Version 8.0.0 | A premium, modern, and high-performance desktop, web, and mobile utility built with Next.js 16 (React 19 & TypeScript), Supabase (PostgreSQL), Tauri v2 (Rust Core), and Capacitor v8. It integrates two comprehensive corporate workspaces under a unified, enterprise-grade, role-based access control (RBAC) and feature flag management structure.
The QC Manager consists of two primary corporate workspaces, accessible dynamically based on administrator-configured role permissions, user overrides, and global feature flags:
- Sign-In / Sign-Out Panel: One-click logging of daily attendances with customizable default shifts and live clock rendering for Bangladesh π§π© and UK π¬π§ timezones.
- Live Work Hours Tracking: Realtime calculation of daily office hours, remaining shift durations, and active break durations.
- Leave Submissions: Request workflows for 4 distinct leave categories:
- Full Leave (Annual leave and Eid vacation days)
- Short Leave (Hourly personal absences with automatic Friday Jummah 20-min adjustments)
- Overtime (Logging of extra hours)
- Reserve Holiday (Working on official holidays to bank leave days)
- Government Holiday Banners:
- Users with reserve capabilities enabled choose between holiday pay ("Get Paid") or reserving it for future leave adjustment ("Reserve").
- Users with reserve disabled automatically receive pay addition notifications (bypassing unnecessary screens and admin approvals).
- Bulk Full Leave Submission: Add up to 10 separate dates simultaneously using an interactive calendar panel. In supervisor/admin dashboards, these dates are grouped into a single, unified action row for one-click approval, rejection, or revision request.
- Leave Deficit Adjustments: Easily request adjustments using accrued overtime hours or reserve holidays to offset short leave deficits.
- Compliance Audit Panel: Conduct deep compliance checks on corporate document types (e.g. PDF/Excel quotes).
- Rules & Configuration Engine: Authorized managers and administrators create, edit, or delete compliance checking rules and view execution histories.
- Category Checklist Selector: Permissions specify allowed document categories (e.g. Van, Bike) per staff account.
- Copy Helper & Admin Sales Summary: Includes session info, sales summary, quick copy actions, detailed report, and a server-side deduplicated Admin Sales Summary powered by high-performance PostgreSQL RPCs.
- Document Template Editors: Live causality editors for EUI and Asitis formats with dynamic driver relationship filtering and Supabase template syncing.
- Quick Import & Custom Entry: Features bulk CSV/Excel quote importing and custom manual record entries, both protected by granular tab permissions.
A master control panel allows Superadmins, Admins, and Supervisors to oversee organization-wide operations securely:
- Unified Profile Form (
StaffSettingsForm): Standardized inline configuration layout used in bothSettings > ProfileandUser Management > User Profile Settings. - Manual Department Control: 100% manual control over staff department assignments (
Data Entry,IT, etc.), completely preserving admin/user choices without automated background overwrites. - Standardized Form UI: Circular checkbox inputs, smooth sliding track toggles, standardized field heights (
h-[36px]), and dynamic 3-column inline grid for Change Password.
Superadmins and delegated Admins can customize access levels for User, Supervisor, and Admin roles across 6 distinct permission categories:
- Main Workspace Sections: KPI & Performance, Todos Panel, Leaderboards, Audit Logs, User Management, BD/UK Clocks.
- Quotes Tracker Subtabs: Copy Helper, Save File, Monthly List, Quote Rules, Login Codes, Causality Editor, Quick Import, Custom Entry.
- Leave Tracker Subtabs: My History, Govt Responses, Settlement, Leave Settings, Staff Leaves Report.
- Settings Subtabs: Profile, Menu Visibility, Sanitizer, Access Matrix, Feature Flags, VPN.
- User Profile View Subtabs: Leave History, Quotes History, Analytics, KPI & Performance, Profile Settings.
- User Profile Settings Components:
profile_component_leave_workspaceβ Leave Tracker Workspace settings cardprofile_component_quotes_workspaceβ Quotes Manager Workspace settings cardprofile_component_kpi_settingsβ KPI & Performance Settings cardprofile_component_change_passwordβ Change Password? section
- Configurable temporary overrides targeting an entire role (
user,supervisor,admin) or a specific individual user byCodename (Full Name). - Features an intuitive interactive DateTime picker modal with presets (
1h,4h,8h,24h,3d,7d,30d), single-click duration extensions, dynamic status badges, and active countdown timers.
- Global Toggles: Superadmins and Admins can toggle features ON/OFF globally across the entire organization. Turning OFF a feature flag immediately revokes access for all roles.
- Per-User Overrides: Individual user feature flag overrides (
User Management > Profile Settings > Feature Flags) allow fine-grained per-staff feature toggles backed by database persistence.
- Multi-Device Concurrent Login: Supports up to 10 simultaneous active sessions across Web, Desktop, and Mobile with local token signouts (
signOut({ scope: 'local' })). - Default Password Lockout: Users logging in with initial credentials (
1234) are locked to a password setup modal until a custom secure password is created. - New Account Onboarding Timer: 10-minute setup completion timer backed by persistent
localStoragetimestamps. - Security Audit Remediation: PII protection on email lookups, atomic
jsonb_setsettings updates, strict PostgreSQL RLS policies, and RPC execution revokes.
- PWA Service Worker (
sw.js): Caches static web assets for offline functionality and fast loading. - IndexedDB Sync Storage (
offlineSync.ts): Queues offline signs, sign-outs, and leaves locally, auto-syncing upon network recovery. - Role-Filtered Supabase Realtime Listeners: Selective WebSocket channels prevent company-wide broadcast storms and minimize network egress.
- System Tray & Native Auto-Updater: Native desktop app (Tauri v2) minimizes to system tray; native desktop and Android (Capacitor) apps feature automated OTA update checking and in-app installation.
| Layer | Technologies Used |
|---|---|
| Frontend | Next.js 16 (App Router), React 19, TypeScript, Tailwind CSS v4, Lucide Icons |
| Vector Media & Flags | Crisp SVG Vector Flags (Bangladesh π§π© & United Kingdom π¬π§) |
| Database & Realtime | Supabase (PostgreSQL), Postgres RLS, Triggers, Cascades, RPC Functions, Deno Edge Functions |
| Desktop Wrapper | Tauri v2 (Rust Core, System Tray, Cross-Platform Desktop Installers) |
| Mobile Wrapper | Capacitor v8 (Android APK Packaging, In-App Installer, Native Plugins) |
- Node.js (v20 or higher)
- Rust (v1.77+ for Tauri desktop compilation)
- Supabase Project & CLI
Run supabase/schema.sql in your Supabase SQL Editor to initialize tables, constraints, RLS policies, RPC functions, and cascade cleanup rules.
NEXT_PUBLIC_SUPABASE_URL=your_supabase_project_url
NEXT_PUBLIC_SUPABASE_ANON_KEY=your_supabase_anon_public_key
SUPABASE_SERVICE_ROLE_KEY=your_supabase_service_role_key# Install dependencies
npm install
# Run web dev server
npm run dev
# Run Tauri desktop dev mode
npm run tauri dev
# Check TypeScript types (0 errors)
npx tsc --noEmit
# Compile Next.js web build
npm run build
# Build Tauri desktop installer
npm run tauri buildπ v8.0.0 β Major Release (Context-Aware Global Search, Recent Items, Continue Where You Left Off & Local-First Draft Recovery) (Current)
- Context-Aware Global Search & Deep Navigation: Upgraded the existing Global Search into an intelligent context-aware command and navigation layer supporting 13 core entities (Codename, Employee Name, Filename, Branch, Leave, Leave Comment, Quotation, Quotation File Type, Mistake, Date, User, Quote Rule, and Login Code) with group categorizations, deep links into tabs, filters, and entity drawers, and intentional exclusion of audit logs.
- Global Search Recent Items: Lightweight, client-only recent history experience when Global Search opens with an empty query, allowing rapid re-navigation to recently opened profiles, records, and settings.
- Continue Where You Left Off: Resilient local persistence of the user's last meaningful navigation context (active route, subtab, year/month date filters, branch selectors, and scroll positions) to immediately restore working context upon returning to the app or refreshing.
- Local-First Draft Recovery & Unsaved Form Protection: Comprehensive protection across all critical data-entry forms (Daily Quotation Entry, Leave Application, Quotation Mistake, Quick Import Batch, and Save File Helper) to eliminate accidental data loss from navigation, refreshes, or app closure.
- Save File Outlook Rich Content Field Protection: Full markup preservation for rich Outlook pastes (complex tables, borders, colors, inline CSS, layouts, and fonts) using DOMPurify sanitization, immediate onPaste synchronization, unmount flushes, and dedicated draft recovery modal previews.
π v7.7.0 β Minor Release (Quotes Dashboard Request AbortController & Cache Pruning, Quotation Mistakes Automation & Leave Overrides)
- Quotes Dashboard Request AbortController & Request Sequencing: Integrated active
AbortControllerand monotonic request sequence IDs (fetchSeqRef) into the quotations pipeline. Rapidly changing Month/Year filters immediately cancels obsolete in-flight HTTP requests, preventing race conditions and stale network responses. - Background Cache Pruning & Cache Optimization: Added non-blocking background cache pruning for IndexedDB records cache, keeping local client storage lightweight and fast.
- Optimized Date Formatting & Dhaka Timezone Caching: Implemented memoized date-part parsing for Asia/Dhaka (
+06:00) timezone strings, eliminating redundant parsing overhead during large dataset filtering. - Quotation Mistakes Automation: Introduced smart default period computation and automated filter initialization for reliable historical mistake tracking.
- Leave Settings & Per-User Overrides: Added merged mode support, custom annual leave overrides, and dynamic per-user leave settings resolution.
- Realtime Synchronization Enhancements: Refined profile and leave update emissions in UserManagement and DashboardModals for instantaneous multi-device UI updates.
π v7.6.4 β Patch Release (Monthly & Sale Summary Skeleton Loading Fix, Atomic Short Leave Adjustments & Requote Trigger Normalization)
- Quotations β Monthly & Sale Summary Loading & Skeleton States: Resolved premature 'No file records found matching the filters' and 'No sale records found matching the filters' table flash when switching month or year filters while data downloads from the database. Added synchronous loading triggers, period completion tracking (
fetchedPeriods), and cross-tab cache sharing with in-flight request deduplication. - Quotations β Sale Summary Stats Skeleton Pulse: Added smooth animated pulse placeholders for Sale Summary stat cards during remote retrieval, matching the Monthly Tab
StatsGridbehavior. - Leave Management β Atomic Short Leave Adjustments: Applied and verified
apply_leave_adjustmentandcancel_leave_adjustmentdatabase functions for atomic transactional consistency across Short Leave, Overtime, and General Adjustment workflows. - Database β Requote Insert Normalization Trigger: Added
trg_records_normalize_file_typetrigger onpublic.recordsto normalize incomingRequote VanandRequote Bikerecords to canonicalRequoteon insertion while preserving existing historical records. - Timezone Boundary & Data Integrity Verification: Standardized month-range queries on canonical Asia/Dhaka (+06:00) timezone bounds, confirming 100% record accuracy across all quotation summary tables.
π v7.6.3 β Patch Release (Clear Approved User Requests & Fix User Deletion FK Constraint Error)
- Settings β Users: Clear Approved User Creation Requests: Excluded approved and rejected user creation requests from the Supervisor's active 'My Account Creation Requests' panel and badge counts while preserving complete historical request records in the database. Approved requests transition seamlessly into active profiles without lingering in the action panel.
- User Deletion FK Constraint Fix: Resolved
audit_logs_target_user_id_fkeyconstraint violation during user account deletion. Updatedaudit_business_row_change()trigger function to safely handle foreign key references during cascade deletion while retaining actor and target identification in JSONB metadata indefinitely. - Audit Metadata Retention: Updated
delete_user_by_idRPC to write a privilegedDELETE_USERaudit log capturing actor, target codename, target role, and target user ID before removing the record fromauth.users. - Realtime State Synchronization: Integrated
user-creation-requests-updatedandprofile-updatedAppEventBus dispatches across all request transitions and account deletion pathways.
π v7.6.2 β Patch Release (Supervisor Codename Display in Admin Approval Panel & Payload Completeness)
- Admin Approval Panel Supervisor Codename Display: Fixed
Manager / Supervisorfield in user creation approval cards to dynamically resolve and display the selected Supervisor's Codename (e.g.@NS720) in blue font-mono format with full-name tooltip, eliminating stale default toSelf. - Search by Supervisor Codename in Approvals: Extended Admin Approval Panel search to support querying by the assigned supervisor's codename and full name.
- User Creation Request Payload Completeness: Enhanced
CreateUserPanelto explicitly saveassigned_supervisor_codename,assigned_supervisor_name, andassigned_supervisor_idinUserCreationSubmittedDataupon submission. - Settings β Users Pending Card Alignment: Synchronized the supervisor display in pending request cards in
Settings β Usersto reflect the resolved supervisor codename.
π v7.6.1 β Patch Release (Late Join Sign-Out Compensatory Offset & Settings Pending User Profiles)
- Chuti Late Join Sign-Out Compensatory Offset: Fixed Late Join leave duration calculation when employees work extra time past scheduled shift end. Missed arrival time is now dynamically offset by extra minutes worked after 10:30 PM (e.g. 05:20 PM in with 10:35 PM out now accurately evaluates to 04:15 instead of being stuck at 04:20), clamped cleanly at 00:00 without negative durations.
- Early Leave Early Arrival Offset: Enhanced Early Leave calculation to symmetrically offset early departures when employees arrive earlier than scheduled shift start.
- Supervisor Pending Profiles in Settings β Users: Newly submitted Supervisor user creation requests immediately appear in Settings β Users in a dimmed/pending badge state and automatically transition to active profiles upon Admin approval.
π v7.6.0 β Minor Release (Supervisor Account Creation Workflow, Requote Normalization & Superadmin Edit Privacy)
- Supervisor User Account Creation & Admin Approval Flow: Restored controlled user account creation capability for Supervisors under a secure dual-phase approval flow. Supervisors submit requests (requiring
userrole and Quotes + Leave Workspace access); Admins review, approve, send back with revision feedback, or reject. - Optimistic Concurrency & Resubmission: Supervisors can review admin feedback, update user details, and resubmit with automated revision version tracking and concurrency conflict detection.
- Database RPC & RLS Security: Backed by secure PostgreSQL functions (
submit_user_creation_request,review_user_creation_request,resubmit_user_creation_request,approve_user_creation_request), strict RLS policies, and tamper-evident audit logs. - Quotes Requote Normalization: Removed obsolete Requote Van and Requote Bike as new input options in Daily Entry and Quick Import while preserving 100% of historical records and reporting compatibility.
- Quotes Workspace Category Overflow Fix: Restructured multi-category tag display in Settings β Users to eliminate horizontal text clipping and container overflows.
- Superadmin Leave Edit Privacy: Eliminated user-facing Edited badge/mark when Superadmin modifies leave records, ensuring completely anonymous and untraced administrative adjustments.
π v7.5.4 β Patch Release (Dynamic Mistakes Filters, Add Mistake Modal UI & Codename Label Cleanup)
- Dynamic Mistakes Filter Options: Branch, Year, and Month filters in
Quotations β Mistakesare now derived dynamically from actual submitted records via an optimized metadata RPC (get_available_mistake_filters), eliminating hardcoded dropdowns. - Default Current Period & Graceful Empty State: Initial load defaults to Current Year and Current Month with an intuitive empty state when no records exist, without jumping to earlier periods.
- Viewer-Scoped Filtering & RLS: Normal users only see filter options derived from their own accessible mistake records, while admins and supervisors maintain company-wide range.
- Filter Consistency & Month Revalidation: Changing the selected year automatically revalidates and resets unavailable months to All Months. Specific date selection synchronizes cleanly with Year and Month without conflicts.
- Add Mistake Modal UI Consistency: Standardized Branch and Codename selectors to full column width with uniform 36px field heights matching Date and Filename inputs.
- Codename Option Cleanup: Cleaned employee selector labels to display strictly the Codename (e.g.
AAN425), preserving 100% underlying data integrity, user ID association, and type-ahead functionality.
- Yearly Tie-Breaker Ordering: When monthly file submissions are equal, ranking now automatically evaluates yearly submissions (
overall_score) so that users with higher yearly file counts take precedence in the leaderboard order. - Leaderboard & Navbar Rank Consistency: Synchronized the server-side RPC
get_leaderboard_dataand client-side rank caching so the user rank displayed in the Leaderboard table and next to the user's name in the Navbar are 100% identical. - Live Cache Synchronization: Integrated dynamic rank cache updates on monthly leaderboard evaluation, ensuring instant navbar rank alignment whenever leaderboard data loads or refreshes.
π v7.5.2 β Patch Release (Global Leaderboard Visibility Scoping Fix & Admin Reports Subtab Alignment)
- Global Leaderboard Scope Fix: Resolved a client-side cross-filtering regression where
rawLeaderboardDatawas filtered against RLS-scopedprofilesList, ensuring all eligible participants across the entire company are visible to all authorized viewers. - Admin Reports Subtabs Alignment: Configured Reports subtab permissions so Admins can access Leaderboard and All Report seamlessly, while keeping personal
My ReportandKPI Reportproperly disabled. - Workspace Boundary Integrity: Enforced strict workspace boundaries so users with Quotes Workspace = OFF cannot access or view Reports or Leaderboard, while Admins retain administrative access to Leaderboard and All Report regardless of their personal quotes submission status.
- Dense Ranking & Tie-Handling: Maintained dynamic dense ranking with continuous rank positions (1, 2, 3...) and exact tie preservation across both Monthly and Yearly views.
π v7.5.1 β Patch Release (Todo Default Working Status, Initial Status Selector & Database Alignment)
- Default Working Status on Todo Creation: Newly created Todo items now automatically default to
Workingupon submission, eliminating the redundant step of manually toggling status after creation. - Interactive Creation Status Selector: Integrated an intuitive status selector (
Working,Completed,Idle) directly within the creation bar, enabling optional selection before creation and resetting toWorkingafter submission. - Database & Service Layer Hardening: Standardized canonical
Workingdefault status intodosService.createTodo/bulkCreateTodosand applied migration20260902193000_default_todo_status_working.sqlsetting Postgres column default to'Working'. - Archive Logs Idle Support: Updated historical Todo logs and badges to render the neutral circle icon and muted tag for
Idletasks alongsideWorkingandCompleted. - Compiler & Code Quality Cleanup: Resolved React 19 compiler ref access warnings and enforced clean linting across all components.
π v7.5.0 β Minor Release (Superadmin Trace-Free Comment Control, Read-Only Leave Comments & Hierarchical Re-Approval Flow)
- Superadmin Trace-Free Comment Control: Provided Superadmin with full direct visibility of stored comments and logs in edit mode, enabling seamless alterations, additions, or complete wipes with zero trace (no edit reason requirement and no forced actor attribution).
- Read-Only Comment Locking for Roles: Enforced read-only display of previous comments for Admins, Supervisors, and Users during leave edits, preventing tampering while ensuring historical context is fully legible.
- Mandatory Edit Reason Appending: Standardized the
Reason for Editing (Required)field across all leave editing views, automatically appending newly entered reasons/remarks directly to the previous comment (Previous Comment | New Reason). - Hierarchical Re-Approval Routing: Hardened the leave re-approval workflow so user leave modifications correctly route to their assigned Supervisor first (
pending_supervisor), transitioning to the Admin queue (approved_by_supervisor) only upon supervisor approval. - Report Analytics Header Cleanup: Removed redundant "Report Summary" banner from the User Profile Analytics panel (
UserAnalyticsPanel), delivering a clean, unobstructed view of performance reports and charts.
π v7.4.3 β Patch Release (Workspace-Based Access Control Hardening for Quotations, Chuti & Reports)
- Target User Workspace Boundary: Enforced target user workspace permissions (
targetUser.has_chuti_accessandtargetUser.has_quotes_access) when Admins and Supervisors inspect user profiles, ensuring revoked workspace data remains completely hidden. - Independent KPI Report Visibility: Decoupled KPI Report from the Quotes Workspace so that users with Quotes Workspace disabled can still access their KPI & Performance evaluations while Leaderboard and My Report are securely hidden.
- Navigation & Routing Hardening: Streamlined multi-workspace router fallback ladders across
page.tsx,WorkspaceSubNav, andUnifiedSidebar, preventing unauthorized route landing and dead link states. - Zero Overhead Background Optimization: Guarded background ranking and notification queries to skip execution when workspace access is disabled, reducing Supabase egress.
- Superadmin Todo View Access Decoupling: Decoupled granted view-only Todo access (
has_todo_access) from generic personal feature flags and role visibility settings, ensuring the Todos tab displays immediately for granted users. - Sidebar Navigation Alignment: Simplified
UnifiedSidebarworkspace checks to usecanAccessModule(profile, null, 'todo')directly, preventing false positive tab hiding. - Real-Time Permission Propagation: Ensured immediate workspace appearance and seamless navigation upon Superadmin grant without requiring full page refresh.
π v7.4.1 β Patch Release (Todo View Access Query Optimization, Modal Stability & DNS Alignment)
- Todo View Access Query Fix: Streamlined
todoAccessService.getTodoAccessList()to query direct columns without ambiguous table joins, eliminating schema cache resolution errors when opening the access modal. - Modal Permission Sync: Enhanced real-time synchronization between
todo_accessrecords and client-side cached profiles. - Infrastructure & DNS Alignment: Documented direct Anycast A-record alignment (
76.76.21.21) for high-availability production web deployments.
- Granular Todo View Access: Superadmins can now selectively grant view-only access to specific registered users via the new Todo View Access modal on the Todo workspace.
- Read-Only Mode for Granted Users: Authorized users can view the Daily List, browse historical All Logs, and copy task checklists without write permissions or mutation capabilities.
- Database & RLS Hardening: Enforced robust PostgreSQL Row Level Security policies on
todosandtodo_access, backed by thesync_profile_todo_accesstrigger for real-time permission sync. - Instant Revocation & Realtime Sync: Immediate revocation and real-time subscription propagation ensure unauthorized sessions are terminated without stale cache bypass.
π v7.3.2 β Patch Release (Leave Type Consistency, Soft-Delete Conflict Resolution, Multiplatform Cleanup & Vercel Sync)
- Soft-Delete Same-Day Conflict Fix: Resolved database trigger
enforce_chuti_same_day_conflicts()and client-side validation logic to strictly ignore soft-deleted and rejected records (AND deleted_at IS NULL), preventing false conflict blocks when adding Full Day Leave. - Exact Leave Type Consistency: Hardened
LeavesRecordsTable,TeamLeaveRecords, and export handlers to preserve exact leave types (Late Join,Early Leave,Short Leave,Full Leave, andOvertime) without collapsing or overwriting. - Auditable Comment Display: Standardized table Comment columns to display only the latest action/adjustment note while preserving complete audit logs in tooltips and modals.
- Multiplatform Release System Cleanup: Streamlined distribution targets to strictly Windows x64, macOS Apple Silicon (ARM64), and Android APK, completely removing deprecated build matrices and legacy OTA web-bundle artifacts for faster CI/CD.
- Soft-Delete Same-Day Conflict Fix: Resolved database trigger
enforce_chuti_same_day_conflicts()and client-side validation logic to strictly ignore soft-deleted and rejected records (AND deleted_at IS NULL), preventing false conflict blocks when adding Full Day Leave. - Exact Leave Type Consistency: Hardened
LeavesRecordsTable,TeamLeaveRecords, and export handlers to preserve exact leave types (Late Join,Early Leave,Short Leave,Full Leave, andOvertime) without collapsing or overwriting. - Auditable Comment Display: Standardized table Comment columns to display only the latest action/adjustment note while preserving complete audit logs in tooltips and modals.
- Multiplatform Release System Cleanup: Streamlined distribution targets to strictly Windows x64, macOS Apple Silicon (ARM64), and Android APK, completely removing deprecated build matrices and legacy OTA web-bundle artifacts for faster CI/CD.
π v7.3.0 β Minor Release (Late Join Leave Type Addition, Locale-Aware Time Pickers, Performance Cache Optimization & Complete 1:1 Skeleton Loader Modernization)
- Late Join Leave Type: Extended Chuti leave management with a dedicated
Late Joinleave type that automatically aggregates into Short Leave summary balances, history records, and team summaries. - Locale-Aware Time Pickers: Enhanced sign-in and sign-out time pickers across the app to dynamically follow the client's OS / browser time format preferences (12-hour AM/PM vs 24-hour mode).
- Performance & Cache Optimization: Upgraded SWR in-memory and IndexedDB offline cache architecture across Quotations and Chuti workflows for instant 0ms rendering with zero layout shifts.
- Comprehensive Skeleton Modernization: Designed 1:1 dark glassmorphic skeleton loaders matching production views across:
- Chuti: Add Leave, Leave History, Team Leave Records, Review & Settlements, and Leave Settings.
- Reports: Leaderboard, KPI Performance Assessment, My Report, and All Report (including dedicated
ReportsDashboardSkeleton). - Todos: My Tasks & Todos (top input bar, task items list with permanent badges).
- Settings: Sanitizer (
SanitizerSkeleton) and Users (UserManagementSkeleton).
π v7.2.0 β Minor Release (Attendance Feature Complete Removal, Overtime Calculation Precision Fix, Enhanced Leave Adjustments & User Management Polish)
- Attendance Module Removal: Completely uninstalled and removed the experimental Home β Attendance & Shift Tracker module from UI, contexts, services, timers, realtime subscriptions, and database migrations.
- Overtime Calculation Precision Fix: Strictly standardized overtime calculation to
MAX(0, Actual Work - Regular Duration)by deducting the configured working duration across all days. - Restricted Self-Service Adjustments: Disabled self-service adjustment submissions on
Add Leaveand restricted adjustment controls strictly to Admin profile management underSettings > Users > Leave History. - Interactive Adjustment Modal: Enhanced
AdjustmentModalin Admin Settings with live calculation breakdown between accumulated Short Leave and Overtime, plus direct Salary Deduction (Salary) support. - Settings UI Cleanups: Removed redundant nested card containers in User Profile (
Leave History,Quotes History) for clean edge-to-edge layout.
π v7.1.0 β Minor Release (Same-Day Multi-Leave Support, Strict Early Leave Form Lockout, Realtime Field Disabling & Chuti Optimization)
- Multiple Short Leaves on Same Day: Removed restrictive unique constraint index from remote PostgreSQL/Supabase database (
unique_user_datedropped) and introduced interactive confirmation warning modal for consecutive short leaves. - Early Leave Isolation & Lockout: Enforced same-day leave lockout when an Early Leave is already recorded on a given date for regular staff, while maintaining administrator override capabilities from User Profile & Leave History.
- Co-existence of Short Leave & Early Leave: Enabled recording Early Leave on dates with existing Short Leaves without erroneous cross-leave hour deductions or conflicting validation blockers.
- Contextual Form Field Disabling: Dynamically disabled and reset all adjustment toggles (Govt Holiday, Eid-ul-Fitr, Eid-ul-Adha, Salary/Other, Overtime Short Leave Adjustment) whenever a date with blocking leave records is selected.
- Leave Form Field Sanitization: Completely disabled Leave Type dropdown, Start/End time pickers, Break toggles, Comment box, and false hour calculations when selecting blocked dates.
π v7.0.0 β Major Release (Enterprise Attendance & Multi-Shift Tracking System, Realtime Cross-User Live Sync, Chuti Permission Hardening & Enhanced Login Security)
- Enterprise Attendance & Multi-Shift Module: Introduced full-featured Home β Attendance system supporting multiple shifts per day, join/close actions, snack breaks, and prayer breaks with zero data loss.
- Continuous Working Time & Gross Elapsed Duration: Standardized working duration calculations so snack breaks and prayer breaks remain included in the total shift and daily working time.
- Realtime Cross-User Live Sync: Enabled instant fleet-wide attendance state synchronization across User, Supervisor, Admin, and Superadmin roles with zero polling overhead and zero full-table refetches.
- Sub-Second Live Clock & Navbar Timer Synchronization: Upgraded LiveClock and Navbar timer ticker loops to sub-second precision, ensuring perfect lockstep synchronization with zero drift.
- Standardized 2-Line Session Badges: Re-engineered Shift, Break, and Prayer Break table badges into uniform 2-line cards displaying start/end timestamps on top and formatted elapsed duration on bottom with pulsing status indicators.
- Superadmin Granular Session Deletion: Empowered Superadmins with safe, granular deletion controls directly on individual Shift, Break, and Prayer Break badges with automated reconciliation of daily metrics and status.
- Leave History Permission Hardening: Secured Chuti adjustment permissions, implemented direct administrative salary deduction adjustments, and streamlined employee approval workflows.
- Enhanced Login Credential Security: Replaced single-field remembering with comprehensive Codename & Password local persistence while removing the password reveal toggle for hardened security.
π v6.10.0 β Minor Release (Smart Year-Linked Monthly Filter, Codename Header Standardization, Copy Helper Cleanup & Security Audit Logs Removal)
- Smart Year-Linked Month Filter: Integrated dynamic month selector in
LeavesRecordsTable.tsxthat lists only months with submitted records. Filter activates when an individual year is selected and automatically resets when Year is set to ALL. - Codename Header Standardization: Updated
UserLeaveHistoryPanel.tsxso the leave history table header displays Codename's Leave Records (e.g. NZ720's Leave Records) instead of full names. - Supervisor Authorization & Real-Time Profile Lookup: Enhanced
useDerivedState.tsto strictly cross-reference liveprofilesListsupervisor assignments, ensuring only assigned or delegated supervisors receive team approval queue items. - Approval Comment Tag Deduplication: Updated
buildStatusUpdatePayloadinuseChutiOperations.tsto prevent duplicate approval tags (e.g.NZ720 Approved | YK920 Approved) from prepending repeatedly when leave entries are updated or re-approved. - Copy Helper Network & Admin Summary Box Cleanup: Completely removed Box 2 (Network & VPN Info) and Box 6 (Sales Summary - Sales Report for Admin) along with all their IP/VPN detection state, network background polling, and modal UI components.
- Feature Flag & System Cleanups: Removed
copy_helper_admin_summaryandaudit_logs_inspectionfeature flags from system registry, default flag states, and Access Control / Feature Flags settings. - Complete Audit Logs / Security Logs Removal: Removed
AuditLogsPanel.tsx,AuditLogsSkeleton.tsx,audit_logsdatabase queries, background activity logging calls, and Security Logs subtab from Profile Settings and navigation registries. - Review & Settlements Table Center Alignment: Updated
AdminSettlementsPanel.tsxso Unused Balance, User Preference, Status, and Action column titles and data cells are center-aligned, keeping Staff Member left-aligned.
- Supervisor Pending Approval Authorization & Real-Time Profile Lookup: Enhanced
useDerivedState.tsto strictly cross-reference liveprofilesListsupervisor assignments, ensuring only assigned or delegated supervisors receive team approval queue items. - Approval Comment Tag Deduplication: Updated
buildStatusUpdatePayloadinuseChutiOperations.tsto prevent duplicate approval tags (e.g.NZ720 Approved | YK920 Approved) from prepending repeatedly when leave entries are updated or re-approved. - 2-Stage Approval Verification Audit: Verified 2-stage approval workflow end-to-end for both supervised staff (Supervisor -> Admin) and direct/unsupervised staff (bypassing supervisor stage directly to Admin).
- Dropdown Portal Positioning & Flicker Elimination: Resolved split-second unpositioned layout shifts and dual-scroll jumps when opening
CustomSelectdropdown menus for the first time across Quick Import queue and all dropdowns. - Copy Helper Hyphenated Date Parsing Fix: Fixed
parseDdMmYyyyToTargetStrin Copy Helper to seamlessly supportDD-MM-YYYYhyphens, restoring real submitted records display in Boxes 4, 5, and 6. - Strict Date Element Editing Isolation: Restricted double-click date editing in Copy Helper strictly to the date string itself (
soldDate), preventing accidental edit triggers on label text. - Streamlined Leave History UI & Excel Export Repositioning: Embedded
Leave Typedropdown filter on the left of the search box andExcelexport button on the right of the search box in Leave History table, completely removing the redundant top filter panel, date inputs, and PDF export. - Title-Adjacent
+ Add LeaveButton: Positioned the+ Add Leavebutton directly beside the user leave records title for intuitive access.
π©Ή v6.9.4 β Patch Release (Global Dropdown Keyboard Type-Ahead & Clean TimePicker Standardization)
- Global Dropdown Keyboard Type-Ahead: Integrated letter-key search and auto-scrolling across all CustomSelect dropdown menus for fast keyboard filtering.
- Strict DD-MM-YYYY Date Format: Standardized all dates to DD-MM-YYYY across Copy Helper, Leave Tracker, and Reports.
- Copy Helper & Records Table Interaction Polish: Standardized double-click and triple-click edit triggers for dates and times, added reset indicators, removed pencil icons, and set cursor-text on hover.
- Dynamic Bulk Leave Days Limit: Dynamic day limit for bulk leave entries matching exact days in the selected month (28, 29, 30, or 31 days).
- Custom TimeInput & Clock Icon Removal: Built reusable
<TimeInput>with 12-hour AM/PM formatting and top-right BD time badges, removing side clock icons globally across Leave Tracker, Settings, Profile Settings, and Table inline edits. - Compact Inline Time Editor: Streamlined inline time editing box width in Daily/Monthly Entry tables (
w-[82px]).
- Sonner Toast Migration: Replaced react-hot-toast with Sonner across the entire project for unified, accessible notifications.
- Bottom-Right Notification Setup: Positioned the global Toaster at bottom-right in RootLayout for clean, non-intrusive alert delivery across desktop, web, and mobile.
- Timezone Boundary Alignment: Fixed server fetch start/end date calculations to use local timezone boundaries (Asia/Dhaka) instead of UTC, preventing early-morning records on the 1st of the month from being omitted.
- Full Month Sync & Prune Fix: Prevented false cache pruning by ensuring full paginated server fetches load complete month records into IndexedDB cache.
- Web Auto-Updater Guard: Restricted binary desktop/mobile auto-update popups strictly to native Tauri Desktop and Capacitor Mobile platforms, preventing update toasts on localhost and web browsers.
- Leaderboard Range Sync: Synced Leaderboard monthly filter options to start from app data launch (June 2026) up to current month (August 2026), defaulting to the current month.
- KPI Dropdown Formatting: Cleaned up KPI Report filter labels to show month name in monthly mode and year number in yearly mode.
- Database-Driven Monthly Filters: Restricted monthly filter dropdowns across Leaderboard, Reports, Quotes Tracker, and KPI Report to show only active months with submitted records (June β August 2026).
- KPI Yearly/Monthly Evaluation Scope: Added a Yearly | Monthly toggle scope in KPI Report page for full-year performance assessment and monthly views.
- Inline Date Stepper Fix: Fixed date picker popup closing issue during month arrow navigation and enforced DD-MM-YYYY format.
- UI Layout Optimization: Cleaned up Team Leave Records header layout and spaced out controls.
π©Ή v6.8.3 β Patch Release (Removed Menu Subtab & Per-User Hidden Tabs Setup)
- Menu Subtab Removal: Completely removed the
Settings > Menusubtab and per-userhidden_tabsconfiguration. - Unified Navigation Governance: All workspace menu items and subtabs are now governed strictly via superadmin Tab Access Control matrix and Role-Based Access Controls (RBAC).
- Critical Security Fix: Fixed privilege escalation in
check_profile_updates()β regular users could modify their own access flags (has_chuti_access,can_manage_rules,supervisor_ids, etc.). Now restricted to superadmin-controlled columns only. - CORS Security Fix: Replaced wildcard origin reflection with a trusted origin whitelist (
qc-manager-app.vercel.app,tauri://localhost,capacitor://localhost,localhost). - Rate Limiter Hardening: Fixed
x-forwarded-forheader spoofing bypass on/api/resolve-emailand/api/forgot-passwordrate limiters. - Egress Optimization: Eliminated full profiles table re-download on INSERT/DELETE realtime events β new profiles are now patched inline from the realtime payload (zero network cost).
- Dead Code Cleanup: Removed unused files (
sanitize.ts,useAppReleaseLinks.ts), dead exports (validateCreateUserForm,validatePassword), debug scripts (scratch/), old database exports (supabase data/), backup logs (supabase/backups/), and AI tool configs (~5.5MB total). - Gitignore Cleanup: Consolidated scattered entries and removed references to deleted files.
- Consolidated Settings Subtabs: Integrated
Security Logs(Audit Logs) andUsers(User Management) into Settings subtabs. - Mobile & Small Screen Scrollable Subtabs: Added responsive horizontal scrolling for subtabs on small displays.
- Subtab UI Polish & Renaming: Updated subtab labels (
Profile,Security Logs,Users) with vibrant icons and cleaned up redundant header cards across Menu, Sanitizer, VPN, and User Management. - Reports Navigation: Defaulted Reports workspace navigation to Leaderboard and added active subtab memory across navigation sessions.
- Smart Cache-First Sync: Optimized
useQuotesDashboardData.tsto check local IndexedDB cache first during page loads and logins, eliminating redundant full-month database downloads. - Delta-Only Background Updates: Executed remote queries solely for new or modified records (
updated_at >= lastSynced), reducing daily Egress per refresh/login to ~0 Bytes when no new entries exist. - Zero-Cost Free Tier Guarantee: Slashed overall monthly network egress by 80β90%, keeping 60 active users ultra-safely below Supabase's 5.0 GB Free Tier ceiling.
- 30-Day Initial Sync Window: Optimized default quote initial background sync from 90 days to 30 days in
useQuotesDashboardData.ts, cutting initial login bandwidth payload size by ~60%. - Zero-Cost Free Tier Alignment: Reduced projected monthly network egress for 60 active users down to ~2.8 GB/month, keeping overall usage safely within Supabase's 5.0 GB Free Tier ceiling.
- On-Demand Historical Queries: Preserved full historical access via dynamic date range filters while keeping routine daily load lean and fast.
π©Ή v6.7.6 β Patch Release (Quick Import Sale Status Tracking & Automatic [SOLD]/[UNSOLD] Formatting)
- Quick Import Sale Status Selector: Added an inline Sold/Unsold dropdown selector for every item in Quick Import (Bulk Import Modal) whenever the file type is detected or selected as 'Sale'.
- Default Unsold Status: Defaulted all parsed Sale files in Quick Import to 'Unsold' (with manual dropdown toggle to 'Sold'), perfectly matching Daily Entry tracking rules.
- Auto-Detection: Auto-detected '[SOLD]' or 'sold' in raw text lines during bulk quote parsing to pre-select 'Sold'.
- Seamless Database & Analytics Integration: Formatted file names on submission with ' [SOLD]' or ' [UNSOLD]' suffixes to feed Copy Helper Box 4 (Sales Summary), Box 6 (Admin Sales Summary), and Save File Helper.
π©Ή v6.7.5 β Patch Release (Copy Helper Date Controls, Unified Feature Flags & Supervisor Delegation Security)
- Copy Helper Date Controls & Independent Filtering: Added independent per-box date pickers with hover pencil icons, DD/MM/YYYY formatting, and independent record filtering across Box 4 (User Sales Summary), Box 5 (Detailed File Report), and Box 6 (Admin Sales Summary).
- Copy Helper Feature Flags: Added
copy_helper_user_summary(Box 4) andcopy_helper_important_notes(Important Notes) to the Feature Flags registry with Superadmin control, and ensured dynamic box renumbering without gaps. - Unified Temporary Access Controls: Extended Temporary Access Controls in Profile Settings to support both Navigation Tabs and Feature Flags with target-user granularity.
- Strict Workspace & Supervisor Access Control: Restricted Quotes Manager Workspace access toggles and supervisor assignments strictly to Admin/Superadmin.
- Supervisor Team & Delegation Scoping: Enforced read-only view mode for Quotes Manager Workspace when viewed by a supervisor for staff outside their assigned or delegated team.
π©Ή v6.7.4 β Patch Release (Granular Profile Settings Permissions, Feature Flags & Complete Documentation Audit)
- Granular User Profile Settings Access Control: Registered
User Profile Settings Componentscategory underSettings > Access, enabling Superadmin and Admin role-level visibility control and temporary overrides for Leave Tracker Workspace, Quotes Manager Workspace, KPI & Performance Settings, and Change Password. - Global Feature Flags Integration: Added matching
profile_component_entries toSettings > Feature Flags, enabling instant global ON/OFF toggles across all user accounts. - Dynamic Component Guarding: Updated
ProfileSettings.tsxandStaffSettingsForm.tsxto dynamically queryisTabVisibleForRolepolicies before rendering sensitive profile form sections. - Manual Department Preservation: Enforced 100% manual control over staff department assignments with no automatic overwrites.
- Full Architectural Audit & Documentation Sync: Completed an A-Z codebase review and completely refreshed project documentation.
π©Ή v6.7.3 β Patch Release (Unified Staff Settings, Role Permissions & Manual Department Control)
- Unified Staff Profile Form: Replaced fragmented profile inputs with unified
StaffSettingsFormacross both Settings > Profile and User Management > User Profile. - Workspace & Feature Flag Permissions: Enforced strict per-role permissions for Leave Tracker, Quotes Manager, and KPI Performance settings across User, Supervisor, Admin, and Superadmin roles.
- Individual Feature Flags Bug Fix: Fixed per-user feature flag overrides to correctly display and persist real database values.
- Manual Department Control: Completely removed legacy auto-swap/auto-repair scripts; user and admin manual department configurations are preserved 100%.
- Dynamic Save Changes Button: Enforced disabled state by default when no fields are modified, enabling dynamically as soon as permitted fields are edited.
- Inline Change Password Layout: Re-aligned the Change Password section into a 3-column inline grid across full container width.
π©Ή v6.7.2 β Patch Release (Flag Icon Verification, Explicit SVG Dimensions & Auto-Repair Refinement)
- Explicit Vector SVG Dimensions: Updated
<BdFlagIcon />and<UkFlagIcon />with explicit SVG dimensions (width=18,height=12) and crisp borders (border-white/20), completely eliminating OS emoji font dependencies. - Refined Department Auto-Repair: Background database migration automatically scans and restores profiles mistakenly set to 'IT' back to 'Data Entry'.
- Live Clock Cross-Platform Consistency: Fixed header clock layout rendering on Windows, macOS, Linux, and mobile browsers.
π©Ή v6.7.1 β Patch Release (Android Auto-Updater Fixes, Cross-Platform SVG Flag Rendering & Department Auto-Repair)
- Android Mobile Auto-Update Fixes: Fixed state timing bug preventing mobile update checks, added 3-source version resolution (GitHub manifest, GitHub API, Supabase), and introduced interactive Download & Install action button with fallback.
- Cross-Platform SVG Vector Flags: Replaced OS-dependent Unicode flag emojis with crisp inline SVG vector icons for Bangladesh π§π© and United Kingdom π¬π§, fixing Windows Segoe UI text rendering issues.
- Department Database Auto-Repair: Implemented automated client-side background migration reverting mistakenly overwritten profile department records from 'IT' back to 'Data Entry'.
- Safe Global Settings Preservation: Updated user profile update handler to safely preserve existing KPI skills, department indicators, and department selections upon saving.
π v6.7.0 β Minor Release (Supervisor Access Controls, Per-Supervisor Overrides, KPI Evaluation Period & Workspace Permission Delegation)
- Per-Supervisor Specific Access Controls: Added supervisor dropdown selector and granular subtab permission overrides under Settings > Access (
User Management > User Profile > Leave History / Quotes History / Analytics / KPI & Performance / Profile Settings). - Workspace Permission Delegation & Prompt Modal: Enables Quotes Manager Workspace with automatic confirmation prompt modal to assign a supervisor. If assigned, filetype permissions and KPI settings are managed by the supervisor (or admin with explicit KPI subtab permission).
- KPI Evaluation Period & Date Bounding: Added Full Year (
Jan 1 - Dec 31) & custom evaluation date ranges for KPI performance calculations automatically fetching submitted quote data. - Header & Button Contrast Fixes: Resolved wrapping white space in leaderboard header and updated disabled button contrast in Light Mode.
π v6.6.0 β Minor Release (Role & Per-User Temporary Access Controls, Custom DateTime Picker, Alignment & Feature Flag Management)
- Superadmin Access Control Matrix: Registered
Quick Import&Custom Quote Entryas controllable subtabs under Tab Access Matrix (Settings > Access). - Per-User & Per-Role Temporary Access: Configurable time-boxed temporary overrides targeting either an entire role (
user,supervisor,admin) or a specific single user byCodename (Full Name). - Added Save Password Checkbox: Added a "Save Password" checkbox to the login panel with continuous syncing to
localStorageand native browser autocomplete attributes (username,current-password). - Multi-User Logout & State Cleanup: Injected state cleanup on logout (clearing
cached_profile_,qc_session_id), invalidating module-level initial state, and adding fetching concurrency guards to fix loading screen hangs during rapid user switches. - Session Heartbeat Egress Elimination: Completely removed repetitive
profiles.global_settingsheartbeat updates for existing user sessions, eliminating unnecessary Supabase DB writes and Realtime broadcast messages while preserving 1-week inactivity logout. - Forgot Password API & Timeout Fix: Optimized the forgot password endpoint to fire admin notification lookups asynchronously (non-blocking), increased native app (Capacitor/Tauri) fetch timeouts to 15 seconds, and added duplicate tap guards to fix false "network error" popups on desktop and Android apps.
- Security Audit Remediation: Resolved 3 critical audit findings: PII protection on email resolution, atomic
jsonb_setsettings updates, and username enumeration prevention.
- Multi-Device Login: A user can now stay logged in simultaneously on Web, Desktop, and Android (up to 10 devices/browsers). Every per-device logout path (manual logout, inactivity expiry, stale-session cleanup, session eviction) now uses
signOut({ scope: 'local' }). - Copy Helper for All Users: The Copy Helper dashboard is now available to every authenticated user. Box visibility is driven by the Sale file-type permission.
- Admin Sales Summary (New): "Sales Report for Admin" box showing today's overall deduplicated sales across all users, computed server-side via a new
get_admin_sales_summaryRPC.
- Leaderboard Data Accuracy: Removed 4,200 duplicate records caused by a faulty cache auto-restore, added a database unique index on
records (user_id, file_name, submitted_at). - Expanded Working Hours (4hβ10h): Working Hours options now span 4 Hours to 10 Hours in 30-minute increments, generated from a single shared source of truth (
src/utils/workingHours.ts). - Save File Helper β Once-Per-Day Directory: Fixed duplicate folder prompt.
- Supabase Optimization: Implemented strict PostgreSQL query filtering inside profile handlers.
- Automated Database Cleanups: Scheduled a daily background cron job inside Supabase to automatically purge audit history older than 90 days.
Developed by Kamrul Islam, IT Officer, B&F Corporate.