Notty CMS — Capability Map
Техническое руководство из исходного проекта Notty. Примеры, параметры и эксплуатационные ограничения.
Все редакцииОбновлено 2026-09-30
Updated: 2026-09-28. Runtime package: 1.0.2.
This is an implementation map, not a declaration that every deployment has passed acceptance.
Task Master contains the roadmap and task status. Dated reports under docs/testflow/runs/
record the exact environment and checks performed in each run.
Implemented capabilities
| Area | Implementation | Limits and verification needs |
|---|---|---|
| Content | CRUD, filters, sorting, pagination, aggregation, bulk operations, relations, components, dynamic zones | Permissions and database dialect behavior need regression coverage |
| Editorial | Draft/publish, scheduling, revisions/diffs, preview tokens, approval workflows, releases, comments/presence | Presence is not field locking or collaborative document editing |
| Localization | ru/en admin UI, content locales, locale settings, translation workflow | Broad admin language coverage and automatic translation remain on the roadmap |
| Databases | PostgreSQL, MySQL/MariaDB, SQLite; schema diff, safe apply, introspection, migration manager | Full database-first workflow and additional database vendors remain future work |
| Media | Uploads, folders, bulk actions, variants, local/S3-compatible/R2/GCS providers, signed delivery | Cloud acceptance requires a configured provider; resumable uploads remain future work |
| Authentication | Separate admin/content-user JWT flows, API tokens, OAuth, password reset, MFA, SSO OIDC and SCIM | External identity providers and mail delivery require live configuration checks |
| Authorization | Admin scopes, content actions, field/entry restrictions, named policies, tenant/workspace context | Hardened multitenancy is explicitly tracked as future work (#25.38) |
| Operations | Jobs, retries, schedules, HMAC webhooks, audit, health/readiness, metrics/tracing, backup/export/import | Restore, cloud, scaling and disaster recovery need deployment-level verification |
| Compliance | Retention, DSAR export, erasure and legal holds | A technical feature does not establish an organization's compliance |
| Delivery APIs | REST, GraphQL, SDK, generated types/validators, OpenAPI, SSE events | WebSocket API and GraphQL subscriptions remain future work |
| Developer tools | CLI, codegen, app scaffolds, plugins/themes, migration tooling, diagnostics, test harnesses | Marketplace, extension sandbox and full theme layout application remain future work |
| AI tools | Schema, migration, query, editorial, automation and scaffold advisors; action audit and guardrails | Current advisors use deterministic rules; no general external LLM assistant, embeddings or automatic media descriptions |
| Editions | Community/Pro/Business/Enterprise manifests, package boundaries, signed licenses, feature gates, optional commerce/portal modules | Most module runtime code remains hosted by server; physical extraction is partial |
Distribution and release
@notty/create, CLI, SDK, plugin/theme SDKs and Community packages publish publicly.- Paid editions/modules use restricted registry access or portable distributions.
- Registry download credentials and signed runtime licenses are independent controls.
- GitLab CI now requires type-check, lint, the full automated suite, builds and boot smoke.
- Post-deploy installation from real registries is tracked in #68.
- NottyPortal (website, documentation, sales/customer portal, entitlement and license issuing) is #62 in a separate project.
- Distribution license texts/metadata are unresolved in #76; the old README reference to a missing MIT
LICENSEwas incorrect.
Future functionality
Task #25 has 38 subtasks. Argon2 password hashing and security headers are complete; 36 enhancements remain deferred/pending. They include:
| Direction | Planned work |
|---|---|
| Content UX | Cards/Grid, Kanban, Calendar, saved/shared views, visual editing, notifications, readonly sharing |
| Content model | GIS/Map, polymorphic relations, complete Document Service, database-first workflow |
| Collaboration/locales | Field locks, realtime editing, more languages, RTL, cross-locale field filling |
| AI | Auto-translation, image descriptions, LLM assistant, MCP, vectors/embeddings |
| Integrations/analytics | No-code flows, BI dashboards, CSV/XML/YAML export, WebSocket/GraphQL subscriptions |
| Platform | Extension sandbox, signed marketplace, multi-storage, TUS, more DB adapters, encrypted fields, hardened tenant isolation |
Canonical references
- Generated app contract
- Distribution model
- Editions and modules
- Module extraction status
- Testing workflow (
claude/testing-workflow.mdв исходном проекте)
Источник: docs/capability-map.md. Снимок документации исходного проекта. Технический справочник сохраняет язык оригинала.