Release Notes

Current version: V1.48 (Release build #4)

v1.48 — Hero and full-page backgrounds are now fully independent
2026-09-03
  • Replaced the single 'Hero Only / Full Page' style toggle with two genuinely independent background slots on /admin/homepage-background: the hero section and the rest of the page can each be set to a completely different photo, the same photo, or Default (off), with no dependency on each other.
  • Every uploaded background now shows 'Use for Hero' and 'Use for Full Page' as separate actions, plus its own Delete. Deleting a photo currently assigned to one or both slots automatically resets just those slots to Default.
  • Also lightened the hero's photo overlay (82% to 55% opacity) — the background photo is now clearly visible instead of being muted almost to a silhouette, while the stat numbers and headline text remain fully legible.
v1.47 — Full-bleed hero background, new 'Full Page' background style option
2026-09-03
  • The homepage hero now spans the full browser width edge-to-edge behind its background photo, instead of sitting as a rounded, margined card with page background visible on either side.
  • New 'Background Style' choice on /admin/homepage-background, independent of which photo is active: 'Hero Section Only' (the original design) or 'Full Page', which extends the same photo — more subtly, so dark text elsewhere on the page stays readable — behind the rest of the homepage too, including the feature cards and Recently Posted section.
  • Fixed a real layout bug this surfaced: stat numbers in the hero (Live internships, Intern candidates, etc.) had no contrast protection against the background photo and could land directly on top of it illegibly. The photo now sits behind a uniform dark overlay across the whole hero, not just a one-sided fade.
v1.46 — Homepage hero background photo, admin-managed
2026-09-03
  • New /admin/homepage-background page — upload any number of background photos for the homepage hero, switch the live site between them, or reset to Default (solid navy, no photo). Uploads are validated by real file content, not just the claimed extension.
  • The homepage hero now shows the admin's chosen background with a smooth gradient fade into the brand navy, positioned on the right side of the hero. Automatically falls back to the plain Default look on smaller screens, regardless of which background is active.
v0.45.0 — Fixed a datetime string-format bug affecting 'Live now' and several background cleanup jobs
2026-08-31
  • Root cause: SQLite's own datetime('now') writes timestamps like '2026-08-31 07:10:19', while several places in the code computed comparison cutoffs using Python's .isoformat(), which produces '2026-08-31T07:05:19.123456'. Comparing these as plain text, the space-vs-'T' difference made a same-day cutoff (like "5 minutes ago") almost always compare incorrectly — this is exactly why the homepage/monitoring/dashboard 'Live now' stat always showed 0, while 24-hour/7-day stats usually looked fine (those comparisons typically span an actual date change, which happens to resolve correctly before ever reaching the broken part of the string).
  • Added utils.sqlite_now() — matches SQLite's own format exactly — and fixed every genuinely affected comparison: 'Live now' on the homepage, /admin/monitoring, and /admin/dashboard; the 24h payment-failure alarm; two chatbot 'transactions this week' answers; and three background cleanup jobs that were silently not working correctly — auto-hiding/deleting old internships, expiring stale pending payments stuck at 'created', and auto-closing resolved tickets.
  • Also fixed a related but different bug in promo code validity: valid_from/valid_until are plain dates with no time component, so comparing them against a full timestamp meant a code set to expire on a given date actually stopped working at the very start of that date instead of the end of it. Codes now correctly remain valid through their entire expiry date.
  • Audited every other timestamp comparison in the codebase using this pattern (23 locations across 9 files) — most (OTP expiry, login lockout, org subscription expiry, internship posting expiry) were already internally self-consistent and did not need changing.
v0.44.0 — Fresher-only 'Internship + Job Upgrade' postings, full profile at registration
2026-08-31
  • New mandatory Posting Type on every internship: 'Internship' (anyone can apply) or 'Internship + Job Upgrade' (only candidates within 1 year of their passout date, either side — e.g. a June 2027 passout is eligible June 2026 through June 2028). Enforced at apply time as a real backend check, not just a frontend hint, with a visible badge on the listing and detail pages. Governed by a new settings toggle.
  • Candidate registration now collects the full profile up front — college (with live search), course, education domain, state, passout month/year, plus optional skills/subjects/bio — instead of leaving it all for a separate profile-completion step afterward. A new candidate can browse and apply for internships immediately after verifying their registration OTP. Organization registration is unchanged.
v0.43.0 — Passout-based eligibility, more chatbot Q&A, profile-health monitoring, troubleshooter drill-down
2026-08-29
  • New required passout month/year on candidate profiles. Search and applications stay open until 1 year after that date — candidates who haven't set it (including everyone migrated before this feature) are never retroactively locked out. Governed by a new settings toggle.
  • 15 new trained chatbot responses covering skeptical, value-proposition questions candidates and organizations actually ask — "what's this for", "what benefit do I get", "is there a guarantee" (answered honestly: no), "why do I have to pay", "is this a scam", and related variants.
  • New 'Profile Health & Verification' box on the Monitoring dashboard — incomplete candidate/organization profile counts and verified/unverified/pending-verification organization counts, all live-refreshing every 45s alongside the rest of the dashboard.
  • The User Troubleshooter now shows payment history for the account (flagging stuck/failed payments), and every notification/payment entry is clickable through to a full detail view — date, status, recipient, subject, full raw content for emails; status, amount, Razorpay IDs, and related application/screening batch for payments.
v0.42.0 — Incomplete-profile reminders, organization verification, location-based posting alerts
2026-08-28
  • New /admin/incomplete-profiles dashboard flags candidates missing name, phone, college, course, education domain, state, or a resume, with a bulk 'send reminder email' action listing exactly what's missing for each person.
  • New 'Verified Organization' badge — an organization can submit CIN, PAN, and admin ID proof for manual review (org.verification). Submission raises a support ticket; admins review the documents and approve/reject from a new Organization Verification queue. Verified organizations now show a checkmark badge on internship listings, the internship detail page, and their own profile.
  • State is now a required field on both internship postings and candidate profiles. When a posting goes live (immediately or via admin approval), every candidate registered in that same state is emailed about it automatically.
  • New settings toggles: 'Email candidates in the same state when a new internship goes live' and 'Allow admin to send incomplete-profile reminder emails' — both default on, independently switchable in /admin/settings.
v0.41.0 — Searchable college & organization directories, real government data
2026-08-24
  • New live-search typeahead on the student profile's College field, seeded with 43,121 real Indian colleges/universities from India's official AISHE government dataset. Still a free-text field underneath, so anything not listed can just be typed and saved normally.
  • New live-search typeahead on organization registration/profile, seeded with a starter list of well-known Indian companies, hospitals, government bodies, and NGOs. New /admin/organizations-directory lets an admin add entries individually or bulk-upload via CSV — the practical path to growing this toward full MCA (Ministry of Corporate Affairs) company registry coverage.
  • Fixed: the admin User Troubleshooter permission was missing from the grantable permissions list, meaning a custom support role could never be given access to it (full admins were unaffected).
v0.40.1 — Admin on/off switch for Google Sign-In
2026-08-19
  • New 'Allow Continue with Google' toggle at /admin/settings, independent of whether GOOGLE_CLIENT_ID/GOOGLE_CLIENT_SECRET are set in .env — lets an admin quickly disable Google Sign-In without touching server files. On by default once real credentials exist.
v0.40.0 — Deeper chatbot FAQ answers, admin user troubleshooter, Google Sign-In for candidates
2026-08-19
  • Chatbot now answers real, detailed FAQ questions honestly — why login/benefits, whether an internship is guaranteed (no, said plainly), refund policy (matching the actual policy's real wording, not an invented one), and concrete troubleshooting steps when something's stuck.
  • New admin user troubleshooter at /admin/troubleshoot — enter a candidate/organization's email or phone and get a real diagnostic report (abandoned registrations, blocked accounts, pending org approvals, missing resumes, active login lockouts, recent notification activity) with a concrete suggested fix for each real problem found.
  • New optional 'Continue with Google' sign-in for candidate registration/login, off by default until GOOGLE_CLIENT_ID/GOOGLE_CLIENT_SECRET are configured. A returning Google sign-in is recognized without creating a duplicate account; an email that already belongs to a password-based account is refused rather than silently linked.
v0.39.3 — Popup ads moved from a centered modal to a bottom-left corner popup
2026-08-15
  • Popup ads no longer show as a centered, backdrop-dimming modal — they now appear as a small, dismissible bottom-left corner popup instead, deliberately opposite the chatbot widget which already occupies the bottom-right corner.
  • The video/iframe-stops-on-close fix from the previous update carries over unchanged in the new layout.
v0.39.2 — Fixed popup ad video/audio continuing to play after the popup is closed
2026-08-15
  • Closing a Bootstrap modal only hides it visually — it never stops an embedded iframe (YouTube/HTML ad) or video (uploaded-video ad) from continuing to play in the background. Now explicitly pauses any <video> and clears any <iframe> src the moment the popup is closed, so playback actually stops.
v0.39.1 — Fixed popup ads never actually appearing
2026-08-15
  • Fixed a real bug: the popup ad's own script ran before Bootstrap's JS had finished loading (Bootstrap loads near the end of the page, after the popup's script position in the document), so it silently failed to show anything — while still marking itself as 'already shown' for that browser tab, meaning it could never display at all once that happened. Now waits for the page's full load event before attempting to show the modal.
v0.39.0 — Chatbot: admin-trained responses can fetch and return real live data
2026-08-15
  • New 'Fetch live data' response type at /admin/chatbot-training — instead of static text, a trained response can point at one of 16 real, reviewed queries (open internship count, a candidate's own applications/quota, an organization's own postings/applicants/subscription/team, admin server health/KPIs/transactions/alarms/tickets) and return the actual, current result for whoever's asking, never the literal instruction typed while training it.
  • Never arbitrary or free-typed queries — admins pick from a fixed dropdown, and every data source declares which audiences it's safe for, enforced at creation time so a candidate-only source can't be mistakenly assigned to an admin or organization audience.
  • A trained response, static or fetch, still can never override a working built-in answer, even with a deliberately overlapping trigger keyword.
v0.38.0 — SMS disabled by default, real image/video uploads for ads, popup ads
2026-08-15
  • SMS is now off by default across the entire app, enforced in two independent layers (channel selection and the actual send function) so no notification, present or future, can send SMS while an admin has it turned off. New 'SMS' toggle at /admin/settings.
  • Homepage ads: admins can now upload actual image and video files instead of only typing a URL, validated by real file content (magic bytes), not just the claimed extension.
  • New 'Popup ads' — any ad can be set to show as a dismissible popup instead of the inline Sponsored section, gated behind its own master switch (off by default) separate from each ad's individual active status.
v0.37.3 — Monitoring dashboard auto-refresh no longer exits full screen
2026-08-15
  • Fixed: the previous auto-refresh used a full page reload, which exits full-screen mode in every browser and can't be silently re-entered afterward (a real browser security restriction). Now fetches the same data as JSON (new /admin/monitoring/data endpoint, sharing one data function with the page itself) and updates the numbers in place every 45 seconds, so a wall-mounted display stays in full screen continuously.
v0.37.2 — Monitoring dashboard auto-refresh
2026-08-15
  • /admin/monitoring now auto-refreshes every 45 seconds (simple full-page reload, visibly indicated on the page). Note: this exits full-screen mode when it fires, since browsers don't allow a page to silently re-request full screen without a real user gesture — flagged clearly for anyone running this as an unattended wall display.
v0.37.1 — RecrIntern logo on the monitoring dashboard
2026-08-15
  • Added the RecrIntern logo to /admin/monitoring's own header, wrapped in a small navy background so it stays legible against the page's light background — placed inside the full-screen target specifically, so it's still visible once the dashboard goes full screen and the navbar (with its own logo) is no longer shown.
v0.37.0 — Chatbot on the public homepage, admin training, better phrasing coverage, monitoring full screen
2026-08-14
  • The chatbot widget now appears on every page for anonymous visitors too, not just logged-in accounts — a new, deliberately narrow public-data-only handler (open internship counts/listings, general platform info).
  • Admins can now teach the bot new responses at /admin/chatbot-training (keywords + a fixed response, scoped to everyone/anonymous/a specific role) — still rule-based, not AI. A trained response only ever fills a gap; it can never override a working built-in answer.
  • Broadened keyword/synonym coverage across every existing intent, plus light text normalization (contractions, extra whitespace) before matching.
  • The monitoring dashboard now has a Full Screen button (scoped to just the dashboard, not the sidebar) with Wake Lock integration to keep the screen from sleeping — built for a wall-mounted ops display.
v0.36.0 — Rule-based chatbot assistant (no AI/LLM) on every page
2026-08-14
  • New chatbot widget on every page for logged-in candidates, organizations, and admin/support accounts — pure keyword matching against real, permission-scoped database queries, deliberately not backed by an LLM.
  • Supports the full 'internships in <city>' -> 'which domain?' -> actual matching postings conversation, plus application status, free-quota, organization postings/applicants/subscription, and admin CPU/KPI/transactions/alarms.
  • Strictly scoped per role: candidates only see public listings plus their own data, organizations resolve through the same shared-team identity as the rest of the app, and admin/monitoring answers are gated by the same permission check the real monitoring dashboard uses.
v0.35.0 — Admin can now delete candidate/organization accounts, with payment history preserved
2026-08-13
  • New Delete action on /admin/users for any candidate or organization account — typed-email confirmation plus a required reason. A permanent record is kept at /admin/deleted-accounts.
  • Payment and invoice history is never deleted along with an account — payments.user_id is now nullable and set to NULL instead of cascading away, so financial records survive account deletion the same way they survive every other delete path in this app.
  • Fixed a related gap found while building this: the admin transactions page used an INNER JOIN to users, which would have hidden a payment entirely from the admin's own list the moment its payer was deleted. Now uses a LEFT JOIN and clearly labels such a payment as '(account deleted)'.
  • Deleting an organization's owner also deletes any team members created under them; deleting a single team member leaves the owner and organization completely untouched.
v0.34.0 — Rejected organization accounts are now deleted, with a permanent audit record
2026-08-13
  • Rejecting an organization now actually deletes the account (org_profiles cascades with it) instead of just flagging it — a full record (email, org name, phone, original registration date, reason, who rejected it, when) is kept at the new /admin/rejected-organizations page.
  • The freed email/phone can be used to register again if whatever caused the rejection gets fixed.
  • The 'Reject' action now only appears for organizations still pending review — never for an already-approved organization — so it can't double as a hidden way to delete an active org through the approval queue.
v0.33.1 — Fixed duplicate-organization registration and inaccurate account status on /admin/users
2026-08-13
  • Registration now blocks a second person from creating a separate organization with an already-used name (case/whitespace-insensitive) — points them toward asking their organization's owner to add them as a team member instead.
  • /admin/users now shows an organization's real approval status (Pending Approval / Not Approved / Active) instead of always showing 'Active' regardless of whether the account can actually be used yet — and a team member's row now correctly shows their owner's organization name instead of blank.
v0.33.0 — Fixed free-quota bug on posting deletion, multi-user organization accounts
2026-08-13
  • Fixed a real bug: closing an organization's posting no longer deletes it (and its applications). Organizations can now only 'Close' a posting — the posting, applications, and screening data are all kept, so a candidate's monthly free-application quota no longer silently resets when a posting they applied to gets closed. Only an admin retains true delete capability.
  • New multi-user organization accounts: an organization's first account (its owner) now requires admin approval at /admin/org-approvals before using the platform. Once approved, the owner can create up to an admin-configurable number of team member accounts (default 4) who share the same organization identity — postings, applicants, subscription, and candidates — with no separate approval needed for those.
v0.32.0 — Clickable monitoring drill-downs, automatic alarms, admin-editable notification text
2026-08-13
  • Every count on the monitoring dashboard (SMTP/SMS sent/failed, transaction success/failed/pending) is now a link into a real filtered detail view, instead of a dead number — including a brand new /admin/notifications-log page.
  • New automatic alarm system: CPU usage, payment/SMS/email failure rate thresholds (admin-configurable) automatically raise a ticket when breached, reusing the existing support ticketing system entirely. Lives in its own dedicated /tickets/alarms view, gated by a permission genuinely separate from regular support tickets.
  • Every email/SMS this app sends (27 distinct notifications) is now admin-editable at /admin/notification-templates, with placeholder documentation and a one-click reset to default. A broken custom edit safely falls back to the default text rather than breaking the send.
v0.31.1 — Distinct sender display names for OTP vs. general emails
2026-08-12
  • Emails now show a display name before the address — 'RecrIntern OTP <no-reply@...>' for verification codes, 'RecrIntern Notification <no-reply@...>' for everything else — so a time-sensitive code stands out at a glance. The underlying address is unchanged either way.
v0.31.0 — Security audit: two real IDOR fixes, plus broader hardening
2026-08-12
  • Fixed a real vulnerability: any candidate could view any other candidate's resume — the route only checked that SOMEONE was logged in as a candidate, not that the file actually belonged to them.
  • Fixed a real vulnerability: any organization could view any candidate's resume for free through the 'own applicants' route, which also completely defeated the paid candidate-search subscription. Both fixes proven with tests that actually attempt the exploit and confirm it's rejected.
  • Resume uploads now validate actual file content (magic bytes), not just the claimed filename extension.
  • Added rate limiting to support ticket creation/replies (previously unprotected).
  • Added a weak-password blocklist at every point an account gets a password.
  • Confirmed no |safe/Markup() usage anywhere — no stored-XSS footguns — and audited ownership checks across every internship/application/ticket-scoped route.
  • Added a Content-Security-Policy in report-only mode (visibility with zero risk of breaking anything), built from the actual external origins this app uses, not guessed.
v0.30.0 — Organizations can delete their own postings, API/SMTP monitoring
2026-08-12
  • Organizations can now permanently delete their own posting once recruitment is done (typed-title confirmation, same pattern as admin's delete). Every applicant is emailed that recruitment has closed, except anyone already marked hired.
  • New 'Integrations & API Health' box on the monitoring dashboard — configured status for SMTP, SMS, Razorpay, Anthropic, and reCAPTCHA, plus real 24-hour sent/failed counts for email and SMS specifically.
v0.29.1 — Admin panel layout: simplified top nav, sections moved to a sidebar
2026-08-12
  • The admin top nav now only shows Dashboard and Log out. Every other section (Users, Internships, Transactions, Subscriptions, Promo Codes, Ads, Monitoring, Tickets, Support Team, Settings, Admins, Staff Roles) moved to a right-side sidebar, shared across every admin page via templates/_admin_sidebar.html.
  • The sidebar is permission-aware, using the same check as the top nav and route-level access control, so a scoped support account only ever sees tabs it's actually been granted.
v0.29.0 — Custom staff roles with per-page permissions, monitoring dashboard
2026-08-11
  • Super admin can now create named roles (e.g. 'Monitoring', 'Ticketing') at /admin/roles, each granted exactly the admin pages checked for it, and assign them to support accounts. Nav bar and post-login landing page both adjust automatically to show only what's granted.
  • Settings, admin management, and creating support accounts stay deliberately non-delegable regardless of what a role grants, to prevent privilege escalation through a custom role.
  • Fixed a real access-control gap this closed: a support account scoped to something other than tickets could previously still view/reply to any ticket by guessing its URL — the internal staff-check only looked at role, not the actual granted permission.
  • New monitoring dashboard (/admin/monitoring) — platform overview, transaction success/failed/pending, application outcomes and new signups (with an honestly-labeled 'abandoned signups' metric, since this app doesn't log failed registration attempts), real CPU/memory usage, and application KPIs.
  • Fixed a real bug in the test suite itself: tests were sorted as strings, not numbers, which silently breaks the moment a suite crosses 99 tests ('test_101' sorts before 'test_72'). Caught by three tests failing when this project crossed that boundary for the first time.
v0.28.0 — Subscription visibility, upgrade path, admin subscriptions tab, invoice alignment fix
2026-08-11
  • Organizations can now see days remaining on their subscription and get an explicit 'Upgrade to Yearly' option when on the monthly plan — upgrading extends from the existing expiry rather than wasting remaining time. A compact status view also shows on the org dashboard.
  • New /admin/subscriptions tab — every subscribed organization, their plan, purchase date, expiry, and days remaining, filterable by active/expired.
  • Fixed: the Kummarod Technologies logo and company seal on invoices weren't aligned — the logo sat visibly higher than the seal. Both now share one explicit baseline.
v0.27.1 — Stale pending payments now auto-expire
2026-08-11
  • A payment stuck at 'Pending' on the admin transactions page meant Razorpay never confirmed it completed (an abandoned checkout) — but nothing ever marked it any other way, so it sat there indefinitely with no way to tell 'recent' from 'abandoned weeks ago'. These now auto-expire to Failed after an admin-configurable timeout (default 24 hours), via the same cleanup job as job-posting expiry and outbox retention.
v0.27.0 — Account blocking, org subscriptions, transactions page, DOB, invoicing
2026-08-11
  • Admin can block/suspend any candidate or organization account with a required reason — blocks login immediately, including force-logging-out an already-active session.
  • Organizations now need a monthly or yearly subscription (admin-configurable price) to proactively search the candidate database — viewing resumes of people who applied to their own posting stays free.
  • New admin transactions page (/admin/transactions) — every payment across the system, candidates and organizations, with totals and filters by status/type/payer.
  • Date of birth is now required at candidate registration (age-validated) and editable from the profile page.
  • Every successful payment now automatically generates a branded PDF invoice — RecrIntern branding, Kummarod Technologies as the billing entity, correct GST breakdown, and the company logo + seal — emailed to the payer as an attachment.
v0.26.0 — Ticket close action, ticket reference numbers, auto-close
2026-08-10
  • Fixed: replying to a resolved ticket was reopening it as intended, but there was no way to actually close a ticket for good — added a separate 'Close Ticket' action. Once closed, no further replies or status changes are accepted from anyone.
  • Every ticket now shows a reference number (e.g. TCK-000123) consistently on every page and in every notification email.
  • Added auto-close: a resolved ticket nobody replied to gets automatically closed after an admin-configurable number of days (default 7, 0 disables it) — runs via the existing cleanup job, no separate scheduled task needed.
v0.25.0 — Built-in support ticketing system, new 'support' user role
2026-08-10
  • Candidates and organizations get a new 'Help' link to raise a support ticket (subject, category, and a threaded conversation) and see their own ticket history.
  • New 'support' account role — genuinely scoped to ticket handling only, not just an admin with a label. Any admin can create one from /admin/support-users. Verified with a real test that checks every actual admin page is closed to it, not just trusting the role check.
  • Tickets auto-assign to whichever support/admin user replies first. Marking a ticket resolved sends the person who raised it a real confirmation email; replying to a resolved ticket automatically reopens it.
  • Caught and fixed two new templates missing their CSRF token before they ever shipped, by proactively re-running the same audit script that caught the ads-page gap last time.
v0.24.0 — Load testing toolkit
2026-08-10
  • Added loadtest/locustfile.py: a safe, no-setup BrowsingUser scenario for testing real anonymous traffic patterns, plus a LoginUser scenario for the full '500 users log in at once' case.
  • Added a controlled rate-limit bypass for load testing (LOAD_TEST_KEY env var + a matching request header — both required, verified with a test that neither alone is sufficient) and loadtest/create_test_accounts.py to bulk-seed real test accounts.
  • Documented the full safe methodology in the README, including why CAPTCHA/OTP/rate-limiting/CSRF all need deliberate handling for a login load test specifically, and why a staging clone is strongly preferred over testing directly against production.
v0.23.1 — Fixed: missing CSRF token on the new ads admin page
2026-08-10
  • admin_ads.html was added after the one-time script that added CSRF tokens to every existing form, so its 4 forms were silently missing the token — fixed, and confirmed working with CSRF actually enabled (not just in the test suite, which disables it).
  • Added a permanent regression test that scans every template file directly for this exact gap, so a future new template with a POST form and no token fails immediately instead of silently passing in tests and breaking in production.
v0.23.0 — Candidate payment acknowledgement, admin-managed homepage ads
2026-08-09
  • Before paying (application fee or AI screening), candidates now see a required acknowledgement that the fee is a platform fee only, not a guarantee of getting the internship — the Pay button stays disabled until it's checked. Doesn't show for organizations paying their own screening batches.
  • Homepage ads are now managed from /admin/ads — supports YouTube videos (any URL format), image+link ads, and custom HTML, with up to 2 ad slots shown at once. The old static/ads/ folder still works as a one-time import source so nothing already in place gets lost.
v0.22.1 — AI interview attention check: fewer false positives, catches real deviations
2026-08-09
  • The camera-based attention flag no longer fires on normal behavior like glancing down to read the question — it now looks for genuinely deviant states: no face detected (camera covered / candidate stepped away) or the face noticeably narrower than the candidate's own baseline (a real head turn), instead of a tight raw-position check.
  • Added debouncing: a deviation now has to show up on two consecutive checks before it counts, so a single blink or bad camera frame is never flagged. A sustained deviation keeps counting periodically instead of firing once and going silent.
v0.22.0 — CSRF protection, rate limiting, security headers, outbox retention
2026-08-07
  • CSRF protection enabled globally (Flask-WTF) — every one of the app's 31 forms now carries a token, proven by a dedicated test that confirms an unprotected request is actually rejected, not just assumed to be.
  • Rate limiting (Flask-Limiter) added to login, registration, forgot-password, and OTP resend endpoints, per-IP — on top of the existing per-email lockout. Also proven with a real test, not just configured.
  • Session cookies hardened (Secure once served over https, HttpOnly, SameSite, 12-hour lifetime) and standard security headers added to every response.
  • instance/outbox/ files (which contain OTP codes in plain text) are now auto-deleted after an admin-configurable retention period (default 2 days), via the same cleanup job used for job-posting expiry.
v0.21.2 — Mobile menu button visibility fix
2026-08-07
  • Fixed: the mobile hamburger menu button was invisible against the dark navy navbar — it was using Bootstrap's default icon meant for light backgrounds. Now uses the dark-background variant, with an explicit white-icon override as a defensive backstop.
v0.21.1 — Footer logo now links to Kummarod Technologies
2026-08-07
  • The "Powered by Kummarod Technologies" logo in the footer is now a clickable link to www.kummarodtechnologies.com, opening in a new tab.
v0.21.0 — Free-quota accuracy, voice-only interview answers, versioning
2026-08-07
  • Fixed: a candidate's first application of the month now correctly consumes their free monthly slot even when they also opt into the paid AI-screening add-on on that same application — previously the add-on charge made the free slot look unused.
  • AI interview: answers are now voice-only (typing removed) — speech-to-text is the sole way to answer each question.
  • AI interview: the "stop listening after ~1 second of silence" behavior was replaced with a 5-second tolerance, with the transcript updating live as the candidate speaks instead of only after they finish.
  • Added this version number + release notes page.
v0.20.0 — Mobile navigation, permanent cache-busting for static assets
2026-08-07
  • Fixed: "Log out" is now a solid, high-contrast button on mobile instead of a subtle outline style, with defensive CSS ensuring the dropdown menu's background and spacing can never cause it to be clipped or blend into the background.
  • Every static asset (logo, CSS, sponsor ads) now carries an automatic cache-busting version tag tied to the file's own last-modified time — fixes a logo update showing correctly on one domain (e.g. www.) but not another (e.g. the bare domain) due to per-hostname browser caching, and prevents that class of bug from recurring on any future asset update.
v0.19.0 — AI interview camera made mandatory (admin-configurable)
2026-08-07
  • Camera access is now required by default before the AI interview's "Start Interview" button becomes clickable, with a clear retry prompt if access is denied.
  • Admin-configurable in Settings → AI interview, in case a candidate genuinely has no webcam.
v0.18.0 — Critical payment fix, full logo asset, mobile-checkout follow-ups
2026-08-07
  • Fixed a serious bug: Razorpay's payment-success redirect could ask the candidate to log in again and leave their application unsubmitted, even though the payment had genuinely succeeded — caused by the browser not sending the session cookie on Razorpay's cross-site redirect. The payment's own cryptographic signature is now used to re-establish the session instead of requiring it up front.
  • Replaced the recreated navbar logo + separately-styled tagline with the actual supplied brand asset, used directly, with a bit of vertical breathing room from the top of the navbar.
v0.17.0 — Job approval workflow, super admin, promo codes, posting expiry
2026-08-06
  • New postings require admin approval before going live (admin-configurable), with approve/reject and a reason shown to the organization.
  • Super admin role: the original admin account can create, promote, demote, and revoke other admin accounts, with safeguards against removing the last super admin.
  • Job postings now have a configurable validity window (default 30/60-day choice at posting time), auto-hide on expiry, and auto-delete 90 days after posting — via a scheduled cleanup job or an admin dashboard button.
  • Promo codes: admin-created or bulk-imported from a CSV dropped in instance/promocodes/, redeemable at the application-fee checkout step.
  • Every email/SMS now saves a local audit copy in instance/outbox/ even when real delivery succeeds, not just failures.
  • Removed SMS notifications for AI interview scheduling/completion (email only).
v0.16.0 — Terms, Privacy, Refund policy, and correct GST handling
2026-08-06
  • Added real Terms & Conditions, Privacy Policy, and Refund Policy pages, with a required acceptance checkbox at registration.
  • GST is now calculated correctly per transaction — CGST+SGST only when the buyer's state matches the company's registered GST state, IGST otherwise — rather than assumed uniformly.
  • Added a company legal/compliance reference document for CA/lawyer review.
v0.15.0 — In-browser AI interview replaces the Twilio phone call
2026-08-06
  • AI screening is now a same-page browser interview instead of a Twilio Voice phone call — no Twilio Voice account or per-minute cost needed.
  • The interviewer reads each question aloud (text-to-speech), with speech-to-text for answering.
  • Added interview-integrity signals: tab-switch detection and an optional camera-based attention heuristic, shown to the employer alongside the score.
  • Added forgot-password (email OTP), mandatory education-domain fields for candidates/organizations, and an admin option to delete or deactivate a posting.
v0.10.0 — Admin panel, AI screening via Anthropic, candidate-paid screening tiers
2026-08-06
  • Added an admin panel (/admin/settings) for OTP on/off, OTP channel, and every price in the app — no redeploy needed to change any of it.
  • AI screening question generation and scoring switched to the Anthropic API (from a keyword-heuristic engine), with a passing score of 35/100.
  • Candidates can now opt into AI screening themselves — bundled at a discount when applying to a paid internship, or as a standalone add-on afterward.
  • Sponsor ads on the homepage now load from a folder — drop files in or out, no code change needed.
v0.5.0 — Password + OTP two-factor authentication
2026-08-05
  • Registration and login now require both a password and a one-time code (email or SMS, admin-selectable), with CAPTCHA on both.
  • Added branding (RecrIntern logo, "Powered by Kummarod Technologies" footer) and the initial homepage sponsor-ad embed.
v0.1.0 — Initial build
2026-08-05
  • First working version: candidate and organization registration, internship posting and search, applications with a free-tier + paid-tier fee model, and Razorpay payment integration.
RecrIntern Assistant