Skip to content

Latest commit

 

History

History
41 lines (30 loc) · 3.06 KB

File metadata and controls

41 lines (30 loc) · 3.06 KB

Changelog

0.3.0 — 2026-06-10

Security hardening — breaking.

  • Breaking: the admin panel is now fail-closed — when no auth callable is configured, all requests are denied with HTTP 401 (previously they were silently allowed) (CWE-306). Pass an auth callable to enable access.
  • Detail views render only detail_fields() (derived from list_display when configured), so columns hidden from the list no longer leak on the detail page (CWE-200).
  • Sensitive/authorization field detection extended to role/admin/superuser/permission/privilege/staff/scope; matched fields are forced read-only unless explicitly opted into form_fields, preventing mass-assignment privilege escalation (CWE-915).
  • CSRF cookie now sets HttpOnly and Max-Age (CWE-1004).
  • Admin HTML responses carry X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and a restrictive Content-Security-Policy (CWE-1021).
  • Non-integer ?page= values no longer cause a 500; page is clamped to a maximum (CWE-20).
  • Security events (auth/CSRF failures, blocked mutations) are now logged (CWE-778).

0.2.0 — 2026-05-16

Security hardening — breaking.

  • CSRF tokens required on all admin POSTs by default (Admin(csrf_enabled=...) to opt out for tests / behind-auth deployments). Token stored in hawkapi_admin_csrf cookie (Secure, SameSite=Lax) and echoed via hidden _csrf form field.
  • Optional auth callable on Admin/init_admin — invoked at the top of every route, raises HTTPException to reject. A UserWarning is emitted at construction and a logger.warning at attach() when no auth is configured.
  • save() catches SQLAlchemyError/ValueError/TypeError and re-renders the form with a 400 plus a short errors["_form"] message instead of leaking a 500.
  • Clear-to-NULL semantics — a field that is present-but-empty in the form is now coerced to None (when nullable) instead of being silently skipped.
  • Pagination links URL-encode the ?q= parameter.
  • ModelResource.__post_init__ warns when an editable field name looks sensitive (password/secret/token/key/hash) and isn't in readonly_fields.
  • Admin.register() raises ValueError on duplicate resource names.

0.1.1 — 2026-05-16

Fix wheel build: drop the empty static/ force-include entry that broke uv build in CI.

0.1.0 — 2026-05-16

Initial release.

  • Admin orchestrator + init_admin(app) — mounts index / list / detail / create / edit / delete routes under /admin.
  • ModelResource — declarative wrapper over a SQLAlchemy model with knobs for list_display, list_search, form_fields, readonly_fields, page_size, can_create/update/delete, custom label, icon.
  • Type-driven widget picker (checkbox / number / date / datetime / textarea / enum / text), automatic from each column's SQLAlchemy type.
  • Search on the list page (?q=) backed by ILIKE against the configured columns.
  • Pagination.
  • Light + dark mode CSS, ~60 lines inline in _base.html.
  • Built on top of hawkapi-sqlalchemy — picks up the session factory from init_database(app, ...).