Download Latest Version 2.4.0 source code.zip (29.6 MB) Google Add to Preferred Sources
Home / 2.4.0
Name Modified Size InfoDownloads / Week
Parent folder
Grandnode2-2.4.0_NoSource.zip 2026-10-04 223.1 MB
2.4.0 source code.tar.gz 2026-10-04 25.2 MB
2.4.0 source code.zip 2026-10-04 29.6 MB
README.md 2026-10-04 10.9 kB
Totals: 4 Items   277.9 MB 0

GrandNode 2.4.0

✨ Highlights

  • .NET 10 and an in-house mediator/mapper: no more MediatR or AutoMapper
  • Storefront on Vue 3, Bootstrap 5 and Vite, with dark mode
  • Store manager panel (Grand.Web.Store): a store owner runs their own store without the full Admin panel (multi-tenant/SaaS)
  • New admin panel UI: Kendo UI is gone; the Admin, Store and Vendor panels now share one component layer and use Tabulator-based grids
  • Two storefront themes: the new Nordic Editorial theme and a rewritten Modern theme
  • Presentation-grade sample data for new installations
  • Multi-instance hosting: runtime-written files can live on a shared volume (Application:MediaPath)
  • Better SEO and structured data: real stock availability, ratings, shipping and return policy in JSON-LD
  • Signed Docker image on GHCR with SBOM and SLSA provenance
  • Security hardening: PBKDF2 passwords, allowlist HTML sanitization, CSRF fixes, SSRF-safe picture import, and IDOR fixes in the Store and Vendor panels

🆕 What's new since 2.4.0-beta

  • Admin frontend modernization: Kendo UI removed, <admin-grid> (Tabulator), Bootstrap 5 and vanilla JS bundles (#843)
  • Admin, Store and Vendor screens moved to the new component layer (<admin-page>, <admin-card>, <admin-field>, <admin-filters>, <admin-popup>). Bulk product edit is now a quick editor (#850). Unused admin styles removed and the dashboard cleaned up (#853)
  • Restyled panel sign-in and two-factor screens, with password recovery inside each panel (/admin, /store, /vendor) (#857). The GrandNode logo in the panels is now an SVG (#858)
  • New Nordic Editorial storefront theme (Theme.Nordic) (#852)
  • Modern theme redesigned as a thin layer over the Default views: 5 overridden views instead of about 110 (#859)
  • Presentation-grade sample data for the installer: a fictional store with 73 products, vendors, collections, blog, knowledgebase and redesigned e-mail templates (#851)
  • Storefront header icons move to a bottom tab bar on phones (#847). The theme selector now says what it selects (#848)
  • Application:MediaPath: runtime-written files (sitemaps, custom CSS/JS, uploads, thumbnails) can be shared across instances (#865)
  • Product availability, rating, shipping details and return policy in the storefront JSON-LD. An explicit AI crawler policy in robots.txt (#861, [#863]). Invalid microdata removed from the quick view (#870)
  • Signed GHCR image (ghcr.io/grandnode/grandnode2) with SBOM and SLSA provenance, published for release tags (#866)
  • Solution migrated to the XML-based GrandNode.slnx (#842)
  • New thumbnails are encoded at quality 80 instead of 100: much smaller pages, better LCP (#855)
  • Fixes: sitemap XML task (#860), installer host:port parsing and a blank admin under Visual Studio (#856), plugin logo and discount rule URLs behind a path base (#854), admin hints rendered as plain text (#864), and a large batch of Admin/Store/Vendor panel fixes (#868)
  • Security: SSRF and local file read in Excel picture import (GHSA-2cq3-3r6w-463v, [#862]), a cross-store leak in the Store customer screen (#821), and a blog comment IDOR in the store panel (#868)
  • README, installation and development docs, issue templates, SECURITY.md and SUPPORT.md (#869)

⚠️ Upgrade notes and breaking changes

  • .NET 10 SDK/runtime is required. Open the solution as GrandNode.slnx (Visual Studio 17.13+, current Rider, or VS Code with C# Dev Kit).
  • Admin views changed. Plugins and themes that override admin views may need updating. admin.legacy.js/.css is removed. Plugin views that use Kendo widgets, k-* classes or Bootstrap 4 data-toggle/data-target/data-dismiss must move to <admin-grid>, window.GrandAdmin and data-bs-*. $(el).data('kendoGrid') → GrandAdmin.grids.get(el).
  • Storefront moved to Vue 3 and Bootstrap 5. Custom storefront themes and view overrides need to follow.
  • MediatR and AutoMapper are replaced by Grand.Mediator and Grand.Mapping. Plugins that reference them need updating.
  • Customer passwords move to PBKDF2. Legacy hashes are upgraded transparently on the next login. Weak JWT secrets now fail at startup.
  • The "Staff" customer group is renamed to "Store manager" by a migration.
  • administration/build/images/grandLogo.png is removed; use grand-logo.svg.
  • MediaSettings.ImageQuality defaults to 80 only on new installations; existing stores keep their stored value.
  • Excel import picture columns accept only public http/https URLs. Allow internal hosts with Security:PictureImportAllowedPrivateHosts.

🔧 Technology modernization

  • Migrated to .NET 10; aligned Aspire on 13 and net10.0
  • Migrated the storefront (Grand.Web) frontend to Vue 3 / Bootstrap 5 / Vite (dark mode, performance and checkout fixes)
  • Migrated the admin frontend off Kendo UI to Tabulator grids, Bootstrap 5 and vanilla JS bundles, on a shared component layer
  • Replaced AutoMapper with an in-house Grand.Mapping
  • Replaced MediatR with an in-house Grand.Mediator
  • Migrated JsonPatch from Newtonsoft to System.Text.Json
  • Migrated the solution file to GrandNode.slnx

🏬 Grand.Web.Store – store management module (SaaS)

The biggest addition in this release: a dedicated Grand.Web.Store application where a store owner or manager runs their store without access to the full Admin panel (multi-tenant/SaaS):

  • Per-store management of products, product attributes and specifications
  • Product reviews, checkout attributes, blog, pages, message templates
  • Store settings, currencies, languages, shipping methods, discounts, contact attributes
  • Tax, payment and email accounts per store
  • Customers and addresses per store, customer/address attributes, online customers panel
  • New "Store manager" role and permissions (renamed from "Staff", with a database migration and default permissions)
  • Password recovery inside the panel

🎨 Storefront and themes

  • New Nordic Editorial theme: serif editorial look, self-hosted fonts, full dark mode, WCAG AA contrast
  • Modern theme rewritten as a clean tech storefront on a thin Default layer
  • Header icons in a bottom tab bar on phones
  • Presentation-grade sample data and redesigned transactional e-mail templates
  • Smaller thumbnails (quality 80) for faster pages

🔎 SEO and structured data

  • Real product availability (InStock, OutOfStock, BackOrder, PreOrder) in microdata and JSON-LD
  • aggregateRating, shippingDetails and merchant return policy in JSON-LD
  • An explicit AI crawler policy in the default robots.txt
  • Fixed empty page <loc> entries in the generated sitemap
  • Removed incomplete microdata from the quick view; one H1 per product page

🏗️ Architecture refactoring

Consolidated duplicated controller and service logic across Admin, Store and Vendor into shared base classes (e.g. BaseProductController, IAdminDataScope<TEntity>) for Product, MerchandiseReturn, Reports, VendorReview, attribute families, Brand, Discount, Blog, Page, News, GiftVoucher, ProductReview, MessageTemplate, Customer and EmailAccount.

🔒 Security

  • Fixed SSRF and local file read through picture columns in Excel imports (GHSA-2cq3-3r6w-463v)
  • Fixed cross-store IDOR gaps in Grand.Web.Store (customer product price/personalization, customer store list, blog comments, and broader store-panel access)
  • Fixed vendor product IDORs and consolidated ownership checks
  • Hashed customer passwords with PBKDF2, with transparent upgrade of legacy hashes; stopped storing passwords reversibly and made JWT secrets fail fast when weak
  • Fixed missing CSRF/antiforgery protection across storefront controllers, admin plugin POST actions, the admin file manager and "Restart application"
  • Replaced the NoScripts blacklist with allowlist-based HTML sanitization
  • Fixed a memory DoS and file-extension bypass in attribute file uploads
  • Added a regex match timeout to ApiQueryOptions and stopped passing raw API query options into the expression parser
  • Fixed an open redirect
  • Hardened OpenAPI metadata generation
  • Locked system-wide settings in the store panel and added an explicit "All stores" scope in admin
  • Removed a tracking pixel from the admin dashboard

⚡ Performance and reliability

  • Shared storage for runtime-written files across instances (Application:MediaPath)
  • Cached the storefront catalog by customer group instead of by individual customer
  • Executed paged and general repository queries directly on the MongoDB driver instead of blocking a thread
  • Batched inventory stock writes into single repository updates
  • Assigned the order number under a unique index instead of a read-max race
  • Improved multi-instance safety: Redis cache invalidation resilience and exactly-once scheduled task execution
  • Fixed the scheduled-task loop permanently stopping on reversible states
  • Fixed blocking S3 calls, unawaited cache notifications and a startup provider issue
  • Shared a single MongoClient instance and fixed the LiteDB TableCollection
  • Fixed the dead plugin version gate and stopped leaking host assemblies into plugin folders
  • Fixed the database version stamp running before its own migrations
  • Added a /health/ready readiness check
  • About 50 KB less admin CSS on every panel page

🐞 Bug fixes (selected)

  • Sitemap XML task no longer crashes without a work context
  • Installer accepts host:port as the MongoDB server name
  • Plugin logo and discount rule URLs work behind a reverse proxy or virtual directory
  • Admin: "Cancel order" restored, required products popup, contact attributes on /contactus, inline adding of tax categories and weights, uncapped blank maximum discount amount, slug cleanup when deleting brands/pages/news/knowledgebase/courses, robots.txt "All stores" fallback
  • Admin field hints shown as plain text instead of raw HTML; 22 missing panel resources added
  • Store logo in PDF invoices with an absolute store URL
  • CSP font-src allows data: URIs
  • Storefront rendering without CSS/JS (Razor tag helper regression)
  • DI resolution error in ProductEmailAFriendValidator
  • CMS lookups scoped to the store; a store can override a shared page

📦 Dependencies and CI/CD

  • NuGet and npm packages updated across the solution (including Vite 8, ESLint 10, Aspire 13.6)
  • Signed Docker image on GitHub Container Registry with an SBOM and SLSA provenance, verified in the same workflow
  • GitHub Actions: SonarCloud analysis, Docker image CI, the whole test suite on pull requests
  • Issue forms, SECURITY.md, SUPPORT.md, a rewritten README and new installation/development guides

Full changelog: https://github.com/grandnode/grandnode2/compare/2.3.0...2.4.0

Source: README.md, updated 2026-10-04