Skip to content

Enfyra Server v2.0.0

Choose a tag to compare

@dothinh115 dothinh115 released this 19 Apr 04:30

Enfyra Server v2.0.0

Breaking Changes

NestJS replaced by Awilix + Express 5. The entire framework has been migrated from NestJS 11 to Awilix 13 DI with a plain Express 5 server. All *.module.ts files are deleted; DI is now wired in src/container.ts. Packages @nestjs/*, passport, passport-jwt, and rxjs have been removed. Deployments that extend or import any NestJS module from the server source will break. Migration: drop external NestJS module wiring; reference services via constructor injection from container.ts.

DB_TYPE env var removed. Database type is now auto-detected from the protocol prefix of DB_URI. Remove DB_TYPE from your .env; DB_URI is now mandatory and validated at startup.

MONGO_URI env var removed. MongoDB connections must be configured via DB_URI=mongodb://....

$dispatch renamed to $trigger in hook/handler context. The macro @DISPATCH becomes @TRIGGER; the method $ctx.$dispatch becomes $ctx.$trigger. Existing hook or handler scripts calling $ctx.$dispatch(...) will throw a runtime error. Update all logic scripts to use $ctx.$trigger(...).

Dev script renamed. yarn start:dev is replaced by yarn dev (uses tsx watch instead of the NestJS CLI). Update any CI pipeline or shell script that invokes start:dev.


Features

  • Added skipRoleGuardMethods field to route_definition, allowing specific HTTP methods on a route to bypass the role guard while still requiring a valid JWT.
  • Added gql_definition table and GraphQLDefinitionProcessor enabling per-table opt-in GraphQL exposure via the isEnabled flag — GraphQL is now disabled by default for new tables.
  • Added cors_origin_definition table and /cors_origin_definition endpoint for managing CORS origins at runtime, replacing the removed corsAllowedOrigins field on setting_definition.
  • Added schema_migration_definition system table to persist migration journal state across all DB engines, enabling structured audit and crash recovery.
  • Implemented BatchFetchEngine for MongoDB in MongoQueryExecutor — flat batch + JS grouping at parity with the SQL path.
  • Added filter operator _is_not_null and confirmed cross-DB support for _gt, _gte, _lt, _lte on relation fields.
  • Added unknown-field and unknown-filter validation in field-parser.ts and filter-parser.ts — requests referencing nonexistent fields or unsupported _-prefixed operators now return 400 with the list of supported operators.
  • Implemented UserRevocationService with Redis pub/sub to propagate JWT revocation across all instances when a user is updated.
  • Added Lua-script-backed atomic sliding window to RateLimitService, reducing Redis round trips; response now includes window and limit fields.
  • Added Zod env validation at startup in src/env.ts — invalid or missing required env vars now crash with a descriptive message instead of silently failing later.
  • Added DEV_WATCH=1 env flag set automatically by yarn dev and yarn debug, skipping the graceful shutdown handler so tsx watch restarts cleanly.
  • Added RouteDefinitionProcessor.ensureMissingHandlers to auto-create default CRUD handlers for enabled routes that have none.
  • Added chunked fetching in the SQL BatchRelationFetcher to avoid oversized IN clauses on wide relation sets.

Bug Fixes

  • Fixed foreign key columns leaking into parent document responses in BatchFetchEngine when not part of the requested field set.
  • Fixed refresh token rotation to use refreshTokenHash comparison on both SQL and MongoDB, closing a replay-attack window on concurrent refresh requests.
  • Fixed ReplicationManager triggering MongoDB initialization on SQL-only deployments.
  • Fixed SQL foreign key DDL bindings in foreign-key-operations.ts and sql-dialect.ts (Expected 2 bindings, saw 0 on Postgres).
  • Fixed BaseCacheService triggering an additional reload when an in-progress load was already running.
  • Fixed MetadataCacheService MongoDB ID filtering to use ObjectId comparisons correctly for table and column definitions.
  • Fixed schema migration recovery to restore MongoDB metadata from raw snapshots when a DDL step fails after the metadata write.
  • Fixed MigrationJournalService to mark stale entries as failed (not pending) during boot recovery, preventing infinite retry loops.
  • Improved DynamicService to return structured error responses instead of unhandled promise rejections on hook execution failures.
  • Removed MySQL-specific connection pool overrides that produced incorrect pool sizing on multi-replica setups.
  • Fixed FlowCacheService.getFlowById to accept string IDs (resolves MongoDB ObjectId lookups).