github owncloud/ocis v8.2.1

4 hours ago

Table of Contents

  • Changelog for 8.2.1

Changes in 8.2.1

Summary

  • Security - Bump golang.org/x/image to v0.45.0: #12806
  • Security - Bump Go and deps: #12902
  • Security - Bump vulnerable dependencies: #12912
  • Security - Harden public link brute force protection: #12945
  • Security - Bump grpc-go dependency: #13020
  • Bugfix - Fix share metadata corruption during concurrent share operations: #12621
  • Bugfix - Cache LDAP instance mapper lookups: #12898
  • Bugfix - Remove the unmarshalable request body field from graph log messages: #12916
  • Bugfix - Correct introduction version for OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL: #12951
  • Bugfix - Return a retryable 503 when the OIDC userinfo call fails transiently: #12999
  • Bugfix - Accept an X-Purge alias for the space-delete Purge header: #13049
  • Change - Replace GRPC_MAX_CONNECTION_AGE with client keepalive: #13020
  • Enhancement - Add TLS support for NATS store and registry connections: #12765
  • Enhancement - Add TLS support for the frontend stat cache store connection: #12932
  • Enhancement - Make the public share expiry janitor configurable: #13020
  • Enhancement - The public link resolution flag added to PROPFIND: #13020

Details

  • Security - Bump golang.org/x/image to v0.45.0: #12806

    Upgraded golang.org/x/image from v0.44.0 to v0.45.0 to address GO-2026-6222:
    excessive memory allocation during VP8L decoding.

    #12806

  • Security - Bump Go and deps: #12902

    Fix the CVE vulnerabilities flagged by the release image scan.

    #12902

  • Security - Bump vulnerable dependencies: #12912

    Bumped google.golang.org/grpc to v1.83.2 and several web frontend dependencies
    to their patched releases via pnpm overrides: @xmldom/xmldom to 0.8.15, js-yaml
    to 4.3.2, vitest to 4.1.11, postcss to 8.5.23, qs to 6.16.0, dompurify to
    3.4.13, esbuild to 0.28.1, colord to 2.9.4, browserslist to 4.28.7, fast-uri to
    3.1.6 and baseline-browser-mapping to 2.11.0.

    #12912

  • Security - Harden public link brute force protection: #12945

    We've hardened the brute force protection for password protected public links so
    that failed password attempts are reliably counted and the rate limit is
    consistently enforced.

    #12945

  • Security - Bump grpc-go dependency: #13020

    We've updated the google.golang.org/grpc dependency to fix a reported
    denial-of-service vulnerability related to gRPC server handling of requests
    missing authority or Host headers. As no tagged release containing the fix was
    available yet, we pulled in a pre-release snapshot of grpc-go that includes it,
    which also required bumping the minimum Go version to 1.26.8.

    #13020

  • Bugfix - Fix share metadata corruption during concurrent share operations: #12621

    When multiple sharing service replicas processed share operations concurrently
    for the same user, the share metadata could become corrupted with references to
    missing data, making all shares inaccessible to that user. The received share
    cache now uses compare-and-swap (etag) validation to detect concurrent writes
    and retries gracefully, preventing metadata corruption.

    #12621

  • Bugfix - Cache LDAP instance mapper lookups: #12898

    In multi-instance deployments, resolving a user's instance name/ID during GET /graph/v1.0/users (and group member expansion) issued a fresh, uncached LDAP
    search per instance/guest attribute value on every request. Under load this
    multiplied into large numbers of redundant LDAP round-trips per page of users,
    saturating the LDAP connection pool and causing request timeouts. The LDAP
    identity backend now caches instance mapper lookups, including negative
    (not-found) results, for a configurable TTL
    (OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL, default 60s).

    #12898

  • Bugfix - Remove the unmarshalable request body field from graph log messages: #12916

    We've removed the body field from the log messages of the graph service's HTTP
    handlers. The field was set from http.Request.Body, an io.ReadCloser, which
    can never be serialized into a useful log value.

    The tracing middleware replaces the request body with a wrapper that carries an
    exported function field, so serializing it failed outright and the log line was
    emitted with "body": "marshaling error: json: unsupported type: func(int64)"
    instead of the payload. Without the tracing middleware the field serialized to
    an empty object. In both cases the intended payload was never logged.

    #12916

  • Bugfix - Correct introduction version for OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL: #12951

    We changed the documented introduction version of the
    OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL from 8.0.0 to 8.2.1.

    #12951

  • Bugfix - Return a retryable 503 when the OIDC userinfo call fails transiently: #12999

    A transient failure of the OIDC userinfo call (a timeout, a network error or a
    5xx/429 from the IdP) was mapped to HTTP 401. Clients read the 401 as an invalid
    session and logged the user out on a brief IdP slowdown.

    The proxy now distinguishes a transient IdP failure from an authentication
    failure and returns a retryable 503 (with Retry-After) for the former, so
    clients retry and keep their session. A genuinely invalid or expired token still
    returns 401.

    #12999

  • Bugfix - Accept an X-Purge alias for the space-delete Purge header: #13049

    Axios >=1.20.0 reserves "purge" as an internal per-HTTP-method header-bucket
    name and strips any outgoing request header matching it case-insensitively. The
    web client's permanent space-delete request set a header literally named Purge,
    so it was silently dropped, and the server treated the request as a disable
    instead of a permanent delete.

    The graph service now also accepts an X-Purge header, and the web client sends
    that instead. The original Purge header is still accepted for other API clients.

    #13049

  • Change - Replace GRPC_MAX_CONNECTION_AGE with client keepalive: #13020

    The grpc clients now send a keepalive ping while a request is in flight and fail
    the requests on a connection whose peer stops answering, instead of waiting for
    as long as the caller allows. This covers both the reva CS3 clients (gateway,
    storage-users, storage-shares, ...) and the go-micro based clients used for
    inter-service calls between the other oCIS services. Set
    GRPC_CLIENT_KEEPALIVE_TIME and GRPC_CLIENT_KEEPALIVE_TIMEOUT to enable and tune
    this; leave them unset to keep grpc's own default (no pings).

    GRPC_MAX_CONNECTION_AGE has been removed. It only closed healthy connections on
    a timer, never ended a request that was already in flight, and silently did
    nothing when its value had no unit suffix.

    #13020

  • Enhancement - Add TLS support for NATS store and registry connections: #12765

    All nats-js-kv store, cache, and service registry connections now support TLS.
    Configure via OCIS_CACHE_ENABLE_TLS, OCIS_PERSISTENT_STORE_ENABLE_TLS, and
    MICRO_REGISTRY_ENABLE_TLS, with corresponding *_TLS_INSECURE and
    *_TLS_ROOT_CA_CERTIFICATE variants per connection type.

    #12765

  • Enhancement - Add TLS support for the frontend stat cache store connection: #12932

    The frontend service was the only remaining place where a nats-js-kv store
    connection could not be secured. Its OCS stat cache forwarded the store type,
    nodes, database, table, TTL and credentials to reva, but not the TLS settings,
    so the connection stayed plaintext with no operator toggle to change it. The
    stat cache now honours OCIS_CACHE_ENABLE_TLS, OCIS_CACHE_TLS_INSECURE and
    OCIS_CACHE_TLS_ROOT_CA_CERTIFICATE like every other cache and store.

    #12932

  • Enhancement - Make the public share expiry janitor configurable: #13020

    The sharing service runs a background janitor that permanently deletes expired
    public shares. Whether that cleanup runs at all could previously only be set in
    the sharing service's yaml config, and how often it ran was fixed internally
    with no way to tune it.

    Both settings are now exposed as environment variables:
    OCIS_SHARING_ENABLE_EXPIRED_SHARES_CLEANUP toggles the cleanup (default:
    enabled, expired shares stay hidden from listings even when disabled), and the
    new OCIS_SHARING_JANITOR_RUN_INTERVAL sets the interval in seconds between
    janitor runs (default: 3600).

    #13020

  • Enhancement - The public link resolution flag added to PROPFIND: #13020

    The public link resolution flag and the context timeout added to PROPFIND
    request The ocdav PROPFIND handler resolves public link shares to populate the
    oc:share-type property. A new toggle for skipping that lookup. The toggle is now
    exposed as OCDAV_DISABLE_PROPFIND_PUBLIC_LINK_RESOLUTION, which can be set to
    reduce load on services for large collections. Also, the bounded context was
    added for least public share request. Since this property is needed only to
    display an icon next to files in the list, indicating that a public link exists,
    it can be omitted if the ListPublicShares request is slow.

    #13020

Don't miss a new ocis release

NewReleases is sending notifications on new releases.