Skip to content

Releases: joacominatel/lazyit

v1.11.0

Choose a tag to compare

@github-actions github-actions released this 10 Aug 16:14
3d69b92

New & Changed

  • feat(web): document node-list deprecation and authoritative impact in the Manual
  • feat(web): consume paged /infra/nodes/page with runtime parsing and bounded id batches
  • feat(api): keep deprecated GET /infra/nodes array, add paged /nodes/page with privacy and snapshot reads
  • feat(shared): add legacy node array schema and keep page/graph contracts
  • feat: add Spanish graph edge notices
  • feat: add English graph edge notices
  • feat: load topology edges in one request
  • feat: test graph edge completeness states
  • feat: derive honest graph edge states
  • feat: add single infra graph edge query
  • feat: add bounded infra graph edge endpoint
  • feat: test infra query validation and graph edges
  • feat: expose bounded infra graph edges
  • feat: test infra role and graph edge queries
  • feat: add infra role and graph edge queries
  • feat: test infra list and graph edge contracts
  • feat: add infra role and graph edge contracts
  • updt: export infra child identity separators
  • updt: align shared Noble hashes at 2.3.0
  • updt: align Next.js ESLint config at 16.3.0
  • updt: align web Noble hashes at 2.3.0
  • feat: api — spec for the over-cap id batch rejection (#1152)
  • feat: web — en+es copy for the truncation, batch and search-picker states (#1152)
  • feat: web — the 'On topology' glyph resolves the visible page exactly (#1152)
  • feat: web — the merge picker becomes a server-searched Combobox (#1152)
  • feat: web — exact edge-endpoint label resolve and a server-searched target picker (#1152)
  • feat: web — the agent wizard polls a bounded PENDING page (#1152)
  • feat: web — the review tray counts the queue and names its batch (#1152)
  • feat: web — the Servers table gets the house pagination, sort and server search (#1152)
  • feat: web — the canvas reads the bounded graph endpoint and shows truncation (#1152)
  • feat: web — specs pinning the 'never looks complete' boundaries (#1152)
  • feat: web — pure truncation/batch notices for the two subset surfaces (#1152)
  • feat: web — paged node hooks, the graph hook and exact asset batch resolves (#1152)
  • feat: web — getInfraNodes returns Page, getInfraGraphNodes lands (#1152)
  • feat: api — specs for the ids filter and the list page params (#1152)
  • feat: api — expose the ids node-list filter (#1152)
  • feat: api — an exact ids filter on the node list for label lookups (#1152)
  • feat: api — specs for the node list page params and the graph read gate (#1152)
  • feat: api — specs for the node page window and the graph truncation flag (#1152)
  • feat: api — GET /infra/nodes pages, GET /infra/graph/nodes lands (#1152)
  • feat: api — paginate listNodes and add the projected listGraphNodes (#1152)
  • feat: shared — specs for the split node-list / graph read contracts (#1152)
  • feat: shared — Page + the bounded InfraGraph contract (#1152)
  • feat(web): en+es copy for the archive-blocked detach and relink (#1202)
  • feat(web): detachPermitted — the per-arm permission decision for the detach (#1202)
  • feat(web): en+es copy for the asset link, its two detach outcomes and the relink (#1202)
  • feat(web): wire the asset link control + close the ADR-0093 §7 duplicate loop (#1202)
  • feat(web): node asset attach/detach control with branch-aware confirmation (#1202)
  • feat(web): relink-sequence — the ADR-0093 §7 two-step, resumable not restartable (#1202)
  • feat(web): relink-sequence tests — resume after a half-completed two-step (#1202)
  • feat(web): detachOutcome — name which detach a click runs, safe only on explicit false (#1202)
  • feat(web): detach-outcome tests — the null/absent fail-safe is the silent branch (#1202)
  • feat(api): project the auto-created marker onto getNodeDetail, no extra query (#1202)
  • feat(api): getNodeDetail assetAutoCreated tests — marker, fail-safe null, one query (#1202)
  • feat(shared): assetAutoCreated on InfraNodeDetailSchema — which detach a click runs (#1202)
  • feat(shared): assetAutoCreated read-tolerance tests for the detach-outcome field (#1202)
  • feat: receive stock — inline model create, reset-on-open, assetModel:write gate, wider dialog
  • feat: CreateAssetModelDialog — optional defaultName seeds the name field on open
  • feat: AssetModelCombobox — optional onSearchChange so callers can observe the search term
  • feat: tests for buildReceivePayload — model chosen last, blank-field omission, serials split
  • feat: extract the receive-stock form→wire payload builder as a pure module
  • updt: es wizard copy — house vocabulary for hypervisor guests (invitados)
  • feat: es wizard copy — hypervisor note, advanced veto, detection feedback, env-token hints (#1225)
  • feat: en wizard copy — hypervisor note, advanced veto, detection feedback, env-token hints (#1225)
  • feat: create-agent wizard — wider dialog, hypervisor callout, veto disclosure, detection feedback (#1225)
  • feat: hypervisor-detection — pure step-3 derivations over detail specs + pending list (#1225)
  • feat: hypervisor-detection tests — facet read-tolerance, banner labels, guest prefix count (#1225)
  • feat: install-commands — token off argv (export/$env + sudo -E) + noHypervisor option (#1225)
  • feat: install-commands tests — env-channel token, --no-hypervisor veto, composed riders (#1225)
  • feat: guest topology, identity join and policy projection specs (ADR-0095)
  • feat: ADR-0095 ingest — /guest/ child topology, corroborated identity absorb, ack policy projection
  • updt: help text names the HYPERVISOR veto key
  • updt: pin the hypervisor veto in the local-limits tests
  • updt: LAZYIT_COLLECT_HYPERVISOR joins the local veto keys
  • updt: wire the hypervisor collector into the Linux collectHost path
  • updt: Hyper-V detection rides the Windows facts sweep; guest sweep wired into collectHost
  • feat: tests for the Hyper-V guest sweep — GUID/MAC normalization, unwrap quirk, zero-cost gating
  • feat: Hyper-V guest sweep — second PowerShell document and gated mappers (ADR-0095)
  • feat: tests for the Linux hypervisor collector — detection predicates, pvesh/virsh parsers, absent-vs-empty
  • feat: Linux hypervisor collector — Proxmox, libvirt, XCP-ng per-tick autodetection (ADR-0095)
  • feat: shared collector types for the hypervisor channel (ADR-0095)
  • feat: install.ps1 contract tests — vmms probe, veto line, upgrade merge (ADR-0095)
  • feat: install.sh contract tests — banner detection corpus, veto line, upgrade merge (ADR-0095)
  • feat: install.ps1 — Hyper-V detection banner + -NoHypervisor veto (ADR-0095)
  • feat: install.sh — hypervisor detection banner + --no-hypervisor veto (ADR-0095)
  • feat(web): es label + Windows-cost copy for the hypervisor guests collector (#1217)
  • feat(web): en label + Windows-cost copy for the hypervisor guests collector (#1217)
  • feat(web): the sixth collect toggle — hypervisor guests, seeded over the shared defaults (#1217)
  • updt: include hypervisor in the ALL_OFF policy literal (ADR-0095 ripple)
  • feat: policy tests — default-true forward-compat and per-agent projection (ADR-0095)
  • feat: collect.hypervisor sixth policy key + projectAgentPolicy version projection (ADR-0095)
  • feat: contract tests for host.hypervisor + host.guests[] and the /guest/ key helpers (ADR-0095)
  • feat: agent report contract — host.hypervisor + host.guests[] + /guest/ child keys (ADR-0095)
  • updt(web): fleet copy for the --upgrade command and the lost-token route, en + es (#1207)
  • feat(web): copy for the fleet view and the update command, en + es (#1207)
  • feat(web): the agent fleet view — distribution, liveness, degraded, command (#1207)
  • feat(web): the per-host update command, with the token stated rather than missing (#1207)
  • feat(web): the Agents tab on the Topology view toggle (#1207)
  • feat(web): ?view gains a third value, read through one total helper (#1207)
  • feat(web): useAgentFleet, keyed under the infra namespace (#1207)
  • feat(web): read GET /infra/agents/fleet (#1207)
  • feat(web): the fleet view's pure rules — platform, filter and the bulk handoff (#1207)
  • feat(web): the token-less per-host update command, lifted to lib/agent (#1207)
  • feat(agent): -KeepToken, the Windows half of the same re-run form (#1208)
  • feat(agent): --keep-token authenticates a re-run with the token already on disk (#1208)
  • feat(api): one aggregate agent line on the existing update.available email (#1206)
  • feat(api): GET /infra/agents/fleet, gated on infra:read (#1206)
  • feat(api): the agent fleet read — buckets, liveness, diagnostics, os family (#1206)
  • feat(shared): the agent fleet wire shape and the version buckets (#1206)
  • feat(web): add the chassis, endpoint-toggle, adoption and duplicate-suspicion copy (en + es) (#1200)
  • feat(web): surface duplicate-inventory suspicion and the reported chassis on the drill-in (#1200)
  • feat(web): name the Asset a confirm will adopt, before the operator clicks (#1200)
  • feat(web): let an auto-confirm rule state a reported chassis (#1200)
  • feat(web): show the reported chassis on each review-tray row (#1200)
  • feat(web): hide reported laptops and desktops by default, with the hidden count on the board (#1200)
  • feat(web): back the Show endpoints toggle with ?endpoints=1 (#1200)
  • feat(web): assert the two chassis cases that render nothing (#1200)
  • feat(web): resolve a reported chassis to a label, or to nothing (#1200)
  • feat(web): pin the endpoint filter, including the no-signal path and the canvas-only boundary (#1200)
  • feat(web): route endpoints off the topology canvas as a pure, view-level filter (#1200)
  • feat(web): es strings for the agent-linked timeline event (#1198)
  • feat(web): en strings for the agent-linked timeline event (#1198)
  • feat(web): es strings for the agent-linked timeline event (#1198)
  • feat(web): en strings for the agent-linked timeline event (#1198)
  • feat(api): persist and merge the chassis rule condition (#1198)
  • feat(api): adopt a corroborated Asset at the confirm gate, and route on chassis (#1198)
  • feat(shared): export the InfraAssetCandidate read type (#1198)
  • feat(api): additive migration for chassis routing and as...
Read more

v1.10.0

Choose a tag to compare

@github-actions github-actions released this 03 Aug 14:16
f79fbcc

New & Changed

  • feat(web): carry the blast-radius banner strings into Spanish (#1182)
  • feat(web): strings for the blast-radius list, its wait and its failure (#1182)
  • feat(web): the blast-radius banner lists the affected nodes again (#1182)
  • feat(web): plan the blast-radius summary from the one impact response (#1182)
  • feat(web): copy for the number slot and the failed preview, en + es (#1180)
  • feat(web): a short 'Blast radius' label for the hover card's hop-depth row (#1182)
  • feat(web): preview and hint copy, en + es (#1180)
  • feat(web): useAssetTagNextPreview (#1180)
  • feat(web): cache key for the next-tag preview (#1180)
  • feat(web): next-tag preview endpoint client (#1180)
  • feat(api): GET /config/asset-tag-scheme/next-tag (#1180)
  • feat(shared): contract for the next-tag preview (#1180)
  • feat(web): tab the node modal — General, Reported facts, Software, Connections, Changes (#1182)
  • feat(web): message keys for the add affordance, the canvas actions and the new tabs (#1181, #1182)
  • feat(web): split canvas selection from node detail so the map stays readable (#1182)
  • feat(web): the empty map carries the add affordance instead of pointing at it (#1181)
  • feat(web): one add control on Topology, agent first and manual behind it (#1181)
  • feat(web): blast radius moves onto the map, where its answer is already drawn (#1182)
  • feat(web): the node drill-in becomes a large tabbed modal, adapting per node kind (#1182)
  • feat(web): let the host-facts projection render without its software list (#1182)
  • feat(web): the topology add affordance leads with the reporting agent (#1181)
  • feat(web): plan the node-detail tab set from the specs projections, not from source (#1182)
  • feat(web): decide re-seed vs conflict when the policy revision moves under a dirty form (#1174)
  • updt(web): the es wizard copy states the real Windows constraints (#1168)
  • updt(web): the en wizard copy states the real Windows constraints (#1168)
  • updt(web): the wizard renders one step structure, and states Windows elevation (#1168)
  • updt(web): the policy revision reads once, beside the page title (#1174)
  • updt(web): tighten the agent policy copy against the code that backs it (es) (#1174)
  • updt(web): tighten the agent policy copy against the code that backs it (en) (#1174)
  • feat(web): add the Reporting agents card to the Settings hub (#1174)
  • updt(web): Settings -> Instance signposts the moved Reporting agents section (#1174)
  • feat(web): Settings -> Reporting agents gets its own route (#1174)
  • feat(web): surface the three agent policy scopes and the auto-confirm rules (#1174)
  • feat(web): group the agent policy editor into cadence, collection and exclusions (#1174)
  • feat(web): Settings i18n (es) for the Reporting agents section (#1174)
  • feat(web): Settings i18n (en) for the Reporting agents section (#1174)
  • updt(web): per-platform wizard copy in the es catalog (#1168)
  • updt(web): per-platform wizard copy in the en catalog (#1168)
  • feat(web): a Linux/Windows choice in the "Add a server" wizard (#1168)
  • feat(web): hold the wizard's commands to the installers they drive (#1168)
  • feat(web): the wizard's install commands, per platform and pure (#1168)
  • feat(web): allow /install.ps1 through the auth proxy, by exact path (#1144)
  • feat(web): install.ps1 — Scheduled Task as SYSTEM, ACL'd config, MZ + sha256 checks (#1144)
  • feat(agent): pin what install.ps1 checks, registers and protects (#1144)
  • feat(devops): cross-compile the Windows agent artifacts into the API image (#1144)
  • feat(api): serve lazyit-agent--, keeping arch-only requests on Linux (#1144)
  • feat(api): pin the os parameter and the legacy arch-only download path (#1144)
  • feat(agent): compile the Windows targets, and name every artifact by os and arch (#1144)
  • updt(agent): key the report on the platform's own dedup key, not /etc/machine-id (#1144)
  • updt(agent): the policy and state cache follow the platform state dir (#1144)
  • updt(agent): read the platform config path, with a --config override (#1144)
  • feat(agent): resolve the config file and state dir per platform (#1144)
  • feat(agent): pin the platform-resolved config and state paths (#1144)
  • feat(agent): dispatch the collector by platform, and re-export the shared surface (#1144)
  • feat(agent): the Windows collector — one PowerShell call, registry software, docker CLI (#1144)
  • feat(agent): pin the Windows collector's mappers, and the two prohibitions (#1144)
  • updt(agent): collect.ts becomes collect/linux.ts, importing the shared half (#1144)
  • feat(agent): name the OS-neutral half of the collector before adding a second OS (#1144)
  • feat(web): es copy for the Changes tab (#1143)
  • feat(web): en copy for the Changes tab (#1143)
  • feat(web): split the node panel into Overview and Changes tabs (#1143)
  • feat(web): the Changes tab body — what moved on this node, newest first (#1143)
  • feat(web): useInfraNodeChanges — keyset-paged node fact history (#1143)
  • feat(web): read a node's change history from the API (#1143)
  • feat(api): GET /infra/nodes/:id/changes (#1143)
  • feat(api): record what MOVED on ingest, reusing the #1153 comparison (#1143)
  • feat(api): additive migration for infra_node_fact_changes (#1143)
  • feat(api): InfraNodeFactChange — an append-only node fact history (#1143)
  • feat(shared): export the infra fact-change contract (#1143)
  • feat(shared): pure fact diff for the infra node change history (#1143)
  • feat(shared): the ack carries the software-delta capability the agent gates its omission on (#1142)
  • feat(api): skip the specs write when nothing changed, and sync a container's Asset (#1142, #1153, #1157)
  • feat(agent): wire the delta into the report, and answer a resend request (#1142)
  • feat(agent): remember the software fingerprint beside the cadence clock (#1142)
  • feat(agent): collectSoftware answers with an outcome, not a maybe-list (#1142)
  • feat(agent): omit an unchanged package list, always send its fingerprint (#1142)
  • feat(shared): softwareState/softwareHash — an absent list can mean keep, never guess (#1142)
  • feat(api): serve the x64-baseline artifact and publish its sha256 (#1137)
  • feat(web): harden the agent unit, de-phase the timer, verify the binary, and support uninstall (#1137)
  • feat(agent): build the pre-AVX2 x64-baseline target and generate checksums (#1137)
  • feat(agent): write a .sha256 beside every compiled artifact (#1137)
  • feat(agent): 'show' and 'test' — stop diagnosing a silent host by guesswork (#1137)
  • feat(agent): --token-file (and stdin), plus the network keys, in config resolution (#1137)
  • feat(agent): read an egress proxy and a private CA from the agent's own config (#1137)
  • feat(web): the rule form refuses a blanket condition, ANY defaults children off (#1145)
  • feat(web): drop hidden rows from the selection and refuse an over-cap batch (#1145)
  • feat(web): the tray's two selection rules, where a test can hold them (#1145)
  • updt(web): state the stale-threshold ceiling in the es error copy (#1140)
  • updt(web): state the stale-threshold ceiling in the en error copy (#1140)
  • feat(web): policy badge copy (en+es) (#1140)
  • feat(web): show the policy acknowledgement on the node drill-in (#1140)
  • feat(web): a policy applied/pending badge on agent-reported nodes (#1140)
  • feat(web): agent policy copy (en+es) (#1140)
  • feat(web): render the agent policy editor on the instance settings page (#1140)
  • feat(web): the fleet agent policy editor in Settings → Instance (#1140)
  • feat(web): agent-policy query + save hooks (#1140)
  • feat(web): agent-policy read/write endpoints (#1140)
  • feat(shared): expose the echoed policy revision on the node drill-in (#1140)
  • feat(web): install a fixed 5-minute tick; cadence moves to lazyit (#1140)
  • feat(agent): no-op on a tick inside the interval, echo the revision, cache the ack policy (#1140)
  • feat(agent): honour the policy — skip disabled collectors, filter by glob, cap software (#1140)
  • feat(agent): read the host's own veto limits and add --force (#1140)
  • feat(agent): policy + state cache — the local half of the interval inversion (#1140)
  • feat(web): group the review tray by host, add select/filter/sort (#1145)
  • feat(web): auto-confirm rules manager (#1145)
  • feat(web): bulk confirm/discard dialogs with per-scope asset defaults (#1145)
  • feat(web): bulk review + auto-confirm rule hooks (#1145)
  • feat(web): bulk review + auto-confirm rule endpoints (#1145)
  • feat(shared): expose the matchable rule subset + the bulk item type (#1145)
  • feat(api): human-only agent-policy routes for the instance, service-account and node scopes (#1140)
  • feat(api): judge each node against the staleness threshold it was served, not one global env var (#1140)
  • feat(api): the report ack carries the resolved policy and records the echoed revision (#1140)
  • feat(api): resolve and write the three agent-policy scopes, read-tolerant and write-strict (#1140)
  • feat(api): additive migration for the agent-policy scopes and revision counter (#1140)
  • feat(api): agent-policy scopes on InfraNode/ServiceAccount + the singleton settings row (#1140)
  • feat(shared): the agent-policy admin wire shape (stored layer + resolved effective) (#1140)
  • feat(api): bulk review + auto-confirm rule routes (#1145)
  • feat(api): bulk confirm/discard + non-retroactive auto-confirm on create (#1145)
  • feat(api): auto-confirm rule storage, CRUD and the read-only matcher (#1145)
  • feat(api): auto-scope auto-confirm rule reads to live rows (#1145)
  • feat(api): InfraAutoConfirmRule model + additive migration (#1145)
  • feat(shared): the report ack carries the resolved agent policy (#1140)
  • feat(shared): server-driven agent policy — a closed contract, three-level resolution, local veto, tick gate (#1140)
  • feat(shared): bulk review actions + operator-authored auto-confirm rules (#1145)
  • feat(shared): the host key a container child was scoped to (#1145)
  • feat(web): container panel strings, en + es (#1139)
  • feat(web): the node drill-in shows a container ...
Read more

v1.9.0

Choose a tag to compare

@github-actions github-actions released this 31 Jul 00:36
d85e4f9

New & Changed

  • feat(topology): reveal linked secrets from the InfraNode panel (#1114)
  • feat(web): taxonomy bulk-delete select + summary copy (en+es)
  • feat(web): multi-select + bulk delete in Settings → Taxonomies
  • feat(web): widen the KB new/edit page container to max-w-6xl
  • feat(web): folder-path category picker search + empty copy (en+es)
  • feat(web): wider KB form, sticky action bar, searchable folder-path category picker
  • feat(web): add shared.code.auto label for auto-detected code fences (en+es)
  • feat(web): auto-highlight no-language code fences at render + "auto" hint
  • feat(web): client-side code-fence language auto-detect helper + test
  • feat(web): slugTaken create-conflict string (en+es) (#1106)
  • feat(web): es strings for KB markdown drag/drop import (#1106)
  • feat(web): en strings for KB markdown drag/drop import (#1106)
  • feat(web): wire markdown drag/drop import into the KB create form (#1106)
  • feat(web): KB new-article markdown drag/drop + choose-file dropzone (#1106)
  • feat(web): client-side KB markdown-import helpers — guard + title derivation (#1106)
  • feat(web): add wiki-link createTooltip string (en+es) (#1106)
  • feat(web): pass folder articleCount to the browse sub-folder row (#1106)
  • feat(web): show per-folder article count on the browse sub-folder row (#1106)
  • feat(web): show per-folder live-article count on the folder tree row (#1106)
  • feat(web): article create form applies sanitized wiki-link prefill (title + slug) (#1106)
  • feat(web): /kb/new reads + sanitizes slug/title prefill params (#1106)
  • feat(web): wire wiki-link create affordance in KB reading view, gated on article:write (#1106)
  • feat(web): unresolved wiki-link becomes a create-this-note link for writers (#1106)
  • feat(web): KB wiki-link create-on-click prefill helper (build href + sanitize params) (#1106)
  • feat(api): compute per-folder articleCount via _count, folder-access aware (#1106)
  • feat(shared): add computed .nullish() articleCount to ArticleCategory read schema (#1106)
  • feat(web): KB browse/search strings — search, quick-switcher, filters (en+es) (#1106)
  • feat(web): heal KB search + dense browse, filters popover, / focus (#1106)
  • feat(web): mount + seed the KB route-shell from the layout (#1106)
  • feat(web): persistent KB tree route-shell (#1106)
  • feat(web): article-scoped ⌘K quick-switcher for /kb (#1106)
  • feat(web): dense line-per-doc KB list rows + search highlight (#1106)
  • updt(web): wrap useArticleCategories queryFn for SSR-token safety (#1106)
  • feat(web): thread SSR Bearer through getArticleCategories (#1106)
  • feat(web): KB search mode + highlight helpers + test (#1106)
  • feat(web): KB route-shell URL derivations + test (#1106)
  • feat(web): KB reading-view strings — covers/connections/toc/siblings (en+es) (#1106)
  • feat(web): compose the calm KB reading view — column + right rail (#1106)
  • feat(web): slim Ledger record header + status stamp + ⋯ cluster (#1106)
  • feat(web): prev/next sibling footer from folder siblings (#1106)
  • feat(web): On this page TOC with IntersectionObserver scroll-spy (#1106)
  • feat(web): Connections rail — non-empty backlinks/links/aliases sections (#1106)
  • feat(web): Covers chip row under the title (only when linked) (#1106)
  • feat(web): KB wiki-link hover Quick View preview (#1106)
  • feat(web): controlled Version History side sheet (opened from ⋯) (#1106)
  • feat(web): let References panel take a title override for the rail (#1106)
  • feat(web): optional hover-preview context for resolved wiki-links (#1106)
  • feat(web): pure KB reading-view derivations — folder-path trail + siblings (#1106)
  • feat(web): es labels for callouts/anchors/lightbox (#1106)
  • feat(web): en labels for callouts/anchors/lightbox (#1106)
  • feat(web): click-to-enlarge mermaid diagrams (#1106)
  • feat(web): open KB inline images in the lightbox (#1106)
  • feat(web): wire slug/callouts + heading/table/img/inline-code renderers, bump prose base (#1106)
  • feat(web): register IT code grammars (python/go/dockerfile/ini/nginx + toml/hcl aliases) (#1106)
  • feat(web): hover-revealed heading deep-link anchor (#1106)
  • feat(web): native-dialog image/diagram lightbox (#1106)
  • feat(web): tinted callout admonition component (#1106)
  • feat(web): post-sanitize callout/admonition rehype pass (#1106)

Fixes

  • fix(web): crypto.randomUUID crashes the workflow step editor on plain-HTTP LAN installs (#1127)
  • fix(api): 3 verified quick-win bugs from code audit (#1119)
  • fix(web): 5 verified quick-win bugs from code audit (#1118)
  • fix(web): specific 'name taken' message on KB create slug conflict (#1106)
  • fix(web): make the degraded KB search global to match the strong search scope (#1106)
  • fix(web): portal lightbox dialog + inline image trigger (valid in p/a, no hydration mismatch) (#1106)

Removed

  • del(web): retire the FolderBrowseCard drill-down grid (#1106)
  • del(web): retire the KB card grid (ArticleCard) (#1106)
  • del(web): drop always-on Version History panel (moves behind ⋯) (#1106)

Full changelog: v1.8.0...v1.9.0

v1.8.0

Choose a tag to compare

@github-actions github-actions released this 19 Jul 23:12
e7ef66c

New & Changed

  • updt(web): register directory-sync manual subcategory (#839)
  • feat(web): es manual directory-sync subcategory label (#839)
  • feat(web): en manual directory-sync subcategory label (#839)
  • feat(web): es directory settings messages (#839)
  • feat(web): en directory settings messages (#839)
  • updt(web): mount directory editor on Settings → Instance (#839)
  • feat(web): AD/LDAP directory settings editor + Sync now (#839)
  • feat(web): directory PENDING review tray (#839)
  • feat(web): directory form-glue unit tests (#839)
  • feat(web): pure directory form-to-wire glue (#839)
  • feat(web): directory-connection query + mutation hooks (#839)
  • feat(web): directory-connection API data-access (#839)
  • updt(api): document DIRECTORY_SECRET_KEY + sweeper interval env (#839)
  • updt(api): register DirectoryModule (#839)
  • updt(api): stamp AD directory-source provenance in users.create (#839)
  • feat(api): DirectoryModule wiring (#839)
  • feat(api): directory controller (GET/PUT connection, POST sync) (#839)
  • feat(api): directory-sync setInterval sweeper (#839)
  • feat(api): directory reconcile engine + hard-invariant tests (#839)
  • feat(api): DirectoryConnection singleton config store (write-only secret) (#839)
  • feat(api): read-only ldapts client + objectGUID/filter-escape helpers (#839)
  • feat(api): directory bind-password AES-256-GCM crypto (own key axis) (#839)
  • feat(api): directory subsystem wiring constants + GUID/env helpers (#839)
  • feat(prisma): additive directory_ldap_source migration (#839)
  • updt(prisma): User AD-directory-source fields + DirectoryConnection singleton (#839)
  • feat(shared): DirectoryConnection schema validation tests (#839)
  • feat(shared): export directory-connection schemas from barrel (#839)
  • feat(shared): DirectoryConnection config + sync-result schemas (#839)
  • feat(web): es email-preference label for the acknowledgement notification (#1029)
  • feat(web): en email-preference label for the acknowledgement notification (#1029)
  • feat(web): es strings for receive stock + acknowledge receipt (#1029)
  • feat(web): en strings for receive stock + acknowledge receipt (#1029)
  • feat(web): catalogue asset_assignment.acknowledged in the bell TYPE_META (#1029)
  • feat(web): render the ACKNOWLEDGED asset-history event (#1029)
  • feat(web): acknowledged state + self-service acknowledge on the owners panel (#1029)
  • feat(web): Acknowledge receipt dialog (self-service, 409-graceful) (ADR-0089 Part B, #1029)
  • feat(web): surface Receive stock in the inventory header (#1029)
  • feat(web): Receive stock dialog with partial-success result (ADR-0089 Part A, #1029)
  • feat(web): useAcknowledgeAssignment mutation hook (#1029)
  • feat(web): acknowledgeAssetAssignment endpoint (#1029)
  • feat(web): useReceiveAssets mutation hook (#1029)
  • feat(web): receiveAssets endpoint for bulk receiving (#1029)
  • feat(web): flag serial-matched rows as updates in the dry-run preview (#1061)
  • feat(web): add date-format + update-existing import labels (es) (#1060/#1061)
  • feat(web): add date-format + update-existing import labels (en) (#1060/#1061)
  • feat(web): per-column date-format picker in the import mapping step (#1060)
  • feat(shared): include the acknowledged verb in the RecentActivityAction allowlist test (#1029)
  • feat(web): add updated / re-import timeline labels (en+es, #1061)
  • feat(web): wire the UPDATED asset-history event into the timeline (#1061)
  • feat(api): update matched live asset on serial re-import + P2002 fallback (#1061)
  • feat(api): emit use-existing for serial-matched live assets in dry-run (#1061)
  • feat(api): stamp re-import provenance + UPDATED marker in AssetsService.update (#1061)
  • feat(api): add UPDATED value to AssetHistoryEventType enum + migration (#1061)
  • feat(shared): add UPDATED to AssetHistoryEventTypeSchema (#1061)
  • feat(shared): add DateFieldMapping + mapping.dates to ImportMappingSchema (#1060)
  • feat(shared): read per-column date format in coerceRow, export DATE_FIELDS (#1060)
  • feat(shared): parse dates strictly per explicit format + detectDateFormat (#1060)
  • feat(api): assert the acknowledgement type is in the email allowlist (#1029)
  • feat(api): make asset_assignment.acknowledged email opt-out-able (#1029)
  • feat(api): acknowledge() tests (flip-once, 409 paths, skip-nudge, 403) (#1029)
  • feat(api): wire NotificationsModule into AssetAssignmentsModule for the ack nudge (#1029)
  • feat(api): POST /asset-assignments/:id/acknowledge (self-service, human-only) (#1029)
  • feat(api): self-scoped set-once acknowledge() + post-commit assigner nudge (ADR-0089 Part B, #1029)
  • feat(api): AcknowledgeAssignmentDto (#1029)
  • feat(api): receiveBatch tests (per-unit tx, partial success, model 400) (#1029)
  • feat(api): POST /assets/batch/receive endpoint (asset:write, partial-success envelope) (#1029)
  • feat(api): AssetsService.receiveBatch loops create() per unit for bulk receiving (ADR-0089 Part A, #1029)
  • feat(api): additive migration for AssetAssignment acknowledgement + ACKNOWLEDGED enum value (ADR-0089 Part B, #1029)
  • feat(shared): assert the acknowledgement notification type is catalogued (#1029)
  • feat(shared): add the targeted asset_assignment.acknowledged notification type (#1029)
  • feat(shared): AcknowledgeAssignment payload + acknowledgement read fields on AssetAssignment (#1029)
  • feat(shared): allow the acknowledged activity verb in RECENT_ACTIVITY_ACTIONS (#1029)
  • feat(shared): add ACKNOWLEDGED to AssetHistoryEventType (ADR-0089 Part B, #1029)
  • feat(shared): export the asset-receive schemas from the barrel (#1029)
  • feat(shared): tests for the ReceiveAssets schema (quantity bounds + serials refinement) (#1029)
  • feat(shared): ReceiveAssets + ReceiveAssetsResult contracts for bulk receiving (ADR-0089 Part A, #1029)
  • feat(web): add the duplicate-IP warning copy (es) (#847)
  • feat(web): add the duplicate-IP warning copy (en) (#847)
  • feat(web): let the duplicate-IP peers re-select their node in the panel (#847)
  • feat(web): warn on the drill-in when another live node shares this IP (#847)
  • feat(api): test the ipConflict signal on getNodeDetail (#847)
  • feat(api): surface the soft duplicate-IP conflict on the node drill-in (#847)
  • feat(shared): test IpAddressSchema + primaryIpv4 validate-or-drop (#847)
  • feat(shared): validate the InfraNode IP as an IPv4/IPv6 value-object (#847)
  • feat(web): es label for the node Reported facts section (#1081)
  • feat(web): en label for the node Reported facts section (#1081)
  • feat(web): render read-only Reported facts on AGENT nodes (reuse Assets inventory projection) (#1081)
  • feat(web): poll the topology canvas for fresh node facts (#1081)
  • feat(web): poll the servers table for fresh liveness/IP (#1081)
  • feat(web): poll the pending review tray for fresh discoveries (#1081)
  • feat(web): export INFRA_LIVE_POLL_MS for the live node surfaces (#1081)
  • feat(api): promote report IP→node (MANUAL-guarded) + serial→Asset + linked-Asset specs sync (#1081)
  • feat(api): migration for infra_node ipAddressSource (default AGENT) (#1081)
  • feat(api): add InfraNodeIpSource enum + ipAddressSource column on InfraNode (#1081)
  • feat(shared): add ipAddressSource + primaryIpv4/sanitizeSerial fact-promotion mappers (#1081)
  • feat(web): i18n for license/seat tracking labels (en+es) (#949)
  • feat(web): License & seats panel with over-allocation warning on application detail (#949)
  • feat(web): license usage cell (used/purchased + over-alloc warning + renewal) on Access list (#949)
  • feat(web): license inputs (seats, cost per seat, renewal) on application form (#949)
  • feat(api): derive Application.seatsUsed (distinct active-grant users) in findOne + findPage (#949)
  • feat(shared): license/seat fields on Application schema; derived read-only seatsUsed (#949)
  • feat(api): add license/seat columns to Application (seatsPurchased, costPerSeat, renewalDate) (#949)
  • feat(web): i18n for local directory onboarding (en+es) (#1072)
  • feat(web): branch the directory-provision panel to the local onboarding flow (#1072)
  • feat(web): local onboarding button with one-time temp-password reveal (#1072)
  • feat(web): add useProvisionLocalUserAccount mutation (#1072)
  • feat(web): add provisionLocalUserAccount endpoint (#1072)
  • feat(api): test provisionLocalAccount onboarding, role-unchanged and reject paths (#1072)
  • feat(api): add POST /users/:id/provision-local-account (#1072)
  • feat(api): provisionLocalAccount onboards a directory person with a temp password (#1072)
  • feat(api): expose canProvisionLocalAccounts in /config/status (#1072)
  • feat(shared): add canProvisionLocalAccounts to ConfigStatus (#1072)
  • updt: add vault-access caution to the SA revoke dialog copy (en+es) (#1066)
  • feat(web): add sku i18n strings for import mapping (es) (#1064)
  • feat(web): add sku i18n strings for import mapping (en) (#1064)
  • feat(web): add sku mapping UI for created AssetModels (#1064)
  • feat(import): cover AssetModel sku from modelConfig in commit spec (#1064)
  • feat(import): carry sku into created AssetModel (#1064)
  • feat(import): add sku UI target + header aliases for model (#1064)
  • feat(import): add sku column/const to ModelConfigSchema (#1064)
  • feat(web): test errorStateKind for 401/403/500/network (#1045)
  • feat(web): add errorStateKind pure classifier for 401/403/retry (#1045)
  • feat(web): es strings for the ragged-rows warning (#1062)
  • feat(web): en strings for the ragged-rows warning (#1062)
  • feat(web): warn on ragged-width rows in the import map step (#1062)
  • feat(shared): add raggedRowCount to ImportDetectedShapeSchema (#1062)
  • feat(web): add email-preference labels for the expiry nudges (en+es) (#1070)
  • feat(web): render the two proactive expiry notification types in the bell (#1070)
  • feat(api): register the ExpiryNotificationsSweeper (#1070)
  • feat(api): test the expiry sweeper emits, dedupes and stays opt-out-able (#1070)
  • feat(api): add daily look-ahead sweeper emitting proactive expiry nudges (#1070)
  • feat(api): default warranty/grant expiry nudges to warning ...
Read more

v1.7.0

Choose a tag to compare

@github-actions github-actions released this 08 Jul 02:37
ea66357

New & Changed

  • feat(web): es strings for the import custom-field shortcut (#1050)
  • feat(web): en strings for the import custom-field shortcut (#1050)
  • feat(web): one-click 'use as custom field' shortcut for ignored import columns (#1050)
  • feat(web): test the custom-field shortcut helpers (#1050)
  • feat(web): add pure helpers for the ignored-column custom-field shortcut (#1050)
  • feat(import): add i18n labels for notes/cost/depreciation targets (es)
  • feat(import): add i18n labels for notes/cost/depreciation targets (en)
  • feat(import): test notes + money/depreciation fields flow through coerceRow
  • feat(import): test money/integer coercion (locale, cents, negatives, empty)
  • feat(import): route money/integer fields through numeric coercion branch
  • feat(import): make notes + cost/depreciation fields mappable
  • feat(import): locale-tolerant money/integer coercers (cents ×100)

Fixes

  • fix(web): add es users.directory.provision.unsupported string (#1048)
  • fix(web): add en users.directory.provision.unsupported string (#1048)
  • fix(web): surface real 400 message + hide Create OIDC account in LOCAL/BYOI (#1048)
  • fix(web): test provision error mapping — 400 not mislabelled needs-email (#1048)
  • fix(web): pure classifier for provision-account errors — surface real cause (#1048)
  • fix(api): test canProvisionAccounts mirrors idp.supportsManagement (#1048)
  • fix(api): emit canProvisionAccounts from GET /config/status (#1048)
  • fix(shared): cover canProvisionAccounts in ConfigStatus schema test (#1048)
  • fix(shared): expose canProvisionAccounts capability on ConfigStatus (#1048)
  • fix(import): i18n for the preview exclusion summary (en+es) #1049
  • fix(import): group the reason-for-exclusion in the dry-run preview
  • fix(import): test status coercion of Snipe-IT labels incl. 'Nueva (deployed)' #1049
  • fix(import): map common Snipe-IT status labels to Asset status
  • fix(import): resolve enum values via the parenthetical meta token
  • fix(api): update user-search where spec for multi-token shape (#1053)
  • fix(api): tokenize user search so 'first last' matches across columns (#1053)
  • fix(api): test multiTokenWhere AND-of-OR tokenization (#1053)
  • fix(api): add multiTokenWhere helper for token-wise free-text search (#1053)
  • fix(web): assert relative /login redirect in auth-expiry test (#1052)
  • fix(web): 401 auth-expiry signs out then redirects to relative /login (#1052)
  • fix(web): logout redirects to relative /login for host-agnostic LAN (#1052)

Full changelog: v1.6.0...v1.7.0

v1.6.0

Choose a tag to compare

@github-actions github-actions released this 05 Jul 23:58
5cbc875

New & Changed

  • updt(infra): document AUTH_TRUST_HOST + the LAN :PORT site-address shape in .env.prod.example (#1035)
  • updt(infra): document the port-only (:PORT) any-host HTTP shape in the Caddyfile (#1035)
  • updt: document AUTH_TRUST_HOST in api .env.example (#1035)
  • feat: es strings for asset cost + depreciation (#954)
  • feat: en strings for asset cost + depreciation (#954)
  • feat: show purchase cost + current book value on asset detail (#954)
  • feat: asset form purchase cost + depreciation fields (#954)
  • feat: test money minor/major helpers (#954)
  • feat: add money minor/major unit helpers (#954)
  • feat: test currentBookValue on findOne (#954)
  • feat: compute currentBookValue on asset detail read (#954)
  • feat: export asset-depreciation util from shared barrel (#954)
  • feat: computed currentBookValue on asset detail schema (#954)
  • feat: purchase-cost/depreciation fields on Asset zod schemas (#954)
  • feat: unit test for computeAssetBookValue (#954)
  • feat: computeAssetBookValue straight-line depreciation util (#954)
  • feat: migration for asset purchase-cost + depreciation columns (#954)
  • feat: add asset purchaseCost/usefulLifeMonths/salvageValue columns (#954)

Fixes

  • fix: add .playwright-mcp/ to .gitignore
  • fix(web): restore explicit trustHost for host-agnostic LAN mode (#1043)
  • fix: derive Secure cookie from origin scheme only, not AUTH_TRUST_HOST (#1035)
  • fix(infra): AUTH_URL uses ${WEB_ORIGIN:-} so unset WEB_ORIGIN in LAN mode is clean (#1035)
  • fix(infra): host-agnostic LAN network mode + start.sh --reconfigure (#1035)
  • fix: boot-config specs for AUTH_TRUST_HOST LAN mode (#1035)
  • fix: validate AUTH_TRUST_HOST requires AUTH_MODE=local (#1035)
  • fix: spec for resolveCorsOrigin host-agnostic CORS (#1035)
  • fix: wire resolveCorsOrigin into enableCors (#1035)
  • fix: reflect request Origin for CORS in LAN host-agnostic mode (#1035)
  • fix: host-agnostic auth in LAN mode via AUTH_TRUST_HOST (#1035)

Full changelog: v1.5.0...v1.6.0

v1.5.0

Choose a tag to compare

@github-actions github-actions released this 04 Jul 02:25
0033e51

New & Changed

  • feat(web): show full location path on asset detail (#845)
  • feat(web): asset location full-path component (#845)
  • feat(web): render location ancestry as a breadcrumb (#845)
  • feat(web): parent-location picker on the location form (#845)
  • feat(web): add parent-location strings to es locations (#845)
  • feat(web): add parent-location strings to en locations (#845)
  • feat(locations): tests for cycle rejection + ancestry resolution (#845)
  • feat(locations): return ancestry path on GET /locations/:id (#845)
  • feat(locations): cycle-safe parent validation + ancestry path resolution (#845)
  • feat(shared): extend Location schemas with parentId + ancestry path/detail (#845)
  • feat(locations): migration for location parentId adjacency list (#845)
  • feat(locations): add self-referential parentId hierarchy to Location (#845)

Fixes

  • fix: add parentId to location Quick View test fixture (#845)
  • fix: carry parentId through the location Quick View mapper (#845)

Full changelog: v1.4.1...v1.5.0

v1.4.1

Choose a tag to compare

@github-actions github-actions released this 04 Jul 01:43
d6fb587

New & Changed

  • feat: link notification emails from the user menu (#879)
  • feat: add es user-menu label for notification emails (#879)
  • feat: add en user-menu label for notification emails (#879)
  • feat: register es account namespace in message barrel (#879)
  • feat: register en account namespace in message barrel (#879)
  • feat: add es account i18n namespace (notification email prefs, #879)
  • feat: add en account i18n namespace (notification email prefs, #879)
  • feat: add notification-email preferences view with per-type toggles (#879)
  • feat: add /account/notifications page shell (#879)
  • feat: add notification-preferences query + optimistic PUT hook (#879)
  • feat: add account notification-preferences endpoint (GET/PUT contract, #879)
  • feat(web): Scan action on assets list header (#875)
  • feat(web): Print label action on asset detail (#875)
  • feat(web): camera QR scanner component with manual fallback (#875)
  • feat(web): /assets/scan client-only route shell (#875)
  • feat(web): printable asset QR label route (#875)
  • feat(web): es strings for asset QR label + camera scan (#875)
  • feat(web): en strings for asset QR label + camera scan (#875)
  • feat: register notification-preferences controller/service in SmtpModule (#879)
  • feat: /account/notification-preferences self-service endpoint (#879)
  • feat: self-service notification email preferences service (#879)
  • feat: exclude email-opted-out users from recipient resolution (#879)
  • feat: migration for notificationEmailOptOutTypes column (#879)
  • feat: add User.notificationEmailOptOutTypes for per-type email opt-out (#879)
  • feat: add per-user email notification preference schemas (#879)

Full changelog: v1.4.0...v1.4.1

v1.4.0

Choose a tag to compare

@github-actions github-actions released this 03 Jul 18:05
2299cfe

New & Changed

  • feat: ES strings for agent inventory panel (#1013)
  • feat: EN strings for agent inventory panel (#1013)
  • feat: render agent inventory instead of raw specs on asset detail (#1013)
  • feat: structured agent inventory panel for asset detail (#1013)

Fixes

  • fix: create /app/attachments owned by node before USER switch (#1019)
  • fix: re-pin canonical recent_activity view migration guard (#1006)
  • fix: cover detached issuance timing + PASSWORD_RESET_REQUESTED audit (#1006)
  • fix: detach forgot-password issuance for existence-independent latency + audit PASSWORD_RESET_REQUESTED (#1006)
  • fix: migration adds PASSWORD_RESET_REQUESTED enum value + re-issues recent_activity view (#1006)
  • fix: add PASSWORD_RESET_REQUESTED to UserHistoryEventType enum (#1006)
  • fix: expect password_reset_requested in activity verbs test (#1006)
  • fix: add password_reset_requested activity verb (#1006)
  • fix: expect PASSWORD_RESET_REQUESTED in user-history enum test (#1006)
  • fix: add PASSWORD_RESET_REQUESTED user-history event (#1006)
  • fix: reject redirected/non-ELF downloads in the agent installer (#980)
  • fix: cover the ingestReport P2002 race fallback in the infra service spec (#1012)
  • fix: make InfraService.ingestReport race-safe against the reporting-source dedup unique (#1012)

Full changelog: v1.3.0...v1.4.0

v1.3.0

Choose a tag to compare

@github-actions github-actions released this 03 Jul 16:57
bddaa8d

New & Changed

  • feat(infra): Caddy default_sni for bare-IP HTTPS (LAN reachability) (#1010)
  • feat: add password-lifecycle i18n copy (change/forgot/reset/checklist, en + es) (#1004)
  • feat: link 'Forgot your password?' from the local login form (#1004)
  • feat: add public /reset-password page (local-mode gated, missing-token state) (#1004)
  • feat: add reset-password form (token from URL, generic error, route to /login) (#1004)
  • feat: add public /forgot-password page (local-mode gated) (#1004)
  • feat: add enumeration-safe forgot-password form (uniform confirmation) (#1004)
  • feat: add /change-password forced-change wall page (#1004)
  • feat: add forced-change client shell (session-token sync + forced ChangePasswordForm) (#1004)
  • feat: add forced-change wall layout (auth + local-mode guards, bare AuthShell) (#1004)
  • feat: mount the change-password panel in the profile view (#1004)
  • feat: add local-mode self-service change-password panel to the profile page (#1004)
  • feat: allow public /forgot-password and /reset-password through route protection (#1004)
  • feat: honor useSession().update to swap the fresh post-change session token (#1004)
  • feat: wire forced-change interception into the query/mutation onError seam (#1004)
  • feat: add shared ChangePasswordForm (self + forced) with fresh-token session swap (#1004)
  • feat: add reusable live password-strength checklist (mirrors ZitadelPasswordSchema) (#1004)
  • feat: test the forced-password-change interception (latch, loop-guard, code match) (#1004)
  • feat: add forced-password-change interception seam (403 PASSWORD_CHANGE_REQUIRED -> /change-password) (#1004)
  • feat: add password-lifecycle mutation hooks; change-password opts out of global auth handling (#1004)
  • feat: add local-mode password-lifecycle API endpoints (change/forgot/reset) (#1004)
  • feat(api): re-pin the canonical recent_activity view migration to password_lifecycle
  • feat(api): exempt GET /users/me from the forced-change gate (ADR-0086 §F4)
  • feat(api): register MustChangePasswordGuard as APP_GUARD between auth and authz
  • feat(api): wire the password-lifecycle controller/service + guard into LocalAuthModule
  • feat(api): tests for the password-lifecycle controller (uniform forgot body, 401 anon)
  • feat(api): PasswordLifecycleController — change/forgot/reset endpoints (ADR-0086 §F4)
  • feat(api): per-IP rate-limit guard for the public reset endpoints (ADR-0086 §F4)
  • feat(api): tests for the forced-change gate (blocks non-exempt, allows exempt/public/non-local)
  • feat(api): MustChangePasswordGuard — forced-change gate, 403 PASSWORD_CHANGE_REQUIRED (ADR-0086 §F4)
  • feat(api): @AllowPasswordChangeRequired exemption decorator (ADR-0086 §F4)
  • feat(api): security-graded tests for PasswordLifecycleService
  • feat(api): PasswordLifecycleService — change/forgot/reset (epoch-bump, enumeration-safe, single-use, ADR-0086 §F4)
  • feat(api): renderPasswordResetEmail branded template (ADR-0086 §F4)
  • feat(api): tests for the reset-token primitives (entropy, hash-at-rest, uniqueness)
  • feat(api): reset-token primitives (CSPRNG mint + SHA-256 hash-at-rest, ADR-0086 §F4)
  • feat(api): offline migration — password_reset_tokens table + enum values + recent_activity view (ADR-0086 §F4)
  • feat(api): PasswordResetToken model + two self-service UserHistory events (ADR-0086 §F4)
  • feat(shared): export the auth-password schemas
  • feat(shared): pin the two new verbs in the recent-activity actions test
  • feat(shared): add password_changed + password_reset_completed recent-activity verbs (ADR-0086 §F4)
  • feat(shared): pin the two self-service password events in the user-history enum test
  • feat(shared): add PASSWORD_CHANGED + PASSWORD_RESET_COMPLETED to UserHistoryEventType (ADR-0086 §F4)
  • feat(shared): tests for the password-lifecycle schemas
  • feat(shared): local-mode password-lifecycle wire contracts (change/forgot/reset) + PASSWORD_CHANGE_REQUIRED code (ADR-0086 §F4)
  • feat(infra): dev-setup local-auth default + --zitadel opt-in (#1000)
  • feat(infra): start.sh 3-way auth with local default + SESSION_SIGNING_SECRET (#1000)
  • feat(infra): import the auth site via an empty-safe glob (#1000)
  • feat(infra): extract the Caddy auth.{domain} site to sites/auth.caddy (#1000)
  • feat(infra): profile the dev Zitadel stack behind oidc in the dev override (#1000)
  • feat(infra): move api/web zitadel_secrets mounts to the oidc overlay (#1000)
  • feat(infra): add docker-compose.oidc.yaml overlay for the bundled Zitadel (#1000)
  • feat(infra): move Zitadel to profiles:[oidc] + mode-aware backup cron (#1000)
  • feat: local setup i18n keys (en+es) (#999)
  • feat: local login i18n keys (en+es) (#999)
  • feat: mode-aware done copy in setup wizard (#999)
  • feat: local-mode welcome step (no IdP picker) (#999)
  • feat: setup wizard local-mode fork (#999)
  • feat: add local to IdpChoice (#999)
  • feat: branch /login on authMode=local (#999)
  • feat: local sign-in form component (#999)
  • feat: add Credentials provider + cookie-scheme fix to auth.ts (#999)
  • feat: test reset-password 200 local-mode body path
  • feat: reset-password returns 200 { temporaryPassword } in local mode, 204 in OIDC (ADR-0086 §5)
  • feat: test local create hashing + local reset mint/epoch/audit + directoryOnly guard
  • feat: local branches in create (hash) + requestPasswordReset (temp-password, epoch-bump, audit) (ADR-0086 §5)
  • feat: test local setup (requires+hashes password, marker write) + oidc marker
  • feat: decouple requiresAdminPassword, local /setup branch + mode-marker write (ADR-0086 §5/§1)
  • feat: test resolveIntegrationMode local branch
  • feat: resolveIntegrationMode returns 'local' when AUTH_MODE=local (ADR-0086 §5)
  • feat: wire AUTH_MODE into the IdP factory + provide LocalProvisioningService (ADR-0086 §5)
  • feat: test LocalProvisioningService — hashing + policy-satisfying temp-password
  • feat: add LocalProvisioningService — set-password primitive + temp-password (ADR-0086 §5)
  • feat: test factory local branch + LocalIdentityProvider no-op (ADR-0086 §5)
  • feat: factory returns LocalIdentityProvider when AUTH_MODE=local (ADR-0086 §5)
  • feat: add LocalIdentityProvider — pure no-op for AUTH_MODE=local (ADR-0086 §5)
  • feat: offline migration — mustChangePassword column, PASSWORD_RESET_BY_ADMIN enum, recent_activity view (ADR-0086 §5)
  • feat: add User.mustChangePassword + PASSWORD_RESET_BY_ADMIN enum value (ADR-0086 §5)
  • feat: add AdminPasswordResetResult schema (local-mode reset temp-password, ADR-0086 §5)
  • feat: assert password_reset_by_admin in the recent-activity verb test
  • feat: add password_reset_by_admin to RECENT_ACTIVITY_ACTIONS (ADR-0086 §5)
  • feat: assert PASSWORD_RESET_BY_ADMIN in the event-type enum test
  • feat: add PASSWORD_RESET_BY_ADMIN to UserHistoryEventType (ADR-0086 §5)
  • feat: SEED_ADMIN_PASSWORD dev-only opt-in for local-auth (F1d, #994)
  • feat: reset-admin-password CLI — F1d local-auth recovery escape hatch (#994)
  • feat: extract admin password-reset core logic (F1d recovery CLI, #994)
  • feat: register LocalAuthModule in AppModule
  • feat: provide+export LocalCredentialService from AuthModule (shared by guard + login)
  • feat: add handleLocal branch to JwtAuthGuard — HS256 session verify + epoch revocation + state gates (ADR-0086 §3)
  • feat: add LocalAuthModule wiring the local login surface (ADR-0086 F1b)
  • feat: add LocalAuthController — @public rate-limited POST /auth/login (ADR-0086 §3)
  • feat: add LoginService — no-enumeration login flow + per-account backoff + rehash-on-login (ADR-0086 §3)
  • feat: add per-IP LoginRateLimitGuard for POST /auth/login (ADR-0086 §3 brute-force E)
  • feat: add LocalCredentialService — argon2id hash/verify + rehash + HS256 session mint/verify (ADR-0086 §3/§4)
  • feat: export local-auth constants + login schemas from @lazyit/shared barrel
  • feat: add local login request/response wire schemas — ADR-0086 F1b
  • feat: add local-auth shared constants (argon2id OWASP params, password cap, session TTL/alg) — ADR-0086 F1b
  • feat: mode-marker decision specs (ADR-0086 F1a)
  • feat: boot-config specs for 3-state AUTH_MODE + local signing-secret (ADR-0086 F1a)
  • feat: read + enforce the auth-mode marker at boot (ADR-0086 F1a)
  • feat: persisted auth-mode marker boot decision (ADR-0086 F1a)
  • feat: 3-state AUTH_MODE (shim|local|oidc), explicit-required + local signing-secret refine (ADR-0086 F1a)
  • feat: offline migration for local-auth columns + instance_config (ADR-0086 F1a)
  • feat: User local-auth columns + single-row InstanceConfig mode marker (ADR-0086 F1a)
  • feat: add 'local' to IntegrationMode + optional ConfigStatus.authMode (ADR-0086 F1a)

Fixes

  • fix(auth): register OIDC provider only when an issuer is configured (local-mode 500) (#1008)
  • fix(api): tests for the same-password rejection + reset-token sweep on change (F-2/F-3)
  • fix(api): reject same-password change + kill outstanding reset tokens on change (F-2/F-3, #1005)
  • fix: re-pin recent_activity canonical migration to 20260703010000_local_auth_provisioning (#618 guard)
  • fix: add es 'local' identity-provider label (ADR-0086 F1a)
  • fix: add en 'local' identity-provider label (ADR-0086 F1a)
  • fix: add 'local' to the exhaustive IntegrationMode label map (ADR-0086 F1a shared→web ripple)

Full changelog: v1.2.0...v1.3.0