{"MetaKeywords":null,"MetaDescription":"GrandNode 2.4 moves to .NET 10, adds a separate panel for store owners, hardens security across the platform and renews the storefront and admin.","MetaTitle":"What's new in GrandNode 2.4","SeName":"whats-new-in-grandnode-24","Title":"What's new in GrandNode 2.4: .NET 10, a store owner panel and a security overhaul","PictureModel":{"ImageUrl":null,"ThumbImageUrl":null,"FullSizeImageUrl":null,"Title":null,"AlternateText":null,"Style":null,"ExtraField":null,"Id":null,"UserFields":[]},"Body":"<p>GrandNode 2.4 is the biggest release since GrandNode 2.0. It moves the platform to .NET 10, gives store owners their own panel, closes a long list of security gaps found in a systematic review, and renews both the storefront and the admin. The full changelog is in the <a href=\"https://github.com/grandnode/grandnode2/releases\" rel=\"noopener\">release notes on GitHub</a>.</p>\n\n<h2 id=\"highlights\">The highlights</h2>\n<ul>\n<li><strong>.NET 10</strong> and a leaner dependency tree.</li>\n<li><strong>A store owner panel</strong> for multi-store and SaaS setups.</li>\n<li><strong>Security:</strong> PBKDF2 passwords, CSRF protection everywhere, allowlist HTML sanitization and fixed cross-store access gaps.</li>\n<li><strong>Performance:</strong> catalog cache per customer group, async database access and safe multi-instance scheduling.</li>\n<li><strong>A new storefront frontend</strong> (Vue 3, Bootstrap 5, Vite) and a modernised admin panel.</li>\n<li><strong>Better data for search engines and AI assistants:</strong> richer structured data and real availability.</li>\n</ul>\n\n<h2 id=\"dotnet-10\">.NET 10 and a leaner stack</h2>\n<p>GrandNode 2.4 runs on .NET 10, with .NET Aspire 13 for local orchestration. Two third-party libraries the whole codebase depended on were replaced with small in-house ones: <code>Grand.Mediator</code> instead of MediatR and <code>Grand.Mapping</code> instead of AutoMapper. JSON Patch moved from Newtonsoft.Json to System.Text.Json, and the solution file moved to the XML-based <code>.slnx</code> format.</p>\n\n<h2 id=\"store-panel\">A panel for store owners</h2>\n<p>The largest new feature is the store owner panel (<code>Grand.Web.Store</code>). In a multi-store installation, each store can now be managed by its own \"Store manager\" without access to the main admin panel: products and their attributes, reviews, CMS pages, blog, message templates, settings, currencies, languages, shipping, discounts, tax, payments, e-mail accounts and customers - all limited to that store. System-wide settings stay locked to the main admin.</p>\n<p>This makes GrandNode a practical base for hosting many independent shops on one installation, the SaaS model. See <a href=\"/store-panel-overview\">the store owner panel</a> in the documentation.</p>\n\n<h2 id=\"security\">Security</h2>\n<p>2.4 is the result of a systematic security review of the codebase. Among the changes:</p>\n<ul>\n<li>Customer passwords are hashed with <strong>PBKDF2</strong>; older hashes are upgraded transparently when a customer signs in, and passwords are no longer stored in a reversible form.</li>\n<li><strong>CSRF protection</strong> on every storefront controller, admin plugin POST actions and the admin file manager.</li>\n<li>An <strong>allowlist HTML sanitizer</strong> replaces the old script blacklist for content written in the editors.</li>\n<li>Fixed <strong>cross-store and vendor access gaps</strong> (IDOR) in the store owner and vendor panels, with ownership checks consolidated in one place.</li>\n<li>Fixed a memory denial-of-service and an extension bypass in file uploads, an open redirect, and API query parsing without a timeout. Weak JWT secrets now stop the application from starting.</li>\n</ul>\n<p>Release Docker images are signed and published with an SBOM and build provenance (SLSA), so you can verify what you deploy.</p>\n\n<h2 id=\"performance\">Performance and reliability</h2>\n<ul>\n<li>The storefront catalog is cached per customer group instead of per customer, so far more visitors share one cache entry.</li>\n<li>Paged and repository queries run asynchronously on the MongoDB driver instead of blocking threads; stock updates are batched.</li>\n<li>Order numbers are assigned under a unique index - no duplicates under load.</li>\n<li>Running several instances is safer: resilient Redis cache invalidation, scheduled tasks that run exactly once, and files written at runtime shared through one media path.</li>\n<li>A <code>/health/ready</code> endpoint for load balancers and orchestrators.</li>\n</ul>\n\n<h2 id=\"frontend\">A new storefront frontend and a modern admin</h2>\n<p>The storefront moved to <strong>Vue 3, Bootstrap 5 and Vite</strong>, with dark mode, faster pages and checkout fixes. Two themes show what it can do: a redesigned <strong>Modern</strong> theme and the new <strong>Nordic Editorial</strong> theme. On phones the header icons move to a bottom bar.</p>\n<p>The admin, store owner and vendor panels were rebuilt on Bootstrap 5 without the commercial Kendo UI library, with new data grids, a consistent component layer and redesigned sign-in screens with password recovery.</p>\n\n<h2 id=\"seo-ai\">Search engines and AI assistants</h2>\n<ul>\n<li>Product structured data (JSON-LD) now includes ratings, shipping details and the return policy, and reports real availability to search engines and AI crawlers.</li>\n<li>The XML sitemap task was fixed, and the product quick view no longer adds incomplete microdata to every page.</li>\n</ul>\n\n<h2 id=\"developers\">For plugin and theme developers</h2>\n<p>Most plugins need small changes for 2.4: target <code>net10.0</code>, replace MediatR and AutoMapper usings with <code>Grand.Mediator</code> and <code>Grand.Mapping</code>, and review storefront views against Vue 3 and Bootstrap 5. The repository also ships the <a href=\"/ai-agent-kit\">AI Agent Kit</a> - architecture notes, conventions and review checklists that coding agents such as Claude Code, Codex or Cursor read from <code>AGENTS.md</code> - which helps with exactly this kind of upgrade. See <a href=\"/developers-upgrade-migrations\">upgrades and migrations</a> and <a href=\"/getting-started-upgrading\">upgrading GrandNode</a>.</p>\n\n<h2 id=\"upgrade\">How to get it</h2>\n<ul>\n<li>Run the <code>grandnode/grandnode2</code> Docker image, or download the release package from <a href=\"https://github.com/grandnode/grandnode2/releases\" rel=\"noopener\">GitHub</a> - see <a href=\"/download\">Download</a>.</li>\n<li>You need the .NET 10 runtime and MongoDB 4.0 or newer - see <a href=\"/getting-started-system-requirements\">system requirements</a>.</li>\n<li>Upgrading an existing store: back up the database and try the upgrade on a copy first. Database migrations run when the application starts.</li>\n</ul>\n<p>Found a problem? Report it on <a href=\"https://github.com/grandnode/grandnode2/issues\" rel=\"noopener\">GitHub</a>.</p>\n\n<h2 id=\"lts\">2.4 and long-term support</h2>\n<p>GrandNode 2.4 is planned as the first long-term support (LTS) release, with 24 months of security fixes for companies that cannot upgrade every few months. LTS releases, backports and private vulnerability notices are part of <a href=\"/official\">GrandNode Official</a>; buy now and your plan period starts when the first LTS release is published.</p>","BodyOverview":"<p>GrandNode 2.4 is the biggest release since 2.0: .NET 10, a separate panel for store owners, a security overhaul, a new storefront frontend and a modernised admin. Here is what changes and how to upgrade.</p>","AllowComments":false,"NumberOfComments":0,"CreatedOn":"2026-10-03T14:00:00","Tags":["GrandNode 2.4","release",".NET 10","security"],"Comments":[],"AddNewComment":{"CommentText":null,"DisplayCaptcha":true,"Captcha":{"ReCaptchaChallengeField":null,"ReCaptchaResponseField":null,"ReCaptchaResponseValue":null,"ReCaptchaResponse":null},"Id":null,"UserFields":[]},"Id":"6ac1275b19d48bd48b804d60","UserFields":[{"Key":"gnc.blog.hash","Value":"0c46a5753ead04625fb07f02b0c225e148042d96","StoreId":""}]}