Change Log
All notable changes to this project will be documented in this file. See Conventional Commits for commit guidelines.
4.0.0-beta.5 (2026-10-08)
⚠ BREAKING CHANGES
- core: models defining canAct are now enforced on REST, gRPC and MCP operations; refused calls return 403. Query pages can be shorter than their LIMIT. OwnerModel ignores a client supplied _user. ResourceAcl.canAct signature changed to (context, action) and entries need a principal.
Bug Fixes
- core: enforce model permissions on every transport, deny by default (#810) (24c1182)
- packaging: point every package's repository at its monorepo folder (#812) (3717b73)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/cache bumped to 4.0.0-beta.5
- @webda/decorators bumped to 4.0.0-beta.5
- @webda/models bumped to 4.0.0-beta.5
- @webda/ql bumped to 4.0.0-beta.5
- @webda/tsc-esm bumped to 4.0.0-beta.5
- @webda/utils bumped to 4.0.0-beta.5
- @webda/workout bumped to 4.0.0-beta.5
- devDependencies
- @webda/compiler bumped to 4.0.0-beta.5
- @webda/content-mapper bumped to 4.0.0-beta.5
- @webda/test bumped to 4.0.0-beta.5
- peerDependencies
- @webda/test bumped to 4.0.0-beta.5
- dependencies
4.0.0-beta.4 (2026-10-08)
⚠ BREAKING CHANGES
- google-auth: configure the provider as its own service next to Authentication (redirects.success/failure, authorized_uris); the referer whitelist, no_referer, exposeScope, project_id, the GoogleAuth.Tokens event and getLocalClient are removed.
- auth: redesign authentication with @webda/auth (#800)
Features
- auth: redesign authentication with @webda/auth (#800) (74dc5df)
- deployers as commands (deployment units, CloudFormation/Lambda, daemonless OCI images) (#796) (2539cc9)
- google-auth: port Google login onto @webda/auth with hardened OAuth flow (#804) (e4c4b57)
Bug Fixes
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/cache bumped to 4.0.0-beta.4
- @webda/models bumped to 4.0.0-beta.4
- @webda/utils bumped to 4.0.0-beta.4
- devDependencies
- @webda/compiler bumped to 4.0.0-beta.4
- @webda/content-mapper bumped to 4.0.0-beta.4
- dependencies
4.0.0-beta.3 (2026-10-05)
⚠ BREAKING CHANGES
- compiler: the accessors, loadParameters and unserializer modules are removed. They wrote into the sources what webdac build now generates through @webda/content-mapper, or methods nothing calls. The unused webdac build --code flag is removed too.
- @webda/ts-plugin and the
tsc-esmbinary are removed, and applications now build with TypeScript 7.1. Generated code changes where TypeScript 6 was wrong, each verified against the shipped output:- AuditEntry.timestamp, declared
number, is no longer coerced to Date; - AbstractOwnerModel no longer emits
new ModelLink(T), a ReferenceError on first raw-uuid assignment; - sample-app's
User extends WebdaUseris now treated as a model (TS6's base-chain guard was keyed on class name), so its relations are initialised and coerced; - imports use the specifier the author wrote, not monorepo-relative paths that only resolve inside this repository;
- the emitted .d.ts is valid (TS6 referenced PrimaryKeyType unimported and wrote BelongTo without its type argument). A build that cannot write its module now fails; under TS6 a strict file-naming violation was logged and the build still reported success.
- AuditEntry.timestamp, declared
- the
@webda/schemapackage is removed, along with itswebda-schema-generatorCLI. Schema generation lives in@webda/content-mapperand is driven by@webda/compiler; nothing in the repo imported@webda/schemaany more after the previous commit. - compiler: model relations are now
type: "string"in Input, Output and Stored schemas instead of an object with no properties, and six services gain thetypeproperty they inherit from ServiceParameters. Anything generated from these schemas — API validation, client types — changes with them. - use AsyncLocalStorage for Context
- remove node 18 support
- remove expose for Store
Features
- add @webda/debug package — introspection API + WebSocket live events (#750) (307b2f2)
- add AbstractRepository and Store2Repository concept (241595d)
- add Behavior and move Binary to Behavior (ef05efb)
- add build hooks (97016bc)
- add codemod system (bbc3086)
- add formatting for context (54dee1e)
- add grpc module and sample-app webui (#756) (4a7df9a)
- add metadata plugins (ffcd62c)
- add openapi CLI command to export OpenAPI definition (#748) (a3a09bf)
- add rest domain service (bfc72e6)
- allow webda serve from @webda/core package (69a6f01)
- blog-system Binary/Binaries demo + e2e suite, with framework fixes (#771) (fe7e187)
- build on TypeScript 7.1; delete @webda/ts-plugin and ts-patch (0008e97)
- capability-based auto-injection for CLI commands (#749) (027f098)
- compiler: generate schemas with @webda/content-mapper (af3b7c5)
- content-mapper: TypeScript 7.1 content mapper package (9b57565)
- core: add MCP operation hints, canCallOperation and the operationStreaming flag (aebe2cc)
- core: carry the operation subject in operation events (5f960f7)
- core: flat models[] config + internal field migration (PR 1 of 3) (#776) (56d4b01)
- core: let operations declare their subject with setOperationSubject (07c3bdf)
- core: read the audit log per subject, per actor or globally (74783ae)
- core: record the operation subject on audit entries (feb62c8)
- debug: capture request/response details + 4xx error UX fixes (#769) (9709f47)
- default REST routes for operations, bean service fixes (#755) (ccebecf)
- enhance debug panels (#759) (63e6e0c)
- improve caching module (08b2db5)
- model Behaviors v1 (#765) (5053245)
- move to node 22 (21daf46)
- move to pnpm and disable many modules for now (ea953b7)
- move to ServiceName (a545a03)
- operation return values, HttpServer routing, and models fixes (#754) (0779301)
- operations system — decouple operations from transport (#753) (54f3151)
- postgres: pubsub + queue services and migrate Store to current core API (#774) (408e229)
- remove expose for Store (c8a36b1)
- remove node 18 support (44e7de2)
- Repository typed events, consumer migration + API positioning (PR 2+3 of 3) (#777) (70b0a75)
- rest: add 201 - Created http code for creation (#680) (5db4dda)
- router auto-instantiation, request routing, and --watch mode (#747) (5cc4a19)
- service capabilities and CLI commands system (#743) (ae2897c)
- test allow dynamic configuration in TestApplication (3af8187)
- update watchers on service parameter on update (f3417d7)
- use AsyncLocalStorage for Context (0df77c8)
- WebdaQLString<T> branded type + ts-plugin compile-time validator (#772) (f0c14c1)
- workout,core: keep piped CLI output clean (e92bd22)
Bug Fixes
- add cli in core (814a599)
- add index.ts for @webda/models (a2ed938)
- add missing types for Mailer service (bcdb6fc)
- auto generated uuid (25a7a28)
- buffer types (1d4fb31)
- compiler metadata, CLI commands, cron/async hooks and long-running command lifecycle (#785) (0515715)
- compiler: make webdac code a working migration tool (578ca7b)
- core: answer unmatched routes with a 404 error body; blog root opens the admin UI (dfbb75a)
- core: call super() first and unconditionally in Binary (65c7da0)
- core: don't JSON-parse multipart request bodies (6d5f61f)
- core: make audit read operations opt-in and record the saved key on Create (f1b25f5)
- core: per-application DomainService schemas and AuditService unsubscribe (ddddfcb)
- core: redirect plain HTTP to https on a TLS port (17f6262)
- core: resolve type error in setModelMetadata for Ancestors/Subclasses (152d044)
- core: route on the uri relative to the HttpContext prefix (7da5ab9)
- core: serve ResourceService folders under their trailing slash (53b3dc3)
- core: stop subclasses inheriting a registered modda's configuration factories (31780a0)
- enforce strict mode on @webda/models (8a6f2c4)
- interactive logger (8c30ee9)
- MemoryQueue wait if no message available (57d4bd8)
- move to nodenext module and update Inject annotation (d7d85e4)
- non passing application (7cd75e5)
- post-migration follow-ups (store create uuid, LambdaServer stage, drop workarounds) (#784) (7eead4d)
- ResourceService: ensure we do not serve . files (#678) (8abbcda)
- rest,debug: give model PATCH its own OpenAPI operation and URL (f3161b1)
- rest: give model action routes their operationId (87fd523)
- rest: match routes without a query template on the path alone (0f8c689)
- state and method override (90b7725)
- unit test models relations (2d160f1)
- update Binary service (282fcb1)
- update repository to use StorableClass (f79fc19)
Miscellaneous Chores
- delete @webda/schema (1fbd1a4)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/cache bumped to 4.0.0-beta.3
- @webda/decorators bumped to 4.0.0-beta.3
- @webda/models bumped to 4.0.0-beta.3
- @webda/ql bumped to 4.0.0-beta.3
- @webda/utils bumped to 4.0.0-beta.3
- @webda/workout bumped to 4.0.0-beta.3
- devDependencies
- @webda/compiler bumped to 4.0.0-beta.3
- @webda/test bumped to 4.0.0-beta.3
- @webda/tsc-esm bumped to 4.0.0-beta.3
- dependencies
4.0.0-beta.1 (2024-08-14)
⚠ BREAKING CHANGES
- update StorageFinder to use promises to allow GCS/S3
Features
- add iterate method definition (88e0b98)
- separate WebdaQL module (69beabb)
- update StorageFinder to use promises to allow GCS/S3 (6f36aec)
Bug Fixes
- add cache-control headers by default (70c040e)
- prometheus missing export and additional close (1e17465)
- pubsub queue abusive close (33ccadc)
Miscellaneous Chores
- prepare version for 4.0 (24e8e78)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.2.0 to ^4.0.0-beta.1
- @webda/ql bumped from ^3.999.0 to ^4.0.0-beta.1
- devDependencies
- @webda/tsc-esm bumped from ^1.3.0 to ^4.0.0-beta.1
- dependencies
3.16.0 (2024-07-16)
Features
- cloudevents: add module (562f4a9)
Bug Fixes
- core: filequeue node 22 lock (266eb8a)
3.15.1 (2024-05-19)
Bug Fixes
- update in otel and json-schema-generator (c1d9866)
3.15.0 (2024-04-12)
Features
Bug Fixes
- WebdaQL prepend with limit and offset (55cb37a)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.1.3 to ^3.2.0
- dependencies
3.14.0 (2024-02-04)
Features
- postgres: add option to create views for each models (1830dc4)
Bug Fixes
- core: plurals with s ending name (b643003)
3.13.2 (2024-01-22)
Bug Fixes
- numeric equals on postgres (75f5e36)
3.13.1 (2024-01-16)
Bug Fixes
- registerInteruptableProcess before Core.get() exists (0b9cbcb)
3.13.0 (2024-01-16)
Features
- add service client event option (cf68e7f)
Bug Fixes
- clean cancel on SIGINT (90c8627)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.1.2 to ^3.1.3
- devDependencies
- @webda/tsc-esm bumped from ^1.2.0 to ^1.3.0
- dependencies
3.12.0 (2024-01-09)
Features
- add a PartialValidator for query (1ef8dea)
- add Aggregation for subscriptions and event listener subscriptions (8bca3ce)
- add encrypter and configuration encryption (b53611c)
- add metrics to pubsub and update store for cache update (5c6e196)
- add mutations on graphql (fa3d647)
- add subscription system (b4f625c)
- make CoreModel class fully compatible with EventEmitter (76c3b9b)
- move ProxyService to runtime (#342) (a95a797)
- move some services from @webda/core to @webda/runtime (#342) (bf78ca9)
- use MemoryStore cache by default on all store (85c9288)
Bug Fixes
- > < characters in query were sanitized (ea19364)
- append condition to query (4c0e3fc)
- ASC/DESC in ORDER BY query with prepended condition (1903a12)
- cache sync (0475815)
- dynamodb scan query splice bad result (5c3d657)
- getMetrics ensure service name is included (00881b7)
- NotEnumerable properties should not be in schema (cb9e4ac)
- test: store metric now have the service name (12baed4)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.1.1 to ^3.1.2
- devDependencies
- @webda/tsc-esm bumped from ^1.1.1 to ^1.2.0
- dependencies
3.11.2 (2023-12-05)
Bug Fixes
3.11.1 (2023-12-04)
Bug Fixes
- allow Binaries to define metadata and metadata schema (2001b1e)
- FileUtils.walk wrong depth limit (9e6ce51)
3.11.0 (2023-11-30)
Features
- add ndjson streams and stream persistence for big MemoryStore (d283948)
Bug Fixes
- tsc-esm: node module import rewrite .js (e4a15ae)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.1.0 to ^3.1.1
- devDependencies
- @webda/tsc-esm bumped from ^1.1.0 to ^1.1.1
- dependencies
3.10.0 (2023-11-29)
Features
- add a setModelStore to force model store (5354f46)
- add action input validation and openapi definition (fc0e28c)
- add util registerModel in test (059eee8)
- allow to get routes from router (dcdbd74)
- allow to specify action name in @Action (ed1429f)
- async module use AsyncAction model directly (862d051)
- compress MemoryStore persistence and handle .gz in FileUtils.save/load (997e11b)
- manage all models by default for a BinaryService (c3524da)
- speed up test by cache unpackedapplication.load (242ee04)
Bug Fixes
- graphql any[] type replaced by string[] (c3ffe20)
3.9.1 (2023-11-22)
Bug Fixes
3.9.0 (2023-11-18)
Features
- add a BinaryModel for big json (7849fac)
- allow return of async function for StoreMigration (baebc5f)
Bug Fixes
- avoid exposing OpenAPI root if not defined (e525412)
- links with ** prefix misplaced with _** by escapeName (6a5a8b9)
3.8.1 (2023-11-15)
Bug Fixes
- getGraph case insensitive (a35ea49)
3.8.0 (2023-11-14)
Features
- add otel module (1841c28)
3.7.0 (2023-11-12)
Features
- add an isEmpty method for Binary (daf5832)
- add CoreModel listeners system (977dd9d)
- add execute/wait method to Throttler (b6cd66b)
- add iterate generator methods (ff45183)
- drop node16 as it is EOL (a6b795a)
- modelmapper service (e5eee5f)
- RESTDomainService: add the url info retriever on Binaries (13fe77c)
- Store: add additionalModels to compose models in store (e0f1d69)
- Throttler add a static method (dd5178e)
Bug Fixes
- BinaryFile: fallback on originalname if name is not present (245a24b)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.0.4 to ^3.1.0
- devDependencies
- @webda/tsc-esm bumped from ^1.0.6 to ^1.1.0
- dependencies
3.6.0 (2023-10-07)
Features
- add isGlobal to Context (6423ba7)
- add stop function for service (c4fb0ec)
- allow context propagation in linked model (e84df9a)
Bug Fixes
- display help command (3d0b790)
- domainservice model actions (48a899a)
- remove completely the _ prefix of action method (3530b60)
- setContext on undefined reference (030db1b)
- write on flushed header (2d1ef2e)
3.5.0 (2023-10-04)
Features
- add absolute url when prefix is in use for Router (8ea07f7)
- add more cases to transformName for RESTDomainService (b1071f2)
- ensure YAMLUtils.parse can handle multiple documents (11061f9)
Bug Fixes
- . route on / url service (426ec2a)
- default toLowerCase for k8s resources name (aaa0d58)
- display of double import warning (c55f2d8)
- ensure a / exists before root collection for RESTDomainService (555782e)
- machineIdSync catch error (7a29f5c)
- set devMode prior to initialization (cb62746)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.0.3 to ^3.0.4
- dependencies
3.4.0 (2023-09-07)
Features
- add swagger-ui for dev (a6adb77)
Bug Fixes
- DomainService collection query (6f81d7c)
- query parameters on collection for DomainService (ef6d18d)
- query SubExpression only (36bccd7)
3.3.0 (2023-08-30)
Features
- allow no domain on cookie to default on domain only (308fa49)
Bug Fixes
- beans local configuration without config declaration (5186555)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.0.2 to ^3.0.3
- devDependencies
- @webda/tsc-esm bumped from ^1.0.5 to ^1.0.6
- dependencies
3.2.2 (2023-07-19)
Bug Fixes
- allow no resolution for symlink to fix aspect_build_js all symlink (a6a97ad)
- make values optional to allow downward compatibility (c0fec4f)
3.2.1 (2023-07-08)
Bug Fixes
- keep symlink path with folder symlinked (bd3d7b5)
- relax version condition between @webda/shell and @webda/core (b634574)
3.2.0 (2023-07-07)
Features
- add a Webda.UpdateContextRoute to be able to alter router decision (22463f9)
- add regexp validator utility classes (b71f1ca)
Bug Fixes
- ignore any .folder in node_modules for pnpm and nx (ebe7f81)
3.1.2 (2023-07-01)
Bug Fixes
3.1.1 (2023-06-30)
Bug Fixes
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.0.1 to ^3.0.2
- devDependencies
- @webda/tsc-esm bumped from ^1.0.4 to ^1.0.5
- dependencies
3.1.0 (2023-06-30)
Features
Bug Fixes
- @types/ws version (f63b002)
- force file format with JSON/YAMLUtils.saveFile (d629ad6)
- improve error message for unsupported diagrams (03238b0)
Dependencies
- The following workspace dependencies were updated
- dependencies
- @webda/workout bumped from ^3.0.0 to ^3.0.1
- devDependencies
- @webda/tsc-esm bumped from ^1.0.3 to ^1.0.4
- dependencies
1.0.1 (2021-03-18)
Note: Version bump only for package @webda/core
1.0.0-beta.0 (2019-08-21)
Bug Fixes
- code smell (af4f211)
- move away from checkCSRF to checkRequest (84a9265)
- resolved routes issue within test (62b41f2)
- update all packages to use the new scope @webda (6acc1d5)
- update imports (7896f0c)
Features
- new versioning system (27ab549)
BREAKING CHANGES
- need to update as CorsFilter is not exported anymore
- new v1.0.0