451 Commits

Author SHA1 Message Date
Julien Neuhart
430ed38cc5 build(makefile): re-enable the embedlit go fix modernizer 2026-09-11 16:13:06 +02:00
Julien Neuhart
fb7536a526 fix(chromium): disable the WebUI omnibox popup preloaded at browser start 2026-09-09 19:38:40 +02:00
Julien Neuhart
b16ce08da7 perf(chromium): skip formatting a discarded debug message per response 2026-09-08 18:35:03 +02:00
Julien Neuhart
fcfd590169 perf(api): build the access log with a single record 2026-09-08 18:35:03 +02:00
Julien Neuhart
b39b8c76aa perf(gotenberg): match allow and deny patterns without recompiling them 2026-09-08 18:34:58 +02:00
Julien Neuhart
34b7b4845e perf(pdfengines): process a request's files concurrently behind an opt-in ceiling 2026-09-08 18:34:51 +02:00
Julien Neuhart
cddaa0fa57 fix(chromium): ceiling the CONNECT tunnels in flight and bound tunnel writes 2026-09-07 18:13:29 +02:00
Julien Neuhart
ade6a327a4 fix(chromium): drop settled requests from the per-conversion network map 2026-09-07 18:13:29 +02:00
Julien Neuhart
35ddf81812 fix(libreoffice): stop the outbound proxy when the daemon fails to start 2026-09-07 18:13:29 +02:00
Julien Neuhart
1891a9ea68 fix(chromium): bound CONNECT tunnels so a silent upstream cannot pin them forever 2026-09-07 18:13:29 +02:00
Julien Neuhart
e1e0a80883 fix(webhook): close the response body when the callback returns an error status 2026-09-07 18:13:29 +02:00
Max Freedom Pollard
c21ceacd4b fix(libreoffice): report an encrypted .xlsb as password-protected (#1655)
Uploading a password-protected .xlsb workbook without its password
answered 500 with the unattributable-failure message instead of 400 with
the remedy.

DetectPasswordProtection in pkg/modules/libreoffice/api/protection.go
infers encryption from a compound-file header carried by an extension
whose unencrypted form is always a ZIP package. The ooxmlExtensions map
listed .xlsx, .xlsm, .xltx and .xltm but not .xlsb, so an encrypted
workbook under that extension fell through to PasswordProtectionUnknown.
The convert route in pkg/modules/libreoffice/routes.go then matched
neither password branch of its exit-code switch and returned the 500
default.

An Excel Binary Workbook is an Open Packaging Conventions ZIP holding
binary parts, so a compound file under that extension is encrypted for
the same reason .xlsx is. Adding .xlsb to the map restores the 400 that
names the 'password' form field.
2026-09-06 13:05:20 +02:00
Julien Neuhart
ac825a2c03 feat(api): warn at startup when the debug route has no authentication 2026-09-05 14:04:21 +02:00
Julien Neuhart
2c9fa6b6ed fix(exiftool): reject metadata keys that collide with ExifTool options 2026-09-05 14:04:21 +02:00
Julien Neuhart
ca8b45cd3a fix(api): keep the filter verdict generic when a redirect is blocked 2026-09-05 14:04:21 +02:00
Julien Neuhart
40cf48442f fix(outbound): treat CGNAT and benchmarking ranges as non-public 2026-09-05 11:34:03 +02:00
Julien Neuhart
df3bac99ed fix(api): keep upload order when de-duplicating repeated filenames 2026-09-05 11:26:10 +02:00
Julien Neuhart
17868b8c02 fix(api): stop upload filenames from failing or silently dropping a request 2026-09-05 10:07:47 +02:00
Julien Neuhart
78284df590 fix(api): snapshot the output filename before echo recycles its context 2026-09-05 10:05:12 +02:00
Julien Neuhart
8f415186d5 fix(api): bound downloadFrom decoding by the entry limit 2026-09-05 10:03:56 +02:00
Julien Neuhart
f675f78f77 fix(webhook): bound webhook delivery with its own retry budget 2026-09-05 10:01:29 +02:00
Julien Neuhart
83b01c2baa fix(api): bound downloadFrom requests by the request deadline 2026-09-05 09:59:29 +02:00
Julien Neuhart
4de9b0f68b docs(outbound): document the allow-list bypass on every allow-list flag and terminate the example patterns 2026-09-04 19:55:57 +02:00
Julien Neuhart
201e80b9d7 feat(outbound): warn at startup about allow-list patterns that grant more than intended 2026-09-04 19:52:41 +02:00
Julien Neuhart
86a013b664 fix(outbound): strip URL userinfo before allow and deny list matching 2026-09-04 19:45:58 +02:00
Julien Neuhart
23d59f3133 refactor: adopt strings.Cut and strings.SplitSeq
Applies what go fix now proposes, so make fmt is a no-op on a clean tree
instead of dirtying these two files on every run. Both rewrites are
equivalent: Cut's first result matches SplitN(s, sep, 2)[0], and SplitSeq
iterates the same substrings without building the intermediate slice.
2026-09-03 19:22:23 +02:00
Julien Neuhart
0e83f737b4 docs(supervisor): point maybeRestartAfterTask at the timeout constant 2026-09-03 17:52:52 +02:00
Julien Neuhart
57b048c611 fix(supervisor): reset the request counter on a failed relaunch
restart() reset reqCounter only after a successful Launch, so a failed
one left it at the limit. maybeRestartAfterTask then re-fired on every
subsequent task, producing back-to-back restarts and, with planned
restarts now reporting healthy, a node that keeps restarting while
claiming health.

Reset on the attempt instead. A process that will not start is recovered
by ensureHealthy, which restarts synchronously and reports the failure.
2026-09-03 17:52:01 +02:00
Julien Neuhart
d79e174c6f fix(supervisor): bound the eager restart with a deadline
maybeRestartAfterTask ran its restart on a bare background context while
the drain loop in doRestartLocked selects only on ctx.Done(). A task that
never completed blocked the drain forever, pinning isRestarting. Since a
planned restart now reports healthy, that left the node claiming health
for good. LibreOffice escaped it because its concurrency of 1 drains no
slots, but Chromium defaults to 6.

Give that restart its own deadline. On expiry it aborts and the next task
retries it.
2026-09-03 16:10:16 +02:00
Julien Neuhart
88ddaed09b fix(supervisor): report healthy during planned process restarts
The eager restart fired after --chromium-restart-after or
--libreoffice-restart-after conversions made Healthy() report false,
so a client probing /health between two conversions got a 503 from an
otherwise serving node. Tasks arriving during that window are requeued
by acquireSlot, not rejected.

Track whether the in-flight restart is planned and keep reporting
healthy for those. Unplanned restarts still report unhealthy so load
balancers get honest information.

Closes #1648
2026-09-03 16:04:20 +02:00
Julien Neuhart
8944db131c fix(api): bound downloadFrom concurrency and entry count 2026-09-02 14:57:29 +02:00
Muhammad Haseeb
7dbff18e65 fix(chromium): fail fast with 503 when Chromium crashes (#1641) 2026-08-31 16:48:21 +02:00
Julien Neuhart
923e5f71eb style(api): remove redundant parentheses in type switch 2026-08-31 13:38:05 +02:00
Julien Neuhart
c636a52666 fix(otel): keep telemetry off unless an exporter is configured 2026-08-31 13:27:05 +02:00
Julien Neuhart
c0f487e333 feat(api): add OIDC bearer token authentication 2026-08-14 17:04:20 +02:00
Julien Neuhart
3de6932279 feat(pdfengines): apply multiple stamps and watermarks on every route 2026-08-14 16:36:40 +02:00
Julien Neuhart
e9a67132ec feat(pdfengines): apply multiple stamps in one request (#1601) 2026-08-14 15:52:14 +02:00
Julien Neuhart
65e5699b71 feat(pdfengines): generate document-title bookmarks when merging (#867) 2026-08-14 12:36:13 +02:00
Julien Neuhart
f90684e165 fix(chromium): add missing import for awaited waitForExpression 2026-08-14 11:58:19 +02:00
Niklas
90e614afa4 feat(chromium): await thenable waitForExpression (#1617) 2026-08-14 11:57:29 +02:00
Ilya Fedorov
38db892552 fix(libreoffice): accept the OOXML PowerPoint show extensions (#1626) 2026-08-14 11:43:12 +02:00
Julien Neuhart
1303e0ebc9 refactor(pdfengines): remove qpdf embed fallback (#1628) 2026-08-14 11:07:16 +02:00
Julien Neuhart
cc1341c3cf chore(deps): update pdfcpu to v0.15.0 (#1628) 2026-08-13 20:39:11 +02:00
Julien Neuhart
1ac1d9887e feat(pdfengines): optimize PDF images to reduce file size (#359) 2026-08-13 19:39:09 +02:00
Julien Neuhart
7a730cfdc2 feat(chromium): add --chromium-clear-storage to clear local storage between conversions (#919) 2026-08-13 14:56:46 +02:00
Julien Neuhart
b213f2ffed fix(chromium): fit the page to content for landscape single-page (#1390) 2026-08-13 14:14:48 +02:00
Julien Neuhart
8d1eeaa73a feat(chromium): screenshot a single element via the selector form field (#947) 2026-08-13 13:56:17 +02:00
Julien Neuhart
2f6818d3df fix(chromium): hint at --chromium-start-timeout when Chromium fails to start 2026-08-13 12:47:45 +02:00
Julien Neuhart
38f6e466d4 chore(libreoffice): drop the now-unneeded gosec nolint 2026-08-13 12:32:55 +02:00
Julien Neuhart
9b48d3f84e chore(libreoffice): silence a gosec G703 false positive on temp-file cleanup 2026-08-13 12:28:46 +02:00