Skip to content

Latest commit

 

History

History
424 lines (303 loc) · 31 KB

File metadata and controls

424 lines (303 loc) · 31 KB

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, this project adheres to Semantic Versioning, commits follow Conventional Commits, and this changelog is generated by Structured Changelog.

v0.11.0 - 2026-10-02

Highlights

  • coreauth -> systemauth: the identity/auth server package, binary, bootstrap user, JWKS key id, env var, and observability metric namespace all rename; the parallel CoreControl naming is retired in favor of the same name
  • cf_ table prefix -> sf_: all 26 identity tables, via the Ent schema annotations
  • API-key visible prefix cf_ -> sf_: newly issued keys read sf_live_.../sf_test_...
  • Unified cross-app principal-link field: PrincipalMixin's sf_principal_id replaces the divergent core_control_principal_id / core_auth_principal_id spelling

Breaking

  • identity/coreauth -> identity/systemauth import path; cmd/coreauth -> cmd/systemauth binary; CoreControlConfig and related types renamed to SystemAuthConfig etc. (d97bdde)
  • All cf_* tables renamed to sf_*; migrations/0001_rename_cf_to_sf.sql provided for an existing dev database with data to keep (5f78037)
  • identity/apikey.DefaultPrefix and identity/credential.APIKeyPrefix move from cf_ to sf_; dev-issued cf_-prefixed keys must be reissued (385fe99)
  • PrincipalMixin's SSO-federation link field renamed to sf_principal_id; consumers on core_control_principal_id or core_auth_principal_id must rename and regenerate Ent (5734a60)

Documentation

  • README Database Tables and Migration Strategy sections updated to sf_*

v0.10.0 - 2026-09-06

Highlights

  • Module path moved from github.com/grokify/systemforge to github.com/plexusone/systemforge; the GitHub repository was transferred to the plexusone org
  • Cross-app authorization vocabulary contract (AppVocabulary) and registry so Forge platform apps share one role/permission/scope convention
  • Shared SpiceDB base schema (principal/organization/platform) with a composition helper for app-contributed fragments

Breaking

  • Module path changed to github.com/plexusone/systemforge. Update imports from github.com/grokify/systemforge/... to github.com/plexusone/systemforge/... (the API is unchanged); the old path still resolves via GitHub's repository-transfer redirect but will not receive new tags (852744b)

Added

  • authz.AppVocabulary contract and VocabularyRegistry validating app-name format, {app}:{resource}:{verb} scope naming, role-hierarchy coverage, and {app}_-prefixed SpiceDB definitions (7886093)
  • BaseSpiceDBSchema and VocabularyRegistry.ComposeSpiceDBSchema, assembling the platform base plus every registered app fragment and rejecting duplicate definitions (d61bc4f)

Fixed

  • Close a line-anchored regex bypass in SpiceDB schema-definition detection: a fragment packing two definitions onto one physical line hid the second from both the {app}_-prefix check and the duplicate-shadowing check, while the raw fragment was still concatenated verbatim into the composed schema — letting an app silently redefine a reserved or foreign definition (3f43040)
  • Exclude github.com/KimMachineGun/automemlimit v1.0.0, which removed memlimit.SetGoMemLimitWithOpts and broke the build via jzelinskie/cobrautil/v2/cobraproclimits (a64fce1)
  • Reference the shared plexusone/.github CI workflows at @main (with check-latest: true added upstream) instead of a stale pinned tag, so go.mod's required Go patch version resolves correctly (1e27a9a)

Dependencies

  • Bump github.com/authzed/spicedb from 1.56.0 to 1.56.1 (84b83e4)
  • Bump google.golang.org/grpc from 1.83.1 to 1.83.2 (1c54f67)
  • Additional transitive dependency updates via go get -u ./... (c86ca67)

Documentation

  • Publish the INIT-SYSTEMFORGE-001 (unified Forge authorization/IAM/shell) and INIT-SYSTEMFORGE-002 (grokify-to-plexusone migration) initiative specs (fd97642)

v0.9.0 - 2026-08-23

Highlights

  • DPoP (RFC 9449) extracted to the standalone github.com/grokify/goauth/dpop package; consumers must update their import path
  • GuardSQL authorization adapter (authzguardsql) consolidated into SystemForge
  • OpenAPI 3.1 spec with an interactive Scalar API reference in the docs site

Breaking

  • The session/dpop package has been removed; DPoP now lives at github.com/grokify/goauth/dpop. Update imports from github.com/grokify/systemforge/session/dpop to github.com/grokify/goauth/dpop (the API is unchanged). The session/bff layer that binds DPoP to sessions remains in SystemForge (1892c0d)

Added

  • authzguardsql adapter mapping GuardSQL schemas/policies to SystemForge authorization (PolicyBuilder, ResourceBuilder, DefaultResourceBuilder); depends on github.com/grokify/guardsql (cc789a7)
  • OpenAPI 3.1 specification and a Scalar interactive API reference (b271108)

Changed

  • bff reverse proxy migrated from the deprecated httputil.ReverseProxy.Director to Rewrite (Go 1.26 SA1019), propagating the session via the outbound request context (1892c0d)

Dependencies

  • Bump github.com/authzed/spicedb from 1.54.0 to 1.56.0 (7624e7f)
  • Bump google.golang.org/grpc from 1.81.1 to 1.83.0 (8b6beab)
  • Bump github.com/redis/go-redis/v9 from 9.20.1 to 9.22.0 (2511c16)
  • Bump github.com/danielgtaylor/huma/v2 from 2.38.0 to 2.39.1 (5c7efaa)
  • Bump golang.org/x/crypto from 0.53.0 to 0.55.0 (ad7951e)
  • Bump github.com/mattn/go-sqlite3 from 1.14.46 to 1.14.50 (35e8528)
  • Bump github.com/plexusone/omniobserve from 0.11.0 to 0.12.0 (af41e73)
  • Additional dependency and toolchain updates (2065044)

Documentation

  • Add a query policy engines guide and integrate it across the docs (434862c)
  • Integrate the interactive API docs into site navigation (293eb0b)
  • Document the authzguardsql adapter and the guardsql rename (ac300af)
  • Update README shields (9b8c673)

v0.8.0 - 2026-06-21

Highlights

  • Organization ownership transfer with transaction-safe implementation
  • OmniStorage session backend with Redis support and size limits
  • SpiceDB API compatibility fix for v1.54.0+

Added

  • Organization ownership transfer functionality with TransferOwnership method (7be89d8)
  • POST /organizations/{slug}/transfer-ownership API endpoint (7be89d8)
  • TransferOwnershipInput type for transfer configuration (7be89d8)
  • OmniStorage session store backend with memory and Redis support (3493416)
  • Session size limits and per-user session limits with auto-eviction (3493416)
  • Site isolation for multi-tenant session management (3493416)

Fixed

  • SpiceDB client API compatibility with v1.54.0+ using grpc.NewClient (4aa41ae)

Dependencies

  • Bump go from 1.26.2 to 1.26.4 (0333e6b)
  • Bump github.com/authzed/authzed-go from 1.9.0 to 1.10.0 (0333e6b)
  • Bump github.com/authzed/spicedb from 1.52.0 to 1.54.0 (0333e6b)
  • Bump github.com/danielgtaylor/huma/v2 from 2.37.3 to 2.38.0 (0333e6b)
  • Bump github.com/go-chi/chi/v5 from 5.2.5 to 5.3.0 (0333e6b)
  • Bump github.com/jackc/pgx/v5 from 5.9.2 to 5.10.0 (0333e6b)
  • Bump github.com/mattn/go-sqlite3 from 1.14.44 to 1.14.46 (0333e6b)
  • Bump github.com/plexusone/omniobserve from 0.9.0 to 0.11.0 (b2a4c49)
  • Add github.com/plexusone/omnistorage-core v0.5.0 (b2a4c49)
  • Bump github.com/redis/go-redis/v9 from 9.19.0 to 9.20.1 (b2a4c49)
  • Bump golang.org/x/crypto from 0.50.0 to 0.53.0 (b2a4c49)
  • Bump google.golang.org/grpc from 1.81.0 to 1.81.1 (b2a4c49)

Documentation

  • Session management overview with architecture diagram (b3d0cd6)
  • BFF sessions documentation with store interface and backends (b3d0cd6)
  • Ownership transfer documentation in memberships guide (f7218a1)

v0.7.0 - 2026-05-10

Highlights

  • BREAKING: Renamed project from CoreForge to SystemForge
  • ProductGraph integration for event correlation and tracking
  • Session invalidation with memory and Redis stores
  • Account lockout protection for identity module

Added

  • ProductGraph client for event correlation and tracking (cf8aa54)
  • ProductGraph integration with observability module (df5c013)
  • Session invalidation with MemoryStore and RedisStore implementations (b4077b1)
  • Account lockout protection in identity module (500fd61)

Changed

  • BREAKING: Renamed project from CoreForge to SystemForge - update all imports from coreforge to systemforge (dc9b68f)

Fixed

  • Session IsExpired flaky test on Windows due to time resolution (e332cfa)
  • golangci-lint errcheck, gosec G115, staticcheck SA1019 issues (16cfbe1)
  • gosec G710 open redirect and G124 insecure cookie lint issues (d8de86f)

Dependencies

  • Bump github.com/plexusone/omniobserve from 0.8.0 to 0.9.0 (2fd164e)
  • Bump google.golang.org/grpc from 1.80.0 to 1.81.0 (2e809c5)
  • Bump github.com/mattn/go-sqlite3 from 1.14.42 to 1.14.44 (4e17458)
  • Bump github.com/authzed/spicedb from 1.51.1 to 1.52.0 (17b7839)
  • Bump github.com/redis/go-redis/v9 from 9.18.0 to 9.19.0 (b85b324)
  • Bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2 (15bbb86)
  • Bump github.com/invopop/jsonschema from 0.13.0 to 0.14.0 (7bd75e2)

Documentation

  • Observability overview documentation (98b3669)
  • ProductGraph task tracking documentation (9ce6db1)
  • ProductGraph integration design documents (062b663)

v0.6.0 - 2026-04-12

Highlights

  • Multi-app platform infrastructure for running multiple SaaS apps on shared backend
  • Schema-per-app PostgreSQL isolation with X-App-ID header routing
  • SystemForge identity and session integration for multiapp deployments

Security

  • Generic 404 responses for missing/invalid X-App-ID to prevent enumeration attacks (f6a70ba)

Added

  • Multi-app server with MultiAppMode and SingleAppMode deployment options (fa15800)
  • AppBackend interface for composable app registration with lifecycle hooks (fa15800)
  • Schema-per-app database isolation using PostgreSQL schemas (app_ prefix) (fa15800)
  • X-App-ID header routing for multi-tenant request dispatch (fa15800)
  • Redis and in-memory cache implementations with app-scoped prefixes (fa15800)
  • SystemForge identity integration with JWT claims extraction and validation (82df768)
  • Session management helpers for multi-tenant deployments (82df768)
  • Ent client factory for schema-isolated database connections (82df768)
  • HTTP middleware for authentication and tenant context propagation (82df768)
  • Example app backend implementation demonstrating AppBackend interface (aac27fc)

Dependencies

  • Bump github.com/mattn/go-sqlite3 from 1.14.40 to 1.14.42 (a895c55)
  • Bump golang.org/x/crypto from 0.49.0 to 0.50.0 (2e1080a)

Documentation

  • Multiapp architecture documentation with deployment patterns (1d705e1)

v0.5.0 - 2026-04-05

Highlights

  • Audience-aware JWT tokens for BFF vs API client separation
  • Ent-backed stores for API keys and BFF sessions with AES-256-GCM encryption
  • Reusable Ent schema mixins for API keys and BFF sessions

Added

  • Audience-aware JWT tokens with GenerateBFFTokenPair and GenerateAPIToken methods (92fa0c5)
  • AES-256-GCM token encryption for BFF sessions with Encryptor type (b978729)
  • Ent-backed BFF session store with automatic expired session cleanup (b978729)
  • Ent-backed API key store with EntClientInterface for app integration (0f352f8)
  • APIKey Ent mixin with fields for key management (prefix, hash, scopes, environment) (896f5a1)
  • BFFSession Ent mixin with encrypted token fields and session metadata (896f5a1)

Dependencies

  • Bump github.com/authzed/spicedb from 1.50.0 to 1.51.0 (5e5f55c)
  • Bump entgo.io/ent from 0.14.5 to 0.14.6 (d2354a0)
  • Bump github.com/danielgtaylor/huma/v2 from 2.37.2 to 2.37.3 (c005e12)
  • Bump github.com/mattn/go-sqlite3 from 1.14.37 to 1.14.38 (9cc6298)
  • Bump google.golang.org/grpc from 1.79.3 to 1.80.0 (994d1c7)

Documentation

  • JWT audience separation guide for BFF vs API tokens (5b4869a)
  • Ent-backed session store integration guide (5b4869a)
  • API key Ent store implementation documentation (5b4869a)
  • OAuth client package documentation (5b4869a)
  • Design documents for JWT audience and Ent stores features (e00bbcc)

v0.4.0 - 2026-03-23

Highlights

  • Backend for Frontend (BFF) package with session management, rate limiting, and API proxy
  • Public profile fields for users and organizations enabling directory listings
  • Huma framework integration for OpenAPI schema generation in BFF endpoints

Added

  • BFF HTTP handler with session creation, API proxy, and CSRF protection (aa49751)
  • Token bucket rate limiter with per-endpoint overrides and standard headers (717bd88)
  • Client IP extraction with Cloudflare and proxy header support (e55385e)
  • Huma API integration for BFF with OpenAPI schema generation (c06a603)
  • Public profile fields for HumanMixin (slug, headline, bio, social links) (d7bfcd1)
  • Public listing fields for OrganizationBase (tagline, description, website) (464b163)

Dependencies

  • Bump github.com/authzed/spicedb from 1.49.2 to 1.50.0 (5d8eb51)
  • Bump google.golang.org/grpc from 1.79.2 to 1.79.3 (b1aadf1)
  • Bump github.com/mattn/go-sqlite3 from 1.14.34 to 1.14.37 (77ebd8c)

Documentation

  • BFF pattern documentation with architecture and integration examples (e680ea0)

Infrastructure

  • Updated shared CI workflows to Go 1.26.x only (f215759)

v0.3.0 - 2026-03-14

Highlights

  • Vendor-agnostic observability integration with OmniObserve (Datadog, New Relic, Dynatrace, OTLP)
  • SaaS marketplace infrastructure with Stripe billing and seat-based licensing
  • Redis-backed rate limiting with sliding window and token bucket algorithms
  • OAuth client management and provider abstraction for CoreAuth

Added

  • Observability package with OmniObserve integration for metrics, traces, and logs (ea139a6)
  • Marketplace package with Stripe subscription and seat-based licensing (c0ba5bd)
  • OAuth client management service in identity/oauthclient (2da5d87)
  • CoreAPI rate limiting package with policy-based controls (3771a54)
  • Redis-backed rate limiter with sliding window algorithm (0269db8)
  • Marketplace Ent entities: License, Listing, Subscription, SeatAssignment (db60b3c)
  • CoreAuth provider abstraction layer for pluggable authentication (bf5a90a)
  • JWT claims enhancement with audience and issuer validation (087d8dd)
  • Session middleware improvements with context utilities (cb60d99)

Dependencies

  • Upgraded OmniObserve to v0.8.0 with unified entry point (9a7280b)
  • Added Stripe Go SDK v82 for payment processing (9a7280b)
  • Added Redis client for rate limiting (9a7280b)

Documentation

  • Authorization PRD and TRD design documents (95d1352)
  • Marketplace PRD design document (95d1352)
  • CoreAPI and CoreAuth documentation (95d1352)

v0.2.0 - 2026-03-08

Highlights

  • SpiceDB authorization provider for Zanzibar-style relationship-based access control (ReBAC)
  • Principal-based identity model supporting humans, agents, applications, and service principals
  • SCIM 2.0 user provisioning with SystemForge-compliant patch operations
  • Identity-authorization sync automatically maintains SpiceDB relationships on identity changes

Added

  • SpiceDB authorization provider with embedded and remote modes (a7d4f61)
  • Principal identity model with type-specific extensions (Human, Agent, Application, ServicePrincipal) (0deab0a)
  • GitHub-style organization system with owner, admin, member roles (b3471b6)
  • SCIM 2.0 user provisioning endpoints with filter, patch, and bulk operations (1f78ff0)
  • Coreauth authentication server with Fosite-based OAuth 2.0 (d46d626)
  • Credential and token management service for principals (a3b02b2)
  • Standardized API contract module with consistent error handling (55be5d3)
  • Coreauth CLI for server and key management operations (803d5b1)
  • User schema extended with profile fields (locale, timezone, avatar) (a303ca5)
  • RelationshipSyncer interface for identity-authorization integration (963b3d3)
  • No-op syncer for deployments without SpiceDB (963b3d3)
  • SpiceDB integration tests with embedded server (be09d6c)

Changed

  • OAuth 2.0 implementation refactored for principal-based identity (ffff607)

Removed

  • Casbin authorization provider (replaced by SpiceDB) (dde3392)

Documentation

  • SpiceDB setup guide for embedded and remote modes (a7d4f61)
  • SpiceDB schema reference with permission inheritance model (a7d4f61)
  • Authorization integration patterns and middleware examples (963b3d3)
  • Updated module documentation for v0.2.0 (8436f16)

v0.1.0 - 2026-02-28

Highlights

  • Batteries-included Go platform module for multi-tenant SaaS applications
  • Complete identity management with users, organizations, and memberships
  • Full OAuth 2.0 server implementation using Fosite with PKCE, client credentials, and JWT bearer grants
  • Session management with JWT, DPoP (RFC 9449) proof-of-possession, and BFF pattern

Added

  • User accounts with email and Argon2id password hashing (3907780)
  • Organizations for multi-tenant applications with name, slug, plan, and settings (3907780)
  • Memberships with flexible role-based user-organization relationships (3907780)
  • OAuth account linking for GitHub and Google providers (3907780)
  • API key service for machine-to-machine authentication with scopes (d13b7a5)
  • OAuth 2.0 server using Fosite with Authorization Code + PKCE grant (297ecc7)
  • Client Credentials grant for service-to-service authentication (297ecc7)
  • Refresh Token grant with rotation and theft detection (297ecc7)
  • JWT Bearer grant (RFC 7523) for service account authentication (297ecc7)
  • Service accounts with RSA/EC key pairs for non-human identities (297ecc7)
  • Token introspection (RFC 7662) and revocation (RFC 7009) endpoints (297ecc7)
  • JWT service supporting HS256, RS256, and ES256 algorithms (4397d6a)
  • DPoP (RFC 9449) proof-of-possession token binding implementation (b086e49)
  • Backend for Frontend (BFF) pattern with server-side sessions (205886b)
  • GitHub and Google OAuth social login handlers (4ea5e42)
  • JWT Bearer and API key authentication middleware (2b84467)
  • Role-based access control (RBAC) with organization-scoped permissions (edf630e)
  • Casbin provider for advanced policy rules (edf630e)
  • Simple provider for lightweight permission checking (edf630e)
  • HTTP middleware for route protection (Chi and stdlib) (edf630e)
  • Feature flag engine with boolean, percentage, and user list flags (edb959d)
  • Organization-scoped feature flag evaluation (edb959d)
  • In-memory feature flag store for development and testing (edb959d)
  • PostgreSQL RLS policy generation and session variable helpers (7240382)
  • Tenant isolation for multi-tenant data separation (7240382)
  • Ent ORM integration with transaction helpers for tenant context (7240382)

Documentation

  • Comprehensive MkDocs documentation site with Material theme (87a8489)
  • Getting started guides: installation, quickstart, configuration (87a8489)
  • Identity module documentation: users, organizations, memberships, API keys (87a8489)
  • OAuth 2.0 documentation: apps, authorization code, client credentials, service accounts, tokens (87a8489)
  • Integration guides: existing apps and migration (87a8489)
  • API reference and Ent schema documentation (87a8489)
  • PRD and TRD design documents for authentication and OAuth (28dffa6)
  • README with badges, quick start examples, and module structure (a91b98e)

Infrastructure

  • GitHub Actions CI workflow for build and test (0f8c44c)
  • GitHub Actions lint workflow with golangci-lint (0f8c44c)
  • Dependabot configuration for Go modules and GitHub Actions (0f8c44c)