Weiko
0b2f4cdb57
Add delete widget action in fields widget side panel ( #19167 )
...
## Context
Add a new "Manage" section in FIELDS widget side panel with a "Delete
widget" action
Next step: Deleting a non-custom fields widget should be reversible
("Reset to default" followup)
<img width="1286" height="398" alt="Screenshot 2026-03-31 at 15 17 31"
src="https://github.com/user-attachments/assets/9ee63c14-52f1-470e-9112-4538271dc6fc "
/>
2026-04-02 07:15:19 +00:00
github-actions[bot]
1622c87b7a
i18n - docs translations ( #19234 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-02 08:44:39 +02:00
github-actions[bot]
f3e2e00e79
i18n - docs translations ( #19229 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-02 07:00:47 +02:00
github-actions[bot]
5de5ed2cb4
i18n - docs translations ( #19228 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-02 05:20:37 +02:00
github-actions[bot]
6eb4c4ca4b
i18n - docs translations ( #19227 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-02 03:04:12 +02:00
github-actions[bot]
ae202a1b59
i18n - docs translations ( #19226 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-02 00:27:21 +02:00
martmull
16e3e38b79
Improve getting started doc ( #19138 )
...
- improves
`packages/twenty-docs/developers/extend/apps/getting-started.mdx`
---------
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
2026-04-01 20:39:44 +00:00
github-actions[bot]
4cc3deb937
i18n - docs translations ( #19217 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-01 18:40:26 +02:00
github-actions[bot]
e15feda3c3
i18n - translations ( #19216 )
...
Created by Github action
---------
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-01 18:15:16 +02:00
Raphaël Bosi
9f95c4763c
[COMMAND MENU ITEMS] Remove deprecated code ( #19199 )
...
This PR is the first one of a cleanup after upgrading command menu items
to V2.
2026-04-01 15:56:52 +00:00
github-actions[bot]
e6fe48b66d
i18n - translations ( #19215 )
...
Created by Github action
---------
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-01 18:00:09 +02:00
Baptiste Devessier
20ac5b7e84
Field widget edition ( #19209 )
...
https://github.com/user-attachments/assets/2f1a5847-3375-414f-a2b8-ce4b533b5512
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-04-01 15:44:49 +00:00
github-actions[bot]
136f362b24
i18n - translations ( #19214 )
...
Created by Github action
---------
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-01 17:40:00 +02:00
Baptiste Devessier
291792f864
Repair Edit Layout command menu item and add a button in settings to start edition too ( #19208 )
...
https://github.com/user-attachments/assets/f23f0777-abf3-4ff4-8fab-ec2004df60bc
2026-04-01 15:24:05 +00:00
Raphaël Bosi
9054d3aef6
[COMMAND MENU ITEMS] Resolve object metadata label in dynamic command menu item label ( #19211 )
...
- Adds a resolveObjectMetadataLabel utility that returns the singular or
plural label from object metadata based on the number of selected
records (e.g., "person" vs "people").
- Exposes a pre-computed objectMetadataLabel string on
CommandMenuContextApi, making it available for label interpolation
(e.g., Delete ${capitalize(objectMetadataLabel)}).
2026-04-01 15:02:24 +00:00
Thomas Trompette
19dd4d6c1b
Fix workflow date fields ( #19210 )
...
Before: broken on forms, missing border right, no fullWidth, not
properly saved
<img width="220" height="160" alt="Capture d’écran 2026-03-31 à 17 10
47"
src="https://github.com/user-attachments/assets/4143fcb7-909f-42a3-b05e-39185395f657 "
/> <img width="231" height="102" alt="Capture d’écran 2026-03-31 à 17
11 05"
src="https://github.com/user-attachments/assets/3989f6b8-ef8a-42a3-9ccc-35a9be1fb67f "
/>
<img width="230" height="75" alt="Capture d’écran 2026-03-31 à 17 12
15"
src="https://github.com/user-attachments/assets/67f5f93f-887f-4e3b-95c2-f5076f41fb21 "
/>
After: save and validate on edition, fix design
<img width="231" height="132" alt="Capture d’écran 2026-03-31 à 17 15
08"
src="https://github.com/user-attachments/assets/d1aa0a64-499d-479d-8d5c-e5e104ad6464 "
/>
<img width="231" height="75" alt="Capture d’écran 2026-03-31 à 17 15
33"
src="https://github.com/user-attachments/assets/8d668713-8466-4e81-8901-4b12b9271244 "
/>
<img width="461" height="156" alt="Capture d’écran 2026-03-31 à 17 14
54"
src="https://github.com/user-attachments/assets/f9d33242-f1cc-48f7-9f63-322799e1f9b8 "
/>
Simplifying FormDateInput using the existing DatePicker
2026-04-01 14:44:24 +00:00
github-actions[bot]
a0c6727a61
i18n - docs translations ( #19212 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-04-01 16:48:34 +02:00
BOHEUS
b002930554
Update documentation on how to upload a file ( #19197 )
...
As per title, update a documentation on how to upload a file given
increasing amount of questions for this problem
CC: @StephanieJoly4
---------
Co-authored-by: Etienne <45695613+etiennejouan@users.noreply.github.com >
2026-04-01 14:15:43 +00:00
Marie
aa0ea96582
Improve app errors logs at sync ( #19174 )
...
1. Fix scrollbar
Before
https://github.com/user-attachments/assets/29792a71-b2dd-49f6-bb90-9d15feeb95aa
After
https://github.com/user-attachments/assets/939a000a-b787-4ea5-a9f0-61fbac886025
2. Introduce verbose vs non-verbose
verbose = what we have today (very detailed)
non-verbose = summarized (with a log to say add --verbose for full
logs!)
without --verbose
<img width="1256" height="876" alt="updated_non_verbose"
src="https://github.com/user-attachments/assets/d6194c41-2366-4297-a7ac-b3f3b27e08dd "
/>
with --verbose
<img width="422" height="819" alt="verbose_logs"
src="https://github.com/user-attachments/assets/409e2e88-ec3d-4bab-957c-ef319895f8c5 "
/>
2026-04-01 13:46:37 +00:00
Gabriel
36dece43c7
Fix: Upgrade Nodemailer to address SMTP command injection vulnerability ( #19151 )
...
📄 Summary
This PR upgrades the nodemailer dependency to a secure version (≥ 8.0.4)
to fix a known SMTP command injection vulnerability
(GHSA-c7w3-x93f-qmm8).
🚨 Issue
The current version used in twenty-server (^7.0.11, resolved to 7.0.11 /
7.0.13) is vulnerable to SMTP command injection due to improper
sanitization of the envelope.size parameter.
This could allow CRLF injection, potentially enabling attackers to add
unauthorized recipients to outgoing emails.
🔍 Root Cause
The vulnerability originates from insufficient validation of
user-controlled input in the SMTP envelope, specifically the size field,
which can be exploited via crafted input containing CRLF sequences.
✅ Changes
Upgraded nodemailer to version ^8.0.4
Ensured compatibility with existing email sending logic
Verified that no breaking changes affect current usage
🔐 Security Impact
This update mitigates the risk of:
SMTP command injection
Unauthorized email recipient manipulation
Potential data leakage via crafted email payloads
📎 References
GHSA: GHSA-c7w3-x93f-qmm8
CVE: (see linked report in issue)
---------
Co-authored-by: Félix Malfait <felix.malfait@gmail.com >
Co-authored-by: Charles Bochet <charlesBochet@users.noreply.github.com >
2026-03-31 19:55:50 +00:00
Charles Bochet
ee3ebd0ca0
Add "search" to reserved metadata name keywords ( #19181 )
...
## Summary
- Adds `search` and `searches` to the `RESERVED_METADATA_NAME_KEYWORDS`
list in `twenty-shared`
- Prevents users from creating custom objects named "search", which
collides with the core `search` GraphQL resolver
2026-03-31 21:16:46 +02:00
Baptiste Devessier
c11e4ece39
Fallback to field metadata ( #19131 )
...
Rely on the field metadata items to always display all object's fields
in the fields widget configuration editor. If fields are missing in the
returned view fields, we add the missing fields through object metadata.
https://github.com/user-attachments/assets/3c4d45e8-05d0-4943-be4b-bcf1e310155c
2026-03-31 19:00:16 +00:00
Charles Bochet
5bbfce7789
Add 1-21 upgrade command to backfill datasource to workspace table ( #19180 )
...
## Summary
- Adds a new `upgrade:1-21:backfill-datasource-to-workspace` command
that copies `dataSource.schema` into `workspace.databaseSchema` for all
active/suspended workspaces that haven't been migrated yet
- Registers the command in the 1-21 upgrade module and wires it into the
upgrade runner (runs before other 1-21 commands)
- Part of the ongoing deprecation of the `dataSource` table in favor of
storing `databaseSchema` directly on `WorkspaceEntity`
2026-03-31 20:34:46 +02:00
Etienne
887e0283c5
Direct execution - Follow up ( #19177 )
...
Feedbacks from https://github.com/twentyhq/twenty/pull/18972
2026-03-31 17:38:24 +00:00
Abdullah.
94e019f012
Complete the structure for homepage in new website. ( #19162 )
...
This PR completes the sections we need for the Homepage. Assets, such as
images, are still placeholder, and will be replaced as they become
available. We're still waiting on Lottie and 3d asset files from the
design team.
2026-03-31 17:19:50 +00:00
Abdul Rahman
c23961fa81
Fix navbar object color not updating immediately when changed in edit mode ( #19075 )
...
https://github.com/user-attachments/assets/f2a8f2af-b92f-4d2e-9570-fe66f0a3eca0
2026-03-31 16:51:01 +00:00
Baptiste Devessier
2612145436
Fix sdk tests ( #19172 )
2026-03-31 15:08:21 +00:00
github-actions[bot]
4c97642258
i18n - translations ( #19171 )
...
Created by Github action
---------
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-31 16:33:53 +02:00
nitin
08f019e9c9
[AI] More tab new design ( #19165 )
...
closes
https://discord.com/channels/1130383047699738754/1480981616666087687
<img width="1596" height="1318" alt="CleanShot 2026-03-31 at 18 06 37"
src="https://github.com/user-attachments/assets/0d87610e-e4ce-4f3d-8047-97d242f230c5 "
/>
2026-03-31 16:26:40 +02:00
Marie
888fa271f0
[Apps SDK] Fix rich app link in documentation ( #19007 )
...
- Fix link to rich app for LLMS
- Add example of extension of existing object in rich app (post card
app)
2026-03-31 13:35:57 +00:00
github-actions[bot]
bb5c64952c
i18n - translations ( #19169 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-31 15:29:13 +02:00
github-actions[bot]
6dedb35a1f
i18n - translations ( #19168 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-31 15:22:30 +02:00
Weiko
436333f110
Add see records link to data model ( #19163 )
...
## Context
Add a link to the INDEX view page of an object to list all its records
directly from the data model page of the object.
<img width="556" height="460" alt="Screenshot 2026-03-31 at 14 04 20"
src="https://github.com/user-attachments/assets/3daa9ee5-ad09-42b5-a406-088ce8c53be4 "
/>
2026-03-31 13:12:43 +00:00
Abdul Rahman
ec283b8f2d
Fix dropping workspace nav items at the bottom of the list ( #18989 )
...
https://github.com/user-attachments/assets/64abd955-892e-48c8-bf7b-d4d8645cf33e
---------
Co-authored-by: Etienne <45695613+etiennejouan@users.noreply.github.com >
2026-03-31 13:06:31 +00:00
github-actions[bot]
c3b969ab74
i18n - translations ( #19166 )
...
Created by Github action
---------
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-31 14:55:02 +02:00
Weiko
287fe90ce9
Add link to workspace members index view page from the settings ( #19164 )
...
## Context
Fixes https://github.com/twentyhq/core-team-issues/issues/2039
<img width="608" height="519" alt="Screenshot 2026-03-31 at 14 28 00"
src="https://github.com/user-attachments/assets/939e47c6-84c2-471c-8da5-b76b161f086a "
/>
2026-03-31 12:39:22 +00:00
Thomas Trompette
d10c0a6439
Fix: composite update events not received ( #19053 )
...
Database batch events (update / insert / soft-delete / hard-delete) were
building recordsBefore / recordsAfter after formatResult ran twice: once
inside WorkspaceSelectQueryBuilder.getMany() / getOne(), and again in
the CUD query builders. On the second pass, already-shaped composite
fields (e.g. emails) went through formatFieldMetadataValue and kept the
same object references as the live TypeORM row, so recordsBefore could
change when the entity was updated—breaking workflow triggers and diffs.
2026-03-31 11:58:12 +00:00
BugIsGod
176e81cd76
fix: clear navigation stack immediately in goBackFromSidePanel ( #19153 )
...
Fixes : #19152
## Summary
goBackFromSidePanel returned early without writing the new (empty) stack
to the store, leaving stale navigation state. And it caused
openRecordInSidePanel to think the record was already open and skip
reopening.
<img width="587" height="405" alt="image"
src="https://github.com/user-attachments/assets/eb36f4c6-43ca-4c08-891a-c592ff673837 "
/>
## Before
https://github.com/user-attachments/assets/03d1e24a-6d1e-4efc-93c1-72be0bc31a89
## After
When close the side panel with Escape, now it can be opened by clicking
arrow button again.
https://github.com/user-attachments/assets/ae700d41-4f81-4d1a-af9a-f97f31f489a6
---------
Co-authored-by: Devessier <baptiste@devessier.fr >
2026-03-31 11:29:03 +00:00
Charles Bochet
1ce4da5b67
Fix upgrade commands 2 ( #19157 )
2026-03-31 12:47:01 +02:00
github-actions[bot]
ef66d6b337
i18n - translations ( #19158 )
...
Created by Github action
---------
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-31 12:23:19 +02:00
BugIsGod
bcca5d0002
fix: show disabled file chip when file no longer exists in timeline ( #19045 )
...
Fixes : #18943
Follow-up pr: #19001
## Summary:
- Timeline activity shows file upload history, but deleted files had no
signed URL and were still rendered as clickable — clicking did nothing
- grab the fileId from properties.diff.after, look it up in the current
record's files field: if present, use live signed URL; if absent, mark
as deleted
- Deleted file chips show line-through label, not-allowed cursor, and
"File no longer exists" tooltip on hover
https://github.com/user-attachments/assets/5df6a675-0003-4fd1-ad57-a07e4338923f
---------
Co-authored-by: Etienne <45695613+etiennejouan@users.noreply.github.com >
2026-03-31 10:07:19 +00:00
Weiko
e0630b8653
Fix TransactionNotStartedError ( #19155 )
...
## Context
Checked in the codebase where we are trying to rollback a non-active
transaction.
packages/twenty-server/src/engine/core-modules/auth/services/sign-in-up.service.ts
seemed to be the only place where it happens.
We could enforce this with a lint rule in the future 🤔
2026-03-31 10:02:50 +00:00
Paul Rastoin
61a27984e8
0.8.0.canary.7 bump (#19150 )
...
Already published on npm
2026-03-31 09:50:28 +02:00
github-actions[bot]
fd21d0c6ca
i18n - docs translations ( #19142 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-31 00:23:38 +02:00
github-actions[bot]
8d539f0e49
i18n - docs translations ( #19139 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-30 22:30:14 +02:00
github-actions[bot]
a6cecdbd49
i18n - docs translations ( #19137 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-30 20:38:05 +02:00
Raphaël Bosi
383935d0d9
Fix widgets drag handles ( #19133 )
...
- Remove drag handles and cursor resize for the placeholder
- Fix the drag handles no longer appearing on hover and always present
drag handle for north and south
This was due to the linaria migration: adding a minus sign or px after a
css variable isn't working, we have to use calc.
## Before
https://github.com/user-attachments/assets/cba398ab-92c8-4924-ba3c-1a28fb4fd163
## After
https://github.com/user-attachments/assets/aec675cd-b809-434d-a8a7-edb12ce37364
2026-03-30 17:07:49 +00:00
Paul Rastoin
37908114fc
[SDK] Extract twenty-front-component-renderer outside of twenty-sdk ( 2.8MB ) (#19021 )
...
Followup https://github.com/twentyhq/twenty/pull/19010
## Dependency diagram
```
┌─────────────────────┐
│ twenty-front │
│ (React frontend) │
└─────────┬───────────┘
│ imports runtime:
│ FrontComponentRenderer
│ FrontComponentRendererWithSdkClient
│ useFrontComponentExecutionContext
▼
┌──────────────────────────────────┐ ┌─────────────────────────┐
│ twenty-front-component-renderer │────────▶│ twenty-sdk │
│ (remote-dom host + worker) │ │ (app developer SDK) │
│ │ │ │
│ imports from twenty-sdk: │ │ Public API: │
│ • types only: │ │ defineFrontComponent │
│ FrontComponentExecutionContext│ │ navigate, closeSide… │
│ NavigateFunction │ │ useFrontComponent… │
│ CloseSidePanelFunction │ │ Command components │
│ CommandConfirmation… │ │ conditional avail. │
│ OpenCommandConfirmation… │ │ │
│ EnqueueSnackbarFunction │ │ Internal only: │
│ etc. │ │ frontComponentHost… │
│ │ │ front-component-build │
│ owns locally: │ │ esbuild plugins │
│ • ALLOWED_HTML_ELEMENTS │ │ │
│ • EVENT_TO_REACT │ └────────────┬────────────┘
│ • HTML_TAG_TO_CUSTOM_ELEMENT… │ │
│ • SerializedEventData │ │ types
│ • PropertySchema │ ▼
│ • frontComponentHostComm… │ ┌─────────────────────────┐
│ (local ref to globalThis) │ │ twenty-shared │
│ • setFrontComponentExecution… │ │ (common types/utils) │
│ (local impl, same keys) │ │ AppPath, SidePanelP… │
│ │ │ EnqueueSnackbarParams │
└──────────────────────────────────┘ │ isDefined, … │
│ └─────────────────────────┘
│ also depends on
▼
twenty-shared (types)
@remote-dom/* (runtime)
@quilted/threads (runtime)
react (runtime)
```
**Key points:**
- **`twenty-front`** depends on the renderer, **not** on `twenty-sdk`
directly (for rendering)
- **`twenty-front-component-renderer`** depends on `twenty-sdk` for
**types only** (function signatures, `FrontComponentExecutionContext`).
The runtime bridge (`frontComponentHostCommunicationApi`) is shared via
`globalThis` keys, not module imports
- **`twenty-sdk`** has no dependency on the renderer — clean one-way
dependency
- The renderer owns all remote-dom infrastructure (element schemas,
event mappings, custom element tags) that was previously leaking through
the SDK's public API
- The SDK's `./build` entry point was removed entirely (unused)
2026-03-30 17:06:06 +00:00
github-actions[bot]
369ae2862f
i18n - docs translations ( #19135 )
...
Created by Github action
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-30 18:40:35 +02:00
github-actions[bot]
5bde41ebbb
i18n - translations ( #19134 )
...
Created by Github action
---------
Co-authored-by: github-actions <github-actions@twenty.com >
2026-03-30 18:30:38 +02:00