VERSION HISTORY
WHAT'S NEW
Latest first. Production and Development use the same release notes.
VIEW ALL SOURCE ON GITHUB ↗Measure notification board opening
Time a notification tap through the first visible board and break down game and account requests.
- Show the last notification-to-board timing on the opened game, labeled by whether the app reused or opened a window.
- Record bounded request-stage and board-opening durations without storing positions or game identifiers in the timing event.
Faster board opening
Skip repeated database setup and unnecessary asset downloads when opening a game.
- Use published database migrations directly on hosted requests while retaining the storage continuity check.
- Serve cached build-hashed scripts, styles and fonts without downloading them again on every game open.
Open boards catch up on your turn
A move notification refreshes the matching game already open on your screen.
- Refresh the exact open board from the authoritative game state when an opponent turn push arrives, without opening the notification.
- Read again after an in-flight poll and on mobile page resume; keep normal polling as a fallback.
Fixed-scale mobile play
Keep menus and games at a fixed scale while preserving scrolling, dragging and the repaired history controls.
- Disable touch zoom across menus and boards, correcting the v0.31.1 interpretation of the feedback.
- Keep one-finger menu scrolling, piece dragging and protection against accidental multi-touch moves.
- Document the alpha release policy: publish tested changes after green GitHub CI without another release approval prompt.
Reliable mobile filters and pinch zoom
Tap history filters reliably and zoom the board without making an accidental move.
- Stop invisible history radio inputs from covering adjacent filters, and enlarge history and language controls.
- Allow pinch zoom over chess pieces while keeping one-finger dragging; cancel the drag when a second finger touches the screen.
- Reserve space for the Settings button beside History navigation and preserve keyboard access to hidden radio controls.
Challenge alerts, planned moves and your language
Receive new challenge notifications, plan your reply while a friend thinks, and choose English or Hebrew for your account.
- Send direct challenge alerts to the invited player's registered devices, including older installed app versions.
- Save one planned move that plays automatically if legal after the opponent replies, even with the app closed.
- Save English or Hebrew separately for each player's game and settings.
- Load notification games alongside account checks and reuse an open app for faster navigation.
Security updates and clearer invitation checks
Update vulnerable dependencies, show saved openings before accepting, and improve notification-test recovery.
- Patch Next.js, image processing and ID-generator dependencies; require the security audit before release.
- Show whether White has already moved in incoming dashboard and activity invitations.
- Offer an immediate restart when a notification test loses earlier evidence, and clean up through the current service worker.
- Preserve mixed-language player names in status and recap text.
Invite now, play whenever
Leave after inviting a friend, or save your opening move before they accept.
- Make it clear that invitations are saved and you do not need to be online together.
- Let White play one opening turn in a pending day-paced game; your friend gets the full move limit when they accept.
- Preserve the opening through acceptance, retries and concurrent actions, with notifications for the correct player's turn.
Keep turn notifications until you act
Opening the browser or viewing your game no longer dismisses its current turn notification.
- Keep the reminder until you tap or dismiss it, or a newer game position makes it obsolete.
- Let you return manually during the four-round test and still tap the notification from Android’s notification drawer.
Simpler notification test, English by default
Follow one clear step at a time while checking all four real notifications on your phone.
- Show one instruction and one primary action, with the complete test results and real game available on demand.
- Keep every delivery, tap, game-opening and user-confirmation check, with clear retry and restart paths.
- Use English throughout sign-in, games, menus, settings and notification diagnostics while preserving user-entered text.
Four-turn Android test on one device
Test closed-app notifications through four real turns against Riot Bot on the phone you are holding.
- Start the guided test from Settings or the new-game page, with no second device or account.
- Riot Bot waits eight seconds before each real reply; the ordinary turn queue sends only to the device that started the test.
- Inspect server delivery, persistent device receipts, notification taps and exact-game opening separately, then confirm the Android notification you saw.
Recover notification setup and unblock healthy devices
Notification recovery is visible, existing device consent survives lost local preferences, and failing endpoints no longer hold up other devices.
- Prioritized first delivery attempts and used durable retry and lease times to drain each notification lane within its request budget.
- Preserved an account-confirmed device registration when its local preference is missing, while respecting explicit disable and dismiss choices.
- Added an optional, in-flow setup recovery notice with visible errors and a Not now action; notification taps recover when Android retires a window.
- Verified mixed-device failures, future leases, retry recovery without additional requests, and four alternating opponent turns in the built Worker. Physical Android delivery and long-outage recovery remain separate verification requirements.
Recover games and notifications without stale screens
Game entry now starts in native Hebrew, stalled reads always offer an exit, accepted games update immediately, and Android notification recovery stays visible.
- Rendered protected game, invitation, Activity, and Settings states in native Hebrew before first paint while preserving left-to-right board coordinates and notation.
- Bound response-body reads, added visible Retry and Home recovery, clarified player referral links, and made lost join-response retries safe for the same account.
- Queued the creator's first-turn push exactly once when a link or direct challenge is accepted, and removed stale waiting copy as soon as the authoritative game becomes active.
- Made one global Activity bell available on every signed-in route and surfaced an actionable Android notification-block banner with safe Settings guidance and an explicit status recheck.
Make multiplayer deadlines authoritative
One-, three-, and five-day games now enforce the same exact deadline across every action, account view, invitation, and notification path.
- Guarded moves, draw claims, resignations, and reactions with SQLite statement time, persisted delayed timeouts at their exact deadline, and suppressed expired turn pushes.
- Settled overdue games before Home, History, and Activity reads, while preserving legacy no-deadline games and consistent results for both seats.
- Required signed invite previews, disclosed pace before link or direct acceptance, removed stale cross-account seat redirects, preserved new invite links without local storage, and restricted waiting-challenge cancellation to its creator.
- Expanded built-worker coverage across every 1/3/5-day create, join, move, reset, rejection, timeout, result, reaction, notification, and Play Again path.
Repair the notification lifecycle
Opted-in devices now repair missing subscriptions, preserve newer turn alerts, and drain durable delivery work without coupling lanes or over-leasing slow backlogs.
- Recreated missing or rotated browser subscriptions after granted consent, and required a focused authoritative game before clearing its turn alert.
- Serialized game-version-aware re-alerting and clearing so overlapping same-game pushes retain the newest turn while an exact provider retry stays deduplicated.
- Bound every delivery batch to one target per lane, isolated lane failures, terminalized exhausted rows, and made stale disablement and cap eviction preserve audit records until the 30-day sweep.
Retry short push outages within the request
Opponent-turn and friend-request pushes now get a bounded third attempt without relying on an unsupported Sites background trigger.
- Retried failed notification lanes at about 0, 2, and 17 seconds while reserving time inside the Worker's post-response execution limit.
- Prioritized due failures over fresh pending rows, capped the final round to one row per failed lane, and preserved durable leases and superseded-turn checks.
- Added policy and end-to-end coverage for two provider failures followed by acceptance, and documented that later recovery still needs API traffic on Sites.
Prepare scheduled notification retries
The release packaged a scheduled retry trigger, but live Sites validation did not produce the recurring event required for autonomous recovery.
- Added an every-minute Cron declaration while preserving immediate delivery and the short first retry.
- Verified that the declaration survived the build, then found no scheduled invocation in Development after the provider propagation window.
- Kept the scheduled handler for a future compatible host and moved current Sites reliability to the bounded request-time policy in v0.27.4.
Prioritize Control notifications on mobile
Control-triggered player messages now use the same immediate delivery class and request the same persistent presentation as ChessRiot’s working Android device test.
- Changed exact-player Control messages from deferrable normal Web Push urgency to high urgency, matching turn alerts, friend requests, and the exact-device test.
- Unified diagnostic and ordinary service-message presentation so a passing device test no longer exercises a more visible notification branch than Control.
- Derived every service-message tag from the signed one-time grant nonce and added regressions for urgency, topic safety, and persistent service display.
Diagnose notification delivery
The device test now distinguishes browser registration, push-service acceptance, service-worker receipt, notification creation, and operating-system presentation instead of claiming an unseen alert was displayed.
- Made the local test persistent with a unique tag and verified that the active service-worker registration retained it before advancing to the server test.
- Added a version handshake plus an exact one-time marker to the encrypted server push, then reported browser receipt, notification API resolution, and retained-notification stages to the same-origin Settings page without exposing an endpoint or payload.
- Replaced the false two-tests-sent success message with stage-specific results, desktop Windows banner and Do Not Disturb recovery, and Brave’s official independent notification test.
Make notifications reach the device
Notification setup is now one explicit browser-to-server transaction, friend requests can alert closed devices, and challenging a friend is a primary action.
- Moved PushManager subscription and device registration into the Enable action, removed game-snapshot cancellation from notification setup, adopted late browser subscriptions safely, and made Not now revoke any late result.
- Added an exact-device test that separates local system display from server Web Push delivery, with fixed payloads, account ownership checks, and provider-stage outcomes.
- Queued friend-request alerts atomically with the request, retried transient delivery failures, suppressed rapid cancel-and-resend notification spam, and deep-linked notification taps to the actionable Activity inbox.
- Promoted Challenge a friend to the signed-in Home primary action, kept Riot Bot explicit, clarified the opponent and waiting-for-acceptance flow, and made the four Home actions responsive on tablet and mobile widths.
Make Android notification recovery honest
Notification setup now identifies the failing browser or server stage, stays off the board, and safely resumes an interrupted Android Allow result.
- Separated service-worker, subscription, serialization, server-status, and device-registration failures into privacy-safe diagnostics, showing Brave Google Push Messaging guidance only when browser subscription creation fails.
- Moved setup errors entirely into Settings with a recovery bell, resumed a granted-but-interrupted onboarding decision after reload, and prevented a stale onboarding card from overwriting a concurrent Settings choice.
- Made service-worker precaching fail soft so one unavailable optional icon or manifest cannot abort background notification installation.
Keep notifications optional
The one-time notification ask can always be skipped, and a browser or push-setup failure can never block play or loop after reload.
- Restored a clear Not now choice while keeping Enable notifications as the one user gesture that opens the browser permission request.
- Recorded the ask once per retained site and browser profile, independent of username, so skipping, switching accounts, or reloading cannot repeat it automatically.
- Made every post-permission setup failure terminal for onboarding, moved interrupted setup repair into the non-blocking app lifecycle, added browser-versus-server diagnostics, and kept deliberate recovery in Settings without re-entering the account gate.
Ask the browser once
ChessRiot now makes one real notification-permission attempt per retained browser/device profile instead of repeating a username-level soft opt-in.
- Added one shared notification step for new and existing signed-in players, whose single Continue action opens the real browser permission request before play.
- Stored the attempt at the website and browser/device level before calling the permission API and serialized simultaneous tabs, so dismissal, denial, failure, reloads, and account changes cannot trigger automatic repeats.
- Made granted-but-interrupted setup resume subscription and server registration without another native prompt, while keeping Settings as a deliberate manual recovery path.
Make notifications one clear choice
Mobile players can enable ChessRiot notifications once per device, and Control can safely test one exact player without a broadcast path.
- Added a dedicated mobile notification step after username onboarding and one inline offer for existing signed-in players, with Enable and Not now choices that never cover a game board or trigger permission without a click.
- Moved notification consent to an account-level device registry, so one opt-in covers existing and future multiplayer games while legacy per-game consent stays narrow until explicit re-consent.
- Made Settings the permanent global device control, detached subscriptions across sign-out and account changes, repaired rotated browser endpoints, prevented duplicate turn alerts during migration, and retained bounded stale-endpoint and transient-failure handling.
- Added owner-only Control inspection and single-player service/test sends with Unicode usernames, fixed title and destination, Production confirmation, single-execution signed grants with safe result replay, budgets, privacy-safe logs, and push-service-only result wording.
Keep alerts off the board
Turn-alert setup no longer blocks mobile play, and Magic failures identify whether Production rejected the key or denied compiler access.
- Replaced the full-screen mobile turn-alert reminder with a one-time bell badge on Settings while keeping the per-game opt-in available inside Current game.
- Remembered the alert offer per game, matching the existing per-game subscription scope without repeatedly covering play.
- Separated rejected OpenAI credentials from project-permission failures in safe operational error codes and clarified that Magic checks support before creating a World.
Keep cold releases observable
A new deployment now establishes its continuity baseline during the first root load, while health remains read-only and real storage changes still fail closed.
- Initialized the environment's storage epoch and account-identity mirror from the first root request after migrations, before Control can mistake an untouched release for a broken version.
- Kept the public health route strictly read-only and preserved hard failure when D1, object storage, environment identity, or account identity no longer matches.
- Added an end-to-end cold-release proof that root initialization creates the mirrored baseline and a later D1 binding swap is rejected.
Make failure states recoverable
Magic errors now explain what failed without enabling free token spend, opponent-turn alerts survive transient failures, and deployments guard account access continuity.
- Committed each opponent-turn alert atomically with its move and added leased, bounded retries for network timeouts, rate limits, and temporary push-service failures.
- Revalidated the exact game version before delayed delivery, used an opaque push topic, cleaned expired endpoints, and stopped global provider incidents from disabling healthy devices.
- Kept Android alerts visible until an authoritative matching game snapshot opens, then cleared them, and made notification taps deterministic with a safe new-window fallback.
- Made compiled Magic rules a staging state and finalized the canonical World, compilation cache, source, and paid entitlement together before Apply Magic can succeed.
- Classified rule, connection, timeout, provider, and configuration failures; capped output; cached semantic rejections; and added account/global compile budgets plus a shared failure circuit.
- Mirrored the permanent D1 storage epoch outside D1, made health read-only, guarded account-identity continuity, and preserved approved Magic flags through the full upgrade chain.
- Repaired the interactive knight tutorial and made multiplayer challenges, invitation sharing, acceptance, and the waiting state one clear start-game flow.
Make async turns calmer
Day-based games now focus on one visible move deadline, Quick Reactions are gone, and Android turn alerts can work after one per-game opt-in.
- Removed the Quick Reactions tab, panel, polling, bubbles, and client handlers from active and completed games.
- Removed cumulative live chess clocks from one-, three-, and five-day games while keeping the authoritative move deadline visible on mobile and desktop.
- Added a direct in-game Android turn-alert opt-in, complete VAPID configuration validation, and Brave-specific recovery guidance while keeping permission explicit and per game.
Choose your own alphabet
Permanent usernames now work in Hebrew and other writing systems, with a normal Android keyboard and clear validation feedback.
- Accepted Unicode letters, marks, and numbers in 3–20-character permanent usernames while retaining internal dot, hyphen, and underscore separators.
- Unified normalized caseless identity across username claims, lookup, challenges, Magic access, and deleted-name reservation while keeping destructive confirmation display-exact.
- Removed Android credential autofill and automatic display-name prefilling from the permanent-handle field, using a normal directional text keyboard instead.
- Made invalid, reserved, taken, and unavailable username errors visible in one announced inline location without trapping the player behind disabled controls.
- Promoted the same tested source tree to Development and Production while preserving isolated data, OAuth credentials, secrets, and access policies.
Create a chess multiverse
Magic Rules now compile explicitly into immutable, forkable Worlds with canonical wallet-style codes, a simple credit economy, and a connected popularity map.
- Added Apply Magic as the only paid compilation boundary, with an empty prompt, an example placeholder, durable global reuse, and one exact game entitlement per credit.
- Added canonical World identity so equivalent rules, phrases, ordering, and languages resolve to the same 160-bit displayable hash while the full digest guards collisions.
- Added creator attribution, parent-to-fork connections, World pages, and an accessible map whose node size follows games with a human move.
- Started every account with 10 credits, changed referral rewards from 100 to 10, and awarded World creators 1 credit after every 5 paid games in which the paying account makes a legal move.
- Made paid Apply requests safe under concurrency, interruption, and replay, and kept creator exports aggregate-only so popularity never reveals another player’s private game metadata.
- Moved active-game World rules out of the board column and into the desktop sidebar or the mobile World drawer.
- Extended Google-established ChessRiot sessions to a sliding one-year window while preserving immutable recent-authentication time for destructive account actions.
Make launch signals fast
Control analytics now reaches Development reliably by replacing cold request-time schema work and scattered queries with one indexed aggregate read.
- Changed the owner-only analytics endpoint from request-time schema initialization plus ten independent database calls to one migration-backed D1 batch.
- Removed three unused daily-series queries and added time-filter indexes for accounts, games, moves, friend requests, referrals, and actor activity.
- Preserved the privacy-safe aggregate contract and mature signup-to-first-move journey without exposing player identifiers.
Replay the finish
Completed matches can now become revocable public replays, while optional onboarding, safe recovery, and a leaner accessibility path prepare Development for launch testing.
- Made the 45-second tutorial fully opt-in from Settings, with no automatic first-account modal, stronger focus movement, live step announcements, and immediate reduced-motion transitions.
- Removed every public link to the current 90-second demo and excluded it from indexing while preserving the direct QA route and bounded owner-only regeneration workshop for a future replacement.
- Added bounded, coalesced recovery for account, signed-home, and initial game reads, including timeout, online, focus, visible-tab, and expired-session handling without ever retrying a game mutation automatically.
- Added opaque, participant-created public recap links for completed games with a read-only board, move replay, result details, native sharing, explicit revocation, and automatic revocation during account deletion.
- Kept recap pages free of seat keys, invitations, account identifiers, and mutation access, and made them noindex with a fresh opaque URL after revocation.
- Added keyboard skip navigation, stronger focus and forced-colors behavior, coarse-pointer target sizing, whole-second hidden-tab-aware clocks, and lower-cost visuals for Save-Data and very slow links.
- Added a privacy-safe mature-cohort signup-to-first-move aggregate for separate Development and Production monitoring without player identifiers or cross-environment joins.
- Updated the demo story recipe for future regeneration to describe optional onboarding and shareable recaps while leaving the current bundled video archived and unadvertised.
Ask for the key
Locked early-access features now offer a clear invitation request, while Control gives the owner an exact queue for individual admission.
- Added a one-click Magic Rules invitation request with a durable Requested state and no false promise of immediate access.
- Added an exact red-badged Control queue that keeps Development and Production separate and supports one-account approval or dismissal.
- Made approval atomic with the existing server feature flag, reject replay and arbitrary feature or username input, and keep pending players blocked from Magic creation.
- Included pending requests in privacy export, removed them with account deletion, and kept access-request telemetry typed and identifier-free.
- Kept local and embedded previews usable by generating client telemetry identifiers with the existing secure browser-compatible UUID helper.
Keep every promise
The launch-readiness release now closes tutorial, export, and retention edge cases before wider rollout.
- Made Escape use the same durable Skip path as the tutorial button, so a failed save leaves the tutorial open with a retry message instead of stranding the account.
- Changed account export to keyset-paginate complete game and move history and added an explicit completeness summary instead of silently stopping at fixed row caps.
- Applied telemetry and moderation-archive retention on every API request, with expired records excluded at their cutoff and physically removed on the next service request.
Know what needs your move
A fast tutorial, one Activity inbox, player safety, privacy controls, launch analytics, and a truthful new demo prepare ChessRiot for 1.0.
- Added a skippable account-backed 45-second tutorial with interactive legal-move practice, Activity preview, durable completion, and Settings replay.
- Added one unread Activity inbox for friend requests, challenges, turns, and results, with inline responses and block-aware durable read state.
- Added outgoing-request cancellation, friend removal, bidirectional blocking, unblock management, private category-based safety reports, and an owner-only moderation queue.
- Added a Privacy & Data center for readable export, blocked-player management, and recently reauthenticated permanent deletion with username reservation and anonymization.
- Added a privacy-safe aggregate analytics API and a separate Control Analytics center with environment and time-window isolation plus honest unavailable states.
- Rebuilt the 90-second signed-out explainer around required accounts, permanent usernames, onboarding, Activity, friends, one-screen play, History, and data controls, with native captions and a final sign-in action.
- Moved Google Analytics 4, Hotjar, and any deeper 90-second interactive lesson to an explicit high-priority backlog instead of shipping third-party tracking by default.
Bring your next rival
Personal player invites now turn a shared link into an instant connection, a ready challenge, and a protected new-player credit reward.
- Added one stable personal invite link per player with native sharing, clipboard fallback, and an invite landing page centered on the inviter.
- Connected players as friends automatically so either player can immediately configure and send a challenge.
- Awarded 100 credits only when a genuinely new Google account joins through the link and completes its permanent username.
- Protected rewards with first-touch attribution, one reward per new account, self-referral rejection, atomic credit and friendship writes, and privacy-safe route logging.
- Made selected History filters legible by removing the inherited duplicate-shadow effect while preserving their selected-state contrast.
Your chess circle, all in one place
Required accounts, permanent usernames, friends, richer skins, and a focused game screen make ChessRiot feel complete across devices.
- Required Google sign-in for play and added one-time, globally unique username onboarding with clear character, safety, and permanence rules.
- Added a signed-in dashboard, automatic complete game history, username-based friend requests, and direct configured challenges with explicit accept or decline controls.
- Kept Magic Rules Coming Soon for most players while adding an owner-controlled, server-enforced account whitelist for supported experimental rules.
- Added cumulative player clocks and tightened the active-game layout so the board, status, and primary controls fit one common desktop or laptop screen.
- Added Mythic Beasts as the twelfth whole-app skin and gave every skin a richer, more distinctive procedural score and themed sound profile.
- Split sound-effect and music volume, added icons to Settings sections, and made every on/off preference a clear checkbox.
- Improved legal-target visibility, homepage piece alignment, capture and promotion motion, and the reduced-motion-safe postgame presentation.
- Separated the signed-out homepage from the account dashboard, moved legal links into registration, and aligned Development and Production on one tested source release.
Private links stay decisive
The final Google-login audit keeps exact seat links authoritative and legacy Development history visible.
- Made an exact private-seat token select that seat even when the browser also carries a different account membership.
- Made guest-to-account linking and concurrent game retries settle safely without silently changing ownership.
- Preserved recent-game discovery for protected Development users who still have legacy Sites-only memberships.
Your games, one account
Optional Google login lets new and explicitly linked games follow you across devices.
- Added environment-isolated Google OpenID Connect with exact callbacks, PKCE, signed state and sessions, and no stored provider tokens or email addresses.
- Kept guest creation, invitations, and exact private seat links fully usable when Google sign-in is absent or unavailable.
- Allowed a signed-in player to add only the exact legacy private seat they explicitly present, while keeping ordinary game reads ownership-neutral.
- Published current identity-independent Privacy and Terms routes from the same source in both environments and linked them from the public shell and Settings.
- Isolated the Development and Production OpenAI keys and added one fixed-marker, opt-in live LLM smoke test with no default CI spend.
- Implemented exact Development and Production OAuth callback routes while keeping Development protected by its Sites user allowlist.
One world, one menu
Skins now shape the whole experience, while one Settings menu gathers audio, assistance, feedback, and game actions.
- Applied all 11 skins before paint across the homepage, setup, menus, board, pieces, music, and special effects.
- Unified duplicate controls into one accessible Settings menu with independent sound, music, master-volume, coach, celebration, notification, surrender, privacy, and version controls.
- Added low-key skin-specific music, longer piece-specific captures, special check, castling, queen-loss, promotion, and white-flag resignation effects.
- Replaced the separate replay dialog with a compact current-move row and expandable full move table, plus a complete captured-piece panel.
- Added a default-on local risk coach for obvious material losses and small tactical fork celebrations, each independently optional.
- Hardened bounded request parsing, health readiness, observability privacy, response headers, Magic compatibility, dependencies, CI, and release artifact validation.
Every piece fights different
Captures now become short piece-specific combat, while missing required fields explain exactly what needs attention.
- Added distinct pawn, knight, bishop, rook, queen, and king capture actions with a visible victim reaction and impact.
- Kept combat pointer-transparent and non-blocking on top of the immediate optimistic board for both human and Riot Bot moves.
- Reconstructed en passant, capture promotion, and atomic two-leg effects from immutable move history without replaying them on refresh or history views.
- Added red inline errors, accessible descriptions, and first-invalid-field focus to Create Game, Join Game, and Feedback.
- Published /capture-lab as the visual regression surface for all six combat actions and reduced motion.
Instant moves and classic finishes
Moves now feel immediate in every game, and a new Mating Set teaches three essential endings.
- Painted locally legal Multiplayer moves immediately while preserving server-authoritative validation, rollback, and stale-write protection.
- Added Solo practice for King + Pawn, King + Rook, and King + Two Bishops against Riot Bot's lone king.
- Kept one version link in the active-game header so the duplicate global label cannot overlap the board.
- Retired Staging from the active deployment and owner-feedback model, leaving Development and Production.
Three new ways to riot
A new game menu launches three smaller chess setups in both Solo and Multiplayer.
- Added Pawn Riot, Half Army, and Pawn Duel while keeping Classic Chess selected by default.
- Made every setup server-owned, immutable, and compatible with Riot Bot, invitations, history, replay, and deadlines.
- Disclosed the selected game before joining and throughout the active match without accepting arbitrary starting positions.
Feedback, accounted for
The owner control panel can count unresolved feedback exactly and safely mark individual items done.
- Added exact new, reviewed, closed, and unresolved feedback counts independent of the bounded item list.
- Added a separate short-lived feedback-management grant and an idempotent close action.
- Recorded privacy-safe feedback completion events with normalized routes and no feedback content.
Invitations, copied
Multiplayer invitations now copy straight to the clipboard instead of opening the operating system share sheet.
- Replaced the native share dialog with one direct Copy invitation link action.
- Confirmed successful copies in place and kept the private link selectable when clipboard access is unavailable.
Riot Bot on the board
Solo replies now appear locally almost at once and both plies are saved together by one authoritative request.
- Ran the same deterministic Riot Bot search in the browser and on the server, preserving every level’s evaluation, depth, and node budget.
- Showed the human move first, then its predicted bot reply, while keeping the board locked until the server confirms the turn.
- Revalidated the bot reply server-side and atomically stored the human and bot plies in one database batch.
- Removed the second bot request and successful post-commit database reads while retaining pending-turn recovery for older or interrupted games.
Riot Bot, right away
Riot Bot now answers promptly even when the hosted edge freezes its runtime clock during search.
- Added a deterministic node cap alongside the existing elapsed-time search budget.
- Kept every bot level’s depth, move ordering, evaluation, and tactical checkmate behavior unchanged.
- Added a frozen-clock regression that reproduces the hosted runtime and bounds Level 5 search.
Community within reach
The ChessRiot WhatsApp community is now one tap away from both the public homepage and the in-game App panel.
- Added a clear WhatsApp community link to the public homepage.
- Added the same link to the App panel without interrupting the current game.
- Centralized the destination and opened both placements safely in a separate tab.
Your turn, even when closed
A multiplayer seat can now opt one browser into a generic turn notification for one game, including after ChessRiot is closed.
- Added opt-in Web Push turn alerts to each multiplayer game’s App panel.
- Bound every browser subscription to one game and one authorized seat, so disabling one game leaves that device’s other game alerts intact.
- Delivered notifications only after a committed opponent move, with duplicate suppression, stale-endpoint cleanup, and no private seat key or player detail in the payload.
- Restricted push endpoints, validated notification navigation, and kept delivery best-effort so a push-service failure can never affect the chess move.
Riot theme verified
The release checks now follow the new flat Riot default.
- Updated rendered-page regression coverage from the retired Blockfield label to Riot.
Crisp 2D chess
The board and pieces now use one clean, modern 2D visual system instead of bevels, block shadows, and platform-dependent glyphs.
- Introduced six original flat vector silhouettes shared by live play, drag, promotion, captures, replay, recent games, and checkmate.
- Rebuilt board squares, frames, coordinates, move targets, captures, selection, and check states with solid color and clean rings.
- Made Riot the fresh teal-and-ivory default while preserving every existing theme as a palette choice.
- Replaced the tilted homepage mock board with a front-on 2D board using the same production pieces.
One game, still moving
The 90-second demo now follows Ron and Omri through one asynchronous match, with the video filling the page instead of sitting below a large headline.
- Replaced the feature-list narration with a complete story from warm-up through invitation, reply, return, and replay.
- Made the video occupy roughly 90–94% of the viewport width and reduced the page heading to a compact label.
- Reordered the real interface captures around the story while removing inactive Magic Rules from the narration.
- Versioned the storyboard contract so an outdated Control build cannot publish stale video over the current story.
ChessRiot in 90 seconds
A narrated, captioned walkthrough now shows Solo, themes, replay, and private multiplayer before you start a game.
- Added a public 90-second demo page linked directly from the homepage.
- Built the walkthrough from current Development interface captures with narration, subtitles, and audio.
- Separated video regeneration from application releases by publishing validated media through a versioned R2 manifest.
- Added a signed, owner-only, rate-limited regeneration lane for the ChessRiot Control panel.
Cleaner foundations
Shared gameplay presentation and request logic is now easier to maintain without changing how ChessRiot plays.
- Centralized board orientation, piece labels, difficulty labels, outcome text, and live status text.
- Centralized new-game request payloads and authenticated client request helpers.
- Added focused regression tests while preserving the Magic Rules Coming Soon boundary.
Magic safely paused
Magic Rules remain visible, but new rule entry is paused while the feature develops in isolation.
- Replaced new-game Magic rule entry with a clear Coming Soon placeholder.
- Removed the runtime LLM compiler, its endpoint, and its token-consuming path from the stable release.
- Moved active Magic development to an isolated feature branch and preview lane.
Solo from the start
New games now open in Solo mode, while preserving White's first move in every game.
- Selected Solo by default on the new-game screen and showed the Level 3 Riot Bot control immediately.
- Kept Multiplayer one tap away without changing either mode's saved behavior.
- Added regression coverage for the default selection and the existing White-first invariant.
First-move history fix
Back now works even while the first Magic move of a game is still being staged.
- Kept the Back arrow available at ply zero when a staged Magic position is visible.
- Made Back cancel that draft and reveal the authoritative starting position.
History polish
History now follows the position you can actually see, with stronger mobile and keyboard behavior.
- Kept the immediately previous position available while a Solo move is shown optimistically.
- Made Back from a staged Magic first leg return to the latest authoritative position without skipping a ply.
- Removed historical board squares from keyboard navigation while keeping their position labels available.
- Moved history controls outside the live status announcement and enlarged their mobile touch targets.
- Restored focus safely after move confirmation, including promotion and committed-move flows.
- Clarified that Confirm every move is stored in the current browser.
History at hand
Browse earlier positions directly on the board and optionally confirm every move before sending it.
- Added always-visible Back and Forward arrows that step through committed positions without changing the live game.
- Kept historical viewing pinned when a new move arrives, with a direct Go Live control and frame-specific check, captures, and last-move highlights.
- Added a browser-local Confirm every move setting that is off by default.
- Applied one confirmation to every human move path, including tap, drag, promotion, and complete atomic Magic turns.
- Blocked stale and duplicate confirmations before they can submit a move.
One front door
ChessRiot now has one fixed public homepage and direct guest play with no login gate.
- Made the public homepage identical for every visitor, independent of hosting identity and saved game theme.
- Moved new-game setup to /app and enabled guest Solo and Multiplayer creation with a display name.
- Made private seat links authoritative for guest play while preserving existing account memberships and older games.
- Limited themes to active games so public, setup, invitation, changelog, loading, and error pages keep one consistent style.
- Removed all user-facing login prompts and kept the retired CAPTCHA path absent.
Direct entry
Players now enter ChessRiot immediately, without a separate human-check screen.
- Removed the Turnstile screen, verification request, and CAPTCHA-bound application session.
- Kept trusted hosting identity, account-bound game membership, request-origin checks, and account rate limits.
- Retired the old CAPTCHA endpoint and redirected existing verification entry points safely into the game.
Knights move twice
Magic knights can now move twice, and game requests work correctly inside the production sandbox.
- Made “Knights move twice.” a real deterministic Magic Rule for Solo and Multiplayer games.
- Generalized atomic two-leg turns so the same enabled rook or knight may move again, while a checking first leg still ends the turn.
- Kept existing v1 Magic Rule documents readable and unchanged while storing knight-enabled games in the compatible v2 schema.
- Extended tap, drag, keyboard, replay, move history, labels, and Riot Bot play to two-step knights.
- Fixed the production request-origin blocker without relaxing cross-site protection.
Magic Rules
Every new Solo or Multiplayer game can optionally carry its own safe, immutable rule changes.
- Added an optional Magic Rules box to game creation with a concise natural-language prompt.
- Compiled recognized prompts into versioned rules and rejected unsupported text instead of executing arbitrary code or silently ignoring it.
- Added atomic two-step rook turns: the same rook may move again before the turn ends, while giving check ends the turn immediately.
- Added no-promotion, no-castling, and no-en-passant rules with server, client, replay, and Riot Bot enforcement.
- Showed Magic Rules before joining, during play, in replay and move history, and on My Games cards.
Every game, every turn
A complete My Games history and account-aware alerts make asynchronous play reliable across devices.
- Added cursor pagination so My Games can reach the complete account history instead of stopping at 50 games.
- Added clear Your turn, Opponent's turn, Waiting, Won, Lost, and Draw states to every game card.
- Made open-app opponent-move alerts watch all owned multiplayer games through the account session.
- Removed the alert dependency on a legacy private-seat token or the currently open game route.
- Added a clear Switch Account action through the trusted ChatGPT sign-out flow.
Secure accounts and a bigger board
Account access, a human check, a board-first layout, and original illustrated themes make ChessRiot safer and more immersive.
- Required a ChessRiot account and server-verified CAPTCHA before any game could be created or played.
- Added account-bound game access, per-account rate limits, and bot-turn leases to reduce automated abuse and duplicate AI work.
- Made the board fill the available desktop or mobile viewport and collapsed secondary match tools.
- Showed the starting position before animating Riot Bot’s White opening when the player starts as Black.
- Placed captured Black pieces with White and captured White pieces with Black.
- Added seven original illustrated theme backgrounds, including medieval army and moonlit castle styles, plus two new themes.
Viewport clearance
Short desktop and landscape layouts keep the board, replay, and controls usable.
- Kept the complete game board above the utility dock across common desktop heights.
- Preserved usable game and replay board sizes in short landscape viewports with vertical scrolling.
- Added clearance after the final mobile card and compacted replay controls around the board.
- Removed a duplicate checkmate announcement and made invalid deadline text neutral.
A more personal async game
Themes, replay, safe reactions, install support, and real move deadlines deepen every match.
- Added nine original themes for the app, board, pieces, panels, and background.
- Added an accessible visual picker that works from every route and synchronizes across tabs.
- Added six rate-limited, preset-only multiplayer reactions, a per-game hide control, and a 15-minute Good Game or Thanks courtesy window.
- Added a short theme-aware victory finisher with reduced-motion support.
- Added a read-only game replay with step controls and keyboard navigation.
- Added one, three, or five-day multiplayer move deadlines, defaulting to three days.
- Added installable PWA support, an unseen-release dot, and opt-in open-app opponent-move notifications.
- Made the exact release version visible on every route and state.
Instant move polish
Immediate solo moves now keep their sound and complete observability trail.
- Restored one accepted move or capture sound for the human ply.
- Restored game-completion telemetry when Riot Bot delivers the final move.
- Kept race telemetry limited to the move that actually committed.
Instant solo moves
Your piece now moves immediately while Riot Bot thinks in the background.
- Added a reversible local preview for every legal solo move before the server response arrives.
- Made the human move durable and visible before Riot Bot starts its reply.
- Added background bot-turn recovery so refresh or browser closure cannot strand a solo game.
Unmistakable piece colors
White and Black now use the same solid voxel-piece shapes with clearly contrasting colors.
- Replaced hollow White glyphs with solid light pieces so the player color cannot look inverted.
- Reduced the bright outline on Black pieces so they read as Black at a glance.
Laptop viewport polish
The complete board now stays inside a common laptop viewport at normal browser zoom.
- Tightened the desktop height cap after real-browser visual QA so the board no longer clips at the bottom.
A clearer, complete game board
The board now fits shorter screens, makes player colors and check unmistakable, and adds captured pieces and game-ending controls.
- Made the full board fit common laptop screens at normal browser zoom and increased important label sizes.
- Added explicit White and Black player cards plus captured-piece trays.
- Highlighted the checked king and explained exactly when a move fails to answer check.
- Added New Game and confirmed End Game or Cancel Game actions.
- Renamed computer difficulty to bot level.
A faster start and clearer releases
A much simpler home screen, visible board motion, in-app feedback, and a public version history.
- Simplified the new-game flow around name, mode, difficulty, and one primary action.
- Added short move and capture animations with reduced-motion support.
- Added a feedback form and an owner-only feedback pool.
- Added this changelog to every environment.
Correct solo turns and observability
Riot Bot can now play either color correctly, chess draw rules are more precise, and operations are visible per environment.
- Riot Bot opens automatically when it is White.
- Added claimable and automatic FIDE draw handling.
- Added privacy-safe health, action, error, and latency telemetry.
Version safety
Changed deployments can no longer silently reuse or decrease the app version.
- Added a single SemVer source and release commands.
- Added build-time checks for reused or inconsistent versions.
Solo play and drag controls
Play Riot Bot at five difficulty levels, or drag pieces in multiplayer.
- Added persistent solo games against Riot Bot.
- Added five difficulty levels with Medium as the default.
- Added mouse and touch drag-and-drop while preserving tap and keyboard input.
Portable private links
Private player links now work across computers and the game has a block-world visual identity.
- Embedded the private seat credential safely in the URL fragment.
- Added explicit private-link sharing and cross-device recovery.
- Restyled the complete experience with an original voxel-inspired look.
Identity, sound, and resilience
The first polish release added ChessRiot’s visual identity, game sounds, and reliability fixes.
- Added move, capture, check, result, and invalid-action sounds.
- Added mute controls, clearer loading, and safer local storage.
- Improved invitation, status, and promotion interactions.
Playable async chess
The first public prototype let two people create, join, resume, and finish a legal asynchronous chess game.
- Added one-use invitations and private player seats.
- Added complete standard chess rules and immutable move history.
- Added persistent two-device play with server-authoritative state.