SCR-2047: SSL: fall back to the JVM's trust store instead of trusting every certificate if no trust managers are available or the trust level is invalid
SCR-2048: User feedback: pseudonymize users in exports with an HMAC keyed by a configurable secret instead of a plain MD5 hash
SCR-2049: New configuration options for user feedback pseudonyms
ASB-64: Virtual "All my public appointments" collection via CalDAV
SCR-1876: New configuration option for the virtual CalDAV collection "All my public appointments"
ASB-65: Import parameter applyDefaultAlarms to apply the user's own reminders to imported appointments
SCR-1875: New optional parameter applyDefaultAlarms for the iCal import request
ASB-132: Light-weight deputy action=reverseIds listing grantors without resolving grant details
SCR-1844: New deputy module action reverseIds that lists the granting users without resolving grant details
ASB-195: Document and cover the folder operations permitted within a shared account's mail folders
ASB-244: Having the Default Reminder Time Configurable for New Accounts
SCR-1975: New Properties to Configure Default Alarms for Newly Provisioned Calendar Accounts
ASB-251: Enforce anti-virus scans, ICAP over TLS with time-outs, strict verdicts and a scan log
SCR-2000: New configuration options for anti-virus scanning
SCR-2001: Stricter anti-virus verdicts, more scanned downloads and a scan log
PBSR-1689: New Options to Reassign Shared Data When Soft-Deleting a User
Soft user delete: a leaver state between deactivated and deleted (core-gitlab-com#44)
PBSR-1694: Subadmin Provisioning Tests for Shared Accounts and Deputy
PBSR-1874: Register a Cross-Context Liaison for Shared Account Permissions
SCR-1985: Changed behavior of listing the permission holders of a shared account
SCR-1986: New administrative REST endpoints for inspecting the cross-context grant index
SCR-1987: Added the "xctx_grants" Cross-Context Grant Index Table and Create-Table Update Task
PBSR-1882: Login Parameter to Admit an Account That Is Not Enabled
SCR-1845: New Configuration Option for Expanding Nested LDAP Distribution Lists
SCR-1861: Add endpoint that resolves a user for external auth
SCR-1878: Vacation notice can answer internal and external senders differently
SCR-1879: New properties "vacation.internal.enabled" and "vacation.internal.externalTagHeader" for vacation notices treating internal and external senders differently
SCR-1880: Changed behavior of Sieve script parsing: "elsif"/"else" control blocks become branches of a single rule instead of unsupported rules
New optional fields of the vacation action in the mail filter v2 API: the explicit vacationMode names the notice's mode - "all" (the classic rule), "split" (external senders receive the separate subjectExt/textExt) or "internalOnly" (external senders receive no notice). Clients supporting the fields send the mode on every vacation write; a vacation action without it comes from a field-unaware client and preserves an existing extended structure across the otherwise complete replace - only an explicit "all" downgrades. While the feature is unavailable, clients echo the mode they read for an existing extended rule; its modes stay accepted. Invalid mode/field combinations, line breaks in subjectExt and in the legacy subject are rejected with MAIL_FILTER-0044, a second vacation action in one rule with MAIL_FILTER-0045.
The sender class is decided solely by the classifier header the mail platform stamps on every delivered message (property ...options.vacation. internal.externalTagHeader names the header, values are fixed: true = external, false = internal); a message carrying neither value - or both - receives no vacation reply at all, so broken or forged stamping fails closed. The feature is an operator opt-in (...options.vacation.internal. enabled, default false) and announced to clients as vacationInternalAvailable while the vacation action itself is offered. The vacationDomains allowlist covers every branch of extended rules, and the vacationRestrictToAddresses restriction covers every vacation-carrying branch.
Sieve scripts containing elsif/else control blocks now parse into single multi-branch rules instead of unsupported error rules, regardless of the feature toggle, and lone CR line breaks are normalized to CRLF; MailFilterInterceptor implementations must not assume single-branch rules any more (Rule.getBranches/hasMultipleBranches). Hand-written multi-branch rules are read-only through both JSON interfaces: the v2 list action announces that up front via errormsg while the leading branch stays reported, and updates are refused - v2 with MAIL_FILTER-0042 for vacation-carrying rules ("changed outside this application") and MAIL_FILTER-0041 otherwise, v1 with the same pair keyed on the vacation flag, pointing editors of extended vacation rules to an up-to-date client.
SCR-1897: Provisioning tokens that open several contexts at once
SCR-1898: New tables provisioning_token in the context schema and crosscontext_provisioning_token in the configdb
SCR-1940: New command line tool createprovisioningtoken
SCR-1941: New command line tool listprovisioningtokens
SCR-1942: New command line tool revokeprovisioningtoken
SCR-1943: New RMI interface OXProvisioningTokenInterface
SCR-1950: New SOAP service OXProvisioningTokenService
SCR-1966: New command line tool detachprovisioningtoken
SCR-1916: Shared bundle com.openexchange.admin.soap.common and optional contextId for admin SOAP operations - SCR-1916
SCR-1921: Administrative SOAP operations accept a plain contextId, and moveContextFilestore reports the correct fault
Archive the folders of an OpenCloud account as a ZIP file
Documentation of the Nextcloud file storage
Documentation of the OpenCloud file storage
Describes the setup of the storage, its authentication, the mapping of the users and groups, and the differences to the other storages
States that OAuth requires the package open-xchange-oauth in addition to open-xchange-file-storage-webdav, and how the endpoints of an instance that is fronted by an identity provider of its own are configured
Describes what an instance with an identity provider of its own requires, so the claims its own client states and the scopes to request for them
Describes how a search is performed, which criteria it states and that its items are taken from an index
Documents the new properties, the new HTTP API actions for the shares of an item, the additional columns 3250 and 7050, and the managed HTTP client of the storage
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Module access reference article, replacing the stale per-tool documentation of access rights and combinations
OAuth, versioning, trash, sharing and search for the Nextcloud file storage
SCR-1970: New folder type for the virtual folders of a file storage
SCR-1971: New properties matching the users and groups of a Nextcloud instance with the ones of the server
SCR-1981: New properties of the OAuth provider of a Nextcloud instance
SCR-1982: The folders of a Nextcloud account are arranged like the ones of an OpenCloud account
SCR-1983: The Nextcloud file storage supports OAuth, versions, trash, sharing and search
SCR-1984: A Nextcloud account whose credentials the instance rejects states an error
OpenCloud documentation, requirement for user mapping per mail
OpenCloud file storage
Integrates the files of an OpenCloud instance as a file storage of its own, accessing the files through WebDAV and the spaces, shares and permissions of the instance through the libre graph API.
Adds the generated client of the libre graph API as the bundle com.openexchange.opencloud, along with the OAuth provider of an OpenCloud instance as the bundle com.openexchange.oauth.opencloud
States the personal space of the user, the project spaces, the shared items and the trash bins of the spaces within the folders of an account
Expresses the shares of an item as its object permissions, and the ones of a folder as its permissions, resolving the users and groups of the instance to the ones of the server
Authenticates with a username and an app token, or with OAuth, in which case the URL of an account is derived from the configured instance
States the OAuth account an account is linked to as a field of its own, so that the configuration a client states keeps it, and derives the URL of the instance from the configuration for such an account
Searches through the search service of the instance, stating a query that yields the items a search term may match, which are matched exactly afterwards, so that a search covers a folder tree of any depth with a single request
Restores a previous version of a file by copying that version onto it
Reads the collections of the libre graph API page by page, and takes over the listing of a trash bin from item to item
Holds the role definitions and the resolved entities of an instance within the cache of the deployment
States the identifier of a request the instance refused along with the issuer, the party and the audience of the access token that was used, so that a token the instance does not accept can be told apart from one it cannot associate with a user of its own
Requests the scopes that are configured, as the claims an instance needs may only be stated if a further scope asks for them
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
SCR-1856: New file storage service for OpenCloud
SCR-1857: New properties for the OpenCloud file storage
SCR-1860: New setting stating the trash folders of the OpenCloud accounts of a user
Optional deputy right to see the granting user's confidential appointments with all details, granted via the new deputy permission attribute classifiedAccess
SCR-1887: New Attribute classifiedAccess for Deputy Permissions to See Confidential Appointments
SCR-1888: New Element classifiedAccess in the Deputy Permissions of the OXDeputyPermissionsService
SCR-1889: New Field classifiedAccess in the Deputy Permission Data Objects of the Administrative RMI and gRPC Interfaces
SCR-1890: New Column classifiedAccess in Table deputy for the Calendar Deputy Right to See Confidential Appointments
Plural existingSecrets lists for every additive existingSecret value of the core-mw chart
SCR-1989: New plural existing*Secrets list values in the core-mw Helm chart
Search by term in the "My attachments" Mail Drive file storage, pushing file name, size and date criteria down to IMAP
Support for external shares and folder permissions in the file storage framework
Prepares the file storage framework for a storage that expresses its shares and permissions through an API of its own, as the OpenCloud storage does.
States the properties of an external share through the new constants in FileStorageShareConstants, along with the exception codes 82 to 87
Lets an item be shared with or without a file identifier, so that a folder is shared through the same actions as a file
States the shares of a folder and of a file as the additional columns 3250 and 7050
Sorts a merged listing of files by the order it is encountered in if no field to sort by is stated
States one value per item for the columns 3250 and 7050, no matter whether the shares of an item can be looked up, and takes over the access to an account from item to item
Skips the permissions that do not refer to an entity of the server when notifying about the added ones
Collects the folders shared by a user from every storage that serves the requested content type, rather than from a single one
States the account of an external storage within the path of a folder
Stores the expiration of an OAuth account's access token as the time stamp it is expected to be
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
SCR-1858: New actions and columns for the shares of items within external file storages
SCR-1859: Folders shared within an external file storage are stated by the shares action of the folders module
WebDAV search and OAuth support to the WebDAV based file storages
Extends the base of the file storages that are based on WebDAV, so that a storage of its own can build upon it.
Expresses a search term as the WebDAV SEARCH request of a storage that supports it
States the resources a REPORT request answers with, so that a storage whose search is served that way needs no parsing of its own
Lets a storage state the context and the scheme its requests are authenticated with, so that OAuth is used rather than a username and a password
Applies a search term as it is stated, so that every term of an "and" is required, a "not" is negated, and a term that cannot be matched against the names of the resources is rejected rather than ignored
Lets a storage state that its folders are not to be held in the folder cache of the middleware
States the trash folder of a storage that has one within its root folder
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
SCR-1855: New bundles for OpenCloud and new dependency of open-xchange-file-storage-webdav on open-xchange-oauth
WebDAV-Push support for CalDAV/CardDAV clients like DAVx5 via a new Web Push transport
SCR-1953: New bundles for WebDAV-Push: com.openexchange.dav.push and com.openexchange.pns.transport.webpush
SCR-1954: New configuration options for the Web Push transport and WebDAV-Push
Provisioning tokens as bearer credentials for scoped provisioning interfaces (core-gitlab-com#43)
SCR-1897: Added provisioning tokens as bearer credentials for scoped provisioning interfaces
SCR-1898: New tables provisioning_token in the context schema and crosscontext_provisioning_token in the configdb
SCR-1901: Added a SCIM 2.0 service provider for provisioning the users of a context from an identity provider
SCR-1902: New properties com.openexchange.scim.deleteMode, com.openexchange.scim.allowBasicAuth and com.openexchange.scim.allowUnauthenticatedDiscovery
SCR-1903: New table scim_external_id in the context schema
SCR-1904: Added package open-xchange-scim and the chart feature scim
SCR-1907: Added the /Groups endpoint to the SCIM 2.0 service provider
SCR-1908: Added the App Suite user extension to the SCIM 2.0 service provider
SCR-1909: Added resource versions with If-Match and read-only checks to the SCIM 2.0 service provider
SCR-1910: Added JSON Web Tokens as bearer credential to the SCIM 2.0 service provider
SCR-1911: New property com.openexchange.scim.allowJwt
SCR-1912: New property com.openexchange.oauth.provider.jwt.audience; EC and RSA-PSS signatures accepted
SCR-1914: Added the /Resources type and group memberships on users to the SCIM 2.0 service provider
SCR-1917: Completed the App Suite user extension of the SCIM 2.0 service provider: capabilities, clearing by null, driveUserFolderMode, filestoreId
SCR-1918: Added the /SharedAccounts, /Deputies and /SecondaryAccounts types to the SCIM 2.0 service provider
SCR-1931: The SCIM endpoint names its origin in the provisioning log entries and counts its authentications
SCR-1940: New command line tool createprovisioningtoken
SCR-1941: New command line tool listprovisioningtokens
SCR-1942: New command line tool revokeprovisioningtoken
SCR-1943: New RMI interface OXProvisioningTokenInterface
SCR-1950: New SOAP service OXProvisioningTokenService
Soft-deleted user state for leavers between disabled and deleted (core-gitlab-com#44)
SCR-1922: New column softDeleted in the user tables
SCR-1923: Soft-deleting and restoring users over OXUserInterface
SCR-1924: Soft-deleting and restoring users over the OXUserService SOAP interface
SCR-1925: Soft-deleting and restoring users over the provisioning API
SCR-1926: New configuration options for soft-deleted users
SCR-1927: Soft-deleted user state for leavers
SCR-1928: New command line tool softdeleteuser
SCR-1929: New command line tool restoreuser
SCR-1930: New option --soft-deleted for listuser
SCR-1933: Soft-deleted user state visible in the HTTP API
SCR-1939: SCIM: query parameter deleteMode on DELETE /Users/{id} for an immediate hard delete
SCR-1938: Alerting for a failed retention purge of a soft-deleted user
SCR-1937: Audit trail of the user lifecycle: soft-delete, restore, delete and failed purge
SCR-1936: Soft-Deleted Attendees Marked with a Read-Only Extended Parameter in the Calendar HTTP API
SCCR-1944: SCR-1949: SCR-1965: MCP server with contacts, mail and calendar tools behind OAuth or user-minted access tokens (core-gitlab-com#45)
SCR-1945: New MCP server endpoint for read-only access to mail, calendar, contacts, files and tasks
SCR-1949: New package open-xchange-mcp with the bundles of the MCP server
SCR-1965: Drive offers the OAuth scope read_files
SCR-1974: New capabilities access_tokens and mcp
Personal access tokens as user-minted bearer credentials for the OAuth provider (core-gitlab-com#49)
SCR-1946: New HTTP API module accesstoken for personal access tokens
SCR-1947: New table access_token in the context database schema
Push notification topics for changed and deleted mail and changed mail folders (core-gitlab-com#50)
SCR-1977: New parameter pushToken for changing mail requests
SCR-1978: New configuration options for live change events
SCR-1979: New bundle com.openexchange.pns.transport.sse
Command-line tool jfrrecord for on-demand flight recordings (core-gitlab-com#51)
SCR-1980: Added command-line tool jfrrecord for on-demand flight recordings
Send a mail at most once per Idempotency-Key or client message identifier (core-gitlab-com#55)
SCR-1993: New header Idempotency-Key and parameter clientMessageId to send a mail at most once
SCR-1994: New configuration options for sending a mail at most once
Sign in with user name and password for a personal access token (core-gitlab-com#56)
SCR-1991: New login actions accessToken and accessTokenSecondFactor to sign in for a personal access token
SCR-1992: New configuration options for signing in for a personal access token
Mobile API under /mobile/v1 with bearer sign-in, problem details and request helpers (core-gitlab-com#58)
SCR-1995: New Mobile API for native mail apps at /mobile/v1
SCR-1996: New configuration options for the Mobile API
SCR-1997: New package open-xchange-mobile-api and Helm feature mobile-api
ASB-56: Cap autocomplete results and honor right_hand_limit for all sort orders
SCR-1877: New configuration option for contact auto-complete result limiting
ASB-132: Report send-on-behalf-of and the granter's addresses in deputy action=reverseIds
SCR-1844: New deputy module action reverseIds that lists the granting users without resolving grant details
PBSR-1873: Single Administrator Credential for Cross-Context Permission Provisioning
SCR-1963: Shared Account Permissions Across Contexts Require Only the Shared Account's Context Administrator
SCR-1964: Cross-Context Shared Account Permissions Are Subject to the Cross-Context Trust Zones
SCR-1851: Bound the init container's configdb and middleware readiness waits
SCR-1862: Fix the spelling of com.openexchange.mail.prependReplyPrefix and keep the old name working
SCR-1863: Upgraded Netty libraries to v4.2.17 and Lettuce to v7.7.0
SCR-1864: Upgraded BouncyCastle, Jackson, PDFBox, jsoup, HttpClient5, FreeMarker, Commons Codec and snappy-java in target platform
SCR-1865: Upgraded commons-collections4, commons-validator, javassist, jctools, joda-time, jakarta.validation-api, xmlunit, protobuf-java, HK2, GlassFish CORBA and Logback in target platform
SCR-1866: Upgraded Kotlin OSGi bundle and Equinox Configuration Admin in target platform, added the OSGi Coordinator API
SCR-1867: Upgraded MySQL Connector/J from 9.7.0 to 26.7.0 in target platform
SCR-1868: Upgraded logback-extensions to 3.0.8, custom fields now use nested elements
SCR-1869: Upgraded Logback from 1.5.38 to 1.6.3 in target platform
SCR-1870: Upgraded Jackrabbit WebDAV from 2.21.19 to 2.22.4 in target platform
SCR-1881: Omit the database password from provisioning responses in the HTTP API, SOAP and listdatabase --csv
SCR-1882: Require credentials for provisioning read operations and fix the defects found while documenting the API
SCR-1883: Create the "Collected addresses" folder on the first collected contact instead of at login
SCR-1891: Upgraded the embedded TwelveMonkeys, CXF, Google API, Jetty and OkHttp libraries
SCR-1893: Upgraded 26 embedded third-party libraries across 20 bundles
SCR-1894: Upgraded the Kotlin OSGi bundle from 2.4.10 to 2.4.20
SCR-1895: Upgraded the embedded SAAJ implementation from 2.0.1 to 3.0.6
SCR-1896: Upgraded the embedded S3 encryption client from 3.6.1 to 4.0.2
SCR-1899: Upgraded eight third-party libraries to their latest patch or minor release
SCR-1905: Upgraded Apache Tika from 3.3.1 to 4.0.0
SCR-1913: Upgraded the Bean Validation API from 1.1.0.Final to 2.0.1.Final
SCR-1915: Resource permissions are returned by getData, validated in simple mode and compared by value in the provisioning API
SCR-1919: Removing the calendar access of a shared account permission is persisted when the permission has no mail access
SCR-1920: Upgraded the Equinox OSGi framework from 3.24.200 to 3.24.300 and dropped the superseded OSGi annotation bundle
SCR-1934: Remove the experimental streaming operation mode of the Anti-Virus service
SCR-1967: Add authentication and TLS configuration for the Cassandra connection
SCR-1973: Consult every configured trust store, not just the first one
SCR-1998: Run virtual threads on more carrier threads than CPU cores, so that threads loading classes cannot pin them all
SCR-2006: Reject Own-Object Rights in Cross-Context Folder Permissions
Keep Migrated Legacy Task Data Read-Only
Read the API URL of an OAuth provider through the configuration cascade
Introduces the default method API.getURL(Session), which states the URL of a provider as it applies to the user of a session, the no-argument variant staying the one that states the URL of the server. Only a provider whose URL is configurable implements it, so the other providers are unaffected
Lets OAuthUtil.handleScribeOAuthException state the URL of the session's user, that being the only place the URL is read and one that holds a session, so the host an untrusted certificate is reported for is the one the user actually connects to
Reads the hostname of the OpenCloud instance through the LeanConfigurationService in OpenCloudAPI, so through the configuration cascade rather than per server, and drops its hardcoded "127.0.0.1" fallback in favor of the default value of the property
Serve complete contacts from the LDAP provider's cache if all mapped fields are cached
State no OAuth for OpenCloud for a user the credentials are not configured for
The credentials of the provider need not be configured for the server, so they may be configured for a certain context or user only, or not at all in a deployment that does not integrate an OpenCloud instance. They are evaluated along with the "enabled" property when the capability of the provider is checked from now on, so a user they are not configured for is stated to have no OAuth for OpenCloud rather than being offered one whose authorization would fail on an empty client identifier or secret.
Strip redundant leading and trailing wildcards from file search patterns so that every storage matches them
Take the link back into an OpenCloud instance from the private link of an item
An instance states the URL that opens an item within its web interface twice: as the "oc:privatelink" property of the item's WebDAV resource, and as the "webUrl" property of its drive item. Only the latter was taken, which an instance of version 5.2 states for a space, but not for an item, so that no link was stated for an item at all there.
Requests "oc:privatelink" along with the "oc:fileid" the resource of the item is looked up by anyway, and takes the link from it, so that the link needs no request of its own. The item of the libre graph API is only asked for if the instance states no private link
Keeps "webUrl" as the fallback, so that an instance that states no private link is served by it nevertheless
Leaves the items of a trash bin with the URL of their space, the trash bin of a space stating no private link
Use 'io.ox/files//opencloud/folder/trash' jslob path
Align the active-task watcher with the request watcher (core-gitlab-com#26)
SCR-1849: New configuration options for the thread pool's active-task watcher
SCR-1850: Changed reporting of long-running tasks by the thread pool's active-task watcher
Make the thread pool's saturation semantics effective and observable (core-gitlab-com#27)
SCR-1847: Changed behavior of the thread pool saturation settings
SCR-1848: New thread pool saturation metrics
Give AJAX job-queue jobs their own virtual-thread budget instead of the shared one (core-gitlab-com#28)
SCR-1841: New configuration option for the AJAX job queue
Accept a schema URN as PATCH path, answer unknown SCIM endpoints with an error document and declare the required mailbox address (core-gitlab-com#43)
SCR-1932
Withhold every share of a soft-deleted user from every other user while the state lasts (core-gitlab-com#44)
SCR-1935: Shares of a soft-deleted user are frozen for every other user
Answer an over-sized request body in the protocol, the same way on both paths (core-gitlab-com#45)
SCR-1972: An over-sized MCP request body is refused with a JSON-RPC error instead of an empty 413
Central mail credential vault for scheduled mail, snoozed mail, data export and push (core-gitlab-com#46)
SCR-1952: New tables mail_credential and mail_credential_migration
SCR-1955: New configuration options for the mail credential vault's token exchange
SCR-1961: Permanent push keeps its credential in the mail credential vault, persisted regardless of com.openexchange.push.credstorage.rdb
ASB-18: Calendar colors set via CalDAV were lost on every other change and could not be set on shared calendars
ASB-19: Give guest_created_by its own column 627 instead of clashing with yomiFirstName
SCR-1874: Moved the user field guest_created_by from column 616 to column 627
ASB-21: Register late-looked-up mailboxes with their actual subscription state instead of LIST-only
ASB-22: Let the folder's create-objects permission suffice for importing iCal data
ASB-25: Report the server's refusal when moving a mail folder into a shared mailbox is denied
ASB-38: Refuse synchronization of ignored paths like the temporary .drive folder
ASB-67: Propagate renamed user categories to contacts, tasks and appointments
ASB-100: Keep a mailbox accessible when the mail server only did not finish indexing in time
ASB-119: Leave \Draft flags untouched when a draft is copied or moved into a foreign folder
ASB-146: Isolate a failing mail account from account status and folder listing
ASB-148: Parse a multipart body that lost its start boundary instead of failing the whole mail
ASB-162: Parse mail filter rule metadata for non-IPv4 update sources and heal polluted rule names
ASB-171: Gate deputy modules on the sharing permission and keep permissions removable
ASB-175: ASB-175: Optionally use the configured no-reply address as From for internal calendar notifications
SCR-1854: New property com.openexchange.calendar.useNoReplyAddressForNotifications
ASB-179: Bind OXTaskManagement again so the jobcontrol CLI works
ASB-180: Apply the configured batch sizes when moving a context and keep its idle connections alive
ASB-181: Drop the cached database assignment when a failed context move is reverted
ASB-185: Let an attendee reply from the mail module to an appointment in an inaccessible public folder
ASB-189: Keep the bearer token alive across the WebDAV auth cache round trip
ASB-190: Keep a user's SMS tokens in one cluster map entry instead of scanning the whole Redis key space to count them
ASB-192: Reload lean reloadables when a configuration file they declared interest in changes
ASB-194: OIDC login declined for a disabled user or context strands the user on a dead-end 403 page
SCR-1886: Readable 403 page for OpenID Connect logins declined because the user or context is disabled
ASB-197: Use the organizer's own address as sender of scheduling mails
ASB-199: CSV contact import drops columns whose name belongs to another CSV flavor
ASB-204: Keep a custom common name of an internal organizer when persisting an event, regardless of whether an alias or the default address is used
ASB-205: Remove the Dovecot Push registration when the owning session ends
SCR-1900: New lean configuration property com.openexchange.push.dovecot.unregisterOnMissingSession
ASB-207: Repair broken internal links in the middleware documentation
ASB-208: CalDAV DELETE on a shared calendar did not unsubscribe the user
ASB-209: Encapsulate a well-formed, terminated res-hdr in ICAP RESPMOD requests
ASB-212: Spell out the Gotenberg liveness and readiness probe timings
ASB-215: Update the shipped Grafana and Zabbix dashboards to the renamed gauges
ASB-216: Declare the foreign-key-dropping update tasks as dependencies of the folder permission primary key restructuring
ASB-221: Drop quotes surrounding an address, as Outlook writes them, when they render it invalid
ASB-222: Keep the calendar user when an update turns a single-user appointment into a meeting
ASB-232: Keep the user's own signatures listed when a shared account's snippets are inaccessible
ASB-233: Name the time zone in scheduling and reminder mails after the event's daylight saving state
ASB-234: Walk the folder tree once when cascading Infostore permissions and let long cascades run as a job
ASB-235: Keep drive file checksums calculated before a sync is aborted
ASB-237: Declare the permission-context column update task as a dependency of the guest permission downscoping
ASB-238: Let a file storage service that cannot state its accounts not fail the whole account and root folder listing
ASB-240: Draw schema numbers outside the creating transaction so a retried creation never reuses an orphaned name
ASB-251: Never hand session cookies, credentials or the request's own Content-Length to the anti-virus service
ASB-252: Copying a user fails for attachments that reference an external URI instead of a stored file
PBSR-1874: Reclaim Cross-Context Liaisons of Deleted Sharing Contexts
SCR-1853: Keep the deputy mail ACL baseline in its own table and fix the surrounding METADATA handling
A client-provided file name made zip_messages produce an empty archive
Add an OpenCloud account that authenticates with credentials rather than with an OAuth account
Every field of the form description of the storage was stated as a mandatory one: the field for the OAuth account along with the ones the WebDAV based storages state for the credentials and the URL. A client that honors the description could therefore add no account at all, an account that states credentials missing the OAuth account, and one that is linked to an OAuth account missing the credentials and the URL.
States none of the fields as a mandatory one, as it depends on the way an account authenticates which of them it states. Which ones an account needs is checked when it is accessed, so an account that misses one is answered with a missing configuration then
Takes a copy of the inherited fields over rather than adjusting them, the form description of the WebDAV based storages sharing its fields with the storages that build upon it
Added missing 'BACKWARD_LINK' capability to OpenCloud file storage
Allow organizer reassignment when the current organizer has no calendar access
Apply the init container's hazelcast join override after the configuration is rendered
Do not announce IGNORABLE_VERSION capability for OpenCloud
Match the single-character wildcard of a search pattern within the OpenCloud file storage
Lets OpenCloudSearchFilterVisitor match a "?" of a pattern against a single character, as an OpenCloud instance does. It was matched literally before, and a pattern that stated no "*" besides was not even recognized as a pattern, so an item was only found if its name held a "?" itself
Rewrites the translation of a pattern into a regular expression around the two wildcards, quoting everything between them, so that a pattern may still state characters that mean something within a regular expression
Leaves a media type that states a "?" out of the query, just like one that states a "*", the instance matching an exact media type only. Stating it would let the query yield less than the search term matches, which the query is built never to do
Pass the virtual folders of a file storage over when a folder is archived
Reading an Event Without an Organizer Fails With a NullPointerException
Resolve image URLs independent of the configured dispatcher prefix
Start an OAuth provider up whose properties are configured through the configuration cascade only
A property of a provider was required to be configured for the server, an unconfigured one keeping the bundle of that provider from starting up at all, stating e.g. a missing "apiKey" property. That holds no longer: every property of a provider is read through the configuration cascade whenever it is asked for, so it may well be configured for a certain context or user only, and a provider that is registered no matter whether it is enabled has none of its properties configured in a deployment that does not use it.
An unconfigured property is taken over as empty from now on, along with a warning naming it, so that the provider is set up nevertheless and states its properties as they are configured for the user they are asked for.
State it towards the user if an OpenCloud instance offers no link back into its web interface
The link that opens an item within the web interface of an OpenCloud instance is the one the instance states for the item itself, which it cannot compose unless it knows the URL it is published under. An instance that states none, just like an item that has no counterpart within the instance at all, let the storage state that its service does not support the operation: an error that names neither the instance nor the reason, and that is logged as an error although nothing failed on the server.
Introduces FILE_STORAGE-0088, which names the instance that offers no link and is stated towards the user, its category being the one of a user input so that it is logged at debug level rather than as an error
States the host of the instance the account refers to along with it, taken from the URL of the account, falling back to that URL and to the display name of the account
States it for the virtual folders of an account as well, so for the ones listing the spaces, the shared items and the trash bins, which have no counterpart to point to either
State the media type of the files of a WebDAV file storage
Unbounded Retry Loop in the Contacts Account Storage Operation
Refresh a session's OAuth tokens before mail access uses them outside of HTTP requests, e.g. for IMAP-IDLE (core-gitlab-com#36)
Drop the registration and release the cluster lock of an IMAP-IDLE listener that failed to start, was canceled after a severe error or is stopped on shutdown (core-gitlab-com#38)
Route an OIDC login declined for an unknown or expired session reservation through the exception handler and keep internal wording out of the bad-request pages (core-gitlab-com#41)
Skip the bcrypt check for a recently verified master password on provisioning calls and expose the authentication duration as a metric (core-gitlab-com#42)
SCR-1892: New configuration option for caching the master administrator's password verification on provisioning calls
Delete a folder's contacts within the folder transaction, including an on-demand contacts trash folder (core-gitlab-com#47)
IMAP-IDLE push no longer logs an error for primary accounts that are not IMAP (core-gitlab-com#50)
Charsets now reach Charset.forName() without patching JDK internals (core-gitlab-com#52)
Fail a schema dump loudly and refuse to re-point contexts to a schema that does not hold their data (support#1607)