v12.2.0
Notifuse/notifusev12.2.0Jul 29, 2026by github-actions[bot]
AI Summary
Replaces TinyMCE with Tiptap, restricts settings fields for minimal access, and introduces import size limits and partial schema snapshots.
Key Highlights
- TinyMCE editor replaced with Tiptap
- Restricted settings fields for minimal app access
- Import file size capped at 50mb by default
- Partial schema snapshot support
Breaking Changes
- TinyMCE is no longer bundled; 'tinymceOverrides' no longer has any effect
- Restricted settings fields for new policies only
- Import file size is now capped at 50mb by default
- Image transformation output size is now restricted to 3000px by default
- Background query flag now treats valueless indicators as true
New Features
- Tiptap WYSIWYG editor
- JSON path filtering to Studio filters
- Search in collection selection
- Global setting for default save action
- LICENSE_KEY_MANAGEMENT_ENABLED environment variable
- Partial schema snapshot via includeCollections/excludeCollections
Full Release Notes
### ⚠️ Potential Breaking Changes
**Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields ([#27996](https://github.com/directus/directus/pull/27996))**
The minimal app permissions now grant read access to only a subset of `directus_settings` fields. This applies to new policies, existing policies are untouched.
**Replaced the TinyMCE editor powering the WYSIWYG with Tiptap... ([#27754](https://github.com/directus/directus/pull/27754))**
**The WYSIWYG interface now runs on Tiptap instead of TinyMCE**
- `tinymceOverrides` no longer has any effect. Stored values are kept and a console warning is logged, but the editor ignores them. Use the `fontsize`/`fontfamily` toolbar menus and `customFormats` instead.
- TinyMCE is no longer bundled with the app, so anything depending on it (custom plugins, skins, content CSS, the global `tinymce` object) no longer applies.
- Existing content that contains markup the editor would normalize now locks the field read-only until the warning dialog is confirmed. Editing and autosave are blocked while locked, including raw-value editing.
**Fixed deployment webhooks resolving a project from the wrong provider when external IDs collide ([#27816](https://github.com/directus/directus/pull/27816))**
The `DeploymentProjectsService.readByExternalId` method now takes the deployment ID as its first argument (i.e. `readByExternalId(deploymentId, externalId)`)
**Added support for multi-collection flat data imports ([#27984](https://github.com/directus/directus/pull/27984))**
**Import file size is now capped by default**
A new `IMPORT_MAX_FILE_SIZE` environment variable (default: `50mb`) limits the size of uploaded import files and schema snapshots. Previously, imports were effectively unrestricted, allowing files larger than `50mb` to be processed. With this change, imports exceeding the configured limit will be rejected. Increase `IMPORT_MAX_FILE_SIZE` to restore the previous behavior.
**Updated `background` query flag handling for `POST /utils/import/:collection`**
The `background` query flag now treats a valueless indicator (i.e. `?background`) as true. If you previously relied on a valueless background flag being interpreted as false, pass an explicit value instead (i.e. `?background=false`).
**Added a `mode` parameter and partial snapshot support to the schema diff endpoint ([#27984](https://github.com/directus/directus/pull/27984))**
The SDK `schemaDiff` command now takes its options as an object (`schemaDiff(snapshot, { force, mode })`)
**Added support for restricting image transformation output size via `ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION` ([#27995](https://github.com/directus/directus/pull/27995))**
**Image transformation output is now restricted**
Image transformations that project an output larger than `ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION` (default `3000` px) on either axis are now rejected with an `IllegalAssetTransformationError`.
- **@directus/app**
- Replaced the TinyMCE editor powering the WYSIWYG with Tiptap ([#27754](https://github.com/directus/directus/pull/27754) by @alvarosabu)
To avoid data loss, the editor preserves attributes (`class`, `id`, `title`, `role`, `lang`, `dir`, `data-*`, `aria-*`) and non-schema semantic tags. If stored HTML still contains markup the editor would normalize, the field is locked read-only with a warning dialog, so no edit or autosave can rewrite it before you confirm; raw-value editing is disabled while locked so the warning can't be bypassed.
- **@directus/api**
- Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields ([#27996](https://github.com/directus/directus/pull/27996) by @br41nslug)
- Fixed deployment webhooks resolving a project from the wrong provider when external IDs collide ([#27816](https://github.com/directus/directus/pull/27816) by @MahinAnowar)
- Added support for multi-collection flat data imports ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- Added support for restricting image transformation output size via `ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION` ([#27995](https://github.com/directus/directus/pull/27995) by @br41nslug)
- **@directus/sdk**
- Added a `mode` parameter and partial snapshot support to the schema diff endpoint ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
### ✨ New Features & Improvements
- **@directus/app**
- Added JSON path filtering to Studio filters. ([#27918](https://github.com/directus/directus/pull/27918) by @robluton)
- Added search to the collection selection in relationship configuration ([#27950](https://github.com/directus/directus/pull/27950) by @baguse)
- Added global setting for default save action ([#27993](https://github.com/directus/directus/pull/27993) by @robluton)
- Added LICENSE_KEY_MANAGEMENT_ENABLED to control license key management ([#27779](https://github.com/directus/directus/pull/27779) by @AlexGaillard)
- **@directus/api**
- Added LICENSE_KEY_MANAGEMENT_ENABLED to control license key management ([#27779](https://github.com/directus/directus/pull/27779) by @AlexGaillard)
- Fixed incomplete json filter paths errors ([#27954](https://github.com/directus/directus/pull/27954) by @robluton)
- Added support for partial schema snapshot via new `includeCollections`/`excludeCollections` parameters ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- Added a `mode` parameter and partial snapshot support to the schema diff endpoint ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- **@directus/composables**
- Added JSON path filtering to Studio filters. ([#27918](https://github.com/directus/directus/pull/27918) by @robluton)
- **@directus/system-data**
- Added global setting for default save action ([#27993](https://github.com/directus/directus/pull/27993) by @robluton)
- **@directus/types**
- Added global setting for default save action ([#27993](https://github.com/directus/directus/pull/27993) by @robluton)
- Added support for multi-collection flat data imports ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- Added support for partial schema snapshot via new `includeCollections`/`excludeCollections` parameters ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- **@directus/env**
- Added LICENSE_KEY_MANAGEMENT_ENABLED to control license key management ([#27779](https://github.com/directus/directus/pull/27779) by @AlexGaillard)
- Added support for multi-collection flat data imports ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- Added support for restricting image transformation output size via `ASSETS_TRANSFORM_IMAGE_MAX_OUTPUT_DIMENSION` ([#27995](https://github.com/directus/directus/pull/27995) by @br41nslug)
- **@directus/sdk**
- Added support for multi-collection flat data imports ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- Added support for partial schema snapshot via new `includeCollections`/`excludeCollections` parameters ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- **@directus/specs**
- Added support for multi-collection flat data imports ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- Added support for partial schema snapshot via new `includeCollections`/`excludeCollections` parameters ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- Added a `mode` parameter and partial snapshot support to the schema diff endpoint ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
- **@directus/errors**
- Added support for multi-collection flat data imports ([#27984](https://github.com/directus/directus/pull/27984) by @ComfortablyCoding)
### 🐛 Bug Fixes & Optimizations
- **@directus/app**
- Fixed the translations split view hiding the second language when resizing the window ([#27681](https://github.com/directus/directus/pull/27681) by @valerkahere)
- Fixed geometry fields losing their subtype on schema changes ([#27828](https://github.com/directus/directus/pull/27828) by @rajkumar0932)
- Fixed stale dynamic permission presets after editing current account ([#27899](https://github.com/directus/directus/pull/27899) by @scarab-systems)
- Fixed a type error in the module bar default configuration ([#27944](https://github.com/directus/directus/pull/27944) by @kheiner)
- Amended app's save-as-copy logic to not create new items when only adjusting order on relationals ([#27871](https://github.com/directus/directus/pull/27871) by @AlexGaillard)
- Fixed the auth module registering a permanent cookie polling interval ([#27851](https://github.com/directus/directus/pull/27851) by @dstockton)
- Fixed presentation fields allowing `required` and/or `readonly` to be set ([#27688](https://github.com/directus/directus/pull/27688) by @sourav-18)
- Fixed missing translations for the Datetime display timezone options ([#28000](https://github.com/directus/directus/pull/28000) by @lazerg)
- Fixed dropdown menus shifting position when flipped above their trigger. ([#27958](https://github.com/directus/directus/pull/27958) by @Harshith-muddasani)
- Updated the remaining *.io references to the current *.com domains where possible ([#27948](https://github.com/directus/directus/pull/27948) by @kheiner)
- Updated the onboarding flow to replace the Privacy Policy link with the Data Processing Agreement ([#27934](https://github.com/directus/directus/pull/27934) by @JamesW1)
- Fixed live preview requesting a draft version before it exists, which caused a forbidden error ([#27848](https://github.com/directus/directus/pull/27848) by @dstockton)
- Fixed issue causing singleton primary key mismatch ([#27919](https://github.com/directus/directus/pull/27919) by @robluton)
- Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields ([#27996](https://github.com/directus/directus/pull/27996) by @br41nslug)
- Fixed many-to-one fields to display the saved key when the referenced item is inaccessible due to permissions ([#27899](https://github.com/directus/directus/pull/27899) by @scarab-systems)
- Fixed a Forbidden error when publishing an itemless content version without `delete` permission on `directus_versions` ([#27892](https://github.com/directus/directus/pull/27892) by @alex-hsieh)
- **@directus/api**
- Updated the remaining *.io references to the current *.com domains where possible ([#27948](https://github.com/directus/directus/pull/27948) by @kheiner)
- Added global setting for default save action ([#27993](https://github.com/directus/directus/pull/27993) by @robluton)
- Fixed OpenAPI spec error schema to match API error format ([#27885](https://github.com/directus/directus/pull/27885) by @kheiner)
- Restricted license key previews to administrators after initial project setup ([#27886](https://github.com/directus/directus/pull/27886) by @ComfortablyCoding)
- Stopped logging the missing custom IP header warning on `/server/ping` and `/server/info`, which are commonly hit directly (health checks) ([#27903](https://github.com/directus/directus/pull/27903) by @dstockton)
- Updated `axios`, `sharp`, `liquidjs`, `js-yaml`, `minimatch`, `adm-zip`, `brace-expansion`, `linkify-it`, `fast-xml-parser` and `tar` to address CVEs ([#27990](https://github.com/directus/directus/pull/27990) by @br41nslug)
- Fixed parsing of the `deep` query parameter, GraphQL nested arguments, and CSV import headers so keys dont collide with built-in object property names ([#27992](https://github.com/directus/directus/pull/27992) by @br41nslug)
- Fixed schema apply ignoring configured license ([#27869](https://github.com/directus/directus/pull/27869) by @ComfortablyCoding)
- Fixed aliased relational fields returning null in GraphQL when nested inside a Many-to-Any field ([#27864](https://github.com/directus/directus/pull/27864) by @apoorva-01)
- Fixed IP denylist not enforced for AI chat file downloads ([#27994](https://github.com/directus/directus/pull/27994) by @br41nslug)
- Fixed background imports (`POST /utils/import/:collection?background=true`) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. ([#27862](https://github.com/directus/directus/pull/27862) by @dstockton)
Added an `IMPORT_MAX_FILE_SIZE` environment variable that caps the size of an uploaded import file, returning `413 Content Too Large` when exceeded. Unset (unlimited) by default.
- Fixed requests referencing duplicate primary keys resulting in forbidden error ([#27882](https://github.com/directus/directus/pull/27882) by @lazerg)
- Fixed manual flows triggerable by non authenticated users ([#27997](https://github.com/directus/directus/pull/27997) by @br41nslug)
- Fixed `count`, `countAll`, and PK counts being inflated when filtering across relations ([#27926](https://github.com/directus/directus/pull/27926) by @ComfortablyCoding)
- Fixed TUS uploads not respecting FILES_MIME_TYPE_ALLOW_LIST ([#27793](https://github.com/directus/directus/pull/27793) by @amitmishra11)
- Fixed WebSocket handlers not validating query parameters ([#27845](https://github.com/directus/directus/pull/27845) by @tsushanth)
- Fixed unnecessary schema cache rebuilds on permission-related changes ([#27876](https://github.com/directus/directus/pull/27876) by @dstockton)
- **@directus/sdk**
- Updated the remaining *.io references to the current *.com domains where possible ([#27948](https://github.com/directus/directus/pull/27948) by @kheiner)
- Fixed nested filters on relational fields losing type inference, so filtering a related collection's field (e.g. `filter: { o2m: { id: { _eq: 5 } } }`) is now type-checked instead of silently accepting any value ([#27815](https://github.com/directus/directus/pull/27815) by @MahinAnowar)
- Removed phantom `timestamp` from directus_operations ([#27942](https://github.com/directus/directus/pull/27942) by @kheiner)
- Fixed an unhandled rejection in the sdk realtime client when the connection closed during a heartbeat ping ([#27846](https://github.com/directus/directus/pull/27846) by @apoorva-01)
- **@directus/specs**
- Updated the remaining *.io references to the current *.com domains where possible ([#27948](https://github.com/directus/directus/pull/27948) by @kheiner)
- Fixed OpenAPI spec error schema to match API error format ([#27885](https://github.com/directus/directus/pull/27885) by @kheiner)
- Fixed background imports (`POST /utils/import/:collection?background=true`) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. ([#27862](https://github.com/directus/directus/pull/27862) by @dstockton)
Added an `IMPORT_MAX_FILE_SIZE` environment variable that caps the size of an uploaded import file, returning `413 Content Too Large` when exceeded. Unset (unlimited) by default.
- Added missing `/users` registration and 2FA endpoint openapi specs ([#27857](https://github.com/directus/directus/pull/27857) by @kheiner)
- Removed OpenAPI query parameters that the underlying controllers never honor ([#27922](https://github.com/directus/directus/pull/27922) by @kheiner)
- Added missing `id` path parameter to the `/comments/{id}` OpenAPI spec ([#27884](https://github.com/directus/directus/pull/27884) by @kheiner)
- **@directus/constants**
- Updated the onboarding flow to replace the Privacy Policy link with the Data Processing Agreement ([#27934](https://github.com/directus/directus/pull/27934) by @JamesW1)
- **@directus/system-data**
- Restricted the settings fields readable with minimal app access to those actually needed by non-admin users, no longer exposing admin-only and sensitive AI configuration fields ([#27996](https://github.com/directus/directus/pull/27996) by @br41nslug)
- **@directus/env**
- Fixed background imports (`POST /utils/import/:collection?background=true`) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. ([#27862](https://github.com/directus/directus/pull/27862) by @dstockton)
Added an `IMPORT_MAX_FILE_SIZE` environment variable that caps the size of an uploaded import file, returning `413 Content Too Large` when exceeded. Unset (unlimited) by default.
- **@directus/utils**
- Fixed background imports (`POST /utils/import/:collection?background=true`) intermittently hanging and importing nothing when running behind a streaming proxy or CDN. ([#27862](https://github.com/directus/directus/pull/27862) by @dstockton)
Added an `IMPORT_MAX_FILE_SIZE` environment variable that caps the size of an uploaded import file, returning `413 Content Too Large` when exceeded. Unset (unlimited) by default.
- **@directus/schema**
- Fixed MSSQL schema introspection reporting the byte size as `max_length` for non-character types ([#27825](https://github.com/directus/directus/pull/27825) by @BIGSUS24)
- **@directus/storage-driver-cloudinary**
- Fixed Cloudinary uploads failing when the configured root contains whitespace ([#27841](https://github.com/directus/directus/pull/27841) by @itsabhay1)
### 📦 Published Versions
- `@directus/app@17.0.0`
- `@directus/api@38.0.0`
- `@directus/composables@11.6.0`
- `@directus/constants@14.4.1`
- `create-directus-extension@12.1.2`
- `@directus/env@6.2.0`
- `@directus/errors@2.5.0`
- `@directus/extensions@4.0.2`
- `@directus/extensions-registry@4.0.2`
- `@directus/extensions-sdk@18.0.2`
- `@directus/memory@4.0.2`
- `@directus/pressure@4.0.2`
- `@directus/schema@14.0.1`
- `@directus/schema-builder@1.0.1`
- `@directus/specs@15.1.0`
- `@directus/storage-driver-azure@13.0.2`
- `@directus/storage-driver-cloudinary@13.0.2`
- `@directus/storage-driver-gcs@13.0.2`
- `@directus/storage-driver-s3@13.0.2`
- `@directus/storage-driver-supabase@4.0.2`
- `@directus/system-data@4.6.0`
- `@directus/themes@2.0.2`
- `@directus/types@16.1.0`
- `@directus/utils@13.5.2`
- `@directus/validation@3.0.2`
- `@directus/sdk@24.0.0`