Skip to content

YunCMS 0.1.25: native lifecycle and transaction fixes

Choose a tag to compare

@raichubuilds raichubuilds released this 06 Oct 15:31
· 18 commits to main since this release
b2d5328

YunCMS 0.1.25 fixes native API startup, managed update shutdown, external authentication errors and transaction-bound Items hooks.

Fixes

  • Reject Express 5 listen errors such as EADDRINUSE, skip afterStart/schedules/automation startup on an unbound server, and clean initialized resources through the normal shutdown path (#29).
  • Let managed update probes wait up to 12 seconds for graceful shutdown. Preserve probe error codes separately from exitCode, and stop the CLI/API process tree when escalation is required (#27).
  • Return HTTP 400 INVALID_AUTH_TRANSACTION for malformed, missing, expired or consumed OAuth/OIDC/SAML transaction state, without creating a session. External-auth permission, configuration and provider failures also use controlled statuses (#28).
  • Defer native transaction-bound Items mutation actions, audit writes and AI automation enqueueing until the outer commit. Rollback and commit failure discard pending success actions. Nested native helper calls join the outer transaction, and post-commit database handles avoid pool deadlocks, including with one connection (#30).
  • Reject array/object/boolean pagination values with INVALID_QUERY; keep scalar numbers/numeric strings and documented defaults compatible (#26, thanks @beytullah-gn).
  • Update security baselines to proxy-addr 2.0.8 and source-map-js 1.2.2 (#32). Advisories: GHSA-jqcg-44mw-7w3h and GHSA-68fv-2mgg-jv7q.

Extension contract

Use withTransaction() or withConnectionTransaction() and bind Items services to the supplied connection. Filters remain inside the transaction; mutation actions run after commit and the helper waits for them before returning. These actions are best-effort effects rather than a durable event queue. Raw manually started transactions are not tracked. See Extensions.

Installation

All four public packages are 0.1.25: @yunsoft/yuncms, @yunsoft/yuncms-api, @yunsoft/yuncms-core, and @yunsoft/yuncms-extensions-sdk.

npm install --save-exact @yunsoft/yuncms@0.1.25

Docker: yunsoftofficial/yuncms:0.1.25 for linux/amd64 and linux/arm64; latest follows this release. Existing deployments should follow Upgrades and keep a verified backup. No new database migration is introduced.

Validation

Node 24.21.0; fast regression suite (79 files); complete source suite (173 files); production Studio build; all four package contract checks; all 17 real MySQL/API integrations with Redis, migration and backup/restore coverage enabled. Native occupied-port, 4.5-second scheduled-job shutdown, process-tree termination, rollback and single-connection audit/automation regressions passed. Authenticated Studio was checked headlessly on desktop and mobile. A fresh Docker installation passed readiness, bundled Studio, Administrator login and session rotation. Clean packed and published-registry Node 24 consumer installations passed CLI/startup/readiness/shutdown checks and npm audit with zero vulnerabilities. Published Docker CLI checks passed for both linux/amd64 and linux/arm64.

Authenticated byte-range Files streaming (#31) remains an open enhancement.

Docker manifest digest (versioned and latest tags): sha256:ac44beb19b53567339308ae1fcab15923eb4efcb85944805e3c3cd0177c72e76.