Core
File lifecycle recovery and project Apps
Track files with durable recovery and adopt bundled Grants Management and Professional Services Apps.
This release requires SDK 0.3.1 and the exact App versions recorded in composer.lock. SDK 0.3.0 introduced the breaking authorized import-store intake and unbound-disposal methods, which custom implementations must adopt. SDK 0.3.1 supplies the spreadsheet and import-review contracts used here. Upgrade People and Time & Absence to 0.3.4 with the coordinated locked Apps.
Shared spreadsheet utilities
Core binds Nexia\Spreadsheet\SpreadsheetFiles to one CSV/XLSX file service. Resource transfer, mapped dataset reading, Agent spreadsheet exports and report exports use that service. CSV output escapes formula-like text; XLSX output preserves strings as strings. Reads enforce existing upload structure and row/cell limits.
The SDK host now exposes a lazy NxSpreadsheetEditor backed by Univer. The caller supplies a workbook snapshot and owns saving, authorization and business validation. Dataset import uses this editor for preview-row corrections; the Agent editor remains unchanged. Corrections are bound to the approval proof and rerun the existing App pipeline.
This file API handles tabular values. It does not promise workbook formatting, charts, macros or formula round trips. CSV encoding and delimiter detection remain in the existing mapped-import layer.
The spreadsheet editor and import-review contracts ship in SDK 0.3.1. The matching People and Time & Absence integrations ship in 0.3.4; use the exact coordinated versions in composer.lock.
Bundled project Apps
Core 0.3.1 bundles Grants Management and Professional Services 0.2.0-beta.6. Professional Services manages project delivery, plans, assignments, milestones, deliverables, timesheets and actuals. Grants Management covers funding opportunities, applications, award agreements, sponsor budgets, reporting and settlement evidence.
Install both App tags with this Core and SDK 0.3.1 release. They have no package prerequisite on each other: Grants may link authorized PSA projects and confirmed actuals through Core Resource References, without a direct App dependency, cross-App data migration or automatic project creation.
Data center import flow
Source selection and upload now share one page. Organization import offers ECOUNT, direct column mapping (parent codes or level columns), and a downloadable Nexia template. The tree can be edited before a fresh preview and final application. Direct/template organization files support up to 500 organizations; the first XLSX sheet is read.
Dataset imports can fill missing columns with explicit batch-wide values, correct preview cells, and return from existing reference-creation forms for revalidation. Optional source-profile controls allow the same workspace to be hosted in migration/onboarding stages. Existing ECOUNT personnel parsing and domain application are reused. People 0.3.4 includes the matching source-profile contribution changes.
Organization import now retains the request language in queued errors and supports choosing a header row for direct files. Dataset review can use App-owned reference cards while preserving draft state when opening existing reference editors.
File lifecycle records and delivery evidence
-
App generation and package validation now use the Core/SDK 0.3 line, including the frontend SDK peer requirement.
-
TXT imports accept files ending with a newline without failing at the end of the file.
-
Audit log pagination keeps a stable order when multiple records share a timestamp.
-
Upload intents support an owner-authorized cancellation endpoint. Verified, unconsumed uploads can be cancelled; cancelled uploads cannot be adopted. Staging cleanup retains retryable deletion evidence.
-
File lifecycle records preserve file, checksum, owner and actor snapshots independently of Media and upload-intent deletion. Lifecycle records reject mutation; this does not provide object-store WORM protection.
-
Resource and report downloads record server delivery attempts. Observed terminal outcomes whose audit write fails are retried by
nexia-files:reconcile-delivery-attempts. Server completion does not prove browser receipt. -
Authorized attachment and Agent reads record file integrity evidence. Classic resource imports enforce structural and row/column limits during parsing.
-
Protected Document/Approval/Signature, public identity, App exports, and browser/XML/CSV exports record owner-aware lifecycle or actual delivery evidence. Terminal upload staging remains through signed URL expiry before durable cleanup.
-
Recovery includes failed unbound storage/export cleanup and a bounded dry-run inventory of Media and protected seals. Audit deletion requires a separately granted database operator role and approved owner-specific cutoff; no automatic retention period is introduced.
-
Gateway usage deliveries carry bounded file-handoff metadata with legacy empty-payload digest compatibility. Analysis diagnostics retain input/result hashes; apply the additive central migration with tenant migrations.
Upgrade
Apply the additive tenant migrations before enabling the corresponding writers. For Grants and Professional Services, apply the installed App tenant migrations before enabling each App. Adopt the coordinated SDK contract changes and the Assets source-provenance migration with the consuming code. Existing records are not backfilled with invented historical events; domain retention rules remain unchanged.
Deploy the migrated Core with the new usage ingestor before starting the new Gateway. The production workflow now waits for the authenticated Core bootstrap to report this exact release before deploying Gateway. This avoids sending new file-handoff metadata to old Core or conflicting usage identities on a retry spanning the upgrade.
Import template downloads (organization, dataset, and Resource Transfer CSV/XLSX/TXT) now use the shared generated-file delivery lifecycle, recording exact byte checksums and delivery outcomes while disposing temporary files after streaming. Existing import permissions and spreadsheet writers remain in force.