Repository navigation
Release v22.13.1
Summary
Cratis.Chronicle, Cratis.Chronicle.AspNetCore and Cratis.Chronicle.Testing are updated from 18.0.0 to 18.1.0, picking up 18.1.0.
Added
- Chronicle 18.1.0: Report substituted compliance behavior in read-model scenarios, including strict-fidelity rejection for projections and reducers.
- Chronicle 18.1.0: Add typed scope enforcement through
IUniqueEventTypesConstraintsStorage.IsAllowedWithinScope, preserving the original method for existing storage providers.
Changed
Cratis.Chronicle,Cratis.Chronicle.AspNetCoreandCratis.Chronicle.Testingare updated to18.1.0- Chronicle 18.1.0: Built-in providers reject direct calls to the legacy
IsAllowedmethod with a non-empty scope key instead of silently ignoring scope. Empty or omitted keys retain unscoped behavior; the engine uses the new typed method. Custom providers implementing only the original method retain their legacy behavior and its scope-key limitations.
Fixed
- Chronicle 18.1.0: Publish discovered client artifacts only after initialization completes, allow retry after failure, and reject reentrant access to incomplete results.
- Chronicle 18.1.0: Apply generation-specific PII metadata in event scenarios, share encryption keys within each scenario, and surface compliance-provider activation failures. Read-model sink encryption and erasure remain outside in-process scenario coverage.
- Chronicle 18.1.0: Preserve dictionary keys, case distinctions, and nested JSON nulls through projection and SQL readback.
- Chronicle 18.1.0: Preserve explicit compliance subjects through reactor/reducer notifications and event-sequence readback, with an event-source fallback for older servers.
- Chronicle 18.1.0: Enforce unique event type constraints across typed source/stream scopes without delimiter collisions, including claims and releases within the same append batch.
- Chronicle 18.1.0: Validate overlapping covered/removal event types against preceding events before releasing their constraint cycle, matching individually appended events.
- Chronicle 18.1.0: Show resolved, quarantined, and unknown failed-partition states accurately, and keep SQL-backed observation current across storage instances.
- Chronicle 18.1.0: Honor configured administrator identities during initial setup and report failed password changes instead of returning false success.
- Chronicle 18.1.0: Deliver required prerelease build outputs reliably and validate generated schemas with real protoc before distributing them.
Removed
- Chronicle 18.1.0: Remove the unused Workbench dashboard prototype and its stale navigation references.
Security
- Chronicle 18.1.0: Require antiforgery protection for authenticated cookie mutations while preserving explicit bearer-token access. Cookie-based access requires HTTPS and matching Workbench assets. Custom cookie clients must obtain a token from
/.cratis/antiforgeryand sendX-CSRF-TOKENon mutations and logout. - Chronicle 18.1.0: Restrict anonymous Identity endpoints to the intended login and refresh surface, and reject authenticated actors without a meaningful subject.
- Chronicle 18.1.0: Enforce Chronicle audiences for JWT and Data Protection access tokens. Existing OAuth tokens without the required audience must be reacquired; coordinate issuers and validators during rolling upgrades.
- Chronicle 18.1.0: Prevent repeated initial administrator password setup and duplicate administrator bootstrap events under competing requests.