Skip to content

Release 2026.30 - #410

Merged
abroa01 merged 14 commits into
mainfrom
development
Jul 17, 2026
Merged

abroa01 merged 14 commits into
mainfrom
development

Conversation

@abroa01

@abroa01 abroa01 commented Jul 17, 2026

Copy link
Copy Markdown
Collaborator

This pull request introduces major improvements to biometric login and recovery on mobile, adds a robust MongoDB healthcheck endpoint for production monitoring, and includes related tests and configuration updates. The biometric changes provide a better user experience for lost or rotated biometric credentials, while the new healthcheck endpoint enables automated liveness and readiness checks for deployments.

Biometric login and recovery improvements:

  • Enhanced biometric login flow in Login.jsx to detect missing or rotated biometric credentials, prompt users for PIN fallback, and guide them through secure biometric re-enrollment when needed. This includes new helpers (isMissingBiometricSecret, clearBiometricEnrollment, setBiometricRecoveryNeeded), state management for recovery, and a new modal UI for biometric re-setup. ([[1]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6R6-R46), [[2]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6R115-R127), [[3]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6L102-R146), [[4]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6L119-R179), [[5]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6L143-R202), [[6]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6R221-R232), [[7]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6R244-R327), [[8]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6L243-R377), [[9]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-44be06dbf6c345c97fed250217cf591dd19bf418cbcc78cc050d48006d4e8fc6R513-R567))
  • Updated BiometricRegistrationModal.jsx to clear legacy keys and recovery flags after successful biometric setup. ([client/mobile/src/ui/Modal/BiometricRegistrationModal.jsxL50-R51](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-bd0c78396ccb9357240bd4858baf65deeae825ee9042b03b1e5796ad17ba094fL50-R51))

Production healthcheck endpoint:

  • Added server/healthcheck.js implementing a /healthcheck HTTP endpoint that verifies MongoDB connectivity and writability using ping, hello, and isMaster commands. The endpoint returns detailed JSON for health monitoring, with correct status codes and support for both GET and HEAD requests. ([[1]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-6274b0325c6bd4bb3df82bccf122274a2c798b60adc8bd7befcd6389862b450eR1-R94), [[2]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-d3f9f1ac91aa1bf0f85894eb43eb424f26c61fd0e44eeb8c0787f48a0ba511ecR44), [[3]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-d3f9f1ac91aa1bf0f85894eb43eb424f26c61fd0e44eeb8c0787f48a0ba511ecR62-R68))
  • Added comprehensive tests for the healthcheck logic, covering healthy, legacy fallback, unwritable, and unavailable MongoDB scenarios. ([[1]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-b4664e9ed887b56f51303b3587f89789d0a33fc24faf0f5264f483d8976094f9R1-R112), [[2]](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-2ab7c3c5008dfeaf54c1692893b6e2677fe5b9afc15935d7c94e515f383deab3R3))

Other improvements:

  • Updated DashboardHeader.jsx header positioning for improved mobile and desktop compatibility. ([client/mobile/src/ui/components/DashboardHeader.jsxL30-R30](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-9e476ce4d1dca845682073a266cee2138f29d0117b68cf3bc7344d30886d9462L30-R30))
  • Updated mobile-config.js to declare only standard HTTPS/TLS is used, skipping the App Store export-compliance prompt. ([mobile-config.jsR36-R43](https://github.com/mieweb/mieweb_auth_app/pull/410/files#diff-ab46c1f22be6bfac7191b6d3a633ac1895a4f1c70c8fe296768a0d199392c7daR36-R43))

These changes together improve user experience, operational reliability, and deployment readiness for the application.

morepriyam and others added 14 commits June 27, 2026 15:52
…compliance prompt

The app uses only standard HTTPS/TLS (exempt encryption), so set the key to
false in Info.plist via mobile-config.js. This stops App Store Connect from
showing 'Missing Compliance' and requiring a manual answer on every upload.
Skip TestFlight export-compliance prompt for iOS builds
- Use MongoInternals.defaultRemoteCollectionDriver().mongo.db.admin()
  instead of rawCollection().db which is undefined on MongoDB driver v4+
  (endpoint returned 503 'admin command interface unavailable' even when
  Mongo was connected and writable)
- Fall back to legacy isMaster command when hello (4.4+) is unavailable
- Send no body on HEAD responses (RFC 9110)
- Add test for the hello->isMaster fallback path
Address review feedback (runleveldev): the readiness check no longer
calls .admin(). The ping/hello/isMaster commands are exempt from MongoDB
access control and run on any database, so the check works with the
standard MeteorJS grant (read-write on the app DB, read-only on local)
without requiring any privileges on the admin database.
Add MongoDB-aware `/healthcheck` readiness endpoint for HA failover
Fix biometric recovery after device restore
fix: prevent mobile header from clipping greeting
@abroa01
abroa01 merged commit 5ccd85e into main Jul 17, 2026
2 checks passed
@abroa01 abroa01 linked an issue Jul 17, 2026 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release 2026.30

3 participants