Skip to content

[pull] main from TryGhost:main - #1402

Merged
pull[bot] merged 9 commits into
code:mainfrom
TryGhost:main
Aug 10, 2026
Merged

pull[bot] merged 9 commits into
code:mainfrom
TryGhost:main

Conversation

@pull

@pull pull Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

9larsons and others added 9 commits August 10, 2026 09:20
no ref
- New e2e spec `e2e/tests/admin/staff-role-smoke.test.ts`: every staff
role performs a real first login in a fresh browser context and the test
asserts the role's landing view plus the navigation it should (and
should not) have:
- **Administrator** → `/analytics`, full sidebar (Analytics, View site,
Posts, Pages, Tags, Members, Settings)
- **Editor** → `/site`, sidebar with Posts, Pages, Tags, Settings (no
Analytics/View site/Members)
  - **Super Editor** → `/site`, Editor set plus Members
  - **Author** → `/site`, Posts and Pages only
- **Contributor** → `/posts`, no sidebar at all — floating avatar menu
with Posts / View site / Your profile
- New Playwright fixtures `ghostAccountEditor`,
`ghostAccountSuperEditor`, `ghostAccountAdministrator`, reusing the
existing StaffAccountFactory invite + MailPit flow (Author/Contributor
already existed).
- New `ContributorUserMenu` page object backed by new selector constants
in `@tryghost/test-data`.
- Corrected the stale `NAV_ITEMS` role-visibility metadata in the
sidebar page object (it claimed Editors see View site and Members,
contradicting the shipped gating) and added `Super Editor` to its
`UserRole` union.
no ref

Version-scoped every `allowBuilds: true` entry in `pnpm-workspace.yaml` to the exact version or versions currently resolved in `pnpm-lock.yaml`. This tightens up our security a touch against worm attacks.
ref 6a0f141

This code has been unused since 2025.

There was an edge case where this job was inserted and then the
associated code was removed, which I considered as an issue. But current
code won't execute this job--with or without the file.
closes https://linear.app/ghost/issue/NY-1404

_I recommend [reviewing this one commit at a
time](https://github.com/TryGhost/Ghost/pull/29811/commits)._

Most of the time, Ghost runs in a UTC environment where this change has
no effect. But if you:

- self-host
- use SQLite
- use a time other than UTC

Automation timezones might have been messed up for you.

This fixes that by forcing everything to use UTC.

In addition to automated tests, I manually tested this by making sure
scheduled automations still worked:

https://github.com/user-attachments/assets/aff984ce-0249-4d43-8844-e3a0fcae193f

Co-authored-by: Troy Ciesco <tmciesco@gmail.com>
no ref

Prunes Playwright e2e tests whose behavior is already pinned by the
`apps/admin` acceptance tier (Vitest Browser Mode against the MSW fake
Admin API), after verifying each counterpart file covers what the e2e
test asserted.
no ref

Some minor updates to fix the devcontainer construction to match changes in the repo from some weeks ago. We're still not actively utilizing the devcontainer setup. This change is largely to shore up future debt/mismatches.
no ref

This change should have no user impact.

Co-authored-by: Troy Ciesco <tmciesco@gmail.com>
no ref

This change should have no user impact.

I noticed that I was getting 429s from IndexNow in development. Let's
stop hitting it in development entirely, as it's never going to work
there.
Indexnow is GA and generally working well. This does the final cleanup around the labs flag.
@pull pull Bot locked and limited conversation to collaborators Aug 10, 2026
@pull pull Bot added the ⤵️ pull label Aug 10, 2026
@pull
pull Bot merged commit ce786e2 into code:main Aug 10, 2026
3 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants