Skip to content

Releases: PointBlueTechnology/DirXMLDev

0.27.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 10 Oct 12:39

[0.27.0] - 2026-10-10

Added

  • Vault.open for services that sign a person in and must not keep the password (Directory
    Console): it borrows the caller's bound JNDI connection (left open by close) and binds the
    extended-operation connection once, through the caller's TLS socket factory. The password is used
    for that bind only. A missing dirxml_misc.jar is now reported as such.
  • Operate.Engine and Operate.CachePage are public, and Environments.Environment.forService
    builds an environment from a name, a driver set and a tier: a service can call Operate with its
    own connections (Operate.vaultEngine(Vault.open(…))) and test against a fake engine.

0.26.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 10 Oct 01:57

[0.26.0] - 2026-10-09

Fixed

  • Designer projects: entitlement policies are read from where real projects keep them (the driver
    set's Idm:RbeContainer, priorities in DirXML-SPPriority, multi-valued attributes as nested
    structures, the display document as hex); verified against three real projects.
  • Entitlement refs derived from a display document (projects and exports) carry LDAP DNs: Designer
    writes the entitlement DNs in NDS dot form, which a deploy cannot write.

Added

  • Designer projects: notification templates are read (the driver set's Identity Vault →
    its template collection → the templates, subject, body and package stamps).

0.25.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 10 Oct 01:27

[0.25.0] - 2026-10-09

Added

  • The low console gaps (docs/console-gaps.md §13): driverset.activation [apply],
    driverset.servers [add|remove], engine.metrics, driver.rights, workorder.list.

0.24.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 10 Oct 00:53

[0.24.0] - 2026-10-09

Added

  • driver.migrate --direction vault (docs/console-gaps.md §11, G5): migrate vault objects into the
    application — an LDAP search, then one <sync> per object through the running driver's subscriber
    channel; --dry-run lists them; --direction app is the old MigrateApp path.
  • driver.log-level [set] (§11, G12): the log level of a driver or the driver set as Designer's page
    holds it (DirXML-DriverTraceLevel, DirXML-LogEvents through SetLogEvents, DirXML-LogLimit,
    DirXML-LogEventsType); --inherit puts a driver back on the set's settings.
  • vault.email-server [set] (§12, G8): the notification collection's SMTP settings, shown and
    written live (the password from the secrets file or stdin, never shown).
  • Notification templates in the tree (§12, G8): the vault's notfMergeTemplate objects as
    templates/<name>.xml, read live and from an LDIF, validated, diffed (TEMPLATE_*) and deployed
    (a removal needs --delete-all templates).
  • Secret kinds (§11, G11): driver.secrets set|remove --kind named|shim-auth|remote-loader|key|keystore;
    vault.deploy --secrets now sets the Remote Loader password (before: skipped as unsupported) and the
    Remote Loader's mutual-authentication key and keystore passwords when the secrets file has
    <driver>.mutual-auth-key-password / <driver>.mutual-auth-keystore-password.

0.23.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 09 Oct 23:21

[0.23.0] - 2026-10-09

Added

  • driver.query (docs/console-gaps.md §10, G9): ask the connected system through the running
    driver with the engine's query verb — class, scope, a DN (LDAP form converted to slash form) or an
    association, search attributes, the attributes to read (none for a match test); the shim's
    <instance>s as text or JSON. Light write gate, audited.
  • driver.health [clear] (§10, G7): the Driver Health job's last state per server from the
    driver's DirXML-uiXMLSmall, the health configuration on its DirXML-ConfigManifest (states,
    condition groups, actions), the set's health jobs and whether the driver is in scope; clear
    removes the recorded status.
  • The main usage now lists job.* and rbe.* beside the other operate commands.

0.22.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 09 Oct 23:01

[0.22.0] - 2026-10-09

Added

  • Role-based entitlement policies (docs/console-gaps.md §9, phase R1, grounded on edir3 with the
    Entitlements Service driver): DirXML-SharedProfile policies in the driver set's
    DirXML-SharedProfileSet container, read from the vault and an LDIF, a Designer export
    (<rbe-policies>) and project (Idm:RbePolicies, unverified), kept as rbe-policies/<name>.xml,
    written back to an export; validate checks them (rbe-no-priority, rbe-duplicate-priority,
    rbe-priorities-not-sequential, rbe-legacy-entitlements-xml, rbe-no-membership,
    rbe-no-entitlement, rbe-unknown-entitlement, rbe-no-service-driver); vault.diff reports
    RBE_ADDED / RBE_REMOVED / RBE_CHANGED; vault.deploy creates the container, writes the policy,
    rewrites the priority list and restarts the Entitlements Service driver (a removal needs
    --delete-all rbe-policies); rbe.list, rbe.members.

Fixed

  • A deploy no longer prints the Identity Applications cache note for a job change; the driver set's own
    removals (jobs, policies) no longer trip the empty-kind guard with a null driver.

0.21.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 09 Oct 20:12

[0.21.0] - 2026-10-09

Added

  • Jobs deploy and operate (docs/console-gaps.md §8, phase J2): vault.diff reports
    JOB_ADDED / JOB_REMOVED / JOB_CHANGED; vault.deploy writes the DirXML-Job object and
    sends NotifyJobUpdate so the scheduler re-reads it (no driver restart; a removal needs
    --delete-all jobs); job.list, job.status (GetJobState: running, configuration,
    scheduled, next run), job.start, job.abort.

0.20.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 09 Oct 19:46

Added

  • Jobs in the model (docs/console-gaps.md §1, phase J1): DirXML-Job objects under a driver
    or the driver set — the configuration document, the servers, the scopes, the trace settings —
    read from the vault and an LDIF, a Designer project (Idm:Jobs, .Job_) and an export
    (<jobs>), kept as drivers/<driver>/jobs/<name>.xml and jobs/<name>.xml, written back to an
    export; validate checks them (job-no-document, job-wrong-root, job-no-class,
    job-no-server, job-unknown-server, job-disabled). Diff and deploy follow in J2.

0.19.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 09 Oct 18:58

Added

  • Identity Console gaps, first set (docs/operate.md): driver.start-option --option auto|manual|disabled (SetDriverStartOption, live, gated and audited); driver.submit --mode command|event|queue (SubmitCommand, SubmitEvent, QueueEvent into the cache of a running
    or stopped driver); driver.associations --driver D [--state …] (the objects associated with a
    driver, by state, through (DirXML-Associations=<driver>#<state>#*)); driver.password-sync
    (the driver set's sync timeout, the driver's password-related settings); object.inspect --dn
    (an object's classes, associations across drivers, password-sync status). Read-only ones need
    no --yes.
  • The usage text now lists vault.schema, vault.app-schema, vault.deploy-schema,
    schema.diff, events.describe, query … events|event and
    events.case, which existed without a line.

0.18.0

Choose a tag to compare

@jcombs-pointblue jcombs-pointblue released this 09 Oct 16:25

Added

  • ApplicationType.of(driver) is public, with displayName(type) (what a diagram labels an
    application: "Active Directory", "JDBC", "User Application"…) and vaultOnly(type) (a driver
    with no external system), for DirXMLDevWeb's Architecture view (#32 there).