URLCode 0.6.2
Immutable
release. Only release title and notes can be modified.
What's Changed
- feat(forms): conditional required fields with requiredWhen by @jimhoyd in #707
- fix(core): name the failing field in validation errors and keep extension RateLimit policies (#702, #696, #701) by @jimhoyd in #720
- feat: auth owns the auth: shorthand, extension activation errors, body-schema length cap, MCP tool errors and 2025-11-25 (#710, #714, #713, #716, #719) by @jimhoyd in #726
- feat: per-key quota, relative form date bounds, store-owned CRUD screen, capability-only extension installs (#703, #705, #709, #711) by @jimhoyd in #727
- fix(cli): extensions add/remove preserve YAML formatting; list --strict accepts library-only add-ons; add-on authoring rules (#715, #718, #712) by @jimhoyd in #728
- feat: operator alias origins for every same-origin check; release-pinned add-on agent catalog (#717, #721) by @jimhoyd in #730
- feat(store,core): per-record ownership via an opaque extension principal (#331) by @jimhoyd in #734
- feat(core): authoring fixture/diff tools, automatic host revision pin, clearer host and cache errors (#722, #723, #724, #725) by @jimhoyd in #735
- feat: per-owner store limits and reassign, user-linked API keys, shared passkey domain, include-aware authoring tools (#731, #732, #729, #733) by @jimhoyd in #737
- feat(form-records): new add-on saving a declared form into an owned store collection, with typed forms/store exports (#529) by @jimhoyd in #740
- docs: prefer tested first-party extensions and guide external AI integration by @jimhoyd in #742
- feat(forms,store,form-records): name off-page field errors; clear optional fields on edit; per-user list page (#739, #738) by @jimhoyd in #743
- feat(core,auth): operator-facing extension activation warnings; auth warns when stored passkeys don't match the relying-party ID (#736) by @jimhoyd in #747
- ci: add Windows and packed-integration legs to PRs that touch installer, manifest, release or integration paths (#744) by @jimhoyd in #748
- Add urlcode report: a read-only review page for a project or a change by @jimhoyd in #749
- Add urlcode studio: the review report served on localhost, rebuilt on every reload by @jimhoyd in #751
- Point readers at urlcode studio and the review report by @jimhoyd in #752
- refactor: split audit, abuse and mail into extensions; versioned auth/admin contract; core request helpers (#745, #746) by @jimhoyd in #754
- fix(ui): confine presentation files to the ui directory by @jimhoyd in #758
- Contribution provenance, full schema descriptions, worker teardown, host-aware MCP and agent-doc fixes (#753, #750, #708, #757, #755, #756, #540) by @jimhoyd in #761
- MCP runners that execute project code require --allow-authoring; bounded docs search reaches installed add-on guides (#590, #759) by @jimhoyd in #762
- release: v0.6.2 by @jimhoyd in #763
- fix(mail): make the copy-escape symlink test cross-platform by @jimhoyd in #764
- fix(audit): retry temp-dir cleanup on Windows EBUSY by @jimhoyd in #766
- fix(admin): use fileURLToPath, not URL.pathname, for Windows-safe test paths by @jimhoyd in #767
- chore: gated tmate debug step in ci.yml for #768 by @jimhoyd in #770
- fix(audit): close the database before removing its test temp directory by @jimhoyd in #771
- chore: revert temporary tmate debug step from ci.yml by @jimhoyd in #772
- fix(audit): close reopened databases and hosts inline, before t.after cleanup by @jimhoyd in #773
- fix(core): give worker-lifecycle's replacement-wait test a bounded, referenced timer by @jimhoyd in #774
- fix: stabilize release verification and npm 10 packaging tests by @jimhoyd in #776
Full Changelog: v0.6.1...v0.6.2