diff --git a/docs/en/Blog-Posts/2026-08-05 v10_7_Preview/POST.md b/docs/en/Blog-Posts/2026-08-05 v10_7_Preview/POST.md index 436be3f7e8..b8a4d5bf65 100644 --- a/docs/en/Blog-Posts/2026-08-05 v10_7_Preview/POST.md +++ b/docs/en/Blog-Posts/2026-08-05 v10_7_Preview/POST.md @@ -6,31 +6,34 @@ Try this version and provide feedback to help us deliver a more stable ABP v10.7 ## Get Started with the 10.7 RC -You can check the [Get Started page](https://abp.io/get-started) to see how to get started with ABP. You can either download [ABP Studio](https://abp.io/get-started#abp-studio-tab) or use the [ABP CLI](https://abp.io/docs/latest/cli). +You can check the [Get Started page](https://abp.io/get-started) to see how to get started with ABP. You can either download [ABP Studio](https://abp.io/get-started#abp-studio-tab) (**recommended**, if you prefer a user-friendly GUI application - desktop application) or use the [ABP CLI](https://abp.io/docs/latest/cli). -By default, ABP Studio uses stable versions to create solutions. To use a preview version, create your solution and then switch it to the preview version from the ABP Studio UI. +By default, ABP Studio uses stable versions to create solutions. Therefore, if you want to create a solution with a preview version, first you need to create a solution and then switch your solution to the preview version from the ABP Studio UI: ![studio-switch-to-preview](studio-switch-to-preview.png) ## Migration Guide -There are no explicitly marked breaking changes in ABP v10.7 RC. You can check the [ABP Version 10.7 Migration Guide](https://abp.io/docs/10.7/release-info/migration-guides/abp-10-7) if you are upgrading from v10.6 or earlier. +Check the [ABP Version 10.7 Migration Guide](https://abp.io/docs/10.7/release-info/migration-guides/abp-10-7) before upgrading from v10.6 or earlier. It covers the services that take new constructor dependencies, the Blazor antiforgery middleware order, the dependency updates, and the AI Management schema change that requires a new EF Core migration. ## What's New with ABP v10.7? In this section, I will introduce some major features released in this version. -Here is a brief list of the topics explained in the next sections: +Here is a brief list of titles explained in the next sections: - BLOB Encryption at Rest and Content Pipeline - HTTP QUERY Method Support -- Angular Resource API Helpers +- Angular Resource API Proxies - ABP Suite React CRUD Page Generation +- ABP Suite Decimal Precision - ABP Studio MCP Configuration -- Reliability and Dependency Updates +- AI Management Web Page Data Sources +- Dependency Updates +- Other Improvements and Enhancements ### BLOB Encryption at Rest and Content Pipeline -ABP v10.7 adds opt-in, transparent encryption at rest for the BLOB Storing system. Encryption uses AES-256-GCM and works on top of the configured storage provider, so application code can continue using `IBlobContainer` as before. +ABP v10.7 adds opt-in, transparent encryption at rest for the BLOB Storing system. Encryption uses AES-256-GCM and works on top of the configured storage provider, so application code can continue using `IBlobContainer` as before. It requires a platform with AES-GCM support and is not available on .NET Standard 2.0 targets. You can enable encryption per container and configure the passphrase from your application's secure configuration: @@ -53,50 +56,66 @@ The new BLOB content pipeline lets you transparently transform content when it i Both features are disabled by default. When enabling encryption for a container that already contains plaintext BLOBs, first allow legacy plaintext reads, re-save the existing content, and then remove the legacy option so the container reads encrypted data only. -> See the [BLOB Encryption](https://abp.io/docs/10.7/framework/infrastructure/blob-storing/encryption) and [BLOB Content Pipeline](https://abp.io/docs/10.7/framework/infrastructure/blob-storing/pipeline) documents, and [#25836](https://github.com/abpframework/abp/pull/25836), for details. +> See the [BLOB Encryption](https://abp.io/docs/10.7/framework/infrastructure/blob-storing/encryption) and [BLOB Content Pipeline](https://abp.io/docs/10.7/framework/infrastructure/blob-storing/pipeline) documents and [#25836](https://github.com/abpframework/abp/pull/25836) for details. ### HTTP QUERY Method Support -ABP now supports the HTTP `QUERY` method for endpoints that need to send request data without using a query string. A `QUERY` endpoint is treated as a safe method: it is excluded from audit logging and starts a non-transactional unit of work by default, like `GET`. +ABP now supports the HTTP `QUERY` method for endpoints that need to send request data without using a query string. A `QUERY` endpoint is treated as a safe method: like `GET`, it starts a non-transactional unit of work and is not audited by default. `GET`, `HEAD` and `QUERY` share the `AbpAuditingOptions.IsEnabledForGetRequests` setting. To expose an action as a `QUERY` endpoint, use the ASP.NET Core `[AcceptVerbs("QUERY")]` attribute. Because the method carries a request body, it still requires an anti-forgery token. > See the [Auto API Controllers](https://abp.io/docs/10.7/framework/api-development/auto-controllers#http-method) documentation and [#25797](https://github.com/abpframework/abp/pull/25797) for details. -### Angular Resource API Helpers +### Angular Resource API Proxies -The Angular proxy generator can now generate optional Resource API helpers for `GET` endpoints. Use the `--resource-api` option with the proxy generator to add `rxResource` helpers while keeping the existing Observable-based services. +The Angular proxy generator can now generate the `GET` endpoints against the Resource API. Pass the `--resource-api` option and every generated `GET` member returns an `rxResource`-based `ResourceRef` instead of an `Observable`. An endpoint with parameters takes them as a single `Signal`, a parameterless endpoint has no signal parameter, and the optional request configuration stays a normal argument. The other HTTP methods keep the Observable-based form. -This option requires Angular 22 or later and is disabled by default, so existing generated proxies continue to work without changes. +This option requires Angular 22 or later and is disabled by default, so existing generated proxies continue to work without changes. Regenerate the proxies with the option only when you are ready to consume the resource form in your components. > See the [Angular Service Proxies](https://abp.io/docs/10.7/framework/ui/angular/service-proxies) documentation and [#25761](https://github.com/abpframework/abp/pull/25761) for details. ### ABP Suite React CRUD Page Generation -ABP Suite now supports generating CRUD pages for React applications, bringing the same productive code-generation experience available for other ABP UI options to React projects. +ABP Suite now supports generating CRUD pages for the React applications in modern solutions, bringing the same productive code-generation experience available for other ABP UI options to React projects. The generation is template-based and does not use AI. Generated React pages include list, search, sorting, paging, filtering, export, create, edit, single and bulk delete operations. They also support validation, permissions, localization, file upload, navigation properties, many-to-many relationships, and master-detail pages with child create, edit, delete, and paging operations. -The generator respects the entity and field configuration you define in ABP Suite, including `ShowOn*`, `IsFilterable`, and `ReadonlyOnEdit` options. Navigation lookups use server-side search. +The generator respects the entity and field configuration you define in ABP Suite, including `ShowOn*`, `IsFilterable`, and `ReadonlyOnEditModal` options. Navigation lookups use server-side search. ![React CRUD page generation demo](react-crud-page.mp4) +### ABP Suite Decimal Precision + +You can now set the precision and scale of a `decimal` property in ABP Suite. For the relational database providers that support fixed-point columns, the generated entity configuration includes the matching `HasPrecision(...)` call. + ### ABP Studio MCP Configuration -ABP Studio provides a simpler experience for configuring Model Context Protocol (MCP) integrations. You can add common integrations through focused configuration forms or manage the complete MCP server list as JSON, with support for secret placeholders and secure platform storage. +ABP Studio provides a simpler experience for configuring Model Context Protocol (MCP) integrations. You can add common integrations through focused configuration forms or manage the complete MCP server list as JSON, with support for secret placeholders and secure platform storage. It is available in ABP Studio v3.0.9 and later. > See the [ABP Studio AI Agent configuration](https://abp.io/docs/10.7/studio/ai-agent-configuration) documentation and [#25870](https://github.com/abpframework/abp/pull/25870) for details. -### Reliability and Dependency Updates +### AI Management Web Page Data Sources + +A workspace data source can now be created from a web page URL, not only from an uploaded file. The page content is converted to markdown and indexed like any other data source, and you can refresh it later to pick up changes to the page. + +The model name fields of the workspace configuration can also suggest the available models of the selected provider, so you don't have to remember the exact model names. The OpenAI and Ollama model catalogs are included; a provider without a registered catalog simply has no suggestions. -This release also includes important reliability improvements: +### Dependency Updates -- BLOB storage providers have improved support for transformed and non-seekable streams. -- Identity session cleanup now uses the sign-in time when a session has not yet recorded a last-accessed time, preventing valid token sessions from being removed too early. -- ABP templates place `UseAntiforgery()` after `UseAuthorization()`, as required by ASP.NET Core. -- MudBlazor packages have been upgraded to **9.7.0**. +ABP v10.7 RC includes the following dependency updates: -> Check the [Package Version Changes](https://abp.io/docs/10.7/package-version-changes) document for all dependency updates. +- MudBlazor upgraded to **9.7.0** +- `MySql.EntityFrameworkCore` upgraded to **10.0.9** + +> Check the [Package Version Changes](https://abp.io/docs/10.7/package-version-changes) document for all updates. + +### Other Improvements and Enhancements + +- **BLOB storing**: The storage providers have improved support for transformed and non-seekable streams. +- **Identity sessions**: The inactive session cleanup uses the sign-in time when a session has not recorded a last-accessed time yet, so valid token sessions are not removed too early. +- **Identity**: The user's last sign-in time is written as a best-effort update in its own unit of work, so a concurrency conflict no longer fails the sign-in request ([#25905](https://github.com/abpframework/abp/pull/25905)). +- **Blazor templates**: `UseAntiforgery()` is called after `UseAuthorization()`, which is the order required by ASP.NET Core. Existing solutions keep their own middleware order, so check the migration guide ([#25874](https://github.com/abpframework/abp/pull/25874)). +- **MySQL**: The `Guid[]` query parameters are mapped correctly, and the passkey and user invitation columns are stored as `json`. ## Community News @@ -111,6 +130,8 @@ Thanks to the ABP Community for all the content they have published. You can als ## Conclusion -ABP v10.7 RC introduces BLOB encryption and a content pipeline, HTTP QUERY support, Angular Resource API helpers, and new ABP Suite and ABP Studio capabilities. Please try the release and provide feedback to help us finalize ABP v10.7. +This version comes with some new features and a lot of enhancements to the existing features. You can see the [Road Map](https://abp.io/docs/10.7/release-info/road-map) documentation to learn about the release schedule and planned features for the next releases. Please try ABP v10.7 RC and provide feedback to help us release a more stable version. For the complete list of changes, see the [ABP 10.7.0-rc.1 release notes](https://github.com/abpframework/abp/releases/tag/10.7.0-rc.1). + +Thanks for being a part of this community! diff --git a/docs/en/cli/index.md b/docs/en/cli/index.md index 1174c12f4b..88b6457d46 100644 --- a/docs/en/cli/index.md +++ b/docs/en/cli/index.md @@ -816,7 +816,7 @@ abp generate-proxy -t csharp -url https://localhost:44302/ - `--module`: Backend module name. Default value: `app`. - `--entry-point`: Targets the Angular project to place the generated code. - `--url`: Specifies api definition url. Default value is API Name's url in environment file. - - `--resource-api`: Adds optional Resource API helpers for `GET` endpoints while keeping the generated Observable services. This parameter requires Angular v22 or later. + - `--resource-api`: Generates the `GET` endpoints against the Resource API: they return an `rxResource`-based `ResourceRef` and take their parameters as a single `Signal` (a parameterless endpoint has no signal parameter and the optional `config` argument is unchanged), instead of returning an `Observable`. Off by default. This parameter requires Angular v22 or later. - `--prompt` or `-p`: Asks the options from the command line prompt (for the unspecified options). - `js`: JavaScript. work in the `*.Web` project directory. There are some additional options for this client: - `--output` or `-o`: JavaScript file path or folder to place generated code in. diff --git a/docs/en/framework/ui/angular/service-proxies.md b/docs/en/framework/ui/angular/service-proxies.md index 4f1c4abc5d..189874fcd5 100644 --- a/docs/en/framework/ui/angular/service-proxies.md +++ b/docs/en/framework/ui/angular/service-proxies.md @@ -88,14 +88,14 @@ export const environment: Config.Environment = { - **target:** Target for the Angular project to place the generated code. For example, if it's `permission-management`, it'll look like this (npm/ng-packs/packages/*permission-management*). - **entryPoint:** To create the generated proxy folder in the target. The directory is `permission-management/proxy/src/lib/proxy` and the `permission-management` is the value of target. If you want to create a folder for the generated proxy, there are two options, you should either set the value `proxy` as the entryPoint or go to project.json and change the `sourceRoot` from `packages/permission-management/src` to `packages/permission-management/proxy/src`. No need to change the sourceRoot of project with the property. if you keep it empty, the proxy will be generated into the folder defined in the sourceRoot property. - **serviceType:** The service type of the generated proxy. The options are `application`, `integration` and `all`. The default value is `application`. A developer can mark a service "integration service". If you want to skip proxy generation for the service, then this is the correct setting. More info about [Integration Services](../../api-development/integration-services.md) -- **resourceApi:** Generates optional `rxResource` helpers for `GET` endpoints. This is off by default and keeps the current Observable-based services unchanged. This parameter requires Angular v22 or later +- **resourceApi:** Generates the `GET` endpoints against the Resource API: they return an `rxResource`-based `ResourceRef` and take their parameters as a single `Signal`, instead of returning an `Observable`. This is off by default, so the generated services keep the Observable-based form unless you enable this option. This parameter requires Angular v22 or later. ### Services The `generate-proxy` command generates one service per back-end controller and a method (property with a function value actually) for each action in the controller. These methods call backend APIs via [RestService](./http-requests#restservice). -If you pass `--resource-api`, the generator keeps those methods and adds matching `rxResource` helpers for read operations. +If you pass `--resource-api`, the `GET` members return an `rxResource`-based `ResourceRef` instead of an `Observable`, and take their parameters as a single `Signal` (a parameterless endpoint has no signal parameter, and the optional `config` argument is unchanged). The other HTTP methods keep the form above. A variable named `apiName` (available as of v2.4) is defined in each service. `apiName` matches the module's `RemoteServiceName`. This variable passes to the `RestService` as a parameter at each request. If there is no microservice API defined in the environment, `RestService` uses the default. See [getting a specific API endpoint from application config](./http-requests#how-to-get-a-specific-api-endpoint-from-application-config) diff --git a/docs/en/release-info/migration-guides/abp-10-7.md b/docs/en/release-info/migration-guides/abp-10-7.md index ffd72f3166..b3821552fa 100644 --- a/docs/en/release-info/migration-guides/abp-10-7.md +++ b/docs/en/release-info/migration-guides/abp-10-7.md @@ -1,17 +1,84 @@ ```json //[doc-seo] { - "Description": "Upgrade your ABP solutions from v10.6 to v10.7 with guidance for BLOB encryption, content pipelines, middleware ordering, and dependency updates." + "Description": "Upgrade your ABP solutions from v10.6 to v10.7 with this migration guide covering important behavior and integration changes." } ``` # ABP Version 10.7 Migration Guide -This document is a guide for upgrading ABP v10.6 solutions to ABP v10.7. There are no explicitly marked breaking changes in this release. Most applications can upgrade their ABP packages without additional migration work. +This document is a guide for upgrading ABP v10.6 solutions to ABP v10.7. This version includes explicitly marked migration-impacting changes for specific customization scenarios, while most applications can upgrade with no additional action beyond the notes below. > **Package Version Changes:** Before upgrading, review the [Package Version Changes](../../package-version-changes.md) document to see version changes on dependent NuGet and NPM packages and align your project with ABP's internal package versions. -## BLOB Encryption and Content Pipeline +## Open-Source (Framework) + +This version contains the following changes on the open-source side: + +### Constructor Changes + +**Who is affected** + +- Applications that derive from the services below, replace them with a derived class, or construct them manually. + +**What changed** + +These services take new constructor dependencies. There is no overload with the previous signature, so a derived class does not compile until its constructor is updated: + +- `IdentityUserManager` takes a new `IUnitOfWorkManager`. +- `EfCoreIdentitySessionRepository` and `MongoIdentitySessionRepository` take a new `IClock`. +- `BlazorServerCurrentApplicationConfigurationCacheResetService` takes a new `ApplicationConfigurationChangedService`. + +`IdentityUserManager` also writes the user's last sign-in time as a best-effort update in its own unit of work now, so the value is saved after the sign-in unit of work completes instead of within it. + +**What to do** + +Add the new parameters to your derived constructors and pass them to the base constructor. + +> See [#25905](https://github.com/abpframework/abp/pull/25905) for details. + +### Blazor Antiforgery Middleware Order + +**Who is affected** + +- Blazor applications that call `UseAntiforgery()` before `UseAuthorization()`. This covers the solutions generated by the classic templates before v10.7 and the solutions generated by the current modern solution templates. + +**What changed** + +- ASP.NET Core requires `UseAntiforgery()` to be called after `UseAuthentication()` and `UseAuthorization()`. +- The classic Blazor startup templates now use that order. Existing solutions keep the middleware order they were generated with, so they are not updated by the package upgrade. + +**What to do** + +Check the `OnApplicationInitialization` method of your Blazor module and move the calls into this order: + +```csharp +app.UseAuthentication(); +// ... +app.UseAuthorization(); +app.UseAntiforgery(); +``` + +> See [#25874](https://github.com/abpframework/abp/pull/25874) for details. + +### Angular Resource API Proxies + +**Who is affected** + +- Angular applications that regenerate their service proxies with the new `--resource-api` option. + +**What changed** + +- With `--resource-api`, every generated `GET` member returns an `rxResource`-based `ResourceRef` instead of an `Observable`, and takes its parameters as a single `Signal`. A parameterless endpoint has no signal parameter, and the optional request configuration stays a normal argument. The other HTTP methods are unchanged. +- The option is off by default, so a regular proxy regeneration keeps the current output. + +**What to do** + +Only pass `--resource-api` when the components that consume the `GET` methods are ready for the resource form. It requires Angular v22 or later. + +> See the [Angular Service Proxies](../../framework/ui/angular/service-proxies.md) document and [#25761](https://github.com/abpframework/abp/pull/25761) for details. + +### BLOB Encryption and Content Pipeline **Who is affected** @@ -44,37 +111,76 @@ options.Containers.Configure(container => If you change transforming pipeline contributors or an encryption passphrase, read and export the existing BLOBs while the old configuration is active, apply the new configuration, and save the content back. Do not change an encryption passphrase in place before migrating the existing BLOBs. -> See the [BLOB Encryption](../../framework/infrastructure/blob-storing/encryption.md) and [BLOB Content Pipeline](../../framework/infrastructure/blob-storing/pipeline.md) documents, and [#25836](https://github.com/abpframework/abp/pull/25836), for details. +> See the [BLOB Encryption](../../framework/infrastructure/blob-storing/encryption.md) and [BLOB Content Pipeline](../../framework/infrastructure/blob-storing/pipeline.md) documents and [#25836](https://github.com/abpframework/abp/pull/25836) for details. -## Blazor Antiforgery Middleware Order +### Dependency Updates **Who is affected** -- Applications that manually configure the ASP.NET Core middleware pipeline in Blazor applications. +- Applications that use EF Core with MySQL, directly reference MudBlazor, or pin transitive package versions. **What changed** -- ABP templates now place `UseAntiforgery()` after `UseAuthorization()`, which is the middleware order required by ASP.NET Core. +- MudBlazor is upgraded from **9.4.0** to **9.7.0**. +- `MySql.EntityFrameworkCore` is upgraded from **10.0.1** to **10.0.9**. +- ABP maps `Guid[]` query parameters through its own type mapping plugin on MySQL, and stores `IdentityUserPasskey.Data` as a serialized `json` column, because the MySQL providers support neither EF Core JSON columns nor primitive collections. The column name and the stored content stay the same. **What to do** -If your application configures these middleware calls manually, verify that it uses the following order: +Review direct MudBlazor references, align them with ABP's package versions, and re-test customized MudBlazor components and forms after upgrading. -```csharp -app.UseAuthorization(); -app.UseAntiforgery(); -``` +If you use the MySQL provider, align your own `MySql.EntityFrameworkCore` reference with ABP's version. + +## Pro -## Dependency Updates +This version contains the following changes on the PRO side: + +### Identity Pro **Who is affected** -- Applications that directly reference MudBlazor or pin transitive package versions. +- Applications that derive from `Volo.Abp.Identity.IdentityProUserManager`, replace it with a derived class, or construct it manually. +- Applications that use Identity Pro with MySQL. **What changed** -- MudBlazor is upgraded from **9.4.0** to **9.7.0**. +- `IdentityProUserManager` takes the new `IUnitOfWorkManager` dependency, like its base class. +- `UserInvitation.AssignedRoles` is stored as a serialized `json` column on MySQL, because the MySQL providers do not support primitive collections. The column name and the stored content stay the same. **What to do** -Review direct MudBlazor references, align them with ABP's package versions, and re-test customized MudBlazor components and forms after upgrading. +Add the parameter to your derived constructor and pass it to the base constructor. + +### AI Management Web Page Data Sources + +**Who is affected** + +- Applications that use the AI Management module with Entity Framework Core. +- Applications that implement `IWorkspaceDataSourceAppService` or `IWorkspaceAppService`, or derive from `WorkspaceDataSourceAppService` or `WorkspaceAppService`. + +**What changed** + +- Workspace data sources can be created from a web page URL, so the `WorkspaceDataSource` entity has the new `SourceType`, `SourceUrl`, `SourceTitle`, and `FetchedAt` properties. +- `IWorkspaceDataSourceAppService` has the new `CreateFromUrlAsync` and `RefreshFromUrlAsync` methods, and `IWorkspaceAppService` has the new `GetModelsAsync` overloads. +- `WorkspaceDataSourceAppService` takes the new `IWebPageMarkdownConverter` dependency and `WorkspaceAppService` takes the new `IEnumerable` dependency. + +**What to do** + +Create a new EF Core migration and apply it to your database after upgrading. + +If you implement these interfaces yourself, implement the new methods. If you derive from the application services, add the new parameters to your constructors. + +### ABP Suite Extensibility + +**Who is affected** + +- Applications or tools that implement `ICodeFormatter`, or that derive from, replace, or manually construct `CrudPageGenerator`. + +**What changed** + +- `ICodeFormatter` has the new `FormatTypescriptCodeAsync` member. +- `CrudPageGenerator` takes the new `ReactUiGenerateCommand` dependency. + +**What to do** + +Implement the new formatter method in your own `ICodeFormatter`, and pass the new parameter to the `CrudPageGenerator` constructor.