Skip to content

Document Directus 12.5.0 - #841

Merged
ChristopherJennings merged 4 commits into
mainfrom
claude/direcuts-12-5-release-docs-c82b8b
Oct 7, 2026
Merged

ChristopherJennings merged 4 commits into
mainfrom
claude/direcuts-12-5-release-docs-c82b8b

Conversation

@ChristopherJennings

Copy link
Copy Markdown
Contributor

Summary

Docs for the Directus 12.5.0 release, checked against the v12.4.1..v12.5.0 code diff. Also backfills one undocumented 12.4.0 breaking change.

Release pages

  • Breaking changes, Version 12.5.0: a new section with these entries:
    • Stricter IP access and IMPORT_IP_DENY_LIST validation.
    • 2FA enforcement follows effective policies.
    • CACHE_SCHEMA_MAX_ITERATIONS is removed and CACHE_SCHEMA_SYNC_TIMEOUT now defaults to 60000.
    • GET /license returns invalid_reason instead of downgrade_reason.
    • License error classes are removed from @directus/errors.
    • File storage values must match a configured location.
    • SDK and type definitions are corrected.
  • Changelog: a new October 2026 entry.
  • 12.4.0 backfill: Flow folders now share directus_folders with a new type field. Admin GET /folders requests return Flow folders too. The 12.4.1 callout now says that release has no breaking changes of its own.

Feature and reference docs

  • Manage Flows: activate or deactivate several Flows at once.
  • Rich text: linked images and paste cleanup. Accessibility shortcuts and the supported HTML list are updated to match.
  • Licensing:
    • the retry schedule
    • keeping the current license when a request fails
    • an invalid_reason values table
    • deactivating a key the licensing service no longer recognizes
    • a corrected PUBLIC_URL callout
  • Auth:
    • valid IP access formats
    • IP allowlists now also gate 2FA
    • 2FA is required through a policy, not the user page, which was wrong before
  • Config: CACHE_SCHEMA_SYNC_TIMEOUT, IMPORT_IP_DENY_LIST, LICENSE_KEY and LICENSE_TOKEN.
  • Errors and files: added LICENSE_INVALID, and the storage location rule on uploads.

Notes for reviewers

  • License endpoint path: the release notes say /server/license, but the route is GET /license (api/src/app.ts:370). These docs use /license.
  • Removed license error codes: no endpoint returned them in 12.4.1, so only extensions that import them are affected.
  • 2FA on refresh: the description of Fix TFA enforcement to use effective permissions directus#28176 says enforce_tfa is recalculated on token refresh. The merged code doesn't do that, so these docs don't claim it.
  • Not in the release notes: the file storage validation (Guard local-driver extensions location in storage path validation directus#28077) and the Flow folders type change in 12.4.0 aren't flagged as breaking upstream. I documented both because API clients can hit them.

Related docs PRs

Test plan

  • Ran pnpm dev and confirmed all 13 changed pages return 200.
  • Every new section link resolves.
  • Spot-checked the rendered breaking changes and licensing sections.

🤖 Generated with Claude Code

Add the Version 12.5.0 section to the v12 breaking changes page covering
stricter IP access and IMPORT_IP_DENY_LIST validation, 2FA enforcement
following effective policies, the CACHE_SCHEMA_MAX_ITERATIONS removal and
new CACHE_SCHEMA_SYNC_TIMEOUT default, the GET /license invalid_reason
field, removed license error classes, file storage location validation,
and corrected SDK and type definitions.

Add the October 2026 (12.5.0) changelog entry. Document bulk Flow
activation, linked images and paste cleanup in the WYSIWYG editor, license
renewal retries and the invalid_reason values, valid IP access formats,
2FA requirements set on policies, the LICENSE_INVALID error code, and the
updated cache, security, license, and storage configuration.

Backfill a 12.4.0 breaking change for Flow folders sharing
directus_folders with a new type field, and note that 12.4.1 has no
breaking changes of its own.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ChristopherJennings
ChristopherJennings requested a review from a team as a code owner October 7, 2026 20:00
@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 7, 2026 9:34pm UTC

Request Review

Comment thread content/configuration/cache.md Outdated
Comment thread content/configuration/security-limits.md Outdated
Comment thread content/guides/03.auth/5.2fa.md Outdated
Comment thread content/guides/04.connect/5.errors.md Outdated
Comment thread content/licensing/1.overview.md Outdated
Comment thread content/licensing/1.overview.md Outdated
Comment thread content/licensing/1.overview.md Outdated
Comment thread content/releases/3.breaking-changes/3.version-12.md Outdated
Simplify the CACHE_SCHEMA_SYNC_TIMEOUT description and breaking change
note, the 2FA policy sentence, the LICENSE_INVALID description, and the
canceled and suspended invalid_reason rows. Describe the license check
schedule as at least every 12 hours, note the hourly retry also covers a
key that could not be applied during startup, and clarify that a failed
renewal is restored without a downgrade if a check succeeds in time.
Clarify that IMPORT_IP_DENY_LIST is read from the environment rather
than validated on save.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ChristopherJennings
ChristopherJennings merged commit 4618be7 into main Oct 7, 2026
4 of 5 checks passed
@ChristopherJennings
ChristopherJennings deleted the claude/direcuts-12-5-release-docs-c82b8b branch October 7, 2026 21:33

This branch was successfully deployed

1 active deployment
Preview — 8204580e Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants