Skip to content

chore(deps): bump ElsaVersion to 3.9.0-preview.5753 and ElsaStudioVersion to 3.9.0-preview.1797 - #271

Merged
sfmskywalker merged 2 commits into
release/3.9.0from
cursor/bump-elsa-preview-5744-16ea
Oct 3, 2026
Merged

sfmskywalker merged 2 commits into
release/3.9.0from
cursor/bump-elsa-preview-5744-16ea

Conversation

@sfmskywalker

@sfmskywalker sfmskywalker commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Why

Keep elsa-extensions release/3.9.0 on the same Feedz pins as the merged 3.9 core/studio fixes:

  • Core 3.9.0-preview.5753 (61aa0f7a): elsa-core#8566 zero-grant permissions=none claim, #8570 docs, #8573 refresh-by-sub (401 when sub is missing or conflicting).
  • Studio 3.9.0-preview.1797 (2842adf0): elsa-studio#1105 OIDC returnUrl open-redirect fix.

This retargets #271 from 5744/1794.

Change

  • Directory.Build.props (the only pin site):
    • <ElsaVersion> 3.9.0-preview.5744 → 3.9.0-preview.5753
    • <ElsaStudioVersion> 3.9.0-preview.1794 → 3.9.0-preview.1797
  • No source changes. Dapper/Mongo IUserStore already filter by UserFilter.Id, which is what refresh-by-sub uses. Extensions do not issue Elsa JWTs, implement IIdentityRefreshTokenService, or parse the permissions claim. Nothing depended on the old refresh 200 + isAuthenticated: false or on a missing permissions claim.

Public-API audit (core 5744→5753, studio 1794→1797)

Compared compiled XML docs of the packages extensions implement or subclass.

Store / feature interfaces this repo implements — none found

Interface Package Status
IUserStore Elsa.Identity unchanged
IUserProvider Elsa.Identity unchanged
IKeyValueStore Elsa.KeyValues unchanged
IWorkflowInstanceStore Elsa.Workflows.Management unchanged
IAccessTokenIssuer, IElsaTokenService, IIdentityRefreshTokenService, IRevokedSessionStore Elsa.Identity unchanged signatures
FeatureBase, IMenuProvider, IPermissionService Elsa.Studio.Core unchanged

New / changed members that do not require an extensions implementation

  • RefreshTokenSubject.FindUserId (new helper, #8573). Refresh now resolves the user only by a single non-blank sub / NameIdentifier. Missing, blank, conflicting, or unknown subject → 401. Extensions have no refresh-token client or tests that depended on the old 200.
  • Zero-grant tokens (#8566): DefaultElsaTokenService / empty AdminApiKeyOptions.Permissions emit permissions: "none". Permission.TryParse already rejects none. Extensions do not enumerate Elsa permission claims.
  • Studio #1105 is local-URL sanitization inside Studio login/OIDC hosts. No Studio extension module in this repo implements that path.

Verification

  • Restore against Feedz 3.9.0-preview.5753 + 3.9.0-preview.1797: succeeded
  • dotnet build Elsa.Extensions.sln -c Release: 0 errors
  • dotnet test Elsa.Extensions.sln -c Release (net10.0). No Docker socket in this environment, so Testcontainers PostgreSQL/Mongo facts failed with DockerUnavailableException. SQLite Dapper tests passed.
Assembly Passed Failed Skipped
Elsa.Dapper.UnitTests 19 0 0
Elsa.Persistence.Dapper.UnitTests 57 4 0
Elsa.MongoDb.UnitTests 27 40 0
Elsa.Scheduling.Quartz.UnitTests 159 0 0
Elsa.Scheduling.Quartz.ComponentTests 7 0 0
Elsa.Scheduling.Hangfire.UnitTests 25 0 0
Elsa.Mqtt.UnitTests 57 0 0
Elsa.Ldap.UnitTests 41 0 0
Elsa.Actors.ProtoActor.UnitTests 23 0 0
Elsa.Workflows.Runtime.ProtoActor.UnitTests 4 0 0
Elsa.Caching.Distributed.ProtoActor.IntegrationTests 8 0 0
Elsa.Logging.Core.UnitTests 18 0 0
Elsa.Logging.Core.IntegrationTests 2 0 0
Elsa.ServiceBus.MassTransit.UnitTests 2 0 0
Elsa.Secrets.Management.UnitTests 1 0 0
Elsa.Slack.Tests 0 0 1
Elsa.ServiceBus.AzureServiceBus.ComponentTests 0 0 1
Total 450 44 2

Failures are all DockerUnavailableException (Mongo Testcontainers fixture + 4 Dapper PostgreSQL facts). Skips are pre-existing. No compile or logic failures from the pin bump; no ext code or test depended on the old refresh/zero-grant behaviour.

Open in Web Open in Cursor 

…sion to 3.9.0-preview.1794

Pin core to release/3.9.0 tip 9fbbef94 and studio to bd443662 so extensions compile against the identity/access work that landed since 5726/1757.

Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>
…sion to 3.9.0-preview.1797

Retarget the 3.9 pin onto core 61aa0f7a (#8566 zero-grant claim, #8570 docs, #8573 refresh-by-sub) and studio 2842adf0 (#1105 open-redirect).

Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>
@cursor cursor Bot changed the title chore(deps): bump ElsaVersion to 3.9.0-preview.5744 and ElsaStudioVersion to 3.9.0-preview.1794 chore(deps): bump ElsaVersion to 3.9.0-preview.5753 and ElsaStudioVersion to 3.9.0-preview.1797 Oct 3, 2026

@sfmskywalker sfmskywalker left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Elsa 3 Code Review: APPROVE + HIGH @ 783d7b1

Code Review, Round 1/4

This PR only bumps versions: two lines in Directory.Build.props, with no code changes.

Verified

  • Diff: ElsaVersion goes from 3.9.0-preview.5726 to 3.9.0-preview.5753, and ElsaStudioVersion from 3.9.0-preview.1757 to 3.9.0-preview.1797. The description gives the "from" values as 5744/1794, but the base has 5726/1757. The target values are correct either way.
  • Both packages are on the Elsa 3 Preview feed, which NuGet.Config maps to Elsa.*.
    • The Elsa.Identity 3.9.0-preview.5753 nuspec points to elsa-core 61aa0f7a, the current release/3.9.0 tip and the #8573 merge commit. That commit contains #8566 (678a7b90) and #8570 (e1db041f).
    • The Elsa.Studio.Core 3.9.0-preview.1797 nuspec points to elsa-studio 2842adf0, the current release/3.9.0 tip and the #1105 merge commit.
  • Where it applies: the PR targets release/3.9.0, so the 3.9 pins move together with the core and studio release branches.

Notes

  • The description says ext doesn't issue JWTs, doesn't implement refresh and doesn't parse the permissions claim, so these core changes don't affect ext's code. That's plausible, given that only the pins change and the build succeeds.
  • The 44 local test failures are all DockerUnavailableException from Testcontainers, an environment problem rather than a regression. CI on ubuntu-latest, which has Docker, is the gate that counts.

Merge gate

APPROVE + HIGH applies to this head. For elsa-extensions, Greptile is waived. Merge once ubuntu-latest is green on 783d7b10. Any further push voids this approval.

@sfmskywalker
sfmskywalker merged commit 9bba55b into release/3.9.0 Oct 3, 2026
4 checks passed
@sfmskywalker
sfmskywalker deleted the cursor/bump-elsa-preview-5744-16ea branch October 3, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants