Commit Graph
22651 Commits
Author SHA1 Message Date
dependabot[bot]andGitHub 77f90e41fc Bump the github-actions-updates group with 19 updates
Bumps the github-actions-updates group with 19 updates:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `6.0.2` |
| [actions/setup-node](https://github.com/actions/setup-node) | `6.3.0` | `6.4.0` |
| [docker/login-action](https://github.com/docker/login-action) | `4.0.0` | `4.2.0` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.0.0` | `7.2.0` |
| [chainguard-dev/setup-chainctl](https://github.com/chainguard-dev/setup-chainctl) | `0.5.0` | `0.5.1` |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.70` | `1.0.133` |
| [github/codeql-action](https://github.com/github/codeql-action) | `4.32.6` | `4.36.0` |
| [actions/setup-go](https://github.com/actions/setup-go) | `6.3.0` | `6.4.0` |
| [actions/github-script](https://github.com/actions/github-script) | `7.0.1` | `9.0.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` |
| [actions/download-artifact](https://github.com/actions/download-artifact) | `8.0.0` | `8.0.1` |
| [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.0.0` | `6.1.2` |
| [actions/cache](https://github.com/actions/cache) | `4.2.3` | `5.0.5` |
| [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `47.0.5` | `47.0.6` |
| [getsentry/action-release](https://github.com/getsentry/action-release) | `3.5.0` | `3.6.0` |
| [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `4.0.0` | `4.1.2` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.0.0` | `4.1.0` |
| [mikepenz/action-junit-report](https://github.com/mikepenz/action-junit-report) | `6.3.1` | `6.4.1` |
| [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.5.2` | `6.0.1` |


Updates `actions/checkout` from 4.2.2 to 6.0.2
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4.2.2...de0fac2e4500dabe0009e67214ff5f5447ce83dd)

Updates `actions/setup-node` from 6.3.0 to 6.4.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/53b83947a5a98c8d113130e565377fae1a50d02f...48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e)

Updates `docker/login-action` from 4.0.0 to 4.2.0
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/b45d80f862d83dbcd57f89517bcf500b2ab88fb2...650006c6eb7dba73a995cc03b0b2d7f5ca915bee)

Updates `docker/build-push-action` from 7.0.0 to 7.2.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...f9f3042f7e2789586610d6e8b85c8f03e5195baf)

Updates `chainguard-dev/setup-chainctl` from 0.5.0 to 0.5.1
- [Release notes](https://github.com/chainguard-dev/setup-chainctl/releases)
- [Commits](https://github.com/chainguard-dev/setup-chainctl/compare/c125f765e82b09a42af3185f3214465314d75c5d...2cddd35a2f120d9973e58094dc6878c93cf58c28)

Updates `anthropics/claude-code-action` from 1.0.70 to 1.0.133
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](https://github.com/anthropics/claude-code-action/compare/26ec041249acb0a944c0a47b6c0c13f05dbc5b44...787c5a0ce96a9a6cfb050ea0c8f4c05f2447c251)

Updates `github/codeql-action` from 4.32.6 to 4.36.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/0d579ffd059c29b07949a3cce3983f0780820c98...7211b7c8077ea37d8641b6271f6a365a22a5fbfa)

Updates `actions/setup-go` from 6.3.0 to 6.4.0
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](https://github.com/actions/setup-go/compare/4b73464bb391d4059bd26b0524d20df3927bd417...4a3601121dd01d1626a1e23e37211e3254c1c06c)

Updates `actions/github-script` from 7.0.1 to 9.0.0
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](https://github.com/actions/github-script/compare/60a0d83039c74a4aee543508d2ffcb1c3799cdea...3a2844b7e9c422d3c10d287c895573f7108da1b3)

Updates `actions/upload-artifact` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a)

Updates `actions/download-artifact` from 8.0.0 to 8.0.1
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3...3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c)

Updates `aws-actions/configure-aws-credentials` from 6.0.0 to 6.1.2
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws-actions/configure-aws-credentials/compare/8df5847569e6427dd6c4fb1cf565c83acfa8afa7...acca2b1b2070338fb9fd1ca27ecee81d687e58e5)

Updates `actions/cache` from 4.2.3 to 5.0.5
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/v4.2.3...27d5ce7f107fe9357f9df03efb73ab90386fccae)

Updates `tj-actions/changed-files` from 47.0.5 to 47.0.6
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](https://github.com/tj-actions/changed-files/compare/22103cc46bda19c2b464ffe86db46df6922fd323...9426d40962ed5378910ee2e21d5f8c6fcbf2dd96)

Updates `getsentry/action-release` from 3.5.0 to 3.6.0
- [Release notes](https://github.com/getsentry/action-release/releases)
- [Changelog](https://github.com/getsentry/action-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getsentry/action-release/compare/dab6548b3c03c4717878099e43782cf5be654289...5657c9e888b4e2cc85f4d29143ea4131fde4a73a)

Updates `sigstore/cosign-installer` from 4.0.0 to 4.1.2
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](https://github.com/sigstore/cosign-installer/compare/faadad0cce49287aee09b3a48701e75088a2c6ad...6f9f17788090df1f26f669e9d70d6ae9567deba6)

Updates `docker/setup-buildx-action` from 4.0.0 to 4.1.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd...d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5)

Updates `mikepenz/action-junit-report` from 6.3.1 to 6.4.1
- [Release notes](https://github.com/mikepenz/action-junit-report/releases)
- [Commits](https://github.com/mikepenz/action-junit-report/compare/49b2ca06f62aa7ef83ae6769a2179271e160d8e4...3a81627bfac62268172037048872e8ebd4207e6d)

Updates `codecov/codecov-action` from 5.5.2 to 6.0.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codecov/codecov-action/compare/671740ac38dd9b0130fbe1cec585b89eea48d3de...e79a6962e0d4c0c17b229090214935d2e33f8354)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions-updates
- dependency-name: actions/setup-node
  dependency-version: 6.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: docker/login-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: docker/build-push-action
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: chainguard-dev/setup-chainctl
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.133
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
- dependency-name: github/codeql-action
  dependency-version: 4.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: actions/setup-go
  dependency-version: 6.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: actions/github-script
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions-updates
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.1.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: actions/cache
  dependency-version: 5.0.5
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions-updates
- dependency-name: tj-actions/changed-files
  dependency-version: 47.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
- dependency-name: getsentry/action-release
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: sigstore/cosign-installer
  dependency-version: 4.1.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: mikepenz/action-junit-report
  dependency-version: 6.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: codecov/codecov-action
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-10 12:19:26 +00:00
Nuno SimõesandGitHub fb77dec493 Configure Dependabot cooldown for GitHub Actions updates (#36887) 2026-06-10 14:09:29 +02:00
Alejandro García MontoroandGitHub 2e3c0ff278 MM-69175: Fix broken CI steps (#36989)
* Fix broken migration/codegen CI self-checks

The git status self-checks in server-ci.yml became silent no-ops once
these jobs moved into the build container (#33679): the resolved shell
is sh, where the bash-only [[ ]] errors out, and git rejects the
checkout with "dubious ownership". Switch to POSIX [ ], mark the
workspace safe so git status runs, and print the diff on failure across
all affected checks.

* Regenerate stale migrations.list

The broken check-migrations step let an outdated migrations.list ship.
Regenerate it with make migrations-extract to add migration 000193.

* make mocks

* make gen-serialized

* make mmctl-docs
2026-06-10 13:54:10 +02:00
Nuno SimõesandGitHub 7ecd62ddc1 ci: invoke post-server-ci workflows via workflow_call from Server CI (#36880) 2026-06-10 11:54:21 +02:00
unified-ci-app[bot]GitHubunified-ci-app[bot] <121569378+unified-ci-app[bot]@users.noreply.github.com>Harrison HealeyMattermost Build
de0779d1bf Update latest minor version to 11.9.0 (#36976)
* Update latest minor version to 11.9.0

* Update update-versions script to include components package

* Update components package and its dependencies to 11.9.0

---------

Co-authored-by: unified-ci-app[bot] <121569378+unified-ci-app[bot]@users.noreply.github.com>
Co-authored-by: Harrison Healey <harrisonmhealey@gmail.com>
Co-authored-by: Mattermost Build <build@mattermost.com>
2026-06-10 05:43:51 +00:00
493fb0ce55 Fix Permission/Membership Policies list columns running together (#36963)
* Fix Permission/Membership Policies list columns running together

The Role and Permissions column values in the policy list views rendered
without a separator and with text hard-clipped mid-word. The cell text was
wrapped in inner .policy-name/.policy-resources divs, so the text-overflow:
ellipsis declared on the parent .DataGrid_cell never applied to the visible
text, and there was no horizontal gap between adjacent columns.

Apply overflow/ellipsis/nowrap directly to the inner value elements and add
right padding (with border-box sizing) so overflowing values truncate with an
ellipsis and stay visually separated from the next column.

Co-authored-by: mattermost-code <matty-code@mattermost.com>

* Satisfy stylelint property order in policies list styles

Co-authored-by: mattermost-code <matty-code@mattermost.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: mattermost-code <matty-code@mattermost.com>
2026-06-09 17:43:33 -04:00
Harrison HealeyandGitHub f3836530b7 MM-69003 Mostly share ESLint config between web app and E2E tests (#36767)
* Switch Cypress to use shared ESLint config

* Run --fix in Cypress

* Manually fix remaining lint issues in Cypress

* Switch Playwright to use shared ESLint config

* Run --fix in Playwright

* Manually fix remaining lint issues in Playwright

* Install and cache web app deps during Cypress CI builds

This also caches the types and client package. That isn't needed currently
since it uses prepackaged versions of those, but I imagine we might change
that at some point.

* Run e2e-tests-check when ESLint plugin is updated

* Change E2E test GHA caching to cache all of web app node_modules

* Fix mismatch between cache save and restore

* Try bumping cache keys

* Copy step to install dependencies to server.run_cypress.sh

I don't know how this must've worked before, but if this fixes the issue,
it seems like neither Cypress nor Playwright actually use the cached
depenendencies.

* Try disabling caching entirely for Cypress tests

* Try bypassing makefile?

* Try also manually building dependencies in run_specs.sh

I don't know why this appears to duplicate run_cypress.sh and
run_playwright.sh, both of which are called run_test.sh which
might not be used any more as best I can tell.

* Try installing the web app dependencies in yet another place

* Disable the extra steps in server.prepare.sh specifically for Cypress

* Revert changes to update cache key and disable web app depenedency cache on Cypress builds
2026-06-09 20:50:58 +00:00
Ben CookeandGitHub cc1547ac46 [MM-68618] Harden file removals (#36427) 2026-06-09 13:27:09 -04:00
Devin BinnieandGitHub 684ddb32a9 [MM-68988][MM-68989][MM-68990][MM-68991][MM-68997][MM-68998] Session Attributes MVF - Server-work (#36934)
* [MM-68988][MM-68989][MM-68990][MM-68991][MM-68997] Session Attributes MVF - Server-work

* PR feedback

* [MM-68998] Add web app hooks for Desktop App to signal a refresh of attributes/manifest

* Fix types

* Adjust the test to test the license first

* PR feedback

* Coderabbit feedback

* More tests
2026-06-09 13:10:53 -04:00
7ad8f71bf5 Automate schema migration release notes process (#36760)
* Create migration-automation.yml

* Create migration_automation.py

* Update migration-automation.yml

* Update migration_automation.py

* Update migration-automation.yml

* Update migration_automation.py

* Update migration-automation.yml

* Update migration_automation.py

* Update migration-automation.yml

* Update migration_automation.py

* Update migration-automation.yml

* Update migration_automation.py

* Update migration-automation.yml

* Update migration-automation.yml

---------

Co-authored-by: Mattermost Build <build@mattermost.com>
2026-06-09 12:41:42 +03:00
Felipe MartinandGitHub 755925fb73 MM-68830: Preserve unknown permissions during migrations on downgrade (#36888)
* MM-68830: Preserve unknown permissions during migrations on downgrade

A server that was upgraded to a newer release (which introduced new
permissions and wrote them into roles) and then downgraded fails fatally
at startup: the permissions migration re-saves every role, and
Role.Save() rejects any permission the older binary does not recognize,
making the downgrade unrecoverable.

Add RoleStore.SavePreservingUnknownPermissions, used only by
doPermissionsMigration, which tolerates and preserves permissions this
build does not recognize (logging a warning) instead of rejecting the
role. The regular Save() — and therefore the role API path — stays
strict, so unknown permissions cannot be introduced through user input.

Unrecognized permissions are kept on disk so they are not lost on a
later re-upgrade.

* MM-68830: assert save forwarding in role cache tests

Address review feedback: assert the underlying store's Save and
SavePreservingUnknownPermissions are actually invoked (the cache
invalidation defer fires regardless of forwarding), and check the
returned errors.

* MM-68830: address review feedback

- Shorten log message in validateForSave
- Rename validationRole -> roleCopy for clarity
- Trim doc comments to describe behavior only
- List all unknown permissions in IsValidWithoutId error
- Assert specific error type in storetest

* MM-68830: add Role.Clone and use it in validateForSave

* MM-68830: add tests for Role.Clone

* MM-68830: fix scheme id deep copy assertion in Role.Clone test
2026-06-09 11:18:19 +02:00
f6e7e71695 Migrate Zephyr manual tests to Cypress E2E (#36971)
* MM-T1814: add 'Add a BOT to a team' Cypress E2E test

Co-authored-by: Maria A Nunez <maria.nunez@mattermost.com>

* MM-T1335: invite guests to public and private channels

Extend invitePeople() helper to accept multiple channels and add a spec
verifying both a public and a private channel are added to the guest
invite list.

Co-authored-by: Maria A Nunez <maria.nunez@mattermost.com>

* MM-T1340: verify guest invite email and join flow (not_cloud)

Add a non-cloud spec covering step 2 of MM-T1340: read the invitation
email, open the join link, complete guest signup, and verify the guest
is added to the team.

Co-authored-by: Maria A Nunez <maria.nunez@mattermost.com>

* MM-T1335: assert channel chips via icons and count

Verified against a licensed E2E server: assert exactly two channel chips
with public and private channel icons rather than an exact text match,
which failed due to extra text in the chip label.

Co-authored-by: Maria A Nunez <maria.nunez@mattermost.com>

* MM-T1340: accept terms and use valid password in guest signup

Verified against a licensed E2E server: the signup Create account button
is gated on a 14+ char password and the terms/privacy checkbox. Use
newTestPassword(), check the agreement, and assert the app loads.

Co-authored-by: Maria A Nunez <maria.nunez@mattermost.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-06-09 10:33:37 +08:00
ffd4814940 MM-T3436: add Cypress E2E for Actiance XML compliance export download (#36970)
Add a Cypress test covering Zephyr case MM-T3436, verifying that with
DownloadExportResults enabled and the Actiance XML export format, a
compliance export provides a Download link and the downloaded archive
contains the posted message content and the file attachment.

Reuses existing compliance helpers (uiEnableComplianceExport,
uiExportCompliance, gotoTeamAndPostImage, downloadAndUnzipExportFile,
verifyActianceXMLFile); modeled on MM-T1173 without the delete step.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-06-09 10:23:20 +08:00
b7dda3435c Move flaky test report from PR comment to Mattermost channel (#36965)
* Move flaky test report from PR comment to Mattermost channel

Replace the github-script step that posted the flaky test summary as a PR
comment with a step that posts the summary to a Mattermost channel via a new
Mattermost incoming webhook (WEBHOOK_URL_FLAKY_TEST_MM). The HTML <table>
summary is converted to a Markdown table, with content pipes escaped and HTML
entities decoded. The existing custom flaky-test hub webhook is left untouched.

Co-authored-by: Maria A Nunez <maria.nunez@mattermost.com>

* Hoist github.server_url into SERVER_URL env var

Keep all GitHub Actions context expressions in the step's env block for
consistency, and build PR_URL purely from shell variables.

Co-authored-by: Maria A Nunez <maria.nunez@mattermost.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-06-08 15:16:46 -04:00
27b2525e88 Fix flaky TestPluginAPIGetUserPreferences (#36855)
GetPreferencesForUser returns default preferences in non-deterministic
order from Postgres (no ORDER BY in preference_store.GetAll), but the
test asserted fixed slice indices. Look up each default preference by
category instead, matching TestPluginAPIUpdateUserPreferences (#36458).

Tests-only change. Verified with go test -run '^TestPluginAPIGetUserPreferences$' -race -count=100 ./channels/app.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: mattermost-code <matty-code@mattermost.com>
2026-06-08 10:52:55 -04:00
Harrison HealeyandGitHub 20c4d8925e Add additional PluggableErrorBoundaries (#36854)
* Add error boundaries around PostOptions and NewMessageSeparator plugin components

* Add additional PluggableErrorBoundaries

* Make pluginId prop of PluggableErrorBoundary mandatory

* Remove accidentally committed change
2026-06-08 04:13:44 -07:00
Felipe MartinandGitHub ca87bd7d24 MM-60669 Prevent bot users from becoming the first system admin (#36867)
On a fresh install, the first user created in the system is granted the
system_admin role based solely on the user store being empty. Bot users
created by plugins on a fresh database could therefore be promoted to the
first system admin.

Skip the first-user system_admin promotion for bot users so that only the
first non-bot user is granted the role.
2026-06-08 12:35:15 +02:00
ff01f82043 MM-69131: Keep app__body off backstage routes to fix dark-theme styling (#36928)
* MM-69131: Keep app__body off backstage routes to fix dark-theme styling

Centralizing app__body ownership on WithUserTheme (MM-67913) made the class
persist on backstage routes (integrations, custom emoji), which render a
static light surface. Under dark themes this leaked themed colors in, making
text and form inputs illegible.

useAppBodyClass now takes the current pathname and omits app__body on
backstage routes via isBackstageRoute, while keeping it persisted across
channels, products, and plugins so the original white-flash fix still holds.

Co-authored-by: Cursor <cursoragent@cursor.com>

* MM-69131: Address theme provider review feedback

Keep backstage route detection local to the theme provider and let the app body class hook read routing context directly.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 12:37:09 -04:00
Doug LauderandGitHub b5ee857af8 MM-67616: Load synced remote member profiles so participant list refreshes (#36861)
When a remote user is synced into a shared channel, the user_added
  websocket event recorded the membership but never loaded the user's
  profile. The member list selectors drop users without a loaded profile,
  so synced members did not appear in the participant list (though they
  showed when posting). Fetch the profile on user_added when it is missing.
2026-06-05 12:08:05 -04:00
Harrison HealeyandGitHub 01892e9d06 MM-69132 Migrate DynamicVirtualizedList to TypeScript (#36923)
* Rename innerRefWidth to _innerRefWidth

* Remove duplicate scrollToFailed prop

* Remove unused style prop from children callback

* Explicitly type listData

* Explicitly type return value of initScrollToIndex

* Inline outerTagName and innerTagName props to simplify typing

* Null check usage of _outerRef

* Replace _innerRefWidth with _innerRef and typing of innerRef

* Replace Object.prototype.hasOwnProperty.call with Object.hasOwn

* Remove unused visibleId prop

This was originally added in
https://github.com/mattermost/dynamic-virtualized-list/pull/29, but we
never ended up using it.

* Stop making type of listData generic

* Migrate DynamicVirtualizedList to TS
2026-06-05 11:40:05 -04:00
Takuya NandGitHub 1fc2824e58 chore(webapp): remove orphaned @types/react-custom-scrollbars (#36818)
Follows up PR 33783

The `@types/react-custom-scrollbars` devDependency provides types for the
`react-custom-scrollbars` runtime package, but that package is no longer a
dependency of any webapp workspace and is not imported anywhere in
webapp/channels (scrollbars now use simplebar-react) after PR 33783.
The type definitions are therefore dead.

Remove it from webapp/channels/package.json and prune its entries from
webapp/package-lock.json (the channels devDep reference and the
node_modules/@types/react-custom-scrollbars package block). It has no
dependents in the lockfile, so no other entries are affected.

Signed-off-by: Takuya Noguchi <takninnovationresearch@gmail.com>
2026-06-05 14:48:22 +00:00
Ben CookeandGitHub 3440453d82 [MM-68425] Update marked (#36710) 2026-06-04 14:44:10 -04:00
b4fcb47201 Remove agent-browser skill and lockfile (#36930)
* Remove agent-browser skill and lockfile

The computerUse subagent now provides a full desktop with Chrome, making
the bespoke agent-browser skill obsolete.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Remove agent-browser install and docs from cloud env

Drop the agent-browser CLI/headless-Chrome install, skip flag, and docs
from the Cursor Cloud Agent Dockerfile, install hook, and notes. Keep the
AWS CLI and the Playwright e2e runtime libraries.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 14:04:05 -04:00
Nuno SimõesandGitHub 56015e8b87 ci: use variables in shell for workflows (#36904) 2026-06-04 19:52:53 +02:00
Nuno SimõesandGitHub 4245b69744 Pass explicit secrets to reusable server CI workflows (#36896) 2026-06-04 19:42:32 +02:00
Nuno SimõesandGitHub 3af36e0a49 ci: scope GitHub Actions workflows (#36890)
* Scope GitHub Actions workflow and job permissions

* Fix workflow permissions gaps from least-privilege scoping
2026-06-04 19:40:30 +02:00
Devin BinnieandGitHub 3fc5b94292 [MM-69115] Fixed issue where channels could end up in two categories (#36875)
* [MM-69115] Fixed issue where channels could end up in two categories

* Additional fix

* PR feedback
2026-06-04 13:22:59 +00:00
M-ZubairAhmedandGitHub ca19b0b834 Remove dynamic-virtualized-list from ignoreDependencies in config.yaml (#36897) 2026-06-04 09:14:20 -04:00
85dae1b884 MM-68417, MM-68420: API support for PAT expiry and admin policy settings (#36706)
* MM-68417, MM-68420: API support for PAT expiry and admin policy settings

POST /users/{id}/tokens now accepts a client-supplied expires_at
(previously stripped per the TODO in api4/user.go), and the create app
method enforces two new ServiceSettings:

  - EnforcePersonalAccessTokenExpiry (bool, default false): when on,
    rejects creates with expires_at == 0
  - MaximumPersonalAccessTokenLifetimeDays (int, default 0 = unlimited):
    caps how far in the future expires_at may be

Rejections return distinct app error ids so clients can disambiguate:
expires_at_required, expires_at_in_past, expires_at_too_far.

GET /users/{id}/tokens already serializes expires_at via the model's
JSON tag added in MM-68419; clients derive token status (active /
expired / inactive) from is_active + expires_at without a separate
server-side field, keeping the response shape minimal.

The Client4 helper CreateUserAccessToken gained an optional variadic
expiresAt parameter (and the mmctl Client interface + mock match)
rather than introducing a parallel WithExpiry method.

Refs: MM-68417, MM-68420

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* MM-68417: exempt bot accounts from PAT expiry enforcement

Mirrors the existing EnableUserAccessTokens bypass at session.go:453,
where bot tokens are allowed even when human PATs are disabled. Bots
are programmatic clients that typically need long-lived credentials,
and integrations that provision them would otherwise break the moment
an admin enables EnforcePersonalAccessTokenExpiry — turning a settings
toggle into a footgun. The expiry policy now applies only to human
users; bots can still be given a future expires_at by callers that
want it, but the server won't require one.

Locked in by a new TestCreateUserAccessToken/bot_tokens_are_exempt
subtest that enables enforcement plus a 30-day cap, creates a bot,
and asserts a non-expiring token is accepted.

Refs: MM-68417

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* MM-68420: bound MaximumPersonalAccessTokenLifetimeDays in isValid

Negative values silently meant "unlimited" (the runtime check is `> 0`),
and very large values overflow int64 when computing
`now + days*86_400_000` at token-creation time, producing a wrap-around
that either rejects all reasonable expiries or accepts past timestamps
as valid.

Bound the setting in ServiceSettings.isValid to [0, MaxPersonalAccess
TokenLifetimeDays] where the cap is 36500 (100 years) — past any
realistic operational use and well clear of int64 overflow. Surfaces
as a config validation error rather than a silently-broken runtime
check. New TestServiceSettingsIsValid cases lock in zero, negative,
upper-bound, and above-upper-bound behavior.

Refs: MM-68420

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* MM-68417: reject multiple expiresAt values in Client4 helper

CodeRabbit caught that the variadic CreateUserAccessToken silently used
expiresAt[0] when callers passed more than one value, masking a
mis-call instead of failing fast. Return an error in that case so the
misuse is visible at the call site rather than producing a token with
the wrong (or right-but-coincidental) expiry.

Refs: MM-68417

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* MM-68417: make expiresAt a required parameter on Client4.CreateUserAccessToken

Drop the variadic in favor of a regular int64 parameter. The variadic
form silently dropped extra values and made a misuse undetectable at
the call site (per CodeRabbit review on PR 36706); the previous fix
guarded against >1 values at runtime, but a required parameter is
strictly better — the compiler now refuses the misuse and every caller
is forced to make a deliberate decision about expiry. Existing callers
that want the old behavior pass 0 (== never expires).

Refs: MM-68417

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* MM-68417: add --expires-in flag to mmctl user token generate

Adds an --expires-in duration flag so operators can create expiring
PATs via the CLI. Accepts the standard Go duration syntax plus a
trailing 'd' for days (the common case for token lifetimes), e.g.
--expires-in 90d, --expires-in 12h, --expires-in 1h30m. Empty (the
default) means no expiry — matching prior behavior. Without this
flag the command was unusable once an admin enables
EnforcePersonalAccessTokenExpiry, since every create would fail with
app.user_access_token.expires_at_required.app_error.

Flag parsing now happens before the user-lookup API call so the
command fails fast on invalid input. Regenerated mmctl docs reflect
the new flag.

Refs: MM-68417

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* MM-68417: cap --expires-in day count to prevent time.Duration overflow

parseExpiresIn returns time.Duration(days) * 24 * time.Hour, which is
int64 nanoseconds and overflows past ~106751 days (CodeRabbit caught
this). Cap at model.MaxPersonalAccessTokenLifetimeDays (36500) so the
CLI rejects values the server would reject anyway, well below the
int64-overflow point. Adds two test cases (at-cap and beyond-cap) to
TestParseExpiresIn.

Refs: MM-68417

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* MM-68420: collapse PAT expiry settings into a single max-lifetime setting

Remove ServiceSettings.EnforcePersonalAccessTokenExpiry and fold the
policy onto MaximumPersonalAccessTokenLifetimeDays: 0 means no policy
(never-expiring tokens allowed, no cap), while a value > 0 requires every
new token to expire within that many days. The two-setting design let an
admin set a maximum but leave enforcement off, silently allowing
never-expiring tokens to sidestep the cap; the only combination the
boolean added (require expiry, no upper bound) has little practical
value. The removed field was introduced on this branch and never
released, so this is not a breaking change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-06-04 14:21:35 +02:00
aa03fae744 [MM-69026] Add zoom and pan to the image file preview (#36775)
* [MM-69026] Add zoom and pan to the image file preview

Enables the existing file-preview-modal zoom controls for image previews
(previously PDF-only) and adds cursor-aware wheel zoom, drag-to-pan,
keyboard shortcuts, and overflow clipping so the panned image can't
escape behind the modal header.

- Per-file default scale (1.0 for images, 1.75 stays for PDFs).
- Translate state alongside scale; auto-snaps to the origin at default scale.
- Native non-passive wheel listener so preventDefault actually fires.
- Wheel step scaled by deltaY magnitude for trackpad pinch.
- Keyboard: +/=, -, 0; skipped when an input/textarea/contentEditable is focused.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Fix eslint no-mixed-operators and lines-around-comment

Parenthesise mixed +/* and -/ arithmetic to satisfy
eslint(no-mixed-operators) and add the blank line before the
inline-input guard comment for lines-around-comment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Cap image zoom at 2x and harden lifecycle / drag-pan

- Add ZoomSettings.MAX_SCALE_IMAGE = 2.0 and route image-path clamp
  sites through a new FilePreviewModal.getMaxScaleForFile. PDFs keep
  the original 3.0 ceiling.
- Reconcile scale/translate in getDerivedStateFromProps when
  props.fileInfos changes so newly appearing indexes get seeded with
  the file's default instead of reading as undefined.
- Gate drag-to-pan on currentScale > defaultScale so dragging at
  default scale (image fits the viewport) doesn't slide the image
  around in empty space.
- Tighten the e2e style-match regex so it only accepts scale values
  strictly greater than 1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Reset image zoom state on same-length file swaps

A websocket post update can replace an attachment at the same index
without changing the array length, which previously bypassed the
length-based reconciliation in getDerivedStateFromProps and let the
old file's zoom/translate state apply to the new file.

Track a per-index identity (file id, falling back to link) and trigger
the same reconciliation when any identity differs at its index;
indexes whose identity is unchanged keep their existing scale/translate.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add unit tests for zoom-related instance behavior and helpers

Covers the gaps flagged by Tests/analysis:

- Static helpers getDefaultScaleForFile, getMaxScaleForFile, and
  getFileIdentity (incl. namespace separation for file vs link
  identities).
- handleKeyDown: +/= zoom in, - zoom out, 0 reset, modifier-key
  bailout, and the INPUT-focus guard.
- handleImageMouseDown drag gate: ignored at default scale and on
  non-left-button mousedowns; sets isDragging when zoomed.
- handleImageWheel clamping at MAX_SCALE_IMAGE (2.0) and MIN_SCALE
  (0.25), plus deltaY=0 short-circuit.
- getDerivedStateFromProps identity reconciliation: same-length swap
  resets the affected index while preserving others; list growth
  seeds the new index with the file's default.

68 tests pass (was 50).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-06-04 11:45:00 +02:00
Nuno SimõesandGitHub 563e1a951d ci: standardize checkout action inputs across workflows (#36876)
* ci: standardize checkout action inputs across workflows

* ci: checkout in claude pipeline use default
2026-06-04 09:01:22 +02:00
fb8cfbaef7 Fix flaky TestSharedChannelPostMetadataSync (#36862)
* Fix flaky TestSharedChannelPostMetadataSync

STEP 6 incorrectly required Cluster A to receive sync traffic after a
resync trigger. When echo prevention suppresses unchanged acknowledgement
payloads, no message arrives and the Eventually timeout fails. Wait for
pending sync tasks, assert the DB still has exactly one acknowledgement,
and only validate sync payload duplicates when traffic is received.

Tests-only change. Verified with `go test -run '^TestSharedChannelPostMetadataSync$' -race -count=50` locally.

Co-authored-by: mattermost-code <matty-code@mattermost.com>

* Assert sync payload ack count outside muA lock

Copy the matching post under muA before calling require.Len so a
failed assertion cannot leave the mutex locked and hang teardown.

Co-authored-by: mattermost-code <matty-code@mattermost.com>

* Retrigger CI after Playwright infra flake

Co-authored-by: mattermost-code <matty-code@mattermost.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: mattermost-code <matty-code@mattermost.com>
2026-06-03 12:15:45 -04:00
Devin BinnieandGitHub 50952dec3f [MM-68648] Implement GetForGroup to get fields in the Property System, add caching for fields (#36836)
* [MM-68648] Implement GetForGroup to get fields in the Property System, add caching for fields

* Re-add CRUD functions for the cache to invalidate when updates happen
2026-06-03 10:39:53 -04:00
61643e1066 MM-68952: Resolve public channel mentions for non-members under Compliance (#36815)
* MM-68952: Resolve public channel mentions for non-members under Compliance

Channel mention name resolution reused HasPermissionToReadChannel, a
content-read check that returns false for non-members of a public channel
when Compliance Monitoring is enabled (MM-45272) or when the channel is on
another team (MM-66791). As a result, the channel_mentions post prop was
stripped per-viewer (since #34235), and the webapp fell back to rendering the
raw (anonymized) channel slug instead of a clickable link.

Introduce HasPermissionToResolveChannelMention, which exposes only a public
channel display name and link (not content) and is therefore independent of
ComplianceSettings, while still requiring team membership for public channels
(blocks cross-team disclosure) and channel membership for private/DM/GM
channels. Switch the three mention call sites (FillInPostProps,
sanitizeChannelMentionsForUser, channelMentionsBroadcastHook) to the new
helper. HasPermissionToReadChannel and all content-read paths are unchanged.

Co-authored-by: Cursor <cursoragent@cursor.com>

* MM-68952: Add author-side and E2E coverage for channel mention resolution

Add a Go test (TestFillInPostPropsChannelMentionResolution) that exercises the
author-side persistence of the channel_mentions prop in FillInPostProps. It
locks in the new behavior: an author who is a team member but not a member of a
referenced public channel now persists the mention prop even when Compliance
Monitoring is enabled, while public channels on other teams and private
channels the author is not in are still dropped.

Add a Playwright spec (channel_mention_resolution.spec.ts) with a license-free
cross-team case (a public channel mention stays unresolved for a viewer not on
the channel's team) and a license-gated case (with Compliance enabled, a team
member who is not in the channel sees the resolved mention link).

Co-authored-by: Cursor <cursoragent@cursor.com>

* MM-68952: Tighten channel mention test assertions and fix lint

Use strings.Builder when assembling the test message to avoid the
golangci-lint stringsbuilder (modernize) warning about string += string
in a loop. Tighten the cross-team public and private non-member cases to
assert.Nil on the resolved mentions so the contract requires no persisted
channel_mentions map rather than merely an empty one.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-03 08:42:39 -04:00
6dac3b9df4 Harden post action request verification (#36840)
* MM-69065 - Authorize post actions against the target post's channel

Require a supplied action cookie to belong to the post named in the request so the authorized channel always matches the channel where the action runs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Rename test client variable to nonMember

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-03 08:41:01 -04:00
ab31663fce MM-69010: Validate incoming webhook user membership (#36811)
* MM-69010: Validate incoming webhook user membership

Incoming webhook creation/update did not verify that the assigned
user_id had legitimate access to the target team or channel, allowing a
team admin to attribute persisted posts to an arbitrary user.

Validate that the assigned user can read the target channel and does not
hold privileges the requester lacks at creation, re-check channel access
when a hook is moved, and require a shared team before a webhook creates
a direct message via an @username payload.

Co-authored-by: Cursor <cursoragent@cursor.com>

* MM-69010: Add regression test for owner+channel update

Verify that changing both the channel and the supplied user_id in a
single update still validates against the retained owner, since the
owner is immutable on update.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Mattermost Build <build@mattermost.com>
2026-06-02 20:26:42 -04:00
1e0bdaf068 MM-69057: Verify post ownership on inbound shared-channel edit/delete (#36814)
The inbound shared-channel sync handler applied edits and deletes from a
remote cluster without checking that the existing post belonged to that
remote, allowing a remote to modify or delete posts it did not own.

Enforce the same ownership check already used for reactions and
acknowledgements before editing or deleting a synced post, and add
regression tests for the cross-remote cases.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-02 16:11:55 -04:00
Julien TantandGitHub 6ef5d58b7f Board channel bookmarks with target_id and readonly bookmark API (#36572)
Automatic Merge
2026-06-02 21:24:05 +02:00
9d27c06085 Restrict group_constrained to channels that support group sync (#36812)
* Restrict group_constrained to channels that support group sync

Enforce that the group_constrained flag can only be applied to public
and private channels across the API handler, model validation, and the
membership cleanup query.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Reject group_constrained on board channels

Extend validation to board channel types (BO/BP) in model, API patch,
and group member cleanup query. Add SupportsGroupSync helper.

Co-authored-by: mattermost-code <matty-code@mattermost.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: mattermost-code <matty-code@mattermost.com>
2026-06-02 14:17:12 -04:00
Alejandro García MontoroandGitHub 8e8b807a42 MM-68665: Implement FileBackendWithLinkGenerator for Azure (SAS for export downloads) (#36758)
* Implement FileBackendWithLinkGenerator for Azure (SAS for export downloads)

Restores feature parity with the S3 driver for the optional presigned
export-download path. Today on Azure-backed deployments the path falls
through with "driver doesn't support link generation"; with this change
admins can opt into direct downloads of bulk export archives just like
they can on S3.

Auth-mode aware:

* Shared key signs a Service SAS in process with the credential the
  backend was constructed with.
* Default credential fetches a user-delegation key from Entra ID per
  call and signs a user-delegation SAS with it.

The link forces Content-Disposition: attachment to mirror the S3
driver's response-content-disposition behavior, and pins HTTPS-only when
the backend was configured with TLS so the SAS cannot be exfiltrated
over plaintext. Plaintext setups (Azurite, on-prem reverse proxies) keep
working because we fall back to allowing both schemes.

Adds ExportAzurePresignExpiresSeconds to FileSettings, defaulting to
21600 seconds (6h), to match the S3 export presign field. The primary
backend never issues SAS, so no AzurePresignExpiresSeconds.

Covered by new unit tests against Azurite (Service SAS round trip,
tamper detection, missing configuration, unknown auth mode). The user-
delegation SAS path needs Entra ID and is verified manually per the
recipe in the docs PR.

------
AI assisted commit

* Rename GeneratePublicLink's argument p to path

* Improve comment on AzureFileBackend.sharedKey

* Simplify the clock skew fix

* Remove MaxAzurePresignExpiresSeconds
2026-06-02 14:29:58 +00:00
127552ce84 Add user setting to disable auto-follow on channel-wide mentions (#36068)
* Add server config to disable auto-follow on channel-wide mentions

Adds `ServiceSettings.ChannelMentionAutoFollowThreads` (default: true)
which, when disabled, prevents @channel/@here/@all mentions in thread
replies from automatically adding users as thread followers. Users still
receive mention notifications; only the thread membership is skipped.

* Refactor: move channel-mention auto-follow to per-user notification setting

Replaces the server-level ServiceSettings.ChannelMentionAutoFollowThreads
config with a per-user notification preference
channel_mention_auto_follow_threads (default: true).

Users can now opt out individually via Notification Settings ->
"Auto-follow threads on channel-wide mentions" (placed above
"Keywords that trigger notifications"), without requiring admin
intervention. Behavior is unchanged for users who have not modified the
setting.

* Add additional test case

* linter fixes and webapp snapshot update

* update user setting description

* em dash removed in description

* Update E2E tests

* prettier:fix

---------

Co-authored-by: gtsaturyan <gtsaturyan@ozon.ru>
Co-authored-by: Harrison Healey <harrisonmhealey@gmail.com>
2026-06-02 09:11:59 -04:00
Ibrahim Serdar AcikgozandGitHub 1b3dc63784 [MM-69078] Surface plugin upload rejections as a toast (parity with download rejections) (#36838)
* Surface plugin upload rejections as a toast (parity with download rejections)

* add some tests
2026-06-02 12:16:35 +02:00
Harshil SharmaandGitHub 6c401066f7 Deleted removed post from content flagging redux store (#36803)
* DEleted removed post from content flagging redux store

* Create a separate action
2026-06-02 14:18:25 +05:30
19e7a2be28 Fix flaky TestCheckUsersEmojiIntegrity (#36756)
* Fix flaky TestCheckUsersEmojiIntegrity

Integrity checks scan the full database for orphaned emoji rows, so
parallel sqlstore tests and leftover rows from sibling tests can inflate
global record counts and flip index-based assertions.

Reset tables at test start and scope the one-record assertion to the
emoji child ID created in that subtest.

Tests-only change. Verified compilation locally; full test loop requires
PostgreSQL (CI).

Co-authored-by: mattermost-code <matty-code@mattermost.com>

* ci: nudge CodeRabbit after all checks green

Co-authored-by: mattermost-code <matty-code@mattermost.com>

* Address PR feedback: 1 items resolved, 0 declined

* Use t.Cleanup with require.NoError for emoji test fixture cleanup

Replace silent defer dbmap.Exec cleanup calls with t.Cleanup handlers
that assert on errors, addressing CodeRabbit review feedback.

Co-authored-by: mattermost-code <matty-code@mattermost.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: mattermost-code <matty-code@mattermost.com>
2026-06-02 14:11:15 +05:30
Harrison HealeyandGitHub a84032f40a MM-69053 Log server message when a user has concurrent React enabled (#36837)
* MM-69053 Log server message when a user has concurrent React enabled

* Add session_id and user_id to server-logged messages sent by the client

* Fix linting

* Fix test
2026-06-02 05:43:55 +00:00
5c360d8077 MM-68995: reject deactivated guests on REST magic-link login (#36746)
Apply CheckUserAllAuthenticationCriteria after guest magic-link token
authentication in POST /api/v4/users/login, matching the web one-time-link
handler and password login paths.

Add regression test ensuring deactivated guests receive 401 inactive while
active guests can still log in via magic_link_token.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Julien Tant <JulienTant@users.noreply.github.com>
2026-06-01 16:33:24 -07:00
Harrison HealeyandGitHub e9f62a6639 MM-69003 Replace eslint-plugin-header with eslint-plugin-headers (#36766)
* MM-69003 Replace eslint-plugin-header with eslint-plugin-headers

* Run prettier --fix

* Fix early merge

* Update ESLint plugin version in package-lock.json
2026-06-01 14:29:38 -04:00
Harrison HealeyandGitHub a57695daa3 MM-69002 Convert ESLint configs to flat config (#36750)
* MM-68153 Migrate all ESLint configuration to flat config files

* Use shared ESLint plugin and ESLint configuration to lint shared ESLint plugin and ESLint configuration as well as non-shared ESLint configuration
2026-06-01 12:03:05 -04:00
ea6ac3f229 MM-68983: Tighten OAuth token issuance and cleanup on user deactivation (#36743)
Reject OAuth grants for users with DeleteAt != 0 across the
implicit, authorization code, and refresh token paths, and purge
stored OAuth access data for the user during deactivation.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 11:58:17 -04:00
Christopher PoileandGitHub da48051967 Upgrade "@mattermost/compass-icons" to 0.1.61 (#36831)
This is the first compass-icons version to actually reach the npm registry
since 0.1.53. Releases 0.1.54-0.1.60 all failed the publish.yml workflow
after trusted publishing was introduced; 0.1.61 adds the package.json
repository field needed for sigstore provenance validation.

Brings in shield-lock-outline, shield-check, file-help-outline-large, and
other icons added upstream between 2026-01 and 2026-06.
2026-06-01 11:42:26 -04:00