Insites Docs Change Log

Change Log

Date Period

Ecommerce v5.12.0

October 05, 2026

New Features

  • Products and Categories now have an Event Stream tab showing every change, with a details drawer for each event
  • Event Details drawer consolidated across Orders, Products and Categories, with a Copy Log button and delete events recorded
  • An events discount can now be restricted to specific event tickets, and Usage Count is editable after create
  • Products and variants now carry net price and unit tax, including on CSV import
  • Product Image can now be toggled as a column on the Products list
  • Choosing a contact who already has a cart now warns immediately instead of failing on save

Improvements

  • Out of Stock Action replaces Website Display on products and variants, and is available through the v2 API
  • Delete confirmation is now consistent across every screen that deletes a record
  • Ecommerce custom field data sources are grouped, with broken table references corrected
  • Display Fields drawer no longer offers toggles that change nothing, and its content no longer flashes in

Bug Fixes

  • Deleting a product now deletes its variants, including on bulk delete, so their SKUs can be reused
  • Checkbox options no longer overlap, tooltips sit beside their labels, and label colour and weight match radio options
  • GET /ecommerce/api/v2/discounts no longer fails with a function tag error
  • Filter chips no longer show raw UUIDs, Keywords accepts multiple values, and Category filters use the right input for every condition
  • Corrected Usage Limit and Discount Type wording, and added the missing Discount Value error message
  • Import Products drawer no longer flashes its content before loading

Breaking Change

  • A cart is now unique per contact. GET /carts/{uuid} looks a cart up by contact_uuid, and creating a second cart for the same contact is refused

Assets v5.3.0

September 25, 2026

changelog image

Breaking Changes

  • The external GET /asset/api/v2/assets listing endpoint now requires an instance API key. External integrators must send their instance API key on this endpoint or the request will be rejected.

New Features

  • Added asset data charts to the Reports page, covering storage growth, file type breakdown and the largest folders.
  • Assets now record their file size at upload. Existing assets are backfilled automatically in the background, so storage figures become accurate without any manual step.
  • File size is now shown in the assets list and in the file details panel.

Improvements

  • Rebuilt the asset upload experience. The upload limit is raised to 600MB, failures are reported instead of failing silently, progress and the remaining limit are visible, and uploads now run concurrently and can be cancelled.
  • Rebuilt the Reports page to a new design, with clearer storage units, full folder paths and improved charts.
  • Parent folders now use the folder icon, matching sub-folders.

Security

  • Asset names are now escaped everywhere they are displayed, and the image preview has been hardened.
  • Closed a case where browsing folders could reveal the names of files outside the folder being viewed.

Bug Fixes

  • Fixed File Name search returning no results.
  • Fixed "Up one folder" not working from a top-level module folder.
  • Fixed folder tree indentation collapsing at deeper levels.
  • Fixed the folder tree accordion icon only toggling once, and appearing on folders with no subfolders.
  • Fixed the folder tree incorrectly highlighting the root folder after a search or refresh.
  • Fixed a folder placeholder appearing as a blank file row.
  • Fixed a flash of unstyled content on the initial All Assets page load.
  • Fixed the "Updated By" spinner hanging when an administrator could not be resolved.
  • Fixed File Size and Last Updated font-size inconsistency in list view.
  • Fixed direct asset links carrying a duplicated cache parameter.

CRM v5.15.0

September 25, 2026

changelog image

New feature

  • Contacts advanced filter can now filter by profile membership and by fields inside a contact's assigned profiles
  • Contacts table Display Fields can now show profile fields as columns, plus a new "Profiles" column listing the profiles a contact holds
  • Profile "Media - File" / "Media - Image" fields can now actually be uploaded and saved, not just displayed
  • CRM Relationships now carry a start and end date-time, so a relationship can record when it began and when it ended

Security

  • Bump the global axios loaded by insites_core's shared admin layout and external CRM activity scripts from EOL 0.x releases to 1.19.0
  • Pin previously-floating CDN dependency versions and add Subresource Integrity (SRI) hashes to insites_core's dependency partials
  • Regenerating the instance API key now always returns a complete key, and a generation that cannot produce one is rejected rather than overwriting the key you already had. If you regenerated your instance API key on 5.14.x, regenerate it once more after upgrading and update any integration that uses it
  • Add an upload_restrictions schema and a shared validate_upload function, so file-upload limits are declared once and enforced consistently
  • Add the verified sha512 Subresource Integrity hash and crossorigin to the moment.js tag on the Event Stream view

Improvements

  • Every nested object reference in the CRM v2 external API now returns id alongside uuid and its reference label, on every method
  • CRM date range filter pills now render in the instance's Localization date format instead of always showing ISO YYYY-MM-DD
  • Contacts list Birth Date column now follows the instance Date Format
  • Time-type field pickers now follow the instance Time Format (12/24hr)
  • Companies list gains combined Phone 1/2/3 and Mobile Phone columns
  • Companies export gains the address advanced-group filter, and Contacts/Companies exports now show readable values beside their UUID columns
  • The Delete Company modal now shows the real record counts for what will be removed

Bug fixes

  • GET /insites/core/administrators/:uuid now returns 404 for an unknown or malformed uuid instead of 200 with an empty result set
  • Fix the Custom Fields sidebar Edit button on Company and Contact profile pages opening the Documents tab instead of Custom Fields
  • Fix the Company Tasks tab Date Range filter rendering a broken, cut-down picker instead of the full calendar
  • Cancel the orphaned WebSocket connectivity-check timer on Instance Configuration unmount
  • Fix Data > Reports, Settings > System Logs and the Import Database Items file-attach step failing to render for some users with "Error Loading Components". Every shared component tag now carries a cache-buster, and the cache-buster is no longer fetched over the network at page-render time where a timeout silently dropped it
  • Fix linked-record custom fields showing blank when the linked record has no name
  • Fix the Contact and Company Event Stream tab always returning zero events, stop add_event leaking into the response body on 36 unwrapped v2 external API endpoints, and guard it so a blank Event Stream response cannot throw ParseJsonTagError
  • Fix advanced filters being silently dropped when the sort order includes a non-base field
  • Write is_archived: false explicitly on every Contact create path, so new contacts cannot be created in an indeterminate archived state
  • Fix the Delete Company confirm input never re-enabling after the record counts finish loading

Pipelines v5.10.2

September 18, 2026

changelog image

Improvements

  • Add Task Due Date advanced filter for opportunities
  • Convert parent-relative imports to @/ aliases; wire sass-loader mixin injection (styling-skill audit safe slice)
  • Add referring company field (lead_referred_by_company_uuid) with 5-section form regroup
  • Add live thousands-separator masking to currency fields
  • Pre-fill Company/Contact on Add Opportunity from a CRM entry point
  • Attach a quick-added Company/Contact to the Opportunity form
  • Show name (email) across all Pipelines person dropdowns
  • Add Quick Selection group to contact/administrator dropdowns; show name (email) format
  • Add opportunity activity rollup toggle and attach affordance
  • Add opportunity Event Stream tracking for 9 approved gaps
  • Replace Company/Contact text labels with icons on opportunity Board card

Bug Fixes

  • Fix locale/ISO date mismatch causing the Task Due Date filter to always return 0 results
  • Fix report charts using dark-mode colour tokens in light mode
  • Fix archived referring company still showing name in opportunity export
  • Fix currency mask clearing Value/Sales Target Value fields on blur
  • Fix opportunity custom fields API — null definitions, unvalidated selects, silent no-op writes; scope custom_field response to its own pipeline
  • Fix geojson custom-field spelling mismatch nullifying custom_field response
  • Fix Target Conversion Date labels and day-count off-by-one
  • Fix doubled plus sign in constructPhoneNumber
  • Wrap long SubHeader titles instead of truncating with ellipsis
  • Fix Task drawer Due Date calendar running off the viewport
  • Fix excess gap between Activities toolbar and list content
  • Fix Link custom field wrapping on opportunity Board card

Platform Update - Error responses

September 16, 2026

changelog image

Improvement

  • Error responses keep the page's content type: A page that sets its content type, from its format or via {% response_headers %}, no longer has an error rendered afterwards re-negotiated against the Accept header. Unrecognised formats render as text/plain, and errors on .js pages return a JSON string literal so the browser never parses an error message as script.

  • Clear response when an instance has no object storage: Requesting a presigned upload URL used to return nothing, and sync reported a failed fetch. The endpoint now returns 501 with a direct_upload_unavailable error, and the CLI falls back to uploading assets through the instance.

  • Host-relative asset URLs with local storage: When an instance serves its own assets from disk, asset_url now returns a host-relative URL instead of pointing at a CDN that never received the files, or raising when no asset host is set. Instances using a CDN are unaffected.

Bug Fix

  • Dynamically cached pages without a layout: A page combining dynamic_cache with layout: "" rendered on the first request and then failed on every cache hit. Pages that declare no layout are now served from cache as-is, which fixes cached sitemap.xml pages.

  • Redundant Liquid context on cache hits: The layout no longer builds a second Liquid context and reparses the layout value on every dynamic cache hit.

  • Partner Portal URLs on non-default ports: An instance registered against a portal on a non-default port dropped the port, so later token validations went to the default port and surfaced as a plain 401. Local setups and private stacks were affected; production was not.

  • Swapped exception names in low-level error logs: IP spoofing attempts were logged as missing-parameter errors and vice versa. The 403 and 406 statuses returned were already correct.

Data v5.7.1

September 15, 2026

changelog image

New Features

  • Show the resolved display value beside the identifier for every data source field in the Database Items export.
  • Link single-value data source cells in the Database Items list through to the linked record, matching the item details view.

Bug Fixes

  • Default the Platform API v2 list page size to 10 instead of the number of query parameters sent.
  • Follow the admin theme rather than the device theme in the Address field's Google Places autocomplete.

Platform Update - Stricter YAML parsing

September 09, 2026

changelog image

Breaking Change

  • Stricter YAML parsing: The YAML parser now rejects unsafe input instead of silently rewriting it, so three patterns that used to deploy will now fail. A file carrying one of them has been deploying a value other than the one it reads, so this is worth checking before you upgrade.

    • :draft — a leading colon. Remove the colon.
    • !ruby/object:Foo — delete the tag declaration.
    • *missing — an orphaned alias. Make sure a matching anchor exists.

    Standard YAML features are unaffected: anchors, aliases, merges and dates all continue to work.

Bug Fix

  • JSON error responses for unparsable bodies: A request sent with Content-Type: application/json whose body is malformed now receives a structured JSON error, {"status":400,"error":"There was a problem in the JSON you submitted: ..."}, instead of plain text. Other content types still receive a text response, now with an explicit Content-Type: text/plain header.

API v5.4.0

August 27, 2026

changelog image

New Features

  • Custom API Endpoints can now be managed over the API: create, list, get, update and delete them under /insites/api/v2/endpoints, gated by the instance API key. Every endpoint must carry at least one authorization policy (no public-by-omission), the slug and file path are namespace-validated, inputs are allow-listed, and each change is recorded in the event stream. Documented under the new API section in the API docs.
  • The Instance API Key policy can now be selected on the Authorization Policies dropdown when configuring a Custom API Endpoint.
  • Documented the error response standard on the API Overview page — the error envelope fields, plus per-item results and success/fail/total counts for bulk ("Add Multiple") endpoints.
  • Documented the GeoJSON serialization standard — GeoJSON values are sent as JSON-encoded strings and returned as parsed JSON objects.
  • New "Controllers" section on the API Overview — what a controller is, how to call one with {% function %}, and when to use a controller instead of the HTTP API. Includes explicit guidance for AI assistants so generated on-instance Liquid uses controllers rather than HTTP calls.
  • Endpoint documentation now renders a Controller Contract section (stability, returns, errors, and silent failures) for any controller that declares a contract in its front matter, in both the HTML docs and the Markdown export.

Improvements

  • Example HTTP and Controller requests are now rendered in read-only code editors, and the Copy Request button copies the exact raw text.
  • Authorization header examples now use the {API_KEY} placeholder consistently across every endpoint and module.
  • Renamed "GraphQL Name" to "Display Name" on the Add and Edit GraphQL pages.
  • Updated the cancel button icon on the Custom API Endpoint pages.
  • Removed unused total counts from internal GraphQL queries.

Bug Fixes

  • Bulk ("Add Multiple") endpoints now display their real array-of-objects request example instead of a placeholder or a single object.
  • Appending .md to a documentation URL now redirects to the real Markdown version instead of returning HTML with a markdown content type. Fixed the CMS, Forms, Permissions, and Stripe reference sections rendering another module's content.
  • Controller request examples now pass the payload with the correct params: params named argument, so the example is copy-paste-valid.
  • cURL examples now escape apostrophes correctly, so a copied command runs as-is instead of breaking at the shell.
  • The Markdown documentation now shows a literal & in cURL example URLs and example data, instead of an HTML-escaped &.
  • The API Overview now documents the search, sort, and pagination defaults accurately: defaults are noted as resource-specific rather than universal, and a dotted search field (e.g. company.name) is documented as returning an error.

Events v5.6.0

August 26, 2026

changelog image

New Features

  • Add event financial reporting: Revenue/Expenses/Net P&L/Margin % columns on All Events, a Financials tab with a Highcharts waterfall, a Net P&L header chip, and a per-user Ex-Tax/Gross toggle.
  • Redesign the event detail page on an operations-first layout: header with operational counters and countdowns, left-column summary cards (Reference, Venue), and a horizontally-scrolling tab rail.

Improvements

  • Group Event Details tab fields into logical sections.
  • Add Archive path to Reassign drawer empty-states.
  • Document nested file keys on Event upload/gallery, Speaker image, Sponsor logo, and Expense attachment/invoice fields.
  • Add explicit error-message prop to Canonical URL field.
  • Add id to nested object refs in Events API v2 example responses.
  • Default list columns now include Revenue, Expenses, Net P&L, and Margin % between Event Start Date and Status.

Bug Fixes

  • Fix silent image upload failures, missing Android Camera option, and reactive-Proxy/gallery-uuid upload bugs.
  • Fix orphaned commas/spaces in PDF ticket venue address.
  • Normalize Events datetime fields to ISO 8601 UTC, reject naive input, and fix a Liquid syntax error in validate_datetime_fields.
  • Remove unused total_entries selections from Events GraphQL queries.
  • Fix URL validation.
  • Hide Link/Password fields for venue events and add URL validation parity with CRM Company Website.
  • Restore pricing tier archive/restore/reassign feature.
  • Fix pricing division migration data loss and non-idempotency.
  • Remove dead pricing field references from event_pricing_division GraphQL that always resolved to null.
  • Guard pagination totalCount against undefined to fix a recurring console error across Speakers, Sponsors, Venue Contacts, System Fields, and other list pages.
  • Fix event import silently discarding ticket prices, and silently discarding whole pricing divisions when venue/area info is missing; prevent duplicate divisions on re-import.
  • Fix event detail page timezone, pagination, and stale-validation bugs; correct day/hour countdown boundary math; show Net P&L/Margin % as neutral/0% instead of red or a dash at zero.
  • Wrap the event title instead of truncating it, hide the date line when no date is set, and remove the Ticket Layout summary card pending a real rendered-ticket thumbnail.

Breaking Changes

  • Every event record is rewritten on upgrade: To populate the new financial columns, the update recalculates Revenue, Expenses, Net P&L and Margin % for every existing event and saves each one, including events with no tickets, sponsors or expenses. Every event's last-updated date becomes the upgrade date, and any list sorted by last updated, including the default All Events order, reshuffles at once. The previous dates are not recorded and cannot be restored after the upgrade; take an export first if you rely on them.
  • Datetime fields require a timezone: Event start and end dates, and every other datetime field, are normalised to ISO 8601 UTC and now reject values without a timezone offset. API clients sending naive datetimes must add an offset or Z.

Platform Update

August 26, 2026

Breaking Change

  • Backslash escapes in string literals: A backslash inside a Liquid string literal now escapes the character after it, and \\ represents one literal backslash. '\' and "\"" no longer work — use the doubled forms instead.

New Feature

  • escape_regex filter: Escapes every character that carries a special meaning in a regular expression, so the result matches the input literally. Use it alongside replace_regex, matches or regex_matches.

Improvement

  • Deploy errors report a line number: Syntax errors and unknown tags now read like Liquid syntax error (line 4): Unknown filters: not_a_filter, instead of leaving you to find the spot.

  • Deprecated filter aliases published: The filter reference now lists aliases as deprecated entries in their own right, including compact, select, reject, detect, any, sort_by, group_by, flatten, dig and fetch. Every one of them keeps working.

  • Argument types published: Filter and tag arguments now publish their declared type, whether they are required, and the calling convention.

  • Ruby 4: The platform now runs on Ruby 4.0.

  • Asset phase in deploy reports: A deploy report carries an asset_status field reading in_progress, success or error.

Deprecation

  • parse_json: {% assign %} takes a JSON literal directly.

Bug Fix

  • {% return %} and {% redirect_to %} work inside {% for %} and {% tablerow %} loops.

  • A %} written inside a comment no longer truncates a {% liquid %} tag.

  • Assets whose names contain spaces or escaped characters load correctly.

  • Uniqueness locks left by a failed job are released, and lock lifetime is capped at one hour.

  • A malformed request body returns 400, and an unparseable transfer coding returns 501.

Filter by

Date Period

1-10 of 508