TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_8.0.0-alpha7
  4. #29408

8.0.0-alpha7
TopLogic Release

2026-07-30

enhancement

critical
#29088
Model-based access rights
#29108
Lightweight UI definition layer (TL Views) based on React UI components
major
#28694
Description of model parts as formatted text (rich text)
#28708
Enable Standard Selection in (Tree) Tables and Grids via TL Script
#29102
Add com.top_logic.layout.react module for React/SSE integration
#29221
Automatic determination of possible authorization configurations
#29349
XML Parsing Functions for TL-Script via XMLImporter
#29374
TL Script: gzip()
#29389
Code Completion for Variables ($) in the TL Script Editor
#29396
Conversation display for TL Views: object list element, file chips, card panels
#29399
Info Service Notifications: Display at the bottom instead of the top, and keep them in place when hovering over them with the mouse
#29400
Introduce a first-class "operation mode" service for applications (OperationMode enum + ApplicationModeService)
minor
#29085
Re-login on session timeout instead of redirect to login page
#29089
Extend the TL Script functions log() and info() to include selectable message levels (INFO, WARN, ERROR)
#29195
Problems with HTML attributes and TL script
#29306
TL Script: dateFormat() should accept an explicit timezone to format Calendar values losslessly
#29382
Expose a public, classpath-driven overload of `Workspace.getAppPaths`
#29385
The app archetype should automatically generate a standard git-ignored local-credentials overlay (tl_config) by default
#29392
Transaction Abort on Non-2xx Response
#29398
Login Form: Use "Username" Instead of "Name"

defect

major
#29383
A dead SOCKET_APPENDER (Chainsaw, localhost:4445) in the default logging configuration can cause logging to stall and operations to abort under heavy load
#29384
The TL-Script functions `resetSequence` and `generateSequenceId` generate a different sequence ID than `SequenceDefaultProvider` (in terms of suffix and context order), so they cannot reset a provider-managed sequence with a dynamic context
#29394
Editable tables in the React UI: Generalized row-set bindings for tabular editing in forms
#29410
Attribut filename der Structured-Text-Bildablage case-sensitive (binär) speichern
#29419
Understandable save failures and form validation feedback in the React view layer
minor
#28816
Reference value attributes only generate errors with SingleSelection
#29359
Inappropriate tooltips on some main tabs
#29360
Occasional error message in the log: "mainLayout" is null.
#29361
Invalid database definition for tag
#29363
Missing validation of dialogs in GOTO statements to dialogs of invisible parents
#29380
Context-sensitive auto-numbering fails if the context and the numbered object are created within a single transaction
#29381
Double-clicking in a graphic component does not work reliably
#29390
Subtree selection ends too early if the lowest level is not included in the level filter
#29393
URL routing in the React view layer is broken: ForwardingReactContext does not delegate getRouteManager()
#29401
Images in an image drop zone cannot be copied or saved using the browser's context menu
#29402
Tree selection is lost when the view is refreshed (invalidated)
#29412
Flaky TestDynamicComponentService.testIncrementalUpdates: asserts on asynchronous WatchService event after a fixed 10ms sleep
#29416
Anzeige des Änderungslogs schlägt fehl, wenn parallel Änderungen committet werden
#29420
FlowDiagram: Fehlerfall im row-wise Sub-Grid: subGridCols=2 und subGridStartCol=1
#29426
FlowDiagram: Text in PDF-eingebettetem Diagramm ist nicht selektierbar

task

major
#29407
Security-Scan: npm-Abhängigkeiten der React-Module aktualisieren
#29408
Security-Scan: httpcore5 anheben; pdfbox-/azure-Findings bewerten
minor
#29415
Slim down the repository CLAUDE.md and consolidate developer guidance into skills and FAQ articles
task

major

#29408

Security-Scan: httpcore5 anheben; pdfbox-/azure-Findings bewerten

DependencyUpdate

Ein Security-Scan (Juli 2026) meldet drei Maven-Findings. Nur eines ist ein echtes, per Upgrade zu behebendes Problem; die beiden anderen sind ein veralteter Jar-Rest bzw. ein False Positive und werden hier zur Nachvollziehbarkeit dokumentiert.

1. httpcore5 — echter Fix (HIGH)

= Paket = = aktuell = = CVE = = Fix =
org.apache.httpcomponents.core5:httpcore5 5.2.4 CVE-2026-54428, CVE-2026-54399 (DoS durch unbegrenzte Header-Länge/-Anzahl) ≥ 5.4.3 (bzw. 5.5-beta2)

httpcore5 kommt transitiv über httpclient5 (im Root-POM auf 5.2.3 gepinnt). Lösung: httpclient5 auf eine Version anheben, die httpcore5 ≥ 5.4.3 zieht (httpclient5 5.5), oder httpcore5 5.4.3 direkt im dependencyManagement überschreiben. CVE-2026-54428 betrifft konkret httpcore5-h2 (HTTP/2). Laufzeitrelevant (u.a. OpenAPI-Client) — daher der eigentlich wichtige Punkt dieses Tickets.

2. pdfbox-io 3.0.7 — kein echtes Finding

Gemeldet: CVE-2026-23907, CVE-2026-33929 auf org.apache.pdfbox:pdfbox-io@3.0.7.

  • Die CVEs betreffen tatsächlich pdfbox-examples (Beispielcode ExtractEmbeddedFiles), das nicht eingebunden ist — die Zuordnung des Scanners zu pdfbox-io ist eine Fehlzuordnung.
  • Das Root-POM pinnt bereits pdfbox 3.0.8 (die Fix-Version); pdfbox 3.0.8 zieht pdfbox-io 3.0.8. Die im lokalen Repo/Scan aufgetauchte pdfbox-io-3.0.7.jar ist nur ein veralteter Rest.

Aktion: Sicherstellen, dass der Scan gegen einen sauberen Build (clean install) läuft; kein Code-Change nötig.

3. azure-keyvault-core 1.2.4 — False Positive (als CRITICAL gemeldet)

Gemeldet: CVE-2026-33117 (CVSS 9.1) auf com.microsoft.azure:azure-keyvault-core@1.2.4.

  • CVE-2026-33117 betrifft com.azure:azure-security-keyvault-keys < 4.10.6 (modernes Azure-SDK für Java).
  • com.microsoft.azure:azure-keyvault-core 1.2.4 ist ein anderes Artefakt (Legacy-Krypto-Helper, transitiv über azure-storage 8.6.6 im Modul com.top_logic.storage.azure). Namens-Kollision im Scanner — das verwundbare Artefakt ist gar nicht eingebunden.

Aktion: Als False Positive markieren / im Scanner unterdrücken. Kein passender Fix, da das betroffene Artefakt nicht verwendet wird.

  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login