> ## Documentation Index
> Fetch the complete documentation index at: https://docs.perfai.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> New features, improvements, and fixes in Perfai Security.

<Update label="v2.4.0" description="June 2026">
  ## Vision Agent: Multi-Tab and SPA Deep Crawl

  The Vision Agent now handles complex single-page applications with client-side routing significantly better. It tracks route changes triggered by JavaScript navigation (not just `<a>` tag clicks), enabling full coverage of React, Next.js, Vue, and Angular applications that use hash-based or history-based routing.

  **What changed:**

  * SPA route detection: Vision Agent now observes `pushState` and `replaceState` events to discover routes that never produce a network navigation
  * Multi-tab session support: workflows that open resources in a new browser tab are now correctly traced end-to-end
  * Improved form interaction: Vision Agent can now complete multi-step forms including file upload inputs, rich text editors, and custom date pickers
  * Crawl depth increased from 4 to 6 levels for apps with deeply nested navigation hierarchies

  **Security Agent improvements:**

  * Mass assignment detection: the Security Agent now probes request bodies for writable fields beyond what the UI exposes, identifying cases where a lower-privileged role can set fields (e.g., `is_admin`, `role`, `org_id`) that should be immutable
  * BFLA (Broken Function Level Authorization): improved detection for admin-only batch and export endpoints that share URL structure with standard CRUD endpoints
</Update>

<Update label="v2.3.0" description="May 2026">
  ## Role Matrix Visualization

  A major dashboard upgrade focused on helping teams understand and act on their permission coverage.

  **Dashboard:**

  * **Role Matrix View**: a new visualization in the Issues tab shows your full role × endpoint permission grid, color-coded by finding severity. Instantly see where your access control boundaries are being violated and which role combinations are highest risk
  * **Workflow Timeline**: replay the exact sequence of UI interactions the Vision Agent recorded for any workflow, step by step, with network requests shown alongside
  * **Bulk triage**: select multiple issues and update status, assign to team members, or push to your issue tracker in one action

  **Integrations:**

  * **GitHub Issues integration**: Perfai findings can now be exported directly as GitHub Issues with appropriate labels (`security`, `critical`, `perfai`) and a standardized body template
  * **Jira integration (beta)**: connect Perfai to a Jira project and push findings as Jira tickets. Supports custom field mapping for severity and component

  **Security Agent:**

  * Horizontal access bypass detection improved: the Security Agent now correctly distinguishes between "User A can access User B's resource" (finding) and "all users can access a shared public resource" (expected behavior), dramatically reducing false positives on public-read endpoints
  * Added detection for JWT `alg: none` and weak secret exploits when the Vision Agent observes JWT tokens in API responses
</Update>

<Update label="v2.2.0" description="April 2026">
  ## Public API Launch and CI/CD Integration

  Perfai's public REST API is now generally available, enabling teams to integrate security testing directly into their development and deployment pipelines.

  **Public API (GA):**

  * `POST /v1/apps` — register an application
  * `POST /v1/apps/{appId}/security-agent` — trigger a security test
  * `GET /v1/apps/{appId}/vulnerabilities` — retrieve findings
  * Authenticate with your dashboard token — see the [API overview](/docs/api/overview) for the current endpoint set

  **CI/CD:**

  * Published official GitHub Actions example for triggering security tests on push to `main`

  **Platform:**

  * **Multi-app dashboard**: improved navigation for accounts with many registered apps, including search, filtering by last-tested date, and a security score overview across all apps
  * **Scan history**: full scan run history per app, with the ability to diff findings between two runs to see what was introduced or fixed
  * **PDF report export**: generate a compliance-ready PDF from any completed scan, formatted for OWASP Top 10 audit evidence packages

  **Vision Agent:**

  * Support for apps that use WebSocket connections: the Vision Agent now records WS message payloads as part of workflow traces, and the Security Agent can replay modified WS frames to test server-side authorization on real-time channels
  * Login flow improvements: better handling of MFA-protected accounts using TOTP (configure a TOTP seed per role) and SSO flows via SAML and OAuth
</Update>
