Skip to content

[pull] main from TryGhost:main - #1514

Merged
pull[bot] merged 12 commits into
code:mainfrom
TryGhost:main
Sep 24, 2026
Merged

pull[bot] merged 12 commits into
code:mainfrom
TryGhost:main

Conversation

@pull

@pull pull Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

9larsons and others added 12 commits September 24, 2026 10:25
ref https://linear.app/ghost/issue/PLA-409

The Cmd-K search modal is moving from Ember to React behind the `globalSearchReact` Labs flag. Search results must not change when the flag flips, so the React side needs Ember's exact matching rules: the same groups, billing config handling, tokenization, ranking and status ordering.
The React editor was excluded from Admin 7 pill styles even though its
controls already use Shade. This enables the shared styling when both
`editorReact` and `admin7Pill` are on, using the existing route
ownership check. The Ember editor and the React editor with the pill
flag off keep their current appearance.

Editor header buttons use normal sizing, with an icon-sized settings
toggle and ghost Preview action. Preview controls use shared header
actions for ghost styling, 2px icon strokes and an icon-sized copy-link
button; the device selector keeps rounded corners. Action groups provide
the same one-second tooltip delay as other page headers.

Shared header actions omit redundant tooltips on static labelled
buttons. Icon actions and keyboard shortcuts retain tooltips;
changing-value actions can opt in. The existing post sort control opts
in, and the Storybook contract documents the convention. The Labs
description now reflects React editor support.

Validation:
- 46 existing acceptance/component checks passed across preview, editor
and design-boundary suites. Added coverage checks the flag boundary
only; no visual assertions.
- Shade's 278 existing tests, build and lint passed. Admin typecheck and
changed-file lint passed.
- Browser smoke checks covered the React editor header, settings panel,
preview dialog and keyboard tooltip behavior; the PageHeader story
renders.
- Independent subagent reviews of flag isolation and component/standards
coverage found no issues.
- The earlier repository-wide `pnpm check` passed formatting and lint,
but reported 27 failures in untouched Ghost Core tests (mostly timeouts,
plus cron/date assertions) and one timeout in the untouched member
custom-field filter test. Stopped the remaining Koenig acceptance run
after those failures; the full check is not green. These unrelated
failures are left out of this PR.
no ref

The React limiter hook (`useLimiter`) never passed a `subscription` to
`LimitService.loadLimits`, so any host config with a `maxPeriodic` limit
(e.g. `hostSettings.limits.emails`) threw `IncorrectUsageError:
Attempted to setup a periodic max limit without a subscription` during
render and broke Admin.

Ember Admin already handles this in
`apps/ember-admin/app/services/limit.js`. The React hook now matches it:

- builds `subscription` from `hostSettings.subscription.start` (monthly
interval) and passes it to `loadLimits`
- when there's no start date, skips `maxPeriodic` limits with a warning
rather than throwing, so the remaining limits still load (registration
stops at the first limit that throws)
- adds `subscription` and `emails` to the `hostSettings` config type

New unit test covers both cases; both fail on `main` with the error
above.
…ing saves (#30968)

no ref

Anything reading posts and tag caches kept showing old data for up to five minutes given certain actions (the default `staleTime`). This shores up that behavior so that post delete and tag creation updates caches.
no ref

Embed card html is previewed in an iframe that shares the editor's origin, so embed scripts run with Admin's access. Sandboxing that iframe breaks most real embeds, because provider players inherit the sandbox. Serving previews from a separate domain isolates them without that trade-off.

When `security.embedPreviewUrl` is configured, the editor loads a small static renderer from that domain and hands it the embed html over postMessage. The renderer is versioned by its message protocol rather than by Ghost release, since Admin, Core and the hosted renderer deploy independently. Without the option, previews behave as before. A configured renderer that can't be used shows a placeholder instead of falling back to the editor's origin.

The renderer ships in the Ghost build outside the admin assets, because it must never be served from Ghost's own domain.
no ref

The Coverage job on `main` has failed since #30972 with `Artifact not
found for name: e2e-coverage`.

The Node test matrix in `job_setup` hardcoded the primary leg as
`22.23.1`. After `NODE_VERSION` moved to `22.23.3`, no acceptance leg
matched the `matrix.node == node_version` coverage gate, so
`e2e-coverage` was never uploaded. The primary line was also still being
tested on 22.23.1 instead of the version we ship.

The primary leg now comes from `NODE_VERSION`, so future bumps can't
drift. The 24.x leg stays hardcoded.
no ref
- pin netlify cli version
- fix pnpmfile use during pnpm dlx
@pull pull Bot locked and limited conversation to collaborators Sep 24, 2026
@pull pull Bot added the ⤵️ pull label Sep 24, 2026
@pull
pull Bot merged commit 9d7248b into code:main Sep 24, 2026
2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants