Repository navigation
v0.2.0
Ships the authorization architecture evolution (DDD ubiquitous language and shared kernel for Capability/Scope/Relationship, tenant scope enforcement, ownership-based authorization, invariant catalog — ADRs 0001–0010), platform hardening (structured logging with request correlation IDs, liveness/readiness health checks, a working rate limiter on login, constant-time comparison for the migration auth key, WebSocket handshake authentication, GraphQL exception detail guarding), and the container-first cloud-agnostic deployment (ADR-0011): a native in-process WebSocket notification path replaces AWS API Gateway as the default, SMTP replaces AWS SES, and the same Docker image is now provisioned by Terraform on both Azure Container Apps and AWS ECS/Fargate, validated end-to-end on both clouds.
Also unifies the API's error response contract on {message}, removes a disconnected RSA credential-encryption endpoint with zero real consumers, fixes an N+1 query/save pattern in the notification broadcast path, and reconciles documentation (README, architecture overview, diagrams) against the actual deployment architecture — plus a full pass translating the frontend's UI strings, logs and comments from Portuguese to English.