4.8 KiB
GovOPlaN 0.1.45 — usability, reliability and security hardening
Release coordination: GovOPlaN #51.
The exact independently versioned composition is recorded in
packages/govoplan-meta/pyproject.toml; unchanged modules retain their versions.
This source release does not by itself establish a deployed or independently
approved production environment. Package, signed catalog and runtime publication
results are recorded separately in the coordination issue.
Runtime publication hold
The runtime image audit completed eleven registry-only amd64 scans, but found unresolved vulnerabilities and inventory gaps. Runtime publication remains held separately from this source release. Patch-only image updates are insufficient; maintained minor-line changes, narrowly evidenced finding decisions, arm64/final-layer scans and deployment checks remain necessary. No audited candidate was automatically adopted and no image was executed during those scans. The remaining gates are tracked in GovOPlaN #52.
Included changes
- Shared page/action placement, reusable navigation grouping/editing, table and dialog sizing, field alignment, multi-select filters and predictable tree selection. Files, Mail, Search, Notifications and domain pages use the same contracts, with browser regression coverage.
- Campaign draft saving and independent Mail/ZIP-policy repair, persistent and bulk message review, clearer delivery eligibility, bounded configurable synchronous delivery, guarded workerless recovery, lightweight SMTP/IMAP progress, reused IMAP connections and recipient-complete reporting.
- Files archive staging/reuse, unpacking previously uploaded archives, numeric progress and bounded traversal. Optional native archive acceleration retains the same validation rules; portable fallbacks remain available.
- Mail credential references and IMAP folder-name decoding; help topics can be found by area and tags without expanding every occurrence of the same topic.
- Authentication provenance/scope and browser-cache hardening, patched rich-text dependencies, spreadsheet/archive/template/Dataflow resource limits, batched Docs/Notifications queries and safe Reporting bind names. See the security/performance review for measurements, test evidence and remaining limitations.
- A deterministic governance-journey clock fixture, fresh-process Campaign import coverage, and a new Cases patch aligning its root npm facade with its Python/WebUI package. Historical published tags are not rewritten.
- Git-root WebUI package facades are aligned with their owning packages, with a cross-composition parity check. Tasks is included in default module discovery; it remains subject to enabled modules and normal permissions.
Upgrade and verification
Back up the database and file storage before upgrading. Apply the complete
selected migration graph before starting the new API/workers. This release
includes additive repair migrations c58a2d7e9f10 (Core ownership history) and
d8f1b4e7a0c3 (Access external-function mappings), plus Campaign delivery-state
migrations. Existing business evidence is retained; a schema downgrade is not
a substitute for a reviewed backup/restore plan. Restart API and worker
processes together after upgrading their matching packages.
Updated UI consumers require Core 0.1.45 where they use its new shared contracts. Tenant keys that previously relied on unintended system permissions/wildcards must be corrected; the release does not preserve that unsafe behavior. Extremely sparse spreadsheets, oversized generated output and excessive archive paths can now fail early with a diagnostic.
For archive staging across multiple hosts, provide shared POSIX storage with working locks or sticky routing. Background delivery still needs configured workers; increasing the synchronous limit does not create a worker or guarantee delivery after a process failure. An unknown SMTP outcome must be reconciled, not automatically resent.
After deployment, manually verify login/logout and least-privilege API keys, Campaign Settings and independent Mail/ZIP saves, archive upload/unpack, recipient-complete reports, and SMTP/IMAP progress with an explicitly approved test mailbox. No release verification sends real campaign mail automatically.
Hard process isolation, forced-password-change/recovery enforcement, bounded Xrechnung subprocess output and large-history pagination remain separate open issues. This release is not a claim that all security or performance debt is resolved. Production-image scans and multi-host evidence must refer to the actual signed runtime being deployed.