Changelog
Everything that changed between releases — from the first passwordless login engine to full observability in v2.5.
v2.5.0 Current
Module Activity Logs & observability
- New Activity Logs screen: server-side DataTable with global search, severity and event-type filters, severity badges, actor labels and metric cards (total events, failures, admin/user actions).
- New
hsc_magiclink_activity_logstable recording every event:token_requested,token_sent_admin,email_sent,email_failed,login_success,login_failed,token_invalidated,tokens_invalidated,token_deleted,rate_limit_exceeded,user_agent_mismatch,ip_mismatch. - Every email send is logged — client requests, admin sends and security alerts record
email_sent/email_failedin the Activity Logs. - Analytics Dashboard — token counts by status, successful logins with month-over-month trend, security events, throttled attempts, top users, recent activity and a system health panel.
- Audit table actions — per-row Invalidate (AJAX) and Delete (AJAX with SweetAlert confirmation, no page reload); deleting a record writes a
token_deletedentry to the Activity Logs. The Browser & Device column was removed from the audit table. - Automatic activity-log pruning via the daily cron (
PruneActivityLogsDays, default 60 days). - Active menu highlighting on all module admin pages.
v2.4.0
- Admin configuration page with granular settings: Strict IP Matching, Login Limit Threshold, Security Alerts toggle, Fallback Redirect URL and token pruning retention (
PruneLogsDays, default 30 days). - Daily cron job now auto-prunes old used/expired/invalidated/failed tokens.
v2.3.0
- Login Security Alert email — after every successful magic-link login the user receives a notification with account, date & time, IP address and browser/device (
EnableLoginSecurityAlert). - New Magic Link Security Alert email template with
{$user_email},{$login_time},{$login_ip},{$user_agent}merge fields.
v2.2.0
- Browser & device fingerprint binding — the requester’s User-Agent is stored as a SHA-256 hash (
user_agentcolumn) and validated at login (BindUserAgent).
v2.1.0
- Token status migrated from a legacy integer flag (
0/1) to string states —active,used,expired— enabling proper single-use/expiry lifecycle management.
v1.2.0
- Custom login button — optionally provide your own HTML for the login-page button instead of the built-in one.
v1.1.0
- Magic Link Request email template moved to the
useremail type (per-user delivery) and auto-created on activation if missing.
v1.0.0
- Initial release: passwordless magic-link login with single-use expiring tokens, IP matching, rate limiting, SSO sign-in via
CreateSsoToken, automatic token invalidation on password change and email-log suppression.