Ignorar a atualização do modelo de segurança quando a função bloqueia as edições de segurança
Ler os direitos de sessão como lista ou CSV legado para os endpoints dos membros
Direitos de armazenamento do KSessionService e SecurityRoleController como Lista<String> de Nomes do tipo "RoleRight". MemberSecurityController elenco para Stri...
Verificando-dns verifica cada rótulo conhecidoAliases; skip depreciated app/media em opcional
Alinhar conhecidosAliases com DNS e auto-cert (add mail, play, apps, sign; drop app, mídia)
Evitar o envenenamento de transações DDL e endurecer corridas de multi-pod
A auto-cura anterior colocou DDL dentro de uma @Transactional syncAll(). Quando um ALTER QUADRO ADD CONSTRAINT disparado sobre uma restrição existente (caso nor...
Fazer RoleRightsSyncService totalmente auto-cura em cada inicialização
Adicionar ou remover um RoleRightType nunca mais precisa ser executado KamoInitializerService. syncAll() agora executa três fases em cada inicialização: 1. Res...
Remover chamadas getType () da OrganizaçãoController após a Organização Remoção de tipo
Definir orgOriginal em registro e expor isOriginalOrg em minhas redes
Extrair RoleRightsSyncService e adicionar o endpoint sync-rights
- RoleRightsSyncService: centraliza a lógica de sincronização de direitos de papel para ambos OrgRole E... tabelas; inicialização e sob demanda - DataLoader: de...
Adicionar PATCH /membership-type endpoint para promoção/demoção de membros
Use getOrganizaçãoByIdWithCaracterísticas no AppDisponível Interceptador
Resolve Initialização PreguiçosaExcepção em /api/security/leades e tudo Outras vias de CRM/POS. O interceptor chamado org.getFeatures() após o fechamento da tra...
Resolver a aba Membros mostrando vazio devido ao problema Hibernate Type () de classe base
O filtro do Hibernate (m) = :type JPQL retorna 0 resultados quando o limite parâmetro é a classe de membro base (herança JOINED). Isto afecta o Endpoint dos mem...
Activar o registo do Hibernate SQL para diagnosticar a consulta de membros que retorna 0
Ativado temporariamente org.hibernate.SQL=DEBUG para ver o que SQL the Type() A consulta do JPQL gera para o endpoint dos membros-subscritores.
Adicionar registro diagnóstico para o endpoint getMembersAndSubscribers
Logs orgId, query result count, and per-member isActive status to help diagnosticar por que a aba Membros mostra lista vazia.
Allow god-mode users to provision ownerless orgs; prefer FQDNs in domain resolution
Add @Transactional to provision-theme for lazy domain loading; remove hardcoded domain from provision request
Add PATCH /org/{id}/colors endpoint to safely update only color palette fields
Add theme provisioning — NATS publisher, provision-theme endpoint, logo upload
Use memberID session key and include creatorType in creatable branch-types response
Add GET /branch-types/creatable and /{id}/usages endpoints
/creatable returns branch types filtered by the caller's creator-type (OWNERS/TEAM_MEMBERS/MEMBERS) via AppliedModelEnforcementService. /{id}/usages returns th...
Use correct session key 'memberID' instead of 'MID'
KSessionService stores member ID under key 'memberID' but both **************** and OrganizationController were reading session.get("MID") which always returned...
Exclude master model from models list; add debug log to child-org creation check
SecurityModelController now filters out the org's master model (identified by org.getMasterModelID()) from the /api/security/models response — it is managed exc...
Read session rights as List<String> names, not CSV of integer IDs
Session rights are stored as a JSON array of RoleRightType name strings. Both **************** and OrganizationController were casting them to String (causing C...
Add GET /branch-types/creatable endpoint with creator-type filtering
Returns only the branch types the calling member is permitted to create a child org under, based on their OWNERS/TEAM_MEMBERS/MEMBERS classification against the...
Gate /network child-org creation by right + member-type applicability
Wires the applied-security-model child-org creation gate end-to-end: - SecurityModelController + MasterModelController round-trip the three new apply-to flag...
Reconstruir a actualização da biblioteca partilhada com o kamo (appConfig upsert- only fixe)
Puxa o endurecido ************* que não apaga mais as linhas do appConfig cujos tipos de serviço estão ausentes da carga útil do chamador — evita perda de dados...
Applied-model is the read-time source of truth for feature availability
Closes the "stale DB leaks a disabled feature" gap by gating every surface that touches OrgFeature / ServiceType through the applied security model. - ********...
Causa raiz de superfície no MasterModelController GET falha
Quando GET /api/security/master-model 500s, registre o traço completo da pilha para stderr (captured by kubectl logs) e inclua a mensagem da causa raiz ligada o...
Wire applied-model enforcement across every controller
Every non-role setting on the applied security model is now enforced at the exact controller boundary it governs, and the scalar settings round-trip cleanly thr...
Enforce system-role assignment and auto-admin for team-member owners
MemberSecurityController now enforces the three assignment invariants defined in the brainstorm spec: - saveMemberSecurity: before persisting the caller's requ...
Master-model + applied-model endpoints and template-aware org seeding
Adds the controllers that surface the new branch-type security flow: - /api/security/master-model (GET/PUT) manages the current org's master model; only writ...
Add org-scoping, password length validation, and code quality improvements to PasswordChangeController
Add @Transactional to DataLoader.run to fix LazyInitializationException on startup
Use JPA entity traversal for grant-all detection (covers dept/job roles)
Supplement session rights with all known rights for grant-all roles
Filter null rights in buildAppliedRightsWithSources; upgrade shared-lib to 1.5.0
Use core NATS pub/sub for email-verified SSE fan-out
Replaces in-memory ConcurrentHashMap broadcast with NATS core pub/sub so all pods receive verification events regardless of which pod handled the token. Falls b...
Add SSE endpoint for real-time email verification + improve welcome email logging
Add resetCode to password reset email, add emailVerifyByCode endpoint, send WELCOME_MEMBER after email verification
Use avatarType field + JDBC for photo URL generation to handle Hibernate proxies
**************** previously used instanceof AvatarPhoto to determine avatar type and cast to read fileExtension. When Hibernate returns a base-class proxy (e.g....
Pass human-readable expiry time to email verification template
Add humanizeMinutes() helper that formats minutes as days/hours/minutes (e.g. "1 day" for 1440 min). Pass as {{expiryText}} to match updated canonical template ...
Add code-based email verification path to /verify-email endpoint
The endpoint now handles both token (link click) and userId+code (manual 6-digit entry). Token path unchanged; code path hashes the supplied code and matches ag...
Como o que vês no transporte?
Cada uma dessas atualizações pousa automaticamente em seu espaço de trabalho. Comece grátis e veja crescer semana após semana.