Development Update — 2026-08-16

by Jamie

Development Update — 2026-08-16

Share

Overview: Where Development Is Heading

Recent backend development is focused on maturing the OpenPGP/MIME signed outgoing email feature to be fully standards-compliant and interoperable with common email clients. The work centers on resolving MIME structure edge cases, ensuring proper inclusion of mail headers and multipart content in signed payloads, and adding supporting functionality like public PGP key attachment, with the immediate goal of delivering a stable, production-ready PGP/MIME signing implementation.

Overview: Where Development Is Heading

The frontend repository is currently prioritizing expanded internationalization support, with recent work implementing locale-prefixed URL routing segments and fallback redirects to deliver seamless localized user experiences. Development is also advancing OpenPGP well-known directory (WKD) integration, including required policy files, correct key formatting, and static file serving fixes, while addressing stability regressions from a reverted route-splitting refactor and edge cases in wallet connectivity and session token parsing.

Project Direction — Both repos are converging on a stable, production-ready NFT marketplace. The backend is hardening core systems while the frontend improves architecture and user experience.

Backend Commits

2b08d9c 2026-08-10 00:08:24
fix:
show plain/html as alternative inside signed PGP/MIME

e97908d 2026-08-10 00:07:04
fix:
ensure signed payload contains mail headers, not blank body

66aad0b 2026-08-10 00:04:35
fix:
wrap base64 at 76 chars and generate RFC-compliant Message-ID

9fb3a2e 2026-08-10 00:02:10
fix:
restore proper multipart/signed wrapper without forwarded text

cd9ecc2 2026-08-09 23:55:23
fix:
wrap plain+html in multipart/alternative inside multipart/mixed

5819410 2026-08-09 23:54:42
fix:
match valid PGP/MIME example with multipart/mixed inside multipart/signed

83318ea 2026-08-09 23:51:16
fix:
sign exact multipart/mixed payload and wrap it in multipart/signed

7fca8a5 2026-08-09 23:43:33
fix:
wrap multipart/mixed inside multipart/signed with plain+html

a5c5511 2026-08-09 23:41:26
refactor:
simplify PGP/MIME signing to minimal plain+html multipart/alternative

3f07253 2026-08-09 23:33:32
fix:
support binary PGP secret keys and keep both text/html in signed MIME

e913899 2026-08-09 23:32:32
fix:
include both plain and HTML parts in PGP/MIME signed email

c1a0220 2026-08-09 23:26:17
fix:
match Thunderbird-valid OpenPGP/MIME structure

b340961 2026-08-09 23:23:35
fix:
build valid OpenPGP/MIME signed messages matching Thunderbird structure

ffd352e 2026-08-09 23:09:03
fix(backend): generate detached OpenPGP signature for PGP/MIME

cbec696 2026-08-09 23:04:21
fix(backend): preserve from/to when sending raw PGP/MIME messages

c47a396 2026-08-09 23:03:10
fix(backend): add proper mail headers to raw PGP/MIME signed output

7ac17bd 2026-08-09 23:02:22
fix(backend): send real PGP/MIME signed outgoing mail

94def8d 2026-08-09 22:53:14
fix(backend): inline PGP signature in signed email text body

64480c4 2026-08-09 22:49:37
feat(backend): attach public PGP key to signed outgoing emails

f83c615 2026-08-09 22:47:33
fix(backend): resolve pgp import path from utils/email.js

5848efb 2026-08-09 22:46:27
fix(backend): sign system notification emails via PGP

bcbbffe 2026-08-09 22:37:20
fix(backend): sign all outgoing email messages with PGP

eeee702 2026-08-09 22:35:41
feat(backend): wire backend PGP signing from .pgpkey and ignore secret

c18aefb 2026-08-09 22:30:15
feat(backend): add backend PGP email signing support

4d67aa0 2026-08-09 20:21:49
feat(i18n): add backend locale detection and translated messages

Frontend Commits

c7d6a39a2 2026-08-16 23:52:38
feat(i18n): add locale-prefixed URL routing (/en, /fr, ...) as a URL segment

4b0f74993 2026-08-16 23:28:04
Merge remote-tracking branch 'origin/hermes' into hermes

8872c58aa 2026-08-16 22:54:12
feat(i18n): add locale-prefixed routes (/en/, /ja/, etc.) with fallback redirects

66a389e58 2026-08-11 05:12:37
fix:
keep AppKit hooks stable across renders in Navbar WalletConnect

4cae2b68b 2026-08-11 05:08:52
fix:
prevent double JSON.parse in Profile/SecInformation by using parseSessionToken() result directly

ccfe3d169 2026-08-11 03:30:08
On hermes: pre-checkout-640c75bd
7d5f5ec0d 2026-08-11 03:30:08 +0100
index on hermes: ec3ad21cb Revert "refactor: split route containers via React.lazy to reduce chunk sizes"

3d30ecd88 2026-08-11 03:30:08
untracked files on hermes: ec3ad21cb Revert "refactor: split route containers via React.lazy to reduce chunk sizes"

ec3ad21cb 2026-08-11 03:12:22
Revert "refactor: split route containers via React.lazy to reduce chunk sizes"

b9200494c 2026-08-11 03:03:45
fix:
add policy file for advanced WKD

82c590b6b 2026-08-11 03:01:40
refactor:
split route containers via React.lazy to reduce chunk sizes

6c95be3ce 2026-08-11 02:00:05
fix(openpgp): serve WKD hu key under checker-expected filename

fe6b4250c 2026-08-11 01:54:33
fix:
replace stale OpenPGP WKD hu file with correct public key from .pgpkey

e03c36f18 2026-08-11 01:45:38
fix(openpgp): convert WKD hu key to binary format

bbbc6258a 2026-08-11 01:40:02
fix(openpgp): add advanced WKD policy and CORS headers

41ce5f04b 2026-08-11 01:37:40
fix(openpgp): add missing .well-known/openpgpkey/policy file

d4a03cb26 2026-08-11 01:27:34
chore:
sync deps, add OpenPGP well-known key, fix doc typo

96d2a221b 2026-08-11 01:18:33
chore:
commit remaining package changes

a0d860090 2026-08-11 01:17:41
fix(build): remove unresolved history import and dead code in FAQ page

59c196372 2026-08-11 01:13:33
fix(App.tsx): restore valid JSX provider nesting

f4227ab8c 2026-08-11 01:09:53
fix(server): serve /.well-known/ static files from client dist

640c75bd7 2026-08-09 20:21:49
feat(i18n): add frontend locale layer and language switcher

8e1e53463 2026-08-08 03:01:44
docs:
update PROJECT_STATUS and REFACTOR to current hermes state

7bd9c1cd7 2026-08-08 02:48:41
chore:
remove unused frontend dependencies from package.json

bbb8e4f2d 2026-08-08 02:18:12
fix:
prevent signin/profile redirect loop by using sessionStorage token in ProfileRedirect