* Fixes "files/folders/files or folders" selections for the various media picker components, re-allowing folder selection from a media picker.
* Import and use enim instead of hardcoded enum value
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Batch delete in DocumentUrlRepository and DocumentUrlAliasRepository to avoid exceeding SQL Server's 2100 parameter limit.
* Address code review feedback.
* Remove the unnecessary trigger rebuild on startup statement in the SQL Server migration path.
* Update Microsoft.Extensions.Caching.Hybrid to latest minor, and other Microsoft dependencies to latest patch.
* Align test and local web project dependency versions.
* Add to backoffice hosts
Add to backoffice hosts, rather than completely replacing the array
* Add unit tests verifying fix.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Extract shared culture-resolution logic from ConvertBlockEditorPropertiesBase, ConvertLocalLinks, FixConvertLocalLinks, and MigrateSingleBlockList into PropertyDataCultureResolver, fixing a bug where NULL languageId (legitimate invariant data) was incorrectly treated as a deleted language reference.
Add unit tests covering all resolution paths including the bug scenario.
* Remove obsoletion on helper.
* Address code review feedback.
* Handle SetValue variation mismatch for invariant data on culture-varying compositions
* Fixed build error in tests.
---------
Co-authored-by: Sven Geusens <sge@umbraco.dk>
* fix(media): prevent upload field image from overflowing content container
The image element used `height: 100%` which resolved to a definite value
when rendered in the old flex-row layout (parent's stretch gave it a height).
After #21887 restructured the wrapper to flex-column, the parent no longer
provides a definite height, so `height: 100%` falls back to `height: auto`
and the image renders at its natural (potentially huge) dimensions.
Fix by giving `img` direct constraints (`max-width: 100%`, `max-height: 400px`,
`height: auto`) so it constrains itself regardless of the parent layout context.
Closes#22106
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* style(media): remove redundant max-height from :host, keep on img
The max-height: 400px is now on the img directly, so the :host constraint
is redundant.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): apply same image overflow fix to SVG upload preview
Same root cause as #22106: img relied on height: 100% resolving via
parent flex-stretch, which breaks in the flex-column layout from #21887.
Move constraints to img directly (max-width: 100%, max-height: 400px,
height: auto) and remove redundant/ineffective host properties.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* style(media): move min-height from :host to img in image and SVG previews
With height: auto on img, min-height on :host left an empty gap when the
image was shorter than the minimum. Moving min-height to img ensures the
checkerboard background fills the full minimum preview area consistently.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): prevent image cropper focus setter from blinking on upload
The #image element had no CSS size constraints, causing it to render at
its natural dimensions briefly before the onload handler applied
width/height: 100% via inline styles. Adding max-width/max-height: 100%
ensures the image is already constrained on first paint, eliminating the
reflow blink when uploading a new image.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): use File object name for extension in file upload preview
When a file is dragged in before saving, the path is a blob URL
(blob:http://...) which produces a garbage extension when split on '.'.
The File object is already passed as a prop via the interface but was
unused. Prefer file.name for extension extraction when available.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Optimise redirect tracker by avoiding re-producing of descendant nodes and avoiding descendant traversal when there has been no change to the node's URL segment.
* Delete inadvertently added file
* Allow URL segment providers to ensure descendent traversal if needed.
* Pushed missing files.
* Refactors to reduce large method code smells.
* fix(core): lowercase file extension before validating against allowed/disallowed lists
Fixes case-sensitive comparison in UmbTemporaryFileManager where uploading a
file with an uppercase extension (e.g. .PDF) would be incorrectly rejected
even when the lowercase extension (pdf) was in AllowedUploadedFileExtensions.
Closes#22096
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): lowercase SVG extension check in media links info app
Fixes case-sensitive .svg check so that media files with uppercase
extensions (e.g. .SVG) correctly use the SVG viewer link.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(core): also lowercase config extension lists before comparison
The server may return extensions in any case (config is stored as-is).
Lowercase both sides to ensure the comparison is truly case-insensitive.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Ensure server-side checks for file extensions are case insensitive.
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Prevent move to recycle bin for documents and media when disable delete when referenced is configured.
* Addressed code review feedback and fixed failing client-side test.
* Add suppression for renamed integration test.
* Simplified solution by moving disableDeleteWhenReferenced setting to modal.
* Fix flicker.
* Apply disable on delete handling to bulk trash dialog.
* Add additional translations.
* Move disableDeleteWhenReferenced resolution to document and media action classes, so the value is passed as modal data rather than being resolved in the modal itself.
* Update OpenApi.json.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Allow "File" media type as fallback when no specific extension match is available at the upload location
* Added regression test.
* Addressed test feedback.
* Fix after merge.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Move #inSessionUpdateCallback guard into #setSessionLocally() so all
callers are protected, not just makeRefreshTokenRequest()'s lock callback.
Previously, completeAuthorizationRequest() called #setSessionLocally()
directly without setting the flag. With keepUserLoggedIn=true and a short
TimeOut, session$ observers fired synchronously inside #setSessionLocally,
triggering #onSessionExpiring → validateToken() → makeRefreshTokenRequest()
before #inSessionUpdateCallback was ever set — causing a second /token call
immediately after the initial code exchange 200.
The no-Web-Locks fallback path in makeRefreshTokenRequest() had the same
gap. Moving the flag into #setSessionLocally() covers all call sites.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Skip /token refresh when access token is still valid
Guard the per-request validateToken() call sites with #isAccessTokenValid()
in configureClient() and getLatestToken(). Previously, every API request
triggered a /token call even when the access token had not expired, causing
unnecessary token churn and OpenIddict ID2019 errors for in-flight requests.
Proactive refresh via UmbAuthSessionTimeoutController and startup validation
in app-auth.controller.ts are unaffected — those call validateToken() directly.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Remove redundant first-check validateToken() on app startup
setInitialState() already handles server verification before the router
evaluates guards — either via a direct /token call (makeRefreshTokenRequest)
or via peer session adoption (BroadcastChannel). The #isFirstCheck guard in
UmbAppAuthController was a leftover from the AppAuth/localStorage era, where
token state was restored from storage and needed a server round-trip to confirm
validity. That assumption no longer holds: if getIsAuthorized() is true after
setInitialState(), the session came directly from the server or from a peer
whose timing is still valid. Stale/revoked peer sessions are handled lazily
by the 401 interceptor, which triggers re-auth as needed.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Wait for ongoing cross-tab refresh before sending requests
Restores the cross-tab lock serialization that was implicitly provided by
the old unconditional validateToken() call. When another tab holds the
umb:token-refresh lock (keepUserLoggedIn proactive refresh), API requests
in this tab now wait for it to complete before proceeding. This prevents
sending requests with an access token that is about to be revoked, which
caused OpenIddict ID2019 errors on in-flight requests.
The fast path (token valid, no refresh in progress) remains: navigator.locks.query()
is a cheap browser-internal call, and the lock.request() no-op is only
incurred when a cross-tab refresh is actually happening.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Extract #ensureTokenReady(), improve naming and JSDoc
- Extract duplicate guard logic from configureClient() and getLatestToken()
into a single #ensureTokenReady() private method
- Rename from #ensureValidToken() → #ensureTokenReady() to distinguish from
the validate/valid naming cluster (validateToken, isAccessTokenValid)
- Add JSDoc to #isAccessTokenValid() clarifying it is a local timestamp check
with no network call
- Improve JSDoc on validateToken() to make clear it forces a network refresh
(unconditional /token call), distinct from the per-request #ensureTokenReady()
gate which skips the call when the access token is still live
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(auth): prevent re-entrant /token call when session$ fires synchronously inside lock
With keepUserLoggedIn=true and a short access token lifetime (e.g. expiresIn ≤ buffer),
#updateSession() triggers session$ synchronously inside the lock callback. The observer
fires #scheduleCheck → #onSessionExpiring → validateToken() before the lock is released.
This re-entrant call captures sessionBefore = newSession (already updated), so the
reference guard cannot detect it, resulting in a duplicate /token request.
Fix by tracking #inSessionUpdateCallback around the #updateSession() call. Re-entrant
callers return true immediately; concurrent non-re-entrant callers are unaffected.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
The window.opener guard in #setAuthStatus() was too broad — it skipped
setInitialState() for ANY window opened via window.open(), including the
preview window. This left isAuthorized stuck at false in the preview window,
causing the loading spinner to never resolve.
The guard is only needed for the OAuth code exchange popup (oauth_complete),
where calling setInitialState() could silently refresh the session, set
isAuthorized=true, and cause the popup to redirect to the backoffice instead
of completing the code exchange.
Fix: narrow the guard to window.opener + pathname === '/oauth_complete'.
The preview window (at path /preview) now correctly calls setInitialState(),
which restores the session from a peer tab via BroadcastChannel.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
security.md:
- Expand auth section with v17 httpOnly cookie model, [redacted] pattern,
configureClient() usage, and explicit warning against calling validateToken()
per request (causes token churn and ID2019 errors)
edge-cases.md:
- window.opener is set for any window.open() target, not just OAuth popups —
must check pathname too (root cause of #22083 preview regression)
- BroadcastChannel does not deliver to the sender — use local-only setters
inside handlers to avoid N² broadcast storms
- sessionRequest must guard with isSessionValid() before responding
- Web Lock umb:token-refresh pattern for cross-tab refresh deduplication
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Updated ui helper to verify the image cropper is rendered
* Added .skip for the failing tests due to the actual issue
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Add bulk fetch endpoints for retrieving full details for multiple entities by provided IDs, for data, document, media and member types.
* Switch to GET endpoints.
* generate new managment api types + sdk
* Update to use "batch" over "fetch".
* Update OpenApi.json and client-side types/sdk.
* Add endpoint summaries and descriptions.
* Align controller method signatures with use of HashSet<Guid> over Guid[].
* Backoffice Performance: Client-side bulk fetch of Element Types for Blocks, Content Type Compositions, and Data Types to reduce API requests (#21610)
* Add readMany for document type details
* Add batch read methods to detail interfaces
* Pre-register content-type structures and bulk load
* Add readMany support to detail request managers
* Simplify loadType and delegate to setType
* add js docs to detail data request manager
* add unit tests for detail data request manager
* Add byUniques support to detail store/repository
* implement readMany for data types
* fix typescript errors
* Preload and pass data type details to properties
* Update content-type-structure-manager.class.ts
* Replace per-property UmbDataTypeDetailRepository requests with the structure manager's bulk-loaded data type details
* Deduplicate inflight detail read/readMany requests
* Use 'read:' inflight cache key prefix
* Add bulk detail requests & status helpers
* Add management API request/cache for media/member types + requestByUniques support
* use observe controller instead of rxjs
* adjust to new apis
* rename prop to make it easier to read
* throw on error
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* remove unused import
* Fixes to failing E2E tests.
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Mole <nikolajlauridsen@protonmail.ch>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Fixed link in notification to editable document.
* Update translations using legacy mail format.
* Delete inadvertently added file
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Allowed for easier public access management.
* Revert the update controller as that is being handled by the frontend.
* Cleaning up pull request
* Preserving obsolete function, updating controller to pass optional parameter.
* pass in the includeAncestors parameter
* Added in an alert message for when the permissions are being inhereited.
* Complete resolution of breaking changes on IPublicAccessPresentationFactory.
* Update call to controller from integration tests.
* Fixed variable name typo and whitespace.
* Added clarifying comment to client-side behaviour.
* Supressed the breaking change on the controller with the additional parameter.
* Added unit tests for PublicAccessPresentationFactory.
* Added localisation for ancestor label.
* Typo and whitespace.
* Updating the model to allow for switching between methods while still preserving ancestor selections.
* update locatlizations
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Auth: Fix popup flow showing backoffice after session timeout re-auth
When a session times out client-side, the parent tab's #session was still
non-null (the timeout signal fires without clearing the session). When the
re-auth popup opened and called setInitialState(), it sent a sessionRequest
via BroadcastChannel. The parent responded with the expired session because
the handler only checked `if (session)` — not if the session was still valid.
The popup's auth context then thought it was already authorized, causing the
oauth_complete handler to hit the early-return `redirectToStoredPath` instead
of completing the authorization code exchange. The popup navigated to the
backoffice instead of exchanging the code and closing.
Fix: only share the session in response to sessionRequest if isSessionValid()
returns true (i.e. session.expiresAt > now).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Fix re-auth popup not opening on session timeout
Two issues:
1. When the countdown modal timer reached 0, it called onLogout() -> signOut()
which performed a full page redirect to /logout before timeoutSignal could
fire. The re-auth popup (makeAuthorizationRequest('timedOut') in
UmbAppAuthController) was never triggered. Fix: reject the modal on timer
expiry instead of calling onLogout(). The catch block in #openTimeoutModal
then calls #tryValidateToken(); if the refresh token is still valid the
session is silently renewed, otherwise timeOut() fires -> timeoutSignal ->
re-auth popup opens.
2. Only the Web Lock leader tab was showing the timeout countdown modal.
All tabs should show the warning so the user can respond from any active
tab. Remove the lock-leader election logic — show the modal on every tab.
When any tab successfully refreshes (Continue button or silent refresh), the
session$ observer fires in all tabs, closing the modal everywhere.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Show re-auth popup when timeout countdown expires
When the countdown reaches zero the user was away and the session has
effectively expired — silently refreshing is the wrong behaviour. Instead:
- Add onExpired callback to UmbModalAuthTimeoutConfig, called (instead of
onLogout) when the countdown hits 0.
- The controller sets onExpired -> timeOut(), which clears the session and
fires timeoutSignal. UmbAppAuthController picks this up and calls
makeAuthorizationRequest('timedOut'), opening the re-auth popup so the
user can sign back in without losing their work.
- The modal uses submit() (not reject()) on expiry so the catch block's
tryValidateToken() is not triggered.
- The Logout button still calls signOut() as before.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Close re-auth modal on other tabs when session is restored
When all tabs showed the re-auth modal and the user signed in on one tab,
the authorized BroadcastChannel message updated every other tab's auth
context but nothing triggered the modal to close on those tabs.
Fix: observe isAuthorized in UmbAppAuthModalElement. When it becomes true
(either from local sign-in or from another tab's BroadcastChannel message),
call #onSuccess() to submit and close the modal.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* chore: adds null guard
* docs: updates CLAUDE.md to let it know that there is a circular check call
* fix: fixes issue where the popup window could redirect to and show the full backoffice inside
* fix: ensures that the timeout modal is not shown until the buffer window is reached and extend the buffer window in case of short timeouts, and use the full expiresAt value for timeout but only the accessTokenExpiresAt for refresh of token
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Append leading / to AliasUrlProvider URLs only if it doesn't already have one
* Add unit tests for AliasUrlProvider.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fixed issue with GetAll on MemberService where skip/take weren't translated to pageIndex/pageSize.
* fix(core): fix paging in MemberService.GetAll skip/take overload
The skip/take overload was passing skip and take directly as pageIndex
and pageSize to the repository, causing incorrect pagination for any
non-zero skip value. Use PaginationHelper.ConvertSkipTakeToPaging to
correctly convert skip/take to page index/size, matching the pattern
used by all other services.
Also update ContentTypeIndexingNotificationHandler to call the
pageIndex/pageSize overload directly, avoiding the redundant conversion.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Treat empty or whitespace filter as no filter in MemberService.GetAll
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* feat: adds new SiteName setting to cookie options to use as a postfix for oauth cookies
* fix: adds configured postfix to oauth cookies to make them work on multiple sites on same domain (fixes regression)
* fix: addresses an issue where the AuthCookieName option was not respected for the _EXPOSED auth cookie
* Update src/Umbraco.Core/Configuration/Models/BackOfficeTokenCookieSettings.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Moved the "exposed" cookie config to IConfigureNamedOptions
* Add missing constants
* Add unit tests to prove the site postfix
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Backoffice: Fix circular dependencies introduced by PRs #21830 and #21846
Two circular dependency chains were created by the combination of recent
auth rewrites and the auth modal split:
1. `resources ↔ auth`: api-interceptor.controller imported UMB_AUTH_CONTEXT
from auth, while auth.context imported UmbApiInterceptorController from
resources.
2. `server → resources → auth → server`: umb-auth-view.element imported
UMB_SERVER_CONTEXT from the server package, and was reachable from
auth/index.ts via the components barrel added in #21846.
Fix for circular 1: Introduce UmbAuthSignalerContext in resources — a
lightweight bridge context with isAuthorized and requestTimeout(). The
interceptor creates it and owns it directly; auth context consumes it via
consumeContext to bridge its own authorization state and react to timeout
signals. Resources now has zero knowledge of the auth package.
Fix for circular 2: Remove umb-auth-view.element from auth/components/index.ts.
The modal already imports it directly within the package; app-auth.element
uses it as a custom element tag string with no class import needed.
Also updates MAX_CIRCULAR_DEPENDENCIES from 1 → 0 since both known cycles
are now resolved.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Backoffice: Fix circular dependencies - part 2
- Remove auth dependency from server.context.ts: replace eager constructor
side-effect (consumeContext + HTTP fetch) with lazy defer()-based observable
using a backing field flag; fetch only happens on first subscription to
isProductionMode
- Re-add umb-auth-view.element.ts to auth/components barrel (now safe since
server no longer imports from auth)
- Ensure umb-auth-view is registered on the /logout route by adding a
side-effect import in app-auth.element.ts
- Fix JSDoc in auth-signaler.context.ts and api-interceptor.controller.ts to
correctly describe ownership and direction
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Make cookie renewal conditional to fix AllowConcurrentLogins enforcement.
* Reduce SecurityStampValidatorOptions validation interval for users to zero.
* Apply member security stamp options.
* Addressed code review feedback.
* Add separate settings for AllowConcurrentLogins for members and users.
* Clarify comment.
* Further unit tests as suggested by code review.
---------
Co-authored-by: mole <nikolajlauridsen@protonmail.ch>
* Move unattended migrations to a background service, allowing liveness checks to recognise the application as healthy but not yet ready to serve requests.
* Add maintenance protection to surface controllers.
* Add protection for delivery API in upgrading state.
* Add protection for management API in upgrading state.
* Skip dynamic route transformer during Upgrading state (ensures surface controllers with attribute routing are handled in the upgrading state).
* Fix regression in attended upgrade state.
* Addressed code review feedback.
* Tidied up comments.
* Scope readiness health check predicate to Umbraco's own check.
* Fixed failing integration test.
* Removed TestCase from test with only a single case.
* Fix localization for "backoffice"
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Removed UpgradeFailed from OpenApi.json and client-side types.
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* fix(media): ensure sequential creation in media drag-and-drop
When multiple folders are dragged into the Media section, the creation
handlers (#handleFile/#handleFolder) were not awaited in the batch loop.
This caused child items to attempt server operations before their parent
folders were fully created, resulting in 404 errors for subsequent items.
Adding await ensures each item is fully created before the next is
processed, which is required because child items in the flat list
reference parent folder IDs that must exist on the server.
Closes#21837
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Task: Bump @umbraco-ui/uui to 1.17.2
Includes the fix for multi-folder drop DataTransfer staleness
(umbraco/Umbraco.UI#1339).
* qa(dropzone): add unit tests for UmbDropzoneManager folder flattening order
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Protect endpoint that sets user groups for a user collection to prevent elevation of permissions for users.
* Update tests from code review feedback.
* Add alias property to collection config interface
Introduced an 'alias' property to the UmbCollectionItemPickerModalCollectionConfig interface
* render collection element when modal is configured with an alias
* expose a picker modal route
* use collection in use picker
* adjust spacing
* add config option for selectOnly
* dynamic modal alias
* support selectable entity item ref
* wip entity data picker collection + ref and card views
* Add entity collection item card extension type + default elements
* implement user collection item card
* fix selection events
* map to prop
* add prop/attr for href
* add support for which detail properties to show
* update type import
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/item/entity-collection-item-card/entity-collection-item-card.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* import card in correct file
* Fix event listener binding for selection events
* implement disabled property for collection item cards
* init commit of collection item ref extension
* fix imports
* add element interface
* Implement UmbEntityCollectionItemElement interface in item cards
Added the UmbEntityCollectionItemElement interface to document and user collection item card elements for improved type safety and consistency. Updated type exports to include the new interface.
* Update collection item ref to use uui-ref-node
Replaces the placeholder div with a uui-ref-node component, passing relevant item properties and event handlers. Adds dynamic icon rendering using umb-icon.
* Refactor entity collection item elements to use shared base
Introduces a new abstract base class for entity collection item elements, consolidating shared logic for card and ref variants. Updates card and ref element implementations to extend the new base, and refactors extension manifest interfaces for consistency. This improves maintainability and reduces code duplication.
* use class instead of magic string
* Use entity collection item card in picker view
Replaces the placeholder card markup with the <umb-entity-collection-item-card> component, enabling selection and deselection functionality for items in the entity data picker card collection view.
* Update entity item ref to collection item ref
Replaces <umb-entity-item-ref> with <umb-entity-collection-item-ref> in the picker collection view. Adjusts event handlers and select-only logic to improve selection behavior and component consistency.
* utilise ref and card kind for picker views
* introduce ref and card collection view kinds
* Utilise card kind for user collection view
* Add item-specific href support to collection views
Introduces a requestItemHref method to collection contexts for retrieving item-specific hrefs. Updates card, ref, and user table collection views to use these hrefs, enabling dynamic linking for collection items. Refactors user table name column layout to accept href via value prop instead of constructing it internally.
* Update ManifestCollectionView import path
Changed the import of ManifestCollectionView from '../extensions/types.js' to '../view/types.js' to reflect its new location.
* remove unused
* use size medium for entity collection item picker
* use box
* render entity actions
* use edit path builder for user links
* rename method
* Revert "rename method"
This reverts commit 4df577688e.
* Update collection-default.context.ts
* make type lint ignore unused args with an underscore
* temp remove unused
* only make collection vie selectable if there are any registered bulk actions
* don't render name link if there is no href
* fix imports
* Render selection actions only if bulk actions exist
* use selectable state
* Update language-table-collection-view.element.ts
* Update language-table-collection-view.element.ts
* Update card-collection-view.element.ts
* clean up
* Refactor collection views to use shared base class
* refactor(collection): parallelize href fetching and make method private
* docs(examples): update collection example to use card and ref kinds
* docs(examples): add icon property to collection example data model
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/types.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update collection-bulk-action.manager.test.ts
* Removed duplicate and redundant '@typescript-eslint/no-unused-vars' rule definitions, consolidating the configuration to use only 'argsIgnorePattern'.
* Handle missing user href in name column layout
Replaces the user name link with a span when the href property is not provided, preventing broken links in the user table name column layout.
* Update user-table-name-column-layout.element.ts
* pass modal data and value to routable modal
* Update picker-input.context.ts
* support selectableFilter
* scaffolding of a collection text filter extension
* Refactor collection text filter to use API interface
* Fix incorrect tag
* Update types.ts
* Update collection-text-filter.extension.ts
* Add cancelation to debounced search on destroy
* clean up
* add js docs
* two way binding of filter value
* clean up
* Add collection text filter manifest example
Introduced a new filter manifest for the example collection and updated the main manifests file to include it. This enables a text filter extension for the example collection.
* Delete unused element and context
* Update src/Umbraco.Web.UI.Client/src/packages/user/user-group/collection/user-group-collection.context-token.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update user-group-table-collection-view.element.ts
* support search for tree item and collection item pickers
* add spacing between collection ref items
* add margin between picker search result items
* remove spacing after last item
* remove padding in search results
* Update collection-item-picker-modal.element.ts
* move select only logic to collection selection manager
* add tests for collection selection manager
* change to filter label instead of search
* delete unused user grid collection view
* Select-only mode is now only disabled when all items are deselected, rather than on every deselection.
* prepare umb table for pickers
* utilize UmbCollectionViewElementBase in user table collection view
* remove console log
* handle select all and select item from same event
* bulk actions workaround
* add bulk action in collections feature toggle
* remove unused method
* make fields optional to avoid a breaking change
* remove unused import
* fix typescript errors
* adjust search styling
* hide with css
* fix ts errors
* Add modal data support to picker input context
Introduces methods to set and get modal data in UmbPickerInputContext, allowing base configuration for picker modals. Updates modal data handling to merge stored modal data with provided data for both direct picker opening and modal route setup.
* Fix bulk action manager test initialization
Added calls to setConfig in tests to properly initialize the observer before subscribing to hasBulkActions. Simplified the test logic for checking emissions when actions are present.
* Update tree-picker-modal.element.ts
* Update picker-search-result.element.ts
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/umb-collection-view-element-base.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Use ifDefined for modal route in user input button
* Use ifDefined for href binding in entity data picker
* Fix collection alias binding in item picker modal
* wire up user table collection view with selectableFilter
* clean up controller aliases
* Update collection-item-picker-modal.element.ts
* Update collection-item-picker-modal.element.ts
* Add support for collection items with thumbnails
Introduces thumbnail support for collection items by extending models and updating the default collection item card to render thumbnails when available. Adds a new example data source and manifest for items with thumbnails, and updates grid styling for card views.
* Improve card grid responsiveness and card sizing
Added a new CSS variable for large card min-width and updated the card grid to use container queries for responsive column sizing. Adjusted user card styles to ensure proper sizing and layout within the grid.
* add example image to thumbnail example
* introduce generic card component
* wip picker views configuration
* Update manifests.ts
* store value as alias
* Improve handling of missing collection view manifests
Refactors manifest storage to use a Map for faster lookup by alias and updates rendering logic to handle missing manifests gracefully. Now displays a 'not found' message with a remove button for missing collection view manifests.
* add sorting
* rename
* Add confirmation modal before removing picker view
* remove unused
* move collection selectOnly logic to context
* Update user-picker-modal.token.ts
* Add data-source package and integrate in input-entity-data
* Add optional description to collection items
* introduce extension picker data source
* fix problem with shallow copy because of js module in object
* nest manifest data
* Hide pagination when all items are shown
* Add a fallback page size
* merge extension insight code with extension code
* clean up
* Add optional description support to default item ref
* Revert "Add data-source package and integrate in input-entity-data"
This reverts commit e02881e8b6.
* fix post merge
* add input-extension utilizing input-entity-data
* proxy value and selection
* add todo
* temp hardcode config
* add typed config model
* Support multiple extension types in filters
* Use extensionTypes filter and deprecate type
Standardize extension collection filtering by introducing extensionTypes and phasing out the old type field.
* More explicit type name
* Expose allowedExtensionTypes as a @property on UmbInputExtensionElement
* Add text filter support for entity data picker
* remove reexport as this is not public available
* remove unused
* clean up
* clean up
* Add storage and getter for allowedExtensionTypes
* Inline collection view alias and remove constant
* Update vite.config.ts
* Update manifests.ts
* Update extension.picker-data-source.ts
* add tests for extension picker data source
* change to an observable feature config
* make feature object optional
* add unit tests
* Reference condition class directly in manifests
* Simplify collection view types and refactor setup
* remove todo
* implement input-extension on picker views configuration
* Add collection view aliases and defaults
* use correct type
* make name optional
* remove debugger
* delete - merge gone wrong. They are now called figure-cards
* map views to layouts
* Add viewsOverride to enforce collection layout order
* clean up observers if data source type changes
* remove unused
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Auth: Split auth modal into reusable view and thin modal wrapper
Extract the full login screen UI from umb-app-auth-modal.element.ts into
a standalone umb-auth-view.element.ts that extends UmbLitElement. The
modal becomes a thin wrapper that delegates rendering to the view and
bridges onSuccess to _submitModal().
The view defaults userLoginState to 'loggedOut', so the /logout route
renders it directly as a component without needing to cast or configure
properties.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix imports and add readonly to styles in umb-auth-view
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: import directly from main app itself to avoid dynamic imports
* Auth: Reopen timeout modal on dismiss and fix login layout height
Reopen the auth modal in a loop when the session has timed out, so
the user cannot dismiss it without re-authenticating. Fix login
layout height from calc(100vh - 64px) to 100vh with box-sizing.
Height fix credit: Lan Nguyen (PR #19843, closes#19628)
Co-Authored-By: Lan Nguyen <lan@umbraco.dk>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix timeout modal reopen by removing explicit modal key
The do/while loop to reopen the modal on dismiss was failing because
reusing the same key caused a race condition in the modal manager —
appendToFrozenArray replaced the old entry but the container's
_modalElementMap still held the stale key, preventing creation of
the new modal element. Letting each open() generate a unique key
via UmbId.new() avoids the collision entirely.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Prevent auth modal from being dismissed via ESC
Add UmbPersistentModalDialogElement that extends UUIModalDialogElement
and intercepts ESC keydown to prevent the native dialog cancel behavior.
The auth modal now always uses this element via type: 'custom', ensuring
users must complete authentication rather than dismissing the modal.
Also simplifies #showLoginModal by using umbOpenModal() and removing
the do/while reopen loop which is no longer needed.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore: renames file and adds appropriate exports
* Auth: Use AbortController for listener cleanup and add cancel handler
Use AbortController to manage event listeners, preventing accumulation
if _openModal is called multiple times. Add cancel event handler
alongside keydown as a fallback for the native dialog cancel behavior.
Clean up listeners on forceClose.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Lan Nguyen <lan@umbraco.dk>
* Auth: Add minimal PKCE client to replace appauth library (closes#20873)
Introduces UmbAuthClient — a focused OAuth PKCE client that replaces the
forked @openid/appauth library. Uses Web Crypto API for code_challenge
generation and fetch() with credentials:'include' for cookie-based auth.
Zero localStorage usage — PKCE state held in memory.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Rewrite auth context with BroadcastChannel and Web Locks
Merges UmbAuthFlow into UmbAuthContext (single consumer, no export).
Replaces localStorage token storage with in-memory session state.
- BroadcastChannel('umb:auth') for cross-tab auth event coordination
- Web Locks API prevents concurrent refresh token race conditions
- postMessage for popup PKCE code_verifier exchange
- sessionStorage for redirect-flow PKCE state (tab-scoped)
- Adds configureClient() for extension developer DX
- Deprecates authorizationSignal (scheduled for removal in Umbraco 19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Update session timeout controller and SharedWorker
Session timeout controller simplified to take only UmbAuthContext (no
separate authFlow parameter). Observes session$ for timing updates.
SharedWorker now accepts expiresAt timestamp instead of full
TokenResponse. Removes TokenResponse import and TOKEN_EXPIRY_MULTIPLIER.
Sends current session state to new tab connections. Cleans up stale
ports via try/catch on postMessage.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Simplify OAuth completion flow and API interceptor
app.element.ts: Remove authorizationSignal wait pattern —
completeAuthorizationRequest() now handles everything. Remove
umbHttpClient.setConfig() call (moved to auth context constructor).
api-interceptor.controller.ts: Replace deprecated authorizationSignal
observer with isAuthorized transition for retrying 401 requests.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Deprecate external/openid package and storage constant
Delete all 17 appauth implementation files. Replace index.ts with
deprecated type-only stubs for backwards compatibility — external
consumers can still reference types through v18.
Mark UMB_STORAGE_TOKEN_RESPONSE_NAME as deprecated (scheduled for
removal in Umbraco 19).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Update auth context tests for new implementation
Rewrite tests to cover the new auth context API surface including
configureClient(), getOpenApiConfiguration(), URL generation, lifecycle
management, and bypass auth mode.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Update extension template to use configureClient() API
Replace manual getOpenApiConfiguration() pattern with the new
configureClient() method on UmbAuthContext — single line to configure
any @hey-api/openapi-ts client for authenticated Management API calls.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix token refresh not firing and adaptive worker timing
Two bugs fixed:
1. makeRefreshTokenRequest() checked expiresAt > now which always
returned true when the worker fired proactively (before session
expiry). Changed to compare session reference before/after acquiring
the Web Lock — only skips if another tab actually refreshed.
2. getLatestToken() checked the full session expiresAt (with 4x
multiplier) instead of the access token expiry. Split UmbAuthSession
into accessTokenExpiresAt and expiresAt so each check uses the
correct threshold.
Also made the worker's buffer and check interval adaptive for short
sessions (< 2 minutes) — buffer is reduced to 25% of session lifetime
and check interval scales proportionally. Fixes the long-standing issue
where very low timeouts caused the buffer to exceed the session.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Propagate sign-out to all tabs via BroadcastChannel
When a user signs out in one tab, broadcast a 'signedOut' message so
other tabs redirect to the logout page. Previously, other tabs only
cleared their in-memory session but continued showing stale data.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Route setInitialState through Web Lock to prevent duplicate refreshes
setInitialState() was calling refreshToken() directly, bypassing the
Web Lock. Concurrent API calls (via getLatestToken) also triggered
refresh through the lock. This caused duplicate /token calls — one
outside the lock, one inside — leading to rolling refresh token
invalidation races.
Now setInitialState() goes through makeRefreshTokenRequest() so all
refresh calls are serialized by the same Web Lock.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Close timeout modal when another tab refreshes the session
When the session$ observable emits a new session (e.g. from a
BroadcastChannel update after another tab refreshed), close any open
timeout modal. Previously the modal stayed open with its own countdown,
eventually triggering a spurious logout even though the session was
already extended.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Replace SharedWorker with setTimeout and leader-elected modal
Four improvements from a fresh design review:
1. Remove SharedWorker — replaced with a simple setTimeout in the
timeout controller. A 15-60s timer is negligible on the main thread,
and the focused tab's timer is never throttled by browsers.
2. Leader-elected timeout modal — uses Web Lock (ifAvailable) so only
one tab shows the timeout modal. Non-leader tabs set a fallback
timeout. When the leader tab resolves the modal, BroadcastChannel
propagates the result and session$ observer closes stale modals.
3. Peer session request — new tabs ask existing tabs for their session
via BroadcastChannel before attempting a server refresh. Avoids the
400 error on fresh sessions and eliminates unnecessary /token calls
for new tabs in an existing session.
4. Single expiry concept — no more refreshToken vs logout distinction
from the worker. The controller checks remaining time and decides
based on keepUserLoggedIn and whether time has fully expired.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix timeout modal not showing during buffer zone
The #onSessionExpiring guard used isSessionValid() which returns true
during the warning buffer (before full expiry), preventing the modal
from ever appearing. Replace with expiresAt comparison that only skips
if the session was actually refreshed since the check was scheduled.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Set auth header at module level to eliminate timing gap
Move `auth: () => '[redacted]'` into the http-client module-level
config so it's available from first import. Previously, extensions
importing umbHttpClient before UmbAuthContext initialized would send
cookies but not the Authorization header needed by
HideBackOfficeTokensHandler, causing 401s.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Bind default interceptors via configureClient()
configureClient() now creates an UmbApiInterceptorController and binds
the default response interceptors (401 retry, error handling,
notifications) alongside auth config. app.element.ts uses this for
umbHttpClient, giving extensions the same middleware pipeline.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix review findings — stale state, double-broadcast, PKCE cleanup
- clearTokenStorage: also set isAuthorized=false on originating tab
- signOut: inline state clearing to avoid double-broadcasting
sessionCleared + signedOut; fix dead URL base arg; use
window.location.origin consistently
- makeRefreshTokenRequest: compare accessTokenExpiresAt values instead
of object identity for robustness
- completeAuthorizationRequest: only remove sessionStorage PKCE entry
when state matches (preserve valid entry on mismatch)
- umb-auth-client: warn when expires_in is missing or zero
- configureClient: guard against duplicate calls with WeakSet
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(auth): resolve lint errors and Copilot review issues
- Add eslint-disable blocks around OAuth wire-format URLSearchParams keys
(client_id, redirect_uri, grant_type, etc.) — these must use snake_case
per RFC 6749/7636 and cannot be renamed
- Fix optional chaining gap in #openTimeoutModal: store modal ref before
awaiting so modal?.onSubmit() is safe when modalManager is undefined
- Fix popup Promise never settling: poll for authWindowProxy.closed and
resolve (cleanup) when the user closes or cancels the login popup
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Deprecate getLatestToken() — always returns '[redacted]' with cookie auth
With cookie-based auth, getLatestToken() always returns '[redacted]'.
The proactive token refresh it performed is no longer needed since:
- The session timeout controller refreshes proactively via setTimeout
- The API interceptor retries 401s automatically
Internal callers (linkLogin, unlinkLogin, server-event, tryXhrRequest)
now use '[redacted]' directly. getOpenApiConfiguration() is kept as the
recommended API for manual fetch calls.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* docs: adds links to deprecations
* docs: adds deprecation notices
* Auth: Deprecate getLatestToken(), clarify openid stub behavior
- Mark getLatestToken() as deprecated (always returns '[redacted]' with
cookie auth). Points to configureClient() and getOpenApiConfiguration().
- Inline '[redacted]' in internal callers (linkLogin, unlinkLogin,
server-event, tryXhrRequest) instead of going through getLatestToken().
- Update getOpenApiConfiguration().token to return '[redacted]' directly.
- Clarify external/openid deprecation header: data classes remain
functional, handler classes reject because the operations are no
longer possible with cookie-based auth.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: overrides options after applying defaults
* Auth: Supply keepUserLoggedIn from backend via HTML attribute
Instead of fetching keepUserLoggedIn asynchronously from the Management
API after authorization, the server now renders it as a boolean attribute
on <umb-app> from SecuritySettings. This eliminates the timing gap where
the access token could expire before the async preference was fetched,
causing 401s on API calls.
Chain: Index.cshtml → <umb-app keep-user-logged-in> → UmbAuthContext →
UmbAuthSessionTimeoutController. When true, the timeout controller
schedules based on accessTokenExpiresAt (proactive refresh) instead of
expiresAt (full session expiry).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix review findings — message storm, PKCE state, spread order
- Fix BroadcastChannel message storm: completeAuthorizationRequest
was calling #updateSession (which broadcasts sessionUpdate) AND
separately broadcasting 'authorized'. Other tabs receiving 'authorized'
called #updateSession again, cascading N² messages. Split into
#setSessionLocally (no broadcast) and #updateSession (broadcasts).
- Increase PKCE state from 10 to 32 characters for stronger CSRF nonce
(was ~59 bits, now ~190 bits of entropy).
- Fix tryXhrRequest spread order: ...options was last, allowing callers
to accidentally override baseUrl/token. Now baseUrl/token come last.
- Remove unused endSessionEndpoint from UmbAuthClientEndpoints interface
(signOut URL is constructed directly in auth.context.ts).
- Export UmbAuthSession interface for extension developers observing
session$.
- Add clarifying comments for: anonymous UmbApiInterceptorController in
configureClient, refresh_token server contract, Web Lock deduplication
edge case.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix review findings — redirect loop, popup leak, navigator.locks fallback
- Fix redirect loop after code exchange by using force=true navigation
so setInitialState() runs with fresh httpOnly cookies
- Clean up pending popup flows before starting new ones (prevents
pkceHandler/closedPoll leaks)
- Add navigator.locks fallback for environments without Web Locks
- Clear session on timeOut() to prevent stale in-memory state
- Make AuthorizationError constructor params optional (compat fix)
- Remove dead #previousAuthUrl field
- Add clarifying comments on configureClient and peer session timeout
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: Wait for both auth and server contexts before initializing SignalR hub
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Use ifAvailable lock to prevent redundant token refresh across tabs
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Add default Authorization header to umbHttpClient
The hey-api `auth` callback is only invoked when requests include
`security` metadata (which generated SDK functions do automatically).
Direct `.get()`/`.post()` calls lack this metadata, so the
Authorization header was silently omitted. Adding it as a default
header ensures all requests through umbHttpClient trigger the
server-side HideBackOfficeTokensHandler cookie swap.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Use exclusive lock with freshness check for token refresh
Replaces ifAvailable lock with an exclusive lock that queues tabs.
After acquiring the lock, isSessionValid() checks whether another tab
already refreshed — preventing sequential /token calls when timers
fire slightly offset.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(web): configure umbHttpClient baseUrl before server connection
Move auth context creation and configureClient() before
UmbServerConnection.connect() so that the generated SDK calls
(ServerService.getServerStatus/getServerConfiguration) have a
valid baseUrl on umbHttpClient.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(auth): use object reference comparison in token refresh lock
The isSessionValid() check inside the Web Lock used expiresAt (full
session lifetime), which incorrectly skipped proactive refreshes when
keepUserLoggedIn=true. The timeout controller fires based on
accessTokenExpiresAt, but the full session was still valid at that
point, so the refresh was silently skipped — eventually causing 401s.
Fix: capture the session object reference before entering the lock
queue. Inside the lock, compare references to detect whether another
tab broadcast a sessionUpdate while we were waiting. This correctly
deduplicates multi-tab refreshes while allowing proactive refreshes
to proceed.
Also fixes prettier formatting in UmbAuthClient constructor.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: do not assume that any endpoint is authenticated or accepts an Authorization header (this should come from the OpenAPI spec)
* E2E: QA: updated acceptance tests to match the authorization changes in #21830 (#22021)
Updated tests to the updated auth
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* fix: compose user-supplied pickableFilter with internal filter in picker input contexts (#21859)
The openPicker method in UmbDocumentPickerInputContext, UmbMediaPickerInputContext,
and UmbMemberPickerInputContext unconditionally overwrites the user-supplied
pickableFilter with the internal implementation. This prevents package developers
from providing custom filtering logic (e.g., filtering out unpublished items).
The fix composes both filters using a logical AND: the internal filter runs first
(access checks, allowedContentTypes), and if it passes, the user-supplied filter
is also evaluated. This preserves the existing behavior while enabling extensibility.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: extract _composePickableFilters into base UmbPickerInputContext class
Move duplicated filter composition logic from document, media, and member
picker input contexts into a shared protected method on the parent class.
This reduces cyclomatic complexity in each openPicker override and
eliminates code duplication across the three picker contexts.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Rename picker filter helper to _combinePickableFilters
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Added api helper for creating tiptap data type with media folder
* Added ui helper for remove image upload folder
* Updated ui helper for selecting media with name
* Added tests for selecting media link in multi url picker
* Added tests for media picker start node
* Added tests for image upload folder in tiptap data type
* Updated tests for user media start nodes
* Updated tests for user group media start nodes
* Make tests run in the pipeline
* Fixed comment
* Cleaned code
* Added tests for add multiple media start nodes to a user
* Reverted npm command
* Add CSP nonce support for inline scripts
* Add UseUmbracoCspNonceInjection middleware for NWebsec integration.
* Add unit tests for InjectNonceIntoDirective method.
* Add documented CSP rules to local website so any issues that conflict with these rules are surfaced in local development and testing.
* Test formatting.
* Addressed code review feedback.
* Use tag helper for nonce rendering.
* Apply suggestions from code review
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Move CspNonceInjectionOptions into it's own file.
* Reduce clutter in Program.cs in local web project, by moving use of documented CSP to an extension method.
* Trigger build
* Exclude CSP from template but keep in local project.
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Update server-side dependencies to latest patch or minor releases.
* Revert and comment upgrade to MailKit.
* Update Microsoft.NET.Test.Sdk to latest minor.
* Migration, model and repository data access for sorting via a sortable field.
Property editor sortable interface and implementation of JSON stored date fields.
* Add migration to populate sortable field for existing date property data.
* Added unit tests for GetSortableValue on datetime property editors.
* Fixed issues raised in code review.
* Re-use code in base from DocumentRepository to avoid additional call to SetEntitySortableValues.
* Move migration to 17.3.
* Fix merge issue.
* Move around migrations so they are in correct order
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
Co-authored-by: Zeegaan <skrivdetud@gmail.com>
* Check whether picker is in a block. If so, act as with a new content node.
* re-use isNew flag to not increase complexity for the requestRoot function
* remove random whitespace added by visual studio
* remove ternary to reduce complexity
* move check to backend
* update fallback in SiteDynamicRootOriginFinder as well
* Revert "update fallback in SiteDynamicRootOriginFinder as well"
This reverts commit 0a14aa7393.
* Revert "move check to backend"
This reverts commit ca8b0c06da.
* get content workspace context - analogous to document-block-property-value-user-permission.workspace-context.ts. import interface for getIsNew().
* Use getContext.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* feat(content): add shared types and repository interface for audit log kind
Introduces UmbAuditLogTagData types, ManifestWorkspaceInfoAppAuditLogKind manifest
interface, and UmbAuditLogHistoryRepository extending the core audit log repository
with getTagStyleAndText() method.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(content): create shared audit log workspace info app element
Reusable element that receives manifest config with auditLogRepositoryAlias
and optional allowedActions. Uses UMB_ENTITY_WORKSPACE_CONTEXT for entity
unique resolution and createExtensionApiByAlias for repository lookup.
Includes reload event listener, pagination, and user avatar caching.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(content): add auditLog kind definition and manifest registration
Registers the 'auditLog' kind for 'workspaceInfoApp' extension type,
mapping to the shared element. Includes info-app and audit-log manifest
aggregators.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(documents,media): register audit log repos as extensions and add getTagStyleAndText
- Register UmbDocumentAuditLogRepository and UmbMediaAuditLogRepository as
extension manifests with type 'repository' and dedicated alias constants
- Add getTagStyleAndText() method to both repositories implementing the
UmbAuditLogHistoryRepository interface from content package
- Export audit-log types from @umbraco-cms/backoffice/content
- Deprecate getDocumentHistoryTagStyleAndText and getMediaHistoryTagStyleAndText
utility functions (scheduled for removal in Umbraco 19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(documents,media): switch audit log info apps to use shared auditLog kind
- Update document and media info-app manifests to use kind: 'auditLog'
with meta configuration (auditLogRepositoryAlias, allowedActions)
- Include repository manifests in document and media audit-log aggregators
- Wire audit-log kind manifests into the content package
- Deprecate UmbDocumentHistoryWorkspaceInfoAppElement and
UmbMediaHistoryWorkspaceInfoAppElement (scheduled for removal in Umbraco 19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(documents,media): add `api` exports to audit log repositories
Required for the extension registry API loader pattern which expects
either a default or named 'api' export from the module.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Linting
* refactor(content): extract renderHistoryItem to reduce cyclomatic complexity
Splits the repeat callback out of #renderHistory into a dedicated
#renderHistoryItem method, reducing the method's cyclomatic complexity
below the threshold of 9.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(content): throw error when workspace entity unique is missing
Restores fail-fast behavior for missing entity unique in audit log
requests, matching the original document/media implementations.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor(audit-log): move getTagStyleAndText to UmbAuditLogRepository as optional method
Removes UmbAuditLogHistoryRepository interface and adds optional
getTagStyleAndText() to UmbAuditLogRepository in core. Moves tag
types to core/audit-log and adds a default type parameter.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(audit-log): export repository alias constants from package entry points
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Linting and tidy-up
* Fixes canceled Rollback modal error
* Removed the `allowedActions` property
* feat(content): formalize `auditLogAction` extension type
Add proper TypeScript interfaces, default kind, and dedicated element
for the `auditLogAction` extension type, replacing the previous
untyped usage that relied on `ManifestEntityAction`.
- Define `ManifestAuditLogAction` and `MetaAuditLogAction` interfaces
- Create `umb-audit-log-action` element using `uui-button` (suited for
the audit log info-app header, unlike `uui-menu-item`)
- Register default and contentRollback kind manifests
- Move contentRollback audit-log-action kind to the content module
- Separate document-specific audit-log-action manifest into its own file
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Dispose event listener created in InMemoryAssemblyLoadContextManager.
* Use using to dispose ICryptoTransform in MemberPasswordHasher.
* Dispose CancellationTokenSource in DatabaseServerMessenger.
* Dispose deserialized JsonDocument in CacheInstructionService.
* Use try/finally to ensure dispose.
* quote table, column and alias names with SqlSyntaxProvider methods in raw sql
* refactoring private methods into new file as internal methods,
refactor new extensions into another file
* refactor GetAlias method
* Double check the change
* improve code health
* change new static classes into public static partial class NPocoSqlExtensions
* resolve some Copilot review suggestions
* revert Copilot suggestion because it decreases code health
* revert test
* compare in with LOWER, change two methods from private to protected in UmbracoDatabaseFactory
* revert Query.cs in this PR
* Refactor for code health and fixing raw sql
* divers small issues fixed
* refactor two methods to respect the DRY pricipal
* update IQuery interface
* clean up
* revert refactoring for CodeScene
* delete obsolete Test
* rename method
* remove new methods and updates, which are not relevat for this PR
* prepare for additional states in the future
* don't mix string building methods
* fix SQL injection danger
* fix test for reverted methods
* another SqlSyntax issue
* fix update
* fix reverted changes
* restore change for this PR
* restore change for this PR
* fix merge bug
* update formating
* extend ISqlSytax for database independent autoIkrement feature
* fix DTOs, extend ISqlSyntax
* fix tests
* revert
* updates
* diverse SqlSyntax and NPoco related updates for custom databse providers
* fix names
* squash merge v173/20453-DTO-attributes-fixed into v173/20453-final-sql-syntax-fixes
* merge
* add default implementation to interface
* fix tests
* fix PrimaryKey for multi columns
* test fix
* Resolve the issues with SqlSyntaxProvider for SQLite. If executed correctly, a single test would reveal the problem.
* add another test
* revert changes which causes even more issues
* fix SQL syntax
* fix column const naming
* ensure column const names from v17.2
* add comment for change
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeTemplateDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* resolve review comments
* Make ReferenceMemberName consistent across all DTOs (use constants defined on the referenced DTO).
* Ensure [ExplicitColumns] attribute exists on all DTOs.
* Ensure we consistently use PrimaryKeyColumnName over PrimaryKeyName.
* Fix further inconsistency to use only TemplateNodeIdColumnName.
* Fixed trailing whitespace.
* Restored primary key constraint name on ContentVersionCleanupPolicyDto (it doesn't seem in scope of PR to remove this).
* Removed the confusing PrimaryKeyColumnName constants for multi-column primary key DTOs where the constant refers to only one of the key columns.
* ReferenceMemberName needs to be a C# property name, so it's safer to use nameof.
* Comment fix.
* Amended accessibility modifiers.
* revert unnecessary changes
* revert unnecessary changes
* revert unnecessary changes
* fix SQLite escape variants
* fix typo
* simple (typo) fixes of Copilot review comments
* solve another Copilot review comment
* improve comments and minimise changes
* add an detailed change comment
* resolve review and revert all integration test. Tests changes will be done in the PostgreSqlProvider-npocp branch like some unit tests.
* remove InsertWithSpecialAutoIncrement()
* update WhereIn() for case sensitive databases
* fix special char in test comment
* throw exception for invalid values
* remove values type check
* add extra check
* resolve review comments
* revert more changes with question
* refine method SiblingsSql of EntityRepository, add another AndSelect() method overload to NPocoSqlExtensions.
* resolve review
* fix replacement
* trigger new pipeline build
* trigger new pipeline build
* Added comment explaining why withAlias: false is needed.
* Add additional tests around sibling retrieval.
* Add tests for the AndSelect overloads.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Content Rollback: Abstract document rollback into reusable entity action and modal kinds
Create shared `rollback` entity action kind and modal kind in the content package,
enabling reuse for upcoming entity types (e.g., Elements in v18). The document
rollback now uses these kinds via manifest meta, while old APIs are preserved
with @deprecated annotations for backward compatibility.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Content Rollback: Address PR review feedback
- Add validation for manifest meta in rollback modal element, throwing
descriptive errors if rollbackRepositoryAlias or detailRepositoryAlias
are not configured
- Remove non-null assertions in favor of validated manifest access
- Fix deprecated requestVersionByDocumentId to delegate through the
generic requestVersionById interface method
- Remove unused requestVersionByDocumentId deprecated method (original
method was requestVersionById, not requestVersionByDocumentId)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Renamed "rollback" to "contentRollback"
for class names and manifest kind.
* Content Rollback: Move repo aliases to entity action meta; remove modal kind
Move rollbackRepositoryAlias and detailRepositoryAlias from the modal
kind manifest meta to the entity action meta, passing them as modal
data. Remove the contentRollback modal kind entirely and register the
modal element directly. Introduce UMB_CONTENT_ROLLBACK_MODAL token so
the entity action no longer needs a configurable rollbackModalAlias.
Deprecate document-level modal constants in favor of content-level ones.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fixed linting errors
* eslint missed an export! 🤦
* refactor(backoffice): rename UMB_ENTITY_ACTION_ROLLBACK_KIND_MANIFEST to UMB_ENTITY_ACTION_CONTENT_ROLLBACK_KIND_MANIFEST
Address PR review feedback to include "Content" in the manifest constant name for consistency.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Create item endpoints that return ancestor IDs for a given collection of entity IDs.
* Return item models instead of just IDs.
* Use async methods.
* Use NamedItemResponseModel for container ancestor endpoints.
* Simplify the usage of ItemAncestorService - use less assumptions about structure and use generic mapping for basic response models.
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Optimize (memory usage, database storage, and processing time) document URL and alias cache for invariant documents.
Store invariant content with NULL languageId instead of duplicating records for each language.
* Additional integration tests verifying aspects of changed functionality.
* Implement and test that URLs and aliases are updated when a content type changes from variant to invariant or vice versa.
* Tidied up migration.
* Corrected file name.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Further updates from code review, resolved warnings.
* Use rebuild key defined in constant in migration.
* Handle possibility of custom URL providers generating different URL segments per culture.
* Resolve breaking change.
* Handling breaking change in DocumentUrlDto.
* Tidied up code comments
* Fix issue where URL aliases on variant content with a shared property were not being recorded.
* Tidy up comment.
* Fix breaking change in nullability.
* Fix breaking change in nullability (2).
* Revert "Fix breaking change in nullability (2)."
This reverts commit c77a37c855.
* Fix failing integration tests.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Updated ui helper for verify the file uploads
* Updated tests due to test helper changes
* Updated tests for block due to UI changes
* Added comment for the failing tests
* Added preview helper
* Added preview helpers
* Added preview tests
* Updates based on comments
* reinitialize the preview locators for the pop up preview page
* Cleaned up based on comments
* Update smokeTest command in package.json
* fix(core,api,web): fix backoffice UI errors on notification cancellation
- Fix ContentTypeServiceBase.DeleteAsync() to use PublishCancelableAsync
directly instead of delegating to the sync Delete() method, which
silently swallowed cancellation and always returned Success.
- Extract shared deletion logic into private PerformDelete() method
to keep both Delete() and DeleteAsync() DRY.
- Mark ProblemDetails with notificationsDeliveredViaHeader extension
when Umb-Notifications header carries event messages, preventing
the frontend from showing duplicate error toasts.
- Add notificationsDeliveredViaHeader to UmbProblemDetails type and
skip redundant ProblemDetails notification in try-execute controller.
- Add integration test for DeleteAsync cancellation detection.
* fix(core,api,web): fix backoffice UI errors on notification cancellation
- Fix ContentTypeServiceBase.DeleteAsync() to use PublishCancelableAsync
directly instead of delegating to the sync Delete() method, which
silently swallowed cancellation and always returned Success.
- Extract shared deletion logic into private PerformDelete() method
to keep both Delete() and DeleteAsync() DRY.
- Mark ProblemDetails with notificationsDeliveredViaHeader extension
when Umb-Notifications header carries event messages, preventing
the frontend from showing duplicate error toasts.
- Add notificationsDeliveredViaHeader to UmbProblemDetails type and
skip redundant ProblemDetails notification in try-execute controller.
- Add integration test for DeleteAsync cancellation detection.
fix: #12636
* fix(core): reduce PerformDelete arguments and trim LOC
Address CodeScene quality gate failures:
- Reduce PerformDelete from 5 to 4 parameters by resolving
EventMessages internally via EventMessagesFactory.Get()
- Trim lines of code to stay within the 1000 LOC threshold
* refactor(core): extract obsolete container methods into partial class
Split ContentTypeServiceBase into two partial class files to address
CodeScene's "Lines of Code in a Single File" quality gate (1007 > 1000).
The #region Containers block was chosen for extraction because all its
methods are already marked [Obsolete] and scheduled for removal in
Umbraco 18, replaced by IContentTypeContainerService and
IMediaTypeContainerService. The region is fully self-contained with no
inbound calls from the rest of the class.
This is a compile-time only change — partial classes produce identical
IL output. No public API, behavior, or binary compatibility impact.
* Revert "refactor(core): extract obsolete container methods into partial class"
This reverts commit 6fd8fd23f6.
* Pass eventMessages from the caller into PerformDelete instead of being re-obtaining from the factory.
* Use try/finally in test to ensure clean-up.
* Restore removed comments.
* Revert client-side updates.
* Revert client-side updates (2).
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add aria-label and name to search input for accessibility
- Add aria-label attribute to search input using localized placeholder text
- Add name attribute ("search-input") to provide form field identification
- Fixes Google Console warning about missing id/name on form field
- Improves WCAG 3.3.2 compliance (Labels or Instructions)
- Improves WCAG 2.5.3 compliance (Form input identifiable names)
Closes#2193
* Reused localized label
* Tidy-up/linting
---------
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Auto-generate HMAC secret key for imaging on new installs.
* Address code review feedback.
* Log results of configuration operations.
* Refactored to use the Attempt pattern.
* Allow custom folder types when creating from media picker.
* Adjust selector padding.
* Corrected call to await.
* Addressed feedback from code review.
* Set entity unique before scaffold processing to fix collection view for new media folders.
* Instead of moving setUnique() earlier in the provider, fix the consumers to observe the unique observable rather than reading synchronously.
* Addressed code review point on context observation.
* implement satisfies type check
* minor refactor
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Prevent save of partial view file when using runtime production mode, and verify for partial views and templates with integration tests.
* Display warning when templates and partial views are not editable in the backoffice.
* Share styles.
* Validate at the partial view API whether updates are allowed based on production runtime mode.
* Add similar checks for templates, handling case where metadata updates are allowed.
* Add integration tests for verifying behaviour in production mode.
* Fix the breaking changes on the constructor of the service classes.
* Use IOptions (we don't need live updates for this setting).
* Addressed code review feedback.
* Add IsProductionMode private property on both updated services.
* Move create template check to validate method.
* Remove entity actions create/delete/rename for templates and partial views whilst running in production mode.
* Addressed code review feedback.
* include server in condition name
* move tag to bottom right corner of workspace
* introduce info modal
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Tiptap Table: fix popover positioning for row and column grips
Refactored the table extension to use a proper container structure
and separate popovers for row and column context menus.
Key changes:
- Added UmbTableView with block container, inner table container,
widgets container, and overlay container structure
- Created TableHandlePlugin to manage grips and popovers centrally
- Changed from single shared popover to separate row and column
popovers, fixing the issue where column menu always appeared
at the first column position
- Updated CSS styles to support the new container structure
- Added proper cleanup when tables are removed from the editor
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Deprecates `UmbBubbleMenu` extension
No longer used internally.
There were issues with the popover and Tiptap editor state.
* Tiptap Table node-view refactor
* Exports `UmbTableView`
* Handles `mouseleave` event
* Adds readonly guard and dynamic grip offset for table handles
Prevents grips/popovers from appearing and dispatching transactions
when the editor is in readonly mode. Replaces hardcoded 16px container
offset with dynamic bounding rect computation to stay in sync with CSS.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Uses TableMap for cell indices instead of DOM child indexes
Resolves cell row/column via ProseMirror position resolution and
TableMap.findCell, which correctly handles merged cells (colspan/rowspan)
instead of relying on DOM child indexes.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Improvement: Use `when` callback parameter in tiptap toolbar disabled button
Use the callback parameter from Lit's `when` directive instead of a
non-null assertion to access the icon value.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Feature: Add `actionButton` kind for tiptap toolbar extensions
Create a new `actionButton` kind that uses the disabled button element,
replacing manual `element` overrides in the Unlink, Undo, and Redo
toolbar manifests.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Improvement: Add dedicated element for `actionButton` tiptap toolbar kind
Addresses review feedback by creating a proper `umb-tiptap-toolbar-button-action`
element for the `actionButton` kind instead of reusing the `-disabled` element.
- Uses `api.isDisabled()` for the disabled state (not `!isActive`)
- Types manifest correctly via generic on base class
- Makes base `UmbTiptapToolbarButtonElement` generic so subclasses can
specify their manifest kind
- Deprecates `umb-tiptap-toolbar-button-disabled` (scheduled for removal in v19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Improvement: Add base API class for `actionButton` toolbar extensions
Introduces UmbTiptapToolbarActionButtonApiBase with a default isDisabled
implementation that returns !isActive(editor), so third-party extensions
get meaningful disabled state without needing to override isDisabled.
Updates undo, redo, and unlink APIs to use the new base class, removing
their redundant isDisabled overrides. Adds a comment explaining the
implicit re-render dependency in the action button element.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* fix(media): display filename in upload field preview
Add visible filename text to the file and image upload field preview
components. Previously, the file preview only showed an icon and the
image preview only used the filename as invisible alt text.
The filename is extracted from the File object when available (blob
URLs during upload), falling back to the last path segment for
persisted server paths.
Closes#21587
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(media): display filename in audio, video, and SVG upload previews
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(media): move filename display to parent upload field with file-info bar
Move filename rendering from 5 individual preview components into the
parent input-upload-field element. The filename and remove action now
share a bordered bar below the preview. Filename is plain text during
upload (blob URL) and a clickable link to the file when saved.
Reverts preview components to their original state (preview only).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* style updates
* link style adjustment
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Add support for running website without backoffice.
* Add support for running delivery API without website or backoffice.
* Reverted unncessary idempotent checks on individual builder extensions.
* Integration tests for service registrations.
* Integration HTTP tests for service registrations.
* Tidy up and code review feedback.
* Remove unnecessary null check.
* Ensure models builder references are added to attempt to resolve the deliver API setup.
* Allow folder selection in media entity picker
* Also handle user and user group media root node picker.
* Allow file selection for users and user groups, fixing failing E2E test.
* Changed media start nodes for user/user group to select folders only
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Add support for member sorting by member type.
* Make the backoffice member table sortable by the supported fields.
* Sort member groups by name.
* Fixed linting issue.
* Use UmbDirection for sort direction
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Fix missing <title> attribute for Icons in document types in backoffice
* Move the title attribute to uui-button from umb-icon.
* Removed color option from lable and title. Added prefix "Change icon:" in the title. Prefix managed from the localization.
* Improve icon tooltip accessibility and i18n in content type header
- Add defensive check in #iconTitle to avoid "undefined" text when icon is unset
- Move colon separator from translation strings to component template
- Use consistent label for both title and aria-label on icon button
- Add Spanish and Italian translations for changeIcon key
* Fix failing test by using an exact match for a label.
---------
Co-authored-by: Pasang Tamang <45009265+pasangtamang@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Document Types returns a list of allowed parent keys
* Media types included
* Add selectable filter for duplicate action based on allowed parents.
* Add optional selectable filter provider support to move action.
* Add selectable filter provider for move action in documents.
* Add selectable filter provider for move action on media.
* Optimize filter providers by using allowedAsRoot property directly.
* Refactor document move action to use repository for selectable filter.
* Move media filter logic from provider to repository .
* Centralize allowed-parent logic in data sources.
* Remove document item lookup from duplicate action.
* Simplify custom filter assignment in move action.
* Remove unused import.
* Rename getSelectableFilter method in document duplicate action..
* Refactor move to action for documents.
* Refactor of media move to action.
* Refactor duplicate action and remove unused imports.
* Clean up.
* Use .js extension for media tree type import
* Export move action and fix imports.
* add interfaces for type safety
* local implementations
* make linter happy
* make linter happy
* Filter out current node in MoveTo action
* Return error instead of throwing on fetch
* Use typed getters for structure data sources
* remove unused
* Add UmbTreeItemModel typing to move-to actions
* align paramater naming
* Defer move repository lookup until after modal
* Fetch type data concurrently with Promise.all
---------
Co-authored-by: NillasKA <kramernicklas@gmail.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Dont blow up GetTestOptions when inside testfixtures
* Dont blow up Reference resolving when working with proxies
* Improve GetAssemblyFolders nullability
* More verbosity
* Messy implementation of documenttypes and datatypes
* Formatting and move service injection to constructor
* cleanup and bubble up new constructor
* Allow folder or item only searches
* feedback pr & subsequent refactoring
* Apply review suggestions
* Update openapi file
* Used constant, resolved minor layout warnings.
* Fix parent key lookup in tree search to check both folders and items.
* Remove TreeItemKind.None from flags enum.
* Add TODOs for removing the default implementation on the interfaces.
* Add permission integration tests.
* Update OpenApi.json.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Skip empty strings in repeatable textstring validation and persistence.
* Override RequiredValidator for repeatable textstring to treat all-empty arrays as no value.
* Updated ui helper for add block list button
* Make AllowEditInvariantFromNonDefaultIsTrue tests run in the pipeline
* Removed .skip since the issue is resolved
* Fixed tests for submit an empty URL in RTE property
* Make TiptapToolbar tests run in the pipeline
* Reverted npm command
* Claude's suggestions
* Rewrite for tags based hybrid cache eviction and optimize the converted, in-memory cache eviction
* Replicate cache invalidation/flushing optimizations for the media cache service
* Do not perform Examine re-indexing for "other" changes on content types
* Clean up TODOs
* Use configured batch size for indexing, and use cached structure for checking publish status
* Default implementations of new interface methods to prevent breaking changes
* Clean out more TODOs
* Refactor logic to extension methods
* Add missing notification handlers to cache tests
* Add additional test coverage.
* Remove OnChange from settings for transient notification handler.
* Adds a migration to clear the hybrid cache to ensure all items are tagged by content type.
* Clear all converted content on type change in auto models builder mode.
* Apply the same fix for data type updates.
* Apply the same fix for data type updates (2).
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Changed the modal size to medium data type picker modals.
* Updated the icon and label alignment so that icon always align vertically top and label in each starts from same position.
* Linting
* Adds `justify-items: center` for "Create new" button icon
---------
Co-authored-by: Pasang Tamang <45009265+pasangtamang@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Add pagination to the member group picker.
* Linting
...and use of `when` directive ;-)
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Move testhelpers and builder into the acceptance test project
* Updated imports in tests
* Updated readme
* Updated postinstall to exclude setting up config
* added a cleanup when npm packing
* update tsconfig path mapping to @umbraco/acceptance-test-helpers
* Added dist to git ignore
* Adds separate README files for npm and GitHub
README.md: contributor-focused (test docs)
README.npm.md: consumer-focused (package docs)
cleanse-pkg.js swaps them during npm pack
* Updated to swap READMEs on npm pack. So the consumer README is the one being released
* Add npm publish pipeline for @umbraco/acceptance-test-helpers
* Configure package.json for npm publishing as @umbraco/acceptance-test-helpers
* Updated missing imports
* Cherrypicked helper changes
* Updated tests
* Updated name of builder
* added tslib
* Fixed test
* Renamed
* Add nbgv version step for test helpers npm package
* Fixes based on comments
* More fixes
* Removed unnecessary imports
* Fix naming of storage_state_path
* Added recommend for storage state
* Create console file if not present
* simpler and more consistent css for block list and block single
* adjust spacing only for default views
* adjust inline and support for Block Grid
* simplify gap css for Grid Entries
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Create new folder on enter in media picker
* Move CSS properties and change value for placeholder.
* Add localization key for labels and placeholder.
---------
Co-authored-by: Emma L Garland <emmagarland77@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Adding CPM into Umbraco Project
* Adding CPM for UmbracoExtension
* remove CPM from umbraco templates
* remove change from readme
* update readme for umbracoproject
* Adding CPM options to Umbraco Project and Umbraco Templates
* update name param
* make central to default option
* Update templates/UmbracoExtension/Umbraco.Extension.csproj
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update templates/UmbracoExtension/.template.config/template.json
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update templates/UmbracoProject/.template.config/template.json
Co-authored-by: Andy Butland <abutland73@gmail.com>
* add PackageManagement into Visual studio display
* Apply suggestions from code review
* Fix ascii art and typo.
* Remove trailing commas in template.json files.
* Aligned casing and grammar between package management choices.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Cleaned up
* Make ScheduledPublishing tests run in the pipeline
* Updated npm command
* Increased timeout
* Updated npm command
* Addec console log to test in the pipeline
* Make tests run in the pipeline
* Removed step to verify that the document is published since it doesn't work in the pipeline - only works locally
* Update npm command
* Fixed tests
* Fixed comments
* Removed unnecessary comments
* Revert npm command
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Ensure local cache instructions count towards last synced ID
* Add obsoletion message to the interface.
* Fixed failing integration tests, then refactored them so they call and test the non-obsolete method.
* Rework the solution to retain existing functionality
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Show correct URLs for invariant content under non-default language domains.
* Use configured domain hosts instead of request host for fallback URL filtering.
* Addressed feedback from code review.
* Fixed code warnings.
* Update file references in integration test csproj.
* Simplify invariant URL culture filtering by determining cultures upfront
Instead of querying all cultures and post-processing to remove irrelevant
URLs, determine the relevant cultures before the loop by checking which
domains are assigned to the content's ancestor path.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Show correct URLs for invariant content under non-default language domains.
* Use configured domain hosts instead of request host for fallback URL filtering.
* Addressed feedback from code review.
* Fixed code warnings.
* Update file references in integration test csproj.
* Simplify invariant URL culture filtering by determining cultures upfront
Instead of querying all cultures and post-processing to remove irrelevant
URLs, determine the relevant cultures before the loop by checking which
domains are assigned to the content's ancestor path.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Update GetContentSchedulesByIds to retrieve data in groups to avoid overrunning the SQL parameter count.
* Protect against duplicate retrieval if duplicate IDs are provided.
Removed explicit 260-character path length checks from PhysicalFileSystem.GetFullPath and deleted associated unit tests. Updated tests to focus on path normalization and validity, and improved path assertions for clarity and cross-platform compatibility. No longer enforce or test for legacy Windows path length restrictions.
* Add data-source package and integrate in input-entity-data
* Add optional description to collection items
* introduce extension picker data source
* fix problem with shallow copy because of js module in object
* nest manifest data
* Hide pagination when all items are shown
* Add a fallback page size
* merge extension insight code with extension code
* clean up
* Add optional description support to default item ref
* Revert "Add data-source package and integrate in input-entity-data"
This reverts commit e02881e8b6.
* fix post merge
* add input-extension utilizing input-entity-data
* proxy value and selection
* add todo
* temp hardcode config
* add typed config model
* Support multiple extension types in filters
* Use extensionTypes filter and deprecate type
Standardize extension collection filtering by introducing extensionTypes and phasing out the old type field.
* More explicit type name
* Expose allowedExtensionTypes as a @property on UmbInputExtensionElement
* Add text filter support for entity data picker
* remove reexport as this is not public available
* remove unused
* clean up
* clean up
* Add storage and getter for allowedExtensionTypes
* Inline collection view alias and remove constant
* Update vite.config.ts
* Update manifests.ts
* Update extension.picker-data-source.ts
* add tests for extension picker data source
* change to an observable feature config
* make feature object optional
* add unit tests
* Reference condition class directly in manifests
* clean up observers if data source type changes
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* UmbracoExtension template: Use runtimeConfigPath for automatic auth
Use hey-api's runtimeConfigPath to pre-configure the generated client
by copying umbHttpClient's config (baseUrl, credentials, auth) at
initialization time. This eliminates the need for entrypoint auth setup
via consumeContext/getOpenApiConfiguration.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: updates extension with newly generated SDK files
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Keep track of rebuilding in memory
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Remove comment
* Revert back to original with lock
* Apply suggestion from @Zeegaan
* Remove unused
* Adress review comments
* Improve in-memory rebuild tracking for index rebuilder.
* Add cross-server rebuild status tracking via ILongRunningOperationService.
* Ensure index is used in operations, to allow rebuild of different indexes concurrently.
* Use Task.Delay.
* Resolve breaking change in constructor.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add data-source package and integrate in input-entity-data
* Add optional description to collection items
* introduce extension picker data source
* fix problem with shallow copy because of js module in object
* nest manifest data
* Hide pagination when all items are shown
* Add a fallback page size
* merge extension insight code with extension code
* clean up
* Add optional description support to default item ref
* Revert "Add data-source package and integrate in input-entity-data"
This reverts commit e02881e8b6.
* fix post merge
* add input-extension utilizing input-entity-data
* proxy value and selection
* add todo
* temp hardcode config
* add typed config model
* Support multiple extension types in filters
* Use extensionTypes filter and deprecate type
Standardize extension collection filtering by introducing extensionTypes and phasing out the old type field.
* More explicit type name
* Expose allowedExtensionTypes as a @property on UmbInputExtensionElement
* remove reexport as this is not public available
* remove unused
* clean up
* clean up
* Add storage and getter for allowedExtensionTypes
* Inline collection view alias and remove constant
* Update vite.config.ts
* Update manifests.ts
* Update extension.picker-data-source.ts
* add tests for extension picker data source
The touchstart handler on the image cropper focus setter needs to call
preventDefault() to prevent scrolling during focal point drag. Use Lit's
@eventOptions({ passive: false }) decorator to explicitly declare this,
resolving the browser warning about non-passive event listeners.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* For indexing in the RTE, replace all HTML tags with spaces to make sure wqord boundaries are preserved. Closes#21778
* Trim the returned string and adjust test cases to match new expected output #21778
* Address review comments:
- Updated XML docs
- Removed trimming in unit tests
- Moved HTML strip implementation to an extensions method
* Removed redundant regexes
* Address comment formatting
* Address failed tests by not replacing multiple characters if the replacement is String.Empty to preserve existing behavior
* Remove unnecessary partial and using.
* Add tests for introduced overload of StripHtml, fix found issues with replacement regex, then optimised by removing second regex and replaced with string operations.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fix umbracoUrlName not working on multi sites
* update documentUrlServiceTests
* Use "is false" for false comparison
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* test: add comprehensive test coverage for BlockEditorVarianceHandler
- Add tests for AlignPropertyVarianceAsync method (collection alignment)
- Add tests for AlignedExposeVarianceAsync method
- Add edge case tests for segment variations
- Add tests for multiple items and deduplication scenarios
- Remove TODO comment
Fixes#21706
* refactor: reduce code duplication in BlockEditorVarianceHandler tests
- Add CreateBlockListValue helper method to eliminate repeated setup code
- Remove redundant test cases to reduce duplication
- Consolidate similar tests while maintaining essential coverage
Fixes code duplication issues reported in PR #21706
* fix: correct assertion in AlignPropertyVarianceAsync_Removes_NonDefault_Culture_Values test
When culture variance is disabled (ContentVariation.Nothing), the culture
should be set to null, not preserved. This matches the behavior tested in
Removes_Default_Culture_When_Culture_Variance_Is_Disabled test.
* fix: always deduplicate expose entries in AlignExposeVariance
Deduplication should always occur at the end of AlignExposeVariance,
even when no alignment is needed. This ensures duplicate expose entries
are removed regardless of whether variance alignment occurred.
* fix: remove expose entries when ContentData is missing
Expose entries that don't have matching ContentData should be removed
from the expose list. This ensures data consistency and prevents orphaned
expose entries.
* test: add 8 additional test cases for BlockEditorVarianceHandler
Adds comprehensive test coverage for:
- Culture assignment scenarios
- Segment variation handling
- Multiple ContentData items
- Edge cases (missing element types, no matching expose)
- Variation matching scenarios
* refactor: eliminate code duplication in BlockEditorVarianceHandler tests
Extract common test patterns into helper methods:
- CreatePropertyValues: Creates property values from configuration tuples
- CreateBlockPropertyValues: Creates block property values with alias/culture/segment
- CreateBlockItemVariations: Creates block item variations from tuples
- ExecuteAlignPropertyVarianceAsync: Executes AlignPropertyVarianceAsync with common setup
- ExecuteAlignedExposeVarianceAsync: Executes AlignedExposeVarianceAsync with common setup
- ExecuteAlignExposeVariance: Executes AlignExposeVariance with common setup
- SetupAlignedExposeTest: Sets up test data for AlignedExposeVarianceAsync tests
This eliminates copy-pasted code patterns across multiple test methods.
* refactor: eliminate duplication in AlignedPropertyVarianceAsync tests
Extract common test setup into ExecuteAlignedPropertyVarianceAsync helper method.
This eliminates duplication in:
- Assigns_Default_Culture_When_Culture_Variance_Is_Enabled
- Removes_Default_Culture_When_Culture_Variance_Is_Disabled
- Ignores_NonDefault_Culture_When_Culture_Variance_Is_Disabled
- AlignedPropertyVarianceAsync_Returns_As_Is_When_Variation_Matches
* fix: add missing using statements for Task, IList, IEnumerable, Func
* fix: correct Assert.ThrowsAsync usage - await the task when accessing exception
* fix: await Assert.ThrowsAsync directly to get exception
* remove: AlignPropertyVarianceAsync_Throws_When_PropertyType_Is_Null test
* fix: mock should return null for unknown content types in AlignExposeVariance test
* Revert production code changes - keep only test additions
* Remove bug-fix verification tests - moved to PR #21801
* refactor: consistently use CreateBlockListValue helper in all tests
* test: restore AlignExpose_Can_Handle_Variant_Element_Type_With_All_Invariant_Block_Values test
* docs: clarify why mock returns null for unknown content types
* refactor: use configuration class to reduce argument count in CreateBlockPropertyValues
* fix: add missing closing brace for Assert.Multiple block
* fix: remove leftover merge conflict marker
* fix: remove duplicate method definitions
* Remove unused code and usings. Encapulate BlockPropertyValueConfig. Fix code warnings.
* Standardise test naming, order of methods and use of Assert.Multiple.
* Complete test coverage with additional tests for AlignedExposeVarianceAsync.
---------
Co-authored-by: root <root@dragon.second>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Ensure document status shown in the Infor workspace view is up to date after unpublish and save/publish operations.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Further feedback from code review.
* Fix false-positive pending changes after save and publish by ensuring the property value preset builder reconstructs objects with the same property key order.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Add media navigation support to PublishedContentQuery
Introduced IMediaNavigationQueryService as a dependency and updated constructors to resolve it. Refactored ItemsAtRoot to accept a navigation query service, enabling MediaAtRoot to retrieve root media items via navigation queries. ContentAtRoot and MediaAtRoot now use the appropriate navigation query service for root item retrieval.
* Add IMediaNavigationQueryService support to content query
Extended PublishedContentQuery and ContentFinderByConfigured404 to accept and use IMediaNavigationQueryService alongside IDocumentNavigationQueryService. Updated constructors and service registrations to ensure both navigation services are available for enhanced content and media navigation scenarios.
* Add obsolete constuctors and expand PublishedContentQuery tests
Introduce [Obsolete] constructor overloads for PublishedContentQuery and ContentFinderByConfigured404 to support legacy usage, scheduled for removal in Umbraco 19. Refactor ItemsAtRoot for clarity. Significantly expand PublishedContentQueryTests with comprehensive unit tests covering constructor validation, Content/Media overloads, root item retrieval, and search functionality, including paging, ordering, and culture context. Add test helpers and mocks to improve test coverage and reliability.
* Fixes to constructor overloads.
* Re-organise tests into unit and integration (so the former, that don't need integration setup, will run more quickly).
* Remove low value integration tests.
---------
Co-authored-by: Fabian Beier <Fabian.Beier@aa-g.de>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* refactor to use the collection item extension point
* Add actions slot to media collection item card
* Set actions slot button background in media card
* Update src/Umbraco.Web.UI.Client/src/packages/media/media/collection/media-collection.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix GUID read repository cache key collision with int-keyed repositories.
* Remove GUID read repository for templates.
* Ensure GUID read repository cache keys are invalidated.
* Further optimisation of by GUD GetAll reads.
* Move default repository cache timespan to a centralised constant.
* Further use of centralised constant.
* Add GetGuidKey<T>(Guid id) and update callers to use it.
* Ensure package migration steps only run once by moving the override of IgnoreCurrentState to true to the derived AutomaticPackageMigrationPlan, where it's needed.
* Add integration test to verify the fix.
* Fix failing integration test (the test migration plans were leaking outside of the new test, and being picked up by the DI container for other tests.
Fix EntityTypeContainerService.UpdateAsync using wrong AuditType
UpdateAsync was logging AuditType.New instead of AuditType.Save,
causing container update operations to be recorded as creations
in the audit log.
* Be explicit about creating foreign key constrains with check (already the default).
* Add a migration to attempt to ensure that all constrains a trusted.
* Updated name of migration class.
* Ensure long timeout for migration.
* Update BulkInsertRecordsSqlServer to use SqlBulkCopyOptions.CheckConstraints and verify that no untrusted constraints remain afterward.
* Ensure NPoco InsertBulk uses SqlBulkCopyOptions.CheckConstraints by introducing UmbracoSqlServerDatabaseType (subclass of SqlServer2012DatabaseType) that overrides InsertBulk to pass SqlBulkCopyOptions.CheckConstraints.
* Also handle InsertBulkAsync.
* Fix GetPermissionsAsync to use path-based permission inheritance
GetPermissionsAsync was querying only explicit per-node permissions,
ignoring the ancestor-based inheritance model. Nodes without explicit
permissions would get group defaults instead of inheriting from their
nearest ancestor with explicit permissions. This caused tree filtering
to hide child nodes that should have been visible.
Replace per-node permission queries with GetPermissionsForPath which
walks the entity path to resolve inherited permissions correctly. Also
pass object types through to enable batched entity lookups.
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Optimise GetPermissionsAsync.
* Add benchmark test.
* Add benchmark test.
* Add integration tests for default and isolated permission resolution
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Make the Delivery API "access" attributes public
* Update src/Umbraco.Cms.Api.Delivery/Filters/DeliveryApiAccessAttribute.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Cms.Api.Delivery/Filters/DeliveryApiMediaAccessAttribute.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Also make the VersionedDeliveryApiRouteAttribute public
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* quote table, column and alias names with SqlSyntaxProvider methods in raw sql
* refactoring private methods into new file as internal methods,
refactor new extensions into another file
* refactor GetAlias method
* Double check the change
* improve code health
* change new static classes into public static partial class NPocoSqlExtensions
* resolve some Copilot review suggestions
* revert Copilot suggestion because it decreases code health
* revert test
* compare in with LOWER, change two methods from private to protected in UmbracoDatabaseFactory
* revert Query.cs in this PR
* Refactor for code health and fixing raw sql
* divers small issues fixed
* refactor two methods to respect the DRY pricipal
* update IQuery interface
* clean up
* revert refactoring for CodeScene
* delete obsolete Test
* rename method
* remove new methods and updates, which are not relevat for this PR
* prepare for additional states in the future
* don't mix string building methods
* fix SQL injection danger
* fix test for reverted methods
* another SqlSyntax issue
* fix update
* fix reverted changes
* restore change for this PR
* restore change for this PR
* fix merge bug
* update formating
* extend ISqlSytax for database independent autoIkrement feature
* fix DTOs, extend ISqlSyntax
* fix tests
* revert
* updates
* diverse SqlSyntax and NPoco related updates for custom databse providers
* fix names
* fix PrimaryKey for multi columns
* Resolve the issues with SqlSyntaxProvider for SQLite. If executed correctly, a single test would reveal the problem.
* add another test
* revert changes which causes even more issues
* fix column const naming
* ensure column const names from v17.2
* add comment for change
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeTemplateDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* resolve review comments
* Make ReferenceMemberName consistent across all DTOs (use constants defined on the referenced DTO).
* Ensure [ExplicitColumns] attribute exists on all DTOs.
* Ensure we consistently use PrimaryKeyColumnName over PrimaryKeyName.
* Fix further inconsistency to use only TemplateNodeIdColumnName.
* Fixed trailing whitespace.
* Restored primary key constraint name on ContentVersionCleanupPolicyDto (it doesn't seem in scope of PR to remove this).
* Removed the confusing PrimaryKeyColumnName constants for multi-column primary key DTOs where the constant refers to only one of the key columns.
* ReferenceMemberName needs to be a C# property name, so it's safer to use nameof.
* Comment fix.
* Amended accessibility modifiers.
* Fixed/tidied comments.
* Fixed references from UserGroupDto.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fix: adds a title to the first entity action in the entity actions bundle, otherwise you do not know what it does, unless the icon is very descriptive
* calculate the label once
* concatenate data-mark string better
* Show character count and instant exceed validation.
* Show character count for textarea editor.
* Add character-count utility and use in editors.
* Rename char count state, add tests, fix imports.
* Update textbox character messages in locales.
* Apply suggestions from code review
* Align textarea and textbox in use of #getMaxLengthMessage private helper function.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fix(manifest): replace %CACHE_BUSTER% token in extension paths served by manifest API
Move cache buster replacement to the presentation layer (manifest controllers)
instead of the infrastructure service. The importmap replacement stays in
HtmlHelperBackOfficeExtensions where it was already handled.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Ordered usings.
* Add unit test for cache buster token replacement.
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fix ambiguous controller constructors.
* Make ReplaceCacheBusterTokens void since it mutates in-place.
* Defensively code against special characters in the cache buster hash.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Imaging: Add format parameter to thumbnail component with webp default
Adds a format parameter to the imaging resize API endpoint and the
umb-imaging-thumbnail component. The component defaults to 'webp' format
for optimal browser support and smaller file sizes.
This ensures that non-image file types (like PDFs) that have custom image
providers can render thumbnails correctly by explicitly requesting an
output format instead of relying on the original file extension.
Changes:
- Add format query parameter to ResizeImagingController
- Pass format through IReziseImageUrlFactory to ImageUrlGenerationOptions
- Add format property to UmbImagingResizeModel TypeScript type
- Add format property to umb-imaging-thumbnail element (default: 'webp')
https://claude.ai/code/session_01GP7N2iTashrG1cBdYVSW97
* Imaging: Include format in cache key generation
Fix cache key to include the format parameter so that different format
requests with identical dimensions are cached separately.
https://claude.ai/code/session_01GP7N2iTashrG1cBdYVSW97
* Imaging: Refactor to use ImageResizeOptions record
Introduces ImageResizeOptions record to encapsulate resize parameters,
addressing CodeScene's "Excess Number of Function Arguments" warning.
Changes:
- Add ImageResizeOptions record with Height, Width, Mode, Format properties
- Add new CreateUrlSets overload accepting ImageResizeOptions
- Mark old CreateUrlSets overload as obsolete (removal in v19)
- Update controller to use new options pattern
https://claude.ai/code/session_01GP7N2iTashrG1cBdYVSW97
* Imaging: Add explicit obsolete method to satisfy API compatibility
The API compatibility checker requires the method to exist explicitly
in the implementation, not just via default interface method.
Co-Authored-By: Claude <noreply@anthropic.com>
* Imaging: Add unit tests for imaging store format parameter
Tests verify that:
- Different formats are cached separately (webp vs png)
- Crops with and without format are cached separately
- Cache operations work correctly with format parameter
Co-Authored-By: Claude <noreply@anthropic.com>
* Add API compatibility suppression for resize imaging endpoint
Suppress CP0002 for adding optional 'format' parameter to the resize
imaging controller endpoint. The HTTP API remains backward compatible
as existing clients simply won't send the new parameter.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix API compatibility for IReziseImageUrlFactory
Restructure interface to maintain binary compatibility:
- Keep original 4-parameter method as required (marked obsolete)
- Add new ImageResizeOptions overload with default implementation
- Factory overrides new method to properly handle format parameter
This allows existing implementations to continue working while
new code uses the ImageResizeOptions overload with format support.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* chore(api): regenerate API compatibility suppression file
Regenerated the CompatibilitySuppressions.xml file with proper metadata
to suppress the breaking change detection for the optional format parameter
added to ResizeImagingController.Urls method. This change is backward
compatible at the HTTP API level.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* feat(imaging): automatic format conversion for non-image files
Move format conversion logic from frontend to backend IImageUrlGenerator
implementations to handle format defaults intelligently based on source
file types.
Why Backend Should Handle This:
1. **Source-aware decisions**: Backend has access to source file extension
and can determine if it's a true image (jpg, png) or processable
non-image (pdf with plugin)
2. **Consistent behavior**: All consumers (backoffice, APIs, custom code)
get consistent format handling without duplicating logic
3. **Plugin compatibility**: When ImageSharp plugins add support for new
file types (e.g., PDF thumbnails), the system automatically converts
them to web-compatible image formats
4. **User override preserved**: Explicit format parameter still works as
an override, giving users control when needed
Changes:
- Add Format property to ImageUrlGenerationOptions for explicit format requests
- ImageSharp implementations auto-detect non-image files and default to WebP
- ReziseImageUrlFactory passes format directly instead of via FurtherOptions
- Frontend imaging-thumbnail component removes hardcoded format='webp' default
- Backend now handles: format override > auto-detect non-images > keep original
Example Scenarios:
- JPEG → No format added (keeps JPEG)
- PNG → No format added (keeps PNG)
- PDF (with plugin) → Auto-adds format=webp
- Any file + explicit format param → Uses specified format
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(imaging): improve robustness and code quality
Address code review feedback with three improvements:
1. Add URI parsing error handling to prevent UriFormatException crashes
when malformed URLs are passed to RequiresFormatConversion()
2. Extract magic string array to class-level constant (TrueImageFormats)
to eliminate duplication and provide single source of truth
3. Remove inconsistent default interface implementation that didn't pass
format parameter, forcing concrete implementations to handle it properly
All changes maintain backward compatibility and improve code safety.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* refactor(imaging): move format determination to factory layer
Refactors format conversion logic from ImageSharp implementations to the factory layer for better separation of concerns and maintainability.
Changes:
- Add ContentImagingSettings.TrueImageFormats configuration (native image formats)
- Move format determination logic to ReziseImageUrlFactory.DetermineOutputFormat()
- Simplify ImageSharp v1 & v2 generators (remove duplicate RequiresFormatConversion())
- Add backward-compatible obsolete constructor to ReziseImageUrlFactory
- Add 50 comprehensive unit tests for format determination and configuration
Benefits:
- Single Responsibility: ImageSharp generators only generate URLs, don't make business decisions
- DRY: Eliminated 70+ lines of duplicated code between ImageSharp packages
- Configurable: TrueImageFormats setting allows customization
- Testable: Format logic tested independently of ImageSharp
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* refactor(imaging): repurpose ImageFileTypes for native format determination
Repurposes the existing unused ContentImagingSettings.ImageFileTypes setting instead of adding a new TrueImageFormats property. This provides better configuration control and eliminates the need for a new setting.
Changes:
- Repurpose ContentImagingSettings.ImageFileTypes (was unused, now active)
- Update ReziseImageUrlFactory to use ImageFileTypes for format determination
- Update TemporaryFileConfigurationPresentationFactory to use config instead of IImageUrlGenerator
- Add comprehensive XML documentation explaining usage in factory layer and backoffice UI
- Update all tests to reference ImageFileTypes
Benefits:
- No new configuration property needed (reuses existing setting)
- Frontend gets configurable format list instead of dynamic ImageSharp formats
- Better separation of concerns (config determines behavior, not infrastructure)
- Clearer documentation of where and how the setting is used
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* test(core): remove duplicate test methods in ContentImagingSettingsTests
Removed duplicate test methods that were causing compilation errors:
- ImageFileTypes_DefaultValue_ContainsExpectedFormats (duplicate)
- ImageFileTypes_DefaultValue_MatchesStaticConstant (duplicate)
- ImageFileTypes_CanBeConfigured_WithCustomFormats (duplicate with incorrect test data)
- Contradicting assertion in StaticConstants_HaveExpectedValues
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(api): suppress CP0006 for IReziseImageUrlFactory.CreateUrlSets overload
Added API compatibility suppression for the new CreateUrlSets overload that
accepts ImageResizeOptions parameter. This change is backward compatible as the
concrete implementation already has both methods and the old method is marked
obsolete to guide users.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fixes merge conflict
* formatting
* fix(api): suppress CP0002 for TemporaryFileConfigurationPresentationFactory constructor change
Added suppression for constructor signature change where IImageUrlGenerator
parameter was replaced with IOptionsSnapshot<ContentImagingSettings> to get
ImageFileTypes directly from configuration instead of from the image URL
generator.
This change is part of the WebP thumbnail feature and aligns with getting
native format information from ContentImagingSettings configuration.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(api): maintain backward compatibility for TemporaryFileConfigurationPresentationFactory constructor
Instead of suppressing the CP0002 error, added back the old constructor marked
as [Obsolete] that chains to the new one. The old constructor:
- Accepts the original parameters (ContentSettings, RuntimeSettings, IImageUrlGenerator)
- Ignores the IImageUrlGenerator parameter (kept only for backward compatibility)
- Uses StaticServiceProvider to get ContentImagingSettings
- Chains to the new constructor
This maintains full backward compatibility while migrating to the new approach
where ImageFileTypes comes directly from ContentImagingSettings configuration.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* test(core): update StaticConstants_HaveExpectedValues test to match actual constant value
The test was checking for format order 'jpg,jpeg,png,gif,webp,bmp,tif,tiff' but
the actual constant StaticImageFileTypes is 'jpeg,jpg,gif,bmp,png,tiff,tif,webp'.
Updated the test to match the actual constant value.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(api): resolve constructor ambiguity in TemporaryFileConfigurationPresentationFactory
Add [ActivatorUtilitiesConstructor] attribute to the new constructor to explicitly
indicate which constructor the DI container should use when both constructors have
the same number of parameters.
This fixes the "ambiguous constructors" error that was preventing the OpenAPI
contract test from running.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix: adds parameter even though it is unused to help the DI system figure out which constructor to use
* test(api): update ReziseImageUrlFactory test to reflect corrected query string handling
The implementation was fixed to correctly handle URLs with query strings by
stripping the query string before extracting the file extension. Updated the
test expectations to verify that PDFs with query strings are now processed
correctly and converted to WebP format, rather than returning empty results.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* chore: adds double obsolete constructor to stay persistent and be able to use only new constructor with same amount of arguments
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Address remaining PR #21570 review comments
- Add GetFileExtension() to UriExtensions for reusable URI extension extraction
- Simplify ReziseImageUrlFactory to use GetFileExtension() instead of manual parsing
- Add default implementation to IReziseImageUrlFactory to avoid CP0006 breaking change
- Remove CP0006 suppression from CompatibilitySuppressions.xml
- Fix Obsolete message format and remove unnecessary [ActivatorUtilitiesConstructor]
- Add TODO for ReziseImageUrlFactory typo rename
- Remove stale ObsoleteOverload test and low-value ContentImagingSettingsTests
- Add unit tests for UriExtensions.GetFileExtension()
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Avoid unnecessary second call to GetFileExtension().
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added further integration test to verify list view permission checks.
* Replace per item GetPermissionsForPath calls with a single batch GetPermissions query across all unique path node ids.
* Added unit test verifying DocumentCollectionPresentationFactory and fixed constructors.
* Replace per-item IsProtected calls with a single batched GetAll query and in-memory path matching.
Compute shared ancestor path keys once for collection siblings instead of per item.
* Eliminate redundant GUID to int conversions in HasScheduleFlagProvider.
* Batch user profile resolution in collection view mapping.
* Addressed issues from code review.
* DRY up GetOwenerName and GetCreatorName in CommonMapper.
* Apply suggestions from code review
Co-authored-by: Mole <nikolajlauridsen@protonmail.ch>
* Apply feedback from code review.
---------
Co-authored-by: Mole <nikolajlauridsen@protonmail.ch>
Mark hey-api generated client code and OpenApi.json as linguist-generated
so they are collapsed by default in GitHub diffs and excluded from
language statistics.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
fix(web): register entity data picker non-editor manifests statically
The entity data picker's picker infrastructure manifests (collection menu,
item, search, tree) were only registered dynamically via the entry point,
meaning they were unavailable until a picker data source was detected.
Split the registration so these manifests are registered statically through
the main property-editors manifest tree, while only property editor manifests
remain dynamically registered.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Update length of type column in LongRunningOperation
* Adding truncation
* Update src/Umbraco.Infrastructure/Examine/ExamineIndexRebuilder.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Used constants.
Handled case where long strings with the same first 200 characters could end up clashing (very unlikely, but we can be defensive).
Introduced a TruncateWithUniqueHash extension method to support this.
* Reverted comment removal.
* Rename migration class.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Use dotnet tool instead
* Uses pipeline build artifacts to reduce compilation time
* Fixed name
* Remove --noRestore
* Move DocFX metadata generation to Build stage
* Updated to use dlls
* Docs: Fix DocFX CSS reference for newer DocFX version
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Added conditions for generating DocFX metadata
* use glob pattern for DLLs
* Move DocFX to Build_Docs stage with separate DLLs artifac
* Fixes based on comments
* Undo commented out Upload C# Docs job
* Removed Build_Docs from Nuget Release so our docs isnt blocking
* Added dependsOn so Upload_API_Docs is only done when Build_Docs are finished
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* cherry-pick from #21672
* cherry pick tab rendering to handle one more case
* move the root route down for it to stay an empty path.
* Revert empty root path commit
* fullPath for root includes 'root'
* revert claude settings commit
* refactor accordingly to feedback
* Updates all obsoletion messages to use a softer expression of intent rather than stating explicit removal in a particular version.
* Code review feedback.
* Updates from code review.
chore(api): regenerate OpenApi.json and backoffice client SDK
The OpenAPI definition and backoffice TypeScript client were out of
sync with recent Management API changes already on main. Regenerated
to bring them up to date.
* Fix suggestion appsettings issue
* Add todo comment to remove UserPasswordConfigurationSettings and MemberPasswordConfigurationSettings
* Apply suggestions from code review
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add tests for property presest value
* save method'
* update accepntance test
* ad timeout to preset value test
* Updated yaml file to copy all .cs files but still keep folder structure
* remove timeout from preset value test
* adding time wait to tests
* adding more timeout
* Adding slow test
* update test
* Format code
* Format code and add more afterEach step to clean language
* Remove test.slow() as it is unnecessary
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Nhu Dinh <hnd@umbraco.dk>
Co-authored-by: Nhu Dinh <150406148+nhudinh0309@users.noreply.github.com>
* Localize "Copy to clipboard" button label
in other Block editor components.
* Adds "Copy to clipboard" action to RTE Block component
* Check if Clipboard Property Context is available
If not, don't show the action button.
* Register "Clipboard Property Context" for Tiptap RTE
we can't make this generic for all RTEs,
since it is bound to the property-editor UI alias.
* Implemented RTE Block's `copyToClipboard()` method
* Added Clipboard Property Value Translators
for Tiptap RTE Blocks.
* Block RTE: fix clipboard paste data structure mismatch
Change paste translator to output UmbPropertyEditorRteValueType (with
markup and blocks) instead of UmbBlockRteValueModel (flat structure).
This ensures the cloner receives the correct type and can properly
regenerate content keys.
Also optimize the cloner to skip DOM parsing when markup is empty,
which is always the case for clipboard paste operations.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* TipTap: debounce block updates to prevent race condition
Add debounceTime to the contents observable to batch rapid emissions
when pasting multiple blocks from clipboard. This prevents the
#updateBlocks method from being called multiple times in quick
succession.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Block RTE: address code review feedback
- Add missing await on insert() and insertFromRtePropertyValues()
- Remove redundant optional chaining on blockContentTypes.every()
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* feat(backoffice): use looser version ranges for peerDependencies
Convert hoisted dependencies to peerDependencies with more permissive version
ranges that allow plugin developers to use different versions without npm conflicts.
Version range strategy:
- Pre-release (0.x.y): >=X.Y.Z <1.0.0
Example: @hey-api/openapi-ts 0.85.0 → >=0.85.0 <1.0.0
Allows plugins to use 0.85.0, 0.91.1, 0.99.99 without conflicts
- Stable (major.x.y where major ≥1): major.x.x
Example: lit ^3.3.1 → 3.x.x
Allows any patch/minor within the major version
This allows plugin developers to:
- Use @hey-api/openapi-ts 0.91.1 while backoffice uses 0.85.0
- Install compatible deduplicated versions when available
- Override versions when needed for their specific use case
Types remain available from peerDependencies (automatically installed by npm 7+).
When @hey-api reaches 1.0.0, the range will automatically become ^1.0.0.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): use semver package for version parsing in cleanse script
Replace regex-based version parsing with the semver package used by npm itself.
This ensures version parsing is consistent with npm's own semver handling and is
more robust for edge cases.
Also update the version range logic to be more explicit and correct:
- Pre-release (0.x.y): >=X.Y.Z <1.0.0
- Stable (1+.x.y): >=X.Y.Z <NEXT_MAJOR.0.0
This ensures plugin developers use at least the tested version and prevents
accidental downgrades to incompatible minor versions.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* chore: formats file
* chore: lockfile
* fix(backoffice): use semver.minVersion to parse version ranges
Fix parsing of version ranges like ^0.85.0 by using semver.minVersion() instead
of semver.parse(). The parse() function only handles exact versions, while
minVersion() extracts the minimum version from a range.
Example transformations:
- ^0.85.0 → 0.85.0 → >=0.85.0 <1.0.0
- ^3.3.1 → 3.3.1 → >=3.3.1 <4.0.0
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): keep caret ranges for stable package versions
Optimize the version range conversion logic:
- Stable versions (major ≥ 1) with caret (e.g., ^3.3.1): Keep as-is
The caret already implements the desired range: >=3.3.1 <4.0.0
- Pre-release versions (0.x.y): Convert to explicit range
^0.85.0 → >=0.85.0 <1.0.0 (caret only allows 0.85.z, not 0.91.z)
- Exact versions (e.g., 3.16.0): Convert to range
3.16.0 → >=3.16.0 <4.0.0
This simplifies the published package.json while maintaining the same semantics
and is more explicit about the intent.
Examples of published peerDependencies:
- lit: ^3.3.1 (unchanged, already has correct range)
- rxjs: ^7.8.2 (unchanged)
- @hey-api/openapi-ts: >=0.85.0 <1.0.0 (converted from ^0.85.0)
- @tiptap/core: >=3.16.0 <4.0.0 (converted from 3.16.0)
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): use caret for stable exact versions
Simplify stable exact versions (e.g., 3.16.0) by adding a caret prefix (^3.16.0)
instead of explicit range (>=3.16.0 <4.0.0). Both are semantically identical for
stable versions but caret is more concise and conventional.
Updated version range logic:
- Stable with caret (^3.3.1): Keep as-is
- Pre-release with caret (^0.85.0): Convert to >=0.85.0 <1.0.0
- Stable exact version (3.16.0): Convert to ^3.16.0
Examples of published peerDependencies:
- lit: ^3.3.1
- rxjs: ^7.8.2
- @hey-api/openapi-ts: >=0.85.0 <1.0.0
- @tiptap/core: ^3.16.0 (now with caret)
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): ensure all pre-release versions get explicit range
Reorganize version conversion logic for clarity:
1. All pre-release (0.x.y) versions → explicit range: >=X.Y.Z <1.0.0
- Examples: ^0.85.0 → >=0.85.0 <1.0.0, 0.85.0 → >=0.85.0 <1.0.0
2. Stable versions with caret (^3.3.1) → keep as-is
3. Stable versions exact (3.16.0) → add caret: ^3.16.0
This ensures pre-release version constraints are properly loosened for plugins
while maintaining stability guarantees.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* treat all modifiers the same
* docs: add backoffice npm package structure documentation
Add comprehensive section to CLAUDE.md explaining:
- Backoffice npm package architecture and plugin model
- Dependency hoisting strategy and version range logic
- How pre-release versions are handled vs stable versions
- Importmap as single source of truth for runtime
- Plugin development implications and expectations
Clarifies that while npm versions constrain types, the actual runtime comes
from importmap, and plugin developers should declare explicit dependencies
rather than relying on transitive deps.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* docs: add npm package publishing guide to backoffice CLAUDE.md
Add comprehensive section explaining:
- Why backoffice uses peerDependencies (importmap provides runtime)
- Dependency hoisting strategy and version range conversion logic
- How pre-release versions are handled differently from stable versions
- Example published peerDependencies showing final output
- Plugin developer guide with dos and don'ts
- Key files involved in the publishing process
Provides clear guidance for plugin developers on version compatibility
and explains the importmap-as-single-source-of-truth architecture.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
---------
Co-authored-by: Claude <noreply@anthropic.com>
* edit regex for oembed flickr
* Apply stricter matching with domain to all embed providers, and validate with unit tests.
* Resolved warnings and added further unit tests.
* Further tightened the URL matching regex for two providers.
* Add regex caching to OEmbedService and unit tests to verify behaviour.
* Restore flickr short URL domain.
* Use https in requests to oembed providers.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* edit regex for oembed flickr
* Apply stricter matching with domain to all embed providers, and validate with unit tests.
* Resolved warnings and added further unit tests.
* Further tightened the URL matching regex for two providers.
* Add regex caching to OEmbedService and unit tests to verify behaviour.
* Restore flickr short URL domain.
* Use https in requests to oembed providers.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Tests: Fix permission controller tests to use correct entity keys
The GetDocumentPermissionsCurrentUserController, GetMediaPermissionsCurrentUserController,
and GetPermissionsCurrentUserController tests were incorrectly creating user data and
passing user keys to the GetPermissions method. These controllers expect document/media
keys, not user keys.
Updated the tests to create the appropriate content/media types and entities, then pass
the correct keys to properly test the permission endpoints.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* add paging UI to picker search results
* implement paging in collection picker data source example
* Hide pagination when all items loaded
* Use paging object for search requests
* Forward paging params in server search queries
* Set default page size in PickerSearchManager
* Use args.paging for skip/take in search
* Update src/Umbraco.Web.UI.Client/src/packages/core/picker/search/picker-search-result.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Reset pagination page when updating query
* dim the box while searching
* Delay loader appearance with fade-in
* Track executed search query and use in results to prevent UI flickering when entering in the search field
* Skip update when dataType is undefined
* Cancel tree loads on context destroy
* fix pagination labels
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Umbraco.Core: add XML documentation to all public members
Add comprehensive XML documentation comments to all public classes,
interfaces, methods, properties, constructors, and enums in Umbraco.Core
to resolve SA1600 StyleCop warnings.
- Document ~2,500+ files across all folders (Services, Models,
Notifications, Configuration, Cache, etc.)
- Use <summary>, <param>, <returns>, <remarks> tags as appropriate
- Apply <inheritdoc/> for interface implementations
- Use <see cref="..."/> for type references
- Preserve all existing comments
This eliminates approximately 15,500 SA1600 warnings from the project.
* Revert any code changes in the PR.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Block RTE: Add delete action with undo support
Adds a delete button to RTE block entries that removes blocks from
both the editor HTML and the block manager data. Implements an
HTML-first deletion approach that enables Ctrl+Z undo support by
leveraging the existing _filterUnusedBlocks mechanism.
- Add delete button to block-rte-entry action bar
- Add pendingDeletions state to manager for HTML-first deletion flow
- Modify entries context to use pending deletion mechanism
- Add Tiptap API observer to process pending deletions
- Remove blocks from editor via ProseMirror transactions
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Updates UmbracoProject template
Removes the framework choice from the template configuration as it's not used and was out of date.
Updates the LTS version to a wildcard to allow minor version updates and mean this doesn't need to be updated all the time!
Updates the description in the dotnet version generated property
* Removes unnecessary build flag
* Remove Custom Version symbol
It doesn't show up in the template anyway and has been marked as obsolete
* Remove framework from Extension template also as not used
* fix: update dotnet new syntax in pipeline
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: NguyenThuyLan <116753400+NguyenThuyLan@users.noreply.github.com>
* Document Types returns a list of allowed parent keys
* Media types included
* Minor fixes to namespace etc.
* Tests
* Fixing breaking change
* Correcting requested changes
* Corrected requested changes
* Removed unnecessary usings, aligned naming between service, repository and tests.
Add a new status for the default implementation (NotImplemented felt more correct than NotFound).
Updated inheritance in service layer so we maintain the NotFound behaviour for member types.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Documents: Remove deprecated entityType from property values
The entityType property on property values was causing "Unsaved Changes"
modal to appear after saving documents with RTE blocks. This occurred
because the server data source added entityType when reading, but
setPropertyValue did not preserve it when updating values.
Since entityType on UmbElementValueModel is deprecated and marked for
removal in v18, the cleanest fix is to stop adding it in the server
data source mapping.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Fix display of validation hint related to a tab.
* Update position of the badge.
* Change position for last tab.
---------
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Add and use a constant for the folder media type GUID identifier.
* Use defined constant and avoid lookup for folder media type when searching for media items.
* Add failing tests illustrating the lack of data type caching by key.
* Implement cache by key in data type repository.
* Apply same for template repository look-ups by key.
* Add tests verifying that content types are already cached by Id and key.
* Use correct default for creator Id in data type builder for tests.
* Use non-obsolete constructor in test.
* Ensured a deleted data type or template is cleared from the by key cache.
* Add IReadRepository implementations
* Utilize by-key repo access in service layers
* Fix test
* Safeguard against potential null reference exception
---------
Co-authored-by: kjac <kja@umbraco.dk>
* quote table, column and alias names with SqlSyntaxProvider methods in raw sql
* refactoring private methods into new file as internal methods,
refactor new extensions into another file
* refactor GetAlias method
* Double check the change
* improve code health
* change new static classes into public static partial class NPocoSqlExtensions
* resolve some Copilot review suggestions
* revert Copilot suggestion because it decreases code health
* revert test
* revert refactoring for CodeScene
* delete obsolete Test
* remove new methods and updates, which are not relevat for this PR
* prepare for additional states in the future
* don't mix string building methods
* fix SQL injection danger
* fix test for reverted methods
* another SqlSyntax issue
* Add additional unit and integration tests verifying the refactorings made in the PR.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Remove the default empty target tag for links, so the target attribute is only output when it has a value.
* Tiptap Link extensions: defaults `target` value to `null`
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Squash merged "v173/20453-21446-21448-FirstOrDefault-vs-ExecuteScalar" into "v173/21448-FirstOrDefault-vs-ExecuteScalar"
* resolce Copilot code review comments
* revert to ExecuteScalar<string>
* revert to Database.ExecuteScalar<string>
* revert .FirstOrDefault<long>(query) and its async variant to .ExecuteScalar<long>(query). It is fine for PostgreSql too.
* Remove the test added for verifying NPoco behaviour (it's not needed in the code base moving forward)
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Exclude invariant options for culture-variant properties in preset builder
* Add unit test verifying the fix.
* added a few more unit tests
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
improvement(web): make ProfilingViewEngine._inner private and modernize string formatting
- Changed internal readonly Inner field to private readonly _inner field
- Replaced string.Format calls with string interpolation
- Removed TODO comment
* Skip leading whitespace in ufm parser
* UFM: Update start function to also skip leading whitespace
The tokenizer was updated to allow whitespace after opening braces,
but the start function still used a string pattern without whitespace
tolerance. This updates start to use a pre-compiled regex that matches
the tokenizer behavior, and adds an additional test case for the
documentation example format.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Upgraded Tiptap to v3.13.0
* Remove eslint disable comments
* Update notes in externals
* `TextDirection` is now part of Tiptap core
* Upgraded Tiptap to v3.16.0
* The `addOptions()` typing error still persists in v3.16.0
* Resolved the export issue
* Removed unrequired `@ts-expect-error`
This came from an upstream merge.
* Move MediaTree write lock before MediaSavingNotification to prevent deadlock
Fixes a deadlock that could occur when saving multiple media items in parallel
when a MediaSavingNotification handler acquires a MediaTree read lock. The
previous ordering allowed two threads to each acquire read locks in their
notification handlers, then both attempt to upgrade to write locks, causing
a classic lock upgrade deadlock in SQL Server.
By acquiring the write lock before publishing the notification, the deadlock
scenario is avoided. Since the write lock is lazy, it only materializes at the
database level when actual queries are made, so notification handlers doing
in-memory work won't hold the lock.
* Apply same fix to MediaService.Delete method
* Apply same fix to DeleteVersions, DeleteVersion, and Sort methods
* Apply same fix to ContentService methods
Move WriteLock before notifications in:
- Save (single and batch)
- Delete
- DeleteVersions
- DeleteVersion
- Copy
* Apply the same pattern to MemberService.
* Add integration tests to verify the fix.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added tests for multi url picker validation message
* Added more tests - not done
* Updated more tests for multi url picker validation message
* Removed unused file
* Bumped version
* Make tests run in the pipeline
* Reverted npm command
* added color variable to code-block to make it readable in dark mode
* Update src/Umbraco.Web.UI.Client/src/packages/core/components/code-block/code-block.element.ts
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Prevent creation of media items with GUID version 7 keys when a media scheme is registered that doesn't support this GUID version.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix log message formatting.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Add support to models builder for nested generic types.
* Fixed existing warnings, added further tests, renamed tests for clarity.
* Add defensive validation for generic brackets passed to SplitGenericArguments.
* Fix failing unit tests.
* Content types: Allow adding composition with clashing property alias when property is being removed
* Further assert on property coming from the composition.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Block editors: Fix false pending changes indicator for invariant BlockList with culture-variant blocks (closes#21223)
When a document with a culture-variant content type has an invariant BlockList property containing culture-variant blocks, and you publish all languages for the first time, the content would incorrectly show as having unpublished changes.
The root cause was inconsistent JSON serialization order between EditedValue and PublishedValue. Two fixes were applied:
1. Sort block item values by culture before serialization in both `FromEditor` and `MergePartialPropertyValueForCulture` to ensure consistent ordering.
2. Add `[JsonIgnore]` to `BlockItemData.Udi` property since this computed property differs between save and publish paths.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Update tests/Umbraco.Tests.Integration/Umbraco.Infrastructure/PropertyEditors/BlockListElementLevelVariationTests.Publishing.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fixed failing integration tests.
* Fix backwards compatibility for legacy UDI format in JSON deserializatio
* Tidy up, remove unused parameters.
* Fixed failing E2E test with copy blocks.
* Separate handling of udi and values in deserialization from current and legacy format, to correctly fix previously failing integeration and E2E tests.
* Fixed failing unit test.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adds link (`umbLink`) support to the Style Menu api
* Tiptap RTE: Fix toggleClassName to handle multi-class strings
The toggleClassName command now properly tokenizes the className parameter
to handle space-separated classes (e.g., "btn btn-primary"). Previously,
the entire string was treated as a single token, causing duplicates and
preventing class removal.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Tiptap RTE: Add ensureUmbLink command for idempotent link creation
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Backoffice: Redirect to list view after entity deletion
When an entity is deleted from its detail workspace, the UI now redirects
to the parent list view and shows a success notification instead of staying
on the deleted entity's page showing a 404 error.
Changes:
- Dispatch UmbEntityDeletedEvent after successful deletion
- Show success notification toast on deletion
- Listen for delete event in workspace editor and navigate to backPath
* Integration tests for #21138
* Make OpenId redirect and postlogout uris support load balanced environments
* Applied review suggestions
* Fix unit test mocks
* Introduce new method overloads and repository implentation, such that a collection view response only loads properties it needs.
* Use non-obsolete method overloads throughout.
* Add unit tests to verify property value retrieval.
* Don't load templates for collection view content retrieval.
* Optimize access checks by verifying the full collection rather than one at a time, and avoid the need to retrieve full content items.
* Added obsoletion messages and aligned behaviour of content and media permission service checks.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Return key in TreeEntityPath collection response, avoiding a later look-up of the key by Id.
* Resolve breaking changes to interfaces.
* Fix further breaking change.
* Additional assert for test verifying property loading for a non-existing property.
* Refactored repositories to avoid having method parameters related to templates on non-document and base content repositories.
* Remove check that verifies all provided keys are found when doing permission checks (although arguably correct, it's a behavioural change, and can also be argued it's corect as is).
* Introduce variable for permission set permissions.
* Provide functional default implementation on FilterAuthorizedAsync.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Squash merge Squash merged v173/20453-fix-more-sql-syntax-issues int v173/20453-fix-more-sql-syntax-issues-squash (copy of main)
* fix 2 unit test
* Replace nameof(DTO.COLUMN_NAME) by constant, because it leads to casing issues for case sensitive databses
* fix Copilot review comments
* resolve review comments
* replace more hard coded strings
* fix test
* fix review comments
* fix database schema
* fix database schema
* fix database schema and ResultColumn reference names
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* add comment from review
* fix two reference column names
* fix breaking change
* fix typo
* Remove unnecessary attributes
* mark 2 unsused DTO classes as obsolete
* reverted change of class UnionHelperDto adding [Column("...")] attributes again, because some integration tests for PostgreSQL provider fail without them. Again a case sensitivty issue.
* replace nameof reference names,
make all column name const consistent
* use NPoco dto instead of raw sql,
extend ISqlSyntaxProvider to handle some sql issues
* reduce complexity
* remove currently unsused extensions to ISqlSyntax
* add missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* add another missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* fix Copilot review comments and build errors
* update ISqlSyntaxProvider and SqlSyntaxProviderBase
* ensure GetPagedDescendants returns ordered by path entities as default
* resolve review comments
* fix review comments
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Migrations/Install/DatabaseSchemaCreator.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.PublishedCache.HybridCache/Persistence/DatabaseCacheRepository.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix Copilot comment
* fix wrong Copilot suggestion
* quote more column names
* resolve review
* Apply suggestions from code review
* synced interface and base class
* Revert "synced interface and base class". For an interface's default implementation, NotImplementedException makes more sense.
This reverts commit cf01cd01fc.
* Fixed remaining code warnings in DatabaseSchemaCreator.
* follow Cotpilot's review suggestion
* revert implementation and fix test
* use default
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adds reusable `emptyRecycleBin` `collectionAction` kind
* Adds `emptyRecycleBin` collection-action to documents
* Adds `emptyRecycleBin` collection-action to media
* Removes `api` export
since the condition is eagerly loaded.
* Fixes type annotations and JSDoc comments
- Uses correct generic type `UmbCollectionHasItemsConditionConfig` in `UmbCollectionHasItemsCondition`
- Corrects JSDoc `@augments` tag in `UmbEmptyRecycleBinCollectionAction`
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fixed linting errors
* Refactors execute() to reduce cyclomatic complexity
Extracts tree refresh logic into private #reloadChildrenOfEntity() method.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Update src/Umbraco.Web.UI.Client/src/packages/media/media/recycle-bin/manifests.ts
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Removed code comment
as caused ambiguity.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Disabled the generation and upload off the docfx csharp api docs.
* Add comment explaining why job is disabled
* Added comment on second job
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added missing code documentation to the Umbraco.Cms.Api.Common project
* Remove duplicate XML summary for All constant
Removed duplicate XML summary documentation for the All constant.
* Removed inline comments no longer required now the information has been moved to XML header remarks
* Fix indentation on refactored path segment extraction in SubTypesSelector
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Squash merge Squash merged v173/20453-fix-more-sql-syntax-issues int v173/20453-fix-more-sql-syntax-issues-squash (copy of main)
* fix 2 unit test
* Replace nameof(DTO.COLUMN_NAME) by constant, because it leads to casing issues for case sensitive databses
* fix Copilot review comments
* resolve review comments
* replace more hard coded strings
* fix test
* fix review comments
* fix database schema
* fix database schema
* fix database schema and ResultColumn reference names
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* add comment from review
* fix two reference column names
* fix breaking change
* fix typo
* Remove unnecessary attributes
* mark 2 unsused DTO classes as obsolete
* reverted change of class UnionHelperDto adding [Column("...")] attributes again, because some integration tests for PostgreSQL provider fail without them. Again a case sensitivty issue.
* replace nameof reference names,
make all column name const consistent
* use NPoco dto instead of raw sql,
extend ISqlSyntaxProvider to handle some sql issues
* reduce complexity
* remove currently unsused extensions to ISqlSyntax
* add missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* add another missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* fix Copilot review comments and build errors
* update ISqlSyntaxProvider and SqlSyntaxProviderBase
* resolve review comments
* fix review comments
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Migrations/Install/DatabaseSchemaCreator.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.PublishedCache.HybridCache/Persistence/DatabaseCacheRepository.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix Copilot comment
* fix wrong Copilot suggestion
* quote more column names
* resolve review
* Apply suggestions from code review
* synced interface and base class
* Revert "synced interface and base class". For an interface's default implementation, NotImplementedException makes more sense.
This reverts commit cf01cd01fc.
* Fixed remaining code warnings in DatabaseSchemaCreator.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(log-viewer): prevent polling toggle reset when changing interval
Fixes issue where changing polling interval would reset the button to 'Polling' state instead of applying the new interval immediately.
- Remove togglePolling() call from closePoolingPopover() method
- Update setPollingInterval() to restart polling with new interval if already enabled
Fixes#21507
* refactor(log-viewer): extract polling start logic and fix regression
- Extract polling start logic into #startPolling() helper method
- Fix regression: enable and start polling when interval is selected while polling is off
- Update togglePolling() to use the helper method for consistency
Addresses feedback on PR #21508
---------
Co-authored-by: Gittensor Miner <miner@gittensor.io>
* Fix for the client side circular dependency.
This should fix the circular dependency without causing any breaking changes to the public APIs.
This issue is detailed here:
https://github.com/umbraco/Umbraco-CMS/issues/21463
* refactor UMB_MODAL_MANAGER_CONTEXT to avoid circular dependency
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Add 'is modal' condition to modal package
Introduces a new 'is modal' condition for extension manifests, allowing actions to be conditionally permitted based on modal context. Updates user collection action manifests to use this condition, preventing certain actions when inside a modal. Includes implementation, configuration, manifest registration, and tests for the new condition.
* rename from is modal to in modal
* added dicationary value search active only with config param set
* Removed code smell, by reducing nesting
* Renamed configuration value to EnableValueSearch.
Added integration tests to verify search results.
* update query to return correct values for each language in the overview
* Use OptionsMonitor and add additional assert to verify fix to indication of which languages have translations.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Sort at last by language name
* ensure document language picker is sorted as variant selector
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/modals/shared/document-variant-language-picker.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/workspace/components/workspace-split-view/workspace-split-view-variant-selector.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/utils.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* refactor to avoid inline methods
* transform into a function
* revert config file commit
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add alias property to collection config interface
Introduced an 'alias' property to the UmbCollectionItemPickerModalCollectionConfig interface
* render collection element when modal is configured with an alias
* expose a picker modal route
* use collection in use picker
* adjust spacing
* add config option for selectOnly
* dynamic modal alias
* support selectable entity item ref
* wip entity data picker collection + ref and card views
* Add entity collection item card extension type + default elements
* implement user collection item card
* fix selection events
* map to prop
* add prop/attr for href
* add support for which detail properties to show
* update type import
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/item/entity-collection-item-card/entity-collection-item-card.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* import card in correct file
* Fix event listener binding for selection events
* implement disabled property for collection item cards
* init commit of collection item ref extension
* fix imports
* add element interface
* Implement UmbEntityCollectionItemElement interface in item cards
Added the UmbEntityCollectionItemElement interface to document and user collection item card elements for improved type safety and consistency. Updated type exports to include the new interface.
* Update collection item ref to use uui-ref-node
Replaces the placeholder div with a uui-ref-node component, passing relevant item properties and event handlers. Adds dynamic icon rendering using umb-icon.
* Refactor entity collection item elements to use shared base
Introduces a new abstract base class for entity collection item elements, consolidating shared logic for card and ref variants. Updates card and ref element implementations to extend the new base, and refactors extension manifest interfaces for consistency. This improves maintainability and reduces code duplication.
* use class instead of magic string
* Use entity collection item card in picker view
Replaces the placeholder card markup with the <umb-entity-collection-item-card> component, enabling selection and deselection functionality for items in the entity data picker card collection view.
* Update entity item ref to collection item ref
Replaces <umb-entity-item-ref> with <umb-entity-collection-item-ref> in the picker collection view. Adjusts event handlers and select-only logic to improve selection behavior and component consistency.
* utilise ref and card kind for picker views
* introduce ref and card collection view kinds
* Utilise card kind for user collection view
* Add item-specific href support to collection views
Introduces a requestItemHref method to collection contexts for retrieving item-specific hrefs. Updates card, ref, and user table collection views to use these hrefs, enabling dynamic linking for collection items. Refactors user table name column layout to accept href via value prop instead of constructing it internally.
* Update ManifestCollectionView import path
Changed the import of ManifestCollectionView from '../extensions/types.js' to '../view/types.js' to reflect its new location.
* remove unused
* use size medium for entity collection item picker
* use box
* render entity actions
* use edit path builder for user links
* rename method
* Revert "rename method"
This reverts commit 4df577688e.
* Update collection-default.context.ts
* make type lint ignore unused args with an underscore
* temp remove unused
* only make collection vie selectable if there are any registered bulk actions
* don't render name link if there is no href
* fix imports
* Render selection actions only if bulk actions exist
* use selectable state
* Update language-table-collection-view.element.ts
* Update language-table-collection-view.element.ts
* Update card-collection-view.element.ts
* clean up
* Refactor collection views to use shared base class
* refactor(collection): parallelize href fetching and make method private
* docs(examples): update collection example to use card and ref kinds
* docs(examples): add icon property to collection example data model
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/types.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update collection-bulk-action.manager.test.ts
* Removed duplicate and redundant '@typescript-eslint/no-unused-vars' rule definitions, consolidating the configuration to use only 'argsIgnorePattern'.
* Handle missing user href in name column layout
Replaces the user name link with a span when the href property is not provided, preventing broken links in the user table name column layout.
* Update user-table-name-column-layout.element.ts
* pass modal data and value to routable modal
* Update picker-input.context.ts
* support selectableFilter
* scaffolding of a collection text filter extension
* Refactor collection text filter to use API interface
* Fix incorrect tag
* Update types.ts
* Update collection-text-filter.extension.ts
* Add cancelation to debounced search on destroy
* clean up
* add js docs
* two way binding of filter value
* clean up
* Add collection text filter manifest example
Introduced a new filter manifest for the example collection and updated the main manifests file to include it. This enables a text filter extension for the example collection.
* Delete unused element and context
* Update src/Umbraco.Web.UI.Client/src/packages/user/user-group/collection/user-group-collection.context-token.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update user-group-table-collection-view.element.ts
* support search for tree item and collection item pickers
* add spacing between collection ref items
* add margin between picker search result items
* remove spacing after last item
* remove padding in search results
* Update collection-item-picker-modal.element.ts
* move select only logic to collection selection manager
* add tests for collection selection manager
* change to filter label instead of search
* delete unused user grid collection view
* Select-only mode is now only disabled when all items are deselected, rather than on every deselection.
* prepare umb table for pickers
* utilize UmbCollectionViewElementBase in user table collection view
* remove console log
* handle select all and select item from same event
* bulk actions workaround
* add bulk action in collections feature toggle
* remove unused method
* make fields optional to avoid a breaking change
* remove unused import
* fix typescript errors
* adjust search styling
* hide with css
* fix ts errors
* Add modal data support to picker input context
Introduces methods to set and get modal data in UmbPickerInputContext, allowing base configuration for picker modals. Updates modal data handling to merge stored modal data with provided data for both direct picker opening and modal route setup.
* Fix bulk action manager test initialization
Added calls to setConfig in tests to properly initialize the observer before subscribing to hasBulkActions. Simplified the test logic for checking emissions when actions are present.
* Update tree-picker-modal.element.ts
* Update picker-search-result.element.ts
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/umb-collection-view-element-base.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Use ifDefined for modal route in user input button
* Use ifDefined for href binding in entity data picker
* Fix collection alias binding in item picker modal
* wire up user table collection view with selectableFilter
* clean up controller aliases
* Update collection-item-picker-modal.element.ts
* Update collection-item-picker-modal.element.ts
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* enable async method
* ensure container is local to the owner content type
* no need to await anyhow
* handle moved groups
* Update src/Umbraco.Web.UI.Client/src/packages/content/content-type/workspace/views/design/content-type-design-editor-properties.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fixes#20665 - Password change error msg
In order to show the right validation message:
- the repository code always notifies the validation failure message
(or a default failure message if none is received)
- in the data-source code, tryExecute is called with the option
to disable the default notification
* Return the original error instead of faking success
---------
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
* Implement document alias cache and service to optimize content finder by alias.
* Renamed to DocumentUrlAlias. Fixed issues on start-up.
* Remove tracking of root ancestor.
* Optimize cache key, tidy up tests, move domain matching to content finder.
* Handle language and document deletes.
* Align further with document URL service.
* Code tidy.
* Fixed comment.
* Refactor scope handling to avoid nested scopes
Extract CreateOrUpdateAliasesInternalAsync to process documents without
creating their own scope. Both CreateOrUpdateAliasesAsync and
CreateOrUpdateAliasesWithDescendantsAsync now create a single scope
and call the internal method, avoiding unnecessary nested scope creation.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Extract CreateOrUpdateAliasesInternalAsync to process documents without
creating their own scope.
* Only return a document for a match under a domain if the document is found under the domain of the current request.
* Fix failing integration tests.
* Apply suggestions from code review.
* Ensured language to culture code map is updated when a language isn't found in the cached map.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
fix(backoffice): resolve event listener memory leaks in auth, dropzone, actions, and router
Fixes memory leaks in 4 components where event listeners registered with .bind(this) could not be properly removed because each .bind() call creates a new function reference.
Changes:
- auth.context.ts: Convert #onStorageEvent to arrow function property
- dropzone-media.element.ts: Convert 4 drag handlers to arrow function properties
- entity-actions-dropdown.element.ts: Convert handler and add disconnectedCallback
- router-slot.element.ts: Convert handler and add proper cleanup in disconnectedCallback
Solution: Arrow function properties maintain consistent references while preserving 'this' context, enabling proper listener removal.
Testing:
- Added unit tests for auth.context.ts
- All builds pass
- Linter passes
- No breaking changes
Documentation:
- Added "Event Listener Cleanup Pattern" section to clean-code.md
- Added "Event Handler Guidelines" section to style-guide.md
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
* refactor(rte): Replace misleading Promise.all with sequential awaits
The inner awaits in Promise.all([await ..., await ...]) made the operations
sequential anyway. Since #loadEditor() depends on _extensions being populated,
sequential execution is correct - this change makes the intent clearer.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* perf(rte): Cache toolbar and statusbar emptiness checks
Instead of calling .flat() on every render to check if toolbar/statusbar
have items, compute the boolean once when values are set in #loadEditor().
This avoids unnecessary array operations during render cycles.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* perf(rte): Pre-compute extension styles during initialization
Instead of calling unsafeCSS() on each style during every render cycle,
collect and process styles once in #loadEditor() and store the result
in _extensionStyles. This avoids repeated CSS processing during renders.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
# Conflicts:
# src/Umbraco.Web.UI.Client/src/packages/tiptap/components/input-tiptap/input-tiptap.element.ts
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Adds `check:duplicate-class-names` devops script
* DevOps: Improve `check:duplicate-class-names` script
- Fix example path in JSDoc comment
- Add support for `export default class` declarations
- Add `--ignore-stories` flag to exclude story files from detection
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Added try/catch on reading file contents
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Resolved potential thread safety issues with PublishStatusService.
* Only update published status in content cache refresher if within a publish or unpublish operation.
* move media-type guid strings into constants partial
* missed one.
* Update src/Umbraco.Core/Constants-MediaTypes.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add member type GUID constants too.
* Removed member type incorrectly recorded as a built-in data type.
* Reuse constant in obsolete GUID constant.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Remove rebuild of document URLs during migration, instead ensuring they will run after migration is complete and Umbraco is running.
* Avoid unnecessary second rebuild of document URL cache after startup with migration that has already triggered a rebuild.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add a toggle, defaulted to off, for display of diffs on the rollback view.
* Used only label for checkbox.
* Align formatting across translations for diffHelp key.
* Changed the checkbox to a toggle
UI semantics, checkboxes imply selection, whereas toggles imply activation.
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Prevent selection of document and member type folders when selecting allowed types for the content picker.
* Added fix for Media Types
* Set `documentTypesOnly` on `umb-input-document-type`
so to disallow selecting element-types.
* Linting
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* fix: aligns media workspace with document workspace to handle "variants" when calculating routes, which fixes an issue where the "Access denied" view would not be shown
* fix: clear root access flag when selecting specific start nodes
When selecting specific document or media start nodes for a user, the UI now automatically sets hasDocumentRootAccess/hasMediaRootAccess to false.
Previously, if a user group had "Has access to all items" enabled, selecting specific start nodes on the individual user wouldn't clear the root access flag. This caused the backend to add -1 (root access) to the start node list, overriding the specific node selections.
This ensures user-specific start node permissions properly override group-level root access settings.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix: add length check to prevent rendering router with empty routes array
The render method now checks both that _routes exists AND has length > 0 before rendering the router-slot. An empty array is truthy, so without the length check, the router-slot could be rendered with an empty routes array, causing runtime errors.
This aligns with the original render logic and prevents the TypeError when media tests run.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fix E2E test URL construction for media workspace deep-linking
The test was constructing an invalid URL by appending the workspace path
directly to the current URL, which included '/collection'. This resulted in:
/umbraco/section/media/collection/workspace/media/edit/ (invalid)
Instead of the correct:
/umbraco/section/media/workspace/media/edit/
The fix removes '/collection' before appending the workspace path, ensuring
the test actually navigates to the workspace editor where the 'Access denied'
view is properly displayed.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Make all tests for media start node run in the pipeline - remember to revert before merging
* Revert npm command before merging
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Nhu Dinh <hnd@umbraco.dk>
* Document Tree: Filter tree items based on user browse permissions
- Add FilterTreeEntities virtual methods to EntityTreeControllerBase for filtering tree entities with total count adjustments
- Override FilterTreeEntities in DocumentTreeControllerBase to filter by ActionBrowse permission
- Extract filtering logic into IDocumentPermissionFilterService for testability
- Add unit tests for DocumentPermissionFilterService
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Complete the scope when no runnable job found. Without this I'm seeing timeouts and lock contention if a long-running document type save operation is running when the first distributed job is requested.
* Run serialization steps of rebuild of content cache in parallel for a small but not insignficant speed optimization.
* Add integration tests for database cache rebuild.
* Optimize rebuild of databaes and memory cache after content type update.
* Add debug log for running distributed job.
* Apply memory cache clear optimization to media.
* Optimize MediaCacheService.RebuildMemoryCacheByContentTypeAsync with lightweight query
Use GetMediaKeysByContentTypeKeys to fetch only media keys instead of loading full ContentCacheNode objects. This matches the same optimization applied to DocumentCacheService.
Also refactors Rebuild() to reuse RebuildMemoryCacheByContentTypeAsync for the memory cache clearing step.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Further updates from code review.
* Further tests for variant documents, composed documents and message pack serialization.
* Fixed failing integration tests.
* Clear the cacje level published content cache on content type change.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix: Resolve 128 SA1600 documentation warnings in Umbraco.Cms.Persistence.Sqlite
- Added XML documentation comments to interceptors, mappers, and services
- Added TODO (V18) comments to SqliteSyntaxProvider.Format methods (CS0114)
- Updated .csproj TODO comment to follow V18 convention
- CS0114 warnings remain suppressed as fix would be binary breaking
* Fixed the issues Copilot complained about with the documentation and..
Fixed two IDE0270 warnings (null check simplification).
* Code Quality: Fix CS0659 and CS0661 build warnings in Item test class
The Item class in test project defined Equals override and equality operators without implementing GetHashCode, causing CS0659 and CS0661 compiler warnings.
Added GetHashCode implementation using RuntimeHelpers.GetHashCode(this) for consistent reference-based equality matching the existing operators behavior.
Removed CS0659/CS0661 from WarningsNotAsErrors in test project as they are no longer needed.
* Code Quality: Remove unused test infrastructure classes
Remove Item, OrderItem, and SimpleOrder classes along with the SimpleOrder_Returns_Null_On_FirstOrDefault_When_Empty test.
These ~370 lines of test infrastructure existed only for a single trivial test that verified FirstOrDefault() returns null on an empty collection - behavior already tested on actual Umbraco collections in the same file.
* Refactor StringExtensions into multiple files using partial classes.
* Tidy/complete XML header comments.
* Fixed warnings in string extension methods.
* Add unit tests for IsLowerCase and IsUpperCase and optimize the methods.
* Add unit tests for ReplaceNonAlphanumericChars and optimize the method.
* Add unit tests for StringWhitespace and optimize the method.
* Add unit tests for StripHtml and DecodeFromHex and optimize the methods.
Fix too aggressive regex for StripHTML to ensure works only on HTML tags.
* Add unit tests for EnsureStartsWith and EnsureENdsWith and optimize the methods.
* Add unit tests for ToSingleLine and StripNewLines and optimize the methods.
* Fix issues raised in code review.
* Added the SA1649 to the "No Warnings" section.
Stylecop is trying to enforce filenames that are like:
CancellableObjectEventArgs{TEventObject}.cs
However Umbraco uses CancellableObjectEventArgs.cs
Unless a policy decision is make to follow this stylecop rule, I think it is better to add this rule to the " NoWarn " section, so we don't see it appear at all.
* Revert accidental package-lock.json change
* Renaming files to match the StyleCop patterns.
Except two which would end up having the same names as other file, so these have been renamed as LegacyIScope & LegacyIScopeProvider, with local Pragma warnings disabled for this Style Cop rule.
* Removing the SA1649 from Warnings NOT as Errors.
In other words, if you turn on show warnings as errors, these will show as errors, rather than being suppressed.
* change to static import
* add support for passing modules to manifest js property
* Replaces dynamic imports of entry-point.js with static imports across all manifests
* Support statically imported modules in loader functions
Extended loadManifestApi and loadManifestElement to handle already resolved module objects (statically imported modules) in addition to dynamic imports. Updated type definitions in utils.ts to include module export types for loader properties.
* Add tests for loadManifest* functions in extension-api
Introduces unit tests for loadManifestApi, loadManifestElement, and loadManifestPlainJs functions. These tests cover various scenarios including direct class constructors, dynamic and static imports, export prioritization, and edge cases for null and undefined inputs.
* Added folder and files for the new condition.
* Registered the condition.
* Added an example to test the condition.
* Added the condition in one of examples.
* Renamed condition.
* Fixed linting error.
* fix(a11y): Toast notifications not announced by screen readers in Chrome
- Move screen reader live region from Shadow DOM to Light DOM (document.body)
Chrome doesn't reliably detect ARIA live regions inside Shadow DOM
- Use role="alert" with fresh elements for each announcement instead of
updating text content of an existing live region
- Fix invalid aria-role="true" attribute (was invalid HTML)
- Fix missing backslash in unicode escape '\u00A0'
The previous implementation had the live region nested 3 levels deep in
Shadow DOM, which Safari handled but Chrome ignored. Creating a new
alert element in Light DOM for each announcement is the most reliable
method across browsers.
Closes#14521🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Removed comment.
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Update Umbraco version in starterkits template
LTS and Latest should both install 17.0.0, at the moment latest uses Umbraco v17.1.0 but a starter kit version 17.0.0-rc1 which is not a good combo
* Update LTS in template to 17.1.0
* Tree pickers: Implement noAccess property UI handling for user start nodes
- Add noAccess observable to document and media tree item contexts
- Add visual styling (grayed out, italic) for noAccess items in tree views
- Update document and media picker input contexts to prevent selection of noAccess items
- Items with noAccess are shown for navigation but cannot be selected in pickers
This implements the UI handling for Feature 63060 "Handle Start Nodes"
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix noAccess implementation and add E2E tests
This commit combines all improvements made to the noAccess property feature:
1. Refactored to use Lit lifecycle methods (updated()) instead of property watchers
2. Added click and keyboard event handlers to prevent navigation
3. Removed disabled attribute that was blocking tree expansion
4. Added comprehensive E2E tests for document and media trees
Critical bug fix: Removed disabled attribute that prevented expansion
- The disabled attribute was blocking ALL interactions including expanding
tree items to show accessible children underneath noAccess ancestors
- Now only sets aria-disabled="true" for screen readers and removes href
- Click and keyboard event handlers still prevent navigation as intended
- Users can now properly navigate through noAccess ancestors to reach
their accessible child nodes
E2E test coverage:
- Display noAccess styling (opacity, italic)
- Prevent navigation when clicking noAccess nodes
- Allow expansion of noAccess nodes to show children
- Picker tests skipped pending infrastructure improvements
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Remove aria-disabled manipulation that interferes with tree expansion
The previous implementation set aria-disabled="true" and removed href
from the menu-item in #updateMenuItemAccessibility(). This approach
caused issues with tree expansion functionality.
Removed:
- #updateMenuItemAccessibility() method
- updated() lifecycle hook that called it
- UUIMenuItemElement import (no longer needed)
The click and keyboard event handlers already prevent navigation to
noAccess nodes, so additional DOM manipulation is not necessary.
Test results:
✅ 4 passing: Display styling and prevent navigation work correctly
❌ 2 failing: These appear to be backend issues:
1. Document expansion: Caret button disabled (backend marking noAccess
items as not selectable, which disables entire menu-item)
2. Media expansion: Child media folder incorrectly has noAccess attribute
(backend data issue - child should be accessible as it's the start node)
The UI implementation is sound. The remaining test failures indicate
backend API issues that need investigation.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fix path comparison bug in UserStartNodeEntitiesService (similar to #21162)
This fixes the same path comparison bug we fixed in PR #21162 but in C# string
comparisons instead of SQL queries.
## Root Cause
Path comparisons without trailing commas caused false matches:
- Path "-1,1001" incorrectly matched prefix "-1,100"
- This marked nodes as ancestors/descendants when they weren't related
## Examples of False Matches
- child.Path = "-1,1001", startNodePath = "-1,100"
- OLD: "-1,1001".StartsWith("-1,100") = TRUE (bug!)
- NEW: "-1,1001,".StartsWith("-1,100,") = FALSE (correct!)
- child.Path = "-1,100", startNodePath = "-1,1001"
- OLD: "-1,1001".StartsWith("-1,100") = TRUE (bug!)
- NEW: "-1,1001,".StartsWith("-1,100,") = FALSE (correct!)
## Fix Applied (Two Locations)
1. Line 146 (ancestor check): Added comma suffix to child.Path
2. Line 226 (IsDescendantOrSelf): Added comma suffix to both paths
This matches the pattern already used correctly in lines 92 and 191 of the
same file, and mirrors the SQL fix from PR #21162.
## Test Impact
This should fix the failing E2E test where child media folders were incorrectly
marked as noAccess when they were actually the user's start node.
Related: #21162
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fix remaining merge conflict markers in media-tree-item.element.ts
* Remove E2E agent markdown file (moved to personal space)
* test: adds mock data for noAccess
* feat: moves noAccess subscriber to base class
* test: adds mock data for media
* feat: moves no-access styling to the base class
* fix: media tree items should inherit styling from the base class
* feat: observes noAccess from children and reports back to the base class
* test: spec file should use undefined instead of null
* docs: add comprehensive comments explaining noAccess opt-in pattern
- Document why noAccess is not in base interface (breaking change)
- Explain opt-in pattern with code examples
- Add JSDoc comments to property, event handlers, and CSS
- Reference accessibility considerations (keyboard users)
- Link child class implementations to base class documentation
* test: adds timeout for URL to settle
* fix: allow clicks on accessible children of noAccess tree items
When a tree item has noAccess, child tree items are rendered in its slot.
Previously, the parent's click handler blocked ALL clicks due to event bubbling,
preventing users from navigating to accessible descendants.
Now checks if click originated from a child tree item element using closest().
If it's a child, allow the click. Only block clicks on the noAccess item itself.
Applied to both mouse clicks and keyboard navigation (Enter/Space).
This enables users to navigate through noAccess ancestors to reach their
accessible start nodes (e.g., Root[noAccess] → Child[noAccess] → Grandchild[accessible]).
Fixes tests:
- should allow expansion of noAccess ancestor node to show children (documents)
- should allow expansion of noAccess ancestor media node to show children (media)
* compare with the closest element to see if we are clicking on the element that is blocked or a sub-element that is not
* fix: adds forbidden route in case of no variants
* test: corrects label locator
* test: adds test to check if you can click or deeplink to restricted media
* test: removes .only
* test: removes duplicated tests
* test: adds test for document no-access
* test: add unit tests for user start node path comparison logic
Adds comprehensive unit tests documenting the path comparison fix that prevents
false matches when node IDs are numeric prefixes of other IDs (e.g., 100 vs 1001).
The fix uses trailing commas on both paths to ensure accurate comparison:
- Without fix: "-1,100".StartsWith("-1,10") = true ❌ (incorrect)
- With fix: "-1,100,".StartsWith("-1,10,") = false ✅ (correct)
Tests cover:
- Numeric prefix edge cases (1 vs 10, 10 vs 100, 100 vs 1001)
- Self comparison (start node itself)
- Descendant relationships
- Deep path hierarchies
- Demonstrates the bug without the fix for documentation
19 test cases total, all passing.
* test: removes .only
* fix: do not overwrite forbidden route
* docs: fixes line number in comment
* test: fixes comment
* feat: uses isSelectableContext to disable and scrub 'href' from base element
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adjust build scripts for custom elements and JSON schema generation to be placed at root level, add generation to build for npm and update .gitignore
* fix: updates umbraco package schema location
* git ignores
* fix: outputs the vscode custom elements file at root
* fix: adds generated files to output
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* fix(backoffice): use hardcoded Umbraco logo in header popover
Fixes issue where the backoffice header logo popover incorrectly
displayed the LoginLogoImageAlternative setting instead of showing
the Umbraco branding.
Changes:
- Added hardcoded umbraco-logo.svg asset to client project
- Updated backoffice-header-logo component to reference static logo
- Wrapped logo in link to umbraco.com
- Removed dependency on BackOfficeLogo endpoint for popover
The small header logo button still uses <umb-app-logo> and remains
customizable via the BackOfficeLogo setting.
Closes#62866
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* chore: removes link to umbraco.com
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(media-picker): auto-select uploaded media items
When uploading media in the media picker modal, uploaded items are now
automatically selected. This works for both single and multiple selection
modes, and correctly handles paginated folders where uploaded items may
not be visible on the current page.
Closes#21115🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix(media-picker): navigate to last page after upload
Uploaded media items get the highest SortOrder, placing them on the last
page. This change navigates to the last page after upload so users can
see their newly uploaded items, which are also auto-selected.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Update src/Umbraco.Web.UI.Client/src/packages/media/media/modals/media-picker/media-picker-modal.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Added tests to create a user group with description
* Clean up
* Moved tests for user group description to other class
* Bumped version
* Make tests run in the pipeline
* Reverted npm command
* Optimize retrieval of ContentCacheNode for draft and publish in when refreshing the hybrid cache.
* Fixed issue with XML header documentation tags.
* Use is null for consistency
---------
Co-authored-by: mole <nikolajlauridsen@protonmail.ch>
Add resilience to ServerEventRouter to prevent failures during unattended
install/upgrade when SignalR (especially Azure SignalR) is configured.
Changes:
- Skip server event routing when runtime level is not Run (Install/Upgrade)
- Add try-catch with warning logging for graceful degradation on SignalR failures
- Add backwards-compatible obsolete constructor using StaticServiceProvider pattern
- Add unit tests for runtime level checks
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
- Add UMB_WORKSPACE_EDIT_PATH_PATTERN and UMB_WORKSPACE_EDIT_VARIANT_PATH_PATTERN
to core workspace paths for generic edit URL generation
- Fix UmbPathPattern to support multi-level chaining via toAbsolutePatternString()
- Refactor workspace-menu-breadcrumb to use new path patterns
- Refactor menu-variant-tree-structure-workspace-context-base to use new patterns
- Refactor tree-item-context-base to use UMB_WORKSPACE_EDIT_PATH_PATTERN
- Refactor user-grid-collection-view to use existing UMB_EDIT_USER_WORKSPACE_PATH_PATTERN
- Remove outdated TODO about encoding uniques (handled at data source)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* fix(stylecop): resolve SA1106 - remove empty statement
* fix(stylecop): resolve SA1400 - add missing access modifiers
* fix(stylecop): resolve SA1028 - remove trailing whitespace
* fix(stylecop): resolve SA1306 - rename fields to lowercase
* fix(stylecop): resolve SA1130 - use lambda syntax
* fix(stylecop): resolve SA1121 - use built-in type aliases
* fix(stylecop): resolve SA1405 - add messages to Debug.Assert calls
* fix(stylecop): resolve SA1649 - rename files to match type names (partial)
* fix(stylecop): resolve SA1401 - convert fields to const/readonly (partial)
* fix(stylecop): resolve SA1116 - reformat multi-line parameters (partial)
* fix(stylecop): revert breaking changes, add V18 TODO comments
* fix: correct TODO comment for SA1306 - should rename to _completed
* Standardize API file names across modules - No code changes, file names.
- Extracts login model to a dedicated file and preserves binding behavior
- Renames multiple API files to align with updated conventions ( Just to match their names in the code, not changing the actual API names, i.e. no breaking changes )
- Updates DI extensions, mappings, and OpenAPI helpers to follow new naming
- Adjusts tests for consistent formatting and readability
- Preserves behavior; no logic changes, references kept intact
* fix(tests): refactor UserEmail to virtual property pattern
- Convert protected field _userEmail to virtual property UserEmail
- Remove dead code (_userEmail += "groupName" executed after request)
- Update derived test classes to use property instead of field
- Maintains original name to avoid breaking changes
- Follows best practice: virtual property allows derived class override
This was originally changed in my PR from UserEmail to _userEmail, so changing it back to ensure no breaking change, even though this is in a test class.
* Committing small fix to prevent a breaking change, adding commit for future removal.
* Renames helper class and removes BOM
Renames internal helper to follow naming conventions without the T prefix
Removes stray BOM from header to ensure clean compilation
No runtime behavior changes
* Split Physical FileSystem interface into it's own file.
* Split the IContentQueryService into it's own file
Also updated XML docs.
* Reverting the package-lock.json
* Updated the typo for Permision -> Permission
Updated the file name and class to: AddUserGroup2PermissionTable
This should be safe to do so as migrations are logged with their GUID's not the class names.
* Update src/Umbraco.Core/Scoping/CoreScope.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Reverting a binary change.
* Reverted rename of public migration class.
* Revert name in migration plan.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Ensure the description field added in a later migration for user groups is available when the earlier migration on this table runs.
* Update implementation of fix to store and use the state of UserGroupDto at the time of migrations.
* scaffolding of a collection text filter extension
* Refactor collection text filter to use API interface
* Fix incorrect tag
* Update types.ts
* Update collection-text-filter.extension.ts
* Add cancelation to debounced search on destroy
* clean up
* add js docs
* two way binding of filter value
* clean up
* Add collection text filter manifest example
Introduced a new filter manifest for the example collection and updated the main manifests file to include it. This enables a text filter extension for the example collection.
* Delete unused element and context
* Update src/Umbraco.Web.UI.Client/src/packages/user/user-group/collection/user-group-collection.context-token.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update user-group-table-collection-view.element.ts
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Add loading indicator to data-type-picker-flow-modal
- Added _isLoading state variable
- Updated #getDataTypes() to set loading state with try-finally
- Added uui-loader component in #renderGrid() when loading
- Created test file with basic tests
- Fixed linter warnings
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* Refactor: Replace inline styles with CSS class for loader
- Added .loader-container CSS class
- Removed inline styles from loader div
- Improves maintainability and follows best practices
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* Improve tests and revert unrelated package-lock.json changes
- Test observable behavior (loader element) instead of private properties
- Added tests for loader visibility during loading states
- Added test for loader removal after loading completes
- Reverted unintended changes to Umbraco.Web.UI.Login/package-lock.json
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* Refactor: Extract helper function in tests for cleaner code
- Added setLoadingState helper function to reduce code duplication
- Updated comments to reflect testing reactive state property
- Improved test readability and maintainability
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* delete test file not testing anything
* show loading indicator in search field instead
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Added tests for removing a not-found member picker
* Added tests for adding thumbnail to block
* Updated tests to match the test helper changes
* Refactor code to avoid duplication
* Added tests for removing a thumbnail from a block list/grid and refactor code
* Bumped version
* Bumped version and make tests run in the pipeline
* Update smokeTest command to use '@smoke' filter
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
- Add noAccess observable to document and media tree item contexts
- Add visual styling (grayed out, italic, cursor: not-allowed) for noAccess items in tree views
- Implement click prevention to block navigation when noAccess is true
- Update document and media picker input contexts with type-safe guards to prevent selection of noAccess items
- Create type guard utilities (isDocumentTreeItem, isMediaTreeItem) in separate utils files
- Items with noAccess are shown for navigation but cannot be selected or opened
This implements Task 63363 for Feature 63060 "Handle Start Nodes"
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Block Grid: Resolve translation keys for group names (closes#20696)
Add localization support for block group names in two locations:
- Block Grid area type permission combobox options
- Block catalogue modal group headers
Translation keys (e.g., #content_isPublished) used as group names
are now properly resolved instead of displaying the raw key.
* fix: moves group.name to mapper so search works
* fix: localizes block types in permissions element too
---------
Co-authored-by: Claude <noreply@anthropic.com>
Fix collection create action causing full page navigation instead of SPA routing
When a collection create action had an href, clicking it would trigger a full
browser navigation instead of using history.pushState for SPA routing. This was
caused by event.stopPropagation() being called before the early return when an
href was present, preventing the global ensureAnchorHistory() listener from
intercepting the click event.
The fix moves stopPropagation() to only execute when we're actually handling
the click via execute() (no href), allowing href-based navigation to bubble
to the window-level router listener for proper SPA navigation.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude <noreply@anthropic.com>
style: fix SA1500, SA1111, SA1134 StyleCop warnings
Fixed 194 StyleCop analyzer warnings across the codebase:
- SA1500: Move opening braces to their own line for multi-line statements (80 warnings)
- SA1111: Move closing parenthesis to same line as last parameter (50 warnings)
- SA1134: Place each attribute on its own line (64 warnings)
Also added XML documentation to any public APIs within the edited files.
* implement preventEditInvariantFromNonDefault for variant blocks
* remove unused
* refactor to enforce both document and block case from the document module
* remove implementation from doc workspace
* prevent editing invariant blocks from non default
* remove unused imports
* more explicit class names
* Refactor invariant edit guard rule creation
Extracted the creation of the invariant property edit guard rule into a reusable _createRule method in the controller base class. Updated block and document workspace controllers to use this method
* Refactor invariant edit rule logic into base controller
Moved the logic for observing properties and variant options and applying property guard rules into a new _observeAndApplyRule method in the base controller. Updated document block and workspace controllers to use this shared method, reducing code duplication and improving maintainability.
* Refactor invariant block edit check into helper methods
Extracted logic for checking invariant blocks and default language datasets into private async methods for better readability and maintainability. This refactor also corrects a context check typo and improves error handling.
* remove unused
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
- Fixed inverted logic in #parseNumber method
- Changed Number.isFinite(num) ? undefined : num to Number.isFinite(num) ? num : undefined
- Previously, valid max values (e.g., 50) were being ignored and defaulting to 100
- Now correctly parses and uses the configured Maximum Value from data type settings
This ensures the Maximum Value setting in Slider datatype configuration
is properly enforced in the slider UI component.
* fix(backoffice): allow drag and drop into empty link picker (closes#21295)
* refactor: use classMap to avoid empty class attribute
* refactor: use margin/padding trick for drop zone
* refactor: use CSS :has() selector instead of class
* also enable it for the Document input
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Route server events for public access updates to indicate an update to the protected document.
* Add unit tests for all ServerEventSender notification handlers.
* Adds additional test recommended in code review.
* Addressed parameter name issue raised in code review.
* Removed margin-top to address the loader icon shifting when entering text
* Space
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Fix test entrypoint
* Fix healthcheck.sh
* Ensure bind mounts gets created on host
* Fix bind mounts permission issues
* Generate self signed cert for dev
* Only generate cert for localhost
* Fixup docker compose file
* Update templates/UmbracoProject/entrypoint.sh
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update templates/UmbracoProject/Dockerfile
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix APP_UID runtime availability and optimize chown performance
- Export APP_UID as ENV so it's available at container runtime
(ARG values from .NET base image are only available at build time)
- Only run chown -R when directory ownership differs from APP_UID
to avoid slow recursive operations on large directories
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Fix bug where with recycle bin media protection on, the files on disk aren't deleted when the recycle bin is emptied.
* Fix display of media URL when in recycle bin and protection of trashed media is enabled.
* Clean-up of ContentCacheRefresher: resolved warnings and tidied up code and comments.
* Only flush the ID/Key map when content is deleted.
* Update src/Umbraco.Core/Cache/Refreshers/Implement/ContentCacheRefresher.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adding description to user groups
* Add description to dto and test and umbraco plan
* update unit test for user group
* remove change from link picker
* edit icon ui for user group
* Fixed table exists check in migration.
* update description in table user groups
* update user group editor css
* update description default
* remove description column element
* add ignore large method
* remove codesence
* update user group descriptions default
* Added description to constructor of ReadOnlyUserGroup.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
When changing a property's variation setting (Shared/Invariant ↔ Variant) via Infinite Editing,
the document would fail to save with a 404 error.
This fix:
- Adds value migration fallback logic in UmbPropertyValuePresetVariantBuilderController
to find values when culture/segment doesn't match exactly
- Overrides reload() in UmbContentDetailWorkspaceContextBase to process incoming data
through _processIncomingData() for proper value transformation
- Detects property variation changes and triggers document reload to migrate values
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Avoid an unnecessary look-up for the super-user when resolving ID from key and vice versa.
Utilise an async database methods given the enclosing method is async.
* Applied suggestions from code review.
* Revered async amend (caused pipeline failures with integration tests).
* Apply suggestions from code review
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Added transitive dependency references to specific libraries where direct dependencies depend on vulnerable versions.
* Enable CentralPackageTransitivePinningEnabled.
* Update MS dependencies to 10.0.1 patch versions.
* Removed System.Text.Encodings.Web.
* Add TODOs for pinned dependency removal.
* working on a auto closing ... modal when focus leaves
* remove appsetting for local development
* rewrites the focus function to check if the shadow dom exsits before trying to set focus
* Fix JSON formatting in appsettings.Development.template.json
* Simplify focus logic in entity action list
Refactored the focus method to directly focus the first menu item after it is rendered, removing unnecessary nested updateComplete checks and focusing logic for the label button.
* Remove unused 'nothing' import and minor formatting
* Call ext.component?.focus() instead of chaining updateComplete promises.
* Update entity-action-list.element.ts
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
Co-authored-by: engjlr <enl@umbraco.dk>
* Add IMarkdownToHtmlConverter abstraction with Markdig and HeyRed implementations
- Add IMarkdownToHtmlConverter interface in Umbraco.Core.Strings
- Add MarkdigMarkdownToHtmlConverter using the Markdig library (new default)
- Add HeyRedMarkdownToHtmlConverter using HeyRed.MarkdownSharp (deprecated, for backwards compatibility)
- Update HealthChecks.MarkdownToHtmlConverter to use the new abstraction
- Update MarkdownEditorValueConverter to use the new abstraction
- Add unit tests for both markdown converter implementations
- Add unit tests for HealthChecks.MarkdownToHtmlConverter syntax highlighting
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from code review.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adds a check to ensure notifications are only added to relevant CMS management API endpoints.
* Add null check for tagging actions to handle null management API GroupName.
* Provide abstraction for the DocInclusionPredicate when configuring SwaggerGenOptions.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Cache: Clear ContentTypeCommonRepository cache when data types change
When a data type's EditorAlias is changed (e.g., BlockList to SingleBlock), the ContentTypeCommonRepository 5-minute cache was not being cleared. This caused content types to return stale PropertyEditorAlias values until server restart, leading to validation using the wrong property editor validators.
The fix adds IContentTypeCommonRepository as a dependency to DataTypeCacheRefresher and calls ClearCache() in RefreshInternal(), matching the pattern already used in ContentTypeCacheRefresher and TemplateCacheRefresher.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Fixed the 22 warnings.
Also updated the XML documentation where required.
* Updating XML docs.
* Noted version in obsoletion message.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Use Append for response headers
- Replaces Add with Append when adding response headers to conform to IHeaderDictionary usage.
- Applies across unauthorized handling, redirects, and custom header signaling.
- Updates tests to use Append consistently.
- Removes ASP0019 from warnings in project configs to reflect new approach.
Silences deprecation warning in dev mode
Silences deprecated runtime-compile warning in dev mode
Keeps development-time runtime compilation enabled for in-memory dev setup
Relates to ASPDEPR003
* Bumped version
* Updated tests to match new changes
* Bumped version
* Bumped version
* Use isSuccessNotificationVisible instead of doesSuccessNotificationHaveText
* Updated tests to avoid flaky tests
* Bumped version of test helper
* Bumped version of test helper
* Bumped version
* Bumped version
* Bumped version
* Update waits to avoid hardcoded values
* fix(SYSLIB0051): Remove obsolete serialization constructors
Removes obsolete formatter-based serialization constructors from exception
classes to resolve SYSLIB0051 warnings. This is NOT a breaking change as:
- Binary serialization is deprecated in modern .NET
- No BinaryFormatter usage exists in the codebase
- Microsoft recommends removing these obsolete constructors
Affected files:
- AuthorizationException.cs
- BootFailedException.cs
- ConfigurationException.cs
- PanicException.cs
- UnattendedInstallException.cs
- RetryLimitExceededException.cs
- IncompleteMigrationExpressionException.cs
- HttpUmbracoFormRouteStringException.cs
- ModelBindingException.cs
Also removes SYSLIB0051 from WarningsNotAsErrors in project files.
* fix(SYSLIB0051): Mark obsolete serialization constructors for removal in v19
* fix: Resolve CS0108 compiler warnings by adding explicit 'new' keyword
fix: Resolve CS0108 compiler warnings by adding explicit 'new' keyword to hiding members
- Add 'new' modifier to Empty properties in BlockGridModel, BlockListModel, RichTextBlockModel
- Add 'new' modifier to DeepCloneWithResetIdentities in IContentType, IMediaType
- Add 'new' modifier to Save/GetById methods in IContentService, IMediaService, IMemberService
- Add 'new' modifier to EFCore interface members (IAmbientEFCoreScopeStack, IEFCoreScope)
- Add 'new' modifier to ExternalLoginSignInResult.NotAllowed and CreateMediaTypeRequestModel.Collection
- Improve XML documentation for edited public members
Note: CS0114 warnings (virtual/override) were intentionally not fixed as they may be breaking changes. Will add more details to the PR.
* fix: Resolve CS0108 compiler warnings by adding explicit 'new' keyword
fix: Resolve CS0108 compiler warnings by adding explicit 'new' keyword to hiding members
- Add 'new' modifier to Empty properties in BlockGridModel, BlockListModel, RichTextBlockModel
- Add 'new' modifier to DeepCloneWithResetIdentities in IContentType, IMediaType
- Add 'new' modifier to Save/GetById methods in IContentService, IMediaService, IMemberService
- Add 'new' modifier to EFCore interface members (IAmbientEFCoreScopeStack, IEFCoreScope)
- Add 'new' modifier to ExternalLoginSignInResult.NotAllowed and CreateMediaTypeRequestModel.Collection
- Improve XML documentation for edited public members
Note: CS0114 warnings (virtual/override) were intentionally not fixed as they may be breaking changes. Will add more details to the PR.
* Modifying the PR based on feedback from Andy.
Files Modified (Removed Duplicate Members)
src/Umbraco.Cms.Api.Management/ViewModels/MediaType/CreateMediaTypeRequestModel.cs
Removed duplicate Collection property (already defined in base class ContentTypeModelBase)
src/Umbraco.Core/Services/IContentService.cs
Removed duplicate GetById(Guid key) method (already in IContentServiceBase<IContent>)
Removed duplicate Save(IEnumerable<IContent> contents, ...) method (already in IContentServiceBase<IContent>)
src/Umbraco.Core/Services/IMediaService.cs
Removed duplicate GetById(Guid key) method (already in IContentServiceBase<IMedia>)
Removed duplicate Save(IEnumerable<IMedia> medias, ...) method (already in IContentServiceBase<IMedia>)
src/Umbraco.Core/Services/IMemberService.cs
Removed duplicate Save(IEnumerable<IMember> members, ...) method (already in IContentServiceBase<IMember>)
Files Left Unchanged (Keeping new keyword)
The following files were correctly fixed with the new keyword because they intentionally hide base members to return more specific types:
BlockGridModel.cs, BlockListModel.cs, RichTextBlockModel.cs - Empty returns specific type
IContentType.cs, IMediaType.cs - DeepCloneWithResetIdentities returns specific interface
ExternalLoginSignInResult.cs - NotAllowed returns ExternalLoginSignInResult instead of SignInResult
IEFCoreScope.cs, IAmbientEfCoreScopeStack.cs - re-declarations for documentation purposes
* fix: Resolve CS0108 compiler warnings by adding explicit 'new' keyword
fix: Resolve CS0108 compiler warnings by adding explicit 'new' keyword to hiding members
- Add 'new' modifier to Empty properties in BlockGridModel, BlockListModel, RichTextBlockModel
- Add 'new' modifier to DeepCloneWithResetIdentities in IContentType, IMediaType
- Add 'new' modifier to Save/GetById methods in IContentService, IMediaService, IMemberService
- Add 'new' modifier to EFCore interface members (IAmbientEFCoreScopeStack, IEFCoreScope)
- Add 'new' modifier to ExternalLoginSignInResult.NotAllowed and CreateMediaTypeRequestModel.Collection
- Improve XML documentation for edited public members
Note: CS0114 warnings (virtual/override) were intentionally not fixed as they may be breaking changes. Will add more details to the PR.
* Modifying the PR based on feedback from Andy.
Files Modified (Removed Duplicate Members)
src/Umbraco.Cms.Api.Management/ViewModels/MediaType/CreateMediaTypeRequestModel.cs
Removed duplicate Collection property (already defined in base class ContentTypeModelBase)
src/Umbraco.Core/Services/IContentService.cs
Removed duplicate GetById(Guid key) method (already in IContentServiceBase<IContent>)
Removed duplicate Save(IEnumerable<IContent> contents, ...) method (already in IContentServiceBase<IContent>)
src/Umbraco.Core/Services/IMediaService.cs
Removed duplicate GetById(Guid key) method (already in IContentServiceBase<IMedia>)
Removed duplicate Save(IEnumerable<IMedia> medias, ...) method (already in IContentServiceBase<IMedia>)
src/Umbraco.Core/Services/IMemberService.cs
Removed duplicate Save(IEnumerable<IMember> members, ...) method (already in IContentServiceBase<IMember>)
Files Left Unchanged (Keeping new keyword)
The following files were correctly fixed with the new keyword because they intentionally hide base members to return more specific types:
BlockGridModel.cs, BlockListModel.cs, RichTextBlockModel.cs - Empty returns specific type
IContentType.cs, IMediaType.cs - DeepCloneWithResetIdentities returns specific interface
ExternalLoginSignInResult.cs - NotAllowed returns ExternalLoginSignInResult instead of SignInResult
IEFCoreScope.cs, IAmbientEfCoreScopeStack.cs - re-declarations for documentation purposes
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Reverted the one of the changes and updated some XML doc tags.
* Should have committed these files.
Corrected a name space in the test files.
* Remove warning on missing access modifiers on interface members.
* Revert breaking namespace change.
* Fixed build errors following namespace reversion.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(tests): Replace obsolete APIs in Umbraco.TestData controllers
Replaced deprecated synchronous service methods with their modern async
equivalents in the TestData controllers to eliminate CS0618 warnings.
Changes:
- LoadTestController: Replace IFileService with ITemplateService,
use IDataTypeService.GetAsync(Guid) instead of GetDataType(int),
use IContentTypeService.CreateAsync() instead of Save()
- SegmentTestController: Use IContentTypeService.UpdateAsync()
instead of Save()
- UmbracoTestDataController: Use IContentTypeService.CreateAsync()
and UpdateAsync() instead of Save()
Also adds comprehensive XML documentation to all three controllers
including class summaries, constructor parameters, and method
documentation.
The controllers now use:
- Constants.DataTypes.Guids.TextstringGuid instead of magic int -88
- Constants.Security.SuperUserKey for async service operations
- Task<IActionResult> return types where async operations are used
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Further amends from code review.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(benchmarks): resolve obsolete BenchmarkDotNet API warnings
Update BenchmarkDotNet configuration to use current API methods:
- Replace deprecated `ManualConfig.Add()` with `AddDiagnoser()` for memory diagnostics
- Replace deprecated `ConfigExtensions.With()` with `AddJob()` for job configuration
- Initialize `_totalItemCount` field to suppress CS0649 warning
These changes resolve 4 compiler warnings (CS0618, CS0649) in the benchmark project
without any functional changes.
* Removing the benchmark artifacts and adding the folder to gitignore
* Added XML Docs to the files in Umbraco.Cms.Imaging.ImageSharp2
This commit fixes the missing XML documentation with the Umbraco.Cms.Imaging.ImageSharp2 project.
Now this project should have no build warnings.
* Update src/Umbraco.Cms.Imaging.ImageSharp2/UmbracoBuilderExtensions.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fixing the build warnings in the Umbraco.Tests.Common Project
The main warning was about the file name not matching the class, this was because an interface was being defined first within the class file.
This should either be moved into its own file, or to the bottom of the file to fix this warning. Rather than creating a new file, I've moved the interface to the bottom, but if you'd prefer a new file, just let me know :)
Also removed the TODO in the project file and the WarningsNotAsErrors as they have all been resolved.
* Moved the interface into it's own file.
* Removed the interfaces folder.
- Replace obsolete constructor call that used IUmbracoContextAccessor
- Use new constructor with IDocumentUrlService instead
- Add using for Umbraco.Cms.Core.Services namespace
- Remove unused Umbraco.Cms.Core.Web namespace
The obsolete constructor was scheduled for removal in Umbraco 18.
This is an internal change only - ControllersAsServicesComposer is not
shipped with Umbraco.Templates package.
This commit fixes around 1,000 build warnings related to SA1117, this warning is related to ensuring each parameter passed into a function is on a new line OR all on one line.
I have also added XML code comments to any public function within these files and fixed some that had invalid / old comments.
When changing a property's variation setting (Shared/Invariant ↔ Variant) via Infinite Editing,
the document would fail to save with a 404 error.
This fix:
- Adds value migration fallback logic in UmbPropertyValuePresetVariantBuilderController
to find values when culture/segment doesn't match exactly
- Overrides reload() in UmbContentDetailWorkspaceContextBase to process incoming data
through _processIncomingData() for proper value transformation
- Detects property variation changes and triggers document reload to migrate values
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
fix(user): fix avatar change and remove functionality
- Fix "Change photo" button not working on subsequent clicks by using
{ once: true } on the event listener and resetting the input value
- Fix avatar not disappearing after removal by clearing _imgSrc when
imgUrls is set to empty array
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
The validation message was showing the total character count instead of how
many characters exceeded the limit. For example, with max=4 and input="12345",
it showed "5 too many" instead of "1 too many".
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Content Type Workspace: Sync current data after save to prevent navigation blocking
After saving a content type, only `_data.setPersisted()` was called without
`_data.setCurrent()`. An observer kept `current` in sync with the structure's
ownerContentType, but timing mismatches caused `persisted` and `current` to
differ, triggering false "unsaved changes" detection and blocking navigation.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Fixed various obsolete .NET API calls.
These all show up as warnings when you try to build the Umbraco solution:
- SYSLIB0045 (6) - Use proper HashAlgorithm creation
- SYSLIB0023 (4) - Replace RNGCryptoServiceProvider with RandomNumberGenerator
- SYSLIB0021 (8) - Replace deprecated crypto types
- SYSLIB0013 (4) - Replace Uri.EscapeUriString
Fix unintended reference comparison in tests
Explicitly casts the mock property to string in a predicate to prevent reference equality checks. Adds constraints for storage type and editor to align with expected data characteristics and improve test reliability. Keeps mock service behavior unchanged; minor formatting tweak included.
* Fixes the warning CS8524 and tidying up the SetStatusRedirectUrlManagementController
I have added throwing an error in the switch statement if neither of the know enums is submitted to the API, in theory this should never happen.
The other option would be to simply return false, but I think throwing the exception is better as it will alert whoever is calling the API that their call is invalid.
* Update src/Umbraco.Cms.Api.Management/Controllers/RedirectUrlManagement/SetStatusRedirectUrlManagementController.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Improves log message clarity
- Refines a warning when a property type alias is missing, clarifying that a default value is returned.
- Improves backoffice token revocation log by including contextual client id for easier troubleshooting.
- Corrects model generation error logging by passing the exception as the first argument for consistency.
* Added tests for media delivery api
* Added tests for content delivery api
* Fixed import
* Added tests for Content Delivery API
* Updated skip tag and issue link for the failing tests
* Bumped version
* Refactor code for content delivery api tests
* Moved repeat steps to beforeEach and added more waits
* Bumped version
* Added more waits
* Updated variable names
* Grouped tests
* Renamed
* Fixed names
* Added tests for rendering content with block list
* Updated tests for rendering content with block lists
* Updated message when has no block lists
* Added tests for rendering content with block grid
* Updated code
* Bumped version
* Changed npm command to make tests run in the pipeline
* Fixed comment
* Reverted command
* fix(code-quality): resolve CS0628 warnings - change protected to private in sealed classes
Changed protected members to private in sealed classes across 26 files. Protected members in sealed classes serve no purpose since sealed classes cannot be inherited. This eliminates 57 CS0628 compiler warnings.
* fix: use public for NUnit SetUp methods per Copilot review
NUnit requires SetUp methods to be at least protected. Using public
avoids CS0628 while allowing NUnit to discover and execute the methods.
* Clean up
- Renames internal fields to clearer names and aligns with conventions
- Changes internal cache holder to use auto-properties for state ( fixes another build warning )
- Removes an unused exception type from the loader and cleans up unused usings
- Adds "Umbraco" to the list of known spellings in .vsCode settings file, amazed this wasn't already there :)
* Improvements to fix CodeScene Code Health Review issues.
- Introduces debug-only logging helpers and routes all log messages through them for consistency
- Centralizes retrieval of discoverable types and scanning logic to simplify paths
- Aligns logging of cached vs non-cached and slow paths with new helpers
- Documents data-holding structure used to store type lists for clarity
* Refactoring to make CodeScene happy, removing code duplication :)
Fix unawaited async calls in tests
- Converts setup to async and awaits data creation
- Awaits operation status update to fix potential unawaited calls
- Updates nested validation tests to use await for helper results
- Removes stray BOM character in a test file
- Improves overall async flow, addressing CS4014
Relates to CS4014
* TDD solution to Block level variance publishing changing to no variance retaining block level variance values and vica versa
* Add similar tests for the other block editors
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Amend the test scenarios
* Simplify the merge clean-up to remove all misaligned values.
* Fix failing test (remove false assumptions)
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* TDD solution to Block level variance publishing changing to no variance retaining block level variance values and vica versa
* Add similar tests for the other block editors
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Amend the test scenarios
* Simplify the merge clean-up to remove all misaligned values.
* Fix failing test (remove false assumptions)
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Add null checks in case content no longer exists
* Add logging statement
* Add integration tests for null handling in cache refresh services
Tests verify that DocumentUrlService and PublishStatusService
do not throw exceptions when called with non-existent content keys,
which can happen when processing stale cache instructions.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add integration tests for stale cache instruction handling
Tests simulate the scenario where a cache instruction is processed
for content that has been deleted (stale instruction). This can happen when:
1. Content is saved (cache instruction queued)
2. Content is deleted before instruction is processed
3. Server restarts and processes the stale instruction
Tests cover:
- ContentCacheRefresher with RefreshBranch for deleted content
- ContentCacheRefresher with RefreshNode for deleted content
- MediaCacheRefresher with RefreshBranch for deleted media
- Processing instructions for content that never existed
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Added tests for removing a not-found content picker
* Added comment
* Bumped version
* Change npm command to make tests run in the pipeline
* Reverted npm command
* Added base class
* Added implementation of base class
* Added missing parameter
* Added try-catch around delete operations in Purge() to ignore locked files during cleanup.
* Content: Fix name() and getName() to use active variant when no variantId provided
When calling `name()` or `getName()` without a variantId argument, the methods
now correctly return the name of the first active variant from the split view
instead of always returning the first variant in the data array.
The `name()` method now returns a reactive observable that updates when the
active variant changes, using `mergeObservables` to combine the split view's
active variant observable with the variants data.
The `getName()` method now uses `splitView.getActiveVariants()[0]` to get the
current active variant synchronously, with a fallback to the first variant if
no active variant is set.
This fixes an issue where block previews could not reactively observe the
document name because the callback parameter was always empty.
Closes#20759🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* chore: use UmbVariantId.compare() for consistent variant matching
Address PR review feedback by using UmbVariantId.Create() and compare()
instead of direct property comparison. This ensures consistent behavior
with the existing variant comparison pattern used throughout the codebase.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* chore: formatting
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Re-provide support for casting a published member to the models builder type.
* Used new constructor for MemberManager in unit tests.
* Fix failing unit tests.
* Relations: Fix descendants query to exclude parent item
The GetPagedDescendantsInReferences query was using a path LIKE without
the comma delimiter, causing it to match both the parent item and its
descendants. This resulted in the trash confirmation dialog showing
the item being deleted in the "descending items with dependencies"
list.
Changed the WhereLike call to use ",%" suffix instead of just "%",
so the query only matches actual descendants (items whose path
starts with the parent's path followed by a comma).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add integration test to verify behaviour.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Fix SQL Server deadlock during concurrent document updates
Add ReadLock on ContentTree in RefreshMemoryCacheAsync to prevent
deadlocks between cache refresh SELECT queries and concurrent document
UPDATE operations. The deadlock occurred because the operations accessed
umbracoNode and umbracoDocument tables in different orders.
The #debouncedLoadTree method was not awaiting repository initialization
before calling loadChildren() when hideTreeRoot was true. This caused a
"repository is missing" error in tree pickers like the Static File picker
used for block thumbnails.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Added tests for regression issue #20962
* Added tests for regression issue #20520
* Added tests for rendering content with RTE
* Added @release tags
* Bumped version
* Make new added tests run in the pipeline
* Updated dataTypeName
* Fixed comments
* Reverted npm command
* fix: add write lock at outer scope to prevent deadlocks in content publishing
Acquire a write lock on ContentTree at the start of PublishAsync to prevent
deadlocks. Previously, inner scopes would acquire read locks first (via
repository operations), then attempt to upgrade to write locks, causing
deadlocks when multiple transactions tried this simultaneously.
By acquiring the write lock at the outer scope, we ensure consistent lock
ordering and prevent the deadlock scenario.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Re-enable lazy locks
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Introduce new content type schema service and models
To be used in the future for content type schema generation.
* Do not fail when content type is not in cache, simply ignore
* Added unit and integration tests
* Fix failing unit tests
* Addressing comments from code review
* add content key and type to link info on RTE delivery API data. Fix tests to accomodate changes
* convert field type content-id -> destination-id. convert field type content-type -> link-type and use LinkType enum instead.
* revert unintended find and replace changes
* apply patch by kjac
* fix unit tests for RTE parsers
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* block context example
* fix clone method
* implement contextual variant id
* use contextual variant id
* ensure currentExposeOf uses elementType configuration
* make hasExposeOf use ElementType configuration for variatId
* Update src/Umbraco.Web.UI.Client/src/packages/rte/components/rte-base.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* rename to displayVariant
* use variantid in this case
* update readme
* return false
* remove unused imports
* return undefined
* append UmbWorkspaceViewElement interface
* remove test
* fallback to false
* fallback to false
* refactor what is not exposed.
* Fix#20944: Updating UI Slider number properties to accept decimal values (#20945)
* updating UI slider properties min, max, initial1, initial2 and step to accept decimal values
* Changes based on Copilot suggestions
* Used a smaller step value configuration.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
Co-authored-by: engjlr <enl@umbraco.dk>
* Manifests: Fix misnaming and mis-registering of the document validation manifest (closes#21128) (#21139)
Fix misnaming and mis-registering of the document validation manifest.
* Performance: Optimize memory footprint of document URL cache (closes#21055) (#21066)
* Optimize memory footprint of document URL cache.
* Update tests/Umbraco.Tests.UnitTests/Umbraco.Core/Services/DocumentUrlServiceTests.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Used properties, added some further comments.
* Fixed failing integration tests.
* Ensure no edge case exists where the culture code to language Id map isn't up to date with the newly created languages.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Block List: Sort mode (#21060)
* Block List: added sort-mode
* Fix missing closing bracket
* register sort mode toolbar element on start up
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
# Conflicts:
# src/Umbraco.Web.UI.Client/src/packages/block/block-list/property-editors/block-list-editor/property-editor-ui-block-list.element.ts
* Update nightly build to include 16 as 17 is now main (#21144)
* Global search items missing Umbraco url segment (#20266)
* Add /umbraco url Segament for searched mapped results to aviod 404 og navigation away from backoffice
* Applied changes from code review.
---------
Co-authored-by: Lucas Bach Bisgaard <lucas.bisgaard@kraftvaerk.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* import
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Jason Andrae <jasona@emergentsoftware.net>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Lee Kelleher <leekelleher@users.noreply.github.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Sven Geusens <sge@umbraco.dk>
Co-authored-by: Lucas Bach Bisgaard <rammi@rammi.dk>
Co-authored-by: Lucas Bach Bisgaard <lucas.bisgaard@kraftvaerk.com>
* get full path of file
* get configuration umbracosspath from BE and use it when get css file
* fix lint error
* update for test fail
* add obsolete constructor
* Update src/Umbraco.Cms.Api.Management/Controllers/Server/ConfigurationServerController.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Cms.Api.Management/Controllers/Server/ConfigurationServerController.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added `umbracoCssPath` to mock Server handler
* Added `umbracoCssPath` to Server Connection controller
* Removed the Tiptap Config Repository/Store code
we can simplify this by reusing the Server Context.
* Used `UMB_SERVER_CONTEXT` to get the `umbracoCssPath`
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Add /umbraco url Segament for searched mapped results to aviod 404 og navigation away from backoffice
* Applied changes from code review.
---------
Co-authored-by: Lucas Bach Bisgaard <lucas.bisgaard@kraftvaerk.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Optimize memory footprint of document URL cache.
* Update tests/Umbraco.Tests.UnitTests/Umbraco.Core/Services/DocumentUrlServiceTests.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Used properties, added some further comments.
* Fixed failing integration tests.
* Ensure no edge case exists where the culture code to language Id map isn't up to date with the newly created languages.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Populate repository cache by GUID when retrieving documents by integer ID, to avoid database hit on subsequent retrieval by key.
* Apply same for media repository.
* Use existing helper to centralise generation of repository cache keys.
* Minor clean-up.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Applied suggestions from code review.
* Apply suggestions from code review
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Applied suggestions from code review.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Block Workspace: Only update view title when opened in modal context
Prevents unintended document title updates when block workspace is used
outside of modal context. Also adds early return in view controller when
no local title is available to avoid setting an empty title prefix.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* View Controller: Reactivate parent view when child is removed
When a non-inheriting child view (like a modal) is removed, the parent
view may have been deactivated. This change ensures the parent view is
reactivated to restore the browser title when the modal closes.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/view/context/view.controller.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Docs: Add PR naming convention to CLAUDE.md
Integrate the PR naming guidelines from PullRequestNaming.md into the
Pull Request Process section of CLAUDE.md for better discoverability.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove area
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Introducing lock and logic to find directory to be deleted
* Obsoleting old ctor
* Expanding obsolete comment
* Adding new parameter to tests
* Adding database to failing integration tests.
* Adding more tests
* Fixing flawed logic
* Cleanup on FileSystemsTests.cs
UFM Filter base, check that the component is connected to the DOM
otherwise the context no longer exists and the `render` still runs,
giving a bunch of "missing filter" warnings.
fix: add write lock at outer scope to prevent deadlocks in content publishing
Acquire a write lock on ContentTree at the start of PublishAsync to prevent
deadlocks. Previously, inner scopes would acquire read locks first (via
repository operations), then attempt to upgrade to write locks, causing
deadlocks when multiple transactions tried this simultaneously.
By acquiring the write lock at the outer scope, we ensure consistent lock
ordering and prevent the deadlock scenario.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Adding allow content type alias settings and validator
* Creating private helper method for tests
* Revisiting logic for disallow types
* Adding tests for validator
* Obsolete unnecessary methods and overloads.
* Fix warning and update naming in tests.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Adjust the document type creation flow so that a template can be created for a content type
Add id, name and alias to the request payload to allow creating multiple templates for the same document type
Small adjustments
Remove unused import and unnecessary async
Switched content type template creation to content type controller
Missing constant export
# Conflicts:
# src/Umbraco.Web.UI.Client/src/packages/core/backend-api/sdk.gen.ts
* Add default implementation for CreateForContentTypeAsync
* Small adjustments from code review
* Introduce InvalidTemplateAlias content type operation status
* Add tests for CreateTemplateAsync and fix alias validation
- Add integration tests for ContentTypeService.CreateTemplateAsync:
- Success case with template association
- NotFound status for non-existent content type
- InvalidTemplateAlias for empty and too-long aliases
- Default template assignment verification
- Fix bug in TemplateService.CreateAsync where alias validation
occurred after GetViewContent call, causing ArgumentNullException
for invalid aliases instead of returning InvalidAlias status
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Use EagerWriteLock for long running operations
Switch from WriteLock to EagerWriteLock when acquiring the lock for
long running operations to ensure proper lock acquisition timing.
* Sync: Fix SyncBootStateAccessor to use ILastSyncedManager
Update SyncBootStateAccessor to use the new ILastSyncedManager interface
instead of the deprecated LastSyncedFileManager, which was causing cold
boots to be triggered every time.
- Replace LastSyncedFileManager field with ILastSyncedManager
- Add new primary constructor accepting ILastSyncedManager
- Add obsolete constructors for backwards compatibility using StaticServiceProvider
- Update GetSyncBootState to use GetLastSyncedExternalAsync
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Sync: Add integration tests for SyncBootStateAccessor
Add integration tests to verify SyncBootStateAccessor correctly
determines cold boot vs warm boot state based on ILastSyncedManager.
- Test cold boot when no last synced ID exists
- Test warm boot when last synced external ID matches a cache instruction
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Sync: Fix SyncBootStateAccessor to use ILastSyncedManager
Update SyncBootStateAccessor to use the new ILastSyncedManager interface
instead of the deprecated LastSyncedFileManager, which was causing cold
boots to be triggered every time.
- Replace LastSyncedFileManager field with ILastSyncedManager
- Add new primary constructor accepting ILastSyncedManager
- Add obsolete constructors for backwards compatibility using StaticServiceProvider
- Update GetSyncBootState to use GetLastSyncedExternalAsync
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Sync: Add integration tests for SyncBootStateAccessor
Add integration tests to verify SyncBootStateAccessor correctly
determines cold boot vs warm boot state based on ILastSyncedManager.
- Test cold boot when no last synced ID exists
- Test warm boot when last synced external ID matches a cache instruction
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Improve deletion logic in UmbracoContentIndex
When re-indexing a node it will first delete it, however in many cases the query to delete doesn't return anything, however a delete command is still executed with an empty integer collection. We can avoid allocating and iterating lists and avoid the deletion call all together if the collection is empty.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Clean-up and warning resolution whilst we are modifying class.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add entity collection item card extension type + default elements
* implement user collection item card
* fix selection events
* map to prop
* add prop/attr for href
* add support for which detail properties to show
* update type import
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/item/entity-collection-item-card/entity-collection-item-card.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* import card in correct file
* Fix event listener binding for selection events
* implement disabled property for collection item cards
* init commit of collection item ref extension
* fix imports
* add element interface
* Implement UmbEntityCollectionItemElement interface in item cards
Added the UmbEntityCollectionItemElement interface to document and user collection item card elements for improved type safety and consistency. Updated type exports to include the new interface.
* Update collection item ref to use uui-ref-node
Replaces the placeholder div with a uui-ref-node component, passing relevant item properties and event handlers. Adds dynamic icon rendering using umb-icon.
* Refactor entity collection item elements to use shared base
Introduces a new abstract base class for entity collection item elements, consolidating shared logic for card and ref variants. Updates card and ref element implementations to extend the new base, and refactors extension manifest interfaces for consistency. This improves maintainability and reduces code duplication.
* use class instead of magic string
* introduce ref and card collection view kinds
* Utilise card kind for user collection view
* Add item-specific href support to collection views
Introduces a requestItemHref method to collection contexts for retrieving item-specific hrefs. Updates card, ref, and user table collection views to use these hrefs, enabling dynamic linking for collection items. Refactors user table name column layout to accept href via value prop instead of constructing it internally.
* Update ManifestCollectionView import path
Changed the import of ManifestCollectionView from '../extensions/types.js' to '../view/types.js' to reflect its new location.
* use box
* render entity actions
* use edit path builder for user links
* rename method
* Revert "rename method"
This reverts commit 4df577688e.
* Update collection-default.context.ts
* make type lint ignore unused args with an underscore
* temp remove unused
* only make collection vie selectable if there are any registered bulk actions
* don't render name link if there is no href
* fix imports
* use selectable state
* Update language-table-collection-view.element.ts
* Update card-collection-view.element.ts
* clean up
* Refactor collection views to use shared base class
* refactor(collection): parallelize href fetching and make method private
* docs(examples): update collection example to use card and ref kinds
* docs(examples): add icon property to collection example data model
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/types.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update collection-bulk-action.manager.test.ts
* Removed duplicate and redundant '@typescript-eslint/no-unused-vars' rule definitions, consolidating the configuration to use only 'argsIgnorePattern'.
* Handle missing user href in name column layout
Replaces the user name link with a span when the href property is not provided, preventing broken links in the user table name column layout.
* Update user-table-name-column-layout.element.ts
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
When multiple Umbraco extensions (e.g., BulletList and OrderedList) include
the same Tiptap extension (ListItem), duplicates were added to the extensions
array, causing Tiptap to log warnings. This change uses a Map to deduplicate
extensions by their name property before passing them to the Editor.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Added 'mandatory' tag as a visual indicator for webhook events being mandatory.
* Map the webhook validation for no events specified to a specific API response problem details message.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
The contributing documentation still referenced the old `contrib` branch,
which was causing AI tools to incorrectly use it as the base branch for
comparisons. Updated all references to use `main` instead.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude <noreply@anthropic.com>
* Back-office auth: Calculate token cookie names at request time
The __Host- cookie prefix enforces secure cookies at browser level,
which caused cookies to be rejected when running over HTTP in local
development environments even when UseHttps was set to false.
Cookie names are now calculated per-request based on both the UseHttps
setting and whether the current request is over HTTPS, matching the
logic used for the Secure cookie option.
* Update src/Umbraco.Cms.Api.Common/DependencyInjection/HideBackOfficeTokensHandler.cs
Co-authored-by: Sven Geusens <sge@umbraco.dk>
---------
Co-authored-by: Sven Geusens <sge@umbraco.dk>
* Adding functionality to overwrite the cacheduration for NewsDashboard
* Making the extension its own class, as to avoid having to inherit the entire service.
* Changing options to duration and adding interface
* Only validate segment values for cultures they are defined for.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Integration test suppressions.
* Remove previous implementation using ISegmentService and rely on values provided in the model to determine segments with cultures.
* Omit null culture and remove passing but unrealistic tests.
* Fixed nullability error.
* Apply suggestions from code review
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Relocated function following code review.
* Reset unchanged files.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* fix(backoffice): Tree menu item shows undefined for variant names without fallback
When a document variant has no name set and there's no fallback language
configured, the tree now falls back to the first variant with any name
instead of displaying "undefined".
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(backoffice): Show (Untitled) when no variant has a name
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
* fix: uses localization string() to localize user-provided labels
* fix: localizes placeholder as well
* Refinements to the Toggle input
The localizations can happen in the `config` setter,
then they don't need to re-get the localization each re-render.
Added a `when` directive to show/hide the label `<span>` tag.
Removed `_currentLabel` as unused.
* Refinements to the Textbox input
The localizations can happen in the `config` setter,
then they don't need to re-get the localization each re-render.
Refactored the `uui-input` attributes/properties.
* Refinements to the Number input
The localizations can happen in the `config` setter,
then they don't need to re-get the localization each re-render.
Refactored the `uui-input` attributes/properties.
* Update src/Umbraco.Web.UI.Client/src/packages/core/components/input-toggle/input-toggle.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/property-editors/text-box/property-editor-ui-text-box.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/property-editors/number/property-editor-ui-number.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Updates based on Copilot feedback
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
Co-authored-by: Lee Kelleher <leekelleher@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Added `icon-sort`
from Lucide's "arrow-down-up" icon.
* Added "Sort" package
with property action and context.
* Adds the "sort" property action and context to the Block Grid property
* [WIP] Observing sort mode toggle on Block Grid editor
* [WIP] Further work on Block Grid editor sort-mode
* Added "umb-sort-mode-toolbar" component
* Fixed typo of private method "renderNoting"
* Renamed "sort" property-action to "sort-mode"
* Corrected bad copypasta!
* Renamed "Sort" package to "Sorter"
to include the Sorter controller and maintain backwards-compatibility.
* Code updates based on @copilot feedback
* Fixed circular references
* Removed reference to "sorter/index.ts"
that I'd missed when relocating the package.
* Moved "sorter" back into "core" package
* Moved the "sort" property-action to a combined "property-actions" location
Fixed up other code, use of constants and manifest clarity.
* rename with claude code (#21036)
* rename with claude code
* include property action in name
* renaming
* Rename sortingMode to isSortMode in property sort context
Refactored property sort mode context and related components to use 'isSortMode'
* add jsdocs
* Update vite.config.ts
* no need to export as element
* add tests
* Ordered the tsconfig namespaces
* Reverted the relocation of the "sorter" controller files
* Import ordering
* Reverted some code style tweaks
* Renamed `sortingMode` to `isSortMode`
* Renamed `sortModeEnabled` to `isSortMode`
* Add tests for property sort mode action
* add js docs
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* fix: sets profiling cookie to httpOnly and strict in order to run non-secure
* fix: adds extra message to explain when you can set a cookie
* fix: simplify cookie explanation comment in WebProfilerRepository
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* fix: checks that the profiler is actually enabled and/or disabled and warns the user if that is not the case
* Update src/Umbraco.Web.UI.Client/src/assets/lang/en.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix: uses 'href' as property instead of attribute
* build: runs on PR to release branches
* Content references: Avoid requesting references for content that is not yet persisted server side (#21035)
* Avoid requesting references for content that is not yet persisted server side.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* refactor to use condition
* revert
* danish translations
* da translation
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* fix: CTRL+Click now opens links in new tab on Linux
The router's anchor click handler incorrectly assumed non-Windows
platforms use Meta (⌘) key for "open in new tab". This broke
CTRL+Click on Linux, which uses CTRL like Windows.
Changed detection from "is Windows" to "is Mac" so Linux correctly
uses CTRL+Click while Mac continues to use Meta+Click.
Also replaced deprecated navigator.platform with navigator.userAgent.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
refactor(backoffice): remove unused uui-dialog element in modal component
Remove dead code that created an unnecessary uui-dialog element inside uui-modal-dialog. The uui-modal-dialog component already manages its own internal dialog element, making the manual creation redundant.
This aligns the dialog implementation with the sidebar implementation pattern, where container elements manage their own internal structure.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude <noreply@anthropic.com>
* Add entity collection item card extension type + default elements
* implement user collection item card
* fix selection events
* map to prop
* add prop/attr for href
* add support for which detail properties to show
* update type import
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/item/entity-collection-item-card/entity-collection-item-card.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* import card in correct file
* Fix event listener binding for selection events
* implement disabled property for collection item cards
* init commit of collection item ref extension
* fix imports
* add element interface
* Implement UmbEntityCollectionItemElement interface in item cards
Added the UmbEntityCollectionItemElement interface to document and user collection item card elements for improved type safety and consistency. Updated type exports to include the new interface.
* Update collection item ref to use uui-ref-node
Replaces the placeholder div with a uui-ref-node component, passing relevant item properties and event handlers. Adds dynamic icon rendering using umb-icon.
* Refactor entity collection item elements to use shared base
Introduces a new abstract base class for entity collection item elements, consolidating shared logic for card and ref variants. Updates card and ref element implementations to extend the new base, and refactors extension manifest interfaces for consistency. This improves maintainability and reduces code duplication.
* use class instead of magic string
* Use ifDefined for href in item card element
* Fix href attribute handling in collection item ref
* Make meta property optional in ManifestEntityCollectionItemBase
* Use ifDefined for href binding in document card
* Fix user card href binding with ifDefined
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* feat: adds `termOrDefault` to be able to safely fall back to a value if the translation does not exist
* feat: accepts 'null' as fallback
* feat: uses 'termOrDefault' to do a safe null-check and uses 'willUpdate' to contain number of re-renders
* feat: uses null-check to determine if key is set
* chore: accidental rename of variable
* uses `when()` to evaluate
* revert commits
* fix: improves the fallback mechanism
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* move legacy icons into a folder
* regenerate icons
* icon compile script for custom
* Reverts "icon-company" to use "building-2" from latest Lucide version
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Implement form control for user picker property editor.
* Added form control support to member picker property editor.
* Added form control support to member group picker property editor and removed super.value.
* Reverted max state to infinity.
* Removed console.log inside the render.
* Removed duplicated import.
* Import missing input components in member picker tests
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Return not found when request for content references when entity does not exist.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Move check for entity existence from controller to the service.
* Update OpenApi.json.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Addressed points raised in code review.
* Update OpenApi.json
* Resolved breaking changes.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
(cherry picked from commit da94e0953b)
* Return not found when request for content references when entity does not exist.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Move check for entity existence from controller to the service.
* Update OpenApi.json.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Addressed points raised in code review.
* Update OpenApi.json
* Resolved breaking changes.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Applies checks for root folders to static file tree service.
* Add integration tests.
* Fix ancestor test.
* Amends from code review.
* Integration test compatibility suppressions.
* Reverted breaking change in test base class.
(cherry picked from commit 84c15ff4d7)
* Applies checks for root folders to static file tree service.
* Add integration tests.
* Fix ancestor test.
* Amends from code review.
* Integration test compatibility suppressions.
* Reverted breaking change in test base class.
* Fix infinite recursion and incorrect error notifications in tree children loading
This commit addresses two critical issues in the tree item children manager:
1. **Infinite recursion vulnerability**: The #resetChildren() method called
loadChildren(), which could recursively call #resetChildren() again if
the underlying issue persisted, creating an infinite loop.
2. **Inappropriate error messages**: The "Menu loading failed" notification
was shown even in legitimate scenarios, such as when deleting the last
child of a node, where an empty tree is the expected outcome.
Changes made:
- Add ResetReason type ('error' | 'empty' | 'fallback') to differentiate
between error states and expected empty states
- Extract #loadChildrenWithOffsetPagination() as a terminal fallback method
that uses only offset pagination and never calls #resetChildren(),
structurally preventing recursion
- Update #resetChildren() to:
- Accept a reason parameter to determine whether to show error notification
- Reset all retry counters (#loadChildrenRetries, #loadPrevItemsRetries,
#loadNextItemsRetries) to ensure clean state
- Call #loadChildrenWithOffsetPagination() instead of loadChildren()
- Only show error notification when reason is 'error'
- Update all call sites of #resetChildren() with appropriate reasons:
- 'error' when retries are exhausted (actual failures)
- 'empty' or 'fallback' when no new target is found (may be expected,
e.g., after deleting items)
The fix makes infinite recursion structurally impossible by creating a
one-way flow: target-based loading can fall back to #resetChildren(),
which calls offset-only loading that never recurses back.
* Fix undefined items array causing tree to break after deletion
This fixes the root cause of issue #20977 where deleting a document type
would cause the tree to "forever load" with a JavaScript error.
The error occurred in #getTargetResultHasValidParents() which called .every()
on data without checking if it was undefined. When the API returned undefined
items (e.g., after deleting the last child), this caused:
TypeError: can't access property "every", e is undefined
The fix adds a guard to check if data is undefined before calling .every(),
returning false in that case to trigger the proper error handling flow.
* Address code review feedback on terminal fallback method
- Change error throwing to silent return for graceful failure handling
- Remove target pagination state updates from offset-only loading method
- Update JSDoc to clarify that method does not throw errors
* Add migration to fix umbracoPropertyData column casing.
* Improve migration with column existence check and logging
- Add ILogger to log when column is renamed
- Check if column exists with incorrect casing before renaming
- Use fluent Rename API instead of raw SQL
- Add XML remarks documentation
?? Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Clarify what old and new column name really is
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: kjac <kja@umbraco.dk>
# Conflicts:
# src/Umbraco.Infrastructure/Migrations/Upgrade/UmbracoPlan.cs
* Add migration to fix umbracoPropertyData column casing.
* Improve migration with column existence check and logging
- Add ILogger to log when column is renamed
- Check if column exists with incorrect casing before renaming
- Use fluent Rename API instead of raw SQL
- Add XML remarks documentation
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Clarify what old and new column name really is
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: kjac <kja@umbraco.dk>
Use AddComponent for OpenAPI security scheme registration
Fixes security requirements being serialized as empty objects in the
OpenAPI document by using the document's AddComponent method instead
of directly manipulating the SecuritySchemes dictionary.
Update table view icon to 'icon-table'
Replaces the 'icon-list' icon with 'icon-table' for all table view manifests across multiple packages to improve consistency and better represent the table view visually.
* Add validation property to PropertyEditorSettingsProperty
Introduces a 'validation' field to the PropertyEditorSettingsProperty interface, allowing configuration of mandatory status and custom mandatory messages for property editor settings.
* Pass validation property to umb-property component
* add menu context and breadcrumbs for document type folders
* add menu context and breadcrumbs for media type folders
* add menu context and breadcrumbs for media type folders
* add menu context and breadcrumbs for partial view folders
* add menu context and breadcrumbs for partial view folders
* add menu context and breadcrumbs for script folders
* Register menu structure workspace contexts and breadcrumbs for document blueprints
* fix menu alias
* remove from blueprints
* fix wrong path when navigating from an inner folder to an outer
* remove debugger
* fix structure link between variant to invariant
* fix up path generation
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* fix: deprecates the upgrade checker
* fix: removes any deprecated UI that no longer has a function for upgrade checks in the backoffice
* chore: generates new api types
* chore: deprecates types
* chore: returns direct task
* docs: explains deprecation
* chore: deprecated model
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Fix preview showing published version when Save and Preview is clicked multiple times
Fixes#20981
When clicking "Save and Preview" multiple times, the preview tab would show the published version instead of the latest saved version. This occurred because:
1. Each "Save and Preview" creates a new preview session with a new token
2. The preview window is reused (via named window target)
3. Without a URL change, the browser doesn't reload and misses the new session token
4. The stale page gets redirected to the published URL
Solution: Add a cache-busting parameter (?rnd=timestamp) to the preview URL, forcing the browser to reload and pick up the new preview session token. This aligns with how SignalR refreshes work.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Improve Save and Preview to avoid full page reloads when preview is already open
When clicking "Save and Preview" multiple times with a preview tab already open, the entire preview tab would reload. This enhancement makes it behave like the "Save" button - only the iframe reloads, not the entire preview wrapper.
Changes:
- Store reference to preview window when opened
- Check if preview window is still open before creating new session
- If open, just focus it and let SignalR handle the iframe refresh
- If closed, create new preview session and open new window
This provides a smoother UX where subsequent saves don't cause the preview frame and controls to reload, only the content iframe refreshes via SignalR.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Close preview window when ending preview session
Changes the "End Preview" behavior to close the preview tab instead of navigating to the published URL. This provides a cleaner UX and ensures subsequent "Save and Preview" actions will always create a fresh preview session.
Benefits:
- Eliminates edge case where preview window remains open but is no longer in preview mode
- Simpler behavior - preview session ends and window closes
- Users can use "Preview website" button if they want to view published page
Also removes unnecessary await on SignalR connection.stop() to prevent blocking if the connection cleanup hangs.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Fix preview cookie expiration and add proper error handling
This commit addresses cookie management issues in the preview system:
1. **Cookie Expiration API Enhancement**
- Added `ExpireCookie` overload with security parameters (httpOnly, secure, sameSiteMode)
- Added `SetCookieValue` overload with optional expires parameter
- Marked old methods as obsolete for removal in Umbraco 19
- Ensures cookies are expired with matching security attributes
2. **PreviewService Cookie Handling**
- Changed to use new `ExpireCookie` method with explicit security attributes
- Maintains `Secure=true` and `SameSite=None` for cross-site scenarios
- Uses new `SetCookieValue` overload with explicit expires parameter
- Properly expires preview cookies when ending preview session
3. **Frontend Error Handling**
- Added try-catch around preview window reference checks
- Handles stale window references gracefully
- Prevents potential errors from accessing closed window properties
These changes ensure preview cookies are properly managed throughout their
lifecycle and support both same-site and cross-site scenarios (e.g., when
the backoffice is on a different domain/port during development).
Fixes#20981🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Track document ID for preview window to prevent reusing window across different documents
When navigating from one document to another in the backoffice, the preview window reference was being reused even though it was showing a different document. This meant clicking "Save and Preview" would just focus the existing window without updating it to show the new document.
Now we track which document the preview window is showing and only reuse the window if:
1. The window is still open
2. The window is showing the same document
This ensures each document gets its own preview session while still avoiding unnecessary full page reloads when repeatedly previewing the same document.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Remove updates to ICookieManager and use Cookies.Delete to remove cookie.
* Fix file not found on click to save and preview.
* Removed further currently unnecessary updates to the cookie manager interface and implementation.
* Fixed failing unit test.
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Created condition for workspace content type unique.
* Changed import.
* Revert import.
* Updated name in the alias example and also import.
* Update src/Umbraco.Web.UI.Client/examples/entity-content-type-condition/index.ts
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Update src/Umbraco.Web.UI.Client/examples/entity-content-type-condition/workspace-view-unique.element.ts
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Moved the manifest definition to the manifest file.
* Changed default export.
* Updated example element to render the real GUID.
* Fixed import.
* Replaced CONTENT_WORKSPACE for PROPERTY_STRUCTURE_WORKSPACE context.
* Moved content type unique condition to the content type folder.
* Fixed import.
* final adjustments
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Adding the sorter controller, and fixing some ui elements so you are able to drag the hostname elements around to sort them
* Fixed sorting
* Changed the html structure and tweaked around with the css to make it look better.
Added a description for the Culture section.
Alligned the rendered text to allign better with the name "Culture and Hostnames"
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/entity-actions/culture-and-hostnames/modal/culture-and-hostnames-modal.element.ts
Forgot to remove this after I was done testing
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/entity-actions/culture-and-hostnames/modal/culture-and-hostnames-modal.element.ts
Changing grid-gap to just gap
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Removed the disabled and readonly props I added since they are not needed.
Removed the conditional rendering that was attached to the readonly and disabled properties
* Removed the item id from the element and changed css and sorter logic to target the hostname-item class instead
* Updated test
* Bumped helpers
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
* Adds choose directive to @umbraco-cms/backoffice/external/lit
This can then allow choose to be imported like so
import { html, customElement, LitElement, property, css, choose } from '@umbraco-cms/backoffice/external/lit';
* Exports all of Lits directives for @umbraco-cms/backoffice/external/lit
Also puts them in alphabetical order to help add any new ones Lit may add in the future
* Regenerate delivery api claud memory file for updated file lines and inclusion of Secure Cookie-Based Token Storage
* Add delivery api memory file
* claude memory file for in memory modelsbuilder project
* Claud memory file for Imagesharp project
* Claude memory file for legacy image sharp project
* Claude memory files for Persistence projects
* Remaining claude memory files
* Log Viewer: Refactor log types chart to use Lit repeat directive
- Import and use repeat directive for better performance
- Add _logLevelKeys state property to track log level keys
- Update setLogLevelCount() to populate _logLevelKeys
- Replace .map() with repeat() in render method for legend and donut slices
- Update willUpdate to observe both filter and response changes
- Resolves TODO comment about using repeat directive
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Donut Chart: Add inline numbers and fix tooltip positioning
- Add showInlineNumbers property to optionally display numbers inside slices
- Implement #getTextPosition() method to calculate text position at slice center
- Render SVG text elements when showInlineNumbers is enabled
- Fix tooltip positioning to appear near cursor (changed from x-10, y-70 to x+10, y+10)
- Recalculate container bounds on each mouse move to handle window resize
- Add pointer-events: none to tooltip to prevent mouse interference
- Add CSS styling for slice numbers (user-select: none)
- Enable inline numbers by default in log viewer log types chart
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Donut Chart: Add clickable slices and visible description
- Add href property to donut-slice element for clickable slices
- Wrap SVG paths in <a> tags when href is provided
- Update Circle interface to include href property
- Add showDescription property to optionally display description text
- Render description as visible text below the chart
- Add CSS styling for description text
- Update log-types-chart to build search URLs with log level and date range
- Observe dateRange from context to build accurate search URLs
- Enable clickable slices and visible description in log-types-chart
Now clicking on a donut slice navigates to the search view filtered by that log level and the current date range.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* fix: uses whole link
* Log Viewer: Fix log types chart layout for larger screens
Add media query to switch from column to row layout on screens wider than 768px. This ensures the legend and donut chart are displayed side by side on desktop resolutions instead of stacked vertically.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* chore: improves mock function
* chore: formatting
* fix: ensures the donut chart works responsively
* feat: adds support for SVGAElement in the router
* adds key for description
* chore: adds test data
* feat: displays numbers in the legend instead of the chart
* chore: restores functionality with lower-cased keys
* fix: adds translation to 'log messages'
* chore: removes unused method
* feat: ensures that the log levels follow the generated LogLevelModel enum from the server, which requires to map the keys as JSON camelCase's the keys
* fix: uses correct property
* fix: reverts back to the original behavior to calculate a relative URL (rather than the automatic .toString() that gets a qualified URL)
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix: uses fullUrl for router
* fix: properly translates new aria-label
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Added tests for notification emails for content
* Bumped version
* Updated tests for notification permission in content
* Added appsettings.json for smtp tests
* Added smtp test project
* Updated nightly E2E test pipeline yaml file to run smtp project in the pipeline
* Fixed command to run smtp4dev in Docker
* Fixed pipeline
* Only run smtp tests on Linux
* Debugged
* Debugging
* Added step to stop smtp4dev container
* Debugging
* Updated port
* Reverted tests
* Added more tests for notification emails
* Formatted code
* Fix css for login screen dark mode
* Removes the outer-layout wrapper, moving the flexbox to the host
Sets the fallback for `--umb-auth-backdrop` to `--uui-color-surface`
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* fix: adds localization to the log viewer
* fix: missing log viewer keys for English
* fix: translations for Danish
* fix: removes unused keys and replaces polling keys
* fix: lowercases values to match what was there before
* Fix validation for url and anchor of multi url picker
* fix codesence warning
* remove redundant validation
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
* Allowed selection of all available fields in Examine search results, and fix layout issue when not all records have all fields.
* Updates from code review.
Add menu item registration examples
Introduces example implementations for registering action, link, and entity menu items in the backoffice. Includes manifests and API to demonstrate how to extend the menu system.
* Updated the content-name element to use the DocumentItemDataResolver.
* Import sorting
* Defaults the entity-type to "document"
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Adds localization manifests for region-specific cultures
This is to support backwards-compatibility and v13 upgradability.
* Removed `uiCulture` from Vietnamese localizations
since it duplicated the English fallback texts.
* 'en' localization file formatting
* Update src/Umbraco.Web.UI.Client/src/assets/lang/en.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update Swashbuckle to v10
* Regenerate backoffice api client
* Add missing space for consistency
* Simplify nullability check
* Small improvement
Didn't notice that these classes were internal, so tried keeping compatibility, but it wasn't needed.
* Fix failing integration test
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Remove unnecessary comma
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix: adds correct fallback for dates to avoid console error
* fix: resolves a TODO by using UmbStringState over rxjs Subject
* Refactor log viewer search to use UmbStringState and improve architecture
- Replace RxJS Subject with UmbStringState to follow Umbraco patterns
- Move debounced search observation to messages list component
- Only triggers when component is mounted (logs are visible)
- Prevents unnecessary API calls on other views
- Simplify search input to just update context state
- Add semantic form structure with role="search" for accessibility
- Add visually-hidden submit button for keyboard navigation
- Allow re-running same query via form submission (bypasses debounce)
- Follow same architecture pattern as date range selector
This resolves the TODO to not use RxJS directly and significantly improves
separation of concerns where the data consumer (messages list) owns the
fetching logic.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Add visible refresh button to log viewer search input
- Add refresh button with icon-refresh next to save and clear buttons
- Allows users to re-run search with same query (bypasses debounce)
- Remove form structure that couldn't work due to Shadow DOM boundaries
- Simplify parent component by removing form submission logic
- Keep role="search" for accessibility
The refresh button provides a more discoverable UI than the hidden submit
button approach and avoids Shadow DOM event bubbling issues.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Fix debouncing by adding local state in search input
- Add local UmbStringState to debounce user input (250ms)
- Only update context filterExpression after debounce
- Remove debouncing from messages list (now handled at input level)
- Saved searches and refresh button still bypass debounce for immediate feedback
This restores the expected debouncing behavior while maintaining the clean
architecture where the messages list triggers searches based on context changes.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* chore: cleans up in docs
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Updated block list tests as the “Add Block” button is hidden after reaching the maximum limit.
* Updated validation option due to UI changes
* Updated tests for current user profile as waitForNetworkToBeIdle() is removed
* Fixed flaky tests
* Bumped version
* Updated tests for current user profile
* Bumped version
* Preserve existing Examine FieldDefinitionCollection if it already exists (#20267)
* Fix missing bracket
* Minor tidy/addition of comments; addition of unit tests.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* add empty trash icon and use it for empty trash-bin and delete from trash-bin
* package lock
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add MemberType/MemberTypeContainer to supported EntityContainer object types
* Implement MemberTypeContainerRepository
* Update and add member type container API endpoints
* Complete server and client-side implementation for member type container support.
* Fix FE linting errors.
* Export folder constants.
* Applied suggestions from code review.
* Updated management API authorization tests for member types.
* Resolved breaking change on copy member type controller.
* Allow content types to be moved to own folder without error.
* Use flag providers for member type siblings endpoint.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Ensure redirects with domains are stored with the domain node id prefix.
* Handle removal of self-referencing redirect when domains are used.
* Use entity path to save further queries for retrieving ancestor IDs.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Applied refactoring suggested in code review.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Use empty folder under temp as localized text source folder in non umbraco core integration tests.
* Added clarifying comment to the GetLocalizedTextService override for tests
Handles rich text blocks created with TinyMCE in convert local links migration.
Refreshes internal datatype cache following migration requiring cache rebuild.
Handles rich text blocks created with TinyMCE in convert local links migration.
Refreshes internal datatype cache following migration requiring cache rebuild.
* Removed skips for tests whose related issues have been fixed.
* Remove skip tags and update tests for content with list view
* Removed skip tags
* Added comment and change to fixme for tests that need to implement later
* Removed skip tag
* Bumped version
* configure max chars for textbox
* min 1
* Adds server-side check for text box min and max character validation.
* Applied suggestion from code review.
* Bumped version of test helper
* Fixed test that was creating a text string data type with too large a maximum characters setting.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Nhu Dinh <hnd@umbraco.dk>
* Replace dependency track bom script with devops task
* Introduce new url variable in order to fix new task uri
The initial variable contained the api path (/api) in the URL.
* Redact back-office PKCE codes from the server
* Update src/Umbraco.Cms.Api.Common/DependencyInjection/HideBackOfficeTokensHandler.cs
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Removes npm commands from the MSBuild of the CSPROJ of the umbraco-extension dotnet new template
Was agreed by the community package team to remove this, as this DX can cause more issues than actually help users in our opinion
* Removed the unused value - good catch by Copilot
* Adding fix for self-referncing redirects for 17
* Using umbraco context on failing tests
* Tests to see if self referencing redirects gets deleted
* Refactoring and adding correct tests.
* Expanding tests for RedirectTrackerTests.cs
* Optimize by only retrieving th list of existing URLs for a content item if we have a valid route to create a redirect for.
* Extract method refactoring, added explanatory comment, fixed warnings and formatting.
* Resolved warnings in RedirectService.
* Minor naming and formatting refactor in tests.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Move access/refresh tokens to secure cookies (#20779)
* feat: adds the `credentials: include` header to all manual requests
* feat: adds `credentials: include` as a configurable option to xhr requests (and sets it by default to true)
* feat: configures the auto-generated fetch client from hey-api to include credentials by default
* Add OpenIddict handler to hide tokens from the back-office client
* Make back-office token redaction optional (default false)
* Clear back-office token cookies on logout
* Add configuration for backoffice cookie settings
* Make cookies forcefully secure + move cookie handler enabling to the BackOfficeTokenCookieSettings
* Use the "__Host-" prefix for cookie names
* docs: adds documentation on cookie settings
* build: sets up launch profile for vscode with new cookie recommended settings
* docs: adds extra note around SameSite settings
* docs: adds extra note around SameSite settings
* Respect sites that do not use HTTPS
* Explicitly invalidate potentially valid, old refresh tokens that should no longer be used
* Removed obsolete const
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Remove configuration option
* Invalidate all existing access tokens on upgrade
* docs: updates recommended settings for development
* build: removes non-existing variable
* Skip flaky test
* Bumped version of our test helpers to fix failing tests
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
* Added form control support to color picker.
* Avoid submit when readonly is true.
* Added mandatory support.
* Added form control support to date picker.
* Removed an unused import.
* Added form control and mandatory support to document picker.
* Added form control support to Eye dropper.
* Added. mandatory support for multi url picker also bind inner input in the eye dropper.
* Removed unused import.
* fix update of value
* fixing not needed override of get and set methods
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Added mandatory support for block grid property editor.
* Added form control and mandatory support to code editor.
* Added form control and mandatory support to markdown editor.
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Implemented input-with-alias in the content-type-design-editor.
* Added auto-generate-alias property to the input and revert deletion of checkAliasAutoGenerate method.
* Added form-validation-message.
* Added validation to the input-with-alias element to avoid special characters.
* Chenged right and left position of the infobox.
* Added focus support to open the modal.
* Moved tabindex out the constructor and added support for enter and space keys.
* Removed isLoding condition from the rich media input and let the thumbnail handle the loader.
* Removed unused import.
* change loader and adjust lit property configuration
* update reflect configuration
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* chore(mock): adds missing try/catch around document lookup
* fix: lets the 'save and preview' button extend the 'save' button to follow the same logic in terms of when it enables/disabled - it did not have much logic before
* fix: runs validation from the server when save and previewing to ensure the UI shows what is missing
Update icon usage in collection menu and example data
Replaces <uui-icon> with <umb-icon> in the default collection menu item element to support colors. Also updates example picker data source items to showcase color support.
* Exclude the relate parent on delete relation type from checks for related documents and media on delete, when disable delete with references is enabled.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Applied suggestions from code review.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* sql column type map include dateonly and timeonly
* Split Mapper and add check null value
* Minor code tidy resolving a few warnings.
* add spaces
* clean code
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fix for partial view caches not being cleared when content is published/unpublished
* Update src/Umbraco.Core/Cache/Refreshers/Implement/ContentCacheRefresher.cs
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Change logic for clearing partial view cache
* Changed logic to only clear partial cache when content is published/unpublished or trashed
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Adds new dictionary/localization item for the clipboard dialog clear all prompt
* Removes the wrapping uui-box and moved inside the component itself
* Adds Clear Clipboard button and logic
* Adds uui-box from outer components consuimg this into this component
* Adds a header to uui-box
* Adds a conditional uui-button when we have items in clipboard
* Adds confirm dialog/prompt to ask if user wants to clear all items
* Adds in general_clipboard item to use in the UUI-box header
* Removes extra space & moves the requestItems outside the for loop
* Be a better citizen
Make sure the promise for the modal is caught and we return out early if user explictiy cancels modal or presses ESC
* Cleanup my noisy comments for a re-review
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* WiP blocklist migration
* Mostly working migration
* [WIP] deconstructed the migration to prefetch and process all data that requires the old definitions
* Working singleblock migration
* Abstracted some logic and applied it to settings elements too.
* Align class and file name.
* Minor code warning resolution.
* More and better comments + made classes internal where it made sense
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add MemberType/MemberTypeContainer to supported EntityContainer object types
* Implement MemberTypeContainerRepository
* Prepare base controller for MemberTypeTreeControllerBase.
* Revert "Prepare base controller for MemberTypeTreeControllerBase."
This reverts commit ad213a23ad.
* Added foldersOnly flag in readiness for support in 17.1.
* Added foldersOnly flag in readiness for support in 17.1 (2).
---------
Co-authored-by: Ronald Barendse <ronald@barend.se>
* Added integration tests for PropertyTypeUsageService and adjusted assert in management API permissions test.
* Commented or fixed management API integration tests verifying permissions where we were asserting on an error response.
Added 'label attribute to the uui-button in the umb-news.card.element + Removing the redundant text for uui-button since label attribute is now present
* Fix block list inline mode
https://github.com/umbraco/Umbraco-CMS/issues/20618
* Fixed potential runtime errors
* Code cleanup
* Fixed Code Health Review
* Revert some changes
Commented out unused state properties and related code.
* Remove commented-out state property in block workspace view
* fix localization
* no need for question mark after ids, they should be presented as required
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Add errorDetail property to umb-entity-item-ref
Add optional errorDetail property to display additional context
(such as file paths or IDs) in error states. This enhances the
error display to show both the error message and relevant details.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Make _removeItem protected in UmbPickerInputContext
Change #removeItem from private to protected to allow subclasses
to reuse the removal logic while customizing the confirmation dialog.
This enables better extensibility for specialized picker contexts.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Fix static file picker to show error state for missing files
Update umb-input-static-file to observe statuses and render based
on item state (loading, error, success). When a static file is
missing (API returns empty array), displays error state with alert
icon and file path detail using umb-entity-item-ref.
Also adds standalone property support for proper single-item styling.
Fixes#19329🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Show file path in static file remove confirmation dialog
Override requestRemoveItem in UmbStaticFilePickerInputContext to
display the file path instead of "Not found" in the confirmation
dialog when removing missing static files.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Show GUID in document picker error state
Display the document GUID as errorDetail when a document is
not found (deleted/gone). This provides useful context for
editors to identify which document was referenced.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Show GUID in document picker remove confirmation dialog
Display the document GUID instead of "Not found" in the remove
confirmation dialog when the document no longer exists. This
provides useful context for editors.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* fix: apply the temp model which the context uses
* Refactor: Move requestRemoveItem logic to base UmbPickerInputContext
Eliminated duplicate code across three picker contexts by:
- Adding protected getItemDisplayName() method to base class
- Moving requestRemoveItem implementation to base class
- Removing duplicate implementations from document, member, and static file pickers
- Static file picker overrides getItemDisplayName() to show file path
Net reduction: 19 lines of code (69 removed, 50 added)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Document Type Picker: Show error state for missing items (fixes#20367)
Apply the same error state handling to the document type picker that was
implemented for static files, documents, and members. When a referenced
document type is missing or deleted:
- Show error state with the GUID as errorDetail
- Allow removal with proper confirmation dialog
- Use umb-entity-item-ref for error display
- Use uui-ref-node-document-type for successful items
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Additional pickers: Show error states for missing items in user, language, media-type, member-type, member-group, and user-group pickers
Apply the same error state handling pattern to six additional picker types:
- user-input: Users
- input-language: Languages
- input-media-type: Media types
- input-member-type: Member types
- input-member-group: Member groups
- user-group-input: User groups
All pickers now:
- Observe statuses from UmbRepositoryItemsManager
- Show error state with GUID when referenced item is missing/deleted
- Use umb-entity-item-ref for error display
- Use specialized components (uui-ref-node, umb-user-group-ref, etc.) for successful items
- Allow removal with proper confirmation dialog showing GUID
Maintains code reusability by using the base class requestRemoveItem method
with getItemDisplayName() for consistent error handling across all pickers.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Lint: Remove unused 'when' imports from input-media-type and user-group-input
* Refactor: Add #renderItem helper method to all pickers for consistency
- Add #renderItem to user-input (extracted from inline repeat callback)
- Change _renderItem to #renderItem in user-group-input for consistency
- Change _renderItem to #renderItem in input-static-file for consistency
All 10 pickers now use consistent #renderItem helper method pattern,
improving code readability and maintainability as suggested by @nielslyngsoe
* `import` sorting
* Corrected (old) JSDoc typos
* Markup tidy-up
* exported `UmbPropertyEditorUIStaticFilePickerElement` as `element`
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
Moves the _data.updateCurrent() call inside the updateLayoutBlock conditional
in setMasterTemplate(). This prevents spurious change detection when loading
templates from the server, while maintaining proper change tracking when users
actually modify the master template via the UI.
This completes the fix started in PR #20529 which added the updateLayoutBlock
parameter but inadvertently left the data model update outside the conditional.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude <noreply@anthropic.com>
* Added custom validation for missing password and user/email
* Changed some of the logic behind custom validation, so it now uses aria-errormessage
* fix: imports from src folder instead
* build(deps-dev): bump vite to 7.2.0
* formatting
* fix: moves the form into the login.page.element.ts component to better control submission
* fix: creates elements globally
* fix: adds id back to form
* fix: no need to store references to all form elements
* fix: errormessage should show with password field in a span as well
* fix: checks validity of form
* fix: constructs form in auth.element.ts anyway and append localization to validation and add oninput and onblur
* chore: fixes import paths
* fix: fixes special case where ?status was not reset
* fix: changes wording in english
* fix: removes duplicate en-us keys
* feat: adds ariaLive and role attributes
* fix: always clears the text
* fix: username required validation should switch between username and email
* package-lock.json updated on (re)install
* Renamed SVG eye icon filenames
to be conventional and kebab-cased.
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
Fix config value access in UmbSliderPropertyValuePreset
Updated the `UmbSliderPropertyValuePreset` class to ensure the `.value` property is accessed for configuration items. This change improves the accuracy of retrieving `enableRange`, `min`, `max`, and `step` values, addressing potential bugs in value processing.
Co-authored-by: Luuk Peters <Luuk.Peters@proudnerds.com>
* Add setter to allow handling of requests to subscribe to newsletter on install.
* Correct serialization of newsletter subscription request.
* Fix serialization and use the Umbraco.EmailMarketing service for newsletter signup.
* Remove logging of user when setting telemetry level.
* Applied suggestions from code review.
* Fix memory leak with IOptionsMonitor.OnChange and non-singleton registered components.
* Dispose disposable data editors in ValueEditorCache.
* Removed unnecessary refactoring and clarified code comments.
* fix: Tiptap Media Picker: Skip media picker modal when editing existing images
Fixes the media picker workflow to match v13 behavior where clicking
an existing image directly opens the alt text/caption editor instead
of forcing users to re-select the same image from the media library.
Also fixes caption text extraction to properly read from the figcaption
node using Tiptap's NodeSelection API instead of unreliable attribute-based
approach.
Changes:
- Skip media picker when currentMediaUdi exists (lines 77-92)
- Extract caption from NodeSelection.node using descendants() (lines 55-73)
- Add NodeSelection export to tiptap externals for proper typing
* Refactor: Extract nested logic from media picker execute method
Reduces cyclomatic complexity from 15 to 1 by extracting conditional
logic into focused private helper methods. Addresses CodeScene warnings
for complex method and nested conditionals (bumpy road smell).
Created helper methods:
- #extractMediaUdi, #extractCaption, #findFigcaptionText
- #getMediaGuid, #updateImageWithMetadata
No functional changes - improves maintainability and testability.
* Added skip tag for the failing tests due to the issues and added waits for the flaky tests
* Commentted code as the reference items displays randomly
* Bumped version
* Added more waits to avoid the flaky tests
* Updated tests for setting culture and hostnames since the first content already has the default domain
* Fixed flaky tests
* Updated tests since the reload step is flaky
* Added more waits for the flaky tests in Windows
* Need to publish first document before set domain for second document
* Make permission tests run in the pipeline
* Added step to ensure the rollback action is completed
* Reverted npm command
* Added skip tag for the permission tests
* Fixed test for the culture and hostname permission
* Removed waits as it is includes in test helper
* Fixed test for adding a media in RTE Tiptap property editor
* Updated test helper function to avoid the flaky tests releated to block
* Added more waits to ensure image uploaded
* Bumped version
* Bumped version
* Reverted
* Reverted code
* Bumped version of test helper
* Bumped version
* Reverted code
* Added more waits to avoid flaky tests
* Added more waits
* Updated nightly pipeline: remove v17/dev, run different app setting tests by default and not run Relation Type in Linux as they are too flaky
* Added more waits
* Added npm command for testWindows
* Added more waits after creating a folder
* Add MoveFile it IFileSystem and implement on file systems.
* Rename media file on move to recycle bin.
* Rename file on restore from recycle bin.
* Add configuration to enabled recycle bin media protection.
* Expose backoffice authentication as cookie for non-backoffice usage.
Protected requests for media in recycle bin.
* Display protected image when viewing image cropper in the backoffice media recycle bin.
* Code tidy and comments.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Introduced helper class to DRY up repeated code between image cropper and file upload notification handlers.
* Reverted client-side and management API updates.
* Moved update of path to media file in recycle bin with deleted suffix to the server.
* Separate integration tests for add and remove.
* Use interpolated strings.
* Renamed variable.
* Move EnableMediaRecycleBinProtection to ContentSettings.
* Tidied up comments.
* Added TODO for 18.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Make the RTE treat an "empty" value as a non-value
* Additional tests
* Add tests for invariant and variant content.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Localized RTE property-editor UI label, removing "[Tiptap]"
* Updated acceptance test
* Localized the button label in the data-type and property-editor picker modals
* Based on @copilot suggestion, localized the property-editor UI label in the other places
* Added mandatory property to number range property editor and bind it to the inner input.
* Added mandatory message support.
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Added request cache to content and media lookups in mult URL picker.
* Allow property editors to cache referenced entities from block data.
* Update src/Umbraco.Infrastructure/PropertyEditors/MultiUrlPickerValueEditor.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add obsoletions.
* Minor spellcheck
* Ensure request cache is available before relying on it.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: kjac <kja@umbraco.dk>
* Generate BOM files on build
* Upload BOM to Dependency Track
* Move Backoffice BOM generation to right after install
The build and/or pack steps are deleting files that are needed for the BOM to be generated properly.
* Split the BOM uploads into different jobs
* Fix wrong usage of parameters
* Move order of dependency track stage
* Fix wrong umbracoVersion value
* Small fixes
* Log curl response headers
* Correct version sent to dependency track
* Adjusted curl flags
* Fix bom file path
* Fix dotnet bom file name
* Add Login UI to dependency track
* Generate BOM for E2E Tests
* Move dependency track stage
* Move acceptance test .env generation to e2e install template
Needed as the post install script is expecting this to exist.
* Use major version if public release
* Missing ')'
* Reverted npm install command changes in static assets project
* enforce update of children when collection
* only load one above and below collection children
* take 50 above a target for default experience
* revert reset target
* remove old impl
* Generate BOM files on build
* Upload BOM to Dependency Track
* Move Backoffice BOM generation to right after install
The build and/or pack steps are deleting files that are needed for the BOM to be generated properly.
* Split the BOM uploads into different jobs
* Fix wrong usage of parameters
* Move order of dependency track stage
* Fix wrong umbracoVersion value
* Small fixes
* Log curl response headers
* Correct version sent to dependency track
* Adjusted curl flags
* Fix bom file path
* Fix dotnet bom file name
* Add Login UI to dependency track
* Generate BOM for E2E Tests
* Move dependency track stage
* Move acceptance test .env generation to e2e install template
Needed as the post install script is expecting this to exist.
* Use major version if public release
* Missing ')'
* Reverted npm install command changes in static assets project
* enforce update of children when collection
* only load one above and below collection children
* take 50 above a target for default experience
* revert reset target
* remove old impl
* Added request cache to content and media lookups in mult URL picker.
* Allow property editors to cache referenced entities from block data.
* Update src/Umbraco.Infrastructure/PropertyEditors/MultiUrlPickerValueEditor.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add obsoletions.
* Minor spellcheck
* Ensure request cache is available before relying on it.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: kjac <kja@umbraco.dk>
Add 'not trashed' condition to document bulk actions
Introduces the UMB_ENTITY_IS_NOT_TRASHED_CONDITION_ALIAS to various document-related bulk action manifests, ensuring actions like duplicate, move, publish, unpublish, and trash are only available for entities that are not already in the recycle bin.
* Better title for icon colors
* Add name for legacy colors
* Translations of colors
* Fixed import, adding missing colour, added Italian translations.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Implimented an inline toggle button to show/hide your password, also changed the css to accommodate these changes
* Cleaned the css
Added the svg's to their own const for easy reuse
Added localization for the arialabel on the button
Seperated the createFormLayoutItem so there is a seperate for the password input
Moved all the conditional logic in the onclick event to fit inside one if/else statement
* Removed old logic that added a 100ms timeout that would sometimes be enough for localization to load, and replaced it with a function.
The function will try and resolve the promise by checking if the localize.terms methods returns a changed value, if not then it retries every 50ms or untill it hits a max retry of 40/2 seconds.
* Re adding the hide for -ms-reveal to support Microsoft Edge browsers
* Removed a console.log
* Alligned the button behavior so it fits better with what we have in the uui libary.
Now the button is always visible instead of appearing on hover or when in focus
* Update src/Umbraco.Web.UI.Login/src/auth.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Login/src/auth.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @iOvergaard
* Apply suggestion from @iOvergaard
* Adding the requested changes via my own fork (#20664)
Changed the logic for waitForLocallization Added the svg's as files that are imported instead of having the raw svg in the code
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Added mandatory support to property-editor-ui-number.
* Added form control to property-editor-ui-tags
* Added validator to the slider when value is missing and support for mandatory and mandatory message.
* Removed unnecessary ternary.
* Removed white space lit error.
* Fix tags input to handle undefined items array
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* change property value to an object
* add const for picker data source type
* Add value editor and converter server-side
* register schema for property editor + move settings ui
---------
Co-authored-by: kjac <kja@umbraco.dk>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Trees: Restore backward compatibility for file system based tree controllers (closes#20602) (#20608)
* Restore backward compatibility for file system based tree controllers.
* Aligned obsoletion messages.
* Reverts nullability update on ConvertNotificationToRequestPayload.
* Remove unused help controller
* Correct documentation links
* Link to the new release site for compares
* Remove unused translation key with reference to Our
* Update NoNodes / NotFound to point to the forum instead of Our
* Change dashboards form Our to Forum and de-emphasize Discord as a support channel
* Removes Help controller reference
* Forgot to rename the css Id
* Update src/Umbraco.Web.UI.Client/src/assets/lang/ar.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix typo in Community Forum help menu item name
* Refer to releases instead of a download page
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update the default dashboard with better content and clearer headings
* Obsolete the HelpController instead
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add ID when updating background job
* Reduce default period to 5 seconds
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Preview Device: refactored config
Fixed "flip" icon style.
Removed "shadow" as unnecessary.
Renamed "className" to "wrapperClass" to be descriptive.
* Preview element CSS refinement
* Preview element: load in private extensions
* Added "Preview Environments" preview-app
Made `unique`, `culture` and `segment` observable in the context.
* Aligned preview-app design
with `hidden` attribute and design consistency.
* Created "Preview" package
* Relocated "Preview Apps" and Context to the new package
* Deprecated `UmbDocumentPreviewRepository` (for v19)
as the methods have moved to `UmbPreviewRepository`.
* Removed Preview Sessions event listeners
* Changed localization from "End" to "Exit"
* chore: consumes context only when needed
* feat: uses the UmbPreviewRepository instead
* feat: adds localization to errors and ensures the function does not randomly throw
* feat: prevents creating a new repository for every click
* feat: prevents potential memory leak by adding a signal to the events added to each iframe update
* feat: adds a custom interface to prevent typescript errors
* feat: ensures new string states are checked properly
* docs: adds comment to avoid confusion
* feat: sets up scaling once per iframe load rather than on each update
* fix: ensures that you can go back to the default segment again
* feat: closes popovers when clicking on the iframe (losing blur) and if selecting an item (expect for devices)
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Removes preview sessions concept
Fixes#19443 and #19471.
The implementation of exiting sessions was a design flawed.
The v13 feature worked due to an implementation bug.
Exiting preview mode should be a deliberate action by the user.
* Added check to only find .css files in FileSystemTreeServiceBase.cs
* Marking GetFiles as virtual and overriding it in StyleSheetTreeService.cs to only find .css files
* Redone tests to fit new format
* Fix tests to use file extensions
* Adding file extensions to all other relevant tests
* Adding file filter to remaining trees
* Adding tests to ensure invalid filetypes wont show
* Encapulation and resolved minor warnings in tests.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Use tryExecute for delete API call
Replaces direct await of #delete with tryExecute to improve error handling in the delete method of UmbManagementApiDetailDataRequestManager.
* utility
* ability to replace
* deprecate removeStatus
* no need to call this any longer
* Sort statuses and ensure not appending statuses, only updating them
* hotfix: ensures that local urls stay relative so we land up on the correct backoffice host that the user initiated the preview session from originally
* feat: since ensureAbsoluteUrl is never supplied anymore, we can remove the parameter altogether
* Remove unused dependency
* Expose IsExternal for URLs
* feat: adds localize controller
* chore: generates api models
* feat: marks the internal preview default url as relative, so that the `<base>` tag is taken into consideration - that way the URL will open on whatever host is active
* Remove IsExternal from the API again
* regenerate types
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Add 'Trashed' state to document workspace view
Introduces a new 'Trashed' label and tag for documents in the workspace view. Updates localization to include the 'Trashed' term for improved clarity when displaying trashed documents.
* Show trashed state in media workspace info view
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* feat: replaces manual WebSocket with the actual SignalR library on the preview context
* feat: informs the developer what went wrong in preview mode
* feat: awaits the stop connection before proceeding
* feat: ensures no existing connection exists
* clean up
* localizations
* group user permission by entity type
* adjustments
* fix lint errors
* Support granular permissions without entity type
Updated granular permission handling to allow permissions that are not tied to a specific entity type. Adjusted rendering logic and manifest interface to support undefined or empty forEntityTypes, and added UI for displaying ungrouped granular permissions.
* revert for now
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Reduce log level of image cropper converter to avoid flooding logs with expected exceptions.
* Don't run publish branch long running operation on a background thread such that UmbracoContext is available.
* Revert to background thread and use EnsureUmbracoContext to ensure we can get an IUmbracoContext in the URL providers.
* Updated tests.
* Applied suggestion from code review.
* Clarified comment.
Fixes SQL error to ensure database relation between user group media start folder and deleted media item is removed.
# Conflicts:
# src/Umbraco.Infrastructure/Persistence/Repositories/Implement/MediaRepository.cs
* Tiptap toolbar config: enable removal of unregistered extensions
* Tiptap statusbar config: enable removal of unregistered extensions
* Tiptap toolbar config: Typescript tidy-up
* Tiptap toolbar sorting amend
Removed the need for the `tiptap-toolbar-alias` attribute,
we can reuse the `data-mark`.
* Tiptap extension config UI amend
If the extension doesn't have a `description`,
then add the `alias` to the title/tooltip, to give a DX hint.
* Tiptap toolbar: adds `title` to placeholder skeleton
* Added missing `forExtensions` for Style Select and Horizontal Rule toolbar extensions
* Update src/Umbraco.Web.UI.Client/src/packages/tiptap/property-editors/toolbar-configuration/property-editor-ui-tiptap-toolbar-configuration.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/tiptap/property-editors/statusbar-configuration/property-editor-ui-tiptap-statusbar-configuration.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Be consistent in use of GetOrCreateAsync overload in exists and retrieval.
Ensure nullability of ContentCacheNode is consistent in exists and retrieval.
* Applied suggestion from code review.
* Move seeding to Umbraco application starting rather than started, ensuring an initial request is served.
* Tighten up hybrid cache exists check with locking around check and remove, and use of cancellation token.
(cherry picked from commit 81a8a0c191)
* Store local time zone as UTC and do not throw validation error when stored time zone is different
* Additional fixes when switching between date time editors with and without time zone
* Additional fixes
* Ensure that an update is triggered when the expected value does not match the stored value
This will happen when switching between editors (with and without time zone) or switching between a specific time zone to the editor's local time zone.
* Fix inconsistencies with null and undefined
* Fix inconsistencies between date/time provided to the client and returned in the value converter (when switching between editors)
* Fix unit tests and small bug
* Adjust integration test
* Small improvement
* Update test data
* Adjust logic so that time zone offsets are updated every time the date value changes
* Do not pre-select time zone when switching between unspecified and time zone editors
* register structure context for recycle bin
* Update manifests.ts
* export consts
* move href construction to context + override for document and media
* Preview Exit: Gets the page's published URL on exit for redirect
* Preview Open Website: Uses the page's published URL
* Tweaked the published URL logic
* Code amends based on @copilot's suggestions
(cherry picked from commit d5a2f0572e)
* make document and media readonly when trashed + reload the entity
* introduce restore event + remove readonly
* handle media audit log todos
* disable content type picker when trashed
* disable template picker when trashed
* Introduce configurable batch size for indexing
* Stop using Examine indexing events for reporting index rebuild operation completeness (it is volatile)
* Block List: adds `$index` support for UFM labels
* Block Grid: adds `$index` support for UFM labels
* Block RTE: adds `$index` support for UFM labels
Which is always zero `0`.
But has been wired up if we do implement the index order in future.
* Updated tests
* E2E: Updated acceptance tests to match changes (#20493)
* Updated tests to match changes
* More updates
* Bumped version
* Reverted change
* feat: adds first draft of a context consume decorator
* feat: uses an options pattern
* feat: changes approach to use `addInitializer` and `queueMicroTask` instead
* feat: adds extra warning if context is consumed on disconnected controllers
* feat: example implementation of consume decorator
* feat: adds support for 'subscribe'
* feat: initial work on provide decorator
* docs: adds license to consume decorator
* feat: adds support for umbraco controllers with `hostConnected`
* feat: uses asPromise to handle one-time subscription instead
* test: adds unit tests for consume decorator
* feat: adds support for controllers through hostConnected injection
* feat: adds support for controllers through hostConnected injection
* test: adds unit tests for provide decorator
* docs: adds more documentation around usage and adds a few warnings in console when it detects wrong usage
* feat: removes unused controllerMap
* docs: adds wording on standard vs legacy decorators
* docs: clarifies usage around internal state
* feat: adds proper return types for decorators
* docs: adds more types
* feat: makes element optional
* feat: makes element optional
* feat: uses @consume in the log viewer to showcase
* chore: cleans up debug info
* feat: renames to `consumeContext` and `provideContext` to stay inline with our own methods
* chore: removes unneeded typings
* chore: removes not needed check
* chore: removes not needed check
* test: adds test for rendered value
* feat: splits up code into several smaller functions
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* docs: augments code example for creating a context
* Update src/Umbraco.Web.UI.Client/src/packages/log-viewer/workspace/views/search/components/log-viewer-search-input.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Made card element it is own reusable component and passing the data as property.
* Created the umb-news-container element to handle all the priority grouping.
* Added hover styles to normal-priority cards.
* Removed unused variable.
* add pickable to vs code dictionary
* set up types for pickable filters in data sources
* pass search pickable filter to search result
* apply filter config in document data source example
* add pickable filters to custom tree example
* Update input-entity-data.context.ts
* remove unused
* Update types.ts
* Added request caching to media picker media retrieval, to improve performance in save operations.
* WIP: Update or insert in bulk when updating property data.
* Add tests verifying UpdateBatch.
* Fixed issue with UpdateBatch and SQL Server.
* Removed stopwatch.
* Fix test on SQLite (failing on SQLServer).
* Added temporary test for direct call to NPoco UpdateBatch.
* Fixed test on SQLServer.
* Add integration test verifying the same property data is persisted as before the performance refactor.
* Log expected warning in DocumentUrlService as debug.
(cherry picked from commit 12adfd52bd)
* Remove Microsoft.CodeAnalysis.CSharp from Infrastructure project
This was only needed for runtime compilation and thus is no longer needed in Infrastructure.
It also caused dependency problems with EF Core Design in previous versions.
* Disable CPM for UI project to better reflect consumers
This will ensure that we face any potential dependency issues consumers are also likely to run into.
* Add `Microsoft.CodeAnalysis.CSharp` reference to `Umbraco.Cms.DevelopmentMode.Backoffice`
* Remove Microsoft.CodeAnalysis.CSharp from Infrastructure project
This was only needed for runtime compilation and thus is no longer needed in Infrastructure.
It also caused dependency problems with EF Core Design in previous versions.
* Disable CPM for UI project to better reflect consumers
This will ensure that we face any potential dependency issues consumers are also likely to run into.
* Add `Microsoft.CodeAnalysis.CSharp` reference to `Umbraco.Cms.DevelopmentMode.Backoffice`
Add conditional registration for Entity Data Picker
Introduces an entry point for the Entity Data Picker property editor that registers its manifests only if picker data sources are present, preventing an unusable UI from appearing by default.
* Adding controller
* Lower case route to match other endpoints
* Adding service and typed output
* Renaming to NewsDashboard
* Moving more stuff to service
* Removing unused code
* Some refactoring in accordance with better architecture
* Created repository and mock data source for the news dashboard also display some data in the UI.
* Minor refactoring: naming, aligning with existing controller patterns.
* Update OpenApi.json.
* Update typed client sdk and types.
* Provide language to API endpoint, just in case we want to localize news in the future.
* Obsoleted configuration
* Moved mock data to mocks folder and updated repository to use the actual response model and service from the Api
* Prepared news repository with server data source.
* Rendered news items according to required group structure.
Added TODOs for remaining tasks.
* Fixed FE build issues.
* Update src/Umbraco.Core/Constants-Configuration.cs
* Fixed grid spacing, sanitize code and make the styles closer to the v13.
* Added container query and padding to the card body.
* Fix padding
* Fixed title according to priority.
* Relocated/renamed the news server data-source file
* Simplified the news repo/data-source classes
by extending `UmbControllerBase`, the host constructor is handled for us.
* Added `types.ts` export type files
* Refactored interface name + typing
* Added `uui-loader` component
* Tweaked styles, added box-shadow to cards
Added flexbox gap to the card body.
* Sorted import order
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Adding controller
* Lower case route to match other endpoints
* Adding service and typed output
* Renaming to NewsDashboard
* Moving more stuff to service
* Removing unused code
* Some refactoring in accordance with better architecture
* Created repository and mock data source for the news dashboard also display some data in the UI.
* Minor refactoring: naming, aligning with existing controller patterns.
* Update OpenApi.json.
* Update typed client sdk and types.
* Provide language to API endpoint, just in case we want to localize news in the future.
* Obsoleted configuration
* Moved mock data to mocks folder and updated repository to use the actual response model and service from the Api
* Prepared news repository with server data source.
* Rendered news items according to required group structure.
Added TODOs for remaining tasks.
* Fixed FE build issues.
* Update src/Umbraco.Core/Constants-Configuration.cs
* Fixed grid spacing, sanitize code and make the styles closer to the v13.
* Added container query and padding to the card body.
* Fix padding
* Fixed title according to priority.
* Relocated/renamed the news server data-source file
* Simplified the news repo/data-source classes
by extending `UmbControllerBase`, the host constructor is handled for us.
* Added `types.ts` export type files
* Refactored interface name + typing
* Added `uui-loader` component
* Tweaked styles, added box-shadow to cards
Added flexbox gap to the card body.
* Sorted import order
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Add property editor data source extension types
Introduces types and extension interfaces for property editor data sources, including manifest and API definitions. Updates the main property-editor types export to include the new data source types.
* add test data sources
* wip collection and item repos
* export consts
* fix picker modal token
* make global components file
* render picker in data type
* wire up repositories
* append editor data source alias to data type detail model
* fix global manifest declaration
* make optional
* fix types
* register collection item picker modal element + wip collection menu extension
* register collection menu for property editor data source
* wire up modal tokens
* fix circular
* register as global element
* register default kind for collection menu
* wip fleshing out collection menu
* pass props + listen for selection events
* fix imports
* accept icon in manifest
* extend base type
* use correct data to calculate length
* export types
* add load more button
* wire up load more
* remove debugger
* add search for property editor data sources
* only select one data source
* rename file
* add entity type
* add manifest for search result item
* fix imports/exports
* fix manifest imports
* wire up data source value with workspace
* remove debugger
* wip property editor + input
* move data-source files
* more specific extension types
* remove copy from file name
* allow settings in manifests
* export types
* merge settings
* fix ui alias
* remerge if data source is removed
* Update data-type-details-workspace-view.element.ts
* reset data
* Update data-type-workspace.context.ts
* update merging + move mapping to data source
* Fix mutation of data.values in data type detail mapping
Refactored #mapServerResponseModelToEntityDetailModel to avoid mutating the original data.values array when removing the editorDataSourceAlias. This ensures the original server response remains unchanged and improves data integrity.
* add forDataSourceTypes to manifest
* update interfaces
* test data source implementations
* only show data source select if property editor supports it
* remove custom context
* remove unused token
* use generic collection item picker modal
* remove custom modal
* export types
* render data source alias on data type into view
* pass data source alias
* allow data source alias
* allow data source alias
* pass data source alias
* add prop for data source alias
* Add property editor data source alias support
* Add editor data source alias to property context
Introduces support for storing and retrieving the editor data source alias in UmbPropertyContext. Updates UmbPropertyElement to use the context for managing the data source alias and ensures the alias is set on the property editor element.
* pass data source alias to input
* pass data source alias to context
* update js docs
* split types from token file
* fix import
* update error message
* add more test sources
* Refactor repository manager initialization logic
Changed the initialization flow in UmbRepositoryItemsManager to support optional repository alias and deferred repository setup. Added setItemRepository and getItemRepository methods for explicit repository management, and moved repository initialization logic to a dedicated private method.
* remove support for passing a filter
* wip wire up input with modal
* add constant
* test user data source
* add todo
* require entityType on webhook items
* add entityType
* use id as unique
* add default icon
* wire up search
* add search to media
* pass config
* support configuration in data sources + temp test cases
* remove temp text
* change to one generic extension type with a data type sub type
* search in label
* pass filter args to collection item picker
* clean up
* aligning interfaces
* iterate status instead of item
* simplify examples
* add types for config
* move to examples
* add custom data examples for collection and tree
* update imports
* add manifests for collection and tree custom data examples
* add type guards
* add type guards
* Update types.ts
* add return type
* remove debuggers
* make observables optional
* add null checks for observables
* use statuses
* extend picker input context
* map config
* use data to set value when there is no observable
* store as string array
* Add getDefaultApiConstructor to tree item element
* make it optional
* fix search types
* add fallback icon and name
* remove unused imports
* pass stored value to input
* rename file
* remove unused config value
* make api observable
* add search to custom collection example
* render fallback item
* fix import order
* add fallback render to tree item element
* Update tree-item.element.ts
* Revert "Update tree-item.element.ts"
This reverts commit 3458877de9.
* Revert "add fallback render to tree item element"
This reverts commit b30219d3ed.
* move from data type to property editor
* align file names
* introduce picker-property-editor module
* remove custom types
* use basic types
* use tree item type
* Update input-entity-data.context.ts
* update types
* add interface for item model
* force unique on collection item model
* require an item model in picker context
* allow icon to be null
* extend item model from user group item model
* add entity type to mapped data
* Update user-group-item.server.data-source.ts
* align static file models
* correct types for user picker
* extend item model
* fix types
* more type fixing
* align models
* align models
* fix types
* add utils for fallback name and icon
* add todo
* use fallback name and icon functions
* Update default-picker-search-result-item.element.ts
* add fallback tree item if none is registered
* add search to example
* extract data source config and pass to api
* align naming
* temp type cast
* move search module into core
* fix illegal imports
* add missing const exports
* make property-editor-data-source module
* register property editor data source ref item + render description
* remove console log
* remove indention
* simplify data source type
* Update src/Umbraco.Web.UI.Client/src/packages/property-editors/entity-data-picker/input/input-entity-data.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/property-editor-data-source/input/input-property-editor-data-source.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/menu/default/default-collection-menu.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* add todo
* hide add button when readonly
* check correct amount config
* Update input-entity-data.element.ts
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adjust the `JsonBlockValueConverter` to handle conflicts with 'values' property (due to old data schema)
* Simplify code
* Add unit test to verify change.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* V16: Cache Version Mechanism (#19747)
* Add RepositoryCacheVersion table
* Add repository
* Add Cache version lock
* Add GetAll method to repository
* Add RepositoryCacheVersionService
* Remember to add lock in data creator
* Work my way out of constructor hell
This is why we use DI folks. 🤦
* Add checks to specific cache policies
* Fix migration
* Add to schema creator
* Fix database access
* Initialize the cache version on in memory miss
* Make cache version service internal
* Add tests
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add missing obsoletions
* Prefer full name
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fixed merge
* V16/feature/move last synced id to db (#19884)
* Foundation work for moving last synced id
* register manager and repo in dependency injection
* Fixing to make tests work
* Replacing the use of the old LastSyncedFileManager.cs with the new LastSyncedManager.cs
* Testing to delete out of sync id and old entries
* changing some stuff to please the reviewer.
* Inverted saving methods id check and fixed documentation mishaps
* Loadbalancing: Add Cache Sync service to allow us to roll forward isolated caches when backoffice is load balanced. (#20398)
* Split cache refreshers into internal and external caches
* Add obsolete constructor for CacheInstructionsPruningJob
* Add xml docs
* Move lastID management into CacheInstructionService
* Cache last synced ids in memory
* Lock when processing instructions
* Sync caches when out of sync
* Fix constructors for ICacheSyncService
* Cache version on request
* Register caches as synced when instructions are processed
* Rename CacheVersionAccessor to IRepositoryCacheVersionAccessor
* Set caches as synced before actually syncing the caches
* Set caches as synced before syncing, within scope, this should also lock the cache version from being written to whilst updating caches
* Only check version for backoffice requests
* Clear request cache when caches are syned
* Default to using NOOP cache version service
* Don't generate local identity in database server messenger anymore
* Fix ambiguous constructor
* Add helper method to switch to load balanced isolated caches
* Fix LastSyncedManagerTests
* Fix RepositoryCacheVersionServiceTests
* Fix DefaultCachePolicyTests
* Use correct constructor in FullDataSetRepositoryCachePolicy
* Minor cleanup
* Add XML docs
* Add more xml docs
* Apply suggestions from code review
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
---------
Co-authored-by: Zeegaan <skrivdetud@gmail.com>
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Fix migration plan
* fix tests
* Fix integration tests
* Fix changes from github review
* Move premigrations to v17
* Make lock constantws sequential
* Fix comment
* Make IRepositoryCacheVersionService and ICacheSyncService protected on EntityRepositoryBase
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Nicklas Kramer <nik@umbraco.dk>
Co-authored-by: NillasKA <kramernicklas@gmail.com>
Co-authored-by: Zeegaan <skrivdetud@gmail.com>
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* remove use of modals in collections
* add parent path to support absolute path generation
* add note
* make tree load more minimalistic
* set type and expand inherited styles
* also set title
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/collection/views/table/document-table-collection-view.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* create actions should not open as modal
* remove unused import
* fix router getActivePath
* make expand open the collection
* setTargetTakeSize to low when Collection parent
* expose typeUnique
* fix opening collection
* remove log
* active manager
* export
* impl active manager
* prepare for search param redirects
* fixed collapse feature
* set routes to undefined
* preserveQuery
* ensureSlash
* make a hard redirect for collections
* only if anscenstors are present in data.
* not full match anyway
* only forceShow on hasCollection
* remove umb-section-sidebar-context-menu
* rename to isMenu
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/workspace/document-workspace-split-view.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/tree/tree-item/document-tree-item.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Serverside generated preview URLs
* Add URL provider notation to UrlInfo
* Change preview URL generation to happen at preview time based on provider alias
* Update XML docs
* Always add culture (if available) to preview URL
* Do not log user input (security vulnerability)
* Fix typo
* Re-generate TypeScript client
from Management API
* Deprecated `UmbDocumentPreviewRepository.enter()` (for v19)
Fixed TS errors
Added temp stub for `getPreviewUrl`
* Adds `previewOption` extension-type
* Adds "default" `previewOption` kind
* Relocated "Save and Preview" workspace action
reworked using the "default" `previewOption` kind.
* Added stub for "urlProvider" `previewOption` kind
* Renamed "workspace-action-default-kind.element.ts"
to a more suitable filename.
Exported element so can be reused in other packages,
e.g. documents, for the new "save and preview" feature.
* Refactored "Save and Preview" button
to work with first action's manifest/API.
* Reverted `previewOption` extension-type
Re-engineered to make a "urlProvider" kind for `workspaceActionMenuItem`.
This is to simplify the extension point and surrounding logic.
* Modified `saveAndPreview` Document Workspace Context
to accept a URL Provider Alias.
* Refactored "Save and Preview" button
to extend `UmbWorkspaceActionElement`.
This did mean exposing certain methods/properties to be overridable.
* Used `umbPeekError` to surface any errors to the user
* Renamed `urlProvider` kind to `previewOption`
* Relocated `urlProviderAlias` inside the `meta` property
* also throw an error
* Added missing `await`
* Fix build errors after forward merge
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Start work
* Introduce dto
* Start making repository
* Add migrations
* Implement fetchable first job
* Fix up to also finish tasks
* Refactor jobs to distributed background jobs
* Filter jobs correctly on LastRun
* Hardcode delay
* Add settings to configure delay and period
* Fix formatting
* Add default data
* Add update on startup, which will update periods on startup
* Refactor service to return job directly
* Update src/Umbraco.Infrastructure/Services/Implement/DistributedJobService.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/BackgroundJobs/DistributedBackgroundJobHostedService.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Migrations/Install/DatabaseDataCreator.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Migrations/Install/DatabaseDataCreator.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/BackgroundJobs/DistributedBackgroundJobHostedService.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Remove unused
* Move jobs and make internal
* make OpenIddictCleanupJob.cs public, as it is used elsewhere
* Minor docstring changes
* Update src/Umbraco.Core/Persistence/Constants-Locks.cs
Co-authored-by: Mole <nikolajlauridsen@protonmail.ch>
* ´Throw correct exceptions
* Update xml doc
* Remove business logic from repository
* Remove more business logic from repository into service
* Remove adding jobs from migration
* fix creation
* Rename to ExecuteAsync
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: mole <nikolajlauridsen@protonmail.ch>
* Member type container in management API
* Fix naming
* Update service
* Fix services
* Register IMemberTypeContainerService in DI container
Added a new service registration for `IMemberTypeContainerService`
in the `AddCoreServices` method of `UmbracoBuilder.cs`.
* Replace auditRepository with auditService in constructor
* Add MemberTypeContainer to UdiEntityType mapping
---------
Co-authored-by: georgebid <91198628+georgebid@users.noreply.github.com>
Co-authored-by: Sebastiaan Janssen <sebastiaan@umbraco.com>
Remove `umb-media-picker-create-item` component
it was not being used internally.
There was previously an issue due to a routing issue,
(in that the Media Picker modal wasn't routed),
so the Media create workspace wouldn't work.
This could be resolved in future and see this feature return.
* add interface for item data resolver
* export interface
* add interface to Document item data resolver implementation
* allow to pass a item data resolver to trash action
* pipe resolver to modal
* pass resolver to document trash manifest
* use resolver in modal when available
* Bump Azure.Identity from 1.13.2 to 1.16.0
* Bump BenchmarkDotNet from 0.14.0 to 0.15.4
* Bump Bogus from 35.6.3 to 35.6.4
* Bump HtmlAgilityPack from 1.12.1 to 1.12.4
* Bump MailKit from 4.11.0 to 4.14.0
* Bump MessagePack from 3.1.3 to 3.1.4
* Bump Microsoft.AspNetCore.Mvc.Testing from 9.0.4 to 9.0.9
* Bump Microsoft.Data.SqlClient from 6.0.1 to 6.1.1
* Bump Microsoft.Extensions.Caching.Hybrid from 9.8.0 to 9.9.0
* Bump Microsoft.Extensions.Logging.Debug from 9.0.4 to 9.0.9
* Bump Microsoft.NET.Test.Sdk from 17.13.0 to 18.0.0
* Bump ncrontab from 3.3.3 to 3.4.0
* Bump Nerdbank.GitVersioning from 3.7.115 to 3.8.118
* Bump OpenIddict packages from 6.2.1 to 7.1.0
* Bump Serilog from 4.2.0 to 4.3.0
* Bump Serilog.Sinks.File from 6.0.0 to 7.0.0
* Bump Swashbuckle.AspNetCore from 8.1.1 to 9.0.6
* Bump System.Data.Odbc from 9.0.4 to 9.0.9
* Bump System.Data.OleDb from 9.0.4 to 9.0.9
* Bump Microsoft.IdentityModel.JsonWebTokens from 8.8.0 to 8.14.0
* Bump SixLabors.ImageSharp.Web from 3.1.5 to 3.2.0
- Implicit global usings were made opt-in (https://github.com/SixLabors/ImageSharp.Web/pull/391)
* Bump NJsonSchema from 11.0.2 to 11.5.1
* Bump Microsoft packages from 10.0.0-preview.7.25380.108 to 10.0.0-rc.1.25451.107
* Remove Azure.Identity package reference as implicitly referenced versions are no longer vulnerable
* Remove System.Runtime.Caching package reference as it is not used
* Remove System.Net.Http package reference as it is not used
* Set 'allowPrerelease' to true
Global.json was showing as invalid due to a pre-release version being referenced while 'allowPrerelease' was set to 'false'. This can be set to 'false' again later on.
* Remove System.Security.Cryptography.Xml package reference as implicitly referenced versions are no longer vulnerable
* Remove System.Text.RegularExpressions package reference as implicitly referenced versions are no longer vulnerable
* Remove Microsoft.IdentityModel.JsonWebTokens package reference as implicitly referenced versions are no longer vulnerable
* Remove System.Text.Encodings.Web package reference as it is not used
* Remove Microsoft.Data.SqlClient package reference as implicitly referenced versions are no longer vulnerable
* Remove Lucene.Net.Replicator package reference as implicitly referenced versions are no longer vulnerable
* Remove Microsoft.Extensions.Caching.Memory package reference where not used
* Add EFCore migration for OpenIddict v7 update
* Apply suggestion from @kjac
Cosmetic update: Removed blank line as suggested by Copilot
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* feat: adds new repository for document by id segment options
* chore: mocks up the new endpoint
* feat: all 'null' segments should appear on all languages
* feat: uses new endpoint in content detail workspace base
* feat: maps up the name of the segment
* chore: mock segment data
* feat: adds filter on available segments
* feat: do not alter behavior depending on "undefined" and "null"
* chore: updates mock handler
* feat: ensures that the segments are loaded based on an override method (because they only work for documents) and that they use a generic type (to avoid circular imports)
* feat: refines the segment filter
* chore: updates deprecated model
* feat: treats all culture-less segments as applying to everything
* docs: updates console warn for developers
* initial notes
* flat mapper impl
* first tests passed
* return incoming value to ensure it does not result in an error from an extension
* define the manifest type on UmbPropertyValueResolver
* finish property value flat-mapper
* make sure also to map values with no extension
* clean up test
* export controller
* fix block editor property resolver
* fix mapper types
* ensureVariantsData method
* ensure Block List only updates if it has an update
* ensure varians across for shared across segment and shared across cultures
* fix variant selector hints for segments
* fix hints in variant selector for segmented variants
* Upgrade to Tiptap v3
* Uses `@ts-expect-error` to ignore the TS complication errors
These can be removed once Tiptap has resolved the TypeScript definitions.
* Off-topic: corrected `flags` property in the mock data
Added in PR #19915
* Update src/Umbraco.Web.UI.Client/src/packages/tiptap/extensions/link/link.tiptap-extension.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Webhooks: Removal of client-side deprecations for v17
* User: Removal of client-side deprecations for v17
* UFM: Removal of client-side deprecations for v17
* Tiptap: Removal of client-side deprecations for v17
* Templating: Removal of client-side deprecations for v17
* RTE: Removal of client-side deprecations for v17
* Relations: Removal of client-side deprecations for v17
* Search: Removal of client-side deprecations for v17
* Property Editors: Removal of client-side deprecations for v17
* URL Picker: Removal of client-side deprecations for v17
* Members: Removal of client-side deprecations for v17
* Media: Removal of client-side deprecations for v17
* Extension Insights: Removal of client-side deprecations for v17
* Documents: Removal of client-side deprecations for v17
* Media: Removal of client-side deprecations for v17
(part 2)
* Data Types: Removal of client-side deprecations for v17
* Core: Removal of client-side deprecations for v17
* Content: Removal of client-side deprecations for v17
* Clipboard: Removal of client-side deprecations for v17
* Blocks: Removal of client-side deprecations for v17
* Mocks: Removal of client-side deprecations for v17
* Libs: Removal of client-side deprecations for v17
* Apps: Removal of client-side deprecations for v17
* DevOps: Removal of client-side deprecations for v17
* Document Publishing Workspace: Removal of client-side deprecations for v17
Refactored to use `UmbDocumentPublishingWorkspaceContext`
* Reverted/modified some of my TODO comments
* Updated TODO comment
* Code cleanup sweep of TODO comments and tweaks
* Updated OpenApi.json, re-gen TS client
Tried to fix up mock data.
* Refactored the document variant name/fields
* Implemented co-pilot suggestions
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Started the implementation of the new date time property editor
* Display picked time in local and UTC
* Adjustments to the way the timezones are displayed and the picker is configured
* Filter out `Etc/` (offset) timezones from the list
* Additional adjustments
* Introduced date format and time zone options (all, local or custom)
* Adjustments to the property editor configuration and value converter
* Use UUICombobox instead of UUISelect for displaying time zone options. Display UTC offset instead of short offset name in label.
* Allow searching by offset
* Ignore case when searching for time zone
* Store dates consistently (always same format)
* Add custom PropertyIndexValueFactory for the new property editor
* Adjustments when switching between time zone modes
* Small fixes and cleanup
* Started improving time zone config selection
* Small adjustments
* Remove selected time zones from the list + display label instead of value
* Localizing labels
* Remove unwanted character
* Fix incorrect order of custom time zones list
* Small fixes (mostly validation)
* Rename input time zone component
* Small adjustments
* Using model for stored value
* Save examine value as ISO format
* Adjusting class names for consistency
* Small fixes
* Add default data type configuration
* Rename `TimeZone` to `UmbTimeZone`
* Fix failing tests
* Started adding unit tests for DateWithTimeZonePropertyEditor
* Additional tests
* Additional tests
* Additional tests
* Fixed searches with regex special characters throwing errors
* Remove offset from generic UmbTimeZone type and added new type specific for the property editor
* Adjust property editor to show error when selected time zone is no longer available, instead of pre-selecting another one
* Do not preselect a time zone if a date is stored without time zone
This most likely means that the configuration of the editor changed to add time zone support. In this case we want to force the editor to select the applicable time zone.
* Fix failing backoffice build
* Added tests for DateTimeWithTimeZonePropertyIndexValueFactory
* Improved picker validation
* Remove unused code
* Move models to their corresponding places
* Renaming `DateTimeWithTimeZone` to `DateTime2`
* Fix data type count tests
* Simplifying code + adjusting value converter to support old picker value
* Adjustments to property editor unit tests
* Fix validation issue
* Fix default configuration for 'Date Time (Unspecified)'
* Rename validator
* Fix comment
* Adjust database creator default DateTime2 data types
* Update tests after adjusting default data types
* Add integration test for DateTime2 returned value type
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Aligning DateTime2Validator with other JSON validators. Added new model for API.
* Removed unused code and updated tests
* Fix validation error message
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Splitting the new date time editor into multiple (per output type)
* Adjust tests in DateTime2PropertyIndexValueFactoryTest
* Update value converter tests
* Group the new date time tests
* Adjust new property editor tests
* Adjust property editor integration tests
* Update data editor count tests
* Naming adjustments
* Small fixes
* Cleanup
- Remove unused files
- Remove 'None' option from configuration and update all the tests
* Update luxon depedencies
* Move GetValueFromSource to the value converter
* Add new property editor examples to mock data
* Re-organizing the code
* Adjustments from code review
* Place the date time property index value factories in their own files
* Small adjustments for code consistency
* Small adjustments
* Minor adjustment
* Small fix from copilot review
* Completed the set of XML header comments.
* use already existing query property
* fail is form control element is null or undefined
* using lit ref for querying and form control registration
* state for timeZonePickerValue and remove _disableAddButton
* Adjustments to form control registration
* Remove unused declaration
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Added the ability to set the telemetry level for an unattended install
Added 'UnattendedTelemetryLevel' to 'UnattendedSettings'
Renamed 'CreateUnattendedUserNotificationHandler' to 'PostUnattendedInstallNotificationHandler'
Set the telemetry level in the unattended install notification handler
* Add DefaultValue attribute to 'UnattendedTelemetryLevel'
* Added UnattendedTelemetryLevel to template.
* Updated cli and ide hosts.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update Readme to signpost the Forum (#20268)
Update README.md with information about the forum
Making a small change to the Readme to signpost the Forum now that it's the place to go for help/questions
* Adding SourceWidth and SourceHeight to ImageUrlGenerationOptions
* Update src/Umbraco.Web.Common/Extensions/FriendlyImageCropperTemplateExtensions.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* QA Skip the known failing smoke test to avoid blocking other PRs (#20269)
Added skip for the failing smoke test
---------
Co-authored-by: Owain Williams <owaingdwilliams@gmail.com>
Co-authored-by: Jason Elkin <jasonelkin86@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Nhu Dinh <150406148+nhudinh0309@users.noreply.github.com>
* It worked before i must have broken it somehow. Commit as checkpoint
* Adding a reference from Web.UI.csproj to TestData to allow composers to be composed
* Changing readme and removing project reference
* Adjusted the UTC SQL Server migration to convert time zone ids to the correct format
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Small rename
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* align naming
* mute updates
* lower threshold
* add expansion model with target
* add function to link entries
* fix self import
* export constants
* update js docs for entity expansion manager
* link entries
* fix import
* do not export from menu here
* fix import
* fix import
* align how we register manifests
* add specific managers for section sidebar menu
* use structure items
* dot not expand current item
* Refactor section sidebar menu to use programmatic extension slot
Replaces the template-based <umb-extension-slot> with a programmatically created UmbExtensionSlotElement for improved performance and UX.
* add section context extension
* register menu as section context instead of hardcoding
* rename folder
* align naming
* export extension slot elements
* fix typings
* destroy extension slot element when host is disconnected
* Added user start node restrictions to sibling endpoints.
* use entry model
* move and rename
* register global context to hold menu state across sections
* temp observe section specific expansions
* temp observe section specific expansions
* add method to collapse multiple items
* Further integration tests.
* Tidy up.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* bind expansion to section
* make entity expansion manager generic
* Revert previous update.
* add helper method
* remove temp test data
* Retrieves item counts before and after the target for sibling endpoints and returns in API response.
* Applied previous update correctly.
* Removed blank line.
* Fix build and test asserts following merge.
* add getItem method
* Update OpenApi.json.
* generate new server types
* include last item in target
* add target pagination type
* return totalBefore and totalAfter
* call siblings endpoint for documents
* add method to load children with target
* rename to item
* wip target pagination manager
* add button to load prev tree items
* render prev and nexts buttons for tree items
* Update tree-load-prev-button.element.ts
* add util to append to unique array
* add state method to prepend data
* implement methods to load next and prev items
* add methods to interface
* Update tree-item-element-base.ts
* Update tree-item-context-base.ts
* remove unused
* align methods
* update types
* add jsdocs
* add deprecation notice
* fix jsdocs
* fix import
* Update tree-data-source.interface.ts
* remove duplicate type
* clean up
* fix page calculations
* remove unused
* clean up
* pass full entry to event
* add type for menu item expansion
* export types
* add menuItem alias
* Update types.ts
* support menu item expansion entry
* add const for menu item alias + use for breadcrumb and menu item
* add data type menu item alias const + apply to breadcrumb
* move to correct manifest
* add menu item alias to expand entries
* Update manifests.ts
* add menu structure kind types
* add kind to manifests
* add menu item context
* filter menu items
* handle menu item expansion
* clean up
* fix order
* add example dashboard and entity action
* import types
* align model type names
* align naming
* use ui component
* add guard for menu item entry
* use correct type
* Update section-sidebar-menu.element.ts
* Update entity-expansion.manager.ts
* export constants
* add menuItemAlias to manifest
* add menuItemAlias to manifest
* add menuItemAlias to manifest
* add menuItemAlias to manifest
* add menu item alias
* add menuItemAlias to manifest
* add menuItemAlias to manifest
* add menuItemAlias to manifest
* add alias
* add kind
* fix import path
* do not expand menu from modal
* collect all menu-item files in one folder
* fix lint errors
* Update content-detail-workspace-base.ts
* clean up
* rename to example
* add button to collapse everything within a section
* return correct data from base
* recalculate after
* fix breadcrumb for non-variant structure
* reload entity
* destroy
* remove self
* Updated acceptance tests to check if a caret button is open before clicking
* Bumped version of test helpers
* use const
* add target paging for tree root items
* more specific field names
* update field name
* add model for offset pagination
* add request to model name
* correct
* using Event Contsants for event map
* comment
* clean event listeners before adding new ones
* use createObservablePart
* add paging type guards
* add types
* add check for unique
* add comment
* pass data type id
* wip reload tree logic
* move start + end target logic to target pagination manager
* use target pagination manager in tree item context
* remove local references to start, end and base targets
* calculate before and after when reloading
* clean up
* support children in tree item context
* add methods to observe an expansion entry
* reload structure when item is created
* UX adjustments
* add controller alias to observer
* Update default-tree.context.ts
* Update default-tree.context.ts
* Update default-tree.context.ts
* test targets in document type tree data source
* when reloading only send the target if its part of the current items
* wip tree request manager
* make data source base a controller
* add tree request helper for document types
* use request helper in data source
* clear more data when clear is called
* when reopening a tree item - reuse previous state
* add tree item children manager
* split to manager
* clean up
* only return an entity model when getting target
* allow entity model as target
* add null checks
* add method for getSiblingsFrom
* implement target for tree data request manager
* Update default-tree.context.ts
* set parent for tree root
* reload if target is new
* add types for tree data request manager
* implement request manager for document tree
* use request manager for media tree
* add request manager for data type tree
* move into folder
* move into folder
* move into folder
* add target support for document blueprint
* add request manager for template tree
* add request manager for media type tree
* add hasChildren flag for root
* make start node its own thing
* move hasChildren logic to children manager
* Create tree-item-expansion.manager.ts
* use expansion manager
* align tree item managers
* Update tree-item-context-base.ts
* support take 0
* add methods to get new targets
* add retries
* add button loading states
* fix next start and end
* reset baset target
* use clear when restting children
* throw error if parent doesn't match request
* show notifcation when children is reset
* only render menu context for non trashed document and media items
* use correct import
* fix types
* update interfaces and imports to fix circular dependencies
* move into tree-item folder
* rename file
* Update tree-item-context-base.ts
* move token out of context file to remove circular dependency
* set take size to 50
* remove unused
* export const
* correct default value
* check on both sides after a new base target
* `import type` sort ordering
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* fix sql syntax issues
* unify all dtos, fix autoIncrement for NPoco.Insert and .BulkInsert
* fix Copilot review comments
* fix sql syntax in TrackedReferencesRepository.GetPagedDescendantsInReferences()
* remove changes in TemplateServiceTests
* Tweaks and fixes from first review.
* Reverted changes outside scope of PR.
* Use FirstOrDefault over SelectTop.
* Fix delete member issue.
* Fixed issue with create of webhooks.
* Reverted changes to default data install.
* Removed unused method.
* Rationalised use of quoting helpers.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix nullability issue.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* First Go at the single block property editor based on blocklistpropertyeditor
* Add simalar tests to the blocklist editor
Also check whether either block of configured blocks can be picked and used from a data perspective
* WIP singleblock Valiation tests
* Finished first full pass off SingleBlock validation testing
* Typos, Future test function
* Restore accidently removed file
* Introduce propertyValueConverter
* Comment updates
* Add singleBlock renderer
* Textual improvements
Comment improvements, remove licensing in file
* Update DataEditorCount by 1 as we introduced a new one
* Align test naming
* Add ignored singleblock default renderer
* Enable SingleBlock Property Indexing
* Enable Partial value merging
* Fix indentation
---------
Co-authored-by: kjac <kja@umbraco.dk>
* fix: moves current user config repository and related dependencies to the 'current-user' package
previously, it was not exported, so is not a breaking change
* chore: moves current-user-allow-mfa condition to the 'current-user' package to avoid circular dependencies (and because it naturally belongs there)
* feat: exports all current-user config-related items
* chore: move to 'current-user'
* chore: make sure to export all constants
* Removing obsoleted code from ApiMediaQueryService.cs
* Removing obsoleted code from ApiRichTextMarkupParserTests.cs
* Removing obsoleted code from ContentCacheRefresher.cs
* Removing obsoleted code from ContentFinderByUrlAlias.cs and adjusting its tests to use the new logic
* Removing obsoleted code from ContentFinderByUrl.cs & its dependencies
* Removing obsoleted code from ApiRichTextMarkupParserTests.cs
* Removing obsoleted code from DocumentCache.cs & its dependencies
* Removing obsoleted code from MediaCache.cs & its dependencies
* Removing obsoleted code from PublishedCacheBase.cs & its dependencies
* Removing obsoleted code from RenderNoContentController.cs and its tests
* Removing obsoleted code from UmbracoRouteValueTransformer.cs
* Removing obsoleted constructors from DefaultUrlProvider.cs
* Removing accidental bookmark
* Introducing a helper method to get the root keys in ApiMediaQueryService.cs
* Removing obsoleted code from Cache classes
* Removing unused imports
* Refactoring to meet the CR
* Added attribute to controller
* Fixing missing using statement
* Removing obsoleted constructor from ExternalLoginService.cs and making usages fit
* Removing obsoleted method from IContentTypeFilter.cs
* Removing obsoleted methods from IContentEditingService.cs
* Removing obosoleted code from DocumentUrlService.cs
* Removed obsoleted code from DataTypeService.cs
* Removed obsoleted code from PublishStatusService.cs
* Removing obsoleted code from the IContentPublishingService.cs and its dependencies. Also implementing a TODO in the service implementation
* Removing obsoleted code from IRelationService.cs
* Removing obsoleted code from ContentPublishingService.cs
* Removing obsoleted code from ContentEditingService.cs
* Removing obsoleted code from Constants-DataTypes.cs
* Removing obsoleted code from IAction.cs and its implementations
* Removing obsoleted code from IContentService.cs
* Removing obsoleted code from DomainUtilities.cs
* Removing obsoleted code from IIndexedEntitySearchService.cs and dependencies
* Removing obsoleted code from UrlProvider.cs
* Removing obsoleted code from AliasUrlProvider.cs
* Removing obsoleted code from ApiContentRouteBuilder.cs
* Removing obsoleted code from ApiPublishedContentCache.cs
* Removing obsoleted class TemplateQueryResult.cs
* Removing obsoleted code from ApiContentBuilder.cs
* Removing obsoleted code from HealthCheck.cs
* Removing obsoleted code from ContentTypeEditingService.cs
* Removing obsoleted code from NewDefaultUrlProvider.cs
* Removing obsoleted code from PublishedElementPropertyBase.cs
* Removing obsoleted code from WebhookRequestService.cs
* Bumping to obsolete in V18, due to usage in class that will be removed in V18
* Removing obsoleted code from PropertyValidationService.cs
* Removing obsoleted code from AddUnroutableContentWarningsWhenPublishingNotificationHandler.cs
* Removing obsoleted code from IMemberService.cs
* Removing obsoleted code from DocumentCache.cs
* Removing obsoleted code from ApiMediaQueryService.cs
* Removing obsoleted code from ApiRichTextMarkupParserTests.cs
* Removing obsoleted code from ContentCacheRefresher.cs
* Removing obsoleted code from ContentFinderByUrlAlias.cs and adjusting its tests to use the new logic
* Removing obsoleted code from ContentFinderByUrl.cs & its dependencies
* Removing obsoleted code from ApiRichTextMarkupParserTests.cs
* Removing obsoleted code from DocumentCache.cs & its dependencies
* Removing obsoleted code from MediaCache.cs & its dependencies
* Removing obsoleted code from PublishedCacheBase.cs & its dependencies
* Removing obsoleted code from RenderNoContentController.cs and its tests
* Removing obsoleted code from UmbracoRouteValueTransformer.cs
* Removing obsoleted constructors from DefaultUrlProvider.cs
* Removing accidental bookmark
* Introducing a helper method to get the root keys in ApiMediaQueryService.cs
* Removing obsoleted code from Cache classes
* Removing unused imports
* Refactoring to meet the CR
* Added attribute to controller
* Fixing missing using statement
* Removing ContentFinderByUrlAndTemplateTests.cs and dependencies
* Removing ContentFinderByAliasTests.cs
* Removing ContentFinderByAliasWithDomainsTests.cs
* Removing ContentFinderByIdentifierTestsBase.cs
* Removing ContentFinderByIdTests.cs
* Fixing ContentFinderByKeyTests.cs & ContentFinderByPageIdQueryTests.cs to work with new code
* Removing ContentFinderByUrlTests.cs & ContentFinderByUrlWithDomainsTests.cs
* Fixing ContentFinderByPageIdQueryTests.cs to actually test the result rather than force the result
* Removing comment and adding test scenario
* Removing obsoleted code from ApiMediaQueryService.cs
* Removing obsoleted code from ApiRichTextMarkupParserTests.cs
* Removing obsoleted code from ContentCacheRefresher.cs
* Removing obsoleted code from ContentFinderByUrlAlias.cs and adjusting its tests to use the new logic
* Removing obsoleted code from ContentFinderByUrl.cs & its dependencies
* Removing obsoleted code from ApiRichTextMarkupParserTests.cs
* Removing obsoleted code from DocumentCache.cs & its dependencies
* Removing obsoleted code from MediaCache.cs & its dependencies
* Removing obsoleted code from PublishedCacheBase.cs & its dependencies
* Removing obsoleted code from RenderNoContentController.cs and its tests
* Removing obsoleted code from UmbracoRouteValueTransformer.cs
* Removing obsoleted constructors from DefaultUrlProvider.cs
* Removing the RadioValueEditor.cs & RadioValueValidator.cs obsoleted classes.
* Removing obsolete constructor from MultipleValueValidator.cs
* Removing obsolete constructor from EmailValidator.cs
* Removing obsoleted code from DataValueReferenceFactoryCollection.cs
* Removing obsoleted code from ApiContentBuilderBase.cs
* Fixing constructor missing attribute
* Making use of the TryGet result
* Fixing use of obsoleted constructor
* Removing silly bookmark comment
* Fixing deleted code and restructuring to use new cache
* Making use of TryGetRootKeys bool, to return null if false.
* Extending code to use new constructor
* Updated PublishedContentQuery.cs to return empty array
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Removing obsoleted code from MigrationPlanExecutor.cs & Interface
* Removing obsoleted code from EmailAddressPropertyEditor.cs
* Removing obsoleted class CacheRebuilder.cs
* Removing obsoleted code from TextBuilder.cs
* Removing obsoleted class ICacheRebuilder.cs
* Removing obsoleted code from SerilogLogger.cs
* Removing the use of Infrastructure IBackgroundTaskQueue.cs and replacing usage with the Core replacement
* Removing obsoleted code from the FileUploadPropertyEditor.cs
* Removing obsoleted code from BlockValuePropertyValueEditorBase.cs
* Removing obsoleted constructors and methods from MultiNodeTreePickerPropertyEditor.cs and TextHeaderWriter.cs
* Removing obsoleted code from CacheInstructionService.cs
* Bumping obsoleted code from MigrationBase.cs to V18
* Removing obsoleted code from EmailSender.cs
* Removing obsoleted code from BlockEditorVarianceHandler.cs
* Removing obsoleted code from IBackOfficeApplicationManager.cs
* Removing obsoleted code from RedirectTracker.cs & RichTextEditorPastedImages.cs
* Persist and expose Umbraco system dates as UTC (#19705)
* Updated persistence DTOs defining default dates to use UTC.
* Remove ForceToUtc = false from all persistence DTO attributes (default when not specified is true).
* Removed use of SpecifyKind setting dates to local.
* Removed unnecessary Utc suffixes on properties.
* Persist current date time with UtcNow.
* Removed further necessary Utc suffixes and fixed failing unit tests.
* Added migration for SQL server to update database date default constraints.
* Added comment justifying not providing a migration for SQLite default date constraints.
* Ensure UTC for datetimes created from persistence DTOs.
* Ensure UTC when creating dates for published content rendering in Razor and outputting in delivery API.
* Fixed migration SQL syntax.
* Introduced AuditItemFactory for creating entries for the backoffice document history, so we can control the UTC setting on the retrieved persisted dates.
* Ensured UTC dates are retrieved for document versions.
* Ensured UTC is returned for backoffice display of last edited and published for variant content.
* Fixed SQLite syntax for default current datetime.
* Apply suggestions from code review
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Further updates from code review.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Migrate system dates from local server time to UTC (#19798)
* Add settings for the migration.
* Add migration and implement for SQL server.
* Implement for SQLite.
* Fixes from testing with SQL Server.
* Fixes from testing with SQLite.
* Code tidy.
* Cleaned up usings.
* Removed audit log date from conversion.
* Removed webhook log date from conversion.
* Updated update date initialization on saving dictionary items.
* Updated filter on log queries.
* Use timezone ID instead of system name to work cross-culture.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Removing obsoleted class GlobalSettingsExtensions.cs
* Removing obsoleted methods and usage from ObjectExtensions.cs
* Removing a ton of obsoleted methods from PublishedContentExtensions.cs
* Removing obsoleted constructors
* Removing obsoleted tag on private method that's still in use.
* Use unrestricted text field when creating data types based on the CheckboxList property editor.
Initialize default checkbox list data type with the unrestricted text field for storage on new installs.
Migrate existing data type and property data.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Correctly use constant.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix nullability of Children extension
* Fix nullability of methods throughout the CMS
* Fix return types of some methods that cannot return null
* Revert nullable changes to result of ConvertSourceToIntermediate for property editors (whilst some property editors we know won't return null, it seems more consistent to adhere to the base class and interface nullability definition).
* Updated new webhook events to align with new nullability definitions.
* Reverted content editing service updates to align with base classes.
* Applied collection nullability updates on content repository to interface.
* Reverted value converter updates to match interface.
* Applied further collection updates to interface.
* Aligned media service interface with implementation for nullability.
* Update from code review.
---------
Co-authored-by: Ivo van der Bruggen <ivo@dutchbreeze.com>
Co-authored-by: Ivo van der Bruggen <ivo@vdbruggensoftware.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Introduce new AuditEntryService
- Moved logic related to the IAuditEntryRepository from the AuditService to the new service
- Introduced new Async methods
- Using ids (for easier transition from the previous Write method)
- Using keys
- Moved and updated integration tests related to the audit entries to a new test class `AuditEntryServiceTests`
- Added unit tests class `AuditEntryServiceTests` and added a few unit tests
- Added migration to add columns for `performingUserKey` and `affectedUserKey` and convert existing user ids
- Adjusted usages of the old AuditService.Write method to use the new one (mostly notification handlers)
* Audit service rework
- Added new async and paged methods
- Marked (now) redundant methods as obsolete
- Updated all of the usages to use the non-obsolete methods
- Added unit tests class `AuditServiceTests` and some unit tests
- Updated existing integration test
* Use the audit service instead of the repository directly in services
* Apply suggestions from code review
* Small improvement
* Update src/Umbraco.Core/Services/AuditService.cs
* Some minor adjustments following the merge
* Delete unnecessary file
* Small cleanup on the tests
* Remove changing user id to 0 (on audit) if user id is admin in media bulk save
* Remove reference to unused IUserIdKeyResolver in TemplateService
* Remove references to unused IShortStringHelper and GlobalSettings in FileService
* Started implementing new LongRunningOperationService and adjusting tasks to use this service
This service will manage operations that require status to be synced between servers (load balanced setup).
* Missing migration to add new lock. Other simplifications.
* Add job to cleanup the LongRunningOperations entries
* Add new DatabaseCacheRebuilder.RebuildAsync method
This is both async and returns an attempt, which will fail if a rebuild operation is already running.
* Missing LongRunningOperation database table creation on clean install
* Store expire date in the long running operation. Better handling of non-background operations.
Storing an expiration date allows setting different expiration times depending on the type of operation, and whether it is running in the background or not.
* Added integration tests for LongRunningOperationRepository
* Added unit tests for LongRunningOperationService
* Add type as a parameter to more repository calls. Distinguish between expiration and deletion in `LongRunningOperationRepository.CleanOperations`.
* Fix failing unit test
* Fixed `PerformPublishBranchAsync` result not being deserialized correctly
* Remove unnecessary DatabaseCacheRebuildResult value
* Add status to `LongRunningOperationService.GetResult` attempt to inform on why a result could not be retrieved
* General improvements
* Missing rename
* Improve the handling of long running operations that are not in background and stale operations
* Fix failing unit tests
* Fixed small mismatch between interface and implementation
* Use the new submit and poll functionality for the Examine index rebuild
* Use a fire and forget task instead of the background queue
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Make sure exceptions are caught when running in the background
* Alignment with other repositories (async + pagination)
* Fix build after merge
* Missing obsoletion messages
* Additional fixes
* Add Async suffix to service methods
* Missing adjustment
* Moved hardcoded settings to IOptions
* Fix issue in SQL Server where 0 is not accepted as requested number of rows
* Fix issue in SQL Server where query provided to count cannot contain orderby
* Additional SQL Server fixes
* Update method names
* Adjustments from code review
* Ignoring result of index rebuild in `IndexingNotificationHandler.Language.cs` (same behavior as before)
* Missed some obsoletion messages
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Introduce new AuditEntryService
- Moved logic related to the IAuditEntryRepository from the AuditService to the new service
- Introduced new Async methods
- Using ids (for easier transition from the previous Write method)
- Using keys
- Moved and updated integration tests related to the audit entries to a new test class `AuditEntryServiceTests`
- Added unit tests class `AuditEntryServiceTests` and added a few unit tests
- Added migration to add columns for `performingUserKey` and `affectedUserKey` and convert existing user ids
- Adjusted usages of the old AuditService.Write method to use the new one (mostly notification handlers)
* Audit service rework
- Added new async and paged methods
- Marked (now) redundant methods as obsolete
- Updated all of the usages to use the non-obsolete methods
- Added unit tests class `AuditServiceTests` and some unit tests
- Updated existing integration test
* Apply suggestions from code review
* Small improvement
* Update src/Umbraco.Core/Services/AuditService.cs
* Some minor adjustments following the merge
* Delete unnecessary file
* Small cleanup on the tests
* Introduce new AuditEntryService
- Moved logic related to the IAuditEntryRepository from the AuditService to the new service
- Introduced new Async methods
- Using ids (for easier transition from the previous Write method)
- Using keys
- Moved and updated integration tests related to the audit entries to a new test class `AuditEntryServiceTests`
- Added unit tests class `AuditEntryServiceTests` and added a few unit tests
- Added migration to add columns for `performingUserKey` and `affectedUserKey` and convert existing user ids
- Adjusted usages of the old AuditService.Write method to use the new one (mostly notification handlers)
* Apply suggestions from code review
* Small improvement
* Some adjustments following code review. Removed UnknownUserKey and used null instead.
* Small adjustments
* Better handle audits performed during the migration state
* Update TODO comment
@@ -9,7 +9,7 @@ In order to use Umbraco as a CMS and build your website with it, you should not
- Are you about to [create a pull request for Umbraco][contribution guidelines]?
- Are you trying to get to the bottom of a problem in your existing Umbraco installation?
If the answer is yes, please read on. Otherwise, make sure to head on over [to the download page](https://our.umbraco.com/download) and start using Umbraco CMS as intended.
If the answer is yes, please read on. Otherwise, make sure to head on over [to the releases page](https://releases.umbraco.com) and start using Umbraco CMS as intended.
## Table of contents
@@ -79,13 +79,12 @@ Conversely, if you are working on front-end only, you want to build the back-end
"AuthorizeCallbackLogoutPathName":"/logout",
"AuthorizeCallbackErrorPathName":"/error",
"BackOfficeTokenCookie":{
"Enabled":true,
"SameSite":"None"
}
```
> [!NOTE]
> If you get stuck in a login loop, try clearing your browser cookies for localhost, and make sure that the `BackOfficeTokenCookie` settings are correct. Namely, that `SameSite` should be set to `None` when running the front-end server separately.
> If you get stuck in a login loop, try clearing your browser cookies for localhost, and make sure that the `Umbraco:Cms:Security:BackOfficeTokenCookie:SameSite` setting is set to `None`.
@@ -24,7 +24,7 @@ Great question! The short version goes like this:
1.**Switch to the correct branch**
Switch to the `contrib` branch
Switch to the `main` branch
1.**Build**
@@ -32,7 +32,7 @@ Great question! The short version goes like this:
1.**Branch**
Create a new branch now and name it after the issue you're fixing, we usually follow the format: `temp-12345`. This means it's a temporary branch for the particular issue you're working on, in this case issue number `12345`. Don't commit to `contrib`, create a new branch first.
Create a new branch now and name it after the issue you're fixing, we usually follow the format: `temp-12345`. This means it's a temporary branch for the particular issue you're working on, in this case issue number `12345`. Don't commit to `main`, create a new branch first.
1.**Change**
@@ -42,7 +42,7 @@ Great question! The short version goes like this:
Done? Yay! 🎉
Remember to commit to your new `temp` branch, and don't commit to `contrib`. Then you can push the changes up to your fork on GitHub.
Remember to commit to your new `temp` branch, and don't commit to `main`. Then you can push the changes up to your fork on GitHub.
#### Keeping your Umbraco fork in sync with the main repository
@@ -59,10 +59,10 @@ Then when you want to get the changes from the main repository:
```
git fetch upstream
git rebase upstream/contrib
git rebase upstream/main
```
In this command we're syncing with the `contrib` branch, but you can of course choose another one if needed.
In this command we're syncing with the `main` branch, but you can of course choose another one if needed.
[More information on how this works can be found on the thoughtbot blog.][sync fork ext]
@@ -79,7 +79,7 @@ You can get in touch with [the core contributors team][core collabs] in multiple
- If there's an existing issue on the issue tracker then that's a good place to leave questions and discuss how to start or move forward.
- If you want to ask questions on some code you've already written you can create a draft pull request, [detailed in a GitHub blog post][draft prs].
- Unsure where to start? Did something not work as expected? Try leaving a note in the ["Contributing to Umbraco"][contrib forum] forum. The team monitors that one closely, so one of us will be on hand and ready to point you in the right direction.
- Unsure where to start? Did something not work as expected? Try leaving a note in the [forum][forum]. The team monitors that one closely, so one of us will be on hand and ready to point you in the right direction.
<!-- Local -->
@@ -90,7 +90,7 @@ You can get in touch with [the core contributors team][core collabs] in multiple
[sync fork ext]: http://robots.thoughtbot.com/post/5133345960/keeping-a-git-fork-updated "Details on keeping a git fork updated"
[draft prs]: https://github.blog/2019-02-14-introducing-draft-pull-requests/ "Github's blog post providing details on draft pull requests"
Always reference these instructions first and fallback to search or bash commands only when you encounter unexpected information that does not match the info here.
## Working Effectively
Bootstrap, build, and test the repository:
- Install .NET SDK (version specified in global.json):
Always wait for commands to complete rather than canceling and retrying.
The full development guide for this repository lives in [CLAUDE.md](../CLAUDE.md). Please read that file for complete instructions on architecture, build steps, testing, branching conventions, and coding patterns.
Enterprise-grade CMS built on .NET 10.0. This repository contains 21 production projects organized in a layered architecture with clear separation of concerns.
**Description**: A short, kebab-case description (a few words). This should be prefixed with the GitHub issue number if the update is related to resolving a tracked issue.
When a public class needs new dependencies, obsolete the existing constructor and add a new one. The old constructor delegates to the new one, resolving missing deps via `StaticServiceProvider`.
```csharp
[Obsolete("Please use the constructor with all parameters. Scheduled for removal in Umbraco 19.")]
- Old constructor marked `[Obsolete("... Scheduled for removal in Umbraco {current-major+2}.")]`
- Old constructor calls new constructor via `: this(...)`
- Uses `StaticServiceProvider.Instance.GetRequiredService<T>()` for new params only
- DI registration must use the NEW constructor (old is for external consumers only)
### 5.2 Obsolete Method + New Overload
When a public method signature needs to change, add the new method/overload and obsolete the old. The obsolete method should call the new one with suitable defaults.
```csharp
[Obsolete("Use the overload taking all parameters. Scheduled for removal in Umbraco 19.")]
publicvoidDoThing(stringname)
=>DoThing(name,extraParam:null);
publicvoidDoThing(stringname,string?extraParam)
{
// Real implementation here
}
```
**Rules**:
- Old method marked `[Obsolete]` with removal schedule
- DRY: old method calls new method, providing defaults for new parameters
- All internal callers must be updated to use the new method
- No callers should remain on the obsolete method within the codebase
### 5.3 Default Interface Implementation
When adding methods to a public interface, provide a default implementation so existing external implementations don't break.
```csharp
publicinterfaceIMyService
{
// Existing method
voidExistingMethod();
// New method with default implementation
voidNewMethod(stringparam)
=>ExistingMethod();// delegate to existing if possible
}
```
**Strategies for the default** (in order of preference):
1.**Use existing interface methods** to satisfy the contract (even if not optimal)
2.**Return a sensible default** like empty collection, null, etc.
3.**Throw `NotImplementedException`** if no reasonable default exists
**Example**: `IContentService.SaveBlueprint` - new overload with `IContent? createdFromContent` has a default impl that calls the old method (ignoring the new param).
**Example**: `IDocumentPresentationFactory.CreateCulturePublishScheduleModels` - full default implementation with logic, uses `StaticServiceProvider` for dependency resolution within the interface.
**Rules**:
- Add `// TODO (V{next-major}): Remove the default implementation when {obsolete method} is removed.` comment
- Default impl should be functionally correct even if not optimal
- If using `StaticServiceProvider` in a default impl, note this is temporary
### 5.4 General Rules
- **Removal policy**: Obsoleted members must remain for at least one full major version before removal. If obsoleted in version N, the earliest removal is version N+2. For example, something obsoleted in v17 is scheduled for removal in v19 (giving the whole of v18 as a deprecation period).
- All `[Obsolete]` attributes must include **"Scheduled for removal in Umbraco {current+2}"**
- Read `version.json` to determine the current major version
- Suppress `CS0618` warnings where obsolete members must call each other:
```csharp
#pragma warning disable CS0618 // Type or member is obsolete
=> OldMethod(param);
#pragma warning restore CS0618 // Type or member is obsolete
```
- Update ALL internal callers to use the new API - no internal code should use obsolete members
---
## 6. Project-Specific Notes
### Centralized Package Management
**All NuGet package versions** are centralized in `Directory.Packages.props`. Individual projects do NOT specify versions.
```xml
<!-- Individual projects reference WITHOUT version -->
The repository contains BOTH (actively supported):
- **Current**: NPoco-based persistence (`Umbraco.Cms.Persistence.Sqlite`, `Umbraco.Cms.Persistence.SqlServer`) - widely used and fully supported
- **Future**: EF Core-based persistence (`Umbraco.Cms.Persistence.EFCore.*`) - migration in progress
**Note**: The codebase is actively migrating to EF Core, but NPoco remains the primary persistence layer and is not deprecated. Both are fully supported.
### Authentication: OpenIddict
All APIs use **OpenIddict** (OAuth 2.0/OpenID Connect):
- Reference tokens (not JWT) for better security
- **Secure cookie-based token storage** (v17+) - tokens stored in HTTP-only cookies with `__Host-` prefix
- Tokens are redacted from client-side responses and passed via secure cookies only (`[redacted]` placeholder)
- ASP.NET Core Data Protection for token encryption
- Configured in `Umbraco.Cms.Api.Common`
- API requests must include credentials (`credentials: include` for fetch)
**Load Balancing Requirement**: All servers must share the same Data Protection key ring.
**Frontend auth pitfalls** — see `src/Umbraco.Web.UI.Client/docs/edge-cases.md` (Auth & Cross-tab section) and `docs/security.md`. Key points:
- Never call `validateToken()` per API request — it revokes the previous reference token (ID2019 errors)
- `window.opener` is set for ANY `window.open()` target, not only OAuth popups — scope guards to the pathname too
- BroadcastChannel does not deliver messages to the sender's own tab
The backoffice (`Umbraco.Web.UI.Client`) is published to npm as **`@umbraco-cms/backoffice`** with a plugin architecture:
#### Architecture Overview
- **Multi-workspace structure**: Subprojects in `src/libs/*`, `src/packages/*`, `src/external/*`
- **Export model**: All exports defined in root `package.json` → `./exports` field
- **Importmap-driven runtime**: Dependencies provided at runtime via importmap (single source of truth)
- **Build-time types**: TypeScript types come from npm peerDependencies
- **Plugin model**: Developers create plugins that import from `@umbraco-cms/backoffice/*` exports
#### Dependency Hoisting Strategy
When building for npm (`npm pack`), the `cleanse-pkg.js` script hoists subproject dependencies to root `peerDependencies` with intelligent version range conversion:
**Version Range Logic** (uses `semver` package):
1. **Pre-release (0.x.y)**: Convert to explicit range
- Input: `^0.85.0` or `0.85.0`
- Output: `>=0.85.0 <1.0.0`
- Rationale: Pre-release caret only allows patch updates, explicit range allows minor upgrades within 0.x.x
- Example: Plugin can use `@hey-api/openapi-ts@0.91.1` while backoffice uses `0.85.0`
2. **Stable with caret (^X.Y.Z where X ≥ 1)**: Keep as-is
- Input: `^3.3.1`
- Output: `^3.3.1` (unchanged)
- Rationale: Caret already implements correct semantics for stable versions
3. **Stable exact versions (X.Y.Z where X ≥ 1)**: Add caret
- Input: `3.16.0`
- Output: `^3.16.0`
- Rationale: Normalizes to conventional semver format
#### Key Dependencies
**Runtime via importmap** (types available from peerDependencies):
**This repository follows a layered architecture with strict dependency rules. The Core defines contracts, Infrastructure implements them, and Web/APIs consume them. Each layer can be understood independently, but dependencies always flow inward toward Core.**
<!-- OpenIddict.AspNetCore, Npoco.SqlServer and Microsoft.EntityFrameworkCore.SqlServer brings in a vulnerable version of Microsoft.IdentityModel.JsonWebTokens -->
<!-- Take top-level depedendency on Microsoft.IdentityModel.JsonWebTokens, because OpenIddict.AspNetCore, Npoco.SqlServer and Microsoft.EntityFrameworkCore.SqlServer depends on a vulnerable version -->
<!-- Azure.Identity, Microsoft.EntityFrameworkCore.SqlServer and Dazinator.Extensions.FileProviders brings in a legacy version of System.Text.Encodings.Web -->
This repository includes configuration for [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) servers, enabling AI tooling integration for Umbraco CMS development workflows.
## Overview
MCP allows AI assistants (like Claude) to interact with external tools and services. This repository configures two MCP servers:
| Server | Purpose | Package |
|--------|---------|---------|
| **umbraco-cms** | Manage Umbraco content types, documents, and media | `@umbraco-cms/mcp-dev@17` |
| **playwright** | Browser automation for testing and debugging | `@playwright/mcp@latest` |
## Quick Start
### 1. Start Umbraco Locally
Ensure your local Umbraco instance is running at `https://localhost:44339` (or update the URL in your `.env.local`).
### 2. Configure Environment Variables
Copy the example environment file and customize it:
> **Warning**: This configuration is for **local development only**.
### Self-Signed Certificates
`NODE_TLS_REJECT_UNAUTHORIZED=0` disables SSL certificate validation. This is necessary for self-signed certificates in local development but:
- **Never use in production**
- Affects all HTTPS connections made by Node.js processes
- Consider trusting your local development certificate instead
### Client Secrets
- Never commit real secrets to source control
- The `.env.local` file is gitignored for this reason
- Use strong, unique secrets even in development
- The example value `1234567890` in `.env.example` is a placeholder only
## File Structure
```
Umbraco-CMS/
├── .mcp.json # MCP server configuration
├── .env.example # Example environment variables (committed)
├── .env.local # Your local environment variables (gitignored)
├── .claude/
│ ├── settings.json # Shared Claude AI permissions (committed)
│ └── settings.local.json # Local Claude overrides (gitignored)
├── .gitignore # Ignores .env.local and settings.local.json
└── MCP.md # This documentation (you are here)
```
## Claude AI Permissions
The `.claude/settings.json` file configures which MCP tools Claude can use automatically without prompting. This is shared across the team for consistent developer experience.
### Customizing Permissions Locally
Create `.claude/settings.local.json` to override permissions for your environment:
```json
{
"permissions":{
"allow":[
"mcp__umbraco__get-all-document-types"
]
}
}
```
## Troubleshooting
### "Connection refused" errors
- Ensure Umbraco is running at the configured `UMBRACO_BASE_URL`
- Check that the port matches your local setup
### "Unauthorized" errors
- Verify the OAuth client is configured in Umbraco
- Check that `UMBRACO_CLIENT_ID` and `UMBRACO_CLIENT_SECRET` match
- Ensure the client has appropriate permissions
### "Certificate" errors
- For local development, set `NODE_TLS_REJECT_UNAUTHORIZED=0` in `.env.local`
- Alternatively, trust your local development certificate
### MCP server not starting
- Ensure Node.js is installed (v22+ recommended, matching .nvmrc)
- Run `npx @umbraco-cms/mcp-dev@17 --help` to verify the package works
# Filter tests that are not part of the Umbraco.Infrastructure namespace. So this will run all tests that are not part of the Umbraco.Infrastructure namespace
# Filter tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace. So this will run all tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace
# Filter tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace. So this will run all tests that are not part of the Umbraco.Infrastructure and the ManagementApi namespace
# Filter tests that are not part of the Umbraco.Infrastructure namespace. So this will run all tests that are not part of the Umbraco.Infrastructure namespace
# Filter tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace. So this will run all tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace
# Filter tests that are not part of the Umbraco.Infrastructure namespace. So this will run all tests that are not part of the Umbraco.Infrastructure namespace
# Filter tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace. So this will run all tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace
# Filter tests that are not part of the Umbraco.Infrastructure namespace. So this will run all tests that are not part of the Umbraco.Infrastructure namespace
# Filter tests that are not part of the Umbraco.Infrastructure and ManagementApi namespace. So this will run all tests that are not part of the Umbraco.Infrastructure namespace
# Filter tests that are not part of the Umbraco.Infrastructure namespace. So this will run all tests that are not part of the Umbraco.Infrastructure namespace
# Filter tests that are not part of the Umbraco.Infrastructure namespace. So this will run all tests that are not part of the Umbraco.Infrastructure namespace
**Configuration**: `BackOfficeTokenCookieSettings.Enabled` (default: true in v17+)
**Implications**: Client-side cannot access tokens; encrypted with Data Protection; load balancing needs shared key ring; API requests need `credentials: include`
---
## 6. Common Issues & Edge Cases
### Polymorphic Deserialization Requires `$type`
**Issue**: Deserializing to an interface without `$type` discriminator fails.
**This library is the foundation for all Umbraco CMS REST APIs. Focus on OpenAPI customization, authentication configuration, and polymorphic serialization when working here.**
=>$"{apiDesc.GroupName}_{apiDesc.ActionDescriptor.AttributeRouteInfo?.Template ?? apiDesc.ActionDescriptor.RouteValues["controller"]}_{(apiDesc.ActionDescriptor.RouteValues.TryGetValue("action", out var action) ? action : null)}_{apiDesc.HttpMethod}";
// IMPORTANT: the handler must be AFTER the built-in query string handler, because the client-side SignalR library sometimes appends access tokens to the query string.
// IMPORTANT: the handler must be AFTER the built-in query string handler, because the client-side SignalR library sometimes appends access tokens to the query string.
:thrownewArgumentException($"Invalid item type. This method can only be used with item type {nameof(PublishedItemType.Content)}, got: {content.ItemType}");
**This library exposes Umbraco content and media via REST for headless scenarios. Focus on query handlers, access control, and member authentication when working here.**
Description=QueryParameterDescription("Explicitly defines which properties should be included in the response (by default all properties are included)"),
[Obsolete("Use IVariationContextAccessor to manipulate the variation context. Scheduled for removal in V17.")]
publicvoidSetRequestCulture(stringculture)
{
// no-op
}
// at the time of writing we're introducing this to get rid of accept-language header values like "en-GB,en-US;q=0.9,en;q=0.8",
// so we don't want to be too restrictive in this regex - keep it simple for now.
[GeneratedRegex(@"^[\w-]*$")]
Some files were not shown because too many files have changed in this diff
Show More
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.