stumpylog
ec7745e71f
Minor improvements from a Claude review
2026-09-02 08:14:41 -07:00
stumpylog
98e87d91ad
Fix: skip vector store document id filter for unrestricted chat users
...
ChatStreamingView built an IN filter from every permitted document id
for the "chat over all documents" case, which exceeds the vector
store's SQLite bound-parameter safety limit on installs with more
than ~32700 documents, silently returning no context. For a user who
can see every document (an active superuser), that filter never
narrows anything, so skip it and let the retriever search the whole
index instead.
2026-09-02 08:14:23 -07:00
Trenton H
d78754bff1
Security: validate remote OCR endpoint against internal SSRF ( #13897 )
...
* Security: validate remote OCR endpoint against internal SSRF
Adds PAPERLESS_REMOTE_OCR_ALLOW_INTERNAL_ENDPOINTS (default true)
and validates remote_ocr_endpoint via validate_outbound_http_url
on the config serializer, matching the existing LLM endpoint handling.
* Validates te outbound url again right before use
* cover empty-value branch of validate_remote_ocr_endpoint because coverage
* re-validate remote OCR endpoint on every outbound request
2026-09-01 20:22:10 +00:00
GitHub Actions
08f2f4bfe2
Auto translate strings
2026-09-01 19:54:47 +00:00
Trenton H
f993462973
Security: Minor additional hardening ( #13898 )
...
* Security: bump jinja2 floor to 3.1.6 (CVE-2025-27516)
* Security: anchor the /share/ URL pattern
* Security: handle missing file on public share view without 500
* Security: scope correspondent last_correspondence to permitted documents
* Security: disable PUT/PATCH on share link bundles
2026-09-01 19:53:28 +00:00
shamoon
ae70b8d60f
Chore: consolidate pickle hmac signing ( #13899 )
2026-09-01 12:41:45 -07:00
GitHub Actions
31e9f4272c
Auto translate strings
2026-09-01 16:56:33 +00:00
shamoon
b8659c1af3
Fix: use root doc metadata for filename generation ( #13893 )
2026-09-01 09:55:04 -07:00
shamoon
ca98dffbd2
Bump version to 3.1.2
2026-09-01 08:09:13 -07:00
github-actions[bot] and Crowdin Bot
4db1451e41
New Crowdin translations by GitHub Action ( #13889 )
...
Co-authored-by: Crowdin Bot <support+bot@crowdin.com >
2026-09-01 08:06:06 -07:00
shamoon
624b7911e5
Merge commit from fork
2026-09-01 07:56:38 -07:00
GitHub Actions
5a1a5333ad
Auto translate strings
2026-09-01 14:48:13 +00:00
shamoon
bfe8213b78
Fix: re-use permitted_object_ids
2026-09-01 07:45:47 -07:00
Trenton H
06e9c1c02b
Chore: Isolate the search index directory in trash-restore tests, they were using a persistent index ( #13876 )
2026-08-31 14:43:14 +00:00
shamoon
a4499dc9c1
Bump version to 3.1.1
2026-08-30 22:36:29 -07:00
github-actions[bot] and Crowdin Bot
ba017ce5b8
New Crowdin translations by GitHub Action ( #13828 )
...
Co-authored-by: Crowdin Bot <support+bot@crowdin.com >
2026-08-30 22:23:23 -07:00
shamoon
fd543f2bff
Fix: 3.1.0 llm suggestions remove existing metadata from prompt, dont drop name suggestions ( #13866 )
2026-08-30 21:25:26 -07:00
shamoon
14b6a41b88
Fix: 3.1 llm suggestions request a flat list we change later ( #13860 )
2026-08-30 07:44:45 -07:00
shamoon
8af3e69084
Fix: 3.1 LLM suggestions normalize flat lists from smaller models ( #13853 )
2026-08-29 23:14:24 -07:00
shamoon
b89fb0f978
Fix: 3.1.0 llm suggestions simplify schema, fix docstrings ( #13850 )
2026-08-29 14:03:30 -07:00
GitHub Actions
535975e2fd
Auto translate strings
2026-08-29 20:03:36 +00:00
shamoon
9c475e0b27
Fix: 3.1.0 llm suggestion raw cache user scoping ( #13849 )
2026-08-29 13:02:05 -07:00
shamoon
7ddc1c9801
Fix: 3.1 LLM suggestions fix rank ordering ( #13848 )
2026-08-29 10:56:05 -07:00
GitHub Actions
6f3945f11f
Auto translate strings
2026-08-28 23:09:08 +00:00
shamoon
a784a642ee
Fixhancement: make imap port required, better error display ( #13845 )
2026-08-28 16:07:41 -07:00
shamoon
00d9bf474a
Fix: always pass a non-empty api key for OpenAI-like servers ( #13838 )
2026-08-28 09:55:13 -07:00
shamoon
05917a04aa
Fix: immediately re-add doc to index after trash restore ( #13818 )
2026-08-27 12:19:31 -07:00
shamoon
a298568962
Security: harden is_public_ip
2026-08-27 00:21:03 -07:00
shamoon
f6f37898e8
Chore: use PinnedIMAP4
2026-08-27 00:21:02 -07:00
shamoon
1630e78aac
Bump version to 3.1.0
2026-08-26 18:07:04 -07:00
4e79553489
New Crowdin translations by GitHub Action ( #13496 )
...
Co-authored-by: Crowdin Bot <support+bot@crowdin.com >
Co-authored-by: shamoon <4887959+shamoon@users.noreply.github.com >
2026-08-26 18:06:05 -07:00
shamoon
406bc1a233
Fix: defer add_nested_tags in ai workflow to avoid losing unsaved changes
2026-08-26 14:18:40 -07:00
shamoon
139739c2a2
Fix: handle social account sync groups claim sent as str
2026-08-26 12:37:29 -07:00
GitHub Actions
cafed919a1
Auto translate strings
2026-08-26 16:50:29 +00:00
shamoon
549afde1fd
Enhancement: Apply AI suggestions workflow action ( #13639 )
2026-08-26 16:41:21 +00:00
GitHub Actions
a8576d827e
Auto translate strings
2026-08-26 14:29:05 +00:00
shamoon
7330c4d9cb
Fix: exclude version documents from bulk edit "all" ( #13791 )
2026-08-26 14:27:31 +00:00
GitHub Actions
35d40b51cb
Auto translate strings
2026-08-25 21:37:07 +00:00
shamoon
78025df405
Performance: fetch note authors with prefetch instead of one query each ( #13790 )
2026-08-25 14:35:22 -07:00
shamoon
f5ddc14588
Fix: also check global change_mailaccount with test
2026-08-25 10:44:49 -07:00
GitHub Actions
2609327e9c
Auto translate strings
2026-08-24 21:44:25 +00:00
shamoon
b90ccf910f
Finally, the remote ocr workflow ( #13637 )
...
* Ok! Backend stuff for the remote ocr workflow
* Frotnend workflow stuff
* And docs
* Fix dynamic action fields thing
* Actually, fix the action dropdown thing
* Fix this validation thing, and we have to check existing actions
* Fix migration
2026-08-24 14:43:05 -07:00
shamoon
c93c996edf
Remote ocr reprocess ( #13636 )
...
* Backend stuff for remote ocr reprocess, add to bulk edit pass in from ui settings
* Ok, frontend reprocess remote option
* Docs
2026-08-24 14:43:05 -07:00
shamoon
7f1609332a
Allow parsers to declare uses remote, and remote ocr_mode ( #13634 )
...
* uses_remote_service + allow_remote to allow opt-in / out of remote OCR
* Add to parser dev docs
* remote_ocr_mode config setting
* Checks for remote_ocr_mode and fix import
* Update config.component.spec.ts
* More tests for remote_ocr_mode
* Docs for remote_ocr_mode
* Ok, wire up the remote_ocr_mode with allow_remote for consumer
* Update consumer.py
* Format remote OCR mode check tests
* Use get_choice_from_env
2026-08-24 14:43:04 -07:00
GitHub Actions
a1f20c9fe7
Auto translate strings
2026-08-24 21:19:19 +00:00
shamoon
4fd1c60731
Enhancement: support using remote OCR engines selectively ( #13633 )
...
* Backend changes and migration for remote OCR Config
* Backend tests
* Frontend stuff, with sections
* Docs
* Update test_tesseract_parser.py
* Actually we cant use this any more, in case settings are in app config
* Dont mark entire test file for db, use a mock for empty engine settings
2026-08-24 14:17:52 -07:00
Sebastian Wieland and shamoon
a0908f6b4a
Enhancement: websocket heartbeat ( #13739 )
...
---------
Co-authored-by: shamoon <4887959+shamoon@users.noreply.github.com >
2026-08-24 15:15:21 +00:00
shamoon and Trenton H
bab9129ff8
Fix: lazy import guardian modules to fix search language setting ( #13768 )
...
Co-authored-by: Trenton H <797416+stumpylog@users.noreply.github.com >
2026-08-24 13:46:20 +00:00
shamoon
294328f174
Fix: version indexing fixes ( #13737 )
2026-08-23 23:04:47 +00:00
shamoon
0458bad5f2
Fix: append charset to file response for text files ( #13759 )
2026-08-22 06:15:53 -07:00