Release Notes
20 Sep 2026: ver. 4.1.0
- First stable release. Kittox leaves beta: the HTMX client port, the REST server and the KIDEx / MCP-KittoX toolchain are feature-complete, and the framework has been through a full security and correctness review.
- KIDEx / MCP-KittoX — YAML validation completed: the RTTI-driven validator now covers every Config, Model, View and Layout node the three examples use;
MCPKittoX --validatereports zero errors on HelloKitto, KEmployee and TasKitto (only intentionally-disabled nodes remain). This closes the last major KIDEx/MCP feature. - Security & correctness review — Core (
Source/Kitto): exposed-perimeter hardening — JWT algorithm pinning (RS256→HS256 confusion closed), immediate token revocation on logout / password change plus an absolute session cap, path-traversal containment on static and BLOB file serving, thread-safe per-user ACL cache with case-insensitive matching, credentials read only from the POST body (never the URL), logout via POST, and LDAP identity taken from the directory. - Security & correctness review — EF layer: faithful database schema introspection (the Size/Scale contract and LOB detection verified on MSSQL, Oracle, Firebird and PostgreSQL), thread-safe regex and access-control, and a number of DoS and injection fixes.
- Automated test suite now at 271 tests, green on Win64 Debug; the integration tests run against real MSSQL, Oracle, Firebird and PostgreSQL servers, and the whole metadata catalogue of the three examples is loaded and walked.
- KIDEx configuration editor: the remaining JWT / Defaults nodes (e.g.
MaxSessionLifetime, Grid and Window defaults) are now discoverable. - KIDEx — Live Preview of Views and Layouts: render a view — or the first view that uses a layout — with the real engine in an embedded browser, without compiling or launching the application. It reloads automatically when you save a metadata or resource file, and includes mobile/tablet device emulation (viewport, device pixel ratio and user-agent). The login form is skipped in preview.
- List as the data-list host:
Controller: Listcomposes presenters in its regions — the default GridPanel, a ChartPanel or CalendarPanel in the Center, a real grid beside a chart (WestController: GridPanel), and the form of the current record beside the grid (EastController: Form: view mode, Edit/Save in place). Filters and Refresh apply to every presenter. Replaces Kitto1'sAutoFormPlacement. - CalendarPanel:
DefaultEventMinutesgives a duration to point-in-time events, event content differs per view (month: time and title; week/day: title and notes), and calendar and chart data honor the List filters. HelloKitto gains a Party calendar. - KIDEx Live Preview — automatic login:
PreviewMode/Auth/Defaultsin the.kproj(File → Settings) logs the preview in as a chosen user or profile, also with custom authenticators; fixed the first render of JWT applications, which came up with an empty menu. - Build:
build_Examples.cmdfinds Delphi through the registry (13, 12, 11, 10.4). - Third-party libraries aligned to their latest releases: Delphi — Delphi-Neon 4.1.0, MarkdownProcessor 1.4.1 (with their LICENSE files in
Source/ThirdParty, shipped by the setup but not added to the library path); client — HTMX 2.0.10, Alpine.js 3.17.3, Chart.js 4.5.1, EventCalendar 5.13.1, SunEditor 2.47.12 (XSS sanitizer fixes), Swagger UI 5.33.0; the never-referenced jQuery 2.1.3 and jSignature bundles were removed.
07 Sep 2026: ver. 4.0.19 Beta
- Automated test suite — 216 tests, green on Win64/Win32 × Debug/Release; 24 of them run against real MSSQL, PostgreSQL, Firebird and Oracle servers, and the whole metadata catalogue of the three examples is loaded and walked.
Test\run_tests.cmd - Detail grids work before the master exists: full data entry on a master still in memory, saved to the database exactly as the grid showed it
CascadeDeleteon a detail reference deletes the details inside the master's transaction, recursively. Off by default; where it is not declared the refusal names the record and counts what holds it back- The framework's own messages in four languages — 93 strings now translated in it/de/es/pt: wizard buttons, grid and calendar toolbars, GoogleMap controls, dialogs, authenticator messages. New
Tools\update_locale.cmdkeeps the catalogues in step and recompiles the.mo - KIDEx — Update Database Structure: the reverse of the Model Wizard, generating and running the DDL that brings the database in line with the Models, multi-dialect, with an editable preview. New and incomplete — read the limitations
- KIDEx — YAML validation driven by RTTI: the validator reads the declarations on the framework classes instead of a hand-written list, and checks enum and integer values too
- KIDEx — configuration editor completed: Auth, Email/SMTP, Defaults, Log and Help Chat now offer every node the framework reads
- KIDEx — scalable DPI-aware icons, a theme selector with a live preview of the twelve VCL styles, and an SVG editor for the project's own icons
- Changed: a server-rendered error dialog now carries a truthful HTTP status (500 / 422 / 400 / 409) and an
X-KittoX-Dialogheader. If you drive Kittox endpoints from your own client, a dialog response is no longer a2xx
25 Aug 2026: ver. 4.0.18 Beta
- Per-domain config readers (
Kitto.Config.<Domain>) for Server, Auth, Notifications, UserFormats, AccessControl, Log, Desktop and Theme, with each view/model descriptor moved next to its consumer; new typed[YamlChildType(name, Class)] - The setup installer now compiles the framework packages (Core + Enterprise + IDE) for every selected Delphi version, creates
KITTOX_HOMEand registers the IDE library search paths — the examples and your own projects compile with no manual step - KIDEx Model Wizard follows changes to the schema: re-running Update models reports added, removed and reordered key and foreign-key columns, a foreign key redirected to another table, and a changed primary key
- KIDEx New Project Wizard: ODAC as a selectable engine, and generated databases named after their engine instead of
Other1/Other2 - Master and detail no longer require the Model's field names to match the database's column names
- ThirdParty units namespaced with a
Kitto.prefix, to avoid clashes with the same libraries shipped by other packages
23 Aug 2026: ver. 4.0.17 Beta
- The JWT envelope is an optional
JWT:sub-block under any authenticator: writeAuth: DB,Auth: LDAP,Auth: MyOwnand addJWT:to issue and validate a self-containedkx_token; without the block the same authenticator uses a plain session cookie. The JOSE crypto lives in an opt-in engine, so the core carries no dependency on it
21 Aug 2026: ver. 4.0.16 Beta
- Help Chat can answer through Claude: streamed token by token, grounded on the documentation index (RAG), with replies rendered from Markdown to safe HTML, on every deployment mode
- Help Chat and Notification Center are opt-in units: add them to
UseKitto.pas, and a clear startup error names the one missing when a feature is enabled in config
12 Aug 2026: ver. 4.0.15 Beta
- New
TKAuthenticator.SupportsPasswordChange, interrogated before writing, so an authenticator that does not own the credentials can refuse instead of reporting a success it discarded - New
TKAuthenticatorDecorator: the forwarding contract of a wrapping authenticator is now checked by the compiler - A security pass over the authentication and session layer. Upgrading is recommended
10 Aug 2026: ver. 4.0.14 Beta
- Full multi-language support: new LanguageSwitcher controller (flag dropdown) for login and home, interface language auto-detected from the browser when
LanguageIdis empty, and the examples shipped in English, Italian, German, Spanish and Portuguese - Help Chat — an in-app assistant: floating bubble and drawer, enabled with
HelpChat/Enabled, with a pluggable provider model and a deterministic docsearch provider that answers from the documentation index and links back to it. Contextual ? button on the List and Form toolbars - Notification Center refinements: opt-in via
Notifications/Enabled, clear-all, per-job remove, downloads via fetch + blob - New
[Retry]/[Reset]dialog for every user-initiated action that fails or times out; background polling stays silent
04 Aug 2026: ver. 4.0.13 Beta
- Notification Center and background tools — run a download-file tool (CSV/TXT/XML/Excel, MergePDF, ReportBuilder) as a background job on a worker pool separate from the HTTP threads, opt-in per tool with one YAML line,
RunMode: Background. A bell shows each job with its status and lets the user download, cancel or dismiss it; jobs are persisted per user on disk and survive logout and a process restart. Configurable underServer/Jobs - Licensing: registration under
HKEY_CURRENT_USER\Software\Ethea\KIDEX, company name and developer e-mail, and several versions of Kittox usable on the same machine - Changed: the framework packages folder is renamed from
Projects/toPackages/
31 Jul 2026: ver. 4.0.12 Beta
- LDAP / Active Directory authentication — new
Auth: LDAP: simple bind against Active Directory or a generic LDAP, no local user table, name and e-mail read from the directory Controller: ReportBuilderToolupdated to the latest ReportBuilder
28 Jul 2026: ver. 4.0.11 Beta
- REST / JSON API — expose an application's data views as a web service, by default under
/api/v4/{View}, in parallel to the HTMLx GUI and on the same engine, models, rules and ACL. Opt-in by addingKitto.Web.ResttoUseKitto.pas: full CRUD with model-level permissions, stateless bearer-token auth, a self-describing OpenAPI 3.0 spec with a built-in Swagger UI, configurable base path and opt-in CORS
20 Jul 2026: ver. 4.0.10 Beta
- Oracle is a fully supported backend: DDL and data scripts for the examples on Oracle XE 21c, the Oracle SQL dialect completed, and FireDAC's
Oradriver wired into the examples. New portable%DB.CONCAT%,%DB.FROM_DUAL%and%DB.CURRENT_DATE%macros make hand-written YAML SQL work across all five dialects - New optional ODAC backend (
EF.DB.ODAC) on Devart ODAC, an alternative Oracle path enabled per application - Attribute-based routing complete: the whole
kx/*surface is served by typed handlers under one shared request-filter chain, and the monolithic dispatcher is gone. NewTKXResourceRegistry.RegisterOverridelets an application subclass a framework handler and replace a single endpoint without forking the route - Navigation guard: a browser navigation typed straight at an internal
kx/*fragment endpoint is rejected and redirected, instead of serving a bare partial {MasterRecord.*}macros resolve in detail-form lookup filters, so dependent lookups populate from the master record being edited- Public-API documentation coverage raised from ~32% to ~74%, surfaced in KIDEx through
[YamlNode]descriptions
06 Jul 2026: ver. 4.0.9 Beta
- The authentication family (
kx/login,kx/logout,kx/resetpassword,kx/changepassword) is the first group to bring its own routing through the attribute-based router, running inside the full per-request context Examples/build_Examples.cmdtakes arguments, so a single example, deployment mode and configuration can be built from the command line
08 Jun 2026: ver. 4.0.8 Beta
- User-selectable theme: set
Theme/UserSelection: True, drop aController: ThemeSwitcheranywhere in the GUI, and the end user picks Light / Auto / Dark live, persisted per application, with no page reload Themeis a structured config block discoverable by KIDEx:Mode, shared font and icon settings, and per-modeLight:/Dark:palettes each with its ownPrimary-Color- MCP-KittoX: 40+ tools (up from 16) — full CRUD on Models, Views and Layouts, database introspection, config read and update,
.poreading, metadata validation and view scaffolding
18 May 2026: ver. 4.0.7 Beta
- RAD Studio IDE plugin gallery: four entries under File > New > Other > KittoX Projects (Standalone, Desktop, ISAPI, Apache), so there are now three ways to scaffold an application — KIDEx, the IDE gallery, and MCP-KittoX
- A generated project authenticates out of the box:
Auth: TextFilewith a ready-to-use file, no users table required - Model Wizard: editable
DisplayLabelandHinton every field, auto-populated from the database's own column comments (MSSQL, PostgreSQL, Firebird, MySQL, Oracle); Beautify names handles names with spaces; New TreeView… is idempotent and merges into an existingMainMenu.yaml - MCP-KittoX
models_create_from_db— the headless Model Wizard, so an AI agent can reverse-engineer Models conversationally, byte-identical to what the visual wizard writes. Plusmodels_list/read,views_list/read,resources_list/readandmenu_generate_main_menu Controller/AutoOpenandController/PagingToolsfollow the Model'sIsLargeflag, and a Reference to a large Model renders as a searchable lookup popup- ACL enforced server-side on every endpoint, with the toolbar's Add/Edit/Delete/Dup disabled for a denied user
01 May 2026: ver. 4.0.6 Beta
- New
Auth: JWTwrapper authenticator (signedkx_tokencookie, sliding expiration) andAccessControl: JWT, reading grants from akx_aclclaim snapshotted at login - Multi-database applications: TasKitto and HelloKitto on SQL Server, PostgreSQL and Firebird, with an optional Environment combo on the login form (
Auth/DatabaseChoices) and cross-dialect macros%DB.TRUE%,%DB.FALSE%,%DB.DATEDIFF,%DB.DATETIME_FROM - New
Tools/SetVersion.ps1: one-shot version bump across constant, dproj, README and installer script - YAML metadata files included in every
.dproj, visible in the Project Manager with KIDEx highlighting
23 Apr 2026: ver. 4.0.5 Beta
- Database connection ownership unified in
TKConfig, with the newDatabaseFor(Name)andCreateStandaloneDBConnection(Name)API and theInDBConnection/InDBTransactionhelpers
22 Apr 2026: ver. 4.0.4 Beta
- DetailTables Style:
Tabs,BottomorPopup - Multi-column sort and manual column resize in grids, with a tooltip on a cell only when its text is actually truncated
- Multi-page form validation
- Edit-mode accent border on comboboxes and other non-text-editable fields
23 Apr 2026: ver. 4.0.3 Beta
- ExportExcel / ExportFlexCel tools
- Grid keyboard navigation
- Editing-mode field borders and form toolbar anchoring
19 Apr 2026: ver. 4.0.2 Beta
- Apache and IIS deployment simplified: static resources are served internally, with no
RewriteRuleto write - New deployment mode: Windows Service behind a reverse proxy (nginx, Apache, IIS), with install and uninstall scripts
- The
Apply*Rulesevent chain (EditRecord,NewRecord,Duplicate,AfterShowEditWindow) - HTTP error feedback with a Retry/Reset dialog
- DDL and DML scripts for the example databases
09 Apr 2026: ver. 4.0.1 Beta
Corrections only.
07 Apr 2026: ver. 4.0.0 Beta (first public release)
First public release of Kittox, the fourth generation of the Kitto framework: a complete rewrite of the client side from ExtJS to HTMX + AlpineJS + TemplatePro, on a new modular server architecture.
Architecture
- HTMX + AlpineJS client: the server generates HTML fragments and the page updates in place. No heavy JavaScript framework
- Attribute-based routing (RTTI): URL routing declared with Delphi custom attributes, resource classes discovered at startup, request context injected
- Server-side store: in-session data stores with record state tracking, transactional master-detail saving in a single database transaction, blob lazy-loading
- Open Core licensing: Core under Apache 2.0, Enterprise modules under AGPL-3.0 or commercial, KIDEx commercial
Controllers
- List (grid with CRUD toolbar, server-side paging, sorting, column layouts, row colours, grouping), GroupingList, Form (field pages, detail tabs, ViewMode/EditMode), Wizard (multi-step with per-step validation)
- BorderPanel, TabPanel, FlexPanel, TreePanel, TilePanel, HtmlPanel, StatusBar, ToolBar
- Enterprise: ChartPanel (Chart.js), CalendarPanel, GoogleMap, Dashboard (auto-refresh)
- Card view: the List controller with a
TemplateFileNamefor custom HTML cards, with full CRUD
Data and forms
- Database agnostic through FireDAC (preferred), DBExpress or ADO
- Detail CRUD in memory: add, edit and delete detail records with no database round-trip until Save All
- Form state machine: ViewMode (Edit / Save All / Close) and EditMode (Save / Cancel)
- Filter panel:
FreeSearch,List,DynaList,ButtonList,DynaButtonList, plusDateSearch,TimeSearch,DateTimeSearch,NumericSearch,BooleanSearch - Custom layouts for grid and form, including a multi-page form with collapsible regions
Mobile
- Automatic detection from user agent and screen size, fullscreen dialogs, a TilePanel menu for phone home pages, and a home view chosen per size (
HomeTinyView,HomeSmallView,HomeView)
Authentication and tools
- Pluggable authenticators
DB,DBCrypt,TextFile,DBServer,OSDB,Nulland access controllersDB,Null, with BCrypt hashing, TOTP two-factor and QR code generation - CSV and Excel export, SQL tool, file download and upload; FlexCel, ReportBuilder and DebenuQuickPDF integration (commercial)
Deployment
- Standalone (VCL desktop or Windows service, embedded Indy HTTP server), Desktop Embedded (WebView2 in a VCL window), Console, IIS (ISAPI) and Apache (module)
KIDEx (visual IDE — Enterprise)
- RTTI-based property discovery, replacing 215 template files, through six YAML attributes; SVG icons; database reverse engineering; project wizard, validators and tree editors
Examples
- HelloKitto (party and invitation manager), TasKitto (activity tracking with dashboard, charts and calendar), KEmployee (employee management with master-detail and card views)
Supported Delphi versions
Delphi 10.4 to the latest, Win32 and Win64.

