Skip to content

v0.10.0

Release Date: 2026-09-06

Highlights

  • Module path moved to plexusone - The GitHub repository transferred from grokify to plexusone; the module path is now github.com/plexusone/systemforge
  • Cross-app authorization vocabulary - authz.AppVocabulary contract and VocabularyRegistry give every Forge platform app one role/permission/scope convention
  • Shared SpiceDB base schema - BaseSpiceDBSchema plus a composition helper assemble the platform base and every registered app fragment

Breaking Changes

Module path moved to github.com/plexusone/systemforge

The GitHub repository was transferred from the grokify org to plexusone. Update your imports:

// Old
import "github.com/grokify/systemforge/session/bff"

// New
import "github.com/plexusone/systemforge/session/bff"

The package API is unchanged — only the module path moved. The old github.com/grokify/systemforge path still resolves via GitHub's repository-transfer redirect, but will not receive new tags going forward.

Added

Cross-App Authorization Vocabulary (authz.AppVocabulary)

Every Forge application implements the same authorization contract — its roles, permissions, OAuth scopes, and an optional SpiceDB fragment:

import "github.com/plexusone/systemforge/authz"

VocabularyRegistry validates on registration: app-name format, {app}:{resource}:{verb} scope naming (with the {app}:admin blanket scope), role-hierarchy coverage, and {app}_-prefixed SpiceDB definitions — so convention drift fails at startup instead of surfacing as an authorization bug. The registry also drives IAM introspection (roles/permissions/scopes per app, AllScopes for consent screens). See docs/authz-conventions.md for the normative two-gate model (role permission and token scope both required) and separation-of-duties guidance.

Shared SpiceDB Base Schema

BaseSpiceDBSchema is the platform-owned foundation of a composed ReBAC deployment: principal, organization (membership ladder plus org administration), and platform. Applications never redefine these — they attach via an {app}_org facet definition referencing organization. VocabularyRegistry.ComposeSpiceDBSchema assembles the base plus every registered fragment in registration order, rejecting any duplicate definition.

Fixed

  • Closed a line-anchored regex bypass in SpiceDB schema-definition detection: a fragment packing two definitions onto one physical line hid the second from both the {app}_-prefix check and the duplicate-shadowing check, while the raw fragment was still concatenated verbatim into the composed schema — letting an app silently redefine a reserved or foreign definition. Found in review before this release shipped.
  • Excluded github.com/KimMachineGun/automemlimit v1.0.0, which removed memlimit.SetGoMemLimitWithOpts and broke the build via jzelinskie/cobrautil/v2/cobraproclimits (still on a pre-v1.0.0-compatible pseudo-version).
  • Shared CI workflows now referenced at plexusone/.github@main instead of a stale pinned tag, picking up an upstream check-latest: true fix so go.mod's required Go patch version resolves correctly instead of silently pinning to a stale cached Go release.

Dependencies

Notable updates: authzed/spicedb 1.56.0 → 1.56.1, google.golang.org/grpc 1.83.1 → 1.83.2, plus routine transitive bumps via go get -u ./....

Upgrade Notes

  1. Update all imports from github.com/grokify/systemforge/... to github.com/plexusone/systemforge/... (no code changes beyond the import path).
  2. go get github.com/plexusone/systemforge@v0.10.0 && go mod tidy.
  3. If you reference this module via a local replace directive, remove it and pin the tagged version before pushing.