Commit Graph

71696 Commits

Author SHA1 Message Date
Fredrik Adelöw 37459ebed3 Merge pull request #33027 from Flagsmith/asaphk/flagsmith-plugin
docs: add the Flagsmith plugin to the microsite directory
2026-03-10 16:36:54 +01:00
Fredrik Adelöw f234b29025 Merge pull request #33234 from backstage/renovate/postgres-17.x
chore(deps): update postgres docker tag to v17.9
2026-03-10 16:34:19 +01:00
Fredrik Adelöw cbc012c664 Merge pull request #32340 from Believe-SA/docs/hooks
feat(docs-ui): document BUI's hooks
2026-03-10 16:29:22 +01:00
Fredrik Adelöw c07c27d2b1 Merge pull request #33258 from backstage/freben/fix-e2e
fix end to end tests
2026-03-10 16:27:40 +01:00
Fredrik Adelöw 26fa44767a Merge pull request #31989 from 0xts/feat/scaffolder-logs-btn
feat: add log download btn for LogViewer
2026-03-10 16:24:26 +01:00
Fredrik Adelöw 1b116e4160 Merge pull request #33210 from backstage/renovate/changesets-cli-2.x-lockfile
chore(deps): update dependency @changesets/cli to v2.30.0
2026-03-10 16:23:34 +01:00
Fredrik Adelöw 2fe57aa333 Merge pull request #33158 from backstage/freben/move-stitch-queue-2
catalog: move stitch queue into dedicated table
2026-03-10 16:21:13 +01:00
Fredrik Adelöw 294f9fe17f Merge pull request #32377 from samarthsinh2660/fix/table-filters-title-layout
fix(core-components): fix Table layout when filters and title are used together
2026-03-10 16:19:10 +01:00
Fredrik Adelöw a302ac285c fix end to end tests
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 16:16:12 +01:00
Fredrik Adelöw 422a79039b Merge pull request #32619 from kaidubauskas-dd/kaidd/fix-user-slack-dms
fix(notifications-slack): Only DM explicit user recipients
2026-03-10 15:33:57 +01:00
Fredrik Adelöw 241aa36b00 Merge pull request #33221 from backstage/freben/add-location-on-conflict-refresh
Add onConflict option to location registration endpoint
2026-03-10 15:19:31 +01:00
Fredrik Adelöw 63746129b2 reports
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 15:18:11 +01:00
Fredrik Adelöw a49c59f2da Update .changeset/curvy-socks-punch.md
Signed-off-by: Fredrik Adelöw <freben@gmail.com>
2026-03-10 14:56:07 +01:00
Fredrik Adelöw 5dc320ed5e remove unnecessary cast
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:39:01 +01:00
Fredrik Adelöw dfdb8e3a73 Add defaultLocationConflictStrategy config option for catalog locations
Adds a catalog config option to set the default conflict strategy when
registering locations, so adopters can default to 'refresh' instead of
'reject' without requiring each caller to specify it explicitly.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:06 +01:00
Fredrik Adelöw d3796b6165 Fix OpenAPI spec linting errors
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:05 +01:00
Fredrik Adelöw 05a3e13b88 Add test for onConflict refresh updating refresh_state
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:05 +01:00
Fredrik Adelöw e8dc06d2e9 Clean up test assertions for createLocation options
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:05 +01:00
Fredrik Adelöw 67fa705515 Use direct DB update for onConflict refresh instead of RefreshService
Simplify by updating refresh_state directly (next_update_at=now,
result_hash='') to force reprocessing, removing the need for
RefreshService wiring in the location store.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:04 +01:00
Fredrik Adelöw ced73ba3a0 Move onConflict refresh logic into DefaultLocationStore
The store now owns the conflict resolution and refresh logic directly,
keeping DefaultLocationService as a thin pass-through layer.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:04 +01:00
Fredrik Adelöw 5d95e8e7ac add changeset
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:04 +01:00
Fredrik Adelöw 32e9499caf Add onConflict query parameter to POST /locations endpoint
Adds an optional `onConflict` query parameter to the location creation
endpoint. When set to 'refresh', a conflict due to an already-registered
location triggers a refresh of the existing location entity instead of
returning a 409 error. The default behavior ('reject') is unchanged.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 14:35:04 +01:00
Ben Lambert d0f4cd215b feat(cli): add auth commands for OIDC login (#32920)
* feat(cli): add auth commands for OIDC login

Signed-off-by: benjdlambert <ben@blam.sh>

* address PR review feedback

- move CIMD check before callback server start
- add try/finally for callback server cleanup
- validate URLs with human-readable errors
- deduplicate config URL candidates
- preserve selected flag on re-authentication
- delete accessToken on logout
- log token refresh to stderr in show command
- fix command descriptions to reference CIMD not DCR
- type keytar as optionalDependency, rename storage paths
- add auth-backend changeset

Signed-off-by: benjdlambert <ben@blam.sh>

* migrate auth module from yargs to cleye pattern

Signed-off-by: benjdlambert <ben@blam.sh>

* address PR review feedback

- consolidate storage imports in auth.ts
- add withMetadataLock to setSelectedInstance
- skip file permission tests on Windows
- clarify changeset endpoint path

Signed-off-by: benjdlambert <ben@blam.sh>

* address review feedback from Rugvip and Copilot

- use stdout for user-facing messages instead of stderr
- remove clientSecret remnants from logout
- make refresh_token optional in token response schema
- add timeout to CIMD metadata fetch
- pass same state to callback server and authorize URL
- remove inaccurate test comment

Signed-off-by: benjdlambert <ben@blam.sh>

* validate state in callback server, add CIMD endpoint tests

- localServer now validates the OAuth state parameter in the request
  handler and returns 400 on mismatch
- Added tests for the CIMD metadata endpoint in OidcRouter covering
  both disabled and enabled cases

Signed-off-by: benjdlambert <ben@blam.sh>

* revert validateRequest to use Zod error details

Signed-off-by: benjdlambert <ben@blam.sh>

* fix callback server hanging by closing keep-alive connections

Signed-off-by: benjdlambert <ben@blam.sh>

* rename secret store service prefix to backstage-cli:auth-instance

Signed-off-by: benjdlambert <ben@blam.sh>

---------

Signed-off-by: benjdlambert <ben@blam.sh>
2026-03-10 13:28:25 +00:00
Fredrik Adelöw d056002e64 Merge pull request #33241 from backstage/freben/scheduler-cancel-task
Add cancelTask to SchedulerService for cancelling running tasks
2026-03-10 14:27:28 +01:00
Fredrik Adelöw c0b9c63be4 Fix TypeScript error in MockSchedulerService test
Use non-null assertion for resolveBlock since TypeScript cannot track
the async reassignment across the setTimeout boundary.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 13:59:40 +01:00
Fredrik Adelöw 25157bec8d Fix AbortController reuse after cancel and prevent overlapping liveness checks
Reset AbortController in MockSchedulerService after cancelTask so
subsequent triggerTask calls receive a fresh signal. Replace setInterval
with a self-scheduling setTimeout loop for liveness checks in TaskWorker
to prevent overlapping DB queries when a check takes longer than the
polling interval.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 13:49:38 +01:00
Fredrik Adelöw 0899cb2cee Fix cancelTask to reschedule next run instead of permanently stopping task
The static cancel() now reads task settings from the DB and computes
the next_run_start_at, so cancelled tasks get picked up again on their
normal schedule. Also stops the liveness check polling immediately on
first detection of a cancelled task.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-10 11:47:51 +01:00
Ben Lambert e8736ea2e8 feat(scaffolder): implementing secrets schema for scaffolder templates (#32320)
* feat: implementing secrets schema for scaffolder templates

Signed-off-by: benjdlambert <ben@blam.sh>

* chore: fix and regenerate openapi
Signed-off-by: benjdlambert <ben@blam.sh>

Signed-off-by: benjdlambert <ben@blam.sh>

* chore: fix review feedback

Signed-off-by: benjdlambert <ben@blam.sh>

* fix: address code review feedback for secrets validation

- Extract validateSecrets helper to deduplicate validation logic
- Add auditorEvent.fail() call on secrets validation failure
- Sanitize instance field in error responses to prevent secret leakage
- Add retry endpoint test coverage for secrets validation
- Split changeset into per-package entries

Signed-off-by: benjdlambert <ben@blam.sh>

* refactor: nest secrets schema under secrets.schema

Move the JSON Schema definition from spec.secrets to
spec.secrets.schema to leave room for future extensions
like secret sources.

Signed-off-by: benjdlambert <ben@blam.sh>

* chore: update API reports

Signed-off-by: benjdlambert <ben@blam.sh>

* chore: use InputError for secrets validation audit event

Signed-off-by: benjdlambert <ben@blam.sh>

---------

Signed-off-by: benjdlambert <ben@blam.sh>
2026-03-10 11:47:40 +01:00
Ben Lambert c74b69788e feat(mcp-actions): Add the ability to configure different plugins for different servers (#33235)
* feat: split MCP actions into per-plugin servers

Add mcpActions.servers config to create multiple MCP server endpoints
scoped by plugin source, with per-server include/exclude filtering.
Add mcpActions.tools for global tool description overrides.

Signed-off-by: benjdlambert <ben@blam.sh>

* feat: namespace tool names, use filter rules for server scoping

- Tool names now use action ID (plugin:name) by default, opt out
  via mcpActions.namespacedToolNames
- Removed pluginSources from server config, use filter.include
  with id glob patterns instead
- Removed tool description overrides (deferred to followup)
- Added server key validation for route safety

Signed-off-by: benjdlambert <ben@blam.sh>

* docs: update README for filter-based server scoping

Signed-off-by: benjdlambert <ben@blam.sh>

* feat: drop SSE routes for split servers

Signed-off-by: benjdlambert <ben@blam.sh>

* fix: handle empty servers config, fix test name

Signed-off-by: benjdlambert <ben@blam.sh>

---------

Signed-off-by: benjdlambert <ben@blam.sh>
2026-03-10 11:28:31 +01:00
Fredrik Adelöw 64073a4290 Merge pull request #33229 from backstage/freben/fix-flaky-techdocs-reader-state-test
fix(techdocs): fix flaky useReaderState stale content test
2026-03-10 04:34:25 +01:00
Fredrik Adelöw 3e4b372955 Implement cancelTask in MockSchedulerService with proper error types
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-09 22:37:08 +01:00
Fredrik Adelöw 164711a61f Add changeset for backend-test-utils cancelTask addition
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-09 22:18:23 +01:00
Fredrik Adelöw 60eec59601 Fix missing cancelTask in mock SchedulerService implementations
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-09 22:16:33 +01:00
Fredrik 015668c5d2 Add cancelTask to SchedulerService for cancelling running tasks
Adds the ability to cancel currently running scheduled tasks via a new
cancelTask method on the SchedulerService interface. For global (distributed)
tasks, the database lock is released and a periodic liveness check detects
the lost ticket and aborts the task function's AbortSignal. For local tasks,
the abort signal is triggered directly. Also adds a REST endpoint at
POST /.backstage/scheduler/v1/tasks/:id/cancel.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Fredrik Adelöw <freben@spotify.com>
2026-03-09 22:00:44 +01:00
backstage-goalie[bot] 88ad2fff14 Merge pull request #33239 from backstage/renovate/typescript-eslint-monorepo
chore(deps): update typescript-eslint monorepo to v8.56.1
2026-03-09 20:49:16 +00:00
renovate[bot] b3af36d91b chore(deps): update typescript-eslint monorepo to v8.56.1
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 20:10:43 +00:00
backstage-goalie[bot] f3f99b811e Merge pull request #33236 from backstage/renovate/cleye-2.x-lockfile
chore(deps): update dependency cleye to v2.3.0
2026-03-09 20:00:17 +00:00
Fredrik Adelöw e46834752a fix(techdocs): fix flaky useReaderState stale content test
Switch from real timers to fake timers so state transitions are
deterministic. The test previously relied on a ~100ms real-time window
between the 1000ms buildingTimeout and the 1100ms mock sync delay,
which was too tight for slow CI machines to observe reliably.

Signed-off-by: Fredrik Adelöw <freben@spotify.com>
Made-with: Cursor
2026-03-09 20:58:22 +01:00
renovate[bot] 649f8272ac chore(deps): update dependency cleye to v2.3.0
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 19:23:05 +00:00
backstage-goalie[bot] 174063f0b9 Merge pull request #33233 from backstage/renovate/ts-checker-rspack-plugin-1.x-lockfile
chore(deps): update dependency ts-checker-rspack-plugin to v1.3.0
2026-03-09 18:47:40 +00:00
renovate[bot] afded9e1eb chore(deps): update postgres docker tag to v17.9
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 18:11:59 +00:00
renovate[bot] 83b0af29f7 chore(deps): update dependency ts-checker-rspack-plugin to v1.3.0
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 18:11:50 +00:00
backstage-goalie[bot] f58441bbed Merge pull request #33232 from backstage/renovate/swagger-ui-react-5.x-lockfile
chore(deps): update dependency swagger-ui-react to v5.32.0
2026-03-09 18:02:55 +00:00
backstage-goalie[bot] 949c2d9575 Merge pull request #33231 from backstage/renovate/strip-ansi-7.x-lockfile
chore(deps): update dependency strip-ansi to v7.2.0
2026-03-09 18:02:50 +00:00
renovate[bot] 2bb08b0f02 chore(deps): update dependency swagger-ui-react to v5.32.0
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 17:14:46 +00:00
renovate[bot] fa13018885 chore(deps): update dependency strip-ansi to v7.2.0
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 17:13:52 +00:00
backstage-goalie[bot] 2135c17953 Merge pull request #33228 from backstage/renovate/react-virtualized-auto-sizer-1.x-lockfile
chore(deps): update dependency @types/react-virtualized-auto-sizer to v1.0.8
2026-03-09 17:01:24 +00:00
backstage-goalie[bot] 0635608ae8 Merge pull request #33226 from backstage/renovate/classnames-2.x-lockfile
chore(deps): update dependency @types/classnames to v2.3.4
2026-03-09 17:01:19 +00:00
backstage-goalie[bot] e335fbda71 Merge pull request #33223 from backstage/renovate/pg-8.x-lockfile
chore(deps): update dependency pg to v8.20.0
2026-03-09 17:01:14 +00:00
renovate[bot] 313617fa4d chore(deps): update dependency @types/react-virtualized-auto-sizer to v1.0.8
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-09 16:14:18 +00:00