Skip to content

Release 26.09.09-01

Choose a tag to compare

@dotCMS-Machine-User dotCMS-Machine-User released this 09 Sep 17:32

dotCMS 26.09.09-01 brings the dotAI portlet and the Experiments results screen to Angular, adds keyboard navigation to Content Drive, and gates UVE's contentlet edit affordances on the user's actual edit permission. It also repairs Tomcat Native SSL offloading in the Docker images and hardens the JVM info endpoint.

Features

  • The dotAI portlet is rebuilt in Angular with Search, Chat, Image, Embeddings and Config Values tabs rendering natively in the admin shell, with the legacy JSP still reachable as an unlisted dotai-legacy portlet for rollback. [#37417]
  • The Experiments portlet gains its results screen at /experiments/:experimentId/results, with a stat strip, Daily and Bayesian tabs, a summary table, and promote and stop actions. [#37004]
  • Content Drive's listing is now fully keyboard operable — arrow navigation, shift-range and modifier selection — backed by a shared shortcut registry other surfaces can reuse. [#32591]
  • New dotcms agent setup command connects an AI coding agent to a dotCMS instance in one step, minting and verifying a token before merging the MCP server into each detected editor's own config across seven supported editors. [#37390]
  • GET /v1/users/filter accepts an opt-in includeRoles parameter that returns each user's directly assigned roles inline, removing the need for a per-row role lookup; without the flag the response is unchanged. [#37236]
  • When OIDC discovery detects Google as the issuer, the dotAuth portlet offers to pre-fill the Cloud Identity groups lookup settings and append the required read-only scope. [#37371]

Enhancements & Adjustments

  • The shared key/value editor is redesigned and rolled out consistently to all three of its consumers — the Edit Content field, the Content Type field variables tab, and the Apps custom-properties panel — with inline editing, hover-revealed row actions, and reversible value hiding. [#37191]
  • The shared-assets filter moves into @dotcms/ui as a reusable component with a store-agnostic facade, so Content Drive and the Asset Picker share one implementation instead of duplicating it. [#37374]
  • Long folder names now clip to one line with an ellipsis and reveal the full name in a tooltip on hover or keyboard focus across all five consumers of the shared folder tree. [#37373]
  • The Asset Picker no longer lists or returns folders as selectable rows; folders are navigated through the sidebar tree and the list shows content only. [#37367]

Fixes

  • Every UVE affordance that modifies a contentlet — edit pencil, quick edit, the style editor, and inline WYSIWYG and Block Editor editing — is now gated on the user's edit permission for that contentlet instead of defaulting to allowed. [#37412]
  • Firing a workflow action with Allow Comments enabled in the new Edit Content UI now shows the comment dialog on the first execution rather than only on a retry, restoring the workflow audit note. [#36883]
  • Workflow actions fired from the Tasks portlet's Task Detail dialog now signal completion back to the shell, so the dialog closes, the confirmation appears, and the displayed step refreshes. [#36779]
  • File Asset Containers now inherit permissions from their container folder rather than the Site, so grants made on the folder are no longer overwritten and roles with View-only access can see the container in the layout editor. [#37402]
  • "Fix Inconsistencies" no longer aborts when content contains an apostrophe — the serialized contentlet JSON is bound as a JDBC parameter instead of being inlined into the generated SQL. [#37325]
  • The image editor now provides its own message service and toast outlet, so it renders correctly when opened from UVE instead of showing a blank dialog. [#37400]
  • Clicking related content from the full-screen editor opens it in a side panel instead of navigating away, so a newly created relation is no longer lost to the unsaved-changes prompt. [#37385]
  • The Roles & Tools portlet gets a round of interface corrections: a tinted detail tab strip, even Grant button spacing, consistent text-styled Cancel buttons, and the removal of role node icons. [#37334]
  • Folder icons render consistently and track expand/collapse state everywhere the shared folder tree is used, including Content Drive. [#37362]
  • Asset Picker uploads now honor the same file-type restriction already applied to browsing, so an upload from an Image field or a Story Block media node can no longer succeed and then silently vanish from the list. [#37372]
  • @dotcms/mcp-server no longer ships its test files inside the published bundle, which previously crashed the server on startup for every invocation. [#37337]
  • npx @dotcms/create-app --local now waits for the database and search services to report healthy before starting dotCMS, and a failed UVE configuration call no longer aborts scaffolding. [#37264]

Infrastructure & Security

  • Tomcat Native is rebuilt from Apache source at 1.3.8 against the image's own APR and OpenSSL 3, replacing the incompatible distro package that broke SSL offloading and could crash the JVM on startup. [#34067]
  • The JVM info endpoint now masks sensitive system-table config overrides using the same obfuscation rules already applied to system properties and environment variables. [#36920]
  • The release pipeline refuses to re-release a version that already has a published GitHub Release, instead of rebuilding for 24 minutes and force-recreating the release branch at the wrong commit. [#37381]
  • The release-notes backfill now republishes repaired notes to the public changelog, fixing entries that rendered with a title and date but no content. [#37389]
  • A step-by-step ES to OpenSearch migration runbook is available for Support and Cloud engineers, covering the phased procedure, decision points and readiness checks. [#37102]
  • Repository AI-context documentation is tightened: orphaned backend docs are linked into the navigation index [#37391], and convergence becomes the developer-triggered closing step of the Spec-Kit flow with documentation drift included in its gap analysis [#37275].
  • Design specifications landed for upcoming work with no runtime change of their own: Content Drive listing performance [#37188] [#37189] [#37190], UVE permission gating [#37404], the workflow comment dialog [#37437], the SDK CLI agent setup command [#37392], Block Editor emoji handling [#37434], the Publishing Queue pending-delete no-op [#37430], and a diff-scoped strict typecheck gate [#37403].