Skip to content

GrantForge 2026.0.0

Latest

Choose a tag to compare

@github-actions github-actions released this 05 Oct 15:19
· 23 commits to dev since this release
1980841

完整变更:1.0.6...v2026.0.0,共 194 个提交。

不兼容变更

  • rename AuthX to GrantForge and refresh branding (84f83254)
  • replace the legacy backend with a Spring Boot 4.1 skeleton (223a12dd)

新功能

  • release: cut releases with one script and list their commits (362546cc)
  • hdfs: add the NameNode agent for Hadoop 3.5.0 (1445466e)
  • agent: let agents credit GrantForge for a strict default deny (0c109094)
  • hdfs: bound path lookups and validate cluster settings (1d20eac3)
  • hdfs: talk to clusters with Hadoop's client like Apache Ranger (02bd6d1a)
  • plugin-host: load the repository's plugins when run from sources (43591418)
  • hdfs: add the HDFS service type plugin shipped with the release (e8b651b7)
  • agent: add the agent core that keeps policies current in systems (f7be272e)
  • import accounts, roles and menus from a 1.x database (169ea055)
  • web: drop the JSON workbench from the console (18a7f0ba)
  • deploy with a Docker image, Compose examples and a Helm chart (cb013c07)
  • benchmark authorization and list APIs at a million accounts (57654a40)
  • review who holds roles in periodic access reviews (a0823d40)
  • let users ask for roles that approvers grant for a while (07b8790a)
  • keep apart roles nobody may hold together (d8fa25b2)
  • let users sign in with OpenID Connect providers (b77f314f)
  • let users sign in with LDAP directories (8438c977)
  • add two-step sign-in with authenticator apps (3254a92c)
  • add sample applications and integration guides (29b7eccc)
  • add a JavaScript client with Vue directives (5581d99d)
  • let applications apply data policies to their own rows (68e45ab5)
  • add a Spring Boot starter for applications (1f428395)
  • let applications ask what their users may do (d7e72122)
  • sign users in to applications with OpenID Connect (2f58406a)
  • register OAuth clients of catalog applications (01d6b14c)
  • search and export the audit log (cf6a8bea)
  • record permission changes with them and keep audit append-only (e8b50fca)
  • simulate what an account would gain or lose (01b68209)
  • show a user's effective permissions and why (f645830b)
  • answer and explain what accounts may use (c71ea138)
  • set a role's field permissions in the console (f1c7cf04)
  • refuse changes of read-only secured fields (a2f0fe50)
  • hide and mask secured fields as roles' field policies say (30aa2420)
  • register the secured fields APIs return and accept (2891ce2a)
  • keep built-in lists to readers' data permissions (ad97b40d)
  • set a role's data permissions in the console (6d766bfc)
  • limit rows to what readers' data policies allow (2bf42cd4)
  • give roles data policies with checked conditions (c0515e78)
  • let entities declare themselves under data permissions (b52e39a5)
  • keep the plugin API compatible and prove it with an example (47de7d26)
  • keep what agents decided and let the console search it (16976c4e)
  • hand agents signed policy snapshots for their service (55ed41eb)
  • write access, masking and row filter policies for services (e22381da)
  • register data services, with their secrets encrypted (01cd7bd4)
  • decide access requests against policies in a Java 8 engine (7649d756)
  • load service type plugins, each in its own class loader (0e4b772f)
  • show what a change would do before it is made (f7c95b26)
  • let roles inherit from other roles (1c3c4e5f)
  • check the catalog for settings that silently do not work (b9b1abaf)
  • show each user only the pages and buttons they may use (bde4ab68)
  • refuse API calls the caller has no permission for (ff753df5)
  • work out each user's permissions from all of their roles (82274c83)
  • grant pages, buttons and APIs to roles (38619909)
  • give roles to users, groups, departments and positions (a394a436)
  • manage the roles of a tenant (521f6430)
  • declare the console's pages and buttons in a permission manifest (36727158)
  • record what pages and buttons need to work (c88c709c)
  • register every API endpoint and its permission at start-up (43adbb11)
  • maintain the resource catalog of each application (aa35b34e)
  • define the plugin API for service types (139d36c5)
  • import and export accounts and departments as CSV (58d6d37c)
  • maintain positions and give them to accounts (ae8a7775)
  • group accounts into user groups (64dc6376)
  • let visitors register their own account when enabled (7869e08a)
  • manage the accounts of a tenant (b96939a9)
  • maintain each tenant's organization tree (dd0641ef)
  • let platform administrators manage tenants (5a2905d6)
  • audit console sign-ins and show the login history (b2a8dac2)
  • edit the profile and change the password from an account page (17fdb64e)
  • list and end console sessions (98ed2178)
  • show console pages from the signed-in user's authorization (495fa1c5)
  • web: sign in with the server session instead of a token (9269e778)
  • server: sign in to the console with database-backed sessions (5038084e)
  • identity: authenticate console sign-ins with a lockout (945b6483)
  • identity: verify legacy hashes and enforce password history (4cab28cf)
  • common: add SHA-256 digest helpers (34507f74)
  • web: add the first-run setup page (b45ffca4)
  • identity: add the first-run setup API (665a0a9a)
  • server: publish non-null record fields as required in the contract (7ba8d3f0)
  • identity: add tenants, user accounts and platform settings (98ec79fd)
  • persistence: allow entities to assign their ID before persisting (c31c00b4)
  • server: expose health probes and Prometheus metrics (53896904)
  • web: translate every console page into English (ea3ac97f)
  • web: translate the console shell into Chinese and English (2013a5f3)
  • server: localize problem details for the request language (3ca52599)
  • web: understand RFC 9457 errors and send the CSRF token (78072a92)
  • api: publish the OpenAPI contract shared by server and console (a5e5427b)
  • server: connect to the configured database through Liquibase (0569f310)
  • persistence: apply portable Hibernate defaults (fa71bb4e)
  • persistence: isolate tenant data with fail-closed filtering (f4c59f24)
  • persistence: enforce portable table and column names (598485fc)
  • persistence: batch IN clause parameters to at most 1000 values (bc1195b9)
  • persistence: add BaseEntity with TSID keys and optimistic locking (6208e23b)
  • persistence: generate time-sorted 64-bit IDs (TSID) (0d3925ac)
  • server: return RFC 9457 problem details for every error (faaba7b8)
  • server: correlate every request with a request ID (1c325e02)
  • common: add null-safe strings, error codes and pagination models (ce6a0e7a)
  • web: replace native controls with custom themed components (b1c614d7)
  • web: rebuild workspace with Vue 3 and Tailwind CSS (d92faa4e)
  • database: add automatic versioned schema upgrades (7f39db9a)

问题修复

  • plugin-host: load only installable plugin modules from the sources (3796c313)
  • identity: page accounts without Optional.get (b7c3c9af)
  • script: find the MySQL driver version the tests resolve (035ed023)
  • docs: publish the site under grantforge.devlive.org (05917d40)
  • plugin-host: refuse plugin calls from an interrupted caller (b5397be7)
  • persistence: map SQL Server long text through its LOB type (87b8f0aa)
  • persistence: expect Unicode long text on SQL Server (ba3f7ec8)
  • script: track the server by its pid file and stop it gracefully (5ac398ed)
  • make the schema work on MySQL, MariaDB, Oracle and SQL Server (a4e22f8d)
  • clear the pmd and spotbugs findings left in recent modules (776f10d4)
  • satisfy checkstyle and spotbugs in recent modules (6306289b)
  • let roles alone decide who may manage roles, grants and tenants (8c213563)
  • satisfy Checkstyle and PMD in the plugin API (c7586c1f)
  • release: keep the server log when starting in the background (934b0e9e)
  • web: fetch a fresh CSRF token before state-changing calls (f320654d)
  • server: store console sessions portably on every database (64836184)
  • persistence: create boolean columns as BIT(1) on MySQL and MariaDB (9b6886c7)
  • test: keep the shared database harness within the quality gates (d4fa73c2)
  • web: keep focus on the pagination buttons while a page loads (3e40a6a2)
  • script: keep packaged defaults when loading external configuration (d8a9e1f8)
  • web: keep focus on the page size selector while a page loads (42070481)
  • script: resolve ShellCheck findings in deployment scripts (aadbc121)
  • menu: repair permission trees and workspace API contracts (fc1b6c5e)

性能

  • authz: work out snapshots in read-only transactions (e8495593)
  • identity: index account search with trigrams on PostgreSQL (d7b64224)
  • page accounts along an index and look the console up once (b6cd8ece)
  • share prepared catalogs between authorization snapshots (2abea35c)
  • keep each user's permissions until what they depend on changes (295e50ab)

重构

  • keep plugin code in the root plugins directory (470bc907)
  • remove the console pages left over from the old API (5a5b68f7)
  • persistence: share portable column types between changelogs (c1647772)
  • test: share the multi-database harness through test-support (924e3505)
  • arch: use a boolean literal in the native query check (e28e6bec)
  • ci: extract shared glob and rule helpers into cilib (b1c9c97c)
  • rename AuthX to GrantForge and refresh branding (84f83254)

文档

  • rewrite the README in English with a Chinese edition (fcca96e6)
  • rebuild the documentation site with Next.js and Tailwind (bca9052a)
  • point repository links to devlive-community/grantforge (ef05d1c1)

测试

  • web: stop writing a screenshot to a macOS-only path (58e70ffd)
  • e2e: add full-stack acceptance tests against the packaged server (16cdc98e)
  • web: cover every view and make the test mapping strict (dcd0f40e)
  • web: cover the auth store, router guards and bootstrap (f0c6dd43)
  • web: cover the shared components, toast store and formatters (866f764c)
  • persistence: verify the persistence foundation on every database (82e7ac0f)
  • arch: forbid native SQL and entities in API code (b02f71b9)
  • arch: enforce shared architecture rules with ArchUnit (7ffa1fab)

构建与 CI

  • accept the licences of the Javadoc build plugin (548b03ee)
  • accept the licences of Hadoop's shaded protobuf (fd9dace5)
  • skip the release bundles in the database tests (f7ab3895)
  • publish the Maven artifacts of a release (4b3b27c4)
  • check commit messages after a force push (455193b7)
  • accept the Bouncy Castle licence in dependency review (607b6a8b)
  • unpack the bundled HDFS plugin when packaging the server (1437ec52)
  • ignore the RFC 6238 test vector in the secret scan (01e7cc07)
  • install pnpm where the distribution is packaged (2bf06ac5)
  • publish releases from version tags (f360add6)
  • accept the permissive licenses of two documentation packages (f230659c)
  • lint Helm charts with a pinned Helm (bf21b40e)
  • refuse changelog column types that are not portable (24ae7dab)
  • check that the permission manifest matches the API and the console (5f8bd923)
  • check message bundles of every module (580fdbbe)
  • check that translations are complete and in use (0f4003f6)
  • web: check indexed access and forbid non-null assertions (c5805a30)
  • pin jackson-databind 2.21.7 for Jackson 2 advisories (dde0115a)
  • guard Liquibase changelog IDs and released changelogs (a506a231)
  • require license headers in Spring Boot .imports files (5ea88a8c)
  • add PMD with a curated rule set for production code (c6a4708c)
  • scan Maven dependencies from a CycloneDX SBOM (578d82d2)
  • enforce JaCoCo line and branch coverage per module (4d9234a6)
  • require Javadoc on public production types and methods (c223fbe2)
  • replace the legacy backend with a Spring Boot 4.1 skeleton (223a12dd)
  • run every CI step through scripts under script/ci (792a24c9)
  • add security workflow with CodeQL and dependency review (739860ad)
  • add secret and vulnerable dependency scanning scripts (106261a3)
  • skip bot-authored commits in the commit message check (864543d6)
  • enforce UTF-8, LF, final newline and whitespace rules (6a2330d6)
  • lint shell scripts, Python and workflows with pinned tools (b6675c63)
  • move documentation publishing into a script (26cc56e5)
  • require a unit test file for every source file (ef8ce587)
  • validate conventional commit messages on push and pull request (cea1d0cc)
  • block private memory, build output and secrets from commits (e427e03c)
  • add license header checker with unit tests (c755ef42)
  • add Java 8 and newer compatibility checks (ed48e6c5)

其他

  • hdfs: clear the Error Prone warnings of the HDFS plugin (92aabb17)
  • ignore local Vitest reporter output (310b79fa)
  • brand: refresh the GrantForge logo and remove the unused old logo (6d1ffc70)
  • add missing final newlines to source and doc files (753369cc)
  • license: apply MIT license headers to all source files (6ca9c8b5)
  • relicense project under the MIT License (868b5f11)
  • 重构导航栏 (8bb66b72)
  • 重构登录页面 (6819695a)
  • 更新 SQL 文件 (2d77c63e)
  • 合并系统接口到菜单模块 (faa44714)
  • 支持渲染静态资源 (479407e1)