Open Source on GitHub

A django starter for internal apps that leverages the include admin theme and components.

v0.20.1 2 stars 1 forks 12 issues

Changelog

Unreleased

  • 507cf6f: release: v0.20.1 — make lint runs mypy; typed-code convention

v0.20.1

  • f64c662: build: make lint run mypy; document the typed-code convention
  • df189fc: v0.20.0: telemetry becomes machine-drivable, and a read-only token stops being able to write

v0.20.0

  • 8235f05: feat(telemetry): make the logs readable by machines, not just people
  • 80282ba: fix(telemetry): close the gaps a seven-round verification found
  • 92d8f38: fix(api): read-only tokens could write through any custom endpoint
  • 9674fc9: feat(telemetry): staff log viewer at /smallstack/logs/
  • bac6001: docs: close the gaps left by the telemetry and JSON-logging work
  • 6be0ef6: feat(telemetry): write logs to the database so a deployment can be debugged from inside it
  • a41046b: fix(logging): emit real JSON and stamp request IDs on every line
  • dcbd0f8: release: v0.19.0 — operator-grade webhook event selection

v0.19.0

  • a7724c2: feat(webhooks): operator-grade event selection for pairing + endpoints
  • 956779e: release: v0.18.0 — scheduler job control console

v0.18.0

  • 3d7735a: feat(scheduler): redesign the job edit page as a control console
  • 1520fce: release: v0.17.0 — alphabetical admin navigation

v0.17.0

  • d19be79: feat(nav): list the admin section A–Z instead of by hand-assigned order
  • 775f0b1: release: v0.16.2 — empty states no longer leak raw template source

v0.16.2

  • 18fd550: fix(templates): empty states rendered raw template source to users
  • 38bb679: release: v0.16.1 — timezone-correct calendar bounds + AST opt-in detection

v0.16.1

  • 2a92a0a: fix(doctor): detect enable_api opt-ins by AST, matching mcp_doctor
  • 472420a: fix(calendar): compare DateTimeFields against aware month boundaries
  • 9d7dcd2: release: v0.16.0 — calendar volume guard + related-tab and doctor fixes

v0.16.0

  • 9b8a3b0: fix(doctor): stop reporting test-module CRUDViews as unregistered opt-ins
  • 9ee4a88: feat(calendar): cap events rendered per day, with a "+N more" drill-down
  • 450f00e: fix(crud): related tabs 500 without DETAIL, and rendered child rows via parent hooks
  • 68a56f8: release: v0.15.2 — palette-correct light mode + invisible-control fixes

v0.15.2

  • 7304b42: fix(palettes): give django a light block and set --link-fg on every palette
  • f93a9e5: fix(theme): make invisible controls palette-correct on gold + high-contrast
  • 6564c25: build: add pre-commit hook running ruff + mypy
  • 87b6521: chore(typecheck): widen mypy scope to all remaining apps
  • 07afe77: chore(typecheck): widen mypy scope to apps/smallstack (framework core)
  • 4b3f513: chore(typecheck): widen mypy scope to usermanager + tokenmgr + explorer
  • c2f3303: chore(typecheck): widen mypy scope to scheduler + webhooks
  • 9d14e9c: fix(datasets): typecheck under mypy + fix offset string-coercion bug
  • d12b0ff: release: v0.15.1 — F4 test-coverage backfill

v0.15.1

  • 6a04d69: test(crud): cover HTML bulk views — update/delete/form (review F4)
  • ba815d3: test: cover REST bulk-update + MCP write handlers (review F4)
  • 7e21c49: test(api): cover auth endpoints — register, password change, admin reset (review F4)
  • b58c096: test(search): cover PostgresFTSBackend 0%->83% (review F4)
  • f92281a: release: v0.15.0 — secure-by-default CRUDView auth, make typecheck, drop debug-toolbar

v0.15.0

  • 4325c27: feat(crud)!: secure-by-default auth — CRUDViews require login unless public
  • 672501f: feat(dev): add mypy type-checking (make typecheck); remove django-debug-toolbar
  • 2c715ae: release: v0.14.3 — codebase-review fixes (XSS, PKCE, deploy-check, dead-code)

v0.14.3

  • 586b8ae: review(round-2): fix fresh-clone check --deploy (F9) + restore examples tests (F10)
  • 9694cd4: fix(search): remove obsolete test_phase2_integration (imports deleted modules)
  • 9db54da: review(round-1): fix XSS + PKCE timing, delete dead search layer, test integrity
  • ebbfc41: docs(readme): bump version badge to 0.14.2
  • 990f74c: docs: remove quality report-card system; refresh bundled README
  • 4e99be7: release: v0.14.2 — https absolute URLs behind kamal-proxy

v0.14.2

  • 7c1c236: fix(production): trust X-Forwarded-Proto behind the proxy → https absolute URLs
  • 05b9d4b: docs(readme): reframe around "one backend, many roles"; drop report-card section
  • b7c69db: docs(help): add Webhooks and RSS/Atom Feeds reference pages
  • 5771491: release: v0.14.1 — reproducible Docker builds + mcp_doctor AST fix

v0.14.1

  • 480f579: fix(mcp): detect enable_mcp opt-ins via AST, not substring match
  • ce5187c: fix(docker): install from the frozen uv.lock for reproducible prod builds
  • fd5cef0: release: v0.14.0 — Django 6.1 + email MAILERS migration

v0.14.0

  • 54a4fb2: test: silence pre-existing naive-datetime + ResourceWarning noise
  • 1f31eb6: refactor(email): migrate to Django 6.1 MAILERS + drop deprecated fail_silently
  • 97bc84b: chore(deps): upgrade Django 6.0 → 6.1
  • 2446ec0: fix(a11y): WCAG 2.1 AA follow-ups across theme, CRUD, feeds surfaces
  • c39ed1e: fix(feeds): enforce master switch, Django-6 enclosure, consume-side auth
  • a856272: release: v0.13.13 — accessibility foundation + RSS/Atom feeds surface

v0.13.13

  • bffe35a: feat(feeds): first-party RSS/Atom publish + consume surface (apps.feeds)
  • cfa976d: feat(a11y): accessibility primitives + WCAG-AA fixes across the theme
  • 229f6fe: release: v0.13.12 — Postgres search hardening + search diagnostics

v0.13.12

  • 229c731: fix(api): api_view no longer force-parses multipart/form bodies as JSON
  • 984940d: fix(theme): make bare-button styling truly zero-specificity in all states
  • 0fb70c3: perf(api): restrict list-endpoint SELECT to serialized columns via .only()
  • a3bc253: feat(search): Postgres out-of-the-box hardening + search diagnostics
  • ccb261f: release: v0.13.11 — datasets bucketed grouping + drilldown (R8)

v0.13.11

  • 8d21257: feat(datasets): R8 — bucketed grouping in series() + bucket drilldown
  • 1f92b4f: release: v0.13.10 — datasets hardening (filterable, paging, ratio measures, date ranges)

v0.13.10

  • 5d98f0a: feat(datasets): downstream hardening — filterable, queryset seam, paging, ratio measures, date ranges
  • 3105566: release: v0.13.9 — datasets @dataset primitive + help RAG

v0.13.9

  • e426f80: feat(datasets): scalar mode, FK expansion, and hardened API/MCP surfaces
  • 9bbf05a: chore(datasets): complete type annotations on the datasets module
  • 004d6a9: docs(datasets): add datasets.md skill — schema introspection for UI builders
  • a9f1112: feat(datasets): @dataset primitive — filtered querysets as typed rows/columns
  • b86573c: feat(help): lexical RAG passage index + search_help_docs MCP tool
  • bc68644: release: v0.13.8 — webhooks foundation

v0.13.8

  • a67d69d: Merge webhooks foundation into main (v0.13.8)
  • 38ce43d: docs(webhooks): update AI-skill routing + refs for the reshape
  • c763ea2: feat(webhooks): strict is_paired key so pairing never adopts a hand-made object [F-031]
  • 22b10ad: fix(webhooks): harden sc webhook pair — stable slug, two secrets, honest UX [F-031]
  • 5e93347: Integrate acceptance-verified webhooks foundation reshape
  • dfd45c0: docs(webhooks): add 'Recipes per service' matrix to webhooks.md
  • 90ffe01: fix(webhooks): surface pair + bulk replay in the webhook command help [F-030]
  • 07d6f9a: fix(webhooks): doctor WARN + docs for unresolved webhook origin [F-029]
  • 84870a6: feat(webhooks): DX + docs — filter picker, doctor hints, webhooks.md [F-015][F-017][F-018][F-024][F-013]
  • c5dc716: feat(webhooks): Azure Event Grid reference adapter — all four seams, zero core edits [F-028]
  • a3902b5: feat(webhooks): one-step S2S pairing + backward-compat envelope upgrade [F-027][F-014]
  • aa4e03e: feat(webhooks): expose + prove the four extension seams [F-019][F-025][F-016][F-026]
  • 3527fe1: feat(webhooks): stable event_id, Retry-After, bulk dead-letter replay [F-021][F-022][F-023]
  • 2157deb: feat(webhooks): loop guard + seam scaffolding foundation [F-020]
  • a5693c7: fix(lint,tests): drop unused QueryDict import + order-independent MCP tool tests [F-012]
  • 093a27a: docs(webhooks): flag-table rows + no-retry/REST-path/gotcha fixes [F-007,F-009]
  • 2eecf16: fix(webhooks): ops polish — doctor WARN, sc flags, monitor drill-down, disabled hints [F-003,F-008,F-010,F-011]
  • 44bed28: feat(webhooks): secret write-path + detail-page actions [F-004,F-005]
  • c14611e: fix(crud): native-value form bridge for scripted surfaces [F-001,F-002,F-003,F-006]
  • 261745c: docs(changelog): backfill compare-link refs for v0.13.3–v0.13.6