Product Updates

See what each release added and fixed.

15 release entriesCurrent v0.11.1Trace the release track
NEXT
IN DEVELOPMENT

Pro Beta Planning & Evidence Iteration

Evidence-led public intelligence improvements continue while v0.12.0 Pro Beta implementation now includes default-off direct email-OTP accounts, local Stripe and Substack adapters, dual-email recovery, server entitlements, Watchlist Delta and reviewed private Brief revisions. Production registration, payment, provider reconciliation and recurring decision-workflow evidence are not yet complete.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. The latest verified Event ledger now gives evidence the primary visual weight: Save is the same compact 44px bookmark utility used by the three homepage deep reads, while its Save/Saved text remains available to assistive technology and its dynamic title and state behavior stay intact. The shared Account, Watchlist and conditional Billing workbench reduces the display-title ceiling from 4rem to 2.75rem and lowers section headings without shrinking body copy, touch targets or controls. The Public and Member Workers deliver this UI slice together without a database migration
  2. Event Watchlist capacity now defaults to twenty saved Events for Free and no product-level collection quota for Pro. The Member Worker resolves the effective entitlement on every read and mutation, returns maxItems=20 or null, and renders used capacity or Unlimited accordingly. Free/Pro plan limits, mutation item count and request-body safety ceilings are centralized defaults with controlled runtime overrides; invalid configuration fails back to safe defaults, and request safety is not presented as a paid-plan quota. Downgrading never deletes saved Events and still permits removal toward the Free limit, while new additions remain blocked above it. The runtime and configuration are deployed; authenticated Free/Pro capacity still awaits controlled production browser acceptance
  3. The public acquisition loop is now one coherent path: a reader opens a verified Event, chooses Save, continues through the unified Google sign-in-or-create action, returns to the same public page, completes the pending save, and can revisit the private Watchlist. Free Watchlist is visible in the desktop header, mobile bottom navigation, homepage and footer; Decision Brief remains a separate secondary path, every new anonymous link goes to /login with an allowlisted source, and authenticated visits to /login return safely to the requested page or Watchlist. Pending Event consumption works for initial controls and dynamically mounted drawers, clears only after success or an already-saved result, and empty Watchlists suggest at most three current verified Events without saving them. The Newsletter fallback states its actual sample date, removes repeated legacy-weekly explanations and uses a ruled reading sequence instead of three equal cards. Migration 0025 stores only fixed Google/account/first-save/7-day-return stages, UTC day, environment and source—never email, IP, user agent, referrer, raw OAuth state or subject, return URL or Event content. Google identity linking is excluded from acquisition, and OAuth completion/account creation is recorded only after Session issue succeeds. Member-bound rows cascade on account deletion; an independent retention Cron purges rows older than 180 days even while private-content maintenance stays disabled, with aggregate-only output and fail-open telemetry. Unspoofable HEAD probes preserve side-effect-free GET routing status, including projection-not-ready, without creating a Watchlist or counting a human visit; HEAD requests to the Google callback return 405 before token exchange, identity writes or Session issue. This slice is committed and deployed, and migration 0025 is applied to production D1. Anonymous entry, redirect and health checks are accepted; authenticated automatic save and return still await controlled production browser acceptance
  4. Watchlist is now an Event-first reading memory instead of a second Topic preference editor. New accounts start with an empty list; Free readers may save zero to twenty Events, Pro has no product-level collection quota, and either plan can remove the final Event. Topic choices remain local to public Trend ordering and no longer appear in Watchlist or consume its capacity. Legacy Topic and Trend rows are hidden without a destructive migration and are naturally pruned by the next versioned Event mutation. The runtime is deployed; authenticated production and historical-data acceptance remain open
  5. Public pages now hydrate only the boolean authenticated Session state with a same-origin no-store request. Desktop, mobile, homepage membership and footer acquisition links become Account and Watchlist for signed-in readers without projecting email, plan, capabilities or Session data into cacheable HTML. A known anonymous Save intent records the pending Event and redirects immediately through the unified Google entry; unknown or expired Sessions still fail closed through the Watchlist 401 path, and the Event is saved after return. This reuses the existing Session and Watchlist APIs, adds no migration, and is deployed; authenticated production browser acceptance remains open
  6. Public Event retention now connects to the existing default Watchlist instead of stopping at a decorative control. The three homepage deep reads, verified update rows, Event detail and timeline evidence drawer expose one Save/Saved action backed by the versioned Watchlist GET and PUT contract; signed-out intent continues through the unified Google entry and returns to the original Event before saving, while signed-in state is refreshed from the server, submits only Event items and retries one version conflict. Free fails visibly at twenty Events without overwriting existing items; Pro has no product-level collection quota. Open the evidence remains the primary reading action in the three homepage Briefs, while Save and Share are compact icon-only 44px utilities with dynamic titles, accessible names and complete states. Public share controls across the homepage, completed daily brief and static or live Event detail use the standard share glyph instead of the ambiguous X-shaped brand mark. Other lists and Event detail retain visible labels. Event detail groups Share on X with canonical-link copy in one compact menu. No migration or public member-state projection is introduced. The previously deployed runtime remains live; this icon treatment is local until the next deployment, and authenticated save/share browser acceptance remains open
  7. The private Member area now has two top-level destinations: Watchlist for recurring Event retention and Account for sign-in, privacy and data controls. Public sign-in and first-time account creation return to the Event-first Watchlist, while Topic preferences stay local to the public Trend view. Primary member actions now use the cool-teal accent with selector specificity that keeps their light labels visible instead of rendering near-black blocks. The standalone settings route, its public proxy entry and the static site's legacy settings data attribute are removed; /settings now returns 404. Internal list versions and cursors are no longer rendered, the Delta action appears only when its server rollout is open, and Free accounts without verified purchase history no longer receive top-level Billing navigation or empty subscription and payment operations. Direct Billing access remains available as a compact truthful Free state. Production payment, Restore, Delta and Decision Brief flags are unchanged
  8. Member entry now stays on the first-party https://aigc.news/ origin. The public Worker forwards an allowlist of login, Account, Watchlist, settings, billing and private API paths to the isolated Member Worker through a Cloudflare Service Binding, and Google OAuth uses the exact callback https://aigc.news/auth/google/callback. Users, same-origin checks and __Host- Session cookies see one hostname while Google secrets and member writes remain isolated. Public /briefs, Event, Trend and Newsletter APIs, Sitemaps and static assets stay on the public runtime; account.aigc.news remains only a migration fallback and is no longer generated in new user links
  9. Member access now has one Google entry instead of separate login and registration decisions. /login shows Continue with Google: an existing identity signs in, while a first-time identity creates a Free account under the current Terms and Privacy versions; Newsletter consent remains separate. The legacy /register URL preserves only a safe same-site returnTo and recognized OAuth errors before redirecting with private no-store caching to the unified page, and OAuth failures return there as well. The old login mode remains fail-closed for compatibility and cannot create an unknown identity. The compact 28rem Studio-cool surface keeps Google as the only public method, uses only a compact AIGC.NEWS wordmark and back link without an additional graphic logo, removes email and code UI, and adds an in-button loading state without changing Session or entitlement boundaries. A controlled user has completed the existing main-domain Google provider smoke; the current acquisition and Event-save slice still requires a fresh post-deploy browser acceptance
  10. The Google OIDC slice defines a useful Free post-login path rather than an empty account shell: both first-time and returning members enter an Event-first Watchlist, which may stay empty until they deliberately save a public Event. Topic choices remain optional local Trend-view preferences and do not become member Watchlist items. The optional onboarding route remains available for future controlled Brief personalization but is not a login gate. Public Event, Trend and Evidence facts remain free; Google login grants no Pro entitlement and does not enable Newsletter consent, Checkout, Substack Restore, Delta or Decision Briefs. Authorization Code plus PKCE, signed state, nonce and Google JWKS/RS256 ID-token verification remain unchanged, and only the provider subject binding is stored. Account continues to expose boolean-only sign-in status plus session, export and deletion controls without provider subject data
  11. The critical Member journey now has a real 390x844 local browser acceptance path. One isolated account uses both development OTPs to bind a different-email Substack purchase and restore Pro; another runs the no-charge site subscription through cancel-scheduled, expiry to Free, visible repurchase/recovery controls and reactivation to Pro with zero console errors. The run exposed and fixed two Billing blockers: development completion did not persist a succeeded Checkout payment state, and a historical successful Checkout was treated as processing forever after its associated subscription terminated, hiding the next purchase action. Billing now distinguishes a newer Checkout still awaiting subscription projection from a completed historical attempt whose later terminal subscription is authoritative. This is local isolated-D1 evidence only, not Stripe sandbox, real Substack or production acceptance
  12. The v0.12.0 local release gate now runs one privacy scanner over the real static export, versioned repository snapshot, safe log fixtures, error artifacts and aggregate Analytics fixtures. It rejects non-allowlisted email addresses, credential-bearing URLs, secrets and headers, payment-provider object identifiers, private identity/billing/content fields, internal data names and local filesystem paths; runtime artifacts additionally reject IP, OTP and Session values plus raw subscriber CSV rows, while reports contain only category and file location. The audit exposed upstream release and commit email addresses in public Signal summaries and the historical snapshot; public serialization now redacts them, credential-bearing public URLs fail closed, and a narrow host allowlist preserves public kernel mailing-list Message-ID links without allowing general email leakage. The versioned snapshot changed only 114 redactions with identical structure and counts, and 416 real text artifacts scan with zero issues locally. Production logs, Pages/CDN and Analytics receivers remain unverified
  13. The two billing sources now share one adapter-level member lifecycle integration. A signed Stripe subscription webhook and controlled Substack full/delta reconciliation create two finite source grants through the normalized inbox, deterministic projector and OR resolver. Stripe cancellation leaves Pro active through Substack; an explicit Substack terminal delta removes the final source and immediately returns the account to Free; a later Stripe reactivation restores Pro. The test never edits the legacy plan or current entitlement records directly and preserves foreign-key integrity. This remains local provider-fixture evidence, not Stripe sandbox or production Substack synchronization
  14. The subscription projector now has deterministic concurrency and crash-recovery gates. An expand-safe last_event_order_key orders provider occurrence time, controlled receipt time, restrictive lifecycle rank and event id; losing events remain in the ignored inbox and cannot overwrite the current subscription or source grant. Provider identities produce deterministic internal customer/subscription ids, while D1 triggers require both objects to share one member owner. Tests cover sequential, delayed and concurrent replay, equal-timestamp state/event conflicts, reconciliation plus webhook on one subscription, and legacy backfill alongside a live provider grant. A forced abort at entitlement-event insertion rolls back customer, subscription, inbox, grant and audit writes before the same event retries safely. This is local D1 evidence only, not provider-sandbox or production acceptance
  15. The v0.12.0 identity slice now has an executable OTP and Session security matrix. In addition to registration, purpose binding, replay, concurrent single consumption, attempt locking, logout/revocation and fresh-auth binding, local tests prove that email-hour, email-day, device-hour, IP-hour and global-hour budgets fail closed before a code is created and emit aggregate no-PII metrics only. Login verification presented with a caller-selected cookie always issues a new random Session token and id rather than accepting the supplied value. This is local D1 and mock-Email evidence only; production Email Sending and real OTP delivery remain unverified
  16. The automated release contract now requires package and product versions to match, exactly one website entry marked released with releaseReady=true, and valid identical dates in the website and repository changelogs. Negative tests reject unreleased, non-ready, empty, impossible, mismatched and duplicate entries, while generated GitHub Release titles now use AIGC.NEWS. An expand-schema compatibility suite also executes the pre-v0.12 Worker column-level SQL and legacy cookie/session path with every v0.12 rollout gate off. It exposed and fixed rolling deployment rejection of sessions created by the old Worker after migration: the new Worker uses session created_at only when the new authenticated_at column is null. The formal version remains v0.11.1; no tag, release or deployment is created by this change
  17. The default-off public Pro-sample path no longer depends on an editor hand-writing placeholder JSON. The existing Pro content review workspace lists gated Event/Evidence candidates from the active public projection, then accepts only one to twelve public refs, a controlled decision lens and a slug. The server rebuilds a URL-free model input with no member, Watchlist, payment, provider or free-text profile data, and applies the Decision Brief v2 question, priority, seven-change, one-to-three-action, near-term-action and counter-signal gates. A D1 idempotency record is inserted before model invocation so exact replay returns the same drafted sample without another charge; request, model or validator failure creates no sample. Success remains review-only and never publishes automatically. This has mock-model and local D1 evidence only; no real model or real sample was used and PRO_SAMPLE_PUBLISH_ENABLED remains false
  18. The no-charge local Checkout now includes a development-only Manage subscription lifecycle. After simulated payment, the Billing portal returns to a session-owned local page that projects active to cancel-scheduled to expired to active through the real normalized subscription-event inbox and entitlement projector. Pro remains valid before the verified period end, becomes Free on expiry, and returns on reactivation of the same subscription; identical idempotency keys do not create another event, guessed cross-account objects return 404, and provider subscription IDs are never rendered. Every page and API is 404 in production. This proves the local state machine and UI only, not Stripe sandbox, a real Portal, cancellation or revenue
  19. Pro Decision Brief generation now has a default-off v2 quality gate. The model receives only a controlled onboarding primary-use lens—company strategy, product planning, investment research, technical diligence, market research or general executive—with no email, free-text profile, organization, payment or provider data. A candidate must ask a concrete decision question, preserve the highest-priority Delta changes in order, show at most seven changes, contain one to three actions with at least one inside 30 days, and include non-empty decision impact, counter-signals and supports/weakens conditions. The same gate applies to Admin approve/correct so manual editing cannot reintroduce oversized or empty output. This is locally verified only; real-model quality, editor samples, preview and recurring delivery remain incomplete
  20. Watchlist Delta now uses delta-v2-materiality: a published object is not automatically material, explanatory-only Events and ordinary Trend refreshes count as checked without becoming items, and future Events or revisions are neither emitted nor consumed by the target cursor. Corrections sort first and the default-off hourly maintenance can queue a relevant correction inside the normal 24-hour cadence, while the same input hash folds correction, scheduled and member refresh triggers into one Workflow run. No-change still returns the current thesis and public Watch next. This is locally verified only; production content and maintenance flags remain off, and recurring-content/preview acceptance is incomplete
  21. The legacy Member share-template surface is now explicitly an optional publishing add-on, while the Pro page continues to lead only with Watchlist Delta, reviewed Decision Briefs and their archive. Free users on /share and the plan-required compose API return to the first-party /pro value page instead of being told to upgrade for sharing or being sent directly to the external newsletter. The public entry remains closed, this is local code only, and it does not make Pro purchasable
  22. The v0.12.0 work now makes the permanently free public-facts boundary executable. Public Event facts and Evidence URLs, published Trends, and every initial, material-shift and correction revision remain on the Public Worker without consulting Member Session, entitlement or Pro-content flags. Anonymous requests and requests carrying invalid Member cookies or Authorization return identical public DTOs with shared public caching and no Cookie variance; public history pagination reaches every published revision. Static validation also requires each published Event page to expose every safe Evidence URL and rejects member-only, entitlement, upgrade or login-continuation gates on Event and Trend output. A local export of 348 Events passes with zero integrity issues. This does not make registration, payment or Pro content operational, and production edge/cache acceptance remains incomplete
  23. The default-off v0.12.0 private Watchlist, Delta and Brief paths now have an explicit object-authorization and concurrency attack matrix. A default-Watchlist mutation affects only the Session member; another member who guesses a snapshot or Brief id receives the same non-enumerating 404 and cannot checkpoint, read HTML/API body or write feedback. Two distinct idempotency keys racing the same snapshot and cursor produce exactly one 200 and one 409, one cursor advance and one checkpoint row. Removing the final entitlement makes the next Delta and Brief list/detail/feedback requests return 403 with private no-store, without trusting old client state. The model request is also asserted to omit the current account email/member/Watchlist/provider/Evidence URL and another member's private focus item. These are local D1 tests only; the production audience remains off
  24. The default-off v0.12.0 private Brief Admin surface now lists only the latest published, corrected or withdrawn revision per series as a safe summary, and exposes strict detail only for the current editable revision. Withdrawn detail returns a null payload; superseded, review and rejected rows are not readable through this route. Correction and withdrawal retain expected-revision, current entitlement, Delta and Evidence provenance, strict brief.v1 validation and append-only member audit. A 409 keeps the editor contents and focus, while payloads never enter URLs, logs or localStorage. An isolated local D1 browser journey passed published revision 1, corrected revision 2 and body-free withdrawn revision 3 at desktop and 390px with no horizontal overflow and zero console errors or warnings; it also caught and fixed a tab panel whose CSS display overrode hidden. Production publishing remains false, and real-candidate plus preview/production acceptance remain incomplete
  25. The default-off v0.12.0 private Delta and Decision Brief path now uses independent versioned JSON Schema artifacts at runtime. Delta snapshot commit and every GET state plus published/corrected Brief serialization fail closed on unknown fields, HTTP or credential-bearing Evidence URLs, HTML and Decision Brief timeframe drift outside 24h, 7d, 30d or 90d. A source prompt-injection corpus covers instruction override, JSON breakout, HTML, URL exfiltration and duplicate-change attacks, proving injected source text remains JSON data and cannot create structural fields, unknown Delta ids or bypass the strict model-output validator. Local contract and runtime DTO tests pass; real-model adversarial and production content-quality acceptance remain incomplete
  26. The default-off v0.12.0 billing plane now exposes an Access-approver-only, read-only aggregate reconciliation report. Fixed checks cover normalized duplicate provider identities, legacy Pro without a current finite source, customer/subscription ownership or parallel-active conflicts, unknown states, overdue synchronization and open quarantine grouped by internal reason code. The query never selects or returns email or email hashes, member/provider/payment object ids, subscriber lists, quarantine object/details, actor or raw payload, and reading it cannot grant, revoke, transfer or resolve anything. Local D1, API-role, no-store and privacy tests pass; alert delivery and production reconciliation remain disabled and unverified
  27. The default-off v0.12.0 private Member surface now has a static-publishing hard gate. Account, Pro, Billing, Restore, Watchlist, Delta and Brief responses have no-store and noindex contract coverage; public validation fails if Auth, Account, Pro, Restore or Watchlist directories appear in the static root, and scans the Sitemap, News Sitemap, llms.txt, robots.txt plus root RSS, Atom and Feed XML for Member origins, private pages or member API URLs. Public /briefs/:slug samples and /product/ remain allowed. The current local dist passes; production edge and cache acceptance remain incomplete
  28. The default-off v0.12.0 Member entry and Pro pages now have a first accessibility and no-JavaScript safety pass. Register and login use native forms with Enter submission, required consent and OTP constraints; Auth, Account, Billing, Restore and Delta mutations expose disabled and aria-busy states, assertive error live regions, network-failure recovery and focused retry fields. Without scripts, Auth and Restore hide native forms so email cannot fall into a default GET, Billing performs no mutation, and committed server HTML remains readable. Local 390x844 browser checks passed the two-step OTP Enter flow, Auth, Account, Billing, Restore and closed-Brief overflow and 44px targets, 3px Tab focus, Restore 503 recovery and key no-script states. Real screen-reader, keyboard and no-script content-state coverage for Watchlist, committed Delta and Brief detail plus production acceptance remain incomplete
  29. The default-off v0.12.0 private Delta and Decision Brief routes now share one server-side Pro authorizer with a fixed fail-closed order: valid Session, feature and audience, rollout allowlist, capability entitlement, then object ownership. A closed rollout no longer advertises an unavailable upgrade to Free members, an allowlist miss does not reveal entitlement state, and only an open audience returns the entitlement-required upgrade boundary. The signed-in Brief closed state returns to Watchlist instead of asking the member to sign in again. Delta and Brief API, HTML, feedback, downgrade and cross-account reads remain private no-store and ownership-scoped, with off/free/allowlist matrix tests passing locally
  30. The default-off v0.12.0 Stripe Checkout path now stores an allowlisted checkout-event inbox and separates Session lifecycle from payment state. Completed-unpaid, async-payment-succeeded, async-payment-failed and expired events converge to pending, succeeded, failed and abandoned without granting Pro; provider occurrence time prevents late completion or expiry from regressing newer facts, exact event replay is a no-op and a reused event id with changed normalized facts is quarantined. A linked PaymentIntent reuses the common payment-alias ledger, while subscription-mode Sessions without one wait for Invoice facts instead of fabricating a payment. Billing reads the persisted state after the return query disappears, suppresses repeat purchase while verification is pending, and exposes failed or expired recovery honestly. Migration-upgrade, recovery, ordering, replay, mismatch, missing-PaymentIntent and no-early-entitlement tests pass locally; Stripe sandbox/live and a real asynchronous payment method remain unverified
  31. The default-off v0.12.0 invite-only Checkout gate now uses finite D1 grants instead of an unaudited environment-variable member list. Only an active member with an unexpired grant can see a purchase control or create Checkout while SITE_CHECKOUT_MODE is allowlist. Cloudflare Access approvers use expected-version grant, up-to-90-day renewal and revoke mutations whose conditional audit insert shares the same D1 batch; expired, revoked, stale-version, editor, wrong-Origin and legacy environment-list attempts fail closed. Admin DTOs omit member email and public export forbids the table name. Production mode remains off
  32. The default-off v0.12.0 Billing and Restore surface now has purpose-specific HMAC rate buckets for same-email claim, dual-email Restore request/verify, Checkout and Portal. Restore limits member, IP, global and target purchase email scopes, including a three-per-day target ceiling across rotating accounts and IPs; replaying the same idempotency key does not count or send again. D1 stores only action, dimension, a 64-character HMAC scope, bucket and count, maintenance removes buckets after 48 hours, and public export treats the table name as forbidden. This has local tests only; production gates remain off
  33. The default-off v0.12.0 entry funnel exposes Sign in and Start free on public desktop, mobile More and the footer, then sends verified Free members directly to Watchlist; one-to-six topic management now lives on that retained-use surface, while /onboarding remains an optional compatibility page instead of a first-reading gate. A development-only checkout simulator is available only when environment, dev OTP and dev checkout gates all agree, labels itself as no-charge, and reuses the real subscription/payment event projectors so the isolated local journey can prove Free, checkout, Pro entitlement, Delta/no-change and Billing without fabricating Stripe sandbox or revenue evidence. The full desktop path plus 390px critical states completed with zero console errors. Maintenance deletes OTP HMAC rate buckets older than 48 hours. Production registration, checkout, content, Substack and maintenance gates remain off, and real Email, Stripe sandbox, alert delivery and preview/production acceptance are still incomplete
  34. The default-off v0.12.0 public Pro-sample path now accepts only strict content plus Event/Evidence references that resolve in the active public projection. Draft, publish, correction and withdrawal are immutable expected-revision records; publication atomically writes a dedicated public version and current pointer with an audit row that has no member link. The public Worker reads only those public projection tables through /api/v1/pro-samples/:slug and /briefs index/detail, revalidates the current pointer with revision ETags, and returns a body-free withdrawal DTO instead of a stale sample when Evidence changes. An Access-protected Admin workspace now lists latest revisions, edits strict public input, publishes/corrects/withdraws samples and exposes only safe summaries for private Brief approve/reject. Withdrawn Admin detail is read-only and cannot recover superseded body content. An isolated local D1 browser journey passed draft, publish, correction, withdrawal, desktop/390px rendering and zero console errors. Email, member/Watchlist/private-Brief/run/payment/provider identifiers, unknown Evidence and stale projection refs fail closed. No real sample has been created or released, PRO_SAMPLE_PUBLISH_ENABLED remains false, and preview edge/cache plus content-value acceptance remain incomplete
  35. The first private v0.12.0 value slice now has a single versioned Watchlist, per-item active-public-projection baselines, explicit cursors and optimistic mutation guards, so existing history is not mislabeled as a first-time change and newly added items start at their join point. /watchlist/delta and its v1 APIs re-check server-side watchlist.delta entitlement plus PRO_CONTENT_AUDIENCE and PRO_DELTA_ENABLED before every private read or mutation. A deterministic compiler pins projection/input hash, compares intrinsic Event timestamps and per-Trend revision numbers so a projection copy cannot fabricate change, resolves real public Trend DTO Evidence, persists ready/no-change/pending/stale/failed envelopes, and advances only through an exact snapshot/watchlist/cursor/projection checkpoint. Member requests only create queued runs; a dedicated MemberContentWorkflow retries bounded compilation, re-checks audience and entitlement before execution and commit, permits same-input retries after failure, and then runs a default-off model Brief step. The model receives only a rebuilt, URL-free Delta input with no member, payment or provider data; strict versioned output validation rejects unknown or duplicate Delta IDs, URLs, HTML and extra fields, while Evidence is rebound from the server ledger. Missing model configuration, request failure or invalid output fails only the Brief run and never publishes a filler or invalidates the verified Delta. Valid output remains review-only until Admin approve/reject/correct/withdraw re-checks the publish flag, current entitlement, expected revision, Evidence ledger and Delta provenance; the Admin surface now exposes safe summaries, approve/reject and current-revision correct/withdraw controls. A separate default-off hourly maintenance handler folds due entitled Watchlists into the same input hash, recovers stale queued/running jobs, and records aggregate-only retention runs while clearing Delta payloads after 90 days, Pro Brief payloads after 12 months of continuous access or a 90-day post-downgrade recovery window, unreferenced run metadata after 30 days and member audit rows after 180 days. After the 24-hour account-deletion window it atomically removes identity, OTP, sessions, preferences, Watchlist/Delta/Brief/feedback and current grants per member while detaching retained subscription/payment/refund/dispute facts from member and email; one failed account is isolated for the next retry. Expired Delta rows return stale and cannot advance cursors. Alert delivery, real-candidate and public-sample content, preview crash recovery, deletion-SLA and production availability remain incomplete, and all production content and maintenance flags stay off
  36. v0.12.0 billing and entitlement implementation now has a local-only, provider-neutral ledger for customers, checkout intents, subscriptions, payments, normalized subscription/payment events, current grants, append-only entitlement events, reconciliation runs/items, claim challenges and quarantine. Existing legacy Pro/Founding rows receive only a finite 90-day manual_legacy review grant and never become fabricated payments. Session, Account, Billing and legacy member-share gates resolve independent Stripe, Substack and manual sources server-side instead of trusting members.plan. The first Stripe adapter creates server-mapped Hosted Checkout and Portal sessions, verifies raw-body webhooks, projects subscription lifecycle, and never grants from a success redirect. Invoice, Refund and Dispute events converge through allowlisted PaymentIntent, Charge, InvoicePayment and Invoice aliases; partial/full refunds and disputes update payment facts without inferring that an otherwise active subscription has ended, and Billing/Account export expose only safe summaries. Billing now renders processing, canceled return, scheduled cancellation, past-due, partial/full refund, dispute, failure, expiry and duplicate-source states from verified ledgers; an unverified Checkout return suppresses repeat-purchase controls, while delayed Substack imports direct the member to wait for reconciliation or use Restore. The Substack path locally normalizes allowlisted columns from the official Subscriber Dashboard CSV before an Access/approver Admin reconciliation applies full or delta runs, row-count protection and finite 72-hour leases; free rows never create billing objects and gift/comp/trial access never becomes reported revenue. Same-email pending purchases can be claimed atomically during registration or refreshed later, while /restore-access binds two OTPs to one member/session/customer for different-email recovery. Production DIRECT_REGISTRATION_ENABLED, SITE_CHECKOUT_MODE, SUBSTACK_RESTORE_ENABLED and Admin SUBSTACK_RECONCILIATION_ENABLED remain off; no remote migration, provider sandbox/live acceptance, real payment/refund or Pro content availability is claimed
  37. The underlying v0.12.0 account core still includes the earlier default-off direct-registration and purpose-bound OTP slice for recovery and compatibility: new-email OTP can atomically record policy, Free member, consent, audit and a secure Session in controlled environments; Account can append communication consent, export only the signed-in DTO, and queue version-checked deletion while revoking every Session. HMAC challenges, enumeration-safe responses, layered email/daily-rotating-device/IP/global limits, replay protection, fresh-auth binding and deletion integrity have local D1/mock-email coverage. Hourly abuse metrics contain only metric, purpose, dimension and count; no scope hash, email, IP, device or challenge is stored. Production D1 migrations 0011–0024 were subsequently applied, but public direct OTP registration remains disabled, /register is now only a compatibility redirect, migration 0025 is not applied, and no production deletion-SLA, real-email, payment-provider, Substack or Pro-content acceptance is claimed
  38. The v0.12.0 Pro Beta docs-first specification now defines planned direct email-OTP registration, a first-party checkout adapter, Substack purchase reconciliation and access recovery, server-side subscription entitlements, Watchlist Delta, evidence-linked Pro Decision Briefs, privacy boundaries, operational recovery and real-payment acceptance gates; none of these planned capabilities are represented as released, and the formal product version remains v0.11.1
  39. The public product is now explicitly English-only: earlier plans for an indexable Chinese /zh mirror are superseded, and neither the current product nor v0.12.0 restores /zh or /zh/* product routes
  40. Public X sharing now uses credential-free Web Intents: readers can share the current three-story homepage brief, an individual homepage Event, or an Event detail only after confirming in X; static export and live Worker hydration use the same bounded public-field copy and canonical URLs, while the separate Pro template code remains an unpublished entitlement
  41. SEO now expands beyond the AIGC News brand query: the homepage explicitly serves AI news intent while preserving evidence-led differentiation; only Events that pass evidence, observable-change, and decision-depth gates remain indexable, with accurate per-Event modification dates, a 48-hour Google News Sitemap, large-image metadata, and a first-party About & Editorial page that explains responsibility, AI assistance, and the Decision Brief relationship
  42. Hourly collection now uses recoverable leases: workflow-start failures are written back immediately, stale queued jobs without an instance are failed after five minutes, and inactive queued/running jobs are recovered after thirty minutes so one orphaned record cannot freeze the public projection
  43. Decision Brief now treats the official Substack RSS feed as the public source of truth: the Worker exposes an allowlisted latest-post DTO and atomically hydrates the dated sample on /newsletter/ with a 24-hour daily edge cache, while timeout, redirect, size, origin, or schema failures preserve the complete versioned static fallback; new posts may take up to one day to appear, and publishing, audience selection, and final Send remain manual in Substack
  44. The public site now prioritizes visitor retention without overstating the newsletter: homepage briefs require a concrete material change and distinguish publishers from hosting platforms; a local Decision Brief explainer with a dated public sample follows the three deep reads, explicitly discloses the external Substack page's legacy weekly wording, and routes Event or Trend subscription intent through the local contract first; static Events no longer expose an ungated Pro share prompt, and dynamic navigation points Verifiable Actions to the real Scout route; Event and Trend details restore full navigation, evidence context, and related exits; Signals opens with five source-distinct leads and category breadth first, while Scout and Sources use ranked small batches before accessible progressive disclosure; mobile navigation keeps Today, Trends, Timeline, Brief, and More with 44px targets and managed focus
  45. The homepage now opens with a three-story jump index and explicit selection rationale; verified Event updates show four items first on mobile and expand to eight while preserving real 24-hour / 7-day / 30-day totals; Trend Pulse adds what to watch next, the top bar focuses on three primary routes plus trend customization and Newsletter, source and date labels are more precise, and unsupported weekly promises have been removed
  46. The homepage now has three deliberate reading depths: three full decision briefs, a live published-Event update ledger with 24-hour / 7-day / 30-day windows and server totals, and one 7-day / 30-day Trend Pulse that labels unchanged reviews explicitly; top-three Events are deduplicated, verified updates require primary evidence or two independent sources, and Signals or future/invalid-time Events never enter the homepage
  47. Homepage and footer guidance typography now sits below editorial content: the completion note, Newsletter prompt, method disclosure, footer statement, wordmark and weekly-brief link use compact responsive sizes while Event headlines keep their existing hierarchy
  48. The homepage is now a continuous 5–8 minute daily decision brief: three ranked Events each show What happened, Why it matters, and What to watch next; evidence opens in place, static export and Worker hydration share the same materiality ranking, random judgments are removed, and the Newsletter appears after the main reading flow
  49. The earlier parallel 0.0.x-to-0.1.0 commercial numbering is superseded by the repository's single SemVer line and the planned v0.12.0 Pro Beta specification; historical planning no longer names future releases
v0.11.1
LATEST RELEASE

Audited Research Continuity

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.11.0
RELEASE

Clearer Evidence and Automated Briefs

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.10.0
RELEASE

Living Evidence Interface

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.9.0
RELEASE

Evidence-Dense Decision Intelligence

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.8.1
RELEASE

A Denser Action Surface

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.8.0
RELEASE

The Industry Evolution Map

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.7.0
RELEASE

The Autonomous Intelligence Loop

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.6.0
RELEASE

The Intelligence Atlas

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.5.1
RELEASE

Snapshot Parity

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.5.0
RELEASE

The Evidence Engine

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.4.0
RELEASE

The Industry Arc

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.3.0
RELEASE

Primary Source Protocol

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Evidence-led event coverage Bilingual publishing controls Source and signal monitoring

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.2.0
RELEASE

The Source & Scout Foundation

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

SourceRun Opportunity Scout

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.
v0.1.0
RELEASE

First Signal

An editorial intelligence update focused on clearer evidence, stronger localization, and a more reliable public reading experience.

New Capabilities

Control Room

What Changed

  1. Improved the public reading experience and strengthened the underlying editorial workflow.