mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-10 10:49:35 +00:00
32a7d53b2b
* feat: add RBAC viewer accounts, atomic deployments, and fleet-wide backups (Pro) Introduces three Pro-tier features: - RBAC: Multi-user system with admin/viewer roles, user management UI, automatic migration from single-admin credentials, viewer restrictions across the entire UI (read-only editor, hidden action buttons) - Atomic Deployments: Pre-deploy file backup to .sencho-backup/, automatic rollback on health probe failure, manual rollback button, health probes added to stack updates, webhook-triggered deploys use atomic rollback - Fleet-Wide Backups: Point-in-time snapshots of compose files across all nodes (local + remote), stored centrally in SQLite, per-stack restore with optional redeploy, graceful handling of offline nodes * fix(settings): use correct ProGate prop name in UsersSection * fix(settings): remove unused isPro prop from UsersSection * fix(auth): fetch user info after login and setup so isAdmin is set correctly * feat(pricing): revise pricing strategy and enforce variant-based seat limits Raise Personal Pro from $49/yr to $69/yr with 3 viewer seats (up from 1). Add $15/mo billing option for Team Pro. Mark lifetime pricing as a 90-day early-adopter offer. Store Lemon Squeezy variant_name on activation/validation and enforce seat limits server-side per variant. * feat(licensing): add Lemon Squeezy checkout, webhook, and billing portal integration Server-side checkout URL generation (POST /api/checkout) with admin email pre-fill and instance_id custom data. HMAC-SHA256 verified webhook endpoint (POST /api/webhooks/lemonsqueezy) handling order, subscription, and payment lifecycle events for automatic license activation. Customer billing portal link stored from webhook events and exposed via GET /api/billing/portal. In-app checkout buttons in Settings with manual license key fallback. * fix(licensing): exempt Lemon Squeezy webhook from auth middleware The catch-all auth middleware on /api/* was blocking the public webhook endpoint. Added /webhooks/lemonsqueezy to the exemption list alongside /auth/* and /webhooks/:id/trigger. * feat(pricing): update pricing to final live rates Personal Pro: $7.99/month, $69.99/year, $249 lifetime. Team Pro: $49.99/month, $499.99/year, $1,499 lifetime. Added personal_monthly checkout variant across backend, frontend, and website. * refactor(licensing): remove server-side checkout/webhook for self-hosted model Sencho is self-hosted — each user runs their own instance, so there is no central server to receive webhooks or hold the store API key. Replaced in-app checkout buttons with a "View Pricing" redirect to sencho.io and kept manual license key activation as the primary flow. - Delete LemonSqueezyService (checkout, webhook, HMAC verification) - Remove POST /api/checkout, GET /api/billing/portal, POST /api/webhooks/lemonsqueezy - Remove raw body parser and auth exemption for webhook route - Remove all LEMONSQUEEZY_* env vars from .env.example - Replace checkout buttons in SettingsModal with single "View Pricing" button - Simplify LicenseContext checkout to open sencho.io pricing page - Update licensing docs to reflect website-based purchase flow * chore: normalize em-dashes to hyphens across codebase (linter) * chore: remove accidentally tracked directories from index
2.1 KiB
2.1 KiB
Manual Steps Required
These actions could not be performed automatically and need to be done manually in the GitHub UI.
1. Branch Protection Rules for main
Go to Settings > Branches > Add branch ruleset for main:
- Require a pull request before merging
- Required approvals: 0 (solo dev - you merge your own PRs after CI passes)
- Dismiss stale reviews when new commits are pushed: ON
- Require status checks to pass before merging
- Add these job names:
Backend (Build, Test, Lint),Frontend (Build, Lint),Docker Build & Scan,E2E Tests (Playwright)
- Add these job names:
- Require conversation resolution before merging
- Do not allow bypassing the above settings (even you must go through PRs)
- Do not allow deletions
- Require signed commits (optional - future improvement)
2. Repository Settings
Go to Settings > General > Pull Requests:
- Check "Automatically delete head branches"
- Set squash merge as default merge strategy
3. Security Settings
Go to Settings > Code security and analysis:
- Enable Dependabot alerts
- Enable Dependabot security updates
- Enable Secret scanning
- Enable Secret scanning push protection
- Enable Private vulnerability reporting
4. Default Branch
Verify that main is set as the default branch:
- Go to Settings > Branches > Default branch
- Should already be
main
5. Delete develop Branch (When Ready)
The develop branch has 1 unmerged commit (37f751c docs: refresh screenshots).
Before deleting, decide whether to:
- Cherry-pick that commit to main via a PR, OR
- Let it go (it's just a screenshot refresh)
Then delete via: Branches page > delete develop
Also clean up stale feature branches that have been merged:
chore/refresh-screenshotsfix/editor-loadingfix/release-please-configfeat/automated-versioningfix/docker-publish-tag-triggerfeat/arm64-docker-buildchore/migrate-to-docs-jsonfix/sync-docs-rsync-excludes-gitfix/ci-docs-jobs,fix/ci-docs-jobs-v2
6. Delete This File
Once all manual steps are complete, delete MANUAL_STEPS.md from the repo.