AutoDM Changelog
A transparent, commit-backed log of every feature launch, performance improvement, and security patch shipped to AutoDM.
Zero-Downtime Releases: Production updates deploy continuously to our cloud cluster and live Instagram Graph API webhook listeners with no disruption to active campaigns.
Full-Stack Security Audit, Tenant Isolation & Dependency Hardening
Repository-wide security audit across the FastAPI backend and Next.js frontend: 18 findings reviewed, 17 fixed and independently re-verified. Closes a critical Next.js advisory, patches vulnerable auth and upload dependencies, makes webhook routing deterministic so an event can never be attributed to another creator, validates ownership before any DM leaves the server, and adds HSTS/CSP plus automated dependency scanning in CI.
Security7
- •Critical Next.js Advisory Patched: Upgraded Next.js past the next/og ImageResponse remote-code-execution advisory (GHSA-vcvr-r3jv-pc5j) — the affected API was live at /opengraph-image. The production dependency audit is now clean.
- •Webhook Events Can No Longer Cross Creators: Inbound Instagram events are resolved strictly by Instagram account ID, deterministically, and refuse to guess when a match is ambiguous — an event for one creator can never fire another creator's automations.
- •Every DM Send Validates Ownership First: The delivery worker now verifies the recipient, campaign and sender account belong to the same creator before decrypting any token or calling Meta.
- •Webhook Signature & Replay Hardening: Malformed signature headers now fail closed with a 401 instead of a server error, and every delivered webhook receives a deterministic dedupe id so replayed events are always recognised.
- •HSTS & Content-Security-Policy: The web app and API edge now send Strict-Transport-Security and a Content-Security-Policy that blocks base-tag injection, plugin embedding, clickjacking and cross-origin form exfiltration.
- •Edge Rate-Limit Bypass Closed: Narrowed the reverse proxy's trusted real-IP ranges to the actual container subnet, and removed a stale configuration that exposed an unauthenticated Celery dashboard.
- •Automated Dependency & CI Security Gates: Added a frontend CI pipeline that blocks known-vulnerable production dependencies, plus Dependabot alerts and a backend dependency scan in CI.
Fixes3
- •Vulnerable Auth & Upload Libraries Patched: Updated the JWT library and the multipart parser to their patched releases, closing multiple denial-of-service and token-validation advisories.
- •Production Safety Checks Can No Longer Be Disabled by a Typo: The environment name is now normalised, so a casing or spelling variation can no longer silently disable the production boot guards.
- •Build Verification Gate Restored: Re-synchronised the documented test count and migration head so the CI verification gate passes again — it was failing before this audit.
Improvements4
- •Sign-In Tokens Bound to Authorized Origins: Sessions can now be restricted to an allow-list of application origins, adding an extra layer of token binding.
- •External Images Send No Referrer: Avatar and thumbnail requests to the Instagram and Clerk CDNs no longer leak the page URL.
- •Leaner Production Images & Safer Host Sandboxing: Production no longer installs test and lint tooling. A global uniqueness rule now guarantees one Instagram account maps to one connection, and the service sandbox blocks kernel-level access while bounding crash restarts.
- •Automated Secret Scanning: Every push is scanned for accidentally committed credentials, with a verified self-test so the check cannot silently stop working.
Unified Automation Suites, Engaged Audience & Admin Portal
Complete overhaul transforming campaigns into live automation suites connected directly to Instagram comment and story triggers. Added real-time engaged audience recipient tracking with delivery diagnostics, responsive mobile touch navigation, scalable Google Ads vector banners, and strict role-based administrative oversight.
Features5
- •Live Automation Suites with Comment & Story Triggers: Campaigns now link directly to live Instagram post/reel comment triggers and story webhooks. Eliminates manual cold CSV list uploads and connects marketing campaigns directly to inbound social engagement.
- •Real-Time Engaged Audience Tracking: New audience management table displaying Instagram handles, trigger keywords, timestamp logging, and instant delivery status badges (Sent, Delivered, Read, Failed).
- •Configurable Send Limits & Unlimited Mode: Set custom delivery limits per time window to stay within preferred thresholds, or activate Unlimited Mode for high-concurrency event launches.
- •Strict Admin Portal Dashboard: Dedicated administrative portal tracking aggregate DM delivery rates, failed attempts, and queue depths with strict RBAC guards for authorized operators only.
- •Google Ads Display & Brand Media Kit: Shipped scalable vector SVG banner suite across IAB standard sizes (300×250, 728×90, 300×600, 320×100) and editorial announcements with 80% safe zone layout.
Improvements4
- •Responsive Mobile Redesign: Added mobile touch drawer navigation, card-based responsive tables for campaigns and recipients, and Google avatar sync across all viewport sizes.
- •Auth-Aware Landing CTAs: Dynamic navigation routing authenticated creators directly to /dashboard while presenting guest registration to new visitors.
- •App-Wide AuthReadyContext: Streamlined onboarding state detection to eliminate duplicate login redirects and reduce auth verification latency.
- •UI Button Deduplication: Cleaned redundant primary action buttons across campaigns, automations, and analytics pages for a streamlined creator interface.
Fixes & Stability4
- •Engagement Chronological Coalescing: Fixed SQL timestamp sorting using COALESCE(sent_at, created_at) to eliminate null ordering anomalies in recipient engagement tables.
- •Leaderboard Ad Banner Text Spacing: Eliminated text overlap across the CTA button in the 728×90 leaderboard ad banner by establishing strict column boundaries and negative space buffers.
- •Strict RBAC on Admin Queries: Prevented non-admin users from executing administrative stat queries and protected sensitive system metrics from unauthorized requests.
- •Normalized Debug Trace URIs: Fixed API base URL concatenation to eliminate duplicate slashes across developer endpoints and trace links.
Production Infrastructure, Security Hardening & Preflight Guards
Deep infrastructure hardening featuring MultiFernet token encryption with key rotation, strict Meta review compliance, developer debug tracing with production tenant scoping, and hardened Nginx rate-limiting architecture.
Features3
- •Production Debug Traces API: Scoped execution traces for deep diagnostic visibility in production with a global kill-switch and strict tenant isolation.
- •Multi-Account Sender Pools: Connect multiple Instagram accounts to share delivery load evenly, avoiding rate limits and scaling high-volume campaigns safely.
- •Automated Production Preflight Guard: Standalone verification suite checking database migrations, Redis queues, and environment configurations before process boot.
Improvements3
- •Daily Analytics Aggregation: Optimized SQL group_by queries for faster loading on high-volume accounts with millions of tracked follower interactions.
- •In-Memory TTL Caching: Bounded TTL cache for Clerk user email lookups to reduce auth latency and eliminate redundant third-party API calls.
- •Nginx Rate Limit Isolation: Modularized rate limit zones into dedicated configuration blocks for reverse proxy stability on production VMs.
Security & Meta Compliance4
- •MultiFernet Token Encryption & Key Rotation: All Instagram Graph API user access tokens are encrypted at rest using MultiFernet with AES-128-CBC encryption, PKCS7 padding, and HMAC-SHA256 authenticated integrity.
- •Linear-Time ReDoS Protection: Migrated suspect user input regex matching to Google RE2 to prevent regex denial of service vulnerabilities.
- •HTTP Security Headers: Configured Permissions-Policy, strict Content-Type sniffing protection, and disabled legacy insecure headers.
- •Webhook Content-Length Guard: Added payload size validation before reading stream buffers to protect webhook listeners from oversized payloads.
Core Platform Launch & Live Instagram OAuth
The foundational release of AutoDM — 100% free Instagram DM automation for creators, built strictly on the official Instagram Graph API with real-time webhooks.
Features4
- •Real-Time Comment-to-DM Dispatch: Automatically deliver direct messages to anyone who comments on your Instagram posts or reels within 3–8 seconds.
- •Story Reply & Mention Automations: Trigger personalized DM links and resources whenever followers reply to or react to your active Instagram stories.
- •Live Instagram OAuth Flow: Direct Meta OAuth authorization with official Instagram App ID and secure token renewal.
- •100% Free Forever Architecture: High-concurrency async pipeline engineered without artificial paywalls, contact caps, or surprise subscription tiers.
Improvements3
- •Extended OAuth Exchange Window: Extended client timeout allowance to 90s for multi-step Meta Graph API token exchanges across high-latency networks.
- •Public Comment Confirmation: Optional public reply wizard ('Check your DM! ✉️') to boost algorithmic post engagement and notify commenters.
- •Friendly Timeout Diagnostics: Human-readable error prompts on slow network connections rather than raw signal aborted messages.
Fixes & Stability2
- •OAuth App ID Alignment: Reconciled Instagram app ID with Meta business app configuration to ensure smooth OAuth handshake.
- •Domain-Safe Auth Redirects: Fixed middleware redirect handshake with Clerk auth to prevent redirect loops on custom domain apex.
Ready to automate your Instagram for free?
Set up in less than 2 minutes. Free forever with unlimited automations.