v2026.10.05.02 – v2026.10.05.03 — 2026-10-05
- feat(lint): reject colour literals in TS/TSX (ADR-009 rule 4)
- feat(a11y): gate is strict in both themes by default, baseline removed
- fix(a11y): pin the fixture to the panel's own server, re-load only on a host network change, init TUNNEL_PID
- docs(notes): couple the admin login address and the operator contact
- docs(notes): queue the admin self-service edit and name the two admin addresses
- docs(notes): fix the export colours in the a11y result note
- fix(a11y): axe at zero in light and dark; baseline emptied, warning amber moved apart from orange
- docs(notes): say the /inbox finding is probably, not provably, a throttling artefact
- docs(notes): record why the a11y gate flaked and the five-run measurement
- fix(a11y): stop the gate flaking — isolate each run, bypass the rate limit, separate not-tested from violations
- fix(a11y): name every unlabeled select, input and event checkbox
- feat(ui): dark theme with system/light/dark switch, antd and stylesheets read the same tokens
- refactor(ui): replace every colour literal in the TSX with a role variable
- refactor(ui): replace every colour literal in the stylesheets with a role variable
- feat(ui): light and dark colour roles from one token file, antd palette read from it
- fix(mail): drop German success text from the test mail and SMTP save replies
- fix(i18n): use one word for the test mail within each language
- fix(i18n): name the recipient on the test-mail buttons in all 15 languages
- fix(ui): AA-corrected text colours in the shared component stylesheets
- feat(ui): colour-role token layer and AA-corrected text colours in the stylesheets
- docs(design): decide light and dark themes with dynamic switching
- docs(notes): the shared pattern behind the axe label findings
- fix(a11y): make overflowing table scrollers keyboard-reachable and trim the fixed baseline entries
- fix(a11y): give switches and progress bars an accessible name
- fix(a11y): name the language select on the public auth pages
- docs(notes): review the accessibility gate and tighten how it ratchets
- docs(notes): record the accessibility gate, its numbers and what it cannot check
- fix(a11y): make every jsx-a11y rule an error now the backlog is cleared
- docs(notes): group the axe findings by cause and set the order of the accessibility work
- docs(notes): review the favicon and dark logo build and add its live checks
- fix(ui): do not flash the default tab title on a branded panel
- feat(branding): favicon upload, dark logo and a public favicon route
- docs(ui): design token inventory for the light/dark theme decision
- fix(branding): drop the redundant embedded-field selector flagged by staticcheck
- refactor(branding): build branding answers in one place and carry a dark logo field
- fix(branding): require the white_label feature for a reseller's logo upload
- docs(adr): favicon upload and a second logo variant for dark backgrounds
- feat(ui): admin profile - login address with password confirmation, explicit operator-contact sync
- feat(ui): favicon and dark-background logo upload for the panel and for resellers
- docs(notes): review the password check limiter and the case-insensitive account paths
- fix(auth): one case-insensitive email check for every account path, SSO included
- fix(auth): rate-limit the current-password check of signed-in users
- docs(notes): review the admin password check and open the case-only duplicate follow-ups
- fix(admin): require the current password to change the login address and tell the old one
- docs(notes): review the admin profile endpoint and require the password for an address change
- feat(admin): let the signed-in admin edit their own login address