← All Reports

Quotation Tool CRM
Development Updates

Servings-per-container now flows from Sales straight into the R&D Lab, the Supplement Facts preview gets macro toggles plus full Child Supplement support, component search returns sharper results, and stickpacks land across the Sample Spec and Master Product Specification - capped by a three-part security hardening push closing XSS, SQL injection, and email-header injection risks.

June 24 - 29, 2026

Section

New Features &
Enhancements

Servings per Qty flowing from Sales into the Lab, a clearer Supplement Facts preview with macro toggles and Child Supplement support, smarter component search, and full stickpacks support across the Sample Spec and Master Product Specification.

Major Enhancement

Servings per Container, Sales to Lab

  • Per-Tier Entry -- Sales can now enter Servings per Qty on each quantity tier in the product modal - Tier A required, Tiers B-D optional.
  • Auto-Fills the Lab -- When the quote moves to R&D, those values pre-fill the Lab Settings without overwriting anything R&D has already edited.
  • Shown in Summaries -- The Sales tab and Edit Product summaries now surface a Servings per Qty column for at-a-glance review.
  • Two-Way Sync -- Changing Containers per Work Order in R&D updates the matching Pricing rows, unless that row was already edited or deleted.
Sales Quoting Initial Data Intake modal (step 2, Composition Intent) for a Capsules quote, with the Quantity Tiers table showing a new SERVINGS PER QTY column circled in red - 1500 maps to 30, 2000 and 10000 to 30/60/90 - beside the QTY and NOTES columns and a Completion Date picker
R&D Edit Lab Settings dialog Container Configuration section with Tier A, B, and C rows, each pairing a Servings Per Container field (Tier A auto-filled to 30 from the Sales values, underlined red) with a Containers per WO field (1500, 2,000, 10,000), above the Servings & Format Details and Capsule Selection panels
Feature Update

Cleaner Supplement Facts Preview

  • Macros Toggle -- Macro rows (Calories, Fat, Carbs, Protein) are hidden by default for supplements and toggle on from the dialog footer; foods still show them by default.
  • Single %DV Column -- Only the 4+ years %DV column shows unless the product is flagged as a Child Supplement, in both the preview and the generated PDF.
  • Aggregated Claims -- Multiple source rows for the same nutrient - such as Magnesium Citrate and Magnesium Oxide - now roll up into a single label-claim line.
Supplement Facts Preview dialog for a 1-Capsule supplement (30 servings per container) showing macros hidden by default - just Vitamin D, Calcium, Magnesium, Sodium, Potassium with Amount Per Serving and a single % Daily Value (4+ YO) column - and a Show Macros toggle circled in red in the footer beside Download PDF and Close
Same Supplement Facts Preview after Show Macros is toggled on, now listing Calories, Calories from Saturated Fat, Total Fat, Saturated Fat, Trans Fat, Cholesterol, Total Carbohydrate, Dietary Fiber, Total Sugars, Includes Added Sugars, and Protein above the vitamins and minerals, still under the single 4+ YO %DV column, with a Hide Macros button in the footer
Feature Update

Child Supplement Support

  • New Service Type -- A Child Supplement service type can now be selected in the Sales tab Service Types alongside Bulk Products, Existing Formula, and the rest.
  • Age-Banded %DV -- Flagging a product as a Child Supplement expands the preview and PDF to show %DV columns for ages 0-1, 1-3, 4+, and Pregnant or Lactating.
  • Accurate Labels -- Children's products now generate the correct multi-column Daily Value breakdown required for their audience.
Edit Product modal (step 3, Choose Components & Service Type) for a Capsules product, with the Service Type checklist showing the new Child Supplement option checked and underlined in red, beside Bulk Products, Existing Formula, Label Design, Tolling/Semi-finish, Formulation, and Stability Testing, above a Plastic Bottle packaging selection and Additional Notes
Supplement Facts Preview for a Child Supplement showing four % Daily Value columns - 0-1 YO, 1-3 YO, 4+ YO, and Pregnant or Lactating - across the macro rows (Calories, Total Fat, Cholesterol, Total Carbohydrate, Protein) and vitamins/minerals (Vitamin D, Calcium, Magnesium, Sodium, Potassium), with Hide Macros, Download PDF, and Close in the footer
Feature Update

Sharper Component Search

  • Most-Relevant First -- Component search now returns the most relevant results for each slot - bottle, lid, neckband, scoop, and more - when first opened or auto-prefilled.
  • Broadens On Typing -- The result pool widens as soon as the user actively types a search, so nothing relevant is hidden once they start looking.
  • Consistent Across Tabs -- The R&D Lab and Sales/Pricing tabs now produce identical results for the same query.
Search Components modal with a search box and Search button above a paginated table of bottle and jar components - columns Part #, Description, Vendors, and Action - listing entries like B1236 8oz Black PET Plastic Single Wall Jar, B1190 625cc HDPE White plastic bottle, B1184 150cc Black HDPE Plastic Pill Packer, and B1183 143.5 White Blanket PP Tube (underlined red), each with a Select button and a page navigator at the bottom
Feature Update

Stickpacks: Sample Spec & Lab Settings

  • Full Stickpacks Support -- The Sample Product Specifications sheet and the Lab Settings dialog now fully support the stickpacks format.
  • Solvent & Flavor -- The Sample Spec modal shows Recommended Solvent, displays Flavor as a read-only value from lab settings, and omits the Aroma row.
  • Free-Text Solvent Qty -- Edit Lab Settings uses a free-text Recommended Solvent Qty input, which the stickpacks formulation header also displays.
Sample Product Specifications sheet for a stickpacks sample (Customer: test, Sample ID 26060901, Serving Size: Serving) with a Product Identification table whose first row is Recommended Solvent (Water (TestOnly), underlined red), followed by Powder Color (blacks) and a read-only Flavor (no) row, no Aroma row, above empty Product Properties and Ingredients panels, with Download PDF / Cancel / Save Settings
Feature Update

Stickpacks on the Master Product Spec

  • Powder Color & Flavor -- The Master Product Specification now correctly shows Powder Color and Flavor rows for stickpacks alongside Avg Weight/Fill and Weight/Fill Variation.
  • Instant Reflection -- Edits made in the Lab Settings dialog now appear in the MPS modal immediately, with no page refresh required.
Master Product Specifications sheet for a stickpacks product (Client: test, 26060901 - stickpacks, 3 stickpacks per container, 6 stickpacks per unit) with an Identification & Product Quality table listing Avg Weight/Fill, Weight/Fill Variation, Powder Color (black) and Flavor (no) rows - both underlined red, Organoleptic test method - above the Limits on Contaminants/Impurities heavy-metals section (Arsenic, Cadmium, Lead) and a Thiamine label-claim row
Section

Bug Fixes

The SP314425 film seal-template component is back in the product components list for film-format products.

Bug Fix

Missing Film Component Restored

  • Back in the List -- The SP314425 film seal-template component was missing from the product components list and could not be picked.
  • Selectable Again -- It can now be selected for film-format products, complete with its linked vendor pricing.
Select Product Component - Film dialog showing R# SP314425 for CannaLyte Hydration (Lemon Lime) Bulk Powder stickpack 52mm seal template, now selectable with one connected vendor - Litho-Flexo Grafics, Inc. at MOQ 3500, $0.2460 per Ea, PO Status Issued, dated Jun 23 2026 - and Remove Link / Cancel / Save controls, over a Product Components grid (Neckband, Case Box, Outer Case Box, Dessicant, Scoop, Lid, Label)
Section

Security Hardening

Three patches close real attack paths: stored cross-site scripting in Ingredient Request notes, SQL injection in the NIH CSV uploader, and email-header injection in the Send Quote dialog.

Security Patch

Cross-Site Scripting Fix in Notes

  • The Risk -- Hidden code pasted into Ingredient Request notes could silently run in another user's browser the moment they opened the request - potentially stealing their session.
  • The Fix -- Notes are now read in a way that ignores any code inside, so they render as plain, harmless text.
  • More To Come -- This is the first form to get the treatment; other free-text areas across the app are being reviewed for the same protection in upcoming updates.
Ingredient Request modal (Row Details Item #1, Pending) for R1040 Vitamin B1 Thiamin HCL, with a Request Notes field containing a malicious test payload - an img onerror script tag followed by bold 'Boom' and '(test script)' text - typed in to attempt cross-site scripting before the fix
Sourcing-side Ingredient Request view for the same Thiamine request (Quote QR-260608-001, Pending), where the Request Notes now render only the harmless plain text 'Boom' - the injected img/onerror script has been neutralized and never executes
Security Patch

SQL Injection Hardening: NIH Uploader

  • Allow-List Guard -- The NIH CSV uploader now clears only an explicit list of approved internal tables before importing data.
  • Defense In Depth -- This internal safety net stops any future change to the upload code from accidentally or maliciously targeting an unintended table.
NIH Data Sync screen explaining that uploaded CSV files populate the NIH tables and run through ETL automatically, with a table of four datasets - Company Information, Dietary Facts, Product Overview, Other Ingredients - each offering a Select CSV upload, a Pending status badge, and a Run action button
Security Patch

Email Header Injection Fix: Send Quote

  • Validated Fields -- The Compose Quote Email form now validates the To, CC, and Subject fields before sending.
  • Capped & Cleaned -- Invalid addresses are rejected, the CC list is capped at 10 recipients, and subjects containing hidden line breaks are blocked.
  • No Hidden Recipients -- This prevents attempts to inject hidden BCC recipients or other email headers through the Send Quote dialog.
Compose Quote Email dialog with a To field (test@example.com), an optional CC field, a Subject reading 'Final Quotation QR-260616-006 - Vitalpax Inc.', and a rich-text Body editor with bold/italic/underline and list controls, plus Edit Template, Cancel, and Send buttons - the form whose To/CC/Subject inputs are now validated against header injection

What We Shipped

5 Features & Enhancements
1 Bug Fix
3 Security Patches

Servings per Qty now flows from Sales into the R&D Lab, the Supplement Facts preview gained macro toggles and full Child Supplement support, component search returns sharper and more consistent results, and stickpacks landed across the Sample Spec and Master Product Specification - while a three-part security push closed cross-site scripting, SQL injection, and email-header injection risks and one fix restored the missing film seal-template component.