Repository navigation
Release v0.19.1
Changes since v0.19.0.
Catalog change tracking, CSP enforcement in dev mode, and an auth deadlock fix. Migration 032 runs automatically at startup.
Catalog change tracking (Delta CDF)
Catalog tables can now track row-level changes (#753). Enable change tracking on a catalog writer, and a catalog reader can read only what changed — inserts, updates, and deletes — via Delta Lake's change data feed.
- Writer:
track_changestoggle enables the feed. Works with append, upsert, update, delete, and merge write modes. - Reader: four modes — full table (default),
since_last_run(cursor-based),since_version, orsince_timestamp. Version and timestamp fields accept${param}references. - Cursors advance only on a completed flow run — delivery is at-least-once, so downstream writers should upsert. Named cursors let multiple pipelines share a position.
- Python API:
read_catalog_table(..., changes_since="last_run")or pass an int/datetime. Writer:write_catalog_table(..., track_changes=True). - Frontend: mode selector on the reader drawer with cursor status and reset; CDC status on the table detail panel; "Track changes" checkbox on the writer.
- Code export covers all three dialects. Vacuum warns when cursors would be affected (409, overridable with
force).
The catalog reader drawer with cursor-based change tracking:
CSP enforcement in dev mode
The Tauri Content Security Policy is now enforced during development (#754).
- Vite dev/preview servers send the same CSP header as the packaged app (plus the HMR websocket). Violations now surface in dev, not just production.
- graphic-walker's CDN leaflet.css (blocked by
style-src 'self') is rewritten to a same-origin copy with build-time SRI validation. - New
csp.spec.tsE2E test verifies the header, zero-violation page loads, and same-origin stylesheet loading.
Bug fixes
- Auth deadlock (#755): auth dependencies were
async def, blocking the event loop with synchronous DB queries and freezing the server under concurrent requests. Nowdef(threadpool), with a 60s TTL user cache. SQLite engine tuned (larger pool, WAL mode) and shared process-wide. /catalog/runs500: attribute name typo in the access filter (result.runs→result.items) broke the endpoint in multi-user mode.- Node descriptions: descriptions are now resolved from settings and seeded from the initial payload, eliminating per-node round-trips on flow load.