KouShenhai/KCloud-Platform-IoT
37.6
Weak · 22 September 2026
95.2k
lines of production code
Java
with TypeScript
6
measurements over time
What this system is
This system is an enterprise-grade IoT cloud platform that manages device connectivity, data ingestion, and multi-tenant administration through a microservices architecture. It features a reactive Spring Cloud gateway for routing and authentication, a Go-based edge gateway for local device management, and a comprehensive backend handling user, device, and configuration data. The platform integrates distributed caching, message queuing, and various storage backends to support scalable IoT operations and visualization.
How it got here
2022–2024 — Platform initialization and core infrastructure
115 changes.
The project was initialized as an enterprise-grade IoT cloud platform, establishing a comprehensive microservices architecture with Spring Boot 3, Nacos, and DDD-based domain layers. This period focused on building foundational common modules for security, caching, logging, and distributed locking, while bootstrapping core services for authentication, administration, and IoT device management.
2025 — Common utilities and observability expansion
80 changes.
This period focused on expanding the laokou-common library with extensive utility classes for encryption, internationalization, and data handling, alongside new AOP aspects for distributed locking, rate limiting, and idempotency. Significant work was also done to enhance system observability by implementing comprehensive operation and trace logging via Kafka, supporting both Elasticsearch and Loki backends. Additionally, the team introduced new infrastructure for IoT visualization, OSS file management, and reactive WebSocket support.
2026 — Edge Gateway and Distributed Infrastructure
42 changes.
This period focused on establishing the KEdge Gateway for IoT device management and implementing a distributed Snowflake ID service with gRPC integration. Significant effort was also directed toward expanding the common storage abstraction to support TDengine and enhancing security through OAuth2 opaque token authentication across gRPC and web layers.
Features
Add API interfaces and DTOs for trace logging and Loki integration
The logstash client module now exposes a new \TraceLogServiceI\ interface and associated DTOs (\TraceLogSaveCmd\, \LokiPushDTO\) to support trace log persistence and Loki-based log pushing. This change introduces the data contracts required for the new reactive logstash implementation, specifically enabling the storage of trace messages and the formatting of logs for Loki ingestion via stream labels.
laokou-service/laokou-logstash/laokou-logstash-client · high confidence
Add API secret request filter
A new \ApiSecretRequestFilter\ has been introduced to intercept incoming requests. When a controller method is annotated with \@ApiSecret\, the filter wraps the original request in a custom wrapper before passing it to the next filter in the chain; otherwise, the request proceeds unchanged. This enables downstream components to access modified or secured request data for API secret validation.
laokou-common/laokou-common-secret/src/main/java/org/laokou/common/secret/filter · high confidence
Add CSV utility for writing CSV files
Introduces a new CsvUtils class in the laokou-common-csv module that provides a static method to write data to CSV files. The utility leverages the OpenCSV library (com.opencsv.CSVWriter) and accepts a functional Executor interface, allowing users to define how rows are written to the file via a lambda or method reference.
laokou-common/laokou-common-csv/src/main · high confidence
Add Checkstyle and SpotBugs configurations with GraalVM JDK 25 base images
This change introduces static analysis tooling and updates the container base images for the laokou-cloud modules. Checkstyle configurations (including header templates, suppressions, and rules prohibiting unused imports, System.out, and specific Lombok/Spring annotations) are added to the root and laokou-gateway/laokou-monitor directories. SpotBugs exclusion filters are added to the root, laokou-gateway, and laokou-monitor directories. Additionally, Dockerfiles for laokou-gateway, laokou-monitor, and laokou-nacos are created or updated to use the GraalVM JDK 25.0.2 base image, and Nacos startup scripts for Linux and Windows are added to support standalone and cluster modes with ZGC enabled.
laokou-cloud · high confidence
Add CommandLog annotation for command execution tracking
A new @CommandLog annotation has been introduced in the domain layer to mark methods for command execution logging. This enables better tracking and observability of command operations within the system.
laokou-common/laokou-common-domain/src/main/java/org/laokou/common/domain/annotation · high confidence
Add Fory-based Kafka serializer and deserializer
The Kafka module now includes \ForyKafkaSerializer\ and \ForyKafkaDeserializer\ classes that use the \ForyFactory\ for serializing and deserializing message payloads. This allows Kafka producers and consumers to leverage Fory's serialization capabilities instead of standard Java or JSON serialization. A corresponding integration test suite verifies the correct serialization of simple objects, complex nested structures, and null/empty fields, as well as end-to-end message transmission via Kafka.
laokou-common/laokou-common-kafka · high confidence
Add ForyConstants utility class with integer constants
A new \ForyConstants\ class has been added to the \laokou-common-fory\ module, providing a centralized set of integer constants (C\_1 through C\_84) for use within the Fory serialization library.
laokou-common/laokou-common-fory/src/main/java/org/laokou/common/fory/constant · high confidence
Add OperateEvent domain event for operation logging
A new OperateEvent class has been introduced in the operation log handler to capture detailed user activity data. This event extends the existing DomainEvent base and includes fields for tracking the operation name, module, URI, HTTP method, request parameters, user agent, IP address, operator identity, execution status, cost time, and error details. It utilizes Lombok's SuperBuilder pattern for construction, enabling structured logging of user interactions within the system.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/handler/event · high confidence
Add OperateLog annotation for operation logging
A new @OperateLog annotation has been introduced in the common-log module, allowing developers to mark methods with a module name and operation description to facilitate structured operation logging.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/annotation · high confidence
Add SFTP client support with upload, download, and delete capabilities
The laokou-common-sftp module now provides an SFTP client implementation, replacing the previous FTP functionality. Users can configure connection details (host, port, username, password, directory) via the spring.sftp prefix. The new SFtpTemplate component enables file operations including uploading, downloading, and deleting files on an SFTP server, utilizing the JSch library for secure transfers. A corresponding test suite validates these operations using a Testcontainers-based SFTP server.
laokou-common/laokou-common-sftp · high confidence
Add SMS result and status entity classes
New entity classes have been added to the SMS module to support structured response handling. SendStatusEnum defines send outcomes with OK (0) and FAIL (1) statuses, while SmsResult provides a serializable container for SMS operation details including name, status, error messages, parameters, and captchas.
laokou-common/laokou-common-sms/src/main/java/org/laokou/common/sms/entity · high confidence
Add SMS service interface and GYY provider implementation
The SMS module now exposes a \SmsService\ interface with a \send\ method and provides an initial implementation via \GYYSmsServiceImpl\. This implementation integrates with the GYY (Guoyangyun) SMS gateway, using configured appcode and template IDs to send verification codes to mobile numbers, and includes logic to map template IDs to specific message content.
laokou-common/laokou-common-sms/src/main/java/org/laokou/common/sms/service · high confidence
Add centralized Docker image name definitions for testcontainers
A new utility class, DockerImageNames, has been added to the testcontainers module to provide a single source of truth for Docker image references used in testing. This class defines specific versions for services including Consul (1.14), Redis, Elasticsearch (using a compatible substitute image), Nacos (v3.1.0), SFTP, MinIO, PostgreSQL, OAuth2, Kafka, and Pulsar (4.0.3). This change standardizes the image tags and repositories across the test suite, ensuring consistent test environments.
laokou-common/laokou-common-testcontainers/src/main/java/org/laokou/common/testcontainers/util · high confidence
Add centralized date and string constant definitions
The i18n common module now includes dedicated constant classes for date formats and string literals. DateConstants defines standard timestamp patterns (such as yyyy-MM-dd HH:mm:ss) and the default GMT+8 timezone, while StringConstants provides reusable values for separators, operators, and the Bearer authentication prefix, allowing other components to reference these shared definitions instead of hardcoding them.
laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/common/constant · high confidence
Add email verification code sending capability
The mail module now includes a concrete implementation for sending email verification codes. A new abstract service base and a specific \MailServiceImpl\ have been added to handle SMTP configuration via \MailProperties\ and to generate numeric codes with a 5-minute validity period, returning structured results indicating success or failure.
laokou-common/laokou-common-mail/src/main/java/org/laokou/common/mail/service/impl · high confidence
Add global exception handler for HTTP method and validation errors
The core module now includes a GlobalExceptionHandler that standardizes error responses. It catches SystemException, BizException, and ParamException to return their specific codes and messages. Crucially, it now handles HttpRequestMethodNotSupportedException by returning a localized message listing the supported HTTP methods, and it processes MethodArgumentNotValidException and ValidationException to extract and return the first field validation error.
laokou-common/laokou-common-core/src/main/java/org/laokou/common/core/exception · high confidence
Add mail result DTO and send status enum
The mail module now includes a new MailResult data transfer object and a SendStatus enumeration to standardize the representation of email sending outcomes. MailResult encapsulates the result details including a fixed operation code (send\_mail\_captcha), status, error message, parameters, and captcha, while SendStatus defines the possible outcomes (OK or FAIL) with corresponding codes and descriptions.
laokou-common/laokou-common-mail/src/main/java/org/laokou/common/mail/dto · high confidence
Add sensitive data masking annotations for JSON serialization
Introduced the @Sensitive annotation, along with the SensitiveSerializer and SensitiveType enum, to enable automatic masking of sensitive fields during JSON serialization. Developers can now annotate fields with @Sensitive(type = SensitiveType.MAIL) or @Sensitive(type = SensitiveType.MOBILE) to automatically format and mask email addresses and mobile numbers respectively in API responses.
laokou-common/laokou-common-sensitive/src/main/java/org/laokou/common/sensitive/annotation · high confidence
Add user-specific and system-wide menu tree building services
The menu service layer now includes dedicated implementations for constructing menu trees: SystemMenuTree retrieves the full menu hierarchy for system-wide contexts, while UserMenuTree fetches menus scoped to a specific user, applying caching and distinguishing between super-admin and regular user access. These services are wired through the MenusServiceImpl, which exposes the tree-building capability via the listTreeMenu method, enabling the UI to render role-based navigation structures.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/menu/service · high confidence
Added AES and RSA encryption utility classes
The \laokou-common-crypto\ module now includes \AESUtils\ and \RSAUtils\ to provide symmetric and asymmetric encryption capabilities. \AESUtils\ implements AES-GCM encryption and decryption, loading a 32-byte key and 12-byte IV from resource files (\conf/secretKey.b256\ and \conf/secretIV.b12\) to produce Base64-encoded output that embeds the IV. \RSAUtils\ handles RSA encryption and decryption using keys loaded from \conf/publicKey.scr\ and \conf/privateKey.scr\, offering methods to encrypt with the public key and decrypt with the private key, with specific error handling for key failures.
laokou-common/laokou-common-crypto/src/main/java/org/laokou/common/crypto/util · high confidence
Added API secret annotation and auto-configuration support
Introduced the \@ApiSecret\ annotation for marking methods and the \@EnableApiSecret\ annotation to activate API secret functionality. The \@EnableApiSecret\ annotation automatically imports the \ApiSecretRequestFilter\, enabling request-level secret validation for secured endpoints.
laokou-common/laokou-common-secret/src/main/java/org/laokou/common/secret/annotation · high confidence
Added API signature validation utilities
Introduced new utility classes in the secret module to handle API authentication: \SecretUtils\ provides a method to generate MD5-based signatures from app credentials and parameters, while \ApiSecretParamValidator\ validates incoming API requests by checking app keys, secrets, nonces, timestamps (with a 60-second expiry window), and signature integrity.
laokou-common/laokou-common-secret/src/main/java/org/laokou/common/secret/util · high confidence
Added API signature verification aspect
A new aspect class, ApiSecretAspectj, has been introduced to automatically validate API request signatures. This component intercepts methods annotated with @ApiSecret and verifies the presence and correctness of security headers (app-key, app-secret, nonce, timestamp, and sign) along with request parameters, ensuring that only authenticated and tamper-proof requests are processed.
laokou-common/laokou-common-secret/src/main/java/org/laokou/common/secret/aspectj · high confidence
Added Idempotent annotation for marking idempotent operations
Introduced the \@Idempotent\ annotation in the \org.laokou.common.idempotent.annotation\ package, allowing developers to mark methods as idempotent. This annotation is retained at runtime and targets methods, enabling downstream infrastructure to identify and enforce idempotency constraints on API calls.
laokou-common/laokou-common-idempotent/src/main/java/org/laokou/common/idempotent/annotation · high confidence
Added IdempotentUtils for request deduplication
A new IdempotentUtils component has been introduced to handle idempotency checks. It validates that a request ID is present and uses Redis to atomically set a key associated with that ID, preventing duplicate submissions within the configured expiration window.
laokou-common/laokou-common-idempotent/src/main/java/org/laokou/common/idempotent/util · high confidence
Added InfluxDB auto-configuration and properties support
The laokou-common-influxdb module now includes Spring Boot auto-configuration for InfluxDB. A new SpringInfluxDBProperties class binds configuration under the spring.influx-db prefix, supporting both token-based and username/password authentication methods. The InfluxDBAutoConfig class provides beans for creating InfluxDBClient instances based on the configured authentication type, allowing applications to easily integrate with InfluxDB without manual client setup.
laokou-common/laokou-common-influxdb · high confidence
Added Kafka-based domain event publisher
A new KafkaDomainEventPublisher component has been introduced to handle domain events via Apache Kafka. This implementation uses Spring Kafka's KafkaTemplate to send DomainEvent payloads to the topic specified in the event's mqTopic field, providing a concrete mechanism for asynchronous event distribution within the domain layer.
laokou-common/laokou-common-domain/src/main/java/org/laokou/common/domain/support · high confidence
Added Kafka-based operation log handler
A new \OperateEventHandler\ component has been introduced to consume operation log events from a Kafka topic. It processes incoming \OperateEvent\ messages, maps them to data objects, and persists them to the database within a transaction, ensuring correct multi-tenant data source context handling during the write operation.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/handler · high confidence
Added MQTT plugin example and documentation
Introduced a new MQTT plugin example within the edge gateway, including a Go source file (main.go) that exports a 'parse' function and a README.md demonstrating how to load, call, and unload the plugin via the plugin manager.
KEdge-Gateway/pkg/plugins/mqtt · high confidence
Added Modbus protocol test assets
A new ZIP archive containing Modbus-related files has been added to the documentation tools directory. This asset likely includes the Modbus TCP/UDP test code and RTU/ASCII test cases mentioned in the associated commit history, providing resources for testing Modbus protocol implementations.
doc/tool · medium confidence
Added MySQL 9 Docker deployment configuration
A new MySQL 9 deployment configuration has been added to the documentation under doc/deploy/docker-compose/mysql9. This includes a my.cnf file that sets up the database with utf8mb4 character encoding, specific InnoDB and MyISAM buffer settings, and standard data directory paths for Docker-based deployment.
doc/deploy/docker-compose/mysql9 · high confidence
Added Nacos configuration and naming service utility classes
New utility classes \ConfigUtils\ and \NamingUtils\ have been added to the \laokou-common-nacos\ module to simplify interactions with the Nacos API. \ConfigUtils\ provides static methods to create \ConfigService\ instances for managing configuration data, while \NamingUtils\ offers similar helpers for creating \NamingService\ instances for service discovery. These utilities wrap the standard \NacosFactory\ methods, allowing developers to initialize Nacos clients with either a server address string or a \Properties\ object more conveniently.
laokou-common/laokou-common-nacos/src/main/java/org/laokou/common/nacos/util · high confidence
Added OSS query execution handlers for single and paginated retrieval
New command query executors have been added to the admin application to support retrieving OSS (Object Storage Service) data. OssGetQryExe enables fetching a single OSS record by ID, while OssPageQryExe provides paginated listing of OSS objects. Both components leverage the existing OssMapper for database access and OssConvertor for data transformation, exposing results via the standard Result wrapper.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/oss/command/query · high confidence
Added OperateLogConvertor for operation log data transformation
A new convertor class has been introduced in the log module to handle the mapping of operation log data between internal models, domain events, and database objects. This component facilitates the capture of request details (such as URI, IP address, and user agent) into a structured entity, transforms that entity into a domain event for further processing (including tenant and user context injection), and finally maps the event to a data object for persistence, with automatic truncation of stack traces and error messages to manage storage size.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/convertor · high confidence
Added OperateLogE entity for operation logging
A new entity class, OperateLogE, has been introduced in the i18n common module to model operation log data. This class captures details such as operation name, module, request URI, user agent, status, cost time, and error information, providing the data structure required for tracking and auditing user actions within the system.
laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/common/entity · high confidence
Added Redis 7 configuration file for Docker Compose deployment
A new Redis configuration file (redis.conf) has been added to the Docker Compose deployment directory for Redis 7. This file provides a standard configuration template including network binding settings, security options like protected mode, and basic network parameters, enabling users to deploy a configured Redis instance via Docker Compose.
doc/deploy/docker-compose/redis7 · high confidence
Added SMS auto-configuration for GYY provider
The SMS module now includes an auto-configuration class that registers a \SmsService\ bean for the GYY (Guoyang Cloud) provider when the \sms.type\ property is set to \GYY\ (or is missing). This configuration relies on new \SmsProperties\ that define the \sms\ configuration prefix, allowing users to specify GYY-specific settings such as \templateId\, \signId\, and \appcode\.
laokou-common/laokou-common-sms/src/main/java/org/laokou/common/sms/config · high confidence
Added Sentinel integration for request flow control and degradation
The laokou-common-sentinel module now integrates Alibaba Sentinel to handle request blocking, degradation, and rate-limiting. This change introduces a Spring Boot auto-configuration that registers a custom BlockExceptionHandler, which intercepts Sentinel exceptions (FlowException, DegradeException, ParamFlowException, SystemBlockException, and AuthorityException) and returns standardized, i18n-aware error responses to users instead of generic failures.
laokou-common/laokou-common-sentinel/src/main/java · high confidence
Added Spring Boot auto-configuration for mail service
The mail module now includes a Spring Boot auto-configuration class (MailAutoConfig) that automatically registers the MailService bean. This enables the application to use the mail service without manual configuration, leveraging standard Spring Boot mail properties.
laokou-common/laokou-common-mail/src/main/java/org/laokou/common/mail/config · high confidence
Added TopicUtils for Pulsar topic name construction
A new utility class, TopicUtils, has been added to the Pulsar module to simplify the creation of Pulsar topic names. It provides a static method, getTopic, which constructs a standard persistent topic URI by combining the tenant code, namespace, and topic name (e.g., persistent://tenant/namespace/topic). This utility supports multi-tenant scenarios and handles various input formats, including special characters and Unicode. A corresponding test suite has been added to verify the correct formatting and behavior of this utility across different inputs.
laokou-common/laokou-common-pulsar · high confidence
Added TraceLog annotation for method-level tracing
A new @TraceLog annotation has been introduced in the trace module, allowing developers to mark specific methods for tracing. This annotation is retained at runtime and targets methods, enabling downstream components to identify and process traced execution points.
laokou-common/laokou-common-trace/src/main/java/org/laokou/common/trace/annotation · high confidence
Added automatic AES encryption/decryption for MyBatis-Plus string fields
A new CryptoTypeHandler has been added to the MyBatis-Plus common module, enabling transparent encryption and decryption of string data at the database layer. When mapped to fields using this handler, string values are automatically encrypted with AES before being written to the database and decrypted upon retrieval, allowing developers to store sensitive data securely without manual cryptographic calls in business logic.
laokou-common/laokou-common-mybatis-plus/src/main/java/org/laokou/common/mybatisplus/handler · high confidence
Added base HTTP error and test validation i18n resource files
New internationalization resource files have been added to the i18n module to support localized error messages and testing. The \base\_message\ files (default, English, US English, and Simplified Chinese) provide translations for standard HTTP status codes and errors, including success, bad request, unauthorized, forbidden, not found, too many requests, internal server error, bad gateway, service unavailable, and method not allowed. Additionally, \test\_validation\ files (default, English, US English, and Simplified Chinese) were added to support i18n testing with a simple test message key.
laokou-common/laokou-common-i18n/src/main/resources · high confidence
Added cluster query execution handlers
New query executors have been added to the admin application to support retrieving cluster information. Specifically, ClusterGetQryExe enables fetching a single cluster by ID, while ClusterPageQryExe provides paginated listing of clusters. These components bridge the command/query interface with the underlying database mappers to return structured cluster data to users.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/cluster/command/query, laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/tenant/command/query · high confidence
Added command execution logging via aspect
A new aspect (CommandLogAspectj) has been introduced to automatically log the success or failure of commands annotated with @CommandLog. On success, it logs the command class name; on failure, it logs the error message and the full stack trace, ensuring better observability of command execution outcomes.
laokou-common/laokou-common-domain/src/main/java/org/laokou/common/domain/aspectj · high confidence
Added cryptographic key and configuration files
The crypto module now includes new configuration files for encryption operations: a private key (privateKey.scr), a public key (publicKey.scr), a secret initialization vector (secretIV.b12), and a secret key (secretKey.b256). These files provide the necessary cryptographic material for the application's data protection features.
laokou-common/laokou-common-crypto/src/main/resources · high confidence
Added data model and mapper for operation logs
The \laokou-common-log\ module now includes the \OperateLogDO\ data object and \OperateLogMapper\ interface, enabling the persistence of detailed user operation records. The data model captures key attributes such as operation name, module, request URI, user agent, operator, service ID, status, cost time, IP address, and stack trace, mapped to the \OPERATE\_LOG\_TABLE\ via MyBatis-Plus.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/mapper · high confidence
Added department command execution handlers
The application layer now includes dedicated command executors for department management operations, specifically saving, modifying, removing, importing, and exporting departments. These new components handle the application logic by validating parameters, converting data, and delegating to the domain service, with save and modify operations explicitly wrapped in transactions via TransactionalUtils. Additionally, the save command registers a specific serialization class with the Fory library to support data handling.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dept/command, laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dept/command/query · high confidence
Added department management service implementation
The DeptsServiceImpl class has been added to handle department-related operations within the admin application. This service implements the DeptsServiceI interface and delegates specific actions—such as saving, modifying, removing, importing, and exporting departments, as well as querying department lists and trees—to corresponding command and query executors.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dept/service · high confidence
Added dictionary management service implementation
The DictsServiceImpl class has been added to provide the application-layer implementation for dictionary operations. It implements the DictsServiceI interface and delegates specific actions—saving, modifying, removing, importing, and exporting dictionaries, as well as querying by ID or paginated lists—to their respective command and query executors.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dict/service · high confidence
Added distributed data caching aspect for annotation-driven cache operations
This change introduces the \DataCacheAspectj\ aspect and \OperateType\ enum in the \laokou-common-data-cache\ module, enabling developers to use the \@DataCache\ annotation to automatically manage distributed cache interactions. The aspect intercepts methods annotated with \@DataCache\, resolving cache names and keys via Spring Expression Language, and delegates execution to specific operation types (GET or DEL). The GET operation implements a cache-aside pattern with distributed locking to prevent cache stampedes, while the DEL operation evicts the specified cache entry.
laokou-common/laokou-common-data-cache/src/main/java/org/laokou/common/data/cache/aspectj · high confidence
Added distributed lock aspect and utility for Redis-based locking
This change introduces the \LockAspectj\ aspect and \LockUtils\ helper within the \laokou-common-lock\ module to enable declarative distributed locking via the \@Lock4j\ annotation. The aspect intercepts methods annotated with \@Lock4j\, resolving lock keys from SpEL expressions and enforcing timeout and retry policies through \LockUtils\, which manages the underlying Redisson lock acquisition and release. This provides a standardized, AOP-driven mechanism for developers to secure concurrent operations against Redis.
laokou-common/laokou-common-lock/src/main/java/org/laokou/common/lock/aspectj · high confidence
Added i18n error messages for user data decryption failures
New internationalization resource files (message.properties, message\_en.properties, message\_zh\_CN.properties, and message\_en\_US.properties) have been added to the context module. These files define user-facing error messages for scenarios where username, email, or phone number decryption fails, ensuring consistent error reporting across supported locales.
laokou-common/laokou-common-context/src/main/resources · high confidence
Added idempotency aspect to prevent duplicate request submissions
The \IdempotentAspectj\ class has been introduced in the idempotent common module to enforce request idempotency via AOP. When a method is annotated with \@Idempotent\, this aspect intercepts the call before execution, checking for duplicate submissions based on a \request-id\ header or parameter. If a repeat submission is detected, it throws a \SystemException\ with the code \S\_Idempotent\_RequestRepeatedSubmit\, thereby protecting backend services from processing the same request multiple times.
laokou-common/laokou-common-idempotent/src/main/java/org/laokou/common/idempotent/aspectj · high confidence
Added initial scaffolding for dynamic SQL execution and builders
This change introduces the foundational structure for a dynamic SQL module within the storage layer. It adds a \DynamicSqlExecutor\ class that wraps Spring's \JdbcTemplate\ and creates a \SqlContext\ for state management. Additionally, it establishes a \builder\ sub-package containing empty placeholder classes for standard SQL operations (Create, Read, Update, Delete, Drop), setting the stage for future implementation of dynamic query generation.
laokou-common/laokou-common-storage/src/main/java/org/laokou/common/storage/sql · high confidence
Added internationalized error messages for Sentinel resilience rules
The laokou-common-sentinel module now includes localized resource bundles (Chinese and English) for Sentinel-specific error messages. Users will see translated text for authorization rule errors, system rule errors, hot spot parameter flow control, degradation, and general flow control events, ensuring consistent user-facing language across different locales.
laokou-common/laokou-common-sentinel/src/main/resources/i18n · high confidence
Added load balancing algorithm implementations
Added new classes in the \laokou-common-algorithm\ module to support load balancing selection strategies. This includes an abstract base class \AbstractAlgorithm\ and concrete implementations for Hash, Random, and Round Robin algorithms, allowing users to select items from a list using different distribution logic.
laokou-common/laokou-common-algorithm/src/main/java/org/laokou/common/algorithm/template/select · high confidence
Added operation log aspect to capture method execution details
A new AOP aspect (OperateLogAspectj) has been introduced to automatically intercept methods annotated with @OperateLog. This aspect captures the target class and method names, request arguments, execution duration, and any thrown exceptions. Upon completion, it constructs an operation log entity and publishes it as a domain event via Kafka, enabling centralized tracking of user operations and system performance.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/aspectj · high confidence
Added query executors for retrieving and paginating data dictionary items
New command query executors have been introduced in the admin application to handle data dictionary lookups. The DictGetQryExe component now supports fetching a single dictionary item by its ID, while DictPageQryExe enables paginated retrieval of dictionary entries. Both executors leverage the existing DictMapper for database access and DictConvertor to transform data objects into client objects, providing the underlying logic for dictionary data queries within the admin module.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dict/command/query · high confidence
Added reactive security and status change notification configuration for Spring Boot Admin
The monitor module now includes a new reactive security configuration that enables compromised password checking via the Have I Been Pwned API and configures Spring Boot Admin's web security with disabled CSRF and custom login/logout handlers. Additionally, a status change notifier has been added to log instance status transitions (UP, DOWN, OFFLINE, UNKNOWN) for monitoring visibility.
laokou-cloud/laokou-monitor/src/main/java/org/laokou/monitor/config · high confidence
Added role management command executors with transactional support
The application layer now includes dedicated command executors for role management operations: saving, modifying, removing, modifying authority, importing, and exporting roles. These executors (RoleSaveCmdExe, RoleModifyCmdExe, RoleRemoveCmdExe, RoleModifyAuthorityCmdExe, RoleImportCmdExe, RoleExportCmdExe) delegate to the domain service and are wrapped in transactions via TransactionalUtils, ensuring data consistency for role creation, updates, deletions, and permission changes. The import and export executors are currently stubbed with parameter validation placeholders.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/role/command · high confidence
Added role query execution logic for list, page, and detail views
The role management module now includes backend query handlers that enable retrieving role data. Specifically, the system can now fetch a paginated list of roles, retrieve a full list of all roles sorted by display order, and fetch the details of a single role including its associated menu and department IDs. These changes provide the necessary data retrieval capabilities for the role management UI.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/role/command/query · high confidence
Added storage model enums and source configuration record
New model classes have been introduced in the storage module to support multi-database configurations. This includes a \StoragePolicy\ enum that maps storage types (TimescaleDB, ClickHouse, IoTDB, InfluxDB, TDengine) to data sources, along with placeholder column-type enums for each specific database engine. Additionally, a \SourceV\ record was added to encapsulate connection details such as endpoint, database name, username, and password.
laokou-common/laokou-common-storage/src/main/java/org/laokou/common/storage/model · high confidence
Added tenant management service implementation
The TenantsServiceImpl class has been added to the admin application layer, implementing the TenantsServiceI interface to handle tenant operations. This service acts as an application facade, delegating save, modify, remove, import, export, page query, and get-by-id requests to their respective command and query executors, thereby completing the implementation of the tenant management feature within the COLA architecture.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/cluster/service, laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/tenant/service · high confidence
Added trace ID and span ID injection for annotated methods
A new aspect in the trace module automatically injects trace and span identifiers into method results. When a method annotated with @TraceLog returns a Result object, the aspect now sets the traceId and spanId fields using the current tracing context, enabling end-to-end request tracking for these specific operations.
laokou-common/laokou-common-trace/src/main/java/org/laokou/common/trace/aspectj · high confidence
Added trace log consumer for multiple service topics
The logstash adapter now includes a new TraceLogHandler component that consumes trace logs from Kafka. This handler listens to six distinct topics (Gateway, Auth, Admin, IoT, OSS, and Report) using separate consumer groups, aggregates the messages, and saves them via the TraceLogService.
laokou-service/laokou-logstash/laokou-logstash-adapter · high confidence
Added trace log persistence capability
The logstash application now includes support for saving trace logs. This change introduces a new command executor and service implementation that handle the creation and storage of trace log messages, enabling distributed tracing visibility within the system.
laokou-service/laokou-logstash/laokou-logstash-app · high confidence
Added trace utility classes to expose trace and span IDs
Added MDCUtils and TraceUtils to the trace module. MDCUtils provides static methods to manage MDC context for traceId and spanId. TraceUtils is a Spring component that retrieves the current trace and span IDs, falling back to MDC values if the SpanContext is unavailable, ensuring trace identifiers are accessible even when the primary tracing context is not active.
laokou-common/laokou-common-trace/src/main/java/org/laokou/common/trace/util · high confidence
Admin client API and DTOs for cluster, department, and dictionary management
The admin client module now exposes service interfaces and data-transfer objects for managing clusters, departments, and dictionaries. Clusters support save, modify, remove, import, export, pagination, and single-item retrieval. Departments add a tree-list query alongside standard CRUD and pagination, with search fields for name, code, and remark. Dictionaries and their items follow the same CRUD and pagination pattern, with dictionary items supporting filtering by dictionary code, name, code, and status.
laokou-service/laokou-admin/laokou-admin-client · high confidence
Annotation-driven XSS and SQL injection protection
The XSS protection module now uses a declarative annotation model. Developers can enable the \XssRequestFilter\ globally via the \@EnableXss\ annotation, which imports the filter configuration. For field-level protection, the new \@XssSql\ annotation serializes values through \XssSerializer\, which sanitizes input by stripping SQL injection patterns via \XssUtils.clearSql\. A general \@Xss\ annotation is also provided for method-level targeting.
laokou-common/laokou-common-xss/src/main/java/org/laokou/common/xss/annotation · high confidence
Auth service bootstrapped with Spring Boot 3, OAuth2.1, and Log4j2
The auth service start module is now initialized with a new entry point (AuthApp) and environment-specific configurations (dev, test, prod). This introduces a shift to Spring Boot 3 with virtual threads enabled, and upgrades the logging infrastructure from Logback to Log4j2, which outputs JSON-formatted logs and integrates with Kafka for distributed tracing in production. The service is configured as an OAuth2.1 authorization server supporting multiple grant types (password, mail, mobile, client credentials, PKCE) and registers with Nacos for service discovery and configuration management.
laokou-service/laokou-auth/laokou-auth-start · high confidence
Automatic CORS configuration for cross-origin requests
The CORS module now provides an automatic configuration that registers a global CORS filter. This filter permits cross-origin requests from all origins, methods, and headers, supports credentials, and sets a one-hour preflight cache duration, ensuring that frontend applications can interact with the backend without manual CORS setup.
laokou-common/laokou-common-cors/src/main/java · high confidence
Automatic Nacos router configuration generation on startup
A new RouterHandler component has been added to the Nacos common module. Upon application startup, it automatically generates a router configuration snippet based on the current service ID and writes it to the logs, instructing users to copy the output into a router.json file for Nacos routing setup.
laokou-common/laokou-common-nacos/src/main/java/org/laokou/common/nacos/handler · high confidence
Automatic creation of Kafka trace-log topics and enhanced thread context propagation
The log4j2 module now automatically creates six Kafka topics (gateway-trace-log, auth-trace-log, admin-trace-log, iot-trace-log, oss-trace-log, and report-trace-log) via a Spring configuration bean, removing the need for manual topic setup. Additionally, a custom TtlThreadContextMap implementation is introduced to replace the default Log4j2 thread context map, using TransmittableThreadLocal to ensure that MDC context is correctly propagated across thread pools in asynchronous environments.
laokou-common/laokou-common-log4j2/src/main/java · high confidence
Automatic data filtering for user and department scope
The system now automatically restricts data access based on the current user's department and creator identity. By annotating methods with @DataFilter, queries are intercepted to append SQL filters that limit results to the user's authorized departments or their own records, while super administrators remain exempt from these restrictions.
laokou-common/laokou-common-mybatis-plus/src/main/java/org/laokou/common/mybatisplus/aspectj · high confidence
Automatic tenant ID injection for paginated queries
A new @Tenant annotation and its corresponding aspect now automatically inject the current user's tenant ID into the parameters of any method accepting a PageQuery argument. This ensures that paginated data retrieval is automatically scoped to the user's tenant without requiring manual parameter handling in service methods.
laokou-common/laokou-common-tenant/src/main/java/org/laokou/common/tenant/aspectj · high confidence
Custom Nacos load balancing with gray release and IPv6 support
The Nacos load balancing module now includes a custom implementation that supports gray release routing and IPv6 address handling. The new \NacosLoadBalancer\ and \LoadBalancerAlgorithm\ components allow requests to be routed to specific service versions based on the URL path (e.g., \/v1/\, \/v2/\) by filtering instances with matching metadata. Additionally, the system automatically detects local IPv6 support and filters service instances accordingly, preferring IPv6 addresses when available. This change replaces the default Spring Cloud load balancer behavior for Nacos services with a more feature-rich, configurable approach.
laokou-common/laokou-common-nacos/src/main/java/com · high confidence
Domain layer scaffolding for cluster, department, dictionary, and logging modules
The domain module now includes the foundational domain-layer components for several administrative features. This includes the cluster management domain service and gateway, the department management domain service with its aggregate root and entity, the dictionary and dictionary-item management domain services with their respective aggregates and entities, and the login and notice log domain services with their entities and status/type enums. These additions provide the core domain models and service interfaces for these areas.
laokou-service/laokou-admin/laokou-admin-domain · high confidence
Dynamic route management via Nacos and Redis
The gateway now supports dynamic route configuration by listening to Nacos for route definition changes and synchronizing them to Redis. This allows route updates to be applied across the gateway cluster without requiring a restart, with local cache refreshed automatically upon synchronization.
laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/repository · high confidence
Enable automatic CORS configuration in Spring Boot
The application now automatically applies Cross-Origin Resource Sharing (CORS) settings without manual bean definition. By adding the \CorsAutoConfig\ class to the Spring Boot auto-configuration imports, the framework detects and registers the CORS configuration on startup, simplifying setup for developers.
laokou-common/laokou-common-cors/src/main/resources · high confidence
Enables Spring Boot auto-configuration for data cache
The data-cache module now registers its auto-configuration class via the standard Spring Boot \AutoConfiguration.imports\ file. This allows the cache functionality to be automatically available to applications without requiring manual component scanning or explicit configuration imports.
laokou-common/laokou-common-data-cache/src/main/resources · high confidence
Gateway CORS and request matching configuration added
The gateway now includes explicit configuration for Cross-Origin Resource Sharing (CORS) and request pattern matching. A new \CorsConfig\ bean implements a WebFilter that dynamically handles preflight OPTIONS requests, allowing origins, headers, and methods from the incoming request, while setting credentials and a one-hour max age for preflight caching. Additionally, a \RequestMatcherProperties\ component is introduced to allow external configuration of ignored URL patterns via the \request-matcher.ignore-patterns\ property, enabling flexible exclusion of specific paths from gateway processing.
laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/config · high confidence
Generated command executors for OSS and Tenant management
The admin application layer now includes generated command executors for OSS and Tenant domains, handling save, modify, remove, import, and export operations. These executors enforce transactional boundaries via TransactionalUtils for create, update, and delete actions, and apply the CommandLog annotation to all commands to facilitate execution tracking.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/oss/command, laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/tenant/command · high confidence
Generated documentation assets now include dark theme support
The build output in target/generated-docs now includes CSS and JavaScript files that enable a dark theme toggle for the generated HTML documentation. Users viewing the documentation can switch between light and dark modes, with the site.css file defining the necessary CSS variables and media queries to handle the visual styling for both themes.
target · high confidence
Initial Edge Gateway UI with user, menu, and device management
The edgeGatewayUI module is introduced as a new frontend application built on @umijs/max and Ant Design. It provides a complete routing structure and UI for managing edge gateway resources, including a User Management page (CRUD for users with admin/operator roles), a Menu Management page (tree-based CRUD for navigation items with enable/disable status), and a Device List page (CRUD for IoT devices). The application implements JWT-based authentication by parsing tokens from localStorage to enforce access controls (e.g., restricting user/menu management to admins) and automatically attaching the token to API requests. It also includes a Login page, a Home page, and system management sections for permissions, logs, and configuration, with development proxying configured for the backend gateway service.
edgeGatewayUI · high confidence
Initial IoT MCP server tooling and configuration
The IoT MCP server module is introduced with a new device tool implementation and its Spring configuration. The \DeviceToolImpl\ class exposes a \getDeviceInfo\ tool that accepts a device serial number (SN) and returns it, while \McpConfig\ registers this tool as a \ToolCallbackProvider\ bean using Spring AI's method-based tool callback provider.
laokou-service/laokou-ai/laokou-ai-mcp-server/laokou-ai-iot-mcp-server/laokou-ai-iot-mcp-server-app, laokou-service/laokou-ai/laokou-ai-mcp-server/laokou-ai-iot-mcp-server/laokou-ai-iot-mcp-server-infrastructure · high confidence
Initial IoT visualization dashboard scaffold
The bigScreen module has been added as a new Umi-based frontend application for IoT data visualization. It provides a basic project structure including a layout with navigation links to Home and Docs pages, a home page displaying a welcome image, and a documentation page. The setup includes configuration for pnpm as the package manager, a Chinese npm registry mirror, and TypeScript support, requiring Node.js 18.x or higher to run.
bigScreen · high confidence
Initial PostgreSQL database schema and setup scripts for multi-tenant platform
This change introduces the complete database initialization scripts for the platform, targeting PostgreSQL 17. It includes \create\_db.sql\ to provision the required databases (\kcloud\_platform\, \kcloud\_platform\_nacos\, \kcloud\_platform\_iot\, \kcloud\_platform\_domain\, \snail\_job\, and \mqtt\) and a set of schema files defining the core tables. The \kcloud\_platform.sql\ script establishes the system management schema, including tables for clusters, departments (with hierarchical support up to 9 levels), and data dictionaries. The \kcloud\_platform\_iot.sql\ script defines the IoT domain tables for devices, sessions, and thing models (specifying data types, units, and limits). The \kcloud\_platform\_domain.sql\ script sets up logging tables for device events, properties, login attempts, notifications, and user operations. Additionally, it provides the necessary schema for Nacos configuration storage (\kcloud\_platform\_nacos.sql\), EMQX MQTT authentication and access control (\emqx.sql\), and Snail Job distributed task scheduling (\snail\_job.sql\).
doc/db · high confidence
Initial React-based IoT platform UI with internationalization and role-based access control
The UI module is introduced as a new React application built on the @umijs/max framework, providing the frontend interface for the IoT platform. It features a comprehensive internationalization system with locale files for English and Chinese, and implements role-based access control via an access.ts configuration that maps permissions and scopes to UI actions. The application includes a dynamic routing system, a home dashboard with device statistics and map visualization, and dedicated pages for managing IoT devices, system users, roles, menus, and dictionaries. Deployment is supported via a Dockerfile using Nginx, and the project is configured to use pnpm for package management.
ui · high confidence
Initial device, gateway, and product category management capabilities
The IoT application now provides the application-layer implementation for managing devices, gateways, and product categories. Users can perform full CRUD operations (save, modify, remove, import, export) and query devices and gateways via pagination or ID. Additionally, the gateway module supports sending commands to devices, including reading and writing properties and rebooting the gateway, with command logs available for tracking.
laokou-service/laokou-iot/laokou-iot-app · high confidence
Initial documentation site and archive structure
The archive location now contains the initial VuePress-based documentation site for KCloud-Platform-IoT, including the site configuration, theme settings, and custom styles. It also includes the initial README and a comprehensive set of guide articles covering project startup (monolith and microservice modes), Docker installation, and Linux commands, along with version update logs for releases 4.0.1, 4.0.2, and 4.0.3.
archive · high confidence
Initial gateway application entry point with reactive and virtual thread support
The gateway module now includes its main application class (GatewayApp) and package definition. This entry point initializes the Spring Boot application as a reactive web server, enables automatic context propagation for Project Reactor, and configures the runtime to use virtual threads for the bounded elastic scheduler. It also sets up Nacos as the route definition repository, disables Sentinel health checks, and ignores SSL trust verification during startup to facilitate secure service discovery.
laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway · high confidence
Initial implementation of the role management service
The role management capability is now available in the admin application. This change introduces the \RolesServiceImpl\ class, which implements the \RolesServiceI\ interface to handle core role operations including saving, modifying, removing, importing, and exporting roles, as well as querying roles by page, list, or ID. The service delegates these tasks to specific command and query executors, providing the backend logic for the role management feature.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/role/service · high confidence
Initial internal API, security, and infrastructure for the edge gateway
This change introduces the core internal backend for the KEdge Gateway, establishing the foundation for device management, user administration, and system configuration. It adds API handlers and routing for registering and managing IoT devices, as well as creating, listing, and updating users and menu items. Security is implemented via JWT-based authentication middleware and an admin-only access control layer, with user passwords hashed using bcrypt. The system relies on in-memory repositories with YAML persistence for users and menus, and introduces a WASM plugin engine (using Extism) for extensible logic. Additionally, it integrates RabbitMQ for messaging with automatic reconnection support and configures structured logging via Zap and Timberjack.
KEdge-Gateway/internal · high confidence
Initial launch configuration for the Snowflake ID service
The \laokou-snowflake-id-start\ module now provides the complete runtime setup for the Snowflake ID service. This includes the \SnowflakeIdApp\ entry point which configures the application as a servlet-based service with a gRPC server on port 20000, while explicitly excluding gRPC OAuth2 resource server auto-configuration. The service registers with Nacos for discovery and configuration management, connects to Redis via Lettuce, and utilizes Log4j2 for logging. Environment-specific configurations (dev, test, prod) are provided, with the production profile notably adding Kafka-based logging appenders for distributed trace logs.
laokou-service/laokou-report/laokou-report-start, laokou-service/laokou-snowflake-id/laokou-snowflake-id-start · high confidence
Initial release of the KEdge Gateway server and network management scripts
This change introduces the initial version of the KEdge Gateway, providing the core server entry point and network configuration utilities. The Go server (main.go) initializes logging, sets up default user and menu repositories from YAML files, and starts an HTTP API server on port 8888 using the Hertz framework. Additionally, a new shell script (arm64\_aarch64\_network.sh) is added to manage network interfaces (eth0, usb0, wlan0) on ARM64 devices, supporting operations like connecting via DHCP or static IP, managing Wi-Fi connections via NetworkManager, and retrieving network status.
KEdge-Gateway/cmd · high confidence
Initial support for TDengine as a data source
Added a new TDengine data source implementation within the storage module. This includes a configuration class (TDengineConfig) and a core implementation (TDengine) that manages the connection lifecycle using HikariCP with the TDengine WebSocket JDBC driver. The implementation provides methods to open and close the data source, validate connectivity, and initialize tables, enabling the application to store data in TDengine.
laokou-common/laokou-common-storage/src/main/java/org/laokou/common/storage/tdengine · high confidence
Introduce IoT MCP Server startup module and device API
This change adds the \laokou-ai-iot-mcp-server-start\ module, providing the entry point (\IoTMcpServerApp\) and configuration for the IoT MCP service. It includes a new \DeviceToolI\ interface for retrieving device information by serial number. The module is configured to run on port 14000 with a \/api\ context path, registers with Nacos in the \IOT\_MCP\_GROUP\, and connects to Redis. Logging is set up via Log4j2, with production environments additionally routing logs to Kafka.
laokou-service/laokou-ai/laokou-ai-mcp-server/laokou-ai-iot-mcp-server/laokou-ai-iot-mcp-server-start · high confidence
Introduce Nacos-based Snowflake ID generation for distributed clusters
The infrastructure module now includes a new configuration and implementation for generating unique IDs using the Snowflake algorithm backed by Nacos. This change adds the \IdGenerator\ interface, a \NacosSnowflakeIdGenerator\ implementation that automatically allocates unique datacenter and machine IDs via Nacos service discovery to prevent collisions in a cluster, and a Spring configuration class (\SnowflakeIdConfig\) to wire these components. It also introduces \SpringSnowflakeIdProperties\ to allow configuration of the Snowflake epoch start timestamp. This enables the service to generate distributed, time-ordered unique IDs without manual node configuration.
laokou-service/laokou-snowflake-id/laokou-snowflake-id-infrastructure · high confidence
Introduce OSS module with Local, Amazon S3, and MinIO storage support
The new laokou-common-oss module provides a unified object storage abstraction that supports three backends: local file storage, Amazon S3, and MinIO. Users can configure storage instances via the BaseOss model hierarchy (Local, AmazonS3, MinIO) and upload files through the auto-configured StorageTemplate, which selects a target storage using a hash-based load-balancing policy. The module includes Spring Boot auto-configuration (StorageAutoConfig) and model converters to map configuration parameters to the specific storage implementations.
laokou-common/laokou-common-oss · high confidence
Introduce Spring Boot Admin server for system monitoring
Added the \MonitorApp\ entry point and package definition for the new monitoring service. This component enables Spring Boot Admin Server capabilities (\@EnableAdminServer\) and integrates with Nacos for service discovery (\@EnableDiscoveryClient\). It is configured as a reactive web application and includes logic to ignore SSL trust issues and disable Nacos logging conflicts, providing a centralized dashboard for observing the health and status of other services in the cloud platform.
laokou-cloud/laokou-monitor/src/main/java/org/laokou/monitor · high confidence
Introduce standalone Netty-based WebSocket server with OAuth2 authentication and Nacos registration
The \laokou-common-websocket\ module now provides a dedicated, non-Spring-MVC WebSocket server built on Netty, configurable via \spring.websocket-server\ properties. This server supports SSL/TLS, configurable heartbeat mechanisms (PING/PONG), and integrates with OAuth2 opaque token introspection for client authentication. Upon startup, the server registers its instance in Nacos for service discovery. The implementation includes session management for tracking client connections and channel routing, allowing applications to enable this standalone WebSocket capability by simply adding the \@EnableWebSocketServer\ annotation.
laokou-common/laokou-common-websocket/src/main · high confidence
Introduces DDD-based DTO and domain event abstractions
The \laokou-common-i18n\ module now provides a set of new base classes and interfaces to support a Domain-Driven Design (DDD) architecture. This includes \AggregateRoot\ for managing domain events, \DomainEvent\ and \DomainEventPublisher\ for event handling, and CQRS-oriented request types like \Command\, \Query\, and \DTO\. Additionally, standard response and pagination structures (\Result\, \Page\, \PageQuery\) and client communication objects (\ClientObject\) are introduced to standardize data transfer across the application.
laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/dto · high confidence
Introduces OSS domain model and upload logging
The OSS domain layer now includes a new \OssDomainService\ that coordinates file uploads and logging via \OssGateway\ and \OssLogGateway\. The \OssA\ aggregate enforces a 100 MB file size limit and validates file extensions against the new \FileFormat\ enum (video, audio, image). Every upload is recorded in \OssLogE\, and the system checks for existing logs by MD5 before uploading, reusing the URL if a match is found. Factory methods and MQ topic constants for OSS logging are also added.
laokou-service/laokou-oss/laokou-oss-domain · high confidence
Introduces centralized cache name constants for data cache configuration
A new \NameConstants\ class has been added to the \laokou-common-data-cache\ module to standardize cache key naming. This class defines static string constants for various cache regions, including OSS, departments, dictionaries, menus, messages, packages, tenants, data sources, user menus, OSS logs, OSS resources, and sessions. This change provides a single source of truth for cache names used across the application, ensuring consistency in how these specific data caches are identified and accessed.
laokou-common/laokou-common-data-cache/src/main/java/org/laokou/common/data/cache/constant · high confidence
Introduces configurable local and distributed Redis cache managers
The \laokou-common-data-cache\ module now provides two distinct Spring \CacheManager\ implementations: \RedisCacheManager\ for distributed caching backed by Redisson's native map cache, and \LocalCacheManager\ for local caching backed by Redisson's local cached maps. These are registered via \DataCacheAutoConfig\ and configured through the \spring.cache\ prefix, allowing users to define TTLs and other properties for both distributed and local cache instances.
laokou-common/laokou-common-data-cache/src/main/java/org/laokou/common/data/cache/config · high confidence
Introduces core storage abstraction interfaces and data models
This change adds the foundational classes for the storage module, including the DataSource interface (defining open, close, create, and test operations), an AbstractDataSource base class, and a Config class for connection details. It also introduces domain models such as Table (with nested Column definitions) and TableData (carrying tenant, gateway, product, and device identifiers), establishing the structural basis for database interactions within the common storage layer.
laokou-common/laokou-common-storage/src/main/java/org/laokou/common/storage · high confidence
Introduction of Fory serialization configuration
A new ForyFactory configuration class has been added to manage the serialization setup. It initializes a ThreadSafeFory instance with Java-specific language settings, schema consistency mode, and code generation enabled, while explicitly disabling cross-language serialization and unknown class deserialization to enhance security and compatibility.
laokou-common/laokou-common-fory/src/main/java/org/laokou/common/fory/config · high confidence
Introduction of MailService interface for email sending
A new MailService interface has been added to the mail module, defining a send method that accepts an email address and returns a MailResult. This establishes the contract for sending emails within the application, serving as the primary entry point for mail-related functionality in this component.
laokou-common/laokou-common-mail/src/main/java/org/laokou/common/mail/service · high confidence
Introduction of common domain interfaces for ID generation, storage, and validation
The \laokou-common-i18n\ module now exposes three new core interfaces to standardize cross-module contracts: \IdGenerator\ for producing single or batch unique identifiers, \OssStorage\ as a contract for object storage operations, and \ValidateName\ for retrieving validation-specific names. These interfaces provide the abstraction layer required for the distributed ID strategies and storage features mentioned in the commit history, allowing implementations elsewhere in the system to adhere to these standardized behaviors.
laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/common · high confidence
IoT domain layer introduces DDD-based services and gateways for devices, gateways, and products
The domain module now provides the core domain logic for the IoT subsystem, implementing a Clean Architecture/DDD structure. It introduces domain services (e.g., DeviceDomainService, GatewayDomainService, ProductDomainService) that enforce business rules and validation before delegating to gateway interfaces (e.g., DeviceGateway, GatewayGateway, ProductGateway). This change adds the ability to manage devices, gateways, and products through a structured domain layer, including specific capabilities like gateway command dispatching (reboot, read/write properties) and session state management.
laokou-service/laokou-iot/laokou-iot-domain · high confidence
Logstash trace logs can now be stored in Loki in addition to Elasticsearch
The infrastructure layer now supports a pluggable storage backend for trace logs. By setting the configuration property \storage.type\ to \loki\, the system switches from the default Elasticsearch storage to Loki, pushing trace data via REST. The configuration is managed through \StorageProperties\ and \LokiProperties\, and the \StorageConfig\ bean wiring selects the appropriate implementation (\TraceLogElasticsearchStorage\ or \TraceLogLokiStorage\) based on this property.
laokou-service/laokou-logstash/laokou-logstash-infrastructure · high confidence
MCP client authorization configuration added
A new Spring configuration class (McpConfig) has been introduced in the laokou-common-mcp module to handle authentication for Model Context Protocol (MCP) clients. It registers a customizer that automatically attaches the current user's OAuth2 access token to outgoing HTTP requests, ensuring secure communication with MCP servers.
laokou-common/laokou-common-mcp · high confidence
MyBatis-Plus auto-configuration registration
The module now registers its auto-configuration classes via Spring Boot's standard mechanism. Specifically, the new file META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports declares MybatisPlusAutoConfig and DataObjectHandler, enabling automatic setup of MyBatis-Plus and data object handling without manual configuration.
laokou-common/laokou-common-elasticsearch/src/main/resources, laokou-common/laokou-common-mybatis-plus/src/main/resources, laokou-common/laokou-common-openapi-doc/src/main/resources · high confidence
New @DataCache annotation for distributed caching
A new @DataCache annotation has been introduced in the data-cache module, allowing developers to declaratively apply distributed caching to methods. The annotation requires a cache name and key, and supports an optional operateType (defaulting to GET) to define the caching behavior, serving as the entry point for the platform's distributed cache implementation.
laokou-common/laokou-common-data-cache/src/main/java/org/laokou/common/data/cache/annotation · high confidence
New @EnablePrintRouter annotation for Nacos router integration
A new @EnablePrintRouter annotation has been added to the Nacos common module. When applied to a configuration class, it automatically imports the RouterHandler, enabling the application to utilize the print router functionality provided by the Nacos integration layer.
laokou-common/laokou-common-nacos/src/main/java/org/laokou/common/nacos/annotation · high confidence
New @Entity annotation for prototype-scoped beans
A new @Entity annotation has been added to the i18n module. It is a meta-annotation combining @Component and @Scope(ConfigurableBeanFactory.SCOPE\_PROTOTYPE), allowing developers to mark classes as Spring-managed prototype beans that are not thread-safe and instantiated per use.
laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/annotation · high confidence
New API contracts and data models for authentication operations
The \laokou-auth-client\ module now exposes new service interfaces and DTOs to support captcha management, login logging, and token removal. Specifically, \CaptchasServiceI\ defines operations to retrieve and send verification codes, \LoginLogServiceI\ and \NoticeLogServiceI\ provide commands to persist login and notification logs, and \TokensServiceI\ allows for token removal (logout). These interfaces are backed by new Data Transfer Objects (DTOs) and Client Objects (COs) for captchas, login logs, notice logs, secrets, and tokens, as well as domain events for login and captcha sending, enabling external consumers to interact with these specific authentication features.
laokou-service/laokou-auth/laokou-auth-client · high confidence
New Algorithm interface for load balancing selection
A new \Algorithm\ interface has been added to the \org.laokou.common.algorithm.template\ package, defining a generic \select\ method that takes a list and an argument to return an instance. This interface serves as the base contract for implementing load balancing algorithms within the platform.
laokou-common/laokou-common-algorithm/src/main/java/org/laokou/common/algorithm/template · high confidence
New AspectJ-based rate limiting with multi-key resolution
The rate limiter now uses an AspectJ interceptor (RateLimiterAspectj) to enforce limits via the @RateLimiter annotation, resolving the limiting key based on IP address, path, user, or tenant through the new Type enum. This allows developers to apply rate limiting declaratively to methods, with Redis-backed token bucket logic handling the enforcement.
laokou-common/laokou-common-rate-limiter/src/main/java/org/laokou/common/ratelimiter/aspectj · high confidence
New Elasticsearch 9 document, index, and search templates
The \laokou-common-elasticsearch\ module now includes new template classes (\ElasticsearchDocumentTemplate\, \ElasticsearchIndexTemplate\, \ElasticsearchSearchTemplate\) and a \Search\ model to manage Elasticsearch 9 operations. These templates provide synchronous and asynchronous APIs for creating, deleting, and querying documents, as well as creating, deleting, and checking the existence of indices. The index template supports automatic schema generation from \@Index\ annotations, including mappings, settings (shards, replicas, refresh interval), and custom analysis configurations (analyzers and filters). The search template supports pagination, highlighting, and query execution.
laokou-common/laokou-common-elasticsearch/src/main/java/org/laokou/common/elasticsearch/template · high confidence
New ExcelUtils utility for high-performance Excel import and export
A new ExcelUtils class has been added to the laokou-common-excel module, providing static methods for importing and exporting Excel files. The export functionality supports large datasets by partitioning data and writing it in parallel using a provided virtual thread ExecutorService, while the import functionality utilizes a listener-based approach to read data into database entities via MyBatis mappers.
laokou-common/laokou-common-excel/src/main/java/org/laokou/common/excel/util · high confidence
New IoT adapter endpoints for device, gateway, session, and product management
The laokou-iot-adapter module now exposes REST APIs for managing IoT entities, including devices, gateways, product categories, products, thing models, data sources, and sessions. These controllers handle CRUD operations, import/export, and pagination, with specific session endpoints allowing users to open and close connections. Additionally, a new Gateway Command controller enables remote operations such as rebooting gateways and reading or writing device properties. Under the hood, the adapter introduces message handlers that listen to Pulsar topics to process device telemetry and manage session lifecycle events (open/close) by deploying or undeploying Vert.x MQTT client services.
laokou-service/laokou-iot/laokou-iot-adapter · high confidence
New IoT client API contracts for devices, gateways, and products
The \laokou-iot-client\ module now exposes the core service interfaces and data transfer objects for managing IoT assets. This includes the \DevicesServiceI\ interface for device CRUD and import/export, the \GatewaysServiceI\ interface for gateway management and command execution (reboot, read/write properties), and the \ProductsServiceI\ interface for product management. Additionally, the \ProductCategorysServiceI\ interface is added to support hierarchical product categorization with tree-list queries. These interfaces define the client-side contracts for the IoT domain, utilizing specific DTOs and ClientObjects for commands, queries, and responses.
laokou-service/laokou-iot/laokou-iot-client · high confidence
New MyBatis-Plus utility classes for dynamic table names, batch processing, SQL formatting, and transactions
Added four new utility classes to the MyBatis-Plus common module: DynamicTableNameUtils provides a ScopedValue-based context for dynamic table name resolution; MybatisUtils introduces a virtual-thread-aware batch insertion mechanism with partitioning, configurable batch sizes, timeout handling, and automatic rollback on failure; SqlUtils enables full SQL reconstruction with parameter substitution and formatting using JSqlParser; and TransactionalUtils offers programmatic transaction management with configurable propagation and isolation levels. These utilities enhance database operation capabilities within the MyBatis-Plus integration layer.
laokou-common/laokou-common-mybatis-plus/src/main/java/org/laokou/common/mybatisplus/util · high confidence
New OAuth2 authentication context and user details utilities
The context module now provides a dedicated set of classes to handle OAuth2 authentication state and user information. It introduces OAuth2AuthenticatedExtPrincipal to represent the authenticated user with extended attributes (such as tenant ID, department ID, permissions, and scopes) and OAuth2Authentication as a record-based authentication object. UserConvertor facilitates mapping between authentication objects and the principal, while UserUtils offers static helpers to retrieve the current user's ID, username, tenant, and department details from the security context. Additionally, UserExtDetails is added as a serializable record for user data, and DomainFactory provides a factory method to obtain the principal instance.
laokou-common/laokou-common-context/src/main/java · high confidence
New OpenAPI documentation auto-configuration with Bearer JWT security
The laokou-common-openapi-doc module now includes an auto-configuration class (OpenApiDocAutoConfig) that initializes the OpenAPI specification. This configuration sets the API document title and version (4.0.4-SNAPSHOT), adds external documentation links, and defines a global security requirement using Bearer token authentication (JWT) via the Authorization header. The feature is enabled by default but can be toggled off via the springdoc.api-docs.enabled property.
laokou-common/laokou-common-openapi-doc/src/main/java · high confidence
New RateLimiter annotation for token-bucket rate limiting
A new @RateLimiter annotation has been added to the rate-limiter module, enabling developers to apply token-bucket rate limiting to specific methods. The annotation allows configuration of the rate key, token rate, interval, TTL, and rate limiting mode (OVERALL or PER\_CLIENT) via Redisson's RateType, providing a declarative way to control request throughput.
laokou-common/laokou-common-rate-limiter/src/main/java/org/laokou/common/ratelimiter/annotation · high confidence
New Redis utility classes for synchronous and reactive access
Added \RedisUtils\ and \ReactiveRedisUtils\ in the \laokou-common-redis\ module to provide simplified, high-level wrappers around Redisson and Spring Data Redis. \RedisUtils\ exposes synchronous operations for common data structures (strings, lists, maps) and distributed locking primitives, while \ReactiveRedisUtils\ offers equivalent non-blocking, reactive methods for keys, buckets, and maps, enabling developers to interact with Redis without managing the underlying template or client instances directly.
laokou-common/laokou-common-redis/src/main/java/org/laokou/common/redis/util · high confidence
New SensitiveUtils for data masking
Added SensitiveUtils in the laokou-common-sensitive module, providing static methods to mask sensitive information such as email addresses and mobile phone numbers, allowing users to format personal data for display while preserving privacy.
laokou-common/laokou-common-sensitive/src/main/java/org/laokou/common/sensitive/util · high confidence
New Vert.x-based MQTT client and Pulsar topic provisioning infrastructure
The IoT infrastructure module now includes a new Vert.x-based MQTT client implementation that supports multiple message handlers for gateway and device events, along with automatic Pulsar topic creation for tenant namespaces. This change introduces a new configuration class (IotConfig) that wires the DeviceMcpMapper with Spring AI tool callbacks, and adds a suite of MQTT message handlers (e.g., for alarms, heartbeats, OTA updates) that route incoming MQTT messages to Pulsar topics. The system now manages MQTT client lifecycle via a service manager and deploys multiple client instances using virtual threads.
laokou-service/laokou-iot/laokou-iot-infrastructure · high confidence
New XSS and SQL injection sanitization utility
Added XssUtils to provide client-side input sanitization for web applications. The utility includes clearHtml to strip dangerous script tags and attributes using Jsoup with a relaxed safelist, and clearSql to detect and reject SQL injection attempts via JSQLParser before they reach the database layer.
laokou-common/laokou-common-xss/src/main/java/org/laokou/common/xss/util · high confidence
New XSS protection filter for annotated endpoints
The XSS module now includes an \XssRequestFilter\ that intercepts requests to controller methods annotated with \@Xss\. When such an endpoint is hit, the filter wraps the request in an \XssRequestWrapper\ that sanitizes input parameters, headers, and JSON request bodies by stripping HTML tags via \XssUtils.clearHtml\ before the request reaches the application logic.
laokou-common/laokou-common-xss/src/main/java/org/laokou/common/xss/filter · high confidence
New admin web controllers for cluster, department, dictionary, menu, and log management
The admin adapter now exposes a comprehensive set of new REST endpoints for managing system resources, including clusters, departments, dictionaries (types and items), menus (standard and internationalized), and various logs (login, notice, operate, and OSS). These controllers implement full CRUD operations, bulk import/export capabilities, and pagination, all secured with specific role-based permissions (e.g., \sys:menu:save\) and enhanced with idempotency, data filtering, and distributed caching where applicable.
laokou-service/laokou-admin/laokou-admin-adapter · high confidence
New annotation-based Elasticsearch mapping configuration
The \laokou-common-elasticsearch\ module now includes a new set of Java annotations (\@Index\, \@Document\, \@Field\, \@Analysis\, \@Analyzer\, \@Setting\, etc.) that allow developers to define Elasticsearch index mappings and settings directly in code. These annotations provide a declarative way to specify field types (e.g., \TEXT\, \KEYWORD\, \DATE\), analyzers, filters, and index settings like shards and replicas, which are then used to generate the corresponding Elasticsearch mapping structures.
laokou-common/laokou-common-elasticsearch/src/main/java/org/laokou/common/elasticsearch/annotation · high confidence
New annotation-based configuration for warm-up and serialization
This change introduces two new components to the core annotation package: the @EnableWarmUp annotation, which allows users to enable warm-up configuration via Spring's @Import mechanism, and the AbstractContextualSerializer class, which extends Jackson's ValueSerializer to support contextual serialization. These additions provide developers with new tools to manage application startup behavior and customize JSON serialization logic within the common core library.
laokou-common/laokou-common-core/src/main/java/org/laokou/common/core/annotation · high confidence
New annotation-driven field encryption for JSON serialization
The crypto module now provides a \@Cipher\ annotation that allows developers to automatically encrypt or decrypt specific fields during JSON serialization. By applying \@Cipher\ to a field, the system uses a \CryptoSerializer\ to transform the value based on the selected \CipherType\ (AES or RSA) and the \isEncrypt\ flag, removing the need for manual encryption logic in service layers.
laokou-common/laokou-common-crypto/src/main/java/org/laokou/common/crypto/annotation · high confidence
New base entity and CRUD mapper interfaces for MyBatis-Plus
The MyBatis-Plus common module introduces a new abstract base entity, BaseDO, and a generic CRUD mapper interface, CrudMapper. BaseDO provides standard audit fields (creator, editor, createTime, updateTime) using java.time.Instant for higher precision, along with soft-delete (delFlag), optimistic locking (version), tenant, and department identifiers, with automatic field filling configured via MyBatis-Plus annotations. CrudMapper extends MyBatis-Plus BaseMapper and adds generic methods for version retrieval and paginated/list queries using PageQuery, establishing a consistent foundation for data access across the application.
laokou-common/laokou-common-mybatis-plus/src/main/java/org/laokou/common/mybatisplus/mapper · high confidence
New cluster management command executors with transactional support
The admin application now includes command executors for cluster operations (save, modify, remove, import, export). These executors handle parameter validation and delegate to the domain service, with save, modify, and remove operations wrapped in application-layer transactions via TransactionalUtils. All executors are annotated with @CommandLog to enable execution tracking.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/cluster/command · high confidence
New command and query executors for dict items and logs
The application now includes command and query executors for managing dictionary items and various logs (login, notice). These executors handle operations such as saving, modifying, removing, importing, exporting, and querying (get, list, page) for these entities. The implementation uses domain services and mappers to interact with the database, and includes parameter validation for dictionary items. Login and notice log executors also handle data source context switching for export and page queries.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dict/item, laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/log, laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/menu/i18n · high confidence
New core configuration infrastructure for async execution, HTTP clients, and serialization
The core module now introduces a comprehensive set of configuration classes that establish the application's foundational behavior. Asynchronous operations are managed via a new AsyncConfig that delegates to a virtual thread executor, supported by a dedicated SpringTaskExecutorConfig defining bootstrap thread pools. HTTP communication is standardized through RestClientConfig, which configures the Spring RestClient to use Apache HttpClient. Serialization is handled by HttpMessageConverterConfig, which registers a custom JsonMapper with specific handling for Long-to-String conversion and Java 8 time types (Instant, LocalDateTime). Additionally, the system includes a WarmUpConfig to pre-load browser capability data at startup, a SystemSettingsProperties class to externalize operational modes and expiration settings, and an OAuth2AuthorizedToken interface to support authentication flows.
laokou-common/laokou-common-core/src/main/java/org/laokou/common/core/config · high confidence
New core utility classes added
A comprehensive set of new utility classes has been added to the core module to support common development tasks. These include AddressUtils for IP geolocation, ArrayUtils and CollectionExtUtils for collection operations, Base64Utils and DigestUtils for encoding and hashing, BigDecimalUtils for precise arithmetic, ClassExtUtils and ReflectionExtUtils for classpath scanning and reflection, CmdUtils for executing system commands, ConvertUtils for object mapping, FileUtils for file I/O and chunked writing, HttpUtils and OkHttpUtils for HTTP client operations, IpUtils for IP address validation and extraction, MapUtils for map manipulation, PropertyUtils for binding YAML properties, and RandomIdGenerator and RandomStringUtils for generating random identifiers. RegexUtils provides validation patterns for emails, mobile numbers, and IP addresses.
laokou-common/laokou-common-core/src/main/java/org/laokou/common/core/util · high confidence
New distributed lock abstraction with Redisson support
The lock component now provides a structured distributed locking API built on Redisson. It introduces a Lock interface and an AbstractLock base class that define tryLock and unlock operations accepting a lock Type and key. The Type enum exposes five lock strategies—normal, fair, read, write, and fenced (strong consistency)—each mapping to the corresponding Redisson lock type via RedisUtils. The RedissonLock implementation handles the actual acquisition and release, including safety checks to ensure only the current thread releases a held lock, and adds clear logging for lock success, failure, and release events to aid troubleshooting in clustered environments.
laokou-common/laokou-common-lock/src/main/java/org/laokou/common/lock · high confidence
New distributed lock annotation with expression support
The \Lock4j\ annotation is introduced in the lock module, allowing developers to apply distributed locking to methods. It supports configurable lock keys via SpEL expressions, custom timeouts, retry counts, and lock types, enabling more flexible and robust concurrency control in distributed environments.
laokou-common/laokou-common-lock/src/main/java/org/laokou/common/lock/annotation · high confidence
New extensible Excel validation interface and abstract base class
The Excel module now provides a new \ExcelValidator\ interface and an \AbstractExcelValidator\ base class in the validator package, allowing users to easily define and extend custom validation rules for Excel data imports. The abstract class handles the validation logic by delegating to a protected \validates\ method, which subclasses implement to return specific validation constraints, streamlining the integration of custom business rules into the Excel processing workflow.
laokou-common/laokou-common-excel/src/main/java/org/laokou/common/excel/validator · high confidence
New gRPC client exception handling for service not found and authentication errors
The gRPC client now includes specific exception handling capabilities. A new ServiceNotFoundException class has been added to represent cases where a service cannot be located. Additionally, a StatusExceptionHandler has been introduced to intercept gRPC StatusExceptions, specifically mapping UNAUTHENTICATED errors to a FORBIDDEN BizException with the relevant service ID, while passing through other exceptions.
laokou-common/laokou-common-grpc-client/src/main/java/org/laokou/common/grpc/client/exception · high confidence
New gateway filters for authentication and Scalar API documentation proxying
The gateway now includes an AuthFilter that enforces token-based authentication on incoming requests, checking for an Authorization header and returning a 401 Unauthorized response if missing, while allowing requests matching configured ignore patterns to pass through. Additionally, a ScalarGatewayFilterFactory has been added to handle requests targeting Scalar API documentation endpoints, allowing them to be proxied to a configurable external URL specified via the scalar\_url parameter.
laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/filter · high confidence
New global exception handler for the gateway
A new global exception handler (ExceptionHandler) has been added to the gateway to standardize error responses. It implements Spring's ErrorWebExceptionHandler to catch and translate exceptions like NotFoundException, ResponseStatusException, and Sentinel BlockException into structured JSON responses with appropriate HTTP status codes and internationalized error messages, ensuring consistent error handling across the gateway.
laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/exception · high confidence
New i18n utility classes for internationalization and common operations
The \laokou-common-i18n\ module now includes a comprehensive set of utility classes in the \util\ package to support internationalization and general application tasks. \I18nUtils\ and \LocaleUtils\ handle locale resolution from HTTP headers and string parsing, while \MessageUtils\ and \ValidatorUtils\ provide access to i18n resource bundles for application messages and validation errors. Additional utilities include \EnumParser\ for enum conversion, \JacksonUtils\ and \YamlUtils\ for data serialization, \InstantUtils\, \LocalDateTimeUtils\, and \LocalDateUtils\ for time handling, and helper classes for Spring context access (\SpringContextUtils\, \SpringEventBus\), SSL configuration (\SslUtils\), and system information (\SystemUtils\).
laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/util · high confidence
New internal tooling and code-quality configurations in laokou-tool
This change introduces several new internal utilities and configuration files within the laokou-tool module. It adds Checkstyle configuration files (checkstyle.xml, checkstyle-header.txt, checkstyle-suppressions.xml) to enforce coding standards, including prohibiting wildcard and static imports, banning System.out.println, and restricting specific Lombok and Spring annotations. It also adds a SpotBugs exclusion file (spotbugs-exclude.xml) to filter out known false-positive bug patterns. Additionally, new Java classes are added: ErrorInfoPrinter, which processes JSON log files to extract and write stack traces to a text file; ModifyProjectBoot, a utility to batch-rename modules, group IDs, package names, and project titles across the project structure; and TraceLog, a data model for parsing trace log entries.
laokou-tool · high confidence
New menu query execution handlers for single, paginated, and tree-based retrieval
The admin application now includes dedicated command/query executors for menu data access: MenuGetQryExe retrieves a single menu item by ID, MenuPageQryExe supports paginated menu listing, and MenuTreeListQryExe builds hierarchical menu trees for both user and system contexts. These handlers delegate to the existing MenuMapper for database access and use MenuConvertor to map data objects to client objects, with the tree executor leveraging injected MenuTree builders (userMenuTreeBuilder and systemMenuTreeBuilder) and registering MenuTreeCO for serialization via Fory.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/menu/command/query · high confidence
New operation log model and enums introduced
The operation logging subsystem now includes a new aggregate model class, OperateLogA, which handles the creation, status tracking, and data population of operation logs, including filtering sensitive request parameters (like HttpServletRequest and MultipartFile) and capturing error stack traces. Additionally, two new enums, Status (defining OK/FAIL states) and Mq (defining the 'operate-log' topic and consumer group for message queue integration), have been added to support the logging infrastructure.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/model · high confidence
New reactive request and response utility classes
Added ReactiveRequestUtils and ReactiveResponseUtils to the reactor common module. ReactiveRequestUtils provides helper methods for extracting headers, query parameters, URL, host, content type, and HTTP method from reactive ServerHttpRequest objects, along with Ant-style path matching. ReactiveResponseUtils simplifies sending JSON responses by writing data directly to the reactive ServerWebExchange with appropriate status codes and content types.
laokou-common/laokou-common-reactor/src/main · high confidence
New structured exception hierarchy with internationalized error codes
The \laokou-common-i18n\ module now provides a dedicated exception framework to standardize error handling. A new \GlobalException\ base class automatically resolves error messages using \MessageUtils\ for internationalization, while specific subclasses (\ParamException\, \BizException\, \SystemException\) allow developers to distinguish between parameter validation, business logic, and system-level failures. A \StatusCode\ class is also introduced to define standard HTTP-like error codes (e.g., \Bad\_Request\, \Unauthorized\), enabling consistent, code-based error reporting across the platform.
laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/common/exception · high confidence
New tenant data model and mapper infrastructure
The tenant module now includes a dedicated auto-configuration class that registers the tenant mapper package, along with a new TenantDO entity and TenantMapper interface. The entity maps to the tenant table and includes fields for tenant name, code, source ID, and package ID, providing the foundational data structure for tenant management operations.
laokou-common/laokou-common-tenant/src/main/java/org/laokou/common/tenant/mapper · high confidence
New testcontainer wrappers for MinIO, Nacos, OAuth2, and SFTP
The testcontainers module now includes dedicated container wrappers for MinIO, Nacos, OAuth2, and SFTP services. MinIOContainer exposes ports 9000 and 9001 with configurable root credentials. NacosContainer runs in standalone mode, exposing admin (8848), HTTP (8080), and gRPC (9848) ports, and includes pre-configured authentication tokens and a wait strategy for the login page. OAuth2Container exposes port 9088. SFtpContainer exposes port 22 and supports configuring SFTP users via environment variables. These classes provide a standardized way to spin up these services for testing.
laokou-common/laokou-common-testcontainers/src/main/java/org/laokou/common/testcontainers/container · high confidence
New user management command executors for CRUD and password reset
The application layer now includes dedicated command executors for user management operations: saving, modifying, removing, and resetting passwords, as well as modifying user authority. These executors (UserSaveCmdExe, UserModifyCmdExe, UserRemoveCmdExe, UserResetPwdCmdExe, UserModifyAuthorityCmdExe) enforce parameter validation and wrap all database updates in transactions using TransactionalUtils. Additionally, placeholder executors for user import and export have been added, and a user avatar upload executor has been introduced with a stubbed implementation.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/user/command · high confidence
New user management service implementation with avatar upload support
The UsersServiceImpl class has been added to handle user management operations, including saving, modifying, removing, importing, exporting, and resetting passwords for users. It also supports querying user profiles and pages, and notably introduces the ability to upload user avatars via the new uploadUserAvatar method. The service integrates with the Fory serialization framework by registering specific classes in a static block.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/user/service · high confidence
New user query execution handlers for admin user management
Added three new command/query executors in the admin application layer to support user data retrieval: UserGetQryExe handles fetching a single user by ID (including their roles and avatar URL from OSS logs), UserPageQryExe supports paginated listing of users, and UserProfileGetQryExe retrieves the current user's profile information. These components implement the specific query logic for the user management feature.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/user/command/query · high confidence
New web-layer endpoints for authentication, captchas, and token management
The auth adapter now exposes a set of new REST controllers that handle the user-facing authentication flows. CaptchasController provides endpoints to retrieve captchas for both username/password and authorization-code logins, as well as to send mobile and email verification codes (with rate limiting). TokensController adds a DELETE endpoint to remove tokens for logout. SecretsController exposes a GET endpoint to retrieve security secret information. LoginController serves the /login page. Additionally, DomainEventHandler listens to Kafka topics to asynchronously process login logs and send captcha notifications via email or SMS.
laokou-service/laokou-auth/laokou-auth-adapter · high confidence
OAuth2 authorization server configuration and authentication infrastructure
The infrastructure layer now includes the core configuration for the OAuth2 authorization server, including \OAuth2AuthorizationServerConfig\ and \OAuth2ResourceServerConfig\, along with properties mapping via \OAuth2AuthorizationServerPropertiesMapper\. This setup registers multiple authentication converters and providers for username/password, mobile, email, and test grant types, enabling the auth service to issue tokens and manage client registrations through Redis-backed repositories.
laokou-service/laokou-auth/laokou-auth-infrastructure · high confidence
OSS client API contracts for uploads and logging
The \laokou-oss-client\ module now exposes the API contracts required for file uploads and operation logging. This includes the \OssLogsServiceI\ interface for saving OSS logs, along with the necessary data transfer objects (\OssLogSaveCmd\, \OssLogCO\) and upload command (\OssUploadCmd\) and result objects (\OssUploadCO\). Additionally, the \OssUploadEvent\ domain event is defined to signal upload completion, providing consumers with file metadata such as name, MD5, URL, size, and upload time.
laokou-service/laokou-oss/laokou-oss-client · high confidence
OSS service implementation added to admin app
The admin application now includes an implementation of the OSS (Object Storage Service) interface, providing capabilities to save, modify, remove, import, and export files, as well as to query and paginate OSS records. This service delegates operations to specific command and query executors, enabling users to manage object storage assets through the admin interface.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/oss/service · high confidence
OSS service introduces file upload logging and gRPC API contract
The OSS application layer now records detailed logs for every file upload operation, persisting these records asynchronously via a new Kafka consumer and command executor to support URL refresh and audit trails. Concurrently, the service exposes its upload capability through a new gRPC interface defined in the OSS protocol buffer, replacing previous transport mechanisms.
laokou-service/laokou-oss/laokou-oss-app · high confidence
OSS upload logging and metadata persistence
The OSS infrastructure layer now records detailed logs for every file upload operation. New database entities (OssLogDO) and MyBatis mappers persist upload metadata such as file name, MD5 hash, URL, size, and content type. The OssLogGatewayImpl provides methods to create these log entries and retrieve upload info by MD5, with caching support. Additionally, the OssConfig registers a Kafka topic for OSS log events and configures Fory serialization for domain events, enabling asynchronous log processing.
laokou-service/laokou-oss/laokou-oss-infrastructure · high confidence
Project initialization with comprehensive documentation and configuration scaffolding
The repository has been initialized with the KCloud-Platform-IoT project, establishing the foundational structure for an enterprise-grade IoT cloud platform. This includes the addition of standard open-source governance files such as a Contributor License Agreement (CLA), Code of Conduct, and detailed contribution guidelines. The project documentation has been set up with comprehensive README files (in Markdown and AsciiDoc) outlining the system architecture, technology stack (Spring Boot, Spring Cloud, Nacos, etc.), and feature set. Additionally, development tooling and configuration files have been added, including .editorconfig for code style consistency, .gitignore for build artifacts, lombok.config for Lombok behavior, renovate.json for automated dependency updates, and .deepsource.toml for static code analysis targeting Java 21.
(repo-wide) · high confidence
Reactive I18n support in the gateway
The gateway now includes a new ReactiveI18nUtils utility that extracts the user's preferred language from the 'Language' or 'Accept-Language' request headers and stores it in the Reactor Context. This enables downstream reactive services to access locale information without relying on thread-local storage, supporting the gateway's shift toward a fully reactive architecture.
laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/util · high confidence
Redis module enables Spring Boot 3 auto-configuration
The Redis common module now registers its configuration classes (ReactiveRedisAutoConfig, RedisAutoConfig, and RedissonAutoConfig) via the Spring Boot 3 standard auto-configuration mechanism. This allows the Redis features to be automatically available to applications without requiring manual component scanning or explicit configuration imports.
laokou-common/laokou-common-redis/src/main/resources, laokou-common/laokou-common-tenant/src/main/resources/META-INF · high confidence
Standalone admin service bootstrapping and configuration
The standalone admin application is now bootstrapped with a dedicated entry point that initializes Spring Security with a transmittable thread-local context strategy and configures the embedded Tomcat server. Environment-specific configurations are provided for development, test, and production profiles, defining connection pools for PostgreSQL (HikariCP), Redis (Lettuce), and Kafka, alongside SMS integration settings. The service uses Flyway for database migrations, enables global log4j2 logging with JSON template layouts, and exposes Swagger documentation via SpringDoc.
laokou-service/laokou-standalone/laokou-standalone-admin/laokou-standalone-admin-start, laokou-service/laokou-standalone/laokou-standalone-auth/laokou-standalone-auth-start · high confidence
Standardized API response wrapping via ResponseBodyHandler
A new ResponseBodyHandler has been added to the core module to intercept and standardize HTTP responses. This component ensures that all controller return values are consistently wrapped in a unified Result object, automatically wrapping non-Result bodies (including nulls) into a success response, which simplifies client-side parsing and ensures a consistent API contract.
laokou-common/laokou-common-core/src/main/java/org/laokou/common/core/handler · high confidence
gRPC API for Snowflake ID generation
The Snowflake ID service now exposes a gRPC interface allowing clients to generate single or batch distributed IDs. The proto definition introduces two RPCs: \generateId\ for a single ID and \generateBatchIds\ for multiple IDs. The service implementation enforces a 'read' authority requirement for both operations, ensuring that only authorized users can request new IDs.
laokou-service/laokou-snowflake-id/laokou-snowflake-id-app · high confidence
gRPC client now supports service discovery with version-based routing and automatic auth propagation
The gRPC client configuration now resolves service targets using the 'discovery:' scheme, leveraging Spring Cloud's DiscoveryClient to find instances. It filters service instances by a specific gRPC version (defaulting to 'v1') and refreshes the instance list automatically on heartbeat events. Additionally, a global client interceptor is registered to automatically propagate the current HTTP Bearer token to gRPC calls, ensuring authenticated requests without manual header management.
laokou-common/laokou-common-grpc-client/src/main/java/org/laokou/common/grpc/client/config · high confidence
Architecture
Infrastructure layer refactored to DDD architecture for admin modules
The infrastructure module has been restructured to follow Domain-Driven Design (DDD) patterns, introducing a standardized gateway implementation layer for core administrative entities including Clusters, Departments, Dicts, DictItems, LoginLogs, and NoticeLogs. This change replaces previous persistence logic with explicit Gateway interfaces and implementations (e.g., \ClusterGatewayImpl\, \DeptGatewayImpl\) that handle data mapping via dedicated Convertors (e.g., \ClusterConvertor\, \DeptConvertor\) and MyBatis-Plus mappers. For Departments, this also introduces support for up to 9 levels of hierarchy with automatic level tracking and child-node updates, while LoginLogs now include AES encryption for username privacy and Excel export capabilities.
laokou-service/laokou-admin/laokou-admin-infrastructure · high confidence
Behavioural changes
3 commits (0 fixes) modifying laokou-common/laokou-common-core/src/main/resources
A change to existing behaviour in laokou-common/laokou-common-core/src/main/resources — 3 commits, 2 files.
laokou-common/laokou-common-core/src/main/resources · medium confidence · unverified
Added DomainFactory for lazy initialization of log model entities
A new DomainFactory class has been introduced in the log module to provide static factory methods for creating OperateLogA and OperateLogE instances. These methods use Spring's BeanProvider to retrieve beans on demand, enabling lazy initialization and reducing the overhead of creating these objects repeatedly during operation logging.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/factory · high confidence
Adds OAuth 2.0 opaque token authentication for gRPC server
The gRPC server now enforces authentication on all requests using Spring Security's OAuth 2.0 resource server support with opaque tokens. A new configuration class registers a global interceptor that validates incoming gRPC calls against an introspection endpoint, ensuring that only authenticated clients can access gRPC services.
laokou-common/laokou-common-grpc-server/src/main · high confidence
Admin service bootstrapping with security, observability, and environment-specific configurations
The admin service entry point (AdminApp) is initialized with Spring Security using a TransmittableThreadLocal strategy to ensure context propagation across threads, while Sentinel health checks are explicitly disabled to prevent startup issues. The service is configured to support multiple environments (dev, test, prod) via distinct YAML profiles that define dynamic data sources (master/domain), Redis/Lettuce connection pools, and Kafka consumers/producers using Fory serialization. Logging is standardized across environments using Log4j2 with JSON template layouts, and the production profile includes a Kafka appender for trace logs with failover capabilities. Additionally, API rate limiting rules for user, tenant, and role endpoints are defined in a Sentinel flow rule JSON file, and HTTP client environment files are provided to facilitate local testing against the admin API.
laokou-service/laokou-admin/laokou-admin-start · high confidence
Auth app layer refactored with new command/query executors and validators
The auth application layer has been restructured to support multiple authentication methods (username/password, authorization code, email, and mobile) through a new set of command and query executors. Captcha generation and sending are now handled by dedicated executors (CaptchaGetQryExe, CaptchaSendCmdExe) with async execution, while login and notice logs are saved asynchronously via LoginLogSaveCmdExe and NoticeLogSaveCmdExe. Token removal (TokenRemoveCmdExe) now explicitly evicts user menu caches and deletes associated Redis sessions. A new validator hierarchy (AuthParamValidator implementations) enforces parameter validation for each auth type, backed by a shared OAuth2ParamValidator for common checks like UUID, captcha, username, password, email, and mobile formats.
laokou-service/laokou-auth/laokou-auth-app · high confidence
Auth domain refactored to COLA architecture with multi-factor login support
The authentication domain has been restructured to follow the COLA (Clean Object-oriented and Layered Architecture) pattern, introducing a new \DomainService\ that orchestrates the authentication flow and a \DomainFactory\ for managing domain object creation. This change adds support for email and mobile phone login methods alongside the existing username/password option, utilizing specific validators for each grant type. The domain now enforces data permissions by checking user roles and department scopes during authentication, and introduces gateway interfaces (e.g., \UserGateway\, \MenuGateway\) to decouple domain logic from infrastructure. Additionally, the system now records login and notice logs via dedicated entities and gateway interfaces, supporting asynchronous logging through message queues.
laokou-service/laokou-auth/laokou-auth-domain · high confidence
Automatic Kafka topic creation and conditional ID generator wiring for operation logs
The operation log module now automatically creates the Kafka topic for operation logs upon startup, ensuring the messaging infrastructure is ready without manual intervention. Additionally, the system configures the distributed ID generator to use a remote RPC implementation (IdGeneratorMapper) only when the application is running in microservice mode, falling back to other configurations in standalone mode.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/config · high confidence
Centralized database table name constants for tenant and IoT domains
A new constant class, DSConstants, has been introduced to centralize the definitions of database table names used across the tenant and IoT modules. This change replaces hardcoded string literals with typed constants, organizing them into nested classes for IoT (e.g., session, source, thing model tables), Master (e.g., user, role, menu, OSS, tenant tables), and Domain (e.g., notice, login, operate log tables). This improves code maintainability and reduces the risk of typos in database queries by providing a single source of truth for table names.
laokou-common/laokou-common-tenant/src/main/java/org/laokou/common/tenant/constant · high confidence
Data dictionary command execution layer refactored to COLA application-layer pattern
The application layer for data dictionary management has been restructured to strictly follow COLA architecture guidelines, moving transaction management and command execution logic into dedicated command executors (DictSaveCmdExe, DictModifyCmdExe, DictRemoveCmdExe, DictImportCmdExe, DictExportCmdExe). This change centralizes transaction lifecycle management at the application layer using TransactionalUtils, ensuring that create, update, delete, import, and export operations are executed within controlled transactions. Additionally, parameter validation is now explicitly handled within these executors via domain model checks (checkDictParam), and command execution logs are automatically captured using the CommandLog annotation for better operational traceability.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dict/command · high confidence
Elasticsearch client auto-configuration upgraded to REST Client 5
The Elasticsearch configuration module has been updated to use the Apache HttpClient 5-based REST Client 5 transport layer. This change introduces a new auto-configuration setup that wires the \Rest5ClientTransport\ to provide \ElasticsearchClient\ and \ElasticsearchAsyncClient\ beans, along with high-level templates for document, index, and search operations. The configuration now supports fine-grained customization of the HTTP client via \Rest5ClientBuilderCustomizer\ beans, allowing users to adjust connection settings, timeouts, proxy routes, and SSL/TLS strategies through the \spring.data.elasticsearch\ properties.
laokou-common/laokou-common-elasticsearch/src/main/java/org/laokou/common/elasticsearch/config · high confidence
Enables automatic mail configuration via Spring Boot auto-configuration
The mail module now registers its auto-configuration class (MailAutoConfig) in the Spring Boot auto-configuration imports file. This allows the mail functionality to be automatically available to applications without requiring manual configuration or additional component scanning.
laokou-common/laokou-common-mail/src/main/resources · high confidence
Enforced uniqueness and safety rules for user management operations
The user administration module now applies strict validation rules when creating, modifying, or deleting users. Administrators can no longer delete super-administrator accounts, and the system prevents saving or updating users with duplicate usernames, email addresses, or mobile phone numbers. Additionally, when resetting a password, the system ensures the new password differs from the current one and meets length requirements.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/user/service/validator · high confidence
Enforced validation rules for department creation and modification
The department management module now applies strict parameter validation when creating or updating departments. Users must provide a valid parent ID (preventing self-referencing and enforcing a maximum hierarchy depth of 9 levels), a non-empty name, and a sort order between 1 and 99999. These checks are implemented via new validator components in the admin application layer to ensure data integrity before persistence.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dept/service/validator · high confidence
Gateway configuration restructured with environment-specific profiles, Sentinel rate limiting, and JSON logging
The gateway now uses distinct YAML profiles (dev, test, prod) to manage environment-specific settings, including separate Nacos namespaces and Redis configurations. Sentinel rate limiting is integrated via a Nacos-published JSON rule file (gateway-flow.json), applying a 100,000 QPS limit with a 500,000 burst capacity to services like laokou-auth, laokou-admin, and laokou-iot. Logging has been standardized to Log4j2 with JSON template layouts for structured output, and the production profile adds a Kafka appender for distributed trace logs. Additionally, the main application.yml defines routes for Scalar API documentation endpoints and configures the HTTP client connection pool for higher concurrency.
laokou-cloud/laokou-gateway/src/main/resources · high confidence
Introduces unified Nacos startup entry point supporting multiple deployment modes
The application now uses a new \NacosApp\ main class to bootstrap Nacos, replacing the previous entry point. This change enables flexible deployment via the \nacos.deployment.type\ property, allowing users to run the Core, Server (Web), and Console components individually or in merged configurations (MERGED, SERVER, SERVER\_WITH\_MCP, CONSOLE) within a single process, rather than relying on separate startup scripts or modules.
laokou-cloud/laokou-nacos/src/main/java · high confidence
IoT service bootstrapping and configuration overhaul
The IoT service now initializes via a new \IotApp\ entry point that enables Pulsar, WebSocket, and security features, while enforcing virtual thread support and configuring a transmittable security context for sub-threads. Configuration is centralized in YAML files (\application.yml\, \application-dev.yml\, etc.) that define dynamic data sources (PostgreSQL), Redis/Lettuce, Kafka, and Nacos integration. Logging is standardized across environments using Log4j2 with JSON template layouts, and the production profile specifically adds a Kafka appender for trace logs with failover capabilities.
laokou-service/laokou-iot/laokou-iot-start · high confidence
Log4j2 migration with async logging and JSON output
The logging infrastructure has been migrated from Logback to Log4j2. This change introduces asynchronous logging via the AsyncLoggerContextSelector and a custom TTL-based ThreadContextMap to support MDC fields like traceId and spanId. Additionally, log output is now formatted as structured JSON using a custom layout definition, replacing the previous string-based format to improve machine readability and performance.
laokou-common/laokou-common-log4j2/src/main/resources · high confidence
Logstash service bootstrapped with virtual threads, JSON logging, and reactive Kafka
The logstash-start module now initializes the application using Spring Boot with virtual threads enabled via the reactor scheduler property, replacing previous thread management. Logging is globally switched to Log4j2 with a custom JSON template layout for both console and file outputs, including trace and span IDs for distributed tracing. The service connects to Kafka using Fory serialization and is configured to auto-create topics. Additionally, the application supports configuration via Nacos, uses Jasypt for encrypted properties, and sets up connections to Elasticsearch and Loki for log storage.
laokou-service/laokou-logstash/laokou-logstash-start · high confidence
Menu management command handlers now enforce transactional execution
The menu administration module has been updated with new command execution handlers (MenuSaveCmdExe, MenuModifyCmdExe, MenuRemoveCmdExe, MenuImportCmdExe, and MenuExportCmdExe). These handlers implement the COLA architecture pattern, where save, modify, and remove operations are wrapped in explicit transactions via TransactionalUtils to ensure data consistency. Additionally, the save handler registers specific DTOs with the Fory serialization framework, and all handlers are annotated with @CommandLog to track execution details.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/menu/command · high confidence
Menu management now enforces strict parameter validation
The menu management feature now includes dedicated validation logic for creating and modifying menus. New validator components ensure that required fields such as parent ID, type, name, path, permission identifier, status, and sort order are present and valid. Additionally, the system checks for duplicate names, paths, and permission identifiers to prevent data conflicts during save and update operations.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/menu/service/validator · high confidence
Monitor service adopts Nacos configuration and Log4j2 JSON logging
The laokou-monitor service now registers with and retrieves its configuration from Nacos (using the IOT\_GROUP) instead of relying on local static files, with environment-specific profiles (dev, test, prod) pointing to the central config server. Additionally, the logging implementation has shifted to Log4j2, outputting file logs in JSON format via JsonTemplateLayout to improve parsing and readability, while console logs retain a structured pattern including trace and span IDs.
laokou-cloud/laokou-monitor/src/main/resources · high confidence
MyBatis-Plus configuration and interceptors overhaul
The MyBatis-Plus configuration module has been completely rewritten to introduce a new set of interceptors and handlers. This includes a DataFilterInterceptor for applying custom SQL filters, a GlobalTenantLineHandler for multi-tenancy support, and a DynamicTableNameHandler for dynamic table routing. The system now features a SqlMonitorInterceptor to log slow SQL queries, a DataObjectHandler for automatic field population (using Instant for timestamps), and a ForySerialCaffeineJsqlParseCache to optimize SQL parsing performance. These changes are managed via the new MybatisPlusAutoConfig and MybatisPlusExtProperties classes.
laokou-common/laokou-common-mybatis-plus/src/main/java/org/laokou/common/mybatisplus/config · high confidence
Nacos configuration and logging infrastructure added
The Nacos service now includes explicit configuration files for development, production, and test environments, defaulting to a PostgreSQL database with a connection pool size of 20 and encrypted credentials. The main application properties enable Nacos authentication, disable Istio MCP, set the deployment type to 'merged', and configure the Tomcat connector with up to 10,000 connections. Logging is standardized via new Logback configurations that route Nacos logs to separate rolling files (debug, error) and the console, and a custom banner displays version 4.0.0 and service details on startup.
laokou-cloud/laokou-nacos/src/main/resources · high confidence
New Docker Compose environment configurations for 4.0.0 deployment
This change introduces a new set of environment variable files (admin, auth, gateway, iot, logstash, monitor, nacos, sentinel, snail-job) for the Docker Compose deployment path, aligning with the 4.0.0 release. These configurations define JVM options (including ZGC and memory settings), service ports, and connection details for Nacos, Sentinel, and Snail Job. Notably, the Nacos configuration now uses PostgreSQL as the data store and includes a specific secret key, while Sentinel is configured with its own authentication credentials and version tag.
doc/deploy/docker-compose/env · high confidence
OAuth2 security module refactored to use Redis for authorization storage and Caffeine for token introspection caching
The security module has been restructured to store OAuth2 authorization data (tokens, client registrations, and user consents) in Redis instead of a relational database, utilizing new \RedisOAuth2AuthorizationService\, \RedisRegisteredClientRepository\, and \RedisOAuth2AuthorizationConsentService\ implementations. To improve performance and reduce database load during resource server validation, the \OAuth2OpaqueTokenIntrospector\ now employs a Caffeine-based local cache for principal data. Additionally, the module introduces an \@EnableSecurity\ annotation to simplify configuration imports and switches to Jackson 3 for Redis serialization.
laokou-common/laokou-common-security/src/main · high confidence
OSS service launch configuration and logging infrastructure
The OSS service start module now includes the main application entry point (OssApp) and environment-specific configuration files. The application bootstraps as a Servlet-based Spring Boot service, enabling virtual threads, distributed caching, and Jasypt encryption. It configures connection pools for PostgreSQL, Redis (Lettuce), and Kafka, and sets up log4j2 logging with JSON template layouts. The production profile adds a Kafka appender for trace logs with failover support, while dev/test profiles use local file logging. An integration test verifies the OSS upload functionality.
laokou-service/laokou-oss/laokou-oss-start · high confidence
Redis serialization and configuration overhaul
The Redis module now uses Jackson (via JsonJackson3Codec) for object serialization instead of the previous Fury/Fory serializer, with a new CodecType enum to manage codec selection. A custom Sha512DigestStringRedisSerializer is introduced for key serialization, and auto-configuration classes (RedisAutoConfig, ReactiveRedisAutoConfig, RedissonAutoConfig) wire these serializers into RedisTemplate, ReactiveRedisTemplate, and Redisson clients. Configuration is centralized in SpringRedissonProperties, supporting single, cluster, and sentinel node types with load balancer options, while the reactive and servlet-specific templates are registered as beans.
laokou-common/laokou-common-redis/src/main/java/org/laokou/common/redis/config · high confidence
Role management parameter validation logic moved to domain layer
The parameter validation logic for role management (including saving and modifying roles) has been refactored from the service layer into the domain layer. This change introduces dedicated validator components (SaveRoleParamValidator, ModifyRoleParamValidator, ModifyRoleAuthorityParamValidator) that delegate to a central RoleParamValidator class, ensuring that checks for role ID, name uniqueness, sort order, data scope, menu IDs, and department IDs are now enforced at the domain level rather than within service implementations.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/role/service/validator · high confidence
SMS module auto-configuration and metadata registration
The SMS module now registers its auto-configuration class (SmsAutoConfig) via Spring Boot 2.7+ conventions, enabling automatic setup without manual scanning. Additionally, configuration metadata for the 'sms.type' property is provided, allowing IDEs and tools to offer better support for SMS-related configuration options.
laokou-common/laokou-common-sms/src/main/resources · high confidence
Snowflake ID generation now delegates to a gRPC service
The local ID generation logic has been replaced with a remote call to the 'laokou-snowflake-id' gRPC service. The new IdGeneratorMapper implementation uses a blocking gRPC stub to fetch single or batch IDs, ensuring that ID generation relies on the centralized Snowflake service rather than local computation.
laokou-common/laokou-common-log/src/main/java/org/laokou/common/log/rpc · high confidence
Spring Boot auto-configuration for Sentinel integration
The module now registers its auto-configuration class (SentinelAutoConfig) via the Spring Boot 2.7+ / 3.x standard mechanism (META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports). This allows the Sentinel configuration to be automatically applied when the module is on the classpath, removing the need for manual component scanning or explicit configuration imports by users.
laokou-common/laokou-common-sentinel/src/main/resources/META-INF · high confidence
Standardized code quality checks across common modules
The laokou-common modules now include standardized Checkstyle and SpotBugs configuration files. This ensures consistent code style enforcement (e.g., prohibiting unused imports, static imports, and System.out.println) and automated static analysis for potential bugs during the build process.
laokou-common · high confidence
Validation rules added for data dictionary entries
The system now enforces strict validation when creating or modifying data dictionaries. Dictionary codes must follow a specific format (lowercase letters and underscores, starting and ending with a letter, no consecutive underscores), and both the code and name are required. Additionally, the system checks for duplicate code and name combinations to prevent conflicts, and ensures the status field is provided.
laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/dict/service/validator · high confidence
Test coverage
Added integration and unit tests for the gRPC client module; Added integration tests for MyBatis-Plus utilities; Added integration tests for Nacos route definition repository; Added integration tests for Redisson lock operations; Added integration tests for idempotent aspect with Redis; Added integration tests for the Excel component; Added integration tests for the gRPC server with OAuth2 security; Added test configuration and schema for the Excel component; Added test coverage for Redis configuration and utility classes; Added test resources for MyBatis-Plus integration testing; Added tests for OAuth2 security repositories; Added tests for load balancing algorithms; Added unit and integration tests for WebSocket server components; Added unit and integration tests for security configuration entities and converters; Added unit tests for CSV utility functions; Added unit tests for Elasticsearch auto-configuration and API templates; Added unit tests for ForyFactory serialization; Added unit tests for I18nFilter; Added unit tests for Nacos configuration and naming utilities; Added unit tests for OAuth2 security configuration components; Added unit tests for OAuth2ExceptionHandler; Added unit tests for SecretUtils and ApiSecretParamValidator; Added unit tests for SensitiveUtils; Added unit tests for TtlThreadContextMap; Added unit tests for UserUtils; Added unit tests for XSS and SQL injection filtering; Added unit tests for core utility classes; Added unit tests for crypto utilities and Jasypt encryption; Added unit tests for i18n common utilities; Added unit tests for reactive request and response utilities.
Dependencies
Routine dependency updates across 144 manifests
This release updates dependencies across 144 manifests, including upgrades to Spring Boot, Spring Cloud, AWS SDK for S3, Elasticsearch, Flyway, and various other libraries. These changes primarily address bug fixes and security patches, ensuring the platform remains stable and secure.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 38 → 38 (-0.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 78 → 80 (+2.6)
- Architecture 99 → 90 (-9.2)
- Maturity 69 → 74 (+4.5)
- Readiness 29 → 23 (-6.2)
- Security 30 → 42 (+12.1)
- Domain Modelling 84 → 88 (+3.4)
- Event-Driven 100 → 100 (+0.0)
- Accessibility 33 → 34 (+1.7)
Resolved (172)
- Boundary-crossing change coupling: GatewayApp.java ↔ AsyncConfig.java (laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/GatewayApp.java)
- Change coupling: DeptDrawer.tsx ↔ MenuDrawer.tsx (ui/src/pages/Sys/Permission/DeptDrawer.tsx)
- Change coupling: DeptDrawer.tsx ↔ UserDrawer.tsx (ui/src/pages/Sys/Permission/DeptDrawer.tsx)
- Change coupling: ElasticsearchIndexTemplate.java ↔ ElasticsearchSearchTemplate.java (laokou-common/laokou-common-elasticsearch/src/main/java/org/laokou/common/elasticsearch/template/ElasticsearchIndexTemplate.java)
- Change coupling: MenuDrawer.tsx ↔ UserDrawer.tsx (ui/src/pages/Sys/Permission/MenuDrawer.tsx)
- Change coupling: StoragePolicy.java ↔ StorageTemplate.java (laokou-common/laokou-common-oss/src/main/java/org/laokou/common/oss/model/enums/StoragePolicy.java)
- Change coupling: TraceLogHandler.java ↔ TraceLogStorage.java (laokou-service/laokou-logstash/laokou-logstash-adapter/src/main/java/org/laokou/logstash/consumer/handler/TraceLogHandler.java)
- Change coupling: dept.tsx ↔ menu.tsx (ui/src/pages/Sys/Permission/dept.tsx)
- Change coupling: login.tsx ↔ notice.tsx (ui/src/pages/Sys/Log/login.tsx)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (archive/package-lock.json)
- Critical CVE: [GHSA redacted] (archive/package-lock.json)
- Critical CVE: [GHSA redacted] (archive/package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (laokou-service/laokou-auth/laokou-auth-app/src/main/java/org/laokou/auth/service/validator/AuthorizationCodeAuthParamValidator.java)
- Duplicated block (10 lines × 3) (laokou-common/laokou-common-mybatis-plus/src/main/java/org/laokou/common/mybatisplus/handler/CryptoTypeHandler.java)
- Duplicated block (10 lines × 3) (laokou-service/laokou-admin/laokou-admin-domain/src/main/java/org/laokou/admin/tenant/ability/TenantDomainService.java)
- Duplicated block (12 lines × 2) (laokou-service/laokou-auth/laokou-auth-domain/src/main/java/org/laokou/auth/model/AuthA.java)
- Duplicated block (5 lines × 2) (laokou-service/laokou-admin/laokou-admin-app/src/main/java/org/laokou/admin/user/service/validator/ModifyUserParamValidator.java)
- Duplicated block (5 lines × 8) (laokou-service/laokou-admin/laokou-admin-domain/src/main/java/org/laokou/admin/dept/model/DeptA.java)
- …and 152 more
New (690)
- Boundary-crossing change coupling: DomainEventPublisher.java ↔ OAuth2UsernamePasswordAuthentication.java (laokou-common/laokou-common-i18n/src/main/java/org/laokou/common/i18n/dto/DomainEventPublisher.java)
- Boundary-crossing change coupling: GatewayApp.java ↔ LogtashApp.java (laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/GatewayApp.java)
- Boundary-crossing change coupling: GatewayApp.java ↔ OssApp.java (laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/GatewayApp.java)
- Boundary-crossing change coupling: MonitorApp.java ↔ AdminApp.java (laokou-cloud/laokou-monitor/src/main/java/org/laokou/monitor/MonitorApp.java)
- Boundary-crossing change coupling: MonitorApp.java ↔ AuthApp.java (laokou-cloud/laokou-monitor/src/main/java/org/laokou/monitor/MonitorApp.java)
- Boundary-crossing change coupling: MonitorApp.java ↔ LogtashApp.java (laokou-cloud/laokou-monitor/src/main/java/org/laokou/monitor/MonitorApp.java)
- CI installs an unverified third-party binary (.github/workflows/maven.yml)
- Change coupling: AESUtils.java ↔ RSAUtils.java (laokou-common/laokou-common-crypto/src/main/java/org/laokou/common/crypto/util/AESUtils.java)
- Change coupling: CaptchaSendCmdExe.java ↔ SendCaptchaEvent.java (laokou-service/laokou-auth/laokou-auth-app/src/main/java/org/laokou/auth/command/CaptchaSendCmdExe.java)
- Change coupling: DeptGatewayImpl.java ↔ dept.tsx (laokou-service/laokou-admin/laokou-admin-infrastructure/src/main/java/org/laokou/admin/dept/gatewayimpl/DeptGatewayImpl.java)
- Change coupling: DiscoveryNameResolver.java ↔ GrpcClientConfig.java (laokou-common/laokou-common-grpc-client/src/main/java/org/laokou/common/grpc/client/config/DiscoveryNameResolver.java)
- Change coupling: ExceptionHandler.java ↔ AuthFilter.java (laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/exception/handler/ExceptionHandler.java)
- Change coupling: GatewayApp.java ↔ MonitorApp.java (laokou-cloud/laokou-gateway/src/main/java/org/laokou/gateway/GatewayApp.java)
- Change coupling: LoginLogSaveCmdExe.java ↔ NoticeLogSaveCmdExe.java (laokou-service/laokou-auth/laokou-auth-app/src/main/java/org/laokou/auth/command/LoginLogSaveCmdExe.java)
- Change coupling: MailServiceImpl.java ↔ GYYSmsServiceImpl.java (laokou-common/laokou-common-mail/src/main/java/org/laokou/common/mail/service/impl/MailServiceImpl.java)
- Change coupling: RoleDeptGatewayImpl.java ↔ UserRoleGatewayImpl.java (laokou-service/laokou-admin/laokou-admin-infrastructure/src/main/java/org/laokou/admin/role/gatewayimpl/RoleDeptGatewayImpl.java)
- Change coupling: SendCaptchaEvent.java ↔ AuthA.java (laokou-service/laokou-auth/laokou-auth-client/src/main/java/org/laokou/auth/dto/domainevent/SendCaptchaEvent.java)
- Change coupling: TraceLogHandler.java ↔ StorageConfig.java (laokou-service/laokou-logstash/laokou-logstash-adapter/src/main/java/org/laokou/logstash/consumer/handler/TraceLogHandler.java)
- Change coupling: TraceLogHandler.java ↔ TraceLogLokiStorage.java (laokou-service/laokou-logstash/laokou-logstash-adapter/src/main/java/org/laokou/logstash/consumer/handler/TraceLogHandler.java)
- Change coupling: UserDomainService.java ↔ UserRoleGatewayImpl.java (laokou-service/laokou-admin/laokou-admin-domain/src/main/java/org/laokou/admin/user/ability/UserDomainService.java)
- …and 670 more
Changes since last survey
- 300 commits — 207 feature/other, 93 fixes
By area
- (repo) — 144 commits
- (root) — 53 commits
- laokou-service/laokou-iot — 27 commits
- laokou-service/laokou-admin — 12 commits
- doc/deploy — 11 commits
- .github/workflows — 10 commits
- laokou-service/laokou-ai — 10 commits
- laokou-service/laokou-standalone — 6 commits
- laokou-service/laokou-auth — 4 commits
- KEdge-Gateway/go.mod — 3 commits
- archive/docs — 3 commits
- laokou-cloud/laokou-nacos — 3 commits
- laokou-cloud/laokou-gateway — 2 commits
- laokou-common/laokou-common-grpc-client — 2 commits
- laokou-common/laokou-common-mybatis-plus — 2 commits
- laokou-common/laokou-common-security — 2 commits
- ui/src — 2 commits
- doc/db — 1 commit
- laokou-common/laokou-common-crypto — 1 commit
- laokou-common/laokou-common-mcp — 1 commit
Notable commits
- fix: fix(deps): update dependency co.elastic.clients:elasticsearch-java to v9.5.2
- fix: fix(deps): update dependency co.elastic.clients:elasticsearch-java to v9.5.2 (#6779)
- fix: fix(deps): update dependency co.elastic.clients:elasticsearch-java to v9.5.3
- fix: fix(deps): update dependency co.elastic.clients:elasticsearch-java to v9.5.3 (#6817)
- fix: fix(deps): update dependency com.alibaba.nacos:nacos-all to v3.2.4
- fix: fix(deps): update dependency com.alibaba.nacos:nacos-all to v3.2.4 (#6796)
- fix: fix(deps): update dependency com.github.mwiede:jsch to v2.28.7
- fix: fix(deps): update dependency com.github.mwiede:jsch to v2.28.7 (#6766)
- fix: fix(deps): update dependency com.github.oshi:oshi-core to v7.6.0
- fix: fix(deps): update dependency com.github.oshi:oshi-core to v7.6.0 (#6778)
- fix: fix(deps): update dependency com.github.oshi:oshi-core to v7.6.1
- fix: fix(deps): update dependency com.github.oshi:oshi-core to v7.6.1 (#6818)
- fix: fix(deps): update dependency com.taosdata.jdbc:taos-jdbcdriver to v3.9.1
- fix: fix(deps): update dependency com.taosdata.jdbc:taos-jdbcdriver to v3.9.1 (#6872)
- fix: fix(deps): update dependency io.micrometer:micrometer-tracing-bom to v1.7.1
- fix: fix(deps): update dependency io.micrometer:micrometer-tracing-bom to v1.7.1 (#6762)
- fix: fix(deps): update dependency io.netty:netty-bom to v4.2.18.final
- fix: fix(deps): update dependency io.netty:netty-bom to v4.2.18.final (#6865)
- fix: fix(deps): update dependency io.projectreactor:reactor-core to v3.8.7
- fix: fix(deps): update dependency io.projectreactor:reactor-core to v3.8.7 (#6763)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
KouShenhai/KCloud-Platform-IoT was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6991aaa53c486b82b8b28efaa9f6072c267ba5c1 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-90d5d2fe38ee.