TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_8.0.0-alpha1
  4. #28710

8.0.0-alpha1
TopLogic Release

2026-03-31

enhancement

major
#28994
TableComponent: ConfigKey should be customizable
#29055
User-specified CSS classes cannot override default numeric alignment in table columns
#29084
JSON Schema Support for Typed Configuration
#29092
Multi-factor authentication and self-service account management
minor
#29037
Upload/update workflows at application startup
#29095
No fixed reference to tl-build-processor in tl-parent-build
#29204
TreeGrid Modelbuilder API: Node predicate does not get component model
nice-to-have
#29103
Making REST client JSON parser robust against empty content

defect

critical
#29080
Unwanted row objects in tables with changes from other sessions
#29199
XSS vulnerability in /jsp/openapi/server/displayAPISpec.jsp
major
#28674
Security issues in the UMLJS project
#28710
Accounts with reused contact have no authorization
#28993
Filters of dynamic columns ignore the attribute type
#29042
Error in column filter for double values
#29107
StackOverflowError when rolling back in the transaction monitor
#29111
JavaDoc-based I18N generation ignores custom ResKey in I18NConstants
minor
#27850
Modelleditor swallows classification with a less-than sign in the name
#28456
Reference to missing files in subsession.jsp
#28485
Immutable/Disbled Boolean fields accessible/focusable via tab
#28651
Unnecessary space for inline tables
#28725
Pointless scroll bar in the help editor
#29053
TL-Script: format() with null input returns IllegalArgumentException
#29061
Missing replacement of KnowledgeItem by ObjectKey in Collections in Queries
#29066
"SafeHTML not started" error with scripted tests
#29069
A calculated attribute of the type "General search expression" cannot return a closure
#29073
Abstract attributes can be accessed in transient objects
#29074
The form data of a component cannot be accessed in a value transformation of a component channel
#29075
After changing the model, calculated attributes that have become invalid can no longer be edited
#29076
API key in REST interface configuration is not hidden
#29087
Incorrect access to the D&D cache in the browser
#29091
Values of a composition attribute cannot be edited if previously used in the same form
#29106
Error when restarting the KnowledgeBase
#29112
Update minimatch and serialize-javascript to fix CVE-2026-27903, CVE-2026-27904, and GHSA-5c6j-r48x-rmvq
#29197
Eclipse error after dependency update: maven-jar-plugin 3.5.0 causes "outside of a scoping block" error in m2e

update

critical
#29110
Update dependency com.fasterxml.jackson.core:jackson-core to v2.21.1 [SECURITY]
defect

major

#28710

Accounts with reused contact have no authorization

Migration

If an account is deleted and a new account is subsequently created that reuses the old contact (see #28461), the new user will have no permissions. A full security rebuild is required for the user to regain their permissions.

**Example:**

  • A contact is listed in the "responsible" attribute.
  • There is a rule that assigns a role to people listed in this attribute.
  • If this contact’s account is deleted, all roles are removed from the SecurityStorage.
  • If the account is recreated and linked to this contact, the security for this contact is not recalculated incrementally (ElementSecurityUpdateManager).

Code Migration

AccessManager role rules (e.g., InitialRoleRule.xml) must be updated. Security now functions exclusively through the model, meaning a rule must include an “attribute” and, if necessary, a “meta-element.”

  • Search and replace <step association=: Instead of navigating generally through the association table, you must identify the MetaAttribute that stores values in this table and navigate through it. For example, {{{

<step association="hasStructureChild" inverse="false" /> }}} must be changed to {{{ <step attribute="children" inverse="false" /> }}}

  • Searching and replacing <rule meta-object=: Instead of specifying the table type, the TLModel type must now be specified. For example, {{{

<rule meta-object="StoredQuery" ... }}} becomes {{{ <rule meta-element="tl.search:StoredQuery" ... }}}

Data Migration

The migrations Ticket_28710_Removed_legacy_types, Ticket_28710_Update_application_types, and Ticket_28710_RoleAssignment_TLSearch ( tl-element module) run automatically on first launch. Please note:

  • Directly assigned global roles will be lost. The hasGlobalRole table will be deleted without replacement; its data will not be transferred. This affects only applications that have programmatically assigned roles using Person#addGlobalRole(...) (the engine did not provide a user interface for this). Such assignments must be mapped as group membership plus role rules before the update.
  • The application must delete its own legacy table types. The modules `tl.legacy.tabletypes ` and ` tl .tables ` no longer exist; the engine migration deletes only the engine’s types (`tl.legacy.tabletypes`:`PersonTable`, `tl.tables`:`PersonTableInterface`, ...). If the application’s database still contains its own types from these modules (from the update from TL 6 to TL 7 or from TableInterface-based models), the application must delete them in a separate migration (template: com.top_logic.demo/src/main/webapp/WEB-INF/kbase/migration/tl-demo/Ticket_28710_Removed_legacy_types.migration.xml) and re-types attributes that reference such types (change-part-type ... target="tl.accounts:Person"). Configuration references such as IndexedObjectNaming <type name="tl.legacy.tabletypes:..."> or defaultFor="tl.legacy.tabletypes:..." must be removed.
  • hasRole is no longer a KnowledgeAssociation, but rather a MOKnowledgeObject of the model type tl.accounts:RoleAssignment (references source, dest, owner); definesRole and hasGlobalRole have been removed. Any custom *Meta.xml files that reference these tables must be updated.

Code Migration (Java)

  • BoundedRole.HAS_ROLE_ASSOCIATION and DEFINES_ROLE_ASSOCIATION are deprecated. Role assignments are written using ` BoundedRole.assignRole(context, person|group, role)` and read using ` getLocalAndGlobalRoles(context, person) ` as well as the queries ` roleAssignmentsForContext(...)` and `roleAssignmentsForRole(...)` (which return a CloseableIterator that must be closed). Code that navigates via getOutgoingAssociations(HAS_ROLE_ASSOCIATION) must be refactored. Person#getGlobalRoles(), addGlobalRole(...), and removeGlobalRole(...) are deprecated.
  • LegacyFlexWrapper and StoredFlexWrapper have been removed: Wrapper classes that inherit from them (such as StoredQuery and StoredReport in the engine) now inherit from com.top_logic.element.meta.kbbased.AttributedWrapper; MapBasedPersistancySupport.getObjects(KnowledgeItem) and setObjects(Collection, KnowledgeItem) replace the FlexData variants.
  • The extension points ExternalRoleProvider (<role-provider>) and SecurityStorageCommitObserver (<commit-observer>) on ElementAccessManager and FallbackAccessManager have been removed without replacement; programmatic role assignment must be expressed as a configured role rule.
  • AccessManager#handleSecurityUpdate(KnowledgeBase, Map, Map, Map, CommitHandler) is now called handleSecurityUpdate(TLObjectChangeSet, CommitHandler); the same applies to LogHandler#logSecurityUpdate(TLObjectChangeSet, Map, Set). An override with the old signature will no longer be silently called if it lacks the @Override annotation.
  • `RoleRule` is abstract (implementations: `DefaultRoleRule`, `SingletonRule`); `PathElement` is an interface (implementation: `PathNavigation`); `RoleRule#matches(...)` takes a `TLObject`; `ElementAccessManager#getRules()` returns a `Map<TLClass, Collection<RoleProvider>>`.
  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login