Enfyra Server v2.0.0
Enfyra Server v2.0.0
Breaking Changes
NestJS replaced by Awilix + Express 5. The entire framework has been migrated from NestJS 11 to Awilix 13 DI with a plain Express 5 server. All *.module.ts files are deleted; DI is now wired in src/container.ts. Packages @nestjs/*, passport, passport-jwt, and rxjs have been removed. Deployments that extend or import any NestJS module from the server source will break. Migration: drop external NestJS module wiring; reference services via constructor injection from container.ts.
DB_TYPE env var removed. Database type is now auto-detected from the protocol prefix of DB_URI. Remove DB_TYPE from your .env; DB_URI is now mandatory and validated at startup.
MONGO_URI env var removed. MongoDB connections must be configured via DB_URI=mongodb://....
$dispatch renamed to $trigger in hook/handler context. The macro @DISPATCH becomes @TRIGGER; the method $ctx.$dispatch becomes $ctx.$trigger. Existing hook or handler scripts calling $ctx.$dispatch(...) will throw a runtime error. Update all logic scripts to use $ctx.$trigger(...).
Dev script renamed. yarn start:dev is replaced by yarn dev (uses tsx watch instead of the NestJS CLI). Update any CI pipeline or shell script that invokes start:dev.
Features
- Added
skipRoleGuardMethodsfield toroute_definition, allowing specific HTTP methods on a route to bypass the role guard while still requiring a valid JWT. - Added
gql_definitiontable andGraphQLDefinitionProcessorenabling per-table opt-in GraphQL exposure via theisEnabledflag — GraphQL is now disabled by default for new tables. - Added
cors_origin_definitiontable and/cors_origin_definitionendpoint for managing CORS origins at runtime, replacing the removedcorsAllowedOriginsfield onsetting_definition. - Added
schema_migration_definitionsystem table to persist migration journal state across all DB engines, enabling structured audit and crash recovery. - Implemented
BatchFetchEnginefor MongoDB inMongoQueryExecutor— flat batch + JS grouping at parity with the SQL path. - Added filter operator
_is_not_nulland confirmed cross-DB support for_gt,_gte,_lt,_lteon relation fields. - Added unknown-field and unknown-filter validation in
field-parser.tsandfilter-parser.ts— requests referencing nonexistent fields or unsupported_-prefixed operators now return400with the list of supported operators. - Implemented
UserRevocationServicewith Redis pub/sub to propagate JWT revocation across all instances when a user is updated. - Added Lua-script-backed atomic sliding window to
RateLimitService, reducing Redis round trips; response now includeswindowandlimitfields. - Added Zod env validation at startup in
src/env.ts— invalid or missing required env vars now crash with a descriptive message instead of silently failing later. - Added
DEV_WATCH=1env flag set automatically byyarn devandyarn debug, skipping the graceful shutdown handler sotsx watchrestarts cleanly. - Added
RouteDefinitionProcessor.ensureMissingHandlersto auto-create default CRUD handlers for enabled routes that have none. - Added chunked fetching in the SQL
BatchRelationFetcherto avoid oversizedINclauses on wide relation sets.
Bug Fixes
- Fixed foreign key columns leaking into parent document responses in
BatchFetchEnginewhen not part of the requested field set. - Fixed refresh token rotation to use
refreshTokenHashcomparison on both SQL and MongoDB, closing a replay-attack window on concurrent refresh requests. - Fixed
ReplicationManagertriggering MongoDB initialization on SQL-only deployments. - Fixed SQL foreign key DDL bindings in
foreign-key-operations.tsandsql-dialect.ts(Expected 2 bindings, saw 0on Postgres). - Fixed
BaseCacheServicetriggering an additional reload when an in-progress load was already running. - Fixed
MetadataCacheServiceMongoDB ID filtering to useObjectIdcomparisons correctly for table and column definitions. - Fixed schema migration recovery to restore MongoDB metadata from raw snapshots when a DDL step fails after the metadata write.
- Fixed
MigrationJournalServiceto mark stale entries asfailed(notpending) during boot recovery, preventing infinite retry loops. - Improved
DynamicServiceto return structured error responses instead of unhandled promise rejections on hook execution failures. - Removed MySQL-specific connection pool overrides that produced incorrect pool sizing on multi-replica setups.
- Fixed
FlowCacheService.getFlowByIdto accept string IDs (resolves MongoDBObjectIdlookups).