Changelog
Releases
Every version of Yuva and what changed in it. Versions follow Semantic Versioning, and until 1.0 any release may change the API and the database schema.
Added3
Bulk actions
Select conversations in the list (checkboxes, shift-click for a range, select all on the page) and close, reopen, snooze, assign, unassign or label them at once. One
POST /v1/conversations/bulkcall for up to 100 conversations; the ones the caller cannot change are listed with the reason and stay selected.Contact merge
Owners and admins merge two contacts of the same person, for example the e-mail one and the in-app one (
POST /v1/contacts/{id}/merge). The target gains the source's addresses, external ids, attributes and conversations; the source is deleted andcontact.deletedcarriesmerged_into_id.Move a conversation to another inbox
(
POST /v1/conversations/{id}/move, shortcutm): replies continue on the target inbox's channel, an e-mail conversation is refused when the target has no e-mail channel, and the timeline shows "Moved from …". New realtime eventconversation.moved.
Added4
Workspace deletion
Owners delete a workspace in the panel (Settings → Workspace → Danger zone) or with
DELETE /v1/workspace; it stops working at once and a background job deletes its data and stored files in batches. Operators useyuva workspace delete.Account deletion
Members delete their account in the panel (Settings → My profile) or with
DELETE /v1/me, refused while they are a workspace's only owner; their messages stay, shown as from a deleted member. Operators useyuva person delete.Panel
Replies from a visitor's typed, unconfirmed address are marked "Unverified sender".
Android SDK on JitPack
implementation("com.github.productdevbook:yuva:v0.0.2")fromhttps://jitpack.io; the local module still works.
Changed1
A person who belongs to no workspace can sign in, sees that, and can delete their account.
The first public release. Pre-alpha: do not put real customer data in it yet.
Added14
Server
One Go binary with Postgres, applying its own migrations on start; River jobs in the same process; attachments and raw e-mails on local disk or S3-compatible storage;
/healthz,/readyzand Prometheus metrics. Docker image forlinux/amd64andlinux/arm64.Workspaces and members
Owners, admins and agents with per-inbox access; sign-in with e-mailed codes and passkeys; invites; workspace API keys; usage counters.
Inboxes, contacts and conversations
Per-inbox branding, language, time zone, business hours and
liveorasyncmode; messages, notes, attachments, assignment, status, priority, labels, canned replies, events and the/v1REST API for all of them, described inopenapi/openapi.yaml.Agent panel
Conversation list with filters and search, thread view, composer, contact sidebar, settings, realtime updates over WebSocket, English and Turkish; installable as a PWA.
E-mail channel
Signed
/ingress/emailfed by a Cloudflare Email Worker (edge/, with a fallback address when the server is unreachable) or by any MTA throughyuva ingest-email; threading, quote stripping, HTML sanitizing, attachments and raw message storage; outbound SMTP per channel with thread headers; loop protection; bounce and complaint handling, including Amazon SES notifications.Catch-all e-mail channels
*@example.comreceives every address of a domain that no other channel has, and replies go out from the address the contact wrote to.Volume without bounces
A sender opens at most 20 new conversations per channel per hour; further mail joins their latest conversation. Only senders above
YUVA_EMAIL_SENDER_HOURLY_CAPare refused.Web widget
The
<yuva-chat>web component for live chat and embedded threads, on the/client/v1API with contact sessions, anonymous visitors, identity tokens signed by the host backend, allowed origins, presence, typing, read receipts and e-mail continuity for unread replies.Mobile SDKs
sdk/swift(YuvaKit) andsdk/kotlinwith a client, conversation list, thread, composer and feedback form.Feedback and webhooks
Feedback conversations with metadata, posting by API key, Standard Webhooks delivery with retries and a delivery log, contact deletion by external id.
`sdk/go`
Identity token signing and webhook verification for host backends.
Member notifications
Web Push with per-member preferences and e-mail fallback.
Retention
An optional per-workspace period after which closed conversations and raw e-mails are deleted.
Operator commands
yuva bootstrap,migrate,api-key,inbox,channel,vapid-keys.
Security1
Hardening of sign-in, sessions, client sessions and identity tokens, inbound mail and outbound connections, attachment handling, rate limiting behind proxies, and the panel's security headers. Report vulnerabilities as described in
SECURITY.md.