# GuestOps Release Notes ## 0.1.0 — Unreleased This is the initial development release of GuestOps Web. It is not yet approved for live hotel operations. ### Current `main` baseline - Responsive shared inbox, search and status filters, saved reply drafts, approved hotel answers, activity history, and hotel settings. - ASP.NET Core authentication with protected cookies, password hashing, CSRF validation, login throttling, role checks, and server-derived hotel membership. - Tenant-scoped MongoDB storage with optimistic concurrency, unique mailbox/message indexes, OAuth state expiry, and worker leases. - Read-only Google OAuth and recent-message import foundation with checkpoint and duplicate protection. - Preview mode, Linux container definitions, Nginx HTTPS example, and automated backend/frontend verification. - Live email sending, PMS writes, payment workflows, and automatic FAQ replies remain disabled on `main`. ### Release-candidate scope The reviewed candidate at `origin/codex/web-foundation` commit `98628ab` extends `0.1.0` with: - AI-assisted reply suggestions and staff-reviewed Gmail sending. - Approval-controlled OHIP PMS and NMI payment workflows. - FAQ automation controls, team invitations, password recovery, and stronger Google connection recovery. - Backup, restore, deployment, and diagnostic tooling. These capabilities are candidate features until the branch is merged, tagged, deployed, and accepted. Google, PMS, and payment-provider acceptance must be completed separately; no live provider calls form part of the local review. ### Known limitations and launch conditions - Gate A still requires a reproducible release artifact, target-Debian deployment, persistent storage/key validation, monitoring, and a successful restore/rollback exercise. - Gate B still requires real Google acceptance and supervised staff testing. Before pilot use, safely paginate beyond the 500-conversation limit, protect drafts across every navigation path, make login throttling proxy-aware, and render dates in the saved hotel timezone—or record and approve explicit operational containment. - Gate C still requires the Rezlynx/Guestline adapter and independently accepted PMS/payment workflows, plus privacy, identity, capacity, and release approvals. - FAQ live mode and all external write actions must remain disabled until their corresponding acceptance gate has passed. See [MILESTONES.md](MILESTONES.md) for the gate assessment, delivery sequence, and remaining work. ### Versioning The .NET projects and frontend package share version `0.1.0`. Future entries should follow semantic versioning and move this section from **Unreleased** to a dated release only after the exact commit and artifacts have been approved.