Commit Graph

1093 Commits

Author SHA1 Message Date
Félix Malfait cebcf4f1f5 Prevent csv export injections (#14347)
**Small Security Issue:** CSV exports were vulnerable to formula
injection attacks when users entered values starting with =, +, -, or @.
(only happens if a logged-in user injects corrupted data)

Solution:
- Added ZWJ (Zero-Width Joiner) protection that prefixes dangerous
values with invisible Unicode character
- This is the best way to preserve original data while preventing Excel
from executing formulas
- Added import cleanup to restore original values when re-importing
 
Changes:
- New sanitizeValueForCSVExport() function for security
- Updated all CSV export paths to use both security + formatting
functions
- Added comprehensive tests covering attack vectors and international
characters
- Also added cursor rules for better code consistency

---------

Co-authored-by: Charles Bochet <charlesBochet@users.noreply.github.com>
2025-09-08 17:57:46 +02:00
nitin 374b5dce66 Fix REST API view name template replacement (#14244)
REST API was returning raw template strings like 'All
{objectLabelPlural}' instead of replaced values. GraphQL had proper
handling but REST controllers don't have access to DataLoaders.

Added minimal template replacement using WorkspaceMetadataCacheService
to replace {objectLabelPlural} placeholders with actual object labels.
No full translations since REST isn't priority for i18n.

addressing -
https://discord.com/channels/1130383047699738754/1412122807281651833
2025-09-08 17:51:30 +02:00
Raphaël Bosi 49ee73a16c Update open api with page layout (#14355)
Closes https://github.com/twentyhq/core-team-issues/issues/1396
2025-09-08 17:19:06 +02:00
Félix Malfait 502bd07db9 Fix wrong path used by backend (#14352)
After moving a section on the frontend, this broke the path that was
sent by email on the backend.
This kind of error comes back every ~2-3 month under different forms so
we need a more robust solution: I moved routes to the shared folder,
that way we will share one common source of truth between the frontend
and the backend.

Fixes #14343
2025-09-08 16:07:13 +02:00
Charles Bochet f9677122b6 Improve Messaging Gmail experience (#14342)
In this PR, I'm solving several issues:
1) We were not checking if the currentWorkspaceMember was owning the
message in the thread. It kind of worked before because the case of
shared threads (with shared threads visibility restriction) was not
happening that often. It seems that the bug has always been there
2) Re-implement orphan messages and threads deletion on messageChannel
deletion. We used to brutally look for all orphans, we disabled it last
week because it was too heavy on db. I've re-implemented it more
carefully and "surgically"
3) Gmail sync was not handling folder synced correctly. It was
leveraging labelIds which it shouldn't do (this is a AND AND parameter)
in full sync
4) Added a command to clean orphan message threads manually if needed.
Usually this is done when you remove a messageChannel, or change
blocklist rules but it can be useful to have it to debug
2025-09-07 20:36:28 +02:00
Harshit Singh b78d139db5 fix: Server-level impersonation doesn't bypass 2FA when enabled (#14340)
## Description

- This PR solves the a sub-issue from
https://github.com/twentyhq/core-team-issues/issues/1421
- impersonation tokens bypasses 2FA as intended 
- Added Audit trails to cover all impersonation events
- Added Proper testing coverage

---------

Co-authored-by: Félix Malfait <felix@twenty.com>
2025-09-07 15:53:23 +02:00
Raphaël Bosi 9445256eee Create PageLayoutWidget resolver and controller (#14315)
Closes https://github.com/twentyhq/core-team-issues/issues/1395
2025-09-05 16:59:51 +02:00
github-actions[bot] 22157be640 i18n - translations (#14324)
Created by Github action

---------

Co-authored-by: Crowdin Bot <support+bot@crowdin.com>
Co-authored-by: github-actions <github-actions@twenty.com>
2025-09-05 14:12:26 +02:00
github-actions[bot] 3bc86cdc10 i18n - translations (#14321)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-09-05 12:46:05 +02:00
Félix Malfait d5f88e566c Get ready for 1000+ members (#14313)
The goal of this PR is to test if Twenty can support a large number of
members, a question which was raised by a large company that is
considering moving away from Salesforce.

I was expecting the currentWorkspaceMembersState to cause a lot more
issue. It would be very hard to get rid of it in the context of actors,
I think that would require a big refactoring. I thought we'd have to do
it but it turns out the perf are pretty good. One thing we need to
improve is the pagination on the roles page, we'll wait for @Bonapara to
update that
2025-09-05 12:37:22 +02:00
github-actions[bot] 094d670590 i18n - translations (#14320)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-09-05 12:20:51 +02:00
Vinay Arvind Badgujar 5824637d1a fix - newly added object not visible in left menu (#14202)
resolves #14190 

added refreshCoreViews() call after object creation to immediately
update core views state, ensuring new objects appear in the navigation
drawer without requiring a refresh

---------

Co-authored-by: Charles Bochet <charles@twenty.com>
Co-authored-by: prastoin <paul@twenty.com>
2025-09-05 10:43:03 +02:00
Raphaël Bosi 9746c3a787 Create PageLayoutTab resolver and controller (#14284)
Closes https://github.com/twentyhq/core-team-issues/issues/1394
2025-09-04 16:07:33 +00:00
Abdul Rahman 79bcd90d8d Feat: role applicability controls (#14239)
Closes [#1404](https://github.com/twentyhq/core-team-issues/issues/1404)

---------

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2025-09-04 08:58:50 +05:30
github-actions[bot] c943480791 i18n - translations (#14279)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-09-03 12:20:36 +02:00
Thomas Trompette 2e7fe238ed Clean step and edge errors (#14261)
- add filters for both resolvers
- map to gql errors

Should fix https://github.com/twentyhq/core-team-issues/issues/996
2025-09-03 10:00:02 +02:00
Charles Bochet c847a72926 add logs to fix note target creation (#14268) 2025-09-03 08:11:03 +02:00
Weiko ee7aec7447 fix auth context injection (#14266) 2025-09-02 23:11:00 +02:00
Weiko 18d6fd2f71 fix rest API tests (#14265) 2025-09-02 23:01:27 +02:00
Weiko 1eeca13458 Fix transactions within rest + limit (#14264) 2025-09-02 21:54:43 +02:00
Raphaël Bosi fed09339f6 Create PageLayout resolver and controller (#14219)
Closes https://github.com/twentyhq/core-team-issues/issues/1393
2025-09-02 16:12:18 +02:00
Charles Bochet 92c27b337a Fix view creation (#14254) 2025-09-02 15:07:15 +02:00
martmull 1801b5086a Remove subscriptions job (#14250)
Remove subscriptions publish job

---------

Co-authored-by: Charles Bochet <charlesBochet@users.noreply.github.com>
2025-09-02 14:40:30 +02:00
github-actions[bot] c613bdc238 i18n - translations (#14252)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-09-02 14:22:50 +02:00
neo773 a7a79090cb fix: QueryRunner overrideDataByFieldMetadata sub fields not being stringified (#14187)
Adding `secondaryLinks` to company is broken, this fixes it

Regression can be traced back to this commit
https://github.com/twentyhq/twenty/pull/10912/files#diff-8a992c6bff80abc8c9075d585d293f6aa98c246df097efb4f904b82dc3ff8114R210-R214



https://github.com/user-attachments/assets/463cee62-8ee3-45dc-9912-fd8fb5244579
2025-09-02 10:05:42 +02:00
github-actions[bot] 2af0e890b2 i18n - translations (#14224)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-09-01 18:47:44 +02:00
Thomas Trompette bcd5cf7f25 Add first frontend version for iterators (#14213)
Add a base for testing iterator step in frontend. Loop next step ids
need to be added to an input since the loop handle does not exist on the
step yet.

Here is an example of run:
<img width="1271" height="653" alt="Capture d’écran 2025-09-01 à 16 21
39"
src="https://github.com/user-attachments/assets/06ecf981-be17-4d31-84f6-11c2cc98cb66"
/>

First create record in the loop name is `{{currentItem}} - first`, the
second is `{{currentItem}} - second`
<img width="276" height="326" alt="Capture d’écran 2025-09-01 à 16 22
25"
src="https://github.com/user-attachments/assets/0ae03b65-aeda-41a6-8693-c17711ec2102"
/>
2025-09-01 16:46:33 +00:00
Charles Bochet 22a200171e Fix view performances (#14209) 2025-09-01 15:24:30 +02:00
Antoine Moreaux 98de9259eb fix(billing): retain original casing for event_name in Stripe meter… (#14204)
…ed event creation
2025-09-01 13:38:03 +02:00
github-actions[bot] fb3341dd9c i18n - translations (#14182)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-08-30 17:46:04 +02:00
neo773 8ab71fef1f feat: message folders control (#14144)
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2025-08-30 17:39:10 +02:00
github-actions[bot] d87eaa141e i18n - translations (#14179)
Created by Github action

---------

Co-authored-by: Crowdin Bot <support+bot@crowdin.com>
Co-authored-by: github-actions <github-actions@twenty.com>
2025-08-30 17:07:07 +02:00
github-actions[bot] 2043694a8f i18n - translations (#14178)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-08-30 17:01:10 +02:00
github-actions[bot] 9e4e8009d7 i18n - translations (#14172)
Created by Github action

---------

Co-authored-by: Crowdin Bot <support+bot@crowdin.com>
Co-authored-by: github-actions <github-actions@twenty.com>
2025-08-30 14:42:31 +02:00
Charles Bochet cef476cd76 Add logs to worker job handling (#14171)
I'm troubleshooting queue worker getting stuck on production and I
suspect a particular job to be the root cause. However I can pinpoint
which one it is. Adding this logs will be helpful to troubleshoot
2025-08-30 14:08:30 +02:00
Weiko 316055be64 Replace view tables position columns from integer to double (#14162) 2025-08-29 18:39:11 +02:00
Antoine Moreaux 1c4568c8b1 feat(pricing/ai): improve billing metered pricing + add pricing on ai chat (#14092)
## TODO:

- [x] display "yearly" or "monthly" wording everywhere it's needed
- [ ] Add button with "downgrade" or "upgrade" to save the change of
credits price + modal to validate
- [x] Add renewal date 
- [ ] Implement
https://docs.stripe.com/billing/subscriptions/subscription-schedules for
`switchFromYearlyToMonthly` and decrease number of credits
2025-08-29 16:23:07 +00:00
Raphaël Bosi 0bdd1c4803 Various fixes on core views (#14093)
- Fix fragments
- Add id to create inputs
- Refresh core views
- Fix kanban loading
- Fix core views creation from current view

---------

Co-authored-by: Charles Bochet <charles@twenty.com>
2025-08-29 11:20:56 +02:00
martmull 71d97c5398 14064 extensibility add coretriggereventlistener table (#14138)
This Pr continues the extensibility journey
- adds a `core.databaseEventTrigger` table
- add a oneToMany relation between `core.serverlessFunction` and
`core.databaseEventTrigger`
- add a job `CallDatabaseEventTriggerJobsJob` triggered by
`EntityEventsToDbListener` triggering `serverlessFunction` based on the
`core.databaseEventTrigger.settings.eventName`
- add a new `trigger-queue` to carry this job
- renamed `DatabaseEventTriggerListener` into
`WorkflowDatabaseEventTriggerListener`
2025-08-29 08:11:35 +02:00
Weiko af6fc1e9ef Add universal identifier to view tables (#14139)
## Context
Introducing a new SyncableEntity abstraction that can be extended by
Entities that we want to "sync" via their universal identifier (the
class will add this uuid to the entity). Starting with views, will
refactor existing syncable entities such as objects/fields later
2025-08-28 17:33:39 +02:00
Félix Malfait e264d7f32b fix: Enable Lingui recommended rules and fix all translation violations (#14133)
- Enable lingui/no-single-variables-to-translate and all other
recommended Lingui rules
- Fix single variable translation patterns (t`${variable}` → variable)
- Fix expression-in-message violations by extracting variables
- Fix t-call-in-function violations by moving translations inside
functions
- Update ESLint configs to use linguiPlugin.configs['flat/recommended']
- Clean up unused imports and improve translation patterns
2025-08-28 15:12:38 +02:00
neo773 6eb9a4e024 Smtp username (#14134)
Tested with vendor resend.com

/closes #14120
2025-08-28 14:49:39 +02:00
martmull 9b41a3be54 Add cron trigger table (#14110)
This Pr begins the extensibility journey
- adds a `core.cronTrigger` table
- add a oneToMany relation between core.serverlessFunction and
`core.cronTrigger` (one serverlessFunction can be triggered by multiple
cronTriggers)
- add a job to trigger a serverless function
- adds a cron to trigger serverlessFunction (via the trigger job) based
on the core.cronTrigger.setting.pattern
- adds a command to register the cron
- add the command in `cron-register-all.command.ts`
2025-08-28 14:47:48 +02:00
Weiko dec2239ae7 Remove typeorm service (#14116)
## Context
To simplify the way we inject our default datasource, I've recently
removed the token injection that was confusion since we only had once
configured on the module level. Now I'm removing TypeORM service which
allows us to instantiate a new Datasource with the same parameters as
the default one, it was redundant and confusing.
2025-08-28 13:21:26 +02:00
github-actions[bot] c15f5c07f8 i18n - translations (#14126)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-08-28 12:35:22 +02:00
Weiko 533d7fe49a Deprecate legacy core datasource token (#14096) 2025-08-27 20:09:54 +02:00
github-actions[bot] c6aa419c18 i18n - translations (#14114)
Created by Github action

---------

Co-authored-by: github-actions <github-actions@twenty.com>
2025-08-27 18:36:40 +02:00
Raphaël Bosi 58db0c9b0a Create PageLayoutWidgetEntity (#14106)
Closes https://github.com/twentyhq/core-team-issues/issues/1391
2025-08-27 16:12:54 +02:00
Raphaël Bosi 262ee457ef Create PageLayoutTab entity (#14104)
Closes https://github.com/twentyhq/core-team-issues/issues/1390
2025-08-27 15:20:24 +02:00
Abdul Rahman 9098df7ddf Add preconfigured Workflow creation agent (#13855)
Co-authored-by: Félix Malfait <felix.malfait@gmail.com>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2025-08-27 14:20:38 +02:00