FF

Author

Form Fuse

AI-Powered

Form Fuse Changelog

All notable changes to Form Fuse are documented here.

Questions or feedback? support@formfuse.in


06/16/26

Improved

Dependencies

  • →Updated AWS SES, Radix UI, and lucide-react packages

06/14/26

Fixed

Login

  • →Password login now sends SSO client_id and client_secret to the token endpoint, matching register and claim flows

06/14/26

Improved

Server logging

  • →Login and API errors now log to console and to LOGS_DIR when configured, including during local development

05/21/26

Fixed

Dashboard and internationalization

  • →Fixed dashboard failing to load after login (infinite re-render from Zustand selector; now uses useShallow)
  • →Configured next-intl default time zone to Asia/Kolkata to eliminate server/client formatting warnings

05/18/26

Fixed

Backend authentication and configuration

  • →Fixed login route to use correct Gateway URL (http://localhost:6999) in development environment
  • →Added AWS SES credentials and AutoMapper license to all backend service appsettings.json
  • →Fixed start-dev.ps1 to launch OAuthServer from correct project path

04/25/26

Improved

Landing page — copy, hierarchy, and conversion

  • →Hero headline rewritten to "Stop building form infrastructure" — outcome-oriented rather than category label
  • →Trust stats line added under hero description: 99.7% spam detection · 0 false positives · works with any frontend
  • →"Free plan · no credit card · up in 5 minutes" anchor added directly below CTA buttons
  • →"Skip the boilerplate" comparison section converted to dark background (zinc-950) for visual rhythm break
  • →All major section headings bumped to text-4xl md:text-5xl for stronger hierarchy
  • →Eyebrow labels (Setup, In practice, Developer-first, Case study) added to each section
  • →"How it works" retitled "Live in 3 steps" with "under 5 minutes" timing expectation
  • →Case study heading rewritten to lead with the stat: "99.7% spam caught. Zero false positives."
  • →Final CTA section: added four-item feature checklist (free plan, no card, any frontend, 5 minutes); secondary button changed from "See how it works" to "Talk to a founder"
  • →Nav trimmed from 8 to 6 items — removed FAQ and Integrations anchor links

04/25/26

Feature

Roadmap page

  • →New public /roadmap page listing upcoming and recently shipped features
  • →Changelog link in header, footer, and dashboard nav replaced with Roadmap
Feature

Two-founder booking on Talk to a Founder

  • →Talk to a Founder page now shows individual cards for Anwar and Geeta, each opening their own Calendly booking flow
  • →Calendly hook refactored to accept a URL at call time instead of a hardcoded constant
Improved

SEO — sitemap, robots, noindex

  • →next-sitemap configured with generateIndexSitemap: false — builds a single sitemap.xml instead of a split index + sitemap-0.xml
  • →robots.ts updated with a comprehensive disallow list covering all private app routes (forms, submissions, integrations, settings, developer, teams, login, register, invite, checkout, blocked, thank-you, /f/)
  • →Stale static public/robots.txt, sitemap.xml, and sitemap-0.xml removed — App Router + next-sitemap are now the single source
  • →noindex added to the protected layout and to login, register, invite, thank-you, and f/[id] route layouts
  • →Changelog page gains title, description, and OpenGraph metadata
  • →Web manifest name and short_name set to Form Fuse
Improved

Landing page response reference

  • →Response reference section rewritten to accurately show /f/ redirect behaviour and /j/ 200/400 responses — removed fictional JSON body

04/18/26

Feature

Expanded i18n — 11 languages

  • →Added Portuguese (pt), Chinese Simplified (zh), Japanese (ja), Russian (ru), Indonesian (id), and Turkish (tr)
  • →FormFuse now supports 11 languages covering ~80% of global internet users
  • →Language preference cookie extended to 1-year expiry so returning users always load their chosen language
  • →hreflang alternate link tags added to every page for SEO — search engines can now serve the correct language to each region
  • →Language switcher in sidebar automatically shows all 11 locales

04/18/26

Feature

Per-form Slack integration

  • →Each form can now connect to a Slack channel via OAuth — legit submissions trigger an instant Slack notification
  • →Full OAuth flow: Add to Slack button → Slack authorization → webhook saved per form
  • →Integrations page at /forms/[id]/integrations — list, toggle enable/disable, and remove integrations
  • →Plug icon button added to each form card on the /forms dashboard
  • →Slack delivery wired inline in FormService.ProcessForm after email send
Fix

Production build fixes

  • →IntlProvider switched from dynamic import() to static imports — fixes Turbopack module-not-found error in production build
  • →Removed ssr: false from privacy, terms, and refund pages — not allowed with Turbopack in Server Components
  • →Fixed missing og:image in Facebook OG debugger — page-level openGraph must always include images field

04/17/26

Improvement

AutoMapper ProjectTo across all list and single-read endpoints

  • →FormsController.List() and Get() now use ProjectTo<T> — queries translate directly to SQL, no over-fetching
  • →SubmissionsController.GetAll() and Get() migrated to ProjectTo<SubmissionModel> with a new SubmissionModel DTO
  • →FormDetailModel.SubmissionCount is now mapped via AutoMapper (Submissions.Count) instead of a separate CountAsync call
New

View Submissions button on Forms page

  • →Each form card now has a "View Submissions" button that navigates to /submissions?formId={id}
  • →Submissions page reads the formId query param on mount and pre-filters to that form automatically
Improvement

Zustand store cleanup

  • →Removed unused activeFormId state and setActiveFormId action from UiSlice — navigation to filtered submissions now uses URL query params instead
  • →Talk to a Founder link removed from dashboard sidebar — it belongs on public pages only

04/17/26

New

Internationalisation (i18n) — 5 languages including Arabic (RTL)

  • →Added full i18n support using next-intl: English, German, French, Spanish, and Arabic
  • →Arabic (العربية) support includes full RTL layout — html dir="rtl", Cairo font, logical Tailwind properties on sidebar and layout
  • →Browser locale is auto-detected on first visit (cookie → browser language → English fallback)
  • →Selected locale is persisted in a server-side cookie for 6 months via POST /api/locale
  • →Root layout reads the locale cookie server-side and sets lang and dir on the <html> tag for correct SSR
New

Talk to a Founder page

  • →Added /talk-to-a-founder — a dedicated page to book a 30-minute call with the founder via Calendly popup
  • →Calendly opens as a popup on "Plan a conversation" button click — no inline embed, no layout shift
  • →Link added to the landing page nav and sidebar under "Talk to a Founder"
Improvement

Public legal pages (Privacy, Terms, Refund)

  • →Privacy, Terms, and Refund pages converted to server components with export const metadata for canonical URLs and SEO meta tags
  • →Translated UI chrome (nav labels, page title, last-updated date, footer) extracted to client components loaded with dynamic({ ssr: false })
  • →Legal prose body remains static English — no large legal blocks in translation JSON files
Improvement

Landing page SSR confirmed

  • →Landing page (page.tsx) is a server component with export const metadata, JSON-LD structured data, and canonical URL — fully crawlable
  • →Interactive child components (PricingSection, FaqSection, CodeTabs, IntegrationTabs) are client islands hydrated after SSR

04/16/26

New

Developer Impersonation Mode

  • →Developers can now impersonate a user account to diagnose support issues — accessible at /developer (gated by has_developer_access on your UserProduct row)
  • →Users can opt in to developer access via Settings → Developer Access toggle (GDPR-compliant consent; off by default)
  • →Impersonation issues a 15-minute short-lived token with no refresh; active session is shown with an amber banner throughout the dashboard
  • →Stopping impersonation or token expiry automatically restores the developer's own session
  • →OAuthServer AdminController (POST /admin/impersonate) only accepts machine-to-machine calls, not user tokens

04/15/26

Fix

Login & Authentication

  • →Fixed login not redirecting to dashboard — API interceptor was calling token refresh with POST instead of GET, causing a 405 and triggering a redirect loop
  • →Fixed middleware blocking /api/proxy/* routes — proxy now bypassed from auth middleware since it handles its own token check
  • →Fixed OAuthServer returning 401 on /connect/userinfo — JWT Bearer scheme was missing; only cookie auth was registered
  • →Fixed DateTime Kind=Unspecified crash when revoking refresh tokens — PostgresEntityContext now applies ValueConverter to stamp all DateTime/DateTime? values read from timestamptz columns as Kind=Utc
Improvement

Login UX

  • →Pressing Enter on the email field now moves focus to the password field
  • →Added Keys enum (src/lib/keys.ts) for type-safe keyboard event comparisons
  • →useShallow applied to all object-returning Zustand selectors to prevent infinite re-render loop in React 19
Maintenance

Security patches

  • →Pinned System.Security.Cryptography.Xml to 10.0.6 in Shared and MemCached packages, resolving NU1901 vulnerability warnings

04/14/26

New

Team Invite Page

  • →New /invite page lets invited users accept or decline team invitations without needing to be logged in first
  • →Invite link in email now redirects to the FormFuse frontend (/invite?token=...) instead of a generic OAuthServer HTML page
  • →Accept and Decline actions update the invite status via the backend API
Improvement

Infrastructure

  • →Removed local SendGridEmailSender registration — email is now handled by SesEmailSender via the shared Skyb framework

04/14/26

Maintenance

Dependency update

  • →Bumped @aws-sdk/client-ses to 3.1030.0

04/11/26

New

Billing — Change Plan & Cancel Subscription

  • →New "Change Plan" modal accessible from the sidebar, top nav, and settings page — shows all plans with monthly/annual toggle; current plan is highlighted
  • →Selecting a paid plan from the modal redirects to /checkout with plan and billing period pre-filled
  • →New "Cancel Subscription" button in settings visible only when the user has an active cancellable subscription
  • →Cancellation confirmation dialog shows next billing date before confirming; calls Paddle API with effective_from: next_billing_period
  • →GET /account/plan now returns canCancel, nextBillingDate, and subscriptionEndDate
  • →POST /account/subscription/cancel backend endpoint added
New

Dashboard & Submissions API

  • →GET /api/dashboard — returns per-user stats: total forms, total submissions, classification breakdown (Legit / LowIntent / Spam), and this-month vs last-month comparisons
  • →GET /api/submissions — paginated submissions list with filters: classification, formId, days (last N days), and custom from/to date range
  • →GET /api/submissions/{id} — single submission detail with parsed JSON data
New

Welcome & Founder Intro Emails (AWS SES)

  • →Switched from Resend to AWS SES for all transactional email
  • →Two emails sent on registration: (1) branded HTML welcome from hello@formfuse.in with 3-step onboarding guide and CTA, (2) personal founder intro from anwar@formfuse.in explaining the no-CAPTCHA AI filtering vision
  • →Founder email is plain-text serif style — personal tone, invites direct replies to anwar@formfuse.in
Improved

Paddle Checkout — Server-Side Token Loading

  • →Paddle client token and environment no longer exposed via NEXT_PUBLIC_ env vars
  • →New /api/config/paddle server route serves credentials at runtime — token never reaches the client bundle
  • →Production Paddle price IDs stored in pricing.production.json; sandbox IDs in pricing.json — selected automatically by NODE_ENV

04/08/26

Redesign

Developer-first Landing Page

  • →Rewrote landing page with a developer-first API product positioning (Stripe / Resend style)
  • →Dark theme with zinc-950 background and syntax-highlighted code blocks
  • →Hero now shows a realistic fetch() code snippet with request/response
  • →Added interactive code examples section with cURL and JavaScript tabs
  • →Removed no-code/form-builder framing; copy now emphasises REST API, webhooks, and JSON responses
  • →New "How it works" cards with numbered steps and inline code badges
  • →Developer experience section with icons highlighting reliability and clean API design

04/05/26

New

Contact Page

  • →Added /contact page with email and website contact details
  • →Contact link in the landing page footer now routes to /contact instead of a placeholder anchor
Fixed

Login Page Prerender Error

  • →Wrapped useSearchParams in a Suspense boundary on the login page to resolve Next.js prerender build failure

03/30/26

New

Teams — Agency Plan

  • →Agency plan users can create teams and invite collaborators by email with Owner, Manager, or Viewer roles
  • →Invited users receive an email with an accept/decline link hosted by the SSO server
  • →After registration, any pending team invites for the user's email are automatically accepted
  • →Account switcher in the sidebar lets users toggle between Personal Account and any team they belong to — selection persists across page loads
  • →Teams nav item appears for Agency plan users and any user who belongs to at least one team
  • →/teams page — lists all teams with role badges; Agency users can create a new team inline
  • →/teams/[teamId] page — Members tab (change role, remove member) and Pending Invites tab (send invite, view expiry); actions gated by role
  • →Role hierarchy: Account Owner → Owner → Manager → Viewer; only Account Owner and Owner can invite or manage members
New

Agency Pricing Tier

  • →Agency plan added: 50 forms, 5,000 submissions/mo, 2,500 AI checks/mo — $29/mo or $23/mo billed annually
  • →Pricing section on the landing page and use-plan hook updated with Agency limits and feature flags
  • →Plan gates throughout the dashboard respect Agency tier (form limit, submission limit, integrations)
Improved

Route Structure

  • →Removed /dashboard prefix from all protected routes — /dashboard/forms → /forms, /dashboard/settings → /settings, etc.
  • →Dashboard home moved to /home; post-login redirect updated accordingly
  • →(protected) route group now holds the shell layout directly — no redundant nesting
Improved

Top Nav & Sidebar

  • →Top nav now shows real user name, email, and initials from the identity store instead of hardcoded placeholder values
  • →Logout button in the user dropdown is now wired up and redirects to /login
  • →Sidebar plan box shows real submission usage with a colour-coded progress bar (green → yellow → red)

03/21/26

New

AppSumo Early Customer Plan — Policy Coverage

  • →Added Section 3 (AppSumo Early Customer Plan) to Refund Policy: $59 one-time for 3 years of Pro access, 14-day refund window via AppSumo, no partial refunds, post-term revert to Free
  • →Added Section 5.5 (AppSumo Early Customer Plan) to Terms of Service: eligibility, included features, 3-year term, renewal at current market price, non-transferability, AppSumo as Merchant of Record
  • →Renumbered subsequent Refund Policy sections (3–11 → 4–12) to accommodate new AppSumo section
New

Refund Policy Page

  • →Added /refund page with full refund policy (12 sections)
  • →Linked from footer alongside Privacy and Terms
New

User Registration

  • →Added /register page with email, password, and name fields
  • →Added POST /api/auth/register route proxying to SSO gateway
Improved

Policy Page UI

  • →Fixed back-to-home button alignment on Refund, Privacy, and Terms pages — icon and label now on the same row
  • →Hover colour on back-to-home button now matches footer link style (hover:text-primary)

03/19/26

Improved

Marketing Copy — Form Backend Positioning

  • →Reframed Form Fuse as a form backend service (like usebasin.com) rather than a spam filter
  • →Updated landing page hero: "Handle Form Submissions Without a Backend"
  • →Rewrote How It Works steps to focus on the form endpoint → store → notify flow
  • →Updated Features section: Drop-in Form Endpoint, Submissions Dashboard, Instant Notifications, Built-in Spam Protection
  • →Updated metadata title, description, and JSON-LD structured data to reflect form backend positioning
  • →Updated FAQ to cover "How do I connect my form?" and "Does it work with static sites?"
  • →Updated Terms of Service section 2 (Description of Service) and section 8 (Spam Filtering Accuracy)
  • →Updated Privacy Policy section 2.2 and section 3 to use form backend language

03/19/26

Improved

App Structure — Route Groups

  • →Reorganised all pages into Next.js route groups: (public) for unauthenticated pages and (protected) for dashboard pages
  • →Deleted legacy flat-layout pages under src/app/ (dashboard/*, login, page, privacy, terms, f/[id], changelog)
  • →Replaced yarn.lock with npm — package manager now consistent with the rest of the monorepo
New

Authentication & Middleware

  • →Root-level middleware.ts protecting all routes by default with PUBLIC_PATHS allowlist
  • →Unauthenticated requests redirected to /login; expired tokens transparently refreshed before the page loads
  • →POST /api/auth/login — proxies credentials to SSO gateway and sets HttpOnly cookies
  • →GET /api/auth/session — reads auth_meta cookie and returns session state
  • →POST /api/auth/logout — clears access_token, refresh_token, and auth_meta cookies
  • →GET /api/auth/refresh — rotates all cookies and redirects to original URL or /login
  • →GET/POST/... /api/proxy/[...path] — catch-all proxy forwarding to gateway with Bearer token injection
  • →useAuthStore (Zustand) with login(), logout(), checkSession(), and clearError()
New

Type System

  • →Ambient Auth namespace in types/auth.d.ts — globally available with no imports required
  • →NodeJS.ProcessEnv augmentation in types/env.d.ts for typed environment variables
  • →.env.development (GATEWAY_URL=http://localhost:5214) and .env.production added
New

SEO & Public Assets

  • →src/app/robots.ts — robots.txt generated at build time
  • →src/app/sitemap.ts — sitemap.xml generated at build time
  • →public/og.png — Open Graph image for social sharing
  • →public/llms.txt — LLM-friendly site description
New

Backend — Spam Detection

  • →ISpamDetectionService interface and SpamDetectionService implementation
  • →SpamDetectionResult model carrying score, label, and per-signal breakdown
  • →Integrated into FormService submission pipeline to gate and flag spammy submissions

03/18/26

Improved

TypeScript Path Aliases

  • →Added @store alias mapping to src/stores/ for cleaner store imports
  • →Added @lib alias mapping to src/lib/ for utility imports
  • →Added @hooks alias mapping to src/hooks/ for hook imports
  • →Updated all existing imports across src/ to use the new aliases

03/18/26

New

Authentication

  • →SSO login via gateway — credentials validated against the OAuthServer using password grant
  • →Three HttpOnly cookies set on login: access_token, refresh_token, and auth_meta
  • →Access token cookie expiry matched to the SSO expires_in value
  • →Refresh token cookie with a fixed 30-day window
  • →auth_meta cookie storing token expiry timestamp, token type, and expires_in for client-side session awareness
  • →POST /api/auth/login — Next.js route that proxies credentials to the SSO gateway
  • →GET /api/auth/session — reads auth_meta cookie server-side and returns session state
  • →POST /api/auth/logout — clears all three auth cookies
  • →GET /api/auth/refresh — exchanges refresh token for new tokens and rotates all cookies, redirects to original URL on success or /login on failure
New

Middleware & Route Protection

  • →Root-level Next.js middleware protecting /dashboard and all sub-routes
  • →Unauthenticated requests redirected to /login
  • →Expired access tokens transparently refreshed via /api/auth/refresh before the page loads
  • →Corrupt or missing auth_meta cookie treated as unauthenticated
  • →Open redirect guard on the refresh redirect parameter
New

API Proxy

  • →GET /api/proxy/[...path] — catch-all proxy forwarding requests to the gateway with Bearer token injected from the access_token cookie
  • →All HTTP methods supported (GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS)
  • →Query strings, request body, and safe headers forwarded as-is
  • →Hop-by-hop headers stripped in both directions
  • →Returns 401 immediately if access_token cookie is absent
New

Auth Store (Zustand)

  • →useAuthStore with isAuthenticated, meta, isLoading, and error state
  • →login() calls /api/auth/login then hydrates meta from /api/auth/session
  • →logout() calls /api/auth/logout and resets all store state
  • →checkSession() rehydrates store from cookie on page load or refresh
  • →clearError() utility for resetting error state before a new attempt
New

Type System

  • →Ambient Auth namespace in types/auth.d.ts — globally available with no imports required
  • →Covers all SSO, cookie, API request/response, and store shapes
  • →process.env typed via NodeJS.ProcessEnv augmentation in types/env.d.ts
  • →nebula-ui TextBox validation props (required, email, url, minLength, maxLength, minValue, maxValue) typed to accept string messages alongside booleans
New

Login Page

  • →Login page wired to useAuthStore — no inline fetch logic
  • →Uses nebula-ui Form component with field-level validation (required, email) handled automatically
  • →Inline server error displayed below fields on failed login
  • →Button disabled and shows "Signing in…" during in-flight request
  • →Redirects to /dashboard on success
New

Environment Configuration

  • →.env.development with GATEWAY_URL=http://localhost:5214
  • →.env.production with GATEWAY_URL=https://gateway.skybin.io
  • →Environment-specific files loaded automatically by Next.js — no code changes needed between environments