MiStorage has no version tags — releases are identified by the working session that produced them. Each entry summarises the session write-up in docs/memories/.
The HQ ↔ location bridge from the single-operator checklist, built end to end. No migration needed.
POST api/tenant-auth/enter: "Manage Facility" signs an HQ administrator into a location's console as its Owner without a second login, with an audit row naming the HQ user.api/customer/{id}/staff* endpoints behind the location page's new Staff tab: list, add, deactivate / reactivate, and set password.LocationStaffAndEntryTests added; suite at 243 tests.Two migrations owed since 09-09 and 09-11 applied to production — the HQ dashboard and Locations list had been failing for four days with 42703: column CollectDriversLicense does not exist.
Saas:Enabled, so the client can open a second location under their own address.LocationContactEmailTests added.Three follow-up passes on the single-operator model, driven by client feedback.
/super-admin/customers is now /super-admin/locations; the old path redirects permanently. The API and the Customer entity are unchanged.ApplicationFieldPolicyService, unit → location → default).api/tenant/{customerId}/settings added so location staff can edit these without asking HQ.After a client demo the product stopped being SaaS: the client is the storage operator. The SaaS layer is archived behind Saas:Enabled (default false), not deleted.
[RequireSaas] and SaasFeatureGateMiddleware: subscription plans, platform invoices, cards on file, merchant boarding, company self-signup and plan management answer 404 while the flag is off.api/tenant-auth/register becomes an administrator action; rent settles to the configured merchant; api/dashboard/stats returns operator figures.NEXT_PUBLIC_SAAS_ENABLED..gitignore rule on docs/ narrowed so session write-ups and the deploy procedure are versioned."Remember me", and the refresh-rotation race that used to sign renters out at random.
RenterSessionOptions: rolling remember-me window with an absolute ceiling, session cookies with a server-side backstop, a rotation grace window, a concurrent-session ceiling that evicts the idlest, and revoked-row retention.POST api/renter-auth/revoke-all does that deliberately.DateTime.MinValue as -infinity, so the generated SQL matched nothing.Client feedback: link → unit → pay, with nothing else in between.
RenterAuth:RequireEmailVerification added and switched off at the client's request while email delivery is blocked.The storefront checkout and the renter's billing UI, plus fixes found in a project-wide sweep.
An unplanned phase inserted first: none of the three audiences had a working password reset.
POST api/rental/start, renter invoices, and staff move-out — before this, unit assignment left no record of when a rental started or ended.Email:Transport = Mock) so the flow can be exercised while SMTP is blocked.CustomerId + Email), with their own refresh-token table and Renter policy.api/public/{subdomain}: location profile with a size guide and live availability, paged unit listings with filters and sorting, and single-unit detail.UnitSizeCatalog: a fixed set of size categories with labels, blurbs and typical dimensions, derived from a unit's width and length.Earlier history (global and local search, notification enhancements, performance optimisation, session-token lifespan, security hardening of 65 tested tasks, and the public storefront's first cut) is recorded in the repository's commit log rather than in session write-ups.