web: decompose nav bar into editable units - #16930
Open
kensternberg-authentik wants to merge 89 commits into
Open
web: decompose nav bar into editable units#16930kensternberg-authentik wants to merge 89 commits into
kensternberg-authentik wants to merge 89 commits into
Conversation
## What
- Bugfix: adds the InvalidationFlow to the Radius Provider dialogues
- Repairs: `{"invalidation_flow":["This field is required."]}` message, which was *not* propagated
to the Notification.
- Nitpick: Pretties `?foo=${true}` expressions: `s/\?([^=]+)=\$\{true\}/\1/`
## Note
Yes, I know I'm going to have to do more magic when we harmonize the forms, and no, I didn't add the
Property Mappings to the wizard, and yes, I know I'm going to have pain with the *new* version of
the wizard. But this is a serious bug; you can't make Radius servers with *either* of the current
dialogues at the moment.
* main: (43 commits) core, web: update translations (#11858) web/admin: fix code-based MFA toggle not working in wizard (#11854) sources/kerberos: add kiprop to ignored system principals (#11852) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh_CN (#11846) translate: Updates for file locale/en/LC_MESSAGES/django.po in it (#11845) translate: Updates for file web/xliff/en.xlf in zh_CN (#11847) translate: Updates for file web/xliff/en.xlf in zh-Hans (#11848) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh-Hans (#11849) translate: Updates for file web/xliff/en.xlf in it (#11850) website: 2024.10 Release Notes (#11839) translate: Updates for file web/xliff/en.xlf in zh-Hans (#11814) core, web: update translations (#11821) core: bump goauthentik.io/api/v3 from 3.2024083.13 to 3.2024083.14 (#11830) core: bump service-identity from 24.1.0 to 24.2.0 (#11831) core: bump twilio from 9.3.5 to 9.3.6 (#11832) core: bump pytest-randomly from 3.15.0 to 3.16.0 (#11833) website/docs: Update social-logins github (#11822) website/docs: remove � (#11823) lifecycle: fix kdc5-config missing (#11826) website/docs: update preview status of different features (#11817) ...
* main: website: bump elliptic from 6.5.7 to 6.6.0 in /website (#11869) core: bump selenium from 4.25.0 to 4.26.0 (#11875) core: bump goauthentik.io/api/v3 from 3.2024083.14 to 3.2024100.1 (#11876) website/docs: add info about invalidation flow, default flows in general (#11800) website: fix docs redirect (#11873) website: remove RC disclaimer for version 2024.10 (#11871) website: update supported versions (#11841) web: bump API Client version (#11870) root: backport version bump 2024.10.0 (#11868) website/docs: 2024.8.4 release notes (#11862) web/admin: provide default invalidation flows for LDAP and Radius (#11861)
* main: core: add `None` check to a device's `extra_description` (#11904) providers/oauth2: fix size limited index for tokens (#11879) web: fix missing status code on failed build (#11903) website: bump docusaurus-theme-openapi-docs from 4.1.0 to 4.2.0 in /website (#11897) translate: Updates for file locale/en/LC_MESSAGES/django.po in de (#11891) stages/authenticator_webauthn: Update FIDO MDS3 & Passkey aaguid blobs (#11884) translate: Updates for file web/xliff/en.xlf in tr (#11878) translate: Updates for file locale/en/LC_MESSAGES/django.po in tr (#11866) core: bump google-api-python-client from 2.149.0 to 2.151.0 (#11885) core: bump selenium from 4.26.0 to 4.26.1 (#11886) core, web: update translations (#11896) website: bump docusaurus-plugin-openapi-docs from 4.1.0 to 4.2.0 in /website (#11898) core: bump watchdog from 5.0.3 to 6.0.0 (#11899) core: bump ruff from 0.7.1 to 0.7.2 (#11900) core: bump django-pglock from 1.6.2 to 1.7.0 (#11901) website/docs: fix release notes to say Federation (#11889)
* main: website/docs: fix slug matching redirect URI causing broken refresh (#11950) website/integrations: jellyfin: update plugin catalog location (#11948) translate: Updates for file locale/en/LC_MESSAGES/django.po in de (#11942) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh_CN (#11946) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh-Hans (#11947) website/docs: clarify traefik ingress setup (#11938) core: bump importlib-metadata from 8.4.0 to 8.5.0 (#11934) web: bump API Client version (#11930) root: backport version bump `2024.10.1` (#11929) website/docs: `2024.10.1` Release Notes (#11926) website: bump path-to-regexp from 1.8.0 to 1.9.0 in /website (#11924) core: bump sentry-sdk from 2.17.0 to 2.18.0 (#11918) website: bump the docusaurus group in /website with 9 updates (#11917) core: bump goauthentik.io/api/v3 from 3.2024100.1 to 3.2024100.2 (#11915) core, web: update translations (#11914)
* main: ci: fix dockerfile warning (#11956)
* main: (21 commits) web: bump API Client version (#11997) sources/kerberos: use new python-kadmin implementation (#11932) core: add ability to provide reason for impersonation (#11951) website/integrations: update vcenter integration docs (#11768) core, web: update translations (#11995) website: bump postcss from 8.4.48 to 8.4.49 in /website (#11996) web: bump API Client version (#11992) blueprints: add default Password policy (#11793) stages/captcha: Run interactive captcha in Frame (#11857) core, web: update translations (#11979) core: bump packaging from 24.1 to 24.2 (#11985) core: bump ruff from 0.7.2 to 0.7.3 (#11986) core: bump msgraph-sdk from 1.11.0 to 1.12.0 (#11987) website: bump the docusaurus group in /website with 9 updates (#11988) website: bump postcss from 8.4.47 to 8.4.48 in /website (#11989) stages/password: use recovery flow from brand (#11953) core: bump golang.org/x/sync from 0.8.0 to 0.9.0 (#11962) web: bump cookie, swagger-client and express in /web (#11966) core, web: update translations (#11959) core: bump debugpy from 1.8.7 to 1.8.8 (#11961) ...
* main: providers/ldap: fix global search_full_directory permission not being sufficient (#12028) website/docs: 2024.10.2 release notes (#12025) lifecycle: fix ak exit status not being passed (#12024) core: use versioned_script for path only (#12003) core, web: update translations (#12020) core: bump google-api-python-client from 2.152.0 to 2.153.0 (#12021) providers/oauth2: fix manual device code entry (#12017) crypto: validate that generated certificate's name is unique (#12015) core, web: update translations (#12006) core: bump google-api-python-client from 2.151.0 to 2.152.0 (#12007) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh-Hans (#12011) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh_CN (#12010) translate: Updates for file web/xliff/en.xlf in zh-Hans (#12012) translate: Updates for file web/xliff/en.xlf in zh_CN (#12013) providers/proxy: fix Issuer when AUTHENTIK_HOST_BROWSER is set (#11968) website/docs: move S3 ad GeoIP to System Management/Operations (#11998) website/integrations: nextcloud: add SSE warning (#11976)
* main: translate: Updates for file locale/en/LC_MESSAGES/django.po in zh-Hans (#12045) translate: Updates for file web/xliff/en.xlf in zh_CN (#12047) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh_CN (#12044) translate: Updates for file web/xliff/en.xlf in zh-Hans (#12046) web/flows: fix invisible captcha call (#12048) rbac: fix incorrect object_description for object-level permissions (#12029) stages/authenticator_webauthn: Update FIDO MDS3 & Passkey aaguid blobs (#12036) core: bump coverage from 7.6.4 to 7.6.5 (#12037) ci: bump codecov/codecov-action from 4 to 5 (#12038) release: 2024.10.2 (#12031)
* main: (28 commits) providers/scim: accept string and int for SCIM IDs (#12093) website: bump the docusaurus group in /website with 9 updates (#12086) core: fix source_flow_manager throwing error when authenticated user attempts to re-authenticate with existing link (#12080) translate: Updates for file locale/en/LC_MESSAGES/django.po in de (#12079) scripts: remove read_replicas from generated dev config (#12078) core: bump geoip2 from 4.8.0 to 4.8.1 (#12071) core: bump goauthentik.io/api/v3 from 3.2024100.2 to 3.2024102.2 (#12072) core: bump maxmind/geoipupdate from v7.0.1 to v7.1.0 (#12073) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh_CN (#12074) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh-Hans (#12075) translate: Updates for file web/xliff/en.xlf in zh-Hans (#12076) translate: Updates for file web/xliff/en.xlf in zh_CN (#12077) web/admin: auto-prefill user path for new users based on selected path (#12070) core: bump aiohttp from 3.10.2 to 3.10.11 (#12069) web/admin: fix brand title not respected in application list (#12068) core: bump pyjwt from 2.9.0 to 2.10.0 (#12063) web: add italian locale (#11958) web/admin: better footer links (#12004) core, web: update translations (#12052) core: bump twilio from 9.3.6 to 9.3.7 (#12061) ...
* main: (33 commits) ci: mirror repo to internal repo (#12160) core: bump goauthentik.io/api/v3 from 3.2024102.2 to 3.2024104.1 (#12149) core: bump debugpy from 1.8.8 to 1.8.9 (#12150) core: bump webauthn from 2.2.0 to 2.3.0 (#12151) core: bump pydantic from 2.10.0 to 2.10.1 (#12152) translate: Updates for file web/xliff/en.xlf in zh_CN (#12156) translate: Updates for file web/xliff/en.xlf in zh-Hans (#12157) core: bump sentry-sdk from 2.18.0 to 2.19.0 (#12153) web: bump API Client version (#12147) root: Backport version change (#12146) website/docs: update info about footer links to match new UI (#12120) website/docs: prepare release notes (#12142) providers/oauth2: fix migration (#12138) providers/oauth2: fix migration dependencies (#12123) web: bump API Client version (#12129) providers/oauth2: fix redirect uri input (#12122) providers/proxy: fix redirect_uri (#12121) website/docs: prepare release notes (#12119) web: bump API Client version (#12118) security: fix CVE 2024 52289 (#12113) ...
* main: ci: only mirror if secret is available (#12181) root: fix database ssl options not set correctly (#12180) core, web: update translations (#12145) core: bump tornado from 6.4.1 to 6.4.2 (#12165) website: bump the docusaurus group in /website with 9 updates (#12172) website: bump typescript from 5.6.3 to 5.7.2 in /website (#12173) ci: bump actions/checkout from 3 to 4 (#12174) core: bump github.com/stretchr/testify from 1.9.0 to 1.10.0 (#12175) core: bump coverage from 7.6.7 to 7.6.8 (#12176) core: bump ruff from 0.7.4 to 0.8.0 (#12177)
* main: website/docs: Fix CSP syntax (#12124)
* main: website/docs: Add note about single group per role (#12169) website/docs: Fix documentation about attribute merging for indirect membership (#12168) root: support running authentik in subpath (#8675) docs: fix contribution link (#12189) core, web: update translations (#12190) core: Bump msgraph-sdk from 1.12.0 to 1.13.0 (#12191) core: Bump selenium from 4.26.1 to 4.27.0 (#12192)
* main: (31 commits) web/admin: bugfix: dual select initialization revision (#12051) web: update tests for Chromedriver 131 (#12199) website/integrations: add Aruba Orchestrator (#12220) core: bump aws-cdk-lib from 2.167.1 to 2.171.1 (#12237) website: bump aws-cdk from 2.167.1 to 2.171.1 in /website (#12241) core, web: update translations (#12236) core: bump python-kadmin-rs from 0.2.0 to 0.3.0 (#12238) core: bump pytest from 8.3.3 to 8.3.4 (#12239) core: bump drf-spectacular from 0.27.2 to 0.28.0 (#12240) core, web: update translations (#12222) core: Bump ruff from 0.8.0 to 0.8.1 (#12224) core: Bump ua-parser from 0.18.0 to 1.0.0 (#12225) core: Bump msgraph-sdk from 1.13.0 to 1.14.0 (#12226) stages/authenticator_webauthn: Update FIDO MDS3 & Passkey aaguid blobs (#12234) website/docs: install: add aws (#12082) core: Bump pyjwt from 2.10.0 to 2.10.1 (#12217) core: Bump fido2 from 1.1.3 to 1.2.0 (#12218) core: Bump cryptography from 43.0.3 to 44.0.0 (#12219) providers/oauth2: allow m2m for JWKS without alg in keys (#12196) translate: Updates for file locale/en/LC_MESSAGES/django.po in fr (#12210) ...
* main: web: simplify `?inline` handler for Storybook (#12246) website/docs: Update Traefik middleware example to reflect latest version of Traefik (#12267) website/docs: add . in https://netbird.company* (#12166) core: bump goauthentik.io/api/v3 from 3.2024104.1 to 3.2024104.2 (#12263) core: bump pydantic from 2.10.2 to 2.10.3 (#12262) core: bump github.com/getsentry/sentry-go from 0.29.1 to 0.30.0 (#12264) core, web: update translations (#12268) website: bump @types/react from 18.3.12 to 18.3.13 in /website (#12269) website: bump prettier from 3.4.1 to 3.4.2 in /website (#12270) ci: bump actions/attest-build-provenance from 1 to 2 (#12271) core: bump golang.org/x/sync from 0.9.0 to 0.10.0 (#12272) core: bump django from 5.0.9 to 5.0.10 (#12273) core: bump webauthn from 2.3.0 to 2.4.0 (#12274) website/integrations: add The Lounge (#11971) core: bump python-kadmin-rs from 0.3.0 to 0.4.0 (#12257) root: fix health status code (#12255) ci: fix should_push always being false (#12252) web: bump API Client version (#12251) providers/oauth2: Add provider federation between OAuth2 Providers (#12083) website/integrations: mastodon: set correct uid field (#11945)
* main: website/docs: add page about the Cobalt pentest (#12249) core: bump aws-cdk-lib from 2.171.1 to 2.172.0 (#12296) website: bump aws-cdk from 2.171.1 to 2.172.0 in /website (#12295) core: bump sentry-sdk from 2.19.1 to 2.19.2 (#12297) core: bump coverage from 7.6.8 to 7.6.9 (#12299) core, web: update translations (#12290) root: fix override locale only if it is not empty (#12283) translate: Updates for file web/xliff/en.xlf in fr (#12276) core: bump twilio from 9.3.7 to 9.3.8 (#12282) website: bump path-to-regexp and express in /website (#12279) core: bump sentry-sdk from 2.19.0 to 2.19.1 (#12280) core: bump ruff from 0.8.1 to 0.8.2 (#12281) website/docs: fix lint (#12287) website/integrations: netbird: fix redirect URI regex (#12284)
* main: flows: better test stage's challenge responses (#12316) enterprise/stages/authenticator_endpoint_gdtc: don't set frame options globally (#12311) stages/identification: fix invalid challenge warning when no captcha stage is set (#12312) website/docs: prepare 2024.10.5 release notes (#12309) website: bump nanoid from 3.3.7 to 3.3.8 in /website (#12307) flows: silent authz flow (#12213) root: use healthcheck in depends_on for postgres and redis (#12301) ci: ensure mark jobs always run and reflect correct status (#12288) enterprise: allow deletion/modification of users when in read-only mode (#12289) web/flows: resize captcha iframes (#12260)
* main: (118 commits) outposts: fix version label (#12486) web: only load version context when authenticated (#12482) core: bump goauthentik.io/api/v3 from 3.2024120.2 to 3.2024121.2 (#12478) ci: bump helm/kind-action from 1.11.0 to 1.12.0 (#12479) web: fix build dev build (#12473) root: fix dev build version being invalid semver (#12472) internal: fix missing trailing slash in outpost websocket (#12470) web: bump API Client version (#12469) admin: monitor worker version (#12463) core: bump jinja2 from 3.1.4 to 3.1.5 (#12467) web: bump API Client version (#12468) release: 2024.12.1 (#12466) web: misc fixes for admin and flow inspector (#12461) website/docs: 2024.12.1 release notes (#12462) core: bump goauthentik.io/api/v3 from 3.2024120.1 to 3.2024120.2 (#12456) core: bump urllib3 from 2.2.3 to 2.3.0 (#12457) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh-Hans (#12454) translate: Updates for file locale/en/LC_MESSAGES/django.po in zh_CN (#12453) translate: Updates for file web/xliff/en.xlf in zh-Hans (#12455) translate: Updates for file web/xliff/en.xlf in zh_CN (#12458) ...
…ing. \# What \# Why \# How \# Designs \# Test Steps \# Other Notes
…rom failing." This reverts commit dddde09.
* main: website/integrations: meshcentral: document (#12509) stages/authenticator_webauthn: Update FIDO MDS3 & Passkey aaguid blobs (#12524) core: bump goauthentik.io/api/v3 from 3.2024121.2 to 3.2024121.3 (#12522) web: bump API Client version (#12520) website/integrations: chronograf: document (#12474) website/integrations: update preparation placeholder (#12507) providers/saml: fix handle Accept: application/xml for SAML Metadata endpoint (#12483) (#12518) core: bump aws-cdk-lib from 2.173.3 to 2.173.4 (#12513) website: bump aws-cdk from 2.173.3 to 2.173.4 in /website (#12514) core: bump coverage from 7.6.9 to 7.6.10 (#12499) core: bump aws-cdk-lib from 2.173.2 to 2.173.3 (#12500) website: bump aws-cdk from 2.173.2 to 2.173.3 in /website (#12501) core: bump github.com/go-ldap/ldap/v3 from 3.4.9 to 3.4.10 (#12502) website/docs: New "Whats Up Docker" URL (#12488)
* main: core: bump github.com/getsentry/sentry-go from 0.30.0 to 0.31.1 (#12543) core: bump google-api-python-client from 2.156.0 to 2.157.0 (#12544) core: bump ruff from 0.8.4 to 0.8.5 (#12545) core: bump msgraph-sdk from 1.15.0 to 1.16.0 (#12546) Update index.mdx (#12542) web: fix source selection and outpost integration health (#12530) Ading a step to paperless guide (#12539) website/integrations: Semaphore (#12515) website/integrations: komga: document (#12476) website/integrations: fix missing quote in paperless-ngx (#12537) website/integrations: cloudflare access: upd placeholder for saas (#12536) website/integrations: veeam-enterprise-manager: don't hardcode helpcenter doc version (#12538)
* main: core: bump golang.org/x/oauth2 from 0.24.0 to 0.25.0 (#12571) website: bump the docusaurus group in /website with 9 updates (#12569) core: bump github.com/coreos/go-oidc/v3 from 3.11.0 to 3.12.0 (#12572) core: bump ruff from 0.8.5 to 0.8.6 (#12573) ci: release: fix AWS cfn template permissions (#12576) translate: Updates for file web/xliff/en.xlf in fr (#12578) translate: Updates for file locale/en/LC_MESSAGES/django.po in fr (#12577) sources/kerberos: authenticate with the user's username instead of the first username in authentik (#12497) website/integrations: Fix deprecated terraform ressource authentik_scope_mapping in docs (#12554) website/user-sources Fix Free IPA docs page (#12549) core: bump aws-cdk-lib from 2.173.4 to 2.174.0 (#12574) website/integrations: semaphore: fix formatting (#12567) website: bump aws-cdk from 2.173.4 to 2.174.0 in /website (#12570) website/integrations: Update Frappe Application index.md (#12527) website: add api reference docs to redirect file (#12551)
* main: lib: add expression helper ak_create_jwt to create JWTs (#12599) api: cleanup owner permissions (#12598) website: bump aws-cdk from 2.174.0 to 2.174.1 in /website (#12593) core: bump aws-cdk-lib from 2.174.0 to 2.174.1 (#12594) website/integrations: portainer: group config steps (#12548) translate: Updates for file web/xliff/en.xlf in fi (#12586) translate: Updates for file locale/en/LC_MESSAGES/django.po in fi (#12584) website/docs: fix Nginx redirection example (#12561)
* main: website: revise full development environment instructions (#12638) website: bump typescript from 5.7.2 to 5.7.3 in /website (#12620) website: bump aws-cdk from 2.174.1 to 2.175.0 in /website (#12621) ci: bump docker/setup-qemu-action from 3.2.0 to 3.3.0 (#12622) core: bump twilio from 9.4.1 to 9.4.2 (#12623) core: bump python-kadmin-rs from 0.5.2 to 0.5.3 (#12624) core: bump ruff from 0.8.6 to 0.9.0 (#12625) core: bump pydantic from 2.10.4 to 2.10.5 (#12626) core: bump google-api-python-client from 2.157.0 to 2.158.0 (#12628) core: bump goauthentik.io/api/v3 from 3.2024121.3 to 3.2024122.1 (#12629) web: bump API Client version (#12617) release: 2024.12.2 (#12615) website/docs: prepare 2024.12.2 release notes (#12614) providers/saml: fix invalid SAML Response when assertion and response are signed (#12611) core: fix error when creating new user with default path (#12609) rbac: permissions endpoint: allow authenticated users (#12608) website/docs: update customer portal (#12603) website/docs: policy for email whitelist: modernize (#12558)
* main: (65 commits) stages/redirect: fix query parameter when redirecting to flow (#12750) website/integrations: cloudflare-access: refactor (#12663) sources/kerberos: handle principal expire time (#12748) lifecycle: build binary dependencies which link against SSL directly (#12724) website/docs: style guide: document styling preferences for URLs (#12715) website/integrations: nextcloud: fix broken link (#12744) core: bump selenium from 4.27.1 to 4.28.0 (#12745) lifecycle: move AWS CFN generation to lifecycle and fix CI (#12743) core: search users' attributes (#12740) web/components: ak-number-input: add support for min (#12703) website/integrations: nextcloud: fix url for "disable username changes" (#12725) core: bump pytest-github-actions-annotate-failures from 0.2.0 to 0.3.0 (#12735) website: bump katex from 0.16.11 to 0.16.21 in /website (#12731) web: bump katex from 0.16.11 to 0.16.21 in /web (#12730) website/integrations: Fix URL for authentik installation instead of mobilizon installation (#12729) core: bump debugpy from 1.8.11 to 1.8.12 (#12718) core: bump ruff from 0.9.1 to 0.9.2 (#12717) core: bump webauthn from 2.4.0 to 2.5.0 (#12719) core: bump structlog from 24.4.0 to 25.1.0 (#12720) website/integrations: all: install -> installation (#12676) ...
* main: web: update gen-client-ts to OpenAPI 7.11.0 (#12756) website/integrations: rustdesk-server-pro (#12706) core: bump codespell from 2.3.0 to 2.4.0 (#12762) root: docker: ensure apt packages are up-to-date (#12683) ci: fix missing build args for dev and release (#12760) web: bump vite from 5.4.11 to 5.4.14 in /web (#12757) web: bump undici from 6.21.0 to 6.21.1 in /web (#12755) lifecycle: fix cryptography's OpenSSL path (#12753)
* main: (111 commits) root: correctly use correct schema for install_id (#13018) website: bump docusaurus-plugin-openapi-docs from 4.3.3 to 4.3.4 in /website (#13011) web: bump API Client version (#13017) core: bump aws-cdk-lib from 2.178.1 to 2.178.2 (#13013) core: bump oss/go/microsoft/golang from 1.23-fips-bookworm to 1.24-fips-bookworm (#13012) website: bump docusaurus-theme-openapi-docs from 4.3.3 to 4.3.4 in /website (#13010) lifecycle/aws: bump aws-cdk from 2.178.1 to 2.178.2 in /lifecycle/aws (#13009) core: bump github.com/sethvargo/go-envconfig from 1.1.0 to 1.1.1 (#13008) web/admin: fix source selection for identification stage (#13007) core: bump sentry-sdk from 2.20.0 to 2.21.0 (#13014) website/integrations: Open WebUI (#12939) root: use correct default schema for install_id (#13006) website/docs: fix a minor typo (#13004) enterprise/providers/ssf: fixes v2 (#13003) root: make default postgres schema configurable (#12949) providers/oauth2: cleanup tokens when user is deactivated (#12859) website/docs: fix Nginx redirection example (#12920) core: bump twilio from 9.4.4 to 9.4.5 (#12993) core: bump coverage from 7.6.11 to 7.6.12 (#12994) core: bump cryptography from 44.0.0 to 44.0.1 (#12992) ...
* main: (77 commits) website/integrations: add hass-openid instructions (#14672) core: add updated_at field to user (#15571) root: Add more opencontainer labels to Dockerfiles (#15923) core: bump goauthentik.io/api/v3 from 3.2025064.2 to 3.2025064.3 (#15949) core, providers/ldap: add parent/child groups to api and ldap results (#14974) web: Make Webdriver optional during install. (#15952) core, web: update translations (#15945) packages/django-dramatiq-postgres: fix typo (#15932) web: bump API Client version (#15942) core: fix flow planner checking against wrong user when creating recovery link (#15390) providers/saml: configuration for default NameID Policy (#15109) core: bump boto3 from 1.39.15 to v1.40.1 (#15926) core: bump jsii from 1.112.0 to v1.113.0 (#15927) core: bump argon2-cffi-bindings from 21.2.0 to v25.1.0 (#15925) core: bump aiohttp from 3.12.14 to v3.12.15 (#15924) core: bump opentelemetry-api from 1.35.0 to v1.36.0 (#15928) web/admin: fix variable name (#15934) policies: fix typo (#15933) web: bump @sentry/browser from 9.43.0 to 10.0.0 in /web in the sentry group across 1 directory (#15911) core: bump github.com/prometheus/client_golang from 1.22.0 to 1.23.0 (#15908) ...
* main: (32 commits) core: bump goauthentik.io/api/v3 from 3.2025064.6 to 3.2025064.7 (#16024) core, web: update translations (#16021) ci: move images from beryju/* to authentik/* (#15321) core, web: update translations (#15985) core: bump cattrs from 24.1.3 to v25.1.1 (#15981) web: bump API Client version (#16002) ci: bump actions/download-artifact from 4 to 5 (#15995) core: bump certifi from 2025.7.14 to v2025.8.3 (#15982) core: bump anyio from 4.9.0 to v4.10.0 (#15979) core: bump boto3 from 1.40.1 to v1.40.2 (#15980) core: bump astral-sh/uv from 0.8.4 to 0.8.5 (#15998) core: bump goauthentik.io/api/v3 from 3.2025064.5 to 3.2025064.6 (#15997) stages/email: implement rate limiting for account verification (#15531) web: Fix stale application slug, missing error state. (#15941) website/docs: change azure ad to entra id (#15691) website/docs: add tips for image optimization (#15978) web: bump API Client version (#15976) providers/oauth2: backchannel logout (#15401) web: bump API Client version (#15953) translate: Updates for file web/xliff/en.xlf in fr (#15974) ...
* main: (210 commits) web: Username truncation, field alignment. (#16283) website/docs: adds a webhook header mapping example (#16301) web: Fix issue where form group uses unknown slot. (#16276) lifecycle: set PROMETHEUS_MULTIPROC_DIR as early as possible (#16298) providers/oauth2: fix logout token missing sid, fix wrong sub mode used (#16295) web: bump core-js from 3.45.0 to 3.45.1 in /web (#16290) root: Remove CODEOWNERS entries from docs/ directory (#16287) *: Fix dead doc link (#16288) web: saml provider view: fix state refresh issues (#14474) web: fix "Explore integrations" link in Quick actions (#16274) website/integrations: fix dead links to external docs (#16273) tasks: add rel_obj to system task exception event (#16270) website/docs: update 2025.8 release notes (#16269) web: bump @patternfly/elements from 4.1.0 to 4.2.0 in /web (#16265) web: bump mermaid from 11.9.0 to 11.10.0 in /web (#16263) web: bump @types/guacamole-common-js from 1.5.3 to 1.5.4 in /web (#16262) security: Bump supported versions (#16261) core: bump channels from 4.3.0 to v4.3.1 (#16260) translate: Updates for file web/xliff/en.xlf in cs_CZ (#16264) website: bump the eslint group in /website with 3 updates (#16248) ...
* main: providers/oauth2: avoid deadlock during session migration (#16361) lifecycle/aws: bump aws-cdk from 2.1025.0 to 2.1026.0 in /lifecycle/aws (#16352) core: bump github.com/stretchr/testify from 1.10.0 to 1.11.0 (#16357) core: bump axllent/mailpit from v1.27.5 to v1.27.6 in /tests/e2e (#16358) website/docs: fix missing trailing slash in vaultwarden documentation (#16348) root: fix security.md (#16345) root: update security.md with github reporting link (#16332) website/docs: 2025.8.1 release notes (#16343) packages/django-dramatiq-postgres: broker: fix various timing issues (#16340) website/docs: adds details to certificates doc (#16335) outposts: allow ingress path type configuration (#16339) core, web: update translations (#16321) outposts: fix service connection update task arguments (#16312) core: use email backend for test_email management command (#16311) core: bump astral-sh/uv from 0.8.12 to 0.8.13 (#16325) website: Move docs netlify.toml (#16320) website/docs: add link in 2025.8 rel notes to back-channel logout docs (#16306) packages/django-dramatiq-postgres: middleware: fix listening on hosts where ipv6 is not supported (#16308) website: Fix version origin detection, build-time URLs (#15774) web/a11y: Associating labels with inputs (#16119)
* main: (71 commits) website: Redirect Azure to Entra. Add tags for search indexing. (#16474) website: Page redirect guide, documentation (#16466) root: bump openapi-generator-cli to v7.15.0 (#16440) ci: bump actions/attest-build-provenance from 2 to 3 (#16462) core: bump astral-sh/uv from 0.8.13 to 0.8.14 (#16461) ci: remove Python client API publication (#16468) website: Unify Netlify redirects with Docusaurus's client-side router. (#16430) core: fix client-side only validation allowing admin to set blank user password (#16467) website/integrations: Update Issuer URL for Immich (#16460) providers/oauth2: include scope in JWT (#16454) lib/sync/outgoing: fix single object sync timeout (#16447) website/docs: capitalized proper name of stages, removed old version references. (#16414) web: bump pino-pretty from 13.0.0 to 13.1.1 in /web (#16411) core: bump h2 from 4.2.0 to 4.3.0 (#16446) web: bump @playwright/test from 1.54.1 to 1.55.0 in /web (#16413) web: bump the react group across 2 directories with 1 update (#16448) web: bump bootstrap from 5.3.7 to 5.3.8 in /web (#16416) web: bump @sentry/browser from 10.6.0 to 10.7.0 in /web in the sentry group across 1 directory (#16433) root: check for brew install of libxml2 before updating path (#16422) core: bump github.com/stretchr/testify from 1.11.0 to 1.11.1 (#16434) ...
* main: (121 commits) website: bump the eslint group in /website with 3 updates (#16674) web: bump the eslint group across 2 directories with 3 updates (#16675) web: bump vite from 7.1.4 to 7.1.5 in /web (#16676) website/docs: fix typo (#16681) core: Include region comments in VSCode Minimap. (#16667) tasks: fix status and healthcheck breaking with connection issues (#16504) website/docs: add period on very last sentence. (#16669) core: bump golang.org/x/sync from 0.16.0 to 0.17.0 (#16657) web: bump the eslint group across 3 directories with 2 updates (#16661) web: bump the storybook group across 1 directory with 5 updates (#16662) core: bump golang.org/x/oauth2 from 0.30.0 to 0.31.0 (#16658) core: bump github.com/prometheus/client_golang from 1.23.1 to 1.23.2 (#16659) website: bump the eslint group in /website with 2 updates (#16660) web: bump the rollup group across 1 directory with 4 updates (#16663) web: bump pino from 9.9.2 to 9.9.4 in /web (#16664) lifecycle/aws: bump aws-cdk from 2.1028.0 to 2.1029.0 in /lifecycle/aws (#16665) core: bump selenium/standalone-chrome from 139.0 to 140.0 in /tests/e2e (#16666) website/integrations: fix missing space after comma (#16650) website/integrations: add missing comma paperless-ngx (#16651) root: bump to debian trixie (#16626) ...
* main: (81 commits) translate: Updates for file web/xliff/en.xlf in de (#16808) stages: update friendly_name model from null to blank (#16672) sources/saml: add default error messages to exceptions (#15562) website/docs: 2025.8.3 release notes (#16809) core, web: update translations (#16783) stages/email_authenticator: Fix email mfa loop (#16579) website/docs: updated Frontend development environment contributor docs (#16731) webiste/integrations: update roundcube doc (#16753) website/docs: update create oauth provider page (#16617) website: bump @types/node from 24.4.0 to 24.5.0 in /website (#16789) web: bump the rollup group across 1 directory with 4 updates (#16792) core: bump github.com/getsentry/sentry-go from 0.35.2 to 0.35.3 (#16786) web: bump the storybook group across 1 directory with 5 updates (#16791) web: bump @types/node from 24.4.0 to 24.5.0 in /packages/esbuild-plugin-live-reload (#16794) web: bump @goauthentik/prettier-config from 1.0.5 to 3.1.0 in /web in the goauthentik group across 1 directory (#16793) web: bump @types/node from 24.4.0 to 24.5.0 in /packages/prettier-config (#16795) web: bump @types/node from 22.15.19 to 24.5.0 in /web (#16796) web: Use curated dictionary for e2e fixtures. (#16750) website/integrations: fix wekan redirect URL (#16801) website/docs: fix docker tabs not rendering properly (#16799) ...
* main: (58 commits) web: bump the esbuild group across 2 directories with 4 updates (#16868) core, web: update translations (#16864) core: bump astral-sh/uv from 0.8.17 to 0.8.18 (#16866) website: bump @types/node from 24.5.1 to 24.5.2 in /website (#16867) web: bump @types/node from 24.5.1 to 24.5.2 in /packages/esbuild-plugin-live-reload (#16869) web: bump pino from 9.9.5 to 9.10.0 in /packages/esbuild-plugin-live-reload (#16870) web: bump @types/node from 24.5.1 to 24.5.2 in /packages/prettier-config (#16871) web: bump @types/node from 22.15.19 to 24.5.2 in /web (#16872) web: bump dompurify from 3.2.6 to 3.2.7 in /web (#16873) web: bump pino from 9.9.5 to 9.10.0 in /web (#16874) web: bump vite from 7.1.5 to 7.1.6 in /web (#16875) web: bump chromedriver from 140.0.2 to 140.0.3 in /web (#16876) lifecycle/aws: bump aws-cdk from 2.1029.1 to 2.1029.2 in /lifecycle/aws (#16877) web: Fix docs links, a11y input descriptors (#16671) website: bump the eslint group in /website with 3 updates (#16788) website: bump the build group in /website with 3 updates (#16787) web: bump the eslint group across 2 directories with 3 updates (#16790) website/docs: extends the example to include `jwt_config` for matrix/synapse (#16860) web/a11y: Flow Search (#15876) web: bump API Client version, remove Webdriver dependencies (#16836) ...
…upport a more DOM-oriented behavior model. The core insights here is that there were two signals being propagated through the system: “page detail change” and “toggle sidebar,” and that they are *Events*.
## What
### Changes to Sidebar handling.
The event `SidebarToggle` has been changed to a more generic `PageNavMenuToggle`, so that we’re not dictating what kind of main menu the UI provides. It has also been made a typed, global event, rather than a CustomEvent. `ak-page-navbar` sends it, and `ak-interface-admin` listens for it, the way Hermes intended. Because events from `ak-page-navbar` propagate *up*,
### Changes to the Page Navbar
The static, ad-hoc handler for page identity has been replaced with a bog-standard event listener. The event listener is placed on `window`, and so has been added to the `connectCallback()/disconnectCallback()` portions of the lifecycle so it is removed successfully on disconnect.
I have also moved the Websocket event handler (`EVENT_WS_MESSAGE`) into the `connectCallback()/disconnectCallback()` lifecycle, for the same reson.
A function, `setPageDetails(header: PageInit);` has been provided to replicate the functionality of `AKPageNavbar.setNavbrDetails()`. This function pushes the event onto `window`, to which we are listening. The event is synchronous (since its origin is in custom code), and is delivered at the same time and in the same way as the prior method.
**Why**: Primarily, it’s the standard way to do things. Both the static method and this method happen in a single JSVM microtask (the same task, actually), so there’s no change in behavior or performance. If we ever want to go to a different idiom, like making the header a child element of a route, or turning this into some series of MPAs using view-transitions and a state-managing webworker, the lifecycle components will no longer get in the way. This change also eliminates the need for every instance of `ak-page-navbar` to keep a static reference to the “current” navbar. We were not using that reference to ensure singleton status, nor clean up multiple instances, so its utility wasn’t clear.
### Changes to pages that need to update the page header details.
A mechanical script<sup>\*</sup> replaced every instance of `import ... ak-page-header` with `import { setPageDetails } from ak-page-navbar`, and every instance of `<ak-page-header ...>` with:
updated(changed: PropertyValues<this>) {
setPageDetails(header: ...derived_from_ak-page-header);
}
In several cases, this left render statements that looked like:
render() {
return html`${this.renderBody()}`;
}
… in which case I manually short-circuited the extra function call.
**Note**: Doing this sometimes resulted in a lot of whitespace changes (thank you very effin’ much, *prettier*), so some of the changes look much bigger than they should. I have made marks in the PR when this happens.
## Not Fixed
The call to `ak-page-header` in `ApplicationPage` looked like this:
<ak-page-header
header=${this.application?.name || msg("Loading")}
description=${ifPresent(this.application?.metaPublisher)}
>
<ak-app-icon
size=${PFSize.Medium}
name=${ifPresent(this.application?.name)}
icon=${ifPresent(this.application?.metaIcon)}
slot="icon"
></ak-app-icon>
</ak-page-header>
When `ak-page-header` was revised to be nothing but an pub-hub style event emitter, it lost any `render` capability at all, falling back to the `nothing` inherited from `lit-html`. That slot does not exist. `ApplicationPage` has not been able to show user-supplied application icons for awhile now, and this commit does not change that.
<hr/>
<sup>\*</sup>The script is written in elisp. If anyone wants to read it, I’m willing to message it to ya.
This commit breaks ak-page-navbar up into seperate units, mapping to the parts of an HTMLElement: The Style block, the HTML template, and the business logic. Doing this makes a *whole lot* of compromises and hacks stand out, like the whaty we backfill uiConfig.navbar.userdisplay, or the way icons are just a mess. No business logic was revised with this commit *at all*. This is simply breaking the component up so that the logic is exposed. \# What \# Why \# How \# Designs \# Test Steps \# Other Notes
* main: (24 commits) root: add mypy (#16904) website: Remove duplicate sidebar entries. (#16922) web: Remove CSS constructor polyfill. (#16920) web: Replace Github Slugger package with change-case. (#16921) website: Fix broken schema links v2 (#16919) website: bump the build group in /website with 3 updates (#16908) core: bump astral-sh/uv from 0.8.18 to 0.8.19 (#16906) core: bump goauthentik.io/api/v3 from 3.2025100.6 to 3.2025100.8 (#16907) website: bump the eslint group in /website with 2 updates (#16909) web: bump the eslint group across 2 directories with 2 updates (#16911) web: bump the rollup group across 1 directory with 4 updates (#16912) web: bump typedoc-plugin-markdown from 4.8.1 to 4.9.0 in /packages/esbuild-plugin-live-reload (#16913) web: bump pino from 9.10.0 to 9.11.0 in /packages/esbuild-plugin-live-reload (#16914) web: bump pino from 9.10.0 to 9.11.0 in /web (#16915) website: add hierarchy line to sidebar (#16565) events: remove deprecated models (#15823) core: update_attributes: only update the model if attributes changed (#16322) Revert "website: Fix broken schema links, non-relative paths, unapplied redirect aliases" (#16902) website: Fix broken schema links, non-relative paths, unapplied redirect aliases (#16900) website/integrations: adds termix (#16889) ...
* main: (24 commits) root: add mypy (#16904) website: Remove duplicate sidebar entries. (#16922) web: Remove CSS constructor polyfill. (#16920) web: Replace Github Slugger package with change-case. (#16921) website: Fix broken schema links v2 (#16919) website: bump the build group in /website with 3 updates (#16908) core: bump astral-sh/uv from 0.8.18 to 0.8.19 (#16906) core: bump goauthentik.io/api/v3 from 3.2025100.6 to 3.2025100.8 (#16907) website: bump the eslint group in /website with 2 updates (#16909) web: bump the eslint group across 2 directories with 2 updates (#16911) web: bump the rollup group across 1 directory with 4 updates (#16912) web: bump typedoc-plugin-markdown from 4.8.1 to 4.9.0 in /packages/esbuild-plugin-live-reload (#16913) web: bump pino from 9.10.0 to 9.11.0 in /packages/esbuild-plugin-live-reload (#16914) web: bump pino from 9.10.0 to 9.11.0 in /web (#16915) website: add hierarchy line to sidebar (#16565) events: remove deprecated models (#15823) core: update_attributes: only update the model if attributes changed (#16322) Revert "website: Fix broken schema links, non-relative paths, unapplied redirect aliases" (#16902) website: Fix broken schema links, non-relative paths, unapplied redirect aliases (#16900) website/integrations: adds termix (#16889) ...
* dev: (24 commits) root: add mypy (#16904) website: Remove duplicate sidebar entries. (#16922) web: Remove CSS constructor polyfill. (#16920) web: Replace Github Slugger package with change-case. (#16921) website: Fix broken schema links v2 (#16919) website: bump the build group in /website with 3 updates (#16908) core: bump astral-sh/uv from 0.8.18 to 0.8.19 (#16906) core: bump goauthentik.io/api/v3 from 3.2025100.6 to 3.2025100.8 (#16907) website: bump the eslint group in /website with 2 updates (#16909) web: bump the eslint group across 2 directories with 2 updates (#16911) web: bump the rollup group across 1 directory with 4 updates (#16912) web: bump typedoc-plugin-markdown from 4.8.1 to 4.9.0 in /packages/esbuild-plugin-live-reload (#16913) web: bump pino from 9.10.0 to 9.11.0 in /packages/esbuild-plugin-live-reload (#16914) web: bump pino from 9.10.0 to 9.11.0 in /web (#16915) website: add hierarchy line to sidebar (#16565) events: remove deprecated models (#15823) core: update_attributes: only update the model if attributes changed (#16322) Revert "website: Fix broken schema links, non-relative paths, unapplied redirect aliases" (#16902) website: Fix broken schema links, non-relative paths, unapplied redirect aliases (#16900) website/integrations: adds termix (#16889) ...
…revise-nav-bar-3 * web/maintenance/revise-nav-bar-2: Prettier has some (silly) opinions. Missed a bug that prevented Storybook from deploying. One more hack. web: applied several fixes to the PR as requested.
* main: web: revise ak-page-navbar to use standard event handlers (#16898)
✅ Deploy Preview for authentik-docs canceled.
|
✅ Deploy Preview for authentik-integrations canceled.
|
❌ Deploy Preview for authentik-storybook failed. Why did it fail? →
|
kensternberg-authentik
marked this pull request as ready for review
September 22, 2025 22:20
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #16930 +/- ##
==========================================
- Coverage 92.82% 92.77% -0.06%
==========================================
Files 838 838
Lines 45374 45374
==========================================
- Hits 42118 42095 -23
- Misses 3256 3279 +23
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
Contributor
|
authentik PR Installation instructions Instructions for docker-composeAdd the following block to your AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-9ba6d03dbe74df3b95e154d7a17393dc8bc1b532
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)sAfterwards, run the upgrade commands from the latest release notes. Instructions for KubernetesAdd the following block to your authentik:
outposts:
container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
image:
repository: ghcr.io/goauthentik/dev-server
tag: gh-9ba6d03dbe74df3b95e154d7a17393dc8bc1b532Afterwards, run the upgrade commands from the latest release notes. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
web: update navbar header into sub-components for ease of styling
This commit breaks ak-page-navbar up into seperate units, mapping to the parts of an HTMLElement: The Style block, the HTML template, and the business logic. Doing this makes a whole lot of compromises and hacks stand out, like the whaty we backfill uiConfig.navbar.userdisplay, or the way icons are just a mess.
No business logic was revised with this commit at all. This is simply breaking the component up so that the logic is exposed.
make web)