Cross-site register now updates the password to the signup value and documents passwordUpdated for storefronts.
Co-authored-by: Cursor <cursoragent@cursor.com>
Let businesses choose product vs store_item sourcing, defaulting from the store module, and expose it on tenant resolve and store-specials.
Co-authored-by: Cursor <cursoragent@cursor.com>
Domain add/edit only upserts Arvan records when updateDns is true, and super-admin user PATCH now accepts firstNameEn and lastNameEn.
Co-authored-by: Cursor <cursoragent@cursor.com>
Support one-time Redis-backed dashboard sign-in handoff and seed European, Middle East, and Far East countries with major cities.
Co-authored-by: Cursor <cursoragent@cursor.com>
Dashboard can download grouped product variants and re-upload to update price and stock. Also expose Content-Disposition for downloads and keep related product/customer API docs in sync.
Co-authored-by: Cursor <cursoragent@cursor.com>
Business settings can store ZarinPal merchant credentials, and the payment registry can initiate and verify ZarinPal alongside Mellat.
Co-authored-by: Cursor <cursoragent@cursor.com>
Tenant zones get an apex ANAME and CNAMEs for www, business, customer, and api without storing origin IPs.
Co-authored-by: Cursor <cursoragent@cursor.com>
Copy static/public into the standalone bundle, point PM2 at server.js, and drop full node_modules after a successful start.
Co-authored-by: Cursor <cursoragent@cursor.com>
Store gateway credentials per business, initiate/verify Mellat at checkout, and resolve old CMS ids from domains in the migrate modal.
Co-authored-by: Cursor <cursoragent@cursor.com>
Public invoices need branding defaultLocale for RTL viewers; customer create aligns with the business add-customer form.
Co-authored-by: Cursor <cursoragent@cursor.com>
Introduce invoices.user_id, business template/invoice APIs, and tenant-domain public URLs so business dashboards can issue invoices without platform-scope template mismatches.
Co-authored-by: Cursor <cursoragent@cursor.com>
Super-admins can assign Admin; owners/admins manage Editor/Viewer via team/access, and the customers list supports all/customers/managers filtering.
Co-authored-by: Cursor <cursoragent@cursor.com>
Sanitize model output to an allowlisted fragment and convert plain/markdown fallbacks so description text stays inside the advanced editor.
Co-authored-by: Cursor <cursoragent@cursor.com>
Prefer the cheapest ChatGPT model that supports our JSON completions, and skip custom temperature for gpt-5/o-series models.
Co-authored-by: Cursor <cursoragent@cursor.com>
OTP already proved phone ownership; treating is_active as a hard block made send-otp succeed while login-otp returned a misleading not-registered error.
Co-authored-by: Cursor <cursoragent@cursor.com>
Adds optional acknowledgeExistingAccount and documents the CELL_EXISTS_OTHER_SITE → SMS link flow for storefronts.
Co-authored-by: Cursor <cursoragent@cursor.com>
Deploy agent waits for build completion, writes status, and checks out origin/HEAD (main or master) so empty-main repos like mashinify can deploy.
Co-authored-by: Cursor <cursoragent@cursor.com>
Expose published customer listings under /tenants/:host/user-products (list, search, details, technical-info) and document them in the website API pack.
Co-authored-by: Cursor <cursoragent@cursor.com>
Per-row ensure and SSL refresh treat storefront as valid only when both names match, and toast messages list each host explicitly.
Co-authored-by: Cursor <cursoragent@cursor.com>
Skip redundant provision on edit, harden TLS hostname checks, and issue apex/business/customer SSL from one endpoint.
Co-authored-by: Cursor <cursoragent@cursor.com>
Append tenant Farsi name to verification SMS, allow optional domain on send-otp, and add SMS_PROXY_* for local delivery via production. Also include websites SSL sync agent/API wiring.
Co-authored-by: Cursor <cursoragent@cursor.com>
Edit Domain can wire deploy_slug the same way as Add Domain so existing businesses get a Deploy button without recreating the domain.
Co-authored-by: Cursor <cursoragent@cursor.com>
Persist deploy_slug on domains, call the websites agent /provision endpoint, and drop the hard-coded host map so Deploy appears from the UI.
Co-authored-by: Cursor <cursoragent@cursor.com>
Expose login-otp and reset-password so dashboards can finish forgot-password and one-time SMS sign-in, and sync website API docs.
Co-authored-by: Cursor <cursoragent@cursor.com>
Expose POST /public/sms/send with API key + domain allowlist for external backends like Balout, wire Meshkee OTP/message sends to Gama, and publish Partner SMS docs on /docs/website.
Co-authored-by: Cursor <cursoragent@cursor.com>
List pages stay cheap by reading ssl_enabled while Nest probes apex hosts in the background; create-business now stores first/last name in both locales.
Co-authored-by: Cursor <cursoragent@cursor.com>
English keys on store/website specials stay unique per business; domain-admin can trigger dashboard SSL sync.
Co-authored-by: Cursor <cursoragent@cursor.com>
Expose branding.defaultLocale, optional user EN name fields, and lightweight dual daily activity for orders/customers; update project context and rules.
Co-authored-by: Cursor <cursoragent@cursor.com>
Reuse the existing user as owner instead of rejecting duplicate cells, so one person can own multiple businesses.
Co-authored-by: Cursor <cursoragent@cursor.com>
Add invoice template CRUD, key points/accounts, public GET endpoint, and migration 039 for account_holder_name.
Co-authored-by: Cursor <cursoragent@cursor.com>
Super admins can manage predefined invoice lines and issue invoices to businesses; schema is ready for future business-scoped use.
Co-authored-by: Cursor <cursoragent@cursor.com>