[1.15.0]
Update leantime to 3.10.0
Full Changelog
Period-Based Status Reports - Added period-based status report screens backed by a shared report engine and a period-aware actuals window for resources. (#3643, #3714)
Mobile SSO - Introduced a generic OIDC mobile SSO bridge with one-time-code to bearer-token exchange, a public /status discovery endpoint advertising auth methods, and AdvancedAuth gating. (#3637, #3662, #3664, #3711)
User Capacity Fields - Added weekly hours and employment type to user profiles for better resource planning. (#3653)
Routing - Resolved plugin controllers whose folder name has an inner capital letter. (#3773)
Ideas on Kanban - Fixed the "Edit" option for Ideas not working in the Kanban view. (#3752)
Sidebar Projects - Admins and owners now see all projects they have access to, fixing an empty project sidebar. (#3710)
Upgrades - The installer now self-heals a missing zp_access_tokens table and a stale session-cached db-version so updates can't get blocked. (#3745, #3735)
Files - File names now display in full with a title tooltip instead of being truncated to 10 characters. (#3734)
Tickets - Archived-project tickets are excluded from open ticket lists, statusDone history is logged with an accurate "last updated" time, and ticket parents are preserved on failed new-ticket submissions. (#3639, #3638, #3650, #3641)
JSON-RPC Authorization - Closed an account-takeover chain: any authenticated user could call the onboarding service over JSON-RPC to set another account's password and role, activate it, then disable its 2FA. The onboarding and 2FA services are no longer RPC-reachable, and a sweep of the remaining unguarded @api methods closed marketplace license-key exposure, cross-user dashboard/widget writes, unauthorized ticket-dependency rewrites, mention forgery, and installer/scheduler/queue triggers. (#3797)