Changelog

What's new in GlobFam

Follow our progress as we build the multi-currency finance platform for global families. Every update, feature, and fix — documented.

17

Releases

92

Features

26

Fixes

147

Total Changes

Post-0.16.0 Hardening

Latest

Lock down the new external remittance RPC to service_role only, fix an accessibility regression on suggestion pills, and tighten the gitignore so ad-hoc working files can't leak into a commit.

v0.16.1May 8, 2026
1 fix
3 total
  • SecurityRevoke EXECUTE on the create_external_remittance function from the anon and authenticated roles. The Next.js route already invokes it via the service_role admin client, so the app keeps working — but a logged-in user can no longer hit /rest/v1/rpc/create_external_remittance directly with a guessed family_id and fabricate remittance rows for another family. Flagged by the database linter and patched in migration 20260506130000.
  • FixSuggestion pills (asset names, banks per country, transaction descriptions) had a role='listitem' on a button with aria-pressed — invalid on listitem and confusing to screen readers. Parent now uses role='group' and the buttons keep native button semantics, so they announce as actionable controls.
  • ChoreTighter .gitignore — ad-hoc screenshots, PDFs, PPTX, and zips at the repo root are now ignored, alongside .playwright-mcp, supabase/.temp, and supabase/.branches. Working-tree cruft can no longer be staged accidentally.

Compliance Polish, External Remittances & Data Hygiene

Compliance alert items are now properly clickable, family-overview tiles work even before data is logged, financial status no longer cries red when there's months of runway, member deletion actually cleans up dependents, and remittances can go to people outside the app.

v0.16.0May 6, 2026
10 features
7 fixes
19 total
  • FeatureCompliance alert rows are now individually actionable — each issue chip (visa expiring, work hours exceeded, below financial threshold) routes to the right detail page for that member. Member name and arrow link to the highest-priority issue.
  • FeatureFamily Members detail page now shows real visa info and owned assets — visa type, expiry status pill, asset list with ownership-adjusted values — replacing the static 'will be available once linked' placeholders.
  • FeatureEdit visa profile from the Family Member card or the Visa Expiry detail page — modal lets you update visa type, number, grant/expiry dates, and notes. Members without a profile get an Add visa profile CTA that creates one in place.
  • FeatureSnooze compliance alerts on the dashboard — X button on each alert dismisses it for 7 days, with an Undo toast. Hash includes the affected member set, so a new issue resurfaces the alert immediately.
  • FeatureRemittance to someone outside the app — new toggle on the receiver section ('Family member' / 'Someone else'). External recipients enter the person's name; only the sender expense is recorded (no paired in-family income). Backed by a new SQL function with audit logging.
  • FeatureBudget month navigator redesigned — full-width three-zone switcher with peek panels (← previous · viewing · next →) and a 'Jump to today' pill when off-current. Removed redundant date from the page eyebrow.
  • FeatureSuggestion pills under text inputs — common asset names per type, banks per country (CommBank, Khan Bank, Chase, etc.), transaction descriptions per category. Click to fill, no typing required. Architecture extensible to AI-generated suggestions later.
  • FeatureCompliance grid tiles are clickable whenever the module is applicable to the visa type — even before data exists. Empty cells show a 'Log your first shift' / 'Add expiry date' / 'Set up threshold' CTA in brand-ocean so users can navigate through to fix missing data.
  • FeatureCompact currency abbreviation for summary tiles (A$1.22M, A$200K) so big numbers never get truncated when columns are narrow. Hover any tile to see the full precise value.
  • FeatureCompliance 'View all' on the /compliance page now smooth-scrolls down to the Family overview section instead of navigating to the same URL. On the dashboard banner it still routes to /compliance.
  • FixFinancial status no longer shows red when the user is below threshold but has months of visa runway left — now amber, with a constructive header that even calculates a savings target ('about A$920/month to close the gap by expiry').
  • FixBudget currency conversion drift — entering a $300 budget no longer round-trips to $309.31 after adding an expense. Budgets now store in the display currency the user typed in, normalised to primary currency server-side on read.
  • FixDeleting a family member now properly cleans up dependents — visa profile, asset ownership rows, and goal assignments are removed; assets owned only by the deleted member are deactivated. Compliance and portfolio queries also defensively filter archived members for legacy data.
  • FixCurrency symbol overlap in the amount input — selecting USD with a 'US$' prefix was running into typed digits. AUD and USD now share the bare '$' symbol; the right-side AUD/USD code badge disambiguates.
  • FixTotal Portfolio value was duplicated on the portfolio page — once in the page hero stats, once in the gradient summary card. Removed the duplicate and turned the section below into a 'Breakdown by type' with share-of-portfolio percentages and a thin allocation bar per card.
  • FixNative button accessibility warning on compliance detail pages — Base UI's nativeButton flag is now correctly disabled when the Button delegates to a Next Link via the render prop.
  • FixDropdowns on portfolio filters and family header replaced the native HTML <select> with the modern Select primitive so the visual language is consistent app-wide. Triggers now show the matching label instead of the raw value (Australia not AU, Newest first not newest).
  • RefactorAsset cards on the portfolio page use a single neutral type chip — Property, Crypto, Bank, Vehicle, Investment, and Super now render with the same calm grey treatment, leaning on icon and label for differentiation rather than colour.
  • RefactorRemoved gradient hover stripes from asset cards, member cards, and the live preview card — read as decorative noise rather than useful affordance.

Modern Forms, Live Feedback & Visa Editing

Complete redesign of the add-asset experience, a new modern dropdown system, visa profile editing from the member page, and live toast + spinner feedback on every mutation so pages refresh themselves.

v0.15.0May 4, 2026
9 features
3 fixes
15 total
  • FeatureAdd asset experience redesigned — five numbered editorial section cards (Type, Identity, Value, Ownership, Notes) with paper-grain texture, eyebrow labels, and a sticky bottom action bar. Currency-integrated amount input with symbol prefix and code badge. Live preview card on the right that mirrors the real portfolio card.
  • FeatureVisa profile editing from the Family Member page — Edit button on the Visa & Compliance card opens a modal with visa type, number, grant/expiry dates, and notes. Members without a profile get an Add visa profile CTA that creates one in place.
  • FeatureMember detail page now shows real visa info (type, expiry, status badge) and a list of owned assets with ownership-adjusted values — replacing the static 'will be available once linked' placeholders.
  • FeatureModern Select dropdown system app-wide — taller items with breathing room, brand-ocean filled check pip on selected, rotating chevron and lifted shadow on open, deeper layered shadow with backdrop blur, and a popup wide enough that long labels never truncate.
  • FeatureCurrency and country dropdowns show rich content — currency badge + code + full label; flag + country name + ISO code. Trigger-side flag/badge no longer collapses with no gap.
  • FeatureBudget month navigator redesigned — three-zone horizontal switcher with peek panels (← previous · viewing · next →), context-aware label that flips to 'This month' when on the current month, and a 'Jump to today' pill when off-current. Mobile-responsive (peek collapses to short month codes).
  • FeatureLive feedback on every mutation — success and error toasts via Sonner, inline Loader2 spinner inside submit buttons, router.refresh() so totals, lists, and cards update instantly without a page reload. Applied to asset, transaction, remittance, goal, contribution, member, family, visa, and delete flows.
  • FeaturePOST /api/compliance/visa-profile endpoint to create a profile when a member has none. Extended PATCH endpoint accepts full visa updates (type, number, dates, notes) alongside the legacy financial-threshold-only shape, with separate audit log actions.
  • FeatureConditional form fields — Institution and Last 4 digits only render in the asset form when the type benefits from them (Bank, Investment, Superannuation), reducing noise for Property/Vehicle/Crypto entries.
  • FixCurrency symbol overlap in amount inputs — selecting USD with a 'US$' prefix was running into typed digits. AUD and USD now share the bare '$' symbol; the right-side AUD/USD code badge disambiguates.
  • FixCurrency, country, member, and sort dropdown triggers now show the matching label instead of the raw value (e.g. 'Australia' instead of 'AU', 'Newest first' instead of 'newest').
  • FixNative HTML <select> elements in portfolio filters and family-header replaced with the modern Select primitive so all dropdowns share one visual language.
  • RefactorAsset cards on the portfolio page use a single neutral type chip — Property, Crypto, Bank, Vehicle, Investment, and Super now render with the same calm grey treatment. Differentiation lives in the icon and label, not in colour, matching the Mercury / Linear / Notion approach.
  • RefactorRemoved the gradient hover stripe at the top of asset cards, member cards, and the live-preview card — it read as decorative noise rather than a useful affordance.
  • RefactorEditorial paper-grain section cards extended to the asset form, matching the Visa Compliance feature's design language.

UI Consistency System

Editorial page heroes across every page, four shared design primitives, loading skeletons that match the real layout, and cleanup of internal labels.

v0.14.0Apr 25, 2026
4 features
1 fix
6 total
  • FeatureEditorial PageHero applied to Portfolio, Budget, Goals, Members, and Settings — paper-grain texture, eyebrow label, gradient-accent title, and inline summary stats
  • FeatureFour shared design primitives: PageHero, SectionHeader, EmptyState, StatTile — single source of truth for repeating patterns
  • FeatureStat tiles use design tokens (positive / amber / destructive / brand) instead of raw color values, so all financial summaries land on the same palette
  • FeatureLoading skeletons match the new PageHero layout — no more visible jolt when content arrives
  • FixRemoved internal “Sprint 3” / “Sprint 2” labels that were leaking from planning docs into the Visa Compliance header and changelog
  • RefactorStandardized empty states across the app — same icon-in-tile + heading + description + CTA shape everywhere

Settings, Notifications & Security

A real /settings page with Profile, Notifications and Security tabs. In-header notification center. Inactivity auto-logout. Password change flow. Security headers across every response.

v0.13.0Apr 24, 2026
6 features
2 fixes
9 total
  • FeatureSettings page with Profile, Notifications, and Security tabs — edit your name and avatar, manage email alerts per visa profile, change your password, and pick how long inactive sessions live
  • FeatureNotification center in the header — real unread badge with count, recent list (unread first, 30-day window for read), per-item mark-read with optimistic UI, mark-all-read action, 60-second background polling
  • FeatureInactivity auto-logout — 30 min default with a 2-minute warning dialog (“Stay signed in / Sign out now”). Configurable 15 min – 4 hrs per device. Cross-tab sync so activity in any tab keeps every tab alive
  • FeaturePassword change flow with current-password verification, validation rules (8+ chars, mixed case, number), rate limiting, and audit logging
  • FeatureSign out of other devices or sign out everywhere from the Security tab — revokes refresh tokens via Supabase admin so other browsers fall back to login on next request
  • SecuritySecurity headers on every response — Content-Security-Policy, Strict-Transport-Security with 2-year preload, X-Frame-Options DENY, Referrer-Policy, Permissions-Policy
  • FeatureLogin banner explains why you were signed out (?reason=inactivity / signed_out) so the experience isn't silent
  • FixTrim whitespace from environment variables — a stray newline in NEXT_PUBLIC_SUPABASE_URL was 500'ing every authenticated page on production
  • FixIdle timer no longer re-fires immediately after a fresh login when localStorage held a stale activity timestamp

Goals & Production Hardening

Savings goals end-to-end. Database row-level security across every family-scoped table. Sliding-window rate limiting. Significant dashboard performance wins.

v0.12.0Apr 23, 2026
3 features
8 total
  • FeatureSavings goals — create, edit, delete, contribute, with 4 templates (tuition, visa renewal, emergency fund, flights home). Progress auto-completes the goal when target is reached
  • FeatureGoals widget on the overview dashboard showing the four most pressing active goals with progress bars and deadline countdowns
  • SecurityRow-level security policies across families, family_members, member_invitations, audit_log, visa_profiles, work_hour_entries, compliance_checks, documents, goals, goal_contributions, notification_log, notification_preferences
  • SecuritySliding-window rate limiting via Upstash Redis — 5 req/min per IP on auth endpoints, 100 req/min per user on the rest. No-ops gracefully if Upstash isn't configured
  • PerformanceCompliance dashboard query is now O(1) batched queries regardless of family size — previously fanned out to 3N sequential database round-trips
  • PerformanceExchange rates cached for 5 minutes server-side, with explicit revalidation on mutations — most dashboard visits no longer hit the database for rates
  • FeatureBudget page polish — overall budget progress hero with income/expense trend indicators, refactored transaction form with clearer field groupings
  • SecurityPinned search_path on every SECURITY DEFINER function (user_family_ids, is_family_member, create_remittance_pair, delete_remittance_pair) — closes the Supabase database linter warning about mutable search paths

Visa Compliance Hub

Full visa compliance for international students and skilled workers — work-hour fortnight tracker, visa expiry countdowns, financial requirement monitoring, and email/in-app alerts when thresholds are crossed.

v0.11.0Apr 16, 2026
9 features
9 total
  • FeatureWork-hour tracker for student visas — log shifts, fortnight totals (Mon-anchored), amber warning at 38 hrs / red at 46 hrs of the 48 hr/fortnight cap
  • FeatureVisa expiry countdown — days remaining ring, renewal cost estimate, status thresholds at 90/60/30/14/7 days
  • FeatureFinancial requirement monitor — bank balance summed from owned assets vs the visa's threshold, with optional manual balance override
  • FeatureCompliance dashboard with member × check grid — quickly see who's green, amber, or red across work hours, expiry, and financials
  • FeatureDaily compliance cron — sends branded email alerts when a member crosses thresholds, with notification preferences per visa profile
  • FeatureCompliance alert banner integrated into the F1 dashboard — surfacing reds and ambers above the fold
  • FeatureEditorial document aesthetic for the compliance pages — paper-grain texture, monospace serial numbers, eyebrow labels, gauge-tick precision feel
  • FeatureThree visa types supported — Student 500, Skilled Worker 482, Partner 820/801 — each with its own applicability rules
  • FeatureNotification preferences dialog — choose which expiry-day milestones email you and toggle channels per profile

Auth Polish & Icon System

Forgot/reset password flow with branded emails, Lucide icon system replacing emojis, refined button interactions, and auth loading feedback.

v0.10.0Mar 31, 2026
4 features
1 fix
6 total
  • FeatureForgot password flow — rate-limited API, branded reset email via Resend, email enumeration prevention
  • FeatureReset password page — password strength meter, expired link handling, auto-redirect on success
  • FeatureLucide icon system — replaced all emoji icons with brand-consistent Lucide icons across budget categories
  • FeatureAuth loading feedback — branded overlay with logo spinner and progress bar during sign-in and registration
  • FixButton hover effect refined — gentle lift with branded shadow instead of flashy sweep animation
  • RefactorCategory icon registry pattern — string keys stored in DB mapped to React components at render time

Portfolio & Budget

Multi-currency asset portfolio with ownership tracking, full budget management with international student categories, and cross-country remittance handling.

v0.9.0Mar 31, 2026
11 features
11 total
  • FeatureMulti-currency portfolio — track bank accounts, property, vehicles, investments, crypto, and superannuation across countries
  • FeatureAsset ownership — assign multiple family members with percentage splits
  • FeaturePortfolio summary with total value, type breakdown, and real-time currency conversion
  • FeatureBudget management with 13 default categories tailored for international students (tuition, visa costs, remittances, etc.)
  • FeatureBudget vs actual tracking with progress bars — amber at 80%, red at 100%
  • FeatureCross-country remittance handling — paired expense/income transactions with live exchange rates
  • FeatureMonthly trend visualization comparing income vs expenses over last 4 months
  • FeatureTransaction form with expense/income/remittance tabs and category selection
  • FeatureBudget category manager — add custom categories, edit icons, delete unused categories
  • FeatureDashboard portfolio and budget widgets with at-a-glance financial overview
  • FeatureExchange rate provider with 5-minute caching and cross-rate computation (AUD/USD/MNT)

Client Feedback & Changelog

New Partner / Co-Earner role for dual-income families, improved button responsiveness across onboarding, and a public changelog page.

v0.8.0Mar 28, 2026
2 features
1 fix
3 total
  • FeatureAdded "Partner / Co-Earner" relationship role for families where both members work
  • FeaturePublic changelog page with timeline, release cards, and stats overview
  • Fix"Launch Dashboard" button now stays in loading state until navigation completes — no more double-tapping

Email Delivery & Auth Hardening

Branded confirmation emails via Resend, duplicate account detection, and registration rate limiting.

v0.7.0Mar 28, 2026
4 features
1 fix
5 total
  • FeatureBranded confirmation email template sent via Resend from verified globfam.io domain
  • FeatureServer-side registration endpoint with confirmation link generation
  • FeatureDuplicate email detection — clear error when account already exists
  • FeatureIn-memory rate limiting on registration endpoint (5 req/min per IP)
  • FixConfirmation emails now land in Gmail Primary instead of Promotions

Profile Photos & Visual Polish

Member profile image upload with drag & drop, client-side compression, and animated topographic patterns across hero cards.

v0.6.0Mar 14, 2026
6 features
3 fixes
10 total
  • FeatureProfile image upload — drag & drop, click to select, client-side WebP compression
  • FeatureReusable MemberAvatar component with 5 sizes, editable mode, and hero variant
  • FeatureAvatar upload API with magic byte validation and Supabase Storage integration
  • FeatureTopographic flow pattern for welcome header with animated contour lines
  • FeatureTwo-line welcome header — personal greeting with family context
  • FeatureUnified add member and invite flow with UI polish
  • FixNormalize email case to prevent duplicate members on invite accept
  • FixUse family_members name for greeting instead of auth metadata
  • FixPointer-events and z-index fixes on hero card overlays
  • RefactorExtracted shared avatar utilities (getInitials, gradients, flags) into single module

Motion, Feedback & Resilience

Animation foundation, toast notifications, skeleton loading states, error boundaries, and branded invitation emails.

v0.5.0Mar 13, 2026
5 features
2 fixes
7 total
  • FeatureMotion foundation — Toaster mount, page entrance animations, reduced-motion support
  • FeatureToast notifications for all user actions (add, edit, delete, invite)
  • FeatureLoading skeletons for all dashboard routes matching component layouts
  • FeatureError boundaries and custom 404 page
  • FeatureBranded invitation email matching landing page design
  • FixEscape apostrophes in error boundary and 404 page
  • FixRemove emojis from invitation email template for professionalism

Family Invitations

Complete invitation system — invite by email, join by shareable code, and seamless onboarding for invited members.

v0.4.0Mar 13, 2026
8 features
1 fix
10 total
  • FeatureInvitation API routes — create, list, revoke, accept, and join by code
  • FeatureInvitation query helpers with Supabase admin client
  • FeatureResend email client integration and invitation email template
  • FeatureInvitation management UI — invite dialog, pending list, shareable code
  • FeatureJoin-by-code page for users with shareable invite links
  • FeatureInvite acceptance page with auth callback integration
  • FeaturePass invite_token through auth flow for seamless acceptance
  • FeatureZod validation schemas for invitations
  • FixLazy-init Resend client and add Suspense boundaries for useSearchParams
  • ChoreUpdate .env.example with Resend environment variables

Core Application

App shell with sidebar navigation, authentication flows, onboarding wizard, family member management, and the overview dashboard.

v0.3.0Mar 12, 2026
7 features
2 fixes
10 total
  • FeatureApp shell — sidebar, header, mobile nav, dashboard and auth layouts
  • FeatureLogin and register pages with auth callback route
  • FeatureMulti-step onboarding wizard with family setup
  • FeatureFamily members API routes, database queries, UI components, and pages
  • FeatureOverview dashboard — welcome header, onboarding checklist, member snapshots
  • FeatureTanStack Query provider and Zustand currency store
  • Featureshadcn/ui installation with core component set
  • FixAddress review issues in auth, onboarding, and members
  • FixPrevent hydration mismatch in welcome header timestamp
  • ChoreCI pipeline with ESLint config and middleware type safety

Infrastructure & Schema

Database schema, authentication middleware, environment validation, and the full testing foundation.

v0.2.0Mar 12, 2026
4 features
1 fix
10 total
  • FeatureComplete Drizzle schema — families, assets, transactions, compliance, goals, audit, exchange rates
  • FeatureAuth middleware — protects dashboard, enforces onboarding completion
  • FeatureSupabase client setup — browser, server, and middleware helpers
  • FeatureAuth, onboarding, and member Zod validation schemas with tests
  • TestUnit tests for currency formatting utilities
  • FixSchema review — add documents table, fix audit_log nullability, add missing indexes
  • ChoreDrizzle config and database connection
  • ChoreEnvironment validation with Zod and .env.example
  • ChoreVitest config with path aliases
  • ChoreInstall foundation dependencies — Supabase, Drizzle, Zod, shadcn/ui, TanStack Query, Zustand

Architecture & Planning

Complete project planning — architecture documentation, technology decisions, user stories, personas, and scope boundaries.

v0.1.0Feb 26, 2026
6 total
  • DocsArchitecture documentation — system overview, ERD, auth specification
  • Docs9 Architecture Decision Records covering all stack choices
  • Docs81 user stories with acceptance criteria across all 6 features
  • Docs3 detailed user personas with usage scenarios
  • DocsNFRs and scope boundaries — v1 vs v2 for all features
  • ChoreInitial project structure with CLAUDE.md and existing docs