Changelog

New features, fixes and improvements in each PAM release · View on GitHub

v2.12.0Current

Minor Changes

✨ Features

  • pam: 个人中心支持修改密码 (829e8f7) (#164)

    • 新增 POST /api/user/password:校验当前密码后通过 Supabase 管理接口设置新密码,当前登录保持不变
    • 密码前端加密传输,服务端解密并校验 6-50 位、无空格、不得与当前密码相同
    • 抽出 resolveSupabaseLoginPassword,登录与改密共用 SUPABASE_LOGIN_PASSWORD_MD5 规则
    • 个人中心新增修改密码卡片(已绑定邮箱时显示),输入时实时校验
  • pam: 信任此应用按设备持久化并自动跳过授权页 (aaa9ed6) (#163)

    • 新增 pam_oauth_consent_grants(用户 + 应用 + 设备,90 天过期)及 patch
    • 同意并勾选信任时写入 httpOnly 设备 cookie 与信任记录
    • 授权页命中有效信任且 scope 被覆盖时直接签发 code 跳回应用
    • 写入/更新信任失败只记日志,不阻断授权

🐞 Bug Fixes

  • pam: 修复授权页手机端按钮遮挡并展示当前授权账号 (8629ed1) (#163)
    • 手机端按钮纵向铺满且同意在上,去掉列布局下的 flex-1
    • 卡片顶部显示当前授权账号,支持切换账号后回到本次授权
    • 信任文案改为按设备、90 天有效

📝 Documentation

  • pamenv: 重构 README,PAM CLI 文档页直接渲染 README (04261a7) (#165)
    • README / README_EN 按使用场景重写:快速开始、命令一览、全局参数、环境与文件、init / fork / pull / push / remove、配置与语言、权限
    • 去掉本地状态文件路径、文件权限、token 实现、文案生成流程、monorepo 构建等与使用无关的内容
    • /docs/cli 页面改为构建时读取 pamenv README(zh → README.md,其余 → README_EN.md),用 react-markdown + remark-gfm 渲染,文档只维护一份
v2.11.0

Minor Changes

✨ Features

  • pam: MemoryKvCacheService 支持列出与计数 (3128e0c) (#161)

    供后台巡检进程内缓存;过期 key 在列举时清理。

  • pam: 后台增加 Memory KV 管理,仅管理员可见 (cb92340) (#161)

    侧栏与 API 走 admin_memory_kv_read/write;支持筛选、删除与清空。已有库需执行 patch-admin-memory-kv.sql。

  • pam: 站点 CORS 规则编辑与 ApiCorsPlugin (942dce0) (#157)

    支持 api.cors_rules 站点配置;OAuth/logout 改走 ApiCorsPlugin, OPTIONS 可走 MemoryKv 缓存;next-kit 升至 1.5.0。

  • pam: 项目卡片封面图可跳转详情 (a691f9f) (#157)

    封面优先走 primaryUrl,否则落到项目详情页。

🐞 Bug Fixes

  • pam: 禁止在 admin client 上 refreshSession (581a3e5) (#159)

    缓存的 service_role client 若被 refreshSession 写入用户 JWT, 随后 PostgREST 会按用户身份走 RLS(pam_roles 读成空)。 改用 ephemeral anon client 做会话刷新,并加固角色 map 缓存。

  • pam,pamenv: device 登录页 i18n 与 verification URI locale (2220913) (#157)

    设备授权页接入 PageI18n;createDeviceCode 带 locale,verification_uri 加语言前缀。

  • pam: CORS 规则编辑铺满宽度 (12c1211) (#157)

    规则编辑不再锁在窄列;「添加规则」移到卡片底栏、紧挨保存按钮。

♻️ Refactors

  • pam: 合并 SQL 为 000 全量脚本并统一 pam_ 表前缀 (04b5b58) (#159)
    • 001–023 合并为 000-pam-full-schema.sql(dev 可重复执行)
    • 审计/OAuth/CLI:pamrequest_logs、pam_oauth*、pam_cli_tokens
    • 代码经 PamTables 引用表名;README / .env.template 同步

🚀 Performance

  • pam: 加速 OAuth 机器端点 (7511da3) (#157)

    Auth refresh/getUser 走缓存 admin client,避免每请求 TLS 重握手;OPTIONS CORS 未命中缓存时回退 env,不再建 IOC;userinfo 先读档案,无字段变化则跳过 UPDATE。

v2.10.1

Patch Changes

♻️ Refactors

  • pam: 面板按 failed 状态展示错误,对齐新 runAsyncStore (6092407) (#155)

    用 store.isSuccess() 判断后续逻辑;渲染层 status === 'failed' 映射 i18n;更新 async-store 文档。

v2.10.0

Minor Changes

✨ Features

  • pam: locales/json 支持 namespaces,并加速词典加载 (b7e6fbb) (#151)

    loadMessages 以静态 JSON 为底合并 API;DB 覆盖改为精简列查询并用 MemoryKvCacheService 缓存。

  • pam: 新增 Locales CMS 后台管理 (6331240) (#149)

    落地 pam_locales 表与 admin_locales 权限;实现仓储与单语 CRUD/导入; 开启 useApiLocales(静态底稿+DB 覆盖);命名空间改为精确下拉筛选。

🐞 Bug Fixes

  • react-kit: useStore 改 ReadableStore,并迁出 next-kit 引用 (8e100de) (#153)

    避免与 pam 双份 corekit-bridge 类型冲突;corekit 相关改为 peer。 pam / brain-oauth 的 useStore 统一从 @brain-toolkit/react-kit 导入。

  • pam: locales 语言判断改用 i18nConfig.supportedLngs (f14fc10) (#151)

    去掉 en/zh 硬编码,统一以 supportedLngs 校验与拼装查询列。

♻️ Refactors

  • react-kit: 迁入 useAsyncStore 并用 next-kit 风格重写 useStore (116fdad) (#153)

    将 pam 面板本地 hook 提升到 @brain-toolkit/react-kit;useStore 改为 useSyncExternalStore + StoreInterface;pam 改为 workspace 依赖并 transpile。

  • pam: 引入 useAsyncStore 约定并迁移 Admin/Teams 面板 (715bee3) (#152)

    新增 [state, store] / usePendingAsyncStore / runAsyncStore;Admin 面板与 Teams、项目详情改用 AsyncStore 生命周期,去掉手写 loading/error。

    lint:fix 后稳定 list.result ?? [] 的 useMemo 依赖。

  • pam: PostgREST 统一 throwOnError,并由 handler 收口错误 (09c463c) (#150)

    默认用 .throwOnError();Auth/可恢复路径仍 throwIfError。 NextApiHandler 将原生错误映射为 api:server__error,生产环境剥离诊断 data。

  • pam: 统一改回 throwIfError,避免与 Auth 双写法 (c3f840e) (#150)

    PostgREST 与 Auth 均 await 后 throwIfError;保留 handler 对原生错误的兜底与生产剥离诊断 data。

v2.9.0

Minor Changes

✨ Features

  • pam: 团队管理 UI 与项目仅拥有者转让/删除 (70eb90e) (#145)

    团队列表/详情、挂载解散;下线写作者;is_owner 按 owner_id。 基于已重建的 polish 分支,避免 squash 后 add/add 冲突。

  • pam: 角色权限核心(permission_key 与后台角色) (ecf96f2) (#143)

    含 session、RequirePermissionPlugin、角色 SQL 种子与后台角色/权限目录。

  • pam: 持久化语言偏好并支持 OAuth ui_locales (fcc2488) (#140)

    NEXT_LOCALE 一年有效;authorize 识别 ui_locales/locale 并落到 /{locale};匹配 supportedLngs。

  • pam: 接入 next-kit 1.4,Session 邮箱可空并带 name/phone (f728dd6) (#139)

    升级 next-kit/oauth-wrapper;业务邮箱进 session,占位邮箱仅用于 mint 修复。

🐞 Bug Fixes

  • pam: 搜索按团队成员可见,修复 pamenv 解析私有项目 (9a9b437) (#147)

    新增 022 重写 pam_search_projects;legacy search 同步 team_id;CLI 文档对齐。

  • pam: Admin SPA 壳、Loading 与鉴权热路径打磨 (ce33db2) (#145)

    含 MemoryKv 缓存、AdminPagesAppShell,以及禁改自己系统角色。 基于已合入的角色核心(squash)重建,避免 add/add 冲突。

  • pam: PamTeamMembersRepo join 断言经 unknown 转换 (cbd10e2) (#145)

    重建 teams 时误用了未含该修复的快照,现补回。

  • pam: 补齐 teams adminTitle,SettingsCard children 可选 (1e5b0fc) (#145)

    AppRoutePage 需要 adminTitle;拥有者提示卡可不传 children。

  • pam: Admin SPA 壳、Loading 与鉴权热路径打磨 (ce33db2) (#144)

    含 MemoryKv 缓存、AdminPagesAppShell,以及禁改自己系统角色。 基于已合入的角色核心(squash)重建,避免 add/add 冲突。

  • pam: PamTeamMembersRepo join 断言经 unknown 转换 (2661597) (#143)

    Supabase 嵌套 select 将 pam_roles 推成数组类型,直接断言会报 TS 错。

  • pam: OAuth userinfo 用 display_name,不再返回手机占位邮箱 (1bf6f47) (#138)

    从 pam_users 组装出站 claims:name 优先 display_name,email 仅业务邮箱,可选 phone_number。

v2.8.0

Minor Changes

✨ Features

  • pam: 个人中心支持修改 display_name (4ad6c5b) (#136)

    新增 POST /api/user/display-name;前端即时校验(字母/数字/下划线), 成功后直接回写 session store,无需再拉 session。

  • pam: 邮箱可空并以 display_name 作为手机账号展示身份 (26080cc) (#135)

    手机登录不再写入 @phone.pam.local 到 pam_users;session 返回业务邮箱/手机/展示名。

  • pam: 支持绑定邮箱与已有邮箱账号合并 (2bb7aea) (#135)

    新增 bind-email send/verify API;新邮箱挂当前账号,已有邮箱验证后合并资源并迁移手机号。

  • pam: 新增个人中心页并以 display_name 优先展示身份 (5d8e24c) (#135)

    用户菜单进入 /account 绑定邮箱;Auth/Admin/协作者/转让选人统一展示规则;手机登录默认 +86;弹层 portal 到 body。

  • pam: 新增项目协作者表与访问角色契约 (0b620ae) (#132)

  • pam: 以角色权限改造项目访问并实现协作者 API (d5f2e67) (#132)

  • pam: 项目详情支持协作成员管理 UI (ce67f64) (#132)

  • pam: 新增 pam_phone_otps 表与手机验证码站点配置 (87e1024) (#131)

  • pam: 定义手机 OTP schema 与通道配置契约 (e0e68ed) (#131)

  • pam: 实现 memory 手机验证码发送校验并接入登录 (3a9fa47) (#131)

  • pam: 新增管理端验证码监控页与 API (ba5810d) (#131)

  • pam: 优化手机登录表单并支持 OTP 通道设置 (8adfeea) (#131)

  • pam: 实现阿里云短信 OTP 并从站点设置读取配置 (787a01a) (#131)

    DysmsAPI SendSms(RPC 签名);Admin「阿里云短信」分组配置密钥/签名/模板,无 ALIYUNSMS* 环境变量。

  • pam: public-config 暴露 OTP 通道并提示 memory 模式找管理员拿码 (6d37e2e) (#131)

    登录页按 phoneOtpProvider 展示提示;memory 不发短信,aliyun 不显示该提示。

  • pam: 新增 pam_users 表存储平台管理员与应用用户档案 (4568c62) (#130)

  • pam: 实现 PamUsersRepo 与 PamUserService 及 platform admin 缓存 (d0513f1) (#130)

  • pam: OAuth 登录时自动 ensure pam_users 档案 (f3c4995) (#130)

  • pam: 引入 PlatformAdminPlugin 并收紧 /admin 页面与 site-settings API (c76e2ed) (#130)

  • pam: Session 返回 platformAdmin 能力并接入客户端 capabilities store (c74516f) (#130)

  • pam: 新增管理端用户搜索与 platform admin 切换 API (8fd951a) (#130)

  • pam: 实现管理端用户列表与 platform admin 开关 UI (325fde0) (#130)

  • pam: Admin 入口与用户菜单仅对 platform admin 可见 (a777f62) (#130)

  • pam: 添加管理员路由并更新 AuthButtonUI 以使用 routerService (b3bbea9) (#130)

  • pam: 站点设置 DB、服务层与 Admin/Public API (b3933dc) (#129)

    • pam_site_settings 表与种子数据(无 updated_by / system.log_level)
    • SiteSettingsRepo/Service/Controller 与运行时缓存
    • /api/admin/site-settings、/api/public-config 及前端 API 封装

    Co-authored-by: Cursor cursoragent@cursor.com

  • pam: 运行时配置改读站点设置并统一 OPENAI 环境变量 (e46e130) (#129)

    Brain OAuth、CLI Token、预览图、OAuth CORS 等从 DB 站点设置读取;LOG_LEVEL 仍保留在 .env。

    Co-authored-by: Cursor cursoragent@cursor.com

  • pam: Admin 站点设置页与后台布局优化 (18297fc) (#129)

    站点设置管理 UI、侧栏抽屉/用户信息固定底栏、移动端适配与 i18n。

    Co-authored-by: Cursor cursoragent@cursor.com

🐞 Bug Fixes

  • pam: 头像菜单个人中心与管理后台改为链接跳转 (f4bd16b) (#136)

    使用 LocaleLink,并补齐必填 title,支持新开标签访问。

  • pam: 加固手机号 OAuth 换票的 provider credentials (c766636) (#134)

    无 cookie 签发 Supabase session,并在 consent 前补写 provider_session_token,避免第三方 SSO 换票失败。

  • pam: 手机号 OTP 登录写入 Supabase refresh 以支持 OAuth 换票 (ef54891) (#133)

    自定义手机号登录此前只写空 refresh 的 cookie,第三方 /oauth/token 因缺少 provider_session_token 失败;现改为 magiclink 换 session 并走 loginWithSession。

  • pam: 首页工具栏筛选面板移动端 Modal 与桌面 Portal 定位 (fdbfbde) (#130)

    移动端用 ResponsiveModal;桌面端 portal 固定定位并随滚动/resize 更新,避免被 overflow 裁剪。

  • pam: 登录页客户端拉 public-config 并移除 Playground 链接 (6d556eb) (#129)

    保持 SSG 壳子 + CSR 拉取登录开关;去掉需登录的 OAuth Playground 入口。

    Co-authored-by: Cursor cursoragent@cursor.com

  • pam: 站点设置保存后立即生效并修复布尔值解析 (ba6f460) (#129)

    public-config 禁用缓存;保存 auth 设置后清除客户端缓存;getBoolean 兼容 DB 字符串;保存成功提示。

  • pam: 修复 Admin 布局 type-check 报错 (a651a62) (#129)

    ComponentType/SVGProps 改从 react 导入;LocaleLink 补 title;users 页 AdminPageShell 补 children。

📝 Documentation

  • pam: 同步协作权限到 CLI 文档与 pamenv README (c12acd6) (#132)

    说明 owner/admin/member 对 pull/push/remove 的差异;Web /docs/cli 与中英文 README 对齐。

♻️ Refactors

  • pam: 请求日志 API 迁至 /api/admin/request-logs 并支持全量查询 (21475a0) (#130)
v2.7.0

Minor Changes

✨ Features

  • pam: pam_search_projects 支持按时间排序 (d13d790) (#126)

    新增 pamListSort 与 013 SQL,RPC 传入 sort_by/sort_order;统一首页 ISR 与 Facade 默认排序。

  • pam: 列表筛选面板、排序与更新时间展示 (e1e6a49) (#126)

    工具栏合并筛选/排序/视图切换;卡片与列表行展示 updated_at;补充中英文 i18n。

  • pam: 新增 pam_search_projects RPC 与列表索引 (bcdaaac) (#125)

    单次 RPC 拉取分页项目与环境摘要;未部署时回退 PostgREST 搜索。附带列表索引与 PostgREST 错误识别工具。

  • pam: 站点 Logo 代理 API 与列表头像 (1315134) (#125)

    新增 /api/pam/site-logo 二进制响应;列表头像经服务端抓取 favicon/logo,避免浏览器直连跨域。

  • pam: 封面预览图、转让项目 UI,并移除列表删除 (c6d6afb) (#124)

    General 增加转让与封面字段;卡片/列表展示封面;首页不再提供删除入口。

  • pam: 转让改为选人确认,封面改为截取入库可刷新 (cff9e71) (#124)

    转让打开弹层加载用户并搜索选择;封面从主环境 URL 截取后存 Supabase Storage,支持重新截取(可配 PAM_SCREENSHOT_URL_TEMPLATE)。

  • pam: 封面置顶,并优化转让选人与列表封面展示 (8c01538) (#124)

    General 封面移至首卡;转让用户搜索加缓存与 SQL 优化;卡片/列表 封面与头像展示完善,弹层与环境变量行交互小改。

  • pam: OTP 发送按 IP 限流 (637bf4a) (#123)

    邮箱/手机 OTP 发送前按客户端 IP 做 60s 冷却,避免刷验证码;附带单测。

  • pam: 优化邮箱 magic link 登录并关闭注册页 (1e69338) (#123)

    发送成功态、重发倒计时与文案补齐;/auth/register 重定向到登录。

🐞 Bug Fixes

  • pam: 列表分页越界 PGRST103 与 hasMore 校正 (00e8516) (#125)

    捕获 PostgREST 越界请求并返回空页;第 2 页起可选跳过 count;修正 planned count 导致的 hasMore 误判。

  • pam: 首页列表状态与转让选人体验 (592d46c) (#125)

    转让后重置列表;无限滚动去重与 total 校正;分类缓存;转让确认移入选人弹层。

  • pam: Brain/CLI 会话下统一 owner 鉴权,并支持转让与封面字段 (871c305) (#124)

    删除/更新/详情改为 assertProjectOwner + admin 读写,避免仅有 应用会话却无 Supabase cookie 时「能见按钮却无权限」。同步加入 preview_image_url 与 transfer API(邮箱经 pam_auth_user_id_by_email)。

  • pam: 未登录跳转登录页时保留当前语言 (de31a31) (#124)

    middleware redirectToPath、LocaleLink、/login 别名与 Brain OAuth 错误回跳不再落到默认英文;localePage 补齐语言前缀。

  • pam: AuthButton 登录链接改用 LocaleLink (9ad49b6) (#123)

    未登录跳转登录页时保留当前语言前缀。

📝 Documentation

  • pam: CLI 文档补充 pull/push --file 用法 (91ff907) (#127)

    Web /docs/cli 示例与 i18n 文案同步 pamenv --file 参数。

    Co-authored-by: Cursor cursoragent@cursor.com

♻️ Refactors

  • pam: 统一顶栏控件样式并增强 AuthButton (11ac31d) (#123)

    抽取 headerChrome;登录态展示邮箱/登出,Pages 布局改用 AuthButton。

🚀 Performance

  • pam: 搜索/详情/环境 API 去重与按需加载 (9636fff) (#125)

    服务端合并重复搜索请求;详情与环境分接口加载;Shell 缓存环境列表。

v2.6.0

Minor Changes

✨ Features

  • pam: 列表可见性筛选与 request log 审计白名单 (4773555) (#121)

    工具栏支持全部/公开/私有筛选;审计改为 allowlist 仅记录变更类 API,并补单测。

  • pam: 删除项目移至通用设置危险区 (014ea86) (#120)

    详情页顶栏去掉删除按钮,改到 General 危险区域;确认框默认文案走 i18n;升级 next-kit 至 ^1.1.0。

  • pam,brain-oauth: create/update 支持 logo_uri 落库 (ba126b4) (#118)

    本地扩展 Create/Update schema,Repo insert/update 写入 logo_uri(空串存 null)。

  • pam,brain-oauth: developer apps 补齐 logo 预览与列表展示 (c57a9dd) (#118)

    表单增加 logo URL 与预览;列表展示头像与可点击 client_uri,并补充 i18n。

  • pam: 新增项目分类 API 与 ISR 拉取 (64ad2fc) (#117)

    Repo/Service 提供去重分类;公开分类走 unstable_cache,并暴露 GET /api/pam/categories。

  • pam: 分类改为 API 建议列表并支持自由输入 (2241750) (#117)

    去掉硬编码预设;列表 ISR 注入分类,表单/筛选使用动态选项与自定义输入。

🐞 Bug Fixes

  • pam,brain-oauth: 修复 rotate-secret URL 拼错导致 405 (ef87e65) (#118)

    apiClientRotateSecret 改为基于 API_CLIENTS_ROTATE_SECRET 生成路径,避免 POST 打到 detail 路由。

  • pam,brain-oauth: 优化 developer apps 弹窗交互并修校验 (1ebc86e) (#118)

    编辑弹窗改为可滚动 sheet 与单行底栏;修正空 redirect URI 校验文案、详情加载竞态与 logo 破损态。

🚀 Performance

  • pam: 加速首页会话与分类接口,并加内存 KV 缓存 (e6dc66d) (#119)

    session 改为 cookie 只读;分类走轻量查询 + TTL 缓存;热路径跳过 request log;复用 admin Supabase 客户端;AuthButton 避免 hydration 闪烁。

v2.5.0

Minor Changes

✨ Features

  • pam: 列表搜索分类筛选与移动端工具栏收紧 (61a06e3) (#115)

    支持预设/自定义分类过滤、关键词高亮与搜索反馈; 移动端隐藏标题文案、分类横滑,新增改为 FAB。

  • pamenv,pam: 本地 CLI 隔离、API 错误 i18n 与 create_source (3b93564) (#114)

    支持 pamenv --local/--url/--domain 与 cwd .pam 隔离;结构化 PamCliApiError 与 locale 缓存;将基础设施错误归一为 api:server__error;CLI 建项走 admin 客户端规避 RLS;pam_projects.create_source 记录创建来源(0=web,1=cli,2=fork)。

  • pam: device 登录回传 locale,并完善 CLI locales API (253a641) (#114)

    浏览器 approve 带上当前页面语言,poll token 回传给 CLI;locales/json 在静态模式下正确返回 api 命名空间。

  • pam: 增加 Brain PKCE 登录并暂时禁用 custom:brain (73b4360) (#113)

    本地 brain-oauth 无法被云端 Supabase 回调时,用授权码+PKCE 直连建会话.

  • pam: 登录页 Brain 按钮文案、图标与禁用提示 (a4b7596) (#113)

    对齐 GitHub 文案风格,补充 Brain/PKCE/Google/手机禁用说明,并使用 brain-oauth logo。

  • pam: 非本地环境禁用 Brain PKCE 登录 (5135cb6) (#113)

    线上暂无跨域请求 Brain API 方案,仅 APP_ENV=localhost 可用。

🐞 Bug Fixes

  • pam: 修复 Brain PKCE 回调会话与 cookie 写入 (1ec94ea) (#113)

    回调在 redirect 响应上设置 pam_session,并避免过大 token 导致 cookie 被丢弃。

  • pam: 修复 Pages 退出跳转与主题 hydration (8eced4f) (#113)

    挂载 AppBridgePages,并用 ClientThemeProvider + timeZone 避免 Pages 控制台闪烁和退出失败。

v2.4.0

Minor Changes

✨ Features

  • pam: 拆分 / 落地页与公开 /projects 列表 (d026c5f) (#111)

    将项目列表迁到 /projects,首页改为介绍落地(示意、用法、CLI、公开项目预览),详情返回指向列表。

  • pam: 落地页增加版本与版权 footer (a855340) (#111)

  • pam: 详情改用 slug,并支持删除与 CLI 环境管理 (f768065) (#110)

    详情 URL 使用 slug(UUID 仍兼容跳转);owner 可删除项目;fork 仅限他人公开项目。create/delete environment 走 admin 客户端,避免 CLI bearer 无 Supabase RLS session。

  • pamenv: 新增 remove,push 延后创建缺失环境 (ec49038) (#110)

    缺失 -e 环境时先完成校验与确认,再一并创建并写入变量;新增 remove 两次确认删除;void 成功响应不再误报失败;补充 defaultEnvUrl 与文档。

🐞 Bug Fixes

  • pam: 鉴权就绪后再 ensure 首页项目列表 (e4a11da) (#111)

    避免游客先拉再登录重拉,以及从详情返回时重复拉取。

  • pam: 允许非敏感环境变量为空字符串 (57bd9a0) (#110)

    与 dotenv 的 KEY= 语义对齐,避免 pamenv push 因空值被 zod 拒绝。

v2.3.0

Minor Changes

✨ Features

  • pam: 支持 Fork 项目并剥离敏感变量 (f6fa207) (#108)

    允许登录用户从可读项目派生私有副本,复制环境结构但不复制敏感值。

    Co-authored-by: Cursor cursoragent@cursor.com

🐞 Bug Fixes

  • pam: 移除 fork 测试中无效的 is_deleted 字段 (d2e0c88) (#108)

    PAMProjectDetail 不含 is_deleted,对齐类型以通过 tsc。

    Co-authored-by: Cursor cursoragent@cursor.com

  • pam: 防止环境变量注释过长导致横向滚动 (6ba47bf) (#108)

    长无断注释在导入后撑开布局,限制容器宽度并强制换行。

    Co-authored-by: Cursor cursoragent@cursor.com

  • pam: 软删后释放 slug 供复用 (b31ce59) (#108)

    将全表 UNIQUE 改为仅未删除行唯一,并补充迁移脚本。

    Co-authored-by: Cursor cursoragent@cursor.com

📝 Documentation

v2.2.0

Minor Changes

✨ Features

  • pam: 新增 pamenv CLI 使用文档页 (f55f1b5) (#104)

📝 Documentation

  • pam: 更新 CLI 文档页安装包名为 pamenv-cli (7b3f206) (#106)

    安装示例改为 pamenv-cli,命令示例仍保持 pamenv。

v2.1.0

Minor Changes

✨ Features

  • pam: 新增 pamenv CLI 使用文档页 (f55f1b5) (#104)
v2.0.0

Major Changes

✨ Features

  • pam: 支持 CLI 鉴权、浏览器授权、环境导出与可吊销 Token (90d73bc) (#102)

  • pam: 环境变量 comments 原样导入展示与草稿导入 (688a1d3) (#102)

  • pam: 优化环境变量注释展示 UI (855171b) (#102)

v1.0.0

Major Changes

✨ Features

  • pam: 敏感变量加密、env 独立 API 与路径参数修复 (26f0d3f) (#97)

    支持敏感变量脱敏/合并落库加密,补齐环境 CRUD 与变量保存接口,并修复 buildApiWithPath 多参数覆盖问题。

  • pam: 项目 general/environments 详情页并去掉列表编辑入口 (85521b9) (#97)

    新增详情壳与分字段保存/环境变量管理页,创建弹窗保留导入能力,列表点击进入 general。

  • pam: AppApi 接入 AborterPlugin,补充 stop 与 PAMAbortId (38bad45) (#97)

    为详情/环境读取接入 abortId,并对并发 searchProjects 做 inflight 去重。

  • pam: 默认邮箱 OTP 登录并跳转首页 (1d736d8) (#93)

    禁用手机号 Tab 点击,登录成功后统一回首页而非 developer 页面。

  • pam: 首页预取公开列表并优化列表展示 (088ef3b) (#93)

    通过 RSC/ISR 预取首屏公开项目消除 loading 闪烁,列表标题下方改为显示完整 URL。

🐞 Bug Fixes

  • pam,brain-oauth: 修复 next-kit 迁移后的类型与构建错误 (ceb595a) (#100)

    放开 PAMSupabaseRepo.search 以支持 ilikeOr;transpile next-kit 并统一 corekit-bridge 版本,避免 ESM 目录导入失败。

  • pam,brain-oauth: 修复 Pages SSG 时 next-intl Context 不一致 (97cae46) (#100)

    i18n hook 改回 app 内调用 next-intl,只复用 kit 的 TranslateI18nUtil,避免预渲染 /about 等页时空 Error。

  • pam: 语言切换时保留动态路由 params (4eea15d) (#99)

    next-intl 的 usePathname 返回模板路径,切换语言时一并传入 useParams,避免地址变成 /projects/[projectId]/general。

  • pam: 非 owner 详情只读,并去掉 API 错误二次 toast (620e83a) (#98)

    详情接口返回 is_owner;General/Environments 按 canEdit 禁用编辑; 业务 catch 不再重复弹 DialogErrorPlugin 已处理的错误。

  • pam: 加固 useStrictEffect 以兼容 Strict Mode 二次挂载 (ebfb6ee) (#97)

  • pam: 忽略 AbortError,避免取消请求弹 toast 或刷错误日志 (a193c83) (#97)

    Strict Mode 重挂与页面切换触发的取消视为预期行为。

  • pam,brain-oauth: 中间件进页门禁并修复 Pages 主题闪烁 (a5bdd08) (#96)

    以 LOGINED_PAGES 为唯一进页鉴权,去掉 WithUserAuth 全屏门;Pages 补 favicon 与主题初始化脚本,主题菜单按偏好选中并同步 brain-oauth。

  • pam,brain-oauth: ThemeSwitcher 使用 SupportedTheme 泛型 (b1d3029) (#96)

    useTheme 默认不含 pink,导致 setTheme 类型报错。

  • pam: 将 Next OAuth 模板文案替换为 PAM 品牌 (2f31e57) (#96)

    更新首页/文档/授权/Playground 等 i18n 标识、manifest 名称与登出日志 auth_provider。

  • pam: 避免裸 hidden 类被浏览器扩展覆盖显示 (e30e743) (#95)

    将 hidden + 响应式显示改为 max-*:hidden,条件显隐改用 HTML hidden,避免 DeepL 等扩展注入的 .hidden 压过 Tailwind utilities。

  • pam,brain-oauth: 恢复误改样式并同步去掉裸 hidden (cc20228) (#95)

    还原登录表单 max-w-[420px] 与 PAMForm 圆角;brain-oauth 仅替换 hidden 写法。

  • pam: OAuth token/userinfo/revoke 返回扁平 RFC JSON (02855a3) (#94)

    兼容 Supabase 等标准 OAuth 客户端,不再使用 { success, data } 信封。

  • web: 更新 OAuth 授权流程以强制登录 (7c991fa) (#94)

    将 ROUTE_OAUTH_AUTHORIZE 添加至 LOGINED_PAGES,确保未登录用户访问授权页时自动重定向至登录页面,并在登录后返回授权页

  • pam: 修复 OAuth token 被加 locale 及 refresh token 存储错误 (773edfc) (#93)

    跳过 /oauth/token 等机器端点的 i18n 重写,并将 provider_session_token 改为存储 Supabase refresh token,避免 PKCE 换票 invalid_grant。

♻️ Refactors

  • pam: 迁移至 @qlover/next-kit 并清理无用代码 (1b0f5a4) (#100)

    将 schema、校验器、仓储、通用 UI/工具改为复用 next-kit,并移除未使用的演示与残留实现。

  • brain-oauth: 迁移至 @qlover/next-kit 并清理无用代码 (f55d54c) (#100)

    与 pam 对齐复用 next-kit,删除应用内重复模块及未接线的死代码。

  • pam: 列表进详情改为 next-intl Link (154ab48) (#99)

    用带 locale 的 Link 替换 button + onOpen,悬停/新开页都能保留语言前缀。

  • pam: 项目详情路径统一为 route.ts 常量 (f270c51) (#99)

    抽出 ROUTEPROJECT* 模板,供 next-intl pathnames 与 Link/跳转复用。

  • pam: 按列表/项目壳/general/environments 拆分 i18n (1cd92d1) (#97)

    将原 page_pam 文案拆到对应页面命名空间,并为共用 env 表单抽离 PAMEnvFormI18n 结构类型。

  • pam: 详情由 Shell 统一拉取,General 复用 context (7e20409) (#97)

    去掉 General 二次 getProjectDetail;列表与环境挂载改用 useStrictEffect + stop。

  • pam: 同步 next-oauth 邮箱登录 PKCE 流程 (332f9ff) (#93)

    将 magic link 从 hash token 改为服务端 PKCE 换 session,并规范化 SITE_URL 与回调页 bootstrap 时机。

v0.3.0

Minor Changes

✨ Features

  • pam: 未登录隐藏新建与编辑删除入口 (592a82a) (#91)

    按登录态控制工具栏新建、列表/卡片操作与弹窗,访客不再看到 mutate 按钮。

  • pam: 登录页改为 PAM 品牌文案并展示版本号 (1877a4f) (#91)

    禁用尚未支持的手机登录 Tab,登录成功后回到首页。

v0.2.0

Minor Changes

✨ Features

  • pam: 优化搜索 UX 与多字段命中率 (6bf773a) (#88)

    将 FTS 改为项目文本字段 ILIKE,缩短防抖并避免搜索闪空;列表同时展示分类与技术栈。

  • pam: 将列表与卡片 UI 对齐 v3 原型 (3b657a0) (#87)

    仅私有显示锁、文字操作菜单(分组与删除红色)、环境 chip 原型配色,以及锁与环境入口的响应式尺寸。

  • pam: 优化列表与卡片布局密度与交互 (124d07e) (#87)

    大屏列表三行排布并加大标题;去掉多余打开仓库/部署入口;userId 可省略复制;卡片收紧空状态与 logo 内边距,并同步 v3 原型。

  • pam: 对齐新建编辑弹窗表单到 v3 原型 (d38820d) (#87)

    统一 field 样式与可见性切换,操作栏移入 Modal footer,并修正 secondary/elevated 背景层次。

  • pam: Integrate sonner for toast notifications and enhance dialog handling (ddc54fc) (#84)

    • Removed deprecated '@ant-design/icons' in favor of '@heroicons/react' for a more modern icon set.
    • Introduced sonner for toast notifications, replacing Ant Design's message component in DialogHandler.
    • Updated DialogHandler to utilize a React-based confirm dialog through DialogUIHost.
    • Refactored PAM components to support new icon imports and improved user feedback mechanisms.
    • Added new icons for GitHub and Google, enhancing the visual consistency across the application.
  • pam: Enhance internationalization support and update schema handling (a70d67b) (#83)

    • Added new @locales/* path mappings in tsconfig.json and vitest.config.ts for improved localization management.
    • Introduced i18nKey.ts schema for validating i18n keys, including utility functions for key manipulation.
    • Updated i18nKeyScheam.ts to utilize the new I18N_KEY_PATTERN from i18nKey.ts.
    • Refactored loadMessages.ts to load locale files using the new path mappings.
    • Added ambient module declarations for locale JSON files in locales.d.ts to support TypeScript integration.
    • Updated DialogErrorPlugin.ts to use the new i18n key validation method.
  • pam: Update tailwind theme integration and enhance CSS generation (cbd45a3) (#83)

    • Updated @qlover/tailwind-theme dependency to version ^0.3.0 in package.json.
    • Refactored CSS imports in tailwind.css to use generated theme file.
    • Introduced generateAppThemeCss utility to create a slim theme CSS file based on supported themes.
    • Integrated theme CSS generation in next.config.ts for both PAM and brain-oauth examples.
    • Added local IP address detection for development environments in next.config.ts.
    • Updated .gitignore to include generated styles directory and ensure proper file exclusions.
  • pam, brain-oauth: Upgrade ESLint configuration and dependencies for improved linting (099fe47) (#83)

    • Updated ESLint and related plugins to version 10.x in package.json for both pam and brain-oauth.
    • Refactored ESLint configuration to utilize @eslint/js and eslint-plugin-import-x.
    • Enhanced ESLint rules and settings for better code quality and consistency.
    • Integrated new theme provider from @wrksz/themes in layout components for improved theming support.
    • Updated README and other documentation to reflect changes in theme integration.
  • pam: Enhance session management and improve authentication flow (df43a83) (#82)

    • Added hasSessionFromRequest method in OAuthSessionService to check for valid sessions from requests.
    • Introduced GUEST_ONLY_AUTH_PAGES constant to define routes accessible only to unauthenticated users.
    • Implemented isAuthGuestOnlyPath function to redirect authenticated users away from guest-only routes.
    • Updated proxy middleware to handle redirection based on session status.
    • Refactored login and register pages to utilize PageI18nProvider for improved internationalization support.
  • pam: Add PAM logo and update layout to include header logo (fcb1053) (#82)

  • apps-pam: Init PAM project (9eb7818) (#64)

  • pam: Refactor code structure for improved readability and maintainability (b59861e) (#64)

  • repo: implement BaseRepository and SupabaseRepo for enhanced data handling (601c8c1) (#64)

  • add PAM project and environment management with RLS and search functionality (638ebc3) (#64)

    • Create SQL schema for pam_projects and pam_environments with necessary indexes and triggers.
    • Implement row-level security policies for project and environment access control.
    • Add sample data insertion script for testing purposes.
    • Develop PAMController to handle project search requests.
    • Introduce PAMService and PAMProjectRepo for project management and search operations.
    • Create validation and schema definitions for project and environment data.
    • Update API routes to include new search endpoint for PAM projects.
    • Enhance localization for home page titles and keywords.
  • repo: add user_id parameter description to search method for clarity (32df417) (#64)

  • auth: enhance user session management and update user retrieval methods (6e258ba) (#64)

  • pam: Enhance project update functionality and API authentication (72c223c) (#64)

    • feat(pam): implement project update functionality with environment handling
    • feat(pam): refactor Supabase client handling and enhance API authentication
    • feat(pam): enhance project update functionality with RPC support and environment management

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Implement project creation API and related schema updates (c160fcd) (#64)

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Implement PAM project management and user session enhancements (8f69654) (#64)

    • feat(pam): Implement PAM search functionality with new API and facade structure
    • fix(pam): Simplify user session refresh logic in SupabaseOAuthProvider
    • Introduced a new toUserSchema function to streamline user profile transformation.
    • Updated refreshUser and getUserInfo methods to utilize the new function for returning user data.
    • Enhanced error handling for missing refresh tokens during session retrieval.
    • feat(pam): Update dependencies and enhance project schema
    • Added @hookform/resolvers dependency with version 5.4.0.
    • Updated @qlover/oauth-wrapper to version 0.6.2.
    • Introduced react-hook-form dependency with version 7.80.0.
    • Modified PAMProjectSchema to include is_deleted field for soft deletion management.
    • Enhanced user session handling in UserController and OAuthUserService for improved user data retrieval.
    • Added validation for unique environment names in project schemas.
    • feat(pam): Implement project creation and management features
    • Added a new ResponsiveModal component for project creation.
    • Introduced PAMForm and PAMFormEnvironments components for handling project input and environment variables.
    • Updated PAMFacade to include methods for creating projects with environment support.
    • Enhanced PAMApi to support project creation API calls.
    • Refactored PAMProjectCard and PAMProjectList components to utilize the new project schema.
    • Improved user experience with form validation and dynamic slug generation.

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com> Co-authored-by: QRenjie renjie.qin@brain.im

  • pam: Refactor PAM project schemas and enhance API handling and UI (cb48ca9) (#64)

    • refactor(pam): Update PAM project schemas and interfaces for improved API handling
    • Introduced PAMApiProjectSchemaType to represent API responses, enhancing data handling in the project management flow.
    • Updated PAMController, PAMService, and related interfaces to utilize the new schema type for search functionality.
    • Refactored PAMProjectRepo to implement a new search parameters interface, allowing for user-specific data retrieval.
    • Adjusted UI components to align with the new schema, ensuring consistent data representation across the application.
    • refactor: update PAM project schemas and interfaces for improved type safety
    • Changed PAM project schemas to use more descriptive types, including renaming and restructuring.
    • Updated interfaces across the PAM service and repository layers to reflect new schema types.
    • Refactored search and create project methods to utilize the new types, enhancing type safety and clarity.
    • Introduced a new utility type Join for better handling of environment fields in queries.
    • Adjusted frontend components to align with updated types, ensuring consistency across the application.
    • feat(pam): Enhance project management with detail and edit functionalities, including API integration and UI updates
    • feat: Refactor PAM project and environment schemas, update repository and service logic
    • Updated BaseRepository to allow default type for generic parameters.
    • Refactored PAMProjectRepo to utilize new environment schemas and improve type safety.
    • Introduced validation for environment names and IDs in PAMService.
    • Added new error identifiers for environment ID and variable key duplication.
    • Updated routes and API interfaces to reflect changes in project and environment handling.
    • Enhanced PAMForm and PAMFormEnvironments components to support new schemas and validation logic.
    • Improved overall type definitions for project and environment handling in schemas.
    • feat(pam): Update project schemas and interfaces for improved handling, enhance UI components with Ant Design icons, and remove unused modal component
    • feat(pam): Refactor PAMToolbar to include create button and update styles for improved UI

    Co-authored-by: QRenjie renjie.qin@brain.im Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Implement project deletion functionality and update related components (927ac11) (#64)

  • pam: Update default search parameters to include sorting by visibility (4c2377e) (#64)

  • pam: Stability fixes for infinite scrolling and paginated sorting in the project list (57d6e02) (#64)

    • fix(pam): Update .gitignore to include .vscode and ensure .cache is properly ignored
    • feat(pam): Add infinite scrolling functionality for project list and integrate load more trigger component
    • Introduced PAMFacadeInfinite to manage infinite scrolling behavior for project lists.
    • Implemented PAMLoadMoreTrigger component to handle loading more projects as the user scrolls.
    • Updated PAMRoot to utilize the new infinite scrolling features, enhancing user experience with seamless data loading.
    • Refactored existing project management logic to support the new loading strategy.
    • refactor(pam): Simplify user info retrieval by updating return type in OAuthWrapperController
    • Removed unused import of OAuthUserInfoResponse.
    • Changed return type of getUserInfo method to Promise<UserSchema> for improved clarity and type safety.

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Implement handler for successful project creation to reset project list (dfbd307) (#64)

    • Added handlerCreateSuccess method to manage post-creation logic, resetting the project list and reloading from the first page.
    • Integrated this method into the project creation flow to enhance user experience by ensuring the latest data is displayed after a project is created.

    Co-authored-by: QRenjie renjie.qin@brain.im

  • pam: Enhance internationalization support and refactor environment handling (f2e203c) (#64)

    • feat(pam): Implement handler for successful project creation to reset project list (#78)
    • Added handlerCreateSuccess method to manage post-creation logic, resetting the project list and reloading from the first page.
    • Integrated this method into the project creation flow to enhance user experience by ensuring the latest data is displayed after a project is created.

    Co-authored-by: QRenjie renjie.qin@brain.im

    • feat(pam): Enhance internationalization support and refactor environment handling
    • Added new validation messages for required environment variable keys and values in validators.ts.
    • Introduced a new page.pam.ts file for PAM page-specific internationalization strings, including titles, descriptions, and labels.
    • Refactored PAMI18n.ts to integrate new internationalization keys and improve structure.
    • Updated PAMEnvironmentSchema.ts to utilize new validation messages for environment variables.
    • Replaced hardcoded strings in various components with internationalized strings from PAMI18n, enhancing localization support.
    • Removed deprecated PAMEnvironmentBlock component and replaced it with a more modular PAMFormEnvironmentBlock for better maintainability.
    • Improved user feedback and error handling in forms related to environment variables.

    Co-authored-by: QRenjie renjie.qin@brain.im


    Co-authored-by: QRenjie renjie.qin@brain.im Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Add PAM page subtitle and enhance styling components (52e6c39) (#64)

    • Introduced a new subtitle for the PAM page to improve user context and navigation.
    • Added a new pam.css file containing presentation utilities for better UI consistency.
    • Updated various components to utilize the new styles, enhancing the overall visual experience.
    • Refactored existing components to improve styling and maintainability, including updates to PAMForm, PAMProjectCard, and PAMToolbar for better alignment with design standards.

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Implement keyword search functionality in PAMToolbar and update interface (7bd4070) (#64)

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Update event_category to event_type in OAuth routes and enhance type definitions (622a919) (#64)

🐞 Bug Fixes

  • apps: 稳定 Dropdown 定位并消除首次展开闪动 (c8d5514) (#87)

    先按最终 minWidth 测量再显示,并忽略 ResizeObserver 首次回调,避免打开时位置跳动。

  • pam: 修正列表项 host 链接截断布局 (d66b0c7) (#87)

    将 truncate 放到外层容器,避免 a 标签自身影响省略显示。

  • pam: Correct package name and version in package.json; update changelog header (c9d43d4) (#82)

  • pam: Update PAMVariableSchema to make id optional and refactor PAMFormEnvironments for improved variable handling (a25fd85) (#64)

    • Made the id field in PAMVariableSchema optional to allow for more flexible variable management.
    • Refactored PAMFormEnvironments to streamline the addition, update, and removal of environment variables, ensuring proper handling of key-value pairs and maintaining unique identifiers for each variable.
    • Enhanced validation checks for incomplete variables and improved user feedback in the UI.

    Co-authored-by: QRenjie renjie.qin@brain.im

  • pam: Update PAMFormEnvironments to use PAMEnvWriteable and improve linting scripts (edefc7b) (#64)

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • pam: Enhance session handling by adding error management for used refresh tokens (a4c9166) (#64)

♻️ Refactors

  • pam: remove unused view mode storage key and enhance configuration (dea1d77) (#86)

    • Removed the pamViewModeStorageKey from common.ts as it was no longer utilized.
    • Introduced pamStorageKey in SeedConfigInterface to manage PAM state persistence.
    • Updated AppConfig to initialize pamStorageKey from environment variables.
    • Refactored PAMFacade to utilize the new pamStorageKey for state management.
    • Adjusted PAMRoot to apply persisted view mode after component mount for improved user experience.
  • apps: replace shell antd with lightweight UI primitives (c4f7c55) (#85)

    Align brain-oauth and pam with fe-base: local Button/Dropdown/Tooltip/Table, antd-free ClientRootProvider, and drop global antd CSS from the app shell.

  • pam: code structure for improved readability and maintainability (12a375a) (#64)

  • pam: Refactor PAM to replace SupabaseBridge with SupabaseRepo across services (8b9e2c0) (#64)

    • refactor(pam): replace SupabaseBridge with SupabaseRepo in OAuth provider
    • refactor(pam): remove SupabaseBridge and replace with SupabaseRepo across services and interfaces
    • refactor(pam): remove SupabaseBridge and integrate SupabaseRepo across repositories and services
    • refactor(pam): remove SupabaseBridge and replace with SupabaseRepo in Locales and PAMProject repositories
    • refactor(pam): remove SupabaseBridge and update related interfaces and services to use Resource types

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>

  • server: Update server interfaces and context management (e1dade5) (#64)

    • Replaced ServerInterface with BootstrapServerInterface in BootstrapServer and NextApiServer.
    • Introduced ServerContext and ServerContextInterface to manage server state and context.
    • Removed ServerStateInterface and refactored related logic to use the new context management.
    • Updated RequestLogsRepository and OAuthUserService to utilize the new context for state management.
    • Enhanced NextApiHandler to handle context-based operations.
    • Refactored SupabaseOAuthProvider to align with new context structure.
    • Adjusted various plugins and handlers to integrate with the new server context.

    Co-authored-by: QRJ <github-actions[bot]@users.noreply.github.com>