BETA Release 26.3

Hello everybody!

Today I am thrilled to announce the BETA version of Libre Workspace 26.3.

Following our recent updates, version 26.3 brings massive architectural upgrades—most notably a fully native mail stack, overhauled Matrix authentication, and a new delegated administrator role for cleaner organization management.

The stable release of 26.3 is planned for July 15th, 2026.

Everyone is welcome to test out this new version and share feedback in this thread or the issues section. To test it out, you can switch non-production systems to the “testing” branch by changing stable to testing inside /etc/apt/sources.list.d/libre-workspace-stable.list and running a normal update.

:rocket: Highlights of Libre-Workspace 26.3.0

:e_mail: Native Mail Stack Integration

We have built a full-featured, native email server stack directly into Libre Workspace!

  • Core Stack: Integrated Postfix (SMTP routing), Dovecot (IMAP/LMTP), and SnappyMail (webmail client).

  • Easy Admin: Includes a step-by-step DNS configuration guide (MX, SPF, DKIM, DMARC) directly in the UI. OpenDKIM automatically generates 2048-bit key pairs on setup.

  • User Features: Automatic folder registration (Drafts, Junk, Trash, etc.), native mail forwarding/aliases management, and built-in Sieve filter support for custom sorting rules and out-of-office replies.

  • REST API & Quotas: A new MTA API client view lets you manage active outbound routes, hourly rate quotas, and remote domains (with a Standalone Mode fallback for unlimited local routing). This will be a bookable service in the future for all libre workspace instances which don’t want to handle the mail sending and receiving by themselves.

:chains: “Libre-Workspace-Glue”

To tie our growing ecosystem together, we have significantly expanded our internal automation capabilities.

  • Future-Proof Automation: Added a robust set of new event signals for addons triggered during user creation, user updates, group creation, and group updates. This lays the groundwork to easily automate Nextcloud group folder creation, Matrix chat rooms, and more.

  • All-in-One Dashboard Layout: We introduced a new sidebar on the left side of the front page. All integrated addons can now be opened directly inside the portal frame—no more jumping between separate browser tabs!

:gear: Libre Workspace Task Queue

We have introduced a brand-new task management system to handle background operations.

  • Traceable & Transparent: This system makes it incredibly clear and easy to follow exactly what the backend is doing during module installations, upgrades, and system processes.

  • Admin Auditing: A dedicated new admin page allows you to trace, audit, and view the execution history of all issued background tasks.

:speech_balloon: Matrix Authentication Service (MAS) Migration

User logins for the Matrix (Synapse) module have been refactored. Authentication is now delegated through the Matrix Authentication Service (MAS) instead of direct LDAP configurations.

  • MAS acts as an intermediate broker, linking Matrix authentication straight into our central OIDC identity provider.

  • Setup and rebuild scripts (setup_matrix.sh / rebuild_matrix.sh) have been rewritten to automate this transition seamlessly.

:shield: Restricted “User Administrator” Role

To support organizations where managers need to add users but shouldn’t touch server infrastructure, we’ve added a delegated admin role. Users in the user-admins LDAP group can manage users and groups, but they:

  • Cannot access the “Easy Dashboard” or system settings.

  • Cannot delete themselves, the default Administrator, or full system admins.

  • Cannot modify privileged security groups or promote anyone to full system admin.

:control_knobs: Dashboard Import/Export & Customizations

  • Migration Tools: Added Django management commands (export_dashboard, import_dashboard) and shell wrappers to easily backup or migrate card layouts, visibility rules, and branding.

  • Smart Layouts: A new overwrite_automatic_generation attribute ensures your custom card titles, icons, and URLs don’t get wiped out during system reloads.

:video_camera: Jitsi Meet Upgrades

  • OIDC Security: Configured OIDC redirection via jitsi-go-openid so only authenticated portal users can create or join rooms.

  • WebSocket Proxies: Added bypass paths in the Jaddy proxy configuration for Colibri WebSockets, completely resolving random call drops during conferences.

:floppy_disk: Maintenance, Backups & Reliability

  • Backup Penalties: If your last 7 backup runs fail, the system status calculator will now automatically deduct 20% from the overall system health score.

  • Borg Remote Paths: Updated backup routines to natively support secure remote storage via the $REMOTEPATH environment variable.

  • IP Change Automation: The change_ip script now scans /root/ directories and automatically runs docker compose down && docker compose up -d to reinitialize networking for containers on host IP changes.

  • Self-Healing Cron: A backend daemon now runs an hourly non-interactive dpkg fix to automatically clear broken or interrupted package installations.

  • SSE Connection Stability: The installation dashboard now automatically retries connection to the Server-Sent Events (SSE) log stream every 3 seconds if it drops out.

:artist_palette: UI/UX & Documentation Updates

  • Appearance Controls: Added an option to force the dashboard into Light Mode, and administrators can now completely disable/hide the “Password Reset” links.

  • Hardware Requirements Documentation: Rewrote installation.rst to provide exact baseline recommendations ranging from a Minimal instance (2 GB RAM, 1 CPU for portal/Nextcloud only) to a Mid-Tier Server (10 GB RAM, 4 CPU) and Enterprise sizing.

  • Translations: Cleaned up duplicate keys and formatting bugs in both English and German localization catalogs.

:bug: Notable Bug Fixes

  • OIDC RSA Key Bloat: Fixed a critical bug where a new duplicate OIDC RSA key pair was generated on every single startup. Added a self-healing patch to safely prune redundant keys from your database.

  • Identifiable Backups: Backup error email subjects now include the specific server instance name for easier troubleshooting in multi-site deployments.

You are welcome to report any bugs you find in this thread or directly at Issues - Libre_Workspace/libre-workspace - Codeberg.org

Cheers,

Jean

2 Likes


image

Es wird gesagt das es nicht übereinstimmt. Das einzige was unterschiedlich ist, ist T5dbE" "nzku
Das liegt daran, das Cloudflare eine Trennung einfügt.
Hier ist der Eintrag aus meinem Cloudflare-DNS

"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAztll1LuieEbwQRqHBAxricjz20DoPwLFFLvGi/r1II2h+PQY8q3MbXhi15aTtpccoV450C5q5XW8p7k0j1wpb5c1V+cCtcrGeXzIAMpzqiIdWfHaeIJoIA7JLBnqb8TsJFV+MI6QPGk9Ra/ydiHtSEHCC545NeFPLZ0XuRedujAyfseKvTLvZevjM2y+T5dbE" "nzku4QDwzOuXHDC61YwUqQlKY8gK5NU9csln8VQdFx2jU++abhtAnm47bHTZbGrqgFPlN6pgmyw0WjfSgoPDUMxFcNYmLFkSnit+mM8g9TCZFdMk/mK8L8xHNbKgd+bC7/7MgR9AvP6KID8hRACZQIDAQAB"

Ansonsten funktioniert es ohne Probleme und die E-Mails kommen da an wo ich Sie hingeschickt habe.

Gut wäre es wenn man auch die Möglichkeit hat, E-Mail-Domains anzulegen oder andere Domains als die System-Domain verwenden zu können.
Vielleicht ist das nicht so kompliziert zu implementieren. Ansonsten ist das E-Mailsystem für mich nicht verwendbar.

1 Like

In Nextcloud werden im Admin-Bereich wieder Header-Probleme angezeigt (sameorigin-Eintrag fehlt)

1 Like

Wow, wie cool, das ist ein großes Update und super Workflow.

Wenn der Kleber jetzt noch dynamisch verschwinden könnte und nur erscheint wenn man zum Rand fährt, wäre es aus meine Sicht perfekt.

Den Taskmanager finde ich auch super. Speziell die Funktion “Show Script Content”

Hallo, ein großes Lob. Durch den Kleber und die anderen Updates macht Libre-Workspace nochmal einen großen Schritt nach vorne! Chapeau!

HTTP-Header

Einige Header sind in Ihrer Instanz nicht richtig eingestellt - Der HTTP-Header `X-Frame-Options` ist nicht auf `sameorigin` gesetzt. Dies stellt ein potenzielles Sicherheits- oder Datenschutzrisiko dar und es wird empfohlen, diese Einstellung zu ändern.

Dies ist die Meldung - nur in der Beta.

Die Header, was das Nextcloud anzeigt? Das war glaube das lästigste bei der Nextcloud. Meine Ich.

Das ist wirklich das nervigste bei Nextcloud.

Nextcloud müsste bald Nervcloud heißen. Spaß beiseite, hatte glaube Jean auch gesagt gehabt, dass es das nervigste an NC ist

2 Likes

Nervcloud macht auch dauerhaft nervende Änderungen an ihrem Zeug. Ich arbeite auch nicht mehr mit Nervcloud sondern habe mir was eigenes Vibecoden lassen. Es hat kein Collabora oder so in sich aber auch das wird sicher irgendwann mit rein kommen… Irgendwann :grin:

Ist nun nichts was für jeden ist, es verwendet auch nur den Speicher meiner Hetzner Storagebox und nicht den lokalen Speicher.

Ich muss nun erstmal schauen wie ich das Problem löse mit meinem art iFrame basierenden PDF Viewer in Firefox, da es mittlerweile nichts eingebettetes mehr unterstützt.

Aber ich kann damit schöne Markdown Dateien schreiben.

Oha, da fehlen mir die Phantasie und Ideen für solche Sachen :slight_smile: Klingt aber spannend!

1 Like

Haha, alles was ich selber vibecode läuft über claude sonnet. Die meisten Sachen sind mir einfach zu überladen, da ich das dann so leicht wie möglich möchte bleibt nur noch vibecoden übrig, da ich das dann auch an meine wünsche anpassen kann und den code einfacher debuggen kann da ich da mit meinem hobby Auge drüber schauen kann.

2 Likes

Danke für den Hinweis, ja liebe Nextcloud, obviously, wir brauchen andere Iframe Options für den Kleber :slight_smile: Schaue mal ob ich diese Meldung deaktivieren kann, ansonsten müssen wir damit leben :slight_smile:

Edit: Wir müssen damit leben. Entweder Libre Workspace Kleber oder diese blöde iframe meldung von Nextcloud… :neutral_face: Kann euch aber versichern, dass das für euch kein großes Sicherheitsrisiko darstellt.

1 Like

Danke für die Fehlermeldung, sollte nun upstream gefixt sein!

Wird es eine Möglichkeit geben mehrere Domains für die Emailadressen geben oder erstmal nur die systemdomain? Ansonsten muss ich erstmal primär auf was anderes setzen denn ich verwende 4 Domains.

Ich nutze ja Claude Sonnet 4.6 zum lernen von Programmierung.finde ich eine spannende Geschichte.klappt zumindest gut.

Der Dolibarr Container startet nicht nach Server Reboot.

Mehrfach probiert.

Gerne mal cat /root/dolibarr/docker-compose.yaml reinposten

Aktuell noch nicht, aber ich gucke mal, ob ich noch schnell zaubern kann/

oot@la:~# cat /root/dolibarr/docker-compose.yml 
services:
    mariadb:
        image: mariadb:latest
        env_file:
            - .env
        environment:
            MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD:-root}
            MYSQL_DATABASE: ${MYSQL_DATABASE:-dolidb}
            MYSQL_USER: ${MYSQL_USER:-dolidbuser}
            MYSQL_PASSWORD: ${MYSQL_PASSWORD:-dolidbpass}

        volumes:
            - ./mariadb:/var/lib/mysql

    web:
        # Choose the version of image to install
        # dolibarr/dolibarr:latest (the latest stable version)
        # dolibarr/dolibarr:develop
        # dolibarr/dolibarr:x.y.z
        image: dolibarr/dolibarr:latest
        env_file:
            - .env
        environment:
            DOLI_INIT_DEMO: ${DOLI_INIT_DEMO:-0}
            DOLI_DB_HOST: ${DOLI_DB_HOST:-mariadb}
            DOLI_DB_NAME: ${DOLI_DB_NAME:-dolidb}
            DOLI_DB_USER: ${DOLI_DB_USER:-dolidbuser}
            DOLI_DB_PASSWORD: ${DOLI_DB_PASSWORD:-dolidbpass}
            DOLI_URL_ROOT: "${DOLI_URL_ROOT:-http://0.0.0.0}"
            DOLI_ADMIN_LOGIN: "${DOLI_ADMIN_LOGIN:-admin}"
            DOLI_ADMIN_PASSWORD: "${DOLI_ADMIN_PASSWORD:-admin}"
            DOLI_CRON: ${DOLI_CRON:-0}
            DOLI_CRON_KEY: ${DOLI_CRON_KEY:-mycronsecurekey}
            DOLI_COMPANY_NAME: ${DOLI_COMPANY_NAME:-MyBigCompany}
            WWW_USER_ID: ${WWW_USER_ID:-33}
            WWW_GROUP_ID: ${WWW_GROUP_ID:-33}
        extra_hosts:
            - "portal.${DOMAIN}:${IP}"

        ports:
            - "22675:80"
        links:
            - mariadb
        volumes:
            - ./documents:/var/www/documents
            - ./custom:/var/www/html/custom
            - ./conf:/var/www/html/conf
            - /etc/ssl/certs/ca-certificates.crt:/etc/ssl/certs/ca-certificates.crt:roroot@la:~# 

da ist die compose.

fehlt da einfach ein restart?