* Lowercase OpenAPI document name on registration to match AddOpenApi internal behaviour
AddOpenApi lowercases the document name when registering its keyed services, so
ReplaceOpenApiSchemaService must receive the same lowercased key or the lookup
throws. BackOfficeOpenApiDocumentBuilder now computes a normalised registration
name and uses it for all DI calls, while keeping DocumentName in its original
casing. ShouldInclude matches [MapToApi] case-insensitively to align with how
documents are registered, and the UI dropdown label falls back to DocumentName
(original casing) rather than the lowercased registration key.
AddUmbracoOpenApiDocument applies the same normalisation for its apiName parameter.
* Add regression tests for mixed-case OpenAPI document name registration
Covers the bug scenario where AddBackOfficeOpenApiDocument with a mixed-case
name and WithJsonOptions threw InvalidOperationException at startup, and verifies
that ShouldInclude matches [MapToApi] case-insensitively.
User-collection-table didn´t format and if you have da backoffice the time is still Am/pm
Co-authored-by: Lucas Bach Bisgaard <lucas.bisgaard@kraftvaerk.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Fix detail data request manager failing as soon as the number of items requested hits the UmbItemDataApiGetRequestController batch limit (40)
Co-authored-by: Paul Woodland <paul.woodland@pwnewmedia.com>
Fix detail data request manager failing as soon as the number of items requested hits the UmbItemDataApiGetRequestController batch limit (40)
Co-authored-by: Paul Woodland <paul.woodland@pwnewmedia.com>
* feat(media): add umb-thumbnail and configurable checkerboard background
Adds `umb-thumbnail` as the recommended alias of `umb-imaging-thumbnail`
(the original tag stays registered for backwards compatibility), and makes
the checkerboard background opt-out via the `--umb-thumbnail-background` CSS
custom property plus an `img` part for full styling control. Also fixes an
action-event listener leak in the thumbnail element, and adds a Storybook
story, an MDX guide, and component tests.
Closes#23177
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(media): address PR review on umb-thumbnail
- Rephrase the imaging-thumbnail JSDoc to a neutral alias statement instead of
a "prefer" wording that read like an undeclared deprecation.
- Guard the thumbnail tests so a renamed private field fails loudly rather than
producing vacuous assertions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(media): make umb-thumbnail canonical, deprecate umb-imaging-thumbnail
Invert the inheritance so the implementation lives on `UmbThumbnailElement`
(`umb-thumbnail`) and `UmbImagingThumbnailElement` (`umb-imaging-thumbnail`)
is the thin subclass. Removing the old tag is now just deleting one file.
The deprecated subclass emits a one-time `UmbDeprecation` warning (a
module-level guard avoids per-instance console spam) and carries a
`@deprecated` JSDoc, scheduled for removal in Umbraco 19.
Migrate the four internal consumers to `umb-thumbnail` so the deprecation
warning targets external code only, not our own.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(media): trim deprecated-alias thumbnail tests to a registration guard
The img part, checkerboard default and --umb-thumbnail-background override are
covered by thumbnail.element.test.ts and inherited from UmbThumbnailElement, so
re-asserting them on the umb-imaging-thumbnail subclass only tested inheritance.
Keep a single backwards-compat guard that the deprecated alias stays registered
and on the inheritance chain.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(media): rename canonical thumbnail to umb-media-thumbnail; alias keeps @deprecated, no runtime warning
Per review (Niels): the forward-looking name is `umb-media-thumbnail`
(`UmbMediaThumbnailElement`), leaving room for non-media thumbnails later. The
implementation, CSS custom property (`--umb-media-thumbnail-background`), story,
guide and internal consumers all use the new name.
`umb-imaging-thumbnail` stays registered as a thin alias and keeps its
`@deprecated` JSDoc (IDE signal) but no longer emits a runtime UmbDeprecation
warning — both tags fly for now. Docs and comments lead with umb-media-thumbnail.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(core): annotate deprecation warnings with caller origin, suppress core noise in production
Deprecation warnings now state where the call most likely came from — Umbraco
core, an /App_Plugins package, or other custom code — by classifying the call
stack (first frame not under /umbraco/backoffice/ is the caller). This answers
the Codegarden feedback that you can't tell whose code triggered a warning.
In production builds, core-origin warnings are suppressed (a consumer can't act
on Umbraco's own code); package/external/unknown origins are always shown. The
production signal is the client build, not the server runtime mode — the latter
is unreliable since Umbraco Cloud defaults to BackofficeDevelopment. The new
umbIsProductionBuild() reads Vite's import.meta.env.PROD (substituted to true in
the shipped core bundle) and falls back to false outside a Vite build.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(core): cleaner deprecation output and drop the throw for stack capture
Read new Error().stack directly instead of throwing and catching — the stack is
populated on construction. Annotate the warning with the resolved origin on its
own line rather than a bracketed prefix, and rely on the browser's native
expandable stack on console.warn for the full clickable trace instead of
printing one ourselves.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(core): trim inline comments in deprecation utils
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(core): address PR review on deprecation origin
- Clarify umbIsProductionBuild docs: in Vite dev import.meta.env is defined
(PROD false); the guard is for non-Vite contexts (tsc pass, web-test-runner).
- Strip query/fragment from parsed frame URLs so the external-origin label
can't carry ?/# noise.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
DocumentHybridCacheStaleSetRaceTests came from the v17 PR #23169 and merged
forward into main (v18) unchanged, but on v18 IDatabaseCacheRepository renamed
GetContentSourceAsync -> GetDocumentSourceAsync and
GetContentSourceForPublishStatesAsync -> GetDocumentSourceForPublishStatesAsync.
The mock setups still referenced the v17 names, failing the build with CS1061.
Rename the two Moq setups to the v18 method names so the test compiles and the
mocks actually intercept the calls DocumentCacheService makes. v17 keeps the
Content* names and is unaffected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Guard against cache poisoning from concurrency
* Resolve code review comments relating to tests.
* Avoid unnecessary second invalidation of memory cache generatio.
* Tighten the cache-generation guard.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Display appropriate content type name in compositions dialog localised texts.
* Fix composition dialog translation typos and link references to the matching workspace
- fr: "sililaire" -> "similaire"
- it: "utlizzato" -> "utilizzato"
- es: remove duplicated "no puede no puede"
The reference list now builds its workspace edit href from the modal's
entityType instead of hardcoding document-type, so links resolve correctly
when the dialog is used for Media Types and Member Types.
* Integrate interaction memories into entity data picker
* Skip resetting unchanged data source API
Add an early-return guard in setDataSourceApi to avoid re-setting the same UmbPickerDataSource instance. Prevents rebuilding the modal token/route (which would close and reopen an open picker modal) on every re-render by only updating when the API actually changes.
* Add UmbEntityInputInteractionMemoryManager + implement across current inputs with memory
* clean up comment
* feat(elements): add value summary for Element Picker property editor
Adds a valueSummary extension so picked element names appear in collection
view columns. Includes a value-type constant, batch resolver, variant-aware
element, and a resolver unit test (11 cases).
* fix(elements): address PR review feedback on element picker value summary
- Call removeUmbControllerByAlias when removing a stale resolver so the
named observer controller is released from the element's controller list
- Call setData on existing resolvers when _value refreshes so renames are
reflected without recreating the resolver
- Remove redundant valueResolver re-export from resolver file (barrel handles it)
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* feat(ufm): add umbElementName UFM component
Adds a new UFM component that resolves Element display names from element
keys, mirroring the umbContentName component pattern. Uses the variant-aware
UmbElementItemDataResolver (via UmbElementItemRepository) for proper
culture/variant handling and (Untitled) fallback.
Also exports UmbElementItemDataResolver from the public
@umbraco-cms/backoffice/element entry point, matching the pattern used by
the documents package.
* fix(ufm): clear stale value and destroy resolvers in element-name element
Clear this.value when the render context produces no usable input, preventing
stale names from lingering when the context changes. Also destroy each
UmbElementItemDataResolver after getName() to avoid accumulating controller
registrations on the host element.
* Update src/Umbraco.Web.UI.Client/src/packages/ufm/components/element-name/element-name.element.ts
Co-authored-by: Andy Butland <abutland73@gmail.com>
* test(ufm): add umbElementName parsing test to marked-ufm.test.ts
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Block RTE: Implement unsupported block rendering
* Fixes `.ProseMirror-selectednode` focus ring
* Markup tidy-up
* Adds test for `umb-unsupported-rte-block`
* Block RTE: Reflect unsupported state as a host attribute
Replaces @state() + toggleAttribute() with @property({ reflect: true })
so Lit manages the 'unsupported' attribute sync during the update cycle,
avoiding constructor-time attribute access flagged by the linter.
Also removes the now-inert uui-text/uui-font classes from the block
wrapper div (backing styles were removed with UmbTextStyles).
* Adds JSDoc comment to `unsupported` property
* Block RTE: Extract #observeBlockViewProps() to reduce constructor size
Moves the block-view-props observer setup out of the constructor into a
dedicated #observeBlockViewProps() method, following the same pattern as
#observeData(). Reduces constructor from 123 to 64 lines (threshold: 70).
The `loaded`-signal test (added in #23167) built its host with
`UmbControllerHostElementMixin(HTMLElement)`, mirroring the older
`UmbBaseExtensionInitializer` tests. But `UmbExtensionInitializerBase`
requires a full `UmbElement` host, so the test failed `tsc` (TS2345)
under the root tsconfig. The product build excludes `*.test.ts`, so it
slipped through CI but breaks `npm run compile`/the editor.
Use `UmbElementMixin(HTMLElement)`, matching what production callers pass
(app/backoffice/preview elements are all UmbElements).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Reconciles app.element.ts with #23020 (parallelized public extensions).
Kept the boot gate (await the app-entry-point initializer before routing)
and restored a blocking inline `await registerPublicExtensions()` instead
of the parallelized deferred form — a marginally slower but more robust
boot, identical to the release/17.5.0 fix (no empty-first-pass timing
reliance). extension-initializer-base.ts, the unit test, the acceptance
test and playwright config merge cleanly.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* External login: wait for app-entry-points before the login provider decision
The backoffice boot stopped waiting for app-entry-point extensions to settle
before deciding which auth provider to use (regression introduced in #22522).
On a slow connection an externally registered authProvider (e.g. Umbraco ID)
is not registered yet when the login screen renders, so the user is dropped on
the local login instead of being redirected to the external provider.
- extension-initializer-base: `loaded` re-arms to `undefined` while a pass is in
flight and resolves to `true` unconditionally (including zero extensions), so
`.asPromise()` gates correctly and never hangs on a default install (which has
no app-entry-points) — the reason the await was removed in the first place.
- app.element: restore the awaited boot gate before routing.
Tests:
- Unit test for the `loaded` signal contract (zero extensions resolves; a late,
slow extension is awaited).
- Playwright acceptance test that deploys an app-entry-point registering an
authProvider after a delay and asserts it is offered on the login screen.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(backoffice): guard the loaded-gate timing for permission loading
Add a test asserting the collection initializer's `loaded` does not open the
gate (`#loadedGuard` awaits it via `.asPromise()`, fronting private-extension
and user-permission loading) until the initially-registered extensions have
instantiated. Addresses the #22522 "user permissions resolved too late" concern
in writing; user-permission condition resolution itself lives in
UmbBaseExtensionInitializer (covered by base-extension-initializer.race.test.ts)
and is untouched by this change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(backoffice): harden loaded signal + narrow acceptance test glob (review)
Address PR review feedback:
- extension-initializer-base: only the latest processing pass settles `loaded`
(monotonic pass id), so a slow earlier pass can't unblock waiters early when
the async observer overlaps passes; and use `Promise.allSettled` so a throwing
`instantiateExtension` can't leave `loaded` stuck at `undefined` (hanging the
boot gate) — failures are logged rather than swallowed.
- playwright.config: narrow the project glob to `**/*.spec.ts` so Playwright
doesn't try to load the App_Plugins `entry-point.js` ESM fixture as a test.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* map settings to become a key-value-object
* implement type safety for block label ufm values
* added TODOs
* support variant value in Block Workspace Label
* External login: wait for app-entry-points before the login provider decision
The backoffice boot stopped waiting for app-entry-point extensions to settle
before deciding which auth provider to use (regression introduced in #22522).
On a slow connection an externally registered authProvider (e.g. Umbraco ID)
is not registered yet when the login screen renders, so the user is dropped on
the local login instead of being redirected to the external provider.
- extension-initializer-base: `loaded` re-arms to `undefined` while a pass is in
flight and resolves to `true` unconditionally (including zero extensions), so
`.asPromise()` gates correctly and never hangs on a default install (which has
no app-entry-points) — the reason the await was removed in the first place.
- app.element: restore the awaited boot gate before routing.
Tests:
- Unit test for the `loaded` signal contract (zero extensions resolves; a late,
slow extension is awaited).
- Playwright acceptance test that deploys an app-entry-point registering an
authProvider after a delay and asserts it is offered on the login screen.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(backoffice): guard the loaded-gate timing for permission loading
Add a test asserting the collection initializer's `loaded` does not open the
gate (`#loadedGuard` awaits it via `.asPromise()`, fronting private-extension
and user-permission loading) until the initially-registered extensions have
instantiated. Addresses the #22522 "user permissions resolved too late" concern
in writing; user-permission condition resolution itself lives in
UmbBaseExtensionInitializer (covered by base-extension-initializer.race.test.ts)
and is untouched by this change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(backoffice): harden loaded signal + narrow acceptance test glob (review)
Address PR review feedback:
- extension-initializer-base: only the latest processing pass settles `loaded`
(monotonic pass id), so a slow earlier pass can't unblock waiters early when
the async observer overlaps passes; and use `Promise.allSettled` so a throwing
`instantiateExtension` can't leave `loaded` stuck at `undefined` (hanging the
boot gate) — failures are logged rather than swallowed.
- playwright.config: narrow the project glob to `**/*.spec.ts` so Playwright
doesn't try to load the App_Plugins `entry-point.js` ESM fixture as a test.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Adds UFM Member Name component
This is to support the standalone Member Picker values.
* fix(ufm): clear stale value on empty member picker; validate UDI-extracted GUIDs
* test(ufm): add umbMemberName parsing tests to marked-ufm.test.ts
Address PR review feedback:
- extension-initializer-base: only the latest processing pass settles `loaded`
(monotonic pass id), so a slow earlier pass can't unblock waiters early when
the async observer overlaps passes; and use `Promise.allSettled` so a throwing
`instantiateExtension` can't leave `loaded` stuck at `undefined` (hanging the
boot gate) — failures are logged rather than swallowed.
- playwright.config: narrow the project glob to `**/*.spec.ts` so Playwright
doesn't try to load the App_Plugins `entry-point.js` ESM fixture as a test.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add a test asserting the collection initializer's `loaded` does not open the
gate (`#loadedGuard` awaits it via `.asPromise()`, fronting private-extension
and user-permission loading) until the initially-registered extensions have
instantiated. Addresses the #22522 "user permissions resolved too late" concern
in writing; user-permission condition resolution itself lives in
UmbBaseExtensionInitializer (covered by base-extension-initializer.race.test.ts)
and is untouched by this change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The backoffice boot stopped waiting for app-entry-point extensions to settle
before deciding which auth provider to use (regression introduced in #22522).
On a slow connection an externally registered authProvider (e.g. Umbraco ID)
is not registered yet when the login screen renders, so the user is dropped on
the local login instead of being redirected to the external provider.
- extension-initializer-base: `loaded` re-arms to `undefined` while a pass is in
flight and resolves to `true` unconditionally (including zero extensions), so
`.asPromise()` gates correctly and never hangs on a default install (which has
no app-entry-points) — the reason the await was removed in the first place.
- app.element: restore the awaited boot gate before routing.
Tests:
- Unit test for the `loaded` signal contract (zero extensions resolves; a late,
slow extension is awaited).
- Playwright acceptance test that deploys an app-entry-point registering an
authProvider after a delay and asserts it is offered on the login screen.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Build: tag prerelease npm publishes with 'next' dist-tag
Prereleases that flow through Deploy_Npm (e.g. 18.0.0-beta1) currently
land on the `latest` dist-tag, so a bare `npm install @umbraco-cms/backoffice`
resolves to an unstable build. Switch to `--tag next` when
NBGV_PrereleaseVersion is non-empty, leaving `latest` for stable releases.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Build: address review feedback on npm prerelease dist-tag
- Add Build to Deploy_Npm dependsOn so stageDependencies.Build.A.outputs
resolves explicitly (mirrors the Upload_API_Docs pattern).
- Pass npmPrereleaseVersion via env: instead of inline macro expansion in
bash, so an unset variable won't be interpreted as command substitution.
* Build: source npmPrereleaseVersion via dependencies, not dependsOn
Switches the variable mapping from stageDependencies (which needs Build
in dependsOn) to dependencies.Build.outputs[...], matching the pattern
the stage's condition already uses on line 941. Avoids drawing a
redundant parallel arrow from Build to Deploy_Npm in the ADO stage
graph — Build is already in the ancestor chain via Deploy_NuGet.
* Build: align Deploy_Npm with Umbraco Deploy publish pattern
- Use stageDependencies form in variables: (dependencies.* only works in conditions).
- Source NBGV_PrereleaseVersionNoLeadingHyphen for a cleaner check.
- Replace echo >> .npmrc with npm config set --location=project.
- Collapse if/else into a tag=latest|next shell variable; single npm publish *.tgz.
- Drop unnecessary env: passthrough and npm init -y.
Per Ronald's feedback on PR #22909 — mirrors the Deploy pipeline's release stage.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
IDomainService.GetAll was removed in #22629; DomainCacheServiceTests was
added later in #23084 against a stale base and still mocked the removed
method, breaking the Release build on release/18.0. Production
DomainCacheService already calls GetAllAsync, so update the four mock
setups to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Build: tag prerelease npm publishes with 'next' dist-tag
Prereleases that flow through Deploy_Npm (e.g. 18.0.0-beta1) currently
land on the `latest` dist-tag, so a bare `npm install @umbraco-cms/backoffice`
resolves to an unstable build. Switch to `--tag next` when
NBGV_PrereleaseVersion is non-empty, leaving `latest` for stable releases.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Build: address review feedback on npm prerelease dist-tag
- Add Build to Deploy_Npm dependsOn so stageDependencies.Build.A.outputs
resolves explicitly (mirrors the Upload_API_Docs pattern).
- Pass npmPrereleaseVersion via env: instead of inline macro expansion in
bash, so an unset variable won't be interpreted as command substitution.
* Build: source npmPrereleaseVersion via dependencies, not dependsOn
Switches the variable mapping from stageDependencies (which needs Build
in dependsOn) to dependencies.Build.outputs[...], matching the pattern
the stage's condition already uses on line 941. Avoids drawing a
redundant parallel arrow from Build to Deploy_Npm in the ADO stage
graph — Build is already in the ancestor chain via Deploy_NuGet.
* Build: align Deploy_Npm with Umbraco Deploy publish pattern
- Use stageDependencies form in variables: (dependencies.* only works in conditions).
- Source NBGV_PrereleaseVersionNoLeadingHyphen for a cleaner check.
- Replace echo >> .npmrc with npm config set --location=project.
- Collapse if/else into a tag=latest|next shell variable; single npm publish *.tgz.
- Drop unnecessary env: passthrough and npm init -y.
Per Ronald's feedback on PR #22909 — mirrors the Deploy pipeline's release stage.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Build: tag prerelease npm publishes with 'next' dist-tag
Prereleases that flow through Deploy_Npm (e.g. 18.0.0-beta1) currently
land on the `latest` dist-tag, so a bare `npm install @umbraco-cms/backoffice`
resolves to an unstable build. Switch to `--tag next` when
NBGV_PrereleaseVersion is non-empty, leaving `latest` for stable releases.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Build: address review feedback on npm prerelease dist-tag
- Add Build to Deploy_Npm dependsOn so stageDependencies.Build.A.outputs
resolves explicitly (mirrors the Upload_API_Docs pattern).
- Pass npmPrereleaseVersion via env: instead of inline macro expansion in
bash, so an unset variable won't be interpreted as command substitution.
* Build: source npmPrereleaseVersion via dependencies, not dependsOn
Switches the variable mapping from stageDependencies (which needs Build
in dependsOn) to dependencies.Build.outputs[...], matching the pattern
the stage's condition already uses on line 941. Avoids drawing a
redundant parallel arrow from Build to Deploy_Npm in the ADO stage
graph — Build is already in the ancestor chain via Deploy_NuGet.
* Build: align Deploy_Npm with Umbraco Deploy publish pattern
- Use stageDependencies form in variables: (dependencies.* only works in conditions).
- Source NBGV_PrereleaseVersionNoLeadingHyphen for a cleaner check.
- Replace echo >> .npmrc with npm config set --location=project.
- Collapse if/else into a tag=latest|next shell variable; single npm publish *.tgz.
- Drop unnecessary env: passthrough and npm init -y.
Per Ronald's feedback on PR #22909 — mirrors the Deploy pipeline's release stage.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Populate the domain cache eagerly during start-up
* Added extension method to encapsulate and test logic for skipping startup seeding.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* update tiptap event listneres
* Tiptap: Add regression test for toolbar button active state on collapsed-cursor toggle (closes#22907)
Tests verify the `transaction` listener wiring that fixes the stored-mark active-state bug.
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* SonarCloud: allow unit test failures without failing the analysis
Test failures should not block SonarCloud analysis - coverage data is
still collected by dotnet-coverage regardless of test outcome. The
regular CI pipeline is the correct gate for test pass/fail.
* SonarCloud: install Java 21 explicitly and skip JRE provisioning
- Add actions/setup-java@v5 (temurin-21) so JAVA_HOME always points to Java 21
- Pass sonar.scanner.skipJreProvisioning=true in the begin command since Java 21 is installed explicitly, removing the need for the scanner to download a JRE at runtime
* SonarCloud: clear SONARQUBE_SCANNER_PARAMS after begin
Prevents the End analysis step from re-applying sonar params that begin already wrote to the analysis config, eliminating the "Ignoring property from env variable" warning.
* SonarCloud: always cancel in-progress runs on new push
* TEMP: add failing test to verify pipeline resilience — revert before merge
* Revert "TEMP: add failing test to verify pipeline resilience — revert before merge"
This reverts commit 828a7510cb.
* Revert "SonarCloud: clear SONARQUBE_SCANNER_PARAMS after begin"
This reverts commit 1911b65db1.
* Make SonarCloud workflow resilient to build and test failures
* Fix inaccurate warning message when unit tests fail
* Revert build step resilience, keep test failure warning
* Improve test failure warning with coverage file check
* Temporary: add failing test to verify SonarCloud workflow resilience
* Revert "Temporary: add failing test to verify SonarCloud workflow resilience"
This reverts commit 71ecd61034.
Backoffice: Move fetchAllPages into the repository module to break a core circular import
#22765 added the offset pagination helper `fetchAllPages` under
`@umbraco-cms/backoffice/utils`, but its contract is expressed entirely in
repository-owned types (`UmbDataSourceResponse<UmbPagedModel<T>>`). That made
`utils` import `repository` while `repository` already imports `utils`,
introducing a 17th core bidirectional module import and tripping
`check:module-dependencies` (threshold 16) — failing the `test` job on every
open PR.
Relocate the helper (and its test) into the `repository` module, which
legitimately owns those types, and export it from
`@umbraco-cms/backoffice/repository`. The sole consumer
(UmbLanguageCollectionRepository) already imports from that module. Core
bidirectional imports are back to 16.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* Recover cache-sync job if database Sync() hangs.
* Apply also to TouchServerJob.
* Addressed code review comments.
* Added debug logging to allow monitorring of job runs.
* Added tests verifying that jobs resume after an inflight call completes.
* Add endpoints for sorting documents and media by system fields.
* Addressed code review feedback.
* Persist sort-children-by-field with a single set-based update.
* Addressed second round of code review feedback.
* DRYed up similar code, improved comments.
* Split tests into individual class files
* Added test for combined sort of invariant and variant children.
* Addressed further code review feedback.
* Include test scenario from #23128 for SortChildren()
* Renamed children authorizer as it is generic, not specific for sorting - and updated XML docs accordingly
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Added api helper for creating element type with compositions
* Added api helper for creating template with displaying element picker
* Added tests for published element extensions
* Make tests run in the pipeline
* Fixed suggestions
* Fixed comment
* Reverted npm command
* Prevent empty domain cache during concurrent initialization.
* Addressed code review comments and added further comment to the code.
* Use Lock object.
* Prevent empty domain cache during concurrent initialization.
* Addressed code review comments and added further comment to the code.
* Use Lock object.
* Ensure all languages are retrieved handling rare (theoretical?) case where the number of languages exceeds the default page size.
* Addressed code review feedback.
* Addressed further code review feedback.
* Add configurable period for scheduled publishing task with optional clock alignment.
* Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Addressed code review comments.
* Clarified the maths, improved comments and test coverage.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Refresh the element container cache on delete to ensure the id/key map is invalidated.
* Rename and additional asserts in test.
* Use a dedicated refresher for element container id/key map eviction
Routing container-delete invalidation through ElementCacheRefresher cleared
the entire elements cache on every payload, so deleting a container triggered
a full clear even though no element data changed (and a second clear on top of
the ElementTreeChangeNotification refresh when the container held elements).
Add a dedicated ElementContainerCacheRefresher whose only job is to evict the
container's IIdKeyMap entry, and route EntityContainerDeletedNotification
through it instead.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Addressed code review feedback.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Added ui helper for does not contain text
* Added constant for cannot be routed in content
* Added ui helper for verify document does not contain link
* Added api helper for unpublish document and publish chain of document
* Added api helper for updating document type
* Added tests for handling broken publish path in backoffice
* Added tests for handling broken publish path in delivery API
* Make tests run in the pipeline
* Clean up
* Fixed comments
* Reverted npm command
* Updated backoffice search element tests to match the test helper changes
* Added step to delete user group before deleting language
* Updated tests for element folder permission due to recent changes
* Fix failing tests for content picker and element with element picker due to UI changes
* Guard read of session ID for log enrichment by presence of session cookie.
* Renamed tests.
* Add configurable option for session ID logging, retaining backward compatibility but giving options to skip session Id logging or use a cookie hash.
* Surface a package migration exception as a boot failure, avoiding being stuck in an upgrading state.
* Addressed code review feedback.
* Fix failing integration tests.
* add allowed type for element picker
* update validation and unit test
* remove redundant code
* update tests name
* revert code GetReferences
* remove un-using code and add more check value
* remove redundant param
* add allowed type for content picker, update validation
* add min max validation into element and its unit test
* update media picker validation
* split validation runner into other class
* update SystemTextJsonSerializerBase back to old code
* update unit tests
* Resolved some code warnings.
* Remove accidentally committed file
* Introduce ITypedValidator and obsolete ITypeJsonValidator to better reflect validators that may or may not contain JSON editor values.
* Extraced ParseAllowedContentTypeKeys into a common helper.
* Aligned parameters on AllowedTypeValidator.
* Align parsing of allowed type Ids on client between document and media pickers.
* Restored validation of media where provided key can't be retrieved.
* Aligned document, media and element configuration labels and weights.
* Added additional unit tests.
* Addressed code review comments.
* Resolved further code warnings and code tidy.
* Resolve potential binary breaking change concern with obsolete ITypedJsonValidator.
* Reuse shared DocumentTypePicker for picker allowed-types config.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Support tree expansion in generic Duplicate To modal
* Add expansion prop to tree picker modal types
* Apply expansion from data to picker context
* move to action: populate tree picker expansion with ancestors
* Pass tree expansion to duplicate document modal
* Extract ancestor fetching into private method
* Use UmbDocumentTreeRepository directly
* Exclude self from ancestor results
* make name more explicit
* Guard ancestor fetch and simplify expansion
* Only set treeExpansion when ancestors exist
* fix type issues
* Parallelize ancestor and pickable filter fetch
* Use getter for treeExpansion; remove unused imports
* Ensure requests to fetch ancestors after retrieving search results are batched to avoid a single query exceeding the maximum URL length.
* Guard against undefined ancestor entries from a failed batch
batchTryExecute resolves each chunk via tryExecute, which never rejects, so
a per-chunk failure comes back as a fulfilled result carrying an error and
leaves an undefined hole in the amalgamated data without surfacing an error.
Detect that before mapping and return an explicit error instead of throwing.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Assert ancestor id uniqueness and silence direct-api lint rule
Strengthen the batching tests to assert every search-result id is requested
exactly once (Set size), not just that the total count matches. Add the
no-direct-api-import disable on the controller's api callback, matching the
existing url data sources, since the call is wrapped by the controller.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Addessed Codescene warnings.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Prevent empty domain cache during concurrent initialization.
* Addressed code review comments and added further comment to the code.
* Use Lock object.
* Include currently missing management API tests in the CI build.
* Fixed failing tests.
* Revert the pipeline updates.
* Addressed code review feedback.
* Delivery API: return inline {} schema for unconstrained property types
ContentTypeSchemaTransformer now checks the raw STJ schema via JsonSchemaExporter before
calling GetOrCreateSchemaAsync. STJ generates boolean true for unconstrained types (JsonNode,
object, types with custom converters), which the pipeline converts to {}. When the raw schema
is true, an inline {} is returned without registering a named component - a named component
adds no value and misleads API consumers into thinking a concrete model shape exists.
* Delivery API: add Plain JSON property to contract test sample types
Adds a Plain JSON property to the sample article page content type used by the OpenAPI contract
tests. This exercises the unconstrained-type fix: the property should appear as inline {} in the
schema, not as a named JsonNode component. Updates the expected contract to reflect the new
property.
* Re-generate typed-schemas-with-sample-types.json
For some reason the previous change got formatted differently, so it was displaying more changes than it should.
* Simplify comments
* Delivery API: guard unconstrained type check with JsonTypeInfoKind.None
* perf(tree): coalesce concurrent identical tree data requests
The tree data request manager hit the network on every call, so multiple
concurrent consumers (sidebar tree, breadcrumb structure, pickers) each
fetched the same data independently — e.g. three identical tree/document/root
requests per document-workspace load.
Apply the existing UmbManagementApiInFlightRequestCache (already used by the
item and detail request managers) to the tree request manager via a shared
static cache, coalescing concurrent identical root/children/ancestors/siblings
calls into a single in-flight request, cleared on settle (in-flight only, so
no stale-cache risk). The document tree opts in; other trees are unchanged
until they pass a cache.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(tree): cover request coalescing; address review feedback
- Add focused tests: concurrent identical root requests share one call,
the in-flight entry is cleared on settle, and no cache means no coalescing.
- Build the cache key lazily (only when a cache is wired) so non-opted-in
trees keep the original lightweight path.
- Constrain the #coalesce generic to drop the cast on cache.set.
- Document the new inflightRequestCache arg; trim the comment to one line.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Tolerate invalid data type configuration when getting the editor value storage type.
* Add logging in case of error.
* Resolve warning.
* Removed exception from warning (it's not useful).
* Log an error instead of a warning.
* Menu Structure: Guard against use-after-destroy in async structure request
When navigating to a trashed item, the IS_NOT_TRASHED condition initially
permits the standard menu structure context, which is then destroyed once the
workspace confirms the item is trashed. The in-flight async #requestStructure()
could resume after destruction and call setValue() on a completed subject,
throwing "_subject is undefined".
Guard the state mutations with the framework's existing _host-cleared-on-destroy
signal, and handle the previously fire-and-forget #requestStructure() promises so
a teardown mid-request is silently abandoned rather than surfacing as an uncaught
rejection. Applied to both the variant and non-variant menu structure base
contexts.
* Menu Structure: Make #requestStructure non-throwing instead of catching at call sites
Per PR review feedback: replace the blanket .catch(() => {}) wrappers with
early returns inside #requestStructure(). The _host guard already prevents
post-destroy state mutation; the throws only fire for can't-happen missing
observable states and were producing unhandled rejections with no caller
able to act on them.
* Added console warning, if the host is still available
* Block Grid: Guard validator against torn-down manager on navigation
The form-control mixin's updated() hook runs validators when the element
re-renders during teardown. If navigation has already disposed _manager,
checkBlockTypeConfigurationValidity would throw "Cannot read properties
of undefined (reading 'getContentTypeKeyOfContentKey')".
Early-return as valid when the manager is gone and use optional chaining
on the per-entry lookup as a safety net.
* Removed optional chaining of `_manager`
As `_manager` has already been checked.
* Reverting the `_manager` optional chaining
As TypeScript compiler doesn't like it, (inside the `filter` callback).
* Update uploaded media file name to a friendly name.
* Correct test description for acronym handling.
The case JUST-A-FILE.jpg verifies all-uppercase words are preserved
as acronyms, not that lowercase words get lowercased.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* Match server-side StripFileExtension semantics in toFriendlyName.
The TypeScript helper previously delegated to getFileExtension, which
diverges from the C# StripFileExtension on two edge cases:
- a trailing dot ("file.") is stripped by the server but not the client
- an "extension" containing whitespace is preserved by the server but
stripped by the client
Inlined a stripFileExtension helper that mirrors the C# rules exactly,
making the "keep in sync" cross-reference accurate. Added tests for both
divergent cases and replaced the contrived leading/trailing whitespace
test with a realistic interior-whitespace case.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* Add parity test for trailing-whitespace extension span.
Restores the ' spaced-name.jpg ' case as a parity test against
StripFileExtension's "extension containing whitespace is preserved"
rule. Output is 'Spaced Name.Jpg' (Jpg title-cased, matching the
server's TextInfo.ToTitleCase behaviour on the now-unstripped extension).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* Handle getContext rejection in ensureMediaNameFromFile.
getContext rejects on timeout when the dataset context never resolves;
callers used void ensureMediaNameFromFile(...) so an unhandled rejection
would bubble. Catch the rejection and treat it as an absent context.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Disable OpenAPI XML documentation source generator
Due to the amount of XML documentation in this solution, the OpenAPI XML documentation source generator produces too many lines of code in a single method (GenerateCacheEntries), which causes a StackOverflowException when running on IIS. The fix disables the analyzer globally via Directory.Build.props.
* Creating notification objects and status
* Adjusting service and tracker to support cancelable notifications
* Adding Operation Status Results to base controller.
* Adding notification support to the delete controller.
* Integration tests
* Changes in accordance to CR
* Changes in accordance to code review
* Fixed further use of obsolete methods in tests.
* Added comment explaining why messages on create or update cancellation are suppressed.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added constant setting for element folder permission
* Added api helper for element folder
* Added api helper for user group with element folder permission
* Added ui helper for element folder permission in user group
* Added tests for element folder permission
* Added locator for restore element
* Added api helper for Combined element + element folder permission methods
* Added more tests for restore element folder
* Make tests run in the pipeline
* Fixed comments
* Reverted npm command
* Updated createEmptyElementType
* Updated tests due to test helper changes
* Added ui helper for not applicable message for element type
* Added tests for showing message for non-applicable Element Type settings
* Added tests for preventing disabling isElement when elements of that type exist
* Make tests run in the pipeline
* Fixed comments
* Update tests/Umbraco.Tests.AcceptanceTest/tests/DefaultConfig/Settings/DocumentType/DocumentTypeSettingsTab.spec.ts
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Reverted npm command
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Adds conditions to Document Recycle Bin
that the user must have "Read" permission.
* Directly imports Media Recycle Bin condition
this will remove an extra fetch request.
* Add SonarCloud CI workflow
Adds a manual-dispatch GitHub Actions workflow for SonarQube Cloud
analysis (build, unit test coverage, scan). Moves file_header_template
and SA1636/SA1633 suppression from .editorconfig comments and
.globalconfig into the active .editorconfig .NET language conventions
section, removing the duplicated suppression from .globalconfig.
* Remove branch filter from pull_request trigger in SonarCloud workflow
Runs analysis on all PRs regardless of target branch.
* Adjust sonarcloud gh action based on feedback
* Add .sonarqube to .gitignore
* Attempt to split build and analysis in order to be able to run in PRs from forks
* Adjust SonarCloud workflows
* Rename SonarCloud workflows to reflect their actual purpose
* Remove sonar.coverage.exclusions
* Include .github in sonar analysis
* Include build directory in sonar analysis
* Apply sonarcloud workflow fixes from test branch
* Remove setup-dotnet step from upload workflow
* Use default branch from context instead of hardcoded main in analysis workflow
* Update checkout action to v6 in upload workflow
* Add actions: read permission to upload workflow
* Enable SCM integration in upload workflow
* Improve cohost polyfill
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Move <target/> part of the polyfill to targets file.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Improve cohost polyfill
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Move <target/> part of the polyfill to targets file.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Improve cohost polyfill
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Move <target/> part of the polyfill to targets file.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added tests
* Cleaned up
* Updated command
* Fixes based on comments
* Split tests
* Updated helpers
* Fixed constant helper after merge
* Use correct helper
* Added constant for element search
* Added ui helper for element backoffice search
* Added tests for element backoffice search
* Updated tests for finding element by name
* Apply suggestion from @andr317c
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Cleaned up
* Reverted npm command
* Fixed npm command
---------
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Backoffice: Strip inherited class comments from TypeDoc API docs
TypeDoc copies the nearest documented ancestor's class comment onto every
undocumented subclass, which meant every UmbLitElement descendant on
apidocs.umbraco.com showed "The base class for all Umbraco LitElement
elements." as its own description. This plugin clears class-level
comments whose sourcePath doesn't match the reflection's own file, so
classes with no JSDoc render blank instead of borrowing the base's text.
Inherited member comments (methods, properties) are left alone.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* Backoffice: Address review comments on TypeDoc strip-inherited plugin
Drop the misleading "strip trailing line/column" sentence — nothing actually
strips, and a future TypeDoc release that appends positions to sourcePath
would now self-document its breakage instead of being hidden by a comment.
Document the sources[0]-only limitation around declaration merging in the
docblock so the constraint is visible to future maintainers.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
* Clear user and user group start nodes when deleting an element container.
* Assert user start node references cleared after container delete
Mirrors the post-delete assertion already present in the user group
sibling test so both tests confirm the reference was cleaned up, not
just that no FK exception was thrown.
* Guard against null entity in PersistDeletedItem override
Mirrors the ArgumentNullException guard in the base
EntityContainerRepository.PersistDeletedItem so a null argument throws
the same exception type.
* perf(core): parallelize independent boot API requests
UmbServerConnection.connect() awaited server status and configuration
sequentially even though they are independent reads; run them with
Promise.allSettled so both errors surface (the app cannot function
without either) while saving a round-trip.
During app startup, public (login) extension registration was awaited
before the auth flow; kick it off in parallel and await it only before
routing, where the login screen actually needs it.
Each serialized call costs a full management-API round-trip, which is
negligible locally but ~150 ms each on high-latency (e.g. Cloud) hosts.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(core): only mark connection connected once both calls succeed
Move isConnected.setValue(true) out of #setStatus() into connect() after
the allSettled check, so the observable never reflects a partially
established connection when configuration fails but status succeeded.
Addresses review feedback on the parallelized connect().
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: removes @hey-api/openapi-ts from the login project
this is an ongoing project to be able to finally merge 'login' into 'client'
* docs(login): update CLAUDE.md to reflect removal of @hey-api/openapi-ts
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Entity refs render readonly when their workspace URL can't be resolved.
Also fixes name on remove dialog.
* Apply read-only on the picked content ref only in the non-routable link picker
* Address PR feedback: simplify document item resolver guard in the link picker, document the implicit uui-card-media disabled dependency in input-media, and cover the disabled card state with a test.
* Drop out of date comments.
* Simplify updates.
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Render $index in block detail overlay label.
* Cache $index, resolve append sentinel, and cover with unit tests.
* refactor(block): use pipeline for index deduplication and clean up stale observer
* Rename function to remove the unnecessary umb prefix.
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Show the edit permissions for document type button only for users with settings access.
* Fix translation for message (the "Permissions" tab is not called "Structure").
* Addressed code review feedback.
* Suppress CS0618 obsolete API warnings in Umbraco.Examine.Lucene
Each obsolete API in this project cannot be migrated to its
non-obsolete replacement without either a breaking public API
change or a change in runtime behaviour:
- LuceneIndex.CommitCount: obsolete with no replacement; retained
in diagnostics metadata to preserve existing output
- IHostingEnvironment.MapPathContentRoot: the IHostEnvironment
extension replacement resolves a different environment
abstraction
- FileSystemDirectoryFactory base constructor: the non-obsolete
overload alters Lucene directory configuration behaviour
Each warning is suppressed locally with an explanatory comment
rather than changed, preserving existing behaviour.
Fixes#15015
* Tightened up comments. Added obsoletion version on unversioned attributes.
Removed warning supressions and fixed constructors.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
`core/manifests.ts` already imports and spreads `core/search/manifests.ts`
into its aggregate (line 23 + 58), so importing `searchManifests`
separately in `.storybook/preview.js` and spreading it next to
`coreManifests` registered the same manifests twice. Remove the redundant
import and spread.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
PR #22957 deleted every package's `manifests.ts` and consolidated the
exports into `umbraco-package.ts`, but `.storybook/preview.js` still
imported from the old paths. The result was a Vite resolve error during
`npm run build-storybook` (first failure: "Could not resolve
../src/packages/block/manifests from .storybook/preview.js").
37 import paths swapped from `…/<pkg>/manifests` to
`…/<pkg>/umbraco-package`. The two packages that still expose their
manifests via a standalone `manifests.ts` — `core` and `core/search` —
are left untouched.
Verified by `npm run build-storybook` — succeeds.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
PR #22995 added `input-tiptap.stories.ts` with an import from
`'../../manifests.js'`, but PR #22957 (already on release/17.5.0) had
deleted that file and moved the `manifests` array into
`umbraco-package.ts`. The merge into release/17.5.0 didn't catch the dead
import, so Storybook 404s on the story load.
Point the import at the new home — `manifests` is still exported by name,
so this is a one-line path fix.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
`core/manifests.ts` already imports and spreads `core/search/manifests.ts`
into its aggregate (line 23 + 58), so importing `searchManifests`
separately in `.storybook/preview.js` and spreading it next to
`coreManifests` registered the same manifests twice. Remove the redundant
import and spread.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
PR #22957 deleted every package's `manifests.ts` and consolidated the
exports into `umbraco-package.ts`, but `.storybook/preview.js` still
imported from the old paths. The result was a Vite resolve error during
`npm run build-storybook` (first failure: "Could not resolve
../src/packages/block/manifests from .storybook/preview.js").
37 import paths swapped from `…/<pkg>/manifests` to
`…/<pkg>/umbraco-package`. The two packages that still expose their
manifests via a standalone `manifests.ts` — `core` and `core/search` —
are left untouched.
Verified by `npm run build-storybook` — succeeds.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
PR #22995 added `input-tiptap.stories.ts` with an import from
`'../../manifests.js'`, but PR #22957 (already on release/17.5.0) had
deleted that file and moved the `manifests` array into
`umbraco-package.ts`. The merge into release/17.5.0 didn't catch the dead
import, so Storybook 404s on the story load.
Point the import at the new home — `manifests` is still exported by name,
so this is a one-line path fix.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Tiptap: Load enabled extensions in parallel and inline manifest APIs
Replace the for…of/await loop in umb-input-tiptap's #loadExtensions with
Promise.all over .map, so all enabled Tiptap extension APIs are fetched
in parallel. Configured-extension order in _extensions is preserved.
Inline the first-party Tiptap manifest API references: every
`api: () => import('./X.tiptap-api.js')` and the equivalent toolbar /
statusbar / kind references now use a static top-of-file import and
`api: ClassName`. The dynamic `await import('rich-text-essentials.tiptap-api.js')`
fallback in input-tiptap.element.ts is inlined for the same reason.
External (plugin-supplied) Tiptap extensions and the lazy modal/toolbar
UI element imports are unchanged.
Why: on Umbraco Cloud, opening a document workspace with a rich text
editor takes ~16 s uncached, of which ~14.6 s is a single serial
waterfall — 31 extension APIs fetched one after the other from a
for…of await loop, ~170 ms RTT stacked. Replacing the loop with
Promise.all collapses that to roughly one round-trip; eagerly bundling
the first-party manifests removes the dynamic chunk explosion that made
the waterfall so long in the first place. The toolbar APIs (~20 of them)
already load in a sub-100 ms parallel burst against the same server,
confirming HTTP/2 multiplexing handles bulk parallel requests fine.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Tiptap: Inline element references for toolbar/statusbar/modal/clipboard manifests
Extends the manifest-inlining pass to the remaining `element: () => import(...)`
and runtime API loader sites in the Tiptap package — toolbar/menu/action-button
kinds, the table & character-map & anchor modals, the colour-picker button, the
property-editor configuration UIs, both clipboard translators, the style-menu
kind, and the default toolbar API fallback in tiptap-toolbar.element.ts.
Result on the same Cloud test site (uncached, 17.5-rc):
Tiptap chunk count: 71 → 4
Total tiptap bytes: ~3.2 MB → ~3.1 MB (essentially unchanged)
Phase 5 of the load — the serial extension chain — collapses to a single
consolidated chunk fetch.
`input-tiptap.element.ts` and `property-editor-ui-tiptap.element.ts` are
intentionally not inlined into anything else: `<umb-input-tiptap>` is a public
element usable standalone (custom dashboards, workspace views), and the
property-editor shell loads via the property-editor UI loader. They remain
exported as their own modules.
CLAUDE.md updated to document the new convention for first-party Tiptap
extensions (direct class refs) and the carve-out for external plugin
extensions that may keep `() => import(...)` to ship their API code in a
separate chunk.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Tiptap: Move extension APIs and elements into a shared lazy boundary chunk
The previous PR collapsed ~70 Tiptap chunks into 3 by inlining first-party API
and element references directly into manifest files. That win came with a real
downside flagged in code review (lke / mra): the API/element implementation
bytes ended up in the manifest registration bundle, so every workspace —
including ones without an RTE — paid ~700 KB of Tiptap code on boot.
This commit keeps the chunk-coalescing win but restores the lazy boundary by
routing every first-party manifest's `api` / `element` reference through a
single shared bundle file `extensions/extension-apis.bundle.ts`. Each manifest
holds a dynamic-import thunk pointing at that one bundle, so:
- Rollup still emits a single chunk for all Tiptap extension code (no chunk
explosion).
- The manifest registration bundle stays slim — it carries only metadata
(alias / label / icon / group / kind / forExtensions) plus the thunks.
- The bundle is only fetched the first time `<umb-input-tiptap>` actually
mounts.
Data-type configuration UIs (`extensions-configuration`,
`toolbar-configuration`, `statusbar-configuration`) read manifest metadata
via `umbExtensionsRegistry.byType(...)` only — they never call
`loadManifestApi` / `loadManifestElement`, so the data-type editor continues
to work without loading any Tiptap implementation code.
Property-editor UI elements (`tiptap-rte`, the three configuration UIs) also
revert to `() => import('./X.element.js')` so each loads on demand from its
own chunk rather than being inlined into the manifest bundle.
`umb-input-tiptap` no longer statically imports the Rich Text Essentials API;
it prepends the alias to the observed list instead, so essentials resolves
through the same lazy bundle as every other extension.
Added a test and stories file that mount `<umb-input-tiptap>` standalone (no
property-editor wrapper) to make the public usage pattern explicit.
Built and verified via `npm run build:for:cms`:
- `dist-cms/packages/tiptap/manifests.js` 48 KB (eager at boot)
- `dist-cms/packages/tiptap/extension-apis.bundle-*.js` 84 KB (lazy)
- `dist-cms/packages/tiptap/tiptap-toolbar-element-api-base-*.js` 654 KB
(lazy dependency of the bundle)
- per-element property-editor UI chunks load on demand when settings open
`npm run check:circular`, `npm run compile`, `npx wtr src/packages/tiptap`
all pass.
Related to #21152, builds on #22995.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Tiptap: Don't mount <umb-input-tiptap> in the standalone test
Mounting the element via fixture() spins up an UmbTiptapRteContext that
consumes UMB_SERVER_CONTEXT. In the unit-test runtime no server context
provider exists, so the context request stays pending. When @open-wc's
fixture tears down at end-of-file the request rejects with
"host disconnected" — surfaced as an unhandled promise rejection that
web-test-runner counts as a fatal runner error, exiting 1 even though every
individual test passed. The rejection happened to be in flight while a
block-grid clipboard test was active in CI, which is why the failure surfaced
there rather than in the tiptap test file itself.
Drop the manifest-registration assertion too — pulling the package-level
`manifests.ts` aggregator triggers a transitive 404 on the
`@umbraco-cms/backoffice/tiptap` importmap entry in the wtr environment.
The class-export + custom-element-registration checks are enough to prove
standalone exportability. The Storybook stories still cover the visual
end-to-end load path.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Display variant node name on sort children dialog.
* Preserve user sort order when patching variant names on culture change
Patch names in-place on the existing _tableItems rather than rebuilding
from _children, so a user's drag-sorted or column-ordered arrangement is
not silently reverted if the app culture changes while the modal is open.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Refactor to reduce cyclomatic complexity of #resolveName method.
* Resolve sort dialog variant names and icons via item data resolvers
Replace the inlined variant-name logic in the content sort dialog with the
shared UmbItemDataResolver abstraction, and add UmbMediaItemDataResolver so
media items resolve their active-culture name and icon the same way documents
do. Each content sort entity action now supplies its resolver through manifest
meta, flowing into the modal via a new content-specific modal data type and a
base-action _getModalData() hook. This also removes the previously hard-coded
document icon in the dialog.
* Disable load more when page of items is being retrieved.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Fix migration of embedded block data when blocks are direct siblings in the 13 RTE source code.
* Apply suggestions from code review to update comments.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Address review: keep RteBlockHelper in original namespace; tidy docs and comment
- Move RteBlockHelper back to Umbraco.Cms.Infrastructure.Migrations.Upgrade.V_15_0_0.LocalLinks
to avoid a binary breaking change within the obsolete window (scheduled removal in v18).
Kept as its own file rather than reverting it into LocalLinkRteProcessor.cs.
- Add a <remarks> note on ConvertBlockUdisToKeys explaining that blocks with malformed UDIs
are dropped rather than preserved.
- Replace the opaque "fix recursive hiccup" comment in LocalLinkRteProcessor with one that
describes what the line actually does.
- Move RteBlockHelperTests back to mirror the production namespace.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Fix migration of embedded block data when blocks are direct siblings in the 13 RTE source code.
* Apply suggestions from code review to update comments.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Address review: keep RteBlockHelper in original namespace; tidy docs and comment
- Move RteBlockHelper back to Umbraco.Cms.Infrastructure.Migrations.Upgrade.V_15_0_0.LocalLinks
to avoid a binary breaking change within the obsolete window (scheduled removal in v18).
Kept as its own file rather than reverting it into LocalLinkRteProcessor.cs.
- Add a <remarks> note on ConvertBlockUdisToKeys explaining that blocks with malformed UDIs
are dropped rather than preserved.
- Replace the opaque "fix recursive hiccup" comment in LocalLinkRteProcessor with one that
describes what the line actually does.
- Move RteBlockHelperTests back to mirror the production namespace.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Batch WHERE IN queries to avoid SQL Server 2100-parameter limit and add memory files.
* Drop past-incident references from SQL parameter-limit docs
The memory files should describe the current rule and safe patterns;
specific historical bugs belong in commit history, not CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Update comments from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Addressed memory file feedback.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Tiptap: Load enabled extensions in parallel and inline manifest APIs
Replace the for…of/await loop in umb-input-tiptap's #loadExtensions with
Promise.all over .map, so all enabled Tiptap extension APIs are fetched
in parallel. Configured-extension order in _extensions is preserved.
Inline the first-party Tiptap manifest API references: every
`api: () => import('./X.tiptap-api.js')` and the equivalent toolbar /
statusbar / kind references now use a static top-of-file import and
`api: ClassName`. The dynamic `await import('rich-text-essentials.tiptap-api.js')`
fallback in input-tiptap.element.ts is inlined for the same reason.
External (plugin-supplied) Tiptap extensions and the lazy modal/toolbar
UI element imports are unchanged.
Why: on Umbraco Cloud, opening a document workspace with a rich text
editor takes ~16 s uncached, of which ~14.6 s is a single serial
waterfall — 31 extension APIs fetched one after the other from a
for…of await loop, ~170 ms RTT stacked. Replacing the loop with
Promise.all collapses that to roughly one round-trip; eagerly bundling
the first-party manifests removes the dynamic chunk explosion that made
the waterfall so long in the first place. The toolbar APIs (~20 of them)
already load in a sub-100 ms parallel burst against the same server,
confirming HTTP/2 multiplexing handles bulk parallel requests fine.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Tiptap: Inline element references for toolbar/statusbar/modal/clipboard manifests
Extends the manifest-inlining pass to the remaining `element: () => import(...)`
and runtime API loader sites in the Tiptap package — toolbar/menu/action-button
kinds, the table & character-map & anchor modals, the colour-picker button, the
property-editor configuration UIs, both clipboard translators, the style-menu
kind, and the default toolbar API fallback in tiptap-toolbar.element.ts.
Result on the same Cloud test site (uncached, 17.5-rc):
Tiptap chunk count: 71 → 4
Total tiptap bytes: ~3.2 MB → ~3.1 MB (essentially unchanged)
Phase 5 of the load — the serial extension chain — collapses to a single
consolidated chunk fetch.
`input-tiptap.element.ts` and `property-editor-ui-tiptap.element.ts` are
intentionally not inlined into anything else: `<umb-input-tiptap>` is a public
element usable standalone (custom dashboards, workspace views), and the
property-editor shell loads via the property-editor UI loader. They remain
exported as their own modules.
CLAUDE.md updated to document the new convention for first-party Tiptap
extensions (direct class refs) and the carve-out for external plugin
extensions that may keep `() => import(...)` to ship their API code in a
separate chunk.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Tiptap: Move extension APIs and elements into a shared lazy boundary chunk
The previous PR collapsed ~70 Tiptap chunks into 3 by inlining first-party API
and element references directly into manifest files. That win came with a real
downside flagged in code review (lke / mra): the API/element implementation
bytes ended up in the manifest registration bundle, so every workspace —
including ones without an RTE — paid ~700 KB of Tiptap code on boot.
This commit keeps the chunk-coalescing win but restores the lazy boundary by
routing every first-party manifest's `api` / `element` reference through a
single shared bundle file `extensions/extension-apis.bundle.ts`. Each manifest
holds a dynamic-import thunk pointing at that one bundle, so:
- Rollup still emits a single chunk for all Tiptap extension code (no chunk
explosion).
- The manifest registration bundle stays slim — it carries only metadata
(alias / label / icon / group / kind / forExtensions) plus the thunks.
- The bundle is only fetched the first time `<umb-input-tiptap>` actually
mounts.
Data-type configuration UIs (`extensions-configuration`,
`toolbar-configuration`, `statusbar-configuration`) read manifest metadata
via `umbExtensionsRegistry.byType(...)` only — they never call
`loadManifestApi` / `loadManifestElement`, so the data-type editor continues
to work without loading any Tiptap implementation code.
Property-editor UI elements (`tiptap-rte`, the three configuration UIs) also
revert to `() => import('./X.element.js')` so each loads on demand from its
own chunk rather than being inlined into the manifest bundle.
`umb-input-tiptap` no longer statically imports the Rich Text Essentials API;
it prepends the alias to the observed list instead, so essentials resolves
through the same lazy bundle as every other extension.
Added a test and stories file that mount `<umb-input-tiptap>` standalone (no
property-editor wrapper) to make the public usage pattern explicit.
Built and verified via `npm run build:for:cms`:
- `dist-cms/packages/tiptap/manifests.js` 48 KB (eager at boot)
- `dist-cms/packages/tiptap/extension-apis.bundle-*.js` 84 KB (lazy)
- `dist-cms/packages/tiptap/tiptap-toolbar-element-api-base-*.js` 654 KB
(lazy dependency of the bundle)
- per-element property-editor UI chunks load on demand when settings open
`npm run check:circular`, `npm run compile`, `npx wtr src/packages/tiptap`
all pass.
Related to #21152, builds on #22995.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Tiptap: Don't mount <umb-input-tiptap> in the standalone test
Mounting the element via fixture() spins up an UmbTiptapRteContext that
consumes UMB_SERVER_CONTEXT. In the unit-test runtime no server context
provider exists, so the context request stays pending. When @open-wc's
fixture tears down at end-of-file the request rejects with
"host disconnected" — surfaced as an unhandled promise rejection that
web-test-runner counts as a fatal runner error, exiting 1 even though every
individual test passed. The rejection happened to be in flight while a
block-grid clipboard test was active in CI, which is why the failure surfaced
there rather than in the tiptap test file itself.
Drop the manifest-registration assertion too — pulling the package-level
`manifests.ts` aggregator triggers a transitive 404 on the
`@umbraco-cms/backoffice/tiptap` importmap entry in the wtr environment.
The class-export + custom-element-registration checks are enough to prove
standalone exportability. The Storybook stories still cover the visual
end-to-end load path.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Use direct imports in core manifests
* Extract theme aliases into constants file
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Use direct imports in core manifests
* Extract theme aliases into constants file
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Backoffice: Add Cache-Control headers to cache-busted backoffice assets (AB#68478)
Adds a UseUmbracoBackOfficeCacheHeaders middleware that sets
Cache-Control: public, max-age=31536000, immutable on responses served
from the cache-busted backoffice path (/umbraco/backoffice/<hash>/*).
The hash in the URL is derived from the Umbraco version, so the URL
itself invalidates on every release - making 'immutable' safe regardless
of whether individual filenames contain a content hash.
In debug mode the cache-bust hash changes per request, so the header is
set to 'no-cache' to avoid filling the browser disk cache with single-use
entries.
Design is non-destructive to consumer customisation, addressing the
review feedback on the v14 attempt (#14475):
- Does not touch StaticFileOptions; consumer
services.Configure<StaticFileOptions>(...) and OnPrepareResponse
callbacks continue to work unchanged.
- Sets the header via Response.OnStarting with a ContainsKey guard, so
any synchronous Cache-Control set upstream wins; consumer OnStarting
callbacks registered later fire first (LIFO) and also win.
- Skips non-2xx responses to avoid long-lived caching of error responses.
Related: GH #21152, PR #22896.
* Backoffice: Correct rationale for no-cache in debug mode
Reword the XML doc on UseUmbracoBackOfficeCacheHeaders to reflect that
IBackOfficePathGenerator is a singleton, so the cache-bust hash is
computed once at startup even in debug mode (per Copilot review on
#22951). The reason for no-cache is not "hash changes per request" but
that built assets may change in place during dev iteration; no-cache
allows fast 304 revalidation while no-store would force full
re-downloads.
No functional change.
* Backoffice: Add unit tests for UseUmbracoBackOfficeCacheHeaders
Covers six scenarios via a minimal in-process pipeline composed with
Microsoft.AspNetCore.TestHost:
- Production: 200 under hash prefix gets immutable header
- Debug: 200 under hash prefix gets no-cache
- Non-2xx under prefix: header not set (status gate)
- Path outside prefix: header not set (path gate)
- Consumer synchronous override: ContainsKey guard skips, consumer wins
- Consumer OnStarting override: LIFO ordering lets consumer win
Adds Microsoft.AspNetCore.TestHost to Umbraco.Tests.UnitTests (standard
Microsoft package, version pinned in tests/Directory.Packages.props).
* Backoffice: Extract cache-headers logic into IMiddleware class
Matches the existing Umbraco middleware convention (BootFailedMiddleware,
PreviewAuthenticationMiddleware, UmbracoRequestMiddleware, etc.) per
Kenn's note: prefer UseMiddleware<T>() with a DI-resolved class over
inline builder.Use lambdas.
The new UmbracoBackOfficeCacheHeadersMiddleware:
- Implements IMiddleware; registered as a singleton in AddWebComponents
- Computes prefix and header value once in the constructor (both
dependencies are singletons themselves, so this is stable)
- Behaviour is unchanged from the inline version
The UseUmbracoBackOfficeCacheHeaders extension method becomes a thin
UseMiddleware<T>() wrapper. Tests updated to register the middleware in
the TestServer DI container so it can be resolved through UseMiddleware.
* Backoffice: Document IMiddleware convention in Web.Common CLAUDE.md
Adds an explicit "Convention" note before the middleware list so future
contributors (and AI assistants) default to the IMiddleware class +
AddSingleton + UseMiddleware<T>() pattern rather than inline
builder.Use(async ...) lambdas. Also lists the new
UmbracoBackOfficeCacheHeadersMiddleware in the folder structure and
middleware reference.
* Backoffice: Tighten middleware convention note with full corroboration
Lists every IMiddleware implementer in the codebase (10/10) and calls
out the two known inline-lambda exceptions (CspNonceExtensions,
WebApplicationExtensions) so the rule reads as the established
convention rather than an absolute, while still steering new work
toward IMiddleware + AddSingleton + UseMiddleware<T>().
* Backoffice: Register cache-headers middleware in AddBackOfficeCore
DI scope validation runs in Development/CI and pre-checks every
singleton's dependency graph can be constructed. The middleware was
registered in AddWebComponents (which runs for every Umbraco bootstrap),
but its IBackOfficePathGenerator dependency is only registered by
AddBackOffice(). The previous CI run on this branch surfaced the
problem in four Delivery-only/Website-only bootstrap tests
(CoreWithDeliveryApi_BootsSuccessfully, DeliveryOnlyScenario_BootsSuccessfully,
etc.) with "Unable to resolve service for type 'IBackOfficePathGenerator'
while attempting to activate 'UmbracoBackOfficeCacheHeadersMiddleware'".
Move the registration alongside IBackOfficePathGenerator in
AddBackOfficeCore (Api.Management), which is the same scope as the
backoffice itself. This also matches the wire-up gate in
UmbracoApplicationBuilder.cs that only calls UseUmbracoBackOfficeCacheHeaders
when IBackOfficeEnabledMarker is registered.
CLAUDE.md updated with the rule ("register the middleware next to its
dependencies' registration") and a pitfall note about DI scope validation.
* Backoffice: Address review feedback from AndyButland (PR #22951)
- Move UseUmbracoBackOfficeCacheHeadersTests from Umbraco.Tests.UnitTests
to Umbraco.Tests.Integration. It uses HostBuilder + TestServer to
exercise the real HTTP pipeline, which is integration-shaped rather
than unit-shaped. Drop Microsoft.AspNetCore.TestHost from UnitTests
(Mvc.Testing in Integration provides it transitively) and from
tests/Directory.Packages.props.
- Soften the misleading "no trailing slash" comment in
UmbracoBackOfficeCacheHeadersMiddleware — we trim anyway, so the
comment is now framed as defensive normalisation.
- Trim the dense middleware convention note in Web.Common/CLAUDE.md to
one paragraph (rule + the two known inline-lambda exceptions). Move
the DI-scope-validation pitfall narrative out of CLAUDE.md and into a
three-line code comment next to the AddSingleton call in
AddBackOfficeCore where it actually applies.
* Backoffice: HTTP verb gate, 304 inclusion, namespace + unused using (PR #22951 review)
Three more from AndyButland's review:
1. Verb gate + 304 inclusion in UmbracoBackOfficeCacheHeadersMiddleware.
Restrict the path-prefix match to GET and HEAD so POST/PUT/DELETE
responses and OPTIONS (CORS preflight) responses don't get tagged as
immutable. Include 304 alongside 2xx in the status gate so
intermediate caches (CDN/proxy) receive the Cache-Control directive on
revalidation responses too. Extended the test suite with four new
cases: NotModifiedResponseUnderPrefix_SetsImmutable,
HeadRequestUnderPrefix_SetsImmutable,
OptionsRequestUnderPrefix_DoesNotSetHeader,
PostRequestUnderPrefix_DoesNotSetHeader. All 10 tests pass.
2. Test namespace updated to Umbraco.Cms.Tests.Integration.* to match
the convention used by ~629 other files in Umbraco.Tests.Integration
(vs the 2 outliers I copied from).
3. Drop unused 'using Umbraco.Extensions;' from the test file.
* Backoffice: Extract conditional checks to satisfy CodeScene complexity gate
CodeScene flagged InvokeAsync with "Complex Conditional" (advisory rule,
code health impact 9.69) after the verb + 304 additions in the prior
commit. Extract the two checks into IsCacheableAssetRequest and
ShouldSetCacheControl helper methods. No behaviour change; tests still
green (10/10, 149 ms).
* Stabilise rollback E2E test by waiting for document reload before asserting.
* Condense rollback wait comment per code-review feedback.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Addressed code review feedback.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* ensure the order from the search endpoints taking a collection of keys is preserved
* Align cosmetic changes to ensure later merge up doesn't run into conflicts.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Use direct imports in core manifests
* Extract theme aliases into constants file
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* update order search result for element, member type, dictionary...
* undo dictionary search API
* reorder search value
* Apply OrderByRequestedIds
* add unit tests for search order
* Reverted unnecessarily changed files, minor test clean-up, aligned controllers for XML docs.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add IgnoredDelayChanged event to allow updates during back-off
* Make Period and IgnoredDelay settable on RecurringBackgroundJobBase with auto-raising events
* Address PR review: handle CTS race, restore negative-IgnoredDelay guard, clarify setter remarks
- Swallow ObjectDisposedException in OnIgnoredDelayChanged for the shutdown race where an in-flight handler reads the to-be-disposed CTS via Interlocked.Exchange before Dispose disposes it.
- Restore "skip back-off when IgnoredDelay <= TimeSpan.Zero (and not Timeout.InfiniteTimeSpan)" guard in IgnoreAndWaitAsync to defend against direct IRecurringBackgroundJob implementations / property overrides returning a negative value that would otherwise tight-loop via ComputeNextDelay clamping to zero.
- Add regression test for the negative-IgnoredDelay skip path.
- Mirror the constructor "stored without raising" remark on the Period and IgnoredDelay setter doc comments.
* Dispose newly-installed CTS when shutdown race wins the rotate-and-cancel
* Clarify XML docs.
* Introduce helper for cancellation source rotate and cancel.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add IgnoredDelayChanged event to allow updates during back-off
* Make Period and IgnoredDelay settable on RecurringBackgroundJobBase with auto-raising events
* Address PR review: handle CTS race, restore negative-IgnoredDelay guard, clarify setter remarks
- Swallow ObjectDisposedException in OnIgnoredDelayChanged for the shutdown race where an in-flight handler reads the to-be-disposed CTS via Interlocked.Exchange before Dispose disposes it.
- Restore "skip back-off when IgnoredDelay <= TimeSpan.Zero (and not Timeout.InfiniteTimeSpan)" guard in IgnoreAndWaitAsync to defend against direct IRecurringBackgroundJob implementations / property overrides returning a negative value that would otherwise tight-loop via ComputeNextDelay clamping to zero.
- Add regression test for the negative-IgnoredDelay skip path.
- Mirror the constructor "stored without raising" remark on the Period and IgnoredDelay setter doc comments.
* Dispose newly-installed CTS when shutdown race wins the rotate-and-cancel
* Clarify XML docs.
* Introduce helper for cancellation source rotate and cancel.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Support anchor fragments that are included in the data attribute but missing in the href when migrating local links.
* Addressed code review feedback.
* Support anchor fragments that are included in the data attribute but missing in the href when migrating local links.
* Addressed code review feedback.
* Workspace Actions: Restore waiting state for buttons with additional options
The waiting state was suppressed whenever a workspace action reported
hasAdditionalOptions() (e.g. Save and publish on multi-variant sites),
so users saw the button jump straight from idle to the success tick
with no in-flight feedback.
Always set 'waiting' on click (unless the action is a link). The
variant-picker modal still opens on top of the button, so the spinner
is effectively invisible during selection — but it becomes visible
as soon as the modal closes and the publish request is in flight.
Fixes#22551
* Workspace Actions: Spin button only while real work is in flight
Replace the eager always-set-waiting behaviour from the previous commit
with an opt-in `isPending` signal so the spinner appears only while
actual work (validation + HTTP) is happening - not while the variant
picker modal is open, and never as a spurious success tick when the
user cancels the modal.
Changes:
- Add optional `isPending: Observable<boolean>` to UmbWorkspaceAction
and a default UmbBooleanState + protected setPending() on the base
class. Optional + backwards compatible for external implementers.
- Add optional `onActionStarting` callback (via a shared
UmbWorkspaceActionExecutionOptions type) to
UmbPublishableWorkspaceContext.saveAndPublish and
UmbSaveableWorkspaceContext.requestSave. The document publishing
context and content detail workspace base invoke the callback at the
join point right after the variant picker resolves (or is skipped
for the single-variant case), so it never fires when the modal is
cancelled.
- Wire the document save and save-and-publish actions to clear pending
at the start of execute() and pass an onActionStarting callback that
flips it true when work begins.
- Update the workspace action element to observe api.isPending: when
the observable is present the waiting state is driven by the
observable (and the success tick is suppressed if the action
resolves without ever signalling pending - i.e. a cancellation).
When the observable is absent the element falls back to the legacy
eager-waiting behaviour. Failures always surface the failed tick.
Fixes#22551
* Reduce cyclomatic complexity of #onClick and _handleSave
CodeScene Code Health Review flagged two complexity issues:
- UmbWorkspaceActionElement.#onClick reached cyclomatic complexity 9
(threshold is < 9). Extracted the api-execution branch into a new
private #runApiAction helper so #onClick collapses to a simple
link-vs-action dispatch.
- _handleSave was already over the threshold (14); my optional-chain
callback invocation pushed it to 16. Moved the
`executionOptions?.onActionStarting?.()` call into a #notifyActionStarting
helper so the call site is a plain method call and contributes zero
cyclomatic complexity to _handleSave.
No behavioural change.
* Reduce cyclomatic complexity of #handleSaveAndPublish
Same fix as the previous commit's #notifyActionStarting extraction in
content-detail-workspace-base: move the optional-chain callback
invocation into a private helper so #handleSaveAndPublish stays at its
pre-PR cyclomatic complexity (15) instead of degrading to 17.
No behavioural change.
* DRY: extract notifyWorkspaceActionStarting into a shared utility
Both UmbDocumentPublishingWorkspaceContext.#handleSaveAndPublish and
UmbContentDetailWorkspaceContextBase._handleSave had identical private
optional-chain callback off the host method's cyclomatic complexity.
Replace both with a single exported notifyWorkspaceActionStarting()
utility co-located with UmbWorkspaceActionExecutionOptions. This:
- Removes a duplication point between the two contexts.
- Gives future workspace context implementations a ready-made way to
honour the optional callback without re-inventing the helper or
paying the cyclomatic-complexity cost at the call site.
No behavioural change.
* Rename isPending -> isExecuting to mirror the execute() method
Niels suggested correlating the observable's name with the action's
`execute()` method, so the symbol set is now:
- isExecuting (observable on UmbWorkspaceAction interface)
- _isExecuting / setExecuting (UmbWorkspaceActionBase)
- #observeIsExecuting / #executionStarted (workspace-action element)
- isExecutingObserver (observer alias)
Pure rename; no behavioural change.
* Address Copilot review: lazy isExecuting, observer scope, finally reset
Five Copilot findings on PR #22554. Three real regressions + two
contract violations, all addressed:
1. UmbWorkspaceActionBase always exposing `isExecuting` made every
existing subclass appear to opt in to the new modal-aware flow,
suppressing waiting/success states for actions that never call
setExecuting(true). Made `_isExecuting`/`isExecuting` lazy: only
created on the first setExecuting() call. Opt-in subclasses call
`setExecuting(false)` in their constructor so the observable is
exposed before the workspace-action element reads it. Subclasses
that don't opt in keep `isExecuting` undefined and the element
falls back to legacy eager waiting feedback.
2. Element observation of `isExecuting` now lives inside #runApiAction
so it tracks whichever api is actually invoked (`_actionApi ?? #api`),
correctly handling subclasses like UmbSaveAndPreviewWorkspaceActionElement
that swap in a different api at runtime. The shared observer alias
replaces any previous observation on re-clicks.
3. UmbSaveWorkspaceAction and UmbDocumentSaveAndPublishWorkspaceAction
now wrap their execute() body in try/finally and reset
setExecuting(false) on completion so the observable honours the
"true while execute() is performing real work, false otherwise"
contract instead of getting stuck at true between executions.
No behavioural change for actions that already worked correctly before
this PR; the regression-prone "always exposed" behaviour is gone.
* Address Claude review: Elements gap, type placement, tests + cleanup
Three follow-ups on top of c15eb2d0bc:
1. Elements gap — UmbElementSaveAndPublishWorkspaceAction +
UmbElementPublishingWorkspaceContext now wire through the same
onActionStarting/notifyWorkspaceActionStarting handshake as the
Document equivalents, so multi-variant Elements (Forms, Commerce, etc.)
get the spinner-after-modal behaviour rather than no spinner at all.
2. Type placement — moved UmbWorkspaceActionExecutionOptions out of
publishable-workspace-context.interface.ts into its own file so the
saveable interface no longer has a directional dependency on the
publishable one. Both peer contexts now import from the same neutral
location.
3. Unit tests — added blackbox coverage for notifyWorkspaceActionStarting
(no-op on undefined options/callback, invokes when present) and the
UmbWorkspaceActionBase.setExecuting lazy-opt-in contract (undefined
until first call, observable then exposed, value flips, sequential
emissions, stable reference across calls).
Code-review cleanup applied on the same pass:
- Dropped the redundant `setExecuting(false)` at the start of execute()
in the save and save-and-publish actions; the finally block plus
UmbBooleanState's value-dedup already cover idempotency on retries.
- Removed an overlong block comment on `_isExecuting`; the JSDoc on
setExecuting already documents the lazy/opt-in contract for subclasses.
- Trimmed an internal motivation comment from notify-workspace-action-
starting.function.ts that referenced cyclomatic complexity.
- Extracted a tiny makeAction() helper in the controller test to remove
the `{ meta: {} as never }` repetition.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Workspace Actions: Align Save button state with Save & Publish (Andy review feedback)
Two related fixes addressing the variant-Save inconsistency Andy reported:
- Element catch block now only sets `failed` once `#executionStarted` is
true. Pre-flight rejections (user cancelling a variant-picker modal,
context-missing throws, etc.) leave the button idle, matching the
silent-cancel path used by `#handleSaveAndPublish`. Legacy actions
that don't opt in to `isExecuting` are unaffected because they set
`#executionStarted = true` eagerly on click.
- `UmbDocumentWorkspaceContext._handleSave` and
`UmbElementWorkspaceContext._handleSave` now accept and forward the
`UmbWorkspaceActionExecutionOptions` argument to `super._handleSave`.
The previous overrides dropped the parameter, so the
`onActionStarting` callback supplied by `UmbSaveWorkspaceAction` never
fired - which is why Save showed no waiting/success indicator even
on a successful submit.
Result: Save and Save-and-publish now behave identically -
cancel = no indicator, submit = waiting then success - for both
invariant and multi-variant documents and elements.
* Docs: Document the modal-aware execution feedback contract for workspace actions
New 'Button state when the action opens a modal' subsection in
docs/workspaces.md explaining the three-piece contract:
UmbWorkspaceActionExecutionOptions + notifyWorkspaceActionStarting +
UmbWorkspaceActionBase.setExecuting. Covers third-party authoring of
modal-aware buttons, the cancel/pre-flight idle behaviour, and the
silent-parameter-drop pitfall on _handleSave overrides.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Workspace Actions: Restore waiting state for buttons with additional options
The waiting state was suppressed whenever a workspace action reported
hasAdditionalOptions() (e.g. Save and publish on multi-variant sites),
so users saw the button jump straight from idle to the success tick
with no in-flight feedback.
Always set 'waiting' on click (unless the action is a link). The
variant-picker modal still opens on top of the button, so the spinner
is effectively invisible during selection — but it becomes visible
as soon as the modal closes and the publish request is in flight.
Fixes#22551
* Workspace Actions: Spin button only while real work is in flight
Replace the eager always-set-waiting behaviour from the previous commit
with an opt-in `isPending` signal so the spinner appears only while
actual work (validation + HTTP) is happening - not while the variant
picker modal is open, and never as a spurious success tick when the
user cancels the modal.
Changes:
- Add optional `isPending: Observable<boolean>` to UmbWorkspaceAction
and a default UmbBooleanState + protected setPending() on the base
class. Optional + backwards compatible for external implementers.
- Add optional `onActionStarting` callback (via a shared
UmbWorkspaceActionExecutionOptions type) to
UmbPublishableWorkspaceContext.saveAndPublish and
UmbSaveableWorkspaceContext.requestSave. The document publishing
context and content detail workspace base invoke the callback at the
join point right after the variant picker resolves (or is skipped
for the single-variant case), so it never fires when the modal is
cancelled.
- Wire the document save and save-and-publish actions to clear pending
at the start of execute() and pass an onActionStarting callback that
flips it true when work begins.
- Update the workspace action element to observe api.isPending: when
the observable is present the waiting state is driven by the
observable (and the success tick is suppressed if the action
resolves without ever signalling pending - i.e. a cancellation).
When the observable is absent the element falls back to the legacy
eager-waiting behaviour. Failures always surface the failed tick.
Fixes#22551
* Reduce cyclomatic complexity of #onClick and _handleSave
CodeScene Code Health Review flagged two complexity issues:
- UmbWorkspaceActionElement.#onClick reached cyclomatic complexity 9
(threshold is < 9). Extracted the api-execution branch into a new
private #runApiAction helper so #onClick collapses to a simple
link-vs-action dispatch.
- _handleSave was already over the threshold (14); my optional-chain
callback invocation pushed it to 16. Moved the
`executionOptions?.onActionStarting?.()` call into a #notifyActionStarting
helper so the call site is a plain method call and contributes zero
cyclomatic complexity to _handleSave.
No behavioural change.
* Reduce cyclomatic complexity of #handleSaveAndPublish
Same fix as the previous commit's #notifyActionStarting extraction in
content-detail-workspace-base: move the optional-chain callback
invocation into a private helper so #handleSaveAndPublish stays at its
pre-PR cyclomatic complexity (15) instead of degrading to 17.
No behavioural change.
* DRY: extract notifyWorkspaceActionStarting into a shared utility
Both UmbDocumentPublishingWorkspaceContext.#handleSaveAndPublish and
UmbContentDetailWorkspaceContextBase._handleSave had identical private
#notifyActionStarting helpers introduced in this PR purely to keep the
optional-chain callback off the host method's cyclomatic complexity.
Replace both with a single exported notifyWorkspaceActionStarting()
utility co-located with UmbWorkspaceActionExecutionOptions. This:
- Removes a duplication point between the two contexts.
- Gives future workspace context implementations a ready-made way to
honour the optional callback without re-inventing the helper or
paying the cyclomatic-complexity cost at the call site.
No behavioural change.
* Rename isPending -> isExecuting to mirror the execute() method
Niels suggested correlating the observable's name with the action's
`execute()` method, so the symbol set is now:
- isExecuting (observable on UmbWorkspaceAction interface)
- _isExecuting / setExecuting (UmbWorkspaceActionBase)
- #observeIsExecuting / #executionStarted (workspace-action element)
- isExecutingObserver (observer alias)
Pure rename; no behavioural change.
* Address Copilot review: lazy isExecuting, observer scope, finally reset
Five Copilot findings on PR #22554. Three real regressions + two
contract violations, all addressed:
1. UmbWorkspaceActionBase always exposing `isExecuting` made every
existing subclass appear to opt in to the new modal-aware flow,
suppressing waiting/success states for actions that never call
setExecuting(true). Made `_isExecuting`/`isExecuting` lazy: only
created on the first setExecuting() call. Opt-in subclasses call
`setExecuting(false)` in their constructor so the observable is
exposed before the workspace-action element reads it. Subclasses
that don't opt in keep `isExecuting` undefined and the element
falls back to legacy eager waiting feedback.
2. Element observation of `isExecuting` now lives inside #runApiAction
so it tracks whichever api is actually invoked (`_actionApi ?? #api`),
correctly handling subclasses like UmbSaveAndPreviewWorkspaceActionElement
that swap in a different api at runtime. The shared observer alias
replaces any previous observation on re-clicks.
3. UmbSaveWorkspaceAction and UmbDocumentSaveAndPublishWorkspaceAction
now wrap their execute() body in try/finally and reset
setExecuting(false) on completion so the observable honours the
"true while execute() is performing real work, false otherwise"
contract instead of getting stuck at true between executions.
No behavioural change for actions that already worked correctly before
this PR; the regression-prone "always exposed" behaviour is gone.
* Address Claude review: Elements gap, type placement, tests + cleanup
Three follow-ups on top of c15eb2d0bc:
1. Elements gap — UmbElementSaveAndPublishWorkspaceAction +
UmbElementPublishingWorkspaceContext now wire through the same
onActionStarting/notifyWorkspaceActionStarting handshake as the
Document equivalents, so multi-variant Elements (Forms, Commerce, etc.)
get the spinner-after-modal behaviour rather than no spinner at all.
2. Type placement — moved UmbWorkspaceActionExecutionOptions out of
publishable-workspace-context.interface.ts into its own file so the
saveable interface no longer has a directional dependency on the
publishable one. Both peer contexts now import from the same neutral
location.
3. Unit tests — added blackbox coverage for notifyWorkspaceActionStarting
(no-op on undefined options/callback, invokes when present) and the
UmbWorkspaceActionBase.setExecuting lazy-opt-in contract (undefined
until first call, observable then exposed, value flips, sequential
emissions, stable reference across calls).
Code-review cleanup applied on the same pass:
- Dropped the redundant `setExecuting(false)` at the start of execute()
in the save and save-and-publish actions; the finally block plus
UmbBooleanState's value-dedup already cover idempotency on retries.
- Removed an overlong block comment on `_isExecuting`; the JSDoc on
setExecuting already documents the lazy/opt-in contract for subclasses.
- Trimmed an internal motivation comment from notify-workspace-action-
starting.function.ts that referenced cyclomatic complexity.
- Extracted a tiny makeAction() helper in the controller test to remove
the `{ meta: {} as never }` repetition.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Workspace Actions: Align Save button state with Save & Publish (Andy review feedback)
Two related fixes addressing the variant-Save inconsistency Andy reported:
- Element catch block now only sets `failed` once `#executionStarted` is
true. Pre-flight rejections (user cancelling a variant-picker modal,
context-missing throws, etc.) leave the button idle, matching the
silent-cancel path used by `#handleSaveAndPublish`. Legacy actions
that don't opt in to `isExecuting` are unaffected because they set
`#executionStarted = true` eagerly on click.
- `UmbDocumentWorkspaceContext._handleSave` and
`UmbElementWorkspaceContext._handleSave` now accept and forward the
`UmbWorkspaceActionExecutionOptions` argument to `super._handleSave`.
The previous overrides dropped the parameter, so the
`onActionStarting` callback supplied by `UmbSaveWorkspaceAction` never
fired - which is why Save showed no waiting/success indicator even
on a successful submit.
Result: Save and Save-and-publish now behave identically -
cancel = no indicator, submit = waiting then success - for both
invariant and multi-variant documents and elements.
* Docs: Document the modal-aware execution feedback contract for workspace actions
New 'Button state when the action opens a modal' subsection in
docs/workspaces.md explaining the three-piece contract:
UmbWorkspaceActionExecutionOptions + notifyWorkspaceActionStarting +
UmbWorkspaceActionBase.setExecuting. Covers third-party authoring of
modal-aware buttons, the cancel/pre-flight idle behaviour, and the
silent-parameter-drop pitfall on _handleSave overrides.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Workspace Actions: Restore waiting state for buttons with additional options
The waiting state was suppressed whenever a workspace action reported
hasAdditionalOptions() (e.g. Save and publish on multi-variant sites),
so users saw the button jump straight from idle to the success tick
with no in-flight feedback.
Always set 'waiting' on click (unless the action is a link). The
variant-picker modal still opens on top of the button, so the spinner
is effectively invisible during selection — but it becomes visible
as soon as the modal closes and the publish request is in flight.
Fixes#22551
* Workspace Actions: Spin button only while real work is in flight
Replace the eager always-set-waiting behaviour from the previous commit
with an opt-in `isPending` signal so the spinner appears only while
actual work (validation + HTTP) is happening - not while the variant
picker modal is open, and never as a spurious success tick when the
user cancels the modal.
Changes:
- Add optional `isPending: Observable<boolean>` to UmbWorkspaceAction
and a default UmbBooleanState + protected setPending() on the base
class. Optional + backwards compatible for external implementers.
- Add optional `onActionStarting` callback (via a shared
UmbWorkspaceActionExecutionOptions type) to
UmbPublishableWorkspaceContext.saveAndPublish and
UmbSaveableWorkspaceContext.requestSave. The document publishing
context and content detail workspace base invoke the callback at the
join point right after the variant picker resolves (or is skipped
for the single-variant case), so it never fires when the modal is
cancelled.
- Wire the document save and save-and-publish actions to clear pending
at the start of execute() and pass an onActionStarting callback that
flips it true when work begins.
- Update the workspace action element to observe api.isPending: when
the observable is present the waiting state is driven by the
observable (and the success tick is suppressed if the action
resolves without ever signalling pending - i.e. a cancellation).
When the observable is absent the element falls back to the legacy
eager-waiting behaviour. Failures always surface the failed tick.
Fixes#22551
* Reduce cyclomatic complexity of #onClick and _handleSave
CodeScene Code Health Review flagged two complexity issues:
- UmbWorkspaceActionElement.#onClick reached cyclomatic complexity 9
(threshold is < 9). Extracted the api-execution branch into a new
private #runApiAction helper so #onClick collapses to a simple
link-vs-action dispatch.
- _handleSave was already over the threshold (14); my optional-chain
callback invocation pushed it to 16. Moved the
`executionOptions?.onActionStarting?.()` call into a #notifyActionStarting
helper so the call site is a plain method call and contributes zero
cyclomatic complexity to _handleSave.
No behavioural change.
* Reduce cyclomatic complexity of #handleSaveAndPublish
Same fix as the previous commit's #notifyActionStarting extraction in
content-detail-workspace-base: move the optional-chain callback
invocation into a private helper so #handleSaveAndPublish stays at its
pre-PR cyclomatic complexity (15) instead of degrading to 17.
No behavioural change.
* DRY: extract notifyWorkspaceActionStarting into a shared utility
Both UmbDocumentPublishingWorkspaceContext.#handleSaveAndPublish and
UmbContentDetailWorkspaceContextBase._handleSave had identical private
#notifyActionStarting helpers introduced in this PR purely to keep the
optional-chain callback off the host method's cyclomatic complexity.
Replace both with a single exported notifyWorkspaceActionStarting()
utility co-located with UmbWorkspaceActionExecutionOptions. This:
- Removes a duplication point between the two contexts.
- Gives future workspace context implementations a ready-made way to
honour the optional callback without re-inventing the helper or
paying the cyclomatic-complexity cost at the call site.
No behavioural change.
* Rename isPending -> isExecuting to mirror the execute() method
Niels suggested correlating the observable's name with the action's
`execute()` method, so the symbol set is now:
- isExecuting (observable on UmbWorkspaceAction interface)
- _isExecuting / setExecuting (UmbWorkspaceActionBase)
- #observeIsExecuting / #executionStarted (workspace-action element)
- isExecutingObserver (observer alias)
Pure rename; no behavioural change.
* Address Copilot review: lazy isExecuting, observer scope, finally reset
Five Copilot findings on PR #22554. Three real regressions + two
contract violations, all addressed:
1. UmbWorkspaceActionBase always exposing `isExecuting` made every
existing subclass appear to opt in to the new modal-aware flow,
suppressing waiting/success states for actions that never call
setExecuting(true). Made `_isExecuting`/`isExecuting` lazy: only
created on the first setExecuting() call. Opt-in subclasses call
`setExecuting(false)` in their constructor so the observable is
exposed before the workspace-action element reads it. Subclasses
that don't opt in keep `isExecuting` undefined and the element
falls back to legacy eager waiting feedback.
2. Element observation of `isExecuting` now lives inside #runApiAction
so it tracks whichever api is actually invoked (`_actionApi ?? #api`),
correctly handling subclasses like UmbSaveAndPreviewWorkspaceActionElement
that swap in a different api at runtime. The shared observer alias
replaces any previous observation on re-clicks.
3. UmbSaveWorkspaceAction and UmbDocumentSaveAndPublishWorkspaceAction
now wrap their execute() body in try/finally and reset
setExecuting(false) on completion so the observable honours the
"true while execute() is performing real work, false otherwise"
contract instead of getting stuck at true between executions.
No behavioural change for actions that already worked correctly before
this PR; the regression-prone "always exposed" behaviour is gone.
* Address Claude review: Elements gap, type placement, tests + cleanup
Three follow-ups on top of c15eb2d0bc:
1. Elements gap — UmbElementSaveAndPublishWorkspaceAction +
UmbElementPublishingWorkspaceContext now wire through the same
onActionStarting/notifyWorkspaceActionStarting handshake as the
Document equivalents, so multi-variant Elements (Forms, Commerce, etc.)
get the spinner-after-modal behaviour rather than no spinner at all.
2. Type placement — moved UmbWorkspaceActionExecutionOptions out of
publishable-workspace-context.interface.ts into its own file so the
saveable interface no longer has a directional dependency on the
publishable one. Both peer contexts now import from the same neutral
location.
3. Unit tests — added blackbox coverage for notifyWorkspaceActionStarting
(no-op on undefined options/callback, invokes when present) and the
UmbWorkspaceActionBase.setExecuting lazy-opt-in contract (undefined
until first call, observable then exposed, value flips, sequential
emissions, stable reference across calls).
Code-review cleanup applied on the same pass:
- Dropped the redundant `setExecuting(false)` at the start of execute()
in the save and save-and-publish actions; the finally block plus
UmbBooleanState's value-dedup already cover idempotency on retries.
- Removed an overlong block comment on `_isExecuting`; the JSDoc on
setExecuting already documents the lazy/opt-in contract for subclasses.
- Trimmed an internal motivation comment from notify-workspace-action-
starting.function.ts that referenced cyclomatic complexity.
- Extracted a tiny makeAction() helper in the controller test to remove
the `{ meta: {} as never }` repetition.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Workspace Actions: Align Save button state with Save & Publish (Andy review feedback)
Two related fixes addressing the variant-Save inconsistency Andy reported:
- Element catch block now only sets `failed` once `#executionStarted` is
true. Pre-flight rejections (user cancelling a variant-picker modal,
context-missing throws, etc.) leave the button idle, matching the
silent-cancel path used by `#handleSaveAndPublish`. Legacy actions
that don't opt in to `isExecuting` are unaffected because they set
`#executionStarted = true` eagerly on click.
- `UmbDocumentWorkspaceContext._handleSave` and
`UmbElementWorkspaceContext._handleSave` now accept and forward the
`UmbWorkspaceActionExecutionOptions` argument to `super._handleSave`.
The previous overrides dropped the parameter, so the
`onActionStarting` callback supplied by `UmbSaveWorkspaceAction` never
fired - which is why Save showed no waiting/success indicator even
on a successful submit.
Result: Save and Save-and-publish now behave identically -
cancel = no indicator, submit = waiting then success - for both
invariant and multi-variant documents and elements.
* Docs: Document the modal-aware execution feedback contract for workspace actions
New 'Button state when the action opens a modal' subsection in
docs/workspaces.md explaining the three-piece contract:
UmbWorkspaceActionExecutionOptions + notifyWorkspaceActionStarting +
UmbWorkspaceActionBase.setExecuting. Covers third-party authoring of
modal-aware buttons, the cancel/pre-flight idle behaviour, and the
silent-parameter-drop pitfall on _handleSave overrides.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Backoffice: Coalesce small Rollup chunks across all workspaces (AB#67983)
Set experimentalMinChunkSize=10_000 as the default in the shared Vite
helper. Every workspace inherits the coalescing automatically; the
threshold can still be overridden per workspace (pass 0 to disable).
Impact on dist-cms output:
- packages/core .js files: 981 -> 272 (-72%)
- All workspaces combined .js files: 2194 -> 1401 (-36%)
- Welcome dashboard .js requests: 510 -> 497 (-2.5%)
- packages/ufm requests in particular: 23 -> 12 (-48%)
- Gzipped bundle total: -1.2%
- Raw bytes: +1.4% (small overhead from merged chunks; gzip wins it back)
All entry chunks are preserved, so every public
@umbraco-cms/backoffice/<sub> import keeps resolving without changes
to package.json exports or tsconfig paths.
Further consolidation (collapsing core's per-subpath entries into a
single bundle with stubs) was prototyped but hits a TDZ cycle between
the eager entry and its dynamic-import descendants. Tracked for v18,
not part of this change.
* Backoffice: Normalise umbraco-package + manifests shapes (AB#67983)
Aligns the two outliers with the conventions used by the other 38
first-party packages:
- documents/umbraco-package.ts now uses the lazy bundle pattern
(type: 'bundle', js: () => import('./manifests.js')) instead of
eagerly importing manifests at module evaluation. The bundle
initializer auto-loads the manifests at boot, so behaviour is
unchanged.
- umbraco-news/manifests.ts now exports `manifests: Array<...>`
instead of a bare `dashboard` object. The bundle initializer
enumerates exports regardless of name, so behaviour is unchanged.
Preparatory cleanup so future build-time manifest aggregation can
treat every workspace uniformly.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Backoffice: Coalesce small Rollup chunks across all workspaces (AB#67983)
Set experimentalMinChunkSize=10_000 as the default in the shared Vite
helper. Every workspace inherits the coalescing automatically; the
threshold can still be overridden per workspace (pass 0 to disable).
Impact on dist-cms output:
- packages/core .js files: 981 -> 272 (-72%)
- All workspaces combined .js files: 2194 -> 1401 (-36%)
- Welcome dashboard .js requests: 510 -> 497 (-2.5%)
- packages/ufm requests in particular: 23 -> 12 (-48%)
- Gzipped bundle total: -1.2%
- Raw bytes: +1.4% (small overhead from merged chunks; gzip wins it back)
All entry chunks are preserved, so every public
@umbraco-cms/backoffice/<sub> import keeps resolving without changes
to package.json exports or tsconfig paths.
Further consolidation (collapsing core's per-subpath entries into a
single bundle with stubs) was prototyped but hits a TDZ cycle between
the eager entry and its dynamic-import descendants. Tracked for v18,
not part of this change.
* Backoffice: Normalise umbraco-package + manifests shapes (AB#67983)
Aligns the two outliers with the conventions used by the other 38
first-party packages:
- documents/umbraco-package.ts now uses the lazy bundle pattern
(type: 'bundle', js: () => import('./manifests.js')) instead of
eagerly importing manifests at module evaluation. The bundle
initializer auto-loads the manifests at boot, so behaviour is
unchanged.
- umbraco-news/manifests.ts now exports `manifests: Array<...>`
instead of a bare `dashboard` object. The bundle initializer
enumerates exports regardless of name, so behaviour is unchanged.
Preparatory cleanup so future build-time manifest aggregation can
treat every workspace uniformly.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Backoffice: Coalesce small Rollup chunks across all workspaces (AB#67983)
Set experimentalMinChunkSize=10_000 as the default in the shared Vite
helper. Every workspace inherits the coalescing automatically; the
threshold can still be overridden per workspace (pass 0 to disable).
Impact on dist-cms output:
- packages/core .js files: 981 -> 272 (-72%)
- All workspaces combined .js files: 2194 -> 1401 (-36%)
- Welcome dashboard .js requests: 510 -> 497 (-2.5%)
- packages/ufm requests in particular: 23 -> 12 (-48%)
- Gzipped bundle total: -1.2%
- Raw bytes: +1.4% (small overhead from merged chunks; gzip wins it back)
All entry chunks are preserved, so every public
@umbraco-cms/backoffice/<sub> import keeps resolving without changes
to package.json exports or tsconfig paths.
Further consolidation (collapsing core's per-subpath entries into a
single bundle with stubs) was prototyped but hits a TDZ cycle between
the eager entry and its dynamic-import descendants. Tracked for v18,
not part of this change.
* Backoffice: Normalise umbraco-package + manifests shapes (AB#67983)
Aligns the two outliers with the conventions used by the other 38
first-party packages:
- documents/umbraco-package.ts now uses the lazy bundle pattern
(type: 'bundle', js: () => import('./manifests.js')) instead of
eagerly importing manifests at module evaluation. The bundle
initializer auto-loads the manifests at boot, so behaviour is
unchanged.
- umbraco-news/manifests.ts now exports `manifests: Array<...>`
instead of a bare `dashboard` object. The bundle initializer
enumerates exports regardless of name, so behaviour is unchanged.
Preparatory cleanup so future build-time manifest aggregation can
treat every workspace uniformly.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Compute next delay to compensate for time drift
* Use SemaphoreSlim to properly handle exceptions, cancellation tokens and triggering immediate executions
* Add RecurringBackgroundJobBase to contain default values and hide obsoleted method
* Add NextExecutionStrategy parameter to adjust the schedule after triggered executions
* Add TriggerExecution methods to RecurringBackgroundJobHostedServiceRunner
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Handle cancellation (application shutdown) and publish RecurringBackgroundJobCanceledNotification
* Match hosted services by Type instead of type name string
* Extract shared helper for TriggerExecution tests
* Clear trigger state when initial delay is interrupted
* Clear _nextExecutionSkipOnOvershoot unconditionally
* Combine ComputeNextDelay tests
* Consolidate trigger state into an immutable record for thread safety
* Use ConcurrentDictionary for thread-safe hosted service lookup
* Remove hosted services from dictionary on stop
* Fix API compatibility errors
* Removed unneeded using.
* Register RecurringBackgroundJobHostedServiceRunner as resolvable singleton
* Remove failed hosted service from dictionary when StartAsync throws
* Use semaphore signaling instead of Task.Delay in trigger tests
Use semaphore signaling instead of Task.Delay in trigger tests 2
* Inject TimeProvider into RecurringHostedServiceBase for deterministic testing
Fix timeprovider
* Use DelayCalculator.GetDelay instead of RecurringHostedServiceBase.GetDelay
* Fix Exception_In_PerformExecuteAsync_Does_Not_Kill_Loop test
* Avoid disposing period-change CTS while wait loop may still reference it
* Configure IEventMessagesFactory mock to return real EventMessages
* Clarify TriggerExecution(TimeSpan) docs and add ChangePeriod test
* Validate period is positive and use GetOrAdd to avoid creating unused hosted services
* Set up Period and Delay on mock job to satisfy constructor validation
* Ensure PeriodChanged event is unsubscribed again
* Fix trigger state race, simplify ReleaseSignal, and add canceled notification test
Fix trigger state
* Use Interlocked for _period reads/writes and implement thread-safe dispose pattern
* Remove hosted service from dictionary before stopping to prevent triggering during shutdown
* Replace Task.Yield with semaphore timeouts in negative assertions
* Tidy RecurringBackgroundJobBase docs and runner error handling
* Wait IgnoredDelay after ignored execution to prevent tight looping when Period is short or zero
* Add IRecurringBackgroundJobTrigger<TJob> for opt-in job triggering
* Register IRecurringBackgroundJobTrigger as open generic and drop AddTriggerableRecurringBackgroundJob
* Fix and add parameter validation
* Allow Timeout.InfiniteTimeSpan as Period for manual-trigger-only recurring jobs
* Migrate built-in jobs to RecurringBackgroundJobBase and require ITriggerableRecurringBackgroundJob in runner trigger overloads
* Support infinite Delay and honor TriggerExecution(TimeSpan) issued during the initial delay
* Handle edge case of backoff via InfiniteTimeSpan.
* Refactored large method.
* Added clarifying documentation.
* Suppress ExecutionContext flow when starting the recurring background loop, restoring previous timer behaviour.
* Relocate Suppress ExecutionContext flow to avoid package validation error.
* Align IRecurringBackgroundJobTrigger generic type constraint with AddRecurringBackgroundJob
* Rename ApplyTriggerState to ComputeNextDelayFromTriggerState
* Allow Timeout.InfiniteTimeSpan as IgnoredDelay to fully disable a job for the remaining application lifecycle
* Fix generic type constraint
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Compute next delay to compensate for time drift
* Use SemaphoreSlim to properly handle exceptions, cancellation tokens and triggering immediate executions
* Add RecurringBackgroundJobBase to contain default values and hide obsoleted method
* Add NextExecutionStrategy parameter to adjust the schedule after triggered executions
* Add TriggerExecution methods to RecurringBackgroundJobHostedServiceRunner
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Handle cancellation (application shutdown) and publish RecurringBackgroundJobCanceledNotification
* Match hosted services by Type instead of type name string
* Extract shared helper for TriggerExecution tests
* Clear trigger state when initial delay is interrupted
* Clear _nextExecutionSkipOnOvershoot unconditionally
* Combine ComputeNextDelay tests
* Consolidate trigger state into an immutable record for thread safety
* Use ConcurrentDictionary for thread-safe hosted service lookup
* Remove hosted services from dictionary on stop
* Fix API compatibility errors
* Removed unneeded using.
* Register RecurringBackgroundJobHostedServiceRunner as resolvable singleton
* Remove failed hosted service from dictionary when StartAsync throws
* Use semaphore signaling instead of Task.Delay in trigger tests
Use semaphore signaling instead of Task.Delay in trigger tests 2
* Inject TimeProvider into RecurringHostedServiceBase for deterministic testing
Fix timeprovider
* Use DelayCalculator.GetDelay instead of RecurringHostedServiceBase.GetDelay
* Fix Exception_In_PerformExecuteAsync_Does_Not_Kill_Loop test
* Avoid disposing period-change CTS while wait loop may still reference it
* Configure IEventMessagesFactory mock to return real EventMessages
* Clarify TriggerExecution(TimeSpan) docs and add ChangePeriod test
* Validate period is positive and use GetOrAdd to avoid creating unused hosted services
* Set up Period and Delay on mock job to satisfy constructor validation
* Ensure PeriodChanged event is unsubscribed again
* Fix trigger state race, simplify ReleaseSignal, and add canceled notification test
Fix trigger state
* Use Interlocked for _period reads/writes and implement thread-safe dispose pattern
* Remove hosted service from dictionary before stopping to prevent triggering during shutdown
* Replace Task.Yield with semaphore timeouts in negative assertions
* Tidy RecurringBackgroundJobBase docs and runner error handling
* Wait IgnoredDelay after ignored execution to prevent tight looping when Period is short or zero
* Add IRecurringBackgroundJobTrigger<TJob> for opt-in job triggering
* Register IRecurringBackgroundJobTrigger as open generic and drop AddTriggerableRecurringBackgroundJob
* Fix and add parameter validation
* Allow Timeout.InfiniteTimeSpan as Period for manual-trigger-only recurring jobs
* Migrate built-in jobs to RecurringBackgroundJobBase and require ITriggerableRecurringBackgroundJob in runner trigger overloads
* Support infinite Delay and honor TriggerExecution(TimeSpan) issued during the initial delay
* Handle edge case of backoff via InfiniteTimeSpan.
* Refactored large method.
* Added clarifying documentation.
* Suppress ExecutionContext flow when starting the recurring background loop, restoring previous timer behaviour.
* Relocate Suppress ExecutionContext flow to avoid package validation error.
* Align IRecurringBackgroundJobTrigger generic type constraint with AddRecurringBackgroundJob
* Rename ApplyTriggerState to ComputeNextDelayFromTriggerState
* Allow Timeout.InfiniteTimeSpan as IgnoredDelay to fully disable a job for the remaining application lifecycle
* Fix generic type constraint
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Compute next delay to compensate for time drift
* Use SemaphoreSlim to properly handle exceptions, cancellation tokens and triggering immediate executions
* Add RecurringBackgroundJobBase to contain default values and hide obsoleted method
* Add NextExecutionStrategy parameter to adjust the schedule after triggered executions
* Add TriggerExecution methods to RecurringBackgroundJobHostedServiceRunner
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Handle cancellation (application shutdown) and publish RecurringBackgroundJobCanceledNotification
* Match hosted services by Type instead of type name string
* Extract shared helper for TriggerExecution tests
* Clear trigger state when initial delay is interrupted
* Clear _nextExecutionSkipOnOvershoot unconditionally
* Combine ComputeNextDelay tests
* Consolidate trigger state into an immutable record for thread safety
* Use ConcurrentDictionary for thread-safe hosted service lookup
* Remove hosted services from dictionary on stop
* Fix API compatibility errors
* Removed unneeded using.
* Register RecurringBackgroundJobHostedServiceRunner as resolvable singleton
* Remove failed hosted service from dictionary when StartAsync throws
* Use semaphore signaling instead of Task.Delay in trigger tests
Use semaphore signaling instead of Task.Delay in trigger tests 2
* Inject TimeProvider into RecurringHostedServiceBase for deterministic testing
Fix timeprovider
* Use DelayCalculator.GetDelay instead of RecurringHostedServiceBase.GetDelay
* Fix Exception_In_PerformExecuteAsync_Does_Not_Kill_Loop test
* Avoid disposing period-change CTS while wait loop may still reference it
* Configure IEventMessagesFactory mock to return real EventMessages
* Clarify TriggerExecution(TimeSpan) docs and add ChangePeriod test
* Validate period is positive and use GetOrAdd to avoid creating unused hosted services
* Set up Period and Delay on mock job to satisfy constructor validation
* Ensure PeriodChanged event is unsubscribed again
* Fix trigger state race, simplify ReleaseSignal, and add canceled notification test
Fix trigger state
* Use Interlocked for _period reads/writes and implement thread-safe dispose pattern
* Remove hosted service from dictionary before stopping to prevent triggering during shutdown
* Replace Task.Yield with semaphore timeouts in negative assertions
* Tidy RecurringBackgroundJobBase docs and runner error handling
* Wait IgnoredDelay after ignored execution to prevent tight looping when Period is short or zero
* Add IRecurringBackgroundJobTrigger<TJob> for opt-in job triggering
* Register IRecurringBackgroundJobTrigger as open generic and drop AddTriggerableRecurringBackgroundJob
* Fix and add parameter validation
* Allow Timeout.InfiniteTimeSpan as Period for manual-trigger-only recurring jobs
* Migrate built-in jobs to RecurringBackgroundJobBase and require ITriggerableRecurringBackgroundJob in runner trigger overloads
* Support infinite Delay and honor TriggerExecution(TimeSpan) issued during the initial delay
* Handle edge case of backoff via InfiniteTimeSpan.
* Refactored large method.
* Added clarifying documentation.
* Suppress ExecutionContext flow when starting the recurring background loop, restoring previous timer behaviour.
* Relocate Suppress ExecutionContext flow to avoid package validation error.
* Align IRecurringBackgroundJobTrigger generic type constraint with AddRecurringBackgroundJob
* Rename ApplyTriggerState to ComputeNextDelayFromTriggerState
* Allow Timeout.InfiniteTimeSpan as IgnoredDelay to fully disable a job for the remaining application lifecycle
* Fix generic type constraint
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Element Tree Picker Data Source: adds item data resolver
This follows PR #22915, which fixes the Entity Data Picker's
removal confirmation message with the entity's name.
* Adds support for `UmbElementFolderItemDataResolver`
Backfills the two required properties on the seven mock document type
entries that were missing them, so the file type-checks against
DocumentTypeResponseModel and DocumentTypeTreeItemResponseModel.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add item data resolver support to picker data sources
* add js docs
* remove duplicated fallback logic
* wip unit tests of requestItemName method
* Use DocumentVariantStateModel in mock documents to fix compiler
* Update input-entity-data.context.ts
* Update input-entity-data.context.test.ts
(cherry picked from commit c74a58246f)
* Add item data resolver support to picker data sources
* add js docs
* remove duplicated fallback logic
* wip unit tests of requestItemName method
* Use DocumentVariantStateModel in mock documents to fix compiler
* Update input-entity-data.context.ts
* Update input-entity-data.context.test.ts
- ElementPickerValueConverterTests: also stub the new synchronous IPublishedElementCache.GetById,
since Moq does not execute default interface implementations.
- PropertyCacheLevelTests.CacheUnknownTest: access a property inside Assert.Throws to trigger the
now-lazy property wrapper materialization.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Extension template: Configure BackOffice JSON options and replace IUser response with WhoAmIResponseModel
Sets the extension template's backoffice API to use the BackOffice named JsonOptions so the extension's serializer is insulated from consumer-level overrides.
The sample whoAmI endpoint previously returned IUser directly. IUser is a Umbraco.Core domain interface, not an API contract - it has no JSON polymorphism configuration and its nested interface properties (e.g. IReadOnlyUserGroup) are not designed to be serialized as part of an HTTP response. Once the BackOffice JsonOptions activated UmbracoJsonTypeInfoResolver for the extension's OpenAPI document, schema generation produced incomplete output (no type information on the Groups property).
Replaces the return type with a flat WhoAmIResponseModel exposing only the fields the dashboard UI consumes (name, email, groups). Domain interfaces should not be exposed directly on a controller - always project into a dedicated response model.
* Extension template: Fully-qualify Cms.Core references and drop Umbraco.Extensions import
The composer and controller base referenced `Cms.Core.Constants...` in short form, which relied on namespace fallback from `Umbraco.Extension.Controllers` finding `Umbraco.Cms.Core`. When consumers instantiate the template with a non-Umbraco root namespace, that fallback breaks. References are now fully qualified as `Umbraco.Cms.Core.Constants...`.
Additionally, the `whoAmI` controller's `using Umbraco.Extensions;` was getting mangled by the template engine's token substitution of `Umbraco.Extension` into the consumer's name. Replaces `WhereNotNull()` with the BCL-only `OfType<string>()` so the controller no longer depends on the `Umbraco.Extensions` namespace.
* Extension template: Tighten whoAmI 204 guard in dashboard
The generated client returns a truthy empty data object (or null body) for a 204 response, so the previous `if (data)` check could pass and render `undefined` values in the notification. Checks `data?.email` instead - it's a required field on a real 200 response and absent in the 204 fallback.
* Extension template: Return 401 Unauthorized from whoAmI and simplify dashboard handling
When `BackOfficeSecurity.CurrentUser` is null, the sample `whoAmI` endpoint now returns `Unauthorized()` instead of `NoContent()`, matching the `GetCurrentUserController` pattern in the Management API. Drops the 204 ProducesResponseType so the OpenAPI spec only advertises 200 plus the framework-emitted 401.
The dashboard collapses its empty-data check into a single `error || !data` guard, moves the notification into the success branch, and regenerates the client to drop the now-unused 204 response.
* Fix edit of a variant property composed to an invariant document.
* Collapse multi-line guard comment to a single line per project policy.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add unit test coverage for invariant content with a culture-variant composition property.
Adds a third mock document/document-type pair representing an invariant
content type whose flattened property list contains a culture-variant
property (the runtime shape produced when a variant composition is applied
to an invariant content type) and a setPropertyValue test asserting the
value is stored as a culture/segment-invariant entry.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Remove null guard for segment variant documents, as null segment is the default segment.
* update mock data and tests to include real compositions
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Fix edit of a variant property composed to an invariant document.
* Collapse multi-line guard comment to a single line per project policy.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add unit test coverage for invariant content with a culture-variant composition property.
Adds a third mock document/document-type pair representing an invariant
content type whose flattened property list contains a culture-variant
property (the runtime shape produced when a variant composition is applied
to an invariant content type) and a setPropertyValue test asserting the
value is stored as a culture/segment-invariant entry.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Remove null guard for segment variant documents, as null segment is the default segment.
* update mock data and tests to include real compositions
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Fix edit of a variant property composed to an invariant document.
* Collapse multi-line guard comment to a single line per project policy.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add unit test coverage for invariant content with a culture-variant composition property.
Adds a third mock document/document-type pair representing an invariant
content type whose flattened property list contains a culture-variant
property (the runtime shape produced when a variant composition is applied
to an invariant content type) and a setPropertyValue test asserting the
value is stored as a culture/segment-invariant entry.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Remove null guard for segment variant documents, as null segment is the default segment.
* update mock data and tests to include real compositions
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* feat(components): adds `umb-entity-frame` component + Storybook stories
* fix(components): address review feedback for `umb-entity-frame`
- Remove `pointer-events: auto` from `.tab` so the overlay is truly passive
(was intercepting events above the parent and causing hover flicker when
toggled via opacity).
- Replace `--uui-color-surface` tab text with `--uui-color-selected-contrast`
(the proper paired contrast token) and expose
`--umb-entity-frame-contrast-color` so consumers can override when supplying
a non-default `--umb-entity-frame-color`. Fixes contrast in dark and
high-contrast themes.
- Add `aria-hidden="true"` to `.tab`; the frame is purely decorative and the
parent owns the real semantics.
- Add a unit test verifying slot content takes precedence over the `label`
property.
* Removed `aria-hidden` from the label tab
As will need to be used with assistive technologies.
* Defensively handle log file corruptions by amalgamating errors per file and reporting as warning.
* Addressed code review comments.
* Use local reference to Newtonsoft.Json so it's clear we are only using it for exception handling.
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Remove the ability to enable or disable the redirect tracker from the UI.
* Addressed code review feedback.
* Update OpenApi.json.
* Regenerate backend SDK from updated OpenApi.json
* Update UI to use lozenge status indicator rather than an imperative action.
* Further UX tweak.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Add auto upgrade coordination for load balanced setups
* Add tests
* Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* fix(infrastructure): move TryBecomeLeaderAsync inside try/catch in UnattendedUpgradeBackgroundService
Ensures DB exceptions thrown during migration coordination set BootFailed
rather than faulting the background service silently.
* Fix feedback
* Update src/Umbraco.Infrastructure/Install/MigrationCoordinator.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Recheck state
* fix(tests): update concurrent race test for post-claim DetermineRuntimeLevel check
The winner now calls DetermineRuntimeLevel() once from the post-claim check
and must see Upgrading; the loser polls twice before seeing Run. Transition
the mock on the second call instead of the first.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Cache cacheversion on scope
* Add tests
* Cache: Use ConcurrentDictionary for the inner per-scope version map
The inner Dictionary<string, Guid> was not thread-safe. Replacing it
with ConcurrentDictionary<string, Guid> removes the hidden assumption
that the root scope is only accessed from a single thread at a time.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Update src/Umbraco.Core/Cache/IRepositoryCacheVersionAccessor.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update tests/Umbraco.Tests.UnitTests/Umbraco.Web.Common/Cache/RepositoryCacheVersionAccessorTests.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.Common/Cache/RepositoryCacheVersionAccessor.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Skips failing test so we can run nightly. THIS NEEDS TO BE REVERTED
* Revert "Skips failing test so we can run nightly. THIS NEEDS TO BE REVERTED"
This reverts commit c34d1736c336b3fcf7803b44e88f6018fa45c275.
* Only write version once pr. scope
* Add tests
* Remove unnececary locks
* Fix thread-safety: replace HashSet with ConcurrentHashSet and use GetOrAdd to eliminate TOCTOU races
* Add unit tests for RepositoryCacheVersionService
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
* Add benchmark test for measuring improvements to children and descendant retrieval.
* Remove unnecessary sort from retrieval of children.
* Return the result of the filtered collection of children/decendants without materialising.
* Lazily build property wrappers when materializing IPublishedContent.
* Cache the ordered children list on NavigationNode.
* Cache descendants per parent on the navigation snapshot.
* Add synchronous fast path for retrieved of cached content.
* Additional unit tests.
* Add TODO to make UpdateSortOrder internal.
* Addressed code review feedback.
* Further unit tests.
* Future-proofed code comments.
* Add benchmark test for measuring improvements to children and descendant retrieval.
* Remove unnecessary sort from retrieval of children.
* Return the result of the filtered collection of children/decendants without materialising.
* Lazily build property wrappers when materializing IPublishedContent.
* Cache the ordered children list on NavigationNode.
* Cache descendants per parent on the navigation snapshot.
* Add synchronous fast path for retrieved of cached content.
* Additional unit tests.
* Add TODO to make UpdateSortOrder internal.
* Addressed code review feedback.
* Further unit tests.
* Future-proofed code comments.
* Add benchmark test for measuring improvements to children and descendant retrieval.
* Remove unnecessary sort from retrieval of children.
* Return the result of the filtered collection of children/decendants without materialising.
* Lazily build property wrappers when materializing IPublishedContent.
* Cache the ordered children list on NavigationNode.
* Cache descendants per parent on the navigation snapshot.
* Add synchronous fast path for retrieved of cached content.
* Additional unit tests.
* Add TODO to make UpdateSortOrder internal.
* Addressed code review feedback.
* Further unit tests.
* Future-proofed code comments.
Correct the gating of the call to UseOutputCache() to only proceed Umbraco managed caching via configuration is enabled, and not consider existing implementation specific registrations.
Correct the gating of the call to UseOutputCache() to only proceed Umbraco managed caching via configuration is enabled, and not consider existing implementation specific registrations.
Adds a 'Default UI language vs fallback culture' subsection so package
authors don't conflate the active UI locale (en-US by default) with the
fallback dictionary culture (en). A third-party language pack overriding
canonical keys must declare 'culture: en-US' on a default install,
otherwise the registry filters it out — the keys come from en.ts but
the override extension's culture has to match the active locale.
Surfaced by a tester report after PR #22743 merged the login screen's
localization into the backoffice client: the registry was forcing 'en'
active at boot (fixed in PR #22822) which masked the distinction, and
the docs didn't spell it out either.
* Localization: Honor DefaultUILanguage on initial load (closes#22808)
Closes#22808.
Previously, the configured DefaultUILanguage was silently overridden to
'en' at startup because the UmbLocalizationRegistry constructor called
loadLanguage(UMB_DEFAULT_LOCALIZATION_CULTURE) unconditionally. The
configured locale rendered into <html lang="..."> by Razor never had a
chance to flow through to the active language.
Changes:
- localization.registry.ts: stop forcing the active language to 'en'
in the constructor. Initial state is canonicalised from
document.documentElement.lang, falling back to 'en' for empty or
malformed input. The extension filter now always includes the
default culture alongside the active locale so 'en' translations
remain available as a key-level fallback regardless of which
language is active. A synchronous tap mirrors the active locale to
document.lang and the manager when the state changes, so a fresh
element rendered between loadLanguage() and the async translation
load picks up the right language immediately.
- localization.manager.ts: drop the MutationObserver on
document.documentElement and rely on the registry as the single
channel for language changes. setActiveLanguage accepts a `silent`
option so the synchronous tap can update fields without firing a
consumer notification (translations may still be loading). A new
notifyLanguageChanged() method is fired by the registry once
translations are in place.
- app.element.ts: subscribe to umbLocalizationRegistry.currentLanguage
in connectedCallback and mirror it onto the host element's lang
attribute, so myApp.lang reflects the source of truth rather than a
stale snapshot of <html lang>.
- auth.element.ts (login app): same lang subscription, plus after the
slim backoffice controller registers extensions, prefer the
visitor's navigator.language if a matching localization extension
exists (falls through baseName -> language -> en automatically).
Tests: new initialization tests for the registry, manager
setActiveLanguage tests, and the controller tests refactored to use
the new explicit setActiveLanguage API instead of writing directly to
document.documentElement.lang.
* Login: Only override DefaultUILanguage with navigator.language when default has no translation
If the admin sets DefaultUILanguage to a language we have a translation for,
respect that choice over the visitor's browser language. Falling back to
navigator.language only when the configured default isn't available avoids
silently ignoring the admin's explicit setting (e.g., DefaultUILanguage='da-DK'
on a site whose visitor's browser is 'en-GB' should still show Danish).
* Simplify: split setActiveLanguage from notifyLanguageChanged
Drop the silent option in favor of two intent-revealing methods:
setActiveLanguage updates the active language and direction without
side-effects; notifyLanguageChanged tells all connected controllers
to re-render against the current state. Callers compose them based
on what they need (the registry's pipeline updates language sync
then flushes notifications after async translation load).
Also extracts baseLocaleOf() helper, simplifies the navigator.language
match logic in the login app's #applyPreferredLanguage, and removes
narration-style comments in the new code.
* Restore deprecated UmbLocalizationManager.updateAll for backward compat
The old MutationObserver-driven updateAll() field was technically part
of the manager's public surface. Restore it as a deprecated alias that
reads document.lang/dir and forwards to setActiveLanguage + notifyLanguageChanged,
with a runtime UmbDeprecation warning pointing consumers at the new API.
* Fix deprecation removal version to v20 + correct baseLocaleOf JSDoc
Per the deprecation policy in CLAUDE.md (current major + 2): a method
deprecated in v18 must remain through v19 before removal, so the
earliest removal is v20, not v19.
Also corrects the baseLocaleOf JSDoc — Intl.Locale.baseName can include
script subtags (e.g. 'zh-Hant-TW'), not just language and region.
* Scope the active language to the host element, drop navigator.language
- Razor now sets `lang` on `<umb-app>` and `<umb-auth>` from
DefaultUILanguage. The element passes its lang through on connect, so
the host owns its own scope — future multi-backoffice scenarios (e.g.
signing into two Umbraco Cloud sites in the same document) get their
own language without fighting over a global `<html lang>`.
- The registry no longer reads or writes `document.documentElement.lang`.
Host elements drive it via `loadLanguage()`; `<html lang>` stays as
whatever Razor rendered.
- Removed the navigator.language preference detection in the login app.
Not in scope for the bug fix and adds behavior the admin can't opt out
of. The existing current-user-locale flow already handles per-user
preference after login.
- Tests updated to assert on `umbLocalizationManager.documentLanguage`
instead of `document.documentElement.lang`.
* Set <html lang="en"> to match the static (noscript) text in the templates
The page's `<html lang>` should describe the language of the document's
own innate content. Both Index.cshtml files only contain English static
text (the noscript fallback), so the page-level lang is now "en".
The dynamic UI inside <umb-app> / <umb-auth> carries its own `lang`
attribute (from DefaultUILanguage), which overrides for that subtree —
correct per the HTML spec for language inheritance.
* Drop deprecated UmbLocalizationManager.updateAll
It was public as an artifact of being an arrow function so it could be
passed to a MutationObserver without binding — not because it was
intended as part of the public API. External usage is effectively
zero, and the new explicit setActiveLanguage + notifyLanguageChanged
covers anyone who did reach for it.
* Docs: document active-language-on-host pattern in package-development.md
After PR #22822, the active UI language is driven by the shell elements
(<umb-app>, <umb-auth>) via their own lang attribute, not by <html lang>.
Document that so future contributors don't reach for the global.
* Collapse setActiveLanguage + notifyLanguageChanged into one method
The silent-write path is just `manager.documentLanguage = ...` — no new
method needed; the field is already public and was always writable. The
notify path keeps setActiveLanguage, which now both sets and notifies.
Net: one new public method on the manager instead of two.
* Inline the active-language write in the registry, drop setActiveLanguage
The previous version added setActiveLanguage on the manager as
a 'cleaner API' than direct field writes. But the manager's fields
(documentLanguage, documentDirection, connectedControllers) have
always been public, the registry is the only caller, and the wrapper
was just more public surface to maintain through the eventual
manager/registry collapse.
Net: -70 lines across the test file, no new public methods on the
manager, the registry pipeline writes the fields and iterates the
controllers directly where it would have called setActiveLanguage.
* Document that documentLanguage/Direction are read-only for consumers
Note in JSDoc that the only supported way to change the active language
is umbLocalizationRegistry.loadLanguage(). The fields stay writable for
the registry pipeline (cross-module internal); the comment is here so
the next contributor doesn't reach for them as a shortcut and end up
with the manager state out of sync with what's actually loaded.
* Localization: Honor DefaultUILanguage on initial load (closes#22808)
Closes#22808.
Previously, the configured DefaultUILanguage was silently overridden to
'en' at startup because the UmbLocalizationRegistry constructor called
loadLanguage(UMB_DEFAULT_LOCALIZATION_CULTURE) unconditionally. The
configured locale rendered into <html lang="..."> by Razor never had a
chance to flow through to the active language.
Changes:
- localization.registry.ts: stop forcing the active language to 'en'
in the constructor. Initial state is canonicalised from
document.documentElement.lang, falling back to 'en' for empty or
malformed input. The extension filter now always includes the
default culture alongside the active locale so 'en' translations
remain available as a key-level fallback regardless of which
language is active. A synchronous tap mirrors the active locale to
document.lang and the manager when the state changes, so a fresh
element rendered between loadLanguage() and the async translation
load picks up the right language immediately.
- localization.manager.ts: drop the MutationObserver on
document.documentElement and rely on the registry as the single
channel for language changes. setActiveLanguage accepts a `silent`
option so the synchronous tap can update fields without firing a
consumer notification (translations may still be loading). A new
notifyLanguageChanged() method is fired by the registry once
translations are in place.
- app.element.ts: subscribe to umbLocalizationRegistry.currentLanguage
in connectedCallback and mirror it onto the host element's lang
attribute, so myApp.lang reflects the source of truth rather than a
stale snapshot of <html lang>.
- auth.element.ts (login app): same lang subscription, plus after the
slim backoffice controller registers extensions, prefer the
visitor's navigator.language if a matching localization extension
exists (falls through baseName -> language -> en automatically).
Tests: new initialization tests for the registry, manager
setActiveLanguage tests, and the controller tests refactored to use
the new explicit setActiveLanguage API instead of writing directly to
document.documentElement.lang.
* Login: Only override DefaultUILanguage with navigator.language when default has no translation
If the admin sets DefaultUILanguage to a language we have a translation for,
respect that choice over the visitor's browser language. Falling back to
navigator.language only when the configured default isn't available avoids
silently ignoring the admin's explicit setting (e.g., DefaultUILanguage='da-DK'
on a site whose visitor's browser is 'en-GB' should still show Danish).
* Simplify: split setActiveLanguage from notifyLanguageChanged
Drop the silent option in favor of two intent-revealing methods:
setActiveLanguage updates the active language and direction without
side-effects; notifyLanguageChanged tells all connected controllers
to re-render against the current state. Callers compose them based
on what they need (the registry's pipeline updates language sync
then flushes notifications after async translation load).
Also extracts baseLocaleOf() helper, simplifies the navigator.language
match logic in the login app's #applyPreferredLanguage, and removes
narration-style comments in the new code.
* Restore deprecated UmbLocalizationManager.updateAll for backward compat
The old MutationObserver-driven updateAll() field was technically part
of the manager's public surface. Restore it as a deprecated alias that
reads document.lang/dir and forwards to setActiveLanguage + notifyLanguageChanged,
with a runtime UmbDeprecation warning pointing consumers at the new API.
* Fix deprecation removal version to v20 + correct baseLocaleOf JSDoc
Per the deprecation policy in CLAUDE.md (current major + 2): a method
deprecated in v18 must remain through v19 before removal, so the
earliest removal is v20, not v19.
Also corrects the baseLocaleOf JSDoc — Intl.Locale.baseName can include
script subtags (e.g. 'zh-Hant-TW'), not just language and region.
* Scope the active language to the host element, drop navigator.language
- Razor now sets `lang` on `<umb-app>` and `<umb-auth>` from
DefaultUILanguage. The element passes its lang through on connect, so
the host owns its own scope — future multi-backoffice scenarios (e.g.
signing into two Umbraco Cloud sites in the same document) get their
own language without fighting over a global `<html lang>`.
- The registry no longer reads or writes `document.documentElement.lang`.
Host elements drive it via `loadLanguage()`; `<html lang>` stays as
whatever Razor rendered.
- Removed the navigator.language preference detection in the login app.
Not in scope for the bug fix and adds behavior the admin can't opt out
of. The existing current-user-locale flow already handles per-user
preference after login.
- Tests updated to assert on `umbLocalizationManager.documentLanguage`
instead of `document.documentElement.lang`.
* Set <html lang="en"> to match the static (noscript) text in the templates
The page's `<html lang>` should describe the language of the document's
own innate content. Both Index.cshtml files only contain English static
text (the noscript fallback), so the page-level lang is now "en".
The dynamic UI inside <umb-app> / <umb-auth> carries its own `lang`
attribute (from DefaultUILanguage), which overrides for that subtree —
correct per the HTML spec for language inheritance.
* Drop deprecated UmbLocalizationManager.updateAll
It was public as an artifact of being an arrow function so it could be
passed to a MutationObserver without binding — not because it was
intended as part of the public API. External usage is effectively
zero, and the new explicit setActiveLanguage + notifyLanguageChanged
covers anyone who did reach for it.
* Docs: document active-language-on-host pattern in package-development.md
After PR #22822, the active UI language is driven by the shell elements
(<umb-app>, <umb-auth>) via their own lang attribute, not by <html lang>.
Document that so future contributors don't reach for the global.
* Collapse setActiveLanguage + notifyLanguageChanged into one method
The silent-write path is just `manager.documentLanguage = ...` — no new
method needed; the field is already public and was always writable. The
notify path keeps setActiveLanguage, which now both sets and notifies.
Net: one new public method on the manager instead of two.
* Inline the active-language write in the registry, drop setActiveLanguage
The previous version added setActiveLanguage on the manager as
a 'cleaner API' than direct field writes. But the manager's fields
(documentLanguage, documentDirection, connectedControllers) have
always been public, the registry is the only caller, and the wrapper
was just more public surface to maintain through the eventual
manager/registry collapse.
Net: -70 lines across the test file, no new public methods on the
manager, the registry pipeline writes the fields and iterates the
controllers directly where it would have called setActiveLanguage.
* Document that documentLanguage/Direction are read-only for consumers
Note in JSDoc that the only supported way to change the active language
is umbLocalizationRegistry.loadLanguage(). The fields stay writable for
the registry pipeline (cross-module internal); the comment is here so
the next contributor doesn't reach for them as a shortcut and end up
with the manager state out of sync with what's actually loaded.
* Localization: Honor DefaultUILanguage on initial load (closes#22808)
Closes#22808.
Previously, the configured DefaultUILanguage was silently overridden to
'en' at startup because the UmbLocalizationRegistry constructor called
loadLanguage(UMB_DEFAULT_LOCALIZATION_CULTURE) unconditionally. The
configured locale rendered into <html lang="..."> by Razor never had a
chance to flow through to the active language.
Changes:
- localization.registry.ts: stop forcing the active language to 'en'
in the constructor. Initial state is canonicalised from
document.documentElement.lang, falling back to 'en' for empty or
malformed input. The extension filter now always includes the
default culture alongside the active locale so 'en' translations
remain available as a key-level fallback regardless of which
language is active. A synchronous tap mirrors the active locale to
document.lang and the manager when the state changes, so a fresh
element rendered between loadLanguage() and the async translation
load picks up the right language immediately.
- localization.manager.ts: drop the MutationObserver on
document.documentElement and rely on the registry as the single
channel for language changes. setActiveLanguage accepts a `silent`
option so the synchronous tap can update fields without firing a
consumer notification (translations may still be loading). A new
notifyLanguageChanged() method is fired by the registry once
translations are in place.
- app.element.ts: subscribe to umbLocalizationRegistry.currentLanguage
in connectedCallback and mirror it onto the host element's lang
attribute, so myApp.lang reflects the source of truth rather than a
stale snapshot of <html lang>.
- auth.element.ts (login app): same lang subscription, plus after the
slim backoffice controller registers extensions, prefer the
visitor's navigator.language if a matching localization extension
exists (falls through baseName -> language -> en automatically).
Tests: new initialization tests for the registry, manager
setActiveLanguage tests, and the controller tests refactored to use
the new explicit setActiveLanguage API instead of writing directly to
document.documentElement.lang.
* Login: Only override DefaultUILanguage with navigator.language when default has no translation
If the admin sets DefaultUILanguage to a language we have a translation for,
respect that choice over the visitor's browser language. Falling back to
navigator.language only when the configured default isn't available avoids
silently ignoring the admin's explicit setting (e.g., DefaultUILanguage='da-DK'
on a site whose visitor's browser is 'en-GB' should still show Danish).
* Simplify: split setActiveLanguage from notifyLanguageChanged
Drop the silent option in favor of two intent-revealing methods:
setActiveLanguage updates the active language and direction without
side-effects; notifyLanguageChanged tells all connected controllers
to re-render against the current state. Callers compose them based
on what they need (the registry's pipeline updates language sync
then flushes notifications after async translation load).
Also extracts baseLocaleOf() helper, simplifies the navigator.language
match logic in the login app's #applyPreferredLanguage, and removes
narration-style comments in the new code.
* Restore deprecated UmbLocalizationManager.updateAll for backward compat
The old MutationObserver-driven updateAll() field was technically part
of the manager's public surface. Restore it as a deprecated alias that
reads document.lang/dir and forwards to setActiveLanguage + notifyLanguageChanged,
with a runtime UmbDeprecation warning pointing consumers at the new API.
* Fix deprecation removal version to v20 + correct baseLocaleOf JSDoc
Per the deprecation policy in CLAUDE.md (current major + 2): a method
deprecated in v18 must remain through v19 before removal, so the
earliest removal is v20, not v19.
Also corrects the baseLocaleOf JSDoc — Intl.Locale.baseName can include
script subtags (e.g. 'zh-Hant-TW'), not just language and region.
* Scope the active language to the host element, drop navigator.language
- Razor now sets `lang` on `<umb-app>` and `<umb-auth>` from
DefaultUILanguage. The element passes its lang through on connect, so
the host owns its own scope — future multi-backoffice scenarios (e.g.
signing into two Umbraco Cloud sites in the same document) get their
own language without fighting over a global `<html lang>`.
- The registry no longer reads or writes `document.documentElement.lang`.
Host elements drive it via `loadLanguage()`; `<html lang>` stays as
whatever Razor rendered.
- Removed the navigator.language preference detection in the login app.
Not in scope for the bug fix and adds behavior the admin can't opt out
of. The existing current-user-locale flow already handles per-user
preference after login.
- Tests updated to assert on `umbLocalizationManager.documentLanguage`
instead of `document.documentElement.lang`.
* Set <html lang="en"> to match the static (noscript) text in the templates
The page's `<html lang>` should describe the language of the document's
own innate content. Both Index.cshtml files only contain English static
text (the noscript fallback), so the page-level lang is now "en".
The dynamic UI inside <umb-app> / <umb-auth> carries its own `lang`
attribute (from DefaultUILanguage), which overrides for that subtree —
correct per the HTML spec for language inheritance.
* Drop deprecated UmbLocalizationManager.updateAll
It was public as an artifact of being an arrow function so it could be
passed to a MutationObserver without binding — not because it was
intended as part of the public API. External usage is effectively
zero, and the new explicit setActiveLanguage + notifyLanguageChanged
covers anyone who did reach for it.
* Docs: document active-language-on-host pattern in package-development.md
After PR #22822, the active UI language is driven by the shell elements
(<umb-app>, <umb-auth>) via their own lang attribute, not by <html lang>.
Document that so future contributors don't reach for the global.
* Collapse setActiveLanguage + notifyLanguageChanged into one method
The silent-write path is just `manager.documentLanguage = ...` — no new
method needed; the field is already public and was always writable. The
notify path keeps setActiveLanguage, which now both sets and notifies.
Net: one new public method on the manager instead of two.
* Inline the active-language write in the registry, drop setActiveLanguage
The previous version added setActiveLanguage on the manager as
a 'cleaner API' than direct field writes. But the manager's fields
(documentLanguage, documentDirection, connectedControllers) have
always been public, the registry is the only caller, and the wrapper
was just more public surface to maintain through the eventual
manager/registry collapse.
Net: -70 lines across the test file, no new public methods on the
manager, the registry pipeline writes the fields and iterates the
controllers directly where it would have called setActiveLanguage.
* Document that documentLanguage/Direction are read-only for consumers
Note in JSDoc that the only supported way to change the active language
is umbLocalizationRegistry.loadLanguage(). The fields stay writable for
the registry pipeline (cross-module internal); the comment is here so
the next contributor doesn't reach for them as a shortcut and end up
with the manager state out of sync with what's actually loaded.
* Elements: Fix UdiEntityTypeHelper.ToUmbracoObjectType() for Element entities
Adds the missing Element and ElementContainer cases so the conversion is
symmetric with FromUmbracoObjectType().
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Remove UdiEntityTypeHelperTests
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Blueprints: Fix UdiEntityTypeHelper.ToUmbracoObjectType() for document blueprint containers
Adds the missing DocumentBlueprintContainer case so the conversion is
symmetric with FromUmbracoObjectType().
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add missing case for MemberTypeContainer.
* Use reflection to ensure other future missed cases are surfaced without having to explicitly extend the tests.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Blueprints: Fix UdiEntityTypeHelper.ToUmbracoObjectType() for document blueprint containers
Adds the missing DocumentBlueprintContainer case so the conversion is
symmetric with FromUmbracoObjectType().
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add missing case for MemberTypeContainer.
* Use reflection to ensure other future missed cases are surfaced without having to explicitly extend the tests.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Blueprints: Fix UdiEntityTypeHelper.ToUmbracoObjectType() for document blueprint containers
Adds the missing DocumentBlueprintContainer case so the conversion is
symmetric with FromUmbracoObjectType().
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add missing case for MemberTypeContainer.
* Use reflection to ensure other future missed cases are surfaced without having to explicitly extend the tests.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Adds the missing GetUdi() overloads for IElement so v18 Global Elements
produce their umb://element/{key} identifier through the same extension
surface used for documents, media and members.
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add auto upgrade coordination for load balanced setups
* Add tests
* Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* fix(infrastructure): move TryBecomeLeaderAsync inside try/catch in UnattendedUpgradeBackgroundService
Ensures DB exceptions thrown during migration coordination set BootFailed
rather than faulting the background service silently.
* Fix feedback
* Update src/Umbraco.Infrastructure/Install/MigrationCoordinator.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Recheck state
* fix(tests): update concurrent race test for post-claim DetermineRuntimeLevel check
The winner now calls DetermineRuntimeLevel() once from the post-claim check
and must see Upgrading; the loser polls twice before seeing Run. Transition
the mock on the second call instead of the first.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* migrate relation type table collection view to table kind
* update page locator
* Request relations when workspace unique is set
* fix types
* split models
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Use constant for relation type collection alias + remove redundant fields
* Add observer keys in relation-type workspace view
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Cache cacheversion on scope
* Add tests
* Cache: Use ConcurrentDictionary for the inner per-scope version map
The inner Dictionary<string, Guid> was not thread-safe. Replacing it
with ConcurrentDictionary<string, Guid> removes the hidden assumption
that the root scope is only accessed from a single thread at a time.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Update src/Umbraco.Core/Cache/IRepositoryCacheVersionAccessor.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update tests/Umbraco.Tests.UnitTests/Umbraco.Web.Common/Cache/RepositoryCacheVersionAccessorTests.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.Common/Cache/RepositoryCacheVersionAccessor.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Skips failing test so we can run nightly. THIS NEEDS TO BE REVERTED
* Revert "Skips failing test so we can run nightly. THIS NEEDS TO BE REVERTED"
This reverts commit c34d1736c336b3fcf7803b44e88f6018fa45c275.
* Only write version once pr. scope
* Add tests
* Remove unnececary locks
* Fix thread-safety: replace HashSet with ConcurrentHashSet and use GetOrAdd to eliminate TOCTOU races
* Add unit tests for RepositoryCacheVersionService
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
Mocks: Add missing signalR property to mock server configuration response
The GetServerConfigurationResponse type was updated in #22700 to require
a signalR.skipNegotiation property, but the MSW mock handler was not
updated to match, causing a tsc compilation error.
Mocks: Add missing signalR property to mock server configuration response
The GetServerConfigurationResponse type was updated in #22700 to require
a signalR.skipNegotiation property, but the MSW mock handler was not
updated to match, causing a tsc compilation error.
* Core: Preserve path case in ShadowFileSystem
ShadowFileSystem stored staged files at their original case via _sfs.AddFile
but tracked them under a lowercased key (NormPath calling ToLowerInvariant).
On Complete(), Inner.AddFile(kvp.Key, _sfs.GetFullPath(kvp.Key)) reconstructed
the staged file's path from the lowercased key, so on case-sensitive file
systems (Linux) File.Move failed with FileNotFoundException whenever a path
contained any uppercase character.
Drop the ToLowerInvariant from NormPath and switch the tracking dictionary
to StringComparer.OrdinalIgnoreCase. Lookups remain case-insensitive
(matching Windows semantics) while the stored key now matches what was
written to disk. IsChild/IsDescendant updated to OrdinalIgnoreCase
StartsWith for consistency.
Added regression test reproducing the original FileNotFoundException with
Views/PageNotFound.cshtml.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Rename regression test to follow Can_ naming convention
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Track canonical staged path per shadow node
The case-insensitive node dictionary preserved only the first inserted
key, so re-staging a logical path with a different case (e.g. AddFile
"Views/Foo.cshtml" then "views/foo.cshtml") wrote a phantom second file
to _sfs on Linux while Complete still resolved the original key — leaving
orphaned shadow files and committing stale content.
Track the original-case staged path on each ShadowNode and route all
_sfs operations (AddFile, OpenFile, GetFullPath, GetLastModified,
GetCreated, GetSize, MoveFile, Complete) through that canonical path.
Inner.AddFile on commit still uses the stored dictionary key, so the
destination case in the inner file system is unchanged.
Expanded the regression test to also exercise OpenFile, GetSize and
AddFile against a different-cased path, and to assert that the staged
file is written exactly once.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Make ShadowNode.CanonicalPath non-nullable
Every node now carries the original-case path it tracks, set at construction.
This removes the defensive 'sf.CanonicalPath ?? path' fallbacks at the read
sites (OpenFile, GetFullPath, GetLastModified, GetCreated, GetSize, Complete)
which were unreachable but noise.
The GetCanonicalPath helper is gone; AddFile and MoveFile now use the existing
node variable inline ('sf?.CanonicalPath ?? path' — node can legitimately be
null when staging a path for the first time).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address Copilot review: normalize delete key, cross-platform test
DeleteDirectory(recursive=false) stored the deletion marker under the
caller-supplied path (which can contain backslashes) instead of the
normalized key, so a follow-up NormPath-based lookup could miss the
deletion and IsChild scans could become inconsistent. Use normPath.
The shadow-second-file assertion in the regression test used
File.Exists on a different-cased path; that returns true on
case-insensitive file systems (Windows / default macOS) regardless of
the actual stored case, so the assertion was platform-dependent.
Replaced it with a directory-count check that's cross-platform.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add cross-platform regression test so any reversion would be caught on a non-case sensitive file system.
* Cleaned up warnings, obsoletions and comments in the existing tests.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
(cherry picked from commit abfa8cb144)
* Core: Preserve path case in ShadowFileSystem
ShadowFileSystem stored staged files at their original case via _sfs.AddFile
but tracked them under a lowercased key (NormPath calling ToLowerInvariant).
On Complete(), Inner.AddFile(kvp.Key, _sfs.GetFullPath(kvp.Key)) reconstructed
the staged file's path from the lowercased key, so on case-sensitive file
systems (Linux) File.Move failed with FileNotFoundException whenever a path
contained any uppercase character.
Drop the ToLowerInvariant from NormPath and switch the tracking dictionary
to StringComparer.OrdinalIgnoreCase. Lookups remain case-insensitive
(matching Windows semantics) while the stored key now matches what was
written to disk. IsChild/IsDescendant updated to OrdinalIgnoreCase
StartsWith for consistency.
Added regression test reproducing the original FileNotFoundException with
Views/PageNotFound.cshtml.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Rename regression test to follow Can_ naming convention
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Track canonical staged path per shadow node
The case-insensitive node dictionary preserved only the first inserted
key, so re-staging a logical path with a different case (e.g. AddFile
"Views/Foo.cshtml" then "views/foo.cshtml") wrote a phantom second file
to _sfs on Linux while Complete still resolved the original key — leaving
orphaned shadow files and committing stale content.
Track the original-case staged path on each ShadowNode and route all
_sfs operations (AddFile, OpenFile, GetFullPath, GetLastModified,
GetCreated, GetSize, MoveFile, Complete) through that canonical path.
Inner.AddFile on commit still uses the stored dictionary key, so the
destination case in the inner file system is unchanged.
Expanded the regression test to also exercise OpenFile, GetSize and
AddFile against a different-cased path, and to assert that the staged
file is written exactly once.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Make ShadowNode.CanonicalPath non-nullable
Every node now carries the original-case path it tracks, set at construction.
This removes the defensive 'sf.CanonicalPath ?? path' fallbacks at the read
sites (OpenFile, GetFullPath, GetLastModified, GetCreated, GetSize, Complete)
which were unreachable but noise.
The GetCanonicalPath helper is gone; AddFile and MoveFile now use the existing
node variable inline ('sf?.CanonicalPath ?? path' — node can legitimately be
null when staging a path for the first time).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address Copilot review: normalize delete key, cross-platform test
DeleteDirectory(recursive=false) stored the deletion marker under the
caller-supplied path (which can contain backslashes) instead of the
normalized key, so a follow-up NormPath-based lookup could miss the
deletion and IsChild scans could become inconsistent. Use normPath.
The shadow-second-file assertion in the regression test used
File.Exists on a different-cased path; that returns true on
case-insensitive file systems (Windows / default macOS) regardless of
the actual stored case, so the assertion was platform-dependent.
Replaced it with a directory-count check that's cross-platform.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add cross-platform regression test so any reversion would be caught on a non-case sensitive file system.
* Cleaned up warnings, obsoletions and comments in the existing tests.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
(cherry picked from commit abfa8cb144)
* Core: Preserve path case in ShadowFileSystem
ShadowFileSystem stored staged files at their original case via _sfs.AddFile
but tracked them under a lowercased key (NormPath calling ToLowerInvariant).
On Complete(), Inner.AddFile(kvp.Key, _sfs.GetFullPath(kvp.Key)) reconstructed
the staged file's path from the lowercased key, so on case-sensitive file
systems (Linux) File.Move failed with FileNotFoundException whenever a path
contained any uppercase character.
Drop the ToLowerInvariant from NormPath and switch the tracking dictionary
to StringComparer.OrdinalIgnoreCase. Lookups remain case-insensitive
(matching Windows semantics) while the stored key now matches what was
written to disk. IsChild/IsDescendant updated to OrdinalIgnoreCase
StartsWith for consistency.
Added regression test reproducing the original FileNotFoundException with
Views/PageNotFound.cshtml.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Rename regression test to follow Can_ naming convention
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Track canonical staged path per shadow node
The case-insensitive node dictionary preserved only the first inserted
key, so re-staging a logical path with a different case (e.g. AddFile
"Views/Foo.cshtml" then "views/foo.cshtml") wrote a phantom second file
to _sfs on Linux while Complete still resolved the original key — leaving
orphaned shadow files and committing stale content.
Track the original-case staged path on each ShadowNode and route all
_sfs operations (AddFile, OpenFile, GetFullPath, GetLastModified,
GetCreated, GetSize, MoveFile, Complete) through that canonical path.
Inner.AddFile on commit still uses the stored dictionary key, so the
destination case in the inner file system is unchanged.
Expanded the regression test to also exercise OpenFile, GetSize and
AddFile against a different-cased path, and to assert that the staged
file is written exactly once.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Make ShadowNode.CanonicalPath non-nullable
Every node now carries the original-case path it tracks, set at construction.
This removes the defensive 'sf.CanonicalPath ?? path' fallbacks at the read
sites (OpenFile, GetFullPath, GetLastModified, GetCreated, GetSize, Complete)
which were unreachable but noise.
The GetCanonicalPath helper is gone; AddFile and MoveFile now use the existing
node variable inline ('sf?.CanonicalPath ?? path' — node can legitimately be
null when staging a path for the first time).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address Copilot review: normalize delete key, cross-platform test
DeleteDirectory(recursive=false) stored the deletion marker under the
caller-supplied path (which can contain backslashes) instead of the
normalized key, so a follow-up NormPath-based lookup could miss the
deletion and IsChild scans could become inconsistent. Use normPath.
The shadow-second-file assertion in the regression test used
File.Exists on a different-cased path; that returns true on
case-insensitive file systems (Windows / default macOS) regardless of
the actual stored case, so the assertion was platform-dependent.
Replaced it with a directory-count check that's cross-platform.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add cross-platform regression test so any reversion would be caught on a non-case sensitive file system.
* Cleaned up warnings, obsoletions and comments in the existing tests.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
The Generate API Docs CI step (npm run generate:ui-api-docs) has been
failing with 3284 TypeScript errors since the TS 5.9.3 -> 6.0.3 bump in
PR #22591. TS 6 stopped auto-loading @types/* under moduleResolution:
"bundler", so every .test.ts file in the program fails to find describe,
it, beforeEach, etc., and typedoc aborts before emitting anything.
Point typedoc at a dedicated tsconfig.typedoc.json that narrows include
to src/**/*.ts + index.ts and excludes *.test.ts and *.stories.ts.
Entry points come from package.json exports and all live under src/, so
the docs build no longer drags test files, stories, mocks, e2e specs,
or storybook stories through the TS program.
Verified locally: npm run generate:ui-api-docs exits 0 and writes
6533 files under src/Umbraco.Web.UI.Client/ui-api/.
The publish cleanse step strips the prerelease suffix from hoisted dependency
ranges via `semver.minVersion(...).major/minor/patch`. For `^2.0.0-rc.1`
this produced `^2.0.0`, which no published `@umbraco-ui/uui` version
currently satisfies, breaking extension installs against
`@umbraco-cms/backoffice@18.0.0-beta1`+.
Use the full SemVer (including any prerelease) as the floor so
`^2.0.0-rc.1` stays satisfiable by the actual published rc.
The publish cleanse step strips the prerelease suffix from hoisted dependency
ranges via `semver.minVersion(...).major/minor/patch`. For `^2.0.0-rc.1`
this produced `^2.0.0`, which no published `@umbraco-ui/uui` version
currently satisfies, breaking extension installs against
`@umbraco-cms/backoffice@18.0.0-beta1`+.
Use the full SemVer (including any prerelease) as the floor so
`^2.0.0-rc.1` stays satisfiable by the actual published rc.
* Mark ServerEventSender as distributed cache notification handler
* Batch and deduplicate notifications in ServerEventSender
* Introduce IDistributedCacheAsyncNotificationHandler<T> and use it in ServerEventSender
* Add ServerEventSender unit tests and address PR review feedback
* feat: adds `__uuiVersions` to system information output
* avoid printet the array of version by handle single or multiple versions
* feat: ensures type safety of global variable
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* transfer style to uui v2
* accordingly interactive state for document-links
* overflow clip for border radius appearance
* link style
* fix block grid area configuration
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Preserve user-supplied property editor UI group names.
* Add support for localised property editor groups, and use localised values for all core property editors.
* Fixed check to look for '#' as the first character of the provided group name.
* danish translation
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Mark ServerEventSender as distributed cache notification handler
* Batch and deduplicate notifications in ServerEventSender
* Introduce IDistributedCacheAsyncNotificationHandler<T> and use it in ServerEventSender
* Add ServerEventSender unit tests and address PR review feedback
* Mark ServerEventSender as distributed cache notification handler
* Batch and deduplicate notifications in ServerEventSender
* Introduce IDistributedCacheAsyncNotificationHandler<T> and use it in ServerEventSender
* Add ServerEventSender unit tests and address PR review feedback
* Updated locator for user group table
* Updated json builder for user groups permission due to element folder permission
* Updated api helper to match with element folder permission
* Updated tests and add comments for the failing tests
* Add submit button state to sort dialog.
* Guard against re-entrant submit in sort-children-of modal.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Set failed button state when sort-children-of submit throws.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
(cherry picked from commit dfe93c5639)
* Add submit button state to sort dialog.
* Guard against re-entrant submit in sort-children-of modal.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Set failed button state when sort-children-of submit throws.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
(cherry picked from commit dfe93c5639)
* Add submit button state to sort dialog.
* Guard against re-entrant submit in sort-children-of modal.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Set failed button state when sort-children-of submit throws.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add helper for registering custom backoffice OpenAPI documents
Bundles AddOpenApi, the [MapToApi]-aware ShouldInclude predicate, the
Umbraco schema reference ID convention, and AddOpenApiDocumentToUi
behind a single IUmbracoBuilder.AddBackOfficeOpenApiDocument call.
Authors pass documentName, an optional title (used both as Info.Title
and the UI dropdown label), and an optional configure callback that
runs last so it can override anything the helper sets. An optional
jsonOptionsName is forwarded to ReplaceOpenApiSchemaService for
documents that need schema-time JSON serialization aligned to a named
JsonOptions.
Schema reference ID logic moves out of ConfigureUmbracoOpenApiOptionsBase
into UmbracoSchemaIdGenerator.CreateSchemaReferenceId so both the new
helper and the base class share one source of truth. The extension
template's composer collapses to a single AddBackOfficeOpenApiDocument
call, with document Info.Version, backoffice security, and the operation
ID transformer staying in the configure callback.
* Refactor backoffice OpenAPI helper into a fluent builder
Replace the parameter-list AddBackOfficeOpenApiDocument helper with a
callback-based form that yields a BackOfficeOpenApiDocumentBuilder. The
builder owns its state and applies it to the IUmbracoBuilder once the
user callback returns, so authors don't need to remember a terminal
Build call. Extension methods can layer on (e.g.
WithBackOfficeAuthentication in Umbraco.Cms.Api.Management) without the
core helper carrying every opinion.
Defaults stay sensible: filtering by [MapToApi(documentName)], the
Umbraco schema reference IDs, and the tag/sort transformers that v17's
global Swashbuckle pipeline applied. UI dropdown registration is
opt-out via ExcludeFromUi rather than opt-in. JSON options for schema
generation are an opt-in via WithHttpJsonOptions (instance or factory),
described purely in terms of the schema effect.
Move UmbracoSchemaIdGenerator's CreateSchemaReferenceId wrapper out of
ConfigureUmbracoOpenApiOptionsBase so both the base config class and
the new builder share one source of truth, and update the
ContentTypeSchemaTransformer / unit test callsites accordingly. Refresh
the extension template to use the new shape.
* Rename WithHttpJsonOptions to WithJsonOptions
The Http qualifier was naming the .NET type rather than the intent.
The parameter type carries the disambiguation; the method name is now
intent-focused and the XML doc explains the use case (matching the
serialization conventions of the API endpoints the document describes).
* Add WithJsonOptions(string) overload for named HTTP JsonOptions
Convenience overload that accepts the registered name and resolves the
matching Microsoft.AspNetCore.Http.Json.JsonOptions via IOptionsMonitor.
Documents on all three WithJsonOptions overloads now explicitly name
the HTTP JsonOptions type so consumers know which framework type they
are configuring.
* Migrate Management API OpenAPI registration to AddBackOfficeOpenApiDocument
Replaces the AddUmbracoOpenApiDocument<ConfigureUmbracoManagementApiOpenApiOptions>
call with the new fluent builder. The custom config class becomes dead
code and is deleted; all per-document opinions (Info metadata, security
requirements, transformers, JSON options) move into the configuration
callback alongside the document registration.
Behavior preserved: same ShouldInclude (now via [MapToApi]-only since
all Management controllers carry the attribute through their base class),
same schema reference IDs, same operation IDs via UmbracoOperationIdTransformer,
same backoffice security requirements, same schema/operation transformers,
same named JSON options for schema generation.
* Cleanup unused usings
* Address PR review feedback on AddBackOfficeOpenApiDocument
Make UmbracoOperationIdTransformer part of the builder's defaults instead of
the Management API adding it explicitly, and expand the XML docs on
AddBackOfficeOpenApiDocument to spell out the defaults a caller opts into.
Add tests covering the new builder and its defaults:
- Unit tests for BackOfficeOpenApiDocumentBuilder defaults (CreateSchemaReferenceId,
ShouldInclude, ConfigureOpenApiOptions composition, WithTitle/WithUiTitle UI
dropdown handling, ExcludeFromUi).
- Integration tests that register sample controllers, fetch the generated OpenAPI
document and verify the defaults end-to-end: Info.Title from WithTitle,
MapToApi filtering, Umbraco operation-id and schema-id conventions (including
the version-suffix branch), tag-by-group-name and tag-first path sorting.
- Integration tests for the three WithJsonOptions overloads (instance, factory,
named) confirming the configured JsonOptions reach schema generation.
* Remove redundant operation-id override from extension template
UmbracoOperationIdTransformer is now part of the AddBackOfficeOpenApiDocument
defaults, so the template's custom action-name transformer would only overwrite
the work the default just did. Drop it, and consolidate the documentation
pointer to a single link.
* Narrow MimeTypesTransformer to JSON-equivalent variants and register it in AddBackOfficeOpenApiDocument
Filter only removes redundant JSON-equivalent MIME types (text/json,
application/*+json, text/plain) when application/json is present.
Non-JSON types like application/xml are preserved. Register the
transformer as a default in AddBackOfficeOpenApiDocument so custom
backoffice documents get the same treatment as Umbraco's own APIs.
* Register RequireNonNullablePropertiesSchemaTransformer in AddBackOfficeOpenApiDocument
* Apply review notes
- Drop RequireNonNullablePropertiesSchemaTransformer and MimeTypesTransformer
from the Management API's ConfigureOpenApiOptions block — both are now
defaults on the builder.
- Expand MimeTypesTransformer XML docs to reflect its broader role (it now
applies to every backoffice document, not just the Management API) and
correct the response-side inline comment.
- Move MimeTypesTransformerTests from the Delivery test folder/namespace to
the Api.Common test folder/namespace, since the transformer is no longer
Delivery-specific.
- Rename BackOfficeOpenApiDocumentExtensionTests to
UmbracoBuilderOpenApiExtensionsTests so the test fixture name matches the
concrete class under test.
* Dont fail silently on missing ambientscope
This makes it in line with other methods in the repo
* Pass on Cancellationtoken to the job to support gracefull job shutdown
(cherry picked from commit 5ae17ace6a)
* Dont fail silently on missing ambientscope
This makes it in line with other methods in the repo
* Pass on Cancellationtoken to the job to support gracefull job shutdown
(cherry picked from commit 5ae17ace6a)
* Dont fail silently on missing ambientscope
This makes it in line with other methods in the repo
* Pass on Cancellationtoken to the job to support gracefull job shutdown
* Login: Reuse backoffice localization for canonical login_* keys (closes#56402)
The login screen no longer ships its own localization tree. The slim backoffice controller registers the backoffice's built-in localization manifests, so all login screen text resolves from the same dictionary the in-backoffice auth view uses. Translators override one place; both screens reflect it.
All consumers in the Login project moved from auth_* to login_*. The Login project's localization/ directory is removed entirely. The auth.* keys it used to ship (form labels, mfa, invite, password reset) now live under login.* in the backoffice's en/da/de/nb/nl/sv lang files. Other backoffice languages fall back to en for these keys, automatically extending the login screen's language coverage.
* Backoffice localization: drop server-only email keys, add login.setPasswordInstruction in en/da/nb/sv
bottomText, resetPasswordEmailCopySubject, resetPasswordEmailCopyFormat, mfaSecurityCodeSubject and mfaSecurityCodeBody are read only by the server's own localization layer — they were dead weight in every backoffice lang dictionary that carried them. Removed across 23 lang files.
login.setPasswordInstruction is rendered on the new-password screen via the now-canonical login_* namespace; it was missing from en (the fallback), da, nb and sv. Added there using the same translation tone as the existing de/nl entries.
* Login: Honour legacy auth_greeting* overrides with UmbDeprecation warning
Translation packages still shipping 'auth_greeting0..6' overrides keep working on both welcome screens (the standalone login page and the in-backoffice umb-auth-view): when an auth_* greeting is registered the consumer prefers it, otherwise the canonical login_* key is used. Each legacy key triggers a one-time UmbDeprecation warning pointing at the canonical name. Scheduled for removal in v20.
* Fix Prettier formatting and correct issue references in deprecation message
Addresses Copilot review feedback on PR #22743:
- Run Prettier on the 6 backoffice lang files I added keys to (en/da/de/nb/nl/sv); the new entries used double quotes which violated the repo's singleQuote: true config and would have failed the format check.
- Update the UmbDeprecation 'solution' link and the inline source comments from #56402 (an ADO work item id) to #20082 (the actual GitHub issue tracking this work).
* Drop stale login_2fa* and login_mfaSecurityCodeMessage from bs.ts and cy.ts
Surfaced by 'devops/localization/compare-languages.js': bs and cy were the only lang files shipping these keys, and they have no en counterpart. The login_2fa* set is leftover from before the codebase renamed 2fa → mfa in the login flow (the live keys are login_mfa*). login_mfaSecurityCodeMessage is server-side only, like the other email-template keys cleaned up in 53ad52702e0. None of these are referenced anywhere in src/. The user-facing user_2fa* keys (consumed by current-user-mfa modals) are unrelated and untouched.
* Drop dead login_2fa* and login_mfaSecurityCodeMessage from nl, hr, tr
Same pattern as 26bc6211d27 (bs/cy cleanup), surfaced by re-running devops/localization/compare-languages.js after the previous pass:
- nl had both legacy 'login_2fa*' AND the canonical 'login_mfa*' (added in commit 1) sitting side by side after the auth.* → login.* port. Six true duplicates dropped, login_mfa* kept.
- hr and tr shipped legacy 'login_2fa*' that have no en counterpart, no consumer in src/, and no mfa pair locally. Dropped to align with en (the source of truth — every other locale should match it).
- All three files also still carried 'login_mfaSecurityCodeMessage' from the same family of server-side email-template keys cleaned up in 53ad52702e0; removed too.
user_2fa* / member_2fa keys are unrelated and untouched (consumed by current-user-mfa modals).
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
(cherry picked from commit def18e440f)
* Login: Consume sibling Umbraco.Web.UI.Client by source for v18 parity
The Login project previously depended on the published `@umbraco-cms/backoffice@^17.3.4` npm package for types, while at runtime the importmap served the in-repo v18 backoffice. The version mismatch forced `as any` workarounds and masked real API drift. Since v18 (with UUI 2.0) isn't on npm yet, switch Login to consume the sibling Client via a local `file:` dep so types and runtime align on v18.
Changes:
- Login `package.json`: `@umbraco-cms/backoffice` → `file:../Umbraco.Web.UI.Client`; added `pre{build,dev,watch}` hooks that run a guard script to fail fast when Client's `dist-cms/` is missing.
- Login `scripts/ensure-client-built.mjs`: new guard with a clear "build the Client first" message.
- Login `CLAUDE.md`: documents the contract and build ordering.
- StaticAssets `.csproj`: `BuildLogin` now depends on `BuildBackoffice` so MSBuild (and therefore the Azure pipeline) builds Client before Login automatically.
- Client `src/tsconfig.build.json`: `declaration: true` so `dist-cms/` ships `.d.ts`.
- Client `package.json`: new `build:types` step (`tsc --emitDeclarationOnly --incremental false && tsc-alias`) wired into `build:for:cms` after `build:workspaces`. Vite workspaces wipe their output dirs before rebuilding JS, stripping the tsc-emitted declarations; re-emitting after workspaces restores them. `tsc-alias` rewrites Client-internal path aliases (e.g. `@umbraco-cms/backoffice/external/lit`) to relative paths so sibling consumers can resolve them.
- `copy-to-cms.js`: filter `.d.ts` and `.tsbuildinfo` from the copy to `wwwroot/umbraco/backoffice` — they're only needed by sibling projects consuming `dist-cms` for types, not at runtime.
- `src/external/uui/vite.config.ts`: set `treeshake: false` so per-component `defineElement()` side-effect calls (used by UUI 2.0 for custom-element registration) are preserved in the bundle. Without this, `<uui-button>` etc. never register and the login screen renders empty controls.
- `src/external/uui/index.ts`: bare `import '@umbraco-ui/uui'` to make the side-effect intent explicit.
- Small v18-compat fixes for `Object.groupBy` (TS 8 types): removed stale `@ts-expect-error`, switched to `Object.entries` + `?? []` to satisfy the `Partial<Record>` return type.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address review feedback and fix CI
- Add `ignoreDeprecations: "6.0"` to `tsconfig.json` and the tsconfig generator to silence the TS 6.0 warning about the implicit baseUrl that TypeScript assigns when `paths` is declared. This was the CI `build` failure. The generator is also synced with the user's es2022 → es2024 bump.
- Drop the now-redundant `--declaration` flag from `build:for:npm` (tsconfig.build.json now has `declaration: true`, so the flag was duplicating intent).
- Align Login's `engines` with the Client's (`node >=24.13`, `npm >=11`) so `file:` install doesn't trip EBADENGINE.
- Guard script: hardcode the relative "../Umbraco.Web.UI.Client" path in the error message instead of interpolating the absolute path, which overflowed the ASCII box in CI logs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Login: update CLAUDE.md Node/npm versions to match engines
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* check-path-length: skip .d.ts/.tsbuildinfo and directory paths
The 120-char Windows MAX_PATH guard protects files that actually ship to
CMS installs. `.d.ts` and `.tsbuildinfo` live in `dist-cms/` for sibling
projects to consume as types and are filtered out by `copy-to-cms.js`
before reaching `wwwroot/umbraco/backoffice` — they never land on a
Windows CMS install. Directories on their own also don't trigger
MAX_PATH; only files within them do, and those are still checked.
Unblocks CI after enabling `declaration: true` in the Client build.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* check-path-length: extract exceedsPathLimit helper (CodeScene)
Decomposes the complex conditional flagged by CodeScene into a named
predicate with a docstring, clarifying when a path is reported.
* Login: switch to generated tsconfig paths; revert dist-cms type machinery
PR #22591 originally aligned Login's TypeScript types with the in-repo v18
backoffice by emitting `.d.ts` into Client's `dist-cms/` and consuming it
via a `file:` dep. That layered six side-effects across the Client build
(declaration: true, build:types step, tsc-alias in postbuild, copy-to-cms
filter, check:paths skip, MSBuild ordering). Reviewers pushed back.
This rework moves the type contract from "ship .d.ts in dist-cms" to
"point Login's tsconfig paths at Client's TypeScript source" — Login's
runtime behaviour is unchanged (vite still externalises /^@umbraco-cms/,
host importmap still serves the JS), only the type-resolution mechanism
swaps.
What's reverted (back to the pre-PR shape):
- src/Umbraco.Web.UI.Client/src/tsconfig.build.json: declaration: false
- src/Umbraco.Web.UI.Client/package.json: drops `build:types` script,
reverts `postbuild` to global-types only, drops `--declaration` from
the tsc CLI in `build:for:cms` and restores it in `build:for:npm`
- src/Umbraco.Web.UI.Client/devops/build/copy-to-cms.js: simple cpSync
- src/Umbraco.Web.UI.Client/devops/build/check-path-length.js: original
- src/Umbraco.Web.UI.Client/tsconfig.json + devops/tsconfig/index.js:
drops `ignoreDeprecations` (not needed once baseUrl is gone)
- src/Umbraco.Cms.StaticAssets/Umbraco.Cms.StaticAssets.csproj:
`BuildLogin` no longer depends on `BuildBackoffice`
What's new on the Login side:
- src/Umbraco.Web.UI.Login/devops/tsconfig/index.js: generator that
reads Client's `package.json` exports and emits a full `tsconfig.json`
with `paths` mapping every `@umbraco-cms/backoffice/<sub>` to
`../Umbraco.Web.UI.Client/src/.../index.ts`. Mirrors Client's existing
generator pattern (DON'T EDIT header, JSON.stringify with tabs).
- src/Umbraco.Web.UI.Login/tsconfig.json: regenerated; standalone `tsc`
works (no `--project` needed) and 140 path aliases resolve types
directly from Client's source.
- src/Umbraco.Web.UI.Login/package.json: drops `@umbraco-cms/backoffice`
npm dep entirely (file: was only nominal — types come via paths,
runtime via importmap, transitives via Client's own `node_modules`
which is `npm install`-ed by CI's backoffice-install.yml). Replaces
the `ensure-client-built` guard with the generator on `pre*` hooks
and adds `generate:tsconfig` for ad-hoc invocation.
- src/Umbraco.Web.UI.Login/CLAUDE.md: documents the new layered
contract (paths/externalisation/importmap) and the install-Client-
before-Login prerequisite.
- src/Umbraco.Web.UI.Login/scripts/ensure-client-built.mjs: deleted.
What stays from the original PR (independent fixes):
- src/Umbraco.Web.UI.Client/src/external/uui/{vite.config.ts,index.ts}:
`treeshake: false` + bare side-effect import — keeps UUI 2.0
per-component `defineElement` calls in the bundle so `<uui-button>`
etc. actually register.
- Object.groupBy cleanups in 6 element files (TS 8 type narrowing).
- Client tsconfig generator: target/lib bumped to ES2024, `baseUrl`
removed.
Verified locally:
- `cd Client && rm -rf dist-cms && cd ../Login && npx tsc` → clean
(proves Login compiles without Client's dist-cms)
- `cd Client && npm run build:for:cms` → 0 emitted .d.ts (back to
pre-PR shape), `check:paths` passes
- Login `npm run build` → 64 KB bundle (unchanged)
- Browser at https://localhost:44339/umbraco: UUI 2.0 components
render, login with `test@umbraco.com`/`test123456` succeeds and
redirects to /umbraco/section/content
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Login: address review — idempotent generator + correct MSBuild ordering
- StaticAssets.csproj: BuildLogin now depends on RestoreBackoffice (not
BuildBackoffice — Login doesn't need dist-cms types). Login's tsc walks
Client source via tsconfig path aliases and resolves transitive deps
(lit, rxjs, …) from Client's node_modules. Without this dependency a
fresh local `dotnet build` could run BuildLogin before Client is
installed; CI was already safe via backoffice-install.yml's npm ci.
- devops/tsconfig/index.js: skip rewrite when content is unchanged. Pre-
hooks ran the generator on every npm command and bumped tsconfig.json
mtime even when nothing changed, which can invalidate caches and rattle
watchers downstream. Read-then-compare-then-write makes the generator
truly idempotent.
- devops/tsconfig/index.js: derive the alias prefix from
`clientPkg.name` instead of hardcoding `@umbraco-cms/backoffice` so a
package rename can't silently break paths.
azure-pipelines.yml needs no changes — backoffice-install.yml already
runs `npm ci` in Client before dotnet build kicks in MSBuild.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Login: postinstall + dev-mode Vite alias + theme CSS path
Audit cleanup pass on the rework:
- Login package.json: collapse predev/prebuild/prewatch into a single
postinstall hook. The generator runs whenever npm install/ci runs
(locally + in CI via RestoreLogin's npm i + the dotnet build chain).
Removes the per-command "tsconfig.json already up to date" noise.
- Login vite.config.ts: in dev mode (`vite serve`), read `paths` from
the generated tsconfig.json and apply them as `resolve.alias` so Vite
can resolve `@umbraco-cms/backoffice/*` to Client source. Vite doesn't
honor tsconfig `paths` natively — without this `npm run dev` failed
with "Failed to resolve import @umbraco-cms/backoffice/utils ...".
Build mode (`vite build`) still externalises the namespace via the
unchanged rollupOptions.external regex; alias is dev-only.
- Login index.html: UUI 2.0 reorganised CSS — the old
`@umbraco-ui/uui-css/dist/uui-css.css` path no longer exists. Point
at `@umbraco-ui/uui/dist/themes/light.css` which is what Client now
ships. Path is relative through Client's node_modules since Login no
longer declares a UUI dep itself.
- Client input-entity-user-permission.element.ts: prettier flagged a
multi-line .map() arrow that should be inline; collapse to one line.
- Login CLAUDE.md: document the postinstall-driven generator.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Use Vite 8 native tsconfigPaths; drop helper plugin and trim comments
- Both vite.config.ts files use `resolve.tsconfigPaths: true` instead of the
`vite-tsconfig-paths` plugin. Plugin and dep removed.
- Trim explanatory comments on csproj target, generator, UUI vite config and
external/uui/index.ts to conclusions only.
* Login: tsconfig generator fails fast on unsupported exports shapes
Distinguish between the legitimate `.` self-reference (target === null) and
unexpected non-string targets (e.g., conditional exports objects). The latter
now throw with a clear message instead of being silently dropped from `paths`,
which would otherwise produce confusing 'Cannot find module' errors at tsc
time later.
* Login: allow Vite dev server to serve Client's UUI assets
The light.css imported from Client's node_modules pulls Lato fonts via
relative URL, which Vite refuses by default since they sit outside
Login's project root. Extend server.fs.allow to the parent directory
(both sibling projects).
* Client: regenerate tsconfig on postinstall
* Login: keep UUI registrations in dev mode
Vite 8's esbuild dep pre-bundle drops the per-component
`customElements.define()` side-effects in @umbraco-ui/uui (a known UUI
issue with Vite 8). Exclude UUI from optimizeDeps so it's served
unbundled in dev. Re-add the bare side-effect import in external/uui
so the entry module evaluates the chain. Production build is unaffected
(workspace's `treeshake: false` already preserves registrations).
Also document the new MSBuild Login targets in StaticAssets CLAUDE.md.
* Login: clarify why optimizeDeps.exclude is needed for UUI
Tested treeshake.moduleSideEffects: true in optimizeDeps.rollupOptions
on Vite 8 / Rolldown 1.0.0-rc.17 — registrations still get stripped.
Excluding the package from the pre-bundle is the only reliable workaround
until UUI's own Vite 8 upgrade lands. Comment captures the conclusion.
* Roll back Vite 8 → 7 in Client and Login
Vite 8.0.10 ships Rolldown 1.0.0-rc.17 which strips UUI 2.0
`customElements.define()` side-effects during dep pre-bundle, leaving
elements unregistered in dev mode. Rather than ship a v18 release tied
to a non-final Rolldown RC, revert the Vite bump and pick it up again
once Rolldown 1.0 final lands.
Changes:
- Client: vite ^8.0.10 → ^7.3.2; vite-plugin-static-copy ^4.1.0 → ^3.2.0;
re-add vite-tsconfig-paths plugin; drop native `resolve.tsconfigPaths`.
- Login: vite ^8.0.10 → ^7.3.2; add vite-tsconfig-paths; configure plugin
with `projects: ['./tsconfig.json', '../Umbraco.Web.UI.Client/tsconfig.json']`
so it can resolve `@umbraco-cms/backoffice/*` imports inside Client
source files (which would otherwise lack a discoverable tsconfig in
Login's project tree). Drop `optimizeDeps.exclude` (no longer needed
without Rolldown). Keep `server.fs.allow` for the cross-project font.
TypeScript 6 + ES2024 + tsconfig path generator + Login architectural
pivot all stay — those are independent of the Vite version.
Verified:
- Production https://localhost:44339/umbraco — login works
- Login dev http://localhost:5191/ — UUI registers, all custom elements defined
- Client dev http://localhost:5192/ — page loads, navigates to /section/content
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address Copilot review
- vite.config.ts (Login): narrow server.fs.allow from the parent dir to
Login + Client only, reducing the dev server's read scope.
- external/uui/vite.config.ts (Client): replace blanket `treeshake: false`
with `moduleSideEffects: (id) => id.includes('@umbraco-ui/uui')` so
Rollup keeps UUI's per-component registration calls but tree-shakes the
rest. Bundle stays at 516 KB / 96 registered tags.
* fix merge overwrites
* update package lock
* fix: do not autogenerate tsconfig on postinstall
* removes postinstall script
* chore: generates tsconfig
* chore: update lockfile
* docs: updates claude.md
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
(cherry picked from commit 8a73d713cd)
* Login: Reuse backoffice localization for canonical login_* keys (closes#56402)
The login screen no longer ships its own localization tree. The slim backoffice controller registers the backoffice's built-in localization manifests, so all login screen text resolves from the same dictionary the in-backoffice auth view uses. Translators override one place; both screens reflect it.
All consumers in the Login project moved from auth_* to login_*. The Login project's localization/ directory is removed entirely. The auth.* keys it used to ship (form labels, mfa, invite, password reset) now live under login.* in the backoffice's en/da/de/nb/nl/sv lang files. Other backoffice languages fall back to en for these keys, automatically extending the login screen's language coverage.
* Backoffice localization: drop server-only email keys, add login.setPasswordInstruction in en/da/nb/sv
bottomText, resetPasswordEmailCopySubject, resetPasswordEmailCopyFormat, mfaSecurityCodeSubject and mfaSecurityCodeBody are read only by the server's own localization layer — they were dead weight in every backoffice lang dictionary that carried them. Removed across 23 lang files.
login.setPasswordInstruction is rendered on the new-password screen via the now-canonical login_* namespace; it was missing from en (the fallback), da, nb and sv. Added there using the same translation tone as the existing de/nl entries.
* Login: Honour legacy auth_greeting* overrides with UmbDeprecation warning
Translation packages still shipping 'auth_greeting0..6' overrides keep working on both welcome screens (the standalone login page and the in-backoffice umb-auth-view): when an auth_* greeting is registered the consumer prefers it, otherwise the canonical login_* key is used. Each legacy key triggers a one-time UmbDeprecation warning pointing at the canonical name. Scheduled for removal in v20.
* Fix Prettier formatting and correct issue references in deprecation message
Addresses Copilot review feedback on PR #22743:
- Run Prettier on the 6 backoffice lang files I added keys to (en/da/de/nb/nl/sv); the new entries used double quotes which violated the repo's singleQuote: true config and would have failed the format check.
- Update the UmbDeprecation 'solution' link and the inline source comments from #56402 (an ADO work item id) to #20082 (the actual GitHub issue tracking this work).
* Drop stale login_2fa* and login_mfaSecurityCodeMessage from bs.ts and cy.ts
Surfaced by 'devops/localization/compare-languages.js': bs and cy were the only lang files shipping these keys, and they have no en counterpart. The login_2fa* set is leftover from before the codebase renamed 2fa → mfa in the login flow (the live keys are login_mfa*). login_mfaSecurityCodeMessage is server-side only, like the other email-template keys cleaned up in 53ad52702e0. None of these are referenced anywhere in src/. The user-facing user_2fa* keys (consumed by current-user-mfa modals) are unrelated and untouched.
* Drop dead login_2fa* and login_mfaSecurityCodeMessage from nl, hr, tr
Same pattern as 26bc6211d27 (bs/cy cleanup), surfaced by re-running devops/localization/compare-languages.js after the previous pass:
- nl had both legacy 'login_2fa*' AND the canonical 'login_mfa*' (added in commit 1) sitting side by side after the auth.* → login.* port. Six true duplicates dropped, login_mfa* kept.
- hr and tr shipped legacy 'login_2fa*' that have no en counterpart, no consumer in src/, and no mfa pair locally. Dropped to align with en (the source of truth — every other locale should match it).
- All three files also still carried 'login_mfaSecurityCodeMessage' from the same family of server-side email-template keys cleaned up in 53ad52702e0; removed too.
user_2fa* / member_2fa keys are unrelated and untouched (consumed by current-user-mfa modals).
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Login: Consume sibling Umbraco.Web.UI.Client by source for v18 parity
The Login project previously depended on the published `@umbraco-cms/backoffice@^17.3.4` npm package for types, while at runtime the importmap served the in-repo v18 backoffice. The version mismatch forced `as any` workarounds and masked real API drift. Since v18 (with UUI 2.0) isn't on npm yet, switch Login to consume the sibling Client via a local `file:` dep so types and runtime align on v18.
Changes:
- Login `package.json`: `@umbraco-cms/backoffice` → `file:../Umbraco.Web.UI.Client`; added `pre{build,dev,watch}` hooks that run a guard script to fail fast when Client's `dist-cms/` is missing.
- Login `scripts/ensure-client-built.mjs`: new guard with a clear "build the Client first" message.
- Login `CLAUDE.md`: documents the contract and build ordering.
- StaticAssets `.csproj`: `BuildLogin` now depends on `BuildBackoffice` so MSBuild (and therefore the Azure pipeline) builds Client before Login automatically.
- Client `src/tsconfig.build.json`: `declaration: true` so `dist-cms/` ships `.d.ts`.
- Client `package.json`: new `build:types` step (`tsc --emitDeclarationOnly --incremental false && tsc-alias`) wired into `build:for:cms` after `build:workspaces`. Vite workspaces wipe their output dirs before rebuilding JS, stripping the tsc-emitted declarations; re-emitting after workspaces restores them. `tsc-alias` rewrites Client-internal path aliases (e.g. `@umbraco-cms/backoffice/external/lit`) to relative paths so sibling consumers can resolve them.
- `copy-to-cms.js`: filter `.d.ts` and `.tsbuildinfo` from the copy to `wwwroot/umbraco/backoffice` — they're only needed by sibling projects consuming `dist-cms` for types, not at runtime.
- `src/external/uui/vite.config.ts`: set `treeshake: false` so per-component `defineElement()` side-effect calls (used by UUI 2.0 for custom-element registration) are preserved in the bundle. Without this, `<uui-button>` etc. never register and the login screen renders empty controls.
- `src/external/uui/index.ts`: bare `import '@umbraco-ui/uui'` to make the side-effect intent explicit.
- Small v18-compat fixes for `Object.groupBy` (TS 8 types): removed stale `@ts-expect-error`, switched to `Object.entries` + `?? []` to satisfy the `Partial<Record>` return type.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address review feedback and fix CI
- Add `ignoreDeprecations: "6.0"` to `tsconfig.json` and the tsconfig generator to silence the TS 6.0 warning about the implicit baseUrl that TypeScript assigns when `paths` is declared. This was the CI `build` failure. The generator is also synced with the user's es2022 → es2024 bump.
- Drop the now-redundant `--declaration` flag from `build:for:npm` (tsconfig.build.json now has `declaration: true`, so the flag was duplicating intent).
- Align Login's `engines` with the Client's (`node >=24.13`, `npm >=11`) so `file:` install doesn't trip EBADENGINE.
- Guard script: hardcode the relative "../Umbraco.Web.UI.Client" path in the error message instead of interpolating the absolute path, which overflowed the ASCII box in CI logs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Login: update CLAUDE.md Node/npm versions to match engines
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* check-path-length: skip .d.ts/.tsbuildinfo and directory paths
The 120-char Windows MAX_PATH guard protects files that actually ship to
CMS installs. `.d.ts` and `.tsbuildinfo` live in `dist-cms/` for sibling
projects to consume as types and are filtered out by `copy-to-cms.js`
before reaching `wwwroot/umbraco/backoffice` — they never land on a
Windows CMS install. Directories on their own also don't trigger
MAX_PATH; only files within them do, and those are still checked.
Unblocks CI after enabling `declaration: true` in the Client build.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* check-path-length: extract exceedsPathLimit helper (CodeScene)
Decomposes the complex conditional flagged by CodeScene into a named
predicate with a docstring, clarifying when a path is reported.
* Login: switch to generated tsconfig paths; revert dist-cms type machinery
PR #22591 originally aligned Login's TypeScript types with the in-repo v18
backoffice by emitting `.d.ts` into Client's `dist-cms/` and consuming it
via a `file:` dep. That layered six side-effects across the Client build
(declaration: true, build:types step, tsc-alias in postbuild, copy-to-cms
filter, check:paths skip, MSBuild ordering). Reviewers pushed back.
This rework moves the type contract from "ship .d.ts in dist-cms" to
"point Login's tsconfig paths at Client's TypeScript source" — Login's
runtime behaviour is unchanged (vite still externalises /^@umbraco-cms/,
host importmap still serves the JS), only the type-resolution mechanism
swaps.
What's reverted (back to the pre-PR shape):
- src/Umbraco.Web.UI.Client/src/tsconfig.build.json: declaration: false
- src/Umbraco.Web.UI.Client/package.json: drops `build:types` script,
reverts `postbuild` to global-types only, drops `--declaration` from
the tsc CLI in `build:for:cms` and restores it in `build:for:npm`
- src/Umbraco.Web.UI.Client/devops/build/copy-to-cms.js: simple cpSync
- src/Umbraco.Web.UI.Client/devops/build/check-path-length.js: original
- src/Umbraco.Web.UI.Client/tsconfig.json + devops/tsconfig/index.js:
drops `ignoreDeprecations` (not needed once baseUrl is gone)
- src/Umbraco.Cms.StaticAssets/Umbraco.Cms.StaticAssets.csproj:
`BuildLogin` no longer depends on `BuildBackoffice`
What's new on the Login side:
- src/Umbraco.Web.UI.Login/devops/tsconfig/index.js: generator that
reads Client's `package.json` exports and emits a full `tsconfig.json`
with `paths` mapping every `@umbraco-cms/backoffice/<sub>` to
`../Umbraco.Web.UI.Client/src/.../index.ts`. Mirrors Client's existing
generator pattern (DON'T EDIT header, JSON.stringify with tabs).
- src/Umbraco.Web.UI.Login/tsconfig.json: regenerated; standalone `tsc`
works (no `--project` needed) and 140 path aliases resolve types
directly from Client's source.
- src/Umbraco.Web.UI.Login/package.json: drops `@umbraco-cms/backoffice`
npm dep entirely (file: was only nominal — types come via paths,
runtime via importmap, transitives via Client's own `node_modules`
which is `npm install`-ed by CI's backoffice-install.yml). Replaces
the `ensure-client-built` guard with the generator on `pre*` hooks
and adds `generate:tsconfig` for ad-hoc invocation.
- src/Umbraco.Web.UI.Login/CLAUDE.md: documents the new layered
contract (paths/externalisation/importmap) and the install-Client-
before-Login prerequisite.
- src/Umbraco.Web.UI.Login/scripts/ensure-client-built.mjs: deleted.
What stays from the original PR (independent fixes):
- src/Umbraco.Web.UI.Client/src/external/uui/{vite.config.ts,index.ts}:
`treeshake: false` + bare side-effect import — keeps UUI 2.0
per-component `defineElement` calls in the bundle so `<uui-button>`
etc. actually register.
- Object.groupBy cleanups in 6 element files (TS 8 type narrowing).
- Client tsconfig generator: target/lib bumped to ES2024, `baseUrl`
removed.
Verified locally:
- `cd Client && rm -rf dist-cms && cd ../Login && npx tsc` → clean
(proves Login compiles without Client's dist-cms)
- `cd Client && npm run build:for:cms` → 0 emitted .d.ts (back to
pre-PR shape), `check:paths` passes
- Login `npm run build` → 64 KB bundle (unchanged)
- Browser at https://localhost:44339/umbraco: UUI 2.0 components
render, login with `test@umbraco.com`/`test123456` succeeds and
redirects to /umbraco/section/content
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Login: address review — idempotent generator + correct MSBuild ordering
- StaticAssets.csproj: BuildLogin now depends on RestoreBackoffice (not
BuildBackoffice — Login doesn't need dist-cms types). Login's tsc walks
Client source via tsconfig path aliases and resolves transitive deps
(lit, rxjs, …) from Client's node_modules. Without this dependency a
fresh local `dotnet build` could run BuildLogin before Client is
installed; CI was already safe via backoffice-install.yml's npm ci.
- devops/tsconfig/index.js: skip rewrite when content is unchanged. Pre-
hooks ran the generator on every npm command and bumped tsconfig.json
mtime even when nothing changed, which can invalidate caches and rattle
watchers downstream. Read-then-compare-then-write makes the generator
truly idempotent.
- devops/tsconfig/index.js: derive the alias prefix from
`clientPkg.name` instead of hardcoding `@umbraco-cms/backoffice` so a
package rename can't silently break paths.
azure-pipelines.yml needs no changes — backoffice-install.yml already
runs `npm ci` in Client before dotnet build kicks in MSBuild.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Login: postinstall + dev-mode Vite alias + theme CSS path
Audit cleanup pass on the rework:
- Login package.json: collapse predev/prebuild/prewatch into a single
postinstall hook. The generator runs whenever npm install/ci runs
(locally + in CI via RestoreLogin's npm i + the dotnet build chain).
Removes the per-command "tsconfig.json already up to date" noise.
- Login vite.config.ts: in dev mode (`vite serve`), read `paths` from
the generated tsconfig.json and apply them as `resolve.alias` so Vite
can resolve `@umbraco-cms/backoffice/*` to Client source. Vite doesn't
honor tsconfig `paths` natively — without this `npm run dev` failed
with "Failed to resolve import @umbraco-cms/backoffice/utils ...".
Build mode (`vite build`) still externalises the namespace via the
unchanged rollupOptions.external regex; alias is dev-only.
- Login index.html: UUI 2.0 reorganised CSS — the old
`@umbraco-ui/uui-css/dist/uui-css.css` path no longer exists. Point
at `@umbraco-ui/uui/dist/themes/light.css` which is what Client now
ships. Path is relative through Client's node_modules since Login no
longer declares a UUI dep itself.
- Client input-entity-user-permission.element.ts: prettier flagged a
multi-line .map() arrow that should be inline; collapse to one line.
- Login CLAUDE.md: document the postinstall-driven generator.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Use Vite 8 native tsconfigPaths; drop helper plugin and trim comments
- Both vite.config.ts files use `resolve.tsconfigPaths: true` instead of the
`vite-tsconfig-paths` plugin. Plugin and dep removed.
- Trim explanatory comments on csproj target, generator, UUI vite config and
external/uui/index.ts to conclusions only.
* Login: tsconfig generator fails fast on unsupported exports shapes
Distinguish between the legitimate `.` self-reference (target === null) and
unexpected non-string targets (e.g., conditional exports objects). The latter
now throw with a clear message instead of being silently dropped from `paths`,
which would otherwise produce confusing 'Cannot find module' errors at tsc
time later.
* Login: allow Vite dev server to serve Client's UUI assets
The light.css imported from Client's node_modules pulls Lato fonts via
relative URL, which Vite refuses by default since they sit outside
Login's project root. Extend server.fs.allow to the parent directory
(both sibling projects).
* Client: regenerate tsconfig on postinstall
* Login: keep UUI registrations in dev mode
Vite 8's esbuild dep pre-bundle drops the per-component
`customElements.define()` side-effects in @umbraco-ui/uui (a known UUI
issue with Vite 8). Exclude UUI from optimizeDeps so it's served
unbundled in dev. Re-add the bare side-effect import in external/uui
so the entry module evaluates the chain. Production build is unaffected
(workspace's `treeshake: false` already preserves registrations).
Also document the new MSBuild Login targets in StaticAssets CLAUDE.md.
* Login: clarify why optimizeDeps.exclude is needed for UUI
Tested treeshake.moduleSideEffects: true in optimizeDeps.rollupOptions
on Vite 8 / Rolldown 1.0.0-rc.17 — registrations still get stripped.
Excluding the package from the pre-bundle is the only reliable workaround
until UUI's own Vite 8 upgrade lands. Comment captures the conclusion.
* Roll back Vite 8 → 7 in Client and Login
Vite 8.0.10 ships Rolldown 1.0.0-rc.17 which strips UUI 2.0
`customElements.define()` side-effects during dep pre-bundle, leaving
elements unregistered in dev mode. Rather than ship a v18 release tied
to a non-final Rolldown RC, revert the Vite bump and pick it up again
once Rolldown 1.0 final lands.
Changes:
- Client: vite ^8.0.10 → ^7.3.2; vite-plugin-static-copy ^4.1.0 → ^3.2.0;
re-add vite-tsconfig-paths plugin; drop native `resolve.tsconfigPaths`.
- Login: vite ^8.0.10 → ^7.3.2; add vite-tsconfig-paths; configure plugin
with `projects: ['./tsconfig.json', '../Umbraco.Web.UI.Client/tsconfig.json']`
so it can resolve `@umbraco-cms/backoffice/*` imports inside Client
source files (which would otherwise lack a discoverable tsconfig in
Login's project tree). Drop `optimizeDeps.exclude` (no longer needed
without Rolldown). Keep `server.fs.allow` for the cross-project font.
TypeScript 6 + ES2024 + tsconfig path generator + Login architectural
pivot all stay — those are independent of the Vite version.
Verified:
- Production https://localhost:44339/umbraco — login works
- Login dev http://localhost:5191/ — UUI registers, all custom elements defined
- Client dev http://localhost:5192/ — page loads, navigates to /section/content
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address Copilot review
- vite.config.ts (Login): narrow server.fs.allow from the parent dir to
Login + Client only, reducing the dev server's read scope.
- external/uui/vite.config.ts (Client): replace blanket `treeshake: false`
with `moduleSideEffects: (id) => id.includes('@umbraco-ui/uui')` so
Rollup keeps UUI's per-component registration calls but tree-shakes the
rest. Bundle stays at 516 KB / 96 registered tags.
* fix merge overwrites
* update package lock
* fix: do not autogenerate tsconfig on postinstall
* removes postinstall script
* chore: generates tsconfig
* chore: update lockfile
* docs: updates claude.md
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Skip operation ID generation for non-controller endpoints
UmbracoOperationIdTransformer is registered globally for the default
OpenAPI document, so any minimal API endpoint that lands there ran
through it. The transformer threw "This handler operates only on
ControllerActionDescriptor" because its conventions (route prefix
stripping, MapToApiVersion lookup) only make sense for MVC actions.
Return null from the generator and skip the assignment when the action
descriptor isn't a ControllerActionDescriptor. The framework's default
operation ID applies in that case.
* Auth: un-deprecates getLatestToken and routes per-request fetches through it
getLatestToken is the only public API for "wait for any in-flight refresh,
trigger one if the access token has expired, then return". External and
internal consumers were warned off it without an equivalent replacement:
configureClient only helps @hey-api/openapi-ts clients, and consumers using
axios/ky/native fetch had no other gate.
- Removes the @deprecated JSDoc + UmbDeprecation.warn() call so the public
surface no longer prints a console warning per call.
- Uses getLatestToken.bind(this) for the auth callback inside configureClient
and the token callback inside getOpenApiConfiguration so both paths share
the same #ensureTokenReady gate.
- Replaces the hard-coded `Authorization: Bearer [redacted]` in unlinkLogin
and #makeLinkTokenRequest with `Bearer ${await getLatestToken()}` so those
fetches participate in the refresh coordination rather than firing with a
potentially-revoked cookie.
Also wires the UmbracoExtension template's entrypoint to call
authContext.configureClient(client), matching the v18 template change. The
framework awaits onInit, so this guarantees the API client is fully
configured before any element in the extension can use it.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Auth: tightens UmbAuthContext correctness and accepts any hey-api client
Pulls in a batch of non-breaking improvements to UmbAuthContext that came
out of an audit on the back of the un-deprecation work in this PR:
Public surface:
- configureClient(client) now accepts a new structural UmbApiClient type
(exported from @umbraco-cms/backoffice/http-client). Each @hey-api/openapi-ts
generation produces a fully-bound Client<…>; the backoffice's umbHttpClient
and an extension's regenerated client are structurally identical but TS
treats them as distinct generic instantiations. The widened parameter lets
extensions wire their own client without `as never` casts at call sites.
bindDefaultInterceptors keeps its strict typeof umbHttpClient parameter
(preserving autocomplete inside interceptor callbacks); the cast happens
once, internally.
Correctness:
- The auth context now holds a single UmbApiInterceptorController, lazy-
initialised on first configureClient() call. Previously each call
instantiated a new controller, which re-provided the UmbAuthSignalerContext
on the host and stacked listeners — visible the moment an extension also
called configureClient. One controller for the lifetime of the host, all
configured clients share it.
- completeAuthorizationRequest checks sessionStorage before asking
window.opener for the PKCE verifier. The previous order hung for the full
postMessage timeout whenever oauth_complete loaded with a non-OAuth
window.opener (which is set for ANY window.open target). The opener
postMessage timeout is also dropped from 5s to 1.5s — a real popup parent
responds within milliseconds; longer is just wait time for the unrelated-
opener case.
- The cross-tab 'authorized' BroadcastChannel handler now routes through
#setSessionLocally so the timestamp math stays in one place. The
'sessionUpdate' handler still applies pre-computed timestamps directly
(peer broadcast already did the math) but does so inside the
#inSessionUpdateCallback guard, so a synchronous session$ observer can no
longer trigger a spurious /token refresh on top of a peer's update.
- #ensureTokenReady drops its query-then-request pattern. Now always queues
behind the umb:token-refresh lock with a no-op callback — if the lock is
free it acquires immediately, if held it waits. Eliminates the race window
between query() and request().
- destroy() invokes #popupCleanup before tearing down so an in-flight popup
flow's window-level message listener and closed-poll interval don't leak
past the context's lifetime. The cleanup helper itself now resolves the
popup-flow Promise — every termination path (authorized, popup closed,
superseded by a new flow, context destroyed) is observable to the awaiter
instead of hanging forever.
Cleanup:
- makeAuthorizationRequest is annotated Promise<void> so the redirect and
popup branches share an explicit return type.
- unlinkLogin wraps the parsed problem-details payload in a real Error (with
the original payload exposed on `.cause`) so callers using `instanceof
Error` or expecting a stack trace get sane behaviour.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Auth: un-deprecates getLatestToken and routes per-request fetches through it
getLatestToken is the only public API for "wait for any in-flight refresh,
trigger one if the access token has expired, then return". External and
internal consumers were warned off it without an equivalent replacement:
configureClient only helps @hey-api/openapi-ts clients, and consumers using
axios/ky/native fetch had no other gate.
- Removes the @deprecated JSDoc + UmbDeprecation.warn() call so the public
surface no longer prints a console warning per call.
- Uses getLatestToken.bind(this) for the auth callback inside configureClient
and the token callback inside getOpenApiConfiguration so both paths share
the same #ensureTokenReady gate.
- Replaces the hard-coded `Authorization: Bearer [redacted]` in unlinkLogin
and #makeLinkTokenRequest with `Bearer ${await getLatestToken()}` so those
fetches participate in the refresh coordination rather than firing with a
potentially-revoked cookie.
Also wires the UmbracoExtension template's entrypoint to call
authContext.configureClient(client), matching the v18 template change. The
framework awaits onInit, so this guarantees the API client is fully
configured before any element in the extension can use it.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Auth: tightens UmbAuthContext correctness and accepts any hey-api client
Pulls in a batch of non-breaking improvements to UmbAuthContext that came
out of an audit on the back of the un-deprecation work in this PR:
Public surface:
- configureClient(client) now accepts a new structural UmbApiClient type
(exported from @umbraco-cms/backoffice/http-client). Each @hey-api/openapi-ts
generation produces a fully-bound Client<…>; the backoffice's umbHttpClient
and an extension's regenerated client are structurally identical but TS
treats them as distinct generic instantiations. The widened parameter lets
extensions wire their own client without `as never` casts at call sites.
bindDefaultInterceptors keeps its strict typeof umbHttpClient parameter
(preserving autocomplete inside interceptor callbacks); the cast happens
once, internally.
Correctness:
- The auth context now holds a single UmbApiInterceptorController, lazy-
initialised on first configureClient() call. Previously each call
instantiated a new controller, which re-provided the UmbAuthSignalerContext
on the host and stacked listeners — visible the moment an extension also
called configureClient. One controller for the lifetime of the host, all
configured clients share it.
- completeAuthorizationRequest checks sessionStorage before asking
window.opener for the PKCE verifier. The previous order hung for the full
postMessage timeout whenever oauth_complete loaded with a non-OAuth
window.opener (which is set for ANY window.open target). The opener
postMessage timeout is also dropped from 5s to 1.5s — a real popup parent
responds within milliseconds; longer is just wait time for the unrelated-
opener case.
- The cross-tab 'authorized' BroadcastChannel handler now routes through
#setSessionLocally so the timestamp math stays in one place. The
'sessionUpdate' handler still applies pre-computed timestamps directly
(peer broadcast already did the math) but does so inside the
#inSessionUpdateCallback guard, so a synchronous session$ observer can no
longer trigger a spurious /token refresh on top of a peer's update.
- #ensureTokenReady drops its query-then-request pattern. Now always queues
behind the umb:token-refresh lock with a no-op callback — if the lock is
free it acquires immediately, if held it waits. Eliminates the race window
between query() and request().
- destroy() invokes #popupCleanup before tearing down so an in-flight popup
flow's window-level message listener and closed-poll interval don't leak
past the context's lifetime. The cleanup helper itself now resolves the
popup-flow Promise — every termination path (authorized, popup closed,
superseded by a new flow, context destroyed) is observable to the awaiter
instead of hanging forever.
Cleanup:
- makeAuthorizationRequest is annotated Promise<void> so the redirect and
popup branches share an explicit return type.
- unlinkLogin wraps the parsed problem-details payload in a real Error (with
the original payload exposed on `.cause`) so callers using `instanceof
Error` or expecting a stack trace get sane behaviour.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Auth: un-deprecates getLatestToken and routes per-request fetches through it
getLatestToken is the only public API for "wait for any in-flight refresh,
trigger one if the access token has expired, then return". External and
internal consumers were warned off it without an equivalent replacement:
configureClient only helps @hey-api/openapi-ts clients, and consumers using
axios/ky/native fetch had no other gate.
- Removes the @deprecated JSDoc + UmbDeprecation.warn() call so the public
surface no longer prints a console warning per call.
- Uses getLatestToken.bind(this) for the auth callback inside configureClient
and the token callback inside getOpenApiConfiguration so both paths share
the same #ensureTokenReady gate.
- Replaces the hard-coded `Authorization: Bearer [redacted]` in unlinkLogin
and #makeLinkTokenRequest with `Bearer ${await getLatestToken()}` so those
fetches participate in the refresh coordination rather than firing with a
potentially-revoked cookie.
Also wires the UmbracoExtension template's entrypoint to call
authContext.configureClient(client), matching the v18 template change. The
framework awaits onInit, so this guarantees the API client is fully
configured before any element in the extension can use it.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Auth: tightens UmbAuthContext correctness and accepts any hey-api client
Pulls in a batch of non-breaking improvements to UmbAuthContext that came
out of an audit on the back of the un-deprecation work in this PR:
Public surface:
- configureClient(client) now accepts a new structural UmbApiClient type
(exported from @umbraco-cms/backoffice/http-client). Each @hey-api/openapi-ts
generation produces a fully-bound Client<…>; the backoffice's umbHttpClient
and an extension's regenerated client are structurally identical but TS
treats them as distinct generic instantiations. The widened parameter lets
extensions wire their own client without `as never` casts at call sites.
bindDefaultInterceptors keeps its strict typeof umbHttpClient parameter
(preserving autocomplete inside interceptor callbacks); the cast happens
once, internally.
Correctness:
- The auth context now holds a single UmbApiInterceptorController, lazy-
initialised on first configureClient() call. Previously each call
instantiated a new controller, which re-provided the UmbAuthSignalerContext
on the host and stacked listeners — visible the moment an extension also
called configureClient. One controller for the lifetime of the host, all
configured clients share it.
- completeAuthorizationRequest checks sessionStorage before asking
window.opener for the PKCE verifier. The previous order hung for the full
postMessage timeout whenever oauth_complete loaded with a non-OAuth
window.opener (which is set for ANY window.open target). The opener
postMessage timeout is also dropped from 5s to 1.5s — a real popup parent
responds within milliseconds; longer is just wait time for the unrelated-
opener case.
- The cross-tab 'authorized' BroadcastChannel handler now routes through
#setSessionLocally so the timestamp math stays in one place. The
'sessionUpdate' handler still applies pre-computed timestamps directly
(peer broadcast already did the math) but does so inside the
#inSessionUpdateCallback guard, so a synchronous session$ observer can no
longer trigger a spurious /token refresh on top of a peer's update.
- #ensureTokenReady drops its query-then-request pattern. Now always queues
behind the umb:token-refresh lock with a no-op callback — if the lock is
free it acquires immediately, if held it waits. Eliminates the race window
between query() and request().
- destroy() invokes #popupCleanup before tearing down so an in-flight popup
flow's window-level message listener and closed-poll interval don't leak
past the context's lifetime. The cleanup helper itself now resolves the
popup-flow Promise — every termination path (authorized, popup closed,
superseded by a new flow, context destroyed) is observable to the awaiter
instead of hanging forever.
Cleanup:
- makeAuthorizationRequest is annotated Promise<void> so the redirect and
popup branches share an explicit return type.
- unlinkLogin wraps the parsed problem-details payload in a real Error (with
the original payload exposed on `.cause`) so callers using `instanceof
Error` or expecting a stack trace get sane behaviour.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Auth: un-deprecates getLatestToken and routes per-request fetches through it
getLatestToken is the only public API for "wait for any in-flight refresh,
trigger one if the access token has expired, then return". External and
internal consumers were warned off it without an equivalent replacement:
configureClient only helps @hey-api/openapi-ts clients, and consumers using
axios/ky/native fetch had no other gate.
- Removes the @deprecated JSDoc + UmbDeprecation.warn() call so the public
surface no longer prints a console warning per call.
- Uses getLatestToken.bind(this) for the auth callback inside configureClient
and the token callback inside getOpenApiConfiguration so both paths share
the same #ensureTokenReady gate.
- Replaces the hard-coded `Authorization: Bearer [redacted]` in unlinkLogin
and #makeLinkTokenRequest with `Bearer ${await getLatestToken()}` so those
fetches participate in the refresh coordination rather than firing with a
potentially-revoked cookie.
Also wires the UmbracoExtension template's entrypoint to call
authContext.configureClient(client), matching the v18 template change. The
framework awaits onInit, so this guarantees the API client is fully
configured before any element in the extension can use it.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Auth: tightens UmbAuthContext correctness and accepts any hey-api client
Pulls in a batch of non-breaking improvements to UmbAuthContext that came
out of an audit on the back of the un-deprecation work in this PR:
Public surface:
- configureClient(client) now accepts a new structural UmbApiClient type
(exported from @umbraco-cms/backoffice/http-client). Each @hey-api/openapi-ts
generation produces a fully-bound Client<…>; the backoffice's umbHttpClient
and an extension's regenerated client are structurally identical but TS
treats them as distinct generic instantiations. The widened parameter lets
extensions wire their own client without `as never` casts at call sites.
bindDefaultInterceptors keeps its strict typeof umbHttpClient parameter
(preserving autocomplete inside interceptor callbacks); the cast happens
once, internally.
Correctness:
- The auth context now holds a single UmbApiInterceptorController, lazy-
initialised on first configureClient() call. Previously each call
instantiated a new controller, which re-provided the UmbAuthSignalerContext
on the host and stacked listeners — visible the moment an extension also
called configureClient. One controller for the lifetime of the host, all
configured clients share it.
- completeAuthorizationRequest checks sessionStorage before asking
window.opener for the PKCE verifier. The previous order hung for the full
postMessage timeout whenever oauth_complete loaded with a non-OAuth
window.opener (which is set for ANY window.open target). The opener
postMessage timeout is also dropped from 5s to 1.5s — a real popup parent
responds within milliseconds; longer is just wait time for the unrelated-
opener case.
- The cross-tab 'authorized' BroadcastChannel handler now routes through
#setSessionLocally so the timestamp math stays in one place. The
'sessionUpdate' handler still applies pre-computed timestamps directly
(peer broadcast already did the math) but does so inside the
#inSessionUpdateCallback guard, so a synchronous session$ observer can no
longer trigger a spurious /token refresh on top of a peer's update.
- #ensureTokenReady drops its query-then-request pattern. Now always queues
behind the umb:token-refresh lock with a no-op callback — if the lock is
free it acquires immediately, if held it waits. Eliminates the race window
between query() and request().
- destroy() invokes #popupCleanup before tearing down so an in-flight popup
flow's window-level message listener and closed-poll interval don't leak
past the context's lifetime. The cleanup helper itself now resolves the
popup-flow Promise — every termination path (authorized, popup closed,
superseded by a new flow, context destroyed) is observable to the awaiter
instead of hanging forever.
Cleanup:
- makeAuthorizationRequest is annotated Promise<void> so the redirect and
popup branches share an explicit return type.
- unlinkLogin wraps the parsed problem-details payload in a real Error (with
the original payload exposed on `.cause`) so callers using `instanceof
Error` or expecting a stack trace get sane behaviour.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Disable inaccessible parent folders in element tree
When an element start node is configured to a child folder, the backend
returns ancestor folders flagged with NoAccess so they show as breadcrumbs.
The element folder tree item used the default tree item element, which
does not observe noAccess, so parent folders rendered as enabled and
clickable in the Library section tree. Added a custom
element-folder-tree-item element that observes the context's noAccess and
forwards it to the base, which already handles disabling the menu item.
* Client: Aliased `DocumentVariantStateModel` for documents and document-blueprints packages
Hoist `UmbDocumentVariantState` and `UmbDocumentBlueprintVariantState` aliases (re-exporting `DocumentVariantStateModel`) into dedicated `variant-state.ts` leaf files. Internal package modules, mocks and the core split-view selector now consume the alias instead of referencing `DocumentVariantStateModel` directly, mirroring the structure on `v18/dev` to reduce upstream-merge conflicts.
* Revert mock data changes
to prevent importing the whole "document" module.
* Tweaked the `DocumentVariantStateModel` import for mock data
Otherwise this is problematic for cherry-picked commits for v18.0.
* Missed one!
`elementStartNodeIds` and `hasElementRootAccess` were added to
`UmbCurrentUserModel` by the Global Elements PR but the documents mock
data set was created without them, causing `undefined.map()` errors in
the document workspace CRUD tests.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Update stored color label if changed on save of document with color picker.
* Clarify intent of change event dispatch in label sync
* Make comparison case insensitive.
* Added unit tests for new behaviour.
* Update stored color label if changed on save of document with color picker.
* Clarify intent of change event dispatch in label sync
* Make comparison case insensitive.
* Added unit tests for new behaviour.
* Update stored color label if changed on save of document with color picker.
* Clarify intent of change event dispatch in label sync
* Make comparison case insensitive.
* Added unit tests for new behaviour.
* Order SQL before FetchOneToMany in dictionary entry retrieval to prevent duplicate items in collection view.
* Used PrimaryKey instead of UniqueId to take advantage of the clustered index.
* Order SQL before FetchOneToMany in dictionary entry retrieval to prevent duplicate items in collection view.
* Used PrimaryKey instead of UniqueId to take advantage of the clustered index.
* temp mock set
* test getPropertyValue
* Extend document workspace context tests to cover read/write property values
* move context files into context folder
* Add document CRUD tests, mock handler & interceptor
* temp mock error interceptor
* Return 404 when document not found
* Use undefined for entity unique state until initialized
* Fix import paths for document workspace editor
* Add test utils and extend document workspace tests
* Update document-workspace-context.test-utils.ts
* Match invariant variant when variantId missing
* Ensure finishPropertyValueChange runs on exit
Wrap setPropertyValue implementation in a try/finally and move finishPropertyValueChange into the finally block so cleanup always runs even if an error is thrown. No other functional changes — code was re-indented and organized but behavior remains the same except for guaranteed cleanup on error.
* Require variantId for culture/segment-variant props
* fix types
* fix mock modal typescript error
* Distinguish unloaded vs root entity unique
* use the real current user context
* hide mock set in UI
* rename mock set
* Move initiatePropertyValueChange into try
* Use 'satisfies' for UmbMockDataSet assertions
* Preserve requested unique on failed load
* Treat missing variantId as invariant
* Reset update lock on destroy
* remove unused group + user
* Guard _current.unmute and remove destroy override
* Add tests for element data manager
* Guard subject access and add destroy test
* Throw when calling methods after destroy
* extend icons with information from theseaurus
* implement new icon search logic
* clean-up data
* icon manager
* sorting with a backup of the name
* refactor into a controller
* improve multi word group search
* embed lucide data
* rename tech into technology
* remove paper from dollar
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* improve search
* related should not show up in search
* update threshold
* separate name words
* also consider full icon name match
* better comment
* other approach for full name matches
* full icon name search if query contains a -
* fix test
* remove related code
* updates to related
* make its own package
* revert changes
* update tsconfig
* package-lock
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* build(deps): updates @hey-api/openapi-ts to latest and regenerates APi types
* build(deps): updates @hey-api/openapi-ts to latest and regenerates APi types (login)
* fix(backoffice): avoid invalid status 0 when synthesizing responses
Default to a 500 fallback status when no upstream Response is provided
to #createResponse, preventing a RangeError from the Response constructor.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* build(deps): updates UmbracoExtension template to @hey-api/openapi-ts 0.97
- Bumps @hey-api/openapi-ts to ^0.97.0 in the extension template.
- Simplifies the generate-openapi.js plugin config: spread @hey-api defaults
and only override @hey-api/sdk with responseStyle: 'fields' so call sites
keep the { data, error } destructuring shape. Removes the redundant
@hey-api/client-fetch redeclaration that triggered duplicate-plugin warnings.
- Drops the hey-api.ts runtime config file in favour of wiring the generated
client through UMB_AUTH_CONTEXT.configureClient() from the entrypoint, so
extensions inherit the same auth callback and default response interceptors
(401 retry, error notifications) as the core backoffice.
- Regenerates the pre-bundled SDK against the template's canonical
Umbraco.Extension scaffold so it matches what `npm run generate-client`
produces on first run; default hey-api output is flat function exports.
- Updates dashboard.element.ts call sites to match the new SDK shape and
renames the user model usage to Iuser to follow the new schema.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* chore(git): marks UmbracoExtension template generated SDK as linguist-generated
So GitHub diffs collapse the regenerated *.gen.ts files in PRs, matching what
we already do for the backoffice client and Login app SDKs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(template): addresses review feedback on PR #22735
- Restores the regenerated SDK's hard-coded baseUrl to https://localhost:44339/
so the SiteDomain template token in the .template.config still substitutes
it at scaffold time. The 5443 port leaked in from the local host I used to
regenerate; that domain is replaced by the user's chosen SiteDomain on
scaffold.
- Stops marking onInit as `async`. The UmbEntryPointOnInit signature returns
void; making the hook async is harmless under TS's bivariant void-return
assignability but is misleading. Kicks the context resolution + client
configuration off via .then() and logs a warning when UMB_AUTH_CONTEXT is
not present (instead of silently optional-chaining).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(template): keeps onInit async — the framework awaits it
The previous tweak was based on Copilot's claim that UmbEntryPointOnInit
returns void. The signature does declare void, but the entry-point
initializer in app-entry-point-extension-initializer.ts and
backoffice-entry-point-extension-initializer.ts both `await
moduleInstance.onInit(...)`, so an async onInit is awaited end-to-end.
Reverting to async ensures configureClient runs to completion before any
element in the extension can hit the API client.
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* temp mock set
* test getPropertyValue
* Extend document workspace context tests to cover read/write property values
* move context files into context folder
* Add document CRUD tests, mock handler & interceptor
* temp mock error interceptor
* Return 404 when document not found
* Use undefined for entity unique state until initialized
* Fix import paths for document workspace editor
* Add test utils and extend document workspace tests
* Update document-workspace-context.test-utils.ts
* Match invariant variant when variantId missing
* Ensure finishPropertyValueChange runs on exit
Wrap setPropertyValue implementation in a try/finally and move finishPropertyValueChange into the finally block so cleanup always runs even if an error is thrown. No other functional changes — code was re-indented and organized but behavior remains the same except for guaranteed cleanup on error.
* Require variantId for culture/segment-variant props
* fix types
* fix mock modal typescript error
* Distinguish unloaded vs root entity unique
* use the real current user context
* hide mock set in UI
* rename mock set
* Move initiatePropertyValueChange into try
* Use 'satisfies' for UmbMockDataSet assertions
* Preserve requested unique on failed load
* Treat missing variantId as invariant
* Reset update lock on destroy
* remove unused group + user
* Guard _current.unmute and remove destroy override
* Add tests for element data manager
* Guard subject access and add destroy test
* Throw when calling methods after destroy
* Delivery API: Fix broken discriminator mapping refs for polymorphic schemas
Microsoft.AspNetCore.OpenApi's MapPolymorphismOptionsToDiscriminator builds each ref as callback(base) + callback(derived), but our typed-schema flow registers the derived schemas without the base prefix. The auto-built mapping refs end up pointing at non-existent schemas, which crashes strict client generators like orval.
Strip the base schema id from the front of each broken ref to recover the registration key the derived schema actually uses.
* Delivery API: Add integration test coverage for the polymorphic discriminator mapping fix
Adds a test-only property editor whose Delivery API value type is a polymorphic interface declared with [JsonDerivedType], wired into the existing typed-schema integration test fixture. The OpenApiContract_HasExpectedSchemas test verifies that the auto-built discriminator mapping refs resolve to the registered derived schema names, providing end-to-end regression coverage for the fix.
Also extends AssertSchemaIsPolymorphicUnion to accept either oneOf (used by our typed schema unions) or anyOf (used by framework-built unions for [JsonDerivedType] interfaces).
* Use a captured schemas local in FixAutoBuiltDiscriminatorMapping
Move the null check for document.Components.Schemas into the top-of-method guard and use the captured non-null local in the loop body. Avoids both the null-conditional ?. operators and the null-forgiving ! operator at the use sites.
* docs(claude): document how unsafeHTML should be used together with escapeHTML()
* fix: adds escapeHTML where appropriate in order not to render html directly
* chore: removes small nitpick fallback
* docs(claude): fixes incorrect using of unsafeHTML
* feat(localization): add localize.htmlString() and convert call sites
Adds a new `htmlString()` method on UmbLocalizationController that escapes
interpolated args via escapeHTML and returns a Lit unsafeHTML directive.
This is the safe replacement for the manual `unsafeHTML(this.localize.string(...))`
pattern, which leaves user-controlled args un-escaped (XSS hazard).
Converts all direct `unsafeHTML(localize.string|term(...))` call sites
across modals, rollback views, packager, property editors, and entity
actions. Also fixes the latent XSS in `trash.action.ts` (sibling of the
previously-fixed `delete.action.ts`).
Updates docs/security.md with guidance on `string()` vs `htmlString()`
and the modal-content wrapping pattern.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* chore(eslint): add no-unsafe-localize rule to flag unsafeHTML(localize.string|term(...))
Catches the XSS pattern this PR's helper replaces, so future regressions
are caught at lint time instead of in review (or in a security advisory).
Suggests `localize.htmlString(...)` as the safe replacement.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(localization): stringify htmlString args before escaping
Addresses review feedback on PR #22731. escapeHTML() short-circuits on
non-strings (returns the value unchanged), so an arg like
{ toString: () => '<script>...</script>' } would bypass the escape and
render unescaped via unsafeHTML.
Stringifies args before escaping while preserving `undefined` so
string()'s placeholder semantics are unchanged. Adds a regression test
covering the toString() bypass.
Also adds the missing html/unsafeHTML imports to the security.md
example so the snippet is self-contained.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(installer-consent-element): sanitise content before rendering it
* fix(dashboard-telem-element): sanitise html before rendering
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: LLaverty <liamlaverty@gmail.com>
* docs(claude): document how unsafeHTML should be used together with escapeHTML()
* fix: adds escapeHTML where appropriate in order not to render html directly
* chore: removes small nitpick fallback
* docs(claude): fixes incorrect using of unsafeHTML
* feat(localization): add localize.htmlString() and convert call sites
Adds a new `htmlString()` method on UmbLocalizationController that escapes
interpolated args via escapeHTML and returns a Lit unsafeHTML directive.
This is the safe replacement for the manual `unsafeHTML(this.localize.string(...))`
pattern, which leaves user-controlled args un-escaped (XSS hazard).
Converts all direct `unsafeHTML(localize.string|term(...))` call sites
across modals, rollback views, packager, property editors, and entity
actions. Also fixes the latent XSS in `trash.action.ts` (sibling of the
previously-fixed `delete.action.ts`).
Updates docs/security.md with guidance on `string()` vs `htmlString()`
and the modal-content wrapping pattern.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* chore(eslint): add no-unsafe-localize rule to flag unsafeHTML(localize.string|term(...))
Catches the XSS pattern this PR's helper replaces, so future regressions
are caught at lint time instead of in review (or in a security advisory).
Suggests `localize.htmlString(...)` as the safe replacement.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(localization): stringify htmlString args before escaping
Addresses review feedback on PR #22731. escapeHTML() short-circuits on
non-strings (returns the value unchanged), so an arg like
{ toString: () => '<script>...</script>' } would bypass the escape and
render unescaped via unsafeHTML.
Stringifies args before escaping while preserving `undefined` so
string()'s placeholder semantics are unchanged. Adds a regression test
covering the toString() bypass.
Also adds the missing html/unsafeHTML imports to the security.md
example so the snippet is self-contained.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(installer-consent-element): sanitise content before rendering it
* fix(dashboard-telem-element): sanitise html before rendering
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: LLaverty <liamlaverty@gmail.com>
* Removed obsoleted property
Updated methods that were still using it
Obsoleted constructors that were still setting the value.
* Updated code that were using the now obsoleted constructors
* More obsoleted constructor fixes
* Update unittests
Removed obsolete (parentId) cases and updated constructors
* DRY up constructor
* Revert "MD files for Design knowledge (#22725)"
This reverts commit 212f3183c1.
* Revert "Backoffice Mocks: Derive user language access from user groups (#22721)"
This reverts commit 9671fec9ad.
* Revert "File-system Services: Complete child scopes on read-miss and validation-failure paths (#22717)"
This reverts commit 489d9ebc2e.
* Revert "manual revert of merge gone wrong"
This reverts commit a443f8ba08.
* Revert "fix(installer-user): added min length message for installer user elem… (#21829)"
This reverts commit 6789d7e757.
* Reapply "Merge branch 'main' of https://github.com/umbraco/Umbraco-CMS into claude/keen-nightingale-5ef5bd"
This reverts commit daecbd02b8.
* fix(installer-user): added min length message for installer user elem… (#21829)
* fix(installer-user): added min length message for installer user element.
* Update src/Umbraco.Web.UI.Client/src/apps/installer/user/installer-user.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix password minlength message binding syntax
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* File-system Services: Complete child scopes on read-miss and validation-failure paths (#22717)
* Ensure scopes in FolderServiceOperationBase are completed.
* Added integration tests to verify the fixes.
* Backoffice Mocks: Derive user language access from user groups (#22721)
fix(mocks): derive user language access from user groups
Previously hasAccessToAllLanguages was hardcoded to true and languages to
an empty array. Now both are derived from the user's user group memberships.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* MD files for Design knowledge (#22725)
* Fix issues following merge.
* Fixed linting errors.
* Fix linter errors (2).
* Restore current-user.context.ts
* Restore block-list-entry.element.ts.
* Removed failing webhook repository test files.
---------
Co-authored-by: Yari Mariën <75362020+Yinzy00@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Delivery API: Generate typed OpenAPI schemas per content type
* Honour Delivery API allow/deny list in typed OpenAPI schemas
ContentTypeSchemaTransformer now filters DocumentTypes through
DeliveryApiSettings.IsAllowedContentType so document types blocked
by AllowedContentTypeAliases / DisallowedContentTypeAliases no longer
leak into the polymorphic union or discriminator mapping.
* Stop registering media derived types in the JSON resolver
ContentJsonTypeResolverBase.GetDerivedTypes goes back to returning
empty. Previously it registered ApiMediaWithCrops and
ApiMediaWithCropsResponse as derived types of their interfaces, which
made every consumer of the resolver (the Delivery API and webhooks)
emit a $type discriminator on media payloads, even when the typed
schema feature was disabled.
The Delivery API still needs a base schema for the typed media
schemas to extend via allOf. Since the concrete media classes are
internal to Umbraco.Infrastructure and cannot be referenced from
[JsonDerivedType] in Core, ContentTypeSchemaTransformer now builds
that base from the interface's own properties when the interface has
no [JsonDerivedType] entries. Content/element interfaces are
unaffected and keep using their declared concrete derived types.
Snapshots regenerated.
* Drop default JsonDerivedType registrations from Delivery API interfaces
Removes the [JsonDerivedType] attributes from IApiContent,
IApiContentResponse, and IApiElement. Without them System.Text.Json
configures no polymorphism by default, so wire payloads stop carrying
$type fields and the OpenAPI spec stops emitting a discriminator on
the generic schemas - matching v17 Delivery API behaviour. Consumers
that need polymorphic serialization can still register derived types
via ContentJsonTypeResolverBase.
Snapshots regenerated.
* Allows nulls at property reference sites without mutating any shared component schema.
Avoid unnecessary re-get of the JsonTypeInfo for the default case.
* Updated expected contracts following code adjustments
* Drop additionalProperties: false from typed schemas
JSON Schema 2020-12 (mandated by OpenAPI 3.1) does not let additionalProperties look through allOf, so a strict validator rejects every inherited field on the composed *ResponseModel/*Model/*PropertiesModel schemas. Most code generators silently ignore it, but the document is technically invalid and the constraint would be a lie anyway since Umbraco can grow new properties in non-major releases.
Removed from all four schema construction sites (response, content type, properties, and the interface-based fallback) and regenerated the affected snapshots.
* Preserve casing of content type aliases in OpenAPI schema IDs
Replaces the legacy ModelsBuilder-style ToCleanString tokenizer with
ToFirstUpperInvariant. The tokenizer split aliases on case boundaries
and mangled capital-letter runs (e.g. "xMLSitemap" -> "XMlsitemap"),
making the typed schema names harder to read for OpenAPI consumers.
Since content type aliases are already valid identifiers, only the
first character needs uppercasing.
Also adds an "xMLSitemap" sample type to the integration tests to
cover the casing-preservation behavior.
* Qualify properties model schema IDs by item type
Document, element, and media types share the same alias namespace
across content/media (a doc-type and a media-type can use the same
alias), so a "{Schema}PropertiesModel" naming scheme could collide.
Properties model schemas now follow the same Content/Element/Media
suffix as their parent *Model schema:
- Document type: ArticlePageContentPropertiesModel
- Element type: TestElementElementPropertiesModel
- Media type: VideoMediaPropertiesModel
Composition references look up each composition's own IsElement so
that a doc-type composing an element-type (allowed in the UI) still
references the correct ElementPropertiesModel schema.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* feat(elements): add granular user permissions for element folders
Add element-folder entity type to applicable entityUserPermission
manifests (Create, Read, Update, Delete, Move) and register a
separate userGranularPermission with a folder-only picker component.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* refactor(elements): separate element folder permissions into own directory
Move element-folder entityUserPermission and userGranularPermission
manifests into folder/user-permissions/ with dedicated component.
Revert element manifests to element-only forEntityTypes. Also adds
permission condition to folder update entity action and filters
permission names by entity type.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Corrects the type-safety of the "selected" event
* Commented out `userGranularPermission` manifest for Element Folders
* Added specific permission verbs for Element Folders
* Added Element Folder User Permission condition
* Updated entity-action manifest conditions
for Element Folder permissions
* Updated permission prefixes
from `Umb.ElementFolder.` to match the server `Umb.ElementContainer.`
* Add explicit element folder permission handling
* The ElementPermissionService should not authorize against element containers anymore
* More granular read permission handling for trees
* Rename ElementFolder to ElementContainer
* Export element folder user permission constants from @umbraco-cms/backoffice/element
The 6 new element folder permission constants were not re-exported
through the element package barrel, causing the export-consts test
to fail.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Updated manifest conditions for Element Folder delete permission
* Enforce update permission on element folder name field
Added nameWriteGuard rule to the element folder workspace context
that blocks renaming when the user lacks the
Umb.ElementContainer.Update permission.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Fix casing
* Fix incorrect condition aliases on element folder actions
- Remove trashed condition from folderCreateOption (create options modal
already handles this via the parent create action's conditions)
- Use folder-specific permission condition alias on recycle-bin folder
trash action instead of the generic element permission condition
* Renamed to `ElementContainerPermissionPresentationModel`
to match the server's future naming of this model.
* refactor(elements): apply review feedback for folder permissions
- Switch nameWriteGuard to fallbackToNotPermitted policy, so the rename
guard expresses intent as "default deny, allow when permitted" rather
than relying on a permitted:false rule cleared by the condition.
- Rename #enforceUpdatePermission to #setupNameWritePermissions for
clarity (the method now manages a positive-grant rule).
- Make condition's #elementFolderPermissions and #fallbackPermissions
optional so "not loaded" is distinguishable from "loaded empty";
bail out early in #checkPermissions until both have populated, to
avoid evaluating permissions against incomplete data.
- Drop constructor consumption of UMB_MODAL_MANAGER_CONTEXT in the
granular permission input element; resolve the modal manager via
getContext at call time inside the two action methods that need it.
* Add missing using to fix the failing build
* updates server api types
* Fix build error after clean-ups
* Fixes FE build error
Temporarily defines the `IPermissionPresentationModelElementContainerPermissionPresentationModel` type,
for future use.
* Remove duplicate migration
* Remove another duplicate migration
* Add performance improvements from #22405 to ElementContainerPermissionService and add unit tests to prove it
* Fix element permission authorization for descendants
* Test for descendant element delete permissions before deleting an element container
* Update tests/Umbraco.Tests.UnitTests/Umbraco.Core/Services/ElementPermissionServiceTests.cs
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
Co-authored-by: kjac <kja@umbraco.dk>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Remove the obsolete IFileService, the implementation and update all callers.
* Extend ServiceContext to include replacement service.
* Restore fallback behaviour for resolved users.
* Make TrySetTemplate async to avoid sync-over-async with new services.
* Addressed code review feedback.
* Reverted updates to stylesheet properties.
* Add helper and tests for path splitting.
* Ensure create of directory path on package data import.
* Verification with integration test.
* Comply with public obsoletion by makng the Properties internal
* Tidied up XML header comments.
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fixed indents.
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
fix(mocks): derive user language access from user groups
Previously hasAccessToAllLanguages was hardcoded to true and languages to
an empty array. Now both are derived from the user's user group memberships.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* View Contexts for Dashboards + Section Views to support Browser Title and Hints
* fix code
* use alias for observe ctrl alias
* remove test code
* Position badge in section icon slot
---------
Co-authored-by: engjlr <enl@umbraco.dk>
* Management API: Override document-level security on AllowAnonymous endpoints
Operations on controllers/actions decorated with [AllowAnonymous] inherit the
document-level Bearer security requirement in OpenAPI 3.x unless they explicitly
declare an empty security array. Without that override, the generated SDK
attaches an Authorization: Bearer header to anonymous endpoints (server/status,
server/configuration, install/*, manifest/manifest/public, etc.), which forces
a /security/back-office/token refresh during the very first page load.
On v18/dev this manifests as a 500 from /server/status during a fresh install:
the Authorization header triggers OpenIddict, which resolves UmbracoDbContext
from DI, which throws because the connection string is empty in the install
state.
The transformer now sets operation.Security = [] on AllowAnonymous endpoints so
they correctly opt out of the document-level security. The committed OpenApi.json
and the regenerated sdk.gen.ts reflect this.
* Management API: Fix unit tests for AllowAnonymous security override
The transformer now sets operation.Security = [] (empty list) on
[AllowAnonymous] endpoints to override document-level security, instead
of leaving it null. Update the two affected tests to assert the new
behaviour and rename them to reflect that the transformer overrides
rather than skips security on anonymous operations.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* WIP
* Cleanup and type generation
* Improve obsoletions
* Fix removed constructor
* Simplify logic because of SignalR's JS limitations
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add SignalRSettings to Schema
* Abstrack SignalRRoutes class
* Fix bool to observable<bool>
* Refactor base class: pull down common service property, make abstract with protected constructor.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Management API sweep
* Remove leftover comment from ContentService
* Clarify TODOs
* Use IPublishedElementCache instead of IElementCacheService in ElementPickerValueConverter
* Rename private helper for clarification
* Fix build error
* Remove "Create" from ElementService, as it was only ever used for tests
* Rename DocumentVariantStateModel to PublishableVariantStateModel in backoffice client
Refresh OpenApi.json and regenerate backend-api after the server-side enum rename, then update all client imports and usages to match.
* Client: Aliased `PublishableVariantStateModel` for each module package
* Client: Resolve circular dependencies for variant-state alias
Hoist the `UmbDocumentVariantState` and `UmbElementVariantState` aliases (re-exporting `PublishableVariantStateModel`) into dedicated `variant-state.ts` files. Internal modules now import the alias from this leaf file instead of the package's root `index.js`, breaking the 5 cycles reported by `npm run check:circular` while keeping the public API surface unchanged.
* Post-merge fixes
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Updated webhook tests since Change the default payload type to "minimal"
* Added .skip tag for block grid area tests due to the actual issues
* Update template tests due to test helpers changes
* Updated locator for rollback button due to UI changes
* Updated locator for block edit button due to UI changes
* Updated locator for delete block icon
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Delivery API: Drop $type discriminator from response payloads
Removed [JsonDerivedType] from IApiContent and IApiContentResponse so
System.Text.Json stops emitting $type on collection endpoints and the
OpenAPI spec stops requiring a discriminator on the generic schemas,
restoring v17 behaviour. Consumers that need polymorphic responses can
still register derived types via ContentJsonTypeResolverBase.
Snapshot regenerated.
* Delivery API: Preserve cultures property order on collection responses
Added [JsonPropertyOrder(100)] to IApiContentResponse.Cultures so the
property is serialized last when the static type is the interface
(collection endpoints), matching the existing attribute on the concrete
ApiContentResponse class. Mirrors the [JsonPropertyOrder(-100)] pattern
already used for ContentType on IApiElement / ApiElement.
Snapshot regenerated.
* Remove unused obseleted InstalledPackage mapping
* Fix up XML header documentation on PackageViewModelMapDefinition.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Ensure content type cache is correctly invalidated for element types.
* Clear key to Id map on clear all.
* Refactor and update tests for additional coverage and naming alignment.
* Updates from code review.
* Backoffice Element Search: add global search provider for elements
Adds an "Elements" category to the backoffice global search, scoped to
the Library section.
Server: SearchElementItemController exposes
GET /umbraco/management/api/v1/item/element/search
backed by IEntitySearchService (DB-backed name match, mirrors the
DataType search pattern). Maps results via IElementPresentationFactory.
Client: new src/packages/elements/search/ module with a search provider,
repository, server data source, search-result-item element, and
globalSearch manifest (alias Umb.GlobalSearch.Element). Wired into the
elements package manifests. Backend SDK regenerated from OpenApi.json.
* Backoffice Element Search: surface ancestors, trashed and draft state
- New ancestors endpoint at /item/element/ancestors so result items can
render a parent breadcrumb (uses NamedItemResponseModel to cover
element folder ancestors).
- ElementItemResponseModel.IsTrashed added and populated by the
presentation factory, flowing through search and item responses.
- Frontend search result item renders breadcrumb, Trashed tag with
strike-through, and Draft tag (mirrors document search result item).
* Address PR review feedback
- Add integration test for AncestorsElementItemController (mirrors
AncestorsDocumentItemControllerTests).
- UmbElementSearchItemModel: declare `name: string` (the search result
contract requires it; mirrors UmbDocumentSearchItemModel).
- Element search data source: drop the empty-string fallback on `name`
and add the same TODO comment used in the document data source.
- Add JSDoc to UmbElementSearchProvider, UmbElementSearchRepository and
UmbElementSearchServerDataSource (matches document equivalents).
* Backoffice Element Search: export search consts and unblock isTrashed on item endpoint
- Re-export ./search/constants.js from the elements package barrel so
UMB_ELEMENT_SEARCH_PROVIDER_ALIAS and UMB_ELEMENT_GLOBAL_SEARCH_ALIAS
are reachable as the export-consts test expects.
- element-item.server.data-source.ts: stop hardcoding isTrashed to false
- now that ElementItemResponseModel exposes the flag, item-based UIs
reflect the actual trashed state.
* Fix naming warning in UmbracoIntegrationTestBase.
* Fixes a namespace.
* Removed TODO for removing registrations of UserPasswordConfigurationSettings and MemberPasswordConfigurationSettings. The inheritance hierarchy of UmbracoUserManager makes this difficult and unnecessary to unpick.
* Aligned TODO with obsoletion message.
* Remove obsoleted code from IDomainService and update all callers.
* Removed obsolete members from IContentTypeBaseService.
* Addressed code review feedback.
* Fix Setup on ThreadSafetyTests.
* Close suggestion dropdown on blur and escape, fix suggestion selection
* Fix code complex
* Fix to tab and complexity
* Fix to tab and complexity
* Fix to tab and complexity
* Clear matches on add/escape and remove focus rule
---------
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* unit test for boolean state
* improve umb class state set value identical check
* consistent ability to make a observablePart
Co-authored-by: Copilot <copilot@github.com>
---------
Co-authored-by: Copilot <copilot@github.com>
* Add table collection view and manifests
* Use table kind in collection example
* Update entity-name-table-column-layout.element.ts
* Recompute table rows when item hrefs change
* define and render columns from manifest
* wip language implementation
* map to unique field
* rename to label
* test implementation for users table
* experiment: value minimal display extension
* register as workspace context
* add boolean display
* clean up
* add example entity actions
* add example description
* Update table-collection-view.element.ts
* Omit base 'meta' and relax table meta type
* Hardcode description column when present
* localize column names
* Update table-collection-view.element.ts
* Type manifest on collection view elements
* Use UmbLitElement instead of LitElement
* fix types
* Update entity-name-table-column-layout.element.ts
* provide entity context for each table row
* fix breaking change and introduce a deprecation warning
* Add status column to example collection view + localize column labels
* implement the UmbTableColumnLayoutElement interface
* add tests for the table collection view
* Make host element optional; add table docs/types
* Update controller-host.mixin.ts
* Update src/Umbraco.Web.UI.Client/src/packages/core/entity-action/global-components/entity-actions-table-column-view/entity-actions-table-column-view.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add language collection context
* introduction of value type and rename to value summary
* Add core DateTime value summary; migrate user last-login
* remove unused
* Rename user group value type to References
* Remove the component's standalone resolution path
* Add start-node value summaries & sections for user group table
* Guard resolver and render when start node missing
* refactor value-summary resolver, coordinator, and API
* introduce default kind
* remove $ in variable name
* make extension element name more specific to not collide with interface name
* add element base
* move to section module
* return as observable from resolver
* use extension item repository
* prefix start node feature with user
* add value type and value summary for date-time-with-time-zone property editor
* render timezone
* Add fallback render if no extensions can be found
* Add color-picker value summary and types
* add summary for slider + align types
* make manifest prop name more explicit
* align element name with class name
* reorganize
* manually combine imports to decrease the number of dynamic imports
* export as valueResolver instead of api
* Inline default value-summary kind manifest
* Use single raw value in value-summary coordinator
* Render summaries on Document Collection cards
* format date the same way as the property editor
* first iteration of docs and skills
* updates to docs + skills
* render icon for language collection items
* remove test collection manifest
* delete local language table collection view implementation
* implement the get hrefs method in the user group collection context
* Update controller-host.mixin.ts
* Update entity-name-table-column-layout.element.ts
* Update entity-actions-table-column-view.element.ts
* Handle undefined row element in table rendering
Allow onRowRendered to accept an undefined element and clean up row contexts when a row is unmounted. Update the callback signature in table.element.ts and handle the undefined case in table-collection-view.element.ts by destroying the host and removing the stored context for the item to avoid memory leaks when rows are removed.
* Update controller-host.mixin.ts
* remove test registration
* Prefix type in value key generation
* Skip render when boolean value is undefined
* Add JSDoc and reorder imports in coordinator
* fix lint errors
* Update icons.ts
* valueResolver to class in tests
* Update index.ts
* Add value-summary and value-type Vite entries
* Cache table config and column cell elements
* Use localization for user state labels
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Remove obsolete methods from IDataTypeService and update callers.
* Fixed failing integration test and resolved code review feedback.
* Further code review feedback.
* Introduce shared helper for retrieving data type from property type.
* Change AddElements to a premigration
* Move AddAllowedInLibraryToContentType to premigration
* Remove old migrations and remove obsoleted migratiobase
Includes updating existing migrations and tests to AsyncMigrationBase
* Update claude files
* update xml comment
* Set correct initalstate
* More cleanup
* Remove old migration tests
* Put the test ignore on the right testcase 🙈
* cleanup async migrateasync calls without awaits in tests
* Updated InitialStateVersion
* Refactor element tree controllers to use start node filter service
Move user start node filtering logic from UserStartNodeFolderTreeControllerBase
and ElementTreeControllerBase into a dedicated ElementStartNodeTreeFilterService,
matching the pattern established for document and media trees in PR #22486.
Add a virtual TreeObjectTypes property to UserStartNodeTreeFilterService so
element trees can query both Element and ElementContainer object types.
* Address PR review feedback
* Apply PR review feedback
Replace TreeObjectType (singular) with abstract TreeObjectTypes (array).
Use static readonly arrays in concrete implementations to avoid
allocations.
Move multi-object-type test into UserStartNodeTreeFilterServiceTests
since it exercises base class behavior, not the element service
specifically.
The manual approval gates added for the duplicate-version rerun were
single-use scaffolding for that specific release. Remove them and
tighten Deploy_Npm and Upload_API_Docs to require Deploy_NuGet to
have actually succeeded (Succeeded or SucceededWithIssues) — so a
NuGet failure deliberately blocks the npm release and docs upload.
Keep the structural change to inspect dependencies.Deploy_NuGet.result
directly rather than rely on the transitive succeeded(). That fix is
permanent: it's what protects npm and docs from cascade-skipping
whenever MyGet has another upstream outage.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Both stages used implicit succeeded(), which is transitive across the
full ancestor graph. A MyGet failure (or a NuGet failure on a re-run
where the version is already published) would therefore cascade-skip
both stages even though their own work is independent of those feeds.
Switch them to inspect dependencies.Deploy_NuGet.result directly so
they remain eligible when NuGet ran and either succeeded or failed,
while still being skipped when Deploy_NuGet itself was Skipped (e.g.
non-release runs). Upload_API_Docs additionally requires Build_Docs
to have produced artifacts.
Add a manual approval gate (ManualValidation@0 server job) to each
stage so a NuGet failure caused by something genuinely unrecoverable
(e.g. expired API key) doesn't auto-promote npm or docs publishes -
the operator must explicitly approve each downstream stage.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add manual deploy to NuGet for when MyGet publish fails.
* Simplified instructions for manual approval.
* Gate NuGet release on MyGet's direct result, not transitive succeeded/failed.
succeeded() and failed() are transitive across the full ancestor graph,
so a failure in Unit/Integration/E2E (which skips Deploy_MyGet) still made
or(succeeded(), failed()) evaluate to true and opened the approval gate
on a broken build. Inspect dependencies.Deploy_MyGet.result instead so
Deploy_NuGet only becomes eligible when MyGet itself actually ran.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Remove obsolete UrlSegment extension methods and update callers. Clarify obsoletion of UrlSegment property for Umbraco 19.
* Use 20 for the new obsoletions.
* Align all existing obsolete and non-obsolete calls to retrieve a URL segment to use IDocumentUrlService.
* Fix failing tests.
* Revert incorrectly updated obsoletion removal version.
* extend icons with information from theseaurus
* implement new icon search logic
* clean-up data
* sorting with a backup of the name
* refactor into a controller
* improve multi word group search
* embed lucide data
* rename tech into technology
* remove paper from dollar
* implement fuzzy search for property editor UIs
* minor style update
* improve property editor UI search
* improve search
* improve search data for Property Editor UIs
* remove alias search from property editor ui search
* add usage keywords
* Property editor Suggestions based on Property Label
* related should not show up in search
* rename to suggestionQuery
* update threshold
* separate name words
* also consider full icon name match
* better comment
* other approach for full name matches
* full icon name search if query contains a -
* fix test
* cache all tokens as well
* catch rejection
* resolve feedback
* handle rejected promise
* cancel debounce on disconnect
Co-authored-by: Copilot <copilot@github.com>
* declare voids
* corrections
Co-authored-by: Copilot <copilot@github.com>
* back out if no tokens
---------
Co-authored-by: Copilot <copilot@github.com>
* Implements `auditLog` kind for Elements
* Implements `contentRollback` kind for Elements
* Adds JSDoc comments to element rollback repository and data source
* Exports `UMB_ELEMENT_AUDIT_LOG_REPOSITORY_ALIAS` from `@umbraco-cms/backoffice/element`
Surfaces the constant through the element audit-log barrel so it's available on the public package entry, matching the documents audit-log pattern.
* Added `rollbackNotificationMessage` for Element Rollback
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Adding a more detailed error message when deleting a logged in user
* Fixing overlooked integration test
* Fixing enum binary mistake. Appending enum to the end rather than in the middle.
* Introducing better naming for the enum
* Add element-level extension methods for variance, culture, fallback support
Published Element Extensions now support the same culture, type-checking,
equality, and creator/writer methods that were previously only available
on Published Content Extensions. Content extensions delegate to the
element versions, preserving backwards compatibility.
New element extensions (Core):
- HasCulture, IsInvariantOrHasCulture, CultureDate
- IsDocumentType (both overloads)
- IsEqual, IsNotEqual
- GetCreatorName, GetWriterName
- HasValue with IPublishedValueFallback and Fallback support
New friendly element wrappers (Web.Common):
- Name, CultureDate, CreatorName, WriterName
New non-friendly element extensions (Web.Common):
- CreatorName, WriterName (with IUserService parameter)
* Add unit tests for PublishedElement extension methods
Tests for core extensions (HasCulture, IsInvariantOrHasCulture,
CultureDate, IsDocumentType, IsEqual/IsNotEqual, GetCreatorName,
GetWriterName, HasValue with fallback) and friendly wrappers (Name,
CultureDate, CreatorName, WriterName). All mocks use MockBehavior.Strict.
* Fix empty XML doc param tag for variationContextAccessor in CultureDate
* Delegate content CreatorName/WriterName to element friendly extensions, remove redundant UserService field
* Address PR review: restore StaticServiceProvider in TearDown, use case-insensitive culture dictionary in tests
* Add remarks note about Fallback.ToAncestors not being supported at element level
* Clarify the casting for readability
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Added api helper for reset auth state
* Added more constant variables for login and forgot password message
* Added ui helper for login page
* Added api helper for smtp
* Added tests for backoffice login
* Added tests for backoffice logout
* Added tests for forgot password
* Added api helper for user
* Make tests run in the pipeline
* Updated appsetting to enable reset password
* Added more waits
* Added waits
* Updated locator
* Fix flaky tests
* Updated confirmation message
* Fixed comments
* Removed unused code
* Reverted npm command
* Update Umbraco extension template for OpenAPI route changes
Following the migration from Swashbuckle to Microsoft.AspNetCore.OpenApi
in #21058, the extension template still pointed at the old Swagger URL
pattern and used outdated terminology in code comments.
- generate-client npm script now points at /umbraco/openapi/{name}.json
instead of /umbraco/swagger/{name}/swagger.json
- generate-openapi.js renames swaggerUrl to openApiUrl and updates the
example URL in the missing-argument error message
- UmbracoExtensionApiComposer.cs comments updated from "Swagger" to
"OpenAPI"
* Scope custom OpenAPI document to extension's own endpoints
Without an explicit ShouldInclude predicate, Microsoft.AspNetCore.OpenApi
only includes endpoints whose ApiExplorer GroupName equals the document
name. The template's controller declared a different group name, so the
custom document was created but stayed empty (paths: []), which in turn
made npm run generate-client produce an empty TypeScript SDK.
Filter by the [MapToApi] attribute already present on the extension's
controller base, mirroring the pattern used by the Management and
Delivery API options.
* Add Microsoft.AspNetCore.OpenApi reference to Central package management
The PerProject mode of the umbraco-extension template took a direct
dependency on Microsoft.AspNetCore.OpenApi (with a long comment
explaining why) but the Central mode did not, so default Central
scaffolds failed to build with the source-generator interceptors
error. Mirror the dependency in the Central csproj block and
Directory.Packages.props.
* Remove obsolete logger configuration extensions.
* Removed obsolete database table DTO and constants.
* Removed obsolete LogFiles constant.
* Moved SuperUserId constants obsoletion to 19.
* Remove further reference to removed table.
* Comment out reference to removed table in migration that is also for removal for 18.
* Remove further obsolete methods from LoggerConfigExtensions
* Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Add ModelState.IsValid validation in controller action
* Update method documentation and return simple BadRequest response (aligns with other usages, e.g. BackOfficeController.Verify2FACode).
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* remove inheritance of readonly state
* keep rendering edit in read-only mode
* INVARIANT variant id as static
* parse readonly state, without variant ids as origin is the property read-only state
* stop inheriting read only
* no need for async
* setup read only state based on user permissions
* simplify document-block-property-level-permissions
* make isPermittedForObservableVariant return undefined in bad case
* revert
* improve life cycle for extension initializer
* fix and clean-up
* clean up
* unit test for the actual problem
* clean up
* clean up
* revert logic
* transform access context into local controller
* re-introduce submit create button
* simplify match
* update js docs
* strict compare on config object level, to cover multiple conditions of the same alias.
* Revert "transform access context into local controller"
This reverts commit 1a83d9586b.
* rename file in manifest
* RTE: set manager readOnly
* set fallback on readOnly
* inherit readOnly state when block workspace is invariant
* read-only tag for Block Workspace
* make guard fallback reactive
* observe readOnly languages
* no if sentence
* observe fallback for property + name guards
* prevent cancelled context get to cause problems
* revert removal of || this._isReadOnly check for component rendering
* add comment for clarification
* remove style import
* mark as readonly and make js-const
* remove `as const`
* unit test for reactive fallback feature
* more guard unit tests
* more variantId tests
* move block language access controller to block package
* Update base-extension-initializer.controller.ts
* fix test
* improve switch condition
* offset condition
* Block Workspace: Add data-mark for acceptance test locator
* apply entity-type to the workspace data-mark
* layout-headline
* Updated locator to use new data-mark
* Updated tests to make them less fragile
* null ctrl alias for constructor initiated observations
* import directly
* do not react to not existing user-data or missing context
* add comment
* refactor package registration logic
* package name for code editor
* leave unregistere out
* await load all bundles
Co-authored-by: Copilot <copilot@github.com>
* move initializer to app element
* Batch register extensions with validation
* remove await on load for extension initializers
* Debounce extension updates and set loaded flag
* remove unused imports
* refactor backoffice -> app
* clean up imports
* rename comment
Co-authored-by: Copilot <copilot@github.com>
* base extension initializer is loaded update
* app loader
Co-authored-by: Copilot <copilot@github.com>
* embed umbraco-packages
* remove lazy loads from dataSourceDataMapper
* revert
* enable routes to be undefined
Co-authored-by: Copilot <copilot@github.com>
* comment
Co-authored-by: Copilot <copilot@github.com>
* make sure load only calls once
Co-authored-by: Copilot <copilot@github.com>
* comments and todos
* destroy consumer if existing
* block language access tests
* load user at the end of loading all package modules
* assign symbol for is-trashed observer
* revert language readonly rules
Co-authored-by: Copilot <copilot@github.com>
* is-trashed context + observation
Co-authored-by: Copilot <copilot@github.com>
* read-only as view prop for block list
Co-authored-by: Copilot <copilot@github.com>
* readonly as view prop
* readonly prop for grid,rte,single
Co-authored-by: Copilot <copilot@github.com>
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
Co-authored-by: Copilot <copilot@github.com>
* Avoid render structure view when element type is active
* Avoid render history clean up when is an element type
* Replace hidden sections with inline "not applicable" message for Element Types
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Mark HttpClient IgnoreCertificateErrors as obsolete due to security risk and add TODO to remove in a future release
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
* feat(block): add blockAction extension type for extensible block entry actions
Introduce a new `blockAction` extension type that allows both internal and
3rd-party extensions to register actions on block items. This replaces the
hardcoded Delete button on Block List entries with an extension-registered
action, while keeping Edit Content, Edit Settings, and Copy to Clipboard
as slotted content for incremental migration.
The new `<umb-block-action-list>` element owns the `<uui-action-bar>` and
renders a `<slot>` for hardcoded actions followed by extension-registered
`blockAction` extensions, enabling one-by-one migration of actions.
* feat(block): apply blockAction extension to grid, rte, and single block editors
Extend the blockAction pattern to all remaining block entry elements.
Each editor now uses <umb-block-action-list> with slotted hardcoded
actions and the Delete action registered via the extension registry.
* fix(block): render blockAction extensions directly in uui-action-bar
Replace umb-extension-with-api-slot with UmbExtensionsElementAndApiInitializer
to render blockAction elements as direct children of uui-action-bar. This fixes
the border-radius issue where the wrapper element broke :first-child/:last-child
structural selectors used by uui-action-bar for button styling.
* refactor(block): replace showOnReadOnly meta with BlockEntryIsReadOnly condition
Add a new Umb.Condition.BlockEntryIsReadOnly condition that checks the
read-only state from UMB_BLOCK_ENTRY_CONTEXT. This replaces the inline
read-only guard and showOnReadOnly meta flag on the default kind element.
Delete action uses the condition with match: false (hidden when read-only).
Copy to Clipboard has no condition (always visible). 3rd-party actions
opt in to read-only gating by adding the condition to their manifest.
* feat(block): migrate clipboard copy to blockAction extension
Move the Copy to Clipboard action from hardcoded buttons to a registered
blockAction extension across all four block editors. The copy logic is
moved from each entry element into its respective entry context, with a
base copyToClipboard() method on UmbBlockEntryContext.
* docs(block): add plan for migrating Edit Content and Edit Settings to blockAction
* feat(block): migrate Edit Settings to blockAction extension
Replace the hardcoded Edit Settings button with a blockAction extension
using the default kind. The API class provides getHref() for workspace
navigation and getValidationDataPath() for the invalid badge.
Adds getValidationDataPath() to the UmbBlockAction interface and default
kind element, enabling any blockAction to display a validation badge.
Introduces Umb.Condition.BlockEntryHasSettings condition to control
visibility based on whether the block has a settings element type.
* feat(block): migrate Edit Content to blockAction extensions
Split the hardcoded Edit Content button into two blockAction extensions
controlled by manifest conditions:
- Umb.BlockAction.EditContent — navigates to workspace content view,
shows validation badge via getValidationDataPath()
- Umb.BlockAction.ExposeContent — calls context.expose() when block
is not yet exposed and content edit is hidden
Adds match support to BlockEntryShowContentEdit condition and creates
a new BlockEntryIsExposed condition at the entry level.
Removes the <slot> from umb-block-action-list — all block entry actions
are now fully driven by the extension registry.
* Removes plan/spec files
* chore(block): address review findings for blockAction feature
- Add TODO comment for stale getHref/getValidationDataPath (I-1)
- Remove orphaned @state() properties from all four entry elements (I-2)
- Add UMB_BLOCK_ENTRY_SHOW_CONTENT_EDIT_CONDITION_ALIAS constant and
replace string literals in edit-content/expose-content manifests (I-3)
- Change Expose Content weight from 400 to 399 (S-1)
- Add JSDoc to exported types and classes (S-2)
- Fix condition import alias — rename workspace-level to
UmbBlockWorkspaceIsExposedCondition (S-3)
* fix(block): revert CSS custom property rename to preserve backwards compatibility
Restore the original per-editor CSS custom property names:
--umb-block-list-entry-actions-opacity, --umb-block-grid-entry-actions-opacity,
--umb-block-single-entry-actions-opacity. The action bar opacity styles are
now back in each entry element (using #actions selector), so the unified
property name is no longer needed.
* fix(block): address PR review feedback from Copilot and Claude bots
- Fix Expose button label regression — replace dynamic
'#blockEditor_createThisFor' (function key) with static '#actions_create'
so the button no longer renders "Create undefined"
- Guard empty-string href in EditContent and EditSettings actions —
'workspaceEdit{Content,Settings}Path' emits '' before ready; return
undefined instead of '' so the button doesn't get href="" (which would
navigate to the base URL on click)
- Clear _href in default kind api setter — prevents stale href when the
api is replaced or set to undefined
- Fix barrel imports in 3 block entry conditions — import
UMB_BLOCK_ENTRY_CONTEXT directly from context-token.js rather than via
the ../index.js barrel, reducing circular dependency risk
- Make block-action-list reactive to contentTypeAlias changes — the
extensions initializer is now re-created when unique or
contentTypeAlias changes, so forContentTypeAlias filters apply
correctly when contentTypeAlias resolves asynchronously
- Throw in base copyToClipboard() — the default no-op on
UmbBlockEntryContext now throws rather than logging a warning, so any
future subclass that fails to override fails visibly
Tests for the new conditions were attempted but deferred to follow-up;
context observable mocking semantics need more investigation.
* fix(block): restore uui-action-bar styling on block-action buttons
Remove the `compact` attribute from the inner `<uui-button>` and bridge
the CSS custom properties set by `uui-action-bar::slotted(*:first-child)`
etc. through `<umb-block-action>`'s shadow DOM via intermediate
`--umb-button-*` variables. Without this bridge, `uui-button`'s own
`:host` declarations shadow the inherited values and the first/last
button border-radius + padding don't apply.
* fix(block): address second-pass PR review feedback
- Throw when RTE editor manifest is missing so clipboard entries are
never written with an empty propertyEditorUiAlias (would silently
fail to match on paste)
- Replace bare `return` with `return nothing` in default kind element
render() for type-level clarity
- Add class-level JSDoc to exported block action classes
(UmbEditContentBlockAction, UmbEditSettingsBlockAction,
UmbDeleteBlockAction, UmbCopyToClipboardBlockAction,
UmbExposeContentBlockAction) and UmbBlockActionDefaultElement
* refactor(block): reduce copyToClipboard complexity per CodeScene feedback
Extract `#buildPropertyValue()` helper in List, RTE, and Single entry
contexts to move the four content/layout/settings/expose ternaries out
of copyToClipboard, lowering its cyclomatic complexity.
Split the compound `||` context guards into sequential early-return
checks so each missing context throws with a specific error message,
and the "Complex Conditional" smell is removed.
* refactor(block): further reduce RTE copyToClipboard complexity
Consolidate three sequential `await getContext(...)` calls into a single
`Promise.all`, dropping the cyclomatic complexity below CodeScene's
threshold of 9.
* refactor(block): extract RTE clipboard write into helper method
Split the post-guard write phase into `#writeClipboardEntry` to bring
both methods well under CodeScene's cyclomatic complexity threshold.
* clean up action
Co-authored-by: Copilot <copilot@github.com>
* show edit content / settings despite read-only state
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Copilot <copilot@github.com>
* Rename "Master Template" to "Layout Template" throughout the codebase
Since Umbraco switched from WebForms to MVC, the "Master" template
terminology has been incorrect — in Razor/MVC the parent template is
called a "Layout", not a "Master page". This renames the concept across
C# models, services, repositories, the Management API, and the
backoffice frontend while preserving backward compatibility via
[Obsolete] members scheduled for removal in Umbraco 20.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Remove dead template layout XML element code and rename test methods
The serializer code that wrote <Master>/<MasterAlias> elements was never
executed because Lazy<int>.IsValueCreated was always false after loading
from the database. The corresponding import code that read these elements
was equally dead since no package.xml ever contained them. Template
parent-child hierarchy is resolved from Razor Layout directives instead.
Also renames 4 test methods from "Master" to "Layout" to match the
updated terminology.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Packaging: Suppress noisy log when imported Template has no Layout
A null Layout is legitimate for root layout files (e.g. `Layout = null;`)
and shouldn't be reported as "invalid". Only log when a non-null Layout
was referenced but couldn't be resolved in the import.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Update acceptance tests and further references in comments.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Sebastiaan Janssen <sebastiaan@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Use InvariantCulture when parsing node paths.
* Add suggested validation of setup to integration test.
* Add more explicit tests for negative sign handling
---------
Co-authored-by: kjac <kja@umbraco.dk>
fix(core): clear element entity cache on content type changes
The ContentTypeCacheRefresher clears IContent isolated cache when a
content type changes, but did not clear IElement cache. This caused
stale element entities to be returned after modifying property type
variation settings (e.g. enabling vary-by-culture), leading to 500
errors when saving elements.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Prevent creation of redirects when the old route is unroutable.
* Addressed code review feedback.
* Extend fix to handle case where a second, child page is "redirected" after preview was left open.
(cherry picked from commit 728789aaf6)
* Ensure published querying parity between V13 and V17
* Add unit tests for published ancestor path querying
* Fix Claude review comments
* Make Unfiltered() public on the interface
* Explicitly evaluate "unfiltered" items
* A little clean-up
* Add integration tests
* Addressed code review feedback.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Prevent creation of redirects when the old route is unroutable.
* Addressed code review feedback.
* Extend fix to handle case where a second, child page is "redirected" after preview was left open.
* Uninstall `Swashbuckle.AspNetCore` and install `Microsoft.AspNetCore.OpenApi`
Also installed `Swashbuckle.AspNetCore.SwaggerUI` for now to use as UI only.
* Registered UI and removed or commented out Swashbuckle specific code
* Started configuring the different Open API documents
* Started moving configuration
* Simplifying configuration
* Added missing configuration for the Delivery API
* Added missing configurations for Management API
Still missing polymorphism settings for both APIs
* Adjust Umbraco Extension template with OpenApi changes
* Handle sub types in open api document generation
* Renaming mime types transformer to align with others
* Added discriminator configuration
* Reference Umbraco.Cms.DevelopmentMode.Backoffice from integration tests project to avoid models mode exception being logged in tests
* Now configuring and using the HTTP json options instead of having custom transformers for handling enums and polymorphism
* Fixes to examples
* Update OpenAPI packages
* Mark most transformers as internal
* Simplify adding backoffice security requirements to your API
* Fix missing required properties
* Re-order transformers to fix missing notification headers
* Fix most build errors after regenerating client
* Fix mime types transformer being applied to Management API
* Additional fixes
* Additional fixes to file response types
* Configure Swagger UI documents
* Clear server list
* Sort APIs in UI
* Re-introduce schema handlers and fix issue with nullable enum schema name
* Simplify examples
* Small optimization
* Simplify nullability check in RequireNonNullablePropertiesSchemaTransformer
* Remove unused property
* Small fixes suggested by Claude
* Undo unintended space changes
* Add unit tests for OpenAPI transformers
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Add unit tests for additional OpenAPI transformers
- RequireNonNullablePropertiesSchemaTransformer (7 tests)
- BackOfficeSecurityRequirementsTransformer (10 tests)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Rename SwaggerGen classes to OpenApi for consistency
- Rename ConfigureUmbracoDeliveryApiSwaggerGenOptions to ConfigureUmbracoDeliveryApiOpenApiOptions
- Rename ConfigureUmbracoMemberAuthenticationDeliveryApiSwaggerGenOptions to ConfigureUmbracoMemberAuthenticationDeliveryApiOpenApiOptions
- Rename ConfigureUmbracoManagementApiSwaggerGenOptions to ConfigureUmbracoManagementApiOpenApiOptions
- Rename SwaggerRouteTemplatePipelineFilter to OpenApiRouteTemplatePipelineFilter
- Update DI registrations to use new class names
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Update OpenAPI contract test for Microsoft.AspNetCore.OpenApi
Update expected Delivery API OpenAPI contract to reflect changes from
the migration to Microsoft.AspNetCore.OpenApi:
- OpenAPI version 3.0.4 → 3.1.1
- Nullable types now use type array format (OpenAPI 3.1 style)
- Polymorphic types use anyOf with discriminator
- Security moved from header parameter to securitySchemes
- Removed unnecessary oneOf wrappers around single $ref
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Disable Models Builder in integration tests by default
* Rename Swagger references to OpenApi for consistency
- Rename SwaggerIsEnabled to OpenApiIsEnabled
- Rename SwaggerRouteTemplate to OpenApiRouteTemplate
- Rename SwaggerUiRoutePrefix to OpenApiUiRoutePrefix
- Rename SwaggerUiConfiguration to ConfigureOpenApiUI
- Rename swaggerPipelineFilter variable to openApiPipelineFilter
- Update code comments from "Swagger JSON" to "OpenAPI specification"
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Re-generate Management API open api doc and UI client after merge
* Add reference in comment to additional PR to fix file return types schema
* Fix Open API validation errors
* OpenAPI: Replace ISchemaIdHandler/ISchemaIdSelector with static UmbracoSchemaIdGenerator
Remove the DI-based schema ID handler/selector pattern and replace with a
static UmbracoSchemaIdGenerator utility class. This allows both Umbraco code
and external consumers to call the schema ID generation logic directly, which
is useful since the Microsoft OpenAPI package's schema selectors only apply
to Umbraco's own OpenAPI documents.
- Remove ISchemaIdHandler, ISchemaIdSelector interfaces and implementations
- Add static UmbracoSchemaIdGenerator.Generate() method
- Update ConfigureUmbracoOpenApiOptionsBase to use UmbracoSchemaIdGenerator directly
- Remove constructor dependencies from API options classes
- Add unit tests for UmbracoSchemaIdGenerator and CreateSchemaReferenceId
* Rename CustomOperationIdsTransformer to UmbracoOperationIdTransformer and make public
- Rename class to better reflect its purpose as Umbraco's operation ID transformer
- Change visibility from internal to public so it can be used by external consumers
- Update XML documentation to clarify usage for custom OpenAPI configurations
* OpenAPI: Update Delivery API contract test for new document format
Update expected OpenAPI output to include explicit empty values in
examples and consistent array formatting in security requirements.
* OpenAPI: Remove obsolete DocumentInclusionSelector abstraction
The document inclusion logic is now handled directly by
ConfigureUmbracoOpenApiOptionsBase.ShouldInclude(), making
the separate IDocumentInclusionSelector abstraction unnecessary.
* OpenAPI: Reorganize Management API OpenApi folder structure
- Move transformers to OpenApi/Transformers subfolder
- Move OpenApiOptionsExtensions from Extensions to OpenApi folder
- Update namespaces accordingly:
- Umbraco.Cms.Api.Management.OpenApi.Transformers (transformers)
- Umbraco.Cms.Api.Management.OpenApi (extensions)
* OpenAPI: Add ExcludeFromDefaultOpenApiDocument attribute
- Add [ExcludeFromDefaultOpenApiDocument] attribute for excluding controllers from the default OpenAPI document
- Make ShouldInclude method protected virtual in ConfigureUmbracoOpenApiOptionsBase for extensibility
- Override ShouldInclude in ConfigureDefaultApiOptions to check for the exclusion attribute
* OpenAPI: Add UmbracoOpenApiOptions for configuring OpenAPI routes
Add UmbracoOpenApiOptions configuration class to allow customizing:
- Enabled: Enable/disable OpenAPI and Swagger UI (default: non-production)
- RouteTemplate: Route template for OpenAPI JSON documents
- UiRoutePrefix: Route prefix for Swagger UI
Umbraco sets defaults via Configure, users can override via PostConfigure.
Simplify OpenApiRouteTemplatePipelineFilter to use options directly.
* Pipeline filters: Add OnPreMapEndpoints and rename OnEndpoints to OnPreEndpoints
- Add OnPreMapEndpoints method to IUmbracoPipelineFilter for registering
endpoints inside UseEndpoints without calling UseEndpoints twice
- Rename OnEndpoints to OnPreEndpoints (with backward-compatible default)
- Add PreMapEndpoints and PreEndpoints properties to UmbracoPipelineFilter
- Mark OnEndpoints and Endpoints as obsolete (removal in Umbraco 19)
- Update UmbracoApplicationBuilder to call OnPreMapEndpoints inside UseEndpoints
- Remove redundant UseEndpoints() call from BackOfficeManagementApiFilter
- Update LoadTestController to use PreMapEndpoints instead of Endpoints
Co-Authored-By: Claude <noreply@anthropic.com>
* OpenAPI: Move MapOpenApi to PreMapEndpoints hook
Move OpenAPI endpoint mapping from PostPipeline to PreMapEndpoints
to avoid calling UseEndpoints twice in the pipeline.
* OpenAPI: Rename URL paths from swagger to openapi
- Change OpenAPI UI and document URLs from /umbraco/swagger to /umbraco/openapi
- Rename OAuth client constant from Swagger to OpenApiUi (value kept as
umbraco-swagger for backwards compatibility with existing DB registrations)
- Update display name to "Umbraco OpenAPI access"
- Add DefaultUiEnabled option to allow disabling the default UI while
keeping OpenAPI documents available (enables use of alternative UIs)
- Update MiniProfiler ignored path
Co-Authored-By: Claude <noreply@anthropic.com>
* OpenAPI: Update Microsoft.AspNetCore.OpenApi to 10.0.2
* OpenAPI: Add AddOpenApiDocumentToUi extension method
Adds a public extension method to simplify adding OpenAPI documents to the
UI document selector. This respects the configured UmbracoOpenApiOptions
route template, so users don't need to hardcode paths.
The documentTitle parameter is optional and defaults to the documentName.
Also updates the UmbracoExtension template to use the new method and
fixes the documentation URL reference.
* OpenAPI: Make OpenApiRouteTemplatePipelineFilter internal
The class has no extension points (all methods are private static) and
customization is now done via UmbracoOpenApiOptions instead.
* OpenAPI: Rename DeliveryApiSecurityFilter to DeliveryApiSecurityTransformer
Aligns naming with other OpenAPI transformers for consistency.
* OpenAPI: Simplify Delivery API member authentication configuration
Replace ConfigureUmbracoMemberAuthenticationDeliveryApiOpenApiOptions with
a simpler AddDeliveryApiOpenApiMemberAuthentication() extension method on
IServiceCollection. This hides implementation details and provides a cleaner
API for users to enable member authentication in the Delivery API OpenAPI document.
* OpenAPI: Add reference to proposal for custom JSON options support
* Move Delivery API transformers to OpenApi/Transformers folder
Aligns the folder structure with the Management API project.
* Update OpenAPI contract tests to use new URL format
Changed from /swagger/{name}/swagger.json to /openapi/{name}.json
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Cms.Api.Delivery/DependencyInjection/UmbracoBuilderExtensions.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fix IAuthorizationService injection detection in BackOfficeSecurityRequirementsTransformer
- Fix bug where parameter.GetType() was used instead of parameter.ParameterType,
causing the IAuthorizationService injection check to always return false
- Replace magic number with BaseAuthorizeAttributeCount constant
- Improve comments explaining the 403 response logic
- Add test for IAuthorizationService injection detection
* Remove unnecessary InterceptorsNamespaces from API projects
* Remove default implementations from IUmbracoPipelineFilter methods
* Update documentation for Microsoft.AspNetCore.OpenApi migration
- Update CLAUDE.md files to reflect the migration from Swashbuckle to Microsoft.AspNetCore.OpenApi for document generation
- Update URL paths from /umbraco/swagger/ to /umbraco/openapi/
- Rename swaggerPath variables to openApiPath in test files
- Update references to removed types (SchemaIdHandler, OperationIdHandler, etc.) with their new equivalents (UmbracoSchemaIdGenerator, UmbracoOperationIdTransformer)
- Remove outdated technical debt reference to deleted SwaggerDocumentationFilterBase
* Update Swashbuckle.AspNetCore.SwaggerUI to 10.1.2
Fixes browser caching behavior and document URL serialization issues.
* Refactor OpenAPI contract tests with validation
- Add OpenAPI spec validation for both Delivery and Management APIs
- Delivery API: Store expected contract in external JSON file for regression testing
- Management API: Compare generated contract against expected contract endpoint
- Organize Delivery API tests under OpenApi/ subdirectory
- Auto-generate Delivery API contract file if it doesn't exist
* Update ElementReferenceResponseModel type reference after OpenAPI regeneration
* Add discriminator values to Delivery API polymorphic JSON serialization
ConfigureJsonPolymorphismOptions now passes derivedType.Name as the
discriminator value for each JsonDerivedType, ensuring the $type property
is present in responses and the OpenAPI schema is valid.
* Move Delivery API OpenAPI contract tests to Umbraco.Api.Delivery folder
* Update Microsoft.AspNetCore.OpenApi to 10.0.3 and Swashbuckle.AspNetCore.SwaggerUI to 10.1.4
* Use JsonDerivedType attributes for Delivery API polymorphic serialization
Move discriminator configuration from ContentJsonTypeResolverBase to
JsonDerivedType attributes on the interfaces. This is the standard STJ
approach and keeps the resolver available for custom overrides only.
* Add OpenAPI test for custom derived type extensibility
Extract shared test infrastructure into OpenApiTestBase and add
OpenApiCustomDerivedTypeTest to verify the OpenAPI spec remains valid
when a consumer registers a custom derived type via
ContentJsonTypeResolverBase.GetDerivedTypes.
* Fix OpenAPI contract test failing on CI due to ContinuousIntegrationBuild path normalization
[CallerFilePath] embeds a compile-time source path that gets normalized to /_/... on Azure DevOps
agents when ContinuousIntegrationBuild=true. At runtime the expected contract file is not found at
that path, causing the test to attempt Directory.CreateDirectory("/_/...") which fails with
permission denied.
Fix by reading contract files from the output directory (CopyToOutputDirectory) instead of the
compile-time source path. The [CallerFilePath] approach is kept only for writing new contracts
during local development, wrapped in a try/catch so it fails gracefully on CI.
* Bump Swashbuckle.AspNetCore.SwaggerUI to 10.1.7
* Remove duplicate InternalsVisibleTo for Umbraco.Tests.UnitTests
* Extract ReplaceOpenApiSchemaService into shared Api.Common helper
Deduplicates the internal OpenApiSchemaService replacement logic
between Management API and Delivery API into a single internal
extension method in Umbraco.Cms.Api.Common. Uses assembly and type
name checks derived from a public type (OpenApiOptions) instead of
hardcoded strings for safer matching.
* Tighten visibility and improve DI extension structure
- Mark FixFileReturnTypesTransformer as internal (temporary workaround)
- Mark AddUmbracoApiOpenApiUI and AddUmbracoApi as internal
- Rename AddUmbracoApi to AddUmbracoOpenApiDocument on IUmbracoBuilder
- Move AddOpenApiDocumentToUi to OpenApiServiceCollectionExtensions
- Encapsulate ReplaceOpenApiSchemaService inside AddUmbracoOpenApiDocument
as an optional jsonOptionsName parameter
* Regenerate OpenApi.json to fix duplicate document patch endpoint
* Move MimeTypesTransformer to shared base and respect [Consumes]
Moves the MIME type filtering from a Delivery API-only document
transformer to a shared operation transformer in Api.Common. When
[Consumes] is present, replaces content types with exactly what it
declares (fixing application/json-patch+json on the patch endpoint).
Otherwise strips non-application/json types. Regenerates OpenApi.json
and client SDK.
* Move Umbraco-specific transformers from shared base to API configs
RequireNonNullablePropertiesSchemaTransformer, FixFileReturnTypes
Transformer, and MimeTypesTransformer are now registered only in
the Management and Delivery API configs. The default API document
(used for consumer endpoints) no longer applies these opinionated
transformers.
* Clarify XML doc for UmbracoOpenApiOptions.Enabled
* Use alphabetically-first tag across all operations for stable path sorting
* Update MimeTypesTransformer tests for operation transformer interface
* Reference dotnet/aspnetcore#66340 in ReplaceOpenApiSchemaService docs
* Add unit tests to verify OpenApiSchemaServiceExtensions usage of internal types.
* Bumped Microsoft.AspNetCore.OpenApi from 10.0.4 to 10.0.6 to match Directory.Packages.props and removed unnecessary Swashbuckle reference.
* Fix indentation.
* Defensively handle a non-integer status code response key in ResponseHeaderTransformer.
* Use TryGetValue in RequireNonNullablePropertiesSchemaTransformer to avoid potential KeyNotFoundException.
* Additional tests and clarifying comments.
* Revert accidental local dev changes to Program.cs, Web.UI.csproj and StaticAssets.csproj.
* Tighten visibility of OpenAPI configuration and transformer classes to internal
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Updated element creation step due to UI changes
* Updated element creation due to UI changes - cont
* Removed unused locator
* Updated locator for elementTreeItem
* Updated tests for library to match the UI changes
* Updated locator for elementVariantDropdown
* Updated tests for element permission and start nodes
* Removed @smoke tags
* Make tests run in the pipeline
* Added comment for failing tests
* Updated tests for element start nodes as the front-end does not support adding a element as start nodes
* Fix flaky tests
* Fixed comment
* Removed obsolete methods and default implementations on IEmailSender.
* Removed the obsolete and unused MemberConfigurationResponseModel.
* Remove the obsolete MediaPermissions and ensure test coverage is maintained.
* Extends `UmbContentRollbackModalValue` with `UmbEntityModel`
so that the Rollback modal can return the entity-type,
to display the correct notification message.
* Housekeeping
* Added localized fallback key
* Fixed typecasting issue for deprecated Document rollback
* Reverted logic, introduced `rollbackNotificationMessage` meta prop
* Added constant variables for audit trail
* Added ui helper for audit trail
* Added tests for audit trails in content
* Added test for audit trail when trash content
* Added tests for audit trail when sort. move and rollback content
* Added tests for audit trail when bulk actions
* Updated tests for creating content
* Fixed comment
* bug(#22607) Add Directory.Packages.props and update restore command
Updated Dockerfile to include Directory.Packages.props and modified restore command to resolve docker build errors during dotnet restore step. Resolves issue #22607
* fix(template): conditionally copy Directory.Packages.props in Dockerfile
Only copy Directory.Packages.props when CPM is enabled, as per-project
package management users won't have this file in their build context.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: mole <nikolajlauridsen@protonmail.ch>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
(cherry picked from commit df3cd50e7f)
* Generate random guid for cert pass
* Changes from review
* Move cert generation and add script to trust cert on host machine
* Generate simple hmac key
(cherry picked from commit fcf5af3d16)
* bug(#22607) Add Directory.Packages.props and update restore command
Updated Dockerfile to include Directory.Packages.props and modified restore command to resolve docker build errors during dotnet restore step. Resolves issue #22607
* fix(template): conditionally copy Directory.Packages.props in Dockerfile
Only copy Directory.Packages.props when CPM is enabled, as per-project
package management users won't have this file in their build context.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: mole <nikolajlauridsen@protonmail.ch>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* add redirect tracking workspace
* change weight to match v13 order
* add missing alignment and text colour
* Align closer with referency by element
* Ad repository pattern from review
* remove obsolete
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/redirect-management/info-app/document-redirect-management-workspace-info-app.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adds JSDocs
* Removed unused `created` and `documentUnique` from `UmbDocumentRedirectUrlModel`
* Align `setStatus` and `delete` return shape with other data source methods
* Align workspace context observer with sibling info-app pattern
* Polish dashboard and info-app: localize hardcoded strings, tidy templates and imports
* Apply review simplifications
- Drop duplicate `unique` guards from data source (kept at repository boundary)
- Drop unnecessary `?? []` fallbacks (`items` is non-nullable in the API type)
- Localize hardcoded zero-results strings in dashboard
- Simplify redundant length check in info-app `#getTargetUrl`
- Drop unused `userIsAdmin` from `UmbDocumentRedirectStatusModel`
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Mark RTE as supports read only
* RTE: Address read-only review feedback
- Remove `pointer-events: none` from `:host([readonly])` so users can select and copy text in read-only mode
- Make the editor's editable state reactive to the `readonly` property via `setEditable`
- Skip rendering the statusbar in read-only mode (mirrors the toolbar) to avoid the missing border-radius regression
- Remove the now-unused `readonly` property from `umb-tiptap-toolbar` and `umb-tiptap-statusbar`
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* init current user workspace
* adding current user workspace and their apis
* add new controllers
* add default implementation
* Update src/Umbraco.Core/Services/UserService.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Cms.Api.Management/ViewModels/User/UpdateCurrentUserRequestModel.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update tests/Umbraco.Tests.Integration/Umbraco.Core/Services/UserServiceCrudTests.Update.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Core/Models/CurrentUserUpdateModel.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* update openApi.json, remove userKey from model, remove redundant authentication check from controllers
* update localize
* allow blob: URLs in img-src CSP for avatar
* save image change later
* Remove references to "current" user from service layer.
Align validation for user profile update with update user service method.
Controller tidy-up of dependencies.
* Add missing controller from last commit.
* resolve conflicts 2
* Renamed/relocated "current-user-workspace" to "profile/edit"
Refactored the "Edit" (profile) button logic,
to handle the check whether the user has access to the Users section.
* Removed the "Section User No Permission" condition
as no longer used.
* UI tweaks + streamlining
* Profile edit: surface save errors and avoid blob URL leak
- Show danger notification when avatar upload/delete or profile update fails
- Refresh current user after avatar upload so the store holds server URLs, not a leaking local blob
- Element save() methods now return boolean; modal keeps itself open when a save fails and no longer double-submits
* Refactored to use `asPromise()`
* Current User: Adapt edit-profile modal into a workspace extension
Replaces Umb.Modal.CurrentUserEditProfile with a workspace registered
against entityType 'current-user'. The UmbSubmittableWorkspaceContextBase
subclass owns the editable user model and pending avatar state; submit()
coordinates uploadAvatar / deleteAvatar / updateProfile and throws on
failure so the workspace stays open, relying on the repository's existing
danger notifications.
The current-user "Edit" action now opens UMB_WORKSPACE_MODAL (sidebar,
small) instead of the bespoke modal. Avatar and settings children become
presentational views wired to the workspace context.
* Current User workspace: Address review findings
- Await initial load promise in submit() to prevent a race where the save
action fires before the first requestCurrentUser() resolves.
- Guard the avatar element's async observer setup against post-disconnect
attachment.
- Document the split between #data (editable persisted state) and
#pendingAvatar (transient UI state) in the workspace context.
- Remove stray JSDoc whitespace in current-user.server.data-source.ts.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* fix raw sql with ISqlSyntaxProvider name escaping
* reduce hard coded strings
* Fix Raw Sql in MemberFilterRepository
* fix formating
* restore MemberFilterRepository
* Correct usage of field name constant.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fix raw sql with ISqlSyntaxProvider name escaping
* reduce hard coded strings
* Fix Raw Sql in MemberFilterRepository
* fix formating
* restore MemberFilterRepository
* Correct usage of field name constant.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Prevent Concurrent_Save_Same_Login_Should_Not_Throw_Duplicate_Key_Exception from failing when exceptions other than what is being guarded against are triggered.
* Addressed code review feedback.
* Generate random guid for cert pass
* Changes from review
* Move cert generation and add script to trust cert on host machine
* Generate simple hmac key
* Add table collection view and manifests
* Use table kind in collection example
* Update entity-name-table-column-layout.element.ts
* Recompute table rows when item hrefs change
* define and render columns from manifest
* wip language implementation
* map to unique field
* rename to label
* test implementation for users table
* clean up
* add example entity actions
* add example description
* Update table-collection-view.element.ts
* Omit base 'meta' and relax table meta type
* Hardcode description column when present
* localize column names
* Update table-collection-view.element.ts
* Type manifest on collection view elements
* Use UmbLitElement instead of LitElement
* fix types
* Update entity-name-table-column-layout.element.ts
* provide entity context for each table row
* fix breaking change and introduce a deprecation warning
* Add status column to example collection view + localize column labels
* implement the UmbTableColumnLayoutElement interface
* add tests for the table collection view
* Make host element optional; add table docs/types
* Update controller-host.mixin.ts
* Update src/Umbraco.Web.UI.Client/src/packages/core/entity-action/global-components/entity-actions-table-column-view/entity-actions-table-column-view.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update controller-host.mixin.ts
* Update entity-name-table-column-layout.element.ts
* Update entity-actions-table-column-view.element.ts
* Handle undefined row element in table rendering
Allow onRowRendered to accept an undefined element and clean up row contexts when a row is unmounted. Update the callback signature in table.element.ts and handle the undefined case in table-collection-view.element.ts by destroying the host and removing the stored context for the item to avoid memory leaks when rows are removed.
* Update controller-host.mixin.ts
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Align GUID-via-UDI and integer locallink sources in migration to consistent type attribute casing.
* Handle Pascal cased type attributes from local links.
* Preserve segment-specific property values after save and publish.
* Addressed feedback from code review.
* Moved fix to a projection in UmbPropertyValuePresetVariantBuilderController.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Preserve segment-specific property values after save and publish.
* Addressed feedback from code review.
* Moved fix to a projection in UmbPropertyValuePresetVariantBuilderController.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Add XML header comments and unit tests for member operation surface controllers.
* Addressed code review feedback.
* Further code review feedback.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Add a constant for the "unroutable content" route
* Add one more constant for URL provider exceptions
* Update src/Umbraco.Core/Routing/UrlProviderExtensions.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Core/Constants-Routing.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Core/DeliveryApi/ApiContentRouteBuilder.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Conditionally render history & structure settings
* Show "not applicable" message instead of hiding the settings
* Refactored to reuse `#renderElementDoesNotSupport()`
* Modified "Allow in Library"
to display a message instead of hiding the field.
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Definition and validation of minimum range for slide property editor.
* Address code review feedback.
* Treat an incorrectly configured negative minimum range as zero.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Ensure that DocumentUrlService and DocumentUrlAliasService will respect read-only, subscriber databases.
* Fixed breaking change in constructor.
* Clarified comment.
* Use pattern matching in SkipDatabaseWrites() check.
* Ensure that DocumentUrlService and DocumentUrlAliasService will respect read-only, subscriber databases.
* Fixed breaking change in constructor.
* Clarified comment.
* Use pattern matching in SkipDatabaseWrites() check.
* Make ApplicationMainUrl on IHostingEnvironment nullable.
Update usage in HttpsCheck healthcheck and add unit tests to verify refactor.
* Improves XML documentation for the property.
* fix(frontend): use keyed repeat for umb-table columns to fix Firefox rendering (#22411)
Column rendering used .map() without keys, causing Firefox's CSS
table-* layout to break when columns changed after initial render.
Switch to repeat() with column.alias keys so Lit properly inserts/removes
DOM nodes. Also removes a stray </uui-table-cell> closing tag.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(frontend): wrap umb-table in Lit `keyed` so Firefox rebuilds the table when columns change
The `repeat()` + alias key change alone did not fix the Firefox issue: Firefox's
`display: table-*` layout engine fails to relayout when cells are inserted into
existing rows, even when Lit's keyed reconciliation does the right thing.
Wrap the `<uui-table>` render in `keyed(columnKey, ...)` so that whenever the
column set changes (keyed on the joined column aliases), Lit discards the entire
subtree and builds a fresh one. Firefox then paints a brand-new table and its
buggy incremental relayout path never runs.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* docs(frontend): document UmbTableColumn.alias uniqueness constraint
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix(frontend): reattach sorter on column rebuild and harden column key
Address two review comments on the keyed() rebuild:
- UmbSorterController caches its container element on first
initialization, so when keyed() replaces <uui-table> the sorter stays
attached to the detached node. Toggle disable()/enable() in updated()
when the column signature changes and the table is sortable, so the
sorter reattaches to the fresh table.
- Build the column key via JSON.stringify instead of a pipe-joined
string, so aliases containing '|' can't collide and defeat the rebuild.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Content: Clear per-culture published flags when copying a document (closes#22540)
When copying a published culture-variant document, the document-level
published flag was cleared on the copy, but the per-culture published
info (mapped to umbracoDocumentCultureVariation.published) was carried
over from the source. This left the database in an inconsistent state
where the document was unpublished overall but each culture row
reported published=1.
Clear PublishCultureInfos on both the root copy and its descendants
alongside the existing Published=false assignment so no culture
variations are persisted as published on the copy.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* Address review feedback: use ClearPublishInfos() helper + add recursive test
- Replace direct property assignment with the existing ClearPublishInfos()
extension method for semantic clarity and consistency with UnpublishCulture.
- Rename test to match the Can_Copy_* convention used by neighbouring tests.
- Add a second test that exercises the recursive descendant path, confirming
per-culture published flags are also cleared on descendants.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* Updates integration tests to explicitly verify the fix.
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fix: prevent open redirect in public surface controllers by validating RedirectUrl with Url.IsLocalUrl
* Update src/Umbraco.Web.Website/Controllers/UmbLoginStatusController.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Web.Website/Controllers/UmbProfileController.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Web.Website/Controllers/UmbRegisterController.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Revert "Dependencies: Upgrade NUnit and related test dependencies to latest major versions (#22155)"
This reverts commit 7014f9a125 on v18/dev
to resolve the Part3Of4 SQL Server integration test nightly hangs that
started around 2026-04-10.
Root cause was confirmed by hang-dump analysis: a sync-over-async call
in ContentCacheRefresher.HandleMemoryCache
(.GetAwaiter().GetResult() on an async cache method) that NUnit 3's
pumping synchronization context had been quietly completing on the test
thread. NUnit 4 dropped that behaviour, so the continuation now requires
a free thread-pool thread; under CI conditions it deadlocks.
Reverting #22155 on a branch was verified to make the nightly pass.
This is a temporary rollback to unblock v18; the proper fix is to make
ContentCacheRefresher.Refresh async end-to-end, tracked separately.
Additional adjustments beyond the pure revert to keep the branch
compiling:
- CoreConfigurationHttpTests.cs: added `using Umbraco.Cms.Core.Services;`
for IUserService (referenced by post-#22155 code unaffected by the
revert).
- ContentVersionCleanupServiceTest.cs: merged imports so both
AutoFixture.NUnit3 (from revert) and Microsoft.Extensions.Options
(from unrelated later commit) stay.
- UdiTests.cs and ContentPermissionResourceTests.cs: removed unused
`using NUnit.Framework.Legacy;` (namespace introduced in NUnit 4).
- BackOfficeAuthorizationInitializationMiddlewareTests.cs: replaced
`[CancelAfter(5000)]` with its NUnit 3 equivalent `[Timeout(5000)]`.
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Correct logging and swallowing of exceptions when retrieving references with changed property types.
* Addressed code review feedback.
* Change multi URL picker to fall back to returning an empty collection if the links JSON could not be deserialised.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Defensively handle case where published status in databse is corrupt.
* Addressed code review feedback.
* Further code review feedback.
* Similar fix for NRE in rebuild of document URLs.
* Add option for rebuild following content type update in the background.
* Add integration test for deferred rebuild.
* Addressed code review feedback.
* add retry and graceful shutdown to deferred cache rebuild.
* Prevent shared DB connection in deferred rebuild background task.
* Move deferred rebuild trigger to post-scope notification.
* Introduce similar deferred behaviour for Examine reindexing.
* Prevent background cache rebuild from blocking foreground content saves.
* Handle potential case of primary key constraint violation when deferred rebuilding content cache and a content item is saved.
* Improved variable naming.
* Add migration to fix data type storage for labels configured with a long string value type.
* Fixed class name and added additional test from code review feedback.
* Further code review feedback.
* Add further test.
* Support separate database DbContexts in AddUmbracoDbContext.
* update internal callers to use new non-obsolete AddUmbracoDbContext overload
- UmbracoEFCoreComposer now calls the new overload with explicit shareUmbracoConnection: true
- Add #pragma CS0618 suppression for v18-obsolete overloads delegating to v19-obsolete overloads
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Update further internal caller to use non-obsolete method.
* Addressed code review feedback.
* Updates after merge/final local review.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Optimize ContentTypeRepository to avoid unnecessary deep-cloning on cache reads.
* Used lightweight benchmark and addressed code review comments.
* Optimize TemplateRepository to avoid unnecessary deep-cloning on cache reads.
* Optimize DomainRepository to avoid unnecessary deep-cloning on cache reads.
* Optimize remaining repositories to avoid unnecessary deep-cloning on cache reads.
* Present dialog for further action after creating an API user.
* Addressed code review feedback.
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
The allowlist referenced mcp__github__create_issue_comment, which
doesn't exist in github-mcp-server v0.17.1 (the tool is
add_issue_comment). Claude's attempts to comment were denied, so
duplicates were labelled but no explanation comment was posted.
Also adds a workflow_dispatch trigger with an issue_number input and
enables show_full_output so future denials are visible in logs.
* eslint rule for Manifest Aliases
* update to handle propertyEditorSchema aliases
* make typescript check
* support localization alias
* Make consts for theme manifests
* no rules for themes
* fix not used, double media-type-root manifest, clean up.
* Improve pascal cases test
* Models, service, repository and migration for external members.
* Integrate identity for external members in MemberUserStore.
* When autolinking external member, skip member type.
* Populate profile.
* Revoke member tokens for delivery API for external members.
* Audit notification handling.
* Management API updates for external members.
* Added IMemberFilterService for combined member queries from management API.
* Referenced by member controller with external members.
* Guard password reset for external members.
* Remove ExternalMemberSettings.
* Convert between content and external members.
* Fixed ambiguous constructor.
* Update OpenApi.json.
* Update client SDK.
* Backoffice ui for external members.
* Refactor member collection retrievel to use presentation factory.
Fixes in testing.
* Fixes from testing.
* Fix icon display on member picker.
* Add external member support to member picker value converter.
* Delete fix, sync data fix, Examine indexing, member collection default icon.
* Add cache refreshers for external members.
* Remove unused "fast path" for just updating login properties.
* Addresed code review feedback.
* Further integration tests.
* Fixed failing unit test.
* Update typed client.
* Addressed code review feedback.
* Early return to reduce nesting in ReferencedByMemberController.
* Introduce MemberPresentationService and MemberReferenceService to move logic out of controllers.
* Test for and fix SQLite deadlock related to cross-store uniqueness checks.
* Additional fix for the "content" member creation.
* Defer external member Examine indexing via the background task queue.
* Add update date to external member record (aligning with content members).
* Add TreatLoginAsMemberUpdate config so member re-index can be skipped on login.
* Add logging to help verify the indexing path chosen on login and register.
* Move ExternalMemberService into Core to align with MemberService.
* Fix deserialization issue with Json payloads.
* Display of external member profile data in backoffice.
* Fixed breaking change.
* Consider existing behaviour of bumping update date on login to be a bug, so no need for configuration and backward compatibility efforts.
* Reduce user start node tree filtering code duplication
Extract shared start node filtering logic from UserStartNodeTreeControllerBase
into a dedicated service hierarchy (IUserStartNodeTreeFilterService and
domain-specific implementations for documents and media).
Existing constructor signatures and protected members are preserved as
obsolete to maintain backward compatibility for external consumers.
* Disambiguate DI constructor resolution for tree controllers
Adds obsolete constructors accepting both the legacy dependencies and the new IDocument/IMediaStartNodeTreeFilterService to the eight concrete tree controllers and to MediaTreeControllerBase. These serve as a superset constructor that lets the DI container unambiguously resolve a single constructor, since the new and existing obsolete constructors have non-subset parameter sets and [ActivatorUtilitiesConstructor] is not honoured by CallSiteFactory at ServiceProvider validation time.
* Address review feedback
- Change constructors on DocumentStartNodeTreeFilterService and
MediaStartNodeTreeFilterService from public to internal (classes are
already internal).
- Add [EditorBrowsable(Never)] to the disambiguation constructors so
IDEs hide them from autocomplete.
- Add inline comments explaining the empty-array fallback in the
obsolete GetUserStartNodeIds/GetUserStartNodePaths overrides.
* Revert filter service constructors to public
DI container requires public constructors for activation, even on
internal classes. Reverts the internal change from the previous commit.
* Add unit tests for UserStartNodeTreeFilterService
Tests ShouldBypassStartNodeFiltering (root access, data type ignore,
no access), MapWithAccessFiltering (access/no-access/missing entities),
and delegation to IUserStartNodeEntitiesService for root, child and
sibling filtering including mixed access scenarios.
* Simplify obsolete-ctor path on document and media tree controllers (#22546)
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Removed line clamp for data type picker
* Removed line clamp on additional labels
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* add users section into user group
* fix test failed
* fix unchange issue
* add notification
* add remainging count
* update take 100
* split user list into separate element
* add localization for text
* add repository for user list in user group
* update key message
* remove remainingCount from user-input
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added early steps of member auth
* Cleaned up
* Cleaned up again
* Cleaned up
* Fixes based on comments
* Updated name of helper
* Reverted to old smokeTest command
* Emit relation saved and deleted notification when automatic relations are added and removed during content updates.
* Addressed code review feedback.
* swapping from column to row
* adds same look for when you upload image on a content node
* Remove duplicated css property
---------
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Avoid requirement for IBackOfficeStore registrations for non-backoffice configured setups.
* Apply same update to other read method potentially called from non backoffice setups.
* Remove comment.
* Preserve GetUserById upgrade fallback; strengthen test assertions
- Add IRuntimeState to UserService and mirror the DbException catch
from BackOfficeUserStore.GetAsync(int) in GetUserById, so the
upgrade-time fallback to GetForUpgrade is preserved.
- Use non-empty arguments in the delivery-only integration test so
the repository-backed code paths are actually exercised, not just
the early-return guards.
- Update UserServiceCrudTests to pass IRuntimeState to the new
constructor parameter.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Introduce IBackOfficeUserReader to avoid code duplication for user read methods between UserService and BackOfficeUserStore.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Implement ElementCacheService with HybridCache backing and database cache support
Fully implements ElementCacheService as the elements equivalent of DocumentCacheService,
backed by Microsoft HybridCache (L1 in-memory + L2 distributed) with database cache table
persistence via cmsContentNu.
Key changes:
- ElementCacheService: full implementation with HybridCache, draft/published separation,
converted element L0 cache, cache tagging, preview service support, and seeding infrastructure
- IDatabaseCacheRepository: added element CRUD methods (Get/Refresh/Rebuild) with SQL queries
using ElementDto/ElementVersionDto
- IContentCacheService: extracted common base interface shared by Document, Media and Element
cache services (8 shared methods including Seed, Rebuild, memory cache operations)
- CacheRefreshingNotificationHandler: added element notification handling, content type changes
now route to element or document service based on IsElement, refactored to single-pass
classification with shared RefreshCacheForContentTypeChanges method
- ElementRefreshNotification: new notification wired to ElementRepository.OnUowRefreshedEntity
- Renamed document-specific methods for clarity (GetContentSource -> GetDocumentSource,
RefreshContent -> RefreshDocument, CreateContentNodeKit -> CreateDocumentNodeKit,
RebuildContentDbCache -> RebuildDocumentDbCache)
- Renamed shared DTOs (CacheRebuildDocumentDto -> CacheRebuildPublishableContentDto) since
they're used by both documents and elements
- Extracted shared RebuildPublishableDbCache method to eliminate duplication between document
and element rebuild logic
* Add element navigation service, publish status tracking, and breadth-first seeding
Adds the infrastructure needed for element cache seeding:
- ElementNavigationService: provides tree traversal for elements, following the
same pattern as DocumentNavigationService/MediaNavigationService
- Split PublishStatusService into an abstract base class with DocumentPublishStatusService
and ElementPublishStatusService subclasses, each with their own interfaces
(IDocumentPublishStatusQueryService, IElementPublishStatusQueryService, etc.)
- ElementBreadthFirstKeyProvider: seeds the element cache on startup by traversing
the element tree breadth-first, filtering out unpublished elements
- Element publish status is initialized on startup and kept in sync via
ElementCacheRefresher
- Old IPublishStatusQueryService/IPublishStatusManagementService interfaces kept
as obsolete for backward compatibility
- Non-breaking constructor changes for ContentCacheRefresher, DocumentUrlService,
ApiContentRouteBuilder via obsolete constructor overloads
* Fix element CacheNodeFactory to set IsDraft from preview parameter
CacheNodeFactory.ToContentCacheNode(IElement, bool preview) was hardcoding
IsDraft = false instead of using the preview parameter. This caused
RefreshElementAsync to never write draft cmsContentNu rows, because
DatabaseCacheRepository.RefreshElementAsync skipped the draft write when
IsDraft was false.
* Use ElementTree lock instead of ContentTree in ElementCacheService
RefreshMemoryCacheAsync was using Constants.Locks.ContentTree instead of
Constants.Locks.ElementTree for the read lock.
* Add ElementCacheServiceTests and fix PublishStatusServiceTests for abstract base
- ElementCacheServiceTests: 9 integration tests covering draft/published retrieval,
rebuild, delete, and RefreshElementAsync behavior
- Updated PublishStatusServiceTests to use DocumentPublishStatusService instead of
the now-abstract PublishStatusService
* Add IPublishedElementCache facade for public element cache access
Introduces the public-facing element cache interface and implementation,
following the same pattern as IPublishedContentCache/IPublishedMediaCache.
- IPublishedElementCache: async-only interface (no legacy sync methods)
- ElementCache: facade delegating to IElementCacheService
- Added Elements property to ICacheManager, IUmbracoContext, and their
implementations
* Add ElementHybridCacheTests and ElementHybridCacheElementTypeTests
Integration tests exercising the full element cache pipeline via
IPublishedElementCache:
ElementHybridCacheTests (7 tests):
- Draft/published retrieval by key
- Unpublished element not accessible without preview
- Draft of published element accessible
- Updated draft element reflects changes
- Deleted element removed from cache
- Element name accessible
ElementHybridCacheElementTypeTests (3 tests):
- Structural type change removes property from cached element
- Non-structural type change preserves property values
- Element removed from cache when element type is deleted
* Fix element navigation to include containers and support breadth-first seeding
The element tree contains both elements and containers (folders) with different
object types. The navigation service now queries both object types to build
the full tree hierarchy.
- Added multi-objectType overloads to INavigationRepository and
ContentNavigationRepository using LEFT JOIN to support nodes without
content rows (containers)
- Single-objectType methods now delegate to the multi-objectType implementation
- ElementNavigationService queries both Element and ElementContainer object types
- ElementBreadthFirstKeyProvider traverses containers without seeding them,
only counting published elements toward the seed limit
- Added ElementBreadthFirstKeyProviderTests (9 tests) including container
traversal scenarios
* Add ElementContentTypeSeedKeyProvider for content-type-based element seeding
Seeds elements whose content types match the configured CacheSettings.ContentTypeKeys,
mirroring the existing ContentTypeSeedKeyProvider for documents. Both providers read
from the same configuration list — document type keys seed documents, element type
keys seed elements.
* Fix ContentNavigationServiceTest mocks for multi-objectType repository overload
The single-type GetContentNodesByObjectType(Guid) now delegates to the
multi-type overload. Updated test mocks to match the IEnumerable<Guid>
signature, verifying exactly one key containing Constants.ObjectTypes.Document.
* Skip Cannot_Get_Published_Again_After_Trashing test
Trashing does not clear the published cache — this is a pre-existing issue
that also affects documents. When a cached item is trashed, the HybridCache
entry remains because RefreshMemoryCacheAsync does not remove entries when
the database returns null for trashed items.
* Replace unsafe casts with StaticServiceProvider in obsolete constructors
The obsolete constructors in ApiContentRouteBuilder and DocumentUrlService
were using direct casts from IPublishStatusQueryService to
IDocumentPublishStatusQueryService, which would fail at runtime for
external consumers compiled against pre-v18 binaries. Use
StaticServiceProvider.Instance.GetRequiredService instead, consistent
with the pattern in ContentCacheRefresher.
* Remove duplicate XML doc summary in GetElementCultureDataForNodes
* Add obsolete constructors for backward compatibility
Preserve the old constructor signatures for CacheManager,
NavigationInitializationNotificationHandler, and
PublishStatusInitializationNotificationHandler so that external
consumers compiled against pre-element-cache versions don't break.
New dependencies are resolved via StaticServiceProvider.
* Pass cancellationToken to ExistsAsync in ElementCacheService.SeedAsync
* Fix DocumentUrlServiceTests to use IDocumentPublishStatusQueryService
* Trigger Build
* Address PR review feedback
- Rename HandlePublishedAsync to HandlePublishStatusAsync in
ContentCacheRefresher for consistency with ElementCacheRefresher
- Make ElementCacheRefresher.HandlePublishStatusAsync async to align
with ContentCacheRefresher's pattern
- Replace inline comments with #region blocks in IDatabaseCacheRepository
- Fix double enumeration in DocumentCacheService.SeedAsync and
ElementCacheService.SeedAsync by materializing to List before logging
* Invalidate element cache entries when trashed
Apply the same fix from #22451 (documents/media) to elements:
- ElementCacheService.RefreshElementAsync: early-return for trashed
elements, deleting from the database cache and removing from memory.
- ElementCacheService.RefreshMemoryCacheAsync: add symmetric else
branches so memory cache entries are removed when the database cache
has no corresponding draft or published node (self-healing).
- Re-enable Cannot_Get_Published_Again_After_Trashing integration test.
* Move element trash cache tests to ElementHybridCacheTests
Move Cannot_Get_Trashed_As_Published and
Cannot_Get_Published_Again_After_Trashing from
ElementPublishingServiceTests to ElementHybridCacheTests where they
belong — these test cache invalidation, not publishing behavior.
Add Cannot_Get_Published_Elements_After_Folder_Trashed to verify that
trashing an element folder clears its child elements from the published
cache.
* Add element hybrid cache variant tests
Add ElementHybridCacheVariantsTests covering culture variant behavior
for the element cache: variant property values per culture, invariant
property consistency across cultures, single culture updates, single
culture publishing, and draft access to both cultures.
Add isElement parameter to
CreateContentTypeWithTwoPropertiesOneVariantAndOneInvariant to support
creating variant element types without a separate builder method.
* Rename IPublishedElementCache.GetByIdAsync to GetByKeyAsync
Align with the codebase convention where Id refers to integer
identifiers and Key refers to GUID identifiers.
* Align IDocumentPublishStatusQueryService method names with element equivalent
Add IsPublished and IsPublishedInAnyCulture to
IDocumentPublishStatusQueryService to match
IElementPublishStatusQueryService naming.
Keep IsDocumentPublished and IsDocumentPublishedInAnyCulture as obsolete
default implementations delegating to the new methods, since
IPublishStatusQueryService (which exposes these names) ships on main.
Update all internal callers to use the new names.
* Keep INNER JOIN for document/media navigation queries
Only use LEFT JOIN when the query includes container types (e.g.
element containers) which don't have umbracoContent rows. Documents
and media always have content rows, so INNER JOIN preserves query
optimizer hints for those queries.
* Consolidate breadth-first seed key provider logic into base class
Make GetSeedKeys virtual on BreadthFirstKeyProvider and introduce
ShouldSeed and ShouldTraverseChildren hooks so subclasses only need
to override filtering logic instead of duplicating the entire
traversal.
- Document: overrides ShouldSeed to filter unpublished nodes
- Element: overrides ShouldSeed + ShouldTraverseChildren (always
traverse, since containers may have published children)
- Media: uses base defaults (seed and traverse everything)
Removes the 'new' hiding pattern and the V16 TODO.
* Revert "Rename IPublishedElementCache.GetByIdAsync to GetByKeyAsync"
This reverts commit 139d66776f.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fix branch authorization from requiring recycle bin permission.
* Use named parameters.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* fix(api): resolve correct old version on upgrade screen (closes#20980)
The upgrade screen always showed the first version of the current major
(e.g. 17.0.0) regardless of the actual database state. This was because
UpgradeSettingsFactory constructed OldVersion from just the running
app's major version number.
The fix adds UmbracoPlan.GetVersionForState() which walks the migration
transition chain and extracts version numbers from migration type
namespaces (V_{major}_{minor}_{patch} convention). RuntimeState calls
this during startup and exposes the result via a new
IRuntimeState.CurrentMigrationVersion property (with a default null
implementation to avoid breaking changes). UpgradeSettingsFactory uses
this resolved version with a fallback to the previous behaviour.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix(api): return 9.4.0 for InitialState in GetVersionForState
InitialState is the final migration state of 9.4 (the lowest supported
upgrade). Returning null caused the fallback to show <major>.0.0 for
databases at that state. Now correctly resolves to 9.4.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* chore(infrastructure): add TODO (V18) to update initialVersion when InitialState changes
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Added TODO for 18.
* Addressed code review feedback.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Allow packages and hosted services to set an ambient backoffice identity via AsyncLocal for scenarios where no HttpContext is available.
* Addressed code review feedback.
* Avoid allocating a string if _publishedContentCache has a cached version & removed preview param, it was always false
* Clarified comment, used GetCacheKey method from location where string was being created.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Use GeneratedRegex instead of generating at runtime
* Add unit tests to verify refactored code.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* update npm dependencies for v17.4.0 minor release
* update dependencies package
* fix lint errors
* remove Dribbble from lucide to simple icons
* revert @hey-api/openapi-ts bump
* chore: regenerate sdk.gen.ts
* chore: regenerate msw sw
* chore: regenerate icons
* build: excludes "mocks/tools" from being compiled
it is an isolated project and so can be used independent of the backoffice
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Propagate tree context's additional request args to tree item children, ensuring tree item children respect the "ignore user start nodes" data type setting for content pickers.
* Add unit tests for additional request args forwarding to tree item children manager.
Covers requestCollection with shape validation and pagination behaviour
(take, skip, consistent total) using the kitchen sink mock set.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Covers createScaffold, requestByUnique, create, save, and delete using
the kitchen sink mock set and MSW-intercepted webhook endpoints.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Uses the kitchen sink mock set to test requestItems and items against
the MSW-intercepted webhook item endpoint.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* extend icons with information from theseaurus
* implement new icon search logic
* clean-up data
* sorting with a backup of the name
* refactor into a controller
* improve multi word group search
* embed lucide data
* rename tech into technology
* remove paper from dollar
* upgrade msw, migrate all interceptors, and update backoffice integration
* Fix msw test runner integration
* wip mock sets
* align news mock data
* clean up
* add interface for mock sets
* Refactor mock DBs to use dataSet directly
* export as data
* align exports
* Update index.ts
* simplify
* remove createTemplateScaffold from data set
* remove getGroupByName from mock set
* remove getGroupWithResultsByName from mock set
* remove getIndexByName from mock set
* remove unused getSearchResultsMockData function
* Add kenn mock data set with SQLite transformation scripts
Introduces a new "kenn" mock data set generated from an Umbraco SQLite database export.
Transformation scripts (devops/sqlite-to-mock/):
- Database connection helper using sql.js
- Transform scripts for data-types, document-types, media-types, documents, media, users, templates, languages, and dictionary
Generated kenn data set includes:
- 156 data types
- 48 document types with properties, containers, and compositions
- 11 media types
- 41 documents with property values and variants
- 75 media items
- 4 users and 6 user groups
- 10 templates, 2 languages, 5 dictionary items
Usage: VITE_MOCK_SET=kenn npm run dev
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix Tab/Group container type mapping in document types
The PropertyGroupType enum in Umbraco.Core defines:
- Group = 0
- Tab = 1
The transformer had this inverted. Fixed the mapping and regenerated
document-type.data.ts with correct container types.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix user group fallbackPermissions in transformer
Read permissions from umbracoUserGroup2Permission table instead of
the empty userGroupDefaultPermissions column. Also handles mapping
legacy single-letter permission codes to new Umb.Document.* format.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove deprecated createTemplateScaffold from template transformer
This function was removed from the UmbMockDataSet interface.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Move sqlite-to-mock script to main package.json
Consolidate the SQLite transformation tooling into the main package by:
- Adding sql.js, @types/sql.js, and tsx as devDependencies
- Adding sqlite-to-mock script that runs transformations and lints output
- Removing the separate devops/sqlite-to-mock/package.json and lock file
This allows the transformation scripts to reuse the main node_modules.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* add url manager and url handlers
* Add CLI parameters to sqlite-to-mock script
The script now requires db-path and set-alias arguments:
npm run sqlite-to-mock -- <db-path> <set-alias>
Changes:
- Add configure(), getDatabase(), getOutputDir(), closeDatabase() for lazy init
- Add CLI argument parsing with validation
- Remove direct execution calls from transform scripts
- Move eslint formatting into the script
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Generate complete mock data sets and auto-discover sets
- Add generate-supporting-files.ts to create index.ts and all
placeholder/static files needed for a complete mock data set
- Use import.meta.glob for dynamic mock set discovery instead
of hardcoded switch statement
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add mock handler for document type configuration
Introduces a new mock handler to serve document type configuration data, updates the mock database to provide configuration, and integrates the handler into the document type mock handlers.
* make all mock data optional
* Add custom service worker to bypass static asset requests
Introduces umbServiceWorker.js to intercept and bypass static asset requests before reaching MSW, improving startup performance in Vite development.
* fix type errors
* Update template-query.manager.ts
* change to runtime load of mock data
* Update package-lock.json
* wip mock set switcher
* Use umbMockManager.availableSetNames in mock header
* remove the test set
* clean up
* move mock files to the client project root
* rename folder
* move sqllite tool into mocks folder
* clean up
* rename folder
* update the correct tsconfig file
* Update README.md
* fix path
* mock search
* add mocks for tree siblings endpoint
* add mocks for document type and media type allowed parents
* split user permissions mock data into its own mock set
* Initialize localization registry in date test
* don't use consts. Inits too much from the modules
* Update property-editor-ui-user-picker.test.ts
* Update property-value-cloner-block-grid.cloner.test.ts
* add custom permission
* make test check for custom permission in specific mock set
* use specific mock set with specific user id
* Update document-user-permission.condition.test.ts
* Update section-user-permission.condition.test.ts
* add mock manager util to internal utils
* add import map to test runner
* Move mock-data-set.types and update imports
* Exclude internal consts in export test
* Rename mock key to userPermissions
* Register mock manifests only in development
* manual merge
* Add labels and alias/label list for mock sets
* Add visibility flag for mock sets
* delete kenn mock set
* Update mock-manager.ts
* fix(mocks): correct document type composition generation in sqlite-to-mock
The compositions were reversed - grouped by parentContentTypeId instead
of childContentTypeId. In cmsContentType2ContentType, the parent is the
composed type and the child is the type using it. Also adds inheritance
vs composition detection based on umbracoNode parentId matching.
* Update src/Umbraco.Web.UI.Client/mocks/msw-handlers/member-type/structure.handlers.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/mocks/tools/sqlite-to-mock/README.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/mocks/db/template-detail.manager.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix mock DB slice and add safety checks
* Adds "Kitchen Sink" mock data set
* Updates to sqlite-to-mock tool
* Default mock data set tweaks
Replaces "loremflickr.com" images with local placeholders
* "Kitchen Sink" mock data updates
* feat(mocks): add member support to sqlite-to-mock tool
Add transformers for members, member types, and member groups to replace
the empty placeholder arrays. Queries cmsMember, cmsMemberType, and
cmsMember2MemberGroup tables for auth data, property visibility, and
group relationships.
* Updated "Kitchen Sink" mock data with Members
* fix(mocks): type rawData in composition-mapped files to avoid never[] inference
When all compositions arrays are empty, TypeScript infers the element
type as never, causing a type error on the .map() callback. Adding an
explicit type annotation for rawData resolves this. Also fixed in both
generators so future runs produce correctly typed output.
* feat(mocks): implement imaging resize URLs handler
Extract the umbracoFile src from media items and build resize URLs with
width, height, mode, and format query parameters. Replaces the empty
urlInfos placeholder.
* Updated placeholder images
* fix(mocks): return actual media file URLs and add missing folders endpoint
The /media/urls handler was returning ancestor-based slug paths instead
of the umbracoFile source path, causing the image cropper modal to
render a generic file preview instead of an image preview.
Also adds the missing /item/media-type/folders handler that was causing
a crash when opening the media picker.
* fix(mocks): parse JSON values stored in varcharValue column
Short JSON values like Color Picker data are stored in varcharValue
rather than textValue in SQLite. The transformers only attempted
JSON.parse on textValue, leaving varcharValue as raw strings. Now also
parses varcharValue when it starts with { or [.
Also fixes the kitchen-sink Color Picker mock data to use parsed objects.
* fix(mocks): add missing document audit log handler
Adds a handler for GET /document/{id}/audit-log that returns the shared
audit log data from the mock data set. Prevents crash in the document
workspace info view history component.
* Mock data tweaks
* move logic from msw handlers to mock services
* remove debugger
* introduce an audit log db class
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* adds same drag styling as when dragging item in the content sectin
* remove unused loader css
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Pass `github_token` and set `allowed_non_write_users: "*"` so the action
bypasses the OIDC actor check, which rejects non-maintainers with
"User does not have write access on this repository". Safe here because
`permissions:` and `--allowedTools` are tightly scoped to issue ops.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* upgrade msw, migrate all interceptors, and update backoffice integration
* Fix msw test runner integration
* wip mock sets
* align news mock data
* clean up
* add interface for mock sets
* Refactor mock DBs to use dataSet directly
* export as data
* align exports
* Update index.ts
* simplify
* remove createTemplateScaffold from data set
* remove getGroupByName from mock set
* remove getGroupWithResultsByName from mock set
* remove getIndexByName from mock set
* remove unused getSearchResultsMockData function
* Add kenn mock data set with SQLite transformation scripts
Introduces a new "kenn" mock data set generated from an Umbraco SQLite database export.
Transformation scripts (devops/sqlite-to-mock/):
- Database connection helper using sql.js
- Transform scripts for data-types, document-types, media-types, documents, media, users, templates, languages, and dictionary
Generated kenn data set includes:
- 156 data types
- 48 document types with properties, containers, and compositions
- 11 media types
- 41 documents with property values and variants
- 75 media items
- 4 users and 6 user groups
- 10 templates, 2 languages, 5 dictionary items
Usage: VITE_MOCK_SET=kenn npm run dev
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix Tab/Group container type mapping in document types
The PropertyGroupType enum in Umbraco.Core defines:
- Group = 0
- Tab = 1
The transformer had this inverted. Fixed the mapping and regenerated
document-type.data.ts with correct container types.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix user group fallbackPermissions in transformer
Read permissions from umbracoUserGroup2Permission table instead of
the empty userGroupDefaultPermissions column. Also handles mapping
legacy single-letter permission codes to new Umb.Document.* format.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove deprecated createTemplateScaffold from template transformer
This function was removed from the UmbMockDataSet interface.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Move sqlite-to-mock script to main package.json
Consolidate the SQLite transformation tooling into the main package by:
- Adding sql.js, @types/sql.js, and tsx as devDependencies
- Adding sqlite-to-mock script that runs transformations and lints output
- Removing the separate devops/sqlite-to-mock/package.json and lock file
This allows the transformation scripts to reuse the main node_modules.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* add url manager and url handlers
* Add CLI parameters to sqlite-to-mock script
The script now requires db-path and set-alias arguments:
npm run sqlite-to-mock -- <db-path> <set-alias>
Changes:
- Add configure(), getDatabase(), getOutputDir(), closeDatabase() for lazy init
- Add CLI argument parsing with validation
- Remove direct execution calls from transform scripts
- Move eslint formatting into the script
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Generate complete mock data sets and auto-discover sets
- Add generate-supporting-files.ts to create index.ts and all
placeholder/static files needed for a complete mock data set
- Use import.meta.glob for dynamic mock set discovery instead
of hardcoded switch statement
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add mock handler for document type configuration
Introduces a new mock handler to serve document type configuration data, updates the mock database to provide configuration, and integrates the handler into the document type mock handlers.
* make all mock data optional
* Add custom service worker to bypass static asset requests
Introduces umbServiceWorker.js to intercept and bypass static asset requests before reaching MSW, improving startup performance in Vite development.
* fix type errors
* Update template-query.manager.ts
* change to runtime load of mock data
* Update package-lock.json
* wip mock set switcher
* Use umbMockManager.availableSetNames in mock header
* remove the test set
* clean up
* move mock files to the client project root
* rename folder
* move sqllite tool into mocks folder
* clean up
* rename folder
* update the correct tsconfig file
* Update README.md
* fix path
* mock search
* add mocks for tree siblings endpoint
* add mocks for document type and media type allowed parents
* split user permissions mock data into its own mock set
* Initialize localization registry in date test
* don't use consts. Inits too much from the modules
* Update property-editor-ui-user-picker.test.ts
* Update property-value-cloner-block-grid.cloner.test.ts
* add custom permission
* make test check for custom permission in specific mock set
* use specific mock set with specific user id
* Update document-user-permission.condition.test.ts
* Update section-user-permission.condition.test.ts
* add mock manager util to internal utils
* add import map to test runner
* Move mock-data-set.types and update imports
* Exclude internal consts in export test
* Rename mock key to userPermissions
* Register mock manifests only in development
* manual merge
* Add labels and alias/label list for mock sets
* Add visibility flag for mock sets
* delete kenn mock set
* Update mock-manager.ts
* fix(mocks): correct document type composition generation in sqlite-to-mock
The compositions were reversed - grouped by parentContentTypeId instead
of childContentTypeId. In cmsContentType2ContentType, the parent is the
composed type and the child is the type using it. Also adds inheritance
vs composition detection based on umbracoNode parentId matching.
* Update src/Umbraco.Web.UI.Client/mocks/msw-handlers/member-type/structure.handlers.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/mocks/tools/sqlite-to-mock/README.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/mocks/db/template-detail.manager.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix mock DB slice and add safety checks
* webhook mock plan
* init webhook mock set + handlers
* Adds "Kitchen Sink" mock data set
* Updates to sqlite-to-mock tool
* Default mock data set tweaks
Replaces "loremflickr.com" images with local placeholders
* "Kitchen Sink" mock data updates
* Add paginated list and remove collection handler
* feat(mocks): add member support to sqlite-to-mock tool
Add transformers for members, member types, and member groups to replace
the empty placeholder arrays. Queries cmsMember, cmsMemberType, and
cmsMember2MemberGroup tables for auth data, property visibility, and
group relationships.
* Updated "Kitchen Sink" mock data with Members
* fix(mocks): type rawData in composition-mapped files to avoid never[] inference
When all compositions arrays are empty, TypeScript infers the element
type as never, causing a type error on the .map() callback. Adding an
explicit type annotation for rawData resolves this. Also fixed in both
generators so future runs produce correctly typed output.
* Add webhook delivery mock data and handlers
* Add webhook event mock data and handlers
* include webhooks in kitchen sink data set
* Add flags to webhook mock; fix item response
* Support pagination in webhook events handler
* Update src/Umbraco.Web.UI.Client/mocks/db/webhook-delivery.db.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update detail.handlers.ts
* Map webhook event aliases to event objects
* remove note about being created from SQL db
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* TipTap: Declare Clear Formatting toolbar button's extension dependencies
* Reworked to have a loose dependency
on the `class` and `style` attribute extensions
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Eliminate closure, fix naming & formatting of exceptions
* Added unit tests around the changed code.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Use configured or detected application URL as request URL fallback in background tasks when constructing absolute URLs.
* Addresed code review feedback.
* upgrade msw, migrate all interceptors, and update backoffice integration
* Fix msw test runner integration
* wip mock sets
* align news mock data
* clean up
* add interface for mock sets
* Refactor mock DBs to use dataSet directly
* export as data
* align exports
* Update index.ts
* simplify
* remove createTemplateScaffold from data set
* remove getGroupByName from mock set
* remove getGroupWithResultsByName from mock set
* remove getIndexByName from mock set
* remove unused getSearchResultsMockData function
* Add kenn mock data set with SQLite transformation scripts
Introduces a new "kenn" mock data set generated from an Umbraco SQLite database export.
Transformation scripts (devops/sqlite-to-mock/):
- Database connection helper using sql.js
- Transform scripts for data-types, document-types, media-types, documents, media, users, templates, languages, and dictionary
Generated kenn data set includes:
- 156 data types
- 48 document types with properties, containers, and compositions
- 11 media types
- 41 documents with property values and variants
- 75 media items
- 4 users and 6 user groups
- 10 templates, 2 languages, 5 dictionary items
Usage: VITE_MOCK_SET=kenn npm run dev
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix Tab/Group container type mapping in document types
The PropertyGroupType enum in Umbraco.Core defines:
- Group = 0
- Tab = 1
The transformer had this inverted. Fixed the mapping and regenerated
document-type.data.ts with correct container types.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix user group fallbackPermissions in transformer
Read permissions from umbracoUserGroup2Permission table instead of
the empty userGroupDefaultPermissions column. Also handles mapping
legacy single-letter permission codes to new Umb.Document.* format.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove deprecated createTemplateScaffold from template transformer
This function was removed from the UmbMockDataSet interface.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Move sqlite-to-mock script to main package.json
Consolidate the SQLite transformation tooling into the main package by:
- Adding sql.js, @types/sql.js, and tsx as devDependencies
- Adding sqlite-to-mock script that runs transformations and lints output
- Removing the separate devops/sqlite-to-mock/package.json and lock file
This allows the transformation scripts to reuse the main node_modules.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* add url manager and url handlers
* Add CLI parameters to sqlite-to-mock script
The script now requires db-path and set-alias arguments:
npm run sqlite-to-mock -- <db-path> <set-alias>
Changes:
- Add configure(), getDatabase(), getOutputDir(), closeDatabase() for lazy init
- Add CLI argument parsing with validation
- Remove direct execution calls from transform scripts
- Move eslint formatting into the script
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Generate complete mock data sets and auto-discover sets
- Add generate-supporting-files.ts to create index.ts and all
placeholder/static files needed for a complete mock data set
- Use import.meta.glob for dynamic mock set discovery instead
of hardcoded switch statement
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add mock handler for document type configuration
Introduces a new mock handler to serve document type configuration data, updates the mock database to provide configuration, and integrates the handler into the document type mock handlers.
* make all mock data optional
* Add custom service worker to bypass static asset requests
Introduces umbServiceWorker.js to intercept and bypass static asset requests before reaching MSW, improving startup performance in Vite development.
* fix type errors
* Update template-query.manager.ts
* change to runtime load of mock data
* Update package-lock.json
* wip mock set switcher
* Use umbMockManager.availableSetNames in mock header
* remove the test set
* clean up
* move mock files to the client project root
* rename folder
* move sqllite tool into mocks folder
* clean up
* rename folder
* update the correct tsconfig file
* Update README.md
* fix path
* mock search
* add mocks for tree siblings endpoint
* add mocks for document type and media type allowed parents
* split user permissions mock data into its own mock set
* Initialize localization registry in date test
* don't use consts. Inits too much from the modules
* Update property-editor-ui-user-picker.test.ts
* Update property-value-cloner-block-grid.cloner.test.ts
* add custom permission
* make test check for custom permission in specific mock set
* use specific mock set with specific user id
* Update document-user-permission.condition.test.ts
* Update section-user-permission.condition.test.ts
* add mock manager util to internal utils
* add import map to test runner
* Move mock-data-set.types and update imports
* Exclude internal consts in export test
* Rename mock key to userPermissions
* Register mock manifests only in development
* manual merge
* Add labels and alias/label list for mock sets
* Add visibility flag for mock sets
* delete kenn mock set
* Update mock-manager.ts
* fix(mocks): correct document type composition generation in sqlite-to-mock
The compositions were reversed - grouped by parentContentTypeId instead
of childContentTypeId. In cmsContentType2ContentType, the parent is the
composed type and the child is the type using it. Also adds inheritance
vs composition detection based on umbracoNode parentId matching.
* Update src/Umbraco.Web.UI.Client/mocks/msw-handlers/member-type/structure.handlers.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/mocks/tools/sqlite-to-mock/README.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/mocks/db/template-detail.manager.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix mock DB slice and add safety checks
* Adds "Kitchen Sink" mock data set
* Updates to sqlite-to-mock tool
* Default mock data set tweaks
Replaces "loremflickr.com" images with local placeholders
* "Kitchen Sink" mock data updates
* feat(mocks): add member support to sqlite-to-mock tool
Add transformers for members, member types, and member groups to replace
the empty placeholder arrays. Queries cmsMember, cmsMemberType, and
cmsMember2MemberGroup tables for auth data, property visibility, and
group relationships.
* Updated "Kitchen Sink" mock data with Members
* fix(mocks): type rawData in composition-mapped files to avoid never[] inference
When all compositions arrays are empty, TypeScript infers the element
type as never, causing a type error on the .map() callback. Adding an
explicit type annotation for rawData resolves this. Also fixed in both
generators so future runs produce correctly typed output.
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(SqliteSyntaxProvider.cs): parameterises the `tableName` variable when passing into `DoesPrimaryKeyExist` method
* fix(SqlServerSyntaxProvider.cs): parameterises the `tableName` variable when passing into the `DoesPrimaryKeyExist` sql statement
* test(DoesPrimaryKeyExist-test): Add test file for DoesPrimaryKeyExist
Co-authored-by: LLaverty <liamlaverty@gmail.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Align output cache extension points for the delivery API with those for the website.
* Fix issue running output cache on website and delivery API at the same time.
* Updates from testing.
* Align website default implementation with naming used for delivery API equivalents.
* Addressed code review feedback.
* Updates from self-review.
* Allow removal of template on a document, and indicate when the selected template is no longer allowed.
* Addressed code review feedback.
* remove duplicate inline color style on template icon
---------
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Document Types: Prevent disabling isElement when elements of that type exist
Mirrors the existing document-to-element guard: switching an element type
to a document type is now blocked when elements of that type exist. Adds
ElementToDocumentHasNoContentAsync to IElementSwitchValidator and a new
ContentTypeOperationStatus.InvalidElementFlagElementHasContent mapped to
a BadRequest in the document type controller.
* Address PR review feedback for isElement guard
Extract shared HasNoContentNodesAsync helper in ElementSwitchValidator
to deduplicate DocumentToElement and ElementToDocument checks. Make
WithAllowedInLibrary conditional on isElement in test setup.
* Add end-to-end integration tests for element switch validation
Add three tests to ContentTypeEditingServiceTests that verify
UpdateAsync returns the correct operation status when element
flag changes are blocked: document-to-element with existing
content, element-to-document with existing elements, and
element-to-document when used in block structures.
* Remove default interface implementation for ElementToDocumentHasNoContentAsync
Per review feedback: custom implementations of IElementSwitchValidator are unlikely, and a default implementation hides the fact that changes to the real implementation would need to be mirrored here. Accept the small breaking change for a clearer upgrade path.
* Group get all paths to avoid exceeding SQL Server's max parameter count.
* Move GetAllPaths batching tests to dedicated test class
Move the explicit SQL Server parameter limit tests into their own
class (EntityServiceGetAllPathsTests) with NewSchemaPerTest so the
raw SqlException surfaces instead of being masked by scope disposal.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* use currentColor as color fallback
* clean up necessary prop
* Add test color behavior coverage for umb-icon
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
Co-authored-by: engjlr <enl@umbraco.dk>
Fork PRs on the `pull_request` event don't have access to repository
secrets, so the action fails and surfaces a red check on the PR. Guard
the job with a head-repo equality check so the workflow simply doesn't
run for fork PRs. Remove once upstream fork support lands
(anthropics/claude-code-action#939) and `pull_request_target` can be
re-enabled.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
pull_request_target fails at OIDC token exchange ("401 Unauthorized -
Invalid OIDC token") against Anthropic's backend, even though the
action itself supports the event (PR #579). Fork PRs will not be
auto-reviewed until the upstream issue is resolved. Kept the
pull_request_target block commented with a pointer to the issues
for when re-enabling becomes viable.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Docs require actions:read at the workflow permissions level in addition
to additional_permissions on the action, so Claude's CI-reading MCP
tools can actually function. See anthropics/claude-code-action
docs/configuration.md.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(core): add member sign-in/sign-out notifications
Add MemberLoginSuccessNotification, MemberLoginFailedNotification,
and MemberLogoutSuccessNotification to achieve parity with the
existing backoffice user authentication notifications.
Override HandleSignIn in MemberSignInManager to publish login
success/failure notifications, and override SignOutAsync to publish
logout notifications. This follows the same pattern used by
BackOfficeSignInManager for backoffice users.
Closes#22461
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* docs(core): add remarks to member auth notification classes
Add <remarks> XML documentation to MemberLoginSuccessNotification,
MemberLoginFailedNotification, and MemberLogoutSuccessNotification
describing intended usage, consistent with the backoffice user
notification equivalents.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat(web): use IIpResolver for member auth notification IP addresses
Use IIpResolver.GetCurrentRequestIpAddress() for consistent IP
resolution in member auth notifications, matching the pattern used
by BackOfficeUserManager.
Introduces IIpResolver as a new constructor parameter with the
existing constructor marked obsolete (removal in Umbraco 19) using
StaticServiceProvider fallback for backwards compatibility.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Fixed filing unit tests.
* Added tests for new functionality.
* Ensure MemberFailedNotification is fired on invalid credentials as well as member not found.
Add the reason for the failure to the notification.
* Add tests for other failed notification publishing states.
* Clarified comments.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
The client CLAUDE.md's action-to-doc table already maps deprecation
to docs/deprecation.md, and the root's callout directs agents to read
the client CLAUDE.md for backoffice work. Having the pattern in both
places is redundant.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Agents working from the repo root now see an explicit instruction to
read the client's CLAUDE.md before touching backoffice code. Prevents
missing project-specific conventions (like UmbDeprecation) that are
documented in the client project but not the root.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Maps specific actions (deprecate, create element, add tests, etc.) to
the docs that MUST be read first. Ensures developers opening only the
client folder see the requirements in their Claude context.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The backoffice client requires both @deprecated JSDoc AND a runtime
UmbDeprecation warning for every deprecation. This was documented in
the client's docs/deprecation.md but not referenced in the root
CLAUDE.md, causing AI agents to miss the runtime warning requirement.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Broadens the .claude gitignore to ignore everything except skills/
(committed for CI workflows) and settings.json (shared config).
Previously only settings.local.json was ignored, leaving lock files,
worktrees, and scheduled_tasks artifacts untracked but visible.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Cache: Invalidate published cache entries when content or media is trashed
Trashed content and media were remaining in the published cache because
ContentRefreshNotification/MediaRefreshNotification wrote the trashed
entities back into the cache, and ContentCacheRefresher.HandleMemoryCache
could not resolve the branch descendants after HandleNavigation had moved
them to the recycle bin.
- DocumentCacheService.RefreshContentAsync / MediaCacheService.RefreshMediaAsync:
early-return for trashed entities, deleting from the database cache and
removing from the local memory cache.
- DocumentCacheService.RefreshMemoryCacheAsync / MediaCacheService.RefreshMemoryCacheAsync:
added symmetric else branches so memory cache entries are removed when the
database cache has no corresponding draft or published node (self-healing).
- ContentCacheRefresher.HandleMemoryCache: added a bin fallback to
TryGetDescendantsKeys so broadcasted RefreshBranch payloads can resolve
descendants moved to the recycle bin on load-balanced servers.
- Integration tests covering trashed content and media cache invalidation.
* Cache: Add tests for restoring trashed content and media
Verifies that restored content is back in the draft cache (but not the
published cache, since restore does not republish) and that restored
media is back in the cache.
* Address PR review feedback
- Add bin fallback to MediaCacheRefresher.HandleMemoryCache for
consistency with ContentCacheRefresher.
- Remove redundant [Test] attributes alongside [TestCase].
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Backoffice: Add explicit controller aliases to observe() calls in tree item and default tree elements
Without explicit aliases, observe() falls back to hashing the callback's
source string on every invocation. The api setter on tree-item-element-base
and the #observeData() method on default-tree.element are called each time
the api property changes, making the hash cost and implicit deduplication
behaviour visible in hot render paths.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
Fix ElementPickerValueConverterTests build by passing IPropertyRenderingContextAccessor
The PublishedProperty constructor was updated to take an
IPropertyRenderingContextAccessor as its 4th argument, but
ElementPickerValueConverterTests was not updated, breaking the
Umbraco.Tests.UnitTests build.
pull_request events from forks cannot access OIDC tokens, causing the
job to fail. pull_request_target runs in the base repo context and has
access to secrets/OIDC while still reading the PR diff via the API.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Ensure MigrationBase formats Guids consistently with NPoco for SQLite
SQLite is case sensitive and doesn't have the concept of uniqueidentifier - Guids are stored as uppercase strings
Add FormatGuid method to SqlSyntaxProvider to centralize the logic
* (Optional) Include default FormatGuid implementation in ISqlSyntaxProvider to make this change non-breaking
* Use ToUpperInvariant for Guids in SQLite
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Tidy up comments, fix existing indentation and add unit tests for GUID formatting.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Updated tipTapSettings to match the recent changes
* Updated ui helper for insert value/dictionary/partial view button
* Updated api helper for media delivery
* Fixed api helper for verify width and height in vector graphic media
* localize rte block clipboard entry label
* RTE Block Clipboard: reuse existing localization controller
Avoids alias collision from creating a new UmbLocalizationController on
hosts that already have one. Exposes the base class controller as
protected so subclasses can reuse it.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Remove obsolete TODO (already fixed to the extend possible)
* Remove irrelevant TODO
* Refactor publishable entity building from DTOs
* Fix TODO for presentation factory
* Move shared view models from Document to Content
* Clarify TODO after testing refactoring feasibility
* Update src/Umbraco.Cms.Api.Management/ViewModels/Content/ScheduleRequestModel.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Cms.Api.Management/Factories/IElementPresentationFactory.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Cleanup element TODOs in core (first take)
* Cleanup more element TODOs in PublishableContentServiceBase and ElementEditingService
* Implement Delivery API for ElementPickerValueConverter (removes TODOs and add a few new ones)
* Move the generic implementation of PublishedElementWrapped to its own class file
* Review comments for IPublishableContentRepository
* Use explicit dependency instead of access-via-casting
* Update src/Umbraco.PublishedCache.HybridCache/PublishedElement.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add login for basic authentication without backoffice.
* Add 2FA to basic authentication flow.
* Accessibility improvements.
* Add tests for BasicAuthLoginController.
* Gate controller so only used when basic authentication is enabled.
Use 2FA view even when login page is not configured.
* Add tests for BasicAuthenticationMiddleware.
* Add support for external login providers.
* Addressed code review feedback.
* Applied suggestions from code review.
* Disable and change text on submit button when logging in.
* Add custom view support.
* Configuration for website output cache settings.
* Interfaces and default implementation for extension points.
* Configure the output cache policy.
* Evict cached documents through updates to related documents, media and members.
* Feedback from code review.
* Update description of service registration in IWebsiteOutputCacheDurationProvider header comment.
Co-authored-by: Sven Geusens <sge@umbraco.dk>
* Use output cache over service provider.
* Optimise and DRY-up eviction handlers.
* Only register IWebsiteOutputCacheManager when the feature is enabled.
* Remove unnecessary check on applying output cache to Umbraco pipeline.
* Add extension point for determining if requests should be cached.
* Broken up large method in DocumentOutputCacheEvictionHandler, put enabled checks around debug logging, further unit test.
---------
Co-authored-by: Sven Geusens <sge@umbraco.dk>
* User Service: Prevent fetching all permissions when no IDs are provided
Ensures that the UserService does not attempt to fetch permissions when the provided ID collection is empty, avoiding potentially expensive database queries that could return permissions for all nodes.
* Move guard into the shared private method and add an integration test to verify the fix.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fixes modal text styling in Insert and Sections in Templates
* fixed review issues and added accesability for the cards so you can use keyboard
* fixing formatting changes
* fixed unused css and fixed accessability to match the card select & deselect
* fixed redundant key and click events
* fixed accessability for button and small bug with not being able to click it
* Apply language fallback to block element expose filtering.
* Handle code review feedback.
* Use builder instead of mocks in tests.
* Fixed failing unit tests.
* Revert previous approach and move fallback handling to the block property value creator.
* Include fallback policy in published property cache key
* Recreate block elements with resolved fallback culture.
* Use correct pattern for dispose.
* Introduce and use PropertyRenderingContext.
* Tidy up Fallback.
* Use core extensions for string comparison
* Less allocations
* Avoid fallback handling when no fallback policies are provided
---------
Co-authored-by: kjac <kja@umbraco.dk>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Reflects the two-workflow split, trigger phrase stripping behavior,
allowed tools, labeling for both PRs and issues, and implementation
gotchas discovered during setup.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude couldn't find the PR because checkout is on main and
gh pr view with no args returns nothing. Now the PR number is
injected directly into the prompt from the GitHub event context.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude discovered and invoked the umb-review skill which uses git diff
against origin/main — but checkout is on main so the diff was empty.
Prompt now explicitly says to use gh pr diff, not git diff or skills.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The sandbox blocks multi-command Bash operations without approval.
Allow gh and git commands so Claude can read diffs, post comments,
and apply labels without permission errors.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The action strips @claude from the comment before passing to Claude,
so commands arrive as just 'review', 'fix', etc. Updated prompt to
match. Also default empty messages to review (PR) or help (issue).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Prompt now reads the user's message and acts accordingly instead of
prescribing behavior. Common patterns like review/help/fix/label
are listed as examples.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude was treating @claude review as a greeting instead of acting
on the PR. Made prompt explicit about reviewing immediately.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
With only opened/ready_for_review triggers, volume is low enough to
let Claude run without a turn limit.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
25 turns was insufficient — the umb-review skill needs many turns to
read docs, references, changed files, and write the review.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- claude-review.yml: Auto PR review on open/push/ready (no trigger needed)
- claude.yml: Interactive — @claude comments, issue assignment/labeling
Follows anthropics/claude-code-action official examples pattern.
Full Option B gating on the interactive workflow.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Only spin up a runner for issue_comment events that mention @claude.
All other event types pass through to the action for internal filtering.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Merge auto and on-demand review workflows into claude-review.yml.
Add issue support via assignee_trigger and label_trigger.
Let claude-code-action handle permission gating and trigger matching.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
claude-code-action gates on write permission by default — the manual
getCollaboratorPermissionLevel check was redundant.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Avoids collision with the claude-code-action bot's own @claude trigger.
Re-enables job-level filter to skip non-matching comments early.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* DevOps: Add Claude automated PR review action (closes #AB66809)
Adds two GitHub Actions workflows that run the umb-review Claude skill on every non-draft PR and on demand via `@claude review` comments. Reviews are advisory-only and post inline comments per finding plus one summary comment per review run.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* DevOps: Disable auto/on-demand triggers for initial testing
Remove pull_request_target trigger from auto workflow (workflow_dispatch only).
Disable on-demand job until auto workflow is validated.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* enables task
* adds more categories
* DevOps: Address Copilot review feedback
- Checkout PR head ref (not base) so git diff works correctly
- Use fetch-depth: 0 for triple-dot diff merge base
- Fix SHA dedup: use full SHA and paginate comment listing
- Include 'maintain' permission in on-demand gate
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Docs: Document Claude automated PR review workflows in CLAUDE.md
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
MediaBreadthFirstSeedCount was initialized with StaticDocumentBreadthFirstSeedCount
instead of StaticMediaBreadthFirstSeedCount, mismatching its [DefaultValue] attribute.
* chore(tree): remove deprecated tree store infrastructure
Remove the entire tree store pattern that was deprecated in favor of
direct tree repository queries. This deletes 29 tree store files,
removes the ManifestTreeStore extension type, updates all 15+ tree
repository constructors to remove store context token parameters,
cleans up manifests/constants/index exports, and migrates all
skip/take pagination to the paging property pattern.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore(workspace): remove deprecated methods and properties
Remove deprecated methods/properties across workspace contexts, menu
structures, tree items, and collections:
- Tree item context: getManifest(), loadMore()
- Content workspace: loadSegments()
- Entity detail workspace: parentUnique/parentEntityType observables,
getParent/setParent/getParentUnique/getParentEntityType methods,
_scaffoldProcessData (replaced by _processIncomingData)
- Menu structure contexts: #parent state, provideContext('UmbMenuStructureWorkspaceContext')
- Document/media/blueprint/member workspaces: contentTypeHasCollection,
getCollectionAlias(), getContentTypeId() (replaced by getContentTypeUnique())
- Collection context: setManifest(), getManifest() from interface and implementation
- Bulk delete action: deprecated _items getter/setter
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore(core): remove deprecated type aliases and exports
Remove deprecated type aliases scheduled for v18 removal:
- PackageManifestResponse (use UmbPackageManifestResponse)
- UmbSectionDefaultElement (use UmbDefaultSectionElement)
- ConditionsCollectionView (use UmbConditionsCollectionView)
- MediaValueType (use UmbMediaValueType)
- UrlParametersRecord (use UmbUrlParametersRecord)
- ActiveVariant (use UmbActiveVariant)
- UmbPropertyValueChangeEvent class and deprecated property-value-change
event listeners
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore(ui): remove deprecated config and UI exports
- Textarea: remove deprecated minHeight/maxHeight config reads
- Image cropper modal: remove deprecated default export
- UFM filters: remove 3 deprecated camelCase filter manifests
(StripHtmlCamelCase, TitleCaseCamelCase, WordLimitCamelCase)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore(repository): make totalAfter/totalBefore mandatory in UmbTargetPagedModel
Make totalAfter and totalBefore required properties (were optional),
fulfilling the TODO to make these mandatory in v18. All downstream
tree data sources already provide these values.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* style: fix lint formatting
Auto-fixed formatting from lint run (line wrapping, trailing newlines).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(collection): default filter parameter in element collection repositories
The UmbCollectionRepository interface defines filter as optional.
Without a default, calling requestCollection() without arguments
would throw when accessing filter.skip/filter.take.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(backoffice): resolve ESLint errors, fix pagination metadata, and remove missed deprecations
- Remove unused UmbObjectState import (ESLint error from merge)
- Remove unused offsetPaging variable in tree-item-children.manager.ts
- Fix totalBefore/totalAfter in all tree data sources to account for skip
offset (was always reporting totalBefore: 0 regardless of skip value)
- Remove deprecated entityType property from UmbElementValueModel
(marked for v18 removal)
- Remove deprecated _items getter/setter from UmbTrashEntityBulkAction
(marked for v18 removal)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix(backoffice): remove entityType references from tests and source after type removal
Remove entityType property from test fixtures and media-dropzone.manager.ts
following removal of the deprecated entityType from UmbElementValueModel.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* entity-action manifests shuffle
* feat(elements): show allowed element types in create action modal
Replace the generic document type picker with a custom create options
modal that fetches allowed element types from the library API and
displays them alongside a folder creation option, following the
established Media create pattern.
* feat(elements): add collection create action with allowed types and folder option
Add custom collection action element that fetches allowed element types
and discovers entityCreateOptionAction extensions (e.g. folder creation),
rendering them as a button or dropdown in the collection toolbar.
* refactor(elements): use dynamic entityCreateOptionAction extensions in create modals
Replace hardcoded folder option in the element create options modal with
UmbExtensionsApiInitializer to dynamically discover entityCreateOptionAction
extensions, enabling 3rd party extensibility.
* style(elements): clean up redundant state, magic strings, and empty styles
Use UMB_ELEMENT_ROOT_ENTITY_TYPE constant instead of magic string,
remove unused _headline state and empty css template, inline
single-use getter.
* fix(elements): address PR review feedback and export missing constants
- Extend UmbNamedEntityModel instead of duplicating name field
- Add getHref() support and error handling matching core patterns
- Add max-height on scroll container, icon fallbacks, element-specific
localization key
- Export UMB_ELEMENT_CREATE_OPTIONS_MODAL and
UMB_ELEMENT_TYPE_STRUCTURE_REPOSITORY_ALIAS through index chain
- Add feature parity checklist to clean-code docs
* style(elements): add noElementTypes localization entry and lint tweaks
* fix(elements): handle href navigation and error handling in create options modal
Navigate via history.pushState when href is present on create option
actions. Only close modal on successful execute, keeping it open on
failure so users can retry.
* Add temporary .skip tag to element smoke tests due to UI changes - to be fixed in another PR
---------
Co-authored-by: Nhu Dinh <150406148+nhudinh0309@users.noreply.github.com>
Co-authored-by: Nhu Dinh <hnd@umbraco.dk>
* Revert production mode validation for templates and partial views at the service layer, and move to management API.
* Remove unused ConfigureProductionMode helper from PartialViewServiceTests
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Add integration tests for UpdateTemplateController production mode behavior
Tests verify that the Management API correctly blocks template content
changes while allowing metadata-only updates in production mode.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Restore partial view service checks.
Add integration tests for template controllers with production mode.
* Align delete with create/update for file system changes in production mode.
* Restore partial view service tests.
* Add test for update to delete template repository.
* Refactored to use single test setup method.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Revert production mode validation for templates and partial views at the service layer, and move to management API.
* Remove unused ConfigureProductionMode helper from PartialViewServiceTests
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Add integration tests for UpdateTemplateController production mode behavior
Tests verify that the Management API correctly blocks template content
changes while allowing metadata-only updates in production mode.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Restore partial view service checks.
Add integration tests for template controllers with production mode.
* Align delete with create/update for file system changes in production mode.
* Restore partial view service tests.
* Add test for update to delete template repository.
* Refactored to use single test setup method.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* todo cleanup
* adding activatorUtilitiesConstructor atribute
* fix failed test by adding ActivatorUtilitiesConstructor
* Apply suggestion from @AndyButland
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Apply suggestion from @AndyButland
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Apply suggestion from @AndyButland
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Apply suggestion from @AndyButland
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Apply suggestion from @AndyButland
Co-authored-by: Andy Butland <abutland73@gmail.com>
* update umbracoPlan and remove ConfigureSecurityStampOptions
* Removed uneeded using.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Exclude invariant culture from culture list endpoint
The Invariant Culture (CultureInfo.InvariantCulture) has an empty Name
property which is not a valid ISO code for Umbraco content. Filter it
out in IsoCodeValidator to prevent it appearing in the culture list.
Fixes#22380
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Add unit tests for IsoCodeValidator.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Remove flex-shrink=0 from umb-body-layout
* Avoid collapsing tabs into the dropdown
* Add arrows left and right and bind a scroll
* Add a resizeObserver to keep track when the tabs container change
* Make the sort mode scrollable
* Move the add tab button inside the tabs list container
* Restore tab scrolling and detect hidden overflow
* Create a reusable scrollable container component
* Remove unused import
* Clean up
* Add HTMLElementTagNameMap to the scrollable container
* Always render the add tab button
* Observe slot children on slotchange
* Remove unused variable
* build(deps): bumps @umbraco-ui to 2.0.0-alpha.1 with new themes
* fix: updates paths to new themes
* feat: uses new uui themes for static cshtml files
* feat: updates to use UUISelectOption and UUIFormControlWithBasicsMixin
* build: copy all themes to "themes" folder
* build(uui): updates themes path so it works relatively with fonts
* build: updates minimum node.js version to build from 22 to 24 to support UUI
* fix: corrects paths to theme css
* docs: update CLAUDE.md files to reflect UUI 2.x for CMS v18
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* docs(storybook): adds theme switcher
* docs(storybook): updates paths
* docs(web): document UUI theme CSS pipeline across build files
Add comments linking the files involved in UUI theme CSS handling:
- manifests.ts: where theme CSS paths are declared, with note on UUI origin
- external/uui/vite.config.ts: where themes are copied for production builds
- vite.config.ts: where themes are copied for dev server and PR previews
- copy-to-cms.js: clarifies UUI themes are already in dist-cms at this point
Each file points to the others, making the dependency on UUI theme
filenames visible without adding abstraction.
https://claude.ai/code/session_015ntS4GXa4s9BQHsjvigDh2
* Update package.json
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix: adjusts types
* update lockfile
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Document patch, variant name only
* Multi variant tests
* Change to json-patch instead of merge to target nested properties
* Fix ManagementApiTest following PR 20820
* Segment suport for properties
* Verify non existing and trashed document patch behaviour
* Mostly working approuch for nested properties
* Fix endpoint route collision (Somehow...)
* Trying a custom way of doing things
* add escape support, more tests and cleanup
* remove unnecesary using
* Cleanup
* Restore things that are breaking
* cleanup
* Namespace cleanup
* Order cleanup
* More comment updates
* Add default implementations
* Improve modelbinding validation
* all string comparison
* Cleanup unused statuses
* Fix PatchPathResolver Filtering not accepting non string values
* Optimize path parsing
* Improve cookie token rework
* more cleanup
* Put AllowedValues on the correct property 🙈
* One more default implementation
* Add link to docs on endpoint swagger info
* PR review corrections
- Removed leftover affectedCultures & affectedSegments
- Extracted IDocumentPatcher interface
- Optimized serialization in patchEngine by moving it 1 level higher
* Update documentation urls
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Removed affected variance tracking that is nog longer being used
* Extract shared data class
* update claude patching namespace
* Remove no longer valid xml comment
* Fix unittests after refactoring patchengine.ApplyOperation(string,...) to patchengine.ApplyOperation(JsonNode,...)
* Refactor base classes
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Optimizations and refactoring of the patcher/engine/parser
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Allows save of a relation type without a child and/or parent object type.
* Addressed code review feedback and code health warnings.
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Updated ui helper for select content card
* Updated ui helper for select media card
* Added ui helper for clear selection button
* Added tests for bulk action in list view content
* Added more tests for clear selection button in list view media
* Make tests run in the pipeline
* Reverted npm command
* Batch thumbnail URL requests to avoid N+1 API calls.
* Handle code review feedback.
* Remove extra newlines.
* chore: formats code
* Use @consumeContext decorator and remove await #init from imaging repository.
Replaces the blocking `await this.#init` pattern with the `@consumeContext`
decorator so the store is consumed opportunistically. This removes the async
gap before batchImagingRequest calls, allowing all thumbnails mounting in the
same Lit render pass to be collected into a single batched API request.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Move imaging URL cache into the request batcher and deprecate UmbImagingStore.
The batcher now owns a module-level URL cache, eliminating the need for the
context-based UmbImagingStore. This removes all context-request events from
the imaging repository and thumbnail hot path. The repository delegates
entirely to the batcher for caching and fetching. UmbMediaDetailRepository
uses the new clearImagingCache() export directly instead of instantiating an
imaging repository. Items with no URL (non-image media) are cached as empty
strings to prevent unnecessary re-fetching.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Remove extra newlines.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Fixes "files/folders/files or folders" selections for the various media picker components, re-allowing folder selection from a media picker.
* Import and use enim instead of hardcoded enum value
---------
Co-authored-by: kjac <kja@umbraco.dk>
* feat(elements): add contentTypeIcon observable and _handleSave override to workspace context
Adds contentTypeIcon observable, icon field to UmbElementDetailModel, and maps icon from server response. Adds _handleSave override to remap validation error colors to warning colors during save, matching Document workspace behavior.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(elements): add loading state, variant selector, and cleanup to split view
Adds loading state observation and binding, variant selector slot with new element-specific variant selector component, and element sortVariants utility. Removes dead #breadcrumbs CSS rule and reorders splitViewIndex to match Document workspace conventions.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(elements): wire up publishing workspace context in variant selector
Consumes UMB_ELEMENT_PUBLISHING_WORKSPACE_CONTEXT in the element variant selector, mirroring the Document pattern. Fixes PUBLISHED_PENDING_CHANGES localization to use the correct key.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(elements): add save modal for element workspace variant picker
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Adds "Update" permission condition on Folder Rename entity-action
* feat(elements): add pending changes manager for element workspace
Mirror the Document workspace's UmbDocumentPublishedPendingChangesManager
to provide client-side comparison of persisted vs published element data.
The variant selector now uses this manager to determine pending changes
state instead of relying solely on the API state. The actual API call to
fetch published element data is left as a TODO until the backend endpoint
exists.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Update src/Umbraco.Web.UI.Client/src/packages/elements/modals/save-modal/element-save-modal.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/elements/utils.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* refactor(menu): delegate breadcrumb href to menu structure context
Move the href resolution logic from the breadcrumb element into the
menu structure workspace context via a new `getItemHref` method on the
interface and base class. This eliminates the need for duplicate
breadcrumb elements that only differ in href behavior, and mirrors the
existing pattern used by the variant breadcrumb.
* feat(elements): add menu structure context and breadcrumb for element folders
Add UmbElementFolderMenuStructureContext that overrides getItemHref to
make folder ancestors and the section root clickable in the breadcrumb.
Register the menu structure context and breadcrumb footer app in the
element folder workspace manifests.
* fix(elements): provide synthetic variant data for folder tree items
Folders don't have variants from the API, so provide a synthetic
published variant using the folder name. This prevents errors when
the tree item mapper expects variant data.
* Updates "umb-element-table-collection-view"
to add the column elements for "name" and (published) "state".
* Refactor exports in constants.ts for clarity
* fix(workspace): prevent breadcrumb TypeError for contexts without getItemHref
Menu structure contexts that don't extend the tree base class (e.g.
UmbLanguageNavigationStructureWorkspaceContext) lack getItemHref, causing
a runtime TypeError in the breadcrumb element. Use optional chaining to
gracefully handle missing implementations.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* docs(menu): add JSDoc to UmbMenuStructureWorkspaceContext interface
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Fixes "files/folders/files or folders" selections for the various media picker components, re-allowing folder selection from a media picker.
* Import and use enim instead of hardcoded enum value
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Show ancestor path in document search results.
* show ancestor breadcrumb path in media search results
* Show the document ancestors name by culture variant
* Extract ancestor fetching to reduce cyclomatic complexity
* Add early return inside #fetchAncestors
* Handle errors from the api call.
* Add fallback title when the name doesn't exist
* Use full item models for search ancestor types
* Batch delete in DocumentUrlRepository and DocumentUrlAliasRepository to avoid exceeding SQL Server's 2100 parameter limit.
* Address code review feedback.
* Remove the unnecessary trigger rebuild on startup statement in the SQL Server migration path.
* Batch delete in DocumentUrlRepository and DocumentUrlAliasRepository to avoid exceeding SQL Server's 2100 parameter limit.
* Address code review feedback.
* Remove the unnecessary trigger rebuild on startup statement in the SQL Server migration path.
* Adds "umb-element-tree-item" custom component
Updates context to use the item data resolver..
* Adds manifests for Element entity-signs
for "Has Pending Changes" and "Has Scheduled Publish"
* Update src/Umbraco.Web.UI.Client/src/packages/elements/tree/element-tree-item.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Attempt to fix the Item Data Resolver `setData` type-casting
* Align element tree item model with item model for type safety
Add required `flags` field to `UmbElementTreeItemModel` (via
`UmbEntityWithFlags`) and `UmbElementTreeItemVariantModel`, matching
the document tree pattern. This ensures the data resolver's `#setFlags()`
receives actual data instead of silently accessing undefined properties.
The `as unknown as` cast in the context remains due to nominal type
differences (entityType union, variant state enum) but is now structurally
safe at runtime.
* Maps `flags` in `UmbElementTreeItemVariantModel`
* Updated locator for element tree item due to UI changes
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Nhu Dinh <hnd@umbraco.dk>
* Compute next delay to compensate for time drift
* Addressed case flagged on code review following stopped service.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added instructions for maintaining the `OpenApi.json` file
* Updated client-side instruction docs
for clean code and style guide.
* Updated "Full API surface" point
* Update CLAUDE.md
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Handle invalid redirect routes without slash in GetUrlFromRoute
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Handle fragment-only routes before parsing node id
* Add unit tests verifying the fix (as well as expanding the test coverage of the URL provider in general).
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* feat: surface ProblemDetails detail in error notifications
Pass the ProblemDetails detail field through to error notifications.
Short details (≤250 chars) are shown inline with CSS line-clamp.
Long details (>250 chars) are shown via a "See error" button that
opens the error viewer modal.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: address PR review — rename detail/details ambiguity and remove as any cast
Rename local `details` variable to `errors` to avoid confusion with `detail`.
Change UmbErrorViewerModalData to a union type (UmbPeekErrorArgs | string)
matching what the modal actually handles at runtime, eliminating the as any cast.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: tighten types and overload _peekError with UmbPeekErrorArgs
- Document UmbPeekErrorArgs interface and its properties
- Add `errors` property to UmbPeekErrorArgs, deprecate `details`
- New _peekError overload: accepts UmbPeekErrorArgs directly
- Old _peekError overload: positional args, deprecated for removal in v19
- Update notification element and interceptor to use `errors`
- Widen UmbErrorViewerModalData to also accept Record<string, unknown>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: extract duplicate errors fallback to #validationErrors getter
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: remove unnecessary null handling in interceptor #peekError
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve tsc errors from type tightening
- UmbErrorViewerModalData: use Record<string, unknown> interface to
satisfy UmbModalToken's object constraint (string not allowed)
- Cast detail string through unknown when opening error viewer
(modal handles strings at runtime, token type doesn't allow it)
- Fix interceptor errors Record to use string[] values
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve eslint errors — unused import, prettier, jsdoc link
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: renames 'See error' button to 'Full Error Message'
* feat: renames Danish button 'Undtagelsesdetaljer' to 'Fejldetaljer'
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add PublishedCultures and UnpublishedCultures to ElementCacheRefresher.JsonPayload
Adds culture-specific publishing details to the element cache refresher payload,
matching the existing ContentCacheRefresher.JsonPayload structure. Also replicates
the performance optimization from #21415 by only clearing partial view cache when
there are actual publish/unpublish culture changes, and fixes the Remove change
type check to use HasType instead of equality (flags enum).
* Reuse content cache logic for partial view cache clearing
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Add workspaces docs, CLAUDE link, and skill
* Export workspace elements as element
* consolidate information
* adjust skill to make use of generic name component
* try to force the agent to follow docs and use skills
* Update SKILL.md
* clean up create package skill
* use data type package as reference
* add initial repository doc + skill
* Update src/Umbraco.Web.UI.Client/docs/workspaces.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/docs/workspaces.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update workspaces.md
* clean up
* Update SKILL.md
* Delete Repositories.md
* Create repositories.md
* Update repositories.md
* Normalize repositories doc links to lowercase
* Update src/Umbraco.Web.UI.Client/.claude/skills/general-create-repository/SKILL.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix data flow link path casing
* fix casing
* export as api + inline store in manifest
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Prevent Host header poisoning of ApplicationMainUrl.
* Introduce options for Umbraco application URL detection and handle situations where it can be undefined.
* Prevent email operations if the application URL is not detected or configured.
Improve log warnings.
* Addressed feedback from code review.
* Move startup application URL logging to a handler.
* Clean up ambiguous log message
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Uncommented placeholders for restore endpoints
* Delete (inside Recycle Bin): wired up correct endpoints
* Added condition for "Empty Recycle Bin" collection-action
to only display in the Recycle Bin root.
* feat(recycle-bin): add destination entity overrides to restoreFromRecycleBin kind
Add optional destinationItemRepositoryAlias, destinationItemDataResolver,
and destinationRootEntityType properties to support cross-entity-type
restore (e.g. element restoring into element-folder). Existing document
and media manifests are unaffected as all new properties fall back to
the original values. Also adds element folder restore manifest.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor(recycle-bin): extract #resolveDestinationItemName to reduce complexity
Extract resolver logic from setDestination into a dedicated method to
bring cyclomatic complexity under the threshold of 9.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Removed Restore Element Folder From Recycle Bin Entity Action
(This is for a separate PR)
* feat(elements): enable element and folder restore from recycle bin
Uncomment element restore manifest with destination overrides, add
folder picker modal, and add null guard for restore item lookup.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fixes bug with selecting the Root for the restore target
* Corrected manifest aliases to use appropriate entity-type name for `ElementFolder`
* Added `UmbElementFolderItemDataResolver` to resolve folder names in recycle bin restore modal
* E2E: QA Added acceptance tests for restoring elements and deleting elements from recycle bin (#22069)
* Updated test helper for move a folder to recycle bin
* Added tests for restore element and delete element from recycle bin
* Added ocmment for the failing tests
* Make recycle bin tests run in the pipeline
* Fixed comment
* Removed duplication code
* Reverted npm command
* Adds `itemDataResolver` to the Element Trash entity-action
* Makes trashed Element Folder name to be read-only
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Nhu Dinh <150406148+nhudinh0309@users.noreply.github.com>
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* add info workspace view into document blueprint
* Add history panel
* update document type route
* remove comment
* move time options format to ultils
* add blueprint auditlog model
* save move action and add authorization for audit log request
* add default implement
* update open api json
* Reused the `workspaceInfoApp: auditLog` kind
Added the manifest for the repository.
Removed the duplicated/unused code.
* UI tweaks + linting
* Renamed "Document Blueprint Workspace View Info Element" file/tag
* Restored the "UmbDocumentBlueprintAuditLog" types
* Add JSDoc to document blueprint audit log repository
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Export audit-log module from document-blueprints index
Adds the missing re-export so UMB_DOCUMENT_BLUEPRINT_AUDIT_LOG_REPOSITORY_ALIAS
is reachable from @umbraco-cms/backoffice/document-blueprint.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: leekelleher <leekelleher@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
* claude review md files
* rename to review
* auto-detect target-branch via GH CLI
* Verify GH CLI is Available
* update table to fit github markdown format
* condensed the output to the essense
* State if the PR is too bad
* using the word `and´
* only relevant suggestions
* clean up
* narrow the scope for large PRs
* diff-first approach with selective reads
* specify that the header_only are amount of file where the only extra loaded is the header
* Complexity detection
* Classification of the PR
* improve other changes
* Ensure Types are kept intact in their type Hierarchy
* align test naming with project, and clean up instructions
* remove hardcoded Claude.md file table for a pattern
* improve skill description
* improved breaking change detection for front-end
* do not suggest breaking changes for PRs targeting main
* rename skill to umb-review
* less nit picky
* first version of skill evals
* Update .claude/skills/umb-review/references/coding-preferences.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update .claude/skills/umb-review/references/impact-analysis.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* remove mentioning the skill action it self
* split out GH CLI guideline
* improve file loading strategy
* make feedback extremely concise
* improve skipped files output
* latests eval
* added further evals
* move summaries into references
* separate Complexity Assessment into a reference file
* Complexity Assessment: secure mixed is still check despite other rules it out
* dont include gen.ts files
* iter 9 evals
* latests eval of 4
* keep only one test for complexity-advisory
* adjusted skill and Evals to match expectations
* improve sibling lookups
* improve skill regarding nit picks and C# patterns
* remove insecure manifest check
* final eval run
* eval grading
* remove review workspace
* remove umb review workspace part 2
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add workspaces docs, CLAUDE link, and skill
* Export workspace elements as element
* consolidate information
* adjust skill to make use of generic name component
* try to force the agent to follow docs and use skills
* Update SKILL.md
* clean up create package skill
* use data type package as reference
* Update src/Umbraco.Web.UI.Client/docs/workspaces.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/docs/workspaces.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update workspaces.md
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Present only changed variants as selected by default when saving and publishing.
* Detect pending changes on document load to ensure language selector variant status reports correctly.
* Avoid concurrent loads.
* Fix issue where with two variants changed but only one saved, both would display with pending changes.
* Addressed code review feedback.
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Element Picker property-editor: adds "Start Node" configuration
* [WIP] Adds server config for Element start node
* [WIP] Attempts to wire up the `dataTypeId`
for the Element Picker start node
* Removed `StartNodeId` from the server config
* Implemented `requestTreeStartNode`
on Element Picker data-source
* Fix duplicate config entries in input-element property setters
The `folderOnly` and `startNode` setters used `.push()` without
deduplication, causing config entries to accumulate on Lit re-renders.
Filter existing entries before pushing to prevent duplicates.
* Update OpenAPI spec and regenerate TypeScript bindings
Add dataTypeId query parameter to element tree endpoints.
* Refactor input-element to compute dataSourceConfig on demand
Replace mutable #dataSourceConfig array with plain Lit properties for
folderOnly and startNode, computing the config inline in render. This
eliminates the duplicate-entry bug and simplifies the component.
Also fix "dont" typo in ignoreUserStartNodes description.
---------
Co-authored-by: Nhu Dinh <150406148+nhudinh0309@users.noreply.github.com>
* Resolve and persist element start node IDs when updating a user
The UpdateAsync method in UserService only resolved Document and Media
start node keys to IDs, completely ignoring ElementStartNodeKeys from
the update model. This caused element start node configuration to be
silently lost on user save.
* Add ElementStartNodeNotFound status and fix XML doc for MapUserUpdate
Introduces a dedicated ElementStartNodeNotFound operation status to
distinguish missing element start nodes from missing element items in
other operations, consistent with ContentStartNodeNotFound and
MediaStartNodeNotFound. Also adds the missing XML doc param for
startElementIds on MapUserUpdate.
* Add blank line to re-trigger the build.
---------
Co-authored-by: kjac <kja@umbraco.dk>
* TipTap: Add width/height to edit image properties (AB#65981)
Add width and height input fields with aspect-ratio lock toggle to the
media caption/alt-text modal. Thread dimensions through the toolbar
action so existing image dimensions are preserved when editing.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* TipTap: Add double-click to open edit modals for images and embeds
Move double-click detection into node extensions via addProseMirrorPlugins
(tiptap-native). Extensions dispatch a generic DOM event, input-tiptap
delegates to the toolbar, and the toolbar executes the active action.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* TipTap: Improve edit image properties, unify embed dimensions, fix figcaption bug (AB#65981)
- Add width/height fields with aspect-ratio lock and maxImageSize cap to image modal
- Unify embed modal dimensions UI with image modal (inline row, lock button, px postfix)
- Fix figcaption cursor bug: editing from inside caption no longer opens new image picker
- Pass user dimensions to imaging endpoint for valid HMAC-signed URLs
- Preview image updates aspect-ratio when dimensions change
- Slim down toolbar API: inline pass-through methods, remove dead code
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: add missing width: 100% to image modal dimension inputs
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use display:block instead of width:100% on dimension inputs
Prevents the right border of the px affix from being clipped.
Applied to both image and embed modals for consistency.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: remove explicit sizing on dimension inputs, let flex handle it
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use @input instead of @change on embed dimension fields
Aligns with image modal behavior so constrained dimensions update
on keystroke. Preview fetch is debounced at 500ms to avoid spam.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: address Copilot review feedback
- Wrap imageSize() in try/catch so modal remains usable on broken URLs
- Recalculate aspect ratio on re-lock in image modal (matches embed)
- Change min="0" to min="1" on dimension inputs (both modals)
- Fix constrain truthiness check to use !== undefined
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* TipTap: Use maxImageSize config for embed defaults, update ratio to 16:9
Replaces hard-coded 360x240 (3:2) embed defaults with maxImageSize from
RTE config and a 16:9 aspect ratio matching modern video embeds.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: select figure before replacing when editing from figcaption
When cursor was inside a figcaption, insertContent would insert a new
figure at the cursor instead of replacing the parent figure. Now selects
the figure node via setNodeSelection before proceeding.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: export UMB_TIPTAP_NODE_DBLCLICK_EVENT from tiptap constants
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore: removes double-click handling (to be implemented later on)
* Apply suggestion from @AndyButland
Co-authored-by: Andy Butland <abutland73@gmail.com>
* feat: adds constants for default width and height and guards against 0-values
* feat: validates that width and height are larger than 1px
* refactor: Extract shared <umb-input-dimensions> component
Deduplicates the width/height dimension input logic that was repeated
in both the media caption/alt-text modal and the embedded media modal.
The new component supports aspect ratio locking, proportional resize,
disabled state, and an optional reset-to-natural-dimensions button.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: embeds should be constrained by default
* feat: defaults embed constrain to true
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: always fetch natural dimensions so reset button appears when editing
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: move reset button below dimensions and cap natural size to maxImageSize
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore: cleanup
* fix: use general_clear localization key for reset button
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: constrain embed preview to sidebar width using aspect-ratio
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: target any first-child element in embed preview, not just iframe
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore: add comment explaining generic selector for oEmbed markup
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use height auto to let embed scale naturally from width
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use !important on width to override inline oEmbed attributes
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use height 100% so iframe fills the aspect-ratio container
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: smooth embed preview aspect-ratio changes with CSS transition
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: smooth image preview aspect-ratio changes with CSS transition
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: show Clear button on embed dimensions using default size as natural
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: use maxImageSize for embed natural dimensions and Clear button
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: media-with-caption modal should be 'medium'
* feat: address review feedback on dimensions and preview
- Rename reset button label from general_clear to general_reset (new key)
- Fix embed preview: use pixel width + aspect-ratio + max-width for
accurate proportional preview at any dimension
- Apply same width+aspect-ratio approach to image preview
- Add uui-box to media caption modal for consistent sidebar background
- Center image and embed previews in their containers
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: simplify embed modal — honest dimensions, responsive iframe preview
Remove maxImageSize and naturalWidth/naturalHeight from embed modal since
oEmbed dimensions are hints (maxwidth/maxheight), not guarantees. Add
localized description explaining this to the user. Fix iframe preview
collapsing to 150px by reading width/height attributes and applying
aspect-ratio via JS (iframes lack intrinsic dimensions unlike images).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: recalculate aspect ratio when dimensions are set externally
When width/height properties are set from outside (e.g. after async
imageSize() resolves), the ratio was not recalculated — leaving it
undefined from connectedCallback. This caused locked mode to silently
fail on first appearance of the media caption/alt-text modal.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Remove unused recycleBin keys from XML language files
The recycleBin area contained keys (contentTrashed, mediaTrashed,
elementTrashed, elementContainerTrashed, itemCannotBeRestored,
itemCannotBeRestoredHelpText, wasRestored) that are no longer
referenced by any backend code since the audit logging was removed
from RelateOnTrashNotificationHandler in #21481.
* RichTextEditor: Filter media picker to allowed media types (closes#21824)
Add allowedMediaTypes config to the RTE data type, filtering the media
picker tree to only show selectable media types. Also applies type-aware
validation to drag-and-drop uploads using UmbMediaTypeStructureRepository,
with a modal picker when multiple types match a dropped file.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Review fixes: cache media type lookups, remove unnecessary localization keys, fix lint
- Cache requestMediaTypesOf results per extension to avoid redundant API calls
when dropping multiple files with the same extension
- Add try/catch around API call to prevent unhandled rejections from crashing
the upload loop
- Remove custom localization keys, reuse same plain strings as MNTP config
- Fix prettier formatting warnings
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: Auto-Pick in media type picker modal no longer silently fails
The modal returns `{ mediaTypeUnique: undefined }` for auto-pick, which
was treated as a cancellation. Now distinguished from cancel (rejected
promise) and falls back to the server's preferred type.
Fixed in both the media dropzone manager and TipTap drag-drop upload.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore: Add localization keys for allowedMediaTypes config, reorder weight
Move allowedMediaTypes next to mediaParentId (weight 91) as they are
related media config options. Use #rte_config_* localization pattern
matching other RTE config properties.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: Show notification when pasting disallowed file types into RTE
The MIME-type pre-filter silently dropped non-image files on paste
(and drag-drop). Now shows the same disallowed file type notification
as the media type validation path.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: Add server-side validation for RTE AllowedMediaTypes config
Validates that media items referenced via data-udi in RTE markup are of
an allowed media type. Follows the same pattern as MNTP's
AllowedTypeValidator. Includes unit tests.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Clean up validator tests: remove unused param and region markers
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Use splitStringToArray for config parsing consistency
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Include media name in validation error for disallowed media types
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* test: Fix and add acceptance tests for RTE allowedMediaTypes config
* feat: Default RTE to Image and SVG allowed media types
Set allowedMediaTypes to Image and Vector Graphics (SVG) in the
default Rich Text Editor data type seed for new installs. Also
update the Vite mock data to match.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: Address Copilot review feedback
Fix test helper that swallowed null allowedMediaTypes parameter,
masking the "no filter configured" test case.
Remove redundant upload failure toast that showed a misleading
"disallowed media type" message for non-validation failures
(the upload manager already handles its own error notifications).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: Use constants for seed GUIDs, normalize file extension casing
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Refactored media type checks into helper shared across RTE and media picker.
Resolved case insensitivity edge case.
Removed unnecessary obsolete constructor.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add flag support for pending changes and scheduled publish
Add entity sign manifests, tree item rendering, and flag provider
support so element tree items display pending changes (pencil) and
scheduled publish (clock) icons, mirroring the existing document
behavior.
Refactor flag providers and presentation factories to reduce
duplication, and move shared IHasFlags implementation into
PublishableVariantResponseModelBase.
* Fix HasScheduleFlagProvider test mocks to match refactored per-item lookups
* Extract PublishableVariantItemResponseModelBase to deduplicate variant item models
* Extract shared base class from Document/Element presentation factories
Introduce PublishableContentPresentationFactoryBase to eliminate code
duplication between DocumentPresentationFactory and ElementPresentationFactory.
Add async alternatives (CreateVariantsItemResponseModelsAsync,
CreateItemResponseModelAsync, PopulateFlagsAsync) and migrate callers in
async contexts to use them. Sync callers in tree/recycle bin controllers
use .GetAwaiter().GetResult() to avoid breaking changes in base classes.
Add IPublishableContentEntitySlim overload to DocumentVariantStateHelper
to unify the identical IDocumentEntitySlim/IElementEntitySlim overloads.
Make RelationTypePresentationFactory properly async with Task.WhenAll.
* Fix flags fallback to use empty array instead of empty string
* Acceptance Tests: Fix element tree item locator to match both elements and folders
The element tree renders umb-element-tree-item for elements but
umb-default-tree-item for folders. Update the E2E test helper locator
to use :is() to match both custom element types.
* Split HasScheduleFlagProvider into document and element providers
Address PR review feedback:
- Split HasScheduleFlagProvider into HasDocumentScheduleFlagProvider and
HasElementScheduleFlagProvider with a shared HasScheduleFlagProviderBase
- Fix N+1 query: use batch GetContentSchedulesByKeys instead of per-item
GetContentScheduleByContentId
- Add GetContentSchedulesByKeys to IPublishableContentService and implement
in PublishableContentServiceBase, removing the duplicate from IContentService
and ContentService
- Inject TimeProvider into base class, replacing DateTime.Now with
_timeProvider.GetUtcNow()
- Split tests to match new provider structure and verify batch retrieval
* Make tree and recycle bin mapping methods async
Remove .GetAwaiter().GetResult() calls introduced by the element flag
support changes. Rename MapTreeItemViewModel to MapTreeItemViewModelAsync
and MapRecycleBinViewModel to MapRecycleBinViewModelAsync across all
tree and recycle bin controllers, properly awaiting async factory calls.
* Extract Task.WhenAll select expressions into named variables
* Add missing XML docs to async methods on IDocumentPresentationFactory
* Fix DateTime vs DateTimeOffset comparison in schedule flag provider
Compare schedule.Date against _timeProvider.GetUtcNow().UtcDateTime
instead of the DateTimeOffset directly, avoiding implicit conversion
issues with DateTimeKind.Unspecified.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Fixed label in account menu button
The account menu button in the backoffice header was displaying user initials
visually (e.g., "AB") but the accessible name only showed "Profile options",
violating WCAG 2.5.3 which requires that when a UI component has visible text,
the accessible name must contain that visible text.
This fix ensures voice navigation software (e.g., Dragon NaturallySpeaking) can
properly recognize commands using the visible initials.
Changes:
- Added getInitials() utility function to extract first and last initial from user names
- Updated current-user-header-app component to include user name and initials in the
button's accessible label (aria-label)
- Updated profileOptions localization term in all 15 language files to include
placeholders for user name and initials using %0% and %1% format
Result:
- Visual display: "AB"
- Accessible label: "User profile for Andreas Lykke Borg (AB)"
The visible initials are now included in the accessible name, providing a
consistent experience for all users including those using assistive technologies.
Fixes#21942
* Update src/Umbraco.Web.UI.Client/src/packages/user/current-user/utils/get-initials.function.ts
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added a fallback profile options label if name is null or empty
* Added test for get-initials function
* Added note about duplicate get-initials function
* Replicated the logic from the UUI avatar
* Add TODO to use utility exposed from UUI library for extracting the initials.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Fixes#22291
In order to show the right validation message:
- the repository code always notifies the validation failure message
(or a default failure message if none is received)
- in the data-source code, tryExecute is called with the option
to disable the default notification
Return the original error instead of faking success
* Allow copying of system media types.
* feat: Improve error message for system media type alias change
Replace the generic "Operation not permitted" error with a specific
"Alias change not permitted" message that explains the constraint and
suggests using the duplicate operation instead.
Also adds an ordering comment in DeepCloneWithResetIdentities and
a test assertion verifying the copy's alias is mutable.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* add frontend claude context for architecture, deprecation, package-development
* update with developer roles
* tighten up for llm consumption
* add information about localization
* add section about kinds
* include test priority
* add llm docs for core primitives and data flow
* add info about caching
* add skills
* organize in folders
* flat list of skills
* Update src/Umbraco.Web.UI.Client/docs/architecture.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/docs/package-development.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* update skill name
* format tech stack based on claude recommendations
* add context about entities
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add more granularity to ContentTypeChangeTypes and handle for structucal changes (pending non-structucal changes).
* Integration tests to validate the granular, structucal change types
* Implement "other" changes
* Make "other" changes less granular.
* Update tests/Umbraco.Tests.Integration/Umbraco.Core/Services/ContentTypeEditingServiceTests.ChangeTypes.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Clean up
* Add test proving the sub-flags do not collide
* Support change detection for both structural and non-structural changes in one operation
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Add missing notifications to element container and element editing services
Add ElementDeletingNotification and ElementTreeChangeNotification to
ElementContainerService for EmptyRecycleBin, Move, MoveToRecycleBin,
and Delete operations, aligning with ContentService notification patterns.
Add ElementTreeChangeNotification to ElementEditingService for Move
and Copy operations.
Refactor DeleteDescendantsLocked to return deleted elements and
DeleteItem to return the deleted entity for use in tree change
notifications.
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Update Microsoft.Extensions.Caching.Hybrid to latest minor, and other Microsoft dependencies to latest patch.
* Align test and local web project dependency versions.
chore(tests): remove dead KeepAlive config remnants
The KeepAlive feature was removed in b619399edb (#15891) but references
to the config remained in 8 acceptance test appsettings.json files and
2 CI pipeline env var definitions. These are no-ops since the setting
no longer exists — remove them.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Nhu Dinh <150406148+nhudinh0309@users.noreply.github.com>
* Update Microsoft.Extensions.Caching.Hybrid to latest minor, and other Microsoft dependencies to latest patch.
* Align test and local web project dependency versions.
* Remove obsolete code
* Update tests in BlockEditorBackwardsCompatibilityTests
* update languageId, remove obsolete construcor from ApiLink
* remove the tests
* Fixed build of unit tests.
* Reverted removal of UmbracoApiController for now (we should do this in a single PR).
* Code style fix.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added migration for SVG width/height
* #22114 worked on SVG width height implementation
* #22244 Code style fixes
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 XmlReaderSettings and using
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Cleanup
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Correction if statement
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Refactor log message
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Correction if statment
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Cleanup
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Cleanup
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Code style adjustments
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Adjust if statement
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Adjust documentation comments
Co-authored-by: Andy Butland <abutland73@gmail.com>
* #22244 Fix log comment
* #22244 Fallback to viewbox if width height attribute has other unit than numeric or px.
* #22244 Refactoring SVG parser, no support for decimals
* #22244 Migration, consistent logging
* #22244 Create vector umbracoWidth and umbracoHeight during clean install
* #22244 Remove SupportedImageType from ISvgDimensionsExtractor
* #22244 pass culture and segment to SetValue
* Add DtdProcessing.Prohibit security hardening to SvgDimensionExtractor.
* Addressed some code styling and robustness of the migration and extractor classes.
* Add further unit tests.
* Add logging to notification handler. Skip when properties don't exist to avoid unnecessary processing.
* Add unit tests for media saving handler.
* Move the dimensions extractor implementation into infrastructure.
---------
Co-authored-by: Markus Johansson <markus@obviuse.se>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fix(core): append SiteName to machine identifier for same-host load balancing
When multiple Umbraco instances run on the same machine (e.g. IIS AAR load
balancing or local LB simulation), they shared the same machineId key in the
umbracoLastSynced table, causing cache sync interference. If Umbraco:CMS:Hosting:SiteName
is configured, it is now appended to the machine name to produce a unique
identifier per instance.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Update tests/Umbraco.Tests.UnitTests/Umbraco.Core/Factories/MachineInfoFactoryTests.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Validate length
* Refactor to enable us to have a validator
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Added api helper for block grid area
* Updated ui helper for block grid area
* Updated tests for block grid area
* Updated json builder for blockGridSpecifiedAllowance
* Formatted code
* Updated ui helper for specifiedAllowance
* Updated tests
* Fixed ui helper for enterSpecifiedAllowanceMinByIndex
* Added ui helper for create content with a block area with specified allowance
* Added tests for create content with ablock grid area with specified allowance
* Format code
* Make tests run in the pipeline
* Fixed tests
* Fixed comments
* Reverted npm command
* Extend and tidy up unit and integration test coverage.
* Add MaxVersionsToDeletePerRun configuration setting.
* Added overload to GetDocumentVersionsEligibleForCleanup to allow restricting results to older than a given date and with a maximum count.
* Use SQL date filter and per-run cap in content version cleanup.
* Handle deletes using optimised process using temp tables.
* Make maxCount nullable and add per-run cap integration test.
* Addressed code review feedback.
* Fix to reporting of cap reached.
* Additional unit tests for max date cut-off logic.
* Add TODOs for removal of default implementations from interfaces.
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Revert timing for ContentVersionCleanupJob.
* Add index to versionDate on umbracoContentVersion.
* Ensure long command timeout for upgrade.
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
Close readline before starting dev server
Close the readline interface before launching the Vite dev server so Ctrl+C can properly terminate the process.
* Added more constant variable for validation message
* Added api helper for creating multi url picker data type with min number
* Renamed
* Updated api helper for creating document with multi url picker
* Added tests for mandatory multi url picker
* Split out tests for content with a multi URL picker.
* Refactor and added tests for publish a block with empty mandatory multi url picker
* Make tests run in the pipeline
* Fixed comments
* Update MFA label to 2FA in English language file
* Changed MFA to 2FA in all other language files.
* Revert "Changed MFA to 2FA in all other language files."
This reverts commit 203294e287.
* Changed MFA to 2FA in all other language files.
---------
Co-authored-by: Marc Love <marc@madebycrunch.com>
* Handle API and surface controllers with correct status code and behaviour when a member isn't logged in.
* Addressed code review feedback.
* Further code review feedback.
* utilize the member type structure repo to get member create options
* align member collection create action with other content types
* remove hardcoded icon
* Update constants.ts
* register as create options
* restore label
* Remove ellipsis from document blueprint label
* Add collection create actions for tree item children
* Show ellipsis for labels with additional options
* Enable additional options for create actions
* Refactor language and member group create actions into create option actions
* Update UiBaseLocators.ts
* Add additionalOptions to create manifests
* Add ellipsis to names in create content modals
* Update DataTypeUiHelper.ts
* Update DocumentTypeUiHelper.ts
* Update creation action locators and tests
* Update LanguageUiHelper.ts
* Adds optional `requestStartNode`
to Entity Data Picker tree source confguration
* Changes the example Document data-source
to use a Document Picker for the start node,
instead of the Content Picker source.
As that is targeted across Documents, Media or Members.
* Example Documents data-source: implemented "start node"
* Renamed `requestStartNode` to `requestTreeStartNode`
* Code tidy-up
* Fix issue where dynamic node query based from current node does not resolve for new documents.
* Add tests verifying the fix. General cleanup of code warnings in dynamic node implementations and tests.
* Addressed failing integration test and code review feedback.
* Allow saving document blueprints with partial variant names.
* Address code review feedback.
* Use shallow copies instead of in-place mutation when filtering unnamed variants before delegating to base class validation.
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* preserve connectionString befor disposing EfCoreDatabase during dispose of EfCoreScope. Fixed by Claude Sonnet 4.6
* Add details of integration tests to memory files.
* Ensure original connection string is captured and remove unnecessary guard.
* Add further test verifying the fixed behaviour.
* Test clean-up.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Updated helpers
* Moved to specific test files
* Added tests with compositions
* Updated helper
* Run tests on pipeline
* Fixed
* Updated helpers
* Added tests for variants
* Added tests
* Updated smoke
* Fixed
* Cleaned up
* Moved to before each
* Reverted test command
* Added ui helper for copy button
* Updated tests since the duplicate button is replaced by the copy button
* Update tests/Umbraco.Tests.AcceptanceTest/lib/helpers/UiBaseLocators.ts
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Added constant variables for public access notification message
* Added ui helper for public access
* Added api helper for setup and delete public access
* Added api helper for create default member group
* Updated tests to use createDefaultMemberGroup instead of the directly create api
* Added tests for setting public access on content
* Added api helper for verify public access
* Updated ui helper for verify public access
* Updated tests for public access
* Make tests run in the pipeline
* Fixed comment
* Reverted npm command
* Added constant variable for healthCheckMessage
* Added appsetting file for imaging setting config tests
* Updates name
* Added project for imagingSettingConfig
* Added ui helper for verify health check of Imaging HMAC Secret Key
* Updated tests for HMAC secret key health check with default settings
* Added tests for HMAC secret key health check is not configured
* Makes test run in the pipeline
* Fixed comment
* Clean code
* Reverted npm command
* Clear stale connection on pooled DbContext before returning to pool.
* style: apply linter comment punctuation fix
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Removed unnessary test.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add to backoffice hosts
Add to backoffice hosts, rather than completely replacing the array
* Add unit tests verifying fix.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update Nunit and AutoFixture.Nunit to new versions
* Adding NonParallelizable
* Add blame-hang timeout to integration tests to detect hanging tests
* remove NonParallelizable, update NUnit3TestAdapter, add Ingore to CoreConfigurationHttpTests
* Resolve CoreConfigurationHttpTests hang with NUnit 4.
- Use Task.Run in CreateHost to escape NUnit 4's SynchronizationContext
which deadlocks sync-over-async calls from async test methods.
- Use await using for factory disposal to avoid same deadlock on shutdown
- Remove WithWebHostBuilder which wraps the factory in a
DelegatedWebApplicationFactory that bypasses the CreateHost override.
- Add ContentRoot property to UmbracoWebApplicationFactory so content
root can be set without WithWebHostBuilder.
- Set ModelsBuilder mode to Nothing to prevent BootFailedException.
- Add AddTestServices for infrastructure test doubles (MainDom, etc.).
* Revert changes to pipelines.
* Remove remaining CollectionAssert using legacy syntax.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Extract shared culture-resolution logic from ConvertBlockEditorPropertiesBase, ConvertLocalLinks, FixConvertLocalLinks, and MigrateSingleBlockList into PropertyDataCultureResolver, fixing a bug where NULL languageId (legitimate invariant data) was incorrectly treated as a deleted language reference.
Add unit tests covering all resolution paths including the bug scenario.
* Remove obsoletion on helper.
* Address code review feedback.
* Handle SetValue variation mismatch for invariant data on culture-varying compositions
* Fixed build error in tests.
---------
Co-authored-by: Sven Geusens <sge@umbraco.dk>
* init implementation
* Add template tree item-children collection and views
* add base class
* Use Settings section for document blueprint paths
* Inline customElement names and update typings
* Make table collection view buttons compact
* remove collection action again as they require create options to be registered first
* move file
* fix export
* fix const exports
* Extract template tree repository alias to constants
* Extract shared culture-resolution logic from ConvertBlockEditorPropertiesBase, ConvertLocalLinks, FixConvertLocalLinks, and MigrateSingleBlockList into PropertyDataCultureResolver, fixing a bug where NULL languageId (legitimate invariant data) was incorrectly treated as a deleted language reference.
Add unit tests covering all resolution paths including the bug scenario.
* Remove obsoletion on helper.
* Address code review feedback.
* Handle SetValue variation mismatch for invariant data on culture-varying compositions
* Fixed build error in tests.
---------
Co-authored-by: Sven Geusens <sge@umbraco.dk>
* Add to backoffice hosts
Add to backoffice hosts, rather than completely replacing the array
* Add unit tests verifying fix.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Adding a file system approach to subscriber servers
* Adding tests
* Alternative lazy injection
* Adding delegate unit tests and making classes internal sealed.
* Adding a check to see if database is readonly
* Modifying DatabaseReadOnlyAccessor.cs
* Add table view to media picker modal
* Use unique id in media picker selection handlers
* Add dateTime formatter and use in media picker
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Add dateTime localization tests
* localize view labels
* Persist media picker view in interaction memory
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* fix(media): prevent upload field image from overflowing content container
The image element used `height: 100%` which resolved to a definite value
when rendered in the old flex-row layout (parent's stretch gave it a height).
After #21887 restructured the wrapper to flex-column, the parent no longer
provides a definite height, so `height: 100%` falls back to `height: auto`
and the image renders at its natural (potentially huge) dimensions.
Fix by giving `img` direct constraints (`max-width: 100%`, `max-height: 400px`,
`height: auto`) so it constrains itself regardless of the parent layout context.
Closes#22106
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* style(media): remove redundant max-height from :host, keep on img
The max-height: 400px is now on the img directly, so the :host constraint
is redundant.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): apply same image overflow fix to SVG upload preview
Same root cause as #22106: img relied on height: 100% resolving via
parent flex-stretch, which breaks in the flex-column layout from #21887.
Move constraints to img directly (max-width: 100%, max-height: 400px,
height: auto) and remove redundant/ineffective host properties.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* style(media): move min-height from :host to img in image and SVG previews
With height: auto on img, min-height on :host left an empty gap when the
image was shorter than the minimum. Moving min-height to img ensures the
checkerboard background fills the full minimum preview area consistently.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): prevent image cropper focus setter from blinking on upload
The #image element had no CSS size constraints, causing it to render at
its natural dimensions briefly before the onload handler applied
width/height: 100% via inline styles. Adding max-width/max-height: 100%
ensures the image is already constrained on first paint, eliminating the
reflow blink when uploading a new image.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): use File object name for extension in file upload preview
When a file is dragged in before saving, the path is a blob URL
(blob:http://...) which produces a garbage extension when split on '.'.
The File object is already passed as a prop via the interface but was
unused. Prefer file.name for extension extraction when available.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Routing: Resolve URL segment collision for siblings differing only in punctuation (closes#22070)
When sibling documents have names that differ only in punctuation
(e.g. "Title" vs "Title."), the URL segment provider strips punctuation
and produces identical segments, causing routing conflicts.
Add collision detection in DocumentUrlService.CreateOrUpdateUrlSegmentsAsync
that checks sibling segments (from both the in-memory cache and the current
batch) and appends a numeric suffix (-2, -3, etc.) when a collision is found.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Routing: Move URL segment collision detection to DocumentRepository name uniqueness (closes#22070)
Reverts the DocumentUrlService approach (URL-level `-2` suffixes) in favour of
detecting collisions at the document name level. When two sibling names produce
the same URL segment (e.g. "Title" and "Title." both clean to "title"), the
existing `(1)` naming convention is applied to the name itself, which then
yields a distinct URL segment.
Changes:
- Revert DocumentUrlService collision resolution logic
- Override EnsureUniqueNodeName in DocumentRepository to augment sibling names
with phantom entries for URL segment collisions (via IShortStringHelper)
- Apply same augmentation in EnsureVariantNamesAreUnique for variant content
- Add IShortStringHelper constructor dependency (with obsolete compat pattern)
- Add unit tests verifying the phantom entry approach
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Routing: Refactor URL segment collision to direct segment comparison
Replace the indirect "phantom entries" approach with a clearer two-step
strategy as suggested in review:
1. Call base.EnsureUniqueNodeName() to handle literal name duplicates
2. Fetch siblings, compute URL segments, and increment (N) suffix until
the resulting segment is unique
This is easier to reason about and avoids manipulating the SimilarNodeName
algorithm. The trade-off is a second sibling fetch (same indexed query),
which only runs on save.
- Replace AugmentNamesForUrlSegmentCollisions with EnsureUniqueUrlSegment
- Apply same pattern in EnsureVariantNamesAreUnique
- Remove phantom entry unit tests from SimilarNodeNameTests
- Add integration tests on ContentService for both invariant and
culture-varying content with punctuation-only name differences
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Updated usages of obsolete constructors.
* Avoid second look-up of siblings data.
* Make EnsureUniqueUrlSegment unit testable, and add tests.
* Pass content.Id rather than 0 in variant unique name check.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* update outdated dependencies to their latest major versions
* change version of JsonPatch.Net back to 3.*.*
* Upgrade Umbraco.Code package
* Update tests
* Resolve NUnit 4 migration issues causing test hangs
* Fix for dotnet test on the pipeline.
* Debug: Fix attempt for integration tests on the pipeline.
* Revert pipeline changes and go back to 5.2.0.
* Debug: Omit suspect tests.
* Debug: Disable tests with timeout.
* Debug: Try 4.6.0.
* Debug: Added reference to Microsoft.CodeAnalysis.CSharp.Workspaces.
* Roll back NUnit upgrade.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Optimise redirect tracker by avoiding re-producing of descendant nodes and avoiding descendant traversal when there has been no change to the node's URL segment.
* Delete inadvertently added file
* Allow URL segment providers to ensure descendent traversal if needed.
* Pushed missing files.
* Refactors to reduce large method code smells.
* Optimise redirect tracker by avoiding re-producing of descendant nodes and avoiding descendant traversal when there has been no change to the node's URL segment.
* Delete inadvertently added file
* Allow URL segment providers to ensure descendent traversal if needed.
* Pushed missing files.
* Refactors to reduce large method code smells.
Change setOneContent to setOneSettings for initialSettings
Line 661 calls setOneContent() with settings data instead of setOneSettings(). This pushes the settings element into the contentData array.
* remove obsolete constructor
* adjust RootDictionaryTreeController constructor to use non-obsolete constructor and remove obsolete base
* todo action v18
* remove ActivatorUtilitiesConstructor atribute that there's only one constructor
* remove obsolete class and method
* remove obsolete code in v18
* remove obsolete code from repositories
* remove obsolete for blocks
* remove obsolete code from services
* remove Icomponent
* remove incorrect IRequestSegmmentService
* remove obsolete properties
* undo change of blocklayoutitembase because of test failed
* bring back somes code due to pr 21999
* bring back some codes and update ContentRouteBuildertests
* remove obsolete code from domains, notification controller and some services
* remove obsolete constructor from ElementMapDefinition
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Updated naming
* Updated path to test files
* created tests
* Reverted retries change
* Updated imports
* Added step
* updates based on comments and clean up
* Added vars
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Added .skip tags for the failing tests due to an actual issue
* Change the way to verify the validation message
* Added .skip tags for failing tests due to the actual issues
* Adding code comments to Umbraco.Cms.Api.Management
* Update src/Umbraco.Cms.Api.Management/Controllers/MemberGroup/UpdateMemberGroupController.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Cms.Api.Management/Controllers/DocumentBlueprint/MoveDocumentBlueprintController.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Cms.Api.Management/Controllers/DataType/CopyDataTypeController.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Cms.Api.Management/Controllers/DocumentType/CopyDocumentTypeController.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Cms.Api.Management/Controllers/DataType/IsUsedDataTypeController.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fixing a missing closing brace on return docs.
* Fixing issue raised by copilot.
Issue was:
Inconsistent use of T: prefix in cref attribute. Other parameters in this PR use the interface name directly without the T: prefix (e.g., <see cref=\"IContentTypeService\"/>). Remove the T: prefix for consistency.
* Fix broken <returns> tags.
* Fixed incorrect descriptions.
* Added missing description.
* Fix positioning of comments.
* Fixed indentation.
* Use standard text for view model properties.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
* fix(core): lowercase file extension before validating against allowed/disallowed lists
Fixes case-sensitive comparison in UmbTemporaryFileManager where uploading a
file with an uppercase extension (e.g. .PDF) would be incorrectly rejected
even when the lowercase extension (pdf) was in AllowedUploadedFileExtensions.
Closes#22096
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(media): lowercase SVG extension check in media links info app
Fixes case-sensitive .svg check so that media files with uppercase
extensions (e.g. .SVG) correctly use the SVG viewer link.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(core): also lowercase config extension lists before comparison
The server may return extensions in any case (config is stored as-is).
Lowercase both sides to ensure the comparison is truly case-insensitive.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Ensure server-side checks for file extensions are case insensitive.
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Updated multiURLPickerSettings as there is a new setting for Culture-specific document links
* Updated tests for verify the default configuration of multi url picker data type
* Increased time for waiting the loader icon disappears to avoid the flaky tests
* Updated tests for reset manual URL using remove button due to locator changes
* Added ui helper for card collection view in content
* Updated tests to reflect that grid view is now the default instead of list view.
* Updated ui helper for public access saving button due to UI changes
* Removed unused code
* Fixed comments
* Removed unused test folder
* Updated auth to clear storage
---------
Co-authored-by: Andreas Zerbst <andr317c@live.dk>
* Basic implementaion
* Tests and schema validation
* Attemp refactor
* Fix json single parent bug
* Surface doctype schema validation to management api
* Improve block schema and make validation errors less verbose
* fix validation error cleanup
* Improved GUID handling | added schema for all propertyEditors
* Add ContentTypeInputSchema
* move contenttype schemas to be actual jsonschemas
* Fix block limit on blocklist and grid
* add datatype schema batch
* Refactoring blocks json schema generation and add to richtext
* Package version update and more tests!
* ConvertToJsonNode optimization
* async refactor
* Add editorUiAlias to x-umbraco-properties and make DataType ref route dynamic
* Removed JsonSchema.net due to possible license issues
* Use void editor in the noop schema test
* Cleanup leftovers from Schema validation removal
* Move batch logic into batchcontroller
* Update src/Umbraco.Infrastructure/PropertyEditors/BlockJsonSchemaHelper.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Cms.Api.Management/Services/ContentTypeJsonSchemaService.cs
Improve lookup on building propertymetadata
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fixed build error.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Provide more descriptive management API responses for invariant with variant composition.
* Improved messaging and fixed integration tests.
* Fixed ordering of new ContentEditingOperationStatus values so existing values retain their integer equivalent.
* Suppress breaking changes in integration tests.
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Prevent move to recycle bin for documents and media when disable delete when referenced is configured.
* Addressed code review feedback and fixed failing client-side test.
* Add suppression for renamed integration test.
* Simplified solution by moving disableDeleteWhenReferenced setting to modal.
* Fix flicker.
* Apply disable on delete handling to bulk trash dialog.
* Add additional translations.
* Move disableDeleteWhenReferenced resolution to document and media action classes, so the value is passed as modal data rather than being resolved in the modal itself.
* Update OpenApi.json.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Allow "File" media type as fallback when no specific extension match is available at the upload location
* Added regression test.
* Addressed test feedback.
* Fix after merge.
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Move #inSessionUpdateCallback guard into #setSessionLocally() so all
callers are protected, not just makeRefreshTokenRequest()'s lock callback.
Previously, completeAuthorizationRequest() called #setSessionLocally()
directly without setting the flag. With keepUserLoggedIn=true and a short
TimeOut, session$ observers fired synchronously inside #setSessionLocally,
triggering #onSessionExpiring → validateToken() → makeRefreshTokenRequest()
before #inSessionUpdateCallback was ever set — causing a second /token call
immediately after the initial code exchange 200.
The no-Web-Locks fallback path in makeRefreshTokenRequest() had the same
gap. Moving the flag into #setSessionLocally() covers all call sites.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Skip /token refresh when access token is still valid
Guard the per-request validateToken() call sites with #isAccessTokenValid()
in configureClient() and getLatestToken(). Previously, every API request
triggered a /token call even when the access token had not expired, causing
unnecessary token churn and OpenIddict ID2019 errors for in-flight requests.
Proactive refresh via UmbAuthSessionTimeoutController and startup validation
in app-auth.controller.ts are unaffected — those call validateToken() directly.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Remove redundant first-check validateToken() on app startup
setInitialState() already handles server verification before the router
evaluates guards — either via a direct /token call (makeRefreshTokenRequest)
or via peer session adoption (BroadcastChannel). The #isFirstCheck guard in
UmbAppAuthController was a leftover from the AppAuth/localStorage era, where
token state was restored from storage and needed a server round-trip to confirm
validity. That assumption no longer holds: if getIsAuthorized() is true after
setInitialState(), the session came directly from the server or from a peer
whose timing is still valid. Stale/revoked peer sessions are handled lazily
by the 401 interceptor, which triggers re-auth as needed.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Wait for ongoing cross-tab refresh before sending requests
Restores the cross-tab lock serialization that was implicitly provided by
the old unconditional validateToken() call. When another tab holds the
umb:token-refresh lock (keepUserLoggedIn proactive refresh), API requests
in this tab now wait for it to complete before proceeding. This prevents
sending requests with an access token that is about to be revoked, which
caused OpenIddict ID2019 errors on in-flight requests.
The fast path (token valid, no refresh in progress) remains: navigator.locks.query()
is a cheap browser-internal call, and the lock.request() no-op is only
incurred when a cross-tab refresh is actually happening.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Extract #ensureTokenReady(), improve naming and JSDoc
- Extract duplicate guard logic from configureClient() and getLatestToken()
into a single #ensureTokenReady() private method
- Rename from #ensureValidToken() → #ensureTokenReady() to distinguish from
the validate/valid naming cluster (validateToken, isAccessTokenValid)
- Add JSDoc to #isAccessTokenValid() clarifying it is a local timestamp check
with no network call
- Improve JSDoc on validateToken() to make clear it forces a network refresh
(unconditional /token call), distinct from the per-request #ensureTokenReady()
gate which skips the call when the access token is still live
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(auth): prevent re-entrant /token call when session$ fires synchronously inside lock
With keepUserLoggedIn=true and a short access token lifetime (e.g. expiresIn ≤ buffer),
#updateSession() triggers session$ synchronously inside the lock callback. The observer
fires #scheduleCheck → #onSessionExpiring → validateToken() before the lock is released.
This re-entrant call captures sessionBefore = newSession (already updated), so the
reference guard cannot detect it, resulting in a duplicate /token request.
Fix by tracking #inSessionUpdateCallback around the #updateSession() call. Re-entrant
callers return true immediately; concurrent non-re-entrant callers are unaffected.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
The window.opener guard in #setAuthStatus() was too broad — it skipped
setInitialState() for ANY window opened via window.open(), including the
preview window. This left isAuthorized stuck at false in the preview window,
causing the loading spinner to never resolve.
The guard is only needed for the OAuth code exchange popup (oauth_complete),
where calling setInitialState() could silently refresh the session, set
isAuthorized=true, and cause the popup to redirect to the backoffice instead
of completing the code exchange.
Fix: narrow the guard to window.opener + pathname === '/oauth_complete'.
The preview window (at path /preview) now correctly calls setInitialState(),
which restores the session from a peer tab via BroadcastChannel.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
security.md:
- Expand auth section with v17 httpOnly cookie model, [redacted] pattern,
configureClient() usage, and explicit warning against calling validateToken()
per request (causes token churn and ID2019 errors)
edge-cases.md:
- window.opener is set for any window.open() target, not just OAuth popups —
must check pathname too (root cause of #22083 preview regression)
- BroadcastChannel does not deliver to the sender — use local-only setters
inside handlers to avoid N² broadcast storms
- sessionRequest must guard with isSessionValid() before responding
- Web Lock umb:token-refresh pattern for cross-tab refresh deduplication
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Updated ui helper to verify the image cropper is rendered
* Added .skip for the failing tests due to the actual issue
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Add bulk fetch endpoints for retrieving full details for multiple entities by provided IDs, for data, document, media and member types.
* Switch to GET endpoints.
* generate new managment api types + sdk
* Update to use "batch" over "fetch".
* Update OpenApi.json and client-side types/sdk.
* Add endpoint summaries and descriptions.
* Align controller method signatures with use of HashSet<Guid> over Guid[].
* Backoffice Performance: Client-side bulk fetch of Element Types for Blocks, Content Type Compositions, and Data Types to reduce API requests (#21610)
* Add readMany for document type details
* Add batch read methods to detail interfaces
* Pre-register content-type structures and bulk load
* Add readMany support to detail request managers
* Simplify loadType and delegate to setType
* add js docs to detail data request manager
* add unit tests for detail data request manager
* Add byUniques support to detail store/repository
* implement readMany for data types
* fix typescript errors
* Preload and pass data type details to properties
* Update content-type-structure-manager.class.ts
* Replace per-property UmbDataTypeDetailRepository requests with the structure manager's bulk-loaded data type details
* Deduplicate inflight detail read/readMany requests
* Use 'read:' inflight cache key prefix
* Add bulk detail requests & status helpers
* Add management API request/cache for media/member types + requestByUniques support
* use observe controller instead of rxjs
* adjust to new apis
* rename prop to make it easier to read
* throw on error
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* remove unused import
* Fixes to failing E2E tests.
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Mole <nikolajlauridsen@protonmail.ch>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Fixed link in notification to editable document.
* Update translations using legacy mail format.
* Delete inadvertently added file
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
* Allowed for easier public access management.
* Revert the update controller as that is being handled by the frontend.
* Cleaning up pull request
* Preserving obsolete function, updating controller to pass optional parameter.
* pass in the includeAncestors parameter
* Added in an alert message for when the permissions are being inhereited.
* Complete resolution of breaking changes on IPublicAccessPresentationFactory.
* Update call to controller from integration tests.
* Fixed variable name typo and whitespace.
* Added clarifying comment to client-side behaviour.
* Supressed the breaking change on the controller with the additional parameter.
* Added unit tests for PublicAccessPresentationFactory.
* Added localisation for ancestor label.
* Typo and whitespace.
* Updating the model to allow for switching between methods while still preserving ancestor selections.
* update locatlizations
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Auth: Fix popup flow showing backoffice after session timeout re-auth
When a session times out client-side, the parent tab's #session was still
non-null (the timeout signal fires without clearing the session). When the
re-auth popup opened and called setInitialState(), it sent a sessionRequest
via BroadcastChannel. The parent responded with the expired session because
the handler only checked `if (session)` — not if the session was still valid.
The popup's auth context then thought it was already authorized, causing the
oauth_complete handler to hit the early-return `redirectToStoredPath` instead
of completing the authorization code exchange. The popup navigated to the
backoffice instead of exchanging the code and closing.
Fix: only share the session in response to sessionRequest if isSessionValid()
returns true (i.e. session.expiresAt > now).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Fix re-auth popup not opening on session timeout
Two issues:
1. When the countdown modal timer reached 0, it called onLogout() -> signOut()
which performed a full page redirect to /logout before timeoutSignal could
fire. The re-auth popup (makeAuthorizationRequest('timedOut') in
UmbAppAuthController) was never triggered. Fix: reject the modal on timer
expiry instead of calling onLogout(). The catch block in #openTimeoutModal
then calls #tryValidateToken(); if the refresh token is still valid the
session is silently renewed, otherwise timeOut() fires -> timeoutSignal ->
re-auth popup opens.
2. Only the Web Lock leader tab was showing the timeout countdown modal.
All tabs should show the warning so the user can respond from any active
tab. Remove the lock-leader election logic — show the modal on every tab.
When any tab successfully refreshes (Continue button or silent refresh), the
session$ observer fires in all tabs, closing the modal everywhere.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Show re-auth popup when timeout countdown expires
When the countdown reaches zero the user was away and the session has
effectively expired — silently refreshing is the wrong behaviour. Instead:
- Add onExpired callback to UmbModalAuthTimeoutConfig, called (instead of
onLogout) when the countdown hits 0.
- The controller sets onExpired -> timeOut(), which clears the session and
fires timeoutSignal. UmbAppAuthController picks this up and calls
makeAuthorizationRequest('timedOut'), opening the re-auth popup so the
user can sign back in without losing their work.
- The modal uses submit() (not reject()) on expiry so the catch block's
tryValidateToken() is not triggered.
- The Logout button still calls signOut() as before.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Close re-auth modal on other tabs when session is restored
When all tabs showed the re-auth modal and the user signed in on one tab,
the authorized BroadcastChannel message updated every other tab's auth
context but nothing triggered the modal to close on those tabs.
Fix: observe isAuthorized in UmbAppAuthModalElement. When it becomes true
(either from local sign-in or from another tab's BroadcastChannel message),
call #onSuccess() to submit and close the modal.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* chore: adds null guard
* docs: updates CLAUDE.md to let it know that there is a circular check call
* fix: fixes issue where the popup window could redirect to and show the full backoffice inside
* fix: ensures that the timeout modal is not shown until the buffer window is reached and extend the buffer window in case of short timeouts, and use the full expiresAt value for timeout but only the accessTokenExpiresAt for refresh of token
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Append leading / to AliasUrlProvider URLs only if it doesn't already have one
* Add unit tests for AliasUrlProvider.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fixed issue with GetAll on MemberService where skip/take weren't translated to pageIndex/pageSize.
* fix(core): fix paging in MemberService.GetAll skip/take overload
The skip/take overload was passing skip and take directly as pageIndex
and pageSize to the repository, causing incorrect pagination for any
non-zero skip value. Use PaginationHelper.ConvertSkipTakeToPaging to
correctly convert skip/take to page index/size, matching the pattern
used by all other services.
Also update ContentTypeIndexingNotificationHandler to call the
pageIndex/pageSize overload directly, avoiding the redundant conversion.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Treat empty or whitespace filter as no filter in MemberService.GetAll
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* feat: adds new SiteName setting to cookie options to use as a postfix for oauth cookies
* fix: adds configured postfix to oauth cookies to make them work on multiple sites on same domain (fixes regression)
* fix: addresses an issue where the AuthCookieName option was not respected for the _EXPOSED auth cookie
* Update src/Umbraco.Core/Configuration/Models/BackOfficeTokenCookieSettings.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Moved the "exposed" cookie config to IConfigureNamedOptions
* Add missing constants
* Add unit tests to prove the site postfix
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Backoffice: Fix circular dependencies introduced by PRs #21830 and #21846
Two circular dependency chains were created by the combination of recent
auth rewrites and the auth modal split:
1. `resources ↔ auth`: api-interceptor.controller imported UMB_AUTH_CONTEXT
from auth, while auth.context imported UmbApiInterceptorController from
resources.
2. `server → resources → auth → server`: umb-auth-view.element imported
UMB_SERVER_CONTEXT from the server package, and was reachable from
auth/index.ts via the components barrel added in #21846.
Fix for circular 1: Introduce UmbAuthSignalerContext in resources — a
lightweight bridge context with isAuthorized and requestTimeout(). The
interceptor creates it and owns it directly; auth context consumes it via
consumeContext to bridge its own authorization state and react to timeout
signals. Resources now has zero knowledge of the auth package.
Fix for circular 2: Remove umb-auth-view.element from auth/components/index.ts.
The modal already imports it directly within the package; app-auth.element
uses it as a custom element tag string with no class import needed.
Also updates MAX_CIRCULAR_DEPENDENCIES from 1 → 0 since both known cycles
are now resolved.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Backoffice: Fix circular dependencies - part 2
- Remove auth dependency from server.context.ts: replace eager constructor
side-effect (consumeContext + HTTP fetch) with lazy defer()-based observable
using a backing field flag; fetch only happens on first subscription to
isProductionMode
- Re-add umb-auth-view.element.ts to auth/components barrel (now safe since
server no longer imports from auth)
- Ensure umb-auth-view is registered on the /logout route by adding a
side-effect import in app-auth.element.ts
- Fix JSDoc in auth-signaler.context.ts and api-interceptor.controller.ts to
correctly describe ownership and direction
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Make cookie renewal conditional to fix AllowConcurrentLogins enforcement.
* Reduce SecurityStampValidatorOptions validation interval for users to zero.
* Apply member security stamp options.
* Addressed code review feedback.
* Add separate settings for AllowConcurrentLogins for members and users.
* Clarify comment.
* Further unit tests as suggested by code review.
---------
Co-authored-by: mole <nikolajlauridsen@protonmail.ch>
* Move unattended migrations to a background service, allowing liveness checks to recognise the application as healthy but not yet ready to serve requests.
* Add maintenance protection to surface controllers.
* Add protection for delivery API in upgrading state.
* Add protection for management API in upgrading state.
* Skip dynamic route transformer during Upgrading state (ensures surface controllers with attribute routing are handled in the upgrading state).
* Fix regression in attended upgrade state.
* Addressed code review feedback.
* Tidied up comments.
* Scope readiness health check predicate to Umbraco's own check.
* Fixed failing integration test.
* Removed TestCase from test with only a single case.
* Fix localization for "backoffice"
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* Removed UpgradeFailed from OpenApi.json and client-side types.
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* fix(media): ensure sequential creation in media drag-and-drop
When multiple folders are dragged into the Media section, the creation
handlers (#handleFile/#handleFolder) were not awaited in the batch loop.
This caused child items to attempt server operations before their parent
folders were fully created, resulting in 404 errors for subsequent items.
Adding await ensures each item is fully created before the next is
processed, which is required because child items in the flat list
reference parent folder IDs that must exist on the server.
Closes#21837
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Task: Bump @umbraco-ui/uui to 1.17.2
Includes the fix for multi-folder drop DataTransfer staleness
(umbraco/Umbraco.UI#1339).
* qa(dropzone): add unit tests for UmbDropzoneManager folder flattening order
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Protect endpoint that sets user groups for a user collection to prevent elevation of permissions for users.
* Update tests from code review feedback.
* Add alias property to collection config interface
Introduced an 'alias' property to the UmbCollectionItemPickerModalCollectionConfig interface
* render collection element when modal is configured with an alias
* expose a picker modal route
* use collection in use picker
* adjust spacing
* add config option for selectOnly
* dynamic modal alias
* support selectable entity item ref
* wip entity data picker collection + ref and card views
* Add entity collection item card extension type + default elements
* implement user collection item card
* fix selection events
* map to prop
* add prop/attr for href
* add support for which detail properties to show
* update type import
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/item/entity-collection-item-card/entity-collection-item-card.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* import card in correct file
* Fix event listener binding for selection events
* implement disabled property for collection item cards
* init commit of collection item ref extension
* fix imports
* add element interface
* Implement UmbEntityCollectionItemElement interface in item cards
Added the UmbEntityCollectionItemElement interface to document and user collection item card elements for improved type safety and consistency. Updated type exports to include the new interface.
* Update collection item ref to use uui-ref-node
Replaces the placeholder div with a uui-ref-node component, passing relevant item properties and event handlers. Adds dynamic icon rendering using umb-icon.
* Refactor entity collection item elements to use shared base
Introduces a new abstract base class for entity collection item elements, consolidating shared logic for card and ref variants. Updates card and ref element implementations to extend the new base, and refactors extension manifest interfaces for consistency. This improves maintainability and reduces code duplication.
* use class instead of magic string
* Use entity collection item card in picker view
Replaces the placeholder card markup with the <umb-entity-collection-item-card> component, enabling selection and deselection functionality for items in the entity data picker card collection view.
* Update entity item ref to collection item ref
Replaces <umb-entity-item-ref> with <umb-entity-collection-item-ref> in the picker collection view. Adjusts event handlers and select-only logic to improve selection behavior and component consistency.
* utilise ref and card kind for picker views
* introduce ref and card collection view kinds
* Utilise card kind for user collection view
* Add item-specific href support to collection views
Introduces a requestItemHref method to collection contexts for retrieving item-specific hrefs. Updates card, ref, and user table collection views to use these hrefs, enabling dynamic linking for collection items. Refactors user table name column layout to accept href via value prop instead of constructing it internally.
* Update ManifestCollectionView import path
Changed the import of ManifestCollectionView from '../extensions/types.js' to '../view/types.js' to reflect its new location.
* remove unused
* use size medium for entity collection item picker
* use box
* render entity actions
* use edit path builder for user links
* rename method
* Revert "rename method"
This reverts commit 4df577688e.
* Update collection-default.context.ts
* make type lint ignore unused args with an underscore
* temp remove unused
* only make collection vie selectable if there are any registered bulk actions
* don't render name link if there is no href
* fix imports
* Render selection actions only if bulk actions exist
* use selectable state
* Update language-table-collection-view.element.ts
* Update language-table-collection-view.element.ts
* Update card-collection-view.element.ts
* clean up
* Refactor collection views to use shared base class
* refactor(collection): parallelize href fetching and make method private
* docs(examples): update collection example to use card and ref kinds
* docs(examples): add icon property to collection example data model
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/types.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update collection-bulk-action.manager.test.ts
* Removed duplicate and redundant '@typescript-eslint/no-unused-vars' rule definitions, consolidating the configuration to use only 'argsIgnorePattern'.
* Handle missing user href in name column layout
Replaces the user name link with a span when the href property is not provided, preventing broken links in the user table name column layout.
* Update user-table-name-column-layout.element.ts
* pass modal data and value to routable modal
* Update picker-input.context.ts
* support selectableFilter
* scaffolding of a collection text filter extension
* Refactor collection text filter to use API interface
* Fix incorrect tag
* Update types.ts
* Update collection-text-filter.extension.ts
* Add cancelation to debounced search on destroy
* clean up
* add js docs
* two way binding of filter value
* clean up
* Add collection text filter manifest example
Introduced a new filter manifest for the example collection and updated the main manifests file to include it. This enables a text filter extension for the example collection.
* Delete unused element and context
* Update src/Umbraco.Web.UI.Client/src/packages/user/user-group/collection/user-group-collection.context-token.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update user-group-table-collection-view.element.ts
* support search for tree item and collection item pickers
* add spacing between collection ref items
* add margin between picker search result items
* remove spacing after last item
* remove padding in search results
* Update collection-item-picker-modal.element.ts
* move select only logic to collection selection manager
* add tests for collection selection manager
* change to filter label instead of search
* delete unused user grid collection view
* Select-only mode is now only disabled when all items are deselected, rather than on every deselection.
* prepare umb table for pickers
* utilize UmbCollectionViewElementBase in user table collection view
* remove console log
* handle select all and select item from same event
* bulk actions workaround
* add bulk action in collections feature toggle
* remove unused method
* make fields optional to avoid a breaking change
* remove unused import
* fix typescript errors
* adjust search styling
* hide with css
* fix ts errors
* Add modal data support to picker input context
Introduces methods to set and get modal data in UmbPickerInputContext, allowing base configuration for picker modals. Updates modal data handling to merge stored modal data with provided data for both direct picker opening and modal route setup.
* Fix bulk action manager test initialization
Added calls to setConfig in tests to properly initialize the observer before subscribing to hasBulkActions. Simplified the test logic for checking emissions when actions are present.
* Update tree-picker-modal.element.ts
* Update picker-search-result.element.ts
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/umb-collection-view-element-base.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Use ifDefined for modal route in user input button
* Use ifDefined for href binding in entity data picker
* Fix collection alias binding in item picker modal
* wire up user table collection view with selectableFilter
* clean up controller aliases
* Update collection-item-picker-modal.element.ts
* Update collection-item-picker-modal.element.ts
* Add support for collection items with thumbnails
Introduces thumbnail support for collection items by extending models and updating the default collection item card to render thumbnails when available. Adds a new example data source and manifest for items with thumbnails, and updates grid styling for card views.
* Improve card grid responsiveness and card sizing
Added a new CSS variable for large card min-width and updated the card grid to use container queries for responsive column sizing. Adjusted user card styles to ensure proper sizing and layout within the grid.
* add example image to thumbnail example
* introduce generic card component
* wip picker views configuration
* Update manifests.ts
* store value as alias
* Improve handling of missing collection view manifests
Refactors manifest storage to use a Map for faster lookup by alias and updates rendering logic to handle missing manifests gracefully. Now displays a 'not found' message with a remove button for missing collection view manifests.
* add sorting
* rename
* Add confirmation modal before removing picker view
* remove unused
* move collection selectOnly logic to context
* Update user-picker-modal.token.ts
* Add data-source package and integrate in input-entity-data
* Add optional description to collection items
* introduce extension picker data source
* fix problem with shallow copy because of js module in object
* nest manifest data
* Hide pagination when all items are shown
* Add a fallback page size
* merge extension insight code with extension code
* clean up
* Add optional description support to default item ref
* Revert "Add data-source package and integrate in input-entity-data"
This reverts commit e02881e8b6.
* fix post merge
* add input-extension utilizing input-entity-data
* proxy value and selection
* add todo
* temp hardcode config
* add typed config model
* Support multiple extension types in filters
* Use extensionTypes filter and deprecate type
Standardize extension collection filtering by introducing extensionTypes and phasing out the old type field.
* More explicit type name
* Expose allowedExtensionTypes as a @property on UmbInputExtensionElement
* Add text filter support for entity data picker
* remove reexport as this is not public available
* remove unused
* clean up
* clean up
* Add storage and getter for allowedExtensionTypes
* Inline collection view alias and remove constant
* Update vite.config.ts
* Update manifests.ts
* Update extension.picker-data-source.ts
* add tests for extension picker data source
* change to an observable feature config
* make feature object optional
* add unit tests
* Reference condition class directly in manifests
* Simplify collection view types and refactor setup
* remove todo
* implement input-extension on picker views configuration
* Add collection view aliases and defaults
* use correct type
* make name optional
* remove debugger
* delete - merge gone wrong. They are now called figure-cards
* map views to layouts
* Add viewsOverride to enforce collection layout order
* clean up observers if data source type changes
* remove unused
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Auth: Split auth modal into reusable view and thin modal wrapper
Extract the full login screen UI from umb-app-auth-modal.element.ts into
a standalone umb-auth-view.element.ts that extends UmbLitElement. The
modal becomes a thin wrapper that delegates rendering to the view and
bridges onSuccess to _submitModal().
The view defaults userLoginState to 'loggedOut', so the /logout route
renders it directly as a component without needing to cast or configure
properties.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix imports and add readonly to styles in umb-auth-view
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: import directly from main app itself to avoid dynamic imports
* Auth: Reopen timeout modal on dismiss and fix login layout height
Reopen the auth modal in a loop when the session has timed out, so
the user cannot dismiss it without re-authenticating. Fix login
layout height from calc(100vh - 64px) to 100vh with box-sizing.
Height fix credit: Lan Nguyen (PR #19843, closes#19628)
Co-Authored-By: Lan Nguyen <lan@umbraco.dk>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix timeout modal reopen by removing explicit modal key
The do/while loop to reopen the modal on dismiss was failing because
reusing the same key caused a race condition in the modal manager —
appendToFrozenArray replaced the old entry but the container's
_modalElementMap still held the stale key, preventing creation of
the new modal element. Letting each open() generate a unique key
via UmbId.new() avoids the collision entirely.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Prevent auth modal from being dismissed via ESC
Add UmbPersistentModalDialogElement that extends UUIModalDialogElement
and intercepts ESC keydown to prevent the native dialog cancel behavior.
The auth modal now always uses this element via type: 'custom', ensuring
users must complete authentication rather than dismissing the modal.
Also simplifies #showLoginModal by using umbOpenModal() and removing
the do/while reopen loop which is no longer needed.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore: renames file and adds appropriate exports
* Auth: Use AbortController for listener cleanup and add cancel handler
Use AbortController to manage event listeners, preventing accumulation
if _openModal is called multiple times. Add cancel event handler
alongside keydown as a fallback for the native dialog cancel behavior.
Clean up listeners on forceClose.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Lan Nguyen <lan@umbraco.dk>
* Auth: Add minimal PKCE client to replace appauth library (closes#20873)
Introduces UmbAuthClient — a focused OAuth PKCE client that replaces the
forked @openid/appauth library. Uses Web Crypto API for code_challenge
generation and fetch() with credentials:'include' for cookie-based auth.
Zero localStorage usage — PKCE state held in memory.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Rewrite auth context with BroadcastChannel and Web Locks
Merges UmbAuthFlow into UmbAuthContext (single consumer, no export).
Replaces localStorage token storage with in-memory session state.
- BroadcastChannel('umb:auth') for cross-tab auth event coordination
- Web Locks API prevents concurrent refresh token race conditions
- postMessage for popup PKCE code_verifier exchange
- sessionStorage for redirect-flow PKCE state (tab-scoped)
- Adds configureClient() for extension developer DX
- Deprecates authorizationSignal (scheduled for removal in Umbraco 19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Update session timeout controller and SharedWorker
Session timeout controller simplified to take only UmbAuthContext (no
separate authFlow parameter). Observes session$ for timing updates.
SharedWorker now accepts expiresAt timestamp instead of full
TokenResponse. Removes TokenResponse import and TOKEN_EXPIRY_MULTIPLIER.
Sends current session state to new tab connections. Cleans up stale
ports via try/catch on postMessage.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Simplify OAuth completion flow and API interceptor
app.element.ts: Remove authorizationSignal wait pattern —
completeAuthorizationRequest() now handles everything. Remove
umbHttpClient.setConfig() call (moved to auth context constructor).
api-interceptor.controller.ts: Replace deprecated authorizationSignal
observer with isAuthorized transition for retrying 401 requests.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Deprecate external/openid package and storage constant
Delete all 17 appauth implementation files. Replace index.ts with
deprecated type-only stubs for backwards compatibility — external
consumers can still reference types through v18.
Mark UMB_STORAGE_TOKEN_RESPONSE_NAME as deprecated (scheduled for
removal in Umbraco 19).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Update auth context tests for new implementation
Rewrite tests to cover the new auth context API surface including
configureClient(), getOpenApiConfiguration(), URL generation, lifecycle
management, and bypass auth mode.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Update extension template to use configureClient() API
Replace manual getOpenApiConfiguration() pattern with the new
configureClient() method on UmbAuthContext — single line to configure
any @hey-api/openapi-ts client for authenticated Management API calls.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix token refresh not firing and adaptive worker timing
Two bugs fixed:
1. makeRefreshTokenRequest() checked expiresAt > now which always
returned true when the worker fired proactively (before session
expiry). Changed to compare session reference before/after acquiring
the Web Lock — only skips if another tab actually refreshed.
2. getLatestToken() checked the full session expiresAt (with 4x
multiplier) instead of the access token expiry. Split UmbAuthSession
into accessTokenExpiresAt and expiresAt so each check uses the
correct threshold.
Also made the worker's buffer and check interval adaptive for short
sessions (< 2 minutes) — buffer is reduced to 25% of session lifetime
and check interval scales proportionally. Fixes the long-standing issue
where very low timeouts caused the buffer to exceed the session.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Propagate sign-out to all tabs via BroadcastChannel
When a user signs out in one tab, broadcast a 'signedOut' message so
other tabs redirect to the logout page. Previously, other tabs only
cleared their in-memory session but continued showing stale data.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Route setInitialState through Web Lock to prevent duplicate refreshes
setInitialState() was calling refreshToken() directly, bypassing the
Web Lock. Concurrent API calls (via getLatestToken) also triggered
refresh through the lock. This caused duplicate /token calls — one
outside the lock, one inside — leading to rolling refresh token
invalidation races.
Now setInitialState() goes through makeRefreshTokenRequest() so all
refresh calls are serialized by the same Web Lock.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Close timeout modal when another tab refreshes the session
When the session$ observable emits a new session (e.g. from a
BroadcastChannel update after another tab refreshed), close any open
timeout modal. Previously the modal stayed open with its own countdown,
eventually triggering a spurious logout even though the session was
already extended.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Replace SharedWorker with setTimeout and leader-elected modal
Four improvements from a fresh design review:
1. Remove SharedWorker — replaced with a simple setTimeout in the
timeout controller. A 15-60s timer is negligible on the main thread,
and the focused tab's timer is never throttled by browsers.
2. Leader-elected timeout modal — uses Web Lock (ifAvailable) so only
one tab shows the timeout modal. Non-leader tabs set a fallback
timeout. When the leader tab resolves the modal, BroadcastChannel
propagates the result and session$ observer closes stale modals.
3. Peer session request — new tabs ask existing tabs for their session
via BroadcastChannel before attempting a server refresh. Avoids the
400 error on fresh sessions and eliminates unnecessary /token calls
for new tabs in an existing session.
4. Single expiry concept — no more refreshToken vs logout distinction
from the worker. The controller checks remaining time and decides
based on keepUserLoggedIn and whether time has fully expired.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix timeout modal not showing during buffer zone
The #onSessionExpiring guard used isSessionValid() which returns true
during the warning buffer (before full expiry), preventing the modal
from ever appearing. Replace with expiresAt comparison that only skips
if the session was actually refreshed since the check was scheduled.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Set auth header at module level to eliminate timing gap
Move `auth: () => '[redacted]'` into the http-client module-level
config so it's available from first import. Previously, extensions
importing umbHttpClient before UmbAuthContext initialized would send
cookies but not the Authorization header needed by
HideBackOfficeTokensHandler, causing 401s.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Bind default interceptors via configureClient()
configureClient() now creates an UmbApiInterceptorController and binds
the default response interceptors (401 retry, error handling,
notifications) alongside auth config. app.element.ts uses this for
umbHttpClient, giving extensions the same middleware pipeline.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix review findings — stale state, double-broadcast, PKCE cleanup
- clearTokenStorage: also set isAuthorized=false on originating tab
- signOut: inline state clearing to avoid double-broadcasting
sessionCleared + signedOut; fix dead URL base arg; use
window.location.origin consistently
- makeRefreshTokenRequest: compare accessTokenExpiresAt values instead
of object identity for robustness
- completeAuthorizationRequest: only remove sessionStorage PKCE entry
when state matches (preserve valid entry on mismatch)
- umb-auth-client: warn when expires_in is missing or zero
- configureClient: guard against duplicate calls with WeakSet
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(auth): resolve lint errors and Copilot review issues
- Add eslint-disable blocks around OAuth wire-format URLSearchParams keys
(client_id, redirect_uri, grant_type, etc.) — these must use snake_case
per RFC 6749/7636 and cannot be renamed
- Fix optional chaining gap in #openTimeoutModal: store modal ref before
awaiting so modal?.onSubmit() is safe when modalManager is undefined
- Fix popup Promise never settling: poll for authWindowProxy.closed and
resolve (cleanup) when the user closes or cancels the login popup
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Auth: Deprecate getLatestToken() — always returns '[redacted]' with cookie auth
With cookie-based auth, getLatestToken() always returns '[redacted]'.
The proactive token refresh it performed is no longer needed since:
- The session timeout controller refreshes proactively via setTimeout
- The API interceptor retries 401s automatically
Internal callers (linkLogin, unlinkLogin, server-event, tryXhrRequest)
now use '[redacted]' directly. getOpenApiConfiguration() is kept as the
recommended API for manual fetch calls.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* docs: adds links to deprecations
* docs: adds deprecation notices
* Auth: Deprecate getLatestToken(), clarify openid stub behavior
- Mark getLatestToken() as deprecated (always returns '[redacted]' with
cookie auth). Points to configureClient() and getOpenApiConfiguration().
- Inline '[redacted]' in internal callers (linkLogin, unlinkLogin,
server-event, tryXhrRequest) instead of going through getLatestToken().
- Update getOpenApiConfiguration().token to return '[redacted]' directly.
- Clarify external/openid deprecation header: data classes remain
functional, handler classes reject because the operations are no
longer possible with cookie-based auth.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: overrides options after applying defaults
* Auth: Supply keepUserLoggedIn from backend via HTML attribute
Instead of fetching keepUserLoggedIn asynchronously from the Management
API after authorization, the server now renders it as a boolean attribute
on <umb-app> from SecuritySettings. This eliminates the timing gap where
the access token could expire before the async preference was fetched,
causing 401s on API calls.
Chain: Index.cshtml → <umb-app keep-user-logged-in> → UmbAuthContext →
UmbAuthSessionTimeoutController. When true, the timeout controller
schedules based on accessTokenExpiresAt (proactive refresh) instead of
expiresAt (full session expiry).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix review findings — message storm, PKCE state, spread order
- Fix BroadcastChannel message storm: completeAuthorizationRequest
was calling #updateSession (which broadcasts sessionUpdate) AND
separately broadcasting 'authorized'. Other tabs receiving 'authorized'
called #updateSession again, cascading N² messages. Split into
#setSessionLocally (no broadcast) and #updateSession (broadcasts).
- Increase PKCE state from 10 to 32 characters for stronger CSRF nonce
(was ~59 bits, now ~190 bits of entropy).
- Fix tryXhrRequest spread order: ...options was last, allowing callers
to accidentally override baseUrl/token. Now baseUrl/token come last.
- Remove unused endSessionEndpoint from UmbAuthClientEndpoints interface
(signOut URL is constructed directly in auth.context.ts).
- Export UmbAuthSession interface for extension developers observing
session$.
- Add clarifying comments for: anonymous UmbApiInterceptorController in
configureClient, refresh_token server contract, Web Lock deduplication
edge case.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Fix review findings — redirect loop, popup leak, navigator.locks fallback
- Fix redirect loop after code exchange by using force=true navigation
so setInitialState() runs with fresh httpOnly cookies
- Clean up pending popup flows before starting new ones (prevents
pkceHandler/closedPoll leaks)
- Add navigator.locks fallback for environments without Web Locks
- Clear session on timeOut() to prevent stale in-memory state
- Make AuthorizationError constructor params optional (compat fix)
- Remove dead #previousAuthUrl field
- Add clarifying comments on configureClient and peer session timeout
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: Wait for both auth and server contexts before initializing SignalR hub
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Use ifAvailable lock to prevent redundant token refresh across tabs
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Add default Authorization header to umbHttpClient
The hey-api `auth` callback is only invoked when requests include
`security` metadata (which generated SDK functions do automatically).
Direct `.get()`/`.post()` calls lack this metadata, so the
Authorization header was silently omitted. Adding it as a default
header ensures all requests through umbHttpClient trigger the
server-side HideBackOfficeTokensHandler cookie swap.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Auth: Use exclusive lock with freshness check for token refresh
Replaces ifAvailable lock with an exclusive lock that queues tabs.
After acquiring the lock, isSessionValid() checks whether another tab
already refreshed — preventing sequential /token calls when timers
fire slightly offset.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(web): configure umbHttpClient baseUrl before server connection
Move auth context creation and configureClient() before
UmbServerConnection.connect() so that the generated SDK calls
(ServerService.getServerStatus/getServerConfiguration) have a
valid baseUrl on umbHttpClient.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(auth): use object reference comparison in token refresh lock
The isSessionValid() check inside the Web Lock used expiresAt (full
session lifetime), which incorrectly skipped proactive refreshes when
keepUserLoggedIn=true. The timeout controller fires based on
accessTokenExpiresAt, but the full session was still valid at that
point, so the refresh was silently skipped — eventually causing 401s.
Fix: capture the session object reference before entering the lock
queue. Inside the lock, compare references to detect whether another
tab broadcast a sessionUpdate while we were waiting. This correctly
deduplicates multi-tab refreshes while allowing proactive refreshes
to proceed.
Also fixes prettier formatting in UmbAuthClient constructor.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: do not assume that any endpoint is authenticated or accepts an Authorization header (this should come from the OpenAPI spec)
* E2E: QA: updated acceptance tests to match the authorization changes in #21830 (#22021)
Updated tests to the updated auth
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* fix: compose user-supplied pickableFilter with internal filter in picker input contexts (#21859)
The openPicker method in UmbDocumentPickerInputContext, UmbMediaPickerInputContext,
and UmbMemberPickerInputContext unconditionally overwrites the user-supplied
pickableFilter with the internal implementation. This prevents package developers
from providing custom filtering logic (e.g., filtering out unpublished items).
The fix composes both filters using a logical AND: the internal filter runs first
(access checks, allowedContentTypes), and if it passes, the user-supplied filter
is also evaluated. This preserves the existing behavior while enabling extensibility.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: extract _composePickableFilters into base UmbPickerInputContext class
Move duplicated filter composition logic from document, media, and member
picker input contexts into a shared protected method on the parent class.
This reduces cyclomatic complexity in each openPicker override and
eliminates code duplication across the three picker contexts.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Rename picker filter helper to _combinePickableFilters
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* poc of minimizing unrelevant validation messages
* remove submit method from interface
* remove call to re-validate, as that is already trigger via `updated`--callback
* Split content type validation for create and update to allow saving elements no longer permitted in library
* Add integration test for element update after AllowedInLibrary toggle
Verify that ElementEditingService.UpdateAsync succeeds when the content
type's AllowedInLibrary flag is set to false after the element was
created, covering the split validation introduced for create vs update.
* Move content type validation into TryGetAndValidateContentType override
Eliminate redundant content type lookups in CreateAsync and UpdateAsync
by moving the IsElement/AllowedInLibrary check into the
TryGetAndValidateContentType override, which distinguishes create from
update by checking if the model is a ContentCreationModelBase.
* Use Assert.Multiple for element property assertions in update test
* Extract IsAllowedLibraryElement static method for readability
* Added api helper for creating tiptap data type with media folder
* Added ui helper for remove image upload folder
* Updated ui helper for selecting media with name
* Added tests for selecting media link in multi url picker
* Added tests for media picker start node
* Added tests for image upload folder in tiptap data type
* Updated tests for user media start nodes
* Updated tests for user group media start nodes
* Make tests run in the pipeline
* Fixed comment
* Cleaned code
* Added tests for add multiple media start nodes to a user
* Reverted npm command
* Add CSP nonce support for inline scripts
* Add UseUmbracoCspNonceInjection middleware for NWebsec integration.
* Add unit tests for InjectNonceIntoDirective method.
* Add documented CSP rules to local website so any issues that conflict with these rules are surfaced in local development and testing.
* Test formatting.
* Addressed code review feedback.
* Use tag helper for nonce rendering.
* Apply suggestions from code review
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Move CspNonceInjectionOptions into it's own file.
* Reduce clutter in Program.cs in local web project, by moving use of documented CSP to an extension method.
* Trigger build
* Exclude CSP from template but keep in local project.
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Update server-side dependencies to latest patch or minor releases.
* Revert and comment upgrade to MailKit.
* Update Microsoft.NET.Test.Sdk to latest minor.
* Migration, model and repository data access for sorting via a sortable field.
Property editor sortable interface and implementation of JSON stored date fields.
* Add migration to populate sortable field for existing date property data.
* Added unit tests for GetSortableValue on datetime property editors.
* Fixed issues raised in code review.
* Re-use code in base from DocumentRepository to avoid additional call to SetEntitySortableValues.
* Move migration to 17.3.
* Fix merge issue.
* Move around migrations so they are in correct order
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
Co-authored-by: Zeegaan <skrivdetud@gmail.com>
* Added tests for content with element picker
* Added tests for element with element picker
* Bumped version
* Renamed tests
* Make tests run in the pipeline
* Bumped version
* Fixed failing tests
* Moved goToBackOffice step to beforeEach
* Moved goToBackOffice to beforeEach
* Fixed comment
* Fixed afterEach() step
* Fixed import
* Fixed
* Reverted npm command
* Check whether picker is in a block. If so, act as with a new content node.
* re-use isNew flag to not increase complexity for the requestRoot function
* remove random whitespace added by visual studio
* remove ternary to reduce complexity
* move check to backend
* update fallback in SiteDynamicRootOriginFinder as well
* Revert "update fallback in SiteDynamicRootOriginFinder as well"
This reverts commit 0a14aa7393.
* Revert "move check to backend"
This reverts commit ca8b0c06da.
* get content workspace context - analogous to document-block-property-value-user-permission.workspace-context.ts. import interface for getIsNew().
* Use getContext.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* feat(recycle-bin): add destination entity overrides to restoreFromRecycleBin kind
Add optional destinationItemRepositoryAlias, destinationItemDataResolver,
and destinationRootEntityType properties to support cross-entity-type
restore (e.g. element restoring into element-folder). Existing document
and media manifests are unaffected as all new properties fall back to
the original values. Also adds element folder restore manifest.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor(recycle-bin): extract #resolveDestinationItemName to reduce complexity
Extract resolver logic from setDestination into a dedicated method to
bring cyclomatic complexity under the threshold of 9.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Removed Restore Element Folder From Recycle Bin Entity Action
(This is for a separate PR)
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* feat(content): add shared types and repository interface for audit log kind
Introduces UmbAuditLogTagData types, ManifestWorkspaceInfoAppAuditLogKind manifest
interface, and UmbAuditLogHistoryRepository extending the core audit log repository
with getTagStyleAndText() method.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(content): create shared audit log workspace info app element
Reusable element that receives manifest config with auditLogRepositoryAlias
and optional allowedActions. Uses UMB_ENTITY_WORKSPACE_CONTEXT for entity
unique resolution and createExtensionApiByAlias for repository lookup.
Includes reload event listener, pagination, and user avatar caching.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(content): add auditLog kind definition and manifest registration
Registers the 'auditLog' kind for 'workspaceInfoApp' extension type,
mapping to the shared element. Includes info-app and audit-log manifest
aggregators.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(documents,media): register audit log repos as extensions and add getTagStyleAndText
- Register UmbDocumentAuditLogRepository and UmbMediaAuditLogRepository as
extension manifests with type 'repository' and dedicated alias constants
- Add getTagStyleAndText() method to both repositories implementing the
UmbAuditLogHistoryRepository interface from content package
- Export audit-log types from @umbraco-cms/backoffice/content
- Deprecate getDocumentHistoryTagStyleAndText and getMediaHistoryTagStyleAndText
utility functions (scheduled for removal in Umbraco 19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(documents,media): switch audit log info apps to use shared auditLog kind
- Update document and media info-app manifests to use kind: 'auditLog'
with meta configuration (auditLogRepositoryAlias, allowedActions)
- Include repository manifests in document and media audit-log aggregators
- Wire audit-log kind manifests into the content package
- Deprecate UmbDocumentHistoryWorkspaceInfoAppElement and
UmbMediaHistoryWorkspaceInfoAppElement (scheduled for removal in Umbraco 19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(documents,media): add `api` exports to audit log repositories
Required for the extension registry API loader pattern which expects
either a default or named 'api' export from the module.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Linting
* refactor(content): extract renderHistoryItem to reduce cyclomatic complexity
Splits the repeat callback out of #renderHistory into a dedicated
#renderHistoryItem method, reducing the method's cyclomatic complexity
below the threshold of 9.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(content): throw error when workspace entity unique is missing
Restores fail-fast behavior for missing entity unique in audit log
requests, matching the original document/media implementations.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor(audit-log): move getTagStyleAndText to UmbAuditLogRepository as optional method
Removes UmbAuditLogHistoryRepository interface and adds optional
getTagStyleAndText() to UmbAuditLogRepository in core. Moves tag
types to core/audit-log and adds a default type parameter.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(audit-log): export repository alias constants from package entry points
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Linting and tidy-up
* Fixes canceled Rollback modal error
* Removed the `allowedActions` property
* feat(content): formalize `auditLogAction` extension type
Add proper TypeScript interfaces, default kind, and dedicated element
for the `auditLogAction` extension type, replacing the previous
untyped usage that relied on `ManifestEntityAction`.
- Define `ManifestAuditLogAction` and `MetaAuditLogAction` interfaces
- Create `umb-audit-log-action` element using `uui-button` (suited for
the audit log info-app header, unlike `uui-menu-item`)
- Register default and contentRollback kind manifests
- Move contentRollback audit-log-action kind to the content module
- Separate document-specific audit-log-action manifest into its own file
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* fix(media): allow focal point to be set to null in image cropper
- Updated UmbImageCropperPropertyEditorValue type to allow null for focalPoint
- Changed component state to use null as default instead of { left: 0.5, top: 0.5 }
- Replaced logical OR (||) with nullish coalescing (??) to preserve null values
- Updated reset function to set focalPoint to null
- Added null handling in all rendering and calculation logic
- Components now default to center (0.5, 0.5) for display when focalPoint is null
Fixes#21273
* refactor(media): extract logic from initializeCrop to reduce function size
- Extracted mask dimension calculation into #calculateMaskDimensions
- Extracted mask style application into #applyMaskStyles
- Extracted image scale calculation into #calculateImageScales
- Extracted image position calculation into separate methods:
- #calculateImagePositionWithCoordinates (for existing crops)
- #calculateImagePositionWithFocalPoint (for focal point positioning)
- Extracted image style application into #applyImageStyles
- Extracted zoom level update into #updateZoomLevel
Reduces #initializeCrop from 72 lines to 33 lines, meeting CI/CD threshold of 70 lines.
Related to #21273
* refactor(media): replace primitive parameters with interfaces to fix code quality warnings
- Created ViewportDimensions interface to group viewport width/height
- Created MaskDimensions interface to group mask dimensions and position
- Created ImageDimensions interface to group image dimensions and position
- Refactored all functions to use interface objects instead of multiple primitives
- Reduced #calculateImageDimensionsAndPosition from 5 args to 2
- Reduced #calculateImagePositionWithCoordinates from 5 args to 2
- Reduced #calculateImagePositionWithFocalPoint from 4 args to 1
Fixes primitive obsession (85.7% -> reduced) and excessive function arguments warnings.
Related to #21273
* fix(media): update modal value interface to allow null focal point
- Updated UmbImageCropperEditorModalValue interface to allow null for focalPoint
- Added explicit null handling when assigning focalPoint in onChange handler
Fixes TypeScript build error where null focalPoint was not assignable to non-nullable type.
Related to #21273
* Refactor image cropper focal-point handling
* Set defaultFocalPoint to null in test file.
* Default focalPoint to null and adjust checks.
---------
Co-authored-by: Francluob <francluob.dev@gmail.com>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
Co-authored-by: engjlr <enl@umbraco.dk>
* Dispose event listener created in InMemoryAssemblyLoadContextManager.
* Use using to dispose ICryptoTransform in MemberPasswordHasher.
* Dispose CancellationTokenSource in DatabaseServerMessenger.
* Dispose deserialized JsonDocument in CacheInstructionService.
* Use try/finally to ensure dispose.
* quote table, column and alias names with SqlSyntaxProvider methods in raw sql
* refactoring private methods into new file as internal methods,
refactor new extensions into another file
* refactor GetAlias method
* Double check the change
* improve code health
* change new static classes into public static partial class NPocoSqlExtensions
* resolve some Copilot review suggestions
* revert Copilot suggestion because it decreases code health
* revert test
* compare in with LOWER, change two methods from private to protected in UmbracoDatabaseFactory
* revert Query.cs in this PR
* Refactor for code health and fixing raw sql
* divers small issues fixed
* refactor two methods to respect the DRY pricipal
* update IQuery interface
* clean up
* revert refactoring for CodeScene
* delete obsolete Test
* rename method
* remove new methods and updates, which are not relevat for this PR
* prepare for additional states in the future
* don't mix string building methods
* fix SQL injection danger
* fix test for reverted methods
* another SqlSyntax issue
* fix update
* fix reverted changes
* restore change for this PR
* restore change for this PR
* fix merge bug
* update formating
* extend ISqlSytax for database independent autoIkrement feature
* fix DTOs, extend ISqlSyntax
* fix tests
* revert
* updates
* diverse SqlSyntax and NPoco related updates for custom databse providers
* fix names
* squash merge v173/20453-DTO-attributes-fixed into v173/20453-final-sql-syntax-fixes
* merge
* add default implementation to interface
* fix tests
* fix PrimaryKey for multi columns
* test fix
* Resolve the issues with SqlSyntaxProvider for SQLite. If executed correctly, a single test would reveal the problem.
* add another test
* revert changes which causes even more issues
* fix SQL syntax
* fix column const naming
* ensure column const names from v17.2
* add comment for change
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeTemplateDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* resolve review comments
* Make ReferenceMemberName consistent across all DTOs (use constants defined on the referenced DTO).
* Ensure [ExplicitColumns] attribute exists on all DTOs.
* Ensure we consistently use PrimaryKeyColumnName over PrimaryKeyName.
* Fix further inconsistency to use only TemplateNodeIdColumnName.
* Fixed trailing whitespace.
* Restored primary key constraint name on ContentVersionCleanupPolicyDto (it doesn't seem in scope of PR to remove this).
* Removed the confusing PrimaryKeyColumnName constants for multi-column primary key DTOs where the constant refers to only one of the key columns.
* ReferenceMemberName needs to be a C# property name, so it's safer to use nameof.
* Comment fix.
* Amended accessibility modifiers.
* revert unnecessary changes
* revert unnecessary changes
* revert unnecessary changes
* fix SQLite escape variants
* fix typo
* simple (typo) fixes of Copilot review comments
* solve another Copilot review comment
* improve comments and minimise changes
* add an detailed change comment
* resolve review and revert all integration test. Tests changes will be done in the PostgreSqlProvider-npocp branch like some unit tests.
* remove InsertWithSpecialAutoIncrement()
* update WhereIn() for case sensitive databases
* fix special char in test comment
* throw exception for invalid values
* remove values type check
* add extra check
* resolve review comments
* revert more changes with question
* refine method SiblingsSql of EntityRepository, add another AndSelect() method overload to NPocoSqlExtensions.
* resolve review
* fix replacement
* trigger new pipeline build
* trigger new pipeline build
* Added comment explaining why withAlias: false is needed.
* Add additional tests around sibling retrieval.
* Add tests for the AndSelect overloads.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Content Rollback: Abstract document rollback into reusable entity action and modal kinds
Create shared `rollback` entity action kind and modal kind in the content package,
enabling reuse for upcoming entity types (e.g., Elements in v18). The document
rollback now uses these kinds via manifest meta, while old APIs are preserved
with @deprecated annotations for backward compatibility.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Content Rollback: Address PR review feedback
- Add validation for manifest meta in rollback modal element, throwing
descriptive errors if rollbackRepositoryAlias or detailRepositoryAlias
are not configured
- Remove non-null assertions in favor of validated manifest access
- Fix deprecated requestVersionByDocumentId to delegate through the
generic requestVersionById interface method
- Remove unused requestVersionByDocumentId deprecated method (original
method was requestVersionById, not requestVersionByDocumentId)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Renamed "rollback" to "contentRollback"
for class names and manifest kind.
* Content Rollback: Move repo aliases to entity action meta; remove modal kind
Move rollbackRepositoryAlias and detailRepositoryAlias from the modal
kind manifest meta to the entity action meta, passing them as modal
data. Remove the contentRollback modal kind entirely and register the
modal element directly. Introduce UMB_CONTENT_ROLLBACK_MODAL token so
the entity action no longer needs a configurable rollbackModalAlias.
Deprecate document-level modal constants in favor of content-level ones.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fixed linting errors
* eslint missed an export! 🤦
* refactor(backoffice): rename UMB_ENTITY_ACTION_ROLLBACK_KIND_MANIFEST to UMB_ENTITY_ACTION_CONTENT_ROLLBACK_KIND_MANIFEST
Address PR review feedback to include "Content" in the manifest constant name for consistency.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Create item endpoints that return ancestor IDs for a given collection of entity IDs.
* Return item models instead of just IDs.
* Use async methods.
* Use NamedItemResponseModel for container ancestor endpoints.
* Simplify the usage of ItemAncestorService - use less assumptions about structure and use generic mapping for basic response models.
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Optimize (memory usage, database storage, and processing time) document URL and alias cache for invariant documents.
Store invariant content with NULL languageId instead of duplicating records for each language.
* Additional integration tests verifying aspects of changed functionality.
* Implement and test that URLs and aliases are updated when a content type changes from variant to invariant or vice versa.
* Tidied up migration.
* Corrected file name.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Further updates from code review, resolved warnings.
* Use rebuild key defined in constant in migration.
* Handle possibility of custom URL providers generating different URL segments per culture.
* Resolve breaking change.
* Handling breaking change in DocumentUrlDto.
* Tidied up code comments
* Fix issue where URL aliases on variant content with a shared property were not being recorded.
* Tidy up comment.
* Fix breaking change in nullability.
* Fix breaking change in nullability (2).
* Revert "Fix breaking change in nullability (2)."
This reverts commit c77a37c855.
* Fix failing integration tests.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Updated ui helper for verify the file uploads
* Updated tests due to test helper changes
* Updated tests for block due to UI changes
* Added comment for the failing tests
* Added preview helper
* Added preview helpers
* Added preview tests
* Updates based on comments
* reinitialize the preview locators for the pop up preview page
* Cleaned up based on comments
* Update smokeTest command in package.json
* Added tests for element reference tracking in info tab
* Removed tags
* Make all ElementReferenceTracking tests run in the pipeline
* Moved goToBackOffice step to beforeEach
* Updated import file
* Make tests run in the pipeline before merging
* Fixed npm command
* Revert npm command
* Make local and global elements behave the same (use the same implementation)
* Await async calls, don't fire-and-forget
* Fix the remaining unit tests
* Flush static fields on friendly published extensions before starting tests
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* fix(core,api,web): fix backoffice UI errors on notification cancellation
- Fix ContentTypeServiceBase.DeleteAsync() to use PublishCancelableAsync
directly instead of delegating to the sync Delete() method, which
silently swallowed cancellation and always returned Success.
- Extract shared deletion logic into private PerformDelete() method
to keep both Delete() and DeleteAsync() DRY.
- Mark ProblemDetails with notificationsDeliveredViaHeader extension
when Umb-Notifications header carries event messages, preventing
the frontend from showing duplicate error toasts.
- Add notificationsDeliveredViaHeader to UmbProblemDetails type and
skip redundant ProblemDetails notification in try-execute controller.
- Add integration test for DeleteAsync cancellation detection.
* fix(core,api,web): fix backoffice UI errors on notification cancellation
- Fix ContentTypeServiceBase.DeleteAsync() to use PublishCancelableAsync
directly instead of delegating to the sync Delete() method, which
silently swallowed cancellation and always returned Success.
- Extract shared deletion logic into private PerformDelete() method
to keep both Delete() and DeleteAsync() DRY.
- Mark ProblemDetails with notificationsDeliveredViaHeader extension
when Umb-Notifications header carries event messages, preventing
the frontend from showing duplicate error toasts.
- Add notificationsDeliveredViaHeader to UmbProblemDetails type and
skip redundant ProblemDetails notification in try-execute controller.
- Add integration test for DeleteAsync cancellation detection.
fix: #12636
* fix(core): reduce PerformDelete arguments and trim LOC
Address CodeScene quality gate failures:
- Reduce PerformDelete from 5 to 4 parameters by resolving
EventMessages internally via EventMessagesFactory.Get()
- Trim lines of code to stay within the 1000 LOC threshold
* refactor(core): extract obsolete container methods into partial class
Split ContentTypeServiceBase into two partial class files to address
CodeScene's "Lines of Code in a Single File" quality gate (1007 > 1000).
The #region Containers block was chosen for extraction because all its
methods are already marked [Obsolete] and scheduled for removal in
Umbraco 18, replaced by IContentTypeContainerService and
IMediaTypeContainerService. The region is fully self-contained with no
inbound calls from the rest of the class.
This is a compile-time only change — partial classes produce identical
IL output. No public API, behavior, or binary compatibility impact.
* Revert "refactor(core): extract obsolete container methods into partial class"
This reverts commit 6fd8fd23f6.
* Pass eventMessages from the caller into PerformDelete instead of being re-obtaining from the factory.
* Use try/finally in test to ensure clean-up.
* Restore removed comments.
* Revert client-side updates.
* Revert client-side updates (2).
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add aria-label and name to search input for accessibility
- Add aria-label attribute to search input using localized placeholder text
- Add name attribute ("search-input") to provide form field identification
- Fixes Google Console warning about missing id/name on form field
- Improves WCAG 3.3.2 compliance (Labels or Instructions)
- Improves WCAG 2.5.3 compliance (Form input identifiable names)
Closes#2193
* Reused localized label
* Tidy-up/linting
---------
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Auto-generate HMAC secret key for imaging on new installs.
* Address code review feedback.
* Log results of configuration operations.
* Refactored to use the Attempt pattern.
* Allow custom folder types when creating from media picker.
* Adjust selector padding.
* Corrected call to await.
* Addressed feedback from code review.
* Set entity unique before scaffold processing to fix collection view for new media folders.
* Instead of moving setUnique() earlier in the provider, fix the consumers to observe the unique observable rather than reading synchronously.
* Addressed code review point on context observation.
* implement satisfies type check
* minor refactor
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Prevent save of partial view file when using runtime production mode, and verify for partial views and templates with integration tests.
* Display warning when templates and partial views are not editable in the backoffice.
* Share styles.
* Validate at the partial view API whether updates are allowed based on production runtime mode.
* Add similar checks for templates, handling case where metadata updates are allowed.
* Add integration tests for verifying behaviour in production mode.
* Fix the breaking changes on the constructor of the service classes.
* Use IOptions (we don't need live updates for this setting).
* Addressed code review feedback.
* Add IsProductionMode private property on both updated services.
* Move create template check to validate method.
* Remove entity actions create/delete/rename for templates and partial views whilst running in production mode.
* Addressed code review feedback.
* include server in condition name
* move tag to bottom right corner of workspace
* introduce info modal
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Tiptap Table: fix popover positioning for row and column grips
Refactored the table extension to use a proper container structure
and separate popovers for row and column context menus.
Key changes:
- Added UmbTableView with block container, inner table container,
widgets container, and overlay container structure
- Created TableHandlePlugin to manage grips and popovers centrally
- Changed from single shared popover to separate row and column
popovers, fixing the issue where column menu always appeared
at the first column position
- Updated CSS styles to support the new container structure
- Added proper cleanup when tables are removed from the editor
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Deprecates `UmbBubbleMenu` extension
No longer used internally.
There were issues with the popover and Tiptap editor state.
* Tiptap Table node-view refactor
* Exports `UmbTableView`
* Handles `mouseleave` event
* Adds readonly guard and dynamic grip offset for table handles
Prevents grips/popovers from appearing and dispatching transactions
when the editor is in readonly mode. Replaces hardcoded 16px container
offset with dynamic bounding rect computation to stay in sync with CSS.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Uses TableMap for cell indices instead of DOM child indexes
Resolves cell row/column via ProseMirror position resolution and
TableMap.findCell, which correctly handles merged cells (colspan/rowspan)
instead of relying on DOM child indexes.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Improvement: Use `when` callback parameter in tiptap toolbar disabled button
Use the callback parameter from Lit's `when` directive instead of a
non-null assertion to access the icon value.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Feature: Add `actionButton` kind for tiptap toolbar extensions
Create a new `actionButton` kind that uses the disabled button element,
replacing manual `element` overrides in the Unlink, Undo, and Redo
toolbar manifests.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Improvement: Add dedicated element for `actionButton` tiptap toolbar kind
Addresses review feedback by creating a proper `umb-tiptap-toolbar-button-action`
element for the `actionButton` kind instead of reusing the `-disabled` element.
- Uses `api.isDisabled()` for the disabled state (not `!isActive`)
- Types manifest correctly via generic on base class
- Makes base `UmbTiptapToolbarButtonElement` generic so subclasses can
specify their manifest kind
- Deprecates `umb-tiptap-toolbar-button-disabled` (scheduled for removal in v19)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Improvement: Add base API class for `actionButton` toolbar extensions
Introduces UmbTiptapToolbarActionButtonApiBase with a default isDisabled
implementation that returns !isActive(editor), so third-party extensions
get meaningful disabled state without needing to override isDisabled.
Updates undo, redo, and unlink APIs to use the new base class, removing
their redundant isDisabled overrides. Adds a comment explaining the
implicit re-render dependency in the action button element.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* fix(media): display filename in upload field preview
Add visible filename text to the file and image upload field preview
components. Previously, the file preview only showed an icon and the
image preview only used the filename as invisible alt text.
The filename is extracted from the File object when available (blob
URLs during upload), falling back to the last path segment for
persisted server paths.
Closes#21587
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(media): display filename in audio, video, and SVG upload previews
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(media): move filename display to parent upload field with file-info bar
Move filename rendering from 5 individual preview components into the
parent input-upload-field element. The filename and remove action now
share a bordered bar below the preview. Filename is plain text during
upload (blob URL) and a clickable link to the file when saved.
Reverts preview components to their original state (preview only).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* style updates
* link style adjustment
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Add support for running website without backoffice.
* Add support for running delivery API without website or backoffice.
* Reverted unncessary idempotent checks on individual builder extensions.
* Integration tests for service registrations.
* Integration HTTP tests for service registrations.
* Tidy up and code review feedback.
* Remove unnecessary null check.
* Ensure models builder references are added to attempt to resolve the deliver API setup.
* Allow folder selection in media entity picker
* Also handle user and user group media root node picker.
* Allow file selection for users and user groups, fixing failing E2E test.
* Changed media start nodes for user/user group to select folders only
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Add support for member sorting by member type.
* Make the backoffice member table sortable by the supported fields.
* Sort member groups by name.
* Fixed linting issue.
* Use UmbDirection for sort direction
---------
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Fix missing <title> attribute for Icons in document types in backoffice
* Move the title attribute to uui-button from umb-icon.
* Removed color option from lable and title. Added prefix "Change icon:" in the title. Prefix managed from the localization.
* Improve icon tooltip accessibility and i18n in content type header
- Add defensive check in #iconTitle to avoid "undefined" text when icon is unset
- Move colon separator from translation strings to component template
- Use consistent label for both title and aria-label on icon button
- Add Spanish and Italian translations for changeIcon key
* Fix failing test by using an exact match for a label.
---------
Co-authored-by: Pasang Tamang <45009265+pasangtamang@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Document Types returns a list of allowed parent keys
* Media types included
* Add selectable filter for duplicate action based on allowed parents.
* Add optional selectable filter provider support to move action.
* Add selectable filter provider for move action in documents.
* Add selectable filter provider for move action on media.
* Optimize filter providers by using allowedAsRoot property directly.
* Refactor document move action to use repository for selectable filter.
* Move media filter logic from provider to repository .
* Centralize allowed-parent logic in data sources.
* Remove document item lookup from duplicate action.
* Simplify custom filter assignment in move action.
* Remove unused import.
* Rename getSelectableFilter method in document duplicate action..
* Refactor move to action for documents.
* Refactor of media move to action.
* Refactor duplicate action and remove unused imports.
* Clean up.
* Use .js extension for media tree type import
* Export move action and fix imports.
* add interfaces for type safety
* local implementations
* make linter happy
* make linter happy
* Filter out current node in MoveTo action
* Return error instead of throwing on fetch
* Use typed getters for structure data sources
* remove unused
* Add UmbTreeItemModel typing to move-to actions
* align paramater naming
* Defer move repository lookup until after modal
* Fetch type data concurrently with Promise.all
---------
Co-authored-by: NillasKA <kramernicklas@gmail.com>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Dont blow up GetTestOptions when inside testfixtures
* Dont blow up Reference resolving when working with proxies
* Improve GetAssemblyFolders nullability
* More verbosity
* Messy implementation of documenttypes and datatypes
* Formatting and move service injection to constructor
* cleanup and bubble up new constructor
* Allow folder or item only searches
* feedback pr & subsequent refactoring
* Apply review suggestions
* Update openapi file
* Used constant, resolved minor layout warnings.
* Fix parent key lookup in tree search to check both folders and items.
* Remove TreeItemKind.None from flags enum.
* Add TODOs for removing the default implementation on the interfaces.
* Add permission integration tests.
* Update OpenApi.json.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Skip empty strings in repeatable textstring validation and persistence.
* Override RequiredValidator for repeatable textstring to treat all-empty arrays as no value.
* Updated ui helper for add block list button
* Make AllowEditInvariantFromNonDefaultIsTrue tests run in the pipeline
* Removed .skip since the issue is resolved
* Fixed tests for submit an empty URL in RTE property
* Make TiptapToolbar tests run in the pipeline
* Reverted npm command
* Claude's suggestions
* Rewrite for tags based hybrid cache eviction and optimize the converted, in-memory cache eviction
* Replicate cache invalidation/flushing optimizations for the media cache service
* Do not perform Examine re-indexing for "other" changes on content types
* Clean up TODOs
* Use configured batch size for indexing, and use cached structure for checking publish status
* Default implementations of new interface methods to prevent breaking changes
* Clean out more TODOs
* Refactor logic to extension methods
* Add missing notification handlers to cache tests
* Add additional test coverage.
* Remove OnChange from settings for transient notification handler.
* Adds a migration to clear the hybrid cache to ensure all items are tagged by content type.
* Clear all converted content on type change in auto models builder mode.
* Apply the same fix for data type updates.
* Apply the same fix for data type updates (2).
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Changed the modal size to medium data type picker modals.
* Updated the icon and label alignment so that icon always align vertically top and label in each starts from same position.
* Linting
* Adds `justify-items: center` for "Create new" button icon
---------
Co-authored-by: Pasang Tamang <45009265+pasangtamang@users.noreply.github.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Add pagination to the member group picker.
* Linting
...and use of `when` directive ;-)
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Move testhelpers and builder into the acceptance test project
* Updated imports in tests
* Updated readme
* Updated postinstall to exclude setting up config
* added a cleanup when npm packing
* update tsconfig path mapping to @umbraco/acceptance-test-helpers
* Added dist to git ignore
* Adds separate README files for npm and GitHub
README.md: contributor-focused (test docs)
README.npm.md: consumer-focused (package docs)
cleanse-pkg.js swaps them during npm pack
* Updated to swap READMEs on npm pack. So the consumer README is the one being released
* Add npm publish pipeline for @umbraco/acceptance-test-helpers
* Configure package.json for npm publishing as @umbraco/acceptance-test-helpers
* Updated missing imports
* Cherrypicked helper changes
* Updated tests
* Updated name of builder
* added tslib
* Fixed test
* Renamed
* Add nbgv version step for test helpers npm package
* Fixes based on comments
* More fixes
* Removed unnecessary imports
* Fix naming of storage_state_path
* Added recommend for storage state
* Create console file if not present
* simpler and more consistent css for block list and block single
* adjust spacing only for default views
* adjust inline and support for Block Grid
* simplify gap css for Grid Entries
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Create new folder on enter in media picker
* Move CSS properties and change value for placeholder.
* Add localization key for labels and placeholder.
---------
Co-authored-by: Emma L Garland <emmagarland77@gmail.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Adding CPM into Umbraco Project
* Adding CPM for UmbracoExtension
* remove CPM from umbraco templates
* remove change from readme
* update readme for umbracoproject
* Adding CPM options to Umbraco Project and Umbraco Templates
* update name param
* make central to default option
* Update templates/UmbracoExtension/Umbraco.Extension.csproj
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update templates/UmbracoExtension/.template.config/template.json
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update templates/UmbracoProject/.template.config/template.json
Co-authored-by: Andy Butland <abutland73@gmail.com>
* add PackageManagement into Visual studio display
* Apply suggestions from code review
* Fix ascii art and typo.
* Remove trailing commas in template.json files.
* Aligned casing and grammar between package management choices.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Cleaned up
* Make ScheduledPublishing tests run in the pipeline
* Updated npm command
* Increased timeout
* Updated npm command
* Addec console log to test in the pipeline
* Make tests run in the pipeline
* Removed step to verify that the document is published since it doesn't work in the pipeline - only works locally
* Update npm command
* Fixed tests
* Fixed comments
* Removed unnecessary comments
* Revert npm command
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
* Add permission-based filtering to element tree endpoints
The element tree endpoints now filter results based on the current
user's browse permissions via a new IElementPermissionFilterService,
mirroring the existing document tree behavior.
Also extracts shared filtering logic from DocumentPermissionFilterService
into a PermissionFilterServiceBase to avoid duplication.
* Add unit tests for ElementPermissionFilterService
* Replace document-specific inheritdoc with neutral XML docs in PermissionFilterServiceBase
* Fix GetPermissionsAsync to use the provided objectTypes parameter instead of hardcoded Document type
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Ensure local cache instructions count towards last synced ID
* Add obsoletion message to the interface.
* Fixed failing integration tests, then refactored them so they call and test the non-obsolete method.
* Rework the solution to retain existing functionality
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Set AllowedInLibrary on element content type in permission tests
The GetElementPermissionsCurrentUserControllerTests were failing because the
test setup created an element content type without setting AllowedInLibrary
to true. The ElementEditingService.TryGetAndValidateContentType method now
requires both IsElement and AllowedInLibrary to be true for element creation.
* Handle element saving and copying notifications in complex property editors
Extend ComplexPropertyEditorContentNotificationHandler to also handle
ElementSavingNotification and ElementCopyingNotification, ensuring that
block property key replacement (BlockList, BlockGrid, RichText) is
applied to elements the same way it is for content.
* Add integration tests for element copy with block editors
Test that block keys are regenerated and block structure is preserved
when copying elements with BlockList, BlockGrid, and RichText editors,
for both invariant and culture-variant content.
* Show correct URLs for invariant content under non-default language domains.
* Use configured domain hosts instead of request host for fallback URL filtering.
* Addressed feedback from code review.
* Fixed code warnings.
* Update file references in integration test csproj.
* Simplify invariant URL culture filtering by determining cultures upfront
Instead of querying all cultures and post-processing to remove irrelevant
URLs, determine the relevant cultures before the loop by checking which
domains are assigned to the content's ancestor path.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Show correct URLs for invariant content under non-default language domains.
* Use configured domain hosts instead of request host for fallback URL filtering.
* Addressed feedback from code review.
* Fixed code warnings.
* Update file references in integration test csproj.
* Simplify invariant URL culture filtering by determining cultures upfront
Instead of querying all cultures and post-processing to remove irrelevant
URLs, determine the relevant cultures before the loop by checking which
domains are assigned to the content's ancestor path.
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Update GetContentSchedulesByIds to retrieve data in groups to avoid overrunning the SQL parameter count.
* Protect against duplicate retrieval if duplicate IDs are provided.
Removed explicit 260-character path length checks from PhysicalFileSystem.GetFullPath and deleted associated unit tests. Updated tests to focus on path normalization and validity, and improved path assertions for clarity and cross-platform compatibility. No longer enforce or test for legacy Windows path length restrictions.
* Add data-source package and integrate in input-entity-data
* Add optional description to collection items
* introduce extension picker data source
* fix problem with shallow copy because of js module in object
* nest manifest data
* Hide pagination when all items are shown
* Add a fallback page size
* merge extension insight code with extension code
* clean up
* Add optional description support to default item ref
* Revert "Add data-source package and integrate in input-entity-data"
This reverts commit e02881e8b6.
* fix post merge
* add input-extension utilizing input-entity-data
* proxy value and selection
* add todo
* temp hardcode config
* add typed config model
* Support multiple extension types in filters
* Use extensionTypes filter and deprecate type
Standardize extension collection filtering by introducing extensionTypes and phasing out the old type field.
* More explicit type name
* Expose allowedExtensionTypes as a @property on UmbInputExtensionElement
* Add text filter support for entity data picker
* remove reexport as this is not public available
* remove unused
* clean up
* clean up
* Add storage and getter for allowedExtensionTypes
* Inline collection view alias and remove constant
* Update vite.config.ts
* Update manifests.ts
* Update extension.picker-data-source.ts
* add tests for extension picker data source
* change to an observable feature config
* make feature object optional
* add unit tests
* Reference condition class directly in manifests
* clean up observers if data source type changes
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* UmbracoExtension template: Use runtimeConfigPath for automatic auth
Use hey-api's runtimeConfigPath to pre-configure the generated client
by copying umbHttpClient's config (baseUrl, credentials, auth) at
initialization time. This eliminates the need for entrypoint auth setup
via consumeContext/getOpenApiConfiguration.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: updates extension with newly generated SDK files
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Keep track of rebuilding in memory
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Remove comment
* Revert back to original with lock
* Apply suggestion from @Zeegaan
* Remove unused
* Adress review comments
* Improve in-memory rebuild tracking for index rebuilder.
* Add cross-server rebuild status tracking via ILongRunningOperationService.
* Ensure index is used in operations, to allow rebuild of different indexes concurrently.
* Use Task.Delay.
* Resolve breaking change in constructor.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add scheduled publishing support for elements
Move PerformScheduledPublish from IContentService to the shared
IPublishableContentService<T> interface so both documents and elements
support scheduled publishing.
Filter ClearSchedule and HasContentForRelease/Expiration queries in
PublishableContentRepositoryBase by NodeObjectTypeId to prevent document
and element schedules from interfering with each other.
Update ScheduledPublishingJob to process both document and element
schedules, and add integration tests verifying cross-entity isolation.
* Simplify ScheduledPublishingJob.ExecuteAsync
Extract duplicated scheduled publishing logic into a generic helper
method and include the entity type in the log message.
* Add element version cleanup to the content version cleanup background job
The existing ContentVersionCleanupJob only cleaned up document versions.
Element versions were left to accumulate despite having the same cleanup
service infrastructure available. This extends the job to also clean up
element versions using the same configuration toggle and schedule.
* Use PascalCase for structured logging names.
* Fixed code warnings and duplicate line breaks.
* Cleaned up usings.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add data-source package and integrate in input-entity-data
* Add optional description to collection items
* introduce extension picker data source
* fix problem with shallow copy because of js module in object
* nest manifest data
* Hide pagination when all items are shown
* Add a fallback page size
* merge extension insight code with extension code
* clean up
* Add optional description support to default item ref
* Revert "Add data-source package and integrate in input-entity-data"
This reverts commit e02881e8b6.
* fix post merge
* add input-extension utilizing input-entity-data
* proxy value and selection
* add todo
* temp hardcode config
* add typed config model
* Support multiple extension types in filters
* Use extensionTypes filter and deprecate type
Standardize extension collection filtering by introducing extensionTypes and phasing out the old type field.
* More explicit type name
* Expose allowedExtensionTypes as a @property on UmbInputExtensionElement
* remove reexport as this is not public available
* remove unused
* clean up
* clean up
* Add storage and getter for allowedExtensionTypes
* Inline collection view alias and remove constant
* Update vite.config.ts
* Update manifests.ts
* Update extension.picker-data-source.ts
* add tests for extension picker data source
The touchstart handler on the image cropper focus setter needs to call
preventDefault() to prevent scrolling during focal point drag. Use Lit's
@eventOptions({ passive: false }) decorator to explicitly declare this,
resolving the browser warning about non-passive event listeners.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* For indexing in the RTE, replace all HTML tags with spaces to make sure wqord boundaries are preserved. Closes#21778
* Trim the returned string and adjust test cases to match new expected output #21778
* Address review comments:
- Updated XML docs
- Removed trimming in unit tests
- Moved HTML strip implementation to an extensions method
* Removed redundant regexes
* Address comment formatting
* Address failed tests by not replacing multiple characters if the replacement is String.Empty to preserve existing behavior
* Remove unnecessary partial and using.
* Add tests for introduced overload of StripHtml, fix found issues with replacement regex, then optimised by removing second regex and replaced with string operations.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fix umbracoUrlName not working on multi sites
* update documentUrlServiceTests
* Use "is false" for false comparison
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Add missing AuditType.Copy audit log for element copy operations
Make the abstract Copy method in ContentEditingServiceBase async and
accept a Guid userKey instead of int userId, allowing the element
copy implementation to use the audit service directly. Add the
missing _auditService.AddAsync(AuditType.Copy, ...) call in
ElementEditingService.CopyAsync to match the document equivalent
in ContentService.Copy.
* Fix copy audit log to record against the original element
The copy audit entry was being logged against the new copy's ID
instead of the original element's ID, inconsistent with how
documents handle copy audit logging.
* Add audit log retrieval endpoint for elements and wire up frontend
Add GET /{id:guid}/audit-log endpoint following the document audit
log pattern. Wire up the existing frontend data source to call the
new API, add element-specific localization strings, and remove the
unsupported sort audit type.
* test: add comprehensive test coverage for BlockEditorVarianceHandler
- Add tests for AlignPropertyVarianceAsync method (collection alignment)
- Add tests for AlignedExposeVarianceAsync method
- Add edge case tests for segment variations
- Add tests for multiple items and deduplication scenarios
- Remove TODO comment
Fixes#21706
* refactor: reduce code duplication in BlockEditorVarianceHandler tests
- Add CreateBlockListValue helper method to eliminate repeated setup code
- Remove redundant test cases to reduce duplication
- Consolidate similar tests while maintaining essential coverage
Fixes code duplication issues reported in PR #21706
* fix: correct assertion in AlignPropertyVarianceAsync_Removes_NonDefault_Culture_Values test
When culture variance is disabled (ContentVariation.Nothing), the culture
should be set to null, not preserved. This matches the behavior tested in
Removes_Default_Culture_When_Culture_Variance_Is_Disabled test.
* fix: always deduplicate expose entries in AlignExposeVariance
Deduplication should always occur at the end of AlignExposeVariance,
even when no alignment is needed. This ensures duplicate expose entries
are removed regardless of whether variance alignment occurred.
* fix: remove expose entries when ContentData is missing
Expose entries that don't have matching ContentData should be removed
from the expose list. This ensures data consistency and prevents orphaned
expose entries.
* test: add 8 additional test cases for BlockEditorVarianceHandler
Adds comprehensive test coverage for:
- Culture assignment scenarios
- Segment variation handling
- Multiple ContentData items
- Edge cases (missing element types, no matching expose)
- Variation matching scenarios
* refactor: eliminate code duplication in BlockEditorVarianceHandler tests
Extract common test patterns into helper methods:
- CreatePropertyValues: Creates property values from configuration tuples
- CreateBlockPropertyValues: Creates block property values with alias/culture/segment
- CreateBlockItemVariations: Creates block item variations from tuples
- ExecuteAlignPropertyVarianceAsync: Executes AlignPropertyVarianceAsync with common setup
- ExecuteAlignedExposeVarianceAsync: Executes AlignedExposeVarianceAsync with common setup
- ExecuteAlignExposeVariance: Executes AlignExposeVariance with common setup
- SetupAlignedExposeTest: Sets up test data for AlignedExposeVarianceAsync tests
This eliminates copy-pasted code patterns across multiple test methods.
* refactor: eliminate duplication in AlignedPropertyVarianceAsync tests
Extract common test setup into ExecuteAlignedPropertyVarianceAsync helper method.
This eliminates duplication in:
- Assigns_Default_Culture_When_Culture_Variance_Is_Enabled
- Removes_Default_Culture_When_Culture_Variance_Is_Disabled
- Ignores_NonDefault_Culture_When_Culture_Variance_Is_Disabled
- AlignedPropertyVarianceAsync_Returns_As_Is_When_Variation_Matches
* fix: add missing using statements for Task, IList, IEnumerable, Func
* fix: correct Assert.ThrowsAsync usage - await the task when accessing exception
* fix: await Assert.ThrowsAsync directly to get exception
* remove: AlignPropertyVarianceAsync_Throws_When_PropertyType_Is_Null test
* fix: mock should return null for unknown content types in AlignExposeVariance test
* Revert production code changes - keep only test additions
* Remove bug-fix verification tests - moved to PR #21801
* refactor: consistently use CreateBlockListValue helper in all tests
* test: restore AlignExpose_Can_Handle_Variant_Element_Type_With_All_Invariant_Block_Values test
* docs: clarify why mock returns null for unknown content types
* refactor: use configuration class to reduce argument count in CreateBlockPropertyValues
* fix: add missing closing brace for Assert.Multiple block
* fix: remove leftover merge conflict marker
* fix: remove duplicate method definitions
* Remove unused code and usings. Encapulate BlockPropertyValueConfig. Fix code warnings.
* Standardise test naming, order of methods and use of Assert.Multiple.
* Complete test coverage with additional tests for AlignedExposeVarianceAsync.
---------
Co-authored-by: root <root@dragon.second>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Ensure document status shown in the Infor workspace view is up to date after unpublish and save/publish operations.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Further feedback from code review.
* Fix false-positive pending changes after save and publish by ensuring the property value preset builder reconstructs objects with the same property key order.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Fix GUID repository cache key prefix in PublishableContentRepositoryBase
The merge of the GUID cache key collision fix (9ea0520) applied
IContent-specific changes from DocumentRepository's nested class, but
in v18/dev this code lives in the generic base class. Two issues:
- EntityByGuidReadRepository.GetCacheKey used the "uRepo_" prefix
while GuidReadRepositoryCachePolicy looks up entries with "uRepoGuid_",
causing PopulateCacheByKey to insert under a key the policy never finds.
- PersistUpdatedItem cleared GetGuidKey<IContent> instead of
GetGuidKey<TEntity>, so ElementRepository would clear the wrong key.
* Add media navigation support to PublishedContentQuery
Introduced IMediaNavigationQueryService as a dependency and updated constructors to resolve it. Refactored ItemsAtRoot to accept a navigation query service, enabling MediaAtRoot to retrieve root media items via navigation queries. ContentAtRoot and MediaAtRoot now use the appropriate navigation query service for root item retrieval.
* Add IMediaNavigationQueryService support to content query
Extended PublishedContentQuery and ContentFinderByConfigured404 to accept and use IMediaNavigationQueryService alongside IDocumentNavigationQueryService. Updated constructors and service registrations to ensure both navigation services are available for enhanced content and media navigation scenarios.
* Add obsolete constuctors and expand PublishedContentQuery tests
Introduce [Obsolete] constructor overloads for PublishedContentQuery and ContentFinderByConfigured404 to support legacy usage, scheduled for removal in Umbraco 19. Refactor ItemsAtRoot for clarity. Significantly expand PublishedContentQueryTests with comprehensive unit tests covering constructor validation, Content/Media overloads, root item retrieval, and search functionality, including paging, ordering, and culture context. Add test helpers and mocks to improve test coverage and reliability.
* Fixes to constructor overloads.
* Re-organise tests into unit and integration (so the former, that don't need integration setup, will run more quickly).
* Remove low value integration tests.
---------
Co-authored-by: Fabian Beier <Fabian.Beier@aa-g.de>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* refactor to use the collection item extension point
* Add actions slot to media collection item card
* Set actions slot button background in media card
* Update src/Umbraco.Web.UI.Client/src/packages/media/media/collection/media-collection.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix GUID read repository cache key collision with int-keyed repositories.
* Remove GUID read repository for templates.
* Ensure GUID read repository cache keys are invalidated.
* Further optimisation of by GUD GetAll reads.
* Move default repository cache timespan to a centralised constant.
* Further use of centralised constant.
* Add GetGuidKey<T>(Guid id) and update callers to use it.
* Ensure package migration steps only run once by moving the override of IgnoreCurrentState to true to the derived AutomaticPackageMigrationPlan, where it's needed.
* Add integration test to verify the fix.
* Fix failing integration test (the test migration plans were leaking outside of the new test, and being picked up by the DI container for other tests.
* Add AllowedInLibrary flag to content types
Add a new boolean property AllowedInLibrary across all layers to
indicate whether a content type is allowed in the library. This is
only meaningful for element types (IsElement = true).
Changes span the core domain model, Management API request/response
models, persistence DTOs/mappers/factories, and a database migration
to add the column to the cmsContentType table.
* Enforce AllowedInLibrary in ElementEditingService.CreateAsync
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(api): add AllowedInLibrary filter to document type search endpoint
Add allowedInLibrary query parameter to GET /document-type/search,
following the same pattern as the existing isElement filter. The old
SearchAsync overload without the parameter is preserved as a default
interface method and marked obsolete (scheduled for removal in v19).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore(api): regenerate OpenApi.json and backoffice client types
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(api): make search query parameter nullable for document type search
Allow the document type search endpoint to be called without a text
query, enabling filter-only usage (e.g. filtering by isElement and
allowedInLibrary without requiring a search term).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(api): replace search allowedInLibrary filter with dedicated endpoint
Revert the search endpoint changes (IContentTypeSearchService, controller)
and instead add a dedicated GET /document-type/allowed-in-library endpoint
that follows the AllowedAtRoot pattern. This ensures IContentTypeFilter
support and a cleaner API separation.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* test(api): add integration tests for GetAllAllowedInLibraryAsync and AllowedInLibraryDocumentTypeController
Add service-level tests verifying correct filtering by IsElement + AllowedInLibrary, pagination, and IContentTypeFilter integration. Add controller-level authorization tests for the allowed-in-library endpoint.
* Map allowedInLibrary through content type data sources
Add allowedInLibrary to UmbContentTypeModel and map it consistently
across document, media, and member type data sources for scaffold, read,
create, and update operations.
* Add AllowedInLibrary support to test builders and set it in all element tests
ElementEditingService.CreateAsync checks contentType.AllowedInLibrary and
returns NotAllowed if false. All element test types were missing this flag,
causing test failures. Adds IWithAllowedInLibraryBuilder interface, extension
method, and sets AllowedInLibrary=true on all element type creation in tests.
* Also enforce IsElement check when creating elements in the library
* Set IsElement and AllowedInLibrary on ElementPublishingServiceTests content types
* Remove AllowedInLibrary from document type tree item response model
The AllowedInLibrary property is not relevant for tree items and is not
used by the frontend. This removes it from the tree item model, its
mapping in the tree controller, and regenerates the OpenAPI spec and
TypeScript client accordingly.
* Refactor element content type validation into base class override
Make TryGetAndValidateContentType protected virtual in
ContentEditingServiceBase and override it in ElementEditingService to
check IsElement and AllowedInLibrary. This guards both create and update
paths (previously only create was guarded) and eliminates duplicate
ContentTypeNotFound handling.
Enable the previously-ignored
Cannot_Create_Element_Based_On_NonElement_ContentType test and add a new
test for the AllowedInLibrary check.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Fix EntityTypeContainerService.UpdateAsync using wrong AuditType
UpdateAsync was logging AuditType.New instead of AuditType.Save,
causing container update operations to be recorded as creations
in the audit log.
* Be explicit about creating foreign key constrains with check (already the default).
* Add a migration to attempt to ensure that all constrains a trusted.
* Updated name of migration class.
* Ensure long timeout for migration.
* Update BulkInsertRecordsSqlServer to use SqlBulkCopyOptions.CheckConstraints and verify that no untrusted constraints remain afterward.
* Ensure NPoco InsertBulk uses SqlBulkCopyOptions.CheckConstraints by introducing UmbracoSqlServerDatabaseType (subclass of SqlServer2012DatabaseType) that overrides InsertBulk to pass SqlBulkCopyOptions.CheckConstraints.
* Also handle InsertBulkAsync.
* Add webhooks for elements
* Review: Removed unused payload type
* Use new object as empty payload
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Fix GetPermissionsAsync to use path-based permission inheritance
GetPermissionsAsync was querying only explicit per-node permissions,
ignoring the ancestor-based inheritance model. Nodes without explicit
permissions would get group defaults instead of inheriting from their
nearest ancestor with explicit permissions. This caused tree filtering
to hide child nodes that should have been visible.
Replace per-node permission queries with GetPermissionsForPath which
walks the entity path to resolve inherited permissions correctly. Also
pass object types through to enable batched entity lookups.
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Optimise GetPermissionsAsync.
* Add benchmark test.
* Add benchmark test.
* Add integration tests for default and isolated permission resolution
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Make the Delivery API "access" attributes public
* Update src/Umbraco.Cms.Api.Delivery/Filters/DeliveryApiAccessAttribute.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Cms.Api.Delivery/Filters/DeliveryApiMediaAccessAttribute.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Also make the VersionedDeliveryApiRouteAttribute public
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Elements: Add DisableDeleteWhenReferenced support and fix delete notifications
- Add DisableDeleteWhenReferenced check to ElementContainerService delete operations
- Fire ElementDeletedNotification and EntityContainerDeletedNotification per item during descendant deletion
- Fix potential infinite loop when items are skipped due to being referenced
- Simplify EmptyRecycleBinAsync to use DeleteDescendantsLocked directly
- Use path descending ordering for consistent deletion order (children before parents)
- Add test for descendant delete notifications
* Elements: Fix EmptyRecycleBin pagination with DisableDeleteWhenReferenced
When DisableDeleteWhenReferenced is enabled and some items are skipped,
the standard skip/take pagination breaks. This change:
- Adds SqlLessThan/SqlGreaterThan SQL expression extensions for string
comparison in LINQ queries
- Uses path-based cursor pagination instead of skip/take
- Tracks protected paths to prevent deleting containers that have
referenced descendants
- Adds ElementRecycleBin to UmbracoObjectTypes enum
* Tests: Add DisableUnpublishWhenReferenced tests for elements
Verify that DisableUnpublishWhenReferenced works correctly for elements
(inherited from ContentPublishingServiceBase):
- Cannot unpublish an element that is being referenced
- Can unpublish an element that is doing the referencing
* Elements: Remove redundant Trashed filter from DeleteDescendantsLocked
The Trashed filter was redundant because:
- EmptyRecycleBinAsync only operates on items under the recycle bin root
- DeleteFromRecycleBinAsync requires containers to be trashed, and all
descendants are marked as trashed when moved to recycle bin
Removing the filter simplifies the query and handles edge cases better.
* Elements: Add proper ProblemDetails responses for publish/unpublish endpoints
Move ContentPublishingOperationStatusResult from DocumentControllerBase to
ContentControllerBase so it can be shared. Add ElementPublishingOperationStatusResult
to ElementControllerBase and update PublishElementController and
UnpublishElementController to return proper error responses instead of empty
BadRequest() when operations fail (e.g., when DisableUnpublishWhenReferenced is enabled).
* Refactor: Use abstract EntityName for content controller error messages
Replace hardcoded "document" terminology in shared ContentControllerBase
error messages with an abstract EntityName property, so each subclass
(document, element, media, member, etc.) provides context-appropriate
error messages.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix: Check DisableUnpublishWhenReferenced when moving elements to recycle bin
ElementEditingService.MoveToRecycleBinAsync was missing the reference
check that ContentEditingService already performs for documents. This
allowed referenced elements to be moved to the recycle bin even when
DisableUnpublishWhenReferenced was enabled.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Prevent moving container to recycle bin when descendants are referenced
Add server-side validation to ElementContainerService.MoveToRecycleBinAsync
that checks for referenced descendants when DisableUnpublishWhenReferenced
is enabled. Uses ITrackedReferencesService.GetPagedDescendantsInReferencesAsync
as an upfront check before any move processing begins.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* quote table, column and alias names with SqlSyntaxProvider methods in raw sql
* refactoring private methods into new file as internal methods,
refactor new extensions into another file
* refactor GetAlias method
* Double check the change
* improve code health
* change new static classes into public static partial class NPocoSqlExtensions
* resolve some Copilot review suggestions
* revert Copilot suggestion because it decreases code health
* revert test
* compare in with LOWER, change two methods from private to protected in UmbracoDatabaseFactory
* revert Query.cs in this PR
* Refactor for code health and fixing raw sql
* divers small issues fixed
* refactor two methods to respect the DRY pricipal
* update IQuery interface
* clean up
* revert refactoring for CodeScene
* delete obsolete Test
* rename method
* remove new methods and updates, which are not relevat for this PR
* prepare for additional states in the future
* don't mix string building methods
* fix SQL injection danger
* fix test for reverted methods
* another SqlSyntax issue
* fix update
* fix reverted changes
* restore change for this PR
* restore change for this PR
* fix merge bug
* update formating
* extend ISqlSytax for database independent autoIkrement feature
* fix DTOs, extend ISqlSyntax
* fix tests
* revert
* updates
* diverse SqlSyntax and NPoco related updates for custom databse providers
* fix names
* fix PrimaryKey for multi columns
* Resolve the issues with SqlSyntaxProvider for SQLite. If executed correctly, a single test would reveal the problem.
* add another test
* revert changes which causes even more issues
* fix column const naming
* ensure column const names from v17.2
* add comment for change
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeTemplateDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* resolve review comments
* Make ReferenceMemberName consistent across all DTOs (use constants defined on the referenced DTO).
* Ensure [ExplicitColumns] attribute exists on all DTOs.
* Ensure we consistently use PrimaryKeyColumnName over PrimaryKeyName.
* Fix further inconsistency to use only TemplateNodeIdColumnName.
* Fixed trailing whitespace.
* Restored primary key constraint name on ContentVersionCleanupPolicyDto (it doesn't seem in scope of PR to remove this).
* Removed the confusing PrimaryKeyColumnName constants for multi-column primary key DTOs where the constant refers to only one of the key columns.
* ReferenceMemberName needs to be a C# property name, so it's safer to use nameof.
* Comment fix.
* Amended accessibility modifiers.
* Fixed/tidied comments.
* Fixed references from UserGroupDto.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fix: adds a title to the first entity action in the entity actions bundle, otherwise you do not know what it does, unless the icon is very descriptive
* calculate the label once
* concatenate data-mark string better
Fix element delete blocked by trash-tracking relation
ElementEditingService was missing the RelateParentOnDeleteAlias
override, so the "relate parent on delete" relation created when
trashing was not excluded from the reference check. This caused
"Cannot delete a referenced content item" when
DisableDeleteWhenReferenced was enabled, even for unreferenced
elements.
* improvement(elements): general UI updates, element picker rework, and constants tidy-up
* fix(elements): forward min/max messages through umb-input-element and minor cleanups
Add minMessage/maxMessage properties to UmbInputElementElement so validation
messages are properly forwarded to the inner umb-input-entity-data component.
Also fix JSDoc grammar, variable naming, and comment tidying.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(elements): sync value/selection and register inner form control in umb-input-element
Add getter/setter overrides for value and selection that keep them in sync
(matching umb-input-content pattern), and register the inner umb-input-entity-data
via addFormControlElement() in firstUpdated() so validation propagates correctly.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(elements): use correct element ID in referenced-by mock handler
Change sentinel ID from 'all-property-editors-document-id' to 'simple-element-id'
to match the actual element mock fixture IDs in element.data.ts.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* test(elements): add unit test for umb-input-element
Add instantiation and conditional a11y audit tests following the
umb-input-document.test.ts pattern.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* feat(elements): add element workspace validation repository
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Global Elements: Address Copilot review feedback on validation PR
Fix JSDoc comments on validation repository/data-source to accurately
describe validation behavior instead of persistence. Use barrel import
for validation repository and remove leftover commented-out code.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Global Elements: Remove redundant guard clauses in validation data source
Remove TypeScript-redundant checks in validateCreate to reduce
cyclomatic complexity below the CodeScene threshold of 9.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* feat(elements): add element reference tracking repository
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fixed linting errors
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Show character count and instant exceed validation.
* Show character count for textarea editor.
* Add character-count utility and use in editors.
* Rename char count state, add tests, fix imports.
* Update textbox character messages in locales.
* Apply suggestions from code review
* Align textarea and textbox in use of #getMaxLengthMessage private helper function.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* fix(manifest): replace %CACHE_BUSTER% token in extension paths served by manifest API
Move cache buster replacement to the presentation layer (manifest controllers)
instead of the infrastructure service. The importmap replacement stays in
HtmlHelperBackOfficeExtensions where it was already handled.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Ordered usings.
* Add unit test for cache buster token replacement.
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Fix ambiguous controller constructors.
* Make ReplaceCacheBusterTokens void since it mutates in-place.
* Defensively code against special characters in the cache buster hash.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Imaging: Add format parameter to thumbnail component with webp default
Adds a format parameter to the imaging resize API endpoint and the
umb-imaging-thumbnail component. The component defaults to 'webp' format
for optimal browser support and smaller file sizes.
This ensures that non-image file types (like PDFs) that have custom image
providers can render thumbnails correctly by explicitly requesting an
output format instead of relying on the original file extension.
Changes:
- Add format query parameter to ResizeImagingController
- Pass format through IReziseImageUrlFactory to ImageUrlGenerationOptions
- Add format property to UmbImagingResizeModel TypeScript type
- Add format property to umb-imaging-thumbnail element (default: 'webp')
https://claude.ai/code/session_01GP7N2iTashrG1cBdYVSW97
* Imaging: Include format in cache key generation
Fix cache key to include the format parameter so that different format
requests with identical dimensions are cached separately.
https://claude.ai/code/session_01GP7N2iTashrG1cBdYVSW97
* Imaging: Refactor to use ImageResizeOptions record
Introduces ImageResizeOptions record to encapsulate resize parameters,
addressing CodeScene's "Excess Number of Function Arguments" warning.
Changes:
- Add ImageResizeOptions record with Height, Width, Mode, Format properties
- Add new CreateUrlSets overload accepting ImageResizeOptions
- Mark old CreateUrlSets overload as obsolete (removal in v19)
- Update controller to use new options pattern
https://claude.ai/code/session_01GP7N2iTashrG1cBdYVSW97
* Imaging: Add explicit obsolete method to satisfy API compatibility
The API compatibility checker requires the method to exist explicitly
in the implementation, not just via default interface method.
Co-Authored-By: Claude <noreply@anthropic.com>
* Imaging: Add unit tests for imaging store format parameter
Tests verify that:
- Different formats are cached separately (webp vs png)
- Crops with and without format are cached separately
- Cache operations work correctly with format parameter
Co-Authored-By: Claude <noreply@anthropic.com>
* Add API compatibility suppression for resize imaging endpoint
Suppress CP0002 for adding optional 'format' parameter to the resize
imaging controller endpoint. The HTTP API remains backward compatible
as existing clients simply won't send the new parameter.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix API compatibility for IReziseImageUrlFactory
Restructure interface to maintain binary compatibility:
- Keep original 4-parameter method as required (marked obsolete)
- Add new ImageResizeOptions overload with default implementation
- Factory overrides new method to properly handle format parameter
This allows existing implementations to continue working while
new code uses the ImageResizeOptions overload with format support.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* chore(api): regenerate API compatibility suppression file
Regenerated the CompatibilitySuppressions.xml file with proper metadata
to suppress the breaking change detection for the optional format parameter
added to ResizeImagingController.Urls method. This change is backward
compatible at the HTTP API level.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* feat(imaging): automatic format conversion for non-image files
Move format conversion logic from frontend to backend IImageUrlGenerator
implementations to handle format defaults intelligently based on source
file types.
Why Backend Should Handle This:
1. **Source-aware decisions**: Backend has access to source file extension
and can determine if it's a true image (jpg, png) or processable
non-image (pdf with plugin)
2. **Consistent behavior**: All consumers (backoffice, APIs, custom code)
get consistent format handling without duplicating logic
3. **Plugin compatibility**: When ImageSharp plugins add support for new
file types (e.g., PDF thumbnails), the system automatically converts
them to web-compatible image formats
4. **User override preserved**: Explicit format parameter still works as
an override, giving users control when needed
Changes:
- Add Format property to ImageUrlGenerationOptions for explicit format requests
- ImageSharp implementations auto-detect non-image files and default to WebP
- ReziseImageUrlFactory passes format directly instead of via FurtherOptions
- Frontend imaging-thumbnail component removes hardcoded format='webp' default
- Backend now handles: format override > auto-detect non-images > keep original
Example Scenarios:
- JPEG → No format added (keeps JPEG)
- PNG → No format added (keeps PNG)
- PDF (with plugin) → Auto-adds format=webp
- Any file + explicit format param → Uses specified format
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(imaging): improve robustness and code quality
Address code review feedback with three improvements:
1. Add URI parsing error handling to prevent UriFormatException crashes
when malformed URLs are passed to RequiresFormatConversion()
2. Extract magic string array to class-level constant (TrueImageFormats)
to eliminate duplication and provide single source of truth
3. Remove inconsistent default interface implementation that didn't pass
format parameter, forcing concrete implementations to handle it properly
All changes maintain backward compatibility and improve code safety.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* refactor(imaging): move format determination to factory layer
Refactors format conversion logic from ImageSharp implementations to the factory layer for better separation of concerns and maintainability.
Changes:
- Add ContentImagingSettings.TrueImageFormats configuration (native image formats)
- Move format determination logic to ReziseImageUrlFactory.DetermineOutputFormat()
- Simplify ImageSharp v1 & v2 generators (remove duplicate RequiresFormatConversion())
- Add backward-compatible obsolete constructor to ReziseImageUrlFactory
- Add 50 comprehensive unit tests for format determination and configuration
Benefits:
- Single Responsibility: ImageSharp generators only generate URLs, don't make business decisions
- DRY: Eliminated 70+ lines of duplicated code between ImageSharp packages
- Configurable: TrueImageFormats setting allows customization
- Testable: Format logic tested independently of ImageSharp
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* refactor(imaging): repurpose ImageFileTypes for native format determination
Repurposes the existing unused ContentImagingSettings.ImageFileTypes setting instead of adding a new TrueImageFormats property. This provides better configuration control and eliminates the need for a new setting.
Changes:
- Repurpose ContentImagingSettings.ImageFileTypes (was unused, now active)
- Update ReziseImageUrlFactory to use ImageFileTypes for format determination
- Update TemporaryFileConfigurationPresentationFactory to use config instead of IImageUrlGenerator
- Add comprehensive XML documentation explaining usage in factory layer and backoffice UI
- Update all tests to reference ImageFileTypes
Benefits:
- No new configuration property needed (reuses existing setting)
- Frontend gets configurable format list instead of dynamic ImageSharp formats
- Better separation of concerns (config determines behavior, not infrastructure)
- Clearer documentation of where and how the setting is used
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* test(core): remove duplicate test methods in ContentImagingSettingsTests
Removed duplicate test methods that were causing compilation errors:
- ImageFileTypes_DefaultValue_ContainsExpectedFormats (duplicate)
- ImageFileTypes_DefaultValue_MatchesStaticConstant (duplicate)
- ImageFileTypes_CanBeConfigured_WithCustomFormats (duplicate with incorrect test data)
- Contradicting assertion in StaticConstants_HaveExpectedValues
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(api): suppress CP0006 for IReziseImageUrlFactory.CreateUrlSets overload
Added API compatibility suppression for the new CreateUrlSets overload that
accepts ImageResizeOptions parameter. This change is backward compatible as the
concrete implementation already has both methods and the old method is marked
obsolete to guide users.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fixes merge conflict
* formatting
* fix(api): suppress CP0002 for TemporaryFileConfigurationPresentationFactory constructor change
Added suppression for constructor signature change where IImageUrlGenerator
parameter was replaced with IOptionsSnapshot<ContentImagingSettings> to get
ImageFileTypes directly from configuration instead of from the image URL
generator.
This change is part of the WebP thumbnail feature and aligns with getting
native format information from ContentImagingSettings configuration.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(api): maintain backward compatibility for TemporaryFileConfigurationPresentationFactory constructor
Instead of suppressing the CP0002 error, added back the old constructor marked
as [Obsolete] that chains to the new one. The old constructor:
- Accepts the original parameters (ContentSettings, RuntimeSettings, IImageUrlGenerator)
- Ignores the IImageUrlGenerator parameter (kept only for backward compatibility)
- Uses StaticServiceProvider to get ContentImagingSettings
- Chains to the new constructor
This maintains full backward compatibility while migrating to the new approach
where ImageFileTypes comes directly from ContentImagingSettings configuration.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* test(core): update StaticConstants_HaveExpectedValues test to match actual constant value
The test was checking for format order 'jpg,jpeg,png,gif,webp,bmp,tif,tiff' but
the actual constant StaticImageFileTypes is 'jpeg,jpg,gif,bmp,png,tiff,tif,webp'.
Updated the test to match the actual constant value.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(api): resolve constructor ambiguity in TemporaryFileConfigurationPresentationFactory
Add [ActivatorUtilitiesConstructor] attribute to the new constructor to explicitly
indicate which constructor the DI container should use when both constructors have
the same number of parameters.
This fixes the "ambiguous constructors" error that was preventing the OpenAPI
contract test from running.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix: adds parameter even though it is unused to help the DI system figure out which constructor to use
* test(api): update ReziseImageUrlFactory test to reflect corrected query string handling
The implementation was fixed to correctly handle URLs with query strings by
stripping the query string before extracting the file extension. Updated the
test expectations to verify that PDFs with query strings are now processed
correctly and converted to WebP format, rather than returning empty results.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* chore: adds double obsolete constructor to stay persistent and be able to use only new constructor with same amount of arguments
* Apply suggestions from code review
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Address remaining PR #21570 review comments
- Add GetFileExtension() to UriExtensions for reusable URI extension extraction
- Simplify ReziseImageUrlFactory to use GetFileExtension() instead of manual parsing
- Add default implementation to IReziseImageUrlFactory to avoid CP0006 breaking change
- Remove CP0006 suppression from CompatibilitySuppressions.xml
- Fix Obsolete message format and remove unnecessary [ActivatorUtilitiesConstructor]
- Add TODO for ReziseImageUrlFactory typo rename
- Remove stale ObsoleteOverload test and low-value ContentImagingSettingsTests
- Add unit tests for UriExtensions.GetFileExtension()
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Avoid unnecessary second call to GetFileExtension().
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added further integration test to verify list view permission checks.
* Replace per item GetPermissionsForPath calls with a single batch GetPermissions query across all unique path node ids.
* Added unit test verifying DocumentCollectionPresentationFactory and fixed constructors.
* Replace per-item IsProtected calls with a single batched GetAll query and in-memory path matching.
Compute shared ancestor path keys once for collection siblings instead of per item.
* Eliminate redundant GUID to int conversions in HasScheduleFlagProvider.
* Batch user profile resolution in collection view mapping.
* Addressed issues from code review.
* DRY up GetOwenerName and GetCreatorName in CommonMapper.
* Apply suggestions from code review
Co-authored-by: Mole <nikolajlauridsen@protonmail.ch>
* Apply feedback from code review.
---------
Co-authored-by: Mole <nikolajlauridsen@protonmail.ch>
Mark hey-api generated client code and OpenApi.json as linguist-generated
so they are collapsed by default in GitHub diffs and excluded from
language statistics.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
fix(web): register entity data picker non-editor manifests statically
The entity data picker's picker infrastructure manifests (collection menu,
item, search, tree) were only registered dynamically via the entry point,
meaning they were unavailable until a picker data source was detected.
Split the registration so these manifests are registered statically through
the main property-editors manifest tree, while only property editor manifests
remain dynamically registered.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Update length of type column in LongRunningOperation
* Adding truncation
* Update src/Umbraco.Infrastructure/Examine/ExamineIndexRebuilder.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Used constants.
Handled case where long strings with the same first 200 characters could end up clashing (very unlikely, but we can be defensive).
Introduced a TruncateWithUniqueHash extension method to support this.
* Reverted comment removal.
* Rename migration class.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Use dotnet tool instead
* Uses pipeline build artifacts to reduce compilation time
* Fixed name
* Remove --noRestore
* Move DocFX metadata generation to Build stage
* Updated to use dlls
* Docs: Fix DocFX CSS reference for newer DocFX version
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Added conditions for generating DocFX metadata
* use glob pattern for DLLs
* Move DocFX to Build_Docs stage with separate DLLs artifac
* Fixes based on comments
* Undo commented out Upload C# Docs job
* Removed Build_Docs from Nuget Release so our docs isnt blocking
* Added dependsOn so Upload_API_Docs is only done when Build_Docs are finished
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
The OpenAPI definition and backoffice TypeScript client were out of
sync with recent Management API changes already on v18/dev. Regenerated
to bring them up to date.
* cherry-pick from #21672
* cherry pick tab rendering to handle one more case
* move the root route down for it to stay an empty path.
* Revert empty root path commit
* fullPath for root includes 'root'
* revert claude settings commit
* refactor accordingly to feedback
* Updates all obsoletion messages to use a softer expression of intent rather than stating explicit removal in a particular version.
* Code review feedback.
* Updates from code review.
chore(api): regenerate OpenApi.json and backoffice client SDK
The OpenAPI definition and backoffice TypeScript client were out of
sync with recent Management API changes already on main. Regenerated
to bring them up to date.
* Begin implementation of repo base
* Move internal mapping - part 1
* Move internal mapping - part 2
* Move versioning, persistence, GUID sub repo and utilities to base
* Fix wrong assumption in cache tests
* Move content repo + recycle bin to base
* Move schedule to base
* Move common delete clauses to base
* Move DTO mapping to base
* Fix a few of the pending TODOs for elements
* Abstract OnUowRefreshedEntity away to concrete implementations
* Handle template editing in a less hardcoded way
* Restore DTO visibility for elements
* Update src/Umbraco.Core/Cache/CacheKeys.cs
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Persistence/Repositories/Implement/PublishableContentRepositoryBase.cs
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Persistence/Repositories/Implement/PublishableContentRepositoryBase.cs
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Update cache key (review comment)
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Fix suggestion appsettings issue
* Add todo comment to remove UserPasswordConfigurationSettings and MemberPasswordConfigurationSettings
* Apply suggestions from code review
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Elements: Add restore from recycle bin functionality
- Add RestoreAsync to IElementEditingService and ElementEditingService
- Add RestoreAsync to IElementContainerService and ElementContainerService
- Add RestoreElementRecycleBinController and RestoreElementFolderRecycleBinController API endpoints
- Add TryGetContainedObjectType to EntityContainer for graceful handling of non-container types
- Update EntityContainerRepository to return null instead of throwing for non-container entities
- Add comprehensive integration tests for element and container restore operations
* Refactor: Remove entity return from Move/Restore/MoveToRecycleBin methods
Simplify the return types of IElementEditingService and IElementContainerService
move operations to return only the operation status instead of the entity.
These operations don't meaningfully change entity data (just location/state),
and no consumers were using the returned entities. Callers can use GetAsync
if they need the updated entity afterward.
* Fix: Capture original path before move for restore relation cleanup
The MoveEventInfo.OriginalPath was incorrectly set to the element's path
after the move, causing DeleteOriginalParentRelationsOnRestore to fail
because the path no longer contained the recycle bin path prefix.
* Tiny little formatting
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Add tests for property presest value
* save method'
* update accepntance test
* ad timeout to preset value test
* Updated yaml file to copy all .cs files but still keep folder structure
* remove timeout from preset value test
* adding time wait to tests
* adding more timeout
* Adding slow test
* update test
* Format code
* Format code and add more afterEach step to clean language
* Remove test.slow() as it is unnecessary
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Nhu Dinh <hnd@umbraco.dk>
Co-authored-by: Nhu Dinh <150406148+nhudinh0309@users.noreply.github.com>
* Localize "Copy to clipboard" button label
in other Block editor components.
* Adds "Copy to clipboard" action to RTE Block component
* Check if Clipboard Property Context is available
If not, don't show the action button.
* Register "Clipboard Property Context" for Tiptap RTE
we can't make this generic for all RTEs,
since it is bound to the property-editor UI alias.
* Implemented RTE Block's `copyToClipboard()` method
* Added Clipboard Property Value Translators
for Tiptap RTE Blocks.
* Block RTE: fix clipboard paste data structure mismatch
Change paste translator to output UmbPropertyEditorRteValueType (with
markup and blocks) instead of UmbBlockRteValueModel (flat structure).
This ensures the cloner receives the correct type and can properly
regenerate content keys.
Also optimize the cloner to skip DOM parsing when markup is empty,
which is always the case for clipboard paste operations.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* TipTap: debounce block updates to prevent race condition
Add debounceTime to the contents observable to batch rapid emissions
when pasting multiple blocks from clipboard. This prevents the
#updateBlocks method from being called multiple times in quick
succession.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Block RTE: address code review feedback
- Add missing await on insert() and insertFromRtePropertyValues()
- Remove redundant optional chaining on blockContentTypes.every()
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* feat(backoffice): use looser version ranges for peerDependencies
Convert hoisted dependencies to peerDependencies with more permissive version
ranges that allow plugin developers to use different versions without npm conflicts.
Version range strategy:
- Pre-release (0.x.y): >=X.Y.Z <1.0.0
Example: @hey-api/openapi-ts 0.85.0 → >=0.85.0 <1.0.0
Allows plugins to use 0.85.0, 0.91.1, 0.99.99 without conflicts
- Stable (major.x.y where major ≥1): major.x.x
Example: lit ^3.3.1 → 3.x.x
Allows any patch/minor within the major version
This allows plugin developers to:
- Use @hey-api/openapi-ts 0.91.1 while backoffice uses 0.85.0
- Install compatible deduplicated versions when available
- Override versions when needed for their specific use case
Types remain available from peerDependencies (automatically installed by npm 7+).
When @hey-api reaches 1.0.0, the range will automatically become ^1.0.0.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): use semver package for version parsing in cleanse script
Replace regex-based version parsing with the semver package used by npm itself.
This ensures version parsing is consistent with npm's own semver handling and is
more robust for edge cases.
Also update the version range logic to be more explicit and correct:
- Pre-release (0.x.y): >=X.Y.Z <1.0.0
- Stable (1+.x.y): >=X.Y.Z <NEXT_MAJOR.0.0
This ensures plugin developers use at least the tested version and prevents
accidental downgrades to incompatible minor versions.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* chore: formats file
* chore: lockfile
* fix(backoffice): use semver.minVersion to parse version ranges
Fix parsing of version ranges like ^0.85.0 by using semver.minVersion() instead
of semver.parse(). The parse() function only handles exact versions, while
minVersion() extracts the minimum version from a range.
Example transformations:
- ^0.85.0 → 0.85.0 → >=0.85.0 <1.0.0
- ^3.3.1 → 3.3.1 → >=3.3.1 <4.0.0
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): keep caret ranges for stable package versions
Optimize the version range conversion logic:
- Stable versions (major ≥ 1) with caret (e.g., ^3.3.1): Keep as-is
The caret already implements the desired range: >=3.3.1 <4.0.0
- Pre-release versions (0.x.y): Convert to explicit range
^0.85.0 → >=0.85.0 <1.0.0 (caret only allows 0.85.z, not 0.91.z)
- Exact versions (e.g., 3.16.0): Convert to range
3.16.0 → >=3.16.0 <4.0.0
This simplifies the published package.json while maintaining the same semantics
and is more explicit about the intent.
Examples of published peerDependencies:
- lit: ^3.3.1 (unchanged, already has correct range)
- rxjs: ^7.8.2 (unchanged)
- @hey-api/openapi-ts: >=0.85.0 <1.0.0 (converted from ^0.85.0)
- @tiptap/core: >=3.16.0 <4.0.0 (converted from 3.16.0)
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): use caret for stable exact versions
Simplify stable exact versions (e.g., 3.16.0) by adding a caret prefix (^3.16.0)
instead of explicit range (>=3.16.0 <4.0.0). Both are semantically identical for
stable versions but caret is more concise and conventional.
Updated version range logic:
- Stable with caret (^3.3.1): Keep as-is
- Pre-release with caret (^0.85.0): Convert to >=0.85.0 <1.0.0
- Stable exact version (3.16.0): Convert to ^3.16.0
Examples of published peerDependencies:
- lit: ^3.3.1
- rxjs: ^7.8.2
- @hey-api/openapi-ts: >=0.85.0 <1.0.0
- @tiptap/core: ^3.16.0 (now with caret)
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* refactor(backoffice): ensure all pre-release versions get explicit range
Reorganize version conversion logic for clarity:
1. All pre-release (0.x.y) versions → explicit range: >=X.Y.Z <1.0.0
- Examples: ^0.85.0 → >=0.85.0 <1.0.0, 0.85.0 → >=0.85.0 <1.0.0
2. Stable versions with caret (^3.3.1) → keep as-is
3. Stable versions exact (3.16.0) → add caret: ^3.16.0
This ensures pre-release version constraints are properly loosened for plugins
while maintaining stability guarantees.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* treat all modifiers the same
* docs: add backoffice npm package structure documentation
Add comprehensive section to CLAUDE.md explaining:
- Backoffice npm package architecture and plugin model
- Dependency hoisting strategy and version range logic
- How pre-release versions are handled vs stable versions
- Importmap as single source of truth for runtime
- Plugin development implications and expectations
Clarifies that while npm versions constrain types, the actual runtime comes
from importmap, and plugin developers should declare explicit dependencies
rather than relying on transitive deps.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
* docs: add npm package publishing guide to backoffice CLAUDE.md
Add comprehensive section explaining:
- Why backoffice uses peerDependencies (importmap provides runtime)
- Dependency hoisting strategy and version range conversion logic
- How pre-release versions are handled differently from stable versions
- Example published peerDependencies showing final output
- Plugin developer guide with dos and don'ts
- Key files involved in the publishing process
Provides clear guidance for plugin developers on version compatibility
and explains the importmap-as-single-source-of-truth architecture.
https://claude.ai/code/session_01CBpcwXYZjzexKkM9Cf57Kb
---------
Co-authored-by: Claude <noreply@anthropic.com>
* edit regex for oembed flickr
* Apply stricter matching with domain to all embed providers, and validate with unit tests.
* Resolved warnings and added further unit tests.
* Further tightened the URL matching regex for two providers.
* Add regex caching to OEmbedService and unit tests to verify behaviour.
* Restore flickr short URL domain.
* Use https in requests to oembed providers.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* edit regex for oembed flickr
* Apply stricter matching with domain to all embed providers, and validate with unit tests.
* Resolved warnings and added further unit tests.
* Further tightened the URL matching regex for two providers.
* Add regex caching to OEmbedService and unit tests to verify behaviour.
* Restore flickr short URL domain.
* Use https in requests to oembed providers.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Tests: Fix permission controller tests to use correct entity keys
The GetDocumentPermissionsCurrentUserController, GetMediaPermissionsCurrentUserController,
and GetPermissionsCurrentUserController tests were incorrectly creating user data and
passing user keys to the GetPermissions method. These controllers expect document/media
keys, not user keys.
Updated the tests to create the appropriate content/media types and entities, then pass
the correct keys to properly test the permission endpoints.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Elements: Add reference tracking and recycle bin query support
- Add Element reference tracking API endpoints (referenced-by, are-referenced, referenced-descendants)
- Add Element recycle bin original-parent and referenced-by endpoints
- Add ElementReferenceResponseModel and ElementContainerReferenceResponseModel
- Add IElementRecycleBinQueryService for querying original parents of trashed elements
- Add Element relation type constants for parent tracking on delete
- Add translation strings for Element recycle bin operations
- Refactor RelateOnTrashNotificationHandler to reduce code duplication using generic helper methods
- Add Element and ElementContainer support to RelateOnTrashNotificationHandler
* Elements: Register Element notification handlers for relation tracking
Add Element and EntityContainer notification handlers for:
- RelateOnTrashNotificationHandler (move to/from recycle bin)
- ContentRelationsUpdate (track element content relations)
* Elements: Remove ReferencedDescendantsElementController
Elements are leaf nodes in the folder structure and cannot have
descendants, making this endpoint unnecessary.
* Elements: Fix ElementPickerPropertyEditor reference extraction
The element picker stores element IDs as Guids, not as UDI strings.
Updated GetReferences to deserialize as Guid array and create UDIs
from the Guid values.
* Elements: Fix TrackedReferencesRepository to include Element published state
Add LEFT JOIN to ElementDto and use COALESCE to get the published state
from either DocumentDto or ElementDto, fixing the issue where Element
references returned published = null.
* Elements: Add ReferencedDescendantsElementFolderController
Add endpoint to get referenced descendants of an element folder.
Unlike elements (which are leaf nodes), folders can have descendants
that may be referenced elsewhere.
* Elements: Add integration tests for Element reference tracking
Add TrackedReferencesServiceElementTests covering:
- GetPagedRelationsForItemAsync for Elements
- GetPagedRelationsForRecycleBinAsync for Elements
- GetPagedKeysWithDependentReferencesAsync for Elements
- GetPagedDescendantsInReferencesAsync for Element containers
* Elements: Add management API controller permission tests for Element reference endpoints
- Add ReferencedByElementControllerTests for element referenced-by endpoint permissions
- Add AreReferencedElementControllerTests for element are-referenced endpoint permissions
- Add ReferencedDescendantsElementFolderControllerTests for folder descendants endpoint permissions
- Fix GetManagementApiUrl to respect [FromQuery(Name="...")] attribute for proper URL generation
* Elements: Split OriginalParentElementRecycleBinController into two controllers
Split the controller to follow the controller-per-operation pattern,
consistent with DeleteElementRecycleBinController and
DeleteElementFolderRecycleBinController.
- OriginalParentElementRecycleBinController: for elements
- OriginalParentElementFolderRecycleBinController: for folders
* Elements: Fix user fallback for audit logging in RelateOnTrashNotificationHandler
Update the handler to properly resolve user key for audit logging, using a switch expression
to handle different entity types. Also sets CreatorId on EntityContainer creation.
* Tests: Fix duplicate query parameter in ItemElementItemControllerTests
Remove the ClientRequest() override that was appending a duplicate id query
parameter to the URL. The base MethodSelector already includes the element key
which gets converted to the query parameter by GetManagementApiUrl, causing
the URL to become ?id=<guid>?id=<guid> and model binding to fail.
* Tests: Fix permission controller tests to use correct entity types
These tests were passing on the base branch only because the URL was being
constructed incorrectly (missing query parameters). After be399134f8 fixed
the GetManagementApiUrl helper to properly include FromQuery parameters,
the tests now correctly build URLs and revealed that they were using user
keys instead of the expected document/media/element node keys.
Updated tests to create the appropriate entity type (document, media, or
element) and pass its key to the permission endpoints.
* Tests: Update RelationTypeRepositoryTest for new element relation types
Update expected counts and fix hardcoded ID lookup after new element
reference tracking relation types were added to the system:
- umbElement (RelatedElement)
- relateParentElementContainerOnElementDelete
- relateParentElementContainerOnContainerDelete
Changes:
- Store created test relation type in field to use actual ID instead of
hardcoded ID 9 which shifted when built-in types were added
- Update GetAll expected count from 9 to 12 (9 built-in + 3 test data)
- Update Count query expected from 6 to 8 (aliases starting with "relate")
* Refactor: Rename methods in RelateOnTrashNotificationHandler for clarity
Rename methods and parameters to better describe their purpose:
- DeleteRelationsOnRestore → DeleteOriginalParentRelationsOnRestore
- CreateRelationsOnTrashAsync → CreateOriginalParentRelationOnTrashAsync
- relationTypeAlias → originalParentRelationTypeAlias
- relationTypeName → originalParentRelationTypeName
These names clarify that the methods handle "original parent" relations
used for restoring items from the recycle bin, not all relations.
* Tests: Fix ReferencedDescendantsElementFolderControllerTests expectations
- Use unique folder names to prevent conflicts between test runs
- Add assertion to verify folder creation succeeds
- Correct expected status codes for Editor and Writer to OK (not NotFound)
The NotFound responses were caused by folder creation failures due to
duplicate names, not actual permission restrictions.
* Tests: Add success assertions to Element controller test setup methods
Add Assert.IsTrue checks after service calls in test setup to ensure
test prerequisites are correctly established before running actual tests.
This prevents silent failures in setup from causing misleading test results.
Assertions added for:
- ElementContainerService.CreateAsync (9 tests)
- ElementEditingService.CreateAsync (19 tests)
- ElementEditingService.MoveToRecycleBinAsync (6 tests)
- ElementContainerService.MoveToRecycleBinAsync (3 tests)
* Elements: Fix MapReference to return un-enriched response when entity not found
Return the mapped response model instead of null when the matching entity
cannot be found for enrichment. This preserves basic reference information
even when variant data cannot be loaded, preventing valid references from
being silently dropped.
Also clean up ElementContainerReferenceResponseModel formatting.
* Fix: Guard GetSlimEntities against empty keys to prevent loading all entities
* Fix: Return ParentIsTrashed status when original parent is in recycle bin
* Breaking: Remove duplicate sync notification handler interfaces
Remove INotificationHandler<ContentMovedToRecycleBinNotification> and
INotificationHandler<MediaMovedToRecycleBinNotification> interfaces along
with their obsolete sync Handle methods. Only the async handlers should
be implemented.
* Tests: Simplify TrackedReferencesServiceElementTests
- Simplify assertions in Get_Descendants_In_References test
- Create Element3 after folder creation to avoid unnecessary update
* Revert: Remove changes to be moved to separate PRs
Revert EntityTypeContainerService.CreateAsync CreatorId change and
permission controller test changes - these should be addressed in
separate PRs.
* Revert: Remove GetMediaPermissionsCurrentUserControllerTests changes
This change should be addressed in a separate PR for v17.
* Refactor: Move recycle bin audit logging to services
Move audit logging for recycle bin operations from RelateOnTrashNotificationHandler
to the individual services (ContentService, MediaService, ElementEditingService,
ElementContainerService). This simplifies the notification handler and keeps audit
logging closer to the operations being performed.
- Simplify audit messages to "Moved to recycle bin from parent {parentId}"
- Add AuditMoveToRecycleBin helper methods to Content and Media services
- Add AuditMoveAsync helper methods to Element services
- Remove unused audit dependencies from RelateOnTrashNotificationHandler
- Add obsolete constructor bridge for backwards compatibility
* Refactor: Extract GetParentIdFromPath extension method
Add GetParentIdFromPath string extension to consolidate duplicate logic
for extracting parent ID from entity path strings. This replaces 5
instances of the same path parsing pattern across services and handlers.
- Add GetParentIdFromPath to StringExtensions.Parsing.cs
- Inline audit calls in ContentService, MediaService,
ElementEditingService, and ElementContainerService
- Update RelateOnTrashNotificationHandler to use the new extension
- Add unit tests for the new extension method
* Refactor: Make CreateOriginalParentRelationOnTrash synchronous
Remove unnecessary async from CreateOriginalParentRelationOnTrash since
the method contains no async operations. Update handlers to return
Task.CompletedTask directly.
* Elements: Implement validation for Element editing endpoints
Move ValidateCulturesAndPropertiesAsync and GetCulturesToValidate from
ContentEditingService to ContentEditingServiceBase, enabling reuse in
ElementEditingService.
- Implement ValidateCreateAsync and ValidateUpdateAsync in ElementEditingService
- Update Element API controllers to return validation results properly
- Update all inheriting services (Media, Member, Blueprint) with new params
* Elements: Add validation tests for ElementEditingService
- Add tests for ValidateUpdateAsync and ValidateCreateAsync
- Cover invariant, culture variant, and permission-based validation scenarios
* Fix bad merge
* Removed unused fields
* Removed old editor UI
---------
Co-authored-by: kjac <kja@umbraco.dk>
* add paging UI to picker search results
* implement paging in collection picker data source example
* Hide pagination when all items loaded
* Use paging object for search requests
* Forward paging params in server search queries
* Set default page size in PickerSearchManager
* Use args.paging for skip/take in search
* Update src/Umbraco.Web.UI.Client/src/packages/core/picker/search/picker-search-result.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Reset pagination page when updating query
* dim the box while searching
* Delay loader appearance with fade-in
* Track executed search query and use in results to prevent UI flickering when entering in the search field
* Skip update when dataType is undefined
* Cancel tree loads on context destroy
* fix pagination labels
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Umbraco.Core: add XML documentation to all public members
Add comprehensive XML documentation comments to all public classes,
interfaces, methods, properties, constructors, and enums in Umbraco.Core
to resolve SA1600 StyleCop warnings.
- Document ~2,500+ files across all folders (Services, Models,
Notifications, Configuration, Cache, etc.)
- Use <summary>, <param>, <returns>, <remarks> tags as appropriate
- Apply <inheritdoc/> for interface implementations
- Use <see cref="..."/> for type references
- Preserve all existing comments
This eliminates approximately 15,500 SA1600 warnings from the project.
* Revert any code changes in the PR.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Block RTE: Add delete action with undo support
Adds a delete button to RTE block entries that removes blocks from
both the editor HTML and the block manager data. Implements an
HTML-first deletion approach that enables Ctrl+Z undo support by
leveraging the existing _filterUnusedBlocks mechanism.
- Add delete button to block-rte-entry action bar
- Add pendingDeletions state to manager for HTML-first deletion flow
- Modify entries context to use pending deletion mechanism
- Add Tiptap API observer to process pending deletions
- Remove blocks from editor via ProseMirror transactions
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Updates UmbracoProject template
Removes the framework choice from the template configuration as it's not used and was out of date.
Updates the LTS version to a wildcard to allow minor version updates and mean this doesn't need to be updated all the time!
Updates the description in the dotnet version generated property
* Removes unnecessary build flag
* Remove Custom Version symbol
It doesn't show up in the template anyway and has been marked as obsolete
* Remove framework from Extension template also as not used
* fix: update dotnet new syntax in pipeline
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: NguyenThuyLan <116753400+NguyenThuyLan@users.noreply.github.com>
* Document Types returns a list of allowed parent keys
* Media types included
* Minor fixes to namespace etc.
* Tests
* Fixing breaking change
* Correcting requested changes
* Corrected requested changes
* Removed unnecessary usings, aligned naming between service, repository and tests.
Add a new status for the default implementation (NotImplemented felt more correct than NotFound).
Updated inheritance in service layer so we maintain the NotFound behaviour for member types.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Documents: Remove deprecated entityType from property values
The entityType property on property values was causing "Unsaved Changes"
modal to appear after saving documents with RTE blocks. This occurred
because the server data source added entityType when reading, but
setPropertyValue did not preserve it when updating values.
Since entityType on UmbElementValueModel is deprecated and marked for
removal in v18, the cleanest fix is to stop adding it in the server
data source mapping.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Fix display of validation hint related to a tab.
* Update position of the badge.
* Change position for last tab.
---------
Co-authored-by: engjlr <enl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Add and use a constant for the folder media type GUID identifier.
* Use defined constant and avoid lookup for folder media type when searching for media items.
* Add failing tests illustrating the lack of data type caching by key.
* Implement cache by key in data type repository.
* Apply same for template repository look-ups by key.
* Add tests verifying that content types are already cached by Id and key.
* Use correct default for creator Id in data type builder for tests.
* Use non-obsolete constructor in test.
* Ensured a deleted data type or template is cleared from the by key cache.
* Add IReadRepository implementations
* Utilize by-key repo access in service layers
* Fix test
* Safeguard against potential null reference exception
---------
Co-authored-by: kjac <kja@umbraco.dk>
* CRUD + folders + API
* Fix infinite recursion
* Distributed cache handling for Elements
* Publishing for Elements (incl. refactor)
* Fix bad file name
* Added "foldersOnly" option to the siblings endpoint
* Update src/Umbraco.Core/Models/UmbracoObjectTypes.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* API for publishing elements
* Published element cache (WIP)
* Fix delete at repo level
* Fixing up a little tests
* Element picker property editor
* Added tests to prove published element status
* Move scheduled content keys to base abstraction
* Add request caching for published element creation (similar to published document creation)
* Apply conditional appcache access to elements as well
* Fix test build errors
* Fix merge from main
* Fix merge
* Add cache invalidation on update (like content and media)
* Move element (incl. tests)
* Element copying
* Add items endpoint incl. variation info at item level
* Make the Element tree items look like Document tree items (with variations)
* Rename all things ElementType to DocumentType
* Move ElementRepository to the right place
* Fix auditing after merge (changes from #19357)
* Fix dates after merge (changes from #19822)
* Fix NPoco querying after merge (changes from #20184)
* Fix various build errors after merge
* Move containers
* Add migration to create element tables
* Re-implement #21105 at base class level
* Fix merge
* Add element tree recycle bin + move element to/from recycle bin
* Controllers for move to recycle bin + recycle bin root
* Support element containers in recycle bin (no controllers)
* Handle error cases for element moves and add more tests
* Do not allow creation of IPublishedElement for trashed elements
* Amend recycle bin controller output and add children controller
* Regenerate OpenApi.json with Element APIs
* Housekeeping: Organize element container service tests
* Fix bad housekeeping
* Add missing siblings controller for recycle bin
* Add "delete from recycle bin" and "empty recycle bin" operations (including API)
* Updated OpenApi.json to reflect new endpoints
* Added `CreateDate` to `ElementTreeItemResponseModel`
Marked `ElementRecycleBinItemResponseModel.DocumentTypeReferenceResponseModel` as nullable.
* Re-generated OpenAPI.json
* Add configuration endpoint for Elements
* Explicitly unpublish published elements when restoring from recycle bin.
* Elements: Remove invalid templateId from ElementVersionDto index definitions (#21384)
* Persistence: Remove invalid templateId from ElementVersionDto index definitions
The ElementVersionDto had index definitions that referenced templateId in
their IncludeColumns, but the ElementVersion table only has id and published
columns. This caused SQL Server clean installs to fail with error 1911:
"Column name 'templateId' does not exist in the target table or view."
This was likely a copy-paste error from DocumentVersionDto which does have
a templateId column.
* Ignore Cannot_Create_Element_Based_On_NonElement_ContentType for the time being
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Fix the ordering of items in the tree
* It's 2026 now...
* Fix missing project structure
* Amend empty recycle bin
* Elements: Fix element recycle bin node insertion on SQL Server (#21390)
Enable IDENTITY_INSERT before inserting the element recycle bin node with an explicit ID, then disable it afterward. This fixes the migration failing on SQL Server with "Cannot insert explicit value for identity column" error.
* Fix count trashed children
* Moved newly added entity service tests to an isolated, per-test DB class so they do not interfere with the existing per-fixture DB tests
* Elements: Element start node permissions (#21375)
* Add Element start node support for Users and UserGroups
- Add StartElementId to UserGroup and element start nodes to User
- Add UserStartNodeFolderTreeControllerBase for tree filtering with folder support
- Update ElementTreeControllerBase to use start node filtering
- Add ElementTreeItemResponseModel.NoAccess property for "no access" items
- Add UserExtensions methods for element start node calculation
- Update User/UserGroup API models and factories
- Add database migration for startElementId column
- Add SectionAccessForElementTree authorization policy
Note: Granular element permissions deferred for future implementation
* Add element root access for default user groups on fresh install
Set StartElementId = -1 for Administrators, Writers, Editors, and
Translators user groups in DatabaseDataCreator, giving them element
root access on fresh installations (matching their content/media access).
* Add multi-type support to UserStartNodeEntitiesService
Added overloads to RootUserAccessEntities, ChildUserAccessEntities, and
SiblingUserAccessEntities that accept multiple UmbracoObjectTypes. This
enables querying for Elements and ElementContainers in a single call
rather than requiring separate queries for each type.
Also added GetAll and GetPagedChildren overloads to IEntityService and
IEntityRepository to support querying multiple object types efficiently
with a single database query.
* Add integration tests for Element start nodes with mixed hierarchy
Added UserStartNodeEntitiesServiceElementTests with a mixed hierarchy
structure containing both containers and elements at each level:
- Level 1: Containers (C1-C5) and Elements (E1-E3)
- Level 2: Child containers (C1-C1 through C1-C10) and Elements (C1-E1, C1-E2)
- Level 3: Leaf elements (C1-C1-E1 through C1-C1-E5)
This tests scenarios where containers and elements are siblings, ensuring
the access filtering works correctly for mixed-type queries.
Also refactored Content and Media tests to use a shared base class
(UserStartNodeEntitiesServiceTestsBase) to reduce code duplication.
* Add Library section for Elements
- Rename Constants.Applications.Elements to Library
- Add SectionAccessLibrary authorization policy
- Add library mapping to SectionMapper
- Grant Library section access to Administrators, Writers, and Editors on fresh install
- Update TreeAccessElements to use Library section
* Add Element tree controller authorization tests
Add integration tests for RootElementTreeController and
ChildrenElementTreeController to verify section-based
authorization works correctly for the Element tree endpoints.
* Fix ReadOnlyUserGroup not passing startElementId to constructor
The obsolete 13-parameter constructor was passing `null` instead of
the actual `startElementId` value to the next constructor, causing
user groups to appear to have no element start node access.
Also update UserFactory.ToReadOnlyGroup to pass the Description
parameter to the ReadOnlyUserGroup constructor.
* Add Element controller authorization tests
Add authorization tests for Element CRUD, Folder, RecycleBin, and Item
controllers to verify user group access permissions.
Tests cover Admin, Editor, Writer, SensitiveData, Translator, and
Unauthorized user groups for each controller endpoint.
* Re-generated OpenApi.json
* Fix Element start node handling to use ElementContainer object type
- Update UserStartNodeFolderTreeControllerBase to query both folder and
item object types when filtering by user start nodes
- Fix UserGroupPresentationFactory to use ElementContainer instead of
Element when resolving element start node IDs/keys
* Revert ByKeyElementController to use synchronous Task.FromResult
The method doesn't have any async operations, so async/await adds
unnecessary overhead.
* Fix UserPresentationFactory to use ElementContainer for element start nodes
Element start nodes reference ElementContainer (folders), not Element items.
* Add recycle bin start node access test for Element controllers
- Add WithStartElementId to UserGroupBuilder
- Add ElementRecycleBinControllerTestBase with shared test verifying
users with non-root element start nodes cannot access recycle bin
- Update all Element recycle bin tests to use the new base class
* Fix UserGroupPresentationFactory and Element test section alias
- Use ElementContainer instead of Element for start node lookups in
IReadOnlyUserGroup overload
- Use Constants.Applications.Library for Element test section alias
* Add obsolete User constructor overload for backward compatibility
- Add obsolete constructor without startElementIds parameter that delegates
to the new constructor with an empty array
- Improve XML documentation for all User constructors
* Elements: Move NoAccess property to FolderTreeItemResponseModel base class
This allows both elements and folders to indicate access status in the tree.
* Elements: Add API versioning attributes to SiblingsElementTreeController
* Elements: Add integration tests for element tree start node permissions
Add tests to verify that users with element start node restrictions can only see
and access elements within their permitted hierarchy.
* Group test files
* Remove type check from GetAllPaths overload
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Elements: Add rollback (#21393)
* Services, repos and tests
* Endpoints for Elements versioning
* Add extra test to prove handling of pinned versions
* Renaming from PR review
* Update tests/Umbraco.Tests.Integration/Umbraco.Infrastructure/Services/ElementVersionCleanupServiceTest.cs
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* More code clean-up after review
* Use correct deleting/deleted versions notifications
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Elements: Regenerate OpenApi.json
* Elements: Add default and granular permissions for Element controllers (#21385)
* Add Element start node support for Users and UserGroups
- Add StartElementId to UserGroup and element start nodes to User
- Add UserStartNodeFolderTreeControllerBase for tree filtering with folder support
- Update ElementTreeControllerBase to use start node filtering
- Add ElementTreeItemResponseModel.NoAccess property for "no access" items
- Add UserExtensions methods for element start node calculation
- Update User/UserGroup API models and factories
- Add database migration for startElementId column
- Add SectionAccessForElementTree authorization policy
Note: Granular element permissions deferred for future implementation
* Add element root access for default user groups on fresh install
Set StartElementId = -1 for Administrators, Writers, Editors, and
Translators user groups in DatabaseDataCreator, giving them element
root access on fresh installations (matching their content/media access).
* Add multi-type support to UserStartNodeEntitiesService
Added overloads to RootUserAccessEntities, ChildUserAccessEntities, and
SiblingUserAccessEntities that accept multiple UmbracoObjectTypes. This
enables querying for Elements and ElementContainers in a single call
rather than requiring separate queries for each type.
Also added GetAll and GetPagedChildren overloads to IEntityService and
IEntityRepository to support querying multiple object types efficiently
with a single database query.
* Add integration tests for Element start nodes with mixed hierarchy
Added UserStartNodeEntitiesServiceElementTests with a mixed hierarchy
structure containing both containers and elements at each level:
- Level 1: Containers (C1-C5) and Elements (E1-E3)
- Level 2: Child containers (C1-C1 through C1-C10) and Elements (C1-E1, C1-E2)
- Level 3: Leaf elements (C1-C1-E1 through C1-C1-E5)
This tests scenarios where containers and elements are siblings, ensuring
the access filtering works correctly for mixed-type queries.
Also refactored Content and Media tests to use a shared base class
(UserStartNodeEntitiesServiceTestsBase) to reduce code duplication.
* Add Library section for Elements
- Rename Constants.Applications.Elements to Library
- Add SectionAccessLibrary authorization policy
- Add library mapping to SectionMapper
- Grant Library section access to Administrators, Writers, and Editors on fresh install
- Update TreeAccessElements to use Library section
* Add Element tree controller authorization tests
Add integration tests for RootElementTreeController and
ChildrenElementTreeController to verify section-based
authorization works correctly for the Element tree endpoints.
* Fix ReadOnlyUserGroup not passing startElementId to constructor
The obsolete 13-parameter constructor was passing `null` instead of
the actual `startElementId` value to the next constructor, causing
user groups to appear to have no element start node access.
Also update UserFactory.ToReadOnlyGroup to pass the Description
parameter to the ReadOnlyUserGroup constructor.
* Add Element controller authorization tests
Add authorization tests for Element CRUD, Folder, RecycleBin, and Item
controllers to verify user group access permissions.
Tests cover Admin, Editor, Writer, SensitiveData, Translator, and
Unauthorized user groups for each controller endpoint.
* Re-generated OpenApi.json
* Fix Element start node handling to use ElementContainer object type
- Update UserStartNodeFolderTreeControllerBase to query both folder and
item object types when filtering by user start nodes
- Fix UserGroupPresentationFactory to use ElementContainer instead of
Element when resolving element start node IDs/keys
* Revert ByKeyElementController to use synchronous Task.FromResult
The method doesn't have any async operations, so async/await adds
unnecessary overhead.
* Fix UserPresentationFactory to use ElementContainer for element start nodes
Element start nodes reference ElementContainer (folders), not Element items.
* Add recycle bin start node access test for Element controllers
- Add WithStartElementId to UserGroupBuilder
- Add ElementRecycleBinControllerTestBase with shared test verifying
users with non-root element start nodes cannot access recycle bin
- Update all Element recycle bin tests to use the new base class
* Fix UserGroupPresentationFactory and Element test section alias
- Use ElementContainer instead of Element for start node lookups in
IReadOnlyUserGroup overload
- Use Constants.Applications.Library for Element test section alias
* Add obsolete User constructor overload for backward compatibility
- Add obsolete constructor without startElementIds parameter that delegates
to the new constructor with an empty array
- Improve XML documentation for all User constructors
* Elements: Add granular permissions for Element controllers
Add Element-specific permission actions:
- ActionElementBrowse, ActionElementNew, ActionElementUpdate, ActionElementDelete
- ActionElementPublish, ActionElementUnpublish, ActionElementMove, ActionElementCopy
Add permission infrastructure:
- ElementPermissionResource for authorization checks
- ElementPermissionHandler and ElementPermissionRequirement
- ElementPermissionService and IElementPermissionService
- ElementPermissionAuthorizer and IElementPermissionAuthorizer
- ElementGranularPermission model
- ElementPermissionMapper for user group permissions
Update Element controllers with authorization:
- Add HandleRequest pattern via CreateElementControllerBase and UpdateElementControllerBase
- Pass cultures for Publish/Unpublish authorization
- Apply authorization checks to Element CRUD and publishing operations
* Elements: Add default element permissions to user groups
Add element action permissions for Admin, Editor, Writer, and Translator
user groups in DatabaseDataCreator, mirroring the document permission pattern.
* Elements: Add current user element permissions endpoint and fix folder authorization
- Add GetElementPermissionsCurrentUserController endpoint to get current user's element permissions
- Fix ElementPermissionService to authorize both Element and ElementContainer (folders)
- Add GetElementPermissionsAsync to IUserService/UserService
- Add ElementNodeNotFound to UserOperationStatus
- Add IEntityService.GetAll overloads for multiple object types
* Elements: Move NoAccess property to FolderTreeItemResponseModel base class
This allows both elements and folders to indicate access status in the tree.
* Elements: Add default implementation to IUserService.GetElementPermissionsAsync
Adds a default throwing implementation to avoid breaking existing IUserService implementations when this method is added.
* Elements: Add API versioning attributes to SiblingsElementTreeController
* Elements: Add integration tests for element tree start node permissions
Add tests to verify that users with element start node restrictions can only see
and access elements within their permitted hierarchy.
* Add granular permissions to element rollback
* Update src/Umbraco.Core/Actions/ActionElementCopy.cs
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Elements: Use lowercase action aliases for consistency
Update all Element action aliases to lowercase to comply with the
IAction.Alias requirement for case-sensitive filesystems. Also rename
ActionElementNew alias from "elementNew" to "elementcreate" to match
the document action's "create" alias pattern.
* Elements: Refactor UserService permission methods to reduce duplication
Consolidate GetMediaPermissionsAsync, GetDocumentPermissionsAsync, and
GetElementPermissionsAsync into a single shared implementation via
a new private GetContentPermissionsAsync helper method.
---------
Co-authored-by: kjac <kja@umbraco.dk>
* Add element folder "item" endpoint
* Include "isTrashed" in folder response models
* Update TODOs
* Rollback a few unnecessarily breaking signature changes
* Use schema constants from #21327
* Elements: Add admin group element permissions during upgrade (#21452)
Grant the admin user group access to the element root node and all
element permissions when upgrading from a previous version. This
ensures parity with fresh installations where the admin group receives
these permissions by default.
* Elements: Fix Writer expected status codes in Element controller permission tests
Update WriterUserGroupAssertionModel to expect Forbidden for operations
that Writers don't have permission for, matching Document controller
behavior and the actual permissions assigned to the Writer group.
Changed from OK/Created to Forbidden:
- CopyElementControllerTests
- DeleteElementControllerTests
- MoveElementControllerTests
- MoveToRecycleBinElementControllerTests
- PublishElementControllerTests
- UnpublishElementControllerTests
- Folder/DeleteElementFolderControllerTests
- Folder/MoveElementFolderControllerTests
- Folder/MoveToRecycleBinElementFolderControllerTests
- RecycleBin/DeleteElementRecycleBinControllerTests
- RecycleBin/DeleteElementFolderRecycleBinControllerTests
- RecycleBin/EmptyElementRecycleBinControllerTests
* Elements: Fix duplicate column name in DocumentVersionDto index definition
The ForColumns parameter incorrectly specified PublishedColumnName twice
instead of IdColumnName and PublishedColumnName, causing SQL Server to
reject index creation with "duplicate column names" error on new installs.
* Add missing element mapper and allow deleting element types with active elements (#21483)
* Add missing element mapper and allow deleting element types with active elements
* Update src/Umbraco.Core/Services/ContentTypeService.cs
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Update src/Umbraco.Core/Services/ContentTypeService.cs
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
---------
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
* Update src/Umbraco.Core/Cache/Refreshers/Implement/ElementCacheRefresher.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Review comment: ReadOnlyUserGroup constructor
* Update comments in ElementEditingService
* Add Library section access to content, media, and member tree policies
* Elements: Add Elements access to data type, document type, and relation authorization policies (#21501)
Add Elements access to data type, document type, and relation authorization policies
* Amend merge from v18/dev
* Global Elements: Backoffice UI implementation (#21410)
* chore: generate new openapi types
* Added package/module for "Library"
* Added default dashboard for Library section
* [WIP] Adds "Elements" package module
Basics of the tree/menu.
* Adds entity-actions for Create and Reload
* Adds entity-action for Move To
* Adds collection workspace view
for root and folders
* Adds entity-action for Duplicate To
* "Reload Children" should only be for root & folders
* Reworked Library sidebar app
Replaced with Elements sidebar app
Removed the Library menu
* chore: generate new openapi types
* Added Item repository
* Added Reference repository
* Added Element Recycle Bin
Tree, menu, entity-actions, workspace (collection view)
* Adds "umb-element-tree-item" to identify the `isTrashed` state
* Re-added Library sidebar app
Removed Library dashboard (we'll figure it out later)
* Recycle Bin type tweaks
* [WIP] Element "Create" modal
* Reverted Element "Create" modal, to use create-options + picker
* chore: generate new openapi types
* Added Element Detail Repository
* [WIP] Element Workspace + Context
* Elements: Add workspace views for edit and info
Add edit and info workspace views to the Element workspace:
- Edit view using shared 'contentEditor' kind pattern
- Info view displaying state tag, dates, element type, and ID
- Menu structure context for tree navigation
- Split-view component for variant editing
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Elements: Add save action and trash state handling
- Add Save workspace action using UmbSubmitWorkspaceAction
- Add isTrashed property to UmbElementDetailModel
- Implement trash state change handling with read-only guard
- Add recycle bin event listeners for trash/restore actions
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Adds Workspace actions for Save, Publish, Scheduled Publish
* Adds Element Configuration repository
* Adds mock handle + data for Elements
* Adds Publish and Unpublish entity actions for Elements
Implements context menu actions for publishing and unpublishing elements
directly from the tree. Uses existing modals and publishing repository.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* package-lock.json update
* Adds bulk entity actions for Publish, Unpublish, Move and Trash
* Localization keys + code tweaks
* Adds reusable `emptyRecycleBin` `collectionAction` kind
* Adds `emptyRecycleBin` for Element Recycle Bin collection
* Element Recycle Bin refactoring
Working towards folder support
* Relations: exported entity-action types
* Restructured "Element Folder" code
* Restructured "Trash" entity-bulk-action code
* Adds `trashFolder` `entityAction` kind
* Adds "Trash" entity-action for Element Folders
* Tidy-up / restructuring
* [WIP] Element Picker property-editor UI
making use of an Elements property-data-source,
with Entity Picker.
* Renamed `UmbElementPropertyDatasetContext` to `UmbElementWorkspacePropertyDatasetContext`
to de-duplicate a class name clash with the underlying base class.
* Added "entity-data-picker" importmap
Exposing the "umb-input-entity-data" component
* Reworking the "Element Picker" property-editor UI
to reuse the Entity Picker internal input component
* Implemented "Element Item Data Resolver" helper
* chore: generate new openapi types
* Fixed up the mocks and types
with new Element start nodes and `noAccess` fields.
* Added UI for "Elements Start Nodes"
* Added "entity-data-picker" export to the Vite config
* Fixed Element Folder picker for "start nodes"
* Adds UI for Element's User Permissions
* Adds Element User Permission condition
Implemented the user permissions for entity actions, etc.
* Adds UI for Element's Granular Permissions
* Adds element-folder item repository
* Element Recycle Bin: implemented `isTrashed`
* Fixed mock folder data manager
* Adds move entity-action for element-folder
Implements the Move action for element folders using the
ElementService.putElementFolderByIdMove API endpoint.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix typos and element tag name mismatches in elements package
- Fix typo 'now' -> 'no' in user-permissions/types.ts
- Fix HTMLElementTagNameMap tag name to match @customElement decorator
- Fix typo 'TDOD' -> 'TODO' in element-detail.server.data-source.ts
- Fix missing 'u' prefix in element-picker tag name declaration
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Ignore local Claude settings in UI Client
* Updated workspace assign access,
to disable root access when start nodes are selected.
* Elements: Display trashed state in Element workspace info panel (#21542)
The state tag in the Element workspace info view was missing a case
for the TRASHED state, causing trashed Elements to incorrectly display
"Not created" instead of "Trashed".
* Elements: Fix folder link in recycle bin list view (#21543)
The trashed element name column always used the element workspace path
pattern, causing folders clicked in the recycle bin list view to show
"Not found". Now checks isFolder and uses the correct workspace path
pattern for folders vs elements.
* Elements: Add missing delete permission conditions to recycle bin actions (#21547)
The Empty Recycle Bin collection action and the folder delete entity
action were missing user permission conditions, making them visible
to users without delete permission.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: leekelleher <leekelleher@gmail.com>
Co-authored-by: Laura Neto <12862535+lauraneto@users.noreply.github.com>
Co-authored-by: Lee Kelleher <leekelleher@users.noreply.github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* quote table, column and alias names with SqlSyntaxProvider methods in raw sql
* refactoring private methods into new file as internal methods,
refactor new extensions into another file
* refactor GetAlias method
* Double check the change
* improve code health
* change new static classes into public static partial class NPocoSqlExtensions
* resolve some Copilot review suggestions
* revert Copilot suggestion because it decreases code health
* revert test
* revert refactoring for CodeScene
* delete obsolete Test
* remove new methods and updates, which are not relevat for this PR
* prepare for additional states in the future
* don't mix string building methods
* fix SQL injection danger
* fix test for reverted methods
* another SqlSyntax issue
* Add additional unit and integration tests verifying the refactorings made in the PR.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Remove the default empty target tag for links, so the target attribute is only output when it has a value.
* Tiptap Link extensions: defaults `target` value to `null`
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Squash merged "v173/20453-21446-21448-FirstOrDefault-vs-ExecuteScalar" into "v173/21448-FirstOrDefault-vs-ExecuteScalar"
* resolce Copilot code review comments
* revert to ExecuteScalar<string>
* revert to Database.ExecuteScalar<string>
* revert .FirstOrDefault<long>(query) and its async variant to .ExecuteScalar<long>(query). It is fine for PostgreSql too.
* Remove the test added for verifying NPoco behaviour (it's not needed in the code base moving forward)
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Exclude invariant options for culture-variant properties in preset builder
* Add unit test verifying the fix.
* added a few more unit tests
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
improvement(web): make ProfilingViewEngine._inner private and modernize string formatting
- Changed internal readonly Inner field to private readonly _inner field
- Replaced string.Format calls with string interpolation
- Removed TODO comment
* Skip leading whitespace in ufm parser
* UFM: Update start function to also skip leading whitespace
The tokenizer was updated to allow whitespace after opening braces,
but the start function still used a string pattern without whitespace
tolerance. This updates start to use a pre-compiled regex that matches
the tokenizer behavior, and adds an additional test case for the
documentation example format.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Upgraded Tiptap to v3.13.0
* Remove eslint disable comments
* Update notes in externals
* `TextDirection` is now part of Tiptap core
* Upgraded Tiptap to v3.16.0
* The `addOptions()` typing error still persists in v3.16.0
* Resolved the export issue
* Removed unrequired `@ts-expect-error`
This came from an upstream merge.
* Move MediaTree write lock before MediaSavingNotification to prevent deadlock
Fixes a deadlock that could occur when saving multiple media items in parallel
when a MediaSavingNotification handler acquires a MediaTree read lock. The
previous ordering allowed two threads to each acquire read locks in their
notification handlers, then both attempt to upgrade to write locks, causing
a classic lock upgrade deadlock in SQL Server.
By acquiring the write lock before publishing the notification, the deadlock
scenario is avoided. Since the write lock is lazy, it only materializes at the
database level when actual queries are made, so notification handlers doing
in-memory work won't hold the lock.
* Apply same fix to MediaService.Delete method
* Apply same fix to DeleteVersions, DeleteVersion, and Sort methods
* Apply same fix to ContentService methods
Move WriteLock before notifications in:
- Save (single and batch)
- Delete
- DeleteVersions
- DeleteVersion
- Copy
* Apply the same pattern to MemberService.
* Add integration tests to verify the fix.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added tests for multi url picker validation message
* Added more tests - not done
* Updated more tests for multi url picker validation message
* Removed unused file
* Bumped version
* Make tests run in the pipeline
* Reverted npm command
* added color variable to code-block to make it readable in dark mode
* Update src/Umbraco.Web.UI.Client/src/packages/core/components/code-block/code-block.element.ts
Co-authored-by: Andy Butland <abutland73@gmail.com>
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Prevent creation of media items with GUID version 7 keys when a media scheme is registered that doesn't support this GUID version.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix log message formatting.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* Add support to models builder for nested generic types.
* Fixed existing warnings, added further tests, renamed tests for clarity.
* Add defensive validation for generic brackets passed to SplitGenericArguments.
* Fix failing unit tests.
* Content types: Allow adding composition with clashing property alias when property is being removed
* Further assert on property coming from the composition.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Block editors: Fix false pending changes indicator for invariant BlockList with culture-variant blocks (closes#21223)
When a document with a culture-variant content type has an invariant BlockList property containing culture-variant blocks, and you publish all languages for the first time, the content would incorrectly show as having unpublished changes.
The root cause was inconsistent JSON serialization order between EditedValue and PublishedValue. Two fixes were applied:
1. Sort block item values by culture before serialization in both `FromEditor` and `MergePartialPropertyValueForCulture` to ensure consistent ordering.
2. Add `[JsonIgnore]` to `BlockItemData.Udi` property since this computed property differs between save and publish paths.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Update tests/Umbraco.Tests.Integration/Umbraco.Infrastructure/PropertyEditors/BlockListElementLevelVariationTests.Publishing.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fixed failing integration tests.
* Fix backwards compatibility for legacy UDI format in JSON deserializatio
* Tidy up, remove unused parameters.
* Fixed failing E2E test with copy blocks.
* Separate handling of udi and values in deserialization from current and legacy format, to correctly fix previously failing integeration and E2E tests.
* Fixed failing unit test.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adds link (`umbLink`) support to the Style Menu api
* Tiptap RTE: Fix toggleClassName to handle multi-class strings
The toggleClassName command now properly tokenizes the className parameter
to handle space-separated classes (e.g., "btn btn-primary"). Previously,
the entire string was treated as a single token, causing duplicates and
preventing class removal.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Tiptap RTE: Add ensureUmbLink command for idempotent link creation
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Backoffice: Redirect to list view after entity deletion
When an entity is deleted from its detail workspace, the UI now redirects
to the parent list view and shows a success notification instead of staying
on the deleted entity's page showing a 404 error.
Changes:
- Dispatch UmbEntityDeletedEvent after successful deletion
- Show success notification toast on deletion
- Listen for delete event in workspace editor and navigate to backPath
* Integration tests for #21138
* Make OpenId redirect and postlogout uris support load balanced environments
* Applied review suggestions
* Fix unit test mocks
* Introduce new method overloads and repository implentation, such that a collection view response only loads properties it needs.
* Use non-obsolete method overloads throughout.
* Add unit tests to verify property value retrieval.
* Don't load templates for collection view content retrieval.
* Optimize access checks by verifying the full collection rather than one at a time, and avoid the need to retrieve full content items.
* Added obsoletion messages and aligned behaviour of content and media permission service checks.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Return key in TreeEntityPath collection response, avoiding a later look-up of the key by Id.
* Resolve breaking changes to interfaces.
* Fix further breaking change.
* Additional assert for test verifying property loading for a non-existing property.
* Refactored repositories to avoid having method parameters related to templates on non-document and base content repositories.
* Remove check that verifies all provided keys are found when doing permission checks (although arguably correct, it's a behavioural change, and can also be argued it's corect as is).
* Introduce variable for permission set permissions.
* Provide functional default implementation on FilterAuthorizedAsync.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Squash merge Squash merged v173/20453-fix-more-sql-syntax-issues int v173/20453-fix-more-sql-syntax-issues-squash (copy of main)
* fix 2 unit test
* Replace nameof(DTO.COLUMN_NAME) by constant, because it leads to casing issues for case sensitive databses
* fix Copilot review comments
* resolve review comments
* replace more hard coded strings
* fix test
* fix review comments
* fix database schema
* fix database schema
* fix database schema and ResultColumn reference names
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* add comment from review
* fix two reference column names
* fix breaking change
* fix typo
* Remove unnecessary attributes
* mark 2 unsused DTO classes as obsolete
* reverted change of class UnionHelperDto adding [Column("...")] attributes again, because some integration tests for PostgreSQL provider fail without them. Again a case sensitivty issue.
* replace nameof reference names,
make all column name const consistent
* use NPoco dto instead of raw sql,
extend ISqlSyntaxProvider to handle some sql issues
* reduce complexity
* remove currently unsused extensions to ISqlSyntax
* add missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* add another missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* fix Copilot review comments and build errors
* update ISqlSyntaxProvider and SqlSyntaxProviderBase
* ensure GetPagedDescendants returns ordered by path entities as default
* resolve review comments
* fix review comments
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Migrations/Install/DatabaseSchemaCreator.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.PublishedCache.HybridCache/Persistence/DatabaseCacheRepository.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix Copilot comment
* fix wrong Copilot suggestion
* quote more column names
* resolve review
* Apply suggestions from code review
* synced interface and base class
* Revert "synced interface and base class". For an interface's default implementation, NotImplementedException makes more sense.
This reverts commit cf01cd01fc.
* Fixed remaining code warnings in DatabaseSchemaCreator.
* follow Cotpilot's review suggestion
* revert implementation and fix test
* use default
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adds reusable `emptyRecycleBin` `collectionAction` kind
* Adds `emptyRecycleBin` collection-action to documents
* Adds `emptyRecycleBin` collection-action to media
* Removes `api` export
since the condition is eagerly loaded.
* Fixes type annotations and JSDoc comments
- Uses correct generic type `UmbCollectionHasItemsConditionConfig` in `UmbCollectionHasItemsCondition`
- Corrects JSDoc `@augments` tag in `UmbEmptyRecycleBinCollectionAction`
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fixed linting errors
* Refactors execute() to reduce cyclomatic complexity
Extracts tree refresh logic into private #reloadChildrenOfEntity() method.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Update src/Umbraco.Web.UI.Client/src/packages/media/media/recycle-bin/manifests.ts
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Removed code comment
as caused ambiguity.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Disabled the generation and upload off the docfx csharp api docs.
* Add comment explaining why job is disabled
* Added comment on second job
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Added missing code documentation to the Umbraco.Cms.Api.Common project
* Remove duplicate XML summary for All constant
Removed duplicate XML summary documentation for the All constant.
* Removed inline comments no longer required now the information has been moved to XML header remarks
* Fix indentation on refactored path segment extraction in SubTypesSelector
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Squash merge Squash merged v173/20453-fix-more-sql-syntax-issues int v173/20453-fix-more-sql-syntax-issues-squash (copy of main)
* fix 2 unit test
* Replace nameof(DTO.COLUMN_NAME) by constant, because it leads to casing issues for case sensitive databses
* fix Copilot review comments
* resolve review comments
* replace more hard coded strings
* fix test
* fix review comments
* fix database schema
* fix database schema
* fix database schema and ResultColumn reference names
* Update src/Umbraco.Infrastructure/Persistence/Dtos/ContentTypeAllowedContentTypeDto.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* add comment from review
* fix two reference column names
* fix breaking change
* fix typo
* Remove unnecessary attributes
* mark 2 unsused DTO classes as obsolete
* reverted change of class UnionHelperDto adding [Column("...")] attributes again, because some integration tests for PostgreSQL provider fail without them. Again a case sensitivty issue.
* replace nameof reference names,
make all column name const consistent
* use NPoco dto instead of raw sql,
extend ISqlSyntaxProvider to handle some sql issues
* reduce complexity
* remove currently unsused extensions to ISqlSyntax
* add missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* add another missing methods to ISqlSyntaxProvider and SqlSyntaxProviderBase
* fix Copilot review comments and build errors
* update ISqlSyntaxProvider and SqlSyntaxProviderBase
* resolve review comments
* fix review comments
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Migrations/Install/DatabaseSchemaCreator.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.PublishedCache.HybridCache/Persistence/DatabaseCacheRepository.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Infrastructure/Persistence/SqlSyntax/ISqlSyntaxProvider.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix Copilot comment
* fix wrong Copilot suggestion
* quote more column names
* resolve review
* Apply suggestions from code review
* synced interface and base class
* Revert "synced interface and base class". For an interface's default implementation, NotImplementedException makes more sense.
This reverts commit cf01cd01fc.
* Fixed remaining code warnings in DatabaseSchemaCreator.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(log-viewer): prevent polling toggle reset when changing interval
Fixes issue where changing polling interval would reset the button to 'Polling' state instead of applying the new interval immediately.
- Remove togglePolling() call from closePoolingPopover() method
- Update setPollingInterval() to restart polling with new interval if already enabled
Fixes#21507
* refactor(log-viewer): extract polling start logic and fix regression
- Extract polling start logic into #startPolling() helper method
- Fix regression: enable and start polling when interval is selected while polling is off
- Update togglePolling() to use the helper method for consistency
Addresses feedback on PR #21508
---------
Co-authored-by: Gittensor Miner <miner@gittensor.io>
* Fix for the client side circular dependency.
This should fix the circular dependency without causing any breaking changes to the public APIs.
This issue is detailed here:
https://github.com/umbraco/Umbraco-CMS/issues/21463
* refactor UMB_MODAL_MANAGER_CONTEXT to avoid circular dependency
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Add 'is modal' condition to modal package
Introduces a new 'is modal' condition for extension manifests, allowing actions to be conditionally permitted based on modal context. Updates user collection action manifests to use this condition, preventing certain actions when inside a modal. Includes implementation, configuration, manifest registration, and tests for the new condition.
* rename from is modal to in modal
* added dicationary value search active only with config param set
* Removed code smell, by reducing nesting
* Renamed configuration value to EnableValueSearch.
Added integration tests to verify search results.
* update query to return correct values for each language in the overview
* Use OptionsMonitor and add additional assert to verify fix to indication of which languages have translations.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Sort at last by language name
* ensure document language picker is sorted as variant selector
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/modals/shared/document-variant-language-picker.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/workspace/components/workspace-split-view/workspace-split-view-variant-selector.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/utils.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* refactor to avoid inline methods
* transform into a function
* revert config file commit
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Sort at last by language name
* ensure document language picker is sorted as variant selector
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/modals/shared/document-variant-language-picker.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/workspace/components/workspace-split-view/workspace-split-view-variant-selector.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/documents/documents/utils.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* refactor to avoid inline methods
* transform into a function
* revert config file commit
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add alias property to collection config interface
Introduced an 'alias' property to the UmbCollectionItemPickerModalCollectionConfig interface
* render collection element when modal is configured with an alias
* expose a picker modal route
* use collection in use picker
* adjust spacing
* add config option for selectOnly
* dynamic modal alias
* support selectable entity item ref
* wip entity data picker collection + ref and card views
* Add entity collection item card extension type + default elements
* implement user collection item card
* fix selection events
* map to prop
* add prop/attr for href
* add support for which detail properties to show
* update type import
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/item/entity-collection-item-card/entity-collection-item-card.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* import card in correct file
* Fix event listener binding for selection events
* implement disabled property for collection item cards
* init commit of collection item ref extension
* fix imports
* add element interface
* Implement UmbEntityCollectionItemElement interface in item cards
Added the UmbEntityCollectionItemElement interface to document and user collection item card elements for improved type safety and consistency. Updated type exports to include the new interface.
* Update collection item ref to use uui-ref-node
Replaces the placeholder div with a uui-ref-node component, passing relevant item properties and event handlers. Adds dynamic icon rendering using umb-icon.
* Refactor entity collection item elements to use shared base
Introduces a new abstract base class for entity collection item elements, consolidating shared logic for card and ref variants. Updates card and ref element implementations to extend the new base, and refactors extension manifest interfaces for consistency. This improves maintainability and reduces code duplication.
* use class instead of magic string
* Use entity collection item card in picker view
Replaces the placeholder card markup with the <umb-entity-collection-item-card> component, enabling selection and deselection functionality for items in the entity data picker card collection view.
* Update entity item ref to collection item ref
Replaces <umb-entity-item-ref> with <umb-entity-collection-item-ref> in the picker collection view. Adjusts event handlers and select-only logic to improve selection behavior and component consistency.
* utilise ref and card kind for picker views
* introduce ref and card collection view kinds
* Utilise card kind for user collection view
* Add item-specific href support to collection views
Introduces a requestItemHref method to collection contexts for retrieving item-specific hrefs. Updates card, ref, and user table collection views to use these hrefs, enabling dynamic linking for collection items. Refactors user table name column layout to accept href via value prop instead of constructing it internally.
* Update ManifestCollectionView import path
Changed the import of ManifestCollectionView from '../extensions/types.js' to '../view/types.js' to reflect its new location.
* remove unused
* use size medium for entity collection item picker
* use box
* render entity actions
* use edit path builder for user links
* rename method
* Revert "rename method"
This reverts commit 4df577688e.
* Update collection-default.context.ts
* make type lint ignore unused args with an underscore
* temp remove unused
* only make collection vie selectable if there are any registered bulk actions
* don't render name link if there is no href
* fix imports
* Render selection actions only if bulk actions exist
* use selectable state
* Update language-table-collection-view.element.ts
* Update language-table-collection-view.element.ts
* Update card-collection-view.element.ts
* clean up
* Refactor collection views to use shared base class
* refactor(collection): parallelize href fetching and make method private
* docs(examples): update collection example to use card and ref kinds
* docs(examples): add icon property to collection example data model
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/default/collection-default.context.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/types.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update collection-bulk-action.manager.test.ts
* Removed duplicate and redundant '@typescript-eslint/no-unused-vars' rule definitions, consolidating the configuration to use only 'argsIgnorePattern'.
* Handle missing user href in name column layout
Replaces the user name link with a span when the href property is not provided, preventing broken links in the user table name column layout.
* Update user-table-name-column-layout.element.ts
* pass modal data and value to routable modal
* Update picker-input.context.ts
* support selectableFilter
* scaffolding of a collection text filter extension
* Refactor collection text filter to use API interface
* Fix incorrect tag
* Update types.ts
* Update collection-text-filter.extension.ts
* Add cancelation to debounced search on destroy
* clean up
* add js docs
* two way binding of filter value
* clean up
* Add collection text filter manifest example
Introduced a new filter manifest for the example collection and updated the main manifests file to include it. This enables a text filter extension for the example collection.
* Delete unused element and context
* Update src/Umbraco.Web.UI.Client/src/packages/user/user-group/collection/user-group-collection.context-token.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update user-group-table-collection-view.element.ts
* support search for tree item and collection item pickers
* add spacing between collection ref items
* add margin between picker search result items
* remove spacing after last item
* remove padding in search results
* Update collection-item-picker-modal.element.ts
* move select only logic to collection selection manager
* add tests for collection selection manager
* change to filter label instead of search
* delete unused user grid collection view
* Select-only mode is now only disabled when all items are deselected, rather than on every deselection.
* prepare umb table for pickers
* utilize UmbCollectionViewElementBase in user table collection view
* remove console log
* handle select all and select item from same event
* bulk actions workaround
* add bulk action in collections feature toggle
* remove unused method
* make fields optional to avoid a breaking change
* remove unused import
* fix typescript errors
* adjust search styling
* hide with css
* fix ts errors
* Add modal data support to picker input context
Introduces methods to set and get modal data in UmbPickerInputContext, allowing base configuration for picker modals. Updates modal data handling to merge stored modal data with provided data for both direct picker opening and modal route setup.
* Fix bulk action manager test initialization
Added calls to setConfig in tests to properly initialize the observer before subscribing to hasBulkActions. Simplified the test logic for checking emissions when actions are present.
* Update tree-picker-modal.element.ts
* Update picker-search-result.element.ts
* Update src/Umbraco.Web.UI.Client/src/packages/core/collection/view/umb-collection-view-element-base.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Use ifDefined for modal route in user input button
* Use ifDefined for href binding in entity data picker
* Fix collection alias binding in item picker modal
* wire up user table collection view with selectableFilter
* clean up controller aliases
* Update collection-item-picker-modal.element.ts
* Update collection-item-picker-modal.element.ts
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* enable async method
* ensure container is local to the owner content type
* no need to await anyhow
* handle moved groups
* Update src/Umbraco.Web.UI.Client/src/packages/content/content-type/workspace/views/design/content-type-design-editor-properties.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fixes#20665 - Password change error msg
In order to show the right validation message:
- the repository code always notifies the validation failure message
(or a default failure message if none is received)
- in the data-source code, tryExecute is called with the option
to disable the default notification
* Return the original error instead of faking success
---------
Co-authored-by: Emma L Garland <1649855+emmagarland@users.noreply.github.com>
* Implement document alias cache and service to optimize content finder by alias.
* Renamed to DocumentUrlAlias. Fixed issues on start-up.
* Remove tracking of root ancestor.
* Optimize cache key, tidy up tests, move domain matching to content finder.
* Handle language and document deletes.
* Align further with document URL service.
* Code tidy.
* Fixed comment.
* Refactor scope handling to avoid nested scopes
Extract CreateOrUpdateAliasesInternalAsync to process documents without
creating their own scope. Both CreateOrUpdateAliasesAsync and
CreateOrUpdateAliasesWithDescendantsAsync now create a single scope
and call the internal method, avoiding unnecessary nested scope creation.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Extract CreateOrUpdateAliasesInternalAsync to process documents without
creating their own scope.
* Only return a document for a match under a domain if the document is found under the domain of the current request.
* Fix failing integration tests.
* Apply suggestions from code review.
* Ensured language to culture code map is updated when a language isn't found in the cached map.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
fix(backoffice): resolve event listener memory leaks in auth, dropzone, actions, and router
Fixes memory leaks in 4 components where event listeners registered with .bind(this) could not be properly removed because each .bind() call creates a new function reference.
Changes:
- auth.context.ts: Convert #onStorageEvent to arrow function property
- dropzone-media.element.ts: Convert 4 drag handlers to arrow function properties
- entity-actions-dropdown.element.ts: Convert handler and add disconnectedCallback
- router-slot.element.ts: Convert handler and add proper cleanup in disconnectedCallback
Solution: Arrow function properties maintain consistent references while preserving 'this' context, enabling proper listener removal.
Testing:
- Added unit tests for auth.context.ts
- All builds pass
- Linter passes
- No breaking changes
Documentation:
- Added "Event Listener Cleanup Pattern" section to clean-code.md
- Added "Event Handler Guidelines" section to style-guide.md
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
* refactor(rte): Replace misleading Promise.all with sequential awaits
The inner awaits in Promise.all([await ..., await ...]) made the operations
sequential anyway. Since #loadEditor() depends on _extensions being populated,
sequential execution is correct - this change makes the intent clearer.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* perf(rte): Cache toolbar and statusbar emptiness checks
Instead of calling .flat() on every render to check if toolbar/statusbar
have items, compute the boolean once when values are set in #loadEditor().
This avoids unnecessary array operations during render cycles.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* perf(rte): Pre-compute extension styles during initialization
Instead of calling unsafeCSS() on each style during every render cycle,
collect and process styles once in #loadEditor() and store the result
in _extensionStyles. This avoids repeated CSS processing during renders.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
# Conflicts:
# src/Umbraco.Web.UI.Client/src/packages/tiptap/components/input-tiptap/input-tiptap.element.ts
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Adds `check:duplicate-class-names` devops script
* DevOps: Improve `check:duplicate-class-names` script
- Fix example path in JSDoc comment
- Add support for `export default class` declarations
- Add `--ignore-stories` flag to exclude story files from detection
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Added try/catch on reading file contents
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Resolved potential thread safety issues with PublishStatusService.
* Only update published status in content cache refresher if within a publish or unpublish operation.
* move media-type guid strings into constants partial
* missed one.
* Update src/Umbraco.Core/Constants-MediaTypes.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add member type GUID constants too.
* Removed member type incorrectly recorded as a built-in data type.
* Reuse constant in obsolete GUID constant.
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Remove rebuild of document URLs during migration, instead ensuring they will run after migration is complete and Umbraco is running.
* Avoid unnecessary second rebuild of document URL cache after startup with migration that has already triggered a rebuild.
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add a toggle, defaulted to off, for display of diffs on the rollback view.
* Used only label for checkbox.
* Align formatting across translations for diffHelp key.
* Changed the checkbox to a toggle
UI semantics, checkboxes imply selection, whereas toggles imply activation.
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* Prevent selection of document and member type folders when selecting allowed types for the content picker.
* Added fix for Media Types
* Set `documentTypesOnly` on `umb-input-document-type`
so to disallow selecting element-types.
* Linting
---------
Co-authored-by: leekelleher <leekelleher@gmail.com>
* fix: aligns media workspace with document workspace to handle "variants" when calculating routes, which fixes an issue where the "Access denied" view would not be shown
* fix: clear root access flag when selecting specific start nodes
When selecting specific document or media start nodes for a user, the UI now automatically sets hasDocumentRootAccess/hasMediaRootAccess to false.
Previously, if a user group had "Has access to all items" enabled, selecting specific start nodes on the individual user wouldn't clear the root access flag. This caused the backend to add -1 (root access) to the start node list, overriding the specific node selections.
This ensures user-specific start node permissions properly override group-level root access settings.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix: add length check to prevent rendering router with empty routes array
The render method now checks both that _routes exists AND has length > 0 before rendering the router-slot. An empty array is truthy, so without the length check, the router-slot could be rendered with an empty routes array, causing runtime errors.
This aligns with the original render logic and prevents the TypeError when media tests run.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fix E2E test URL construction for media workspace deep-linking
The test was constructing an invalid URL by appending the workspace path
directly to the current URL, which included '/collection'. This resulted in:
/umbraco/section/media/collection/workspace/media/edit/ (invalid)
Instead of the correct:
/umbraco/section/media/workspace/media/edit/
The fix removes '/collection' before appending the workspace path, ensuring
the test actually navigates to the workspace editor where the 'Access denied'
view is properly displayed.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Make all tests for media start node run in the pipeline - remember to revert before merging
* Revert npm command before merging
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Nhu Dinh <hnd@umbraco.dk>
* Document Tree: Filter tree items based on user browse permissions
- Add FilterTreeEntities virtual methods to EntityTreeControllerBase for filtering tree entities with total count adjustments
- Override FilterTreeEntities in DocumentTreeControllerBase to filter by ActionBrowse permission
- Extract filtering logic into IDocumentPermissionFilterService for testability
- Add unit tests for DocumentPermissionFilterService
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Complete the scope when no runnable job found. Without this I'm seeing timeouts and lock contention if a long-running document type save operation is running when the first distributed job is requested.
* Run serialization steps of rebuild of content cache in parallel for a small but not insignficant speed optimization.
* Add integration tests for database cache rebuild.
* Optimize rebuild of databaes and memory cache after content type update.
* Add debug log for running distributed job.
* Apply memory cache clear optimization to media.
* Optimize MediaCacheService.RebuildMemoryCacheByContentTypeAsync with lightweight query
Use GetMediaKeysByContentTypeKeys to fetch only media keys instead of loading full ContentCacheNode objects. This matches the same optimization applied to DocumentCacheService.
Also refactors Rebuild() to reuse RebuildMemoryCacheByContentTypeAsync for the memory cache clearing step.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Further updates from code review.
* Further tests for variant documents, composed documents and message pack serialization.
* Fixed failing integration tests.
* Clear the cacje level published content cache on content type change.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix: Resolve 128 SA1600 documentation warnings in Umbraco.Cms.Persistence.Sqlite
- Added XML documentation comments to interceptors, mappers, and services
- Added TODO (V18) comments to SqliteSyntaxProvider.Format methods (CS0114)
- Updated .csproj TODO comment to follow V18 convention
- CS0114 warnings remain suppressed as fix would be binary breaking
* Fixed the issues Copilot complained about with the documentation and..
Fixed two IDE0270 warnings (null check simplification).
* Code Quality: Fix CS0659 and CS0661 build warnings in Item test class
The Item class in test project defined Equals override and equality operators without implementing GetHashCode, causing CS0659 and CS0661 compiler warnings.
Added GetHashCode implementation using RuntimeHelpers.GetHashCode(this) for consistent reference-based equality matching the existing operators behavior.
Removed CS0659/CS0661 from WarningsNotAsErrors in test project as they are no longer needed.
* Code Quality: Remove unused test infrastructure classes
Remove Item, OrderItem, and SimpleOrder classes along with the SimpleOrder_Returns_Null_On_FirstOrDefault_When_Empty test.
These ~370 lines of test infrastructure existed only for a single trivial test that verified FirstOrDefault() returns null on an empty collection - behavior already tested on actual Umbraco collections in the same file.
* Refactor StringExtensions into multiple files using partial classes.
* Tidy/complete XML header comments.
* Fixed warnings in string extension methods.
* Add unit tests for IsLowerCase and IsUpperCase and optimize the methods.
* Add unit tests for ReplaceNonAlphanumericChars and optimize the method.
* Add unit tests for StringWhitespace and optimize the method.
* Add unit tests for StripHtml and DecodeFromHex and optimize the methods.
Fix too aggressive regex for StripHTML to ensure works only on HTML tags.
* Add unit tests for EnsureStartsWith and EnsureENdsWith and optimize the methods.
* Add unit tests for ToSingleLine and StripNewLines and optimize the methods.
* Fix issues raised in code review.
* Added the SA1649 to the "No Warnings" section.
Stylecop is trying to enforce filenames that are like:
CancellableObjectEventArgs{TEventObject}.cs
However Umbraco uses CancellableObjectEventArgs.cs
Unless a policy decision is make to follow this stylecop rule, I think it is better to add this rule to the " NoWarn " section, so we don't see it appear at all.
* Revert accidental package-lock.json change
* Renaming files to match the StyleCop patterns.
Except two which would end up having the same names as other file, so these have been renamed as LegacyIScope & LegacyIScopeProvider, with local Pragma warnings disabled for this Style Cop rule.
* Removing the SA1649 from Warnings NOT as Errors.
In other words, if you turn on show warnings as errors, these will show as errors, rather than being suppressed.
* change to static import
* add support for passing modules to manifest js property
* Replaces dynamic imports of entry-point.js with static imports across all manifests
* Support statically imported modules in loader functions
Extended loadManifestApi and loadManifestElement to handle already resolved module objects (statically imported modules) in addition to dynamic imports. Updated type definitions in utils.ts to include module export types for loader properties.
* Add tests for loadManifest* functions in extension-api
Introduces unit tests for loadManifestApi, loadManifestElement, and loadManifestPlainJs functions. These tests cover various scenarios including direct class constructors, dynamic and static imports, export prioritization, and edge cases for null and undefined inputs.
* Added folder and files for the new condition.
* Registered the condition.
* Added an example to test the condition.
* Added the condition in one of examples.
* Renamed condition.
* Fixed linting error.
* fix(a11y): Toast notifications not announced by screen readers in Chrome
- Move screen reader live region from Shadow DOM to Light DOM (document.body)
Chrome doesn't reliably detect ARIA live regions inside Shadow DOM
- Use role="alert" with fresh elements for each announcement instead of
updating text content of an existing live region
- Fix invalid aria-role="true" attribute (was invalid HTML)
- Fix missing backslash in unicode escape '\u00A0'
The previous implementation had the live region nested 3 levels deep in
Shadow DOM, which Safari handled but Chrome ignored. Creating a new
alert element in Light DOM for each announcement is the most reliable
method across browsers.
Closes#14521🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
* Removed comment.
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Update Umbraco version in starterkits template
LTS and Latest should both install 17.0.0, at the moment latest uses Umbraco v17.1.0 but a starter kit version 17.0.0-rc1 which is not a good combo
* Update LTS in template to 17.1.0
* Tree pickers: Implement noAccess property UI handling for user start nodes
- Add noAccess observable to document and media tree item contexts
- Add visual styling (grayed out, italic) for noAccess items in tree views
- Update document and media picker input contexts to prevent selection of noAccess items
- Items with noAccess are shown for navigation but cannot be selected in pickers
This implements the UI handling for Feature 63060 "Handle Start Nodes"
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix noAccess implementation and add E2E tests
This commit combines all improvements made to the noAccess property feature:
1. Refactored to use Lit lifecycle methods (updated()) instead of property watchers
2. Added click and keyboard event handlers to prevent navigation
3. Removed disabled attribute that was blocking tree expansion
4. Added comprehensive E2E tests for document and media trees
Critical bug fix: Removed disabled attribute that prevented expansion
- The disabled attribute was blocking ALL interactions including expanding
tree items to show accessible children underneath noAccess ancestors
- Now only sets aria-disabled="true" for screen readers and removes href
- Click and keyboard event handlers still prevent navigation as intended
- Users can now properly navigate through noAccess ancestors to reach
their accessible child nodes
E2E test coverage:
- Display noAccess styling (opacity, italic)
- Prevent navigation when clicking noAccess nodes
- Allow expansion of noAccess nodes to show children
- Picker tests skipped pending infrastructure improvements
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Remove aria-disabled manipulation that interferes with tree expansion
The previous implementation set aria-disabled="true" and removed href
from the menu-item in #updateMenuItemAccessibility(). This approach
caused issues with tree expansion functionality.
Removed:
- #updateMenuItemAccessibility() method
- updated() lifecycle hook that called it
- UUIMenuItemElement import (no longer needed)
The click and keyboard event handlers already prevent navigation to
noAccess nodes, so additional DOM manipulation is not necessary.
Test results:
✅ 4 passing: Display styling and prevent navigation work correctly
❌ 2 failing: These appear to be backend issues:
1. Document expansion: Caret button disabled (backend marking noAccess
items as not selectable, which disables entire menu-item)
2. Media expansion: Child media folder incorrectly has noAccess attribute
(backend data issue - child should be accessible as it's the start node)
The UI implementation is sound. The remaining test failures indicate
backend API issues that need investigation.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fix path comparison bug in UserStartNodeEntitiesService (similar to #21162)
This fixes the same path comparison bug we fixed in PR #21162 but in C# string
comparisons instead of SQL queries.
## Root Cause
Path comparisons without trailing commas caused false matches:
- Path "-1,1001" incorrectly matched prefix "-1,100"
- This marked nodes as ancestors/descendants when they weren't related
## Examples of False Matches
- child.Path = "-1,1001", startNodePath = "-1,100"
- OLD: "-1,1001".StartsWith("-1,100") = TRUE (bug!)
- NEW: "-1,1001,".StartsWith("-1,100,") = FALSE (correct!)
- child.Path = "-1,100", startNodePath = "-1,1001"
- OLD: "-1,1001".StartsWith("-1,100") = TRUE (bug!)
- NEW: "-1,1001,".StartsWith("-1,100,") = FALSE (correct!)
## Fix Applied (Two Locations)
1. Line 146 (ancestor check): Added comma suffix to child.Path
2. Line 226 (IsDescendantOrSelf): Added comma suffix to both paths
This matches the pattern already used correctly in lines 92 and 191 of the
same file, and mirrors the SQL fix from PR #21162.
## Test Impact
This should fix the failing E2E test where child media folders were incorrectly
marked as noAccess when they were actually the user's start node.
Related: #21162
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fix remaining merge conflict markers in media-tree-item.element.ts
* Remove E2E agent markdown file (moved to personal space)
* test: adds mock data for noAccess
* feat: moves noAccess subscriber to base class
* test: adds mock data for media
* feat: moves no-access styling to the base class
* fix: media tree items should inherit styling from the base class
* feat: observes noAccess from children and reports back to the base class
* test: spec file should use undefined instead of null
* docs: add comprehensive comments explaining noAccess opt-in pattern
- Document why noAccess is not in base interface (breaking change)
- Explain opt-in pattern with code examples
- Add JSDoc comments to property, event handlers, and CSS
- Reference accessibility considerations (keyboard users)
- Link child class implementations to base class documentation
* test: adds timeout for URL to settle
* fix: allow clicks on accessible children of noAccess tree items
When a tree item has noAccess, child tree items are rendered in its slot.
Previously, the parent's click handler blocked ALL clicks due to event bubbling,
preventing users from navigating to accessible descendants.
Now checks if click originated from a child tree item element using closest().
If it's a child, allow the click. Only block clicks on the noAccess item itself.
Applied to both mouse clicks and keyboard navigation (Enter/Space).
This enables users to navigate through noAccess ancestors to reach their
accessible start nodes (e.g., Root[noAccess] → Child[noAccess] → Grandchild[accessible]).
Fixes tests:
- should allow expansion of noAccess ancestor node to show children (documents)
- should allow expansion of noAccess ancestor media node to show children (media)
* compare with the closest element to see if we are clicking on the element that is blocked or a sub-element that is not
* fix: adds forbidden route in case of no variants
* test: corrects label locator
* test: adds test to check if you can click or deeplink to restricted media
* test: removes .only
* test: removes duplicated tests
* test: adds test for document no-access
* test: add unit tests for user start node path comparison logic
Adds comprehensive unit tests documenting the path comparison fix that prevents
false matches when node IDs are numeric prefixes of other IDs (e.g., 100 vs 1001).
The fix uses trailing commas on both paths to ensure accurate comparison:
- Without fix: "-1,100".StartsWith("-1,10") = true ❌ (incorrect)
- With fix: "-1,100,".StartsWith("-1,10,") = false ✅ (correct)
Tests cover:
- Numeric prefix edge cases (1 vs 10, 10 vs 100, 100 vs 1001)
- Self comparison (start node itself)
- Descendant relationships
- Deep path hierarchies
- Demonstrates the bug without the fix for documentation
19 test cases total, all passing.
* test: removes .only
* fix: do not overwrite forbidden route
* docs: fixes line number in comment
* test: fixes comment
* feat: uses isSelectableContext to disable and scrub 'href' from base element
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adjust build scripts for custom elements and JSON schema generation to be placed at root level, add generation to build for npm and update .gitignore
* fix: updates umbraco package schema location
* git ignores
* fix: outputs the vscode custom elements file at root
* fix: adds generated files to output
---------
Co-authored-by: Jacob Overgaard <752371+iOvergaard@users.noreply.github.com>
* fix(backoffice): use hardcoded Umbraco logo in header popover
Fixes issue where the backoffice header logo popover incorrectly
displayed the LoginLogoImageAlternative setting instead of showing
the Umbraco branding.
Changes:
- Added hardcoded umbraco-logo.svg asset to client project
- Updated backoffice-header-logo component to reference static logo
- Wrapped logo in link to umbraco.com
- Removed dependency on BackOfficeLogo endpoint for popover
The small header logo button still uses <umb-app-logo> and remains
customizable via the BackOfficeLogo setting.
Closes#62866
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* chore: removes link to umbraco.com
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
* fix(media-picker): auto-select uploaded media items
When uploading media in the media picker modal, uploaded items are now
automatically selected. This works for both single and multiple selection
modes, and correctly handles paginated folders where uploaded items may
not be visible on the current page.
Closes#21115🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix(media-picker): navigate to last page after upload
Uploaded media items get the highest SortOrder, placing them on the last
page. This change navigates to the last page after upload so users can
see their newly uploaded items, which are also auto-selected.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Update src/Umbraco.Web.UI.Client/src/packages/media/media/modals/media-picker/media-picker-modal.element.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Added tests to create a user group with description
* Clean up
* Moved tests for user group description to other class
* Bumped version
* Make tests run in the pipeline
* Reverted npm command
* Optimize retrieval of ContentCacheNode for draft and publish in when refreshing the hybrid cache.
* Fixed issue with XML header documentation tags.
* Use is null for consistency
---------
Co-authored-by: mole <nikolajlauridsen@protonmail.ch>
Add resilience to ServerEventRouter to prevent failures during unattended
install/upgrade when SignalR (especially Azure SignalR) is configured.
Changes:
- Skip server event routing when runtime level is not Run (Install/Upgrade)
- Add try-catch with warning logging for graceful degradation on SignalR failures
- Add backwards-compatible obsolete constructor using StaticServiceProvider pattern
- Add unit tests for runtime level checks
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
- Add UMB_WORKSPACE_EDIT_PATH_PATTERN and UMB_WORKSPACE_EDIT_VARIANT_PATH_PATTERN
to core workspace paths for generic edit URL generation
- Fix UmbPathPattern to support multi-level chaining via toAbsolutePatternString()
- Refactor workspace-menu-breadcrumb to use new path patterns
- Refactor menu-variant-tree-structure-workspace-context-base to use new patterns
- Refactor tree-item-context-base to use UMB_WORKSPACE_EDIT_PATH_PATTERN
- Refactor user-grid-collection-view to use existing UMB_EDIT_USER_WORKSPACE_PATH_PATTERN
- Remove outdated TODO about encoding uniques (handled at data source)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* fix(stylecop): resolve SA1106 - remove empty statement
* fix(stylecop): resolve SA1400 - add missing access modifiers
* fix(stylecop): resolve SA1028 - remove trailing whitespace
* fix(stylecop): resolve SA1306 - rename fields to lowercase
* fix(stylecop): resolve SA1130 - use lambda syntax
* fix(stylecop): resolve SA1121 - use built-in type aliases
* fix(stylecop): resolve SA1405 - add messages to Debug.Assert calls
* fix(stylecop): resolve SA1649 - rename files to match type names (partial)
* fix(stylecop): resolve SA1401 - convert fields to const/readonly (partial)
* fix(stylecop): resolve SA1116 - reformat multi-line parameters (partial)
* fix(stylecop): revert breaking changes, add V18 TODO comments
* fix: correct TODO comment for SA1306 - should rename to _completed
* Standardize API file names across modules - No code changes, file names.
- Extracts login model to a dedicated file and preserves binding behavior
- Renames multiple API files to align with updated conventions ( Just to match their names in the code, not changing the actual API names, i.e. no breaking changes )
- Updates DI extensions, mappings, and OpenAPI helpers to follow new naming
- Adjusts tests for consistent formatting and readability
- Preserves behavior; no logic changes, references kept intact
* fix(tests): refactor UserEmail to virtual property pattern
- Convert protected field _userEmail to virtual property UserEmail
- Remove dead code (_userEmail += "groupName" executed after request)
- Update derived test classes to use property instead of field
- Maintains original name to avoid breaking changes
- Follows best practice: virtual property allows derived class override
This was originally changed in my PR from UserEmail to _userEmail, so changing it back to ensure no breaking change, even though this is in a test class.
* Committing small fix to prevent a breaking change, adding commit for future removal.
* Renames helper class and removes BOM
Renames internal helper to follow naming conventions without the T prefix
Removes stray BOM from header to ensure clean compilation
No runtime behavior changes
* Split Physical FileSystem interface into it's own file.
* Split the IContentQueryService into it's own file
Also updated XML docs.
* Reverting the package-lock.json
* Updated the typo for Permision -> Permission
Updated the file name and class to: AddUserGroup2PermissionTable
This should be safe to do so as migrations are logged with their GUID's not the class names.
* Update src/Umbraco.Core/Scoping/CoreScope.cs
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Reverting a binary change.
* Reverted rename of public migration class.
* Revert name in migration plan.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* Ensure the description field added in a later migration for user groups is available when the earlier migration on this table runs.
* Update implementation of fix to store and use the state of UserGroupDto at the time of migrations.
* Prevent setting of entity Key to a new value for already persisted entities.
* Handled file based entities that have a key dependent on their path, so need to be able to have the key changed on move.
* Fixed package data update of content type to resolve failing integration test.
---------
Co-authored-by: Kenn Jacobsen <kja@umbraco.dk>
* scaffolding of a collection text filter extension
* Refactor collection text filter to use API interface
* Fix incorrect tag
* Update types.ts
* Update collection-text-filter.extension.ts
* Add cancelation to debounced search on destroy
* clean up
* add js docs
* two way binding of filter value
* clean up
* Add collection text filter manifest example
Introduced a new filter manifest for the example collection and updated the main manifests file to include it. This enables a text filter extension for the example collection.
* Delete unused element and context
* Update src/Umbraco.Web.UI.Client/src/packages/user/user-group/collection/user-group-collection.context-token.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update user-group-table-collection-view.element.ts
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Add loading indicator to data-type-picker-flow-modal
- Added _isLoading state variable
- Updated #getDataTypes() to set loading state with try-finally
- Added uui-loader component in #renderGrid() when loading
- Created test file with basic tests
- Fixed linter warnings
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* Refactor: Replace inline styles with CSS class for loader
- Added .loader-container CSS class
- Removed inline styles from loader div
- Improves maintainability and follows best practices
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* Improve tests and revert unrelated package-lock.json changes
- Test observable behavior (loader element) instead of private properties
- Added tests for loader visibility during loading states
- Added test for loader removal after loading completes
- Reverted unintended changes to Umbraco.Web.UI.Login/package-lock.json
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* Refactor: Extract helper function in tests for cleaner code
- Added setLoadingState helper function to reduce code duplication
- Updated comments to reflect testing reactive state property
- Improved test readability and maintainability
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
* delete test file not testing anything
* show loading indicator in search field instead
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: nielslyngsoe <6791648+nielslyngsoe@users.noreply.github.com>
Co-authored-by: Mads Rasmussen <madsr@hey.com>
* Added tests for removing a not-found member picker
* Added tests for adding thumbnail to block
* Updated tests to match the test helper changes
* Refactor code to avoid duplication
* Added tests for removing a thumbnail from a block list/grid and refactor code
* Bumped version
* Bumped version and make tests run in the pipeline
* Update smokeTest command to use '@smoke' filter
---------
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
- Add noAccess observable to document and media tree item contexts
- Add visual styling (grayed out, italic, cursor: not-allowed) for noAccess items in tree views
- Implement click prevention to block navigation when noAccess is true
- Update document and media picker input contexts with type-safe guards to prevent selection of noAccess items
- Create type guard utilities (isDocumentTreeItem, isMediaTreeItem) in separate utils files
- Items with noAccess are shown for navigation but cannot be selected or opened
This implements Task 63363 for Feature 63060 "Handle Start Nodes"
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Block Grid: Resolve translation keys for group names (closes#20696)
Add localization support for block group names in two locations:
- Block Grid area type permission combobox options
- Block catalogue modal group headers
Translation keys (e.g., #content_isPublished) used as group names
are now properly resolved instead of displaying the raw key.
* fix: moves group.name to mapper so search works
* fix: localizes block types in permissions element too
---------
Co-authored-by: Claude <noreply@anthropic.com>
Fix collection create action causing full page navigation instead of SPA routing
When a collection create action had an href, clicking it would trigger a full
browser navigation instead of using history.pushState for SPA routing. This was
caused by event.stopPropagation() being called before the early return when an
href was present, preventing the global ensureAnchorHistory() listener from
intercepting the click event.
The fix moves stopPropagation() to only execute when we're actually handling
the click via execute() (no href), allowing href-based navigation to bubble
to the window-level router listener for proper SPA navigation.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude <noreply@anthropic.com>
style: fix SA1500, SA1111, SA1134 StyleCop warnings
Fixed 194 StyleCop analyzer warnings across the codebase:
- SA1500: Move opening braces to their own line for multi-line statements (80 warnings)
- SA1111: Move closing parenthesis to same line as last parameter (50 warnings)
- SA1134: Place each attribute on its own line (64 warnings)
Also added XML documentation to any public APIs within the edited files.
* Delete GetStartContentNodes
* Delete GetStartMediaNodes
* Delete GetAllowedApplications
* Delete ClaimTypes
* Update protected recycle bin functionality to no longer used removed claim details. Added unit tests to verify behaviour.
* Fixed failing unit tests now the number of claims included is reduced.
Addressed comments from code review.
* Minor code tidy.
* Expose claim necessary for retrieving the user key.
---------
Co-authored-by: Andy Butland <abutland73@gmail.com>
* implement preventEditInvariantFromNonDefault for variant blocks
* remove unused
* refactor to enforce both document and block case from the document module
* remove implementation from doc workspace
* prevent editing invariant blocks from non default
* remove unused imports
* more explicit class names
* Refactor invariant edit guard rule creation
Extracted the creation of the invariant property edit guard rule into a reusable _createRule method in the controller base class. Updated block and document workspace controllers to use this method
* Refactor invariant edit rule logic into base controller
Moved the logic for observing properties and variant options and applying property guard rules into a new _observeAndApplyRule method in the base controller. Updated document block and workspace controllers to use this shared method, reducing code duplication and improving maintainability.
* Refactor invariant block edit check into helper methods
Extracted logic for checking invariant blocks and default language datasets into private async methods for better readability and maintainability. This refactor also corrects a context check typo and improves error handling.
* remove unused
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
- Fixed inverted logic in #parseNumber method
- Changed Number.isFinite(num) ? undefined : num to Number.isFinite(num) ? num : undefined
- Previously, valid max values (e.g., 50) were being ignored and defaulting to 100
- Now correctly parses and uses the configured Maximum Value from data type settings
This ensures the Maximum Value setting in Slider datatype configuration
is properly enforced in the slider UI component.
* fix(backoffice): allow drag and drop into empty link picker (closes#21295)
* refactor: use classMap to avoid empty class attribute
* refactor: use margin/padding trick for drop zone
* refactor: use CSS :has() selector instead of class
* also enable it for the Document input
---------
Co-authored-by: Niels Lyngsø <niels.lyngso@gmail.com>
* Route server events for public access updates to indicate an update to the protected document.
* Add unit tests for all ServerEventSender notification handlers.
* Adds additional test recommended in code review.
* Addressed parameter name issue raised in code review.
* Removed margin-top to address the loader icon shifting when entering text
* Space
---------
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
* Fix test entrypoint
* Fix healthcheck.sh
* Ensure bind mounts gets created on host
* Fix bind mounts permission issues
* Generate self signed cert for dev
* Only generate cert for localhost
* Fixup docker compose file
* Update templates/UmbracoProject/entrypoint.sh
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update templates/UmbracoProject/Dockerfile
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Fix APP_UID runtime availability and optimize chown performance
- Export APP_UID as ENV so it's available at container runtime
(ARG values from .NET base image are only available at build time)
- Only run chown -R when directory ownership differs from APP_UID
to avoid slow recursive operations on large directories
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Fix bug where with recycle bin media protection on, the files on disk aren't deleted when the recycle bin is emptied.
* Fix display of media URL when in recycle bin and protection of trashed media is enabled.
* Clean-up of ContentCacheRefresher: resolved warnings and tidied up code and comments.
* Only flush the ID/Key map when content is deleted.
* Update src/Umbraco.Core/Cache/Refreshers/Implement/ContentCacheRefresher.cs
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Adding description to user groups
* Add description to dto and test and umbraco plan
* update unit test for user group
* remove change from link picker
* edit icon ui for user group
* Fixed table exists check in migration.
* update description in table user groups
* update user group editor css
* update description default
* remove description column element
* add ignore large method
* remove codesence
* update user group descriptions default
* Added description to constructor of ReadOnlyUserGroup.
---------
Co-authored-by: Lan Nguyen Thuy <lnt@umbraco.dk>
Co-authored-by: Andy Butland <abutland73@gmail.com>
Co-authored-by: Andreas Zerbst <73799582+andr317c@users.noreply.github.com>
When changing a property's variation setting (Shared/Invariant ↔ Variant) via Infinite Editing,
the document would fail to save with a 404 error.
This fix:
- Adds value migration fallback logic in UmbPropertyValuePresetVariantBuilderController
to find values when culture/segment doesn't match exactly
- Overrides reload() in UmbContentDetailWorkspaceContextBase to process incoming data
through _processIncomingData() for proper value transformation
- Detects property variation changes and triggers document reload to migrate values
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Avoid an unnecessary look-up for the super-user when resolving ID from key and vice versa.
Utilise an async database methods given the enclosing method is async.
* Applied suggestions from code review.
* Revered async amend (caused pipeline failures with integration tests).
* Apply suggestions from code review
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
---------
Co-authored-by: Nikolaj Geisle <70372949+Zeegaan@users.noreply.github.com>
* Added transitive dependency references to specific libraries where direct dependencies depend on vulnerable versions.
* Enable CentralPackageTransitivePinningEnabled.
* Update MS dependencies to 10.0.1 patch versions.
* Removed System.Text.Encodings.Web.
* Add TODOs for pinned dependency removal.
* working on a auto closing ... modal when focus leaves
* remove appsetting for local development
* rewrites the focus function to check if the shadow dom exsits before trying to set focus
* Fix JSON formatting in appsettings.Development.template.json
* Simplify focus logic in entity action list
Refactored the focus method to directly focus the first menu item after it is rendered, removing unnecessary nested updateComplete checks and focusing logic for the label button.
* Remove unused 'nothing' import and minor formatting
* Call ext.component?.focus() instead of chaining updateComplete promises.
* Update entity-action-list.element.ts
---------
Co-authored-by: Niels Lyngsø <nsl@umbraco.dk>
Co-authored-by: Engiber Lozada <89547469+engijlr@users.noreply.github.com>
Co-authored-by: engjlr <enl@umbraco.dk>
* Add IMarkdownToHtmlConverter abstraction with Markdig and HeyRed implementations
- Add IMarkdownToHtmlConverter interface in Umbraco.Core.Strings
- Add MarkdigMarkdownToHtmlConverter using the Markdig library (new default)
- Add HeyRedMarkdownToHtmlConverter using HeyRed.MarkdownSharp (deprecated, for backwards compatibility)
- Update HealthChecks.MarkdownToHtmlConverter to use the new abstraction
- Update MarkdownEditorValueConverter to use the new abstraction
- Add unit tests for both markdown converter implementations
- Add unit tests for HealthChecks.MarkdownToHtmlConverter syntax highlighting
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestion from code review.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
When changing a property's variation setting (Shared/Invariant ↔ Variant) via Infinite Editing,
the document would fail to save with a 404 error.
This fix:
- Adds value migration fallback logic in UmbPropertyValuePresetVariantBuilderController
to find values when culture/segment doesn't match exactly
- Overrides reload() in UmbContentDetailWorkspaceContextBase to process incoming data
through _processIncomingData() for proper value transformation
- Detects property variation changes and triggers document reload to migrate values
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
description:Bump the Umbraco CMS version across all required files. Use when the user asks to bump, update, or set the version number — e.g., "bump version to 17.3.4", "set version to 18.0.0-rc", "update version". Accepts the target version as an argument.
argument-hint:<version> (e.g., 17.3.4, 18.0.0-rc)
---
# Bump Version - Umbraco CMS
Updates the Umbraco CMS version string across all files that track it.
**Do NOT use AskUserQuestion if a version argument is provided. Only ask if `$ARGUMENTS` is empty or cannot be parsed as a version.**
## Arguments
-`$ARGUMENTS` - Required: the target version string (e.g., `17.3.4`, `18.0.0-rc`)
## Files to Update
The following 5 files must be updated with the new version:
| 5 | `tests/Umbraco.Tests.AcceptanceTest/package-lock.json` | top-level `"version"` AND `packages[""].version` |
**Note**: For major version bumps (e.g., 17.x to 18.x), `src/Umbraco.Web.UI.Login/package.json` has a caret-ranged dependency on `@umbraco-cms/backoffice` (e.g., `^17.2.0`) that will need manual updating. This skill does not handle that — major bumps involve many other changes beyond version strings.
## Instructions
### 1. Parse and Validate the Version
Extract the version from `$ARGUMENTS`. It must be a valid semver-like string (e.g., `17.3.4`, `18.0.0-rc`, `17.4.0-preview.1`). If no version is provided or it cannot be parsed, ask the user for the target version.
### 2. Read the Current Version
Read `version.json` and extract the current `"version"` value. If the current version already equals the target version, report that the version is already set and stop — do not edit, stage, or commit anything.
Otherwise, display both versions:
```
Bumping version: {current} -> {target}
```
### 3. Update All Files
Update each of the 5 files listed above, replacing the old version with the new version. For each file:
- **`version.json`**: Replace the `"version"` value.
- **`package.json` files**: Replace the `"version"` value (near the top of the file).
- **`package-lock.json` files**: Replace BOTH the top-level `"version"` value AND the `"version"` inside the `"packages": { "": { ... } }` block. These are always in the first ~10 lines of the file.
Use targeted edits — do NOT rewrite entire files. Be precise to avoid changing version strings in dependency entries.
### 4. Verify
After all edits, grep for the target version value across the 5 files to confirm all updates landed correctly:
description:Improve a set of auto-generated GitHub release notes for an Umbraco CMS release. Cross-checks the notes against every PR carrying the release label, adds any that are missing, re-files every PR under the most appropriate category, and strips purely-internal entries. Use whenever the user asks to tidy up, improve, complete, or recategorize release notes for a given version, or mentions a release-notes text file plus a version number.
Takes a file of auto-generated GitHub release notes and produces an improved version that:
1.**Is complete** — every merged PR carrying the `release/<version>` label appears.
2.**Is well-categorized** — every PR sits under the most appropriate heading.
3.**Is free of noise** — purely-internal entries of no value to a reader are removed.
The result is written to a **new** file alongside the input, so the user can diff the two.
**Run autonomously.** Do NOT use `AskUserQuestion` once the required arguments (version and input file path) are available — only ask if one of them is missing from `$ARGUMENTS` and cannot be inferred (see Arguments). Beyond that, make the categorization calls yourself using the rules below; if a handful are genuinely borderline, place them anyway and note the borderline ones in your closing summary so the user can override.
## Arguments
`$ARGUMENTS` contains two values:
1.**Version** — e.g. `17.5.0`, `18.1.0`. The GitHub label to search is `release/<version>` (so version `17.5.0` → label `release/17.5.0`).
2.**Input file path** — full path to the text file holding the auto-generated notes (e.g. `C:\Temp\release-17.5.0-rc.md`).
If either is missing, ask the user once for the missing value, then proceed.
## Prerequisites
Run `gh auth status`. If it fails, tell the user to authenticate `gh` (e.g. `gh auth login`) and stop — the skill needs the GitHub CLI to query PRs. The repo is always `umbraco/Umbraco-CMS`.
## Procedure
### 1. Read the input notes
Read the input file. Note its structure — it is GitHub's generated format:
- A leading HTML comment (`<!-- Release notes generated ... -->`).
- A `## What's Changed` heading followed by `### <emoji> <Category>` sub-headings, each with `* <title> by @<author> in <url>` bullets.
- A trailing `## New Contributors` section and a `**Full Changelog**: ...` line.
Extract the set of PR numbers already present (parse the `/pull/<number>` from each bullet). Preserve each existing bullet's **exact text** (title, author, URL) when you re-emit it — only its category placement may change.
This is the authoritative list of what the release *should* contain. Each row gives number, author, labels, title.
**Guard against silent truncation.**`gh pr list` caps at `--limit` without warning, so a large release could drop the overflow and the skill would still look "complete". Count the returned rows and compare against the limit:
```bash
gh pr list --repo umbraco/Umbraco-CMS --label "release/<version>" --state closed --limit 1000 --json number --jq 'length'
```
If this equals 1000, the limit was hit — raise `--limit` and re-fetch before continuing. Do **not** proceed on a truncated list.
### 3. Reconcile
- **Missing labelled PRs** (labelled but not in the input file): these must be **added**. Build a bullet as `* <title> by @<author> in https://github.com/umbraco/Umbraco-CMS/pull/<number>`.
- **Author handle.** `<author>` in the template is the raw `.author.login` value — the bullet supplies the leading `@`, so do not prepend another. `gh`'s `.author.login` already returns bot accounts with the `[bot]` suffix as part of the login — Dependabot comes back as `dependabot[bot]`, not `dependabot` or `app/dependabot` (the `app/` form only appears in git committer metadata and CODEOWNERS, never in `gh`'s JSON). So the login is already in the right shape; use it verbatim (e.g. `.author.login` of `dependabot[bot]` renders as `@dependabot[bot]`, matching what GitHub's generator wrote for the existing bullets). The only thing to guard against is accidentally stripping or altering the `[bot]` suffix.
- **PRs in the file but not labelled**: keep them. The generated notes span a commit range (see the `Full Changelog` compare link), so they legitimately include backports / earlier-version PRs that lack the current label. For any of these you need to categorize, fetch its labels with:
Do **not** invent or alter the `New Contributors` section — carry it over verbatim. You cannot reliably recompute first-time contributors, so leave it as the generator produced it (mention this in the summary).
### 4. Categorize every PR
Use exactly these headings, in this order. Omit any heading that ends up with no entries.
| Heading | What goes here | Primary signal |
|---|---|---|
| `### 🙌 Notable Changes` | **Don't recategorize existing entries.** Label-driven — but still add any missing PR carrying this label here. | label `category/notable` |
| `### 💥 Breaking Changes` | **Don't recategorize existing entries.** Label-driven — but still add any missing PR carrying this label here. | label `category/breaking` |
| `### 🚀 New Features` | New user- or developer-facing capability | label `type/feature` / `category/feature`; or title introduces/adds a genuinely new capability |
| `### 🚤 Performance` | Performance improvements | label `category/performance`; or `Performance:` title prefix |
| `### 🐛 Bug Fixes` | Fixes to broken/incorrect behaviour | default for anything describing a fix |
| `### 🧪 Testing` | Test additions/changes only | label `category/test-automation` / `area/test`; or `E2E`/`QA`/"acceptance tests"/"unit test coverage"/"add tests" titles |
| `### 🛡️ Code Quality, Documentation and Refactoring` | Refactors, deprecations, API tidy-ups, XML/MD documentation, knowledge-base (`MD`) updates | label `category/refactor`; or titles about refactoring, deprecating, renaming, documenting, constants extraction, MD/CLAUDE.md content |
| `### 🧑💻 Developer Experience` | Things that improve the experience of developers building on or contributing to Umbraco — dev tooling, build/watch ergonomics, test mocks/harnesses, backoffice dev utilities | `Developer Experience` title prefix; dev tooling; mock/harness changes |
**Rules:**
- **Notable and Breaking are off-limits for recategorization** — never move a PR that is *already in the input file* into or out of these sections; they are driven purely by their labels and the generator placed them correctly. This does **not** exempt them from completeness: a PR discovered as missing in step 3 that carries `category/notable` or `category/breaking` must still be **added** under the matching section.
- Label signals beat title wording, except a `Performance:`/`Developer Experience:` title prefix is decisive for its section.
- A PR with both `type/feature` and `category/refactor` whose title clearly describes a refactor (e.g. "swap relative imports", "re-export type") belongs under Code Quality, not New Features.
- "Add ... tests"/"unit test coverage" → Testing, even if it also touches docs. If a PR adds XML documentation *and* tests, lead with where the title's emphasis lies (documentation → Code Quality; test coverage → Testing).
- When a PR is genuinely 50/50, pick the more reader-useful heading and list it in your closing summary as borderline.
### 5. Remove purely-internal noise
Drop entries that have **no value to anyone reading release notes** — pure repository plumbing with no shipped impact. Examples:
- Branch/merge maintenance ("Fix main branch after merge issue").
- CI/pipeline fixes that don't change the product.
- Reverts of changes that never shipped in a release.
**Keep** anything that ships in the product or genuinely helps developers building on Umbraco — that includes documentation/MD updates, dev tooling, and test mocks (those go to Code Quality or Developer Experience, they are *not* noise). When unsure whether something is noise, keep it and flag it in the summary rather than silently dropping it. List every removal in your closing summary.
### 6. Write the output
Write to a new file in the **same folder** as the input, named by appending ` - with updates` before the extension:
- Input `C:\Temp\release-17.5.0-rc.md` → Output `C:\Temp\release-17.5.0-rc - with updates.md`
Preserve the leading HTML comment, the `## What's Changed` heading, the `## New Contributors` section, and the `**Full Changelog**` line exactly. Only the `### <category>` groupings and their bullets change.
### 7. Report
Give a concise summary:
- Count of PRs added (with their numbers), and which categories they landed in.
- Notable recategorizations (PRs moved out of the catch-all Bug Fixes into Features/Performance/Testing/etc.).
- Every entry removed, with the one-line reason.
- Any borderline calls the user may want to override.
- The output file path.
## Verification
Before reporting done, confirm:
- Every PR number from step 2 is present in the output (except any you deliberately removed in step 5 — and those must be in the removal list).
- No PR appears under more than one heading.
- Notable and Breaking sections are byte-for-byte unchanged from the input.
- The header comment, New Contributors, and Full Changelog lines are intact.
description:Automated PR code review for Umbraco CMS. Analyzes changed files for intent, impact on consumers, breaking changes, architecture compliance, and code quality. Non-interactive — outputs a full structured review. Use this skill whenever the user asks to review a branch, review a PR, check their changes for issues, analyze a diff, or validate breaking change patterns — even if they don't say "review" explicitly. Does NOT apply to writing new code, fixing bugs, refactoring, explaining architecture, writing tests, or reviewing documentation content.
argument-hint:<target-branch>
---
# PR Review - Umbraco CMS
Automated, non-interactive PR code review. Analyzes changed files for intent, impact on consumers, breaking changes, architecture compliance, and code quality.
**Do NOT use AskUserQuestion at any point. This skill runs fully autonomously.**
## Arguments
-`$ARGUMENTS` - Optional: target branch to diff against (auto-detected from PR, falls back to `origin/main`)
## Instructions
### 0. Verify GH CLI is Available
Run `gh auth status`. If it fails, read `references/gh-cli-setup.md` and present the setup instructions to the user. Do not proceed with the review.
### 1. Resolve Target Branch
Determine the target branch for comparison using this priority order:
1.**Explicit argument**: If `$ARGUMENTS` is provided and non-empty, use it as the target branch
2.**PR target branch**: If no argument, run `gh pr view --json baseRefName --jq '.baseRefName'` to detect the target branch of the current branch's open PR. If a PR exists, use `origin/{baseRefName}` as the target branch.
3.**Fallback**: If no argument and no PR found (command fails or returns empty), default to `origin/main`
Store the resolved target branch for use in subsequent steps. Log which resolution method was used (e.g., "Target branch: `origin/v18/dev` (from PR #1234)").
### 2. Load Review Standards
#### 2a. Load coding preferences
Read the coding preferences and code review scoring criteria from:
-`references/coding-preferences.md` (relative to this skill file)
Parse and internalize all rules, conventions, scoring categories, and severity definitions. These are your review criteria.
#### 2b. Load area-specific documentation
Once the changed file list is known (after step 3a), determine which areas of the codebase are touched and load the relevant documentation. Execute this sub-step between 3a and 3b. This documentation takes precedence over sibling comparison for architectural and pattern validation.
**Resolution order for each changed file:**
1.**Find the nearest `CLAUDE.md`** — walk up from the changed file's directory toward the repository root. The first `CLAUDE.md` found is the area guide for that file. Read it.
2.**Read referenced docs** — if the `CLAUDE.md` references documentation files (e.g., a `docs/` directory), use the descriptions in the `CLAUDE.md` to determine which docs are relevant to the type of code being changed, and read those. If unsure, read all referenced docs — the cost of reading is low, the cost of missing a convention is high.
3.**Follow cross-references in loaded docs** — if a loaded doc references another doc as covering a complementary or related concern, and the changed files touch that concern, read the referenced doc too. Repeat until no new relevant cross-references remain.
4.**Check for applicable skills** — review the available skills list. If a skill exists for the type of code being changed, read the skill file to understand the expected patterns, structure, and conventions it enforces. Do NOT invoke the skill — just use it as a reference for what the correct implementation should look like.
**Store all loaded documentation** for use in step 4. These docs define the authoritative patterns and conventions that the review evaluates against.
### 3. Gather Changed Files
#### 3a. Collect file list, stats, and diff
Run these git commands (where `{target}` is the resolved target branch):
Log the skip list: "Skipped {N} noise files: {comma-separated list of filenames}"
#### 3c. Read reviewable changed files
Read the full file for every reviewable changed file.
#### 3d. Track file counts
Keep track of these numbers for the review output in step 7: total changed files, noise files skipped, and reviewable files read. Also record: distinct production layers touched, distinct project directories, and total lines changed — these feed step 3e.
#### 3e. Assess PR complexity
Follow the procedure in `references/complexity-assessment.md`. Store the triggered dimensions and suggestions for step 7.
#### 3f. Classify PR scope
Classify the PR to determine which review steps are relevant:
| **Gen-only** | All reviewable files are `gen.ts` | Skip steps 5 and 6; step 4 reviews impact on other code only |
| **Docs-only** | All reviewable files are `.md` | Skip steps 5 and 6; step 4 reviews intent and readability only |
| **Test-only** | All reviewable files are in `tests/` | Skip steps 5 and 6; step 4 reviews intent, code quality, and test coverage only |
| **Config-only** | All reviewable files are `.csproj`, `.props`, `.json` config, or CI/build files | Skip step 5; step 6 checks dependency version changes only |
| **Standard** | Anything else | No skips — run all steps |
### 4. Raw Code Review
Review each changed file holistically. Think like a senior developer reading a colleague's PR. Note all findings without worrying about format or severity yet.
#### 4a. Read and reason about each file
For each changed file, reason about: What does this code do? Is it correct? What's missing — validation, error handling, notifications, cleanup, edge cases? Could this break anything for consumers?
#### 4b. Validate against documentation and patterns
Use a **docs-first** approach: classify the code by what it does, check it against documented conventions, and only fall back to sibling comparison when docs don't cover the pattern.
**Step 1 — Determine the correct approach from documentation, then check whether the PR matches**
A PR is a proposed solution, not the source of truth. This step has two parts that must happen in order — do not start part B until part A is complete.
**Part A — Before validating/judging the implementation**, determine what the correct approach is for each new class or file based on what it does. Use the documentation loaded in step 2b to identify the expected base classes, patterns, and conventions. Write down the expected approach. Classify based on what the code does, not based on what neighboring files look like.
**Part B — Now compare the PR's implementation** against the expected approach from Part A. If it deviates from the documented approach, flag it. If the documentation specifies reference examples, read those examples to verify the implementation matches.
**Pattern match is the leading finding.** If the documentation defines a pattern that fits what the code does, the first and most important finding is whether the code follows that pattern.
**Step 2 — Fall back to sibling comparison**
If the documentation does not cover the specific pattern, or for cross-cutting concerns not addressed in docs, fall back to sibling comparison:
1.**New method on existing class/interface**: Grep for the most similar existing method on the same class using `-A 80` to capture the full method body (e.g., `UpdateCurrentUserAsync` → grep for `UpdateAsync` in the same file with `-A 80`). Compare line by line for missing cross-cutting concerns: notifications/events, validation, scoping, authorization, error handling, audit logging.
2.**New TS class**: Grep for siblings by base class (`extends {BaseClass}`) or by interface (`implements {Interface}`) or by name suffix (e.g., `CurrentUserController` → grep for `UserController`). Compare for missing concerns.
3.**New CS class**: Grep for siblings by base class (`class {ClassName} : {BaseClass}`) or by interface (`class {ClassName} : {Interface}`) or by name suffix (e.g., `ManagementApiComposer` → grep for `ApiComposer`). Compare for missing concerns.
**Important:** Sibling comparison validates cross-cutting concerns, but it must not override documented conventions. If a sibling deviates from documented patterns, that sibling is wrong — do not copy its deviation.
Store your raw findings — they feed into step 7.
### 5. Impact Analysis
**Skip this step if PR scope is docs-only, test-only, or config-only.**
Follow the procedure in `references/impact-analysis.md`.
### 6. Breaking Changes Check
**Skip this step if PR scope is docs-only or test-only. If config-only, only check for dependency version changes that could break consumers.**
Follow the procedure in `references/breaking-changes.md`.
### 7. Consolidate and Output Review
Merge findings from step 4 (raw review), step 5 (impact analysis), and step 6 (breaking changes). For each finding, assign severity (Critical/Important/Suggestion) and verify it relates to changed code — not pre-existing issues. Before outputting, drop any finding about whitespace, blank lines, formatting, or comment wording. Then present the review in this exact format:
```markdown
## PR Review
**Target:**`{target_branch}` · **Based on commit:**`{head_sha}`
[If any skipped files, append: · **Skipped:** {skipped} files out of {total} total]
[If step 3f classification is not "Standard", append: · **Classified as:** {classification}]
[1–2 sentences: what this PR accomplishes , keep it as short as possible, only highlight the primary essence.]
- **Modified public API:** {changed existing interfaces/types/classes/methods}
[Omit bullet if none]
- **Affected implementations (outside this PR):** {interfaces/types/classes/methods using modified public API}
[Omit bullet if none]
- **Breaking changes:** {violations with specifics}
[Omit bullet if none]
- **Other changes:** {changes not listed above that an Umbraco user, plugin developer, or API consumer would notice — e.g., behavior changes, default value changes, error message changes, new configuration options, removed functionality. Exclude internal renames, formatting, and private implementation details.}
[Omit bullet if none]
[If step 3e triggered any dimensions, insert this block. Omit entirely if nothing triggered:]
> [!NOTE]
> **Complexity advisory** — This PR may benefit from splitting.
>
> - **{Dimension}:** {Explanation and concrete split suggestion from step 3e}
> [one bullet per triggered dimension]
>
> _This is an observation, not a blocker. The full review follows below._
---
### Critical
[Must fix before merge — security vulnerabilities, data loss, broken functionality, breaking changes without proper patterns]
[Nice to have — readability, minor refactoring, alternative approaches]
- **`{file}:{line}`**: {detail}
[Omit section if none]
---
[One of:]
## Approved
This looks good to be merged as-is, but please do a manual sanity check and testing before merging.
## Approved with Suggestions for improvement
Good to go, but please carefully consider the importance of the suggestions.
## Request Changes
Critical and important issues must be addressed first.
## Needs re-work
This is in such a bad state that the feedback of this review is not sufficient to guide improvements, the PR cannot be approved.
```
**Guidelines for the review output:**
— When reporting information, be extremely concise and sacrifice grammar for sake of concision.
- Only review code that was changed in the diff — pre-existing issues are out of scope. Focus on what compilers and linters cannot catch: behavioral side-effects (e.g., a changed default alters runtime behavior for consumers), architectural violations (e.g., a new dependency breaks layering), breaking changes for external consumers of the public API, and security implications. Leave type errors, missing imports, and broken references to CI.
- Be specific — always reference file and line number
- Explain WHY something is an issue, not just WHAT, but avoid stating the obvious.
- For complex matters, provide concrete fix suggestions, including code snippets when helpful
- Keep it constructive — the goal is to help, not gatekeep
- Don't repeat the same finding for every occurrence — mention it once and note "same pattern in {other files}"
- Focus on substantive issues only. Do NOT flag purely cosmetic or stylistic concerns. Specifically, never flag: code formatting or whitespace, comment grammar or wording, redundant-but-harmless syntax (e.g., optional chaining after a truthiness check), code duplication that doesn't cause bugs, or HTML template cosmetics. The only exception is when a stylistic issue has a concrete impact on performance or rendering. Note: missing JSDoc/documentation on public or exported APIs is a substantive finding (per coding preferences), not a cosmetic one — flag it as a Suggestion.
- For breaking changes, reference the specific pattern from the CLAUDE.md that should be applied
- Do not suggest changes that would themselves introduce breaking changes. If a suggestion would alter public API surface (e.g., changing return types, renaming public members), it is not appropriate for a PR targeting `main` within a major version. Only suggest non-breaking alternatives.
"prompt":"Review the changes in PR #22214 (branch origin/pr/22214 targeting main). This is a large frontend refactor migrating create entity actions to use entityCreateOptionAction extensions, with deprecations.",
"expected_output":"A structured review that identifies frontend deprecation patterns, flags the large PR complexity, handles 75+ files correctly, checks for breaking changes in exported components, and produces the correct output format.",
{"id":"frontend-breaking-change-awareness","text":"Checks frontend-specific breaking changes (exports, custom elements) not just backend"},
{"id":"file-references-present","text":"Findings reference specific files with line numbers"},
{"id":"no-false-critical-on-deprecations","text":"Properly deprecated code is NOT flagged as Critical breaking change"},
{"id":"no-stylistic-nitpicks","text":"Review does not flag purely cosmetic/stylistic issues (formatting, whitespace, naming conventions, comment grammar, code style preferences) unless they affect performance or rendering. Missing JSDoc on new public APIs is NOT a stylistic issue — it is a legitimate finding."},
{"id":"manifest-alias-rename-detected","text":"Alias renames (CreateOptions → Create) flagged as Critical breaking change"},
{"id":"non-exported-deletions-dismissed","text":"Deleted action classes NOT flagged as breaking (verified against package.json exports)"},
{"id":"noise-files-filtered","text":"Does not review noise files (generated files, lock files, etc.)"},
{"id":"complexity-advisory-triggers","text":"Review includes a complexity/split advisory for the large 75+ file scope"}
]
},
{
"id":1,
"name":"pr-21672-small-frontend-bugfix",
"prompt":"Review the changes in PR #21672 (branch origin/pr/21672 targeting main). This is a small 4-file frontend bugfix implementing tab validation badges in the block editor.",
"expected_output":"A clean review that correctly identifies this as a small focused bugfix, avoids false positives, and either approves or approves with minor suggestions.",
"pr_number":21672,
"pr_branch":"origin/pr/21672",
"base_branch":"origin/main",
"files":[],
"assertions":[
{"id":"complexity-advisory-absent","text":"Review does NOT include a complexity/split advisory"},
{"id":"no-false-breaking-changes","text":"Review does not flag breaking changes"},
{"id":"proportionate-verdict","text":"Verdict is 'Request Changes'"},
{"id":"concise-review","text":"Review output is under 200 lines"},
{"id":"no-stylistic-nitpicks","text":"Review does not flag purely cosmetic/stylistic issues (formatting, whitespace, naming conventions, comment grammar, code style preferences) unless they affect performance or rendering. Missing JSDoc on new public APIs is NOT a stylistic issue — it is a legitimate finding."}
]
},
{
"id":2,
"name":"pr-22217-small-backend-webhook",
"prompt":"Review the changes in PR #22217 (branch origin/pr/22217 targeting v18/dev). This is a tiny 3-file backend change to the default webhook payload type.",
"expected_output":"A concise review that correctly resolves v18/dev as target branch, handles the small change proportionately, and considers the behavioral impact of changing a default value.",
"pr_number":22217,
"pr_branch":"origin/pr/22217",
"base_branch":"origin/v18/dev",
"files":[],
"assertions":[
{"id":"correct-target-branch","text":"Review references 'v18/dev' as the target branch (not 'main')"},
{"id":"default-value-change-noted","text":"Review discusses the behavioral impact of changing the default payload type"},
{"id":"proportionate-review","text":"Review output is under 150 lines"},
{"id":"no-stylistic-nitpicks","text":"Review does not flag purely cosmetic/stylistic issues (formatting, whitespace, naming conventions, comment grammar, code style preferences) unless they affect performance or rendering. Missing JSDoc on new public APIs is NOT a stylistic issue — it is a legitimate finding."},
{"id":"ignores-preexisting-issues","text":"Does NOT flag the ~30 builder extension methods with Legacy defaults (pre-existing, not changed in the PR)"},
{"id":"side-effect-detection","text":"Flags stale WebhookSettings.cs docs as a side-effect of the constant value change"},
{"id":"consumer-identification","text":"Identifies affected consumers outside the PR (WebhookSettings, UmbracoBuilder, or WebhookEventCollectionBuilderExtensions)"}
"prompt":"Review the changes in PR #22268 (branch origin/pr/22268 targeting main). This is a 29-file frontend feature adding a current user workspace modal.",
"expected_output":"A review of a medium-sized new feature PR. Should assess the new code for architectural compliance, check for breaking changes (new exports, custom elements), and evaluate code quality without flagging pre-existing issues.",
"pr_number":22268,
"pr_branch":"origin/pr/22268",
"base_branch":"origin/main",
"files":[],
"assertions":[
{"id":"complexity-advisory-triggers","text":"Review includes a complexity/split advisory (3 layers: Core, API, Frontend across 27+ files)"},
{"id":"breaking-changes-on-interface-additions","text":"Flags new interface methods without default implementations as breaking changes (Pattern 3)"},
{"id":"no-stylistic-nitpicks","text":"Review does not flag purely cosmetic/stylistic issues unless they affect performance or rendering. Missing JSDoc on new public APIs is NOT a stylistic issue — it is a legitimate finding."},
{"id":"diff-scoped","text":"All findings reference code that was changed in the diff, not pre-existing issues"},
{"id":"new-feature-assessed","text":"Review assesses the new feature's architecture, patterns, or integration approach — not just absence of bugs"},
{"id":"no-false-notification-finding","text":"Review does NOT flag UpdateCurrentUserAsync as missing UserSavingNotification/UserSavedNotification — the sibling UpdateAsync also does not publish these notifications, so flagging their absence would be a false positive"}
"prompt":"Review the changes in PR #22215 (branch origin/pr/22215 targeting main). This is a 2-file frontend feature adding user management to the user group workspace.",
"expected_output":"A review that catches the architecture violation: the workspace context directly imports and calls UserService and UserGroupService (generated API clients) instead of going through a repository. In the Umbraco backoffice, workspace contexts access data via repositories, not by calling API services directly. The review should flag this as a significant architecture issue and request changes.",
"pr_number":22215,
"pr_branch":"origin/pr/22215",
"base_branch":"origin/main",
"files":[],
"assertions":[
{"id":"service-bypass-detected","text":"Review flags that the workspace context directly imports/calls UserService or UserGroupService instead of using a repository"},
{"id":"repository-pattern-recommended","text":"Review recommends using the repository pattern (going through a repository/data-source layer) rather than calling API services directly from the workspace context"},
{"id":"verdict-request-changes","text":"Verdict is 'Request Changes' (the architecture violation warrants requesting changes, not just approving with suggestions)"},
{"id":"no-stylistic-nitpicks","text":"Review does not flag purely cosmetic/stylistic issues (formatting, whitespace, naming conventions, comment grammar, code style preferences) unless they affect performance or rendering. Missing JSDoc on new public APIs is NOT a stylistic issue — it is a legitimate finding."},
{"id":"no-false-breaking-changes","text":"Review does not flag breaking changes (this PR only adds new code, no public API is removed or modified)"}
This document describes how to detect and validate breaking changes during PR review. It covers both backend (.NET) and frontend (TypeScript/Lit) patterns.
---
## Version Detection
**Always read `version.json`** at the repository root to determine the current major version. This drives the obsolete removal target calculation:
- Current major version: read from `version.json` → `version` field (e.g., `"17.4.0-rc"` → major version `17`)
- Obsolete removal target: `current + 2` (e.g., if current is 17, removal is scheduled for Umbraco 19)
- Format: `[Obsolete("... Scheduled for removal in Umbraco {current+2}.")]`
---
## Backend (.NET) Breaking Changes
### What Constitutes a Breaking Change
Any of these on a `public` or `protected` member:
- Removing or renaming a class, interface, struct, record, or enum
- Removing or renaming a method, property, or field
- Changing a method signature (parameters, return type)
- Adding required parameters to an existing method
- Adding methods to a public interface (without default implementation)
- Changing a constructor signature on a public class
- Removing or changing enum values
- Changing type hierarchy (base class, implemented interfaces)
- [ ] Old constructor has `[Obsolete]` attribute with correct removal version
- [ ] Old constructor calls new constructor via `: this(...)`
- [ ]`StaticServiceProvider.Instance.GetRequiredService<T>()` used for new params only
- [ ] DI registration uses the NEW constructor (old is for external consumers only)
- [ ] Removal version is `{current_major + 2}`
**Common mistakes to flag:**
- Removing the old constructor entirely (breaking change!)
- Old constructor NOT calling new constructor (code duplication)
- Wrong removal version in `[Obsolete]`
- Missing `StaticServiceProvider` resolution for new dependencies
- DI registration still using the old constructor
### Pattern 2: Obsolete Method + New Overload
When a method signature needs to change, add the new overload and obsolete the old.
**Correct pattern:**
```csharp
[Obsolete("Use the overload taking all parameters. Scheduled for removal in Umbraco 19.")]
publicvoidDoThing(stringname)
=>DoThing(name,extraParam:null);
publicvoidDoThing(stringname,string?extraParam)
{
// Real implementation here
}
```
**Validation checklist:**
- [ ] Old method has `[Obsolete]` attribute with correct removal version
- [ ] Old method calls new method, providing defaults for new parameters
- [ ] All internal callers updated to use the new method
- [ ] No internal code references the obsolete method (except the delegation)
### Pattern 3: Default Interface Implementation
When adding methods to a public interface, provide a default implementation.
**Correct pattern:**
```csharp
publicinterfaceIMyService
{
voidExistingMethod();
// New method with default implementation
voidNewMethod(stringparam)
=>ExistingMethod();// delegate to existing if possible
}
```
**Strategies for defaults (in order of preference):**
1. Use existing interface methods to satisfy the contract
2. Return a sensible default (empty collection, null, etc.)
3. Throw `NotImplementedException` if no reasonable default exists
**Validation checklist:**
- [ ] New interface method has a default implementation
- [ ] TODO comment present: `// TODO (V{next-major}): Remove the default implementation when {obsolete method} is removed.`
- [ ] Default implementation is functionally correct (even if not optimal)
- [ ] If `StaticServiceProvider` is used in default impl, noted as temporary
### Obsolete Attribute Validation
For any `[Obsolete]` attribute found in changed code:
1.**Format**: Must contain `"Scheduled for removal in Umbraco {version}."`
2.**Version**: Must be `current_major + 2` (read from `version.json`)
3.**Pragma**: Where obsolete members must call each other, `#pragma warning disable CS0618` / `#pragma warning restore CS0618` must be present
### Internal Caller Check
After finding obsolete patterns, verify:
- Search the codebase for usages of the obsolete member
- **No internal code** (inside `src/`) should reference obsolete members
- Only the obsolete member's own delegation (calling the new version) is acceptable
- External consumers (outside the repo) get the deprecation period to migrate
---
## Frontend (TypeScript/Lit) Breaking Changes
The backoffice is published as `@umbraco-cms/backoffice` with 140+ named exports. Plugin developers depend on this public API surface.
**Critical frontend rule (does not apply to backend .NET where `public`/`protected` visibility determines the API surface): only symbols reachable through the `package.json` `exports` field are public API.** Anything not exported — whether classes, functions, constants, types, or entire files — is an internal implementation detail, even if other internal code imports it. Removing or changing unexported frontend symbols is not a breaking change. Before flagging a frontend deletion or rename as breaking, verify the symbol is reachable via `package.json` exports. If it is not, do not flag it.
### Custom Elements (Web Components)
**Breaking changes:**
- Renaming or removing a registered custom element tag (`umb-*`)
- Removing elements from `HTMLElementTagNameMap`
- Removing or changing `@property()` decorated fields on exported components
- Removing event emissions (checked via `this.dispatchEvent`)
- Removing CSS custom properties (`@cssprop` in JSDoc)
- Removing CSS parts (`@csspart` in JSDoc)
**How to detect:**
- Check diff for removed `@customElement('umb-...')` decorators
- Check diff for removed `@property()` fields on exported components
- Check diff for removed entries in `HTMLElementTagNameMap` declarations
### Exported Types/Interfaces
**Breaking changes:**
- Removing exports from `package.json``exports` field
- Changing the shape of exported interfaces (removing properties, changing types)
- Renaming exported types (consumers import by name)
- Removing union type members
- Changing generic type parameter constraints
**How to detect:**
- Check if `package.json``exports` field is modified
- Check diff for removed `export` statements
- Check diff for changed interface/type shapes
### Manifest/Extension System
**Breaking changes:**
- Renaming a manifest `alias` value — plugin developers reference aliases by string in conditions, overwrites, and extension registry lookups. Alias renames are not caught by the compiler since they are string-based. A renamed alias silently breaks any plugin that references the old string.
- Removing support for a manifest `type` that plugins use
- Changing manifest `alias` resolution or validation
- Removing or renaming manifest `kind` types
- Changing extension bundle structure
**How to detect:**
- **Alias renames**: Compare `alias:` values in manifest files before and after. Changed alias strings are Critical — the old alias should be preserved as a deprecated entry.
- Search for changes to manifest type definitions
- Check for removed or renamed manifest kinds
### Context API
**Breaking changes:**
- Removing context tokens from exports
- Changing the shape of data provided by a context
- Removing context provider/consumer mechanisms
**How to detect:**
- Check for removed context token exports
- Check for changes to context provider classes
### Controllers/Lifecycle
**Breaking changes:**
- Changing controller base class inheritance requirements
- Removing controller lifecycle hooks
- Breaking cleanup mechanisms in `disconnectedCallback()`
### Observable/State
**Breaking changes:**
- Removing observable properties from the public API
- Changing observable emission patterns
### npm Publishing
**Breaking changes:**
- Changing version constraints that exclude previously-supported versions
- Adding incompatible peer dependency constraints
**How to detect:**
- Check if `package.json``peerDependencies` or `dependencies` changed
- Verify version ranges are not narrowed
---
## Reporting Breaking Changes
When a breaking change is detected, report:
1.**What**: The specific change and which public symbol is affected
2.**Pattern**: Which mitigation pattern should be applied (Pattern 1, 2, or 3 for backend)
3.**Severity**: Critical (no mitigation present) or Important (mitigation present but incorrect)
4.**Fix**: Concrete code suggestion showing the correct pattern
If no breaking changes are detected, state: "No breaking changes detected."
- **Log messages**: Technical, detailed, with context
- Include correlation IDs and relevant data in logs
---
## Security
- **Always check for security issues** using OWASP Top 10 as baseline
- Flag potential vulnerabilities immediately
- Suggest secure alternatives when spotting risky patterns
- Apply principle of least privilege
---
## Immutability
- Prefer **immutability** by default
- Allow internal properties to be mutated, as long as they are not direct references coming from the outside
---
## Nullability
- **TypeScript / JavaScript**
- Prefer `undefined` for optional/omitted values (e.g., optional parameters, props, and fields)
- Use `null` only when the domain model explicitly encodes "no value" or "not set" (e.g., `string | null` from APIs/DB), and be consistent with existing types
- Avoid mixing `null` and `undefined` for the same concept within the same model or API surface
- **C#**
- use nullable types (e.g., `string?`, `int?`) where absence is valid
- Prefer domain modeling (value objects, options/results, empty collections) over `null` where appropriate, but respect existing conventions in the codebase
---
## C# Specific
- use Notification pattern (not C# events), Composer pattern (DI registration), Scoping with `Complete()`, Attempt pattern for operation results.
---
## Architecture
- Follow **Clean Architecture** principles
- **Fail-fast** principle: detect and report errors as early as possible
- Within the established layered architecture (Core/Infrastructure/Web/API), organize code by feature inside each layer where practical, while preserving dependency direction
- One class per file
- Avoid N+1 queries
- Profile before optimizing non-critical paths
### Type Hierarchy Consistency
When parallel model types have inconsistent relationships to a shared base type:
**TypeScript**: manipulations via `Omit`, `Pick`, intersection overrides, or workarounds like `as unknown as` / double-casts to bridge type mismatches.
**C#**: hiding base members with `new` to change types, explicit interface implementations to mask mismatches, or downcasting base return types in derived classes.
- **Do NOT suggest** the PR code should deviate from its base type to match a sibling that already deviates. Copying the deviation spreads the problem.
- **Do flag** the architectural inconsistency: parallel models should share a compatible base contract. The model that manipulates or deviates from the base type is the one that needs attention — not the one that extends it correctly.
- **Frame the suggestion** as: "These related models have inconsistent type hierarchies. `{deviating type}` manipulates the base contract of `{base type}`, which forces shared consumers like `{shared utility}` to require a shape that conforming subtypes can't satisfy."
---
## Code Style
- Follow standard naming conventions for the language (C# or JS/TS)
- Keep components small and focused on a single responsibility
- Prefer early returns
- Small functions
- No nested ternaries
---
## Severity Levels
| Severity | Meaning |
|----------|---------|
| **Critical** | Must fix before merge — security vulnerabilities, data loss risks, broken functionality |
For any file where the whitespace-ignored diff is less than **half** the full diff size (and the full diff is over 50 lines), that file has significant formatting changes mixed with logic. Flag it with a split suggestion: "File(s) {list} contain significant formatting changes mixed with logic. Consider a separate formatting-only commit or PR to keep the functional diff reviewable."
## Multi-project scope check
Skip this section entirely if ALL production files reside in a single project directory or if the PR is docs-only, test-only, dependency-bump-only, or rename-only.
Otherwise, flag any dimension that applies:
| Dimension | Condition | Suggestion |
|---|---|---|
| **Size** | 30+ files OR 1500+ lines, spanning 2+ projects | "If changes in {projectA} and {projectB} are independently functional, they could be separate PRs." |
| **Mixed intent** | 2+ intent categories (new feature, bugfix, refactor, dependency update) with 15+ files or 3+ projects | "Consider extracting the {secondary intent} into a separate PR." |
Intent categories — detect from diff characteristics, not commit messages:
- **New feature**: new files or new `public`/`export` declarations
- **Bug fix**: small targeted edits, no new files (don't co-flag with new feature)
- **Refactor**: file renames, symbols moved but logic unchanged
- **Dependency update**: changes to `.csproj`, `Directory.Packages.props`, `package.json`
This document describes how to perform impact analysis during PR review. The goal is to look beyond the diff to understand how changes affect consumers in other parts of the codebase.
---
## 1. Extract Changed Public Symbols
Scan the diff output for changes to public API surface:
### Backend (.NET)
Look for added, modified, or removed lines containing:
- **Notification handlers**: if a notification type changed, search for `INotificationHandler<NotificationTypeName>` and `INotificationAsyncHandler<NotificationTypeName>`
- **Interface implementations**: if an interface changed, search for `: IInterfaceName` or `IInterfaceName,`
### Excluding the Changed File
When reporting consumers, exclude files that are part of the PR's changes (they're already being reviewed). The interesting consumers are those **outside** the PR that may be affected.
---
## 3. Check Dependency Flow Direction
The Umbraco architecture enforces strict unidirectional dependencies:
```
Api.Management / Api.Delivery (depend on Api.Common)
file_header_template=Copyright (c) Umbraco.\nSee LICENSE for more details.
# SA1636: File header copyright text should match
# Justification: .editorconfig supports file headers. If this is changed to a value other than "none", a stylecop.json file will need to added to the project.
description:"Please write the *exact* version, example: `10.1.0`. Use the help icon in the Umbraco backoffice to find the version you're using"
description:"Please write the *exact* version, example: `10.1.0`. Click the Umbraco logo in the top left corner of the backoffice to find the version you're using."
Always reference these instructions first and fallback to search or bash commands only when you encounter unexpected information that does not match the info here.
## Working Effectively
Bootstrap, build, and test the repository:
- Install .NET SDK (version specified in global.json):
Always wait for commands to complete rather than canceling and retrying.
The full development guide for this repository lives in [CLAUDE.md](../CLAUDE.md). Please read that file for complete instructions on architecture, build steps, testing, branching conventions, and coding patterns.
**Description**: A short, kebab-case description (a few words). This should be prefixed with the GitHub issue number if the update is related to resolving a tracked issue.
See `.github/CONTRIBUTING.md` for full guidelines.
### Pull Request Process
@@ -173,7 +199,7 @@ Use the format: `Area: Description (closes #IssueID)`
- Describe the change and its impact
- Be specific, not vague (describe "a golden retriever" not just "a dog")
**Issue Linking**: Add `(closes #IssueID)` to auto-close linked issues on merge.
**Issue Linking**: Add `(closes #IssueID)` to the title for readability, AND include a closing keyword on its own line in the PR body (e.g., `Fixes #IssueID`) so GitHub actually auto-links and auto-closes the issue on merge. GitHub only parses closing keywords (`closes`, `fixes`, `resolves`) from the PR body or commit messages — the title suffix is cosmetic and does **not** trigger auto-close on its own.
### Commit Messages
@@ -202,9 +228,11 @@ Project ownership is distributed across teams. Check individual project director
1.**Layered Architecture with Dependency Inversion**
- Core defines contracts (interfaces)
- Infrastructure implements contracts
- Infrastructure implements contracts that need Infrastructure-owned machinery
- Web/APIs consume implementations via DI
**Where service implementations live**: Services whose dependencies are satisfiable from Core interfaces alone (repositories, scope, config, other Core services) live in `Umbraco.Core/Services/` — this covers the majority of domain services (`MemberService`, `ContentService`, `MediaService`, `ContentTypeService`, `EntityService`, `AuditService`, `ExternalMemberService`, etc.). Service implementations only live in `Umbraco.Infrastructure/Services/Implement/` when they genuinely need Infrastructure concerns — Examine indexes (`ContentSearchService`, `MediaSearchService`, `IndexedEntitySearchService`), log files (`LogViewerRepository`), packaging internals (`PackagingService`), webhook firing (`WebhookFiringService`), distributed-job coordination (`DistributedJobService`). When adding a new service, default to Core and only move to Infrastructure if a concrete dependency forces it.
2.**Interface-First Design**
- All services defined as interfaces in Core
- Enables testing, polymorphism, extensibility
@@ -234,20 +262,132 @@ Project ownership is distributed across teams. Check individual project director
---
## 5. Project-Specific Notes
## 5. Avoiding Breaking Changes
No binary breaking changes are allowed within a major version. Three patterns are used:
When a public class needs new dependencies, obsolete the existing constructor and add a new one. The old constructor delegates to the new one, resolving missing deps via `StaticServiceProvider`.
```csharp
[Obsolete("Please use the constructor with all parameters. Scheduled for removal in Umbraco 19.")]
- Old constructor marked `[Obsolete("... Scheduled for removal in Umbraco {current-major+2}.")]`
- Old constructor calls new constructor via `: this(...)`
- Uses `StaticServiceProvider.Instance.GetRequiredService<T>()` for new params only
- DI registration must use the NEW constructor (old is for external consumers only)
### 5.2 Obsolete Method + New Overload
When a public method signature needs to change, add the new method/overload and obsolete the old. The obsolete method should call the new one with suitable defaults.
```csharp
[Obsolete("Use the overload taking all parameters. Scheduled for removal in Umbraco 19.")]
publicvoidDoThing(stringname)
=>DoThing(name,extraParam:null);
publicvoidDoThing(stringname,string?extraParam)
{
// Real implementation here
}
```
**Rules**:
- Old method marked `[Obsolete]` with removal schedule
- DRY: old method calls new method, providing defaults for new parameters
- All internal callers must be updated to use the new method
- No callers should remain on the obsolete method within the codebase
### 5.3 Default Interface Implementation
When adding methods to a public interface, provide a default implementation so existing external implementations don't break.
```csharp
publicinterfaceIMyService
{
// Existing method
voidExistingMethod();
// New method with default implementation
voidNewMethod(stringparam)
=>ExistingMethod();// delegate to existing if possible
}
```
**Strategies for the default** (in order of preference):
1.**Use existing interface methods** to satisfy the contract (even if not optimal)
2.**Return a sensible default** like empty collection, null, etc.
3.**Throw `NotImplementedException`** if no reasonable default exists
**Example**: `IContentService.SaveBlueprint` - new overload with `IContent? createdFromContent` has a default impl that calls the old method (ignoring the new param).
**Example**: `IDocumentPresentationFactory.CreateCulturePublishScheduleModels` - full default implementation with logic, uses `StaticServiceProvider` for dependency resolution within the interface.
**Rules**:
- Add `// TODO (V{next-major}): Remove the default implementation when {obsolete method} is removed.` comment
- Default impl should be functionally correct even if not optimal
- If using `StaticServiceProvider` in a default impl, note this is temporary
### 5.4 General Rules
- **Removal policy**: Obsoleted members must remain for at least one full major version before removal. If obsoleted in version N, the earliest removal is version N+2. For example, something obsoleted in v17 is scheduled for removal in v19 (giving the whole of v18 as a deprecation period).
- All `[Obsolete]` attributes must include **"Scheduled for removal in Umbraco {current+2}"**
- Read `version.json` to determine the current major version
- Suppress `CS0618` warnings where obsolete members must call each other:
```csharp
#pragma warning disable CS0618 // Type or member is obsolete
=> OldMethod(param);
#pragma warning restore CS0618 // Type or member is obsolete
```
- Update ALL internal callers to use the new API - no internal code should use obsolete members
---
## 6. Project-Specific Notes
### Centralized Package Management
**All NuGet package versions** are centralized in `Directory.Packages.props`. Individual projects do NOT specify versions.
**NuGet package versions** are centralized in `Directory.Packages.props`. There are two `Directory.Packages.props` files in the source tree, with multi-level merging enabled so the test file inherits from the root:
| File | Scope |
|------|-------|
| `Directory.Packages.props` (root) | Production source code packages — referenced by all `src/**` projects |
| `tests/Directory.Packages.props` | Test-only packages (NUnit, Moq, Bogus, BenchmarkDotNet, etc.) — adds entries on top of the inherited root file |
When updating dependencies, decide which file the package belongs in:
- A package used only by test projects → `tests/Directory.Packages.props`
- A package used by any production project (or by both production and tests) → root `Directory.Packages.props`
```xml
<!-- Individual projects reference WITHOUT version -->
**Opt-out**: `src/Umbraco.Web.UI/Umbraco.Web.UI.csproj` sets `<ManagePackageVersionsCentrally>false</ManagePackageVersionsCentrally>` and specifies versions inline (for `Microsoft.EntityFrameworkCore.Design`, `Microsoft.Build.Tasks.Core`, `Microsoft.ICU.ICU4C.Runtime`, etc.). Update those versions directly in that csproj when bumping. Two further `Directory.Packages.props` files exist under `templates/` for the project/extension templates and have their own version sets — keep `Microsoft.AspNetCore.OpenApi` aligned between the root file and `templates/UmbracoExtension/`.
When a PR changes Management API controllers or models, the `OpenApi.json` file in the Management API project must be updated:
1. Run the Umbraco instance locally
2. Open Swagger UI and navigate to the swagger.json link (e.g. `https://localhost:44339/umbraco/swagger/management/swagger.json`)
3. Copy the full JSON content and paste it into `src/Umbraco.Cms.Api.Management/OpenApi.json`
**Important**: Commit only the substantive changes — not IDE-applied formatting (whitespace, reordering, etc.). Extraneous formatting diffs make PRs harder to review and merge-ups more error-prone.
### Backoffice npm Package
The backoffice is published to npm as `@umbraco-cms/backoffice`. Runtime dependencies are provided via importmap; npm peerDependencies provide types only. For full details on dependency hoisting, version range logic, and plugin development, see `/src/Umbraco.Web.UI.Client/CLAUDE.md` → "npm Package Publishing".
### SQL Server 2100-parameter limit
Any `WHERE IN (@0, @1, ...)` built from a runtime-sized collection risks hitting SQL Server's 2100-parameter ceiling and throwing `SqlException` 8003 in production.
Batch with `IEnumerable<T>.InGroupsOf(Constants.Sql.MaxParameterCount)` or `Database.FetchByGroups(...)` whenever the collection size is driven by user data — not just when it currently fits. Watch for products of two scaling dimensions (documents × languages, properties × versions) and config-tunable batch sizes whose defaults are safe but ceilings aren't.
Full guidance, safe patterns and decision rule: see `/src/Umbraco.Infrastructure/CLAUDE.md` → "Avoiding the SQL Server 2100-parameter limit".
### Known Limitations
@@ -296,6 +464,104 @@ APIs use `Asp.Versioning.Mvc`:
---
## 7. CI/CD — Claude AI Assistant
Two GitHub Actions workflows powered by `anthropics/claude-code-action@v1`. Advisory only — does not block merging.
### Workflows
| File | Trigger | Purpose |
|------|---------|---------|
| `claude-review.yml` | `pull_request: [opened, ready_for_review]` | Auto-review every non-draft PR using the `umb-review` skill |
| `claude.yml` | `@claude` comments, issue assign/label | Interactive assistant for PRs and issues |
### Auto-Review (`claude-review.yml`)
Runs the full `.claude/skills/umb-review/SKILL.md` procedure on every newly opened or un-drafted PR. Produces inline comments per finding and one summary comment with a verdict. Skips draft PRs. No turn limit.
### Interactive (`claude.yml`)
Responds to `@claude` mentions on PRs and issues. The trigger phrase is stripped before Claude sees the message, so:
- `@claude review` → light review using `gh pr diff` (not the umb-review skill)
- `@claude fix ...` → implements a fix on a new branch
- `@claude help` → answers questions about the codebase
- `@claude label` → applies labels
- `@claude` (empty) → defaults to `review` on PRs, `help` on issues
Also triggers on issue assignment to `claude` or adding the `claude` label. Gated: only runs when `@claude` appears in the comment/issue body. Max 25 turns.
**On Issues** (based on content): same `area/*` and `category/*` labels, plus `affected/v14` through `affected/v17` and `affected/backoffice`.
Labels are only added, never removed. Claude applies only labels it is confident about.
### Key Implementation Notes
- **Checkout required** — the action internally runs `git fetch origin main` for trusted file restoration. Without `actions/checkout`, it fails with `fatal: not a git repository`.
- **`id-token: write` permission** — required for OIDC token exchange with the Claude GitHub App.
- **Trigger phrase stripping** — the action strips `@claude` from comments before passing to Claude. Prompts must reference commands without the prefix (e.g., `review` not `@claude review`).
- **PR number injection** — the interactive workflow injects the PR/issue number into the prompt via `${{ github.event.issue.number }}` since Claude can't discover it from `gh pr view` when checked out on `main`.
---
## 8. Code Comment Policy
**Default to no comment.** Applies to all code in this repository — C#, TypeScript, Razor, build scripts. Well-named identifiers and small functions are the primary form of self-documentation; comments are a fallback for the rare cases where the code itself cannot carry the meaning.
### When NOT to comment
- **Don't restate what the code does.** A line calling `resetState()` does not need `// Reset state`. A method named `validateInput` does not need `// Validate input`.
- **Don't narrate a sequence of calls.** If three lines run in order, the order is in the code — don't paraphrase it above.
- **Don't reference the current task, fix, callers, or PR.** No `// Fix for X`, `// Used by Y`, `// Added for the Z flow`, `// See PR #1234`. That belongs in commit messages and PR descriptions; in source it rots as the codebase evolves.
### When a comment IS justified
Write a comment only when **removing it would leave a future reader confused**. Concretely:
- **A non-obvious WHY.** A hidden constraint, business rule, or ordering requirement that is not visible from the code.
- **A workaround for a specific bug or platform quirk.** Link the issue (`(#21996)`, `https://...`) so the comment can be deleted once the upstream fix lands.
- **A subtle invariant** that the type system or method names do not enforce.
- **An edge case the code intentionally handles** that would surprise a reader (e.g. "must run before X because Y").
- **API documentation** — XML doc comments on C# members, JSDoc on exported TypeScript symbols. Required for the public contract; still keep them concise.
### TODOs
Allowed, but cheap to write and cheaper to leave behind. Keep them short and trackable: `// TODO (V19): remove once obsolete overload is gone` or `// TODO: pagination [NL]`. A TODO should have an author or a version trigger.
---
## 9. Testing Practices
### Tests for a bug fix must fail before the fix
Verify any test you add for a bug fix actually catches the bug: either write the failing test first (TDD), or temporarily revert the production change and confirm the test fails before re-applying. A test that passes both ways proves nothing. Watch for coincidental passes — default seed/sort orders can make a buggy path produce the right answer for the test's specific inputs; construct inputs so the broken and fixed behaviours give visibly different results.
For integration tests that exercise caching or cache refreshers, see `tests/Umbraco.Tests.Integration/CLAUDE.md` — the harness disables caching by default, which can produce false greens.
---
## Quick Reference
### Essential Commands
@@ -317,6 +583,16 @@ dotnet format
dotnet pack -c Release
```
### Integration Test Database Configuration
Integration tests are configured in `tests/Umbraco.Tests.Integration/appsettings.Tests.json`.
The `Tests:Database:DatabaseType` setting controls which database is used:
- `"SQLite"` (default) - No external dependencies
- `"LocalDb"` - Uses SQL Server LocalDB, required for SQL Server-specific tests (e.g., page-level locking, `sys.dm_tran_locks`)
SQL Server-specific tests use `BaseTestDatabase.IsSqlite()` to skip when running on SQLite.
### Key Projects
| Project | Type | Description |
@@ -342,6 +618,9 @@ dotnet pack -c Release
For detailed information about individual projects, see their CLAUDE.md files:
- **Core Architecture**: `/src/Umbraco.Core/CLAUDE.md` - Service contracts, notification patterns
**Important**: When working on backoffice client code (anything under `src/Umbraco.Web.UI.Client/`), read `/src/Umbraco.Web.UI.Client/CLAUDE.md` first. It contains action-specific checklists (deprecation, testing, security, etc.) that are not duplicated here.
This repository includes configuration for [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) servers, enabling AI tooling integration for Umbraco CMS development workflows.
## Overview
MCP allows AI assistants (like Claude) to interact with external tools and services. This repository configures two MCP servers:
| Server | Purpose | Package |
|--------|---------|---------|
| **umbraco-cms** | Manage Umbraco content types, documents, and media | `@umbraco-cms/mcp-dev@17` |
| **playwright** | Browser automation for testing and debugging | `@playwright/mcp@latest` |
## Quick Start
### 1. Start Umbraco Locally
Ensure your local Umbraco instance is running at `https://localhost:44339` (or update the URL in your `.env.local`).
### 2. Configure Environment Variables
Copy the example environment file and customize it:
> **Warning**: This configuration is for **local development only**.
### Self-Signed Certificates
`NODE_TLS_REJECT_UNAUTHORIZED=0` disables SSL certificate validation. This is necessary for self-signed certificates in local development but:
- **Never use in production**
- Affects all HTTPS connections made by Node.js processes
- Consider trusting your local development certificate instead
### Client Secrets
- Never commit real secrets to source control
- The `.env.local` file is gitignored for this reason
- Use strong, unique secrets even in development
- The example value `1234567890` in `.env.example` is a placeholder only
## File Structure
```
Umbraco-CMS/
├── .mcp.json # MCP server configuration
├── .env.example # Example environment variables (committed)
├── .env.local # Your local environment variables (gitignored)
├── .claude/
│ ├── settings.json # Shared Claude AI permissions (committed)
│ └── settings.local.json # Local Claude overrides (gitignored)
├── .gitignore # Ignores .env.local and settings.local.json
└── MCP.md # This documentation (you are here)
```
## Claude AI Permissions
The `.claude/settings.json` file configures which MCP tools Claude can use automatically without prompting. This is shared across the team for consistent developer experience.
### Customizing Permissions Locally
Create `.claude/settings.local.json` to override permissions for your environment:
```json
{
"permissions":{
"allow":[
"mcp__umbraco__get-all-document-types"
]
}
}
```
## Troubleshooting
### "Connection refused" errors
- Ensure Umbraco is running at the configured `UMBRACO_BASE_URL`
- Check that the port matches your local setup
### "Unauthorized" errors
- Verify the OAuth client is configured in Umbraco
- Check that `UMBRACO_CLIENT_ID` and `UMBRACO_CLIENT_SECRET` match
- Ensure the client has appropriate permissions
### "Certificate" errors
- For local development, set `NODE_TLS_REJECT_UNAUTHORIZED=0` in `.env.local`
- Alternatively, trust your local development certificate
### MCP server not starting
- Ensure Node.js is installed (v22+ recommended, matching .nvmrc)
- Run `npx @umbraco-cms/mcp-dev@17 --help` to verify the package works
=> type.Namespace?.StartsWith("MyProject") is true;
OpenAPI transformers are scoped per-document. To customize a document, implement `IOpenApiDocumentTransformer`, `IOpenApiOperationTransformer`, or `IOpenApiSchemaTransformer` and register with your OpenAPI options.
**Decision**: Make `SchemaIdHandler`, `OperationIdHandler`, etc. virtual.
**Why**: Management API and Delivery API have different schema ID requirements. Virtual methods allow override without rewriting the entire handler.
**Example**: Management API might prefix all schemas with "Management", Delivery API with "Delivery".
With Microsoft.AspNetCore.OpenApi, transformers are configured per OpenAPI document. This means custom transformers only apply to the documents they're registered with, not globally. Each API (Management, Delivery) configures its own transformers via `ConfigureUmbracoOpenApiOptionsBase` subclasses.
=>$"{apiDesc.GroupName}_{apiDesc.ActionDescriptor.AttributeRouteInfo?.Template ?? apiDesc.ActionDescriptor.RouteValues["controller"]}_{(apiDesc.ActionDescriptor.RouteValues.TryGetValue("action", out var action) ? action : null)}_{apiDesc.HttpMethod}";
/// <param name="jsonOptionsFactory">Factory invoked when the schema service is first resolved. Receives the resolving <see cref="IServiceProvider"/> and returns the <see cref="JsonOptions"/> to use.</param>
/// <returns>The same <see cref="IServiceCollection"/> for chaining.</returns>
/// <remarks>
/// Workaround for <see href="https://github.com/dotnet/aspnetcore/issues/66340">dotnet/aspnetcore#66340</see>.
/// <param name="documentName">The name/identifier of the OpenAPI document.</param>
/// <param name="documentTitleFactory">Factory invoked when SwaggerUI options are resolved. Returning <c>null</c> falls back to <paramref name="documentName"/>.</param>
/// Applies the accumulated configuration to the supplied <see cref="IUmbracoBuilder"/>'s service
/// collection. Called by <c>AddBackOfficeOpenApiDocument</c> once the user-supplied callback returns.
/// </summary>
/// <param name="builder">The Umbraco builder to register services against.</param>
internalvoidBuild(IUmbracoBuilderbuilder)
{
// AddOpenApi lowercases the document name when registering its keyed services (https://github.com/dotnet/aspnetcore/blob/v10.0.9/src/OpenApi/src/Extensions/OpenApiServiceCollectionExtensions.cs#L64),
// so we must normalise here to keep AddOpenApiDocumentToUi and ReplaceOpenApiSchemaService in sync.
/// Generates a sanitized and consistent schema identifier for a given type following Umbraco's schema id naming conventions.
/// </summary>
protectedstringUmbracoSchemaId(Typetype)
{
varname=SanitizedTypeName(type);
name=HandleGenerics(name,type);
if(name.EndsWith("Model")==false)
{
// because some models names clash with common classes in TypeScript (i.e. Document),
// we need to add a "Model" postfix to all models
name=$"{name}Model";
}
// make absolutely sure we don't pass any invalid named by removing all non-word chars
returnRegex.Replace(name,@"[^\w]",string.Empty);
}
privatestringSanitizedTypeName(Typet)=>t.Name
// first grab the "non-generic" part of any generic type name (i.e. "PagedViewModel`1" becomes "PagedViewModel")
.Split('`').First()
// then remove the "ViewModel" postfix from type names
.TrimEnd("ViewModel");
privatestringHandleGenerics(stringname,Typetype)
{
if(!type.IsGenericType)
{
returnname;
}
// use attribute custom name or append the generic type names, ultimately turning i.e. "PagedViewModel<RelationItemViewModel>" into "PagedRelationItem"
Some files were not shown because too many files have changed in this diff
Show More
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.