This patch applies targeted UI refinements: action signals are more precise, the golden avatar ring is now shown only on the active or winner seat, replay displays stay consistent across state transitions, and missing follow-up community cards now use a filled-in simulation path. Core hand logic, chips, and payment behavior are unchanged.
The golden avatar ring now marks only the active or winner seat, so the hero seat no longer stays highlighted incorrectly.
Replay displays stay more consistent across state transitions, reducing stale visuals from prior hands.
Replay simulation now fills in missing follow-up community cards.
A reused signal path was clarified so action cues are less likely to fire incorrectly.
Poker rules, chip flow, and payment behavior remain unchanged.
Released
H5BackendMarketing site
Publishing the production load-test numbers and capacity boundary
The capacity post now publishes the test machine and measured boundary: a Tencent Cloud SA2.MEDIUM4 with 2 vCPU, 3.6 GiB of memory, and 2 Mbps fixed public egress. In the solo-table model, 150 concurrent players stayed within budget, 200 exceeded the latency budget, and 300 collapsed; in the six-player model, two runs at 60 players across 10 tables straddled the budget (69 ms and 157 ms server p99), while 120 players across 20 tables clearly exceeded it. The post also states that public-egress utilization was not sampled, so the collapse cannot be attributed solely to CPU, scheduling, or bandwidth. The H5 and backend also fix membership-status error handling: a failed lookup stays unknown instead of turning a database error into a false “does not auto-renew” message. Poker rules, chips, and payment prices are unchanged.
Publishes the production host: 2 vCPU, 3.6 GiB memory, a 3 GiB app-container limit, 2 Mbps fixed public egress, with Postgres and Caddy on the same machine.
Publishes the solo-table boundary: 150 players passed the latency budget, 200 exceeded it, and 300 collapsed.
Publishes the six-player-table boundary: two 60-player, 10-table runs straddled the budget at 69 ms and 157 ms server p99; 120 players across 20 tables clearly exceeded it.
A failed membership-status lookup stays unknown; H5 says “does not auto-renew” only when the absence of a manageable recurring subscription is explicit.
Labels the connection and table guards as a 2026-08-21 deployment snapshot and states that public-egress utilization was not sampled.
Released
H5BackendMarketing site
Staged membership rollout, clearer subscription status, and refreshed product media
The Max welcome campaign can now grant to one eligible canary account while pausing automatic grants to new registrations, then open the remaining rollout only after the membership and in-app message are verified. The H5 membership sheet now always presents the actual entitlement expiry date and shows management controls only when a manageable recurring subscription exists; members without one see that the membership does not auto-renew, instead of gifts or one-time purchases being described as an upcoming renewal. The marketing site's bilingual table, review, stats, and solver product scenes and sharing images are regenerated from the current H5 interface. Poker rules, chips, and payment prices are unchanged.
Campaign operators can restrict a batch to one eligible account; registration, guest upgrade, email verification, and OAuth linking cannot bypass that canary boundary during verification.
Removing the staged restriction and opening grants to later registrations happen in the same campaign-state update, while existing membership and notification grants remain idempotent.
The H5 membership sheet labels every date as “Valid until” rather than promising a next renewal from store state the service cannot confirm locally.
Auto-renew controls or store-management links appear only when a manageable recurring subscription exists; gifted and one-time membership no longer exposes a dead-end control.
The site's bilingual table, review, stats, and solver product scenes and sharing images are regenerated from one current H5 source baseline and pinned by hash.
Released
iOS
iOS 1.1.3: in-app memberships, a sign-in fix, and working legal links
iOS 1.1.3 build 353 is now live on the App Store. This update brings BluffKing memberships inside the iOS app for the first time: Pro and Max monthly and yearly plans are purchased directly through the App Store and managed or cancelled in the system subscription settings — the previous public build, 1.1.1, shipped no in-app purchases at all. It also adds six-digit email-code registration with a clearer account-recovery flow, fixes the create-account screen staying stuck loading after a failed sign-in, and makes the Terms of Use (EULA) and Privacy Policy open from both the membership purchase screen and the Legal & privacy screen. The Privacy Policy and App Support links on the App Store listing now resolve; they previously pointed at a retired address. Membership does not affect dealing, practice-chip settlement, or game outcomes.
iOS gains in-app Pro and Max memberships for the first time: monthly and yearly plans are purchased through the App Store and managed or cancelled in the system subscription settings.
Adds six-digit email-code registration with a clearer sign-in and account-recovery flow.
Fixed the create-account screen staying stuck loading after a failed sign-in.
Terms of Use (EULA) and Privacy Policy open directly from both the membership purchase screen and the Legal & privacy screen.
The App Store listing's Privacy Policy and App Support links now resolve; they previously pointed at a retired address.
Released
H5BackendMarketing site
Registered-user Max gift and in-app notifications
BluffKing can now use an auditable, idempotent membership campaign to grant 30 days of Max to every eligible registered user and send a bilingual H5 in-app message inviting suggestions and bug reports through the official X (Twitter) or Telegram channels. Activation covers existing accounts; new registrations and upgraded guest accounts receive the grant automatically after email verification or OAuth identity linking while the campaign remains active. An existing Max term is extended from its current end rather than overwritten or shortened. Guest, staff, test, and deleted accounts are excluded, and reactivation cannot duplicate either the entitlement or notification. This release creates no orders, changes no payment price, and adds no new redemption entry to the Flutter embed or Telegram client.
A staff writer explicitly activates the campaign and the actor is recorded; applying the database migration alone never starts the bulk grant.
Each eligible registered user receives exactly one 30-day Max entitlement and one in-app message, protected by unique constraints, row locking, and an idempotency key.
The H5 Home bell shows an unread dot; the message follows the selected language and exposes only the official X (Twitter) and Telegram feedback links.
New registrations and upgraded guest accounts receive the gift after email verification or OAuth identity linking while the campaign is active; deactivation stops later grants without revoking anything already issued.
The gift extends an existing Max term through the entitlement ledger without creating payment orders or rewriting historical order and revenue data.
Released
H5BackendMarketing site
Measured capacity, service-wide rate limits, and two new bilingual engineering posts
We measured what the production server actually holds and used that number to add the capacity controls the backend was missing: an in-flight request bound, a request deadline, live connection and table ceilings, and per-caller limits on the endpoints that previously had none. Overload now returns an explicit retry-later response with Retry-After instead of slowing everyone down; health checks and static assets are unaffected, and the table ceiling never refuses a join — though when every connection slot is taken the server is full for new connections of any kind. The marketing site also adds two bilingual engineering posts: how to measure your own service's ceiling, and how to rate-limit properly. Poker rules, accounts, membership, and payments are unchanged.
Measured what the production server actually holds and set the operating point at 80 % of that ceiling instead of estimating it.
Added the backend's missing global capacity controls: in-flight request bound, request deadline, live connection and table ceilings, with an explicit Retry-After response under overload.
Added per-caller limits to the endpoints that previously had none, and unified the 429/503 response shape.
Health checks and static assets are exempt by design, and the table ceiling refuses only the creation of a new table, never a join — the connection ceiling is global and applies to every new connection.
The site adds two bilingual engineering posts: measuring your service's ceiling, and rate limiting properly.
Released
H5BackendMarketing site
H5 Max membership redemption and iOS WebView stability
Registered users can now redeem BluffKing-issued Max membership codes from the H5 profile, while the entry remains hidden in the Flutter embed and Telegram. Staff can issue codes in batches, bind them to a recipient, set expiry, revoke unused codes, and atomically grant a 30-day Max reward when accepting feedback. Codes are stored only as digests, with single-use redemption, idempotent retry, and a membership entitlement ledger preventing duplicate or unauthorized claims. This release also contains iOS WebView focus-access failures within the host boundary and improves their diagnostics, re-captures marketing product scenes from the current H5 UI, and regenerates sharing images from the deterministic site template; poker rules and practice chips are unchanged.
Registered H5 users can open redemption from the profile or the /me?redeem=1 deep link; Flutter-embedded and Telegram hosts do not expose the entry.
Staff can batch-issue 30-day Max codes, bind recipients, set expiry, revoke unused codes, and copy plaintext that is shown only once.
Feedback acceptance and reward-code creation commit in one database transaction, with at most one live reward code per feedback item.
The database stores only SHA-256 code digests and trailing hints; single-use redemption, row locks, idempotent retries, rate limits, and a source-neutral entitlement ledger protect membership grants.
iOS WebView focus-access failures are contained at the host boundary with additional stage and DOM-context diagnostics for aggregation.
Four bilingual product scenes are re-captured from the current H5 UI, while both sharing images are regenerated from the deterministic site template.
Released
Marketing site
New bilingual article: What FDEs actually do
The marketing site adds a bilingual public guide to FDE work, directly answering what the role does, which day-to-day problems it solves, and which skills matter, using AI agents entering established customer-service, logistics, and restaurant workflows as the central example. This release only updates marketing content; it does not change H5, backend, gameplay, accounts, memberships, or payments.
Adds the Chinese and English article “What FDEs Actually Do: AI Agents in Traditional Industries,” combining public sources, employee accounts, and the author's own comparison in one practical answer.
Released
H5BackendMarketing site
Human-table action-window and reconnect fixes, accessibility and site updates
This H5/backend release gives every human decision window a server-issued epoch that the client returns with bet, check, fold and other actions. A delayed action from an expired or disconnected window can no longer land on that seat's later decision; reconnect snapshots restore a window only when it is still provable, otherwise the client clears the stale epoch. H5 and the marketing site also improve small-text contrast and key touch-target sizes, while the advanced encrypted-dealing disclosure now states its operating boundaries more precisely. A bilingual engineering article corrects the historical account of engine-blind dealing, and four bilingual product scenes are re-captured from the current H5. Poker rules, practice chips, memberships and payment behavior are unchanged.
The backend issues a decision_epoch for every human action window; the updated H5 echoes it so an expired or in-flight action cannot spill into the same seat's later decision.
Reconnect snapshots carry both the live action deadline and epoch: the client restores a provably current window and clears an unprovable epoch, so a valid post-reconnect action is not silently discarded.
H5 language, password-recovery, OAuth and empty-state actions, plus marketing navigation, legal pages, footer and pricing links, gain stronger text contrast or touch targets of at least 44px.
The advanced encrypted-dealing disclosure now states its full-human practice-chip scope, that the server holds no unrevealed hole-card plaintext, and the operator-trust, remote-binary-verification and disconnect-reveal boundaries.
A bilingual engineering article corrects the engine-blind release history to ADR-101, and the table, review, solver and stats product scenes are re-captured in English and Chinese from the current H5.
Released
H5BackendMarketing site
Outs-calculator, classic-table spectating, coach-verdict and hand-history fixes, localized errors and UI copy, lobby/room/account reliability fixes
This release folds in the fixes from three quality loops. Table and tools: the free outs calculator no longer counts a flush or straight draw that lives entirely on the board as yours; the classic table no longer shows a phantom seat or seated-only controls while you are spectating; your stack is no longer briefly double-counted when a stack update arrives as a hand settles; the quick calculators and the fairness-verify page localize server-side errors. Coach and review: the post-hand coach never grades the big blind's free option as a fold, recognises the hand-level aggressor, and describes preflop spots by starting hand rather than a postflop made-hand band; hand history shows showdown ranks in your language, labels uncontested pots clearly, and adds ranks for revealed opponents. Lobby, rooms, accounts: backing out of a public table joined by code frees the seat, the legacy join-by-code endpoint enforces the block list and reports host status correctly, room preview returns an explicit error on database failure, room-code digits are exactly uniform, nicknames at sign-up / guest upgrade are checked against the same character allowlist, and email change returns 500 rather than "expired" on database failure. UI: hardcoded English copy across drills, review, setup, lobby, quick-bet chips and accessibility labels is localized; calling-station AI opponents no longer stack off while drawing near-dead. Backend reliability fixes (closing back-pressure-evicted connections, export/stats error codes, refund-queue cascade on account erasure) ship too, and the AGPL §13 corresponding-source subset is republished with this release. The marketing site's product screenshots are refreshed to this UI. None of this changes memberships or payment behavior.
The outs calculator (/tools and POST /api/tools/poker/outs) now requires at least one of your hole cards to take part in a flush or straight draw, so outs are never overcounted.
Classic-table spectating hides the hero zone, start-hand, bust and take-a-seat prompts, makes empty seats inert, and shows a read-only spectator banner.
When a stack update arrives as a hand settles, the client drops that seat’s staged pot payout first and adopts the server value.
Post-hand coach: a preflop free option is never graded as a fold, and the coach reads the hand-level aggressor (not just the current street), so continuation-bet / semi-bluff barrel rules are reachable.
Quick calculators and the /fairness verify page localize server-side 400 errors by reason_code instead of echoing raw English.
The spectator-roster name separator is localized, and Home / Lobby player entries no longer keep a stale “spectator” badge.
Backend: back-pressure-evicted WebSocket connections are closed and detached; export and stats endpoints return 500 on database failure; account erasure cascades refund-queue rows (migration 0072).
Hand history: showdown ranks are localized (no more raw enums like high_card), uncontested pots read "won pot (no showdown)", and revealed opponents get a rank label too.
Post-hand coach describes preflop spots by starting hand (AKs, JJ+ …) instead of postflop "weak pair / overpair" bands.
Lobby/rooms: backing out of a public table joined by code frees the seat; the legacy join-by-code endpoint enforces the block list and reports host status correctly; room preview returns an explicit error on database failure; room-code digits are exactly uniform.
Accounts: nicknames at sign-up / guest upgrade use the same character allowlist as the profile page; email change returns 500 instead of "expired" on database failure.
UI copy: drill title / board / hint captions, review timeline, setup persona strip, lobby VPIP, classic-table quick-bet POT prefix and accessibility labels are all localized.
AI opponents: calling-station personas no longer stack off while drawing near-dead for most of their chips.
Backend source and tests pass strict formatting and all-target Clippy checks; trusted-QA self-tests no longer depend on implicit temp files in sandbox-denied locations.
The AGPL §13 corresponding-source subset is republished with this release (public tag solver-src-2026-08-19-2); the postflop solver’s source link points at the new tag.
Marketing site: product screenshots and OG images re-captured from this release's H5 UI (four scenes × EN/ZH).
Released
Marketing site
New engineering article: Don't leave the second-order pin to memory
The marketing site adds a bilingual engineering article on making a tool emit the downstream repin step when it changes a content-hash-protected release file, and on turning a dangerous stale assertion into a regression guard. This release only updates marketing content and internal release guidance; it does not change H5, backend, gameplay, account, membership, or payment behavior.
Adds the bilingual article “Don’t leave the second-order pin to memory,” distilling the reusable release-automation pattern that receipts beat reminders and bad assertions should be inverted.
Released
Backend
Improving BNB payment endpoint resilience
This backend release accompanies an operational configuration rotation away from a BNB USDT RPC endpoint that persistently rate-limited log queries. Before release, the replacement candidate and existing fallback each passed production-egress probes for chain ID, block height, finality, log queries, and transaction receipts. Every deployed process still independently re-attests its configured endpoints at startup and retains only those that pass full validation; it continues to fail closed when none are healthy. Deposit addresses, the custody recovery anchor, prices, membership entitlements, and gameplay are unchanged.
Operational configuration no longer uses the RPC endpoint that returned HTTP 429 for eth_getLogs on two consecutive production starts.
Before release, the replacement candidate and existing fallback passed production-egress probes; runtime admission is still decided independently at each startup.
Provider quarantine and fail-closed behavior are unchanged; payment amounts, custody, and gameplay are unaffected.
Released
Android
Android 1.1.5: privacy and sign-in fixes
Android 1.1.5 build 356 is now live on the Google Play production track. This update ensures public display names are never derived from your email address, fixes the sign-in screen getting stuck loading after a failed login, and links the applicable Terms of Use and Privacy Policy for this platform in the subscription flow. Poker rules, practice chips, accounts, and payment behavior are unchanged.
Public display names are never derived from your email address.
Fixed the sign-in screen staying stuck loading after a failed attempt.
The subscription flow now links the applicable Terms of Use and Privacy Policy for this platform.
Released
BackendMarketing site
Android 1.1.5 version catalog and site labels
The public app-version catalog served at /api/app/version now advertises Android 1.1.5 build 356, so older installs get an update prompt at the right time; the marketing site’s store labels and product facts are synced to Android 1.1.5. No gameplay, account, or payment changes.
The /api/app/version catalog now advertises Android 1.1.5 build 356.
The marketing site’s store badges and product facts now show Android v1.1.5.
Released
BackendMarketing site
Cleaner registration conflicts, static-analysis boundaries, and payment-node resilience
The backend now treats concurrent duplicate registrations as an expected conflict, preserving the existing response while avoiding database error-level noise for the expected 409; email verification and account-uniqueness protections are unchanged. When one BNB USDT RPC is rate-limited and another has fully passed chain-ID, capability, and freshness checks, the verifier quarantines the limited endpoint and starts with the attested provider; startup still fails if no provider passes or any configuration/semantic error is found. The marketing site adds the bilingual engineering article “When your static analyzer starts imagining the browser, stop proving.” Unready production candidates also preserve redacted startup diagnostics before rollback. Poker rules, chip settlement, and membership behavior are unchanged.
Concurrent duplicate registrations keep the same conflict result without logging an expected request as a database error.
Account uniqueness, email-verification proof, and transaction rollback semantics remain unchanged.
A new bilingual article explains when static checks should narrow the authoring rule and leave the remaining proof to a real browser test.
If an unpublished production candidate cannot become ready, the release flow preserves redacted startup diagnostics before rollback cleanup.
When one payment RPC is rate-limited, the service quarantines it and uses only a fully attested healthy provider; no healthy provider or a configuration error still fails closed.
Released
H5BackendMarketing site
Hotfix releases keep safety gates without the daily three-release cap
Emergency fixes now use a separate production-admission class: they neither consume the ordinary three-release daily allowance nor stop when that allowance is full. Only a first release authorized by the repository owner and bound to the exact target version can use this lane; changelog, review, build, cost, serialization, duplicate-release, and rollback safeguards all remain in force. Gameplay, accounts, membership, and payment behavior are unchanged.
Ordinary production releases remain capped at three per day; an authorized hotfix does not consume those three slots.
The emergency lane still records every release and retains exact-version, serialization, duplicate-release, cross-day, and rollback protections.
This update changes release reliability rules only; gameplay, accounts, membership, and payments are unchanged.
Released
H5BackendMarketing site
Multiplayer timeout handling and table-display fixes
In multiplayer tables, a seat is paused after three consecutive hands without a voluntary action: future deals and blinds stop, a 30-second countdown appears, and “Stay at table” keeps the seat; otherwise it is released. H5 also keeps committed-bet chips attached to their owner on compact screens and updates the visible stack and winner banner when a device cannot run the chip-flight animation. The marketing site adds the bilingual engineering article “Never wait for the latest CI run” and refreshes its English and Chinese product and social-sharing imagery to match the current table interface.
After three consecutive inactive hands, the seat pauses; reconnect keeps the same countdown, and the player has 30 seconds to explicitly stay before the seat is released.
Committed bets remain visually tied to their owner across 2–9-player layouts and clear the pot, board, and neighboring seats; animation failures no longer block settlement display.
A new bilingual article explains how to bind release waits to the exact workflow run and verify live effect through public version receipts; English and Chinese product and social-sharing imagery now matches the current table interface.
Released
Marketing site
Marketing-site releases join the unified changelog
Product updates now explicitly show marketing-site releases. Every future production release of the marketing site, H5, or backend adds a corresponding bilingual public update that names its web surface; iOS and Android continue to update when each store version is actually live.
The changelog adds a Marketing site channel label alongside H5, Backend, iOS, and Android.
Marketing-site production changes and H5/backend releases both require a matching public record through the release guard.
Public iOS and Android updates still follow the versions that are actually live in each store.
Released
H5Backend
Old support links no longer 404; sitemap reports real update dates
Two site-level fixes. First: before the game moved to app.bluffking.ai in June 2026, the website's help page linked to bluffking.ai/support, and that address has returned 404 ever since; it now permanently redirects to app.bluffking.ai/support, so old bookmarks and search results work again. Second: every page's last-modified time in sitemap.xml was the build clock, which marked all pages as freshly updated on every release; it now carries each page's real last-modified date. Poker rules, accounts, membership, and payment behavior are unchanged.
bluffking.ai/support and /support/ now issue a 301 to app.bluffking.ai/support instead of dead-ending; the website's own /zh/support/ and /en/support/ help pages are unaffected.
sitemap.xml lastmod values are derived from each page's real commit history, and are omitted rather than back-filled with build time when no date is available.
Added an automated test pinning the rule that the sitemap must never present the build clock as an update time.
Released
H5Backend
Tools pages: mobile header overlap fix
Fixes the mobile free-tools pages (Equity Calculator, Scare-Card Probability, Pot Odds) where long header titles could paint under the 中文 / EN language toggle in the top-right corner. Header titles now truncate with an ellipsis before reaching the toggle; poker rules, accounts, membership, and payment behavior are unchanged.
Mobile (390px-wide) tools headers: long titles truncate automatically, so the language toggle stays clear and tappable instead of being painted over.
Added an automated regression covering the header layout of all 8 tools pages in both languages to prevent recurrence.
Marketing product screenshots and share cards re-captured against the current UI.
Released
H5Backend
Website Chinese copy: fluency polish
This release polishes the Chinese copy across the homepage, product, and pricing pages: hard-translated phrases such as "手后可验证" become natural Chinese ("一手打完即可验证", "每手结束后公开验证材料"), and several europeanized or truncated sentences are smoothed. Every fairness and feature statement keeps its exact meaning — standard tables still default to server-visible commit-reveal dealing; poker rules, accounts, membership, and payment behavior are unchanged.
The hard-translated "手后" time phrase is replaced with natural per-hand wording across all five occurrences (hero headline and body, trust card, product, and pricing pages).
Truncated or europeanized sentences are smoothed, including the FAQ heading, a section kicker, and the Coach FAQ question.
Chinese wording only: English copy, fairness claims, and every factual number are unchanged.
Released
H5Backend
Website search discoverability: category terms and structured data
Website titles and descriptions now carry the category terms (Texas Hold'em, 德州扑克, 德扑 — the English homepage title previously said only Poker), and the site gains schema.org structured data for the first time: organization and website info, an application entry with App Store and Google Play install links plus factual fields like 2–9 seats and 7 AI styles, and blog post markup. Every description keeps the practice-chips, no-real-money boundary; gameplay, accounts, membership, and payments are unchanged.
The English homepage title now says Texas Hold'em (previously just Poker); product, pricing, blog, and about titles gain category terms
Chinese pages use 德扑 for the first time, covering 德州扑克 / 德扑 naturally across titles and descriptions
First site-wide schema.org structured data: organization and website info, an application entry (App Store / Google Play install links, 2–9 seats, 7 AI styles), and blog post markup
Released
H5Backend
Homepage: fairness-first hero messaging
This release updates the homepage hero to lead with fairness: matching the product page, it states that standard tables default to server-visible commit-reveal dealing — the deck is committed before the deal and verification material is released afterward — and tunes headline sizing and line height for the new bilingual copy. Poker rules, chip settlement, accounts, memberships, and payment behavior are unchanged.
The hero headline now leads with fairness-first positioning.
Body copy mirrors the product page: default commit-reveal dealing, committed before the deal and verifiable after the hand.
Headline font sizing and line height are tuned for the new bilingual copy.
Released
H5Backend
Table 2 live squid progress is now always visible
This release keeps squid-round status visible during live hands on Table 2 with explicit total holders, remaining count, and holder badges. The player marker now uses an 🦑 icon instead of text, and each in-hand round shows “Round N · Total X · Held Y · Left Z” so everyone can quickly verify progress. This does not change poker rules, chip settlement, fairness, accounts, or payment behavior.
Live Table 2 rounds now keep squid progress visible with round totals and holder counts.
Seat badges now use an 🦑 icon for immediate identification of holders.
Squid progress is no longer hidden during hands; status now stays in sync with current seat holders.
Released
Android
Android 1.1.4: a clearer Me screen and Tools entry
Android 1.1.4 build 338 is now live on the Google Play production track. This update removes the duplicate poker-tools shortcut from Me and keeps Tools in the bottom navigation, while retaining Stats, History, Fairness verification, and Drills with UI stability improvements. Poker rules, practice chips, accounts, memberships, and payment behavior are unchanged.
Me no longer duplicates the poker-tools shortcut; the bottom Tools tab is the single entry point.
Stats, History, Fairness verification, and Drills remain available.
Improves Android UI stability without changing gameplay or payments.
Released
H5Backend
Stricter release regression bindings
This update repairs stale bindings in release verification. The production regression for leaving a table now follows the current friend-room and public-table semantics, both expiry gates continue to share one terminal-state predicate, and QA source receipts are rebound to their reviewed current versions. This reduces the risk of stale metadata blocking a release or obscuring a real failure. Poker rules, chip settlement, table UI, accounts, and payment behavior are unchanged.
The production table-exit regression now matches current friend-room seat retention and public-table seat release semantics.
Expiry release checks continue to share one terminal interaction predicate, preventing gate drift.
QA source receipts now bind the reviewed current versions and reliably exercise failure paths inside the restricted sandbox.
Released
H5Backend
More reliable synchronized releases and source traceability
This update strengthens the synchronized release guardrails for the website, H5, and backend. Production deployment now validates host cutover prerequisites before consuming a release attempt, manual hotfixes are deduplicated from automatic CI delivery by exact commit, and release tooling follows only the matching CI and production runs. The public corresponding-source notice for the solver also verifies the published tag and its exact metadata. Poker rules, chip settlement, table UI, accounts, and payment behavior are unchanged.
Production validates host cutover prerequisites before consuming a daily release attempt.
Manual hotfixes and automatic CI delivery are deduplicated by exact commit to prevent duplicate releases.
Release tooling waits only for CI and production runs that belong to the target commit.
The public solver corresponding-source notice verifies the published tag and exact metadata.
Released
H5
Safer table exits and consistent frosted navigation
Table 2 now clearly separates ordinary back navigation from an explicit leave. Between hands, returning home from friend rooms or bot practice preserves the seat and stack; only the menu's deliberate leave action gives up the seat. Mid-hand confirmation remains in place, and public matchmaking tables continue to release seats under their existing policy. When a session has ended, hardware back or an edge swipe exits the expired table instead of hiding the terminal notice and stranding the player on an unusable felt. The marketing site's navigation and glass panels also retain their frosted effect consistently in production builds across Chrome, Firefox, and Safari. Poker rules, pot settlement, accounts, and payment behavior are unchanged.
Returning home between hands preserves the seat and stack in friend rooms and bot practice, while explicit leave still releases the seat.
Mid-hand back navigation still requires confirmation, and public-table seat-release policy is unchanged.
Hardware back and edge swipes now exit an ended session instead of revealing an unusable expired table.
Frosted navigation and glass panels remain consistent in production CSS across Chrome, Firefox, and Safari.
Released
Backend
Clearer daily service signals and anomaly alerts
The daily operations report now distinguishes active usage across H5, embedded Flutter, Telegram, and browser surfaces, with coarse iOS, Android, and other-system totals. Zero-only metrics no longer crowd the report, while missing registrations, sessions that never start, and established users with no daily activity are called out explicitly. Retention now keeps both cohort size and retained-user count, so very low but non-zero results are not displayed as zero. This improves privacy-safe aggregate monitoring and incident detection only; poker rules, chips, accounts, and payment behavior are unchanged.
Breaks down real active users by client surface and coarse operating system, with cross-surface duplication stated explicitly.
Suppresses all-zero sections while highlighting missing registration, seating, gameplay-start, and real-activity signals.
Pairs retention cohorts with retained-user counts, distinguishing true zero from a non-zero result below 0.1%.
Keeps the report aggregate-only, without adding IP, country, or user-identity collection.
Released
H5Backend
Friend spectating, the new default table, steadier bot decisions, and release guardrails
Authenticated users with a friend-room code can now join as seatless spectators: they take no seat, hold no chips, cannot act on the game, never receive any player's unrevealed hole cards, and never receive the post-hand fairness seed reveal. Hosts can disable spectating, while two-sided blocks, public tables, and advanced encrypted-dealing tables all deny it. The default table entry for H5 and mobile WebViews now converges on Table 2, with the classic table retained as a fallback; top-bar actions, report and block controls, fairness access, winner presentation, voluntary card reveals, time bank, squid prompts, and nine-seat layout parity are included, with the top bar and nine-seat name readability also polished. Practice bots also handle locked shared-board outcomes, forced chops, and higher two-pair upgrades more reliably while preserving their distinct styles. The marketing site adds first-party anonymous page-view metrics (no third-party analytics, no tracking cookies, no IP stored), disclosed in Privacy Policy v2.8 and Cookie Policy v1.5. On delivery, the website, H5, and backend now share one traceable guardrail for each synchronized Production release: at most three release attempts per Singapore calendar day, with duplicate or indeterminate cutovers never retried automatically; pre-release checks are focused on inputs that actually affect live delivery, avoiding duplicate builds; and the five-minute database watchdog and alerting move to a VPS-native timer, with GitHub retaining a daily independent liveness sample. This release also removes orphaned code and obsolete build inputs that no longer participate in the product; poker rules, chip settlement, and account data are unchanged.
Friend rooms now support read-only spectating: unrevealed hole cards and the post-hand fairness seed stay hidden from spectators, and the rail roster remains visible to the table.
Hosts can disable spectating; two-sided blocks, public tables, and advanced encrypted-dealing tables cannot be railed.
The default table route now uses Table 2, with the classic table retained as a fallback.
Table 2 closes parity gaps in table actions, report and block controls, fairness, winners and voluntary reveals, time bank, squid prompts, and nine-seat layout, with the top bar and seat-name readability also polished.
Bots make more reliable decisions on locked shared-board outcomes, forced chops, and higher two-pair upgrades.
The marketing site adds first-party anonymous page-view metrics, disclosed in Privacy Policy v2.8 and Cookie Policy v1.5.
The site also publishes the bilingual engineering article “Prose doesn't execute,” tracing how written rules become executable guardrails.
The website, H5, and backend are counted as one synchronized release rather than separate releases.
Duplicate triggers, cancellations, and indeterminate cutovers are handled conservatively to prevent accidental repeat releases.
Release checks avoid duplicate builds, while a proven VPS-native five-minute database watchdog keeps a daily independent GitHub liveness sample.
Removes orphaned source and stale build cache inputs that are no longer compiled or loaded; poker rules, chip settlement, and account data are unchanged.
Released
Android
Android 1.1.3: memberships and the latest table features
Android 1.1.3 is now live on Google Play with Pro/Max memberships, the latest table features, reliability improvements, and expanded availability across markets that permit simulated-poker apps. Google policy restricts Algeria, Iran, Libya, Qatar, Syria, and Yemen; South Korea remains unavailable pending GRAC classification.
Adds native Google Play Pro and Max monthly and yearly memberships.
Brings practice-vs-bots, friend-room, and table-rule capabilities up to date.
Improves mobile reliability and platform compatibility.
Released
H5Backend
Safer TestFlight Sandbox acceptance, test-payment retries, and registration metrics
Native Apple purchase verification can now process TestFlight Sandbox transactions on the production backend only for exact allowlisted accounts that are also marked as internal tests. Every payment, subscription, and entitlement fact keeps its Sandbox tag and stays out of revenue and paid metrics. An authorized refunded-balance run on Telegram Test Server may now replace only an expired invoice with no payment fact, while the whole authorization remains capped at one successful test payment. First-time Google, Apple, and Telegram account creation now also enters the trusted server-side registration funnel, while routine sign-ins, auto-linking, and lost concurrency races do not double-count. Ordinary accounts, Production-store transactions, and real revenue reporting are unchanged.
TestFlight Sandbox purchases are limited to exact authorized internal QA accounts and isolated from Production revenue and paid metrics.
Telegram Test Server may safely retry only expired invoices with no payment fact and remains capped at one successful test payment.
First-time Google, Apple, and Telegram account creation now enters the trusted server-side registration funnel.
Re-logins, account auto-linking, and concurrency races do not create duplicate registration counts.
Released
H5Backend
A cleaner homepage, sharper bot practice, and an Android catalog update
The homepage no longer repeats the operating-company card, keeping the page focused on poker practice, review, and strategy training; BLUFF KING PTE. LTD.'s legal name, UEN, Singapore registration, and DPO contact remain fully available in the footer, About, Contact, and legal pages. Bot practice also gets better preflop re-raise ranges: TAG, LAG, and Maniac now have more distinct 3-bet/4-bet styles, while a zero-stack bot is replenished in the same seat at the table's starting stack so the practice roster stays intact. The in-app mobile version catalog now also recognizes public Android 1.1.3 build 312 on Google Play, giving older clients accurate update prompts and the official store destination. Practice chips, the no-real-money boundary, game rules, accounts, membership, payments, and user data are unchanged.
Removed the repeated operating-company card so the homepage stays focused on product value.
The legal name, UEN, and jurisdiction remain in the footer, company page, contact page, and legal documents.
The public DPO contact in Privacy remains unchanged.
TAG, LAG, and Maniac preflop re-raise ranges are now calibrated over real starting-hand combinations for clearer differentiation.
A busted bot is replenished in the same practice seat so the configured roster does not gradually shrink.
The mobile version catalog now recognizes Android 1.1.3 build 312 while keeping iOS and Android metadata and store links independent.
The practice-chip and no-real-money boundary remains clear on the homepage and footer.
Released
H5Backend
Live straddle and finite squid are now available in practice-vs-bots
Until now these two table rules could only be enabled in friend rooms. For table-rule purposes a bot occupying a seat is a player too: straddle is a purely seat-position forced bet, so a bot in that seat posts it exactly like it already posts a small or big blind, and the finite-squid roster no longer recognises humans only — a bot seat becomes a participant as soon as it is dealt in (it is never sent a join prompt, since consent means nothing for a bot). The same change lets a friend room that fills empty seats with bots enable squid. Squid penalties remain a separate table-side ledger that never rewrites poker pots or hand history; practice chips only.
The practice-vs-bots setup now offers the straddle and finite-squid toggles (3+ seats required).
A bot seat joins the current squid round automatically as soon as it is dealt in — it is never sent a join prompt.
A friend room that fills empty seats with bots can now enable squid as well.
Squid penalties never rewrite poker pots or hand history; practice chips only.
Released
H5Backend
Advanced encrypted dealing (highest-encryption mode) now available on all-human, no-AI tables
All-human, no-AI rooms can now have the host enable Advanced encrypted dealing: on a hand where the mode is on, the server does not hold your unshown hole-card plaintext. Required disclosure: this secrecy holds only for that hand; if any player drops, the whole table visibly downgrades to standard (server-visible) dealing; practice chips only. Default tables stay server-visible verifiable dealing, unchanged; settlement logic is unchanged.
Advanced encrypted dealing is now available — the host enables it in all-human, no-AI rooms.
On that hand, the server does not hold your unshown hole-card plaintext.
If any player drops, the whole table visibly downgrades to standard (server-visible) dealing.
Practice chips only; default tables and settlement logic are unchanged.
Released
H5Backend
Engineering post reworked: what a subscription AI really costs on the meter, itemized per model
The Build Notes post on subscription-AI billing was rewritten to lead with its real point: for one flat monthly subscription, what the same usage would cost at the metered API list price — one 30-day window paid $400 and lists at $53,403 (~133×). It adds a per-model usage table (each model's input, cache read/write, and output tokens with list-price subtotals) and explains why a fully-autonomous AI team runs on the flat fee, not the metered API. Content-only release — game rules, room links, accounts, and user data are unchanged.
The post now centers on the real metered cost behind the subscription: $400 paid vs $53,403 at list price (~133×).
Adds a per-model breakdown: each model's input, cache read/write, and output token counts with list-price subtotals and totals.
Adds a worked derivation (tokens × unit price = amount) so every dollar figure is traceable, not conjured.
States the takeaway: a fully-autonomous AI team on the metered API can cost more than a human — the flat subscription is what makes it viable.
Content-only release — no change to gameplay, backend, or user data.
Released
H5Backend
New engineering post: itemize the AI subscription that has no bill
A new bilingual engineering post is live in the site's Build Notes: how to reconstruct a per-model, per-token bill for a subscription AI from the local Claude Code / Codex CLI logs, and the three streaming/aggregation traps that decide whether the total is right. This is a content-only release — it updates the marketing site article and this public changelog; game rules, room links, accounts, and user data are unchanged.
New post “Itemize the AI subscription that has no bill” is live in both languages.
Shows where subscription-AI usage lives in the local CLI logs, and which fields to read.
Breaks down three aggregation traps: streaming dedupe, forked-session double-count, cached-input-is-a-subset.
Content-only release — no change to gameplay, backend, or user data.
Released
H5Backend
Land back in the table you opened after sign-up; safer, more reliable block & report
After you open a table as a guest and then register, we now take you straight back into that table instead of the lobby. Block and report are also more reliable: a report always targets the player you selected (even if seats shuffle while you hold), the report description limit is measured in real bytes (so longer non-English text is no longer misjudged), the report control is keyboard- and screen-reader-accessible, and a blocked player stays hidden on both table layouts even after they change seats or rename. Game rules, room links, and user data are unchanged.
Tap a table as a guest, then after sign-up you land in that table instead of the lobby.
A report always targets the selected player, even if seats change during the press.
The report description limit now counts UTF-8 bytes, so longer non-English text is no longer wrongly rejected or accepted.
The report control is keyboard/screen-reader accessible; blocked players stay hidden across both table layouts even after they reseat or rename.
Released
H5Backend
Telegram release checks aligned with the latest authentication policy
Release verification in the real Telegram App container now uses an isolated test-domain account and a test credential that meets the current strength policy, preventing stale fixtures from being mistaken for product failures. User login rules, game rules, room links, and user data are unchanged.
The Telegram device-verification account now stays inside the test domain and metrics exclusions.
The QA credential follows the current password-strength policy without weakening server-side gates.
QA credentials no longer enter launch URLs or run logs.
Released
H5Backend
More reliable release verification and device screenshots
The release flow now confirms its isolated QA environment before device screenshots and multiplayer verification, so an environment reset cannot be mistaken for a product failure. Game rules, user accounts, room links, and user data are unchanged.
After an environment reset, fixed QA fixtures are restored only when needed and re-verified before device checks begin.
Authentication, network, or unexpected-state errors still fail closed and never bypass the release gate.
The closed-table screenshot oracle now matches the centered new-table layout used in the real product.
Released
H5Backend
Clearer blog navigation and new-table maintenance
The website's article section is accurately labeled “Blog” again, with a new bilingual engineering article about brand-language migrations. The H5 new table also completes a behavior-preserving internal naming cleanup; game rules, room links, and user data are unchanged.
Navigation, page titles, and return links consistently use “Blog,” leaving a clear boundary for a future standalone Insights feature.
Published “Borrow the layout, not the vocabulary,” a reusable guide to naming migrations and information architecture.
Added automated brand-language checks to keep retired codenames out of future releases.
Released
H5Backend
Consistent new-table naming and a clearer company website
The new table now uses consistent BluffKing-owned naming across the product, code, and public materials. The website is also rebuilt as a clearer company and product destination, with less repetition and a sharper focus on practice, review, strategy training, fairness, and product boundaries.
Unified all new-table naming under BluffKing-owned terminology.
Rewrote Home, Product, Company, Support, and Contact to remove manual-like and repetitive copy.
Refocused navigation on the product, pricing, insights, and company information.
Released
H5Backend
Squid upgrade: doubling, full mode, and fairer mid-round joins
Private friend rooms now offer classic, doubling, and full squid modes. A player sitting down mid-round can join immediately or wait for the next round without resetting anyone else's marks or multiplier; short-handed rounds pause instead of clearing. The new table also improves seat badges, action labels, rule access, and room-information layout.
New doubling squid (penalty doubles per round, capped at 4×) and full squid (stacked marks, weighted settlement); classic stays the unchanged default.
Fairer mid-round joins: newcomers choose "join now" or "wait"; existing marks and multipliers are never reset, and a reused seat never inherits the prior occupant's status.
Both tables show mode, multiplier, stacked marks, and pending-join status; the mobile web table gains squid indicators.
The new table improves seat badges, action labels, rule access, and room-information layout.
Released
H5Backend
Checkout prefills your account email + custom-blind setup fixes
Signed-in users no longer re-type their email at subscription checkout: the backend now forwards the account email to Stripe's checkout page to prefill it. To avoid ever locking a wrong address onto a receipt, prefill applies only to verified-owned emails (for example Google/Apple sign-in or a verified email); username or not-yet-verified accounts still fill it in at checkout. This release also fixes custom blinds in room setup: editing the small blind proposes the conventional 2× big blind (50 → 100) while the big blind stays editable for non-2× structures like 2/5, and forced-straddle and squid-penalty amounts now show the real chip value based on your blinds instead of a fixed “2 BB” label.
Subscription checkout: accounts with a verified email get it prefilled on the Stripe page — no re-typing.
Custom blinds: editing the small blind auto-proposes a 2× big blind, which stays editable for non-2× structures like 2/5.
Forced-straddle and squid-penalty amounts display real chip values based on your blinds, not a fixed label.
Released
H5Backend
Payment order and refund reliability fix
This hotfix restructures the subscription payment model: an order is now recorded separately from each individual payment attempt, consistently across Stripe, Telegram Stars, and on-chain BNB USDT. Retrying after a failed payment creates its own attempt record, refunds are tied to the exact payment they reverse, and duplicate refund requests execute only once. The matching backend data migration is fail-closed, and the H5 payment pages are updated to match, including an adjusted list of available payment methods.
Orders are separated from payment attempts: every retry gets its own record, and payment-status polling and on-chain transaction submission reference the payment attempt.
Refunds map to one specific payment attempt, and duplicate refund requests are safely de-duplicated so nothing is refunded twice.
H5 payment methods adjusted: Alipay and WeChat Pay are no longer offered for new payments, and Apple Pay / Google Pay are marked as native-app-only.
This hotfix expands the daily operations report with two session metrics alongside the existing created, started, closed, and completed-hand totals: sessions that both started and closed, and sessions that reached their configured duration. Reporting continues to use a fixed UTC+08:00 calendar-day window and sends aggregate, de-identified data only. H5 and the marketing site are synchronized to the same release; poker rules and the player interface are unchanged.
“Started and closed” counts the intersection of sessions created that day, with at least one completed hand, and closed before day end.
“Reached configured duration” counts only started sessions whose end time is at or after the room's scheduled deadline.
The report contains no user identity or per-session details; this release does not change poker rules or the player interface.
Released
H5Backend
Private-table rule and blind-marker visibility fix
This hotfix keeps essential private-table rules clearly visible during play. The H5 table now shows dealer, small-blind, big-blind, and straddle positions while retaining the room's configured straddle and Squid penalty. The backend also resends authoritative room rules on join and reconnect so rule information is not lost after a refresh or network recovery.
Seat badges now identify D, SB, BB, and STR positions, including overlapping dealer and small-blind roles in heads-up play.
Configured straddle and Squid penalties remain visible on the table, with waiting and active states distinguished.
The backend resends authoritative room rules when players join, refresh, or reconnect, keeping the H5 display consistent.
Released
H5Backend
Trusted release-gate and backend build-compatibility hardening
This production batch hardens the trusted Codex QA and release gates: the deterministic sandbox binds toolchain and dependency identities more strictly and holds Flutter's real cache lock while reading its toolchain, preventing concurrent SDK updates from changing the object under verification. Local-environment, device-proof, and regression scripts also strengthen path, process, and cleanup boundaries. Backend source and tests are updated for all-target Clippy compatibility. These changes do not alter poker rules, accounts, pricing, or other runtime product behavior.
The trusted launcher brings Flutter, Dart, dependency, and tool-wrapper identities into closed verification and removes concurrent-upgrade races with Flutter's real cache lock.
Local startup, device-proof, tunnel, and regression scripts add stricter path, process-ownership, environment-isolation, and failure-cleanup checks.
Backend daily-report queries and test helpers now pass all-target Clippy checks; the adjustments affect build and test compatibility only, not runtime semantics.
Released
H5Backend
Route-update recovery, operational reporting, and an AI coding guide
This production batch ships previously merged but not-yet-deployed commit 7cc95b56 together with the new site article. That commit adds one loop-guarded document recovery when a deployment invalidates a lazy route module, prevents native-bridge failures from creating unhandled Promise rejections, distinguishes web, Telegram, and Flutter client errors, and moves the daily operations report to a fixed calendar-day window with hand-completion and redacted error breakdowns. The website patch in this batch also publishes a bilingual beginner guide from conversational GPT use to production Claude Code and Codex workflows.
Commit 7cc95b56: a stale page reloads at most once when its route module is gone; a persistent failure cannot enter a refresh loop.
Commit 7cc95b56: operations reports use a complete calendar-day snapshot with hand, client-surface, and fixed error-category breakdowns.
Website patch: a new bilingual AI coding guide covers CLI, Remote Control, Memory, MCP, Skills, Plugins, Harnesses, Workflows, and Hooks.
Released
H5
Collision-free V1 table layouts for 2–9 players
V1 now uses explicit per-player-count layouts with separate compact- and normal-height geometry. Opponent seats, bet chips, community cards, pot, room stamp, hero hand, and controls each stay in independent safe regions. The fix covers 2–9 players across mobile browser, standalone, tablet, and short desktop viewports.
The shared ellipse that squeezed horizontal capsules is replaced by symmetric per-count layouts for 2–9 players.
Compact and tall canvases use independent seat and bet lanes, keeping the board, pot, and hero controls unobstructed.
A real-Chromium 40-scenario painted-collision gate now covers every player count across five viewport classes.
Released
H5
Clearer Max monthly and yearly price comparison
The Max pricing card now follows the same comparison order as Pro: monthly first, then yearly. The limited yearly offer remains highlighted and explicitly shows “Best value” plus US$358.30 saved versus paying monthly for a year. Prices and membership benefits are unchanged.
Max now presents monthly before yearly, making the yearly offer easier to compare directly.
Yearly remains US$0.50 (regular US$299) and now shows the US$358.30 savings versus twelve monthly payments.
Released
Backend
Database monitoring, indexes, and payment uniqueness hardening
The backend adds parameter-redacted slow-query observation, sustained-signal alert thresholds, and a five-minute database health check. The database now enforces at most one current subscription projection and one user-initiated in-flight payment order per user, with order/user/provider identity checks. Each paid order retains its own entitlement fact and the read side selects the highest live tier, so out-of-order Pro settlement cannot downgrade Max. A new checkout releases an overdue unpaid pending slot, while possibly captured submitted evidence remains provider-reconciled; already-captured Apple/Google receipts bypass the checkout gate. Critical foreign-key indexes are added and two redundant indexes are removed to reduce write amplification.
SQL over 500ms feeds five-minute trend counts; sustained slow queries, one five-second query, long transactions, repeated deadlocks, connection pressure, or repeated pool waits trigger alerts.
Slow-query logging explicitly disables bind-parameter capture so emails, sessions, and payment payloads stay out of operational logs.
The database rejects concurrent checkouts and a second current subscription projection; entitlements remain per paid order with the highest live tier effective, and overdue unpaid intents release their slot.
Indexes now cover subscriptions.latest_order_id and oauth_nonces.user_id; two redundant hand_actions and coach_hints indexes are removed.
Released
H5Backend
Table and startup upgrades, localized emails, alerting ready, and restored Max pricing
This release ships H5, backend, and the marketing site together: the current actor gets a reconnect grace window, multiway all-ins show live main and side pots, folding when a check is free requires confirmation, and folded players may voluntarily reveal after the hand. Telegram cold-start navigation now recovers automatically; verification-code, password-reset, and email-change messages follow the user's active language; and the backend gains configurable anomaly aggregation and alerting while container logs have rotation limits. H5 and server passwords share an 8–128-character rule, and one-time local payment methods explicitly describe the fixed-term training membership being purchased. Max monthly returns to US$29.90 (3000 XTR/month), while Max yearly keeps the US$0.50 beta promo with a struck-through US$299 regular price.
The current actor is no longer auto-folded immediately after disconnecting; a grace window and stale-action isolation prevent accidental actions after timeout.
Multiway all-ins now show the main pot and every side pot live, with Total reconciled to the breakdown.
Folding when a check is free now asks for confirmation, and folded players can choose to reveal their cards after the hand ends.
Hand-history and standings drawers use a denser layout so nine-player showdown information fits better on phones.
Telegram Mini App cold starts size to the visible viewport immediately and resume bottom-navigation synchronization when a delayed WebApp bridge arrives.
Verification-code, password-reset, and email-change messages use the active product language, safely falling back to English instead of mixing languages.
The server gains configurable anomaly aggregation, de-duplication, and Telegram alerting; container log caps activate with this release to prevent logs from filling the disk.
H5 and server signup, credential setup, and password reset now share an 8–128-character rule while still rejecting common and predictable passwords.
One-time Alipay, WeChat Pay, and PayNow checkout now labels the fixed-term training-membership fee and explicitly excludes wagering, chips, deposits, and cash prizes.
Max monthly returns to the standard US$29.90 / 3000 XTR; Max yearly remains a US$0.50 limited beta offer with the US$299 regular price struck through.
Production releases are now built only from main and require one new bilingual changelog entry before prod switches; H5, backend, and the site share one SHA and release id.
Released
H5Backend
Open-source solver mirror re-synced to the deployed build
This release re-publishes the public AGPL §13 Corresponding Source (the engine and postflop-solver subset) so it byte-matches the deployed build (tag solver-src-2026-07-18). It is a routine dependency-lock refresh only — solver results and gameplay are unchanged.
The public mirror tag solver-src-2026-07-18 is byte-identical to the deployed build, keeping the AGPL §13 source offer valid.
Only the dependency lock (Cargo.lock) was refreshed; the postflop-solver source and algorithm are unchanged.
Released
H5Backend
Email signup now uses six-digit, proof-first verification
H5 signup now proves mailbox ownership with a six-digit code before showing password and consent. Existing accounts are routed to sign-in or recovery. The server remains compatible with legacy eight-digit clients while strengthening new-password and email-account lookup rules.
New H5 signup codes are exactly six digits and preserve leading zeroes; legacy clients can still finish their eight-digit flow during the compatibility window.
After verification, new mailboxes continue to account creation while existing mailboxes move to sign-in or recovery instead of a late registration conflict.
New and reset passwords require at least 15 characters and reject common weak choices; existing short passwords can still sign in.
Sign-in and password recovery prefer canonical email lookup while retaining an exact-email compatibility path for legacy accounts.
Released
Backend
Telegram Stars test balances now require provenance attestation
Real-provider verification on Telegram's Test Server now requires the controlled test flow to attest both an existing Stars balance and its non-store test provenance before creating an order, preventing store-funded, refunded, or disputed balances from being treated as safe test funds. Production Telegram Stars checkout is unchanged.
Missing, mismatched, or store-origin provenance is rejected before any order write or Telegram provider call.
Each restricted run remains limited to one 1-XTR invoice, with the one-run budget still preventing retries from expanding risk.
The test wrapper, operational status, and bilingual incident review now agree: stop real-provider testing when no trusted non-store test balance is available.
Released
H5Backend
Table hands upgraded to a readable side drawer
Table history now opens as a full-height right drawer with larger board and hole cards, while rabbit hunt is strictly scoped to the selected hand. This release also fixes bet, pot, and hero-zone collisions on compact iPhone viewports.
History focuses one hand at a time with large board and hole cards, a visible slice of the table, and bottom hand-by-hand paging.
Rabbit hunt now lives inside the selected history hand; its runout never enters the live board or another history hand.
History enforces strict visibility: the viewer always sees their own cards; opponents are face-up only when explicitly authorized by the server, while folds, mucks, and unpersisted voluntary reveals stay face-down.
Dedicated safe lanes separate top bets, pot, blind markers, hero cards, and the bottom rail in iPhone 14 browser viewports.
Released
H5
Every sub-screen now has a way back
A full audit of back navigation across every H5 screen: the Solver page had no back button at all, and the Drills and History pages only showed one when entered from specific paths. In shells without browser chrome (installed PWA or Telegram Mini App), players could get stuck on those screens. All three now always show a back button.
The Solver page gained a back button: it returns along the in-app history when present (for example from Review), and falls back to the Tools hub otherwise.
The Drills and History back buttons no longer depend on an entry parameter — arriving from a notification, from Review, or via a direct link still offers a way back.
Back handling is safe for cold deep links: with no in-app history it falls back to the parent screen instead of a dead browser back.
Released
H5Backend
Stripe checkout fixed with availability-aware payment options
This release fixes the API-version mismatch that blocked Stripe Elements sessions for Apple Pay and Google Pay, and only exposes payment methods that Stripe has enabled and the release preflight has verified.
Apple Pay and Google Pay Elements sessions now use the API version matched to the frontend Stripe.js release.
Methods not enabled on the live Stripe account, such as Alipay, WeChat Pay, or Google Pay, are hidden and cannot be forced through the server endpoint.
The release preflight now verifies Stripe's live payment-method configuration and wallet domain, then creates and expires no-charge sessions; rejected requests mark the local order rejected and retain only safe diagnostic fields.
Released
Backend
Mobile update checks now report the correct store versions
In-app update checks now return the currently published App Store and Google Play versions independently instead of reusing a stale shared version record.
iOS and Android now compare against the build currently published in their own store.
Local installs and candidate builds no longer overwrite the published catalog before a store release is available.
Released
H5Backend
In-app subscription verification goes live, plus Telegram subscription fixes
This release activates server-side verification and real-time developer notifications for Google Play in-app subscriptions in production, and fixes Telegram Stars subscriptions that could not be cancelled or refunded after lapsing.
Google Play subscription purchases are now server-verified and grant membership automatically, with real-time developer notifications (RTDN) active.
Telegram Stars subscriptions can now be cancel-marked and refunded correctly even after they lapse; other provider rejections still fail closed.
A test-environment-only subscription-period override enables repeatable regression checks; production stays locked to 30-day periods and rejects misconfiguration at startup.
Released
H5Backend
Email-code protection for account signup and upgrades
H5 now sends an eight-digit email code for new-account signup, guest upgrade, and Telegram account email/password setup, confirming inbox access before the account write completes.
Signup now includes send-code and enter-code steps, and submits the new account only after verification.
Guest upgrades and Telegram account email/password setup use the same inbox-ownership check while preserving existing hands and account data.
Codes expire after ten minutes and allow up to five attempts; delivery failures prompt a retry instead of being treated as a successful send.
Released
H5Backend
Legacy APK hosting fully retired
Google Play remains the website's only Android install path. Legacy APK files, static hosting, server mounts, and deployment or rollback preservation logic have all been removed.
Historical APK download bookmarks retain only a permanent redirect to Google Play and no longer map to any APK file or hosted directory.
Production releases no longer mount, copy, or exempt any APK directory from deletion.
Released
H5Backend
Android website entry moves exclusively to Google Play
The website no longer offers direct APK downloads. Every Android entry and historical download link now opens the official Google Play listing for the current public release and future updates.
Every Android entry on the website now uses BluffKing's official Google Play listing.
Legacy APK download URLs permanently redirect to Google Play instead of serving an outdated installer.
Released
H5Backend
Friend-beta pricing: Max drops to each channel's minimum charge
During the friend-beta period, Max membership drops to each payment channel's minimum chargeable amount: US$0.50 per month and US$0.50 per year on Stripe, and 1 XTR per month on Telegram Stars. Pro membership pricing is unchanged.
Max monthly on Stripe drops from US$29.90 to US$0.50, Stripe's minimum chargeable USD amount.
Max yearly on Stripe drops from US$299 to US$0.50, and Telegram Stars monthly drops from 3000 XTR to 1 XTR, the Telegram minimum.
Pro membership and its Telegram Stars pricing stay unchanged.
Released
H5Backend
Bet-slider fix and hardened release rails
This release fixes a new-table bet slider issue where releasing a drag could commit the action twice and improves VPIP/PFR stat accuracy.
The new-table bet slider now commits exactly one action per drag.
Added VPIP/PFR regression cases for forced-blind folds, call-shaped all-ins, and wager-increasing short all-ins so stat classification keeps poker semantics.
Continued hardening the release and independent-review rails, including a credential-lookup fix for unattended reviews, so every merge keeps passing independent scrutiny.
Released
H5Backend
Public release notes, payment safeguards, and a steadier table
This release launches public release notes, continues improving table and membership experiences, keeps the not-yet-enabled BNB rail hidden and disabled server-side, restores compatibility with the existing migration 0060 checksum, and strengthens App Store notification verification.
Added bilingual public release notes for future H5, backend, and mobile releases.
Refined table countdowns, status information, and small-screen layout while aligning membership descriptions across H5 and mobile.
Strengthened regression protection for blinds, action order, and session continuation.
The BNB Chain USDT option now follows its server-side switch; it stays hidden while disabled and cannot be bypassed through order or administrative endpoints.
Restored the checksum of production-applied migration 0060 and moved the refund-constraint change to new migration 0063 so this upgrade can start safely.
Added support for official App Store test notifications so the notification path can be verified before purchases open.
Released
Android
Android 1.1.2: Tools tab and richer standings
Android 1.1.2 adds the Tools tab and a session leaderboard summary, shows VPIP and win rate in standings, introduces the free time bank for extending action time, and improves overall stability.
New Tools tab with quick access to poker calculators.
Session leaderboard summary, plus VPIP and win rate in standings.
Free time bank for extending action time.
Smoother table experience on small screens, stability improvements and bug fixes.
Released
H5Backend
Table controls, session continuity, and fairness updates
This release focuses on clearer live-table play, smoother recovery after interruptions, and fairness information players can verify directly.
Refined mobile table layout, betting controls, and dealer / blind markers so key information stays visible.
Improved table identification and recovery when returning to the lobby, reconnecting, or resuming a session.
Expanded verifiable-deal seed evidence and made showdown results easier to read.
Adjusted AI opponent names, styles, and action timing for more natural, readable practice tables.
Released
iOSAndroid
iOS 1.1.1 and Android 1.1.0
The first public mobile releases bring practice tables, friend rooms, review, replay, and focused drills to the native apps with phone-specific display refinements.
iOS: corrected blind display, added the new Tools entry, and improved overall stability.
Android: improved edge-to-edge display, bottom navigation, and table information accuracy.
Both apps include practice-chip tables, AI opponents, friend rooms, hand review, and training drills.