Public development record

Project
changelog.

What changed in NFTerra's public website, product definition, engineering baseline, and development workflow. Entries describe delivered project work—not unannounced game releases.

The development-facing source of truth

What exists now. What comes next.

NFTerra is building the shared Android/iOS backend, with Android first. Tested local workflows settle mint costs and whole-item trades using funded Copper and encrypted history. New source and ownership components preserve traded bases and partially consumed materials, with combined buyer-mint conformance tests. Signed actions and private receipt reads are also tested for preregistered characters. A single funded shared coordinator remains integration work. Hosting stays at EUR 0; no playable public game or real-value economy is live.

Current phasePre-production foundation implementation

Future items are planning direction, not dates, launch promises, or claims that the functionality already exists.

Review the current concept
Delivered project work

What has been completed.

  • Canonical inventory distinguishes ordinary, consumable, stackable, quest, sealed and minted items. Whole sealed bases and ordinary stacks can move between two local fixture inventories and return with the same identity, metadata and visible level. Consumed or merged identities cannot reappear; schema-1 mint history remains recoverable through the inventory upgrade.
  • Immutable sealed-source records now stay separate from current ownership, quantity and lifecycle. Shared ownership components preserve positive material remainders and consumed identities; restoration requires the original genesis and actual inventory histories. Combined domain tests cover a traded base and buyer-owned mint inputs on both outcome paths. These components do not yet form a shared funded coordinator or service.
  • The local mint coordinator freezes visible costs, success probability, failure losses, minter profile and base level before consent. It reserves funded Copper and inventory together, resolves one saved outcome, consumes the disclosed inputs and sends charged tokens to the project treasury. Successful candidates remain pending blockchain confirmation and cannot equip.
  • Encrypted PostgreSQL economy state, permanent base/attempt/reservation identity guards, original retry receipts, audit and outbox commit together. Two-process tests cover concurrent requests, restarts, process crashes, partial failure, failed writes, wrong keys and tampered or older state; no automatic expiry removes economic history.
  • The local item-exchange coordinator freezes merchant-skill fees, reserves inventory capacity and funded payment, pays seller consideration and treasury fees once, and keeps received items locked until its explicitly simulated receipt is verified. Encrypted state, permanent identity guards, audit, outbox and simulated inbox reconcile across concurrent requests, restarts and failed writes. Public marketplace and receipt publication remain planned.
  • A separate local device-key fixture verifies fixed P-256 signed acknowledgements and fresh signed receipt reads for two preregistered test characters. Current credential checks, original proof preservation, revocation and encrypted PostgreSQL history are verified across concurrent processes, crashes and failed writes. It does not enroll real devices, authenticate economic actions or provide mobile wallet signing.
  • A versioned template generator rolls statistics, distinct affixes and procedural names within the base's level limits. Minter level and relevant skills influence possibilities without raising the base level or the shared 100-point skill cap. Private entropy and hidden inputs stay out of player responses and public work records.
  • An ephemeral local-chain wallet generates an address and signs currency transfers to external test wallets. Local NFT contracts enforce approved game-wallet recipients and internal settlement authority. The wallet proof is not a delivered mobile wallet, custody service or public-chain deployment.
  • A .NET 10 API now supports PostgreSQL-backed synthetic sessions and fixed-price test purchases. State, command history, audit events and an outbox commit together; concurrent retries, restarts, conflicting commands, failed writes and unavailable storage are verified.
  • Exact integer Copper accounting and local ERC-20 checks enforce three decimals and the one-billion-token ceiling: one Gold/token equals ten Silver, one hundred Bronze, or one thousand Copper. Funded reservations and partial settlement conserve the initial allocation and recycle game charges to the configured treasury. Synthetic balances are not issued or redeemable cryptocurrency.
  • The Android client source now retains pending requests across app restarts and displays server-confirmed test inventory and denominations. The API 36 emulator has booted and reached the local PostgreSQL-backed API through ADB; Unity APK generation remains blocked by missing entitlement.
  • A Yasa-owned Google Cloud development project has been created in the company organization. The approved hosting budget is EUR 0; billing is disabled and no hosted game service or managed database has been provisioned. Local Docker data services remain the working backend environment.
  • The public website leads with NFTerra's geographic game, skill-shaped NFT ownership, cryptocurrency economy, and guild/town DAO systems for shared assets, contracts, escrow, member rights, voting, and town operation.
  • Unity 6 LTS, native Google Maps bridges, .NET, PostGIS, Redis, Google Cloud, and guarded Polygon adapters form the selected engineering baseline.
  • The repository contains a phased development plan, prioritized NFT-### backlog, quality checks, release workflow, deployment backups, and public changelog.
  • The website and structured changelog now serve as the development-facing presentation of current truth, completed project work, and planned next work.
  • The character presentation exposes every race and starting-class page from the header, gives the six race directions and five starting loadouts coherent concept art, and leads with player identity while keeping approval boundaries explicit below the heroes.
  • The sitewide footer now provides a categorized project directory, structured release and development status, verifiable operator details, specialized enquiry routes, and a prominent no-sale warning.
  • The public enquiry flow is protected by server-validated Cloudflare Turnstile, layered with CSRF, origin checks, abuse throttling, input limits, and private credential handling.
  • The product intake, requirements, architecture, first-playable scope, phased plan, backlog, testing strategy, and Definition of Done are reconciled with the current website while clearly separating planned game systems from delivered project foundations.
  • Every website SVG now passes an automated intrinsic bounds and paint-order check, with the technology stack and three other explanatory diagrams rebuilt or refined for reliably contained text and artwork.
Planned next work

What the project intends to do next.

  • Compose the tested source, ownership, inventory, fee and generation components with one funded currency ledger in a single shared coordinator. Preserve original base inputs and exact material remainders, then add atomic encrypted persistence, authenticated economic consent and verified public receipt reconciliation.
  • Extend the signed-action foundation to reviewed economic consent and eligible player enrollment, with native mobile key protection, attestation and recovery decisions. Keep wallet signing independent from device credentials and preserve the shared 100-point skill cap.
  • Add verified outbox/inbox delivery and chain finality reconciliation to the tested mint coordinator. Keep generated candidates unavailable until canonical NFT ownership is confirmed; retain original outcomes during retries, delays and recovery. Reward balancing and content remain deferred.
  • Connect tested wallet and Polygon adapters only after domain settlement and reconciliation are ready. Define organization charters and explicit rights before shared custody, escrow and DAO execution.
  • Complete licensed Unity import and ARM64 APK generation, then verify a physical Android device. Native Maps and foreground-location integration remain separate acceptance gates.
  • Keep hosting at EUR 0. Prepare restricted cloud deployment only when billing, a concrete budget and operational controls are authorized; the company project shell is already available.
  • Qualify purchase and external token-trading routes, Google Play's paid randomized-NFT restriction and Apple's NFT functionality restriction before commercial integration. No sale, liquidity pool, fiat redemption or public chain deployment is active.
  • Implement and verify Android/iOS clients sharing the same authoritative worlds, protocol, inventory and economy. Cross-play is confirmed; cross-save and device migration remain separate decisions.
  • Transfer local NFT-### work records into hosted issues once a repository host is selected, run hosted quality checks, and later qualify macOS/Xcode for iPhone builds.

2026-09-06 · Website and planning release

0.10.0 — Immutable item sources and shared ownership components

Published record

New domain components preserve a sealed base's original source separately from its current owner and quantity. Combined tests transfer a base, release its simulated receipt and resolve buyer-owned mint inputs without changing the source or recreating consumed items. A single funded coordinator and durable shared service remain integration work.

Added

Added in 0.10.0

  • An immutable sealed-base registry keyed by the existing item identity, preserving visible level, versioned source and template, and private hidden potential through ownership changes. Deep copies and original-state checks prevent source replacement.
  • A shared ownership component with separate state and transfer revisions, typed trade and mint reservations, permanent consumed identities and tradeable positive material remainders.
  • Mandatory restoration against pinned original genesis and actual canonical inventories, reconciling current entries, exact reservation histories and terminal evidence before returning an authority.
  • Combined domain conformance checks for transfer, pending receipt, buyer-owned materials, fixed synthetic generation, success/failure disposition, original retries and restored source identity.
Security

Security in 0.10.0

  • Private source inputs stay out of public item projections and transfer commitments. Actual inventory reservation and event evidence are required for live mint disposition; a claimed outcome or matching-looking snapshot cannot substitute.
  • Compact typed terminal evidence and protected history capacity are checked against saturated inventory and ownership histories, avoiding repeated copies of full inventory history.
  • Released mint and exchange fixture readers remain unchanged. The new components do not merge their balances, authenticate economic actions, submit blockchain work or confirm usable NFTs.

2026-09-06 · Website and planning release

0.9.0 — Signed local device actions and protected receipt access

Published record

Preregistered test characters can now sign a one-use local acknowledgement and later read its original receipt with fresh proof. Signature verification, revocation and protected history are tested together. This foundation remains separate from player enrollment, native mobile keys, wallet signing and economic consent.

Added

Added in 0.9.0

  • A pinned public-key manifest and separate demonstration client keys for two synthetic character associations. HTTP callers cannot enroll a key, claim another character or replace a credential.
  • A versioned P-256 signed-action transcript that binds the local audience, character, purpose, resource, operation, credential epoch, payload and expiry, with strict key and signature encodings.
  • One-use acknowledgement and signed receipt-read workflows, original proof preservation, trusted revocation and expiry, finite protected history and cryptographic revalidation during restoration.
  • An opt-in local identity API with encrypted PostgreSQL state, permanent identity claims and atomic audit/outbox records. Independent API processes verify the same authority before committing a result.
Security

Security in 0.9.0

  • Current credential activity and a valid, unexpired signature are required before exposing a private original receipt. After expiry a fresh signed read retrieves the same result without granting new authority.
  • Wrong signatures do not consume another challenge or occupy its operation ID. Changed manifests, replaced state keys, conflicting associations and tampered stored evidence fail closed without reseeding.
  • Device private keys stay outside server state; wallet keys and platform attestation remain separate. These signatures authorize only synthetic acknowledgements, not minting, trading, treasury operations or general login.
Fixed

Fixed in 0.9.0

  • Aligned development launch profiles and prior integration harnesses so the new optional identity routes cannot be enabled by inherited test configuration.
  • Removed stale internal documentation exceptions that suggested ordinary items could silently become NFTs or that project charges could burn tokens.

2026-09-06 · Website and planning release

0.8.0 — Whole-item exchange with frozen merchant fees

Published record

A local two-player fixture now trades sealed bases and ordinary stacks without changing their identity or level. Inventory, funded payment and treasury fees settle once, while received items wait for an explicitly simulated receipt. This is tested backend infrastructure, not a public marketplace or real-value sale.

Added

Added in 0.8.0

  • A two-inventory exchange coordinator with immutable price and merchant-skill fee quotes, protected outgoing items, reserved receiving capacity, exact seller consideration and treasury charges.
  • A persistent ownership directory that distinguishes item departure from consumption or merging, preserves identity through return sales and rejects quest items and unsupported NFT settlement paths.
  • An opt-in loopback exchange API with encrypted PostgreSQL state, global fixture identity guards, atomic audit/outbox records and a deduplicated simulated receipt inbox. No caller-provided transaction hash proves completion.
  • Domain, store, HTTP and two-process database checks cover return trades, whole stacks, original retries, competing settlement and cancellation, overspending, restarts, forced-write rollback and tampered receipt records.
  • Historical inventory-schema compatibility verified against a fixture generated by the actual tagged 0.7 domain assembly, including finalized and pending mint reservations and their original receipts.
Fixed

Fixed in 0.8.0

  • A valid-length replacement encryption key now blocks new fixture creation beside inaccessible existing history in both the mint and exchange stores.
  • Public receipt requests are reconciled against their message and operation identities, event schema, settlement time and blinded payload; missing or changed records fail closed.
  • Development launch profiles and integration harnesses explicitly isolate optional exchange routes, and the documented PostgreSQL startup command now selects the correct launch profile.
Security

Security in 0.8.0

  • Received items remain unavailable while receipt work is pending. Local confirmation is marked as simulation throughout and does not claim public-chain finality or production player authentication.
  • Private provenance and commitment blinding stay inside authenticated state. Protected terminal history capacity allows valid settlement, cancellation and receipt release despite command saturation.

2026-09-06 · Website and planning release

0.7.0 — Atomic mint settlement and merchant-skill fee quotes

Published record

A valueless local economy now connects inventory, funded currency and mint generation in one durable workflow. Exact costs and losses are quoted before commitment, fees return to the treasury, and retries preserve one result. Generated items remain pending chain confirmation; this does not launch a game, token sale or marketplace.

Added

Added in 0.7.0

  • An opt-in local quote, commit and resolve API with server-owned minter profiles, visible base levels, frozen success/failure terms and no client-selected entropy, recipe or fee recipient.
  • Atomic base/material reservations, partial currency capture and release, one permanent attempt per committed base, and generated candidates that cannot become usable equipment before later chain reconciliation.
  • Encrypted PostgreSQL economy snapshots, independent storage revisions, permanent relational identity guards, original creation and command receipts, and transactional audit/outbox writes without automatic history expiry.
  • Versioned trading/merchant-skill fee quotes with the shared 100-point cap, exact integer rounding, configurable floors/caps, buyer/seller payer modes, expiry and a frozen reference vector. Full item-market settlement and production rates remain open.
  • A local encryption-key preparation helper, dedicated economy launch profile, adapter runbook, ADR-0017, portable HTTP checks and a disposable two-process database fault suite.
  • The complete notice for the website's pinned jQuery dependency and reproduction instructions, preserving its existing license and project licensing boundaries.
Fixed

Fixed in 0.7.0

  • Protected terminal command capacity so rejected requests cannot strand committed mint or inventory/currency reservations; older mint-attempt schema versions fail explicitly instead of being reinterpreted.
  • Preserved rollback when a later reservation or storage write fails, including when an API process exits inside a transaction. Restored rejected commands cannot become accepted after later state changes.
  • Bound encrypted storage revisions independently from accepted gameplay revisions and normalized database timestamps, preventing older-history replay and timestamp-precision recovery failures.
Security

Security in 0.7.0

  • Authenticated private state with a separately provisioned local AES-GCM key. Missing, replaced, inaccessible or invalid keys fail closed without generating new balances or overwriting the key.
  • Kept hidden generation inputs and entropy out of HTTP results, ordinary logs, relational claims and outbox payloads. Production excludes the local routes even when the feature flag is enabled.

2026-09-06 · Website and planning release

0.6.0 — Level-bounded minting and unified inventory foundations

Published record

Local domain components now model the inventory and template-driven mint attempt, including visible levels for tradeable sealed bases. Wallet and contract proofs enforce the currency-versus-item transfer boundary. This is engineering delivery and aligned product documentation, not a playable mobile release or real-value asset service.

Added

Added in 0.6.0

  • Canonical inventory classes, stack consumption/splitting/merging, quest binding, unique equipment identities, visible item levels, exclusive locks, immutable audit deltas and original retry receipts.
  • A pure versioned generator with source-level template bands, independent base-level quality gates, minter level/skill influence, weighted distinct affixes, bounded integer statistics, procedural names and cryptographic commitments. A frozen reference vector checks future algorithm compatibility; fixture values are not production balance.
  • Committed mint attempts with frozen inputs, private entropy, disclosed reservation/loss references, one recorded success or failure, owner-versus-specialist separation, bounded command history and validated snapshot restoration. Emitted consumption and candidate records remain pending coordinator work, not charges or confirmed NFTs.
  • An ephemeral local-chain wallet proof with a generated address, signed ERC-20 transfers, pinned chain/contract identity and a consistent-block asset view. Signing refuses public networks and does not expose or persist private keys.
  • ADRs 0013–0016 for Android/iOS cross-play, independent device and asset boundaries, the local template-generation prototype and recycling system charges to the project treasury.
Changed

Changed in 0.6.0

  • Confirmed one inventory for currency, minted equipment, sealed bases, consumables, materials, bound quest items and stacks such as arrows. Only currency may transfer to external wallets; item NFTs remain usable and tradeable inside NFTerra.
  • Confirmed mob equipment drops require successful currency-funded minting before use. Ordinary consumables, ammunition, materials and quest items retain their normal rules. Sealed bases remain tradeable and retain their server-assigned level; an expert cannot mint low-level bases into high-level equipment.
  • Recorded Android/iOS shared-world play as a requirement, with Android first and native differences behind adapters. Device registration uses cryptographic keys and server verification; IMEI is not a wallet seed or account credential.
  • Confirmed that game-system charges and project trade fees return existing tokens to the Yasa-owned treasury for approved resale inside or outside the game. Peer consideration goes to its seller. Trading/merchant skill influences trade fees, with exact rates and curves still open; these charges do not burn tokens or expand supply.
  • Made live website, changelog and matching specifications the explicit first lookup when development is uncertain, and aligned the inventory, economy, minting and technology explanations.
Security

Security in 0.6.0

  • Restricted local NFT mint recipients and transfers to approved game wallets and consented internal settlement, including ordinary ERC-721 transfer entry points; added role separation, revocation, pause and rollback checks.
  • Updated repository development-tool dependencies and compatible transitive packages to clear reported npm audit findings. Contract TypeScript is checked strictly alongside the local behavioral suite.

2026-09-06 · Website and planning release

0.5.0 — Durable backend transactions and exact currency denominations

Published record

Local backend systems now preserve synthetic purchases and retry history across restarts, and currency arithmetic follows the confirmed billion-token cap with Gold, Silver, Bronze and Copper units. Android environment checks and a company Cloud project advance the tooling foundation; no public game or real-money service is released.

Added

Added in 0.5.0

  • An asynchronous session-store boundary and pinned EF Core/Npgsql PostgreSQL adapter with row locks, versioned aggregate snapshots, atomic audit/outbox writes and minimized unavailable-store responses.
  • A synthetic material purchase endpoint with server-owned catalogue prices, integer test Copper, one receipt per operation and proof against concurrent duplicate charges or grants.
  • Exact denomination parsing, formatting and arithmetic with three decimal places, hard-cap checks, and local ERC-20 cap and transfer tests.
  • A separate in-memory funded currency ledger component with explicit initial allocation, transfers, reservations, fixed recipients, commit/cancel terminal states, exact retries and immutable audit deltas. It is not yet connected to the API, database or blockchain.
  • Android client pending-request storage across restarts, replay reconciliation, test shop display, and emulator start/reuse and ADB-to-API health-check commands.
  • A disposable two-process PostgreSQL suite covering restart recovery, concurrent purchases, conflicting requests, insufficient funds, forced transaction rollback and corrupt/unavailable storage.
  • ADR-0012 and aligned specifications for the supply ceiling, denominations, intended distribution channels and external fiat-provider boundary.
Changed

Changed in 0.5.0

  • Prioritized underlying backend and currency systems while deferring reward rates, mobs and content design.
  • Created yasa-nfterra-development under the existing authorized Yasa company Google account and organization. Hosting is limited to EUR 0; no paid billing or hosted service was enabled.
  • Recorded Uniswap on Polygon as an external trading candidate, distinct from the NFTerra item marketplace, and documented provider/store qualification before real value.
Fixed

Fixed in 0.5.0

  • Prevented database outages wrapped by EF Core from escaping as development exception pages; requests receive a minimized 503 and never fall back to fresh memory state.
  • Refreshed current client state after replaying an original command receipt, avoiding stale inventory and movement sequence after other session activity.
  • Aligned current supply statements with the confirmed one-billion-token ceiling and explicitly recorded the Google Play commercial randomized-NFT launch conflict.

2026-09-06 · Website and planning release

0.4.0 — Android-first local technology foundation

Published record

Implementation begins with a prepared Unity Android client, tested .NET development API, local data services, and simulated-chain currency and NFT candidates. This records local engineering delivery, not a released Android game or public blockchain deployment. Commercialization is deferred.

Added

Added in 0.4.0

  • A .NET 10 API with independent domain/application assemblies, synthetic movement and gathering, bounded sessions, audit events, and tests for validation, concurrency, retries, and development-route isolation.
  • A Unity Universal 2D Android source project, development-only client/server harness, reproducible template preparation and ARM64 IL2CPP build entry point, plus a separate reference-assembly compile check.
  • Digest-pinned local PostgreSQL/PostGIS and Redis services, generated private credentials, loopback bindings, foundation migration history, outbox/inbox/audit scaffolding, and disposable recovery verification.
  • Pinned Hardhat 3.15.0, Solidity 0.8.28 and OpenZeppelin 5.6.1 tooling with local-only development ERC-20 and ERC-721 candidates and 13 passing invariant tests.
  • A repository-local NFT-### work register, technology implementation guide, root development commands, and backend/contract checks in the quality workflow.
Changed

Changed in 0.4.0

  • Moved the local project status from implementation planning to Android-first foundation implementation while preserving the full product boundaries and separate commercialization stage.
  • Documented actual limitations: Unity APK generation is blocked by inactive entitlement, the API remains in memory, and real map, wallet, chain reconciliation, marketplace and DAO integration are not delivered.
Fixed

Fixed in 0.4.0

  • Recovered Docker Desktop from inaccessible stale inference and Secrets Engine runtime sockets by preserving and replacing only their stopped runtime directories, without deleting existing databases or volumes.
  • Aligned the minting-page illustration and open-decision copy with the already selected Polygon ERC-721 standard.

2026-07-16 · Website and planning release

0.3.6 — Starting-class discovery and loadout art

Published record

The Characters dropdown now exposes the complete starting-class catalogue and all five class pages alongside the race catalogue. The classes page has five dedicated loadout studies, and every class detail page now leads with artwork for its actual opening equipment rather than repeating a generic skill-system image.

Changed

Changed in 0.3.6

  • Expanded the Characters dropdown with a distinct Starting loadouts group, a View all route, and direct links to Archer, Wizard, Fighter, Builder, and Harvester on desktop and mobile.
  • Rebuilt the starting-class catalogue as five illustrated loadout cards that name each profession theme, opening items, and dedicated detail route.
  • Replaced the repeated generic class-detail hero and social image with class-specific responsive artwork and Open Graph presentation.
Added

Added in 0.3.6

  • Five coherent rain-dark concept studies depicting the practical Archer bow and quiver, Wizard staff and ritual focus, Fighter sword and helmet, Builder hammer, and Harvester hoe and seed pouch.
  • Full, 960-pixel, 640-pixel, and social-image derivatives for every class, plus retained generation sources, prompt provenance, and reproducible ImageMagick commands.
  • Automated presentation assertions requiring the all-classes route, five individual class links, five illustrated cards, class-specific detail art, and accessible image descriptions.
Fixed

Fixed in 0.3.6

  • Removed the navigation imbalance that exposed every race but reduced all five starting classes to one visually secondary link.
  • Removed generic skill-web artwork from class pages where it failed to show the selected opening loadout.
  • Kept every illustration within the confirmed item-only class boundary: the art conveys equipment and setting without implying skills, bonuses, abilities, or permanent professions.

2026-07-16 · Website and planning release

0.3.5 — Bounded technical and system diagrams

Published record

The technology-stack illustration has been rebuilt as a legible three-stage architecture diagram, and every website image has been reviewed for text, artwork, and responsive overflow. Three additional SVG layout defects found during the sitewide audit are corrected, with an automated bounds check added to the normal quality workflow.

Changed

Changed in 0.3.5

  • Rebuilt the selected technology stack around three clearly separated stages for the native Android and iPhone client, authoritative Google Cloud game world, and guarded Polygon ownership rail.
  • Replaced connector captions embedded beneath later panels with unambiguous bidirectional arrows and moved authority boundaries into a dedicated full-width summary band.
  • Refined the ecosystem mindmap, geographic concept map, and shared skill-budget diagram with wider cards, shorter copy, and contained result columns.
Added

Added in 0.3.5

  • A headless-browser regression check that renders every website SVG at its intrinsic viewBox and fails when graphics leave the canvas, text escapes its nearest card, or later artwork occludes text.
  • A sitewide visual inventory covering all text-bearing SVG diagrams and text-free raster explanatory images, plus responsive page checks at narrow mobile through desktop widths.
Fixed

Fixed in 0.3.5

  • Removed artwork crossing the Unity stack label and split the PostgreSQL/PostGIS heading so both remain inside their cards.
  • Contained the ecosystem center title and settlement heading, geographic-map explanatory copy, and all three skill-budget result values within their intended panels.
  • Prevented the original technology diagram's connector labels and other elements from disappearing beneath adjacent architecture panels.

2026-07-16 · Website and planning release

0.3.4 — Development truth and executable roadmap

Published record

NFTerra's internal product and development records now match the current public concept while separating the full intended game, the narrower valueless first playable, and the foundation work that is actually delivered. The roadmap now identifies current blockers, immediate execution order, and concrete work for every major published system.

Changed

Changed in 0.3.4

  • Converted the mostly blank project intake into a resolved current-truth snapshot covering product, location, characters, economy, ownership, technology, operations, compliance, and the decisions that genuinely remain open.
  • Added a current execution snapshot and public-concept-versus-milestone boundary to the development plan, with backend work intentionally able to proceed while Unity, Google-owner, and macOS/Xcode gates are unresolved.
  • Clarified the first playable as a valueless economy validation rather than a non-economic build, and required any prototype race or starting-loadout subset to preserve the published no-bonus and item-only rules.
  • Aligned the development handbook's authority order with the mandated website and structured-changelog source-of-truth workflow.
Added

Added in 0.3.4

  • A delivery-state matrix that distinguishes the deployed website and local quality tooling from the unscaffolded Unity client, backend, data services, contracts, chain adapters, and playable systems.
  • Issue-ready backlog items for race identity, starting loadouts, mint resolution, procedural generation, specialist escrow, post-mint work, economy simulation, Polygon contracts, ERC-4337 integration, reconciliation, marketplace settlement, public receipts, mage-assisted restructuring, territory, totems, fees, siege, and location partners.
  • Character-creation, device-identity, race-bonus, and starting-loadout invariants to the testing strategy and truth-surface requirements to the Definition of Done.
Fixed

Fixed in 0.3.4

  • Removed stale architecture language that treated the blockchain standards and wallet integration family as undecided after Polygon, ERC-20, ERC-721, ERC-4337, and thirdweb had already been selected as the guarded baseline.
  • Removed blank intake prompts for decisions already answered by the website, requirements, or accepted ADRs while retaining unresolved balance, delivery, safety, custody, legal, and launch questions.
  • Prevented the complete public product vision from being mistaken for either implemented functionality or mandatory first-playable scope.

2026-07-16 · Website and planning release

0.3.3 — Character-first race and class heroes

Published record

The race and starting-class catalogues now lead with the identity, story, and possibility players are choosing rather than using unresolved design decisions as sales headlines. Approval and rules boundaries remain visible in their dedicated status sections.

Changed

Changed in 0.3.3

  • Reframed the race hero around choosing a people and carrying its story into the world, with concrete facts about six origins, the shared skill system, and earned professions.
  • Reframed the starting-class hero around choosing how a character begins and earning who they become through action and finite skill choices.
  • Moved approval and limitation language out of promotional hero badges and facts while preserving the exact race-bonus and class-item boundaries in the status strips and explanatory sections below.
Added

Added in 0.3.3

  • A dedicated five-adventurer class-catalogue scene showing the Archer, Wizard, Fighter, Builder, and Harvester opening loadouts with practical starter equipment.
  • Responsive WebP and Open Graph derivatives for the new class art, with source provenance and reproducible ImageMagick commands.
  • Automated regression checks that reject approval-process language in race and class hero titles while confirming the rules remain explicit elsewhere.
Fixed

Fixed in 0.3.3

  • Removed process-led race headline language such as origins being 'in design' from the primary page promise.
  • Replaced the generic skill-system diagram on the class catalogue with art that actually depicts its five starting loadouts.
  • Separated compelling character fantasy from honest product-status disclosure instead of making unresolved choices the visual headline.

2026-07-16 · Website and planning release

0.3.2 — Official project footer and trust directory

Published record

NFTerra's sitewide footer is now a structured project directory and transparency surface: it identifies the Finnish operator, reports the current website release and development phase, separates product areas and enquiry audiences, and makes the absence of a live game or public token/NFT sale unmistakable.

Changed

Changed in 0.3.2

  • Replaced the long mixed Explore column with four distinct directories for discovery, economy and ownership, organizations and world systems, and contact and public records.
  • Reframed the project introduction around real geography, specialist skills, tradeable loot, player-created NFT equipment, NFTerra cryptocurrency, and a persistent player economy.
  • Elevated YASA LTD / Yasa Oy from a passive address column to the clearly labelled official project operator with its published business identity, Helsinki address, parent-company website, and project email.
Added

Added in 0.3.2

  • A public project-record panel that reads the current website version, update date, and development phase from the canonical structured changelog.
  • Explicit no-playable-build and no-public-sale status statements, plus an anti-impersonation warning against unsolicited wallet connections or fund transfers.
  • Specialized player, business-partner, investor, and general-contact routes alongside dedicated privacy, risk, security, and changelog links.
  • Automated footer assertions covering public status, sale boundaries, official operator identity, categorized navigation, specialized enquiries, and legal/security routes.
Fixed

Fixed in 0.3.2

  • Removed overlapping and weakly categorized links that made the previous footer harder to scan and less authoritative.
  • Clarified that the displayed release is the public website record rather than a playable game release.
  • Replaced vague trust presentation with factual operator, status, legal, security, and release-record evidence.

2026-07-16 · Website and planning release

0.3.1 — Race navigation and origin concept art

Published record

NFTerra's six current race directions are now directly discoverable from the Characters header menu and presented through one coherent dark-fantasy concept-art set with clearly labelled working origins.

Changed

Changed in 0.3.1

  • Replaced the generic character-system diagram on the race catalogue and detail heroes with an ensemble scene and a distinct environmental portrait for every race.
  • Expanded the race catalogue and detail pages with origin names, environmental stories, and visual signals while identifying all of them as working narrative direction rather than approved canon.
  • Aligned the canonical character and requirements documentation with the illustrated race-origin directions and the existing no-bonus boundary.
Added

Added in 0.3.1

  • An accessible Characters dropdown linking the character overview, all-races catalogue, every individual race page, and starting-class catalogue on desktop and mobile.
  • A unified seven-image source set covering the six race origins and their shared catalogue scene, plus responsive WebP and Open Graph derivatives.
  • Automated presentation assertions for race navigation, race artwork, working-origin language, and the continued absence of approved gameplay bonuses.
Fixed

Fixed in 0.3.1

  • Removed the flat navigation structure that hid race subpages behind the general Characters page.
  • Removed the repeated generic diagram that made every race page look identical and failed to communicate the races' appearance or origins.

2026-07-16 · Website and planning release

0.3.0 — Cooperative DAO systems for guilds and towns

Published record

NFTerra's DAO direction now reflects the needs of successful guilds and towns: shared assets and ownership rights, contracts, escrow, proposals, voting, distributions, settlement operations, and auditable execution without transferring authority over game rules.

Changed

Changed in 0.3.0

  • Replaced the market-only DAO page and defensive hero with a cooperative organization model built around owning, contracting, and deciding together.
  • Aligned the homepage, nutshell, guild, territory, economy, technology, terms, navigation, and footer language with the broader guild-and-town DAO purpose.
  • Updated the canonical product, trading, organization, territory, system-context, wallet, legal, security, requirements, backlog, and contributor documentation to use one consistent authority model.
Added

Added in 0.3.0

  • A responsive DAO operating-model diagram connecting member rights and shared custody to proposals, voting, contracts, escrow, server validation, and reconciled outcomes.
  • Explicit personal, collective, share-defined, escrowed, and operated-world ownership classes, plus a worked example of a collectively funded town forge.
  • ADR-0011 and later-backlog items for organization rights, custody, contracts, escrow, voting, and settlement-governance implementation.
  • Automated assertions that preserve the cooperative DAO capabilities and reject the obsolete market-only hero and shared-ownership exclusion.
Fixed

Fixed in 0.3.0

  • Removed language that incorrectly presented shared ownership as unapproved or reduced DAO systems to a narrow catalogue of market actions.
  • Clarified that explicit organization ownership and economic rights are planned while membership and deposits never silently create equal, transferable, or yield-bearing shares.
  • Preserved the game-authority boundary: guild and town governance may operate budgets and valid requests, but land control remains non-NFT server state.

2026-07-16 · Website and planning release

0.2.6 — Homepage ownership and economy hero

Published record

The homepage hero now presents NFTerra's geographic MMORPG and its distinctive economic loop together: tradeable sealed loot, skill-shaped NFT minting, character inventory ownership, NFTerra cryptocurrency settlement, and bounded DAO coordination.

Changed

Changed in 0.2.6

  • Replaced the generic game-board headline with a clearer promise connecting real-world play to player-created ownership.
  • Rewrote the hero introduction and metadata to name NFTerra cryptocurrency, successful mint-created NFT equipment, the character inventory-wallet, and the player economy without implying that any service is already live.
  • Rebalanced the desktop and mobile hero layouts around a legible two-part presentation while retaining the planned Google Play and App Store availability badges.
Added

Added in 0.2.6

  • A linked ownership-loop panel showing the planned path from tradeable sealed loot through risky specialist minting and unique NFT creation to cryptocurrency-settled exchange.
  • A bounded DAO-enabled coordination callout and automated homepage assertions that preserve the currency, NFT, sealed-loot, and governance explanation.

2026-07-16 · Website and planning release

0.2.5 — Safer external and form-reference links

Published record

External website references now open in a separate tab without opener access, while the contact-form privacy notice preserves an enquiry in progress by opening separately.

Changed

Changed in 0.2.5

  • Every public link to an external website now opens in a new tab with safe opener and referrer isolation.
  • The privacy-notice link beside contact consent now opens separately so visitors can review the notice without navigating away from a partially completed form.
Added

Added in 0.2.5

  • An automated website assertion that rejects external links without new-tab and opener protection, plus a dedicated check for the contact-form privacy link.

2026-07-16 · Website and planning release

0.2.4 — Contact security hardening

Published record

The shared NFTerra enquiry form now uses Cloudflare Turnstile with mandatory server-side verification, while a sitewide security review strengthens request handling, session defaults, host redirects, browser policy, dependency checks, and release validation.

Added

Added in 0.2.4

  • A managed Cloudflare Turnstile challenge on the shared contact form used by player, partner, investor, developer, press, and support enquiries.
  • Automated website checks that require the widget, the server-side verifier, hostname and action validation, the required Content Security Policy allowance, and the absence of a production-style Turnstile secret from public source.
  • A repeatable security-review record covering the PHP surface, public dependencies, form controls, production headers, TLS, and dynamic application testing.
Changed

Changed in 0.2.4

  • The contact endpoint now caps request size, verifies each real submission through Cloudflare's fixed HTTPS Siteverify endpoint, and fails closed before database or email side effects.
  • Session handling now requires strict cookie-only session identifiers, while Apache redirects use the canonical NFTerra hostname instead of trusting an arbitrary Host header.
  • The Content Security Policy allows only Cloudflare's required Turnstile script and frame origin, and the privacy notice now discloses security-signal processing for bot prevention.
Security

Security in 0.2.4

  • Turnstile tokens are limited to Cloudflare's documented maximum length, single-use validation is delegated to Siteverify, and successful responses must match the configured NFTerra hostname and contact action.
  • The private Turnstile secret remains in excluded production configuration and credential storage; only the public site key is rendered to visitors.
  • Production dependency and browser-library scans found no shipped vulnerable packages; the local QA toolchain remains isolated from the deployed website.

2026-07-16 · Website and planning release

0.2.3 — Project identity and mobile service foundations

Published record

NFTerra now has a dedicated Google-service ownership model, isolated development and production project shells, and a verified project mailbox for enquiries, recovery, autoresponders, and YASA correspondence archiving.

Added

Added in 0.2.3

  • A dedicated Google owner account with the NFTerra domain mailbox attached for recovery and privacy-minimized activity defaults.
  • Separate nfterra-development and nfterra-production Google Cloud and Firebase project shells, with production Android and iOS app registrations using fi.yasa.nfterra.
  • The official Firebase Unity SDK 13.13.0 staged outside source control with an integrity hash and Analytics package ready for the licensed Unity bootstrap.
  • Incoming SiteGround forwarding to the YASA archive, automatic Bcc for sent webmail, and an operational platform-account ownership record.
  • Website autoresponder archiving for outgoing acknowledgement messages without exposing archive or account credentials publicly.
Changed

Changed in 0.2.3

  • The public contact, privacy, terms, footer, structured organization data, inquiry receiver, and autoresponder identity now use the dedicated NFTerra support address.
  • Google Cloud, Firebase, Maps Platform, and Play Console onboarding now share one project-owned Google identity while remaining separated by projects, IAM, billing, and release roles.
  • The mobile bootstrap now records Google provider review and Unity license activation as explicit gates before Firebase config import, Maps keys, or playable builds.
Security

Security in 0.2.3

  • Generated account credentials remain only in the excluded noshare credential store and are not copied into source control, public changelog data, screenshots, or operational documentation.
  • No billing profile, unrestricted API key, service-account key, store enrollment, or production signing credential was created during project provisioning.

2026-07-16 · Website and planning release

0.2.2 — Mobile store availability badges

Published record

The homepage hero now identifies Google Play and the App Store as NFTerra's planned mobile distribution channels without implying that either store listing or game build is available.

Added

Added in 0.2.2

  • Non-interactive Google Play and App Store badges in the homepage hero with explicit coming-soon labels.
  • Responsive badge styling and accessible text that preserve the planned-product boundary without placeholder store URLs.

2026-07-16 · Website and planning release

0.2.1 — Project source-of-truth workflow

Published record

NFTerra now treats its website and structured changelog as the development-facing source-of-truth presentation for current design, completed project work, and planned next work. A matching Codex skill enforces the same reading and reconciliation workflow.

Added

Added in 0.2.1

  • A current project-status block containing the active phase, delivered highlights, and next planned work in the canonical structured changelog.
  • A reusable NFTerra Project Workflow Codex skill that activates for NFTerra development, website, documentation, QA, release, and deployment work.
  • Public changelog presentation for what exists now and what the project plans to do next.
Changed

Changed in 0.2.1

  • The engineering and release workflows now require development questions and changes to begin from the relevant website page and structured changelog before consulting deeper specifications and implementation evidence.
  • Product, architecture, code, tests, website copy, current status, roadmap, and release history must be reconciled in the same scoped change whenever they would otherwise contradict.
  • The generated repository changelog now includes the same current status and planned-next-work presentation as the public page.

2026-07-16 · Website and planning release

0.2.0 — Race and starting-class catalogue

Published record

NFTerra's character section now contains dedicated catalogue and detail pages for six race directions and five starting classes. The release establishes that race bonuses remain unapproved and classes only select starting items.

Added

Added in 0.2.0

  • A race catalogue and individual pages for Human, Automaton, Atlantean, Felinor, Barbearian, and Otterfolk.
  • A starting-class catalogue and individual pages for Archer, Wizard, Fighter, Builder, and Harvester.
  • Character subpage links in the main character guide, global footer, and XML sitemap.
Changed

Changed in 0.2.0

  • Class language now consistently states that a class only chooses profession-themed opening items and grants no skills, experience, statistics, bonuses, affinities, abilities, or permanent profession lock.
  • Race language now separates legacy narrative themes from all gameplay bonuses, which still require explicit approval.
  • Product requirements and vision documentation now preserve the same race, class, and 100-point skill boundaries as the public website.
Fixed

Fixed in 0.2.0

  • Removed the previous suggestion that a starting class could grant an early affinity or other mechanical bonus.

2026-07-16 · Website and planning release

0.1.1 — Location partner proposition

Published record

The partner proposition now leads with putting verified businesses on the game map and turning local gameplay into real-world visits. This remains a planned programme; partner onboarding and campaigns are not live.

Added

Added in 0.1.1

  • Two proposed campaign-funding routes: supported NFTerra currency and a direct business-to-business agreement.
  • A clearer venue-to-map-to-visit campaign journey with privacy-thresholded aggregate reporting.
  • Explicit campaign options for earned-experience boosts, improved drop opportunities, encounters, recovery, resources, and events.
Changed

Changed in 0.1.1

  • The location-partner page now centers its business message on visible game-map placement, safe player visits, repeat traffic, and measurable campaign activity.
  • Partner documentation now distinguishes buying a bounded campaign opportunity from directly granting experience, creating items, choosing winners, or modifying player state.
  • The overview now links real-world venues directly to the full location-partnership explanation.

2026-07-16 · Website and planning release

0.1.0 — Development baseline

Published record

NFTerra now has an implementation-ready product, technology, and delivery baseline. This is a website and planning release; it does not represent a playable game, token launch, NFT sale, or live marketplace.

Added

Added in 0.1.0

  • A phased development plan with measurable exit gates from foundation through closed testing and real-value readiness.
  • A prioritized engineering backlog covering the initial mobile, backend, location, identity, skill, and loot work.
  • A Definition of Done, test strategy, engineering workflow, and release process for repeatable delivery.
  • A pull-request template and continuous repository quality workflow for reviewable changes.
  • A selected first-playable stack using Unity, native Google Maps and location services, .NET, PostGIS, Google Cloud, and Polygon adapters.
  • A pinned Unity 6.3 LTS Android development toolchain alongside the verified backend and native Android workstation stack.
  • A public changelog page backed by the same structured record as the repository changelog.
Changed

Changed in 0.1.0

  • Project status moved from open-ended technical discovery to pre-production implementation planning.
  • Public technology explanations now distinguish selected engineering choices from production security, custody, legal, and scale gates.
  • Guild and clan systems are explained separately from conquest, buildings, resources, local fees, totems, siege, and territory.
  • Character documentation now preserves one device-associated character and one shared 100-point budget across all skills.
Fixed

Fixed in 0.1.0

  • Removed stale wording that described the selected client, backend, database, hosting, and target chain as wholly undecided.
  • Corrected public explanations so sealed unminted loot remains tradeable while only successful minting creates the usable NFT.
  • Reduced over-promotion of secondary specialist mechanics and removed misleading numbered-system framing.
  • Versioned the web-app manifest URL so hosting cache revalidation cannot return an empty manifest to new browsers.

How this record works

One current status. One reviewed history.

The public page and repository changelog come from the same structured source. Automated checks fail if the generated repository record falls behind.

  • The status block presents the current phase, delivered highlights, and planned next work.
  • Versions use semantic versioning for completed releases.
  • Release entries never present future game systems as delivered.
  • Corrections remain visible through later patch releases.
  • Every website deployment includes backup, verification, and rollback evidence.