Repository navigation
Releases: LiveHelperChat/livehelperchat
Release list
Standard queue chat priority range for operators
What's Changed
- Added a standard queue chat priority range for operators. The new
chat_min_priority_stdandchat_max_priority_stdattributes limit which chats the regular auto assignment queue can assign to an operator; they mirrorchat_min_priority/chat_max_priority, which only apply to the chat priority queue. Both values are editable in the department assignment window (individual departments and department groups),0means no limit and the values are inclusive. - fix(mailconv): guard against failed fetchAndLock returning false in mail parser and mailing worker by @mysubcult in #2415
Full Changelog: 4.93v...4.94v
Team lead
- Added
team_lead_user_idattribute for operators. Team lead can be assigned in the new/edit user window under the user groups section. The team lead is shown read-only above the username in the operator account page. User list now has a team lead column and a multi-select team lead filter.
execute doc/update_db/update_359.sql for update
Full Changelog: 4.92v...4.93v
MCP Support
What's Changed
Related video manual about MCP setup - https://www.youtube.com/watch?v=PfcDh0JekIk
-
Notable changes since 4.91v
- AI MCP server: added a Model Context Protocol endpoint so external AI clients (ChatGPT custom connectors, Claude, and other MCP hosts) can inspect a Live Helper Chat installation; the endpoint
aimcp/mcpspeaks Streamable HTTP through the officialmcp/sdkPHP SDK and is a thin bridge that only authenticates the caller and forwards the request, while the protocol itself (handshake, protocol revisions, sessions,tools/list,tools/call, JSON-RPC framing, CORS) is handled by the SDK; a new "MCP Setup" screen (aimcp/key, linked from the Rest API page and protected by the newlhaimcp/usepermission) stores the server name and the access token, shows the endpoint URL and the list of exposed tools read directly from the tool attributes so the page cannot drift fromtools/list; the endpoint stays disabled until a token is generated and accepts it either as anAuthorization: Bearerheader or as a?token=parameter (a generated token usesrandom_bytesand comparisons usehash_equals), and allowed CORS origins plus an optional host allowlist for the SDK DNS rebinding protection can be configured through theai_mcp_optionschat configuration. - MCP tools and helpers: eight read-only tools are exposed -
get_user_id_by_email,get_user_id_by_username,get_user_permissions,get_url_permissions,check_user_object_access,explain_chat_access,get_department_auto_assign_settingsandexplain_chat_auto_assign;LiveHelperChat\Mcp\Accessresolves a back office URL into module/view and the permissions it requires with the same logic as the permission explorer (absolute URL, plain path, with/withoutindex.php, with/without siteaccess) and evaluates permissions grouped so that checks in the same group are OR-ed and different groups are AND-ed;LiveHelperChat\Mcp\Rulesdiagnoses object level access for departments, users, chats and canned message replace variables, reporting only identifiers, booleans and generic placeholders (no names, e-mail addresses, chat nicks or message bodies) and can be extended by extensions with the newai_mcp.object_access_rulesevent;LiveHelperChat\Mcp\AutoAssignis a read-only port oferLhcoreClassChatWorkflow::autoAssign()which replays the candidate and gate checks without any write or lock, so it can be run safely against a live installation to answer "would chat X be auto assigned?" or "why was operator Y not auto assigned to chat X?". - MCP sessions and dependencies: handshake sessions are stored in the new
lh_mcp_sessiontable instead of per-request or per-node state, so the endpoint also works on load balanced installations; sessions expire one hour after the last write (the SDK default), a failing query is reported as a missing session instead of turning the endpoint into a PHP error page, and expired sessions are purged by the regular chat cleanup cron so the table stays small;composer.jsongained themcp/sdkandsymfony/finderdependencies,erLhcoreClassSystem::$QueryStringis now a declared property,ezcUrl::parsePathElement()no longer warns when a path element isnull, and the new table is created by the regular database update. - Audit log size protection: audit records larger than the MySQL
max_allowed_packetno longer break the operation being logged - oversized audit messages are truncated to a safe size (16 MB minus a 1 MB reserve for the rest of the query) with UTF-8 safe truncation and a marker showing the original size, and a failing log write is reported througherror_log()instead of propagating up, unlessdebug_outputis enabled so developers still see the error. - Chat transfer to human:
chat/transfertohumannow runs inside a database transaction, loads the chat withfetchAndLock()and locks the department before changing the state, re-validates the chat hash and status after the lock was acquired, and returns a JSON error instead of failing when the chat does not exist or was closed/transferred in the meantime; a missing chat is also handled safely when grouping canned message items, and incomplete canned message replace conditions (missing field, comparator or value) are skipped instead of raising warnings. - Assignment and SQL mode fixes: editing a department operator assignment returns "Assignment record was not found" instead of failing when the assignment record is missing; aggregate queries in the department operator lists (operators, operators group) and in collected survey results set
sql_mode=''so installations withONLY_FULL_GROUP_BYenabled can still list operators and survey results; the operator assignment priority field gained an explanation that it is only taken into account when the department enables assignment by operator priority, otherwise auto-assignment sorts by lowest workload / least recently accepted first. - Bot: the "Update message" bot command can now update the
del_st(deleted status) field of a message, and the bot workflow translation/replace helper guards against a non-object chat. - Widget and operator profile: relative URIs in chat responses are treated as same site links, so they open inside the embedded chat instead of a new browser window; send button and in-progress icons received small padding and alignment fixes; new
--lhc-message-spacingand--lhc-message-group-spacingCSS variables let a theme control the spacing between message bubbles and between message groups without overriding the whole stylesheet; the "job title in new row" theme option is now implemented with CSS classes (op-job-title-sep,operator-profile-content,op-photo) instead of duplicated template markup; the widget React app version was bumped. - Miscellaneous: updated install scripts,
structure.jsonanddb.dbmlfor the newlh_mcp_sessiontable; bumped version to 4.92v.
- AI MCP server: added a Model Context Protocol endpoint so external AI clients (ChatGPT custom connectors, Claude, and other MCP hosts) can inspect a Live Helper Chat installation; the endpoint
-
Summary
- This release focuses on AI tooling for administrators, plus reliability and compatibility fixes.
- A Model Context Protocol endpoint lets AI clients read permission, access and auto-assignment information from an installation through eight read-only tools, protected by an access token and a dedicated
lhaimcp/usepermission. - MCP sessions live in the new
lh_mcp_sessiontable, making the endpoint safe for load balanced setups, with automatic expiry and cleanup. - Oversized audit records are truncated instead of breaking the logged operation, and a failing log write no longer interrupts the request flow.
- Chat transfer to human, department assignments and SQL mode sensitive queries are hardened, and incomplete canned message replace conditions are handled safely.
- Widget links, message spacing and operator profile job titles were polished.
execute doc/update_db/update_358.sql for update
- Treat relative ur is as same site in chat responses by @niels-heinemann in #2410
- Allow self-signed and unverified SSL certificates in Mailconv SMTP transport by @mysubcult in #2413
Full Changelog: 4.91v...4.92v
Restricted replaceable variables
-
Notable changes since 4.90v
- Chat widget CAPTCHA providers: added Google reCAPTCHA v3 and Cloudflare Turnstile support for verifying chat widget visitors through provider-based CAPTCHA validation; CAPTCHA settings gained a chat-specific enable flag and a configurable reCAPTCHA v3 score threshold; a dedicated widget CAPTCHA helper loads the provider script and resolves the token, which is now sent and verified as part of the widget online chat submission; the CAPTCHA settings screen gained a provider toggle and CAPTCHA settings are exposed through the widget online settings endpoint.
- Canned message replaceable variables: added a
configurationfield tolh_canned_msg_replacestoring per-variable JSON options to hide the variable value from the replaceable variables list ("Hide value in list") and to restrict management of the variable to operators holding the newuse_replace_sensitivepermission of thelhcannedmsgmodule ("Restricted access"); restricted variables show a "Restricted" badge, their value and clone/edit/delete actions are hidden from operators without the permission, and access control is enforced in the clone, edit and delete handlers. - Exact counts for chat and mail searches: the chat and mail conversation search panels gained an "Exact count" toggle; by default the result total is capped by counting only the first 1,000 matching rows through new
limit_countsupport ingetCount(), avoiding slow full-table scans on large result sets, and the paginator shows an approximate total ("~") whenever the count was capped; enabling "Exact count" performs a precise count of every matching row. - Bot REST API actions: authentication credentials used for NTLM, Bearer token and API key (header and query parameter) requests now resolve through replaceable variables; authorization headers are masked in debug logs by shortening them from both sides so secrets are not exposed; new user language dynamic variables (
{{user_locale}},{{user_site_access}},{{user_content_language}},{{user_content_language_name}}) were added for REST API bot actions, backed by a newuser_languagemagic property on the chat model; streaming requests gained a configurable row start pattern so response streams that do not use the SSEdata: {prefix are parsed correctly. - Bot trigger arguments: invisible message arguments (
{message_invisible_N}) passed from the widget are now consistently forwarded to every trigger execution path, including theme-based bot trigger execution and the default trigger, by centralizing trigger argument processing early in the widget online submission flow. - Offline reasons for operators: the offline reasons feature now supports operator access control through a new
offlinereasons_operatorpermission that can be granted with limitations restricting operators to specific reasons; the status (online/offline) modal shows a reason selector when an operator goes offline and stores the selection asoffline_reason_id, and only the reasons an operator is allowed to use are exposed in the dashboard and status modal; the permission editor and "who grants" summary show the offline-reason limitation, specific function limitations are now respected over wildcard grants, and offline reasons can be deleted. - Statistics averages: agent statistics averages now include the full result set instead of trimming the highest and lowest ten percent, and preserve fractional values when computing the averages.
- Security hardening: file downloads in incoming webhooks and online-user avatar fetching were hardened against SSRF - only HTTP/HTTPS URLs are accepted,
localhostand private/reserved IP addresses are rejected, the resolved hostname is pinned to a validated IP to prevent DNS rebinding, and redirect following is disabled; message validation and the message preview modal were fixed. - Reliability: the bot "Close chat" command now runs inside a database transaction with row locking to prevent race conditions and partial state updates during chat closure; the mail conversation fetch API returns an error instead of failing fatally when the conversation cannot be found; mailbox syncing now limits SQL statement execution and lock-wait time and sets IMAP open/read/write/close timeouts so a slow mail server cannot stall the sync process.
- Message masking test tool: added a chat-context simulation mode where a chat and a test message are supplied and the tool reproduces the real widget masking flow with step-by-step diagnostics (chat found, guardrails enabled, chat assigned to operator, matching masking rule, operator permission, masking result) using the chat's department, assigned operator and permissions, along with clearer explanations.
- Miscellaneous: added RAR and other MIME type detection for downloaded webhook attachments; added Latvian (
lv_LV) and Estonian (et_EE) translations and updated the translation update script; widened the widget theme custom CSS fields fromtexttomediumtextto prevent CSS truncation; updated install scripts and database structure definitions; bumped version to 4.91v.
-
Summary
- This release focuses on safeguarding sensitive data, richer chat widget CAPTCHA options, and performance tuning for large searches.
- Chat widget visitors can now be verified with Google reCAPTCHA v3 or Cloudflare Turnstile, controlled by a chat-specific CAPTCHA switch and a configurable score threshold.
- Canned message replaceable variables can hide their values from lists and be locked down to operators with a dedicated permission.
- Chat and mail searches gain an "Exact count" option while default counts are capped and marked approximate for large result sets.
- Bot REST API actions support variable-based authentication with masked secrets, user language variables, and flexible streaming row parsing, and invisible message arguments now reach all trigger workflows.
- Offline reasons become permission-controlled, file downloads are hardened against SSRF, and mail fetching, chat closing, statistics averaging and translation coverage were improved.
execute doc/update_db/update_357.sql for update
Full Changelog: 4.90v...4.91v
4.90v Track who set user online manually
- Notable changes since 4.88v
- Track who set a user online: added
online_by_user_idcolumn tolh_users_online_sessionrecording which operator set a user online; online-hours statistics gained a "Set online by" column showing that operator.
- Track who set a user online: added
execute doc/update_db/update_356.sql for update
Full Changelog: 4.89v...4.90v
4.89v Enhancements
-
Notable changes since 4.88v
- Online operators widget customization: added a new "Online operators widget settings" screen under Statistics (
statistic/onlineopsettings) with a newonlineop_settingspermission, letting operators choose which columns appear in the online operators dashboard widget (Name, Status, Last assignment, Live chats/free slots, Department, Reason for offline, Session duration) and their position; the widget now renders the configured columns, shows "offline since" in the name column when a dedicated column is hidden, restores expand/collapse actions, preserves passed column widths and allows controlling widget columns from the embed code. - Track who set a user offline: added
updated_by_user_idcolumn tolh_users_online_sessionrecording which operator set a user offline or online; online-hours statistics gained a "Set offline by" column showing that operator, with the offline action attributed only to the operator who explicitly set the user offline; last visit is now updated when toggling the hide-online status in user edit. - Autoclose enhancements: all autoclose settings now accept fractional timeout values; the activity timeout supports sender-based modes by appending
,1(close only when the visitor sent the last message) or,2(close only when the operator sent the last message) to the configured value; settings descriptions in the chat list configuration were clarified. - Chat cleanup on close:
cleanupOnClose()is now executed when chats are closed via the cronjob or by changing their status (previously it only ran on manual close), removing orphaned records such as auto-responder chat links, bot repeat restrictions, bot chat events, pending bot events, voice/video sessions, transfers, group chats and temporary files; a new utility croncron/util/cleanup_orphan_chats_datacleans orphaned chat data for chats that were closed before this fix, iterating chats from newest to oldest with an optional start chat id parameter. - Blocked users search: added a block type (
btype) filter to the blocked users search covering all block types (IP, Nick, Nick and Department, IP + Nick, IP + Nick and Department, E-mail, Country, Online user, Sender E-mail). - Transfer department window: improved the transfer department window using the searchable multi-dropdown with radio selection and added
on_changehandler support to the multi-dropdown renderer. - Mail conversations: added "Expand all"/"Collapse all" actions to the mail conversation screen for quickly expanding or collapsing all message bodies.
- Message edit history: added a new "Preview message" modal (
chat/previewmsg) and an "Edited" link on edited admin messages opening the preview with the edit history. - Widget filters reset: "Reset widget filters" now clears widget local storage client-side instead of performing a server-side action; fixed a related typo.
- Miscellaneous: added the Isle of Man flag icon; updated install scripts and database structure definition for the new column; bumped version to 4.89v.
- Online operators widget customization: added a new "Online operators widget settings" screen under Statistics (
-
Summary
- This release focuses on dashboard customization and data hygiene.
- The online operators widget becomes fully configurable with selectable and reorderable columns, backed by a new settings screen and permission.
- Online-hours statistics now show which operator set a user offline, recorded in a new
updated_by_user_idfield. - Autoclose rules gain finer control with fractional timeouts and sender-based activity modes, while close-time cleanup is fixed for cron/status-driven closures, with a dedicated script to purge previously orphaned data.
- Search, transfer, mail, and message-preview UX are improved across blocked users, department transfer, mail conversations, and edited-message history.
execute doc/update_db/update_355.sql for update
Full Changelog: 4.88v...4.89v
4.88v Offline reasons
4.88v
-
Notable changes since 4.87v
- Offline reasons: introduced configurable offline reasons with the new
lh_abstract_offline_reasonmodel and CRUD interface; operators can select a reason (e.g. "Lunch", "Meeting") with an icon when setting themselves offline, persisted onlh_usersandlh_users_online_session; offline reasons are displayed in online-hours statistics and user-box menus with a redesigned status control layout; a newofflinereasonspermission controls access to this feature. - Forms module overhaul: added comprehensive search and filtering for collected forms, including department filter, chat operator filter, date range, creator filter, and chat-time search; introduced field change tracking for internal forms — when an operator edits a previously submitted form, field history (old/new values and modifier) is logged; added translation support and improved template variable management for forms; refactored module navigation with proper permission checks and removed deprecated index page; enhanced embed code generation with access control; clearing chat attributes when deleting collected form data now properly reverts associated chat variables and additional data entries.
- Bot enhancements: added secondary translations group support for bots, allowing an optional second translations group in bot configuration with proper validation and item retrieval from both groups; added "Trigger on bot skip" option to proactive invitations, executing triggers when a visitor skips the bot; fixed missing
last_msg_idupdate after sending invitation messages. - Security hardening: refactored CAPTCHA to use browser fingerprinting (combining multiple HTTP headers) and SHA-256 hashing for improved security across chat validation, FAQ, voting, and widget modules; added more detailed CAPTCHA error messages; added
ignoreactivityglobalpermission allowing individual users to opt out of activity tracking; replaced redirect with proper permission-denied page for abstract list views; addedfrom_addressemptiness check to prevent mailbox sync failures on null sender addresses. - Performance and stability: improved MySQL reconnect logic by removing stale connection caching and properly resetting reconnect counters; guarded compiled config caching behind database connection checks to prevent warmup/CLI failures; wrapped
setinactive.phpin a transaction with row locking and addedsyncAndLock()tosetoffline.phpto prevent race conditions on online status updates; addedresetSession()methods across persistent session helpers for clearing cached ezcPersistentSession instances; added server info panel showing address, name, port, software, and uptime in audit configuration. - Admin custom fields: refactored processing to prevent duplicate field values by moving admin fields after JS variable processing and tracking processed identifiers; admin custom fields with
uemptyshow condition are now hidden from returning visitors who already have a non-default nickname set; added support for original author re-modifying fields. - UI and UX: updated Bootstrap badge classes from v4 to v5 (
badge-*tobg-*) across GroupChat, operators template, and mailing import templates; improved assignment configuration UX; translated theme before survey rendering infillandfillwidgetmodules; adjusted naming for less confusion; added server and user timestamps to audit config and login pages. - Miscellaneous: fixed #2400; added support for BOM UTF format files; added avatar caching; added search attribute support for extensions; fixed installer config validation with clearer error messages; refactored
addmsgadmin.phpinput validation to handle missing input gracefully; handled edge database reconnect cases; fixed CAPTCHA time drift validation; ensured dynamic property support.
- Offline reasons: introduced configurable offline reasons with the new
-
Summary
- This release introduces a major new feature — configurable offline reasons — allowing operators to specify why they are offline with visual indicators across the UI and statistics.
- The forms module receives a comprehensive upgrade with advanced search/filtering, field change tracking, translation support, and improved permission handling.
- Bot capabilities expand with secondary translations groups and trigger-on-skip functionality.
- Security is strengthened through CAPTCHA fingerprinting, SHA-256 hashing, and multiple permission/validation improvements.
- Performance and stability are enhanced with improved MySQL reconnect handling, race condition fixes, and guarded config caching.
execute doc/update_db/update_354.sql for update
Full Changelog: 4.87v...4.88v
4.87v Forms flow improvements for Quality Assessment extension
4.87v
-
Notable changes since 4.86v
- Performance and caching: improved dashboard online-operator retrieval with better user-data fetching and caching; prefill departments cache for faster lookups; ensure static cache version is respected across the application even without extensions; optimized chat archive range fetching with cached range checks before database queries, plus methods for matching ranges and verifying chat existence in archives with proper overlap handling.
- Performance statistics: added total offline time tracking to agent statistics widgets with new help modal explaining offline time; updated translations, tooltip descriptions, and column spans in the agent statistics table for improved clarity; enhanced operator performance access checks to include write permissions.
- Webhooks and events: added support for unread-message flow in webhook conditions with checkboxes enabling unread-message handling for admin messages; updated backend logic across message types and enhanced chat update logic to reflect unread-message states for operators; dropped redundant
chat_iddependency. - Mail conversation: enhanced Mail Conversation API and search functionality; added proper API error handling.
- Bot: refactored bot condition evaluation to streamline logic in action buttons and text triggers; updated type casting for threshold values in bot action commands.
- ChatML export: significantly improved ChatML export logic and configuration; fixed properties in exported ChatML; resolved edge cases and format inconsistencies; export script improvements.
- REST API: added support for REST file captions with configurable skip extensions (#2394).
- Template and variable system: added support for
{item:path}syntax enabling nested attribute extraction in output formatting; host values now support replaceable variables; fixed item replacement logic for proper handling of non-string values in templates. - Debug and diagnostics: improved debug invitation logic with detailed checks for message-seen status, timeout handling, and reshown conditions; enhanced debug message view UX, API scroll behavior, spacing, and col-span variables; logs now include exception URLs; added logging for changed user groups.
- Widget and online visitors: dedicated online visitors page now always shows visitors even when the widget is minimized.
- Bug fixes: fixed #2391 and #2395; updated checkbox labels for clarity; trimmed whitespace from messages before saving for data consistency; updated message retrieval limits across components for better performance and consistency; avoided throwing SQL errors in edge cases.
-
Summary
- This release strengthens performance through improved caching strategies (departments, archive ranges, static cache, operator data) and extends performance statistics with offline-time tracking.
- Webhook conditions gain unread-message-flow support, bot condition evaluation is streamlined, and the ChatML export pipeline receives a comprehensive overhaul.
- Template variables now support nested
{item:path}extraction, debug/invitation diagnostics are enhanced, and several stability issues are resolved.
execute doc/update_db/update_353.sql for update
What's Changed
- Allow REST file API for single attachment with caption by @mysubcult in #2394
Full Changelog: 4.86v...4.87v
4.86v Performance widgets
-
Notable changes since 4.85v
- Performance statistics dashboard widgets: added new
dep_performanceandop_performancedashboard widgets that display real-time aggregated statistics for departments and operators respectively; widgets support configurable columns (chats received, chats answered, wait time, first/average response time, thumbs up/down, online/offline time) with configurable position and update intervals; new settings UI under Statistics for both department and operator performance configuration. - Performance stats cron aggregator: new cron job (
cron/stats/performance) aggregates department and operator performance data into the newlh_abstract_performancetable; supports forced regeneration via-p force; configurable update interval and day range; cron respects sql_mode and local timezone settings. - New
PerformanceandPerformanceWidgetsmodels:Performancemodel stores/retrieves serialized performance snapshots;PerformanceWidgetsprovides formatted data for dashboard sync, including per-department and per-operator stats with access-control filtering. - Security and authentication hardening: improved password verification logic in REST API validator; added constant-time response delay in forgot-password flow to mitigate timing attacks; updated hashing methods for login and password update flows; implemented expired hash cleanup (deleteExpiredHashes) called from setRemindHash, remindpassword, and forgotpassword modules; removed LDAP authentication components; updated autologin with nonce support and improved hash validation; masked error messages for users without access to unhidden emails in send and reply APIs.
- Bot and event system: enhanced chat variable update handling and event dispatching; ignored default trigger message when a trigger is started manually; added support for invisible arguments in bot triggers; added event dispatch for transfer-to-human action; added event argument for custom is-online status checks.
- Editor and operator UI: added switch-editor option in active chat tab and a new permission for operators to toggle between new and old editors; added icons and colors to the transfer window; increased subject modal window width; fixed form loading scroll event; avoided null being displayed before a chat starts.
- Export and reports: enhanced export functionality with ChatML support and UI improvements; fixed compatibility with non-strict sql_mode for certain reports.
- Bug fixes: fixed matching rule search; minor fixes including string conversion and typo corrections.
- Performance statistics dashboard widgets: added new
-
Summary
- This release introduces a new real-time performance dashboard with configurable department and operator widgets backed by a cron aggregator and a dedicated
lh_abstract_performancetable. - Security is hardened across authentication flows: stronger hashing, timing-safe responses, expired hash cleanup, autologin nonce support, and LDAP removal.
- Operator productivity is improved with a switchable editor, richer transfer UI, and expanded bot/event capabilities. Export and report compatibility are also addressed.
- This release introduces a new real-time performance dashboard with configurable department and operator widgets backed by a cron aggregator and a dedicated
execute doc/update_db/update_352.sql for update
Full Changelog: 4.85v...4.86v
Contributors
4.85v Security updates
-
Notable changes since 4.84v
- Security and access control: tightened chat operation permissions by requiring proper read/write access checks; additional permission hardening was applied across related flows.
- CSP and policy handling: completed CSP parser integration and follow-up fixes, including policy exposure hardening and parser/library alignment.
- Voice messaging and widget UX: improved voice-message flow and UX, updated voice app behavior, kept cursor focus on desktop, and added a widget-theme option to disable voice messages.
- Translation workflow: improved automatic translation reliability, added DeepL model/formality options, enhanced metadata/error handling, and refined start/stop and old-message translation flows.
- Analytics and timing metrics: improved chat duration/response-time calculations, participant timing accounting, and operator duration output in reports.
- REST API and diagnostics: added optional custom REST API messages, improved exception visibility/traceback details, and enabled direct log viewing from back office.
- Invitations and online-hours logic: enhanced invitation alias/profile handling and improved overlapping online-hours period calculations.
- UI/translations/dependencies: updated translations, refreshed JS dependencies (including html-react-parser migration), and applied multiple package/security updates.
- Misc fixes: delivered issue-specific fixes and regressions cleanup (including #2378, #2379, #2382), plus release workflow updates.
-
Summary
- This release focuses on security hardening, CSP maturity, and operator productivity, while also improving voice messaging UX and translation automation quality.
- It also improves chat/mail timing metrics and diagnostics, with additional stability updates across UI, dependencies, and release automation.
No new DB migration script required for this release.
Full Changelog: 4.84v...4.85v