Conversation
Pass user and company ids into form, list, and header button modifier eval; validate required fields from resolveFieldModifiers on save. Document list column and empty action context limits in CONTRIBUTING.
Add document parsing with t-name templates, safe expressions, merged static and dynamic class attrs, t-set over remaining siblings, and scope destructuring in named templates. Fix self-closing tags and add composition runtime tests.
Load security/sys.field.access.csv on module sync, validate model and field names, and warn on orphan rows after sync. Document CSV format and list export in MODULE_STANDARD.
Add GET/POST /web/settings/field-acl for system admins, batch upsert of sys.field.access deny rules, menu and URL action, flash messages, and hub CSS.
Point menu_general_settings at action_settings.hub (/web/settings) and stop syncing the legacy window action; keep a minimal res.config.settings model/view for CRM inherit only.
Add category cards with dedupe and hub template/CSS; exclude hub nav from center cards.
Consolidate settings nav rules, map URL actions to direct paths, force /web/settings for menu_general_settings, and hide Personal/Account security from the settings sidebar.
…oute Remove password flow from the hub; restore /web/settings/account; align shell page data and tests.
Send menu_general_settings + res.config.settings workspace hits to /web/settings.
Move field-access URL actions into security_actions, add model ACL hub action, and link form views to the matrix pages.
Expose field/model ACL routes and map matrix menu XML ids to hub URLs for correct sidebar links and active highlight.
Add shared ACL matrix helpers, effective-rights labels, and a settings hub field-acl page with model/group filters and safe CSV download.
Persist sys.access rows from the settings hub, register routes, and flash feedback after save.
Document matrix conventions in MODULE_STANDARD and expose test hooks for matrix row naming and CSV disposition safety.
Platform P1: record store, commands, debug, modifiers, Sum composition, settings hub & security matrices (SUM-PLAT-07–12, 26)
README updated
CHINMAYVIVEK
approved these changes
Sep 29, 2026
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Promotes
devtomainfor the Sumeru kernel: a broad security hardening pass, P0 platform parity (SUM-PLAT-01 through SUM-PLAT-05), engineering standards (test layout, lint/Makefile, render shell), and core/parser/module fixes merged via PR #100.Security (SUM-SEC)
csrf_secretrequirement__Host-session cookies, centralized cookie helpers, Secure policydatasredactionP0 platform parity
orm.WithElevatedEngineering & shell (incl. PR #95 “platform” hygiene)
sumeru/test/;testexports.gopattern documentedtrue/falseCore fixes (PR #100 and related)
&in field maps, eval0/1as numbersMerged PRs (high level)
Out of scope (follow-up)
platformis 27 commits ahead ofdev(SUM-PLAT-07–12, debug/command palette, settings hub, field/model ACL matrices, collection-bar UX, etc.). Thisdev→mainPR does not include that work unlessplatformis merged intodevfirst.Upgrade / deploy notes
cd sumeru && makeon the release tag/commit before tagging.base,mail, security CSV changes) on each database after deploy.csrf_secretand review cookie/HTTPS settings in production.Test plan
dev(make/ GitHub Actions)<xpath>extensions