Conversation
* chore: Upgrade mermaid to 11.17.1 Also bumps @mermaid-js/layout-elk to 0.2.3, which is the matching release, and dedupes katex — mermaid now requires ^0.16.47 where the project pinned ^0.16.45, which would otherwise ship two copies. Note that classDiagram now uses the unified (v2) renderer by default. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: Hold @mermaid-js/layout-elk at 0.2.2 0.2.3 inlines its own copy of mermaid instead of importing the peer, which duplicates every diagram chunk and adds 3.4MB to the built bundle. Pinned exactly so the range cannot drift back onto it.
…3552) The browser closes IndexedDB connections at times the page does not control – a frozen or discarded tab, a navigation away, or another tab deleting the database at logout. Persisted store data is a cache that API traffic always overrides, so these failures have no effect for the user, but each one was reported to Sentry as a warning. - Log connection closed failures at debug level instead of reporting them - Delete the database in clear() rather than emptying it through a transaction, which cannot fail against a closed connection - Keep persistence enabled when hydration fails on a closed connection, rather than disabling it for the rest of the session Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps [@octokit/auth-app](https://github.com/octokit/auth-app.js) from 8.2.0 to 8.3.0. - [Release notes](https://github.com/octokit/auth-app.js/releases) - [Commits](octokit/auth-app.js@v8.2.0...v8.3.0) --- updated-dependencies: - dependency-name: "@octokit/auth-app" dependency-version: 8.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [dd-trace](https://github.com/DataDog/dd-trace-js) from 5.117.0 to 5.123.0. - [Release notes](https://github.com/DataDog/dd-trace-js/releases) - [Commits](DataDog/dd-trace-js@v5.117.0...v5.123.0) --- updated-dependencies: - dependency-name: dd-trace dependency-version: 5.123.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [react-hook-form](https://github.com/react-hook-form/react-hook-form) from 7.76.0 to 7.85.0. - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](react-hook-form/react-hook-form@v7.76.0...v7.85.0) --- updated-dependencies: - dependency-name: react-hook-form dependency-version: 7.85.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#13544) Bumps [prosemirror-dropcursor](https://github.com/prosemirror/prosemirror-dropcursor) from 1.8.2 to 1.8.3. - [Changelog](https://github.com/ProseMirror/prosemirror-dropcursor/blob/master/CHANGELOG.md) - [Commits](https://github.com/prosemirror/prosemirror-dropcursor/commits) --- updated-dependencies: - dependency-name: prosemirror-dropcursor dependency-version: 1.8.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the aws group with 5 updates: | Package | From | To | | --- | --- | --- | | [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1111.0` | `3.1115.0` | | [@aws-sdk/lib-storage](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage) | `3.1111.0` | `3.1115.0` | | [@aws-sdk/s3-presigned-post](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-presigned-post) | `3.1111.0` | `3.1115.0` | | [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) | `3.1111.0` | `3.1115.0` | | [@aws-sdk/signature-v4-crt](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/signature-v4-crt) | `3.1111.0` | `3.1115.0` | Updates `@aws-sdk/client-s3` from 3.1111.0 to 3.1115.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/clients/client-s3) Updates `@aws-sdk/lib-storage` from 3.1111.0 to 3.1115.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-storage/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/lib/lib-storage) Updates `@aws-sdk/s3-presigned-post` from 3.1111.0 to 3.1115.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/packages/s3-presigned-post) Updates `@aws-sdk/s3-request-presigner` from 3.1111.0 to 3.1115.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/packages/s3-request-presigner) Updates `@aws-sdk/signature-v4-crt` from 3.1111.0 to 3.1115.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/signature-v4-crt/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/packages/signature-v4-crt) --- updated-dependencies: - dependency-name: "@aws-sdk/client-s3" dependency-version: 3.1115.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/lib-storage" dependency-version: 3.1115.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/s3-presigned-post" dependency-version: 3.1115.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/s3-request-presigner" dependency-version: 3.1115.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/signature-v4-crt" dependency-version: 3.1115.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fix: Refactor useCollectionTrees hook * Avoid unneccessary work
…utline#13558) Nested .oxlintrc.json files replace the root config per-rule rather than merging, so the root's shared/** override for no-restricted-imports was dead config and the sonner restriction was not enforced anywhere. Move the restrictions into shared/.oxlintrc.json, add the prosemirror-tables entry to app/.oxlintrc.json where the same shadowing applies to .tsx files, and drop the dead root override.
* fix: Make count-based limit checks reliable under concurrency Limits enforced by counting rows before an insert could be exceeded by requests that ran at the same time, as each one read the same count before any of them had written. Add a LockHelper that takes a Postgres advisory lock for the remainder of the transaction, and use it to serialize the check for webhook subscriptions, team domains, share subscriptions and pins. The counts now also run on the transaction so they include rows written earlier in the same request. * Remove excessive tests * Also guard simultaneous row removal
* chore: Reduce cardinality of datadog metrics * address feedback
Heading numbers are drawn by a ProseMirror decoration, and the server strips all plugin decorations before it serializes, so exported HTML always came out unnumbered. Compute the same labels during export and write them to the rendered headings as a data attribute, which the exported editor styles already render. A revision takes the preference from the document it belongs to. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…13566) Resolve the sidebar context from location state when no provider supplies one, and preserve it when leaving or deleting a revision from history.
…osition (outline#13575) Dropping a file in the margins around a document previously did nothing. react-dnd's window level dragover handler forced dropEffect to "none" for any target outside of .ProseMirror, so the browser never dispatched a drop event there.
* chore: Vendorize y-indexeddb persistence Replaces the y-indexeddb dependency with a small typed module in app/utils/IndexeddbPersistence.ts so we have full control over the underlying database rows. The IndexedDB schema is unchanged and remains compatible with databases created by y-indexeddb, so existing local caches continue to work. Differences from upstream: - Promise-based API (whenSynced) instead of the lib0 Observable events, which simplifies MultiplayerEditor and lets it handle environments where IndexedDB exists but cannot be opened (e.g. Firefox private browsing) by falling back to no local persistence. - Skips writing an empty state row every time a document is opened. - Exposes a public compact() to merge all rows into one on demand. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9 * chore: Remove persistence tests and fake-indexeddb dependency Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9 * chore: Make trim size a private class member, drop unused custom store Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9 * fix: Guard async persistence callbacks against post-cleanup state updates Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XYncL4PQ5jaEeMBNgjRzf9 * Added onversionchange handler --------- Co-authored-by: Claude <noreply@anthropic.com>
…utline#13571) The revision branch of DocumentMeta keys the "You updated" case off revision.createdBy, but the displayed name falls back to the document's current updatedBy. Viewing a revision created by another user therefore attributes it to whoever last edited the document, next to the revision's own timestamp. Display revision.createdBy's name instead, falling back to "Unknown" when the author is unavailable, matching the existing deletedBy handling. Fixes outline#13570 Co-authored-by: Claude <noreply@anthropic.com>
…utline#13403) * checkpoint * feat: Convert @ prefixed links to mentions on server Markdown writes A Markdown link preceded by "@" now becomes a mention when brought in through the documents API, MCP, or an import, so an exported mention survives a round trip instead of degrading to a plain link. The editor rule creates a generic mention carrying the href, and the type of resource it points at is resolved by the plugin that recognizes the URL through a new MentionProvider hook. Mentions of external resources also serialize to their real URL rather than a mention:// URI, so the reference resolves outside of Outline. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: Escape values interpolated into rendered mention HTML markdown-it leaves markup in a link label intact when html is disabled, so the label and attributes are escaped before being written into the tag. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ine#13577) * feat: Support HEIC avatar uploads with in-browser conversion HEIC and HEIF images picked for an avatar are now converted to JPEG in the browser before the cropper opens. The browser's own decoder is used when it supports the format, otherwise a WebAssembly decoder is loaded on demand. Also collects the image utilities into an ImageHelper class, fixes the crop dialog's submit button never disabling, and stops the upload from forwarding request headers the browser controls itself. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: Use only the browser's own HEIC decoder Drops the bundled WebAssembly decoder in favour of the browser's native support. This removes an LGPL dependency and a 3MB lazy chunk, and lets the Content Security Policy stay as it was. Browsers without HEIC support now get a message asking for a JPEG or PNG. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: Add class-level JSDoc to ImageHelper Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…3583) Dynamic client registration rejected any client sending more than 10 redirect URIs. The limit is now 20, shared between the register and update schemas, and the error reports how many were received. OAuth client errors were swallowed without reaching logs or Sentry, leaving a failing integration invisible beyond its status code. 4xx responses are now logged with the reason. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: Preserve MCP attachment form values * fix: Escape MCP attachment form arguments * fix: Support current TypeScript library target
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: Preserve expanded code blocks after undo * refactor: Rename used editor state parameter
* fix: Deadlock on cleanup task retry * Add transaction advisory lock around team deletion
) External providers can legitimately report several groups with the same display name. Previously the second group failed the team-wide name uniqueness check, or duplicates slipped through on creation and then broke every subsequent sync with a validation error. - Scope the group name uniqueness check by (team, externalId) so synced groups with different external ids can share a name while manually created groups remain unique among themselves - Compare names with lower() equality instead of iLike so LIKE wildcards in names are not treated as collisions - Stamp externalId on groups created by the syncer and backfill it on previously synced groups
…ne#13895) * perf: Load templates on demand and cache fetchAll results fetchAll on the base store now returns the first result for repeat calls with the same params, with a force option for callers that need fresh data. Templates load when the command bar, document header, or block menu needs them instead of on every page load. * Make fetchAll caching opt-in via fetchAllIfNeeded fetchAll always fetches again. fetchAllIfNeeded returns the previous result for the same params until a model is added to or removed from the store. Mount-effect callers for reference lists use it.
* feat: Add plan-based feature entitlements * feat: Gate audit log behind AuditLog entitlement * Guard guests * features
* wip * fix: Position grips in merged cells from the rendered layout * fix: Only merge row and column selections that cover whole rows or columns * perf: Find merged cell spans without scanning the table map * refactor: Extract helpers for cells starting in a row or column
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.4.0 to 10.7.2. - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.4.0...v10.7.2) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.7.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [undici](https://github.com/nodejs/undici) from 7.29.0 to 7.30.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.29.0...v7.30.0) --- updated-dependencies: - dependency-name: undici dependency-version: 7.30.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 10.0.0 to 10.0.2. - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v10.0.0...v10.0.2) --- updated-dependencies: - dependency-name: nodemailer dependency-version: 10.0.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.5 to 8.3.1. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.3.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [chrono-node](https://github.com/wanasit/chrono) from 2.9.1 to 2.10.1. - [Release notes](https://github.com/wanasit/chrono/releases) - [Commits](wanasit/chrono@v2.9.1...v2.10.1) --- updated-dependencies: - dependency-name: chrono-node dependency-version: 2.10.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the aws group with 6 updates: | Package | From | To | | --- | --- | --- | | [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1135.0` | `3.1140.0` | | [@aws-sdk/cloudfront-signer](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/cloudfront-signer) | `3.1125.0` | `3.1138.0` | | [@aws-sdk/lib-storage](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage) | `3.1135.0` | `3.1140.0` | | [@aws-sdk/s3-presigned-post](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-presigned-post) | `3.1135.0` | `3.1140.0` | | [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) | `3.1135.0` | `3.1140.0` | | [@aws-sdk/signature-v4-crt](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/signature-v4-crt) | `3.1135.0` | `3.1140.0` | Updates `@aws-sdk/client-s3` from 3.1135.0 to 3.1140.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/clients/client-s3) Updates `@aws-sdk/cloudfront-signer` from 3.1125.0 to 3.1138.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/cloudfront-signer/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1138.0/packages/cloudfront-signer) Updates `@aws-sdk/lib-storage` from 3.1135.0 to 3.1140.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-storage/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/lib/lib-storage) Updates `@aws-sdk/s3-presigned-post` from 3.1135.0 to 3.1140.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/packages/s3-presigned-post) Updates `@aws-sdk/s3-request-presigner` from 3.1135.0 to 3.1140.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/packages/s3-request-presigner) Updates `@aws-sdk/signature-v4-crt` from 3.1135.0 to 3.1140.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/signature-v4-crt/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1140.0/packages/signature-v4-crt) --- updated-dependencies: - dependency-name: "@aws-sdk/client-s3" dependency-version: 3.1140.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/cloudfront-signer" dependency-version: 3.1138.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/lib-storage" dependency-version: 3.1140.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/s3-presigned-post" dependency-version: 3.1140.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/s3-request-presigner" dependency-version: 3.1140.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws - dependency-name: "@aws-sdk/signature-v4-crt" dependency-version: 3.1140.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@octokit/auth-app](https://github.com/octokit/auth-app.js) from 8.3.0 to 8.3.1. - [Release notes](https://github.com/octokit/auth-app.js/releases) - [Commits](octokit/auth-app.js@v8.3.0...v8.3.1) --- updated-dependencies: - dependency-name: "@octokit/auth-app" dependency-version: 8.3.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the sentry group with 2 updates: [@sentry/node](https://github.com/getsentry/sentry-javascript) and [@sentry/react](https://github.com/getsentry/sentry-javascript). Updates `@sentry/node` from 10.75.0 to 10.75.3 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@10.75.0...10.75.3) Updates `@sentry/react` from 10.75.0 to 10.75.3 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@10.75.0...10.75.3) --- updated-dependencies: - dependency-name: "@sentry/node" dependency-version: 10.75.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: sentry - dependency-name: "@sentry/react" dependency-version: 10.75.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: sentry ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…nts (outline#13899) * fix: Invalidate collaboration connections on document lifecycle events * fix: Invalidate descendant connections and handle unarchive
…ine#13923) * feat: Redirect root domain app links to the signed-in workspace * fix: Treat non-object sessions cookie values as empty
Ports forward con2's custom bits onto a fresh base (upstream main, v1.9.1+212 commits, vs. con2's previous anchor at v0.67.0 from Jan 2023), replacing the pieces that no longer fit the current codebase: - New plugins/kompassi plugin, replacing the old hand-rolled OAuth2 provider (server/routes/auth/providers/kompassi.ts, which used an auth-provider mechanism that no longer exists upstream). Talks to Kompassi's now-standard OIDC provider instead of the legacy /oauth2 + /api/v2/people/me endpoints, keeps the same hard sign-in gate and admin-group role sync (KOMPASSI_ACCESS_GROUPS / KOMPASSI_ADMIN_GROUPS), and syncs groups via Outline's core (currently unused by any bundled plugin) group-sync framework instead of the old plugin's manual, not-team-scoped GroupUser sync. Deliberately keeps authenticationProvider.name = "kompassi" (not "oidc") and forces emailVerified = true so existing user accounts and the existing AuthenticationProvider row on each site reattach instead of being orphaned; see plugins/kompassi/server/auth/ kompassiRouter.ts for the reasoning. - New plugins/local, a straight port of the old insecure dev-only sign-in shortcut onto the current plugin/accountProvisioner APIs. - server/models/Attachment.ts: reapply the MinIO isPrivate override. - Dockerfile.con2 rewritten as a thin wrapper around upstream's own now-current Dockerfile/Dockerfile.base (Node 26, previously we carried a frozen Node 16 fork of both) instead of forking them; skaffold.in.yaml gains a third build stage to fit. - kubernetes/, .github/workflows/con2.yaml ported over unchanged, since the env var surface (KOMPASSI_*, POSTGRES_*, etc.) didn't change. Verified: yarn install, yarn tsc (0 errors), yarn oxlint --type-aware on the new/changed files, yarn build:server, and yarn vite:build all pass on this branch. Not yet verified: an actual login against Kompassi (needs a registered OIDC Application, none exist yet for Outline on Kompassi) or a real Docker/K8s deploy. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…image The init container ran "yarn sequelize:migrate", a script upstream renamed to db:migrate years ago, in an image that no longer ships yarn. Run the compiled checkMigrations script directly instead; it is the same check the server forks on boot, so a failing migration now fails the rollout before traffic shifts. PGSSLMODE already selects the SSL mode, so the production-ssl-disabled sequelize env is not needed. Also: FILE_STORAGE_UPLOAD_MAX_SIZE replaces the deprecated AWS_S3_UPLOAD_MAX_SIZE, the pod runs as uid 1001 to match the image's nodejs user, the writable home mount follows that user, and the local-storage test directory is ignored. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ng them Core group sync matches groups through external_groups rows, never by name, so the first synced sign-in created a second copy of every group the legacy provider had mirrored, leaving collection permissions on the old ones. A data migration links each existing group of a team with a kompassi provider under its own name, which is the id the plugin reports. The sync provider now reports only groups named in KOMPASSI_ACCESS_GROUPS and KOMPASSI_ADMIN_GROUPS. The legacy provider mirrored only those, and a Kompassi account belongs to dozens of groups from unrelated events (51 appeared on the first sync of the con2 dump against 5 before). Verified by restoring the con2 dump into a scratch database and running all migrations: the five groups end up linked to the kompassi provider. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
On the fork the scheduled ones (stale, auto-close-prs, docker-nightly, update-node, codeql) would run against con2's issues and registries, and the push-triggered ones target refs or secrets this repository does not have. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The 2020 Minio rejects the download URLs the current AWS SDK signs (SignatureDoesNotMatch), and Minio is end of life, so con2.fi moves to garage.con2.fi now rather than after the Helm and CloudNativePG steps. The other four sites stay on Minio until their own upgrade. Garage has no ACLs, so aws_s3_acl can be empty, which makes the server omit the x-amz-acl header. con2-s3-cors.js stores the CORS rule browser uploads need; it reads the pod's own AWS_* settings so it runs inside the pod. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
NOTE: our main branch is
con2and the intent ofcon2-nextis to become the nextcon2branch. This pull request exists not for the purpose of merging intomainbut to make our diff against upstream reviewable.Ports forward con2's custom bits onto a fresh base (upstream main, v1.9.1+212 commits, vs. con2's previous anchor at v0.67.0 from Jan 2023), replacing the pieces that no longer fit the current codebase:
Verified: yarn install, yarn tsc (0 errors), yarn oxlint --type-aware on the new/changed files, yarn build:server, and yarn vite:build all pass on this branch. Not yet verified: an actual login against Kompassi (needs a registered OIDC Application, none exist yet for Outline on Kompassi) or a real Docker/K8s deploy.