Core App — Change Log
This log tracks software changes for this area.
Current status
| Item |
Status |
Notes |
| Active development |
Open |
Core infrastructure stabilized and modularized |
| Next release target |
TBA |
Align with policy-based authorization rollout |
| Known risk |
Medium |
Core underpins all apps (permissions + request context critical) |
Recent changes (newest first)
| Date |
Type |
Summary |
Impact |
Reference |
| 2026-04-14 |
Feature |
Introduced policy layer (core.policies) for centralized authorization logic |
High |
policies/ |
| 2026-04-14 |
Refactor |
Moved org resolution logic into request_context service |
High |
services/request_context |
| 2026-04-14 |
Refactor |
Simplified middleware to delegate org resolution |
Medium |
middleware |
| 2026-04-14 |
Feature |
Added audit logging service (log_audit) with structured change tracking |
High |
services/audit |
| 2026-04-14 |
Feature |
Added audit log query helpers (by object, actor, action) |
Medium |
services/audit |
| 2026-04-14 |
Refactor |
Standardized DRF exception envelope via api_exception_handler |
Medium |
exceptions |
| 2026-04-14 |
Feature |
Added DRF mixins for org scoping and audit fields |
Medium |
mixins |
| 2026-04-14 |
Feature |
Introduced storage abstraction (local + S3 public/private) |
Medium |
storage |
| 2026-04-14 |
Feature |
Added upload validation utility (validate_upload) |
Medium |
uploads |
| 2026-04-14 |
Feature |
Added secure token generation utility (generate_share_token) |
Low |
tokens |
| 2026-04-14 |
Refactor |
Removed unused favorites and attachment modules from core |
Low |
cleanup |
| 2026-04-14 |
Test |
Added comprehensive pytest coverage for core services, mixins, and policies |
Medium |
tests/core |
Open items and status
| ID |
Title |
Status |
Priority |
Owner |
Target |
Reference |
| CORE-001 |
Add audit log API endpoints (read/query UI support) |
Open |
P2 |
Unassigned |
TBA |
|
| CORE-002 |
Introduce structured error codes in exception handler |
Open |
P2 |
Unassigned |
TBA |
|
| CORE-003 |
Extend policy system with capability-based permissions (ABAC-lite) |
Open |
P1 |
Unassigned |
TBA |
|
| CORE-004 |
Add request correlation IDs for tracing/logging |
Open |
P2 |
Unassigned |
TBA |
|
| CORE-005 |
Introduce file scanning (virus/content validation) in uploads |
Open |
P1 |
Unassigned |
TBA |
|
| CORE-006 |
Add token expiration and hashing helpers |
Open |
P2 |
Unassigned |
TBA |
|
| CORE-007 |
Add caching layer for org resolution (request_context) |
Open |
P2 |
Unassigned |
TBA |
|
| CORE-008 |
Improve policy test coverage across all apps |
Open |
P2 |
Unassigned |
TBA |
|
Known bugs
| ID |
Symptom |
Severity |
Status |
Workaround |
Reference |
| BUG-CORE-001 |
Missing org context may lead to inconsistent permission behavior if not guarded by permissions |
Medium |
Open |
Always use HasCurrentOrg |
|
| BUG-CORE-002 |
Audit logs may grow unbounded without retention policy |
Medium |
Open |
Manual cleanup or DB retention rules |
|
Breaking changes and migrations
| Date |
Change |
Action required |
Reference |
| 2026-04-14 |
Introduction of policy layer (core.policies) |
Replace direct role checks with policy helpers |
|
| 2026-04-14 |
Org resolution moved to request_context service |
Use request.org or attach_current_org instead of custom logic |
|
| 2026-04-14 |
Exception responses standardized |
Clients should rely on error envelope |
|
Notes
Architecture direction
The core app is evolving into a true platform layer providing:
- request context resolution
- policy-based authorization
- audit logging
- shared infrastructure utilities
Key risks
- Incorrect policy usage may lead to data leaks across tenants
- Request context must always be enforced for org-scoped endpoints
- Audit logging must remain consistent to ensure traceability
Recommended next steps
- Expand policy adoption across all apps
- Add audit log read endpoints
- Introduce structured error codes
- Add upload security enhancements (scanning, validation layers)
Long-term improvements
- Move toward capability-based authorization (RBAC + ABAC hybrid)
- Introduce event-driven audit streaming
- Add global observability (tracing + metrics)
- Implement file lifecycle and retention policies
The core app now serves as the foundation of the backend architecture, ensuring:
- consistency
- security
- scalability
- maintainability