Commit Graph

  • dcda257280 chore(security): drop advisory identifiers from code comments Manish Gupta 2026-08-07 15:51:17 +05:30
  • 5662b76106 release: v1.4.1 #9545 v1.4.1 sriram veeraghanta 2026-08-07 15:35:02 +05:30
  • 31853ab2b8 chore: resolve dependabot security alerts (pnpm + pip) (#9549) v1.4.1-rc2 sriram veeraghanta 2026-08-05 00:48:59 +05:30
  • fa027167f6 fix(web): guard unguarded data derefs causing work-item and layout crashes (#9546) Atul Tameshwari 2026-08-05 00:21:19 +05:30
  • 8eeb8d762a fix: harden markdown attachment uploads feat/file-uploads-md-mdx-support vihar 2026-08-04 21:35:48 +05:30
  • 5adf526995 fix: reject suspicious filenames and match file icons case-insensitively sriram veeraghanta 2026-05-15 01:54:23 +05:30
  • ddb11a8012 feat: support .md and .mdx file uploads sriram veeraghanta 2026-05-03 00:01:24 +05:30
  • ed61f9925b chore: update package version sriramveeraghanta 2026-08-04 20:11:48 +05:30
  • 25c6843fce fix: enforce FILE_SIZE_LIMIT on published Space asset upload (#9242) sriram veeraghanta 2026-08-04 20:10:03 +05:30
  • c5951e7def [WEB-8510] fix(web): fix clipped/overlapping LayoutDropDown button in Create View modal (#9542) v1.4.1-rc1 Atul Tameshwari 2026-08-04 19:50:50 +05:30
  • a18177ce5e feat(api): enhance workspace module query to include member IDs (#9541) Atul Tameshwari 2026-08-04 19:50:08 +05:30
  • 194266581c fix(web): add trailing slash to notification list API call (#9521) Igor Bojczuk 2026-08-03 19:45:54 +02:00
  • 9fd1d537e2 [SECUR-243] fix(security): scope issue relation list to the URL project Manish Gupta 2026-08-03 16:35:56 +05:30
  • 96257d141e [SECUR-243] fix(security): scope issue relation removal to the URL project Manish Gupta 2026-08-03 15:13:18 +05:30
  • 69036c173a [SECUR-243] fix(security): scope issue comment + relation create to the URL project Manish Gupta 2026-08-03 13:24:21 +05:30
  • 65f4a99657 docs: add Zenith Hosting deploy option (#9529) Josh 2026-08-03 17:36:56 +10:00
  • 1ed664e8f8 [WEB-8512] feat: add workspace member reactivation command (#9520) Nikhil 2026-08-02 03:17:23 +05:30
  • 917b23a6c1 release: v1.4.0 #9160 v1.4.0 sriram veeraghanta 2026-07-31 17:53:44 +05:30
  • 53ead0a2d1 [WEB-8374] test: assert preference payload and persistence, not just 200 Manish Gupta 2026-07-31 17:10:50 +05:30
  • b9a01fdaef [WEB-8382][WEB-8383] docs: document 403 responses in the OpenAPI contract Manish Gupta 2026-07-31 16:59:25 +05:30
  • 39856932cd [WEB-8477] fix(api): filter "Updated At" by updated_at column, not created_at (#9514) Manish Gupta 2026-07-30 20:30:21 +05:30
  • 027a5a0330 fix: cast avatar_asset to CharField to resolve mixed type errors in URL concatenation (#9512) Satya Bharadwaj 2026-07-30 20:29:41 +05:30
  • e496b24f27 [WEB-8477] fix: created_at/updated_at filters return no work items (#9513) Manish Gupta 2026-07-30 19:51:16 +05:30
  • 7564480cf7 fix: resolve React Doctor errors and restore its PR baseline (#9488) sriram veeraghanta 2026-07-30 01:04:02 +05:30
  • 08a7d12b9d fix: resolve open CodeQL security alerts (#9505) sriram veeraghanta 2026-07-29 20:28:09 +05:30
  • ca3b48ef87 chore: upgrade Django 4.2 → 5.2 (#9325) sriram veeraghanta 2026-07-29 19:58:33 +05:30
  • cd82da1b8a [INFRA-461] chore: bump nginx to 1.31-alpine in web and admin Dockerfiles (#9490) Akshat Jain 2026-07-29 19:40:07 +05:30
  • 55610f4068 chore: retire departed code owners (apps/live, ox configs) (#9504) Manish Gupta 2026-07-29 19:39:38 +05:30
  • 4a671ac797 [GIT-243]fix: InstanceConfiguration not created for some keys (#9303) Sangeetha 2026-07-29 19:33:02 +05:30
  • ff4bf5d64c Merge pull request #9496 from makeplane/preview v1.4.0-rc2 Manish Gupta 2026-07-29 12:20:05 +05:30
  • 15e835710c [SECUR-242] fix(api): scope bulk-asset associate by uploader, not project_id (regression from #9288) (#9495) Manish Gupta 2026-07-29 12:16:05 +05:30
  • 6bc666abdb [SECUR-236] chore: drop overlapping per_page + auth fixes, defer to #9429 / #9335 Manish Gupta 2026-07-28 18:05:30 +05:30
  • 49c4da6d4b fix: strip control characters from sanitized filenames (#9151) Karthikeyan Ganesh 2026-07-28 17:52:46 +05:30
  • 6a061acc69 chore: pacakge version bump v1.4.0-rc1 sriramveeraghanta 2026-07-28 15:50:53 +05:30
  • 687483ea79 chore: add copyright header to authentication test package __init__ Manish Gupta 2026-07-28 15:31:40 +05:30
  • 3257ee9305 [SECUR-236] fix: address CodeRabbit — composite account throttle key + rate guard Manish Gupta 2026-07-28 15:12:13 +05:30
  • 47ab37cade [SECUR-236] fix: harden pagination bounds and auth brute-force rate limiting Manish Gupta 2026-07-28 14:49:12 +05:30
  • 00b94d36a8 [WEB-8401] test: add unauthorized PATCH regression coverage (CodeRabbit #9483) Manish Gupta 2026-07-27 12:59:47 +05:30
  • 000175cb57 [WEB-8400] test: cover same-workspace/other-project board scope (CodeRabbit #9481) Manish Gupta 2026-07-27 12:35:32 +05:30
  • ddefe762f3 [WEB-8401] fix(security): scope public Space asset mutations to the creator (GHSA-5q33-2766-fprm) Manish Gupta 2026-07-27 12:25:13 +05:30
  • 834ee3cc17 [WEB-8400] fix(security): scope DeployBoardViewSet queryset to the URL workspace/project (GHSA-h4w5-vhxc-265g) Manish Gupta 2026-07-27 12:07:00 +05:30
  • 02f2d44abe [WEB-8382][WEB-8383] fix(security): external-API issue comment + attachment authz (GHSA-h4p4-mwfg-qh82, GHSA-xvc5-m5jf-gvpj) Manish Gupta 2026-07-24 17:47:44 +05:30
  • 6b0f69ba11 [WEB-8374] fix(security): scope ProjectMemberPreferenceEndpoint to the caller (GHSA-gx67-r6wp-3357) Manish Gupta 2026-07-24 17:23:13 +05:30
  • 110bd545c9 [WEB-8372] fix: invalidate states cache on partial_update + strengthen member test (CodeRabbit/Copilot #9473) Manish Gupta 2026-07-24 15:13:13 +05:30
  • 73675d7e34 [WEB-8372] fix(security): restrict StateViewSet.partial_update to project admins (GHSA-4jpp-964m-27cr) Manish Gupta 2026-07-24 14:36:13 +05:30
  • 1549846f01 [WEB-8353] fix(security): extend guest visibility to attachment writes + scope activity to project (Copilot/CodeRabbit #9467) Manish Gupta 2026-07-23 15:40:41 +05:30
  • c52f6de62a [WEB-8353] fix(security): enforce guest issue visibility on attachments + activity (GHSA-wq96-4xjj-j4qg) Manish Gupta 2026-07-23 15:13:56 +05:30
  • 3b7f51710a [WEB-8333] perf: avoid double permission check on PUT delegation (Copilot #9461) Manish Gupta 2026-07-23 15:01:40 +05:30
  • 63d1515300 [WEB-8332] fix: no-op partial_update when payload has no writable field (Copilot #9460) Manish Gupta 2026-07-23 14:55:31 +05:30
  • 4c2f89bace [WEB-8333] test: cover inboxes alias + exercise true MEMBER path on issue PUT (CodeRabbit/Copilot #9461) Manish Gupta 2026-07-23 14:50:51 +05:30
  • cff6438279 [WEB-8332] test: assert allowed role applied + guard cascade on invalid update (CodeRabbit #9460) Manish Gupta 2026-07-23 14:48:28 +05:30
  • 74c0672845 [WEB-8333] test: exercise ROLE.MEMBER path in positive controls (Copilot #9461) Manish Gupta 2026-07-22 18:06:32 +05:30
  • ea8a66719f [WEB-8332] fix: validate role before guest-cascade, make it atomic (Copilot #9460) Manish Gupta 2026-07-22 17:55:26 +05:30
  • bf7568b1e6 [WEB-8333] fix(security): guard undecorated viewset routes with project-membership check (GHSA-27v6 / GHSA-w83f) Manish Gupta 2026-07-22 17:40:20 +05:30
  • 46670e688f [WEB-8332] fix(security): block workspace-member mass-assignment (GHSA-f739-39g5-jj49) Manish Gupta 2026-07-22 17:18:52 +05:30
  • a6256705e5 fix(security): stop logging OAuth bearer tokens and emails in clear text fix/codeql-cleartext-logging-oauth sriram veeraghanta 2026-07-22 00:36:10 +05:30
  • a8e53b6ac7 chore(deps): resolve open Dependabot security alerts (#9456) sriram veeraghanta 2026-07-22 00:26:18 +05:30
  • e78665ff35 [WEB-8291] fix: gate project invitation list/retrieve/destroy to project admins (GHSA-r68c-48rr-m67f) Manish Gupta 2026-07-20 11:50:26 +05:30
  • 7448c698cf [WEB-8289] test: make fixture ownership real (address Copilot review) Manish Gupta 2026-07-20 11:25:25 +05:30
  • 656acf7a5c [WEB-8289] fix: scope draft-to-issue conversion to the draft owner (GHSA-vfqm-7rh7-84hq) Manish Gupta 2026-07-20 10:51:03 +05:30
  • 7cef741c29 feat(api): add lite list endpoints for projects, members, cycles, and modules (#9410) Akhil Vamshi Konam 2026-07-17 17:40:26 +05:30
  • af1be50b48 [WEB-8074] fix: scope IssueListEndpoint to guest created_by (#9374) Manish Gupta 2026-07-16 16:03:25 +05:30
  • cfe951c8af [WEB-8095] fix: scope page-version reads to the URL project (GHSA-g49r/ghcr) (#9380) Manish Gupta 2026-07-16 16:03:06 +05:30
  • 5842ca8bf2 [WEB-8075] fix: scope ProjectMemberPermission SAFE_METHODS to project membership (#9375) Manish Gupta 2026-07-16 16:01:52 +05:30
  • b3591b9e63 [WEB-8068] fix: scope workspace cycles/modules listing to project membership (#9373) Manish Gupta 2026-07-16 16:00:08 +05:30
  • 8ef78bf0c1 [GIT-248 | GIT-254] refactor: store and components consolidation to core (#9245) Atul Tameshwari 2026-07-16 13:13:04 +05:30
  • bed58d9b17 chore: clean up React Doctor warnings in admin app (#9418) sriram veeraghanta 2026-07-15 00:47:34 +05:30
  • e63f0c3b34 [WEB-8066] fix: scope workspace asset get/patch/delete to project membership (#9372) Manish Gupta 2026-07-14 20:11:32 +05:30
  • 9a7d840761 refactor(api/observability): unify OTEL_ENABLED gate, isolate instrumentors, pass sampler vars through compose sriram veeraghanta 2026-07-14 13:27:40 +05:30
  • 38306e3893 docs(otel): self-hoster guide + reference collector config sriram veeraghanta 2026-07-14 01:15:45 +05:30
  • b8b5f5d932 chore(deploy): wire OpenTelemetry env into community API deployment templates sriram veeraghanta 2026-07-14 01:15:12 +05:30
  • 5514160067 feat(api/observability): trace-correlate JSON logs via LOGGING dict when OTEL_ENABLED sriram veeraghanta 2026-07-14 01:12:47 +05:30
  • bd331a64d3 feat(api/observability): instrument Celery workers + trace-correlate worker logs sriram veeraghanta 2026-07-14 01:11:32 +05:30
  • cd3f0042fb feat(api/observability): bootstrap OpenTelemetry in wsgi/asgi/manage entry points sriram veeraghanta 2026-07-14 01:10:26 +05:30
  • 810b8c89e8 feat(api/observability): add OpenTelemetry bootstrap package + unit tests sriram veeraghanta 2026-07-14 01:09:24 +05:30
  • d3d3de44cf [WEB-8012] fix: prevent ORM group_by/sub_group_by injection in issue endpoints (#9347) Manish Gupta 2026-07-13 20:40:01 +05:30
  • 9dff20e048 [WEB-7887] fix(security): prevent stored XSS via SVG attachment served inline (GHSA-ch8j-vr4r-qf6h) (#9312) Manish Gupta 2026-07-13 20:33:46 +05:30
  • 18ea715960 fix(user): clone user data before updates to prevent mutations (#9285) Atul Tameshwari 2026-07-13 20:28:38 +05:30
  • dc9d80b2d2 [WEB-8060] fix(security): enforce authz on is_active member (de)activation (#9367) Manish Gupta 2026-07-09 18:37:39 +05:30
  • 2e007e138b [WEB-8019] fix(security): scope CycleIssue reassignment lookup to workspace/project (#9349) Manish Gupta 2026-07-09 18:33:48 +05:30
  • 6395e1d39a [WEB-8017] fix(security): sanitize order_by on external REST API list endpoints (#9348) Manish Gupta 2026-07-09 18:32:53 +05:30
  • e1ef42023a [WEB-7895] fix: scope UserProjectInvitationsViewset to workspace-validated project IDs (GHSA-45hc-q4mw-jhxm) (#9333) Manish Gupta 2026-07-09 18:32:22 +05:30
  • 73e360844b [WEB-7888] fix(security): normalize href before protocol check in CustomLinkExtension (GHSA-v2vv-7wq3-8w2j) (#9313) Manish Gupta 2026-07-09 18:30:54 +05:30
  • 14a4c22f94 [WEB-7877] fix(security): enforce token + auth validation on project invite accept/reject (#9308) Manish Gupta 2026-07-09 18:28:59 +05:30
  • b91b61c379 [WEB-7778] fix(security): reject unverified OAuth provider emails to prevent ATO (Cluster E) (#9289) Manish Gupta 2026-07-09 16:31:33 +05:30
  • 4fc79a2d7e fix(security): block bot user logins (#9368) sriram veeraghanta 2026-07-08 01:51:37 +05:30
  • d5dda5d41c fix: Issues created or updated via REST API send no notifications or emails (#9307) Ivan Kuznetsov 2026-07-07 21:21:15 +01:00
  • 7fbf14a6cb [WEB-7894] fix: eliminate TOCTOU race in InstanceAdminSignUp (GHSA-p548-28jp-wr4p) (#9332) Manish Gupta 2026-07-01 17:44:08 +05:30
  • 5829f0febf [WEB-7892] fix(security): scope attachment PATCH/DELETE/GET by issue_id, drop created_by overwrite (GHSA-5mxw-g5mw-3v3w) (#9315) Manish Gupta 2026-07-01 17:41:08 +05:30
  • 4b52dce76e [WEB-7855] fix(security): prevent project invite email disclosure via unauthenticated GET (#9305) Manish Gupta 2026-07-01 17:34:45 +05:30
  • 24fad369e9 [WEB-7945] fix(security): prevent shell injection in feature-deployment.yml (#9334) Manish Gupta 2026-07-01 13:38:36 +05:30
  • 28ae25b564 [WEB-7847] fix: enforce workspace membership on entity-search endpoint (#9296) Manish Gupta 2026-06-30 18:35:10 +05:30
  • 4577dc3f7a [WEB-7776] fix(security): scope FileAsset queries to prevent cross-project IDOR (Cluster F) (#9288) Manish Gupta 2026-06-30 18:26:59 +05:30
  • 90ae8457d0 [GIT-239 | GIT-240] refactor: hooks and constants consolidation to core (#9204) Rahul Cheryala 2026-06-26 20:36:52 +05:30
  • 1e8f3630c7 [WEB-7787] fix(auth): restore activation flow and narrow deactivation guard (#9304) Manish Gupta 2026-06-24 14:40:24 +05:30
  • 6c9dbb5043 [WEB-7787] fix(security): block deactivated user login and fix WorkspaceOwnerPermission (#9290) Manish Gupta 2026-06-23 18:10:40 +05:30
  • cc3eb974f1 [WEB-7813] fix: prevent ORM order_by injection in issue and other endpoints (#9292) Manish Gupta 2026-06-23 18:02:52 +05:30
  • 1acc69e816 [WEB-7805] fix: remove hardcoded SECRET_KEY from community deployment manifests (#9291) Manish Gupta 2026-06-23 17:59:19 +05:30
  • 971c2aadb4 [WEB-7769] fix(security): scope EstimatePoint create/destroy to workspace and project (#9286) Manish Gupta 2026-06-23 17:52:41 +05:30
  • 0d58adb69d [WEB-7774] fix(security): sanitize comment_html and intake description_html with nh3 (#9287) Manish Gupta 2026-06-23 17:52:31 +05:30