Commit Graph

  • e093a22094 chore: remove posthog integration and analytics scaffold (#9634) sriram veeraghanta 2026-08-24 21:07:34 +05:30
  • 5f7d92784c release: v1.4.2 #9632 v1.4.2 master sriram veeraghanta 2026-08-23 20:03:06 +05:30
  • bd25c20105 [INFRA-502] fix(security): bind external-API work item attachments to the URL work item web-8375/external-api-issue-authz Manish Gupta 2026-08-21 17:23:19 +05:30
  • 8d992aebf3 [INFRA-501] test: pin absence of the asset identifier fields on a denied dedup match Manish Gupta 2026-08-21 14:24:12 +05:30
  • 0effe3c2ae [INFRA-501] fix(security): stop the external-id dedup echo disclosing foreign asset ids Manish Gupta 2026-08-21 13:06:53 +05:30
  • 83d5bda1ce [INFRA-501] fix(security): enforce project membership on every workspace-level asset route Manish Gupta 2026-08-21 12:04:36 +05:30
  • e056bbf9eb chore: dump version v1.4.2-rc1 sriram veeraghanta 2026-08-16 23:36:30 +05:30
  • d9841a5e02 fix(security): guard ProjectViewSet PUT — routed verb fell through to DRF Manish Gupta 2026-08-13 17:04:16 +05:30
  • f494bfd76d fix(security): scope the duplicate ProjectMemberPermission POST branch too secur-247/project-member-permission-post-scope Manish Gupta 2026-08-13 14:18:02 +05:30
  • 0f9249153f fix(security): scope ProjectMemberPermission POST to the URL project Manish Gupta 2026-08-13 13:34:54 +05:30
  • 1c8a60f858 [WEB-8632] fix(web): auto-reload on stale chunk load failure during navigation (#9579) Atul Tameshwari 2026-08-10 17:34:02 +05:30
  • dd88794fec chore(deps): bump the pip group across 2 directories with 1 update dependabot/pip/apps/api/pip-e901ebb543 dependabot[bot] 2026-08-10 04:14:27 +00:00
  • f21ee4d42a chore(security): drop advisory identifiers from code comments web-8291/project-invite-list-admin-scope Manish Gupta 2026-08-07 16:02:26 +05:30
  • f75d1ae91b chore(security): drop advisory identifiers from code comments Manish Gupta 2026-08-07 16:03:00 +05:30
  • ded0e06685 chore(security): drop advisory identifiers from code comments web-8332/workspace-member-mass-assignment Manish Gupta 2026-08-07 16:02:11 +05:30
  • 96a51159c6 chore(security): drop advisory identifiers from code comments web-8333/undecorated-route-idor Manish Gupta 2026-08-07 16:02:11 +05:30
  • 9133face1f chore(security): drop advisory identifiers from code comments web-8289/draft-to-issue-owner-scope Manish Gupta 2026-08-07 16:02:10 +05:30
  • edb0ccd5fb chore(security): drop advisory identifiers from code comments web-8374/member-preference-idor Manish Gupta 2026-08-07 16:00:10 +05:30
  • 3639e026cc chore(security): drop advisory identifiers from code comments web-8400/deploy-board-cross-workspace-idor Manish Gupta 2026-08-07 16:00:10 +05:30
  • 3321fd3102 chore(security): drop advisory identifiers from code comments web-8372/state-partial-update-admin-only Manish Gupta 2026-08-07 15:59:53 +05:30
  • 448367ed27 chore(security): drop advisory identifiers and shorten comments web-8401/space-asset-mutation-authz Manish Gupta 2026-08-07 15:59:31 +05:30
  • 880960390a chore(security): drop advisory identifiers from code comments Manish Gupta 2026-08-07 15:59:05 +05:30
  • dcda257280 chore(security): drop advisory identifiers from code comments Manish Gupta 2026-08-07 15:51:17 +05:30
  • 5662b76106 release: v1.4.1 #9545 v1.4.1 sriram veeraghanta 2026-08-07 15:35:02 +05:30
  • 31853ab2b8 chore: resolve dependabot security alerts (pnpm + pip) (#9549) v1.4.1-rc2 sriram veeraghanta 2026-08-05 00:48:59 +05:30
  • fa027167f6 fix(web): guard unguarded data derefs causing work-item and layout crashes (#9546) Atul Tameshwari 2026-08-05 00:21:19 +05:30
  • 8eeb8d762a fix: harden markdown attachment uploads feat/file-uploads-md-mdx-support vihar 2026-08-04 21:35:48 +05:30
  • 5adf526995 fix: reject suspicious filenames and match file icons case-insensitively sriram veeraghanta 2026-05-15 01:54:23 +05:30
  • ddb11a8012 feat: support .md and .mdx file uploads sriram veeraghanta 2026-05-03 00:01:24 +05:30
  • ed61f9925b chore: update package version sriramveeraghanta 2026-08-04 20:11:48 +05:30
  • 25c6843fce fix: enforce FILE_SIZE_LIMIT on published Space asset upload (#9242) sriram veeraghanta 2026-08-04 20:10:03 +05:30
  • c5951e7def [WEB-8510] fix(web): fix clipped/overlapping LayoutDropDown button in Create View modal (#9542) v1.4.1-rc1 Atul Tameshwari 2026-08-04 19:50:50 +05:30
  • a18177ce5e feat(api): enhance workspace module query to include member IDs (#9541) Atul Tameshwari 2026-08-04 19:50:08 +05:30
  • 194266581c fix(web): add trailing slash to notification list API call (#9521) Igor Bojczuk 2026-08-03 19:45:54 +02:00
  • 9fd1d537e2 [SECUR-243] fix(security): scope issue relation list to the URL project Manish Gupta 2026-08-03 16:35:56 +05:30
  • 96257d141e [SECUR-243] fix(security): scope issue relation removal to the URL project Manish Gupta 2026-08-03 15:13:18 +05:30
  • 69036c173a [SECUR-243] fix(security): scope issue comment + relation create to the URL project Manish Gupta 2026-08-03 13:24:21 +05:30
  • 65f4a99657 docs: add Zenith Hosting deploy option (#9529) Josh 2026-08-03 17:36:56 +10:00
  • 1ed664e8f8 [WEB-8512] feat: add workspace member reactivation command (#9520) Nikhil 2026-08-02 03:17:23 +05:30
  • 917b23a6c1 release: v1.4.0 #9160 v1.4.0 sriram veeraghanta 2026-07-31 17:53:44 +05:30
  • 53ead0a2d1 [WEB-8374] test: assert preference payload and persistence, not just 200 Manish Gupta 2026-07-31 17:10:50 +05:30
  • b9a01fdaef [WEB-8382][WEB-8383] docs: document 403 responses in the OpenAPI contract Manish Gupta 2026-07-31 16:59:25 +05:30
  • 39856932cd [WEB-8477] fix(api): filter "Updated At" by updated_at column, not created_at (#9514) Manish Gupta 2026-07-30 20:30:21 +05:30
  • 027a5a0330 fix: cast avatar_asset to CharField to resolve mixed type errors in URL concatenation (#9512) Satya Bharadwaj 2026-07-30 20:29:41 +05:30
  • e496b24f27 [WEB-8477] fix: created_at/updated_at filters return no work items (#9513) Manish Gupta 2026-07-30 19:51:16 +05:30
  • 7564480cf7 fix: resolve React Doctor errors and restore its PR baseline (#9488) sriram veeraghanta 2026-07-30 01:04:02 +05:30
  • 08a7d12b9d fix: resolve open CodeQL security alerts (#9505) sriram veeraghanta 2026-07-29 20:28:09 +05:30
  • ca3b48ef87 chore: upgrade Django 4.2 → 5.2 (#9325) sriram veeraghanta 2026-07-29 19:58:33 +05:30
  • cd82da1b8a [INFRA-461] chore: bump nginx to 1.31-alpine in web and admin Dockerfiles (#9490) Akshat Jain 2026-07-29 19:40:07 +05:30
  • 55610f4068 chore: retire departed code owners (apps/live, ox configs) (#9504) Manish Gupta 2026-07-29 19:39:38 +05:30
  • 4a671ac797 [GIT-243]fix: InstanceConfiguration not created for some keys (#9303) Sangeetha 2026-07-29 19:33:02 +05:30
  • ff4bf5d64c Merge pull request #9496 from makeplane/preview v1.4.0-rc2 Manish Gupta 2026-07-29 12:20:05 +05:30
  • 15e835710c [SECUR-242] fix(api): scope bulk-asset associate by uploader, not project_id (regression from #9288) (#9495) Manish Gupta 2026-07-29 12:16:05 +05:30
  • 6bc666abdb [SECUR-236] chore: drop overlapping per_page + auth fixes, defer to #9429 / #9335 Manish Gupta 2026-07-28 18:05:30 +05:30
  • 49c4da6d4b fix: strip control characters from sanitized filenames (#9151) Karthikeyan Ganesh 2026-07-28 17:52:46 +05:30
  • 6a061acc69 chore: pacakge version bump v1.4.0-rc1 sriramveeraghanta 2026-07-28 15:50:53 +05:30
  • 687483ea79 chore: add copyright header to authentication test package __init__ Manish Gupta 2026-07-28 15:31:40 +05:30
  • 3257ee9305 [SECUR-236] fix: address CodeRabbit — composite account throttle key + rate guard Manish Gupta 2026-07-28 15:12:13 +05:30
  • 47ab37cade [SECUR-236] fix: harden pagination bounds and auth brute-force rate limiting Manish Gupta 2026-07-28 14:49:12 +05:30
  • 00b94d36a8 [WEB-8401] test: add unauthorized PATCH regression coverage (CodeRabbit #9483) Manish Gupta 2026-07-27 12:59:47 +05:30
  • 000175cb57 [WEB-8400] test: cover same-workspace/other-project board scope (CodeRabbit #9481) Manish Gupta 2026-07-27 12:35:32 +05:30
  • ddefe762f3 [WEB-8401] fix(security): scope public Space asset mutations to the creator (GHSA-5q33-2766-fprm) Manish Gupta 2026-07-27 12:25:13 +05:30
  • 834ee3cc17 [WEB-8400] fix(security): scope DeployBoardViewSet queryset to the URL workspace/project (GHSA-h4w5-vhxc-265g) Manish Gupta 2026-07-27 12:07:00 +05:30
  • 02f2d44abe [WEB-8382][WEB-8383] fix(security): external-API issue comment + attachment authz (GHSA-h4p4-mwfg-qh82, GHSA-xvc5-m5jf-gvpj) Manish Gupta 2026-07-24 17:47:44 +05:30
  • 6b0f69ba11 [WEB-8374] fix(security): scope ProjectMemberPreferenceEndpoint to the caller (GHSA-gx67-r6wp-3357) Manish Gupta 2026-07-24 17:23:13 +05:30
  • 110bd545c9 [WEB-8372] fix: invalidate states cache on partial_update + strengthen member test (CodeRabbit/Copilot #9473) Manish Gupta 2026-07-24 15:13:13 +05:30
  • 73675d7e34 [WEB-8372] fix(security): restrict StateViewSet.partial_update to project admins (GHSA-4jpp-964m-27cr) Manish Gupta 2026-07-24 14:36:13 +05:30
  • 1549846f01 [WEB-8353] fix(security): extend guest visibility to attachment writes + scope activity to project (Copilot/CodeRabbit #9467) Manish Gupta 2026-07-23 15:40:41 +05:30
  • c52f6de62a [WEB-8353] fix(security): enforce guest issue visibility on attachments + activity (GHSA-wq96-4xjj-j4qg) Manish Gupta 2026-07-23 15:13:56 +05:30
  • 3b7f51710a [WEB-8333] perf: avoid double permission check on PUT delegation (Copilot #9461) Manish Gupta 2026-07-23 15:01:40 +05:30
  • 63d1515300 [WEB-8332] fix: no-op partial_update when payload has no writable field (Copilot #9460) Manish Gupta 2026-07-23 14:55:31 +05:30
  • 4c2f89bace [WEB-8333] test: cover inboxes alias + exercise true MEMBER path on issue PUT (CodeRabbit/Copilot #9461) Manish Gupta 2026-07-23 14:50:51 +05:30
  • cff6438279 [WEB-8332] test: assert allowed role applied + guard cascade on invalid update (CodeRabbit #9460) Manish Gupta 2026-07-23 14:48:28 +05:30
  • 74c0672845 [WEB-8333] test: exercise ROLE.MEMBER path in positive controls (Copilot #9461) Manish Gupta 2026-07-22 18:06:32 +05:30
  • ea8a66719f [WEB-8332] fix: validate role before guest-cascade, make it atomic (Copilot #9460) Manish Gupta 2026-07-22 17:55:26 +05:30
  • bf7568b1e6 [WEB-8333] fix(security): guard undecorated viewset routes with project-membership check (GHSA-27v6 / GHSA-w83f) Manish Gupta 2026-07-22 17:40:20 +05:30
  • 46670e688f [WEB-8332] fix(security): block workspace-member mass-assignment (GHSA-f739-39g5-jj49) Manish Gupta 2026-07-22 17:18:52 +05:30
  • a6256705e5 fix(security): stop logging OAuth bearer tokens and emails in clear text fix/codeql-cleartext-logging-oauth sriram veeraghanta 2026-07-22 00:36:10 +05:30
  • a8e53b6ac7 chore(deps): resolve open Dependabot security alerts (#9456) sriram veeraghanta 2026-07-22 00:26:18 +05:30
  • e78665ff35 [WEB-8291] fix: gate project invitation list/retrieve/destroy to project admins (GHSA-r68c-48rr-m67f) Manish Gupta 2026-07-20 11:50:26 +05:30
  • 7448c698cf [WEB-8289] test: make fixture ownership real (address Copilot review) Manish Gupta 2026-07-20 11:25:25 +05:30
  • 656acf7a5c [WEB-8289] fix: scope draft-to-issue conversion to the draft owner (GHSA-vfqm-7rh7-84hq) Manish Gupta 2026-07-20 10:51:03 +05:30
  • 7cef741c29 feat(api): add lite list endpoints for projects, members, cycles, and modules (#9410) Akhil Vamshi Konam 2026-07-17 17:40:26 +05:30
  • af1be50b48 [WEB-8074] fix: scope IssueListEndpoint to guest created_by (#9374) Manish Gupta 2026-07-16 16:03:25 +05:30
  • cfe951c8af [WEB-8095] fix: scope page-version reads to the URL project (GHSA-g49r/ghcr) (#9380) Manish Gupta 2026-07-16 16:03:06 +05:30
  • 5842ca8bf2 [WEB-8075] fix: scope ProjectMemberPermission SAFE_METHODS to project membership (#9375) Manish Gupta 2026-07-16 16:01:52 +05:30
  • b3591b9e63 [WEB-8068] fix: scope workspace cycles/modules listing to project membership (#9373) Manish Gupta 2026-07-16 16:00:08 +05:30
  • 8ef78bf0c1 [GIT-248 | GIT-254] refactor: store and components consolidation to core (#9245) Atul Tameshwari 2026-07-16 13:13:04 +05:30
  • bed58d9b17 chore: clean up React Doctor warnings in admin app (#9418) sriram veeraghanta 2026-07-15 00:47:34 +05:30
  • e63f0c3b34 [WEB-8066] fix: scope workspace asset get/patch/delete to project membership (#9372) Manish Gupta 2026-07-14 20:11:32 +05:30
  • 9a7d840761 refactor(api/observability): unify OTEL_ENABLED gate, isolate instrumentors, pass sampler vars through compose sriram veeraghanta 2026-07-14 13:27:40 +05:30
  • 38306e3893 docs(otel): self-hoster guide + reference collector config sriram veeraghanta 2026-07-14 01:15:45 +05:30
  • b8b5f5d932 chore(deploy): wire OpenTelemetry env into community API deployment templates sriram veeraghanta 2026-07-14 01:15:12 +05:30
  • 5514160067 feat(api/observability): trace-correlate JSON logs via LOGGING dict when OTEL_ENABLED sriram veeraghanta 2026-07-14 01:12:47 +05:30
  • bd331a64d3 feat(api/observability): instrument Celery workers + trace-correlate worker logs sriram veeraghanta 2026-07-14 01:11:32 +05:30
  • cd3f0042fb feat(api/observability): bootstrap OpenTelemetry in wsgi/asgi/manage entry points sriram veeraghanta 2026-07-14 01:10:26 +05:30
  • 810b8c89e8 feat(api/observability): add OpenTelemetry bootstrap package + unit tests sriram veeraghanta 2026-07-14 01:09:24 +05:30
  • d3d3de44cf [WEB-8012] fix: prevent ORM group_by/sub_group_by injection in issue endpoints (#9347) Manish Gupta 2026-07-13 20:40:01 +05:30
  • 9dff20e048 [WEB-7887] fix(security): prevent stored XSS via SVG attachment served inline (GHSA-ch8j-vr4r-qf6h) (#9312) Manish Gupta 2026-07-13 20:33:46 +05:30
  • 18ea715960 fix(user): clone user data before updates to prevent mutations (#9285) Atul Tameshwari 2026-07-13 20:28:38 +05:30