-
-
Notifications
You must be signed in to change notification settings - Fork 0
0.35.0
Hussein Jarrar edited this page Sep 12, 2026
·
2 revisions
5 changes · 2 Bugfixes, 3 New Features · 52 points.
-
RADD-1122 Six authorization defects found while tracing the directory readers (share expiry/deny, wiki batch policy, template scope, field scope transition, attachment grants)
What was wrong. Replacing full-catalog reads with bounded windows (RADD-1115) meant reading every authorization path those catalogs sat behind, and six of them were wrong. None was in the original audit's twelve.
accessattachmentsdashboardsfieldspagesviews· 5 pts ·0402db2e -
RADD-1121 September audit: the twelve prioritized defects (credential scope, merge authz, account cache, login throttle, live cache, mobile shell, realtime, overlays, lazy routes, PR checks)
What was wrong. The 9 September repository audit (research/audit-2026-09-09/README.md) found twelve defects it ranked ahead of everything else. Four were trust-boundary bugs: an API key could mint an unscoped child token (POST /tokensnever intersected the caller's scope) and a narrowly scoped admin PAT passed the…
authciitemsrealtimeweb· 13 pts ·e2405698
-
RADD-1115 Bound directory and query work and measure interactive scaling
The initial September research identified these outstanding outcomes, and the user explicitly requested full completion. Ledger: research/audit-2026-09-09/OUTSTANDING.md, rows P2,P3,P4,P5,P6.
13 pts ·9e54fa62 -
RADD-1120 Prove pinned-image adoption, upgrades and complete data portability
The initial September research identified these outstanding outcomes, and the user explicitly requested full completion. Ledger: research/audit-2026-09-09/OUTSTANDING.md, rows C1,O1,O2,V2.
13 pts ·584a00e1 -
RADD-1113 Paginate long discussions without leaking hidden comments
The issue and wiki discussion clients fetch and render the entire comment history. The backend filters internal/team visibility after loading all rows, so long mail-driven threads have unbounded memory and rendering cost. The current list service also bypasses the registered per-parent read guard.
commentsperformance· 8 pts ·c15cb6ae
Changes from v0.34.0 to v0.35.0.
Mirrored from project.radd-hq.com on 2026-09-12. Documentation is written there; this copy is regenerated by scripts/publish_wiki.py and hand edits do not survive it.
-
Developer guide
- Architecture: the kernel and plugins
- Develop, test and deploy
- Events and consumers
- Permissions and access control
- The MCP server
- The query language for developers
- The REST API and authentication
- Write a backend plugin
- Write a page editor extension
- Write a plugin user interface
- Write an automation node
-
Release notes
- 0.36.4
- 0.36.3
- 0.36.2
- 0.36.1
- 0.36.0
- 0.35.0
- 0.34.0
- 0.33.0
- 0.32.0
- 0.31.1
- 0.31.0
- 0.30.0
- 0.29.0
- 0.28.0
- 0.27.0
- 0.26.0
- 0.25.1
- 0.25.0
- 0.24.1
- 0.24.0
- 0.23.1
- 0.23.0
- 0.22.0
- 0.21.0
- 0.20.0
- 0.19.0
- 0.18.1
- 0.18.0
- 0.17.2
- 0.17.1
- 0.17.0
- 0.16.0
- 0.15.0
- 0.14.1
- 0.14.0
- 0.13.1
- 0.13.0
- 0.12.0
- 0.11.0
- 0.10.0
- 0.9.2
- 0.9.1
- 0.9.0
- 0.8.1
- 0.8.0
- 0.7.1
- 0.7.0
- 0.6.6
- 0.6.5
- 0.6.4
- 0.6.3
- 0.6.2
- 0.6.1
- 0.6.0
- 0.5.0
- 0.4.1
- 0.4.0
- 0.3.2
- 0.3.0
- 0.2.0
- 0.1.0
-
User guide
- AI features
- Attachments
- Automations
- Cycles and releases
- Instance settings
- Intake forms and the portal
- Notifications and the inbox
- Personal settings
- Project settings
- Projects
- Reports and dashboards
- Search and the query language
- Start here
- The application window
- The card designer
- The roadmap
- The service desk
- The wiki
- Time logging and the timesheet
- Views
- Work items