Skip to content

Document /server/health authentication breaking change in 12.0 - #834

Merged
ChristopherJennings merged 1 commit into
mainfrom
claude/thread-eval-docs-update-fc4aec
Sep 24, 2026
Merged

ChristopherJennings merged 1 commit into
mainfrom
claude/thread-eval-docs-update-fc4aec

Conversation

@ChristopherJennings

Copy link
Copy Markdown
Contributor

Summary

Directus 12.0.0 (directus/directus#27160) restricted /server/health to authenticated users. The GitHub release listed it as breaking, but the Version 12 breaking changes page didn't. A customer upgrading from 11.17.4 had an unauthenticated health probe fail, which triggered an automatic rollback.

Changes

  • Breaking changes → Version 12 (12.0.0): new section, "/server/health Requires Authentication", covering:
    • the 403 for unauthenticated requests, and using /server/ping for liveness checks
    • sending a static token when you need dependency checks; non-admins get only status, admins get the full report
    • results are cached (HEALTHCHECK_CACHE_TTL, default 5m) and shared across instances
    • cache, rateLimiter and rateLimiterGlobal checks replaced by one redis: check
    • new HEALTHCHECK_ENABLED / HEALTHCHECK_SERVICES variables
    • also added this and the existing IP_TRUST_PROXY section to the 12.0.0 "Jump to" list
  • Breaking changes → Version 12 (12.2.0): notes that TinyMCE is no longer bundled (custom plugins, skins, content CSS, global tinymce object).
  • Self-hosting → Deploying: Health Checks section now puts /server/ping first and explains /server/health auth and response shape.
  • Configuration → Health Check: adds the auth note and fixes an "edis" → "Redis" typo.

Reviewer notes

  • Status code: the release note says unauthenticated requests get a 404, but ServerService.health() throws ForbiddenError (403), and the e2e tests expect "You don't have permission to access this." The docs say 403. The GitHub release text may need a correction.
  • Sweep: I checked the 12.0.0–12.4.1 release notes against the breaking changes page. 12.1, 12.3, 12.4 and the patch releases match. Two 12.0.0 items are deliberately left out and need a decision:
    • The release note lists AI Translations as license-gated. The licensing docs don't mention it, so it needs confirming first.
    • The BUSL-1.1 → MSCL-1.0-GPL relicense is marked breaking in the release.
  • Anchors and links were checked on the local dev server.

🤖 Generated with Claude Code

Directus 12.0.0 (directus/directus#27160) restricted /server/health to
authenticated users, but the Version 12 breaking changes page never listed
it. A customer's unauthenticated health probe failed after upgrading and
triggered an automatic rollback.

- Add a 12.0.0 breaking change section covering the 403 response, the
  /server/ping alternative, per-role response shape, shared caching, the
  redis check rename, and the new HEALTHCHECK_* variables
- Note that TinyMCE is no longer bundled in the 12.2.0 WYSIWYG section
- Explain auth requirements on the deploying and health check config pages

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ChristopherJennings
ChristopherJennings requested a review from a team as a code owner September 24, 2026 21:11
@vercel

vercel Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Sep 24, 2026 9:15pm UTC

Request Review

@ChristopherJennings
ChristopherJennings merged commit 4c39c3e into main Sep 24, 2026
6 checks passed
@ChristopherJennings
ChristopherJennings deleted the claude/thread-eval-docs-update-fc4aec branch September 24, 2026 21:41

This branch was successfully deployed

1 active deployment
Preview — e5ea96c6 Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant