309 earlier updates, newest first. Showing 281–300 on page 15 of 16.
Released
H5Backend
Consistent new-table naming and a clearer company website
The new table now uses consistent BluffKing-owned naming across the product, code, and public materials. The website is also rebuilt as a clearer company and product destination, with less repetition and a sharper focus on practice, review, strategy training, fairness, and product boundaries.
Unified all new-table naming under BluffKing-owned terminology.
Rewrote Home, Product, Company, Support, and Contact to remove manual-like and repetitive copy.
Refocused navigation on the product, pricing, insights, and company information.
Released
H5Backend
Squid upgrade: doubling, full mode, and fairer mid-round joins
Private friend rooms now offer classic, doubling, and full squid modes. A player sitting down mid-round can join immediately or wait for the next round without resetting anyone else's marks or multiplier; short-handed rounds pause instead of clearing. The new table also improves seat badges, action labels, rule access, and room-information layout.
New doubling squid (penalty doubles per round, capped at 4×) and full squid (stacked marks, weighted settlement); classic stays the unchanged default.
Fairer mid-round joins: newcomers choose "join now" or "wait"; existing marks and multipliers are never reset, and a reused seat never inherits the prior occupant's status.
The mobile web table gained squid mode, multiplier, stacked-mark, and pending-join indicators; both surfaces showed them at this release, and the temporary surface was removed in the later Table2-only release.
The new table improves seat badges, action labels, rule access, and room-information layout.
Released
H5Backend
Checkout prefills your account email + custom-blind setup fixes
Signed-in users no longer re-type their email at subscription checkout: the backend now forwards the account email to Stripe's checkout page to prefill it. To avoid ever locking a wrong address onto a receipt, prefill applies only to verified-owned emails (for example Google/Apple sign-in or a verified email); username or not-yet-verified accounts still fill it in at checkout. This release also fixes custom blinds in room setup: editing the small blind proposes the conventional 2× big blind (50 → 100) while the big blind stays editable for non-2× structures like 2/5, and forced-straddle and squid-penalty amounts now show the real chip value based on your blinds instead of a fixed “2 BB” label.
Subscription checkout: accounts with a verified email get it prefilled on the Stripe page — no re-typing.
Custom blinds: editing the small blind auto-proposes a 2× big blind, which stays editable for non-2× structures like 2/5.
Forced-straddle and squid-penalty amounts display real chip values based on your blinds, not a fixed label.
Released
H5Backend
Payment order and refund reliability fix
This hotfix restructures the subscription payment model: an order is now recorded separately from each individual payment attempt, consistently across Stripe, Telegram Stars, and on-chain BNB USDT. Retrying after a failed payment creates its own attempt record, refunds are tied to the exact payment they reverse, and duplicate refund requests execute only once. The matching backend data migration is fail-closed, and the H5 payment pages are updated to match, including an adjusted list of available payment methods.
Orders are separated from payment attempts: every retry gets its own record, and payment-status polling and on-chain transaction submission reference the payment attempt.
Refunds map to one specific payment attempt, and duplicate refund requests are safely de-duplicated so nothing is refunded twice.
H5 payment methods adjusted: Alipay and WeChat Pay are no longer offered for new payments, and Apple Pay / Google Pay are marked as native-app-only.
This hotfix expands the daily operations report with two session metrics alongside the existing created, started, closed, and completed-hand totals: sessions that both started and closed, and sessions that reached their configured duration. Reporting continues to use a fixed UTC+08:00 calendar-day window and sends aggregate, de-identified data only. H5 and the marketing site are synchronized to the same release; poker rules and the player interface are unchanged.
“Started and closed” counts the intersection of sessions created that day, with at least one completed hand, and closed before day end.
“Reached configured duration” counts only started sessions whose end time is at or after the room's scheduled deadline.
The report contains no user identity or per-session details; this release does not change poker rules or the player interface.
Released
H5Backend
Private-table rule and blind-marker visibility fix
This hotfix keeps essential private-table rules clearly visible during play. The H5 table now shows dealer, small-blind, big-blind, and straddle positions while retaining the room's configured straddle and Squid penalty. The backend also resends authoritative room rules on join and reconnect so rule information is not lost after a refresh or network recovery.
Seat badges now identify D, SB, BB, and STR positions, including overlapping dealer and small-blind roles in heads-up play.
Configured straddle and Squid penalties remain visible on the table, with waiting and active states distinguished.
The backend resends authoritative room rules when players join, refresh, or reconnect, keeping the H5 display consistent.
Released
H5Backend
Trusted release-gate and backend build-compatibility hardening
This production batch hardens the trusted Codex QA and release gates: the deterministic sandbox binds toolchain and dependency identities more strictly and holds Flutter's real cache lock while reading its toolchain, preventing concurrent SDK updates from changing the object under verification. Local-environment, device-proof, and regression scripts also strengthen path, process, and cleanup boundaries. Backend source and tests are updated for all-target Clippy compatibility. These changes do not alter poker rules, accounts, pricing, or other runtime product behavior.
The trusted launcher brings Flutter, Dart, dependency, and tool-wrapper identities into closed verification and removes concurrent-upgrade races with Flutter's real cache lock.
Local startup, device-proof, tunnel, and regression scripts add stricter path, process-ownership, environment-isolation, and failure-cleanup checks.
Backend daily-report queries and test helpers now pass all-target Clippy checks; the adjustments affect build and test compatibility only, not runtime semantics.
Released
H5Backend
Route-update recovery, operational reporting, and an AI coding guide
This production batch ships previously merged but not-yet-deployed commit 7cc95b56 together with the new site article. That commit adds one loop-guarded document recovery when a deployment invalidates a lazy route module, prevents native-bridge failures from creating unhandled Promise rejections, distinguishes web, Telegram, and Flutter client errors, and moves the daily operations report to a fixed calendar-day window with hand-completion and redacted error breakdowns. The website patch in this batch also publishes a bilingual beginner guide from conversational GPT use to production Claude Code and Codex workflows.
Commit 7cc95b56: a stale page reloads at most once when its route module is gone; a persistent failure cannot enter a refresh loop.
Commit 7cc95b56: operations reports use a complete calendar-day snapshot with hand, client-surface, and fixed error-category breakdowns.
Website patch: a new bilingual AI coding guide covers CLI, Remote Control, Memory, MCP, Skills, Plugins, Harnesses, Workflows, and Hooks.
Released
H5
Collision-free V1 table layouts for 2–9 players
V1 now uses explicit per-player-count layouts with separate compact- and normal-height geometry. Opponent seats, bet chips, community cards, pot, room stamp, hero hand, and controls each stay in independent safe regions. The fix covers 2–9 players across mobile browser, standalone, tablet, and short desktop viewports.
The shared ellipse that squeezed horizontal capsules is replaced by symmetric per-count layouts for 2–9 players.
Compact and tall canvases use independent seat and bet lanes, keeping the board, pot, and hero controls unobstructed.
A real-Chromium 40-scenario painted-collision gate now covers every player count across five viewport classes.
Released
H5
Clearer Max monthly and yearly price comparison
The Max pricing card now follows the same comparison order as Pro: monthly first, then yearly. The limited yearly offer remains highlighted and explicitly shows “Best value” plus US$358.30 saved versus paying monthly for a year. Prices and membership benefits are unchanged.
Max now presents monthly before yearly, making the yearly offer easier to compare directly.
Yearly remains US$0.50 (regular US$299) and now shows the US$358.30 savings versus twelve monthly payments.
Released
Backend
Database monitoring, indexes, and payment uniqueness hardening
The backend adds parameter-redacted slow-query observation, sustained-signal alert thresholds, and a five-minute database health check. The database now enforces at most one current subscription projection and one user-initiated in-flight payment order per user, with order/user/provider identity checks. Each paid order retains its own entitlement fact and the read side selects the highest live tier, so out-of-order Pro settlement cannot downgrade Max. A new checkout releases an overdue unpaid pending slot, while possibly captured submitted evidence remains provider-reconciled; already-captured Apple/Google receipts bypass the checkout gate. Critical foreign-key indexes are added and two redundant indexes are removed to reduce write amplification.
SQL over 500ms feeds five-minute trend counts; sustained slow queries, one five-second query, long transactions, repeated deadlocks, connection pressure, or repeated pool waits trigger alerts.
Slow-query logging explicitly disables bind-parameter capture so emails, sessions, and payment payloads stay out of operational logs.
The database rejects concurrent checkouts and a second current subscription projection; entitlements remain per paid order with the highest live tier effective, and overdue unpaid intents release their slot.
Indexes now cover subscriptions.latest_order_id and oauth_nonces.user_id; two redundant hand_actions and coach_hints indexes are removed.
Released
H5Backend
Table and startup upgrades, localized emails, alerting ready, and restored Max pricing
This release ships H5, backend, and the marketing site together: the current actor gets a reconnect grace window, multiway all-ins show live main and side pots, folding when a check is free requires confirmation, and folded players may voluntarily reveal after the hand. Telegram cold-start navigation now recovers automatically; verification-code, password-reset, and email-change messages follow the user's active language; and the backend gains configurable anomaly aggregation and alerting while container logs have rotation limits. H5 and server passwords share an 8–128-character rule, and one-time local payment methods explicitly describe the fixed-term training membership being purchased. Max monthly returns to US$29.90 (3000 XTR/month), while Max yearly keeps the US$0.50 beta promo with a struck-through US$299 regular price.
The current actor is no longer auto-folded immediately after disconnecting; a grace window and stale-action isolation prevent accidental actions after timeout.
Multiway all-ins now show the main pot and every side pot live, with Total reconciled to the breakdown.
Folding when a check is free now asks for confirmation, and folded players can choose to reveal their cards after the hand ends.
Hand-history and standings drawers use a denser layout so nine-player showdown information fits better on phones.
Telegram Mini App cold starts size to the visible viewport immediately and resume bottom-navigation synchronization when a delayed WebApp bridge arrives.
Verification-code, password-reset, and email-change messages use the active product language, safely falling back to English instead of mixing languages.
The server gains configurable anomaly aggregation, de-duplication, and Telegram alerting; container log caps activate with this release to prevent logs from filling the disk.
H5 and server signup, credential setup, and password reset now share an 8–128-character rule while still rejecting common and predictable passwords.
One-time Alipay, WeChat Pay, and PayNow checkout now labels the fixed-term training-membership fee and explicitly excludes wagering, chips, deposits, and cash prizes.
Max monthly returns to the standard US$29.90 / 3000 XTR; Max yearly remains a US$0.50 limited beta offer with the US$299 regular price struck through.
Production releases are now built only from main and require one new bilingual changelog entry before prod switches; H5, backend, and the site share one SHA and release id.
Released
H5Backend
Open-source solver mirror re-synced to the deployed build
This release re-publishes the public AGPL §13 Corresponding Source (the engine and postflop-solver subset) so it byte-matches the deployed build (tag solver-src-2026-07-18). It is a routine dependency-lock refresh only — solver results and gameplay are unchanged.
The public mirror tag solver-src-2026-07-18 is byte-identical to the deployed build, keeping the AGPL §13 source offer valid.
Only the dependency lock (Cargo.lock) was refreshed; the postflop-solver source and algorithm are unchanged.
Released
H5Backend
Email signup now uses six-digit, proof-first verification
H5 signup now proves mailbox ownership with a six-digit code before showing password and consent. Existing accounts are routed to sign-in or recovery. The server remains compatible with legacy eight-digit clients while strengthening new-password and email-account lookup rules.
New H5 signup codes are exactly six digits and preserve leading zeroes; legacy clients can still finish their eight-digit flow during the compatibility window.
After verification, new mailboxes continue to account creation while existing mailboxes move to sign-in or recovery instead of a late registration conflict.
New and reset passwords require at least 15 characters and reject common weak choices; existing short passwords can still sign in.
Sign-in and password recovery prefer canonical email lookup while retaining an exact-email compatibility path for legacy accounts.
Released
Backend
Telegram Stars test balances now require provenance attestation
Real-provider verification on Telegram's Test Server now requires the controlled test flow to attest both an existing Stars balance and its non-store test provenance before creating an order, preventing store-funded, refunded, or disputed balances from being treated as safe test funds. Production Telegram Stars checkout is unchanged.
Missing, mismatched, or store-origin provenance is rejected before any order write or Telegram provider call.
Each restricted run remains limited to one 1-XTR invoice, with the one-run budget still preventing retries from expanding risk.
The test wrapper, operational status, and bilingual incident review now agree: stop real-provider testing when no trusted non-store test balance is available.
Released
H5Backend
Table hands upgraded to a readable side drawer
Table history now opens as a full-height right drawer with larger board and hole cards, while rabbit hunt is strictly scoped to the selected hand. This release also fixes bet, pot, and hero-zone collisions on compact iPhone viewports.
History focuses one hand at a time with large board and hole cards, a visible slice of the table, and bottom hand-by-hand paging.
Rabbit hunt now lives inside the selected history hand; its runout never enters the live board or another history hand.
History enforces strict visibility: the viewer always sees their own cards; opponents are face-up only when explicitly authorized by the server, while folds, mucks, and unpersisted voluntary reveals stay face-down.
Dedicated safe lanes separate top bets, pot, blind markers, hero cards, and the bottom rail in iPhone 14 browser viewports.
Released
H5
Every sub-screen now has a way back
A full audit of back navigation across every H5 screen: the Solver page had no back button at all, and the Drills and History pages only showed one when entered from specific paths. In shells without browser chrome (installed PWA or Telegram Mini App), players could get stuck on those screens. All three now always show a back button.
The Solver page gained a back button: it returns along the in-app history when present (for example from Review), and falls back to the Tools hub otherwise.
The Drills and History back buttons no longer depend on an entry parameter — arriving from a notification, from Review, or via a direct link still offers a way back.
Back handling is safe for cold deep links: with no in-app history it falls back to the parent screen instead of a dead browser back.
Released
H5Backend
Stripe checkout fixed with availability-aware payment options
This release fixes the API-version mismatch that blocked Stripe Elements sessions for Apple Pay and Google Pay, and only exposes payment methods that Stripe has enabled and the release preflight has verified.
Apple Pay and Google Pay Elements sessions now use the API version matched to the frontend Stripe.js release.
Methods not enabled on the live Stripe account, such as Alipay, WeChat Pay, or Google Pay, are hidden and cannot be forced through the server endpoint.
The release preflight now verifies Stripe's live payment-method configuration and wallet domain, then creates and expires no-charge sessions; rejected requests mark the local order rejected and retain only safe diagnostic fields.
Released
Backend
Mobile update checks now report the correct store versions
In-app update checks now return the currently published App Store and Google Play versions independently instead of reusing a stale shared version record.
iOS and Android now compare against the build currently published in their own store.
Local installs and candidate builds no longer overwrite the published catalog before a store release is available.
Released
H5Backend
In-app subscription verification goes live, plus Telegram subscription fixes
This release activates server-side verification and real-time developer notifications for Google Play in-app subscriptions in production, and fixes Telegram Stars subscriptions that could not be cancelled or refunded after lapsing.
Google Play subscription purchases are now server-verified and grant membership automatically, with real-time developer notifications (RTDN) active.
Telegram Stars subscriptions can now be cancel-marked and refunded correctly even after they lapse; other provider rejections still fail closed.
A test-environment-only subscription-period override enables repeatable regression checks; production stays locked to 30-day periods and rejects misconfiguration at startup.