Skip to content

Release 26.09.03-01

Choose a tag to compare

@dotCMS-Machine-User dotCMS-Machine-User released this 03 Sep 19:45

dotCMS 26.09.03-01 makes index deletions durable so removed content can no longer linger in search results, adds post-authentication group fetching for identity providers that cannot emit group claims, and restores the release-notes pipeline.

Features

  • OAuth and OIDC group memberships can now be fetched from the identity provider after authentication, using {email} and {sub} placeholders in groupsUrl plus a new groupsResponsePath key to extract group values, so providers such as Google Workspace and GitHub that cannot emit groups in token claims can drive dotCMS role mapping. [#37195]

Fixes

  • Content deletions are now journaled so index removals lost to a restart, a rejected task, or a partial bulk write are retried instead of leaving orphaned documents behind in search, listings, URL maps, and widget counts. [#37276]
  • Index removals on the OpenSearch write leg are now durable once OpenSearch serves reads, closing the same orphaned-document gap during the longest phase of the migration. [#37333]
  • Popover content renders with its padding restored by default, fixing the UVE toolbar copy-URL list that sat flush against the panel edges. [#37341]

Infrastructure & Security

  • GET /api/v1/roles/layouts now requires an authenticated backend user with access to the Roles portlet; anonymous callers previously received the full tool-group catalog. [#37323]
  • Release-notes generation works again after silently failing across the previous four releases and publishing empty release descriptions. [#37361]
  • Release-notes and QA-status tooling resolves merged pull requests through the commits-to-pull-requests API instead of parsing squash-commit subjects, so merge-commit PRs are no longer dropped or attributed to the wrong number. [#37213]
  • The DOTBOT_REVIEW_MODELS variable now replaces the automated review model roster rather than adding to it. [#37348]
  • Manual workflow dispatch accepts a pull request URL as well as a bare number. [#37324]
  • Post-merge test plans are built from an issue's approved specification when spec-driven work exists, in preference to the issue's acceptance criteria. [#37326]
  • Specification published for Content Drive bulk file upload, covering both the server and browser halves ahead of implementation. [#37346]
  • Specification published for keeping emoji part of the surrounding Block Editor text node, so linked phrases are no longer split and emoji characters survive VTL rendering. [#37340]