Leantime - Package Updates
-
[1.14.0]
- Update leantime to 3.9.0
- Full Changelog
- Mobile Push Notifications - Mobile devices can now register Expo/FCM push tokens against access tokens and receive ticket and unread-count notifications via a new dispatcher (#3398, #3401, #3457)
- Logic Model Board - Added a Logic Model canvas board with WorkStructure orchestration (#3455)
- Task Collaborators - Completed multi-collaborator support for tasks, ensuring collaborators always receive ticket notifications and appear with full metadata across list and widget views (#1099)
- Postgres Compatibility - Fixed write limits, sequences, pdo_pgsql handling, and JS escaping for PostgreSQL deployments (#3447)
- Auth & Dashboard 500s - Hardened authentication and the dashboard against server errors and offline hangs (#3448)
- Marketplace 500s - Stopped marketplace errors by coercing API data into typed model properties (#3446)
- Milestone & Wiki Dialogs - Restored data binding in the milestone and wiki dialogs (#3444)
- Weekly Timesheet Grid - Blank cells are now skipped when saving the weekly grid (#3449)
- Client Discussion Count - Fixed an inaccurate discussion count on the client detail page (#3426)
- Mobile Responsiveness - Responsive stabilization sweep for phones and tablets (#3442)
-
[1.14.1]
- Update leantime to 3.9.2
- Full Changelog
- Route Caching - Automatically recovers from stale route cache and corrects an invalid exception import to prevent routing errors (#3523)
- Bearer/PAT Authentication - Fixed Bearer and personal access token authentication by validating against the core token store (#3522)
- Bearer API Authentication - Restored user context for Sanctum Bearer API requests, fixing a 3.9.0 regression (#3514)
- API Contract Tests - Added a Bearer-auth JSON-RPC contract test suite with a CI gate (#3513)
-
[1.14.2]
- Update leantime to 3.9.4
- Full Changelog
- My Work Across Projects - Fixed an issue that prevented "My Work" from loading tickets across different projects, and exposed and secured the mark-ticket-done action (#3527)
- Bearer Authentication - Resolved a Bearer token error (-32001) that denied every permission-gated API method for mobile and token-based integrations. The Sanctum-guard session stored the raw role integer instead of the role name the permission engine expects (#3525)
- Unified Session Handling - All authentication paths (web login, API key, and Bearer token) now build the user session through a single factory, so the role and two-factor state can no longer diverge between them. This also makes two-factor handling consistent for token-based authentication and adds clearer diagnostics when an unresolvable role is encountered (#3526)
- API Auth Test Coverage - The Bearer JSON-RPC contract tests now run through the real server auth path and cover non-manager roles, catching authorization regressions for non-admin users that owner-only testing missed (#3526)
-
[1.14.3]
- Update leantime to 3.9.5
- Full Changelog
- Mobile API Endpoints - Added session-scoped mobile endpoints for the notifications inbox and calendar (#3529)
- Blueprints Canvas - Fixed a 404 error when adding or editing canvas items (#3544)
- Editor Mentions - The @mention dropdown now appears directly beneath the caret (#3530)
- General Fixes - Resolved several recently reported bugs (#3532)
- symfony/yaml - Promoted to a production dependency (#3543)
-
[1.14.4]
- Update leantime to 3.9.6
- Full Changelog
- Security Hardening - Addressed authorization, SSRF, reset-token, LDAP, and stored-XSS vulnerabilities (#3584)
- Plugin Management - Plugin management now requires the proper permission and install input is validated more strictly (#3583)
- Avatar Rendering - User IDs are now encoded in avatar image sources to prevent DOM-based XSS (#3582)
- API Responses - Credentials are now stripped from getUser API responses (#3556, #3576)
- Content Templates - Introduced a generic content templates domain (#3493)
- My Day Schedule API - Added a getMyDaySchedule API endpoint that respects work hours and timezone (#3579)
- Personal Access Tokens - Added shared AI/MCP support classes and personal access token management (#3560)
- Domain Events - Added class-based domain events and filters with a legacy-string plugin bridge (#3503)
- Project Roles - Fixed user role inheritance when adding a user to a project (#3580)
- Kanban View - Fixed a rendering error caused by an undefined variable in the kanban view (#3554)
-
[1.14.5]
- Update leantime to 3.9.7
- Full Changelog
- Personal Access Tokens - Completed the move of personal access token management into core with a dedicated token controller and language keys (#3597)
- MCP Domain Tools - Reorganized MCP tool classes into their respective domain modules (#3581)
- Program Board - Fixed milestones, kanban rendering, and status rollup clarity on the program board (#3592)
- MCP Runtime - Repaired runtime bugs in domain tools uncovered during live end-to-end testing (#3586)
- System Update - System updates now properly clear cached bootstrap manifests.
- General Fixes - Resolved a batch of recently reported bugs (#3540, #3331, #3310, #3589, #3330, #3546, #3593)
- API Rate Limit - Raised the default API rate limit from 10 to 120 requests per minute (#3591)
-
[1.14.6]
- Update leantime to 3.9.8
- Full Changelog
- Milestones - Fixed reports showing 0% completion and the timeline "Show Tasks" view displaying nothing (#3624, #3625, #3628)
- Milestone Modal - Resolved focus loss, restored save-and-close, and fixed a 500 error when saving goals (#3605)
- To-Dos - Kept To-Dos from closed projects browsable once the project is reopened (#3626, #3627)
- Post-3.9.7 Regressions - Fixed a file browser out-of-memory issue, strategy grouping, and 403 errors for legacy roles (#3621)
- MCP Endpoint - The /mcp endpoint now accepts Leantime API keys, and a shim for the removed php-mcp provider lets in-place upgrades boot (#3601, #3602, #3607)
- Program Board - Moved the card status dropdown below the field row (#3599)
- Sessions - Isolated sessions into their own Redis database to avoid clashes with other cached data (#3604)
- Bumped the McpServer submodule to include the bulkAddTasks fix (#3620, #3622)
- Synced composer.lock content hash with composer.json (#3603)
-
[1.15.0]
- Update leantime to 3.10.0
- Full Changelog
- Period-Based Status Reports - Added period-based status report screens backed by a shared report engine and a period-aware actuals window for resources. (#3643, #3714)
- Mobile SSO - Introduced a generic OIDC mobile SSO bridge with one-time-code to bearer-token exchange, a public
/statusdiscovery endpoint advertising auth methods, and AdvancedAuth gating. (#3637, #3662, #3664, #3711) - User Capacity Fields - Added weekly hours and employment type to user profiles for better resource planning. (#3653)
- Routing - Resolved plugin controllers whose folder name has an inner capital letter. (#3773)
- Ideas on Kanban - Fixed the "Edit" option for Ideas not working in the Kanban view. (#3752)
- Sidebar Projects - Admins and owners now see all projects they have access to, fixing an empty project sidebar. (#3710)
- Upgrades - The installer now self-heals a missing
zp_access_tokenstable and a stale session-cached db-version so updates can't get blocked. (#3745, #3735) - Files - File names now display in full with a title tooltip instead of being truncated to 10 characters. (#3734)
- Tickets - Archived-project tickets are excluded from open ticket lists, statusDone history is logged with an accurate "last updated" time, and ticket parents are preserved on failed new-ticket submissions. (#3639, #3638, #3650, #3641)
- JSON-RPC Authorization - Closed an account-takeover chain: any authenticated user could call the onboarding service over JSON-RPC to set another account's password and role, activate it, then disable its 2FA. The onboarding and 2FA services are no longer RPC-reachable, and a sweep of the remaining unguarded
@apimethods closed marketplace license-key exposure, cross-user dashboard/widget writes, unauthorized ticket-dependency rewrites, mention forgery, and installer/scheduler/queue triggers. (#3797)
-
[1.15.1]
- Update leantime to 3.10.1
- Full Changelog
- Personal Webhooks - Added personal webhook delivery for notifications. (#3799)
- Beta Badge - Added a Beta badge variant for navigation menu items. (#3777)
- Timezones - The PHP process now always runs in UTC and the user's timezone is applied explicitly. This fixes timestamps (comments, history, audit, files, canvas items, wiki) being stored in the viewer's local time, due-date buckets and quick-add dates near midnight, and calendar "Invalid DateTime" errors. (#3802, #3803, #3804)
- Files - Uploads in the same second no longer overwrite each other; non-Latin filenames upload and download correctly (UTF-8
Content-Disposition); no more double extensions in the file list. (#3802, #3803) - Tickets - The ticket header shows the real last-updated date; due dates are localized in table and subtask views; priority/effort sorting fixed; "Related to" works on new to-dos. (#3802, #3805, #3787, #3788)
- CSV export - Exports plain text instead of HTML and formats due dates. (#3802, #3803)
- Notifications - Mattermost attachment fields are now sent as an array. (#3784)
- npm Advisories - Cleared the newly reported high-severity npm advisories. (#3801)
LEAN_DEFAULT_TIMEZONEis now only the default timezone for users who haven't set one; the server process always runs in UTC. Timestamps written before this release in a non-UTC timezone are not migrated and may display shifted by the old offset.
-
[1.15.2]
- Update leantime to 3.10.3
- Full Changelog
- Set
LEAN_APP_URL- Password reset and invite emails now link only to a trusted app URL. IfLEAN_APP_URLis not set, Leantime learns the URL the first time an owner or admin signs in (after 2FA). Until then, reset and invite emails are not sent, and admins see a banner explaining why. SettingLEAN_APP_URLis recommended. (#3826) - Plugin cron jobs now run - Console runs (
schedule:run,bin/leantime) now load enabled plugins. Scheduled jobs from RecurringTasks, CalDAV, GoogleCalendar and others now actually run. Expect a catch-up on the first scheduler run after upgrading. (#3831) - Moving tickets between projects now clears a parent, milestone or sprint that belongs to the old project, and maps the status to the new project's equivalent. (#3832)
- Health endpoint -
GET /healthfor load balancers and uptime monitoring; it bypasses session and auth. (#3829) - Users added via the API/CLI without a password now receive an invite (#3822)
- Timer stops when a ticket is moved to Done (#415)
- Ticket detail tabs work again (#3807)
- Portfolio pages render again (#3819)
- Plugin scheduled jobs never ran from cron (#3831)
- Email links (password reset, invites) are built from a trusted app URL and no longer from the request's Host header (#3826)
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login