Skip to content
CAI
Software that uses CAICheck a score

apache/causeway

41.4

Weak · 22 September 2026

331.9k

lines of production code

Java

with JavaScript

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Apache Causeway is a Java-based framework for building domain-driven applications by automatically generating user interfaces from domain models. It supports multiple presentation viewers, including Wicket, RESTful Objects, GraphQL, and HTMX-based web components, while managing authentication, security, and persistence via JPA. The system provides extensive tooling for auditing, command replay, and data export, along with a modular architecture that facilitates integration with modern enterprise standards like Spring Boot and Jakarta EE.

How it got here

2004–2022 — Apache Causeway modernization and Jakarta migration

175 changes.

The project underwent a comprehensive modernization, migrating from legacy Java EE and RestEasy stacks to Jakarta EE and Spring Boot 4. This involved restructuring the core architecture into modular Java components, refactoring viewers to use Spring MVC, and standardizing data models with Java records. The period also focused on enhancing the developer experience through extensive documentation updates, new testing fixtures, and expanded support for modern authentication protocols like Keycloak and OAuth2.

2023–2025 — GraphQL viewer and QueryDSL integration

73 changes.

This period focused on introducing a new GraphQL viewer with pluggable schema strategies and expanding the persistence layer with QueryDSL support for type-safe queries. Concurrently, the project enhanced documentation with interactive D3.js diagrams, added GitHub-based layout loading, and implemented extensive regression testing across JPA, Wicket, and REST viewers.

2026 — Web Components viewer foundation and samples

17 changes.

This period focused on establishing the core infrastructure for a new declarative Web Components viewer, introducing custom elements for actions, collections, and menus across HTMX and Vue implementations. It also delivered comprehensive sample applications, including secured Pet Clinic variants and Vega visualization tools, to demonstrate and validate the new presentation layer capabilities.

Features

Add H2 Console integration for prototyping environments

This change introduces a new H2 Console web module and a corresponding 'Prototyping' menu item within the testing UI. The console is automatically enabled in prototyping deployments that use an H2 in-memory database, providing a secure interface to inspect and manage the database schema and data via a servlet mapped to /db.

causeway-testing-h2console-ui · high confidence

Add secured Vue Petclinic sample application

A new secured variant of the Vue Petclinic sample application is now available, providing a complete Spring Boot backend and Vue.js frontend for demonstration purposes. The application includes a Java entry point that configures the Causeway runtime with JPA persistence, GraphQL viewing, and security bypass presets, alongside a route controller to serve the Vue single-page application. The frontend assets include a custom CSS theme with light and dark mode support and a JavaScript bundle implementing the Vue 3 runtime, enabling users to run and inspect a fully functional, secured webcomponents-based sample.

viewers/webcomponents/sample-vue-petclinic · high confidence

Add secured authentication for the Vue Webcomponents viewer

This change introduces a complete authentication stack for the Vue-based webcomponents viewer, enabling secure sign-in flows backed by the Secman user repository. It adds a dedicated login page served via a servlet filter, along with Spring Security components (authentication provider, user details service, and entry point) to handle credential validation and session management. The implementation also includes an authentication context endpoint that exposes the current user's identity and CSRF token to the client, ensuring the Vue frontend can maintain a secure, authenticated session.

(repo-wide) · high confidence

Added Algolia search configuration files

New configuration files for Algolia search indexing have been added to the documentation attachments. The \algolia-config.json\ file defines the indexing scope for the Apache Causeway website, specifying start and stop URLs to exclude specific documentation versions and paths, and configuring selectors to extract page hierarchy and text content. The accompanying \algolia.env\ file provides the necessary application ID and API key for the search service integration.

antora/components/comguide/modules/ROOT/attachments · high confidence

Added Gradle wrapper configuration

The project now includes a Gradle wrapper configuration file (gradle-wrapper.properties) that specifies the use of Gradle version 6.5.1. This allows users to build the project using a consistent, self-contained Gradle distribution without needing to install Gradle globally.

gradle · high confidence

Added JPA embeddable support for Blob and Clob values

The persistence library now includes utility classes, BlobJpaEmbeddable and ClobJpaEmbeddable, to enable the persistence of Blob and Clob domain values. These classes act as JPA embeddables that marshal the application-level Blob and Clob types into database columns (storing name, MIME type, and the actual binary or character data), providing a concrete implementation for storing large object data within the JPA persistence layer.

causeway-persistence-jpa-applib · high confidence

Adds JPA persistence support for Vega value types

This change introduces the \persistence-jpa\ module for the Vega value type, providing automatic database persistence via a JPA \AttributeConverter\. The module registers \CausewayVegaConverter\ to transparently serialize \Vega\ objects to and from \String\ columns in the database, and configures Spring Boot to scan for this converter automatically.

valuetypes/vega/persistence-jpa · high confidence

Adds JPA-specific Querydsl integration module

The persistence/querydsl/jpa module now provides the concrete JPA implementation for the Querydsl integration layer. This includes a Spring Boot auto-configuration module that wires up the JPA-specific services, a factory for creating detached queries using JPA Querydsl, and a support component that bridges the application's query DSL abstractions to the underlying JPA EntityManager and JPAQueryFactory. This enables applications using JPA to leverage Querydsl for type-safe queries within the Causeway framework.

persistence/querydsl/jpa · high confidence

Adds Querydsl integration module for autocomplete and query execution

This change introduces the new \persistence/querydsl/integration\ module, which wires together the Querydsl application and metamodel components via a Spring configuration. It provides the \AutoCompleteGeneratedQueryServiceImpl\, enabling applications to programmatically perform autocomplete searches and execute queries against entities that have Querydsl facets, delegating to the generated query logic.

persistence/querydsl/integration · high confidence

Adds Server-Sent Events (SSE) support for Wicket applications

The Wicket extension now includes a new Server-Sent Events (SSE) capability. This introduces a dedicated \SseService\ implementation that manages event streams and allows applications to submit SSE tasks for asynchronous execution, as well as a \WebModuleServerSentEvents\ that registers the \/sse\ servlet endpoint to handle the connections.

causeway-extensions-sse-wicket · high confidence

Adds ability to re-publish execution log entries to the outbox

The Execution Republisher extension now contributes a 'Copy to Outbox' action to Execution Log entries. This allows users to manually re-publish a specific execution from the log to the outbox, facilitating reprocessing when downstream handling of an outbox item previously failed.

extensions/core/executionrepublisher/applib · high confidence

Adds core documentation and configuration generation infrastructure

This change introduces new files to support the core module's documentation and configuration management. It adds an Antora site definition (\core/adoc/antora.yml\) for design docs, a Groovy script (\core/config/generateConfigDocs.groovy\) to generate configuration documentation from Spring metadata, and \.gitignore\ files for the \codegen-bytebuddy\ and \mmtest\ subdirectories. These additions establish the tooling and structure for maintaining core configuration and design documentation.

core · high confidence

Adds documentation site styling and search assets

The documentation site now includes a local copy of the DocSearch CSS for the search interface, a font-face stylesheet for Google Fonts (Open Sans, Raleway, Montserrat) that references locally cached font files from the gstatic CDN, and a custom site stylesheet defining typography, syntax highlighting colors, and layout rules for the Antora-generated documentation.

antora/supplemental-ui/css · high confidence

Adds layout-v1 XSD schemas to supplemental UI

The Antora supplemental UI now includes the XML Schema Definition (XSD) files for the layout-v1 specification, covering component definitions, Bootstrap 3 grid and menu bar structures, and link metadata. These files are now available in the documentation source, enabling users to validate their layout XML against the schema directly within the Antora documentation site.

antora/supplemental-ui/applib/layout-v1 · high confidence

A new partial template for the header content menubar has been introduced, which renders a 'Home' link in the navigation bar. Currently, this link points to a placeholder URL ('\#'), serving as scaffolding for the documentation site's header structure.

antora/supplemental-ui/partials · high confidence

Adds retired reference artifacts and build scripts

The retired directory now includes a cribsheet documenting build workflows, a collection of shell scripts for building, testing, and managing the project (including GitHub PR merging and branch cleanup), and Java source files for Log4j2 plugins (DuplicateMessageFilter and TruncatingMessageFactory) intended as reference implementations.

retired · high confidence

Adds retry action for command log entries with explicit publishing controls

A new 'Retry' action is now available for command log entries, allowing users to reset a command's state (clearing results, exceptions, and timestamps) and mark it as PENDING for re-execution. This action is explicitly configured with commandPublishing and executionPublishing set to DISABLED to prevent redundant event emissions during the retry process.

causeway-extensions-commandreplay-primary · high confidence

Adds simple in-memory authentication module with password encryption

Introduces a new 'Simple' authentication module for Apache Causeway, providing an in-memory user and role management system suitable for development or testing. The module includes a SimpleRealm for storing users and roles, and a SimpleAuthenticator that validates credentials using Spring's PasswordEncoder, ensuring passwords are stored and compared in encrypted form rather than plain text.

causeway-security-simple · high confidence

Adds web components sample domain model and menu

The sample HTML viewer now includes a new domain service menu titled "Web Components" (SampleMenu) and the underlying domain objects (SampleObject, SampleRelatedObject) required to exercise the web component interactions. This provides a concrete, deterministic data set for verifying the new Vaadin-based web component presentation layer.

causeway-viewer-webcomponents-sample-html · high confidence

Caffeine-based title cache implementation added

A new Caffeine-based caching module has been introduced for the title cache extension, replacing the previous JCache approach. This module configures a CaffeineCacheManager with a maximum size of 100 entries and a write-expiration of 10 minutes, providing a lightweight, in-memory caching solution for application titles without requiring external JCache providers.

extensions/core/titlecache/caffeine · high confidence

Command Log extension introduces command replay and background execution capabilities

The Command Log extension now provides a comprehensive framework for recording, managing, and replaying application commands. Users can view and search command history via the new Activity menu, with contributions showing recent commands for specific users or objects. The extension introduces a Command Replay Manager that allows administrators to export, import, and replay command sequences to secondary systems for regression testing or state synchronization, including support for excluding or retrying specific commands. Additionally, a new BackgroundService and RunBackgroundCommandsJob enable the execution of commands asynchronously, with controls to pause, resume, and monitor background command execution.

extensions/core/commandlog/applib · high confidence

Command Replay and Background Execution capabilities

The Command Log extension now supports replaying and exporting recorded commands, as well as deferring action invocations to background execution. A new BackgroundService allows wrapping domain objects to persist actions as background command log entries for later processing. The CommandManager ViewModel provides a UI for managing command sequences, including filtering by timestamp, excluding specific commands, deleting entries, and exporting sequences as YAML. Supporting classes like CommandExportManager, CommandKnownParticipantsValidator, and CommandManagerMovementSupport enable validation of command dependencies, timestamp adjustment during movement, and export formatting.

causeway-extensions-commandlog-applib · high confidence

Command Replay primary-side infrastructure and UI services

This change introduces the primary-side components for the Command Replay extension, activated via the 'commandreplay-primary' Spring profile. It adds a Spring module configuration that wires up the primary services, a configuration class to read the secondary Wicket base URL, and a mixin action allowing users to open an entity on the secondary instance. It also provides a domain service for retrieving command logs by interaction ID, a SPI processor to capture command execution results and timings, and a UI service (exposed as 'Activity') that enables searching and downloading command logs as XML.

incubator/extensions/core/commandreplay/primary · high confidence

Command replay on secondary instances via Quartz scheduling

The command-replay extension now supports running on secondary instances to automatically replicate and replay commands from a primary system. This is achieved through a new Spring module (activated by the 'commandreplay-secondary' profile) that configures a Quartz job to periodically fetch command logs and execute them on the secondary. The system includes services to analyze replay results for discrepancies in exceptions or outcomes, and provides UI actions to manually upload commands or exclude specific entries from the replay queue.

incubator/extensions/core/commandreplay/secondary · high confidence

Default implementation for entity version access

A new default service, EntityVersionAccessorDefault, has been added to the persistence commons module to provide a standard mechanism for retrieving the version of a domain entity. This service integrates with the existing object manager and entity facets to ensure consistent version retrieval across the application.

causeway-persistence-commons · high confidence

Demo app adds local replay control actions

The demo application now includes a dedicated controller (DemoReplayController) that exposes resume and pause actions for command replay within the web UI. This implementation allows users to manually control the state of the command replay process directly from the demo interface, supplementing the core replay infrastructure.

incubator/examples/demo/web · high confidence

Documentation for Apache Causeway Starter Apps

Added new Asciidoctor documentation pages for the HelloWorld and SimpleApp starter applications. The new content includes navigation structures, an overview of the starter apps, and detailed guides on prerequisites, downloading, and running the applications via Maven or Docker. It also covers usage instructions for the Wicket viewer and Swagger REST API, along with code examples for domain objects and services.

starters/adoc/modules/starters · high confidence

Excel export now supports custom cell styling and image embedding

The Excel exporter has been refactored to support individual cell and row coloring via a new CellStyleProvider, allowing users to apply predefined background colors (e.g., blue, green, warning) to specific cells or entire rows. Additionally, the exporter now handles image data (BufferedImage) by embedding them directly into cells, automatically resizing images to a maximum height of 120 points and adjusting row heights accordingly.

causeway-extensions-tabular-excel · high confidence

Excel fixture extension adds demo app for bulk import/export and pivot analysis

The Excel fixture extension now includes a demo application that demonstrates bulk updating of To-Do items via Excel spreadsheets, including importing and exporting data through a dedicated manager service, as well as generating pivot tables aggregated by category and subcategory. It also provides fixture scripts and row handlers to populate the demo data from Excel resources, enabling users to test and understand the Excel integration capabilities within the framework.

extensions/core/excel/fixture · high confidence

Execution Outbox applib exposes menu, REST API, and persistence subscriber

The execution-outbox applib now provides the core components for the outbox pattern: an ExecutionOutboxMenu service adds 'Activity' menu actions to view oldest or all outbox entries; a new OutboxRestApi domain service exposes server-side REST endpoints (pending, delete, deleteMany) for an external outbox client to fetch and acknowledge entries; and an ExecutionSubscriberForExecutionOutbox SPI implementation automatically persists execution events to the outbox repository when the extension is enabled in configuration.

causeway-extensions-executionoutbox-applib · high confidence

Execution Outbox extension adds persistent execution logging and REST API

The Execution Outbox extension now provides a new \ExecutionOutboxEntry\ domain model and repository to persist records of action invocations and property edits, enabling users to track execution history and audit trails. This change introduces a Spring configuration module that wires the entry, menu, and subscriber components, and adds an \OutboxRestApi\ with an \OutboxEvents\ wrapper to expose pending execution logs via a REST endpoint, including content mapping to serialize the entries as \InteractionsDto\ for external consumers.

extensions/core/executionoutbox/applib · high confidence

ExecutionOutboxEntry JPA persistence model introduced

The JPA persistence layer for the Execution Outbox now uses a concrete entity class (ExecutionOutboxEntry) and a composite primary key (ExecutionOutboxEntryPK) to store execution metadata. This change introduces the database schema mapping for interaction IDs, sequences, execution types, timestamps, and target bookmarks, enabling the outbox to persist execution state for auditing and replay.

causeway-extensions-executionoutbox-persistence-jpa · high confidence

Foundational command replay controls: recording suppression, advisor policies, and bookmark remapping

This change introduces the core infrastructure required for reliable command replay in Causeway 4. It adds an opt-in \recording-support\ configuration (disabled by default) that allows marking specific domain objects or view models to suppress command logging, and provides application-wide pause/resume events to temporarily suspend persistence (e.g., during initial fixture installation). It also defines a configurable interaction-advisor policy (\CHECK\, \CHECK\_BUT\_IGNORE\, \NO\_CHECK\) for command DTO execution, ensuring replayed actions and properties can be validated or bypassed as needed. Finally, it implements a replay-mapping SPI and an in-memory listener that remaps recorded target and reference-parameter bookmarks before execution, allowing replayed commands to be redirected to new objects while preserving the original audit data.

openspec · high confidence

FullCalendar Wicket UI viewer implementation

The Wicket UI layer for the FullCalendar extension is introduced, providing concrete Wicket components that render collections of domain objects as interactive calendar views. This includes the Spring module configuration, abstract base panels for calendar rendering, and specific factories and event providers for both Calendarable and CalendarEventable domain types, along with the necessary HTML templates and CSS styling to display the calendar in the Wicket viewer.

extensions/vw/fullcalendar/wicket/ui · high confidence

GitHub layout resource loader

The application can now load layout resources directly from a GitHub repository. A new service searches for layout XML files by filename within a configured repository and retrieves their content via the GitHub API, enabling layout definitions to be managed in version control rather than bundled locally.

causeway-extensions-layoutloaders-github · high confidence

GraphQL viewer documentation and analysis artifacts

Adds comprehensive documentation for the GraphQL viewer, including guides on API variants (Simple vs Rich schemas), i18n handling via AsciiIdentifierService, and rich schema capabilities like application entry points and collection windowing. Includes a detailed reference application coverage analysis with a coverage matrix, probe operations, and summary to identify correctness gaps in object interaction, value semantics, and resource links.

viewers/graphql/adoc/modules/ROOT · high confidence

GraphQL viewer introduces extensible marshalling and authentication SPIs

The GraphQL application library now exposes new service provider interfaces (SPIs) that allow users to customize how data is converted and how user identity is determined. The new ScalarMarshaller interface enables custom marshalling of Java scalar types to and from GraphQL scalar types, supporting a chain-of-responsibility pattern where implementations can opt into reversible input coercion. Additionally, the UserMementoProvider interface allows applications to define how the executing user's identity is extracted from the GraphQL execution context, replacing the previous static fallback with a pluggable mechanism.

viewers/graphql/applib · high confidence

GraphQL viewer introduces rich schema strategy and application entry points

The GraphQL viewer now supports a pluggable schema strategy that exposes application entry points (such as menu bars and the configured home page) via a new ApplicationEntryService, and provides a richer object model for domain objects and services. This includes detailed metadata fields (breadcrumbs, layout, icons, CSS classes) and enhanced action handling with explicit invoke and parameter introspection, allowing clients to discover and execute actions with greater fidelity than before.

causeway-viewer-graphql-model · high confidence

GraphQL viewer now supports configurable schema styles (Simple, Rich, and combined)

The GraphQL viewer now allows users to choose between 'Simple', 'Rich', or combined schema styles via the \viewer.graphql.schemaStyle\ configuration property. This change introduces new top-level query and mutation types (\SimpleTopLevelQuery\, \RichTopLevelQuery\, etc.) and a custom execution strategy that ensures GraphQL field resolution occurs within the correct Causeway interaction context. The viewer also enforces that full metamodel introspection is enabled, as required for generating the GraphQL schema dynamically.

viewers/graphql/viewer · high confidence

HTMX Pet Clinic sample application with declarative web component layouts

A new sample application demonstrating the HTMX web component viewer is added, featuring both a permissive mode and a secured mode with local SecMan authentication. The sample includes a custom HTML shell, declarative layout files for pages (Home, Pet, PetOwner, Visit), collections, and previews, along with Playwright acceptance tests to validate the UI behavior.

viewers/webcomponents/sample-htmx-petclinic · high confidence

Initial JDBC persistence module stub

Adds a new stub module for JDBC-based persistence, introducing the JdbcEntityFacet to handle entity lifecycle operations (fetch, persist, refresh, delete) via Spring Data JDBC. The module registers the JdbcEntityFacetFactory to detect entities annotated with @Persistent and wires the necessary Spring Data relational components for metadata mapping and data access.

persistence/jdbc · high confidence

Initial prototype for tabular PDF export

The tabular PDF export extension now includes a working proof-of-concept that renders tabular data into PDF documents. This implementation introduces a new PDF generation engine built on Apache PDFBox, replacing previous approaches. It supports exporting tabular sheets with headers and data rows, handling various data types including strings, dates, numbers, and images. The system includes font management utilities that load FreeSans fonts and handle character encoding, with fallback mechanisms for unsupported characters. The export functionality is accessible through the PdfFileWriter class, which coordinates the creation of PDF documents from tabular models.

causeway-extensions-tabular-pdf · high confidence

Interactive D3.js entity diagrams added to default help

The default help content now includes interactive entity diagrams rendered via D3.js, providing a visual representation of domain object relationships. This is implemented through new \HelpNode\ structures for organizing help topics and pages, and an abstract \EntityDiagramPageAbstract\ component that generates these diagrams using the \ObjectGraphRendererD3js\. Users can now view dynamic, clickable graphs of their application's object model directly within the help interface, alongside the existing static PlantUML options.

causeway-extensions-docgen-help · high confidence

Introduce generic Vue viewer for application routing and shell integration

This change adds a new Vue-based viewer implementation for the Causeway web components, providing the core routing infrastructure and UI components. It introduces Vue components for the application home page, generic object pages, and object route handling, along with a plugin system to integrate with the Vue router and application shell. The viewer includes boundary validation to ensure the correct DOM structure, policy hooks for customizing navigation and action handling, and support for local resource navigation with security checks. It also handles logout actions by suppressing them in menus and placing secured sign-out in the tertiary menu, while consolidating utility menu and action results.

viewers/webcomponents/vue · high confidence

Introduce secondary command replay fetcher and job data utilities

This change adds the core implementation for the secondary command replay extension, introducing the CommandFetcher service to retrieve command DTOs from the primary instance via the RestfulClient and the JobExecutionData helper to manage Quartz job context data. These components enable the extension to fetch and process command logs from a primary system, forming the backend mechanism for command replay functionality.

causeway-extensions-commandreplay-secondary · high confidence

Introduces Markdown value type with JAXB support

Adds a new Markdown value type to the Causeway application library, allowing users to store and manage Markdown content. The implementation includes a JAXB adapter to enable serialization support for view models, ensuring the Markdown value can be persisted and transmitted correctly within the framework.

causeway-valuetypes-markdown-applib · high confidence

Introduces Querydsl support for persistence queries

Adds a new \persistence/querydsl/applib\ module that integrates Querydsl into the framework. This includes a \QueryDslRepository\ base class for type-safe entity querying, \QueryDslSupport\ and \DetachedQueryFactory\ interfaces for building and executing queries, and an \AutoCompleteGeneratedQueryService\ to support declarative autocomplete features defined via \@DomainObject\ and \@Property\ annotations. The module also provides utility classes for wildcard-to-regex conversion and case sensitivity handling, along with a \PredicatePrettifier\ in the testsupport module for debugging query predicates.

persistence/querydsl/applib · high confidence

Introduces SPI for PDF.js viewer configuration

Adds the PdfJsViewerAdvisor service interface, which allows implementations to provide specific rendering advice (such as page number, scale, and height) for PDF objects viewed in the application. This SPI enables customization of how PDF blobs are rendered by users, with a default implementation that currently returns null advice.

causeway-extensions-pdfjs-applib · high confidence

Introduces Server-Sent Events (SSE) application library

Adds the core application library for Server-Sent Events support, including the \SseService\ for managing event channels and submitting tasks, the \SseChannel\ interface for handling event streams, and the \@ServerSentEvents\ annotation to mark observable sources. This provides the foundational API for applications to implement real-time server-to-client event broadcasting.

extensions/vw/sse/applib · high confidence

Introduces Server-Sent Events (SSE) support in the Wicket viewer

This change adds the Wicket-specific implementation for the Server-Sent Events extension, enabling real-time, server-push updates to the UI. It introduces a new Spring module configuration that wires together the SSE service, a dedicated servlet for handling asynchronous event streams, and Wicket markup components that inject client-side JavaScript to listen for these events. Users can now utilize SSE capabilities within Wicket-based applications, allowing views to react to backend changes without polling.

extensions/vw/sse/wicket · high confidence

Introduces Vega chart value type support

Adds the \VegaValueSemantics\ component to the metamodel, enabling the use of Vega and Vega-Lite chart specifications as value types within applications. This change provides the underlying semantics for parsing, rendering, and decomposing Vega JSON data, allowing users to store and display interactive charts directly in their domain models.

valuetypes/vega/metamodel · high confidence

Introduces Vega value type for interactive visualizations

Adds a new immutable Vega value type to the Causeway application library, allowing domain models to hold JSON payloads for interactive visualizations (Vega and Vega-Lite). This change includes the core value class, a builder interface, stringification utilities, and a JAXB adapter to support serialization in view models, alongside the necessary Java module descriptor and Spring configuration stub.

valuetypes/vega/applib · high confidence

Introduces Wicket UI for PDF.js viewer

Adds the Wicket-based user interface components for the PDF.js viewer extension, including the main Spring module configuration, the \PdfJsViewerPanel\ component factory, and the associated HTML, CSS, and JavaScript resources. This enables the rendering of PDF blobs within the Causeway Wicket viewer with interactive features such as page navigation, zoom, and printing.

extensions/vw/pdfjs/wicket/ui · high confidence

Introduces abstract base class for scalar marshallers

The GraphQL viewer library now provides an abstract base class, ScalarMarshallerAbstract, to simplify the implementation of scalar type marshallers. This new class implements the ScalarMarshaller SPI and handles common logic for type matching and input support configuration, allowing developers to create custom scalar marshalling logic with less boilerplate code.

causeway-viewer-graphql-applib · high confidence

Introduces declarative web component foundation for actions, collections, and application menus

This change adds the core web component foundation for the Causeway viewer, introducing a suite of new declarative elements and their supporting logic. Users can now define application menus, navigable breadcrumbs, and interactive action buttons using custom elements (e.g., \\<cw-action\>\, \\<cw-collection\>\, \\<cw-breadcrumbs\>\). The foundation includes a robust action dispatch system that supports nested queries, root mutations, and legacy mutations, along with declarative result presentation styles (inline, dialog, sidebar). Collection handling is enhanced with declarative column definitions, sorting, filtering, and paging capabilities, backed by a new grid projection system. Additionally, the foundation provides the infrastructure for rich GraphQL application entry reads, including menu bar descriptors and home object resolution.

viewers/webcomponents/foundation · high confidence

Introduces extensible HTMX web component viewer with application-authored shell support

The HTMX viewer now allows applications to provide their own HTML shell structure via the new HtmxAuthenticationShell interface and HtmxShellDefinition, enabling custom authentication chrome and layout while the framework handles declarative template binding, route context management, and validation of required web component slots (such as cw-graphql-client and cw-menubars).

causeway-viewer-webcomponents-htmx · high confidence

Introduces generic HTMX web component viewer

Adds a new HTMX-based viewer module that allows applications to define custom HTML pages, collection presentations, previews, and application shells via classpath resources. The module registers Spring beans to load and validate these HTML fragments, supporting both cached and development-time reload modes, and renders them using a declarative template system with configurable authentication and routing.

viewers/webcomponents/htmx · high confidence

Introduces metamodel support for Server-Sent Events (SSE) annotations

The metamodel extension now recognizes the @ServerSentEvents annotation on methods. A new SseAnnotationFacetFactory processes these annotations to create an SseObserveFacet, which identifies the associated SseSource event stream type and automatically derives the corresponding SSE endpoint path (e.g., /sse?eventStream=...). This enables the application to expose method results as real-time server-sent event streams.

extensions/vw/sse/metamodel · high confidence

Introduces modular GraphQL model with simple and rich schema strategies

The GraphQL viewer is now structured as a dedicated module (org.apache.causeway.incubator.viewer.graphql.model) that exposes a new, pluggable schema architecture. This change introduces a SchemaStrategy interface with two distinct implementations—Simple and Rich—allowing the GraphQL API surface to be tailored to different needs. The model layer now handles the construction of GraphQL types, data fetchers, and input/output semantics for domain objects, services, actions, and properties, while also supporting hyphenated namespaces in logical type names.

viewers/graphql/model · high confidence

Introduces viewer-commons applib module with UI services and prototyping mixins

The new \org.apache.causeway.viewer.commons.applib\ module provides shared abstractions for viewer implementations, including \BrandingUiService\, \HeaderUiService\, \MenuUiService\, and \UserProfileUiService\ to expose UI-specific models (such as \BrandingUiModel\ and \UserProfileUiModel\) to the presentation layer. It also introduces prototyping mixins (\Object\_impersonate\, \Object\_impersonateWithRoles\) that allow administrators to switch user identities directly from object views, with command and execution publishing explicitly disabled for these actions.

viewers/commons/applib · high confidence

Introduction of the commons module with core utility APIs

The commons module has been introduced, providing a new set of core utility APIs for the platform. This includes the \Can\<T\>\ immutable collection type for handling zero, one, or multiple elements, binding interfaces (\Observable\, \Writable\) for state management, and functional interfaces like \IndexedConsumer\ and \ThrowingRunnable\. The module also exposes internal utilities for assertions, byte manipulation, and constants, along with a Java module descriptor (\module-info.java\) that defines the public API surface and dependencies on libraries such as Jackson, JAXB, and Micrometer.

commons · high confidence

JPA persistence implementation for Execution Outbox

This change introduces the JPA-based persistence layer for the Execution Outbox extension, providing the concrete repository, entity mappings, and Spring Boot configuration required to store outbox entries using JPA (specifically EclipseLink). It includes the module configuration, the JPA repository implementation, and integration tests to verify the functionality.

extensions/core/executionoutbox/persistence-jpa · high confidence

JPA persistence implementation for the Execution Log extension

The Execution Log extension now includes a JPA-based persistence module, providing a concrete repository implementation for storing execution log entries. This change introduces the necessary Spring Boot configuration, entity definitions, and a JPA repository to persist log data, along with integration tests and a test-specific persistence configuration (migrated to Jakarta EE 3.0 schema) to verify the functionality.

extensions/core/executionlog/persistence-jpa · high confidence

JPA persistence layer for the Command Log extension

This change introduces the JPA-based persistence implementation for the Command Log extension, providing the database storage for command execution logs and replay-result mappings. It registers the \CommandLogEntry\ and \CommandReplayResultMapping\ entities, along with their respective Spring Data repositories, within the \CausewayModuleExtCommandLogPersistenceJpa\ configuration. The module also includes a teardown fixture for test cleanup and an ORM template for schema generation. Additionally, it adds integration tests to verify the persistence of command logs, the behavior of the command background gate, and the workflow mutations of the unified command manager.

extensions/core/commandlog/persistence-jpa · high confidence

JPA persistence support for Session Log extension

The Session Log extension now includes a JPA-based persistence module, enabling session activity to be stored in a relational database via EclipseLink. This change introduces the \SessionLogEntry\ entity and its repository, along with a Spring Boot auto-configuration module (\CausewayModuleExtSessionLogPersistenceJpa\) that registers the necessary beans and scans for entities. It also provides a teardown fixture script for manual cleanup during testing and includes integration tests to verify the persistence layer works correctly with the application's security and runtime services.

extensions/security/sessionlog/persistence-jpa · high confidence

JPA regression test base module split

The regression test base module has been split to provide a dedicated JPA test domain, introducing JPA-specific entities (JpaBook, JpaInventory, JpaProduct), view models (JpaInventoryJaxbVm, JpaBookView), and Spring Boot configurations (Configuration\_usingJpa, Configuration\_usingSpringDataJpa) to support testing against JPA persistence stacks.

regressiontests/base-jpa · high confidence

Local SecMan authentication support for HTMX webcomponents viewer

The HTMX webcomponents viewer now supports local authentication via Spring Security's SecMan provider. This change introduces a dedicated security configuration that handles login, logout, and CSRF protection specifically for the HTMX viewer routes. Users will experience seamless authentication flows where unauthenticated HTMX requests are redirected to a login page, and successful logins return the user to their intended destination. The implementation includes custom authentication entry points, success/failure handlers, and a security validator to ensure proper configuration of paths and CSRF settings.

causeway-viewer-webcomponents-htmx-security-secman · high confidence

Markdown value type metamodel implementation

The metamodel layer for the Markdown value type has been introduced, providing the semantic wiring for the Markdown value. This includes a Spring configuration module that imports the MarkdownValueSemantics component, which implements the Parser and Renderer interfaces to handle the conversion, decomposition, and HTML rendering of Markdown values within the application.

valuetypes/markdown/metamodel · high confidence

Markdown value type support added to Causeway

The valuetypes/markdown/applib module has been introduced, providing a new capability to convert Markdown content to HTML within the application. This includes a new module definition (org.apache.causeway.valuetypes.markdown.applib) that exposes packages for value handling and JAXB, and relies on the Flexmark library (including GFM strikethrough and table extensions) for rendering. A new configuration class, CausewayModuleValMarkdownApplib, registers the module namespace, and a Converter utility class enables the actual Markdown-to-HTML transformation, supporting features like tables and strikethrough syntax out of the box.

valuetypes/markdown/applib · high confidence

New 'Beyond the Basics' user guide section

Adds a new 'Beyond the Basics' (btb) module to the Apache Causeway user guide, providing documentation for advanced topics. This includes guides on headless access (interacting with the runtime outside standard viewers), customizing the programming model, internationalization (i18n), logging configuration (including the DuplicateMessageFilter and TruncatingMessageFactory), and troubleshooting visibility and usability issues. The section also offers practical hints and tips, such as implementing 'Are you sure?' confirmations, custom CSS, handling void/null results, spellchecking, persisting object titles, overriding default service implementations, and managing subclass properties in tables.

antora/components/userguide/modules/btb · high confidence

New Antora block macros for Jira issues and placeholder text

Added two new Antora extension files in the lib directory: jira-issue.js and lorem.js. The jira-issue.js file registers a block macro that converts Jira issue keys into clickable links to the Apache Jira instance. The lorem.js file registers a block macro that generates placeholder 'lorem ipsum' text for documentation purposes, allowing authors to insert dummy content during drafting.

antora/lib · high confidence

New Apache Causeway Petclinic sample domain and UI layout

This location introduces the complete domain model and presentation layer for the Petclinic sample application. It adds seed data configuration to populate pet owners, pets, and visits, alongside domain services for filtering and repository access. The UI is defined through layout XML files that structure the home page, pet owner details, and pet records, and configure primary menus for managing owners and scheduling visits, as well as a tertiary account menu.

viewers/webcomponents/sample-petclinic-domain · high confidence

New AsciiDoc styling themes added to Antora

Two new CSS style sheets, \asciidoc-classic\ and \boot-flatly\, have been added to the Antora AsciiDoc styles directory. The \asciidoc-classic\ theme provides a traditional look with Georgia serif fonts for body text and specific styling for headings, lists, and code blocks. The \boot-flatly\ theme applies the Flatly design system (via Bootswatch), featuring the Lato font, a clean white background, and distinct styling for blockquotes, tables, and links, giving documentation a modern, Bootstrap-inspired appearance.

antora/.asciidoctor-styles · high confidence

New AsciiDoc value type with automatic HTML rendering and PlantUML support

This change introduces the \AsciiDoc\ value type within the \causeway-valuetypes-asciidoc-applib\ module, allowing domain models to store AsciiDoc markup that is automatically converted to HTML for display. The implementation registers a Spring configuration module that initializes an Asciidoctor converter, enabling syntax highlighting via Prism. Additionally, if the \kroki\ backend URL is configured, the converter registers extensions to support PlantUML diagrams within AsciiDoc blocks, converting them into open blocks processed by the Kroki service. A JAXB adapter is also provided to ensure the \AsciiDoc\ value type serializes correctly in XML contexts.

causeway-valuetypes-asciidoc-applib · high confidence

New Asciidoc builder components and D3.js object graph rendering

The Asciidoc builder module now includes new classes to support richer documentation generation: \BlockVisitor\ for structural node traversal, \IncludeStatement\ and \Xref\ records to model and generate Asciidoc include and cross-reference syntax, and \ObjectGraphRendererD3js\ which renders interactive, force-directed object graphs using D3.js. The D3.js renderer embeds SVG output with JavaScript that visualizes entity relationships, supports node dragging and highlighting, and displays tooltips containing field information for each entity.

causeway-valuetypes-asciidoc-builder · high confidence

New CI scripts for site generation and build orchestration

The CI pipeline now uses a new set of shell scripts in scripts/ci/ to orchestrate builds and documentation. The main entry point, build-site.sh, delegates to \_build-site.sh, which conditionally runs helper scripts to copy examples, generate configuration documentation from Spring metadata, generate project documentation, fix line endings, and finally run Antora to build the site. Additional scripts handle building artifacts and Docker images, calculating baseline and revision versions, and performing a dry-run build. A new Groovy script, checkmissinglicenses.groovy, has been added to identify dependencies with missing license information by comparing Maven license reports against the supplemental-models.xml file.

scripts · high confidence

New CORS extension module for Apache Causeway

A new extension module has been added to handle Cross-Origin Resource Sharing (CORS) for RESTful endpoints. The implementation registers a Spring Filter that applies CORS policies to the REST base path (defaulting to /restful/\*), allowing administrators to configure allowed origins, methods, headers, and credentials via the application configuration. A corresponding test verifies that the filter is correctly mapped to the expected URL pattern using default settings.

extensions/vro/cors/impl · high confidence

New CalendarEvent value type for the FullCalendar extension

The FullCalendar extension now provides a new \CalendarEvent\ value type, allowing users to model calendar events with a title, calendar name, optional notes, and a timestamp. This value type includes built-in semantics for serialization (via JAXB and value decomposition), rendering (custom HTML and title templates), and default value generation, enabling richer interaction with calendar data within Causeway applications.

causeway-extensions-fullcalendar-applib · high confidence

New DataTableProvider for tabular data integration

A new abstract DataTableProvider class has been added to the tabular application library, providing a centralized way to generate DataTable instances for domain object types. This provider automatically configures table columns by excluding mixins and including only properties enabled for snapshots, and offers methods to stream data tables and entity specifications for all registered entity types.

extensions/vw/tabular/applib · high confidence

New DslQueryJpa implementation for Querydsl-based persistence

The persistence layer now includes a new \DslQueryJpa\ class that implements the \DslQuery\ interface using Querydsl's JPA support. This change enables the application to execute queries defined via the Querydsl DSL against JPA entities, providing methods for projection, filtering, ordering, and fetching results directly through the JPA provider.

causeway-persistence-querydsl-jpa · high confidence

New Excel export capability for tabular data

The tabular data integration now supports exporting to Excel format. A new \TabularExcelExporter\ component has been added to handle the conversion of tabular sheets into \.xlsx\ files, utilizing JSpecify for nullability annotations and including helper utilities for date/time conversions. This enables users to download tabular views directly as Excel spreadsheets.

extensions/vw/tabular/excel · high confidence

New Execution Log extension for tracking command and property executions

The Execution Log extension introduces a new \ExecutionLogEntry\ domain object and repository to persist and query command and property executions. Users can now view recent executions via the \Activity\ menu, filter by date range, or inspect executions linked to specific objects, users, or interactions through contributed collections and actions.

extensions/core/executionlog/applib · high confidence

New GitHub Layout Loader extension

Adds a new extension that enables dynamic loading of domain model layout resources directly from a GitHub repository. Users can configure a GitHub repository and API key via the \causeway.extensions.layoutLoaders.github\ configuration properties. The extension provides a tertiary menu with actions to enable or disable dynamic layout loading at runtime, allowing the application to fetch and apply layout definitions (e.g., \.layout.xml\ files) from the specified repo on demand.

extensions/core/layoutloaders/github · high confidence

New GraphQL endpoints for downloading application resources and object content

The GraphQL viewer now exposes new REST-style HTTP endpoints under /graphql/application and /graphql/object to allow direct downloading of resources. Users can retrieve menu bar layouts, object icons, grid layouts, and property values (Blobs and Clobs) via these endpoints. Access is controlled by the new 'resources' configuration section (e.g., setting response types to FORBIDDEN, ATTACHMENT, or INLINE), and authentication falls back to a configurable username/roles if no principal is provided.

causeway-viewer-graphql-viewer · high confidence

New JPA metamodel module for annotation-driven persistence metadata

A new \persistence/jpa/metamodel\ module has been introduced to handle JPA-specific metadata derivation. It registers facet factories that interpret JPA annotations—such as \@Table\, \@Column\, and \@Transient\—to configure domain object properties. This allows the application to automatically derive table names, column constraints (like mandatory status and max length), and transient behavior directly from JPA annotations, replacing or supplementing previous mechanisms.

persistence/jpa/metamodel · high confidence

New JPA persistence module for the SecMan security extension

The SecMan security extension now includes a new JPA persistence module that stores application permissions, roles, tenancies, and users in a dedicated database schema named 'causewayExtSecman'. This module provides the JPA entity mappings, Spring Data repositories, and a Spring Boot auto-configuration module to enable persistent storage of security data, along with integration tests to verify the consistency of role assignments and tenancy hierarchies.

extensions/security/secman/persistence-jpa · high confidence

New JPA-based regression test domain model and services

The JPA regression test base module now includes a comprehensive set of new domain entities and services to support testing. This includes entity classes such as JpaBook, JpaProduct, JpaInventory, and JpaProductComment, along with supporting entities like JpaEntityGeneratedLongId and JpaEntityNonGeneratedStringId. A new domain service, JpaInventoryResource, provides actions for managing these entities, while JpaRestEndpointService facilitates RESTful interactions using Spring's RestClient. Additionally, LifecycleEventSubscriberJpaForTesting captures JPA lifecycle events for testing purposes, and an Employee entity is added for Spring Data integration tests.

causeway-regressiontests-base-jpa · high confidence

New Keycloak security module for OAuth2/OIDC authentication

A new \security/keycloak\ module has been added to provide Keycloak-based authentication. This module registers a Spring Security \SecurityFilterChain\ that enables OAuth2/OIDC login, configures a JWT decoder for token validation, and integrates a custom \KeycloakOauth2UserService\ for user info retrieval. It also includes a dedicated logout handler to propagate logout events to Keycloak and manages session creation policies, allowing users to authenticate against a Keycloak realm.

security/keycloak · high confidence

New PDF tabular export extension

A new extension has been added to enable exporting tabular data as PDF documents. This feature introduces a \TabularPdfExporter\ component that integrates with the existing tabular export framework, allowing users to download table views as PDF files. The implementation uses Apache PDFbox for rendering, supporting features like styled headers, alternating row colors, and image cells within the exported tables.

extensions/vw/tabular/pdf · high confidence

New REST client for the Execution Outbox extension

This change introduces a new REST client library for the Execution Outbox extension, allowing applications to programmatically interact with outbox entries via HTTP. It provides an \OutboxClient\ API that supports retrieving pending interactions, deleting single entries, and deleting multiple entries, with configurable URIs for these operations. The module includes a Spring configuration class to wire the client and adds integration tests to verify its behavior against a running server.

extensions/core/executionoutbox/restclient · high confidence

New RESTful Objects client with OAuth2 and Blob/Clob support

The Restful Objects viewer now uses a new \RestfulClient\ implementation that supports both Basic and OAuth2 (Azure) authentication, and handles Blob, Clob, and composite value parameters in action invocations.

causeway-viewer-restfulobjects-client · high confidence

New RestfulObjects client with OAuth2 Azure authentication support

The RestfulObjects viewer now includes a new client module that provides a modern REST client implementation. This client supports both Basic and OAuth2 Azure authentication modes, allowing users to configure credentials via the RestfulClientConfig. It also introduces configurable request/response debug logging through ClientConversationFilter and uses Jackson for JSON parsing.

viewers/restfulobjects/client · high confidence

New Spring OAuth2 extension for JWT and OAuth2 user authentication

The \spring-oauth2\ extension is introduced to support authentication via Spring Security's OAuth2 client. It provides configuration beans that import the core Spring security module and register authentication converters for both JWT tokens and OAuth2 user principals. The JWT converter extracts the user name from the 'appid' claim or subject, while the OAuth2 user converter maps attributes like 'login', 'avatar\_url', and 'name' to the user profile. Additionally, a RESTful authentication strategy is added to enable stateless JWT-based authentication for Restful Objects clients by configuring the \isis.viewer.restfulobjects.authentication.strategy-class-name\ property.

extensions/security/spring-oauth2 · high confidence

New Wicket integration layer for FullCalendar

This change introduces the Wicket integration module for the FullCalendar extension, providing the server-side components and configuration required to embed and interact with the calendar in Apache Wicket applications. It adds the \CausewayModuleExtFullcalendarWicketIntegration\ Spring module, the core \FullCalendar\ and \AbstractFullCalendar\ Wicket components, and a suite of callback classes (such as \EventClickedCallback\ and \DateRangeSelectedCallback\) to handle client-side events via AJAX. The diff also includes supporting configuration classes like \CalendarConfig\ and \EventSource\, as well as resource references for the FullCalendar JavaScript assets.

extensions/vw/fullcalendar/wicket/integration · high confidence

New abstract base class for GraphQL integration tests

The \causeway-viewer-graphql-testsupport\ module now provides \CausewayViewerGraphqlIntegTestAbstract\, a new base class designed to simplify integration testing for GraphQL viewers. This class automatically configures a Spring Boot test context with security bypassed and an in-memory H2 database, allowing developers to write tests by placing GraphQL query files with a \.gql\ suffix in their test resources. It leverages JUnit 5 dynamic tests and approval testing to validate responses, reducing the boilerplate required to set up HTTP clients and test fixtures for GraphQL endpoints.

causeway-viewer-graphql-testsupport · high confidence

New abstract test utility for exporting GraphQL schemas

Introduces PrintSchemaIntegTestAbstract, an abstract base class for integration tests that automatically generates and writes the current GraphQL schema to src/test/resources/schema.gql. This enables IDEs to provide code-completion and intellisense for GraphQL queries used in tests, and allows overriding the API variant via Spring's DynamicPropertySource.

viewers/graphql/testsupport · high confidence

New core webapp module with health, configuration, and session management

The core webapp module has been introduced, providing the foundational Spring Boot integration for the application. This includes a health indicator that aggregates results from registered health check services, a configuration view service that exposes application settings and environment details, and a key-value store implementation backed by the HTTP session. Additionally, the module defines a WebModule abstraction for programmatic servlet context initialization, routing filters for documentation redirection, and session-scoped message broker support.

core/webapp · high confidence

New core/interaction module with interaction scope and message broker

This change introduces the new \core/interaction\ module, which provides the infrastructure for managing interaction scopes and cross-boundary messaging. It registers a custom \InteractionScope\ in the Spring container via \InteractionScopeBeanFactoryPostProcessor\, enabling beans to be scoped to the lifecycle of a user interaction. Additionally, it includes \MessageBrokerImpl\, a thread-safe, serializable component that allows messages, warnings, and application errors to be queued and drained across interaction boundaries.

core/interaction · high confidence

New default implementations for translations and user profile UI services

The viewer commons services module now provides default implementations for resolving application translations and displaying user profile information. TranslationsResolverDefault reads translation files from the configured resource location or the standard /WEB-INF path, filtering for valid message format lines. UserProfileUiServiceDefault constructs the user profile model by retrieving the current user's name (handling impersonation and anonymous states) and translating the anonymous label, relying on the core UserService and TranslationService.

causeway-viewer-commons-services · high confidence

The Causeway Vega application library now includes two new builder classes, VegaDonutDiagram and VegaNodeLinkDiagram, which allow developers to programmatically construct specific Vega/Vega-Lite chart definitions. The donut diagram builder generates a Vegal-Lite specification for categorical data with configurable dimensions, while the node-link diagram builder creates a Vegal specification for hierarchical tree structures with customizable layout and styling options.

causeway-valuetypes-vega-applib · high confidence

New filter to log request URLs on exceptions while suppressing client abort noise

A new \CausewayLogOnExceptionFilter\ has been added to the webapp module. This filter intercepts exceptions during request processing to log the URL of the request that caused the error, aiding in debugging. It specifically suppresses logging for \ClientAbortException\ (which occurs when a user navigates away) and ignores static resource requests (\.css\, \.js\, \.woff2\), reducing log noise while preserving visibility into application errors.

core/webapp/src/main/java/org/apache/causeway/core/webapp/modules/logonlog · high confidence

New functional and collection utilities in commons

The commons module introduces several new types to improve type safety and functional programming patterns. A new \Can\<T\>\ type system replaces previous collection wrappers, providing distinct implementations for empty, singleton, and multiple cardinalities, along with a \CanVector\ for fixed-size mutable vectors. Functional programming support is expanded with \Either\, \Railway\ (implementing the Railway Pattern for success/failure chaining), and \Try\ (wrapping operations that may throw exceptions). Additionally, a new \ImmutableEnumSet\ record provides a safe, immutable view over \EnumSet\, and \GraphUtils\ offers basic graph data structures and algorithms.

causeway-commons · high confidence

New interaction-scoped bean lifecycle management

The core interaction module now introduces an \InteractionScope\ that allows beans to be scoped to the lifetime of a single user interaction. This new scope automatically manages bean creation and destruction, ensuring that scoped instances are cleaned up when the top-level interaction closes, which helps prevent memory leaks and ensures state consistency within a user's request context.

causeway-core-interaction · high confidence

New interactive help and entity diagram pages

The docgen help extension now provides a structured, tree-based help interface accessible via a new 'Help' menu item. This interface includes a welcome page that summarizes application home pages and menu actions, and introduces entity relationship diagrams for domain objects. These diagrams are available in two formats: static PlantUML renderings and interactive visualizations powered by D3.js, allowing users to explore their domain model relationships directly within the application.

extensions/core/docgen/help · high confidence

New internal test support utilities and documentation metadata

This change introduces new internal testing infrastructure within the core/internaltestsupport module. It adds the @DisabledIfRunningWithSurefire annotation, allowing tests to be conditionally skipped when running under the Maven Surefire plugin. It also provides abstract contract test classes (ComparableContractTest\_compareTo and ValueTypeContractTestAbstract) to help verify value-type semantics like equals, hashCode, and compareTo. Additionally, an antora.yml file is added to define documentation metadata for this module.

core/internaltestsupport · high confidence

New persistence commons module with change tracking and deadlock recognition

The persistence/commons module is introduced, providing the core infrastructure for entity change tracking, deadlock recognition, and repository services. It registers the EntityChangeTrackerDefault to monitor and publish entity property changes within transactions, the DeadlockRecognizerDefault to detect deadlocks from Spring's DeadlockLoserDataAccessException and SQL Server messages, and the RepositoryServiceDefault for standard persistence operations. The module also includes metamodel refiners to validate column annotation facets (such as MaxLength, Mandatory, and BigDecimal constraints) and exposes a PreAndPostValueEvaluatorService SPI to control which property changes are published.

persistence/commons · high confidence

New programmatic AsciiDoc builder and writer library

Introduces a new library in the \valuetypes/asciidoc/builder\ module that provides a fluent API for constructing AsciiDoc documents programmatically. The \AsciiDocBuilder\ and \AsciiDocFactory\ classes allow developers to build document models with sections, blocks, tables, and diagrams using Java objects rather than raw text strings. The \AsciiDocWriter\ and \NodeWriter\ components then serialize these models back into AsciiDoc source, supporting various block styles and diagram types. This enables dynamic generation of documentation content within the application.

valuetypes/asciidoc/builder · high confidence

New security-bypass module for integration testing

A new 'security-bypass' module has been added to the framework, providing a dedicated Spring configuration module (CausewayModuleSecurityBypass) that registers bypass implementations for both authentication (AuthenticatorBypass) and authorization (AuthorizorBypass). These components are designed for integration testing scenarios, where they allow all authentication requests to be considered valid and all object visibility/usability checks to pass, effectively disabling security enforcement for the duration of the test.

security/bypass · high confidence

New simple in-memory security module

Adds a new 'security/simple' module providing a lightweight, in-memory authentication and authorization implementation. This module introduces a SimpleRealm for managing users and roles, a SimpleAuthenticator for password-based login (using BCrypt), and a SimpleAuthorizor for checking read/change permissions based on role grants. It is designed as a drop-in replacement for development or simple use cases, requiring only the standard Causeway core and Spring Security crypto dependencies.

security/simple · high confidence

New simplified, serializable menu and header UI models

The viewer commons library introduces a new set of immutable Java record classes to represent the application's header and navigation bar UI state. This includes HeaderUiModel (combining branding, user profile, and navbar data), NavbarUiModel, and a hierarchy of menu model classes (MenuAction, MenuDropdown, MenuSpacer, NavbarSection) that are designed to be trivially serializable. These models provide the structured data required for viewers to render the top-level navigation bar and menu dropdowns.

causeway-viewer-commons-applib · high confidence

New template resource serving and caching infrastructure

The webapp now includes a new \TemplateResourceServlet\ and \TemplateResourceCachingFilter\ within the \templresources\ module. The servlet handles HTML templates by loading them from the file system or classpath, replacing placeholders with runtime values (such as the restful base path), and serving the resulting content. The accompanying filter manages HTTP caching headers (Cache-Control, Expires, Last-Modified) based on a configurable cache time, and marks cached requests via a request attribute to allow other filters to skip unnecessary session handling.

core/webapp/src/main/java/org/apache/causeway/core/webapp/modules/templresources · high confidence

New test-support services for meta-model and interaction testing

The causeway-core-mmtestsupport module now includes a suite of new classes designed to simplify JUnit testing of domain objects and meta-model components. These additions provide no-op or simplified implementations of core services, including ConfigurationTester for validating Causeway configuration, FactoryService\_forTesting for object instantiation, InteractionService\_forTesting for managing interaction layers without side effects, MetaModelContext\_forTesting for building test meta-model contexts, MethodRemover\_forTesting for tracking method removals, and TitleServiceForTesting for basic title/icon generation. These tools allow developers to write unit tests that rely on standard Causeway services without needing a full application context.

causeway-core-mmtestsupport · high confidence

New test-support stubs for core services

The core/mmtestsupport module now includes a suite of test-dummy implementations for key application services, including ServiceInjector, ServiceRegistry, TranslationService, and WrapperFactory. These stubs provide simplified, non-functional behaviors (such as returning the input object unchanged or empty results) to allow unit tests to instantiate domain objects and interact with the framework's service infrastructure without requiring a full application context or external dependencies.

core/mmtestsupport · high confidence

New title cache API interfaces for domain objects

The title cache extension now provides a new \applib\ module containing marker interfaces that allow domain objects to opt into title caching. Implementing \Cached\ signals that a domain object's title should be cached, while \CachedWithCacheSettings\ allows fine-tuning the cache behavior by specifying the expiry duration (in minutes) and maximum number of entries. These interfaces work in conjunction with \DomainObjectLayout\#titleUiEvent()\ to enable configurable title caching for application entities.

extensions/core/titlecache/applib · high confidence

New viewer-commons model abstractions for UI rendering and resource management

This change introduces a new set of model classes in the viewer-commons module to standardize how the UI is constructed and rendered. It adds a UiComponentFactory interface and supporting records (UiString, ButtonRequest, ComponentRequest) to decouple UI component creation from specific viewer implementations. Action decoration is consolidated into ActionDecorators and specific decorator models (Disabling, Prototyping, Confirm, Tooltip, FormLabel) to provide consistent metadata for buttons and menu items. Layout handling is updated with UiGridLayout, which wraps Bootstrap grid structures and applies automatic cleanup (removing empty tabs/rows). Additionally, a WebjarEnumerator utility is added to dynamically scan the classpath for webjar resources, removing the need to hardcode version strings for assets like Font Awesome.

causeway-viewer-commons-model · high confidence

New web component viewer foundation and documentation

The viewers area now includes a new web component viewer foundation module, providing framework-neutral browser components backed by the rich GraphQL schema. This foundation includes a GraphQL client, coordinated application menus, object contexts, property editors, collections, and a PDF reader, all packaged as ECMAScript modules. The change also adds comprehensive documentation (README, USAGE, antora guides) and sample applications (HTMX, Vue, plain HTML) to demonstrate integration, alongside pinned PDF.js assets for document viewing.

viewers · high confidence

OAuth2 users are now automatically created based on autoCreatePolicy

The delegated Spring OAuth2 extension now includes an ApplicationUserAutoCreationService that listens for successful OAuth2 authentication events. When a user logs in via OAuth, the system checks the principal type and, if it is an OidcUser, automatically creates a corresponding ApplicationUser entity. The creation behavior is governed by the autoCreatePolicy configuration: users can be ignored, created in a locked state, or created as unlocked, with optional initial roles and email addresses applied as configured.

causeway-extensions-secman-delegated-springoauth2 · high confidence

PDF.js viewer configuration via metamodel facets

The PDF.js viewer extension now supports configuring the viewer's initial state (page, scale, height) through the metamodel. This is achieved by introducing a \PdfJsViewerFacet\ and a corresponding \PdfJsViewerFacetFromAnnotationFactory\ that processes the \@PdfJsViewer\ annotation on properties or mixin types. The facet allows runtime \PdfJsViewerAdvisor\ implementations to override these default configuration values, enabling dynamic customization of the viewer's appearance and behavior based on the context.

extensions/vw/pdfjs/metamodel · high confidence

PDF.js viewer extension introduces configurable annotation and module

The PDF.js viewer extension now provides a new \@PdfJsViewer\ annotation that can be applied to properties or parameters of type Blob to render them using the PDF.js viewer, with configurable initial page, scale, and height. A new \CausewayModuleExtPdfjsApplib\ module registers the \PdfJsViewerAdvisor\ for dependency injection, and supporting configuration classes (\PdfJsConfig\, \Scale\) are introduced to manage viewer settings.

extensions/vw/pdfjs/applib · high confidence

Pet Clinic domain model for the WebComponents viewer sample

The sample application now includes a complete domain model for the pet clinic scenario, introducing JPA entities for Pet, PetOwner, and Visit, along with domain services (PetOwners, Visits) to manage creation, search, and listing of these objects. The model supports editing pet and visit details, viewing owner agreements as PDF blobs, and includes a ViewerFallback entity with actions to open local resources and trigger a logout, providing the data layer required for the new Vue-based webcomponents viewer.

causeway-viewer-webcomponents-sample-petclinic-domain · high confidence

Querydsl-based autocomplete support for domain objects and properties

This change introduces a new metamodel module that enables autocomplete functionality for domain objects and properties using Querydsl. It adds a Spring configuration module that wires in an AutoCompleteGeneratedQueryMetaModelRefiner, which registers an AutoCompleteGeneratedQueryFacetFactory. This factory processes @DomainObject and @Property annotations to create AutoCompleteUsingQueryDslFacet instances, allowing developers to configure searchable properties, result limits, and minimum input lengths for autocomplete features via Querydsl predicates.

persistence/querydsl/metamodel · high confidence

Repository initialization with Apache Causeway project scaffolding

The repository has been initialized with the core Apache Causeway project structure, including the root README, CONTRIBUTING guidelines, and the project's Apache License 2.0. Configuration files for version control (.gitignore, .gitattributes), IDE consistency (.editorconfig), and Apache infrastructure (.asf.yaml) have been added. Documentation tooling is configured via .asciidoctorconfig and causeway-tooling.yml, while CI/CD and development workflows are supported by build scripts (build-site.sh) and an .mcp.json file for integrated development tools.

(repo-wide) · high confidence

Runtime auto-complete query generation via Query DSL

The persistence layer now supports dynamic auto-complete queries using Query DSL. A new facet class generates queries at runtime by searching specified String properties with configurable case sensitivity, wildcards, and result limits, allowing users to benefit from efficient, on-the-fly search capabilities without pre-generated metadata.

causeway-persistence-querydsl-metamodel · high confidence

Security Manager (SecMan) application library scaffolding

The \extensions/security/secman/applib\ module has been introduced as the application-layer foundation for the Security Manager extension. This change adds the core domain model for managing application permissions, roles, tenancies, and users, including the \ApplicationPermission\ interface and its associated \ApplicationPermissionRepository\ for querying and persisting security rules. It also provides the \ApplicationOrphanedPermissionManager\ view model to identify and relocate permissions that no longer map to existing application features, and registers the necessary Spring configuration, menus, and mixins to expose these security management capabilities within the Causeway application.

extensions/security/secman/applib · high confidence

Session log extension introduces activity tracking and querying

The Session Log extension now provides a new domain model and UI for tracking user sessions. A new SessionLogEntry entity records login and logout events, including session GUIDs, HTTP session IDs, and timestamps. The SessionLogMenu service exposes actions in the Activity secondary menu to list active sessions or search logs by username and date range. Additionally, a mixin contributes a recent sessions collection to any domain object implementing HasUsername, allowing users to view recent activity directly on user profiles.

extensions/security/sessionlog/applib · high confidence

Session log extension now persists login/logout events and supports auto-logout on restart

The Session Log extension now actively records user session activity by persisting a log entry to the database each time a user logs in, logs out, or their session expires. This is handled by the new \SessionSubscriberForSessionLog\ service, which creates or updates \SessionLogEntry\ records. Additionally, a new \SessionLogServiceInitializer\ component automatically logs out all sessions from previous application runs if the \autoLogoutOnRestart\ configuration option is enabled, ensuring a clean state upon restart.

causeway-extensions-sessionlog-applib · high confidence

Spring Security integration module added

A new Spring Security module has been introduced to handle authentication and authorization within the application. This module registers a Spring Security filter that intercepts requests, extracts the authenticated user from the Spring Security context, and converts it into a Causeway UserMemento using pluggable converters (supporting AuthenticatedPrincipal, String, and UserDetails). It also includes a configuration bean that allows administrators to disable Spring's CSRF protection filters if needed, and provides an Authenticator service that relies on the pre-established Spring Security context for user identity.

security/spring · high confidence

Spring Security integration module and authentication conversion SPI

The security-spring module now includes a new WebModule that automatically registers the Spring Security filter on all URL patterns, enabling Spring Security integration. Additionally, a new AuthenticationConverter SPI is introduced to allow converting Spring Authentication objects into Causeway UserMementos, supporting a chain-of-responsibility pattern with configurable priority.

causeway-security-spring · high confidence

Support for CDI injection in JPA EntityListeners

The EclipseLink persistence module now includes a custom BeanManager implementation that enables dependency injection into classes annotated with @EntityListeners. Since these listener classes are not managed by Spring, this change allows them to resolve injection points via the application's CDI context, ensuring that services and other beans can be properly injected into entity lifecycle callbacks.

causeway-persistence-jpa-eclipselink · high confidence

Website assets now include Algolia search and optimized font caching

The website now features a full-text search capability powered by Algolia, implemented via the new \docsearch.min.js\ library and corresponding UI elements in \index.html\. Additionally, a new \\_headers\ configuration file has been introduced to set a one-week cache duration for font assets, improving load performance for site visitors.

antora/supplemental-ui · high confidence

Wicket UI support for Vega value types

Adds a new Wicket-based UI module for rendering Vega and Vega-Lite visualizations within the application. This change introduces the \VegaComponentWkt\ Wicket component, which dynamically loads the necessary JavaScript libraries (Vega 5.25, Vega-Lite 5.9.1, and Vega Embed 6.22.1) via WebJars based on the schema type. It also registers Spring components (\VegaPanelFactoriesWkt\) to integrate these visualizations into both parented and standalone attribute panels, allowing users to view interactive charts defined by Vega specifications directly in the UI.

valuetypes/asciidoc/ui/wicket, valuetypes/vega/ui/wicket · high confidence

Wicket viewer adds 'Clear Hints' action to reset object presentation

The Wicket viewer now includes a new 'Clear Hints' action (accessible via the metadata panel) that allows users to reset the presentation of a domain object to its initial state. This clears any stored UI preferences such as tab selections, column sorting, or pagination settings, ensuring the object is rendered fresh upon the next visit. This functionality is implemented via the new \Object\_clearHints\ mixin in the \viewers/wicket/applib\ module, which integrates with the existing \HintStore\ and \BookmarkService\.

viewers/wicket/applib · high confidence

Architecture

Applib module migrated to Java Platform Module System (JPMS)

The \api/applib\ module now uses the Java Platform Module System, defined by the new \module-info.java\. This introduces explicit module boundaries, exporting core packages (such as \annotation\, \services\, and \events\) while requiring transitive dependencies on Jakarta EE APIs (activation, annotation, inject, persistence, XML binding) and Spring modules (beans, context, core, web). The module also declares static dependencies on Lombok and requires Jackson and SLF4J, establishing a stricter, modularized foundation for the framework's API layer.

api/applib, core/metamodel, viewers/wicket/ui · high confidence

Migrate viewer-commons services to a new module

The viewer-commons services (branding, header, menu, user profile, and translations) have been moved into a new \viewers/commons/services\ module. This change introduces a dedicated Spring configuration module (\CausewayModuleViewerCommonsServices\) that wires the default implementations of these UI services, making them available as a reusable, modular component for other viewers.

viewers/commons/services · high confidence

Migration of core runtime services to a dedicated module with Jakarta EE and OpenTelemetry support

The core runtime services have been consolidated into a new \core/runtimeservices\ module, introducing a formal Java Platform Module System (JPMS) structure that exports service packages and declares dependencies on Jakarta Activation, Mail, and Annotation APIs. This migration includes the introduction of OpenTelemetry integration for observing action invocations and property edits, a configurable HMAC authority for bookmark security (supporting environment variable secrets), and the adoption of Jakarta EE annotations for dependency injection and service prioritization across the runtime layer.

core/runtimeservices · high confidence

New viewer-commons model module for shared UI domain objects

A new \org.apache.causeway.viewer.commons.model\ module has been introduced to centralize shared UI model interfaces used across viewers. This module defines the core UI model hierarchy, including the \UiModel\ marker interface, and specific models for actions (\UiActionForm\, \HasActionInteraction\, \HasManagedAction\) and attributes (\UiAttribute\, \UiParameter\, \UiProperty\). It also provides component type definitions (\UiComponentType\) for rendering various UI elements like domain objects, collections, and forms, along with decorator interfaces (\IconDecorator\, \DangerDecorator\) and CSS resource definitions. This refactoring consolidates model logic previously scattered across viewer implementations into a common library.

viewers/commons/model · high confidence

Restful Objects rendering module migrated to Java Platform Module System

The Restful Objects rendering component has been converted to a Java module (org.apache.causeway.viewer.restfulobjects.rendering), introducing explicit module boundaries and dependencies. This change requires consumers to declare a dependency on the new module rather than the previous classpath arrangement. The module exports its core rendering packages (context, domainobjects, domaintypes, exhandling, service, util) and declares required dependencies on Spring, Jackson, Swagger, and internal Causeway modules, establishing the structural foundation for the rendering layer.

viewers/restfulobjects/rendering · high confidence

Wicket Viewer restructured into modular Spring configuration and services

The Wicket Viewer has been reorganized to use Spring Boot auto-configuration, introducing a central \CausewayModuleViewerWicketViewer\ configuration class that wires together UI modules, initialization configs (such as Bootstrap, jQuery, and Select2), and core services. This change includes new Wicket-specific implementations for services like \BookmarkUiService\, \HintStore\, and \ObjectRenderService\, as well as a custom \ResourceSettings\ to prioritize application-specific i18n properties. The refactoring also updates the authentication session handling in \AuthenticatedWebSessionForCauseway\ and establishes a default page registry in \PageClassListDefault\ to map logical page types to their Wicket implementations.

viewers/wicket/viewer · high confidence

Wicket viewer model module is extracted and modularized

The Wicket viewer's model layer is now a standalone Java module (org.apache.causeway.viewer.wicket.model) with its own module-info.java, providing a clean separation of concerns. This new module exposes packages for core models, interactions, collections, and UI hints, and declares dependencies on the core application library, common model abstractions, and Wicket. It also introduces a Spring configuration module (CausewayModuleViewerWicketModel) to wire the model layer with the core webapp module, establishing the foundation for the viewer's data and interaction models.

viewers/wicket/model · high confidence

Behavioural changes

1 commit (0 fixes) modifying antora/components/refguide/modules/applib-classes/images, antora/components/refguide/modules/applib-methods/images

A change to existing behaviour in antora/components/refguide/modules/applib-classes/images, antora/components/refguide/modules/applib-methods/images — 1 commit, 14 files.

antora/components/refguide/modules/applib-classes/images, antora/components/refguide/modules/applib-methods/images · medium confidence · unverified

2 commits (0 fixes) modifying antora/components/refguide/modules/applib-svc/images

A change to existing behaviour in antora/components/refguide/modules/applib-svc/images — 2 commits, 11 files.

antora/components/conguide/modules/ROOT/images, antora/components/refguide/modules/applib-svc/images · medium confidence · unverified

Adds Java module descriptor for the Asciidoctorj application library

The Asciidoctorj application library now includes a module-info.java file, formally declaring its module name (org.apache.causeway.valuetypes.asciidoc.applib) and its dependencies. This enables the library to be used within the Java Platform Module System (JPMS), exposing packages for value types, JAXB, and the main library, while requiring static access to Lombok and standard dependencies like Jakarta Inject, JAXB, Spring, and Asciidoctorj.

valuetypes/asciidoc/applib · high confidence

Apache Causeway user guide restructured for Antora

The user guide documentation has been reorganized into the Antora component structure, introducing a new navigation file and configuration. The content has been updated to reflect the project's rebranding from 'Isis' to 'Apache Causeway' and the migration from JDO to JPA persistence, with references to legacy technologies like JScience and Bootstrap 3 removed. The guide now covers core domain concepts including entities, services, view models, and modularity, alongside advanced topics such as business rules, events, and value types.

antora/components/userguide/modules/ROOT · high confidence

AsciiDoc value type now renders with syntax highlighting and pretty-printed XML for DTOs

The metamodel for the AsciiDoc value type now includes dedicated semantics classes that provide syntax highlighting (using Prism themes) for AsciiDoc content in the UI. Additionally, the Change, Command, and Interaction DTO value semantics have been extended to render their XML payloads as pretty-printed HTML with syntax highlighting, improving readability of these objects in the application interface.

valuetypes/asciidoc/metamodel · high confidence

Audit trail extension refactored for Causeway 2.0 with new UI and query capabilities

The audit trail application library has been restructured for version 2.0, introducing a new 'Activity' menu under the secondary menu bar that allows users to search for audit records by date range or view the most recent entries. The domain model now uses an interface for \AuditTrailEntry\ and includes mixins to display recent audit entries and the originating command for specific domain objects. Additionally, the repository now supports querying audit entries by username, and the UI layout has been updated to use Bootstrap 5 namespaces.

extensions/security/audittrail/applib · high confidence

Audit trail persistence layer now supports querying by username

The JPA persistence implementation for the audit trail has been updated to include new named queries that allow filtering audit entries by the username who performed the action. Specifically, the \AuditTrailEntry\ entity now supports lookups by username combined with timestamp ranges (before, after, between) and in combination with specific target objects, enabling users to trace activity for specific accounts more effectively.

causeway-extensions-audittrail-persistence-jpa · high confidence

The audit trail extension now persists audit entries using JPA (specifically EclipseLink) instead of its previous storage mechanism. This change introduces a new \AuditTrailEntry\ entity and repository, along with a Spring Boot module configuration that handles entity scanning and provides a teardown fixture for test environments. Users benefit from standard JPA-based persistence for audit logs, ensuring compatibility with existing JPA infrastructure and simplifying database schema management through automatic schema creation.

extensions/security/audittrail/persistence-jpa · high confidence

Audit trail property change logging can now be disabled via configuration

The audit trail extension now respects a specific configuration property to enable or disable the persistence of entity property change logs. The new EntityPropertyChangeSubscriberForAuditTrail implementation checks the extensions.audittrail.persist.isEnabled setting before creating audit entries, allowing users to turn off this specific aspect of audit logging without disabling the entire audit trail.

causeway-extensions-audittrail-applib · high confidence

ByteBuddy codegen module migrated to Java Platform Module System (JPMS)

The core/codegen-bytebuddy module now exposes its functionality as a named JPMS module (org.apache.causeway.core.codegen.bytebuddy). This change introduces a module-info.java that explicitly exports the services and core packages, and declares static dependencies on Lombok alongside runtime requirements for ByteBuddy, the Causeway commons, and Spring Context/Core. The module's Spring configuration class (CausewayModuleCoreCodegenByteBuddy) remains in place to wire the ByteBuddy-based proxy factory service, ensuring the codegen capability is available to consumers while adhering to the new module structure.

core/codegen-bytebuddy · high confidence

Caffeine-based title caching extension

The title cache module has been renamed from JCache to Caffeine and now uses the Caffeine library for in-memory caching. This change introduces a new subscriber that listens for title computation events and caches entity titles using configurable expiry durations and maximum sizes, improving performance by avoiding repeated title calculations for cached entities.

causeway-extensions-titlecache-caffeine · high confidence

Centralized configuration and bean type classification via Java records

The core configuration module now uses Java records to define application settings and internal metadata, providing better IDE support and immutability. Key additions include the main CausewayConfiguration record, specific configuration records for Eclipselink persistence and email services, and a new bean type classification system (CausewayBeanTypeClassifier, CausewayBeanMetaData, CausewayBeanTypeRegistry) that manages how domain objects, view models, and services are discovered and categorized by the framework.

causeway-core-config · high confidence

Command log persistence model and replay result mapping

The JPA persistence layer for the command log extension now includes a comprehensive domain model for command log entries, featuring new database indexes and named queries to support efficient lookups by interaction ID, target, timestamp ranges, and background execution status. Additionally, a new \CommandReplayResultMapping\ entity has been introduced to persist the mapping between recorded and actual bookmarks during command replay operations, enabling the system to track and identify discrepancies in replayed command outcomes.

causeway-extensions-commandlog-persistence-jpa · high confidence

Core configuration module restructured for Java 17 and Spring Boot 4

The core configuration module has been reorganized to support the upgrade to Java 17 and Spring Boot 4.x. This includes the introduction of a Java module descriptor (\module-info.java\) for the \org.apache.causeway.core.config\ module, which explicitly declares dependencies on Jakarta EE libraries (validation, persistence, injection) and Spring Boot components. The module now centralizes configuration properties via \CausewayModuleCoreConfig\, including email settings and Eclipselink configurations, and introduces a \CausewayBeanFactoryPostProcessor\ to manage domain object discovery during Spring bootstrapping. Additionally, new services handle environment initialization (locale, time zone, deployment type) and provide preset configurations for debugging and prototyping modes.

core/config · high confidence

Core domain model types refactored to Java records

The \causeway-applib\ module has migrated several foundational domain model classes to Java records, including \Identifier\, \LogicalType\, \TreeNode\, \TreePath\, \TreeState\, \FontAwesomeLayers\, and \VirtualClock\ implementations. This change standardizes these types as immutable value objects, simplifying their construction and ensuring consistent equality and hashing behavior based on their state, which improves reliability for framework internals and application code relying on these identifiers and tree structures.

causeway-applib · high confidence

Core runtime module restructured with new flush management and Xray configuration

The core runtime module has been reorganized into a new Java module (org.apache.causeway.core.runtime) that wires together the metamodel, interaction, and transaction sub-modules. This update introduces a FlushMgmt utility to control auto-flush suppression via ThreadLocal state, and adds an XrayInitializerService that populates the Xray debug view with environment and primary configuration properties during metamodel loading.

core/runtime · high confidence

Core security module refactored for v2 with modularized authentication and authorization

The core security module has been restructured for version 2, introducing a new Java module (org.apache.causeway.security.api) that exports authentication and authorization services. This change includes a refactored authentication flow with new interfaces like AuthenticationRequest and Authenticator, a centralized AuthorizationManager that now considers action semantics for safer permission checks, and dedicated services for login, logout, and user session management. The module also adds test coverage for session encodability to ensure reliable serialization of user contexts.

core/security · high confidence

Documentation of Apache Causeway standard XSD schemas

The documentation now includes detailed reference pages for the standard XSD schemas used for enterprise integration: the metamodel (mml), command (cmd), interaction execution (ixn), and changes (chg) schemas, along with the common schema types they share. These pages describe the XML structures, namespaces, and DTOs (such as \oidDto\, \commandDto\, and \changesDto\) that facilitate exporting the internal metamodel and capturing user intentions and execution results for auditing or replication. The documentation also notes that the legacy 'aim' schema was removed in version 1.13.0 and replaced by the cmd and ixn schemas.

api/schema/src/main/adoc/modules/schema · high confidence

Excel extension API restructured for Causeway 2.0

The Excel extension's application library has been completely rewritten for version 2.0, introducing a new service-oriented API. Users can now export domain objects to Excel spreadsheets and import them back using the new \ExcelService\, which supports both standard data grids and pivot tables. The API provides fine-grained control over worksheet generation via \WorksheetSpec\ and \WorksheetContent\, allowing for multiple sheets and custom configurations. Import modes (\STRICT\ and \RELAXED\) allow users to handle malformed data gracefully. New annotations (\@PivotRow\, \@PivotColumn\, \@PivotValue\, \@HyperLink\) enable declarative configuration of pivot table structures and hyperlink formatting directly on domain model properties.

extensions/core/excel/applib · high confidence

Excel fixture demo now uses JPA instead of JDO

The Excel fixture demo application has migrated its data layer from JDO to JPA. The \ExcelDemoToDoItem\ domain model now uses JPA annotations (e.g., \@Entity\, \@Table\) and the \ExcelDemoToDoItemMenu\ service uses JPA-compatible repository queries. This change aligns the demo with the platform's shift away from JDO, ensuring the Excel upload and fixture scripts work correctly with the new persistence model.

causeway-extensions-excel-fixtures · high confidence

Execution log persistence can now be disabled via configuration

The execution log subscriber now respects a new configuration property, allowing users to disable the persistence of execution log entries. The \ExecutionSubscriberForExecutionLog\ implementation checks the \causeway.extensions.executionLog.persist.enabled\ setting via \isEnabled()\ before creating and persisting entries, providing a way to turn off this auditing feature without removing the extension.

causeway-extensions-executionlog-applib · high confidence

Execution log persistence model migrated to JPA 3.1 and JSpecify

The JPA persistence layer for the Execution Log extension has been updated to use Jakarta EE 10 (JPA 3.1) annotations, replacing the older javax.persistence imports. The domain model classes, including ExecutionLogEntry and its composite key ExecutionLogEntryPK, now rely on JSpecify annotations (org.jspecify.annotations.NonNull) instead of Lombok's NonNull for null-safety metadata. This change ensures compatibility with modern Jakarta-based persistence providers and aligns the extension's null-handling conventions with the broader framework migration.

causeway-extensions-executionlog-persistence-jpa · high confidence

FullCalendar extension introduces programmatic calendar interfaces and SPI

The fullcalendar application library now provides the Calendarable and CalendarEventable interfaces, with methods like getCalendarNames() and toCalendarEvent() marked as @Programmatic to exclude them from the user interface. It also adds a CalendarableDereferencingService SPI, allowing calendar markers to open the owner object rather than the calendar object itself, and includes a default HTML template for rendering calendar event cards.

extensions/vw/fullcalendar/applib · high confidence

FullCalendar integration introduces new callback data models using Java 8 time

The FullCalendar Wicket integration now includes new callback parameter classes—DroppedEvent, SelectedRange, and View—that utilize the modern java.time API (LocalDateTime, LocalDate) instead of legacy date libraries. This change supports the reorganization of the fullcalendar package structure and ensures that event dropping, range selection, and view state data are handled with standard Java 8 date-time types, aligning with the removal of Joda Time support.

causeway-extensions-fullcalendar-wicket-integration · high confidence

Home page UI updated with Bootstrap 4 and Animate.css

The home page UI now utilizes Bootstrap v4.0.0 for layout and styling, replacing the previous version, and includes Animate.css v3.5.2 to enable CSS-based animations on the page elements.

antora/supplemental-ui/js/home · high confidence

Homepage styling and branding updates

The homepage CSS has been updated to apply the Causeway brand palette (purple, cyan, pink, blue, yellow) and fix visual issues. Specific changes include correcting the vertical positioning of the logo and text in the header, adjusting the z-index of menu items to prevent overlapping, and adding copyright headers to the CSS files. The site now uses the 'Reveal' theme base with custom ISIS and Causeway color variables.

antora/supplemental-ui/css/home · high confidence

Introduces OpenSpec workflow skills and operational standards

Adds a suite of new AI agent skills and documentation to standardize the development workflow. The \.pi/prompts/\ directory now includes \opsx-explore\, \opsx-propose\, \opsx-apply\, and \opsx-archive\ to guide users through the OpenSpec change lifecycle, from initial investigation and proposal to implementation and final archiving. Operational standards are defined in \.pi/standards/\ for commit message formatting and OpenSpec workflow rules, while a new retrospective note in \.pi/notes/\ provides token-saving best practices for HTMX viewer sessions. A symlink in \.pi/skills\ now points to the shared agent skills directory.

.pi · high confidence

Introduction of abstract PDF.js viewer facet base class

The PDF.js metamodel extension now includes a new abstract base class, PdfJsViewerFacetAbstract, which serves as the foundation for PDF viewer facets. This class implements the PdfJsViewerFacet interface and manages configuration via PdfJsConfig, providing a standardized way to handle PDF viewer instances within the metamodel layer.

causeway-extensions-pdfjs-metamodel · medium confidence

JPA applib module migrated to Jakarta EE and Java Modules

The JPA application library has been migrated to the Jakarta EE namespace (e.g., \jakarta.persistence\, \jakarta.inject\) and structured as a Java Platform Module System (JPMS) module. This includes the addition of \module-info.java\ to define module dependencies and exports, and the renaming of core classes such as \CausewayModulePersistenceJpaApplib\ and \CausewayEntityListener\ to reflect the new package structure. The \CausewayEntityListener\ now handles JPA lifecycle events (like \@PostLoad\) using the updated Jakarta annotations and integrates with the new \JpaSupportService\ to manage \EntityManager\ access and object lifecycle publishing.

persistence/jpa/applib · high confidence

JPA column precision and scale now drive numeric digit facets

The JPA persistence metamodel now derives MaxTotalDigits, MaxFractionalDigits, and MinFractionalDigits facets directly from the JPA @Column annotation's precision and scale attributes. These facets are installed with low precedence, allowing @ValueSemantics to override them if explicitly configured, ensuring that numeric validation and display constraints align with the database schema definition.

causeway-persistence-jpa-metamodel · high confidence

JPA persistence integration module refactored to Jakarta EE and Java Modules

The JPA persistence integration module has been migrated to the Jakarta EE namespace (jakarta.persistence, jakarta.inject) and structured as a Java Platform Module System (JPMS) module. This change updates the underlying persistence stack to use Jakarta-standard APIs, ensuring compatibility with modern Spring Boot and Jakarta-based ecosystems, while also exposing specific type converters for Java time, util, AWT, and Causeway schema types via the new module exports.

persistence/jpa/integration · high confidence

JPA persistence models for security domain entities are re-implemented

The JPA persistence layer for the security manager extension has been updated with new entity implementations for ApplicationPermission, ApplicationRole, ApplicationTenancy, and ApplicationUser. These classes now implement the corresponding interfaces from the application library and include specific JPA annotations, named queries, and relationships (such as the many-to-many link between roles and users) to support the underlying data storage.

causeway-extensions-secman-persistence-jpa · high confidence

JPA weaving safeguard now supports configurable enforcement modes

The JPA integration layer now includes a new safeguard mechanism that validates whether entity classes have been properly byte-code enhanced. This change introduces a configurable \SafeguardMode\ that allows administrators to choose between three behaviors: logging a warning for non-weaved entities (\LOG\_ONLY\), throwing an error only if a subclass is weaved but a parent is not (\REQUIRE\_WEAVED\_WHEN\_ANY\_SUB\_IS\_WEAVED\), or strictly requiring all entities in the inheritance hierarchy to be weaved (\REQUIRE\_WEAVED\). This provides better control over startup failures and debugging information related to JPA enhancement issues.

causeway-persistence-jpa-integration · high confidence

Keycloak integration now propagates logouts and extracts custom roles

The Keycloak security module now includes a dedicated logout handler that propagates user logouts to Keycloak's OIDC end-session endpoint, addressing a gap where Spring Security did not previously support this flow. Additionally, the OAuth2 user service has been enhanced to extract and map custom roles from Keycloak access tokens, supporting client roles, realm roles, and generic roles with configurable prefixes, ensuring that user permissions are correctly synchronized with the application.

causeway-security-keycloak · high confidence

Migrate Markdown value-type UI to Wicket

The Wicket UI layer for the Markdown value-type has been migrated to a new module structure. This change introduces a dedicated Spring configuration module that wires up the necessary panel factories, enabling both parented and standalone rendering of Markdown content within Wicket-based views. The implementation includes a specific Wicket component and factory classes that handle the client-side JavaScript required for syntax highlighting, ensuring consistent display of Markdown attributes in the user interface.

valuetypes/markdown/ui/wicket · high confidence

Migrate RestfulObjects viewer from RestEasy to Spring Web MVC

The RestfulObjects viewer has been migrated from the RestEasy framework to Spring Web MVC (RestControllers). This change replaces the previous RestEasy-based resource classes with new Spring-based components, including the SwaggerSpecResource for API documentation, the \_DomainResourceHelper for domain object rendering, and the CausewayRestfulObjectsInteractionFilter2 for request handling. Users will now interact with the viewer through Spring's standard MVC infrastructure, which may affect custom integrations that relied on RestEasy-specific features or configuration.

causeway-viewer-restfulobjects-viewer · high confidence

Migrated AsciiDoc and Markdown value types to JPA persistence

The AsciiDoc and Markdown value types now include dedicated JPA persistence modules that automatically handle database storage. These modules provide JPA \AttributeConverter\ implementations (\CausewayAsciiDocConverter\ and \CausewayMarkdownConverter\) that transparently convert the rich value types to and from String columns in the database. The changes also introduce Spring Boot auto-configuration modules that register these converters and scan for them, ensuring that applications using these value types no longer need manual persistence setup.

valuetypes/asciidoc/persistence-jpa, valuetypes/markdown/persistence-jpa · high confidence

The EclipseLink persistence module has been migrated to the Jakarta EE namespace (replacing javax.\* with jakarta.\* imports) and converted to a Java Platform Module System (JPMS) module. This change updates the module-info.java to declare dependencies on jakarta.persistence, jakarta.inject, and other Jakarta libraries, and refactors internal classes (such as the JPA configuration, exception translation, and metadata services) to use the new namespaces. Users relying on this module will need to ensure their environment supports the Jakarta EE 9+ APIs and JPMS.

persistence/jpa/eclipselink · high confidence

The layout configuration system now includes formal XSD schemas for defining UI structure, located in the \antora/supplemental-ui/applib/layout\ directory. These schemas define the structure for core components (actions, properties, field sets, domain objects), Bootstrap 3 grid layouts (rows, columns, tabs), link definitions, and menu bar configurations. This provides a validated contract for how layout XML files should be structured, enabling better tooling support and ensuring consistency in how application interfaces are described.

antora/supplemental-ui/applib/layout · high confidence

PDF.js viewer integration updated for v4.x/v5.x and Wicket resource handling

The Wicket integration for the PDF.js viewer has been updated to support PDF.js versions 4.x and 5.x. This change introduces a new module-based resource loading strategy (using .mjs files) and configures the Wicket resource guard to allow access to necessary PDF.js assets like .bcmap and .mjs files. The integration now dynamically initializes the PDF viewer with specific worker and cmap URLs, ensuring correct rendering and printing functionality within the Wicket application.

extensions/vw/pdfjs/wicket/integration · high confidence

Programmatic ServletContext initialization replaces web.xml

The web application now initializes its servlet context programmatically via the new CausewayWebAppContextInitializer, eliminating the need for a web.xml descriptor. This change introduces a structured, two-phase startup process: first, it prepares the WebModuleContext, and second, it initializes registered WebModules (such as the LogOn Exception Logger and Template Resources modules) to register their filters and servlets. This modular approach ensures that web components are set up in a defined order and allows for cleaner configuration management within the application.

causeway-core-webapp · high confidence

Re-implemented OutboxClient using the new RestClient

The Execution Outbox REST client has been re-implemented to use the new RestfulClient infrastructure, replacing the previous underlying HTTP client. This change introduces support for OAuth2 Azure authentication alongside the existing Basic authentication, allows configuration of connect and read timeouts, and utilizes Java records for internal message structures (DeleteMessage, DeleteManyMessage). Users interacting with the outbox via this extension will benefit from the updated client capabilities and authentication modes.

causeway-extensions-executionoutbox-restclient · high confidence

Refactored core security authentication and logout mechanisms

The security module has been restructured to improve authentication handling and logout behavior. A new abstract base class, AuthenticationRequestAbstract, now manages user roles for authentication requests. The AuthenticationManager has been updated to support user refinement via UserMementoRefiners and includes a new RandomCodeGeneratorDefault for generating secure validation codes. Additionally, a dedicated LogoutMenu service has been introduced to handle logout actions, allowing for configurable redirects to either the login page or a specific logout endpoint based on the user's authentication source.

causeway-core-security · high confidence

The metamodel core has been refactored to replace mutable classes with immutable Java records, improving thread safety and code clarity. Key changes include converting the action execution logic into the new ActionExecutor record, which manages domain event phases (EXECUTING/EXECUTED) and argument updates, and restructuring the consent system into the Consent sealed interface with Allow/Veto variants and a detailed VetoReason record that distinguishes between security and programming-model origins. Additionally, the InteractionResult is now a record that aggregates veto reasons and advising facets, while supporting services like ExecutionContext and MetaModelContext\_usingSpring have been adapted to work with this new immutable, record-based architecture.

causeway-core-metamodel · high confidence

Refactors proxying internals to use records and capture invocation origin

The core runtime's proxying mechanism has been refactored to improve clarity and maintainability. The \WrappingObject\ interface now defines a new \Origin\ record to explicitly store the underlying POJO, any associated managed mixee, and the \SyncControl\ state, ensuring this context is preserved on proxy creation. Additionally, a new \WrapperInvocationHandler\ interface introduces a \WrapperInvocation\ record to encapsulate method invocation details (target, method, arguments, and origin), replacing previous abstract handler implementations. These changes streamline how the framework handles object wrapping and method interception without altering the external API.

causeway-core-runtime · high confidence

Refactors transaction scoping to prevent stack overflows and adds change-tracking events

The transaction module introduces new event types, PostStoreEvent and PreStoreEvent, to support change tracking, and significantly refactors the StackedTransactionScope implementation. This refactoring replaces the previous object-holding mechanism with a UUID-based nesting stack to manage transaction scopes, specifically addressing and preventing stack overflow errors that could occur during nested transaction handling and after-completion callbacks.

causeway-core-transaction · high confidence

Reimplemented proxy factory to support additional fields and modern class loading

The ByteBuddy-based proxy factory service has been re-implemented to support the creation of proxies with additional fields, a capability previously unavailable. This change also introduces a new ClassLoadingStrategyAdvisor to handle JVM-specific class loading requirements (specifically JDK 9+ module access), replacing older strategies. The implementation now uses JSpecify annotations for null-safety and integrates with Spring's Objenesis for instance creation, ensuring robust proxy generation across different Java versions.

causeway-core-codegen-bytebuddy · high confidence

Removal of CVS administrative configuration files

The CVS administrative files in the repository root (CVSROOT) have been deleted. This includes configuration and hook scripts such as config, commitinfo, loginfo, notify, rcsinfo, taginfo, verifymsg, modules, cvswrappers, editinfo, checkoutlist, and commitinfo. These files previously controlled repository behavior including pre-commit checks, log message verification, notification routing, tag validation, and module definitions; their removal means these custom CVS server-side hooks and configurations are no longer active.

CVSROOT · high confidence

Rename IsisModule classes to CausewayModule

The module configuration class for the Flyway extension has been renamed from IsisModuleExtFlywayImpl to CausewayModuleExtFlywayImpl, reflecting the project's rebranding from Isis to Causeway. This change updates the Java class name and package structure to align with the new naming convention, ensuring consistency across the codebase.

extensions/core/flyway/impl · high confidence

Restful Objects applib migrated to Spring REST and Jackson 3

The Restful Objects application library has been refactored to replace the previous JBoss RestEasy implementation with Spring's RestController-based architecture. This change introduces a new Java module definition and updates the underlying JSON serialization to Jackson 3.x (tools.jackson), while also removing legacy Joda Time support. For users, this represents a significant backend shift in how the REST API is served and serialized, requiring compatibility with the new Spring and Jackson dependencies.

viewers/restfulobjects/applib · high confidence

Restful Objects rendering layer refactored to Spring MVC and Java records

The Restful Objects rendering module has been migrated from the RestEasy framework to Spring MVC (RestControllers), replacing the previous JBoss-specific implementation. This change introduces a new rendering architecture where core components such as ResponseFactory, ResourceContext, and RepresentationService are implemented as Java records, and exception handling is standardized via new ExceptionPojo and ExceptionDetail records. For users, this ensures consistent HTTP response generation and error reporting while aligning the viewer with the modern Spring Boot stack.

causeway-viewer-restfulobjects-rendering · high confidence

Restful Objects viewer adopts Jackson 3.x and Spring RestClient

The Restful Objects viewer library has migrated its JSON processing from the legacy Jackson 2.x API to Jackson 3.x (indicated by the \tools.jackson\ package imports in the new \JsonRepresentation\ class). Additionally, the HTTP client implementation has been refactored to use Spring's \RestClient\ instead of the previous \jakarta.ws.rs\-based approach, as evidenced by the new \RestfulRequest\ and \RestfulResponse\ classes and the removal of JAX-RS dependencies. These changes update the underlying infrastructure for handling REST payloads and network requests.

causeway-viewer-restfulobjects-applib · high confidence

Restful Objects viewer documentation restructured and renamed to Apache Causeway

The documentation for the Restful Objects viewer has been reorganized into a new Antora module structure under \viewers/restfulobjects/adoc/modules/ROOT\. All references to the previous 'Isis' project name have been updated to 'Apache Causeway', and the documentation now includes new pages for the REST Client, content negotiation (including the simplified v2 profile), layout resources, and hints and tips. This restructure improves navigation and aligns the viewer's documentation with the broader Apache Causeway project branding and architecture.

viewers/restfulobjects/adoc/modules/ROOT · high confidence

Restful Objects viewer migrates to Spring REST controllers

The Restful Objects viewer implementation has been refactored to use Spring's @RestController and @RestControllerAdvice annotations instead of the previous RestEasy (JBoss) framework. This change introduces Spring-based exception handling via ExceptionMapperForRestfulObjects and registers the viewer's REST resources (such as DomainObjectResourceServerside, DomainServiceResourceServerside, and HomePageResourceServerside) as Spring components within the new CausewayModuleViewerRestfulObjectsViewer configuration module.

viewers/restfulobjects/viewer · high confidence

Restored Isis v1 namespace schemas for changes and commands

The XML schemas for the Isis v1 namespaces (chg and cmd) have been restored to the supplemental UI documentation, now hosted under the https://causeway.apache.org/schema-v1 path. This update includes versioned schema definitions (e.g., chg-1.0.xsd through chg-2.0.xsd and cmd-1.0.xsd through cmd-2.0.xsd) that define the structure for transaction changes and command invocations, ensuring that documentation for these specific API contracts is available for users.

antora/supplemental-ui/schema-v1 · high confidence

Runtime services migrated to Java records and Spring-managed defaults

The default implementations for core runtime services—including BookmarkService, CommandExecutorService, EmailService, FactoryService, InteractionService, and ObjectIconService—have been refactored to use Java records and are now registered as Spring beans via the @Service annotation. This change standardizes service instantiation, simplifies dependency injection through record components, and ensures consistent lifecycle management within the application context.

causeway-core-runtimeservices · high confidence

Schema module migrated to Jakarta EE and v2.0

The schema module has been updated to use the Jakarta XML Binding (JAXB) API instead of the legacy Java EE javax.xml.bind, requiring the jakarta.xml.bind and jakarta.inject dependencies. Additionally, the internal XML schemas (XSDs) and generated Java packages have been bumped to version 2.0 (e.g., org.apache.causeway.schema.cmd.v2), introducing new DTO structures for commands, interactions, changes, and the metamodel that align with the framework's v2.0 release.

api/schema · high confidence

Secman application library refactored to use mixins and new value types

The security manager application library has been restructured to improve modularity and UI consistency. Domain objects like ApplicationRole, ApplicationTenancy, and ApplicationUser now expose their behaviors (such as updating names, descriptions, or unlocking users) via dedicated mixin classes (e.g., ApplicationRole\_updateName, ApplicationUser\_unlock) rather than direct methods. Permission management is supported by new value types like ApplicationPermissionValue and a ViewModel wrapper ApplicationFeatureChoices, which enables refined autocomplete search for application features. Additionally, the ApplicationRoleMenu service now provides a dedicated 'Security' menu entry for managing roles and finding users.

causeway-extensions-secman-applib · high confidence

Secman integration module introduces v1 compatibility for permission evaluation

The secman integration module now includes an SPI for transforming ApplicationFeatureIds before permission evaluation, with a default identity transformer and a v1-compatibility transformer that converts logical type names to physical package names. This allows existing v1-style permissions to work without migration. The module also wires up the Secman authenticator, authorization facets, and other integration services via Spring auto-configuration.

extensions/security/secman/integration · high confidence

Secman integration now enforces user status checks and preserves role assignments during authentication

The secman integration module now implements a new AuthenticatorSecman that explicitly vetoes login attempts for users who are not in an UNLOCKED status or who lack a persisted encrypted password, preventing disabled or incomplete accounts from authenticating. Additionally, the UserMementoRefinerFromApplicationUser has been updated to ensure that original roles assigned to the application user are preserved and added to the authenticated user context, correcting previous behavior where these roles might have been lost during the refinement stage.

causeway-extensions-secman-integration · high confidence

Security documentation restructured for Apache Causeway

The security guide documentation has been reorganized to align with the Apache Causeway rebranding and updated navigation structure. New files establish a clear hierarchy, including an overview of the authentication and authorization SPIs, details on permissions and auditing, and specific usage instructions for the Wicket and Restful Objects viewers. The navigation includes links to core security modules (bypass, keycloak, spring) and extensions (SecMan, Audit Trail, Spring OAuth2, Session Log), ensuring users can easily find configuration and implementation details for securing their applications.

security/adoc/modules/ROOT · high confidence

Server-side Prism syntax highlighting with theme support

The viewer-commons prism module now performs syntax highlighting server-side using GraalJS, ensuring that adoc rendering looks consistent between server and client. This change introduces a new module structure (module-info.java) and utility classes (PrismUtils, PrismTheme) to manage Prism resources and themes. Users can now select from multiple Prism themes (Default, Coy, Dark, etc.), with the Coy theme including a specific CSS override to remove box shadows from code blocks.

viewers/commons/prism · high confidence

Server-side syntax highlighting for code blocks

The viewer now performs syntax highlighting for code blocks on the server side using the Prism library and GraalJS, ensuring that the visual appearance of highlighted code matches the previous client-side rendering. This change introduces a new standalone highlighting engine within the commons prism module that processes HTML content, identifies code nodes by their language class, and applies syntax highlighting before the content is sent to the browser.

causeway-viewer-commons-prism · high confidence

Session log persistence model refactored to use JPA interfaces and embedded IDs

The JPA persistence layer for the session log extension has been updated to align with the application's domain model changes. The \SessionLogEntry\ entity now implements the \SessionLogEntry\ interface defined in the \applib\ module, ensuring consistency with the abstracted domain contract. Additionally, the primary key structure has been refactored to use an embedded \SessionLogEntryPK\ class, which includes a dedicated \Semantics\ component for value-based identification. This change supports the broader migration of domain objects to interface-based contracts and improves the structural integrity of the persisted session log data.

causeway-extensions-sessionlog-persistence-jpa · high confidence

The .codex/skills path is no longer a standalone directory but a symbolic link pointing to ../.agents/skills. This change consolidates skill definitions into the .agents directory, meaning any skills previously accessible via .codex/skills are now sourced from the shared .agents location.

.codex · high confidence

Standardized extension documentation structure and build configuration

This change introduces a consistent documentation and build scaffolding across all extensions. It adds \antora.yml\ configuration files to every extension module (including core, security, and view-layer extensions) to define their documentation metadata and navigation, ensuring they are properly indexed in the user guide. Additionally, \.build-jpa-enhance\ marker files are added to persistence-enabled extensions (such as commandlog, executionlog, and audittrail) to explicitly enable static weaving via profile activation rules in the parent POM, ensuring these modules are correctly processed during the build.

extensions · high confidence

Transaction module restructured for Jakarta EE and Spring integration

The core/transaction module has been reorganized into a dedicated Java module (org.apache.causeway.core.transaction) with explicit exports for change tracking and scope services. This change introduces a new @TransactionScope annotation and a BeanFactoryPostProcessor to register a StackedTransactionScope in Spring, enabling transaction-scoped beans. It also adds a TimestampService that automatically updates OnUpdatedBy and OnUpdatedAt mixins on pre-store events, and refactors the entity change tracking interfaces (EntityChangeTracker, EntityChangesPublisher, EntityPropertyChangePublisher) to support publishing property changes and entity lifecycle events within the transaction scope.

core/transaction · high confidence

Updated home page branding assets and technology badges

The documentation site's home page visuals have been refreshed with new SVG assets. This includes updated logos for the Apache Wicket, Bootstrap, and Spring frameworks in the 'built-with' section, as well as new versions of the main Causeway logo (including a BMP-embedded SVG variant). These changes update the visual identity and technology stack representation on the landing page.

antora/supplemental-ui/img · high confidence

Updated published XSD schemas for commands and changes

The published XML schema definitions (XSDs) for the 'chg' (changes) and 'cmd' (commands) namespaces have been updated to their latest versions. This includes the introduction of new major versions (2.0) for both schemas, which rename fields such as 'transactionId' to 'interactionId' and 'user' to 'username', and add JAXB annotations for Java binding. Additionally, the 'cmd' schema has been extended with new minor versions (1.2–1.4) that introduce fields like 'logicalMemberIdentifier', 'timings', and 'userData' to support more detailed command metadata and custom data attachment.

antora/supplemental-ui/schema · high confidence

Updated reference documentation for the Causeway Applib module

The reference guide index for the Causeway application library (applib) has been regenerated and updated. This includes new or refreshed documentation pages for core module classes such as CausewayModuleApplib, Identifier, and ViewModel, as well as comprehensive updates to the API documentation for domain object annotations including @Action, @ActionLayout, @Collection, @CollectionLayout, @DomainObject, @DomainObjectLayout, and @DomainService. The changes reflect the current state of the applib API, ensuring the documentation accurately describes the available annotations, their attributes, and their usage for defining domain semantics and UI layout.

antora/components/refguide-index/modules/applib · high confidence

Wicket UI module restructured with new Spring configuration and component registry

The Wicket viewer UI module has been reorganized to improve modularity and maintainability. A new Spring configuration module (CausewayModuleViewerWicketUi) centralizes the registration of core services, including a new theme provider that supports Bootswatch themes (defaulting to Flatly) and a dedicated logout handler that properly manages Wicket session invalidation within the interaction layer. The component factory system has been refactored into a new registry (ComponentFactoryRegistry) using Java records for keys and lists, simplifying how UI components are discovered and instantiated. Additionally, new UI components have been introduced, such as a markup panel with server-side syntax highlighting via Prism, a date/time picker with FontAwesome icons, and an export factory for collection contents, enhancing the viewer's rendering and interaction capabilities.

causeway-viewer-wicket-ui · high confidence

Wicket Viewer model layer refactored to Java records and simplified navigation

The Wicket Viewer model layer has been significantly refactored to use Java records, replacing previous class-based implementations for core models such as ActionModel, BookmarkTreeNode, and BookmarkedPagesModel. This change introduces specific behavioral updates: action results from table columns now support configurable routing (reload current page vs. open in a new tab) via the new ColumnActionModifier enum, and the bookmark navigation tree has been simplified to improve parent-child relation handling and title synchronization. Additionally, the model layer now includes dedicated models for handling multi-choice and single-choice selections via Select2 widgets, and service actions are now backed by a dedicated ServiceActionsModel.

causeway-viewer-wicket-model · high confidence

Wicket viewer refactored with new integration handlers and service implementations

The Wicket viewer module has been refactored to introduce new integration components for request lifecycle management, telemetry, and authentication. A new RehydrationHandler intercepts requests to reload view-models and re-fetch detached entities, while TelemetryStartHandler and TelemetryStopHandler manage OpenTelemetry observation scopes and tag metrics like entities loaded and dirtied. SessionAuthenticator handles interaction context determination, including impersonation support. The WebRequestCycleForCauseway now coordinates these handlers, manages session expiration flags, and validates the meta-model before rendering. Additionally, new services include DeepLinkServiceWicket for generating deep links to domain objects, IconResourceReferenceFactoryDefault for serving object icons with byte-range support, and WebModuleWicket for configuring the Wicket filter. Component registration is now handled by ComponentFactoryConfigWkt, and page class resolution is managed by PageClassRegistryDefault.

causeway-viewer-wicket-viewer · high confidence

Test coverage

Add mixin-based counter bump action for regression testing; Added ComparableContractTester for validating object ordering; Added Cucumber integration test object factory; Added Cucumber-based regression tests for command execution and audit session persistence; Added HSQL DB Manager prototyping menu; Added JPA integration tests for command execution and audit session logging; Added JPA-specific regression tests for command, entity, execution, lifecycle, and property publishing; Added Wicket integration and logging tests for regression suite; Added architecture test support library for domain and module rules; Added comprehensive domain object fixture for testing all supported data types; Added documentation for the Fixture Scripts testing module; Added domain model and services for the GraphQL test2 viewer; Added integration tests for GraphQL rich value and resource semantics; Added integration tests for layout facets and configuration; Added integration tests for the Excel extension module; Added integration tests for the FakeData module; Added integration tests for the RestfulObjects viewer; Added integration tests for the async wrapper factory; Added regression test for generic event publishing; Added regression test model for layout verification; Added regression tests for REST, LDAP, and metamodel performance; Added regression tests for REST-JPA integration; Added regression tests for action and collection interactions; Added regression tests for async wrapper domain events; Added regression tests for bootstrapping, configuration, and service injection; Added regression tests for wrapper interactions and mixin actions; Added test to verify JPA entity enhancement; Added testing fixtures module for populating demo data; Added tests for CommandDto YAML serialization and replay import; Added tests for testing module documentation and fixture data; Added unit tests for UiObjectWkt hint management; Added unit tests for Wicket Viewer components and converters; Added value semantics regression tests; Documentation for integration test support utilities; Expanded GraphQL test domain with new entities, services, and value types; Expanded regression tests for domain model validation and introspection; Expanded test coverage for metamodel facet factories and domain events; H2 Console UI module migrated to Jakarta EE; New FakeDataService for generating test data; New JPA persistence regression tests; New JPA+Wicket regression test application and tests; New fixtures testing library for prototyping and integration testing; New integration test support utilities for approvals, Swagger, and validation; New integration testing support library for Causeway; New regression test domain fixtures and validation models; New regression test for command, execution, and audit logging; New testing fixtures for Excel data import; New testing fixtures library for domain object setup and teardown; New testing utilities for contract verification and approval testing; New unit test support library for contract testing and assertions; Regression test suite updated with new domain models and Wicket configuration; Rename IsisModule classes to CausewayModule.

Dependencies

Routine dependency updates across 227 manifests

This release updates dependencies across 227 Maven manifests, including bumping Spring Boot from 3.2.0 to 3.2.1, upgrading Apache Wicket from 9.7.0 to 9.8.0, and updating the OWASP dependency-check-maven plugin from 9.0.4 to 9.0.5. Other notable changes include updates to Vaadin, JUnit, Lombok, and various internal framework libraries to their latest stable versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 39 → 41 (+2.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 33 → 34 (+0.6)
  • Architecture 100 → 69 (-30.3)
  • Maturity 69 → 75 (+6.3)
  • Readiness 57 → 74 (+16.7)
  • Security 43 → 68 (+25.6)
  • Domain Modelling 57 → 48 (-9.2)
  • Accessibility 33 → 34 (+0.8)

Resolved (163)

  • (anonymous) (cognitive 17) (antora/supplemental-ui/js/home/main.js)
  • (anonymous) (cognitive 20) (antora/supplemental-ui/js/home/lib/magnific-popup/magnific-popup.js)
  • Change coupling: AutoCompleteGeneratedDslQuery.java ↔ AutoCompleteGeneratedQueryFacetFactory.java (persistence/querydsl/metamodel/src/main/java/org/apache/causeway/persistence/querydsl/metamodel/facets/AutoCompleteGeneratedDslQuery.java)
  • Change coupling: Can_Empty.java ↔ Can_Multiple.java (commons/src/main/java/org/apache/causeway/commons/collections/Can_Empty.java)
  • Change coupling: Can_Empty.java ↔ Can_Singleton.java (commons/src/main/java/org/apache/causeway/commons/collections/Can_Empty.java)
  • Change coupling: DomainObjectInvocationHandler.java ↔ PluralInvocationHandler.java (core/runtimeservices/src/main/java/org/apache/causeway/core/runtimeservices/wrapper/handlers/DomainObjectInvocationHandler.java)
  • Change coupling: FacetedMethodParameter.java ↔ TypeOfFacet.java (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/facets/FacetedMethodParameter.java)
  • Change coupling: InteractionUtils.java ↔ ActionVisibilityContext.java (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/interactions/InteractionUtils.java)
  • Change coupling: InteractionUtils.java ↔ CollectionVisibilityContext.java (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/interactions/InteractionUtils.java)
  • Change coupling: NavigationToolbar.java ↔ TotalRecordsToolbar.java (viewers/wicket/ui/src/main/java/org/apache/causeway/viewer/wicket/ui/components/table/nav/NavigationToolbar.java)
  • Change coupling: SchemaStrategyRich.java ↔ SchemaStrategySimple.java (viewers/graphql/model/src/main/java/org/apache/causeway/viewer/graphql/model/domain/rich/SchemaStrategyRich.java)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (commons/src/main/java/org/apache/causeway/commons/internal/primitives/_Ints.java)
  • Duplicated block (10 lines × 2) (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/facets/collections/collection/CollectionAnnotationFacetFactory.java)
  • Duplicated block (10 lines × 2) (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/facets/collections/collection/CollectionAnnotationFacetFactory.java)
  • Duplicated block (10 lines × 2) (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/interactions/managed/ActionInteraction.java)
  • Duplicated block (10 lines × 2) (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/specloader/typeextract/TypeExtractor.java)
  • Duplicated block (10 lines × 2) (core/metamodel/src/main/java/org/apache/causeway/core/metamodel/util/snapshot/XmlSchema.java)
  • Duplicated block (10 lines × 2) (core/runtimeservices/src/main/java/org/apache/causeway/core/runtimeservices/wrapper/handlers/DomainObjectInvocationHandler.java)
  • …and 143 more

New (1355)

  • #applyPresentation (cognitive 79) (viewers/webcomponents/foundation/src/grid-widget.mjs)
  • #applyPresentation (cyclomatic 45) (viewers/webcomponents/foundation/src/grid-widget.mjs)
  • #captureParameter (cognitive 29) (viewers/webcomponents/foundation/src/interaction-controller-element.mjs)
  • #captureParameter (cyclomatic 25) (viewers/webcomponents/foundation/src/interaction-controller-element.mjs)
  • #describeActionInteraction (cognitive 19) (viewers/webcomponents/foundation/src/service-action-context.mjs)
  • #describeActionInteraction (cyclomatic 20) (viewers/webcomponents/foundation/src/service-action-context.mjs)
  • #describeApplicationEntry (cognitive 35) (viewers/webcomponents/foundation/src/graphql-client.mjs)
  • #describeApplicationEntry (cyclomatic 33) (viewers/webcomponents/foundation/src/graphql-client.mjs)
  • #describeObject (cognitive 30) (viewers/webcomponents/foundation/src/graphql-client.mjs)
  • #describeObject (cyclomatic 16) (viewers/webcomponents/foundation/src/graphql-client.mjs)
  • #flush (cognitive 43) (viewers/webcomponents/foundation/src/object-context-controller.mjs)
  • #flush (cyclomatic 31) (viewers/webcomponents/foundation/src/object-context-controller.mjs)
  • #handleKeydown (cyclomatic 19) (viewers/webcomponents/foundation/src/menubar-element.mjs)
  • #initialize (cognitive 33) (viewers/webcomponents/foundation/src/pdf-document-reader.mjs)
  • #initialize (cyclomatic 27) (viewers/webcomponents/foundation/src/pdf-document-reader.mjs)
  • #load (cognitive 35) (viewers/webcomponents/foundation/src/menu-context-controller.mjs)
  • #load (cyclomatic 32) (viewers/webcomponents/foundation/src/menu-context-controller.mjs)
  • #observePages (cognitive 21) (viewers/webcomponents/foundation/src/pdf-document-reader.mjs)
  • #prepareLayout (cognitive 29) (viewers/webcomponents/foundation/src/object-element.mjs)
  • #presentation (cognitive 25) (viewers/webcomponents/foundation/src/property-element.mjs)
  • …and 1335 more

Changes since last survey

  • 300 commits — 245 feature/other, 55 fixes

By area

  • openspec/changes — 161 commits
  • viewers/webcomponents — 92 commits
  • (repo) — 11 commits
  • viewers/graphql — 7 commits
  • openspec/planned-changes — 6 commits
  • openspec/specs — 6 commits
  • valuetypes/asciidoc — 4 commits
  • parent/pom.xml — 3 commits
  • regressiontests/referenceapp — 2 commits
  • (root) — 1 commit
  • .pi/notes — 1 commit
  • antora/components — 1 commit
  • bom/pom.xml — 1 commit
  • commons/pom.xml — 1 commit
  • extensions/core — 1 commit
  • extensions/security — 1 commit
  • viewers/restfulobjects — 1 commit

Notable commits

  • fix: CAUSEWAY-4056: archives Petclinic logo navigation fix
  • fix: CAUSEWAY-4056: archives field widget keyboard focus fixes
  • fix: CAUSEWAY-4056: docs(openspec): archive Grid preview icon parity fix
  • fix: CAUSEWAY-4056: docs(openspec): archive deleted void action navigation fix
  • fix: CAUSEWAY-4056: docs(openspec): archive editor and pager presentation fixes
  • fix: CAUSEWAY-4056: docs(openspec): archive narrow multiline layout fix
  • fix: CAUSEWAY-4056: docs(openspec): archive utility menu and Vue result fixes
  • fix: CAUSEWAY-4056: docs(openspec): plan deleted void action navigation fix
  • fix: CAUSEWAY-4056: docs(openspec): plan editor and pager cosmetic fixes
  • fix: CAUSEWAY-4056: docs(openspec): plan utility menu and Vue result fixes
  • fix: CAUSEWAY-4056: docs(openspec): propose narrow multiline layout fix
  • fix: CAUSEWAY-4056: fix(executionoutbox): compile dormant REST client tests
  • fix: CAUSEWAY-4056: fix(graphql): align rebased metamodel APIs
  • fix: CAUSEWAY-4056: fix(graphql): support boxed primitive mutations
  • fix: CAUSEWAY-4056: fix(graphql): update member metadata introspection coverage
  • fix: CAUSEWAY-4056: fix(petclinic): keep collections beside owner details
  • fix: CAUSEWAY-4056: fix(webcomponents): account for sticky result header
  • fix: CAUSEWAY-4056: fix(webcomponents): activate secured Vue source profile
  • fix: CAUSEWAY-4056: fix(webcomponents): adjust PetOwner visit page size
  • fix: CAUSEWAY-4056: fix(webcomponents): align Grid preview toggle icon
  • …and 280 more

Architecture

  • Containers 0 added · 0 removed · contexts 94 added · 0 removed · edges 323 added · 0 removed

Added bounded contexts (94)

  • causeway-applib
  • causeway-commons
  • causeway-core-codegen-bytebuddy
  • causeway-core-config
  • causeway-core-interaction
  • causeway-core-internaltestsupport
  • causeway-core-metamodel
  • causeway-core-mmtest
  • causeway-core-mmtestsupport
  • causeway-core-runtime
  • causeway-core-runtimeservices
  • causeway-core-security
  • causeway-core-transaction
  • causeway-core-webapp
  • causeway-extensions-audittrail-applib
  • causeway-extensions-audittrail-persistence-jpa
  • causeway-extensions-commandlog-applib
  • causeway-extensions-commandlog-persistence-jpa
  • causeway-extensions-commandreplay-primary
  • causeway-extensions-commandreplay-secondary
  • …and 74 more

Added dependency edges (323)

  • causeway-applib → causeway-commons (coupling)
  • causeway-core-codegen-bytebuddy → causeway-commons
  • causeway-core-config → causeway-applib (coupling)
  • causeway-core-config → causeway-commons
  • causeway-core-interaction → causeway-applib
  • causeway-core-interaction → causeway-commons
  • causeway-core-interaction → causeway-core-metamodel
  • causeway-core-metamodel → causeway-applib (coupling)
  • causeway-core-metamodel → causeway-commons (coupling)
  • causeway-core-metamodel → causeway-core-config (coupling)
  • causeway-core-metamodel → causeway-core-security
  • causeway-core-mmtest → causeway-applib (coupling)
  • causeway-core-mmtest → causeway-commons
  • causeway-core-mmtest → causeway-core-config
  • causeway-core-mmtest → causeway-core-metamodel (coupling)
  • causeway-core-mmtest → causeway-core-mmtestsupport
  • causeway-core-mmtest → causeway-core-security
  • causeway-core-mmtestsupport → causeway-applib (coupling)
  • causeway-core-mmtestsupport → causeway-commons
  • causeway-core-mmtestsupport → causeway-core-config (coupling)
  • …and 303 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

apache/causeway was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 351eae721d91366b1c4444131f0fcbf85faa323c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-90d5d2fe38ee.