Every change we have shipped, newest first.
September 22, 2026
0.1.0-beta.23Changed
- The home page is now a drive through a night-time car meet under the Charlotte skyline. Scroll in from above the city, watch the lot fill as cars roll in and back into their spots, and end at the pin.
September 20, 2026
0.1.0-beta.22Changed
- Everything listed under 0.1.0-beta.21 arrives with this release. That one never reached the site.
September 20, 2026
0.1.0-beta.21Added
- Organizers can now boost a meet from its Promote tab. For $3 it sits in the promoted slot on Discover until the meet ends.
- Vendors can say how a meet went and whether they would come back, and organizers see it on the vendor's record.
- Businesses can pay to promote a meet. The organizer decides first, and nothing is charged until they confirm.
- A vendor's record shows the club how their offer performed: opens, claims, and the per-meet trend.
- Every vendor gets a record page for the club: who to contact, whether they are active, and every meet they have backed.
- Vendors see real tap and redemption counts per meet, and confirm their load-in the night before.
- Organizers can browse vendors near a meet, filter by what they do and how far out, and invite one from the list.
- A meet can say it is taking vendors, and a vendor can ask to be there even before a spot is posted; the organizer confirms into a slot or opens one on the spot.
- Organizers can invite a vendor to a slot, and the vendor accepts or declines from their console.
- Vendors can edit their profile and standing offer from the console.
- Vendors booked through way-point now show on the meet page and the club's vendor roster, with their offer.
- Vendors can sign themselves up. Open the vendor page, tell us your business name, what you bring, and your home city, and your console is ready. From there you can ask organizers for a spot at their meets.
- Organizers hear about a vendor's ask as soon as it comes in, instead of finding it later on the Vendors tab.
- Pro clubs can now open up to two vendor slots on a meet. Ultimate still opens as many as you want.
Changed
- Checkout now says what cancelling does and how refunds work, right beside the button. The footer names who runs way-point and how to reach us.
- Pricing, the guides, and How it works now share the home page's look, with one header and footer across all of them.
- The home page is rebuilt around one meet week, from the first post to the score after. You can try an RSVP right on the page and watch the address appear.
- Meet recaps now name the businesses that were actually on the lot, read from the day's real bookings.
- Plans copy across the app now says Pro includes up to two vendor slots per meet.
Fixed
- Discover meets nearby now takes you to the map after you sign in, and the home page says which features need Pro.
- A link to way-point now shows a preview image when you share it in Discord or a group chat.
- The maps on the home page no longer show a map provider's watermark.
- Editing a meet that runs past midnight no longer moves its end before its start.
- Postponing a meet keeps its start time, even across a daylight saving change.
- Meet times read in the club's local time everywhere, including share images, reminders and roundups. Late-evening meets no longer show up on the wrong day.
- Upgrading when you already have a plan now points you to billing to switch, instead of starting a second subscription.
- Starting a new plan can no longer be undone when an old plan ends.
- When opening a vendor spot is refused, the reason now shows next to the button you pressed instead of at the top of the card.
- Your vendor console now shows the meets you have asked to be at, and you can withdraw an ask you no longer want.
- Discover shows every nearby meet on first load, matching the count in its own header.
- Free clubs see the upgrade path on vendor slots instead of a form that errors, Pro organizers can see their two-slot cap, and a failed spot or load-in save now says so.
- The vendor page is findable by search engines, has a way back to your account, and no longer shows developer wording when loading fails.
- Pasting more lines into the mod importer no longer shifts your ticks and edits onto the wrong mods.
- Asking for the same vendor slot again after withdrawing no longer re- pings every organizer.
- The vendor console no longer shows another business's offer, hides a booking when a lookup fails, or offers slots a club already passed on.
- Sponsor tools and the vendor roster are back to Ultimate plans only.
- The vendor console shows your real bookings and open slots now, instead of sample numbers.
Security
- Updated the web framework and the outbound request library to versions that close published security advisories, including a critical one.
August 8, 2026
0.1.0-beta.20Added
- The home page answers the questions people ask most, starting with what the free plan really runs.
- The pricing page compares Free, Pro, and Ultimate side by side, so you can see what changes when you upgrade.
August 7, 2026
0.1.0-beta.19Fixed
- Organizers can print the route card for a cruise they run, without RSVPing to their own meet.
August 6, 2026
0.1.0-beta.18Added
- Organizers now see when traffic slows a cruise route on meet day, and can push a faster road to the pack in one tap.
- On meet day, share where you are with the people going to that meet. You turn it on yourself, nobody else sees it, and your dot goes 60 seconds after your last ping or the moment you stop.
- Season recaps now total the season's cruises: how many, and how far.
- Cruise routes can print a route card: the stops, the order, and the distance on one page.
- Cruise routes now show a turn sheet: every turn, in order, with distances.
- Meet recaps for public meets now draw the planned route on a map.
August 5, 2026
0.1.0-beta.17Added
- A vendor passed over when a club steps down can say they would still come. The club owner sees who is asking, right beside the upgrade button.
- Vendors now hear back in their alerts when an organizer confirms or passes on their pitch.
Fixed
- Vendors now get a clear answer when a club steps down from Ultimate, instead of waiting on a request nobody could see.
- The newsletter now sends exactly what you wrote, to the channels you picked.
August 5, 2026
0.1.0-beta.16Fixed
- Pro pages now stay locked when we cannot check the club's plan, instead of briefly showing Pro content.
August 5, 2026
0.1.0-beta.15Changed
- A club at its member cap turns new join requests down until an organizer makes room or moves up a plan. Nobody already in a club loses their place, and nothing is deleted.
- Meet scores, the season pages, and the meet and season recap links you share now need Pro. We still keep score on every plan, so a free club's numbers are already there the day it moves up. Check-in stays free, and the honor button still records who showed.
- Free now covers one club of up to 25 members. Pro covers three clubs of up to 100 members each. Ultimate has no cap on either. Announcements go out to the same numbers: 25 on Free, 100 on Pro, no limit on Ultimate.
Fixed
- Shared meet flyers now use the way-point typefaces instead of falling back to a plain system font.
August 3, 2026
0.1.0-beta.14Changed
- A build page is titled with its own handle when it has one.
- Calendar entries for a meet's drive now use the same wording as the flyer, recap, and caption.
Fixed
- Maps stop waiting on a slow route provider and draw the straight line after a few seconds instead.
- Long meet titles now fit inside the flyer instead of running off the edge.
- Leaving club setup half-way no longer strands a club or creates a duplicate. Come back and you pick up where you left off.
August 3, 2026
0.1.0-beta.13Changed
- The club page names its sections plainly, and the make filter is a chip you can take off.
August 3, 2026
0.1.0-beta.12Changed
- The Club page reads tighter: tap a make to see who drives it, and a new board ranks the biggest power and torque figures in the club.
August 2, 2026
0.1.0-beta.11Changed
- Section actions like Log a service now look like buttons instead of plain text.
- The build page reads better: power and mods share one card, Share stands out, and the actions you cannot undo sit apart at the bottom.
Added
- See every season side by side: turnout and meets per year, how much the club grew, and how many of last year's crowd came back. Pro.
- Name a build. Give the car what you call it, and the name leads on the build page, in your garage, and on the rolling grid at a meet. Share the link and it leads there too. Leave it blank and nothing changes. A name stays with the car when you hand it over. The handle still clears.
- The Members page is now Club: the roster sits under a free picture of your club, with what everyone drives, the most common makes, and the biggest scene.
- Export a build sheet: the whole spec, the mod list, the power history and the service record on one page, as a PNG or a print-ready PDF, in light or dark.
Fixed
- The number of meets you have been to no longer depends on how old they are. It counts your whole history, for good.
- The onboarding wizard's Back button now only appears once there is a step to go back to, and the header link says what it does: Finish this later.
- The privacy policy says we guard your data without listing how. Naming defences helps the wrong reader and turns a description into a promise.
August 2, 2026
0.1.0-beta.10Fixed
- The member who owns a club can no longer be removed from it, or dropped from admin, by another organizer. Hand the club over first, then make the change.
Changed
- The guide and the privacy policy now say plainly that a meet keeps its full detail today, and that an account keeps working through its 30 day wait.
August 2, 2026
0.1.0-beta.9Added
- Terms of service, in plain English. They cover your account, who owns the photos you post, that meets are run by their organizers and not by us, and how a paid plan renews and cancels.
Changed
- The acceptable use policy now covers how members treat each other, the content you post and still own, an 18 and over rule, and the risk you take on at a meet.
- A privacy policy at /legal/privacy: what way-point collects, who else sees it, how long it is kept, and how to delete your account.
- Sign-in and checkout now link the Terms, Acceptable Use policy, and Privacy Policy, and say them by name. Checkout also shows what a plan costs, that it renews each month until you cancel, and that you can cancel any time from your account page.
Fixed
- Sign-in can no longer be jammed by a burst of traffic, and abuse limits now hold even when a caller tries to dodge them.
- Build photos, meet covers, and push alerts can no longer be pointed at private network addresses.
- Signing out now clears the pages this device kept, so the next person to sign in on a shared device cannot read them offline.
- A mistyped garage link now shows a normal not-found page instead of an error.
- The account page now says plainly that disconnecting a sign-in method does not sign out devices already signed in with it.
- You'll now get a notification when a new sign-in method is linked to your account.
August 2, 2026
0.1.0-beta.8Fixed
- The bell now shows an icon for follow and transfer updates, and route suggestion decisions link back to their meet again.
- Asking to delete your account now withdraws any offers you made to hand off a car, and tells the buyer. Following someone whose account is leaving is refused, the same as a member who doesn't exist.
- A car handed over no longer leaves your upcoming RSVPs still naming it.
- Taking a handed-over build now tells you plainly if it arrives hidden.
- A photo claimed by a hidden build now shows a quiet claimed label instead of a blank one.
- Hidden builds no longer sneak in as the default pick when you RSVP to a meet or claim a photo. With every build hidden, you can still RSVP, and claiming a photo shows a clear note instead of an error.
Changed
- Your plan now sets how many clubs you can run. Free runs 1, Pro runs up to 3, and Ultimate has no limit. Running a club means being an admin or a mod of it. Joining clubs as a member is still free and uncapped. If you already run more clubs than your plan covers, you keep every one of them: the limit only stops the next one.
August 2, 2026
0.1.0-beta.7Added
- Three new guides anyone can read without signing in: what way-point does, how to organize a car meet, and how to run a car club. They are linked from the bottom of the home page.
Fixed
- Fixed the account page crashing on iPhones browsing without the app installed.
- Importing a maintenance note no longer drops a reading written on the same line as its heading, like "Brake fluid: 60,000".
- Sharing a hidden build now shows a quiet note instead of a dead link. A story or mod list that is too long now says which one, and a failed check for hand-over offers shows up instead of looking empty.
- Handed-over builds now show up under their new owner on meet pages, and follow requests no longer error on a bad link.
- Meet alerts push only cover meets again, not follow and build handover updates. Tapping an alert no longer jumps your open tab to the home page.
Changed
- Scanning QR codes at the gate is now a Pro feature. The I'm here button stays free, so a free club still records who showed up and still gets a real meet score.
- Posting a meet to Discord or email now goes by club size. Free posts for clubs up to 100 members, Pro up to 250, and Ultimate has no cap. We count your active members when the post goes out. Some free clubs are already over 100, and those posts will stop until the club's owner upgrades.
August 1, 2026
0.1.0-beta.6Changed
- The account page got tidier. Your picture now sits with your name at the top, the alert switches share one card, and the shortcut buttons that repeated the menu are gone.
- A build's story now sits under its photo as a caption instead of in its own box.
- Adding a mod to a build now opens the new row at the top of the list, so a long build no longer needs a scroll before you can type.
- A build with no handle stays that way. Nothing gets invented from the make and model, so a handle on a garage is always one its owner chose.
- The maintenance log now reads Current mileage, plainly, instead of miles on the clock.
Added
- Paste a maintenance log straight into a build. Headings become the service, readings land under them, and you review the list before anything is added.
- Hide a build until you are ready to show it. A hidden build stays yours to log and edit, and nobody else sees it in your garage, on the club roster, or rolling in to a meet. Flip it back to public whenever the reveal is ready.
- Follow other members to keep up with their builds. A follow is a request, so the other person approves it before you see anything. Turn one down and they are not told.
- Sold the car? Hand the whole build to the buyer. Paste their garage link, they accept, and the mods, maintenance log, power history and photos go with it. Either of you can back out first.
Fixed
- Adding a build no longer duplicates it on retry after a failed save, and a rejected field now says which one.
August 1, 2026
0.1.0-beta.5Added
- Turn on meet alerts from your account page. way-point pings your device when a meet moves, is cancelled, or a new one lands. On iPhone, install way-point to your home screen first.
- A meet's flyer and share post now say the drive: the route name, how many stops, and how far. The stop list and the exact lot stay behind the RSVP.
- A meet recap now names the cruise the meet drove, with its stop count and distance. Anyone you share the recap with sees it, and the stops themselves stay private.
- Put a face to your name: upload a profile picture on your account page. JPG, PNG or WebP, up to 3MB. Remove it and you go back to your initial.
- Tell us something from the guide: send an idea or report a problem, signed in or not, and get a reference back.
- You can disconnect a sign-in provider from Account and keep everything else. Your clubs, builds and history stay. If it is the only way you can sign in, way-point refuses and tells you what to set up first.
- Share a meet to X or TikTok in one tap. way-point writes the caption, draws the poster, and hands both to your phone's share sheet. Copy the caption or save the picture if it does not. An RSVP-only lot never goes in the post.
- Your club's channels get a recap post after a meet, once the photo pool fills up. It counts the shots and the claimed builds, and links back to the recap.
Changed
- Pro and Ultimate lost their coming soon badges. Upgrade straight from the pricing page, and the plan cards now list what each tier really includes today.
- Recap posts are now off until you turn them on. Open club settings to switch them on, and way-point will post one recap to your channels after a meet's photo pool fills.
Fixed
- A build page names its own car's garage again, even when you own more than one.
- Deleting your account now removes the photos you uploaded from storage, not just the pages that showed them. The same goes for a photo you delete: the file is deleted too, and a delete that fails is retried until it works.
- The model picker now finds your truck when you leave out the hyphen. Typing F250 finds F-250, and the list only shows that make's models.
July 31, 2026
0.1.0-beta.4Added
- Cancel your plan from your account, without leaving for anyone else's site. It runs to the end of the period you paid for, and you can resume any time before then.
- Build and recap links now unfurl with a card instead of a bare line of text.
- Share a build as a picture. Pick from four cards: the photo, the spec sheet, the mod list, or the dyno. Sized for a feed post.
- Classics and antiques now suggest too. Older builds pull from a wider list, so a 1976 Honda CB550 turns up instead of nothing.
Changed
- Your plan is yours, not your club's. Buy it once and every club you own gets it. Hand a club to someone else and it runs on their plan instead.
- The power card centres its dials and drops a line that repeated the chart below it.
- The guide now walks through the garage: photos, importing a mod list, power, and the maintenance log.
- The make and model suggestions now cover trucks and motorcycles, not just cars.
Fixed
- Deleting your account now stops your plan, so nothing more is charged. Change your mind inside the 30 days and the plan comes back with the account. Leaving is refused while a club still needs you, and the refusal names who could take it on.
- Adding an older build explains that suggestions only go back to 1981, instead of showing an empty list.
- Save stays in view while you edit a build, so a long mod list no longer buries it.
July 31, 2026
0.1.0-beta.3Changed
- Update power now sets torque as well, without you opening the build editor.
July 30, 2026
0.1.0-beta.2Added
- Update your power straight from the power card. It plots on the chart and lands in your build timeline.
Changed
- A build's power now reads as one card: horsepower and torque as dials, and the dyno history as a line. The figures used to appear twice on the page.
July 30, 2026
0.1.0-beta.1Added
- You can put a photo on your build. Upload one from your phone or computer, or keep claiming a shot from the club photo pool.
Changed
- Replacing or removing a build photo now deletes the old one, instead of leaving it behind.
- You can correct a mod name while reviewing an imported list, before anything is added.
- Adding a build asks for the year first, so the make and model can suggest as you go. The lists scroll now, so you can find your car without typing.
Fixed
- Logging work on a build starts on today's date.
- Removing a build takes you back to your garage instead of leaving you on a page that no longer exists.
July 30, 2026
0.1.0-alpha.20Added
- Adding a build suggests the year, make and model as you type. You can still type anything, so a kit car or a swap goes in exactly as before.
July 30, 2026
0.1.0-alpha.19Added
- The guide now carries every change we have shipped, and you can read both without signing in.
Fixed
- The icons above your name in the sidebar now line up with it.
- The guide has a way back into the app. Opening it used to leave you on the front page with no way back.
- What's new now reaches you. The release notes were never opening for anyone, so if you have missed a few, you will see them on your next visit.
July 30, 2026
0.1.0-alpha.18Added
- Your builds now keep a maintenance log. Log oil changes, filters and fluids by mileage, and set your own reminder for how often each one comes round.
July 30, 2026
0.1.0-alpha.17Added
- Your garage can import a mod list. Paste the note you already keep, tick what it found, and the build fills itself in.
Changed
- The account page is reordered. What you can do sits at the top, your plan reads under your name, and the promoted-meets switch moved down beside the rest of the settings. Sign out is back in the sidebar too.
Fixed
- Your name in the sidebar is shown in full again. It was being cut short to make room for the icons beside it, which now sit on their own row above it.
July 30, 2026
0.1.0-alpha.16Fixed
- Discover keeps the map on screen when there is nothing nearby. It used to swap the map for a line of text, which made a quiet week look like a broken page.
July 30, 2026
0.1.0-alpha.15Changed
- The guide at How way-point works is now walkthroughs. Numbered steps for each job, with a picture of the screen you do it on, and a contents list to jump around. There is a help link in the sidebar too.
July 30, 2026
0.1.0-alpha.14Changed
- Your name in the sidebar now opens your account, where settings and sign out already live. That corner used to say the same thing three times.
Fixed
- If you have no club yet, your account page now points you at what the plans cost instead of showing nothing.
- Trimmed the helper text across the app. Fewer words, and nothing that explains what the screen already shows.
July 30, 2026
0.1.0-alpha.13Fixed
- Starting a club was buried in your account settings, under the section for deleting it. It now sits with your clubs, where you would look for it, and works on a phone.
- The Leaving section of your account was cramped against the edge of its card, and the button to keep your account looked weaker than the one to delete it. Both fixed. If you are a club's only admin, it now takes you straight to that club's members so you can hand it over.
- A brand new account used to open on another club's back office, full of meets and scores that were not yours. Now it opens on meets near you, and starting your own club is one tap away.
- Your club's city is now picked from a list instead of typed. A typo used to leave the club off the Discover map with nothing to tell you, and there are five Charlottes in the United States.
Added
- You can ask to join a club. Open any of their meets and the option is there, under the RSVP. Organizers answer it from the members page. You still do not need to be a member to roll in.
July 29, 2026
0.1.0-alpha.12Fixed
- The blurred strip behind the status bar was missing in some browsers.
July 29, 2026
0.1.0-alpha.11Added
- You can ask way-point to delete your account. It is disabled straight away and removed for good after 30 days, so you can change your mind.
July 29, 2026
0.1.0-alpha.10Fixed
- Signing in with Google or Discord works again.
- If signing in fails, way-point now tells you what happened and what to try, instead of showing a bare error page.
July 29, 2026
0.1.0-alpha.9Added
- Meets now have a share image, so posting one somewhere shows the meet instead of a bare link.
- Clubs can show their Instagram on a meet, so anyone who finds the meet can find the club's feed.
July 29, 2026
0.1.0-alpha.8Added
- Groundwork for paid plans. Nothing is charged yet, and every club stays on the free plan until it is switched on.
Fixed
- way-point opens in light or dark to match your device. It always opened dark before, whatever your device was set to.
July 29, 2026
0.1.0-alpha.7Added
- A weekly roundup post. Turn it on and way-point posts your club's channels once a week with what is coming up, plus one nearby promoted meet if you want to carry it. Off until you turn it on, and the promoted line always says it is promoted.
- Boost a meet. Pay a few dollars and your meet shows up in its own labeled spot beside the map results. It never changes the order of what people find: that stays distance and fit. Members can turn promoted meets off in Account.
- Sign in after we ship something and you get a short note about what changed, once. Everything we have released stays at What's new in the sidebar.
- The composer shows meet-day weather. If rain or cold is going to thin the lot, you see it while you are still planning, and one tap pushes the meet a week. Forecasts come from the National Weather Service, so they cover the US.
- Builds have a timeline. Log what you did and the day you did it, and your build page reads as a story instead of a parts list. Dyno days carry the figure, and once you have a few the power history draws itself. Your builds only: everyone else's is read-only.
- Vendor booking, for real. Organizers open the spots they actually have on a meet, vendors ask for them, and the organizer confirms or passes. Confirming books the spot and answers everyone else who asked, so one spot is never promised twice. A booked vendor sees the load-in, the spot, and the note the organizer wrote, instead of numbers the app made up.
- Discover tells you which meets are your kind of meet. Each card can carry a small match dial and one line saying why: the vibes you turn up for, whether people you have rolled with are going, and how full the lot is getting. Sort by best match when you want fit instead of distance, and set how far to look with the new radius slider. Never RSVP'd to anything yet? It reads the clubs you are in instead, and says so. The reason line never names another member.
- Ended meets age into numbers. A meet keeps full detail for a year. After that, who RSVP'd and who checked in is deleted, and the counts move onto the meet: cars, fans, waitlist peak, how many showed. Shots nobody claimed are cleared, which is what claiming is for. The meet, its recap, its season numbers, and the organizer's venue confirmation are never deleted. Set the window with RETENTION_MONTHS, and see what a pass would do first with RETENTION_DRY_RUN.
- Members can suggest a change to a rally route. Send the organizer a note, and a stop if you have one in mind. Nothing moves until an organizer approves it. Approving a suggestion with a stop adds it to the route, and the member who sent it hears back either way. The people driving the cruise know the road; now they have somewhere to say so.
- A plain guide to how Waypoint works, at /help and in docs. It covers meets, who sees the address and when, RSVPs, garages, rallies, check-in, scores, photos, announcements, roles, and plans. Public on purpose: someone deciding whether to RSVP can read how the address rule works before they do.
- Calendar entries name the cruise. Save a meet that has a rally and the entry now says the route, how many stops, and how far, so it reads like a plan instead of a time and a place. It never carries the stops themselves: a calendar file leaves the app and cannot be taken back.
- A club now hears when its card fails. Stripe retries for a while before it cancels, and that window used to pass in silence: the first sign was features disappearing. The account page now says the payment did not go through, with the button to fix the card, and says nothing has changed yet, because nothing has.
- A security policy, so anyone who finds a way to read a gated meet's address knows where to send it.
- Waypoint now sends the day-of reminder it always promised. The composer used to post everything the moment you pressed the button and then tell you a reminder was queued, when nothing was scheduling one. Each connected channel now gets a reminder booked for the morning of the meet, in the club's own timezone, and the composer shows you when it will go. Cancel the meet and the reminder does not send.
- Sign-in, the waitlist, and address lookups now carry per-caller limits. They are the surfaces the web app answers itself, so nothing bounded them before: a script could hammer sign-in or run up our geocoder for free. The caps are loose enough that a real person never meets one.
- Paying clubs can manage their own billing. The account page opens Stripe's portal to change the card, switch plans, cancel, or read invoices. Cancelling there moves the club back to free through the same webhook that upgrades it, so leaving never needs an email to us.
- The upgrade buttons are real. Pressing one opens Stripe Checkout as soon as payment keys are in place; until then it says so and offers the waitlist, and it tells a member to ask an admin instead of showing them an error. Nothing to change on the day billing turns on.
- The gate can run itself overnight while GitHub Actions is off. `script/nightly` runs the tests, both production builds, the docs score, and the browser suites, then files or bumps the nightly-red issue when something breaks. `script/nightly-install` puts it on a daily timer. Dependency audits report without turning the run red, since a nightly that cries wolf gets ignored.
Changed
- Signing in by emailed link is gone. It never worked, and leaving it on the page promised something the app could not do. Google and Discord both work.
- way-point now runs from Virginia, closer to the clubs it serves.
- Setting way-point up on a new host is now a written checklist instead of a guess.
- way-point now has one home on the web. The whole app runs on a single host, so the parts talk to each other privately and nothing but the app itself is reachable from the internet.
- Shipping a release now runs the full test suite first and stops if anything fails, so a broken build cannot reach anyone.
- Discover fits more meets across the page on a wide screen, instead of two cards with room to spare. It picks the number of columns from how much space there is, so nothing gets squeezed.
- Cards hold their facts in plain rows now, split by a thin line, instead of grey boxes inside boxes. Rally cards, the RSVP panel, meet scores, and the home page all read cleaner.
- Recap cards you share keep their dark look in both themes. They are made to be posted, so they should look the same to everyone who sees one.
- Green buttons are brighter in light mode, and easier to read on, not harder.
- The promoted column on Discover is narrower.
- Light mode runs on a white page now. Cards are drawn by a thin edge instead of sitting on grey, and grey moved to where it works on white: chips, pills, and fields. Every view was checked, on a computer and on a phone. Dark mode is unchanged.
- Each promoted meet is its own card now, and it highlights amber to match its label and its map pin.
- Promoted meets are easier to spot. They sit in a ranked column beside the map results on a computer, at the top of the list on a phone, and their map pins are amber instead of green.
- The landing page no longer says "no ads", because a club can now pay to promote a meet. It says what is still true instead: no feed to scroll, and nobody selling your data.
- The app is now called way-point, and it lives at way-point.io. Same product, same green pin.
- Discover's map controls sit in one line with the meet count, instead of stacked under it.
- The vendor console lists slots an organizer actually opened. It used to offer every meet you were not already at, whether or not that club wanted vendors.
- Notifications clear on a button, not on opening. Open the bell and your unread items stay unread until you press "Mark all read", so you can glance at one thing and come back to the rest.
- Discover's range and sort moved onto the map. The range is a chip that says how far you are looking, and sort is now two named choices, Closest or Best match, instead of a checkbox that only named one of them. Both sit with the other map buttons, and phones reach them without opening filters.
- The issue tracker now sorts by what can actually be worked on: milestone 1 is everything buildable today, milestone 2 is everything waiting on an account, a domain, or counsel. The old phase milestones are retired.
- Season turnout counts fans, not just cars. The chart now draws people who came without a car alongside RSVPs and check-ins, on the same axis, so a meet that drew a crowd no longer reads as a quiet one. Each count on the upcoming-meet panel opens the roster behind it.
- Pro badges now open a panel that says what the tier costs and what it adds, with the upgrade button right there. They used to be decoration, or a link that dropped you on the pricing page and lost whatever you were doing. The three places that listed plan features now read from one source, so they cannot drift apart.
- Rally mileage follows real roads. The map has drawn the driving line for a while, but the miles beside it were still straight lines between stops, which undercounts every cruise: the Lake Norman route reads 39.8 miles now instead of 27.9. Routes saved without a working router still fall back to straight legs, and the card says which number you are looking at.
- The dark map now looks like the rest of the app. Stock Mapbox dark is a cool grey, so the map read as a rectangle pasted onto the page. Discover and rally maps repaint it in the app's warm near-black, with roads kept just as readable as before. Light maps and the satellite editor are untouched.
- The hosting cost plan now reflects the Mapbox move. The old $25 tile line is gone, since map loads sit inside the free tier and routing is cached server-side, so the growth estimate drops from $149 to $124 a month.
- The garage is an index of builds now. Each build gets a small card with its photo, how deep the build runs, and a dial showing its power. Click one to open its own page with the spec sheet, the story, the mod list, and the whole log. A garage with ten cars reads as fast as a garage with one.
- Power reads as a dial on the card, so you can compare two builds at a glance. The build page charts every dyno day behind it, oldest to newest, and says how much the car has picked up.
Fixed
- way-point now opens in light or dark to match your device, the first time you visit. It always opened dark before, whatever your device was set to.
- Sign-in no longer breaks entirely when one login option is only half set up. Sign in with Google or Discord.
- Sign-in no longer breaks entirely when one login option is only half set up.
- The site now starts up correctly when hosted, and saving a change works from the real address instead of only in local testing.
- An urgent fix made straight to the live site can no longer be lost by the next release.
- The first deploy no longer fails partway with a database it cannot reach.
- The deploy setup no longer stops partway through with a settings error.
- The deploy setup no longer fails on its first run.
- Fixed a console error on every page after closing What's New.
- The search box in the sidebar is visible again in light mode. It was the same white as the panel it sits in.
- Sign-in fields, rally cards, and the panels on the home page have clear edges in light mode instead of soft grey shapes.
- Discover's meet cards are full width again. They had collapsed into a narrow strip on the left.
- Light mode is easier to read. The page is a lighter grey, cards lift off it, and chips and pills no longer blur into one band. Dark mode is unchanged.
- What's New stays closed once you close it. It was coming back every time you opened a different page.
- Moving a meet to a new time tells everyone who RSVP'd. It only ever told them about a new place, so people turned up on the old date.
- Map buttons are readable on a dark map again. They were tinted with the page background, which is the same shade as the basemap, so they read as floating text with no edge.
- Patched a tar flaw in the build tooling. It was a crash bug in the Capacitor CLI's dependency tree, never in the served app.
- The season chart counts people who actually checked in. Check-in writes arrival records, and the chart was reading a separate column nothing filled in, so a club that scanned every car still saw a zero.
- The readability checker scores app copy again instead of code. It read TypeScript generics as HTML tags, so hook declarations and style strings were being graded as if they were sentences. Two screens that were failing the check were only ever failing on their own source code.
- The env sample lists every setting the app reads again. Seven had gone missing, so a fresh clone ran with silent defaults and no hint the settings existed. A test now fails when the sample and the code drift apart.
- The API no longer implies it is reporting errors when it is not. Setting a Sentry key made it log that reports would flow, and nothing was sending them; now it warns that errors are being dropped, and says so again each time one is. The web app logs failures with or without a key, where before it swallowed them when none was set.
- A reminder can no longer be lost to a crash or a deploy. If the server stopped between picking a post up and sending it, that post sat unsent forever and nothing said so. Interrupted sends are now picked back up, shutdown waits for a send in progress, and after an outage the queue skips reminders for meets that already happened instead of announcing them late.
- The drift checker can no longer be fooled by a line break. It read docs one line at a time, so a retired claim that wrapped across two lines slipped past it, and one had.
- Discover says "1 meet" instead of "1 meets".
- The dark map now really is the Waypoint dark map. The styling shipped but never ran, so every map has been wearing stock Mapbox colours: the repaint waited on an event that had already passed. Maps now match the app's warm near-black, roads stay as readable as before, and the route line keeps its green.
- The gate now catches a half-regenerated API contract. The Go side was checked and the TypeScript side was not, so a forgotten command could leave the web app's types describing an API that no longer existed, with everything still compiling.
- A shipping build of the iOS app can no longer point at localhost. It used to be the default, so a build that forgot to say where it points installed fine and then showed a blank screen with no explanation. A release build now has to name an https address, and cleartext follows the address instead of always being on.
- A database problem no longer looks like missing data. Eight reads threw their error away and returned a zero, so an outage showed up as a club with no season, a garage with no cars, or a benchmark for the wrong city, and nothing was logged. The composer had the same bug in a worse place: it reported a successful send when it could not read the club's channels.
- Two pieces of CI that would have gone wrong the day Actions comes back: red runs now attach the failing run's screenshots instead of the committed reference images, and the secret scan no longer trips over a dummy check-in code in a test.
- The Mapbox token now appears where people look for it: the env sample a fresh clone copies, the deploy env table, and a maps section in the setup guide. A new machine used to land on the keyless fallback with nothing to say the real map stack existed.
- The docs finished the move to Mapbox. The architecture diagram shows the real map and routing dependencies, the agent guide no longer describes the old Leaflet stack or the retired timed pin drop, and the drift checker now watches that guide too. The 12-month projections pick up the lower hosting line, which moves the burn to $824/mo and puts break-even on the April-May 2027 line.
Security
- Rally routes now follow their meet's location rule. The stop list is the address written out, but a member could read the stops of an RSVP-only meet from the rally directory without RSVP'ing. Gated routes now show their name, length, and stop count, and the stops appear when you RSVP, the same moment the address does.
- The routing proxy can no longer be used to run up a bill. Map coordinates are snapped to a metre before they become a cache key, so a caller cannot dodge the shared cache by adding decimals, and each caller gets a cap on how often they can reach the router. Routing can also use its own server-side key now, separate from the map key that ships to browsers.
- Claiming a photo now needs club membership. A signed-in stranger could claim photos in any club's pool, and because a claim moves, that took the photo off the member who had it. The organizer-only photo actions also check who is asking before they check the club's plan, so a stranger can no longer learn what a club pays for.
- Discover no longer gives away the exact spot of an RSVP-gated meet. The map pin was blurred to about a kilometre, but the distance shown next to it was measured from the real address, so a few lookups from different points could work backwards to it. Distance now comes from the blurred pin. Public meets are unchanged.
- Next.js moves to 16.2.11, which clears nine advisories against the web app, including a denial of service in the App Router that our server actions were exposed to.
- The API's OpenAPI library moves to 0.144.0. The advisory behind it never applied here, since our request validator always demanded a signed token, but the version was worth taking anyway.
July 24, 2026
0.1.0-alpha.6Fixed
- Killed the silent navigation killer: rally preview maps were stuck in an invisible re-render loop that kept the app router too busy to commit link clicks, so pages sometimes refused to change. The road-line hook now keys on content, and the browser suites write their screenshots outside the repo so the dev watcher never restarts the router mid-test.
Added
- Rally organizers can have the route chosen for them. On a two-stop route, "Suggest a route" fetches up to three traffic-aware road options with time and distance; picking one pins it to the route as a handful of our own via points, so no provider geometry is ever stored. Drawing stop by stop stays the default, and editing stops clears the pin.
- The maps moved to Mapbox GL: dark and light styles on Discover and rally maps, real satellite imagery in the parking editor, and route lines that follow live traffic-aware roads. Tokenless environments keep the old stack, and all routing now flows through one cached server endpoint so paid usage stays near zero. Recorded as the maps decision in docs/DECISIONS.md; closes the unlicensed-routing gap.
July 24, 2026
0.1.0-alpha.5Added
- Rally route maps draw the driving line along real roads between stops, with a straight-line fallback when the router is out. Seed rallies now cruise famous Charlotte stops with real addresses: NoDa, Birkdale Village, Ramsey Creek Park, the Whitewater Center, Crowders Mountain, and a Camp North End to Charlotte Motor Speedway parade lap.
- Organizers scan attendee QR codes with the camera now. The live check-in card opens the rear camera, decodes the code, and checks the car in through the same path as typing. No camera, or a blocked one, falls back to the manual field. The card also captures the gate: an arrived count against expected entries and a "Here now" list that updates with every scan.
- The rally editor's address field now suggests places while you type. Suggestions come from Photon (built for live lookup; the public Nominatim host forbids it) and lean toward the meet's own area, so "Optimist" finds Charlotte before Ontario. The Find place button still runs the full search.
- The market analysis records Rollout (rollout.club, iOS beta) as the closest live competitor: an enthusiast private social network with convoy RSVPs, build logs, and shop messaging. The analysis draws the organizer-side vs member-side split and flags member social as our thinnest surface.
- The market analysis names its two live neighbors: RevMatch (show-day ticketing and ops) and PullUp (meet discovery), with the case for why the club operating system is still an open category and the ticketing collision to watch.
Changed
- The landing page copy went benefit-first: "Set it up once. Waypoint runs the rest." leads, each section says its one promise in plain words, and the channel mechanics moved out of the hero. The honest split between live sends and post kits stays.
- The landing page reads in full sentences again (the staccato fragments did not land), the location-reveal section gave its slot to the garage ("Every build gets a page."), rallies got their own section with the app's route map ("The drive is the event."), and the meet-score section now sells the season: trends, show rates, and planning more of what works.
- The landing page shows the real app now. A new Discover section renders the app's own map and meet card in a phone frame ("Every meet. On the map."), the meet-score graphic is the app's actual season chart, and the hero preview matches the meet page: rolling in builds, calendar, share, and reminders.
- The hero headline covers one-offs, not just series: "You bring the cars. Waypoint runs the meet." The prose across the page took an Apple-style pass: short beats, one promise per line. The RSVP-reveal chip left the hero (reveal is simply how RSVP works now) and social post kits took its place.
- The edit-meet page folded its six-card right column into four tabs: Attendees, Parking, Rally, and Promote. Deep links to the rally editor still open the right tab.
- Check-in left the edit page. When a meet goes live, organizers get the check-in card on the meet page itself, from an hour before rollout until two hours after the posted end.
- The Attendees roster grew into its tab: it now uses most of the screen instead of a short scroll box sized for the old six-card stack.
- The market analysis names the audience split: show-scale tools serve gated, staffed, SEMA-scale events; Waypoint serves the homegrown organizer running cruises, lot shows, and weekly meets with no gate at all.
Fixed
- The landing's season graphic is now the real thing: the shareable season recap flyer the app auto-builds, with a sample season behind it, instead of a chart.
- The landing's season graphic switched again, to the post-meet recap card: score, would-show-again, the loudest crowd note, and the "You said, we did" fix. The anti-feed manifesto band left the page; its spirit lives as one line under the closing button: "No feed. No ads. Just the meet."
- The rally section sells the point: setting up a cruise takes minutes and nobody gets lost between the rollout and the finish. The season graphic grew a longer trend line and a row of season headlines: turnout growth, show rate, best meet.
- A stalled route lookup no longer hangs page loads: the road pathing request aborts after six seconds and the map falls back to straight legs.
- The API's read rate limit gets 10x headroom outside production, so dev browsing and the e2e gate stop tripping 429s through the shared demo users. Production keeps the tight ceiling.
- Drawn parking zones are fully editable on upcoming meets: select a zone and drag its corner handles to reshape the polygon. Zone rows also went two-line, so the label and note inputs get real width instead of collapsing to slivers.
- The map zoom buttons dropped Leaflet's stock white chrome for the flat overlay style: translucent surface, ink glyphs, no borders, matched in dark and light themes.
- The member shell now marks Pro pages the way the organizer shell does: amber Pro chips on Rallies and Photos in the rail, and a Pro badge on the home Rallies card. Members of free clubs already got the blurred upgrade gate on those pages; now the nav says so before the tap.
- Discover location services work now. The iOS shell asks for location permission (it silently denied before), the map shows your dot on load when you already allowed location, a denied or failed locate says so instead of doing nothing, and the dot got an accent style plus a GPS accuracy halo. Locating zooms the map to a 10 mile radius around you, like Apple Maps.
July 23, 2026
0.1.0-alpha.4Changed
- The discover hero left the member home everywhere: the Discover tab and rail entry are one tap away, and the meets-near-you glance tile keeps the scent. The next-up meet now sits nearly above the fold on phones.
- The member home's coming-up cards use the shared meet card on phones too (title, capacity bar, RSVP, calendar), and meet pages opened while signed in carry the mobile back nav home like every other drill-in.
- The member home's coming-up cards on desktop are now the same meet card Discover uses: title first, date and spot as metadata, the capacity bar with spots left, and a visible RSVP button with calendar actions. One card style everywhere.
- The member home on desktop opens with a fuller at-a-glance card (upcoming meets, next meet date, meets near you join the stats) and drops the discover banner and club selector; the rail covers both. Coming-up cards gain the meet title, spot, and open-spot count. Phones keep the banner, the selector (their only club switcher), and the settled compact layout.
Fixed
- The mobile-nav browser suite regains the phone meet-card and meet-page back-nav checks that a cleanup step dropped from the #375 commit.
- The member home reads cleanly at desktop widths: the club select is compact, the discover banner went neutral so green flows once into the next-up card, and the rallies card is phone-only (the rail links it on desktop). Phone rendering is untouched.
July 23, 2026
0.1.0-alpha.3Changed
- Light mode moved to cool, neutral grays (near Apple's light surfaces) in place of the warm tan. The green accent gains contrast on the new ground; dark mode keeps the warm garage palette.
- The command palette is desktop-only now. Phones drop the Search tab (a palette is a keyboard idiom), leaving Club, Discover, and You in the tab bar. Desktop keeps the sidebar search and the ⌘K shortcut.
- The Discover sheet on phones lost its chip rail: the counted Filters button is the one filter surface, and cards start one row higher.
- Discover on phones is now map-first. The map owns the screen, panning it narrows the list, and the meet cards ride in a draggable sheet (peek, half, full). Filters moved behind a counted Filters button with a sheet; one chip row stays for quick picks. The old layout trapped page scrolls on the embedded map. Desktop keeps the pill row, inline map, and card grid.
- Mobile tab roots are now drill-in hubs, the iOS pattern from the HIG. Club, Dyno, and Community each open a hub page that lists its sections with live counts; tapping a row pushes the section, and a back link (or the edge swipe) returns. The chip row above page titles is gone. Desktop keeps its sidebar.
- The mobile tab bar slimmed to four tabs: Club, Discover, Search, and You. Dyno and Community fold into the Club hub as labeled rows that keep their tier chips and live counts.
Added
- Members can browse rally routes now: the API opens the list and route reads to any club member (writes stay with organizers), the member home links the season, and route pages hide the editor. They drive the rallies, after all.
- A club switcher on phones: the Club hub title opens the same club menu the desktop sidebar has, with roles, pending counts, and quick actions. Organizers of several clubs were stuck in one club on mobile before.
- A status-bar scrim in the iOS shell: content scrolling under the clock and dynamic island now passes behind a progressive blur, so both stay readable. Plain browsers never see it.
Fixed
- The member tab bar now leads with Home, matching the organizer bar's home-first order.
- Club selector rows stopped labeling each club with your own role; they show member count and the next meet.
- Five mobile shell defects: active section chips now keep their Pro tag, the You tab glyph matches its neighbors, badges no longer wrap or stretch out of their pill, the garage header names two clubs and counts the rest instead of crushing the line, and the club roster no longer side-scrolls the page on phones.
July 22, 2026
0.1.0-alpha.2Added
- A session hardening review and a data inventory. Sessions now cap at 14 days with a daily rolling refresh, set explicitly in `apps/web/auth.ts` and pinned by a test. The decisions, including the accepted no-revocation risk of JWT sessions, live in `docs/THREAT-MODEL.md`. A new `docs/DATA-INVENTORY.md` lists every kind of personal data we hold, who reads it, and how long it lives, plus what we deliberately never store.
- An audit log for sensitive events: sign-ins, club role changes, venue attestations, and channel connects and disconnects. Rows hold ids only (never emails, addresses, or secrets) and purge after 180 days.
- Sign in with Apple on the sign-in page, behind `AUTH_APPLE_ID` and `AUTH_APPLE_SECRET`. It binds accounts by Apple's stable user id, and private relay emails never show up as display names. Real credentials arrive with the Apple Developer enrollment.
- A You tab in the mobile bottom nav: account, plan, your garage, and sign out all live one tap away again.
- The iOS app shell: the Capacitor project under `apps/web/ios` with brand icon and splash, the `waypoint://` deep-link scheme, and one command to regenerate assets. Dependencies resolve through Swift Package Manager.
- A written threat model (`docs/THREAT-MODEL.md`): assets, actors, entry points, trust boundaries, and the ranked risks, each mapped to the issue that guards it.
- An incident runbook (`docs/RUNBOOK-INCIDENT.md`): severity calls, first response, leaked secrets, exposed data, and who runs the show. Counsel review still pending.
- Observability groundwork: the API logs one JSON line per request (route pattern, status, duration, request id, user id; never raw paths or query strings), `/healthz` now pings the database and answers 503 when it fails, and both apps carry a Sentry-ready error hook that stays off until a DSN is set. (#12, accounts follow in #81)
- A dedicated `cmd/migrate` binary runs schema migrations as a deploy step, with a `-down` rollback flag. Production API boots no longer migrate. Every migration's Down now flags what it destroys, and the rollback runbook lives in the deployment doc.
- A scripted backup restore drill (`script/restore-drill`) and a recovery runbook (`docs/RUNBOOK-RESTORE.md`) with proposed RPO and RTO targets.
- Pro rally routes with ordered map stops, straight-line distance, an aerial organizer editor, and reveal-safe route cards on meet pages.
- A Rally nav view groups upcoming and past meet routes for the active season.
- Rally cards now lead with route maps, dates, distance, and stops. Meet pages tease attached rallies without sharing a locked route. Organizers can find stops by address or add exact coordinates.
- Discover cards flag meets that include a rally route.
- Secret scanning on every pull request and push to `main`, plus weekly Dependabot updates for pnpm, Go modules, and GitHub Actions.
- Notifications for club members: an owner moving a meet, cancelling it, or scheduling a new one now shows up in the app. A bell in the nav carries the unread count and a short feed.
- A seeded public meet with a real address and color-coded parking zones (ok to park, caution, no parking), so Discover shows what geofenced parking looks like.
- Stripe Connect onboarding for club payouts. Club admins connect a Stripe Express account from Edit club and see its status: not started, pending, or connected. A signed webhook keeps that status current, and a live check catches up even where the webhook can't reach (local dev). This is setup only: no ticket sales or vendor payouts move money yet. (#183 phase 1)
- Arrival tracking, phase A: know who actually showed up, not just who RSVP'd. Every RSVP gets a private check-in code with a QR to show at the gate; a club manager checks people in by scanning it or typing the code in by hand. Anyone can also tap "I'm here" instead. All three paths land on the same arrival record, so the organizer roster shows who has arrived no matter which one fired.
- Mod categories go deep: engine, drivetrain, suspension, brakes, wheels & tires, exterior, interior, electronics, other. Sam's Miata ships seeded with a real spec sheet and mod list to show it off.
- Builds are editable: owners rewrite identity, spec sheet, story, and the ordered mod list from the garage, and the build card shows it all to everyone.
- Billing rails: Stripe sits behind a gateway interface, club admins get a checkout endpoint, and a signed webhook writes each club's plan. Replayed events are no-ops. Dev and CI never need a Stripe account.
- RSVP counts split by entry type in every list: spectators on Discover cards, waitlist numbers on the organizer dashboard. Organizers also get an attendee roster per meet: each build, spectators, and the waitlist in queue order.
- Themed tooltips across the app. Nav icons, dyno numbers, benchmark ranks, the capacity dial, and the pin-drop countdown now explain themselves on hover, keyboard focus, or tap. They replace the browser's native tooltips on those spots.
- Build specs in the garage API. A car now carries horsepower, torque, drivetrain, engine, a story, and a grouped mod list in the owner's order. Owners write them through two new endpoints. The edit UI comes next.
- The test program: ~100 tests across eleven suites (RSVPs and the waitlist, the location reveal ladder, meet lifecycle and recurrence, distribution drafts and calendar files, photo pool, Discover geo, season analytics, auth hardening, the web unit layer). A spec-driven check fails CI when a new write endpoint skips the authz registry.
- A nightly CI run of the whole gate on main. Red nights file a loud issue instead of failing quietly.
- ESLint for the web app, wired into CI and `script/test`.
- Members see their club at a glance: a full-width card with members, meets this season, last score and trend, season average, new photos.
- The command palette searches clubs (listed above members) and switches the active club on select.
- Vibe tags for the whole scene: Kid-friendly, Charity, American, Muscle, Exotics, Luxury, Lowriders, Off-road, Drift, EVs; Bikes-ok became Bikes.
- Planning docs: hosting cost plan, decision log (Stripe over Square), the go-live sprint to August 31, and 12-month financial projections.
Changed
- Weekly dependency patches: prettier, react, postcss, next-auth beta, Capacitor core, Tailwind PostCSS, and goose.
- Dependabot stops proposing the ESLint 10 major until the plugin ecosystem supports it; minors and patches still flow.
- The API now bounds every request: read, write, idle, and header-size limits on the server, a 1 MiB cap on JSON and webhook bodies (413 past it), and length and item ceilings across the contract. Guest rate limits key on a per-client hash the BFF forwards, so one guest cannot exhaust the shared anonymous bucket.
- Your clubs on the member home is a picker now, not a pill row, so it holds up at any club count.
- The iOS app skips the marketing page: it opens on sign-in, or straight into the app once you have signed in before.
- The mobile landing lost its header row: content starts at the top and sign-in sits inline with the tagline badge.
- The landing header slimmed down: text-only brand, a quiet sign-in link, and no theme toggle. The hero carries the pin.
- Swiping back now plays the iOS pop animation: the page slides off to the right while the one before it surfaces underneath.
- Mobile tabs got real sections: chip rows switch between Meets, Rallies, and Members (and Dyno's and Community's views), the page title breathes below the clock, and Plan a meet spans the screen. Swiping back now only leaves sub-views; it never walks the bottom tabs.
- Mobile went chrome-less: no top bar at all. Swipe from the left edge to go back, search from the bottom tab bar, and the theme follows your phone. The bell waits for real push alerts.
- The mobile top bar follows iOS conventions now: a back chevron leads on drill-in pages, the page title sits centered, and actions stay on the right. The wordmark left the bar. In the iOS app, the edge swipe goes back, like any native screen.
- The Go API now refuses any request without proof it came from the web app, guest reads included. Tokens are single-use in production, so a captured one cannot be replayed. The web app also sends HSTS, frame-ancestors, and nosniff headers on every page.
- Deleted photos, rally routes, and sponsors now keep a 30-day recovery window before they are gone for good. Deleted rows hide right away and can be restored by SQL inside the window.
- CI actions are pinned to exact commits, and workflow tokens now hold the least access each job needs. New gates scan Go code and both dependency trees for known flaws on every pull request and each night. Placeholder dev secrets carry a "change-me" marker that scanners skip.
- Go tests now use table cases where they help. Setup checks use `require`, result checks use `assert`, and both agent guides share the same rules.
- CI now uses pnpm 11.15.1 with the latest setup action.
- Meet locations show right away now. Public meets show their address on the spot. RSVP-gated meets reveal it the moment you RSVP, not on a 3-hour clock. Owners can move a meet after it goes live, and everyone who RSVP'd gets notified.
- The build editor opens as a centered dialog instead of a side panel; a dense form (identity, specs, story, mods) reads better with room around it.
- Nav tooltips removed (read as confusing in practice); the primitive and every other tooltip site stay.
- The member home's Next Up card gets an accent tint so it pulls the eye first.
- AI flyers moved from Pro to Ultimate.
- The account page centers its content and shows the viewer's real role and the club's real plan.
- GitHub Actions run current majors (Node 24); a nightly schedule joined the three PR checks.
Fixed
- The rally browser suite no longer misreports a leftover stop from an earlier run as a validation failure; it checks the stop-count change, not a fixed position.
- Error logs and the error reporter now redact coordinate pairs, so a gated meet location can never ride an error message off the box.
- The club picker in the iOS app draws only its own styling now, with padded text and chevron, instead of WebKit's native select chrome against the edges.
- The paywall browser suite drives the new club picker instead of the retired pills.
- The sign-in page went chrome-less on mobile like the rest of the app: no logo, toggle, or close button, swipe back to leave, and the form centers in the visible area.
- Swiping from the left edge now goes back on mobile for real, and the tab-bar search icon matches its neighbors.
- The landing and sign-in backgrounds reach the very top of the screen on iOS instead of cutting off at the status bar.
- Tooltips near the top of the screen flip below their trigger instead of opening into the iOS status bar.
- Focusing a search box or form field on iOS no longer zooms the page and strands the bottom nav off screen: controls hold 16px on touch devices.
- The theme toggle draws a flat sun and moon in the icon color. iOS was substituting its yellow emoji sun.
- The icon generator now runs on demand instead of living in the dependency tree, clearing 15 dev-only vulnerability alerts.
- Mobile feels native now: the top bar's blur reaches up under the iOS status bar, drill-in pages get a back chevron, and the expanded Discover map's controls sit clear of the status bar.
- The mobile shell got room to breathe: sign-in scrolls and has a close button, the theme toggle is no longer clipped, and the top nav sits cleanly below the iOS status bar instead of drawing a line through itself.
- One member navigating quickly no longer hits the API's read ceiling: the broad per-user limit now fits server-component page fan-out. Write limits are unchanged.
- Public identity fields no longer fall back to a user's email. A blank name now shows a neutral member handle on garages, rosters, attendee lists, and check-ins.
- Sign-in return URLs now stay inside Waypoint. External hosts, protocol-relative tricks, backslashes, and encoded forms all fall back to the plan page.
- Check-in codes and public meet IDs now fail closed when secure random generation fails. The write aborts instead of storing a guessable value.
- Announcement emails now escape organizer text, so meet titles and locations render as text, never as markup. The RSVP link must live on the Waypoint origin, and each email ships a plain-text copy.
- Forced patched sharp and postcss releases under Next.js, closing the open libvips and PostCSS advisories in the web dependency tree.
- The citywide benchmark now requires a signed-in club admin or mod. Anonymous callers and outsiders no longer read private rank and metric data.
- The seed tool refuses production and non-local databases. A flag allows staging. Its wipe now matches demo data by email domain and fixed demo IDs, never orphaned clubs, and reports errors instead of hiding them.
- Internal failures now return safe copy and a request ID. Detailed errors stay in redacted API logs instead of reaching browser actions.
- Secret scans now ignore one known fingerprint in generated OpenAPI code. The source contract remains under the full scan.
- Club role changes now enforce the admin hierarchy. A club keeps at least one admin, even when two role changes run at the same time.
- Discord connections now accept only real HTTPS webhook URLs. Outbound posts block redirects and refuse private or reserved network addresses.
- Sign-in now binds accounts to stable provider IDs before it looks at email. Only providers that prove email ownership may create or link an account.
- The landing page now separates live Discord and email sends from social post kits. It also reflects rally routes, arrival check-in, and the current flyer tool without claiming unfinished automation.
- The notification menu now opens into the page and stays inside narrow browser windows.
- Local browser suites fall back to the database container when the host has no `psql`.
- Repeat check-in scans keep their result visible instead of refreshing unchanged roster data.
- The notification bell opens without triggering a Next.js render error.
- The OpenAPI type generator now uses the patched `js-yaml` release, closing a high-severity CPU denial-of-service vulnerability.
- Current product docs and member copy now match the immediate RSVP location reveal. The local test gate blocks the retired timed-reveal wording.
- Closing the build editor discards edits, and Add a build opens the same full editor as Edit.
- Tooltips anchor to their trigger again instead of the viewport corner.
- The dyno page renders again: tooltips no longer break on server-component children.
- Club-private meets no longer reveal to any signed-in user who RSVPs (members only).
- Every freed car spot fills from the waitlist: cancels, kind switches, and capacity raises all promote in order.
- Series edits run on the club's clock (no more UTC drift on kept meets) and no longer resurrect cancelled dates.
- Cancelled meets say so on their page, refuse new RSVPs, and leave the plan list.
- "Your first build" now means the first one you added, not a random pick between builds.
- The city benchmark stops ranking a club against itself.
- A moved photo claim releases the previous build's photo.
- The Discover map no longer paints over the command palette.
July 16, 2026
0.0.1-alpha.1Added
- Meet scheduling that runs itself. A series like "every 2nd Sunday" builds a whole season. The composer pairs scheduling with channel posting on one screen.
- Location control per meet: public, club-private, or RSVP-gated. Gated meets drop the exact pin 3 hours before start, only to people who RSVP'd.
- RSVPs with car caps and waitlists that promote on their own. Car vs spectating. People with several cars pick the build they bring.
- Public meet pages built to be shared. Flyer hero, the location card, the "Rolling in" grid of builds, and calendar/share/reminder actions.
- Venue attestation. A meet can't be created or moved until the organizer confirms, on the record, that the owner sanctioned the venue. Public pages show the marker. The acceptable-use policy serves at `/legal/acceptable-use`.
- The photo pool. Per-meet galleries credit the shooters. Owners claim shots of their car, and the claim becomes the build's photo. Organizers pick meet covers.
- Garages and multi-build identity. Every member gets a build page, and the roster shows each build as a chip.
- Dyno. Season line charts, the latest-meet scorecard, the meet log, a city benchmark, and recap pages built to share.
- Discover. A real map of nearby meets with vibe filters, viewport browsing, and full-screen mode. Gated meets get privacy-rounded pins.
- Many clubs per person, with a role-aware switcher. Member mode for people who manage nothing. Join requests, and rosters members can read.
- The true paywall. Three tiers (Free, Pro \$5, Ultimate) enforced server-side, with blurred upgrade gates, a pricing page, and the Pro waitlist. Vendor accounts gate the vendor console.
- Distribution. Discord webhooks and Resend email are live. The newsletter composer drafts in three tones. Instagram and Facebook get post previews.
- Parking plans drawn on aerial photos, shown once the spot reveals.
- The Waypoint brand. The pin with the sports-car silhouette, a full asset kit, and USPTO-ready drawing files (`docs/branding`).
- The paper trail. A fact-checked business plan, a sales plan, a system map with every third party and token, and legal drafts.
- The engine room. The spec generates the Go server and the typed TS client. CI runs web, api, and e2e browser suites on every PR. Tooling follows scripts-to-rule-them-all. Work flows through issues, PRs, and milestones.
Changed
- All docs pass a readability gate (FRE >= 60, grade <= 9, zero em dashes), enforced by `tools/readability.py`.
- The OpenAPI spec lives at `services/api/openapi.yaml`, next to the API it defines.
- Work tracking moved from TODO.md to GitHub issues and milestones; this changelog carries the shipped history.
Fixed
- Meet times generate in the club's timezone, not the server's. An 8:00 am Charlotte meet is 8:00 am in Charlotte from any host.
- Series creation collided with a same-shaped route and returned 405. Creation moved to its own path.
- Empty future meets no longer 500 the "Also coming up" tiles. Nil slices marshal as [] everywhere.
- Discover filters repopulate the map when deselected, and card hover no longer re-pans the map.
Security
- Role checks on all organizer writes, with typed 403s. Club identity and role changes are admin-only.
- Requests validate against the contract at the edge. Writes are rate-limited per user.
- Channel credentials seal with `AES-256-GCM` at rest. Production refuses dev-default secrets. The dev login can't exist in production builds.
- Exact locations stay gated. Discover pins round to ~1 km for non-public meets, and reveal timing is enforced server-side.