Back to changelog
Fixed

Rolino fixed changes

Page 1 of 11. Each page contains at most 30 entries so agents and people can read it without a large context load.

  1. Current

    The landing page's agent setup is now always visible. Its setup prompt, copy button, and guide link are readable in light and dark mode.

  2. Current

    Landing page visitors can now open navigation and log in on mobile or skip to the content with a keyboard. Product previews now use consistent supported channels and clearly mark example content.

  3. Current

    Agent recovery now reports contract version 0.20.0 and accepts ISO 8601 publication times with explicit UTC offsets.

  4. Current

    YouTube now accepts completed public videos before changing schedules. Delivery refreshes preserve pending schedule approvals, and due checks share worker capacity across platforms. Missed private schedules require a new publication decision.

  5. Current

    Publishing connections now replace stale health results after reconnecting and clear resolved connection errors without starting a new upload.

  6. Current

    Manual-only delivery checks now stop after they return an unresolved result, and saved deliveries with a removed connection return a clear reconnect action.

  7. Current

    Post destination badges now remain stable when sorting changes the card order.

  8. Current

    Brand Studio now asks for connection attention only after an actionable provider failure or when scheduled work depends on an unavailable channel. Optional disconnected channels and normal access-token expiry with a refresh path no longer appear as broken, while expired connections without a refresh path still require attention.

  9. Current

    The desktop month calendar now gives every week enough room for complete post cards, scrolls instead of compressing crowded months, and shows every event with its destination and scheduled time from the **+N more** list. Week view now keeps its time-grid scrollbar hidden until the user points into or focuses the scrollable area. Agenda view now fits its surface to the visible rows and contains long event titles within the available width instead of leaving a large blank area or adding a horizontal scrollbar. On small screens, Agenda now uses grouped day sections with readable times and two-line event titles instead of compressing the desktop table.

  10. Current

    Media cleanup workers now bind every deletion to the confirmed workspace, project, asset, storage identity, and asset version. Changed files are skipped without contacting storage, and browser deletion retries now appear in pending storage without double-counting stored media.

  11. Current

    Storage reports and cleanup previews now use consistent database snapshots, API media routes have database-backed filter and isolation coverage, packaged and remote MCP tests execute every storage-cleanup operation, and Tiptap 3.31.2 removes the reported production dependency advisory.

  12. Current

    Agent Media Library cleanup now respects read-only workspace entitlements during preview and confirmed execution, keeps cleanup history when expired idempotency records are removed, records replay, rejection, worker, and final outcomes, and fully describes media filters and status pagination in OpenAPI.

  13. Current

    Hosted storage now counts adjusted Instagram and LinkedIn images, keeps transformed-file bytes reserved when browser or agent post edits replace media until object deletion succeeds, and atomically rejects upload completion when its reservation expired or capacity changed. Pricing structured data now exposes monthly and annual offers together.

  14. Current

    Workspace Billing and Media Library now show a consistent storage bar and stored usage for uncapped legacy and self-hosted workspaces instead of hiding the storage row.

  15. Current

    Hosted storage limits now include reserved uploads during admission checks, count only stored files in customer usage, cover generated Blog images, and release Media Library capacity only after object deletion succeeds.

  16. Current

    The preregistered CLI now keeps valid OAuth resource links for each deployment and repairs a missing link on the next authorization request, so a local process cannot break production CLI sign-in.

  17. Current

    SEO opportunity listing and detail reads now expose only canonical public tasks, skip incompatible internal detector rows without failing the complete request, and keep pagination correct when raw findings exist.

  18. Current

    Verified native OAuth clients can now use a temporary port with an exact `localhost` callback, so clients such as Claude Code can complete browser authentication without widening the registered scheme, host, path, or query.

  19. Current

    Repository secret scans now exclude two exact non-secret test labels without weakening scans for other values or files.

  20. Current

    Production dependency installs now use patched URL parsing and MySQL driver versions required transitively by the application, authentication, and database toolchain, so the high-severity package audit passes.

  21. Current

    Remote MCP now creates credential rate-limit buckets only after authentication from the verified workspace grant, so fake bearer values cannot create unbounded database rows. Old request-limit rows and unused anonymous OAuth client registrations now expire through bounded maintenance, while active connections remain valid. Codex CLI 0.152.1 is the verified minimum and 0.145 is clearly unsupported.

  22. Current

    Concurrent platform feature grants now resolve as one idempotent grant instead of sometimes failing on their unique workspace boundary. The command palette also ignores malformed keyboard events before reading shortcut keys, and shared interface state now updates without cascading effect renders.

  23. Current

    OAuth consent now removes only stale consent records that have no matching active workspace grant, while keeping valid connections. OAuth and remote MCP requests now use shared bounded rate limits, and database tests prove cross-user isolation, cross-workspace isolation, scope enforcement, and immediate revocation. Codex URL-only setup can now register a safe native public OAuth client through the rate-limited standard endpoint without a host-specific client record.

  24. Current

    Removing the obsolete host-specific MCP OAuth client now also revokes its active workspace grants, clears pending consent selections, and keeps deployment readiness tied to the latest database migration.

  25. Current

    CLI and remote MCP browser authorization now show the complete opt-in capability list, so users can grant draft and scheduling access instead of receiving an unavoidable read-only connection. Hosted Codex setup now uses native Codex configuration and OAuth discovery, keeps protocol initialization public, and challenges protected tool discovery at `tools/list`. Agent setup names the two permissions required to prepare and schedule social posts.

  26. Current

    Create Post now uses the project's last explicit destination choice from browser or agent drafts, preserves existing project choices during migration and saved empty choices afterward, falls back to its only connected account on first use, and removes disconnected destinations during duplication and automatic checks.

  27. Current

    YouTube connection now replaces a stale local callback address with Rolino's configured public address in production, so onboarding cannot send users to `localhost`.

  28. Current

    Weekly Blog plan checks now save a complete proposal set atomically and show health only when the completed job matches the exact active plan revision and week.

  29. Current

    Weekly Blog plan checks now use each opportunity once, fail visibly when a selected proposal cannot be completed, and reject duplicate topics, expired evidence, changed page evidence, and incompatible work types before acceptance.

  30. Current

    Blog performance recommendations now require exact-page evidence for page-specific signals; only the query-spread detector can use an observed query-to-page relationship.