NEXUS
Release Notes

MiStorage Release Notes

MiStorage has no version tags — releases are identified by the working session that produced them. Each entry summarises the session write-up in docs/memories/.

2026-09-17September 17, 2026Not yet deployed

HQ enters a location's console; Staff tab

The HQ ↔ location bridge from the single-operator checklist, built end to end. No migration needed.

  • POST api/tenant-auth/enter: "Manage Facility" signs an HQ administrator into a location's console as its Owner without a second login, with an audit row naming the HQ user.
  • Four api/customer/{id}/staff* endpoints behind the location page's new Staff tab: list, add, deactivate / reactivate, and set password.
  • LocationStaffAndEntryTests added; suite at 243 tests.
  • A MiStorage-specific SMTP account was requested from the client so email verification can be switched back on.
2026-09-15September 15, 2026In production

Production catch-up; one owner, many locations

Two migrations owed since 09-09 and 09-11 applied to production — the HQ dashboard and Locations list had been failing for four days with 42703: column CollectDriversLicense does not exist.

  • The contact-email uniqueness rule on locations is archived behind Saas:Enabled, so the client can open a second location under their own address.
  • LocationContactEmailTests added.
  • New rule recorded in the deploy procedure: publish and migrate together, every time.
2026-09-11September 11, 2026In production

Locations, editable units, application fields

Three follow-up passes on the single-operator model, driven by client feedback.

  • /super-admin/customers is now /super-admin/locations; the old path redirects permanently. The API and the Customer entity are unchanged.
  • The staff console stops calling itself a facility — it says Location, the same word HQ uses.
  • Units are editable after creation: name, monthly rate, dimensions, climate control and out-of-service.
  • A location's own phone number, shown on the storefront.
  • Whether the rental application asks for a Social Security Number and a driver's licence is now switchable per unit, per location, or installation-wide (ApplicationFieldPolicyService, unit → location → default).
  • api/tenant/{customerId}/settings added so location staff can edit these without asking HQ.
2026-09-10September 10, 2026In production

The single-operator pivot

After a client demo the product stopped being SaaS: the client is the storage operator. The SaaS layer is archived behind Saas:Enabled (default false), not deleted.

  • [RequireSaas] and SaasFeatureGateMiddleware: subscription plans, platform invoices, cards on file, merchant boarding, company self-signup and plan management answer 404 while the flag is off.
  • api/tenant-auth/register becomes an administrator action; rent settles to the configured merchant; api/dashboard/stats returns operator figures.
  • Frontend mirror flag NEXT_PUBLIC_SAAS_ENABLED.
  • The .gitignore rule on docs/ narrowed so session write-ups and the deploy procedure are versioned.
2026-09-09September 9, 2026In production

Renter session management

"Remember me", and the refresh-rotation race that used to sign renters out at random.

  • RenterSessionOptions: rolling remember-me window with an absolute ceiling, session cookies with a server-side backstop, a rotation grace window, a concurrent-session ceiling that evicts the idlest, and revoked-row retention.
  • Signing in no longer ends other sessions; POST api/renter-auth/revoke-all does that deliberately.
  • Only a rotated token replayed outside the grace window is treated as theft.
  • A backfill bug caught in review: Npgsql renders DateTime.MinValue as -infinity, so the generated SQL matched nothing.
2026-09-08September 8, 2026In production

Three-step checkout; email verification becomes a switch

Client feedback: link → unit → pay, with nothing else in between.

  • The storefront checkout is three steps: available units, pick one, fill in details and pay.
  • The rental application collects driver's licence, emergency contact and employer; the SSN is encrypted at rest with AES-256-GCM.
  • RenterAuth:RequireEmailVerification added and switched off at the client's request while email delivery is blocked.
  • Renter portal: account home, my units, address book, move-out notice.
2026-09-01September 1, 2026In production

Phase 4 frontend; three holes patched

The storefront checkout and the renter's billing UI, plus fixes found in a project-wide sweep.

  • Storefront checkout, renter account leases and invoices, staff lease list with move-out.
  • Tenant login fix on production: the cross-site refresh cookie is now re-issued first-party through the frontend's relay routes.
  • All frontend claims verified by driving a real browser against a real backend.
2026-08-25August 25, 2026In production

Phase 3.5 password recovery; Phase 4 rental flow

An unplanned phase inserted first: none of the three audiences had a working password reset.

  • Forgot / reset password for HQ, location staff and renters.
  • Lease entity, quotes, POST api/rental/start, renter invoices, and staff move-out — before this, unit assignment left no record of when a rental started or ended.
  • Anniversary billing with no proration or deposit, deliberately: inventing a billing policy is the client's call.
  • Email mock transport (Email:Transport = Mock) so the flow can be exercised while SMTP is blocked.
2026-08-21August 21, 2026In production

Phase 3 renter identity; raw-PAN removal

  • Renter accounts scoped per location (CustomerId + Email), with their own refresh-token table and Renter policy.
  • Email verification, uniform registration acknowledgement, per-audience rate-limit buckets.
  • The last raw-PAN code path deleted — closes the named SAQ A-EP item.
2026-08-10August 10, 2026In production

Phase 2 public storefront API

  • api/public/{subdomain}: location profile with a size guide and live availability, paged unit listings with filters and sorting, and single-unit detail.
  • Anonymous, read-only, GET only; only live locations and Available units are visible; responses cacheable for 60 seconds.
  • Storefront UI followed on 2026-08-12, server-rendered so it is indexable and fast on a phone.
2026-08-05August 5, 2026In production

Phase 1 unit size taxonomy

  • UnitSizeCatalog: a fixed set of size categories with labels, blurbs and typical dimensions, derived from a unit's width and length.
  • One migration with a backfill verified against real rows.
2026-07-31July 31, 2026

Customer portal planning

  • Requirements gathered across the client meetings mapped against the codebase; gap analysis written up as the plan of record.
  • Six phases scoped, compliance first. No code changed.