ddcore 0.26
0.26.3 — 2026-10-05
Fixed
- A form's field widths follow the width of the form itself, not the browser window, so an open sidebar no longer squeezes a quarter-line field (a Datetime, say) until its value is cut off. Below 800px of line a quarter takes half the line; below 480px every field takes the whole line, as a phone already did.
0.26.2 — 2026-10-04
Added
- On a site with tenancy, a workspace can show something in one space only:
space: "platform" | "tenant"on the workspace, or on asidebar,shortcutsornumberCardsentry. Boot leaves out the other space's, and its number cards answer 404 there. Withoutspaceit shows in both, as before; any other value fails the load. Seereport-api(#76). - On a site with tenancy, the desk says which space it is in at the top: under the site's name in the sidebar (and in the mobile header), the tenant's title, or Platform in its own color, so the space that changes what every tenant shares never looks like a tenant. For an operator it opens the tenant menu. With the sidebar collapsed, the logo keeps the space's color. Page titles end with the space (
Projects · Demo Ltd), so browser tabs of two spaces can be told apart (#77).
Fixed
- Inside a tenant, a shared DocType no longer looks editable only to fail at save: the permissions the desk receives for it leave out write, create, delete, submit, cancel, amend and import, so Save, New, Delete, Rename, Duplicate and Import disappear, and its form and list say "Shared by every tenant: read only here" (an operator also gets Go to the platform, back to the same page). See
tenancy(#75). - A saved document's form is read only when the user may not write it, for any DocType, not only a Single or one under a workflow; its fields were left editable before (#75).
0.26.1 — 2026-10-03
Added
- A field can stay out of the desk's Duplicate with
noCopy: true; the copy takes the field's default, and aTablewith it starts empty. Seefieldtypes(#74). - On a site with tenancy, desk URLs name their tenant (
?tenant=<id>), so a link copied from the address bar opens in the space it was copied from. A link naming another tenant no longer loads the page: an operator is asked to enter that tenant (which moves the session, every tab with it), and a tenant's own user is told the link is not theirs. Seetenancy.
Changed
- Duplicate no longer copies a
uniquefield nor areadOnlyone (afetchFromstill follows its Link), on the document and on its child rows: the copy takes their defaults, so it no longer fails at save with a duplicate value or carries what the server wrote on the original (#74).
0.26.0 — 2026-10-03
Added
- An app can serve a static site to anyone under a URL prefix of its own:
defineApp({ www: { "/r": "client/checkout/build" } })serves that folder at/r/, withindex.htmlfor a directory and as the fallback of a client-side route (fallback: nullfor a plain 404), so a public page — a SvelteKitadapter-staticbuild withpaths.base: "/r"— no longer needs a server of its own.GET/HEADonly,/rredirects to/r/, a path that climbs out of the folder is a 404, and every file goes out withnosniff, a referrer policy andX-Frame-Options: DENY(frame: truelifts it). A prefix is one lowercase segment, not one ddcore uses nor another app's; the load says which rule a declaration broke. The site's data comes from guest methods on the same origin. Seewww(#68). - A whitelisted method declared with
cors: truecan be called by pages on the origins listed in"cors": { "origins": [...] }inddcore.json, orDDCORE_CORS_ORIGINS(comma-separated):https://shop.example.com,https://*.partner.examplefor its subdomains, or*. The preflight answers204with the origin echoed and the method's ownmethods, and the call's response (an error too) is readable by the page,X-Request-Idincluded. Credentials are never allowed, so the caller sends an API key or comes as Guest. Every other route, and every method withoutcors, answers as before. Seecontroller-api→ "Calls from another origin" (#68).