What’s New
What’s New
More detailed information about changes in each version can be found in GitHub Releases.
v3.0.0
- 🔑 New login endpoint (breaking): the JSON-RPC method
get_jwtis replaced byPOST /{prefix}/{database}/token, which takes the PostgreSQL login and password as HTTP Basic authentication — credentials no longer travel in request bodies, and a reverse proxy can rate-limit logins by URL.get_jwton/jsonrpcnow answers 404 /-32601. Migrate withcurl -X POST …/token -u login:password. - 📥 File downloads: new
POST /{prefix}/{database}/fileendpoint serves binary files from set-returning PostgreSQL functions — one row directly, several rows as a streamed ZIP — with the same authentication, role switching and rate limiting as JSON-RPC.capabilities()reportskind: "file". Re-applysql/schema.sql(it is idempotent) to get the new fields. - 🧰 Tools: new JWT Signer that signs tokens locally in the browser from a hand-entered
JWT_SECRET(no network access, secret never stored), screenshots and hosted versions of every tool (explorer.,sse-tester.,jwt-getter.,jwt-signer.pgarachne.com), clickable tool cards and cross-links. Thetools/folders were renamed toexplorer,jwt-getterandsse-tester— updateSTATIC_FILES_PATHif you serve them. - 🐛 Fixes and hardening: a function returning SQL
NULLnow yields"result": nullinstead of HTTP 500, and/fileZIP paths reject Windows-hostile names and case-insensitive collisions; empty results are rolled back. - 📚 Docs and dependencies: step-by-step Quick Start, JSON-RPC page as a pure reference, a “Why PostgreSQL” architectural decision, reverse-proxy guidance for large downloads, and refreshed Go modules (
golang.org/x/netsecurity update).
v2.2.0
- 🔑 Optional JWT:
JWT_SECRETis no longer required. Without it JWT support is disabled (get_jwtreturns 404 /-32601) and clients use HTTP Basic credentials or API tokens. - 🛡️ Rate limiting for every auth method (security):
LOGIN_RATE_LIMITnow also covers HTTP Basic and Bearer (JWT/API token) attempts on all endpoints, not justget_jwt. Previously passwords could be guessed viaAuthorization: Basicwithout any limit. - 🔒 Privilege-only access (breaking):
pgarachne.allowed_schemas()is removed.capabilities()(and with it MCPtools/listand the OpenAPI export) lists everyjsonbfunction the caller may execute and use the schema of. RevokeEXECUTE/USAGEwhere that is unwanted; see the Security page. - ⚠️ Other breaking changes:
save_idempotency_keynow takes a role scope (re-applysql/schema.sqlbefore upgrading the binary),universal_update/universal_deleterefuse empty filters unless"all": trueis passed, anduniversal_readaccepts only*or plain column names inselect(closes an SQL injection hole). - 🐛 Fixes: SSE deadlock on listener reconnect, slow or wrong-password logins stalling other requests, MCP
prompts/getargument rendering, a malformed function comment breakingcapabilities, falsy results shown as errors in the Explorer, and an XSS in the Explorer result view. - 📚 Docs: new
llms-full.txt, GitHub Sponsors card, tooltips on navbar icons, and this page now also lists v2.0.3 and v2.1.0.
v2.1.0
- 📄 Per-method OpenAPI export:
generate_openapi_spec()now also emits one documentation-only path per exposed method, for tools that expect one operation per path (Swagger UI, Postman, codegen). A newopenapi.yamlendpoint returns the same spec as YAML. - 🔒 Authenticated, role-filtered OpenAPI export:
/openapi.jsonnow requires the same authentication as/jsonrpcand only lists the methods the caller’s role may execute — previously the endpoint was unauthenticated and listed every method to anyone. - 🔌 MCP protocol upgrade: the MCP endpoint now speaks protocol version
2026-07-28exclusively; the oldinitialize/pinghandshake is no longer supported. SeeAGENTS.mdfor the full reference. - 🐛 Connection pool fix: direct-auth (Basic Auth) connection pools are now correctly evicted when idle, fixing an issue where routine password rotation could eventually lock out new credentials.
- 📦 Dependency and CI updates: routine Go dependency refresh (now requires Go 1.26) and matching CI tooling bumps.
v2.0.3
- 🔒 Security hardening: role switching no longer builds SQL via string concatenation (uses the parameterized
set_config()function instead), static file serving now resolves paths throughos.Rootso a symlink can’t escape the served directory, tightened log/PID file permissions, and stricter validation of docs-site search result links. - 🚀 New Quick Start page (all 10 languages): a fast path from install to a working endpoint, without the full Installation/Configuration detour.
- 📄
llms.txtdiscoverability: linked from the homepage, the MCP page, the README, and every page’s header, so LLM crawlers can find it. - 🐛 Fixes: the mobile menu toggle now correctly shows a working Home button on wide screens, the custom 404 page’s links now resolve correctly regardless of URL depth, and the mobile menu gained a “Home” entry.
v2.0.2
- 🔒 Security hardening: Closed several static-analysis findings — HMAC-based (instead of plain SHA-256) direct-auth pool cache keys, an explicit containment check for static file serving, HTML-escaping of the SSE Tester’s login status text, a URL-scheme allowlist for docs-site search result links, and least-privilege permissions on the CI workflow.
- 📦 Dependency updates: Upgraded all Go dependencies, including
gin-gonic/ginto v1.12.0 andlib/pqto v1.12.3 (now requires Go 1.25). - 🌐 3 new languages: The documentation site is now available in Polish, Ukrainian, and Greek — 10 languages total.
v2.0.1
- 🔒 Security fix: Upgraded the transitive HTTP/3 dependency
quic-goto v0.59.1, closing a QPACK trailer expansion vulnerability that could let a malicious peer exhaust memory on the server or client. - 🎨 Docs site polish: New light/dark/auto theme switcher and icon-only language switcher, GitHub/Support icon links in the navbar, fixed double-encoded JSON-LD structured data, and an expanded
llms.txt.
v2.0.0
- 🔒 Secure defaults (breaking):
DB_SSLMODEnow defaults torequire,ALLOWED_ORIGINSno longer defaults to*, andJWT_SECRETmust be at least 32 bytes. Existing deployments must review their configuration before upgrading. - 🧹 Legacy cleanup: Removed the
/api/…and/sse/…redirect routes and the deprecated JSON-RPCloginalias. Use/{prefix}/:database/…andget_jwtdirectly. - 🛡️ Tighter auth & error handling: New per-IP login rate limit (
LOGIN_RATE_LIMIT_PER_IP) closes a credential-spraying gap, and MCP tool errors no longer leak raw PostgreSQL error text by default (opt back in withMCP_SQL_ERROR_DETAIL). - ⚙️ Configurable connection limits: The direct-auth connection pool cap is now configurable via
DIRECT_POOL_LIMIT. - 🔑 External IdP support (BYO JWT): New
JWT_ISSUER,JWT_AUDIENCE, andJWT_LEEWAYsettings bind issued tokens to a specific issuer/audience and tune clock-skew tolerance. - 🧰 New tools: A standalone JWT Getter (
/tools/get-jwt) and SSE Tester (/tools/test-sse) join the Explorer for quick manual testing. - 🐛 Reliability fixes: Fixed a stuck SSE shutdown and a dead-connection recovery bug that could leave the server unable to reconnect to PostgreSQL.
- 🧪 CI hardening: Added
golangci-lint, the Go race detector, andgovulncheckto every build, plus expanded test coverage. - 📦 Release process: Added
CHANGELOG.mdand split the release workflow intomake release-local(build & verify) andmake release(tag, publish, update the Homebrew tap).
v1.3.0
- 🌐 PgArachne Explorer – modern PWA: Complete visual & functional refresh – dark/light theme (auto), responsive cards layout, JSON syntax highlighting, copy-to-clipboard button, better auth UX (password/token tabs), PWA install support (manifest, icons, service worker), shareable links via
?url=…parameter. - 🛠️ Model Context Protocol (MCP) support: New endpoint
/{prefix}/{db}/mcpwith standard methodsresources/list,resources/read,prompts/list,prompts/get– fully backed by PostgreSQL functions and reusing existing auth & role switching. - 🔧 Configurable API prefix: Default changed to
/db/{database}/jsonrpcand/db/{database}/sse, with the legacy/api/…and/sse/…paths kept as 307 redirects for backward compatibility. Controlled via theAPI_PREFIXenvironment variable. - 🛡️ Idempotency protection: Optional
idempotencyKeyfield in JSON-RPC requests – automatic duplicate detection (HTTP 409 + error code on collision) usingpgarachne.save_idempotency_key(). - 📚 Documentation improvements: New /tools/ section with cards (Explorer + upcoming macOS Toolbar), new page “Architectural Decisions”, SECURITY.md with vulnerability reporting instructions, better typography across all languages via TypoLima, improved 404 page support for GitHub Pages.
- 📝 Login method rename: JSON-RPC method
loginrenamed toget_jwt(old name kept as deprecated alias with warning in logs). - 📊 Logging cleanup: When logging to file, console shows only minimal startup info → cleaner output in production/docker environments.
v1.2.0
- 🛡️ Security: Access token validation now occurs before establishing a database connection. Improved protection against IP spoofing (added
TRUSTED_PROXIESsetting) and hiding internal database errors from end users. - 📊 Isolated Metrics: The Prometheus
/metricsendpoint moved from the public API to its own secure port (by default available only on127.0.0.1:9090). - 📦 New Installation Option: The project now has an official Homebrew tap for macOS and Linux. Builds are signed and generated via GoReleaser.
- 📚 Redesigned Documentation: Completely new look built on the Hugo framework. Added lightning-fast full-text search, code copying capabilities, and production deployment examples (Nginx hardening, BYO JWT).
- ⚙️ Improved Daemon Management: Added support for custom
PID_FILEpath configuration.
v1.1.0
- 🔌 Unified API: All calls go through
POST /api/<db>(the called method is specified in the JSON-RPC body). - ⚡ Real-time Notifications: New endpoint
GET /sse/<db>?channels=...for listening to database events with multi-channel support. - 📈 Observability: Detailed Prometheus metrics for HTTP, auth, JSON-RPC, and SSE.
- 🏋️ Major Stability Improvements: Protection against slow clients, strict timeouts, and automatic connection cleanup.