Changelog¶
Every release of Consoletium, newest first. The format follows Keep a Changelog and the numbers follow semantic versioning: MAJOR when a customer must act (a breaking change to the API, a setting or a data format), MINOR for new capability, PATCH for fixes.
[Unreleased]¶
Added¶
- consoletium.com (
site/): the marketing site in English, Simplified Chinese and Malay — modules, pricing picker, migration from any system, compliance, an anonymised customer story, blog, demo and contact forms — with screenshots from a demo company. Published to Cloudflare Pages by.github/workflows/site.yml. - Account portal (
portal/, app.consoletium.com): sign up, verify the email, two-step sign-in for owners, choose modules and users, pay by card (Stripe Checkout) or request invoice billing (approved by staff); the Stripe webhook writes what each company may use; a worker creates the company's system; one click signs the owner in. Staff admin for approvals, suspensions, support sign-in, jobs and website leads. English, Chinese and Malay, including emails. Runs as two services on the platform (deploy/PORTAL.md). - Single sign-on into the ERP (
POST /api/auth/sso): a 60-second RS256 token from the portal, single use, for this company only; support sign-ins are audited and show a banner. - The nightly backup also dumps the portal's database.
- Migration from any system. One bundle format (
docs/MIGRATION-FORMAT.md) read by one importer, one reconciliation and one sign-off pack (app/migration/). Connectors write it: Xero and QuickBooks Online (OAuth, read-only), AutoCount and SQL Account (read-only database or their exports), and a mapped-export route for SAP Business One, Odoo, Dynamics, Sage, MYOB and any other system (docs/CONNECTORS.md). - Import centre (Setup › Migration): templates, upload, checks, preview,
import, reconciliation and sign-off pack, for companies loading their own
data. A paid add-on:
addonsin entitlements, licences andADDONS. - Company data export (
app/seed/export_company.py,deploy/export_tenant.sh): every table as CSV, attachments, reports and a manifest, with secrets redacted; requested from the portal, emailed as a signed link, and always taken before an account is archived. - Portal: AI usage on Consoletium's key charged on the next invoice; add-ons bought (or granted by staff); exports; any second currency once priced.
- Site: optional Plausible analytics (cookie-less, CSP generated to match) and a currency switcher that appears when a second currency is priced.
Changed¶
- Bundle discounts are fixed amounts in Stripe, so the charge equals the quoted price to the cent.
- PyJWT 2.15 (fixes PYSEC-2026-4141).
external_refwidened to 120 characters (migration 0013) so connector references fit.
Fixed¶
- Customer and supplier payments now record how much of them was applied; the all-types ageing listed settled payments again as unapplied cash. Voiding a payment still works (its applied amount is not a payment against it) and clears that applied amount.
[0.9.0] — 2026-10-06¶
The first version of Consoletium as a product rather than one company's system. Not yet 1.0: that waits for a second company to close a month-end on it (roadmap stage 4).
Added¶
- Modules. Thirteen sellable modules with dependencies, enforced by the
API (403 naming the module) and reflected in the menus; a screen whose
module is off explains itself.
app/core/modules.py. - Entitlements from
.env(standalone), the account portal (SaaS) or a signed licence file (self-hosted). - Licences. Ed25519-signed licence files with modules, user seats,
expiry and grace; read-only mode after grace or when an account is
suspended; Setup › Plan & Licence;
tools/licence/licence_tool.py. - User seats enforced when creating or reactivating staff users.
- Tenants. Database-per-company hosting: shared PostgreSQL and Caddy,
one backend and job runner per company, provisioning, encrypted backups,
upgrades and deprovisioning.
deploy/. - Country packs for Singapore (GST, F5) and Malaysia (SST, MyInvois
tax types);
seed_basesets up a new company in either. - AI cost control. Every AI call goes through one gateway: on the plan, on the company's own Anthropic key or Consoletium's, capped and metered by purpose; usage on the plan screen and a billing feed for the portal.
- Versioning.
VERSION, this changelog, the version in/api/healthand/api/meta, CI and tagged image builds. - Security. Content-Security-Policy, frame and permissions headers on
every tenant and on self-hosted installs; a request addressed to another
company is refused (421); commercial deployments always start with the
production checks; dependency audits, static analysis, a secret scan and
Dependabot in CI;
SECURITY.md, a customer security statement, a threat model and a penetration-test scope. - Operations. Server bootstrap (
deploy/ops/bootstrap_server.sh), monitoring with alerts on change (monitor.sh), a monthly automated restore drill that checks the ledger balances (restore_drill.sh) anddocs/OPERATIONS.md. - Documentation site for docs.consoletium.com (
docs-site/): the user guide and screen reference generated from the manual sources, plus administration, migration, self-hosting and security pages; published to Cloudflare Pages by.github/workflows/docs.yml.
Changed¶
- Product separated from the original customer: company name, logins,
database name and branding are configuration; the repository is split
into
erp/,deploy/,docs/andtools/. - The demo data is built on the Singapore pack (
seed_demo). - The dashboard's AI review is now metered and capped like the other AI features.
- Sign-in tokens use PyJWT (python-jose removed); React Router 7 and Vite 8.
- The single-company
docker-compose.ymlnow runs the job runner, keeps attachments and the licence in a volume, and serves the same security headers as the hosted service. - The user manual and screen reference describe the item list on Enter Sales Orders / Enter Purchase Orders and the server-calculated totals.
Fixed¶
- Tests and checkers moved into
tests/andtools/run again, anderp <name>finds them. - Supplier ASN screen failed to open; the sign-in screen no longer fails when the password rules cannot be loaded.