Commit graph

12414 commits

Author SHA1 Message Date
Lauri Ojansivu
107e2ac900 Add support for Docker/Compose Secrets for passwords to Docker/Snap/Bundle platforms.
Thanks to Roemer and xet7 !

Fixes #5724
2025-10-10 23:46:48 +03:00
Lauri Ojansivu
3b60bdea14 Updated ChangeLog. 2025-10-10 23:22:59 +03:00
Lauri Ojansivu
f6591d7820 Security Fix usd-2022-0041: CWE-284 Improper Access Control.
Thanks to Christian Pöschl of usd AG and xet7 !
2025-10-10 23:19:58 +03:00
Lauri Ojansivu
6bbd622066 Updated ChangeLog. 2025-10-10 23:16:26 +03:00
Lauri Ojansivu
ee79cab7b2 Security Fix JVN#86586539: Stored XSS.
Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7.
2025-10-10 23:14:06 +03:00
Lauri Ojansivu
a0b94065c5 Updated ChangeLog. 2025-10-10 23:09:28 +03:00
Lauri Ojansivu
e1fa607f87 Security Fix JVN#74210258: Stored XSS.
Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7 !
2025-10-10 23:06:06 +03:00
Lauri Ojansivu
2e91a359f5 Updated ChangeLog. 2025-10-10 23:02:37 +03:00
Lauri Ojansivu
9720e703fd Security Fix JVN#14269684: Broken access control.
Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7 !
2025-10-10 22:59:20 +03:00
Lauri Ojansivu
f88898d5b8 Updated ChangeLog. 2025-10-10 22:22:43 +03:00
Lauri Ojansivu
30c1597b65 Security Fix FG-VD-22-078: Prevent SVG Billion Laughs Attack.
Thanks to Nguyen Thanh Nguyen of Fortinet's FortiGuard Labs and xet7 !
2025-10-10 22:16:47 +03:00
Lauri Ojansivu
5bc5171220 Updated ChangeLog. 2025-10-10 22:12:25 +03:00
Lauri Ojansivu
d0f118e7af Security Fix: Computational Resource Abuse in Export endpoints.
Thanks to Anynymous Security Researcher and xet7 !
2025-10-10 22:09:27 +03:00
Lauri Ojansivu
c481443667 Updated ChangeLog. 2025-10-10 22:04:30 +03:00
Lauri Ojansivu
b87cff1289 Security Fix: IDOR CWE-639 that affected WeKan 7.80-7.93.
Thanks to apitech.fr and xet7 !
2025-10-10 21:59:04 +03:00
Lauri Ojansivu
0c080830bc Updated ChangeLog. 2025-10-10 21:48:27 +03:00
Lauri Ojansivu
cdd7d69c66 Drag any files from file manager to minicard or opened card. Part 2.
Thanks to xet7 !

Fixes #2936
2025-10-10 21:46:07 +03:00
Lauri Ojansivu
c1cbcdcc72 Updated ChangeLog. 2025-10-10 21:21:12 +03:00
Lauri Ojansivu
1c84b19f24 Show console.log 'Legacy attachments route loaded' only when environment variable DEBUG=true.
Thanks to xet7 !
2025-10-10 21:19:00 +03:00
Lauri Ojansivu
2c73dae019 Merge branch 'main' of github.com:wekan/wekan 2025-10-10 21:16:29 +03:00
Lauri Ojansivu
d285850a04 Updated ChangeLog. 2025-10-10 21:15:55 +03:00
Lauri Ojansivu
719ef87efc Make possible for lists to have different names at different swimlanes. Make possible to drag list from one swimlane to another swimlane.
Thanks to xet7 !
2025-10-10 21:14:44 +03:00
Lauri Ojansivu
039b9abf5e Updated translations 2025-10-10 20:37:22 +03:00
Lauri Ojansivu
39daf56811 Updated ChangeLog. 2025-10-10 19:12:09 +03:00
Lauri Ojansivu
a8de2f224f Use attachments from old CollectionFS database structure, when not yet migrated to Meteor-Files/ostrio-files, without needing to migrate database structure.
Thanks to xet7 !
2025-10-10 19:07:04 +03:00
Lauri Ojansivu
dda013844c Updated ChangeLog. 2025-10-10 18:55:13 +03:00
Lauri Ojansivu
3e9481c5bd Drag any files from file manager to minicard or opened card.
Thanks to xet7 !

Fixes #2936
2025-10-10 18:52:30 +03:00
Lauri Ojansivu
85ac03a892 Updated ChangeLog.
Some checks failed
Docker / build (push) Has been cancelled
Docker Image CI / build (push) Has been cancelled
Release Charts / release (push) Has been cancelled
Test suite / Meteor tests (push) Has been cancelled
Test suite / Coverage report (push) Has been cancelled
2025-10-09 05:54:04 +03:00
Lauri Ojansivu
752699d1c2 Mobile one board per row. Board zoom size percent. Board toggle mobile/desktop mode. In Progress.
Thanks to xet7 !

Related #5902
2025-10-09 05:48:41 +03:00
Lauri Ojansivu
339ca581ab Merge branch 'main' of github.com:wekan/wekan 2025-10-09 02:07:00 +03:00
Lauri Ojansivu
20e9cf1144 Text and icons from fixed sizes to scaleable sizes. Thanks to xet7. 2025-10-09 02:06:26 +03:00
Lauri Ojansivu
9737884c4b Text and icon from fixed sized to scaleable sizes. Thanks to xet7. 2025-10-09 02:06:16 +03:00
Lauri Ojansivu
2f5670e830 v7.97
Some checks are pending
Docker / build (push) Waiting to run
Docker Image CI / build (push) Waiting to run
Release Charts / release (push) Waiting to run
Test suite / Meteor tests (push) Waiting to run
Test suite / Coverage report (push) Blocked by required conditions
2025-10-08 23:57:08 +03:00
Lauri Ojansivu
108b18cebf Updated ChangeLog. 2025-10-08 23:48:26 +03:00
Lauri Ojansivu
814ac22a0d Updated ChangeLog. 2025-10-08 23:43:55 +03:00
Lauri Ojansivu
3814a218c2 Removed white box that appeared when clicking something.
Thanks to xet7 !

Fixes #5899
2025-10-08 23:38:44 +03:00
Lauri Ojansivu
3fda90612d Some mobile fixes.
Thanks to xet7 !

Fixes #5899
2025-10-08 23:32:13 +03:00
Lauri Ojansivu
05762aa50c Updated ChangeLog.
Some checks are pending
Docker / build (push) Waiting to run
Docker Image CI / build (push) Waiting to run
Release Charts / release (push) Waiting to run
Test suite / Meteor tests (push) Waiting to run
Test suite / Coverage report (push) Blocked by required conditions
2025-10-08 09:37:51 +03:00
Lauri Ojansivu
9a31371de0 Fixed translation of "Change Language" at login page.
Thanks to xet7 !
2025-10-08 09:36:39 +03:00
Lauri Ojansivu
b9b7143185 Updated ChangeLog. 2025-10-08 09:21:26 +03:00
Lauri Ojansivu
972721bdb5 Merge branch 'seve12-main' 2025-10-08 09:17:53 +03:00
Lauri Ojansivu
3a48982916 v7.96 2025-10-08 08:44:09 +03:00
Lauri Ojansivu
6b3a6f9f7d Updated ChangeLog. 2025-10-08 08:44:09 +03:00
Lauri Ojansivu
48fddecb62 Updated to MongoDB 7.0.25 at Snap Candidate.
Thanks to MongoDB developers !
2025-10-08 08:44:09 +03:00
Lauri Ojansivu
7f0d1cc5b3 Updated ChangeLog. 2025-10-08 08:44:09 +03:00
Lauri Ojansivu
70e82be0b4 Hide extra keyboard shortcuts toggle. Thanks to xet7. 2025-10-08 08:44:09 +03:00
Lauri Ojansivu
5fc0809844 Updated ChangeLog. 2025-10-08 08:44:09 +03:00
Lauri Ojansivu
c79990bcd9 Added missing screenshots from wekan.github.io history to wekan/docs/Features/ . Thanks to xet7 2025-10-08 08:44:09 +03:00
dependabot[bot]
cd9e7412ea Bump docker/login-action from 3.5.0 to 3.6.0
Bumps [docker/login-action](https://github.com/docker/login-action) from 3.5.0 to 3.6.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](184bdaa072...5e57cd1181)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-08 08:44:09 +03:00
Lauri Ojansivu
3e472606b5 Fixed links at docs. Thanks to xet7 2025-10-08 08:44:08 +03:00