Skip to main content

Changelog

4.0.0-beta.5 (2026-10-08)​

⚠ BREAKING CHANGES​

  • core: models defining canAct are now enforced on REST, gRPC and MCP operations; refused calls return 403. Query pages can be shorter than their LIMIT. OwnerModel ignores a client supplied _user. ResourceAcl.canAct signature changed to (context, action) and entries need a principal.

Bug Fixes​

  • core: enforce model permissions on every transport, deny by default (#810) (24c1182)
  • packaging: point every package's repository at its monorepo folder (#812) (3717b73)

Dependencies​

  • The following workspace dependencies were updated
    • dependencies
      • @webda/serialize bumped to 4.0.0-beta.5
    • devDependencies
      • @webda/compiler bumped to 4.0.0-beta.5
      • @webda/test bumped to 4.0.0-beta.5
      • @webda/tsc-esm bumped to 4.0.0-beta.5
    • peerDependencies
      • @webda/ql bumped to 4.0.0-beta.5
      • @webda/utils bumped to 4.0.0-beta.5

4.0.0-beta.4 (2026-10-08)​

⚠ BREAKING CHANGES​

  • auth: redesign authentication with @webda/auth (#800)

Features​

  • add @webda/create (npm create @webda) with agent guidance (#799) (e29822a)
  • auth: redesign authentication with @webda/auth (#800) (74dc5df)
  • deployers as commands (deployment units, CloudFormation/Lambda, daemonless OCI images) (#796) (2539cc9)

Dependencies​

  • The following workspace dependencies were updated
    • dependencies
      • @webda/serialize bumped to 4.0.0-beta.4
    • devDependencies
      • @webda/compiler bumped to 4.0.0-beta.4
    • peerDependencies
      • @webda/utils bumped to 4.0.0-beta.4

4.0.0-beta.3 (2026-10-05)​

⚠ BREAKING CHANGES​

  • compiler: the accessors, loadParameters and unserializer modules are removed. They wrote into the sources what webdac build now generates through @webda/content-mapper, or methods nothing calls. The unused webdac build --code flag is removed too.
  • @webda/ts-plugin and the tsc-esm binary are removed, and applications now build with TypeScript 7.1. Generated code changes where TypeScript 6 was wrong, each verified against the shipped output:
    • AuditEntry.timestamp, declared number, is no longer coerced to Date;
    • AbstractOwnerModel no longer emits new ModelLink(T), a ReferenceError on first raw-uuid assignment;
    • sample-app's User extends WebdaUser is now treated as a model (TS6's base-chain guard was keyed on class name), so its relations are initialised and coerced;
    • imports use the specifier the author wrote, not monorepo-relative paths that only resolve inside this repository;
    • the emitted .d.ts is valid (TS6 referenced PrimaryKeyType unimported and wrote BelongTo without its type argument). A build that cannot write its module now fails; under TS6 a strict file-naming violation was logged and the build still reported success.
  • compiler: model relations are now type: "string" in Input, Output and Stored schemas instead of an object with no properties, and six services gain the type property they inherit from ServiceParameters. Anything generated from these schemas — API validation, client types — changes with them.

Features​

  • add AbstractRepository and Store2Repository concept (241595d)
  • add dirty Mixin system (acf39c5)
  • add event repository (c9106ec)
  • add EventRepository (52cc09c)
  • add formatting for context (54dee1e)
  • add metadata plugins (ffcd62c)
  • add more types (ab7a7c5)
  • add new models module (5ce4d89)
  • add property paths modification (6e23c2c)
  • add Settable (ca1e68a)
  • add WebdaQL as peer dependencies and implement query/iterate (fbf3414)
  • allow uid and pk on repository (9f17f55)
  • blog-system Binary/Binaries demo + e2e suite, with framework fixes (#771) (fe7e187)
  • build on TypeScript 7.1; delete @webda/ts-plugin and ts-patch (0008e97)
  • compiler: generate schemas with @webda/content-mapper (af3b7c5)
  • content-mapper: TypeScript 7.1 content mapper package (9b57565)
  • dirty deep detector (910faf6)
  • ensure operation schemas are exported (301ad65)
  • ensure we use UID and reserve UUID for @webda/core (da289ff)
  • improve caching module (08b2db5)
  • mock: add @webda/mock — coherent mock-data generation for models (#761) (c15a9b1)
  • model Behaviors v1 (#765) (5053245)
  • move to node 22 (21daf46)
  • move to pnpm and disable many modules for now (ea953b7)
  • operation return values, HttpServer routing, and models fixes (#754) (0779301)
  • ql: bind ? and :name query parameters (#788) (4a8647b)
  • Repository typed events, consumer migration + API positioning (PR 2+3 of 3) (#777) (70b0a75)
  • update OneToMany (c0a2fb3)
  • update watchers on service parameter on update (f3417d7)
  • use symbols for relations (8e3e0d0)
  • WebdaQLString<T> branded type + ts-plugin compile-time validator (#772) (f0c14c1)

Bug Fixes​

  • add index.ts for @webda/models (a2ed938)
  • auto generated uuid (25a7a28)
  • back to 100% cov for models (bae0122)
  • clean up models (96c27f0)
  • compiler metadata, CLI commands, cron/async hooks and long-running command lifecycle (#785) (0515715)
  • compiler: make webdac code a working migration tool (578ca7b)
  • core: make audit read operations opt-in and record the saved key on Create (f1b25f5)
  • enforce strict mode on @webda/models (8a6f2c4)
  • generate Stored schema (1cd57eb)
  • models: filter query results by class to stop subclass leakage (#770) (a58056d)
  • models: use the generated primary key when creating without one (bb1baf0)
  • move @webda/decorators to strict mode (532da54)
  • post-migration follow-ups (store create uuid, LambdaServer stage, drop workarounds) (#784) (7eead4d)
  • serialize: stop persisting OneToMany helpers (04f3b27)
  • stores: escape WebdaQL string values and handle TRUE/FALSE in query translators (d02f0a2)
  • unit test models relations (2d160f1)
  • unit tests (1d54f9b)
  • update Binary service (282fcb1)
  • update repository to use StorableClass (f79fc19)
  • use getPatch from DirtyState (aae857e)
  • use symbols for webda configuration (a89f640)

Dependencies​

  • The following workspace dependencies were updated
    • devDependencies
      • @webda/compiler bumped to 4.0.0-beta.3
      • @webda/serialize bumped to 4.0.0-beta.3
      • @webda/test bumped to 4.0.0-beta.3
      • @webda/tsc-esm bumped to 4.0.0-beta.3
    • peerDependencies
      • @webda/ql bumped to 4.0.0-beta.3
      • @webda/utils bumped to 4.0.0-beta.3