BoxLang 🚀 A New JVM Dynamic Language Learn More...
A production-ready ColdBox HMVC starter for the BoxLang language - authentication, SSO, RBAC permissions, API tokens, rate limiting, an Alpine-powered admin panel, and a real test suite, so you spend day one building features instead of scaffolding.
@secured handler annotations, CSRF rotation,
JWT support, and a resource:action permission model
with roles and permissions admin screens.cbsecurity-passkeys, with an optional policy that
requires a passkey before a user can proceed.app/, fully separated from the public webroot in
public/ - enhanced security by default.BaseEntity/BaseService conventions on top
of cborm, migrations and seed data via cfmigrations, and qb for
anything raw SQL does better.Full documentation lives here:
bx-cli)Easily get started with the cbGenesis template by following these 5 steps:
bx-cli)Install BoxLang into your operating system using our Quick Installer or the BoxLang Version Manager (BVM). Once installed, you can proceed with adding the BoxLang-native CommandBox CLI module.
Warning: Make sure you have the BoxLang-native CommandBox CLI installed, as the regular Lucee CommandBox is not supported.
# Install CommandBox
install-bx-module bx-cli
# Install the ColdBox CLI Module
box install coldbox-cli
This installs the BoxLang-native CommandBox CLI module and the
ColdBox CLI module, allowing you to use the box commands
specific to BoxLang.
This template requires Vite and UI elements that require Node.js 22+ to build and run properly. So make sure you have Node.js 22+ installed on your system.
Use the coldbox-cli to scaffold a new project.
box coldbox create app name="my-app" skeleton="cbgenesis"
# Install BoxLang Dependencies
box install
# Install Node.js Dependencies
npm install
Configure your database connection in the .env file and
run the necessary migrations to set up the database schema.
box migrate up
box migrate seed
CBGenesis comes pre-configured with AI skills to enhance your
application's capabilities. These skills are located in the
.agents/skills/ directory and can be customized or
extended as needed. This will be done via the
coldbox-cli and the coldbox ai namespace commands:
# Discover AI Integrations
coldbox ai --help
# Update AI Integrations
coldbox ai refresh
You can update/remove your AI Agents via the coldbox ai
agents commands.
box server start
Apache 2.0 License
You can report issues and bugs related to this project on the GitHub Issues page.
You can support the development of this project by starring the repository on GitHub, contributing to the codebase, or providing financial support through platforms like Patreon or purchasing a BoxLang license. Your support helps us maintain and improve the project for the community.
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
pendingEmail column and a PURPOSE_EMAIL_CHANGE action token. (#24)COLDBOX_REINIT_PASSWORD environment variable for ?fwreinit. Left unset, each boot falls back to a random UUID, which closes framework reinit rather than leaving it open. (#28)BaseSecureHandler.preHandler() rejects any request into a secured handler that is not GET, HEAD, or OPTIONS and does not carry a valid rc.csrf, replacing the per-handler static.csrfVerify opt-in maps. Handlers that render HTML override onInvalidCSRF() to flash and redirect instead of returning a bare 403. (#35)[email protected] account is created reset-pending. The bootstrap password hash ships in this repository and is public, so signing in with it no longer grants a session; it sends you straight to the reset-password form. (#29)cbMinPasswordLength plus upper, lower, digit, and special character) and a confirmation-match check are now enforced on password reset, not just on registration. (#34)pendingEmail, hasAvatar, and user_sso_identities migrations are folded into the base ..._users.bx migration now that they ship together, so a fresh install runs one users migration instead of four.permissions[] field per selected permission, so an empty selection sent no field at all, and populate() leaves a relationship alone when its key is missing. The form now always sends a single comma-delimited permissions field, empty when nothing is selected. (#68)DEFAULTS since the app's last boot). bulkSave() now creates the row instead of assuming it already exists. (#63)doRegister called a non-existent .validate() on the user entity, and the email field was silently dropped by the entity's population exclude list. (#31)getValidationResult() where cborm defines getValidationResults(). (#30)isValidPassword() was called on securityService, which does not define it, instead of settingService. (#32)RoleService.deleteRole() threw a MissingMethodException and, once reachable, a Hibernate cascade error. It now clears the role from its assigned users on the owning side of the relationship and flushes before deleting. (#33)appenders key, so it was never registered and nothing was written to app/logs. (#27)ormReload() ran on every request in development rather than only on an authenticated framework reinit. (#28)
$
box install cbgenesis