Repository navigation
chore(deps): bump ElsaVersion to 3.9.0-preview.5753 and ElsaStudioVersion to 3.9.0-preview.1797 - #271
Merged
Conversation
…sion to 3.9.0-preview.1794 Pin core to release/3.9.0 tip 9fbbef94 and studio to bd443662 so extensions compile against the identity/access work that landed since 5726/1757. Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>
…sion to 3.9.0-preview.1797 Retarget the 3.9 pin onto core 61aa0f7a (#8566 zero-grant claim, #8570 docs, #8573 refresh-by-sub) and studio 2842adf0 (#1105 open-redirect). Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>
sfmskywalker
commented
Oct 3, 2026
sfmskywalker
left a comment
Member
Author
There was a problem hiding this comment.
Elsa 3 Code Review: APPROVE + HIGH @ 783d7b1
Code Review, Round 1/4
This PR only bumps versions: two lines in Directory.Build.props, with no code changes.
Verified
- Diff:
ElsaVersiongoes from3.9.0-preview.5726to3.9.0-preview.5753, andElsaStudioVersionfrom3.9.0-preview.1757to3.9.0-preview.1797. The description gives the "from" values as 5744/1794, but the base has 5726/1757. The target values are correct either way. - Both packages are on the Elsa 3 Preview feed, which
NuGet.Configmaps toElsa.*.- The
Elsa.Identity3.9.0-preview.5753 nuspec points to elsa-core61aa0f7a, the currentrelease/3.9.0tip and the #8573 merge commit. That commit contains #8566 (678a7b90) and #8570 (e1db041f). - The
Elsa.Studio.Core3.9.0-preview.1797 nuspec points to elsa-studio2842adf0, the currentrelease/3.9.0tip and the #1105 merge commit.
- The
- Where it applies: the PR targets
release/3.9.0, so the 3.9 pins move together with the core and studio release branches.
Notes
- The description says ext doesn't issue JWTs, doesn't implement refresh and doesn't parse the permissions claim, so these core changes don't affect ext's code. That's plausible, given that only the pins change and the build succeeds.
- The 44 local test failures are all
DockerUnavailableExceptionfrom Testcontainers, an environment problem rather than a regression. CI onubuntu-latest, which has Docker, is the gate that counts.
Merge gate
APPROVE + HIGH applies to this head. For elsa-extensions, Greptile is waived. Merge once ubuntu-latest is green on 783d7b10. Any further push voids this approval.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Keep elsa-extensions
release/3.9.0on the same Feedz pins as the merged 3.9 core/studio fixes:3.9.0-preview.5753(61aa0f7a): elsa-core#8566 zero-grantpermissions=noneclaim, #8570 docs, #8573 refresh-by-sub (401 whensubis missing or conflicting).3.9.0-preview.1797(2842adf0): elsa-studio#1105 OIDCreturnUrlopen-redirect fix.This retargets #271 from
5744/1794.Change
Directory.Build.props(the only pin site):<ElsaVersion>3.9.0-preview.5744→3.9.0-preview.5753<ElsaStudioVersion>3.9.0-preview.1794→3.9.0-preview.1797IUserStorealready filter byUserFilter.Id, which is what refresh-by-sub uses. Extensions do not issue Elsa JWTs, implementIIdentityRefreshTokenService, or parse thepermissionsclaim. Nothing depended on the old refresh200+isAuthenticated: falseor on a missing permissions claim.Public-API audit (core 5744→5753, studio 1794→1797)
Compared compiled XML docs of the packages extensions implement or subclass.
Store / feature interfaces this repo implements — none found
IUserStoreIUserProviderIKeyValueStoreIWorkflowInstanceStoreIAccessTokenIssuer,IElsaTokenService,IIdentityRefreshTokenService,IRevokedSessionStoreFeatureBase,IMenuProvider,IPermissionServiceNew / changed members that do not require an extensions implementation
RefreshTokenSubject.FindUserId(new helper, #8573). Refresh now resolves the user only by a single non-blanksub/NameIdentifier. Missing, blank, conflicting, or unknown subject → 401. Extensions have no refresh-token client or tests that depended on the old 200.DefaultElsaTokenService/ emptyAdminApiKeyOptions.Permissionsemitpermissions: "none".Permission.TryParsealready rejectsnone. Extensions do not enumerate Elsa permission claims.Verification
3.9.0-preview.5753+3.9.0-preview.1797: succeededdotnet build Elsa.Extensions.sln -c Release: 0 errorsdotnet test Elsa.Extensions.sln -c Release(net10.0). No Docker socket in this environment, so Testcontainers PostgreSQL/Mongo facts failed withDockerUnavailableException. SQLite Dapper tests passed.Failures are all
DockerUnavailableException(Mongo Testcontainers fixture + 4 Dapper PostgreSQL facts). Skips are pre-existing. No compile or logic failures from the pin bump; no ext code or test depended on the old refresh/zero-grant behaviour.