Site Changelog

Every update, improvement, and fix shipped to the store.

26.25.0

All notable changes to lucirift.com

September 7, 2026 lucirift

Changed

  • Make the homepage a compact creative hub with direct music, resources, and marketplace links, earlier product picks, tighter supporting sections, and exact account and activity counts.
  • Organize primary navigation around Products, Music, Explore, Community, and Support. Keep custom links accessible when the header switches to its mobile menu.
  • Group footer links into Explore, Community, and Help & Legal, with collapsible groups on phones and expanded desktop columns.
  • Standardize page spacing and headings across customer and staff pages, reduce surface shadows and decorative motion, and narrow long-form reading layouts while retaining configurable colors, fonts, and both themes.
  • Move the product purchase panel ahead of long descriptions on phones, align catalog card actions, add search result feedback and a clear-search action, and keep cart summaries sticky only when they fit the viewport.
  • Add mobile marketplace filter disclosures and section navigation for settings and page customization.
  • Replace staff product and bundle cards with compact management rows, retain labeled actions and permissions, and clarify empty analytics states.

Fixed

  • Add keyboard product ordering, visible save feedback, serialized saves, and persisted-order readback after failed or uncertain saves. Block further ordering if readback fails until it can be reloaded.
  • Keep controls with the hidden attribute out of the layout, including the product-order recovery button.
  • Add linked validation summaries and inline errors to edited support, product request, marketplace, and settings forms.
  • Reduce the mobile chat message area’s minimum height so the composer is easier to reach.

26.24.4

Changed

  • Match MFA and payment handoff screens to the existing authentication backdrop, card spacing, and typography.
  • Align account security and privacy headings with the shared utility-page styling, and place privacy staff navigation in the standard staff layout with the correct active section.
  • Scale long download-page headings for smaller screens.
  • Share file-upload button styling across marketplace and staff forms, and use the theme’s accent foreground for category filters, pagination, badges, music controls, sale banners, and Select2 selections.

Fixed

  • Show bundle product checkmarks when selected and hide them again on deselection.
  • Add visible keyboard focus to switches and selection cards, clarify switch boundaries, and separate the dashboard’s monthly and lifetime labels.
  • Keep disabled inputs and icon buttons visually consistent and offset anchor scrolling below the site header.

26.24.3

Changed

  • Replace the shared page background ring with a subtle accent-colored pentagram that scales with the viewport.

26.24.2

Fixed

  • Exclude executable scripts from Cloudflare Rocket Loader across customer, account, marketplace, support, maintenance, and staff pages. Preserve native script ordering for theme setup, shared controls, and vendor dependencies.
  • Add template validation and rendered-page regression coverage for missing Rocket Loader exclusions and exclusions placed after the script source attribute.

26.24.1

Changed

  • Reorganize profiles with a compact account header, library tabs that own the item counts, and grouped security, privacy, and Discord settings. Keep retention notices visible before the library.
  • Collapse staff product and serial grant forms, improve mobile product rows and long names, and preserve existing account actions and permissions.

Fixed

  • Prevent the tab fallback from recursing on public profiles. Add keyboard tab navigation and accessible panel relationships.
  • Contain and restore focus in profile dialogs, support Escape cancellation, and submit email and transfer forms through browser validation with inline failure feedback.
  • Add populated profile fixtures and isolated browser checks for tabs, dialogs, forms, and private profile states in both themes.

26.24.0

Added

  • Add optional authenticator MFA for local, Discord, Google, and GitHub authentication, with encrypted setup secrets, one-time backup codes, expiring challenges, replay protection, rate limits, and revocable trusted browsers.
  • Add account security, public and account privacy requests, and a permission-controlled staff privacy queue with identity verification, cancellation, response deadlines, delivery retries, retention decisions, and external cleanup evidence.
  • Add checkpointed account erasure with a persisted file manifest, restricted retained records, session invalidation, durable payment reconciliation holds, processing retries, and owner-controlled re-erasure after backup restoration.
  • Enroll newly created accounts in the 90-day retention policy. Purchases, redeemed keys, and staff grants permanently qualify accounts. Add registration notices, account deadlines, reminder delivery, role exemptions, and an owner-reviewed dry run before automatic deletion is enabled.
  • Add shared themed confirmation and input dialogs and toast notifications on signed-in and signed-out pages, replacing native application alerts and confirmations.

Changed

  • Keep generated personal download files associated with their download records for erasure, and prevent late account-owned saves from recreating erased data.
  • Accept Google and GitHub identities in payment records using the user model’s authentication-method contract.
  • Require recent primary authentication and MFA proof for credential changes and provider linking. Password recovery preserves MFA; security changes invalidate older sessions and remembered browsers.
  • Reject sessions for missing or erased accounts and block account activity during confirmed deletion requests.
  • Add disposable MongoDB, HTTP-route, and browser interaction regression coverage for privacy and MFA behavior.

26.23.1

Fixed

  • Lay out navbar notification popout rows with the icon beside the title, message, and metadata column, matching the notifications page instead of stacking the icon above the text. Rows keep aligned label and timestamp positions, truncating titles, and correct alignment for live SSE-prepended notifications. Enlarged the popout icon glyph to match the page’s icon proportion.
  • Added a regression assertion that popout rows use the side-by-side flex layout.

26.23.0

Added

  • Show three randomly selected public products on each homepage load, including current sale prices, free products, and paused sales labels.
  • Add recent music with release dates, upcoming labels, and direct links to tracks in the music library, plus the latest published game servers.
  • Add homepage links to free resources, the community marketplace, and product requests. Show distinct empty and unavailable states when discovery sections have no content or fail to load.
  • Add isolated homepage route and rendering tests for public query limits, dependency failures, pricing, escaped content, and music links.

Fixed

  • Point the homepage scroll arrow to the always-present discovery section when optional features are hidden.

26.22.2

Fixed

  • Keep the Cloudflare widget hidden throughout browser checks so sign-in, registration, checkout, and Discord verification use the store’s custom status and retry controls.
  • Show a custom failure message if a widget requests interaction, without submitting a token or exposing the provider interface. Disable provider retries and feedback UI so retries stay in the custom controls.
  • Clarify that the configured Turnstile widget must use Invisible mode in Cloudflare, and include its privacy addendum on the privacy policy page when enabled.
  • Add browser regression coverage for hidden provider states, failure recovery, and keyboard retries at mobile and desktop widths.

26.22.1

Fixed

  • Bound PayPal business captures to the buyer’s saved provider order, amount, and currency before claiming the snapshot or granting products. Capture retries use a stable provider request ID.
  • Matched coupon codes literally and rechecked expiry, usage, sale products, and bundles in all four checkout providers. PayPal and Stripe fulfillment use saved coupon details instead of mutable session values.
  • Enforced CSRF validation on email changes and session-bound state on Discord sign-in.
  • Removed rejected chat and support uploads, including partial image conversions, while retaining attachments once their messages are saved.
  • Kept personalized downloads specific to each request so buyer identities and attribution nonces cannot cross cache entries.
  • Sandboxed public SVG uploads, disabled raw HTML in shared Markdown, and escaped staff nonce lookup values.
  • Removed private email editing fields from public profiles and restored SMTP test certificate verification.
  • Added isolated security regression tests, browser checks for nonce rendering and SVG execution, and a local SMTP certificate check.

Changed

  • Pending PayPal business checkouts created before this update must be restarted because they lack a saved provider order binding.
  • Raw HTML in Markdown content now displays as text. Standard Markdown formatting and information containers remain supported.

26.22.0

Added

  • Generate public/sitemap.xml after database startup, check after content saves and every minute, and replace the file only when public URLs change.
  • Include public products, categories, posts, showcases, requests, servers, marketplace pages, and enabled GitHub portfolio pages while excluding hidden, draft, archived, and private content.
  • Advertise the sitemap through /robots.txt, preserve the previous file on generation failure, and retry unavailable builds automatically.
  • Added isolated sitemap tests and operational documentation covering visibility, pagination, scheduling, file replacement, limits, and recovery.

26.21.1

Fixed

  • Corrected chat attachment middleware so message submissions parse their content and reach the save handler instead of hanging until the browser timeout.
  • Added isolated HTTP regression tests for text and image-only submissions, invalid attachments, empty messages, muted or missing members, CSRF rejection, and database failure.

26.21.0

Added

  • Added persistent owner-only maintenance mode with a separate CSRF-protected Store Settings form, fresh access checks, uncached status responses, and a standalone page in both themes. Maintenance defaults to disabled.
  • Restricted maintenance sign-in and recovery to configured owners while preserving existing customer sessions and carts. Active tabs check access every ten seconds, and non-owner event streams close when maintenance starts.
  • Added isolated page rendering, responsive browser review, maintenance, authentication, payment-return, and theme contrast regression coverage.

Fixed

  • Replaced the PayPal Standard confirmation spinner and reload loop with a themed pending page and explicit retry. Confirmed returns resolve the payment associated with the signed-in customer’s snapshot. The PayPal handoff now uses the shared theme and escaped fields.
  • Repaired marketplace creator, listing, and staff statistics loops that failed Eta rendering with populated content.
  • Prevented long product names from widening the mobile cart. Restored keyboard focus when closing mobile navigation and respected reduced motion for scrolling.
  • Added missing field labels in staff and game-status forms, improved accent and status text contrast across themes, and provided music playback and like-save failure feedback.
  • Kept the maintenance control available when Discord settings choices cannot load, with independent save feedback.

26.20.8

Fixed

  • Replaced double-escaped bullet entities in the five PayPal, Stripe, and Coinbase credential placeholders with actual bullet characters. Saved credentials and blank-field save behavior are unchanged.
  • Added rendered Eta tests covering saved and unset credential placeholders, password input types, and prevention of credential prefilling or disclosure.

26.20.7

Fixed

  • Kept protected checkout buttons disabled until their submit handlers are attached, and attached those handlers immediately instead of waiting for DOMContentLoaded.
  • Excluded cart consent initialization from Rocket Loader, retained consent when the security handler loads late, and prevented checkbox changes from unlocking an active security check.
  • Made a failed Cloudflare script load retryable, bounded script loading to 15 seconds, and prevented submission after consent is withdrawn.
  • Clarified the cart’s missing-token message without assuming that the customer blocked Cloudflare.
  • Added an isolated Playwright checkout check using the actual cart templates and scripts, intercepted payment requests, and mocked Cloudflare responses. It covers all four checkout endpoints, token and CSRF handoff, missing or delayed initialization, load failures, retry, timeout, consent changes, and disabled protection.

26.20.6

Fixed

  • Distinguished rejected PayPal credentials, rate limits, API errors, timeouts, and network failures in service health checks instead of labeling every failure as an unreachable API.
  • Added bounded PayPal health requests and cleared provider-specific health caches when payment settings change.
  • Excluded the shared Turnstile initializer from Cloudflare Rocket Loader on every protected form, added versioned client loading, and repaired missing response fields or optional status controls before submission.
  • Refined notification popouts, toasts, and the full notifications list with calmer unread treatment, clearer content hierarchy, compact metadata, stronger keyboard focus, and versioned assets.
  • Added regression coverage for PayPal health classification, Turnstile initialization, and notification presentation.

26.20.5

Changed

  • Replaced the footer’s hardcoded white payment tiles with larger theme-aware payment marks that retain their existing light-mode treatment and use a cohesive dark-mode surface.
  • Consolidated the cart’s repeated Turnstile notices into one shared security status above the payment choices while preserving payment-specific validation actions.

Fixed

  • Made Community Chat submissions restore the Send button on every outcome, show active progress and accessible errors, time out stalled requests, and reuse message IDs safely when retrying.
  • Closed notification streams in background tabs, added bounded reconnect backoff, and stopped per-user stream limits from producing repeated 503 responses.
  • Added regression coverage for footer payment theming, chat submission recovery, notification stream lifecycle, and the shared cart security status.

26.20.4

Fixed

  • Restored product view statistics to the existing per-product record format, preserving imported counts and metadata while using atomic array updates for product creation, views, and deletion.
  • Prevented the shared product and marketplace galleries from widening grid columns beyond the mobile viewport.
  • Excluded the Google Analytics and Tawk.to loaders from Cloudflare script rewriting, and gave the Tawk.to loader a stable serialized configuration source.
  • Added regression coverage for existing statistics records, narrow shared galleries, and integration script loading.

26.20.3

Fixed

  • Stored game status icons under portable /uploads/game-status/ URLs with one optimized WebP extension, collision-resistant names, bounded dimensions, and cleanup for replaced or deleted files.
  • Repaired legacy absolute game status icon paths when rendering existing records.
  • Matched the game status icon pickers to the established staff upload control styling.
  • Supplied and normalized the active game server manager tab so /servers/manage no longer fails with tab is not defined.
  • Added regression coverage for game status icon paths, upload control styling, and the game server tab local.

26.20.2

Fixed

  • Registered the game server manager routes before the public server slug route so /servers/manage no longer resolves as a missing listing named manage.
  • Added route-order regression coverage for the game server manager and public listing routes.

26.20.1

Fixed

  • Prevented Turnstile from adding a second cf-turnstile-response field, which caused a completed green challenge to be rejected as missing.
  • Added server compatibility for identical duplicate response fields from cached clients while rejecting conflicting or malformed token values.
  • Added regression coverage for the Turnstile response-field contract and duplicate-token normalization.

26.20.0

Changed

  • Reorganized the desktop and mobile Community navigation into Discover, Participate, and Latest groups, with a compact desktop panel and bounded mobile scrolling.
  • Added Arrow key, Home, End, and Escape behavior with focus restoration to shared dropdown menus.

Fixed

  • Made CSRF tokens available before multipart parsing on game status, game servers, announcements, music, resources, and support upload forms.
  • Added missing CSRF headers to support attachment messages, typing updates, and profile product transfers.
  • Added template validation and regression tests that reject POST forms without readable CSRF protection, including multipart forms that rely only on hidden fields.

26.19.0

Added

  • A dry-run-first resource port tool that transfers legacy resource records, hosted downloads, and card banners from Ricochet into LuciRift-Studio.
  • Resource port safeguards for schema normalization, source and target identity, unsafe paths and URLs, missing media, filename collisions, existing records, credential redaction, and failed-write file cleanup.
  • Focused tests for resource metadata preservation, legacy text limits, URL and path validation, database credential handling, media discovery, and collision-safe destinations.

26.18.1

Fixed

  • Centered music play controls over cover art and synchronized each card’s play or pause icon, pressed state, and accessible label with the shared audio player.

26.18.0

Added

  • A dry-run-first Node tool for porting music track records, audio files, and cover art from the old Ricochet database and repository into LuciRift-Studio without storing connection credentials in the command.
  • Music port safeguards for source and target identity, schema validation, bounded track counts, missing media, filename collisions, existing records, credential redaction, and per-track file cleanup after failed writes.
  • Focused migration tests covering arguments, database labels, record preservation, path validation, legacy media discovery, and collision-safe filenames.

26.17.3

Fixed

  • The Discord Verification staff page now renders its outcome filter without triggering Eta’s inline-array parsing edge case.
  • Discord channel, role, verification record, and attempt lists now fall back to empty collections when Discord data is unavailable.
  • Template validation now rejects unsafe inline array iteration inside Eta tags before it can become a runtime rendering failure.

2.15.0

Added

  • A persistent 24-hour cooldown for each user, product, and product version. The server claims the cooldown atomically before preparing the download, so double-clicks and parallel requests cannot start duplicate transfers.
  • Download-page cooldown states with immediate button locking, remaining-time labels, automatic re-enabling, and exact availability times after a reload.

Changed

  • Product downloads now use CSRF-protected form submissions. Legacy direct download links return to the product’s download page.
  • Download access and file availability are checked before cooldowns, records, or counters are changed. Preparation failures release only the lock created by that request.

2.14.0

Added

  • Owner-managed Cloudflare Turnstile protection for local sign-in, registration, PayPal, Stripe, Coinbase, and Discord verification, with encrypted secret storage, server-side action and hostname checks, bounded retries, and accessible browser progress states.
  • Discord account linking and member verification with eligibility checks, durable role grants and revocations, automatic reconciliation, privacy-minimized attempt auditing, configurable retention, a publishable Discord panel, and a dedicated staff permission and workspace.
  • Persistent per-product view counters stored with site statistics and shown on product cards and product details.
  • A live footer visitor count, site version badge, and compact overall service status linked to the full status page.

Changed

  • Showcase descriptions now support safely rendered Markdown on detail pages and clean plain-text excerpts on showcase cards.
  • Disabling Turnstile now disables Discord verification and queues website-managed verified roles for removal.

2.13.4

Fixed

  • Rebuilt the staff product Discord role selector with wrapping role chips, one aligned remove action per role, responsive search space, keyboard focus treatment, and a cleaner multi-select dropdown.

2.13.3

Fixed

  • Reduced and realigned the product gallery image controls in staff create and edit forms, with compact geometry, consistent spacing, visible focus, and clearer disabled states.

2.13.2

Fixed

  • Improved the home-page About Us card with preserved authored line breaks, readable 16-pixel typography, and complete visual treatment for Markdown headings, emphasis, deleted text, lists, and long content.

2.13.1

Fixed

  • Kept the home-page review marquee filled from edge to edge at wide viewport sizes, including when only a few reviews are available.

2.13.0

Added

  • A Community Marketplace with public search, filters, sorting, pagination, listing details, creator profiles, external purchase links, seller support details, and dedicated Marketplace Terms.
  • Seller Center tools for permanent creator profiles, current-terms acceptance, draft and published listings, flexible pricing, verification applications, profile status controls, and signed-in reporting.
  • Verified and unverified seller labels with clear trust disclosures. Marketplace verification confirms reviewed public identity evidence and does not endorse a seller or listing.
  • Marketplace staff tools for ordered categories, seller and listing moderation, verification review and revocation, report resolution, user notifications, and staff action logs under the new Marketplace permission.
  • Marketplace banners and galleries using the shared product carousel, with one banner and up to 32 additional optimized images, multi-file previews, removal, drag and keyboard ordering, thumbnails, swipe controls, and the full-size viewer.

Changed

  • Product browsing now groups visible items into their configured product categories, with section headings, live item counts, and search behavior that hides empty category sections.
  • Product and marketplace galleries now share the same storefront viewer and staff upload controls while preserving existing product behavior.
  • Public marketplace pages now participate in the approved language, Google Analytics, and Tawk.to integrations. Seller Center, reporting actions, and staff management remain private surfaces.

2.12.0

Added

  • Owner-managed Google Analytics 4 and Tawk.to integrations with validated identifiers, immediate loading on approved public storefront pages, and explicit exclusion of private, account, checkout, support, and staff surfaces.
  • A 21-language public storefront switcher backed by MyMemory, with persistent preferences, bounded translation caching, UTF-8-safe request chunks, right-to-left support, dynamic-content translation, and complete keyboard navigation.
  • An editable AI Policy with safe Markdown rendering, current legal-page styling, last-updated metadata, navigation links, and page title customization.

Changed

  • Rebuilt the GitHub Portfolio with a full-width profile summary, six-stat strip, accessible contribution graphic, compact language overview, responsive two-column repository cards, and server-side search, visibility filters, and 12-item pagination.

2.11.1

Fixed

  • Balanced the product-card View and Add to Cart controls with equal widths, a shared height, and single-line labels at narrow card widths.

2.11.0

Added

  • Public announcement index and detail pages with search, pagination, safe Markdown rendering, cover images, draft publishing controls, and homepage highlights. The existing one-off user notification broadcast remains available separately.
  • Public video showcase index and detail pages with privacy-enhanced YouTube embeds, linked products, featured ordering, view counts, homepage highlights, and staff management.
  • Product galleries with up to 32 additional optimized images, staff upload and reordering controls, thumbnails, keyboard and swipe navigation, and a full-size image viewer.

Changed

  • Added Announcements and Showcase links to desktop, mobile, footer, and staff publishing navigation.
  • Product image uploads now validate JPG, PNG, and WebP files up to 8 MiB, use collision-resistant names, and remove replaced or deleted product media.

2.10.0

Changed

  • Aligned all 30 staff pages with the public storefront shell, spacing, layered background, card treatment, and responsive content width.
  • Replaced the second sticky staff header with a compact, permission-aware workspace card beneath the public navbar. The current staff area remains visible, desktop groups use the existing dropdown pattern, and mobile groups remain expandable.

Fixed

  • Gave the public and staff mobile navigation independent controls so both menus open, close, announce their state, and dismiss without duplicate element IDs or cross-targeting.

2.9.1

Changed

  • Reorganized the staff navigation into permission-aware Catalog, Operations, Publishing, and Administration menus. Desktop uses compact dropdowns, while mobile uses scrollable accordion sections with the current area highlighted and expanded.
  • Added the GitHub Portfolio manager to the staff navigation and improved its menu buttons with current-page semantics, visible expansion state, and specific mobile open and close labels.

2.9.0

Added

  • Google and GitHub sign-in with owner-managed encrypted credentials, live strategy registration, verified-email account creation, account-link collision checks, banned-account rejection, and provider-specific login feedback.
  • Customer profile-picture uploads for JPG, PNG, WebP, and GIF files up to 5 MB, converted to bounded WebP avatars with a self-service remove action. Custom, Discord, provider, and default avatars now resolve in a consistent order across profiles, navigation, download history, staff user views, and chat snapshots.
  • Discord alerts for new product versions, serial-product restocks, low stock, cart additions, successful logins, and web-server errors. Alerts support dedicated channels, optional role pings, bounded embed content, safe mention controls, store branding, and error deduplication with rate limiting.
  • Abandoned-cart reminders with owner-configurable timing, in-app notifications, optional email delivery, and one reminder per stale cart period.

Changed

  • Staff Settings now includes Discord alert channels and roles, low-stock and cart-reminder thresholds, an error-log destination, and Google and GitHub login configuration.
  • The public GitHub Portfolio navigation entry appears as soon as the portfolio is enabled and published. Before the first successful sync, the route now shows a preparation page instead of a not-found error.

2.8.0

Added

  • Public Product Updates page at /product-updates: a reverse-chronological timeline of every product version changelog, visible to everyone, not just product owners. Includes a product filter, a “My products only” scope for logged-in customers, version pills, release dates, Markdown changelogs, and pagination. It reads the same embedded product versions that the staff Update Product flow already writes and announces to owners.
  • Music page at /music with a custom sticky player: filterable discography (All, Current, Upcoming, Legacy), track cards with cover art, play counts, and like buttons, and a bottom player bar with play/pause, previous/next, seek, persisted volume, auto-advance through the visible tracks, and media-session (hardware key) support. Staff with the new canManageMusic permission upload and manage tracks (MP3, WAV, OGG up to 100 MB with WebP cover art) from a new Staff Panel page. The Track schema and audio storage layout replicate the live store exactly (same tracks collection, audio streamed from /music/<file>), so existing song databases work as-is.
  • Community Game Servers at /servers: owners list their game servers with a logo, Markdown description, Discord invite, join link, and a Public or Whitelist-only access type; publishing is a completeness gate rather than a staff approval. Each server page shows its news feed (News/Update posts with dates and Markdown), and whitelisted servers swap Join for Apply to Join. The manager at /servers/manage handles drafts, edits, publishing, archiving, restoring, and per-server news with the same lifecycle. The FiveMServer and FiveMUpdate schemas replicate the live store’s collections (fivemservers, fivemupdates) for database compatibility. Managed through the new canManageFiveM permission, which owners can grant to trusted community members on the Team page.
  • GitHub Portfolio at /github: a public engineering page built from a GitHub snapshot with a profile card, lifetime totals (repositories, contributions, commits, pull requests, reviews, stars), a 12-month contribution heatmap, languages in use, and a searchable repository ledger with public/private filters. Background sync runs through the GitHub GraphQL API on a configurable interval (15 minutes to daily) with encrypted multi-token support, an atomic sync lease, rate-limit-aware retries, and a 30-second read cache; the last complete snapshot stays visible (with a “snapshot delayed” banner) whenever GitHub is unreachable. Configured owner-only at /staff/github: username, interval, enable/publish toggles, fine-grained PAT management with live validation, Sync Now, and per-repository visibility. GithubStatsConfig and GithubStatsSnapshot replicate the live store’s collections.
  • Navigation: the Community dropdown gains Music, Product Updates, Game Servers, and a conditional GitHub Portfolio entry; the mobile menu and footer Community columns mirror the additions; and staff navigation gains Music, Game Servers, and GitHub Portfolio links.
  • New granular staff permissions canManageMusic and canManageFiveM with checkboxes in the team add and edit forms and permission badges.

Fixed

  • Navbar dropdown menus rendered underneath the Staff Panel bars on staff pages because both sticky shells shared the same stacking order. The site header now sits above the staff panel, so every dropdown (Community, Status, Legal, notifications, user menu) paints over it.

2.7.0

Added

  • Resources page at /resources: staff-curated free tools, scripts, and downloads with banner images or icons, category filter chips with counts, live search, download counters, and a redirect/download endpoint (/resources/go/:id) that streams hosted files or opens external links. Staff manage resources from a new Staff Panel page (gated by the content-team permission) with banner upload, hosted file hosting up to 100 MB, edit, and delete; every mutation posts a Discord audit log entry.
  • Site Changelog at /changelog: public release notes with version pills, dates, authors, and Markdown bodies rendered server-side. Staff write entries from a new Staff Panel page with a summary, a Markdown editor, and a draft/publish flow (publishing stamps the date; unpublishing clears it).
  • Product Requests at /product-requests: a public suggestion board with search, status and category filters, Popular/Newest sorting, and pagination. Logged-in users submit requests (title, category, optional https reference link, description) and upvote or withdraw support atomically. Staff moderate inline on the request page: move requests through Submitted, Under Review, Planned, Added, or Not Planned with a status history timeline, link the released product when marking a request Added, and delete requests. Status changes notify the request author through the notification system and every staff action posts a Discord audit log entry.
  • Community Chat at /chat: a live single-room chat over Server-Sent Events with in-memory presence (online and recently-offline member lists, typing indicators, 25-second heartbeats, eight-second offline grace, two-hour stream recycling, three streams per member, and 2,000 connections store-wide). Messages support up to 2,000 characters and four images per message (8 MB each, converted to WebP) behind a 1.2-second per-member cooldown and a 100 MB daily attachment quota, with retry-safe client message IDs. Staff (new canManageChat permission) delete messages as tombstones and mute members for 10 minutes to 7 days with a reason; muted members see a banner and cannot send. All images are served through an authorized, path-guarded endpoint.
  • A Community dropdown in the desktop navbar (Resources, Site Changelog, Product Requests, and Community Chat when logged in), a matching Community group in the mobile menu, Community links in the footer, and Resources and Changelog pages in the staff navigation.
  • New granular staff permission canManageChat with checkboxes in the team add and edit forms and a Chat label in the staff permission badges.

Changed

  • The desktop navbar was reorganized to stay roomy as the site grows: Reviews moved into the Community dropdown (Reviews, Resources, Product Requests, Community Chat, Site Changelog), the legal-only dropdown is now named Legal, and primary links show icons only below the extra-large breakpoint with accessible names. Verified overflow-free from 1024 px to 1920 px; the mobile menu mirrors the new grouping.
  • The Product Requests page header moves the New Request button into the filter bar so the page opens with one aligned action row.
  • The footer now lays out Brand, Navigation, Community, and Legal as one balanced five-column row instead of wrapping the legal links under the brand column.

Fixed

  • Changelog entries and the profile service modal rendered nothing because Eta’s raw-output tag is <%~ %>, not <%- %>; both now output their HTML.

2.6.0

Added

  • Redeem system at /redeem: logged-in users enter one code, and the store checks its own gift codes first, then falls back to Jinxxy license keys.
  • Redeem gift codes: staff generate codes (8-character, one product per code) on a new Staff Panel page with quantity up to 100 per batch, configurable uses per code, and optional expiry. A code grants its product to the redeeming account, can be limited to a single use (one account per use), tracks every redemption, and can be deleted later.
  • Jinxxy key redemption: when enabled in Staff Settings with an encrypted Jinxxy Creator API key, the redeem page also accepts Jinxxy license keys (full UUID or short key). The store looks the license up through the Jinxxy API, matches its product name to a store product (exact name, case-insensitive), grants the matching product, and records the license ID so each Jinxxy key works exactly once. Unmatched products are refused with a contact-support message and the key stays unused.
  • Every successful redemption creates a zero-total invoice (transaction ID prefix REDEEM-, PDF generated), sends the user an in-app notification of the new redeem type linking to the invoice, posts a Discord audit log entry, and grants the product’s Discord roles the same way checkout does.
  • Redemption history on the redeem page listing each user’s redeemed products, codes, and dates.
  • New granular staff permission canManageRedeemCodes with checkboxes in the team add and edit forms, a Redeem Codes link in the staff navigation, and a Redeem entry in the user and mobile menus.
  • Staff Settings gained a Redeem & Jinxxy section with the enable toggle and the encrypted Jinxxy API key field.

Fixed

  • The Discord roles multi-select on the product create and edit forms rendered as an unreadable white dropdown: Select2’s hardcoded light theme is now restyled to match the site’s dark and light tokens.
  • Applying a discount code in the cart crashed with “recommendedBundles is not defined” because the discount route re-rendered the cart without that variable. Bundle recommendations are now built by one shared helper used by both cart renders, and the recommendations section stays populated after applying a code.
  • The Top Customers card on the staff overview showed “undefined” for email-registered accounts; the query now fetches usernames and falls back through Discord username to username.
  • Owner shortcut links on the product page (Update Product, Edit Product) used a barely visible ghost style and now use the visible secondary button style.
  • The profile Products tab was rearranged: the Add Product to User and Add Serial to User controls have aligned, full-width inputs with matching buttons, and owned products render as full-width rows with a product-type label and right-aligned actions instead of a ragged half-width grid.

2.5.0

Changed

  • Primary navigation reorganized with dropdown menus: Home, Products, Reviews, and Support stay as direct links, a Status dropdown holds System Status and Game Status, and a More dropdown holds the legal documents with labeled groups. The mobile menu uses the same grouped structure, and opening one dropdown now closes the others.

Added

  • Real-time system status page at /status: overall banner, Store API group (Dashboard uptime, Database ping with latency, Server Load with a live bar), and a Services group (Discord Bot, Stripe, PayPal, Coinbase, Email) with per-service latency pills and Operational/Degraded/Down states. The page polls /status/live every 8 seconds and patches itself without refresh; probe results are cached so visitors never wait on network checks.
  • Status incidents: staff can open, update with timeline entries, resolve, and delete incidents (owner only). Active incidents appear on the status page and automatically affect the overall banner; resolved incidents show under Past Incidents.
  • Game status board at /game-status: game groups (GTA V, FiveM, and whatever staff configures) with tracked products and detection statuses (Undetected, Updating, Working / Testing, Working / Risky, Major Outage), summary tiles, status filter tabs with search, N/N clear badges per group, product links, and a report-issue footnote linking to Support and Status.
  • Staff editors (owner only) for incidents and the game status board: group and item management with icons, positions, visibility, product links, and optional icon image uploads. Every mutation clears the public cache and posts a Discord audit log entry.
  • License Terms page at /license-terms and Refund Policy page at /refund-policy, both markdown documents edited in Staff Settings like the Terms of Service, with automatic Last Updated dates and footer links.

2.4.0

Added

  • Support ticket system: customers can open tickets with subject, category, priority, message, and image attachments (JPG, PNG, WebP, GIF, max 4 per message and 5 MB each), view their tickets with status filters, reply in a realtime chat, request a human agent, and close or reopen tickets.
  • Ticket chat updates in real time over a per-ticket Server-Sent Events stream with new-message, typing-indicator, and ticket-status events for both the customer and staff views.
  • OpenRouter-powered AI first-line agent: auto-replies while a ticket is unassigned and has no staff replies, escalates to the team when it cannot help (via a deterministic handoff marker the server strips), stops permanently on a ticket once a staff member replies, and gives up after three consecutive AI replies. Configured in Staff Settings with an encrypted API key, model id, and system prompt.
  • Staff helpdesk: ticket queue with stat tiles (open, awaiting customer, unassigned, high priority), status and unassigned/mine filters, subject search, pagination, a ticket view with realtime chat, assign-to-me, status and priority controls, and an AI draft-reply assist that never posts without staff review.
  • Support notifications (bell badge, popout, notifications page) for customers and staff on ticket activity, plus an email to the customer on staff replies when email sending is enabled.
  • New granular staff permission canManageTickets with checkboxes in the team add and edit forms, a Tickets link in the staff navigation, and a Support link in the customer navigation.

2.3.0

Added

  • In-app notification system with per-user notifications stored in MongoDB.
  • Notification bell in the navbar with an unread count badge and a dropdown popout listing the latest notifications, an in-popout mark-all-read action, loading, empty, and error states, and a link to the full page.
  • Live toast popups: new notifications arrive in real time over a Server-Sent Events stream, appear as stacked toasts below the navbar, and can be dismissed or clicked through to their link. The stream reconnects and syncs missed notifications, and stops retrying after repeated failures.
  • Full notifications page with All and Unread tabs, unread styling, relative timestamps, mark-read on open, per-item delete, mark-all-read, and windowed pagination.
  • Notifications are generated for order confirmations across PayPal, PayPal Standard, Stripe, and Coinbase checkout, new product versions for users who own the product, staff announcements, and account security events (ban, unban, email change requests).
  • Staff Announcements page at /staff/announcements for broadcasting a title, message, and optional internal link to all users, with a recent broadcasts list showing recipient and read counts.
  • New granular staff permission canSendAnnouncements with checkboxes in the team add and edit forms, and an Announcements link in the staff navigation.

Changed

  • Staff navigation strip no longer scrolls horizontally; links wrap inside a rounded panel so every page is visible without a scrollbar.
  • Profile page redesigned to match the current page patterns: the hero banner card was replaced with a clean page header (avatar, name, badges, joined/spent/auth summary, ID copy), a three-tile stat strip, and a single workspace card with a tab header bar and bordered inner rows for products, serials, and invoices. All inline onclick handlers were replaced with event listeners, service product details now render from server-side markdown (removing the markdown-it CDN script), tab states expose aria-pressed, Escape closes modals, and the transfer button shows a loading state.