Commit Graph
861 Commits
Author SHA1 Message Date
Kevin JahnsandManuel Raynaud 4041d38db2 ⬆️(collaboration) upgrade yhub to 0.8.0 and adopt its permission model
yhub 0.8.0 retires the 'r' | 'rw' | null access vocabulary. The auth
plugin now answers a typed permission object stating, facet by facet,
what a subject may do with a document, and yhub enforces every facet
itself - on the websocket and on the REST routes alike. Three rules we
wanted but could not express under the old vocabulary become one-line
facets. Our whole access policy now lives in
src/yhub-server/permissions.js, apart from the server so that it can be
read and tested without standing up redis and postgres.

Read-only users no longer share their cursor #2544. A read-only
connection could still propagate awareness updates to everyone else in
the document, even though its document updates were already dropped.
Presence is now a permission of its own, separate from the right to
edit: a reader receives it and never publishes it. The collaboration
server enforces that rather than trusting the editor to stay quiet, so a
modified or stale client changes nothing. The frontend has to know it
too - the http fallback provider has no receive-only mode, so a reader's
provider is built with no awareness instance at all, or its first PATCH
would take a 403 and close it for good.

The browser is granted only the two routes it uses, the websocket and
ydoc for the http fallback. Everything else - history, rollback, prune,
and every backend-internal endpoint - is refused to it, as is any
endpoint a future release adds, because the grant names no wildcard.
create-ydoc in particular was reachable by any signed-in editor and is
now the backend's alone.

Anonymous visitors are given the userid "anonymous" rather than no
identity at all, which is what lets them keep editing public documents:
yhub refuses the upgrade of a caller that holds the write but cannot be
attributed. Their edits share one author.

Room is DocRef throughout, which is a rename of object keys and not only
of types: the worker event payload and the stream message lookup both
carry it, and both fail silently rather than loudly when missed.

Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:01:41 +02:00
Manuel Raynaud 795cca30bf 🐛(frontend) stop reconnecting to the websocket based on the status code
The yhub server returns custom status code when the websocket is not
accessible, like 4401 when an access is removed and 4404 when a document
is deleted. the websocket client now use these custom status code to
stop reconnection forever.
2026-09-22 16:00:55 +02:00
Manuel Raynaud cfe837bc32 (collaboration) notify the backend when the worker persists new content
notify the backend when the worker persists new content for
a document, so the lists ordered by `updated_at` follow the edits made on the
collaboration server. The backend serves it on
`POST /api/v1.0/documents/{id}/content-updated/`, authenticated with a short
lived RS256 JWT the collaboration server signs (`aud: "docs-backend"`) and
the backend verifies against the JWKS the collaboration server publishes on
`/collaboration/jwks/v1` — the mirror of the admin token the backend signs to
call it, so no long lived secret is shared and either side can roll its key
on its own
2026-09-22 16:00:51 +02:00
Manuel Raynaud 3e10ba1b9f (backend) serve documents/{id}/formatted-content/ from yhub
The formatted-content endpoint was using the `document.content` to fetch
the ydoc from s3, we want to move from this usage to using yhub to
retrieve the content, so yhub is becoming our source of thruth.
2026-09-22 16:00:51 +02:00
Manuel Raynaud 2408690380 💥(backend) remove the documents/{id}/content/ endpoint
Both its PATCH and its GET: the content of a document is saved and
served by the collaboration server. The `content_patch` and
`content_retrieve` abilities go with it.
2026-09-22 16:00:50 +02:00
Manuel Raynaud 565a8c0da6 (backend) duplicate a document through the collaboration server
its stateis fetched from yhub and seeded into the copy instead
of being copied from the content stored by Django
2026-09-22 16:00:50 +02:00
Manuel Raynaud d200995c01 (collaboration) add a get-ydoc endpoint on yhub
`GET /collaboration/get-ydoc/v1/docs/{id}` answers the current Yjs state of a
document as a raw binary update, the read counterpart of create-ydoc, and
204 when the document has no content yet
2026-09-22 16:00:50 +02:00
Manuel Raynaud 7e851c0133 (backend) call YHubService to seed initial document content
When a new Docs is created and a file is sent, as before we convert it
first and we need to use the raw content to seed it by calling the
create-ydoc api in the YHub service.
2026-09-22 16:00:49 +02:00
Manuel Raynaud 95282ff410 ️(backend) reintroduce the reset connection mechanism
When an access change or is deleted or a link configuration changes, we
call the yhub server to reset connections and remove them if needed. The
YHubService is used for this.
2026-09-22 16:00:49 +02:00
Manuel Raynaud 6d0e2e6301 (backend) add a service to call the yhub REST API
The backend application will have to call the yhub REST API for some
operations. We want to use a dedicated service to do that. This first
commit introduces the shape of this service, it only does the
configuration for now, calling actions will be implemented later.
2026-09-22 16:00:48 +02:00
Manuel Raynaud f8ee47fe5b 🔧(collaboration) adapt docker stack for development purpose
The yhub image was build only for a production usage. In development we
want to have a hot reload when a file is modified. For this the
Dockerfile is modified, the nodemon package install in dev environment
and used to watch modification against the source files.
2026-09-22 16:00:48 +02:00
Kevin JahnsandManuel Raynaud 43c48dbc10 🔒️(collaboration) reject admin jwts not issued for the yhub audience
yhub verified Django's RS256 admin JWT without checking "aud", so the
y-converter token Django hands to the converter process was replayable
here — and admin: true short-circuits getAccessType to "rw" on every
document, plus the backend-internal reset-connections purpose and the
X-User-Id attribution override. Require aud: "yhub", as y-provider
already does for its own audience. Nothing in the backend calls yhub's
admin endpoints yet, so no caller is affected.

Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:00:46 +02:00
Kevin JahnsandManuel Raynaud 8e295b5955 (collaboration) soft-migrate legacy S3 documents into yhub
With SOFT_MIGRATION=true, the first access to a document yhub does not
know yet fetches the legacy snapshot from Django's S3 media bucket
({id}/file, UTF-8 base64 of a raw Yjs update), seeds the room through
the compute pool - attributed to "system" with a migration=s3 custom
attribution - and only then admits the connection, so the initial sync
always includes the seed. Now that the frontend no longer bootstraps
rooms client-side (content GET/PATCH removal), this is the only path
that brings legacy content into yhub; keep the flag on until a batch
backfill has migrated the full corpus.

A missing S3 object is the brand-new-document case and yields an empty
room; every real failure fails closed (opaque 401, y-websocket retries
with backoff). Existence is probed postgres-first (bare SELECT, then
the valkey stream, then the SELECT again to close the compaction
race). Guard rails: a per-docid verdict cache (poison objects cannot
sustain an S3 retry storm, transient errors expire in 15s, per-replica
seed backpressure denies once without caching), in-flight dedup, a
token-owned cross-replica valkey lock released by compare-and-delete,
a 10s S3 fetch timeout that also destroys a late-arriving response
stream, and the same 10MiB decoded cap as create-ydoc. Concurrent
seeds stay correct regardless: the frozen snapshots share one Yjs
lineage, so duplicates merge as CRDT no-ops.

Also reject non-lowercase docids (Django serializes UUIDs lowercase; a
case variant would open a parallel room and miss its S3 object) and
refuse to boot when AWS_S3_ENDPOINT_URL carries a path the minio
client cannot address. On AWS the read-only credentials must include
s3:ListBucket so a missing object surfaces as NoSuchKey rather than
AccessDenied - see the README for the full guarantees and ops notes.

Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:00:46 +02:00
Kevin JahnsandManuel Raynaud 62de1b6124 (collaboration) add create-ydoc endpoint on yhub
Python cannot call yhub's built-in PATCH ydoc api because its body must
be lib0-any encoded - a lib0-specific binary framing with no
implementation outside javascript. The new endpoint
POST /collaboration/create-ydoc/v1/{org}/{docid} accepts the raw binary
Yjs update (pycrdt get_update() / Y.encodeStateAsUpdate output) as
application/octet-stream, so Django can seed a document's initial state
with a plain requests.post(url, data=raw_bytes) - needed by the
server-side creation flows (file import, create-for-owner, duplication,
template instantiation) whose yhub rooms currently stay empty until the
first browser connects.

Strict create semantics: 409 when the room already has content
(checked via getDoc, covering persisted state and uncompacted stream
messages; yhub has no atomic create, concurrent creates merge via CRDT
and never corrupt). The initial content is attributed to the optional
X-User-Id header, else to the caller's identity. Access uses the
default purpose, i.e. standard document write access like the built-in
ydoc routes: the admin JWT, or a user session with update ability.
Malformed updates map to 400 (the compute worker rejects them and the
pool replaces the thread), empty updates to 400, bodies over 10MiB to
413.

Gotcha worth noting: req.bytes() resolves to a Node Buffer, but yhub's
compute-task schema validates with lib0's exact-constructor Uint8Array
check, so the body is re-viewed as a plain Uint8Array before it is
handed to the compute pool.

Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:00:44 +02:00
Kevin JahnsandManuel Raynaud 3798f83f52 (collaboration) add admin reset-connections endpoint on yhub 0.4.0
Add POST /collaboration/reset-connections/v1/{org}/{docid} (optional
X-User-Id header) to yhub-server. It distributes yhub recheckAuth: every
server re-runs the access check per matching connection and closes only
those whose access actually changed (close code 4401), so unaffected
clients see no reconnect churn. The endpoint authenticates with the
RS256 admin JWT issued by JWTService, verified against the backend JWKS
(new jose dependency); the admin token acts as the "system" user and is
the only principal granted the reset-connections access purpose. The
backend does not trigger it on permission changes yet - that wiring
comes separately, now that CollaborationService is gone.

yhub is upgraded to 0.4.0 and serves every route under the
/collaboration/ prefix (server.apiPrefix): the websocket moves to
/collaboration/ws/v1/docs, and the built-in document apis are meant to
be publicly exposed alongside it, with reset-connections as the one
backend-internal exception.

Also harden websocket auth: fail closed when the backend errors (only a
genuine 401/403 falls back to the anonymous identity, so a signed-in
editor can never hide from a targeted recheck under an anon userid) and
tolerate small clock skew when verifying the cached admin token.

Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:00:43 +02:00
Manuel Raynaud ebfc759053 🔥(backend) remove CollaborationService and can-edit endpoint
The CollaborationService was doing nothing since we started the
migration to yhub, all the code using it is now removed. Also the
`can-edit` endpoint and all the safeguard mechanism relying on the
presence of other users connected to the websocket will not be used
anymore, it will be possible to replace all of this with yhub, so all
this code is also removed.
2026-09-22 16:00:42 +02:00
Manuel Raynaud dde9718ca0 🔧(dev) generate the JWT signing key when bootstrapping the dev stack
Thw private key needed to generate a jwt token will be mandatory. In
order to ease the development we want to automate its generation
2026-09-22 16:00:42 +02:00
Manuel Raynaud af0cdeaf1a (backend) publish the JWT public key on a JWKS endpoint
The yhub service will need our public key in order to validate the jwt
token we will used. We choose to expose a jwks endpoint as it is a
standard wat to do this.
2026-09-22 16:00:41 +02:00
Manuel Raynaud b9cd646605 (backend) add a service generating cached RS256 JWT tokens
We want to generate jwt token using the RS256 algotrithm. This token
will be used for internal call with the yhub service.
2026-09-22 16:00:39 +02:00
Kevin JahnsandManuel Raynaud eb94d726b0 ♻️(collaboration) switch collaboration server from hocuspocus to yhub
Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:00:22 +02:00
MANI KandAnthony LC a75dbaaeb9 🐛(frontend) clear callout background on Backspace
Reset the background when Backspace converts a callout to a paragraph.
Preserve content, alignment, regular text deletion, and undo behavior.

Fixes #2052

Signed-off-by: Manixhor <manigururam@hotmail.com>
2026-09-22 10:36:39 +02:00
Gokul KrishnaandAnthony LC 3fa9186289 (frontend) add markdown download option
Export Markdown as a ZIP containing the document and same-origin media.
Normalize filenames and restore the export UI after asynchronous failures.
Cover media packaging, modal behavior, filenames, and the browser flow.

Signed-off-by: Gokul Krishna <gokul.06krishna@gmail.com>
2026-09-22 09:33:53 +02:00
Anthony LC 74d822bb27 🚸(frontend) add shortcut indication on doc option
For users to know the keyboard shortcut for opening
the presenter mode, we add a visual indication of the
shortcut in the doc option menu.
2026-09-21 14:16:29 +02:00
Ovgodd b303173923 💄(frontend) redesign 404 error standalone page
Use the standalone layout for the 404 page to unify error page chrome.
2026-09-21 11:09:00 +02:00
Anthony LC c6631ae29e (frontend) duplicate with subdocuments
We can now choose to duplicate documents along with
their subdocuments. A confirmation modal will now
appear to let the user choose whether to include
subdocuments in the duplication, only if the document
has subdocuments.
A toast notification will inform the user and
give the possibility to undo the duplication if
needed.
2026-09-18 16:17:31 +02:00
Anthony LC f52224cac9 🐛(frontend) fix redirect after deleting a document
We fixed the redirect behavior after deleting a
document to ensure the user stays on the correct page
after deleting a document.
We added a test to avoid regression in the redirect
behavior.
2026-09-18 15:49:28 +02:00
risk-altandAnthony LC 5b661d7224 🥅(frontend) warn before uploading a file over the size limit
Dropping a file larger than the allowed size showed a bare "unknown
error" in the editor. The proxy in front of the API cuts the request
and answers a 413 with an HTML body, so errorCauses threw while
parsing it as JSON and no cause ever reached the error panel.

The size limit the backend already enforces is now exposed by the
config endpoint, and the editor checks the file against it before
sending anything, with the same toast wording the document import
uses. errorCauses no longer throws on a body it cannot parse, and a
413 without a usable cause falls back to an explicit message, which
covers the instances whose proxy limit is lower than the application
one.

The size formatting duplicated in the import hook moved to a shared
util.

Signed-off-by: risk-alt <aldu6974@gmail.com>
2026-09-17 16:04:26 +02:00
Anthony LC f15544e47e 🐛(frontend) reduce PostHog volume from web vitals and opt_in spam
$opt_in fired on every reconnect since opt_in_capturing() captures an
event by default, even though this call just re-enables tracking after
a network drop and isn't a real consent action. Also disable web
vitals capture, which fed a single low-value insight.
2026-09-17 10:35:22 +02:00
Ovgodd 10e8b03f14 🐛(export) keep image aspect ratio in PDF columns
Ensure images in PDF columns keep their original aspect ratio
2026-09-17 08:51:01 +02:00
Anthony LC 0aa15262d4 (helm) allow disallowing search engine indexing per instance
Add an optional ConfigMap-backed robots.txt mounted into the frontend
static export (frontend.robotsTxt.enabled/content), following the same
pattern as backend.themeCustomization, and enable it with a full
Disallow on the feature review-app environment.
2026-09-16 17:40:57 +02:00
Anthony LC 147bf68dda 🔖(release) minor 5.7.0
Added:
- 🔧(backend) fine tune redis cache options
- (frontend) make the full last-update date available
- 💄(frontend) redesign email confirmation standalone page

Changed:
- ⬆️(backend) upgrade celery to version 5.6.3
- ️(backend) stop using LEFT(value, LENGTH(path)) in sql queries
- 🚚(project) switch docspec image to ghcr.io/docspec/api
- 🚚(global) move favorite documents API endpoint
  to `/documents/favorites/`

Fixed:
- 🐛(backend) skip session creation for the liveness probe
- 🐛(frontend) preserve page titles when adding an emoji
- 🐛(frontend) scroll to the linked block in read-only documents
- 🐛(frontend) hide the selection highlight on presenter images
- 🐛(y-provider) prevent process crash on malformed websocket frames
- 🐛(frontend) keep commented text sharp when printing to PDF
- 🐛(docker) pull minio images from quay.io
- ️(frontend) restore presenter focus trapping after share links
- 🐛(frontend) export any raster image supported by the browser to a PDF
2026-09-15 16:19:39 +02:00
Anthony LC 5979c09b65 🐛(frontend) fix find & replace crash when editor becomes read-only
BlockNoteReader (read-only docs) doesn't register the find & replace
tiptap extension. If the panel is left open while the active editor
switches to it -- e.g. a collaborative doc turning read-only after a
WebSocket disconnect -- calling into its commands threw
"commands.clearSearch is not a function".

useFindReplace now exposes whether the current editor actually
supports find & replace, and FindReplace closes the panel and renders
nothing when it doesn't, instead of crashing.
2026-09-15 16:19:23 +02:00
Manuel RaynaudandAnthony LC 26811a6bce 🐛(y-provider) prevent crash on malformed frames from rejected websockets
When a WebSocket connection is rejected for a missing Origin or cookies,
or hits a route with no matching handler, express-ws still completes the
upgrade handshake and only closes the socket afterwards. The `ws`
library keeps parsing incoming frames during the close handshake, which
can take up to 30 seconds, and no 'error' listener was attached to these
sockets in the meantime. A single malformed frame (e.g. reserved bits
set) made the parser emit an unhandled 'error' event, crashing the whole
process and taking down realtime collaboration for every connected user.

We now attach the error listener on every WebSocket as soon as it is
created, before any routing or middleware runs, so malformed frames are
logged instead of crashing the server.
2026-09-15 15:35:15 +02:00
tanguy chenierandAnthony LC e695722283 🐛(frontend) keep commented text sharp when printing to PDF
Gecko cannot express a blended run in PDF, so it falls back to a bitmap of that
run: every commented sentence came out of Print as a 72 dpi image while the rest
of the page stayed text. The print stylesheet already hid the comment highlight,
but only its background and border, so mix-blend-mode stayed and that is what
forces the fallback.

Measured on the engine the report came from, printing the same page twice:
with the current rule the commented run is not extractable and the file carries
an image plus its alpha mask, with mix-blend-mode neutralised it is text again
and the file carries no image at all.

Signed-off-by: tanguy chenier <tanguychenier@gmail.com>
2026-09-14 14:40:54 +02:00
BOUKERFA Mohamed El AmineandAnthony LC 250b533417 (frontend) Scroll to linked block when read-only
Make the "Copy link to block" scroll for users with
Read-only permissions.

Signed-off-by: BOUKERFA Mohamed El Amine <boukerfa.ma@gmail.com>
2026-09-14 14:20:29 +02:00
Julien MaupetitandGitHub 31cff890b8 🚚(global) move favorite documents API endpoint to /documents/favorites/
To respect the globally used pattern, we can safely switch to a simpler
path
2026-09-14 10:01:36 +00:00
Nicolas ClercandGitHub 0c45a2824b 🐛(docker) pull minio images from quay.io
MinIO stopped publishing images on Docker Hub in October 2025 and
archived its GitHub repository in February 2026. `minio/mc` and
`minio/minio` can no longer be pulled, so the `createbuckets` service
fails with `pull access denied for minio/mc`. The same images are still
served from quay.io.

Signed-off-by: Nicolas Clerc <kernicpanel@nclerc.fr>
2026-09-14 08:18:32 +00:00
Stephan MeijerandAnthony LC 2986cc6158 🚚(project) switch docspec image to ghcr.io/docspec/api
Signed-off-by: Stephan Meijer <me@stephanmeijer.com>
2026-09-11 15:52:39 +02:00
fch-aaandAnthony LC e13e26e07a (frontend) expose the full last-update date
Keep the relative timestamp in the document header while exposing the
localized full date through the existing tooltip on hover and keyboard focus.

Signed-off-by: fch-aa <21101725+fch-aa@users.noreply.github.com>
2026-09-11 15:17:27 +02:00
Manuel Raynaud fbc3ef83ba ️(backend) stop using LEFT(value, LENGTH(path)) in sql queries
Comparing path with LEFT(value, LENGTH(path)) makes a sequential scan on
all the Document table, the more this table grow, the more the query
using it will be slow. We dediced instead to lookup on the path
extracting all ancestors path for a given document and then make a path
IN statement to use the index existing on the path column.
2026-09-11 12:55:20 +02:00
Anthony LC afc11adc52 🐛(y-provider) prevent process crash on malformed websocket frames
The ws library emits an unhandled 'error' event when a client sends a
frame with unexpected RSV bits (e.g. permessage-deflate mismatch),
which was crashing the whole y-provider process since no listener was
attached to the socket. Add an error listener to log and drop the
offending connection instead.
2026-09-11 10:57:25 +02:00
Cyril 9ebca52361 ️(frontend) restore presenter focus trapping after share links
Restore FocusScope and aria-disabled for access presenter nav after share links
2026-09-11 08:59:18 +02:00
Ovgodd bcc1eb9faf 🐛(frontend) hide the selection highlight on presenter images
Presenter reset no longer hid selection; image slides appeared focused on open.
2026-09-09 15:10:06 +02:00
Manuel Raynaud 137cecc0e1 🔧(backend) fine tune redis cache options
We want to configure other options on the redis cache. By default there
is no timeout on the connection to socket and no timeout for read/write
operations. We set default values in all caches used in production. The
settings IGNORE_EXCEPTIONS differ between the default and the session
cache. Activating it behaves like a missed cache. Enabling it for the
session should lead to unwanted side effects, by returning falsy on the
session creation, a retry mechanism of 10000 attempts is made in the
SessionStore.create method, the request can stay in this loop for a long
time.
2026-09-08 16:26:15 +02:00
Manuel Raynaud 36a890a119 ⬆️(backend) upgrade celery to version 5.6.3
Celery version 5.6 has several fixes we want : two significant memory
leaks have been resolved and also a fix allowing a better use of psycopg
pool.
2026-09-08 14:44:56 +02:00
Mathieu AgopianandAnthony LC a5f26434ba 🐛(frontend) export any raster image supported by the browser to a PDF
WebP format isn't supported by react-pdf/renderer and so wasn't exported
properly, and some PNG images were also not exporting.
First drawing those raster images to a canvas and providing a dataURL to
react-pdf/renderer fixes those two bugs at once.

Signed-off-by: Mathieu Agopian <mathieu@agopian.info>
2026-09-08 12:10:07 +02:00
Manuel Raynaud 1e61b4a789 🐛(backend) skip session creation for the liveness probe
The ForceSessionMiddleware force the session creation, we want to
ignore it when the request is the liveness probe. The liveness probe
must not check if redis is available, this is the readiness probe job
2026-09-08 08:56:42 +02:00
Ovgodd 050a584e7b 💄(frontend) redesign email confirmation standalone page
Email confirmation is a business page and now uses the shared chrome.
2026-09-07 10:24:57 +02:00
fch-aaandAnthony LC 1f126cf629 🐛(frontend) preserve title when adding an emoji
The emoji action could reuse a stale document title while a rename was being
submitted, replacing the new title with the emoji alone.

Keep the latest submitted title in the header and cover the interaction
with a regression test.

Signed-off-by: fch-aa <21101725+fch-aa@users.noreply.github.com>
2026-09-07 09:27:57 +02:00
Manuel Raynaud 3c1275c88d 🔖(release) patch 5.6.1
Added

- (frontend) export presenter slides as PDF #2487

Fixed

- 🐛(frontend) hide Leave in the doc menu when not logged in #2626
- 🐛(backend) allow to configure settings DATA_UPLOAD_MAX_MEMORY_SIZE
2026-09-04 18:19:06 +02:00