Changelog

What we shipped, when. Newest first.

Forms are now easier to build without losing advanced control

30 July 2026

What's new

A clearer Form Builder for every club

  • Form creation now opens in a Guided setup where staff can write a question in

plain language and choose a straightforward answer style.

  • Common member-information packs add contact, address, emergency, guardian,

health and consent fields without making staff search through the complete field catalogue.

  • Yes / No / Other creates the three choices and a linked “Please tell us

more” follow-up automatically. The follow-up appears only when Other is chosen.

  • Guided setup, Full control and Preview all edit the same form. Switching views

never converts, duplicates or discards the underlying questions.

  • Full control keeps pages, review steps, conditional rules, validation, member

record bindings, layout content and payment/form settings available when they are needed.

  • The form itself now has more room. A visually distinct Steps panel shows

the current section and lets staff move any step up or down directly in the list. The question builder and current-step canvas use separate surfaces so each working area is easier to recognise at a glance.

  • Field settings and the complete field library open only when requested. Mobile

settings use the same accessible drawer pattern as the rest of the application.

  • Form cards keep Edit visible and place Responses, sharing, duplication and

Archive in a contained action menu, preventing actions from overflowing when a card is hovered or viewed on a narrower screen.

  • Preview now supports Next, Back and direct step navigation without forcing

staff to complete required questions. The final action is shown in a disabled preview-only state, so testing a form can never submit it.

  • The editor header now keeps the form name and Save action together, while the

programme audience selector has its own clearly labelled area below. Sharing remains in each form card's action menu, away from unsaved editor changes.

  • Every Steps panel now exposes Add, Rename and Remove controls in Guided setup,

Full control and mobile layouts. Removing a step asks for confirmation and explains whether questions or content will be removed with it.

  • Forms now opens with permanent Enrolment and Trial Booking journey cards. The

enrolment card follows the selected programme and clearly identifies a direct override, inherited club default or missing setup; the trial card links to the real booking journey. Event Booking is no longer offered as a generic starter because event-specific requirements remain with Events.

  • Those permanent journeys now sit in a distinct Built-in journeys panel

with their own icons, foundation labels and coloured card edges, making them clearly different from optional forms in the club's reusable form library.

  • Trial Booking questions are now editable per club. Clubs can organise their

own steps, questions, choices and required answers while Allsorted continues to protect the visitor's contact details, class/date choice, capacity check, guardian consent and final booking transaction.

  • Club-defined trial answers follow a booking when staff reschedule it and are

available to authorised coaches from the existing protected answers popup. Trial templates are deliberately not exposed as generic shareable forms: the public trial journey must reserve a real class and date.

  • Enrolment invitation sends now keep a stable button footprint, show

Sending… while work is in progress and retain an honest Sent, Queued, Not sent or Review needed outcome afterward. Success, information, warning and failure feedback now uses the shared toast surface instead of shifting the page with temporary inline banners.

  • Trial and enrolment invite rows now include a contained actions menu with a

protected history timeline. Staff can see when a trial was booked, invites were created, email delivery was attempted, opened, clicked or bounced, and when enrolment completed. An inconclusive delivery links to those safe details and Communications rather than stopping at an unexplained “needs review”.

Automations stays inside the screen

  • The Communications navigation wraps within the Automations page on narrow

screens instead of creating a sideways swipe area.

  • Automation category filters now wrap onto additional lines, keeping the Build

page vertical-only while preserving every filter as a visible one-tap option.

Assess everyone on the mat from the live register

  • A selected lesson now offers an On the mat assessment mode using the

register's saved Present and Late marks, so coaches no longer have to switch between separate levels to find everyone training in that lesson.

  • Each present member has one mobile-friendly expandable card. Opening it loads

that member's current level, assessment list, saved RAG scores, coaching notes, completion summary and attendance-since-level count in the same register page.

  • Assessment data is loaded only for the open member, keeping a large live

register responsive. RAG score changes reuse the existing protected assessment authority and visibly roll back with a toast if the server cannot save them.

  • Register, mobile assessment and examiner scoring views now share one clear

R / A / G control. The comment action consistently sits immediately to the left of Red, existing comment counts remain visible, and register comments use the same protected dated-comment history as the main Assessments screen.

  • Missing progression levels, empty assessment lists, no-one present, loading

failures and retry actions now have explicit lesson-floor states rather than appearing as blank content.

A simpler Courses workspace

  • Courses now separates the operational overview from the searchable course

library, so progress and attention items no longer push the actual courses below a large dashboard and filter panel.

  • Overview focuses on published courses, enrolled learners, average completion

and courses needing attention. Recently updated courses and attention items link directly to the relevant workspace.

  • Secondary library filters now live in a compact filter drawer while status

and search remain immediately available.

  • Overview, Courses and Packages now use the same animated icon-glass navigation

as the Communications centre and member information, keeping section changes visually consistent across desktop and mobile.

  • Each course has dedicated Curriculum, Settings, Learners and Insights tabs.

Curriculum keeps the course outline beside one focused lesson editor, with an Edit/Preview switch; course details, audience, access, pricing and certificate configuration now live under Settings.

  • Insights provides a read-only completion summary, progress distribution and

recent learner activity from the existing protected course-progress route.

  • Non-quiz lessons now use one Complete and continue action. Progress is

saved first, the latest server-authoritative unlock state is loaded, and the learner then advances to the next available lesson.

  • Course Packages now honours the existing list, detail, summary and subscriber

response contracts. Package counts render safely, existing packages reopen with their full course selection, and subscriber/revenue figures use the protected API fields without crashing the page.

Templates now explains and controls its live connections

  • Every communication template now shows whether it is unused or connected to

live, draft, paused, inactive or archived work. Where this is used brings together current Automation Builder versions, legacy rules, communication flows and event invitations, with a direct route back to each dependency.

  • Editing a template used by live messages now explains that the next resolved

content will change. Archiving has an explicit high-consequence warning, and the server refuses an unacknowledged archive when a live dependency exists.

  • Staff can create a safe draft automation with the selected template already

attached, then choose its trigger and publish in Automation Builder. Nothing sends from Templates itself.

  • A template can be assigned to an existing editable automation draft or an

event invitation from one controlled panel. Published automation versions are never changed, channel compatibility is enforced, tenant ownership is checked before every write and stale edit markers prevent overwriting newer changes.

Deployment note

  • The interface reuses the existing guarded form-template API and persisted

field/page/settings format. Editable Trial Booking answers additionally require the additive, locally rehearsed trial-booking-form-responses-01.sql migration before deployment. No new environment variable or feature flag is required.

  • Draft/published template versions and link-version pinning remain the next

server-authority delivery; this update does not describe the current Save action as publishing.

  • Template dependency inventory and assignments use existing tables and the

existing Automation Builder flags. No SQL migration or new environment variable is required.

Safer form publishing and configurable enrolment journeys

  • Form changes now remain drafts until a club deliberately publishes them.

Publishing creates an immutable live version, preserves the previous revision for in-progress links and keeps historical responses attributable to the questions members actually saw.

  • Enrolment invitations pin their published form version. Editing the next

version cannot silently change a link already sent to a member.

  • Required identity, programme, lesson, consent, signature, review and payment

stages remain protected by Allsorted. Clubs can still organise their own questions and optional extras without being able to remove a required legal or transactional stage.

  • Archived form families can be restored safely by cloning an old revision into

a new draft; restoration never rewrites historical data.

Annual credentials are ready for club-specific configuration

  • Annual Requirements can now record the governing organisation, member-facing

explanation, exact fee, validity period, evidence rule, renewal window and how long a renewal link remains usable.

  • A clear readiness state keeps online renewal and renewal-link automation off

until the definition is complete. The initial online journey supports insurance that does not require a member evidence upload; DBS, coaching and evidence-bearing credentials remain staff-tracked until their dedicated collection journeys are delivered.

  • Clubs that do not opt in continue using the existing insurance renewal

behaviour. Opted-in renewal tokens pin the exact configuration, and a free renewal no longer tries to create a zero-value Stripe payment.

  • These changes require the additive

form-template-version-lifecycle-01.sql and configurable-credential-renewal-01.sql units before application deployment. Both were applied and reapplied on the existing local Docker stack only; no production SQL or feature activation was performed.

Private lesson video saves and delivery reviews are now explicit

29 July 2026

What's new

Private lesson videos now survive the full authoring journey

  • A lesson now keeps an external YouTube/Vimeo URL separate from a private

storage object path, so a completed upload can be saved and reloaded.

  • Upload and finalisation intents are tied to the exact club, lesson, media

field and staff member. A consumed intent cannot be replayed onto another lesson or another club.

  • Staff previews and portal playback use short-lived signed reads only after

the existing course, enrolment and lesson gates pass.

Invoice PDFs can use safely stored club logos

  • Invoice PDFs now load PNG, JPEG and WebP logos through the same club-scoped

storage boundary as other generated documents.

  • Logos have a fixed maximum footprint so supplier and invoice details do not

overlap. Missing, malformed, oversized, external or other-club objects fall back to the club name without an outbound web request.

  • Replacing an object at the same storage path now invalidates the PDF cache,

so the next invoice render uses the new branding.

Behind the scenes — uncertain deliveries require review

  • Provider evidence is now recorded as accepted, rejected, retryable or

indeterminate, separately from the local queue status.

  • A scheduled send containing an unknown provider result moves to

review_required. The worker claimant never selects that state, preventing an automatic resend that could contact the member twice.

  • Scheduled workers use explicit 15-minute leases and guarded state

transitions. Terminal work cannot silently return to the queue.

  • Admin Health, the Owner Action Centre and Automations Failures now surface

safe review counts and context. Retry controls appear only when provider evidence explicitly says a retry is safe.

  • The delivery-review runbook documents the evidence and decisions operators

need; it deliberately provides no blind resend path.

Custom permissions have a controlled one-club pilot gate

  • Turning on the Custom-RBAC environment master is no longer enough to affect

every club. Enforcement additionally requires that exact club's controlled pilot flag.

  • Clubs outside the pilot retain their existing base-role permissions and do

not load staged overrides or presets. An unreadable pilot state fails closed rather than ignoring a stored deny.

  • Settings now explains whether enforcement is active for the current club.

The pilot runbook covers deny-wins, system locks, expiry, module gates, self-elevation, last-owner protection and configuration-only rollback.

  • A read-only owner diagnostic guide consolidates the lesson-staff integrity,

reminder-drain and deployed database-census evidence without applying SQL.

Form Builder changes now pass through the club permissions boundary

  • Creating, editing, duplicating, defaulting, archiving and restoring a form now

goes through a guarded server route instead of writing the database directly from the browser.

  • Form responses now load through that same club-scoped authority, so a failed

read is shown as unavailable instead of looking like there were no responses.

  • Starter forms and blank enrolment seeds are owned by the server. Form fields,

pages, conditional rules and programme scope are checked before saving.

  • Missing and other-club form identifiers receive the same response, demo-club

writes remain blocked, and save controls cannot be activated repeatedly while a request is in flight.

  • Archive and unsaved-change warnings now use the accessible in-product dialog;

save results use non-blocking notifications instead of browser alerts.

Deployment note

  • The outbound delivery lifecycle requires the additive owner-applied SQL unit

supabase/_proposed/outbound-provider-lifecycle-01.sql before the matching application code is deployed.

  • The SQL was applied twice and its state transitions were rehearsed against

the existing local Docker database only. No remote SQL, feature flag, real message or push was performed.

  • Custom RBAC remains remotely OFF. The two-key gate and owner preflight were

verified locally only; owner-run browser rehearsal and independent review are required before a production pilot.

  • Form Builder authority uses a code-first SQL closure:

supabase/_proposed/form-builder-server-authority-01.sql. Deploy the guarded route first, then the owner applies the SQL. It was applied and reapplied only on the existing local Docker stack; no remote SQL was run. P2.1 template versioning and published-link pinning are not included in this first delivery.

Enrolment signatures no longer block completion

28 July 2026

What's new

Public enrolments now keep consent signatures through final review

  • A parent who grants photo and video consent is prompted to draw or type a

signature before leaving the consent step, instead of reaching a disabled final button with no way to correct it.

  • Drawn signature evidence now remains available after its canvas leaves the

page, so the final review and submission use the signature that was captured.

  • The form confirms when a drawn or typed signature is present and removes the

missing-signature error as soon as the parent corrects it.

Grading lesson counts now follow the right programme

27 July 2026

What's new

Lessons since grading now reset against the programme that was graded

  • Multi-programme members now use the grading date stored against the relevant

programme rather than another programme's legacy date.

  • A lesson on the grading date is no longer described as happening "since"

that grading. The counter starts with later Present or Late attendance.

  • Programme-specific counts include only lessons explicitly linked to that

programme. General classes and historical attendance without a lesson link are not guessed into a programme.

  • If the counter cannot be checked, staff see an honest unavailable message;

the scores API no longer returns believable blank counts after a failed read.

Behind the scenes - erasure no longer trips over unlinked attendance

  • Attendance records without a lesson can now be retained in the deletion audit

during an authorised member erasure or parent teardown.

  • A null lesson is explicitly not treated as proof of a parent cascade, so the

existing refusal of unauthorised direct attendance deletion remains in force.

  • The two database changes were owner-applied in the reviewed order and passed

their 4/4 and 8/8 production postflights before the matching code merge.

Club logos no longer trigger arbitrary server requests

  • PDF and inline-email branding now downloads only the current club's logo from

this project's club-logos storage bucket.

  • Internal, metadata, external-host and cross-club logo URLs are rejected

without making a request.

  • Club Details now uses the validated logo uploader only. A legacy externally

linked logo should be re-uploaded; PDFs deliberately fall back to the club name until that is done.

Large course and video uploads are safer and more reliable

  • Course media now uploads straight to private storage, so large files no

longer have to pass through the application server before progress appears.

  • Course documents are checked as real PDF, image, video or Office files before

their storage path can be saved. Renamed ZIP files and unsafe archives are rejected.

  • Family video submissions are confirmed against the object actually stored;

missing, altered, oversized or replayed uploads are refused instead of saving misleading metadata.

Safer previews and spreadsheet exports

  • Automation email previews now keep template HTML inside an isolated preview

frame, so a template cannot run code in the AllSorted page.

  • Grading and event CSV exports treat formula-looking names and values as text

when opened in Excel, LibreOffice or Google Sheets.

  • The stricter browser script policy is fully tested but remains off by default;

it will move through report-only review before any production enforcement.

Safer diagnostics and more honest cleanup

  • Error reports now remove credentials, contact details, addresses, dates of

birth, safeguarding and medical details, and payment/provider references before any event can leave the browser, server or edge runtime.

  • Stopping staff impersonation now invalidates the server-side credential before

clearing the browser cookie, so a failed cleanup cannot be presented as a safe stop while a copied token remains usable.

  • Push-subscription cleanup and delivery timestamps are checked and retried.

Persistent metadata failures are reported without sending a successful push a second time or claiming that a dead subscription was removed.

Enrolment invitations now preserve uncertain delivery

26 July 2026

What's new

Behind the scenes - uncertain invitations are not sent twice

  • If the email provider may have accepted an enrolment invitation but its

response cannot be confirmed, the invitation now remains visibly unresolved instead of being labelled failed.

  • Staff see a warning to check Communications before sending again. The public

post-trial request remains deliberately opaque and cannot reveal whether an address was delivered, queued, suppressed or unresolved.

  • Queued and unresolved invitations now keep that status after a page reload.

Their Resend action remains unavailable, and the server refuses to create a replacement token, until the existing delivery reaches a known outcome.

  • Provider identity and bookkeeping intent are now stored in the same outbox

settlement that proves an email sent. The email-outbox cron repairs those durable post-send history/token markers without calling Resend again; failed and concurrent clears stay visible until a reread proves the marker is gone.

  • The Phase 5 release checklist now includes the provider receipt, Action Brief

and task-reminder SQL units in one ordered deployment matrix. Nothing was pushed, no remote SQL was applied and no real communication was sent.

  • A hash-pinned two-window owner runner keeps migration-before-code and

code-before-migration SQL in the reviewed order. Phase 5 closure is implemented locally and awaits independent review; it remains undeployed.

Behind the scenes - dependency security gate now decides rather than block

  • Two production advisories were fixed by upgrade, not suppressed. Image

processing moves to sharp 0.35.3, which also clears the advisory Next.js was reported under - Next.js held no advisory of its own there and stays on the current supported release. Nothing was downgraded.

  • The image optimiser was assessed as genuinely exposed, not theoretically:

member-facing pages use Next.js image optimisation over remote sources, so those library flaws were treated as reachable and fixed on that basis.

  • The weekly security audit previously had to pass or fail as a whole, which

meant one advisory with no available upstream fix could only be handled by weakening the check. It now runs against an explicit register that must match an advisory exactly - identifier, package, installed version and dependency path. The audit fails if any of those change, if a new high or critical advisory appears, if a register entry no longer matches anything, or once an entry expires.

  • Anything that reads as an authorisation or access-control flaw can never be

registered. The audit stops and reports instead.

  • One entry is registered today: a denial-of-service flaw in a pattern-matching

library reached only through spreadsheet export and error reporting, neither of which passes member-supplied text to it. The published fix cannot be applied because the affected copies are pinned by their parent packages, which was verified rather than assumed. This entry expires on 9 August 2026, and the security audit fails from that date until it is re-assessed - it cannot be renewed by moving the date alone.

  • Test-suite timeouts no longer report runner speed as a test failure. No

assertion changed; only the time budget for whole-tree source scans.

Behind the scenes - faster, cleaner development checks

  • Everyday checks now reuse TypeScript's incremental cache and select related or

domain-owned tests. The complete cold type-check, full suite, every scanner, lint and production build remain mandatory at phase, PR and release boundaries.

  • Reviewed packs cover Events, Money, Communications, Grading, Portal,

Memberships, Reporting, Automations and Platform work. Shared authority, database, dependency and CI changes automatically escalate to the full gate.

  • A workspace doctor now identifies oversized Next/Turbopack caches, generated

browser evidence and stale worktrees. Next output can be reset safely; evidence cleanup is dry-run by default and protects canonical and operational records.

  • Smoke artifacts no longer persist portal bearer tokens, and smoke run IDs are

constrained to a safe basename before any report or screenshot path is built.

  • This tooling phase changes no member or staff product behaviour and requires no

migration, environment change, feature flag or communication.

  • The test catalogue is now executable and locked: every test file belongs to

one class, each run publishes an execution manifest, and the aggregate rejects missing, duplicate, unclassified or silently skipped database coverage.

  • TypeScript 7 is available as the fast full-project checker while TypeScript

5.9 remains in place for Next.js, ESLint and compiler-based tooling. A parity gate runs both compilers and proves both reject a deliberate type error.

  • Six whole-app scanners now share one fresh in-memory source inventory. Their

rules and baselines are unchanged, and known-bad controls prove each optimized scanner still fails when it should.

  • Seven test classes now run as parallel CI lanes. The database lane creates a

disposable, fingerprinted Supabase catalogue on isolated ports, runs all 29 database files serially and refuses skipped, pending or todo database tests. The data-only fixtures, seed and both local API keys are verified before the class starts. The old optional database waiver is gone; one exact-once aggregate keeps the existing required CI / test check name.

  • The first clean-runner pass found two environment-only defects: the schema

diagnostic tried to replay 12 managed-role default privileges, and a control test inherited the outer GitHub SHA inside its temporary repository. Both are now explicit, controlled transformations rather than CI-only surprises.

  • Disposable database startup checks now identify the exact unhealthy service.

Local service-role verification uses the running PostgREST gateway; the database suites retain the stronger GoTrue admin-user behaviour proof without making a catalogue-listing endpoint a prerequisite for starting the class.

  • PostgREST readiness now uses a zero-row table read instead of generating the

full OpenAPI document for the application schema. Transient schema-cache rebuilds after reset are retried within a fixed limit; persistent failures still stop the lane and include the provider's safe error response.

  • Strict database evidence now preserves and prints every pending or todo test

name instead of throwing before the count was copied into the lane manifest. The raw Vitest report is retained with the class evidence for diagnosis; the zero-pending gate itself remains unchanged.

  • The disposable database now installs the reviewed PostgreSQL function defaults

before replay creates any function. This prevents fresh Supabase bootstrap grants from silently widening functions that are service-only in the captured catalogue. A preflight checks representative money, erasure, grading and invite authorities before any test starts.

  • That default-authority check now creates a real throwaway function inside a

rolled-back transaction before and after the database class. It proves the applying role, owner and inherited PUBLIC/anon/authenticated/service-role permissions instead of inferring them from default-ACL rows.

  • The schema-only database now receives a pinned CI-only attendance cutover

singleton. This supplies the real prerequisite used by class-pack triggers and turns an unexplained missing-row failure into a preflighted fixture contract.

  • Once the central database preflight succeeds, the census and Phase 2D runtime

suites fail loudly if they lose the database or local API keys; they can no longer account for six skipped assertions. Census failures retain the spawn error, signal, stderr and stdout tail with a larger bounded output buffer.

  • Historical exposure tests now create their vulnerable grants inside their own

controlled window and restore the exact state they captured; they no longer depend on an old shared-database posture or test-file order. The database lane also fingerprints functions, grants, RLS, policies, constraints, indexes, triggers and default privileges before and after all 29 files, failing if a green-looking test leaves catalogue residue for the next file.

  • Function-authority fingerprints now compare the complete effective grant set

in a stable order. PostgreSQL may store equivalent ACL entries in a different array order after a revoke and re-grant; that harmless representation change no longer fails CI, while any changed grantee, grantor, privilege or grant option still changes the fingerprint.

  • The exact-once matrix now accounts for 1,087 test files after the reviewed

database-baseline authority contract was added. The 29-file strict database class remains unchanged and still permits no skipped, pending or todo tests.