Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
bd8042c
fix: validate relationship lookup keys instead of rejecting them (#50)
Exotic209093 Oct 4, 2026
3dd484f
fix: update changed records by target Id on compare sync (#52)
Exotic209093 Oct 4, 2026
db82d7c
fix: reset import state on dataset change and gate advanced push (#44…
Exotic209093 Oct 4, 2026
f896107
test: mock chrome storage quota, alarms, and commands APIs
Exotic209093 Oct 4, 2026
bec7b2a
fix: per-row bulk results and source-row index mapping (#45, #46, #47)
Exotic209093 Oct 4, 2026
9f6f7b3
fix: restore typecheck for token-refresh payload and migration ID pai…
Exotic209093 Oct 4, 2026
ab2dade
Merge branch 'fix/v0.7-import-state' into release/v0.7.0
Exotic209093 Oct 4, 2026
47069d4
Merge branch 'fix/v0.7-lookup-compare' into release/v0.7.0
Exotic209093 Oct 4, 2026
fd8df52
test(soql): expect lowercase null literal for IS [NOT] NULL
Exotic209093 Oct 4, 2026
b93ff8b
fix(lint): clear the seven lint errors introduced by #112-#123
Exotic209093 Oct 4, 2026
1da073f
test(background): dispatch through every onMessage listener and fix m…
Exotic209093 Oct 4, 2026
bd52d74
test(api): cover rawCall same-origin passthrough and cross-origin block
Exotic209093 Oct 4, 2026
7e6feff
fix: check lookup match fields against the referenced object on Impor…
Exotic209093 Oct 4, 2026
183a36f
fix(bulk): send and read Bulk CSV values verbatim
Exotic209093 Oct 4, 2026
da73531
fix(migration): stop stalling on all-failed pushes and test ID pairing
Exotic209093 Oct 4, 2026
ce82e02
fix(storage): keep the quota guard from blocking or recursing on writes
Exotic209093 Oct 4, 2026
5749822
chore(deps): apply non-breaking npm audit fixes to dev dependencies
Exotic209093 Oct 4, 2026
6ad7834
Merge branch 'fix/main-green' into release/v0.7.0
Exotic209093 Oct 4, 2026
b9fef74
chore: strip stray BOMs and repair mis-encoded dashes in source comments
Exotic209093 Oct 4, 2026
d0f698d
chore(deps): upgrade jest to 30 and typescript-eslint to 8 to clear a…
Exotic209093 Oct 4, 2026
2431f58
fix(clone): pair inserted IDs with source rows by result index (#49)
Exotic209093 Oct 4, 2026
3c9d326
fix(import): report rows dropped at mapping in the error file
Exotic209093 Oct 4, 2026
a0c0224
Merge branch 'fix/v0.7-clone-dropped' into release/v0.7.0
Exotic209093 Oct 4, 2026
fac9c1e
fix(export): guard only string cells against CSV formula injection
Exotic209093 Oct 4, 2026
b2c8e83
fix(bulk): type Bulk query results from field describe metadata
Exotic209093 Oct 4, 2026
ec5efec
Merge branch 'fix/v0.7-export-fidelity' into release/v0.7.0
Exotic209093 Oct 4, 2026
35c1bb1
chore(release): prepare v0.7.0
Exotic209093 Oct 4, 2026
1ffd000
docs: record the maintainer's packaged-extension check for v0.7.0
Exotic209093 Oct 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 37 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,42 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.7.0] — 2026-10-04

The trust release: every defect from the 2026-08-31 audit (#40–#106) is fixed,
the CI gates are green again, and the write paths are re-validated against a
real development org.

### Fixed — imports and other writes
- **The file you review is the file that's pushed** — loading a new file on Import no longer pushes a previously cleansed dataset (#44), and changing the dataset resets mapping, validation, and stage progress so stale mapped rows can't be re-pushed (#51).
- **Retry keeps your mappings** — Retry Failed Rows restores the manual mappings used for the original push instead of re-running automap (#51).
- **Per-row results everywhere** — Bulk pushes report per-row errors and record IDs mapped back to the input rows; REST results carry their input index, so out-of-order batches and 204 upserts no longer shift IDs (#47). Rows dropped at mapping no longer shift error-file rows or make Retry re-send successful rows (#46), and now appear in the error file with their mapping error.
- **Bulk import keeps every column** — the CSV header is the union of all records' fields, explicit blanks clear fields with `#N/A`, and values are sent verbatim (no spreadsheet-guard apostrophes on `-`, `+`, `@` values) (#45).
- **Production typed confirmation on every route** — Advanced → Data Push now gets the same production gate and warnings as Import (#48).
- **Relationship lookups validate** — external-ID and related-field lookups pass validation, and the match field is checked against the referenced object's describe (#50).
- **Compare sync updates instead of duplicating** — Changed records are updated by target Id; only Added records are inserted (#52).
- **Undo, Copy between orgs, and Clone** — undo targets the right org (#42); Copy between orgs writes to the target org, builds its ID map, and no longer stalls on all-failed pushes (#43); clone and migration pair IDs with source rows by result index, not position (#49, #90).
- **No duplicate inserts from lost responses** — network errors on non-idempotent writes are no longer retried (#83).
- Dates no longer shift a day in UTC+ time zones (#53); Bulk error CSVs are parsed properly (#97); aggregates no longer produce silent `NaN` (#102); pipeline joins keep colliding right-side fields (#92).

### Fixed — schedules and long-running jobs
- Schedules keep their alarms across service-worker restarts, honour the selected time zone, and no longer revert edits or resurrect deleted schedules (#54, #55, #62).
- Snapshot writes report quota failures instead of recording success; the storage quota guard no longer blocks or recurses on writes; terminal checkpoints are pruned (#56, #63, #94, #99).
- Bulk jobs: no false "interrupted" or 10-minute-timeout failures, cancel works after restarts, no duplicate history rows, and tokens refresh mid-job (#57–#61).

### Fixed — security and export fidelity
- Session tokens are no longer persisted to `chrome.storage.local`, are not broadcast to every UI surface, and the REST explorer only sends the token to the org's own origin (#64, #65, #67). Privileged message handlers check the sender (#68).
- CSV and Excel exports neutralise spreadsheet formulas in text cells without turning real negative numbers into text (#66).
- Exports keep every column (no 14-column truncation, no 50-row sampling), drop nested `attributes`, write a UTF-8 BOM for Excel, and surface export failures (#69, #70, #72, #73, #79).
- Bulk exports type values from field metadata, matching REST — without corrupting leading-zero text, long IDs, or text that looks like `true` (#80).
- Snapshots, Compare, Convert, Saved Jobs, Activity, and SOQL escaping fixes (#71, #74–#78, #81, #82, #91, #93).

### Changed
- **Store listing** — new name ("WaveLink — Salesforce SOQL Export & Data Import Tool") and summary; permission declarations match the manifest (`unlimitedStorage` added, `activeTab` removed).
- The global Ctrl+Z shortcut no longer hijacks text-field undo, and the legacy tutorial no longer auto-opens (#84, #85). Accessibility attributes added across 34 components (#103).
- Upgraded Jest to 30 and typescript-eslint to 8, clearing all dependency audit advisories.
- `npm run validate:salesforce` now also checks Bulk per-row identity, ragged columns, blank-means-clear, verbatim values, and Bulk-vs-REST value types.

## [0.6.0] — 2026-08-31

### Added
Expand Down Expand Up @@ -83,6 +119,7 @@ in and out of Salesforce right from your browser, with nothing leaving your devi

- Initial release.

[0.7.0]: https://github.com/Exotic209093/WaveLink/releases/tag/v0.7.0
[0.6.0]: https://github.com/Exotic209093/WaveLink/releases/tag/v0.6.0
[0.2.0]: https://github.com/Exotic209093/WaveLink/releases/tag/v0.2.0
[0.1.0]: https://github.com/Exotic209093/WaveLink/releases/tag/v0.1.0
4 changes: 2 additions & 2 deletions PRIVACY.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,9 +43,9 @@ When you request an operation, the necessary authentication information, Salesfo

## 5. Chrome permission explanations

- **storage:** saves organisation connections, tokens, queries, mappings, jobs, schedules, snapshots, results, activity, and preferences locally.
- **storage:** saves organisation connections, queries, mappings, jobs, schedules, snapshots, results, activity, and preferences locally.
- **cookies:** reads the `sid` cookie from supported Salesforce domains to authenticate to an existing Salesforce session.
- **activeTab:** identifies the Salesforce context in the tab where you invoke WaveLink.
- **unlimitedStorage:** lets locally retained snapshots, checkpoints, and results exceed Chrome's default 10 MB extension-storage quota. The data stays on your device.
- **tabs:** finds open Salesforce tabs, lets you choose a connected organisation, and opens the full Extension workspace.
- **alarms:** wakes the Extension to run locally configured export schedules.
- **offscreen:** provides a local extension document for eligible long-running job and file-processing work when a visible page is not available.
Expand Down
96 changes: 53 additions & 43 deletions docs/CHROME_WEB_STORE.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Chrome Web Store release kit

This file is the source of truth for the WaveLink 0.6.0 listing and privacy declarations. Copy text exactly unless the Chrome Web Store dashboard requires a shorter value.
This file is the source of truth for the WaveLink 0.7.0 listing and privacy declarations. Copy text exactly unless the Chrome Web Store dashboard requires a shorter value.

## Dashboard and public links

Expand All @@ -18,49 +18,59 @@ npm run assets:store
npm run package
```

Upload `wavelink-0.6.0.zip`. The package contains the compiled Manifest V3 extension, icons, and bundled privacy page; it excludes source, tests, and build-only files.
Upload `wavelink-0.7.0.zip`. The package contains the compiled Manifest V3 extension, icons, and bundled privacy page; it excludes source, tests, and build-only files.

## Store listing

### Product name

> WaveLink — Salesforce Data Export & Import
> WaveLink — Salesforce SOQL Export & Data Import Tool

The product name comes from `public/manifest.json` and is 42 characters.
The product name comes from `public/manifest.json` and is 52 characters (limit 75).

### Summary

> Safely export, import, compare, schedule, and repeat Salesforce data jobs—directly from your browser.
> Export Salesforce data with SOQL to CSV, Excel, JSON or XML right in Chrome. No Java, no install, no server. Free and open source.

The summary comes from `public/manifest.json` and is 101 characters, below Chrome's 132-character limit.
The summary comes from `public/manifest.json` and is 130 characters, below Chrome's 132-character limit.

### Detailed description

> Move data in and out of your org with confidence.
> Get Salesforce data out in seconds — straight from the browser tab you're already logged into.
>
> WaveLink is a local-first data workspace for administrators, developers, and consultants. Query and export records, validate imports before they run, compare snapshots, schedule recurring exports, and replay saved jobs—all without sending customer data to a WaveLink server.
> WaveLink is a free, open-source data workspace for Salesforce admins, developers, and consultants. Write or build a SOQL query, preview the records, pick your columns, and download CSV, Excel, JSON, or XML. No Java runtime, no desktop Data Loader install, no third-party server holding your data.
>
> WHAT YOU CAN DO
> EXPORT
>
> • Export with SOQL through REST or Bulk API 2.0
> • Download CSV, JSON, Excel, or XML with only the columns you choose
> • Import CSV, JSON, and XLSX through a guided mapping and validation flow
> • Preview impact with dry runs, production warnings, and typed confirmation
> • Retry failed rows, download results, and undo supported inserts
> • Save reusable jobs and schedule local snapshots
> • Compare files, snapshots, or connected orgs
> • Copy a reviewed single-object dataset between connected orgs
> • Inspect objects, records, API usage, and schemas in Advanced tools
> • SOQL editor with autocomplete, plus a visual query builder for fields, filters, GROUP BY, and aggregates
> • REST for quick queries, Bulk API 2.0 for large objects — with progress and cancel
> • CSV, Excel (XLSX), JSON, or XML with only the columns you choose
> • Save queries as reusable jobs and re-run them in one click
>
> BUILT FOR SAFER DATA WORK
> SNAPSHOTS AND COMPARE
>
> The target org, environment, operation, and record count remain visible before a write. Bulk jobs keep resumable checkpoints, and unified activity history makes results and eligible recovery actions easy to find.
> • Schedule recurring local snapshots of key objects
> • Compare two files, two snapshots, or two connected orgs field-by-field
>
> LOCAL-FIRST PRIVACY
> IMPORT
>
> WaveLink has no analytics, telemetry, advertising, or developer-operated backend. Data is stored in your browser and exchanged only with Salesforce domains selected by you. Uploaded records, query results, snapshots, job history, account details, and authentication information are handled only to provide the features you request. See the privacy policy for complete handling and deletion details.
> • Guided CSV, JSON, and Excel import with field mapping, validation, and dry runs
> • Production warnings and typed confirmation before writes
>
> Requires an active Salesforce browser session. WaveLink is independent and is not affiliated with or endorsed by Salesforce, Inc.
> ADVANCED
>
> • Record Inspector, object and field browser, REST/Tooling API explorer, anonymous Apex, and API usage
>
> PRIVATE BY DESIGN
>
> WaveLink has no analytics, telemetry, advertising, or WaveLink backend. Your records stay in your browser and are exchanged only with the Salesforce orgs you select. Source code: https://github.com/Exotic209093/WaveLink
>
> Uses your existing Salesforce browser session. WaveLink is independent and is not affiliated with or endorsed by Salesforce, Inc.

### Localised listing

Add **Español** in the dashboard with the Spanish summary and description in
[`launch-kit.md`](launch-kit.md#spanish-listing-store-listing--add-language--español).

### Category and language

Expand All @@ -69,15 +79,15 @@ The summary comes from `public/manifest.json` and is 101 characters, below Chrom

### Release notes

> WaveLink 0.6.0 is a major workflow, safety, and reliability update:
> WaveLink 0.7.0 is the "data you can trust" release — every known data-corruption, automation, and security defect from the August audit is fixed:
>
> • New task-first interface and seven-stage Guided Import
> • Unified Saved Jobs, Schedules, Snapshots, and Activity
> • Bulk API 2.0 query support and resumable job checkpoints
> • CSV, JSON, Excel, and XML exports with selected-column support
> • Production typed confirmation and clearer org context
> • Improved accessibility, performance budgets, and package security
> • A focused, single-object Copy flow replaces the former migration suite
> • Imports push exactly the file and rows you reviewed; retry and error files target the right rows
> • Bulk imports keep every column, clear fields correctly, and report per-row results
> • Production typed confirmation on every write route; relationship lookups validate
> • Undo, Copy between orgs, and Compare sync work correctly (no duplicates)
> • Schedules survive browser restarts and fire on time in your time zone
> • Session tokens no longer stored at rest; exports neutralise spreadsheet formulas
> • Exports keep every column, non-ASCII text, and REST-consistent value types

If no release-notes field is shown, keep this text for the submission notes rather than appending it to the permanent description.

Expand All @@ -88,15 +98,15 @@ Upload in this order:
| Order | File | Dimensions | Purpose |
|---:|---|---:|---|
| Icon | `public/icons/icon-128.png` | 128×128 | Store and install icon |
| 1 | `screenshots/screenshot-01-home.png` | 1280×800 | Connected Home workspace |
| 2 | `screenshots/screenshot-02-export.png` | 1280×800 | SOQL export and results |
| 3 | `screenshots/screenshot-03-import-review.png` | 1280×800 | Production-aware import review |
| 4 | `screenshots/screenshot-04-compare.png` | 1280×800 | Compare workspace |
| 5 | `screenshots/screenshot-05-activity.png` | 1280×800 | Jobs and activity history |
| 1 | `screenshots/screenshot-02-export.png` | 1280×800 | SOQL export and results |
| 2 | `screenshots/screenshot-01-home.png` | 1280×800 | Connected Home workspace |
| 3 | `screenshots/screenshot-04-compare.png` | 1280×800 | Compare workspace |
| 4 | `screenshots/screenshot-05-activity.png` | 1280×800 | Jobs and activity history |
| 5 | `screenshots/screenshot-03-import-review.png` | 1280×800 | Production-aware import review |
| Small promo | `screenshots/promo-small-440x280.png` | 440×280 | Required promotional tile |
| Marquee promo | `screenshots/promo-marquee-1400x560.png` | 1400×560 | Optional large promotional tile |

All screenshots are captures of v0.6.0 at the required dimensions. Organisation, user, and record identifiers are redacted. Regenerate promotional graphics with `npm run assets:store`.
All screenshots are captures of v0.6.0 at the required dimensions; the 0.7.0 changes are fixes with no visible layout change on these screens. Organisation, user, and record identifiers are redacted. Regenerate promotional graphics with `npm run assets:store`.

## Privacy practices

Expand All @@ -108,15 +118,15 @@ All screenshots are captures of v0.6.0 at the required dimensions. Organisation,

**storage**

> Saves selected Salesforce org connections and authentication information, queries, mappings, reusable jobs, schedules, snapshots, results, activity history, checkpoints, undo information, and preferences in Chrome extension storage. This keeps the workspace available across extension sessions without a WaveLink backend.
> Saves selected Salesforce org connections (without access tokens, which are kept only in memory-backed session storage), queries, mappings, reusable jobs, schedules, snapshots, results, activity history, checkpoints, undo information, and preferences in Chrome extension storage. This keeps the workspace available across extension sessions without a WaveLink backend.

**cookies**

> Reads the Salesforce `sid` session cookie from supported Salesforce domains so the user can connect an already authenticated org and make requested API calls. WaveLink does not read cookies from unrelated domains.

**activeTab**
**unlimitedStorage**

> Identifies the Salesforce context in the tab where the user invokes WaveLink. It is not used to inspect unrelated page content.
> Lets locally retained snapshots, job checkpoints, and result files exceed Chrome's default 10 MB extension-storage quota so scheduled snapshots and large jobs are not silently truncated. All of this data stays on the user's device and can be purged from Settings.

**tabs**

Expand Down Expand Up @@ -174,14 +184,14 @@ The repository must be pushed before saving this URL so reviewers can reach the

## Final submission checklist

- [ ] Push the v0.6.0 code and public privacy policy to `main`.
- [ ] Push the v0.7.0 code and public privacy policy to `main`.
- [ ] Confirm the privacy-policy URL loads while signed out of GitHub.
- [ ] Upload `wavelink-0.6.0.zip` and confirm version 0.6.0 is detected.
- [ ] Upload `wavelink-0.7.0.zip` and confirm version 0.7.0 is detected.
- [ ] Replace the description with the text in this file.
- [ ] Upload all five screenshots in the documented order.
- [ ] Upload the icon and promotional tiles.
- [ ] Verify category, language, homepage, support URL, and privacy URL.
- [ ] Reconfirm every permission and data-use declaration against the uploaded package.
- [ ] Add the v0.6.0 release notes where the dashboard permits.
- [ ] Add the v0.7.0 release notes where the dashboard permits.
- [ ] Preview the public listing at desktop width and check every image crop.
- [ ] Save the draft, review the dashboard's warnings, and submit only after a final joint check.
Loading
Loading