Skip to content

ddcore 0.12 ​

This series was written after the fact, from the repository's history. It records what an app would notice in each release — a capability, a contract, a default — and not every commit that went into it.

0.12.0 — 2026-09-16 ​

Added ​

  • Field permissions (SEC-02): a permlevel on a field, and permission rows per level, remove what a user may not read from documents, lists, export, Version diffs, print, per-recipient notifications and webhook payloads, and refuse a filter, sort, grouping or aggregate over them. An unwritable change is refused before the hooks run; values the user never saw survive a save and are carried by an amendment; a child table is judged by its parent. fieldLevels reaches the Desk, and ddcore.redact is there for app code, which stays trusted otherwise. See field permissions.
  • doc.applyWorkflow applies a workflow transition from server code, with the same guards the HTTP endpoint uses.
  • The documentation site: a landing page and the human guides, built with VitePress and published to GitHub Pages.
  • The Desk steps date parts with the arrow keys, and spells date placeholders in the reader's own letters rather than in English ones.

Fixed ​

  • Access scopes (SEC-01) no longer have a way around them: db.exists and dbSet apply them — a dbSet on a child row resolves its scope under the parent — Dynamic Link fields are checked on direct reads and writes, a scoped user is refused User Permission itself, and webhook administration and delivery are closed to scoped users below ignorePermissions.
  • Workflows close the same class of escape: insert, delete and db.setValue no longer bypass a workflow's guards, ignorePermissions does not lift them, and a workflow is validated when the app loads rather than at the first transition.
  • The vault's master key no longer leaks through ddcore.secret, and renaming a record re-keys its secrets instead of orphaning them.
  • Assignments: an update to a ToDo cannot rewrite the assignment or spoof assigned_by, the side effects are isolated in savepoints, and assigners and co-assignees see their own tasks.
  • Print: the page format and orientation are written into the HTML, Currency prints in the site currency, the columns block renders, and a disabled Letter Head can neither become nor clear the default.
  • A notification rule no longer offers internal DocTypes as targets, Audit Event refuses dbSet, a Single is never "new" even before its first save, and the workspace dashboard link lights only on the dashboard.

MIT Licensed · ddcore (Data Driven Core) · Development documentation (main)