Skip to content

Commit 2e02053

Browse files
committed
Merge remote-tracking branch 'origin/main' into feat/file-transformers
# Conflicts: # test/a11y/collections/Media/index.ts
2 parents f9ef622 + e6cd442 commit 2e02053

355 files changed

Lines changed: 16255 additions & 5986 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/actions/audit-dependencies/src/lib/catalog.test.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ describe('loadCatalogs', () => {
2323
[
2424
'catalog:',
2525
" zod: '^4.6.0'",
26-
" react: '19.2.6'",
26+
" react: '19.3.0'",
2727
'catalogs:',
2828
' react18:',
2929
" react: '18.2.0'",
@@ -34,7 +34,7 @@ describe('loadCatalogs', () => {
3434
const catalogs = await loadCatalogs({ repoRoot: dir })
3535

3636
expect(catalogs.default.zod).toBe('^4.6.0')
37-
expect(catalogs.default.react).toBe('19.2.6')
37+
expect(catalogs.default.react).toBe('19.3.0')
3838
expect(catalogs.named.react18.react).toBe('18.2.0')
3939
})
4040

‎app-tanstack/app/_payload.tsx‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
/* THIS FILE WAS GENERATED AUTOMATICALLY BY PAYLOAD. MODIFY AT YOUR OWN RISK. */
12
import { payloadLayoutRoute } from '@payloadcms/tanstack-start/client'
23
import { createFileRoute } from '@tanstack/react-router'
34

‎app-tanstack/app/_payload/admin.$.tsx‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
/* THIS FILE WAS GENERATED AUTOMATICALLY BY PAYLOAD. MODIFY AT YOUR OWN RISK. */
12
import { payloadAdminSplatRoute } from '@payloadcms/tanstack-start/client'
23
import { createFileRoute } from '@tanstack/react-router'
34

‎app-tanstack/app/_payload/admin.index.tsx‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
/* THIS FILE WAS GENERATED AUTOMATICALLY BY PAYLOAD. MODIFY AT YOUR OWN RISK. */
12
import { payloadAdminIndexRoute } from '@payloadcms/tanstack-start/client'
23
import { createFileRoute } from '@tanstack/react-router'
34

‎app-tanstack/app/_payload/api.$.ts‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
/* THIS FILE WAS GENERATED AUTOMATICALLY BY PAYLOAD. MODIFY AT YOUR OWN RISK. */
12
import { payloadApiHandlers } from '@payloadcms/tanstack-start/server'
23
import { createFileRoute } from '@tanstack/react-router'
34

‎app-tanstack/app/_payload/server.functions.ts‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
/* THIS FILE WAS GENERATED AUTOMATICALLY BY PAYLOAD. MODIFY AT YOUR OWN RISK. */
12
import type { ServerFunctionClientArgs } from 'payload'
23

34
import { createServerFunctionClient } from '@payloadcms/tanstack-start/client'

‎docs/access-control/overview.mdx‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -45,9 +45,9 @@ const defaultPayloadAccess = ({ req: { payload, user } }) => {
4545

4646
<Banner type="warning">
4747
**Important:** By default, all [Local API](../local-api/overview) operations
48-
respect Access Control based on the passed `user`. Set
49-
`overrideAccess: true` only when the operation should entirely bypass
50-
Access Control. See [Local API Access Control](../local-api/access-control).
48+
respect Access Control based on the passed `user`. Set `overrideAccess: true`
49+
only when the operation should entirely bypass Access Control. See [Local API
50+
Access Control](../local-api/access-control).
5151
</Banner>
5252

5353
## Base Access Control

‎docs/authentication/api-keys.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,7 @@ Payload ensures that the same, uniform [Access Control](../access-control/overvi
104104

105105
### API Key Only Auth
106106

107-
If you want to use API keys as the only authentication method for a collection, you can disable the default local strategy by setting `disableLocalStrategy` to `true` on the collection's `auth` property. This will disable the ability to authenticate with email and password, and will only allow for authentication via API key.
107+
If you want to use API keys as the only authentication method for a collection, you can disable the default local strategy by setting `disableLocalStrategy` to `true` on the collection's `auth` property. Setting it to `false` keeps local authentication enabled. Disabling the local strategy prevents authentication with email and password, leaving API keys as the collection's authentication method.
108108

109109
```ts
110110
import type { CollectionConfig } from 'payload'

‎docs/authentication/custom-strategies.mdx‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,8 @@ The `authenticate` function is passed the following arguments:
4040

4141
At its core a strategy simply takes information from the incoming request and returns a user. This is exactly how Payload's built-in strategies function.
4242

43+
The example below sets `disableLocalStrategy` to `true` because the custom strategy replaces local authentication. Set it to `false` or omit it to keep email and password authentication enabled alongside your custom strategy.
44+
4345
Your `authenticate` method should return an object containing a Payload user document and any optional headers that you'd like Payload to set for you when we return a response.
4446

4547
```ts

‎docs/authentication/overview.mdx‎

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@ The following options are available:
8888
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
8989
| **`cookies`** | Set cookie options, including `secure`, `sameSite`, and `domain`. For advanced users. |
9090
| **`depth`** | How many levels deep a `user` document should be populated when creating the JWT and binding the `user` to the `req`. Defaults to `0` and should only be modified if absolutely necessary, as this will affect performance. |
91-
| **`disableLocalStrategy`** | Advanced - disable Payload's built-in local auth strategy. Only use this property if you have replaced Payload's auth mechanisms with your own. |
91+
| **`disableLocalStrategy`** | Set to `true` to disable local authentication, `false` (default) to keep it enabled, or an object to retain auth fields while disabling it. [More details](#disable-local-strategy). |
9292
| **`forgotPassword`** | Customize the way that the `forgotPassword` operation functions. [More details](./email#forgot-password). |
9393
| **`lockTime`** | Set the time (in milliseconds) that a user should be locked out if they fail authentication more times than `maxLoginAttempts` allows for. |
9494
| **`loginWithUsername`** | Ability to allow users to login with username/password. [More](/docs/authentication/overview#login-with-username) |
@@ -100,6 +100,27 @@ The following options are available:
100100
| **`useSessions`** | True by default. Set to `false` to use stateless JWTs for authentication instead of sessions. Stateless JWTs cannot be revoked, so they stay valid until `tokenExpiration` even after a password change. |
101101
| **`verify`** | Set to `true` or pass an object with verification options to require users to verify by email before they are allowed to log into your app. [More details](./email#email-verification). |
102102

103+
### Disable Local Strategy
104+
105+
The built-in local strategy authenticates users with an email or username and password. It is enabled by default. Set `disableLocalStrategy` to `true` to disable it, or to `false` to explicitly keep it enabled. Only disable the local strategy if you have configured another authentication method, such as [API keys](./api-keys) or a [custom strategy](./custom-strategies).
106+
107+
You can also pass an object to disable the local strategy while retaining its auth fields:
108+
109+
```ts
110+
{
111+
slug: 'users',
112+
auth: {
113+
disableLocalStrategy: {
114+
enableFields: true,
115+
optionalPassword: true,
116+
},
117+
},
118+
}
119+
```
120+
121+
- `enableFields` retains the local auth fields in the database and generated types.
122+
- `optionalPassword` makes the password field optional when auth fields are retained.
123+
103124
### Login With Username
104125

105126
You can allow users to login with their username instead of their email address by setting the `loginWithUsername` property to `true`.

0 commit comments

Comments
 (0)