Release history
Shop updates
Concise changes that affect requests, payments, reviews, delivery, or privacy.
Valid commission submissions now remain on-page during transport, recover safely after connection interruption, and open only a verified same-origin private workspace after server confirmation.
- Keeps the form visible while a same-origin, no-store submission request is in flight.
- Retains the native form fallback when modern browser transport is unavailable.
- Aborts interrupted browser transport locally and restores the submit control without discarding the draft.
- Keeps the same idempotency key so retrying the unchanged form reopens the original request instead of duplicating it.
- Returns the complete fragment-bearing private-workspace URL through a JSON success contract, verifies the same origin before navigation, and keeps native form fallback unchanged.
- Shows server failure text and the X-Request-ID support reference beside the submit action.
- Clears saved drafts after first-success and duplicate-recovery completion.
- Expands the static public-form and accessibility baseline to 22 controls.
- Keeps settings schema 29 and order schema 11 unchanged.
The commission form now keeps its requirements checklist beside final review, checks reference files before transfer, and handles offline or repeated submission attempts without moving the customer.
- Places the calm requirements checklist inside the final review section instead of the beginning of the form.
- Uses concise requirement names so legal acknowledgements remain readable in the checklist.
- Preflights reference count, per-file size, and supported JPG, PNG, WEBP, or PDF type before upload.
- Shows selected reference count and total size without replacing authoritative server checks.
- Keeps offline submission on the current page with the browser draft intact.
- Locks a valid submission against repeated Enter, double-click, or retry events until navigation completes.
- Adds a ten-second quote timeout, offline guidance, and no-store request behavior.
- Removes forced focus from failed automatic private-link exchange.
- Keeps settings schema 29 and order schema 11 unchanged.
Commission requirements now appear as a calm checklist without forced scrolling, focus movement, or intrusive validity popups, while submission remains fail-safe and accessible.
- Keeps the customer at the current scroll position when required information is incomplete.
- Replaces the assertive error panel with a polite requirements checklist.
- Adds a compact remaining-requirements status beside the submit action.
- Removes forced focus, smooth scrolling, invalid-field links, and custom browser validity popups.
- Avoids repeated live-region announcements while the remaining checklist is unchanged.
- Clears stale invalid state after conditional contact requirements change.
- Adds a source control that rejects reintroduction of forced validation scrolling or focus.
- Keeps settings schema 29 and order schema 11 unchanged.
Critical customer and administrator paths now share consistent keyboard navigation, live feedback, form recovery, touch targets, high-contrast support, and a package-level accessibility baseline.
- Adds skip links and focusable main landmarks across public and administrator layouts.
- Announces current navigation state and makes mobile menus Escape- and focus-safe.
- Adds linked, focused error summaries to critical customer forms.
- Adds live draft, quote, payment, access, notice, and connection status semantics.
- Uses 44-pixel primary touch targets plus forced-colors and reduced-motion safeguards.
- Protects manually entered private tokens and improves interrupted-connectivity guidance.
- Adds a 14-control storage-independent accessibility verifier to CLI and Diagnostics.
- Keeps settings schema 29 and order schema 11 unchanged.
The complete internal commission lifecycle can now be certified through production classes in disposable protected storage before real credentials are entered.
- Runs 64 production-code checks in a separate child PHP CLI process and disposable storage root.
- Covers pricing, idempotency, payment matching, workflow, review, delivery, refund, reversal hold, dispute, webhook, notification, accounting, and signed integrity.
- Shares Midtrans and external-gateway signature rules between live endpoints and the certification harness.
- Uses an owner-only worker marker and random per-run token to prevent accidental simulation in normal operation.
- Verifies live orders remain unchanged and destroys every synthetic record after each run.
- Retains only an HMAC-signed summary bound to the exact release, schemas, and launch configuration.
- Adds certification to Commissioning, Diagnostics, Settings, launch readiness, backup, navigation, and runtime cleanup.
- Upgrades settings schema 28 to 29 while preserving order schema 11.
Business identity, cPanel paths, SMTP, protected credentials, one primary API payment provider, scheduler planning, backup preparation, and launch evidence are now coordinated through one fail-closed administrator workflow.
- Adds one guided Commissioning center for business identity, canonical HTTPS URL, operation environment, cPanel paths, SMTP, and one primary API payment provider.
- Stores SMTP, PayPal, Midtrans, and external-gateway secrets in owner-only protected files with rollback-safe browser rotation.
- Generates the exact PHP CLI, master cron, health, webhook, storage, backup, and key paths without requiring source-code or JSON editing.
- Creates an external backup directory and encryption key without displaying or exporting secret bytes.
- Adds a secret-free commissioning worksheet and a CLI readiness report.
- Refuses environment or primary-provider changes while unresolved provider checkout or recovery evidence depends on the current configuration.
- Requires operational notification transport and monitored-inbox proof for real-money launch instead of allowing a disabled-email bypass.
- Uses post-redirect-get for sensitive commissioning actions to prevent browser refresh from repeating credential or remote-provider operations.
- Rejects truncated, control-character, nested, public-root, or symlinked commissioning paths and reports PHP CLI and recovery readiness only from verified resources.
- Upgrades settings safely from schema 27 to schema 28 while preserving order schema 11 and all protected business records.
The release package, runtime constants, schemas, manifests, and current operator instructions are now verified as one deployment contract before a staged candidate can be activated.
- Corrects the deployment checklist settings-schema reference from 26 to 27.
- Adds a package-level consistency verifier for release version, build, settings schema, order schema, JSON manifests, and current operator documents.
- Adds a CLI-only release-check command that does not load protected storage or create runtime records.
- Rejects staged deployment candidates whose metadata or current deployment instructions disagree.
- Adds release-documentation consistency to administrator Diagnostics.
- Tracks the generated file inventory in the checksum manifest so official staged candidates are not falsely rejected as untracked.
- Keeps settings schema 27 and order schema 11 unchanged without migrating protected business records.
Public growth now degrades deliberately before storage exhaustion, while authenticated provider evidence retains a protected emergency reserve and operational queues stop at explicit recoverable limits.
- Adds a central storage-pressure controller with warning, critical, emergency, and unknown fail-closed states.
- Adds an optional cPanel protected-storage quota ceiling and uses the stricter of verified quota remainder and filesystem free space.
- Pauses new commission intake and large uploads at warning pressure before existing business records are endangered.
- Pauses ordinary customer mutations at critical pressure while retaining a smaller reserve for authenticated provider callbacks and financial recovery evidence.
- Bounds active webhook and notification queues and returns retryable backpressure instead of silently losing new work.
- Keeps duplicate webhook delivery idempotent even when the active queue is already full.
- Adds Resource capacity to administrator navigation, Commissioning, Diagnostics, Operations, and launch readiness.
- Adds protected-storage usage, effective free space, hosting quota remainder, and active queue visibility.
- Rotates verified old encrypted backups before creating the next bundle, then verifies final retention afterward.
- Refuses a backup when the external target cannot hold a complete encrypted copy while preserving its configured reserve.
- Connects resource pressure to maintenance health and the signed post-deployment observation state.
- Fixes delayed rollback compatibility with older source schedulers by using a temporary source maintenance guard and two-phase health verification.
A newly switched release now remains fail-closed through a signed observation window, while a committed release can be rolled back safely within a bounded period only when protected configuration and operational queues remain compatible.
- Adds an HMAC-signed post-deployment stability record bound to the exact version and build.
- Requires several clean CLI maintenance observations across a minimum elapsed time before public service health and intake can become ready.
- Returns an already stable release to degraded state when later maintenance detects schema, package, queue, incident, deployment, transaction, or housekeeping failure.
- Uses five-minute maintenance retries while observing or degraded, then returns to the normal hourly cadence after stability.
- Adds a CLI-only controlled rollback preflight for a committed staged release inside a configurable rollback window.
- Refuses delayed rollback when protected configuration changed after deployment, preventing newer credentials or settings from being discarded.
- Validates the retained source release, PHP syntax, supported order schemas, webhook/email queues, payment recovery, and critical incidents before rollback.
- Freezes runtime writes while restoring the source application and its exact pre-upgrade protected configuration.
- Preserves the reverted target application and candidate-modified configuration for evidence rather than deleting them.
- Runs authenticated source maintenance and health verification before recording rollback completion.
- Adds release stability and controlled rollback status to Deployment, Diagnostics, Commissioning, Settings, health, scheduler, and launch controls.
- Upgrades settings safely to schema 26 while retaining order schema 11 and existing protected business records.
Upgrades can now be preflighted and switched from PHP CLI as signed transactions, with forward-schema rejection, exact protected-configuration snapshots, automatic application/config rollback, and interrupted-switch recovery.
- Adds a CLI-only staged deployment workflow that verifies the candidate outside the public web root before any live directory is changed.
- Requires same-filesystem atomic renames, external protected storage, exact release checksums, no untracked files or symlinks, required files, compatible PHP, and PHP syntax validation.
- Rejects application releases whose settings or order schema is older than protected data already in use.
- Makes older code fail closed with HTTP 503 or CLI exit 3 before it can normalize or rewrite settings and commission records created by a newer schema.
- Records every deployment phase in an HMAC-signed protected transaction and pauses customer mutations during preparation, switching, verification, or required rollback.
- Creates a verified permission-aware snapshot of the complete protected config tree before activating a candidate.
- Automatically restores both the previous application directory and the exact source configuration if candidate maintenance cannot commit authenticated health.
- Preserves failed candidate code and candidate configuration separately for evidence and diagnosis instead of overwriting them.
- Adds a CLI recovery command for interrupted preparation, switching, candidate verification, and rollback states.
- Defers webhook processing and mutating background jobs during a release transition while allowing authenticated callbacks to be stored durably.
- Bounds old configuration rollback snapshots to at least the five newest and 180 days after signed-state verification.
- Adds an administrator Release deployment view with status, commands, schema inventory, rollback paths, and protected snapshot evidence.
Every upload remains pending until CLI checksum verification commits an HMAC-signed deployment state, while unhandled failures receive request IDs and bounded signed privacy-minimized incident records instead of disappearing into generic hosting logs.
- Records every new version/build as pending and requires current-release CLI checksum verification before launch readiness can pass.
- Adds X-Request-ID correlation for web, API, webhook, administrator, and CLI failure paths.
- Stores uncaught exceptions and fatal shutdowns in a signed protected incident ledger without request bodies, cookies, credentials, customer tokens, email addresses, or raw stack traces.
- Deduplicates recurring failures, counts occurrences, validates HMAC integrity, and requires signed administrator audit before typed resolution.
- Blocks launch on a missing or unsafe incident key, damaged incident evidence, or any unresolved critical runtime incident.
- Adds a minimal public health endpoint driven by a fresh successful CLI maintenance snapshot; pending or degraded state returns HTTP 503.
- HMAC-signs deployment and health state with an owner-only protected key; legacy checksum-only state is returned to pending and recommitted by CLI maintenance.
- Preserves recurring resolved evidence with new occurrence IDs, caps open incidents at 1,000 with one critical capacity record, and bounds resolved retention after signature verification.
- Extends redaction to phone-like numbers, network addresses, URL query values, and absolute filesystem paths.
- Extends maintenance, Diagnostics, Commissioning, Dashboard, and Launch controls with deployment and runtime-incident evidence.
- Keeps Settings schema 24 and order schema 11 while preserving all existing protected business records.
Administrators can now configure PayPal API checkout through a protected onboarding flow, review every payment route from one place, and follow deployment-specific cron, backup, and acceptance steps.
- Adds PayPal OAuth and Orders API creation, approval, capture, return, webhook, and status-verification paths.
- Stores the PayPal client secret in a protected file, rolls back failed rotations, and invalidates old credential proof after configuration changes.
- Requires the PayPal sandbox/live environment to match the shop environment before API checkout can become ready.
- Preserves the original webhook event JSON for PayPal signature verification and contains unsupported events safely.
- Adds one payment setup hub for PayPal, QRIS, DANA, ShopeePay, and BCA routes.
- Adds deployment-path, cPanel cron, encrypted-backup, and independent-restore command templates.
- Fixes scheduled provider reconciliation dispatch and atomic payment lookup defects found during the production-path review.
The shop now requires a signed deployment dossier for live payment, workflow, browser, connectivity, and business-policy tests before public intake can open.
- Adds a signed checklist for the production payment lifecycle and complete commission workflow.
- Adds desktop, mobile, keyboard, zoom, screen-reader, and interrupted-connectivity acceptance records.
- Binds approval to the current release, deployment, protected storage, merchant destination, workflow controls, and legal versions.
- Invalidates stale approval automatically after relevant changes or after the configured validity period.
- Preserves every acceptance revision in an append-only signed history and administrator audit.
- Keeps commissions closed until automated server proof and manual deployed acceptance both pass.
Customers can now review a ledger-based receipt, current schedule, and formal complaint record, while the artist receives clearer accounting and delivery controls.
- Adds a customer receipt based on verified payments, refunds, contract changes, and the remaining balance.
- Adds signed production dates, update commitments, completion estimates, and overdue warnings.
- Adds a formal complaint record with an evidence hash, chronology, retention hold, and administrator resolution.
- Adds accounting exports with masked references, separate currencies, exchange-rate references, and recorded provider fees.
- Adds authenticated SMTP delivery through a protected password file while keeping failed messages in the existing retry workflow.
- Improves privacy retention for schedule and complaint records and keeps public pages read-only during ordinary browsing.
Payment changes, refunds, delivery records, private access, and provider callbacks now use stricter transaction checks and clearer recovery behavior.
- Prevents rejected payment or workflow updates from being saved or reported as successful.
- Separates price reductions from payment reversals so a refund cannot create the wrong customer balance or workflow status.
- Rechecks manual payment and refund details inside the protected order lock before committing them.
- Recovers provider callbacks after a crashed worker while allowing only one active processor for each callback.
- Checks protected references, payment proofs, message files, and delivery files against their stored byte count and SHA-256.
- Keeps read receipts outside the permanent commission ledger and expands alerts for settlement, refund, payment hold, and delivery events.
Email delivery and payment-webhook recovery records are now signed, structurally validated, and preserved in protected quarantine when integrity fails instead of disappearing from operational views.
- HMAC-signs notification and webhook records with canonical content hashes and validates state, identifier, provider directory, and filename relationships.
- Preserves malformed, edited, structurally mismatched, or unsafe queue records as raw protected evidence with signed incident metadata.
- Fails closed when the queue signing key is missing or wrong without replacing the key or mass-quarantining recoverable active records.
- Prevents notification identifier collisions and duplicate webhook callbacks from overwriting unreadable or corrupted evidence.
- Adds administrator audit, verified evidence download, typed resolution, dashboard visibility, Diagnostics, Commissioning guidance, and a required launch gate.
- Detects orphaned evidence blobs, unexpected quarantine entries, unsafe links, changed preserved blobs, invalid metadata, and bounded-scan overflow.
- Uses verified queue reads in retention, storage accounting, scheduler maintenance, and webhook exception recovery.
- Preserves the owner-only queue signing key, signed records, and quarantine incidents through encrypted backup and verified restore.
- Rebuilds webhook dead-letter quick flags only after the complete signed inbox validates successfully, preserving existing flags during key loss or corruption.
- Preserves or normalizes owner-only permissions during storage migration and encrypted restore for provider/SMTP credentials, MFA material, and signing keys.
- Makes administrator MFA fail closed when protected MFA files are missing, symlinked, or not owner-only.
The deployed application can now verify its own release files, the master scheduler performs bounded runtime hygiene, and private customer-link exchange has proxy-aware brute-force protection.
- Verifies tracked application files against the packaged SHA-256 manifest and reports missing, changed, symlinked, unsafe, or unexpected executable files.
- Makes current application integrity a required Diagnostics and Commissioning gate rather than relying only on successful extraction.
- Adds independent source and order attempt budgets for private customer-link exchange with Retry-After responses and bounded security evidence.
- Accepts forwarded client addresses only through configured trusted proxy boundaries and evaluates forwarding chains from the nearest trusted edge.
- Runs hourly cleanup for expired rate-limit records, seven-day idempotency records, and stale atomic temporary files without deleting authoritative business records.
- Requires a current signed CLI maintenance heartbeat before launch, proving the one-entry cPanel scheduler is installed and functioning.
- Runs release verification inside scheduled maintenance so post-deployment corruption or unexpected executable uploads become visible during normal operations.
- Raises Settings schema to 24 while preserving existing commissions, credentials, schedules, evidence, proxy settings, and acceptance history.
Pre-launch setup is now consolidated into one guided control center, SMTP credentials use protected storage, and one integrity-checked cPanel scheduler can operate every due background job.
- Adds a Commissioning center that sequences external storage, MFA, operational email, payment credentials, the master scheduler, and signed deployment acceptance.
- Moves SMTP password bytes into a managed chmod-0600 file or an explicit DEFTRIAL_SHOP_SMTP_PASSWORD_FILE path, with rollback-safe rotation and removal.
- Adds authenticated SMTP STARTTLS or implicit-TLS probing, strict certificate verification, capability-aware AUTH LOGIN/PLAIN negotiation, bounded responses, and safer message framing.
- Binds monitored-inbox and deployment-acceptance proof to the active SMTP identity and protected-secret fingerprint so credential changes invalidate stale proof.
- Adds one master cPanel cron entry that runs only due enabled jobs while retaining each job’s independent lock, heartbeat, retry policy, and individual fallback script.
- Rejects unsupported or misspelled scheduler tasks, quarantines damaged scheduler state, and requires an explicit reset before scheduled work resumes.
- Extends strict integer amount parsing across dynamic provider creation, status, refund, and reconciliation paths.
- Introduces encrypted backup schema 3 to preserve owner-only credential permissions and restores legacy schema-1/schema-2 secret paths as chmod 600.
- Raises Settings schema to 23 while preserving existing commissions, payment configuration, schedules, evidence, provider records, and operational history.
Midtrans and external-gateway credentials now use protected file-backed storage, while every material configuration change closes intake until the deep launch preflight passes again.
- Moves Midtrans server keys and external HMAC secrets out of settings.json into protected chmod-0600 files or explicit environment-managed paths.
- Migrates matching legacy plaintext credentials automatically during protected POST or CLI initialization and fails closed on conflicts without deleting either credential.
- Adds one QRIS provider-vault setup area with environment alignment, endpoint validation, safe secret rotation, and rollback after failed settings commits.
- Adds launch and diagnostic checks for plaintext remnants, secret integrity, restrictive permissions, selected-provider readiness, and production storage boundaries.
- Closes public intake after material settings, pricing, payment, or MFA changes and permits reopening only through the deep Launch checklist.
- Uses effective operational readiness for public availability and queue indicators instead of a stale requested-open flag.
- Uses strict integer settlement parsing for dynamic gateways and dimension/pixel safeguards for manual QRIS images.
- Raises Settings schema to 22 while preserving existing orders, payment routes, evidence, and acceptance history.
PayPal API checkout now uses capture-authoritative settlement, configuration-bound commissioning proof, safer customer returns, and explicit refund or reversal containment before credentials are entered.
- Requires a current configuration-bound PayPal commissioning proof before API checkout can create an order.
- Treats only a completed identified capture as settlement; an order-level completed state cannot mark the commission paid by itself.
- Separates buyer cancellation, funding-source decline, pending capture, denied capture, refund, approval reversal, and payment reversal into explicit recoverable states.
- Adds an idempotent provisional payment hold for PayPal reversals so production and delivery stop until exact ledger reconciliation or evidence-supported resolution.
- Closes authenticated refund and reversal webhooks only after the exact provider reference is reconciled, while pending or failed provider operations create durable administrator attention records.
- Prevents invalid order/state requests from consuming the legitimate PayPal return retry budget and keeps verified settlements readable during provider outages.
- Extends the payment setup hub with readiness evidence, safe credential rotation, active-checkout change guards, and environment-managed secret controls.
- Raises Settings schema to 21 while preserving existing payment preferences, commissions, evidence, and provider configuration.
Scheduled work, payment checks, operational email, encrypted backups, and older private links now have clearer proof and safer recovery behavior.
- Shows whether required cPanel scheduled jobs actually ran successfully instead of relying only on saved configuration.
- Adds local ledger checks and fair scheduled verification for enabled dynamic payment providers.
- Confirms that the monitored shop email can receive a real one-time verification message.
- Verifies the physical encrypted backup bundle and a separate restored copy before backup readiness is accepted.
- Backs up large artwork in authenticated bounded chunks while continuing to restore earlier backup bundles.
- Prevents overlapping background jobs and removes private tokens from legacy transcript and file-download navigation.
Long commissions, administrator history, privacy cleanup, public updates, and narrow-screen pages now remain more dependable as the shop grows.
- Keeps long signed commission histories responsive by storing individual events with verified chain heads.
- Fails closed when evidence, administrator-audit, or required two-factor material is missing instead of silently replacing it.
- Extends privacy cleanup to linked payment-intent, webhook, notification, idempotency, and safety records.
- Keeps official software releases visible while preserving administrator-edited public notices.
- Prevents the request form, administrator dashboard, and Settings page from forcing whole-page horizontal scrolling on mobile screens.
- Improves keyboard focus, initial-payment wording, recovery-code entry, and legacy-record compatibility.
Commission requests, payment creation, customer access, evidence, background delivery, and backups now use stronger safeguards against duplicates, interrupted writes, leaked links, and incomplete recovery.
- Prevents browser retries and double submissions from creating duplicate commission requests.
- Keeps payment-provider results in a recoverable intent record until the current commission revision accepts them safely.
- Separates sandbox and production payment records and rejects cross-environment settlement.
- Moves private customer access into a scoped session so ordinary workspace links no longer contain the access secret.
- Adds durable webhook and email queues with administrator-visible retries and dead-letter states.
- Preserves signed history through compact changes and periodic checkpoints instead of repeating the full conversation after every update.
- Adds named administrator auditing, sensitive-action confirmation, two-factor authentication, link rotation, and a readable customer record download.
- Adds portable evidence ZIP export plus encrypted backup and verified restore tools for protected runtime data.
Commission messages, decisions, payments, reviews, and delivery records now receive a signed revision history. Administrators can verify integrity, review repeat-customer history, and export a complete evidence package when needed.
- Preserved the complete ticket conversation instead of silently dropping older messages.
- Added signed revision checks for commission, payment, review, refund, and delivery changes.
- Added a protected administrator export containing the order record, attachments, and verification evidence.
- Added a customer-history view for repeat commissions without creating a public customer directory.
The shop now keeps new requests closed until its required identity, storage, HTTPS, legal, and payment settings are ready, with clearer administrator actions for completing setup.
- Added a verified tool for moving protected shop records outside the public website folder while keeping the previous copy for rollback.
- Storage migration now pauses other write requests during the verified copy and switch, preventing a record from finishing on the former storage path.
- Added retention review that removes expired personal content and files while preserving required payment, refund, license, and legal evidence.
- Incomplete expired-file cleanup now remains visible, can be retried, and keeps request intake closed until resolved.
- Added a launch interlock so request intake cannot open around unresolved required checks.
- Improved the administrator dashboard and diagnostic with direct actions for remaining launch requirements.
- Strengthened outbound payment and service connections to HTTPS only, without redirects, with certificate and host verification.
The shop now supports approved payments through QRIS, PayPal, DANA, ShopeePay, and BCA bank transfer when the artist has configured the relevant merchant account.
- Added dedicated DANA, ShopeePay, and BCA transfer checkout options with exact-amount and merchant-account verification.
- Clarified that QRIS can also be paid from compatible e-wallet and mobile-banking applications.
- Added an administrator editor for concise public shop updates.
- Improved checkout safeguards so unavailable payment options are not offered to customers.
- Updated the Terms and Privacy Notice for the expanded payment and verification workflow.
Payment records, refunds, callbacks, protected files, and administrator alerts were tightened before public use.
- Payment callbacks now use the configured public HTTPS shop address.
- Manual payments require a unique merchant reference, exact amount, currency, and recipient match.
- Protected uploads are checked for unexpected file changes before download.
- Refund records are tied to the payment they came from.
Unfinished commission forms can be restored after a refresh, and the artist has better tools for reviewing unsafe or abusive requests.
- Restores unfinished form fields in the same browser.
- Keeps English as the default with Bahasa Indonesia available from the language switch.
- Adds a clearer request-to-delivery process and optional private ticket.