Release notes
Elsewrite changelog
Last reviewed July 21, 2026
Elsewrite 1.0.1
Changed
- Replaced the planned persistent top/notch handler with an invocation-only contextual capsule anchored beside selected text or the caret, with cursor and active-screen fallbacks.
- Fast Mode now specifies direct replacement followed by an ephemeral Done/Undo confirmation; normal translation opens contextual Review, while onboarding, Settings and History remain separate native windows.
- Approved the paired-rails/coral-cursor visual system and six-screen onboarding direction as the canonical composition, hierarchy, density and rhythm for native and web implementation.
- Unified the Elsewrite mark across the app icon, onboarding, menu bar, Settings and website, with the capsule identified by its coral seam, removing unrelated SF Symbols and the provisional boxed-letter web badge.
- The website now ships pinned, self-hosted Geist Sans and Geist Mono rather than relying on an unverified local font installation.
Elsewrite 1.0.0
Changes
- Adopted Elsewrite as the public product name, including bundle identity, activation URL, Keychain namespaces, release artifacts and customer-facing copy.
- Set `https://elsewrite.affwork.dev` as the canonical origin under the existing studio domain.
- Isolated the Elsewrite deployment at `elsewrite.affwork.dev`; the `affwork.dev` studio index is explicitly owned by a separate repository, Coolify project and deployment.
- Renamed the prepared Coolify resources to Elsewrite while preserving their IDs and recorded the independently deployed Affwork studio as external infrastructure.
- Added a fail-closed Developer ID release smoke that detects interactive Keychain waits and proves trial, device identity, History key and license certificate continuity across signed updates without exposing their values.
- Local QA packages reserve builds below `1000`; local Developer ID foundations use `1000...1999`; hosted candidates use the monotonic `2000 + GitHub run number` range, preserve reservations and reject manual numbers or workflow reruns.
- Release candidates now require Gatekeeper approval of the quarantined app extracted from the notarized DMG, in addition to validating the distribution container.
- GitHub workflows now pin Node.js 24-based `actions/checkout` v7, `actions/setup-node` v7 and `pnpm/action-setup` v6 and `actions/upload-artifact` v7 by immutable commits, removing deprecated action runtimes while preserving supply-chain reproducibility.
- Operators can now run a content-free release-readiness check that reports missing DNS, signing identity, workflow or GitHub secret names without accessing credential values.
- Release configuration fixes canonical endpoints and Apple identity in the reviewed workflow, keeps only four rotatable public values in GitHub Variables and limits GitHub Secrets to six genuinely sensitive signing, Sparkle and notarization values.
- A no-Keychain release-key generator now produces verified license/Sparkle Ed25519 material with restrictive permissions and overwrite refusal; real credential creation remains owner-gated.
- Phase transition validation now refuses to close product creation while signed-candidate, macOS 15/26 manual QA, blocker decision or installed-checksum evidence remains incomplete.
Changed
- Global shortcuts now install only after AppKit finishes launching, report Carbon handler failures instead of discarding them, release every temporary registration explicitly and have an executable registration/delivery regression test.
- The top handler now uses the owned Glossa nonactivating-panel foundation: a continuous edge-attached shape, dark native material, Glossa's compact size and motion/accessibility paths, content-driven workflow sizes and focus-preserving panel lifecycle. Hover now changes the idle silhouette only subtly; click explicitly opens the workbench and pointer exit restores idle.
- The clicked handler now presents balanced, visible Review, History and OCR controls; History opens its dedicated window and OCR uses an explicit in-surface chooser instead of relying on menu-button rendering inside the nonactivating panel.
- The menu-bar item is now a compact fallback for opening the handler, History, Settings, onboarding and updates instead of rendering a second translation workbench in a tray popover.
- Added an auditable native design gate, NotchNook interaction-reference captures, owned Glossa provenance and a required original SVG brand/asset system; two ambiguous logo reductions were rejected rather than shipped.
- Selected a 16px-first Elsewrite identity direction, added editable color, monochrome, menu-bar, app-icon and wordmark SVG masters, replaced the generic Translate menu-bar symbol with original template geometry, and made packaging generate the app ICNS from its dedicated master.
- First-run setup now opens in a dedicated resizable window and can be reopened from the tray until it is complete.
- Language families now place the runtime's generic locale before regional variants unless the user's probable locale, favorites or recents explicitly promote a variant.
- Initial trial, license and encrypted-History Keychain reads now run off the main actor so a macOS authorization wait cannot freeze the menu-bar UI during launch.
- License activation, refresh, deactivation and History recovery now route every Keychain lifecycle operation through a non-main actor or detached task, keeping the UI responsive beyond launch too.
- Settings language choices now hide every regional variant of the effective source and repair an invalid primary/additional destination immediately when the source changes.
- The translation runtime now starts from configuration state changes instead of a lazy menu view, so Settings opened directly after onboarding always has complete Fast destinations and shortcuts.
- Lifetime and monthly purchases now map to distinct Dodo offers under one Elsewrite app identity, so either plan activates through the same native license flow without manual database seeding.
- Automatic Dodo license keys are now accepted as opaque credentials instead of requiring an Elsewrite-specific visual prefix; activation still matches product and purchase email and stores only a server-secret hash of the key.
- Pre-launch hosting now stays explicitly non-commercial; enabling checkout makes the production healthcheck fail closed until live payment, licensing, email, database and canonical URL settings are complete and consistent.
- License API requests now reject malformed identifiers and oversized device names before database access, and activation exchange acquires a connection only after parsing, rate limiting and validation succeed.
- The web host now sends fail-closed framing, referrer, MIME, browser-permission and transport headers, protecting one-time license links and seat-management forms from clickjacking and URL leakage.
- Customer portal seat removal now authorizes ownership, deactivates the device and appends its audit event in one database operation; repeated or cross-customer attempts change nothing.
- Database contracts now run in a disposable isolated schema, allowing repeatable local validation without resetting or mutating the development application's tables.
Product definition
- Defined the international-first, translation-focused macOS 1.0.
- Added review, optional Fast Mode, OCR, encrypted local history and complete Settings to the MVP.
- Defined the three-day local trial, US$25 lifetime and US$3 monthly offers with five Macs each.
- Defined signed device-bound certificates, lifetime offline continuity and refund revocation.
- Defined first-party privacy-safe analytics, SEO launch pages and the single-deploy web stack.
- Moved Natural Refinement, Desk modules, glossary, export, sync, teams, voice and documents to the post-launch backlog.
- Originally tracked the product under the internal Phrasewell codename pending a public name.
Repository foundation
- Added an auditable four-phase goal and current-state system.
- Added the self-improvement method, metric dictionary, adversarial fixtures and append-only outcomes.
- Added competitive-intelligence and channel experiment guidance.
- Added the private Next.js/PostgreSQL/Docker Compose foundation, health endpoint and CI.
- Added GitHub and Coolify deployment runbooks.
Native foundation
- Added the Swift 6/macOS 15 package and a minimal menu-bar host.
- Added deterministic fallback for ambiguous short text such as `va`.
- Added destination rotation that cannot create a same-language route.
- Added initial immutable job-state handling that ignores stale completions and routes Fast results directly toward replacement; the Apple Translation actor remains under development.
- Added local multi-language term detection plus deterministic protection for URLs, email, inline code, handles, hashtags and acronyms, with opaque restoration and no word glossary.
- Added fail-closed structural whitespace and list-marker anchors with regression tests.
- Added selection-first Accessibility capture with secure-field refusal before content reads.
- Added source/target revalidation, direct replacement, guarded paste fallback and exact Undo.
- Added conditional clipboard restoration that preserves a newer user copy.
- Added the real Apple Translation lifecycle for macOS 15+ with superseded-job cancellation and Review/Fast input-size safety limits.
- Added a functional development workbench for Review, Copy, Replace, Fast, Cancel and Undo while the final active-display handler is still under development.
- Added a runtime-derived Apple language catalog with regional locale normalization, probable-locale ordering, speaker-based fallback ordering and same-language route exclusion.
- Added the canonical explicit-source-first six-step onboarding with optional Auto Detect, searchable native/localized language names, route readiness, Accessibility retry/settings, real gateway capture/replacement implementation, Launch at Login and unticked analytics consent.
- Added persisted, validated language preferences and confidence-gated on-device source detection.
- Revalidated Auto Detect routes against the effective source and added searchable native/localized selectors to the development workbench.
- Added a device-local three-day trial start record in a ThisDeviceOnly Keychain item.
- Added device integration probes for the runtime language catalog and a direct installed-model translation route.
- Added the first original active-display `NSPanel` handler with focused-window/frontmost-window/ cursor display resolution, reduced-motion resizing and screen-sharing exclusion.
- Added state-scoped Carbon shortcut registration for `Control+Option+T`, optional Fast activation, `Command+Return`, `Escape` and safe `Shift+Tab` destination cycling.
- Added interaction Settings for Review-only, dedicated Fast and Fast-default modes, a separate fixed Fast destination, and always/hover/activity handler visibility.
- Added local Vision OCR for pasted images, dropped image files and a selected area on the active display, with `Control+Option+O`, Review-only output and just-in-time Screen Recording permission.
- Added in-memory-only OCR image handling and a synthetic Vision probe that verifies recognition without retaining user images or recognized content.
- Added encrypted local History backed by SQLite and per-field AES-GCM, with a random device-only Keychain key, completed-action provenance, local search, route/origin/action filters, favorites, configurable retention and Delete All.
- Added a separate native History window plus three recent completed translations in the handler; cancellation and failures never create History entries.
- Replaced the temporary settings form with a native sidebar for General, Languages, Shortcuts, Translation, OCR, History, Privacy & Analytics, and License & Updates, including functional language reconfiguration, appearance, launch-at-login, permission help and onboarding restart.
- Added the offline entitlement foundation: Ed25519/compact-JWS certificate verification with device-claim checks, perpetual lifetime and expiring monthly policies, plus trial-expiry enforcement for translation and OCR while Settings and History remain available.
- Added device-bound activation with a random Keychain identity, signed proof-of-possession, five-seat enforcement, silent status refresh limited to once per 24 hours and immediate self-deactivation.
- Added order-independent Dodo purchase, entitlement, subscription and refund ingestion with durable webhook receipts, revocation audit logs and replay-safe database transitions.
- Added a passwordless email portal for viewing and removing active Macs, with short-lived one-use links, enumeration-safe responses and Resend delivery.
- Added one-time email activation links that atomically exchange a short-lived token for a device-bound certificate, while preserving manual email + key activation as a fallback.
- Added durable, order-independent purchase, refund, subscription-state and delivery-failure lifecycle emails with one-click purchase activation, independent retry/dead-letter handling and no license keys or user content in the message body.
- Added Sparkle 2 update checks, signed-feed configuration and an automated candidate workflow that assigns monotonic build numbers, signs, notarizes and staples the release DMG.
- Added signed appcast generation from the exact notarized DMG and canonical changelog, plus one-time in-app release notes for each installed marketing version.
- Fixed release packaging so Sparkle is embedded at the executable rpath and nested components are signed correctly for both Developer ID releases and ad-hoc QA builds.