Quentin Gliech
ff8cb9e52c
build(deps): bump docker/login-action from 3.6.0 to 3.7.0 ( #5457 )
2026-02-04 17:03:10 +01:00
Quentin Gliech
5c7bbb9b1f
build(deps): bump actions/setup-node from 6.1.0 to 6.2.0 ( #5420 )
2026-02-04 16:50:47 +01:00
Quentin Gliech
f13b0914b4
build(deps-dev): bump @graphql-codegen/cli from 6.1.0 to 6.1.1 in /frontend in the graphql-codegen group ( #5429 )
2026-02-04 16:50:38 +01:00
Quentin Gliech
048291a3e5
build(deps): bump peter-evans/create-pull-request from 8.0.0 to 8.1.0 ( #5442 )
2026-02-04 16:50:29 +01:00
Quentin Gliech
09ac97253a
build(deps-dev): bump the vitest group in /frontend with 2 updates ( #5428 )
2026-02-04 16:50:06 +01:00
dependabot[bot]
0e3dc0396f
build(deps-dev): bump the vitest group in /frontend with 2 updates
...
Bumps the vitest group in /frontend with 2 updates: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8 ) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ).
Updates `@vitest/coverage-v8` from 4.0.16 to 4.0.17
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.17/packages/coverage-v8 )
Updates `vitest` from 4.0.16 to 4.0.17
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.17/packages/vitest )
---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
dependency-version: 4.0.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: vitest
- dependency-name: vitest
dependency-version: 4.0.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: vitest
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-04 13:54:39 +00:00
dependabot[bot]
04bc6cf5db
build(deps-dev): bump @graphql-codegen/cli
...
Bumps the graphql-codegen group in /frontend with 1 update: [@graphql-codegen/cli](https://github.com/dotansimha/graphql-code-generator/tree/HEAD/packages/graphql-codegen-cli ).
Updates `@graphql-codegen/cli` from 6.1.0 to 6.1.1
- [Release notes](https://github.com/dotansimha/graphql-code-generator/releases )
- [Changelog](https://github.com/dotansimha/graphql-code-generator/blob/master/packages/graphql-codegen-cli/CHANGELOG.md )
- [Commits](https://github.com/dotansimha/graphql-code-generator/commits/@graphql-codegen/cli@6.1.1/packages/graphql-codegen-cli )
---
updated-dependencies:
- dependency-name: "@graphql-codegen/cli"
dependency-version: 6.1.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: graphql-codegen
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-04 13:54:23 +00:00
Quentin Gliech
db7c4c3506
build(deps): bump lodash from 4.17.21 to 4.17.23 in /frontend ( #5445 )
2026-02-04 14:35:46 +01:00
matrixbot
a2981145cc
Automatic merge back to main ( #5463 )
2026-02-03 23:22:52 +01:00
github-actions[bot]
f92d3eb7ff
1.11.0-rc.0
v1.11.0-rc.0
2026-02-03 22:15:50 +00:00
matrixbot
803ed0a01a
Translations updates for main ( #5462 )
2026-02-03 23:15:02 +01:00
github-actions[bot]
07068143ef
Translations updates
2026-02-03 18:03:02 +00:00
Devon Hudson
c0b3bbdd8b
Update bytes version ( #5461 )
2026-02-03 18:02:33 +00:00
Devon Hudson
a8b6cc7479
Update bytes version
2026-02-03 10:23:51 -07:00
Quentin Gliech
24249811b4
Add syn2mas flag to ignore missing auth providers ( #5451 )
2026-01-29 11:23:17 +01:00
dependabot[bot]
028db8808d
build(deps): bump docker/login-action from 3.6.0 to 3.7.0
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 3.6.0 to 3.7.0.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/v3.6.0...v3.7.0 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: 3.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-28 13:54:26 +00:00
Quentin Gliech
26baa39cbf
Bump opa-wasm and wasmtime ( #5455 )
2026-01-27 21:06:08 +01:00
Devon Hudson
172b4831d8
Merge branch 'main' into devon/wasmtime-update
2026-01-27 18:46:11 +00:00
Devon Hudson
1cc05d0b0c
Automatic merge back to main ( #5454 )
2026-01-27 18:46:03 +00:00
Devon Hudson
7cbc010437
Bump opa-wasm and wasmtime
2026-01-27 11:36:49 -07:00
github-actions[bot]
9eeb870c14
1.10.0
v1.10.0
2026-01-27 16:15:51 +00:00
Devon Hudson
ac6e97e195
Translations updates for v1.10 ( #5453 )
2026-01-27 16:10:42 +00:00
github-actions[bot]
aa241a9994
Translations updates
2026-01-27 15:53:13 +00:00
Jason Robinson
6a786dccbc
Add syn2mas flag to ignore missing auth providers
...
Currently `syn2mas` will always error in the Synapse checks phase if it finds auth providers in the `user_external_ids` database table, that are not configured in Synapse config. While normally this the right thing to do, we may have situations where we know what we're doing, and want to ignore invalid looking data in the external identifiers table. If the flag is given, ignore errors and output them as warnings instead.
2026-01-26 14:57:31 +02:00
Quentin Gliech
378f24b118
Clear out last active IP on each sessions after 30 days ( #5448 )
2026-01-26 13:57:01 +01:00
Quentin Gliech
dbdb2970ed
Refactor inactive IP cleanup to use pagination
...
This should avoid dead many dead tuples when processing batches of
sessions to cleanup
2026-01-23 18:52:33 +01:00
Quentin Gliech
b0e836eb44
Cleanup finished user/browser sessions ( #5444 )
2026-01-23 18:27:45 +01:00
Quentin Gliech
40cb5b0094
Cleanup finished OAuth 2.0 sessions ( #5443 )
2026-01-23 18:23:55 +01:00
Quentin Gliech
f842f33a66
Re-enable the upstream authentication sessions cleanup job ( #5439 )
2026-01-23 18:17:11 +01:00
Quentin Gliech
8e6061bf04
Developer documentation about the various cleanup jobs ( #5447 )
2026-01-23 18:16:11 +01:00
Quentin Gliech
af81a6cf78
Clean up leftovers in the database schema, part 2 ( #5408 )
2026-01-23 18:13:29 +01:00
Quentin Gliech and Olivier 'reivilibre'
2d929278c1
Minor reword in the cleanup jobs documentation
...
Co-authored-by: Olivier 'reivilibre' <oliverw@element.io >
2026-01-23 17:43:13 +01:00
Quentin Gliech
69f324e4e8
Clean up unsupported threepids from already deactivated users ( #5407 )
2026-01-23 17:42:46 +01:00
Quentin Gliech
bcdaae7103
Add cleanup jobs developer documentation
2026-01-23 16:37:52 +01:00
Quentin Gliech
5abc7f3f69
Include pagination params in the tracing fields of cleanup methods
2026-01-23 16:30:26 +01:00
Quentin Gliech
26caee7c99
Add cleanup jobs for inactive session IP addresses
...
This adds three new scheduled cleanup jobs that clear the last_active_ip
field from sessions that have been inactive for more than 30 days:
- CleanupInactiveOAuth2SessionIpsJob
- CleanupInactiveCompatSessionIpsJob
- CleanupInactiveUserSessionIpsJob
This helps with data minimization by not retaining IP addresses longer
2026-01-23 16:29:29 +01:00
dependabot[bot]
868d6cdc21
build(deps): bump lodash from 4.17.21 to 4.17.23 in /frontend
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.17.23
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-23 09:56:39 +00:00
Quentin Gliech
5bca9726b6
Add cleanup job for finished user sessions
...
Implements hard deletion of user/browser sessions that have been finished for more than 30 days, but only after all child sessions are cleaned up.
User sessions can only be deleted when no child sessions exist, ensuring backchannel logout propagation continues to work correctly.
2026-01-22 15:44:57 +01:00
Quentin Gliech
700007dbfd
Fix FK constraint to preserve backchannel logout chain
...
Change compat_sessions.user_session_id FK from ON DELETE SET NULL to ON DELETE NO ACTION. This prevents deletion of user_sessions while compat_sessions still reference them, which is critical for backchannel logout propagation.
When an upstream IdP sends a backchannel logout, MAS must trace through:
upstream_oauth_authorization_sessions -> user_sessions -> compat_sessions
If user_session_id links are SET NULL, logout propagation fails.
Uses two-step migration (DROP+ADD NOT VALID, then VALIDATE) to minimize table locking during deployment.
2026-01-22 15:44:57 +01:00
Quentin Gliech
a66d652a70
Add cleanup job for finished OAuth2 sessions
...
Implements hard deletion of OAuth2 sessions that have been finished for more than 30 days, including their associated access and refresh tokens.
2026-01-22 15:44:56 +01:00
dependabot[bot]
4cdf275c73
build(deps): bump peter-evans/create-pull-request from 8.0.0 to 8.1.0
...
Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request ) from 8.0.0 to 8.1.0.
- [Release notes](https://github.com/peter-evans/create-pull-request/releases )
- [Commits](https://github.com/peter-evans/create-pull-request/compare/v8.0.0...v8.1.0 )
---
updated-dependencies:
- dependency-name: peter-evans/create-pull-request
dependency-version: 8.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-22 13:54:16 +00:00
matrixbot
ebcefc6ab5
Automatic merge back to main ( #5441 )
2026-01-21 16:04:19 +01:00
github-actions[bot]
a7ca1d477b
1.10.0-rc.0
v1.10.0-rc.0
2026-01-21 14:56:30 +00:00
Quentin Gliech
c4c001bbd5
Translations updates for main ( #5440 )
2026-01-21 15:55:30 +01:00
github-actions[bot]
b089c35aa8
Translations updates
2026-01-21 14:45:17 +00:00
Quentin Gliech
c29c4c3a5e
Re-enable upstream OAuth session cleanup job
...
It should be safe to run now
2026-01-21 14:50:03 +01:00
Quentin Gliech
0486c6e05d
Use the user_session_id on upstream authorisations for filtering instead
...
of authentications
This makes it one less table to read
2026-01-21 14:49:07 +01:00
Quentin Gliech
c4c85978fe
Add trigger and backfill for upstream OAuth user session tracking
...
Introduce a new trigger and a backfill migration to populate the
`user_session_id` column in `upstream_oauth_authorization_sessions`
based on `user_session_authentications`. This ensures historical data is
consistent and aids in backward compatibility.
2026-01-21 14:49:07 +01:00
Quentin Gliech
3834cbc105
Add index on the user_session_id foreign key for upstream auth sessions
2026-01-21 14:49:07 +01:00
Quentin Gliech
da164a8c43
Do not cleanup upstream OAuth sessions that may still be useful ( #5437 )
2026-01-21 13:20:38 +01:00