Skip to content

v0.2.0-M11

Pre-release
Pre-release

Choose a tag to compare

@ancongui ancongui released this 01 Mar 10:29
· 895 commits to main since this release

v0.2.0-M11 (2026-03-01)

Thread-safety, correctness, and robustness audit — 18 fixes across DI container, web layer, resilience, security, and data modules.

Fixed

  • Thread-safe singleton initialization: DI container now uses RLock with double-check pattern
  • Condition list inheritance: @conditional_on_* decorators prevent cross-class mutation via MRO
  • @transactional rollback_for semantics: Selective rollback matching Spring's @Transactional
  • SecurityException status code: Base SecurityException → 403; UnauthorizedException retains 401
  • @secure decorator: Authorization failures raise ForbiddenException (403)
  • Security context bridge: SecurityMiddleware bridges to RequestContext for @pre_authorize/@post_authorize
  • Lazy controller race condition: asyncio.Lock prevents duplicate bean resolution
  • Parameter coercion errors: _coerce() raises InvalidRequestException (HTTP 400)
  • Bulkhead TOCTOU: Consistent capacity tracking via _active counter
  • asyncio.get_event_loop() → get_running_loop() (3 sites)

Changed

  • Resilience sync/async support: All 4 decorators detect sync functions automatically
  • Event bus optimization: Pre-sorted listeners at subscribe time
  • Repository dynamic PK: find_all_by_ids()/delete_all() use sa_inspect instead of hardcoded .id
  • Nested repository patching: _patch_repositories() patches one level deep
  • Kahn's algorithm: deque for O(1) popleft
  • Auto-config logging: ImportError logged at DEBUG instead of swallowed
  • Filter chain: Fast path + 100MB body size guard

CI

  • Added missing --ignore for test_mongo_projection_query.py and test_mongo_query_compiler.py

Full Changelog: v0.2.0-M10...v0.2.0-M11