SpacetimeDB v2.11.0
Security Notice
On September 1, we became aware of a security vulnerability in SpacetimeDB that allowed an attacker who knew a token’s subject and issuer to impersonate the corresponding Identity. We released a patch on September 4 in v2.10.0, upgrading our JWT authentication library to address the issue. We waited 30 days after the release before publicly disclosing the vulnerability to give users time to upgrade. We recommend that everyone running an earlier version upgrade to v2.10.0 or later as soon as possible to avoid being affected by this vulnerability.
We are not aware of any instances of the vulnerability being actively exploited in the wild.
New Features
Human-readable database descriptions
spacetime describe can now print a readable description of a database schema in addition to its machine-readable form. The output makes it easier to inspect tables, reducers, types, indexes, constraints, sequences, schedules, and row-level security rules directly from the CLI.
(#5947)
Improvements
Clearer database update failures
Failed database updates now print the complete error chain instead of only the outermost error. This provides the underlying validation or migration failure directly in CLI and server output, making failed publishes and updates easier to diagnose.
(#6046)
More reliable C# subscriptions and indexes
The C# SDK now handles an unsubscribe request made before a subscription becomes active, permits enum-valued index columns, and validates malformed fixed-size row data instead of risking a divide-by-zero failure.
(#5684)
Clearer custom installation paths
CLI self-install and update behavior now handles custom --root-dir installation paths more consistently, with clearer documentation for self-hosted installations.
(#6008)
Bug Fixes
Fixed generated React projects
spacetime init --template react-ts now writes the generated database name to .env.local. Previously, projects whose generated database name differed from the local project name could be created with a broken initial configuration.
(#5941)
Correct authorization inside HTTP handler transactions
HTTP handlers now preserve the caller's authorization context when opening transactions. This fixes authenticated operations that could incorrectly run with internal authority.
(#5978)
Fixed repeated C++ JWT claim access
C++ modules can now read authentication claims repeatedly without exhausting the underlying byte source.
(#5977)
Additional Changes
- C# SDK testing now uses the shared SDK test suite and harness, expanding coverage for subscriptions, procedures, views, and connection lifecycle behavior. (#5684)
- macOS C# quickstart documentation includes the current .NET 10 workaround. (#5727)
- CLI documentation no longer lists the nonexistent
--forceoption. (#5988) - Documentation and agent-facing resources now point to the official SpacetimeDB agent tooling, and the README uses the current X account link. (#6077, #6078)
What's Changed
- Added human-readable output to
spacetime describein #5947 - Printed complete error chains for failed database updates in #6046
- Fixed generated React template database names in
.env.localin #5941 - Fixed authorization context inside HTTP handler transactions in #5978
- Fixed repeated C++ JWT claim access in #5977
- Expanded C# SDK test coverage and fixed subscription, enum-index, and malformed-row edge cases in #5684
- Improved custom
--root-dirinstallation behavior and documentation in #6008 - Documented the macOS .NET 10 workaround in #5727
- Removed the nonexistent CLI
--forceoption from documentation in #5988 - Improved test reliability after memoization lock poisoning in #5846
- Added SQL parser regression coverage in #5932
- Updated agent-tooling links and the README social link in #6077 and #6078
Full public changelog: v2.10.2...release/candidate/v2.11.0