Release 2.12.0 — One permission model with no holes, bug reports and the system version in the UI, AI period analysis
Release date: 2026-10-05
This release is about the platform's foundation: after a cross-cutting audit, access rights live in one model instead of scattered checks, and every hole found along the way was closed. On top of that come the interfaces your users asked for — filing a bug without leaving the page, seeing the running version in the footer, and asking AI about any period rather than a single day.

Components included:
PanDev Metrics Core
Version: 5.12.0
PanDev Metrics Web (backoffice)
Version: 2.12.0
The CLI, the Chrome extension and the IDE plugins ship unchanged in this release — their current versions are the ones published with 2.11.0 (CLI 2.5.16, Chrome 3.3.0, Cursor / Antigravity 2.5.0, DBeaver 1.2.0, Eclipse 1.4.5).
Highlights
- One permission model — and the holes closed. Roles and access were rebuilt end to end: a golden access matrix as the gate for every later change, one AccessPolicy in Core instead of per-endpoint checks, role-granting rules that stop anyone from handing out rights above their own, and a CI guard that walks every
/api/**endpoint looking for ones without a department or company check. - No more "a user without rights opened the page". The rebuild started from a security audit, so it closes specific holes rather than only tidying code: a maintainer could grant roles above their own and invite people; the invitation endpoint trusted the caller; the
/excel-staticsendpoints had no rights check at all, so any signed-in user could export any department's report and email Excel anywhere; a pure Team Lead got a 403 on the department list; a company ADMIN could not even see the DORA section, and a department owner could not see the Calendar. - Bug reports from inside the app. A bug button files a report with client diagnostics — no screenshot juggling, no "please describe your environment".
- The running version is in the footer. Frontend and Core versions, with an update indicator when a newer image is available.
- AI analysis over a period, not just a day. Ask about a date range and get aggregated activity metrics in the modal; the daily analysis endpoint was extended to match.
- Task Flow that behaves under filters. Drag-and-drop now works with "Assigned to me" and other filters on, the release section appears when creating a task, and moving a card between columns responds noticeably faster.
- Meetings widget redesigned, and the day summary's "Activity time" finally includes meeting time — a manager's day of calls no longer looks empty.
- Integrations that report their own failures. Failed integration connections now land in the error table, Jira Server/DC webhooks work again on legacy Jira versions, and Jira 11 no longer dies on an HTML response.
- Faster where it hurt: the releases list back to sub-second after a regression to 3 s, the finances summary under 10 s, and task-card moves no longer waiting on a slow response.
PanDev Metrics Core 5.12.0

- A single access policy.
PermissionandAccessPolicyreplace scattered per-endpoint checks, piloted on charts, the kanban and "company admin", then rolled out across facades andSecurityConfig. Authorization now has one place to read and one place to change. - A golden access matrix — a snapshot of who may do what, kept as the gate for every subsequent change, so a permission regression fails loudly instead of shipping quietly.
- Role grants follow rank. You can grant and revoke only roles below your own and only for people below you; a department OWNER can both grant and revoke OWNER for another OWNER; the department "head" becomes a label without rights, assigned manually. A company ADMIN can assign themselves any role in a department and join with any role.
- Invitations and membership hardened. Invitation v1 checks rights (role and the department's company), a maintainer can no longer invite above their own level, registration no longer writes a duplicate membership row in the first department (cloud), and membership changes happen as one operation — transfer with a role, head and last-owner rules, inviting an existing person.
- Roles in the token, read from the database. The application token takes both company and department roles from the database instead of the token body, an eternal plugin token no longer loses company roles, department role lookups verify the person's own company, and the refresh token is only accepted on login, logout and company switch.
- Fewer needless reads per request. The role version travels in the token instead of reading
jwt_tokenon every web request, and stalejwt_tokenrows are cleaned up. - A CI guard over the whole API. A registry of
/api/**endpoints with a guardian in CI fails the build when a new endpoint appears without a department or company check — the mechanism that keeps the holes from coming back. - Visibility rules, one per concept. Departments visible in v1/v3 lists, the card and Task Flow boards follow one rule; people visibility is the same rule for the list, the directory, cards and charts; writing requires member or above, Viewer only reads.
- Tenant isolation and data leaks. Reading another tenant's data, the
TENANTscope, colleagues' AI spend and another company's project were closed as part of the audit, along with "Task Flow in someone else's department". - Data quality and integrations. GitLab polling stores a new project's cursor correctly (in a
text[], not jsonb), connection failures land in the error table, Jira Server/DC webhook paths are correct for legacy Jira, Jira 11 tolerates HTML responses and reads the assignee on Cloud, and/api/v1/rolesreturns empty lists instead ofnullso the Employees page stops crashing for non-admins. - Performance. Release lists regained their per-status counters in SQL and came back from 3 s, and the finances summary stopped taking more than 10 s.
- Readable, testable code. Charts facade tests no longer depend on someone else's
SecurityContext, and the JWT filters run only in their own chains — removing the root of a double check.
PanDev Metrics Web 2.12.0

- Bug reporter in the interface. The bug button opens a report with collected client diagnostics, and it stays reachable even when a UI error takes over the whole screen — exactly when a report is most useful.
- System version in the footer. Frontend and Core versions with an update hint when a newer release exists, and a cleaned-up footer layout (Windows 11 and Mac 14"/15" overlaps fixed).

- AI period analysis. The period-analysis modal shows aggregated activity metrics for the selected range, with
PeriodAnalysisModalrefactored into thin components.

- Meetings and activity. The "Activity in meetings" widget was redesigned, the day summary's activity time includes meetings, and the "today" axis is synchronized across the task timeline and the activity widgets.
- Documentation editor. Fixed: editing no longer deletes records; the
@mention tooltip points at the right thing; and the Notion-like editor was polished. - Task Flow. Releases are offered when creating a task or bug, drag-and-drop works with filters on, card moves between columns are faster, and
NaNno longer leaks intoapi/v1/dashboards/NaN/releases. - Organization in the sidebar. Users, departments and teams are grouped into one "Organization" folder, and the navigation menu now always shows the
›arrow on sections that have children. - Roles in the interface. The Users screen shows and edits roles, a department owner can change the role of a company admin member, "Developer" is renamed to "Member", the legacy MANAGER role is gone, and the sidebar union of roles replaces the old per-role menus.
- Roles frontend aligned with the new backend model — including the "rate" field in the employee card and the "invite yourself" edge case, so the interface and Core agree on who may do what.
- Consistent controls. One rule and a brighter look for toggles, the User Story icon is green, and reports of integration errors no longer surface as YouTrack texts.
- Quality of life. The task filter range persists when moving from a team to its people, the teams dropdown on team metrics is sorted, the "Select a date range" section stays inside the page, loaders match the loading artwork, and frontend autotests were extended.
Upgrade notes
- Core 5.12.0 and Web 2.12.0 upgrade together — the new permission model spans both, and the interface expects the new
/me/permissionscontract. - Expect permission changes. Roles are now enforced by rank: if someone could previously grant a role equal to or above their own, they cannot any more. Review who holds OWNER in your departments, because the department "head" is now a label without rights and is assigned manually.
- The
LEADERrole becomesOWNERin the department model — check invitations and department memberships that referenced it. - Integrations: failed connections now write to the error table, so expect new rows there after the upgrade — that is the mechanism working, not a regression.
- No new plugin versions ship with this release; CLI, Chrome and IDE plugins stay on their 2.11.0 versions.
Download Release:
- PanDev Metrics Core 5.12.0:
docker pull pandevofficial/pandev-metrics:5.12.0 - PanDev Metrics Web 2.12.0:
docker pull pandevofficial/pandev-metrics-backoffice:2.12.0 - PanDev Metrics CLI 2.5.16:
brew install pandev-metriks/pandev-cli/pandev-cli-plugin(orbrew upgrade) - Chrome 3.3.0, Cursor 2.5.0, Antigravity 2.5.0: update automatically from their stores
- DBeaver 1.2.0 and Eclipse 1.4.5: from the Plugins page of your workspace