All checks were successful
CI/CD / detect-changes (pull_request) Successful in 19s
CI/CD / test-frontend (pull_request) Has been skipped
CI/CD / test-go-pg (pull_request) Successful in 2m14s
CI/CD / test-sqlite (pull_request) Successful in 2m56s
CI/CD / build-and-deploy (pull_request) Successful in 1m21s
surface.admin.access permission + seeded Admins system group replaces hardcoded role == "admin" middleware checks. Admin bypass removed from RequirePermission — all permissions flow through group membership. Bootstrap, seed, OIDC, and admin handlers sync group membership on role changes. Demotion/deletion safeguards use group member count. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
105 lines
4.7 KiB
Markdown
105 lines
4.7 KiB
Markdown
# Changelog
|
||
|
||
All notable changes to Switchboard Core are documented here.
|
||
|
||
## [Unreleased] — v0.2.0
|
||
|
||
### Added
|
||
|
||
- **Admin → RBAC group migration**: `surface.admin.access` permission replaces
|
||
hardcoded `role == "admin"` checks. Seeded "Admins" system group carries all
|
||
platform permissions. Admin middleware now resolves grants through the standard
|
||
permission system — no special-casing. Any group can grant `surface.admin.access`.
|
||
- `AdminsGroupID` constant (`00000000-0000-0000-0000-000000000002`)
|
||
- `SyncAdminsGroupMembership()` — shared helper used by bootstrap, seed, OIDC,
|
||
and admin handlers to keep group membership in sync with role changes
|
||
- `SeedAdminsGroupMember()` test helper
|
||
- System groups re-seeded after `TruncateAll` in test helper
|
||
|
||
### Changed
|
||
|
||
- `RequireAdmin()` / `RequireAdminPage()` now accept `store.Stores` and check
|
||
`surface.admin.access` grant instead of `role == "admin"`
|
||
- `RequirePermission()` no longer bypasses checks for admin role — admins get
|
||
permissions through group membership like everyone else
|
||
- Bootstrap/seed/OIDC login all add admin users to Admins group
|
||
- Admin create/update/delete handlers sync Admins group membership on role change
|
||
- Demotion/deletion safeguards count Admins group members instead of `CountByRole`
|
||
- Kernel permissions: 6 → 7 (added `surface.admin.access`)
|
||
|
||
### Migration notes
|
||
|
||
- 002_teams.sql (both dialects): added Admins group seed with all permissions
|
||
- No new migration files — edited in place per pre-MVP policy
|
||
|
||
---
|
||
|
||
## [v0.1.0] — 2026-03-26
|
||
|
||
Forked from chat-switchboard v0.38.5. Gutted to a pure extension platform.
|
||
|
||
### Removed
|
||
|
||
- **AI/Chat system**: providers, model catalog, routing policies, personas,
|
||
channels, messages, completion streaming, tool loop, compaction, memory,
|
||
knowledge bases, notes, workspaces, projects, folders, files, export/import
|
||
- **Task scheduler**: entire scheduler package, task store, task handlers.
|
||
Tasks will be rebuilt as a Starlark extension with three trigger primitives
|
||
(time, webhook, event)
|
||
- **Session system**: channel-based anonymous sessions. Workflow instances
|
||
will get new storage in v0.2.0
|
||
- **Health accumulator**: provider health windows, tool health tracking.
|
||
Replaced with kernel-only Prune (ws_tickets, rate_limit_counters, presence)
|
||
- **15 Go packages**: tools, compaction, extraction, roles, mentions,
|
||
notelinks, export, memory, knowledge, providers, routing, capabilities,
|
||
filters, retention, workspace
|
||
- **29 handler files**, 6 test files, ~44K lines total
|
||
|
||
### Fixed
|
||
|
||
- CI deploy: k8s resource quantity vars (`BE_MEMORY_REQUEST` → `MEMORY_REQUEST`)
|
||
aligned with CI workflow outputs — `envsubst` was producing empty strings
|
||
- CI deploy: image var (`BE_IMAGE` → `IMAGE`) — caused `InvalidImageName` in pods
|
||
- CI rollout: deployment name (`switchboard` → `switchboard-be`) — rollout
|
||
verification was looking for wrong deployment name
|
||
- Nginx BASE_PATH: regex cache-header locations intercepted static asset
|
||
requests before alias could strip the sub-path prefix — moved inside alias block
|
||
- Post-login blank page: dead Go template references (`surface-chat`,
|
||
`surface-notes`, `surface-projects`) caused html/template to silently
|
||
produce Content-Length: 0 responses
|
||
- Login branding: "Chat Switchboard" → "Switchboard Core", updated tagline
|
||
and feature pills to reflect platform pivot
|
||
|
||
### Changed
|
||
|
||
- Module renamed: `chat-switchboard` → `switchboard-core`
|
||
- VERSION: `0.1.0`
|
||
- Default DB name: `switchboard_core`
|
||
- Fresh migrations: 9 files × 2 dialects (postgres + sqlite), 27 tables
|
||
- Store interfaces: 40 → 20 (13 in interfaces.go + 7 in separate iface files)
|
||
- Stage modes: `chat_only` removed, `custom` added
|
||
- Task output modes: `channel|note|webhook` → `notification|webhook|log`
|
||
- Kernel permissions: 16 → 6 (`extension.use`, `extension.install`,
|
||
`workflow.create`, `workflow.submit`, `admin.view`, `token.unlimited`)
|
||
- Everyone group seed: `["extension.use","workflow.submit"]`
|
||
- Global settings seed: site name "Switchboard Core"
|
||
- Config: removed 7 dropped fields (SessionExpiryDays, WorkflowStaleHours,
|
||
ProviderAutoDisableThreshold, ExtractionConcurrency, etc.)
|
||
- Health stores rewritten: kernel-only Prune for stale tickets, counters, presence
|
||
- Maintenance goroutine replaces scheduler for background cleanup
|
||
|
||
### Retained
|
||
|
||
- Identity & auth (builtin, mTLS, OIDC)
|
||
- Teams, groups, permissions
|
||
- Package system (surfaces, extensions, libraries, workflows)
|
||
- Starlark sandbox with capability-gated modules
|
||
- Extension connections & dependencies
|
||
- Workflow definitions, stages, versions
|
||
- Notifications & preferences
|
||
- Audit log
|
||
- Object storage (PVC, S3)
|
||
- WebSocket hub & presence
|
||
- Multi-replica HA (ws_tickets, rate_limit_counters)
|
||
- Frontend shell (preact+htm, SDK, vendor libs)
|