Release v2026.10.3-deploy.cf5d82d8f649Surgery

Surgery v2026.10.3-deploy.cf5d82d8f649

This patch tightens web authentication so valid sessions are less likely to be cleared during token refresh, and account changes reset cached data more cleanly. It also adds a documented HIPAA implementation plan that states enablement is still planned and recommends synthetic patient data until the required agreements, controls, and review are complete.

October 3, 2026

Highlights

01

Web sessions now survive token refresh more safely, which reduces incorrect sign-outs.

02

Login, logout, and auth changes now clear cached query data to prevent one account's data from lingering into another session.

03

Release checks now cover the web app's auth refresh path before shipping.

04

The deployment runbook now documents how to recover a verified production publication receipt without redeploying.

05

A new HIPAA implementation plan sets explicit guardrails: HIPAA enablement is not complete, and synthetic patient data should be used for now.

Changelog

What changed in v2026.10.3-deploy.cf5d82d8f649

Features

  • Added a HIPAA implementation plan for the current AWS EC2 + Neon deployment, including provider agreement steps, application gaps, and release gates before using real patient data.
  • Added an operations workflow to recover a verified production publication receipt by source SHA without rebuilding or redeploying the app.

Improvements

  • Improved access-token refresh handling in the web app so concurrent requests share one refresh flow and auth failures return clearer session-expired behavior.
  • Improved auth-state synchronization in the web app by broadcasting auth changes and re-syncing the current user from storage.
  • Expanded release validation to run web app auth/session tests during the release workflow.

Fixes

  • Fixed a web auth issue where a late or stale refresh flow could clear a valid newly authenticated session.
  • Fixed account isolation during auth changes by clearing stored session state and cached query data when users log in, log out, or the session expires.

Screenshots