| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| Grandnode2-2.4.0_NoSource.zip | 2026-10-04 | 223.1 MB | |
| 2.4.0 source code.tar.gz | 2026-10-04 | 25.2 MB | |
| 2.4.0 source code.zip | 2026-10-04 | 29.6 MB | |
| README.md | 2026-10-04 | 10.9 kB | |
| Totals: 4 Items | 277.9 MB | 0 | |
GrandNode 2.4.0
✨ Highlights
- .NET 10 and an in-house mediator/mapper: no more MediatR or AutoMapper
- Storefront on Vue 3, Bootstrap 5 and Vite, with dark mode
- Store manager panel (
Grand.Web.Store): a store owner runs their own store without the full Admin panel (multi-tenant/SaaS) - New admin panel UI: Kendo UI is gone; the Admin, Store and Vendor panels now share one component layer and use Tabulator-based grids
- Two storefront themes: the new Nordic Editorial theme and a rewritten Modern theme
- Presentation-grade sample data for new installations
- Multi-instance hosting: runtime-written files can live on a shared volume (
Application:MediaPath) - Better SEO and structured data: real stock availability, ratings, shipping and return policy in JSON-LD
- Signed Docker image on GHCR with SBOM and SLSA provenance
- Security hardening: PBKDF2 passwords, allowlist HTML sanitization, CSRF fixes, SSRF-safe picture import, and IDOR fixes in the Store and Vendor panels
🆕 What's new since 2.4.0-beta
- Admin frontend modernization: Kendo UI removed,
<admin-grid>(Tabulator), Bootstrap 5 and vanilla JS bundles (#843) - Admin, Store and Vendor screens moved to the new component layer (
<admin-page>,<admin-card>,<admin-field>,<admin-filters>,<admin-popup>). Bulk product edit is now a quick editor (#850). Unused admin styles removed and the dashboard cleaned up (#853) - Restyled panel sign-in and two-factor screens, with password recovery inside each panel (
/admin,/store,/vendor) (#857). The GrandNode logo in the panels is now an SVG (#858) - New Nordic Editorial storefront theme (
Theme.Nordic) (#852) - Modern theme redesigned as a thin layer over the Default views: 5 overridden views instead of about 110 (#859)
- Presentation-grade sample data for the installer: a fictional store with 73 products, vendors, collections, blog, knowledgebase and redesigned e-mail templates (#851)
- Storefront header icons move to a bottom tab bar on phones (#847). The theme selector now says what it selects (#848)
Application:MediaPath: runtime-written files (sitemaps, custom CSS/JS, uploads, thumbnails) can be shared across instances (#865)- Product availability, rating, shipping details and return policy in the storefront JSON-LD. An explicit AI crawler policy in robots.txt (#861, [#863]). Invalid microdata removed from the quick view (#870)
- Signed GHCR image (
ghcr.io/grandnode/grandnode2) with SBOM and SLSA provenance, published for release tags (#866) - Solution migrated to the XML-based
GrandNode.slnx(#842) - New thumbnails are encoded at quality 80 instead of 100: much smaller pages, better LCP (#855)
- Fixes: sitemap XML task (#860), installer
host:portparsing and a blank admin under Visual Studio (#856), plugin logo and discount rule URLs behind a path base (#854), admin hints rendered as plain text (#864), and a large batch of Admin/Store/Vendor panel fixes (#868) - Security: SSRF and local file read in Excel picture import (GHSA-2cq3-3r6w-463v, [#862]), a cross-store leak in the Store customer screen (#821), and a blog comment IDOR in the store panel (#868)
- README, installation and development docs, issue templates,
SECURITY.mdandSUPPORT.md(#869)
⚠️ Upgrade notes and breaking changes
- .NET 10 SDK/runtime is required. Open the solution as
GrandNode.slnx(Visual Studio 17.13+, current Rider, or VS Code with C# Dev Kit). - Admin views changed. Plugins and themes that override admin views may need updating.
admin.legacy.js/.cssis removed. Plugin views that use Kendo widgets,k-*classes or Bootstrap 4data-toggle/data-target/data-dismissmust move to<admin-grid>,window.GrandAdminanddata-bs-*.$(el).data('kendoGrid')→GrandAdmin.grids.get(el). - Storefront moved to Vue 3 and Bootstrap 5. Custom storefront themes and view overrides need to follow.
- MediatR and AutoMapper are replaced by
Grand.MediatorandGrand.Mapping. Plugins that reference them need updating. - Customer passwords move to PBKDF2. Legacy hashes are upgraded transparently on the next login. Weak JWT secrets now fail at startup.
- The "Staff" customer group is renamed to "Store manager" by a migration.
administration/build/images/grandLogo.pngis removed; usegrand-logo.svg.MediaSettings.ImageQualitydefaults to 80 only on new installations; existing stores keep their stored value.- Excel import picture columns accept only public
http/httpsURLs. Allow internal hosts withSecurity:PictureImportAllowedPrivateHosts.
🔧 Technology modernization
- Migrated to .NET 10; aligned Aspire on 13 and net10.0
- Migrated the storefront (
Grand.Web) frontend to Vue 3 / Bootstrap 5 / Vite (dark mode, performance and checkout fixes) - Migrated the admin frontend off Kendo UI to Tabulator grids, Bootstrap 5 and vanilla JS bundles, on a shared component layer
- Replaced AutoMapper with an in-house
Grand.Mapping - Replaced MediatR with an in-house
Grand.Mediator - Migrated JsonPatch from Newtonsoft to System.Text.Json
- Migrated the solution file to
GrandNode.slnx
🏬 Grand.Web.Store – store management module (SaaS)
The biggest addition in this release: a dedicated Grand.Web.Store application where a store owner or manager runs their store without access to the full Admin panel (multi-tenant/SaaS):
- Per-store management of products, product attributes and specifications
- Product reviews, checkout attributes, blog, pages, message templates
- Store settings, currencies, languages, shipping methods, discounts, contact attributes
- Tax, payment and email accounts per store
- Customers and addresses per store, customer/address attributes, online customers panel
- New "Store manager" role and permissions (renamed from "Staff", with a database migration and default permissions)
- Password recovery inside the panel
🎨 Storefront and themes
- New Nordic Editorial theme: serif editorial look, self-hosted fonts, full dark mode, WCAG AA contrast
- Modern theme rewritten as a clean tech storefront on a thin Default layer
- Header icons in a bottom tab bar on phones
- Presentation-grade sample data and redesigned transactional e-mail templates
- Smaller thumbnails (quality 80) for faster pages
🔎 SEO and structured data
- Real product availability (
InStock,OutOfStock,BackOrder,PreOrder) in microdata and JSON-LD aggregateRating,shippingDetailsand merchant return policy in JSON-LD- An explicit AI crawler policy in the default robots.txt
- Fixed empty page
<loc>entries in the generated sitemap - Removed incomplete microdata from the quick view; one H1 per product page
🏗️ Architecture refactoring
Consolidated duplicated controller and service logic across Admin, Store and Vendor into shared base classes (e.g. BaseProductController, IAdminDataScope<TEntity>) for Product, MerchandiseReturn, Reports, VendorReview, attribute families, Brand, Discount, Blog, Page, News, GiftVoucher, ProductReview, MessageTemplate, Customer and EmailAccount.
🔒 Security
- Fixed SSRF and local file read through picture columns in Excel imports (GHSA-2cq3-3r6w-463v)
- Fixed cross-store IDOR gaps in
Grand.Web.Store(customer product price/personalization, customer store list, blog comments, and broader store-panel access) - Fixed vendor product IDORs and consolidated ownership checks
- Hashed customer passwords with PBKDF2, with transparent upgrade of legacy hashes; stopped storing passwords reversibly and made JWT secrets fail fast when weak
- Fixed missing CSRF/antiforgery protection across storefront controllers, admin plugin POST actions, the admin file manager and "Restart application"
- Replaced the NoScripts blacklist with allowlist-based HTML sanitization
- Fixed a memory DoS and file-extension bypass in attribute file uploads
- Added a regex match timeout to
ApiQueryOptionsand stopped passing raw API query options into the expression parser - Fixed an open redirect
- Hardened OpenAPI metadata generation
- Locked system-wide settings in the store panel and added an explicit "All stores" scope in admin
- Removed a tracking pixel from the admin dashboard
⚡ Performance and reliability
- Shared storage for runtime-written files across instances (
Application:MediaPath) - Cached the storefront catalog by customer group instead of by individual customer
- Executed paged and general repository queries directly on the MongoDB driver instead of blocking a thread
- Batched inventory stock writes into single repository updates
- Assigned the order number under a unique index instead of a read-max race
- Improved multi-instance safety: Redis cache invalidation resilience and exactly-once scheduled task execution
- Fixed the scheduled-task loop permanently stopping on reversible states
- Fixed blocking S3 calls, unawaited cache notifications and a startup provider issue
- Shared a single
MongoClientinstance and fixed the LiteDBTableCollection - Fixed the dead plugin version gate and stopped leaking host assemblies into plugin folders
- Fixed the database version stamp running before its own migrations
- Added a
/health/readyreadiness check - About 50 KB less admin CSS on every panel page
🐞 Bug fixes (selected)
- Sitemap XML task no longer crashes without a work context
- Installer accepts
host:portas the MongoDB server name - Plugin logo and discount rule URLs work behind a reverse proxy or virtual directory
- Admin: "Cancel order" restored, required products popup, contact attributes on /contactus, inline adding of tax categories and weights, uncapped blank maximum discount amount, slug cleanup when deleting brands/pages/news/knowledgebase/courses, robots.txt "All stores" fallback
- Admin field hints shown as plain text instead of raw HTML; 22 missing panel resources added
- Store logo in PDF invoices with an absolute store URL
- CSP
font-srcallowsdata:URIs - Storefront rendering without CSS/JS (Razor tag helper regression)
- DI resolution error in
ProductEmailAFriendValidator - CMS lookups scoped to the store; a store can override a shared page
📦 Dependencies and CI/CD
- NuGet and npm packages updated across the solution (including Vite 8, ESLint 10, Aspire 13.6)
- Signed Docker image on GitHub Container Registry with an SBOM and SLSA provenance, verified in the same workflow
- GitHub Actions: SonarCloud analysis, Docker image CI, the whole test suite on pull requests
- Issue forms,
SECURITY.md,SUPPORT.md, a rewritten README and new installation/development guides
Full changelog: https://github.com/grandnode/grandnode2/compare/2.3.0...2.4.0