Skip to content

feat: edit notification templates from the admin UI - #744

Merged
ymarcon merged 3 commits into
masterfrom
feat/743-notification-templates-editor
Oct 3, 2026
Merged

ymarcon merged 3 commits into
masterfrom
feat/743-notification-templates-editor

Conversation

@ymarcon

@ymarcon ymarcon commented Oct 3, 2026

Copy link
Copy Markdown
Member

Closes #743

Summary

  • Application page: notification templates of the application folder (notifications/<application id>/, the name applications authenticate with when sending emails), plus the ones inherited from the fallback folder. The fallback folder is also shown in the properties list.
  • Settings page: Agate's own templates (notifications/*.ftl).
  • Templates states: Default (bundled), Custom (Agate home), Overridden (both), Inherited from . Saving writes to AGATE_HOME/conf/templates/notifications/; reverting/removing deletes the file so the bundled/inherited one applies again. FreeMarker template cache is cleared on change.
  • Edit dialog with Edit / Preview tabs: Ace editor with FreeMarker syntax highlighting (monokai, as in Opal), server-side HTML preview of the unsaved content (current user as recipient, sample values, statements using sender-only variables are skipped), displayed in a sandboxed iframe. Name filter on the templates table.

REST

/config/notification-templates (agate-administrator), ?folder= (none: Agate's own):

  • GET list, GET|PUT|DELETE /{name}, POST /{name}/_preview

Security

  • Templates are parsed before saving (400 with FreeMarker message on error).
  • Folder/name whitelisted, normalized path must stay under the notifications root.
  • Templates becoming editable by administrators from the web, FreeMarker is hardened: new_builtin_class_resolver: safer, api_builtin_enabled: false (no bundled template uses ?new/?api).

Deployment note

AGATE_HOME/conf must be writable by the agate user (otherwise saving returns a 500 with the IO error).

Tests

  • NotificationTemplateServiceTest: write/list/revert, inherited templates, Agate's own templates, invalid template, preview, path traversal.
  • agate-core and agate-rest test suites pass; UI lint, type-check and build pass.

- Application page: edit the templates of the application folder
  (notifications/<application id>/), including the ones inherited from the
  fallback folder; Settings page: edit Agate's own templates.
- Edited templates are saved in AGATE_HOME/conf/templates/notifications/ and
  override the bundled ones; reverting deletes the override.
- FreeMarker syntax highlighting (Ace) and server-side HTML preview of the
  unsaved content, rendered in a sandboxed iframe.
- Templates are validated before saving; folder and name are whitelisted
  against path traversal.
- FreeMarker hardening: new_builtin_class_resolver=safer,
  api_builtin_enabled=false.
@ymarcon
ymarcon merged commit ca83aa0 into master Oct 3, 2026
2 checks passed
@ymarcon
ymarcon deleted the feat/743-notification-templates-editor branch October 3, 2026 15:23
ymarcon added a commit that referenced this pull request Oct 3, 2026
* feat: edit notification templates from the admin UI (#743)

- Application page: edit the templates of the application folder
  (notifications/<application id>/), including the ones inherited from the
  fallback folder; Settings page: edit Agate's own templates.
- Edited templates are saved in AGATE_HOME/conf/templates/notifications/ and
  override the bundled ones; reverting deletes the override.
- FreeMarker syntax highlighting (Ace) and server-side HTML preview of the
  unsaved content, rendered in a sandboxed iframe.
- Templates are validated before saving; folder and name are whitelisted
  against path traversal.
- FreeMarker hardening: new_builtin_class_resolver=safer,
  api_builtin_enabled=false.

* feat: notification template preview language selector (#743)

* feat: notification templates table actions on row hover, as in other tables (#743)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Edit notification templates from the admin UI

1 participant