Repository navigation
完整变更:1.0.6...v2026.0.0,共 194 个提交。
不兼容变更
- rename AuthX to GrantForge and refresh branding (84f83254)
- replace the legacy backend with a Spring Boot 4.1 skeleton (223a12dd)
新功能
- release: cut releases with one script and list their commits (362546cc)
- hdfs: add the NameNode agent for Hadoop 3.5.0 (1445466e)
- agent: let agents credit GrantForge for a strict default deny (0c109094)
- hdfs: bound path lookups and validate cluster settings (1d20eac3)
- hdfs: talk to clusters with Hadoop's client like Apache Ranger (02bd6d1a)
- plugin-host: load the repository's plugins when run from sources (43591418)
- hdfs: add the HDFS service type plugin shipped with the release (e8b651b7)
- agent: add the agent core that keeps policies current in systems (f7be272e)
- import accounts, roles and menus from a 1.x database (169ea055)
- web: drop the JSON workbench from the console (18a7f0ba)
- deploy with a Docker image, Compose examples and a Helm chart (cb013c07)
- benchmark authorization and list APIs at a million accounts (57654a40)
- review who holds roles in periodic access reviews (a0823d40)
- let users ask for roles that approvers grant for a while (07b8790a)
- keep apart roles nobody may hold together (d8fa25b2)
- let users sign in with OpenID Connect providers (b77f314f)
- let users sign in with LDAP directories (8438c977)
- add two-step sign-in with authenticator apps (3254a92c)
- add sample applications and integration guides (29b7eccc)
- add a JavaScript client with Vue directives (5581d99d)
- let applications apply data policies to their own rows (68e45ab5)
- add a Spring Boot starter for applications (1f428395)
- let applications ask what their users may do (d7e72122)
- sign users in to applications with OpenID Connect (2f58406a)
- register OAuth clients of catalog applications (01d6b14c)
- search and export the audit log (cf6a8bea)
- record permission changes with them and keep audit append-only (e8b50fca)
- simulate what an account would gain or lose (01b68209)
- show a user's effective permissions and why (f645830b)
- answer and explain what accounts may use (c71ea138)
- set a role's field permissions in the console (f1c7cf04)
- refuse changes of read-only secured fields (a2f0fe50)
- hide and mask secured fields as roles' field policies say (30aa2420)
- register the secured fields APIs return and accept (2891ce2a)
- keep built-in lists to readers' data permissions (ad97b40d)
- set a role's data permissions in the console (6d766bfc)
- limit rows to what readers' data policies allow (2bf42cd4)
- give roles data policies with checked conditions (c0515e78)
- let entities declare themselves under data permissions (b52e39a5)
- keep the plugin API compatible and prove it with an example (47de7d26)
- keep what agents decided and let the console search it (16976c4e)
- hand agents signed policy snapshots for their service (55ed41eb)
- write access, masking and row filter policies for services (e22381da)
- register data services, with their secrets encrypted (01cd7bd4)
- decide access requests against policies in a Java 8 engine (7649d756)
- load service type plugins, each in its own class loader (0e4b772f)
- show what a change would do before it is made (f7c95b26)
- let roles inherit from other roles (1c3c4e5f)
- check the catalog for settings that silently do not work (b9b1abaf)
- show each user only the pages and buttons they may use (bde4ab68)
- refuse API calls the caller has no permission for (ff753df5)
- work out each user's permissions from all of their roles (82274c83)
- grant pages, buttons and APIs to roles (38619909)
- give roles to users, groups, departments and positions (a394a436)
- manage the roles of a tenant (521f6430)
- declare the console's pages and buttons in a permission manifest (36727158)
- record what pages and buttons need to work (c88c709c)
- register every API endpoint and its permission at start-up (43adbb11)
- maintain the resource catalog of each application (aa35b34e)
- define the plugin API for service types (139d36c5)
- import and export accounts and departments as CSV (58d6d37c)
- maintain positions and give them to accounts (ae8a7775)
- group accounts into user groups (64dc6376)
- let visitors register their own account when enabled (7869e08a)
- manage the accounts of a tenant (b96939a9)
- maintain each tenant's organization tree (dd0641ef)
- let platform administrators manage tenants (5a2905d6)
- audit console sign-ins and show the login history (b2a8dac2)
- edit the profile and change the password from an account page (17fdb64e)
- list and end console sessions (98ed2178)
- show console pages from the signed-in user's authorization (495fa1c5)
- web: sign in with the server session instead of a token (9269e778)
- server: sign in to the console with database-backed sessions (5038084e)
- identity: authenticate console sign-ins with a lockout (945b6483)
- identity: verify legacy hashes and enforce password history (4cab28cf)
- common: add SHA-256 digest helpers (34507f74)
- web: add the first-run setup page (b45ffca4)
- identity: add the first-run setup API (665a0a9a)
- server: publish non-null record fields as required in the contract (7ba8d3f0)
- identity: add tenants, user accounts and platform settings (98ec79fd)
- persistence: allow entities to assign their ID before persisting (c31c00b4)
- server: expose health probes and Prometheus metrics (53896904)
- web: translate every console page into English (ea3ac97f)
- web: translate the console shell into Chinese and English (2013a5f3)
- server: localize problem details for the request language (3ca52599)
- web: understand RFC 9457 errors and send the CSRF token (78072a92)
- api: publish the OpenAPI contract shared by server and console (a5e5427b)
- server: connect to the configured database through Liquibase (0569f310)
- persistence: apply portable Hibernate defaults (fa71bb4e)
- persistence: isolate tenant data with fail-closed filtering (f4c59f24)
- persistence: enforce portable table and column names (598485fc)
- persistence: batch IN clause parameters to at most 1000 values (bc1195b9)
- persistence: add BaseEntity with TSID keys and optimistic locking (6208e23b)
- persistence: generate time-sorted 64-bit IDs (TSID) (0d3925ac)
- server: return RFC 9457 problem details for every error (faaba7b8)
- server: correlate every request with a request ID (1c325e02)
- common: add null-safe strings, error codes and pagination models (ce6a0e7a)
- web: replace native controls with custom themed components (b1c614d7)
- web: rebuild workspace with Vue 3 and Tailwind CSS (d92faa4e)
- database: add automatic versioned schema upgrades (7f39db9a)
问题修复
- plugin-host: load only installable plugin modules from the sources (3796c313)
- identity: page accounts without Optional.get (b7c3c9af)
- script: find the MySQL driver version the tests resolve (035ed023)
- docs: publish the site under grantforge.devlive.org (05917d40)
- plugin-host: refuse plugin calls from an interrupted caller (b5397be7)
- persistence: map SQL Server long text through its LOB type (87b8f0aa)
- persistence: expect Unicode long text on SQL Server (ba3f7ec8)
- script: track the server by its pid file and stop it gracefully (5ac398ed)
- make the schema work on MySQL, MariaDB, Oracle and SQL Server (a4e22f8d)
- clear the pmd and spotbugs findings left in recent modules (776f10d4)
- satisfy checkstyle and spotbugs in recent modules (6306289b)
- let roles alone decide who may manage roles, grants and tenants (8c213563)
- satisfy Checkstyle and PMD in the plugin API (c7586c1f)
- release: keep the server log when starting in the background (934b0e9e)
- web: fetch a fresh CSRF token before state-changing calls (f320654d)
- server: store console sessions portably on every database (64836184)
- persistence: create boolean columns as BIT(1) on MySQL and MariaDB (9b6886c7)
- test: keep the shared database harness within the quality gates (d4fa73c2)
- web: keep focus on the pagination buttons while a page loads (3e40a6a2)
- script: keep packaged defaults when loading external configuration (d8a9e1f8)
- web: keep focus on the page size selector while a page loads (42070481)
- script: resolve ShellCheck findings in deployment scripts (aadbc121)
- menu: repair permission trees and workspace API contracts (fc1b6c5e)
性能
- authz: work out snapshots in read-only transactions (e8495593)
- identity: index account search with trigrams on PostgreSQL (d7b64224)
- page accounts along an index and look the console up once (b6cd8ece)
- share prepared catalogs between authorization snapshots (2abea35c)
- keep each user's permissions until what they depend on changes (295e50ab)
重构
- keep plugin code in the root plugins directory (470bc907)
- remove the console pages left over from the old API (5a5b68f7)
- persistence: share portable column types between changelogs (c1647772)
- test: share the multi-database harness through test-support (924e3505)
- arch: use a boolean literal in the native query check (e28e6bec)
- ci: extract shared glob and rule helpers into cilib (b1c9c97c)
- rename AuthX to GrantForge and refresh branding (84f83254)
文档
- rewrite the README in English with a Chinese edition (fcca96e6)
- rebuild the documentation site with Next.js and Tailwind (bca9052a)
- point repository links to devlive-community/grantforge (ef05d1c1)
测试
- web: stop writing a screenshot to a macOS-only path (58e70ffd)
- e2e: add full-stack acceptance tests against the packaged server (16cdc98e)
- web: cover every view and make the test mapping strict (dcd0f40e)
- web: cover the auth store, router guards and bootstrap (f0c6dd43)
- web: cover the shared components, toast store and formatters (866f764c)
- persistence: verify the persistence foundation on every database (82e7ac0f)
- arch: forbid native SQL and entities in API code (b02f71b9)
- arch: enforce shared architecture rules with ArchUnit (7ffa1fab)
构建与 CI
- accept the licences of the Javadoc build plugin (548b03ee)
- accept the licences of Hadoop's shaded protobuf (fd9dace5)
- skip the release bundles in the database tests (f7ab3895)
- publish the Maven artifacts of a release (4b3b27c4)
- check commit messages after a force push (455193b7)
- accept the Bouncy Castle licence in dependency review (607b6a8b)
- unpack the bundled HDFS plugin when packaging the server (1437ec52)
- ignore the RFC 6238 test vector in the secret scan (01e7cc07)
- install pnpm where the distribution is packaged (2bf06ac5)
- publish releases from version tags (f360add6)
- accept the permissive licenses of two documentation packages (f230659c)
- lint Helm charts with a pinned Helm (bf21b40e)
- refuse changelog column types that are not portable (24ae7dab)
- check that the permission manifest matches the API and the console (5f8bd923)
- check message bundles of every module (580fdbbe)
- check that translations are complete and in use (0f4003f6)
- web: check indexed access and forbid non-null assertions (c5805a30)
- pin jackson-databind 2.21.7 for Jackson 2 advisories (dde0115a)
- guard Liquibase changelog IDs and released changelogs (a506a231)
- require license headers in Spring Boot .imports files (5ea88a8c)
- add PMD with a curated rule set for production code (c6a4708c)
- scan Maven dependencies from a CycloneDX SBOM (578d82d2)
- enforce JaCoCo line and branch coverage per module (4d9234a6)
- require Javadoc on public production types and methods (c223fbe2)
- replace the legacy backend with a Spring Boot 4.1 skeleton (223a12dd)
- run every CI step through scripts under script/ci (792a24c9)
- add security workflow with CodeQL and dependency review (739860ad)
- add secret and vulnerable dependency scanning scripts (106261a3)
- skip bot-authored commits in the commit message check (864543d6)
- enforce UTF-8, LF, final newline and whitespace rules (6a2330d6)
- lint shell scripts, Python and workflows with pinned tools (b6675c63)
- move documentation publishing into a script (26cc56e5)
- require a unit test file for every source file (ef8ce587)
- validate conventional commit messages on push and pull request (cea1d0cc)
- block private memory, build output and secrets from commits (e427e03c)
- add license header checker with unit tests (c755ef42)
- add Java 8 and newer compatibility checks (ed48e6c5)
其他
- hdfs: clear the Error Prone warnings of the HDFS plugin (92aabb17)
- ignore local Vitest reporter output (310b79fa)
- brand: refresh the GrantForge logo and remove the unused old logo (6d1ffc70)
- add missing final newlines to source and doc files (753369cc)
- license: apply MIT license headers to all source files (6ca9c8b5)
- relicense project under the MIT License (868b5f11)
- 重构导航栏 (8bb66b72)
- 重构登录页面 (6819695a)
- 更新 SQL 文件 (2d77c63e)
- 合并系统接口到菜单模块 (faa44714)
- 支持渲染静态资源 (479407e1)