56 Commits
Author SHA1 Message Date
Ruslan KonviserandClaude Opus 5 a472bfa248 fix(security): CSV formula injection + rate-limit residuals (GHSA-7xp5, GHSA-86mw) (#10243)
* fix(security): neutralize spreadsheet formulas in CSV exports

GHSA-7xp5-j564-4752 (medium): exported cells were written verbatim, so a stored
value beginning with = + - or @ executed as a formula when a colleague opened the
export in Excel or Sheets. A shared encoder in @gauzy/utils prefixes an
apostrophe to any cell starting with a formula trigger (including the full-width
forms), leaves strictly numeric values alone, and is reversed on import so an
export/import round-trip stays byte-exact. Every field is now quoted, which also
stops a bare CR inside a value from starting a new spreadsheet row, and the
invoice CSV in the web app gets real RFC 4180 quoting instead of JSON.stringify.

GHSA-86mw-2crg-vmhc residuals (low): the public invite routes are throttled, the
shipped compose files no longer trust a forwarded client IP while publishing the
API port directly, and RequestContext.currentIp() resolves the client address the
same way the throttler does instead of reading a spoofable header.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(cspell): add the new vocabulary and use US spellings

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(export-import): decode CSV cells only for archives we marked

The import side reversed the spreadsheet-formula escape on every parsed row,
but an uploaded ZIP is not necessarily one this server wrote: it can be a dump
from an older Gauzy, a filled-in `/export/template`, or a CSV set built by
external tooling. For those, un-escaping is data loss — a legitimate value such
as `'=notes` was persisted as `=notes`, silently. Both review bots flagged this
as the one thing blocking the merge, and they were right: the decoder had no way
to tell "we escaped this" from "somebody else wrote this".

A data export now carries a `gauzy-export.json` marker at the archive root
(format, version, `spreadsheetSafeCells`), written by `exportTables` and
`exportSpecificTables`. `ImportService` resolves that marker once per import and
decodes rows only when it is present and recognized; anything else is imported
byte for byte as it was parsed. `/export/template` is deliberately NOT marked —
an operator fills it in by hand, so nothing in it was ever escaped. The manifest
reader is defensive about an attacker-supplied file: missing, oversized,
malformed, a foreign format or a newer version all mean "do not decode".

The invoice/payment CSV builder no longer has a path that skips encoding: a
pre-joined header line used to be written through verbatim, and it was the only
value in the file that reached disk unquoted and un-neutralized. `buildCsv` and
`generateCsv` now declare `headers: string[]` (both callers already pass one),
and a stray string from an untyped caller is split and encoded rather than
trusted.

Tests: `import.service.spec.ts` imports the same escaped CSV with and without a
marker and asserts the apostrophe survives when unmarked (reverting the gate
fails those 5 tests); `export.service.spec.ts` asserts the data archive carries
the marker and the template archive does not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-20 14:59:19 +02:00
Ruslan Konviser 24c6a4dbe2 Merge pull request #10225 from heykav/fix/is-class-instance-null-prototype
fix(utils): isClassInstance throws on a null-prototype object
2026-09-18 02:23:38 +02:00
Ruslan Konviser 624355f8b7 fix(utils): don't throw when constructor itself is null or undefined
`{"constructor": null}` is valid JSON, so any parsed payload can carry an own
`constructor` that is null or undefined. Reading `.name` on it throws exactly
like the null-prototype case this branch fixes, and the crash is reachable from
real input: `parseObject`, `deepClone` and `deepMerge` all call
`isClassInstance`, and `{"constructor":null}` survives `JSON.parse` intact.

Read the constructor into a local first and treat null/undefined as plain data.
Behaviour is unchanged for every input that did not already throw - checked
against the pre-fix implementation across 27 object shapes (plain literals,
null-prototype objects, class instances, Date/Map/Set/RegExp, arrays,
primitives, nested values); only the previously-throwing shapes changed, and
all of them now answer `false`.
2026-09-18 02:21:38 +02:00
Trapa-EurekaandClaude Opus 5 d810c81cf3 feat(core): persistence invariants, config/boundary validation, migration smoke test and correlation IDs (#10198)
Adds test harnesses for tenant isolation, TypeORM/MikroORM parity, persistence invariants and idempotency; startup validation for DB config; Nx plugin/core boundary rules; a fresh-database migration smoke test; and a correlation id carried from HTTP requests into docs queue jobs and logs.

Testing (packages/core/src/lib/core/testing):
- tenant-isolation: an in-memory tenant-aware repository, fixtures and strict assertions (a non-empty page, every row in the caller's tenant). Applied to EmployeeService and OrganizationProjectService.
- orm-conformance and persistence-invariants: suites that run the same checks under TypeORM and MikroORM (run-both-orms.sh uses yarn nx).
- idempotency: assertion helpers and specs for token cleanup (positive control), employee notifications and the Zapier timer webhook.
- database/migration-smoke.spec.ts: runs the full migration chain on a fresh better-sqlite3 database. It is excluded from the default core jest run; run it with `nx run core:test-migration-smoke`.

Idempotency:
- EmployeeNotificationService.create() takes an opt-in `absorbRedelivery`. With it set, an identical unread, unarchived notification under 60 s old (same receiver, entity, type, sender, title and message) is returned instead of inserted, and a missing key or a failed lookup inserts as usual. The event handler does not enable it (the in-process EventBus never redelivers), so every caller inserts one row per event as before.
- ZapierWebhookService skips resending a webhook that already succeeded for the same subscription, action and time log within 5 minutes. The key is reserved while in flight, failed deliveries stay retryable, pruning stops at the first unexpired entry, and the cache is capped at 10,000 entries.

Config (packages/config):
- An unknown DB_TYPE fails fast with the list of supported values; an empty DB_TYPE still means better-sqlite3; mongodb throws an Error.
- Pool and timeout variables are parsed with Number.parseInt semantics, only for postgres and mysql. They throw only where tarn already refused to start and warn otherwise. SQLite ignores them and still prints the startup values.

Observability:
- RequestContextMiddleware accepts an inbound x-correlation-id of 1-128 visible ASCII characters (otherwise it generates a UUIDv4) and echoes it on the response. CORS allows and exposes X-Correlation-Id. RequestContext.currentCorrelationId() is added.
- The docs queue carries the correlation id through job payloads (including bulk reindex) into pipeline outcome, error, dead-letter and enqueue-failure logs.

Boundaries and build:
- Every project gets a type tag. The ESLint depConstraints stop type:core depending on plugins, and plugins may depend only on core, shared libs and the known extension points (ai-chat, job-proposal, integration-ai, job-*-ui).
- core declares @gauzy/scheduler (package.json and implicitDependencies); the webapp Dockerfile copies scheduler's package.json.
- The integration-zapier jest config can import @gauzy/core (transformIgnorePatterns, allowJs, isolatedModules).
- Fixes the stale @nrwl/nx eslint-disable id in the e2e roles-permissions steps and the broken @gauzy/core mock in the docs document-scope spec.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 23:35:52 +02:00
Krishna Anubhav ( Kavy ) f434f92c3b test(utils): cover isClassInstance/deepClone/deepMerge with null-prototype objects 2026-09-18 01:30:22 +05:30
Krishna Anubhav ( Kavy ) ec96bafdc7 fix(utils): isClassInstance throws on a null-prototype object 2026-09-18 01:30:21 +05:30
Ruslan KonviserandClaude Opus 5 9c866c72e1 fix(security): cover reserved address ranges and harden the connect-time lookup
Three follow-ups from the independent verification of the connection-level
SSRF guard.

The private-address predicate in @gauzy/utils treated several special-purpose
ranges as public: benchmarking space 198.18.0.0/15 (a common cluster CIDR),
the IETF and documentation ranges, multicast, 240.0.0.0/4, deprecated
site-local fec0::/10, the NAT64 local-use prefix 64:ff9b:1::/48 and the
deprecated IPv4-compatible ::a.b.c.d form, so [::7f00:1] passed the literal
check. They are now refused. The shared predicate is also used by the core
SSRF agent and the Make.com, Zapier and Ever Async integrations; none of their
legitimate destinations sits in these ranges.

The validating lookup's promise chain now ends in a catch. If Node's connect
callback ever threw synchronously, the throw would otherwise become an
unhandled rejection, which terminates the process on Node 24.

An empty constructor in a spec mock tripped the no-empty-function lint rule.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 12:31:24 +02:00
Ruslan KonviserandClaude Opus 5 f89cb35b37 fix(security): harden AI-provider SSRF guard and webhook secret handling
Addresses the review findings on the GitHub webhook and AI-provider SSRF fix.

The DNS pre-flight in ssrfSafeFetch now fails closed: only a definitive
non-existence answer (ENOTFOUND and equivalents) is let through, every other
resolver failure is refused. Verdicts are no longer cached, IP literals skip
the lookup, and the lookup honours the request AbortSignal so a stalled
resolver cannot outlive the dictation or catalogue timeout. The successful
transcription body is now read under a 4 MiB byte budget instead of being
buffered whole by response.json().

GAUZY_AI_CHAT_ALLOW_PRIVATE_BASE_URLS now governs tenant-entered base URLs
only. The new isPrivateAiProviderEndpointAllowed(credentials) helper allows
operator environment values and built-in local defaults, and the twelve
catalogue and speech call sites across nine provider plugins pass it.

A resolver seam is threaded through fetchCatalogueJson and the speech helpers
and the provider specs stub dns.lookup, so the suites no longer depend on live
DNS and the raised testTimeout in five jest configs is removed.

isPrivateOrLoopbackHost in @gauzy/utils now recognises NAT64 (64:ff9b::/96)
and 6to4 (2002::/16) addresses that embed a private IPv4 address, which also
covers the Make.com and Zapier webhook guards.

The webhook receiver keys the HMAC with the configured secret verbatim and
trims only to detect a blank one. Test fixtures for the secret are generated
at runtime, the raw-bytes test now really distinguishes raw bytes from a
re-serialization, and the credential service gains tests for the
null-clear and omitted base URL branches.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 05:46:03 +02:00
Ruslan KonviserandClaude Opus 5 52ae8427fe Fix: make ESLint runnable again across the workspace (#10117)
No lint invocation in this repo could reach a single file. `nx run-many -t lint --all` failed for
93 of 93 projects, and no CI workflow runs lint, so nothing ever noticed. Two independent bugs,
either of which alone was fatal.

1. The root `eslint.config.js` was `module.exports = new FlatESLint({ overrides: [] })`, importing
   a `FlatESLint` class from `@nx/eslint-plugin-nx`. That could never have worked: a flat config
   must export an array, and no Nx package has ever exported such a class. `@nx/eslint-plugin-nx`
   is the beta-only predecessor NAME of `@nx/eslint-plugin` — the repo declared both, the real one
   at ^22.5.2 and this one pinned at 16.0.0-beta.1. The v16 beta drags a nested `@nx/devkit@16`
   that expects an `nx` internal path nx@22 no longer ships, so every `eslint` invocation died
   with `Cannot find module 'nx/src/utils/typescript'`.

2. All 41 project configs did `[...require('../../.eslintrc.json')]`. That file is a JSON object,
   so the spread threw `TypeError: baseConfig is not iterable` — a different failure, on the path
   `nx lint <project>` actually takes. `packages/mcp-server` also had the wrong depth.

Changes: remove `@nx/eslint-plugin-nx`, add `typescript-eslint@^8.40.0` (the only genuinely
missing package — `@nx/eslint-plugin`'s flat configs require it unconditionally); rewrite the root
config as a real flat array shaped like Nx 22's own generator output, with real `ignores`
replacing the legacy `"ignorePatterns": ["**/*"]` that disabled linting workspace-wide; repoint
all 41 project configs at the root flat config, dropping the FlatCompat bridge the 12 `.cjs` ones
used; disable the deprecated `@typescript-eslint/no-empty-interface`, which Nx's presets still
enable alongside its v8 replacement `no-empty-object-type` and so double-reported every
occurrence; and re-enable `no-dupe-keys`, `no-dupe-class-members`, `no-dupe-args` and
`no-unreachable`, which typescript-eslint's `eslint-recommended` overlay turns off on the grounds
that `tsc` reports them — no CI job here runs `tsc --noEmit`, and a duplicate key in
`packages/core/jest.config.ts` has already silently changed behaviour once.

The legacy `.eslintrc.json` files are deliberately KEPT: `.codacy/codacy.yaml` pins eslint@8.57.0,
which does read them.

The guardrail is proven, not assumed — against the real historical bug:

    packages/core/jest.config.ts
      29:2  error  Duplicate key 'transformIgnorePatterns'  no-dupe-keys

Findings are REPORTED, NOT FIXED (a separate job): 8,887 files linted, 2,290 with problems,
2,649 errors / 6,110 warnings, zero parse errors. Lint should not become a required check until
that backlog is triaged.

Verified: packages/core 56/56 suites and 612/612 tests; build-monorepo-root, build-api, build-libs
and build-web all green; all 42 configs load; `nx lint <project>` now runs and reports instead of
crashing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 13:07:25 +02:00
Ruslan Konviser 5322891a65 Merge remote-tracking branch 'origin/develop' into fix/sec-ssrf-egress
# Conflicts:
#	.cspell.json
2026-06-27 19:18:56 +02:00
Ruslan KonviserandClaude Opus 4.8 a118faa27a fix(security): address review feedback on SSRF egress guards
- utils (isPrivateOrLoopbackHost): normalize a trailing root dot (localhost.), detect IPv4-mapped
  IPv6 in BOTH dotted (::ffff:127.0.0.1) and hex (::ffff:7f00:1) forms, and match the full fe80::/10
  link-local and fc00::/7 unique-local ranges via first-hextet masking instead of crude string
  prefixes (CodeRabbit/Greptile).
- make-com webhook: add an SSRF-safe HTTPS agent whose DNS resolver refuses connections to
  private/loopback/link-local resolved IPs, and use it for the outbound POST. This closes
  DNS-rebinding / hostname-based SSRF at connection time (no TOCTOU gap) on top of the literal
  store-time/request-time checks (CodeRabbit Critical / Greptile P1).
- make-com-api: validate the stored zone once via getValidatedZone() and reuse it in
  getZoneBaseUrl/getZone/getSetupStatus so read paths and isComplete stay consistent and never
  expose an out-of-allowlist zone (CodeRabbit).
- cspell: allowlist security vocabulary and identifiers.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 16:51:42 +02:00
Ruslan KonviserandClaude Opus 4.8 1801cf865a fix(security): address review feedback on injection hardening
- image-asset: add content-based validation. The multer fileFilter only inspects the
  client-controlled MIME type/filename (spoofable), so re-check the stored bytes and reject
  markup (SVG/XML/HTML/XHTML) that would execute as stored XSS from /public. The rejected file is
  deleted because /public serves from disk regardless of the DB record (flagged by CodeRabbit/Cubic).
- deep-clone: only skip __proto__ (not constructor/prototype). Cloning must preserve ordinary own
  data keys named constructor/prototype; the dangerous recursion only exists in deepMerge, which
  still blocks all three (flagged by Cubic).
- search handler: reuse the exported PLUGIN_SORTABLE_FIELDS / PLUGIN_SORT_DIRECTIONS from the DTO
  instead of duplicating the allowlist, so validation and the SQL sink cannot drift.
- cspell: allowlist security vocabulary and advisory-id fragments.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 16:41:05 +02:00
Ruslan KonviserandClaude Opus 4.8 4dabd55660 fix(security): SSRF egress guards for Make.com (zone + webhook) and Zapier
- make-com: validate the `zone` against the MAKE_COM_ZONES allowlist via a SetZoneDTO
  (`@IsIn`) + `@UseValidationPipe`, and re-check it before building the API base URL, so a
  tenant can no longer inject an arbitrary host into `https://${zone}.make.com/...`
  (GHSA-vcwx-qh95-54g6).
- make-com: validate the stored `webhookUrl` with an SSRF egress guard at store time AND
  again before each outbound POST, rejecting non-HTTPS, embedded credentials,
  loopback/private/link-local hosts and the cloud-metadata IP (GHSA-534m-c6mh-mp98).
- utils: add a reusable, browser-safe `getUnsafeOutboundUrlReason` /
  `isPrivateOrLoopbackHost` helper, used by both integrations.
- zapier: apply the same egress guard UNCONDITIONALLY (the private-IP/loopback block
  previously ran only when `NODE_ENV === 'production'`, leaving dev/staging unprotected).

Note: literal host/IP checks only; DNS-rebinding / hostname->private-IP hardening (resolve
and re-check at request time) is a recommended follow-up.

Refs: GHSA-vcwx-qh95-54g6, GHSA-534m-c6mh-mp98

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 16:19:08 +02:00
Ruslan KonviserandClaude Opus 4.8 37f376d9b9 fix(security): harden against SQL injection, prototype pollution and SVG XSS
- registry: validate plugin search/category `sortBy` & `sortDirection` against an
  explicit allowlist (`@IsIn`) instead of `@IsString`, closing the unauthenticated
  ORDER BY SQL injection (GHSA-xqcf-j9jr-7w59). A case-normalizing `@Transform`
  keeps legacy `asc`/`desc` clients working, and the query handler also clamps the
  sort inputs as defense-in-depth.
- utils: filter `__proto__`/`constructor`/`prototype` in `deepMerge` and
  `deepClone` to prevent prototype pollution (GHSA-qfc6-v3g6-rxf8), and give
  `POST /auth/email/verify/resend-link` a validated DTO + `whitelist` pipe.
- core: reject SVG and other non-raster uploads on the image-asset endpoint via a
  multer `fileFilter` (passed through `LazyFileInterceptor`) to stop stored XSS
  from `/public/<key>` (GHSA-p334-cm7f-php5).

Refs: GHSA-xqcf-j9jr-7w59, GHSA-qfc6-v3g6-rxf8, GHSA-p334-cm7f-php5

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 15:51:20 +02:00
Rahul R. c9a475c338 [Fix] Hidden Sidebar Menus (#9569)
* feat(utils): parse env variables with fallback value

* fix(pages): use `pages.routes` instead of `pages-routing.module`

* fix(ui-core): base nav menu standlone component & improve menu category

* fix(core): update `tenant-aware-crud.service` to support save many method without checking tenant

* fix(core): update `task-metadata.service` for execute tenant update tasks

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* fix(ui-auth): update auth APIs service methods

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* fix(ui-core): build for tooltip directive

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]

* Apply suggestion from @greptile-apps[bot]
2026-03-05 18:44:29 +01:00
Ruslan Konviserandcoderabbitai[bot] b70bc3dc55 Fix/more security (#9506)
* fix: more security focused fixes

* fix: add env var to all relevant places

* fix: multiple ORMs

* Update packages/config/src/lib/environments/environment.prod.ts

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Update packages/core/src/lib/auth/email-confirmation.service.ts

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* fix: more

* chore: spelling

* fix: more

* fix: regex

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-02-24 18:06:43 +01:00
b161467904 chore: update Angular to v21 (#9390)
* @rahul-rocket chore(deps): chore(deps): bump @angular/core from ^20.2.4 to 21.1.2

* fix(ui): update missing jest.preset.js

* fix(nx-migrations): migrate nx from 21.5.1 to 22.4.4

* chore(deps): bump jest-preset-angular to 16.0.0

* chore(deps): bump @nebular/* packages to 17.0.0 for Angular 21 compatibility

* chore(deps): upgrade all packages to Angular 21 and compatible dependencies

* chore(deps): upgrade all packages to Angular 21 and compatible dependencies

* fix(nx-migrations): migrate nx from 21.5.1 to 22.4.4

* Update yarn.lock

* Update yarn.lock

* fix(nx-migrations): migrate nx from 21.5.1 to 22.4.4

* fix(nx-migrations): migrate nx from 21.5.1 to 22.4.4

Replace 'jest-preset-angular/setup-jest' imports with the new 'setupZoneTestEnv' function.

* @nx/jest: replace-removed-matcher-aliases-v22-3

Replace removed matcher aliases in Jest v30 with their corresponding matcher

* chore(deps): @angular/common and @angular/core peerDependencies to ^21.1.0

* Update package.json

* fix(nx-migrations): migrate nx from 21.5.1 to 22.4.4

* chore(deps): bump @nebular/theme from ^16.0.0 to ^17.0.0

* chore(deps): upgrade all packages to Angular 21

* chore(deps): upgrade all packages to Angular 21

* fix(build): update helmet import to support 8.x default export

* fix(build): resolve TypeScript errors and improve code quality

- Fix TemplateRef type conflicts caused by duplicate @angular/core packages (ngx-permissions)
- Change moment imports from namespace to default imports for ESM compatibility
- Convert constructor injection to inject() function in multiple components
- Add OnPush change detection strategy to WindowLayoutComponent
- Make CountdownConfirmationComponent standalone
- Update LayoutWithDraggableObject to use any[] for draggableObject type

* fix(build): fix moment & timezone namespace packages

* fix(build): add jest config for missing packages

* chore(deps): bump swiper from 8.3.1 to 12.1.0

* fix(build): update swiper module and syntax

* Update time-tracking.component.ts

* chore(deps): downgrade `node-polyfill-webpack-plugin` from 4.1.0 to 1.1.4

* fix(deps): resolve browserslist "Unknown version 143 of and_chr" error

Add caniuse-lite and browserslist to yarn resolutions to force all

* fix(nx-migrations): migrate nx from 21.5.1 to 22.4.4

* fix(deps): standardize Angular 21.0.0 versions across all packages and fix compatibility issues

- Fix @angular/* packages to use exact version 21.0.0 (remove caret ^) across all apps, packages, and plugins
- Add @angular/cdk resolution to 21.0.0 to force consistent version

* fix(build): `ui-config` replace env files module issue

* fix(build): `ui-config` replace env files module issue

* fix(build): replace all TemplateRef<HTMLElement> with TemplateRef<any>

* Update package.json

* Update apps\agent\tsconfig.json

* chore(deps): upgrade packages to latest version

* Update yarn.lock

* Update yarn.lock

* fix(build): apply AI suggestion by bot agent reviewers

* fix(build): apply AI suggestion by bot agent reviewers

* fix(nx-migrations): migrate nx from 21.5.1 to 22.4.4

* chore(deps): bump @nestjs/common and @nestjs/core to 11.1.14

* fix(build): replace all TemplateRef<HTMLElement> with TemplateRef<any>

* fix(plugins): apply AI suggestion by bot agent reviewers

* Update yarn.lock

* chore(deps): bump packages

* Update yarn.lock

* chore(deps): bump packages

* chore(deps): bump packages

* fix(plugins): replace 'jest-preset-angular/setup-jest' imports with the new 'setupZoneTestEnv'

* fix(plugins): apply AI suggestion by bot agent reviewers

* fix(cspell): typo spelling :-)

* fix(plugins): apply AI suggestion by bot agent reviewers

* fix: fontawesome icon change version to FA 7

* refactor(ui-core): migrate dashboard directives to standalone

* refactor(ui-core): migrate pipes/directives to standalone

* fix(plugins): apply AI suggestion by bot agent reviewers

* fix(plugins): apply AI suggestion by bot agent reviewers

* chore(deps): bump packages

* refactor(ui-core): migrate directives to standalone

* fix(plugins): apply AI suggestion by bot agent reviewers

---------

Co-authored-by: Ruslan Konviser <evereq@gmail.com>
Co-authored-by: syns2191 <sutralian@gmail.com>
2026-02-20 09:52:34 +01:00
Ruslan Konviser 9804ca0754 fix: builds 2026-02-01 15:24:22 +01:00
Rahul R. 8a4a8edd52 chore(deps): upgrade packages (#9387)
* chore(deps): bump typescript from ^5.8.0 to ^5.9.3

* chore(deps): bump tslib from ^2.3.0 to ^2.6.2

* Update yarn.lock

* Update apps\desktop-timer\src\package.json
2026-01-31 13:10:37 +01:00
Rahul R. ab6c4d549f chore(deps): downgrade tslib from 2.6.2 to 2.3.0
fix(ui): downgrade tslib to resolve Angular build warnings
fix(build): downgrade tslib to 2.3.0 for Angular compatibility
2026-01-31 14:36:10 +05:30
Rahul R. 947bf55f8d chore(deps): bump @ng-select/ng-select from ^14.9.0 to ^20.7.0 2026-01-31 11:30:36 +05:30
Rahul R. 20e0bc6f3d chore(deps): upgrade to Node 24 LTS compatible versions
- ngx-countdown: ^19.0.0 → ^20.0.0
- ngx-draggable-dom: ^19.0.7 → ^20.0.0
- @types/node: ^20.14.9 → ^24.10.0
2026-01-24 12:30:52 +05:30
Rahul R. 2b2b43df88 Reapply "fix: trying to faster build for packages"
This reverts commit dcbea3ba59.
2026-01-24 11:03:37 +05:30
Rahul R. dcbea3ba59 Revert "fix: trying to faster build for packages"
This reverts commit c3c0cc29e2.
2026-01-23 19:11:35 +05:30
Rahul R. c3c0cc29e2 fix: trying to faster build for packages 2026-01-23 13:27:01 +05:30
Rahul R.anddependabot[bot] 514dbc258b chore(deps): packages updates (#9340)
* chore(deps): bump nx from 21.1.0 to 21.2.0

* chore(deps): chore(deps): bump @angular/core from ^19.2.17 to ^20.0.7

- Update @angular/common and @angular/core peerDependencies from ^19.2.17 to ^20.0.7 across all UI packages
- Upgrade @nebular packages (auth, eva-icons, security, theme) from ^15.0.0 to ^16.0.0
- Update @nebular/bootstrap from ^9.1.0-rc.6 to ^9.1.0-rc.8

* chore(deps): upgrade all packages to Angular 20 and compatible dependencies

Angular packages updated to ^20.0.7 (cdk/material to ^20.0.6):
- @angular/animations, common, compiler, core, forms, language-service
- @angular/platform-browser, platform-browser-dynamic, router, service-worker
- @angular/cdk, @angular/material

* chore(deps): bump @swimlane/ngx-charts from ^22.0.0-alpha.1 to ^23.0.0

* fix(deps): upgrade Angular 20 compatible third-party packages

- @angular-slider/ngx-slider: ^19.0.0 → ^20.0.0
- @bluehalo/ngx-leaflet: ^19.0.0 → ^20.0.0
- @swimlane/ngx-charts: ^22.0.0-alpha.1 → ^23.0.0

* chore(peer-deps): downgrade @angular/core to ^20.0.0

* chore(deps): bump nx from 21.1.0 to 21.2.0

* fix: resolve Angular control flow migration errors

* chore(deps): bump nx from 21.1.0 to 21.2.0

* chore(deps): bump tar from 7.4.3 to 7.5.3

Bumps [tar](https://github.com/isaacs/node-tar) from 7.4.3 to 7.5.3.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v7.4.3...v7.5.3)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump nx from 21.1.0 to 21.2.0

* chore(deps): bump nx from 21.1.0 to 21.2.0

* Update dashboard-skeleton.component.html

* fix: build issue

* refactor(package): simplify `build:package:common` command

* refactor(package): simplify `build:package:core` command

* refactor(package): simplify `build:package:ui-auth` command

* refactor(package): simplify `build📦*` commands

* refactor(package): simplify `build📦*` commands

* chore(deps): upgrade typeorm to 0.3.28 across all packages

* chore(deps): upgrade uuid to 13.0.0

* chore(deps): upgrade moment-timezone to 0.6.0

* chore(deps): upgrade typescript to 5.9.3

* chore(deps): upgrade angular2-smart-table to 4.1.1

* Revert "chore(deps): upgrade angular2-smart-table to 4.1.1"

This reverts commit 42045044ab.

* chore(deps): upgrade typescript to 5.9.3

* chore(build): add CommonJS dependencies to allowed list for `desktop-ui-lib`

* Update menu-item.component.html

* Update menu-item.component.ts

* fix: seeder command

* fix: tasks sprint settings view

* chore(deps): downgrade @ng-select/ng-select from 15.0.0 to 14.9.0

* chore(deps): upgrade terser-webpack-plugin to 5.3.16 and camelcase to 9.0.0

- Update terser-webpack-plugin across all apps
- Upgrade camelcase and fix imports for v9 default export
- Remove unused camelcase from apps/gauzy and root package.json

* chore: upgrade @nestjs/* packages to latest versions

- Upgrade core NestJS packages from 11.1.10 to 11.1.12:
  * @nestjs/common
  * @nestjs/core
  * @nestjs/platform-express
  * @nestjs/testing
  * @nestjs/microservices
  * @nestjs/platform-socket.io
  * @nestjs/websockets

- Upgrade GraphQL packages:
  * @nestjs/apollo: 13.1.0 → 13.2.3
  * @nestjs/graphql: 13.1.0 → 13.2.3
  * Add @as-integrations/express5: ^1.1.2 (required for GraphQLModule)

- Upgrade other NestJS packages:
  * @nestjs/jwt: 11.0.0 → 11.0.2
  * @nestjs/serve-static: 5.0.3 → 5.0.4
  * @nestjs/swagger: 11.1.5 → 11.2.5
  * @nestjs/throttler: 6.4.0 → 6.5.0

- Add camelcase resolution (^9.0.0) to root package.json

Updated across all apps and packages in the monorepo.

* chore(deps): bump dotenv from ^16.0.3 to ^17.2.3

* Update public layout component html

* chore(deps): bump angular2-smart-table from ^3.7.0 to ^4.1.1

* chore(deps): bump dotenv from ^16.0.3 to ^17.2.3

* Update package.json

* chore(deps): upgrade @mikro-orm/* packages to 6.6.4

Upgrade all @mikro-orm packages from 6.4.13 to 6.6.4 across core, config,  plugins, and desktop-api packages.

* perf: optimize API startup (reduce DB retries/timeouts)

* Update selector.abstract.ts

* fix(config): use Number.parseInt and simplify db timeout logic

* Update yarn.lock

* chore(deps): upgrade packages to latest versions

* Update package.json

* chore(deps): upgrade packages to latest versions

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-21 17:08:25 +01:00
samuel mbabhazi 605e09cb2d Merge pull request #9312 from ever-co/fix/8504-replace-bcrypt-with-crypto
Fix/8504 replace bcrypt with crypto
2026-01-07 09:10:43 +01:00
Rahul R. 9fac5b43cc fix: update x migration using migrations.json 2026-01-06 16:52:17 +05:30
Ruslan Konviser a9ede6e0cb chore: update Node requirements 2025-12-22 23:24:15 +01:00
Ruslan Konviser d1b70b94b1 chore: update NodeJs 2025-06-21 21:15:02 +02:00
Rahul R. 460f7936f9 fix: move base query DTO to core DTOs folder 2025-05-14 12:40:37 +05:30
Rahul R. 786d8edc09 fix(api): set query parser to extended 2025-05-13 12:28:30 +05:30
Rahul R. e6b86f4c9d [Chore] Support Angular v19 (Nx v20.8.0) (#8610)
* chore(nx): migrate @nx/workspace to version 20.3.0

* chore(material): run migration-v19 for Angular Material update

* chore(packages): run explicit-standalone-flag migration for Angular v19

* chore(deps): downgrade TypeScript to 5.5.4 for Angular compatibility

* chore(deps): bump Angular ESLint dependencies to version 19

* chore(deps): bump @ng-select/ng-select to version 14.1.0

* chore(deps): bump @commitlint packages to latest versions

* fix(cspell): typo spelling :-)

* chore(packages): migrate initializers to new provider functions

* chore(deps): update the @angular/cli package version to ~19.0.0

* chore(deps): update packages to support Angular v19

* chore(packages): migrate initializers to new provider functions

* fix: correct Sentry.TraceService injection in AppInitializer

* Update yarn.lock

* Update yarn.lock

* fix: update yarn.lock

* fix(cspell): typo spelling :-)

* fix: update yarn.lock

* chore(deps): bump @angular/common to version 19.0.0

* chore(nx): migrate @nx/workspace to version 20.4.2

* chore(deps): update yarn.lock

* chore(nx): migrate @nx/workspace to version 20.4.4

* chore(deps): bump @angular/core from 19.1.5 to 19.1.6

* chore(deps): upgrade @nebular/auth and @nebular/theme to v15

- Upgrade @nebular/auth from ^14.0.2 to ^15.0.0
- Upgrade @nebular/theme from ^14.0.2 to ^15.0.0

* chore(deps): bump @angular-slider/ngx-slider from ^18.0.0 to ^19.0.0

* chore(deps): bump ngx-page-scroll and ngx-page-scroll-core to v14

- Bump ngx-page-scroll from ^13.0.0 to ^14.0.0
- Bump ngx-page-scroll-core from ^13.0.0 to ^14.0.0

* chore(deps): bump ngx-permissions from ^17.1.0 to ^19.0.0

* chore(deps): bump @ng-select/ng-select from ^14.1.0 to ^14.2.2

* chore(deps): bump @fortawesome/angular-fontawesome from 0.15.0 to 1.0.0

* fix: desktop build (make component standalone disabled)

* chore(deps): bump @angular/core from 18.2.12 to 19.1.6

* chore(nx): migrate @nx/workspace to version 20.8.0

* chore(deps): bump ng2-file-upload to version ^8.0.0

* chore(deps): bump @angular/core from 19.1.6 to 19.2.7

* chore(deps): bump @fullcalendar/core from ^6.1.15 to ^6.1.17

* chore(deps): bump @angular-eslint packages to v19.3.0

* fix: add `standalone: false` to angular components

* chore(deps): downgrade @angular-builders/custom-webpack from v19.0.1 to v18.0.0

* chore(deps): bump angular2-smart-table from ^3.5.0 to ^3.6.1

* refactor(styles): replace @import with @use for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* chore(deps): bump @angular/core from 19.0.0 to 19.2.0

* chore(deps): updated dependencies for `@fullcalendar/angular`

* fix(cspell): typo spelling :-)

* Revert "chore(deps): updated dependencies for `@fullcalendar/angular`"

This reverts commit 4b34d72071.

* chore(deps): switch @angular/* to ^19.2.7

* fix: revert nx migrations.json

* Revert "chore(deps): switch @angular/* to ^19.2.7"

This reverts commit edd9105c51.

* fix: align @angular/cdk version with @angular/core version

* chore(deps): bump @angular-builders/custom-webpack from 18.0.0 to 19.0.1

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* refactor(styles): replace `@import` with `@use` for SCSS module

* chore(deps): bump typescript from 5.5.4 to ^5.8.3

* fix(server-dashboard): remove redundant nullish coalescing from autoStart check

* fix: add suggestions from greptile-apps bot review

* fix: add suggestions from greptile-apps bot review
2025-04-26 15:47:55 +05:30
Rahul R. e9ccea9d6b fix: removed unused file 2025-01-25 11:08:54 +05:30
Rahul R. 966919c14f refactor: plain & interface of object uses 2025-01-24 16:52:04 +05:30
Rahul R. fb09f86732 feat: added plan object & instance of object 2025-01-24 16:37:49 +05:30
Rahul R. 712e05c355 fix: added few constants and utils 2025-01-24 12:47:45 +05:30
Rahul R. 260567cb1a fix: update Array Sum utils function 2025-01-23 14:04:04 +05:30
Rahul R. 45eb0b37bc fix: update Array Sum utils function 2025-01-23 13:20:52 +05:30
Rahul R. 5967958987 Merge branch 'develop' into fix/tenant-setting-middleware 2025-01-23 13:13:57 +05:30
Rahul R. 23680f8113 fix(cspell): typo spelling :-) 2025-01-23 13:12:19 +05:30
Rahul R. c717a7a71a fix: updated @gauzy/utils version 2025-01-23 12:35:36 +05:30
Rahul R. 26b1aab78b fix: updated @gauzy/utils version 2025-01-23 11:31:44 +05:30
Rahul R. ececdd5578 refactor: updated @gauzy/utils package 2025-01-22 18:15:14 +05:30
Rahul R. 3f0d5388ce fix: moved tenant setting middleware to tenant setting folder 2025-01-22 14:37:06 +05:30
Rahul R. 998ee01396 feat(utils): add isJSON utility function to validate JSON strings 2025-01-22 12:20:07 +05:30
adkif 7430573592 Revert "fix: moves isJSON utility to @gauzy/utils package"
This reverts commit 07303b582f.
2025-01-21 10:52:49 +02:00
adkif 07303b582f fix: moves isJSON utility to @gauzy/utils package
Moves the `isJSON` utility function from `desktop-lib` to the shared `@gauzy/utils` package to avoid code duplication and promote reusability.

Removes the now redundant `util.ts` file from `desktop-lib`.
2025-01-17 23:55:12 +02:00
Rahul R. d29e8f0281 feat: array random element utils 2025-01-13 16:30:48 +05:30
Rahul R. fc291e9b09 fix: update directory paths for packages inside modules folder
This PR updates the `repository.directory` field in the `package.json` files for packages located within the `packages` folder.
2025-01-11 11:58:43 +05:30