Skip to content

Core

Developer console and current App contracts

0.6.0

Introduce project pairing, local development and deployment review with SDK 0.6.0.

Added

  • Added a developer console with separate developer accounts, project ownership, revocable CLI pairing, immutable deployment versions and administrator review. Discovery advertises project pairing, project management, manifest validation and review submission; remote Functions remain unavailable. Dedicated sandbox hosts provide project-owned Nexia workspaces with expiring owner access.

  • CLI 0.1.0-alpha.3 supports starter initialization, local app reload inside real Nexia Work Tabs and static bundle submission for review. The console provides manual, Docker and AI-assisted setup instructions. Core remains on the operator-managed server and is excluded from developer source and Docker images. Project secrets stay outside the source directory; submissions reject executable server files, hidden files and traversal paths.

  • Reviewers can inspect submitted source and a sandboxed preview before recording a decision. Submission does not publish an App to tenants.

  • App packages can contribute business-result notifications and publish them from durable events through public SDK contracts, using Core recipient authorization, preferences and localized rendering.

  • Policy-based automatic approval records its policy version and evaluated evidence separately from human signatures and delivers a distinguishable bound approval outcome.

  • Added nexia-seed:import --profile=mytec for checksum-validated private seed bundles, existing-tenant imports, and tenant creation through the normal App installer. Validation is read-only unless --apply is supplied. Optional --reset clears supported tenant business data while preserving accounts, organization, and App installations; unsupported data or retained references stop the reset. Supply bundles separately under private storage and the new owner's password through MYTEC_SEED_IMPORT_PASSWORD. Ship the matching App fixture contributions with this command; no SDK or schema change is required.

Changed

  • Reserve platform, development, testing, administration, authentication, infrastructure and AI service hostnames before tenant signup. Domain creation and reassignment enforce the same reservations, including case variants and full platform hostnames; unrelated customer domains remain available.

  • Agent dashboard generation now prefers matching registered recipes, existing widgets, and ready reports before creating a new report. New report-backed widgets are grounded in catalog previews, including the available data shape, grain, labels, period, scope, and presentation.

  • dashboard.compose(final:false) keeps a partial registered-widget composition available while the Agent prepares report-backed gaps. Omitting final continues to finish the dashboard immediately.

  • Newly generated report widgets size to their initial content. Saved or manually arranged dashboard geometry remains unchanged.

  • Report exploration now displays authorized human reference labels across the user's all-scope Operating Unit targets. Report-exploration choices use those labels rather than internal identifiers; references that cannot be resolved remain non-identifying.

  • Resource Composition now uses one current schema-1 contract. It requires explicit population semantics, uses where for typed predicates, and exposes semantic capabilities from capabilities.composition.features without version negotiation or a rollout flag.

  • The current composition planner supports bounded native-source, inverse, forward exact-reference, canonical-alignment, and temporal paths. Declared decimal results use canonical numeric strings; unsupported shapes, ambiguous temporal matches, invalid owner intervals, and duplicate or null provider grains are refused in the execution snapshot.

  • Forward polymorphic references include the owner-published discriminator, so equal public IDs from another target cannot join. Pivot rollups are available for supported native and forward aggregate plans and are separately replanned from authorized source data.

  • Agent report creation and query now reauthorize current source access; the focused lifecycle flow also refuses export and scheduling after the source App is disabled.

  • npm packages move to the @nexia organization: @amuzcorp/nexia-app-sdk-react becomes @nexia/sdk, @amuzcorp/nexia-cli becomes @nexia/cli, and the development packages become @nexia/dev-client and @nexia/dev-protocol.

  • Developer accounts remain independent of production workspace accounts and subscriptions. Each account may have one active sandbox; provisioning and deletion reserve that slot. Owners can renew to seven days from the renewal time, delete their sandbox and create a replacement. Deleted sandbox records and creation, renewal and deletion events are retained. Expired sandboxes deny access and may be renewed only when the account has no other active sandbox.

Fixed

  • Developer sandbox deletion cleans its private and public object-storage prefixes while retaining lifecycle history. Failed cleanup keeps the sandbox's slot reserved until deletion is retried successfully.

  • Demo report reseeding now runs provider grain validation and report execution in one repeatable-read snapshot, allowing unchanged stale reports to receive a new revision while preserving dry-run rollback.

  • Resource Composition preserves exact large monetary values through numeric aggregation and report display instead of silently converting them to floating-point values.

  • Related-resource Inspectors now keep their close button when opened from a detail page without a selected list row.

  • Seed import failures now show an exception type and HTTP status when the underlying error has no message, including in the failure receipt.

  • Seed imports synchronize the selected tenant's permission catalog before writing fixtures, including when an already-installed App gains new permissions. Check mode remains read-only.

Upgrade required

  • Install SDK PHP and React 0.6.0 and the matching App releases before upgrading to Core 0.6.0. Run central migrations to create the developer workspace tables. Developer accounts and CLI connections are separate from tenant and administrator authentication.

  • Adopt the matching SDK notification and automatic-approval contracts before this Core change, run tenant migrations, and synchronize permission catalogs. Automatic approval remains disabled until an administrator activates a policy for a binding with an App fact provider.

  • The optional period_stock and demand_orders datasets require the matching Inventory and Demand Planning fixture App versions, their tenant migrations, and the corresponding installed Apps before import. Existing bundles without these datasets remain valid. Apply an incremental bundle to an existing tenant with --apply and omit --reset.

  • Reset persisted development data before adopting the current schema-1 contract. Old Resource Composition payload shapes are not converted at runtime. Install matching App SDK and owner App releases so descriptors and providers can publish the required references, interval metadata, discriminator bindings, and authorized source fields.

  • Replace the old npm dependency names and imports, including the SDK /host and /testing subpaths, and regenerate dependency locks. Existing published versions and distribution tags are retained under the new names; use the same version constraints.

  • Use npm install --global @nexia/cli@alpha for the CLI. The executable remains nexia.

  • The former @amuzcorp npm packages are removed after migration. Old npm locks and imports must be updated before reinstalling; the old package names are no longer an installation fallback.

  • Composer package names, PHP namespaces, and GitHub repositories are unchanged. Existing immutable release records retain their original names.

  • Apply the new Central lifecycle and foreign-key index migrations before serving the developer console. Use APP_ENV=developers with the included Horizon supervisors so sandbox provisioning is consumed. The removed DEVELOPER_SANDBOXES_PER_ACCOUNT override no longer changes the one-active-sandbox policy.

  • Developer environments can set PRODUCT_STORAGE_PROXY_UPLOADS=true to stream authenticated Upload Intent requests into the private bucket without per-sandbox CORS rules.