Skip to content

Release v0.19.1

Choose a tag to compare

@Edwardvaneechoud Edwardvaneechoud released this 22 Sep 15:17
· 52 commits to main since this release

Changes since v0.19.0.

Catalog change tracking, CSP enforcement in dev mode, and an auth deadlock fix. Migration 032 runs automatically at startup.

Catalog change tracking (Delta CDF)

Catalog tables can now track row-level changes (#753). Enable change tracking on a catalog writer, and a catalog reader can read only what changed — inserts, updates, and deletes — via Delta Lake's change data feed.

  • Writer: track_changes toggle enables the feed. Works with append, upsert, update, delete, and merge write modes.
  • Reader: four modes — full table (default), since_last_run (cursor-based), since_version, or since_timestamp. Version and timestamp fields accept ${param} references.
  • Cursors advance only on a completed flow run — delivery is at-least-once, so downstream writers should upsert. Named cursors let multiple pipelines share a position.
  • Python API: read_catalog_table(..., changes_since="last_run") or pass an int/datetime. Writer: write_catalog_table(..., track_changes=True).
  • Frontend: mode selector on the reader drawer with cursor status and reset; CDC status on the table detail panel; "Track changes" checkbox on the writer.
  • Code export covers all three dialects. Vacuum warns when cursors would be affected (409, overridable with force).

The catalog reader drawer with cursor-based change tracking:

Catalog reader with change tracking

CSP enforcement in dev mode

The Tauri Content Security Policy is now enforced during development (#754).

  • Vite dev/preview servers send the same CSP header as the packaged app (plus the HMR websocket). Violations now surface in dev, not just production.
  • graphic-walker's CDN leaflet.css (blocked by style-src 'self') is rewritten to a same-origin copy with build-time SRI validation.
  • New csp.spec.ts E2E test verifies the header, zero-violation page loads, and same-origin stylesheet loading.

Bug fixes

  • Auth deadlock (#755): auth dependencies were async def, blocking the event loop with synchronous DB queries and freezing the server under concurrent requests. Now def (threadpool), with a 60s TTL user cache. SQLite engine tuned (larger pool, WAL mode) and shared process-wide.
  • /catalog/runs 500: attribute name typo in the access filter (result.runs → result.items) broke the endpoint in multi-user mode.
  • Node descriptions: descriptions are now resolved from settings and seeded from the initial payload, eliminating per-node round-trips on flow load.