YunaiV/ruoyi-vue-pro
37.5
Weak · 24 September 2026
446.4k
lines of production code
Java
primary language
4
measurements over time
What this system is
This system is a comprehensive enterprise backend framework built on Spring Boot, providing a modular architecture with dedicated starters for security, data persistence, messaging, and monitoring. It includes a suite of business modules for workflow management (BPM), instant messaging (IM), customer relationship management (CRM), financial management (FMS), and human resources (HRM), alongside an AI module supporting chat, image generation, and knowledge bases. The platform features robust infrastructure capabilities such as multi-tenancy, distributed locking, rate limiting, and extensive database compatibility across multiple SQL dialects.
How it got here
2019–2022 — Framework modularization and multi-tenancy
63 changes.
The project established its foundational architecture by initializing a multi-module Maven structure and refactoring core components into distinct, reusable Spring Boot starters. Significant work focused on implementing comprehensive multi-tenant isolation across database, cache, and message queues, while enhancing the MyBatis and security modules with cross-database compatibility and modular authentication. The period also introduced essential infrastructure features such as distributed tracing, idempotency, and job scheduling, alongside initial database schema definitions for multiple SQL dialects.
2023–2025 — AI integration and module expansion
107 changes.
This period focused on integrating comprehensive AI capabilities, including chat, image generation, and knowledge bases, while significantly expanding the platform's business modules. The infrastructure layer was enhanced with robust code generation, unified file storage, and workflow management, alongside new IoT, CRM, and payment features.
2026 — IM module implementation and new module expansions
56 changes.
This period focused on the comprehensive development of the Instant Messaging (IM) module, establishing its core data models, services, and real-time communication features including voice/video calls via LiveKit. Concurrently, the project expanded its functional scope by introducing initial APIs for Warehouse Management (WMS) and enhancing existing modules such as HRM, FMS, and OA with new administrative and workflow capabilities.
Features
AI Knowledge Base document and segment management with intelligent splitting and reranking
The AI knowledge base module now provides full service-layer management for knowledge bases, documents, and segments, including creating, updating, and deleting documents and segments, as well as reindexing when embedding models change. Document ingestion automatically downloads content via URL, parses it using Apache Tika, and splits it into segments using an auto-detect strategy that supports Markdown QA format and semantic text splitting to preserve context. Search results are optionally re-ranked using a configurable RerankModel to improve relevance, and segment updates or status changes trigger asynchronous vector store synchronization.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/knowledge · high confidence
AI module configuration and model factory initialization
The AI module now initializes its core configuration and model factory via \AiAutoConfiguration\ and \YudaoAiProperties\. This includes registering a default \ObservationRegistry\ to prevent errors when missing, and defining beans for various AI providers (Gemini, Doubao, SiliconFlow, HunYuan, etc.) that are conditionally enabled via properties. The configuration also sets up vector store properties (Qdrant, Redis, Milvus) and integrates with Spring AI's tool calling and token estimation capabilities.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/framework/ai/config · high confidence
AI module introduces new enums for model platforms, document splitting, and content generation roles
The AI module now includes a comprehensive set of enumeration definitions that establish the foundation for its AI capabilities. This includes \AiPlatformEnum\ which adds support for multiple AI providers such as Anthropic, Gemini, Grok, and various domestic platforms like TongYi and WenXin. \AiDocumentSplitStrategyEnum\ introduces new document processing strategies, specifically Markdown QA and semantic splitting, alongside existing token and paragraph methods. Additionally, \AiChatRoleEnum\ defines built-in roles for writing assistance and mind-map generation, while \AiWriteTypeEnum\ and \DictTypeConstants\ provide the structure for customizable writing tasks and configuration options.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/enums · high confidence
Add AI music generation support via Suno integration
The AI module now includes a new capability to generate music using the Suno API. This change introduces the \AiMusicService\ interface and its implementation, which handles music generation (via description or lyrics), status synchronization through scheduled jobs (\AiSunoSyncJob\), and CRUD operations for music records. The feature is wired into the web layer via \AiWebConfiguration\ for API exposure and includes the necessary data objects and mappers to persist music metadata and status.
(repo-wide) · high confidence
Add AI workflow service interface and implementation
Introduces the AI workflow service layer, providing CRUD operations (create, update, delete, get, page) and a test execution capability for AI workflows. The implementation integrates with the Tinyflow engine to parse workflow graphs and execute them, utilizing Fastjson2 for JSON processing and the existing AI model service for LLM provider integration.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/workflow · high confidence
Add CronUtils helper for Quartz cron expression validation and next execution times
A new CronUtils class has been added to the Quartz starter to provide utility methods for validating cron expressions and calculating the next N execution times. This allows the system to accurately determine future trigger times for scheduled tasks, addressing issues where specifying a year in a cron expression previously resulted in only a single execution or errors when viewing task details in the backend.
yudao-framework/yudao-spring-boot-starter-job/src/main/java/cn/iocoder/yudao/framework/quartz/core/util · high confidence
Add OpenGauss database schema scripts
Added SQL migration scripts for the OpenGauss database, including the main application schema (ruoyi-vue-pro.sql) and the Quartz scheduler tables (quartz.sql). These files provide the necessary table structures, indexes, and sequences to run the application on OpenGauss, enabling compatibility with this specific database engine.
sql/opengauss · high confidence
Add manual VO data translation support via TranslateUtils
The framework now provides a \TranslateUtils\ class to manually trigger data translation for Value Objects (VOs) when annotation-based approaches like \@TransMethodResult\ are not applicable. This utility initializes with a \TransService\ bean (configured via \YudaoTranslateAutoConfiguration\ only when \TransService\ is present) and exposes a static \translate\ method that batches-translates a list of VO objects in-place, allowing developers to integrate translation logic directly into their service code.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/translate · high confidence
Add support for Dameng (DM) database in Flowable and Liquibase
This change introduces a new patch module that enables the Flowable engine and Liquibase to operate with Dameng (DM) databases. It adds a custom \DmDatabase\ implementation for Liquibase to handle DM-specific connection and schema behaviors, updates the Liquibase \BooleanType\ to map boolean columns to the \bit\ type for DM, and registers the \DmDatabase\ class in the Liquibase service provider configuration so it is automatically detected.
sql/dm/flowable-patch · high confidence
Added DM8 database initialization scripts
Added SQL initialization scripts for the DM8 (DaMeng) database, including the full schema for the Quartz scheduler (\quartz.sql\) and the core application tables (\ruoyi-vue-pro-dm8.sql\). This enables the application to run on the DM8 database platform.
sql/dm · high confidence
Added ERP-style service layer for the demo03 student module
The infrastructure module now includes a new \Demo03StudentErpService\ interface and its implementation, providing CRUD operations for students along with their associated sub-entities (courses and grades). This service layer supports batch deletion and transactional consistency, serving as a code-generation example for master-detail (ERP-style) data handling within the demo03 module.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/demo/demo03/erp · high confidence
Added HighGo database schema and Quartz initialization scripts
New SQL migration files have been added to the sql/highgo directory to support HighGo database deployments. This includes ruoyi-vue-pro.sql, which contains the full application schema adapted for HighGo (using types like int2/int8 and sequences), and quartz.sql, which provides the PostgreSQL-compatible table structure required for the Quartz scheduler.
sql/highgo · high confidence
Added KingbaseES database schema scripts
Added SQL migration scripts for the KingbaseES database, including the Quartz scheduler tables (quartz.sql) and the main application schema (ruoyi-vue-pro.sql), enabling the application to run on this specific database platform.
sql/kingbase · high confidence
Added Local LiveKit PoC Environment for Video Integration Testing
A new self-contained Proof of Concept (PoC) environment for LiveKit Server has been added to the \script/livekit-poc\ directory, enabling local development and verification of video integration features. This includes a \docker-compose.yml\ configuration to run the LiveKit server with specific port mappings (7880 for HTTP/WebSocket, 7881 for WebRTC TCP fallback, and 7882 for WebRTC UDP) and a \livekit.yaml\ configuration file that sets up webhook callbacks to the local yudao backend for room management events. A \verify.sh\ script is provided to automate the validation process, which includes waiting for the service, generating JWT tokens with appropriate permissions, creating and listing rooms via the API, and providing a browser link for real-time media testing. This setup allows developers to quickly test local media connections and room management logic without requiring a production LiveKit instance.
script/livekit-poc · high confidence
Added Quartz scheduler and application database schemas for MySQL
The \sql/mysql\ directory now includes \quartz.sql\ and \ruoyi-vue-pro.sql\, providing the necessary database structures for the Quartz job scheduler and the core application tables. The Quartz script initializes standard scheduling tables and pre-loads job definitions for system maintenance tasks such as access log cleaning, error log cleaning, and payment order synchronization. The main application script defines the schema for infrastructure components, including API access and error logs, code generation configurations, and system settings, ensuring the database is ready for deployment.
sql/mysql · high confidence
Added channel material type enumeration
Introduced the ImChannelMaterialTypeEnum to define specific content types for IM channel materials, supporting both internal rich text content (which renders in a client-side detail page) and external links (which open in a browser).
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/enums/channel · high confidence
Added data access layer for IM emoji packs and user items
Introduced MyBatis mapper interfaces for managing IM emoji packs and user-specific emoji items. The new \ImFacePackItemMapper\, \ImFacePackMapper\, and \ImFaceUserItemMapper\ provide database query capabilities for paginated listings, status-based filtering, and user-specific retrieval, enabling the backend to store and retrieve emoji pack metadata and individual user emoji assets.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/face · high confidence
Added data access layer for IM group management and sensitive word filtering
This change introduces the MyBatis mapper interfaces for the IM module's group and sensitive word domains. ImGroupMapper provides paginated group listing and row-level locking for updates, while ImGroupMemberMapper handles member queries, role-based filtering, and bulk status updates. ImGroupRequestMapper supports group join request management, including cursor-based incremental pulls and request reset logic. Additionally, ImSensitiveWordMapper enables sensitive word management with status-based queries and max-update-time tracking.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/group · high confidence
Added data model for tracking conversation read positions
A new data object, ImConversationReadDO, has been introduced to store the maximum read message ID and read time for users across private chats, group chats, and channels. This entity serves as the single source of truth for read status, enabling the system to accurately track and retrieve the last read position within any conversation type.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/dataobject/conversation · high confidence
Added data models for IM channels and channel materials
Introduced the ImChannelDO and ImChannelMaterialDO data objects to support the backend implementation of IM channels. ImChannelDO defines the structure for operational broadcast channels (including code, name, avatar, sort order, and status), while ImChannelMaterialDO models the reusable content library associated with channels, supporting various material types such as rich text and links.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/dataobject/channel · high confidence
Added data models for system and user emoji packs
The IM module now includes database entity definitions to support emoji management. This introduces \ImFacePackDO\ and \ImFacePackItemDO\ for storing system-level emoji packs and their individual images, and \ImFaceUserItemDO\ for storing user-specific private emojis. These models enable the backend to persist emoji metadata such as names, icons, URLs, dimensions, and sort order, laying the groundwork for the emoji management interface.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/dataobject/face · high confidence
Added database access layer for IM channel and channel material management
Introduced MyBatis mapper interfaces for managing IM channels and their associated materials. The new ImChannelMapper provides methods to retrieve channels by code, list them by status and sort order, and perform paginated searches using code, name, and status filters. The ImChannelMaterialMapper enables querying material counts and lists by channel ID, as well as paginated searches filtered by channel ID, type, title, and creation time range.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/channel · high confidence
Added database persistence for RTC call records and participants
The IM module now persists real-time call data to the database, enabling the management backend to query call history and participant details. This change introduces \ImRtcCallMapper\ and \ImRtcParticipantMapper\ to support operations such as paginated call listing, filtering by status and time, and retrieving participants by room or call ID, shifting the system from in-memory or transient storage to a durable, cluster-compatible state.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/rtc · high confidence
Added demo controllers for student, course, and grade management with sub-table support
New admin API endpoints have been added for managing students, their associated courses, and grades. The ERP-style controller exposes full CRUD operations for students and allows batch deletion of both students and their related courses and grades, while the normal-style controller provides simplified endpoints for listing courses and retrieving grades by student ID. Request and response value objects are included to handle pagination, filtering, and Excel export functionality for these entities.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/demo/demo03/erp · high confidence
Added demo service implementations for contact and category management
The infra module now includes service interfaces and implementations for the demo01 contact and demo02 category examples. The contact service adds support for batch deletion of contacts, while the category service implements hierarchical category management with validation for parent-child relationships, name uniqueness, and cycle detection.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/demo/demo01 · high confidence
Added inner service layer for demo03 student CRUD with batch delete and diff-based child table updates
The demo03 module now includes a new inner service interface and implementation for managing students, their courses, and grades. This service supports standard create, read, update, and delete operations, including a new batch delete capability for students. For child tables (courses and grades), updates are now handled using a diff-list approach to efficiently calculate and apply additions, modifications, and deletions in a single transaction, ensuring data consistency when modifying parent-child relationships.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/demo/demo03/inner · high confidence
Added read-position tracking and reliable incremental pull for IM conversations
The IM module now includes a new \ImConversationReadMapper\ that enables tracking of per-user read positions within conversations. This supports reliable incremental message pulling using a cursor based on update time and record ID, ensuring users can fetch new read-status updates efficiently. Additionally, it introduces a monotonic update mechanism for read positions, using a compare-and-swap condition to prevent read-position regression in cases of out-of-order or concurrent updates, thereby improving the consistency of read receipts.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/conversation · high confidence
Added request and response VO classes for the demo contact module
New Value Object classes have been introduced for the demo contact feature to handle API interactions. The Demo01ContactPageReqVO supports paginated queries with filters for name, sex, and creation time. The Demo01ContactSaveReqVO manages creation and updates, enforcing validation rules such as requiring name, sex, birthday, and description. The Demo01ContactRespVO defines the data structure returned to users, including fields for ID, name, sex, birthday, description, avatar, and creation time, and includes annotations for Excel export functionality.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/demo/demo01/vo · high confidence
Added service layer for conversation read-position tracking and compensation
The IM module now includes a new service interface and implementation (ImConversationReadService) that manages per-user read positions within conversations. This service ensures read positions are monotonically increasing, handling concurrent or out-of-order updates safely via database constraints and CAS-style updates. It provides methods to update, retrieve, and batch-fetch read positions, and supports incremental pulling of read-position changes using a cursor (update time + ID) to facilitate offline compensation and reconnection scenarios.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/conversation · high confidence
Added trace ID injection filter for request tracing
The TraceFilter component has been added to the monitor starter, automatically injecting a 'trace-id' header into HTTP responses. This enables users to correlate incoming requests with backend logs and distributed tracing data without manual configuration.
yudao-framework/yudao-spring-boot-starter-monitor/src/main/java/cn/iocoder/yudao/framework/tracer/core/filter · high confidence
Adds multi-datasource support and Druid ad removal filter
The framework now supports configuring multiple data sources (master and slave) via the new DataSourceEnum and the MyBatis-Plus dynamic datasource annotation. Additionally, a new servlet filter (DruidAdRemoveFilter) has been introduced to automatically strip the Druid monitoring console's bottom banner and advertisement from the response, ensuring a cleaner user interface for database monitoring.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/datasource/core · high confidence
Admin API for trade after-sales and brokerage management
The trade module now exposes admin REST endpoints for managing after-sales requests and brokerage (commission) operations. Administrators can page, view details, and approve, reject, receive, or refund after-sales via the new AfterSaleController, and manage brokerage users, records, and withdrawal approvals via the BrokerageUserController, BrokerageRecordController, and BrokerageWithdrawController. These controllers wire existing trade services and member user lookups, and include endpoints for payment callbacks that update after-sale refund and brokerage withdrawal statuses.
yudao-module-mall/yudao-module-trade · high confidence
Automated RTC call state management via scheduled jobs
Two new scheduled jobs have been added to the IM module to handle Real-Time Communication (RTC) call lifecycle events. The \ImRtcCallCleanupJob\ identifies and cleans up 'zombie' calls that were not properly terminated (e.g., due to lost webhooks or client crashes) based on a configurable time threshold. The \ImRtcParticipantTimeoutJob\ scans for participants stuck in the 'INVITING' state beyond a set timeout, marking them as 'NO\_ANSWER' and pushing rejection signals to the frontend to ensure the UI converges correctly. Both jobs support configurable thresholds via system properties or job parameters.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/job · high confidence
BPM module adds data access, messaging, and workflow triggers
The BPM module introduces new MyBatis mappers for managing process categories, forms, definitions, expressions, listeners, user groups, and OA leave requests, alongside a new message service that sends SMS notifications for approval outcomes and task assignments. It also implements an OA leave workflow that creates process instances and updates status via listeners, and adds a trigger framework supporting form updates/deletions and synchronous/asynchronous HTTP requests during process execution.
(repo-wide) · high confidence
BPM sub-process initiator and user task listener implementations
Added BpmCallActivityListener to correctly determine the initiator for sub-processes based on configurable settings (main process initiator, form field, or admin fallback), and added BpmUserTaskListener to execute HTTP requests upon user task assignment with relevant context variables.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/service/task/listener · high confidence
BPM workflow engine definition enums introduced
The workflow module now defines a comprehensive set of enumerations in the \definition\ package to standardize process configuration. These enums cover condition operators (including new 'contains' and 'not contains' logic), node types (mapping simple design nodes to BPMN elements like inclusive gateways for parallel branches), user task behaviors (approval methods, timeout/rejection/empty-handler strategies), and process control features (auto-approve, child-process start-user logic, boundary events, and trigger types). This provides the foundational data structures for the new simple-mode designer and enhanced branching logic.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/enums/definition · high confidence
CRM module introduces new business, status, and clue management APIs
The CRM module now exposes comprehensive REST APIs for managing business opportunities, their lifecycle statuses, and sales leads. Administrators can create, update, delete, and query business opportunities (including filtering by customer or contact), manage configurable business status groups and individual statuses, and handle lead operations such as creation, transfer, and conversion to customers. The implementation includes dedicated controllers, request/response value objects with Excel export support, and permission-protected endpoints for these core CRM entities.
yudao-module-crm · high confidence
Code generator now supports configurable VO/DO modes and Excel import/export
The code generation templates in the infrastructure module have been updated to support a new VO/DO (Value Object / Data Object) mode, allowing users to choose whether generated entities include Swagger and Excel annotations directly on the Data Objects. Additionally, the generator now produces backend Java code for Excel import and export functionality, including controller endpoints, request/response View Objects, and service logic, controlled by the \import-enable\ configuration flag.
yudao-module-infra/src/main/resources · high confidence
Defines RTC call lifecycle and participant states
The IM module now includes a set of enums to model the full lifecycle of Real-Time Communication (RTC) calls. This introduces specific statuses for the call itself (Created, Running, Ended) and for individual participants (Inviting, Joined, Rejected, No Answer, Left), along with enumerations for call end reasons (such as Hangup, Reject, Cancel, Busy, Error) and media types (Voice, Video). These definitions provide the structured state machine required to track call progress and handle outcomes like missed calls or busy signals.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/enums/rtc · high confidence
Expanded AI model support with unified factory and new provider integrations
The AI module now supports a wider range of providers through a centralized model factory. New integrations include Grok, Gemini, and SiliconFlow (chat and image), alongside existing support for TongYi, YiYan, DeepSeek, DouBao, HunYuan, ZhiPu, MiniMax, Moonshot, StepFun, XingHuo, BaiChuan, OpenAI, Azure OpenAI, Anthropic, and Ollama. The factory also adds support for Midjourney and Suno APIs. To simplify integration, several providers (BaiChuan, MiniMax, Moonshot, StepFun) now reuse the DeepSeek client, while others (DouBao, Gemini, SiliconFlow, HunYuan, Grok) reuse the OpenAI client, ensuring consistent behavior across different platforms.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/framework/ai/core · high confidence
IM module Swagger API documentation configuration
The IM module now includes a dedicated web configuration class that registers a specific OpenAPI (Swagger) group named 'im'. This ensures that the module's API endpoints are correctly categorized and visible in the generated API documentation, improving discoverability for developers and API consumers.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/framework/web · high confidence
IM module adds manager dashboard statistics service
The IM module introduces a new service layer (\ImStatisticsManagerService\ and its implementation) dedicated to the manager backend's data dashboard. This service aggregates and exposes key metrics for users (total, new, active), groups (total, new, size distribution), and messages (private/group counts, daily trends, type distribution, and top senders) over configurable time ranges, delegating data retrieval to a new mapper while keeping the logic separate from core business services.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/statistics · high confidence
IM module introduces structured error codes, content types, and conversation enums
The IM module now defines a comprehensive set of error codes (ErrorCodeConstants) covering messages, groups, members, friends, sensitive words, face packs, channels, and RTC calls, providing specific user-facing messages for scenarios like read-disabled states, pin limits, mute restrictions, and friend/block actions. It also establishes the message content type enumeration (ImContentTypeEnum) that maps to OpenIM segment numbers for user chat (text, image, voice, video, file, merge, card, face), channel materials, signal events (recall, receipt, read), RTC signaling, friend notifications, and group events, alongside a conversation type enum (ImConversationTypeEnum) for private, group, and channel sessions. These enums standardize how the system reports errors and categorizes message types across the IM layer.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/enums · high confidence
IM module structure and sensitive word data model introduced
The instant messaging (IM) module has been initialized with its core package structure and a new data model for managing sensitive words. Users can now benefit from a dedicated module for IM features (such as chat and message handling) with a clear URL prefix (/im/) and database table naming convention (im\_). Additionally, the system introduces a new 'im\_sensitive\_word' table and corresponding data object, enabling the storage and management of sensitive word lists with status tracking, which supports content moderation within the IM context.
(repo-wide) · high confidence
Idempotent module now supports user-level deduplication via new key resolver
The idempotent protection starter has been refactored to use Spring Boot's AutoConfiguration model, ensuring it initializes after the Redis auto-configuration. A key addition is the UserIdempotentKeyResolver, which enables idempotency checks scoped to specific users, allowing the system to distinguish between identical requests made by different users. The configuration also registers the existing Default and Expression key resolvers alongside the new user-specific one.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/idempotent/config · high confidence
Infra module adds code generation, config, and log cleanup capabilities
The infra module now includes code generation support via MapStruct converters for table and column metadata, configuration management converters, and scheduled jobs to automatically clean up job, access, and error logs older than 14 days. It also registers a dedicated Swagger API group for the infra module and provides package documentation for its controller, convert, framework, and message queue components.
(repo-wide) · high confidence
Initial PostgreSQL database schema and Quartz scheduler support
This change introduces the initial PostgreSQL database migration scripts for the application. It includes the full schema definition in \sql/postgresql/ruoyi-vue-pro.sql\, covering core tables for infrastructure logs, code generation, and system management, along with necessary sequences and comments. Additionally, it adds \sql/postgresql/quartz.sql\, providing the standard Quartz job scheduler tables adapted for PostgreSQL, enabling scheduled task execution on this database platform.
sql/postgresql · high confidence
Initial SQL Server database schema and Quartz support
Added the initial SQL Server database migration scripts (\ruoyi-vue-pro.sql\ and \quartz.sql\) to enable the application to run on Microsoft SQL Server. The main schema script includes a \dual\ table with a single row of data (required for compatibility with other database dialects) and full table definitions for core modules like API access logs. The Quartz script provides the necessary table structures for scheduled job execution, using SQL Server-specific syntax such as \GO\ batch separators.
sql/sqlserver · high confidence
Initial backend service layer for IM emoji packs and user-specific emojis
This change introduces the backend service interfaces and implementations for managing IM emoji packs and individual user emojis. It enables administrators to create, update, delete, and paginate emoji packs and their items, while enforcing constraints such as preventing the deletion of packs that still contain items. For end-users, it supports retrieving enabled emoji packs and managing personal emoji collections, including limits on the number of private emojis and ownership validation to prevent unauthorized deletions.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/face · high confidence
Initial trade module API contracts and domain enums
The trade module now exposes its core domain definitions and inter-service contracts. This includes the TradeOrderApi interface for retrieving order details and canceling paid orders, along with the TradeOrderRespDTO used for responses. Additionally, the module introduces a comprehensive set of enums to standardize trade logic across the system, covering order statuses and types (normal, seckill, bargain, combination, points), after-sale workflows (apply, refund, return), brokerage and commission records/withdrawals, delivery methods (express, pickup), and error codes for orders, after-sales, pricing, logistics, and distribution.
yudao-module-mall/yudao-module-trade-api · high confidence
Initializes group request handling and member role enums
Adds three new enumeration classes to the IM module to support group management features: ImGroupMemberRoleEnum defines member roles (Owner, Admin, Normal) with helper methods for role checks; ImGroupRequestHandleResultEnum standardizes the outcomes for group join requests (Unhandled, Agreed, Refused); and ImGroupAddSourceEnum captures how users discover groups (Search, Invite, QR Code, Share Link), though only Invite is currently functional as the other sources are marked as unimplemented.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/enums/group · high confidence
Integrated dictionary management and enhanced Excel export capabilities
The Excel starter now includes a local dictionary cache (DictFrameworkUtils) with a 1-minute TTL, enabling efficient label-value lookups for Excel operations. New annotations (@DictFormat, @ExcelColumnSelect) and converters (DictConvert, MultiDictConvert) allow fields to automatically format dictionary values as labels during export and parse labels back to values during import, including support for multi-value fields. Exported Excel files now feature auto-sized columns and configurable dropdown lists in specified columns. Additionally, the @InDict validation annotation ensures imported data values exist within the dictionary, and Long ID precision is preserved during export.
yudao-framework/yudao-spring-boot-starter-excel/src/main · high confidence
Introduce HTTP API signature verification for request integrity and replay protection
This change adds a new HTTP API signature module that allows developers to protect endpoints by annotating them with @ApiSignature. The framework automatically validates incoming requests by verifying a signature computed from query parameters, request body, headers, and the application secret (SHA-256). It also enforces replay protection by storing nonces in Redis, ensuring each request is unique within a configurable timeout window (default 60 seconds). This provides a standardized way to secure API interactions against tampering and duplicate submissions.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/signature · high confidence
Introduce backend services for managing IM channels and materials
Added the backend service layer for the IM module, introducing \ImChannelService\ and \ImChannelMaterialService\ (with their implementations) to enable administrators to create, update, delete, and query IM channels and their associated materials. The channel service enforces unique codes and prevents deletion if materials are present, while the material service prevents deletion if materials have been used in messages, ensuring data integrity for historical message lookups.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/channel · high confidence
Introduce comprehensive multi-tenant isolation for database, cache, and message queues
This release adds a complete multi-tenant isolation layer to the framework. Database queries are automatically filtered by tenant ID using a MyBatis Plus interceptor, with support for ignoring specific tables or entities via configuration or annotations. Redis cache keys are automatically suffixed with the tenant ID to ensure data separation, and message queues (Kafka, RabbitMQ, RocketMQ) are enhanced to propagate the tenant ID in message headers, ensuring consumers process data in the correct tenant context. Additionally, scheduled jobs can now execute per-tenant using the new @TenantJob annotation.
yudao-framework/yudao-spring-boot-starter-biz-tenant/src/main/java · high confidence
Introduces LiveKit-based real-time communication support
The IM module now integrates with LiveKit to enable real-time audio/video calls. This change adds a configuration class and a core client that handles JWT token generation for user authentication, manages room lifecycle via server APIs (such as deleting rooms and listing participants), and processes webhook events to track room and participant status. This provides the backend foundation for RTC features, including identity management and connection state tracking.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/framework/rtc · high confidence
Introduces Redis-based distributed locking for IM RTC calls
This change adds a new Redis DAO layer to manage concurrent access for real-time communication (RTC) calls. It introduces a distributed lock mechanism that serializes invite requests for both private and group calls, preventing race conditions when establishing sessions. The implementation uses Redisson to ensure that only one invite process runs at a time per conversation pair or group, throwing a 'busy' error if the lock cannot be acquired within 5 seconds.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/redis · high confidence
Introduces backend service for IM real-time voice and video calls
Adds the core backend service interface and implementation for managing real-time communication sessions. This change introduces a complete call lifecycle including creation, inviting participants, joining, accepting, rejecting, and leaving calls, with specific logic for both private and group conversations. It integrates with LiveKit for media handling, manages participant states, handles timeout scenarios (such as no-answer), and records call history for admin review.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/rtc · high confidence
Introduces enums for friend request sources, handling results, and relationship states
This change adds three new enumeration classes to the IM module's friend subsystem to structure friend-related data. ImFriendAddSourceEnum defines the channels through which a friend request is initiated (search, group, QR code, or card). ImFriendRequestHandleResultEnum standardizes the possible outcomes of a request (unhandled, agreed, or refused). ImFriendStateEnum consolidates the friend relationship status into a single state value, distinguishing between non-friends, active friends, and blocked users, which supports efficient caching and state checks in the private chat flow.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/enums/friend · high confidence
Introduces pluggable IoT message bus and device management APIs
The IoT core module now supports a configurable message bus architecture, allowing users to select between local, Redis, Kafka, RabbitMQ, or RocketMQ implementations via the \yudao.iot.message-bus.type\ property, with Redis and Kafka including specific cleanup and resend jobs. Additionally, a new \IotDeviceCommonApi\ interface and associated DTOs have been added to expose device authentication, information retrieval, dynamic registration (including gateway sub-device registration), and Modbus device configuration queries, alongside new enumerations for protocol types, serialization formats, and Modbus-specific settings like byte order and raw data types.
yudao-module-iot/yudao-module-iot-core · high confidence
Introduction of BaseDO with metadata fields and translation support
The framework introduces a new \BaseDO\ abstract class in the MyBatis starter, providing a standard base for data objects. This class automatically handles \createTime\, \updateTime\, \creator\, and \updater\ fields via MyBatis Plus field filling, and includes a \deleted\ field for soft deletion. It also implements \TransPojo\ to enable global VO data translation and ignores the \transMap\ property to prevent Jackson serialization errors in Spring Cache. A \clean()\ method is provided to reset these metadata fields.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/core/dataobject · high confidence
Introduction of Friend and Friend Request Data Models
Added the ImFriendDO and ImFriendRequestDO data objects to support the new friend management capabilities. ImFriendDO defines the structure for storing bidirectional friend relationships, including fields for silent mode (notification blocking), custom display names, pinning contacts, and blocking users. ImFriendRequestDO introduces the data structure for the friend application workflow, capturing the requestor, recipient, application reason, and handling status (agree/refuse) to enable the new friend request logic.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/dataobject/friend · high confidence
Introduction of Job Log Framework Service Interface
A new \JobLogFrameworkService\ interface has been added to the Quartz job starter, defining methods to create job logs and asynchronously update their execution results (including end time, duration, success status, and result data). This service layer standardizes how job execution logs are recorded and updated within the framework.
yudao-framework/yudao-spring-boot-starter-job/src/main/java/cn/iocoder/yudao/framework/quartz/core/service · high confidence
Member module API and admin controllers exposed
The member module now exposes a set of internal APIs and admin controllers for managing user addresses, points, experience levels, groups, and configuration. External modules can use the new \MemberAddressApi\, \MemberConfigApi\, \MemberLevelApi\, \MemberPointApi\, and \MemberUserApi\ to interact with member data. Administrators can now manage these resources via the new REST endpoints under \/member/address\, \/member/config\, \/member/group\, \/member/level\, and \/member/experience-record\.
yudao-module-member · high confidence
New AI chat conversation and message services
The chat module now includes dedicated service interfaces and implementations for managing AI chat conversations and messages. Users can create, update, and delete their own chat conversations, as well as retrieve conversation lists and paginated views. The message service enables sending chat messages (both synchronous and streaming), retrieving message history for specific conversations, and deleting messages. The implementation integrates with knowledge bases, web search, and MCP tools to enhance chat responses, and supports features like pinned conversations and admin-level deletion.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/chat · high confidence
New AI image generation service with multi-platform support
Added the AiImageService interface and its implementation to handle AI-powered image generation. The service supports creating, retrieving, updating, and deleting image records, including specific Midjourney operations (imagine, sync, notify, action). It integrates with Spring AI to support multiple image generation platforms, including OpenAI, Silicon Flow, Stability AI, and Alibaba's DashScope (Tongyi), allowing users to generate images via various AI models.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/image · high confidence
New AI model management services for API keys, chat roles, models, and tools
The AI module now includes dedicated service interfaces and implementations for managing AI API keys, chat roles, model configurations, and tools. Administrators can create, update, and delete API keys and models, while chat roles can be associated with specific knowledge bases and tools. The tool service validates tool existence using Spring AI's ToolCallbackResolver, ensuring that registered tools are available before assignment to chat roles.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/model · high confidence
New AI module data access layer with multi-modal support
The AI module's data access layer has been established with a comprehensive set of new database entities and MyBatis mappers. This introduces persistent storage for AI chat conversations and messages (including reasoning content, web search results, and attachments), AI-generated images, music, mind maps, and text writing. It also adds support for AI knowledge bases (documents and segments), chat roles with MCP client configuration, API keys, tools, and workflows. The mappers provide the necessary SQL operations to manage these entities, enabling the backend to store and retrieve data for these diverse AI capabilities.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/dal · high confidence
New AI services for mind map generation and content writing
The AI module now includes backend services for generating mind maps and AI-assisted writing. The new AiMindMapService and AiWriteService interfaces and implementations allow users to generate content via streaming responses, retrieve individual items, and view paginated lists. These services integrate with existing AI model and chat role configurations to handle prompt construction and model selection.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/mindmap, yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/write · high confidence
New AI utility classes for chat options and file handling
Added AiUtils and FileTypeUtils to the AI module. AiUtils provides a centralized way to build Spring AI ChatOptions for various platforms (including Tongyi, DeepSeek, OpenAI, Anthropic, etc.), handles Spring placeholder resolution for API keys, and extracts reasoning content from chat responses. FileTypeUtils leverages Apache Tika to detect MIME types and identify image files, decoupling this functionality from the cloud module.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/util · high confidence
New API access and error log query endpoints for admin clients
The Infra module now exposes dedicated REST controllers for API access logs and API error logs, enabling admin clients (such as the uniapp) to query individual log entries and paginated lists. The ApiAccessLogController provides GET endpoints to retrieve a specific access log by ID and to fetch paginated access logs, while the ApiErrorLogController adds similar GET endpoints for error logs plus a PUT endpoint to update the processing status of an error log. These controllers are backed by new request and response value objects that define the queryable fields (e.g., user ID, application name, request URL, duration, exception details) and support Excel export for both log types.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/logger · high confidence
New BPM API interfaces and event structure for process management
The BPM module now exposes a dedicated API package (\cn.iocoder.yudao.module.bpm.api\) for internal module communication. This includes \BpmProcessInstanceApi\ for creating process instances and allowing initiators to cancel running instances with a reason, as well as \BpmProcessTaskApi\ for triggering specific tasks. Additionally, a new \BpmProcessInstanceStatusEvent\ has been introduced to signal process status changes, notably including a \reason\ field when a process instance ends, enabling downstream listeners to react to specific termination causes.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/api · high confidence
New BPM data models for process definitions, forms, and OA workflows
This change introduces a suite of new database entity classes in the BPM module to support enhanced workflow management. Key additions include BpmProcessDefinitionInfoDO for storing extended process definition metadata (such as form types, visibility, and user/department start permissions), BpmFormDO for managing dynamic form configurations, and BpmCategoryDO for organizing process categories. It also adds BpmOALeaveDO to support OA leave application workflows, BpmProcessInstanceCopyDO for tracking process instance copies/carbon copies, and supporting entities like BpmUserGroupDO, BpmProcessListenerDO, and BpmProcessExpressionDO to enable flexible process listeners and expressions.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/dal/dataobject · high confidence
New BPM definition service layer for process models, categories, and forms
This change introduces the core service interfaces and implementations for managing BPM definition assets within the \yudao-module-bpm\ module. It adds \BpmCategoryService\ to handle process classification with validation to prevent deletion of categories currently in use by models, \BpmFormService\ for managing dynamic form configurations, and \BpmModelService\ to support the creation, import, and export of process models (including both standard BPMN and simplified DingTalk/Feishu-style models). Additionally, it provides \BpmProcessDefinitionService\ for handling the deployment and state management of process definitions, alongside supporting services for process expressions and listeners.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/service/definition · high confidence
New BPM task and process status enums introduced
The BPM module now defines explicit enumerations for task and process instance states, including BpmTaskStatusEnum (with states like SKIP, WAIT, APPROVING, RETURN), BpmProcessInstanceStatusEnum, BpmCommentTypeEnum, BpmAttachmentTypeEnum, BpmTaskSignTypeEnum, and BpmReasonEnum. These enums standardize how task lifecycle states, comment types, attachment types, sign types, and process reasons are represented and formatted in the system, enabling consistent status tracking and messaging for workflow operations.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/enums/task · high confidence
New BaseMapperX interface with join support and concurrency-safe queries
The MyBatis starter now provides a new \BaseMapperX\ interface that extends \MPJBaseMapper\ (from mybatis-plus-join) to enable join queries. It adds \selectJoinPage\ methods that support sorting parameters, and introduces \selectFirstOne\ and \selectFirstOneForUpdate\ methods to safely retrieve a single record in concurrent scenarios where multiple inserts might occur, preventing errors from non-unique results.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/core/mapper · high confidence
New DTOs for structured group and private message sending
The IM module introduces two new data transfer objects, ImGroupMessageSendDTO and ImPrivateMessageSendDTO, to standardize how messages are dispatched. ImGroupMessageSendDTO provides static factory methods for various group events (such as creation, member changes, and message pinning) and includes fields for targeting specific users and requesting read receipts. ImPrivateMessageSendDTO adds a 'persistent' flag to control whether a message is stored and pushed to both parties or sent as a unilateral notification (e.g., deletion alerts), alongside a 'receipt' flag for read-receipt control.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/message/dto · high confidence
New Docker and Jenkins deployment scripts added to script directory
Added a new \script/docker\ directory containing \docker-compose.yml\, \docker.env\, \Docker-HOWTO.md\, and related Dockerfiles to enable local deployment of the system using Docker Compose. This includes configuration for MySQL, Redis, the backend server, and the admin UI, along with instructions for building and running the services. Additionally, a \script/jenkins/Jenkinsfile\ was added to define a CI/CD pipeline for building, archiving, and deploying the application.
script/docker · high confidence
New ERP finance and product management controllers
The ERP module now exposes administrative APIs for managing settlement accounts, finance payments, finance receipts, product categories, products, and product units. These new controllers enable users to create, update, delete, query, and export Excel reports for these entities, with specific endpoints for listing enabled items for frontend dropdowns and handling multi-item operations for payments and receipts.
yudao-module-erp · high confidence
New FMS closing and account-set configuration APIs
The financial management module now exposes administrative REST endpoints for managing accounting periods, closing schemes, templates, and voucher generation, as well as configuring account sets and users. Users can retrieve the current accounting period, view closing overviews, and perform close/cancel-close operations. They can also create, update, and delete closing schemes and templates, configure profit-loss and special closing settings, and generate profit-loss or scheme-based closing vouchers. Additionally, account sets can be created, updated, and initialized, while account users can be listed and their default status updated.
yudao-module-fms · high confidence
New HRM attendance management capabilities
The HRM module now includes a comprehensive set of administrative APIs for managing employee attendance. Administrators can configure attendance groups (including shifts, locations, WiFi rules, and deduction policies), define holidays, and manage leave requests. The system supports recording clock-in/out events with location and device details, and provides detailed daily and monthly attendance statistics with Excel export functionality.
yudao-module-hrm · high confidence
New IM statistics dashboard for managers
Added a dedicated MyBatis mapper (ImStatisticsManagerMapper) that provides SQL queries for the IM manager dashboard, covering user metrics (total, new, active), group metrics (total, new, size distribution), and message metrics (private/group counts, daily trends, type distribution, and top senders) within a specified time range.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/statistics · high confidence
New IP and Area lookup utilities
The IP starter now includes utilities to resolve IP addresses to geographic regions and to query administrative area hierarchies. IPUtils loads the ip2region.xdb database at startup to map IP addresses to area IDs and full Area objects, while AreaUtils loads a local area.csv file to provide a tree of countries, provinces, cities, and districts, supporting lookups by ID, path string, or type. The Area model uses Jackson annotations to safely serialize parent-child relationships without causing stack overflow errors during debugging or default serialization.
yudao-framework/yudao-spring-boot-starter-biz-ip/src/main/java · high confidence
New IoT Gateway module with multi-protocol support
Introduces the \yudao-module-iot-gateway\ module, providing a standalone Spring Boot application to manage IoT device connections. It implements a protocol-agnostic architecture via \IotProtocolManager\, supporting HTTP, TCP, UDP, CoAP, WebSocket, MQTT, EMQX, and Modbus TCP (Client/Server). The gateway handles device authentication, dynamic registration (including sub-devices), and message routing through a message bus, with configuration managed via \IotGatewayProperties\.
yudao-module-iot/yudao-module-iot-gateway · high confidence
New IoT management endpoints for devices, alerting, and Modbus configuration
The IoT module now exposes a comprehensive set of administrative REST APIs for managing IoT infrastructure. Administrators can perform full CRUD operations on devices, including binding/unbinding sub-devices to gateways, managing device groups, and exporting device lists to Excel. A new alerting system allows configuring alert rules (with support for SMS, email, and in-app notifications), viewing alert records, and processing them. Additionally, dedicated endpoints are provided for configuring Modbus connection settings and data points for devices, as well as querying device messages and property history.
yudao-module-iot/yudao-module-iot-biz · high confidence
New MES Serial Number (SN) management and Product Receipt API interfaces
This update introduces new API client modules and a user interface for managing Serial Numbers (SN) within the MES Warehouse Management module. Users can now generate SN codes, query them via a paginated list with filters (SN code, item ID, batch code, creation time), and export the data to Excel. The diff also adds the underlying API definitions for Product Receipts (including main records, lines, and details) and their associated CRUD and workflow actions (submit, stock, execute, cancel), enabling the frontend to interact with these new backend endpoints.
yudao-ui/yudao-ui-admin-vue3 · high confidence
New MES shift planning and calendar management APIs
Added backend controllers and request/response objects for the MES shift planning (cal) module, enabling administrators to manage shift plans, plan shifts, plan-team associations, work teams, team members, and holiday settings. The new endpoints support creating, updating, deleting, and querying these entities, including a dedicated calendar list endpoint that aggregates team shifts while filtering out holidays, and a confirm-plan action to lock plans.
yudao-module-mes · high confidence
New MyBatis Plus type handlers for encrypted fields and collection serialization
The MyBatis starter now includes new type handlers to simplify data mapping. EncryptTypeHandler enables automatic AES encryption and decryption of string fields in the database, configured via the mybatis-plus.encryptor.password property. Additionally, StringListTypeHandler, IntegerListTypeHandler, LongListTypeHandler, and LongSetTypeHandler allow Java collections (List/Set) to be stored as comma-separated strings in VARCHAR columns, reducing the need for manual conversion logic.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/core/type · high confidence
New OA module introduces announcement, attendance, and contact management capabilities
The yudao-module-oa module has been added, providing a new Office Automation feature set for administrators. This includes an Announcement system allowing users to create, update, delete, and forward announcements, with support for tracking read status and managing published vs. received lists. An Attendance system is introduced, enabling clock-in/out functionality, viewing personal attendance records, and generating weekly and monthly reports that track metrics like late arrivals, early departures, and leave days. Additionally, a Contact management feature allows users to maintain external contact lists, organize them into custom categories, and share contacts with other users within the system.
yudao-module-oa · high confidence
New PMS knowledge base content management APIs
The yudao-module-pms module now exposes a comprehensive set of admin REST endpoints for managing knowledge base content, including documents, folders, labels, and collaboration permissions. Users can create, update, move, and delete documents and folders, organize content with labels, and configure granular collaboration permissions. The API also supports global document search, view tracking, favorites, and likes, and provides a hierarchical tree view of the knowledge base structure.
yudao-module-pms · high confidence
New Redis-based message queue implementation with Pub/Sub and Stream support
This change introduces a new Redis message queue implementation within the framework, supporting both broadcast consumption via Redis Pub/Sub and clustered consumption via Redis Streams. It includes auto-configuration for consumer and producer beans, a core template with interceptor support, and scheduled jobs to handle pending message resending and stream cleanup to prevent memory exhaustion. Users can now leverage Redis as a message broker with automatic listener registration and robust message lifecycle management.
yudao-framework/yudao-spring-boot-starter-mq/src/main/java/cn/iocoder/yudao/framework/mq/redis · high confidence
New SQL migration and testing tools in sql/tools
A new \sql/tools\ directory has been introduced to streamline database operations. It includes a Python-based \convertor.py\ script that transforms MySQL schema scripts into formats compatible with Oracle, PostgreSQL, SQL Server, Dameng (DM8), KingbaseES, OpenGauss, and HighGo databases. Additionally, a \docker-compose.yaml\ file provides pre-configured services for running these databases locally for testing, including specific configurations for Apple Silicon Oracle images and manual schema initialization steps for SQL Server and Dameng.
sql/tools · high confidence
New SecurityFrameworkUtils utility for centralized authentication management
The security starter introduces a new SecurityFrameworkUtils class that centralizes access to the current authenticated user and token handling. It provides methods to retrieve the LoginUser, user ID, nickname, and department ID from the Spring Security context, and supports extracting the authentication token from either HTTP headers or query parameters. Additionally, it includes a setLoginUser method to manually establish the security context (useful for non-web contexts like scheduled jobs) and a skipPermissionCheck helper that automatically bypasses permission checks when the current user is accessing a different tenant than their own.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/security/core/util · high confidence
New TokenAuthenticationFilter for OAuth2 token validation and mock login
The security starter now includes a new TokenAuthenticationFilter that validates OAuth2 access tokens via the OAuth2TokenCommonApi and populates the Spring Security context with LoginUser details. It supports user-type matching for admin and app API endpoints while skipping type checks for WebSocket connections, and includes a configurable mock-login feature for development that bypasses real token validation when enabled.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/security/core/filter · high confidence
New WebSocket starter with multi-broker broadcasting and token authentication
This release introduces a new \yudao-spring-boot-starter-websocket\ module that provides a complete, auto-configured WebSocket infrastructure. It supports token-based authentication via a handshake interceptor and allows the connection path to be configured. A key capability is the pluggable message sender system, enabling developers to choose between local, Redis, RabbitMQ, Kafka, or RocketMQ for broadcasting messages across distributed instances. The framework also includes a listener-based message handling model, allowing applications to register specific handlers for different message types.
yudao-framework/yudao-spring-boot-starter-websocket · high confidence
New admin API endpoints for WeChat Official Account management
The \yudao-module-mp\ module now exposes a comprehensive set of REST controllers for managing WeChat Official Account resources in the admin backend. Administrators can now create, update, and query account credentials (app ID, secret, token), manage permanent and temporary media materials (including news images), configure hierarchical custom menus, and handle message operations such as sending customer service messages, syncing and sending template messages, and configuring auto-reply rules. These endpoints are secured with specific permissions (e.g., \mp:account:create\, \mp:material:upload-permanent\) and include request/response validation for fields like media types and message content.
yudao-module-mp · high confidence
New admin API endpoints for scheduled job management and logging
The infra module now exposes dedicated REST controllers for managing scheduled tasks and their execution logs. Administrators can create, update, delete, and trigger jobs, as well as perform batch deletions and synchronize job definitions. The API also supports paginated queries, Excel exports, and retrieving the next execution times for a job. Additionally, a separate endpoint allows viewing, paginating, and exporting detailed logs for job executions, providing better visibility into task history and status.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/job · high confidence
New admin API endpoints for workflow comments, categories, forms, and model management
This change introduces a suite of new REST controllers in the BPM module's admin API, enabling administrators to manage workflow definitions and interactions. Specifically, it adds a comment management interface (BpmCommentController) allowing users to view and create comments on process instances, and a model management interface (BpmModelController) supporting the import, export, and deployment of process models via JSON. Additionally, it exposes full CRUD APIs for workflow categories (BpmCategoryController), dynamic forms (BpmFormController), process definitions (BpmProcessDefinitionController), process expressions (BpmProcessExpressionController), process listeners (BpmProcessListenerController), and user groups (BpmUserGroupController), along with the necessary request/response value objects to support these operations.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/controller · high confidence
New admin API for managing system parameter configurations
The Infra module now exposes a new REST API at /infra/config for administrators to manage system parameters. Users can create, update, query, and delete individual configurations, as well as perform batch deletions. The API supports paginated listing with filtering by name, key, type, and creation time, and includes an export endpoint to download configuration data as an Excel file. A specific endpoint allows retrieving configuration values by key, with built-in protection that prevents the return of values marked as invisible.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/config · high confidence
New admin APIs for AI chat, image generation, and knowledge base management
The AI module now exposes comprehensive admin controllers for managing conversations, messages, images, and knowledge bases. Administrators can create, update, and delete chat conversations and messages, with support for streaming responses, file attachments, and web search integration. Image generation capabilities are available for OpenAI, Stable Diffusion, and Midjourney, including public/private listing and Midjourney-specific actions. Knowledge base management allows for CRUD operations on knowledge bases and documents, enabling the configuration of embedding models and segmentation parameters.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/controller · high confidence
New admin APIs for IM friends, groups, face packs, and read receipts
The admin backend now exposes dedicated REST controllers for managing IM social features and state. Users can manage friend relationships (list, pull, update, block, delete) and friend requests (apply, agree, refuse) with incremental pull support for offline sync. Group management includes creating, updating, dissolving, inviting, kicking, transferring ownership, pinning/unpinning messages, and muting members or the entire group. A new face pack system allows listing enabled packs with items and managing personal custom emoji (create/delete). Additionally, a new endpoint allows clients to incrementally pull conversation read positions for reconnection and offline compensation.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/controller · high confidence
New admin endpoints for code generation and Redis monitoring
The Infra module now exposes two new administrative capabilities. First, the Codegen Controller provides a complete API for managing code generation configurations, including listing database tables, creating and updating table/column definitions, previewing and downloading generated code, and deleting single or multiple table definitions. Second, a new Redis Controller allows administrators to retrieve real-time Redis monitoring information, including server info, database size, and command statistics.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/codegen · high confidence
New admin statistics endpoints for members, products, trade, and payments
The statistics module now exposes dedicated admin API controllers for member, product, trade, and payment analytics. Administrators can retrieve member summaries and analyses (including user counts, visit data, and regional/sex/terminal breakdowns), view product performance metrics (such as browse and conversion rates) with Excel export, and access trade summaries and order trends (including pending shipments and refunds) with Excel export. A new payment controller provides wallet recharge summaries. These endpoints are supported by new request/response value objects and MapStruct converters to structure the statistical data.
yudao-module-mall/yudao-module-statistics · high confidence
New app-side file upload and presigned URL endpoints
The application now exposes a new \AppFileController\ under \/infra/file\ for client apps, adding endpoints to upload files directly (\/upload\), retrieve presigned URLs for external storage providers like OSS or Qiniu (\/presigned-url\), and register uploaded files (\/create\). This introduces a dedicated request VO with directory validation, enabling users to manage file storage via the app interface.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/app · high confidence
New channel, group, and private message service interfaces and implementations
The IM module now exposes dedicated service interfaces and implementations for managing channel, group, and private messages. These services provide the core capabilities for sending, pulling, marking as read, and recalling messages across all three conversation types, along with administrative endpoints for querying and deleting messages. The implementation includes idempotency checks for sending, sensitive word validation, read-position tracking, and WebSocket-based real-time notifications.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/message · high confidence
New code generation engine and builder for UniApp and Vben5 templates
The code generation module now uses a new internal engine (CodegenEngine) and builder (CodegenBuilder) to generate code. This introduces support for new frontend templates, specifically UniApp (Wot) for mobile admin interfaces and Vben5 (Element Plus and Ant Design Schema) for modern Vue 3 admin panels. The builder also refines default mappings for column operations and UI types, and handles comment sanitization to prevent code generation errors.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/codegen/inner · high confidence
New code generation service interface and implementation
The Infra module introduces a new \CodegenService\ interface and its \CodegenServiceImpl\ implementation to manage code generation definitions. This service enables users to create, update, synchronize, and delete code generation table and column definitions from the database, as well as execute the code generation process to produce source code files.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/codegen · high confidence
New common API interfaces for cross-module communication
The yudao-common module now exposes a set of new API interfaces under the \cn.iocoder.yudao.framework.common.biz\ package to facilitate communication between framework starters and business modules. These include \ApiAccessLogCommonApi\ and \ApiErrorLogCommonApi\ for asynchronous logging, \OperateLogCommonApi\ for operation logs, \DictDataCommonApi\ for dictionary data, \OAuth2TokenCommonApi\ for token management, \PermissionCommonApi\ for user permissions, and \TenantCommonApi\ for multi-tenant validation. Corresponding DTOs (e.g., \ApiAccessLogCreateReqDTO\, \OAuth2AccessTokenRespDTO\) are also added to define the data contracts for these interactions.
yudao-framework/yudao-common · high confidence
New conditional query wrapper classes with database-specific LIMIT support
The MyBatis starter introduces three new query wrapper classes—LambdaQueryWrapperX, MPJLambdaWrapperX, and QueryWrapperX—that extend MyBatis Plus wrappers with 'IfPresent' methods (such as likeIfPresent, inIfPresent, and betweenIfPresent) to automatically omit query conditions when values are null or empty. Additionally, QueryWrapperX adds a limitN method that adapts the LIMIT clause syntax for different databases, using ROWNUM for Oracle, TOP for SQL Server, and standard LIMIT for MySQL, PostgreSQL, and others.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/core/query · high confidence
New data masking annotations and API access logging
The web starter now includes a comprehensive data masking system, allowing developers to annotate fields with annotations like @MobileDesensitize, @IdCardDesensitize, and @EmailDesensitize to automatically mask sensitive data in JSON responses. These annotations support Spring EL expressions to conditionally disable masking based on user permissions. Additionally, the framework introduces a new API access logging system, configurable via the \yudao.access-log.enable\ property, which records request details, response times, and operation types, with the ability to mask sensitive parameters using the \@ApiAccessLog\ annotation.
yudao-framework/yudao-spring-boot-starter-web · high confidence
New data models for group management, membership, and join requests
The IM module introduces three new data objects to support advanced group features: ImGroupDO now includes fields for group-wide mute (mutedAll) and pinned messages (pinnedMessageIds); ImGroupMemberDO adds support for member roles (role), silent mode (silent), and individual mute expiration (muteEndTime); and ImGroupRequestDO is added to track join requests with approval workflows, including fields for application content, handling results, and inviter information.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/dataobject/group · high confidence
New data source configuration management API
The infrastructure module now exposes a new REST API for managing database connection configurations via the \/infra/data-source-config\ endpoint. Administrators can create, update, retrieve, and list data source configurations, as well as delete single or multiple entries in bulk. The API requires specific permissions (e.g., \infra:data-source-config:create\) and handles request/response validation for connection details such as name, URL, username, and password.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/db · high confidence
New database source configuration and file management services
The infra module introduces new service interfaces and implementations for managing database source configurations (DataSourceConfigService) and file storage configurations (FileConfigService). The database source service allows creating, updating, and deleting dynamic data sources, including a special 'master' configuration, and querying table metadata using MyBatis Plus Generator. The file service adds capabilities to manage multiple file storage configurations (e.g., S3, local), test connectivity, and handle file uploads with configurable path strategies (date-based prefixes, timestamp suffixes).
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file · high confidence
New demo category management endpoints and Excel export
Added a new demo controller and associated request/response objects under the infra module's demo02 package, exposing REST endpoints for creating, updating, deleting, querying, and listing example categories. The controller includes an export feature that generates an Excel file using the framework's ExcelUtils, with response objects annotated for Excel property mapping.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/demo/demo02 · high confidence
New demo contact controller with batch delete support
A new Demo01ContactController has been added to the infrastructure module's demo area, providing standard CRUD endpoints (create, update, get, page) along with a new batch delete endpoint (/delete-list) for managing example contacts. This controller also includes an Excel export feature and is secured with specific permission checks for each operation.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/demo/demo01 · high confidence
New demo controller for inner master-detail student management
A new REST controller and associated request/response value objects have been added for the 'inner' master-detail demo scenario (Demo03StudentInnerController). This exposes standard CRUD endpoints for students, including a new batch-delete capability, pagination, Excel export, and specific endpoints to retrieve associated child records (courses and grades) by student ID, enabling administrators to manage nested student data structures in the infrastructure module.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/demo/demo03/inner · high confidence
New department-based data permission rule with SQL parenthesis fix
The framework now includes a new \DeptDataPermissionRule\ implementation that automatically filters data by \dept\_id\ and optionally by \user\_id\ (for 'view self' scenarios) using OR conditions. This change also fixes a SQL syntax issue where the generated \IN\ clause for department IDs was missing required parentheses, ensuring correct query execution. A \DeptDataPermissionRuleCustomizer\ interface is provided to allow users to configure custom column mappings for these filters.
yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission/core/rule/dept · high confidence
New deploy.sh script for yudao-server deployment
A new shell script (deploy.sh) has been added to the script/shell directory to automate the deployment of the yudao-server application. This script handles the full deployment lifecycle including backing up the existing JAR, stopping the running service, transferring the new build artifact, starting the service with configured JVM options and profiles, and performing a health check against the /actuator/health/ endpoint to verify successful startup.
script/shell · high confidence
New file management API request/response models
The infra module now exposes a comprehensive set of Value Objects for the file management API, enabling administrators to paginate and filter file configurations and files, create and update file configurations, upload files with validated directory paths, and retrieve file details or pre-signed URLs for direct uploads.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/vo · high confidence
New friend and friend request management data access layer
The IM module introduces dedicated MyBatis-Plus mappers for managing friend relationships and friend requests, enabling efficient data retrieval and administrative oversight. ImFriendMapper provides methods to query individual friend links, list a user's friends, and perform incremental pulls using a cursor-based approach (update\_time + id) to support reliable synchronization without loading excessive history. It also supports filtering by status and includes a silent flag for managing notification preferences. ImFriendRequestMapper handles friend request records with similar incremental pull capabilities, allowing users to fetch requests where they are either the sender or recipient. It includes logic to handle request updates, such as reusing existing records by resetting their state to unhandled, and supports administrative paging with filters for request status and source.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/friend · high confidence
New friend request workflow and sensitive word management
The IM module introduces a formal friend request lifecycle, allowing users to apply for, approve, or reject friend connections via the new ImFriendRequestService, which handles optimistic locking, auto-accept toggles, and WebSocket notifications. The existing friend management capabilities are expanded to support silent re-adding of friends, updating single-side attributes (display name, silent mode, pinning), and deleting friends with an option to clear local chat history. Additionally, a new sensitive word management system is added, enabling administrators to maintain a blocklist that is enforced via a high-performance, tenant-aware trie-based cache for real-time text validation.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/friend · high confidence
New group management and membership services
The IM module introduces dedicated service interfaces and implementations for group administration and membership lifecycle. Group owners and administrators can now manage group settings (name, notice, avatar, join approval), handle join requests (approve/reject with audit trails), and control membership (invite, remove, transfer ownership, add/remove admins). The system enforces member count limits, validates friend relationships for initial group creation, and supports silent synchronization of member nickname changes. Join requests are handled via a new approval workflow that creates pending records when enabled, or allows direct entry when disabled, with appropriate WebSocket notifications pushed to relevant parties.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/group · high confidence
New infrastructure APIs for configuration, file storage, and WebSocket messaging
The infra module now exposes dedicated API interfaces and implementations to allow other modules to interact with system configuration, file services, and WebSocket communication. Developers can retrieve parameter values by key via the new ConfigApi, upload files and generate pre-signed URLs for access via FileApi, and send messages to specific users or sessions via WebSocketSenderApi. Additionally, API access and error logging are now exposed through ApiAccessLogApiImpl and ApiErrorLogApiImpl, enabling centralized logging of API interactions. A demo WebSocket listener is also included to illustrate single and broadcast messaging patterns.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/api · high confidence
New infrastructure data objects for codegen, file, job, and logging modules
The infra module now includes a comprehensive set of new data objects to support core infrastructure capabilities. Code generation is backed by CodegenTableDO and CodegenColumnDO, which store table and column metadata for the new batch-delete code generation feature. File management is supported by FileDO, FileContentDO, and FileConfigDO, with the latter handling multi-storage configurations (local, S3, FTP, SFTP, DB) and legacy compatibility. Scheduled tasks are defined by JobDO and JobLogDO, introducing retry counts, intervals, and monitoring timeouts. Finally, API observability is enhanced with ApiAccessLogDO and ApiErrorLogDO, which now capture detailed request/response parameters, trace IDs, and exception stack traces for debugging.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/dal/dataobject · high confidence
New job execution handler and invoker components
The Quartz job starter now includes a new \JobHandler\ interface for defining task logic and a \JobHandlerInvoker\ class that acts as the Quartz job entry point. The invoker manages the execution lifecycle, including logging start/end times, capturing results or exceptions, and handling retry logic with configurable intervals and counts before rethrowing failures.
yudao-framework/yudao-spring-boot-starter-job/src/main/java/cn/iocoder/yudao/framework/quartz/core/handler · high confidence
New message validation and quote handling utilities
Added ImMessageUtils to validate IM message content (text, images, voice, video, files, cards, merges, materials) and manage message quote fields. This includes enforcing length limits, URL safety checks, and parsing/appending/removing quote references in message payloads.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/util · high confidence
New parameter configuration and scheduled job management services in the infrastructure module
The infrastructure module now exposes service interfaces and implementations for managing system parameter configurations and scheduled jobs. Users can create, update, retrieve, and delete individual or multiple parameter configurations, with protection against deleting system-defined types. For scheduled jobs, users can create, update, start, stop, trigger, and delete jobs (including batch deletion), with automatic synchronization to the Quartz scheduler. Job logs can be queried and cleaned up based on age, with asynchronous updates for execution results.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/config, yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/job · high confidence
New process instance copy and task service interfaces introduced
The BPM module now includes new service interfaces and implementations for managing process instance copies (cc/copy-to) and task operations. The \BpmProcessInstanceCopyService\ allows administrators and automatic triggers to create, query, and delete process instance copies, recording details like the reason, activity, and involved users. The \BpmProcessInstanceService\ and \BpmTaskService\ interfaces define core capabilities for querying, creating, and managing process instances and tasks, including approval details, next node prediction, and task status filtering. These services form the backend foundation for features like process copying, detailed approval tracking, and enhanced task management within the workflow engine.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/service/task · high confidence
New product management APIs and admin controllers for brands, categories, and comments
This change introduces the product module's inter-module API contracts and the corresponding admin backend controllers. It adds \ProductCategoryApi\, \ProductCommentApi\, \ProductSkuApi\, and \ProductSpuApi\ interfaces (with implementations) to expose product data and operations to other services. On the admin side, it adds controllers for managing product brands, categories, comments (including creation, visibility toggling, and replies), and favorites, along with all necessary request/response value objects.
yudao-module-mall/yudao-module-product · high confidence
New public API and admin management interfaces for the payment module
The pay module now exposes a structured set of remote APIs and admin controllers for managing payment applications, channels, orders, refunds, transfers, and wallets. Developers can create and query pay orders, refunds, and transfers via dedicated API interfaces (e.g., PayOrderApi, PayRefundApi, PayTransferApi, PayWalletApi) with defined request/response DTOs, while admins can manage payment apps and channels through new REST endpoints under /pay/app and /pay/channel. Demo controllers are also provided to illustrate order creation, payment callbacks, and refund flows.
yudao-module-pay · high confidence
New rate limiter starter with multi-level key resolution
The \yudao-spring-boot-starter-protection\ module now includes a new rate limiter component backed by Redisson. Developers can apply the \@RateLimiter\ annotation to methods to enforce request limits, with built-in support for global, user, client IP, and server node scopes via dedicated key resolvers. An expression-based resolver is also provided for custom logic. The configuration automatically registers the necessary AOP aspects and Redis DAO beans, requiring only the \yudao-redis\ starter to be present.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/ratelimiter · high confidence
New security service interface and implementation for permission, role, and scope checks
The security starter now exposes a new \SecurityFrameworkService\ interface and its default implementation (\SecurityFrameworkServiceImpl\). This service centralizes authorization checks, allowing users to verify permissions, roles, and OAuth2 scopes via methods like \hasPermission\, \hasRole\, and \hasScope\. The implementation delegates permission and role checks to the \PermissionCommonApi\ while handling scope checks locally against the logged-in user's scopes. It also includes a bypass mechanism for cross-tenant access via \skipPermissionCheck()\ and ensures that checks fail securely if no user is logged in.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/security/core/service · high confidence
New service interfaces for querying API access and error logs
The infra module now exposes dedicated service interfaces (ApiAccessLogService and ApiErrorLogService) that provide methods to retrieve individual log entries and paginated lists. This enables admin clients, such as the uniapp, to directly query API access and error logs rather than relying solely on internal logging mechanisms.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/logger · high confidence
New utility for temporarily disabling data permissions
A new DataPermissionUtils class has been added to the data-permission starter, providing static methods (executeIgnore) to temporarily bypass data permission checks for specific code blocks. This allows developers to execute logic without applying the current tenant or user-based data filters, which is useful for administrative operations or system-level tasks that need to access all data regardless of standard permission rules.
yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission/core/util · high confidence
New workflow comment service interface and implementation
Added the BpmCommentService interface and its implementation to enable creating and retrieving comments for workflow instances. The service integrates with Flowable's TaskService to fetch comments by process instance ID and to add new comments linked to specific tasks, supporting both user-provided messages and templated comment types via BpmCommentTypeEnum.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/service/comment · high confidence
New yudao-server module with Docker support and graceful disabled-module handling
This change introduces the standalone yudao-server module, providing the main application entry point, a Dockerfile for containerized deployment (using Eclipse Temurin 8 JRE on port 48080), and environment-specific configuration files (local, dev). To improve the developer experience and startup speed, the server now includes a DefaultController that intercepts requests to disabled modules (such as BPM, Pay, Mall, AI, and IoT), returning a clear 'module disabled' error with documentation links instead of generic 404s. Additionally, a ProjectReactor utility is included to allow one-click renaming of the project's Maven coordinates and package structure.
yudao-server · high confidence
Oracle database schema and Quartz job scheduler scripts added
New SQL scripts for the Oracle database have been introduced, providing the full application schema (ruoyi-vue-pro.sql) and the Quartz job scheduler tables (quartz.sql). The application schema includes infrastructure tables for API access and error logging, as well as code generation metadata, with data types and storage configurations adapted for Oracle compatibility.
sql/oracle · high confidence
Persistent storage for RTC call records and participants
The system now persists Real-Time Communication (RTC) call history to the database, enabling the management console to query past calls. This change introduces two new data objects: \ImRtcCallDO\ for call-level details (such as status, media type, and timing) and \ImRtcParticipantDO\ for per-user participation records (including roles and join/leave times). These entities map to the \im\_rtc\_call\ and \im\_rtc\_participant\ tables, linking participants to calls via the \room\ identifier to support the new read-only query features for call lists and participant details.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/dataobject/rtc · high confidence
Promotion module exposes inter-module APIs and admin article management
The promotion module now provides a set of internal APIs for other modules to interact with its features, including bargain, combination (group-buying), coupon, discount, point, reward, and seckill activities. These APIs allow external modules to validate participation conditions, update stock, and retrieve activity details. Additionally, the module introduces admin controllers for managing promotional articles and their categories, enabling administrators to create, update, delete, and query articles and categories through the backend.
yudao-module-mall/yudao-module-promotion · high confidence
Real-time friend list updates on profile changes
The system now automatically notifies a user's friends when that user's profile information is updated. An asynchronous message consumer listens for profile update events and, after the transaction commits, pushes a FRIEND\_INFO\_UPDATED notification to all mutual friends via WebSocket, ensuring their friend lists reflect the latest changes without delay or stale data.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/mq · high confidence
Standardized Infra module error codes and code generation enums
The infra module now provides a centralized set of error codes (ErrorCodeConstants) for configuration, scheduled jobs, API error logs, file management, and code generation, ensuring consistent error reporting. Additionally, new enums have been introduced to configure the code generator, including support for Vue3/Vben5 front-end templates, VO/DO mode selection, and specific table structures like master-sub and ERP modes.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/enums · high confidence
Structured message models and unified read/receipt tracking
The IM module introduces dedicated data objects for channel, group, and private messages, standardizing how messages are stored and retrieved. Group and private messages now include explicit fields for message status and receipt status, enabling unified tracking of read positions and delivery receipts. Additionally, a set of structured content models (text, image, video, audio, file, location, face, card, material, merge, quote, and recall) is added to support rich message types and features like message quoting and card-style channel content.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/dataobject/message · high confidence
Support for custom TTL in Redis cache names
The framework now allows specifying custom expiration times for Redis caches directly within the cache name. By appending a TTL value and unit (e.g., '10m' for 10 minutes, '1h' for 1 hour, '5d' for 5 days, or '30s' for seconds) separated by a hash symbol (e.g., 'myCache\#10m'), users can override the default cache timeout on a per-cache basis without changing configuration files.
yudao-framework/yudao-spring-boot-starter-redis/src/main/java/cn/iocoder/yudao/framework/redis/core · high confidence
System module exposes cross-service APIs for core domain objects
The system module now provides a comprehensive set of remote APIs (interfaces and implementations) for other modules to consume, covering departments, posts, roles, permissions, dictionary data, OAuth2 tokens, SMS codes, SMS/mail/notify messaging, social logins, and login/operation logs. This enables other services to query and manage these system resources without direct database access.
yudao-module-system · high confidence
User-level idempotency support via new key resolver
The \Idempotent\ annotation now supports user-level idempotency through the new \UserIdempotentKeyResolver\. Developers can specify this resolver in the \keyResolver\ attribute to ensure that idempotency checks are scoped per user, preventing duplicate submissions from the same user while allowing concurrent requests from different users. The aspect handles key resolution, Redis-based locking, and optional key deletion on exception.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/idempotent/core/aop · high confidence
WMS module: initial release of inventory, home statistics, and item master data APIs
This change introduces the initial backend API surface for the WMS module. It adds controllers and request/response VOs for home page statistics (order summaries, trends, and inventory summaries), inventory management (current stock levels and detailed inventory history with price/amount tracking), and item master data (items, SKUs, categories, and brands) including CRUD operations and list queries. These endpoints provide the foundational data access for warehouse inventory tracking and product catalog management.
yudao-module-wms · high confidence
Behavioural changes
Added comprehensive geographic area data for region lookups
The \area.csv\ resource file has been added to the IP starter module, providing a structured dataset of countries and regions (including IDs, names, types, and parent IDs). This data enables the application to resolve area identifiers, such as fixing issues where specific administrative areas (like direct-controlled municipalities or Zhongshan) could not be correctly identified during address imports or lookups.
yudao-framework/yudao-spring-boot-starter-biz-ip/src/main/resources · high confidence
Added normal-mode student service with diff-based child-table updates
The infrastructure module now includes a new normal-mode implementation for the demo03 student entity, providing service interfaces and implementations for creating, updating, deleting, and paginating students, along with their associated course and grade child tables. A key behavioral improvement in the update logic for one-to-many child tables (courses) is the use of a diff-list strategy: instead of simple replace-all operations, the service calculates differences between old and new lists to perform targeted batch inserts, updates, and deletes, ensuring more efficient and accurate synchronization of related data.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/demo/demo03/normal · high confidence
Adopts MyBatis Plus MultiDataPermissionHandler for SQL-level data filtering
The data permission module now integrates directly with MyBatis Plus's MultiDataPermissionHandler to intercept and modify SQL statements before execution. This change replaces previous implementation approaches with a standardized plugin that dynamically appends permission conditions to queries based on configured DataPermissionRules, ensuring that users only retrieve data they are authorized to access while supporting multi-table permission logic.
yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission/core/db · high confidence
Async task context propagation and optional Quartz scheduling
The job starter now automatically propagates multi-tenant context to asynchronous tasks by injecting a TtlRunnable decorator into both ThreadPoolTaskExecutor and SimpleAsyncTaskExecutor instances. Additionally, Spring's built-in scheduling is enabled by default, while the Quartz scheduler is now optional; if the Quartz Scheduler bean is not present, the system logs an info message and continues with a null-safe SchedulerManager, allowing users to disable the heavier Quartz dependency to improve startup speed.
yudao-framework/yudao-spring-boot-starter-job/src/main/java/cn/iocoder/yudao/framework/quartz/config · high confidence
Async-safe security context propagation via TransmittableThreadLocal
The security context holder strategy now uses Alibaba's TransmittableThreadLocal instead of a standard ThreadLocal. This ensures that Spring Security context (such as authentication details) is correctly propagated to asynchronous execution threads (e.g., @Async), preventing context loss in multi-threaded scenarios.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/security/core/context · high confidence
Automatic ID strategy and Quartz configuration for supported databases
The framework now automatically configures MyBatis Plus ID generation strategies and Quartz job store delegates based on the primary database type. For databases like Oracle, PostgreSQL, Kingbase, DB2, and H2, the system sets the ID type to INPUT; for others like MySQL and DM, it defaults to AUTO. Additionally, it automatically sets the correct Quartz JDBC delegate class for PostgreSQL, Oracle, SQL Server, DM, and Kingbase to ensure compatibility. This logic is handled by a new \IdTypeEnvironmentPostProcessor\ and integrated into \YudaoMybatisAutoConfiguration\, which also registers specific key generators for databases requiring them when the ID type is set to INPUT.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/config · high confidence
Business trace aspect migrated to OpenTelemetry
The business tracing aspect (BizTraceAspect) and its utility class (TracerFrameworkUtils) now use OpenTelemetry APIs instead of the previous OpenTracing implementation. This change updates how business method traces are created, managed, and recorded, ensuring compatibility with the OpenTelemetry standard while preserving the existing @BizTrace annotation behavior for recording business operation spans and error details.
yudao-framework/yudao-spring-boot-starter-monitor/src/main/java/cn/iocoder/yudao/framework/tracer/core/aop · high confidence
Centralized IM configuration with read receipts and RTC controls
The IM module now uses a unified configuration class (ImProperties) to manage global settings, replacing scattered constants. Administrators can now explicitly toggle private and group read receipts via the new privateReadEnabled and groupReadEnabled flags, disabling read status tracking and UI elements when turned off. Additionally, real-time communication (RTC) settings are centralized, allowing control over LiveKit integration, token TTL, participant limits, and timeout thresholds for call ringing and zombie cleanup.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/framework/config · high confidence
Code generator configuration options for VO type, batch deletion, and Excel import
The code generator now exposes configurable properties via the \yudao.codegen\ prefix, allowing users to control the generated output structure. Specifically, you can now set the VO type mode (\voType\), toggle the generation of batch delete interfaces (\deleteBatchEnable\), and enable or disable Excel import interface generation (\importEnable\). These settings are managed through the new \CodegenProperties\ class and registered in \CodegenConfiguration\, giving developers finer control over the code generation behavior without modifying templates.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/framework/codegen · high confidence
Custom distributed lock failure handling and key constants
The protection starter now defines a custom lock failure strategy that throws a ServiceException when a distributed lock cannot be acquired, replacing the default behavior. Additionally, it introduces a constants interface for Lock4j Redis keys to standardize the key format used by the locking mechanism.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/lock4j/core · high confidence
Custom lock4j failure strategy loaded before default auto-configuration
The lock4j starter now registers a custom DefaultLockFailureStrategy bean via a new YudaoLock4jConfiguration that runs before LockAutoConfiguration. This ordering ensures the custom bean is available when the default auto-configuration's @ConditionalOnMissingBean check runs, preventing conflicts that could occur after package renaming or other customizations.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/lock4j/config · high confidence
Customized security error responses for unauthenticated and unauthorized access
The security starter now includes specific handler implementations for Spring Security exceptions. When a user attempts to access a resource without being logged in, the system returns a 401 UNAUTHORIZED response, enabling the frontend to redirect to the login page. When a logged-in user lacks the necessary permissions, the system returns a 403 FORBIDDEN response. Both handlers log the relevant security events and return standardized JSON error results instead of default browser error pages.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/security/core/handler · high confidence
Data permission annotation processing moved to biz component
The core data permission annotation processing logic, including the @DataPermission annotation, the AOP advisor/interceptor, and the context holder, has been relocated from the generic framework module to the new yudao-spring-boot-starter-biz-data-permission module. This change reorganizes the codebase structure to treat data permission as a distinct business component, while the underlying mechanism for intercepting methods and managing permission context remains functionally equivalent.
yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission, yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission/core/annotation, yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission/core/aop · high confidence
Druid monitoring now removes advertisement banners by default
The datasource auto-configuration now automatically registers a filter that removes advertisement banners from the Druid web monitoring interface (specifically the common.js file) when the stat-view-servlet is enabled. This ensures a cleaner user experience when accessing database monitoring dashboards without requiring manual configuration.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/datasource/config · high confidence
Extensible idempotent key resolution with user-level support
The idempotent protection starter now uses a pluggable key-resolver architecture instead of a single hardcoded strategy. A new IdempotentKeyResolver interface allows different implementations to define how the idempotent key is generated: the default resolver still uses a method-name plus arguments hash, a new ExpressionIdempotentKeyResolver enables Spring EL-based key construction from method parameters, and a new UserIdempotentKeyResolver incorporates the current login user ID and type into the key, enabling user-scoped idempotency. This gives users finer control over idempotent key generation and supports scenarios where keys must be unique per user.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/idempotent/core/keyresolver · high confidence
Flattened IM WebSocket notification API with unified envelope and typed payloads
The IM module now uses a single, flattened WebSocket notification envelope (ImNotificationWebSocketDTO) with a fixed type of "im-notification" to deliver all real-time updates. This envelope wraps specific, typed payload objects organized into sub-packages: message notifications (private, group, channel, read receipts, and read syncs), friend relationship events (add, delete, block/unblock, info updates, and request approvals/rejections), group management events (creation, dissolution, member changes, admin roles, mute/ban, info/notice updates, message pinning, and join requests), and RTC call signaling (start, end, participant connect/disconnect, and call status changes). For users, this change standardizes how the client receives and processes all IM state changes, ensuring consistent handling of chat messages, social graph updates, group administration, and voice/video call states through a single, predictable WebSocket message structure.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/websocket/notification · high confidence
Improved MyBatis utility functions for sorting and database detection
The MyBatis utility layer now provides more robust support for sorting and database identification. MyBatisUtils.addOrder has been updated to correctly handle LambdaQueryWrapper instances by appending ORDER BY clauses via the last() method, resolving previous compatibility issues. Additionally, JdbcUtils.getDbType now delegates to MyBatis-Plus for URL-based detection and uses the dynamic data source to determine the current database type, ensuring accurate cross-database operations such as the new cross-database find\_in\_set implementation.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/core/util · high confidence
Infrastructure module adopts MyBatis-Plus for data access layer
The data access layer for the infrastructure module has been migrated to use MyBatis-Plus. All mapper interfaces in this area now extend MyBatis-Plus base mappers (such as BaseMapperX or BaseMapper) and utilize its query wrapper classes (LambdaQueryWrapperX or LambdaQueryWrapper) for defining database operations. This change standardizes the persistence implementation across code generation, configuration, database source, file, job, and logging components within the module.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/dal/mysql · high confidence
Introduce MapStruct-based conversion classes for BPM models, definitions, tasks, and messages
The BPM module now uses MapStruct to convert internal Flowable entities (Model, ProcessDefinition, ProcessInstance, Task) and related data objects into API response VO classes. This standardizes how process model lists, definition pages, task lists, and message payloads are built, ensuring consistent field mapping (e.g., form/category names, user/dept details, suspension state, deployment time, BPMN XML, and task status/reason) across the admin API responses.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/convert · high confidence
Introduction of simplified LoginUser model with tenant and expiration support
The security starter now uses a streamlined LoginUser class that removes previously stored fields like username, password, roleIds, and deptId, relying instead on a flexible 'info' map for additional data such as nickname and department ID. This model introduces explicit support for multi-tenancy via a tenantId field and a visitTenantId for context switching, along with an expiresTime field to track token validity. It also includes a transient context map for temporary caching during request processing.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/security/core · high confidence
Migrate distributed tracing to OpenTelemetry and add metrics support
The tracer configuration now uses OpenTelemetry instead of the previous OpenTracing/SkyWalking implementations, automatically registering a Tracer bean, a BizTraceAspect for AOP tracing, and a TraceFilter to inject trace IDs into HTTP response headers. Additionally, a new YudaoMetricsAutoConfiguration is introduced to automatically add a common 'application' tag to all metrics when Micrometer is present, controlled by the yudao.metrics.enable property.
yudao-framework/yudao-spring-boot-starter-monitor/src/main/java/cn/iocoder/yudao/framework/tracer/config · high confidence
Migrate to Spring Boot 2.7 auto-configuration and add ID type auto-adaptation
The MyBatis starter now supports Spring Boot 2.7 by replacing the legacy spring.factories registration with the new AutoConfiguration.imports mechanism, registering data source, MyBatis, and data translation auto-configurations. Additionally, an EnvironmentPostProcessor is introduced to automatically adapt the ID generation strategy for Oracle and PostgreSQL databases at startup.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/resources · high confidence
Migrated to Spring Boot 2.7 auto-configuration mechanism
The framework's starter modules (data permission, job, monitor, and redis) now use the Spring Boot 2.7 standard \META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports\ file to register their auto-configuration classes. This change replaces previous registration methods to ensure compatibility with Spring Boot 2.7's updated auto-configuration loading process.
(repo-wide) · high confidence
Modular security configuration with customizable URL rules and configurable password complexity
The security starter now uses a new \AuthorizeRequestsCustomizer\ abstraction, allowing each Maven module to define its own URL security rules rather than relying on a single global configuration. The framework also introduces \SecurityProperties\ to allow customization of the password encoder's BCrypt complexity (iterations) and the list of URLs permitted without authentication. Additionally, the \TokenAuthenticationFilter\ is now managed exclusively by the Spring Security filter chain, preventing duplicate Servlet registration.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/security/config · high confidence
New GoView dashboard integration and JmReport security hardening
The report module now includes a new GoView integration, adding controllers, services, and database entities for managing GoView projects and executing SQL-based data queries. Additionally, the JmReport (JimuReport) integration has been updated to enforce stricter security: the JmReportTokenServiceImpl now explicitly grants specific drag-and-design permissions only to super-admins to address a reported vulnerability, and the SecurityConfiguration permits unauthenticated access to JmReport frontend assets while relying on the token service for API protection.
yudao-module-report · high confidence
New Redis-backed Idempotent DAO implementation
The idempotence starter now includes a dedicated Redis DAO (IdempotentRedisDAO) that manages idempotency keys using the format 'idempotent:{uuid}'. This component provides methods to atomically set keys if they do not already exist (with a specified timeout) and to delete them, forming the underlying storage layer for user-level idempotency checks.
yudao-framework/yudao-spring-boot-starter-protection/src/main/java/cn/iocoder/yudao/framework/idempotent/core/redis · high confidence
New file configuration management and improved URL decoding for file downloads
Administrators can now manage file storage configurations (create, update, delete, and test) via the new FileConfigController, enabling setup for various storage backends. Additionally, the file download endpoint now correctly decodes special characters (such as '+' and '%') in file paths, resolving issues where files with such characters in their names could not be retrieved.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file · high confidence
Operate logs are now recorded asynchronously via a dedicated service implementation
The framework now implements the \ILogRecordService\ interface in \LogRecordServiceImpl\ to handle operation logging. This change introduces asynchronous log recording by delegating to \OperateLogCommonApi.createOperateLogAsync\, which resolves previous issues where request context was lost during async operations. The service automatically enriches log entries with trace IDs, user details (ID, type), module information (type, subtype, business ID, action, extra data), and request metadata (method, URL, IP, user agent) before sending them asynchronously.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/operatelog/core/service · high confidence
Quartz scheduler integration now disabled by default
The job scheduling module now defaults to a disabled state to improve startup performance. When Quartz is not configured, attempting to add, update, delete, pause, resume, or trigger a job will throw a service exception indicating that the scheduler is disabled, rather than failing with a null reference or unexpected error. Users must explicitly enable the Quartz dependency to use the job scheduling features.
yudao-framework/yudao-spring-boot-starter-job/src/main/java/cn/iocoder/yudao/framework/quartz/core/scheduler · high confidence
RabbitMQ integration now uses Jackson2 JSON serialization
The RabbitMQ auto-configuration in the MQ starter has been updated to use Jackson2JsonMessageConverter for message serialization, replacing the previous default mechanism. This change ensures that messages sent and received via RabbitMQ are serialized as JSON using Jackson, which may affect compatibility with existing consumers or producers that relied on the prior serialization format.
yudao-framework/yudao-spring-boot-starter-mq/src/main/java/cn/iocoder/yudao/framework/mq/rabbitmq · high confidence
Redis cache configuration refactored with transaction awareness and scan-based eviction
The Redis starter now uses a new \YudaoCacheAutoConfiguration\ that configures the cache manager to use a single colon (\:\) as the key separator to prevent display issues in Redis Desktop Manager, and employs a \BatchStrategies.scan\ approach for cache eviction to improve performance on large datasets. Additionally, transaction awareness is enabled on the cache manager, ensuring that cache eviction and update operations are deferred until after a transaction commits, which prevents stale reads during concurrent access.
yudao-framework/yudao-spring-boot-starter-redis/src/main/java/cn/iocoder/yudao/framework/redis/config · high confidence
Refactored BPM task assignment and multi-instance behavior
The BPM framework's task assignment logic has been refactored to use a new strategy-based architecture. A new \BpmTaskCandidateInvoker\ and \BpmTaskCandidateStrategy\ interface replace previous expression-based approaches, allowing for more flexible and configurable task candidate calculation (e.g., by department, leader, or start user). Additionally, custom \BpmActivityBehaviorFactory\ and related behavior classes (\BpmUserTaskActivityBehavior\, \BpmParallelMultiInstanceBehavior\, \BpmSequentialMultiInstanceBehavior\) have been introduced to handle task assignment and multi-instance execution, improving compatibility with CallActivity and SubProcess scenarios and ensuring correct handling of tenant context and data permissions.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/framework · high confidence
Refactored IM message data access with dedicated mappers for channels, groups, and private chats
The message data access layer has been restructured into three distinct MyBatis mappers: ImChannelMessageMapper, ImGroupMessageMapper, and ImPrivateMessageMapper. This change replaces the previous monolithic approach with specialized queries for each message type, introducing cursor-based pagination (using minId/maxId) for efficient message history retrieval and offline sync. The mappers also implement specific logic for handling read receipts, such as querying pending receipts for group chats and updating receipt statuses for private messages, while providing admin management interfaces for paginated message queries.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/dal/mysql/message · high confidence
Refactored data permission configuration to use Spring Boot 3 AutoConfiguration
The data permission starter now uses Spring Boot's standard \@AutoConfiguration\ annotation instead of the legacy \@Configuration\ approach, improving compatibility with modern Spring Boot versions. The configuration is split into two focused classes: \YudaoDataPermissionAutoConfiguration\ handles the core MyBatis Plus interceptor setup and rule factory, while \YudaoDeptDataPermissionAutoConfiguration\ conditionally registers department-based permission rules only when specific security classes and customizers are present.
yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission/config · high confidence
Reorganization of framework starter modules
The project has restructured its internal components by splitting out the monitor, protection, and Redis starters into their own dedicated modules (yudao-spring-boot-starter-monitor, yudao-spring-boot-starter-protection, and yudao-spring-boot-starter-redis). This change introduces specific annotations and package documentation for business tracing via SkyWalking, idempotency handling, distributed locking via Lock4j, and Redis operations, reflecting a shift towards a more modular architecture where these capabilities are now distinct, reusable starters rather than monolithic blocks.
(repo-wide) · high confidence
Restructuring of MyBatis starter package organization
The yudao-spring-boot-starter-mybatis module has been reorganized to separate concerns into distinct packages: a new 'datasource' package for database connection pool configuration (utilizing Druid) and multi-datasource support, and a 'mybatis' package for MyBatis Plus integration. This change improves code modularity and clarity for developers using the framework.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/datasource, yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis · medium confidence
Security configuration for MCP Server endpoints
The AI module now includes a dedicated security configuration that automatically permits unauthenticated access to Model Context Protocol (MCP) Server endpoints. This ensures that SSE and Streamable HTTP endpoints defined in the Spring AI MCP server properties are accessible without requiring authentication, allowing external clients to interact with the AI services.
yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/framework/security · high confidence
Spring Boot 3 auto-configuration registration for protection features
The protection starter now registers its components via the Spring Boot 3 standard auto-configuration mechanism. A new \META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports\ file explicitly declares the configurations for idempotency, distributed locking, rate limiting, and API signature verification, ensuring these features are automatically enabled when the starter is on the classpath.
yudao-framework/yudao-spring-boot-starter-protection/src/main/resources · high confidence
Spring Boot 3 auto-configuration registration for security and operation logs
The security starter now registers its auto-configuration classes via the Spring Boot 3 standard mechanism. The new file META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports explicitly lists YudaoSecurityAutoConfiguration, YudaoWebSecurityConfigurerAdapter, and YudaoOperateLogConfiguration, ensuring these components are automatically applied when the starter is on the classpath.
yudao-framework/yudao-spring-boot-starter-security/src/main/resources · high confidence
Spring Boot Admin monitoring now requires authentication and supports iframe embedding
The Infra module now includes a dedicated Spring Boot Admin Server configuration that enforces login for all monitoring pages (except static assets and the login page itself), using an in-memory user store isolated from the main system users. To ensure the monitoring UI renders correctly when embedded in an iframe, the security headers have been updated to allow framing from the same origin (configurable via \spring.boot.admin.frame-ancestors\) and to permit necessary inline scripts and styles for the Vue-based frontend. Additionally, the Infra module's security configuration explicitly permits access to Actuator endpoints, Swagger documentation, and Druid monitoring without authentication.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/framework/monitor · high confidence
Standardized BPM error codes and added comment type dictionary constant
The BPM module now uses centralized constants for error handling and dictionary types. A new \ErrorCodeConstants\ interface defines specific error codes for workflow models, definitions, instances, tasks (including withdrawal and delegation), forms, user groups, categories, and listeners, ensuring consistent error messaging. Additionally, a \DictTypeConstants\ interface was introduced to define the dictionary type for process comments (\bpm\_comment\_type\), supporting the new comment functionality.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/enums · high confidence
Standardized IM message status and receipt enums
The IM module now uses dedicated enums to manage message lifecycle and delivery confirmation. ImMessageStatusEnum defines message states including sending, normal, and recalled, while ImMessageReceiptStatusEnum introduces a model for receipt tracking with states for no receipt required, pending, and completed. This change provides a unified and explicit way to handle message status and read receipts within the system.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/enums/message · high confidence
Unified asynchronous WebSocket notification service for IM module
The IM module now uses a dedicated \ImWebSocketService\ to handle all WebSocket push notifications. This service ensures that notifications are sent asynchronously only after the associated database transaction has committed, preventing clients from receiving updates before the data is persisted. It supports sending notifications to specific users, broadcasting to all online admin users, and batching multiple recipients in a single call.
yudao-module-im/src/main/java/cn/iocoder/yudao/module/im/service/websocket · high confidence
Unified database type enum with native FIND\_IN\_SET support
The framework introduces a new \DbTypeEnum\ that consolidates previous database type definitions and adds support for OceanBase. This enum provides database-specific SQL templates for the \FIND\_IN\_SET\ operation, enabling compatible list-searching behavior across MySQL, Oracle, PostgreSQL, SQL Server, H2, DM, KingbaseES, and OceanBase without requiring application-level code changes.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/core/enums · high confidence
Unified file storage client framework with S3 region support and improved reliability
The infrastructure module now uses a unified file client architecture (AbstractFileClient with a factory pattern) supporting local, database, FTP, SFTP, and S3 storage backends. For S3, a configurable region is now supported (with a fallback to endpoint-derived region and then us-east-1), and presigned URLs correctly decode paths to handle special characters (including Chinese filenames and plus signs). Local file reads return null instead of throwing an exception when a file is missing, and path validation is strengthened to prevent directory traversal. Additionally, file responses use inline disposition for images to improve mobile playback compatibility.
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/framework/file · high confidence
Updated Spring Boot auto-configuration imports for MQ components
The auto-configuration registration file has been updated to explicitly import the Redis MQ producer and consumer configurations, as well as the RabbitMQ configuration. This change aligns the starter's auto-configuration mechanism with Spring Boot 2.7+ standards and ensures that the RabbitMQ implementation is automatically wired when present, supporting the broader refactoring to allow multiple MQ backends.
yudao-framework/yudao-spring-boot-starter-mq/src/main/resources · high confidence
Updated Spring Boot auto-configuration registration for tenant starter
The tenant starter now registers its components using Spring Boot 2.7+ conventions. The legacy spring.factories file is replaced by a new AutoConfiguration.imports file that explicitly lists YudaoTenantAutoConfiguration, and a new spring.factories file registers TenantKafkaEnvironmentPostProcessor to handle Kafka-related environment configuration for multi-tenancy.
yudao-framework/yudao-spring-boot-starter-biz-tenant/src/main/resources · high confidence
Fixes
Fix for missing audit fields in asynchronous database operations
The DefaultDBFieldHandler now correctly populates creator, updater, createTime, and updateTime fields even when database operations occur in asynchronous contexts. Previously, the handler failed to retrieve the current login user ID in async scenarios, resulting in empty audit fields; this change ensures that SecurityFrameworkUtils.getLoginUserId() is called at the point of field population, guaranteeing accurate user attribution for both insert and update operations.
yudao-framework/yudao-spring-boot-starter-mybatis/src/main/java/cn/iocoder/yudao/framework/mybatis/core/handler · high confidence
Fix: Prevent infinite expiration for BPM process ID keys without infix prefix
The BPM module's Redis DAO for generating process IDs now correctly handles cache expiration when no infix (date/time prefix) is configured. Previously, keys generated without an infix prefix were set to expire after 1 day, causing the sequence counter to reset daily. The fix ensures that when no infix is present, the expiration is not set (or handled appropriately to persist), preventing the sequence from restarting and ensuring continuous, unique process ID generation.
yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/dal/redis · high confidence
Fixes data permission interference with easy-trans data reading
The data permission module now explicitly bypasses permission filtering when calls originate from the easy-trans library (SimpleTransService). This prevents the data permission rules from incorrectly blocking or altering data reads performed during the translation process, resolving issues where data could not be read due to permission checks.
yudao-framework/yudao-spring-boot-starter-biz-data-permission/src/main/java/cn/iocoder/yudao/framework/datapermission/core/rule · high confidence
Rename of operation log configuration class
The operation log configuration class has been renamed from YudaoOperateLogV2Configuration to YudaoOperateLogConfiguration. This change updates the class name to reflect the removal of the 'V2' suffix, while maintaining the same functionality for configuring the log record service.
yudao-framework/yudao-spring-boot-starter-security/src/main/java/cn/iocoder/yudao/framework/operatelog/config · high confidence
Test coverage
Added base test classes for unit testing; Added disabled integration tests for FTP and SFTP file clients; Added integration test for AiBoChaWebSearchClient; Added integration tests for AI image generation models; Added integration tests for DouBao MCP model tool usage; Added integration tests for Suno music and WenDuoDuo/XunFei PPT APIs; Added integration tests for multiple AI chat models; Added test configurations for embedded Redis and SQL initialization; Added test resources for code generation assertions; Added unit and integration tests for S3 file client; Added unit test for file attachment filename encoding; Added unit test infrastructure for the IM module; Added unit tests for API signature verification; Added unit tests for AreaUtils and IPUtils; Added unit tests for BPM task candidate assignment strategies; Added unit tests for DataPermissionRuleHandler SQL modification; Added unit tests for DataPermissionUtils; Added unit tests for DictFrameworkUtils; Added unit tests for Excel multi-value dictionary conversion and row-limit reading; Added unit tests for IM module mappers and services; Added unit tests for LocalFileClient; Added unit tests for MyBatis query wrappers and pagination utilities; Added unit tests for code generation engines and services; Added unit tests for data permission core components; New test utility classes for assertion and random data generation.
Dependencies
Initial project scaffolding with JDK 8 and Spring Boot 2.7.18
The project is initialized as a multi-module Maven structure (yudao) with a dedicated BOM (yudao-dependencies) for centralized version management. The baseline runtime is set to JDK 8 and Spring Boot 2.7.18, with the framework layer (yudao-framework) providing core starters for MyBatis, Redis, Web, Security, and business capabilities like multi-tenancy and data permissions. Key dependency choices include Flowable 6.8.0 for workflows, Knife4j 4.5.0 for API documentation, and FastExcel 1.3.0 for Excel processing, while explicitly excluding older libraries like Activiti and Guice to maintain a clean, modern stack.
(dependencies) · high confidence
Housekeeping
Added package-info.java documentation for the operatelog module; Initial project scaffolding and documentation; MQ starter package documentation update.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 34 → 37 (+3.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 92 → 94 (+2.4)
- Architecture 97 → 94 (-3.0)
- Maturity 64 → 65 (+0.8)
- Readiness 12 → 21 (+8.8)
- Security 48 → 45 (-2.8)
- Accessibility 40 → 40 (+0.0)
Resolved (262)
- Boundary-crossing change coupling: BrokerageWithdrawServiceImpl.java ↔ PayTransferUnifiedReqDTO.java (yudao-module-mall/yudao-module-trade/src/main/java/cn/iocoder/yudao/module/trade/service/brokerage/BrokerageWithdrawServiceImpl.java)
- Change coupling: FileApi.java ↔ FileService.java (yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/api/file/FileApi.java)
- Change coupling: ProductCommentRespVO.java ↔ ProductCommentConvert.java (yudao-module-mall/yudao-module-product/src/main/java/cn/iocoder/yudao/module/product/controller/admin/comment/vo/ProductCommentRespVO.java)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/mindmap/AiMindMapServiceImpl.java)
- Duplicated block (10 lines × 2) (yudao-module-bpm/src/main/java/cn/iocoder/yudao/module/bpm/framework/flowable/core/candidate/BpmTaskCandidateInvoker.java)
- Duplicated block (10 lines × 2) (yudao-module-crm/src/main/java/cn/iocoder/yudao/module/crm/framework/operatelog/core/SysAdminUserParseFunction.java)
- Duplicated block (10 lines × 2) (yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/dal/dataobject/file/FileConfigDO.java)
- Duplicated block (10 lines × 2) (yudao-module-iot/yudao-module-iot-gateway/src/main/java/cn/iocoder/yudao/module/iot/gateway/protocol/coap/handler/upstream/IotCoapRegisterHandler.java)
- Duplicated block (10 lines × 2) (yudao-module-iot/yudao-module-iot-gateway/src/main/java/cn/iocoder/yudao/module/iot/gateway/protocol/coap/handler/upstream/IotCoapRegisterSubHandler.java)
- Duplicated block (10 lines × 2) (yudao-module-iot/yudao-module-iot-gateway/src/main/java/cn/iocoder/yudao/module/iot/gateway/protocol/mqtt/IotMqttProtocol.java)
- Duplicated block (10 lines × 2) (yudao-module-mall/yudao-module-statistics/src/main/java/cn/iocoder/yudao/module/statistics/job/product/ProductStatisticsJob.java)
- Duplicated block (10 lines × 2) (yudao-module-mes/src/main/java/cn/iocoder/yudao/module/mes/service/wm/itemreceipt/MesWmItemReceiptLineServiceImpl.java)
- Duplicated block (10 lines × 2) (yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java)
- Duplicated block (10 lines × 2) (yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/service/transfer/PayTransferServiceImpl.java)
- Duplicated block (10 lines × 3) (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/dal/mysql/chat/AiChatMessageMapper.java)
- Duplicated block (10 lines × 3) (yudao-module-iot/yudao-module-iot-gateway/src/main/java/cn/iocoder/yudao/module/iot/gateway/protocol/tcp/handler/upstream/IotTcpUpstreamHandler.java)
- Duplicated block (10 lines × 3) (yudao-module-wms/src/main/java/cn/iocoder/yudao/module/wms/service/order/movement/WmsMovementOrderServiceImpl.java)
- Duplicated block (10 lines × 4) (yudao-module-iot/yudao-module-iot-gateway/src/main/java/cn/iocoder/yudao/module/iot/gateway/protocol/coap/handler/upstream/IotCoapAuthHandler.java)
- …and 242 more
New (2692)
- BannerApplicationRunner.run (cognitive 16) (yudao-framework/yudao-spring-boot-starter-web/src/main/java/cn/iocoder/yudao/framework/banner/core/BannerApplicationRunner.java)
- BannerApplicationRunner.run (cyclomatic 17) (yudao-framework/yudao-spring-boot-starter-web/src/main/java/cn/iocoder/yudao/framework/banner/core/BannerApplicationRunner.java)
- Change coupling clique: CrmContactPageReqVO.java, CrmContactSaveReqVO.java, CrmContactDO.java (yudao-module-crm/src/main/java/cn/iocoder/yudao/module/crm/controller/admin/contact/vo/CrmContactPageReqVO.java)
- Change coupling clique: IotProductRespVO.java, IotProductSaveReqVO.java, IotProductDO.java (yudao-module-iot/yudao-module-iot-biz/src/main/java/cn/iocoder/yudao/module/iot/controller/admin/product/vo/product/IotProductRespVO.java)
- Change coupling clique: KeFuMessageController.java, AppKeFuMessageController.java, KeFuConversationServiceImpl.java, KeFuMessageServiceImpl.java (yudao-module-mall/yudao-module-promotion/src/main/java/cn/iocoder/yudao/module/promotion/controller/admin/kefu/KeFuMessageController.java)
- Change coupling: AfterSaleController.java ↔ AfterSaleServiceImpl.java (yudao-module-mall/yudao-module-trade/src/main/java/cn/iocoder/yudao/module/trade/controller/admin/aftersale/AfterSaleController.java)
- Change coupling: AiChatMessageRespVO.java ↔ AiChatMessageDO.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/controller/admin/chat/vo/message/AiChatMessageRespVO.java)
- Change coupling: AiImageController.java ↔ AiImageMapper.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/controller/admin/image/AiImageController.java)
- Change coupling: AiImageController.java ↔ AiImageServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/controller/admin/image/AiImageController.java)
- Change coupling: AiImageMapper.java ↔ AiImageService.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/dal/mysql/image/AiImageMapper.java)
- Change coupling: AiImageRespVO.java ↔ AiImageServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/controller/admin/image/vo/AiImageRespVO.java)
- Change coupling: AiKnowledgeDocumentServiceImpl.java ↔ AiKnowledgeSegmentServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/knowledge/AiKnowledgeDocumentServiceImpl.java)
- Change coupling: AiKnowledgeDocumentServiceImpl.java ↔ AiKnowledgeServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/knowledge/AiKnowledgeDocumentServiceImpl.java)
- Change coupling: AiMindMapServiceImpl.java ↔ AiWriteServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/service/mindmap/AiMindMapServiceImpl.java)
- Change coupling: AiModelFactory.java ↔ AiApiKeyService.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/framework/ai/core/model/AiModelFactory.java)
- Change coupling: AiModelFactory.java ↔ AiApiKeyServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/framework/ai/core/model/AiModelFactory.java)
- Change coupling: AiModelFactoryImpl.java ↔ AiApiKeyService.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/framework/ai/core/model/AiModelFactoryImpl.java)
- Change coupling: AiModelFactoryImpl.java ↔ AiApiKeyServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/framework/ai/core/model/AiModelFactoryImpl.java)
- Change coupling: AiMusicController.java ↔ AiMusicServiceImpl.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/controller/admin/music/AiMusicController.java)
- Change coupling: AiMusicDO.java ↔ SunoApi.java (yudao-module-ai/src/main/java/cn/iocoder/yudao/module/ai/dal/dataobject/music/AiMusicDO.java)
- …and 2672 more
Changes since last survey
- 66 commits — 43 feature/other, 23 fixes
By area
- (repo) — 21 commits
- yudao-module-pay/src — 7 commits
- (root) — 5 commits
- yudao-framework/yudao-spring-boot-starter-web — 4 commits
- .image/common — 3 commits
- yudao-module-hrm/src — 3 commits
- yudao-module-system/src — 3 commits
- yudao-dependencies/pom.xml — 2 commits
- yudao-framework/yudao-spring-boot-starter-mybatis — 2 commits
- yudao-module-bpm/src — 2 commits
- yudao-module-fms/src — 2 commits
- yudao-module-infra/src — 2 commits
- yudao-module-mes/src — 2 commits
- yudao-module-oa/src — 2 commits
- yudao-module-pms/src — 2 commits
- sql/mysql — 1 commit
- yudao-framework/yudao-common — 1 commit
- yudao-framework/yudao-spring-boot-starter-security — 1 commit
- yudao-module-iot/yudao-module-iot-biz — 1 commit
Notable commits
- fix: !1590 fix: 移除匿名访问创建文件
- fix: Merge pull request #1187 from nemisolv/fix/web-properties-validation
- fix: Merge pull request #1203 from RecursiveVar/fix/money-utils-percent-division
- fix: Merge pull request #1204 from RecursiveVar/fix/mail-template-render
- fix: fix(bpm): 使用流程变量发起人 ID计算部门负责人
- fix: fix(infra): use provider endpoint for OSS presign
- fix: fix(iot): 修正设备消息发送权限标识
- fix: fix(mes): 修复排班计划倒班字段联动清理及生成排班异常
- fix: fix(mes): 修复排班计划倒班字段联动清理及生成排班异常
- fix: fix(pay): 修复微信支付证书临时文件失效问题
- fix: fix(基础设施): 修复 MoneyUtils.calculator 整数除法把折扣分截断的问题(60.2% 变 60%)
- fix: fix(邮件): 修复代码块含 $ 或 \ 时 appendReplacement 抛 Illegal group reference 的问题,并补充单测
- fix: fix: cascade validation for web properties
- fix: fix: cascade validation for web properties
- fix: fix: 修复支付宝支付回调渠道用户 ID 获取问题 (!266)
- fix: fix: 修复支付宝支付回调渠道用户 ID 获取问题 (!266)
- fix: fix: 对齐 PR1187 与 PR1204 修复
- fix: fix: 移除匿名访问创建文件
- fix: fix(fms):单测报错
- fix: fix(security):禁用 TokenAuthenticationFilter 的 Servlet 全局注册
- …and 46 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
YunaiV/ruoyi-vue-pro was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 8e80602b875f69158faf4c92445e67691821bf0f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-ae95d6cad036.