================================================================================ RedFamosa — Changelog Self-hosted SMM panel with resellers, automatic order fulfilment and a wallet. ================================================================================ -------------------------------------------------------------------------------- v1.6.0 - 29 August 2026 -------------------------------------------------------------------------------- NEW - License activation. The installer now has a License step: enter the purchase code from your Envato Downloads page and the wizard verifies it and fetches the install data it needs. One purchase code activates one production domain; localhost and *.test staging hosts never count. - Admin -> License screen: see your activation status, re-check it on demand, or release the domain to move the installation to another server. IMPROVED - Existing installations are not interrupted: updating to this version (or any later one, even skipping versions) never asks for a code mid-update. A banner offers activation with a 14-day window before applying further updates and installing add-ons require an active license. The running panel itself is never degraded by license state - and never by network problems: only a confirmed revocation (refund/chargeback) closes those two doors, after a 7-day grace period. FIXED - Panels whose base currency is not USD no longer see the dollar symbol on amounts in Admin -> Payments (Min/Max), Payment Bonuses, Subscriptions, Drip-feed and Transaction Logs, or on the reseller's My Payment Methods page. Every amount now carries the symbol of the currency it is actually stored in; the figures themselves were always correct. -------------------------------------------------------------------------------- v1.5.1 - 27 August 2026 -------------------------------------------------------------------------------- FIXED - Updating from 1.3.x no longer shows a brief server error at the moment the new files are applied: every screen involved in an update (the update screen, the panel layout and the "we are updating" page) can now be rendered safely by the previous version while the switch happens. - The "we are updating" page shown to visitors during an update is now fully self-contained, so it can never fail at the exact moment it is needed. IMPROVED - While the update is applying its files, an admin who browses to another page now sees the "we are updating" notice instead of a half-updated page. The System Update screen itself stays available the whole time. - After an update (both from the System Update screen and from the /update assistant), the PHP opcode cache is reset automatically - on hosts that cache aggressively, this prevents the old version from being served after the files have already changed. -------------------------------------------------------------------------------- v1.5.0 - 27 August 2026 -------------------------------------------------------------------------------- NEW - Ticket badge in the admin menu: an amber counter next to Tickets shows how many tickets are waiting on staff (new tickets and customer replies). It updates live as tickets are answered or closed and stays visible until every ticket has been attended to. The reseller panel gets the same badge for its own tickets. - Email alerts for the operator: a new ticket, a new deposit (both gateway payments and offline deposits awaiting approval) and every new customer sign-up now also send an email to the staff who handle them - so you stay updated without being logged in. All three messages are editable under Admin - Email Templates ("New ticket alert", "New deposit alert", "New sign-up alert"). - Ticket categories manager: define your own categories and subcategories (Admin - Tickets - Categories) and they replace the built-in list on the customer's new-ticket form. Rename, hide or delete them at any time - existing tickets always keep the category they were opened with. With no custom categories defined, the shipped list keeps working as before. - Broadcast (Admin - Broadcast): compose one message and email it to all your customers without publishing anything on the site - ideal for "new payment method", "new services" or maintenance notices. Messages are sent individually (recipients never see each other's addresses), delivery runs in the background, and every past broadcast stays listed with its recipient count. DB - Two new tables (ticket_categories, broadcasts). Both migrations are additive and run automatically during the update. -------------------------------------------------------------------------------- v1.4.2 - 27 August 2026 -------------------------------------------------------------------------------- FIXED - Updating FROM an older version (1.3.x and earlier) through the System Update screen no longer ends in a server error at the moment the new files are applied. The instant after the swap, the still-running old version used to draw the NEW screen and crash on things it never had; that screen now detects the situation, shows "New version applied - reloading", and reloads itself so the new code finishes the database and cleanup steps on its own. If you ever see an error on this screen mid-update, simply reload the page - the update completes itself. - Changing your profile photo now shows the new photo immediately on every screen. Each upload is stored under a fresh filename, so browsers and CDN caches can no longer keep serving the previous picture after a change (admin, client and reseller profiles). -------------------------------------------------------------------------------- v1.4.1 - 27 August 2026 -------------------------------------------------------------------------------- FIXED - The in-app updater now survives hostings that kill the request which swaps the new files into place. If that response is lost, the very next progress tick recognises the files are already on the new version and carries on with the database and cleanup steps instead of stopping with "No staged update found" — and reloading the System Update screen finishes a half-applied update on its own, even when the release has no new database changes. - The moment the new files are applied mid-update no longer renders a reply from mixed old/new code, which could produce a server error on some hostings at the worst possible moment. IMPROVED - After a successful update the applied ZIP is removed from "Available packages" automatically, so a stale Update button can no longer invite a second run of a package that is already installed. -------------------------------------------------------------------------------- v1.4.0 - 25 August 2026 -------------------------------------------------------------------------------- NEW - Automatic cleanup of unpaid panels, with fair warning. The subscription lifecycle now has a proper ending: when a reseller panel is suspended for non-payment (after its grace window), it is kept for a retention period — 30 days by default, configurable via RF_PURGE_SUSPENDED_AFTER_DAYS in .env, 0 disables it — and then permanently deleted by the billing cron. The reseller is warned by email and in-app notification at 14, 7, 3 and 1 days before the deletion date, each warning sent only once, and renewing at any point cancels the countdown. After a deletion the reseller's own login and wallet balance survive (they live on the main site), so they can come back and start a fresh panel. Panels an admin suspended by hand are never touched — only billing suspensions expire. Both warning emails are editable under Settings -> Email templates. - Paid plans can now be contracted directly from "Get Your Own Panel". Existing customers upgrading to a reseller panel are no longer limited to the free tier: every public plan is on offer, and paid plans follow a strict funds-first rule — the review step shows the plan price next to the customer's current balance, the first period is charged from the wallet the moment the panel is created, and if the balance does not cover it the conversion is blocked with an "Add funds first" shortcut instead. Plans with trial days start on their trial, exactly as configured. (The public reseller signup keeps its everyone-starts-free ladder: visitors have no wallet to charge yet.) SECURITY - Closed a loophole on installations that sell only paid plans (no free public tier): a panel created through the public signup with a paid, no-trial plan used to start active with its first period merely "due", which let it operate through the whole grace window without ever paying. Such panels are now created locked (suspended) until the first period is actually paid from the Billing screen — add funds, pay, and the panel activates on the spot. NEW - "Get Your Own Panel" inside the customer dashboard. When the reseller signup is open, logged-in customers see a new sidebar entry where they can launch their own white-label panel on the spot — their existing account and wallet balance carry over, no second registration needed. (Until now the signup page was only reachable by visitors who were not signed in.) The page walks the customer through it: a "How it works" intro, the platform's live plans with their real pricing and features, and a review step that shows the panel name, the full web address and the starting plan before anything is created. Because the upgrade turns the customer account into a reseller account (managed from the Panel area from then on), nothing happens until the customer explicitly confirms — and anyone who prefers to keep their customer account as-is gets a one-click path to register a separate reseller account instead. - Custom comments on the order form. Services of the "custom comments" / "mentions with custom list" type now show a comment box on the New Order page: customers type exactly what they want posted, one comment per line, and the live receipt prices the order by the number of lines. (Previously these services could only be ordered through the API.) - Automatic notification system across the whole panel. Customers now get an in-app notification (and, where it matters, an email) the moment something happens to them, and operators get pinged when the panel needs them — no more refreshing pages to find out: * Support tickets: when staff replies (from the ticket screen or the CRM inbox), the customer instantly receives a notification and an email that deep-link straight into the ticket. When a customer opens a ticket or writes back, the support team is notified. * Orders: placing an order sends a confirmation (in-app + email), and the customer is notified when an order completes, is partially delivered, canceled or refunded. * Deposits: every credited payment — any gateway, or a manual approval — notifies the customer with a receipt (in-app + email), and gateway payments also notify the panel's money managers. * Sign-ups: new registrations notify the staff who manage users. * On a reseller panel, all of the above reaches the reseller (never the parent panel's staff) and links to the reseller's own screens. - Broadcast announcements. Publishing a News item now offers "Notify my customers": every customer of the panel gets an in-app notification linking to the announcement, with an optional "Also send it by email" box. Each announcement can be broadcast only once (editing never re-sends), and the fan-out runs in the background so thousands of customers never slow down the save. Resellers have the same option for their own storefront announcements. - Four new editable email templates in Admin -> Email Templates (category "Orders, Deposits & Support"): Order received, Deposit credited, Ticket reply and Announcement — each with placeholders, live preview and test send, like every other template. - Full right-to-left (RTL) support. Every screen — landing page, client portal, admin area, reseller panels and e-mails — mirrors automatically whenever the visitor's language is marked as RTL in Admin -> Languages. - Arabic translation included out of the box (100% of the interface, Modern Standard Arabic). Enable it in Admin -> Languages; it ships already marked as RTL. - Optional WhatsApp number at sign-up. A new switch (Settings -> Default setting -> "Ask for a WhatsApp number at sign-up" — resellers have their own in Panel Settings) adds an optional WhatsApp field to the registration form. The number shows on the user's row in Admin -> Users, is editable there and in the client's own Profile page. Made for operators whose customer support runs on WhatsApp. IMPROVED - System Update uploads now work on any hosting, no matter its upload limit. Picking the release ZIP no longer transfers anything — you choose the file, see its name and size, and the upload only starts when you press "Upload package". The file then travels in small 1 MB pieces (so a ~20 MB release passes even the strictest 2 MB upload_max_filesize shared hostings, with no php.ini changes), a live progress bar shows the percentage, and when the last piece arrives the server verifies the package and the update starts by itself. If anything goes wrong the screen states the exact reason — not a valid release ZIP, a lost piece, an expired session, or a server refusal — instead of a generic error, and the storage/app/updates FTP route remains available as an alternative. - Honest support branding: the client portal only presents its support chat as "AI Support" (bot avatar, assistant badge, AI welcome message) when an active AI agent is actually configured. Without one, the same chat calls itself plain "Support" and greets as the human team it really is. Nothing else changes — same conversations, same staff. - The red "Report" button on the support screen is now labelled "Create New Ticket" — clients did not realise it opened a ticket. - Chat content (CRM inbox bubbles, conversation previews, internal notes) now lays out each message in its own language direction, so mixed-language conversations read naturally in LTR and RTL interfaces. - URLs, phone numbers and e-mail fields keep their natural left-to-right order inside an RTL interface. - 30 interface strings (payment and integration form hints) that could not be translated before were added to the language files. - Gateway add-ons can now pre-fill a credential when you add a new payment method (e.g. a ready-made webhook secret you copy into the gateway's dashboard instead of inventing one). Editing an existing method still keeps every credential field blank ("leave blank to keep"). FIXED - Updating from 1.3.x through Admin -> System Update could flash a "500 Server Error" dialog right after the new files were applied, leaving the run looking broken (and, on some servers, the database step unfinished) even though the files were already in place. The window between "files swapped" and "database migrated" is now fully covered: the step runner survives the swap, the screen finishes a half-applied update by itself the next time it is opened, and a completed update ends on a freshly reloaded page with a clear confirmation instead of a half-updated one. - Account and panel names can no longer contain links or HTML. A spammer registering as "$1,111 deposit available" showed up as phishing-looking text in the admin dashboard's Latest Users; names with tags or URLs are now rejected at sign-up, on profile edits and on the reseller signup. International names are unaffected. - Landing back from a hosted payment page (Flutterwave, Korapay, Paystack and similar redirect gateways) before the gateway's webhook arrived showed an error page instead of the payment receipt. The deposit is now reconciled with the gateway on the spot and the receipt appears as expected; the wallet was never at risk. - Profile pictures (and other uploaded images: blog covers, payment-method logos, chat-widget assets) could not be changed on installations made from an early package: the web server kept serving stale files instead of the new upload. Updating now repairs the storage link automatically — existing uploads are kept, nothing needs to be done by hand. - Service rates no longer show dead trailing zeros. A whole-number rate on a panel configured for 0 decimals used to read "18,200.0000" — it now reads "18,200", while sub-cent rates such as "0.0049" keep every meaningful decimal. The Settings -> Currency decimals option now visibly governs rate displays as well. - New Order and Mass Order forms no longer overflow the screen on mobile when a service has a long name; the name is shortened with an ellipsis and every field stays inside the card (LTR and RTL alike). - One payment instruction on the Binance manual method was written in Spanish on English installations; it is now properly translatable and ships in English, Spanish and Arabic. -------------------------------------------------------------------------------- v1.3.12 - 22 August 2026 -------------------------------------------------------------------------------- FIXED - Outgoing e-mail (SMTP): sending failed on every installation with 'The "tls" scheme is not supported' as soon as SMTP was configured in Admin -> Settings -> Email. The panel now derives the transport scheme from your chosen encryption (SSL -> smtps, STARTTLS/none -> smtp), so the settings saved in the admin are always the ones used to send. No .env changes are needed - updating fixes existing installations as-is. -------------------------------------------------------------------------------- v1.3.11 - 22 August 2026 -------------------------------------------------------------------------------- One major update carrying everything built since v1.0.2: wholesale pricing so resellers can undercut you and still earn, self-serve reseller signup, add-ons, one-click updates from the admin panel, a notification centre, per-panel languages, a live CRM inbox - and a long list of fixes across the reseller pricing chain, per-panel account isolation and the client experience. UPDATING FROM v1.0.2 - v1.0.2 predates the System Update screen this release introduces, so this one update is applied by uploading the files (FTP or File Manager) and finishing at yourpanel.com/update - the documentation walks through it step by step (chapter 3.9). Every later update can then be applied from Admin -> System Update in one click. NEW - Wholesale pricing: plans and individual resellers take a catalogue price adjustment that can be NEGATIVE, so a reseller can buy below your retail price and undercut you while you still earn on every order. A discount never goes below what your provider charges you - the floor is applied service by service, so nothing you type can make you sell at a loss. - Resellers become a business of their own: visitors sign up for a panel by themselves from a public plans page, resellers connect their OWN payment gateways (Stripe, PayPal, bank transfer, Binance Pay) and approve their customers' transfers from a Customer Deposits screen, and a reseller-only mode closes your direct client area entirely if selling panels is your whole business. - Add-ons: gateways and extensions install from a ZIP under Admin -> Add-ons, keep their own version, settings and database migrations, and survive every panel update untouched. Add-ons can extend the New Order form (extra fields, replaced controls) across the form, Mass Order and the API. Payment gateway add-ons are available separately. - Updating without a shell: Admin -> System Update applies a release ZIP for you (extract, swap with backup, migrate, clear caches, restart the worker), keeps a code backups panel you can restore from, and records an update history of every version the installation has run. Shared hosting without SSH uses the update assistant at yourpanel.com/update. - The package now installs on hosts where the document root cannot be changed (a cPanel domain locked to public_html): extract everything into public_html and the included root .htaccess forwards requests to public/ automatically while refusing to serve files such as .env. - Notification centre: a bell in the header of the admin, reseller and client areas with unread badges, a full filterable history, and alerts for deposits, renewals, trials ending, CRM tokens expiring and more. Pending deposits also show a live badge in the menu. - Languages per panel: each reseller picks which installed languages their panel and storefront offer and the default one; the language a customer picks now follows their account across devices. - Exchange rates that update themselves every six hours from a public market feed, with an optional exchange margin in your favour. No API key. - Home page: five new landing skins (Momentum, Velocity, Franchise, Boost, Neon) and three new blocks - a working sign-in card, a "we accept" payment methods row and a reseller pitch - all managed from the Landing Studio, on your site and on each reseller's. - Plans now choose which payment gateways each tier may connect, and price rounding is configurable (4 decimals by default, per-panel override for resellers with their own providers). - Admin -> Cron Jobs shows a "Process queued messages" task with a one-click "Run now" rescue button. IMPROVED - The CRM inbox behaves like a real chat: conversations open at the newest message, follow incoming messages automatically, refresh every few seconds while open and pause when the tab is in the background. Incoming messages land within seconds even with no queue worker and no cron. - Buying a plan ends in a receipt with the balance left, upgrades are paid up front from the panel's own balance, and self-serve signup contracts the free plan only - nobody can take a paid tier and never pay for it. - Bank transfer instructions are shown at a readable size with one-tap copy for the amount and account. - A reseller signs in on their own domain like everyone else; boundaries between panels are unchanged and covered by tests. - Payment gateway credential fields carry the names the processor actually uses, on your Payments screen and on a reseller's alike. - "Landing Page" and "Client Portal" moved into a "Website" menu group, identical on the admin and reseller sides. FIXED - Connecting Messenger, Instagram or WhatsApp from a reseller panel stalled after approving on Facebook. The flow now always returns to the single registered redirect URI - one URI in your Meta App serves the owner panel and every reseller, with no extra domains to whitelist. - The reseller pricing chain: a commission that reached only half the catalogue, prices with the margin applied twice, catalogues frozen by a rounding change, a first provider import that ignored the panel's commission, and rounding that quietly ate the markup on cheap services (now 4 decimals). The markup you type is now the markup you get, everywhere a price is shown. - Your revenue reports counted a reseller's margin as yours and ignored your wholesale earnings. Orders now record your own profit on the order itself, and orders a reseller fulfils with their own supplier no longer clutter your admin queue. - Per-panel account isolation: password recovery resolves inside the panel the visitor is on, reset links are stored per account, e-mails to a reseller's customers carry the reseller's name, "e-mail already taken" only looks inside the right panel, and nobody can take over a reseller's sign-in by registering their address on the storefront. - The client panel's header search: prices now match what the signed-in client actually pays, partial IDs match, curated-out services stay hidden, and results open in a dropdown that fills the order form. - An expired session shows a friendly "Session Expired" dialog with a one-click sign-in everywhere, instead of a raw "419 Page Expired". - Readability on dark client themes (order receipt, statistics, add funds), landing pages no longer clip their headline on phones, the drip-feed confirmation no longer inflates its figures, invoices print in one currency, a deposit's bonus can no longer show another customer's, and the welcome notification opens a page that exists. DATABASE - This update adds tables and columns (notifications, per-user language, order profit tracking, add-ons, update history). They are applied automatically by the update assistant or System Update; the manual path is php artisan migrate --force, as described in the documentation. -------------------------------------------------------------------------------- v1.0.2 — 13 August 2026 -------------------------------------------------------------------------------- This release is about one thing: every switch, field and dropdown in Settings now does what its label says. We went through all of them one by one and fixed each control that was not connected to anything. Nothing was removed from the product, and no setting you have already saved changes meaning. FIXED — settings that did not take effect · The Currency tab could not be saved at all. Choosing a thousands separator, a decimal separator, the number of decimals, the default markup, the rounding or the conversion rate and pressing Save appeared to work but stored nothing, so the tab always reopened on the previous values. All six fields now save, including a space as the thousands separator. · Settings → SEO did not reach the front page. A meta title and description entered there applied to the FAQ, Terms, blog and content pages but the home page ignored them and kept the title it shipped with. The home page now follows the same settings. If you have filled in the SEO fields inside the Landing editor those still win for the home page; leaving them empty now inherits the site-wide values instead of a fixed text. · The home page did not publish a canonical address, a share image or the indexing preference at all. It now does, from the same Settings → SEO values every other public page uses. · robots.txt ignored the "Allow search engines to index this site" switch. A file shipped with the script was being served instead of the live one, so the switch changed the page tags but never the file a crawler reads. That file is gone and robots.txt now follows the switch. An empty favicon.ico placeholder shipped beside it has been removed too, so a browser follows the icon your Branding settings declare instead of being handed a blank one. · The sitemap and the canonical tags disagreed with each other when a canonical host was configured: the sitemap kept listing the old address. Both now use the host you set. · "Rows per page" only reached about a third of the list screens. Tickets, transactions, staff, deposits, subscribers, subscriptions, domains, languages, news, webhooks, API keys, blacklists, activity logs, CRM contacts, the client's blog and the public service list all stayed on fifteen rows whatever you typed. They now all follow the setting. A few screens whose layout depends on their own page size keep it on purpose. · "Date format" changed almost nothing on screen, and "Timezone" changed nothing at all — dates were printed in a fixed format and in UTC. Both now apply everywhere a date is shown, including invoices and PDF exports, and month names follow the interface language. If a signed-in user has their own timezone set, theirs is used. Stored data is unchanged; this affects only what is displayed. · A reseller switching off "Disable signup" left their own storefront open. Registration on a reseller's domain was decided by the platform owner's switch instead of the reseller's, in four places including the page that actually creates the account. Each panel now decides for itself. · The sign-in page kept offering "Create one" after signups were switched off, and the home page still showed sign-up buttons, even though the registration page correctly turned visitors away. Those links are now hidden when signups are closed. · Analytics IDs were accepted and then silently discarded. A malformed GA4, Google Tag Manager or Meta pixel ID saved without complaint and reported success, but nothing was ever added to your pages. The form now checks the ID against the same rules the page uses and tells you what the correct shape looks like. · The "Enable API" switch did nothing — the public API, its documentation page and the client's API-key screen stayed open regardless. Switching it off now closes all three, and the API key entry disappears from the client menu. · "Auto convert currency" was never applied when importing a provider catalogue; the conversion box always opened unticked. It now follows the setting. · The password rules on the profile screens always read "at least 8 characters" no matter what minimum you had set. They now show your number. · The support e-mail, phone and working hours had nowhere to appear on the default client skin, which does not include the footer that shows them. That skin now shows the same footer as the other two. · The minimum reCAPTCHA and platform-default fields were saved without any validation. They are now checked before being stored. · Reseller brand colours accepted any short text instead of a colour. FIXED — appearance · A quotation mark in the landing page's font setting was written into the page in a form the browser could not read, which made the heading font fall back to a default. Colours, fonts and skin values are now written into the page correctly everywhere, and are checked before being used. CHANGED · Removed the "Orders for average-time calc" field from Settings → Defaults. It was not used by any calculation in the product. No other setting is affected and nothing you have configured changes. · The "Enable API tab" switch is now labelled "Enable public API", because it controls the whole API rather than one screen. -------------------------------------------------------------------------------- v1.0.1 — 13 August 2026 -------------------------------------------------------------------------------- FIXED · Signing in with an expired session no longer dead-ends on "419 Page Expired". A sign-in page left open longer than the session lifetime — or one whose session the server discarded for any other reason — answered the submit with a blank error screen that offered nothing to click. The form now comes back with the e-mail still filled in and a line saying the session expired, and the next attempt signs in normally. The same applies to sign-up and to the password-reset request. · The session cookie name is now written to .env by the installer instead of being recomputed from the application name on every request. Renaming the panel in Settings no longer changes the cookie and signs everybody out, and a name written in a script that cannot be transliterated (Chinese, Japanese, an emoji-only name) no longer produces an unusable cookie name. · The installer no longer mangles a database password that contains a dollar sign followed by a digit — "S3cret$1pass" was written to .env as "S3cretpass", leaving the install unable to reach its own database with credentials the operator knew were correct. · An installation that cannot write its own .env now says exactly that, and which permission to change, on the first page. It used to fail with a generic server error. · The public landing page now uses the favicon uploaded in Settings → Branding. It previously kept a built-in icon whatever the operator uploaded. · The landing page's video player fills its frame instead of collapsing to a strip, and no longer ships pointing at a third-party sample clip: the "Watch demo" button appears once a video URL of your own is set. -------------------------------------------------------------------------------- v1.0.0 — 28 July 2026 — first public release -------------------------------------------------------------------------------- WHAT IT IS A white-label SMM panel you host yourself. You sell social-media services from one or more upstream providers; your resellers get their own branded storefront on their own domain, with their own customers, prices, wallet and support inbox, inside your platform. A six-step web installer sets it up with no terminal. Highlights: · Owner console, reseller console and customer portal, each with its own navigation, permissions and branding. · Money held in DECIMAL(18,6) and calculated with bcmath — never floats. Every balance change is a locked transaction with a signed, append-only ledger entry recording the balance after it. · Automatic order fulfilment against upstream providers, with status polling, drip-feed, refills, cancellations and a circuit breaker that stops calling a provider that has stopped answering. · Public key/action API, compatible with the SMM panel conventions bots already speak, with real idempotency on order placement. · Omnichannel CRM: WhatsApp, Messenger, Instagram, Telegram and e-mail in one inbox, with AI replies and a visual automation builder. · Custom domains per reseller, with real DNS verification. · English and Spanish throughout, light and dark, responsive to 375px. SECURITY · Public API keys are stored as SHA-256 hashes. The columns that held them in cleartext are dropped. An existing key keeps working; nobody — including the platform owner, and including anyone holding a copy of the database — can read one back out. The customer's API screen shows a key once, at the moment it is created, and says so plainly. · Outbound webhooks are checked against a public-address guard before every delivery attempt, not once at save time, because DNS can be repointed between the two. · The base currency of a panel is validated against the currency catalogue and frozen once the panel's ledger has any history. Nothing in the product converts settled balances, so allowing the change would relabel them rather than convert them. · Third-party credentials (provider API keys, app secrets, OAuth client secrets) no longer use password-typed inputs, which browsers treat as credentials for this site — offering to save them and later autofilling the operator's own e-mail and password into a Client ID field. · The installer no longer writes the database password back into the page. FIXED · Inbound CRM messages are de-duplicated by a database constraint instead of a check-then-insert. Two simultaneous deliveries of the same provider event could previously both be stored, which also fired the automation engine and the AI reply twice — answering a customer twice for one message. · The owner's Subscriptions screen filtered on a value nothing ever writes, so it was empty on every install. It now matches the same orders the customer's own subscriptions screen has always shown. · Every destructive action asks with the product's own dialog. It previously used the browser's built-in confirm popup, which cannot be themed, prints the server's hostname in its title bar, and offers to block further dialogs — on a white-label storefront, an unwanted announcement of the machine behind the brand. · Forms and actions refuse a second click while the first is still in flight. Two clicks on "Add funds" were two deposits; two on "Place order" were two orders that the upstream provider billed for twice. ADDED · Admin → Security → Domains. Every hostname claimed across the platform, and the ability to release one. Hostnames are globally unique, so a reseller could claim a name, never verify it, and hold it for ever with no way to free it short of editing the database. · Admin → System → Webhooks. Register endpoints to receive a signed POST on every order status change, with retries and a delivery log. · Admin → Orders → Request refill. Support can now request a refill on a customer's behalf; previously only the customer could, from their own order list. CHANGED · Two permissions were removed from the roles matrix: `platforms.manage` and `api.manage`. Neither guarded anything — there is no platform editor, and the only API control is the switch in Settings, already covered by `settings.manage`. A checkbox that decides nothing is worse than a missing one, because un-ticking it feels like closing a door. · New accounts are no longer given an API key at creation. Keys are stored hashed, so one minted before anybody could see it was unusable. The key is created on the first visit to the API screen and shown there once. -------------------------------------------------------------------------------- KNOWN LIMITATIONS IN v1.0.0 -------------------------------------------------------------------------------- Stated plainly, so nothing here is a surprise after purchase. · NO AFFILIATE PROGRAMME. The database carries a referral column and nothing reads it. There are no affiliate screens, no commission calculation and no payouts. Planned for a later release. · NO IN-HOUSE SUBSCRIPTION ENGINE. Subscription-type services work and are forwarded upstream with their posts / delay / expiry settings, but the RECURRENCE is executed by your provider, not by this panel. RedFamosa does not generate repeat orders on a schedule of its own. · NO PLATFORM EDITOR. Social networks (Instagram, TikTok, …) are created automatically when you import an upstream catalogue. You can organise services with Categories, but you cannot yet rename, reorder, re-icon or hide a network from the interface. · NO PUBLIC BLOG PAGES. Posts and categories can be written and managed in both the owner and reseller consoles; there is no public-facing blog route yet, so published posts are not reachable by visitors. · SSL FOR CUSTOM DOMAINS IS YOUR HOST'S JOB. Reseller domains are verified by DNS and routed by this product, but certificates are left to your hosting control panel (cPanel AutoSSL) or CDN (Cloudflare). The status is displayed; it is not issued here. · TIKTOK AND YOUTUBE ARE NOT CRM CHANNELS. WhatsApp, Messenger, Instagram, Telegram and e-mail are implemented. The other two are not. · TRANSACTIONAL E-MAIL IS MINIMAL. Subscription lifecycle notices are sent. Order, deposit and ticket events are shown in the interface but are not yet e-mailed. An editable template layer is planned. · ROLLING BACK THE API-KEY MIGRATION DOES NOT RESTORE KEYS. Hashing is one-way. If you roll that migration back, every user must generate a new key. This is a decision, not a routine step. -------------------------------------------------------------------------------- UPGRADING -------------------------------------------------------------------------------- Run the migrations. Two of them change existing data: · API keys are hashed in place. Existing keys keep working and stop being readable. Nobody has to reconfigure a bot. · Duplicate CRM messages sharing an external id within a conversation are removed before a unique constraint is added, keeping the earliest of each group — the one whose automations and replies already ran. Then run `php artisan app:seed-permissions`, which adds the new permissions and deletes the two retired ones from existing installs.