Commit Graph

1365 Commits

Author SHA1 Message Date
dependabot[bot]
fe4fb9416d chore(deps): bump golang.org/x/sync from 0.22.0 to 0.23.0 (#1658)
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.22.0 to 0.23.0.
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-11 07:20:22 +02:00
Julien Neuhart
fb7536a526 fix(chromium): disable the WebUI omnibox popup preloaded at browser start 2026-09-09 19:38:40 +02:00
Julien Neuhart
b16ce08da7 perf(chromium): skip formatting a discarded debug message per response 2026-09-08 18:35:03 +02:00
Julien Neuhart
fcfd590169 perf(api): build the access log with a single record 2026-09-08 18:35:03 +02:00
Julien Neuhart
b39b8c76aa perf(gotenberg): match allow and deny patterns without recompiling them 2026-09-08 18:34:58 +02:00
Julien Neuhart
06ed58b6e7 ci(build): reuse the Docker build cache across runs 2026-09-08 18:34:54 +02:00
Julien Neuhart
34b7b4845e perf(pdfengines): process a request's files concurrently behind an opt-in ceiling 2026-09-08 18:34:51 +02:00
Julien Neuhart
ab3832d9e5 test(integration): drop the per-scenario Docker network 2026-09-08 18:34:43 +02:00
Julien Neuhart
cddaa0fa57 fix(chromium): ceiling the CONNECT tunnels in flight and bound tunnel writes 2026-09-07 18:13:29 +02:00
Julien Neuhart
ade6a327a4 fix(chromium): drop settled requests from the per-conversion network map 2026-09-07 18:13:29 +02:00
Julien Neuhart
35ddf81812 fix(libreoffice): stop the outbound proxy when the daemon fails to start 2026-09-07 18:13:29 +02:00
Julien Neuhart
1891a9ea68 fix(chromium): bound CONNECT tunnels so a silent upstream cannot pin them forever 2026-09-07 18:13:29 +02:00
Julien Neuhart
e1e0a80883 fix(webhook): close the response body when the callback returns an error status 2026-09-07 18:13:29 +02:00
Max Freedom Pollard
c21ceacd4b fix(libreoffice): report an encrypted .xlsb as password-protected (#1655)
Uploading a password-protected .xlsb workbook without its password
answered 500 with the unattributable-failure message instead of 400 with
the remedy.

DetectPasswordProtection in pkg/modules/libreoffice/api/protection.go
infers encryption from a compound-file header carried by an extension
whose unencrypted form is always a ZIP package. The ooxmlExtensions map
listed .xlsx, .xlsm, .xltx and .xltm but not .xlsb, so an encrypted
workbook under that extension fell through to PasswordProtectionUnknown.
The convert route in pkg/modules/libreoffice/routes.go then matched
neither password branch of its exit-code switch and returned the 500
default.

An Excel Binary Workbook is an Open Packaging Conventions ZIP holding
binary parts, so a compound file under that extension is encrypted for
the same reason .xlsx is. Adding .xlsb to the map restores the 400 that
names the 'password' form field.
2026-09-06 13:05:20 +02:00
Julien Neuhart
ac825a2c03 feat(api): warn at startup when the debug route has no authentication 2026-09-05 14:04:21 +02:00
Julien Neuhart
2c9fa6b6ed fix(exiftool): reject metadata keys that collide with ExifTool options 2026-09-05 14:04:21 +02:00
Julien Neuhart
ca8b45cd3a fix(api): keep the filter verdict generic when a redirect is blocked 2026-09-05 14:04:21 +02:00
Julien Neuhart
40cf48442f fix(outbound): treat CGNAT and benchmarking ranges as non-public 2026-09-05 11:34:03 +02:00
Julien Neuhart
df3bac99ed fix(api): keep upload order when de-duplicating repeated filenames 2026-09-05 11:26:10 +02:00
Julien Neuhart
17868b8c02 fix(api): stop upload filenames from failing or silently dropping a request 2026-09-05 10:07:47 +02:00
Julien Neuhart
78284df590 fix(api): snapshot the output filename before echo recycles its context 2026-09-05 10:05:12 +02:00
Julien Neuhart
8f415186d5 fix(api): bound downloadFrom decoding by the entry limit 2026-09-05 10:03:56 +02:00
Julien Neuhart
f675f78f77 fix(webhook): bound webhook delivery with its own retry budget 2026-09-05 10:01:29 +02:00
Julien Neuhart
83b01c2baa fix(api): bound downloadFrom requests by the request deadline 2026-09-05 09:59:29 +02:00
Julien Neuhart
9a46fdd681 style: escape backslashes in the Chromium allow-list scenario table 2026-09-04 20:00:22 +02:00
Julien Neuhart
4de9b0f68b docs(outbound): document the allow-list bypass on every allow-list flag and terminate the example patterns 2026-09-04 19:55:57 +02:00
Julien Neuhart
201e80b9d7 feat(outbound): warn at startup about allow-list patterns that grant more than intended 2026-09-04 19:52:41 +02:00
Julien Neuhart
86a013b664 fix(outbound): strip URL userinfo before allow and deny list matching 2026-09-04 19:45:58 +02:00
Julien Neuhart
9c5acd7418 chore(deps): update Go dependencies 2026-09-04 10:00:28 +02:00
Julien Neuhart
e29b7cb4f5 build(makefile): fix lint-todo for golangci-lint v2 2026-09-03 19:23:14 +02:00
Julien Neuhart
23d59f3133 refactor: adopt strings.Cut and strings.SplitSeq
Applies what go fix now proposes, so make fmt is a no-op on a clean tree
instead of dirtying these two files on every run. Both rewrites are
equivalent: Cut's first result matches SplitN(s, sep, 2)[0], and SplitSeq
iterates the same substrings without building the intermediate slice.
2026-09-03 19:22:23 +02:00
Julien Neuhart
8a0de7d5d7 build(makefile): disable two go fix modernizers that emit broken code
go fix runs the modernize suite since Go 1.26, and two of its analyzers
rewrite this codebase into code that does not compile, so make fmt broke
the build and then make lint. CONTRIBUTING tells every contributor to run
both before opening a PR.

embedlit folded telemetryCfg.LogLevel into a literal that already set that
key, and errorsastype rewrote errors.As to errors.AsType[HttpError] even
though HttpError does not embed error. Disable both, with a TODO covering
when each can come back.
2026-09-03 19:22:23 +02:00
Julien Neuhart
3c691cbebc test(health): assert conversions succeed across a planned restart 2026-09-03 17:55:35 +02:00
Julien Neuhart
0e83f737b4 docs(supervisor): point maybeRestartAfterTask at the timeout constant 2026-09-03 17:52:52 +02:00
Julien Neuhart
57b048c611 fix(supervisor): reset the request counter on a failed relaunch
restart() reset reqCounter only after a successful Launch, so a failed
one left it at the limit. maybeRestartAfterTask then re-fired on every
subsequent task, producing back-to-back restarts and, with planned
restarts now reporting healthy, a node that keeps restarting while
claiming health.

Reset on the attempt instead. A process that will not start is recovered
by ensureHealthy, which restarts synchronously and reports the failure.
2026-09-03 17:52:01 +02:00
Julien Neuhart
d79e174c6f fix(supervisor): bound the eager restart with a deadline
maybeRestartAfterTask ran its restart on a bare background context while
the drain loop in doRestartLocked selects only on ctx.Done(). A task that
never completed blocked the drain forever, pinning isRestarting. Since a
planned restart now reports healthy, that left the node claiming health
for good. LibreOffice escaped it because its concurrency of 1 drains no
slots, but Chromium defaults to 6.

Give that restart its own deadline. On expiry it aborts and the next task
retries it.
2026-09-03 16:10:16 +02:00
Julien Neuhart
88ddaed09b fix(supervisor): report healthy during planned process restarts
The eager restart fired after --chromium-restart-after or
--libreoffice-restart-after conversions made Healthy() report false,
so a client probing /health between two conversions got a 503 from an
otherwise serving node. Tasks arriving during that window are requeued
by acquireSlot, not rejected.

Track whether the in-flight restart is planned and keep reporting
healthy for those. Unplanned restarts still report unhealthy so load
balancers get honest information.

Closes #1648
2026-09-03 16:04:20 +02:00
Julien Neuhart
8944db131c fix(api): bound downloadFrom concurrency and entry count 2026-09-02 14:57:29 +02:00
Johannes Klein
676570074a fix(Dockerfile): re-add libreoffice-math so DOCX math formulas render
The v8.30.0 image slimming replaced the libreoffice metapackage with an
explicit component list that omits libreoffice-math. Writer imports OMML
equations as Math objects, so without the component every formula is
silently dropped from converted PDFs.

Fixes #1644
2026-09-02 11:55:30 +02:00
dependabot[bot]
11179cb271 chore(deps): bump google.golang.org/grpc from 1.83.0 to 1.83.1 (#1646)
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.83.0 to 1.83.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.83.0...v1.83.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 10:51:17 +02:00
Julien Neuhart
c2a85f92d0 chore(deps): update unoconverter to v0.5.0 2026-08-31 19:01:18 +02:00
Muhammad Haseeb
7dbff18e65 fix(chromium): fail fast with 503 when Chromium crashes (#1641) 2026-08-31 16:48:21 +02:00
Julien Neuhart
923e5f71eb style(api): remove redundant parentheses in type switch 2026-08-31 13:38:05 +02:00
Julien Neuhart
334f859d95 chore(deps): update golangci-lint to v2.13.2 2026-08-31 13:36:02 +02:00
Julien Neuhart
0819514b7b chore(deps): update Go to 1.27.0 2026-08-31 13:36:02 +02:00
Julien Neuhart
c636a52666 fix(otel): keep telemetry off unless an exporter is configured 2026-08-31 13:27:05 +02:00
dependabot[bot]
0b16b0ab34 chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.1 (#1636)
Bumps [github.com/stretchr/testify](https://github.com/stretchr/testify) from 1.11.1 to 1.12.1.
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](https://github.com/stretchr/testify/compare/v1.11.1...v1.12.1)

---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-21 11:57:55 +02:00
Julien Neuhart
c0f487e333 feat(api): add OIDC bearer token authentication v8.36.0 2026-08-14 17:04:20 +02:00
Julien Neuhart
3de6932279 feat(pdfengines): apply multiple stamps and watermarks on every route 2026-08-14 16:36:40 +02:00
Julien Neuhart
e9a67132ec feat(pdfengines): apply multiple stamps in one request (#1601) 2026-08-14 15:52:14 +02:00