Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
318 commits
Select commit Hold shift + click to select a range
e7d8654
refactor: Explicit component props (1/23) (#41175)
tassoevan Jul 7, 2026
a7551fa
refactor: Explicit component props (2/23) (#41176)
tassoevan Jul 7, 2026
0523a4a
fix(ux): Missing a visible quote message link (#41091)
dougfabris Jul 7, 2026
b6cac3b
refactor: Explicit component props (3/23) (#41177)
tassoevan Jul 7, 2026
37cc624
refactor: Explicit component props (5/23) (#41179)
tassoevan Jul 7, 2026
5740ec5
refactor: Explicit component props (6/23) (#41180)
tassoevan Jul 7, 2026
9ffcbd2
refactor: Explicit component props (7/23) (#41181)
tassoevan Jul 7, 2026
8ed8599
refactor: Explicit component props (8/23) (#41182)
tassoevan Jul 7, 2026
160e7f1
refactor: Explicit component props (9/23) (#41183)
tassoevan Jul 7, 2026
4fa7ab6
refactor: Explicit component props (10/23) (#41184)
tassoevan Jul 7, 2026
31249c3
refactor: Explicit component props (4/23) (#41178)
tassoevan Jul 7, 2026
38e80cb
ci: fix Docker image size report showing zero for current (#41226)
ggazzo Jul 7, 2026
39bfdf4
refactor: Explicit component props (15/23) (#41214)
tassoevan Jul 7, 2026
355c8c0
fix: LDAP channel sync finishing early when one of the channels on ma…
KevLehman Jul 8, 2026
d4e7012
refactor: Explicit component props (20/23) (#41219)
tassoevan Jul 8, 2026
e8f64e8
refactor: Explicit component props (21/23) (#41220)
tassoevan Jul 8, 2026
aadd798
refactor: Explicit component props (23/23) (#41222)
tassoevan Jul 8, 2026
175a19c
fix: team conversion permissions checked incorrectly (#41206)
julio-rocketchat Jul 8, 2026
e75965c
refactor: Explicit component props (18/23) (#41217)
tassoevan Jul 8, 2026
6405491
fix: users.CreateToken endpoint lacks user-generate-access-token perm…
jonasflorencio Jul 8, 2026
0709149
fix: imported fixes 07-08-2026 (#41233)
julio-rocketchat Jul 8, 2026
4551b27
refactor: Explicit component props (11/23) (#41210)
tassoevan Jul 8, 2026
c3a3741
refactor: Explicit component props (12/23) (#41211)
tassoevan Jul 8, 2026
c7b78c2
refactor: Explicit component props (13/23) (#41212)
tassoevan Jul 8, 2026
9219709
refactor: Explicit component props (14/23) (#41213)
tassoevan Jul 8, 2026
d480490
refactor: Explicit component props (16/23) (#41215)
tassoevan Jul 8, 2026
d91ce3a
refactor: Explicit component props (19/23) (#41218)
tassoevan Jul 8, 2026
ed63cfc
refactor: Explicit component props (22/23) (#41221)
tassoevan Jul 8, 2026
5894a29
chore: message parser limit on the client (#40600)
gabriellsh Jul 8, 2026
70c4d9e
chore: reject non-renderable image formats for avatars (#41223)
abhinavkrin Jul 8, 2026
eddd589
chore: remove emojione in favor of native emojis (#39411)
sampaiodiego Jul 8, 2026
3d8723b
test: fix omnichannel-takeChat flake by waiting for agent availabilit…
KevLehman Jul 8, 2026
668d529
test: registration invalid URL test running before page is ready (#40…
jessicaschelly Jul 9, 2026
8e9047c
chore: remove media call channels model (#41194)
pierre-lehnen-rc Jul 9, 2026
bfc2abe
fix: Video attachment controls not clickable on Chromium 150 (#41230)
ricardogarim Jul 9, 2026
01dfb44
chore: correct log error details on videoconf service (#41256)
pierre-lehnen-rc Jul 9, 2026
8e33c5a
fix(ui): Misaligned username in Read Receipts list (#41199)
abhinavkrin Jul 9, 2026
f633d7e
refactor: Explicit component props (17/23) (#41216)
tassoevan Jul 9, 2026
d0f8943
chore: explicit meteor package imports (#41259)
KevLehman Jul 9, 2026
13b4a7b
feat: Phishing resistant MFA (#40721)
yash-rajpal Jul 9, 2026
3b27160
chore: reorganize backend folder structure — Phase 5 (meteor methods)…
sampaiodiego Jul 10, 2026
87663fa
chore(ui): Change quote attachment link icon (#41228)
dougfabris Jul 10, 2026
398525a
refactor(ui-client): Non-standard `useThemeMode` (#41284)
tassoevan Jul 10, 2026
6f85f55
regression: URL preview embeds flicker on new messages/reactions (Rea…
ggazzo Jul 10, 2026
0b70a73
fix: incorrect cursor position after inserting mention (#41074)
abhinavkrin Jul 10, 2026
5f21093
chore: use public preact JSX import in livechat (TS7 compat) (#41263)
ggazzo Jul 10, 2026
8dacf28
chore(streamer): defensively guard against a null session socket (#41…
ggazzo Jul 10, 2026
4186deb
fix(apps-engine): IUser used wrong federation type definition (#41304)
d-gubert Jul 10, 2026
ee8e048
fix(apps-engine): tighten types for TS7 (exception, uikit responder) …
ggazzo Jul 10, 2026
8cf05af
chore(ui-voip): Widget stories broken due to initial body height of `…
gabriellsh Jul 10, 2026
eec6083
fix(message-parser): trailing backtick before line end breaks code bl…
ggazzo Jul 10, 2026
1637a8b
fix: Prevent app remount when VoIP license/permission changes (#41200)
dougfabris Jul 10, 2026
582d25d
chore: remove unused model query methods (#41227)
KevLehman Jul 10, 2026
23bdbad
fix: DST verifier unlinking all departments from custom business hour…
KevLehman Jul 11, 2026
719e3db
fix: LDAP users not merging by email during sync (#41279)
abhinavkrin Jul 11, 2026
edbaeef
fix: Setup wizard forced back into registration on upgrade when Show_…
KevLehman Jul 11, 2026
ed594fd
fix(a11y): add keyboard support in room members list (#41122)
juliajforesti Jul 13, 2026
d9fca72
test: fix flaky timeout in preview-public-channel spec (#41319)
KevLehman Jul 13, 2026
dd4023e
regression: fix issues rendering some existing emojis (#41305)
MartinSchoeler Jul 13, 2026
b9b2228
refactor(authorization): accept IUser in hasPermissionAsync wrappers …
ggazzo Jul 13, 2026
8ed0fa0
fix: server crash when re-enabling push notifications (#41341)
KevLehman Jul 13, 2026
73c3aec
chore: migrate batch4 client DDP callers + add 6 REST endpoints (#40728)
ggazzo Jul 13, 2026
01202cc
test: fix race in uikit-interactions e2e by awaiting interaction resp…
KevLehman Jul 13, 2026
460858e
fix: engagement dashboard fill (#41207)
sampaiodiego Jul 13, 2026
9690412
chore: reorganize backend folder structure — Phase 6 (lib, hooks, fea…
sampaiodiego Jul 14, 2026
c4bede4
refactor(authorization): accept a minimal user shape (UserWithRoles) …
ggazzo Jul 14, 2026
b634242
test: fix flaky omnichannel status toggle assertion in navbar page ob…
KevLehman Jul 14, 2026
a60e261
chore(authorization): bound roles-cache key to user id, skip cache wh…
ggazzo Jul 14, 2026
0faaaeb
test: fix strict mode violation flake in OC manual selection queue te…
KevLehman Jul 14, 2026
001902a
chore(api): migrate audit/chat/ldap/engagement single-route endpoints…
devin-ai-integration[bot] Jul 14, 2026
9860e02
chore(api): migrate engagement dashboard messages/users endpoints to …
devin-ai-integration[bot] Jul 14, 2026
d371c06
chore: bump fuselage packages (#41354)
ricardogarim Jul 14, 2026
4b34bd6
fix: import Slack files as attachments instead of raw URLs (#41285)
ricardogarim Jul 15, 2026
3598e2d
chore: upgrade xml-crypto to v6 (#41379)
abhinavkrin Jul 15, 2026
71d4d82
fix: server crash when LDAP search filter is invalid (#41373)
KevLehman Jul 15, 2026
1b7f9f2
test: stabilize flaky E2E message and navigation flows (#41114)
jessicaschelly Jul 15, 2026
012dd32
regression: Prevent saving license with non-plausible value (#41306)
dougfabris Jul 15, 2026
0e7b205
chore: reorganize backend folder structure — Phase 7 (omnichannel and…
sampaiodiego Jul 15, 2026
9db6a29
test: update stale proxyquire mock paths breaking unit test CI (#41403)
KevLehman Jul 15, 2026
bfacbd3
chore: Permissions translations in title case (#41380)
yash-rajpal Jul 15, 2026
7720156
chore(eslint): Replace eslint-plugin-import with eslint-plugin-import…
tassoevan Jul 16, 2026
cc63c0f
test: Remove virtual flag from CodeMirror spec mocks to fix flaky sui…
tassoevan Jul 16, 2026
8bbd1c6
refactor(api): pass this.user to permission checks in REST endpoints …
ggazzo Jul 16, 2026
cff23f9
fix: Disable composer actions without subscription to channel (#41202)
yash-rajpal Jul 16, 2026
ae72939
refactor(authorization): forward only { _id, roles } from hasPermissi…
ggazzo Jul 16, 2026
abab8a0
refactor: replace Fuselage styling prop shorthands with full prop nam…
tassoevan Jul 16, 2026
2ec4d29
fix(apps): write Deno runtime config to temp directory (#41338)
AlgoArtist06 Jul 16, 2026
f96b66d
docs: Add frontend guidelines (#41423)
tassoevan Jul 16, 2026
4b57346
feat: (poc) Unified AI Search (#40890)
Dnouv Jul 16, 2026
0e20907
chore: auto detect screen share based on video direction (#41366)
pierre-lehnen-rc Jul 16, 2026
ec7b1be
fix: dates showing one day earlier for users in negative UTC-offset (…
nazabucciarelli Jul 16, 2026
ffe1b64
fix: race condition in E2EE rooms creation causing 'incorrect encrypt…
nazabucciarelli Jul 16, 2026
81458c0
refactor: replace Fuselage styling prop shorthands with full prop nam…
ricardogarim Jul 17, 2026
14d0718
chore: refactor apps converters to TypeScript with Zod codecs (1/2) (…
d-gubert Jul 17, 2026
65a366e
feat: show relative time in Omnichannel Contact Center date columns (…
abhinavkrin Jul 17, 2026
74f50d1
feat(federation): Add XMPP bridge support (#40758)
sampaiodiego Jul 17, 2026
6d2c9f1
chore: remove unused @rocket.chat/log-format package (#41426)
tassoevan Jul 17, 2026
fce0bc7
chore: avoid fetching data just for counting (#41313)
sampaiodiego Jul 17, 2026
e8697f3
chore(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#41011)
dependabot[bot] Jul 17, 2026
d75d98b
chore(deps): bump docker/login-action from 4.1.0 to 4.2.0 (#40670)
dependabot[bot] Jul 17, 2026
c582421
chore(deps): bump github/codeql-action from 4.35.5 to 4.36.2 (#40831)
dependabot[bot] Jul 17, 2026
8975214
chore(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 (#40841)
dependabot[bot] Jul 17, 2026
f8d6b46
chore(deps): bump github/codeql-action/autobuild from 4.36.2 to 4.37.…
dependabot[bot] Jul 17, 2026
1bf84cb
feat: validate password policy length on settings save (#41173)
ricardogarim Jul 17, 2026
74d6cac
feat: no egress for offline licenses (#41148)
cardoso Jul 17, 2026
a3afae7
ci(codeql): align codeql-action steps to v4.37.1 (#41456)
ggazzo Jul 17, 2026
1629d33
chore: Align `react-stately` slim barrel patches for submenu support …
dougfabris Jul 17, 2026
aeb7467
chore(deps): bump websocket-driver (#41427)
yasnagat Jul 17, 2026
adc1570
regression: combined emojis displayed as separate emojis and some fla…
abhinavkrin Jul 17, 2026
13ea804
chore: bump fuselage packages (#41430)
ricardogarim Jul 17, 2026
f6c5579
fix: Restore Away to quick status menu (#41414)
ricardogarim Jul 17, 2026
c103cf5
chore: make screen share not rely on bundles from previous negotiatio…
pierre-lehnen-rc Jul 17, 2026
6a94ee4
ci: speed up merge queue runs (#41368)
KevLehman Jul 18, 2026
302f0c4
chore: add dom lib for WebRTC/DOM globals (TS7 compat) (#41262)
ggazzo Jul 18, 2026
7619669
ci: fix dynamic-import response truncation flake (proxy transport rac…
KevLehman Jul 18, 2026
6041285
fix: pagination and projection options silently ignored by model quer…
KevLehman Jul 17, 2026
b7bf284
chore: TS7 low-risk type fixes (assertions, casts) (#41264)
ggazzo Jul 18, 2026
34aa635
chore: Ensure page always reloads when app is crashes (#41453)
yash-rajpal Jul 17, 2026
7a360be
fix: prevent AI navbar search crashes and restore clear action (#41434)
Dnouv Jul 18, 2026
297df1a
fix(apps): resolve deno-runtime module not found after upgrade (#40947)
dsaicharan072-cmyk Jul 19, 2026
6ebabce
fix: newer license in env not applied (#41472)
cardoso Jul 20, 2026
82ae946
chore: use @rocket.chat/cron for presence status expiration in micros…
ricardogarim Jul 20, 2026
3240cdb
refactor(authorization): pass IUser to permission checks where alread…
ggazzo Jul 20, 2026
f2fc52d
chore: Switch AI Search feature as opt-in (#41464)
tassoevan Jul 20, 2026
0b5e592
refactor(gazzodown,livechat): Problematic import (#41463)
tassoevan Jul 20, 2026
0a1baf2
chore: remove duplicated emoji css (#41425)
ricardogarim Jul 20, 2026
b0ecca0
ci: skip redundant test re-run on develop push after merge queue (#41…
ggazzo Jul 20, 2026
8d8cd01
feat: FIPS 140-3 Compliant Docker Images (#39324)
cardoso Jul 20, 2026
a93d6da
ci: Update DockerHub login condition for queue type
ggazzo Jul 20, 2026
dddc5bd
chore(deps): bump adm-zip (#41476)
julio-rocketchat Jul 20, 2026
1d60700
chore(deps): bump dependencies with medium and low-severity CVEs (#41…
julio-rocketchat Jul 20, 2026
8d4507d
fix: missing "user left" system message after omnichannel room forwar…
KevLehman Jul 20, 2026
ea70952
ci: publish fips images as tags to dockerhub (#41486)
sampaiodiego Jul 20, 2026
4a4c297
chore(deps): bump GitHub Actions dependencies (#41485)
ggazzo Jul 20, 2026
6a8b36b
chore: correct Phishing-Resistant MFA changeset to minor bump (#41492)
ricardogarim Jul 21, 2026
ea64e17
Release 8.7.0-rc.0
rocketchat-github-ci Jul 21, 2026
cfe1da9
chore: update package versions to 8.8.0-develop and 1.65.0-develop
ggazzo Jul 21, 2026
0986cc2
chore: update version to 8.8.0-develop in rocketchat.info
ggazzo Jul 21, 2026
eb8c624
ci: enable e2e retries on merge queue runs (#41496)
ggazzo Jul 21, 2026
2077b7e
fix(meteor): meteor/* type resolution under TS7 (drop packages.d.ts f…
ggazzo Jul 21, 2026
7b7f88f
feat(voice): Remove input requirement for stablishing internal calls …
gabriellsh Jul 21, 2026
c162052
chore: type shim for csv-parse/lib/sync (TS7 compat) (#41314)
ggazzo Jul 21, 2026
3c7866d
chore(deps): Patch dependencies (#41487)
tassoevan Jul 21, 2026
04d4322
chore: declare '*.css' side-effect imports (TS7 compat) (#41261)
ggazzo Jul 21, 2026
ac4a0d9
chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#41494)
dependabot[bot] Jul 21, 2026
caed5c4
test: point oembed API tests at the CI mock-server instead of real pr…
KevLehman Jul 21, 2026
30623d9
chore: Replace some `SidebarV1` components in favor of `SidebarV2` (#…
yash-rajpal Jul 21, 2026
a7ef3b2
chore: Upgrade Yarn from 4.12.0 to 4.17.1 (#41510)
tassoevan Jul 22, 2026
5a11882
regression: fix verify email endpoint (#41491)
sampaiodiego Jul 22, 2026
83edf2f
refactor(ui-contexts,fuselage-ui-kit,ui-client): Decouple room naviga…
tassoevan Jul 22, 2026
79a6d1c
chore(eslint): Upgrade ESLint to v10 and bump plugins (#41509)
tassoevan Jul 22, 2026
eb99fc4
fix: livechat tags.save rejected by response validation on edit (+ e2…
ggazzo Jul 22, 2026
4c6cdfe
chore(deps): bump axios, brace-expansion, shell-quote, and tar deps (…
yasnagat Jul 22, 2026
2a16c57
regression: ASCII emoticons not converted to emojis by the native emo…
KevLehman Jul 22, 2026
c774ae1
regression: skin-toned emoji not enlarged when sent alone (#41515)
ricardogarim Jul 22, 2026
68758b1
regression: tooltips not reappearing on subsequent hovers (#41428)
abhinavkrin Jul 22, 2026
0c15350
test(unit): fix flaky mongo connection test (#41526)
sampaiodiego Jul 22, 2026
915ca08
regression: native emojis bottom-aligned in messages (#41527)
ricardogarim Jul 23, 2026
1e2f96a
regression(api): implement missing im.leave, dm.leave and dm.blockUse…
ggazzo Jul 23, 2026
126f056
Merge remote-tracking branch 'origin/master' into release-8.7.0
ggazzo Jul 23, 2026
4d59332
Release 8.7.0-rc.1
rocketchat-github-ci Jul 23, 2026
8116c62
Release 8.7.0-rc.2
rocketchat-github-ci Jul 23, 2026
e46a00f
Merge remote-tracking branch 'origin/release-8.7.0' into develop
ggazzo Jul 23, 2026
3c0f20c
regression: markdown links break when their URL contains an emoji sho…
cardoso Jul 23, 2026
150916a
regression: emoji avatars overlap message content and render undersiz…
abhinavkrin Jul 23, 2026
6edcdd7
fix: Deleted thread not being displayed correctly in thread context (…
dougfabris Jul 23, 2026
d81ca08
regression: Prevent inherited properties from being treated as emoji …
yash-rajpal Jul 23, 2026
76d8910
regression: device logout showing success feedback when request fails…
KevLehman Jul 23, 2026
abd22bd
refactor: Use WHATWG URL instead of node url/querystring (#41529)
tassoevan Jul 23, 2026
a27dd2f
chore(passport-x): declare passport-oauth1 exports for TS7 (#41311)
ggazzo Jul 23, 2026
a0134b9
regression: quick-reaction emojis rendered larger on message toolbar …
KevLehman Jul 23, 2026
ae0b8fb
regression: missing emojis in picker search (#41342)
MartinSchoeler Jul 24, 2026
c8b080b
regression: custom OAuth client secret logged in plaintext at debug l…
KevLehman Jul 24, 2026
640bc06
test: deflake read-receipts-thread viewed-in-thread test (#41547)
ggazzo Jul 24, 2026
2a8ace0
regression: auto away not triggering in the web client (#41549)
ricardogarim Jul 24, 2026
fb3314b
test: deflake omnichannel monitors sidebar navigation (#41540)
ggazzo Jul 24, 2026
2052886
chore: migrate 2FA TOTP DDP methods to /v1/users.totp.* REST endpoint…
ggazzo Jul 24, 2026
6dc66fb
chore: migrate OAuth services admin DDP methods to REST (#40737)
ggazzo Jul 24, 2026
fcf244e
regression: native emoji rendered as corrupted characters in omnichan…
KevLehman Jul 24, 2026
1393186
chore: migrate audit DDP methods to /v1/audit.* REST endpoints (EE) (…
ggazzo Jul 27, 2026
d281351
chore: paginated thread message list (#40998)
MartinSchoeler Jul 27, 2026
5ba7bd5
test: deflake livechat business-hours and room.forward queue tests (#…
ggazzo Jul 27, 2026
e8db099
regression: video embedded in custom homepage content repeatedly relo…
ricardogarim Jul 27, 2026
4947601
feat: Introduce draft message indicator (#41355)
dougfabris Jul 27, 2026
d59ea47
regression: canned response emojis appear as shortcodes to livechat v…
nazabucciarelli Jul 27, 2026
5641644
test: navigate Omnichannel admin pages by URL (#41554)
dougfabris Jul 27, 2026
1d2bfd7
chore: refactor apps converters to TypeScript with Zod codecs (2/2) (…
d-gubert Jul 27, 2026
b27e38c
chore(apps): swap default runtime backend from deno to node (#41474)
d-gubert Jul 27, 2026
987f8d6
regression: combined picker emojis split into separate symbols (#41534)
ricardogarim Jul 28, 2026
1ddb72e
chore: migrate sendMessage + getReadReceipts callers to REST (#40675)
ggazzo Jul 28, 2026
5a92469
chore(apps): consolidate accessor implementation to runtime (1/4) (#4…
d-gubert Jul 28, 2026
9ac66cc
regression: custom emojis with mixed skin-tone names missing from sea…
ricardogarim Jul 28, 2026
008fee8
regression: shortcodes changed meaning (#41587)
cardoso Jul 28, 2026
c47bb4e
regression: emoji picker hover preview is no longer enlarged (#41541)
ricardogarim Jul 28, 2026
621768d
chore: migrate readThreads and push_test DDP callers to REST (#41593)
ggazzo Jul 28, 2026
9bd5a7d
regression: Jump to message not working for audio played from quoted …
KevLehman Jul 28, 2026
c108c39
regression: custom HTML in sidebar footer and login pages repeatedly …
ricardogarim Jul 28, 2026
a4f5098
chore(deps): bump `js-yaml`, `linkify-it`, `@opentelemetry/sdk-node`,…
yasnagat Jul 29, 2026
b96e046
chore: export ConnectionStatus type from @rocket.chat/ddp-client (#41…
Rohit3523 Jul 29, 2026
5fe3b80
regression: blank thread preview on horizontal rule (#41626)
ricardogarim Jul 29, 2026
b3eee9b
chore(api): migrate channels.ts to typed HTTP methods (#41415)
ggazzo Jul 29, 2026
9399296
regression: Update express OAuth route handlers on re-register (#41624)
yash-rajpal Jul 29, 2026
81ff841
regression: Unicode emojis on use emoji preference (#41627)
yash-rajpal Jul 29, 2026
cff1ac2
chore(api): migrate groups.ts to typed HTTP methods (#41422)
ggazzo Jul 29, 2026
a18df96
chore(apps): consolidate accessor implementation to runtime (2/4) (#4…
d-gubert Jul 29, 2026
3c136e0
chore: Upgrade fuselage packages (#41629)
dougfabris Jul 29, 2026
772d8ca
chore(apps): consolidate accessor implementation to runtime (3/4) (#4…
d-gubert Jul 30, 2026
cb7c5c2
test: deflake livechat BH on-agent-created assertions (#41633)
ggazzo Jul 30, 2026
34bb68e
regression: Stop audio player on user logout (#41603)
yash-rajpal Jul 30, 2026
4409899
feat: classification banners for ABAC rooms (#41307)
KevLehman Jul 30, 2026
4c475e5
refactor: use ContextualbarV2 components everywhere (#41637)
tassoevan Jul 30, 2026
21edebe
regression: emoji bottom clipped in messages and announcement banner …
KevLehman Jul 30, 2026
c7970e7
refactor(api): migrate remaining groups endpoints to typed router (#4…
ggazzo Jul 30, 2026
0a5c2f3
Release 8.7.0-rc.3
rocketchat-github-ci Jul 31, 2026
17a0576
chore(apps): consolidate accessor implementation to runtime (4/4) (#4…
d-gubert Jul 31, 2026
29ce956
regression: audio attachment duration is not shown until playback (#4…
abhinavkrin Jul 31, 2026
3ee9475
refactor(livechat): finish TypeScript migration and convert component…
tassoevan Jul 31, 2026
3ee1d44
refactor(api): migrate EE sessions/licenses/roles to typed HTTP metho…
ggazzo Jul 31, 2026
c6ae3d0
chore: fix missing peer dependency warnings (YN0002) (#41503)
KevLehman Jul 31, 2026
bd1a5dc
regression: preserve gif animation and correct thumbnail after `sharp…
yasnagat Jul 31, 2026
d823c0f
fix: audio attachments cannot be seeked using the progress slider (#4…
abhinavkrin Jul 31, 2026
94478c6
chore: improve handling of errors on screen share negotiation (#41372)
pierre-lehnen-rc Jul 31, 2026
0df7297
chore(audio): read attachment duration via native <audio preload=meta…
ggazzo Aug 3, 2026
56fb288
Release 8.7.0-rc.4
rocketchat-github-ci Aug 3, 2026
0c5bcc9
chore: update drachtio-srf patch with missing callingName attribute (…
pierre-lehnen-rc Aug 3, 2026
6ce2488
test: migrate API tests from callback style to async/await (#41636)
ricardogarim Aug 3, 2026
441d252
chore(deps): bump rharkor/caching-for-turbo from 2.5.0 to 2.5.1 (#41579)
dependabot[bot] Aug 3, 2026
543c772
refactor(ui-voip): Make draggable optional and extract `MediaCallWidg…
gabriellsh Aug 3, 2026
dd60cf8
Merge remote-tracking branch 'origin/release-8.7.0' into develop
ggazzo Aug 3, 2026
e64e2bb
chore: fix formatting lint error in `SidebarFooterDefault` (#41674)
tassoevan Aug 4, 2026
e0d2aab
chore(deps): bump github/codeql-action/analyze from 4.37.1 to 4.37.4 …
dependabot[bot] Aug 4, 2026
5a7414b
chore(deps): bump github/codeql-action/autobuild from 4.37.1 to 4.37.…
dependabot[bot] Aug 4, 2026
17c6075
chore(deps): bump actions/stale from 10.4.0 to 11.0.0 (#41676)
dependabot[bot] Aug 4, 2026
c8bb0d7
chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.4 (#4…
dependabot[bot] Aug 4, 2026
c0e3a7b
chore: group codeql-action dependabot updates
ggazzo Aug 4, 2026
d18228d
chore(deps): bump docker/login-action from 4.4.0 to 4.6.0 (#41678)
dependabot[bot] Aug 4, 2026
2d8a6f7
fix: reaction list shows blank entries when UI_Use_Real_Name is enabl…
Rohit3523 Aug 4, 2026
9bf5285
fix: session not being marked as logged out when logging out via REST…
Rohit3523 Aug 4, 2026
4c37fbf
ci: pin synapse docker version (#41692)
sampaiodiego Aug 4, 2026
a9296f1
chore(deps): bump `brace-expansion`, `ip-address`, `fast-uri` (#41685)
yasnagat Aug 5, 2026
5f49831
docs: split frontend guidelines by topic and document i18n convention…
tassoevan Aug 5, 2026
692be5e
refactor(ui-voip): Separate widget visibility from call state and sim…
gabriellsh Aug 5, 2026
e10346e
chore: update package versions to 9.0.0-develop across all relevant f…
ggazzo Feb 25, 2026
5cc65bd
chore!: stop transpiling webhook integration scripts with Babel (#40142)
ggazzo Apr 14, 2026
23d3192
chore: remove sendFileMessage meteor method (#40288)
nazabucciarelli Apr 24, 2026
05174f6
Reapply "chore!: remove insertOrUpdateSound and uploadCustomSound Met…
ggazzo May 13, 2026
8953357
chore!: remove deleteCustomSound Meteor method (#40883)
nazabucciarelli Jun 23, 2026
7a535ae
chore!: Remove `/ufs` endpoint (#41054)
KevLehman Jun 30, 2026
416bb8a
chore!: remove WebDav integration (#40856)
yasnagat Jul 20, 2026
e7cd9a3
chore: apps converters golden spec breaking unit tests (#41756)
ricardogarim Aug 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
5 changes: 5 additions & 0 deletions .changeset/abac-classification-banners.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': minor
---

Adds classification banners to ABAC-managed rooms: admins can describe US-Government-style classification markings (levels, special access programs, releasability, colors) in a new JSON setting, and matching rooms display a colored classification banner above the room header for all members.
8 changes: 8 additions & 0 deletions .changeset/all-baths-cry.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/model-typings': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/models': minor
'@rocket.chat/meteor': minor
---

Adds `current` field to `DeviceManagementSession` type and `currentLoginToken` parameter to `aggregateSessionsByUserId`, allowing the sessions endpoint to identify and flag the caller's active session.
6 changes: 6 additions & 0 deletions .changeset/apps-engine-runtime-default-node.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/apps': minor
'@rocket.chat/meteor': minor
---

Changes the default apps-engine runtime backend from `deno` to `node`. The previous behavior can be restored by setting the environment variable `APPS_ENGINE_RUNTIME_BACKEND='deno'`
8 changes: 8 additions & 0 deletions .changeset/atomic-model-operations.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/core-typings': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/models': patch
---

Fixes race conditions in several check-then-write database flows by collapsing them into single atomic operations: CAS login tokens can no longer be consumed by two concurrent logins, revoking a room invite no longer emits duplicate removal notifications, and deleting an integration now enforces the creator-only permission scope in the delete itself
5 changes: 5 additions & 0 deletions .changeset/better-results-press.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": major
---

Removes `/ufs` legacy endpoint for downloading files
5 changes: 5 additions & 0 deletions .changeset/block-fallback-rendering.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/gazzodown": patch
---

Degrades blocks without a dedicated renderer to their raw markup instead of dropping them. When a block carries a `fallback` `[start, end]` offset span, `Markup`/`PreviewMarkup` slice the original message source (passed via the new optional `source` prop) and render that text. This avoids duplicating the markup into the AST while keeping unsupported blocks visible.
5 changes: 5 additions & 0 deletions .changeset/breezy-moons-search.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes own account showing twice in navbar room search when searching by username
32 changes: 32 additions & 0 deletions .changeset/breezy-parts-kiss.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
'@rocket.chat/web-ui-registration': minor
'@rocket.chat/model-typings': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/passport-x': minor
'@rocket.chat/desktop-api': minor
'@rocket.chat/models': minor
'@rocket.chat/i18n': minor
'@rocket.chat/meteor': minor
---

## Phishing-Resistant Multi-Factor Authentication

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release changelog will contain this OAuth feature twice because .changeset/flat-poets-cheat.md already documents the same change. Consolidating the notes and package bump into one changeset would avoid duplicate release documentation.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/breezy-parts-kiss.md, line 12:

<comment>The release changelog will contain this OAuth feature twice because `.changeset/flat-poets-cheat.md` already documents the same change. Consolidating the notes and package bump into one changeset would avoid duplicate release documentation.</comment>

<file context>
@@ -0,0 +1,31 @@
+'@rocket.chat/meteor': major
+---
+
+## Phishing-Resistant Multi-Factor Authentication
+
+Introduces a more secure and reliable server-side OAuth authentication flow.
</file context>


Introduces a more secure and reliable server-side OAuth authentication flow.

### What’s New

- **Improved OAuth login security**
OAuth authentication now happens fully on the server, reducing the risk of token theft, phishing attacks, and client-side credential interception.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: This security claim is unconditional even though Accounts_OAuth_Use_Modern_Flow defaults to false; existing and new installations continue using the legacy flow until an administrator enables it. Qualifying this and the following security bullets with “when enabled” would keep the release notes from overstating the default behavior.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/breezy-parts-kiss.md, line 19:

<comment>This security claim is unconditional even though `Accounts_OAuth_Use_Modern_Flow` defaults to `false`; existing and new installations continue using the legacy flow until an administrator enables it. Qualifying this and the following security bullets with “when enabled” would keep the release notes from overstating the default behavior.</comment>

<file context>
@@ -0,0 +1,31 @@
+### What’s New
+
+- **Improved OAuth login security**  
+  OAuth authentication now happens fully on the server, reducing the risk of token theft, phishing attacks, and client-side credential interception.
+
+- **Built-in CSRF, state validation, and PKCE protection**  
</file context>


- **Built-in CSRF, state validation, and PKCE protection**
OAuth logins now include stronger protection against CSRF attacks, request tampering, and authorization code interception through secure state validation and PKCE support.

- **Improved two-step verification with OAuth logins**
Users with email or TOTP two-factor authentication enabled will now be asked to complete 2FA even when signing in with providers like Google, GitHub, GitLab, and others.

- **Improved mobile & desktop app login**
Mobile and desktop apps now support a smoother and more secure deep-link OAuth login flow.

- **A new setting to enable/disable new OAuth Flow**
Enable this new setting `Accounts_OAuth_Use_Modern_Flow` to use all of the above mentioned features.
5 changes: 5 additions & 0 deletions .changeset/bump-patch-1784768845125.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Bump @rocket.chat/meteor version.
5 changes: 5 additions & 0 deletions .changeset/bump-patch-1784771780188.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Bump @rocket.chat/meteor version.
5 changes: 5 additions & 0 deletions .changeset/bump-patch-1785461760418.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Bump @rocket.chat/meteor version.
5 changes: 5 additions & 0 deletions .changeset/bump-patch-1785760239936.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Bump @rocket.chat/meteor version.
5 changes: 5 additions & 0 deletions .changeset/code-fence-trailing-backtick.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/message-parser": patch
---

Fixes code fences failing to render when a line inside them ends with an inline-code backtick (e.g. `` - **Node**: `22.22.3` ``). A trailing backtick immediately before a line break could not be consumed as content, causing the whole ```` ``` ```` block to fall back to markdown parsing and split apart. Trailing 1-2 backticks before a line end (or EOF) are now treated as code content.
5 changes: 5 additions & 0 deletions .changeset/ddp-migrate-batch5-totp-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Migrates the `TwoFactorTOTP` account settings page from the five `2fa:*` DDP methods to the new TOTP REST endpoints. DDP methods stay registered for external SDK/mobile clients with deprecation logs pointing at the new routes until 9.0.0.
5 changes: 5 additions & 0 deletions .changeset/ddp-migrate-batch6-audit-callers.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Migrated the audit panel (`AuditLogTable`, `useAuditMutation`) from the three `auditGet*` DDP methods to the new `/v1/audit.*` REST endpoints. DDP methods stay registered with deprecation logs pointing at the new routes until 9.0.0.
11 changes: 11 additions & 0 deletions .changeset/ddp-migrate-batch7-oauth-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
'@rocket.chat/meteor': patch
---

Migrates the Admin → OAuth services group page from `useMethod` (DDP) to `useEndpoint` (REST):

- `addOAuthService` → existing `POST /v1/settings.addCustomOAuth`
- `removeOAuthService` → new `POST /v1/settings.removeCustomOAuth`
- `refreshOAuthService` → new `POST /v1/settings.refreshOAuthServices`

DDP methods stay registered with deprecation logs pointing at the new routes until 9.0.0.
7 changes: 7 additions & 0 deletions .changeset/ddp-migrate-readthreads-pushtest.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/meteor': patch
---

Migrated the last two thread-read call sites (`ThreadChat`, `useThreadMessagesQuery`) from the `readThreads` DDP method to `POST /v1/chat.readThread`, and pointed the admin "send a test push to my user" setting at `POST /v1/push.test` instead of the `push_test` DDP method. Both DDP methods stay registered with deprecation logs pointing at the new routes until 9.0.0.

`POST /v1/push.test` now also returns the `message` translation key and its `params`, matching what the DDP method returned, so the admin setting still reports how many devices the test reached.
7 changes: 7 additions & 0 deletions .changeset/deep-ways-poke.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/core-typings': patch
'@rocket.chat/models': patch
'@rocket.chat/meteor': patch
---

Fixes the Slack importer storing shared files as raw URLs in the message body. Imported file messages now stay hidden until "Download Pending Files" button fetches them, then display as native attachments with image previews. Failed downloads (e.g. invalidated export links) are no longer silently saved as the file's content — they are counted as errors and can be retried.
6 changes: 6 additions & 0 deletions .changeset/desktop-set-user-roles.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/desktop-api': minor
'@rocket.chat/meteor': patch
---

Added a `setUserRoles` bridge method to the desktop API and pushed the logged-in user's roles to the desktop app. This lets the desktop client restrict supportedVersions messages (such as version-expiration warnings) to specific roles like admins, instead of showing them to every user. The push is reactive to role changes; desktop builds without the bridge method fall back to their own role lookup.
5 changes: 5 additions & 0 deletions .changeset/emoji-zwj-tag-sequences.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/message-parser': patch
---

Fixes an issue in which some combined emojis like 😶‍🌫️, 😮‍💨 and 😵‍💫 were being displayed as two separate emojis, and the flags of some countries like England 🏴󠁧󠁢󠁥󠁮󠁧󠁿, Scotland 🏴󠁧󠁢󠁳󠁣󠁴󠁿 and Wales 🏴󠁧󠁢󠁷󠁬󠁳󠁿 were being displayed as a plain black flag
5 changes: 5 additions & 0 deletions .changeset/empty-boxes-cross.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes engagement dashboard loading unnecessary data into memory on startup
6 changes: 6 additions & 0 deletions .changeset/empty-garlics-reply.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/core-typings': patch
'@rocket.chat/meteor': patch
---

Fixes the password policy allowing a maximum length lower than the minimum length to be saved — a combination that made it impossible to set any valid password. The server now rejects such configurations when password policy settings are saved and shows an error explaining the constraint.
5 changes: 5 additions & 0 deletions .changeset/fancy-days-knock.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
10 changes: 10 additions & 0 deletions .changeset/fancy-deserts-mate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
'@rocket.chat/core-services': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/ai-search': minor
'@rocket.chat/ui-client': minor
'@rocket.chat/i18n': minor
'@rocket.chat/meteor': minor
---

Adds AI Search with semantic message results, optional OpenAI-compatible answers, and AI Center configuration.
7 changes: 7 additions & 0 deletions .changeset/fifty-candies-heal.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/meteor': patch
---

fix: Buttons from emoji picker misbehaving on clicks

An infinite render loop was preventing proper behavior when clicking on the emoji picker buttons. It was fixed by removing the unnecessary state update that was causing the loop and replacing multiple fires of the same mouseover event (when a mouseenter event was the right one to use). There is a chance this pre-existing bug was hidden by React 18's event delegation.
5 changes: 5 additions & 0 deletions .changeset/fifty-turkeys-judge.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/eslint-config': minor
---

Upgrades ESLint to v10 and bumps plugins
13 changes: 13 additions & 0 deletions .changeset/fips-mode-support.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/federation-matrix': minor

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release metadata gives @rocket.chat/federation-matrix a minor FIPS feature release even though it has no FIPS implementation or dedicated FIPS image and is not one of the services named in the feature description. Removing this package from the changeset would avoid an unrelated version bump and misleading package changelog entry.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/fips-mode-support.md, line 4:

<comment>The release metadata gives `@rocket.chat/federation-matrix` a minor FIPS feature release even though it has no FIPS implementation or dedicated FIPS image and is not one of the services named in the feature description. Removing this package from the changeset would avoid an unrelated version bump and misleading package changelog entry.</comment>

<file context>
@@ -0,0 +1,13 @@
+---
+'@rocket.chat/meteor': minor
+'@rocket.chat/core-typings': minor
+'@rocket.chat/federation-matrix': minor
+'@rocket.chat/account-service': minor
+'@rocket.chat/authorization-service': minor
</file context>

'@rocket.chat/account-service': minor
'@rocket.chat/authorization-service': minor
'@rocket.chat/ddp-streamer': minor
'@rocket.chat/omnichannel-transcript': minor
'@rocket.chat/presence-service': minor
'@rocket.chat/queue-worker': minor
---

Adds support for running Rocket.Chat in FIPS mode. The monolith and all microservices (ddp-streamer, account-service, authorization-service, presence-service, queue-worker, omnichannel-transcript) can now enforce FIPS-compliant cryptography via Node.js/OpenSSL FIPS, with dedicated FIPS Docker images. Running in FIPS mode requires a license including the new `fips` module, and FIPS status is now reported in server logs and statistics.
5 changes: 5 additions & 0 deletions .changeset/fix-business-hour-agents-availability.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes agents' business-hour availability not being updated when they are removed from a department linked to a business hour while multiple business hours are enabled. The recomputation step always failed, leaving removed agents available (or unavailable) according to a business hour that no longer applied to them — and, on deployments running with `EXIT_UNHANDLEDPROMISEREJECTION` (or in development/test mode), the unhandled rejection crashed the server process.
7 changes: 7 additions & 0 deletions .changeset/fix-business-hour-dst-department-unlink.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/meteor': patch
---

Fixes multiple business hours losing their linked departments after a daylight saving time change or a server restart. The automatic timezone adjustment re-saved business hours without their department associations, causing business hours configured with timezones to silently stop applying to agents.

Also fixes agents keeping a business hour's availability after their department was removed from it: saving a business hour with a smaller department list unlinked the departments but never cleared the business hour from the removed departments' agents.
5 changes: 5 additions & 0 deletions .changeset/fix-deno-runtime-symlink.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/apps': patch
---

Fixes an issue that would cause apps to fail with 'Module not found' errors in some cases
6 changes: 6 additions & 0 deletions .changeset/fix-license-env-precedence.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/license': patch
---

Fixes the license provided via the `ROCKETCHAT_LICENSE` environment variable not being applied when it is newer than the one persisted in the workspace.
5 changes: 5 additions & 0 deletions .changeset/forty-stars-bathe.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes error message being shown when logging out current device via Device Management despite successful logout.
7 changes: 7 additions & 0 deletions .changeset/four-tigers-clap.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/models': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/meteor': patch
---

Fixes a race condition that left messages permanently undecryptable ("incorrect encryption key") in rooms created with encryption enabled. When several members opened such a room at the same time, each client could independently generate and distribute a different group key. Establishing the room key is now atomic (first-write-wins) on the server, and a client that loses the race discards its locally generated key and adopts the established one instead of encrypting with a divergent key.
6 changes: 6 additions & 0 deletions .changeset/fruity-items-fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/apps': minor
'@rocket.chat/meteor': minor
---

Adds an alternative runtime runner for apps. It can be enabled via environment variable `APPS_ENGINE_RUNTIME_BACKEND='node'`
10 changes: 10 additions & 0 deletions .changeset/funny-wings-sell.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
'@rocket.chat/model-typings': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/ui-client': minor
'@rocket.chat/models': minor
'@rocket.chat/i18n': minor
'@rocket.chat/meteor': minor
---

Replaces the "Drafts in sidebar" feature preview with an always-on draft indicator. Thread-composer drafts are also persisted per thread and indicated in the thread list
8 changes: 8 additions & 0 deletions .changeset/gentle-cats-change.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/core-typings': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/models': patch
---

Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
7 changes: 7 additions & 0 deletions .changeset/hungry-snakes-help.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
"@rocket.chat/i18n": minor
"@rocket.chat/media-signaling": minor
"@rocket.chat/ui-voip": minor
---

Removes voice calling microphone requirement for starting a successful call, allowing users to join as "listen-only".
13 changes: 13 additions & 0 deletions .changeset/integration-scripts-no-babel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
'@rocket.chat/meteor': major
---

**Breaking:** Stopped transpiling webhook integration scripts with Babel. Scripts now run as-is inside `isolated-vm` (modern V8).

Class method bodies are now in strict mode per the ES2015 spec. Scripts that relied on sloppy-mode behaviors provided by the previous Babel transpilation must be updated:

- **Implicit globals** — `msg = buildMessage(...)` inside a class method now throws `ReferenceError`. Add `let`, `const`, or `var`.
- **`this` in nested regular functions** — `function helper() { this.JSON.stringify(...) }` now has `this === undefined` instead of `globalThis`. Use arrow functions or pass the dependency explicitly.
- **`arguments.callee`** — Throws `TypeError`. Use a named function expression instead.
- **Octal literals** — `0777` is now a `SyntaxError`. Use `0o777`.
- **Duplicate parameter names** — `function(a, a) {}` is now a `SyntaxError`.
6 changes: 6 additions & 0 deletions .changeset/json-setting-validation-feedback.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@rocket.chat/meteor": minor
"@rocket.chat/i18n": minor
---

Adds inline JSON validation feedback to admin settings that hold JSON (`code: application/json`), showing an error in the editor and blocking save while the value is malformed
5 changes: 5 additions & 0 deletions .changeset/ldap-channel-sync-removal-abort.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes LDAP channel sync aborting the entire add/removal pass when a mapped channel could not be resolved, which prevented users from being removed from channels when "Auto Remove Users from Channels" was enabled.
6 changes: 6 additions & 0 deletions .changeset/ldap-merge-email-lookup.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/models': patch
'@rocket.chat/meteor': patch
---

Fixes LDAP sync failing to merge an existing user matched by email, which caused a `Username already exists` error when the user's username differed from the directory.
5 changes: 5 additions & 0 deletions .changeset/ldap-sync-crash-invalid-filter.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes the server crashing during LDAP login or sync when the configured search settings produce an invalid LDAP filter (for example, an empty User Search Field). The operation now fails gracefully with a logged error instead of terminating the process.
7 changes: 7 additions & 0 deletions .changeset/license-validate-preview.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/license': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/meteor': minor
---

Adds a new `licenses.validate` REST endpoint that validates a Rocket.Chat license (V2 or V3 JWT) against the current workspace without applying it, so a license can be previewed before it is applied from the UI. A valid license responds with success; an invalid one responds with the validation behaviors that rejected it.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release note incorrectly labels V2 licenses as JWTs, which can mislead clients about the token format accepted by licenses.validate. Describing the formats as “V2 licenses or V3 JWTs” keeps the migration/API documentation precise.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/license-validate-preview.md, line 7:

<comment>The release note incorrectly labels V2 licenses as JWTs, which can mislead clients about the token format accepted by `licenses.validate`. Describing the formats as “V2 licenses or V3 JWTs” keeps the migration/API documentation precise.</comment>

<file context>
@@ -0,0 +1,7 @@
+'@rocket.chat/meteor': minor
+---
+
+Adds a new `licenses.validate` REST endpoint that validates a Rocket.Chat license (V2 or V3 JWT) against the current workspace without applying it, so a license can be previewed before it is applied from the UI. A valid license responds with success; an invalid one responds with the validation behaviors that rejected it.
</file context>

5 changes: 5 additions & 0 deletions .changeset/light-geckos-start.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Disables more actions on message composer during public channel preview.
5 changes: 5 additions & 0 deletions .changeset/livechat-forward-ul-message.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes an issue where the "user left" system message could be added to an Omnichannel conversation only after the forwarding process had already finished, causing it to appear out of order in the conversation history
5 changes: 5 additions & 0 deletions .changeset/lucky-donkeys-listen.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes audio attachments not being seekable using the progress slider
5 changes: 5 additions & 0 deletions .changeset/message-content-body-source.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": patch
---

Passes the original message text to the message renderer so blocks without a dedicated renderer (e.g. tables on clients that don't render them yet) can degrade to their raw markup via the parser's `fallback` source offsets, instead of disappearing.
5 changes: 5 additions & 0 deletions .changeset/moody-eggs-juggle.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes an issue where the cursor jumped to the wrong position after inserting a mention at the start or middle of a message.
5 changes: 5 additions & 0 deletions .changeset/nice-fans-cover.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": minor
---

Replaces proprietary emojis with native (unicode) emojis and increases available emoji set
6 changes: 6 additions & 0 deletions .changeset/offline-license-no-egress.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/license': minor
---

Adds support for the `offline` license flag, suppressing every outbound connection to Rocket.Chat Cloud services and the Push Gateway at its source, so air-gapped workspaces never initiate calls that would violate their security compliance.
6 changes: 6 additions & 0 deletions .changeset/old-bats-sniff.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/apps-engine': patch
'@rocket.chat/meteor': patch
---

Fixes wrong FederationLookup type assigned to IUser in apps. The correct data is there, but the type does not represent it.
Loading
Loading