[{"data":1,"prerenderedAt":520},["ShallowReactive",2],{"$f1h3d1mgzsbob":3,"mdc--em1v6t-key":15},{"release":4,"newer":10,"older":12,"page":14},{"tag":5,"name":5,"publishedAt":6,"url":7,"prerelease":8,"markdown":9},"v1.0.7","2026-03-20T19:59:54Z","https:\u002F\u002Fgithub.com\u002Fanhourtec\u002FBookYourPTO-SaaS\u002Freleases\u002Ftag\u002Fv1.0.7",false,"### New Features\r\n\r\n- **E-Signature Platform** — Complete document signing system with drag-and-drop field placement, sequential and parallel signing workflows, typed or drawn signatures, and multi-signer support.\r\n\r\n- **Drag-and-drop field placement** — Place signature, initials, date signed, name, email, company, and title fields directly onto PDF documents. Fields are color-coded per signer.\r\n\r\n- **Sequential and parallel signing** — Configure signing order when assigning documents. Sequential mode notifies each signer only when it's their turn. Multiple signers can share the same order number to sign in parallel.\r\n\r\n- **Typed signatures** — Choose from 8 cursive font styles to generate a typed signature, in addition to drawing freehand. Signatures can be saved for reuse across documents.\r\n\r\n- **Signature validation** — Canvas signatures are validated for quality: minimum size, ink coverage, and stroke complexity. Trivial scribbles are rejected with a clear error message.\r\n\r\n- **Audit trail PDF** — Every signed document can be downloaded with a full audit trail appended, showing all signers' names, emails, timestamps, and signing status.\r\n\r\n- **Document sharing without signature** — Documents can be shared for review without requiring a signature. Recipients receive a notification and email.\r\n\r\n- **Department head document permissions** — Configurable read and create permissions for department heads. Create access implies read. Bulk Send remains admin\u002Fexecutive only.\r\n\r\n- **Breached password detection** — Passwords are checked against the Have I Been Pwned database in real-time as users type during registration and password changes. Breached passwords are blocked from being set. Existing users with breached passwords are notified via in-app notification and email on their next login.\r\n\r\n- **Remember Me** — Server-enforced session vs persistent login. Unchecked by default — users must opt in to stay logged in across browser sessions.\r\n\r\n- **Leave approval from detail modal** — Approvers can now approve or reject leave requests directly from the leave detail modal without navigating away.\r\n\r\n- **Group booking restricted** — Group leave booking is now restricted to administrators and executives only.\r\n\r\n### Improvements\r\n\r\n- **Documents index redesigned** — Sidebar navigation with My Documents, All Documents (admin), Action Required, Completed, and Drafts views. Admins and executives can see all documents across the organization.\r\n\r\n- **Table layout rebuilt** — Documents table uses a proper table layout with status badges, action buttons, and a Recipient column in Action Required view for admins.\r\n\r\n- **Browser back button support** — Switching between document views now uses `pushState` so the browser back button works correctly.\r\n\r\n- **Signature timestamp on PDF** — Each signature and initials field in the rendered PDF shows the signer's name and timestamp.\r\n\r\n- **Email messaging for shared documents** — Emails for non-signature documents say \"shared a document with you\" instead of \"sent for signing.\"\r\n\r\n- **Due date timezone handling** — Due dates are now inclusive with a 24-hour buffer. A document due on March 20 is not marked overdue until March 21.\r\n\r\n- **Dept head uploader filtering** — When department heads upload documents, the user autocomplete is filtered to their department only.\r\n\r\n- **Self-approval prevention** — Users can no longer approve their own leave requests, even if they have approver permissions.\r\n\r\n- **Dashboard scroll optimization** — Scrollbar only appears on screens below 1320px width.\r\n\r\n### Security\r\n\r\n- **Data encryption at rest** — Sensitive personal data (phone numbers, addresses, tax IDs, emergency contacts, bank details, webhook URLs, leave reasons) is now encrypted at the application level using AES-256-GCM, in addition to database-level encryption.\r\n\r\n- **HttpOnly cookie authentication** — Refresh tokens are now stored in HttpOnly secure cookies instead of browser-accessible storage, protecting against cross-site scripting (XSS) token theft.\r\n\r\n- **Security headers** — Content Security Policy, Strict Transport Security, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are now set on all responses.\r\n\r\n- **SSRF protection** — Webhook URLs (Slack, Teams) are validated against private IP ranges, localhost, and cloud metadata endpoints before making server-side requests.\r\n\r\n- **SSO domain verification** — DNS-based domain verification for SSO prevents cross-organization domain hijacking. HMAC-signed state parameters protect against CSRF in SSO flows.\r\n\r\n- **Breached password blocking** — New passwords are checked against 900M+ known breached passwords via Have I Been Pwned before being accepted.\r\n\r\n- **Auth gate hardening** — Unauthenticated users no longer see a brief flash of authenticated UI. API requests are blocked immediately when no session exists.\r\n\r\n- **Guided tour security** — Tours no longer fire for unauthenticated users.\r\n\r\n### Privacy & Data Protection\r\n\r\n- **Data export** — Users can export all their personal data in machine-readable JSON format from their account settings.\r\n\r\n- **Data deletion** — Users can request deletion of their personal data. Data is anonymized to preserve organizational reporting integrity.\r\n\r\n- **Data sharing opt-out** — Users can opt out of third-party data sharing.\r\n\r\n- **Data retention automation** — Automated cleanup of data beyond the configurable retention period (default 7 years for tax\u002Ffinancial record-keeping).\r\n\r\n- **Privacy policy updated** — Added sections for legal basis of processing, international data transfers, data breach notification, children's privacy, and Do Not Track signals.\r\n\r\n- **Cookie policy updated** — Added details for authentication cookies and security cookies.\r\n\r\n- **Terms of use updated** — Added sections for data processing, data portability, and service availability.\r\n\r\n### Bug Fixes\r\n\r\n- **Completed view duplicates** — Fixed documents appearing multiple times when they had multiple signers.\r\n\r\n- **Action Required filtering** — Shared documents no longer appear in Action Required. View now only shows documents assigned to the current user.\r\n\r\n- **Unassigned fields not rendering** — Legacy fields with null assignment correctly render in the PDF.\r\n\r\n- **Billing: immediate charge on upgrade** — Plan upgrades and add-on purchases now charge proration immediately instead of deferring to the next invoice.\r\n\r\n- **Settings access** — Fixed \u002Fsettings being blocked for non-admin users.\r\n\r\n- **TOTP login flow** — Fixed 2FA verification being blocked by the API interceptor during login.\r\n\r\n- **Email verification resend** — Fixed resend verification endpoint missing auth headers.\r\n\r\n- **Password change token refresh** — Fixed token handling after password change to prevent unnecessary logouts.",{"tag":11,"name":11},"v1.0.8",{"tag":13,"name":13},"v1.0.6",2,{"data":16,"body":17},{},{"type":18,"children":19},"root",[20,29,155,161,263,269,352,358,431,437],{"type":21,"tag":22,"props":23,"children":25},"element","h3",{"id":24},"new-features",[26],{"type":27,"value":28},"text","New Features",{"type":21,"tag":30,"props":31,"children":32},"ul",{},[33,45,55,65,75,85,95,105,115,125,135,145],{"type":21,"tag":34,"props":35,"children":36},"li",{},[37,43],{"type":21,"tag":38,"props":39,"children":40},"strong",{},[41],{"type":27,"value":42},"E-Signature Platform",{"type":27,"value":44}," — Complete document signing system with drag-and-drop field placement, sequential and parallel signing workflows, typed or drawn signatures, and multi-signer support.",{"type":21,"tag":34,"props":46,"children":47},{},[48,53],{"type":21,"tag":38,"props":49,"children":50},{},[51],{"type":27,"value":52},"Drag-and-drop field placement",{"type":27,"value":54}," — Place signature, initials, date signed, name, email, company, and title fields directly onto PDF documents. Fields are color-coded per signer.",{"type":21,"tag":34,"props":56,"children":57},{},[58,63],{"type":21,"tag":38,"props":59,"children":60},{},[61],{"type":27,"value":62},"Sequential and parallel signing",{"type":27,"value":64}," — Configure signing order when assigning documents. Sequential mode notifies each signer only when it's their turn. Multiple signers can share the same order number to sign in parallel.",{"type":21,"tag":34,"props":66,"children":67},{},[68,73],{"type":21,"tag":38,"props":69,"children":70},{},[71],{"type":27,"value":72},"Typed signatures",{"type":27,"value":74}," — Choose from 8 cursive font styles to generate a typed signature, in addition to drawing freehand. Signatures can be saved for reuse across documents.",{"type":21,"tag":34,"props":76,"children":77},{},[78,83],{"type":21,"tag":38,"props":79,"children":80},{},[81],{"type":27,"value":82},"Signature validation",{"type":27,"value":84}," — Canvas signatures are validated for quality: minimum size, ink coverage, and stroke complexity. Trivial scribbles are rejected with a clear error message.",{"type":21,"tag":34,"props":86,"children":87},{},[88,93],{"type":21,"tag":38,"props":89,"children":90},{},[91],{"type":27,"value":92},"Audit trail PDF",{"type":27,"value":94}," — Every signed document can be downloaded with a full audit trail appended, showing all signers' names, emails, timestamps, and signing status.",{"type":21,"tag":34,"props":96,"children":97},{},[98,103],{"type":21,"tag":38,"props":99,"children":100},{},[101],{"type":27,"value":102},"Document sharing without signature",{"type":27,"value":104}," — Documents can be shared for review without requiring a signature. Recipients receive a notification and email.",{"type":21,"tag":34,"props":106,"children":107},{},[108,113],{"type":21,"tag":38,"props":109,"children":110},{},[111],{"type":27,"value":112},"Department head document permissions",{"type":27,"value":114}," — Configurable read and create permissions for department heads. Create access implies read. Bulk Send remains admin\u002Fexecutive only.",{"type":21,"tag":34,"props":116,"children":117},{},[118,123],{"type":21,"tag":38,"props":119,"children":120},{},[121],{"type":27,"value":122},"Breached password detection",{"type":27,"value":124}," — Passwords are checked against the Have I Been Pwned database in real-time as users type during registration and password changes. Breached passwords are blocked from being set. Existing users with breached passwords are notified via in-app notification and email on their next login.",{"type":21,"tag":34,"props":126,"children":127},{},[128,133],{"type":21,"tag":38,"props":129,"children":130},{},[131],{"type":27,"value":132},"Remember Me",{"type":27,"value":134}," — Server-enforced session vs persistent login. Unchecked by default — users must opt in to stay logged in across browser sessions.",{"type":21,"tag":34,"props":136,"children":137},{},[138,143],{"type":21,"tag":38,"props":139,"children":140},{},[141],{"type":27,"value":142},"Leave approval from detail modal",{"type":27,"value":144}," — Approvers can now approve or reject leave requests directly from the leave detail modal without navigating away.",{"type":21,"tag":34,"props":146,"children":147},{},[148,153],{"type":21,"tag":38,"props":149,"children":150},{},[151],{"type":27,"value":152},"Group booking restricted",{"type":27,"value":154}," — Group leave booking is now restricted to administrators and executives only.",{"type":21,"tag":22,"props":156,"children":158},{"id":157},"improvements",[159],{"type":27,"value":160},"Improvements",{"type":21,"tag":30,"props":162,"children":163},{},[164,174,184,203,213,223,233,243,253],{"type":21,"tag":34,"props":165,"children":166},{},[167,172],{"type":21,"tag":38,"props":168,"children":169},{},[170],{"type":27,"value":171},"Documents index redesigned",{"type":27,"value":173}," — Sidebar navigation with My Documents, All Documents (admin), Action Required, Completed, and Drafts views. Admins and executives can see all documents across the organization.",{"type":21,"tag":34,"props":175,"children":176},{},[177,182],{"type":21,"tag":38,"props":178,"children":179},{},[180],{"type":27,"value":181},"Table layout rebuilt",{"type":27,"value":183}," — Documents table uses a proper table layout with status badges, action buttons, and a Recipient column in Action Required view for admins.",{"type":21,"tag":34,"props":185,"children":186},{},[187,192,194,201],{"type":21,"tag":38,"props":188,"children":189},{},[190],{"type":27,"value":191},"Browser back button support",{"type":27,"value":193}," — Switching between document views now uses ",{"type":21,"tag":195,"props":196,"children":198},"code",{"className":197},[],[199],{"type":27,"value":200},"pushState",{"type":27,"value":202}," so the browser back button works correctly.",{"type":21,"tag":34,"props":204,"children":205},{},[206,211],{"type":21,"tag":38,"props":207,"children":208},{},[209],{"type":27,"value":210},"Signature timestamp on PDF",{"type":27,"value":212}," — Each signature and initials field in the rendered PDF shows the signer's name and timestamp.",{"type":21,"tag":34,"props":214,"children":215},{},[216,221],{"type":21,"tag":38,"props":217,"children":218},{},[219],{"type":27,"value":220},"Email messaging for shared documents",{"type":27,"value":222}," — Emails for non-signature documents say \"shared a document with you\" instead of \"sent for signing.\"",{"type":21,"tag":34,"props":224,"children":225},{},[226,231],{"type":21,"tag":38,"props":227,"children":228},{},[229],{"type":27,"value":230},"Due date timezone handling",{"type":27,"value":232}," — Due dates are now inclusive with a 24-hour buffer. A document due on March 20 is not marked overdue until March 21.",{"type":21,"tag":34,"props":234,"children":235},{},[236,241],{"type":21,"tag":38,"props":237,"children":238},{},[239],{"type":27,"value":240},"Dept head uploader filtering",{"type":27,"value":242}," — When department heads upload documents, the user autocomplete is filtered to their department only.",{"type":21,"tag":34,"props":244,"children":245},{},[246,251],{"type":21,"tag":38,"props":247,"children":248},{},[249],{"type":27,"value":250},"Self-approval prevention",{"type":27,"value":252}," — Users can no longer approve their own leave requests, even if they have approver permissions.",{"type":21,"tag":34,"props":254,"children":255},{},[256,261],{"type":21,"tag":38,"props":257,"children":258},{},[259],{"type":27,"value":260},"Dashboard scroll optimization",{"type":27,"value":262}," — Scrollbar only appears on screens below 1320px width.",{"type":21,"tag":22,"props":264,"children":266},{"id":265},"security",[267],{"type":27,"value":268},"Security",{"type":21,"tag":30,"props":270,"children":271},{},[272,282,292,302,312,322,332,342],{"type":21,"tag":34,"props":273,"children":274},{},[275,280],{"type":21,"tag":38,"props":276,"children":277},{},[278],{"type":27,"value":279},"Data encryption at rest",{"type":27,"value":281}," — Sensitive personal data (phone numbers, addresses, tax IDs, emergency contacts, bank details, webhook URLs, leave reasons) is now encrypted at the application level using AES-256-GCM, in addition to database-level encryption.",{"type":21,"tag":34,"props":283,"children":284},{},[285,290],{"type":21,"tag":38,"props":286,"children":287},{},[288],{"type":27,"value":289},"HttpOnly cookie authentication",{"type":27,"value":291}," — Refresh tokens are now stored in HttpOnly secure cookies instead of browser-accessible storage, protecting against cross-site scripting (XSS) token theft.",{"type":21,"tag":34,"props":293,"children":294},{},[295,300],{"type":21,"tag":38,"props":296,"children":297},{},[298],{"type":27,"value":299},"Security headers",{"type":27,"value":301}," — Content Security Policy, Strict Transport Security, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are now set on all responses.",{"type":21,"tag":34,"props":303,"children":304},{},[305,310],{"type":21,"tag":38,"props":306,"children":307},{},[308],{"type":27,"value":309},"SSRF protection",{"type":27,"value":311}," — Webhook URLs (Slack, Teams) are validated against private IP ranges, localhost, and cloud metadata endpoints before making server-side requests.",{"type":21,"tag":34,"props":313,"children":314},{},[315,320],{"type":21,"tag":38,"props":316,"children":317},{},[318],{"type":27,"value":319},"SSO domain verification",{"type":27,"value":321}," — DNS-based domain verification for SSO prevents cross-organization domain hijacking. HMAC-signed state parameters protect against CSRF in SSO flows.",{"type":21,"tag":34,"props":323,"children":324},{},[325,330],{"type":21,"tag":38,"props":326,"children":327},{},[328],{"type":27,"value":329},"Breached password blocking",{"type":27,"value":331}," — New passwords are checked against 900M+ known breached passwords via Have I Been Pwned before being accepted.",{"type":21,"tag":34,"props":333,"children":334},{},[335,340],{"type":21,"tag":38,"props":336,"children":337},{},[338],{"type":27,"value":339},"Auth gate hardening",{"type":27,"value":341}," — Unauthenticated users no longer see a brief flash of authenticated UI. API requests are blocked immediately when no session exists.",{"type":21,"tag":34,"props":343,"children":344},{},[345,350],{"type":21,"tag":38,"props":346,"children":347},{},[348],{"type":27,"value":349},"Guided tour security",{"type":27,"value":351}," — Tours no longer fire for unauthenticated users.",{"type":21,"tag":22,"props":353,"children":355},{"id":354},"privacy-data-protection",[356],{"type":27,"value":357},"Privacy & Data Protection",{"type":21,"tag":30,"props":359,"children":360},{},[361,371,381,391,401,411,421],{"type":21,"tag":34,"props":362,"children":363},{},[364,369],{"type":21,"tag":38,"props":365,"children":366},{},[367],{"type":27,"value":368},"Data export",{"type":27,"value":370}," — Users can export all their personal data in machine-readable JSON format from their account settings.",{"type":21,"tag":34,"props":372,"children":373},{},[374,379],{"type":21,"tag":38,"props":375,"children":376},{},[377],{"type":27,"value":378},"Data deletion",{"type":27,"value":380}," — Users can request deletion of their personal data. Data is anonymized to preserve organizational reporting integrity.",{"type":21,"tag":34,"props":382,"children":383},{},[384,389],{"type":21,"tag":38,"props":385,"children":386},{},[387],{"type":27,"value":388},"Data sharing opt-out",{"type":27,"value":390}," — Users can opt out of third-party data sharing.",{"type":21,"tag":34,"props":392,"children":393},{},[394,399],{"type":21,"tag":38,"props":395,"children":396},{},[397],{"type":27,"value":398},"Data retention automation",{"type":27,"value":400}," — Automated cleanup of data beyond the configurable retention period (default 7 years for tax\u002Ffinancial record-keeping).",{"type":21,"tag":34,"props":402,"children":403},{},[404,409],{"type":21,"tag":38,"props":405,"children":406},{},[407],{"type":27,"value":408},"Privacy policy updated",{"type":27,"value":410}," — Added sections for legal basis of processing, international data transfers, data breach notification, children's privacy, and Do Not Track signals.",{"type":21,"tag":34,"props":412,"children":413},{},[414,419],{"type":21,"tag":38,"props":415,"children":416},{},[417],{"type":27,"value":418},"Cookie policy updated",{"type":27,"value":420}," — Added details for authentication cookies and security cookies.",{"type":21,"tag":34,"props":422,"children":423},{},[424,429],{"type":21,"tag":38,"props":425,"children":426},{},[427],{"type":27,"value":428},"Terms of use updated",{"type":27,"value":430}," — Added sections for data processing, data portability, and service availability.",{"type":21,"tag":22,"props":432,"children":434},{"id":433},"bug-fixes",[435],{"type":27,"value":436},"Bug Fixes",{"type":21,"tag":30,"props":438,"children":439},{},[440,450,460,470,480,490,500,510],{"type":21,"tag":34,"props":441,"children":442},{},[443,448],{"type":21,"tag":38,"props":444,"children":445},{},[446],{"type":27,"value":447},"Completed view duplicates",{"type":27,"value":449}," — Fixed documents appearing multiple times when they had multiple signers.",{"type":21,"tag":34,"props":451,"children":452},{},[453,458],{"type":21,"tag":38,"props":454,"children":455},{},[456],{"type":27,"value":457},"Action Required filtering",{"type":27,"value":459}," — Shared documents no longer appear in Action Required. View now only shows documents assigned to the current user.",{"type":21,"tag":34,"props":461,"children":462},{},[463,468],{"type":21,"tag":38,"props":464,"children":465},{},[466],{"type":27,"value":467},"Unassigned fields not rendering",{"type":27,"value":469}," — Legacy fields with null assignment correctly render in the PDF.",{"type":21,"tag":34,"props":471,"children":472},{},[473,478],{"type":21,"tag":38,"props":474,"children":475},{},[476],{"type":27,"value":477},"Billing: immediate charge on upgrade",{"type":27,"value":479}," — Plan upgrades and add-on purchases now charge proration immediately instead of deferring to the next invoice.",{"type":21,"tag":34,"props":481,"children":482},{},[483,488],{"type":21,"tag":38,"props":484,"children":485},{},[486],{"type":27,"value":487},"Settings access",{"type":27,"value":489}," — Fixed \u002Fsettings being blocked for non-admin users.",{"type":21,"tag":34,"props":491,"children":492},{},[493,498],{"type":21,"tag":38,"props":494,"children":495},{},[496],{"type":27,"value":497},"TOTP login flow",{"type":27,"value":499}," — Fixed 2FA verification being blocked by the API interceptor during login.",{"type":21,"tag":34,"props":501,"children":502},{},[503,508],{"type":21,"tag":38,"props":504,"children":505},{},[506],{"type":27,"value":507},"Email verification resend",{"type":27,"value":509}," — Fixed resend verification endpoint missing auth headers.",{"type":21,"tag":34,"props":511,"children":512},{},[513,518],{"type":21,"tag":38,"props":514,"children":515},{},[516],{"type":27,"value":517},"Password change token refresh",{"type":27,"value":519}," — Fixed token handling after password change to prevent unnecessary logouts.",1790889965215]