Skip to content

[RELEASE] 4.4.0 - #1490

Merged
Badatos merged 28 commits into
mainfrom
dev_v4
Sep 17, 2026
Merged

Badatos merged 28 commits into
mainfrom
dev_v4

Conversation

@Badatos

@Badatos Badatos commented Jul 8, 2026 •

Copy link
Copy Markdown
Collaborator

Prepare next 4.4.0 release

Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.1.1 to 12.2.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@12.1.1...12.2.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 12.2.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Olivier Bado-Faustin <12731381+Badatos@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@Badatos Badatos self-assigned this Jul 8, 2026
@Badatos Badatos changed the title [RELEASE] 4.2.x [RELEASE] 4.3.x Jul 8, 2026
Badatos and others added 4 commits July 8, 2026 11:48
## Summary

Prevents the Podfile widget from generating invalid URLs such as `/podfile/undefined` and fixes malformed markup in the video channel link.

## Changes

- Only generate typed Podfile URLs when the type is explicitly `image` or `file`.
- Ignore invalid folder types when building dynamic folder links in JavaScript.
- Resolve clicks on nested folder elements with `closest("a.folder")` so folder links keep their expected `data-target`.
- Close the opening `<a>` tag for channel links in `video-info.html`.
## configuration.json
* Add missing "ARCHIVE_ROOT" param
* Uniformize `attribute_scores` in FR and EN 
## check obsolete video
* no more send emails when there is no deleted or archived videos
## check_video_owner
* Format email sent with HTML table
@Badatos Badatos changed the title [RELEASE] 4.3.x [RELEASE] 4.3.1 Jul 20, 2026
@Badatos Badatos added this to the 4.x milestone Jul 20, 2026
dependabot Bot and others added 15 commits July 21, 2026 15:29
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@12.2.0...12.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 12.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Replace the full `Video.save()` used when attaching `overview.vtt` with a targeted update.
- Prevent stale video instances from clearing a thumbnail attached by another encoding callback.
- Add a regression test covering concurrent thumbnail persistence.
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@12.2.0...12.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 12.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Several minor bugfixes
---------

Co-authored-by: Céline Didier <ceine.didier@univ-lorraine.fr>
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.15.2 to 3.17.2.
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](encode/django-rest-framework@3.15.2...3.17.2)

---
updated-dependencies:
- dependency-name: djangorestframework
  dependency-version: 3.17.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Olivier Bado-Faustin <12731381+Badatos@users.noreply.github.com>
## Summary

- Display complete filenames, including extensions, in Podfile cards and tooltips.
- Add dedicated icons for ODT, ODS, ODP, and VTT files.
- Show an extension badge when no dedicated icon is available.
- Add template filters and regression tests for filenames, extensions, icons, and image previews.
- Convert png files to webp files

## Related issue

Fixes #1504
## Summary

- Add a configurable Runner Manager administration URL while preserving the default /admin URL.
- Support the /api/health endpoint introduced in Esup-Runner Manager 1.8.0, with a fallback to the legacy /manager/health endpoint.
- Add timestamped output modes to process_tasks: concise by default, detailed with --verbose, and silent with --verbosity 0.
- Add regression tests covering administration URLs, health endpoint compatibility, and command output modes.
Il m'est arrivé d'avoir des fichier "migration" manquants après un transfert ou une migration. Cette commande permet de s'assurer qu'il ne manque aucun fichier de migration, et s'il en manque, il en fait la liste avec pour chacun l'emplacement où il est sensé se trouver.
…abilize Tests (#1510)

## Summary

- Fix statistics access controls to address security advisory GHSA-9543-4fhq-r448. Restrict statistics pages, JSON responses and aggregate queries to authorized videos on the current site.
- Preserve password authorization across statistics requests while rechecking access restrictions and invalidating authorization when the video password changes.
- Validate redirect targets, safely render alerts and theme labels, and prevent internal exception details from being exposed to users.
- Declare explicit GitHub Actions token permissions and address unsafe patterns to reduce GitHub code scanning alerts.
- Prevent concurrent Runner result imports from callbacks and periodic workers using per-task file locks under the shared `MEDIA_ROOT`. Mark tasks as completed only after successful local import, keeping failed attempts eligible for retry.
- Preserve generated thumbnails when submitting video edit forms opened during encoding.
- Fix v3-to-v4 exports by correcting invalid meeting recurrence end dates and merging duplicate video deletion dates while preserving video relationships.
- Fix video tag serialization in the REST API, preserve Elasticsearch authentication and TLS options in test settings, and load debug toolbar URLs only when the application is enabled.
- Use timezone-aware datetimes for upcoming-event filtering, personal meeting room creation and test fixtures.
- Run Elasticsearch indexing and deletion synchronously in test settings to avoid SQLite locking and cross-test races, while restoring the active language after indexing.
- Expand regression coverage and isolate encoding, transcription and recorder workers in tests. Verify worker dispatch and ensure video duplication copies the source file correctly.
- Fix videos missing from a channel’s root when they belong to a theme in another channel, with regression tests for page rendering and AJAX loading.
- Refresh translation catalogs.

## Related issues

Fixes #1501
Fixes #1448
Fixes #1447
@Badatos
Badatos marked this pull request as ready for review September 11, 2026 09:04
Comment thread pod/playlist/views.py Fixed
@Badatos Badatos changed the title [RELEASE] 4.3.1 [RELEASE] 4.4.0 Sep 11, 2026
Badatos and others added 2 commits September 11, 2026 16:22
Bump Esup-Pod to 4.4.0 and some fixes:
# Playlists :
* Use Bootstrap colors for playlist add/remove buttons
* Add js Unit tests for playlists
* Ensure preventRefreshButton use json format

# Video Comments:
* Add titles on "voted" icons
* Fix for `Uncaught TypeError: can't access property "toLocaleString", since is undefined` in comment-script.js
* Run unit tests for javascript files
* Add margin bellow comments
## Summary

- Enforce playlist permissions for editing, video additions, removals and reordering.
- Apply password protection consistently across playlist pages and players, with session access invalidated when the password changes.
- Preserve ownership, co-owners and existing passwords when editing playlists.
- Fix playback order, empty playlists, AJAX pagination and atomic reordering.
- Restore favorites controls and icons, and handle missing form fields or card buttons.
- Add regression tests and complete missing Python docstrings.

## Testing

- 340 Django tests passed across playlists, video and enrichment using isolated test services.
- JavaScript regression tests passed.
- Flake8 passed on the modified Python scope.
- Manual checks covered favorites, public/private playlists and access restrictions between accounts.
Comment thread pod/playlist/static/playlist/js/utils-playlist.js Fixed
Comment thread pod/playlist/forms.py Fixed
## Summary

- Update pytubefix from 10.7.3 to 11.1.0.
- Prefer the ANDROID client for progressive downloads, retaining ANDROID_VR and WEB as fallbacks.
- Update the regression test to cover the new client fallback order.

## Validation

- Pending: run the 7 import video view tests.
- Pending: verify a YouTube download with audio using pytubefix 11.1.0.
## Summary

- Restrict redirects after playlist removal to same-origin HTTP(S) URLs.
- Use Django password hashing for new playlist passwords.
- Upgrade legacy SHA-256 hashes after successful verification, preserving whitespace compatibility and protecting concurrent password changes.
- Add regression tests for unsafe redirects, password compatibility, session access and concurrent updates.

## Compatibility

Upgrading a legacy hash invalidates existing playlist access sessions. Affected visitors must enter the same password again.

## Validation

- 429 Django tests passed using an isolated local runner with pod.main.test_settings.
- 70 JavaScript tests passed.
- flake8, Black formatting checks and git diff --check passed.
Comment thread pod/playlist/utils.py Fixed
LoicBonavent and others added 2 commits September 16, 2026 16:28
## Summary

- Fix French encoding notifications: use “terminé” and “encodée”, preserving transcription agreement.
- Add missing spaces after the author and date labels.
- Apply EMAIL_SUBJECT_PREFIX exactly once, falling back to the site name when empty.
- Refresh French and Dutch translation catalogs.
- Add regression tests for email prefixes, French wording, and encoding push notifications.

## Validation

- Flake8 passes.
- All 188 tests pass across pod.video.tests and pod.video_encode_transcript.tests.test_utils.
- make lang and make compilelang complete successfully.
- All 11 encoding utility tests pass again after translation compilation.
+ Fix bug preventing video from being removed from playlist
+ dispose bootstrap tooltip before removing videocard from playlist
@Badatos
Badatos merged commit a3e6829 into main Sep 17, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants