dependabot[bot]
1cb352847a
build(deps): bump moment in /backend in the prod-minor-updates group
...
Bumps the prod-minor-updates group in /backend with 1 update: [moment](https://github.com/moment/moment ).
Updates `moment` from 2.30.1 to 2.31.0
- [Release notes](https://github.com/moment/moment/releases )
- [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md )
- [Commits](https://github.com/moment/moment/compare/2.30.1...2.31.0 )
---
updated-dependencies:
- dependency-name: moment
dependency-version: 2.31.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-21 13:04:26 +00:00
jc21
9ad799c13f
Merge pull request #5869 from zalaghi/feat/persian-locale
...
Add Persian locale
2026-09-21 07:25:22 +10:00
jc21
5d0be3a5d5
Merge pull request #5871 from qwist1233-cpu/tr-missing
...
Add missing Turkish (tr) translations
2026-09-21 07:20:43 +10:00
qwist1233-cpu and Claude Fable 5.1
735149210e
Add missing Turkish (tr) translations
...
Adds the 31 keys present in en.json but missing from tr.json (2FA, certificate key type, trust forwarded proto).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com >
2026-09-20 11:05:01 +03:00
Amir Zalaghi
0e152e8afe
Add Persian locale
2026-09-18 22:12:13 +02:00
jc21
568c105945
Merge pull request #5858 from NginxProxyManager/dependabot/npm_and_yarn/backend/prod-patch-updates-14e248b7a3
...
Bump the prod-patch-updates group across 1 directory with 3 updates
2026-09-15 07:35:48 +10:00
jc21
3105a23834
Merge pull request #5861 from NginxProxyManager/dependabot/npm_and_yarn/frontend/prod-minor-updates-2b7ce5bc75
...
Bump the prod-minor-updates group across 1 directory with 6 updates
2026-09-15 07:35:21 +10:00
dependabot[bot]
803f4968a2
Bump the prod-minor-updates group across 1 directory with 6 updates
...
Bumps the prod-minor-updates group with 6 updates in the /frontend directory:
| Package | From | To |
| --- | --- | --- |
| [@tabler/core](https://github.com/tabler/tabler ) | `1.4.0` | `1.5.1` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.101.4` | `5.102.8` |
| [@tanstack/react-table](https://github.com/TanStack/table/tree/HEAD/packages/react-table ) | `9.1.2` | `9.2.4` |
| [react](https://github.com/react/react/tree/HEAD/packages/react ) | `19.2.8` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom ) | `19.2.8` | `19.3.0` |
| [react-intl](https://github.com/formatjs/formatjs ) | `10.1.22` | `10.2.0` |
Updates `@tabler/core` from 1.4.0 to 1.5.1
- [Release notes](https://github.com/tabler/tabler/releases )
- [Changelog](https://github.com/tabler/tabler/blob/dev/docs/CHANGELOG.md )
- [Commits](https://github.com/tabler/tabler/compare/@tabler/core@1.4.0...@tabler/core@1.5.1 )
Updates `@tanstack/react-query` from 5.101.4 to 5.102.8
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.102.8/packages/react-query )
Updates `@tanstack/react-table` from 9.1.2 to 9.2.4
- [Release notes](https://github.com/TanStack/table/releases )
- [Changelog](https://github.com/TanStack/table/blob/main/packages/react-table/CHANGELOG.md )
- [Commits](https://github.com/TanStack/table/commits/@tanstack/react-table@9.2.4/packages/react-table )
Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react )
Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom )
Updates `react-intl` from 10.1.22 to 10.2.0
- [Release notes](https://github.com/formatjs/formatjs/releases )
- [Commits](https://github.com/formatjs/formatjs/compare/react-intl@10.1.22...react-intl@10.2.0 )
---
updated-dependencies:
- dependency-name: "@tabler/core"
dependency-version: 1.5.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
- dependency-name: "@tanstack/react-query"
dependency-version: 5.102.8
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
- dependency-name: "@tanstack/react-table"
dependency-version: 9.2.4
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
- dependency-name: react
dependency-version: 19.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
- dependency-name: react-dom
dependency-version: 19.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
- dependency-name: react-intl
dependency-version: 10.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-14 13:04:46 +00:00
dependabot[bot]
d8488048ca
Bump the prod-patch-updates group across 1 directory with 3 updates
...
Bumps the prod-patch-updates group with 3 updates in the /backend directory: [@apidevtools/json-schema-ref-parser](https://github.com/APIDevTools/json-schema-ref-parser ), [compression](https://github.com/expressjs/compression ) and [mysql2](https://github.com/sidorares/node-mysql2 ).
Updates `@apidevtools/json-schema-ref-parser` from 16.0.0 to 16.0.2
- [Release notes](https://github.com/APIDevTools/json-schema-ref-parser/releases )
- [Commits](https://github.com/APIDevTools/json-schema-ref-parser/compare/v16.0.0...v16.0.2 )
Updates `compression` from 1.8.1 to 1.8.2
- [Release notes](https://github.com/expressjs/compression/releases )
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md )
- [Commits](https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2 )
Updates `mysql2` from 3.24.2 to 3.24.4
- [Release notes](https://github.com/sidorares/node-mysql2/releases )
- [Changelog](https://github.com/sidorares/node-mysql2/blob/master/Changelog.md )
- [Commits](https://github.com/sidorares/node-mysql2/compare/v3.24.2...v3.24.4 )
---
updated-dependencies:
- dependency-name: "@apidevtools/json-schema-ref-parser"
dependency-version: 16.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
- dependency-name: compression
dependency-version: 1.8.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
- dependency-name: mysql2
dependency-version: 3.24.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-14 13:04:01 +00:00
jc21
58605cbc70
Merge pull request #5848 from siimaarmaa/develop
...
Translate the entire user interface into Estonian and ensure that the Estonian flag is displayed./Tõlgi kogu kasutajaliides eesti keelde ja kinnita Eesti lipp.
2026-09-09 10:11:03 +10:00
jc21
280fcde528
Merge pull request #5834 from 12LuA/patch-1
...
Remove broken sorting from Audit Logs
2026-09-09 07:27:36 +10:00
jc21
c70fcb9f7c
Merge pull request #5836 from jmrplens/fix/invalidate-tokens-on-password-change
...
Invalidate tokens issued before a password change
2026-09-09 07:27:00 +10:00
Cursor Agent and Siim Aarmaa
f477946bd9
Tõlgi kogu kasutajaliides eesti keelde ja kinnita Eesti lipp.
...
UI-tekstid olid eesti keele valikus, aga sisu oli inglise keeles. Nüüd on et.json täielikult eesti keeles (sh puudunud võtmed), abitekstid ühtlustatud ja lipukoodiks jääb EE (Eesti), mitte ET (Etioopia). Kuupäevad kasutavad et-EE lokaati ja 24-tunnist kellaaega.
Muudatuse tegi Aarmaa IT - Siim Aarmaa
Co-authored-by: Siim Aarmaa <siimaarmaa@users.noreply.github.com >
2026-09-08 15:52:39 +00:00
jc21
18f1fe22b1
Merge pull request #5837 from jamalkamaladdin/feat/az-locale
...
Add Azerbaijani locale
2026-09-08 07:04:06 +10:00
jc21
9fc56a2209
Merge pull request #5840 from NginxProxyManager/dependabot/npm_and_yarn/test/mocha-12.0.0
...
Bump mocha from 11.8.0 to 12.0.0 in /test
2026-09-08 07:03:37 +10:00
jc21
37b19d892c
Merge pull request #5841 from NginxProxyManager/dependabot/npm_and_yarn/test/cypress-16.0.0
...
Bump cypress from 15.21.1 to 16.0.0 in /test
2026-09-08 07:03:25 +10:00
jc21
17f126482f
Merge pull request #5838 from NginxProxyManager/dependabot/npm_and_yarn/backend/apidevtools/swagger-parser-13.0.0
...
Bump @apidevtools/swagger-parser from 12.1.0 to 13.0.0 in /backend
2026-09-08 07:03:09 +10:00
dependabot[bot]
81ec7e8d6a
Bump cypress from 15.21.1 to 16.0.0 in /test
...
Bumps [cypress](https://github.com/cypress-io/cypress ) from 15.21.1 to 16.0.0.
- [Release notes](https://github.com/cypress-io/cypress/releases )
- [Changelog](https://github.com/cypress-io/cypress/blob/develop/CHANGELOG.md )
- [Commits](https://github.com/cypress-io/cypress/compare/v15.21.1...v16.0.0 )
---
updated-dependencies:
- dependency-name: cypress
dependency-version: 16.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-07 13:03:41 +00:00
dependabot[bot]
dd45ad8f51
Bump mocha from 11.8.0 to 12.0.0 in /test
...
Bumps [mocha](https://github.com/mochajs/mocha ) from 11.8.0 to 12.0.0.
- [Release notes](https://github.com/mochajs/mocha/releases )
- [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md )
- [Commits](https://github.com/mochajs/mocha/compare/v11.8.0...v12.0.0 )
---
updated-dependencies:
- dependency-name: mocha
dependency-version: 12.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-07 13:03:33 +00:00
dependabot[bot]
33250a0e38
Bump @apidevtools/swagger-parser from 12.1.0 to 13.0.0 in /backend
...
Bumps [@apidevtools/swagger-parser](https://github.com/APIDevTools/swagger-parser ) from 12.1.0 to 13.0.0.
- [Release notes](https://github.com/APIDevTools/swagger-parser/releases )
- [Changelog](https://github.com/APIDevTools/swagger-parser/blob/main/CHANGELOG.md )
- [Commits](https://github.com/APIDevTools/swagger-parser/compare/v12.1.0...v13.0.0 )
---
updated-dependencies:
- dependency-name: "@apidevtools/swagger-parser"
dependency-version: 13.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-07 13:03:22 +00:00
Jamal
2070fd186a
Add Azerbaijani locale
2026-09-07 11:58:07 +04:00
José M. Requena Plens
e4585ac688
Stamp the password change from the app clock, not the database one
...
Your CI caught this: the check passed on SQLite and never fired on the
stack where the database container runs on a different timezone from the
app, so a stale token stayed valid. The comparison was between a token's
`iat`, which is UTC seconds from Node, and `auth.modified_on`, which the
driver hands back interpreted in the app's timezone. With the app on
Australia/Brisbane and the database on UTC, that column comes back ten
hours in the past and the token always looks newer than the change.
Record the moment in `auth.meta.password_changed_at` instead, written by
`setPassword` with the same `Date.now()` clock that mints `iat`. Same
unit on both sides, one clock, and no timestamp parsing: the Date and
local-string branch is gone, and so is the whole-second flooring that
Postgres microseconds made necessary.
Rows written before this have no marker and revoke nothing until their
next password change, which is the safe direction to be wrong in.
2026-09-06 20:15:12 +02:00
José M. Requena Plens
1ffe3609f4
Invalidate tokens issued before a password change
...
Tokens are stateless JWTs, so changing a password left every session that
the old one had opened working until its own expiry, up to a day later.
That is the case the password change is meant to close: an administrator
resetting a compromised account did not evict whoever was already in it.
The auth row already records when the password last changed, so no
migration is needed: `Access.init()` reads it alongside the user it
already loads and refuses a token whose `iat` is older. Both sides are
compared as whole seconds, which is all `iat` carries, so a token minted
in the same second as the change is kept. Postgres stores that column to
the microsecond, which is why the comparison is not done in milliseconds.
It is reported as 401 rather than the usual 403 because that is what the
frontend clears the session on, so the browser holding the dead token
lands on the login page instead of a page full of errors, and `can()`
lets that one error through unwrapped for the same reason.
Only the password does this. A user row changing (a rename, an avatar,
permissions) does not, and a user with no password auth row, which is
what a login through an external provider looks like, is not affected.
2026-09-06 19:48:02 +02:00
Luca
24b072a120
fix: Rename user.avatar to owner and disable sorting
2026-09-06 17:31:47 +02:00
jc21
a2d427902a
Merge pull request #5828 from NginxProxyManager/dependabot/npm_and_yarn/backend/fast-uri-3.1.7
...
Bump fast-uri from 3.1.5 to 3.1.7 in /backend
2026-09-04 07:42:57 +10:00
dependabot[bot]
ebbd262e06
Bump fast-uri from 3.1.5 to 3.1.7 in /backend
...
Bumps [fast-uri](https://github.com/fastify/fast-uri ) from 3.1.5 to 3.1.7.
- [Release notes](https://github.com/fastify/fast-uri/releases )
- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7 )
---
updated-dependencies:
- dependency-name: fast-uri
dependency-version: 3.1.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-02 22:41:08 +00:00
jc21
5e6c53f0e2
Merge pull request #5726 from NginxProxyManager/dependabot/npm_and_yarn/test/axios-1.18.0
...
Bump axios from 1.19.0 to 1.20.0 in /test
2026-09-01 07:10:25 +10:00
jc21
baa5683bba
Merge pull request #5823 from NginxProxyManager/dependabot/npm_and_yarn/backend/prod-minor-updates-1a71c66db8
...
Bump mysql2 from 3.23.4 to 3.24.2 in /backend in the prod-minor-updates group
2026-09-01 07:10:12 +10:00
jc21
386a166025
Merge pull request #5820 from NginxProxyManager/dependabot/npm_and_yarn/test/cypress/grep-7.0.0
...
Bump @cypress/grep from 6.0.3 to 7.0.0 in /test
2026-09-01 07:09:32 +10:00
dependabot[bot]
f7a696cf08
Bump mysql2 in /backend in the prod-minor-updates group
...
Bumps the prod-minor-updates group in /backend with 1 update: [mysql2](https://github.com/sidorares/node-mysql2 ).
Updates `mysql2` from 3.23.4 to 3.24.2
- [Release notes](https://github.com/sidorares/node-mysql2/releases )
- [Changelog](https://github.com/sidorares/node-mysql2/blob/master/Changelog.md )
- [Commits](https://github.com/sidorares/node-mysql2/compare/v3.23.4...v3.24.2 )
---
updated-dependencies:
- dependency-name: mysql2
dependency-version: 3.24.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: prod-minor-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-31 13:04:27 +00:00
dependabot[bot]
ec65105db2
Bump @cypress/grep from 6.0.3 to 7.0.0 in /test
...
Bumps [@cypress/grep](https://github.com/cypress-io/cypress ) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/cypress-io/cypress/releases )
- [Changelog](https://github.com/cypress-io/cypress/blob/develop/CHANGELOG.md )
- [Commits](https://github.com/cypress-io/cypress/compare/@cypress/grep-v6.0.3...@cypress/grep-v7.0.0 )
---
updated-dependencies:
- dependency-name: "@cypress/grep"
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-31 13:04:01 +00:00
dependabot[bot]
aa211ea423
Bump axios from 1.19.0 to 1.20.0 in /test
...
Bumps [axios](https://github.com/axios/axios ) from 1.19.0 to 1.20.0.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.19.0...v1.20.0 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.18.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-31 10:43:00 +00:00
jc21
cd4448ebef
Merge pull request #5713 from NginxProxyManager/dependabot/npm_and_yarn/test/systeminformation-5.31.17
...
Bump systeminformation from 5.31.6 to 5.31.17 in /test
2026-08-31 20:41:29 +10:00
jc21
e2546bfb51
Merge pull request #5737 from NginxProxyManager/dependabot/npm_and_yarn/frontend/immutable-5.1.9
...
Bump immutable from 5.1.5 to 5.1.9 in /frontend
2026-08-31 20:40:55 +10:00
jc21
c19182d978
Merge pull request #5743 from NginxProxyManager/dependabot/npm_and_yarn/test/tar-7.5.22
...
Bump tar from 7.5.15 to 7.5.22 in /test
2026-08-31 20:40:38 +10:00
jc21
1cbfe370ec
Merge pull request #5756 from NginxProxyManager/dependabot/npm_and_yarn/docs/postcss-8.5.25
...
Bump postcss from 8.5.14 to 8.5.25 in /docs
2026-08-31 20:40:25 +10:00
jc21
6c2a57ad83
Merge pull request #5769 from NginxProxyManager/dependabot/npm_and_yarn/test/fast-uri-3.1.5
...
Bump fast-uri from 3.1.2 to 3.1.6 in /test
2026-08-31 20:40:10 +10:00
jc21
b75b0adaf2
Merge pull request #5812 from vzagorovskiy/fix/keep-failed-nginx-config-as-err
...
Keep the failed nginx config as a .conf.err file
2026-08-29 10:14:42 +10:00
vzagorovskiy
a570c0e503
Keep the failed nginx config as a .conf.err file
...
When `nginx -t` fails, configure() is meant to move the broken config to
<id>.conf.err so the failure can be inspected. renameConfigAsError()
unlinked the source file before renaming it, so the rename always failed
and the config was simply deleted. The deleteConfig() call after it then
removed any .err file left over from an earlier failure.
- unlink the destination .err file instead of the source
- return the rename promise so the delete does not race it
- pass delete_err_file = false so the new .err file survives
- drop the stale 4th argument in the success path, which silently made
delete_err_file false and left old .err files behind
2026-08-28 11:47:02 +03:00
jc21
6383017b4c
Merge pull request #5780 from NginxProxyManager/dependabot/npm_and_yarn/test/js-yaml-4.3.1
...
Bump js-yaml from 4.1.1 to 4.3.1 in /test
2026-08-28 16:29:35 +10:00
jc21
3f2cd26913
Merge pull request #5789 from quokkawiki/develop
...
Fixed Estonian flag bug
2026-08-28 14:16:55 +10:00
jc21
ece5dea0ad
Merge branch 'develop' into develop
2026-08-28 07:57:25 +10:00
jc21
a75eb467ca
Merge pull request #5807 from vgoer/changes-not-taking-effect
...
fix: Changes not taking effect
2026-08-28 07:51:55 +10:00
jc21
708ea5cfbb
Merge pull request #5809 from tapacko88/feat/ukrainian-locale
...
Add Ukrainian locale
2026-08-28 07:50:51 +10:00
tapacko
d77d5c643d
Add Ukrainian locale
2026-08-26 23:39:25 +01:00
jc21
934a3fafe5
Merge pull request #5765 from fatihemre/feat/collapsible-custom-locations
...
Collapse custom locations into a filterable list
2026-08-27 07:42:43 +10:00
vgoer
08b4bbdbd4
fix: Changes not taking effect
2026-08-26 07:39:31 +00:00
jc21
a7677c18c3
Merge branch 'develop' into feat/collapsible-custom-locations
2026-08-26 13:00:05 +10:00
dependabot[bot]
1d894f8ed1
Bump fast-uri from 3.1.2 to 3.1.6 in /test
...
Bumps [fast-uri](https://github.com/fastify/fast-uri ) from 3.1.2 to 3.1.6.
- [Release notes](https://github.com/fastify/fast-uri/releases )
- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.6 )
---
updated-dependencies:
- dependency-name: fast-uri
dependency-version: 3.1.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-26 02:59:09 +00:00
dependabot[bot]
7cde02c446
Bump js-yaml from 4.1.1 to 4.3.1 in /test
...
Bumps [js-yaml](https://github.com/nodeca/js-yaml ) from 4.1.1 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.1 )
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-26 02:59:07 +00:00