Skip to content

baseplate@0.6.19

Choose a tag to compare

@github-actions github-actions released this 06 Sep 22:48
· 12 commits to main since this release
Immutable release. Only release title and notes can be modified.
a139b7a

Patch Changes

  • #1036 0a595f4 Thanks @kingston! - Generated tsconfigs now set moduleResolution to nodenext to match their module setting.

  • #1042 9c2117d Thanks @kingston! - Template extraction now fails when a template declares a projectExports entry that its source file no longer exports, naming the template, symbol and file, so renaming or deleting an export no longer leaves a stale entry that breaks an unrelated generator later. Configuring a template's exports now records a default export as exportedAs: 'default' rather than silently dropping it.

  • #1032 daef666 Thanks @kingston! - Database-backed test suites now create each worker's database once per run instead of checking for it before every test file, and raise the default test timeout to 15s so tests are not failed by a contended CI database.

  • #1030 e5c3315 Thanks @kingston! - Template extraction now resolves imports of a generated sibling package back to the import provider that owns them, and skips files the project has snapshotted as diverged, so apps sourcing their UI components from a shared library can have their templates extracted. The generated email service and notification email channel no longer carry /* TPL_* */ marker comments.

  • #1033 4805d5a Thanks @kingston! - Generated backends now derive signing keys per purpose from a single APP_SECRET, so features needing signed tokens no longer each provision a secret of their own, and secrets retired into APP_SECRET_PREVIOUS keep verifying so rotating does not invalidate values already issued. APP_SECRET is required: set it in every deployed environment before upgrading, or the app will fail to start.

  • #1035 2671e93 Thanks @kingston! - Each app now carries its own public URL, and the backend reads them through getApiUrl, getWebUrl and getWebOrigins, so anything minting an absolute link names the client it means rather than declaring a URL setting of its own. ALLOWED_ORIGINS and AUTH_FRONTEND_URL are gone: set API_URL and a WEB_URL_<APP> per web app before upgrading, or the app will fail to start, plus ADDITIONAL_WEB_ORIGINS for any trusted origin that is not an app in the project.

  • #1042 9c2117d Thanks @kingston! - The auth hook that returns the signed-in user id is now consistently useUserIdOrThrow in use-user-id-or-throw.ts across Better Auth, local auth and placeholder auth, following Prisma's OrThrow naming; Better Auth apps should rename their imports of useRequiredUserId. Import maps for auth context, password reset and Stripe billing no longer offer symbols that the generated files stopped exporting.

  • #1043 840dcb3 Thanks @kingston! - The generated backend now uses fastify 5.12.1 and Prisma 7.10.0, which carry security fixes for request schema validation, proxy header handling, and Prisma Studio's local server binding.

  • #1031 616d2f5 Thanks @kingston! - Authorization expressions can now compare an optional field against null (e.g. model.engagementEffectiveAt !== null), including as an exists()/all() condition value, so presence-gated rules no longer have to be hand-written. Comparing a required field, or a json field, against null is flagged as a warning.

  • #1035 2671e93 Thanks @kingston! - Guesses at an emailed verification code are now counted before the code is compared, so a burst of concurrent guesses can no longer exceed the code's attempt budget, and simultaneous guesses no longer surface a Prisma error or discard a code another request is still redeeming. Every validation spends an attempt, including a correct one.

  • #1048 00800a2 Thanks @kingston! - Generated apps no longer depend on sonner: toasts come from a Base UI toast.tsx component that the app owns, which stacks, swipes to dismiss, announces errors assertively, and sits bottom-right instead of top-center. Code that imported toast from 'sonner' should import it from the generated components instead (@/components/ui/toast, or the shared component library in library mode).

  • #1034 902e8ae Thanks @kingston! - Auth now derives its signing keys from APP_SECRET instead of AUTH_SECRET and BETTER_AUTH_SECRET, which are no longer read and can be dropped from your environment. Upgrading signs existing users out and invalidates outstanding one-time codes.

  • #1038 74ae3ed Thanks @kingston! - Password reset and email verification links now point back to the app the request came from, so a reset started on the admin console emails an admin console link instead of always linking to the project's default web app; a request from an unrecognised origin still falls back to that default. Invite links are unchanged.

  • #1036 0a595f4 Thanks @kingston! - Accepting an invite no longer replaces the password of an account that registered after the invite was sent; the accept-invite page now tells that user to sign in instead.

  • #1028 94d84c1 Thanks @kingston! - Signing in, signing out, and session changes from another tab no longer unmount the app, so the previous screen no longer flashes before the new one and page state survives the transition.

  • #1041 5fe4f0a Thanks @kingston! - Editing a component, hook, or service in a generated web app now updates the page in place instead of rebuilding the router and remounting the whole app, so your route, scroll position, and open subscriptions survive a save. Sentry is now initialised from main.tsx via initSentry(router) rather than importing the router itself.

  • #1040 6a5a1bf Thanks @kingston! - Backends now generate an in-memory email adapter, so a test can assert on the message a provider would have received — its rendered subject, body and headers — instead of mocking the send call.

  • #1040 6a5a1bf Thanks @kingston! - Notification emails now carry one-click List-Unsubscribe headers, backed by a signed endpoint that turns email off for the topics that email covered; a notification belonging to no topic carries no header, since the user cannot switch it off.

  • #1044 9e622b6 Thanks @kingston! - New projects' default dark-mode popover background now matches the card background, an elevated shade above the page background, rather than being indistinguishable from it.

  • #1045 36f7701 Thanks @kingston! - Page titles, empty states and help text now come from shared components rather than one-off classes, so headings and descriptions are consistent across settings, packages and data pages.

  • #1039 fc4a2b1 Thanks @kingston! - Rendered markdown and HTML now get their typography from a typeset class that sizes to its container, replacing the global h1-h3/p rules and the text-style-* utilities, so headings outside typeset need their own text utilities. New PageHeader and Section components cover page and section titles with overridable heading levels, an inline-link utility gives links in ordinary copy the same styling typeset gives links inside it, and generated card components now also export CardAction.

  • #1044 9e622b6 Thanks @kingston! - Generated apps now define --radius and its full size scale, so components like InputGroup that depend on it render with the correct corner radius instead of square corners. Fixed the dark variant matcher to also activate on a bare .dark class, ported the Sidebar/Badge/Alert tone and pointer-cursor fixes from ui-components, and switched the root layout from a fixed 100vh to min-height: 100dvh.

  • #1046 57e356a Thanks @kingston! - Generated components are now caught up with current shadcn Base UI, so inputs, cards, calendars, radio groups and dialogs pick up upstream's refreshed sizing, radii and range styling, and controls fill with a new --control-background token that flips with the surface beneath them instead of always matching the page. Alert gains an AlertAction slot for a dismiss or retry control, and ButtonGroup gains a vertical orientation plus ButtonGroupText and ButtonGroupSeparator, matching upstream; it now squares off only children that set a data-slot, so a plain wrapper between buttons keeps its own corners. Components that deliberately differ from shadcn now say so inline.

  • #1047 2299376 Thanks @kingston! - Text-entry and button-like controls (Input, Textarea, InputGroup, InputOtp, NumberField, Combobox, Autocomplete, Select) now accept an optional size of sm, default or xl, and Button gains xl and icon-xl. xl renders single-line controls at 44px with larger text; omitting size leaves every control looking exactly as it does today.

  • #1044 9e622b6 Thanks @kingston! - Fixed a shadow rule on Sidebar's outline button variant that silently no-opped against oklch tokens, renamed the surface-* status-color utilities to tone-* (freeing "surface" for background/card/popover), added tone-success/tone-warning variants to Badge, and gave buttons a pointer cursor by default. Alert's border now tints with its variant instead of always rendering the default border color. Removed remaining literal bg-white/bg-black colors from Slider, ColorPickerField, Dialog, and Sheet.

  • #1048 00800a2 Thanks @kingston! - Toasts are now built on Base UI instead of sonner: they stack bottom-right, swipe to dismiss and announce errors assertively. The toast facade takes the message first with optional description, actionProps, priority, timeout and id, and Toaster now takes Base UI provider props, so sonner options such as position, closeButton and action no longer apply.