All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, this project adheres to Semantic Versioning, commits follow Conventional Commits, and this changelog is generated by Structured Changelog.
v0.11.0 - 2026-10-02
- coreauth -> systemauth: the identity/auth server package, binary, bootstrap user, JWKS key id, env var, and observability metric namespace all rename; the parallel CoreControl naming is retired in favor of the same name
- cf_ table prefix -> sf_: all 26 identity tables, via the Ent schema annotations
- API-key visible prefix cf_ -> sf_: newly issued keys read sf_live_.../sf_test_...
- Unified cross-app principal-link field: PrincipalMixin's sf_principal_id replaces the divergent core_control_principal_id / core_auth_principal_id spelling
- identity/coreauth -> identity/systemauth import path; cmd/coreauth -> cmd/systemauth binary; CoreControlConfig and related types renamed to SystemAuthConfig etc. (
d97bdde) - All cf_* tables renamed to sf_*; migrations/0001_rename_cf_to_sf.sql provided for an existing dev database with data to keep (
5f78037) - identity/apikey.DefaultPrefix and identity/credential.APIKeyPrefix move from cf_ to sf_; dev-issued cf_-prefixed keys must be reissued (
385fe99) - PrincipalMixin's SSO-federation link field renamed to sf_principal_id; consumers on core_control_principal_id or core_auth_principal_id must rename and regenerate Ent (
5734a60)
- README Database Tables and Migration Strategy sections updated to sf_*
v0.10.0 - 2026-09-06
- Module path moved from
github.com/grokify/systemforgetogithub.com/plexusone/systemforge; the GitHub repository was transferred to the plexusone org - Cross-app authorization vocabulary contract (
AppVocabulary) and registry so Forge platform apps share one role/permission/scope convention - Shared SpiceDB base schema (
principal/organization/platform) with a composition helper for app-contributed fragments
- Module path changed to
github.com/plexusone/systemforge. Update imports fromgithub.com/grokify/systemforge/...togithub.com/plexusone/systemforge/...(the API is unchanged); the old path still resolves via GitHub's repository-transfer redirect but will not receive new tags (852744b)
authz.AppVocabularycontract andVocabularyRegistryvalidating app-name format,{app}:{resource}:{verb}scope naming, role-hierarchy coverage, and{app}_-prefixed SpiceDB definitions (7886093)BaseSpiceDBSchemaandVocabularyRegistry.ComposeSpiceDBSchema, assembling the platform base plus every registered app fragment and rejecting duplicate definitions (d61bc4f)
- Close a line-anchored regex bypass in SpiceDB schema-definition detection: a fragment packing two
definitions onto one physical line hid the second from both the{app}_-prefix check and the duplicate-shadowing check, while the raw fragment was still concatenated verbatim into the composed schema — letting an app silently redefine a reserved or foreign definition (3f43040) - Exclude
github.com/KimMachineGun/automemlimitv1.0.0, which removedmemlimit.SetGoMemLimitWithOptsand broke the build viajzelinskie/cobrautil/v2/cobraproclimits(a64fce1) - Reference the shared
plexusone/.githubCI workflows at@main(withcheck-latest: trueadded upstream) instead of a stale pinned tag, sogo.mod's required Go patch version resolves correctly (1e27a9a)
- Bump
github.com/authzed/spicedbfrom 1.56.0 to 1.56.1 (84b83e4) - Bump
google.golang.org/grpcfrom 1.83.1 to 1.83.2 (1c54f67) - Additional transitive dependency updates via
go get -u ./...(c86ca67)
- Publish the
INIT-SYSTEMFORGE-001(unified Forge authorization/IAM/shell) andINIT-SYSTEMFORGE-002(grokify-to-plexusone migration) initiative specs (fd97642)
v0.9.0 - 2026-08-23
- DPoP (RFC 9449) extracted to the standalone
github.com/grokify/goauth/dpoppackage; consumers must update their import path - GuardSQL authorization adapter (
authzguardsql) consolidated into SystemForge - OpenAPI 3.1 spec with an interactive Scalar API reference in the docs site
- The
session/dpoppackage has been removed; DPoP now lives atgithub.com/grokify/goauth/dpop. Update imports fromgithub.com/grokify/systemforge/session/dpoptogithub.com/grokify/goauth/dpop(the API is unchanged). The session/bff layer that binds DPoP to sessions remains in SystemForge (1892c0d)
authzguardsqladapter mapping GuardSQL schemas/policies to SystemForge authorization (PolicyBuilder,ResourceBuilder,DefaultResourceBuilder); depends ongithub.com/grokify/guardsql(cc789a7)- OpenAPI 3.1 specification and a Scalar interactive API reference (
b271108)
- bff reverse proxy migrated from the deprecated
httputil.ReverseProxy.DirectortoRewrite(Go 1.26 SA1019), propagating the session via the outbound request context (1892c0d)
- Bump
github.com/authzed/spicedbfrom 1.54.0 to 1.56.0 (7624e7f) - Bump
google.golang.org/grpcfrom 1.81.1 to 1.83.0 (8b6beab) - Bump
github.com/redis/go-redis/v9from 9.20.1 to 9.22.0 (2511c16) - Bump
github.com/danielgtaylor/huma/v2from 2.38.0 to 2.39.1 (5c7efaa) - Bump
golang.org/x/cryptofrom 0.53.0 to 0.55.0 (ad7951e) - Bump
github.com/mattn/go-sqlite3from 1.14.46 to 1.14.50 (35e8528) - Bump
github.com/plexusone/omniobservefrom 0.11.0 to 0.12.0 (af41e73) - Additional dependency and toolchain updates (
2065044)
- Add a query policy engines guide and integrate it across the docs (
434862c) - Integrate the interactive API docs into site navigation (
293eb0b) - Document the authzguardsql adapter and the guardsql rename (
ac300af) - Update README shields (
9b8c673)
v0.8.0 - 2026-06-21
- Organization ownership transfer with transaction-safe implementation
- OmniStorage session backend with Redis support and size limits
- SpiceDB API compatibility fix for v1.54.0+
- Organization ownership transfer functionality with TransferOwnership method (
7be89d8) - POST /organizations/{slug}/transfer-ownership API endpoint (
7be89d8) - TransferOwnershipInput type for transfer configuration (
7be89d8) - OmniStorage session store backend with memory and Redis support (
3493416) - Session size limits and per-user session limits with auto-eviction (
3493416) - Site isolation for multi-tenant session management (
3493416)
- SpiceDB client API compatibility with v1.54.0+ using grpc.NewClient (
4aa41ae)
- Bump go from 1.26.2 to 1.26.4 (
0333e6b) - Bump github.com/authzed/authzed-go from 1.9.0 to 1.10.0 (
0333e6b) - Bump github.com/authzed/spicedb from 1.52.0 to 1.54.0 (
0333e6b) - Bump github.com/danielgtaylor/huma/v2 from 2.37.3 to 2.38.0 (
0333e6b) - Bump github.com/go-chi/chi/v5 from 5.2.5 to 5.3.0 (
0333e6b) - Bump github.com/jackc/pgx/v5 from 5.9.2 to 5.10.0 (
0333e6b) - Bump github.com/mattn/go-sqlite3 from 1.14.44 to 1.14.46 (
0333e6b) - Bump github.com/plexusone/omniobserve from 0.9.0 to 0.11.0 (
b2a4c49) - Add github.com/plexusone/omnistorage-core v0.5.0 (
b2a4c49) - Bump github.com/redis/go-redis/v9 from 9.19.0 to 9.20.1 (
b2a4c49) - Bump golang.org/x/crypto from 0.50.0 to 0.53.0 (
b2a4c49) - Bump google.golang.org/grpc from 1.81.0 to 1.81.1 (
b2a4c49)
- Session management overview with architecture diagram (
b3d0cd6) - BFF sessions documentation with store interface and backends (
b3d0cd6) - Ownership transfer documentation in memberships guide (
f7218a1)
v0.7.0 - 2026-05-10
- BREAKING: Renamed project from CoreForge to SystemForge
- ProductGraph integration for event correlation and tracking
- Session invalidation with memory and Redis stores
- Account lockout protection for identity module
- ProductGraph client for event correlation and tracking (
cf8aa54) - ProductGraph integration with observability module (
df5c013) - Session invalidation with MemoryStore and RedisStore implementations (
b4077b1) - Account lockout protection in identity module (
500fd61)
- BREAKING: Renamed project from CoreForge to SystemForge - update all imports from coreforge to systemforge (
dc9b68f)
- Session IsExpired flaky test on Windows due to time resolution (
e332cfa) - golangci-lint errcheck, gosec G115, staticcheck SA1019 issues (
16cfbe1) - gosec G710 open redirect and G124 insecure cookie lint issues (
d8de86f)
- Bump github.com/plexusone/omniobserve from 0.8.0 to 0.9.0 (
2fd164e) - Bump google.golang.org/grpc from 1.80.0 to 1.81.0 (
2e809c5) - Bump github.com/mattn/go-sqlite3 from 1.14.42 to 1.14.44 (
4e17458) - Bump github.com/authzed/spicedb from 1.51.1 to 1.52.0 (
17b7839) - Bump github.com/redis/go-redis/v9 from 9.18.0 to 9.19.0 (
b85b324) - Bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2 (
15bbb86) - Bump github.com/invopop/jsonschema from 0.13.0 to 0.14.0 (
7bd75e2)
- Observability overview documentation (
98b3669) - ProductGraph task tracking documentation (
9ce6db1) - ProductGraph integration design documents (
062b663)
v0.6.0 - 2026-04-12
- Multi-app platform infrastructure for running multiple SaaS apps on shared backend
- Schema-per-app PostgreSQL isolation with X-App-ID header routing
- SystemForge identity and session integration for multiapp deployments
- Generic 404 responses for missing/invalid X-App-ID to prevent enumeration attacks (
f6a70ba)
- Multi-app server with
MultiAppModeandSingleAppModedeployment options (fa15800) - AppBackend interface for composable app registration with lifecycle hooks (
fa15800) - Schema-per-app database isolation using PostgreSQL schemas (
app_prefix) (fa15800) - X-App-ID header routing for multi-tenant request dispatch (
fa15800) - Redis and in-memory cache implementations with app-scoped prefixes (
fa15800) - SystemForge identity integration with JWT claims extraction and validation (
82df768) - Session management helpers for multi-tenant deployments (
82df768) - Ent client factory for schema-isolated database connections (
82df768) - HTTP middleware for authentication and tenant context propagation (
82df768) - Example app backend implementation demonstrating AppBackend interface (
aac27fc)
- Bump github.com/mattn/go-sqlite3 from 1.14.40 to 1.14.42 (
a895c55) - Bump golang.org/x/crypto from 0.49.0 to 0.50.0 (
2e1080a)
- Multiapp architecture documentation with deployment patterns (
1d705e1)
v0.5.0 - 2026-04-05
- Audience-aware JWT tokens for BFF vs API client separation
- Ent-backed stores for API keys and BFF sessions with AES-256-GCM encryption
- Reusable Ent schema mixins for API keys and BFF sessions
- Audience-aware JWT tokens with
GenerateBFFTokenPairandGenerateAPITokenmethods (92fa0c5) - AES-256-GCM token encryption for BFF sessions with
Encryptortype (b978729) - Ent-backed BFF session store with automatic expired session cleanup (
b978729) - Ent-backed API key store with
EntClientInterfacefor app integration (0f352f8) - APIKey Ent mixin with fields for key management (prefix, hash, scopes, environment) (
896f5a1) - BFFSession Ent mixin with encrypted token fields and session metadata (
896f5a1)
- Bump github.com/authzed/spicedb from 1.50.0 to 1.51.0 (
5e5f55c) - Bump entgo.io/ent from 0.14.5 to 0.14.6 (
d2354a0) - Bump github.com/danielgtaylor/huma/v2 from 2.37.2 to 2.37.3 (
c005e12) - Bump github.com/mattn/go-sqlite3 from 1.14.37 to 1.14.38 (
9cc6298) - Bump google.golang.org/grpc from 1.79.3 to 1.80.0 (
994d1c7)
- JWT audience separation guide for BFF vs API tokens (
5b4869a) - Ent-backed session store integration guide (
5b4869a) - API key Ent store implementation documentation (
5b4869a) - OAuth client package documentation (
5b4869a) - Design documents for JWT audience and Ent stores features (
e00bbcc)
v0.4.0 - 2026-03-23
- Backend for Frontend (BFF) package with session management, rate limiting, and API proxy
- Public profile fields for users and organizations enabling directory listings
- Huma framework integration for OpenAPI schema generation in BFF endpoints
- BFF HTTP handler with session creation, API proxy, and CSRF protection (
aa49751) - Token bucket rate limiter with per-endpoint overrides and standard headers (
717bd88) - Client IP extraction with Cloudflare and proxy header support (
e55385e) - Huma API integration for BFF with OpenAPI schema generation (
c06a603) - Public profile fields for HumanMixin (slug, headline, bio, social links) (
d7bfcd1) - Public listing fields for OrganizationBase (tagline, description, website) (
464b163)
- Bump github.com/authzed/spicedb from 1.49.2 to 1.50.0 (
5d8eb51) - Bump google.golang.org/grpc from 1.79.2 to 1.79.3 (
b1aadf1) - Bump github.com/mattn/go-sqlite3 from 1.14.34 to 1.14.37 (
77ebd8c)
- BFF pattern documentation with architecture and integration examples (
e680ea0)
- Updated shared CI workflows to Go 1.26.x only (
f215759)
v0.3.0 - 2026-03-14
- Vendor-agnostic observability integration with OmniObserve (Datadog, New Relic, Dynatrace, OTLP)
- SaaS marketplace infrastructure with Stripe billing and seat-based licensing
- Redis-backed rate limiting with sliding window and token bucket algorithms
- OAuth client management and provider abstraction for CoreAuth
- Observability package with OmniObserve integration for metrics, traces, and logs (
ea139a6) - Marketplace package with Stripe subscription and seat-based licensing (
c0ba5bd) - OAuth client management service in
identity/oauthclient(2da5d87) - CoreAPI rate limiting package with policy-based controls (
3771a54) - Redis-backed rate limiter with sliding window algorithm (
0269db8) - Marketplace Ent entities: License, Listing, Subscription, SeatAssignment (
db60b3c) - CoreAuth provider abstraction layer for pluggable authentication (
bf5a90a) - JWT claims enhancement with audience and issuer validation (
087d8dd) - Session middleware improvements with context utilities (
cb60d99)
- Upgraded OmniObserve to v0.8.0 with unified entry point (
9a7280b) - Added Stripe Go SDK v82 for payment processing (
9a7280b) - Added Redis client for rate limiting (
9a7280b)
- Authorization PRD and TRD design documents (
95d1352) - Marketplace PRD design document (
95d1352) - CoreAPI and CoreAuth documentation (
95d1352)
v0.2.0 - 2026-03-08
- SpiceDB authorization provider for Zanzibar-style relationship-based access control (ReBAC)
- Principal-based identity model supporting humans, agents, applications, and service principals
- SCIM 2.0 user provisioning with SystemForge-compliant patch operations
- Identity-authorization sync automatically maintains SpiceDB relationships on identity changes
- SpiceDB authorization provider with embedded and remote modes (
a7d4f61) - Principal identity model with type-specific extensions (Human, Agent, Application, ServicePrincipal) (
0deab0a) - GitHub-style organization system with owner, admin, member roles (
b3471b6) - SCIM 2.0 user provisioning endpoints with filter, patch, and bulk operations (
1f78ff0) - Coreauth authentication server with Fosite-based OAuth 2.0 (
d46d626) - Credential and token management service for principals (
a3b02b2) - Standardized API contract module with consistent error handling (
55be5d3) - Coreauth CLI for server and key management operations (
803d5b1) - User schema extended with profile fields (locale, timezone, avatar) (
a303ca5) - RelationshipSyncer interface for identity-authorization integration (
963b3d3) - No-op syncer for deployments without SpiceDB (
963b3d3) - SpiceDB integration tests with embedded server (
be09d6c)
- OAuth 2.0 implementation refactored for principal-based identity (
ffff607)
- Casbin authorization provider (replaced by SpiceDB) (
dde3392)
- SpiceDB setup guide for embedded and remote modes (
a7d4f61) - SpiceDB schema reference with permission inheritance model (
a7d4f61) - Authorization integration patterns and middleware examples (
963b3d3) - Updated module documentation for v0.2.0 (
8436f16)
v0.1.0 - 2026-02-28
- Batteries-included Go platform module for multi-tenant SaaS applications
- Complete identity management with users, organizations, and memberships
- Full OAuth 2.0 server implementation using Fosite with PKCE, client credentials, and JWT bearer grants
- Session management with JWT, DPoP (RFC 9449) proof-of-possession, and BFF pattern
- User accounts with email and Argon2id password hashing (
3907780) - Organizations for multi-tenant applications with name, slug, plan, and settings (
3907780) - Memberships with flexible role-based user-organization relationships (
3907780) - OAuth account linking for GitHub and Google providers (
3907780) - API key service for machine-to-machine authentication with scopes (
d13b7a5) - OAuth 2.0 server using Fosite with Authorization Code + PKCE grant (
297ecc7) - Client Credentials grant for service-to-service authentication (
297ecc7) - Refresh Token grant with rotation and theft detection (
297ecc7) - JWT Bearer grant (RFC 7523) for service account authentication (
297ecc7) - Service accounts with RSA/EC key pairs for non-human identities (
297ecc7) - Token introspection (RFC 7662) and revocation (RFC 7009) endpoints (
297ecc7) - JWT service supporting HS256, RS256, and ES256 algorithms (
4397d6a) - DPoP (RFC 9449) proof-of-possession token binding implementation (
b086e49) - Backend for Frontend (BFF) pattern with server-side sessions (
205886b) - GitHub and Google OAuth social login handlers (
4ea5e42) - JWT Bearer and API key authentication middleware (
2b84467) - Role-based access control (RBAC) with organization-scoped permissions (
edf630e) - Casbin provider for advanced policy rules (
edf630e) - Simple provider for lightweight permission checking (
edf630e) - HTTP middleware for route protection (Chi and stdlib) (
edf630e) - Feature flag engine with boolean, percentage, and user list flags (
edb959d) - Organization-scoped feature flag evaluation (
edb959d) - In-memory feature flag store for development and testing (
edb959d) - PostgreSQL RLS policy generation and session variable helpers (
7240382) - Tenant isolation for multi-tenant data separation (
7240382) - Ent ORM integration with transaction helpers for tenant context (
7240382)
- Comprehensive MkDocs documentation site with Material theme (
87a8489) - Getting started guides: installation, quickstart, configuration (
87a8489) - Identity module documentation: users, organizations, memberships, API keys (
87a8489) - OAuth 2.0 documentation: apps, authorization code, client credentials, service accounts, tokens (
87a8489) - Integration guides: existing apps and migration (
87a8489) - API reference and Ent schema documentation (
87a8489) - PRD and TRD design documents for authentication and OAuth (
28dffa6) - README with badges, quick start examples, and module structure (
a91b98e)