NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #4160 most downloaded on pub.dev
Bones_API - A powerful API backend framework for Dart. It comes with a built-in HTTP Server, route handler, entity handler, SQL translator, and DB adapters.
Last release 16 days ago
02 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
353 releases · first in 2021
Now checks for missing reference columns.
DBSQLAdapter:
ALTER TABLE with CONSTRAINTs.SQLGenerator:
generateAddColumnAlterTableSQL:
FOREIGN KEY and UNIQUE.buildSQL: implement ifNotExists for ADD COLUMN.
AlterTableSQL:
indexes.buildSQL: implement ifNotExists for ADD COLUMN.SQLGenerator:
generateAddColumnAlterTableSQL.DBSQLAdapter:
checkDBTables:
ALTER TABLE SQLs to fix missing table columns.One column per quarter.
Added checkDB: checks DB tables and fields.
DBAdapter:
checkDB: checks DB tables and fields.
generateTables to checkDB.createPoolElement: optimize calls to createConnection when creating multiple connections simultaneously.FieldsFromMap:
getFieldsKeysInMap.TableScheme:
relationshipTables.EntityHandler:
valueToDynamicNumber for DateTime types.APIEntityTypeNullableExtension to avoid resolution to APIEntityObjectExtension on Type? variables.SQLBuilder: added logger and messages.DBMySQLAdapter:
TIME SQL type as Time class.Fix _jsonEncodableProvider: do not use EntityHandler if there's a registered ClassReflection.
Json:
_jsonEncodableProvider: do not use EntityHandler if there's a registered ClassReflection.APIServer:
_toJsonEncodableAccessRules when there's an EntityAccessRules for
an entity but there's no encodable function.Force POST request if any parameter is a List or Map.
APIModuleHttpProxy:
POST request if any parameter is a List or Map.APIRouteBuilder.resolveValueByType:
_resolveValueType to resolveValueByTypeList, Set and Map parameters.- reflection_factory: ^2.1.0
Added _credential field to allow return (by get credential) of the APICredential instance used in the authentication process.
APIAuthentication:
_credential field to allow return (by get credential) of the APICredential instance used in the authentication process.Added authenticateMultiple for when the request has an APICredential and also a payload with credential.
APISecurity:
authenticateMultiple for when the request has an APICredential and also a payload with credential.APICredential:
originalCredential field.APICredential.fromMap and checkCredential.APIDBModule: Added credential support.- Time.toString: - Fix withSeconds parameter. - Added Time.copyWith.
Time.toString:
withSeconds parameter.Time.copyWith.- reflection_factory: ^2.0.7 - hotreloader: ^3.0.6 - statistics: ^1.0.25 - petitparser: ^5.3.0 - meta: ^1.9.1
- decodeQueryStringParameters: - Added parameter charset. - swiss_knife: ^3.1.5 - resource_portable: ^3.0.2 - archive: ^3.3.7
decodeQueryStringParameters:
charset.- APIRoot: - Added loadDependencies.
APIRoot:
loadDependencies.- New HTMLDocument. - APIDBModule: - Added insert & update support. - Added delete operation. - Added UI (HTML). - EntityHandler: - Added resolveIDs.
HTMLDocument.APIDBModule:
EntityHandler:
resolveIDs.resolveValueByType.- EntityReferenceList: - Fix add.
EntityReferenceList:
add.Added constructor EntityField.indexed().
CreateIndexSQL.EntityField:
_indexed and isIndexed.EntityField.indexed().DBSQLAdapter:
entityRepositoriesBuildOrder.DBAdapter:
allRepositories:
entityRepositoriesBuildOrder to return the repositores in the build order.APIDBModule:
tables: list repositories ordered by name.dump: list repositories in build order to allow use of the dump to populate a DB.Fix call to bucket.info: replace with _getObjectInfo & try/catch.
DBObjectGCSAdapter:
bucket.info: replace with _getObjectInfo & try/catch.New library: bones_api_db_gcp.dart.
DBObjectGCSAdapter.bones_api_db_gcp.dart.DBObjectDirectoryAdapter: clean code.DBEntityRepositoryProvider:
requiredAdapters and requiredEntityRepositoryProviders:
initializeDependencies.Base class for DBObjectMemoryAdapter and DBObjectDirectoryAdapter.
DBObjectAdapter:
DBObjectMemoryAdapter and DBObjectDirectoryAdapter.DBAdapterRegister:
DBAdapter registration, avoiding repetitive static code in
DBSQLAdapter, DBObjectAdapter and DBRelationalAdapter.EntityHandler
equalsValuesEntityMap.getEntityIDFrom.equalsValuesEntity now also using equalsValuesEntityMap.
DBSQLMemoryAdapter.disposeEntities: force _resolveID before dispose.
EntityReference:
disposeEntities: force _resolveID before dispose.EntityReferenceList:
disposeEntities: force _resolveIDs before dispose.APIRouteBuilder:
_resolveValueType: resulve List, Set, Map generic types.Added REDIRECT: to perform URL/Location redirects.
APIResponseStatus
REDIRECT: to perform URL/Location redirects._normalizeID: ensure safe ID for File path.
DBObjectDirectoryAdapter:
_normalizeID: ensure safe ID for File path.EntityReferenceBase:
_getEntityID: allow use of dynamic.id if there's not EntityHandler.- petitparser: ^5.2.0 - postgres: ^2.6.1
Added allowRequestLetsEncryptCertificate.
APIServer:
allowRequestLetsEncryptCertificate.IterableEntityRepositoryProviderExtension:
EntityHandler:
isValidEntityType.APIToken:
generateToken.IterableEntityRepositoryProviderExtension:
getEntityRepository: added parameter removeClosedProviders.Added getAsMap, getAsList, getAs.
APIConfig:
getAsMap, getAsList, getAs.WithRuntimeTypeNameSafe.ExtensionRuntimeTypeNameUnsafe:
runtimeTypeNameUnsafeavoid_dynamic_calls.avoid_type_to_string.no_runtimeType_toString.discarded_futures.no_adjacent_strings_in_list.Improve internal use of EntityCache.
EntityCache.EntityReferenceBase:
_entityCache._InitializationChain._isParent.APIModuleHttpProxy:
onCall: using Json.decoder with EntityHandlerProvider.globalProvider.Json:
decoder.Json.defaultFieldValueResolver:
Json.defaultFieldValueResolver:
EntityReference and ``.Adde properties globalRules and noGlobalRules.
APIRouteRule:
globalRules and noGlobalRules.- Added APIEntityRules.
APIEntityRules.New APIEntityAccessRules, EntityAccessRules, EntityAccessRulesCached and EntityAccessRulesContext:
APIEntityAccessRules, EntityAccessRules, EntityAccessRulesCached and EntityAccessRulesContext:MergeEntityResolutionRulesError to MergeEntityRulesError.ValidateEntityResolutionRulesError to ValidateEntityRulesError.EntityAccessRules and EntityResolutionRules now extends EntityRules.APIRouteHandler:
entityAccessRules.entityResolutionRules.APIResponse:
apiRequest.EntityReferenceBase:
toJson: added parameter jsonEncoder.
jsonEncoder.Json:
toJson: expose parameter toEncodableProvider.APIServer:
resolveBody:
EntityAccessRules of the context.copyWith: added conflictingEntityTypes.
EntityResolutionRules:
mergeTolerant.copyWith: added conflictingEntityTypes.merge: allowing conflicting merge when mergeTolerant is present.Added innocuous const instance.
EntityResolutionRules:
innocuous const instance.isInnocuous, isValid, validate.copyWith and merge.ValidateEntityResolutionRulesError and MergeEntityResolutionRulesError.EntityRulesResolver.
resolveEntityResolutionRules: returns a EntityResolutionRulesResolved.registerContextProvider(EntityRulesContextProvider).APIRoot:
EntityRulesResolver.registerContextProvider.APIEntityResolutionRules.APIRouteHandler: added entityResolutionRules.APIRequest: added routeHandler.bones_api_entity_rules.dart.Better handling of errors: throwing with StackTrace.
APIRoot._callZoned:
StackTrace.EntityResolutionRules:
isEagerEntityTypeInfo and isLazyEntityTypeInfo.DBEntityRepository:
resolveEntities and _resolveEntitiesSubEntities.APIServer:
_sendAPIResponse: better handling of error response.Time.parse:
String as bytes.Remove unecessary UPDATE CASCADE for id (auto increment) references.
SQLGenerator:
UPDATE CASCADE for id (auto increment) references.Fix getEntityByID implementation: wasn't passing parameter resolutionRules to sub-calls.
TransactionEntityProvider:
getEntityByID implementation: wasn't passing parameter resolutionRules to sub-calls._ensureRelationshipsStored: avoid store of relationship fields if not in changedFields.
DBRelationalEntityRepository:
_ensureRelationshipsStored: avoid store of relationship fields if not in changedFields.DBMemorySQLAdapter and DBMemoryObjectAdapter:
TableScheme without relationship fields duplicated in the main fields.Updated bones_api_template.tar.gz.
testAPIServer tool.bones_api_template.tar.gz.- reflection_factory: ^1.2.21
- reflection_factory: ^1.2.19
defaultApiCacheControl and defaultStaticFilesCacheControl:
APIServer:
defaultApiCacheControl and defaultStaticFilesCacheControl:
no-transform directive.Added fields: apiCacheControl and staticFilesCacheControl.
APIServer:
apiCacheControl and staticFilesCacheControl.cache-control default values.- statistics: ^1.0.24 - resource_portable: ^3.0.1 - swiss_knife: ^3.1.3 - archive: ^3.3.5 - mercury_client: ^2.1.8
DBAdapter and DBRepositoryAdapter:
DBAdapter and DBRepositoryAdapter:
doSelectAllDBMemoryObjectAdapter:
doSelectAll.APIDBModule:
dump route.APIRoot._callZoned: fix error handling.
APIRoot._callZoned: fix error handling.Added constructor parameter name and onlyOnDevelopment.
APIDBModule:
name and onlyOnDevelopment.APISecurity:
authenticate with request parameter from an APIModule.Allow method routes with parameter APIAuthentication.
APIModule:
APIAuthentication.APIRoot._callZoned: ensure that is catching Future errors.APIConfig.development to inform development environment.APIDBModule: a development module only to show DB entities.Added disposeAuthenticationData.
APISecurity:
disposeAuthenticationData.Fix constructor parameter headers to ensure that it's always modifiable.
APIResponse:
headers to ensure that it's always modifiable.APIServer:
gzip encoding.cache-control response header.Added logout and invalidateToken.
APISecurity:
logout and invalidateToken.OPTIONS method for authenticationRoute (/authenticate).- reflection_factory: ^1.2.17 - async_events: ^1.0.7
Added useSessionID to enable/disable the SESSIONID cookie.
APIServer:
useSessionID to enable/disable the SESSIONID cookie.cookieless for a server that blocks all cookies.Keep-Alive.APIRequest:
protocol and keepAlive.APIResponse:
keepAliveTimeout and keepAliveMaxRequests.- reflection_factory: ^1.2.16
Added: toEntityReference, toEntityReferenceList and toList.
ClassReflectionExtension:
toEntityReference, toEntityReferenceList and toList.TypeInfoEntityExtension:
isValidEntityReferenceType and isValidEntityReferenceListType.JsonDecoder.registerTypeDecoder for EntityReference and EntityReferenceList:
null values as EntityReference.asNull and EntityReferenceList.asNull.APIRoot.resolveModule: defaults to path part #0.
APIRoot.resolveModule: defaults to path part #0.APIModule.resolveRoute: defaults to path part #1 ?? #0.
resolveRoute method (allowing personalization).APIRouteBuilder: allow path parts as parameter value by parameterIndex.Added Etag: WeakEtag and StrongEtag.
Etag: WeakEtag and StrongEtag.CacheControlDirective and CacheControl.APIResponse:
payloadETag and cacheControl.APIResponse.notModified.- APISecurity: - Adjust _storeTokeInfo. - async_events: ^1.0.6
APISecurity:
_storeTokeInfo.DBSQLAdapter.generateCreateTableSQLs:
DBSQLAdapter.generateCreateTableSQLs:
getCredentialPermissions: Added parameter previousPermissions.
APISecurity:
getCredentialPermissions: Added parameter previousPermissions.getAuthenticationData: Added parameter previousData.Ensure that parameter EntityResolutionRules? resolutionRules is fully propagated while fetching and resolving entities.
EntityResolutionRules? resolutionRules is
fully propagated while fetching and resolving entities.TransactionEntityProvider to correctly resolve entities while
calling entityHandler.createFromMap inside a Transaction.EntityReferenceBase:
typeName for correct generation of JSON.withEntity to copy.MimeType and DataURLBase64 from package swiss_knife.Add EntityHandler.typeName to avoid minification issues with Types name.
EntityHandler.typeName to avoid minification issues with Types name.Your coding agent can read these notes before it upgrades. Set up the MCP server →