Conversation
update dev from staging
Release 1.5 merger
Co-authored-by: Filip Ślęzak <fslezak@teonite.com>
* validate phone number during enrollment * also check phone numbers in core API endpoints
* don't send empty strings when phone number is not providecleand * use zod trim() instead of trimObjectStrings helper
* fix open redirect pentest issue * add tests and handling of get requests, allow redirects if url is allowed for the client * compare the whole url, not just domain * cargo clippy fixes * wip fix openid flow tests * fix panic in the contains_redirect_url method * cleanup eprintln statements * bring back the other openid flow test * state-based fallback url in openid test
* put random & secret modules into a common crate * move DB setup code to common crate * move version to common crate * move id types to common crate * move AuthCode model into common crate * move auth key model * move biometric auth model * move device login model * remove unnecessary feature flags * move global value macro * move model error * move server config * move hex module * move protos to a separate crate * put mailer into a separate crate * update query data * remove commented out code * add new crates * update flake inputs * move AsCsv trait * fix failing test * move claims struct
* custom Debug implementation for Settings struct to avoid exposing license key in logs * cargo update
* fix links in readme * fix frontend links
Merge main into dev after 1.5.1 release
* implement & test sbom files creation during CI process * add sbom workflow file * strip 'v' from ref_name * fix version stripping * rename sbom file * fix asset path * spdx format * uncomment build-binaries job * run sbom on self-hosted workers * use shogo82148/actions-upload-release-asset upload action
* CI: scan code with trivy * update e2e pnpm deps * update web dependencies * configure trivy scan-ref * include low severity vulns in sbom
* regenerate sboms and advisories periodically * fix sbom file name * remove branch push trigger
* add base framework for validating events in API integration tests * add way to also test user context * use queue clear helper * add user login helper * update some tests in user module * update remaining tests in user module * format docstring * fix message formatting
* workflow test * ready to release * delete comment * add EOL * Added ruby to path * for loop * typo 2 * refresh html
* client version checking 1 * Apply suggestions from code review Co-authored-by: Adam <adam@defguard.net> * Update client_version.rs * tests * fix * update min version * use encoded protos for passing platform * fix * Update proto * fix tests --------- Co-authored-by: Adam <adam@defguard.net>
* add option to prefetch users to openid provider settings * handle new option in frontend * add base prefetch tests * handle user creation during directory sync * update log * make mobile phone optional * update tests * hide checkbox for other providers * Microsoft sync fixes * adjust logs * trigger ldap sync for created users * linter fix * username validation * Update crates/defguard_core/src/enterprise/directory_sync/mod.rs Co-authored-by: Aleksander <170264518+t-aleksander@users.noreply.github.com> * update query data --------- Co-authored-by: Aleksander <170264518+t-aleksander@users.noreply.github.com>
* add option to specify enrollment token expiration time * add test * update dependencies
* reproduce issue in test * don't throw errors if device is not found * avoid showing private key in debug logs * update test
* don't allow 0 netmask in forms * validate sizes of all used networks * update dependencies * add basic validation test * improve backend address parsing * update nix flake inputs * update deps * update test * change approach * return error when trying to add /0 subnet
Related issue: #880 Adds "force all traffic" option to enterprise settings. When selected, all clients are forced to route all traffic via the vpn.
… without name (#1719) * filter mfa locations, validate ip/domain in wizard * Reject device without name
* fix client traffic policy helpers styling * remove unused useMemo deps * tweak the header
* Fix validators Created new patterns, Moved validators to Validate.* Fixed validators in Wizards,smtp configuration * Unit testing for web, unit tests for validators * Created Validate.any/all function. Removed logic from zod * add licenses exceptions
moubctez
previously approved these changes
Dec 9, 2025
…in permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
moubctez
approved these changes
Dec 9, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge release branch into main in preparation for 1.6 release
Related #1736