Complete-site navigation provisioning: hierarchical/authoritative navigation, registry destination reuse, duplicate suppression, plus all 4.6.57 deployment and migration safeguards.
Full package changelog
# DivisionDesk Core 4.6.58 QA — 2026-09-18
- Site Templates can now provision nested primary/footer navigation.
- `navigation_mode: authoritative` hides stale/duplicate menu items rather than leaving old module links beside the template navigation.
- Template URLs automatically reuse matching registered destinations, preserving module/auth behavior instead of replacing it with hard-coded links.
- Retains all 4.6.57 public-root, CLI, asset, theme, lifecycle and domain-migration safeguards.
# DivisionDesk Core 4.6.57 QA — 2026-09-17
- Makes the configured public filesystem root authoritative across CSS, uploads, image derivatives, setup/health checks, module public payload deployment, Core updates, scheduler bootstrap discovery, and complete-site assets. `public_html`, managed `/public`, and subfolder layouts no longer silently diverge.
- Reworks fresh installation around staged verified extraction, protected license authorization, public-root detection/override, noexec-safe runner execution, HTTPS transport fallback, ZIP extraction fallback, disk/writability preflight, and refusal to overwrite an existing application tree.
- Makes module public deployment fail-safe: modern `addon/public` payloads deploy to the configured public root, while legacy lifecycle writes into canonical `/public` are detected and mirrored before a package is recorded installed.
- Unifies fresh module lifecycle execution through `ModuleLifecycle`: `Install::install()` is authoritative with backward-compatible `Install::run()` support, and missing lifecycle classes/methods now fail installation instead of being silently skipped. Failed module setup is disabled/not marked installed so Cubicle cannot report a partial package as successful.
- Makes Core updates deploy package `/public` into the configured public root transactionally instead of recreating a hidden canonical web root; rollback tracks newly deployed public files.
- Adds complete-site asset deployment/verification and required-theme activation support. A site template cannot report success when declared assets or its required installed theme are missing.
- Makes CLI error handling CLI-safe (STDERR/nonzero exit, no HTTP headers/HTML) and removes the scheduler shebang/public-bootstrap assumptions exposed on cPanel/GoDaddy.
- Persists the installer-selected public path into site configuration and deployment settings; external document roots can use a generated application-root marker.
- Extends Move / Relocate to rewrite known self-URL fields when the canonical domain changes while preserving external URLs, and keeps licensing transfer authorization in the existing relocation flow.
- Retains the newest three successful Core rollback backups by default and safely cleans stale generated installer/repository/update staging directories.
- Rewords System Health telemetry self-test events so successful tests are clearly identified as tests rather than application errors.
# DivisionDesk Core Changelog
## 4.6.56 — 2026-09-15
- Added Core responsive-image derivative service at `image.php` for safe local public images.
- Generates proportional cached WebP derivatives on first request and reuses them thereafter.
- Originals are never modified; cache keys include source path, mtime, size, requested width, and quality.
- Adds long-lived immutable browser caching and ETag support.
- Rejects traversal, remote/non-public sources, cache recursion, and unsupported image MIME types.
## 4.6.55 — 2026-09-15
### Improved
- Public pages now load Core, renderer, and active-theme CSS through one versioned, cached `site-css.php` response, preserving cascade order while reducing render-blocking stylesheet requests.
- Member login and verification documents now declare English language metadata and a meta description.
- Member authentication helper/brand text contrast was strengthened for WCAG AA readability.
## 4.6.54 QA
- Preserve administrator navigation parent/order/label choices across registry synchronization; suggested placement now applies only when a registry destination is first provisioned.
- Exclude wildcard `*` from navigation audience capability choices.
- Normalize www/non-www aliases for high-frequency admin badge/alert polling so requests remain on the origin currently serving the admin UI.
## 4.6.53 QA — 2026-09-15
- Adds explicit Up/Down controls for menu items so sibling order can be changed reliably without changing submenu parentage.
- Disables Up on the first sibling and Down on the last sibling.
- Retains drag/drop for hierarchy changes and all 4.6.52 navigation fixes.
## 4.6.53 QA navigation audience refinement
- Fix site-local custom Navigation URLs so root-relative links such as `/news`, `/events`, `/shop`, and `/admin.php` resolve under the configured DivisionDesk base path instead of the domain root, while avoiding double-prefixing already resolved URLs.
- Added server-side per-menu audience rules: everyone, authenticated members, or a required capability.
- Navigation Manager can assign capabilities such as `admin.access` to custom or registry items.
- Canonicalized legacy member logout destinations to `/logout`.
- Core Home/About destinations now resolve correctly inside Navigation Manager.
# DivisionDesk Core 4.6.53 — Navigation Save and Logout Routing
- Fixed Navigation Manager order/nesting saves under Core's fetch-first POST layer. `tree_json` is now initialized immediately and synchronized after each drag operation, so the fetch capture layer cannot serialize an empty menu tree.
- Public logout now distinguishes a pure administrator login from a normal member login: administrators return to Administration login, members return to the public home page, and mixed/ambiguous sessions safely return home.
- Replaced the active Pages list's textual Trash action with an accessible trash-can icon while preserving all existing protected-page behavior.
- No protected-page lifecycle, registry ownership, or Navigation Manager rename/move/show-hide behavior changed.
# DivisionDesk Core 4.6.47 — Security Schema Verification Compatibility
- Fixes a false security-schema repair failure on managed MySQL/MariaDB hosts immediately after atomic `RENAME TABLE`.
- Unique-key verification now reads live table indexes with `SHOW INDEX` instead of relying on `information_schema.statistics`, which can be stale immediately after an atomic rename on some hosts.
- Index metadata parsing is tolerant of MySQL/MariaDB PDO column-name casing and preserves ordered composite-key verification.
- Security repair schema version advanced to 5 so affected installs re-verify using the corrected path.
- Retains the protected Core download transport fix and Mega Setup hierarchy fix from 4.6.46/4.6.45.
# DivisionDesk Core 4.6.46 — Protected Update Transport Compatibility
- Protected Core package downloads now prefer cURL, matching the working new-install transport and avoiding shared-host failures in PHP URL-stream handling.
- The stream fallback now captures HTTP status instead of collapsing every failure into a generic release-server error.
- Protected one-use download tokens are no longer echoed in updater exceptions.
- HTTP error responses from DivisionDesk Server surface the Server-provided explanation when available.
- Retains the 4.6.45 Mega Setup terminology fix and 4.6.44 fresh MySQL/MariaDB schema parity repair.
# DivisionDesk Core 4.6.45 — Mega Setup Terminology Compatibility Fix
- Fixed `public/mega-setup.php` calling removed `Terminology::all()` after the neutral hierarchy migration.
- Mega Setup now uses the supported `Terminology::mappings()` API.
- Retains the 4.6.44 fresh MySQL/MariaDB schema parity repair.
- Added regression coverage so Mega Setup cannot reference a nonexistent Terminology API again.
# DivisionDesk Core 4.6.44 — Fresh MySQL Install Schema Repair
- Restored MySQL/MariaDB schema parity for ten Core tables that already existed in the SQLite schema but were absent from `database/schema.sql`.
- Fresh MySQL installation now creates `site_settings` before `Settings::seedDefaults()` runs, fixing the setup failure `Table ... site_settings doesn't exist`.
- Also restores fresh-install definitions for Page Builder layouts/revisions, reusable sections, media folders/items, member role assignments, login codes, trusted logins, and menu locations.
- Adds a schema-parity regression so future releases fail QA if a Core table exists for SQLite but is omitted from MySQL.
- No licensing-enforcement behavior changed.
# DivisionDesk Core 4.6.43 — Licensing Enrollment UX
- Adds Settings → Licensing & Enrollment to the administration navigation.
- Core update failures involving licensing/signing keys now link directly to that screen.
- The existing explicit legacy-enrollment workflow remains deliberate; upgrades do not silently enable license enforcement.
# DivisionDesk Core 4.6.42 — Organization Unit Meeting Schedule Text
- Organization Units now treats `meeting_time` as a schedule string rather than an HTML clock-only value, allowing entries such as `2nd Tuesday at 7:00 PM`.
- The editor uses a normal text field with a recurrence-aware example.
- When the authoritative `scv_camps` provider is MySQL/MariaDB and `meeting_time` is a non-text type such as `TIME`, Core safely widens that existing column to `TEXT` before saving. SQLite already accepts text and requires no table migration.
- Core continues to use the existing `scv_camps` organization-unit source and does not create a competing table.
- Licensing, hierarchy semantics, and Store/Cubicle behavior are otherwise unchanged.
# DivisionDesk Core 4.6.41 — Protected Core Update Delivery
- Core updater now requests a signed, license/entitlement-validated one-use download token from DivisionDesk Server before any Core package bytes are transferred.
- Public release metadata remains readable for update discovery, but the updater no longer requires or consumes a public Core archive URL.
- Authorized package version, size, and SHA-256 are cross-checked against the public release manifest before extraction.
- Existing update backup, preflight, migration, rollback, and reporting behavior is preserved.
# DivisionDesk Core 4.6.40 — Mega Setup & Deployment Readiness
- Added a resumable Mega Setup Wizard for new installations while preserving opt-in behavior for existing upgraded sites.
- New installs defer optional entitled package downloads until the administrator chooses desired modules/features in Mega Setup.
- Added guided organization/hierarchy terminology, site-profile/branding, contact/social, timezone, and deployment-layout configuration.
- Added outbound SMTP configuration and test-mail readiness checks; deployment readiness requires a successful real mail test when outbound email is configured for production.
- Added entitlement-filtered module/theme selection and secure download/install using the existing RepositoryClient/package-security path rather than a parallel installer.
- Added entitled theme installation/activation, preview-image support, and site-template application with merge-by-default and explicit replace safeguards/backups.
- Added orchestration of package setup wizards through SetupWizardRegistry, including return-to-Mega-Setup flow; installed modules without a wizard require explicit administrator review, and failed module boots block readiness.
- Added deployment-readiness reporting that separates required actions, recommendations, and completed checks, including scheduler/cron guidance and Core-generated command information.
- Added contextual Learn More guidance for credentials that must be obtained from external providers.
- Added configurable deployment layouts with separate application root, public filesystem path, public URL, and URL base path; `/public`, cPanel `public_html`, and subfolder deployments are supported as distinct concepts.
- Added Website → Configuration → Move / Relocate with Prepare Move and Complete Move phases. Same-host path moves update deployment/base URL state after preflight; hostname changes require the existing licensing transfer/authorization path rather than silently rewriting licensed identity.
- Added first-login onboarding handoff after technical installation and preserved legacy-upgrade safety: existing installations are not forced into the new wizard.
- Retains all Core 4.6.39 neutral hierarchy contracts and compatibility aliases.
# DivisionDesk Core 4.6.39 — Neutral Hierarchy Migration
- Added neutral canonical hierarchy levels `level_1` through `level_4` with compatibility aliases for historical `national`, `division`, `brigade`, and `camp` keys.
- Added configurable singular/plural hierarchy terminology with SCV-compatible defaults.
- Added `OrganizationUnitDirectory`, a neutral Core facade over the existing authoritative `scv_camps` source; Core does not create a second Camp/unit table.
- Added Organization → Organization Units editor with add/edit/suspend/reactivate, contact, meeting/location, and repeatable social-link support when the provider exposes those columns.
- Added hierarchy terminology editor to Organization Units so terminology can be configured before the Mega Setup Wizard is completed.
- Added neutral `unit_code`, `unit_name`, `level_2_name`, and `level_3_name` aliases while preserving existing provider columns for module compatibility.
- Updated Core role/access/administrator/profile/import surfaces to render configured hierarchy terminology while preserving stable role, variable, import, and storage keys.
- Added neutral canonical role-level API while retaining the historical role-level API for existing modules.
- Restored the 4.6.38 technical installer unchanged; Mega Setup Wizard work is intentionally deferred to the next phase.
# DivisionDesk Core 4.6.38 — Licensing Enrollment, Cubicle & Attribution
- Added explicit licensing enrollment without changing upgrade behavior: existing installed sites remain `legacy_unenforced` until an administrator deliberately enrolls them.
- New installations now require DivisionDesk Server license/domain preflight in both browser and CLI installers before Core is downloaded/extracted, then cryptographic installation enrollment before the site database is created or `installed.lock` is written.
- Purchased module entitlements issued with a new license are handed to the existing RepositoryClient/Cubicle package installer after base Core setup, preserving the same dependency, signature, download-authorization, migration, and lifecycle path.
- Added persistent installation identity, Server-signed locally verifiable authorization certificates, runtime-domain validation, certificate refresh/transfer support, and neutral administrator recovery for enforced licensing failures.
- Added entitlement enforcement at Core/module/theme/widget-pack package boundaries while preserving package data; expired themes fall back to Core Basic and enrolled Core requires an active Core entitlement.
- Rebranded the software package Store experience as **Cubicle** while preserving `/store.php` route compatibility; enrolled clients use Server-authoritative visibility/entitlement state and protected download authorization.
- Added permission-controlled **Report a Problem** using the existing signed Server client-auth contract and diagnostic context.
- Changed Analytics Traffic Channels to preserve recognizable acquisition sources individually (Google, Bing, DuckDuckGo, Facebook, X, Instagram, Reddit, TikTok, paid search, Email, etc.) instead of collapsing search/social/email into broad buckets.
- Added licensing/certificate, legacy-safety, Cubicle-visibility, and Analytics attribution regression coverage.
# DivisionDesk Core 4.6.37 — Functional Navigation, Attribution & Import Center
- Reorganized Administration navigation by function: Settings pages from Core and installed modules collect under Settings, while reporting/analytics pages collect under Reports; operational module pages keep their declared Website/Organization/Modules destinations.
- Added explicit `nav_kind` support (`settings`, `reports`, `normal`, or `auto`) to the shared admin registry/module menu contract so packages can override conservative functional inference without changing routes or permissions.
- Expanded Analytics acquisition attribution with broad Traffic Channels (Campaign, Direct, Internal, Organic Search, Social, Referral, Other) while retaining granular Sources, referrers, and UTM fields.
- Expanded search/social referrer recognition and paid-click attribution for Google/Microsoft/TikTok/LinkedIn campaign identifiers without changing the Analytics schema.
- Added the shared Core Import Center for CSV/TSV staging, preview, field mapping, capability/CSRF enforcement, and package-extensible import targets via `Registry::importer()`.
- Added a built-in SCV Camp import target that writes to the existing SCV Operations `scv_camps` directory when present; Core does not create a competing Camp data store.
- Updated System Health telemetry testing to emit an explicit `TelemetrySelfTest` record/message so intentional probes are distinguishable from production errors while still exercising local, database, and Server delivery.
- Preserved the Server 1.22.9 telemetry contract; no Server-side change is required by this Core release.
# DivisionDesk Core 4.6.36 — Admin Navigation Grouping
- Refined the existing Administration mega-menu grouping without changing routes, permissions, screens, or admin functionality.
- Module admin entries now respect the functional destination explicitly declared by the module (`Website`, `Organization`, `Modules`, or `Reports`) instead of every module entry being forced into the Modules dropdown.
- Publishing/content integrations can therefore live with Website content, while operational modules such as Communications, Documents, Events, Membership, Finance, and SCV workflows can remain grouped under Organization when their package declares that destination.
- Reserved the Modules dropdown for package/module management and module pages that intentionally declare `Modules`; Core Store, Installed Modules, and Package Security now live together under its Packages section.
- Simplified the More dropdown into four coherent sections: Access & Accounts, Configuration, System & Maintenance, and Help & Diagnostics.
- Preserved the existing five top-level navigation destinations, Admin Modes, capability filtering, mega-menu behavior, search, alerts, and profile menu.
# DivisionDesk Core 4.6.35 — Builder/Public Responsive Parity
- Fixed breakpoint preview reflow so Desktop/Tablet/Mobile switching recalculates page-relative positioned blocks after the device frame finishes resizing; no element click is required to correct the preview.
- Added ResizeObserver/transition reflow hooks so asynchronously loaded widget previews and frame-size changes cannot leave stale geometry on the Builder canvas.
- Versioned the public renderer stylesheet to prevent stale cached CSS from making published widget Cards/List/Grid layouts differ from the Builder preview after Core upgrades.
- Hardened canonical widget card selectors for common widget wrapper/card class patterns and single-column mobile rendering.
- Reworked public page visual-boundary measurement to track both normal-flow section bottoms and actual absolute-positioned element bottoms, including late image/content size changes, so the footer remains below all page content.
- Added runtime resize/mutation/image-load remeasurement for page-positioned content while avoiding cumulative min-height growth.
# DivisionDesk Core 4.6.34 — Responsive Layout Engine & Builder Structure
- Added `Auto (recommended)` responsive behavior for Builder blocks. Desktop free positioning remains visually free; inherited free-position blocks return to safe document flow on Tablet/Mobile unless that breakpoint has an explicit layout override.
- Added responsive layout warnings on Tablet/Mobile for horizontal overflow and meaningful element overlap; the warning can select the first affected element.
- Preserved explicit Scale/Fixed behavior and per-breakpoint overrides for advanced designs.
- Made the selected-element contextual popover draggable via its grip so it can be moved away from obscured content.
- Added native Builder structure blocks for DIV, SPAN, UL, and OL with sanitized inline editing and public semantic rendering.
- Added canonical Core widget presentation wrappers for Cards, List, Grid, and Inline layouts, including responsive card grids and shared visual treatment.
- Directory-style widget presentation now reduces role-directory person names to First + Last while leaving underlying formal/member data unchanged.
- Retained Layers drag ordering, Lock/Unlock, z-order controls, floating shared Core WYSIWYG, page/footer containment, site styles, accessibility, widgets, templates, and legacy layout compatibility.
# DivisionDesk Core 4.6.33 — Floating WYSIWYG Toolbar
- Fixed the Visual Builder canonical Core WYSIWYG toolbar so it is truly out-of-flow and no longer consumes the left/sidebar or canvas layout space.
- Builder now requests the shared `App\Core\Editor::toolbar()` with a Builder-only CSS class and initial hidden state; the toolbar markup remains centralized in Core.
- The toolbar appears only while editing inline rich text, floats adjacent to the active editable element, and automatically moves below the selection when there is not enough room above it.
- The floating toolbar remains draggable; a manually dragged toolbar keeps the user-selected position for the current Builder session.
- Added safe optional `class` and `hidden` toolbar rendering options to the canonical Core Editor API without duplicating editor controls.
# DivisionDesk Core 4.6.32 — Responsive Canvas & Working Layers
- Reworked Builder free-position geometry after reviewing current Wix Studio, Webflow, Framer, and CSS responsive-layout guidance.
- New palette/asset drag drops are free-positioned at the drop point and use page-relative placement.
- New free-position elements store horizontal X and width proportionally (`%`) by default while retaining pixel vertical placement; existing 4.6.31 layouts without unit metadata remain pixel-compatible.
- Added explicit unit selectors for responsive geometry (`px`, `%`, `rem`, `em`, `vw`, `vh`) with per-breakpoint inheritance.
- Added a visible Flow/Free positioning state to each selected block toolbar.
- Rebuilt Layers rows with a visible drag grip, z-order, Lock/Unlock control, and an actions menu for Bring to Front, Bring Forward, Send Backward, and Send to Back.
- Layer drag/drop now updates stacking order consistently; the top layer is the front-most positioned object.
- Locked layers cannot be canvas-dragged, resized, or reordered until unlocked.
- Preserved page visual-boundary/footer containment for page-positioned content.
- Preserved Core shared WYSIWYG, theme/style inheritance, accessibility runtime, templates, widgets, and legacy Builder layout compatibility.
# DivisionDesk Core 4.6.31 — Builder Layering & Page Precision
- Added page-relative exact positioning as the default precision scope while retaining container-relative compatibility.
- Added real layer stacking controls: drag reorder, Bring Forward, Send Backward, displayed stack order, and per-layer Lock/Unlock.
- Locked elements cannot be accidentally dragged from the canvas or Layers panel.
- Public pages now measure page-positioned content and extend the page boundary so the footer remains below the lowest visual content.
- Builder canvas likewise expands to contain low-positioned exact content while preserving intentional blank space.
- Retained responsive breakpoint inheritance, shared Core WYSIWYG, themes/prebuilt styles, and accessibility behavior.
# DivisionDesk Core 4.6.31 — Builder Precision UX
- Exact placement is now immediately enabled from the block crosshair control; X/Y/Z controls appear first in Design and the selected element can be dragged directly.
- Exact-positioned elements support 1px arrow-key nudging and Shift+arrow/drag 10px steps.
- The contextual Design/Content inspector can be dragged anywhere and stays where the editor places it.
- The canonical shared WYSIWYG toolbar remains the same Core toolbar, but its Builder instance is now a movable floating surface.
- Existing responsive breakpoint inheritance, themes/site styles, structured layouts, and accessibility behavior are preserved.
# DivisionDesk Core 4.6.31
## Builder Studio — professional visual design foundation
- Rebuilt the Visual Builder workspace around first-class Add, Assets, Layers, Pages, Site Styles, and Components tools while preserving the existing structured page JSON, Page Layouts, reusable sections, complete Site Templates, shared Core WYSIWYG, module widgets/components, revisions, and trusted Code mode.
- Added breakpoint-aware design overrides for Desktop, Tablet, and Mobile. Tablet inherits Desktop until overridden; Mobile inherits Tablet/Desktop until overridden.
- Added precision positioning for Builder blocks with breakpoint-specific absolute X/Y coordinates, z-index, width, min-height, direct canvas dragging, direct resize handles, and Shift-assisted 10px snapping. Exact positioning can be returned to normal flow on any smaller breakpoint.
- Added responsive design controls for width, max-width, min-height, margin, padding, font size, background, text color, corner radius, shadow, section gap, section background image, and section padding.
- Public rendering now safely emits only allow-listed responsive design CSS values and preserves legacy visual-positioning behavior for existing pages.
## Assets / Media
- Promoted Core Media into a first-class Builder Assets workspace with search, Images/Video/Audio/Files filters, thumbnails, and drag-to-canvas behavior.
- Dragging an image creates an Image block, video creates a Video block, audio creates an Audio block, and a document creates a linked download/action button.
- Added hosted audio rendering and expanded Core Media uploads to common web video/audio and PowerPoint formats while retaining the existing upload size/security boundary.
## Site Styles and theme compatibility
- Added optional global Site Styles for brand colors, typography, content widths, and component radii. Blank values continue to inherit the active prebuilt theme; Site Styles are opt-in and do not replace theme packages.
- Existing theme styling remains authoritative unless an administrator explicitly sets a Site Style or per-element override.
## Accessibility
- Preserved the existing Core public Accessibility control unchanged.
- Added a Builder accessibility audit for missing image alt text, heading-order jumps, empty button text, and likely mobile overflow caused by exact positioning.
- Builder accessibility checks are advisory design-time safeguards; Core semantic rendering and public accessibility behavior remain the runtime contract.
## Builder usability
- Upgraded Layers into a selectable section/column/block tree.
- Added an in-Builder Pages navigator and richer reusable Components pane.
- Replaced text-heavy Builder chrome with compact icon-first actions where the action is recognizable, retaining labels/tooltips where needed for accessibility and clarity.
- Added Builder asset cache-busting for the 4.6.31 interface.
# DivisionDesk Core 4.6.27
- Centralized the canonical WYSIWYG toolbar in `App\Core\Editor::toolbar()`.
- Visual Builder now renders that shared Core toolbar instead of maintaining duplicate toolbar markup.
- Package editors using `App\Core\Editor::render()` therefore use the exact same Core toolbar source and inherit future Core editor changes sitewide.
# DivisionDesk Core 4.6.26
- Expands the existing Communications Analytics view; no parallel analytics store is introduced.
- Preserves `communications.email.opened` / `.clicked` as first-per-delivery unique signals so the existing Email Open Rate retains its meaning.
- Adds observed-open and observed-click reporting for repeat tracked requests, with campaign and recipient drill-down when Communications exposes its read-only reporting bridge.
- Adds hover/tap tooltips to Website Traffic charts showing date, Visits, Unique Visitors, and Page Views without changing traffic collection or counting.
- Retains all 4.6.25 security/data-integrity behavior unchanged.
# DivisionDesk Core 4.6.25
- Finalizes the Core 4.6 security/data-integrity release gate without changing the verified 4.6.24 runtime repair design.
- Retires stale regression assertions that contradicted the authoritative Membership Manager role-assignment architecture or hard-coded historical Core versions.
- Converts the superseded 4.6.22 destructive-repair regression into a guard that proves the unsafe repair path cannot return.
- Keeps the update-only atomic security-table rebuild, pre/post verification and rollback, update mutex, emergency OOM telemetry reserve, SQL-bounded Access Control reads, and Administrator compatibility grants.
# DivisionDesk Core 4.6.24
- Fixes legacy MySQL security repair when `roles.role_key` / `permissions.permission_key` are TEXT by normalizing staging columns to VARCHAR(190) before UNIQUE indexes are created. Live tables remain untouched until verified atomic swap.
- Supersedes the invalid 4.6.22 security repair path. Security-table repair is no longer executed from normal page bootstrap.
- Replaces multi-million-row duplicate DELETEs with a canonical-table rebuild and one atomic MySQL table swap, preserving the oldest logical role/permission IDs and effective role-permission relationships.
- Retains the old security tables until the replacement set passes verification and atomically restores the old set if post-swap verification fails.
- Adds a non-blocking Core update mutex so a manual update cannot race a concurrently running automatic update.
- Forces SecuritySeeder v4 and grants `*` to both historical Administrator role keys (`admin` and `organization_administrator`).
- Clears accumulated security-schema repair notices after a successful repair.
## 4.6.22 — 2026-09-06
- Replaces the silent legacy role/permission cleanup with a bounded MySQL security-schema repair that can safely remove millions of duplicate rows while preserving canonical role-permission relationships.
- Verifies and enforces UNIQUE keys for `roles.role_key`, `permissions.permission_key`, and `role_permissions(role_id,permission_id)` before marking the repair complete.
- Failed security-schema repair is now recorded through DivisionDesk error telemetry instead of being silently ignored.
- Legacy Core `admin` accounts now receive full `*` Administrator capability so the two historical Administrator role keys cannot produce contradictory access behavior; `organization_administrator` remains the Membership Manager mapping.
- Access Control labels the historical `admin` role as `Administrator (Core account)` and the roster-backed role as `Administrator (Organization)` to remove UI ambiguity.
## 4.6.21 — 2026-09-06
- Repairs legacy MySQL `roles`/`permissions` duplication while preserving canonical `role_permissions` relationships.
- Enforces UNIQUE keys on `role_key`, `permission_key`, and role/permission pairs.
- Makes Core capability/security seeding defensive even before schema repair.
- Access Control now groups permissions in SQL instead of loading an unbounded duplicate table into PHP memory.
- Keeps 4.6.20 local/Server telemetry diagnostics and reserves emergency memory so out-of-memory fatals can still be reported to DivisionDesk Server.
# Core 4.6.19
## 4.6.20 — Error telemetry hardening and access-control diagnostics
- Registers Core error handling immediately after the autoloader so configuration/session/bootstrap failures are captured instead of escaping before logging is active.
- Error logging destinations are now independent: local file logging, local `error_events` persistence, and DivisionDesk Server telemetry each run even if another destination fails.
- Technical 500 pages now show a unique error reference and truthfully state whether the report was saved locally and/or delivered to DivisionDesk Server.
- `ErrorReporter` now validates the actual HTTP status/JSON result instead of treating any response body (including HTTP errors) as successful telemetry.
- System Health now reports local error-log writability and the most recent telemetry-delivery result, plus a protected end-to-end telemetry self-test.
- Roles & Permissions now normalizes legacy/current role and permission display columns from `SELECT *`, catches/report its own data/render failures, and remains usable without assuming optional schema columns.
- Fixes RoleManager session refresh runtime bug (`array_map()` called with one argument) that could cause `access-control.php` and other permission-aware requests to return HTTP 500.
- Keeps administrator/account permissions additive with Membership Manager organizational roles.
- Adds regression coverage for RoleManager refresh syntax/runtime contract.
# Core 4.6.18
- Fixes the administrator/member-role permission bridge introduced during role-authority consolidation: administrator-account permissions and linked Membership Manager organizational roles are now additive rather than one overwriting the other.
- Refreshes effective roles after installed add-ons boot on each normal request, allowing newly assigned Administrator (`*`) access to take effect without depending on a stale session.
- Keeps any residual legacy Core member-role rows effective until Membership Manager has actually migrated them, so a failed/unmappable migration cannot silently remove access.
- Allows an installed role provider to link an administrator account to exactly one active roster member by email; ambiguous duplicate emails are not auto-linked.
- Hardens the Roles & Permissions page against older role-table schemas and fixes a defensive security-seeder grant edge case.
# Core 4.6.17
- Consolidates member-role assignment authority with Membership Manager 1.3.12+: when the roster provider advertises authoritative assignments, Core no longer merges legacy `member_role_assignments` rows into effective member permissions.
- Access → Member Roles becomes an informational handoff to Membership Manager instead of maintaining a competing assignment store once the authoritative roster provider is active.
- Keeps the legacy Core member-role path intact for installations without Membership Manager and during staged upgrades from older roster providers.
- Retains Core 4.6.16 access-page scaling/duplicate-display repairs and all 4.6.15 Analytics/timezone behavior.
# Core 4.6.16
- Repairs Access → Roles & Permissions so large or historically duplicated role catalogs no longer produce an oversized/failed page; only one selected role permission set is rendered at a time.
- Member Roles defensively collapses exact duplicate legacy role display rows while preserving existing assignments as recognized aliases.
- Adds `organization_administrator` as the full-control organizational Administrator access role using the existing `*` capability.
- Permission saves validate selected permission IDs, use duplicate-safe inserts, and consolidate duplicate legacy rows for the selected role key without changing unrelated roles.
- Retains all 4.6.15 Analytics/timezone and scheduler behavior unchanged.
# Core 4.6.15
- Analytics reporting dates now use the configured site timezone while UTC remains the canonical storage format.
- Custom ranges, Today/7 days/30 days/month/year presets, overview cards, communications metrics, sources, devices, referrers, landing pages, bot summaries, module metrics, and journey ranges all query the correct UTC boundaries for the selected local dates.
- Traffic-over-time day buckets are now grouped in site-local dates, fixing evening activity appearing on the following UTC day.
- Real-Time and journey timestamps are converted back to site-local time for display.
- Analytics date inputs retain native browser date controls and now open the native date picker from the date field where supported; the active site timezone is displayed beside the range controls.
- Acquisition/source classification is intentionally unchanged in this release.
- Retains the 4.6.14 durable job-queue scheduler fix unchanged.
# Core 4.6.14
- Background job queue reliability: every scheduler invocation now drains due persistent `core_jobs` work even when the normal 60-second scheduler interval was stamped moments earlier. This prevents queued Communications bulk-delivery jobs from being skipped while the CLI reports `nothing due`.
- The interval gate remains unchanged for ordinary recurring jobs; only the durable queue receives the due-work override.
- Add-ons are still booted before CLI tick, so package job handlers are registered before queued work is dispatched.
# Core 4.6.13
- Events Registration 2.1 authoritative pricing: new registrations no longer require attendee types.
- Supports event-level base registration fee and optional per-additional-guest registration fee.
- Quantity-choice add-ons permit blank per-item choices; Events UI is responsible for warning before submit.
- Historical attendee-type registrations remain readable.
## 4.6.11
- Events registration now validates/stores full primary-attendee address/contact data and member/camp details.
- Adds server-authoritative Guest Names, Quantity, and Quantity + Per-item Choice option semantics.
- Reducing a quantity discards values beyond the submitted quantity; stale hidden choices cannot affect totals.
- Numeric quantity options charge per unit and zero means no selection.
- Legacy duplicate `Registration Fee` options are ignored when the attendee type already has a base price.
- Retains 4.6.10 Events/Finance checkout and QR fixes.
## 4.6.10
- Corrects `config/version.php`, the canonical runtime version marker used by Core update verification.
- 4.6.9 accidentally left that file reporting 4.6.8, causing an otherwise-copied update to fail verification and roll back.
- Retains all 4.6.9 Events/Finance registration, pay-now/pay-later, QR/check-in and base-path URL fixes.
## 4.6.9
- Repairs Events payment handoff to current Finance.
- Adds pay-now/pay-later registration behavior without duplicating registrations.
- Fixes doubled base paths in Events confirmation/check-in links.
- Pending-balance registrations receive QR credentials and remain check-in eligible.
- Retains 4.6.8 polling/session-lock fixes.
# DivisionDesk Core Changelog
## 4.6.8
- Prevented overlapping/duplicate admin badge and alert pollers from accumulating slow requests.
- Added global poller guards, single-flight scheduling, and 8-second request timeouts.
- Added a read-and-close session bootstrap mode for read-only async endpoints so they do not hold the PHP session lock.
- `admin-alerts.php` now uses the read-and-close session mode while retaining full add-on registration.
## 4.6.7
- Carries forward the Core 4.6.6 transactional-email handoff and secure one-click member sign-in changes.
- Regenerated `release/core-files.json` against the exact 4.6.7 package contents so Server-side Core file verification matches the published version.
## 4.6.6
- Added `core:mail.transactional` event contract so Communications can own tracked transactional delivery when installed, with Core Mailer fallback.
- Member sign-in code emails now include a secure signed one-click link plus the six-digit manual fallback.
- One-click sign-in only succeeds in the browser session that initiated login, preventing mail-security scanners from consuming the login.
# DivisionDesk Core 4.6.5
## Performance and public-renderer quality
- Versioned Core static assets now receive long-lived immutable browser caching.
- Small active theme CSS is inlined; larger theme CSS is versioned with ETag/Last-Modified caching.
- Analytics browser confirmation is deferred until load/idle and sent once per analytics session/tab.
- Lightweight Analytics requests open PHP sessions read-only and release the session lock immediately.
- Shared Core scripts are versioned and deferred.
- Public pages now include a language attribute, a single main landmark, and a fallback meta description.
- Retains all Core 4.6.4 performance, 4.6.3 migration verification, and earlier stabilization fixes.
# DivisionDesk Core 4.6.4
## Performance stabilization
- Core security role/permission seeding is now version-gated instead of executing hundreds of SQL statements on every request.
- Public navigation registry synchronization is signature-cached and only re-runs when registered destinations or navigation edits change.
- Chat schema/default seeding no longer probes chat tables on every request once its schema version is current.
- Analytics browser-confirmation and heartbeat requests use a lightweight bootstrap and no longer initialize the full package/widget/application runtime.
- Retains all 4.6.3 cross-engine migration verification, 4.6.2 Analytics/chat/migration snapshot, and 4.6.1 release-stabilization fixes.
- Fixed SQLite → MySQL/MariaDB migration verification for tables with textual primary keys such as `site_settings`. Verification no longer depends on each engine's default collation/order.
- Text keys are now ordered bytewise (`COLLATE BINARY` on SQLite and `BINARY` on MySQL/MariaDB) before streaming fingerprints are compared.
- Tables without a primary key now receive deterministic all-column verification ordering instead of relying on physical/insertion order.
- Added canonical scalar comparison for integer, floating-point and decimal values so PDO/database type representation differences do not create false verification failures.
- Verification failures now identify row/key and column when possible while reporting only length/hash summaries for differing values, preventing sensitive setting contents from being exposed.
- Added Core 4.6.3 regression coverage for cross-engine ordering, canonicalization and safe diagnostics.
# DivisionDesk Core 4.6.2
- Database migration now freezes Analytics writes before refreshing the source snapshot row counts, preventing `analytics_events` from changing between preflight/copy/verification.
- Migration UI consumes the frozen snapshot counts returned after rollback protection is active.
- Non-empty destination databases now prompt for explicit destructive confirmation and can be emptied automatically before preflight.
- `communications-chat.php` is a hard page-view exclusion. Its requests may update session liveness only and never increment page views or engaged time.
- Historical Communications Chat page-view pollution is excluded from Overview, traffic series and Top Pages reporting.
- Analytics Top Pages now resolves human-readable page titles and links titles to the page in a new tab.
- Added Core 4.6.2 focused regression coverage for migration consistency, destination-empty UX, chat liveness/page-view exclusion and Top Pages presentation.
# DivisionDesk Core 4.6.1
- Fixed post-login Administration rendering where authentication forms could be intercepted by the generic fetch layer, causing the redirected admin page to load as fetch content instead of a full document and delaying `core.css` until refresh.
- Admin and member authentication/verification forms now use native browser document navigation; the fetch helper also excludes authentication endpoints defensively and promotes redirected non-JSON POST fetch responses to real top-level navigation so the authenticated shell/head assets always reload.
- Fixed member login completion redirecting to domain `/` instead of the configured DivisionDesk installation root on subdirectory installs. Safe member return paths are normalized through `Url::basePath()` / `Url::redirect()`.
- Added Administration **Member Roles** management with multi-role checkboxes and built-in Camp, Brigade and Division officer/access roles. Camp/Brigade/Division scope is inferred from the member hierarchy instead of requiring a duplicate scope selection.
- Core-managed member role assignments are now additive with roles supplied by Membership Manager/Rosters rather than being ignored when a roster role provider is active; Core roles can also be assigned locally before/without a roster provider.
- Added built-in roles for Camp Commander, Camp Adjutant, Camp Treasurer, Camp Webmaster, Brigade Commander, Lt. Brigade Commander, Division Commander, Division Adjutant, Lt. Division Commander, 2nd Lt. Division Commander, Division Webmaster, Division Treasurer, Division Communications Chairman, Division Events Manager, and Division Page Editor.
- Fixed Analytics page-view inflation: XHR/fetch/prefetch requests are excluded from document-view collection, and same-page document refreshes/tab-state reloads no longer increment logical page views within the same session.
- Expanded the Analytics Overview to more closely match the approved mockup, including the six-card KPI row, traffic-source donut, top pages, email/social/member engagement panels, top referrals, device breakdown and real-time overview.
- Added returning-member, email-bounce and unsubscribe summary signals to Analytics reporting.
- Fixed SQLite → MySQL/MariaDB migration error 1075 caused by treating every integer component of a composite SQLite primary key as `AUTO_INCREMENT`. Only a single integer primary key can now translate as auto-incrementing.
- Fixed failed database-transfer cleanup so a prepare-stage failure drops any partially-created destination tables; users can retry against the same empty destination after **Cancel Move & Clean Up**.
- Fixed SQLite partial UNIQUE index translation so a partial uniqueness rule is not broadened into an unconditional MySQL UNIQUE constraint during migration.
- Added Core 4.6.1 release-blocking regressions for authentication navigation, base-path redirects, Analytics logical-page counting, database schema translation/cleanup, multi-role management and the retained Storefront namespace parser fix.
# DivisionDesk Core 4.6.0
- Added full-page **Visual / Code** Page Builder mode for the complete editable page body.
- Added canonical DivisionDesk page-source markers so dynamic module/widget content remains dynamic in Code mode.
- Added trusted HTML/CSS/JavaScript/PHP page-source preservation; executable JavaScript/PHP requires the new `pages.code` capability.
- Trusted PHP is executed through a generated server-side page-code cache include rather than direct `eval()`, with runtime error isolation/logging.
- Added permission-driven authenticated principals: authenticated members can use Administration features when their roles grant the required capability, without a duplicate administrator password account.
- Added `AdminAuth::principal()` and `AdminAuth::requireAdminAccount()` while retaining capability checks through `RoleManager`.
- Added canonical reusable `Editor::render()` WYSIWYG entry point so modules such as Publishing can consume the Core editor without recreating Site Builder toolbar markup.
- Added Analytics 2.0 traffic quality: `human`, `likely_human`, `unknown`, `likely_bot`, and `bot`, with confidence scores and classification reasons.
- Added known crawler identification plus JavaScript browser confirmation and engagement evidence; lack of JavaScript alone is never treated as proof of a bot.
- Added human/bot/unknown/all traffic filters, previous-period comparisons, referrer/landing-page reports, bot summaries, cross-module activity, session journeys, and expanded Real-Time reporting.
- Expanded Analytics Center into Overview, Website, Communications, Social, Members, Organizations, Events, Finance, Content, and Real-Time views with styling aligned more closely to the approved dark Analytics mockup.
- Added `analytics.view` capability and updated Core 4.6 API/endpoint documentation.
# DivisionDesk Core 4.5.4
- Fixed Page Builder HTTP 500 / `Unexpected token '<'` failures when an installed package registers an editor profile before Core editor defaults are initialized.
- `EditorRegistry::boot()` now ensures each required Core profile (`page`, `publishing`, and `email`) exists individually instead of treating any pre-registered package profile as proof that Core boot completed.
- Unknown editor profiles now safely fall back to the guaranteed Core `page` profile without reading an undefined array key.
- Retains the 4.5.3 notification dismiss/Clear all controls and Builder script-safe serialization, plus the 4.5.2 SQLite concurrency and Analytics corrections.
# DivisionDesk Core 4.5.3
- Fixed Page Builder startup failures (`Unexpected token '<'`) when page, widget, or registered component data contains HTML capable of terminating an inline `<script>` block.
- Builder bootstrap JSON now uses script-safe hexadecimal escaping and substitutes invalid UTF-8 instead of emitting malformed startup JavaScript.
- Added an explicit dismiss control to every Administration notification.
- Added **Clear all** to mark all currently unread/dismissible notifications as read without opening each destination.
- Notification actions refresh the bell/count immediately after dismissal.
# DivisionDesk Core 4.5.2
- Fixed SQLite `database is locked` regressions exposed by Core Analytics under overlapping PHP requests.
- Added a 5-second SQLite busy timeout and WAL/NORMAL concurrency tuning with compatibility fallback.
- Deferred automatic public page-view persistence until request shutdown so payments, forms, navigation, and module business logic take priority over telemetry.
- Fixed Analytics IP-hash salt persistence: 4.5.0 stored the salt as non-autoload while reading through the autoload cache, causing an unnecessary `site_settings` write on every tracked request.
- Public navigation registry sync now updates menu rows only when parent, label, or order actually changed rather than issuing writes on every public page request.
- Analytics collection failures now use a file-only analytics log path so a telemetry lock cannot recursively create another database write through the Core error-event logger.
# DivisionDesk Core 4.5.0
- Added Core Unified Analytics 1.0 with durable first-party session/event storage.
- Added pseudonymous guest visitor/session tracking and authenticated member journeys.
- Added referral classification and UTM campaign attribution.
- Added measured cumulative session engagement heartbeats and real-time active-session reporting.
- Added the Analytics Center dashboard and authenticated reporting API.
- Added `Integration::analytics()` as the stable package-facing analytics SDK method.
- Added automatic EventBus signal capture with recursion protection and confidence metadata.
- Added Core mail send/failure analytics signals without storing message bodies or recipient addresses in analytics properties.
- Added Core 4.5.0 endpoint/API contracts and release QA documentation.
- Updated embedded Developer Platform integration documentation for Analytics.
# Changelog
## 4.4.6 — 2026-08-30
- Corrected `config/version.php` to 4.4.6; the Core updater verifies this file after copying the update.
- Carries forward the verified `Addons::declaredAddonClass()` namespace parser correction.
- Fixes valid addon namespaces ending in letters such as `n`, `r`, or `t` being truncated.
- `Addons\Storefront` now resolves correctly instead of being read as `Addons\Storefro`.
- Supersedes the previously published bad 4.4.5 artifact.
## 4.4.5 — 2026-08-30
- Fixed `App\Core\Addons::declaredAddonClass()` namespace parsing.
- The previous `trim()` mask could strip valid trailing namespace letters such as `n`, `r`, and `t`.
- `Addons\Storefront` is now preserved correctly instead of being misread as `Addons\Storefro`.
- No Storefront package workaround is required after this Core patch.
# DivisionDesk Core 4.4.4
- Added optional parent relationships for module-page navigation destinations.
- Navigation registry synchronization now creates destinations first, then resolves parent/child links, including already-installed auto-added destinations.
- Enables modules to expose cohesive public dropdown navigation while continuing to render through the active site theme/header/footer.
- Added safe MemberAuth methods for listing and revoking remembered member devices.
- No breaking Core API or database contract change.
# DivisionDesk Core 4.4.3
- Fixed member OTP completion failure when a roster provider omits `display_name`.
- Valid OTP codes are no longer consumed until member login completion succeeds.
- Preserved safe member return targets so `my-membership.php` authentication returns to the requested page.
- Versioned Core asset URLs so CSS/JS changes are not hidden by stale browser caches after upgrade.
- Organization navigation categories now render in one vertical collapsed stack instead of a two-column grid/horizontal-scroll layout.
- Retains the 4.4.2 UTC OTP expiration, immediate delivery, resend/cooldown, and editable email-template improvements.
# DivisionDesk Core 4.4.2
- Fixed member OTP expiration to use consistent UTC timestamps across PHP and SQLite/MySQL verification.
- Added reliable resend-code flow with cooldown and specific expired/incorrect/locked feedback.
- Member verification mail is sent synchronously through the configured transport and a failed send removes the unusable code.
- Added editable professional HTML/plain-text member sign-in templates under `templates/email/`.
- Redesigned Member Login, Verify Login, and My Account using shared Core admin UI styling.
- My Account now has distinct Profile, Password & Security, and Remembered Devices sections with responsive layouts.
- Organization navigation with more than three categories now collapses categories into expandable sections instead of presenting a long persistent scroll list.
- Preserves all Core 4.4.1 platform, Store, Builder, Chatroom, scheduler, setup-wizard, search, API/SDK, and package-security behavior.
# DivisionDesk Core 4.4.1
- Fixed a package-scheduler defect exposed by Social Media: `bin/scheduler.php` now boots installed modules and Widget Packs before `Scheduler::tick()`.
- Package recurring jobs, registered Smart Actions and job handlers are therefore available during the real CLI cron process.
- No Page Builder, Chatroom, Store, accessibility, setup-wizard, or other 4.4.0 feature was removed.
# DivisionDesk Core 4.4.0
## Chatrooms & Meeting Mode
- Added the first-party Core Chatroom service and Page Builder widget with multiple switchable rooms.
- Rooms support Public, Members Only, or Private access with explicit room members, moderators and room administrators.
- Added near-instant incremental conversation updates without full-page refresh or blinking.
- Added online presence, live Meeting Mode attendance, attendance corrections and meeting start/end records.
- Added smart inline detection for motions, seconds, vote requests/results, officer/committee reports and adjournment.
- Detected meeting actions render as contextual hyperlinks inside the conversation (for example, **Second this motion**) rather than a separate bank of parliamentary buttons.
- Added structured voting with per-attendee Aye/Nay/Abstain responses and deterministic vote closure/results.
- Added optional raw transcript and Smart Minutes generation including date/time, chair/start record, attendance, reports, motions, seconds, vote results and adjournment.
- Added Smart Answers for approved common questions, native/custom/animated emoji support, safe hyperlinks, SSRF-protected URL previews and image thumbnails.
- Added responsive desktop/tablet/mobile Chatroom UI matching the approved DivisionDesk Meeting Mode design target.
## Core release blockers corrected
- Package downloads now always carry the installed Core version and client key on every DivisionDesk Server download path, including fallback/cached catalog URLs; the same identity is also carried in request headers.
- Public newsletter signup no longer invokes an administrator-only Smart Action. Core stores the subscriber reliably and emits `newsletter.subscribed` for integrations.
- Newsletter storage now repairs older table shapes missing status/source/timestamp columns.
- Page Builder charts now honor the Show Labels setting visually and contain wide bar charts inside a responsive internal scroller instead of overflowing the page/container.
- Store lifecycle continues to show Uninstall alongside Update for installed modules/widgets/widget packs and inactive themes.
## Compatibility
- Built directly on the current Core 4.3.9 production tree. Existing Admin Search, setup wizard framework, scheduler, AJAX/fetch framework, accessibility controls, Builder/editor, Developer Platform, package trust and Store lifecycle contracts are retained.
# DivisionDesk Core 4.3.9
- Built directly from the complete 4.3.8 corrective tree, which itself is based on the uploaded 4.3.6 production Core.
- Package download errors now preserve useful plain-text Server response bodies as well as JSON errors, so HTTP 409 reports its actual cause.
- Retains the Store fallback trust/grant preservation and stale-cache invalidation introduced in 4.3.8.
- No module/theme/widget/widget-pack lifecycle functionality removed.
# DivisionDesk Core 4.3.8
## Production staging corrective release
- Reworked `bin/doctor.php` into conservative PHP 8.1 syntax after the production Server staging gate rejected the unchanged 4.3.6-era doctor file under the hosting lint environment.
- Preserves all Core 4.3.7 Store trust/fallback corrections and the complete 4.3.6 runtime baseline.
- No existing 4.3.6 runtime file is removed.
# DivisionDesk Core 4.3.7
## Production Store trust corrective release
Built directly from the complete DivisionDesk Core 4.3.6 release.
- Fixed the legacy/fallback Store catalog path so it preserves DivisionDesk Server-authoritative `server_trust`, `security_review_state`, `official`, `granted_permissions`, and nested trust metadata.
- This prevents an Official DivisionDesk package from being silently downgraded to Community immediately before `PackageValidator`, which caused false `DD-PKG-020` failures for reviewed providers such as `graph.facebook.com`.
- Kept the existing 4.3.6 security model intact: the package ZIP cannot self-award Official trust; trust is derived only from remote Store/Server metadata.
- Added Widget Pack coverage to fallback Store package reconstruction so 4.3.6 Widget Pack lifecycle support is not lost on fallback.
- Store catalog cache schema bumped to 2 so stale pre-fix thin catalog records are ignored.
- Package-download errors now preserve the Server's JSON error detail for HTTP 4xx/5xx responses instead of reducing every failure to a status number.
- Installed `.security.json` records the Server security-review state used during validation for diagnostics.
- No existing 4.3.6 module/theme/widget/widget-pack lifecycle, reinstall, uninstall, usage-preservation, builder, setup, scheduler, or admin contracts were removed.
# DivisionDesk Core 4.3.6
- Fixes Store lifecycle controls so installed modules, non-active themes, standalone widgets, and published widget-container packages can be reinstalled or uninstalled from the Store.
- Reinstall forces a fresh verified download of the same Store version without purging module data; required dependencies remain validated/installed first.
- Widget uninstall preserves Page Builder JSON and reusable sections, warns/asks for confirmation when the package is in use, and allows clean reinstall later.
- Recognizes Platform 1.0 `type: widget` packages whose `widget.json` / `manifest.json` contains `widgets[]` as containers: Core exposes each qualified child widget individually and never creates a pack-level pseudo-widget.
- Adds child-widget package security context so one container security record protects every child renderer.
- Preserves both typed `WidgetContext` and legacy `array $context` renderer callbacks.
- Translates package download HTTP 401/403 into an actionable license/entitlement message instead of exposing the raw download URL/client key.
- Keeps Platform 1.0 package/Store contracts backward-compatible.
# DivisionDesk Core 4.3.5
- Fixes direct WYSIWYG editing so editable text no longer reopens the legacy Content Block inspector; selection is preserved across toolbar interaction and font, size, bold/italic/underline, colors, highlights, alignment, lists, links and inline images persist through save/render sanitization.
- Makes empty canvas and open column space valid drag/drop targets with insertion-aware placement instead of requiring a pre-existing empty column.
- Renames and surfaces the native accessible `Chart / Graph` block in the element palette.
- Adds Upload & Select directly to the Builder Media picker and normalizes legacy `/uploads/...` URLs for subdirectory installations.
- Guarantees Core Setup Wizard Back / Save & Continue / Skip / Finish navigation with AJAX busy state and validation feedback even when a module only supplies fields/render callbacks.
- Makes desktop admin mega menus JS-controlled and single-open so adjacent menus cannot overlap; Escape/click-away closes them.
- Makes module-provided admin destinations Advanced by default unless the module explicitly chooses another minimum mode; mode still never grants permissions.
- Prevents duplicate/legacy addon slug identities such as `socialmedia` and `social-media` from reaching PHP class redeclaration: Core preflights installed rows/classes and the installer refuses colliding identities.
- Adds Media Library avatar selection/upload from My Account.
- Extends Builder/UI regression coverage for all above defects.
# DivisionDesk Core 4.3.3
- Hardens the shared public router so optional theme/navigation/page/widget/footer failures are isolated and reported instead of taking down every public page.
- Adds defensive handling for malformed legacy navigation/page metadata and a permanent public-runtime regression suite.
- Preserves Developer Platform 1.0 contracts and all 4.3.x backward compatibility.
# DivisionDesk Core 4.3.2
- Reworks Builder interaction around direct in-canvas editing and Builder-safe real widget/module previews.
- Preserves legacy widget callback signatures through a reflected compatibility adapter.
- Adds Core float-left/right text wrapping, width controls, and responsive stacking.
- Moves Admin Mode switching to the profile/avatar menu and makes Novice/Advanced/Webmaster materially filter interface complexity without changing authorization.
- Anchors mega menus to their trigger and constrains them to the viewport.
- Rebuilds dashboard first-run scheduler state as setup/onboarding and reclassifies missing package-schema job failures as package setup/update conditions.
- Keeps scheduler web fallback opt-in rather than silently running jobs on public requests.
- Updates Developer Platform 1.0 exact contracts without breaking package APIs.
# DivisionDesk Core 4.3.1
- Rebuilt the Visual Page Builder shell to match the approved direct-editing design: compact dark header, Pages → current-page breadcrumb, one floating WYSIWYG toolbar, dark grouped/collapsible scrollable element library, contextual block popovers, responsive preview dock, autosave state, Publish action, and Page Settings modal with SEO/social-sharing preview.
- Preserved existing version-1 Builder layout JSON and existing module/widget/component registration contracts.
- Replaced nested Administration flyouts with viewport-safe mega menus under a reduced top-level navigation set: Dashboard, Website, Organization, Modules, Reports, More.
- Improved live Administration search so Feature/Action results and Help/Documentation results are visually separated; fuzzy, phonetic, alias and synonym matching remain permission-filtered. Ctrl/Cmd+K focuses live search.
- Added first-run Scheduler Setup workflow. A scheduler that has never been seen is now onboarding/setup, not a 10-minute health failure. Only a previously healthy scheduler that becomes late raises a runtime warning.
- Scheduler errors caused by a missing package table are isolated as package setup/update warnings instead of generic red fatal notices; successful subsequent runs clear their prior notice.
- Added `/scheduler-setup.php` CSRF-protected setup/test actions and documented the exact request/response contract.
- Updated Help, Core endpoint inventory, Core API contracts, Platform contract tests and UI regression tests.
# DivisionDesk Core 4.2.9
- Fixed shared installed-module boot lifecycle so packages are registered once per request.
- Removed the redundant unprotected second `Addons::bootInstalled()` call from the public site router.
- Made `Addons::bootInstalled()` idempotent across public/admin/Builder/Help/search routes.
- Added per-package register failure isolation: a broken package is reported and skipped instead of taking down the entire client site.
- Failed package registration is attempted only once per request and surfaced through an Administration notice/error report.
- Added regression coverage proving a healthy module registers once and a deliberately broken module cannot escape the package boot boundary.
# DivisionDesk Core Changelog
## 4.2.9 — 2026-08-18
- Fixed a site-wide 500 failure triggered after installing modules: `bootstrap.php` already booted packages, while the public router booted them a second time outside the protected boundary.
- Installed module boot is now idempotent; successfully registered modules are never registered twice in the same request.
- Package `register()` failures are isolated per package, logged through Core error reporting, and surfaced as an administrator notice instead of aborting the public request.
- A package that fails initialization is not repeatedly retried during the same request.
- Public routing no longer redundantly calls `Addons::bootInstalled()` after bootstrap.
- This hardening also protects Builder, Help, Administration Search, Integration Actions, and other routes that may invoke the boot service more than once.
- Regression test: healthy module registers once across two boot calls; intentionally broken module throws once, is isolated, and does not propagate a fatal error.
## 4.2.7 — 2026-08-18
### Fixed
- Store protocol trust normalization now honors the Server-authoritative `server_trust` field as well as supported legacy trust fields. Official packages no longer fall back to Community during quarantine validation merely because Server used the current trust field name.
- Store catalog retrieval now merges all successful modern Server catalog endpoints instead of stopping after the first successful endpoint. This prevents a module-only endpoint from hiding Themes, Widgets, Site Templates, or Page Layouts exposed by another current catalog source.
- Store catalog requests now send the persistent client key, Core version, channel, and `runtime=client` so DivisionDesk Server can apply licensing/entitlement/runtime visibility consistently.
- Modern catalog data remains authoritative for trust, licensing, runtime, and permission metadata; legacy repository data may supplement missing download/checksum fields but cannot overwrite richer Server security metadata.
- Removed an accidental nested Core working-tree copy from the release tree and added release-root sanity checks.
### Added
- `bin/store-probe.php`, a non-secret diagnostic probe that queries the live Server catalog endpoints and reports response keys, package-family counts, trust/runtime/licensing fields, and normalized trust independently of the Store UI.
### Development rule
- Cross-component protocol awareness is a hard DivisionDesk release rule: Core, Server, modules, themes, widgets, templates and related packages must be reviewed against the latest shared contracts before release.
# DivisionDesk Core 4.2.5
- Fixed Store AJAX endpoint resolution when a form contains an input named `action`; the literal form action attribute is now used so requests cannot become `/[object HTMLInputElement]`.
- Store catalog extraction now merges flat and grouped package-family records so Modules, Themes, Widgets, Site Templates/Complete Sites, and Page Layouts can coexist in one Server response.
- Fixed Page Builder/WYSIWYG assets on subdirectory installs by using the configured DivisionDesk base path instead of root-relative `/assets/...` URLs.
- Added the shared fetch helper to the Visual Builder so Save/Apply operations use the standard spinner/busy-state behavior.
- Corrected related root-relative asset/navigation links in Media, Page settings, Navigation, Revisions, Roles, member login/verification, and setup-complete screens.
- Rebuilt Administration navigation for smaller screens with an explicit Menu control, stacked/collapsible groups, bounded scrolling, full-width search, and non-overflowing nested menus.
- Added regression checks for named `action` controls, mixed Store catalog shapes, Builder asset base paths/WYSIWYG initialization contract, and responsive Administration navigation markup.
# DivisionDesk Core 4.2.4
## AJAX endpoint regression hotfix
- Fixed a shared fetch-layer DOM collision where forms containing an input named `action` shadowed the native `HTMLFormElement.action` property. This produced requests to `/public/[object HTMLInputElement]` and HTTP 403 responses.
- The shared Core AJAX layer now resolves the endpoint from the literal `action` attribute with `getAttribute('action')`, so named form controls cannot alter the request URL.
- Applied the same safe endpoint resolution to the browser installer and direct Legal Policies/Search form JavaScript paths.
## Store catalog completeness
- Store catalog extraction now merges flat `packages` arrays with grouped Modules, Themes, Widgets, Site Templates/Complete Sites, and Page Layout buckets from the same Server response.
- Mixed catalog response shapes are de-duplicated by canonical package type + slug instead of returning early after the flat modules list and silently dropping other families.
## Regression coverage
- Added an explicit `[object HTMLInputElement]` endpoint regression check.
- Added a mixed flat+grouped five-family catalog regression test.
# DivisionDesk Core 4.2.3
## Store stabilization
- Store mutations no longer self-post to `/public/store.php`; the Store page is GET-only and all install/update/download/apply actions target the dedicated JSON `/store-action.php` endpoint.
- Modern Server catalog responses are normalized from flat `packages` arrays or grouped package-family buckets. Modules, Themes, Widgets, Site Templates, and Page Layouts all share one canonical client contract.
- Package type aliases/fields such as `package_type`, `widget-pack`, `site_template`, `complete-site`, and `page_layout` are normalized before Store categorization.
- A successful modern catalog remains authoritative even when optional legacy repository sources fail, including legacy DD-PKG-012 failures.
- Server-advertised Store catalog endpoints remain preferred; `/api/store-catalog.php` is the canonical compatibility default and `/api/store.php` remains legacy fallback only.
## Security / request integrity
- Added explicit CSRF enforcement to authenticated Core mutation paths that were still relying only on login/session state: Media, Media Edit, Navigation, Page metadata, Page Builder JSON saves/template/reusable actions, Site Profile, Template export, Platform sync, revision restore, administrator account changes, administrator login, member login, and member verification.
- Page Builder custom JSON POSTs now send `X-CSRF-Token` and return HTTP 419 JSON on invalid tokens.
- Existing fetch/AJAX interception remains in place; action-specific busy labels/spinners and duplicate-submit prevention continue to apply.
## Regression tests
- Added Store regression coverage for grouped five-family catalogs, Server Official trust preservation, legacy DD-PKG-012 isolation, no Store self-posting forms, and dedicated Store action endpoint contracts.
- Fresh SQLite schema execution and Events Registration 2.0 check-in schema verification remain clean.
# DivisionDesk Core 4.2.2
## Store catalog endpoint/failover hotfix
- Core Store now prefers the Server-advertised Store catalog endpoint and recognizes `/api/store-catalog.php` as the current canonical endpoint, with `/api/store.php` retained only for compatibility.
- A successful modern catalog response is authoritative even when `packages` is empty; failure of an optional legacy repository endpoint no longer blanks the Store.
- Last-known-good catalog responses are cached for temporary Server outages.
- Heartbeat can advertise future endpoint changes through `endpoints.store_catalog` / `store_catalog_endpoint`, eliminating hard-coded endpoint coupling.
- Store errors identify the failing Server catalog source rather than implying that local Core scanned the remote Server file.
# DivisionDesk Core 4.2.1
## 4.2.1 SQLite upgrade hotfix
- Fixed the 4.1.x -> 4.2.x SQLite migration failure `no such column: checkin_token_hash`.
- SQLite schema application is now two-pass and idempotent: compatible CREATE statements run first, missing Events Registration 2.0 columns are added, then the full schema/index set is re-applied strictly.
- Migration errors in the Registration 2.0 column-add phase are no longer silently swallowed.
- Added an explicit regression test for an existing `event_registrations` table that predates `checkin_token_hash`.
## Added
- Core-owned Events and Registration 2.0: configurable attendee types, capacity/waitlists, flexible registration questions/options, per-type/option pricing, paid-registration provider handoff, signed QR check-in, printable badges, attendance, cancellation/refund workflows, CSV/reporting, confirmations and scheduled reminders.
- Core Events administration, registration setup, public registration/confirmation, badge, export and check-in endpoints.
- Events permissions and Administration navigation.
## Changed
- Existing legacy Events add-on installations are enhanced non-destructively: Core reuses the existing Events/registration tables and adds missing Registration 2.0 fields while leaving the mature legacy provider enabled so recurrence, categories, ICS/API, import/export and Builder widgets are not lost during upgrade.
- Server/Store trust metadata now normalizes current and legacy authority fields before restricted package validation.
- Server responses containing HTML instead of JSON now identify that condition explicitly and include a bounded diagnostic excerpt.
## Fixed
- Fixed Core Store catalog regression where first-party packages could be misclassified as Community when Server used legacy Official metadata, causing false DD-PKG-012 security errors against Official code.
- Fixed native Events QR generation mask/format encoding discovered by decoder QA.
- Fixed dollar-to-cent conversion for integer-looking UI prices such as `25`, which must mean $25.00 rather than 25 cents.
## Security
- Third-party validator rules remain unchanged in strength. Official bypass is granted only from remote Server/Store trust authority; package-local `official`/`trusted` flags do not elevate trust.
# DivisionDesk Core Changelog
## 4.1.0 — 2026-08-18
### Shared Client/Server module architecture
- Added the formal package runtime contract: `client`, `server`, or `both`. Legacy packages remain `client` for backward compatibility.
- Core now rejects Server-only packages during dependency planning, quarantine validation, installation, module boot, lifecycle execution, and package Help discovery.
- Package-local metadata cannot widen the runtimes authorized by DivisionDesk Server.
- Added `Integration::runtime()` and `PackageContext::runtime()` so portable `both` packages can adapt through the SDK without relying on host internals.
- Recorded package runtime in Core-generated `.security.json` metadata and local package inventory.
### Publishing/distribution integration
- Formalized the existing destination registry as `DistributionRegistry`, with package ownership, package-qualified IDs, optional capability enforcement, duplicate protection, and delivery lifecycle events.
- `Registry::destination()`, `Integration::destinations()`, and `Integration::distribute()` allow future Publishing to discover Website, email, Social Media, and other installed delivery providers without hard-coded module dependencies.
- Destination delivery emits `distribution.before`, `distribution.after`, and `distribution.failed`.
### Page Builder charts
- Added a native Chart block to the drag/drop Page Builder.
- Supports bar, line, and donut visualizations from editable label/value data.
- Charts are rendered by Core without a third-party JavaScript dependency and include an accessible data table.
- Chart configuration is preserved in normal Page Builder layouts, Page Layouts, reusable sections, and Site Templates.
### Release rules
- Existing fetch/AJAX busy-state rules remain mandatory. No new state-changing browser endpoint was introduced in this revision.
- PHP/JavaScript syntax, runtime-target failure paths, destination registration/delivery, chart rendering, Help documentation, Core integrity, and ZIP integrity are release gates.
## 4.0.0 — 2026-08-18
### Platform services
- Formalized the once-per-minute Core scheduler/background-job dispatcher, package Smart Action scheduling, job locking/retry diagnostics, and corrected Administration/Help cron guidance to `* * * * *`.
- Added provider-based public Site Search with Core page/layout indexing, snippets, JSON results, AJAX results with a visible Searching spinner, and package search-provider registration.
- Added first-party Newsletter Signup, Site Search, and Organization Profile Page Builder widgets. Newsletter Signup delegates to a registered Communications Smart Action rather than duplicating mailing-list logic in Core.
- Added organization context/catalog/provisioning services so DivisionDesk Server can supply organization types plus required/recommended/optional package guidance and Core can install required dependencies.
- Added module-owned page/navigation registration and capability-provider registration to the Integration SDK.
### Page Builder, templates, and site composition
- Preserved drag/drop + WYSIWYG authoring, Page Layouts, reusable sections, complete Site Templates, theme switching, and 25-revision behavior while adding organization/capability conditional content.
- Added server-side rich-text sanitization before rendered WYSIWYG content reaches the public page; unsafe script/event/javascript URL content is removed even if saved content was modified outside the editor.
- Added organization-aware Core widgets and template condition evaluation without coupling templates to a particular membership or organization module.
- Existing Site Template application continues to create a backup before merge/replace and Page Layouts continue to receive fresh builder IDs on application.
### Store, dependencies, and package trust
- Expanded dependency planning for required/optional/conflicting packages, Core/PHP compatibility, capability dependencies, version constraints, cycles, and uninstall dependent checks.
- Added local Package Security controls for disabling packages, reducing Server trust, and denying optional capabilities. Local policy cannot elevate trust.
- A locally downgraded Official package is revalidated under its reduced trust rules before execution; packages that cannot satisfy the restricted model are blocked with an administrator notice.
- Added cryptographic SHA-256/RSA package-signature verification support for Store packages and Core release packages when DivisionDesk Server supplies signing metadata. Modified signed artifacts fail verification.
- Hardened restricted-package analysis against PHP global state, ambient session/environment/cookie access, direct Core/database access, process execution, direct stream/filesystem/network primitives, shell backticks, dynamic includes, undeclared networking/capabilities, unsafe JavaScript globals, malformed manifests, duplicate IDs, and archive traversal/symlinks.
- Added package-qualified identity enforcement and local package security inventory/diagnostics.
### Mediated package capabilities
- Expanded PackageContext/WidgetContext with least-privilege organization, viewer, storage, scheduler, and HTTP capabilities.
- Package storage is isolated in Core-managed settings storage with a bounded JSON payload.
- Mediated HTTP enforces HTTPS, authorized hosts, DNS resolution, private/reserved-network SSRF blocking, no URL credentials, redirect suppression, bounded timeout/response size, and audit logging.
### Legal & Policies Wizard
- Added Website → Legal & Policies Wizard for Privacy Policy, Terms of Use, Cookie Policy, Accessibility Statement, Website Disclaimer, Copyright/Intellectual Property Notice, and capability-relevant refund/payment/account policies.
- Wizard supports Preview before publishing, effective-date/jurisdiction/contact/site-practice inputs, normal editable Page Builder output, policy-profile metadata, and version history through Page Builder revisions.
- Added `Registry::legalPolicy()` so modules can contribute capability-aware policy/disclosure content while Core retains applicability, sanitization, preview, publishing, and revision control.
- Generated content is explicitly presented as an editable starting template/workflow aid rather than individualized legal advice.
### Unified UI and accessibility
- Added reusable Core UI helpers and Developer → UI Showcase for notices, empty states, badges, spinners, progressive disclosure, validation, and fetch/AJAX conventions.
- Added the public icon-only Accessibility control on the left side with text-size and contrast preferences; public footer injections remain excluded from Administration/API responses.
- Preserved the Core-wide fetch-first POST layer. New/custom asynchronous actions use action-specific busy labels/spinners, `aria-busy`, duplicate-action prevention, and explicit success/error feedback.
- Added explicit CSRF protection to Store state-changing actions and Automatic Updates controls; corrected legacy Theme activation to a protected POST action.
### Help, roles, diagnostics, and acceptance testing
- Added automatic package-provided Help ingestion for modules, themes, widgets, Site Templates, and Page Layouts using safe package-relative Help files or inline topics.
- Retained granular role/permission administration and capability-driven Administration visibility as the authorization foundation for the new services.
- Expanded System Health into a simple attention summary backed by database, permissions, Server heartbeat, scheduler, queue, ZIP, update-writability, and acceptance-target checks.
- Added protected Reference Host Acceptance Tests for explicitly authorized demo/test/development clients. The suite exercises real database rollback, Core integrity, Page Builder save/revision cleanup, scheduler/queue contracts, search/widgets, multiple widget instances, sanitization, conditional content, trust policy, cryptographic sign/tamper verification, ZIP quarantine validation, organization/legal generation, and authenticated/CSRF endpoint contracts; results can be reported to a Server-provided acceptance endpoint.
### Update/install reliability
- Preserved update preflight writability checks, maintenance lock, transaction backup, database migration hook, post-copy version verification, automatic rollback, and user rollback backups.
- Core update ZIPs now use the same hardened archive path/symlink validator as Store packages and can be cryptographically signature-verified before extraction.
- Browser/CLI installer and updater continue to create sane writable paths and fail before mutation when PHP cannot safely write the incoming tree.
### Release rules
- Fetch/AJAX with visible busy feedback, syntax checking, error-path testing, endpoint testing, input preservation on recoverable errors, Help updates, and explicit reporting of environment-limited tests remain mandatory release gates.
## 3.9.0 — 2026-08-18
### Integration SDK
- Expanded the existing Core event bus into a package-aware, priority-ordered integration contract while preserving existing `Registry::eventListener()` compatibility. Listener failures are isolated, logged, and do not stop unrelated listeners.
- Added capability-protected, package-qualified Smart Actions through `Registry::smartAction()` / `SmartActionRegistry`. Smart Actions can be discovered without hard-coding another module and emit before/after/failed lifecycle events.
- Added authenticated `/integration-actions.php` JSON discovery/invocation endpoint with server-side capability enforcement, CSRF protection, input validation, and explicit JSON failures.
- Added `Registry::dashboard()` / `DashboardRegistry` so modules can contribute capability-protected dashboard cards without modifying Core dashboard source. Failed dashboard contributions are logged and isolated.
- Added Integration SDK visibility to Developer & Advanced for registered Smart Actions, event listeners, ownership, priority, capabilities, and dashboard contributions.
### Fetch/AJAX interaction standard
- Added reusable `DivisionDeskFetch.request()` and `DivisionDeskFetch.busy()` APIs for custom asynchronous interfaces.
- Core fetch-first POST forms now replace the initiating control with an action-specific spinner/status such as Loading, Saving, Publishing, Installing, Sending, Uploading, Updating, Removing, Applying, or Preparing while awaiting the response.
- Busy controls use `aria-busy`, prevent duplicate submission, restore their prior label afterward, and respect reduced-motion preferences.
- Updated Page Builder custom fetch operations to use the shared busy-state helper for Save, reusable-section Save, and template Apply operations.
### Developer and Help documentation
- Added `docs/INTEGRATION-SDK.md`, expanded the Module SDK, and added a searchable Help Center topic covering events, Smart Actions, dashboard hooks, loose coupling, capabilities, and the asynchronous busy-state standard.
- Existing package security/trust requirements remain authoritative and apply to integrations; events and Smart Actions do not bypass package capability boundaries.
### Release requirements
- PHP and JavaScript syntax checks, integration/error-path unit tests, endpoint contract checks, fetch busy-state checks, Core integrity verification, and ZIP integrity are release gates. Live database-backed endpoint execution remains a target-host acceptance test when the build environment lacks PDO drivers.
## 3.8.1 — 2026-08-17
### Package security and trust
- Added a quarantine-first package security validator to the Store installation path. Restricted package code is validated before it can replace an installed module, theme, or widget.
- Added externally assigned `official`, `trusted`, and `community` trust handling. Package-local author/developer/official claims never grant trust.
- Added stable `DD-*` security errors for prohibited global state, loose helper symbols, direct session/database/Core-service access, shell/process execution, filesystem mutation, direct network primitives, remote-code loading, malformed permissions, and JavaScript global leakage.
- Added package-qualified widget machine IDs (`package-id:widget-id`) with duplicate protection and backward lookup for pre-3.8.1 standalone `widget.slug` builder references.
- Added read-only `PackageContext` / `WidgetContext` runtime objects for standalone widgets.
- Added mediated HTTPS `PackageHttpClient` with authorized-host enforcement, HTTPS-only policy, private/reserved-network SSRF prevention, bounded timeout/response size, and no automatic redirects.
- Added Core-generated `.security.json` package records containing trust and granted permissions. Runtime permissions are read from that record rather than directly from manifest requests.
- Added package trust/security visibility to Developer & Advanced.
- Added Help Center and SDK/package-security documentation for the hard extension rules.
### Deferred hardening
- Local trust downgrade/capability denial UI, cryptographic package signing, deeper AST analysis, and additional mediated privileged capabilities remain explicit backlog items and are not presented as completed in this release.
## 3.8.0 — 2026-08-17
### Added
- WYSIWYG rich-text editing inside drag-and-drop Page Builder text blocks, including paragraph/headings, bold, italic, underline, lists, links, and an HTML source toggle.
- Organization-level metadata for standalone and module widgets, with Page Builder compatibility guidance.
- DivisionDesk Server announcement ingestion through the existing platform heartbeat so Server notices can appear in the administrator notification center.
- Server-provided admin push enrollment configuration can now participate in the Core push prompt alongside module push providers.
### Changed
- Page Builder continues to support installed Page Layouts, reusable sections, Site Templates, module components, standalone widgets, and module widgets while adding richer visual authoring.
- Browser notification Help now explains that Core/Server announcements as well as module alerts can use the administrator notification channel.
### Release requirements
- Changed browser actions remain fetch/AJAX based. PHP and JavaScript syntax, error paths, changed endpoints, and Help documentation are release-gate requirements.
## 3.7.0 — 2026-08-15
### Database portability
- Added Configuration → Database with a guided SQLite ↔ MySQL / MariaDB migration workflow.
- Destination connection and emptiness are checked before copying begins.
- Public write actions are briefly paused during the copy so the source cannot change halfway through verification.
- DivisionDesk creates rollback protection and leaves the source database untouched.
- Core and installed-module tables are discovered dynamically rather than relying on a Core-only table list.
- Data is copied in small fetch-driven batches with visible progress.
- Indexes, composite keys, and foreign-key relationships are recreated.
- Every table is verified by row count and a deterministic content checksum before activation.
- DivisionDesk switches config only after all tables pass verification; failed activation restores the prior configuration.
- Cancelling a failed/incomplete move cleans up the temporary destination copy.
- A stale migration lock expires automatically so an abandoned browser session cannot permanently block public submissions.
### Administration notifications
- Added a reusable Administration toolbar notification center for Core and installed modules.
- The notification bell is hidden when there are no unread alerts.
- Clicking the bell opens a compact flyout of unread alerts; each alert can link directly to the screen or record that needs attention.
- Added module registration APIs for administration alert providers and browser-push enrollment providers.
- Core Admin Notices also participate in the notification center.
### Browser notifications
- Administration can show a simple Enable Browser Notifications banner when an installed module supplies a compatible push provider and the current browser/device is not subscribed.
- The banner explains what notifications do and keeps advanced implementation details out of the normal workflow.
- Enrollment happens without leaving or refreshing the Administration page.
### Fetch-first forms
- Added a Core-wide POST form submission layer using fetch.
- Normal POST forms no longer perform browser POST navigations, eliminating Confirm Form Resubmission prompts.
- Existing page-specific fetch handlers continue to take precedence.
- File uploads are supported through FormData; download responses are handled as downloads.
- Redirecting POST actions are followed with fetch and the resulting Administration content is updated in place.
- The browser installer uses the same fetch-first behavior.
- The Core audit found no browser POST form outside the fetch-first coverage path.
## 3.6.5 — 2026-08-15
### Administration usability
- Admin navigation items may expose a live unread badge.
- Badge counts refresh with lightweight fetch polling every 20 seconds without a page reload.
- Badge polling is opt-in per registered admin item and leaves navigation usable if an optional module endpoint is unavailable.
## 3.6.4 — 2026-08-15
### Added
- PublicFooterRegistry and `Registry::publicFooter()` for module-owned site-wide public UI.
- Public footer injections are excluded from Administration/API responses.
## 3.6.3 — 2026-08-14
### Fixed
- Restored bounded HTTPS redirect following in the cURL Platform transport. Core 3.6.2 could treat a normal canonical redirect as a non-JSON API response.
- DivisionDesk Store no longer silently swallows every Store/Repository endpoint failure and renders an apparently blank catalog.
- If all catalog endpoints fail, Store now displays the actual upstream transport/API errors while leaving the Administration page usable.
- Store API and legacy repository requests use an 8-second bounded timeout.
### QA
- Full PHP syntax pass, JSON parsing and JavaScript syntax checks performed across the current Core, Server and Communications packages.
- Core verification manifest regenerated after the final 3.6.3 contents were frozen.
## 3.6.2 — 2026-08-14
### Fixed
- DivisionDesk Server API errors are no longer collapsed into the generic `Could not contact DivisionDesk Server`.
- Platform HTTP transport prefers cURL when available and preserves HTTP status plus JSON error bodies.
- Stream fallback retains HTTP error bodies where supported and reports underlying transport errors.
- Server responses with `{ok:false,error:"..."}` are surfaced directly to modules.
- Invalid/non-JSON Server responses include a short safe response excerpt for diagnostics.
## 3.6.1 — 2026-08-14
### Fixed
- Module database migrations now execute before `Install.php` or `Update.php`.
- Fresh module installs no longer run both the install hook and the update hook.
- Module updates receive both `from_version` and target `version` lifecycle context.
- Store-time Addon registration now uses the same scoped Registry context as normal module boot.
- Fixes installation of modules that seed tables created by migrations, including Communications.
## 3.6.0 — 2026-08-14
### Added
- Renamed the SSH bootstrap installer to **`DivisionDesk-install`**.
- Added single-file **`divisiondesk-install.php`** browser installer for installations without SSH.
- Browser installer uses local filesystem installation first, with FTP, FTPS, SFTP and manual ZIP fallbacks.
- FTP/FTPS/SFTP credentials are request-only and are never persisted.
- CLI and browser installers consume the same formal DivisionDesk Core release-manifest contract.
- Installer bootstrap self-cleanup/self-disable integration with successful Website Setup.
- Core installer/verification service plus `bin/core-verify.php` groundwork for future guided repair of missing/changed Core files.
- Formal release manifest installer metadata: current version, package URL, SHA-256, exact package size, minimum PHP and installer API compatibility.
- Persistent background Job Queue with priorities, delayed execution, retry/backoff, failed jobs, idempotency keys, worker heartbeat and retention cleanup.
- Job-handler registry so modules can submit background work without implementing their own cron system.
- Encrypted Secret Vault using AES-256-GCM with a site-local key stored outside the public web root.
- Shared transport interface/registry for Email, SMS, Push and future communication providers.
- Shared authenticated-webhook/HMAC helper and webhook activity log.
- Core Event Bus for module-to-module notification triggers.
- Administration Job Queue diagnostics, manual worker execution and failed-job retry.
### Changed
- Installation documentation now uses `DivisionDesk-install`; legacy `scv-install` naming is no longer presented to users.
- Core updater accepts the formal `package_url` / `sha256` / `package_size` release manifest while retaining compatibility aliases.
- Scheduler now processes the shared Job Queue and cleans old completed jobs.
- Administration flyout sizing/spacing refined to reduce oversized module menus.
### Security
- Provider credentials can now be stored encrypted rather than in ordinary site settings.
## 3.5.4 — 2026-08-14
### Added
- Persistent **Remember Me** authentication for administrators using revocable, hashed device tokens.
- Automatic restoration of remembered administrator and member sessions on all DivisionDesk web requests.
- Administration **Email Delivery** settings with SMTP, PHP `mail()`, and Development/Log transports.
- SMTP test-mail tool and mail-attempt log.
- Administration navigation subgroups/flyouts so module tools can be grouped under their parent module.
- Module registration context so installed modules automatically receive a navigation subgroup when they register Organization tools.
- Changelog page in Administration.
- Formal `CHANGELOG.md` package convention in the Module SDK.
### Changed
- DivisionDesk production platform/server default is now `https://divisiondesk.com/`.
- Public `Member Login` navigation changes to **Logout** while a member or administrator is authenticated.
- Administration navigation shows the current administrator account and Logout links.
- Page Builder widget blocks now display the actual widget name, selected layout, and key configuration settings.
- Widget inspector now uses registered widget metadata to generate layout and setting controls.
- `Powered by DivisionDesk` now links to `https://divisiondesk.com/`.
- Email delivery status distinguishes SMTP acceptance, PHP-mail queue acceptance, development logging, and failures.
### Fixed
- Page Builder now preserves the widget identifier when a widget is dragged into a page. Previously a newly inserted widget could be saved without its widget key and later render as `Widget unavailable:`.
- Core package/server URL fallbacks no longer reference temporary project domains.
## 3.5.3 — 2026-08-14
### Fixed
- Administration registry Core items no longer disappear when an installed module registers its Administration destinations before Core boot.
- Help Center Core topics no longer disappear when module help topics register first.
## 3.5.2 — 2026-08-14
### Fixed
- Hardened Administration registry handling of short/malformed navigation definitions that could cause `Undefined array key` errors.
## 3.5.0–3.5.1 — 2026-08-14
### Added
- Capability-driven Administration.
- Grouped Administration navigation.
- Help Center and Administration search.
- Automatic update scheduler/background-job foundation.
- Module lifecycle and migration framework.
- Audit log, notices, system health, and developer tools.
- Standardized DivisionDesk footer.
## 3.4.0 — 2026-08-14
### Added
- Universal Variable Registry and Site Profile.
- Role/data resolver architecture.
- Standalone and module Widget registries.
- Site Template 2.0 support.
- Page Layout and Site Template export foundations.