TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_8.0.0-alpha10
  4. #29760

8.0.0-alpha10
TopLogic Release

2026-10-09

enhancement

major
#29651
TL Views: Container <accordion> mit einklappbaren Abschnitten
#29652
TL Views: Hinweisbox <alert> im Inhalt einer View
#29654
TL Views: Auswahlfeld als Radio-Gruppe für beliebig viele Optionen
#29661
TL Views: Prototyp "TopLogic UI on MUI" – Adaptermodul mit Material UI für die ersetzbaren Komponenten
#29692
TL Views: Formularfelder, Tabellenzellen und das Bearbeiten eines Formulars richten sich nach den Modell-Zugriffsrechten
#29693
TL Views: Große und mehrwertige Werte erscheinen in Tabellenzellen als einzeilige Vorschau mit einem Knopf, der den vollständigen Editor in einem Dialog öffnet
#29707
Reduce PR CI build time: parallel reactor build, sharded scripted tests, affected-module builds
#29730
React-Oberfläche: Kanban-Board als View-Element (Karten per Drag & Drop zwischen Spalten verschieben)
#29735
User menu: the application cannot say what the account is called
#29741
anonymous-Benutzer soll per Default nicht in Personenauswahlfeldern auftauchen
#29744
TL Views: Entwicklerwerkzeuge (Designer, Aufzeichnen, Untersuchen, Agentenzugriff) in einem eigenen Entwicklungsmenü der App-Leiste
#29752
React-UI: Kleine Verbesserungen der Oberfläche (Snackbar, Hover, Tooltips, Schieberegler, Abstände)
#29758
ModelAccessRights: Anlegerecht in Kompositionsattribut für Spezialisierung des Zieltyps prüfen
#29759
React-UI: Commit-Nachrichten für Änderungen aus Sichten (TL-Script-Aktionen, Transaktionen, Löschen) konfigurierbar, sinnvolle Standard-Nachrichten
#29760
Improve the React UI of the model-based security configuration; let a TL-Script function determine the access parent of a type
#29765
Engine developer docs (FAQ) are not discoverable when developing an application based on the engine
minor
#29513
Drag&Drop: Commit-Nachricht für Drop-Operationen konfigurierbar, sinnvolle Standard-Nachricht
#29747
Make the LDAP configuration ldapConf.xml configurable by system properties / environment variables
#29754
OpenAPI-Server: Variablenname für Request-Parameter, deren Name kein gültiger TL-Script-Bezeichner ist (z.B. Header X-Gitea-Event)

defect

major
#29581
TopLogicServlet: Vertrag dokumentieren - eine Anfrage hat nur im Fenster einen Benutzer
#29642
React dialog size memory: one key for every dialog, stored size beats the declared width and is never clamped to the window
#29646
TL Views: Der Build der React-Client-Module prüft die TypeScript-Typen nicht, in com.top_logic.layout.react sind dadurch 29 Typfehler aufgelaufen
#29697
HistoryQuery: Start- und Stop-Revision aus HistoryQueryArguments werden bei der Suche ignoriert.
#29701
TL Views: a form shown again after its sidebar section or tab was hidden keeps the values it had when hidden; a reload renders the stale values again
#29711
Setzen einer geordneten Liste (ListStorage) ist beim Einfügen vor bestehenden Elementen überquadratisch langsam; TestListStorage misst Wanduhrzeit und scheitert unter Last
#29712
Problem beim Zurücksetzen einer Selektion im Baum
#29716
Modellbasierte Leseprüfung: Rollen-Lookup kompiliert pro Objekt und Gruppe neue KB-Abfragen, Nicht-Admin wartet 70 s statt 9 s
#29723
Model editor class diagram fails with "Comparison method violates its general contract!"
#29724
PathNavigation: abstract attribute rejected by isDerived() check even though concrete overrides exist and are tracked
#29728
FlowChartComponent: Ein Neubau des Diagramms entfernt Objekte aus der Selektion, die im Diagramm nicht dargestellt werden
#29731
TL Views: <persist-transient> copies the draft's empty values over the creation defaults; a sequence number or creation date computed at commit is lost
#29732
TL Views: <create-transient container="…"> creates the draft without the container's context; option lists and context-dependent defaults of the draft see no container
#29734
View form: <store-form-state/> does not persist new rows of a <composition-table>, so saving a persistent owner fails
#29737
TL Views: a collapsing toolbar measures its commands only when its groups change; a command that shows itself later keeps a 0 px toolbar and draws over the panel title
#29740
Fehlender Schutz für den anonymous-Benutzer
#29745
Zugriff auf ein abstraktes Attribut meldet einen Fehler, der nicht sagt, dass das Attribut abstrakt ist: eigene Storage für abstrakte Attribute
#29746
FileManagerOverlay/FileManagerDelegate cannot read resources inside web-fragment WARs (tl_config overlay fails on engine configuration files)
#29773
PostgreSQL: Große SQL-Migrationen werden durch nicht freigegebene Autosave-Savepoints quadratisch langsam
minor
#29029
Incrementally deactivated drop-down select box can still be operated
#29514
Befehlsfreigabe und Berechtigung von Drag&Drop
#29696
Scheduler: Start- und Cluster-Verhalten von Tasks bereinigen – <on-startup/> pro Knotenstart, Tasks erst ab RUNNING, run-on-startup entfernen, kein Default für isNodeLocal()
#29699
TL-Script: htmlText(htmlSource($text), images) drops the images of a stored structured text, since it does not accept the "ref:" references it writes itself
#29700
TL Views: the open session of a deleted account keeps evaluating as that account; every model event logs "DeletedObjectAccess … was already deleted" from its observers
#29722
FlowDiagram: Fehlerhafte Baum-Layout-Berechnung
#29727
TL-Script Auswertungen mit Filtern können zu "null"-Literalen führen.
#29733
TL Views: a click on the padding of the React rich-text editor's content area does not focus the editor; the typed text is lost
#29736
Click-region menu opens flush on the window edge and under the trigger's tooltip
#29738
TL Views: the menu cliques of a toolbar are labelled in English in every language ("More", "View", "Export")
#29739
React tooltip stays open at the window's top-left corner when its anchor is removed under the pointer
#29743
React UI: Tooltip eines Menüeintrags erscheint hinter dem Menü
#29753
OpenAPI-Client: NullPointerException bei Antwort ohne Body (z.B. 204) mit Status ungleich 200
#29774
OpenAPI server: API key authentication cannot resolve an account — Person.byName called without an InteractionContext

task

major
#29725
CheckDependencies: npm-Abhängigkeiten werden nicht aktualisiert, transitive Maven-Abhängigkeiten mit bekannten Sicherheitslücken
#29726
WYSIWYG-Editor: Umstellung auf Tiptap 3 (Sicherheitslücke GHSA-cp6q-959q-f8rh)
enhancement

major

#29760

Improve the React UI of the model-based security configuration; let a TL-Script function determine the access parent of a type

MigrationReactUI

The coverage view of the model-based access definition (Administration > Access control > Coverage, React view admin/access-control/coverage.view.xml) and the configuration editor it uses are improved, and the access parent of a type can be computed by a TL-Script function.

Access parent

  • The access parent of a type is configured as one polymorphic element <access-parent> of the <class> entry of the SecurityConfigurationService, holding exactly one definition: <container/>, <target reference="..."/>, <self/> or <script expr="..."/>.
  • <script expr="..."/> (ScriptAccessParent): a TL-Script function computes the access parent of an object. It is evaluated without security. A result of several objects, a non-object result, an object without access control of its own (e.g. a transient object) or a failure denies access and is logged; an empty result means no access parent.
  • A delegating access parent together with grants or marks of the same entry is rejected with a message naming the conflicting property by its label.
  • Dropping an access parent an underlying configuration layer sets (by a mark, or by removing it in the access rights dialog) stores <self/> as override.

Coverage view

  • The coverage table is a tree table: the modules of the analyzed types are its nodes, their types the children. A module is selected like any row; "Module access rights…" is offered only while a module is selected.
  • A mark (internal, without access control) inherited from a module or a generalization is reported with its origin (the type itself, then a marked generalization, then the module); dropping a mark is offered only for a mark of the type's own.
  • The access rights dialog shows the marks and the access parent in effect, also those an underlying configuration layer sets.
  • Rule creation ("Role parent…", "Role rule…") moved to the "Rules in effect" panel, next to editing and deleting; a script step of a rule is shown as written.
  • The dialogs check their form before saving (check-config-form) and disable Save while errors are shown (config-form-valid); the individual violations are listed below the refusal.
  • Table header stays aligned with the body when scrolled fully right; dialog forms are inset; icons of options are shown.

Configuration editor (React)

  • An optional non-polymorphic item property is edited as a list of at most one entry; an item that may not be null offers no removal.
  • A TL-Script valued property is edited in the TL-Script editor of the script console; parse and compile errors are reported when the editor is left.
  • An unset mandatory item written as text, and an unset mandatory polymorphic item, are reported as missing.
  • The type selector is labelled in the user's language and marked mandatory.
  • Errors of a field whose control does not display them are shown in the field chrome.

Table (React)

  • TreeRowSource.refresh() recomputes the displayed rows after the tree changed, keeping the expansion state.
  • A tree table offers no grouping: neither the column header menu nor the column selection offers to group by a column.
  • In a cell showing several values as one line, the name of a value keeps its gap to the icon.

Migration

The access parent of a type is no longer configured by the attributes access-parent and access-reference of the <class> entry of the SecurityConfigurationService, but by an element <access-parent> holding exactly one definition. The old attributes are rejected as configuration error at startup.

= old = = new =
access-parent="container" <access-parent><container/></access-parent>
access-parent="container" access-reference="X" <access-parent><container reference="X"/></access-parent>
access-parent="target" access-reference="X" <access-parent><target reference="X"/></access-parent>
access-parent="self" <access-parent><self/></access-parent>
access-parent="auto" remove the attribute

Also check WEB-INF/autoconf/com.top_logic.model.security.SecurityConfigurationService.config.xml: the "Access rights…" dialog of the coverage view writes to it.

The record TypeCoverage holds the origin of the marks (withoutSecurityOrigin, internalOrigin, a TLModelPart) instead of the booleans withoutSecurity and internal; the accessors withoutSecurity() and internal() remain.

  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login