Repository navigation
v0.2.0-M11
Pre-release
Pre-release
v0.2.0-M11 (2026-03-01)
Thread-safety, correctness, and robustness audit — 18 fixes across DI container, web layer, resilience, security, and data modules.
Fixed
- Thread-safe singleton initialization: DI container now uses RLock with double-check pattern
- Condition list inheritance:
@conditional_on_*decorators prevent cross-class mutation via MRO @transactionalrollback_for semantics: Selective rollback matching Spring's@Transactional- SecurityException status code: Base
SecurityException→ 403;UnauthorizedExceptionretains 401 @securedecorator: Authorization failures raiseForbiddenException(403)- Security context bridge:
SecurityMiddlewarebridges toRequestContextfor@pre_authorize/@post_authorize - Lazy controller race condition:
asyncio.Lockprevents duplicate bean resolution - Parameter coercion errors:
_coerce()raisesInvalidRequestException(HTTP 400) - Bulkhead TOCTOU: Consistent capacity tracking via
_activecounter asyncio.get_event_loop()→get_running_loop()(3 sites)
Changed
- Resilience sync/async support: All 4 decorators detect sync functions automatically
- Event bus optimization: Pre-sorted listeners at subscribe time
- Repository dynamic PK:
find_all_by_ids()/delete_all()usesa_inspectinstead of hardcoded.id - Nested repository patching:
_patch_repositories()patches one level deep - Kahn's algorithm:
dequefor O(1) popleft - Auto-config logging:
ImportErrorlogged at DEBUG instead of swallowed - Filter chain: Fast path + 100MB body size guard
CI
- Added missing
--ignorefortest_mongo_projection_query.pyandtest_mongo_query_compiler.py
Full Changelog: v0.2.0-M10...v0.2.0-M11