TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_8.0.0-alpha7
  4. #29385

8.0.0-alpha7
TopLogic Release

2026-07-30

enhancement

critical
#29088
Model-based access rights
#29108
Lightweight UI definition layer (TL Views) based on React UI components
major
#28694
Description of model parts as formatted text (rich text)
#28708
Enable Standard Selection in (Tree) Tables and Grids via TL Script
#29102
Add com.top_logic.layout.react module for React/SSE integration
#29221
Automatic determination of possible authorization configurations
#29349
XML Parsing Functions for TL-Script via XMLImporter
#29374
TL Script: gzip()
#29389
Code Completion for Variables ($) in the TL Script Editor
#29396
Conversation display for TL Views: object list element, file chips, card panels
#29399
Info Service Notifications: Display at the bottom instead of the top, and keep them in place when hovering over them with the mouse
#29400
Introduce a first-class "operation mode" service for applications (OperationMode enum + ApplicationModeService)
minor
#29085
Re-login on session timeout instead of redirect to login page
#29089
Extend the TL Script functions log() and info() to include selectable message levels (INFO, WARN, ERROR)
#29195
Problems with HTML attributes and TL script
#29306
TL Script: dateFormat() should accept an explicit timezone to format Calendar values losslessly
#29382
Expose a public, classpath-driven overload of `Workspace.getAppPaths`
#29385
The app archetype should automatically generate a standard git-ignored local-credentials overlay (tl_config) by default
#29392
Transaction Abort on Non-2xx Response
#29398
Login Form: Use "Username" Instead of "Name"

defect

major
#29383
A dead SOCKET_APPENDER (Chainsaw, localhost:4445) in the default logging configuration can cause logging to stall and operations to abort under heavy load
#29384
The TL-Script functions `resetSequence` and `generateSequenceId` generate a different sequence ID than `SequenceDefaultProvider` (in terms of suffix and context order), so they cannot reset a provider-managed sequence with a dynamic context
#29394
Editable tables in the React UI: Generalized row-set bindings for tabular editing in forms
#29410
Attribut filename der Structured-Text-Bildablage case-sensitive (binär) speichern
#29419
Understandable save failures and form validation feedback in the React view layer
minor
#28816
Reference value attributes only generate errors with SingleSelection
#29359
Inappropriate tooltips on some main tabs
#29360
Occasional error message in the log: "mainLayout" is null.
#29361
Invalid database definition for tag
#29363
Missing validation of dialogs in GOTO statements to dialogs of invisible parents
#29380
Context-sensitive auto-numbering fails if the context and the numbered object are created within a single transaction
#29381
Double-clicking in a graphic component does not work reliably
#29390
Subtree selection ends too early if the lowest level is not included in the level filter
#29393
URL routing in the React view layer is broken: ForwardingReactContext does not delegate getRouteManager()
#29401
Images in an image drop zone cannot be copied or saved using the browser's context menu
#29402
Tree selection is lost when the view is refreshed (invalidated)
#29412
Flaky TestDynamicComponentService.testIncrementalUpdates: asserts on asynchronous WatchService event after a fixed 10ms sleep
#29416
Anzeige des Änderungslogs schlägt fehl, wenn parallel Änderungen committet werden
#29420
FlowDiagram: Fehlerfall im row-wise Sub-Grid: subGridCols=2 und subGridStartCol=1
#29426
FlowDiagram: Text in PDF-eingebettetem Diagramm ist nicht selektierbar

task

major
#29407
Security-Scan: npm-Abhängigkeiten der React-Module aktualisieren
#29408
Security-Scan: httpcore5 anheben; pdfbox-/azure-Findings bewerten
minor
#29415
Slim down the repository CLAUDE.md and consolidate developer guidance into skills and FAQ articles
enhancement

minor

#29385

The app archetype should automatically generate a standard git-ignored local-credentials overlay (tl_config) by default

BuildInfra

Request

The application Maven archetype (tl-archetype-app) should generate, for every new application, a standard, leak-free mechanism for providing developer-local secrets (Trac XML-RPC credentials, database passwords, external API tokens, ...) that must not be committed and that survives application restarts without requiring manual setup each time the application starts.

Motivation

Apps regularly need secrets injected via aliases, e.g.:

<alias>
    <entry name="%TRAC_PASSWORD%" value="${env:TRAC_PASSWORD:}"/>
</alias>

With only the ${env:...} default, the value is empty unless an environment variable is present in the launching process. This is fragile:

  • A shell launched by a skill, CI, or tool is typically non-interactive and does not source the user’s shell profile, so an “export in .bashrc”-style environment file is not picked up.
  • Passing the secret as a -Dkey=value JVM/Maven argument leaks it into the process command line (visible via ` ps`).

There is no out-of-the-box, documented pattern, so every app re-invents (or omits) this, and developers encounter avoidable HTTP 401 / empty-credential failures.

Proven pattern (please make this the archetype default)

TopLogic already supports a configuration overlay via XMLProperties.Setting.CONFIG_FILE (the tl_config system/JNDI property). MultiProperties.pushSystemProperty loads the named file last (so its alias entries override the base configuration) and silently ignores it when absent ("Configuration '...' not found, will be ignored!"), ensuring that a fresh checkout still boots. The property value is only a path, never the secret.

Configuration that worked well in an app:

  1. .mvn/jvm.config (committed): -Dtl_config=local.conf.xml — a non-secret path pointer, automatically read by Maven on every invocation.
  2. local.conf.xml (git-ignored): the actual overlay with literal alias values, e.g.
<root>
    <alias>
        <entry name="%TRAC_USER%" value="..."/>
        <entry name="%TRAC_PASSWORD%" value="..."/>
    </alias>
</root>
  1. local.conf.xml.template (committed): documents the file for other checkouts.
  2. .gitignore: Ignores the actual local.conf.xml file.
  3. Eclipse startup: uses the same property as an absolute path, -Dtl_config="${workspace_loc:<project>}/local.conf.xml", so it resolves independently of the launch working directory.

Both launch paths (Maven exec:java and the Eclipse com.top_logic.ide.jetty.Bootstrap launch) then read the same single git-ignored file.

Suggested scope

  • Archetype generates items 1, 3, and 4 above and the Eclipse startup VM argument (item 5) by default; item 2 is created by the developer from the template.
  • Consider including a brief section in the generated README to document this mechanism.
  • The specific alias names are application-specific; the archetype should include an empty or example overlay, not any actual alias.

Filed as a follow-up to setting this up manually in an application.

  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login