What's Changed
- Add country geolocation to session tracking and audit trails (#3989) #4187
- Add SMTP2GO delivery accounting #4193
- Apply anonymous TTL ceiling to V1 API (#4172) #4176
- chore(docs): add move breadcrumb to companion spec pointer #4189
- Configure Zed tasks and JSON LSP for git worktree setup #4182
- docs(security): application security review, 2026-08-14 #4166
- docs(security): weekly audit for 2026-08-13 #4156
- docs: Add behavioral specification for Privy Links #4185
- docs: add email quality controls epic and notifications design brief #4186
- Document HttpOrigin middleware Host header requirements #4178
- Enforce per-domain signin/signup opt-ins in full mode (ADR-024) #4184
- Enforce the per-domain signin/signup config axis on full-mode auth routes #4169
- feat(cli): add customer reconcile operation to repair role-index drift #4175
- feat(colonel): improve admin UX and performance #4191
- Isolate test Valkey and PostgreSQL per worktree to prevent fixture contamination #4179
- Parallelize test lanes and CI validation #4188
- Release v0.26.5: tighten admin gates, enforce domain auth opt-ins, strict booleans #4197
- Revise ADR guidance, plus a new policy on issue and PR referencing in code #4183
Fixes
- Fix custom-domain HttpOrigin 403s and consolidate middleware into a Registry + per-app profiles (#4170) #4181
- Fix three authorization and validation gaps in SSO and billing #4196
- fix(auth): close the settings-API restrict_to fail-open and repoint stale docs #4165
- fix(auth): set verified on SSO-provisioned customers #4177
- fix(domains): store CustomDomain booleans natively, surface resolving #4192
- fix(masthead): resolve neutral alt/site-name from productName directly #4174
- fix(secret): make branded instructions "Show More" toggle deterministic #4180
Full Changelog: v0.26.5-rc1...v0.26.5-rc2