Release 0.10.0
A privilege-escalation fix in the Windows installer, the multi-site portability work, and a documentation and API surface that a second site can rely on. The installer created C:\shopdb-flask, C:\Python314 and C:\MySQL84 without breaking inheritance from the drive root, whose default DACL grants Authenticated Users an inherit-only Modify. Two files inside those roots are executed by someone else - shopdb-admin.ps1 self-elevates, and instance config.py is loaded unconditionally by the app - so any logged-on user could replace either and wait. Verified fixed as SYSTEM in the Windows 11 VM against the shipped functions. Contract 0.19.0 is breaking: get_dashboard_widgets returns data and shape, not a component name. The change itself shipped earlier without a bump, with the contract docs still teaching the dead shape; both are corrected. The version and the changelog are the release; the detail is in the entry.
This commit is contained in:
17
CHANGELOG.md
17
CHANGELOG.md
@@ -10,6 +10,19 @@ ADR-007 and ADR-002.
|
|||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
|
## [0.10.0] - 2026-08-17
|
||||||
|
|
||||||
|
A security release. The Windows installer left the directories it creates
|
||||||
|
writable by every logged-on user, which made two of the files it puts there a
|
||||||
|
local privilege escalation; that is fixed and verified on Windows. Alongside it,
|
||||||
|
the work that makes this product genuinely adoptable by a second site: one
|
||||||
|
site's hostnames, share paths and networks are out of the product code and out
|
||||||
|
of the published documentation, and the rule that keeps them out now fails the
|
||||||
|
build rather than printing a warning nobody read.
|
||||||
|
|
||||||
|
The plugin contract moved to 0.19.0, which is a BREAKING change - see the
|
||||||
|
Changed section and CONTRACT-STABILITY.md before upgrading a plugin you wrote.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- Applications accept an uploaded image and an uploaded installer, rather than
|
- Applications accept an uploaded image and an uploaded installer, rather than
|
||||||
@@ -1002,7 +1015,9 @@ letting other GE Aerospace sites stand up their own self-hosted instance
|
|||||||
integration that passed the key as a query parameter. See
|
integration that passed the key as a query parameter. See
|
||||||
`docs/COLLECTOR-INTEGRATION.md`.
|
`docs/COLLECTOR-INTEGRATION.md`.
|
||||||
|
|
||||||
[Unreleased]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.8.1...HEAD
|
[Unreleased]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.10.0...HEAD
|
||||||
|
[0.10.0]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.9.0...v0.10.0
|
||||||
|
[0.9.0]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.8.1...v0.9.0
|
||||||
[0.8.1]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.8.0...v0.8.1
|
[0.8.1]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.8.0...v0.8.1
|
||||||
[0.8.0]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.7.0...v0.8.0
|
[0.8.0]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.7.0...v0.8.0
|
||||||
[0.7.0]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.6.0...v0.7.0
|
[0.7.0]: https://gitea.proudtech.net/ge-aerospace/shopdb-flask/compare/v0.6.0...v0.7.0
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ never by editing this file.
|
|||||||
|
|
||||||
| series | value | governed by |
|
| series | value | governed by |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| product `__version__` | `0.9.0` | ADR-007 |
|
| product `__version__` | `0.10.0` | ADR-007 |
|
||||||
| plugin contract `__contract_version__` | `0.19.0` | ADR-002 |
|
| plugin contract `__contract_version__` | `0.19.0` | ADR-002 |
|
||||||
|
|
||||||
They move independently. A contract bump is not a release.
|
They move independently. A contract bump is not a release.
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "shopdb-frontend",
|
"name": "shopdb-frontend",
|
||||||
"version": "0.9.0",
|
"version": "0.10.0",
|
||||||
"private": true,
|
"private": true,
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
@@ -63,7 +63,7 @@ __contract_version__ = '0.19.0'
|
|||||||
# plugin-contract version above are distinct series with independent
|
# plugin-contract version above are distinct series with independent
|
||||||
# bump rules. Not part of the shopdb.api contract surface, so it is
|
# bump rules. Not part of the shopdb.api contract surface, so it is
|
||||||
# not re-exported there.
|
# not re-exported there.
|
||||||
__version__ = '0.9.0'
|
__version__ = '0.10.0'
|
||||||
|
|
||||||
|
|
||||||
def create_app(config_name: str = None) -> Flask:
|
def create_app(config_name: str = None) -> Flask:
|
||||||
|
|||||||
Reference in New Issue
Block a user