redb 4.2.0 #16
reliktbk
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
redb4.2.0 is out across all four products. It is the largest release of the 4.x line so far, and most of it is in redb.Route: one tracing contract now lives in the core, and every transport follows it. Security fixes come first, then what breaks, then what is new.Security
redb.Identity.
/connect/logoutacts on the browser's own session: auserIdin the request no longer chooses whom to sign out. A logout without a validid_token_hintasks the End-User first, as the specification requires. Signing a user out everywhere revoked their sessions and nothing else, so refresh tokens outlived the sign-out. A retired signing key is offered to nobody now, by construction rather than by registration order. An open redirect after sign-in was possible through a control character inreturnUrl.redb.Route. An
http:consumer refuses credentials it would not check, and drops response-only headers it receives in a request; a client can no longer suppress a response header the route wrote. RabbitMQ honoursssl=trueon every connection path, including named connection factories, which never used TLS at all. The AS2 receiver authenticates before it acts, and an MDN confirms only what it actually proves.redb.Tsak. A module whose http input carries credentials no longer starts, because nothing ever checked them.
Read before upgrading
Tracing is one contract in the core, and every transport follows it. Receive spans are roots; a message that arrives without a trace context opens a root receive span rather than hanging off whatever was current; span names carry the destination; and
EnableTelemetry=falsenow covers transport spans too. This changes the shape of your traces on Kafka, RabbitMQ, AMQP, IBM MQ, SQS and SNS, Azure Service Bus, gRPC, SOAP, AS2, AS4, Telegram, Mail, Exec and the LLM connector. Dashboards built on span names or on the old parenting will need a look.seda:andvm:queues are bounded by default, at 1000, as they are in Camel. An unbounded queue hid backpressure until the process ran out of memory.A typed read fails on a value it cannot parse. A header, a property or a received body read as a type now throws instead of handing back the type's default. The same rule reached Controllers: a value that does not convert is a binding error.
Cache. A hit never replays another caller's headers, and
putstores only the headers it names. A value found under our key that is not a redb.Route cache entry is an error rather than a hit.Endpoints and repositories. A bad parameter value or an unknown parameter name stops the endpoint, on every connector; a route with a bad static target no longer starts. Idempotent and claim-check repositories are found by their bare name. There is one
ackModeon every broker consumer.An aggregation group holds its own exchanges and completes in a DI scope of its own, with
forceCompletionOnStopto close open groups on shutdown instead of dropping them without a word.RabbitMQ and Kafka have their own behavioural notes in the changelog: an RPC reply keeps its bytes, a named connection factory is the whole connection, a consumed key is carried over, and librdkafka properties that would break a stated guarantee are refused.
New
AS4 (
redb.Route.As4): eDelivery AS4 1.16 over ebMS 3.0, next to the AS2 connector.redb.Templates, a collection of seven project templates.Inbound authentication on
http:consumers andRest(...), Basic and Bearer, with REST request validation: 406, declared parameters, an error handler.RedbQueryand<redbQuery>return one object, a count or a yes or no, filter and order on the base fields of the stored object, and the route language gainedinandnot in.[ConnectionParameter]: a connection factory is the whole connection, for every connector, and TLS options carry the names most connectors use.RabbitMQ: a private CA, TLS versions, revocation checks, EXTERNAL and OAuth 2.0 logins, and a separate
publisherConnection. AS2: duplicate detection and spooling of the received message withstreamBody.Route-XML and the VS Code extension:
<bean>holds lists and references to other beans, the package gate knows repository names and types, and an option read by only one side of an endpoint is caught in the editor rather than at start.The core
The
redbconsole template turns on the PVT prefilter and change tracking. On Pro,ToAggregateSqlStringAsyncshowed the aggregate without the query'sWhere. Tree projections handleTake,SkipandDistinctafterWhereandOrderBy, andDistinctByon a tree query no longer returns every node. On SQL Server Free an unknown nested field resolved to its parent, and an array grouping skipped a key or aggregate field the item does not have; both builders now refuse what they cannot read. A stored collection element that did not convert to its element type was lost without a word.Links
Questions, or an upgrade that does not go the way this describes? Reply here or open a thread in Q&A.
All reactions