CSRF enforcement on /api/admin/* with fetch auto-injection
IP/UA binding on SSO transfer token
sanitizeNext locked to APP_DOMAIN (open-redirect prevention)
timingSafeEqual on webhook HMAC
Rate limit on /login and /sso/callback
Skip link + ARIA roles + Cookie consent banner (PDPL)
Onboarding wizard for new users
v1.1.0
#hub-integration
Full Zayenha Hub integration
SSO via auth.zayenha.com with link.zayenha.com bridge
/webhook/zayenha accepts 11 Hub events
/billing/return page for Hub Checkout returns
/account page with 3-zone model
11 app_* tables for integration (Migrations 0005-0008)
logout returns 200 HTML (not 302 redirect)
v1.0.0
#launch
Public launch
Link shortening with custom alias
Pro Bio pages
WhatsApp campaigns with ready templates
Hijri calendar links (Ramadan, Eids, National Day)
Detailed click analytics
Full AR/EN + RTL support
Cookies
We use essential cookies to run the site and remember your preferences (language, session). Accept to allow additional cookies for analytics and improvement, or decline to use essential only. More info in our privacy policy.