The fallback uses POSIX shell syntax, but npm on Windows runs scripts in cmd.exe. docker/start.sh keeps the fallback for Docker, and the manual guide sets the two variables.
From the repository root, `npx prisma migrate deploy` stops with "Could
not find Prisma Schema". It also does not use the fallback for
`NEXT_PRIVATE_DIRECT_DATABASE_URL`. The `npm run prisma:migrate-deploy`
command above it does the same work and uses the fallback.
`npm run prisma:migrate-deploy` stopped with error P1012 when
`NEXT_PRIVATE_DIRECT_DATABASE_URL` was not set. If the direct URL is
empty, the script uses `NEXT_PRIVATE_DATABASE_URL`, the same as the
Docker start script.
The manual migration command in the upgrade guide does not use the start
script, and Prisma cannot find the schema at the default path in the
image. The command sets the two variables and gives the path to the
schema.
The Docker start script runs Prisma migrations. The Prisma schema reads
`NEXT_PRIVATE_DIRECT_DATABASE_URL`, and the migrations stopped with error
P1012 when the variable was not set.
If the variable is empty, the start script sets it to
`NEXT_PRIVATE_DATABASE_URL`. This agrees with the documentation and with
docker/production/compose.yml.
Strip encryption from PDFs that open with an empty user password via
libpdf's ignorePermissions, still rejecting user-password PDFs.
Upgrade @libpdf/core to 0.5.1, which also keeps overlapping and layered
text intact during text extraction.
Resolves#3303
Selecting password auth failed with a generic "Unauthorized" for users
who signed up via OAuth or passkey, with no way to set one.
Detect the missing password and email the existing reset link from the
signing dialog and security settings. Require a 2FA code and rate limit
update-password.
Upgrade to Node 24 LTS, using the alpine 3.23 tag to handle issues with
streaming zip files on 24.16 which hangs npm ci.
Pin npm to 11.19.1 for min-release-age-exclude support.
Slim the runner image by dropping dev deps, the react-email CLI, and
esbuild,
none of which run in production.
Install turbo from the lockfile version instead of a hardcoded one.
`/api/health` and `/api/certificate-status` reported the cert as
available when `NEXT_PRIVATE_SIGNING_TRANSPORT` was unset, even though
sealing defaults to the local P12 and fails if it is missing,
unreadable, or expired.
Disable autocapture and person profiles for anonymous users, and
redact signing tokens from captured URLs.
Manually wire exception capture into the signing, editor and embed
flows with recipient/envelope context for debugging recipient-reported
issues.
Track activation events (webhooks, api tokens, direct links, embed
sessions) server-side with org attribution, and drop client events
already tracked in-app.