glueful / thallo-collections
Developer-defined data collections with a public CRUD/query API, as a removable Thallo capability pack.
Requires
- php: ^8.3
- glueful/framework: ^1.64.0
- glueful/thallo-contracts: v1.0.0-beta.77
- glueful/thallo-tenancy: v1.0.0-beta.77
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
- dev-main
- v1.0.0-beta.77
- v1.0.0-beta.76
- v1.0.0-beta.75
- v1.0.0-beta.74
- v1.0.0-beta.73
- v1.0.0-beta.72
- v1.0.0-beta.71
- v1.0.0-beta.70
- v1.0.0-beta.69
- v1.0.0-beta.68
- v1.0.0-beta.67
- v1.0.0-beta.66
- v1.0.0-beta.65
- v1.0.0-beta.64
- v1.0.0-beta.63
- v1.0.0-beta.62
- v1.0.0-beta.61
- v1.0.0-beta.60
- v1.0.0-beta.59
- v1.0.0-beta.58
- v1.0.0-beta.57
- v1.0.0-beta.56
- v1.0.0-beta.55
- v1.0.0-beta.54
- v1.0.0-beta.53
- v1.0.0-beta.52
- v1.0.0-beta.51
- v1.0.0-beta.50
- v1.0.0-beta.49
- v1.0.0-beta.48
- v1.0.0-beta.47
- v1.0.0-beta.46
- v1.0.0-beta.45
- v1.0.0-beta.44
- v1.0.0-beta.43
- v1.0.0-beta.42
- v1.0.0-beta.41
- v1.0.0-beta.40
- v1.0.0-beta.39
- v1.0.0-beta.38
- v1.0.0-beta.37
- v1.0.0-beta.36
- v1.0.0-beta.35
- v1.0.0-beta.34
- v1.0.0-beta.33
- v1.0.0-beta.32
- v1.0.0-beta.31
- v1.0.0-beta.30
- v1.0.0-beta.29
- v1.0.0-beta.28
- v1.0.0-beta.27
- v1.0.0-beta.26
- v1.0.0-beta.25
- v1.0.0-beta.24
- v1.0.0-beta.23
- v1.0.0-beta.22
- v1.0.0-beta.21
This package is auto-updated.
Last update: 2026-10-02 11:05:58 UTC
README
Developer-defined data collections for Thallo — schemas backed by
real per-collection tables, with an auto-generated CRUD/query API, an admin
schema builder, per-operation access policies, soft relations, and emitted change events — packaged
as a capability pack. It depends only on the framework and glueful/thallo-contracts, and an
operator can switch it off without touching the core.
Each collection is a first-class table (coll_<name>), not a JSON blob, so rows are queryable,
indexable, and relationable like any other table — while the schema is defined and evolved entirely
through the admin API.
What it provides
- Schema management (
CollectionManager) — create a collection (validated name →coll_<name>table with the standard system columns:id,uuid, timestamps,created_by_*/updated_by_*), add/drop fields, add/remove indexes, replace the access policy, set field order, and drop the collection. In-place field-type changes are blocked; destructive ops require a typed confirmation (waived on an empty table). - Field types —
collections.string(VARCHAR),text(TEXT),integer(INT/BIGINT),decimal,boolean,date,datetime,json,email,url,enum,relation,asset. Each declares filterable/sortable/indexable capabilities. - Public data API —
GET/POST/PATCH/DELETE /v1/collections/{name}(list with filter/sort/ field-projection/expand + offset pagination, get, create, bulk-create, update, delete). Behind an optional API key + a per-collection scope gate (collections.{name}.{read|write|delete}) driven by the collection's access policy. - Admin schema API —
/v1/admin/collections(index/show/store/add-field/drop-field/add-index/ drop-index/update-access/destroy) behindauth+ Aegiscontent_permission. - Access policy — per operation
{read, write, delete}, eachpublic(no auth) orscoped(api-key scope OR the caller's session permission). Defaults to all-scoped. - Soft relations — a
relationfield targets another collection (collection:<name>) or the framework users table (users); existence-validated, one-level batch expand, restrict-on-delete. - Change events — pure
CollectionRow{Created,Updated,Deleted}(data) andCollection{Created,Updated,Dropped}(schema) events for subscribers (audit, analytics, webhooks, search) to consume without coupling to the pack.
The capability
The provider registers a single capability in boot():
new Capability('thallo.collections', label: 'Collections', description: '…');
- Enabled by default. An operator turns it off or on in the admin under Extensions ›
Capabilities. The switch is stored system-wide and overrides the deploy-time
thallo.capabilitiesconfig map. - Gated, not just UI. When disabled, the public + admin routes are never registered (requests
404, not a live-but-disabled handler). Migrations run on install, not enable, so disabling the capability preserves thecollection_definitionsmetadata and everycoll_*data table. - Permissions. The pack declares
collections.manage,collections.schema.manage, andcollections.data.manage; the host app grants them toadministratorin its own dependent migration.
Boundary
Depends on glueful/thallo-contracts and glueful/framework — and never on glueful/thallo (the
application). The repo's composer boundaries check enforces this at both the Composer-dependency
and source level (no Thallo\Core\ references in src/ or routes/).
Install
The pack ships with Thallo: glueful/thallo-core requires it at the same version and the project's
config/serviceproviders.php loads its provider, so there is nothing to install or enable per pack.
Its metadata tables are created by php glueful migrate:run with the rest of the schema.
Switching the capability off (Extensions › Capabilities) drops it from
GET /v1/admin/capabilities, so the collections admin section hides and the public
/v1/collections/* surface is gone. Existing coll_* tables remain on disk.
Contributing
This repository is a read-only mirror, published from
glueful/thallo on every release; its main is overwritten
by the next split, so nothing can land here. Issues and pull requests belong in glueful/thallo,
where this code lives at packages/thallo-collections/.