Skip to content

[WEB-5657] feat: add synchronization configuration for multiple providers in authentication adapter #8336

Merged
sriramveeraghanta merged 13 commits intopreviewfrom
auth-sync
Dec 22, 2025
Merged

[WEB-5657] feat: add synchronization configuration for multiple providers in authentication adapter #8336
sriramveeraghanta merged 13 commits intopreviewfrom
auth-sync

Conversation

@pablohashescobar
Copy link
Copy Markdown
Member

@pablohashescobar pablohashescobar commented Dec 15, 2025

Description

  • implement check_sync_enabled method to determine if sync is enabled for Google, GitHub, GitLab, Gitea providers
  • update user data synchronization logic to utilize the new method
  • add configuration variables for enabling sync for each provider in instance configuration files

Type of Change

  • Improvement (change that would cause existing functionality to not work as expected)

Test Scenarios

  • verify login/sign up with google, github, gitlab and gitea.

References

WEB-5657

Summary by CodeRabbit

  • New Features

    • Added per-provider sync toggles in admin auth settings for Google, GitHub, GitLab and Gitea.
  • Improvements

    • Optional automatic profile sync (display name and avatar) during login when enabled, with old avatar cleanup.
    • Forms now provide clearer save feedback and reliably reset to returned settings.
    • Better display-name generation for accounts missing a name.

✏️ Tip: You can customize this high-level summary in your review settings.

pablohashescobar and others added 6 commits December 12, 2025 14:55
- Implemented `check_sync_enabled` method to verify if sync is enabled for Google, GitHub, GitLab, and Gitea.
- Added `sync_user_data` method to update user details, including first name, last name, display name, and avatar.
- Updated configuration variables to include sync options for each provider.
- Integrated sync check into the login/signup process.
Copilot AI review requested due to automatic review settings December 15, 2025 09:45
@makeplane
Copy link
Copy Markdown

makeplane bot commented Dec 15, 2025

Linked to Plane Work Item(s)

This comment was auto-generated by Plane

@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai bot commented Dec 15, 2025

Note

Other AI code review bot(s) detected

CodeRabbit has detected other AI code review bot(s) in this pull request and will avoid duplicating their findings in the review comments. This may lead to a less comprehensive review.

Walkthrough

Adds ENABLE_*_SYNC toggles to admin provider forms and type defs, a reusable ControllerSwitch form component, backend sync and avatar handling in the auth adapter (with S3 bulk-delete support), a User.get_display_name helper, and new instance config variables for provider sync flags.

Changes

Cohort / File(s) Summary
Admin Authentication Forms
apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx, apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx, apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx, apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx
Add ENABLE_*_SYNC default values and *_FORM_SWITCH_FIELD descriptors; render ControllerSwitch; switch submit flow to async/await with try/catch; include sync flags in reset from response; adjust Save button handler to call handleSubmit correctly.
Admin Switch Component
apps/admin/core/components/common/controller-switch.tsx
New generic ControllerSwitch component and TControllerSwitchFormField type; binds a labeled ToggleSwitch to react-hook-form and maps "0"/"1" string values to boolean.
Backend Auth Adapter
apps/api/plane/authentication/adapter/base.py
Add check_sync_enabled(), sync_user_data(), delete_old_avatar(); refactor download_and_upload_avatar() to use S3Storage and guard missing URLs; integrate sync/avatar handling into complete_login_or_signup() and adjust save flow.
Backend Storage Utilities
apps/api/plane/settings/storage.py
Add S3Storage.delete_files(object_names) to perform bulk S3 deletions via delete_objects with ClientError handling.
Backend Models & Config
apps/api/plane/db/models/user.py, apps/api/plane/utils/instance_config_variables/core.py
Add User.get_display_name(cls, email) classmethod; add instance config variables ENABLE_GOOGLE_SYNC, ENABLE_GITHUB_SYNC, ENABLE_GITLAB_SYNC, ENABLE_GITEA_SYNC sourced from env (default "0", not encrypted).
Type Definitions
packages/types/src/instance/auth.ts
Extend provider authentication configuration key unions to include ENABLE_GOOGLE_SYNC, ENABLE_GITHUB_SYNC, ENABLE_GITLAB_SYNC, ENABLE_GITEA_SYNC and update TInstanceAuthenticationConfigurationKeys.

Sequence Diagram

sequenceDiagram
    participant AdminUI as Admin UI
    participant Form as Admin Form
    participant API as Backend API
    participant DB as Database
    participant Adapter as Auth Adapter
    participant IDP as Identity Provider
    participant S3 as S3 Storage

    AdminUI->>Form: Toggle ENABLE_*_SYNC and submit
    Form->>API: POST provider config (includes ENABLE_*_SYNC)
    API->>DB: Persist config
    API-->>Form: Return updated config
    Form-->>AdminUI: Show toast and reset form

    Note over IDP,Adapter: Later — user authenticates via provider
    IDP->>Adapter: OAuth response (user data + avatar URL)
    Adapter->>Adapter: check_sync_enabled(provider)
    alt sync enabled
        Adapter->>Adapter: sync_user_data(user, idp_data)
        Adapter->>S3: download_and_upload_avatar(avatar_url)
        S3->>S3: delete_files(old_avatar_objects)
        S3-->>Adapter: return FileAsset or fail
        Adapter->>DB: save_user_data(updated profile, avatar ref)
    else sync disabled
        Adapter->>DB: save_user_data(minimal)
    end
    Adapter-->>API: complete login/signup response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

  • Inspect avatar lifecycle and sync gating in apps/api/plane/authentication/adapter/base.py (check_sync_enabled, sync_user_data, delete_old_avatar, download_and_upload_avatar).
  • Verify S3Storage.delete_files correctness and error handling in apps/api/plane/settings/storage.py.
  • Confirm ControllerSwitch value mapping ("0"/"1" ↔ boolean) and react-hook-form typings in apps/admin/core/components/common/controller-switch.tsx.
  • Check admin forms for correct initialization, submission, and reset of ENABLE_*_SYNC fields in apps/admin/.../form.tsx.
  • Validate User.get_display_name edge cases in apps/api/plane/db/models/user.py.
  • Ensure TypeScript type updates in packages/types/src/instance/auth.ts align with runtime keys.

Poem

🐰 I toggled tiny switches bright,

Sync sprites hummed into the night,
Old avatars hopped out of sight,
New faces landed soft and light,
A joyful rabbit sings: byte!

Pre-merge checks and finishing touches

❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 35.29% which is insufficient. The required threshold is 80.00%. You can run @coderabbitai generate docstrings to improve docstring coverage.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: adding synchronization configuration for multiple providers in the authentication adapter, which aligns with the changeset scope.
Description check ✅ Passed The description covers key aspects: implementation of check_sync_enabled, user data sync updates, and configuration variables. However, it lacks details on new components (ControllerSwitch UI), storage improvements (delete_files), and user model enhancements (get_display_name).
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch auth-sync

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between bc57b22 and 38f97d0.

📒 Files selected for processing (1)
  • apps/api/plane/db/models/user.py (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • apps/api/plane/db/models/user.py
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
  • GitHub Check: Build packages
  • GitHub Check: Analyze (javascript)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
apps/api/plane/authentication/adapter/base.py (2)

186-188: Bug: Avatar content downloaded twice, using wrong variable for upload.

The code chunks the response into content (line 178) but then uses response.content (line 187) for upload. This causes the avatar to be downloaded twice and wastes bandwidth. Use the already-downloaded content variable.

             # Create file-like object
-            file_obj = BytesIO(response.content)
+            file_obj = BytesIO(content)
             file_obj.seek(0)

290-292: Fix inverted is_signup boolean logic.

Line 292 sets is_signup = bool(user), which is backwards. When a user is found (existing user, login flow), is_signup becomes True; when no user is found (new user, signup flow), it becomes False. This contradicts the codebase semantics where is_signup=True denotes a signup flow and is_signup=False denotes a login flow—as confirmed by usage in provider/credentials/email.py (which checks for existing users when is_signup=True and raises an error) and the email views (which pass is_signup=False for login and is_signup=True for signup).

Change line 292 to:

is_signup = user is None
🧹 Nitpick comments (10)
apps/api/plane/settings/storage.py (1)

191-201: Fix docstring and add type annotations for consistency.

The docstring says "Delete an S3 object" (singular) but the method deletes multiple objects. Also, this method lacks type annotations unlike the adjacent upload_file method.

-    def delete_files(self, object_names):
-        """Delete an S3 object"""
+    def delete_files(self, object_names: list[str]) -> bool:
+        """Delete multiple S3 objects in a single request"""

Additionally, be aware that AWS S3 delete_objects has a limit of 1000 objects per request. If callers may pass larger lists, consider batching.

apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (2)

153-160: Add user feedback on error.

The error is only logged to console. Users won't know the save failed. Consider adding an error toast for better UX, matching the success toast pattern.

     } catch (err) {
       console.error(err);
+      setToast({
+        type: TOAST_TYPE.ERROR,
+        title: "Error!",
+        message: "Failed to save GitLab configuration. Please try again.",
+      });
     }

10-10: Unused import.

The cn utility is imported but not used in this file.

-import { cn } from "@plane/utils";
apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (2)

176-178: Add user feedback on error.

Same issue as other provider forms - errors are only logged to console. Add an error toast for user feedback.

     } catch (err) {
       console.error(err);
+      setToast({
+        type: TOAST_TYPE.ERROR,
+        title: "Error!",
+        message: "Failed to save GitHub configuration. Please try again.",
+      });
     }

12-12: Unused import.

The cn utility is imported but not used in this file.

-import { cn } from "@plane/utils";
apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx (1)

151-165: Consider adding user feedback on configuration save failure.

The error is logged but the user receives no feedback when saving fails. For consistency with the success case, consider showing an error toast.

     } catch (err) {
       console.error(err);
+      setToast({
+        type: TOAST_TYPE.ERROR,
+        title: "Error!",
+        message: "Failed to save Google authentication configuration.",
+      });
     }
apps/admin/core/components/common/controller-switch.tsx (1)

29-35: Simplify the boolean comparison and consider adding a fallback for undefined values.

The === true comparison is redundant. Also, parseInt(undefined) returns NaN, which coerces to false - this works but is implicit.

           render={({ field: { value, onChange } }) => (
             <ToggleSwitch
-              value={Boolean(parseInt(value))}
-              onChange={() => (Boolean(parseInt(value)) === true ? onChange("0") : onChange("1"))}
+              value={Boolean(parseInt(value || "0"))}
+              onChange={() => (parseInt(value || "0") ? onChange("0") : onChange("1"))}
               size="sm"
             />
           )}
apps/api/plane/authentication/adapter/base.py (3)

112-134: Consider refactoring repetitive provider sync check to use a dictionary lookup.

The current implementation repeats the same pattern for each provider. A dict-based approach would be more maintainable.

     def check_sync_enabled(self):
         """Check if sync is enabled for the provider"""
-        if self.provider == "google":
-            (ENABLE_GOOGLE_SYNC,) = get_configuration_value([
-                {"key": "ENABLE_GOOGLE_SYNC", "default": os.environ.get("ENABLE_GOOGLE_SYNC", "0")}
-            ])
-            return ENABLE_GOOGLE_SYNC == "1"
-        elif self.provider == "github":
-            (ENABLE_GITHUB_SYNC,) = get_configuration_value([
-                {"key": "ENABLE_GITHUB_SYNC", "default": os.environ.get("ENABLE_GITHUB_SYNC", "0")}
-            ])
-            return ENABLE_GITHUB_SYNC == "1"
-        elif self.provider == "gitlab":
-            (ENABLE_GITLAB_SYNC,) = get_configuration_value([
-                {"key": "ENABLE_GITLAB_SYNC", "default": os.environ.get("ENABLE_GITLAB_SYNC", "0")}
-            ])
-            return ENABLE_GITLAB_SYNC == "1"
-        elif self.provider == "gitea":
-            (ENABLE_GITEA_SYNC,) = get_configuration_value([
-                {"key": "ENABLE_GITEA_SYNC", "default": os.environ.get("ENABLE_GITEA_SYNC", "0")}
-            ])
-            return ENABLE_GITEA_SYNC == "1"
-        return False
+        sync_keys = {
+            "google": "ENABLE_GOOGLE_SYNC",
+            "github": "ENABLE_GITHUB_SYNC",
+            "gitlab": "ENABLE_GITLAB_SYNC",
+            "gitea": "ENABLE_GITEA_SYNC",
+        }
+        key = sync_keys.get(self.provider)
+        if not key:
+            return False
+        (sync_enabled,) = get_configuration_value([
+            {"key": key, "default": os.environ.get(key, "0")}
+        ])
+        return sync_enabled == "1"

233-247: Inconsistent return value and redundant database lookup.

  1. The method returns False on exception but implicitly returns None on success - this inconsistency could cause issues for callers.
  2. Line 237 queries FileAsset.objects.get(pk=user.avatar_asset_id) when user.avatar_asset is already available from line 236's check.
     def delete_old_avatar(self, user):
         """Delete the old avatar if it exists"""
         try:
             if user.avatar_asset:
-                asset = FileAsset.objects.get(pk=user.avatar_asset_id)
+                asset = user.avatar_asset
                 storage = S3Storage(request=self.request)
                 storage.delete_files(object_names=[asset.asset.name])
                 user.avatar_asset = None
                 asset.delete()
                 user.save()
+            return True
         except FileAsset.DoesNotExist:
-            pass
+            return True
         except Exception as e:
             log_exception(e)
             return False

268-277: Avatar is always deleted and re-uploaded even if unchanged.

The current implementation deletes the old avatar and uploads a new one on every sync, even if the avatar URL hasn't changed. This wastes S3 operations and could cause brief avatar unavailability. Consider comparing the source URL before deletion.

         # Download and upload avatar only if the avatar is different from the one in the storage
         avatar = self.user_data.get("user", {}).get("avatar", "")
-        # Delete the old avatar if it exists
-        self.delete_old_avatar(user=user)
-        avatar_asset = self.download_and_upload_avatar(avatar_url=avatar, user=user)
-        if avatar_asset:
-            user.avatar_asset = avatar_asset
-        # If avatar upload fails, set the avatar to the original URL
-        else:
-            user.avatar = avatar
+        # Only update avatar if URL has changed
+        if avatar and avatar != user.avatar:
+            # Delete the old avatar if it exists
+            self.delete_old_avatar(user=user)
+            avatar_asset = self.download_and_upload_avatar(avatar_url=avatar, user=user)
+            if avatar_asset:
+                user.avatar_asset = avatar_asset
+            # If avatar upload fails, set the avatar to the original URL
+            else:
+                user.avatar = avatar
📜 Review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 22339b9 and 0df31a8.

📒 Files selected for processing (10)
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx (5 hunks)
  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (5 hunks)
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (5 hunks)
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx (5 hunks)
  • apps/admin/core/components/common/controller-switch.tsx (1 hunks)
  • apps/api/plane/authentication/adapter/base.py (5 hunks)
  • apps/api/plane/db/models/user.py (1 hunks)
  • apps/api/plane/settings/storage.py (1 hunks)
  • apps/api/plane/utils/instance_config_variables/core.py (4 hunks)
  • packages/types/src/instance/auth.ts (1 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{ts,tsx,mts,cts}

📄 CodeRabbit inference engine (.github/instructions/typescript.instructions.md)

**/*.{ts,tsx,mts,cts}: Use const type parameters for more precise literal inference in TypeScript 5.0+
Use the satisfies operator to validate types without widening them
Leverage inferred type predicates to reduce the need for explicit is return types in filter/check functions
Use NoInfer<T> utility to block inference for specific type arguments when they should be determined by other arguments
Utilize narrowing in switch(true) blocks for control flow analysis (TypeScript 5.3+)
Rely on narrowing from direct boolean comparisons for type guards
Trust preserved narrowing in closures when variables aren't modified after the check (TypeScript 5.4+)
Use constant indices to narrow object/array properties (TypeScript 5.5+)
Use standard ECMAScript decorators (Stage 3) instead of legacy experimentalDecorators
Use using declarations for explicit resource management with Disposable pattern instead of manual cleanup (TypeScript 5.2+)
Use with { type: "json" } for import attributes; avoid deprecated assert syntax (TypeScript 5.3/5.8+)
Use import type explicitly when importing types to ensure they are erased during compilation, respecting verbatimModuleSyntax flag
Use .ts, .mts, .cts extensions in import type statements (TypeScript 5.2+)
Use import type { Type } from "mod" with { "resolution-mode": "import" } for specific module resolution contexts (TypeScript 5.3+)
Use new iterator methods (map, filter, etc.) if targeting modern environments (TypeScript 5.6+)
Utilize new Set methods like union, intersection, etc., when available (TypeScript 5.5+)
Use Object.groupBy / Map.groupBy standard methods for grouping instead of external libraries (TypeScript 5.4+)
Use Promise.withResolvers() for creating promises with exposed resolve/reject functions (TypeScript 5.7+)
Use copying array methods (toSorted, toSpliced, with) for immutable array operations (TypeScript 5.2+)
Avoid accessing instance fields via super in classes (TypeScript 5....

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/core/components/common/controller-switch.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • packages/types/src/instance/auth.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Enable TypeScript strict mode and ensure all files are fully typed

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/core/components/common/controller-switch.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • packages/types/src/instance/auth.ts
**/*.{js,jsx,ts,tsx,json,css}

📄 CodeRabbit inference engine (AGENTS.md)

Use Prettier with Tailwind plugin for code formatting, run pnpm fix:format

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/core/components/common/controller-switch.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • packages/types/src/instance/auth.ts
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

**/*.{js,jsx,ts,tsx}: Use ESLint with shared config across packages, adhering to max warnings limits per package
Use camelCase for variable and function names, PascalCase for components and types
Use try-catch with proper error types and log errors appropriately

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/core/components/common/controller-switch.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • packages/types/src/instance/auth.ts
🧠 Learnings (3)
📚 Learning: 2025-07-14T11:22:43.964Z
Learnt from: gakshita
Repo: makeplane/plane PR: 7393
File: apps/admin/app/(all)/(dashboard)/email/email-config-form.tsx:104-104
Timestamp: 2025-07-14T11:22:43.964Z
Learning: In the Plane project's SMTP configuration implementation, the email configuration form (email-config-form.tsx) hardcodes ENABLE_SMTP to "1" in form submission because the form is only rendered when SMTP is enabled. The enable/disable functionality is managed at the page level (page.tsx) with a toggle, and the form only handles configuration details when SMTP is already enabled.

Applied to files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
📚 Learning: 2025-11-25T10:18:05.172Z
Learnt from: CR
Repo: makeplane/plane PR: 0
File: .github/instructions/typescript.instructions.md:0-0
Timestamp: 2025-11-25T10:18:05.172Z
Learning: Applies to **/*.{ts,tsx,mts,cts} : Utilize narrowing in `switch(true)` blocks for control flow analysis (TypeScript 5.3+)

Applied to files:

  • apps/admin/core/components/common/controller-switch.tsx
📚 Learning: 2025-08-06T09:01:17.915Z
Learnt from: shivam-jainn
Repo: makeplane/plane PR: 7545
File: apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx:139-143
Timestamp: 2025-08-06T09:01:17.915Z
Learning: In the Plane project's Gitea authentication form (apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx), the GITEA_HOST field should not be included in the form reset after submission. It should default back to "https://gitea.com" rather than maintaining the submitted value, as this provides a sensible default for most users.

Applied to files:

  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
🧬 Code graph analysis (7)
apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (3)
apps/admin/core/components/common/controller-switch.tsx (2)
  • TControllerSwitchFormField (11-14)
  • ControllerSwitch (16-40)
packages/propel/src/toast/toast.tsx (1)
  • setToast (245-265)
apps/space/core/store/root.store.ts (1)
  • reset (62-75)
apps/admin/core/components/common/controller-switch.tsx (1)
packages/ui/src/button/toggle-switch.tsx (1)
  • ToggleSwitch (56-56)
apps/api/plane/settings/storage.py (1)
apps/api/plane/utils/exception_logger.py (1)
  • log_exception (9-20)
apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx (1)
apps/admin/core/components/common/controller-switch.tsx (2)
  • TControllerSwitchFormField (11-14)
  • ControllerSwitch (16-40)
apps/api/plane/authentication/adapter/base.py (2)
apps/api/plane/settings/storage.py (2)
  • S3Storage (15-201)
  • delete_files (191-201)
apps/api/plane/db/models/user.py (4)
  • save (150-168)
  • User (42-176)
  • get_display_name (171-176)
  • avatar_url (129-137)
apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx (1)
apps/admin/core/components/common/controller-switch.tsx (2)
  • TControllerSwitchFormField (11-14)
  • ControllerSwitch (16-40)
apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (1)
apps/admin/core/components/common/controller-switch.tsx (2)
  • TControllerSwitchFormField (11-14)
  • ControllerSwitch (16-40)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: check:format
  • GitHub Check: Build packages
  • GitHub Check: Analyze (javascript)
🔇 Additional comments (14)
apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (1)

15-16: LGTM on sync toggle integration.

The ENABLE_GITLAB_SYNC toggle is properly integrated: added to form state, defined as a switch field, rendered via ControllerSwitch, and included in the reset payload after submission. This follows the consistent pattern across other provider forms.

Also applies to: 46-46, 114-117, 194-194, 200-200

apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx (2)

147-152: Verify GITEA_HOST reset behavior change is intentional.

Based on previous learnings, the GITEA_HOST field was intended to reset to the default "https://gitea.com" rather than the submitted value. This change now resets it from the response. Please confirm this behavioral change is intentional.

Also, similar to other provider forms, add an error toast for user feedback:

     } catch (err) {
       console.error(err);
+      setToast({
+        type: TOAST_TYPE.ERROR,
+        title: "Error!",
+        message: "Failed to save Gitea configuration. Please try again.",
+      });
     }

15-16: LGTM on sync toggle integration.

The ENABLE_GITEA_SYNC toggle is correctly integrated into the form following the same pattern as other provider forms.

Also applies to: 45-45, 109-112, 189-189, 194-194

apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (1)

17-18: LGTM on sync toggle integration.

The ENABLE_GITHUB_SYNC toggle is properly integrated following the consistent pattern across provider forms.

Also applies to: 48-48, 110-113, 212-212, 218-218

apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx (5)

16-17: LGTM!

Imports are correctly added for the new ControllerSwitch component and its type definition.


43-47: LGTM!

The ENABLE_GOOGLE_SYNC field is correctly added to the form's default values, maintaining consistency with the existing configuration pattern.


99-102: LGTM!

The switch field descriptor is well-typed using TControllerSwitchFormField<GoogleConfigFormValues> which ensures type safety between the form values and the field configuration.


199-199: LGTM!

The ControllerSwitch is correctly wired with the form control and field configuration.


205-205: LGTM!

The onClick handler correctly wraps handleSubmit(onSubmit) with void to handle the async form submission while preserving proper event handling.

apps/admin/core/components/common/controller-switch.tsx (1)

6-14: LGTM!

The type definitions are well-structured with proper generic constraints, enabling type-safe usage across different form configurations.

apps/api/plane/utils/instance_config_variables/core.py (2)

47-52: LGTM!

The ENABLE_GOOGLE_SYNC configuration follows the established pattern, with a safe default of "0" (disabled) and correctly marked as non-encrypted since it's a boolean flag.


74-79: LGTM!

All provider sync flags (ENABLE_GITHUB_SYNC, ENABLE_GITLAB_SYNC, ENABLE_GITEA_SYNC) consistently follow the same pattern with safe defaults.

Also applies to: 102-107, 135-140

packages/types/src/instance/auth.ts (1)

19-40: LGTM!

Type definitions are correctly updated to include the new ENABLE_*_SYNC keys for all providers. The union types properly compose to form TInstanceAuthenticationConfigurationKeys.

apps/api/plane/authentication/adapter/base.py (1)

337-339: LGTM!

The sync integration correctly gates user data synchronization behind the check_sync_enabled() check, ensuring sync only occurs when explicitly enabled per provider.

Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
apps/api/plane/db/models/user.py (1)

170-178: Good fixes from previous review; avoid splitting email twice.

The previous issues with using self instead of cls and missing None checks have been addressed. However, the email is still split twice (lines 175 and 176), which is inefficient.

Apply this diff to store the split result:

 @classmethod
 def get_display_name(cls, email):
     if not email:
         return "".join(random.choice(string.ascii_letters) for _ in range(6))
+    parts = email.split("@")
     return (
-        email.split("@")[0]
-        if len(email.split("@")) == 2
+        parts[0]
+        if len(parts) == 2
         else "".join(random.choice(string.ascii_letters) for _ in range(6))
     )
📜 Review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 0df31a8 and 1601f76.

📒 Files selected for processing (1)
  • apps/api/plane/db/models/user.py (1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: check:lint
  • GitHub Check: check:types
  • GitHub Check: Analyze (javascript)

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds synchronization configuration for multiple OAuth providers (Google, GitHub, GitLab, Gitea) in the authentication system. It introduces a mechanism to control whether user attributes (name, display name, avatar) should be refreshed from the OAuth provider during each sign-in.

Key changes:

  • Adds check_sync_enabled method and sync_user_data method to the authentication adapter
  • Adds ENABLE_{PROVIDER}_SYNC configuration variables for each OAuth provider
  • Implements a new ControllerSwitch component for the admin UI to toggle sync settings
  • Adds delete_files method to S3Storage for batch avatar deletion
  • Adds get_display_name class method to User model for generating display names

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 22 comments.

Show a summary per file
File Description
packages/types/src/instance/auth.ts Adds TypeScript type definitions for new sync configuration keys for all four OAuth providers
apps/api/plane/utils/instance_config_variables/core.py Adds configuration variables for enabling sync for Google, GitHub, GitLab, and Gitea with default value "0"
apps/api/plane/settings/storage.py Adds delete_files method to S3Storage class for batch deletion of S3 objects
apps/api/plane/db/models/user.py Adds get_display_name method to extract display name from email or generate fallback
apps/api/plane/authentication/adapter/base.py Implements check_sync_enabled, sync_user_data, and delete_old_avatar methods; integrates sync into login flow
apps/admin/core/components/common/controller-switch.tsx New reusable switch component for form-controlled toggle switches
apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx Adds sync toggle UI, updates form handling to include ENABLE_GOOGLE_SYNC, improves error handling
apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx Adds sync toggle UI, updates form handling to include ENABLE_GITLAB_SYNC, improves error handling
apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx Adds sync toggle UI, updates form handling to include ENABLE_GITHUB_SYNC, improves error handling
apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx Adds sync toggle UI, updates form handling to include ENABLE_GITEA_SYNC, improves error handling
Comments suppressed due to low confidence (1)

apps/api/plane/db/models/user.py:171

  • Class methods or methods of a type deriving from type should have 'cls', rather than 'self', as their first parameter.
    def get_display_name(cls, email):

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

GITHUB_CLIENT_ID: config["GITHUB_CLIENT_ID"],
GITHUB_CLIENT_SECRET: config["GITHUB_CLIENT_SECRET"],
GITHUB_ORGANIZATION_ID: config["GITHUB_ORGANIZATION_ID"],
ENABLE_GITHUB_SYNC: config["ENABLE_GITHUB_SYNC"],
Copy link

Copilot AI Dec 15, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The form defaultValues should provide a fallback value for ENABLE_GITHUB_SYNC in case config["ENABLE_GITHUB_SYNC"] is undefined. This could cause issues with the ControllerSwitch component which expects a string value to parse. Consider using 'config["ENABLE_GITHUB_SYNC"] || "0"' to ensure a valid default.

Suggested change
ENABLE_GITHUB_SYNC: config["ENABLE_GITHUB_SYNC"],
ENABLE_GITHUB_SYNC: config["ENABLE_GITHUB_SYNC"] || "0",

Copilot uses AI. Check for mistakes.
Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
apps/api/plane/authentication/adapter/base.py (1)

286-286: Critical: is_signup logic is inverted, causing sync to run for new users instead of existing users.

Line 286 sets is_signup = bool(user), which is True when the user already exists (a login) and False when the user is None (a new signup). This naming is inverted from the semantic meaning.

The condition on line 332 not is_signup therefore triggers sync for new signups, not existing users. This causes:

  1. Duplicate work: new user data was just set in lines 310-326
  2. Missed sync: existing users logging in never get their IdP data synchronized

Fix the logic inversion:

         # Check if the user is present
         user = User.objects.filter(email=email).first()
-        # Check if sign up case or login
-        is_signup = bool(user)
+        # Check if this is an existing user (login) or new user (signup)
+        is_existing_user = user is not None
         # If user is not present, create a new user
         if not user:

Then update the sync condition:

-        # Check if IDP sync is enabled and user is not signing up
-        if self.check_sync_enabled() and not is_signup:
+        # Sync user data from IDP for existing users when enabled
+        if self.check_sync_enabled() and is_existing_user:
             user = self.sync_user_data(user=user)

And update the callback:

         # Call callback if present
         if self.callback:
-            self.callback(user, is_signup, self.request)
+            self.callback(user, not is_existing_user, self.request)

Also applies to: 331-333

♻️ Duplicate comments (1)
apps/api/plane/authentication/adapter/base.py (1)

263-271: Avatar deletion before download creates data loss risk.

The old avatar is deleted (line 265) before attempting to download the new one (line 266). If the download or upload fails, the user permanently loses their avatar asset and falls back to just a URL reference.

Delete the old avatar only after successfully uploading the new one:

         # Download and upload avatar only if the avatar is different from the one in the storage
         avatar = self.user_data.get("user", {}).get("avatar", "")
-        # Delete the old avatar if it exists
-        self.delete_old_avatar(user=user)
         avatar_asset = self.download_and_upload_avatar(avatar_url=avatar, user=user)
         if avatar_asset:
+            # Delete the old avatar only after successful upload
+            self.delete_old_avatar(user=user)
             user.avatar_asset = avatar_asset
         # If avatar upload fails, set the avatar to the original URL
         else:
             user.avatar = avatar
🧹 Nitpick comments (2)
apps/api/plane/authentication/adapter/base.py (2)

226-227: Consider using the existing FK reference directly.

user.avatar_asset already holds the FileAsset instance. The additional FileAsset.objects.get(pk=user.avatar_asset_id) query is redundant unless you're deliberately re-fetching to confirm DB state.

     def delete_old_avatar(self, user):
         """Delete the old avatar if it exists"""
         try:
             if user.avatar_asset:
-                asset = FileAsset.objects.get(pk=user.avatar_asset_id)
+                asset = user.avatar_asset
                 storage = S3Storage(request=self.request)
                 storage.delete_files(object_names=[asset.asset.name])

321-326: Clarify intent: both avatar_asset and avatar URL are stored on success.

Both the asset reference and the original URL are stored when upload succeeds (lines 322-323). If this is intentional as a fallback mechanism, a brief comment would clarify the design. Otherwise, line 323 duplicates line 326's fallback behavior.

📜 Review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 1601f76 and 4576b20.

📒 Files selected for processing (1)
  • apps/api/plane/authentication/adapter/base.py (5 hunks)
🧰 Additional context used
🧬 Code graph analysis (1)
apps/api/plane/authentication/adapter/base.py (4)
apps/api/plane/settings/storage.py (2)
  • S3Storage (15-201)
  • delete_files (191-201)
apps/api/plane/authentication/views/app/gitea.py (2)
  • get (23-53)
  • get (57-103)
apps/api/plane/db/models/asset.py (1)
  • FileAsset (24-96)
apps/api/plane/db/models/user.py (4)
  • save (150-168)
  • User (42-178)
  • get_display_name (171-178)
  • avatar_url (129-137)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
  • GitHub Check: Build packages
  • GitHub Check: Analyze (javascript)
🔇 Additional comments (3)
apps/api/plane/authentication/adapter/base.py (3)

24-24: LGTM!

Moving the S3Storage import to module level improves clarity and follows Python import conventions.


94-96: LGTM!

Minor formatting improvement for readability.


112-124: LGTM!

Clean implementation using dictionary mapping for provider-to-config-key lookup. The configuration retrieval pattern is consistent with __check_signup.

Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

♻️ Duplicate comments (4)
apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (1)

46-46: Fallback value already present.

The past review comment suggested adding || "0" fallback, but the code already includes it. This ensures the ControllerSwitch component receives a valid string value to parse.

apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (1)

45-45: Fallback value already present.

The past review comment suggested adding || "0" fallback, but it's already implemented correctly. This prevents issues with the ControllerSwitch component.

apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx (2)

45-45: Fallback value already present.

The code already includes the || "0" fallback as suggested in past review comments, ensuring proper initialization for the ControllerSwitch component.


194-195: LGTM: Button props are correct.

The past review comment suggested adding size="lg", but it's already present on line 194. The void wrapper on line 195 correctly handles the async submission.

🧹 Nitpick comments (3)
apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (1)

161-177: Async/await refactor improves readability.

The migration from promise chaining to async/await with try/catch is cleaner. However, consider showing a user-facing error toast on failure for better UX, similar to the success toast.

     } catch (err) {
       console.error(err);
+      setToast({
+        type: TOAST_TYPE.ERROR,
+        title: "Error!",
+        message: "Failed to save GitHub authentication configuration. Please try again.",
+      });
     }
apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (1)

144-160: Async/await refactor improves code clarity.

The change to async/await is cleaner than promise chaining. Consider adding an error toast for user feedback on failure, matching the success toast pattern.

     } catch (err) {
       console.error(err);
+      setToast({
+        type: TOAST_TYPE.ERROR,
+        title: "Error!",
+        message: "Failed to save GitLab authentication configuration. Please try again.",
+      });
     }
apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx (1)

140-156: Async/await refactor improves maintainability.

The migration to async/await is cleaner. Consider adding a user-facing error toast for consistency with the success notification.

     } catch (err) {
       console.error(err);
+      setToast({
+        type: TOAST_TYPE.ERROR,
+        title: "Error!",
+        message: "Failed to save Gitea authentication configuration. Please try again.",
+      });
     }
📜 Review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 4576b20 and 888b364.

📒 Files selected for processing (4)
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx (5 hunks)
  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (5 hunks)
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (5 hunks)
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx (5 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • apps/admin/app/(all)/(dashboard)/authentication/google/form.tsx
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{ts,tsx,mts,cts}

📄 CodeRabbit inference engine (.github/instructions/typescript.instructions.md)

**/*.{ts,tsx,mts,cts}: Use const type parameters for more precise literal inference in TypeScript 5.0+
Use the satisfies operator to validate types without widening them
Leverage inferred type predicates to reduce the need for explicit is return types in filter/check functions
Use NoInfer<T> utility to block inference for specific type arguments when they should be determined by other arguments
Utilize narrowing in switch(true) blocks for control flow analysis (TypeScript 5.3+)
Rely on narrowing from direct boolean comparisons for type guards
Trust preserved narrowing in closures when variables aren't modified after the check (TypeScript 5.4+)
Use constant indices to narrow object/array properties (TypeScript 5.5+)
Use standard ECMAScript decorators (Stage 3) instead of legacy experimentalDecorators
Use using declarations for explicit resource management with Disposable pattern instead of manual cleanup (TypeScript 5.2+)
Use with { type: "json" } for import attributes; avoid deprecated assert syntax (TypeScript 5.3/5.8+)
Use import type explicitly when importing types to ensure they are erased during compilation, respecting verbatimModuleSyntax flag
Use .ts, .mts, .cts extensions in import type statements (TypeScript 5.2+)
Use import type { Type } from "mod" with { "resolution-mode": "import" } for specific module resolution contexts (TypeScript 5.3+)
Use new iterator methods (map, filter, etc.) if targeting modern environments (TypeScript 5.6+)
Utilize new Set methods like union, intersection, etc., when available (TypeScript 5.5+)
Use Object.groupBy / Map.groupBy standard methods for grouping instead of external libraries (TypeScript 5.4+)
Use Promise.withResolvers() for creating promises with exposed resolve/reject functions (TypeScript 5.7+)
Use copying array methods (toSorted, toSpliced, with) for immutable array operations (TypeScript 5.2+)
Avoid accessing instance fields via super in classes (TypeScript 5....

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Enable TypeScript strict mode and ensure all files are fully typed

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
**/*.{js,jsx,ts,tsx,json,css}

📄 CodeRabbit inference engine (AGENTS.md)

Use Prettier with Tailwind plugin for code formatting, run pnpm fix:format

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

**/*.{js,jsx,ts,tsx}: Use ESLint with shared config across packages, adhering to max warnings limits per package
Use camelCase for variable and function names, PascalCase for components and types
Use try-catch with proper error types and log errors appropriately

Files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
🧠 Learnings (3)
📚 Learning: 2025-07-14T11:22:43.964Z
Learnt from: gakshita
Repo: makeplane/plane PR: 7393
File: apps/admin/app/(all)/(dashboard)/email/email-config-form.tsx:104-104
Timestamp: 2025-07-14T11:22:43.964Z
Learning: In the Plane project's SMTP configuration implementation, the email configuration form (email-config-form.tsx) hardcodes ENABLE_SMTP to "1" in form submission because the form is only rendered when SMTP is enabled. The enable/disable functionality is managed at the page level (page.tsx) with a toggle, and the form only handles configuration details when SMTP is already enabled.

Applied to files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx
  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
📚 Learning: 2025-10-09T20:42:31.843Z
Learnt from: lifeiscontent
Repo: makeplane/plane PR: 7922
File: apps/admin/app/(all)/(dashboard)/ai/form.tsx:19-19
Timestamp: 2025-10-09T20:42:31.843Z
Learning: In the makeplane/plane repository, React types are globally available through TypeScript configuration. Type annotations like React.FC, React.ReactNode, etc. can be used without explicitly importing the React namespace. The codebase uses the modern JSX transform, so React imports are not required for JSX or type references.

Applied to files:

  • apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx
📚 Learning: 2025-08-06T09:01:17.915Z
Learnt from: shivam-jainn
Repo: makeplane/plane PR: 7545
File: apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx:139-143
Timestamp: 2025-08-06T09:01:17.915Z
Learning: In the Plane project's Gitea authentication form (apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx), the GITEA_HOST field should not be included in the form reset after submission. It should default back to "https://gitea.com" rather than maintaining the submitted value, as this provides a sensible default for most users.

Applied to files:

  • apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx
🧬 Code graph analysis (1)
apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (3)
apps/admin/core/components/common/controller-switch.tsx (2)
  • TControllerSwitchFormField (11-14)
  • ControllerSwitch (16-40)
packages/propel/src/toast/toast.tsx (1)
  • setToast (245-265)
apps/space/core/store/root.store.ts (1)
  • reset (62-75)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: check:lint
  • GitHub Check: check:types
  • GitHub Check: Analyze (javascript)
🔇 Additional comments (12)
apps/admin/app/(all)/(dashboard)/authentication/github/form.tsx (4)

15-16: LGTM: ControllerSwitch imports added correctly.

The type and component imports are necessary for the new synchronization toggle feature.


108-111: LGTM: Switch field definition is correct.

The GITHUB_FORM_SWITCH_FIELD properly defines the field descriptor for the ControllerSwitch component with appropriate name and label.


210-210: LGTM: ControllerSwitch integration is correct.

The component is properly bound to the form control and switch field descriptor.


216-216: LGTM: Void wrapper correctly handles async submit.

The void wrapper properly discards the promise returned by handleSubmit(onSubmit)(e) to satisfy event handler typing.

apps/admin/app/(all)/(dashboard)/authentication/gitlab/form.tsx (4)

14-15: LGTM: ControllerSwitch imports added correctly.

The imports are consistent with the other authentication forms and necessary for the new synchronization toggle feature.


113-116: LGTM: Switch field definition follows established pattern.

The GITLAB_FORM_SWITCH_FIELD is correctly defined and consistent with other provider forms.


193-193: LGTM: ControllerSwitch properly integrated.

The component is correctly bound to the form and renders the synchronization toggle.


199-199: LGTM: Void wrapper correctly handles async submission.

The void operator properly discards the promise for event handler compatibility.

apps/admin/app/(all)/(dashboard)/authentication/gitea/form.tsx (4)

15-16: LGTM: ControllerSwitch imports consistent with other forms.

The imports are correct and follow the established pattern across authentication forms.


109-112: LGTM: Switch field definition is correct.

The GITEA_FORM_SWITCH_FIELD follows the same pattern as other provider forms.


148-148: Verify GITEA_HOST reset behavior aligns with expectations.

Based on learnings, the GITEA_HOST field should default back to "https://gitea.com" rather than maintaining the submitted value. The current implementation resets to the response value, which may differ from the intended behavior.

Based on learnings, GITEA_HOST should not be included in the reset or should default to "https://gitea.com". Please confirm whether the current behavior is intentional.


189-189: LGTM: ControllerSwitch integration is correct.

The component is properly bound to form control and renders the synchronization toggle.

@sriramveeraghanta sriramveeraghanta merged commit c2ce21e into preview Dec 22, 2025
15 checks passed
@sriramveeraghanta sriramveeraghanta deleted the auth-sync branch December 22, 2025 06:53
KooshaPari added a commit to KooshaPari/Planify that referenced this pull request Mar 29, 2026
)

* [PAI-963] feat: enhance CustomSelect component with context for dropdown management (makeplane#8202)

* feat: enhance CustomSelect component with context for dropdown management

* refactor: streamline CustomSelect component structure and improve dropdown options rendering

* [WEB-5603] feat: enhance workspace settings layout and members page (makeplane#8266)

* feat: enhance workspace settings layout and members page with new components

* refactor: update workspace settings layout and members page to use default exports

* refactor: settings layout import changes

* refactor: simplify workspaceSlug usage in settings layout

* [WEB-5592] chore: add static files update settings for static files support (makeplane#8251)

* chore: add static files collection and update settings for static files support

* chore: add WhiteNoise middleware for static file handling

* chore(deps): upgrade WhiteNoise to version 6.11.0 and add static file reverse proxy in Caddyfile

* [WEB-5256]chore: quick actions refactor (makeplane#8019)

* chore: quick actions refactor

* chore: lint fix

* chore: unified factory for actions

* chore: lint fix

* * chore: removed redundant files
* chore: updated imports

* chore: updated interfaces to types

* chore: updated undefined handling

* [WIKI-829] fix: add option to only show placeholder on empty editor (makeplane#8232)

* feat: add placeholderOnEmpty functionality to editor components

* Update packages/editor/src/core/extensions/placeholder.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* refactor: rename placeholderOnEmpty to showPlaceholderOnEmpty across editor components

* chore : make optional

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* [WIKI-830] fix: copy clipboard functionality in the editor (makeplane#8229)

* feat: enhance clipboard functionality for markdown and HTML content

* fix: improve error handling and state management in CustomImageNodeView component

* fix: correct asset retrieval query by removing workspace filter in DuplicateAssetEndpoint

* fix: update meta tag creation in PasteAssetPlugin for clipboard HTML content

* feat: implement copyMarkdownToClipboard utility for enhanced clipboard functionality

* refactor: replace copyMarkdownToClipboard utility with copyTextToClipboard for simplified clipboard operations

* refactor: streamline clipboard operations by replacing copyTextToClipboard with copyMarkdownToClipboard in editor components

* refactor: simplify PasteAssetPlugin by removing unnecessary meta tag handling and streamlining HTML processing

* feat: implement asset duplication processing on paste for enhanced clipboard functionality

* chore:remove async from copy markdown method

* chore: add paste html

* remove:prevent default

* refactor: remove hasChanges from processAssetDuplication return type for simplified asset processing

* fix: format options-dropdown.tsx

* feat: add timezone selection to workspace settings (makeplane#8248)

* feat: add timezone selection to workspace onboarding, creation and settings

* refactor: remove timezone selection from workspace creation and onboarding forms

* [WEB-5285] feat: enhance ChangeTrackerMixin to capture changed fields on save (makeplane#8270)

- Added an override for the save method in ChangeTrackerMixin to store changed fields before resetting tracking.
- Implemented a new method, _reset_tracked_fields, to ensure subsequent saves detect changes relative to the last saved state.
- Updated IssueComment to utilize _changes_on_save for determining changed fields, improving accuracy in tracking modifications.

* [WEB-5585]chore: timeline chart refactor (makeplane#8246)

* chore: timeline chart refactor

* fix: format

* [WEB-5575]feat: enhance APITokenLogMiddleware to support logging to MongoDB (makeplane#8241)

* feat: enhance APITokenLogMiddleware to support logging to MongoDB

- Added functionality to log external API requests to MongoDB, with a fallback to PostgreSQL if MongoDB is unavailable.
- Implemented error handling for MongoDB connection and logging operations.
- Introduced additional fields for MongoDB logs, including timestamps and user identifiers.
- Refactored request logging logic to streamline the process and improve maintainability.

* fix: improve MongoDB availability checks in APITokenLogMiddleware

- Enhanced the logic for determining MongoDB availability by checking if the collection is not None.
- Added a check for MongoDB configuration before attempting to retrieve the collection.
- Updated error handling to ensure the middleware correctly reflects the state of MongoDB connectivity.

* feat: implement logging functionality in logger_task for API activity

- Added a new logger_task module to handle logging of API activity to MongoDB and PostgreSQL.
- Introduced functions for safely decoding request/response bodies and processing logs based on MongoDB availability.
- Refactored APITokenLogMiddleware to utilize the new logging functions, improving code organization and maintainability.

* refactor: simplify MongoDB logging in logger_task and middleware

- Removed direct dependency on MongoDB collection in log_to_mongo function, now retrieving it internally.
- Updated process_logs to check MongoDB configuration before logging, enhancing error handling.
- Cleaned up logger.py by removing unused imports related to MongoDB.

* feat: add Celery task decorator to process_logs function in logger_task

- Introduced the @shared_task decorator to the process_logs function, enabling asynchronous processing of log data.
- Updated function signature to include a return type of None for clarity.

* [WEB-5609] fix: extended sidebar item pin/unpin makeplane#8287

* [WEB-5608] chore: Hide "Pro" Features in Community Edition (makeplane#8288)

* chore: Hide "Pro" Features in Community Edition

* refactor: remove time tracking feature and simplify project features list

* chore: moving star us button to the top navigation (makeplane#8289)

* chore: optimize turborepo (makeplane#8286)

* [WIKI-844] fix: realtime sync post vite migration with title editor sync and indexed db access (makeplane#8294)

* fix: robust way to handle socket connection and read from indexeddb cache when reqd

* fix: realtime sync working with failure handling

* fix: title editor added

* merge preview into fix/realtime-sync

* check

* page renderer props

* lint errors

* lint errors

* lint errors

* sanitize html

* sanitize html

* format fix

* fix lint

* [WEB-4440] fix: duplicate sequence when creating multiple workitems in rapid succession (makeplane#8298)

- Replace advisory lock with transaction-level lock in Issue model save method
- Updated the save method in the Issue model to use a transaction-level advisory lock for better concurrency control.
- Simplified the locking mechanism by removing the explicit unlock step, as the lock is automatically released at the end of the transaction.
- Maintained existing functionality for sequence and sort order management while improving code clarity.

* chore: format files in API server (makeplane#8292)

* chore: fix ruff checks (makeplane#8305)

* fix: editor sync changes (makeplane#8306)

* chore: upate function declarations

* chore: formatted files

* chore: fix/check tooling improvements with turbo (makeplane#8304)

* fix: broken lock file

* chore: add Plane sync label to github templates makeplane#8303

Co-authored-by: Pushya Mitra Thiruvooru <pushya@Pushyas-MacBook-Pro.local>

* [WEB-5624] chore: added webhook translations makeplane#8312

* chore(deps): upgrade next themes package

* [WEB-5654]fix: custom select selection and dropdown close makeplane#8324

* [WEB-5124] chore: intake work item toast enhancements (makeplane#8329)

* [WEB-5647] chore: list layout work item identifier enhancements (makeplane#8326)

* chore: file formating

* [WEB-5650] feat: Enable Gitea OAuth configuration  (makeplane#8325)

* feat: implement OAuth configuration helper and integrate into auth forms

* fix: ensure OAuth providers are disabled by default if not configured

* [WEB-5602] feat: new design system (makeplane#8220)

* chore: init tailwind v4

* chore: update all configs

* chore: add source to parse monorepo packages

* chore: combine all css files

* feat: added extended colors

* chore: update typography

* chore: update extended color var names

* refactor: remove initial spacing variable and update dark mode selector

* chore: update css files

* chore: update animations

* chore: remove spacing tokens

* fix: external css files

* chore: update tailwind-merge version

* chore: update font family

* chore: added brief agents.md and story for new design system

* chore: enhance design system documentation with rare exceptions for visual separation

* chore: add fontsource package for typography

* chore: material symbols font added

* chore: update shadow default

* chore: add stroke and outline theme vars

* chore: update ring and fill colors

* chore: overwrite tailwind typography tokens

* chore: add high contrast mode tokens

* chore: update scrollbar colors

* chore: backward compatibility for buttons and placeholders

* chore: add priority colors

* chore: update urgent priority color

* chore: update plan colors

* chore: add missing utility class

* chore: update height and padding classes

* chore: update label colors

* chore: add missing utlity

* chore: add typography plugin to space app

* chore: replace existing classNames with new design system tokens makeplane#8244 (makeplane#8278)

* chore: update border colors

* chore: update all borders

* chore: update text colors

* chore: update css variables

* chore: update font sizes and weights

* chore: update bg colors

* chore: sync changes

* fix: uncomment spacing-1200 variable in variables.css

* chore: update primary colors

* refactor: updated border to border-subtle

* refactor: update various components and improve UI consistency across the application

* updated classnames

* updated classnames

* refactor: update color-related class names to use new design system variables for consistency

* chore: default automations

* chore: update text sizes

* chore: home and power k

* chore: home and power k

* chore: replace ui package button components

* chore: update text sizes

* chore: updated issue identifier (makeplane#8275)

* refactor: top navigation and sidebar design token (makeplane#8276)

* chore: update all button components (makeplane#8277)

* chore: new button component

* chore: update existing buttons

* chore: overwrite tailwind typography tokens

* fix: twMerge config + fixed cn instances

* refactor: toast design token updated (makeplane#8279)

* chore: update existing buttons

* chore: tooltip design token updatged (makeplane#8280)

* chore: moved cn utility to propel (makeplane#8281)

* chore: update space app UI (makeplane#8285)

* chore; update space app filters component

* fix: button whitespace wrap

* chore: space app votes

* chore: update dropdown components

* refactor: auth, onboarding, sidebar, and common component design token migration (makeplane#8291)

* chore: checkbox component design token updated

* chore: indicator and oauth component design token updated

* chore: sidebar design token updated

* chore: auth and onboarding design token updated

* chore: update divider color

* style: update background colors and hover effects across list components

* fix: tailwind merge

* refactor: toggle switch design token migration and header utility classname added (makeplane#8295)

* chore: toggle component design token updated

* chore: h-header utility class added

* chore: updated color tokens for work item detail page (makeplane#8296)

* chore: update react-day-picker UI

* refactor: update button sizes and styles in filters components

* refactor: breadcrumbs design token updated (makeplane#8297)

* chore: update priority icon colors

* refactor: updated layout variables

* chore: update plan card primary CTA

* Chore update editor design system (makeplane#8299)

* refactor: update styles for callout, color selector, logo selector, and image uploader

* refactor:fix image

* chore: update settings UI

* chore: updated notifications color and size tokens (makeplane#8302)

* chore: update sm button border radius

* fix: logo renderer

* chore: icon button component

* chore: remove deprecated classes

* chore: remove deprecated classes

* chore: update editor list spacing

* fix: icon button size

* chore: improvements (makeplane#8309)

* chore: update cycles and modules pages

* refactor: update background styles across various components to use new design system colors

* fix: button type errors

* chore: update modals design system (makeplane#8310)

* refactor: callout bg

* refactor: code  bg

* refactor: modal size and variant

---------

Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>

* chore: update next-themes

* design: update billing and plans component styles and remove unused utility functions (makeplane#8313)

* refactor: empty state design token migration and improvements (makeplane#8315)

* fix: profile page

* refactor: tabs design token updated (makeplane#8316)

* chore: updated buttons and tokens for work items (makeplane#8317)

* fix: adjust trial button spacing in checkout modal

* chore: update add button hover state

* fix: type error (makeplane#8318)

* fix: type error

* chore: code refactor

* refactor: update button sizes and background styles in rich filters components

* refactor: update editor bg

* refactor: enhance Gantt chart sidebar functionality and styling

- Removed unused  prop from .
- Updated  to include new props for better block management and scrolling behavior.
- Improved auto-scroll functionality for Gantt chart items.
- Adjusted styles in  component for consistent design.

* regression: gantt design

* chore: new badge component

* fix: favorite star

* chore: update backgroung, typography and button sizes across workspace settings general and members pages

* fix: header button sizes

* fix: emoji icon logo (makeplane#8323)

* more fixes

* chore: update settings sidebar

* refactor: avatar component

* chore: updated work item detail sidebar (makeplane#8327)

* refactor: update link preview

* fix: work item property dropdowns

* fix: dropdown buttons border radius

* chore: update power k translation

* chore: updated profile activity design (makeplane#8328)

* chore: update settings pages

* chore: update work item sidebar alignments (makeplane#8330)

* refactor: admin design system

* chore: update page header

---------

Co-authored-by: Jayash Tripathy <76092296+JayashTripathy@users.noreply.github.com>
Co-authored-by: VipinDevelops <vipinchaudhary1809@gmail.com>
Co-authored-by: Vamsi Krishna <46787868+vamsikrishnamathala@users.noreply.github.com>
Co-authored-by: Anmol Singh Bhatia <121005188+anmolsinghbhatia@users.noreply.github.com>
Co-authored-by: gakshita <akshitagoyal1516@gmail.com>
Co-authored-by: Palanikannan M <akashmalinimurugu@gmail.com>
Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com>
Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>
Co-authored-by: M. Palanikannan <73993394+Palanikannan1437@users.noreply.github.com>

* fix: formatting

* reexport types

* fix: lint error

---------

Co-authored-by: Jayash Tripathy <76092296+JayashTripathy@users.noreply.github.com>
Co-authored-by: VipinDevelops <vipinchaudhary1809@gmail.com>
Co-authored-by: Vamsi Krishna <46787868+vamsikrishnamathala@users.noreply.github.com>
Co-authored-by: Anmol Singh Bhatia <121005188+anmolsinghbhatia@users.noreply.github.com>
Co-authored-by: gakshita <akshitagoyal1516@gmail.com>
Co-authored-by: Palanikannan M <akashmalinimurugu@gmail.com>
Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com>
Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>
Co-authored-by: M. Palanikannan <73993394+Palanikannan1437@users.noreply.github.com>

* [WEB-5668] fix: add fetchWorkspaceLevelProjectEntities method and update project-related fetch keys (makeplane#8347)

* [SILO-783] feat: added porters and new serializer based exporter (makeplane#8335)

* [WEB-5699] refactor: update styling and classnames of charts according to new design system (makeplane#8345)

* refactor: update styling and class names according to new design system in charts

* refactor: clean up

* feat: custom theming enhancements (makeplane#8342)

* [WEB-5671] chore: settings workspace members enhancements makeplane#8346

* [WEB-5666] chore: set project timezone same as workspace timezone in project (makeplane#8340)

* [WEB-5614] fix: new design system consistency (makeplane#8351)

* chore: tooltip enhancements

* chore: project card enhancements

* chore: work item card enhancements

* chore: update component styles and class names for consistency across the application

---------

Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>

* [WEB-5708] regression: remove material icon instances from the Space app (makeplane#8353)

* chore: sync changes (makeplane#8343)

* [WEB-5614] chore: work item detail and list layout enhancements makeplane#8355

* regression: replace old css vars with the new design system tokens (makeplane#8354)

* chore: replace old css vars

* fix: replace shadow and primary colors

* chore: remove hardcoded colors

* [WEB-5614] chore: custom theme on colour improvement makeplane#8356

* [WEB-5732] style: update work item detail properties UI (makeplane#8357)

* [WEB-5730] fix: user mention colors makeplane#8358

* [WEB-5614] fix: empty state and padding token fixes (makeplane#8359)

* [WEB-5614] chore: update component styles and class names for consistency across projects makeplane#8360

* [WEB-5614] chore: logo and icon enhancements makeplane#8362

* fix: work item property icon renderer (makeplane#8363)

* [WEB-5614] fix: sidebar and label dropdown makeplane#8364

* fix: material icons font file (makeplane#8366)

* [WEB-5614] chore: lucide icon code refactor makeplane#8365

* fix: nested context menu UI (makeplane#8367)

* [WEB-5708] style: space app kanban card UI (makeplane#8368)

* [WEB-5742] fix: input field background makeplane#8369

* [WEB-5641] chore: sub work item quick menu padding makeplane#8370

* chore: replace old classNames (makeplane#8372)

* chore: update component styles and class names for consistency across the application (makeplane#8376)

* [WEB-5660] [WEB-5737] fix: cycle and module sidebar makeplane#8375

* [WEB-5676] style: gantt column outline makeplane#8374

* [WEB-5614] chore: platform design token enhancements (makeplane#8373)

* [WEB-5649] [WEB-5675] fix: local font files makeplane#8377

* [WEB-5614] chore: primitive token updated (makeplane#8378)

* fix: tooltip imports (makeplane#8379)

* [WEB-5614] chore: platform header and breadcrumb enhancements (makeplane#8383)

* [WEB-5652] fix: kanban quick add UI makeplane#8382

* [WEB-5726] fix: showing an empty state on deleted work item link makeplane#8381

* fix: space app default background (makeplane#8384)

* [WIKI-849] feat: debounce for mention search (makeplane#8380)

* fix: font imports (makeplane#8387)

* chore: platform layout enhancements (makeplane#8386)

* fix: image uploader bg in light mode (makeplane#8385)

* [WEB-5614] refactor: update styling and structure across various components (makeplane#8388)

* fix: input fields bg (makeplane#8389)

* fix: custom z-index classNames (makeplane#8395)

* [WEB-5454] fix: optimize date validation logic in CycleCreateUpdateModal makeplane#8394

* [WEB-5614] chore: work item detail comment and sidebar enhancements (makeplane#8397)

* [WEB-5675] chore: implement `fontsource` as the fonts library (makeplane#8398)

* [WEB-5762] fix: workitem detail sidebar properties design consistency (makeplane#8400)

* [WEB-5761]fix: intake spacing issue (makeplane#8399)

* [WEB-5614] chore: sidebar enhancement makeplane#8401

* [WEB-5768]chore: updated comment UI makeplane#8402

* [WEB-5614] chore: package and layout enhancements makeplane#8403

* chore: update storybook dependency

* [WEB-5657] feat: add synchronization configuration for multiple providers in authentication adapter  (makeplane#8336)

* feat: add sync functionality for OAuth providers

- Implemented `check_sync_enabled` method to verify if sync is enabled for Google, GitHub, GitLab, and Gitea.
- Added `sync_user_data` method to update user details, including first name, last name, display name, and avatar.
- Updated configuration variables to include sync options for each provider.
- Integrated sync check into the login/signup process.

* feat: add sync toggle for OAuth providers in configuration forms

* fix: remove default value for sync options in OAuth configuration forms

* chore: delete old avatar and upload a new one

* chore: update class method

* chore: add email nullable

* refactor: streamline sync check for multiple providers and improve avatar deletion logic

* fix: ensure ENABLE_SYNC configurations default to "0" for Gitea, Github, Gitlab, and Google forms

* fix: simplify toggle switch value handling in ControllerSwitch component

---------

Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>

* [WEB-5657] chore: synchronization configuration for multiple providers in authentication adapter makeplane#8409

* [WEB-5746]fix: workspace member modal z-index makeplane#8410

* [WEB-5773] fix: editor image full screen modal (makeplane#8413)

* [WEB-5774] fix: editor nodes background colors (makeplane#8416)

* [WEB-5776]chore: updated design system for alert modal makeplane#8415

* [WEB-5775] fix: mentions search on empty query makeplane#8417

* [WEB-5662][WEB-5770] fix: alignment of cycles in sidebar and layout selection dropdown button (makeplane#8414)

* fix: alpha colors (makeplane#8418)

* [WEB-5784] fix: truncation issue in wi properties (makeplane#8422)

* fix: update background surface 2 variables in tailwind config

* fix: improve layout and truncation handling in issue link and list items

* docs: update readme with react router badge (makeplane#8424)

Updated feature list and modified the local development section.

* [WEB-5788] fix: board layout group by icon makeplane#8426

* [WEB-5792] regression: editor font family makeplane#8427

* [WIKI-740] refactor: editor table performance (makeplane#8411)

* [WEB-5786] fix: updated font size for dates at Kanban card makeplane#8429

* [WEB-5772] fix: theme switch flicker (makeplane#8428)

* [WEB-5784] fix: truncation of links in work items (makeplane#8430)

* [WEB-5772] chore: theme switcher and editor colors enhancements (makeplane#8436)

* [WEB-5772] chore: theme switcher code refactor makeplane#8438

* chore: workspace events (makeplane#8439)

* chore: adding invite and joined events

* chore: adding workspace create and update events

* [WEB-5798] refactor: web and admin auth related components and update admin designs (makeplane#8431)

* refactor: web and admin auth related components and update admin designs.

* fix: format

* [WEB-5581] fix: resolve logo spinner hydration and theme loading issues (makeplane#8450)

- Fix hydration mismatch by lazy loading components that depend on theme
- Ensure LogoSpinner renders with correct theme on initial load

* [WEB-5791] fix: broken favicon in links (makeplane#8396)

* fix: using base url of a redirect url

* chore: internal networks check for the final_url

* fix: none final_url

* fix: exception handling

* fix: exception handling

* chore: remove unused imports

* refactor: moved ip address check logic into separate function

* fix: ValueError logic

* [WEB-5667] fix: estimate value display in analytics makeplane#8448

* [WEB-5779] fix: handle loading state while fetching project cover image (makeplane#8419)

* refactor: replace cover image handling with CoverImage component across profile and project forms

* fix: extend CoverImage component to accept additional img props

* Update apps/web/core/components/common/cover-image.tsx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix: handle undefined cover image URL in ProfileSidebar component

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* [WEB-5782]chore: migrated modals to @plane/ui (makeplane#8420)

* chore: migrated modal to @plane/ui

* chore: fixed spacings

* [WEB-5808] chore: sidebar project list enhancements (makeplane#8451)

* chore: sidebar project list enhancements

* chore: code refactor

* chore: code refactor

* [WEB-5324] refactor: add Unified OAuth Configuration and Missing Gitea Options (makeplane#8050)

* refactor: add Unified OAuth Configuration and Missing Gitea Options

- Replaced the AuthenticationModes component with a more streamlined implementation using AuthenticationMethodCard.
- Removed obsolete authentication modes files from the codebase.
- Enhanced the AuthRoot component to utilize the new OAuth configuration hook for better management of authentication options.
- Updated type definitions for instance authentication modes to reflect the new structure.

* refactor: update OAuth type imports and remove obsolete types

- Replaced local type imports with centralized imports from @plane/types in core, extended, and index OAuth hooks.
- Removed the now redundant types.ts file as its definitions have been migrated.
- Enhanced type definitions for OAuth options to improve consistency across the application.

* feat: add new Gitea logo and update OAuth icon imports to use standard HTML img tags

* chore: remove unused authentication logos and upgrade button component

* [WEB-5574]chore: notification card refactor (makeplane#8234)

* chore: notification card refactor

* chore: moved base activity types to constants package

* [WEB-5804] refactor: decouple filter value types from filter configurations (makeplane#8441)

* [WEB-5804] refactor: decouple filter value types from filter configurations

Remove value type constraints from filter configurations to support
operator-specific value types. Different operators can accept different
value types for the same filter property, so value types should be
determined at the operator level rather than the filter level.

- Remove generic value type parameter from TFilterConfig
- Update TOperatorConfigMap to accept union of all value types
- Simplify filter config factory signatures across all filter types
- Add forceUpdate parameter to updateConditionValue method

* refactor: remove filter value type constraints from filter configurations

Eliminate the generic value type parameter from filter configurations to allow for operator-specific value types. This change enhances flexibility by enabling different operators to accept various value types for the same filter property.

- Updated TFilterConfig and related interfaces to remove value type constraints
- Adjusted filter configuration methods and types accordingly
- Refactored date operator support to align with the new structure

* [WEB-5785]fix: favorites icon size makeplane#8449

* [WEB-5781]chore: removed info banner for preferences makeplane#8442

* [WEB-5809] refactor: tailwind config inline variables (makeplane#8437)

* refactor: actions icon migration (makeplane#8219)

* chore: gitignore updated

* chore: check icon added to propel package

* feat: search icon migration

* chore: check icon migration

* chore: plus icon added to propel package

* chore: code refactor

* chore: plus icon migration and code refactor

* chore: trash icon added to propel package

* chore: code refactor

* chore: trash icon migration

* chore: edit icon added to propel package

* chore: new tab icon added to propel package

* chore: edit icon migration

* chore: newtab icon migration

* chore: lock icon added to propel package

* chore: lock icon migration

* chore: globe icon added to propel package

* chore: globe icon migration

* chore: copy icon added to propel package

* chore: copy icon migration

* chore: link icon added to propel package

* chore: link icon migration

* chore: link icon migration

* chore: info icon added to propel package

* chore: code refactor

* chore: code refactor

* chore: code refactor

* chore: code refactor

* regression: red and green color backgrounds (makeplane#8456)

* [WEB-5815] chore: removed the deleted states (makeplane#8457)

* Typo: database extension error message (makeplane#8461)

* [WEB-5179] chore: icon utils code refactor makeplane#8458

* [WEB-5790] feat: new email templates (makeplane#8423)

* chore: remove unused get_client_ip import (makeplane#8453)

Remove unused import `get_client_ip` from workspace/invite.py.
Identified by ruff linter (F401 error).

Signed-off-by: majiayu000 <1835304752@qq.com>

* [WEB-5822] fix: migrate ImagePickerPopover to Propel Tabs component and render only enabled tabs makeplane#8290

- Replace custom tab implementation with Propel Tabs
- Dynamically render only enabled tabs based on configuration
- Filter tabs by isEnabled property for cleaner conditional rendering
- Improve tab navigation and accessibility with Propel components

* chore: navigation preference enhancements (makeplane#8468)

* [WEB-5472] refactor: components of project creation flow (makeplane#8462)

* [WEB-857] regression: image uploader error state makeplane#8471

* [WEB-4959]chore: refactor project member page makeplane#8464

* [WEB-5472] refactor: project form makeplane#8472

* migration: added webhook version, navigation related fields and allowed_rate_limit for APIToken (makeplane#8339)

* migration: added version field in webhook

* chore: add max_length

* chore: added product tour fields

* chore: updated the migration file

* chore: removed the duplicated migration file

* chore: added allowed_rate_limit for api_tokens

* chore: changed key feature tour to product tour

* chore: added is_subscribed_to_changelog field

---------

Co-authored-by: NarayanBavisetti <narayan3119@gmail.com>

* fix: correct spelling error in database.ts log message (makeplane#8452)

Fix "convertion" -> "conversion" in error log message.

Signed-off-by: majiayu000 <1835304752@qq.com>

* [WEB-5598] refactor: streamline object creation in workspace seed task and improve error handling in workspace creation makeplane#8264

* chore: remove posthog events (makeplane#8465)

* chore: remove posthog events

* chore: remove event tracking

* chore: lint errors

* chore: minor changes based on comments

* fix: type errors

* Revert "[WEB-4959]chore: refactor project member page makeplane#8464" (makeplane#8476)

This reverts commit c97e418.

* chore: remove unused right sidebar component and clean up workspace member settings (makeplane#8477)

* [WEB-5537]refactor: rename IssueUserProperty to ProjectUserProperty and update related references  (makeplane#8206)

* refactor: rename IssueUserProperty to ProjectUserProperty and update related references across the codebase

* migrate: move issue user properties to project user properties and update related fields and constraints

* refactor: rename IssueUserPropertySerializer and IssueUserDisplayPropertyEndpoint to ProjectUserPropertySerializer and ProjectUserDisplayPropertyEndpoint, updating all related references

* fix: enhance ProjectUserDisplayPropertyEndpoint to handle missing properties by creating new entries and improve response handling

* fix: correct formatting in migration for ProjectUserProperty model options

* migrate: add migration to update existing non-service API tokens to remove workspace association

* migrate: refine migration to update existing non-service API tokens by excluding bot users from workspace removal

* chore: changed the project sort order in project user property

* chore: remove allowed_rate_limit from APIToken

* chore: updated user-properties endpoint for frontend

* chore: removed the extra projectuserproperty

* chore: updated the migration file

* chore: code refactor

* fix: type error

---------

Co-authored-by: NarayanBavisetti <narayan3119@gmail.com>
Co-authored-by: sangeethailango <sangeethailango21@gmail.com>
Co-authored-by: vamsikrishnamathala <matalav55@gmail.com>
Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>

* [WIKI-826] chore: add unique id as key to logo selector (makeplane#8494)

* [VPAT-50] chore(security): add X-Frame-Options header to nginx configuration to prevent clickjacking attacks (makeplane#8507)

* [VPAT-50] chore(security): add X-Frame-Options header to nginx configuration to prevent clickjacking attacks

* [SECURITY] chore: enhance nginx configuration with additional security headers

* chore: updated migration file name (makeplane#8515)

* chore(deps): react router upgraded

* [WEB-5890] migration: added getting_started_checklist, tips, explored_feature fields on the workspace member table (makeplane#8489)

* migration: added getting_started_checklist and tips field

* fix: remove defaults and added explored_features field

* fix: added user table migration

* [WEB-5907] fix: magic code sign-in at Space app. makeplane#8552

* [WIKI-735] fix: table insert handle z-index makeplane#8545

* [WEB-5898] chore: update tailwind config makeplane#8516

* chore(deps): bump lodash-es in the npm_and_yarn group across 1 directory (makeplane#8573)

Bumps the npm_and_yarn group with 1 update in the / directory: [lodash-es](https://github.com/lodash/lodash).


Updates `lodash-es` from 4.17.21 to 4.17.23
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.17.23)

---
updated-dependencies:
- dependency-name: lodash-es
  dependency-version: 4.17.23
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [WEB-5845] chore: changing description field to description json (makeplane#8230)

* chore: migrating description to description json

* chore: replace description with description_json

* chore: updated migration file

* chore: updated the migration file

* chore: added description key in external endpoint

* chore: updated the migration file

* chore: updated the typo

---------

Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>

* chore: fix typos in comments (makeplane#8553)

* [GIT-61] chore: allow .md files to be uploaded (makeplane#8571)

* chore: allow .md files to be uploaded

* chore: allow .md files to be uploaded

* [WEB-5860] [WEB-5861] [WEB-5862] style: improved settings interface (makeplane#8520)

* style: improved profile settings

* chore: minor improvements

* style: improved workspace settings

* style: workspace settings content

* style: improved project settings

* fix: project settings flat map

* chore: add back navigation from settings pages

* style: settings content

* style: estimates list

* refactor: remove old code

* refactor: removed unnecessary line breaks

* refactor: create a common component for page header

* chore: add fade-in animation to sidebar

* fix: formatting

* fix: project settings sidebar header

* fix: workspace settings sidebar header

* fix: settings content wrapper scroll

* chore: separate project settings features

* fix: formatting

* refactor: custom theme selector

* refactor: settings headings

* refactor: settings headings

* fix: project settings sidebar padding

* fix: sidebar header padding

* fix: sidebar item permissions

* fix: missing editable check

* refactor: remove unused files

* chore: remove unnecessary code

* chore: add missing translations

* fix: formatting

* [GIT-45] fix: allow markdown file attachments (makeplane#8524)

* fix: allow markdown file attachments

- Add text/markdown to ATTACHMENT_MIME_TYPES
- Fixes issue where .md files were rejected with 'Invalid file type' error

* added the support for frontend mime type too

* fix: node view renders (makeplane#8559)

* fix node renders

* fix handlers

* fix: duplicate id

* fix: pdf export (makeplane#8564)

* feat: pdf export

* fix: tests

* fix: tests

---------

Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>

* migration: back migrate all product tour fields to set true (makeplane#8575)

* [GIT-66] improvement: prevent disabling last enabled authentication method (makeplane#8570)

* fully translated into Ukrainian language (makeplane#8579)

* chore:  add copyright (makeplane#8584)

* feat: adding new copyright info on all files

* chore: adding CI

* fix: module percentage calculation (makeplane#8595)

* fix: file fomatting

* [SECUR-113] fix: ssrf for work item links (makeplane#8607)

* [SECUR-104] fix: Arbitrary Modification of API Token Rate Limits#8612

* chore(deps): upgrade django version

* [WEB-6058] chore : add logic to handle save#8614

* chore(deps): update the node pacakges

* fix: type fix for description payload (makeplane#8619)

* fix: type fix

* fix: duplicate type fix

* chore(deps): update lodash package

* [WEB-6149] migration: change estimate point key max value to 50 makeplane#8620

* fix: remove ee folder from web (makeplane#8622)

* chore: merge constants and services (makeplane#8623)

* fix: remove constants and services

* fix: formatting

* fix: types check

* chore: merge helpers and layouts (makeplane#8624)

* fix: remove constants and services

* fix: formatting

* chore: merge helpers and layouts

* fix: workspace disbale flag handling

* chore(deps): bump cryptography (makeplane#8625)

Bumps the pip group with 1 update in the /apps/api/requirements directory: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 44.0.1 to 46.0.5
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@44.0.1...46.0.5)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.5
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* style: update ASCII art in install script header (makeplane#8628)

* [WEB-6038] fix: work item empty title flicker makeplane#8618

* fix: workitem description input inital load (makeplane#8617)

* [WEB-6137] fix: work item peek view outside click makeplane#8610

* [SECUR-105] fix: csv injection vulnerability sanitization makeplane#8611

* [WIKI-877] fix: order of this dropdown options in pages makeplane#8563

* [WEB-5899]fix: project sort order (makeplane#8530)

* fix: project sort order

* chore: updated queryset for sort_order

* chore: admin folder structure (makeplane#8632)

* chore: admin folder structure

* fix: copy right check and formatting

* fix: types

* i18n(ru): expand Russian translation coverage (makeplane#8603)

Added missing translations for:
- Profile preferences (language, timezone settings)
- Account settings sections (preferences, notifications, security, api-tokens, activity)
- Workspace settings (billing, exports, webhooks headings/descriptions)
- Project settings (states, labels, estimates, automations headings/descriptions)
- Power-K command palette (contextual actions, navigation, creation, preferences, help)
- Sidebar elements (stickies, your_work, pin/unpin)
- Common actions (copy_markdown, overview)
- Navigation customization options

* chore(deps): update axios dependency

* [GIT-57 | WEB-5912] fix: app sidebar ux and responsiveness (makeplane#8560)

* fix: project extended sidebar accordion ux

* fix: app sidebar mobile responsiveness ux

* chore: code refactor

* refactor: table drag preview using decorations (makeplane#8597)

* refactor: table drag preview using decorations

* fix: history meta for table drag state

* [WEB-5884] chore: layout loader enhancements makeplane#8500

* [WEB-1201] chore: dropdown options hierarchy improvements (makeplane#8501)

* chore: sortBySelectedFirst and sortByCurrentUserThenSelected utils added

* chore: members dropdown updated

* chore: module dropdown updated

* chore: project and label dropdown updated

* chore: code refactor

* [GIT-44] refactor(auth): add PASSWORD_TOO_WEAK error code (makeplane#8522)

* refactor(auth): add PASSWORD_TOO_WEAK error code and update related error handling in password change flow

* fix(auth): update import to use type for EAuthenticationErrorCodes in security page

* Update apps/web/app/(all)/profile/security/page.tsx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update apps/web/app/(all)/[workspaceSlug]/(settings)/settings/account/security/page.tsx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* refactor: updated auth error exception accross zxcvbn usages

* fix: improve error handling for password strength validation and update error messages

* i18n(ru): update Russian translations for stickies and automation description

Added translation for 'stickies' and improved formatting of the automation description in Russian locale.

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update translations.ts: issue-artifacts discoverd (makeplane#7979)

* [WEB-5873] fix: user avatar ui consistency (makeplane#8495)

* fix: user avatar ui consistency

* chore: code refactor

* [SILO-820] fix: update serializer for module detail API endpoint to use ModuleUpdateSerializer (makeplane#8496)

* [VPAT-51] fix: update workspace invitation flow to use token for validation makeplane#8508

- Modified the invite link to include a token for enhanced security.
- Updated the WorkspaceJoinEndpoint to validate the token instead of the email.
- Adjusted the workspace invitation task to generate links with the token.
- Refactored the frontend to handle token in the invitation process.

Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>

* [WEB-5871] chore: added intake count for projects (makeplane#8497)

* chore: add intake_count in project list endpoint

* chore: sidebar project navigation intake count added

* fix: filter out closed intake issues in the count

* chore: code refactor

* chore: code refactor

* fix: filter out deleted intake issues

---------

Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>

* [WEB-5829] fix: Intake open work count (makeplane#8547)

* fix: open intake count at sidebar header

* chore: reverted inbox store arguments to core store

* fix: intake count update

* [WEB-5863] fix: estimate point input validation makeplane#8492

Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>

* [VPAT-55] chore(security): implement input validation across authentication and workspace forms (makeplane#8528)

* chore(security): implement input validation across authentication and workspace forms

  - Add OWASP-compliant autocomplete attributes to all auth input fields
  - Create centralized validation utilities blocking injection-risk characters
  - Apply validation to names, display names, workspace names, and slugs
  - Block special characters: < > ' " % # { } [ ] * ^ !
  - Secure sensitive input fields across admin, web, and space apps

* chore: add missing workspace name validation to settings and admin forms

* feat: enhance validation regex for international names and usernames

- Updated regex patterns to support Unicode characters for person names, display names, company names, and slugs.
- Improved validation functions to block injection-risk characters in names and slugs.

* [VPAT-16] improvement: add file validation to prevent malicious uploads makeplane#8493

Add client-side checks for double extensions, dangerous file types,
dot files, and path traversal patterns. Addresses security audit
recommendations for file upload validation.

* [WEB-5827] fix: persist external cover image URLs (Unsplash) in project updates makeplane#8482

* [VPAT-27] chore(security): disable autocomplete on sensitive input fields makeplane#8517

Disable autocomplete on authentication and security-related forms to prevent
browsers from storing sensitive credentials. This affects sign-in, password
reset, account security, and onboarding forms across admin, web, and space apps.

Modified components:
- Auth forms (email, password, unique code, forgot/reset/set password)
- Account security pages
- Instance setup and profile onboarding
- Shared UI components (auth-input, password-input)

* [WEB-5917] fix: generate clean plain text from HTML email template makeplane#8535

* [WEB-5878] chore: add validation for project name/identifier for special characters (makeplane#8529)

* chore: update ProjectSerializer to raise validation for special characters in name and identifier

* chore: update external endpoints

* fix: external api serializer validation

* update serializer to send error code

* fix: move the regex expression to Project model

* [WEB-6194]migration: added archived_at in IssueView makeplane#8641

* migration: added archived_at in IssueView

* fix: lint

* fix: IDOR Vulnerabilities in Asset & Attachment Endpoints (makeplane#8644)

* fix: idor issues in project assets and issue attachements

* fix: comments

* fix: Member Information Disclosure via Public Endpoint makeplane#8646

* chore: Add forum link and remove discord link on readme (makeplane#8655)

* Update README to remove Discord and add Forum link

Removed Discord badge and replaced Releases link with Forum link.

* Fix forum link in README.md

* fix: Update healthcheck endpoint in Dockerfile to target /spaces/ path (makeplane#8674)

* Change Dependabot update interval from weekly to daily

* [WIKI-887] fix: add scroll in heading layout (makeplane#8596)

* fix: add scroll in heading layout

* chore: remove visible scroll  bar

* fix :format

* chore: fix outline scroll

* chore: fix format

* chore: fix translation

---------

Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>

* fix: merge lists in editor (makeplane#8639)

* chore: replace prettier with oxfmt (makeplane#8676)

* fix: replace eslint with oxlint (makeplane#8677)

* fix: replace eslint with oxlint

* chore: adding max warning

* fix: formatting

* chore(deps): minimatch and rollup package vulnerabilities (makeplane#8675)

* fix: package updates

* fix: package upgrades

* fix: minimatch package vulnerabilities

* fix: ajv package vulnerabilities

* fix: lint

* fix: format

* [SILO-1028] feat: Project Summary external API (makeplane#8661)

* add project summary endpoint

* update response structure

* [WIKI-852] chore: update page version save logic (makeplane#8440)

* chore: updated the logic for page version task

* chore: updated the html variable

* chore: handled the exception

* chore: changed the function name

* chore: added a custom variable

* [WEB-5225] feat: enhance authentication logging with detailed error and info message (makeplane#7998)

* feat: enhance authentication logging with detailed error and info messages

- Added logging for various authentication events in the Adapter and its subclasses, including email validation, user existence checks, and password strength validation.
- Implemented error handling for GitHub OAuth email retrieval, ensuring proper logging of unexpected responses and missing primary emails.
- Updated logging configuration in local and production settings to include a dedicated logger for authentication events.

* chore: address copilot comments

* chore: addressed some additional comments

* chore: update log

* fix: lint

* [WEB-6420] chore: migrate community references from Discord to Forum (makeplane#8657)

* chore: replace Discord references with Forum links

* chore: migrate help and community CTAs from Discord to Forum

* refactor: replace Discord icons with lucide MessageSquare

* chore: rename Discord labels and keys to Forum

* chore: remove obsolete Discord icon component

* chore: update Discord references to Forum in templates

* chore: code refactoring

* fix: dependabot and codeql CI

* fix: disable react-in-jsx-scope rule in oxlint config (makeplane#8682)

After makeplane#8677 replaced ESLint with OxLint, the react-in-jsx-scope rule
was not disabled. This causes all commits touching JSX files to fail
the pre-commit hook (oxlint --deny-warnings).

React 17+ uses automatic JSX runtime so explicit React imports are
not required.

Fixes makeplane#8681

* chore: space folders (makeplane#8707)

* chore: change the space folders structure

* fix: format

* chore(deps): django version upgrade

* [GIT-40]fix: apply sub-issue display filter when adding work items makeplane#8534

* [WEB-5606] fix: work item preview word break makeplane#8537

* [WIKI-892] fix: description input component re-render makeplane#8600

* [WIKI-785] refactor: editor markdown handler makeplane#8546

* [WEB-5911] fix: error outline button text color makeplane#8531

* [SECUR-116] fix: ssrf webhook url for ip address makeplane#8716

* [WEB-6420] chore: self-host social icons in project invitation email (makeplane#8718)

* chore: add self-hosted social icon assets for email templates

* chore: pass current_site to project invitation email context

* chore: replace mailinblue CDN icons with self-hosted static assets

* feat: Complete Agent and Worktrees modules

- Add Agent CRUD API and frontend
- Add Worktrees page with CRUD
- Add extended routes for /agents and /worktrees
- Add custom sidebar navigation

---------

Signed-off-by: majiayu000 <1835304752@qq.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: pratapalakshmi <137189067+pratapalakshmi@users.noreply.github.com>
Co-authored-by: b-saikrishnakanth <130811169+b-saikrishnakanth@users.noreply.github.com>
Co-authored-by: Nikhil <118773738+pablohashescobar@users.noreply.github.com>
Co-authored-by: Vamsi Krishna <46787868+vamsikrishnamathala@users.noreply.github.com>
Co-authored-by: Vipin Chaudhary <VipinChaudhary1809@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>
Co-authored-by: Dheeraj Kumar Ketireddy <dheeraj.ketireddy@plane.so>
Co-authored-by: Anmol Singh Bhatia <121005188+anmolsinghbhatia@users.noreply.github.com>
Co-authored-by: Aaron <lifeiscontent@users.noreply.github.com>
Co-authored-by: M. Palanikannan <73993394+Palanikannan1437@users.noreply.github.com>
Co-authored-by: pushya22 <130810100+pushya22@users.noreply.github.com>
Co-authored-by: Pushya Mitra Thiruvooru <pushya@Pushyas-MacBook-Pro.local>
Co-authored-by: Aaryan Khandelwal <65252264+aaryan610@users.noreply.github.com>
Co-authored-by: Jayash Tripathy <76092296+JayashTripathy@users.noreply.github.com>
Co-authored-by: gakshita <akshitagoyal1516@gmail.com>
Co-authored-by: Palanikannan M <akashmalinimurugu@gmail.com>
Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com>
Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>
Co-authored-by: Henit Chobisa <chobisa.henit@gmail.com>
Co-authored-by: Sangeetha <sangeethailango21@gmail.com>
Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>
Co-authored-by: Bavisetti Narayan <72156168+NarayanBavisetti@users.noreply.github.com>
Co-authored-by: Shaikh Naasir <yoursdeveloper@protonmail.com>
Co-authored-by: lif <1835304752@qq.com>
Co-authored-by: NarayanBavisetti <narayan3119@gmail.com>
Co-authored-by: vamsikrishnamathala <matalav55@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>
Co-authored-by: yy <yhymmt37@gmail.com>
Co-authored-by: punto <119956578+AshrithSathu@users.noreply.github.com>
Co-authored-by: Ship it <161483884+vcscroll@users.noreply.github.com>
Co-authored-by: Akshat Jain <akshatjain9782@gmail.com>
Co-authored-by: stelmsk <151884118+stelmsk@users.noreply.github.com>
Co-authored-by: Cornelius <70640137+conny3496@users.noreply.github.com>
Co-authored-by: Vihar Kurama <vihar.kurama@gmail.com>
Co-authored-by: Saurabh Kumar <70131915+Saurabhkmr98@users.noreply.github.com>
Co-authored-by: darkingtail <51188676+darkingtail@users.noreply.github.com>
Co-authored-by: Claude Code <claude@anthropic.com>
AbstractBike added a commit to AbstractBike/plane that referenced this pull request Apr 2, 2026
* fix: editor sync changes (#8306)

* chore: upate function declarations

* chore: formatted files

* chore: fix/check tooling improvements with turbo (#8304)

* fix: broken lock file

* chore: add Plane sync label to github templates #8303

Co-authored-by: Pushya Mitra Thiruvooru <pushya@Pushyas-MacBook-Pro.local>

* [WEB-5624] chore: added webhook translations #8312

* chore(deps): upgrade next themes package

* [WEB-5654]fix: custom select selection and dropdown close #8324

* [WEB-5124] chore: intake work item toast enhancements (#8329)

* [WEB-5647] chore: list layout work item identifier enhancements (#8326)

* chore: file formating

* [WEB-5650] feat: Enable Gitea OAuth configuration  (#8325)

* feat: implement OAuth configuration helper and integrate into auth forms

* fix: ensure OAuth providers are disabled by default if not configured

* [WEB-5602] feat: new design system (#8220)

* chore: init tailwind v4

* chore: update all configs

* chore: add source to parse monorepo packages

* chore: combine all css files

* feat: added extended colors

* chore: update typography

* chore: update extended color var names

* refactor: remove initial spacing variable and update dark mode selector

* chore: update css files

* chore: update animations

* chore: remove spacing tokens

* fix: external css files

* chore: update tailwind-merge version

* chore: update font family

* chore: added brief agents.md and story for new design system

* chore: enhance design system documentation with rare exceptions for visual separation

* chore: add fontsource package for typography

* chore: material symbols font added

* chore: update shadow default

* chore: add stroke and outline theme vars

* chore: update ring and fill colors

* chore: overwrite tailwind typography tokens

* chore: add high contrast mode tokens

* chore: update scrollbar colors

* chore: backward compatibility for buttons and placeholders

* chore: add priority colors

* chore: update urgent priority color

* chore: update plan colors

* chore: add missing utility class

* chore: update height and padding classes

* chore: update label colors

* chore: add missing utlity

* chore: add typography plugin to space app

* chore: replace existing classNames with new design system tokens #8244 (#8278)

* chore: update border colors

* chore: update all borders

* chore: update text colors

* chore: update css variables

* chore: update font sizes and weights

* chore: update bg colors

* chore: sync changes

* fix: uncomment spacing-1200 variable in variables.css

* chore: update primary colors

* refactor: updated border to border-subtle

* refactor: update various components and improve UI consistency across the application

* updated classnames

* updated classnames

* refactor: update color-related class names to use new design system variables for consistency

* chore: default automations

* chore: update text sizes

* chore: home and power k

* chore: home and power k

* chore: replace ui package button components

* chore: update text sizes

* chore: updated issue identifier (#8275)

* refactor: top navigation and sidebar design token (#8276)

* chore: update all button components (#8277)

* chore: new button component

* chore: update existing buttons

* chore: overwrite tailwind typography tokens

* fix: twMerge config + fixed cn instances

* refactor: toast design token updated (#8279)

* chore: update existing buttons

* chore: tooltip design token updatged (#8280)

* chore: moved cn utility to propel (#8281)

* chore: update space app UI (#8285)

* chore; update space app filters component

* fix: button whitespace wrap

* chore: space app votes

* chore: update dropdown components

* refactor: auth, onboarding, sidebar, and common component design token migration (#8291)

* chore: checkbox component design token updated

* chore: indicator and oauth component design token updated

* chore: sidebar design token updated

* chore: auth and onboarding design token updated

* chore: update divider color

* style: update background colors and hover effects across list components

* fix: tailwind merge

* refactor: toggle switch design token migration and header utility classname added (#8295)

* chore: toggle component design token updated

* chore: h-header utility class added

* chore: updated color tokens for work item detail page (#8296)

* chore: update react-day-picker UI

* refactor: update button sizes and styles in filters components

* refactor: breadcrumbs design token updated (#8297)

* chore: update priority icon colors

* refactor: updated layout variables

* chore: update plan card primary CTA

* Chore update editor design system (#8299)

* refactor: update styles for callout, color selector, logo selector, and image uploader

* refactor:fix image

* chore: update settings UI

* chore: updated notifications color and size tokens (#8302)

* chore: update sm button border radius

* fix: logo renderer

* chore: icon button component

* chore: remove deprecated classes

* chore: remove deprecated classes

* chore: update editor list spacing

* fix: icon button size

* chore: improvements (#8309)

* chore: update cycles and modules pages

* refactor: update background styles across various components to use new design system colors

* fix: button type errors

* chore: update modals design system (#8310)

* refactor: callout bg

* refactor: code  bg

* refactor: modal size and variant

---------

Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>

* chore: update next-themes

* design: update billing and plans component styles and remove unused utility functions (#8313)

* refactor: empty state design token migration and improvements (#8315)

* fix: profile page

* refactor: tabs design token updated (#8316)

* chore: updated buttons and tokens for work items (#8317)

* fix: adjust trial button spacing in checkout modal

* chore: update add button hover state

* fix: type error (#8318)

* fix: type error

* chore: code refactor

* refactor: update button sizes and background styles in rich filters components

* refactor: update editor bg

* refactor: enhance Gantt chart sidebar functionality and styling

- Removed unused  prop from .
- Updated  to include new props for better block management and scrolling behavior.
- Improved auto-scroll functionality for Gantt chart items.
- Adjusted styles in  component for consistent design.

* regression: gantt design

* chore: new badge component

* fix: favorite star

* chore: update backgroung, typography and button sizes across workspace settings general and members pages

* fix: header button sizes

* fix: emoji icon logo (#8323)

* more fixes

* chore: update settings sidebar

* refactor: avatar component

* chore: updated work item detail sidebar (#8327)

* refactor: update link preview

* fix: work item property dropdowns

* fix: dropdown buttons border radius

* chore: update power k translation

* chore: updated profile activity design (#8328)

* chore: update settings pages

* chore: update work item sidebar alignments (#8330)

* refactor: admin design system

* chore: update page header

---------

Co-authored-by: Jayash Tripathy <76092296+JayashTripathy@users.noreply.github.com>
Co-authored-by: VipinDevelops <vipinchaudhary1809@gmail.com>
Co-authored-by: Vamsi Krishna <46787868+vamsikrishnamathala@users.noreply.github.com>
Co-authored-by: Anmol Singh Bhatia <121005188+anmolsinghbhatia@users.noreply.github.com>
Co-authored-by: gakshita <akshitagoyal1516@gmail.com>
Co-authored-by: Palanikannan M <akashmalinimurugu@gmail.com>
Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com>
Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>
Co-authored-by: M. Palanikannan <73993394+Palanikannan1437@users.noreply.github.com>

* fix: formatting

* reexport types

* fix: lint error

---------

Co-authored-by: Jayash Tripathy <76092296+JayashTripathy@users.noreply.github.com>
Co-authored-by: VipinDevelops <vipinchaudhary1809@gmail.com>
Co-authored-by: Vamsi Krishna <46787868+vamsikrishnamathala@users.noreply.github.com>
Co-authored-by: Anmol Singh Bhatia <121005188+anmolsinghbhatia@users.noreply.github.com>
Co-authored-by: gakshita <akshitagoyal1516@gmail.com>
Co-authored-by: Palanikannan M <akashmalinimurugu@gmail.com>
Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com>
Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>
Co-authored-by: M. Palanikannan <73993394+Palanikannan1437@users.noreply.github.com>

* [WEB-5668] fix: add fetchWorkspaceLevelProjectEntities method and update project-related fetch keys (#8347)

* [SILO-783] feat: added porters and new serializer based exporter (#8335)

* [WEB-5699] refactor: update styling and classnames of charts according to new design system (#8345)

* refactor: update styling and class names according to new design system in charts

* refactor: clean up

* feat: custom theming enhancements (#8342)

* [WEB-5671] chore: settings workspace members enhancements #8346

* [WEB-5666] chore: set project timezone same as workspace timezone in project (#8340)

* [WEB-5614] fix: new design system consistency (#8351)

* chore: tooltip enhancements

* chore: project card enhancements

* chore: work item card enhancements

* chore: update component styles and class names for consistency across the application

---------

Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>

* [WEB-5708] regression: remove material icon instances from the Space app (#8353)

* chore: sync changes (#8343)

* [WEB-5614] chore: work item detail and list layout enhancements #8355

* regression: replace old css vars with the new design system tokens (#8354)

* chore: replace old css vars

* fix: replace shadow and primary colors

* chore: remove hardcoded colors

* [WEB-5614] chore: custom theme on colour improvement #8356

* [WEB-5732] style: update work item detail properties UI (#8357)

* [WEB-5730] fix: user mention colors #8358

* [WEB-5614] fix: empty state and padding token fixes (#8359)

* [WEB-5614] chore: update component styles and class names for consistency across projects #8360

* [WEB-5614] chore: logo and icon enhancements #8362

* fix: work item property icon renderer (#8363)

* [WEB-5614] fix: sidebar and label dropdown #8364

* fix: material icons font file (#8366)

* [WEB-5614] chore: lucide icon code refactor #8365

* fix: nested context menu UI (#8367)

* [WEB-5708] style: space app kanban card UI (#8368)

* [WEB-5742] fix: input field background #8369

* [WEB-5641] chore: sub work item quick menu padding #8370

* chore: replace old classNames (#8372)

* chore: update component styles and class names for consistency across the application (#8376)

* [WEB-5660] [WEB-5737] fix: cycle and module sidebar #8375

* [WEB-5676] style: gantt column outline #8374

* [WEB-5614] chore: platform design token enhancements (#8373)

* [WEB-5649] [WEB-5675] fix: local font files #8377

* [WEB-5614] chore: primitive token updated (#8378)

* fix: tooltip imports (#8379)

* [WEB-5614] chore: platform header and breadcrumb enhancements (#8383)

* [WEB-5652] fix: kanban quick add UI #8382

* [WEB-5726] fix: showing an empty state on deleted work item link #8381

* fix: space app default background (#8384)

* [WIKI-849] feat: debounce for mention search (#8380)

* fix: font imports (#8387)

* chore: platform layout enhancements (#8386)

* fix: image uploader bg in light mode (#8385)

* [WEB-5614] refactor: update styling and structure across various components (#8388)

* fix: input fields bg (#8389)

* fix: custom z-index classNames (#8395)

* [WEB-5454] fix: optimize date validation logic in CycleCreateUpdateModal #8394

* [WEB-5614] chore: work item detail comment and sidebar enhancements (#8397)

* [WEB-5675] chore: implement `fontsource` as the fonts library (#8398)

* [WEB-5762] fix: workitem detail sidebar properties design consistency (#8400)

* [WEB-5761]fix: intake spacing issue (#8399)

* [WEB-5614] chore: sidebar enhancement #8401

* [WEB-5768]chore: updated comment UI #8402

* [WEB-5614] chore: package and layout enhancements #8403

* chore: update storybook dependency

* [WEB-5657] feat: add synchronization configuration for multiple providers in authentication adapter  (#8336)

* feat: add sync functionality for OAuth providers

- Implemented `check_sync_enabled` method to verify if sync is enabled for Google, GitHub, GitLab, and Gitea.
- Added `sync_user_data` method to update user details, including first name, last name, display name, and avatar.
- Updated configuration variables to include sync options for each provider.
- Integrated sync check into the login/signup process.

* feat: add sync toggle for OAuth providers in configuration forms

* fix: remove default value for sync options in OAuth configuration forms

* chore: delete old avatar and upload a new one

* chore: update class method

* chore: add email nullable

* refactor: streamline sync check for multiple providers and improve avatar deletion logic

* fix: ensure ENABLE_SYNC configurations default to "0" for Gitea, Github, Gitlab, and Google forms

* fix: simplify toggle switch value handling in ControllerSwitch component

---------

Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>

* [WEB-5657] chore: synchronization configuration for multiple providers in authentication adapter #8409

* [WEB-5746]fix: workspace member modal z-index #8410

* [WEB-5773] fix: editor image full screen modal (#8413)

* [WEB-5774] fix: editor nodes background colors (#8416)

* [WEB-5776]chore: updated design system for alert modal #8415

* [WEB-5775] fix: mentions search on empty query #8417

* [WEB-5662][WEB-5770] fix: alignment of cycles in sidebar and layout selection dropdown button (#8414)

* fix: alpha colors (#8418)

* [WEB-5784] fix: truncation issue in wi properties (#8422)

* fix: update background surface 2 variables in tailwind config

* fix: improve layout and truncation handling in issue link and list items

* docs: update readme with react router badge (#8424)

Updated feature list and modified the local development section.

* [WEB-5788] fix: board layout group by icon #8426

* [WEB-5792] regression: editor font family #8427

* [WIKI-740] refactor: editor table performance (#8411)

* [WEB-5786] fix: updated font size for dates at Kanban card #8429

* [WEB-5772] fix: theme switch flicker (#8428)

* [WEB-5784] fix: truncation of links in work items (#8430)

* [WEB-5772] chore: theme switcher and editor colors enhancements (#8436)

* [WEB-5772] chore: theme switcher code refactor #8438

* chore: workspace events (#8439)

* chore: adding invite and joined events

* chore: adding workspace create and update events

* [WEB-5798] refactor: web and admin auth related components and update admin designs (#8431)

* refactor: web and admin auth related components and update admin designs.

* fix: format

* [WEB-5581] fix: resolve logo spinner hydration and theme loading issues (#8450)

- Fix hydration mismatch by lazy loading components that depend on theme
- Ensure LogoSpinner renders with correct theme on initial load

* [WEB-5791] fix: broken favicon in links (#8396)

* fix: using base url of a redirect url

* chore: internal networks check for the final_url

* fix: none final_url

* fix: exception handling

* fix: exception handling

* chore: remove unused imports

* refactor: moved ip address check logic into separate function

* fix: ValueError logic

* [WEB-5667] fix: estimate value display in analytics #8448

* [WEB-5779] fix: handle loading state while fetching project cover image (#8419)

* refactor: replace cover image handling with CoverImage component across profile and project forms

* fix: extend CoverImage component to accept additional img props

* Update apps/web/core/components/common/cover-image.tsx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix: handle undefined cover image URL in ProfileSidebar component

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* [WEB-5782]chore: migrated modals to @plane/ui (#8420)

* chore: migrated modal to @plane/ui

* chore: fixed spacings

* [WEB-5808] chore: sidebar project list enhancements (#8451)

* chore: sidebar project list enhancements

* chore: code refactor

* chore: code refactor

* [WEB-5324] refactor: add Unified OAuth Configuration and Missing Gitea Options (#8050)

* refactor: add Unified OAuth Configuration and Missing Gitea Options

- Replaced the AuthenticationModes component with a more streamlined implementation using AuthenticationMethodCard.
- Removed obsolete authentication modes files from the codebase.
- Enhanced the AuthRoot component to utilize the new OAuth configuration hook for better management of authentication options.
- Updated type definitions for instance authentication modes to reflect the new structure.

* refactor: update OAuth type imports and remove obsolete types

- Replaced local type imports with centralized imports from @plane/types in core, extended, and index OAuth hooks.
- Removed the now redundant types.ts file as its definitions have been migrated.
- Enhanced type definitions for OAuth options to improve consistency across the application.

* feat: add new Gitea logo and update OAuth icon imports to use standard HTML img tags

* chore: remove unused authentication logos and upgrade button component

* [WEB-5574]chore: notification card refactor (#8234)

* chore: notification card refactor

* chore: moved base activity types to constants package

* [WEB-5804] refactor: decouple filter value types from filter configurations (#8441)

* [WEB-5804] refactor: decouple filter value types from filter configurations

Remove value type constraints from filter configurations to support
operator-specific value types. Different operators can accept different
value types for the same filter property, so value types should be
determined at the operator level rather than the filter level.

- Remove generic value type parameter from TFilterConfig
- Update TOperatorConfigMap to accept union of all value types
- Simplify filter config factory signatures across all filter types
- Add forceUpdate parameter to updateConditionValue method

* refactor: remove filter value type constraints from filter configurations

Eliminate the generic value type parameter from filter configurations to allow for operator-specific value types. This change enhances flexibility by enabling different operators to accept various value types for the same filter property.

- Updated TFilterConfig and related interfaces to remove value type constraints
- Adjusted filter configuration methods and types accordingly
- Refactored date operator support to align with the new structure

* [WEB-5785]fix: favorites icon size #8449

* [WEB-5781]chore: removed info banner for preferences #8442

* [WEB-5809] refactor: tailwind config inline variables (#8437)

* refactor: actions icon migration (#8219)

* chore: gitignore updated

* chore: check icon added to propel package

* feat: search icon migration

* chore: check icon migration

* chore: plus icon added to propel package

* chore: code refactor

* chore: plus icon migration and code refactor

* chore: trash icon added to propel package

* chore: code refactor

* chore: trash icon migration

* chore: edit icon added to propel package

* chore: new tab icon added to propel package

* chore: edit icon migration

* chore: newtab icon migration

* chore: lock icon added to propel package

* chore: lock icon migration

* chore: globe icon added to propel package

* chore: globe icon migration

* chore: copy icon added to propel package

* chore: copy icon migration

* chore: link icon added to propel package

* chore: link icon migration

* chore: link icon migration

* chore: info icon added to propel package

* chore: code refactor

* chore: code refactor

* chore: code refactor

* chore: code refactor

* regression: red and green color backgrounds (#8456)

* [WEB-5815] chore: removed the deleted states (#8457)

* Typo: database extension error message (#8461)

* [WEB-5179] chore: icon utils code refactor #8458

* [WEB-5790] feat: new email templates (#8423)

* chore: remove unused get_client_ip import (#8453)

Remove unused import `get_client_ip` from workspace/invite.py.
Identified by ruff linter (F401 error).

Signed-off-by: majiayu000 <1835304752@qq.com>

* [WEB-5822] fix: migrate ImagePickerPopover to Propel Tabs component and render only enabled tabs #8290

- Replace custom tab implementation with Propel Tabs
- Dynamically render only enabled tabs based on configuration
- Filter tabs by isEnabled property for cleaner conditional rendering
- Improve tab navigation and accessibility with Propel components

* chore: navigation preference enhancements (#8468)

* [WEB-5472] refactor: components of project creation flow (#8462)

* [WEB-857] regression: image uploader error state #8471

* [WEB-4959]chore: refactor project member page #8464

* [WEB-5472] refactor: project form #8472

* migration: added webhook version, navigation related fields and allowed_rate_limit for APIToken (#8339)

* migration: added version field in webhook

* chore: add max_length

* chore: added product tour fields

* chore: updated the migration file

* chore: removed the duplicated migration file

* chore: added allowed_rate_limit for api_tokens

* chore: changed key feature tour to product tour

* chore: added is_subscribed_to_changelog field

---------

Co-authored-by: NarayanBavisetti <narayan3119@gmail.com>

* fix: correct spelling error in database.ts log message (#8452)

Fix "convertion" -> "conversion" in error log message.

Signed-off-by: majiayu000 <1835304752@qq.com>

* [WEB-5598] refactor: streamline object creation in workspace seed task and improve error handling in workspace creation #8264

* chore: remove posthog events (#8465)

* chore: remove posthog events

* chore: remove event tracking

* chore: lint errors

* chore: minor changes based on comments

* fix: type errors

* Revert "[WEB-4959]chore: refactor project member page #8464" (#8476)

This reverts commit c97e41851530fbb0426c542fa8739ab95218f8a5.

* chore: remove unused right sidebar component and clean up workspace member settings (#8477)

* [WEB-5537]refactor: rename IssueUserProperty to ProjectUserProperty and update related references  (#8206)

* refactor: rename IssueUserProperty to ProjectUserProperty and update related references across the codebase

* migrate: move issue user properties to project user properties and update related fields and constraints

* refactor: rename IssueUserPropertySerializer and IssueUserDisplayPropertyEndpoint to ProjectUserPropertySerializer and ProjectUserDisplayPropertyEndpoint, updating all related references

* fix: enhance ProjectUserDisplayPropertyEndpoint to handle missing properties by creating new entries and improve response handling

* fix: correct formatting in migration for ProjectUserProperty model options

* migrate: add migration to update existing non-service API tokens to remove workspace association

* migrate: refine migration to update existing non-service API tokens by excluding bot users from workspace removal

* chore: changed the project sort order in project user property

* chore: remove allowed_rate_limit from APIToken

* chore: updated user-properties endpoint for frontend

* chore: removed the extra projectuserproperty

* chore: updated the migration file

* chore: code refactor

* fix: type error

---------

Co-authored-by: NarayanBavisetti <narayan3119@gmail.com>
Co-authored-by: sangeethailango <sangeethailango21@gmail.com>
Co-authored-by: vamsikrishnamathala <matalav55@gmail.com>
Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>

* [WIKI-826] chore: add unique id as key to logo selector (#8494)

* [VPAT-50] chore(security): add X-Frame-Options header to nginx configuration to prevent clickjacking attacks (#8507)

* [VPAT-50] chore(security): add X-Frame-Options header to nginx configuration to prevent clickjacking attacks

* [SECURITY] chore: enhance nginx configuration with additional security headers

* chore: updated migration file name (#8515)

* chore(deps): react router upgraded

* [WEB-5890] migration: added getting_started_checklist, tips, explored_feature fields on the workspace member table (#8489)

* migration: added getting_started_checklist and tips field

* fix: remove defaults and added explored_features field

* fix: added user table migration

* [WEB-5907] fix: magic code sign-in at Space app. #8552

* [WIKI-735] fix: table insert handle z-index #8545

* [WEB-5898] chore: update tailwind config #8516

* chore(deps): bump lodash-es in the npm_and_yarn group across 1 directory (#8573)

Bumps the npm_and_yarn group with 1 update in the / directory: [lodash-es](https://github.com/lodash/lodash).


Updates `lodash-es` from 4.17.21 to 4.17.23
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23)

---
updated-dependencies:
- dependency-name: lodash-es
  dependency-version: 4.17.23
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [WEB-5845] chore: changing description field to description json (#8230)

* chore: migrating description to description json

* chore: replace description with description_json

* chore: updated migration file

* chore: updated the migration file

* chore: added description key in external endpoint

* chore: updated the migration file

* chore: updated the typo

---------

Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>

* chore: fix typos in comments (#8553)

* [GIT-61] chore: allow .md files to be uploaded (#8571)

* chore: allow .md files to be uploaded

* chore: allow .md files to be uploaded

* [WEB-5860] [WEB-5861] [WEB-5862] style: improved settings interface (#8520)

* style: improved profile settings

* chore: minor improvements

* style: improved workspace settings

* style: workspace settings content

* style: improved project settings

* fix: project settings flat map

* chore: add back navigation from settings pages

* style: settings content

* style: estimates list

* refactor: remove old code

* refactor: removed unnecessary line breaks

* refactor: create a common component for page header

* chore: add fade-in animation to sidebar

* fix: formatting

* fix: project settings sidebar header

* fix: workspace settings sidebar header

* fix: settings content wrapper scroll

* chore: separate project settings features

* fix: formatting

* refactor: custom theme selector

* refactor: settings headings

* refactor: settings headings

* fix: project settings sidebar padding

* fix: sidebar header padding

* fix: sidebar item permissions

* fix: missing editable check

* refactor: remove unused files

* chore: remove unnecessary code

* chore: add missing translations

* fix: formatting

* [GIT-45] fix: allow markdown file attachments (#8524)

* fix: allow markdown file attachments

- Add text/markdown to ATTACHMENT_MIME_TYPES
- Fixes issue where .md files were rejected with 'Invalid file type' error

* added the support for frontend mime type too

* fix: node view renders (#8559)

* fix node renders

* fix handlers

* fix: duplicate id

* fix: pdf export (#8564)

* feat: pdf export

* fix: tests

* fix: tests

---------

Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>

* migration: back migrate all product tour fields to set true (#8575)

* [GIT-66] improvement: prevent disabling last enabled authentication method (#8570)

* fully translated into Ukrainian language (#8579)

* chore:  add copyright (#8584)

* feat: adding new copyright info on all files

* chore: adding CI

* fix: module percentage calculation (#8595)

* fix: file fomatting

* [SECUR-113] fix: ssrf for work item links (#8607)

* [SECUR-104] fix: Arbitrary Modification of API Token Rate Limits#8612

* chore(deps): upgrade django version

* [WEB-6058] chore : add logic to handle save#8614

* chore(deps): update the node pacakges

* fix: type fix for description payload (#8619)

* fix: type fix

* fix: duplicate type fix

* chore(deps): update lodash package

* [WEB-6149] migration: change estimate point key max value to 50 #8620

* fix: remove ee folder from web (#8622)

* chore: merge constants and services (#8623)

* fix: remove constants and services

* fix: formatting

* fix: types check

* chore: merge helpers and layouts (#8624)

* fix: remove constants and services

* fix: formatting

* chore: merge helpers and layouts

* fix: workspace disbale flag handling

* chore(deps): bump cryptography (#8625)

Bumps the pip group with 1 update in the /apps/api/requirements directory: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 44.0.1 to 46.0.5
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/44.0.1...46.0.5)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.5
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* style: update ASCII art in install script header (#8628)

* [WEB-6038] fix: work item empty title flicker #8618

* fix: workitem description input inital load (#8617)

* [WEB-6137] fix: work item peek view outside click #8610

* [SECUR-105] fix: csv injection vulnerability sanitization #8611

* [WIKI-877] fix: order of this dropdown options in pages #8563

* [WEB-5899]fix: project sort order (#8530)

* fix: project sort order

* chore: updated queryset for sort_order

* chore: admin folder structure (#8632)

* chore: admin folder structure

* fix: copy right check and formatting

* fix: types

* i18n(ru): expand Russian translation coverage (#8603)

Added missing translations for:
- Profile preferences (language, timezone settings)
- Account settings sections (preferences, notifications, security, api-tokens, activity)
- Workspace settings (billing, exports, webhooks headings/descriptions)
- Project settings (states, labels, estimates, automations headings/descriptions)
- Power-K command palette (contextual actions, navigation, creation, preferences, help)
- Sidebar elements (stickies, your_work, pin/unpin)
- Common actions (copy_markdown, overview)
- Navigation customization options

* chore(deps): update axios dependency

* [GIT-57 | WEB-5912] fix: app sidebar ux and responsiveness (#8560)

* fix: project extended sidebar accordion ux

* fix: app sidebar mobile responsiveness ux

* chore: code refactor

* refactor: table drag preview using decorations (#8597)

* refactor: table drag preview using decorations

* fix: history meta for table drag state

* [WEB-5884] chore: layout loader enhancements #8500

* [WEB-1201] chore: dropdown options hierarchy improvements (#8501)

* chore: sortBySelectedFirst and sortByCurrentUserThenSelected utils added

* chore: members dropdown updated

* chore: module dropdown updated

* chore: project and label dropdown updated

* chore: code refactor

* [GIT-44] refactor(auth): add PASSWORD_TOO_WEAK error code (#8522)

* refactor(auth): add PASSWORD_TOO_WEAK error code and update related error handling in password change flow

* fix(auth): update import to use type for EAuthenticationErrorCodes in security page

* Update apps/web/app/(all)/profile/security/page.tsx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update apps/web/app/(all)/[workspaceSlug]/(settings)/settings/account/security/page.tsx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* refactor: updated auth error exception accross zxcvbn usages

* fix: improve error handling for password strength validation and update error messages

* i18n(ru): update Russian translations for stickies and automation description

Added translation for 'stickies' and improved formatting of the automation description in Russian locale.

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update translations.ts: issue-artifacts discoverd (#7979)

* [WEB-5873] fix: user avatar ui consistency (#8495)

* fix: user avatar ui consistency

* chore: code refactor

* [SILO-820] fix: update serializer for module detail API endpoint to use ModuleUpdateSerializer (#8496)

* [VPAT-51] fix: update workspace invitation flow to use token for validation #8508

- Modified the invite link to include a token for enhanced security.
- Updated the WorkspaceJoinEndpoint to validate the token instead of the email.
- Adjusted the workspace invitation task to generate links with the token.
- Refactored the frontend to handle token in the invitation process.

Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>

* [WEB-5871] chore: added intake count for projects (#8497)

* chore: add intake_count in project list endpoint

* chore: sidebar project navigation intake count added

* fix: filter out closed intake issues in the count

* chore: code refactor

* chore: code refactor

* fix: filter out deleted intake issues

---------

Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>

* [WEB-5829] fix: Intake open work count (#8547)

* fix: open intake count at sidebar header

* chore: reverted inbox store arguments to core store

* fix: intake count update

* [WEB-5863] fix: estimate point input validation #8492

Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>

* [VPAT-55] chore(security): implement input validation across authentication and workspace forms (#8528)

* chore(security): implement input validation across authentication and workspace forms

  - Add OWASP-compliant autocomplete attributes to all auth input fields
  - Create centralized validation utilities blocking injection-risk characters
  - Apply validation to names, display names, workspace names, and slugs
  - Block special characters: < > ' " % # { } [ ] * ^ !
  - Secure sensitive input fields across admin, web, and space apps

* chore: add missing workspace name validation to settings and admin forms

* feat: enhance validation regex for international names and usernames

- Updated regex patterns to support Unicode characters for person names, display names, company names, and slugs.
- Improved validation functions to block injection-risk characters in names and slugs.

* [VPAT-16] improvement: add file validation to prevent malicious uploads #8493

Add client-side checks for double extensions, dangerous file types,
dot files, and path traversal patterns. Addresses security audit
recommendations for file upload validation.

* [WEB-5827] fix: persist external cover image URLs (Unsplash) in project updates #8482

* [VPAT-27] chore(security): disable autocomplete on sensitive input fields #8517

Disable autocomplete on authentication and security-related forms to prevent
browsers from storing sensitive credentials. This affects sign-in, password
reset, account security, and onboarding forms across admin, web, and space apps.

Modified components:
- Auth forms (email, password, unique code, forgot/reset/set password)
- Account security pages
- Instance setup and profile onboarding
- Shared UI components (auth-input, password-input)

* [WEB-5917] fix: generate clean plain text from HTML email template #8535

* [WEB-5878] chore: add validation for project name/identifier for special characters (#8529)

* chore: update ProjectSerializer to raise validation for special characters in name and identifier

* chore: update external endpoints

* fix: external api serializer validation

* update serializer to send error code

* fix: move the regex expression to Project model

* [WEB-6194]migration: added archived_at in IssueView #8641

* migration: added archived_at in IssueView

* fix: lint

* fix: IDOR Vulnerabilities in Asset & Attachment Endpoints (#8644)

* fix: idor issues in project assets and issue attachements

* fix: comments

* fix: Member Information Disclosure via Public Endpoint #8646

* chore: Add forum link and remove discord link on readme (#8655)

* Update README to remove Discord and add Forum link

Removed Discord badge and replaced Releases link with Forum link.

* Fix forum link in README.md

* fix: Update healthcheck endpoint in Dockerfile to target /spaces/ path (#8674)

* Change Dependabot update interval from weekly to daily

* [WIKI-887] fix: add scroll in heading layout (#8596)

* fix: add scroll in heading layout

* chore: remove visible scroll  bar

* fix :format

* chore: fix outline scroll

* chore: fix format

* chore: fix translation

---------

Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>

* fix: merge lists in editor (#8639)

* chore: replace prettier with oxfmt (#8676)

* fix: replace eslint with oxlint (#8677)

* fix: replace eslint with oxlint

* chore: adding max warning

* fix: formatting

* chore(deps): minimatch and rollup package vulnerabilities (#8675)

* fix: package updates

* fix: package upgrades

* fix: minimatch package vulnerabilities

* fix: ajv package vulnerabilities

* fix: lint

* fix: format

* [SILO-1028] feat: Project Summary external API (#8661)

* add project summary endpoint

* update response structure

* [WIKI-852] chore: update page version save logic (#8440)

* chore: updated the logic for page version task

* chore: updated the html variable

* chore: handled the exception

* chore: changed the function name

* chore: added a custom variable

* [WEB-5225] feat: enhance authentication logging with detailed error and info message (#7998)

* feat: enhance authentication logging with detailed error and info messages

- Added logging for various authentication events in the Adapter and its subclasses, including email validation, user existence checks, and password strength validation.
- Implemented error handling for GitHub OAuth email retrieval, ensuring proper logging of unexpected responses and missing primary emails.
- Updated logging configuration in local and production settings to include a dedicated logger for authentication events.

* chore: address copilot comments

* chore: addressed some additional comments

* chore: update log

* fix: lint

* [WEB-6420] chore: migrate community references from Discord to Forum (#8657)

* chore: replace Discord references with Forum links

* chore: migrate help and community CTAs from Discord to Forum

* refactor: replace Discord icons with lucide MessageSquare

* chore: rename Discord labels and keys to Forum

* chore: remove obsolete Discord icon component

* chore: update Discord references to Forum in templates

* chore: code refactoring

* fix: dependabot and codeql CI

* fix: disable react-in-jsx-scope rule in oxlint config (#8682)

After #8677 replaced ESLint with OxLint, the react-in-jsx-scope rule
was not disabled. This causes all commits touching JSX files to fail
the pre-commit hook (oxlint --deny-warnings).

React 17+ uses automatic JSX runtime so explicit React imports are
not required.

Fixes #8681

* chore: space folders (#8707)

* chore: change the space folders structure

* fix: format

* chore(deps): django version upgrade

* [GIT-40]fix: apply sub-issue display filter when adding work items #8534

* [WEB-5606] fix: work item preview word break #8537

* [WIKI-892] fix: description input component re-render #8600

* [WIKI-785] refactor: editor markdown handler #8546

* [WEB-5911] fix: error outline button text color #8531

* [SECUR-116] fix: ssrf webhook url for ip address #8716

* [WEB-6420] chore: self-host social icons in project invitation email (#8718)

* chore: add self-hosted social icon assets for email templates

* chore: pass current_site to project invitation email context

* chore: replace mailinblue CDN icons with self-hosted static assets

* [WIKI-874] refactor: description input component (#8544)

* refactor: description input component

* fix: add missing prop to rich text editor

* chore(deps): bump python-json-logger from 3.3.0 to 4.0.0 in /apps/api (#8692)

Bumps [python-json-logger](https://github.com/nhairs/python-json-logger) from 3.3.0 to 4.0.0.
- [Release notes](https://github.com/nhairs/python-json-logger/releases)
- [Changelog](https://github.com/nhairs/python-json-logger/blob/main/docs/changelog.md)
- [Commits](https://github.com/nhairs/python-json-logger/compare/v3.3.0...v4.0.0)

---
updated-dependencies:
- dependency-name: python-json-logger
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump pytest from 7.4.0 to 9.0.2 in /apps/api (#8693)

Bumps [pytest](https://github.com/pytest-dev/pytest) from 7.4.0 to 9.0.2.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/7.4.0...9.0.2)

---
updated-dependencies:
- dependency-name: pytest
  dependency-version: 9.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [WEB-6599] feat: instance not ready ui revamp (#8755)

* feat: instance not ready ui revamp

* chore: code refactoring

* chore: code refactoring

* chore(deps): upgrade the undici and flatted versions

* [WEB-6610] Fix work item drag handle hover gap (#8759)

* [WEB-6610] Fix work item drag handle hover gap

Amp-Thread-ID: https://ampcode.com/threads/T-019ce703-e30e-769b-9436-a7f5506e8a6c
Co-authored-by: Amp <amp@ampcode.com>

* fix: use p-0! pl-6! for correct drag handle hover area

Amp-Thread-ID: https://ampcode.com/threads/T-019ce703-e30e-769b-9436-a7f5506e8a6c
Co-authored-by: Amp <amp@ampcode.com>

* fix: update containerClassName to -ml-6 border-none p-0! pl-6!

Amp-Thread-ID: https://ampcode.com/threads/T-019ce703-e30e-769b-9436-a7f5506e8a6c
Co-authored-by: Amp <amp@ampcode.com>

---------

Co-authored-by: Amp <amp@ampcode.com>

* chore(deps): bump the actions group across 1 directory with 11 updates (#8741)

Bumps the actions group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4` | `6` |
| [makeplane/actions](https://github.com/makeplane/actions) | `1.0.0` | `1.4.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` |
| [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.1.0` | `2.5.0` |
| [actions/setup-node](https://github.com/actions/setup-node) | `4` | `6` |
| [actions/setup-go](https://github.com/actions/setup-go) | `5` | `6` |
| [docker/login-action](https://github.com/docker/login-action) | `3` | `4` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3` | `4` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `6.9.0` | `7.0.0` |
| [tailscale/github-action](https://github.com/tailscale/github-action) | `2` | `4` |
| [actions/cache](https://github.com/actions/cache) | `4` | `5` |



Updates `actions/checkout` from 4 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

Updates `makeplane/actions` from 1.0.0 to 1.4.0
- [Release notes](https://github.com/makeplane/actions/releases)
- [Commits](https://github.com/makeplane/actions/compare/v1.0.0...v1.4.0)

Updates `actions/upload-artifact` from 4 to 7
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v7)

Updates `softprops/action-gh-release` from 2.1.0 to 2.5.0
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/softprops/action-gh-release/compare/v2.1.0...v2.5.0)

Updates `actions/setup-node` from 4 to 6
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v4...v6)

Updates `actions/setup-go` from 5 to 6
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](https://github.com/actions/setup-go/compare/v5...v6)

Updates `docker/login-action` from 3 to 4
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/v3...v4)

Updates `docker/setup-buildx-action` from 3 to 4
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/v3...v4)

Updates `docker/build-push-action` from 6.9.0 to 7.0.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/v6.9.0...v7.0.0)

Updates `tailscale/github-action` from 2 to 4
- [Release notes](https://github.com/tailscale/github-action/releases)
- [Commits](https://github.com/tailscale/github-action/compare/v2...v4)

Updates `actions/cache` from 4 to 5
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: makeplane/actions
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: softprops/action-gh-release
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: actions/setup-node
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/setup-go
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/setup-buildx-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/build-push-action
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: tailscale/github-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/cache
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove chat support component

* fix: added workspace member check in allow permission for creator #8778

* fix: package updates

* fix: remove unused imports and variables (part 1 — packages & non-web-core) (#8751)

* fix: remove unused imports and variables (part 1)

Resolve oxlint no-unused-vars warnings in packages/*, apps/admin,
apps/space, apps/live, and apps/web (non-core).

* fix: resolve CI check failures

* fix: resolve check:types failures

* fix: resolve check:types and check:format failures

- Use destructuring alias for activeCycleResolvedPath
- Format propel tab-navigation file

* fix: format propel button helper with oxfmt

Reorder Tailwind classes to match oxfmt canonical ordering.

* fix: remove unused imports and variables (part 2 — web/core non-issues) (#8752)

* fix: remove unused imports and variables (part 2)

Resolve oxlint no-unused-vars warnings in apps/web/core/
(excluding components/issues/).

* fix: resolve CI check failures

* fix: resolve check:types failures

* fix: remove unused imports and variables (part 3) (#8753)

Resolve oxlint no-unused-vars warnings in
apps/web/core/components/issues/.

* fix: removed unused files

* chore: remove service token endpoint which is unused (#8797)

* fix: broken lockfile

* fix: add model_activity.delay() to API issue update/create paths for webhook dispatch (#8792)

Fixes #6746

API-driven issue updates (PUT update, PUT create-via-upsert, PATCH) were
missing `model_activity.delay()` calls, so webhooks were never dispatched
for changes made through the API. The web UI paths already include these
calls (e.g. in `post()` at L475), but the `put()` and `partial_update()`
methods only called `issue_activity.delay()`.

This adds `model_activity.delay()` immediately after each existing
`issue_activity.delay()` in these three code paths, using the same
signature as the existing call in `post()`.

Tested on Plane CE v1.2.1 self-hosted: API PATCH triggers
`webhook_send_task` in the Celery worker, confirming webhook delivery.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* [WEB-6702] feat: redesign intake action buttons and use design tokens (#8801)

* feat: intake action buttons redesign

* chore: code refactoring

* Open [WEB-6739] fix: color inside of active projects of analytics overview tab #8803

* [WEB-6734] fix: circular progress indicator stroke color#8802

* fix: migrate page navigation pane tabs from headless ui to propel (#8805)

* chore(deps): bump requests (#8804)

Bumps the pip group with 1 update in the /apps/api/requirements directory: [requests](https://github.com/psf/requests).


Updates `requests` from 2.32.4 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.32.4...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: tsdown watch (#8813)

closes #8791

* [WEB-6762] fix: missing profile icons for recent activities on "Your Work" Page #8812

* [WEB-6763] fix: date range dropdown clipped in sub-issues list #8809

* [WEB-6783] fix: crash when deleting work item from peek view in workspace spreadsheet (#8821)

* fix: guard against undefined issue in SpreadsheetIssueRow

* fix: add defensive guard for isIssueNew in list block-root

* chore(deps): bump cryptography (#8819)

Bumps the pip group with 1 update in the /apps/api/requirements directory: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 46.0.5 to 46.0.6
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.6
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [SILO-1087] feat: add IssueRelations external API (#8763)

* add IssueRelations external API

* update serializer methods and filter by slug

* [SILO-1026] feat: add estimates external API endpoints (#8664)

* add project summary endpoint

* update response structure

* add estimates external API endpoints with migrations

* fix invalid project and workspace error

* [WEB-6794] fix: align profile cover update with correct unsplash and upload handling (#8830)

* fix: profile cover update

* chore: code refactoring

* chore: code refactoring

* chore(deps): update dependency overrides (#8831)

Update brace-expansion override from 2.0.2 to 5.0.5 and add picomatch,
yaml@1, and yaml@2 overrides to pin transitive dependency versions.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* chore(deps): replace dotenvx with dotenv and update overrides (#8832)

* chore(deps): replace dotenvx with dotenv and update dependency overrides

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* chore: sort devDependencies in package.json files

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* chore: version bump

* fix: scope IssueBulkUpdateDateEndpoint query to workspace and project (#8834)

The bulk update date endpoint fetched issues by ID without filtering
by workspace or project, allowing any authenticated project member to
modify start_date and target_date of issues in any workspace/project
across the entire instance (IDOR - CWE-639).

Scoped the query to include workspace__slug and project_id filters,
consistent with other issue endpoints in the codebase.

Ref: GHSA-4q54-h4x9-m329

* chore: adding traget commit sha for the github release

* [INFRA-346] chore: remove artifacts.plane.so references from community deployments (#8836)

* chore: Intake snooze modal width

* [INFRA-351] fix: correct directory and command for space program in supervisor.conf #8838

* [WEB-6813] fix: module not associated when accepting intake work items (#8839)

* fix: intake module association on accept

* chore: code refactoring

* chore: add ops/ — NixOS module + obs + hooks

---------

Signed-off-by: majiayu000 <1835304752@qq.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: sriram veeraghanta <veeraghanta.sriram@gmail.com>
Co-authored-by: Aaron <lifeiscontent@users.noreply.github.com>
Co-authored-by: pushya22 <130810100+pushya22@users.noreply.github.com>
Co-authored-by: Pushya Mitra Thiruvooru <pushya@Pushyas-MacBook-Pro.local>
Co-authored-by: b-saikrishnakanth <130811169+b-saikrishnakanth@users.noreply.github.com>
Co-authored-by: Vamsi Krishna <46787868+vamsikrishnamathala@users.noreply.github.com>
Co-authored-by: Anmol Singh Bhatia <121005188+anmolsinghbhatia@users.noreply.github.com>
Co-authored-by: Aaryan Khandelwal <65252264+aaryan610@users.noreply.github.com>
Co-authored-by: Jayash Tripathy <76092296+JayashTripathy@users.noreply.github.com>
Co-authored-by: VipinDevelops <vipinchaudhary1809@gmail.com>
Co-authored-by: gakshita <akshitagoyal1516@gmail.com>
Co-authored-by: Palanikannan M <akashmalinimurugu@gmail.com>
Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com>
Co-authored-by: b-saikrishnakanth <bsaikrishnakanth97@gmail.com>
Co-authored-by: M. Palanikannan <73993394+Palanikannan1437@users.noreply.github.com>
Co-authored-by: Henit Chobisa <chobisa.henit@gmail.com>
Co-authored-by: Sangeetha <sangeethailango21@gmail.com>
Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>
Co-authored-by: Nikhil <118773738+pablohashescobar@users.noreply.github.com>
Co-authored-by: Bavisetti Narayan <72156168+NarayanBavisetti@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Shaikh Naasir <yoursdeveloper@protonmail.com>
Co-authored-by: lif <1835304752@qq.com>
Co-authored-by: NarayanBavisetti <narayan3119@gmail.com>
Co-authored-by: vamsikrishnamathala <matalav55@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com>
Co-authored-by: yy <yhymmt37@gmail.com>
Co-authored-by: punto <119956578+AshrithSathu@users.noreply.github.com>
Co-authored-by: Ship it <161483884+vcscroll@users.noreply.github.com>
Co-authored-by: Akshat Jain <akshatjain9782@gmail.com>
Co-authored-by: stelmsk <151884118+stelmsk@users.noreply.github.com>
Co-authored-by: Cornelius <70640137+conny3496@users.noreply.github.com>
Co-authored-by: Dheeraj Kumar Ketireddy <dheeraj.ketireddy@plane.so>
Co-authored-by: Vihar Kurama <vihar.kurama@gmail.com>
Co-authored-by: Saurabh Kumar <70131915+Saurabhkmr98@users.noreply.github.com>
Co-authored-by: darkingtail <51188676+darkingtail@users.noreply.github.com>
Co-authored-by: Amp <amp@ampcode.com>
Co-authored-by: ouchan <111338754+ouchanip@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants