github clockworklabs/SpacetimeDB v2.11.0
Release v2.11.0

2 hours ago

SpacetimeDB v2.11.0

Security Notice

On September 1, we became aware of a security vulnerability in SpacetimeDB that allowed an attacker who knew a token’s subject and issuer to impersonate the corresponding Identity. We released a patch on September 4 in v2.10.0, upgrading our JWT authentication library to address the issue. We waited 30 days after the release before publicly disclosing the vulnerability to give users time to upgrade. We recommend that everyone running an earlier version upgrade to v2.10.0 or later as soon as possible to avoid being affected by this vulnerability.

We are not aware of any instances of the vulnerability being actively exploited in the wild.

New Features

Human-readable database descriptions

spacetime describe can now print a readable description of a database schema in addition to its machine-readable form. The output makes it easier to inspect tables, reducers, types, indexes, constraints, sequences, schedules, and row-level security rules directly from the CLI.

(#5947)

Improvements

Clearer database update failures

Failed database updates now print the complete error chain instead of only the outermost error. This provides the underlying validation or migration failure directly in CLI and server output, making failed publishes and updates easier to diagnose.

(#6046)

More reliable C# subscriptions and indexes

The C# SDK now handles an unsubscribe request made before a subscription becomes active, permits enum-valued index columns, and validates malformed fixed-size row data instead of risking a divide-by-zero failure.

(#5684)

Clearer custom installation paths

CLI self-install and update behavior now handles custom --root-dir installation paths more consistently, with clearer documentation for self-hosted installations.

(#6008)

Bug Fixes

Fixed generated React projects

spacetime init --template react-ts now writes the generated database name to .env.local. Previously, projects whose generated database name differed from the local project name could be created with a broken initial configuration.

(#5941)

Correct authorization inside HTTP handler transactions

HTTP handlers now preserve the caller's authorization context when opening transactions. This fixes authenticated operations that could incorrectly run with internal authority.

(#5978)

Fixed repeated C++ JWT claim access

C++ modules can now read authentication claims repeatedly without exhausting the underlying byte source.

(#5977)

Additional Changes

  • C# SDK testing now uses the shared SDK test suite and harness, expanding coverage for subscriptions, procedures, views, and connection lifecycle behavior. (#5684)
  • macOS C# quickstart documentation includes the current .NET 10 workaround. (#5727)
  • CLI documentation no longer lists the nonexistent --force option. (#5988)
  • Documentation and agent-facing resources now point to the official SpacetimeDB agent tooling, and the README uses the current X account link. (#6077, #6078)

What's Changed

  • Added human-readable output to spacetime describe in #5947
  • Printed complete error chains for failed database updates in #6046
  • Fixed generated React template database names in .env.local in #5941
  • Fixed authorization context inside HTTP handler transactions in #5978
  • Fixed repeated C++ JWT claim access in #5977
  • Expanded C# SDK test coverage and fixed subscription, enum-index, and malformed-row edge cases in #5684
  • Improved custom --root-dir installation behavior and documentation in #6008
  • Documented the macOS .NET 10 workaround in #5727
  • Removed the nonexistent CLI --force option from documentation in #5988
  • Improved test reliability after memoization lock poisoning in #5846
  • Added SQL parser regression coverage in #5932
  • Updated agent-tooling links and the README social link in #6077 and #6078

Full public changelog: v2.10.2...release/candidate/v2.11.0

Don't miss a new SpacetimeDB release

NewReleases is sending notifications on new releases.