ddcore 0.12
This series was written after the fact, from the repository's history. It records what an app would notice in each release — a capability, a contract, a default — and not every commit that went into it.
0.12.0 — 2026-09-16
Added
- Field permissions (SEC-02): a
permlevelon a field, and permission rows per level, remove what a user may not read from documents, lists, export, Version diffs, print, per-recipient notifications and webhook payloads, and refuse a filter, sort, grouping or aggregate over them. An unwritable change is refused before the hooks run; values the user never saw survive a save and are carried by an amendment; a child table is judged by its parent.fieldLevelsreaches the Desk, andddcore.redactis there for app code, which stays trusted otherwise. See field permissions. doc.applyWorkflowapplies a workflow transition from server code, with the same guards the HTTP endpoint uses.- The documentation site: a landing page and the human guides, built with VitePress and published to GitHub Pages.
- The Desk steps date parts with the arrow keys, and spells date placeholders in the reader's own letters rather than in English ones.
Fixed
- Access scopes (SEC-01) no longer have a way around them:
db.existsanddbSetapply them — adbSeton a child row resolves its scope under the parent — Dynamic Link fields are checked on direct reads and writes, a scoped user is refusedUser Permissionitself, and webhook administration and delivery are closed to scoped users belowignorePermissions. - Workflows close the same class of escape: insert, delete and
db.setValueno longer bypass a workflow's guards,ignorePermissionsdoes not lift them, and a workflow is validated when the app loads rather than at the first transition. - The vault's master key no longer leaks through
ddcore.secret, and renaming a record re-keys its secrets instead of orphaning them. - Assignments: an update to a
ToDocannot rewrite the assignment or spoofassigned_by, the side effects are isolated in savepoints, and assigners and co-assignees see their own tasks. - Print: the page format and orientation are written into the HTML, Currency prints in the site currency, the columns block renders, and a disabled
Letter Headcan neither become nor clear the default. - A notification rule no longer offers internal DocTypes as targets,
Audit EventrefusesdbSet, a Single is never "new" even before its first save, and the workspace dashboard link lights only on the dashboard.