Client Version Compatibility
Handle the tab that has been open since two deploys ago.
What it adds
The server tells the client which build it expects, and the client responds — quietly for an optional update, insistently when the old code can no longer talk to the API.
What your agent is told to do
7
What your agent is told to do
7-
1
Stamp every build with a version identifier and return it on API responses, either in a header or a small metadata endpoint. The client compares it against the version it was built as.
-
2
Separate two cases and treat them differently. A newer build being available is an optional update — offer it and let the user finish what they are doing. An API contract the running client cannot satisfy is a hard incompatibility and must block further writes.
-
3
For an optional update, show an unobtrusive, dismissible prompt and apply the new version at the next natural navigation. Do not interrupt.
-
4
For a hard incompatibility, block with an explanation of what happened and a reload action. Say the app updated; do not show a version string or an API error as the primary message.
-
5
Never reload while unsaved work exists. Detect dirty forms and in-flight requests, tell the user what will be lost, and give them a chance to save or copy it out.
-
6
Do NOT reload automatically on a timer or on a failed request. A reload loop against a stale asset host is indistinguishable from an outage to the user.
-
7
Data-age display, freshness labels, and manual data refresh are owned by Stale Data Indicator. This feature is about the code being old, not the data — do not build a second freshness surface.
Edge cases it handles
7
Edge cases it handles
7- Several tabs may run different versions. Broadcast the detection between them so the user is not prompted separately in each, and do not reload a background tab silently.
- A cached HTML shell or service worker can serve the old build after a reload, producing a loop. Bound the reload attempts, and clear or update the service worker before reloading.
- A rollback means the server version goes backwards. The client must treat a mismatch as a mismatch in either direction rather than assuming newer is always ahead.
- During a rolling deploy, requests alternate between old and new servers. Do not raise a hard incompatibility on a single mismatched response — require it to persist.
- Version checks must not add a request per API call. Read the header already coming back on normal traffic rather than polling.
- The check itself failing — offline, blocked, no header — must be silent. An unknown version is not an incompatible version.
- A user who dismisses an optional update must not be re-prompted every few minutes; back off, and only escalate if the update becomes mandatory.
Definition of done
9
Definition of done
9- Every build carries a version identifier the client can compare against the server's.
- Optional updates prompt unobtrusively and can be dismissed; breaking incompatibility blocks writes with an explanation.
- No reload occurs while unsaved work or in-flight requests exist without a warning.
- Multiple tabs coordinate detection and background tabs are not reloaded silently.
- Reload attempts are bounded and stale service workers are cleared before reloading, so no loop occurs.
- A rolling deploy does not trigger a false hard incompatibility.
- A failed or unavailable version check is silent to the user.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Upload Malware Scanning
Upload Malware Scanning
Quarantine uploaded files until they are known safe.
What it does
A quarantine lifecycle for uploads: every new file is unreachable until scanned, with defined handling for scanner failures and infected results.
How it works
- 1 Give every upload an explicit scan state — pending, clean, infected, or error — and default it to pending the moment the bytes land.
- 2 Make pending and infected files unreachable from every access path in the app, including admin views, previews, thumbnails, and any signed URL. A quarantine with one exception is not a quarantine.
- 3 Scan asynchronously and update the state; do not block the upload request on the scanner.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/upload-malware-scanning
Rate Limiting
Rate Limiting
Stop one client from ruining it for everyone.
What it does
Throttling on the endpoints that get abused: auth, search, exports, and public forms.
How it works
- 1 Identify the endpoints worth protecting: sign-in, sign-up, password reset, search, exports, and anything unauthenticated.
- 2 Limit by a stable identifier — user ID where signed in, IP otherwise. Be aware IP is shared behind NAT and proxies.
- 3 Return 429 with a Retry-After header. Do not silently drop the request.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/rate-limiting
Password Generator
Password Generator
Offer a strong password in one click wherever someone sets or changes credentials.
What it does
A generate control on password fields that produces a strong value, shows it, and hands it to the user safely.
How it works
- 1 Add the control to every place a password is set: sign-up, password change, password reset completion, and any admin screen that provisions credentials for someone else.
- 2 Generate the value in the browser using the platform's cryptographic random source. The value must never be produced on the server or sent anywhere.
- 3 Reveal the generated password by default so the user can record it, and offer a regenerate control beside it. A hidden generated password that the user cannot see is a password they will immediately reset.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/password-generator
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.