fullstackhero/dotnet-starter-kit
61.7
Weak · 21 September 2026
102.6k
lines of production code
TypeScript
with C#
1
measurement over time
What this system is
This system is a multi-tenant SaaS platform framework built on .NET 10 and React 19, providing the core infrastructure for managing tenants, users, and billing. It includes a comprehensive admin console for platform operators to manage identity, subscriptions, and system health, alongside a customizable tenant-facing dashboard for end-users to manage their own resources, catalog, and communications. The backend leverages a modular architecture with built-in support for event-driven messaging, background jobs, and real-time updates via SignalR and SSE, all deployable via Docker or AWS infrastructure.
How it got here
2021–2025 — Framework initialization and core module development
72 changes.
The project was initialized with a .NET 10 and React 19 stack, establishing a modular architecture with comprehensive building blocks for identity, multitenancy, auditing, and eventing. This period focused on defining the core infrastructure, including transactional outbox patterns, hybrid caching, and S3-compatible storage, while implementing the initial v1 APIs for user management and tenant lifecycle.
2026 — multi-module expansion and infrastructure modernization
146 changes.
This period focused on expanding the platform with new core modules for billing, chat, tickets, and file management, while introducing advanced identity features like impersonation and two-factor authentication. Concurrently, the project modernized its infrastructure by adopting Terraform for AWS deployment, implementing a transactional outbox for reliable eventing, and rebuilding the admin and dashboard clients with React 19 and a unified design system.
Features
Add HTTP request idempotency middleware
The framework now includes an idempotency mechanism for POST, PUT, and PATCH requests. By adding the \.WithIdempotency()\ filter to an endpoint, clients can send an \Idempotency-Key\ header; if a request with that key has already been processed, the system replays the cached response instead of executing the handler again. This uses the new HybridCache infrastructure for storage and supports tenant isolation and tag-based invalidation.
src/BuildingBlocks/Web/Idempotency · high confidence
Add OpenTelemetry metrics for outbox dead-lettering and recovery
The eventing building block now exposes OpenTelemetry metrics to monitor outbox message reliability. Users can track the number of messages that exhaust their retries and are moved to a dead-letter state, as well as the count of dead-lettered messages that are successfully reset and redriven for another dispatch attempt.
src/BuildingBlocks/Eventing/Telemetry · high confidence
Add SendGrid as an alternative mailing provider
The mailing subsystem now supports SendGrid alongside the existing SMTP provider. A new \SendGridMailService\ implements the \IMailService\ interface, allowing users to configure and send emails via SendGrid. The implementation includes robust error handling: it throws exceptions for transient failures (429 rate limits, 5xx server errors) to enable automatic retries, while logging permanent rejections (e.g., invalid API keys) without retrying to avoid dead-letter queue flooding.
src/BuildingBlocks/Mailing/Services · high confidence
Add Server-Sent Events (SSE) infrastructure for real-time push
This change introduces the core infrastructure for Server-Sent Events, enabling real-time push notifications to web clients. It adds a DI registration (\AddHeroSse\) and an endpoint mapper (\MapHeroSseEndpoints\) that expose two routes: \POST /api/v1/sse/token\ for issuing short-lived, single-use authentication tokens (required because browsers cannot send Authorization headers with EventSource), and \GET /api/v1/sse/stream\ for the actual event stream. The implementation includes an \SseConnectionManager\ for tracking active connections by user and tenant, supporting targeted sends and broadcasts. To ensure immediate client connectivity, the stream endpoint eagerly flushes headers and sends an initial comment, while also handling HTTP/2 compatibility by omitting the \Connection\ header and disabling proxy buffering via \X-Accel-Buffering\.
src/BuildingBlocks/Web/Sse · high confidence
Add Terraform environment configurations for dev, staging, and prod
New Terraform variable and backend configuration files have been added for the dev (us-east-1 and ap-south-1), staging, and production environments. These files define the infrastructure parameters for each stage, including distinct VPC CIDR blocks, S3 bucket naming conventions, and database settings. The production configuration enables high-availability features such as multi-AZ databases, WAF protection, and autoscaling, while the dev environment introduces a new ap-south-1 region deployment with specific networking and Fargate Spot settings.
deploy/terraform/apps/starter/envs · high confidence
Add configurable security headers middleware
The application now includes a new security headers middleware that automatically adds standard hardening headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, X-XSS-Protection) and a configurable Content-Security-Policy to HTTP responses. This feature is enabled by default but can be disabled or tuned via options, including specific excluded paths (such as /scalar and /openapi) and custom script/style sources for CSP compliance.
src/BuildingBlocks/Web/Security · high confidence
Add contracts for user impersonation management
Introduces the API contracts for the new user impersonation feature, allowing administrators to start, end, and revoke impersonation sessions. This includes the StartImpersonationCommand for initiating a session with a target user and optional duration, EndImpersonationCommand to terminate an active session, and RevokeImpersonationGrantCommand to cancel a grant with a reason. It also defines the GetImpersonationGrantsQuery for listing grants with filters for status, actor, and tenant, alongside the ImpersonationGrantDto and ImpersonationResponse records to structure the data returned to clients.
src/Modules/Identity/Modules.Identity.Contracts/v1/Impersonation · high confidence
Add dedicated health check endpoints and Redis/Hangfire probes
The application now exposes /health/live and /health/readiness endpoints to support container orchestration probes. The liveness endpoint performs a lightweight process check, while the readiness endpoint verifies external dependencies and returns a 503 status if any check fails. New health checks have been added to specifically validate Redis connectivity (via a round-trip cache operation) and Hangfire storage accessibility.
src/BuildingBlocks/Web/Health · high confidence
Add full-text message search in chat
Users can now search chat messages using full-text search powered by Postgres tsvector. The new /search endpoint accepts a query string, optional channel scope, and pagination parameters, returning messages from channels the user is a member of. Results are ranked by relevance and include message attachments, mentions, and reactions.
src/Modules/Chat/Modules.Chat/Features/v1/Search · high confidence
Add tenant-aware feature flag support for web endpoints
The web building block now includes a feature flag system that supports tenant-specific overrides. Developers can register the feature management services via \AddHeroFeatureFlags\, which configures a \TenantFeatureFilter\ to enable or disable features based on the current tenant ID (resolved from the multi-tenant context or request headers). Additionally, a new \RequireFeature\ extension allows gating individual API endpoints behind feature flags, returning a 404 Not Found when the specified feature is disabled for the current tenant.
src/BuildingBlocks/Web/FeatureFlags · high confidence
Added HTTP request samples for identity, tenant, and health endpoints
New .http files have been added to the Requests directory, providing ready-to-use examples for testing the API. These include samples for identity operations (roles, users, tokens), multitenancy management (tenants), and system health checks (root, liveness, readiness).
src/Host/FSH.Starter.Api/Requests · high confidence
Added Identity Groups API contracts
The Identity module now exposes a complete set of command and query contracts for managing user groups. This includes operations to create, update, and delete groups, as well as retrieve group details and lists. Additionally, it supports managing group membership by adding or removing users from a group, with responses providing details such as the count of added users and IDs of those who were already members.
src/Modules/Identity/Modules.Identity.Contracts/v1/Groups · high confidence
Added TOTP two-factor authentication contracts
The identity module now exposes the command contracts required to manage Time-based One-Time Password (TOTP) two-factor authentication. Users can initiate enrollment via the new EnrollTwoFactorCommand, which generates a shared secret and QR code URI; confirm the setup using VerifyEnrollTwoFactorCommand; and disable the feature entirely with DisableTwoFactorCommand, which requires the current password for security.
src/Modules/Identity/Modules.Identity.Contracts/v1/TwoFactor · high confidence
Adds configurable HTTP resilience infrastructure for external calls
This change introduces a new building block for managing HTTP client resilience, allowing services to automatically apply retry, circuit breaker, and timeout policies to outgoing requests. The implementation uses the Microsoft.Extensions.Http.Resilience library and exposes an \AddHeroResilience\ extension method that reads settings from the \HttpResilienceOptions\ configuration section. Users can now control key behaviors such as the maximum number of retry attempts (default 3), retry delay (default 1 second), total request timeout (default 30 seconds), and circuit breaker thresholds (default 50% failure ratio, 5-second break duration) via configuration, with the ability to globally enable or disable the feature.
src/BuildingBlocks/Web/HttpResilience · high confidence
Admin UI: Image upload component and presigned upload hook
The admin interface now includes a new \ImageInput\ component and a \useFileUpload\ hook that enable users to upload images via a three-step presigned URL protocol (request URL, PUT to storage, finalize) or paste an external image URL. The component supports mode toggling between file upload and URL pasting, displays real-time upload progress, enforces client-side extension and size limits, and handles errors with toast notifications. The underlying hook orchestrates the upload lifecycle, including cancellation and progress tracking via XMLHttpRequest.
clients/admin/src/components/file, clients/admin/src/hooks · high confidence
Admin app rebuild with theme support and webhook creation UI
The admin application has been rebuilt, introducing a new theme system that allows users to toggle between light and dark modes with persistence, and a new interface for creating webhook subscriptions. Users can now define webhook endpoints with optional HMAC-SHA256 signing secrets and select specific event types to subscribe to, with validation ensuring at least one event is selected before submission.
clients/admin/src/components/theme, clients/admin/src/components/webhooks · high confidence
Admin console adopts new design tokens and global styles
The admin console now uses a new global stylesheet (globals.css) that defines a comprehensive design token system based on oklch color scales. This introduces a new neutral palette (removing the previous warm cream tint), a primary rose brand accent, and semantic variables for surfaces, typography (Outfit, Figtree, JetBrains Mono), and motion. The styles are shadcn-compatible, ensuring existing UI primitives continue to work while providing a consistent, accessible visual foundation for the admin interface.
clients/admin/src/styles · high confidence
Admin console authentication and session management
The admin console now includes a complete authentication layer built on React Context and local storage. It handles token issuance, silent refresh at boot to prevent flash-of-unauthenticated-content, and cross-tab session synchronization. A new inactivity guard tracks user activity across tabs, displaying a warning modal before automatically logging the user out. Route protection is enforced via a ProtectedRoute component for general authentication and a RouteGuard component for granular, permission-based access control.
clients/admin/src/auth · high confidence
Admin console introduces inactivity auto-logout and unified auth shell
The admin console now automatically signs out users after a period of inactivity, displaying a forced-choice modal with a visual countdown ring that warns users before termination. This feature is driven by runtime configuration values (inactivityIdleMs, inactivityWarningMs) and is implemented via a new InactivityGuard component. Additionally, a new AuthShell component standardizes the split-screen visual aesthetic (brand stage on the left, form on the right) across all unauthenticated surfaces like password recovery and email confirmation. A new DemoAccountsDialog has also been added to allow developers to instantly sign in as pre-configured operator accounts during development.
clients/admin/src/components/auth · high confidence
Admin console scaffolding with API client and permission system
The admin console now includes a dedicated API client library that handles authentication, automatic token refresh, tenant context propagation, and structured error parsing for user-facing messages. A comprehensive permission catalog mirrors server-side authorization rules, enabling the UI to enforce role-based access control and render assignable permissions for the role editor. Additionally, a React Query client is configured with specific retry logic that prevents retrying on 401/403 errors to ensure proper session handling.
clients/admin/src/lib · high confidence
Audit module v1 API endpoints and handlers
This change introduces the v1 implementation of the Auditing module's read endpoints, providing users with the ability to retrieve individual audit records, list and search audit events with pagination and filters, view aggregate summaries by type/severity/source/tenant, and query specific subsets like security or exception audits. The implementation includes dedicated endpoints for tracing events by correlation ID and trace ID, with built-in tenant isolation, cross-tenant permission checks, time-window constraints (90-day max, 7-day default), and payload JSON search capabilities.
src/Modules/Auditing/Modules.Auditing/Features/v1 · high confidence
Auditing module persistence layer with JSONB search and retention
The Auditing module now includes a dedicated persistence layer that stores audit records in a PostgreSQL database. This implementation enables efficient querying of audit data by adding composite indexes for tenant and time-based filtering, as well as GIN indexes on the JSONB payload and text fields to support fast ILIKE searches. A background retention job automatically purges old audit events in batches to manage storage, while a save-changes interceptor captures entity modifications. Additionally, a file-based dead-letter queue ensures audit events are preserved even if the primary database sink fails.
src/Modules/Auditing/Modules.Auditing/Persistence · high confidence
Auditing module service registration and HTTP middleware
The auditing module now registers its core infrastructure services, including the audit client, security audit, database context, serializer, and background worker, via the new AddAuditingCore extension method. It also exposes UseAuditHttp to add the auditing middleware to the application pipeline, enabling HTTP request auditing.
src/Modules/Auditing/Modules.Auditing/Infrastructure/Hosting · high confidence
Automated background jobs for purging deleted and orphaned files
The Files module now includes two new Hangfire jobs to automatically clean up file assets. PurgeDeletedFilesJob runs daily to hard-delete soft-deleted files that have exceeded the configured retention period, removing their storage bytes and refunding the associated storage quota. PurgeOrphanedFilesJob runs hourly to remove file assets stuck in a PendingUpload state past their deadline, cleaning up any uploaded bytes without affecting quota since those bytes were never debited.
src/Modules/Files/Modules.Files/Jobs · high confidence
Billing database schema expanded with wallet, top-up, and plan interval support
The PostgreSQL billing schema has been extended to support prepaid wallet top-ups and more flexible billing plans. New tables include Wallets and WalletTransactions for managing prepaid balances, and TopupRequests to handle the lifecycle of top-up approvals. The Plans table now supports annual pricing and billing intervals, while Invoices have been enriched with period start/end dates and a purpose field to distinguish between different invoice types. A unique constraint on wallet transaction reference IDs ensures idempotency for top-up credits.
src/Host/FSH.Starter.Migrations.PostgreSQL/Billing · high confidence
Billing module database context and default plan seeding
The billing module now includes its own Entity Framework Core context (BillingDbContext) using the 'billing' schema, exposing entities for plans, subscriptions, invoices, usage snapshots, wallets, and top-up requests. A database initializer has been added to automatically apply migrations and seed default subscription plans (free, pro, pro-annual) on startup if none exist.
src/Modules/Billing/Modules.Billing/Data · high confidence
Billing module database schema and configuration
This change introduces the Entity Framework Core configurations for the new internal billing module, defining the database schema for billing entities. It establishes tables for Billing Plans (supporting monthly/annual pricing and JSON-based overage rates), Invoices (with distinct purposes for usage and subscriptions), Invoice Line Items, Subscriptions, Usage Snapshots, and Wallets (including transactions and top-up requests). The configuration enforces data integrity through unique constraints, such as one active subscription per tenant, unique invoices per period and purpose, and exactly-once top-up credits via wallet transactions.
src/Modules/Billing/Modules.Billing/Data/Configurations · high confidence
Catalog module API contracts for brands, categories, and products
This change introduces the v1 API contracts for the Catalog module, defining the commands, queries, and DTOs for managing Brands, Categories, and Products. It enables soft-delete and restore operations for all three entity types, supports multi-image product management (including adding, removing, reordering, and setting thumbnails), and provides search and list capabilities with pagination and sorting. The contracts also define specific authorization permissions for viewing, creating, updating, deleting, restoring, and adjusting stock for products.
src/Modules/Catalog/Modules.Catalog.Contracts · high confidence
Catalog module introduces multi-image support with soft-delete and file access policies
The Catalog module now supports attaching multiple images to products, including setting a thumbnail (cover image), reordering, and removing images, with the first attached image automatically becoming the thumbnail. Products, brands, and categories now support soft-delete and restore operations, allowing items to be hidden from standard views while preserving data integrity. The module also integrates with the Files module via a new ProductFileAccessPolicy, defining specific permissions for attaching, reading, and deleting product images, and includes a database initializer that seeds demo catalog data for tenant environments.
src/Modules/Catalog/Modules.Catalog · high confidence
Catalog v1 API: Brand, Category, and Product Image management endpoints
This change introduces the v1 API implementation for managing Brands, Categories, and Product Images within the Catalog module. For Brands, it adds full CRUD operations (Create, Read, Update, Delete), search with pagination and sorting, and soft-delete capabilities including listing and restoring trashed brands. For Categories, it provides CRUD operations, a hierarchical tree view endpoint, search with parent filtering, and soft-delete/restore functionality, including cycle detection when updating parent relationships. For Products, it adds the ability to attach images to existing products. All endpoints are secured with specific permissions and follow the existing Mediator pattern.
src/Modules/Catalog/Modules.Catalog/Features/v1 · high confidence
Centralized identity permission definitions for users, roles, sessions, and impersonation
A new centralized registry of identity permissions has been introduced in the Identity module's contracts layer. This file defines string-based permission constants for managing Users, UserRoles, Roles, RoleClaims, Sessions, Groups, and Impersonation, and aggregates them into a single list. This ensures that permission strings used for authorization checks remain consistent with the registered permission metadata, preventing drift between UI controls and backend policy enforcement.
src/Modules/Identity/Modules.Identity.Contracts/Authorization · high confidence
Chat domain model for channels, messages, and interactions
The chat module's domain layer now includes the core aggregates for chat functionality: ChatChannel (supporting 1:1 DMs, group DMs, and named channels with soft-delete/restore), Message (with support for attachments, mentions, reactions, editing, soft-deletion, and pinning), and associated entities like ChannelMember and MessageReaction. Domain events are introduced for channel creation, member changes, and message lifecycle events (created, edited, deleted, pinned, unpinned).
src/Modules/Chat/Modules.Chat/Domain · high confidence
Chat module adds mention parsing and real-time channel membership services
The chat module introduces new services to support @username mentions and real-time channel access. MentionParser extracts @username tokens from message bodies using a conservative regex, while MentionResolver maps those usernames to user IDs by fetching the active user list. ChannelMembershipChecker verifies if a user belongs to a specific channel, and UserChannelLookup retrieves all channels a user is a member of to pre-join connections upon connecting to the SignalR hub.
src/Modules/Chat/Modules.Chat/Services · high confidence
Chat module database schema and migration updates
The chat module's PostgreSQL database schema has been established and extended with several new capabilities. The initial migration creates core tables for channels, members, messages, and attachments. Subsequent migrations add support for message mentions (tracking @username references), message reactions (with unique constraints per user/emoji), and full-text search on message bodies using a PostgreSQL tsvector column. The schema also introduces message pinning, allowing users to pin specific messages within a channel, and implements multi-tenancy isolation by adding a TenantId column to the ChannelMembers table to ensure data separation between tenants.
src/Host/FSH.Starter.Migrations.PostgreSQL/Chat · high confidence
Chat module database schema and persistence layer introduced
The Chat module now includes its dedicated Entity Framework Core context (ChatDbContext) and database initializer, establishing a persistent storage layer for chat features. This change introduces the database schema for core domain entities including Channels, Messages, Channel Members, Message Attachments, Mentions, and Reactions, along with the specific EF configurations required to map these entities to the database. This provides the underlying data structure necessary for the chat functionality to store and retrieve messages, manage channel memberships, and handle attachments and interactions.
src/Modules/Chat/Modules.Chat/Data · high confidence
Chat module v1 contracts: commands, queries, and DTOs
The Chat module now exposes a v1 contract layer defining the wire format for chat operations. This includes commands for channel management (create, update, archive, restore, add/remove members), message handling (send, edit, delete, pin/unpin, reactions), and direct messaging (find or create). Queries allow listing channels, retrieving channel details, paginating messages and thread replies, discovering channels, and performing full-text message search. Data transfer objects define the structure for channels, members, messages (including attachments, reactions, and pinning metadata), and enums for channel types and member roles.
src/Modules/Chat/Modules.Chat.Contracts/v1 · high confidence
Chat v1 message management: send, edit, delete, pin, and react
This location introduces the v1 API endpoints and handlers for managing chat messages within a channel. Users can now send messages (including replies and attachments) with @username mention resolution, edit or delete their own messages (with moderators able to delete any), and pin or unpin messages to a channel. Additionally, users can add or remove emoji reactions on messages. All actions are authorized against channel membership and broadcast in real-time via SignalR to keep clients synchronized.
src/Modules/Chat/Modules.Chat/Features/v1/Messages · high confidence
Dashboard authentication with secure impersonation and inactivity timeouts
The dashboard now includes a complete authentication layer that handles login, session management, and security policies. It supports secure cross-app impersonation via URL hash tokens to prevent leakage, ensuring operators can switch contexts without exposing credentials. The system enforces inactivity auto-logout with a warning modal, automatically signing out users after a period of silence. Additionally, it improves session reliability by performing silent token refreshes at boot to prevent stale-token loops and correctly resolves user display names from JWT claims.
clients/dashboard/src/auth · high confidence
Dashboard layout overhaul with command palette, permission-gated navigation, and session safety banners
The dashboard shell has been redesigned to include a new command palette (⌘K) for quick navigation and actions, a collapsible sidebar with persisted state, and a redesigned topbar with a profile dropdown. Navigation items are now permission-gated to mirror server-side authorization, ensuring users only see links they can access. The layout also introduces an impersonation banner to clearly indicate when an operator is acting on behalf of another user, and an expiry banner to alert tenants about subscription status. Additionally, an inactivity guard has been added to auto-logout users after a period of inactivity, and mobile navigation has been implemented via a drawer.
clients/dashboard/src/components/layout · high confidence
Files module introduces presigned-URL lifecycle and automated retention
The new Files module provides a complete lifecycle for file assets using presigned URLs, exposing endpoints for uploading, finalizing, downloading, listing (including shared and trashed files), and restoring files. It includes configurable retention policies via appsettings, with background Hangfire jobs that automatically purge orphaned pending uploads hourly and permanently delete soft-deleted files after 30 days.
src/Modules/Files/Modules.Files · high confidence
Files module v1 API: upload, visibility, sharing, and trash management
This location introduces the v1 feature handlers, validators, and endpoints for the Files module, enabling a complete file lifecycle. Users can now request presigned upload URLs with category and quota validation, finalize uploads with virus scanning and outbox-based event publishing, and manage file visibility (Public/Private) with policy-gated authorization. The API supports listing personal files, viewing a tenant-wide 'Shared' feed of public files, and retrieving metadata or short-lived presigned download URLs. Additionally, soft-delete functionality is exposed via a trash view and a restore endpoint, allowing administrators to recover deleted assets.
src/Modules/Files/Modules.Files/Features/v1 · high confidence
HTTP request/response body auditing with PII masking and stable source keys
The auditing module now captures and records the bodies of HTTP requests and responses, enabling detailed inspection of API activity in the audit center. To protect sensitive data, captured bodies are automatically masked for Personally Identifiable Information (PII) before storage. The system also introduces stable, dashboard-friendly source keys (e.g., \api.identity.RegisterUser\) derived from route names and module slugs, allowing users to reliably filter and pin specific endpoint audits. Additionally, endpoints can opt out of body capture or skip auditing entirely using the \\[NoAudit\]\ attribute, and audit tags now reflect whether PII was masked or if a request was rejected due to quota limits.
src/Modules/Auditing/Modules.Auditing/Infrastructure/Http · high confidence
Identity database schema expanded with session management, user groups, and impersonation support
The PostgreSQL identity schema has been extended to support advanced identity features. A new 'UserSessions' table tracks active sessions with device details, IP addresses, and revocation status, including an index on expiration time for efficient cleanup. User organization is now supported via 'Groups', 'UserGroups', and 'GroupRoles' tables, allowing users to be assigned to groups with associated roles. Additionally, the schema includes infrastructure for impersonation grants, enabling administrators to act on behalf of other users. These changes are reflected in the 'identity' schema within the database.
src/Host/FSH.Starter.Migrations.PostgreSQL/Identity · high confidence
Identity module initialization with authentication, user management, and security features
The Identity module is introduced, providing a complete identity management system including JWT-based authentication, user registration, profile management, and role/group administration. Key security features include TOTP two-factor authentication, account lockout after five failed login attempts, password history enforcement, and user impersonation with audit trails. The module also supports tenant-aware session management, allowing administrators to view and revoke sessions, and integrates with a billing grace period configuration to control login access for expired subscriptions. Additionally, it exposes metrics for generated tokens and registers health checks for its database context.
src/Modules/Identity/Modules.Identity · high confidence
Identity module introduces domain events for user lifecycle actions
The Identity module now exposes a set of domain events to signal key user lifecycle changes, enabling external systems or internal handlers to react to these occurrences. Specifically, the following events have been added: PasswordChangedEvent (triggered when a user changes their password, including resets), SessionRevokedEvent (triggered when a user session is revoked), UserActivatedEvent and UserDeactivatedEvent (triggered when user accounts are activated or deactivated, respectively), UserRegisteredEvent (triggered upon new user registration), and UserRoleAssignedEvent (triggered when roles are assigned to a user). Each event carries relevant context such as the user ID, timestamp, and optional correlation or tenant identifiers.
src/Modules/Identity/Modules.Identity/Domain/Events · high confidence
Identity module introduces session management, impersonation, and password policy services
The Identity module adds several new capabilities: session management with device classification and background cleanup, user impersonation with grant tracking and caching, and password policies including history enforcement and expiry checks. It also introduces a new CurrentUserService for consistent user context, a RequestContextService for request metadata, and a UserCountQuotaGaugeProvider for tenant user limits. The module now supports group-based roles, TOTP two-factor authentication, and improved permission caching with HybridCache.
src/Modules/Identity/Modules.Identity/Services · high confidence
Introduce Auditing module with API endpoints and background retention
The new Auditing module provides REST API endpoints (v1) for retrieving audit logs, including summaries, security events, and exception details, accessible via the /api/v{version}/audits route. It automatically registers an EF Core DbContext, health checks, and a background Hangfire job to purge old audit records based on configurable retention policies, while intercepting database changes to capture audit trails.
src/Modules/Auditing/Modules.Auditing · high confidence
Introduce Chat module with Slack-style messaging, channel management, and file access policies
The new Chat module (order 800) provides Slack-style messaging including DMs, group DMs, and named channels. It exposes API endpoints for channel lifecycle (create, update, archive, restore, member management, discovery) and message operations (send, edit, delete, pin/unpin, reactions, thread replies, and full-text search via Postgres tsvector). File attachments for chat channels are governed by a dedicated access policy that allows members to attach and read files, while only the uploader can delete them. The module integrates with Identity for @username resolution, uses SignalR with a Redis backplane for real-time updates, and registers health checks for its database context.
src/Modules/Chat/Modules.Chat · high confidence
Introduce Hangfire-based background job infrastructure with multi-tenant support
The application now includes a dedicated job processing subsystem using Hangfire, registered via the new \AddHeroJobs\ extension. This infrastructure supports PostgreSQL and SQL Server storage backends, configurable via \HangfireOptions\ (which enforce required username/password credentials for the dashboard). Key features include multi-tenant context propagation, where job filters automatically inject the current tenant and user ID into background jobs, and a dedicated \HangfireStaleLockCleanupService\ that runs as a hosted service to clean up stale locks in PostgreSQL. The Hangfire dashboard is secured with basic authentication and exposes telemetry via a custom filter that integrates with .NET Activity tracing.
src/BuildingBlocks/Jobs · high confidence
Introduce Notifications module with inbox REST API and billing email integration
This change adds the Notifications module, providing a new REST API for managing a per-user notification inbox (GET /api/v1/notifications, GET /api/v1/notifications/unread-count, POST /api/v1/notifications/read-all, POST /api/v1/notifications/{id}/read) backed by a dedicated database schema and tenant-aware context. It also wires up integration-event handlers that automatically send tenant-admin billing emails (nearing expiry, grace period, expired, and invoice issued) and create inbox notifications for chat mentions, including live SignalR updates for new mentions.
src/Modules/Notifications · high confidence
Introduce RabbitMQ-based distributed event bus
Added a new RabbitMQ implementation for the event bus in the BuildingBlocks layer, enabling distributed event publishing via a durable topic exchange. The \RabbitMqEventBus\ class handles connection management, automatic reconnection on failure, and configurable retry logic for publishing integration events. Configuration is exposed through \RabbitMqOptions\, allowing users to specify host, port, credentials, virtual host, exchange name, SSL usage, and retry settings.
src/BuildingBlocks/Eventing/RabbitMq · high confidence
Introduce S3-compatible storage backend with MinIO support
The application now supports storing files in Amazon S3 or any S3-compatible service (such as MinIO) via a new \S3StorageService\ implementation. This change adds configuration options for bucket, region, prefix, public access settings, and explicit credentials, including a \ServiceUrl\ to target custom endpoints and \ForcePathStyle\ for compatibility with services like MinIO that do not support virtual-hosted-style URLs. Users can now leverage this backend for file uploads, downloads, deletion, and size checks, with automatic content-type detection and path sanitization.
src/BuildingBlocks/Storage/S3 · high confidence
Introduce SSE live feed with optimized context and token refresh logic
The dashboard now includes a new Server-Sent Events (SSE) infrastructure to provide real-time live feeds. This change introduces a dedicated API module for issuing short-lived SSE tokens and a React context provider that manages the connection lifecycle, including automatic reconnection with exponential backoff. To improve performance, the context is split into status and event components, preventing unnecessary re-renders in the UI when new events arrive. The implementation also documents the invariant that SSE tokens are single-use and refreshed implicitly upon reconnection.
clients/dashboard/src/sse · high confidence
Introduce SendGrid as an alternative email provider
The mailing building block now supports SendGrid as an alternative to SMTP for sending emails. Users can configure the new provider via \MailOptions\ (setting \UseSendGrid\ to true and providing a SendGrid API key), which registers a shared \ISendGridClient\ to optimize resource usage under load. The existing SMTP implementation remains available as the default when SendGrid is not enabled.
src/BuildingBlocks/Mailing · high confidence
Introduce billing contract data transfer objects
Added a set of new Data Transfer Objects (DTOs) in the billing module to support usage-based invoicing, prepaid wallet management, and plan definitions. These include BillingPlanDto (with interval and annual pricing), InvoiceDto (with purpose and period spans), SubscriptionDto, UsageSnapshotDto, WalletDto, WalletTransactionDto, TopupRequestDto, and InvoiceLineItemDto, establishing the data structures for the new internal billing capabilities.
src/Modules/Billing/Modules.Billing.Contracts/Dtos · high confidence
Introduce billing domain contracts and enums
The billing module now exposes its core domain contracts, including enums for invoice status, subscription status, plan intervals, invoice purposes, wallet states, and top-up request statuses. These definitions establish the data structures used for usage-based invoicing, prepaid wallet management, and subscription lifecycle tracking within the billing system.
src/Modules/Billing/Modules.Billing.Contracts · high confidence
Introduce billing plan management with interval and annual pricing support
This change adds the core endpoints for managing billing plans within the v1 Plans module. Users can now create, update, and list billing plans via the new /plans POST, PUT, and GET endpoints. The plan model has been extended to support billing intervals (e.g., monthly, annual) and annual pricing, allowing for more flexible subscription structures. Additionally, a new GetPlanTerm query is available to retrieve specific plan term details by key, and the CreatePlan endpoint is protected with idempotency to prevent duplicate submissions.
src/Modules/Billing/Modules.Billing/Features/v1/Plans · high confidence
Introduce core context interfaces for user and request metadata
Added new interfaces in the core context building block to abstract user and request information from framework-specific dependencies. ICurrentUser provides access to authenticated user details such as name, ID, email, tenant, roles, and claims. ICurrentUserInitializer allows setting the current user context from a ClaimsPrincipal or a user ID. IRequestContext exposes HTTP request metadata like IP address, User-Agent, client ID, and origin, enabling handlers to access this data for auditing and logging without directly depending on ASP.NET Core.
src/BuildingBlocks/Core/Context · high confidence
Introduce dedicated FSH.Starter.DbMigrator console for deployment-time schema management
A new standalone console application (FSH.Starter.DbMigrator) is introduced to handle database migrations and seeding as an explicit deployment step, replacing the previous pattern of auto-migrating at API startup. This tool applies EF Core migrations across the tenant catalog and every tenant's per-module databases, featuring a chiseled Dockerfile for containerized execution, an advisory lock to prevent concurrent migration races, and a wait-for-database loop to handle cold-starts. It supports specific commands to apply migrations, seed data, or provision demo tenants (acme, globex) in development, ensuring the API only starts against a fully migrated schema.
src/Host/FSH.Starter.DbMigrator · high confidence
Introduce file asset domain model with upload lifecycle and soft-delete support
The Files module now includes a core FileAsset aggregate that tracks files through a presigned upload lifecycle (PendingUpload → Available or Quarantined) and supports soft-delete semantics. Users can now have files marked as available, quarantined, or soft-deleted, with visibility changes restricted to available files. The domain also introduces scan status tracking (NotScanned, Clean, Infected, ScanFailed) and emits domain events (FileFinalizedDomainEvent, FileSoftDeletedDomainEvent) to signal state changes.
src/Modules/Files/Modules.Files/Domain · high confidence
Introduce file asset storage with multi-tenant database support
The Files module now includes a dedicated data layer to manage file assets. This introduces a \FileAsset\ entity with configuration for properties like storage key, content type, and visibility, along with specific database indexes for efficient querying by owner, status, and deletion state. A new \FilesDbContext\ is provided, configured to use the 'files' schema and integrated with the existing multi-tenancy infrastructure to ensure data isolation per tenant. Additionally, a database initializer is added to automatically apply pending migrations for the file storage schema upon application startup.
src/Modules/Files/Modules.Files/Data · high confidence
Introduce framework-owned eventing system with transactional outbox and inbox
The eventing building block now provides a centralized, framework-owned infrastructure for reliable event handling. It introduces a dedicated \EventingDbContext\ that stores outbox and inbox messages in a shared \framework\ schema, ensuring transactional consistency between business data and events regardless of whether tenants use shared or dedicated databases. The system supports configurable event bus providers (InMemory or RabbitMQ) and includes a background outbox dispatcher with exponential retry backoff, lease-based multi-instance safety, and idempotent inbox processing. Configuration is managed via \EventingOptions\, allowing tuning of batch sizes, retry limits, and dispatch intervals, while DI registrations are simplified to a single, unambiguous store implementation to resolve previous ambiguity in multi-module setups.
src/BuildingBlocks/Eventing · high confidence
Introduce idempotent inbox store for integration events
The framework now includes a non-generic EF Core inbox store (\EfCoreInboxStore\) that tracks processed integration events per handler to ensure idempotent consumption. This prevents duplicate processing when events are published directly or retried from the outbox, handling concurrent insert races gracefully. The underlying \InboxMessage\ entity is configured as a global entity to allow cross-tenant lookups during background processing, with tenant association stored explicitly per row.
src/BuildingBlocks/Eventing/Inbox · high confidence
Introduce in-memory event bus with tenant context and idempotency
Adds an in-memory implementation of the event bus for single-process deployments. This component resolves event handlers via dependency injection, caches reflection metadata to optimize the hot path, and establishes a tenant context before handler execution to ensure correct data scoping. It also supports optional idempotency through an inbox store, allowing it to skip events that have already been processed by a specific handler.
src/BuildingBlocks/Eventing/InMemory · high confidence
Introduce shared SignalR hub with presence tracking and channel management
The application now includes a centralized SignalR hub (\AppHub\) in the \src/BuildingBlocks/Web/Realtime\ module to handle real-time features such as chat, typing indicators, and user presence. This hub supports joining specific channel groups for targeted message delivery and maintains an in-memory presence tracker to broadcast online/offline status changes scoped to tenant groups, preventing unnecessary global fan-out. The setup includes optional Redis backplane support for multi-instance deployments and exposes an HTTP endpoint (\/api/v1/realtime/presence\) for clients to poll initial presence state. Interfaces like \IChannelMembershipChecker\ and \IUserChannelLookup\ allow modules to integrate their own membership logic without coupling to the hub implementation.
src/BuildingBlocks/Web/Realtime · high confidence
Introduce structured module system with ordered startup and validation
The application now uses a new module architecture to organize features. Modules implement the IModule interface, allowing them to register services, map Minimal API endpoints, and configure middleware. Startup order is controlled via the new FshModuleAttribute, ensuring dependencies are initialized correctly. Additionally, the module loader automatically integrates FluentValidation for all modules, simplifying input validation across the application.
src/BuildingBlocks/Web/Modules · high confidence
Introduce tenant quota enforcement with API call and storage meters
The Quota building block now enforces per-tenant usage limits for API calls and storage bytes. A new \QuotaEnforcementMiddleware\ intercepts requests, checks the tenant's remaining quota against configured plans, and rejects excess usage with HTTP 429 (including a \Retry-After\ header and RFC 9457 ProblemDetails). Quota tracking is backed by Redis counters in production (with automatic TTL reset at the billing period boundary) or falls back to an in-memory store for development and tests. The system supports plan-based limits with tenant-specific overrides, exempts the root tenant by default, and ignores health/readiness endpoints. Additionally, an extensibility hook (\IQuotaGaugeProvider\) allows modules to report live usage for gauge-based resources like user counts.
src/BuildingBlocks/Quota · high confidence
Introduce tenant-scoped Webhooks module with secure delivery and retry
This change adds a new Webhooks module that allows tenants to subscribe to system events and receive them via HTTP POST. Subscriptions are scoped to the tenant, and deliveries are handled asynchronously via a Hangfire background job that automatically retries on transient failures (5xx, timeouts, network errors) with exponential backoff. To ensure security, the module enforces tenant isolation, protects signing secrets using ASP.NET Data Protection, and implements an SSRF guard that blocks internal, loopback, and cloud-metadata IP ranges at both the URL-creation and connection-resolve times. The module exposes a v1 API for creating, deleting, listing, and testing subscriptions, as well as viewing delivery history.
src/Modules/Webhooks · high confidence
Introduce the Tickets module for issue tracking and lifecycle management
This change adds the Tickets module, providing a complete system for creating, searching, and managing support tickets. Users can now create tickets with titles, descriptions, and priorities, and assign them to team members. The module enforces a strict ticket lifecycle (Open, InProgress, Resolved, Closed) with specific state transitions, such as auto-advancing to InProgress upon assignment. It also supports soft deletion with the ability to restore trashed tickets, adding comments to tickets, and viewing detailed ticket history. The module includes its own database schema, authorization permissions (View, Create, Update, Delete, Restore, Assign, Resolve, Reopen, Close, Comment), and domain events for tracking status changes and assignments.
src/Modules/Tickets · high confidence
Introduce token refresh and generation command contracts
Added new command and response contracts for the Identity module's token management. The \RefreshTokenCommand\ now accepts an optional access token to allow the handler to cross-check the subject against the refresh token as a safeguard, while the \GenerateTokenCommand\ supports an optional two-factor code for authentication flows.
src/Modules/Identity/Modules.Identity.Contracts/v1/Tokens · high confidence
Introduce usage-based billing with prepaid wallet support
The billing module now supports usage-based invoicing and prepaid wallet top-ups. A new BillingService orchestrates the workflow: it snapshots tenant usage via IUsageReporter, generates draft invoices for metered overages (excluding base subscription fees to avoid double-billing), and handles prepaid wallet operations including creating wallets and issuing top-up invoices. An IInvoicePdfRenderer (backed by QuestPDF) allows on-demand PDF generation for invoices. A MonthlyInvoiceJob (Hangfire) automates the generation of these usage invoices for all active tenants at the start of each month. The system is multi-tenant aware and uses an outbox for event publishing.
src/Modules/Billing/Modules.Billing/Services · high confidence
Introduce usage-based billing, prepaid wallets, and subscription lifecycle management
The billing module now supports usage-based invoicing alongside standard subscription plans. New domain entities (BillingPlan, Invoice, Subscription, UsageSnapshot) allow plans to define billing intervals (monthly or yearly) and per-resource overage rates, with invoices automatically generated for both subscription terms and metered usage. A prepaid wallet system has been added, enabling tenants to top up balances via TopupRequest workflows and allowing credits/debits to be applied against invoices. The module also integrates with the multitenancy layer to automatically manage subscription state and issue invoices when tenants are created or renewed.
src/Modules/Billing/Modules.Billing/Domain · high confidence
Introduce v1 invoice and subscription management endpoints with strict multi-tenant isolation
This change adds the v1 API endpoints for the billing module, enabling administrators to generate, issue, mark as paid, and void invoices, as well as assign and view subscriptions. The implementation enforces strict multi-tenant security: tenant users are restricted to their own data (invoices and subscriptions), while the root operator can access cross-tenant records. Key features include on-demand PDF invoice downloads, idempotency protection on mutating actions (generate, issue, pay, assign), and validation for invoice periods and subscription plan keys.
src/Modules/Billing/Modules.Billing/Features/v1/Invoices · high confidence
Introduces JSON masking for sensitive audit data and a new serialization service
The auditing module now includes a \JsonMaskingService\ that automatically masks sensitive fields (such as passwords, tokens, and secrets) in audit logs by detecting keywords in JSON property names, replacing their values with '\\\\'. Additionally, a new \SystemTextJsonAuditSerializer\ has been added to handle payload serialization using \System.Text.Json\ with camel-case naming and null-ignoring options, ensuring consistent and secure formatting of audit entries.
src/Modules/Auditing/Modules.Auditing/Infrastructure/Serialization · high confidence
Introduces JSON-based event serialization with type caching
The system now includes a new JsonEventSerializer implementation for the eventing architecture. This component handles the serialization and deserialization of integration events using System.Text.Json, ensuring consistent camel-case property naming. To optimize performance during event processing, it employs a concurrent dictionary to cache resolved event types, avoiding repeated reflection lookups for the same event type names.
src/BuildingBlocks/Eventing/Serialization · high confidence
Introduces auditing attributes and quota resource definitions
This change adds foundational types for the auditing and quota systems. It introduces \AuditIgnoreAttribute\ and \AuditSensitiveAttribute\ to control how properties are handled during audit logging, specifically allowing sensitive data to be masked or hashed. It also defines the \QuotaResource\ enum, which specifies the resources (such as API calls, storage, users, and feature flags) that can be metered per tenant, and provides \HttpContextItemKeys\ to signal when a request has been rejected due to quota enforcement.
src/BuildingBlocks/Shared/Auditing · high confidence
Introduces centralized web platform configuration and observability middleware
The web building block now provides a unified \AddHeroPlatform\ and \UseHeroPlatform\ extension method to configure the application pipeline. This includes registering a new \CurrentUserMiddleware\ that enriches distributed tracing with user ID, tenant ID, and correlation ID tags. The pipeline also enables response compression (Brotli/Gzip), configurable CORS handling (ensuring it runs before HTTPS redirection to support preflight requests), security headers, rate limiting, and optional integrations for OpenTelemetry, feature flags, idempotency, Server-Sent Events (SSE), and real-time capabilities.
src/BuildingBlocks/Web · high confidence
Introduces configurable CORS policy with credential support
The application now includes a dedicated CORS configuration module (CorsOptions) that allows users to define allowed origins, headers, and methods via configuration. By default, it enables a permissive policy that supports credentialed requests (AllowCredentials) by echoing the request origin, which ensures compatibility with SignalR negotiate calls that require credentials. Users can switch to a restrictive mode by setting AllowAll to false and explicitly listing allowed origins, headers, and methods.
src/BuildingBlocks/Web/Cors · high confidence
Introduces shared persistence configuration and pagination contracts
This change adds foundational building blocks for database configuration and data retrieval within the shared persistence layer. It introduces \DatabaseOptions\ to manage provider selection (PostgreSQL or MSSQL) and connection strings, alongside a \DbProviders\ constant class. Additionally, it defines the \IPagedQuery\ interface for specifying pagination and sorting parameters, and the \PagedResponse\<T\>\ class to structure paginated results, enabling consistent handling of list data across the application.
src/BuildingBlocks/Shared/Persistence · high confidence
Introduces the Auditing module contract definitions
This change adds the core contracts for the new Auditing module, defining the data structures and interfaces used to capture and process audit events. It introduces strongly-typed payloads for entity changes, security actions, activity tracking, and exceptions, along with the \AuditEnvelope\ that carries normalized metadata like tenant, user, and trace identifiers. The module provides configuration options for HTTP body capture limits, path exclusions, and configurable retention policies for different event types. It also defines interfaces for the audit pipeline, including publishers, sinks, dead-letter queues, and enrichers, as well as attributes and extensions to allow developers to exclude specific endpoints from body capture for privacy compliance.
src/Modules/Auditing/Modules.Auditing.Contracts · high confidence
Introduces v1 billing contracts for invoices, plans, subscriptions, usage, and prepaid wallets
This change adds the v1 contract layer for the new internal billing module, defining the commands and queries that enable usage-based invoicing, plan management, and prepaid wallet top-ups. Administrators can now trigger bulk invoice generation, manage plan terms (including annual pricing and billing intervals), and assign or view tenant subscriptions. The module also supports capturing usage snapshots for billing periods and provides a prepaid wallet system where users can request top-ups and operators can approve or reject them, with invoices issued upon approval.
src/Modules/Billing/Modules.Billing.Contracts/v1 · high confidence
Introduction of OriginOptions configuration class
A new \OriginOptions\ class has been added to the \FSH.Framework.Web.Origin\ namespace to support configuration of the application's origin URL. This class exposes an optional \OriginUrl\ property of type \Uri\, allowing users to specify the base URL for the origin in the application's settings.
src/BuildingBlocks/Web/Origin · high confidence
Introduction of the internal billing module with usage-based invoicing and wallet management
The new BillingModule registers the core billing infrastructure, including database context, services, and integration event handlers for tenant subscription events. It exposes a comprehensive set of v1 API endpoints under /api/v{version}/billing for managing subscription plans, assigning subscriptions, generating and issuing invoices (including PDF downloads), capturing usage snapshots, and handling prepaid wallet top-up requests. Additionally, it configures a recurring Hangfire job to automatically generate monthly invoices on the first of each month.
src/Modules/Billing/Modules.Billing · high confidence
Local storage backend now supports presigned URLs and HEAD operations
The local file storage implementation has been updated to support presigned upload URLs and HEAD object requests, aligning its capabilities with the S3 backend. This change introduces a local presigned token store for development environments and adds methods to generate short-lived upload tokens and retrieve object metadata (size and content type) without downloading the file. Users can now utilize these features for direct browser uploads and upload validation in local development setups, ensuring feature parity with production S3 storage.
src/BuildingBlocks/Storage/Local · high confidence
Multitenancy module introduces tenant lifecycle, billing, and theme management capabilities
The Multitenancy module now provides comprehensive tenant lifecycle management, including creation, activation, deactivation, and renewal with plan switching. It enforces subscription expiry with a configurable grace window, emitting integration events for nearing expiry, entering grace, and expiration states. A new tenant theme customization system allows per-tenant UI configuration (palettes, typography, brand assets) with caching support. The module also includes tenant provisioning status tracking, migration status monitoring, and an operator override to adjust tenant validity dates explicitly. Authorization permissions are defined for tenant management, theme updates, and subscription upgrades.
src/Modules/Multitenancy · high confidence
New ElastiCache Redis module with Valkey 8 support and hardened security defaults
A new Terraform module for deploying ElastiCache replication groups has been added, defaulting to the Valkey 8.0 engine (with legacy Redis 7.1 support) and enforcing encryption in transit and at rest. The module configures security groups to restrict access to specific VPC CIDRs or security groups, enables automatic minor version upgrades, and supports optional slow-log and engine-log delivery to CloudWatch. It exposes primary and reader endpoints, connection strings for .NET applications, and allows customization of node types, cluster counts, and snapshot retention.
_deploy/terraform/modules/elasticache\redis · high confidence
New FSH CLI with project scaffolding, environment checks, and update management
The CLI tool now provides a comprehensive set of commands for managing the FullStackHero .NET Starter Kit. Users can scaffold new projects with the \new\ command, which supports options to exclude the Aspire AppHost or React frontend, skip npm installs, and automatically initialize a git repository. A \doctor\ command has been added to validate the development environment by checking for the .NET 10 SDK, Git, Docker, and the FSH template, while also warning about port conflicts. The \info\ command displays current CLI and template versions alongside available updates, and a new \update\ command allows users to upgrade both the CLI tool and the dotnet new template in one step. Under the hood, version comparison logic has been improved to correctly handle semantic versions and pre-release tags, preventing false update notifications.
src/Tools · high confidence
New FSH Design System UI Components
The dashboard now includes a new set of UI components (Avatar, Badge, Button, Card, Dialog, DropdownMenu, Input, Label, Skeleton, Switch) styled according to the FSH design system. These components provide a consistent visual language with semantic token support, accessible interactions, and specific features like avatar status indicators, dialog/sheet animations, and skeleton loading states.
clients/dashboard/src/components/ui · high confidence
New FSH design-system UI primitives for the admin console
The admin console now uses a unified FSH design system, introducing a new set of React UI components in the \clients/admin/src/components/ui\ directory. This includes an Avatar with status indicators and initials fallback, a Badge with semantic variants (success, warning, danger, etc.), and a Button with multiple styles (default, signal, saffron, soft) and sizes. Layout and structure are handled by Card components (with an interactive hover variant) and a modern Select dropdown that replaces native selects. Interaction patterns are standardized with Dialog and Sheet primitives (edge-anchored panels) built on Radix, a reusable ConfirmDialog for destructive actions, and a Skeleton for loading states. Form inputs are styled with a consistent Input and Label, while a Switch toggle and a Table with hover-highlighted rows complete the set. These components provide a consistent visual language and accessibility foundation for the admin interface.
clients/admin/src/components/ui · high confidence
New Groups and User Impersonation management APIs
The Identity module now exposes full CRUD operations for Groups (create, read, update, delete, and list with search) and granular member management (add/remove users). Creating or updating groups allows assigning roles, and any membership or role changes automatically invalidate the affected users' permission caches to ensure immediate effect. Additionally, a new User Impersonation feature allows administrators to act as other users; this includes starting and ending impersonation sessions, listing active grants with tenant-scoped visibility, and revoking grants, with all actions audited via the security audit service.
src/Modules/Identity/Modules.Identity/Features/v1 · high confidence
New Health Dashboard for Monitoring Liveness and Readiness
The admin interface now includes a dedicated Health page that displays real-time status for liveness and readiness probes, auto-refreshing every 10 seconds. Users can view aggregate statistics for healthy, degraded, and failing checks, along with detailed breakdowns of individual dependency checks. The page also provides manual refresh capabilities and displays error bands when probes fail, helping administrators quickly assess system stability and dependency health.
clients/admin/src/pages/health · high confidence
New Identity contract DTOs for groups, sessions, and permissions
The Identity module's contract layer now exposes a comprehensive set of Data Transfer Objects to support new identity capabilities. These include GroupDto and GroupMemberDto for managing user groups, UserSessionDto for tracking active user sessions, and PermissionCatalogEntryDto for exposing the host-wide permission catalog to the UI. Additionally, new DTOs support two-factor authentication (TwoFactorEnrollmentResponse, UserDto.TwoFactorEnabled), password expiry status (PasswordExpiryStatusDto), and refined token handling (TokenDto, TokenResponse), enabling the frontend to interact with these specific identity features.
src/Modules/Identity/Modules.Identity.Contracts/DTOs · high confidence
New My Files page with file management and preview capabilities
The dashboard now includes a dedicated My Files page that allows users to view, search, and filter their uploaded files by type (image, document, archive). Users can switch between tabs for their own files and shared files, preview PDFs and other documents in a dialog, and manage file visibility and sharing settings directly from the interface.
clients/dashboard/src/pages/files · high confidence
New React + Vite admin console with runtime configuration and permission-aware routing
The admin interface has been rebuilt as a modern React application using Vite, introducing a new user experience for managing tenants, users, roles, billing, and audits. The app loads runtime configuration (such as API URLs and inactivity timeouts) from /config.json at boot, allowing operators to adjust settings without rebuilding the client. Navigation is secured via a permission-aware routing system that mirrors server-side authorization, ensuring users only see surfaces they are allowed to access. Key interactions, such as creating roles or users, have been moved into modern dialog components for a smoother workflow, and the UI includes a custom toast notification system that respects the in-app theme.
clients/admin/src · high confidence
New Settings page with deep-linkable tabs for profile, security, and appearance
The dashboard now includes a dedicated Settings page that organizes user preferences into a structured, deep-linkable interface. Users can manage their profile (including photo uploads and contact details), review and revoke active sessions, and customize the dashboard's visual appearance with theme modes, accent colors, fonts, and density settings. A new Branding tab allows tenant administrators to edit tenant-specific color palettes and logos. Placeholder sections for API keys and notification preferences are also present to maintain navigation integrity while those backend features are developed.
clients/dashboard/src/pages/settings · high confidence
New Settings pages for profile, security, appearance, and sessions
The admin console now includes dedicated Settings pages for managing user identity and preferences. The Profile tab displays read-only account details (username, email, name) and allows avatar uploads via a new presigned URL flow, replacing the previous base64 limitation. The Security tab enables password changes and two-factor authentication enrollment/disabling. The Appearance tab provides a theme picker for light and dark modes, with a placeholder for future density controls. The Sessions tab lists active devices and allows revoking individual or all other sessions. These pages are unified under a new SettingsLayout with an editorial-style navigation rail.
clients/admin/src/pages/settings · high confidence
New Terraform module for one-shot ECS Fargate tasks
A new reusable Terraform module has been added to deploy/terraform/modules/ecs\_task, enabling the execution of short-lived, one-shot AWS ECS Fargate tasks (such as database migrations) on demand. This module provisions the necessary infrastructure—including a CloudWatch log group, an egress-only security group, an IAM task execution role with optional Secrets Manager access, and the ECS task definition itself—without creating a long-running service, load balancer, or autoscaling group. It exposes outputs for the task definition ARN and family, allowing external scripts to invoke the task via \aws ecs run-task\.
_deploy/terraform/modules/ecs\task · high confidence
New Terraform modules for ECS, VPC networking, and RDS PostgreSQL
This change introduces three new, production-grade Terraform modules to the \deploy/terraform/modules\ directory. The \ecs\_service\ module provisions AWS ECS services on Fargate, including associated CloudWatch log groups, security groups, ALB target groups/listener rules, and IAM execution roles with Secrets Manager access. The \network\ module defines the foundational VPC infrastructure, including public and private subnets, NAT gateways, route tables, and optional VPC endpoints for S3, ECR, and CloudWatch Logs to optimize cost and security. The \rds\_postgres\ module manages PostgreSQL database instances with configurable storage, multi-AZ high availability, automated backups, encryption, and optional Secrets Manager integration for master password management. All modules require Terraform \>= 1.15 and the AWS provider \>= 6.0.
_deploy/terraform/modules/ecs\_service, deploy/terraform/modules/network, deploy/terraform/modules/rds\postgres · high confidence
New Terraform modules for infrastructure bootstrapping and SPA hosting
This change introduces new Terraform modules in the deploy/terraform directory to standardize infrastructure provisioning. The bootstrap module provisions a secure S3 bucket for Terraform state storage, utilizing native S3 locking (available in Terraform 1.10+) and enforcing strict security policies including SSL-only access and TLS 1.2 minimums. Additionally, the static\_site module provides a reusable component for hosting Single Page Applications via a private S3 origin and CloudFront distribution, featuring built-in support for client-side routing fallbacks, runtime configuration injection, and managed security headers.
deploy/terraform · high confidence
New WAF module with AWS Managed Rules and rate limiting
A new Terraform module in deploy/terraform/modules/waf introduces an AWS WAFv2 Web ACL for regional protection. It enables rate limiting (default 2000 requests per 5 minutes per IP) and includes AWS Managed Rules for common threats, known bad inputs, SQL injection, and IP reputation. The module allows associating the Web ACL with an Application Load Balancer, supports logging to CloudWatch Logs with configurable retention and field redaction, and requires Terraform \>= 1.15 and the AWS provider \>= 6.0.
deploy/terraform/modules/waf · high confidence
New admin API client layer scaffolding
The admin console now includes a comprehensive API client layer in \clients/admin/src/api\ that provides TypeScript types and fetch wrappers for all core admin capabilities. This new code introduces dedicated modules for auditing (with integer-to-string enum normalization), billing (plans, subscriptions, invoices, and wallet top-up requests), file management (presigned uploads/downloads), health probes, identity (users, roles, sessions, 2FA, and impersonation), tenant lifecycle (provisioning, renewal, and theme/branding), notifications, and webhooks. For users, this establishes the foundational data-fetching infrastructure required for the rebuilt admin interface, enabling features like tenant provisioning status tracking, impersonation, and self-serve billing management.
clients/admin/src/api · high confidence
New admin UI component library for consistent branding and error handling
The admin interface now includes a set of new shared components to standardize the visual language and error states. Branding is handled by BrandMark and BrandMarkXL, which replace the previous console identity with a unified 'fullstackhero' wordmark and gradient 'F' logo. User experience is improved with EmptyState for empty list results, KpiTile for stat displays, and Monogram for user initials. Error handling is centralized via RouteError (displaying stack traces for 4xx/5xx errors) and ForbiddenView (showing missing permissions for 403s), while SectionRule provides consistent breadcrumb-style headers for page sections.
clients/admin/src/components · high confidence
New admin console layout with permission-gated navigation and inactivity logout
The admin console now uses a dedicated app shell (app-shell.tsx) featuring a collapsible desktop sidebar, a mobile navigation drawer, and a top bar with user profile and theme controls. Navigation items are filtered by user permissions, ensuring users only see sections they are authorized to access. The layout also includes an inactivity guard that automatically logs out users after a period of inactivity, enhancing security for the admin interface.
clients/admin/src/components/layout · high confidence
New admin console with unified auth and dashboard pages
The admin application now includes a complete set of new pages for authentication, dashboarding, and system management. Users can sign in, confirm email addresses, and reset passwords using a modernized, consistent UI that mirrors the dashboard's visual style. The new dashboard provides an operator overview with real-time KPIs for tenants, plans, and invoices, along with quick navigation to tenants, users, billing, and invoices. Additional features include a notification inbox with live updates, webhook subscription management with testing capabilities, and a standardized 404 page. A demo account dialog is also available for local development to simplify onboarding.
clients/admin/src/pages · high confidence
New admin notification bell and user session management components
The admin interface now includes a top-bar notification bell that displays an unread count badge, previews recent notifications in a popover, and updates in real-time via SignalR events. Additionally, administrators can view a user's active sessions on their detail page, seeing device and IP details, and revoke individual sessions or sign the user out of all devices at once.
clients/admin/src/components/notifications, clients/admin/src/components/sessions · high confidence
New appearance customization system with font, accent, and density controls
The dashboard now includes a comprehensive appearance configuration system that allows users to personalize the interface. Users can select from a variety of sans-serif fonts (such as Geist, Inter Tight, and DM Sans) which are applied via CSS variables and loaded lazily to maintain performance. The system supports eleven preset accent color palettes (including Rose, Indigo, and Emerald) as well as a custom accent picker that lets users define any brand hue by adjusting hue and chroma values. Additionally, users can toggle between 'comfortable' and 'compact' density modes to control spacing across the dashboard, with all preferences persisted in local storage.
clients/dashboard/src/components/theme · high confidence
New audit detail and summary data transfer objects
The auditing module now exposes three new DTOs in the contracts layer to support richer audit data consumption. \AuditDetailDto\ provides comprehensive event information, including trace identifiers (TraceId, SpanId, CorrelationId, RequestId), user and tenant context, and a deserialized \JsonElement\ payload. \AuditSummaryDto\ offers a lightweight view of individual audit events with core metadata. \AuditSummaryAggregateDto\ enables aggregated reporting by exposing counts of events grouped by type, severity, source, and tenant.
src/Modules/Auditing/Modules.Auditing.Contracts/Dtos · high confidence
New billing management pages for plans, invoices, and top-ups
The admin interface now includes dedicated pages for managing billing resources. The Plans list displays active and inactive subscription plans with pricing and overage details, allowing admins to create and edit plans via a dialog. The Invoices list provides a paginated view with KPIs for billed, outstanding, and paid amounts, along with filters for tenant, status, and billing period; the Invoice detail page shows full invoice metadata and allows admins to issue, mark as paid, void, or download PDFs. A new Top-ups list page enables admins to approve or reject prepaid wallet top-up requests, which generates draft invoices upon approval. All pages are gated by the Billing.Manage permission and use a shared layout with tabbed navigation.
clients/admin/src/pages/billing · high confidence
New catalog management pages for brands, categories, and products
The dashboard now includes dedicated pages for managing catalog entities. Users can create, edit, and delete brands and categories, with categories supporting a nested tree structure. The products section allows for full CRUD operations, including filtering by brand, category, and active status, as well as adjusting stock levels and changing prices directly from the product list and detail views.
clients/dashboard/src/pages/catalog · high confidence
New centralized identity permission and claim constants
The identity building block now includes a set of new constants and helper classes to standardize authorization and user data handling. A central \PermissionConstants\ registry allows modules to register permissions (e.g., \FshPermission\) which are then categorized into Root, Admin, and Basic scopes, with \SystemPermissions\ defining cross-cutting platform permissions like tenant management and impersonation for the SuperAdmin. New \ActionConstants\ and \ResourceConstants\ provide standardized strings for actions (View, Create, Delete, etc.) and resources (Tenants, Users, Roles, etc.). Additionally, \ClaimConstants\ and \CustomClaims\ define specific claim types (including actor claims for impersonation), and \ClaimsPrincipalExtensions\ offer helper methods to extract these claims. An \EndpointExtensions\ method and \RequiredPermissionAttribute\ are also introduced to facilitate declarative permission checks on API endpoints.
src/BuildingBlocks/Shared/Identity · high confidence
New channel management and discovery endpoints
This update introduces a comprehensive set of v1 API endpoints for managing chat channels. Users can now create, update, archive, and restore channels, as well as discover public channels not yet joined. Membership is managed via endpoints to add or remove users, with private channels restricted to admins for these actions. The system also supports finding or creating direct messages (DMs) and group DMs, and includes a read-marker endpoint to track and broadcast read status in real-time via SignalR.
src/Modules/Chat/Modules.Chat/Features/v1/Channels · high confidence
New chat and notification UI components in the dashboard
Added three new React components to the dashboard's notification area: ChatGlobalNotifier, which listens for incoming chat messages via SignalR and displays custom toasts for channels not currently viewed; ChatUnreadBadge, a topbar pill showing the total count of unread chat messages across all channels; and NotificationBell, a dropdown inbox for system notifications with real-time updates and a 'Mark all read' action. Also added RealtimeStatusPill, a connection status indicator used within the notification and chat surfaces to show live/reconnecting/offline states.
clients/dashboard/src/components/notifications · high confidence
New chat interface with real-time messaging and channel management
The dashboard now includes a dedicated /chat page featuring a two-column layout with a channel rail for browsing channels and direct messages, and a main area for message history. Users can send messages with file attachments, use @-mention autocomplete, and pin messages. The interface supports real-time updates, including typing indicators and read receipts, and includes a channel settings dialog for managing members and privacy. A search overlay allows users to find messages within a channel, and the layout is responsive for mobile devices.
clients/dashboard/src/pages/chat · high confidence
New core abstractions and query string constants added
The framework now includes a new IAppUser interface in the core abstractions layer, defining common user properties such as first and last name, profile image URL, active status, and refresh token details. Additionally, a new QueryStringKeys class has been introduced in the common utilities to provide standardized constants for query string parameters, specifically for authentication codes and user identifiers.
src/BuildingBlocks/Core/Abstractions, src/BuildingBlocks/Core/Common · high confidence
New dashboard API client modules for billing, catalog, chat, files, identity, and more
The dashboard now includes a comprehensive set of new API client modules (audits, billing, catalog, chat, files, health, identity, notifications, permissions-catalog, sessions, tenants, tickets, and wallet) that provide the frontend with strongly-typed TypeScript interfaces and HTTP wrappers for the backend's v1 endpoints. This enables users to interact with core platform capabilities including self-service billing and prepaid wallet top-ups, product catalog management (brands, categories, products), real-time chat with channels and messages, file uploads and visibility controls, user and role administration, session management, tenant branding and theme customization, support ticketing, and system health monitoring.
clients/dashboard/src/api · high confidence
New dashboard pages for activity, audits, health, invoices, and login
The dashboard now includes dedicated pages for live activity streaming (via Server-Sent Events), detailed audit logs with filtering and time-range presets, system health monitoring with auto-refresh and latency history, invoice listing and detail views with PDF download, and a redesigned login flow featuring a demo account picker for development environments. These pages replace or supplement previous dashboard surfaces, providing structured, filterable, and real-time views for operators.
clients/dashboard/src/pages · high confidence
New database configurations for Groups, User Groups, Password History, and User Sessions
The Identity module now includes Entity Framework Core configurations for four new domain entities, enabling new identity capabilities. GroupConfiguration defines the Groups table with multi-tenant support and indexes on Name, IsDefault, and IsDeleted. GroupRoleConfiguration establishes the many-to-many relationship between Groups and Roles with cascade deletes. PasswordHistoryConfiguration adds a PasswordHistory table to track user password changes, including indexes for efficient lookups by UserId and creation date. UserGroupConfiguration creates the UserGroups junction table linking Users to Groups with cascade deletes. UserSessionConfiguration introduces a UserSessions table to track user login sessions, storing details like IP address, user agent, and refresh token hashes, with indexes for performance.
src/Modules/Identity/Modules.Identity/Data/Configurations · high confidence
New domain building blocks and Money value object
The core domain layer now includes foundational types for the application's domain model. This adds base classes and interfaces for entities (BaseEntity, AggregateRoot), auditability (IAuditableEntity), soft deletion (ISoftDeletable), and tenant isolation (IHasTenant, IGlobalEntity). It also introduces a domain event infrastructure (DomainEvent, IDomainEvent, IHasDomainEvents) that integrates with the Mediator library for event publishing. Additionally, a new Money value object is provided to handle currency-aware arithmetic operations safely.
src/BuildingBlocks/Core/Domain · high confidence
New file upload, preview, and product image management components
The dashboard now includes a new file management UI located in \clients/dashboard/src/components/file\. This introduces a \FileDropzone\ component for drag-and-drop file uploads with live progress and error handling, a \FilePreviewDialog\ for viewing files (images, PDFs, text) with metadata, visibility toggling, and deletion controls, an \ImageInput\ component supporting both file uploads and URL pasting for single images, and a \ProductImageManager\ that allows uploading multiple images to a product, setting a cover thumbnail, and previewing/removing images in a gallery grid.
clients/dashboard/src/components/file · high confidence
New identity management components and authentication pages
The dashboard now includes a UserPicker component for selecting users via debounced search, and a complete set of authentication pages: email confirmation, forgot password, and password reset. These changes enhance user identity management and streamline the authentication flow within the dashboard interface.
clients/dashboard/src/components/identity, clients/dashboard/src/pages/auth · high confidence
New identity management pages for users, roles, and groups
The dashboard now includes dedicated pages for managing identity resources: Users, Roles, and Groups. The Users page allows administrators to register new users, search, and filter by account status, email confirmation, and assigned roles. The Roles page provides a list of roles and a detail view for editing permissions, including a system-role guard that prevents modification of built-in roles like Admin and Basic. The Groups page enables the creation and management of user groups, allowing admins to add members and assign roles to the group as a whole.
clients/dashboard/src/pages/identity · high confidence
New impersonation management UI with session recovery
The admin interface now includes a dedicated section for managing active impersonation sessions. Operators can view a live-updating list of active impersonations, revoke them immediately (which invalidates the token for the next request), and re-open their own closed sessions for recovery. The impersonation flow itself has been modernized into a two-step dialog that allows searching for users within a tenant and configuring session duration, with tokens passed securely via URL hash to the dashboard.
clients/admin/src/components/impersonation · high confidence
New impersonation management page with session recovery
Admins now have a dedicated list page to view, filter, and manage impersonation grants in real time. The page displays live statistics for active, ended, revoked, and expired sessions, allowing administrators to revoke active grants immediately. A key new capability is the ability to re-open a session for the current user if they accidentally closed their browser tab while impersonating, provided the underlying grant is still active on the server.
clients/admin/src/pages/impersonation · high confidence
New integration event for channel mentions
Added the MentionedInChannelIntegrationEvent record to the Chat module's contracts. This event is published for each resolved @user mention in a sent message, carrying details such as the channel ID, message ID, author, and the specific user mentioned. The Notifications module consumes this event to trigger bell-icon updates and SignalR push notifications for the affected users, ensuring they are alerted to direct mentions within channels.
src/Modules/Chat/Modules.Chat.Contracts/Events · high confidence
New integration event for issued invoices
The billing module now exposes an InvoiceIssuedIntegrationEvent to signal when an invoice has been issued and is ready for payment. This event carries essential billing details such as the invoice ID, number, amount, currency, and due date, enabling downstream consumers to trigger tenant notifications regarding new billing obligations.
src/Modules/Billing/Modules.Billing.Contracts/Events · high confidence
New modular infrastructure components for ALB, ECS, CloudWatch, and S3/CloudFront
The deployment infrastructure now includes dedicated Terraform modules for core AWS resources, allowing for more granular and reusable configuration. The new ALB module provisions Application Load Balancers with configurable HTTP/HTTPS listeners, SSL policies, and logging. The ECS Cluster module manages cluster settings, capacity providers (defaulting to Fargate), and optional ECS Exec command logging. The CloudWatch Alarms module introduces monitoring for ECS services (CPU, memory, task count), RDS instances (CPU, storage, connections, latency), and ALB metrics, with notifications sent via SNS. Additionally, the S3 Bucket module has been expanded to support CloudFront distributions with Origin Access Controls, intelligent tiering, and comprehensive lifecycle and CORS configurations.
(repo-wide) · high confidence
New pagination extension for paginating IQueryable results
A new \PaginationExtensions\ class has been added to the persistence building blocks, providing a \ToPagedResponseAsync\ extension method for \IQueryable\ sources. This allows consumers to easily convert query results into a \PagedResponse\ with metadata (total count, total pages) while enforcing a default page size of 20 and a maximum limit of 100. The implementation handles page number validation and relies on pre-applied ordering from specifications or explicit calls, decoupling pagination logic from sorting concerns.
src/BuildingBlocks/Persistence/Pagination · high confidence
New persistence interceptors for audit tracking and domain events
Added two new Entity Framework Core interceptors in the persistence building blocks: \AuditableEntitySaveChangesInterceptor\ automatically populates audit metadata (created/modified timestamps and user IDs) for entities implementing \IAuditableEntity\, and handles soft deletes for \ISoftDeletable\ entities while preserving owned-type references to prevent database constraint violations; it also includes a recursion guard to prevent stack overflows during nested save operations. \DomainEventsInterceptor\ automatically publishes domain events collected from tracked entities after a successful save, ensuring that event handlers do not fail the database transaction if they throw exceptions.
src/BuildingBlocks/Persistence/Inteceptors · high confidence
New polished UI component library for dashboard list and detail pages
The dashboard now uses a new set of UI components in the list area to replace older patterns, providing a consistent, polished look across list and detail views. This includes a searchable Combobox for filters and form fields, a unified PageHero for non-list surfaces, and a full Entity shell (header, search, filter pills, pager, and list cards) for list pages. Detail views now feature an EntityDetailHero with avatar, badges, stats, and meta rows, along with an EntityDetailBack link. Supporting primitives like ToneIconTile, Field wrappers, and ErrorBands ensure visual consistency and accessibility throughout these surfaces.
clients/dashboard/src/components/list · high confidence
New session management contracts for Identity module
The Identity module now exposes a set of new command and query contracts to support user and administrative session management. Users can retrieve their own active sessions and revoke specific sessions or all sessions (optionally excluding one). Administrators gain the ability to view all sessions within a tenant with pagination and search filtering, as well as revoke individual or all sessions for a specific user. These contracts define the interface for the underlying session handling logic.
src/Modules/Identity/Modules.Identity.Contracts/v1/Sessions · high confidence
New single-host Docker Compose deployment for FullStackHero
A new production-grade Docker Compose setup is now available in the deploy/docker directory, allowing users to deploy the full FullStackHero stack (API, Admin, Dashboard, Postgres, Valkey, and MinIO) on a single host. The configuration includes a .env.example file documenting all required environment variables (such as JWT keys, admin passwords, and public URLs), a docker-compose.yml that orchestrates the services with health checks and dependency ordering, and a README with a five-minute deployment guide. Key operational details include the use of Valkey instead of Redis, a dedicated migrator service for database schema updates and seeding, and a MinIO initialization step to ensure the storage bucket exists before the API starts.
deploy/docker · high confidence
New standalone React admin console with Docker deployment
A new standalone admin console built with React 19, Vite 7, and Tailwind 4 has been added to the \clients/admin\ directory. It includes a Dockerfile that builds the SPA and serves it via nginx, featuring runtime configuration injection through \envsubst\ for API and dashboard URLs. The setup provides a complete development environment with Vite proxying for local API calls, ESLint configuration for code quality, and Playwright for end-to-end testing.
clients/admin · high confidence
New storage request and metadata models for presigned uploads
The storage building block now includes three new types to support presigned URL workflows: \FileUploadRequest\ carries the filename, content type, and byte data for uploads; \PresignedUploadUrl\ represents the short-lived URL and required headers for direct browser-to-storage PUTs; and \StoredObjectMetadata\ holds size, content type, last modified date, and ETag returned by a HEAD request, enabling the Files module to verify upload integrity upon finalization.
src/BuildingBlocks/Shared/Storage · high confidence
New structured exception types for HTTP error handling
The core exception library now includes \CustomException\ as a base class that carries an HTTP status code and a list of detailed error messages, along with specific subclasses for common HTTP errors: \UnauthorizedException\ (401), \ForbiddenException\ (403), and \NotFoundException\ (404). These types allow the application to throw exceptions that explicitly convey the HTTP response status and associated validation or business-rule errors, enabling more consistent and informative error responses across the stack.
src/BuildingBlocks/Core/Exceptions · high confidence
New system pages for tenant-wide session management and unified trash/recycle bin
The dashboard now includes two new system-level pages. The Sessions page allows administrators to view, search, and filter active and inactive user sessions across the tenant, with the ability to revoke individual sessions or all sessions for a specific user. The Trash page provides a unified view for soft-deleted records (products, brands, categories, tickets, and files), allowing users to restore items from a single interface, with tab visibility gated by specific permissions.
clients/dashboard/src/pages/system · high confidence
New tenant management and branding tools in the admin interface
The admin panel now includes several new components for managing tenant lifecycles and appearance. Operators can create new tenants via a modern dialog with live preview and plan selection, adjust a tenant's validity date directly without issuing an invoice, and renew or change subscription plans. Additionally, a new branding card allows operators to edit light and dark color palettes and brand assets for individual tenants.
clients/admin/src/components/tenants · high confidence
New tenant-facing dashboard with real-time usage and live activity
A new standalone tenant dashboard has been added to the product, providing a user interface for monitoring account status and activity. The dashboard displays current-period usage against plan limits via bar charts, shows subscription details, and presents a live feed of activity events using Server-Sent Events (SSE). It supports user customization through selectable accent palettes, 12 font families, and a compact density mode. The application is built with React 19, Vite 7, and Tailwind 4, and includes a Dockerfile for containerized deployment with Nginx.
clients/dashboard · high confidence
New ticket management interface with listing, detail, and actions
The dashboard now includes a dedicated Tickets section, introducing a main listing page for searching, filtering by status and priority, and creating new tickets, alongside a detailed view for inspecting ticket properties, viewing comment threads, and performing actions such as assigning, resolving, or reopening tickets.
clients/dashboard/src/pages/tickets · high confidence
New unified UI primitives for the admin list and form views
The admin interface now uses a new set of shared UI components in the list area to standardize the look and feel of pages and forms. This includes a new EntityPageHeader for consistent page titles and counts, a FormShell with FormSection and FormActions for structured editor layouts, and a SettingsSection for compact configuration cards. Form inputs are wrapped in a new Field component that automatically handles accessibility labels, hints, and error states, while a new Select component replaces native dropdowns with a Radix-based menu. Additional primitives like ErrorBand, FilterBar, Pagination, and Stat tiles provide consistent feedback, filtering, and data display across the admin dashboard.
clients/admin/src/components/list · high confidence
New usage snapshot capture and retrieval endpoints
Operators can now manually capture usage snapshots for billing purposes via a new POST /usage/snapshots/capture endpoint, which is idempotent and restricted to root operators or the tenant's own context to prevent cross-tenant data fabrication. Additionally, a GET /usage endpoint allows listing captured usage snapshots, with access controls ensuring non-root tenants can only view their own data while root operators can filter by specific tenant, year, and month.
src/Modules/Billing/Modules.Billing/Features/v1/Usage · high confidence
New user management API contracts for the Identity module
The Identity module now exposes a comprehensive set of command and query contracts for user administration, enabling features such as user registration, profile updates (including avatar/image management), role and group assignment, password changes, and email confirmation workflows. These contracts define the input/output structures for operations like searching, retrieving, activating, and deleting users, forming the backend interface for the User Management UI.
src/Modules/Identity/Modules.Identity.Contracts/v1/Users · high confidence
New v1 Identity API contracts for role and permission management
This change introduces the v1 contract definitions for the Identity module, enabling new role and permission capabilities. For roles, users can now create or update roles (UpsertRole), retrieve single or paginated lists of roles (GetRole, GetRoles), delete roles (DeleteRole), and update the permissions assigned to a specific role (UpdatePermissions). Additionally, a new query (GetRoleWithPermissions) allows retrieving a role along with its associated permissions, and a permission catalog query (GetPermissionCatalog) exposes the available permissions filtered by tenant context.
src/Modules/Identity/Modules.Identity.Contracts/v1/Roles · high confidence
New v1 multitenancy API endpoints for tenant lifecycle, status, and theme management
This change introduces a comprehensive set of v1 API endpoints for the Multitenancy module, enabling operators and tenants to manage tenant lifecycles and configurations. Key capabilities include creating tenants with automatic plan-based validity and billing events (CreateTenant), adjusting tenant validity dates explicitly (AdjustTenantValidity), and renewing subscriptions with optional plan switching (RenewTenant). Operators can now activate or deactivate tenants (ChangeTenantActivation), view detailed migration statuses across all tenants (GetTenantMigrations), and manage tenant-specific UI themes (GetTenantTheme, UpdateTenantTheme, ResetTenantTheme). Additionally, tenants can check their own status (GetMyTenantStatus) and provisioning progress (GetTenantProvisioningStatus), while operators can retry failed provisioning workflows (RetryTenantProvisioning). All endpoints are secured with specific permissions and follow a consistent command/query pattern.
src/Modules/Multitenancy/Modules.Multitenancy/Features/v1 · high confidence
New wallet top-up request workflow and wallet retrieval endpoints
This change introduces a complete lifecycle for wallet top-up requests within the Billing module, allowing tenants to submit requests for additional funds and administrators to approve or reject them. Users can now create a top-up request via a new POST endpoint, view their own pending or completed requests through a paginated list, and retrieve their current wallet balance. Administrators gain the ability to view all top-up requests across tenants, approve requests to generate invoices, and reject requests with a reason. The implementation enforces strict multi-tenant isolation, ensuring users only see and modify data for their own tenant, while root administrators have cross-tenant visibility.
src/Modules/Billing/Modules.Billing/Features/v1/Wallets · high confidence
Notifications module database schema and tenant isolation
This change introduces the initial database migration for the Notifications module, creating a 'Notifications' table in the 'notifications' schema with fields for user ID, type, title, body, link, source, metadata, and timestamps. It also adds a subsequent migration that enforces multi-tenancy by adding a required 'TenantId' column to the table and marking the entity for Finbuckle multi-tenant isolation.
src/Host/FSH.Starter.Migrations.PostgreSQL/Notifications · high confidence
Per-version OpenAPI documentation with Bearer authentication and Scalar UI
The OpenAPI building block now generates separate OpenAPI documents for each configured API version (e.g., /openapi/v1.json), automatically applying Bearer token authentication to all endpoints in those documents. A new configuration model (OpenApiOptions) allows setting the API title, description, contact, license, and the list of versions to document. The API also exposes a Scalar-based interactive reference page, configured to prefer Bearer security and use the Alternate theme with dark mode enabled.
src/BuildingBlocks/Web/OpenApi · high confidence
PostgreSQL initialization script adds required extensions
A new SQL initialization script (01-create-databases.sql) has been added to the Docker deployment configuration. This script runs on the first boot to ensure that the pgcrypto, uuid-ossp, and pg\_trgm extensions are installed in the fsh database, which are required for the application's security, UUID generation, and full-text search capabilities.
deploy/docker/postgres-init · high confidence
Real-time chat and presence updates via SignalR
The dashboard now uses a shared SignalR connection to receive live chat events (such as message creation, editing, deletion, and typing indicators) and user presence status changes. This connection is authenticated via access tokens and automatically rebuilds when tokens rotate or the user signs in, while avoiding unnecessary reconnection attempts when signed out. User presence is tracked in real-time through hub events, with a fallback polling mechanism to ensure status updates are eventually consistent even if the real-time connection is temporarily unavailable.
clients/dashboard/src/realtime · high confidence
Reliable outbox event dispatch with multi-instance safety and per-tenant drainage
The framework now persists integration events in an outbox table that commits atomically with the business transaction, ensuring events are never lost or published for rolled-back work. A background hosted service periodically drains the outbox, correctly handling multi-tenant scenarios by dispatching from every tenant database rather than just the default one. For deployments running multiple dispatcher instances, the system uses PostgreSQL's FOR UPDATE SKIP LOCKED to safely lease messages, preventing duplicate delivery, and implements exponential backoff with dead-lettering for failed events, allowing operators to inspect and redrive stuck messages.
src/BuildingBlocks/Eventing/Outbox · high confidence
Repository initialization and developer onboarding documentation
The repository has been initialized with a complete set of developer onboarding and governance files. This includes a comprehensive \README.md\ and \README-template.md\ detailing the .NET 10 / React 19 tech stack, Aspire orchestration, and deployment options. A new \AGENTS.md\ file establishes the canonical guide for AI coding tools, with \CLAUDE.md\ and \GEMINI.md\ acting as thin bridges. The project now enforces a single \main\ branch model (removing \develop\) via \CONTRIBUTING.md\ and \SECURITY.md\. Infrastructure and build hygiene are improved with a new \.dockerignore\ to exclude test and build artifacts, a \coverage.runsettings\ file to exclude background services from coverage metrics, and a \global.json\ pinning the SDK to version 10.0.100.
(repo-wide) · high confidence
Shared validation rules for paginated queries
A new PagedQueryValidator has been added to the Web Validation building block to standardize validation for paginated requests. This validator automatically enforces that the page number is greater than 0, the page size is between 1 and 100, and the sort expression does not exceed 200 characters, reducing code duplication across query validators.
src/BuildingBlocks/Web/Validation · high confidence
Tenant storage quota enforcement and S3/MinIO support
The storage subsystem now supports S3-compatible backends (including MinIO) via configuration, allowing users to switch from local file storage to cloud storage. Additionally, when the quota system is enabled, the framework enforces per-tenant storage limits by metering bytes on upload and refunding them on delete, rejecting uploads that exceed the tenant's allocated quota with an insufficient storage error.
src/BuildingBlocks/Storage · high confidence
Tickets module v1: full ticket lifecycle and soft-delete support
This change introduces the v1 Tickets module, providing endpoints to create, search, update, and view tickets, as well as assign, resolve, close, and reopen them. It adds the ability to post comments on tickets and lists them, and implements soft-delete with a trash view and restore capability. Ticket numbers are generated sequentially per tenant (e.g., TK-1), and all write endpoints are idempotent; authorization is enforced via ticket-specific permissions.
src/Modules/Tickets/Modules.Tickets/Features/v1 · high confidence
Webhook subscription management and delivery tracking
This change introduces the v1 API endpoints for managing webhook subscriptions, allowing users to create, list, delete, and test subscriptions. The Create endpoint validates that webhook URLs use HTTP or HTTPS schemes and blocks private or loopback hosts to prevent Server-Side Request Forgery (SSRF) attacks, while also protecting signing secrets at rest. Users can view paginated lists of their subscriptions and delivery history, and trigger test deliveries to verify endpoint connectivity.
src/Modules/Webhooks/Modules.Webhooks/Features/v1 · high confidence
Removals
Removal of default Weather Forecast API endpoint
The default Weather Forecast controller, which previously exposed a GET endpoint returning simulated weather data, has been removed from the application. Users will no longer have access to this sample API route.
src/Bootstrapper/Controllers · high confidence
Security
Identity module event handlers now minimize PII in logs and use outbox for integration events
The Identity module's event handlers have been updated to improve security and reliability. Logging statements in handlers for password changes, session revocations, user activation/deactivation, and role assignments now use pseudonymous UserIds instead of email addresses to minimize personally identifiable information (PII). Additionally, the handler for new user registrations now publishes integration events via the outbox pattern rather than directly to the bus, ensuring reliable delivery, and the welcome email handler includes error handling that logs failures by UserId without exposing the recipient's email address.
src/Modules/Identity/Modules.Identity/Events · high confidence
Architecture
Identity module service interfaces moved to Contracts project
The service interfaces for the Identity module (including user management, roles, sessions, impersonation, and password handling) have been moved from the implementation project to the \Modules.Identity.Contracts\ project. This change establishes a clear separation of concerns by defining the public API surface in the contracts layer, which should improve modularity and reduce coupling between the identity implementation and other parts of the system.
src/Modules/Identity/Modules.Identity.Contracts/Services · high confidence
Behavioural changes
API host initialization, hardened production config, and outbox job cleanup
The FSH.Starter.Api host now initializes the application via Program.cs, registering all module assemblies (Identity, Multitenancy, Auditing, Webhooks, Billing, Catalog, Tickets, Files, Chat, Notifications) and enabling framework features like caching, jobs, and real-time communication. Production deployments are hardened with strict configuration requirements (Database, Redis, JWT keys) and security headers, while the Dockerfile switches to a chiseled .NET 10 runtime for a smaller attack surface. To prevent log flooding from retired per-module Hangfire jobs, a new background service automatically cleans up orphaned outbox-dispatcher recurring jobs on startup.
src/Host/FSH.Starter.Api · high confidence
Added authorization permission definitions for Auditing and Billing modules
New permission contracts have been introduced for the Auditing and Billing modules, defining the specific access controls available to users. For Auditing, the system now supports a basic 'View Audit Trails' permission and a root-level 'View Audit Trails Across Tenants' permission, which allows querying audits across all tenants rather than being restricted to the current tenant's data. For Billing, two permissions are defined: 'View Billing' for basic read access and 'Manage Billing' for administrative control. These definitions establish the foundational authorization rules that backend services and UI components will enforce.
src/Modules/Auditing/Modules.Auditing.Contracts/Authorization, src/Modules/Billing/Modules.Billing.Contracts/Authorization · high confidence
Added marker class for identity contract assembly scanning
A new marker class, IdentityContractsMarker, has been added to the Modules.Identity.Contracts assembly. This type serves as a signal for assembly scanning mechanisms (such as MediatR handlers or dependency injection registrations) to identify and process contracts within the identity module, ensuring that related services and interfaces are correctly discovered and wired up.
src/Modules/Identity/Modules.Identity.Contracts · high confidence
Admin app introduces centralized SignalR connection management
The admin application now uses a new RealtimeProvider context to manage a single shared SignalR connection to the /api/v1/realtime/hub endpoint. This implementation automatically handles reconnection with exponential backoff and, crucially, stops the connection attempt when the user is signed out to prevent anonymous negotiation spam. The context exposes a status indicator and an event subscription mechanism, currently pre-registering for 'NotificationCreated' events to ensure the dashboard receives updates reliably.
clients/admin/src/realtime · high confidence
AppHost scaffolding now auto-seeds admin and demo tenants on launch
The AppHost orchestration now automatically runs a database migrator and seeders when the application starts, provisioning a root admin account and demo tenant data without manual intervention. This change ensures the development environment is ready to use immediately after launch, while also introducing a persistent Valkey cache (replacing the previous Redis setup) and configuring MinIO with CORS settings to support browser-based file uploads directly from the admin and dashboard interfaces.
src/Host/FSH.Starter.AppHost · high confidence
Audit records database schema hardened with optimized indexes
The PostgreSQL audit schema has been updated to improve query performance and data handling. The \TenantId\ column type was changed from \character varying(64)\ to \text\ to remove length restrictions. Additionally, the database now enables the \pg\_trgm\ extension and replaces the previous single-column indexes with a more robust set of composite and specialized indexes, including GIN indexes on \PayloadJson\ and trigram-based indexes on \Source\ and \UserName\, alongside composite indexes for tenant-scoped lookups.
src/Host/FSH.Starter.Migrations.PostgreSQL/Audit · high confidence
Caching building block migrated to HybridCache with OpenTelemetry observability
The caching infrastructure in src/BuildingBlocks/Caching has been replaced with Microsoft.Extensions.Caching.Hybrid, providing a layered L1 (in-process) and L2 (Redis or in-memory) cache. This change introduces configurable SSL/TLS for Redis connections via CachingOptions, standardized cache key conventions with bulk invalidation tags (e.g., permissions, themes, idempotency), and transparent OpenTelemetry integration. An ObservableHybridCache decorator now automatically records cache hits, misses, invalidations, and factory execution durations, giving users built-in observability for caching performance without code changes.
src/BuildingBlocks/Caching · high confidence
Catalog database schema: soft deletes, product images, and model fixes
The PostgreSQL catalog migrations now support soft deletes for Brands, Categories, and Products, adding IsDeleted, DeletedBy, and DeletedOnUtc columns and filtering unique slug indexes to exclude deleted records. Product images have been moved from a single ImageUrl column on Products to a dedicated ProductImages table that supports multiple images per product with thumbnail and sort-order tracking, including a migration that preserves existing image URLs as thumbnails. The ProductImage entity's ID generation is explicitly configured as client-side (ValueGeneratedNever) to align with the application's GUID strategy, and the previous partial unique index on ProductImages.IsThumbnail has been removed to allow multiple thumbnails per product.
src/Host/FSH.Starter.Migrations.PostgreSQL/Catalog · high confidence
Chat module authorization permissions and assembly registration
The Chat module now defines specific authorization requirements for channel and message operations. Users must be granted permissions to view and create channels, manage all channels, send messages, edit or delete their own messages, and delete any message. Additionally, a marker class has been added to ensure the Mediator source generator correctly scans the Chat contracts assembly for command and query records.
src/Modules/Chat/Modules.Chat.Contracts, src/Modules/Chat/Modules.Chat.Contracts/Authorization · high confidence
Chat module internal authorization, mapping, and attachment URL resolution
The chat module now includes internal helpers to enforce channel membership and admin roles (throwing 404 for non-members to prevent probing), map domain entities to DTOs, and resolve expired presigned attachment URLs at read time by fetching fresh ones from the Files module. This ensures historical images remain accessible and access policies are re-enforced on every view.
src/Modules/Chat/Modules.Chat/Features/v1/Internal · high confidence
Dashboard application scaffold with runtime configuration and modernized UI components
The dashboard client has been restructured with a new entry point that loads runtime configuration from /config.json at boot, enabling dynamic settings for API URLs, demo mode, and inactivity timeouts. The application shell now integrates a custom 'FshToaster' for notifications that respects the in-app theme (light/dark) rather than the OS preference, and includes a command palette provider. Routing is implemented with lazy-loaded chunks for all pages (login, catalog, settings, files, etc.) to improve initial load performance, featuring dedicated error boundaries and skeleton loading states. Additionally, the app handles specific terminal states for tenant deactivation and impersonation revocation, ensuring graceful UX when access is lost mid-session.
clients/dashboard/src · high confidence
Database schema updates for multi-tenancy, themes, quotas, and expiry notices
This location introduces a series of PostgreSQL migrations for the multi-tenancy module. The schema now supports tenant provisioning workflows with tracking tables for steps and status. Tenant themes have been added to allow customization of colors, fonts, and logos (including dark mode variants), with URL fields for assets expanded to 2048 characters. Tenant records now include a 'Plan' field and a 'QuotaLimits' JSONB column to manage resource constraints. Finally, a new 'TenantExpiryNotices' table has been added to track expiration notifications, ensuring administrators are alerted before tenant access expires.
src/Host/FSH.Starter.Migrations.PostgreSQL/MultiTenancy · high confidence
Enforce permission-based authorization and secure JWT configuration
The Identity module now enforces a unified permission-based authorization policy for all endpoints, ensuring that role-based access control is consistently applied via both default and fallback policies to prevent broken access control. Additionally, JWT bearer options are hardened with strict validation (including signing key length and placeholder detection), HTTPS metadata requirements, and improved error handling that surfaces specific rejection reasons in development while maintaining opaque responses in production. Impersonation tokens are now validated against a revocation service to ensure immediate effect of grant revocation.
src/Modules/Identity/Modules.Identity/Authorization/Jwt · high confidence
Enforce simultaneous per-tenant, per-user, and per-IP rate limiting
The application now applies chained rate limits based on tenant, user, and IP address simultaneously, using a fixed-window algorithm. Health check endpoints are exempt from these limits. When a limit is exceeded, clients receive a 429 Too Many Requests response with an RFC 6585-compliant ProblemDetails JSON body, including Retry-After, traceId, and correlationId headers for debugging.
src/BuildingBlocks/Web/RateLimiting · high confidence
Enforces uploader-based access control for file operations
The Files module now implements a default authorization policy that restricts file attachment to authenticated users, allows public files to be read by any tenant user while restricting private files to the uploader, and limits file deletion exclusively to the uploader. This policy serves as the baseline for built-in owner types, with other modules able to register custom implementations to override these rules.
src/Modules/Files/Modules.Files/Authorization · high confidence
Eventing tables moved to framework schema with outbox lease support
The database migration for the eventing subsystem now creates the InboxMessages and OutboxMessages tables within the 'framework' schema instead of the default schema. Additionally, the OutboxMessages table has been extended with 'ClaimedBy' and 'ClaimedUntilUtc' columns and a new 'IX\_OutboxMessages\_Pending' index to support row-level leasing (FOR UPDATE SKIP LOCKED) for outbox processing, ensuring safer concurrent consumption of events.
src/Host/FSH.Starter.Migrations.PostgreSQL/Eventing · high confidence
File assets now support tenant isolation
The database schema for the Files module has been updated to support multi-tenancy. A new 'TenantId' column was added to the 'FileAssets' table, and the unique constraint on 'StorageKey' was modified to be scoped per tenant (unique per StorageKey + TenantId). This ensures that file assets are isolated by tenant, preventing cross-tenant access via storage keys.
src/Host/FSH.Starter.Migrations.PostgreSQL/Files · high confidence
Files module introduces access policy registry and secure storage key generation
The Files module now enforces stricter security and organization for stored files. A new \FileAccessPolicyRegistry\ allows modules to register specific access policies per owner type, defaulting to forbidden if no policy is found. Additionally, the \StorageKeyBuilder\ generates canonical storage keys that include a mandatory tenant prefix and sanitize filenames to prevent cross-tenant collisions and unsafe characters. A no-op file scanner is also provided as a placeholder for future antivirus integration.
src/Modules/Files/Modules.Files/Services · high confidence
Files module introduces granular visibility controls and permission-based access
The Files module now supports per-file visibility settings (Public or Private) and a dedicated permission catalog. Users can change a file's visibility after upload, with access governed by specific permissions such as Upload, Delete Own, Delete Any, View Trash, and Restore. The module exposes new commands and queries to manage these visibility states, list shared files, and handle file access policies, ensuring that only authorized users can modify or view files based on their ownership and assigned roles.
src/Modules/Files/Modules.Files.Contracts · high confidence
Identity domain entities now support domain events, soft deletes, and impersonation tracking
The Identity module's domain layer has been refactored to introduce Domain-Driven Design patterns. FshUser now implements IHasDomainEvents, emitting lifecycle events for registration, password changes, activation, deactivation, and role assignments. Group entities now support soft deletion and implement IAuditableEntity. New domain models have been added to support administrative features: ImpersonationGrant tracks server-side impersonation sessions for revocation, UserSession manages refresh tokens and session revocation with domain events, and PasswordHistory stores password hashes to enforce history policies. These changes enable more robust auditability, security controls, and event-driven behavior within the identity system.
src/Modules/Identity/Modules.Identity/Domain · high confidence
Identity module database schema and initialization restructured for multitenancy and new features
The Identity module's data layer has been rebuilt to support multitenancy, user groups, and password history. Entity Framework Core configurations now explicitly mark core identity tables (Users, Roles, UserClaims, etc.) as multitenant, while ImpersonationGrants are configured as non-multitenant to allow cross-tenant auditing. The database context now includes DbSets for new domain entities: PasswordHistory, UserSession, Group, GroupRole, UserGroup, and ImpersonationGrant. A new initializer seeds default roles, system groups ("All Users" and "Administrators"), and admin users per tenant, and enforces password policies including history tracking and expiry settings.
src/Modules/Identity/Modules.Identity/Data · high confidence
Inactivity auto-logout with warning modal
Authenticated users are now automatically signed out after a period of inactivity, with a visible countdown warning giving them the option to stay logged in or sign out immediately. This security feature uses runtime configuration to define idle and warning durations, ensuring sessions are terminated promptly to protect user accounts.
clients/dashboard/src/components/auth · high confidence
Introduce global exception handler with structured error responses
A new GlobalExceptionHandler has been added to standardize how API errors are reported to clients. It converts unhandled exceptions into RFC 7807 ProblemDetails responses, mapping specific exception types (such as FluentValidation.ValidationException, CustomException, UnauthorizedAccessException, KeyNotFoundException, and BadHttpRequestException) to appropriate HTTP status codes (400, 401, 404, 500) and including detailed error messages. The response payload now includes trace and correlation IDs to aid in debugging and log correlation, while sensitive stack traces are logged server-side but not exposed in the client response.
src/BuildingBlocks/Web/Exceptions · high confidence
Introduce tenant lifecycle, quota, and secure provisioning models
The multitenancy building block now includes a richer tenant model that supports plan-based quota limits and per-tenant overrides, along with explicit activation/deactivation and validity periods (including a default one-month demo period for new tenants). A new in-process password buffer ensures initial admin passwords are passed securely from tenant creation through background provisioning without ever being persisted on the tenant record. Constants for the root tenant and schema are also standardized.
src/BuildingBlocks/Shared/Multitenancy · high confidence
Introduce transactional outbox and per-tenant event dispatching abstractions
The eventing layer now supports durable, at-least-once delivery via a transactional outbox pattern, replacing direct event bus publishing with an IOutboxWriter that persists events within the caller's database transaction. To ensure correct multi-tenant isolation during background processing, new abstractions (IEventTenantScope, IEventingDrainScope, EventingDrainTarget) establish the ambient tenant context and connection string before handlers are resolved, allowing the dispatcher to drain outbox rows from dedicated per-tenant databases.
src/BuildingBlocks/Eventing.Abstractions · high confidence
Introduces a modern design-token system with swappable accent palettes and improved contrast
The dashboard now uses a new CSS design-token architecture in globals.css, replacing the previous global warm-cream tint with neutral greys to prevent color casts and ensure selected accent palettes (rose, indigo, violet, sky, emerald, amber) appear correctly. This system introduces shadcn-compatible semantic variables, explicit surface elevation tiers, and a theme contract that allows users to select from 12 fonts and multiple accent colors via the Appearance settings. Additionally, muted foreground contrast has been increased to meet WCAG 2.2 AA standards, and typography now uses Outfit for headings and Figtree for body text.
clients/dashboard/src/styles · high confidence
Introduces structured query contracts for auditing endpoints
The auditing module now exposes specific query objects for retrieving audit data, enabling more granular filtering and pagination. Users can fetch a single audit by ID, view a summary with date and tenant filters, or retrieve paginated lists of audits with support for sorting, severity, tags, source, correlation/trace IDs, and search. New dedicated queries allow filtering security events by action and user, and exception events by area, severity, type, and location, with explicit skip/take parameters for paging. Additionally, audits can be retrieved by correlation or trace ID within a date range, and a new ExcludeEventType filter allows hiding specific event types (like system HTTP noise) while maintaining correct paging totals.
src/Modules/Auditing/Modules.Auditing.Contracts/v1 · high confidence
Modern dialog for creating new users
The user creation interface in the admin panel has been replaced with a modern dialog component. This change introduces a streamlined, modal-based workflow for adding new accounts, featuring integrated form validation via Zod and real-time error handling. Users can now create accounts directly from the current view without navigating to a separate page, with immediate feedback on success or failure via toast notifications.
clients/admin/src/components/users · high confidence
New high-performance, dual-lane auditing pipeline with security guarantees
The auditing module has been replaced with a new, production-grade implementation that uses a non-blocking, channel-based publisher with two distinct lanes: a high-throughput default lane that drops oldest events under pressure to maintain low latency, and a compliance-grade security lane that never drops events and back-pressures publishers to ensure critical security events (like login failures or impersonation) are always captured. A dedicated background worker drains these channels in batches with exponential backoff and retries, sending failed batches to a dead-letter queue to prevent data loss during sink outages. The system now includes OpenTelemetry metrics for monitoring published, dropped, flushed, and dead-lettered events, and provides a fluent API for creating audit events with automatic enrichment of tenant, user, and trace context from both HTTP and background (Hangfire) scopes.
src/Modules/Auditing/Modules.Auditing/Core · high confidence
New path-aware authorization and automatic role-permission synchronization
The Identity module now includes a custom authorization middleware that bypasses permission checks for specific public paths (such as /scalar, /openapi, and /favicon.ico) while enforcing standard policies for all other endpoints. Additionally, a background service runs at startup to automatically sync permission claims to the built-in Admin and Basic roles for each tenant, ensuring that newly defined permissions are immediately available without manual intervention.
src/Modules/Identity/Modules.Identity/Authorization · high confidence
New specification pattern for composable, strongly-typed EF Core queries
The persistence layer now introduces a specification pattern (ISpecification, Specification, SpecificationEvaluator) that allows queries to be built by composing filters, includes, and ordering expressions rather than writing raw LINQ. This enables consistent application of EF Core behaviors such as AsNoTracking, AsSplitQuery, and IgnoreQueryFilters, and supports projected queries (ISpecification\<T, TResult\>) with a Selector. A key behavioral addition is the ApplySortingOverride method, which allows client-provided sort expressions (e.g., "Name,-CreatedOn") to override default ordering using a whitelist of sort keys, ensuring deterministic results when no valid client sort is provided. Extension methods (ApplySpecification) simplify applying these specifications to IQueryable instances.
src/BuildingBlocks/Persistence/Specifications · high confidence
OpenTelemetry observability now respects orchestrator environment variables and exports metrics more frequently
The OpenTelemetry configuration in the web building block has been updated to improve integration with orchestrators like Aspire and reduce dashboard latency. The service name is now automatically adopted from the \OTEL\_SERVICE\_NAME\ environment variable (falling back to the application name), ensuring the process is listed only once in the dashboard. Additionally, OTLP metric exports now default to a 10-second interval (instead of the SDK's 60-second default) to prevent empty metric views after restarts, while still honoring the \OTEL\_METRIC\_EXPORT\_INTERVAL\ environment variable. The setup also respects \OTEL\_EXPORTER\_OTLP\_ENDPOINT\ for automatic collector discovery.
src/BuildingBlocks/Web/Observability/OpenTelemetry · high confidence
Optimized validation pipeline behavior for mediator commands and queries
The system now uses a new ValidationBehavior that reduces runtime allocations and reflection overhead during request validation. By caching validators into an array and handling single-validator cases separately, the framework avoids per-request array allocations and unnecessary Task.WhenAll calls, resulting in faster validation for commands and queries that rely on FluentValidation.
src/BuildingBlocks/Web/Mediator · high confidence
Persistence layer refactored to support atomic cross-context transactions and strict tenant isolation
The persistence infrastructure in src/BuildingBlocks/Persistence has been rebuilt to ensure data integrity and security. A new ScopedDbConnectionProvider and AmbientDbTransactionRegistry now allow multiple DbContexts within a single scope to share the same database connection, enabling outbox writes to enlist in the business transaction atomically rather than committing separately. Additionally, BaseDbContext now enforces tenant isolation by default for all new entities (unless marked as IGlobalEntity) and supports tenant-specific connection strings while maintaining transactional consistency. The layer also introduces connection string validation for PostgreSQL and SQL Server, named global query filters for soft deletes, and startup logging for database configuration.
src/BuildingBlocks/Persistence · high confidence
Plan creation and editing moved to a dialog interface
The billing plan management interface now uses a modal dialog for creating and editing plans, replacing the previous navigation-based flow. This change consolidates the plan form into a reusable component that handles both creation and editing states, providing immediate feedback via toast notifications and automatically refreshing the plan list upon successful submission.
clients/admin/src/components/billing · high confidence
Redesigned audit trail interface with side-sheet detail view
The admin audits section has been rebuilt with a new list page and a slide-out detail sheet. The list page now features a summary strip showing total events, errors, security events, and exceptions, along with a filter bar for event type, severity, tenant ID, and correlation ID, plus debounced text search. Clicking an audit item opens a side sheet (AuditDetailSheet) that displays the full forensic record, including identity badges (event type, severity, source), correlation IDs (trace, span, correlation, request), context grid, and payload panel, replacing the previous full-page detail view.
clients/admin/src/pages/audits · high confidence
Redesigned tenant management with dialog-based creation and detailed status views
The tenant management interface has been rebuilt with a new list view that displays tenants in a paginated table (desktop) or cards (mobile), featuring status badges for activation and expiry states. Tenant creation now occurs via an inline dialog launched from the list page rather than a separate page, with the old /tenants/new route redirecting to the list to preserve bookmarks. The new tenant detail page provides a comprehensive overview including identity, branding, and subscription details, and introduces capabilities for live provisioning status monitoring (with auto-retry and polling), tenant activation/deactivation, plan renewal, validity adjustment, and user impersonation, all gated by specific admin permissions.
clients/admin/src/pages/tenants · high confidence
Redesigned user and role management interfaces with modern dialogs and filtering
The admin console's user and role management pages have been completely rewritten to use a modern, dashboard-style UI. User creation is now handled via a dialog launched from the list view, with legacy direct URLs redirecting seamlessly to the list. The user list now supports pagination, debounced search, and filtering by status, email confirmation, and assigned role. The user detail view provides a comprehensive identity card, role assignment editor, and session management. Similarly, role management features a new list view with search, a dialog-based creation flow, and a detail view that distinguishes between editable custom roles and read-only system roles, allowing administrators to manage permission grants.
clients/admin/src/pages/users · high confidence
Refactored demo data seeding into a dedicated migrator component
The logic for populating the development environment with rich demo content (including the 'acme' and 'globex' tenants, their users, roles, catalog items, tickets, and chat data) has been moved from the API runtime into a new \DemoSeeder\ class within the \FSH.Starter.DbMigrator\ project. This change ensures that demo data is provisioned exclusively via the migrator's \seed-demo\ command rather than mutating the database on API startup, aligning with the project's principle of separating migration concerns from runtime behavior. The new seeder is idempotent, meaning re-running the command against an already-seeded database is a safe no-op, and it correctly handles tenant provisioning records and subscription seeding to ensure the admin panels and dashboards display accurate data out of the box.
src/Host/FSH.Starter.DbMigrator/DemoSeed · high confidence
Removal of legacy .NET 5 ASP.NET Core project structure
The traditional ASP.NET Core project scaffolding has been removed from the Bootstrapper project. Specifically, the \Program.cs\ entry point, the \Startup.cs\ class (which previously handled service configuration and middleware pipeline setup including Swagger and HTTPS redirection), and the sample \WeatherForecast.cs\ model have been deleted. This change eliminates the standard \IHostBuilder\ and \IStartup\ pattern, indicating a migration away from the classic ASP.NET Core hosting model (likely towards .NET 6+ minimal APIs or a different hosting strategy defined in other parts of the application).
src/Bootstrapper · high confidence
Starter Kit now deploys React SPAs and a one-shot DB Migrator on AWS with safer, region-aware scripts
The Starter Kit deployment has shifted from a server-rendered Blazor service to hosting two private React SPAs (Dashboard and Admin) via S3 and CloudFront, with Terraform managing their runtime configuration. Database migrations are now executed as a one-shot ECS Fargate task after infrastructure apply, supporting optional demo tenant seeding. Deploy and destroy scripts for both bash and PowerShell enforce an explicit AWS region, isolate Terraform state per environment/region to prevent cross-region clobbering, and fail fast on image build or migration errors.
deploy/terraform/apps/starter · high confidence
Starter app stack infrastructure modernized with Terraform 1.15.4 and AWS provider 6.46
The Starter app stack has been updated to use Terraform core version 1.15.4 and the AWS provider version 6.46, with the provider lock file committed to ensure reproducible builds. This change introduces a collapsed root module structure for the app stack, featuring a partial S3 backend configuration for state management and explicit provider default tags for environment, project, and owner tracking. The infrastructure now supports modernized networking with VPC endpoints for S3, ECR, Logs, and Secrets Manager, and provisions an Application Load Balancer with optional HTTPS and WAF integration. Additionally, the stack now includes outputs for hosting React SPAs (Dashboard and Admin sites) via S3 and CloudFront, and exposes details for a one-shot DbMigrator ECS task.
_deploy/terraform/apps/starter/app\stack · high confidence
Switch logging implementation to Serilog with OTLP export
The application's logging infrastructure has been replaced with Serilog, introducing structured logging that enriches events with HTTP context details (method, path, user identity, tenant) and supports exporting logs via OTLP to the Aspire dashboard. This change ensures logs are grouped under the correct service name in observability tools and respects the global OpenTelemetry configuration for endpoint and protocol settings.
src/BuildingBlocks/Web/Observability/Logging · high confidence
Tickets module database schema with soft delete and tenant isolation
The PostgreSQL migration files for the Tickets module now define the initial schema for the Tickets and TicketComments tables, including support for soft deletes (IsDeleted, DeletedOnUtc, DeletedBy columns) and multi-tenant isolation (TenantId column). The schema ensures that ticket numbers remain unique per tenant and that soft-deleted records are excluded from unique constraints via database filters.
src/Host/FSH.Starter.Migrations.PostgreSQL/Tickets · high confidence
Upgrade to .NET 10 and enforce strict build quality standards
The project has upgraded its target framework to .NET 10 (net10.0) and enabled the latest C\# language features. To ensure code quality and consistency between local development and CI, the build system now treats all warnings as errors, enforces code style analysis, and utilizes a centralized Directory.Build.props file. This change also introduces a new .editorconfig for consistent C\# formatting and establishes a source-ownership model where only the CLI and template projects are packaged as NuGet packages, preventing accidental publication of internal module binaries.
src · high confidence
Upgrade to Asp.Versioning 10.0.0 and configure API versioning
The project has upgraded the Asp.Versioning library from version 8.1.1 to 10.0.0. This change includes the addition of a new \Extensions.cs\ file in the \src/BuildingBlocks/Web/Versioning\ directory, which registers the API versioning services. The configuration sets the default API version to 1.0, enables version reporting, assumes the default version when unspecified, and reads the API version from the URL segment. It also configures the API explorer to group versions in the format 'vVVV' and substitute the API version in the URL.
src/BuildingBlocks/Web/Versioning · high confidence
Webhooks schema updated with multi-tenancy and renamed secret column
The PostgreSQL webhooks migration now includes a TenantId column on both the Subscriptions and Deliveries tables to support multi-tenancy, and the Subscriptions table's SecretHash column has been renamed to ProtectedSecret.
src/Host/FSH.Starter.Migrations.PostgreSQL/Webhooks · high confidence
Fixes
Dashboard API client and error-handling infrastructure
The dashboard now uses a dedicated API client that enforces per-request timeouts (defaulting to 30 seconds) to prevent stalled requests, and includes robust error handling for critical session states: it detects tenant deactivation (403) and impersonation revocation (401) to route users to dedicated terminal pages instead of leaving them with broken error banners. The client also aligns with the server's token refresh contract and surfaces specific validation or identity errors to users. Supporting this are utilities for consistent date/time formatting, a global React Query error hook to manage these terminal states, permission maps to gate Recycle bin tabs, and hooks to resolve user IDs and usernames for display in chat and mentions.
clients/dashboard/src/lib · high confidence
Ensure wwwroot directory exists for API startup
Added a .gitkeep file to the wwwroot directory to ensure the folder is present in the repository. This prevents a DirectoryNotFoundException during application initialization, as the static web assets system requires the physical directory to exist before the builder runs.
src/Host/FSH.Starter.Api/wwwroot · high confidence
Test coverage
Added E2E tests for impersonation session revocation handling; Added Playwright E2E tests for Chat and Files pages; Added Playwright E2E tests for dashboard authentication flows; Added Playwright E2E tests for the admin client; Added Playwright end-to-end tests for Dashboard Settings; Added Playwright end-to-end tests for Identity management pages; Added Playwright end-to-end tests for dashboard system pages; Added Playwright end-to-end tests for the dashboard overview, activity, and invoices pages; Added Playwright test helpers for the dashboard; Added end-to-end tests for billing subscription and WhatsApp wallet features; Enforce architectural rules via Architecture.Tests.
Dependencies
Upgrade to .NET 10 and React 19 with Aspire 13.4
The application has been upgraded to .NET 10 (targeting net10.0) and the frontend admin and dashboard clients now use React 19, Vite 7, and Tailwind CSS 4. The infrastructure layer has been updated to Aspire 13.4.0 for hosting JavaScript, PostgreSQL, and Redis services. Additionally, several NuGet packages have been pinned to address security vulnerabilities, including System.Security.Cryptography.Xml (10.0.10), Microsoft.OpenApi (2.9.0), and MessagePack (2.5.301).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 62.
Lenses
- Code Health 53
- Architecture 85
- Maturity 65
- Readiness 69
- Security 78
- Domain Modelling 67
- Event-Driven 90
- Accessibility 82
- Performance 77
Changes since last survey
- 300 commits — 176 feature/other, 124 fixes
By area
- (repo) — 78 commits
- src/Modules — 45 commits
- clients/admin — 34 commits
- src/Tests — 25 commits
- src/BuildingBlocks — 19 commits
- clients/dashboard — 18 commits
- deploy/terraform — 13 commits
- src/Host — 11 commits
- (root) — 9 commits
- .github/workflows — 8 commits
- docs/src — 8 commits
- src/Directory.Packages.props — 6 commits
- superpowers/plans — 6 commits
- .agents/skills — 3 commits
- src/Tools — 3 commits
- superpowers/specs — 3 commits
- src/FSH.Starter.slnx — 2 commits
- .agents/rules — 1 commit
- .template.config/icon.png — 1 commit
- .template.config/template.json — 1 commit
Notable commits
- fix: @ fix(docker): create MinIO bucket in prod compose + add migrator to root compose
- fix: Merge branch 'main' into chore/aws-deploy-fixes-and-comment-trim
- fix: Merge branch 'main' into fix/permission-gate-nav-surfaces
- fix: Merge branch 'main' into fix/scaffold-dx
- fix: Merge branch 'main' into fix/template-ide-excludes
- fix: Merge pull request #1255 from fullstackhero/fix/template-ide-excludes
- fix: Merge pull request #1257 from fullstackhero/fix/cli-doctor-info
- fix: Merge pull request #1259 from fullstackhero/fix/scaffold-dx
- fix: Merge pull request #1260 from fullstackhero/fix/demo-login-and-session-restore
- fix: Merge pull request #1262 from fullstackhero/fix/scaffold-no-frontend-build-and-health-url
- fix: Merge pull request #1263 from fullstackhero/fix/dev-root-password-advertisement
- fix: Merge pull request #1264 from fullstackhero/fix/cli-version-comparison-and-version-flag
- fix: Merge pull request #1265 from fullstackhero/fix/remove-unimplemented-sqlserver-option
- fix: Merge pull request #1267 from fullstackhero/fix/admin-app-issues
- fix: Merge pull request #1271 from fullstackhero/fix/billing-tenant-security-audit
- fix: Merge pull request #1277 from fullstackhero/fix/eventing-tenant-context-outbox-dispatch
- fix: Merge pull request #1279 from fullstackhero/fix/dashboard-and-platform-fixes
- fix: Merge pull request #1280 from fullstackhero/fix/ci-resend-verb-and-password-toggle-label
- fix: Merge pull request #1281 from fullstackhero/fix/dashboard-tenant-deactivated-and-impersonation-exit
- fix: Merge pull request #1282 from fullstackhero/fix/inactivity-stale-activity-stamp
- …and 280 more
API surface
- 168 HTTP endpoints (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
fullstackhero/dotnet-starter-kit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3f2959e683e9f83f13e55e1678c9119f63c7e8e5 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.