- Customer accounts now require email verification (hashed, single-use,
time-limited tokens) before they can request/confirm bookings, with
resend flows on login/account/booking widget and rate limiting.
- Admins get a private, rotatable iCalendar (ICS) subscription feed of
their confirmed bookings and public events, timezone-correct for
Europe/Berlin including DST, never exposing meeting passwords.
- Adds a full SEO layer: per-page canonical/OG/Twitter metadata with
CMS-editable overrides and content-derived fallbacks, a dynamic
sitemap.xml and robots.txt driven by real published content, JSON-LD
(Organization/LocalBusiness, WebSite, WebPage, BreadcrumbList, Service,
Event, BlogPosting) that never fabricates data, and a CMS-managed
redirect table for changed slugs.
- Global ANOUMA-naming audit: the brand name is never used to label
personal account/calendar areas anywhere in the app, CMS, or emails.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- setup.sh: interactive/non-interactive one-shot installer (build, DB
healthcheck, migrate, seed, start), idempotent secret generation, NPM
reverse-proxy network auto-detection and optional join, optional
AUTO_UPDATE cron install.
- update.sh: release-tag-gated updates only (never bare main), DB backup
with retention before every update, lock file against concurrent runs,
automatic code rollback on failed post-update healthcheck.
- Dockerfile: multi-stage build, non-root user, built-in HEALTHCHECK against
the new /api/health route, wholesale COPY so new source dirs (e.g.
scripts/) never silently go missing at runtime.
- docker-compose.yml: internal anouma-network (configurable), named volume
for Postgres, app depends_on postgres healthy, no unnecessary published
ports; docker-compose.override.yml.example documents joining an existing
NPM network without ever touching NPM itself.
- Fix host-detection: isHost was Boolean(user), wrongly granting host
privileges to logged-in customers; now checks user.collection === "users".
- Wire configurable STUN/TURN servers through to the WebRTC client
(lib/meeting/iceServers.ts) so a TURN server can be added later via env
vars only, no code changes.
- DEPLOYMENT.md, updated README.md and .env.example documenting the whole
flow: NPM integration, env vars, WebRTC, updates, backups, rollback.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>