MMashDiv

Forex Investment 6.2.3

1 October 2026

This release has upgrade notes. Read them before updating — they describe behaviour changes that need your attention.

INVESTMENTSREFUNDSSTATUSADMIN API

Forex Investment v6.2.3

Release Date: October 1, 2026 Tags: INVESTMENTS, REFUNDS, STATUS, ADMIN API

Overview

An investment's principal could be paid twice. An admin could set a cancelled, rejected or completed investment back to ACTIVE from the edit dialog, and settlement then paid it out again on top of the refund or payout already received. Four more routes to a double payment or a lost principal, reachable only through the API, are closed with it. Status changes are now limited to ending an active investment, which always returns the principal.

If you ever cancelled investments through the admin API, read Upgrade Notes before using Recover.

Requires Core v6.8.2 only for the plan page's pinned panel, which follows a header measurement Core 6.8.2 defines; the investment changes need nothing new.

Update Instructions

pnpm updator

No schema change, no seeder, no .env change.


Upgrade Notes

Investments cancelled through the API before this update

This applies only if you, or a script, cancelled investments through the admin API's per-investment status endpoint (PUT /api/admin/forex/investment/:id/status) before updating. The admin panel never used it.

  • Do not run Recover (POST /api/admin/forex/investment/recover) on those investments. They carry no record of the refund they were paid, and the update does not add one, so Recover would re-activate them without taking it back.
  • Nothing lists them. If you kept the backend's console output, each such cancel wrote a FOREX_INVESTMENT_REFUND line ending Idempotency key: forex_investment_refund_<id>.

Status changes an admin can no longer make

  • The edit dialog now refuses any status change other than ACTIVE → CANCELLED or ACTIVE → REJECTED, with the reason. Marking an investment COMPLETED by hand — which paid nobody and left the principal unreturnable — is refused: settlement completes an investment. A cancelled investment returns to ACTIVE only through Recover, which takes the refund back first; there is no button for it.

Fixed

A principal could be paid twice

The edit dialog could reach the first and the last of these; the others needed the API to be called directly.

  • Fixed the edit dialog letting a cancelled, rejected or completed investment be set back to ACTIVE, after which settlement paid it out again on top of the refund or payout already received.
  • Fixed an investment cancelled through the per-investment status endpoint and then recovered being paid its principal twice: the endpoint refunded without recording it, so Recover took nothing back. It now records the refund, as the edit dialog already did.
  • Fixed an investment its owner had cancelled through the API being paid again after an admin restored it. Recover now refuses it, and an admin cancel or reject refuses to refund a principal that already went back to the owner's wallet.
  • Fixed the admin API's investment create accepting a status other than ACTIVE, which took the principal and never returned it. Any other status is now refused.
  • Fixed the edit route saving its other fields when the status change failed, and, through the API, refunding the new owner when the owner and status changed in one request. The status now moves first.

The plan page's pinned panel

  • Fixed the pinned side panel on the plan page slipping under the taller "Stacked" header; it now follows the header's actual height.