Commit Graph
235 Commits
Author SHA1 Message Date
Anthony LCandManuel Raynaud d3e9bf73ee ✈️(frontend) add offline support with yhub
The offline support couldn't work with the existing
implementation anymore, because there is no request
to get or save data anymore, everything is handled
with web sockets.
In order to support offline functionality, we
leveraged y-indexeddb to store and synchronize
local changes, ensuring that the application remains
functional even when offline.
2026-09-22 16:03:33 +02:00
Kevin JahnsandManuel Raynaud 0d6a283408 (collaboration) fall back to http polling when the websocket is blocked
Some networks refuse a websocket upgrade - corporate proxies, captive
portals - and a browser is told nothing more than "the connection
closed", so those users could not edit at all. The editor now runs a
second transport next to the socket, polling the collaboration server's
REST api on the same room, with the same session cookie and the same
authorization, and only while the socket is down. Local changes go out
about a second after the last keystroke and remote ones arrive within
ten seconds, so editing works with visibly more latency rather than not
at all. The socket keeps being retried underneath, so a client that fell
back during an outage returns to it on its own, and nothing is lost in
either direction - both transports publish from the same document.

This makes /collaboration/ydoc/ a route browsers call, so
COLLABORATION_SERVER_ORIGIN is now handed to yhub as its cors
configuration and gates the http routes as well as the websocket.

Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:01:20 +02:00
Anthony LCandManuel Raynaud f27109fe25 🛂(y-provider) verify jwt token instead of the shared api key
The /api/convert route no longer accepts the Y_PROVIDER_API_KEY shared
secret. It now verifies the admin JWT signed by Django against the
JWKS published on its /api/v1.0/jwks endpoint.
2026-09-22 16:00:43 +02:00
Kevin JahnsandManuel Raynaud eb94d726b0 ♻️(collaboration) switch collaboration server from hocuspocus to yhub
Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-22 16:00:22 +02:00
renovate[bot]andGitHub 51164f2ef7 ⬆️(dependencies) update @ai-sdk/openai to v3.0.112 2026-09-18 10:16:31 +00:00
renovate[bot]andGitHub 17c03b5da0 ⬆️(dependencies) update @ai-sdk/openai to v3.0.106 2026-09-10 08:17:10 +00:00
renovate[bot]andGitHub d8e5d5e796 ⬆️(dependencies) update sharp to v0.35.4 [SECURITY] 2026-09-09 09:54:31 +00:00
renovate[bot]andGitHub 64b23e864b ⬆️(dependencies) update next to v16.3.3 [SECURITY] 2026-09-09 01:43:59 +00:00
Anthony LC 7c106e33a8 🔒️(js) fix security warning
- browserslist
- nanoid
2026-09-03 13:30:48 +02:00
Anthony LC ee624e875e (frontend) add math and diagram blocks to the editor
Last version of Blocknote added support for math
and diagram blocks. This commit updates the
dependencies to include the necessary toolbar
items to create math and diagram blocks in
the editor.
2026-09-03 13:30:47 +02:00
Anthony LC ac580bc81b 🚨(frontend) adapt codebase to Blocknote 0.54.0
We bumped Blocknote to 0.54.0, which introduced
some breaking changes. This commit adapts our
codebase to the new API and ensures compatibility
with the latest version of Blocknote.
2026-09-03 11:07:27 +02:00
renovate[bot]andAnthony LC 0e8bc3a518 ⬆️(dependencies) update js dependencies 2026-09-03 09:15:26 +02:00
Anthony LC 85177dc3ca (frontend) add find and replace feature to the editor
We have added a new feature to the editor that allows
users to find and replace text within their documents.
This feature enhances the editing experience by
providing a convenient way to search for specific
words or phrases and replace them with new content.
2026-08-28 12:20:06 +02:00
Anthony LC e0fcd2a01e ⬆️(frontend) replace ui-kit by ui-components
A major release was made on the ui-kit side,
ui-kit is replaced by ui-components, which is a new
package that contains the same components as ui-kit
but with some improvements.
To build the tokens, a new dev dependency is necessary,
which is @gouvfr-lasuite/ui-tokens.
These replacements bring better separation of concerns
and a better architecture for the future.
We need to adapt our codebase to use the new package
and the new dev dependency.
2026-08-28 11:09:11 +02:00
Anthony LC bfada16063 🐛(i18n) fix export translations
Last upgrade of js-yaml has a compatibility issue
with i18next-parser library, which causes the
export / import translations to fail.
2026-08-24 14:05:51 +02:00
renovate[bot]andGitHub c9e32e34e8 ⬆️(dependencies) update dompurify to v3.4.13 [SECURITY] 2026-08-09 13:56:58 +00:00
Anthony LC 58f70e0d2c 🔒️(js) fix security warning
- brace-expansion
- svgo
- postcss
- undici
- sharp
2026-08-07 09:16:33 +02:00
Anthony LC c37e9b162f ⬆️(dependencies) update js dependencies 2026-08-06 17:44:21 +02:00
renovate[bot]andGitHub d2dc74c0f9 ⬆️(dependencies) update postcss to v8.5.23 [SECURITY]
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) 
leads to Arbitrary .map File Disclosure
GHSA-r28c-9q8g-f849

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled 
sourceMappingURL reads arbitrary .map files when from is unset
CVE-2026-69153 / GHSA-fxqj-rqcc-2cmp
2026-08-04 15:03:17 +02:00
renovate[bot]andGitHub eed828d8c7 ⬆️(dependencies) update js-yaml to v5.2.2 [SECURITY] 2026-07-28 19:42:08 +00:00
renovate[bot]andGitHub 845f134a51 ⬆️(dependencies) update next to v16.2.11 [SECURITY] 2026-07-23 02:11:03 +00:00
Anthony LC ba0a80cdef ⬆️(dependency) upgrade fetch-mock to 12.6.0
Previous version had security vulnerabilities,
better to upgrade to the latest version.
We had to adapt tests to the new version of fetch-mock.
2026-07-21 14:57:28 +02:00
Anthony LC b550a4543b 🔒️(js) fix security warning
- brace-expansion
- body-parser
2026-07-21 14:57:28 +02:00
Anthony LC b17df9971c 📌(dependencies) add @gouvfr-lasuite/cunningham-react resolution
@gouvfr-lasuite/ui-kit pin @gouvfr-lasuite/cunningham-react,
so multiple versions of
@gouvfr-lasuite/cunningham-react were being installed,
which was causing issues.
We pin the version to 4.3.1, forcing all packages to
use the same version.
2026-07-21 14:57:28 +02:00
Anthony LC 11efa78088 ⬇️(dependency) downgrade ai packages to previous version
Blocknote is not compatible with the latest version
of the ai packages:
- @ai-sdk/openai
- ai
Better to downgrade to the previous version until the
compatibility issue is resolved.
2026-07-21 14:25:32 +02:00
Anthony LC aff6f2b4cc ⬇️(dependency) downgrade typescript to v6.0.3
We are downgrading TypeScript from version 7.0.2
to 6.0.3.
To bump the version of TypeScript, we will need
to update the codebase to be compatible with the
new version.
2026-07-21 14:25:32 +02:00
renovate[bot]andAnthony LC be5071682b ⬆️(dependencies) update js dependencies 2026-07-21 14:25:32 +02:00
Anthony LC 4bd835ac47 (frontend) add Lottie animation to header floating bar
We want to animate the header floating bar with
a Lottie animation. This commit adds the Lottie
dependency and implements the animation in the
HeaderFloatingBar component.
2026-07-03 17:42:20 +02:00
Anthony LC 50b696cba1 (frontend) add a user menu
We are now using the UserMenu component from
the ui-kit. It is a dropdown displaying the user's
name and email, along with a logout button and a
language picker. To fit the design of the user menu,
we adapted the LanguagePicker adn are now using the
ui-kit language picker component.
2026-07-01 17:56:46 +02:00
Anthony LC 3304c12b2c 🔒️(js) fix security warning
Moderate:
- @babel/core
- @opentelemetry/core
- dompurify
- form-data
- js-yaml
- markdown-it
- undici
- ws
2026-06-23 12:17:47 +02:00
Anthony LC b8c2406361 📌(dependencies) pin prosemirror deps
We are pinning the prosemirror dependencies to avoid
conflicts with other versions.
2026-06-23 12:17:47 +02:00
renovate[bot]andAnthony LC e4b6132dfd ⬆️(dependencies) update js dependencies 2026-06-23 12:17:47 +02:00
Nathan Panchout 5f7e59a8dd (frontend) add presenter mode
Add a presenter overlay that turns the current document into a
slide deck. The editor's blocks are snapshot at open time and
split into slides on each divider; navigation is driven by
keyboard shortcuts and a floating bar with browser fullscreen
support. The overlay is wired to the doc header toolbox via a
new "Present" entry, lazy-loaded to keep the editor bundle lean.
2026-06-02 16:25:56 +02:00
Anthony LC 31588ac08d ⬆️(frontend) bump Blocknote to 0.51.4
We bumped the Blocknote editor to version 0.51.4,
which includes several bug fixes and improvements,
particularly 1 bug fix about emoji on the side bar.
2026-06-02 14:31:41 +02:00
Anthony LC 2ad24384bd 🔒️(js) fix security warning
Moderate:
- ajv CVE-2025-69873
- qs CVE-2026-8723
- protobufjs CVE-2026-45740
- fast-uri CVE-2026-6322
2026-06-01 15:18:26 +02:00
renovate[bot]andGitHub ae9a6a14da ⬆️(dependencies) update js dependencies 2026-06-01 10:11:21 +00:00
Anthony LC 41f76ebde8 ⬆️(dependencies) upgrade Blocknote to 0.51.1
Upgrade Blocknote to 0.51.1 to get the latest
features and bug fixes.
2026-05-19 21:36:26 +02:00
Anthony LC 9cde092250 ⬇️(frontend) downgrade major release @hocuspocus
@hocuspocus made a major release, we need to do
a substantial refactor to be compatible with it.
This PR downgrades to the previous major release,
which is still compatible with our codebase,
until we have time to do the necessary refactor.
2026-05-19 17:01:44 +02:00
renovate[bot]andAnthony LC 18e9c3accb ⬆️(dependencies) update js dependencies 2026-05-19 17:01:44 +02:00
renovate[bot]andGitHub 0501551abb ⬆️(dependencies) update next to v16.2.6 [SECURITY] 2026-05-11 21:33:48 +00:00
renovate[bot]andGitHub 85128c7b11 ⬆️(dependencies) update axios to v1.15.2 [SECURITY] 2026-05-05 12:25:22 +00:00
renovate[bot]andAnthony LC 9231730bf0 ⬆️(dependencies) update js dependencies 2026-05-05 10:50:49 +02:00
Anthony LC fa9d56d79b 🔒️(js) fix security warning
Critical:
- protobufjs CVE

High:
- lodash CVE
- picomatch CVE
- Vite CVE

Moderate:
- postcss CVE
- uuid CVE
- dompurify CVE
- follow-redirects CVE
2026-04-29 15:04:58 +02:00
renovate[bot]andGitHub c464715158 ⬆️(dependencies) update uuid to v14 [SECURITY] 2026-04-27 21:21:59 +00:00
renovate[bot]andGitHub 0060c59615 ⬆️(dependencies) update axios to v1.15.0 [SECURITY] 2026-04-13 08:30:36 +00:00
renovate[bot]andGitHub 48fb17bf3e ⬆️(dependencies) update next to v16.2.3 [SECURITY] 2026-04-11 01:12:58 +00:00
renovate[bot]andGitHub be38e68dd5 ⬆️(dependencies) update lodash to v4.18.1 [SECURITY] 2026-04-03 18:39:40 +00:00
Anthony LC 4aa7d52406 ⬆️(frontend) Update blocknote dependencies to 0.47.3
We updated the blocknote dependencies to
version 0.47.3.
This update includes a bug fix when we copy
paste a docx content into a document.
2026-04-03 09:57:23 +02:00
Anthony LC 9c832197ed 🔒️(js) fix security warning
Critical;
- fix handlebars CVE
High:
- fix picomatch CVE
- fix flatted CVE
- fix serialize-javascript CVE
- path-to-regexp CVE
Moderate:
- brace-expansion CVE
- yaml CVE
2026-03-31 17:08:35 +02:00
renovate[bot]andAnthony LC da091a07ea ⬆️(dependencies) update js dependencies 2026-03-31 17:08:35 +02:00