Skip to content

Commit 3db9757

Browse files
authored
build(deps): bump axios to 1.20.0 (#13056)
The release filesystem scan (Trivy, fs scan of services/idp/pnpm-lock.yaml) flagged 7 HIGH vulnerabilities in axios 1.19.0, all fixed in 1.20.0. Only the 8.0 line is affected, as services/idp no longer exists on 8.1, 8.2 and master. Also adds the 8.0.9 section to CHANGELOG.md, which the 8.0.9 release commit did not regenerate. Signed-off-by: Julian Koberg <julian.koberg@kiteworks.com>
1 parent 4e5f9dd commit 3db9757

4 files changed

Lines changed: 200 additions & 6 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 187 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# Table of Contents
22

3+
* [Changelog for 8.0.9](#changelog-for-809-2026-10-02)
34
* [Changelog for 8.0.8](#changelog-for-808-2026-08-20)
45
* [Changelog for 8.0.7](#changelog-for-807-2026-07-31)
56
* [Changelog for 8.0.6](#changelog-for-806-2026-07-15)
@@ -67,6 +68,192 @@
6768
* [Changelog for 1.1.0](#changelog-for-110-2021-01-22)
6869
* [Changelog for 1.0.0](#changelog-for-100-2020-12-17)
6970

71+
# Changelog for [8.0.9] (2026-10-02)
72+
73+
The following sections list the changes for 8.0.9.
74+
75+
[8.0.9]: https://github.com/owncloud/ocis/compare/v8.0.8...v8.0.9
76+
77+
## Summary
78+
79+
* Security - Bump grpc-go dependency: [#13020](https://github.com/owncloud/ocis/pull/13020)
80+
* Security - Bump axios to 1.20.0: [#13056](https://github.com/owncloud/ocis/pull/13056)
81+
* Bugfix - Keep shares visible in sharedWithMe when a resource cannot be statted: [#12430](https://github.com/owncloud/ocis/pull/12430)
82+
* Bugfix - Release the quota of upload sessions with unreadable node metadata: [#12739](https://github.com/owncloud/ocis/pull/12739)
83+
* Bugfix - Remove the unmarshalable request body field from graph log messages: [#12918](https://github.com/owncloud/ocis/pull/12918)
84+
* Bugfix - Correct introduction version for OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL: [#12949](https://github.com/owncloud/ocis/pull/12949)
85+
* Bugfix - Return a retryable 503 when the OIDC userinfo call fails transiently: [#13047](https://github.com/owncloud/ocis/pull/13047)
86+
* Change - Replace GRPC_MAX_CONNECTION_AGE with client keepalive: [#13020](https://github.com/owncloud/ocis/pull/13020)
87+
* Enhancement - Add TLS support for the frontend stat cache store connection: [#12777](https://github.com/owncloud/ocis/pull/12777)
88+
* Enhancement - Make the public share expiry janitor configurable: [#13020](https://github.com/owncloud/ocis/pull/13020)
89+
* Enhancement - The public link resolution flag added to PROPFIND: [#13020](https://github.com/owncloud/ocis/pull/13020)
90+
91+
## Details
92+
93+
* Security - Bump grpc-go dependency: [#13020](https://github.com/owncloud/ocis/pull/13020)
94+
95+
We've updated the google.golang.org/grpc dependency to fix a reported
96+
denial-of-service vulnerability related to gRPC server handling of requests
97+
missing authority or Host headers. As no tagged release containing the fix was
98+
available yet, we pulled in a pre-release snapshot of grpc-go that includes it,
99+
which also required bumping the minimum Go version to 1.26.8.
100+
101+
https://github.com/owncloud/ocis/pull/13020
102+
103+
* Security - Bump axios to 1.20.0: [#13056](https://github.com/owncloud/ocis/pull/13056)
104+
105+
We've updated the axios dependency of the idp service to 1.20.0. This fixes
106+
several denial-of-service, request-smuggling and server-side request forgery
107+
vulnerabilities flagged by the release filesystem scan.
108+
109+
https://github.com/owncloud/ocis/pull/13056
110+
111+
* Bugfix - Keep shares visible in sharedWithMe when a resource cannot be statted: [#12430](https://github.com/owncloud/ocis/pull/12430)
112+
113+
The graph `sharedWithMe` handler resolves each received share by fanning out a
114+
per-resource `Stat` call with a concurrency limit, all sharing the request
115+
context. When a `Stat` failed for any reason (slow or stuck downstream, deleted
116+
space, gateway error, deadline exceeded) the worker logged at debug and returned
117+
without emitting a drive item, so the share was silently omitted from the
118+
response and the handler still returned `200 OK` with a partial,
119+
non-deterministic list. A single chronically-slow share could therefore make
120+
other, recently-accepted shares intermittently invisible, and repeated calls
121+
returned different subsets of the user's shares.
122+
123+
The handler now:
124+
125+
- bounds each per-share `Stat` with its own timeout derived from the request
126+
context, so one slow resource can no longer consume the deadline shared by all
127+
the other shares. The bound is configurable via
128+
`GRAPH_RECEIVED_SHARES_STAT_TIMEOUT` (default `10s`); - returns a degraded drive
129+
item built from the data already present in the share record (ids, permissions,
130+
grantees, timestamps, mountpoint name) when the resource cannot be statted due
131+
to a transient or indeterminate failure (timeout, slow or unavailable
132+
downstream), so the share stays visible instead of intermittently disappearing.
133+
A genuinely missing resource or revoked access (for example after the sharer was
134+
deleted) still drops the share, as before; - logs the dropped/degraded shares at
135+
warning level with a per-request count for operator visibility.
136+
137+
https://github.com/owncloud/ocis/pull/12430
138+
139+
* Bugfix - Release the quota of upload sessions with unreadable node metadata: [#12739](https://github.com/owncloud/ocis/pull/12739)
140+
141+
When an upload's target node lost its metadata, e.g. because an ancestor was
142+
moved to the trash while the upload was still in flight, the upload could never
143+
finish processing. It stayed in "Processing" forever, could not be downloaded or
144+
deleted, and kept consuming the space quota.
145+
146+
Cleaning such a session up with `ocis storage-users uploads sessions --clean`
147+
did not help either: it removed the uploaded bytes and the session info file
148+
before failing to revert the node, so it destroyed the only copy of the data
149+
without releasing any quota.
150+
151+
Cleanup now reverts the node before removing anything irreversible and falls
152+
back to the session metadata when the node cannot be read, so the quota is
153+
released and the orphaned node is removed. If the quota cannot be released the
154+
upload is kept so it can be retried instead of being lost.
155+
156+
A new `--orphaned` filter lists the affected sessions:
157+
158+
```
159+
ocis storage-users uploads sessions --orphaned
160+
ocis storage-users uploads sessions --orphaned --clean
161+
```
162+
163+
Note that evaluating the filter reads the node metadata of every session, so it
164+
is only done when the flag is set.
165+
166+
https://github.com/owncloud/ocis/pull/12739
167+
168+
* Bugfix - Remove the unmarshalable request body field from graph log messages: [#12918](https://github.com/owncloud/ocis/pull/12918)
169+
170+
We've removed the `body` field from the log messages of the graph service's HTTP
171+
handlers. The field was set from `http.Request.Body`, an `io.ReadCloser`, which
172+
can never be serialized into a useful log value.
173+
174+
The tracing middleware replaces the request body with a wrapper that carries an
175+
exported function field, so serializing it failed outright and the log line was
176+
emitted with `"body": "marshaling error: json: unsupported type: func(int64)"`
177+
instead of the payload. Without the tracing middleware the field serialized to
178+
an empty object. In both cases the intended payload was never logged.
179+
180+
https://github.com/owncloud/ocis/pull/12918
181+
182+
* Bugfix - Correct introduction version for OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL: [#12949](https://github.com/owncloud/ocis/pull/12949)
183+
184+
We changed the documented introduction version of the
185+
OCIS_LDAP_INSTANCE_MAPPER_CACHE_TTL from 8.0.0 to 8.3.0.
186+
187+
https://github.com/owncloud/ocis/pull/12949
188+
189+
* Bugfix - Return a retryable 503 when the OIDC userinfo call fails transiently: [#13047](https://github.com/owncloud/ocis/pull/13047)
190+
191+
A transient failure of the OIDC userinfo call (a timeout, a network error or a
192+
5xx/429 from the IdP) was mapped to HTTP 401. Clients read the 401 as an invalid
193+
session and logged the user out on a brief IdP slowdown.
194+
195+
The proxy now distinguishes a transient IdP failure from an authentication
196+
failure and returns a retryable 503 (with Retry-After) for the former, so
197+
clients retry and keep their session. A genuinely invalid or expired token still
198+
returns 401.
199+
200+
https://github.com/owncloud/ocis/pull/13047
201+
202+
* Change - Replace GRPC_MAX_CONNECTION_AGE with client keepalive: [#13020](https://github.com/owncloud/ocis/pull/13020)
203+
204+
The grpc clients now send a keepalive ping while a request is in flight and fail
205+
the requests on a connection whose peer stops answering, instead of waiting for
206+
as long as the caller allows. This covers both the reva CS3 clients (gateway,
207+
storage-users, storage-shares, ...) and the go-micro based clients used for
208+
inter-service calls between the other oCIS services. Set
209+
GRPC_CLIENT_KEEPALIVE_TIME and GRPC_CLIENT_KEEPALIVE_TIMEOUT to enable and tune
210+
this; leave them unset to keep grpc's own default (no pings).
211+
212+
GRPC_MAX_CONNECTION_AGE has been removed. It only closed healthy connections on
213+
a timer, never ended a request that was already in flight, and silently did
214+
nothing when its value had no unit suffix.
215+
216+
https://github.com/owncloud/ocis/pull/13020
217+
218+
* Enhancement - Add TLS support for the frontend stat cache store connection: [#12777](https://github.com/owncloud/ocis/pull/12777)
219+
220+
The frontend service was the only remaining place where a `nats-js-kv` store
221+
connection could not be secured. Its OCS stat cache forwarded the store type,
222+
nodes, database, table, TTL and credentials to reva, but not the TLS settings,
223+
so the connection stayed plaintext with no operator toggle to change it. The
224+
stat cache now honours `OCIS_CACHE_ENABLE_TLS`, `OCIS_CACHE_TLS_INSECURE` and
225+
`OCIS_CACHE_TLS_ROOT_CA_CERTIFICATE` like every other cache and store.
226+
227+
https://github.com/owncloud/ocis/pull/12777
228+
229+
* Enhancement - Make the public share expiry janitor configurable: [#13020](https://github.com/owncloud/ocis/pull/13020)
230+
231+
The sharing service runs a background janitor that permanently deletes expired
232+
public shares. Whether that cleanup runs at all could previously only be set in
233+
the sharing service's yaml config, and how often it ran was fixed internally
234+
with no way to tune it.
235+
236+
Both settings are now exposed as environment variables:
237+
OCIS_SHARING_ENABLE_EXPIRED_SHARES_CLEANUP toggles the cleanup (default:
238+
enabled, expired shares stay hidden from listings even when disabled), and the
239+
new OCIS_SHARING_JANITOR_RUN_INTERVAL sets the interval in seconds between
240+
janitor runs (default: 3600).
241+
242+
https://github.com/owncloud/ocis/pull/13020
243+
244+
* Enhancement - The public link resolution flag added to PROPFIND: [#13020](https://github.com/owncloud/ocis/pull/13020)
245+
246+
The public link resolution flag and the context timeout added to PROPFIND
247+
request The ocdav PROPFIND handler resolves public link shares to populate the
248+
oc:share-type property. A new toggle for skipping that lookup. The toggle is now
249+
exposed as OCDAV_DISABLE_PROPFIND_PUBLIC_LINK_RESOLUTION, which can be set to
250+
reduce load on services for large collections. Also, the bounded context was
251+
added for least public share request. Since this property is needed only to
252+
display an icon next to files in the list, indicating that a public link exists,
253+
it can be omitted if the ListPublicShares request is slow.
254+
255+
https://github.com/owncloud/ocis/pull/13020
256+
70257
# Changelog for [8.0.8] (2026-08-20)
71258

72259
The following sections list the changes for 8.0.8.
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
Security: Bump axios to 1.20.0
2+
3+
We've updated the axios dependency of the idp service to 1.20.0. This fixes
4+
several denial-of-service, request-smuggling and server-side request forgery
5+
vulnerabilities flagged by the release filesystem scan.
6+
7+
https://github.com/owncloud/ocis/pull/13056

‎services/idp/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@
8888
"@types/react-dom": "^17.0.26",
8989
"@types/react-redux": "^7.1.34",
9090
"@types/redux-logger": "^3.0.13",
91-
"axios": "^1.18.0",
91+
"axios": "^1.20.0",
9292
"classnames": "^2.5.1",
9393
"form-data": "4.0.6",
9494
"i18next": "^23.16.8",

‎services/idp/pnpm-lock.yaml‎

Lines changed: 5 additions & 5 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)