Skip to content

CON2: recreate fork on current upstream main - #14

Open
japsu wants to merge 447 commits into
mainfrom
con2-next
Open

japsu wants to merge 447 commits into
mainfrom
con2-next

Conversation

@japsu

@japsu japsu commented Aug 4, 2026

Copy link
Copy Markdown

NOTE: our main branch is con2 and the intent of con2-next is to become the next con2 branch. This pull request exists not for the purpose of merging into main but to make our diff against upstream reviewable.

Ports forward con2's custom bits onto a fresh base (upstream main, v1.9.1+212 commits, vs. con2's previous anchor at v0.67.0 from Jan 2023), replacing the pieces that no longer fit the current codebase:

  • New plugins/kompassi plugin, replacing the old hand-rolled OAuth2 provider (server/routes/auth/providers/kompassi.ts, which used an auth-provider mechanism that no longer exists upstream). Talks to Kompassi's now-standard OIDC provider instead of the legacy /oauth2 + /api/v2/people/me endpoints, keeps the same hard sign-in gate and admin-group role sync (KOMPASSI_ACCESS_GROUPS / KOMPASSI_ADMIN_GROUPS), and syncs groups via Outline's core (currently unused by any bundled plugin) group-sync framework instead of the old plugin's manual, not-team-scoped GroupUser sync. Deliberately keeps authenticationProvider.name = "kompassi" (not "oidc") and forces emailVerified = true so existing user accounts and the existing AuthenticationProvider row on each site reattach instead of being orphaned; see plugins/kompassi/server/auth/ kompassiRouter.ts for the reasoning.
  • New plugins/local, a straight port of the old insecure dev-only sign-in shortcut onto the current plugin/accountProvisioner APIs.
  • server/models/Attachment.ts: reapply the MinIO isPrivate override.
  • Dockerfile.con2 rewritten as a thin wrapper around upstream's own now-current Dockerfile/Dockerfile.base (Node 26, previously we carried a frozen Node 16 fork of both) instead of forking them; skaffold.in.yaml gains a third build stage to fit.
  • kubernetes/, .github/workflows/con2.yaml ported over unchanged, since the env var surface (KOMPASSI_, POSTGRES_, etc.) didn't change.

Verified: yarn install, yarn tsc (0 errors), yarn oxlint --type-aware on the new/changed files, yarn build:server, and yarn vite:build all pass on this branch. Not yet verified: an actual login against Kompassi (needs a registered OIDC Application, none exist yet for Outline on Kompassi) or a real Docker/K8s deploy.

tommoor and others added 30 commits August 24, 2026 16:59
* chore: Upgrade mermaid to 11.17.1

Also bumps @mermaid-js/layout-elk to 0.2.3, which is the matching release,
and dedupes katex — mermaid now requires ^0.16.47 where the project pinned
^0.16.45, which would otherwise ship two copies.

Note that classDiagram now uses the unified (v2) renderer by default.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: Hold @mermaid-js/layout-elk at 0.2.2

0.2.3 inlines its own copy of mermaid instead of importing the peer, which
duplicates every diagram chunk and adds 3.4MB to the built bundle. Pinned
exactly so the range cannot drift back onto it.
…3552)

The browser closes IndexedDB connections at times the page does not
control – a frozen or discarded tab, a navigation away, or another tab
deleting the database at logout. Persisted store data is a cache that
API traffic always overrides, so these failures have no effect for the
user, but each one was reported to Sentry as a warning.

- Log connection closed failures at debug level instead of reporting them
- Delete the database in clear() rather than emptying it through a
  transaction, which cannot fail against a closed connection
- Keep persistence enabled when hydration fails on a closed connection,
  rather than disabling it for the rest of the session

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps [@octokit/auth-app](https://github.com/octokit/auth-app.js) from 8.2.0 to 8.3.0.
- [Release notes](https://github.com/octokit/auth-app.js/releases)
- [Commits](octokit/auth-app.js@v8.2.0...v8.3.0)

---
updated-dependencies:
- dependency-name: "@octokit/auth-app"
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [dd-trace](https://github.com/DataDog/dd-trace-js) from 5.117.0 to 5.123.0.
- [Release notes](https://github.com/DataDog/dd-trace-js/releases)
- [Commits](DataDog/dd-trace-js@v5.117.0...v5.123.0)

---
updated-dependencies:
- dependency-name: dd-trace
  dependency-version: 5.123.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [react-hook-form](https://github.com/react-hook-form/react-hook-form) from 7.76.0 to 7.85.0.
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.76.0...v7.85.0)

---
updated-dependencies:
- dependency-name: react-hook-form
  dependency-version: 7.85.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#13544)

Bumps [prosemirror-dropcursor](https://github.com/prosemirror/prosemirror-dropcursor) from 1.8.2 to 1.8.3.
- [Changelog](https://github.com/ProseMirror/prosemirror-dropcursor/blob/master/CHANGELOG.md)
- [Commits](https://github.com/prosemirror/prosemirror-dropcursor/commits)

---
updated-dependencies:
- dependency-name: prosemirror-dropcursor
  dependency-version: 1.8.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the aws group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1111.0` | `3.1115.0` |
| [@aws-sdk/lib-storage](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage) | `3.1111.0` | `3.1115.0` |
| [@aws-sdk/s3-presigned-post](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-presigned-post) | `3.1111.0` | `3.1115.0` |
| [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) | `3.1111.0` | `3.1115.0` |
| [@aws-sdk/signature-v4-crt](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/signature-v4-crt) | `3.1111.0` | `3.1115.0` |


Updates `@aws-sdk/client-s3` from 3.1111.0 to 3.1115.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/clients/client-s3)

Updates `@aws-sdk/lib-storage` from 3.1111.0 to 3.1115.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-storage/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/lib/lib-storage)

Updates `@aws-sdk/s3-presigned-post` from 3.1111.0 to 3.1115.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/packages/s3-presigned-post)

Updates `@aws-sdk/s3-request-presigner` from 3.1111.0 to 3.1115.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/packages/s3-request-presigner)

Updates `@aws-sdk/signature-v4-crt` from 3.1111.0 to 3.1115.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/signature-v4-crt/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/packages/signature-v4-crt)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1115.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/lib-storage"
  dependency-version: 3.1115.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/s3-presigned-post"
  dependency-version: 3.1115.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1115.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/signature-v4-crt"
  dependency-version: 3.1115.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fix: Refactor useCollectionTrees hook

* Avoid unneccessary work
…utline#13558)

Nested .oxlintrc.json files replace the root config per-rule rather than
merging, so the root's shared/** override for no-restricted-imports was
dead config and the sonner restriction was not enforced anywhere.

Move the restrictions into shared/.oxlintrc.json, add the
prosemirror-tables entry to app/.oxlintrc.json where the same shadowing
applies to .tsx files, and drop the dead root override.
* fix: Make count-based limit checks reliable under concurrency

Limits enforced by counting rows before an insert could be exceeded by
requests that ran at the same time, as each one read the same count
before any of them had written. Add a LockHelper that takes a Postgres
advisory lock for the remainder of the transaction, and use it to
serialize the check for webhook subscriptions, team domains, share
subscriptions and pins. The counts now also run on the transaction so
they include rows written earlier in the same request.

* Remove excessive tests

* Also guard simultaneous row removal
* chore: Reduce cardinality of datadog metrics

* address feedback
Heading numbers are drawn by a ProseMirror decoration, and the server
strips all plugin decorations before it serializes, so exported HTML
always came out unnumbered.

Compute the same labels during export and write them to the rendered
headings as a data attribute, which the exported editor styles already
render. A revision takes the preference from the document it belongs to.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…13566)

Resolve the sidebar context from location state when no provider supplies
one, and preserve it when leaving or deleting a revision from history.
…osition (outline#13575)

Dropping a file in the margins around a document previously did nothing.
react-dnd's window level dragover handler forced dropEffect to "none" for
any target outside of .ProseMirror, so the browser never dispatched a drop
event there.
* chore: Vendorize y-indexeddb persistence

Replaces the y-indexeddb dependency with a small typed module in
app/utils/IndexeddbPersistence.ts so we have full control over the
underlying database rows. The IndexedDB schema is unchanged and remains
compatible with databases created by y-indexeddb, so existing local
caches continue to work.

Differences from upstream:
- Promise-based API (whenSynced) instead of the lib0 Observable events,
  which simplifies MultiplayerEditor and lets it handle environments
  where IndexedDB exists but cannot be opened (e.g. Firefox private
  browsing) by falling back to no local persistence.
- Skips writing an empty state row every time a document is opened.
- Exposes a public compact() to merge all rows into one on demand.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9

* chore: Remove persistence tests and fake-indexeddb dependency

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9

* chore: Make trim size a private class member, drop unused custom store

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9

* fix: Guard async persistence callbacks against post-cleanup state updates

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9

* Added onversionchange handler

---------

Co-authored-by: Claude <noreply@anthropic.com>
…utline#13571)

The revision branch of DocumentMeta keys the "You updated" case off
revision.createdBy, but the displayed name falls back to the document's
current updatedBy. Viewing a revision created by another user therefore
attributes it to whoever last edited the document, next to the
revision's own timestamp.

Display revision.createdBy's name instead, falling back to "Unknown"
when the author is unavailable, matching the existing deletedBy
handling.

Fixes outline#13570

Co-authored-by: Claude <noreply@anthropic.com>
…utline#13403)

* checkpoint

* feat: Convert @ prefixed links to mentions on server Markdown writes

A Markdown link preceded by "@" now becomes a mention when brought in
through the documents API, MCP, or an import, so an exported mention
survives a round trip instead of degrading to a plain link.

The editor rule creates a generic mention carrying the href, and the
type of resource it points at is resolved by the plugin that recognizes
the URL through a new MentionProvider hook. Mentions of external
resources also serialize to their real URL rather than a mention:// URI,
so the reference resolves outside of Outline.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: Escape values interpolated into rendered mention HTML

markdown-it leaves markup in a link label intact when html is disabled,
so the label and attributes are escaped before being written into the
tag.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ine#13577)

* feat: Support HEIC avatar uploads with in-browser conversion

HEIC and HEIF images picked for an avatar are now converted to JPEG in
the browser before the cropper opens. The browser's own decoder is used
when it supports the format, otherwise a WebAssembly decoder is loaded
on demand.

Also collects the image utilities into an ImageHelper class, fixes the
crop dialog's submit button never disabling, and stops the upload from
forwarding request headers the browser controls itself.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* refactor: Use only the browser's own HEIC decoder

Drops the bundled WebAssembly decoder in favour of the browser's native
support. This removes an LGPL dependency and a 3MB lazy chunk, and lets
the Content Security Policy stay as it was.

Browsers without HEIC support now get a message asking for a JPEG or PNG.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs: Add class-level JSDoc to ImageHelper

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…3583)

Dynamic client registration rejected any client sending more than 10
redirect URIs. The limit is now 20, shared between the register and
update schemas, and the error reports how many were received.

OAuth client errors were swallowed without reaching logs or Sentry,
leaving a failing integration invisible beyond its status code. 4xx
responses are now logged with the reason.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: Preserve MCP attachment form values

* fix: Escape MCP attachment form arguments

* fix: Support current TypeScript library target
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: Preserve expanded code blocks after undo

* refactor: Rename used editor state parameter
* fix: Deadlock on cleanup task retry

* Add transaction advisory lock around team deletion
tommoor and others added 26 commits September 26, 2026 08:07
)

External providers can legitimately report several groups with the same
display name. Previously the second group failed the team-wide name
uniqueness check, or duplicates slipped through on creation and then
broke every subsequent sync with a validation error.

- Scope the group name uniqueness check by (team, externalId) so synced
  groups with different external ids can share a name while manually
  created groups remain unique among themselves
- Compare names with lower() equality instead of iLike so LIKE wildcards
  in names are not treated as collisions
- Stamp externalId on groups created by the syncer and backfill it on
  previously synced groups
…ne#13895)

* perf: Load templates on demand and cache fetchAll results

fetchAll on the base store now returns the first result for repeat calls
with the same params, with a force option for callers that need fresh
data. Templates load when the command bar, document header, or block
menu needs them instead of on every page load.

* Make fetchAll caching opt-in via fetchAllIfNeeded

fetchAll always fetches again. fetchAllIfNeeded returns the previous
result for the same params until a model is added to or removed from
the store. Mount-effect callers for reference lists use it.
* feat: Add plan-based feature entitlements

* feat: Gate audit log behind AuditLog entitlement

* Guard guests

* features
* wip

* fix: Position grips in merged cells from the rendered layout

* fix: Only merge row and column selections that cover whole rows or columns

* perf: Find merged cell spans without scanning the table map

* refactor: Extract helpers for cells starting in a row or column
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.4.0 to 10.7.2.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.4.0...v10.7.2)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [undici](https://github.com/nodejs/undici) from 7.29.0 to 7.30.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 10.0.0 to 10.0.2.
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v10.0.0...v10.0.2)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 10.0.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.5 to 8.3.1.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [chrono-node](https://github.com/wanasit/chrono) from 2.9.1 to 2.10.1.
- [Release notes](https://github.com/wanasit/chrono/releases)
- [Commits](wanasit/chrono@v2.9.1...v2.10.1)

---
updated-dependencies:
- dependency-name: chrono-node
  dependency-version: 2.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the aws group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1135.0` | `3.1140.0` |
| [@aws-sdk/cloudfront-signer](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/cloudfront-signer) | `3.1125.0` | `3.1138.0` |
| [@aws-sdk/lib-storage](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage) | `3.1135.0` | `3.1140.0` |
| [@aws-sdk/s3-presigned-post](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-presigned-post) | `3.1135.0` | `3.1140.0` |
| [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) | `3.1135.0` | `3.1140.0` |
| [@aws-sdk/signature-v4-crt](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/signature-v4-crt) | `3.1135.0` | `3.1140.0` |


Updates `@aws-sdk/client-s3` from 3.1135.0 to 3.1140.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/clients/client-s3)

Updates `@aws-sdk/cloudfront-signer` from 3.1125.0 to 3.1138.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/cloudfront-signer/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1138.0/packages/cloudfront-signer)

Updates `@aws-sdk/lib-storage` from 3.1135.0 to 3.1140.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-storage/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/lib/lib-storage)

Updates `@aws-sdk/s3-presigned-post` from 3.1135.0 to 3.1140.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/packages/s3-presigned-post)

Updates `@aws-sdk/s3-request-presigner` from 3.1135.0 to 3.1140.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/packages/s3-request-presigner)

Updates `@aws-sdk/signature-v4-crt` from 3.1135.0 to 3.1140.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/signature-v4-crt/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/packages/signature-v4-crt)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/cloudfront-signer"
  dependency-version: 3.1138.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/lib-storage"
  dependency-version: 3.1140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/s3-presigned-post"
  dependency-version: 3.1140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: "@aws-sdk/signature-v4-crt"
  dependency-version: 3.1140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@octokit/auth-app](https://github.com/octokit/auth-app.js) from 8.3.0 to 8.3.1.
- [Release notes](https://github.com/octokit/auth-app.js/releases)
- [Commits](octokit/auth-app.js@v8.3.0...v8.3.1)

---
updated-dependencies:
- dependency-name: "@octokit/auth-app"
  dependency-version: 8.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the sentry group with 2 updates: [@sentry/node](https://github.com/getsentry/sentry-javascript) and [@sentry/react](https://github.com/getsentry/sentry-javascript).


Updates `@sentry/node` from 10.75.0 to 10.75.3
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.75.0...10.75.3)

Updates `@sentry/react` from 10.75.0 to 10.75.3
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.75.0...10.75.3)

---
updated-dependencies:
- dependency-name: "@sentry/node"
  dependency-version: 10.75.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sentry
- dependency-name: "@sentry/react"
  dependency-version: 10.75.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sentry
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…nts (outline#13899)

* fix: Invalidate collaboration connections on document lifecycle events

* fix: Invalidate descendant connections and handle unarchive
…ine#13923)

* feat: Redirect root domain app links to the signed-in workspace

* fix: Treat non-object sessions cookie values as empty
Ports forward con2's custom bits onto a fresh base (upstream main,
v1.9.1+212 commits, vs. con2's previous anchor at v0.67.0 from Jan
2023), replacing the pieces that no longer fit the current codebase:

- New plugins/kompassi plugin, replacing the old hand-rolled OAuth2
  provider (server/routes/auth/providers/kompassi.ts, which used an
  auth-provider mechanism that no longer exists upstream). Talks to
  Kompassi's now-standard OIDC provider instead of the legacy
  /oauth2 + /api/v2/people/me endpoints, keeps the same hard
  sign-in gate and admin-group role sync (KOMPASSI_ACCESS_GROUPS /
  KOMPASSI_ADMIN_GROUPS), and syncs groups via Outline's core
  (currently unused by any bundled plugin) group-sync framework
  instead of the old plugin's manual, not-team-scoped GroupUser sync.
  Deliberately keeps authenticationProvider.name = "kompassi" (not
  "oidc") and forces emailVerified = true so existing user accounts
  and the existing AuthenticationProvider row on each site reattach
  instead of being orphaned; see plugins/kompassi/server/auth/
  kompassiRouter.ts for the reasoning.
- New plugins/local, a straight port of the old insecure dev-only
  sign-in shortcut onto the current plugin/accountProvisioner APIs.
- server/models/Attachment.ts: reapply the MinIO isPrivate override.
- Dockerfile.con2 rewritten as a thin wrapper around upstream's own
  now-current Dockerfile/Dockerfile.base (Node 26, previously we
  carried a frozen Node 16 fork of both) instead of forking them;
  skaffold.in.yaml gains a third build stage to fit.
- kubernetes/, .github/workflows/con2.yaml ported over unchanged,
  since the env var surface (KOMPASSI_*, POSTGRES_*, etc.) didn't
  change.

Verified: yarn install, yarn tsc (0 errors), yarn oxlint --type-aware
on the new/changed files, yarn build:server, and yarn vite:build all
pass on this branch. Not yet verified: an actual login against
Kompassi (needs a registered OIDC Application, none exist yet for
Outline on Kompassi) or a real Docker/K8s deploy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…image

The init container ran "yarn sequelize:migrate", a script upstream renamed
to db:migrate years ago, in an image that no longer ships yarn. Run the
compiled checkMigrations script directly instead; it is the same check the
server forks on boot, so a failing migration now fails the rollout before
traffic shifts. PGSSLMODE already selects the SSL mode, so the
production-ssl-disabled sequelize env is not needed.

Also: FILE_STORAGE_UPLOAD_MAX_SIZE replaces the deprecated
AWS_S3_UPLOAD_MAX_SIZE, the pod runs as uid 1001 to match the image's nodejs
user, the writable home mount follows that user, and the local-storage test
directory is ignored.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ng them

Core group sync matches groups through external_groups rows, never by
name, so the first synced sign-in created a second copy of every group the
legacy provider had mirrored, leaving collection permissions on the old
ones. A data migration links each existing group of a team with a kompassi
provider under its own name, which is the id the plugin reports.

The sync provider now reports only groups named in KOMPASSI_ACCESS_GROUPS
and KOMPASSI_ADMIN_GROUPS. The legacy provider mirrored only those, and a
Kompassi account belongs to dozens of groups from unrelated events (51
appeared on the first sync of the con2 dump against 5 before).

Verified by restoring the con2 dump into a scratch database and running all
migrations: the five groups end up linked to the kompassi provider.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
On the fork the scheduled ones (stale, auto-close-prs, docker-nightly,
update-node, codeql) would run against con2's issues and registries, and
the push-triggered ones target refs or secrets this repository does not
have.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
japsu and others added 3 commits October 1, 2026 13:27
The 2020 Minio rejects the download URLs the current AWS SDK signs
(SignatureDoesNotMatch), and Minio is end of life, so con2.fi moves to
garage.con2.fi now rather than after the Helm and CloudNativePG steps. The
other four sites stay on Minio until their own upgrade.

Garage has no ACLs, so aws_s3_acl can be empty, which makes the server omit
the x-amz-acl header. con2-s3-cors.js stores the CORS rule browser uploads
need; it reads the pod's own AWS_* settings so it runs inside the pod.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.