Skip to content

What's new

A factual summary of what has been built, by roadmap phase. The tracker (roadmap) holds the status of every item and the decisions record why. Items that are only partly done are marked as such there; this page lists what works.

  • A monorepo (api/, admin/, front/) with the 50 PHP packages vendored under api/packages and no escolalms/* dependency: Monorepo, API packages.
  • Laravel 13 on PHP 8.4 (with Passport 13 and a data migration for every tenant), and the recommender package removed.
  • Styling with CSS custom properties only; the shared component library @ulams/ui with a component playground in this site.
  • Multi-tenancy by host with one command to create, list and delete tenants: Tenancy, Tenants, First tenant.
  • H5P as a separate Node service, with the PHP H5P server removed: H5P for operators.
  • Security work: payment and Jitsi callbacks verified, LRS tokens verified, upload hardening, no committed secrets (Security); ulams:upgrade, one idempotent per-tenant upgrade command (Upgrades); a scheduler that runs each minute once even on several nodes (ADR 0068, Queues and scheduler).
  • Smaller admin and front images on unprivileged nginx (Images, Container images).
  • Demo mode with seeded admin, tutor and student users and an hourly reset: Demo mode.
  • This documentation site, the brand identity (Brand) and the CI that checks them (CI).
  • LiaScript topics with versions and a preview: LiaScript.
  • Adapt Learning: import a built package, and build from JSON source with an admin screen for sources, versions and build status: Adapt.
  • LTI 1.3, both as a platform (launch external tools, grade passback, deep linking, Names and Role Provisioning Services) and as a tool for Moodle or Canvas, with client-side OIDC through postMessage storage and monthly key rotation: LTI, LTI tools, LTI launch.
  • cmi5 with one-time launch tokens and playback from the content origin: cmi5.
  • Upload hardening and an isolated content origin for SCORM, Adapt, LiaScript and cmi5, with same-site cookie hardening, exact-Origin checks, sandboxing and a CSP that reports first and then enforces: Content origin, Security headers.
  • H5P multi-tenancy, learner state through a proxy, and cleanup of unused content: H5P, H5P for operators.
  • An LLM layer with a model per task chosen in configuration, validated structured output, prompt caching, per-call logging of model, tokens and cost, and hard limits: LLM layer.
  • Ingestion of PDF, Markdown and DOCX into source documents with stable fragment ids, treated as untrusted input.
  • An interview with defaults (“decide for me”), an editable course brief, then objectives, outline, lessons, quizzes and metadata that the author approves, each element citing its source fragments: Course builder, Administering the builder.
  • Element-level chat editing as reviewable patches, versions with diffs and undo, and live progress over an AG-UI event stream: Course builder API, Generative UI.
  • Long runs on dedicated queue connections with their own retry_after: Performance.
  • Sources that stay connected to a course: upload, URL and Git connectors, with change detection by webhook, poll or manually and a fragment-level diff.
  • Impact analysis through citations, update proposals reviewed as one diff, progress rules that keep completion on a minor edit, staleness signals, learner notices and an audit trail: Living Course (admin), Living Course (developers).
  • Inbound webhooks and their signatures: Webhooks.