TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_8.0.0-alpha7
  4. #29221

8.0.0-alpha7
TopLogic Release

2026-07-30

enhancement

critical
#29088
Model-based access rights
#29108
Lightweight UI definition layer (TL Views) based on React UI components
major
#28694
Description of model parts as formatted text (rich text)
#28708
Enable Standard Selection in (Tree) Tables and Grids via TL Script
#29102
Add com.top_logic.layout.react module for React/SSE integration
#29221
Automatic determination of possible authorization configurations
#29349
XML Parsing Functions for TL-Script via XMLImporter
#29374
TL Script: gzip()
#29389
Code Completion for Variables ($) in the TL Script Editor
#29396
Conversation display for TL Views: object list element, file chips, card panels
#29399
Info Service Notifications: Display at the bottom instead of the top, and keep them in place when hovering over them with the mouse
#29400
Introduce a first-class "operation mode" service for applications (OperationMode enum + ApplicationModeService)
minor
#29085
Re-login on session timeout instead of redirect to login page
#29089
Extend the TL Script functions log() and info() to include selectable message levels (INFO, WARN, ERROR)
#29195
Problems with HTML attributes and TL script
#29306
TL Script: dateFormat() should accept an explicit timezone to format Calendar values losslessly
#29382
Expose a public, classpath-driven overload of `Workspace.getAppPaths`
#29385
The app archetype should automatically generate a standard git-ignored local-credentials overlay (tl_config) by default
#29392
Transaction Abort on Non-2xx Response
#29398
Login Form: Use "Username" Instead of "Name"

defect

major
#29383
A dead SOCKET_APPENDER (Chainsaw, localhost:4445) in the default logging configuration can cause logging to stall and operations to abort under heavy load
#29384
The TL-Script functions `resetSequence` and `generateSequenceId` generate a different sequence ID than `SequenceDefaultProvider` (in terms of suffix and context order), so they cannot reset a provider-managed sequence with a dynamic context
#29394
Editable tables in the React UI: Generalized row-set bindings for tabular editing in forms
#29410
Attribut filename der Structured-Text-Bildablage case-sensitive (binär) speichern
#29419
Understandable save failures and form validation feedback in the React view layer
minor
#28816
Reference value attributes only generate errors with SingleSelection
#29359
Inappropriate tooltips on some main tabs
#29360
Occasional error message in the log: "mainLayout" is null.
#29361
Invalid database definition for tag
#29363
Missing validation of dialogs in GOTO statements to dialogs of invisible parents
#29380
Context-sensitive auto-numbering fails if the context and the numbered object are created within a single transaction
#29381
Double-clicking in a graphic component does not work reliably
#29390
Subtree selection ends too early if the lowest level is not included in the level filter
#29393
URL routing in the React view layer is broken: ForwardingReactContext does not delegate getRouteManager()
#29401
Images in an image drop zone cannot be copied or saved using the browser's context menu
#29402
Tree selection is lost when the view is refreshed (invalidated)
#29412
Flaky TestDynamicComponentService.testIncrementalUpdates: asserts on asynchronous WatchService event after a fixed 10ms sleep
#29416
Anzeige des Änderungslogs schlägt fehl, wenn parallel Änderungen committet werden
#29420
FlowDiagram: Fehlerfall im row-wise Sub-Grid: subGridCols=2 und subGridStartCol=1
#29426
FlowDiagram: Text in PDF-eingebettetem Diagramm ist nicht selektierbar

task

major
#29407
Security-Scan: npm-Abhängigkeiten der React-Module aktualisieren
#29408
Security-Scan: httpcore5 anheben; pdfbox-/azure-Findings bewerten
minor
#29415
Slim down the repository CLAUDE.md and consolidate developer guidance into skills and FAQ articles
enhancement

major

#29221

Automatic determination of possible authorization configurations

MigrationSecurity

In the application, components are assigned to different authorization domains. In the role-permission configuration, only these components are then displayed for a given authorization domain.

Components and commands have their own authorization object. Here, you can configure an authorization object that has nothing to do with the authorization structure, allowing for the configuration of inconsistencies.

Improvement

  • There are no longer any authorization structures. This eliminates the need to duplicate roles (e.g., navigation or selection) that are logically identical but are defined across all authorization structures.
  • The SecurityObjectProvider must specify which types the security object can have. The inheritance rules can then be used to determine which roles can exist on objects of this type. This allows the system to offer only those options that are theoretically relevant.

Code Migration

  • Role rules of the form {{{

<inheritance-rule

base="structureRoot@MyModule"
...

/> }}} should be replaced with {{{ <inheritance-rule

...

>

<script-step expr="MyModule#ROOT"/>

</inheritance-rule> }}}

  • Steps in Role Rules {{{

<step attribute="myAttr" meta-element="MyModule:MyClass" ... /> }}} replace with {{{ <step attribute="MyModule:MyClass#myAttr" ... /> }}}

  • Assignments of roles to singletons for groups must be replaced with standard role rules. In : {{{

<config service-class="com.top_logic.util.model.ModelService"> <instance><settings>

<module name="MyModule">
<singletons>
<singleton type="Root">
<role-assignments>
<role-assignment role="MyModule.role" group="MyGroup"/>
....

}}} Remove the <role-assignments> tag, including its contents. Instead, introduce a role rule: {{{ <singleton-rule

target="MyModule#ROOT"
role="MyModule.role"

>

<group-with-name name="MyGroup"/>

</singleton-rule> }}}

  • The "Navigation" and "Selection" roles are available in the base system. These can be used instead of the custom roles.
  • Roles are no longer defined within a module but in a central registry. Model files and configuration files must be updated, and the role definitions must be moved.

Example in myModule.model.xml: {{{ <module name="myModule">

<annotations>
....
<roles> <-- Remove tag
<role name="myModule.role1"/>
</roles>
</annotations>

</module> }}} Example in application configuration: {{{ <config service-class="com.top_logic.util.model.ModelService"> <instance>

<settings>
<module name="myModule">
<roles> <-- Remove tag
<role name="myModule.role1"/>
</roles>
....
</module>
</settings>

</instance> </config> }}} Instead: {{{ <config service-class="com.top_logic.base.services.InitialRolesManager">

<instance>
<roles>
<role name="myModule.role1"/>
</roles>
</instance>

</config> }}} Note: It is no longer necessary to use the module as a prefix. It is only written here with a prefix because this serves as the identifier; otherwise, the roles cannot be identified among the existing ones.

  • If the "model" SecurityObjectProvider is used, the possible types of the model should be specified as much as possible. To do this, search for securityObject="model". If, in the specific view, the model can have either the type myModule:type1 or myModule:type2, for example, the entry should be replaced with securityObject="model(myModule:type1,myModule:type2)"
  • The default behavior regarding whether a button bar (e.g., in dialogs) is displayed has changed and must be checked
  • The behavior regarding whether a layout is considered a security master (e.g., if there is exactly one layout in the dialog) has changed and must be verified. It is better to explicitly mark a component as a security master.
  • Role profiles must be updated.
  • Remove the security domain from layout files; role rules require an ID. To do this, run the Maven target {{{

mvn exec:java@migrate-ticket29221 }}} . Layouts in the database are updated automatically.

  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login