Skip to content

Changelog

All notable changes to Hubuum Frontend are documented in this file.

The project follows Semantic Versioning.

Unreleased

0.0.18 - 2026-09-22

Added

  • Add server-side task discovery filters, bookmarkable searches, sort controls, and cursor pagination to the Tasks workspace.
  • Show retained import, export, backup, reindex, schema-validation, and remote call details, including output retention and authorized output/report links. Missing historical values remain unknown instead of appearing as false.

Changed

  • Update Next.js to 16.3.6. Application, development, API generator, and GitHub Actions dependencies pass the release freshness gate with no exceptions.

Compatibility

  • Retain the released Server v0.0.16 baseline and its pinned image. Task discovery uses that release's search and retained-metadata contract; no backend upgrade is required for deployments already on Server v0.0.16.

0.0.17 - 2026-09-22

Compatibility

  • Adopt the released Server v0.0.16 OpenAPI contract and immutable image sha256:37b3299edd845a0c2aa7772d7d68565233ac8c1802bc44be3fb4bbc6dfa8778e from commit 8f4194ffe25d172d579b676f109efbdc71d9aab7. Regenerate the API client for credential approvals, retained task details, and task search.
  • Promote credential approval support from the tested preview to the released server baseline. Existing password confirmation and older-server fallbacks are preserved; approval secrets remain inside the BFF.
  • Before upgrading the server, deploy approval-capable clients, retain a verified v0.0.15 backup, quiesce protected mutations, drain workers, and apply the task discovery and credential approval migrations. Upgrade all API replicas and workers, administrator tools, template worker, and restore executor together. Backup format remains 6. See docs/compatibility.md for rollout requirements.

Changed

  • Run live credential mutation and approved restore browser checks as part of the complete authenticated release suite against the pinned server release.

0.0.16 - 2026-09-22

Changed

  • Upgrade disposable backend and smoke-test PostgreSQL fixtures from 17 to 18 with an immutable image pin. Test stacks create fresh databases; no production database migration is part of this change.

  • Update Next.js to 16.3.5, TanStack Query to 5.103.2, Zod to 4.6.5, CodeMirror state to 6.7.6 and view to 6.43.13, development tooling, and Docker build workflow actions. All application, development, and GitHub Actions dependencies are current; no release dependency exceptions are needed.

  • Update the pinned Orval API generator to 8.36.0 and Node 24 build/CI runtime to 24.21.0 with a verified immutable container digest.

Added

  • Add an isolated local sandbox with server tag/SHA/PR selection, restored corpus data, password provisioning, keep/resume support, and ownership-checked cleanup, including verified orphaned frontends on Linux.
  • Request fresh password confirmation for credential mutations when the server requires it, including token creation and renewal, local users and password changes, credential imports, and restore confirmation. The BFF keeps approval secrets out of the browser and preserves operation, expiry, revision, and idempotency bindings. Older servers retain their existing mutation flow.
  • Added a guided Schema workspace for Server v0.0.15: propose immutable revisions, review policy changes, analyze object impact, and explicitly activate. Saved links reopen revisions and reports; history, compliance, revalidation, and administrator pending activation share the existing console controls.
  • Added schema and validation audit filters, schema task labels, effective validation limits, and a release-pinned backend contract check.
  • Show the effective backup capture-row limit in administrator Configuration, with an unavailable value on older servers.
  • Added task cancellation with guarded queued withdrawal, durable-request polling, UTF-8 reason validation, deadline and cancellation metadata, remote dispatch evidence, and aggregate unattempted import counts. Configuration shows all per-kind execution limits.

Compatibility

  • Credential approval support is a preview for the upcoming server, verified against commit 61f1bfd3455af26254e1dc73e697a80b0536813a and image digest sha256:e40fc33e2cbd6d73ce1bb281d3836468feb28493ff4343c1099211083cf83181. The supported released-server baseline remains v0.0.15; older servers do not require the new password confirmation flow.
  • Adopted the released Server v0.0.15 OpenAPI contract and immutable CI image. Required contract checks cover schemas, retained diagnostics and HTML repair reports, cancellation, execution limits, and backup format 6.
  • Server v0.0.15 does not consolidate errors in HTML reports. The console keeps individual saved diagnostics and supports report resource-limit failures.
  • Drain old task/schema workers and run migrations before starting matching v0.0.15 server, administrator, worker, template worker, and restore-executor binaries. Restore older backups using their matching release before upgrading. See docs/compatibility.md for the full upgrade requirements.

Fixed

  • Include the script-pinned API generator in release dependency freshness checks.
  • Prevent concurrent stale-lock recovery or a delayed release from removing a newer sandbox owner's lock. Recover earlier PID-file locks safely.

0.0.15 - 2026-09-10

Added

  • Added visible keyboard hints for empty workspace search (/) and the desktop Go to control (Ctrl/Cmd+K).

Compatibility

  • Adopted the Hubuum Server v0.0.14 contract and immutable CI image. The API shapes and backup format 5 are unchanged; the server fixes backup validation and recovery of membership provenance, history, and resource revisions.
  • Use matching v0.0.14 server, administrator, template worker, and separate restore-executor binaries. This server release adds no database migration; the certified application upgrade and rollback path is from v0.0.13.

Changed

  • Updated React and its types to 19.3.0, Zod to 4.6.1, and Node.js types to 26.5.1 as part of the release dependency gate.

Fixed

  • Kept dependency freshness checks from requiring a downgrade when npm's latest tag points to an older maintenance release, while still requiring available updates in the declared dependency range.

0.0.14 - 2026-09-09

Compatibility

  • Adopted the Hubuum Server v0.0.13 contract and immutable CI image. Run the server's separate hubuum-admin --migrate workload before startup and deploy hubuum-admin --restore-executor before allowing web restore confirmations. Install the matching template worker and follow the server's version 5 backup and upgrade requirements, including intermediate upgrades from v0.0.9.
  • Updated restore confirmation for 202 Accepted, with capability-authenticated status polling through success or failure after old sessions become invalid. Keep the restore page open until completion; capabilities stay in memory.
  • Target Server v0.0.13 for its restore maintenance-generation and JSON null fixes. Upgrade the separate restore executor alongside the server and other matching binaries.

Added

  • Added About Hubuum with frontend and connected-server versions, configurable local listen addresses and ports, and Enter support in the Go to palette.
  • Added complete, on-demand resource lookup across collection, class, object, import, export, relation, membership, and IAM administration workflows.

Changed

  • Improved Go to navigation, pinned destinations, sign-in controls, resource picker placement, mobile focus, table loading continuity, keyboard shortcuts, and lazy editor loading with debounced validation.
  • Updated application and development dependencies, including Next.js 16.3.4, Playwright 1.63.0, Vitest 5.0.0, Biome 2.5.12, Orval 8.30.0, and PostCSS 8.5.28. Refreshed Valkey to 9.1.2, Alpine images to 3.24, and the pinned browser image. All GitHub Actions pins were checked against their latest stable versions; no dependency exceptions were needed.
  • Added dependency freshness and full authenticated browser release gates, portable visual checks, and Docker/Podman-compatible development startup.

Fixed

  • Kept cursor pagination synchronized with browser history and loaded complete class and object relation results, export catalogs, permission selections, principal memberships, and detail references beyond initial preload limits.
  • Aligned the release readiness backend target with the release contract and added explicit database migration workloads to disposable test stacks.

Security

  • Required per-request CSP script nonces, prevented shared caching of private responses, sandboxed active report content, and preserved safe export metadata.
  • Bounded sign-out waits while retaining a visible error when logout fails. Restore status uses a narrowly scoped capability-authenticated read route; server-side session and administrator checks continue to protect other APIs.

0.0.13 - 2026-08-29

Compatibility

  • Retained the Hubuum Server v0.0.9 contract and immutable CI target.

Added

  • Added keyboard-accessible, on-demand target-object search to object relation creation, with debounced queries, bounded results, and no eager class preload.

Changed

  • Updated all application, development, generation, container, and GitHub Actions dependencies, including Node.js 24.20.0, Next.js 16.3.3, Orval 8.27.0, Biome 2.5.11, and Vitest 4.1.11.
  • Regenerated the API client with safe normalization for mutable and tuple-based request headers before content-type defaults are merged.

0.0.12 - 2026-08-14

Compatibility

  • Retained the Hubuum Server v0.0.9 contract and immutable CI target.

Added

  • Added grouped audit filters, removable active filters, cumulative table drill-downs, readable collection context, and permission-aware actor and entity lookups.
  • Added reusable keyboard-accessible directory search for collections, classes, objects, groups, service-account owners, report includes, and remote-target scopes without eagerly preloading large resource sets.

Changed

  • Redirected expired or revoked protected sessions directly to sign-in with a resumable destination and an accessible expiry explanation.
  • Aligned the Events workspace heading and audit table values, filters, and density behavior with neighboring administration surfaces.
  • Distributed AMD64 and ARM64 image builds across native GitHub-hosted runners before assembling and attesting the multi-architecture manifest.
  • Updated Next.js to 16.3.1, Biome to 2.5.8, and Axe Playwright to 4.13.0.

Fixed

  • Preserved every configured remote-target subject type when editing and enforced object class-scope requirements for multi-subject targets.

Security

  • Rejected cross-origin, same-site sibling, contradictory, and metadata-free browser mutations at the shared BFF boundary before reading sessions or forwarding requests.
  • Enforced server-side administrator authorization for generic /api/v0/meta/* proxy requests.
  • Updated the transitive nanoid dependency to 3.3.18 to resolve GHSA-2v37-7h3g-55p8.

0.0.11 - 2026-08-07

Compatibility

  • Adopted the Hubuum Server v0.0.9 contract and pinned CI to its immutable release image digest.

Added

  • Added token cloning from token detail views, preserving exact permission and resource boundaries while requiring a fresh expiry.
  • Added matching password-confirmation fields before self-service or admin user password changes are submitted.

Changed

  • Regenerated the API client for canonical point responses, revisioned resources and permission sets, token lifecycle endpoints, nested membership principals, and backup format version 4.
  • Adapted class context, principal details and settings, collection permissions, group membership, event deliveries, and computed-field mutations to the new response and ETag contracts.
  • Updated Node.js 24 LTS to 24.19.0 and Node.js types to 26.2.0.

0.0.10 - 2026-08-05

Compatibility

  • Retained the Hubuum Server v0.0.5 contract and immutable CI target.

Added

  • Added schema-aware, class-contextual object creation with guided data rows, a synchronized JSON editor, compact structured-value previews, and focused inspection of large arrays and objects.
  • Added stable retry leases and idempotency keys for imports, exports, backups, and remote invocations so ambiguous failed responses can be retried without creating duplicate tasks.
  • Added privacy-bounded structured operational events for backend requests, BFF traffic, and Valkey health, including safe correlation, latency, status, and content-length fields.
  • Added a required authenticated browser smoke gate, a scheduled full authenticated Playwright suite, and production JavaScript performance budgets.

Changed

  • Streamed generic BFF request and response bodies without UTF-8 transcoding or full buffering, while propagating browser cancellation and preserving the existing authentication, correlation, header, and session boundaries.
  • Reduced Valkey write amplification by coalescing concurrent session hydration, refreshing sliding sessions at bounded intervals, and using conditional writes that cannot recreate deleted sessions.
  • Improved object and report workflows with readable compact counts, relative font-size preferences, stronger dark navigation contrast, and saved-query editing directly from report cards.
  • Updated ioredis to 6.0.0, Next.js to 16.3.0, CodeMirror View to 6.43.8, Biome to 2.5.7, Orval to 8.23.0, PostCSS to 8.5.25, React type packages, compatible transitive dependencies, and the pinned artifact attestation action to v4.2.2.

Fixed

  • Preserved readable labels for hidden intermediate relation paths while batching and de-duplicating related-object metadata requests.
  • Required POST for logout so cross-site navigation, link scanners, and speculative GET requests cannot revoke a session.

Security

  • Kept binary and large BFF payloads byte-preserving while continuing to keep bearer tokens server-side and suppress unsafe upstream response headers.
  • Redacted credentials, query values, fragments, and credential-bearing path segments at the structured logging boundary.

0.0.9 - 2026-07-30

Compatibility

  • Retained the Hubuum Server v0.0.5 contract and immutable CI target.

Added

  • Added Stillwater atmospheres for Sunset, Golden Hour, Clouds, and Forest, each with a complete light and dark palette, ambient artwork, and matching variable typography.
  • Added selectable bundled login backgrounds and safe discovery and serving of optional runtime-mounted private backgrounds across local, Compose, Docker, and Helm deployments.
  • Added a Recent and Pinned home workspace with responsive multi-column lists, direct class bookmarks, migration of legacy class pins, and a 30-pin limit.
  • Added contextual browser titles and focused unit and Playwright coverage for themes, navigation, resource summaries, tables, workflows, and responsive behavior.

Changed

  • Unified the console around the Stillwater design language, including navigation, menus, controls, cards, resource pages, tables, imports, tasks, administration, and account settings.
  • Reorganized navigation around Data, Workflows, Observe, and Administration, aligned account destinations, and made classes and objects directly reachable while preserving useful recent and pinned shortcuts.
  • Simplified page hierarchy and table controls, distinguished table downloads from Hubuum export workflows, and improved object, relation, computed-field, remote-invocation, and active-import exploration.
  • Updated Playwright to 1.62.1, the pinned Docker login action to v4.6.0, and the pinned artifact attestation action to v4.2.1.

Fixed

  • Improved light-theme navigation contrast, responsive top-bar behavior, profile-menu opacity, table resizing, and polling while imports and tasks are active.
  • Normalized legacy class shortcut variants so the same class is not pinned multiple times under obsolete view and create destinations.

0.0.8 - 2026-07-28

Compatibility

  • Retained the Hubuum Server v0.0.5 contract and immutable CI target.

Added

  • Added live elapsed-time values to task details, derived from lifecycle timestamps and refreshed through the existing active-task polling cycle.
  • Added Server-Timing diagnostics for bookmarkable report session access, template and cache reads, task validation or submission, output time-to-first-byte, and total response-header latency.
  • Added compact report-card metadata for the current saved-default export's generation time and stored-output expiry, kept distinct from template update time without triggering report generation.

Changed

  • Updated CodeMirror View to 6.43.7, Biome to 2.5.6, Node.js types to 26.1.2, and the pinned Docker login action to v4.5.2.
  • Tightened report-card spacing and moved result/template timing beside the collection, scope, and saved-query metadata.
  • Added readable saved-query details and class identity to report-card metadata.
  • Kept template creation in the Templates tab instead of repeating a new-template action in the Reports tab.
  • Moved the less common one-off JSON exporter into its own top-level tab so the Reports tab stays focused on saved reports.

Fixed

  • Redirected Refresh now as soon as report generation completes instead of waiting for cancellation of an unused output stream, avoiding minute-long stalls and duplicate output fetches.
  • Generated report correlation IDs with a cryptographically secure random UUID.

0.0.7 - 2026-07-27

Compatibility

  • Retained the Hubuum Server v0.0.5 contract and immutable CI target.

Added

  • Added stable authenticated report URLs for saved export templates. Reports reuse the latest viable task, regenerate when output expires or exceeds a requested maximum age, and coordinate concurrent generation through Valkey.
  • Added raw task-output pages, explicit one-time refresh URLs, customized bookmark links, and open-in-new-tab actions throughout export history and task details.
  • Added a template-first report catalog and a visual one-run configurator for query, freshness, missing-data, object, and output-limit overrides.
  • Added standard HTML document wrapping with useful metadata, responsive and print styles, alternating table rows, and an advanced full-document mode.

Changed

  • Reworked template creation into a guided details, target, query, related, rules, and design workflow while keeping the full existing export controls.
  • Made existing visual server filters editable in place and added contextual hover and keyboard-focus explanations to ambiguous report actions.

Fixed

  • Preserved the requested report destination through authentication and allowed raw report requests to select their actual response content type.
  • Rejected partially numeric export and include values instead of silently accepting numeric prefixes.

Security

  • Serve generated HTML reports without console injection and with a script-disabled sandbox policy on the authenticated console origin.

0.0.6 - 2026-07-26

Compatibility

  • Imported the Hubuum Server v0.0.5 OpenAPI contract and pinned the live compatibility suite to its immutable multi-architecture image digest. The suite now verifies public default-token lifetime discovery, authoritative login and mint expiry timestamps, and redacted token-retention settings.

Added

  • Added the effective server default lifetime beside the optional expiry field in regular token minting and initial service-account token creation.
  • Added expired-token retention, purge status, interval, and batch size to the administrator runtime-configuration view.

Fixed

  • Inferred nested export relation depth from the selected class graph and rendered the effective depth per include, preventing default nested includes from silently stopping after the first hop.
  • Ordered export-template history with the resource-supported timestamp field so opening saved history no longer fails with a valid_from sorting error.

0.0.5 - 2026-07-26

Compatibility

  • Imported the generated OpenAPI contract from the Hubuum Server v0.0.4 release PR, regenerated the BFF-prefixed client, and validated the complete live backend suite against the released v0.0.4 image. The compatibility gate now pins that image by digest and covers minting, inspecting, exercising, revoking, and rejecting both unscoped and explicitly scoped tokens.

Added

  • Added guided service-account creation with explicit owner groups, scoped initial tokens, human and service-account group membership editing, and owner-group token management from normal user accounts.
  • Added human token management for self-service and administrators while suppressing mint controls for service-account actors and disabled service accounts.
  • Added shared server-side object filter controls to object browsing, ad-hoc exports, and export-template authoring, with alphabetically ordered schema data fields.
  • Added a Grant all action to collection group-permission editing.
  • Added up to four ordered numeric object measures (sum, average, min, and max) alongside grouped or global permission-aware aggregation, with contributing/skipped counts and aggregate exports.
  • Added resolved actor, root initiator, and task provenance to audit, history, and task-event views, plus initiator filters for audit queries and event subscriptions.
  • Added keyboard-accessible token detail dialogs with complete permission and resource boundaries, resolved collection/class/object names alongside their exact IDs, lifecycle metadata, and a hash-free raw metadata view.

Changed

  • Updated token minting and token metadata for Server v0.0.4's singular scope object. Token lists now show the exact permission and resource dimensions returned by the server.
  • Moved token creation into an Escape-dismissible guided modal launched beside token exports, and aligned token lifecycle rows and actions.
  • Updated Next.js to 16.2.12, Playwright to 1.62.0, and the pinned Docker login action to v4.5.1.

Fixed

  • Reduced protected-navigation backend request fan-out by disabling eager prefetch on persistent navigation and coalescing principal, administrator, and settings bootstrap reads in a short per-session cache.

Security

  • Reject transport-controlled remote-target headers before submission and enforce the server's 255-byte limit for optional idempotency keys.

0.0.4 - 2026-07-23

Compatibility

  • Updated the pinned CI contract target to Hubuum Server v0.0.3 and imported its released OpenAPI contract, including all explicit by-name routes, permission-aware object aggregates, client pagination discovery, computed querying, and RFC 6902 object-data patching.

Added

  • Added full-class, permission-aware object grouping with server filters, aggregate cursor pagination, exact aggregate totals, and distinct null, missing, and unavailable groups. Personal custom fallback fields retain page-local grouping because their display expressions are not server fields.
  • Added result-type-aware shared and personal computed-field filters and full-result computed sorting to the objects workspace.
  • Added guarded JSON Patch saves for focused and data-only object edits, including a granular advanced-editor change review, so stale values fail safely and unrelated concurrent data changes can compose.
  • Added effective pagination-limit discovery for the object fetch controls and forwarded the server's X-Page-Limit response metadata through the BFF.
  • Added consistent audit-event and resource-history detail dialogs with full stored-state inspection, side-arrow navigation, and keyboard browsing.

Changed

  • Reworked event-subscription, import, remote-target, and API-token creation into guided flows with progressive validation, contextual summaries, and a final review step.
  • Standardized computed-field and export-template workflows on the shared, keyboard-accessible flow navigation and continue controls.
  • Replaced remote-target authentication JSON with structured secret-reference fields and made the explicit read-only preset the default for new API tokens.
  • Streamlined object details around focused inline edits, a raw JSON data editor, compact connection controls, and quick relation-depth selectors.

Fixed

  • Kept locally saved appearance and other portable preferences authoritative until a later server snapshot confirms them, and prevented application-shell initialization from resetting those preferences during a refresh.
  • Added branded favicon and Apple touch-icon assets, including the legacy precomposed path, so browser icon discovery no longer reaches a 404 route.
  • Collected every cursor page for task events, import outcomes, event sinks, and collection event subscriptions so tables and exports do not silently omit records after the first page.
  • Encoded by-name class and object path segments and reconciled Find-on-page with server-side grouping.
  • Kept long object paths, inline controls, editor hints, and audit change counts within their intended cells and lines.

Security

  • Updated Next.js to 16.2.11 and overrode Sharp to 0.35.3 to resolve the production dependency advisories reported before release.

0.0.3 - 2026-07-18

Compatibility

  • Hubuum Frontend v0.0.3 targets Hubuum Server v0.0.2; release checks run against the immutable digest published for that server image tag.

Added

  • Page-local object grouping by object, data, custom, shared computed, or personal computed fields, with aggregate counts, grouped-value sorting, example object links, and grouped exports.
  • Grouping and aggregate-sorting examples in the report template editor, populated from the selected class's fields.

Changed

  • Reworked computed-field creation into a staged field picker with available and selected columns, reordering, operation guidance, and previews.
  • Made computed columns independently selectable, identified shared and personal columns with compact icons, and sorted class data fields.
  • Added quick server-fetch limits for 50, 100, 250, and MAX, with the server compatibility cap applied when its advertised maximum is unavailable.
  • Kept read-only runtime configuration on its dedicated admin page and removed the duplicate statistics-page presentation.

Fixed

  • Hiding a computed column no longer changes computed-field definitions or starts a shared-field reindex task.

0.0.2 - 2026-07-17

Compatibility

  • Hubuum Frontend v0.0.2 targets Hubuum Server v0.0.2; release checks run against the immutable digest published for that server image tag.

Added

  • Admin-only backup and restore workspace with background backup tracking, integrity metadata, staged validation, and explicit destructive confirmation.
  • Dedicated read-only admin configuration page for the server's redacted effective runtime settings.
  • Server-persisted shared and personal computed fields with typed operations, JSON Pointer inputs, previews, shared rebuilds, and computed values in object tables, exports, search, and detail views.
  • Configurable object-reachability depth, persisted in the relations URL, for exploring paths up to 10 hops.
  • Dedicated account appearance settings for theme, density, and primary and secondary workspace colors.
  • Inline, type-aware editing for object data and direct fields on object, class, and collection detail pages.
  • Detailed audit-event inspection and administration of event sinks.
  • A complete class-relation inventory with contextual filters and clearer relation navigation.
  • Redesigned export and template-authoring workspaces with query building, related-object controls, previews, and Minijinja-aware editing.
  • Playwright browser-quality coverage for accessibility, color contrast, responsive layouts, and visual regression, with portable checks enforced in CI.

Changed

  • Simplified related-object cards to emphasize the object, description, hop count, and indirect route without displaying object data previews.
  • Improved the responsive application shell with mobile search, a single primary create action, clearer account controls, and more useful non-admin dashboard summaries.
  • Made collection, class, and object tables easier to use on narrow screens with scroll guidance, sticky identifying columns, combined column controls, and accessible sorting.
  • Improved action contrast, touch targets, compact typography, and dialog focus management across light and dark themes.
  • Standardized click-to-edit interactions and Escape-to-cancel behavior across detail views, menus, forms, and dialogs.
  • Updated the dependency baseline and adopted the TypeScript 7 compiler while retaining the TypeScript 6 programmatic API required by Next.js.

Fixed

  • Task completion notifications now catch tasks that finish before the first poll, ignore old completed-task backlogs, and remain visible above dialogs.

0.0.1 - 2026-07-13

Added

  • Initial Next.js console for Hubuum classes, objects, collections, relations, imports, exports, templates, tasks, audit history, and IAM administration.
  • Server-side BFF authentication with Valkey-backed sessions.
  • Runtime health and readiness endpoints for container orchestration.
  • Multi-architecture frontend image, OCI Helm chart, and local Compose quickstart for use with an external Hubuum Server.
  • Compatibility coverage for Hubuum Server v0.0.1.
  • Visible immutable build identity in the application shell, login page, and health endpoints.

Security

  • Backend bearer tokens remain in the frontend's server-side session store and are never stored in browser-readable or HttpOnly token cookies.
  • The production image and chart run as a non-root user with dropped capabilities and read-only root filesystems.