f451 1.1: Classifications and Frozen Releases

One day after version 1.0.0, f451 1.1.0 is out. Pages get a security classification, and approved versions can be frozen as a read-only copy in Git. The update is backward compatible. If you turn on neither feature, nothing changes.
Four Classes That Control Where Content Travels
Every page can carry one of four classes: public, internal, confidential, and strictly confidential. The class appears as a chip on the page, and strictly confidential pages also get a banner saying not to distribute the content.
| Class | Effect |
|---|---|
| Public | Chip on the page |
| Internal | Chip on the page |
| Confidential | Chip, search shows the hit without a text snippet |
| Strictly confidential | Chip and banner, never shown in search and not listed as a related page in the graph |
A class neither grants nor revokes read access. Who may read a page is still decided by the repository, as it has been in f451 from the start. The class tells readers how to handle the content and keeps it out of channels through which it would spread further. Those are search snippets, related-page lists, and AI agents.
Classes are turned on per space in _meta/schema.yaml.
classification:
default: internal
max: confidential
The key setting is max. A space the whole company can read gets max: internal. A confidential page can then be neither saved nor approved there, because the editor offers nothing above the limit and the API rejects a higher class. Without the block, a space behaves exactly as before.
A Ceiling for AI Agents
Until now, an agent using the MCP service read everything its user may read, through that user’s personal API token. As of 1.1, every API token has a ceiling chosen when it is created, by default “internal”. For a page above that ceiling, the token sees only title and class. Content, Markdown source, and every write action are refused, and the agent tells its user that the token is too narrow.
In a space with classes, an agent can therefore work on operations documentation without the content of confidential pages ending up in its model context. It still sees title and class. Existing tokens get the ceiling “internal” through a migration. That only matters in spaces that turn classes on. Browser sessions have no ceiling, because anyone who can read a repository reads every page in it.
Frozen Releases Next to the Page
In a versioned space (versioning: true), every approval has received a version number since 1.0. The release archive builds on that, because the number names the copy. Ticking “Freeze as release” in the review creates a complete copy of the page, including the attachments it references, right next to it in the repository.
<page folder>/
index.md
_media/
_releases/
1.2.0/
page.md
_media/
The copy is written in the same commit as the new version number, so there is never a version without its copy. A frozen release opens read-only, with its own class, tags, and metadata from the moment of approval. It stays readable as a whole page, even after the page has been edited many times, the Git history was rewritten, or the database was lost. Agents read a release via read_page with a version.
Read-only here means read-only through f451. No route writes into _releases/. Anyone with write access to the repository can still change the files in Git. f451 notices this at the next reindex and visibly marks the release as changed after freezing. For an audit, that means a later change to a release file does not go unnoticed.
There is one limit. Deleting a page deletes its releases too. To keep them, archive the page instead of deleting it.
Try It
In the Playground of the live demo, versioning and classes are turned on. Sign in through Forgejo with writer / 43dc099d5da028f4. Set a page to “strictly confidential” and search for it to see the difference right away. You can also freeze an approval as a release, change the page afterwards, and open the release from the header line. It still shows the old version. The demo is reset every night.
The full description is in the Admin Guide under Classifications and Releases, and in the changelog.
Sources
- f451 1.1.0, release notes: github.com/rotecodefraktion/f451/releases/tag/v1.1.0
- Changelog 1.1.0: CHANGELOG.md
- Admin Guide, Classifications: classifications/index.md
- Admin Guide, Releases: releases/index.md
- Live demo: f451.rotecodefraktion.de