Skip to main content

Changelog

4.0.0-beta.5 (2026-10-08)​

⚠ BREAKING CHANGES​

  • core: models defining canAct are now enforced on REST, gRPC and MCP operations; refused calls return 403. Query pages can be shorter than their LIMIT. OwnerModel ignores a client supplied _user. ResourceAcl.canAct signature changed to (context, action) and entries need a principal.

Bug Fixes​

  • core: enforce model permissions on every transport, deny by default (#810) (24c1182)
  • packaging: point every package's repository at its monorepo folder (#812) (3717b73)

Dependencies​

  • The following workspace dependencies were updated
    • dependencies
      • @webda/workout bumped to 4.0.0-beta.5
    • devDependencies
      • @webda/compiler bumped to 4.0.0-beta.5
      • @webda/core bumped to 4.0.0-beta.5
      • @webda/test bumped to 4.0.0-beta.5
      • @webda/utils bumped to 4.0.0-beta.5
    • peerDependencies
      • @webda/core bumped from ^4.0.0-beta.1 to ^4.0.0-beta.5

4.0.0-beta.4 (2026-10-08)​

Dependencies​

  • The following workspace dependencies were updated
    • devDependencies
      • @webda/compiler bumped to 4.0.0-beta.4
      • @webda/core bumped to 4.0.0-beta.4
      • @webda/utils bumped to 4.0.0-beta.4
    • peerDependencies
      • @webda/core bumped from ^4.0.0-beta.1 to ^4.0.0-beta.4

4.0.0-beta.3 (2026-10-05)​

⚠ BREAKING CHANGES​

  • compiler: the accessors, loadParameters and unserializer modules are removed. They wrote into the sources what webdac build now generates through @webda/content-mapper, or methods nothing calls. The unused webdac build --code flag is removed too.
  • @webda/ts-plugin and the tsc-esm binary are removed, and applications now build with TypeScript 7.1. Generated code changes where TypeScript 6 was wrong, each verified against the shipped output:
    • AuditEntry.timestamp, declared number, is no longer coerced to Date;
    • AbstractOwnerModel no longer emits new ModelLink(T), a ReferenceError on first raw-uuid assignment;
    • sample-app's User extends WebdaUser is now treated as a model (TS6's base-chain guard was keyed on class name), so its relations are initialised and coerced;
    • imports use the specifier the author wrote, not monorepo-relative paths that only resolve inside this repository;
    • the emitted .d.ts is valid (TS6 referenced PrimaryKeyType unimported and wrote BelongTo without its type argument). A build that cannot write its module now fails; under TS6 a strict file-naming violation was logged and the build still reported success.
  • compiler: model relations are now type: "string" in Input, Output and Stored schemas instead of an object with no properties, and six services gain the type property they inherit from ServiceParameters. Anything generated from these schemas — API validation, client types — changes with them.

Features​

  • add build hooks (97016bc)
  • add grpc module and sample-app webui (#756) (4a7df9a)
  • blog-system Binary/Binaries demo + e2e suite, with framework fixes (#771) (fe7e187)
  • build on TypeScript 7.1; delete @webda/ts-plugin and ts-patch (0008e97)
  • compiler: generate schemas with @webda/content-mapper (af3b7c5)
  • content-mapper: TypeScript 7.1 content mapper package (9b57565)
  • enhance debug panels (#759) (63e6e0c)
  • WebdaQLString<T> branded type + ts-plugin compile-time validator (#772) (f0c14c1)

Bug Fixes​

  • compiler metadata, CLI commands, cron/async hooks and long-running command lifecycle (#785) (0515715)
  • compiler: make webdac code a working migration tool (578ca7b)
  • unit test models relations (2d160f1)

Dependencies​

  • The following workspace dependencies were updated
    • dependencies
      • @webda/workout bumped to 4.0.0-beta.3
    • devDependencies
      • @webda/compiler bumped to 4.0.0-beta.3
      • @webda/core bumped to 4.0.0-beta.3
      • @webda/test bumped to 4.0.0-beta.3
      • @webda/utils bumped to 4.0.0-beta.3
    • peerDependencies
      • @webda/core bumped from ^4.0.0-beta.1 to ^4.0.0-beta.3