Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
209 commits
Select commit Hold shift + click to select a range
855c5c2
test: flaky `session-expiration-redirect.spec` (#41018)
gabriellsh Jun 22, 2026
ffaa115
refactor(ui-voip): extract PeerCardsView from MediaCallRoomSection (#…
ggazzo Jun 22, 2026
46d7c8e
Merge remote-tracking branch 'origin/release-8.6.0' into develop
ggazzo Jun 23, 2026
c3b4d0e
bump rocket.chat to 8.7.0-develop
ggazzo Jun 23, 2026
4fb271e
test(e2e): work around E2E test instabilities (#41005)
tassoevan Jun 23, 2026
e626fb9
fix: voice call fails if user navigates during initial connection (#4…
pierre-lehnen-rc Jun 23, 2026
5620611
chore: Change navbar's search input icon size (#41042)
dougfabris Jun 23, 2026
7da5ec6
Merge remote-tracking branch 'origin/release-8.6.0' into develop
ggazzo Jun 23, 2026
80cddeb
chore(deps): bump ajv (#41049)
julio-rocketchat Jun 24, 2026
2e8ea32
chore(deps): bump rharkor/caching-for-turbo from 2.4.2 to 2.5.0 (#41064)
dependabot[bot] Jun 24, 2026
0433f00
feat(desktop): push user roles to the desktop app (#41056)
ggazzo Jun 24, 2026
3d0aa38
chore: improve voip enums definitions (#41045)
pierre-lehnen-rc Jun 24, 2026
0241250
test: fix rooms-join flaky test (#41072)
sampaiodiego Jun 25, 2026
aa96fe5
refactor(ui-voip): Extract MediaCallCardList and PopoutDockPrompt fro…
aleksandernsilva Jun 25, 2026
660215a
chore: use @rocket.chat/logger in presence service (#41034)
ricardogarim Jun 25, 2026
41fde25
i18n: Rocket.Chat language update from Lingohub 🤖 on 2026-06-22Z (#41…
lingohub[bot] Jun 25, 2026
64af832
chore(apps): unit test improvements (#40785)
d-gubert Jun 25, 2026
e4dba79
fix(federation): edited and deleted messages corrupting event tree (#…
sampaiodiego Jun 26, 2026
32880c4
Merge remote-tracking branch 'origin/release-8.6.0' into develop
ggazzo Jun 26, 2026
2c4292b
chore(deps): bump actions/cache from 5.0.5 to 6.0.0 (#41073)
dependabot[bot] Jun 26, 2026
e929d2d
chore: improve Docker images for micro services (#41083)
sampaiodiego Jun 26, 2026
294ee5d
test(e2e): close leaked browser contexts in omnichannel livechat spec…
ggazzo Jun 26, 2026
eed19bc
test: use gotoChannel when possible (#41084)
sampaiodiego Jun 29, 2026
275a6ed
chore(deps): bump actions/cache/save from 6.0.0 to 6.1.0 (#41096)
dependabot[bot] Jun 29, 2026
3cd35ab
chore: reorganize backend folder structure — Phase 1 (slash commands)…
sampaiodiego Jun 29, 2026
3cd7db6
fix: Imported fixes 06-24-26 (#41069)
jonasflorencio Jun 30, 2026
9f08d1a
chore(deps): bump mailparser, nodemailer, and undici, markdown-it (#4…
julio-rocketchat Jun 30, 2026
a158ae7
refactor: React 19 (#40796)
tassoevan Jun 30, 2026
3001445
chore: reorganize backend folder structure — Phase 2 (external bridge…
sampaiodiego Jun 30, 2026
6ca1ce7
refactor(uikit-playground,deps): Update `react-split-pane` (#41118)
tassoevan Jun 30, 2026
615ae2b
fix: `customFields` property missing on `admin.getRoom` endpoint (#41…
KevLehman Jun 30, 2026
b6e0d3b
chore: bump license (#41130)
ggazzo Jul 1, 2026
70c0ff0
feat(message-parser): block fallback for unsupported renderers (#41110)
ggazzo Jul 1, 2026
761314d
test: Flaky should navigate on navbar toolbar pressing tab (#41135)
dougfabris Jul 1, 2026
4117a1d
feat(message-parser): horizontal rule (thematic break) (#41113)
ggazzo Jul 1, 2026
890d394
test: Flaky should display rooms in direct message filter (#41137)
dougfabris Jul 1, 2026
cbbcd47
test: add guards to composer focus to prevent flakyness (#41106)
sampaiodiego Jul 2, 2026
5e5990a
chore: apply least privilege permissions to github actions (#40687)
yasnagat Jul 2, 2026
e36211a
refactor: Use flat components (#41139)
tassoevan Jul 2, 2026
5508c6c
chore(apps): refactor deno-runtime imports (#41103)
d-gubert Jul 2, 2026
2f28c1c
fix: grant actions:read at ci.yml top level to fix CI startup_failure…
KevLehman Jul 2, 2026
ef28aee
chore: reorganize backend folder structure — Phase 3 (REST API) (#41126)
sampaiodiego Jul 2, 2026
e5da5d0
feat(message-parser): add GFM table support (#41109)
ggazzo Jul 2, 2026
6da12d7
fix: Keyboard activation doesn't toggle Display menu controls (#41089)
juliajforesti Jul 2, 2026
ae5a95d
chore: Upgrade fuselage packages (#41150)
dougfabris Jul 2, 2026
c7aff48
fix: current device logout showing error (#40351)
juliajforesti Jul 3, 2026
1cc7bbd
chore(spotlight): parallelize searches and slim connected-users pipel…
KevLehman Jul 3, 2026
115dfe8
feat: Validate `code: application/json` settings on UI (#41142)
KevLehman Jul 3, 2026
ebd4a12
test: refactor team management permissions (#41136)
jessicaschelly Jul 3, 2026
eb88328
Merge remote-tracking branch 'origin/master' into develop
ggazzo Jul 3, 2026
9a80dd7
chore(apps): refactor deno-runtime to drop Deno specific APIs (#41125)
d-gubert Jul 3, 2026
376c9d8
feat(audio): persistent audio player across room navigation (#41120)
ggazzo Jul 3, 2026
8dc4964
chore(apps): isolate platform independent logic from deno-runtime (#4…
d-gubert Jul 3, 2026
7f39354
test: add coverage for livechat rooms delete endpoint (#41162)
jessicaschelly Jul 3, 2026
d51868c
test: isolate session expiration e2e users (#41166)
jessicaschelly Jul 4, 2026
cf5dfd2
chore(deps): patch file-type (#41161)
yasnagat Jul 4, 2026
5ed0dac
fix: Use request's `RelayState` for SAML Single Sign Out (#41145)
KevLehman Jul 4, 2026
3296b4d
fix: business-hour availability not recomputed when agents are remove…
KevLehman Jul 4, 2026
0759f83
fix: own account showing twice in navbar room search when searching b…
nazabucciarelli Jul 6, 2026
31df377
test: Flaky `chat-transfer-manager` spec (#41170)
KevLehman Jul 6, 2026
784c287
feat(apps): introduce alternative node-runtime (#41019)
d-gubert Jul 6, 2026
b2b5edf
feat: Improve manual license management (#40916)
dougfabris Jul 6, 2026
78fb2fc
refactor: Replace deprecated `addon` prop (#41151)
tassoevan Jul 6, 2026
a62b126
chore: reorganize backend folder structure — Phase 4 (domain function…
sampaiodiego Jul 6, 2026
44f2b6b
refactor: Remove local definitions of `DeepWritable` (#41185)
tassoevan Jul 6, 2026
e1e426b
fix: Buttons from emoji picker misbehaving on clicks (#41195)
tassoevan Jul 6, 2026
bafa6c1
test: fix race condition in business hours toggle e2e test (#41198)
KevLehman Jul 7, 2026
5f92f9a
chore: atomic updates (#41174)
KevLehman Jul 7, 2026
e7d8654
refactor: Explicit component props (1/23) (#41175)
tassoevan Jul 7, 2026
a7551fa
refactor: Explicit component props (2/23) (#41176)
tassoevan Jul 7, 2026
0523a4a
fix(ux): Missing a visible quote message link (#41091)
dougfabris Jul 7, 2026
b6cac3b
refactor: Explicit component props (3/23) (#41177)
tassoevan Jul 7, 2026
37cc624
refactor: Explicit component props (5/23) (#41179)
tassoevan Jul 7, 2026
5740ec5
refactor: Explicit component props (6/23) (#41180)
tassoevan Jul 7, 2026
9ffcbd2
refactor: Explicit component props (7/23) (#41181)
tassoevan Jul 7, 2026
8ed8599
refactor: Explicit component props (8/23) (#41182)
tassoevan Jul 7, 2026
160e7f1
refactor: Explicit component props (9/23) (#41183)
tassoevan Jul 7, 2026
4fa7ab6
refactor: Explicit component props (10/23) (#41184)
tassoevan Jul 7, 2026
31249c3
refactor: Explicit component props (4/23) (#41178)
tassoevan Jul 7, 2026
38e80cb
ci: fix Docker image size report showing zero for current (#41226)
ggazzo Jul 7, 2026
39bfdf4
refactor: Explicit component props (15/23) (#41214)
tassoevan Jul 7, 2026
355c8c0
fix: LDAP channel sync finishing early when one of the channels on ma…
KevLehman Jul 8, 2026
d4e7012
refactor: Explicit component props (20/23) (#41219)
tassoevan Jul 8, 2026
e8f64e8
refactor: Explicit component props (21/23) (#41220)
tassoevan Jul 8, 2026
aadd798
refactor: Explicit component props (23/23) (#41222)
tassoevan Jul 8, 2026
175a19c
fix: team conversion permissions checked incorrectly (#41206)
julio-rocketchat Jul 8, 2026
e75965c
refactor: Explicit component props (18/23) (#41217)
tassoevan Jul 8, 2026
6405491
fix: users.CreateToken endpoint lacks user-generate-access-token perm…
jonasflorencio Jul 8, 2026
0709149
fix: imported fixes 07-08-2026 (#41233)
julio-rocketchat Jul 8, 2026
4551b27
refactor: Explicit component props (11/23) (#41210)
tassoevan Jul 8, 2026
c3a3741
refactor: Explicit component props (12/23) (#41211)
tassoevan Jul 8, 2026
c7b78c2
refactor: Explicit component props (13/23) (#41212)
tassoevan Jul 8, 2026
9219709
refactor: Explicit component props (14/23) (#41213)
tassoevan Jul 8, 2026
d480490
refactor: Explicit component props (16/23) (#41215)
tassoevan Jul 8, 2026
d91ce3a
refactor: Explicit component props (19/23) (#41218)
tassoevan Jul 8, 2026
ed63cfc
refactor: Explicit component props (22/23) (#41221)
tassoevan Jul 8, 2026
5894a29
chore: message parser limit on the client (#40600)
gabriellsh Jul 8, 2026
70c4d9e
chore: reject non-renderable image formats for avatars (#41223)
abhinavkrin Jul 8, 2026
eddd589
chore: remove emojione in favor of native emojis (#39411)
sampaiodiego Jul 8, 2026
3d8723b
test: fix omnichannel-takeChat flake by waiting for agent availabilit…
KevLehman Jul 8, 2026
668d529
test: registration invalid URL test running before page is ready (#40…
jessicaschelly Jul 9, 2026
8e9047c
chore: remove media call channels model (#41194)
pierre-lehnen-rc Jul 9, 2026
bfc2abe
fix: Video attachment controls not clickable on Chromium 150 (#41230)
ricardogarim Jul 9, 2026
01dfb44
chore: correct log error details on videoconf service (#41256)
pierre-lehnen-rc Jul 9, 2026
8e33c5a
fix(ui): Misaligned username in Read Receipts list (#41199)
abhinavkrin Jul 9, 2026
f633d7e
refactor: Explicit component props (17/23) (#41216)
tassoevan Jul 9, 2026
d0f8943
chore: explicit meteor package imports (#41259)
KevLehman Jul 9, 2026
13b4a7b
feat: Phishing resistant MFA (#40721)
yash-rajpal Jul 9, 2026
3b27160
chore: reorganize backend folder structure — Phase 5 (meteor methods)…
sampaiodiego Jul 10, 2026
87663fa
chore(ui): Change quote attachment link icon (#41228)
dougfabris Jul 10, 2026
398525a
refactor(ui-client): Non-standard `useThemeMode` (#41284)
tassoevan Jul 10, 2026
6f85f55
regression: URL preview embeds flicker on new messages/reactions (Rea…
ggazzo Jul 10, 2026
0b70a73
fix: incorrect cursor position after inserting mention (#41074)
abhinavkrin Jul 10, 2026
5f21093
chore: use public preact JSX import in livechat (TS7 compat) (#41263)
ggazzo Jul 10, 2026
8dacf28
chore(streamer): defensively guard against a null session socket (#41…
ggazzo Jul 10, 2026
4186deb
fix(apps-engine): IUser used wrong federation type definition (#41304)
d-gubert Jul 10, 2026
ee8e048
fix(apps-engine): tighten types for TS7 (exception, uikit responder) …
ggazzo Jul 10, 2026
8cf05af
chore(ui-voip): Widget stories broken due to initial body height of `…
gabriellsh Jul 10, 2026
eec6083
fix(message-parser): trailing backtick before line end breaks code bl…
ggazzo Jul 10, 2026
1637a8b
fix: Prevent app remount when VoIP license/permission changes (#41200)
dougfabris Jul 10, 2026
582d25d
chore: remove unused model query methods (#41227)
KevLehman Jul 10, 2026
23bdbad
fix: DST verifier unlinking all departments from custom business hour…
KevLehman Jul 11, 2026
719e3db
fix: LDAP users not merging by email during sync (#41279)
abhinavkrin Jul 11, 2026
edbaeef
fix: Setup wizard forced back into registration on upgrade when Show_…
KevLehman Jul 11, 2026
ed594fd
fix(a11y): add keyboard support in room members list (#41122)
juliajforesti Jul 13, 2026
d9fca72
test: fix flaky timeout in preview-public-channel spec (#41319)
KevLehman Jul 13, 2026
dd4023e
regression: fix issues rendering some existing emojis (#41305)
MartinSchoeler Jul 13, 2026
b9b2228
refactor(authorization): accept IUser in hasPermissionAsync wrappers …
ggazzo Jul 13, 2026
8ed0fa0
fix: server crash when re-enabling push notifications (#41341)
KevLehman Jul 13, 2026
73c3aec
chore: migrate batch4 client DDP callers + add 6 REST endpoints (#40728)
ggazzo Jul 13, 2026
01202cc
test: fix race in uikit-interactions e2e by awaiting interaction resp…
KevLehman Jul 13, 2026
460858e
fix: engagement dashboard fill (#41207)
sampaiodiego Jul 13, 2026
9690412
chore: reorganize backend folder structure — Phase 6 (lib, hooks, fea…
sampaiodiego Jul 14, 2026
c4bede4
refactor(authorization): accept a minimal user shape (UserWithRoles) …
ggazzo Jul 14, 2026
b634242
test: fix flaky omnichannel status toggle assertion in navbar page ob…
KevLehman Jul 14, 2026
a60e261
chore(authorization): bound roles-cache key to user id, skip cache wh…
ggazzo Jul 14, 2026
0faaaeb
test: fix strict mode violation flake in OC manual selection queue te…
KevLehman Jul 14, 2026
001902a
chore(api): migrate audit/chat/ldap/engagement single-route endpoints…
devin-ai-integration[bot] Jul 14, 2026
9860e02
chore(api): migrate engagement dashboard messages/users endpoints to …
devin-ai-integration[bot] Jul 14, 2026
d371c06
chore: bump fuselage packages (#41354)
ricardogarim Jul 14, 2026
4b34bd6
fix: import Slack files as attachments instead of raw URLs (#41285)
ricardogarim Jul 15, 2026
3598e2d
chore: upgrade xml-crypto to v6 (#41379)
abhinavkrin Jul 15, 2026
71d4d82
fix: server crash when LDAP search filter is invalid (#41373)
KevLehman Jul 15, 2026
1b7f9f2
test: stabilize flaky E2E message and navigation flows (#41114)
jessicaschelly Jul 15, 2026
012dd32
regression: Prevent saving license with non-plausible value (#41306)
dougfabris Jul 15, 2026
0e7b205
chore: reorganize backend folder structure — Phase 7 (omnichannel and…
sampaiodiego Jul 15, 2026
9db6a29
test: update stale proxyquire mock paths breaking unit test CI (#41403)
KevLehman Jul 15, 2026
bfacbd3
chore: Permissions translations in title case (#41380)
yash-rajpal Jul 15, 2026
7720156
chore(eslint): Replace eslint-plugin-import with eslint-plugin-import…
tassoevan Jul 16, 2026
cc63c0f
test: Remove virtual flag from CodeMirror spec mocks to fix flaky sui…
tassoevan Jul 16, 2026
8bbd1c6
refactor(api): pass this.user to permission checks in REST endpoints …
ggazzo Jul 16, 2026
cff23f9
fix: Disable composer actions without subscription to channel (#41202)
yash-rajpal Jul 16, 2026
ae72939
refactor(authorization): forward only { _id, roles } from hasPermissi…
ggazzo Jul 16, 2026
abab8a0
refactor: replace Fuselage styling prop shorthands with full prop nam…
tassoevan Jul 16, 2026
2ec4d29
fix(apps): write Deno runtime config to temp directory (#41338)
AlgoArtist06 Jul 16, 2026
f96b66d
docs: Add frontend guidelines (#41423)
tassoevan Jul 16, 2026
4b57346
feat: (poc) Unified AI Search (#40890)
Dnouv Jul 16, 2026
0e20907
chore: auto detect screen share based on video direction (#41366)
pierre-lehnen-rc Jul 16, 2026
ec7b1be
fix: dates showing one day earlier for users in negative UTC-offset (…
nazabucciarelli Jul 16, 2026
ffe1b64
fix: race condition in E2EE rooms creation causing 'incorrect encrypt…
nazabucciarelli Jul 16, 2026
81458c0
refactor: replace Fuselage styling prop shorthands with full prop nam…
ricardogarim Jul 17, 2026
14d0718
chore: refactor apps converters to TypeScript with Zod codecs (1/2) (…
d-gubert Jul 17, 2026
65a366e
feat: show relative time in Omnichannel Contact Center date columns (…
abhinavkrin Jul 17, 2026
74f50d1
feat(federation): Add XMPP bridge support (#40758)
sampaiodiego Jul 17, 2026
6d2c9f1
chore: remove unused @rocket.chat/log-format package (#41426)
tassoevan Jul 17, 2026
fce0bc7
chore: avoid fetching data just for counting (#41313)
sampaiodiego Jul 17, 2026
e8697f3
chore(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#41011)
dependabot[bot] Jul 17, 2026
d75d98b
chore(deps): bump docker/login-action from 4.1.0 to 4.2.0 (#40670)
dependabot[bot] Jul 17, 2026
c582421
chore(deps): bump github/codeql-action from 4.35.5 to 4.36.2 (#40831)
dependabot[bot] Jul 17, 2026
8975214
chore(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 (#40841)
dependabot[bot] Jul 17, 2026
f8d6b46
chore(deps): bump github/codeql-action/autobuild from 4.36.2 to 4.37.…
dependabot[bot] Jul 17, 2026
1bf84cb
feat: validate password policy length on settings save (#41173)
ricardogarim Jul 17, 2026
74d6cac
feat: no egress for offline licenses (#41148)
cardoso Jul 17, 2026
a3afae7
ci(codeql): align codeql-action steps to v4.37.1 (#41456)
ggazzo Jul 17, 2026
1629d33
chore: Align `react-stately` slim barrel patches for submenu support …
dougfabris Jul 17, 2026
aeb7467
chore(deps): bump websocket-driver (#41427)
yasnagat Jul 17, 2026
adc1570
regression: combined emojis displayed as separate emojis and some fla…
abhinavkrin Jul 17, 2026
13ea804
chore: bump fuselage packages (#41430)
ricardogarim Jul 17, 2026
f6c5579
fix: Restore Away to quick status menu (#41414)
ricardogarim Jul 17, 2026
c103cf5
chore: make screen share not rely on bundles from previous negotiatio…
pierre-lehnen-rc Jul 17, 2026
6a94ee4
ci: speed up merge queue runs (#41368)
KevLehman Jul 18, 2026
302f0c4
chore: add dom lib for WebRTC/DOM globals (TS7 compat) (#41262)
ggazzo Jul 18, 2026
7619669
ci: fix dynamic-import response truncation flake (proxy transport rac…
KevLehman Jul 18, 2026
6041285
fix: pagination and projection options silently ignored by model quer…
KevLehman Jul 17, 2026
b7bf284
chore: TS7 low-risk type fixes (assertions, casts) (#41264)
ggazzo Jul 18, 2026
34aa635
chore: Ensure page always reloads when app is crashes (#41453)
yash-rajpal Jul 17, 2026
7a360be
fix: prevent AI navbar search crashes and restore clear action (#41434)
Dnouv Jul 18, 2026
297df1a
fix(apps): resolve deno-runtime module not found after upgrade (#40947)
dsaicharan072-cmyk Jul 19, 2026
6ebabce
fix: newer license in env not applied (#41472)
cardoso Jul 20, 2026
82ae946
chore: use @rocket.chat/cron for presence status expiration in micros…
ricardogarim Jul 20, 2026
3240cdb
refactor(authorization): pass IUser to permission checks where alread…
ggazzo Jul 20, 2026
f2fc52d
chore: Switch AI Search feature as opt-in (#41464)
tassoevan Jul 20, 2026
0b5e592
refactor(gazzodown,livechat): Problematic import (#41463)
tassoevan Jul 20, 2026
0a1baf2
chore: remove duplicated emoji css (#41425)
ricardogarim Jul 20, 2026
b0ecca0
ci: skip redundant test re-run on develop push after merge queue (#41…
ggazzo Jul 20, 2026
8d8cd01
feat: FIPS 140-3 Compliant Docker Images (#39324)
cardoso Jul 20, 2026
a93d6da
ci: Update DockerHub login condition for queue type
ggazzo Jul 20, 2026
dddc5bd
chore(deps): bump adm-zip (#41476)
julio-rocketchat Jul 20, 2026
1d60700
chore(deps): bump dependencies with medium and low-severity CVEs (#41…
julio-rocketchat Jul 20, 2026
8d4507d
fix: missing "user left" system message after omnichannel room forwar…
KevLehman Jul 20, 2026
ea70952
ci: publish fips images as tags to dockerhub (#41486)
sampaiodiego Jul 20, 2026
4a4c297
chore(deps): bump GitHub Actions dependencies (#41485)
ggazzo Jul 20, 2026
d19487c
chore: update package versions to 9.0.0-develop across all relevant f…
ggazzo Feb 25, 2026
72167db
chore!: stop transpiling webhook integration scripts with Babel (#40142)
ggazzo Apr 14, 2026
0aac0ae
chore: remove sendFileMessage meteor method (#40288)
nazabucciarelli Apr 24, 2026
5f3e8c7
Reapply "chore!: remove insertOrUpdateSound and uploadCustomSound Met…
ggazzo May 13, 2026
db2ce7a
chore!: remove deleteCustomSound Meteor method (#40883)
nazabucciarelli Jun 23, 2026
1e5873b
chore!: Remove `/ufs` endpoint (#41054)
KevLehman Jun 30, 2026
7621bfc
chore!: remove WebDav integration (#40856)
yasnagat Jul 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
8 changes: 8 additions & 0 deletions .changeset/all-baths-cry.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/model-typings': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/models': minor
'@rocket.chat/meteor': minor
---

Adds `current` field to `DeviceManagementSession` type and `currentLoginToken` parameter to `aggregateSessionsByUserId`, allowing the sessions endpoint to identify and flag the caller's active session.
8 changes: 8 additions & 0 deletions .changeset/atomic-model-operations.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/core-typings': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/models': patch
---

Fixes race conditions in several check-then-write database flows by collapsing them into single atomic operations: CAS login tokens can no longer be consumed by two concurrent logins, revoking a room invite no longer emits duplicate removal notifications, and deleting an integration now enforces the creator-only permission scope in the delete itself
5 changes: 5 additions & 0 deletions .changeset/better-results-press.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": major
---

Removes `/ufs` legacy endpoint for downloading files
5 changes: 5 additions & 0 deletions .changeset/block-fallback-rendering.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/gazzodown": patch
---

Degrades blocks without a dedicated renderer to their raw markup instead of dropping them. When a block carries a `fallback` `[start, end]` offset span, `Markup`/`PreviewMarkup` slice the original message source (passed via the new optional `source` prop) and render that text. This avoids duplicating the markup into the AST while keeping unsupported blocks visible.
5 changes: 5 additions & 0 deletions .changeset/breezy-moons-search.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes own account showing twice in navbar room search when searching by username
31 changes: 31 additions & 0 deletions .changeset/breezy-parts-kiss.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
'@rocket.chat/web-ui-registration': major
'@rocket.chat/model-typings': major
'@rocket.chat/core-typings': major
'@rocket.chat/rest-typings': major
'@rocket.chat/passport-x': major
'@rocket.chat/models': major
'@rocket.chat/i18n': major
'@rocket.chat/meteor': major
---

## Phishing-Resistant Multi-Factor Authentication

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release changelog will contain this OAuth feature twice because .changeset/flat-poets-cheat.md already documents the same change. Consolidating the notes and package bump into one changeset would avoid duplicate release documentation.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/breezy-parts-kiss.md, line 12:

<comment>The release changelog will contain this OAuth feature twice because `.changeset/flat-poets-cheat.md` already documents the same change. Consolidating the notes and package bump into one changeset would avoid duplicate release documentation.</comment>

<file context>
@@ -0,0 +1,31 @@
+'@rocket.chat/meteor': major
+---
+
+## Phishing-Resistant Multi-Factor Authentication
+
+Introduces a more secure and reliable server-side OAuth authentication flow.
</file context>


Introduces a more secure and reliable server-side OAuth authentication flow.

### What’s New

- **Improved OAuth login security**
OAuth authentication now happens fully on the server, reducing the risk of token theft, phishing attacks, and client-side credential interception.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: This security claim is unconditional even though Accounts_OAuth_Use_Modern_Flow defaults to false; existing and new installations continue using the legacy flow until an administrator enables it. Qualifying this and the following security bullets with “when enabled” would keep the release notes from overstating the default behavior.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/breezy-parts-kiss.md, line 19:

<comment>This security claim is unconditional even though `Accounts_OAuth_Use_Modern_Flow` defaults to `false`; existing and new installations continue using the legacy flow until an administrator enables it. Qualifying this and the following security bullets with “when enabled” would keep the release notes from overstating the default behavior.</comment>

<file context>
@@ -0,0 +1,31 @@
+### What’s New
+
+- **Improved OAuth login security**  
+  OAuth authentication now happens fully on the server, reducing the risk of token theft, phishing attacks, and client-side credential interception.
+
+- **Built-in CSRF, state validation, and PKCE protection**  
</file context>


- **Built-in CSRF, state validation, and PKCE protection**
OAuth logins now include stronger protection against CSRF attacks, request tampering, and authorization code interception through secure state validation and PKCE support.

- **Improved two-step verification with OAuth logins**
Users with email or TOTP two-factor authentication enabled will now be asked to complete 2FA even when signing in with providers like Google, GitHub, GitLab, and others.

- **Improved mobile & desktop app login**
Mobile and desktop apps now support a smoother and more secure deep-link OAuth login flow.

- **A new setting to enable/disable new OAuth Flow**
Enable this new setting `Accounts_OAuth_Use_Modern_Flow` to use all of the above mentioned features.
5 changes: 5 additions & 0 deletions .changeset/code-fence-trailing-backtick.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/message-parser": patch
---

Fixes code fences failing to render when a line inside them ends with an inline-code backtick (e.g. `` - **Node**: `22.22.3` ``). A trailing backtick immediately before a line break could not be consumed as content, causing the whole ```` ``` ```` block to fall back to markdown parsing and split apart. Trailing 1-2 backticks before a line end (or EOF) are now treated as code content.
7 changes: 7 additions & 0 deletions .changeset/deep-ways-poke.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/core-typings': patch
'@rocket.chat/models': patch
'@rocket.chat/meteor': patch
---

Fixes the Slack importer storing shared files as raw URLs in the message body. Imported file messages now stay hidden until "Download Pending Files" button fetches them, then display as native attachments with image previews. Failed downloads (e.g. invalidated export links) are no longer silently saved as the file's content — they are counted as errors and can be retried.
6 changes: 6 additions & 0 deletions .changeset/desktop-set-user-roles.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/desktop-api': minor
'@rocket.chat/meteor': patch
---

Added a `setUserRoles` bridge method to the desktop API and pushed the logged-in user's roles to the desktop app. This lets the desktop client restrict supportedVersions messages (such as version-expiration warnings) to specific roles like admins, instead of showing them to every user. The push is reactive to role changes; desktop builds without the bridge method fall back to their own role lookup.
5 changes: 5 additions & 0 deletions .changeset/emoji-zwj-tag-sequences.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/message-parser': patch
---

Fixes an issue in which some combined emojis like 😶‍🌫️, 😮‍💨 and 😵‍💫 were being displayed as two separate emojis, and the flags of some countries like England 🏴󠁧󠁢󠁥󠁮󠁧󠁿, Scotland 🏴󠁧󠁢󠁳󠁣󠁴󠁿 and Wales 🏴󠁧󠁢󠁷󠁬󠁳󠁿 were being displayed as a plain black flag
5 changes: 5 additions & 0 deletions .changeset/empty-boxes-cross.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes engagement dashboard loading unnecessary data into memory on startup
6 changes: 6 additions & 0 deletions .changeset/empty-garlics-reply.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/core-typings': patch
'@rocket.chat/meteor': patch
---

Fixes the password policy allowing a maximum length lower than the minimum length to be saved — a combination that made it impossible to set any valid password. The server now rejects such configurations when password policy settings are saved and shows an error explaining the constraint.
5 changes: 5 additions & 0 deletions .changeset/fancy-days-knock.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
10 changes: 10 additions & 0 deletions .changeset/fancy-deserts-mate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
'@rocket.chat/core-services': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/ai-search': minor
'@rocket.chat/ui-client': minor
'@rocket.chat/i18n': minor
'@rocket.chat/meteor': minor
---

Adds AI Search with semantic message results, optional OpenAI-compatible answers, and AI Center configuration.
7 changes: 7 additions & 0 deletions .changeset/fifty-candies-heal.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/meteor': patch
---

fix: Buttons from emoji picker misbehaving on clicks

An infinite render loop was preventing proper behavior when clicking on the emoji picker buttons. It was fixed by removing the unnecessary state update that was causing the loop and replacing multiple fires of the same mouseover event (when a mouseenter event was the right one to use). There is a chance this pre-existing bug was hidden by React 18's event delegation.
13 changes: 13 additions & 0 deletions .changeset/fips-mode-support.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/federation-matrix': minor

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release metadata gives @rocket.chat/federation-matrix a minor FIPS feature release even though it has no FIPS implementation or dedicated FIPS image and is not one of the services named in the feature description. Removing this package from the changeset would avoid an unrelated version bump and misleading package changelog entry.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/fips-mode-support.md, line 4:

<comment>The release metadata gives `@rocket.chat/federation-matrix` a minor FIPS feature release even though it has no FIPS implementation or dedicated FIPS image and is not one of the services named in the feature description. Removing this package from the changeset would avoid an unrelated version bump and misleading package changelog entry.</comment>

<file context>
@@ -0,0 +1,13 @@
+---
+'@rocket.chat/meteor': minor
+'@rocket.chat/core-typings': minor
+'@rocket.chat/federation-matrix': minor
+'@rocket.chat/account-service': minor
+'@rocket.chat/authorization-service': minor
</file context>

'@rocket.chat/account-service': minor
'@rocket.chat/authorization-service': minor
'@rocket.chat/ddp-streamer': minor
'@rocket.chat/omnichannel-transcript': minor
'@rocket.chat/presence-service': minor
'@rocket.chat/queue-worker': minor
---

Adds support for running Rocket.Chat in FIPS mode. The monolith and all microservices (ddp-streamer, account-service, authorization-service, presence-service, queue-worker, omnichannel-transcript) can now enforce FIPS-compliant cryptography via Node.js/OpenSSL FIPS, with dedicated FIPS Docker images. Running in FIPS mode requires a license including the new `fips` module, and FIPS status is now reported in server logs and statistics.
5 changes: 5 additions & 0 deletions .changeset/fix-business-hour-agents-availability.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes agents' business-hour availability not being updated when they are removed from a department linked to a business hour while multiple business hours are enabled. The recomputation step always failed, leaving removed agents available (or unavailable) according to a business hour that no longer applied to them — and, on deployments running with `EXIT_UNHANDLEDPROMISEREJECTION` (or in development/test mode), the unhandled rejection crashed the server process.
7 changes: 7 additions & 0 deletions .changeset/fix-business-hour-dst-department-unlink.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/meteor': patch
---

Fixes multiple business hours losing their linked departments after a daylight saving time change or a server restart. The automatic timezone adjustment re-saved business hours without their department associations, causing business hours configured with timezones to silently stop applying to agents.

Also fixes agents keeping a business hour's availability after their department was removed from it: saving a business hour with a smaller department list unlinked the departments but never cleared the business hour from the removed departments' agents.
5 changes: 5 additions & 0 deletions .changeset/fix-deno-runtime-symlink.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/apps': patch
---

Fixes an issue that would cause apps to fail with 'Module not found' errors in some cases
6 changes: 6 additions & 0 deletions .changeset/fix-license-env-precedence.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/license': patch
---

Fixes the license provided via the `ROCKETCHAT_LICENSE` environment variable not being applied when it is newer than the one persisted in the workspace.
28 changes: 28 additions & 0 deletions .changeset/flat-poets-cheat.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
'@rocket.chat/web-ui-registration': minor
'@rocket.chat/model-typings': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/desktop-api': minor
'@rocket.chat/models': minor
'@rocket.chat/i18n': minor
'@rocket.chat/meteor': minor
---

## Phishing-Resistant Multi-Factor Authentication

Introduces a more secure and reliable server-side OAuth authentication flow.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Administrators who upgrade will not receive the documented modern OAuth behavior by default because Accounts_OAuth_Use_Modern_Flow defaults to false, yet this release note describes it as automatic and never tells them to enable the setting. The note should explicitly identify the toggle and its default/rollout behavior.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/flat-poets-cheat.md, line 14:

<comment>Administrators who upgrade will not receive the documented modern OAuth behavior by default because `Accounts_OAuth_Use_Modern_Flow` defaults to `false`, yet this release note describes it as automatic and never tells them to enable the setting. The note should explicitly identify the toggle and its default/rollout behavior.</comment>

<file context>
@@ -0,0 +1,28 @@
+
+## Phishing-Resistant Multi-Factor Authentication
+
+Introduces a more secure and reliable server-side OAuth authentication flow.
+
+### What’s New
</file context>


### What’s New

- **Improved OAuth login security**
OAuth authentication now happens fully on the server, reducing the risk of token theft, phishing attacks, and client-side credential interception.

- **Built-in CSRF, state validation, and PKCE protection**
OAuth logins now include stronger protection against CSRF attacks, request tampering, and authorization code interception through secure state validation and PKCE support.

- **Improved two-step verification with OAuth logins**
Users with email or TOTP two-factor authentication enabled will now be asked to complete 2FA even when signing in with providers like Google, GitHub, GitLab, and others.

- **Improved mobile & desktop app login**
Mobile and desktop apps now support a smoother and more secure deep-link OAuth login flow.
5 changes: 5 additions & 0 deletions .changeset/forty-stars-bathe.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes error message being shown when logging out current device via Device Management despite successful logout.
7 changes: 7 additions & 0 deletions .changeset/four-tigers-clap.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/models': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/meteor': patch
---

Fixes a race condition that left messages permanently undecryptable ("incorrect encryption key") in rooms created with encryption enabled. When several members opened such a room at the same time, each client could independently generate and distribute a different group key. Establishing the room key is now atomic (first-write-wins) on the server, and a client that loses the race discards its locally generated key and adopts the established one instead of encrypting with a divergent key.
6 changes: 6 additions & 0 deletions .changeset/fruity-items-fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/apps': minor
'@rocket.chat/meteor': minor
---

Adds an alternative runtime runner for apps. It can be enabled via environment variable `APPS_ENGINE_RUNTIME_BACKEND='node'`
8 changes: 8 additions & 0 deletions .changeset/gentle-cats-change.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/core-typings': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/models': patch
---

Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
13 changes: 13 additions & 0 deletions .changeset/integration-scripts-no-babel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
'@rocket.chat/meteor': major
---

**Breaking:** Stopped transpiling webhook integration scripts with Babel. Scripts now run as-is inside `isolated-vm` (modern V8).

Class method bodies are now in strict mode per the ES2015 spec. Scripts that relied on sloppy-mode behaviors provided by the previous Babel transpilation must be updated:

- **Implicit globals** — `msg = buildMessage(...)` inside a class method now throws `ReferenceError`. Add `let`, `const`, or `var`.
- **`this` in nested regular functions** — `function helper() { this.JSON.stringify(...) }` now has `this === undefined` instead of `globalThis`. Use arrow functions or pass the dependency explicitly.
- **`arguments.callee`** — Throws `TypeError`. Use a named function expression instead.
- **Octal literals** — `0777` is now a `SyntaxError`. Use `0o777`.
- **Duplicate parameter names** — `function(a, a) {}` is now a `SyntaxError`.
6 changes: 6 additions & 0 deletions .changeset/json-setting-validation-feedback.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@rocket.chat/meteor": minor
"@rocket.chat/i18n": minor
---

Adds inline JSON validation feedback to admin settings that hold JSON (`code: application/json`), showing an error in the editor and blocking save while the value is malformed
5 changes: 5 additions & 0 deletions .changeset/ldap-channel-sync-removal-abort.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes LDAP channel sync aborting the entire add/removal pass when a mapped channel could not be resolved, which prevented users from being removed from channels when "Auto Remove Users from Channels" was enabled.
6 changes: 6 additions & 0 deletions .changeset/ldap-merge-email-lookup.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/models': patch
'@rocket.chat/meteor': patch
---

Fixes LDAP sync failing to merge an existing user matched by email, which caused a `Username already exists` error when the user's username differed from the directory.
5 changes: 5 additions & 0 deletions .changeset/ldap-sync-crash-invalid-filter.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes the server crashing during LDAP login or sync when the configured search settings produce an invalid LDAP filter (for example, an empty User Search Field). The operation now fails gracefully with a logged error instead of terminating the process.
7 changes: 7 additions & 0 deletions .changeset/license-validate-preview.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/license': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/meteor': minor
---

Adds a new `licenses.validate` REST endpoint that validates a Rocket.Chat license (V2 or V3 JWT) against the current workspace without applying it, so a license can be previewed before it is applied from the UI. A valid license responds with success; an invalid one responds with the validation behaviors that rejected it.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release note incorrectly labels V2 licenses as JWTs, which can mislead clients about the token format accepted by licenses.validate. Describing the formats as “V2 licenses or V3 JWTs” keeps the migration/API documentation precise.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/license-validate-preview.md, line 7:

<comment>The release note incorrectly labels V2 licenses as JWTs, which can mislead clients about the token format accepted by `licenses.validate`. Describing the formats as “V2 licenses or V3 JWTs” keeps the migration/API documentation precise.</comment>

<file context>
@@ -0,0 +1,7 @@
+'@rocket.chat/meteor': minor
+---
+
+Adds a new `licenses.validate` REST endpoint that validates a Rocket.Chat license (V2 or V3 JWT) against the current workspace without applying it, so a license can be previewed before it is applied from the UI. A valid license responds with success; an invalid one responds with the validation behaviors that rejected it.
</file context>

5 changes: 5 additions & 0 deletions .changeset/light-geckos-start.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Disables more actions on message composer during public channel preview.
5 changes: 5 additions & 0 deletions .changeset/livechat-forward-ul-message.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes an issue where the "user left" system message could be added to an Omnichannel conversation only after the forwarding process had already finished, causing it to appear out of order in the conversation history
5 changes: 5 additions & 0 deletions .changeset/message-content-body-source.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": patch
---

Passes the original message text to the message renderer so blocks without a dedicated renderer (e.g. tables on clients that don't render them yet) can degrade to their raw markup via the parser's `fallback` source offsets, instead of disappearing.
5 changes: 5 additions & 0 deletions .changeset/moody-eggs-juggle.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes an issue where the cursor jumped to the wrong position after inserting a mention at the start or middle of a message.
5 changes: 5 additions & 0 deletions .changeset/nice-fans-cover.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": minor
---

Replaces proprietary emojis with native (unicode) emojis and increases available emoji set
6 changes: 6 additions & 0 deletions .changeset/offline-license-no-egress.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/license': minor
---

Adds support for the `offline` license flag, suppressing every outbound connection to Rocket.Chat Cloud services and the Push Gateway at its source, so air-gapped workspaces never initiate calls that would violate their security compliance.
6 changes: 6 additions & 0 deletions .changeset/old-bats-sniff.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/apps-engine': patch
'@rocket.chat/meteor': patch
---

Fixes wrong FederationLookup type assigned to IUser in apps. The correct data is there, but the type does not represent it.
5 changes: 5 additions & 0 deletions .changeset/olive-nails-fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Enables keyboard activation for Display menu radio buttons and checkboxes
5 changes: 5 additions & 0 deletions .changeset/omnichannel-contact-center-date-relative-time.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Changes the date columns in the Omnichannel Contact Center to show both the formatted date and the relative time: the **Last Chat** column in the contacts list, and the **Started at** and **Last Message** columns in the chats list
6 changes: 6 additions & 0 deletions .changeset/parser-horizontal-rule.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@rocket.chat/message-parser": minor
"@rocket.chat/gazzodown": minor
---

Adds support for horizontal rules (thematic breaks) in the message parser. A line of 3 or more contiguous dashes (`---`, with nothing else on the line) is parsed into a new `HORIZONTAL_RULE` block node and rendered with Fuselage's `Divider`. The node carries an optional `fallback` — a `[start, end]` offset span into the original source — so renderers without horizontal-rule support can slice the source to show the raw markup instead of dropping it, without duplicating the text into the AST. Only `-` is accepted: CommonMark also allows `*` and `_`, but those collide with emphasis and with censored words (bad-words masks a term as a run of `*`), so a bare `***` / `_______` line stays text/emphasis instead of becoming a divider.
6 changes: 6 additions & 0 deletions .changeset/persistent-audio-player.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/i18n': minor
---

Added a persistent audio player. Playing an audio attachment now continues across room navigation: the audio keeps playing when you switch or close the conversation, and a "Now playing" card appears at the top of the sidebar with play/pause, seek, playback speed (1x/1.5x/2x), and a shortcut back to the originating conversation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release note says the Now playing card appears at the top of the sidebar, but the component is mounted after the room list and is documented as pinned to the bottom. Describing it as the bottom sidebar card would keep the generated changelog accurate.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/persistent-audio-player.md, line 6:

<comment>The release note says the Now playing card appears at the top of the sidebar, but the component is mounted after the room list and is documented as pinned to the bottom. Describing it as the bottom sidebar card would keep the generated changelog accurate.</comment>

<file context>
@@ -0,0 +1,6 @@
+'@rocket.chat/i18n': minor
+---
+
+Added a persistent audio player. Playing an audio attachment now continues across room navigation: the audio keeps playing when you switch or close the conversation, and a "Now playing" card appears at the top of the sidebar with play/pause, seek, playback speed (1x/1.5x/2x), and a shortcut back to the originating conversation.
</file context>

5 changes: 5 additions & 0 deletions .changeset/push-reenable-crash.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes a server crash when re-enabling the "Enable Push" setting after it was disabled. Push notifications are now fully reconfigured on re-enable, so settings changed while push was disabled are picked up as well.
5 changes: 5 additions & 0 deletions .changeset/quiet-lizards-jump.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Ensures the `users.CreateToken` endpoint checks for the `user-generate-access-token` permission when generating a login token for another user

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release note names an endpoint that does not match the actual API, so users searching for users.CreateToken will not find this change. Naming the createToken DDP method (or describing the actual exposed route) keeps the release documentation actionable.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/quiet-lizards-jump.md, line 5:

<comment>The release note names an endpoint that does not match the actual API, so users searching for `users.CreateToken` will not find this change. Naming the `createToken` DDP method (or describing the actual exposed route) keeps the release documentation actionable.</comment>

<file context>
@@ -0,0 +1,5 @@
+'@rocket.chat/meteor': patch
+---
+
+Ensures the `users.CreateToken` endpoint checks for the `user-generate-access-token` permission when generating a login token for another user
</file context>

5 changes: 5 additions & 0 deletions .changeset/quiet-teams-guard.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
5 changes: 5 additions & 0 deletions .changeset/ready-taxis-join.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Restores Away as a selectable preset in the quick status menu, custom status modal, and account profile page.
5 changes: 5 additions & 0 deletions .changeset/remove-webdav-integration.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': major
---

Removes the WebDAV integration. All WebDAV accounts, settings, and file-picker functionality have been removed, and existing WebDAV settings are cleared from the database on upgrade
5 changes: 5 additions & 0 deletions .changeset/rest-batch4-logout-cleanup.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': minor
---

Deprecates the `logoutCleanUp` DDP method and stops the client from calling it. The post-logout side effects (`afterLogoutCleanUpCallback` + `Apps.IPostUserLoggedOut`) now run server-side via a new `Accounts.onLogout` handler and from `POST /v1/users.logout`, so both DDP and REST logout paths fire them without a client round-trip. The DDP method keeps its original implementation and registration with a deprecation log pointing at `/v1/users.logout` until 9.0.0.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The release note says logoutCleanUp is retained only until 9.0.0, even though this 9.0.0 release still registers the method and emits its deprecation warning. Wording that it remains available in 9.0.0 and is planned for removal in a later release would avoid misleading existing DDP clients.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .changeset/rest-batch4-logout-cleanup.md, line 5:

<comment>The release note says `logoutCleanUp` is retained only until 9.0.0, even though this 9.0.0 release still registers the method and emits its deprecation warning. Wording that it remains available in 9.0.0 and is planned for removal in a later release would avoid misleading existing DDP clients.</comment>

<file context>
@@ -0,0 +1,5 @@
+'@rocket.chat/meteor': minor
+---
+
+Deprecates the `logoutCleanUp` DDP method and stops the client from calling it. The post-logout side effects (`afterLogoutCleanUpCallback` + `Apps.IPostUserLoggedOut`) now run server-side via a new `Accounts.onLogout` handler and from `POST /v1/users.logout`, so both DDP and REST logout paths fire them without a client round-trip. The DDP method keeps its original implementation and registration with a deprecation log pointing at `/v1/users.logout` until 9.0.0.
</file context>

6 changes: 6 additions & 0 deletions .changeset/rest-cloud-connect-workspace.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/rest-typings': minor
'@rocket.chat/meteor': minor
---

Added `POST /v1/cloud.connectWorkspace` (replaces the deprecated `cloud:connectWorkspace` DDP method). Body is `{ token }`; auth-gated with `manage-cloud` permission. The legacy DDP method remains registered with a deprecation log pointing at the new route.
Loading
Loading