Commit Graph

23249 Commits

Author SHA1 Message Date
dependabot[bot]
d88bb3ed09 core: bump clap from 4.6.3 to 4.6.4 (#24401)
Bumps [clap](https://github.com/clap-rs/clap) from 4.6.3 to 4.6.4.
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md)
- [Commits](https://github.com/clap-rs/clap/compare/clap_complete-v4.6.3...clap_complete-v4.6.4)

---
updated-dependencies:
- dependency-name: clap
  dependency-version: 4.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:31:05 +01:00
dependabot[bot]
f4599a0179 core: bump django-filter from 25.2 to 26.1 (#24386)
Bumps [django-filter](https://github.com/carltongibson/django-filter) from 25.2 to 26.1.
- [Release notes](https://github.com/carltongibson/django-filter/releases)
- [Changelog](https://github.com/carltongibson/django-filter/blob/main/CHANGES.rst)
- [Commits](https://github.com/carltongibson/django-filter/compare/25.2...26.1)

---
updated-dependencies:
- dependency-name: django-filter
  dependency-version: '26.1'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:30:31 +01:00
dependabot[bot]
bbf2d8a080 core: bump cachetools from 7.1.4 to 7.1.6 (#24387)
Bumps [cachetools](https://github.com/tkem/cachetools) from 7.1.4 to 7.1.6.
- [Changelog](https://github.com/tkem/cachetools/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/tkem/cachetools/compare/v7.1.4...v7.1.6)

---
updated-dependencies:
- dependency-name: cachetools
  dependency-version: 7.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:30:15 +01:00
dependabot[bot]
0ed162f17e core: bump pnpm/pnpm from 11.15.1 to 11.17.0 in /lifecycle/container (#24392)
Bumps pnpm/pnpm from 11.15.1 to 11.17.0.

---
updated-dependencies:
- dependency-name: pnpm/pnpm
  dependency-version: 11.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:30:05 +01:00
dependabot[bot]
e40b0cf2d4 core: bump tokio from 1.52.4 to 1.53.0 (#24400)
Bumps [tokio](https://github.com/tokio-rs/tokio) from 1.52.4 to 1.53.0.
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](https://github.com/tokio-rs/tokio/compare/tokio-1.52.4...tokio-1.53.0)

---
updated-dependencies:
- dependency-name: tokio
  dependency-version: 1.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:29:54 +01:00
dependabot[bot]
40ff96a6d7 core: bump glob from 0.3.3 to 0.3.4 (#24402)
Bumps [glob](https://github.com/rust-lang/glob) from 0.3.3 to 0.3.4.
- [Release notes](https://github.com/rust-lang/glob/releases)
- [Changelog](https://github.com/rust-lang/glob/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rust-lang/glob/compare/v0.3.3...v0.3.4)

---
updated-dependencies:
- dependency-name: glob
  dependency-version: 0.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:29:32 +01:00
dependabot[bot]
c39e8794c0 core: bump tokio-util from 0.7.18 to 0.7.19 (#24403)
Bumps [tokio-util](https://github.com/tokio-rs/tokio) from 0.7.18 to 0.7.19.
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](https://github.com/tokio-rs/tokio/compare/tokio-util-0.7.18...tokio-util-0.7.19)

---
updated-dependencies:
- dependency-name: tokio-util
  dependency-version: 0.7.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:29:08 +01:00
dependabot[bot]
936bae0b59 ci: bump github/codeql-action/analyze from 4.37.2 to 4.37.3 (#24397)
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.2 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:28:49 +01:00
dependabot[bot]
e928201814 ci: bump github/codeql-action/autobuild from 4.37.2 to 4.37.3 (#24394)
Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 4.37.2 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

---
updated-dependencies:
- dependency-name: github/codeql-action/autobuild
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:28:36 +01:00
dependabot[bot]
2886d520f6 ci: bump aws-actions/configure-aws-credentials from 6.2.2 to 6.2.3 (#24395)
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.2 to 6.2.3.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:28:28 +01:00
dependabot[bot]
9b8b1b2fd8 ci: bump github/codeql-action/init from 4.37.2 to 4.37.3 (#24398)
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.2 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:28:21 +01:00
dependabot[bot]
ea215b04a5 ci: bump taiki-e/install-action from 2.84.0 to 2.85.0 in /.github/actions/setup (#24399)
ci: bump taiki-e/install-action in /.github/actions/setup

Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.84.0 to 2.85.0.
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](a6b2e2dcd8...7572810d7d)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.85.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:28:16 +01:00
dependabot[bot]
24e5bae617 core: bump quinn-proto from 0.11.14 to 0.11.16 in the cargo group across 1 directory (#24370)
core: bump quinn-proto in the cargo group across 1 directory

Bumps the cargo group with 1 update in the / directory: [quinn-proto](https://github.com/quinn-rs/quinn).


Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](https://github.com/quinn-rs/quinn/compare/quinn-proto-0.11.14...quinn-proto-0.11.16)

---
updated-dependencies:
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-25 22:48:32 +01:00
Jens L.
81e05e2964 enterprise/providers/ssf: log event user when sending SSF event (#24359)
* enterprise/providers/ssf: log event user when sending SSF event

* also log event type
2026-07-25 15:06:30 +01:00
Jens L.
d3cc08d6b5 enterprise/endpoints/connectors/fleet: fix exception when host has no policies (#24355) 2026-07-25 14:57:57 +01:00
Ryan Pesek
328ccafacf providers/scim: fix scim changed detection for nested attributes (#24332)
fix scim changed detection for nested attributes

Co-authored-by: Jens L. <jens@goauthentik.io>
2026-07-25 13:07:13 +01:00
Dominic Roy
658ee6062b core: validate imported password hashes at the API boundary (#24130)
* core: validate imported password hashes at API boundary

* core: Gergo says to not restrict blueprint hashes

* core: move to authentik.lib.validators and use as validator

* core: validate bootstrap hashes independently of blueprints
2026-07-24 15:47:32 -04:00
Ryan Pesek
05128dd1b2 core/groups: fix n+1 queries for list groups when include_users=false (#23216)
* fix n+1 queries for list groups when include_users=false

* add test for unpaginated branch

---------

Co-authored-by: Simonyi Gergő <28359278+gergosimonyi@users.noreply.github.com>
2026-07-24 18:38:50 +02:00
Amélie-Laura Lilith Krejčí
e36c628342 sources/ldap: implement nested group parentship sync (#19069)
* sources/ldap: add sync_group_parentage field

* sources/ldap: regenerate schema after adding field

* sources/ldap: add group parentage synchronizer

* web/admin: add LDAP source toggle for sync_group_parentage

* sources/ldap: rename LDAPSource fields to more accurate names

* web/admin: update admin UI with new field names

Also added better descriptions to all relevant fields, explaining how they interact with each other.

* sources/ldap: add unit tests

* sources/ldap: fix problem discovered by test

* sources/ldap: lint

* web/admin: lint

* website/docs: update LDAP source docs about lookup fields & membership

* sources/ldap: fix renamed attributes

* web/admin: make web

* sources/ldap: update tests and entries.json fixture

* sources/ldap: update migration with current help_text

* sources/ldap: fix lint error

* sources/ldap: restore membership.py to main, with renamed fields

in prep for separating out the synchronizers

* sources/ldap: abstract get_group into BaseMembershipLDAPSynchronizer

* sources/ldap: add separate ParentshipLDAPSynchronizer

* sources/ldap: fix wrong attribute name in extra parents filtering

* remove renames

* rename `sync_group_parents` to `sync_group_hierarchy`

* set `sync_group_hierarchy` default to `False`

This is a breaking change if it's `True`. It should be changed
eventually, but not in this release.

* revert pagination function change

I'm not entirely sure why, but this change hangs the test
`test_membership_sync_special_chars_in_group_dn`.

* add `sync_group_hierarchy` guard to hierarchy sync

* simplify hierarchy sync

* reword group `parentship` to `hierarchy`

* fix lint

* remove dead code

* move `syncGroupHierarchy` toggle next to similar toggles

---------

Co-authored-by: Simonyi Gergő <28359278+gergosimonyi@users.noreply.github.com>
Co-authored-by: Simonyi Gergő <gergo@goauthentik.io>
2026-07-24 18:04:38 +02:00
Jens L.
b32135975f website/integrations: fix favicon (#24354)
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
2026-07-24 15:14:35 +01:00
authentik-automation[bot]
d80647b165 core, web: update translations (#24331)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-24 14:58:57 +02:00
Emil Burzo
b233d487bb core, web, docs: introduce base URL (#24159) 2026-07-24 12:33:08 +00:00
dependabot[bot]
9e65f793d8 core: bump openapitools/openapi-generator-cli from v7.22.0 to v7.24.0 in /packages/client-ts (#24337)
* core: bump openapitools/openapi-generator-cli in /packages/client-ts

Bumps openapitools/openapi-generator-cli from v7.22.0 to v7.24.0.

---
updated-dependencies:
- dependency-name: openapitools/openapi-generator-cli
  dependency-version: v7.24.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* gen

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jens Langhammer <jens@goauthentik.io>
2026-07-24 12:26:49 +01:00
dependabot[bot]
d775263cca core: bump openapitools/openapi-generator-cli from v7.23.0 to v7.24.0 in /packages/client-go (#24335)
* core: bump openapitools/openapi-generator-cli in /packages/client-go

Bumps openapitools/openapi-generator-cli from v7.23.0 to v7.24.0.

---
updated-dependencies:
- dependency-name: openapitools/openapi-generator-cli
  dependency-version: v7.24.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* gen

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jens Langhammer <jens@goauthentik.io>
2026-07-24 12:19:03 +01:00
dependabot[bot]
124b98c295 core: bump openapitools/openapi-generator-cli from v7.23.0 to v7.24.0 in /packages/client-rust (#24336)
core: bump openapitools/openapi-generator-cli in /packages/client-rust

Bumps openapitools/openapi-generator-cli from v7.23.0 to v7.24.0.

---
updated-dependencies:
- dependency-name: openapitools/openapi-generator-cli
  dependency-version: v7.24.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:36:17 +01:00
dependabot[bot]
02ac33937c ci: bump github/codeql-action/autobuild from 4.37.1 to 4.37.2 (#24343)
Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 4.37.1 to 4.37.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](7188fc3636...e0647621c2)

---
updated-dependencies:
- dependency-name: github/codeql-action/autobuild
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:35:55 +01:00
dependabot[bot]
b8bd0cd7c7 ci: bump github/codeql-action/init from 4.37.1 to 4.37.2 (#24349)
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.1 to 4.37.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](7188fc3636...e0647621c2)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:35:45 +01:00
dependabot[bot]
d8f3f1366d ci: bump astral-sh/setup-uv from 8.3.2 to 9.0.0 in /.github/actions/setup (#24350)
ci: bump astral-sh/setup-uv in /.github/actions/setup

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](11f9893b08...c771a70e62)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:35:36 +01:00
dependabot[bot]
716c005d91 core: bump axllent/mailpit from v1.30.4 to v1.30.5 in /tests/e2e (#24338)
Bumps axllent/mailpit from v1.30.4 to v1.30.5.

---
updated-dependencies:
- dependency-name: axllent/mailpit
  dependency-version: v1.30.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:49 +01:00
dependabot[bot]
2b7b941b35 core: bump types-jwcrypto from 1.5.7.20260518 to 1.5.8.20260720 in the types group (#24339)
core: bump types-jwcrypto in the types group

Bumps the types group with 1 update: [types-jwcrypto](https://github.com/python/typeshed).


Updates `types-jwcrypto` from 1.5.7.20260518 to 1.5.8.20260720
- [Commits](https://github.com/python/typeshed/commits)

---
updated-dependencies:
- dependency-name: types-jwcrypto
  dependency-version: 1.5.8.20260720
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: types
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:45 +01:00
dependabot[bot]
5be4bf6685 core: bump astral-sh/uv from 0.11.29 to 0.11.30 in /lifecycle/container (#24340)
Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.11.29 to 0.11.30.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/uv/compare/0.11.29...0.11.30)

---
updated-dependencies:
- dependency-name: astral-sh/uv
  dependency-version: 0.11.30
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:41 +01:00
dependabot[bot]
7460ee49bb core: bump geoip2 from 5.2.0 to 5.3.0 (#24341)
Bumps [geoip2](https://github.com/maxmind/GeoIP2-python) from 5.2.0 to 5.3.0.
- [Release notes](https://github.com/maxmind/GeoIP2-python/releases)
- [Changelog](https://github.com/maxmind/GeoIP2-python/blob/main/HISTORY.rst)
- [Commits](https://github.com/maxmind/GeoIP2-python/compare/v5.2.0...v5.3.0)

---
updated-dependencies:
- dependency-name: geoip2
  dependency-version: 5.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:36 +01:00
dependabot[bot]
2580304295 core: bump constructs from 10.7.0 to 10.7.1 (#24342)
Bumps [constructs](https://github.com/aws/constructs) from 10.7.0 to 10.7.1.
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.0...v10.7.1)

---
updated-dependencies:
- dependency-name: constructs
  dependency-version: 10.7.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:32 +01:00
dependabot[bot]
84f1f5ba84 core: bump sentry-sdk from 2.65.0 to 2.66.0 (#24344)
Bumps [sentry-sdk](https://github.com/getsentry/sentry-python) from 2.65.0 to 2.66.0.
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getsentry/sentry-python/compare/2.65.0...2.66.0)

---
updated-dependencies:
- dependency-name: sentry-sdk
  dependency-version: 2.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:25 +01:00
dependabot[bot]
39664364cb core: bump serde_json from 1.0.150 to 1.0.151 (#24345)
Bumps [serde_json](https://github.com/serde-rs/json) from 1.0.150 to 1.0.151.
- [Release notes](https://github.com/serde-rs/json/releases)
- [Commits](https://github.com/serde-rs/json/compare/v1.0.150...v1.0.151)

---
updated-dependencies:
- dependency-name: serde_json
  dependency-version: 1.0.151
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:21 +01:00
dependabot[bot]
6f0bafabea core: bump clap from 4.6.2 to 4.6.3 (#24346)
Bumps [clap](https://github.com/clap-rs/clap) from 4.6.2 to 4.6.3.
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md)
- [Commits](https://github.com/clap-rs/clap/compare/clap_complete-v4.6.2...clap_complete-v4.6.3)

---
updated-dependencies:
- dependency-name: clap
  dependency-version: 4.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:17 +01:00
dependabot[bot]
054d77a6c1 ci: bump github/codeql-action/analyze from 4.37.1 to 4.37.2 (#24347)
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.1 to 4.37.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](7188fc3636...e0647621c2)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:13 +01:00
dependabot[bot]
e29db8aed1 core: bump time from 0.3.53 to 0.3.54 (#24348)
Bumps [time](https://github.com/time-rs/time) from 0.3.53 to 0.3.54.
- [Release notes](https://github.com/time-rs/time/releases)
- [Changelog](https://github.com/time-rs/time/blob/main/CHANGELOG.md)
- [Commits](https://github.com/time-rs/time/compare/v0.3.53...v0.3.54)

---
updated-dependencies:
- dependency-name: time
  dependency-version: 0.3.54
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 11:34:09 +01:00
Jens L.
f429aeac95 endpoints/connectors/agent: fix auth schema correctly (#24327)
* endpoints/connectors/agent: fix auth schema correctly

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* oops

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* gen

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

---------

Signed-off-by: Jens Langhammer <jens@goauthentik.io>
2026-07-23 22:57:55 +01:00
Jens L.
bf9159c3b9 core: adjust label for clarity for core_default_app_access (#24326) 2026-07-23 19:59:33 +01:00
Ken Sternberg
f6e4c5f2fb web/admin: QOL: Add "Expiring in n days" and "Expiring today" notices to LicenseStatusCard (#24300)
* Some revisions to the enterprise status card.

* web/maint: clean-up ak-enterprise-status-card

## What

This commit updates ak-enterprise-status-card with the following improvements:

- `@state()` replaced with `@property({ attribute: false })`, which gets us better linting and typechecking for client code
- `renderSummaryBadge()` uses a map expression instead of switch statement. Removes some boilerplate and clutter
- Slightly adjusted some margins, cleaning up the card. It’s a little shorter now, too.
- Fixed some misconceptions around what `msg(str` actually does. The remaining `msg` strings are all that lit-localize actually uses.
- Duplicate progress bars replaced with a single function that does the percentage and severity in a new scope, creating a tighter and more visually appealing codebase.
- Includes a complete Storybook story file with multiple stories for Valid, Expiring, Exceeded, Unlicensed and Loading

## Why

This mostly started as a test-case for ak-progress-bar. I needed a case where I could see the progress bar in use, and we didn’t have many of them. I decided to add a Storybook story for the Enterprise Status card, because it was a standalone component that used two of them, so it would be a good place to see how they looked stacked one atop another.

While I was rigging the Storybook, the linter complained that `@state()` wasn’t appropriate for properties that were being passed to the component. So I cleaned those. While trying to balance the whitespace around the `∞` symbol, I got frustrated with all the repetition and unbalanced code, and, well, things sorta spiraled out from there.

Anyway, it’s nicer now.

* Noticed a typo; prettier had an opinion.

* Another typo.

* The severities ought to be in order, otherwise it's a mental pause.

* The language between licensed and isLicensed was confusing, so internally the progressBar expression uses 'allowed' for the number of licensed users, and 'licensed' for the overall state of the product.

* Adding the '@file' comment.

* web/admin: QOL: Add “Expiring in `n` days” and “Expiring today” notices to LicenseStatusCard

This was pretty straightforward, and it’s a nice thing that people will notice.

Updated the Storybook stories: for the sake of testability, the dates are stable with respect to the current date: “Expiring Soon” is always 14 days out and “Expiring Today” is always 12 hours out.

* Some revisions to the enterprise status card.

* web/maint: clean-up ak-enterprise-status-card

## What

This commit updates ak-enterprise-status-card with the following improvements:

- `@state()` replaced with `@property({ attribute: false })`, which gets us better linting and typechecking for client code
- `renderSummaryBadge()` uses a map expression instead of switch statement. Removes some boilerplate and clutter
- Slightly adjusted some margins, cleaning up the card. It’s a little shorter now, too.
- Fixed some misconceptions around what `msg(str` actually does. The remaining `msg` strings are all that lit-localize actually uses.
- Duplicate progress bars replaced with a single function that does the percentage and severity in a new scope, creating a tighter and more visually appealing codebase.
- Includes a complete Storybook story file with multiple stories for Valid, Expiring, Exceeded, Unlicensed and Loading

## Why

This mostly started as a test-case for ak-progress-bar. I needed a case where I could see the progress bar in use, and we didn’t have many of them. I decided to add a Storybook story for the Enterprise Status card, because it was a standalone component that used two of them, so it would be a good place to see how they looked stacked one atop another.

While I was rigging the Storybook, the linter complained that `@state()` wasn’t appropriate for properties that were being passed to the component. So I cleaned those. While trying to balance the whitespace around the `∞` symbol, I got frustrated with all the repetition and unbalanced code, and, well, things sorta spiraled out from there.

Anyway, it’s nicer now.

* Noticed a typo; prettier had an opinion.

* Another typo.

* The severities ought to be in order, otherwise it's a mental pause.

* The language between licensed and isLicensed was confusing, so internally the progressBar expression uses 'allowed' for the number of licensed users, and 'licensed' for the overall state of the product.

* Adding the '@file' comment.

* web/admin: QOL: Add “Expiring in `n` days” and “Expiring today” notices to LicenseStatusCard

This was pretty straightforward, and it’s a nice thing that people will notice.

Updated the Storybook stories: for the sake of testability, the dates are stable with respect to the current date: “Expiring Soon” is always 14 days out and “Expiring Today” is always 12 hours out.

* Adjusting to the current mergestorm.

* Fixed linting issue. Maybe the CI/CD gods will be satisfied.

* Of course prettier has opinions.

* Removed duplicate comment. Damned merge bugs.
2026-07-23 09:50:59 -07:00
Dominic Roy
020fe6d5e7 stages/authenticator: protect devices from stage deletion (#24324)
* stages/authenticator: protect devices from stage deletion

Deleting an SMS, email, Duo, or GDTC authenticator stage currently cascades into its associated devices or connections, allowing an administrator to unintentionally remove enrolled authenticators.

* Remove deprecated
2026-07-23 16:16:50 +00:00
Dominic Roy
9478a91a87 core: prompt securely when hashing passwords (#24126)
* core: prompt securely when hashing passwords

* Be More Functional.

* Emil.

* website/docs: clarify password automation guidance

* core: simplify password hash command usage

* Simplify

* fix test
2026-07-23 12:03:37 -04:00
Dominic Roy
f0c5345ca9 events: show account changes in user event history (#24323)
User model updates are recorded with the affected user in the event's model context, while the User events tab currently filters only by actor or top-level username.

As a result, administrator actions such as activating or deactivating an account appear in Events > Logs but not in that account’s event history.

Extend the existing username filter to recognize User model context by
its complete app, model, and PK identity.

Closes #24315
2026-07-23 14:54:36 +00:00
Dominic Roy
89d5242b7c website/integrations: The Lounge: cleanup (#23628)
* website/integrations: The Lounge: cleanup

Signed-off-by: Dominic Roy <dominic@goauthentik.io>
Agent-thread: https://koala.sdko.net/th?h=co&d=a7k&t=019f241f-3fc9-7ad1-b347-061342e3e778
Co-authored-by: Agent <gptagent@svc.sdko.net>

* Update website/integrations/chat-communication-collaboration/thelounge/index.md

Signed-off-by: Dewi Roberts <dewi@goauthentik.io>

---------

Signed-off-by: Dominic Roy <dominic@goauthentik.io>
Signed-off-by: Dewi Roberts <dewi@goauthentik.io>
Co-authored-by: Agent <gptagent@svc.sdko.net>
Co-authored-by: Dewi Roberts <dewi@goauthentik.io>
2026-07-23 13:52:30 +00:00
dependabot[bot]
6c2caaa795 ci: bump taiki-e/install-action from 2.83.4 to 2.84.0 in /.github/actions/setup (#24312)
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 13:47:01 +00:00
Emil Burzo
3d54bd41ec ci: add working dir prefix to file paths (#24319) 2026-07-23 16:38:09 +03:00
authentik-automation[bot]
eb5419d3ff core, web: update translations (#24304)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-23 15:36:10 +02:00
Marc 'risson' Schmitt
5f6b68d182 packages/ak-common/tracing: make console subscriber optional (#24219)
Signed-off-by: Marc 'risson' Schmitt <marc.schmitt@risson.space>
2026-07-23 14:51:08 +02:00
dependabot[bot]
79cbf3b091 website: bump the build group in /website with 6 updates (#24305)
Bumps the build group in /website with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [@swc/core-darwin-arm64](https://github.com/swc-project/swc) | `1.15.43` | `1.15.46` |
| [@swc/core-linux-arm64-gnu](https://github.com/swc-project/swc) | `1.15.43` | `1.15.46` |
| [@swc/core-linux-x64-gnu](https://github.com/swc-project/swc) | `1.15.43` | `1.15.46` |
| [@swc/html-darwin-arm64](https://github.com/swc-project/swc) | `1.15.43` | `1.15.46` |
| [@swc/html-linux-arm64-gnu](https://github.com/swc-project/swc) | `1.15.43` | `1.15.46` |
| [@swc/html-linux-x64-gnu](https://github.com/swc-project/swc) | `1.15.43` | `1.15.46` |


Updates `@swc/core-darwin-arm64` from 1.15.43 to 1.15.46
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/swc-project/swc/compare/v1.15.43...v1.15.46)

Updates `@swc/core-linux-arm64-gnu` from 1.15.43 to 1.15.46
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/swc-project/swc/compare/v1.15.43...v1.15.46)

Updates `@swc/core-linux-x64-gnu` from 1.15.43 to 1.15.46
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/swc-project/swc/compare/v1.15.43...v1.15.46)

Updates `@swc/html-darwin-arm64` from 1.15.43 to 1.15.46
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/swc-project/swc/compare/v1.15.43...v1.15.46)

Updates `@swc/html-linux-arm64-gnu` from 1.15.43 to 1.15.46
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/swc-project/swc/compare/v1.15.43...v1.15.46)

Updates `@swc/html-linux-x64-gnu` from 1.15.43 to 1.15.46
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/swc-project/swc/compare/v1.15.43...v1.15.46)

---
updated-dependencies:
- dependency-name: "@swc/core-darwin-arm64"
  dependency-version: 1.15.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build
- dependency-name: "@swc/core-linux-arm64-gnu"
  dependency-version: 1.15.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build
- dependency-name: "@swc/core-linux-x64-gnu"
  dependency-version: 1.15.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build
- dependency-name: "@swc/html-darwin-arm64"
  dependency-version: 1.15.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build
- dependency-name: "@swc/html-linux-arm64-gnu"
  dependency-version: 1.15.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build
- dependency-name: "@swc/html-linux-x64-gnu"
  dependency-version: 1.15.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-23 13:48:22 +01:00