SYSTEM LOG / CHANGES
Notes from systems in motion.
- More reliable internal foundation for future processing notifications This commit adds a PostgreSQL-backed durable record of notification events and delivery tasks. It preserves committed processing outcomes, prevents duplicates, and keeps history safe after channel deletion; automatic outbound sending is not included yet.
- Reliable notification delivery with audit trail and retries Multimodal Input Pipeline now includes a background service for delivering HTTP notifications. Events are sent, temporary errors are retried, unsafe redirects are blocked, and deliveries have a safe audit trail. Project owners/administrators can inspect their own channel history; platform administrators can view an operational summary and retry only failed deliveries.
- New platform administration area The stable /admin interface gives platform administrators one place for users, projects, shared processing providers, and notifications. It adds one-time password dialogs, project HTTP notification delivery history, and retry for failed deliveries.
- Shared processing connections and project fallback management in Multimodal Input Pipeline Platform administrators now have a dedicated admin contour for shared processing connections: create/update one option per capability, protected API key storage, enable/disable, health checks, and a safe project effective view with an explicit fallback policy.
- Added unified project administration Platform administrators can now manage all projects through a protected administration layer without personal membership: paginated search, safe summaries and counts, project creation with an explicit owner, settings updates, member and role changes, atomic ownership transfer, archive and restore.
- Provider keys and sensitive notification headers are now stored encrypted The commit strengthens configuration security in Multimodal Input Pipeline: provider API keys and sensitive HTTP notification headers are stored as AES-256-GCM, legacy values are rewritten at startup, and reads/API/UI show only masked state.
- Multimodal Input Pipeline Adds Safeguards for Platform Administrators Multimodal Input Pipeline now uses a separate persisted USER/ADMIN platform role. Active platform administrators can access administrative areas, while disabling a user immediately ends their browser session.
- Secure account administration added for platform administrators The platform now has a service API for securely managing local accounts. Platform administrators can search and list users, create accounts, update profiles and roles, enable or disable access, and reset passwords. Temporary passwords are generated safely, returned only once in non-cacheable responses, and require the user to set a permanent password.
- cURL Import for HTTP Channels Is Easier in Lifecycle Circuit Importing an HTTP channel from a cURL command now opens in a separate dialog. After parsing, the method, URL, headers, and body are shown in a clearer preview with masked secret header values, then users can apply the result to the channel with one click.
- Lifecycle Circuit: Import HTTP notification settings from cURL HTTP notification channels in Lifecycle Circuit now support choosing the request method and importing configuration from a pasted cURL command. LC parses the command on the server, never executes curl or a shell, and shows a preview with masked secret headers before you apply it.