← Back to all sparks
I

InvoiceShelf

FINANCE
Velocity6.3

Self-hosted invoicing and expense tracking application

InvoiceShelf 3.0 alphas let Claude, ChatGPT and Cursor draft and send invoices.

invoicingmcpmulti-tenant-hostingsecurity-hardeningself-hosted
◆Current state
InvoiceShelf is pushing 3.0 through public alphas at a rate of several a week, each marked not for production. Alpha.5 added an MCP server so AI assistants can read, draft and send documents with the connecting user's permissions. Later alphas add role presets, user administration for the super admin, official modules on managed installs and a Docker image that runs on a read-only filesystem, alongside a steady stream of security fixes.
◆Where it's heading
3.0 is turning a single-company invoicing app into something a hosting provider can run for many customers: role presets across companies, provider-controlled module installs, a separate customer-portal host and a locked-down container. The security fixes (guessable document links, SSRF through mail settings, a setup token that acted as super-admin) show the multi-tenant hardening is still catching up with the feature work.
◆Prediction
Expect more alphas that close security issues and fill out hosted-provider controls before a beta; the entries show no beta date.

◆Recent moves

  1. 13d ago

    3.0 alpha.10: owners install official modules on managed hosts

    Owners on a managed install can now add, update and remove official, signed modules themselves when the host mounts a writable Modules directory, and each Docker start checks modules against the running version. It continues 3.0's work on making InvoiceShelf something hosting providers can offer.

    View source ↗
  2. 14d ago

    3.0 alpha.9: role presets and admin user management

    The super administrator can define role presets (Owner, Manager, Read only ship by default) that every company gets, and create users and assign them to companies. It's the multi-company administration layer the hosted direction needs.

    View source ↗
  3. 14d ago

    3.0 alpha.8: SSRF fixes and a read-only, host-ready Docker image

    Closes SSRF and related holes in mail, disk and installer settings, fixes foreign-currency documents on PostgreSQL, and makes the image run on a read-only filesystem with its own customer-portal host. Security and hosting readiness advance together, as they have through the alpha series.

    View source ↗
  4. 15d ago

    3.0 alpha.7: PDF font folder and signed-out redirect fixes

    Two fixes: PDFs failed in containers with an empty storage volume, and signed-out visitors hit a not-found page instead of sign-in. Routine alpha stabilisation.

    View source ↗
  5. 16d ago

    3.0 alpha.6: fixes that blocked fresh installs and restarts

    Fixes three bugs that stopped 3.x installs from being created or restarted, including a PostgreSQL migration failure present since alpha.2. Found while preparing the public demo; no new capability.

    View source ↗
  6. 16d ago

    3.0 alpha.5: AI assistants connect over MCP

    ⚡ SPARK

    Alpha.5 is where 3.0 stops being only a redesign: AI assistants connect over MCP and act on invoices with the connecting user's permissions. It also adds the headless install and demo mode that the later hosting-focused alphas build on.

    View source ↗