BoxLang 🚀 A New JVM Dynamic Language Learn More...

CB Genesis Starter Template

v1.0.0-snapshot MVC

CBGenesis

alt text

A production-ready ColdBox HMVC starter for the BoxLang language - authentication, SSO, RBAC permissions, API tokens, rate limiting, an Alpine-powered admin panel, and a real test suite, so you spend day one building features instead of scaffolding.

What You Get

  • Auth & RBAC, Batteries Included - Session auth via cbauth, @secured handler annotations, CSRF rotation, JWT support, and a resource:action permission model with roles and permissions admin screens.
  • Single Sign-On - cbSSO with a shipped Google OAuth provider (More included), account linking, auto-provisioning by allowed email domain, and full audit trail integration.
  • Passkeys / WebAuthn - Passwordless sign-in backed by cbsecurity-passkeys, with an optional policy that requires a passkey before a user can proceed.
  • Modern Template Structure - Application code lives in app/, fully separated from the public webroot in public/ - enhanced security by default.
  • Hibernate ORM + qb - BaseEntity/BaseService conventions on top of cborm, migrations and seed data via cfmigrations, and qb for anything raw SQL does better.
  • Alpine.js + Bootstrap 5 UI - Server-rendered BXM views, small Alpine.js components, light/dark theme switching, and a Vite-compiled SCSS/JS pipeline with HMR.
  • Audit Log & Rate Limiting - Every sign-in, sign-out, and authorization failure is written to a searchable audit trail; an IP-based rate limiter throttles login, registration, and password-reset abuse.
  • API Tokens - Per-user, hashed personal access tokens with expiration and a scheduled purge job, ready for programmatic API access.
  • Email Workflows - cbMailServices-powered templates for password reset, email verification, invitations, and welcome messages.
  • A Real Test Suite - TestBox unit specs for every entity and service, plus integration specs that exercise real HTTP requests.
  • Production Ready - A real go-live checklist, Docker support (app + MySQL/PostgreSQL/MSSQL), and a choice of CommandBox or the BoxLang MiniServer.

Documentation

Full documentation lives here:

Requirements

  • BoxLang 1.17+ (with bx-cli)
  • Node.js 22+
  • ColdBox 8.2+
  • MySQL/PostgreSQL/MSSQL/SQLite/Oracle/MariaDB

Quick Start

Easily get started with the cbGenesis template by following these 5 steps:

1. BoxLang & CommandBox (bx-cli)

Install BoxLang into your operating system using our Quick Installer or the BoxLang Version Manager (BVM). Once installed, you can proceed with adding the BoxLang-native CommandBox CLI module.

Warning: Make sure you have the BoxLang-native CommandBox CLI installed, as the regular Lucee CommandBox is not supported.

# Install CommandBox
install-bx-module bx-cli
# Install the ColdBox CLI Module
box install coldbox-cli

This installs the BoxLang-native CommandBox CLI module and the ColdBox CLI module, allowing you to use the box commands specific to BoxLang.

2. Node.js

This template requires Vite and UI elements that require Node.js 22+ to build and run properly. So make sure you have Node.js 22+ installed on your system.

3. Scaffold the Project

Use the coldbox-cli to scaffold a new project.

box coldbox create app name="my-app" skeleton="cbgenesis"

3. Install Dependencies

# Install BoxLang Dependencies
box install
# Install Node.js Dependencies
npm install

4. Database Setup

Configure your database connection in the .env file and run the necessary migrations to set up the database schema.

box migrate up
box migrate seed

5. AI Skills

CBGenesis comes pre-configured with AI skills to enhance your application's capabilities. These skills are located in the .agents/skills/ directory and can be customized or extended as needed. This will be done via the coldbox-cli and the coldbox ai namespace commands:

# Discover AI Integrations
coldbox ai --help

# Update AI Integrations
coldbox ai refresh

You can update/remove your AI Agents via the coldbox ai agents commands.

6. Start the Server

box server start

License

Apache 2.0 License

Issues

You can report issues and bugs related to this project on the GitHub Issues page.

❤️ Support Us

You can support the development of this project by starring the repository on GitHub, contributing to the codebase, or providing financial support through platforms like Patreon or purchasing a BoxLang license. Your support helps us maintain and improve the project for the community.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

Unreleased

Added

  • Self-service email change: a signed-in user requests a new address from their profile, confirms it from a token emailed to the new address, and the old address gets a heads-up notice. Backed by a new nullable pendingEmail column and a PURPOSE_EMAIL_CHANGE action token. (#24)
  • COLDBOX_REINIT_PASSWORD environment variable for ?fwreinit. Left unset, each boot falls back to a random UUID, which closes framework reinit rather than leaving it open. (#28)

Changed

  • CSRF verification is now deny-by-default. BaseSecureHandler.preHandler() rejects any request into a secured handler that is not GET, HEAD, or OPTIONS and does not carry a valid rc.csrf, replacing the per-handler static.csrfVerify opt-in maps. Handlers that render HTML override onInvalidCSRF() to flash and redirect instead of returning a bare 403. (#35)
  • The seeded [email protected] account is created reset-pending. The bootstrap password hash ships in this repository and is public, so signing in with it no longer grants a session; it sends you straight to the reset-password form. (#29)
  • The password policy (cbMinPasswordLength plus upper, lower, digit, and special character) and a confirmation-match check are now enforced on password reset, not just on registration. (#34)
  • Pre-release migration cleanup: the pendingEmail, hasAvatar, and user_sso_identities migrations are folded into the base ..._users.bx migration now that they ship together, so a fresh install runs one users migration instead of four.

Fixed

  • Unchecking every permission on a role and saving reported success but kept the old permissions. The roles form sent one repeated permissions[] field per selected permission, so an empty selection sent no field at all, and populate() leaves a relationship alone when its key is missing. The form now always sends a single comma-delimited permissions field, empty when nothing is selected. (#68)
  • Saving Global Settings crashed with "Cannot invoke method [setValue()] on a null object" and saved nothing, whenever the settings cache still recognized a key whose database row was missing (a stale cache, or a key added to DEFAULTS since the app's last boot). bulkSave() now creates the row instead of assuming it already exists. (#63)
  • Self-service registration and admin invitations were both broken: doRegister called a non-existent .validate() on the user entity, and the email field was silently dropped by the entity's population exclude list. (#31)
  • Every validation error path in the handlers returned a 500 instead of the validation messages, calling the singular getValidationResult() where cborm defines getValidationResults(). (#30)
  • Changing your password from the profile page always failed: isValidPassword() was called on securityService, which does not define it, instead of settingService. (#32)
  • RoleService.deleteRole() threw a MissingMethodException and, once reachable, a Hibernate cascade error. It now clears the role from its assigned users on the owning side of the relationship and flushes before deleting. (#33)
  • The LogBox rolling file appender was declared outside the appenders key, so it was never registered and nothing was written to app/logs. (#27)
  • Mementifier's date mask setting was misspelled, so entity mementos ignored the configured format. (#26)
  • ormReload() ran on every request in development rather than only on an authenticated framework reinit. (#28)
  •   Ortus Solutions
  • Published
  • 1.0.0-snapshot is the latest of 1 release(s)
    Published
  • Published on {{ getFullDate("2026-09-29T13:26:30Z") }}

$ box install cbgenesis

No collaborators yet.
   
  • {{ getFullDate("2026-06-24T18:33:15Z") }}
  • {{ getFullDate("2026-09-29T13:26:30Z") }}
  • 341
  • 19