release: finalize BZOD v0.8.0
This commit is contained in:
1 parent
d7e0ac7679
commit
d398341f01
35 files changed
+2417
-525
No files matched your search
+1
-1
@@ -1,6 +1,6 @@
|
||||
# BZOD Administrator Guide
|
||||
|
||||
Version: v0.7.0
|
||||
Version: v0.8.0
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# BZOD Architecture Guide
|
||||
|
||||
Version: v0.7.0
|
||||
Version: v0.8.0
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Backup & Restore Guide
|
||||
|
||||
Version: v0.7.0
|
||||
Version: v0.8.0
|
||||
Applies To: BZOD Multi-User Platform
|
||||
|
||||
---
|
||||
|
||||
@@ -4,6 +4,31 @@ All notable changes to this project will be documented in this file.
|
||||
|
||||
The format is based on Keep a Changelog and this project follows Semantic Versioning.
|
||||
|
||||
# v0.8.0 — Core Admin Separation, Tenant Boundary & Authentication Hardening
|
||||
|
||||
## Added
|
||||
|
||||
* Core Admin is strictly platform-operator-only and has no tenant application storage.
|
||||
* Inspection-only global URL and landing-page registries for Admin.
|
||||
* Strict Admin/tenant route boundary with HTTP 403 enforcement.
|
||||
* TenantId-based active ownership and tenant filesystem topology.
|
||||
* Tenant-aware analytics worker grouping.
|
||||
* Deterministic cross-role session invalidation and cookie clearing.
|
||||
|
||||
## Changed
|
||||
|
||||
* Removed active production dependencies on the legacy `system.db.global_slugs` registry.
|
||||
* Removed request-time TenantId generation and integer tenant filesystem fallbacks from active tenant operations.
|
||||
* Admin resource creation endpoints reject Core Admin actors with `403 Forbidden`.
|
||||
* User login and Admin login now establish role-specific sessions and clear the opposite-role session.
|
||||
|
||||
## Compatibility
|
||||
|
||||
* Historical v0.7.x migration and legacy restore compatibility remains preserved.
|
||||
* Legacy database/schema identifiers are retained only where required for migration and historical restore support.
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
# v0.7.0 — Responsive UI, Theme Support & Build Metadata
|
||||
|
||||
+1
-1
@@ -2,7 +2,7 @@
|
||||
|
||||
BZOD includes a comprehensive command-line interface for server administration, backups, migrations, diagnostics, validation, and multi-user management.
|
||||
|
||||
The current command list for BZOD v0.7.0 is:
|
||||
The current command list for BZOD v0.8.0 is:
|
||||
|
||||
```text
|
||||
$ bzod --help
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
# BZOD v0.7.0 vs Self-Hosted URL Management Platforms
|
||||
# BZOD v0.8.0 vs Self-Hosted URL Management Platforms
|
||||
|
||||
BZOD is a modern, privacy-focused, self-hosted URL Management Platform written in Rust and developed as part of the NX9 Platform.
|
||||
|
||||
|
||||
+1
-1
@@ -2,7 +2,7 @@
|
||||
|
||||
# BZOD Database Architecture
|
||||
|
||||
BZOD v0.7.0 uses SQLite exclusively.
|
||||
BZOD v0.8.0 uses SQLite exclusively.
|
||||
|
||||
Rather than using a single monolithic database, BZOD separates data into administrative and tenant-specific databases. This architecture improves security, isolation, backup flexibility, disaster recovery, and scalability.
|
||||
|
||||
|
||||
+3
-3
@@ -1,6 +1,6 @@
|
||||
# BZOD Installation Guide
|
||||
|
||||
Version: v0.7.0
|
||||
Version: v0.8.0
|
||||
|
||||
---
|
||||
|
||||
@@ -183,13 +183,13 @@ sudo pacman -S \
|
||||
Example:
|
||||
|
||||
```bash
|
||||
wget https://example.com/bzod-v0.7.0-linux-amd64.tar.gz
|
||||
wget https://example.com/bzod-v0.8.0-linux-amd64.tar.gz
|
||||
```
|
||||
|
||||
Extract:
|
||||
|
||||
```bash
|
||||
tar -xzf bzod-v0.7.0-linux-amd64.tar.gz
|
||||
tar -xzf bzod-v0.8.0-linux-amd64.tar.gz
|
||||
```
|
||||
|
||||
Install:
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
# BZOD Multi-User Architecture Guide
|
||||
|
||||
Version: v0.7.0
|
||||
Version: v0.8.0
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -1,3 +1,30 @@
|
||||
# BZOD v0.8.0 — Multi-Tenant Core Separation & Authorization Hardening
|
||||
|
||||
Release Date: 2026-08-21
|
||||
|
||||
## Highlights
|
||||
|
||||
- **Core Admin separation**: Admin is a platform operator, not a tenant and not an application resource owner.
|
||||
- **Global slug registries**: Active URL and landing-page ownership uses `slugs/global_urls.db` and `slugs/global_landing_pages.db`.
|
||||
- **Strict route boundary**: Core Admin is forbidden from `/user/*`; normal tenant users are forbidden from `/admin/*`.
|
||||
- **Capability enforcement**: Admin resource creation through UI and REST/bulk endpoints returns `403 Forbidden`.
|
||||
- **Tenant identity hardening**: Active tenant operations require an immutable `TenantId`; no request-time fallback generation or `users/1` application fallback.
|
||||
- **Session hygiene**: Admin/user session cookies and server-side sessions are invalidated when switching principals or logging out.
|
||||
- **Tenant-aware analytics**: Analytics events are grouped and persisted by `TenantId`.
|
||||
- **Legacy compatibility preserved**: Legacy migration and restore paths remain available without being active production paths.
|
||||
|
||||
## Verification
|
||||
|
||||
- Phase 5 Core Separation tests: **4/4 passed**
|
||||
- Admin capability boundary tests: **11/11 passed**
|
||||
- Admin/user route and session boundary tests: **27/27 passed**
|
||||
- Phase 6A elimination tests: **6/6 passed**
|
||||
- Workspace regression suite: **all tests passed**
|
||||
- `cargo fmt --all -- --check`: **PASS**
|
||||
- `cargo clippy --workspace --all-targets --all-features -- -D warnings`: **PASS**
|
||||
|
||||
---
|
||||
|
||||
# BZOD v0.7.0 — Responsive UI, Theme Support & Build Metadata
|
||||
|
||||
Release Date: 2026-08-11
|
||||
|
||||
+4
-4
@@ -1,6 +1,6 @@
|
||||
# BZOD Security Guide
|
||||
|
||||
Version: v0.7.0
|
||||
Version: v0.8.0
|
||||
|
||||
---
|
||||
|
||||
@@ -16,7 +16,7 @@ BZOD is designed as a self-hosted URL shortener and landing page platform with a
|
||||
* Disaster recovery
|
||||
* Operational simplicity
|
||||
|
||||
This document describes the security architecture, threat model, authentication mechanisms, authorization controls, and operational security recommendations for BZOD v0.7.0.
|
||||
This document describes the security architecture, threat model, authentication mechanisms, authorization controls, and operational security recommendations for BZOD v0.8.0.
|
||||
|
||||
---
|
||||
|
||||
@@ -620,7 +620,7 @@ If compromise is suspected:
|
||||
|
||||
# Security Testing
|
||||
|
||||
BZOD v0.7.0 includes tests covering:
|
||||
BZOD v0.8.0 includes tests covering:
|
||||
|
||||
* Authentication
|
||||
* Authorization
|
||||
@@ -665,7 +665,7 @@ These may be addressed in future releases.
|
||||
|
||||
# Summary
|
||||
|
||||
BZOD v0.7.0 provides:
|
||||
BZOD v0.8.0 provides:
|
||||
|
||||
* Centralized authentication
|
||||
* Secure session management
|
||||
|
||||
+14
-2
@@ -1,11 +1,23 @@
|
||||
# Upgrade Guide
|
||||
|
||||
Version: v0.7.0
|
||||
Version: v0.8.0
|
||||
|
||||
This document describes the upgrade process for existing BZOD deployments upgrading to BZOD v0.7.0.
|
||||
This document describes the upgrade process for existing BZOD deployments upgrading to BZOD v0.8.0.
|
||||
|
||||
---
|
||||
|
||||
# BZOD v0.8.0 Upgrade Overview
|
||||
|
||||
BZOD v0.8.0 completes the TenantId-based multi-tenant topology and separates Core Admin from tenant application resources. The active runtime uses the Core databases under `admin/`, global slug registries under `slugs/`, and tenant databases under `users/<TenantId>/`.
|
||||
|
||||
Key upgrade characteristics:
|
||||
|
||||
* Core Admin has no tenant directory, `content.db`, or `analytics.db`.
|
||||
* Active production operations no longer use `system.db.global_slugs`.
|
||||
* Active tenant ownership is represented by immutable `TenantId`.
|
||||
* Legacy integer IDs and legacy slug data remain available only to migration/restore compatibility paths.
|
||||
* Existing legacy deployments should use the repository's migration and restore commands rather than manually copying legacy tenant directories into the v0.8 topology.
|
||||
|
||||
# Overview
|
||||
|
||||
BZOD v0.5.1 is a platform hardening release focused on:
|
||||
|
||||
Reference in new issue
Block a user