Repository navigation
Release 26.09.03-01
dotCMS 26.09.03-01 makes index deletions durable so removed content can no longer linger in search results, adds post-authentication group fetching for identity providers that cannot emit group claims, and restores the release-notes pipeline.
Features
- OAuth and OIDC group memberships can now be fetched from the identity provider after authentication, using
{email}and{sub}placeholders ingroupsUrlplus a newgroupsResponsePathkey to extract group values, so providers such as Google Workspace and GitHub that cannot emit groups in token claims can drive dotCMS role mapping. [#37195]
Fixes
- Content deletions are now journaled so index removals lost to a restart, a rejected task, or a partial bulk write are retried instead of leaving orphaned documents behind in search, listings, URL maps, and widget counts. [#37276]
- Index removals on the OpenSearch write leg are now durable once OpenSearch serves reads, closing the same orphaned-document gap during the longest phase of the migration. [#37333]
- Popover content renders with its padding restored by default, fixing the UVE toolbar copy-URL list that sat flush against the panel edges. [#37341]
Infrastructure & Security
GET /api/v1/roles/layoutsnow requires an authenticated backend user with access to the Roles portlet; anonymous callers previously received the full tool-group catalog. [#37323]- Release-notes generation works again after silently failing across the previous four releases and publishing empty release descriptions. [#37361]
- Release-notes and QA-status tooling resolves merged pull requests through the commits-to-pull-requests API instead of parsing squash-commit subjects, so merge-commit PRs are no longer dropped or attributed to the wrong number. [#37213]
- The
DOTBOT_REVIEW_MODELSvariable now replaces the automated review model roster rather than adding to it. [#37348] - Manual workflow dispatch accepts a pull request URL as well as a bare number. [#37324]
- Post-merge test plans are built from an issue's approved specification when spec-driven work exists, in preference to the issue's acceptance criteria. [#37326]
- Specification published for Content Drive bulk file upload, covering both the server and browser halves ahead of implementation. [#37346]
- Specification published for keeping emoji part of the surrounding Block Editor text node, so linked phrases are no longer split and emoji characters survive VTL rendering. [#37340]