Skip to content

2026.0.0 - #968

Merged
qianmoQ merged 34 commits into
devlive-community:devfrom
qianmoQ:2026.0.0
Sep 21, 2026
Merged

qianmoQ merged 34 commits into
devlive-community:devfrom
qianmoQ:2026.0.0

Conversation

@qianmoQ

@qianmoQ qianmoQ commented Sep 20, 2026

Copy link
Copy Markdown
Member

Changelog category (leave one)

  • New Feature
  • Bug Fix
  • Documentation (changelog entry is not required)
  • Other

Changelog entry (Details of this change)

If there is an issue connection, write it to the end of the question
e.g: issue-7
Please delete this information when submitting

  • e.g: Support xxxx

Affected version

  • e.g: latest version

The header bar and container were nested flex containers whose children
shrank to content width, packing the menu and the right cluster to the
left; stretch them full width and distribute the menu items evenly
- rebuild the page with a hero header, a channel card (in-app plus
  installed notify plugins) with enabled/disabled status and quick
  enable, and a scenario card whose switches apply across all enabled
  channels
- add a batch settings dialog (channels x scenarios) matching the
  prototype and per-change auto save through changeNotify
- drop the old wrapper card and per-channel configure modal; add the
  notification i18n keys for en and zh-cn
- channel tiles render the actual notifyConfigure entries (in-app plus
  installed notify plugins) instead of invented email/sms channels
- scenario rows map to the server enum (created/updated/deleted/
  dynamic/syncdata) with a per-scenario channel picker in the gear
  dialog and a batch dialog applying channels x scenarios
- rename the in-app channel label and clean up unused i18n keys
Earlier experiments persisted invented channel entries (email, sms and
domain types) into the user notifyConfigure; only keep the built-in
in-app channel and installed notify plugins, silently writing the
cleaned list back
Move the breadcrumb into the content column so the sidebar card top
aligns with it, and widen the header-to-content gap
Bump the ci ui job and the frontend-maven-plugin node download to 20.x
and declare engines >=20 in package.json
- add a search input with a cmd-k shortcut hint to the header; cmd/ctrl
  + k focuses it
- drop the language select from the header (language switching lives in
  the profile preferences) and reduce the help item to its icon
- show the account avatar as a brand gradient circle with the initial
  letter instead of username text
- add a checkUsername endpoint validating the 4-20 char format
  (letters, numbers, underscores, no leading digit) and uniqueness
- rebuild the username page per prototype: hero header, current
  username field, debounced backend-validated new username input with
  success/error icons and messages, current password, info card with a
  numbered explanation list, and save/cancel actions
- add the matching i18n keys for en and zh-cn
The {id} template from the base controller collided with the literal
checkUsername path causing an ambiguous handler error
- hero header with title and description
- password form with current/new/confirm fields, a four-segment
  strength meter (weak/medium/strong) and a live criteria checklist
  (length, uppercase, digit, special character)
- security tips card with five numbered recommendations and an account
  protection promo panel; add the matching i18n keys
- hero header with title, description and brand slogan
- basic configuration card: host, API token, timeout and context count
  fields with required marks and help texts
- configuration guide card with four numbered explanations and a quick
  configuration card (OpenAI, Claude, DeepSeek, custom) that autofills
  the host address
- add a testChat endpoint performing a server-side models request to
  verify the connection, wired to the Test Connection button
Logo and menu form the left group; search, help, bell and account form
the right group pinned to the trailing edge. The menu no longer
stretches across the whole header
The left group div was never closed, so the whole header packed to the
left; now the menu group and the user cluster are two siblings
distributed by justify-between
- left sidebar with executor/dataset tabs and the configuration row
  list, each row with a quick test action that validates all fields
  server-side
- right content shows the selected entry's schema fields (string,
  number, boolean switch, password) with tooltips and descriptions
- keep list/detail/save data flow and the admin-only marker
- card header with title/description and page action slot
- filter row slot with built-in search/reset action buttons
- built-in row selection with selected-count footer and batch action
  buttons (pages opt in via rowSelection/batchActions props)
- total count and pagination grouped in the footer
- migrate the 12 list pages to the upgraded component (cards removed,
  titles passed as props)
- left field panel with dataset header, field search, all/dimension/
  metric tabs and grouped draggable field lists
- three color-coded drop zones (metrics, dimensions, filters) with
  hints, chip removal and per-chip configuration
- header actions: clear, preview, query and an overflow menu with
  publish and the row limit
- results card with query result / execution log tabs, row total and
  csv export
- append hand-maintained utility definitions (mb-1/mb-3, items-start/end,
  aspect-video, arbitrary --dc-* color classes) left undefined after the
  view-shadcn-ui removal
- swap leftover border-blue-500/ring-blue-300/stroke-blue-400 and
  hover:text-blue-400 accents to --dc-primary tokens in builder, workflow
  and dashboard editors plus header/footer
- fix pending workflow edge: stroke-dasharray was applied as a class, now
  set as an SVG attribute
- custom webkit scrollbars: 8px rounded thumb with content-box inset,
  themed via --dc-* (placeholder tone, darker on hover/active), track
  and corner transparent, follows dark mode automatically
- gate the standard scrollbar-width/color fallback behind
  @supports (-moz-appearance: none) for Firefox only: Chromium 121+
  prefers the standard properties and would ignore the webkit rules,
  falling back to macOS overlay scrollbars that stay hidden
DataSet sync failed with a NullPointerException when a plugin YAML
configure (e.g. Doris) declares pipeline entries without an executor
or type field: the filter invoked equals() on the possibly-null entry
fields. Compare with the arguments as the anchor via Objects.equals
and tolerate a null pipelines list.

Fixes devlive-community#953
…ilable

getDatabases() hardcoded a query against information_schema.SCHEMATA,
so connecting a source without that schema (e.g. Hive) failed with
'Could not resolve table reference: information_schema.schemata'.
When the SQL path fails on a healthy connection, load databases via
DatabaseMetaData.getSchemas() (getCatalogs() as a last resort) and
return them in the same response shape.

Fixes devlive-community#930
Sources without information_schema (e.g. Dameng) still failed on the
table list and column detail pages after the getDatabases fallback.
Apply the same failure-triggered fallback to getTables() and
getColumns(), loading tables/views, column details and primary keys
via DatabaseMetaData in the original response shape.

Fixes devlive-community#957
The multiplication sign rendered as a tiny asterisk and the expression
was drawn with a random color over the default black background, so
many codes were hard to read. Use the proper multiplication sign
(U+00D7), paint a white background, draw each character in a dark
random color and switch to bold sans-serif.

Fixes devlive-community#863
The default url() concatenated user-supplied host, database and URL
parameters without any validation, letting an attacker craft arbitrary
JDBC parameters - e.g. H2 INIT for remote code execution or MySQL
allowLoadLocalInfile for arbitrary file reading (issue devlive-community#966 PoCs).

Introduce JdbcUrlGuard and apply it in url(): hosts accept only
hostname characters (IPv6 literals included), databases and parameter
keys/values must not contain parameter separators, and a normalized
denylist blocks known dangerous JDBC parameters (INIT, RUNSCRIPT,
allowLoadLocalInfile, autoDeserialize, interceptors, ...). Invalid
input surfaces as a connection failure message.

Fixes devlive-community#966
… secret

Plugin installation downloads a remote archive and loads its classes
into the server JVM, but the endpoint only required an authenticated
user - combined with the well-known default JWT signing secret
(DataCapSecretKey) this allowed forging a token for any ordinary user
and achieving remote code execution.

- require the ADMIN authority on plugin install and uninstall
- log a prominent startup warning when datacap.security.secret is
  still the shipped default so operators know tokens can be forged

Fixes devlive-community#965
Extract findPipelineExecutor from convertFieldBody so the matching
logic is unit testable, and cover the issue devlive-community#953 regression: entries
missing executor/type, null pipelines and null lookup arguments must
be skipped instead of raising NullPointerException.

Fixes devlive-community#953
- url() must reject the issue devlive-community#966 payloads: H2 INIT injected through
  the database field, parameter separators in host and the
  allowLoadLocalInfile env parameter, while valid URLs still build
- getDatabases/getTables/getColumns must fall back to JDBC metadata
  when information_schema SQL fails on a healthy connection (issues
  devlive-community#930, devlive-community#957), pass successful responses through untouched and keep
  connection failures as-is

Fixes devlive-community#966
Generate 200 captchas and assert every expression uses the full-height
multiplication sign (no tiny asterisk), only contains supported
operators and that multiplication results still match their operands.

Fixes devlive-community#863
Two defects surfaced once the SQL engine tests actually ran:

- TableManager.delete inverted the no-condition case: DELETE without
  a WHERE clause kept every row and reported 0 deletions. A null
  condition now matches all rows.
- The parser keeps the raw text of string literals, so stored values
  and WHERE/SET comparisons carried surrounding single quotes.
  SQLExecutor now strips them at the insert, update and condition
  boundaries.
The Run Tests step guarded itself with
`if: ${{ env.QINIU_ENDPOINT != '' }}`, but a step cannot read its own
env mapping in the if expression and no workflow-level env exists, so
the condition always evaluated false and the whole test stage was
silently skipped. The object storage secrets are only forwarded as
-D system properties for the fs tests, which now skip on their own
when the properties are absent, so the guard is unnecessary.
With the test stage now actually running, several integration tests
hard-fail in environments that cannot satisfy their dependencies:

- Testcontainers based tests (Redis, Mongo, Dameng, Influxdb) assume
  a usable Docker environment and skip otherwise; Dameng additionally
  skips on non-amd64 hosts because its image ships amd64 only
- Redis and Mongo containers drop their fixed host port bindings in
  favor of dynamically mapped ports to avoid host port conflicts
- Tests downloading 2024.4.0-SNAPSHOT artifacts from the external CDN
  (executor remote plugin install, tar plugin loader) are gated behind
  -Ddatacap.test.remotePlugin=true; the stale artifacts are no longer
  recognized by the current plugin SPI
- Cloud storage IO tests (s3/cos/alioss) skip when their credentials
  are not provided via -D<prefix>.* system properties

Docker Desktop 29 rejects docker-java's default API version with
HTTP 400, so the guards pin api.version=1.41 unless explicitly set.
@qianmoQ
qianmoQ enabled auto-merge September 21, 2026 12:11
@qianmoQ
qianmoQ merged commit 778d3f4 into devlive-community:dev Sep 21, 2026
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant