Two bugs caused the cards list and integrations to show stale data
after a user edited a card in the detail view:
1. ResponseCard.name is a denormalized display string set only at
OCR / survey-submit time. Editing firstName or lastName never
recomputed it, so the table header and Name column kept the old
value. PUT /api/cards/[id] now recomputes name from first + last
whenever either changes (unless the caller passed an explicit
name). The detail page header reads from in-flight edits so the
title updates live as the user types.
2. The default form template marked only firstName/lastName as
isCore. Every other field (email, cellPhone, address, etc.) was
non-core, so dynamic-field edits landed in ResponseCard.fieldData
JSON and never touched the top-level columns the list view,
search, CSV export, and integrations read from. The PUT route
now promotes any fieldData keys that match canonical columns up
to those columns; the default template marks all canonical
fields as isCore so new orgs avoid the problem in the first
place.
Adds scripts/backfill-core-fields.ts (dry-run by default; pass
--apply to commit) to flip existing FormField rows to isCore = true
where the key matches a canonical column and to promote any
existing fieldData values into empty top-level columns + recompute
stale name values.
Co-authored-by: Cursor <cursoragent@cursor.com>
Phase 1 - Security & Bug Fixes:
- Add requireApiAuth helper and protect all 25 unprotected API routes
- Add org-tenant scoping to all card, job, stats, and notification queries
- Fix SSRF in ai-test, mask secrets in settings API, fix middleware bypass
- Fix cards pagination routing, stat filter sync, drag-drop file passing
- Add PUT /api/auth/me for profile persistence, stuck job recovery
- Fix email watcher MIME type detection
Phase 2 - Dynamic Fields & Digital Survey:
- Add FormTemplate, FormField, Person, PasswordResetToken models to schema
- Add fieldData, formTemplateId, firstName, lastName, personId to ResponseCard
- Build FormTemplate CRUD API with field management and org scoping
- Build Form Builder UI with field ordering, type config, and section management
- Refactor card detail page to render fields dynamically from templates
- Add dynamic OCR prompt/schema generation from template fields
- Build public survey page at /s/[orgSlug]/[formSlug] with branding
- Add QR code generation API and share section component
Phase 3 - People & Analytics:
- Build People CRUD API with merge and batch auto-link endpoints
- Build People list and detail pages with search, merge dialog
- Add auto-link logic in OCR completion to match/create Person records
- Add /api/stats/trends endpoint with time series and team activity
- Build Reports page with Recharts (area charts, bar charts, pipeline)
- Upgrade dashboard with sparklines and People stat card
Phase 4 - UX Polish:
- Replace silent error handling with toast notifications across all pages
- Add loading skeletons, differentiated empty states
- Add ARIA labels, skip-to-content link, accessible column toggle
- Add forgot password flow, Cmd+K command palette, Collection Days pages
- Unify Echo branding and theme toggle consistency
Made-with: Cursor