Changelog
What changed in Eddytor, week by week - new features, fixes, and doc updates.
Every notable change to Eddytor, newest first. Entries are grouped by week and split into Added, Changed, and Fixed. For endpoint-level details, see the API reference.
2026-08-26
Added
- Microsoft Fabric is its own connection provider - a three-step wizard (credentials → lakehouse → options) registers a OneLake lakehouse without you typing the account name or base path. See Microsoft Fabric.
Changed
- The Azure Blob connection form is a three-step wizard too - credentials, location, options, and a summary before you connect. Its Use Microsoft Fabric endpoint checkbox is gone; pick the Fabric provider instead.
- Unity Catalog linking is now offered only where it applies - on Azure Blob's options step, never on Fabric.
2026-08-23
Engine v2.8.0 – v2.8.6 · Web UI v2.5.0 – v2.5.3
Added
- Workspace roles now govern per-request authority - what a request may do is decided by the caller's role in the workspace it targets.
- Multi-level domain chains - domains can nest parent/child hierarchies deeper than one level.
- Seed domain mappings from table data - auto-detect reads existing values and creates editable inline mappings in the Web UI.
- Composite primary keys - an atomic endpoint sets a multi-column primary key, and the Web UI designate-PK modal supports it.
- Microsoft Fabric endpoints -
eddytor az storage registergains Fabric endpoint and base-path flags, mirrored in the Web UI register form. - AI Magic overhaul - scoped analysis, filters, refreshed model catalogs, seven new MDM actions, and a redesigned result drawer. See AI analysis.
- Unity Catalog managed tables resolve read-only during storage discovery.
- Storage discovery exclude patterns and Azure tag-filtered browsing.
- Resizable file explorer - drag the Web UI sidebar's right edge to any width between 280 and 600 px, double-click the handle to reset to 320 px. The width is remembered per browser. See Navigating the Web UI.
Fixed
- Setting a single-column primary key now validates for duplicate values first.
- OAuth refresh-token rotation allows a 60-second grace window for replayed requests, so parallel clients no longer get signed out.
- Removing an organisation member now revokes their pending invites and tokens.
- SSO: sign-in is refused when an email domain maps to more than one organisation, invite links grant access only to the organisations they were issued for, and invite matching and re-invite acceptance work reliably.
- Permission guards that name legacy scopes no longer grant roles.
- OAuth client registration rejections now name the reserved
client_namefragments.
2026-08-16
Engine v2.7.6 · Web UI v2.4.3 – v2.4.4
Added
- Rotate storage credentials without re-registering - swap keys on an existing storage connection from CLI, REST, or the Web UI.
- Every REST operation now carries a stable
operationIdin the OpenAPI spec, so generated clients keep their method names across releases. - The Azure admin-consent flow in the Web UI is redesigned into three explicit steps.
Changed
- The account Security tab is renamed Identity.
Fixed
- Tables on Google Cloud Storage survive discovery - the
gs://logstore factory is registered at startup. - The CLI defaults its host to
api.eddytor.com. - OpenAPI spec accuracy: typed 200 responses, correct server URL, security wiring, and media types.
- Row- and column-level security enforcement now also covers Delta merge and delete write paths and additional read paths. See row/column security.
2026-08-09
Engine v2.7.0 – v2.7.5 · Web UI v2.4.0 – v2.4.2
Added
- Workspaces arrive on Eddytor Cloud - a dedicated v2 cluster with workspace-scoped storage. Learn more under Workspaces.
- Device-flow signup -
eddytor logincan create your account and organisation in one step. - OAuth consent screen, dynamic-client-registration hardening, and token-scope enforcement.
- Sidebar workspace switcher in the Web UI.
- SSO connections take a provider-driven issuer URL and can reuse an existing SSO app registration. See SSO (OIDC).
- Storage-account discovery shows visible progress in the Web UI.
Changed
- Auth emails and identity-provider error pages carry Eddytor branding.
Fixed
- Security hardening: stricter rate limiting and request-body size limits, sign-in responses no longer reveal whether an account exists, and sensitive token values no longer appear in logs.
- The magic-link verify page requires POST, so mail scanners can no longer burn the token before you click it.
- The Web UI origin is allowed in the provider-link
return_toallow-list. - The request body cap no longer rejects bodyless requests with
411.
2026-08-02
Engine v2.6.0 · Web UI v2.3.0
Added
- Workspace-owned storage connections - register storage that belongs to a workspace instead of a single user. See shared storage.
- Azure tenant-wide admin consent is surfaced on provider apps.
Fixed
- Policies are grouped and resolved by table UUID instead of fully-qualified name, so renames no longer detach them.
- Workspace share-by dates render in the correct format.
2026-07-26
Engine (pre-v2.6.0) · Web UI v2.2.0
Added
- Row- and column-level security - Cedar-based policies restrict which rows and columns each principal can read or write, manageable from the Web UI. Start at row/column security.
2026-07-19
Added
- Multi-org accounts - one account can belong to several organisations, with credentials bound to the organisation they were issued in.
- Workspaces - a sub-organisation tier with workspace-bound credentials. See switching and credentials.
2026-06-28
Web UI v2.1.1
Added
- This help center launched - guides for deploying, configuring, and operating Eddytor, plus the full table lifecycle.
Fixed
- Explorer: clicking an already-open table no longer leaves it stuck loading.