सदस्य समापन बिंदुओं के लिए सूची या विरासत CSV के रूप में सत्र के अधिकार पढ़ें
KSessionService and SecurityRoleController स्टोर अधिकार के रूप में List<String> of रोलराइट टाइप नाम। सदस्यसुरक्षानियंत्रक ने स्ट्रिंग में डाल दिया और विभाजित कि...
सत्यापित DNS प्रत्येक KnownAliases लेबल की जाँच करता है; वैकल्पिक रूप से deprecated app/मीडिया को छोड़ दें
DNS और ऑटो-cert (add mail, play, apps, sign; ड्रॉप ऐप, मीडिया) के साथ नोनअलियास को संरेखित करें।
डीडीएल को लेनदेन-जाने से बचें और बहु-पॉड दौड़ को सख्त करें
पिछले स्व-चिकित्सा ने डीडीएल को @transactional सिंक ऑल () के अंदर डाल दिया। जब ALTER टेबल एडीडी कॉन्स्ट्रेंट ने एक मौजूदा बाधा (पहले के बाद सामान्य मामले) पर फा...
रोलराइट्स
रोलराइट टाइप को जोड़ने या हटाने के लिए फिर से चलने की आवश्यकता नहीं होनी चाहिए KamoInitializerService. सिंकऑल () अब हर स्टार्टअप पर तीन चरण चलाते हैं: 1. हील ब...
पंजीकरण पर orgOriginal सेट करें और मेरीनेटवर्क्स में isOriginalOrg को उजागर करें
रोलRightsSyncService निकालें और सिंक-दाएं समापन बिंदु जोड़ें
- रोलRightsSyncService: दोनों के लिए भूमिका अधिकार सिंक लॉजिक को केंद्रीकृत करता है ********** टेबल; स्टार्टअप और ऑन-डिमांड - DataLoader: स्टार्टअप पर रोलRights...
सदस्य पदोन्नति / पदोन्नति के लिए PATCH / सदस्यता-प्रकार का समापन बिंदु जोड़ें
GetOrganizationByIdWithFeatures in AppAvailability इंटरसेप्टर
Resolves LazyInitializationException on /api/security/leads and all अन्य CRM/POS-gated पथ। इंटरसेप्टर जिसे org.getFeatures () कहा जाता है लेनदेन बंद होने के बाद...
सदस्य टैब को हाइबरनेट TYPE () आधार श्रेणी के मुद्दे के कारण खाली दिखाना
हाइबरनेट के TYPE(m) = :type JPQL फिल्टर रिटर्न 0 परिणाम जब सीमा पैरामीटर आधार सदस्य वर्ग (JOINED विरासत) है। यह प्रभावित करता है सदस्य सदस्यताकर्ता समापन बिंदु।...
हाइबरनेट SQL लॉगिंग को सदस्यों के क्वेरी को वापस करने के लिए सक्षम करें 0
अस्थायी रूप से सक्षम org.hibernate.SQL=DEBUG को यह देखने के लिए कि किस SQL को टाइप () क्या है? जेपीक्यूएल क्वेरी सदस्य-सब्सक्राइबर एंडपॉइंट के लिए उत्पन्न होती ...
GetMembersAndSubscribers endpoint के लिए नैदानिक लॉगिंग जोड़ें
लॉग orgId, क्वेरी परिणाम गिनती, और प्रति सदस्य isActive स्थिति मदद करने के लिए निदान क्यों सदस्यों टैब खाली सूची दिखाता है।.
Allow god-mode users to provision ownerless orgs; prefer FQDNs in domain resolution
आलसी डोमेन लोड करने के लिए अनंतिम थीम के लिए @transactional जोड़ें; प्रावधान अनुरोध से हार्डकोड डोमेन को हटा दें
Add PATCH /org/{id}/colors endpoint to safely update only color palette fields
Add theme provisioning — NATS publisher, provision-theme endpoint, logo upload
Use memberID session key and include creatorType in creatable branch-types response
Add GET /branch-types/creatable and /{id}/usages endpoints
/creatable returns branch types filtered by the caller's creator-type (OWNERS/TEAM_MEMBERS/MEMBERS) via AppliedModelEnforcementService. /{id}/usages returns th...
Use correct session key 'memberID' instead of 'MID'
KSessionService stores member ID under key 'memberID' but both **************** and OrganizationController were reading session.get("MID") which always returned...
Exclude master model from models list; add debug log to child-org creation check
SecurityModelController now filters out the org's master model (identified by org.getMasterModelID()) from the /api/security/models response — it is managed exc...
Read session rights as List<String> names, not CSV of integer IDs
Session rights are stored as a JSON array of RoleRightType name strings. Both **************** and OrganizationController were casting them to String (causing C...
Add GET /branch-types/creatable endpoint with creator-type filtering
Returns only the branch types the calling member is permitted to create a child org under, based on their OWNERS/TEAM_MEMBERS/MEMBERS classification against the...
Gate /network child-org creation by right + member-type applicability
Wires the applied-security-model child-org creation gate end-to-end: - SecurityModelController + MasterModelController round-trip the three new apply-to flag...
Rebuild for kamo-shared-library update (appConfig upsert-only fix)
Pulls the hardened **************** that no longer deletes appConfig rows whose service types are absent from the caller's payload — prevents silent data loss w...
Applied-model is the read-time source of truth for feature availability
Closes the "stale DB leaks a disabled feature" gap by gating every surface that touches OrgFeature / ServiceType through the applied security model. - ********...
Surface root-cause on MasterModelController GET failure
When GET /api/security/master-model 500s, log the full stack trace to stderr (captured by kubectl logs) and include the root-cause message on the wire rather th...
Wire applied-model enforcement across every controller
Every non-role setting on the applied security model is now enforced at the exact controller boundary it governs, and the scalar settings round-trip cleanly thr...
Enforce system-role assignment and auto-admin for team-member owners
MemberSecurityController now enforces the three assignment invariants defined in the brainstorm spec: - saveMemberSecurity: before persisting the caller's requ...
Master-model + applied-model endpoints and template-aware org seeding
Adds the controllers that surface the new branch-type security flow: - /api/security/master-model (GET/PUT) manages the current org's master model; only writ...
Add org-scoping, password length validation, and code quality improvements to PasswordChangeController
Add @Transactional to DataLoader.run to fix LazyInitializationException on startup
Use JPA entity traversal for grant-all detection (covers dept/job roles)
Supplement session rights with all known rights for grant-all roles
Filter null rights in buildAppliedRightsWithSources; upgrade shared-lib to 1.5.0
Use core NATS pub/sub for email-verified SSE fan-out
Replaces in-memory ConcurrentHashMap broadcast with NATS core pub/sub so all pods receive verification events regardless of which pod handled the token. Falls b...
Add SSE endpoint for real-time email verification + improve welcome email logging
Add resetCode to password reset email, add emailVerifyByCode endpoint, send WELCOME_MEMBER after email verification
Use avatarType field + JDBC for photo URL generation to handle Hibernate proxies
**************** previously used instanceof AvatarPhoto to determine avatar type and cast to read fileExtension. When Hibernate returns a base-class proxy (e.g....
Pass human-readable expiry time to email verification template
Add humanizeMinutes() helper that formats minutes as days/hours/minutes (e.g. "1 day" for 1440 min). Pass as {{expiryText}} to match updated canonical template ...
जैसा कि आप शिपिंग देखते हैं?
इन अद्यतनों में से प्रत्येक स्वचालित रूप से अपने कार्यक्षेत्र में उतरता है। प्रारंभ करें और सप्ताह के बाद इसे सप्ताह के अंत में देखें।.