642 Commits
Author SHA1 Message Date
Sylvain Zimmer 25ed4f98eb fix required uv versions 2026-02-23 10:38:52 +01:00
Sylvain ZimmerGitHubcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
fb5a8a338f Apply suggestion from @coderabbitai[bot]
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-02-23 10:27:29 +01:00
Sylvain ZimmerGitHubcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
9e9d3cda40 Apply suggestion from @coderabbitai[bot]
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-02-23 10:23:30 +01:00
Sylvain Zimmer 8b893da43f add to changelog 2026-02-21 19:55:41 +01:00
Sylvain Zimmer cf037cc451 add defaults for caddy vars 2026-02-21 16:41:15 +01:00
Sylvain Zimmer d1ca9cda84 scalingo fix 2026-02-21 14:08:52 +01:00
Sylvain Zimmer 8abcbcc8e3 Switch from nginx to Caddy 2026-02-21 13:59:27 +01:00
Sylvain Zimmer 2e74db3d8d use mgmt command 2026-02-21 00:44:53 +01:00
Sylvain Zimmer 367f5cf996 fix gh action objectstorage 2026-02-21 00:39:44 +01:00
Sylvain Zimmer c0b8713951 fix create bucket command 2026-02-20 23:31:54 +01:00
Sylvain Zimmer bd39585c83 review fixes 2026-02-20 19:41:01 +01:00
Sylvain Zimmer de27586d1a fixes 2026-02-20 16:33:05 +01:00
Sylvain Zimmer 1e8c2129e1 add distroless runtime option 2026-02-20 15:58:54 +01:00
Sylvain Zimmer dee043939d continue devx upgrade. remove backend translations, upgrade all deps 2026-02-20 13:39:39 +01:00
Sylvain Zimmer 46c2da9876 upgrade base images 2026-02-20 02:29:04 +01:00
Sylvain Zimmer 916b88cb43 fix UV_PYTHON_DOWNLOADS value 2026-02-20 02:13:49 +01:00
Sylvain Zimmer 5062e5d36a 🔨(devx) update developer experience: uv, makefile & more 2026-02-20 02:02:31 +01:00
Sylvain ZimmerandGitHub ab24b60160 ✨(throttle) add outbound message recipients throttling (#506)
This is inspired by #466 but focuses on outbound backend-only changes.
2026-02-20 00:41:58 +01:00
Stanislas BruhièreandGitHub 850929ca48 ✨(mda) use a webhook+logging instead of a pushgateway for selfchecks (#550) 2026-02-19 20:40:14 +01:00
Stephan MeijerandGitHub 31361094e9 ⬆️(ci) upgrade GitHub Actions workflow steps to latest versions (#555)
Update all GitHub Actions to their latest major versions for improved
performance, security patches, and Node.js runtime compatibility.

Signed-off-by: Stephan Meijer <me@stephanmeijer.com>
2026-02-19 20:38:17 +01:00
Stephan MeijerandGitHub 9fd5eb6c43 👷(docker) add arm64 platform support for image builds (#554)
Signed-off-by: Stephan Meijer <me@stephanmeijer.com>
2026-02-19 18:11:58 +01:00
Sylvain ZimmerandGitHub e5ce447905 ✨(exports) add task to export a mailbox in mbox, with labels (#553)
This also makes sure we can reimport X-Keywords later.

For now it's admin-side only, we'll add a user-facing UI. First part of #211.
2026-02-19 18:10:19 +01:00
Sylvain ZimmerandGitHub 9b5375cba3 ✨(import) add support for PST imports & stream data for mbox (#544)
Fixes #183. Replaces #517.
2026-02-19 14:03:43 +01:00
Sylvain ZimmerandGitHub d8afd35847 ✨(mailboxes) add a denylist for personal mailbox prefixes (#540)
Personal mailboxes now enforce configurable prefix restrictions; blocked prefixes return a clear error. Domains can indicate identity synchronization status; when disabled, creating personal mailboxes is prevented and returns a specific error.
2026-02-19 12:52:44 +01:00
Jean-Baptiste PENRATHandGitHub 6a97f56cc3 ✨(frontend) add multi-column layout block for signature editor (#551)
Allow signatures to use a 2-column layout (image + text) via a custom
BlockNote block. The column list node must keep the name `columnList`
internally to stay compatible with BlockNote's built-in block
manipulation logic (fixColumnList, replaceBlocks, etc.).

A typo in uikit prevent us to use turbopack to build frontend. Now it's fixed
let's use some rusty stuff. For now we are using it only for dev.
For now it generates broken production build.

https://github.com/suitenumerique/ui-kit/pull/144
https://github.com/vercel/next.js/discussions/77721
2026-02-19 12:01:45 +01:00
Stanislas BruhièreandGitHub 9afd35dac6 ✨(backend) enable celery task events for worker monitoring (#549) 2026-02-19 09:33:49 +01:00
Jean-Baptiste PENRATHandGitHub a4d1d39d9c 🐛(frontend) hide delivery statuses for drafts and trashed messages (#552)
Drafts and trashed messages should not display delivery status
indicators or retry options since they were never actually sent
or are no longer relevant to the user.
2026-02-18 20:33:02 +01:00
Jean-Baptiste PENRATHandGitHub 712f39c13f ✨(frontend) customize editor menus and side panel (#548)
Hide block types that are not relevant for the email composer
(toggle lists, code blocks, file/video/audio, tables) from both
the slash menu and the block type selector. Add a custom side menu
with drag handle that is hidden on read-only blocks (signature,
quoted-message). Fix toolbar dropdown being clipped by the Floating
UI size middleware when the toolbar wraps.
2026-02-18 16:09:49 +01:00
Jean-Baptiste PENRATHandGitHub a91c85c25e 🚸(frontend) use display_name for labels and auto-unfold active parents (#547)
Labels now show their display_name instead of name in badges,
ensuring users just see the label name instead of the full
path name that could be long so hard to read.
Parent labels automatically unfold when a child label is active,
improving navigation discoverability.
2026-02-18 13:49:40 +01:00
Jean-Baptiste PENRATHandGitHub 522e6fb81c ⬆️(backend) upgrade django-lasuite from 0.0.19 to 0.0.24 (#546)
The previous version had a bug in the OIDC token refresh middleware
that used the wrong session key (`oidc_token_expiration` instead of
`oidc_id_token_expiration`), causing it to consider the token as
always expired and attempt a refresh on every request. Combined with
the expiration not being updated after a successful refresh, this led
to race conditions on concurrent requests and "authentication session
has expired" errors on the Drive endpoint.
2026-02-18 13:00:42 +01:00
Jean-Baptiste PENRATHandGitHub 82bb4e1204 ⚡️(global) optimize MessageTemplate serialization and body handling (#545)
Avoid transferring heavy body content (especially base64 images) when
only metadata is needed. The frontend now explicitly requests the body
fields it needs via ?bodies=raw,html,text, and modals lazily fetch
body content only when editing a template.

Key changes:
- Replace 3 read serializers with a single ReadMessageTemplateSerializer
  that dynamically includes body fields based on ?bodies= query param
- Cache parsed blob content on the model to avoid redundant JSON parsing
- Skip expensive base64 image validation on update when body is unchanged
- Refactor frontend modals to lazy-load body via retrieve on edit
2026-02-18 12:02:21 +01:00
jbpenrath 67e214e10c ⚡️(frontend) defer HTML/text body export to send/save time
Generating HTML and text body on every keystroke via blocksToMarkdownLossy
caused ProseMirror's DOMSerializer to create real <img> elements, triggering
unwanted blob download requests for inline images.

The export is now deferred to send time using useImperativeHandle/forwardRef,
and the Object URL cache in useHtmlWithObjectUrls uses a lightweight
fingerprint to avoid recreating URLs for unchanged images.
2026-02-17 19:02:29 +01:00
jbpenrath 6468ab4e7a ✨(frontend) enrich editor toolbar
Through the new email exporter, we are able to add more blocknote tools
to customize text layout. So we revamp a little bit the toolbar and add
color style button.
2026-02-17 19:02:29 +01:00
jbpenrath c53e8bfcd4 ✨(global) allow to add image block into template and signature composers
Images are embedded as base64 data URLs directly in the BlockNote content,
unlike the message composer which uses blob uploads + CID references.
This approach keeps templates and signatures self-contained without
requiring an attachment system.

Furthermore, a email-safe safe html exporter has been created to
serialize blocknote content into html.

A new backend setting MAX_TEMPLATE_IMAGE_SIZE (default 2 MiB) controls
the maximum allowed image size for these composers.
2026-02-17 19:02:28 +01:00
BastienandGitHub 100f671e1e (chore) bump keycloak to 26.5.3 (#543) 2026-02-16 22:36:12 +01:00
jbpenrath 81db18107c ✨(frontend) allow to add image block into message body
Allow users to insert images directly in the message body via the
BlockNote editor. Non-image files are intercepted and redirected as
regular attachments.
2026-02-11 11:57:48 +01:00
jbpenrath 03387b667a 🌐(frontend) translate _many french variants
Since i18next 21, plural suffixes have been aligned with
the JS API Intl.PluralRules. This API is itself based on CLDR.
Then this repository defines for french language 3 plural
variants : one, other and many. So since i18next 21, when we
generate french translation key we get _many variants.

https://github.com/i18next/i18next/blob/master/CHANGELOG.md#2100
https://www.unicode.org/cldr/charts/48/supplemental/language_plural_rules.html
2026-02-11 10:21:01 +01:00
Jean-Baptiste PENRATHandGitHub ae3522a95e 💬(frontend) improve outbox wording (#539)
Improve CTA labels when failure deliveries.
2026-02-10 10:38:27 +01:00
Sylvain ZimmerandGitHub 6bd7292460 ✨(metrics) new API route for storage usage metrics (#538)
Will be queried by deploy center
2026-02-08 17:41:04 +01:00
jbpenrath 8a6200e3d5 ♻️(e2e) move specific e2e management commands into a dedicated app
Move e2e management command into a dedicated app only installed in e2e
environment to not expose those commands in other environment.
2026-02-05 19:10:12 +01:00
jbpenrath ffca2231e6 ✨(global) add outbox conditional folder
Add outbox conditional folder to display messages having message recipients with None, retry or failed state.
Inform visually the user is something is wrong with a message.
Allow user to update MessageRecipient from failed to cancelled to hide ui warning.
2026-02-05 19:04:02 +01:00
Sylvain ZimmerandGitHub 8f36b1685d 🔒️(frontend) add defense in-depth for XSS vulnerabilities (#520)
Avoid using HTML strings whenever possible, always try to use the react render to string functions with JSX.
2026-02-05 11:22:39 +01:00
Sylvain ZimmerandGitHub 55993a9780 ✨(dns) stronger DNS checks + configurable records (#522)
adds "Insecure" and "Conflicting" DNS status badges and messages with new checks, and introduces a new MESSAGES_DNS_RECORDS setting.  Fixes #482.
2026-02-05 11:15:42 +01:00
Jean-Baptiste PENRATHandGitHub 021ee22e75 🐛(backend) delete orphan attachments when removed from draft (#532)
When users remove attachments from drafts, only the M2M relationship
was being severed, leaving Attachment and Blob records orphaned in the
database. Over time, this leads to unnecessary storage consumption and
data accumulation.

A management command is also provided to clean up existing orphans.
2026-02-05 10:56:03 +01:00
Jean-Baptiste PENRATHandGitHub dded0ebd12 🐛(frontend) fix cursor position when clicking in combobox input (#534)
The combobox input uses a CSS technique with a ::after pseudo-element
(containing the input value via `content: attr(data-value)`) overlaid on
the actual input to enable auto-sizing. However, this ::after element
was intercepting mouse clicks instead of letting them pass through to
the underlying input.

When a user clicked to reposition the cursor within the text:
1. The click landed on ::after (not the input directly)
2. This caused the input to lose focus (blur)
3. The wrapper's onClick handler then called focus() on the input
4. focus() placed the cursor at the end of the text by default

Adding `pointer-events: none` to the ::after pseudo-element allows
clicks to pass through to the input, preserving the expected cursor
positioning behavior.

Resolve #533
2026-02-04 18:48:34 +01:00
mv2kprf1andGitHub eda1f735f1 🔧(frontend) configure Orval headers to suppress version info (#530)
Orval’s default headers function formats the Orval version
into a string, in the format: ${pkg.name} v${pkg.version}

Each time the Orval version is upgraded, this change
propagates across each header, creating massive diff
noise.

Configured Orval to suppress version info in output headers
while preserving the existing output structure.

This keeps each file exactly the same as they
are today, except without the version string.

Signed-off-by: mv2kprf1 <mv2kprf1@users.noreply.github.com>
2026-02-04 16:55:42 +01:00
Sylvain ZimmerandGitHub 6fe2db7be2 ✨(print) add Print button in messages context menu (#518) 2026-02-04 00:38:50 +01:00
jbpenrathandClaude Opus 4.5 796a4b7a35 🐛(frontend) close left panel when clicking active folder on mobile
On mobile, users expect the left panel to close when they tap any folder,
including the currently active one. This allows them to return to the
main content area without having to use the close button.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-03 19:00:21 +01:00
jbpenrath eef8793fee ⬆️(frontend) upgrade frontend deps
Upgrade frontend deps
Especially blocknote to version 0.46.2 which fix an issue that
prevented link popover to be closed with static toolbar.
2026-02-03 19:00:21 +01:00
jbpenrath ce2c1b3ed0 ✨(composer) add autofocus option to message, template, and signature composers
Enhanced user experience by adding an autofocus feature to the
message composer, template composer, and signature composer
components, ensuring the cursor is positioned at the end of the input
field upon loading.
2026-02-03 19:00:21 +01:00