Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
225 commits
Select commit Hold shift + click to select a range
855c5c2
test: flaky `session-expiration-redirect.spec` (#41018)
gabriellsh Jun 22, 2026
ffaa115
refactor(ui-voip): extract PeerCardsView from MediaCallRoomSection (#…
ggazzo Jun 22, 2026
46d7c8e
Merge remote-tracking branch 'origin/release-8.6.0' into develop
ggazzo Jun 23, 2026
c3b4d0e
bump rocket.chat to 8.7.0-develop
ggazzo Jun 23, 2026
4fb271e
test(e2e): work around E2E test instabilities (#41005)
tassoevan Jun 23, 2026
e626fb9
fix: voice call fails if user navigates during initial connection (#4…
pierre-lehnen-rc Jun 23, 2026
5620611
chore: Change navbar's search input icon size (#41042)
dougfabris Jun 23, 2026
7da5ec6
Merge remote-tracking branch 'origin/release-8.6.0' into develop
ggazzo Jun 23, 2026
80cddeb
chore(deps): bump ajv (#41049)
julio-rocketchat Jun 24, 2026
2e8ea32
chore(deps): bump rharkor/caching-for-turbo from 2.4.2 to 2.5.0 (#41064)
dependabot[bot] Jun 24, 2026
0433f00
feat(desktop): push user roles to the desktop app (#41056)
ggazzo Jun 24, 2026
3d0aa38
chore: improve voip enums definitions (#41045)
pierre-lehnen-rc Jun 24, 2026
0241250
test: fix rooms-join flaky test (#41072)
sampaiodiego Jun 25, 2026
aa96fe5
refactor(ui-voip): Extract MediaCallCardList and PopoutDockPrompt fro…
aleksandernsilva Jun 25, 2026
660215a
chore: use @rocket.chat/logger in presence service (#41034)
ricardogarim Jun 25, 2026
41fde25
i18n: Rocket.Chat language update from Lingohub 🤖 on 2026-06-22Z (#41…
lingohub[bot] Jun 25, 2026
64af832
chore(apps): unit test improvements (#40785)
d-gubert Jun 25, 2026
e4dba79
fix(federation): edited and deleted messages corrupting event tree (#…
sampaiodiego Jun 26, 2026
32880c4
Merge remote-tracking branch 'origin/release-8.6.0' into develop
ggazzo Jun 26, 2026
2c4292b
chore(deps): bump actions/cache from 5.0.5 to 6.0.0 (#41073)
dependabot[bot] Jun 26, 2026
e929d2d
chore: improve Docker images for micro services (#41083)
sampaiodiego Jun 26, 2026
294ee5d
test(e2e): close leaked browser contexts in omnichannel livechat spec…
ggazzo Jun 26, 2026
eed19bc
test: use gotoChannel when possible (#41084)
sampaiodiego Jun 29, 2026
275a6ed
chore(deps): bump actions/cache/save from 6.0.0 to 6.1.0 (#41096)
dependabot[bot] Jun 29, 2026
3cd35ab
chore: reorganize backend folder structure — Phase 1 (slash commands)…
sampaiodiego Jun 29, 2026
3cd7db6
fix: Imported fixes 06-24-26 (#41069)
jonasflorencio Jun 30, 2026
9f08d1a
chore(deps): bump mailparser, nodemailer, and undici, markdown-it (#4…
julio-rocketchat Jun 30, 2026
a158ae7
refactor: React 19 (#40796)
tassoevan Jun 30, 2026
3001445
chore: reorganize backend folder structure — Phase 2 (external bridge…
sampaiodiego Jun 30, 2026
6ca1ce7
refactor(uikit-playground,deps): Update `react-split-pane` (#41118)
tassoevan Jun 30, 2026
615ae2b
fix: `customFields` property missing on `admin.getRoom` endpoint (#41…
KevLehman Jun 30, 2026
b6e0d3b
chore: bump license (#41130)
ggazzo Jul 1, 2026
70c0ff0
feat(message-parser): block fallback for unsupported renderers (#41110)
ggazzo Jul 1, 2026
761314d
test: Flaky should navigate on navbar toolbar pressing tab (#41135)
dougfabris Jul 1, 2026
4117a1d
feat(message-parser): horizontal rule (thematic break) (#41113)
ggazzo Jul 1, 2026
890d394
test: Flaky should display rooms in direct message filter (#41137)
dougfabris Jul 1, 2026
cbbcd47
test: add guards to composer focus to prevent flakyness (#41106)
sampaiodiego Jul 2, 2026
5e5990a
chore: apply least privilege permissions to github actions (#40687)
yasnagat Jul 2, 2026
e36211a
refactor: Use flat components (#41139)
tassoevan Jul 2, 2026
5508c6c
chore(apps): refactor deno-runtime imports (#41103)
d-gubert Jul 2, 2026
2f28c1c
fix: grant actions:read at ci.yml top level to fix CI startup_failure…
KevLehman Jul 2, 2026
ef28aee
chore: reorganize backend folder structure — Phase 3 (REST API) (#41126)
sampaiodiego Jul 2, 2026
e5da5d0
feat(message-parser): add GFM table support (#41109)
ggazzo Jul 2, 2026
6da12d7
fix: Keyboard activation doesn't toggle Display menu controls (#41089)
juliajforesti Jul 2, 2026
ae5a95d
chore: Upgrade fuselage packages (#41150)
dougfabris Jul 2, 2026
c7aff48
fix: current device logout showing error (#40351)
juliajforesti Jul 3, 2026
1cc7bbd
chore(spotlight): parallelize searches and slim connected-users pipel…
KevLehman Jul 3, 2026
115dfe8
feat: Validate `code: application/json` settings on UI (#41142)
KevLehman Jul 3, 2026
ebd4a12
test: refactor team management permissions (#41136)
jessicaschelly Jul 3, 2026
eb88328
Merge remote-tracking branch 'origin/master' into develop
ggazzo Jul 3, 2026
9a80dd7
chore(apps): refactor deno-runtime to drop Deno specific APIs (#41125)
d-gubert Jul 3, 2026
376c9d8
feat(audio): persistent audio player across room navigation (#41120)
ggazzo Jul 3, 2026
8dc4964
chore(apps): isolate platform independent logic from deno-runtime (#4…
d-gubert Jul 3, 2026
7f39354
test: add coverage for livechat rooms delete endpoint (#41162)
jessicaschelly Jul 3, 2026
d51868c
test: isolate session expiration e2e users (#41166)
jessicaschelly Jul 4, 2026
cf5dfd2
chore(deps): patch file-type (#41161)
yasnagat Jul 4, 2026
5ed0dac
fix: Use request's `RelayState` for SAML Single Sign Out (#41145)
KevLehman Jul 4, 2026
3296b4d
fix: business-hour availability not recomputed when agents are remove…
KevLehman Jul 4, 2026
0759f83
fix: own account showing twice in navbar room search when searching b…
nazabucciarelli Jul 6, 2026
31df377
test: Flaky `chat-transfer-manager` spec (#41170)
KevLehman Jul 6, 2026
784c287
feat(apps): introduce alternative node-runtime (#41019)
d-gubert Jul 6, 2026
b2b5edf
feat: Improve manual license management (#40916)
dougfabris Jul 6, 2026
78fb2fc
refactor: Replace deprecated `addon` prop (#41151)
tassoevan Jul 6, 2026
a62b126
chore: reorganize backend folder structure — Phase 4 (domain function…
sampaiodiego Jul 6, 2026
44f2b6b
refactor: Remove local definitions of `DeepWritable` (#41185)
tassoevan Jul 6, 2026
e1e426b
fix: Buttons from emoji picker misbehaving on clicks (#41195)
tassoevan Jul 6, 2026
bafa6c1
test: fix race condition in business hours toggle e2e test (#41198)
KevLehman Jul 7, 2026
5f92f9a
chore: atomic updates (#41174)
KevLehman Jul 7, 2026
e7d8654
refactor: Explicit component props (1/23) (#41175)
tassoevan Jul 7, 2026
a7551fa
refactor: Explicit component props (2/23) (#41176)
tassoevan Jul 7, 2026
0523a4a
fix(ux): Missing a visible quote message link (#41091)
dougfabris Jul 7, 2026
b6cac3b
refactor: Explicit component props (3/23) (#41177)
tassoevan Jul 7, 2026
37cc624
refactor: Explicit component props (5/23) (#41179)
tassoevan Jul 7, 2026
5740ec5
refactor: Explicit component props (6/23) (#41180)
tassoevan Jul 7, 2026
9ffcbd2
refactor: Explicit component props (7/23) (#41181)
tassoevan Jul 7, 2026
8ed8599
refactor: Explicit component props (8/23) (#41182)
tassoevan Jul 7, 2026
160e7f1
refactor: Explicit component props (9/23) (#41183)
tassoevan Jul 7, 2026
4fa7ab6
refactor: Explicit component props (10/23) (#41184)
tassoevan Jul 7, 2026
31249c3
refactor: Explicit component props (4/23) (#41178)
tassoevan Jul 7, 2026
38e80cb
ci: fix Docker image size report showing zero for current (#41226)
ggazzo Jul 7, 2026
39bfdf4
refactor: Explicit component props (15/23) (#41214)
tassoevan Jul 7, 2026
355c8c0
fix: LDAP channel sync finishing early when one of the channels on ma…
KevLehman Jul 8, 2026
d4e7012
refactor: Explicit component props (20/23) (#41219)
tassoevan Jul 8, 2026
e8f64e8
refactor: Explicit component props (21/23) (#41220)
tassoevan Jul 8, 2026
aadd798
refactor: Explicit component props (23/23) (#41222)
tassoevan Jul 8, 2026
175a19c
fix: team conversion permissions checked incorrectly (#41206)
julio-rocketchat Jul 8, 2026
e75965c
refactor: Explicit component props (18/23) (#41217)
tassoevan Jul 8, 2026
6405491
fix: users.CreateToken endpoint lacks user-generate-access-token perm…
jonasflorencio Jul 8, 2026
0709149
fix: imported fixes 07-08-2026 (#41233)
julio-rocketchat Jul 8, 2026
4551b27
refactor: Explicit component props (11/23) (#41210)
tassoevan Jul 8, 2026
c3a3741
refactor: Explicit component props (12/23) (#41211)
tassoevan Jul 8, 2026
c7b78c2
refactor: Explicit component props (13/23) (#41212)
tassoevan Jul 8, 2026
9219709
refactor: Explicit component props (14/23) (#41213)
tassoevan Jul 8, 2026
d480490
refactor: Explicit component props (16/23) (#41215)
tassoevan Jul 8, 2026
d91ce3a
refactor: Explicit component props (19/23) (#41218)
tassoevan Jul 8, 2026
ed63cfc
refactor: Explicit component props (22/23) (#41221)
tassoevan Jul 8, 2026
5894a29
chore: message parser limit on the client (#40600)
gabriellsh Jul 8, 2026
70c4d9e
chore: reject non-renderable image formats for avatars (#41223)
abhinavkrin Jul 8, 2026
eddd589
chore: remove emojione in favor of native emojis (#39411)
sampaiodiego Jul 8, 2026
3d8723b
test: fix omnichannel-takeChat flake by waiting for agent availabilit…
KevLehman Jul 8, 2026
668d529
test: registration invalid URL test running before page is ready (#40…
jessicaschelly Jul 9, 2026
8e9047c
chore: remove media call channels model (#41194)
pierre-lehnen-rc Jul 9, 2026
bfc2abe
fix: Video attachment controls not clickable on Chromium 150 (#41230)
ricardogarim Jul 9, 2026
01dfb44
chore: correct log error details on videoconf service (#41256)
pierre-lehnen-rc Jul 9, 2026
8e33c5a
fix(ui): Misaligned username in Read Receipts list (#41199)
abhinavkrin Jul 9, 2026
f633d7e
refactor: Explicit component props (17/23) (#41216)
tassoevan Jul 9, 2026
d0f8943
chore: explicit meteor package imports (#41259)
KevLehman Jul 9, 2026
13b4a7b
feat: Phishing resistant MFA (#40721)
yash-rajpal Jul 9, 2026
3b27160
chore: reorganize backend folder structure — Phase 5 (meteor methods)…
sampaiodiego Jul 10, 2026
87663fa
chore(ui): Change quote attachment link icon (#41228)
dougfabris Jul 10, 2026
398525a
refactor(ui-client): Non-standard `useThemeMode` (#41284)
tassoevan Jul 10, 2026
6f85f55
regression: URL preview embeds flicker on new messages/reactions (Rea…
ggazzo Jul 10, 2026
0b70a73
fix: incorrect cursor position after inserting mention (#41074)
abhinavkrin Jul 10, 2026
5f21093
chore: use public preact JSX import in livechat (TS7 compat) (#41263)
ggazzo Jul 10, 2026
8dacf28
chore(streamer): defensively guard against a null session socket (#41…
ggazzo Jul 10, 2026
4186deb
fix(apps-engine): IUser used wrong federation type definition (#41304)
d-gubert Jul 10, 2026
ee8e048
fix(apps-engine): tighten types for TS7 (exception, uikit responder) …
ggazzo Jul 10, 2026
8cf05af
chore(ui-voip): Widget stories broken due to initial body height of `…
gabriellsh Jul 10, 2026
eec6083
fix(message-parser): trailing backtick before line end breaks code bl…
ggazzo Jul 10, 2026
1637a8b
fix: Prevent app remount when VoIP license/permission changes (#41200)
dougfabris Jul 10, 2026
582d25d
chore: remove unused model query methods (#41227)
KevLehman Jul 10, 2026
23bdbad
fix: DST verifier unlinking all departments from custom business hour…
KevLehman Jul 11, 2026
719e3db
fix: LDAP users not merging by email during sync (#41279)
abhinavkrin Jul 11, 2026
edbaeef
fix: Setup wizard forced back into registration on upgrade when Show_…
KevLehman Jul 11, 2026
ed594fd
fix(a11y): add keyboard support in room members list (#41122)
juliajforesti Jul 13, 2026
d9fca72
test: fix flaky timeout in preview-public-channel spec (#41319)
KevLehman Jul 13, 2026
dd4023e
regression: fix issues rendering some existing emojis (#41305)
MartinSchoeler Jul 13, 2026
b9b2228
refactor(authorization): accept IUser in hasPermissionAsync wrappers …
ggazzo Jul 13, 2026
8ed0fa0
fix: server crash when re-enabling push notifications (#41341)
KevLehman Jul 13, 2026
73c3aec
chore: migrate batch4 client DDP callers + add 6 REST endpoints (#40728)
ggazzo Jul 13, 2026
01202cc
test: fix race in uikit-interactions e2e by awaiting interaction resp…
KevLehman Jul 13, 2026
460858e
fix: engagement dashboard fill (#41207)
sampaiodiego Jul 13, 2026
9690412
chore: reorganize backend folder structure — Phase 6 (lib, hooks, fea…
sampaiodiego Jul 14, 2026
c4bede4
refactor(authorization): accept a minimal user shape (UserWithRoles) …
ggazzo Jul 14, 2026
b634242
test: fix flaky omnichannel status toggle assertion in navbar page ob…
KevLehman Jul 14, 2026
a60e261
chore(authorization): bound roles-cache key to user id, skip cache wh…
ggazzo Jul 14, 2026
0faaaeb
test: fix strict mode violation flake in OC manual selection queue te…
KevLehman Jul 14, 2026
001902a
chore(api): migrate audit/chat/ldap/engagement single-route endpoints…
devin-ai-integration[bot] Jul 14, 2026
9860e02
chore(api): migrate engagement dashboard messages/users endpoints to …
devin-ai-integration[bot] Jul 14, 2026
d371c06
chore: bump fuselage packages (#41354)
ricardogarim Jul 14, 2026
4b34bd6
fix: import Slack files as attachments instead of raw URLs (#41285)
ricardogarim Jul 15, 2026
3598e2d
chore: upgrade xml-crypto to v6 (#41379)
abhinavkrin Jul 15, 2026
71d4d82
fix: server crash when LDAP search filter is invalid (#41373)
KevLehman Jul 15, 2026
1b7f9f2
test: stabilize flaky E2E message and navigation flows (#41114)
jessicaschelly Jul 15, 2026
012dd32
regression: Prevent saving license with non-plausible value (#41306)
dougfabris Jul 15, 2026
0e7b205
chore: reorganize backend folder structure — Phase 7 (omnichannel and…
sampaiodiego Jul 15, 2026
9db6a29
test: update stale proxyquire mock paths breaking unit test CI (#41403)
KevLehman Jul 15, 2026
bfacbd3
chore: Permissions translations in title case (#41380)
yash-rajpal Jul 15, 2026
7720156
chore(eslint): Replace eslint-plugin-import with eslint-plugin-import…
tassoevan Jul 16, 2026
cc63c0f
test: Remove virtual flag from CodeMirror spec mocks to fix flaky sui…
tassoevan Jul 16, 2026
8bbd1c6
refactor(api): pass this.user to permission checks in REST endpoints …
ggazzo Jul 16, 2026
cff23f9
fix: Disable composer actions without subscription to channel (#41202)
yash-rajpal Jul 16, 2026
ae72939
refactor(authorization): forward only { _id, roles } from hasPermissi…
ggazzo Jul 16, 2026
abab8a0
refactor: replace Fuselage styling prop shorthands with full prop nam…
tassoevan Jul 16, 2026
2ec4d29
fix(apps): write Deno runtime config to temp directory (#41338)
AlgoArtist06 Jul 16, 2026
f96b66d
docs: Add frontend guidelines (#41423)
tassoevan Jul 16, 2026
4b57346
feat: (poc) Unified AI Search (#40890)
Dnouv Jul 16, 2026
0e20907
chore: auto detect screen share based on video direction (#41366)
pierre-lehnen-rc Jul 16, 2026
ec7b1be
fix: dates showing one day earlier for users in negative UTC-offset (…
nazabucciarelli Jul 16, 2026
ffe1b64
fix: race condition in E2EE rooms creation causing 'incorrect encrypt…
nazabucciarelli Jul 16, 2026
81458c0
refactor: replace Fuselage styling prop shorthands with full prop nam…
ricardogarim Jul 17, 2026
14d0718
chore: refactor apps converters to TypeScript with Zod codecs (1/2) (…
d-gubert Jul 17, 2026
65a366e
feat: show relative time in Omnichannel Contact Center date columns (…
abhinavkrin Jul 17, 2026
74f50d1
feat(federation): Add XMPP bridge support (#40758)
sampaiodiego Jul 17, 2026
6d2c9f1
chore: remove unused @rocket.chat/log-format package (#41426)
tassoevan Jul 17, 2026
fce0bc7
chore: avoid fetching data just for counting (#41313)
sampaiodiego Jul 17, 2026
e8697f3
chore(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#41011)
dependabot[bot] Jul 17, 2026
d75d98b
chore(deps): bump docker/login-action from 4.1.0 to 4.2.0 (#40670)
dependabot[bot] Jul 17, 2026
c582421
chore(deps): bump github/codeql-action from 4.35.5 to 4.36.2 (#40831)
dependabot[bot] Jul 17, 2026
8975214
chore(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 (#40841)
dependabot[bot] Jul 17, 2026
f8d6b46
chore(deps): bump github/codeql-action/autobuild from 4.36.2 to 4.37.…
dependabot[bot] Jul 17, 2026
1bf84cb
feat: validate password policy length on settings save (#41173)
ricardogarim Jul 17, 2026
74d6cac
feat: no egress for offline licenses (#41148)
cardoso Jul 17, 2026
a3afae7
ci(codeql): align codeql-action steps to v4.37.1 (#41456)
ggazzo Jul 17, 2026
1629d33
chore: Align `react-stately` slim barrel patches for submenu support …
dougfabris Jul 17, 2026
aeb7467
chore(deps): bump websocket-driver (#41427)
yasnagat Jul 17, 2026
adc1570
regression: combined emojis displayed as separate emojis and some fla…
abhinavkrin Jul 17, 2026
13ea804
chore: bump fuselage packages (#41430)
ricardogarim Jul 17, 2026
f6c5579
fix: Restore Away to quick status menu (#41414)
ricardogarim Jul 17, 2026
c103cf5
chore: make screen share not rely on bundles from previous negotiatio…
pierre-lehnen-rc Jul 17, 2026
6a94ee4
ci: speed up merge queue runs (#41368)
KevLehman Jul 18, 2026
302f0c4
chore: add dom lib for WebRTC/DOM globals (TS7 compat) (#41262)
ggazzo Jul 18, 2026
7619669
ci: fix dynamic-import response truncation flake (proxy transport rac…
KevLehman Jul 18, 2026
6041285
fix: pagination and projection options silently ignored by model quer…
KevLehman Jul 17, 2026
b7bf284
chore: TS7 low-risk type fixes (assertions, casts) (#41264)
ggazzo Jul 18, 2026
34aa635
chore: Ensure page always reloads when app is crashes (#41453)
yash-rajpal Jul 17, 2026
7a360be
fix: prevent AI navbar search crashes and restore clear action (#41434)
Dnouv Jul 18, 2026
297df1a
fix(apps): resolve deno-runtime module not found after upgrade (#40947)
dsaicharan072-cmyk Jul 19, 2026
6ebabce
fix: newer license in env not applied (#41472)
cardoso Jul 20, 2026
82ae946
chore: use @rocket.chat/cron for presence status expiration in micros…
ricardogarim Jul 20, 2026
3240cdb
refactor(authorization): pass IUser to permission checks where alread…
ggazzo Jul 20, 2026
f2fc52d
chore: Switch AI Search feature as opt-in (#41464)
tassoevan Jul 20, 2026
0b5e592
refactor(gazzodown,livechat): Problematic import (#41463)
tassoevan Jul 20, 2026
0a1baf2
chore: remove duplicated emoji css (#41425)
ricardogarim Jul 20, 2026
b0ecca0
ci: skip redundant test re-run on develop push after merge queue (#41…
ggazzo Jul 20, 2026
8d8cd01
feat: FIPS 140-3 Compliant Docker Images (#39324)
cardoso Jul 20, 2026
a93d6da
ci: Update DockerHub login condition for queue type
ggazzo Jul 20, 2026
dddc5bd
chore(deps): bump adm-zip (#41476)
julio-rocketchat Jul 20, 2026
1d60700
chore(deps): bump dependencies with medium and low-severity CVEs (#41…
julio-rocketchat Jul 20, 2026
8d4507d
fix: missing "user left" system message after omnichannel room forwar…
KevLehman Jul 20, 2026
ea70952
ci: publish fips images as tags to dockerhub (#41486)
sampaiodiego Jul 20, 2026
4a4c297
chore(deps): bump GitHub Actions dependencies (#41485)
ggazzo Jul 20, 2026
6a8b36b
chore: correct Phishing-Resistant MFA changeset to minor bump (#41492)
ricardogarim Jul 21, 2026
ea64e17
Release 8.7.0-rc.0
rocketchat-github-ci Jul 21, 2026
5a11882
regression: fix verify email endpoint (#41491)
sampaiodiego Jul 22, 2026
4c6cdfe
chore(deps): bump axios, brace-expansion, shell-quote, and tar deps (…
yasnagat Jul 22, 2026
2a16c57
regression: ASCII emoticons not converted to emojis by the native emo…
KevLehman Jul 22, 2026
c774ae1
regression: skin-toned emoji not enlarged when sent alone (#41515)
ricardogarim Jul 22, 2026
68758b1
regression: tooltips not reappearing on subsequent hovers (#41428)
abhinavkrin Jul 22, 2026
915ca08
regression: native emojis bottom-aligned in messages (#41527)
ricardogarim Jul 23, 2026
1e2f96a
regression(api): implement missing im.leave, dm.leave and dm.blockUse…
ggazzo Jul 23, 2026
126f056
Merge remote-tracking branch 'origin/master' into release-8.7.0
ggazzo Jul 23, 2026
4d59332
Release 8.7.0-rc.1
rocketchat-github-ci Jul 23, 2026
8116c62
Release 8.7.0-rc.2
rocketchat-github-ci Jul 23, 2026
3c0f20c
regression: markdown links break when their URL contains an emoji sho…
cardoso Jul 23, 2026
150916a
regression: emoji avatars overlap message content and render undersiz…
abhinavkrin Jul 23, 2026
d81ca08
regression: Prevent inherited properties from being treated as emoji …
yash-rajpal Jul 23, 2026
76d8910
regression: device logout showing success feedback when request fails…
KevLehman Jul 23, 2026
a0134b9
regression: quick-reaction emojis rendered larger on message toolbar …
KevLehman Jul 23, 2026
ae0b8fb
regression: missing emojis in picker search (#41342)
MartinSchoeler Jul 24, 2026
c8b080b
regression: custom OAuth client secret logged in plaintext at debug l…
KevLehman Jul 24, 2026
2a8ace0
regression: auto away not triggering in the web client (#41549)
ricardogarim Jul 24, 2026
fcf244e
regression: native emoji rendered as corrupted characters in omnichan…
KevLehman Jul 24, 2026
e8db099
regression: video embedded in custom homepage content repeatedly relo…
ricardogarim Jul 27, 2026
d59ea47
regression: canned response emojis appear as shortcodes to livechat v…
nazabucciarelli Jul 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
8 changes: 8 additions & 0 deletions .changeset/all-baths-cry.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/model-typings': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/models': minor
'@rocket.chat/meteor': minor
---

Adds `current` field to `DeviceManagementSession` type and `currentLoginToken` parameter to `aggregateSessionsByUserId`, allowing the sessions endpoint to identify and flag the caller's active session.
8 changes: 8 additions & 0 deletions .changeset/atomic-model-operations.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/core-typings': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/models': patch
---

Fixes race conditions in several check-then-write database flows by collapsing them into single atomic operations: CAS login tokens can no longer be consumed by two concurrent logins, revoking a room invite no longer emits duplicate removal notifications, and deleting an integration now enforces the creator-only permission scope in the delete itself
5 changes: 5 additions & 0 deletions .changeset/block-fallback-rendering.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/gazzodown": patch
---

Degrades blocks without a dedicated renderer to their raw markup instead of dropping them. When a block carries a `fallback` `[start, end]` offset span, `Markup`/`PreviewMarkup` slice the original message source (passed via the new optional `source` prop) and render that text. This avoids duplicating the markup into the AST while keeping unsupported blocks visible.
5 changes: 5 additions & 0 deletions .changeset/breezy-moons-search.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes own account showing twice in navbar room search when searching by username
32 changes: 32 additions & 0 deletions .changeset/breezy-parts-kiss.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
'@rocket.chat/web-ui-registration': minor
'@rocket.chat/model-typings': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/passport-x': minor
'@rocket.chat/desktop-api': minor
'@rocket.chat/models': minor
'@rocket.chat/i18n': minor
'@rocket.chat/meteor': minor
---

## Phishing-Resistant Multi-Factor Authentication

Introduces a more secure and reliable server-side OAuth authentication flow.

### What’s New

- **Improved OAuth login security**
OAuth authentication now happens fully on the server, reducing the risk of token theft, phishing attacks, and client-side credential interception.

- **Built-in CSRF, state validation, and PKCE protection**
OAuth logins now include stronger protection against CSRF attacks, request tampering, and authorization code interception through secure state validation and PKCE support.

- **Improved two-step verification with OAuth logins**
Users with email or TOTP two-factor authentication enabled will now be asked to complete 2FA even when signing in with providers like Google, GitHub, GitLab, and others.

- **Improved mobile & desktop app login**
Mobile and desktop apps now support a smoother and more secure deep-link OAuth login flow.

- **A new setting to enable/disable new OAuth Flow**
Enable this new setting `Accounts_OAuth_Use_Modern_Flow` to use all of the above mentioned features.
5 changes: 5 additions & 0 deletions .changeset/bump-patch-1784768845125.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Bump @rocket.chat/meteor version.
5 changes: 5 additions & 0 deletions .changeset/bump-patch-1784771780188.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Bump @rocket.chat/meteor version.
5 changes: 5 additions & 0 deletions .changeset/code-fence-trailing-backtick.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/message-parser": patch
---

Fixes code fences failing to render when a line inside them ends with an inline-code backtick (e.g. `` - **Node**: `22.22.3` ``). A trailing backtick immediately before a line break could not be consumed as content, causing the whole ```` ``` ```` block to fall back to markdown parsing and split apart. Trailing 1-2 backticks before a line end (or EOF) are now treated as code content.
7 changes: 7 additions & 0 deletions .changeset/deep-ways-poke.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/core-typings': patch
'@rocket.chat/models': patch
'@rocket.chat/meteor': patch
---

Fixes the Slack importer storing shared files as raw URLs in the message body. Imported file messages now stay hidden until "Download Pending Files" button fetches them, then display as native attachments with image previews. Failed downloads (e.g. invalidated export links) are no longer silently saved as the file's content — they are counted as errors and can be retried.
6 changes: 6 additions & 0 deletions .changeset/desktop-set-user-roles.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/desktop-api': minor
'@rocket.chat/meteor': patch
---

Added a `setUserRoles` bridge method to the desktop API and pushed the logged-in user's roles to the desktop app. This lets the desktop client restrict supportedVersions messages (such as version-expiration warnings) to specific roles like admins, instead of showing them to every user. The push is reactive to role changes; desktop builds without the bridge method fall back to their own role lookup.
5 changes: 5 additions & 0 deletions .changeset/emoji-zwj-tag-sequences.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/message-parser': patch
---

Fixes an issue in which some combined emojis like 😶‍🌫️, 😮‍💨 and 😵‍💫 were being displayed as two separate emojis, and the flags of some countries like England 🏴󠁧󠁢󠁥󠁮󠁧󠁿, Scotland 🏴󠁧󠁢󠁳󠁣󠁴󠁿 and Wales 🏴󠁧󠁢󠁷󠁬󠁳󠁿 were being displayed as a plain black flag
5 changes: 5 additions & 0 deletions .changeset/empty-boxes-cross.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes engagement dashboard loading unnecessary data into memory on startup
6 changes: 6 additions & 0 deletions .changeset/empty-garlics-reply.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/core-typings': patch
'@rocket.chat/meteor': patch
---

Fixes the password policy allowing a maximum length lower than the minimum length to be saved — a combination that made it impossible to set any valid password. The server now rejects such configurations when password policy settings are saved and shows an error explaining the constraint.
5 changes: 5 additions & 0 deletions .changeset/fancy-days-knock.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
10 changes: 10 additions & 0 deletions .changeset/fancy-deserts-mate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
'@rocket.chat/core-services': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/ai-search': minor
'@rocket.chat/ui-client': minor
'@rocket.chat/i18n': minor
'@rocket.chat/meteor': minor
---

Adds AI Search with semantic message results, optional OpenAI-compatible answers, and AI Center configuration.
7 changes: 7 additions & 0 deletions .changeset/fifty-candies-heal.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/meteor': patch
---

fix: Buttons from emoji picker misbehaving on clicks

An infinite render loop was preventing proper behavior when clicking on the emoji picker buttons. It was fixed by removing the unnecessary state update that was causing the loop and replacing multiple fires of the same mouseover event (when a mouseenter event was the right one to use). There is a chance this pre-existing bug was hidden by React 18's event delegation.
13 changes: 13 additions & 0 deletions .changeset/fips-mode-support.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/core-typings': minor
'@rocket.chat/federation-matrix': minor
'@rocket.chat/account-service': minor
'@rocket.chat/authorization-service': minor
'@rocket.chat/ddp-streamer': minor
'@rocket.chat/omnichannel-transcript': minor
'@rocket.chat/presence-service': minor
'@rocket.chat/queue-worker': minor
---

Adds support for running Rocket.Chat in FIPS mode. The monolith and all microservices (ddp-streamer, account-service, authorization-service, presence-service, queue-worker, omnichannel-transcript) can now enforce FIPS-compliant cryptography via Node.js/OpenSSL FIPS, with dedicated FIPS Docker images. Running in FIPS mode requires a license including the new `fips` module, and FIPS status is now reported in server logs and statistics.
5 changes: 5 additions & 0 deletions .changeset/fix-business-hour-agents-availability.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes agents' business-hour availability not being updated when they are removed from a department linked to a business hour while multiple business hours are enabled. The recomputation step always failed, leaving removed agents available (or unavailable) according to a business hour that no longer applied to them — and, on deployments running with `EXIT_UNHANDLEDPROMISEREJECTION` (or in development/test mode), the unhandled rejection crashed the server process.
7 changes: 7 additions & 0 deletions .changeset/fix-business-hour-dst-department-unlink.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/meteor': patch
---

Fixes multiple business hours losing their linked departments after a daylight saving time change or a server restart. The automatic timezone adjustment re-saved business hours without their department associations, causing business hours configured with timezones to silently stop applying to agents.

Also fixes agents keeping a business hour's availability after their department was removed from it: saving a business hour with a smaller department list unlinked the departments but never cleared the business hour from the removed departments' agents.
5 changes: 5 additions & 0 deletions .changeset/fix-deno-runtime-symlink.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/apps': patch
---

Fixes an issue that would cause apps to fail with 'Module not found' errors in some cases
6 changes: 6 additions & 0 deletions .changeset/fix-license-env-precedence.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/license': patch
---

Fixes the license provided via the `ROCKETCHAT_LICENSE` environment variable not being applied when it is newer than the one persisted in the workspace.
5 changes: 5 additions & 0 deletions .changeset/forty-stars-bathe.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes error message being shown when logging out current device via Device Management despite successful logout.
7 changes: 7 additions & 0 deletions .changeset/four-tigers-clap.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/models': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/meteor': patch
---

Fixes a race condition that left messages permanently undecryptable ("incorrect encryption key") in rooms created with encryption enabled. When several members opened such a room at the same time, each client could independently generate and distribute a different group key. Establishing the room key is now atomic (first-write-wins) on the server, and a client that loses the race discards its locally generated key and adopts the established one instead of encrypting with a divergent key.
6 changes: 6 additions & 0 deletions .changeset/fruity-items-fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/apps': minor
'@rocket.chat/meteor': minor
---

Adds an alternative runtime runner for apps. It can be enabled via environment variable `APPS_ENGINE_RUNTIME_BACKEND='node'`
8 changes: 8 additions & 0 deletions .changeset/gentle-cats-change.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
'@rocket.chat/meteor': patch
'@rocket.chat/core-typings': patch
'@rocket.chat/model-typings': patch
'@rocket.chat/models': patch
---

Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
6 changes: 6 additions & 0 deletions .changeset/json-setting-validation-feedback.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@rocket.chat/meteor": minor
"@rocket.chat/i18n": minor
---

Adds inline JSON validation feedback to admin settings that hold JSON (`code: application/json`), showing an error in the editor and blocking save while the value is malformed
5 changes: 5 additions & 0 deletions .changeset/ldap-channel-sync-removal-abort.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes LDAP channel sync aborting the entire add/removal pass when a mapped channel could not be resolved, which prevented users from being removed from channels when "Auto Remove Users from Channels" was enabled.
6 changes: 6 additions & 0 deletions .changeset/ldap-merge-email-lookup.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/models': patch
'@rocket.chat/meteor': patch
---

Fixes LDAP sync failing to merge an existing user matched by email, which caused a `Username already exists` error when the user's username differed from the directory.
5 changes: 5 additions & 0 deletions .changeset/ldap-sync-crash-invalid-filter.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes the server crashing during LDAP login or sync when the configured search settings produce an invalid LDAP filter (for example, an empty User Search Field). The operation now fails gracefully with a logged error instead of terminating the process.
7 changes: 7 additions & 0 deletions .changeset/license-validate-preview.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@rocket.chat/license': minor
'@rocket.chat/rest-typings': minor
'@rocket.chat/meteor': minor
---

Adds a new `licenses.validate` REST endpoint that validates a Rocket.Chat license (V2 or V3 JWT) against the current workspace without applying it, so a license can be previewed before it is applied from the UI. A valid license responds with success; an invalid one responds with the validation behaviors that rejected it.
5 changes: 5 additions & 0 deletions .changeset/light-geckos-start.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Disables more actions on message composer during public channel preview.
5 changes: 5 additions & 0 deletions .changeset/livechat-forward-ul-message.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes an issue where the "user left" system message could be added to an Omnichannel conversation only after the forwarding process had already finished, causing it to appear out of order in the conversation history
5 changes: 5 additions & 0 deletions .changeset/message-content-body-source.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": patch
---

Passes the original message text to the message renderer so blocks without a dedicated renderer (e.g. tables on clients that don't render them yet) can degrade to their raw markup via the parser's `fallback` source offsets, instead of disappearing.
5 changes: 5 additions & 0 deletions .changeset/moody-eggs-juggle.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Fixes an issue where the cursor jumped to the wrong position after inserting a mention at the start or middle of a message.
5 changes: 5 additions & 0 deletions .changeset/nice-fans-cover.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": minor
---

Replaces proprietary emojis with native (unicode) emojis and increases available emoji set
6 changes: 6 additions & 0 deletions .changeset/offline-license-no-egress.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/license': minor
---

Adds support for the `offline` license flag, suppressing every outbound connection to Rocket.Chat Cloud services and the Push Gateway at its source, so air-gapped workspaces never initiate calls that would violate their security compliance.
6 changes: 6 additions & 0 deletions .changeset/old-bats-sniff.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/apps-engine': patch
'@rocket.chat/meteor': patch
---

Fixes wrong FederationLookup type assigned to IUser in apps. The correct data is there, but the type does not represent it.
5 changes: 5 additions & 0 deletions .changeset/olive-nails-fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Enables keyboard activation for Display menu radio buttons and checkboxes
5 changes: 5 additions & 0 deletions .changeset/omnichannel-contact-center-date-relative-time.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@rocket.chat/meteor': patch
---

Changes the date columns in the Omnichannel Contact Center to show both the formatted date and the relative time: the **Last Chat** column in the contacts list, and the **Started at** and **Last Message** columns in the chats list
6 changes: 6 additions & 0 deletions .changeset/parser-horizontal-rule.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@rocket.chat/message-parser": minor
"@rocket.chat/gazzodown": minor
---

Adds support for horizontal rules (thematic breaks) in the message parser. A line of 3 or more contiguous dashes (`---`, with nothing else on the line) is parsed into a new `HORIZONTAL_RULE` block node and rendered with Fuselage's `Divider`. The node carries an optional `fallback` — a `[start, end]` offset span into the original source — so renderers without horizontal-rule support can slice the source to show the raw markup instead of dropping it, without duplicating the text into the AST. Only `-` is accepted: CommonMark also allows `*` and `_`, but those collide with emphasis and with censored words (bad-words masks a term as a run of `*`), so a bare `***` / `_______` line stays text/emphasis instead of becoming a divider.
6 changes: 6 additions & 0 deletions .changeset/persistent-audio-player.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@rocket.chat/meteor': minor
'@rocket.chat/i18n': minor
---

Added a persistent audio player. Playing an audio attachment now continues across room navigation: the audio keeps playing when you switch or close the conversation, and a "Now playing" card appears at the top of the sidebar with play/pause, seek, playback speed (1x/1.5x/2x), and a shortcut back to the originating conversation.
Loading
Loading