What’s New

7 min read

What’s New

More detailed information about changes in each version can be found in GitHub Releases.

v3.0.0

  • 🔑 New login endpoint (breaking): the JSON-RPC method get_jwt is replaced by POST /{prefix}/{database}/token, which takes the PostgreSQL login and password as HTTP Basic authentication — credentials no longer travel in request bodies, and a reverse proxy can rate-limit logins by URL. get_jwt on /jsonrpc now answers 404 / -32601. Migrate with curl -X POST …/token -u login:password.
  • 📥 File downloads: new POST /{prefix}/{database}/file endpoint serves binary files from set-returning PostgreSQL functions — one row directly, several rows as a streamed ZIP — with the same authentication, role switching and rate limiting as JSON-RPC. capabilities() reports kind: "file". Re-apply sql/schema.sql (it is idempotent) to get the new fields.
  • 🧰 Tools: new JWT Signer that signs tokens locally in the browser from a hand-entered JWT_SECRET (no network access, secret never stored), screenshots and hosted versions of every tool (explorer., sse-tester., jwt-getter., jwt-signer.pgarachne.com), clickable tool cards and cross-links. The tools/ folders were renamed to explorer, jwt-getter and sse-tester — update STATIC_FILES_PATH if you serve them.
  • 🐛 Fixes and hardening: a function returning SQL NULL now yields "result": null instead of HTTP 500, and /file ZIP paths reject Windows-hostile names and case-insensitive collisions; empty results are rolled back.
  • 📚 Docs and dependencies: step-by-step Quick Start, JSON-RPC page as a pure reference, a “Why PostgreSQL” architectural decision, reverse-proxy guidance for large downloads, and refreshed Go modules (golang.org/x/net security update).

v2.2.0

  • 🔑 Optional JWT: JWT_SECRET is no longer required. Without it JWT support is disabled (get_jwt returns 404 / -32601) and clients use HTTP Basic credentials or API tokens.
  • 🛡️ Rate limiting for every auth method (security): LOGIN_RATE_LIMIT now also covers HTTP Basic and Bearer (JWT/API token) attempts on all endpoints, not just get_jwt. Previously passwords could be guessed via Authorization: Basic without any limit.
  • 🔒 Privilege-only access (breaking): pgarachne.allowed_schemas() is removed. capabilities() (and with it MCP tools/list and the OpenAPI export) lists every jsonb function the caller may execute and use the schema of. Revoke EXECUTE/USAGE where that is unwanted; see the Security page.
  • ⚠️ Other breaking changes: save_idempotency_key now takes a role scope (re-apply sql/schema.sql before upgrading the binary), universal_update/universal_delete refuse empty filters unless "all": true is passed, and universal_read accepts only * or plain column names in select (closes an SQL injection hole).
  • 🐛 Fixes: SSE deadlock on listener reconnect, slow or wrong-password logins stalling other requests, MCP prompts/get argument rendering, a malformed function comment breaking capabilities, falsy results shown as errors in the Explorer, and an XSS in the Explorer result view.
  • 📚 Docs: new llms-full.txt, GitHub Sponsors card, tooltips on navbar icons, and this page now also lists v2.0.3 and v2.1.0.

v2.1.0

  • 📄 Per-method OpenAPI export: generate_openapi_spec() now also emits one documentation-only path per exposed method, for tools that expect one operation per path (Swagger UI, Postman, codegen). A new openapi.yaml endpoint returns the same spec as YAML.
  • 🔒 Authenticated, role-filtered OpenAPI export: /openapi.json now requires the same authentication as /jsonrpc and only lists the methods the caller’s role may execute — previously the endpoint was unauthenticated and listed every method to anyone.
  • 🔌 MCP protocol upgrade: the MCP endpoint now speaks protocol version 2026-07-28 exclusively; the old initialize/ping handshake is no longer supported. See AGENTS.md for the full reference.
  • 🐛 Connection pool fix: direct-auth (Basic Auth) connection pools are now correctly evicted when idle, fixing an issue where routine password rotation could eventually lock out new credentials.
  • 📦 Dependency and CI updates: routine Go dependency refresh (now requires Go 1.26) and matching CI tooling bumps.

v2.0.3

  • 🔒 Security hardening: role switching no longer builds SQL via string concatenation (uses the parameterized set_config() function instead), static file serving now resolves paths through os.Root so a symlink can’t escape the served directory, tightened log/PID file permissions, and stricter validation of docs-site search result links.
  • 🚀 New Quick Start page (all 10 languages): a fast path from install to a working endpoint, without the full Installation/Configuration detour.
  • 📄 llms.txt discoverability: linked from the homepage, the MCP page, the README, and every page’s header, so LLM crawlers can find it.
  • 🐛 Fixes: the mobile menu toggle now correctly shows a working Home button on wide screens, the custom 404 page’s links now resolve correctly regardless of URL depth, and the mobile menu gained a “Home” entry.

v2.0.2

  • 🔒 Security hardening: Closed several static-analysis findings — HMAC-based (instead of plain SHA-256) direct-auth pool cache keys, an explicit containment check for static file serving, HTML-escaping of the SSE Tester’s login status text, a URL-scheme allowlist for docs-site search result links, and least-privilege permissions on the CI workflow.
  • 📦 Dependency updates: Upgraded all Go dependencies, including gin-gonic/gin to v1.12.0 and lib/pq to v1.12.3 (now requires Go 1.25).
  • 🌐 3 new languages: The documentation site is now available in Polish, Ukrainian, and Greek — 10 languages total.

v2.0.1

  • 🔒 Security fix: Upgraded the transitive HTTP/3 dependency quic-go to v0.59.1, closing a QPACK trailer expansion vulnerability that could let a malicious peer exhaust memory on the server or client.
  • 🎨 Docs site polish: New light/dark/auto theme switcher and icon-only language switcher, GitHub/Support icon links in the navbar, fixed double-encoded JSON-LD structured data, and an expanded llms.txt.

v2.0.0

  • 🔒 Secure defaults (breaking): DB_SSLMODE now defaults to require, ALLOWED_ORIGINS no longer defaults to *, and JWT_SECRET must be at least 32 bytes. Existing deployments must review their configuration before upgrading.
  • 🧹 Legacy cleanup: Removed the /api/… and /sse/… redirect routes and the deprecated JSON-RPC login alias. Use /{prefix}/:database/… and get_jwt directly.
  • 🛡️ Tighter auth & error handling: New per-IP login rate limit (LOGIN_RATE_LIMIT_PER_IP) closes a credential-spraying gap, and MCP tool errors no longer leak raw PostgreSQL error text by default (opt back in with MCP_SQL_ERROR_DETAIL).
  • ⚙️ Configurable connection limits: The direct-auth connection pool cap is now configurable via DIRECT_POOL_LIMIT.
  • 🔑 External IdP support (BYO JWT): New JWT_ISSUER, JWT_AUDIENCE, and JWT_LEEWAY settings bind issued tokens to a specific issuer/audience and tune clock-skew tolerance.
  • 🧰 New tools: A standalone JWT Getter (/tools/get-jwt) and SSE Tester (/tools/test-sse) join the Explorer for quick manual testing.
  • 🐛 Reliability fixes: Fixed a stuck SSE shutdown and a dead-connection recovery bug that could leave the server unable to reconnect to PostgreSQL.
  • 🧪 CI hardening: Added golangci-lint, the Go race detector, and govulncheck to every build, plus expanded test coverage.
  • 📦 Release process: Added CHANGELOG.md and split the release workflow into make release-local (build & verify) and make release (tag, publish, update the Homebrew tap).

v1.3.0

  • 🌐 PgArachne Explorer – modern PWA: Complete visual & functional refresh – dark/light theme (auto), responsive cards layout, JSON syntax highlighting, copy-to-clipboard button, better auth UX (password/token tabs), PWA install support (manifest, icons, service worker), shareable links via ?url=… parameter.
  • 🛠️ Model Context Protocol (MCP) support: New endpoint /{prefix}/{db}/mcp with standard methods resources/list, resources/read, prompts/list, prompts/get – fully backed by PostgreSQL functions and reusing existing auth & role switching.
  • 🔧 Configurable API prefix: Default changed to /db/{database}/jsonrpc and /db/{database}/sse, with the legacy /api/… and /sse/… paths kept as 307 redirects for backward compatibility. Controlled via the API_PREFIX environment variable.
  • 🛡️ Idempotency protection: Optional idempotencyKey field in JSON-RPC requests – automatic duplicate detection (HTTP 409 + error code on collision) using pgarachne.save_idempotency_key().
  • 📚 Documentation improvements: New /tools/ section with cards (Explorer + upcoming macOS Toolbar), new page “Architectural Decisions”, SECURITY.md with vulnerability reporting instructions, better typography across all languages via TypoLima, improved 404 page support for GitHub Pages.
  • 📝 Login method rename: JSON-RPC method login renamed to get_jwt (old name kept as deprecated alias with warning in logs).
  • 📊 Logging cleanup: When logging to file, console shows only minimal startup info → cleaner output in production/docker environments.

v1.2.0

  • 🛡️ Security: Access token validation now occurs before establishing a database connection. Improved protection against IP spoofing (added TRUSTED_PROXIES setting) and hiding internal database errors from end users.
  • 📊 Isolated Metrics: The Prometheus /metrics endpoint moved from the public API to its own secure port (by default available only on 127.0.0.1:9090).
  • 📦 New Installation Option: The project now has an official Homebrew tap for macOS and Linux. Builds are signed and generated via GoReleaser.
  • 📚 Redesigned Documentation: Completely new look built on the Hugo framework. Added lightning-fast full-text search, code copying capabilities, and production deployment examples (Nginx hardening, BYO JWT).
  • ⚙️ Improved Daemon Management: Added support for custom PID_FILE path configuration.

v1.1.0

  • 🔌 Unified API: All calls go through POST /api/<db> (the called method is specified in the JSON-RPC body).
  • ⚡ Real-time Notifications: New endpoint GET /sse/<db>?channels=... for listening to database events with multi-channel support.
  • 📈 Observability: Detailed Prometheus metrics for HTTP, auth, JSON-RPC, and SSE.
  • 🏋️ Major Stability Improvements: Protection against slow clients, strict timeouts, and automatic connection cleanup.