elsa-workflows/elsa-core
64.2
Adequate · 23 September 2026
147.1k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is Elsa Workflows, a .NET-based workflow engine and automation platform that manages the definition, execution, and persistence of complex business processes. It provides a modular architecture supporting multiple database backends, multitenancy, and distributed runtime coordination, while offering extensive APIs for programmatic workflow management and real-time monitoring. The platform also integrates AI capabilities through a copilot system and allows for runtime workflow modifications via an alterations module.
How it got here
2018–2023 — Platform architecture and API expansion
95 changes.
The project established foundational development standards and upgraded to .NET 10 while introducing a modular feature system with dependency resolution. Significant work focused on expanding the workflow engine with scheduling, HTTP activities, and runtime alterations, alongside a comprehensive overhaul of the REST API and client libraries to support advanced management and observability.
2024–2025 — multitenancy and distributed runtime
56 changes.
This period focused on establishing a robust multitenancy framework and distributed workflow runtime, enabling the system to coordinate across clustered nodes with secure tenant isolation. Significant efforts were made to refactor the persistence layer for Entity Framework Core across multiple database providers and to introduce comprehensive scripting capabilities via C\#, JavaScript, Python, and Liquid expressions.
2026 — Shell architecture and modular diagnostics
51 changes.
The project refactored its core infrastructure to adopt a CShells-based modular architecture, enabling dynamic package loading and granular feature management. This period also introduced comprehensive operational capabilities, including structured logging with live streaming, a secrets management system with multi-provider persistence, and an AI copilot integration.
Features
Add Activity Descriptors API client resources
The API client now includes support for querying activity descriptors, introducing new response models and enumerations. Users can now consume the \ListActivityDescriptorsResponse\ to retrieve collections of activity descriptors, while the client exposes \ActivityKind\ (Action, Trigger, Job, Task) and \PortType\ (Embedded, Flow) enums to represent activity execution modes and port classifications.
src/clients/Elsa.Api.Client/Resources/ActivityDescriptors/Enums, src/clients/Elsa.Api.Client/Resources/ActivityDescriptors/Responses · high confidence
Add Elsa README video assets
A new Remotion-based video project has been added to the \design/video/elsa-readme-video\ directory to generate assets for the repository's README. This includes the source code for an animated video showcasing Elsa Workflows, along with configuration files (Remotion config, TypeScript config) and a README explaining how to build the video and GIF assets.
design/video · high confidence
Add Expressions shell feature
The Elsa.Expressions module now registers an Expressions shell feature that provides expression evaluation services. This feature installs the IExpressionEvaluator and IWellKnownTypeRegistry services, making them available for use within the platform's shell architecture.
src/modules/Elsa.Expressions/ShellFeatures · high confidence
Add GitHub Copilot adapter for Weaver AI
This change introduces the Copilot AI provider for the Weaver AI system, allowing users to connect their GitHub Copilot sessions to Elsa's AI workflows. The module registers a new \CopilotProvider\ that manages session creation and resumption, maps Copilot-specific events (such as assistant messages, reasoning deltas, and tool executions) to the standard AI provider event model, and handles tool invocations through the \ElsaCopilotToolFunction\. Configuration is exposed via \CopilotOptions\, supporting settings for runtime paths, URLs, GitHub tokens, model selection, and streaming preferences, and is wired up through the \CopilotAIFeature\ shell feature.
src/modules/Elsa.AI.Copilot · high confidence
Add JavaScript functions for resolving secrets
The \Elsa.Secrets.JavaScript\ module now exposes a \getSecret\ function within JavaScript expressions, allowing workflows to resolve secrets by name at runtime. This is implemented via a \SecretsJavaScriptHandler\ that registers the function definition and handles the \EvaluatingJavaScript\ notification to inject the resolver into the script engine.
src/modules/Elsa.Secrets.JavaScript · high confidence
Add MySQL and Oracle persistence providers for external authentication
The External Authentication module now supports MySQL and Oracle databases in addition to existing providers. This change introduces the \Elsa.ExternalAuthentication.Persistence.EFCore.MySql\ and \Elsa.ExternalAuthentication.Persistence.EFCore.Oracle\ modules, providing EF Core DbContext factories, shell features, and extension methods (\UseMySql\, \UseOracle\) to configure persistence. Initial database migrations are included for both providers, creating tables for authorization grants, broker transactions, connection observations, preview results, registry versions, and sessions. The Oracle implementation specifically maps large JSON and binary payloads to LOB types (NCLOB/BLOB) to handle data exceeding standard column limits.
(repo-wide) · high confidence
Add OpenID Connect external authentication adapter
Elsa now supports authenticating users via OpenID Connect through a new protocol adapter. This feature enables the authorization-code flow with mandatory S256 PKCE, supports both discovery-based and manual trust modes, and allows administrators to configure client credentials, scopes, and logout endpoints. Existing v1 connection settings are automatically migrated to the new v2 model, replacing the old authority and callback URI fields with deployment-derived callback paths.
src/modules/Elsa.ExternalAuthentication.OpenIdConnect · high confidence
Add RadioList UI Hint support to API Client
The API client now includes models to support the RadioList UI hint, enabling the representation of radio button selection lists. This change introduces the RadioList record to define a collection of items with an option to treat the list as a flags enum, the RadioListItem record to define individual text and value pairs, and the RadioListProps class to expose the radio list configuration within UI hint properties.
src/clients/Elsa.Api.Client/Shared/UIHints/RadioList · high confidence
Add SAS token generation and validation feature
The new Elsa.SasTokens module introduces the ability to create and decrypt Shared Access Signature (SAS) tokens for securing workflow interactions. It provides an ITokenService interface and a DataProtectorTokenService implementation that leverages ASP.NET Core Data Protection to encrypt payloads, supporting both time-limited and non-expiring tokens. The feature registers the necessary data protection services and DI bindings, making it available for use in securing access to workflow resources.
src/modules/Elsa.SasTokens · high confidence
Add SQLite persistence for secrets with tenant scoping
This location introduces the SQLite-backed persistence layer for the Secrets module, enabling secrets to be stored in a local SQLite database. The implementation includes the initial database schema and migrations that enforce unique secret names within each tenant scope (via a TenantId column and a composite unique index), ensuring secrets are properly isolated across tenants.
src/modules/Elsa.Secrets.Persistence.EFCore.Sqlite · high confidence
Add SQLite persistence for structured logs
Users can now persist diagnostics structured log events to a local SQLite database. This module provides a new \SqliteStructuredLogPersistenceFeature\ that registers the necessary services, including a connection factory, SQL dialect, and schema migrator, allowing structured logs to be stored in a file-based SQLite database (defaulting to \elsa-structured-logs.db\). Configuration is exposed via manifest settings for the connection string and migration behavior, and the feature integrates with the existing relational structured log infrastructure for write queuing and retention policies.
src/modules/Elsa.Diagnostics.StructuredLogs.Persistence.Sqlite · high confidence
Add client API for listing log persistence strategies
The Elsa API client now includes support for querying available log persistence strategies. Users can call the new \ListAsync\ method on \ILogPersistenceStrategiesApi\ to retrieve a list of \LogPersistenceStrategyDescriptor\ objects, which provide the type name, display name, and description for each registered strategy.
src/clients/Elsa.Api.Client/Resources/LogPersistenceStrategies · high confidence
Add client API for listing workflow context provider descriptors
The API client now includes support for retrieving workflow context provider descriptors. A new model, WorkflowContextProviderDescriptor, exposes the provider's Name and Type, and the corresponding IWorkflowContextProviderDescriptorsApi interface allows users to call the /workflow-contexts/provider-descriptors endpoint to list available providers.
src/clients/Elsa.Api.Client/Resources/WorkflowExecutionContexts · high confidence
Add client API for querying installed features
The API client now includes a new IFeaturesApi interface that allows applications to retrieve details about specific installed features or list all available features via the /features/installed endpoints. This enables clients to programmatically check feature availability and descriptors at runtime.
src/clients/Elsa.Api.Client/Resources/Features/Contracts · high confidence
Add client support for discovering output converters
Workflow authors can now programmatically discover available output converters compatible with specific source and destination types. This change introduces a new client API (\IOutputConvertersApi\) that queries the server for converter descriptors, including details like the converter ID, display name, supported types, and optional settings schemas, enabling dynamic selection of converters in binding boundaries.
src/clients/Elsa.Api.Client/Resources/OutputConverters · high confidence
Add client support for listing workflow activation strategies
The API client now includes a new interface and model for workflow activation strategies, allowing users to retrieve a list of available strategies via the \/descriptors/workflow-activation-strategies\ endpoint. This addition introduces the \IWorkflowActivationStrategiesApi\ contract and the \WorkflowActivationStrategyDescriptor\ record, which exposes the strategy's type name, display name, and description.
src/clients/Elsa.Api.Client/Resources/WorkflowActivationStrategies · high confidence
Add client support for reporting task completion
The Elsa API client now includes the ability to report that a specific task has been completed. This change introduces the \ITasksApi\ interface and the \ReportTaskCompletedRequest\ model, allowing users to call the \/tasks/{taskId}/complete\ endpoint via the \ReportTaskCompletedAsync\ method.
src/clients/Elsa.Api.Client/Resources/Tasks · high confidence
Add copy adornment support for single-line input fields
The SingleLine input field now supports an optional copy adornment feature. A new SingleLineProps class introduces an EnableCopyAdornment property, allowing the UI to display a copy button for single-line text inputs when enabled, and an AdornmentText property for customizing the display text.
src/clients/Elsa.Api.Client/Shared/UIHints/SingleLine · high confidence
Add database persistence support for User Tasks across MySQL, Oracle, PostgreSQL, SQL Server, and SQLite
This change introduces the persistence layer for the User Tasks module, enabling workflows to store and retrieve human tasks in relational databases. The diff adds EF Core configuration, design-time factories, initial migrations, and shell features for five database providers: MySQL (targeting server version 9.0.0), Oracle, PostgreSQL, SQL Server, and SQLite (which defaults to a shared-cache file named elsia.sqlite.db if no connection string is provided). Each provider is registered as a distinct shell feature under the 'User Tasks' and 'Persistence' categories, allowing users to select their preferred database backend for task storage.
(repo-wide) · high confidence
Add optional Elsa Secrets bridge for External Authentication
This change introduces a new optional module that allows External Authentication secret bindings to be backed by Elsa Secrets. Users can now configure secret references using the resolver type \elsa-secrets\, pointing to an existing Elsa Secret name. The module provides a service registration (\AddElsaSecretsExternalAuthentication\) and a shell feature that wires up the \ElsaSecretBindingResolver\. This resolver manages the lifecycle of secrets (create, delete, resolve) within the Elsa Secrets store, ensuring that secret values are never exposed in management models and that rotations generate new fingerprints, invalidating in-flight transactions.
src/modules/Elsa.ExternalAuthentication.Secrets · high confidence
Add relational persistence layer for structured logs
This module introduces a provider-neutral relational storage backend for Elsa's diagnostics structured logs, enabling logs to be persisted in SQL databases. It includes the database schema (the \StructuredLogEvents\ table with indexes), a write buffer with background processing and configurable retention (max age/rows), and a SQL builder that supports filtering, sorting, and pagination. Concrete database providers (such as SQLite, SQL Server, or PostgreSQL) implement the connection factory and SQL dialect interfaces to wire this layer into the platform.
src/modules/Elsa.Diagnostics.StructuredLogs.Persistence.Relational · high confidence
Add shell reload API support
The client library now includes support for reloading application shells via new API endpoints. Users can trigger a reload for all shells or a specific shell using the new \IShellsApi\ interface methods (\ReloadAllAsync\ and \ReloadAsync\). The response models (\ShellReloadResponse\) and status enum (\ShellReloadStatus\) provide detailed feedback on the reload operation, including status indicators like Completed, Partial, Failed, Busy, NotFound, and RequestedShellFailed.
src/clients/Elsa.Api.Client/Resources/Shells · high confidence
Added API client for user login
The API client now includes support for authenticating users via a new login endpoint. This change introduces the necessary request and response models (LoginRequest and LoginResponse) and an interface (ILoginApi) that allows applications to send credentials to the /identity/login endpoint and receive authentication status along with access and refresh tokens.
src/clients/Elsa.Api.Client/Resources/Identity · high confidence
Added TestContainer activity for sequential child execution
A new \TestContainer\ class has been introduced in the shared testing utilities to provide a deterministic, sequential execution model for container activities. Unlike the standard container which may schedule children in parallel or based on complex logic, this implementation iterates through child activities one by one, ensuring they run in order. This aids in testing workflows where predictable, step-by-step execution is required.
src/common/Elsa.Testing.Shared/Activities · high confidence
Added bundled Lodash library to client-side distribution
The JavaScript client library for Elsa Expressions now includes a bundled version of Lodash (dist/lodash.js). This adds a comprehensive utility library to the browser-side runtime, enabling workflows and expressions to utilize Lodash functions for data manipulation and object handling without requiring external network requests or separate package imports.
src/modules/Elsa.Expressions.JavaScript.Libraries · high confidence
Added client API for testing workflow activities
The Elsa API client now includes support for the testing API, allowing users to programmatically test individual activities within a workflow. This change introduces the \ITestsApi\ interface with a \TestActivityAsync\ method that sends a \TestActivityRequest\ (containing workflow and activity handles) to the \/tests/activities\ endpoint and returns a \TestActivityResponse\ detailing the activity's state, payload, outputs, exception status, and execution status.
src/clients/Elsa.Api.Client/Resources/Tests · high confidence
Added client interface for listing activity descriptors
A new API client interface, IActivityDescriptorsApi, has been introduced to allow applications to retrieve activity descriptors from the server. This interface exposes a ListAsync method that maps to the GET /descriptors/activities endpoint, enabling users to fetch available activity definitions via the Elsa API client.
src/clients/Elsa.Api.Client/Resources/ActivityDescriptors/Contracts · high confidence
Added core data models for workflow alteration plans and jobs
Introduced the \AlterationPlan\ and \AlterationJob\ entity classes along with their corresponding status enums (\AlterationPlanStatus\ and \AlterationJobStatus\) to support the persistence and tracking of workflow alteration operations. These models define the structure for plans containing alterations and individual jobs executing those alterations against specific workflow instances, including fields for status, timestamps, and logs.
src/modules/Elsa.Alterations.Core/Entities, src/modules/Elsa.Alterations.Core/Enums · high confidence
Added custom JSON and type converters for numeric, boolean, and version types
New JSON converters have been introduced in the Elsa.Common module to handle serialization of specific data types with greater control: BigInteger, Decimal, Integer, Boolean, and Nullable Boolean. These converters ensure that numeric values and booleans can be correctly read from and written to JSON strings or numbers, addressing potential mapping issues (such as JavaScript BigInt limitations). Additionally, a new converter for VersionOptions allows versioning metadata to be serialized as either numeric IDs or string representations, and a corresponding TypeConverter supports string-based conversion for design-time or configuration scenarios.
src/modules/Elsa.Common/Converters · high confidence
Added glass.ai design asset
A new Adobe Illustrator design file named glass.ai has been added to the design/artwork directory. This vector graphic, created in Adobe Illustrator 26.5, serves as a visual asset for the project.
design/artwork · high confidence
Added no-op distributed locking implementation and configuration options
A new no-op implementation of the distributed locking infrastructure has been added to support single-host development and testing scenarios. This includes the NoopDistributedLock, NoopDistributedSynchronizationHandle, and NoopDistributedSynchronizationProvider classes, which satisfy the IDistributedLock interface without performing actual distributed coordination. Additionally, DistributedLockingOptions now exposes an AllowLocalLockProviderInDistributedRuntime flag, allowing users to suppress startup warnings when using local lock providers in distributed runtime configurations.
src/modules/Elsa.Common/DistributedHosting · high confidence
Added sample workflow definitions demonstrating the new Script DSL
The server now includes sample workflow files in the \src/apps/Elsa.Server.Web/Workflows\ directory that showcase the newly added Elsa Script DSL capabilities. These samples include \for-loop.elsa\, which demonstrates loop constructs and variable access using JavaScript and C\# expressions; \hello-world.elsa\ and \hello-world-http.elsa\, which provide basic text output and HTTP endpoint integration examples using the DSL; and \triggers.json\, a JSON-based workflow definition for an HTTP trigger. These files serve as reference implementations for users adopting the new scripting syntax.
src/apps/Elsa.Server.Web/Workflows · high confidence
Added security and quality architecture assessments for Elsa Workflows Core
New documentation files have been added to the \doc/security-assessment\ directory, providing static analysis-based assessments of the Elsa Workflows Core (v3.7.0) architecture, ISO 25010 software quality, and technology profile. These documents evaluate the framework's coverage of integration, processing, data management, reliability, security, and distributed systems patterns, highlighting both built-in capabilities (such as JWT authentication, bookmark-based async request-reply, and distributed locking) and areas requiring host-application implementation (such as external message broker integration, circuit breakers, and full-text search). The assessments are explicitly marked as AI-assisted drafts requiring human review before use in architectural decisions.
doc/security-assessment · high confidence
Adds module-based feature installation and topological dependency sorting
The Elsa Features extension library now provides a structured way to install and configure features via a new \IModule\ abstraction, allowing users to register features through \IServiceCollection\ and \IModule.Use\<T\>()\ methods while preventing duplicate installations. Additionally, a new topological sorting utility (\TSort\) is available for \IEnumerable\<T\>\, enabling the system to order feature dependencies correctly and optionally detect cyclic dependencies during the configuration phase.
src/common/Elsa.Features/Extensions · high confidence
Automated Elsa release announcements on Discord, LinkedIn, and X
The .agents directory now includes a new 'Elsa Release Announcements' skill that drafts and publishes verified release announcements to Discord, LinkedIn, and X. This skill provides a structured workflow for generating channel-specific copy (using Discord, LinkedIn, and X templates), managing publication state, and ensuring safe, resumable delivery. It includes helper scripts for posting to Discord (with embed suppression and crossposting) and managing Buffer connector receipts for LinkedIn and X, along with comprehensive tests to validate the announcement logic and state management.
.agents · high confidence
Automated generation of the ADR table of contents
A new script, scripts/adr/generate-toc.sh, has been added to automatically regenerate the Architecture Decision Records (ADR) table of contents (doc/adr/toc.md) from the individual ADR files. This eliminates the need for manual maintenance of the index, which previously drifted from the actual documents. The script supports a --check mode to verify that the table of contents is up to date without writing changes, ensuring consistency between the index and the ADR files.
scripts/adr · high confidence
BPMN interchange module introduces stable error codes and optimistic concurrency for document updates
The new Elsa.Bpmn.Interchange module provides endpoints to analyze, import, and export BPMN documents, featuring a structured authorization model and stable, machine-readable error codes for import and export refusals. Document updates now use optimistic concurrency control via ETags and If-Match headers to prevent lost updates, while the interchange format preserves non-BPMN metadata and ensures that unbound tasks are validated at publish time.
src/modules/Elsa.Bpmn.Interchange · high confidence
Core alteration services and extensibility registration
The Elsa alterations module now registers its core infrastructure services, including the workflow dispatcher, instance finder, and serializer, via the new AddAlterationsCore extension method. Additionally, a generic AddAlteration method is provided to allow users to register custom alteration handlers and their corresponding types, enabling the system to process specific workflow alterations.
src/modules/Elsa.Alterations.Core/Extensions · high confidence
Design documentation for provider-neutral persistence strategy
Added design documents outlining a proof-of-concept and roadmap for a new persistence layer where modules declare storage intent once and database providers handle physical schema materialization. The documentation details the proposed architecture, including provider-neutral descriptors and specific planning/rendering layers for relational and document databases, and establishes a phased migration strategy that prioritizes low-risk metadata and module stores while retaining specialized providers for high-throughput workflow runtime operations.
design · high confidence
Distributed workflow runtime with cluster-safe locking
This module introduces a distributed workflow runtime implementation designed for clustered deployments. It ensures that critical operations—such as running workflow instances, reloading or refreshing workflow definitions, and processing the bookmark queue—are protected by distributed locks, preventing race conditions and concurrent execution across multiple application nodes. A new lock provider validator runs at startup to warn if a local-only lock provider is detected in a distributed setup, and the runtime includes a resilient client with retry logic for lock acquisition.
src/modules/Elsa.Workflows.Runtime.Distributed · high confidence
Durable Entity Framework Core persistence for external authentication
The External Authentication module now supports a durable, cross-node persistence layer backed by Entity Framework Core. This replaces the previous in-memory stores with implementations that persist identity provider connections, external identity links, broker transactions, authorization grants, authentication sessions, and refresh tokens to the database. The change introduces a new \ExternalAuthenticationElsaDbContext\ and a set of EF Core stores (e.g., \EFCoreExternalAuthenticationStateStore\, \EFCoreExternalIdentityProvisioner\) that use a context lease factory to ensure singleton stores do not capture tenant-scoped services. Users can enable this behavior by calling \UseEntityFrameworkCore\ on the feature or \AddExternalAuthenticationEntityFrameworkCore\ on the service collection, ensuring that external authentication state survives application restarts and is consistent across multiple nodes.
src/modules/Elsa.ExternalAuthentication.Persistence.EFCore · high confidence
EF Core persistence for secrets now supports MySQL and SQL Server with tenant scoping
This change introduces Entity Framework Core persistence providers for the Secrets module, enabling storage in both MySQL and SQL Server databases. The database schema includes a new TenantId column, allowing secrets to be scoped to specific tenants. To enforce data integrity, the migrations implement a unique index on the combination of TenantId and NormalizedName, ensuring that secret names are unique within each tenant context. The update also includes migration logic to handle existing data by stamping null TenantIds with a default value and aborting if duplicate keys are detected, requiring operators to resolve conflicts before upgrading.
src/modules/Elsa.Secrets.Persistence.EFCore.MySql, src/modules/Elsa.Secrets.Persistence.EFCore.SqlServer · high confidence
EF Core persistence layer for Identity module
The Identity module now supports Entity Framework Core as a persistence provider. This change introduces EF Core implementations for the User, Application, and Role stores, along with the corresponding database context and entity configurations. Users can now opt into EF Core-based identity persistence, which manages tenant-scoped uniqueness for users, applications, and roles, and handles the storage of roles and permissions as string collections.
src/modules/Elsa.Persistence.EFCore/Modules/Identity, src/modules/Elsa.Persistence.EFCore/Modules/Labels · high confidence
EF Core persistence layer for workflow management restored
The Entity Framework Core persistence implementation for the workflow management module has been restored, bringing back the ability to store and retrieve workflow definitions and instances in a relational database. This change re-introduces the \ManagementElsaDbContext\ and associated configuration classes that define the database schema, including specific indexes for versioning, status, and tenant isolation. It also provides the \EFCoreWorkflowDefinitionStore\ and \EFCoreWorkflowInstanceStore\ implementations, allowing users to persist their workflow state using EF Core instead of alternative storage providers.
src/modules/Elsa.Persistence.EFCore/Modules/Management · high confidence
Elsa API Client initialization and core extension methods
The Elsa API Client library is now available for integration, providing a comprehensive set of extension methods and configuration utilities. This includes dependency injection helpers to register API clients with API key authentication, JSON serialization converters for types like VersionOptions, and utility extensions for handling JsonObject properties, dictionary lookups, and HTTP response headers.
src/clients/Elsa.Api.Client/Extensions · high confidence
Elsa Server Web host now supports distributed runtime, multitenancy, and configurable rate limiting
The Elsa.Server.Web reference host has been updated to enable a distributed workflow runtime and multitenancy by default, allowing it to coordinate across multiple instances and serve distinct tenants with separate HTTP prefixes and database connections. It now includes opt-in ingress rate limiting for both the management API and HTTP workflow triggers, configurable via the IngressRateLimiting section. The host also registers a sample activity host (Penguin) to demonstrate custom activity hosting, uses SQLite as the default persistence provider, and configures specific timings for workflow inactivity, bookmark queue purging, and restart of interrupted workflows.
src/apps/Elsa.Server.Web · high confidence
Expanded API client model definitions for workflow graph and activity management
The API client now includes a comprehensive set of new model classes to support advanced workflow graph operations and activity handling. This adds models for activity designer metadata (position and size), hierarchical activity nodes with parent/child traversal, and connection endpoints with support for graph vertices. It also introduces models for activity outputs with converter configurations, dynamic outcomes, switch cases, and HTTP status code handling. Additionally, the update brings in foundational entities like versioned entities with publication status, generic list and paged responses with HATEOAS links, and utility models such as property bags for non-polymorphic data transfer and timestamp filters for enhanced workflow instance queries.
src/clients/Elsa.Api.Client/Shared/Models · high confidence
Expanded API client models for workflow definitions and execution
The API client now includes a comprehensive set of new models to support advanced workflow definition management and execution. Users can now bulk export workflow definitions with an option to include consuming workflows, and import workflow files with response tracking. The client exposes detailed definitions for workflow inputs, outputs, and variables, including UI hints and storage driver types. New models support activity testing via \ActivityHandle\ and \ExecuteResponse\, and introduce \WorkflowCommitStateOptions\ to configure when workflow state is committed (starting, executing, or executed). Additionally, the client now supports read-only workflows, tracks the tool version that created definitions, and provides handles for referencing workflow definitions by ID or version.
src/clients/Elsa.Api.Client/Resources/WorkflowDefinitions/Models · high confidence
Expanded API client request models for workflow definition management
The API client now includes a comprehensive set of request models for managing workflow definitions, enabling bulk operations and more granular control. Users can now perform bulk delete and bulk publish/retract actions on multiple workflow definitions or versions simultaneously. New request types support executing and dispatching workflows with optional inputs, correlation IDs, and specific version targeting. The list workflow definitions request has been enhanced with filtering capabilities, including search terms, labels, materializer names, and system workflow inclusion, alongside pagination and ordering. Additionally, saving a workflow definition now supports an optional flag to publish it immediately, and a new request allows updating references in consuming workflows to point to the latest version of a definition.
src/clients/Elsa.Api.Client/Resources/WorkflowDefinitions/Requests · high confidence
Expanded Workflow Definitions API client with execution, bulk operations, and export/import capabilities
The API client for workflow definitions has been significantly expanded to support new operational workflows. Users can now execute or dispatch workflows directly via the new \IExecuteWorkflowApi\ interface. The \IWorkflowDefinitionsApi\ interface now includes methods for bulk publishing, retracting, and deleting definitions and versions, as well as exporting and importing definitions (including recursive export of consuming workflows). Additional utility endpoints for counting definitions, validating unique names, retrieving subgraphs, and identifying consuming workflows are also now available in the client.
src/clients/Elsa.Api.Client/Resources/WorkflowDefinitions/Contracts · high confidence
Expanded workflow instance filtering and bulk management capabilities
The API client now supports more granular querying and management of workflow instances. Users can filter workflow lists by multiple statuses, multiple definition IDs, and whether instances have incidents, in addition to existing filters like search terms and correlation IDs. A new bulk cancellation request allows cancelling multiple instances at once, specifying instance IDs, definition IDs, and version options. Journal records can now be filtered by activity IDs, activity node IDs, excluded activity types, and event names via a dedicated filter object.
src/clients/Elsa.Api.Client/Resources/WorkflowInstances/Requests · high confidence
Git branching workflow extension with auto-commit hooks
The Specify tool now includes a bundled Git extension that automates repository initialization, feature branch creation (with sequential or timestamp numbering), branch validation, and remote detection. It also introduces configurable auto-commit hooks that can stage and commit changes before or after core workflow steps like specification, planning, and implementation, with behavior controlled via \.specify/extensions/git/git-config.yml\.
.specify · high confidence
Initial implementation of the Alterations module feature
The Alterations module is now available, providing a system for managing and executing workflow alterations. This feature registers core services such as the alteration plan manager, job dispatcher, and schedulers, while supporting both in-memory and custom persistence stores for alteration plans and jobs. It also integrates with the workflow engine by adding the \ExecuteAlterationPlanWorkflow\ and configures serialization aliases for alteration parameters.
src/modules/Elsa.Alterations/Features · high confidence
Introduce Alterations module for workflow modifications
The new Alterations module allows workflows to be modified at runtime through a set of registered handlers. This location registers the core alteration types and their corresponding handlers, including Migrate, ModifyVariable, ScheduleActivity, CancelActivity, and Cancel, making them available for use in workflow definitions.
src/modules/Elsa.Alterations/Extensions · high confidence
Introduce Alterations shell feature for modifying running workflows
The Alterations module now registers as a dedicated shell feature that provides capabilities for modifying running workflow instances. This feature declares dependencies on the FastEndpoints and WorkflowRuntime features, configures serialization aliases for alteration plan parameters, and registers the core services for managing alteration plans, jobs, and runners (including default in-memory stores and background dispatchers). It also registers the ExecuteAlterationPlan workflow, enabling users to define and execute alterations against active workflows.
src/modules/Elsa.Alterations/ShellFeatures · high confidence
Introduce C\# expression evaluation for workflows
Workflows can now evaluate C\# expressions using the Roslyn scripting engine. This adds a new 'Run C\#' activity and a C\# expression handler, allowing users to write and execute C\# code within workflow steps. The feature includes proxies to access workflow variables, inputs, and activity outputs, and supports dot notation for ExpandoObject (JSON) variables. By default, host-code execution is disabled for security; administrators must explicitly enable it via the \AllowHostCodeExecution\ option in \CSharpOptions\.
src/modules/Elsa.Expressions.CSharp · high confidence
Introduce CheckList UI hint model for multi-select inputs
The API client now includes a dedicated CheckList UI hint model, allowing users to define multi-select input fields with multiple options. This change adds the CheckList record to hold the list of items and a flags enum indicator, the CheckListItem class to define individual option text, value, and selection state, and the CheckListProps class to expose the checklist configuration within the broader UI hint system.
src/clients/Elsa.Api.Client/Shared/UIHints/CheckList · high confidence
Introduce EF Core persistence for identity-neutral User Tasks
The \Elsa.UserTasks.Persistence.EFCore\ module now provides a relational persistence layer for the identity-neutral User Tasks feature. This implementation introduces a new database schema with tables for tasks, candidates, exclusions, events, operations, and invitations, along with EF Core entity configurations and migrations. It registers the \EFCoreUserTaskRepository\ as the primary store and replaces in-memory defaults for guest session issuance and invitation delivery outboxes with durable, encrypted storage to ensure secrets survive restarts and failovers.
src/modules/Elsa.UserTasks.Persistence.EFCore, src/modules/Elsa.UserTasks.Persistence.VNext · high confidence
Introduce Elsa-specific FastEndpoints shell feature
A new shell feature, ElsaFastEndpointsFeature, has been added to register the Elsa FastEndpoints configurator and integrate the authorization and permission models. This feature depends on the core CShells FastEndpointsFeature and ensures that Elsa's specific serialization settings and permission descriptors are applied when the shell is enabled.
src/common/Elsa.Api.Common/ShellFeatures · high confidence
Introduce ElsaScript DSL for defining workflows via code
This change adds the ElsaScript DSL module, providing a new way to define workflows using a C\#-like syntax instead of the visual designer or JSON. The diff introduces a complete Abstract Syntax Tree (AST) in the \Elsa.Dsl.ElsaScript.Ast\ namespace, including nodes for statements (if, for, foreach, while, switch), expressions, flowcharts, and activity invocations. It also includes the \ElsaScriptCompiler\ which parses this source code and compiles it into Elsa \Workflow\ objects, allowing developers to write workflow logic programmatically with support for variables, expressions, and flowchart structures.
src/modules/Elsa.Workflows.Core · high confidence
Introduce Entity Framework Core persistence for the Secrets module
The Secrets module now supports storing secrets in a relational database via Entity Framework Core. This change adds a new persistence layer that registers the \EFCoreSecretRepository\ and associated services, defines the \SecretsElsaDbContext\ with a unique index on \TenantId\ and \NormalizedName\ to enforce per-tenant name uniqueness, and handles serialization of complex properties like tags and versions. Users can enable this backend by calling \UseEntityFrameworkCore\ on the secrets feature, allowing secrets to be persisted alongside other Elsa data rather than relying solely on in-memory or file-based storage.
src/modules/Elsa.Secrets.Persistence.EFCore · high confidence
Introduce FeatureBase abstraction for feature configuration
A new FeatureBase abstract class has been added to the Elsa Features abstractions layer, providing a standardized base type for implementing features. This class implements the IFeature interface and exposes the containing module and service collection, while defining virtual lifecycle methods (Configure, ConfigureHostedServices, Apply) that derived feature classes can override to register services and hosted services.
src/common/Elsa.Features/Abstractions · high confidence
Introduce Persistence vNext provider-neutral schema and runtime entity foundations
This change adds the initial scaffolding for the Persistence vNext architecture, establishing a provider-neutral schema model and runtime entity management. It introduces a schema catalog that aggregates persistence providers and validates for duplicate tables or storage units, alongside a startup task that materializes the schema across configured document stores (with support for MongoDB and PostgreSQL dialects). Additionally, it adds a runtime entity subsystem featuring a definition/instance model with audit logging, a persistence evaluator to guide migration decisions based on workload characteristics, and service registrations to wire these components into the application.
(repo-wide) · high confidence
Introduce Python expression evaluation for workflows
This change adds a new Python expression capability to the platform, allowing users to evaluate Python code within workflow expressions and activities. The module introduces a 'Run Python' activity and a Python expression handler that leverages Python.NET to execute scripts. To address security concerns regarding unsandboxed host-code execution, the feature is disabled by default; users must explicitly enable it via the \AllowHostCodeExecution\ option in \PythonOptions\. When enabled, the evaluator provides access to workflow inputs, outputs, variables, and outcomes through dedicated proxy objects (InputProxy, OutputProxy, ExecutionContextProxy, OutcomeProxy) injected into the Python scope.
src/modules/Elsa.Expressions.Python · high confidence
Introduce User Tasks module for workflow-bound human tasks
The new User Tasks module enables workflows to pause and wait for human interaction through a dedicated \UserTask\ activity. This activity creates a task with configurable properties such as title, assignee, candidates, due dates, and custom actions, then suspends the workflow until a human completes, cancels, or times out the task. The module provides a comprehensive API surface for managing these tasks, including listing, claiming, assigning, completing, and revoking guest invitations. It supports structured permissions, tenant isolation, and identity resolution, with background workers handling due-date sweeps, projection reconciliation, and invitation delivery. The implementation includes in-memory defaults for repositories and guest sessions, allowing for easy integration and testing while supporting pluggable persistence providers.
src/modules/Elsa.UserTasks · high confidence
Introduce VNext secrets persistence provider with tenant isolation safeguards
A new persistence implementation for secrets is available via the \Elsa.Secrets.Persistence.VNext\ module, which stores secret documents in a generic document store keyed by secret name. This provider is designed for single-tenant deployments; it actively prevents multitenancy by throwing a \NotSupportedException\ if a non-default tenant context is detected, ensuring that secrets are not inadvertently shared across tenants. The module registers the \VNextSecretRepository\ and defines the underlying schema for secret storage, including fields for name, type, scope, and status.
src/modules/Elsa.Secrets.Persistence.VNext · high confidence
Introduce Weaver AI Copilot with structured agent, grounding, and tooling capabilities
This change introduces the core infrastructure for the Weaver AI Copilot within the Elsa AI Host module. It establishes a new set of abstractions for AI providers, conversations, proposals, and tools, enabling the system to interact with AI models. The host now supports structured authorization for AI agents, allowing specific permissions to be required for agent execution. It also introduces 'grounding' capabilities, which allow the AI to access and reason about workflow definitions, instances, and activities. Additionally, a suite of tools is provided for searching activities, managing workflow proposals, and inspecting runtime instances, all exposed via new API endpoints for chat, capabilities, and tools.
src/modules/Elsa.AI.Host · high confidence
Introduce common service implementations for compression, JSON formatting, memory storage, and system clock
This change adds new concrete service implementations to the common services module, providing foundational capabilities for the platform. Users gain access to a CompressionCodecResolver for managing compression algorithms, a JsonFormatter for serializing and deserializing data using System.Text.Json with enum string conversion, a thread-safe MemoryStore for in-memory entity persistence with concurrent dictionary support, and a SystemClock abstraction for consistent time handling. These services are now available for dependency injection within the Elsa.Common.Services namespace.
src/modules/Elsa.Common/Services · high confidence
Introduce core abstractions and filtering for the Alterations module
The Elsa.Alterations.Core module now provides the foundational infrastructure for managing workflow alterations, including abstract base classes for alterations and their handlers, configuration options, and query filters for alteration jobs and plans. Users can now define custom alteration types and handlers via the new \AlterationBase\ and \AlterationHandlerBase\ classes, while the \AlterationJobFilter\ and \AlterationPlanFilter\ classes enable querying these entities by ID, plan ID, and status. The module also introduces \RunAlterationsResult\ to report the outcome of alteration runs, including success status and execution logs.
(repo-wide) · high confidence
Introduce dedicated serialization for workflow alterations
The system now includes a dedicated serializer for workflow alterations, enabling proper JSON serialization and deserialization of alteration objects. This change introduces polymorphic serialization support, allowing different alteration types to be correctly identified and handled during workflow persistence and retrieval. Users will benefit from more reliable handling of alteration data in serialized workflows, ensuring that specific alteration types are preserved and restored accurately.
src/modules/Elsa.Alterations.Core/Serialization · high confidence
Introduce in-memory caching infrastructure
The Elsa.Caching module now provides a dedicated in-memory caching layer. This change introduces a centralized cache manager and a change-token signaling system, allowing components to cache data and react to invalidations. Users can enable this feature via the \UseMemoryCache\ extension method, which registers the necessary services for memory-based caching and token-based change notifications.
src/modules/Elsa.Caching · high confidence
Introduce shell-based feature discovery and registry abstractions
The features module now supports automatic discovery of features from shell descriptors via the new \ShellInstalledFeatureProvider\, which maps shell feature metadata to Elsa's \FeatureDescriptor\ model. This is complemented by new \IInstalledFeatureProvider\ and \IInstalledFeatureRegistry\ interfaces that separate read-only discovery from write-capable registration, alongside \IFeature\ and \IModule\ interfaces that define the feature lifecycle and service configuration model.
src/common/Elsa.Features/Services · high confidence
Introduce structured log diagnostics module with live streaming and REST API
A new diagnostics module captures structured ILogger events, providing a REST API for recent logs and source lists, plus a SignalR hub for live log streaming to Studio. The module includes an in-memory store with a bounded ring buffer, automatic redaction of sensitive values, and storage diagnostics reporting.
src/modules/Elsa.Diagnostics.StructuredLogs · high confidence
Introduces Entity Framework Core persistence for AI conversations, proposals, and audit records
The Elsa AI module now supports storing AI conversation history, workflow proposals, and audit events in a relational database via Entity Framework Core. This change adds the \AIDbContext\ and corresponding entity models (\AIConversationRecord\, \AIProposalRecord\, \AIAuditRecord\) along with EF Core-specific store implementations (\EFCoreAIConversationStore\, \EFCoreAIProposalStore\, \EFCoreAIAuditSink\). It also includes a background service (\EFCoreAIConversationCleanupService\) that automatically deletes expired conversations based on retention policies, with specific handling for SQLite compatibility. Users can enable this persistence by registering the \AIPersistenceFeature\ or calling \AddAIPersistenceStores\ with their database configuration.
src/modules/Elsa.AI.Persistence.EFCore · high confidence
Introduces a comprehensive multitenancy framework with tenant lifecycle management and isolation
This change adds a new multitenancy module to Elsa.Common, providing the core infrastructure for managing multiple tenants within the application. It introduces a tenant resolution strategy (ITenantResolver) and an ambient tenant accessor (ITenantAccessor) that uses AsyncLocal storage to propagate the current tenant context across operations. The module includes a DefaultTenantService that manages the lifecycle of tenants, handling activation, deactivation, and deletion events, and ensures that startup, background, and recurring tasks are coordinated per tenant. Additionally, it provides TenantVisibility helpers to enforce data isolation in memory-based stores, ensuring that entities are only visible to their owning tenant or are accessible as agnostic (\*).
src/modules/Elsa.Common/Multitenancy · high confidence
Introduces a new Mediator package with command, request, and notification patterns
The \Elsa.Mediator\ library has been introduced, providing a reusable mediator implementation that supports sending requests, executing commands, and publishing notifications. This change adds a new architectural component featuring a middleware pipeline for commands and notifications, background processing via hosted services for jobs and commands, and dependency injection extensions to register handlers and channels. Users can now decouple background command execution from caller cancellation tokens and configure worker counts for background processing.
src/common/Elsa.Mediator · high confidence
Introduces configurable resilience and retry tracking for workflow activities
The Elsa.Resilience.Core module now provides a framework for applying resilience strategies to workflow activities. Users can define strategies via identifiers or expressions, and the system automatically detects transient exceptions (such as network timeouts or database errors) to trigger retries. When retries occur, the system records detailed attempt metadata (including delays and outcomes) and exposes a flag in the execution context, enabling better visibility into retry behavior within the workflow designer.
src/modules/Elsa.Resilience.Core · high confidence
Introduces new expression and memory model classes
This change adds a set of new model classes to the Elsa.Expressions module to support expression handling and memory management. The new files include Brackets for defining bracket pairs, Expression for representing literal and delegate expressions, and ExpressionDescriptor for describing expression types and their serialization behavior. It also introduces ExpressionExecutionContext to provide the context in which expressions are evaluated, including access to services and memory. The memory system is modeled with MemoryBlock for storing values and metadata, MemoryBlockReference for referencing these blocks, and MemoryRegister for managing the collection of blocks. Additionally, Literal and ObjectLiteral classes are added to represent constant values and JSON literals respectively, and ExpressionEvaluatorOptions allows for configuring extra variables in the expression context.
src/modules/Elsa.Expressions/Models · high confidence
Introduction of Alteration Context for Workflow State Modifications
The system now provides a dedicated context object for handling workflow alterations, enabling more structured and observable state changes. This context exposes the current workflow execution state, a cancellation token, and a service provider, allowing alteration handlers to interact deeply with the running workflow. It introduces explicit success and failure states, ensuring that alterations are properly tracked, and includes a logging mechanism that records events and messages directly to an alteration log, improving visibility into how and why workflow states are modified.
src/modules/Elsa.Alterations.Core/Contexts · high confidence
Introduction of ExpressionOptions for type alias configuration
A new ExpressionOptions class has been added to the Elsa.Expressions module to centralize the configuration of type aliases used within the expression system. This class initializes a predefined set of aliases for common .NET types (such as Int32, String, Boolean, DateTime, and various JSON-related types like JsonElement and JsonNode) and exposes a RegisterTypeAlias method, allowing users to extend or customize how specific types are referenced and resolved in expressions.
src/modules/Elsa.Expressions/Options · high confidence
Introduction of common entity base classes and ordering types
The \Elsa.Common.Entities\ module now provides foundational types for domain modeling, including \Entity\ (with \Id\ and optional \TenantId\), \ManagedEntity\ (adding \CreatedAt\, \UpdatedAt\, and \Owner\), and \VersionedEntity\ (adding \CreatedAt\, \Version\, \IsLatest\, and \IsPublished\). Additionally, \OrderDefinition\<T, TProp\>\ and the \OrderDirection\ enum are introduced to support structured query sorting.
src/modules/Elsa.Common/Entities · high confidence
JavaScript expressions now support dynamic outcome branching and provide TypeScript intellisense
The JavaScript expression module now allows scripts executed via the 'Run JavaScript' activity to control workflow branching by calling the new \setOutcome()\ and \setOutcomes()\ functions, which set the activity's completion outcome dynamically. Additionally, the module introduces a new endpoint that generates TypeScript definition files for the Monaco editor, enabling intellisense and type checking for JavaScript expressions within the workflow designer.
src/modules/Elsa.Expressions.JavaScript · high confidence
Liquid expression evaluation is now available for workflow templates
This change introduces the Elsa.Expressions.Liquid module, enabling users to evaluate Liquid templates as expressions within workflows. It provides a new Liquid expression type, a template manager with caching, and built-in filters for Base64 encoding and extracting dictionary keys. The implementation allows templates to access workflow variables, activity inputs, and configuration data (when explicitly enabled), and registers the feature under the 'Expressions' and 'Scripting' categories.
src/modules/Elsa.Expressions.Liquid · high confidence
Modular server now supports dynamic package loading and assembly cataloging
The ModularServer.Web application now integrates the Nuplane package loader, enabling the runtime discovery and loading of external packages from a local directory. This introduces a new assembly catalog API (endpoints like /catalog/packages and /catalog/plugins) that exposes loaded assemblies and discovered plugin types to consumers. The server also registers a sample plugin package (Elsa.SamplePackage) to demonstrate the feature, and configures OpenTelemetry diagnostics for the new loading lifecycle.
src/apps/Elsa.ModularServer.Web · high confidence
Multi-tenant HTTP routing with configurable tenant resolution
The Elsa.Tenants.AspNetCore module now provides multi-tenant HTTP routing capabilities. This includes a middleware that initializes the tenant scope for each request and adjusts the request path base based on the tenant's route prefix. Tenants can be resolved via HTTP headers (defaulting to 'X-Tenant-Id'), the request host, or a route prefix in the URL. The module also registers services to generate tenant-specific endpoint routes and base paths, ensuring that HTTP workflows are correctly isolated and routed per tenant.
src/modules/Elsa.Tenants.AspNetCore · high confidence
MySQL persistence support added to Elsa
The system now supports MySQL as a database provider for its Entity Framework Core persistence layer. This change introduces the \Elsa.Persistence.EFCore.MySql\ module, which includes design-time DbContext factories for the Identity, Management, Runtime, Labels, Alterations, and Tenants modules, along with the necessary EF Core configuration extensions. It also provides the initial database migrations and model snapshots for these contexts, enabling users to store and manage workflows, identities, and tenant data in a MySQL database.
src/modules/Elsa.Persistence.EFCore.Sqlite · high confidence
New API client enums for log persistence and workflow definition sorting
The API client now exposes two new enumeration types to support recent backend capabilities. LogPersistenceMode allows clients to specify how log records are stored (Inherit, Include, or Exclude), aligning with the new log storage levels. OrderByWorkflowDefinition provides sorting options for workflow definitions by Created date, Name, or Version, enabling more flexible list queries.
src/clients/Elsa.Api.Client/Resources/WorkflowDefinitions/Enums · high confidence
New API client for external authentication descriptors
The client now exposes a dedicated API interface to query runtime descriptors for external authentication components. Users can programmatically retrieve lists of available adapters, policies, permission grant sources, and permissions (including the new two-axis resource/verb model for permissions). This enables applications to dynamically discover and configure external authentication settings based on the installed extension catalogs.
src/clients/Elsa.Api.Client/Resources/ExternalAuthentication/Descriptors · high confidence
New API client models for activity descriptors
The API client now includes a new set of models in the \ActivityDescriptors\ namespace to represent activity metadata retrieved from the server. This introduces \ActivityDescriptor\ to describe activity types (including properties like \IsStart\, \IsTerminal\, \IsContainer\, and \ConstructionProperties\), \InputDescriptor\ and \OutputDescriptor\ for property details (supporting features like \IsSensitive\ for secure inputs and \UIHint\ for UI rendering), \Port\ for defining activity connectivity, and a base \PropertyDescriptor\. These models enable the client to accurately reflect activity structure, input/output definitions, and UI hints provided by the Elsa API.
src/clients/Elsa.Api.Client/Resources/ActivityDescriptors/Models · high confidence
New API client models for activity execution tracking and reporting
The Elsa API client now includes a new set of models and request types under the ActivityExecutions resource, enabling users to query detailed execution logs, summaries, and statistics for workflow activities. This addition introduces \ActivityExecutionRecord\ for full execution details (including state, faults, and call stack depth), \ActivityExecutionRecordSummary\ for lightweight views, \ActivityExecutionCallStack\ for tracing execution chains, and \ActivityExecutionStats\/\ActivityExecutionReport\ for aggregated performance metrics. Request classes \ListActivityExecutionsRequest\ and \GetActivityExecutionReportRequest\ allow filtering these records by workflow instance and specific activity node IDs.
src/clients/Elsa.Api.Client/Resources/ActivityExecutions/Models · high confidence
New API client resources for storage drivers and variable types
The API client now includes dedicated contracts, models, and responses for querying storage drivers and variable types. Users can call the new \IStorageDriversApi\ to list available storage drivers (including their type name, display name, priority, and deprecation status) via the \/descriptors/storage-drivers\ endpoint, and use \IVariableTypesApi\ to list variable types (including category and description) via the \/descriptors/variables\ endpoint.
src/clients/Elsa.Api.Client/Resources/StorageDrivers · high confidence
New API endpoint to list installed system features
A new GET endpoint at /features/installed has been added to the Workflows API, allowing users to retrieve a list of currently installed features. This endpoint requires the SystemFeatures:View permission and returns a list of FeatureDescriptors, providing visibility into the system's feature configuration.
src/modules/Elsa.Workflows.Api/Endpoints/Features/List · high confidence
New API endpoint to retry faulted workflow activities
A new REST endpoint at /alterations/workflows/retry has been added, allowing users to retry one or more workflow instances that have encountered faults. The endpoint accepts a list of workflow instance IDs and an optional list of specific activity IDs; if no specific activities are provided, it automatically targets all activities with incidents (faults) within those instances. Upon execution, it runs the necessary alterations to clear the faults and dispatches the updated workflow instances for continued execution.
src/modules/Elsa.Alterations/Endpoints/Workflows · high confidence
New API endpoints for activity execution logs, bookmarks, and workflow features
The Workflows API now exposes several new endpoints to enhance observability and management capabilities. Users can retrieve detailed activity execution logs, including summaries, counts, and call stacks, via the new /activity-executions endpoints. A new /bookmark-queue/dead-letters API allows administrators to list, view, delete, and replay dead-lettered bookmark queue items. Additionally, the API provides endpoints to list installed system features (/features/installed) and retrieve activity descriptor options (/descriptors/activities/{activityTypeName}/options/{propertyName}), while the bookmark resume endpoint now supports asynchronous resumption via a queue.
src/modules/Elsa.Workflows.Api · high confidence
New API response models and credential validation result
The API now includes new model classes to standardize response formats: \CountResponse\ for single counts, \ListResponse\<T\>\ for generic item lists, and \PagedListResponse\<T\>\ for paginated results which also supports HATEOAS-style links via the new \LinkedResource\ and \Link\ records. Additionally, a \ValidateCredentialsResult\ record has been added to provide a structured way to return authentication validation outcomes.
src/common/Elsa.Api.Common/Models · high confidence
New Activity Executions API client with call stack support
The Elsa API client now includes a dedicated client for querying activity execution data, enabling users to retrieve execution reports, list activity executions and summaries, fetch individual execution records by ID, and inspect the execution call stack (including optional cross-workflow chains) for debugging and monitoring purposes.
src/clients/Elsa.Api.Client/Resources/ActivityExecutions/Contracts · high confidence
New Alteration Plan execution workflow and activities
Users can now define and execute alteration plans through a new system workflow and associated activities. The \ExecuteAlterationPlanWorkflow\ orchestrates the process by submitting a plan, generating jobs for matching workflow instances, and conditionally dispatching those jobs or completing the plan immediately if no jobs are generated. This is supported by new activities: \SubmitAlterationPlan\ to create the plan, \GenerateAlterationJobs\ to identify and create jobs for affected instances, \DispatchAlterationJobs\ to execute the jobs, \CompleteAlterationPlan\ to mark the plan as finished, and \AlterationPlanCompleted\ to trigger upon completion.
src/modules/Elsa.Alterations/Activities · high confidence
New Alterations API client library
The client library now includes a new \IAlterationsApi\ interface and supporting models to interact with the Alterations feature. This allows users to retrieve alteration plans, dry-run filters to see which workflow instances would be affected, submit and run alteration plans, and perform bulk retries on workflow instances with incidents. The implementation uses \JsonObject\ for alterations and includes enums for activity and plan statuses.
src/clients/Elsa.Api.Client/Resources/Alterations · high confidence
New Alterations API endpoints for planning, dry-running, and executing workflow changes
The Alterations module now exposes a set of new API endpoints that allow users to manage workflow instance alterations through a structured plan. Users can submit alteration plans via POST /alterations/submit, preview which instances would be affected without executing changes via POST /alterations/dry-run, retrieve the status and details of a specific plan via GET /alterations/{id}, and manually execute a plan via POST /alterations/run. These endpoints include input validation for timestamp filters and require specific permissions to execute or view alteration plans.
src/modules/Elsa.Alterations/Endpoints/Alterations · high confidence
New AuthorizeFlow activity for flow-level authorization
A new AuthorizeFlow activity has been added to the Elsa.Server.Web module, enabling workflows to pause execution and require explicit user authorization before proceeding. When this activity runs, it generates a unique bookmark trigger URL and redirects the user to it; the workflow resumes with an 'Authorized', 'Unauthorized', or 'Error' outcome based on the user's response, allowing for secure, interactive permission checks within flowcharts.
src/apps/Elsa.Server.Web/Activities · high confidence
New Blob Storage workflow provider with extensible format handling
The Elsa platform now includes a new \Elsa.WorkflowProviders.BlobStorage\ module that allows workflow definitions to be loaded from any storage backend compatible with FluentStorage (such as local directories, Azure Blob Storage, or AWS S3). This provider automatically scans the configured storage for workflow files and uses an extensible handler system to parse them; it currently includes a built-in handler for JSON-formatted workflows. Administrators can configure the storage source and register custom format handlers to support additional file types, enabling flexible, file-based workflow deployment without requiring a database.
src/modules/Elsa.WorkflowProviders.BlobStorage · high confidence
New BpmnProcess activity for executing BPMN scopes
The Elsa.Bpmn module now includes a BpmnProcess activity that acts as a container for executing a BPMN process definition. This activity hosts the BPMN interpreter, manages the lifecycle of the process scope (including start, completion, and cancellation), and handles the mapping of BPMN elements to Elsa workflow activities via work bindings. It supports triggers for message, signal, and timer start events, and exposes Done and Cancelled outcomes as explicit flow ports to control downstream execution paths.
src/modules/Elsa.Bpmn · high confidence
New Docker infrastructure for .NET 10.0, OpenTelemetry, and multi-database support
The project now provides a complete set of Dockerfiles and compose configurations to run Elsa Server and Studio on .NET 10.0. The standard images include Python 3.11 support and CA certificates for secure HTTPS connections. A new Datadog-enabled image (\ElsaServer-Datadog.Dockerfile\) and associated compose file (\docker-compose-datadog+otel-collector.yml\) introduce OpenTelemetry auto-instrumentation and tracing via a Datadog agent. The \docker-compose.yml\ has been expanded to include services for PostgreSQL, SQL Server, MySQL, Oracle, MongoDB, RabbitMQ, Redis, and an SMTP mock server, allowing for easy local development with various database backends.
docker · high confidence
New EF Core persistence layer for workflow runtime components
The EF Core module now provides a complete persistence implementation for the workflow runtime, introducing dedicated stores for activity execution logs, bookmarks, bookmark queues (including a new dead-letter store for failed items), and workflow triggers. This change includes a new \RuntimeElsaDbContext\ and entity configurations that define database schemas with specific indexes for performance, such as unique constraints on triggers to prevent duplicate registrations in multi-engine environments. Additionally, workflow commit operations are now wrapped in ambient transactions to ensure atomicity, and the execution log store defaults to ordering by timestamp and sequence for consistent log retrieval.
src/modules/Elsa.Persistence.EFCore/Modules/Runtime · high confidence
New Elsa Platform Integration module for automated recipe deployment
A new integration module has been added to enable the Elsa runtime to receive and apply deployment commands from the Elsa Platform. This introduces a background worker that polls for runtime commands (such as Deploy and Rollback), downloads Loom recipe artifacts, and applies them to the local environment. The module includes configuration options for the Platform endpoint, workspace, and engine credentials, along with services to manage shell configuration overlays and workflow definition imports. It also defines the data models and API client required to communicate with the Platform's deployment endpoints.
src/modules/Elsa.Platform.Integration · high confidence
New Elsa module registration and activity pipeline configuration extensions
Developers can now register the Elsa module and configure its features using the new \AddElsa\ and \ConfigureElsa\ extension methods on \IServiceCollection\, which handle module creation and application. Additionally, a new \ConfigureDefaultActivityExecutionPipeline\ extension on \IServiceProvider\ allows for direct configuration of the default activity execution pipeline.
src/modules/Elsa/Extensions · high confidence
New HTTP activities and extensible content handling
The HTTP module introduces several new workflow activities: DownloadHttpFile for fetching files from URLs, WriteFileHttpResponse for serving files (including resumable downloads and zipped archives), and updated SendHttpRequest/FlowSendHttpRequest activities that support status-code-based outcomes. It also adds an extensible content handling system via IHttpContentFactory and base classes like DownloadableContentHandlerBase and HttpCorrelationIdSelectorBase, allowing users to customize how HTTP request/response bodies are parsed and written.
src/modules/Elsa.Http · high confidence
New Incident Strategies API client
Added a new client interface and model for the Incident Strategies resource, enabling users to list available incident strategies via the \/descriptors/incident-strategies\ endpoint. The \IIncidentStrategiesApi\ interface exposes a \ListAsync\ method that returns a list of \IncidentStrategyDescriptor\ objects, each containing the strategy's type name, display name, and optional description.
src/clients/Elsa.Api.Client/Resources/IncidentStrategies · high confidence
New Labels module with REST API and tenant isolation
This change introduces the Elsa Labels module, enabling users to create, view, update, and delete labels and associate them with workflow definitions via new REST endpoints (e.g., /labels, /workflow-definitions/{id}/labels). The module enforces per-tenant isolation in its in-memory stores, ensuring labels are scoped to the current tenant, and supports filtering workflow definitions by label. It also includes cascading deletion, automatically removing label associations when a workflow definition is deleted.
src/modules/Elsa.Labels · high confidence
New ObjectConverter and ObjectFormatter helpers for expression evaluation
Added ObjectConverter and ObjectFormatter helpers in the Elsa.Expressions module to improve how expression values are converted and displayed. ObjectConverter provides robust type conversion strategies, including support for JsonElement, JsonNode, ExpandoObject, and date-like types, with options for strict mode and custom serializer settings. ObjectFormatter ensures arrays and collections are serialized to JSON strings rather than default type names, and handles byte arrays and memory-like types correctly.
src/modules/Elsa.Expressions/Helpers · high confidence
New OpenTelemetry diagnostics module for ingestion and live querying
The Elsa platform now includes a new OpenTelemetry diagnostics module that enables the ingestion of traces, metrics, and logs via OTLP HTTP (Protobuf) and gRPC collectors, with configurable API key authentication and loopback bypass. The module provides an in-memory store with configurable capacity limits for traces, spans, metrics, and logs, and exposes REST endpoints for searching and retrieving these telemetry signals. A real-time live feed is available via a SignalR hub, allowing clients to subscribe to telemetry updates as they arrive. The feature is gated by a new 'diagnostics/opentelemetry' permission, requiring users to have View access to search traces, logs, metrics, and resources.
src/modules/Elsa.Diagnostics.OpenTelemetry · high confidence
New REST API endpoints for reloading application shells
This change introduces new API endpoints that allow administrators to reload application shells via HTTP. Specifically, a POST to /shells/{shellId}/reload triggers a reload for a specific shell, while POST to /shells/reload attempts to reload all active shells. Both endpoints require the 'reload' permission on the 'system/shells' resource. The API returns structured responses indicating success, failure, or if a shell was not found, enabling better error handling for shell management operations.
src/modules/Elsa.Shells.Api · high confidence
New Resilience module with strategy management, retry tracking, and simulation endpoints
The new Elsa.Resilience module introduces a set of APIs for managing workflow resilience. Users can now browse available resilience strategies via the /resilience/strategies endpoint and inspect retry attempt records for specific activities using /resilience/retries/{activityInstanceId}. Additionally, a /simulate-response endpoint allows developers to simulate resilience responses (such as HTTP 429 or 503 errors) for testing purposes, with session management and input validation. The module also integrates with the workflow engine to record retry attempts and modify activity descriptors for resilient activities.
src/modules/Elsa.Resilience · high confidence
New Scheduling Activities and Core Infrastructure
This change introduces the core scheduling activities—Cron, Delay, StartAt, and Timer—along with the underlying bookmark payloads, scheduler contracts, and handlers required to manage them. Users can now define workflows that pause for a specific duration (Delay), trigger at a future timestamp (StartAt), or repeat at fixed intervals or via CRON expressions (Timer, Cron). The module also registers the necessary infrastructure, including the local scheduler, trigger/bookmark schedulers, and cleanup handlers to ensure scheduled jobs are properly removed when workflow definitions or bookmarks are deleted.
src/modules/Elsa.Scheduling · high confidence
New Scripting API client interfaces and models
The API client now includes dedicated contracts and models for the scripting resource, enabling integration with expression descriptors and JavaScript type definitions. Users can retrieve a list of available expression descriptors via the new IExpressionDescriptorsApi, and fetch JavaScript type definitions for specific workflow activities using IJavaScriptApi to support features like Monaco editor auto-completion. The change also introduces the Expression and ExpressionDescriptor models, where the Expression value is now an object type to support dynamic content, and adds an extension method to map expression descriptors to Monaco language identifiers.
src/clients/Elsa.Api.Client/Resources/Scripting · high confidence
New Secrets module with tenant isolation and API endpoints
The new Elsa.Secrets module introduces a comprehensive system for managing secrets, including creating, reading, updating, rotating, and revoking them via a set of REST endpoints (e.g., POST /secrets, GET /secrets/{name}). It enforces tenant isolation by stamping secrets with tenant IDs and filtering visibility based on the current tenant context, ensuring that secrets are scoped and isolated per tenant. The module supports multiple secret types (text, RSA key, X509 certificate) and stores (encrypted, configuration), and integrates with the expression engine to allow secrets to be referenced in workflows.
src/modules/Elsa.Secrets · high confidence
New Workflow Instances API client interface
The API client now includes a dedicated \IWorkflowInstancesApi\ interface that exposes methods for managing workflow instances, including listing, retrieving, deleting, and cancelling single or bulk instances. It also adds support for exporting and importing workflow instances, retrieving execution state, and accessing workflow instance variables. Journal records can be fetched with pagination (skip/take) or filtered by activity IDs, enabling more granular inspection of workflow execution history.
src/clients/Elsa.Api.Client/Resources/WorkflowInstances/Contracts · high confidence
New activities for invoking CLR methods and embedding workflow definitions
The workflow management module now includes \HostMethodActivity\ and \HostMethodActivityProvider\, which allow public methods on configured CLR types to be exposed and executed as workflow activities, with inputs resolved from workflow data or the service provider. Additionally, \WorkflowDefinitionActivity\ enables workflows to be embedded and executed as activities within other workflows, handling input/output mapping and versioning, while the new \SetOutput\ activity allows explicit assignment of values to workflow definition outputs, including support for ancestor and composite activity scopes.
src/modules/Elsa.Workflows.Management · high confidence
New alteration dispatch and instance filtering services
The system now includes dedicated services to manage workflow alterations: AlteredWorkflowDispatcher handles the execution of scheduled work for successful alteration results by delegating to the core workflow dispatcher, while WorkflowInstanceFinder provides robust filtering capabilities for locating workflow instances based on complex criteria (including activity execution status and running state), with support for selecting all records when filters are empty.
src/modules/Elsa.Alterations.Core/Services · high confidence
New alteration handlers for workflow control and modification
This change introduces a set of new alteration handlers within the Elsa.Alterations module, enabling runtime manipulation of workflow instances. Specifically, it adds handlers to cancel entire workflows or specific activities, migrate running instances to newer workflow definition versions, schedule activities for execution (including resetting faulted activities), and modify variable values during runtime. These capabilities allow for more dynamic workflow management and error recovery without requiring external orchestration.
src/modules/Elsa.Alterations/AlterationHandlers · high confidence
New client API for managing external authentication connections
The Elsa API client now includes a dedicated \IExternalAuthenticationConnectionsApi\ interface and supporting models for administrator-managed external authentication connections. This addition enables users to programmatically list, create, update, enable, disable, archive, and restore connections, as well as validate and test their configuration. The API supports advanced features such as managing secret bindings, initiating authentication previews to verify claim projections and policy decisions, and handling shadowed connection relationships where one connection overrides another. This provides a comprehensive client-side contract for the external authentication management endpoints.
src/clients/Elsa.Api.Client/Resources/ExternalAuthentication/Connections · high confidence
New client API for managing external identity links
The Elsa API client now includes a dedicated interface for administrator-managed external identity links, enabling users to list, prelink, atomically replace, and unlink external identities. This change introduces the \IExternalIdentityLinksApi\ contract along with supporting request, response, and model classes (such as \ExternalIdentityLink\ and \IdentityLinkUser\) to support cursor-paged listing and user search operations for external authentication connections.
src/clients/Elsa.Api.Client/Resources/ExternalAuthentication/IdentityLinks · high confidence
New client API for retrieving activity descriptor options
A new client interface, IActivityDescriptorOptionsApi, has been added to allow applications to programmatically retrieve options for specific activity properties. This feature enables users to query the available configuration options for a given activity type and property name via a POST request to the /descriptors/activities/{activityTypeName}/options/{propertyName} endpoint, passing a context object to customize the request. The response returns a dictionary of option items, facilitating dynamic UI generation or validation based on the activity's current configuration capabilities.
src/clients/Elsa.Api.Client/Resources/ActivityDescriptorOptions · high confidence
New code editor configuration options for UI hints
The client library now exposes specific configuration classes for the code editor UI hint, allowing consumers to control editor appearance and behavior. Users can now set the editor height (Default or Large) via the new EditorHeight enum, enable single-line mode, and specify the syntax highlighting language through CodeEditorOptions. Additionally, a dedicated MultiLineOptions record is provided to configure height settings specifically for multi-line editor contexts.
src/clients/Elsa.Api.Client/Shared/UIHints/CodeEditor · high confidence
New common contracts for tasks, serialization, and utilities
The \Elsa.Common.Contracts\ module now exposes a set of foundational interfaces and abstract base classes that standardize core capabilities across the platform. This includes a task hierarchy (\ITask\, \IBackgroundTask\, \IRecurringTask\, \IStartupTask\) to support consistent background and startup execution, particularly in multi-tenant scenarios. Serialization is abstracted via \IJsonSerializer\ and \IFormatter\ for flexible object-to-string conversion, while \ISerializationOptionsConfigurator\ allows fine-grained control over \JsonSerializerOptions\. Additional contracts include \ICompressionCodec\ and \ICompressionCodecResolver\ for pluggable compression strategies, \ISystemClock\ for testable time handling, and \ILogRecord\ for logging abstraction.
src/modules/Elsa.Common/Contracts · high confidence
New common extension methods for collections, configuration, dependency injection, and more
The \src/modules/Elsa.Common/Extensions\ directory now contains a comprehensive set of new extension methods to simplify common development tasks. \CollectionExtensions\ and \EnumerableExtensions\ provide \AddRange\, \RemoveWhere\, and \Paginate\ helpers for easier data manipulation. \ConfigurationExtensions\ adds \GetSectionAsJson\ to easily serialize configuration sections. \DependencyInjectionExtensions\ and \ServiceCollectionExtensions\ offer fluent methods for registering memory stores, serialization options, and various task types (startup, background, recurring) while safely handling duplicate registrations. \JsonSerializerOptionsExtensions\ simplifies JSON configuration with methods to add converters and clone options for value conversion. \PropertyAccessorExtensions\ and \TypeExtensions\ provide reflection utilities for setting/getting properties and checking type characteristics (nullable, collection, numeric). \QueryableExtensions\ adds pagination and ordering for LINQ queries, while \VersionedEntityExtensions\ standardizes filtering entities by version states (draft, latest, published). \ExceptionExtensions\ introduces an \IsFatal\ helper for robust error handling, and \StringExtensions\ adds utility methods for null/empty string handling.
src/modules/Elsa.Common/Extensions · high confidence
New common models for pagination, result handling, and versioning
The \Elsa.Common.Models\ namespace now includes new types to standardize data handling across the platform. \Page\<T\>\ and \PageArgs\ provide a unified way to handle pagination with support for both offset/limit and page/size formats, enabling consistent list views. The \Result\<T\>\ monad introduces a strongly typed pattern for handling success and failure states, allowing developers to chain operations via \OnSuccess\ and \OnFailure\ delegates instead of relying on exceptions for control flow. Additionally, \VersionOptions\ offers a structured way to query versioned entities, supporting filters like Latest, Published, Draft, and specific versions, which improves clarity when accessing workflow definitions and other versioned resources.
src/modules/Elsa.Common/Models · high confidence
New compression codec implementations for GZip, Zstd, and None
The Elsa.Common.Codecs module now includes three new compression strategies: GZip, Zstd, and None. The GZip codec uses standard .NET compression streams for encoding and decoding. The Zstd codec leverages the IronCompress library to handle Zstandard compression, with proper disposal of the compression result to prevent memory leaks. The None codec provides a pass-through implementation that returns input unchanged, useful for scenarios where no compression is desired. These implementations all conform to the ICompressionCodec interface.
src/modules/Elsa.Common/Codecs · high confidence
New contracts and notifications for the Alterations module
This change introduces the core interface contracts and notification types for the new Alterations feature in Elsa. It defines the extensibility model via \IAlteration\ and \IAlterationHandler\, allowing custom logic to be applied to workflow instances. It also establishes the infrastructure for managing and executing these changes through interfaces for job dispatching (\IAlterationJobDispatcher\, \IAlterationJobRunner\), persistence (\IAlterationJobStore\, \IAlterationPlanStore\), and planning (\IAlterationPlanManager\, \IAlterationPlanScheduler\). Additionally, it adds serialization support (\IAlterationSerializer\) and workflow resumption logic (\IAlteredWorkflowDispatcher\), alongside notifications for job and plan lifecycle events to enable reactive handling of alteration outcomes.
src/modules/Elsa.Alterations.Core/Contracts · high confidence
New data models for workflow alteration plans and logging
The core alteration module now includes dedicated model classes to support structured alteration planning and execution tracking. Users can define alteration plans via \AlterationPlanParams\, which allows specifying a set of alterations and a comprehensive \AlterationWorkflowInstanceFilter\ to target specific workflow instances based on IDs, names, statuses, timestamps, and activity filters. Additionally, \ActivityFilter\ provides granular filtering for individual activities within those instances. To improve observability, \AlterationLog\ and \AlterationLogEntry\ models have been introduced to record detailed logs of alteration events, including messages, log levels, timestamps, and associated event names, while \NewAlterationJob\ defines the payload for triggering these alteration jobs.
src/modules/Elsa.Alterations.Core/Models · high confidence
New enums for log persistence, flowchart merge modes, and timestamp filtering
The client API now exposes three new enumeration types to support advanced workflow configuration and querying. LogPersistenceEvaluationMode allows users to select between 'Strategy' and 'Expression' modes for log persistence evaluation. MergeMode defines six strategies for handling multiple inbound execution paths in flowcharts: None, Stream, Merge, Converge, Cascade, and Race, enabling precise control over synchronization and concurrency behavior. Additionally, TimestampFilterOperator provides six comparison operators (Is, IsNot, LessThan, GreaterThan, LessThanOrEqual, GreaterThanOrEqual) for filtering workflow instances by timestamp.
src/clients/Elsa.Api.Client/Shared/Enums · high confidence
New extension methods for type aliasing and JSON parsing in Elsa Expressions
This change introduces a new set of extension methods in the \Elsa.Expressions\ module to simplify configuration and data handling. Developers can now easily register type aliases for expressions via \ExpressionOptions\, \IModule\, and \IServiceCollection\ extensions, allowing custom types to be referenced by short names in workflows. Additionally, a new \JsonElementExtensions.GetValue\ method provides a convenient way to parse JSON elements into their corresponding .NET objects (such as strings, decimals, booleans, or raw text for complex structures), and \TypeExtensions\ adds helpers for resolving generic element types and generating friendly type names, improving the robustness of expression type resolution.
src/modules/Elsa.Expressions/Extensions · high confidence
New feature dependency attributes introduced
Added the \DependsOn\ and \DependencyOf\ attributes to the \Elsa.Features.Attributes\ namespace. These attributes allow developers to declaratively specify feature dependencies, enabling automatic enabling of features based on the activation of other features.
src/common/Elsa.Features/Attributes · high confidence
New feature management system with dependency resolution and hosted service ordering
The Elsa Features module now includes a new \Module\ implementation that manages feature lifecycle, including topological sorting of feature dependencies to ensure correct initialization order and priority-based ordering for hosted services. A new \FeatureDescriptor\ model provides structured metadata (name, namespace, display name, description) for each feature, which is registered into the service collection as \IInstalledFeatureRegistry\ and \IInstalledFeatureProvider\ for client applications to inspect enabled features.
src/common/Elsa.Features/Implementations · high confidence
New feature-based infrastructure and multitenancy support in Elsa.Common
This change introduces a new feature-based configuration system within the Elsa.Common module, registering core services such as a Mediator, SystemClock, JSON formatters, and string compression codecs via dedicated feature classes. It also adds comprehensive multitenancy support, including tenant resolution, scope management, background work queues, and task lifecycle coordination, alongside new attributes for type forwarding and task dependencies to aid serialization and scheduling.
src/modules/Elsa.Common/Features · high confidence
New helper utilities for task dependency sorting, type forwarding, and fatal exception detection
Added three new helper classes to the common module: TopologicalTaskSorter enables tasks to declare dependencies via attributes and ensures they execute in the correct order while detecting circular dependencies; TypeHelper supports type migration by resolving deprecated types to their replacements using ForwardedTypeAttribute; and ExceptionExtensions provides an IsFatal method to identify unrecoverable process-level failures (such as OutOfMemoryException) that should not be caught.
src/modules/Elsa.Common/Helpers · high confidence
New identity management APIs and structured authorization model
This change introduces a comprehensive set of new endpoints and contracts for managing identity resources, including users, roles, and applications, alongside a structured authorization model. Users can now create and manage applications via a new POST /identity/applications endpoint, which generates client IDs, secrets, and API keys. Role management is expanded with endpoints to create roles with specific permissions, delete roles (including a remediation workflow for cross-module dependencies), and inspect deletion impact. A new login endpoint (POST /identity/login) and token refresh mechanism (POST /identity/refresh-token) handle authentication and token issuance. Additionally, a structured permission system is exposed via GET /identity/permissions (catalog), GET /identity/me/permissions (user's effective grants), and GET /identity/permissions/reach (wildcard coverage), allowing clients to dynamically adapt UI and access based on the current permission state.
src/modules/Elsa.Identity · high confidence
New integration testing utilities for Elsa workflows
The \Elsa.Testing.Shared.Integration\ package now provides a comprehensive suite of components for integration testing, centered around the new \WorkflowTestFixture\ class which manages service provider lifecycle and tenant activation. It includes \TestApplicationBuilder\ for configuring Elsa features and output capture, extension methods in \RunWorkflowExtensions\ and \DispatchWorkflowExtensions\ to run workflows to completion (including automatic bookmark resumption), and \RunWorkflowResultAssertions\/\RunWorkflowResultExtensions\ for journal-based assertions on activity execution. Additionally, the legacy \RunActivityExtensions\ are marked obsolete in favor of the new fixture.
src/common/Elsa.Testing.Shared.Integration · high confidence
New operational dashboard API endpoints
Elsa Studio now exposes a new set of read-only API endpoints under the /dashboard/\* path to power the operational dashboard. Hosts can enable this feature via the DashboardApiFeature module. The API includes GET /dashboard/overview for aggregate runtime and workflow metrics, POST /dashboard/workflow-trends for trend data, GET /dashboard/needs-attention for priority findings, GET /dashboard/recent-activity for recent workflow instances, and POST /dashboard/workflow-hotspots for top workflows by metric. All endpoints require the 'dashboard' permission with the 'View' verb. The API supports time-range filtering (1h, 24h, 7d) and system workflow inclusion toggles, and is designed to be extensible via IDashboardContributor implementations.
src/modules/Elsa.Dashboard.Api · high confidence
New opt-in module for live and recent console log diagnostics
The new \Elsa.Diagnostics.ConsoleLogs\ module enables operational diagnostics by capturing raw \stdout\ and \stderr\ output from the backend process. It enriches these logs with workflow and activity metadata (such as workflow instance IDs and activity IDs) via ambient context accessors, allowing users to filter and query logs by execution context. The module exposes recent bounded history through a REST endpoint (\POST /diagnostics/console-logs/recent\) and provides real-time streaming via a SignalR hub (\/elsa/hubs/diagnostics/console-logs\). Access to both endpoints is controlled by the \diagnostics/console-logs\ permission, and the feature is opt-in, requiring explicit configuration via \UseConsoleLogs\.
src/modules/Elsa.Diagnostics.ConsoleLogs · high confidence
New resilience API client for strategies and retry attempts
The Elsa API client now includes support for querying resilience configurations and tracking retry history. Users can retrieve a list of resilience strategies filtered by category and access detailed records of retry attempts for specific activity instances, including attempt numbers, delays, and associated details.
src/clients/Elsa.Api.Client/Resources/Resilience · high confidence
New shared EF Core persistence infrastructure and multitenancy handling
This change introduces the \Elsa.Persistence.EFCore.Common\ module, providing a shared base for Entity Framework Core persistence. It adds \ElsaDbContextBase\ to handle tenant ID assignment and schema configuration, and implements multitenancy via \ApplyTenantId\ and \SetTenantIdFilter\ handlers that automatically tag entities and filter queries by tenant. The module also includes a \CombinedPersistenceShellFeatureBase\ for unified configuration of persistence settings, a \DbExceptionClassifier\ for provider-specific transient error and duplicate key detection, and \BulkUpsertExtensions\ for efficient bulk operations across SQL Server, SQLite, PostgreSQL, MySQL, and Oracle.
src/modules/Elsa.Persistence.EFCore.Common · high confidence
New shared testing infrastructure for workflow execution and event tracking
The \Elsa.Testing.Shared.Component\ library now provides a comprehensive set of utilities to simplify workflow testing. It introduces an \AsyncWorkflowRunner\ that allows tests to execute workflows and await their completion, automatically tracking activity execution records and handling timeouts via a new \SignalManager\. To support this, a suite of \WorkflowEvents\ and specific event argument classes (such as \WorkflowStateCommittedEventArgs\ and \ActivityExecutedEventArgs\) have been added to expose internal runtime notifications to test code. Additionally, a \TriggerSignal\ activity and \TestTenantsProvider\ are included to facilitate signal triggering and multitenancy scenarios within tests.
src/common/Elsa.Testing.Shared.Component · high confidence
New shared unit testing infrastructure for workflow activities
The \Elsa.Testing.Shared\ library now provides a comprehensive set of utilities for unit testing workflow activities. This includes the \ActivityTestFixture\ class, which offers a fluent API to configure services, set up execution contexts, and execute activities in isolation. Supporting this are extension methods for validating activity attributes and checking scheduled outcomes, as well as fake scheduler strategies (\FakeActivityExecutionContextSchedulerStrategy\ and \FakeWorkflowExecutionContextSchedulerStrategy\) to simulate workflow scheduling without external dependencies. Additionally, the package introduces logging and text output helpers (\XunitLogger\, \XunitConsoleTextWriter\, \CapturingTextWriter\) to integrate test output with xUnit, and utility classes like \UnicodeRangeGenerator\ for testing internationalization.
src/common/Elsa.Testing.Shared · high confidence
New tenant management API and multitenancy configuration system
This change introduces a complete tenant management system within the Elsa.Tenants module. It adds a set of REST API endpoints (POST /tenants, GET /tenants/{id}, GET /tenants, POST /tenants/{id}, DELETE /tenants/{id}, POST /tenants/refresh) for creating, reading, updating, deleting, and refreshing tenant records. It also establishes the underlying infrastructure for multitenancy, including a configurable tenant resolution pipeline (ITenantResolverPipelineBuilder), a default in-memory tenant store (MemoryTenantStore), and providers for loading tenants from configuration or the store. Additionally, it integrates tenant context propagation into the mediator pipeline via TenantPropagatingMiddleware to ensure tenant scope is maintained across commands.
src/modules/Elsa.Tenants · high confidence
New workflow activation strategies and core runtime activities
The workflow runtime now includes three new activation strategies—Singleton, Correlation, and Correlated Singleton—that allow you to prevent duplicate workflow instances based on definition ID and/or correlation ID. Additionally, new activities have been added to the runtime: DispatchWorkflow and BulkDispatchWorkflows for creating and dispatching child workflows (with optional wait-for-completion), ExecuteWorkflow for synchronous child execution, PublishEvent for emitting events (including local-scoped ones), Event for waiting on published events, and RunTask for requesting external task execution and resuming on completion.
src/modules/Elsa.Workflows.Runtime · high confidence
New workflow definition API response models
The API client now includes specific response models for workflow definition operations, enabling clients to handle detailed results from bulk actions and updates. These new records expose the count of deleted definitions, the status of published/retracted items (including those already published or not found), the workflow state after execution, the count of consuming workflows, and the specific IDs of workflows affected by reference updates or consuming a specific definition. This allows users to programmatically verify the outcome of bulk publish/retract/delete actions and understand dependencies between workflow definitions.
src/clients/Elsa.Api.Client/Resources/WorkflowDefinitions/Responses · high confidence
New workflow instance API client models
The Elsa.Api.Client now exposes a comprehensive set of data models for interacting with workflow instances, enabling clients to query and manage workflow state, execution logs, and incidents. This includes the WorkflowInstance and WorkflowInstanceSummary models for basic instance metadata, the WorkflowState model which aggregates detailed runtime information such as bookmarks, activity execution contexts, completion callbacks, faults, and incident counts, and the ActivityIncident model for tracking specific activity-level errors. Additional models support bulk export requests, persistent and resolved variable states, exception details, and execution log records, providing a complete view of workflow lifecycle and execution history.
src/clients/Elsa.Api.Client/Resources/WorkflowInstances/Models · high confidence
New workflow instance response models added
The API client now includes response models for bulk deletion and execution state queries. Users can now deserialize responses containing the count of deleted workflow instances and the current status, sub-status, and last updated timestamp of a workflow instance.
src/clients/Elsa.Api.Client/Resources/WorkflowInstances/Responses · high confidence
New workflow instance status and sorting enums in the API client
The API client now exposes specific enums for filtering and interpreting workflow instance data. Users can sort workflow lists by creation date, last execution, finish time, or name using the new OrderByWorkflowInstance enum. Additionally, the client provides WorkflowStatus (Running, Finished) and WorkflowSubStatus (Pending, Executing, Suspended, Finished, Cancelled, Faulted, Interrupted) to distinguish between general states and detailed execution phases, including the new Interrupted state for instances paused during graceful runtime shutdowns.
src/clients/Elsa.Api.Client/Resources/WorkflowInstances/Enums · high confidence
Oracle database support for secrets persistence
This release adds Oracle as a supported database provider for the Secrets module. Users can now store secrets in an Oracle database by enabling the 'Oracle Secrets Persistence' shell feature and providing a connection string. The implementation includes the necessary EF Core configurations, design-time factories, and a migration history that establishes the initial schema and enforces tenant-scoped uniqueness for secret names.
src/modules/Elsa.Secrets.Persistence.EFCore.Oracle · high confidence
Real-time workflow update messages and feature descriptors added to API client
The API client now includes specific message models for real-time workflow updates, enabling clients to react to activity execution events (ActivityExecuting, ActivityExecuted), activity execution log updates, workflow instance updates, and workflow execution log updates. Additionally, a FeatureDescriptor model has been added to represent feature metadata, including name, namespace, display name, and description, allowing clients to query and display feature information.
src/clients/Elsa.Api.Client/RealTime, src/clients/Elsa.Api.Client/Resources/Features/Models · high confidence
Stable application instance names and heartbeat monitoring for clustering
The Elsa.Hosting.Management module now supports configuring a stable, unique name for each application instance via the \ApplicationInstanceOptions\ (allowing explicit configuration or reading from an environment variable like a Kubernetes pod name). This prevents the accumulation of orphaned per-instance transport entities (such as Azure Service Bus subscriptions) across restarts by ensuring the same logical instance reuses its entity names. Additionally, the module introduces \InstanceHeartbeatService\ and \InstanceHeartbeatMonitorService\ hosted services that periodically write and check instance heartbeats, allowing the system to detect and clean up unhealthy or stopped instances.
src/modules/Elsa.Hosting.Management · high confidence
Structured authorization model and API infrastructure
This change introduces a structured permission model for Elsa, registering the permission evaluator, descriptor registry, and authorization handlers via DI, and automatically discovering permission descriptors from loaded Elsa assemblies to ensure modules can define and enforce access controls. It also adds infrastructure for the API layer, including FastEndpoints integration with custom JSON serialization, Swagger/OpenAPI documentation generation with JWT Bearer and API Key support, and hooks for applying ASP.NET Core rate limiting policies to the API route prefix.
src/common/Elsa.Api.Common/Extensions · high confidence
Support for managing workflow variable test values
The API client now provides extension methods to manage test values for workflow variables. Users can retrieve, set, and clear specific test values for variables within a workflow definition via the new \GetVariableTestValues\, \GetVariableTestValue\, \SetVariableTestValue\, and \ClearVariableTestValue\ methods, which store this data in the workflow definition's custom properties.
src/clients/Elsa.Api.Client/Resources/WorkflowDefinitions/Extensions · high confidence
Behavioural changes
AI persistence migrations moved to provider-specific projects
The Entity Framework Core migrations for AI data (conversations, proposals, and audit records) have been relocated from a shared location into the individual database provider modules (MySQL, Oracle, and PostgreSQL). This change ensures that database-specific migration scripts and design-time factories are maintained alongside their respective provider implementations, allowing each database backend to manage its own schema evolution independently.
(repo-wide) · high confidence
Add optional refresh parameter to list activity descriptors request
The ListActivityDescriptorsRequest now includes an optional Refresh property, allowing users to request that activity descriptors be refreshed when listing them.
src/clients/Elsa.Api.Client/Resources/ActivityDescriptors/Requests · high confidence
Add structured fault categories and codes for alterations
The Elsa.Alterations module now exposes dedicated constants for fault handling, specifically defining the 'Alteration' fault category and the 'PlanNotFound' fault code. This change provides a standardized way to identify and categorize specific error conditions within the alterations workflow, improving clarity for users and developers when troubleshooting plan-related issues.
src/modules/Elsa.Alterations, src/modules/Elsa.Alterations/Constants · high confidence
Alteration execution logs are now included in workflow execution history
The RunAlterationsMiddleware now automatically appends logs generated during alteration processing to the main workflow execution log. This ensures that users can see the outcomes and details of alterations directly within the standard workflow execution history, providing better visibility into how alterations affected the workflow run.
src/modules/Elsa.Alterations/Middleware · high confidence
Build infrastructure consolidation and .NET 10 support
The build system has been reorganized to use centralized MSBuild props files (Directory.Build.props, Fody.props, PackageManifest.props) in the src directory, replacing scattered per-project configurations. This change adds support for .NET 10 alongside existing .NET 8 and 9 targets, enforces ConfigureAwait.Fody weaving globally to prevent context-capture issues, and ensures the Elsa.Api.Common package no longer publishes an invalid runtime-kind-less manifest.
src · high confidence
Completion logic for alteration plans and job notifications
The Alterations module now automatically manages the lifecycle of alteration plans and resumes affected workflows. When an alteration job finishes, the system checks if all jobs in the plan are done; if so, it marks the plan as complete. Upon plan completion, any workflows waiting for that specific plan are triggered via the bookmark queue. Additionally, if a completed job leaves scheduled work for its associated workflow, that workflow instance is automatically resumed.
src/modules/Elsa.Alterations/Handlers · high confidence
Configurable JSON serialization for the API client
The API client now uses a new RefitSettingsHelper to configure JSON serialization, introducing support for custom serializer options via a callback. This allows users to inject their own JsonSerializerOptions configuration, enabling tailored behavior such as custom converters or naming policies, while defaulting to camel-case naming and specific converters like TypeJsonConverter.
src/clients/Elsa.Api.Client/Helpers · high confidence
Console Logs and Workflow Runtime dashboards are now separate modules
The dashboard contributions for Console Logs and Workflow Runtime have been extracted into their own dedicated modules (Elsa.Diagnostics.ConsoleLogs.Dashboard and Elsa.Workflows.Runtime.Dashboard). This change decouples these specific dashboard features from their core runtime modules, allowing them to be enabled or disabled independently via new module extension methods (UseConsoleLogsDashboard, UseWorkflowRuntimeDashboard) and shell feature manifests. Users will see these dashboard sections remain available but now managed through distinct, optional feature flags.
src/modules/Elsa.Diagnostics.ConsoleLogs.Dashboard, src/modules/Elsa.Workflows.Runtime.Dashboard · high confidence
Customizes FastEndpoints serialization to align with Elsa API standards
The Elsa API now uses a dedicated configurator to handle JSON serialization for FastEndpoints, ensuring that request deserialization and response serialization match the settings used by the broader Elsa Workflows API. This change also adds support for parsing DateTimeOffset values using the invariant culture, providing consistent date-time handling across API endpoints.
src/common/Elsa.Api.Common/FastEndpointConfigurators · high confidence
Decouple expression evaluation into specialized handlers
The expression evaluation logic in the Elsa.Expressions module has been refactored to use a decoupled, handler-based architecture. This change introduces specific expression handlers, such as DelegateExpressionHandler for executing delegate-based expressions and LiteralExpressionHandler for converting literal values to target types using a well-known type registry. A new TypeConversionException has also been added to provide detailed context (value and target type) when type conversions fail, improving error reporting for users working with complex expression evaluations.
src/modules/Elsa.Expressions · high confidence
Decoupled expression evaluation contracts
The expression evaluation system has been refactored to decouple expression types and their management. New interfaces have been introduced to separate concerns: IExpressionDescriptorProvider and IExpressionDescriptorRegistry now handle the discovery and storage of expression syntax descriptors, while IExpressionEvaluator and IExpressionHandler manage the actual execution of expressions. Additionally, IWellKnownTypeRegistry provides a centralized way to register and resolve type aliases, improving how expressions interact with known types.
src/modules/Elsa.Expressions/Contracts · high confidence
Dropdown UI hint now supports configurable item sorting
The dropdown UI hint model has been updated to allow control over the display order of options. A new \SortItems\ property on the \SelectList\ record defaults to true (alphabetical sorting) but can be set to false to preserve the original order of items provided by the provider. This change enables users to disable automatic sorting when the specific sequence of dropdown options is important.
src/clients/Elsa.Api.Client/Shared/UIHints/DropDown · high confidence
EF Core persistence for Alterations and Tenants modules with atomic tenant ownership
The EF Core persistence layer for the Alterations and Tenants modules has been implemented, introducing dedicated DbContexts (AlterationsElsaDbContext and TenantsElsaDbContext) and store implementations (EFCoreAlterationJobStore, EFCoreAlterationPlanStore, EFCoreTenantStore). A key behavioral change in the Alterations stores is the introduction of atomic, tenant-aware upserts: when multi-tenancy is enabled, SaveAsync and SaveMany now use a compare-and-swap strategy that stamps the ambient tenant ID and ensures rows are only updated by their owning tenant, preventing cross-tenant data corruption. The Tenants module adds a ConfigurationJsonConverter to persist IConfiguration objects as JSON strings.
src/modules/Elsa.Persistence.EFCore/Modules/Alterations · high confidence
Enforced tenant isolation in in-memory alteration stores
The in-memory stores for alteration jobs and plans now strictly enforce tenant isolation, matching the behavior of the Entity Framework persistence layer. When saving or updating records, the stores automatically apply the current tenant ID and prevent cross-tenant data collisions by throwing specific exceptions if a hidden plan or job ID conflict is detected. This ensures that multi-tenant environments using the memory store do not inadvertently expose or overwrite data belonging to other tenants.
src/modules/Elsa.Alterations.Core/Stores · high confidence
Expressions feature now registers core service dependencies
The Expressions feature now explicitly configures its internal services during initialization. Specifically, the system registers the IExpressionEvaluator implementation as scoped and the IWellKnownTypeRegistry as a singleton, ensuring that expression evaluation and type resolution are properly wired into the application's dependency injection container.
src/modules/Elsa.Expressions/Features · high confidence
Introduce Architecture Decision Records for Elsa Workflows
The project now maintains a formal set of Architecture Decision Records (ADRs) in the \doc/adr\ directory to document key architectural choices. This initial batch of 23 records covers significant behavioral and structural changes, including a token-centric execution model for Flowcharts with explicit merge modes, standardized tenant ID handling using empty strings and asterisk sentinels, direct bookmark management in the workflow execution context, and a new security model for external authentication and identity management. These records provide a permanent, searchable history of why specific design decisions were made, such as switching from counter-based to token-based flowchart joins or separating external identity from Elsa authorization.
doc/adr · high confidence
Introduce CShells-based shell features for infrastructure and multitenancy
The Elsa.Common module now registers core infrastructure services as modular shell features using the CShells framework. This includes the Default Formatters feature (registering JSON serialization and type converters), the Mediator feature (configuring in-process notifications and background processing), the String Compression feature (providing GZip and Zstd codecs), and the System Clock feature. Additionally, the Multitenancy feature now manages tenant resolution, scopes, and lifecycle events as a shell feature, with tenant activation and deactivation handled via the new IShellInitializer and IDrainHandler primitives during shell startup and draining.
src/modules/Elsa.Common/ShellFeatures · high confidence
Introduce Elsa Core as a shell feature with dependency tracking
The Elsa workflow module is now exposed as a distinct shell feature named "Elsa Core". This feature declares explicit dependencies on the Workflow Management and Workflow Runtime features, ensuring they are initialized in the correct order, and registers a service provider to bridge shell feature capabilities with the existing Elsa feature API.
src/modules/Elsa/ShellFeatures · high confidence
Introduce NUKE-based build system with GitHub Actions support
The build process has been migrated to use the NUKE build automation framework, replacing the previous build configuration. This change introduces a new \build\ directory containing the core build script (\Build.cs\), CI integration for GitHub Actions (\Build.CI.GitHubActions.cs\), and code style configuration (\.editorconfig\). The new system configures the CI pipeline to run on pull requests targeting \main\, \patch/\\, and \develop/\\ branches, automatically setting up the .NET 10.x SDK and executing compile and test targets.
build · high confidence
Introduce configurable recurring task scheduling with cron and interval support
The recurring tasks subsystem has been refactored to support flexible scheduling configurations. Users can now define task execution schedules using either fixed time intervals or standard cron expressions via the new \RecurringTaskSchedule\ configuration API. The system introduces distinct schedule implementations (\CronSchedule\ and \IntervalSchedule\) that drive a new \ScheduledTimer\ for executing background actions, along with attributes like \OrderAttribute\ and \SingleNodeTaskAttribute\ to control task priority and multi-node execution behavior.
src/modules/Elsa.Common/RecurringTasks · high confidence
Introduce unified commit strategy descriptor model and API client
The client now exposes a unified model for commit strategies via the new \CommitStrategyDescriptor\ record, which encapsulates the strategy's technical name, display name, and description. This model is consumed by the newly added \ICommitStrategiesApi\ interface, which provides methods to list workflow and activity commit strategies through dedicated endpoints (\/descriptors/commit-strategies/workflows\ and \/descriptors/commit-strategies/activities\), replacing previous fragmented or non-descriptor-based access patterns.
src/clients/Elsa.Api.Client/Resources/CommitStrategies · high confidence
Mask Authorization header values in activity state logs
The system now automatically masks the value of the 'Authorization' input on SendHttpRequest activities by replacing the actual token with asterisks. This prevents sensitive credentials from appearing in plain text within activity state logs or debugging outputs, improving security visibility for users monitoring workflow execution.
src/apps/Elsa.Server.Web/Filters · high confidence
New Docker scripts and compose files for Citus, YugabyteDB, and updated SQL Server
The scripts/docker directory now includes dedicated Docker Compose configurations for Citus (docker-compose-citus.yml) and YugabyteDB (docker-compose-yugabyte.yml), enabling users to run the application with these distributed database backends. The main docker-compose.yml has been updated to use SQL Server 2022 (mcr.microsoft.com/mssql/server:2022-latest) and includes a new Citus service definition. Additionally, new shell and PowerShell scripts (build-and-run-all-in-one-web.sh, docker-run-all-in-one-web.ps1) have been added to simplify building and running the all-in-one web application locally.
scripts/docker · high confidence
New MissingConfigurationException for configuration errors
A new \MissingConfigurationException\ has been added to the \Elsa.Common.Exceptions\ namespace. This exception is thrown when required configuration data is absent, allowing applications to handle missing configuration scenarios with a specific error type rather than generic exceptions.
src/modules/Elsa.Common/Exceptions · high confidence
New configuration options for API key authentication and HTTP client customization
The Elsa API client now exposes explicit options for configuring API key authentication and HTTP client behavior. Users can set the \ApiKey\ and specify the \AuthenticationHandler\ type (defaulting to \ApiKeyHttpMessageHandler\) within \ElsaClientBuilderOptions\ to control how the client authenticates with the server. Additionally, new delegates allow fine-grained customization of the HTTP client setup (\ConfigureHttpClient\, \ConfigureHttpClientBuilder\), retry policies for transient failures (\ConfigureRetryPolicy\), and JSON serialization settings (\ConfigureJsonSerializerOptions\), providing greater flexibility in how the client connects and handles errors.
src/clients/Elsa.Api.Client/Options · high confidence
New expression evaluation and type aliasing services
The system now includes an ExpressionEvaluator service that resolves expression types via a descriptor registry and delegates evaluation to specific handlers, and a WellKnownTypeRegistry that manages type-to-alias mappings using case-insensitive string comparison to support flexible type referencing in expressions.
src/modules/Elsa.Expressions/Services · high confidence
New external authentication broker and connection management APIs
The \Elsa.ExternalAuthentication\ module now exposes a dedicated broker API to handle external identity flows and a revamped management API for identity provider connections. Users can now discover available login methods via \GET /external-authentication/login-methods\, initiate external authorization via \GET /external-authentication/authorize/{connectionKey}\, and handle provider callbacks via \GET /external-authentication/callback/{connectionKey}\. A new token exchange endpoint (\POST /external-authentication/token\) supports standard OAuth 2.0 flows, while a new logout flow (\POST /external-authentication/logout\ and \GET /external-authentication/logout/continue/{handle}\) manages session revocation and upstream provider logout. Connection management has been updated with new endpoints (\GET/POST/PUT /external-authentication/connections\) that enforce host-wide scope, require ETag-based concurrency control (\If-Match\), and support shadow relationship management, allowing configuration-based connections to be promoted or overridden by database connections. The module also introduces structured contracts for adapters, identity link management, and permission grant sources, along with rate limiting policies for discovery, initiation, and callback endpoints.
src/modules/Elsa.ExternalAuthentication · high confidence
New security configuration and permission definitions for workflow runtime and bookmark queues
The API common module now includes explicit configuration for endpoint security roles (Admin, Reader, Writer) and a centralized set of permission constants. These permissions define access control for managing and reading the workflow runtime status, as well as reading, replaying, and deleting items in the bookmark queue dead-letter store.
src/common/Elsa.Api.Common · high confidence
Oracle persistence layer restored with LOB column handling and migration helpers
The EF Core Oracle persistence module has been re-established, introducing explicit entity configurations for Management and Runtime contexts to map large data fields to Oracle NCLOB and BLOB types, preventing truncation of workflow definitions, instances, and execution records. A new MigrationHelper class provides re-runnable PL/SQL logic to safely convert column datatypes without in-place alterations, addressing Oracle's restrictions on LOB modifications. The module also includes initial migration scaffolding for Identity and Alterations schemas, along with design-time DbContext factories to support database tooling.
src/modules/Elsa.Persistence.EFCore.Oracle · high confidence
PostgreSQL persistence for secrets with tenant scoping
This location introduces the PostgreSQL-backed persistence layer for the Secrets module, including the EF Core DbContext factory, extension methods for wiring the provider, and the shell feature registration. The database schema now supports multi-tenancy: a new TenantId column has been added to the Secrets table, and uniqueness is enforced by a composite unique index on (TenantId, NormalizedName). The migration logic ensures existing null TenantId values are stamped with an empty string and validates that no duplicate (TenantId, NormalizedName) keys exist before applying the constraint, ensuring secrets are properly scoped to tenants.
src/modules/Elsa.Secrets.Persistence.EFCore.PostgreSql · high confidence
PostgreSQL persistence layer restructured with multi-tenant support and improved migration handling
The PostgreSQL persistence module has been reorganized to support a multi-DbContext architecture (Identity, Management, Runtime, Labels, Alterations, Tenants) with dedicated design-time factories for each. This change introduces multi-tenancy support by adding a TenantId column to the AlterationJobs and AlterationPlans tables, along with corresponding database indexes. The migration infrastructure has been enhanced with helper methods for safe column alterations (DateTime and Boolean) and improved exception handling that transforms PostgreSQL-specific unique constraint violations into generic application exceptions. Additionally, the module now configures the WorkflowDefinition entity to use PostgreSQL's native JSONB type for the StringData property, and includes updated migrations that reflect schema changes such as renaming SerializedWorkflowInstanceIds to SerializedWorkflowInstanceFilter and changing Status columns from integer to text types.
src/modules/Elsa.Persistence.EFCore.PostgreSql · high confidence
Refactored alteration execution to commit state before re-importing workflow instances
The alteration runner now explicitly commits the modified workflow state to the persistence layer before re-importing it into the workflow runtime. This change ensures that the updated state is persisted during the alteration process, addressing previous issues where state might not have been correctly saved or where redundant save operations occurred. The refactoring also includes updates to the plan manager, job dispatcher, and scheduler to support this new execution flow, improving reliability and consistency of workflow alterations.
src/modules/Elsa.Alterations/Services · high confidence
Refactored workflow JSON serialization with configurable options and type aliasing
The serialization layer in Elsa.Common has been overhauled to use a new \ConfigurableSerializer\ base class that centralizes \JsonSerializerOptions\ management, including camel-case naming, null ignoring, and a standardized set of converters (such as \DecimalJsonConverter\ and \BigIntegerJsonConverter\). This change introduces a robust type aliasing system via \ISerializationTypeRegistry\ and \SerializationTypeResolver\, allowing workflows to serialize and deserialize types using stable aliases rather than full assembly-qualified names, which improves compatibility. Additionally, a new \ConfigurationJsonConverter\ enables direct serialization and deserialization of \IConfiguration\ objects, and the system now supports external configuration of serializer options through \ISerializationOptionsConfigurator\.
src/modules/Elsa.Common/Serialization · high confidence
Removes ReadLine activity from automatic registration
The Elsa feature configuration now explicitly excludes the ReadLine activity from automatic registration. This prevents containers from hanging when awaiting user input, requiring users to opt-in to this activity explicitly if needed.
src/modules/Elsa/Features · high confidence
SQL Server persistence layer restructured with modular DbContexts and updated Alterations schema
The SQL Server persistence module has been reorganized to support a modular architecture, introducing dedicated DbContext factories for Identity, Management, Runtime, Labels, Alterations, and Tenants. This change includes a database schema update for the Alterations module where the Status column in AlterationJobs and AlterationPlans tables has been migrated from an integer to a string type, and the SerializedWorkflowInstanceIds column was renamed to SerializedWorkflowInstanceFilter. Additionally, TenantId columns have been added to both AlterationJobs and AlterationPlans tables with corresponding indexes to support multi-tenancy.
src/modules/Elsa.Persistence.EFCore.SqlServer · high confidence
Structured authorization model and testing infrastructure for endpoint coverage
This change introduces a structured authorization model that requires every endpoint to explicitly declare its access level (via RequirePermission, RequireAuthenticatedOnly, or AllowAnonymous), eliminating the risk of ungated endpoints. To support this, a new EndpointCoverage test utility has been added to the shared testing library, which uses reflection to assert that all Elsa endpoints in an assembly have declared access. Additionally, a TestTenantAccessor is provided for tests to manage tenant context, and the Alterations module now defines stable permission constants and descriptors for inspecting and running alteration plans.
src/common/Elsa.Testing.Shared/Authorization, src/common/Elsa.Testing.Shared/Multitenancy, src/modules/Elsa.Alterations/Permissions · high confidence
Structured authorization model for API endpoints
API endpoints now use a structured authorization model that allows developers to declare specific resource and verb permissions (e.g., \RequirePermission\) or require authentication without specific grants (e.g., \RequireAuthenticatedOnly\). This change introduces new base classes (\ElsaEndpoint\*\) and an internal \EndpointSecurity\ helper that integrates with the \IPermissionEvaluator\ to enforce these rules, while preserving legacy string-based permission declarations for backward compatibility.
src/common/Elsa.Api.Common/Abstractions · high confidence
Structured authorization model with hierarchical permissions and wildcard support
The authorization system has been replaced with a structured model that uses hierarchical resource paths paired with verbs (e.g., 'workflows/definitions:view'). This change introduces support for wildcards, allowing grants to cover entire subtrees (e.g., 'workflows/\') or all verbs, ensuring forward compatibility with future resources. A new validation layer prevents malformed patterns (like 'workflows\') from being silently ignored, and a centralized registry allows modules to declare their supported resources and verbs, enabling consistent role editing and introspection across the application.
src/common/Elsa.Api.Common/Authorization, src/common/Elsa.Api.Common/Permissions · high confidence
Updated Elsa DSL lexer and parser generated files
The generated ANTLR 4.9.2 lexer and parser files for the Elsa DSL have been updated. This includes new or refreshed artifacts (ElsaLexer.java, ElsaParser.java, and their associated .interp, .tokens, listener, and visitor files) in the gen directory, reflecting changes to the underlying grammar definitions.
gen · high confidence
Updated brand assets and artwork
The design/logo directory has been updated with new artwork files, including the addition of a new PDF source file (Elsa.ai) and an updated vector logo (Esla\_vector-18.svg), replacing or supplementing previous versions to reflect the latest brand identity.
design/logo · high confidence
Updated custom icon artwork
The custom icon design in the \design/custom\ directory has been updated with a new Adobe Illustrator source file (\icon.ai\). This change replaces the previous icon asset with the latest version of the artwork, ensuring the visual identity reflects the current design specifications.
design/custom · high confidence
Updated migration generation scripts for database schema V3.4
The migration helper scripts in \scripts/migrations\ have been updated to generate Entity Framework Core migrations for database schema version V3.4. The \efcore-3.4.sh\ script now targets the 'Tenants' module alongside 'Alterations', 'Runtime', 'Management', 'Identity', and 'Labels' across all supported database providers (MySQL, SQL Server, SQLite, PostgreSQL, Oracle). This change reflects the addition of multitenancy support for background tasks and runtime tenant management, ensuring the database schema migrations align with the new tenant-aware data structures.
scripts/migrations · high confidence
Fixes
Prevent integration test crashes by adding Elsa background task shutdown
A new \ShutdownElsaAsync\ extension method has been added to the \Elsa.Testing.Extensions\ package to resolve crashes in ASP.NET Core integration tests. When using \WebApplicationFactory\, background and recurring tasks could continue running after the test host disposed resources, leading to errors. This method explicitly deactivates tenants to ensure all Elsa background tasks are properly stopped before the test environment is torn down.
src/extensions · high confidence
Test coverage
Added TLS CA trust validation smoke test script; Introduce component testing framework for Elsa workflows.
Dependencies
Adopts Central Package Management and upgrades to .NET 10
The project now uses Central Package Management (Directory.Packages.props) to define and version all NuGet dependencies in a single location, simplifying dependency updates across the solution. This change includes upgrading the primary target framework to .NET 10, with specific package versions pinned for .NET 10 (e.g., Microsoft.AspNetCore.\* 10.0.9, FastEndpoints 8.2.0) while maintaining compatibility versions for .NET 8 and 9. Key library upgrades visible in the manifest include FastEndpoints (7.1.1/8.2.0), Jint (4.15.3), and AutoMapper (16.0.0).
(dependencies) · high confidence
Housekeeping
Establishes repository development standards and build infrastructure
Introduces foundational configuration files that standardize the development environment and build process. An .editorconfig enforces consistent C\# coding conventions (4-space indentation, file-scoped namespaces, nullability), while .gitignore prevents build artifacts and IDE files from being committed. New documentation files (AGENTS.md, CLAUDE.md, CONTEXT.md, CONTRIBUTING.md) define project structure, testing guidelines, and contribution workflows. Build automation is standardized via Directory.Build.props and Directory.Build.targets, which centralize package metadata, enable NuGet security auditing, and enforce correct ConfigureAwait.Fody weaving to prevent silent build failures.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 62 → 64 (+1.7)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 78 → 78 (-0.7)
- Architecture 67 → 67 (-0.5)
- Maturity 81 → 83 (+2.1)
- Readiness 71 → 73 (+1.4)
- Security 55 → 62 (+7.5)
- Event-Driven 100 → 100 (+0.0)
- Accessibility 66 → 66 (+0.0)
- Performance 72 → 62 (-10.1)
Resolved (181)
- BarePragmaDisable (src/modules/Elsa.Persistence.EFCore.MySql/DbContextFactories.cs)
- BarePragmaDisable (src/modules/Elsa.Persistence.EFCore.Oracle/DbContextFactories.cs)
- BarePragmaDisable (src/modules/Elsa.Persistence.EFCore.PostgreSql/DbContextFactories.cs)
- BarePragmaDisable (src/modules/Elsa.Persistence.EFCore.SqlServer/DbContextFactories.cs)
- BarePragmaDisable (src/modules/Elsa.Persistence.EFCore.Sqlite/DbContextFactories.cs)
- Build status unknown
- Change coupling: EvictWorkflowDefinitionServiceCache.cs ↔ RefreshActivityRegistry.cs (src/modules/Elsa.Workflows.Management/Handlers/Notifications/EvictWorkflowDefinitionServiceCache.cs)
- Change coupling: EvictWorkflowDefinitionServiceCache.cs ↔ WorkflowDefinitionPublisher.cs (src/modules/Elsa.Workflows.Management/Handlers/Notifications/EvictWorkflowDefinitionServiceCache.cs)
- CommentedOutCode (src/clients/Elsa.Api.Client/Shared/Models/Container.cs)
- CommentedOutCode (src/clients/Elsa.Api.Client/Shared/Models/Container.cs)
- CommentedOutCode (src/modules/Elsa.Workflows.Core/Services/PropertyOptionsResolver.cs)
- CommentedOutCode (src/modules/Elsa.Workflows.Core/Services/PropertyOptionsResolver.cs)
- CommentedOutCode (src/modules/Elsa.Workflows.Core/Services/PropertyOptionsResolver.cs)
- CommentedOutCode (src/modules/Elsa.Workflows.Core/State/PersistentVariableState.cs)
- CommentedOutCode (src/modules/Elsa.Workflows.Core/State/PersistentVariableState.cs)
- Consequences section begins but only one consequence (reflecting a failed state) is listed; trade-offs of the alternative considered are not mentioned (doc/adr/0002-fault-propagation-from-child-to-parent-activities.md)
- Context and decision are both boilerplate filler; the body gives no rationale for why ADRs were chosen (vs. alternatives like a wiki or commit log) and no consequences beyond citing Nygard's article (doc/adr/0001-record-architecture-decisions.md)
- Duplicated block (10 lines × 2) (src/modules/Elsa.Expressions.CSharp/Handlers/GenerateArgumentAccessors.cs)
- Duplicated block (11 lines × 2) (src/modules/Elsa.Http/Activities/DownloadHttpFile.cs)
- Duplicated block (11 lines × 3) (src/modules/Elsa.Persistence.EFCore.Common/Extensions/BulkUpsertExtensions.cs)
- …and 161 more
New (868)
- BpmnProcess.AddStartTriggerPayload (cognitive 20) (src/modules/Elsa.Bpmn/Activities/BpmnProcess.cs)
- BulkPublish.ExecuteAsync (cognitive 18) (src/modules/Elsa.Workflows.Api/Endpoints/WorkflowDefinitions/BulkPublish/Endpoint.cs)
- CRAP 30: BackgroundJobProcessor.ProcessJobsAsync (src/common/Elsa.Mediator/Services/BackgroundJobProcessor.cs)
- Change coupling: Endpoint.cs ↔ Endpoint.cs (src/modules/Elsa.Workflows.Api/Endpoints/WorkflowDefinitions/Export/Endpoint.cs)
- Change coupling: Endpoint.cs ↔ Endpoint.cs (src/modules/Elsa.Workflows.Api/Endpoints/WorkflowDefinitions/Import/Endpoint.cs)
- ClassTooLong: DefaultUserTaskManager (src/modules/Elsa.UserTasks/Services/DefaultUserTaskManager.cs)
- ClassTooLong: ElsaParser (gen/ElsaParser.java)
- ClassTooLong: ExternalAuthenticationBroker (src/modules/Elsa.ExternalAuthentication/Services/ExternalAuthenticationBroker.cs)
- Consequences are one bullet ('Allows composite activities to reflect a failed state immediately...') with no trade-offs or alternatives considered (e.g. query runtime vs aggregate-count cost) (doc/adr/0002-fault-propagation-from-child-to-parent-activities.md)
- Context and decision are both boilerplate ('We need to record the architectural decisions made on this project.') plus a citation; no real problem statement or explicit decision body (doc/adr/0001-record-architecture-decisions.md)
- CreateSchedulesStartupTask.ScheduleBookmarksAsync (cognitive 16) (src/modules/Elsa.Scheduling/StartupTasks/CreateSchedulesStartupTask.cs)
- Cross-context type BrokerInitiationResult (Elsa.ExternalAuthentication → performance)
- Cross-context type ConnectionObservation (Elsa.ExternalAuthentication → Elsa.ExternalAuthentication.Persistence.EFCore)
- Cross-context type ConnectionObservation (Elsa.ExternalAuthentication → Elsa.ExternalAuthentication.Persistence.EFCore)
- Cross-context type ConnectionTestContext (Elsa.ExternalAuthentication → Elsa.ExternalAuthentication.OpenIdConnect)
- Cross-context type ConnectionTestResult (Elsa.ExternalAuthentication → Elsa.ExternalAuthentication.OpenIdConnect)
- Cross-context type ConnectionValidationContext (Elsa.ExternalAuthentication → Elsa.ExternalAuthentication.OpenIdConnect)
- Cross-context type ConnectionValidationError (Elsa.ExternalAuthentication → Elsa.ExternalAuthentication.OpenIdConnect)
- Cross-context type ConnectionValidationResult (Elsa.ExternalAuthentication → Elsa.ExternalAuthentication.OpenIdConnect)
- Cross-context type CreateWorkflowInstanceResponse (Elsa.Workflows.Runtime → Elsa.Workflows.Runtime.Distributed)
- …and 848 more
Changes since last survey
- 183 commits — 106 feature/other, 77 fixes
By area
- src/modules — 89 commits
- test/integration — 18 commits
- (repo) — 16 commits
- test/unit — 15 commits
- (root) — 12 commits
- .agents/skills — 6 commits
- .github/workflows — 4 commits
- doc/wiki — 4 commits
- test/component — 4 commits
- specs/013-rbac-authorization-model — 3 commits
- src/apps — 3 commits
- doc/migrations — 2 commits
- src/common — 2 commits
- .github/actions — 1 commit
- build/_build.csproj — 1 commit
- design/video — 1 commit
- doc/security-assessment — 1 commit
- src/PackageManifest.props — 1 commit
Notable commits
- fix: Fix Alterations ownership parity and MySQL retry (#8133)
- fix: Fix MemoryRoleStore global role ID uniqueness (#8127)
- fix: Fix StateMachine transition lifecycle ordering
- fix: Fix UserTasks net10 EmptyRequest compilation (#8031)
- fix: Fix scheduling startup backlog catch-up
- fix: Merge pull request #7917 from Shivamkmr8/improve-revert-version-allocation
- fix: Merge pull request #7919 from elsa-workflows/claude/fix-nuke-nuget-frameworks
- fix: Merge pull request #7920 from elsa-workflows/claude/fix-wiki-link-check
- fix: Use last version for revert version allocation
- fix: fix(alterations): atomic EF tenant ownership on Save/SaveMany (#8128)
- fix: fix(alterations): honor tenant isolation in Memory alteration stores (#8106)
- fix: fix(alterations): preserve tenant context for background alteration jobs (#7962)
- fix: fix(auth): validate wildcard permission patterns and warn on deny-list stripping (#7997)
- fix: fix(bpmn): detect designer-edited drafts as stale BPMN source (#8065)
- fix: fix(bpmn): keep a top-level call activity's fire-and-forget flag through the document PUT (#8082)
- fix: fix(bpmn): keep subprocess bodies through the document PUT (#8077)
- fix: fix(bpmn): let a process with only a plain start event publish (#8081)
- fix: fix(bpmn): let the graph hash alone decide BPMN source staleness (#8079)
- fix: fix(bpmn): make document PUT If-Match and save a compare-and-swap (#8092)
- fix: fix(bpmn): refuse documents with duplicate element ids before recursion (#8080)
- …and 163 more
API surface
- Unchanged — 6 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
elsa-workflows/elsa-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 610790ec57ae9d5c334181d50c1e65f99613fd86 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.