Skip to content

Release 2026-10-05 - (expected chart version 5.37.0) - #5585

Merged
fisx merged 27 commits into
masterfrom
release_2026-10-05_12_40
Oct 6, 2026
Merged

fisx merged 27 commits into
masterfrom
release_2026-10-05_12_40

Conversation

@zebot

@zebot zebot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

[2026-10-05] (Chart Release 5.37.0)

Release notes

API changes

  • The meetings endpoints (POST /meetings, PUT /meetings/{domain}/{id}, GET /meetings/{domain}/{id}, GET /meetings/list) expose a type field ("immediate" or "scheduled") on the meeting object starting at API version V19: required on create, optional on update (omitting it keeps the stored type). Meetings created via V15–V18 endpoints and all pre-existing meetings are scheduled. The V17/V18 endpoint shapes are unchanged. (WPB-28985: add wire meetings type #5556)

  • The meetings endpoints (POST /meetings, PUT /meetings/{domain}/{id}, GET /meetings/{domain}/{id}, GET /meetings/list) expose a link field on the meeting object starting at API version V19: an https join link whose final path segment is the meeting's UUID. The field is present only when the meeting has a live join code; it is omitted otherwise (e.g. meetings created before this change, deployments whose code store cannot hold meeting codes, or multi-ingress deployments with no join-link URI configured for the user's domain). The V15-V18 endpoint shapes are unchanged. (WPB-28987: add meeting join link #5558)

Features

Bug fixes and other updates

Documentation

Internal changes

battermann and others added 26 commits September 22, 2026 09:50
Master->Develop after release
When an Issuer gets replaced by an IdP update, it is kept in the
oldIssuers list for this IdP. But, it doesn't reference an active IdP
anymore.

Thus, looking up IdPs by this Issuer is deemed to fail.

Previously, deleting IdPs with such updated Issuers failed
(erroneously). This commit fixes this behaviour by acknowledging the
fact, that an old issuer may not point to an active IdP.
`minio/minio` was removed from docker hub. But, it is still available
via the official quay.io repo.

This was spotted when the related SBOMs pipeline failed.
* saml2-web-sso: Delete test verifying that base64-bytestring works the same as coreutils

The test is absurd in this package, if base64-bytestring is not spec compliant
it should be a bug in the library. The library already has tests against
particular strings, so this test is adding nothing.

* saml2-web-sso: Remove unused deps
…ss-services (#5236)

* fix: WPB-25750 Enable passing cspExtraConnectSrc value to nginx-ingress-services when working with multi-ingresses

* fix: WPB-25750 fix typos for account host names in multi-ingress related configs

* fix: WPB-25750 enabling integration tests for nginx

* fix: WPB-25750 set envoy to be default ingress mode

* fix: WPB-25750 enabling integration tests for nginx

* ci trigger

* ci trigger

* ci trigger

* wpb-25750: update blacklist url to point to wire-prod
This image is not part of the `wireServer.images*` attribute set, so it
need to be defined separately.

This fixed the bug of missing SBOMs for nginz in dependency track.
* WPB-28985: add wire meetings type

* WPB-28985: freeze legacy update schemas (drop type)

Legacy V15-V18 update endpoints used type aliases of the V19
UpdateMeeting, so the V19-only 'type' field leaked into the frozen
request schemas and pre-V19 clients could mutate the stored meeting
type. Introduce UpdateMeetingLegacy without mtype and map legacy
updates onto the shared implementation with mtype = Nothing.

* WPB-28985: fix toLegacyV18 Haddock (Meeting -> MeetingV18)

* WPB-28985: DRY integration helpers (parameterize version)
* WPB-28987: add meeting join link

* Remove meetings.has_code: derive join-code presence at read time

Replace the denormalized meetings.has_code boolean (PR #5558) with a
read-time lookup in the code store via a new CodeStore.GetMeetingCode
effect:

- Postgres: point lookup on conversation_codes PK
- Cassandra: pure Nothing short-circuit (no round trip; meeting codes
  never live there)
- DualWrite: Postgres-only routing (GetCode reads Cassandra, which
  cannot hold meeting codes)
- test mock mirrors production keying

storedMeetingToMeeting / storedMeetingToMeetingWithConversation are now
effectful; all callers updated. hasCode removed from StoredMeeting, the
store operation, all SQL statements, the migration, and
postgres-schema.sql. Behavior is preserved: meetings with a join-code
row serve the real link, all others the nil-UUID placeholder. As a side
effect the flag-drift failure class (stale flag serving a dead link,
e.g. after code TTL expiry) is eliminated; expired codes now degrade to
the placeholder.

Stacked PRs: rebasing #5559 drops SetMeetingHasCode entirely (refresh
becomes delete + recreate); #5560 unaffected.

Verified: wire-subsystems test suite 601 examples 0 failures (both link
specs pass); whole project type checks via make c.

* fix integration test: use getMeetingV with version argument

* fix: code are Maybe

* fix: copilot comment

* Hello CI

* Hello CI

* Hello CI

* Hello CI

* Hello CI

* Hello CI
* UserStore.Migration: Tolerate invalid assets

Co-authored-by: VeryMilkyJoe <jana.chadt+github@posteo.com>
Add sections for team-settings and account-pages. And, describe more
settings in the webapp's section.
…S 1.3+PQ options by default (#5480)

* See https://wearezeta.atlassian.net/browse/WPB-27369

envoy gateway: FIPS_2022_05 settings, to help with BSI TR-02102-2 TLS conformance

This has been deployed to a few internal environments with different settings; the results can be seen under https://wearezeta.atlassian.net/wiki/spaces/PET/pages/3280273465/TLS+versions+ciphers+ingress+nginx+envoy

 - [x] Add a new entry in an appropriate subdirectory of `changelog.d`
 - [x] Read and follow the [PR guidelines](https://docs.wire.com/latest/developer/developer/pr-guidelines.html)
During user password verification, we check that passwords are
longer than 8 characters, as older accounts might have been created
before these checks were introduced.
verify that a personal user who is the last conversation admin gets a 403
adminless-conversation when trying to leave while there are still
eligeble members in the conversation
@zebot
zebot requested review from a team as code owners October 5, 2026 12:41
@zebot zebot added the ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist label Oct 5, 2026
@fisx
fisx merged commit 7568f59 into master Oct 6, 2026
8 checks passed
@fisx
fisx deleted the release_2026-10-05_12_40 branch October 6, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants