v0.10.0¶
Release Date: 2026-09-06
Highlights¶
- Module path moved to plexusone - The GitHub repository transferred from
grokifytoplexusone; the module path is nowgithub.com/plexusone/systemforge - Cross-app authorization vocabulary -
authz.AppVocabularycontract andVocabularyRegistrygive every Forge platform app one role/permission/scope convention - Shared SpiceDB base schema -
BaseSpiceDBSchemaplus a composition helper assemble the platform base and every registered app fragment
Breaking Changes¶
Module path moved to github.com/plexusone/systemforge¶
The GitHub repository was transferred from the grokify org to plexusone. Update your imports:
// Old
import "github.com/grokify/systemforge/session/bff"
// New
import "github.com/plexusone/systemforge/session/bff"
The package API is unchanged — only the module path moved. The old github.com/grokify/systemforge path still resolves via GitHub's repository-transfer redirect, but will not receive new tags going forward.
Added¶
Cross-App Authorization Vocabulary (authz.AppVocabulary)¶
Every Forge application implements the same authorization contract — its roles, permissions, OAuth scopes, and an optional SpiceDB fragment:
VocabularyRegistry validates on registration: app-name format, {app}:{resource}:{verb} scope naming (with the {app}:admin blanket scope), role-hierarchy coverage, and {app}_-prefixed SpiceDB definitions — so convention drift fails at startup instead of surfacing as an authorization bug. The registry also drives IAM introspection (roles/permissions/scopes per app, AllScopes for consent screens). See docs/authz-conventions.md for the normative two-gate model (role permission and token scope both required) and separation-of-duties guidance.
Shared SpiceDB Base Schema¶
BaseSpiceDBSchema is the platform-owned foundation of a composed ReBAC deployment: principal, organization (membership ladder plus org administration), and platform. Applications never redefine these — they attach via an {app}_org facet definition referencing organization. VocabularyRegistry.ComposeSpiceDBSchema assembles the base plus every registered fragment in registration order, rejecting any duplicate definition.
Fixed¶
- Closed a line-anchored regex bypass in SpiceDB schema-definition detection: a fragment packing two
definitions onto one physical line hid the second from both the{app}_-prefix check and the duplicate-shadowing check, while the raw fragment was still concatenated verbatim into the composed schema — letting an app silently redefine a reserved or foreign definition. Found in review before this release shipped. - Excluded
github.com/KimMachineGun/automemlimitv1.0.0, which removedmemlimit.SetGoMemLimitWithOptsand broke the build viajzelinskie/cobrautil/v2/cobraproclimits(still on a pre-v1.0.0-compatible pseudo-version). - Shared CI workflows now referenced at
plexusone/.github@maininstead of a stale pinned tag, picking up an upstreamcheck-latest: truefix sogo.mod's required Go patch version resolves correctly instead of silently pinning to a stale cached Go release.
Dependencies¶
Notable updates: authzed/spicedb 1.56.0 → 1.56.1, google.golang.org/grpc 1.83.1 → 1.83.2, plus routine transitive bumps via go get -u ./....
Upgrade Notes¶
- Update all imports from
github.com/grokify/systemforge/...togithub.com/plexusone/systemforge/...(no code changes beyond the import path). go get github.com/plexusone/systemforge@v0.10.0 && go mod tidy.- If you reference this module via a local
replacedirective, remove it and pin the tagged version before pushing.