TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_8.0.0-alpha1
  4. #29080

8.0.0-alpha1
TopLogic Release

2026-03-31

enhancement

major
#28994
TableComponent: ConfigKey should be customizable
#29055
User-specified CSS classes cannot override default numeric alignment in table columns
#29084
JSON Schema Support for Typed Configuration
#29092
Multi-factor authentication and self-service account management
minor
#29037
Upload/update workflows at application startup
#29095
No fixed reference to tl-build-processor in tl-parent-build
#29204
TreeGrid Modelbuilder API: Node predicate does not get component model
nice-to-have
#29103
Making REST client JSON parser robust against empty content

defect

critical
#29080
Unwanted row objects in tables with changes from other sessions
#29199
XSS vulnerability in /jsp/openapi/server/displayAPISpec.jsp
major
#28674
Security issues in the UMLJS project
#28710
Accounts with reused contact have no authorization
#28993
Filters of dynamic columns ignore the attribute type
#29042
Error in column filter for double values
#29107
StackOverflowError when rolling back in the transaction monitor
#29111
JavaDoc-based I18N generation ignores custom ResKey in I18NConstants
minor
#27850
Modelleditor swallows classification with a less-than sign in the name
#28456
Reference to missing files in subsession.jsp
#28485
Immutable/Disbled Boolean fields accessible/focusable via tab
#28651
Unnecessary space for inline tables
#28725
Pointless scroll bar in the help editor
#29053
TL-Script: format() with null input returns IllegalArgumentException
#29061
Missing replacement of KnowledgeItem by ObjectKey in Collections in Queries
#29066
"SafeHTML not started" error with scripted tests
#29069
A calculated attribute of the type "General search expression" cannot return a closure
#29073
Abstract attributes can be accessed in transient objects
#29074
The form data of a component cannot be accessed in a value transformation of a component channel
#29075
After changing the model, calculated attributes that have become invalid can no longer be edited
#29076
API key in REST interface configuration is not hidden
#29087
Incorrect access to the D&D cache in the browser
#29091
Values of a composition attribute cannot be edited if previously used in the same form
#29106
Error when restarting the KnowledgeBase
#29112
Update minimatch and serialize-javascript to fix CVE-2026-27903, CVE-2026-27904, and GHSA-5c6j-r48x-rmvq
#29197
Eclipse error after dependency update: maven-jar-plugin 3.5.0 causes "outside of a scoping block" error in m2e

update

critical
#29110
Update dependency com.fasterxml.jackson.core:jackson-core to v2.21.1 [SECURITY]
defect

critical

#29080

Unwanted row objects in tables with changes from other sessions

LayoutFrameworkMigrationSecurityIssue

Due to the current implementation of receiveModelChangedEvent and receiveModelCreatedEvent in the TableComponent, it can happen that unwanted row objects appear in a table after these row objects have previously been changed or created in another session.

This ensures that users see elements that they are not allowed to see (for authorization reasons).

**Example situation:**

  • You have a tree that displays project elements.
  • The selection of the tree serves as a model for a table that displays, for example, the components of the selected project element.
  • The table has an editor / dialog in which the component selected in the table is displayed.

**Procedure:**

  • User 1 selects a project element and sees (only) the components for the selected project element in the table.
  • User 2 selects another project element, selects a component there and changes it in the editor / dialog.
  • User 1 updates the GUI (e.g. by pressing F5 or moving columns in the table or by clicking within the table without changing the model in the tree).
  • Error: The component changed by user 2 suddenly appears in the table of user 1, although it does not belong to the currently selected project element.
  • A reselection in the project tree "repairs" the table again until a component is changed (or created) again in another session.

**Cause:**

The problem is due to the implementation / configuration and different interpretation of the supportsListElement method in the ListModelBuilder.

  • If an element is changed or created, supportsListElement is called on the table for this element. If the element is "supported", the table adds this element directly to the list of row objects without further checks instead of calling the ModelBuilder again.
  • In practice, the methods are usually implemented in the form element instanceof MyType, whereby every object of this type is added to the list, regardless of whether it matches the selection of the master or other (functional) filters implemented in ModelBuilder.
  • If a component is set as a model in the editor / dialog via a goto or bookmark link, the table attempts to set this component as a selection and to set a matching model. Here supportsListElement is also checked, but this time with a different semantics, which expects exactly this usual implementation of element instanceof MyType.

**Solution:**

In the corresponding receive methods of the TableComponent, an invalidate() must be called instead of addRow(), so that the ModelBuilder calculates in the normal way which components should now be displayed after the change and which should not.

The whole thing must also be checked for other classes implementing receive methods, e.g. TreeTableComponent, GridComponent, ...

Implementation

  • If object types are specified in the table, an instanceOf check is automatically performed. Only elements that pass the instanceOf check are transferred to the ListModelBuilder#supportsListElement API.
  • A new ElementUpdate constant com.top_logic.mig.html.ElementUpdate.UNKNOWN has been introduced. If this is returned in ListModelBuilder#supportsListElement, the table is invalidated and the list is recreated.
  • ListModelByExpression has been adapted so that if no supportsElement script is set, ElementUpdate.UNKNOWN is always returned. New tables/grids are created without supportsElement to prevent the developer from customizing "elements" but forgetting "suportsElement".

Code migration

  • If it is unclear whether an object should be added to the list or removed from the list, the ListModelBuilder must return ElementUpdate.UNKNOWN in ListModelBuilder#supportsListElement.
  • InApp tables and grids must be checked. If the table/grid displays all objects of a type, "true" must be returned. If the table/grid is to rebuild the list when an element of the supported type is created, "supportsElement" must be left empty.
  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login