Open full dated project history
# GeoPunch Project Change Log
Last reconstructed: 2026-07-24
Current build: 20260725-testing-efficiency-auto-verify-v27
## 2026-07-25 — Efficiency, automatic verification, and notification controls (v27)
- Added a company-controlled 5–120 second notification duration with a 30-second default and close controls.
- Protected actions now automatically verify current server data and continue after Live status is restored instead of requiring a manual refresh or verify click.
- Added domain-aware and employee-scoped synchronization so unrelated changes no longer force every open screen to reread all of its data.
- Coalesced revision bursts, reduced backup/focus/health polling, and removed a duplicate backend Company read while retaining real-time listeners and fail-closed edits/exports.
- Added a deterministic 100-run 500-employee/50-admin usage and cost planning model covering normal roster, punch, request, approval, correction, reporting, and payroll workflows.
## 2026-07-25 — Testing UX, edit-presence, deletion audit, and Position repair (v26)
- Replaced the repetitive full-screen server verification overlay with a compact professional header status showing Live/Synchronizing state and the latest server-confirmation time. Manual verification remains available from the header control.
- Corrected the background freshness probe so an unchanged company revision performs only a lightweight server check instead of forcing a complete screen reload.
- Standardized application notices to remain visible for 30 seconds with an immediate close control.
- Added server-backed Time Entry edit reservations so a second user sees who is editing, cannot open the same session, and PayPak export is blocked while a relevant editor remains open.
- Added Company Manager-or-higher Time Entry deletion with a mandatory reason and immutable backend copy of the original entries, actor, role, and deletion timestamp.
- Fixed employee and role saves to use the exact server document ID and revision, and made trusted-device resets and role/access changes refresh the affected signed-in user automatically.
- Improved roster and employee Position snapshots/fallbacks so newly created and historical generic Time Entries resolve the intended current Position without overwriting genuinely unresolved legacy Positions.
- Time Entries now default to the collapsed summary view.
## 2026-07-24 — Strict live-data consistency lock (v25)
- GeoPunch now requires Hosting, Functions, the running content-hashed JavaScript/CSS paths, and their signed asset identities to agree before any account or company data loads.
- Critical screens use server-authoritative reads and display **Live** only after the complete screen is loaded between two matching stable company revisions. A cache fallback can no longer be presented as current.
- Every important shared write is serialized through a server lease and exact company revision. A request from an older screen is rejected even if its cross-computer listener notification has not arrived yet.
- Added record revisions for Time Entries, roster shifts, requests, employees, locations, jobs, and company settings. Stale saves are refused and reloaded rather than silently overwriting another user.
- Approvals and PayPak export revalidate on the server; PayPak is withheld if any company write occurs during generation and receives a traceable export-run revision/digest audit.
- Scheduled automation and production-to-testing company copies now emit the same writing/stable revision signals as normal users.
- Added automatic shell repair, immutable hashed assets with browser integrity checks, a visible Live/Synchronizing/Not Verified status, fail-closed action lock, and an administrator client-health dashboard.
## 2026-07-24 — Data consistency and self-healing app shell (v24)
- Fixed the stale-service-worker path that could leave one browser on an older GeoPunch shell while another user saw current data.
- GeoPunch now verifies the deployed build before loading account/company data, activates updates immediately, retries failed updates, and removes only obsolete GeoPunch shell caches without deleting sign-in, trusted-device, preference, or Station Mode queue data.
- Added strict login/company context guards and cancellation for backend requests, Firestore queries, listeners, roster windows, Time Entries, dashboard data, reports, employee history, and company switching so an old request cannot populate a new session.
- Added authoritative server refreshes for the active screen when the app resumes, returns from the browser back/forward cache, regains connectivity, or receives a same-company change from another GeoPunch tab.
- Added cross-tab mutation notification and full company-state isolation on sign-out/company switch so backend and employee views converge without clearing site data.
## 2026-07-22 — PayPak-only employee exemption (v23)
- Changed the employee exemption so it applies only to PayPak XLSX export.
- Exempt employees remain visible in Time Entries, employee filters, manual Time Entry creation, Position quick editing, approval actions, and Time & Position Review.
- Added the canonical `excludeFromPayPakExport` field while retaining compatibility with existing v21/v22 employee records and spreadsheet columns.
- Updated employee cards, Excel import/export, diagnostics, and help text so none imply that Time Entries are hidden.
## 2026-07-22 — Roster leadership, protected group directories, and Position display (v22)
- Company Owners, Company Admins, and Company Managers can be rostered. Group Owners, Group Admins, and the Platform Owner remain excluded from roster assignment.
- Group Owner and Group Admin records are removed from shared employee/user listings throughout the application. A protected account can still see itself, and the Platform Owner can see all records.
- Added server-filtered directory endpoints, historical-record privacy keys, guarded startup/cache sequencing, team-roster and PayPak filtering, and Firestore directory read protection.
- Replaced Location / Job in Time Entries with a responsive Positions display. Single-Position sessions stay compact; split sessions show each Position and its allocated hours in collapsed and expanded views.
## 2026-07-22 — Time-entry exemption and bare-bones Position review (v21)
- Added an employee-level exemption that keeps punch history intact while removing that employee from Time Entries, Time & Position Review, and PayPak XLSX exports.
- Enforced the PayPak exemption in the backend so hidden employees cannot be included by a stale browser or direct export request.
- Replaced the Time & Position Review with a five-column report: Employee, Day, Total Day Hours, Position, and Position Hours. Each Position receives its own line and repeats the employee/day total.
- Removed rate, pay, estimated pay, billing totals, and Position amount calculations from the Time Entries interface and Position editor. GeoPunch rates remain available only to the PayPak export generator when that rate source is enabled.
## 2026-07-22 — Position-only legacy correction and compact Time Review (v20)
- Added a briefcase quick editor for completed Time Entries so Position assignments, split hours, rates, and Position approval can be corrected without changing clock-in/out, location, job, or manual-edit notes.
- Deleted, missing, or stale-ID legacy Positions remain explicitly unresolved until a current Company Records Position is chosen; GeoPunch no longer guesses from the employee’s current Position or a reused display name.
- Position edits require exact allocated minutes, reject duplicate Position rows, and can be saved or updated-and-approved by an authorized approver.
- Previously approved clock times can recover payroll readiness after Position-only approval; clock times that were never approved remain pending.
- PayPak export blocks unresolved Position references instead of exporting guessed mappings.
- Replaced the previous Time Entries review layout with a compact employee → day → Position table, inline totals, issue badges, and direct Edit Positions actions.
## 2026-07-21 — Time review, allocation approval, payroll, and diagnostics (v19)
- Replaced the generic Needs Review workflow with explicit Incomplete, Photo Review, Pending Approval, Adjusted, and Approved states. Saving a time correction now records the entry as reviewed; authorized approvers also confirm it immediately.
- Added a Time Entries Review Report grouped by employee, work day, and Position, including split hours, rates, estimated pay, approval state, and CSV/print actions without requiring Reports-page access.
- Position allocation changes now invalidate earlier approval and require explicit reapproval. Allocation duration is verified against the authoritative clock timestamps.
- PayPak export now validates allocation totals instead of silently redistributing hours, blocks unsafe partial exports, uses allocated Position rates, and identifies each Position in the Description.
- Fixed Backend Manually Entered request employee loading by loading the employee directory whenever Requests opens and whenever the manual-entry section expands.
- Added employee self-service Forgot Password email reset on the sign-in screen.
- Added read-only System Diagnostics for screen wiring, reference-data loading, time-duration mismatches, allocation/approval consistency, payroll configuration, and session-only runtime/backend issue capture.
- Fixed a Station Mode startup promise failure caused by its IndexedDB name being initialized after startup began.
## 2026-07-21 — PayPak Professional 4.0 Gross Pay export (v18)
- Added Payroll / PayPak Employee ID to employee profiles and employee Excel import/export.
- Added PayPak Professional 4.0 Gross Pay XLSX export with the exact 12-column Sheet1 layout.
- Added configurable Regular/Overtime/Double-Time or Position-based Pay Rate ID mapping.
- Added optional daily/weekly overtime, double time, GeoPunch or PayPak rate sourcing, Taxable Y/N, and configurable Reference values.
- Added Position-specific PayPak Rate IDs and descriptions to Company Records and Company Records Excel.
- Added approved-only payroll export, duplicate payroll-ID protection, missing-mapping warnings, flat/hourly handling, and overnight/weekly-overtime safeguards.
- Optimized payroll reads to query completed OUT entries only and batch-load only employees present in the selected period.
> History note: this timeline is reconstructed from the GeoPunch build metadata, audit files, and project archives available in the current workspace. The exact original inception date and any changes that only exist in separate chats named `geopunch` or `geopunch_v2` were not directly accessible, so the pre-2026-06-26 baseline is marked as reconstructed rather than exact.
## Reconstructed inception baseline — before 2026-06-26
- Established GeoPunch as a Firebase-backed, multi-company time and attendance application.
- Added separate Platform Owner, employer/backend, and employee portal experiences.
- Added Firebase Authentication, company-linked users, role-based access, employee profiles, locations, jobs, rosters, GPS punch-in/out, leave/equipment requests, time entries, and reports.
- Added the initial PWA/service-worker installation model and responsive browser interface.
## 2026-06-26 — Attendance automation and testing environment
### 20260626-attendance-automation-readfix-v1
- Replaced broad attendance scans with due-only reminder queues.
- Reduced scheduled attendance processing frequency and background Firestore reads.
- Limited bulk processing and reused embedded shift/employee data where available.
### 20260626-testing-firebase-v1
- Created a separate `geopunch-testing` Firebase target.
- Split testing and live Firebase configuration while keeping functional code aligned.
## 2026-06-27 — In-app notification write control
### 20260627-inapp-write-opt-v1
- Stopped creating employee in-app notification documents when the company disabled that delivery channel.
- Preserved email and push delivery without unnecessary Firestore writes.
## 2026-06-29 — Roles, approvals, confirmation, and Company Records
### 20260629-role-clock-approval-records-v1
- Allowed rostered owners/admins/managers/supervisors with employee records to use the employee clock.
- Made automatic clock-out use the rostered shift end.
- Added time-entry approval controls and manager/supervisor manual-edit tracking.
- Added Company Records navigation, individual setup-link email delivery, and roster-manager reporting.
### 20260629-shift-confirmation-clock-v2
- Fixed single-shift confirmation.
- Added the employer setting controlling whether confirmation is required before punch-in.
- Added location snapshots/fallbacks so confirmed shifts remained usable by the clock.
### 20260629-company-records-pill-v3
- Modernized Company Records navigation.
- Split Locations, Jobs, Positions, and Equipment Types into dedicated sections.
## 2026-07-01 to 2026-07-02 — Read/write optimization and anytime clocking
### 20260701-read-write-optimization-v4
- Added roster, time-entry, report, dashboard, and reference-data caching.
- Reduced broad reloads after setup links, trusted-device actions, user changes, request changes, and location edits.
- Stopped GPS/radius edits from rewriting historical records.
### 20260702-employee-anytime-allocation-v5
- Added “Clock in anytime at default location.”
- Hid roster access for anytime-clock employees.
- Added Position allocation of completed time-entry hours.
- Added role-aware User Access visibility and Position rates.
### 20260702-firestore-ui-v6 and hotfixes
- Added Excel support for anytime-clock settings.
- Improved time-entry editing, employee-list collapse behavior, Position allocation controls, and missed-clock reminders.
- Fixed broken asset paths, undefined Firestore audit fields, and responsive time-entry editor layout.
## 2026-07-04 to 2026-07-05 — Android employee-app experiments
- Created and tested Capacitor/WebView/hosted employee-portal Android shells.
- Documented Android SDK, Gradle, Java, Node, signing, and Firestore transport requirements.
- These experiments remained separate from the main web/PWA production release.
## 2026-07-07 — Departments, access control, work modes, and company settings
### 20260707-company-departments-access-v7
- Added Departments and department-based roster/report filters.
- Added Company Manager role and page-level backend access controls.
- Added configurable work-week start day.
- Added approved leave overlays, manual admin leave, request visibility control, no-set-time Positions, work-from-home/different-location shifts, and Firestore-safe location refresh.
## 2026-07-14 — Publishing, requests, reports, printing, and dashboard fixes
### 20260714-roster-publish-request-controls-v8
- Added draft/published roster workflow, Day Off mode, request-type limits, department sort order, approved-request editing/removal, and duplicate-safe roster copying.
- Added roster printing and allocation cost reporting.
### 20260714-dashboard-refresh-reports-v9
- Fixed first-load dashboard counts and employee editor duplication.
- Added targeted refresh buttons with cooldown/freshness protection.
- Fixed roster/report popup printing and employee Requests listener path.
- Expanded summary and detailed reports.
### 20260714-letter-roster-reports-v10
- Rebuilt daily, weekly, and monthly roster prints as Letter-landscape employee-by-date matrices.
- Added pagination, requested-off overlays, draft markers, and department-aware ordering.
## 2026-07-15 — Roster layouts, time repair, requests, and multiple locations
### 20260715-roster-time-location-v11
- Added compact and weekly-matrix backend roster layouts.
- Added dashboard clocked-in drilldown, vacation/request editing from roster, request-source grouping, per-employee vacation allowance, missing-punch repair, manual time entries, and multiple employee clock locations.
### 20260715-settings-time-collapse-v11-1
- Fixed request-visibility saving.
- Added zero-read Collapse All/Expand All Time Entries summaries with exact clock-in/out times and edit/approve actions.
## 2026-07-18 — Company Records, payouts, availability, dashboard, backup, and Excel
### 20260718-company-records-job-payout-v12
- Added editable Company Record IDs/descriptions, Job Entry Types, flat/hourly Position rates, fixed-time auto clock-out, non-working weekdays, user dark mode, dashboard drilldowns/job filtering, Job payout reports, and Platform Owner production-to-testing company copy.
- Added paged roster/time-entry loads for 500-employee companies and removed a hardcoded owner-bootstrap fallback key.
### 20260718-employee-company-records-excel-v13
- Added Employee Excel import/export using authoritative Company Record IDs.
- Added blank-preserve and `CLEAR` semantics.
- Added complete Company Records Excel import/export with stable System Keys, upsert-only behavior, duplicate protection, caching, and unchanged-write suppression.
## 2026-07-19 — Import reliability, short IDs, onboarding, dark mode, and matrix status
### 20260719-employee-import-reference-hotfix-v13-1
- Fixed false unknown Position/Department errors caused by stale client reference data and Excel character variations.
### 20260719-employee-import-render-hotfix-v13-2
- Fixed the removed `renderEmployees()` post-import refresh path.
### 20260719-employee-import-preview-v14
- Rebuilt Employee and Company Records imports with no-write preview, per-field diffs, exact row errors, and stable legacy ID compatibility.
### 20260719-short-record-ids-roster-copy-v15
- Added deterministic short Company Record IDs, one-time migration, legacy aliases, project-wide current-reference updates, and repaired matrix Copy to Next Day.
- Removed the weekly-matrix delete icon and eliminated the unconditional admin Location preload.
### 20260719-employee-onboarding-publish-qol-v16
- Added employee onboarding guidance and Chrome recommendation.
- Improved trusted-device GPS/push setup, Equipment Request protections, default Position snapshots for anytime clocking, dashboard name resolution, and side-panel shift deletion.
### 20260719-roster-border-dark-contrast-v16-1
- Refined publication and dark-mode contrast styling.
### 20260719-v13-matrix-day-status-v16-2
- Restored the v13 weekly-matrix shift appearance.
- Moved draft/published status color to the employee/day cell background.
## 2026-07-20 — Roster readability, guided spotlight tour, full audit, and embedded history
### 20260720-employee-setup-activation-hotfix-v17-1
- Corrected compact roster scaling across desktop, tablet, and mobile.
- Made weekly-matrix Position names use the full saved name, with safe single-line ellipsis instead of mixed abbreviations.
- Retained the roster legend wording: “Draft / not visible to employees” and “Published / visible to employees.”
- Replaced the passive employee guide with an interactive spotlight walkthrough that blurs the surrounding screen and focuses the exact field, tab, or button being explained.
- Made tour-only section changes render locally so the walkthrough does not start Requests, Roster, or History Firestore loads unless the employee actually opens those screens.
- Added a first-time setup spotlight walkthrough for login email, password creation, and account activation.
- Added this dated Change Log as static text under Backend Settings, with no Firestore reads or writes.
- Completed production/testing parity, package, security, listener, query-bound, and Firestore-usage reviews.
### 20260720-tour-layout-employee-drawer-v17-2
- Rebuilt the employee spotlight walkthrough around the visual viewport so the coach card, highlighted control, navigation buttons, and scrollable instructions stay inside desktop and mobile screens.
- Added mobile keyboard and browser-toolbar-aware repositioning.
- Fixed Employee editing so values are populated only after the form moves into the side drawer, and the top Add Employee form is clean when the drawer closes.
- Added no Firestore reads, writes, listeners, or backend routes.
### 20260720-project-parity-employee-punch-v17-3
- Repaired employee updates when stored Position or Department Record IDs are stale, shortened, or present only as legacy aliases.
- Added a fresh Company Records retry only when a cached Position/Department lookup fails.
- Added current Position/Department Record IDs to employee-save requests so both Firebase projects validate the same data.
- Added a targeted current-user active-shift listener for every employee-linked account, including managers/admins using the Employee Portal.
- Updated Punch In/Punch Out locally from the backend response so the main clock button changes immediately without waiting for a listener round trip.
- Added conflict recovery for a stale Punch In/Punch Out screen without broad Firestore reads.
### 20260720-trust-gps-requests-roster-v17-4
- Made trusted-device registration independent of GPS and notification availability; permission failures warn without blocking device trust.
- Added precise-to-balanced GPS retry behavior and recent-fix fallback for map centering.
- Restored employee request and Equipment Type dropdown loading directly from the current company document.
- Added approved leave, vacation, and time-off entries to the employee roster without exposing coworker request details.
- Replaced generic roster “Requested Off” wording with the saved request type.
- Added explicit 16-character Company Record ID warnings and backend validation.
- Made Employee editing load Locations directly instead of depending on first opening Company Records.
- Made administrative punch-out corrections close the matching active shift automatically.
- Rebuilt dark-mode contrast on a true-black base with near-black surfaces and high-contrast text.
- Added a bounded employee approved-time-off roster query and index.