Light mode version of Land Your Home

Partner API access, and invites, licences and transaction access locked down

New

  • Partner applications can now connect to Land Your Home on a user's behalf. The user signs in and approves the connection on a new "Authorise access" screen showing which application is asking and what it can see, and can deny it. The partner API now issues each partner its own revocable keys with usage limits, and every request also needs the user's approval, so a partner can only see and do what that user could.

  • Partners can now read a user's property chains, transactions, the people on a transaction, stages and properties through the API, with paging for long lists. Each person's name, email, phone and company are shown only as far as they have chosen to share them, and nothing outside what the user themselves could see is returned.

  • Partners can now make changes on a user's behalf through the API: remove a link from a chain, merge two chains, leave a chain, and change their own or another person's role and permissions on a transaction. Each change needs both the partner's permission to write and the user's own permission on that transaction, and can never give someone more access than the user has themselves.

  • Partners can now create a chain, link existing transactions together, and add a property to a chain through the API. Each step is checked against the user's own permissions on the chain.

  • Partners can now read a single stage, add stages to a transaction, change them, set what a stage depends on, and delete them through the API. A stage can be assigned to the user or left unassigned, and a stage can only depend on another stage of the same transaction.

  • Partners can now work with invitations and access requests through the API: see the invitations a user has received and sent, invite someone to a transaction (they get the usual email, and an in-app notification if they have an account), accept, decline or revoke invitations, ask to join a transaction, and accept other people's requests to join. Nothing outside what the user could do themselves is allowed.

  • Partners can now read a user's address book through the API: the other people on their chains and the transactions they're on together. Each person's name, email, phone and company are only shown as far as that person has chosen to share them.

Improvements

  • Stages that partners create or change through the API now get the same update reminders as stages edited in the app: a stage assigned to the user with a date for its next update reminds them at 9am that day, and the reminder is moved or cancelled if the stage changes or is deleted.

  • Behind-the-scenes tidy-up of how PropChain talks to the database, so the same logic can be shared with the partner API. There is no change to how anything looks or works.

Fixes

  • Invites and licences can now only be seen by the people they concern: the person who sent an invite, the person invited, the people on the property chain, and team admins for team invites. Invite codes are no longer visible to anyone in the app.
  • Nobody can add themselves to someone else's property transaction, create licences, or reassign licences by going around the app. Inviting someone, declining or revoking an invite, redeeming a licence, putting a licence on a chain, and creating a QR code now all run as single checked steps.
  • Inviting someone to a transaction now also stops you giving them more access than you have yourself, and an invite is created before its email is sent.
  • A licence that already belongs to a team can no longer be redeemed by someone outside it, and a free licence assigned to one team member can no longer be used up by another.
  • Who can change a transaction's people and details is now enforced everywhere, not just in the screens. You can only change someone else's role or permissions if you're allowed to edit parties, only up to your own level, and never someone with more access than you; the last person able to manage parties can't be removed. Editing sale, property and listing details needs the matching edit permission, and you now get a clear message if you don't have it.
  • Transactions, their people, stages and history are only visible to the people involved (and their neighbours in the same chain), and the transaction history can no longer be forged.
  • Accepting a request to join a transaction can no longer grant more access than the person accepting holds.
  • Merging two chains now checks that you are involved in the shared property, and either moves everything across or nothing, so a chain can no longer be left half-merged.
  • Starting a chain, linking transactions and adding a property to a chain now each happen as a single step, so a failure part-way no longer leaves a half-built chain behind. Previously anyone signed in could link any two transactions into any chain; that is no longer possible, and linking now needs permission to edit the chain on the transactions involved.
  • Stages created through the API are checked: an owner has to be someone on the transaction, and stages can't be made to depend on each other in a loop.
  • The address book now decides what each person has shared in the database itself, instead of sending everyone's details to the screen to hide, so contact details a person keeps private are never sent to anyone else.

On this page