WSheet Social

Changelog

WSheet Social release notes — publishing reliability, security, and product improvements.

We update this log with each release wave. For live operational status see status.wsheet.com.

2026-08-23 · Wave 1 — Trust & reliability

Publishing trust surface

  • OAuth connect flows now bind to your browser session to prevent cross-workspace token injection.
  • Reverse-proxy forwarded headers restore HTTPS detection for HSTS, rate limiting, and audit client IPs.
  • Webhook connection lookups are scoped by workspace when the payload includes a tenant identifier.
  • Security page now documents EU hosting, encryption at rest, backups, and deletion on cancellation.
  • Arabic help articles cover platform connection, Instagram business setup, and common publish failures.
  • Status page runbook added for status.wsheet.com; synthetic probe worker stub ships behind a feature flag.

2026-08-20 · Wave 0 — Stop the bleeding

Critical reliability & security fixes

  • Production startup rejects placeholder JWT signing keys and all-zero data-protection keys.
  • Development-only token exposure flags are clamped outside Development environments.
  • Publish failure notifications now include the owner, platform, and actionable provider error text.
  • Publications stuck in Publishing are guarded against duplicate live posts on worker restart.
  • Calendar and publishing actions show API error details instead of generic failure toasts.
  • Publish now and cancel require confirmation in English and Arabic.
  • Docker Compose defaults hardened: production environment, localhost port binding, Redis password required.