# Changelog All notable changes to shopdb-flask are recorded here. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). The product version (`__version__`) and the plugin-contract version (`__contract_version__`) are distinct series with independent bump rules; see ADR-007 and ADR-002. ## [Unreleased] ## [0.5.0] - 2026-07-10 First release cut with a version, tag, changelog, and CI. Focused on letting other GE Aerospace sites stand up their own self-hosted instance (single-tenant per ADR-004). ### Added - First-run setup wizard (`/setup`): creates the initial superadmin in-app, configures each plugin (create tables here vs connect your own database), uploads light/dark floor-map blueprints, and seeds starter reference data. - Self-hosted employee directory and USB plugins: in-app management plus CSV import, no external database required. Both ship default-disabled with an enable-time provisioning note. - Dell warranty plugin: real Dell provider, bulk warranty sync, add-warranty from asset pages, PC hero warranty badge, disk-cached Dell API token. - Custom fields, and a two-pane settings shell with tabbed, searchable System Settings and Settings index pages. - Dashboard defaults (visitor-IP to business-unit mapping) for kiosk displays; printer installer endpoint (data plus floor-map positions). - Global toast notifications replacing `alert()` calls. - Multi-stage Docker build that compiles the Vue frontend and ships `frontend/dist`, which Flask serves. - Documentation overhaul: new CONFIG, UPGRADE, and BACKUP-RESTORE guides; reconciled README, DEPLOY, CLAUDE, and ROADMAP. - ADR-007 (product versioning and releases), CHANGELOG, and best-effort Gitea Actions CI (backend tests, naming/style gate, frontend build). ### Changed - Plugin contract (`__contract_version__`) settled at 0.5.0: full plugin import surface exposed via `shopdb.api`, dead search hook removed, and the dashboard-widgets hook wired to a real consumer. - Role-based access control now enforced on write routes, including admin-only guards on dashboard-defaults writes. - Branding, ServiceNow integration, employee-ID pattern, printer hostname template, and floor-plan blueprints are settings-driven and per-site configurable, with GE defaults preserved as shipped fallbacks (branding and floor-plan configurability landed in this release; some consumer wiring continues under Unreleased). ### Security - Dashboard-defaults writes now require admin authorization instead of any authenticated user. - Collector error responses no longer leak exception detail; failures are logged server-side with generic client-facing messages. - Login rate limiting added (IP-based fixed window) on top of the existing account lockout. ### BREAKING - Collector API key must now be sent in the `X-API-Key` header. The api-key-in-querystring fallback has been removed. Update any collector integration that passed the key as a query parameter. See `docs/COLLECTOR-INTEGRATION.md`. [Unreleased]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.5.0...HEAD [0.5.0]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/releases/tag/v0.5.0