Skip to content

chore(deps): Bump the minor-and-patch group across 1 directory with 8 updates - #9

Closed
dependabot[bot] wants to merge 17 commits into
mainfrom
dependabot/npm_and_yarn/frontend/minor-and-patch-47d6183fb7
Closed

chore(deps): Bump the minor-and-patch group across 1 directory with 8 updates#9
dependabot[bot] wants to merge 17 commits into
mainfrom
dependabot/npm_and_yarn/frontend/minor-and-patch-47d6183fb7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 19, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 8 updates in the /frontend directory:

Package From To
vue 3.5.39 3.5.40
vue-router 5.1.0 5.2.0
@ownclouders/eslint-config 12.3.2 12.5.0
@ownclouders/extension-sdk 12.3.2 12.5.0
happy-dom 20.10.6 20.11.0
prettier 3.8.3 3.9.5
vitest 4.1.7 4.1.10
vue-tsc 3.3.2 3.3.7

Updates vue from 3.5.39 to 3.5.40

Release notes

Sourced from vue's releases.

v3.5.40

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Changelog

Sourced from vue's changelog.

3.5.40 (2026-07-16)

Bug Fixes

Commits

Updates vue-router from 5.1.0 to 5.2.0

Release notes

Sourced from vue-router's releases.

v5.2.0

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates @ownclouders/eslint-config from 12.3.2 to 12.5.0

Release notes

Sourced from @​ownclouders/eslint-config's releases.

12.5.0

Changelog for ownCloud Web 12.5.0 (2026-07-01)

Summary

  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797
  • Bugfix - Fix danger filled button text color on focus: #13887
  • Bugfix - Open external apps based on the file mime type: #13888
  • Bugfix - Validate URL before opening password-protected folder: #13924
  • Enhancement - OwnCloud branded login background: #13875
  • Enhancement - Add a documentation screenshot capture tool: #13894
  • Enhancement - Add an HTML editor app: #13895
  • Enhancement - Save a copy of office documents to another format (Collabora): #13906

Details

  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797

    On iOS/iPadOS, we now display a button to open the PDF file in the browser instead of the native PDF viewer. This is a workaround to avoid issues with the native PDF viewer on iOS/iPadOS.

    owncloud/web#13797 owncloud/web#13816

  • Bugfix - Fix danger filled button text color on focus: #13887

    We've fixed the OcButton danger filled variant not applying the correct text color when focused via keyboard.

    owncloud/web#13887

  • Bugfix - Open external apps based on the file mime type: #13888

    We've fixed the external app redirect (/external) picking an arbitrary app when no app query parameter was present. It fell back to the first registered app provider, which might not support the file's mime type, so the following request to open the file failed with an "app not found" error that surfaced as a generic error to the user.

    The redirect now resolves the app from the file's mime type, preferring the configured default application, and shows an explicit error when no suitable app is available instead of silently redirecting to the wrong one.

    owncloud/web#13888

  • Bugfix - Validate URL before opening password-protected folder: #13924

... (truncated)

Changelog

Sourced from @​ownclouders/eslint-config's changelog.

Changelog for ownCloud Web unreleased (UNRELEASED)

The following sections list the changes in ownCloud web unreleased relevant to ownCloud admins and users.

Summary

  • Security - Validate postMessage origin in embed mode modals: #13844
  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797
  • Bugfix - Add explicit size to space header image: #13822
  • Bugfix - Apply vault theme after OIDC callback: #13826
  • Bugfix - Gate MFA expiry dialog on vault capability: #13827
  • Bugfix - Logo not rendering in Firefox: #13834
  • Bugfix - Fix theme switching issues: #13843
  • Bugfix - Pass vault parameter to capabilities endpoint: #13867
  • Bugfix - Filter notifications by vault mode: #13877
  • Bugfix - Fix danger filled button text color on focus: #13887
  • Bugfix - Open external apps based on the file mime type: #13888
  • Enhancement - OwnCloud branded login background: #13875
  • Enhancement - Add a documentation screenshot capture tool: #13894

Details

  • Security - Validate postMessage origin in embed mode modals: #13844

    We've fixed a cross-site request forgery (CSRF) vulnerability where the embed mode modals (Save As, Export As PDF and the file picker) processed incoming postMessage events without verifying the sender's origin. A malicious page holding a reference to an authenticated ownCloud window could forge owncloud-embed:select, owncloud-embed:file-pick or owncloud-embed:cancel messages and trigger authenticated file writes in the victim's space. Incoming messages are now validated against an allowlist consisting of the application's own origin and the optionally configured embed.messagesOrigin.

    owncloud/web#13844

  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797

    On iOS/iPadOS, we now display a button to open the PDF file in the browser instead of the native PDF viewer. This is a workaround to avoid issues with the native PDF viewer on iOS/iPadOS.

    owncloud/web#13797 owncloud/web#13816

  • Bugfix - Add explicit size to space header image: #13822

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​ownclouders/eslint-config since your current version.


Updates @ownclouders/extension-sdk from 12.3.2 to 12.5.0

Release notes

Sourced from @​ownclouders/extension-sdk's releases.

12.5.0

Changelog for ownCloud Web 12.5.0 (2026-07-01)

Summary

  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797
  • Bugfix - Fix danger filled button text color on focus: #13887
  • Bugfix - Open external apps based on the file mime type: #13888
  • Bugfix - Validate URL before opening password-protected folder: #13924
  • Enhancement - OwnCloud branded login background: #13875
  • Enhancement - Add a documentation screenshot capture tool: #13894
  • Enhancement - Add an HTML editor app: #13895
  • Enhancement - Save a copy of office documents to another format (Collabora): #13906

Details

  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797

    On iOS/iPadOS, we now display a button to open the PDF file in the browser instead of the native PDF viewer. This is a workaround to avoid issues with the native PDF viewer on iOS/iPadOS.

    owncloud/web#13797 owncloud/web#13816

  • Bugfix - Fix danger filled button text color on focus: #13887

    We've fixed the OcButton danger filled variant not applying the correct text color when focused via keyboard.

    owncloud/web#13887

  • Bugfix - Open external apps based on the file mime type: #13888

    We've fixed the external app redirect (/external) picking an arbitrary app when no app query parameter was present. It fell back to the first registered app provider, which might not support the file's mime type, so the following request to open the file failed with an "app not found" error that surfaced as a generic error to the user.

    The redirect now resolves the app from the file's mime type, preferring the configured default application, and shows an explicit error when no suitable app is available instead of silently redirecting to the wrong one.

    owncloud/web#13888

  • Bugfix - Validate URL before opening password-protected folder: #13924

... (truncated)

Changelog

Sourced from @​ownclouders/extension-sdk's changelog.

Changelog for ownCloud Web unreleased (UNRELEASED)

The following sections list the changes in ownCloud web unreleased relevant to ownCloud admins and users.

Summary

  • Security - Validate postMessage origin in embed mode modals: #13844
  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797
  • Bugfix - Add explicit size to space header image: #13822
  • Bugfix - Apply vault theme after OIDC callback: #13826
  • Bugfix - Gate MFA expiry dialog on vault capability: #13827
  • Bugfix - Logo not rendering in Firefox: #13834
  • Bugfix - Fix theme switching issues: #13843
  • Bugfix - Pass vault parameter to capabilities endpoint: #13867
  • Bugfix - Filter notifications by vault mode: #13877
  • Bugfix - Fix danger filled button text color on focus: #13887
  • Bugfix - Open external apps based on the file mime type: #13888
  • Enhancement - OwnCloud branded login background: #13875
  • Enhancement - Add a documentation screenshot capture tool: #13894

Details

  • Security - Validate postMessage origin in embed mode modals: #13844

    We've fixed a cross-site request forgery (CSRF) vulnerability where the embed mode modals (Save As, Export As PDF and the file picker) processed incoming postMessage events without verifying the sender's origin. A malicious page holding a reference to an authenticated ownCloud window could forge owncloud-embed:select, owncloud-embed:file-pick or owncloud-embed:cancel messages and trigger authenticated file writes in the victim's space. Incoming messages are now validated against an allowlist consisting of the application's own origin and the optionally configured embed.messagesOrigin.

    owncloud/web#13844

  • Bugfix - Add open button to PDF viewer on iOS/iPadOS: #13797

    On iOS/iPadOS, we now display a button to open the PDF file in the browser instead of the native PDF viewer. This is a workaround to avoid issues with the native PDF viewer on iOS/iPadOS.

    owncloud/web#13797 owncloud/web#13816

  • Bugfix - Add explicit size to space header image: #13822

... (truncated)

Commits
  • b16a34f [full-ci] chore: prepare final release from web repo (#13930)
  • be0f6ac Chore/sync master branch with stable 12.4 (#13814)
  • 0215824 chore: sync 12.3 branch changelog and version (#13729)
  • 02ec681 fix(deps): update dependency @​vitejs/plugin-vue to ^6.0.6 (#13700)
  • 06dab4f fix(deps): update dependency @​vitejs/plugin-vue to ^6.0.5
  • 6e4fcf5 Revert "Merge pull request #13521 from owncloud/chore/revert-changes-to-master"
  • 69b4edc Revert "Merge pull request #13519 from owncloud/stable-12.3"
  • See full diff in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​ownclouders/extension-sdk since your current version.


Updates happy-dom from 20.10.6 to 20.11.0

Release notes

Sourced from happy-dom's releases.

v20.11.0

🎨 Features

Commits

Updates prettier from 3.8.3 to 3.9.5

Release notes

Sourced from prettier's releases.

3.9.5

🔗 Changelog

3.9.4

  • Angular: Format @content(name) -> @content (name) to align with other block syntax (#19499 by @​fisker)

🔗 Changelog

3.9.3

🔗 Changelog

3.9.1

🔗 Changelog

3.9.0

diff

🔗 Prettier 3.9: Major parser upgrades and Formatting improvements

3.8.5

🔗 Changelog

3.8.4

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.5

diff

Markdown: Cap ordered list mark at 999,999,999 (#19351 by @​tats-u)

CommonMark parsers only support ordered list item numbers up to 999,999,999.

With this change, Prettier now caps the ordered list item number at 999,999,999 to ensure that the output is correctly parsed as an ordered list by CommonMark parsers. Numbers larger than 999,999,999 are not parsed as list item numbers and are left unchanged in the output:

<!-- Input -->
999999998. text
999999998. text
999999998. text
999999998. text
1234567890123456789012) text
<!-- Prettier 3.9.4 -->
999999998. text
999999999. text
1000000000. text
1000000001. text
1234567890123456789012) text
<!-- Prettier 3.9.5 -->
999999998. text
999999999. text
999999999. text
999999999. text
1234567890123456789012) text

Markdown: Avoid corrupting empty link with title (#19487 by @​andersk)

Do not remove <> from an inline link or image with an empty URL and a title, as this removal would change its interpretation.

<!-- Input -->
[link](https://github.com/prettier/prettier/blob/main/<> "title")
<!-- Prettier 3.9.4 -->
[link](https://github.com/prettier/prettier/blob/main/ "title")
<!-- Prettier 3.9.5 -->
</tr></table>

... (truncated)

Commits

Updates vitest from 4.1.7 to 4.1.10

Release notes

Sourced from vitest's releases.

v4.1.10

   🐞 Bug Fixes

    View changes on GitHub

v4.1.9

🐞 Bug Fixes

View changes on GitHub

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • db616d2 chore: release v4.1.10 (#10718)
  • bae52b5 fix(vm): fix external module resolve error with deps optimizer query for enco...
  • a7a61e7 chore: release v4.1.9 (#10598)
  • 934b0f5 fix(pool): prevent test run hang on worker crash (#10543) [backport to v4] (#...
  • 7fb2965 fix(browser): wait for orchestrator readiness before resolving browser sessio...
  • a518019 fix: fix importOriginal with optimizer and query import [backport to v4] (#...
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • See full diff in compare view

Updates vue-tsc from 3.3.2 to 3.3.7

Release notes

Sourced from vue-tsc's releases.

v3.3.7

language-core

  • fix: wrap single expression event handlers to avoid ASI after return (#6115) - Thanks to @​KazariEX!

typescript-plugin

  • fix: filter const globals from template completions

Our Sponsors ❤️

... (truncated)

Changelog

Sourced from vue-tsc's changelog.

3.3.7 (2026-07-08)

language-core

  • fix: wrap single expression event handlers to avoid ASI after return (#6115) - Thanks to @​KazariEX!

typescript-plugin

  • fix: filter const globals from template completions

3.3.6 (2026-06-30)

language-core

  • fix: make generic component internal context inference type-safe across .d.ts boundary (#6104) - Thanks to @​Holiden!
  • fix: do not treat non-trivial property accesses as compound - Thanks to @​KazariEX!
  • fix: treat semicolon-terminated expressions as compound - Thanks to @​KazariEX!
  • fix: preserve return types for compound event handlers - Thanks to @​KazariEX!
  • fix: use WeakMap to cache inline TS ASTs - Thanks to @​KazariEX!
  • fix: match upstream CSS v-bind parsing behavior - Thanks to @​KazariEX!
  • fix: include setup bindings as potential component names (#6111) - Thanks to @​KazariEX!
  • perf: reduce boundary code feature allocations - Thanks to @​KazariEX!
  • refactor: centralize code features and deprecate allCodeFeatures - Thanks to @​KazariEX!

3.3.5 (2026-06-13)

language-core

  • fix: include event modifiers in duplicate listener checks (#6097) - Thanks to @​KazariEX!

3.3.4 (2026-06-08)

language-core

  • fix: only exclude already-set props from inherited attrs when checkRequiredFallthroughAttributes is enabled (#6088) - Thanks to @​KazariEX!
  • fix: camelize slot props regardless of htmlAttributes option (#6089) - Thanks to @​KazariEX!
  • fix: detect duplicate event listeners across name formats (#6094) - Thanks to @​whysopaul!

language-service

  • fix: respect var hoisting for destructured props hints (#6092) - Thanks to @​KazariEX!

typescript-plugin

  • fix: do not treat class and style as a boolean property (#6081) - Thanks to @​KazariEX!

3.3.3 (2026-05-30)

vscode

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

LukasHirt and others added 17 commits July 14, 2026 20:46
Apache-2.0 licensing (REUSE-compliant), OSPO community files,
Conventional Commits enforcement via commitlint/husky, CI workflow
covering frontend/backend/e2e jobs, and the local dev docker-compose
stack (oCIS + Traefik + ai-llm-proxy + this backend), all based on
owncloud/web-app-skeleton's conventions.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Extension entry point registers AI Workflows as a full app (nav item
+ own routes), scaffolded from web-app-skeleton's defineWebApplication
pattern. Adds a workflow list view backed by the Graph-shaped backend
CRUD API, and a Vue Flow canvas for building trigger/LLM/action node
graphs. No execution yet — that lands with the backend graph
interpreter.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Standalone HTTP service (chi router, stdlib log/slog, no ocis-pkg or
reva dependency) that validates bearer tokens itself against oCIS's
IdP userinfo endpoint, exactly like a well-behaved external sidecar.
Workflow definitions are persisted as JSON via WebDAV in the caller's
own oCIS space (no NATS, no system-user credential, no internal gRPC),
with a /me/workflows CRUD surface shaped after oCIS's Graph API
conventions (value-wrapped collections, PATCH updates, Graph-style
error envelopes).

Signed-off-by: Lukas Hirt <info@hirt.cz>
Two issues found while getting the builder canvas working against a
real oCIS Web instance: (1) vue-router isn't among extension-sdk's
externalized deps, so importing useRouter/useRoute from 'vue-router'
directly bundles a second, disconnected router instance whose
injection silently resolves to undefined — switched to
@ownclouders/web-pkg's useRouter/useRoute, which share the host app's
actual router; (2) client-side navigation into this app's :id
sub-route throws inside Web's persistent-layout sidebar code
(a resource-injection assumption unrelated to this app), so
list<->builder navigation uses a hard navigation instead, which is
proven reliable.

Also excludes tests/e2e from vitest's default include pattern, since
extension-sdk's own exclude list only accounts for a top-level e2e/
directory.

Signed-off-by: Lukas Hirt <info@hirt.cz>
LLM calls are now made directly by the backend against a configured
LLM_ENDPOINT/LLM_API_KEY — no external ai-llm-proxy service, no
web-extensions sibling checkout needed for local dev. Extends the dev
docker-compose stack with the workflows backend as a Traefik-routed
sidecar (path-prefixed + stripped, same pattern ai-llm-proxy used to
occupy) and enables PROXY_ENABLE_APP_AUTH/auth-app on the oCIS
container, since background/automated workflow runs will authenticate
via oCIS app-passwords now that LLM calls no longer require a real
IdP-issued token to reach an external validator.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Backend suite (build-tagged e2e) makes real HTTP calls through Traefik
against the live compose stack and asserts on Graph-shaped responses —
no mocks. Frontend suite drives a real browser through login, building
a trigger->LLM->action graph on the Vue Flow canvas, and saving it.

Both share get-token.ts, a small headless-Playwright script that logs
in through oCIS's real sign-in page: the IdP hashes credentials
client-side, so there is no plain HTTP request to replay to obtain a
token, and a real browser session is the only practical way to get
one. All actual assertions in the backend suite are still plain Go
net/http against the real API.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Per explicit direction: n8n's UX, not its branding/colors. Replaces
the fixed "Add LLM step"/"Add action" toolbar with a searchable,
categorized node-type picker triggered by "+" (on an empty canvas or
on a node's output handle, auto-connecting when opened from a node).
Node cards on the canvas are now compact and display-only; clicking
one opens a Node Details View modal for configuration instead of
inline form fields. Top bar gains an inline-editable workflow name
and an Active/Inactive toggle. Adds a minimap and re-fits the
viewport after each node is added, since newly added nodes otherwise
render further right each time without ever re-centering.

Also fixes two bugs the rework's e2e coverage caught: a v-model
directive ordering lint warning, and a template attribute with
literal double quotes inside a double-quoted HTML attribute that
vue-tsc rejected as a syntax error.

Signed-off-by: Lukas Hirt <info@hirt.cz>
The single interpreter every workflow run (manual/scheduled/event)
goes through: walks a workflow's trigger->llm->action graph, calling
this backend's own directly-configured LLM_ENDPOINT for llm nodes
(pkg/llm, no external proxy) and oCIS's WebDAV/Graph APIs for action
nodes with the run's own token. {{file.name}}/{{file.content}}/
{{llm.output}} template variables are substituted into prompts and
action params; node/edge "condition" fields are stored but not yet
evaluated (every reachable node runs unconditionally for now).

Action handlers (pkg/webdavfile, pkg/ocisclient/tags.go):
- tag: real Graph tags API. Resolving a WebDAV path to the Graph
  resourceId turned out to need a PROPFIND for the oc:fileid WebDAV
  property, not a Graph path-lookup endpoint — Graph has none.
- move/copy/rename: real WebDAV MOVE/COPY.
- comment: oCIS has no native file-comments API, unlike tags — this
  writes a JSON sidecar list under the user's own .workflows/
  folder instead. Real and retrievable, documented as not visible in
  oCIS Web's own UI, not a stub.
- notify: github.com/unraid/apprise-go (BSD-2-Clause, see NOTICE.md),
  100+ integrations behind one target-URL scheme, with an SSRF guard
  on the generic webhook schemes.

Execution history is stored the same way workflow definitions are —
JSON via WebDAV in the caller's own space — and the run endpoint
responds the way a real Graph async action would (202 + Location),
even though execution is currently synchronous.

Adds a fake-llm fixture (cmd/fakellm, a ~30-line OpenAI-compatible
stub) to the dev stack so it — and its e2e suite — never depend on a
real LLM provider being reachable.

Signed-off-by: Lukas Hirt <info@hirt.cz>
New "Executions" panel: a resourcePath input + Run now button, and
the run history below it (status pill, per-node results). runWorkflow
parses the execution id out of the 202 response's Location header
rather than assuming a body, matching the backend's Graph-style async
action shape.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Backend: uploads a real file, runs a trigger->llm->tag graph through
the real API, and asserts the tag actually landed by reading it back
over WebDAV — no mocks. Frontend: builds and saves a workflow through
the UI, runs it via the Executions panel, and asserts success and the
LLM output render.

Also fixes both existing specs to clean up the workflows/files they
create (build-workflow.spec.ts now does it via the UI's own delete
button, exercising that flow too) — a prior run left test data behind
that only surfaced when checking the store by hand.

Signed-off-by: Lukas Hirt <info@hirt.cz>
…oken

webdavstore, webdavfile, and ocisclient all hard-coded "Bearer "+token
when setting the Authorization header. Scheduled/event-triggered runs
(next up) authenticate to oCIS with an app-password over HTTP Basic,
not a bearer token, so these packages now take the full header value
as-is and every call site formats it. Manual runs are unaffected —
callers just now write "Bearer "+token explicitly instead of it being
implicit three packages down.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Enabling automation (POST /me/automation) mints an oCIS app-password
via auth-app using the caller's own live token in the same request —
no separate consent redirect needed, since the user is already
authenticated to our API at that moment. The credential is encrypted
(AES-256-GCM, pkg/secretbox) and stored in a new local SQLite database
(pkg/localdb, pure-Go driver) — this is the sidecar's own operational
state, not user content, so it never goes through any oCIS API.

A background scheduler (pkg/scheduler) polls a denormalized trigger
index for due schedule-triggered workflows and runs them through the
same executor as manual runs, authenticating via the owner's stored
app-password over HTTP Basic — no live session involved. The trigger
index is kept in sync automatically whenever a workflow with a
schedule/event trigger is created, updated, or deleted.

Verified end-to-end against the real stack: connect mints a real
app-password, a workflow scheduled for "every second" actually fires
on its own using that stored credential, and disconnect revokes it.

Cron expressions accept an optional leading seconds field (still
backwards compatible with classic 5-field syntax) — mainly so tests
(and anyone who wants sub-minute schedules) aren't stuck waiting on
minute boundaries.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Automation is per-user, not per-workflow, so it's a status pill and
toggle button in the workflow list header rather than anything
per-row: shows whether background execution is enabled and lets the
user connect (mint an app-password) or disconnect (revoke it) it.

test(e2e): cover automation and scheduled execution end-to-end

Backend: connects automation (mints a real auth-app token), verifies
status, disconnects (revokes it) — then separately, creates a
schedule-triggered workflow and polls until it actually fires on its
own via the background scheduler, authenticated with the stored
app-password, no live session involved. Frontend: exercises the
connect/disconnect UI, including that the connected state survives a
page reload.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Add a per-user SSE consumer manager that reconciles against the
trigger index and runs event-triggered workflows through the same
executor manual/scheduled runs use, resolving SSE spaceId/itemId
payloads to WebDAV paths via Graph's drive-item-by-id endpoint. No
NATS client is involved anywhere in the process.

Guard event matching against this backend's own .workflows
bookkeeping writes (workflow definitions, execution records) -
without it, an event trigger with no path filter is
indistinguishable from a real upload and re-triggers itself on every
execution it records.

Also fixes a schema migration gap: trigger_index rows created before
this milestone lacked the new path_prefix/extension columns, and
CREATE TABLE IF NOT EXISTS is a no-op against an existing table.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Backend: connect automation, create an upload-triggered workflow
scoped to a path/extension filter, upload a matching file over
WebDAV, and assert the workflow fires on its own via the SSE
consumer - no manual/scheduled trigger involved.

Frontend: build a workflow with a File Event Trigger node, configure
its event type and path filter through the Node Details panel, and
confirm both persist across a reload.

Widen the scheduled-trigger test's polling window: with the SSE
manager now running continuously alongside the scheduler, first-fire
latency under load comfortably exceeds the original 25s budget.

Signed-off-by: Lukas Hirt <info@hirt.cz>
Add a reuse job running fsfe/reuse-action so REUSE/SPDX compliance is
enforced on every push and PR, not just checked manually. Fixes the
one pre-existing gap it surfaces: LICENSES/BSD-2-Clause.txt (bundled
for apprise-go's redistribution requirement, since it's statically
linked into the backend binary) wasn't referenced by any SPDX tag,
since apprise-go itself isn't vendored into this repo - tag NOTICE.md,
the file that documents it, with the combined license identifier.

Add a dependency license check to the frontend CI job
(scripts/check-licenses.mjs, via `pnpm licenses list --json`) that
fails on any GPL/AGPL/LGPL/MPL-family dependency other than
@ownclouders/* - ownCloud Web's own AGPL-3.0 SDK, unavoidable for any
Web extension and already an accepted, load-bearing dependency here.

Drop the stable-* branch trigger: there's no such branch in this repo.

Signed-off-by: Lukas Hirt <info@hirt.cz>
… updates

Bumps the minor-and-patch group with 8 updates in the /frontend directory:

| Package | From | To |
| --- | --- | --- |
| [vue](https://github.com/vuejs/core) | `3.5.39` | `3.5.40` |
| [vue-router](https://github.com/vuejs/router) | `5.1.0` | `5.2.0` |
| [@ownclouders/eslint-config](https://github.com/owncloud/web/tree/HEAD/packages/eslint-config) | `12.3.2` | `12.5.0` |
| [@ownclouders/extension-sdk](https://github.com/owncloud/web/tree/HEAD/packages/extension-sdk) | `12.3.2` | `12.5.0` |
| [happy-dom](https://github.com/capricorn86/happy-dom) | `20.10.6` | `20.11.0` |
| [prettier](https://github.com/prettier/prettier) | `3.8.3` | `3.9.5` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.7` | `4.1.10` |
| [vue-tsc](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc) | `3.3.2` | `3.3.7` |



Updates `vue` from 3.5.39 to 3.5.40
- [Release notes](https://github.com/vuejs/core/releases)
- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)
- [Commits](vuejs/core@v3.5.39...v3.5.40)

Updates `vue-router` from 5.1.0 to 5.2.0
- [Release notes](https://github.com/vuejs/router/releases)
- [Commits](vuejs/router@v5.1.0...v5.2.0)

Updates `@ownclouders/eslint-config` from 12.3.2 to 12.5.0
- [Release notes](https://github.com/owncloud/web/releases)
- [Changelog](https://github.com/owncloud/web/blob/master/CHANGELOG.md)
- [Commits](https://github.com/owncloud/web/commits/v12.5.0/packages/eslint-config)

Updates `@ownclouders/extension-sdk` from 12.3.2 to 12.5.0
- [Release notes](https://github.com/owncloud/web/releases)
- [Changelog](https://github.com/owncloud/web/blob/master/CHANGELOG.md)
- [Commits](https://github.com/owncloud/web/commits/v12.5.0/packages/extension-sdk)

Updates `happy-dom` from 20.10.6 to 20.11.0
- [Release notes](https://github.com/capricorn86/happy-dom/releases)
- [Commits](capricorn86/happy-dom@v20.10.6...v20.11.0)

Updates `prettier` from 3.8.3 to 3.9.5
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.3...3.9.5)

Updates `vitest` from 4.1.7 to 4.1.10
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest)

Updates `vue-tsc` from 3.3.2 to 3.3.7
- [Release notes](https://github.com/vuejs/language-tools/releases)
- [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vuejs/language-tools/commits/v3.3.7/packages/tsc)

---
updated-dependencies:
- dependency-name: vue
  dependency-version: 3.5.40
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vue-router
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@ownclouders/eslint-config"
  dependency-version: 12.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@ownclouders/extension-sdk"
  dependency-version: 12.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: happy-dom
  dependency-version: 20.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: prettier
  dependency-version: 3.9.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: vitest
  dependency-version: 4.1.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: vue-tsc
  dependency-version: 3.3.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 19, 2026
@LukasHirt LukasHirt closed this Jul 20, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/minor-and-patch-47d6183fb7 branch July 20, 2026 11:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant