Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
98 commits
Select commit Hold shift + click to select a range
163abf3
Upgrade to NGINX 1.31.0 (#14226)
giohappy May 15, 2026
02a2544
extende docs validation
giohappy May 15, 2026
ae9469c
build(deps): bump django-allauth from 65.16.1 to 65.17.0
dependabot[bot] May 25, 2026
6ea701e
build(deps): bump requests from 2.33.1 to 2.34.2
dependabot[bot] May 18, 2026
bd69c1d
Add read DEFAULT_MAX_UPLOAD_SIZE from environment
EHJ-52n Apr 20, 2026
32a8636
backport pillow upgrade (#14269)
mattiagiupponi May 27, 2026
9158947
[Fixes #14244] Do not return WWW-Authenticate inside API exception re…
github-actions[bot] May 27, 2026
c9c657b
[Fixes #14262] Avoid returning all permissions in dataset owner paylo…
github-actions[bot] May 27, 2026
979d760
[Fixes #13512] Create a task that loads required thesauri automatical…
Copilot May 27, 2026
c860a30
adding improvements in the new docs
Gpetrak May 29, 2026
08d8e88
Upgrade to Geoserver 2.28.4 (#14289)
giohappy Jun 4, 2026
a36ec4a
[Fixes #14291] Add parameter for beat DB file location (#14292) (#14303)
github-actions[bot] Jun 8, 2026
c958223
build(deps): bump django from 5.2.14 to 5.2.15 (#14301)
github-actions[bot] Jun 9, 2026
918429c
Update django_geonode_mapstore_client version
giohappy Jun 9, 2026
5e4108a
[Backport 5.1.x][Fixes #14245] Management command to clear GWC cache …
github-actions[bot] Jun 9, 2026
96cfb17
[Backport 5.1.x][Fixes #14306] Refact create_tile_layers as a subcomm…
github-actions[bot] Jun 9, 2026
8eadd6f
Fix #14305 (#14307) (#14316)
github-actions[bot] Jun 10, 2026
4fa63e8
[Fixes #11920] Remove call to command rebuild_index in tasks.py (#143…
github-actions[bot] Jun 10, 2026
026505b
[Fixes #14318] Improve logging (#14319) (#14320)
github-actions[bot] Jun 10, 2026
55bdd6c
[Fixes #14321] copy_with_dump is missing from copy_table_with_ogr2ogr…
github-actions[bot] Jun 11, 2026
2168d41
Sanitize metadata input
etj Jun 10, 2026
2263d0b
[Fixes #14339] Drop support Dropbox storage manager (#14347)
github-actions[bot] Jun 17, 2026
7950e61
build(deps): bump cryptography from 48.0.0 to 49.0.0 (#14346)
github-actions[bot] Jun 17, 2026
eadafcd
Upgrade of setuptools with fixes to dependencies (#14330) (#14349)
github-actions[bot] Jun 17, 2026
1ca8488
Update lxml dependency version to 6.1.1
giohappy Jun 11, 2026
2f11330
[Fixes #14344] Pack rdf files in build distribution (#14345) (#14350)
github-actions[bot] Jun 17, 2026
c78706c
[Fixes #14000] Refact extraMetadata (#14286) (#14351)
github-actions[bot] Jun 17, 2026
2592448
Fix to exception handling for XLSX (#14138) (#14352)
github-actions[bot] Jun 18, 2026
de298ee
[Backport Fixes #14354] Cannot upload multiple layers from GPKG file …
mattiagiupponi Jun 19, 2026
1b8ffd1
increase pyjwt-version
Jun 19, 2026
a31df5a
[Fixes #14366] Upload error message (#14370) (#14371)
github-actions[bot] Jun 22, 2026
f537413
[Fixes #14374] Add deletion of temporary files in case of rollback (#…
github-actions[bot] Jun 22, 2026
2b73f32
[Fixes #14306] Refact create_tile_layers as a subcommand of gwc - add…
etj Jun 9, 2026
6b9c5ec
[Fixes #14306] Refact create_tile_layers as a subcommand of gwc - refact
etj Jun 9, 2026
ed585c0
[Fixes #14358] Align GWC template to the default GWC configuration
etj Jun 23, 2026
acf7f78
[Fixes #14369] Map thumbnail is not saved if remote WMS without services
mattiagiupponi Jun 23, 2026
692274f
Update Nginx image version to 1.31.2-latest
giohappy Jun 25, 2026
166345e
Improve asset file retrieval
etj Jun 26, 2026
ed36af4
Fix dynamic version resolution in pyproject.toml
giohappy Jun 29, 2026
8d79b7b
[Fixes #14386] Replace Dataset does not keep in account the user perm…
github-actions[bot] Jul 1, 2026
c645757
Revise security vulnerability reporting instructions (#14403)
simboss Jul 3, 2026
6487c64
build(deps): bump django from 5.2.15 to 5.2.16
dependabot[bot] Jul 13, 2026
5ab5aa5
build(deps): bump boto3 from 1.39.3 to 1.43.46
dependabot[bot] Jul 13, 2026
930acd8
[Fixes #14406] Introducing a new setting for the URL validation (#14407)
Gpetrak Jul 9, 2026
6f239ad
build(deps): bump pillow from 12.2.0 to 12.3.0
dependabot[bot] Jul 6, 2026
4d76284
build(deps): bump pymupdf from 1.27.2.3 to 1.28.0
dependabot[bot] Jul 6, 2026
83f7421
build(deps): update jwcrypto requirement from >=1.5.7 to >=1.5.8
dependabot[bot] Jun 29, 2026
1987a3b
[Fixes #14321] Copy with dump, invalid error variable name (#14420) (…
github-actions[bot] Jul 15, 2026
eb1438a
Improve error handling in upsert (#14432) (#14443)
github-actions[bot] Jul 15, 2026
ebd18b1
[Fixes #14437] Fixes keywords lost on style updates (#14441)
github-actions[bot] Jul 15, 2026
d97519a
[Fixes #14455] XML metadata is not regenerated after updating metadat…
github-actions[bot] Jul 23, 2026
5c3f187
[Fixes #13646] Multilang: use multilang entries in ISO19115 (#14421) …
github-actions[bot] Jul 23, 2026
f8e7077
[Backport PR #14402 to 5.1.x] Moving the logic of PROFILE_LANGUAGE_CH…
sijandh35 Jul 30, 2026
0086d54
[Fixes #14484] Created a m2m signal to sync group members (#14485) (#…
nrjadkry Aug 7, 2026
058283f
Removed redundant code for merging files from assets and links. (#145…
github-actions[bot] Aug 12, 2026
e017772
Upload size validation (#14507)
giohappy Aug 12, 2026
4bdd126
correct timeseries endpoint check
sijandh35 Jul 22, 2026
0f1bf9c
Xml upload download improvements (#14505)
giohappy Aug 13, 2026
56e2796
Fix broken tests (#14516) (#14518)
github-actions[bot] Aug 14, 2026
c6a1ad4
Aligned docker setup docs to the new goenode-project archtiecture
giohappy Aug 19, 2026
5a6832a
Aligned bare docker setup docs
giohappy Aug 19, 2026
119aea8
[Fixes #14498] 3d tiles with multiple folders, raise error 21 (#14499…
github-actions[bot] Aug 20, 2026
5e1ae77
[Backport #14519] GroupProfile.access default is public, not a valid …
mattiagiupponi Aug 20, 2026
2e6c555
[Fixes #14533] Fixes XML File upload fails when trying to upload (#14…
github-actions[bot] Aug 20, 2026
328982d
Document the XLSX_UPLOAD_ENABLED configuration
giohappy Aug 21, 2026
7603968
build(deps): bump lxml from 6.1.1 to 6.1.2
dependabot[bot] Aug 24, 2026
2ddca6a
[Backport #14522 to 5.1.x] Improvements to URLs parsing (#14557)
sijandh35 Aug 26, 2026
54709bf
[Fixes #14544] Attribute fetch for ArcGIS REST remote datasets is bro…
github-actions[bot] Aug 31, 2026
e35737c
Improvements in resource thumbnail handling (#14571) (#14572)
github-actions[bot] Sep 2, 2026
5d99c07
improvement in harvesters endpoint (#14567) (#14569)
github-actions[bot] Sep 3, 2026
38fbf56
document thumbnail issue fixed (#14560) (#14578)
github-actions[bot] Sep 3, 2026
5454211
Improvements of catalouge metadata (#14576) (#14579)
github-actions[bot] Sep 3, 2026
3d400a6
BACKPORT Fixes #14574 Improvements on cloning (#14598)
mattiagiupponi Sep 14, 2026
87831c7
Profile page fixes
sijandh35 Sep 14, 2026
2201ba7
[Fixes #14394] remove support of GoogleCloudStorage (#14400)
mattiagiupponi Jul 14, 2026
b150e45
build(deps): bump boto3 from 1.43.88 to 1.43.92
dependabot[bot] Sep 14, 2026
1ce7bda
build(deps): bump djangorestframework from 3.17.2 to 3.18.1
dependabot[bot] Sep 14, 2026
fd243fe
build(deps): bump pdok-geopackage-validator from 0.14.4 to 0.14.5
dependabot[bot] Sep 14, 2026
81c4d1f
Fix dynamic-rest deps (#14604)
mattiagiupponi Sep 16, 2026
02bb45b
Backport #14605: Cloning issues fixes on GeoStories, Dashboards, and …
mattiagiupponi Sep 18, 2026
cf4ce8f
improvement_on_error_redirect (#14610) (#14614)
github-actions[bot] Sep 18, 2026
31ac62d
Limit embed endpoints to GET only (#14609) (#14611)
github-actions[bot] Sep 18, 2026
69a2a00
improvement on assets (#14626) (#14630)
github-actions[bot] Sep 23, 2026
f26fb71
Improvement in remote service (#14627) (#14632)
github-actions[bot] Sep 23, 2026
245cd51
improvements on linked resources (#14628) (#14634)
github-actions[bot] Sep 23, 2026
0e2cd4c
Fix gdal apt dependnecy in base image
giohappy Sep 24, 2026
c22de79
Upgrade to Nginx 1.31.6 and Geoserver 2.28.5
giohappy Sep 24, 2026
554e5f2
Pin to geonode-dynamic-rest 2.3.0.3
giohappy Sep 24, 2026
1ab0ed9
Update django_geonode_mapstore_client dependency source (#14650)
giohappy Sep 24, 2026
c64c3a6
[Backport 5.1.x] [Fixes #14639] Add lon to accepted CSV fields for po…
github-actions[bot] Sep 25, 2026
43bb3f8
Improvements in Asset (#14615) (#14657)
github-actions[bot] Sep 25, 2026
6e43814
[Backport 5.1.x][Fixes #14637] The check in is_monochromatic_image fo…
mattiagiupponi Sep 25, 2026
6090afa
Fixed typo in dependency
giohappy Sep 25, 2026
5ae706f
[Fixes #14660] XLSX upload fix (#14661) (#14662)
github-actions[bot] Sep 28, 2026
dbc4e59
Fixed search fields lookup
giohappy Sep 28, 2026
9ddcc4f
[Fixes #14659][5.1.x] Error in uploaded metadata in multilang instances
etj Sep 28, 2026
aa36588
[Fixes #14638] Extent is not assigned correctly to datasets created f…
github-actions[bot] Sep 28, 2026
4038798
[Fixes #14651] Management command for metadata validation
etj Sep 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .env.sample
Original file line number Diff line number Diff line change
Expand Up @@ -248,4 +248,7 @@ DEFAULT_MAX_PARALLEL_UPLOADS_PER_USER=5
# FORCE_READ_ONLY_MODE=False Override the read-only value saved in the configuration

# Enable or not the XLSX / XLS upload
XLSX_UPLOAD_ENABLED=False
XLSX_UPLOAD_ENABLED=False

# List of trusted hosts (format: domain:port) allowed to bypass URL safety validation.
# SAFE_URL_TRUSTED_HOSTS=[]
2 changes: 1 addition & 1 deletion .env_dev
Original file line number Diff line number Diff line change
Expand Up @@ -210,4 +210,4 @@ UPSERT_CHUNK_SIZE= 100
UPSERT_LIMIT_ERROR_LOG=100

# Enable or not the XLSX / XLS upload
XLSX_UPLOAD_ENABLED=False
XLSX_UPLOAD_ENABLED=False
35 changes: 30 additions & 5 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,17 +2,42 @@

## Supported Versions

GeoNode versions supported with security updates.
GeoNode [versions](https://github.com/GeoNode/geonode/wiki/Releases) supported with security updates.

| Version | Supported |
| ------- | ------------------ |
| 4.0.x | :white_check_mark: |
| 5.1.x | :white_check_mark: |
| 5.0.x | :white_check_mark: |
| < 4.0 | :x: |
| < 5 | :x: |

This approach provides ample time for upgrading ensuring you are always working with a supported GeoNode release.

If your organization is making use of a GeoNode version that is no longer in use by the community all is not lost.
You can volunteer on the developer list to make additional releases, or engage with one of our
[Commercial Support](https://geonode.org/providers/) providers.

## Reporting a Vulnerability

- **DO NOT** send a security alert on the public mailing list or any other public channel
- **SEND** the report to geonode-psc@lists.osgeo.org and be prapred to collaborate with the GeoNode PSC
1. **DO NOT** report vulnerabilities on the public mailing list or any other public channel
2. There are **two options** to report a security vulnerability:
- Send the report by email to geonode-psc@lists.osgeo.org and be prepared to collaborate with the GeoNode PSC
- Navigate to [Private vulnerability reporting](https://github.com/geonode/geonode/security/advisories/new) and create a new vulnerability report. For more information see [GitHub documentation](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability).

3. There is no expected response time.
4. Keep in mind participants are volunteering their time, an extensive fix may require fundraising/resources.

Thanks for you support and help!

## Coordinated vulnerability disclosure

Disclosure policy:

1. The reported vulnerability has been verified by working with the GeoNode PSC
2. GitHub [security advisory](https://github.com/geonode/geonode/security) is used to reserve a CVE number by the GeoNode Organization
3. A fix or documentation clarification is accepted and backported to active branches
4. A fix is included for the active branches release downloads ([reelases](https://github.com/GeoNode/geonode/releases), or issued via emergency update)
6. The CVE vulnerability is published by the GeoNode Organization with mitigation and patch instructions

This represents a balance between transparency and participation that does not overwhelm participants.
Those seeking greater visibility are encouraged to volunteer with the [geonode-devel](https://lists.osgeo.org/cgi-bin/mailman/listinfo/geonode-devel) list;
or work with one of the [commercial support providers](https://geonode.org/providers/) who participate on behalf of their customers.
6 changes: 4 additions & 2 deletions celery-cmd
Original file line number Diff line number Diff line change
Expand Up @@ -16,13 +16,14 @@ CELERY__WORKER_CONCURRENCY=${CELERY__WORKER_CONCURRENCY:-"4"}

# Celery beat settings
CELERY__BEAT_SCHEDULE=${CELERY__BEAT_SCHEDULE:-"celery.beat:PersistentScheduler"}
CELERY__BEAT_DB=${CELERY__BEAT_DB:-"/mnt/volumes/statics/celerybeat-schedule"}
CELERY__BEAT_LOG=${CELERY__BEAT_LOG:-"/var/log/celery_beat.log"}

# Harvester settings
CELERY__HARVESTER_WORKER_NAME=${CELERY__HARVESTER_WORKER_NAME:-"harvesting_worker@%h"}
CELERY__HARVESTER_CONCURRENCY=${CELERY__HARVESTER_CONCURRENCY:-"10"}
CELERY__HARVESTER_AUTOSCALE_VALUES=${CELERY__HARVESTER_AUTOSCALE_VALUES:-"15,10"}
CELERY__HARVESTER_MAX_MEMORY_PER_CHILD=${CELERY__MAX_MEMORY_PER_CHILD:-"500000"}
CELERY__HARVESTER_MAX_MEMORY_PER_CHILD=${CELERY__HARVESTER_MAX_MEMORY_PER_CHILD:-"500000"}

# --- FIX: Remove stale Beat pidfile before starting beat ---
BEAT_PIDFILE="/tmp/celerybeat.pid"
Expand All @@ -43,6 +44,7 @@ fi

echo "Starting Celery Beat..."
$CELERY_BIN -A $CELERY_APP beat --scheduler=$CELERY__BEAT_SCHEDULE \
--schedule=$CELERY__BEAT_DB \
--loglevel=$CELERY__LOG_LEVEL -f $CELERY__BEAT_LOG --pidfile=/tmp/celerybeat.pid &

echo "Starting Default Celery Worker..."
Expand All @@ -67,4 +69,4 @@ wait -n

# Exit with the status of the process that exited first
# Docker will restart the container if this is non-zero (i.e., a failure)
exit $?
exit $?
6 changes: 3 additions & 3 deletions docker-compose-dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ services:

# Nginx is serving django static and media files and proxies to django and geonode
geonode:
image: geonode/nginx:1.28.0-v1
image: geonode/nginx:1.31.0-latest
container_name: nginx4${COMPOSE_PROJECT_NAME}
env_file:
- .env
Expand All @@ -79,7 +79,7 @@ services:

# Geoserver backend
geoserver:
image: geonode/geoserver:2.28.x-latest
image: geonode/geoserver:2.28.4-latest
container_name: geoserver4${COMPOSE_PROJECT_NAME}
healthcheck:
test: "curl -m 10 --fail --silent --write-out 'HTTP CODE : %{http_code}\n' --output /dev/null http://geoserver:8080/geoserver/ows"
Expand All @@ -105,7 +105,7 @@ services:
condition: service_healthy

data-dir-conf:
image: geonode/geoserver_data:2.28.x-latest
image: geonode/geoserver_data:2.28.4-latest
container_name: gsconf4${COMPOSE_PROJECT_NAME}
entrypoint: sleep infinity
volumes:
Expand Down
4 changes: 2 additions & 2 deletions docker-compose-geoserver-server.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ version: '2.2'
services:

data-dir-conf:
image: geonode/geoserver_data:2.28.x-latest
image: geonode/geoserver_data:2.28.4-latest
restart: on-failure
container_name: gsconf4${COMPOSE_PROJECT_NAME}
labels:
Expand All @@ -13,7 +13,7 @@ services:
- geoserver-data-dir:/geoserver_data/data

geoserver:
image: geonode/geoserver:2.28.x-latest
image: geonode/geoserver:2.28.4-latest
restart: unless-stopped
container_name: geoserver4${COMPOSE_PROJECT_NAME}
stdin_open: true
Expand Down
6 changes: 3 additions & 3 deletions docker-compose-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ services:

# Nginx is serving django static and media files and proxies to django and geonode
geonode:
image: geonode/nginx:1.28.0-v1
image: geonode/nginx:1.31.0-latest
container_name: nginx4${COMPOSE_PROJECT_NAME}
env_file:
- .env_test
Expand Down Expand Up @@ -80,7 +80,7 @@ services:

# Geoserver backend
geoserver:
image: geonode/geoserver:2.28.x-latest
image: geonode/geoserver:2.28.4-latest
container_name: geoserver4${COMPOSE_PROJECT_NAME}
healthcheck:
test: "curl -m 10 --fail --silent --write-out 'HTTP CODE : %{http_code}\n' --output /dev/null http://geoserver:8080/geoserver/ows"
Expand All @@ -106,7 +106,7 @@ services:
condition: service_healthy

data-dir-conf:
image: geonode/geoserver_data:2.28.x-latest
image: geonode/geoserver_data:2.28.4-latest
container_name: gsconf4${COMPOSE_PROJECT_NAME}
entrypoint: sleep infinity
volumes:
Expand Down
6 changes: 3 additions & 3 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ services:

# Nginx is serving django static and media files and proxies to django and geonode
geonode:
image: geonode/nginx:1.28.0-v1
image: geonode/nginx:1.31.6-latest
container_name: nginx4${COMPOSE_PROJECT_NAME}
env_file:
- .env
Expand All @@ -92,7 +92,7 @@ services:

# Geoserver backend
geoserver:
image: geonode/geoserver:2.28.x-latest
image: geonode/geoserver:2.28.5-latest
container_name: geoserver4${COMPOSE_PROJECT_NAME}
healthcheck:
test: "curl -m 10 --fail --silent --write-out 'HTTP CODE : %{http_code}\n' --output /dev/null http://geoserver:8080/geoserver/ows"
Expand All @@ -118,7 +118,7 @@ services:
condition: service_healthy

data-dir-conf:
image: geonode/geoserver_data:2.28.x-latest
image: geonode/geoserver_data:2.28.5-latest
container_name: gsconf4${COMPOSE_PROJECT_NAME}
entrypoint: sleep infinity
volumes:
Expand Down
2 changes: 2 additions & 0 deletions docker/base/ubuntu/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ RUN wget --quiet -O - https://www.postgresql.org/media/keys/ACCC4CF8.asc | apt-k
# will install python3.10
RUN apt-get install lsb-release -y
RUN echo "deb https://apt.postgresql.org/pub/repos/apt/ `lsb_release -cs`-pgdg main" |tee /etc/apt/sources.list.d/pgdg.list
# Keep GDAL from the Ubuntu archive, pgdg ships newer builds that break libgdal-dev / pip GDAL==3.8.4
RUN printf 'Package: *gdal*\nPin: release o=apt.postgresql.org\nPin-Priority: -1\n' > /etc/apt/preferences.d/pgdg-no-gdal

# Prepraing dependencies
RUN apt-get install -y \
Expand Down
5 changes: 2 additions & 3 deletions docs/mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,12 +63,12 @@ nav:
- Attributes Table: "user-guide/maps/maps_configuration/attribute_table.md"
- Timeline: "user-guide/maps/maps_configuration/timeline.md"
- Other Menu Tools: "user-guide/maps/maps_configuration/options_menu.md"
- Documents:
- Upload/Add Documents: "user-guide/documents/upload.md"
- Documents: "user-guide/documents/upload.md"
- GeoStories: "user-guide/geostory/geostory.md"
- Dashboards: "user-guide/dashboard/dashboard.md"
- Styling: "user-guide/resource_styling.md"
- Sharing: "user-guide/sharing.md"
- Default Language: "user-guide/default-language.md"
- Metadata: "user-guide/metadata.md"
- Administration:
- GeoNode Admins Guide:
Expand Down Expand Up @@ -104,7 +104,6 @@ nav:
- Customize the look and feel:
- GeoNode Themes: "admin/gnode_theme/geonode_themes.md"
- Theming your GeoNode Project: "admin/gnode_theme/theme_geonode_project.md"
- Changing the Default Language: "admin/default_lang.md"
- Thesauri: "admin/thesauri/thesauri.md"
- Developer Guide:
- API Usage: "development/api.md"
Expand Down
4 changes: 2 additions & 2 deletions docs/src/admin/admin_panel/admin_panel_theming.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,15 +30,15 @@ Just below the `Description` field, you will find the `Enabled` checkbox, which
*Theme Name and Description*
///

## Jumbotron and Get Started link

!!! Note
Remember, every time you want to apply some changes to the theme, you **must** save the theme and reload the GeoNode browser tab.

In order to quickly switch back to the Home page, you can just click the `VIEW SITE` link in the top-right corner of the Admin dashboard.

![](img/theming/view_site.png){ align=center }

## Jumbotron and Get Started link

The next section allows you to define the first important theme properties. This part involves the GeoNode main page sections.

![](img/theming/theme_properties.png){ align=center }
Expand Down
28 changes: 14 additions & 14 deletions docs/src/admin/admin_panel/group.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
## Creating a Group

| In GeoNode is possible to create new groups with set of permissions which will be inherited by all the group members.
| The creation of a Group can be done both on the GeoNode UI and on the *Admin Panel*, we will explain how in this paragraph.
In GeoNode is possible to create new groups with set of permissions which will be inherited by all the group members.
The creation of a Group can be done both on the GeoNode UI and on the *Admin Panel*, we will explain how in this paragraph.

The `Create Groups` link of *About* menu in the navigation bar allows administrators to reach the *Group Creation Page*.

Expand All @@ -26,9 +26,9 @@ The new created group will be searchable in the *Groups List Page*.
!!! note "Important notes"
The `Create a New Group` button on the *Groups List Page* allows to reach the *Group Creation Form*.

| As already mentioned above, groups can also be created from the Django-based *Admin Interface* of GeoNode.
| The *Groups* link of the *AUTHENTICATION AND AUTHORIZATION* section allows to manage basic Django groups which only care about permissions.
| To create a GeoNode group you should take a look at the *GROUPS* section.
As already mentioned above, groups can also be created from the Django-based *Admin Interface* of GeoNode.
The *Groups* link of the *AUTHENTICATION AND AUTHORIZATION* section allows to manage basic Django groups which only care about permissions.
To create a GeoNode group you should take a look at the *GROUPS* section.

![groups_admin_section](img/groups_admin_section.png)

Expand Down Expand Up @@ -143,8 +143,8 @@ On the *Group Profile Form* page you can insert a logo from your disk by click o
![editing_group_logo](img/editing_group_logo.png)


| Click on `Update` to apply the changes.
| Take a look at your group now, you should be able to see that logo.
Click on `Update` to apply the changes.
Take a look at your group now, you should be able to see that logo.

![group_logo](img/group_logo.png)

Expand All @@ -156,12 +156,12 @@ The `Manage Group Members` link opens the *Group Members Page* which shows *Grou
**Managers** can edit group details, can delete the group, can see the group activities and can manage memberships.
Other **Members** can only see the group activities.

| In Public Groups, users can join the group without any approval.
Other types of groups require the user to be invited by the group managers.
| Only group managers can *Add new members*.
In the picture below, you can see the manager can search for users by typing their names into the *User Identifiers* search bar.
Once found, he can add them to the group by clicking the `Add Group Members` button.
The *Assign manager role* flag implies that all the users found will become managers of the group.
In Public Groups, users can join the group without any approval.
Other types of groups require the user to be invited by the group managers.
Only group managers can *Add new members*.
In the picture below, you can see the manager can search for users by typing their names into the *User Identifiers* search bar.
Once found, he can add them to the group by clicking the `Add Group Members` button.
The *Assign manager role* flag implies that all the users found will become managers of the group.

![add_new_member](img/add_new_member.png)

Expand All @@ -171,4 +171,4 @@ The following picture shows you the results.
![new_members](img/new_members.png)


If you want to change the role of group members after adding them, you can use the "promote" button to make a member into a manager, and the "demote" button to make a manager into a regular member.
If you want to change the role of group members after adding them, you can use the "promote" button to make a member into a manager, and the "demote" button to make a manager into a regular member.
22 changes: 11 additions & 11 deletions docs/src/admin/admin_panel/oauth.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
# OAuth2 Access Tokens

This small section won't cover entirely the GeoNode OAuth2 security integration, this is explained in detail in other sections of the documentation
(refer to :ref:`oauth2_fixtures_and_migration` and :ref:`oauth2_tokens_and_sessions`).
(refer to the [Django OAuth Toolkit Admin Setup](../../setup/configuration/components/geonode_security_backend/geonode_security_backend.md#django-oauth-toolkit-admin-setup) and [GeoNode / GeoServer Authentication Mechanism](../../setup/configuration/components/geonode_security_backend/geonode_security_backend.md#geonode-geoserver-authentication-mechanism) sections).

Here we will focus mainly on the :guilabel:`Admin > DJANGO/GEONODE OAUTH TOOLKIT` panel items with a specific attention to the ``Access tokens`` management.
Here we will focus mainly on the `Admin > DJANGO/GEONODE OAUTH TOOLKIT` panel items with a specific attention to the ``Access tokens`` management.

The :guilabel:`Admin > DJANGO/GEONODE OAUTH TOOLKIT` panel (as shown in the figure below) allows an admin to manage everything related to
The `Admin > DJANGO/GEONODE OAUTH TOOLKIT` panel (as shown in the figure below) allows an admin to manage everything related to
GeoNode OAuth2 grants and permissions.

As better explained in other sections of the documentation, this is needed to correctly handle the communication between GeoNode and GeoServer.
Expand All @@ -14,24 +14,24 @@ As better explained in other sections of the documentation, this is needed to co

Specifically from this panel an admin can create, delete or extend OAuth2 ``Access tokens``.

The section :ref:`oauth2_tokens_and_sessions` better explains the concepts behind OAuth2 sessions; we want just to refresh the mind here
The [GeoNode / GeoServer Authentication Mechanism](../../setup/configuration/components/geonode_security_backend/geonode_security_backend.md#geonode-geoserver-authentication-mechanism) section better explains the concepts behind OAuth2 sessions; we want just to refresh the mind here
about the basic concepts:

* If the `SESSION_EXPIRED_CONTROL_ENABLED <../../basic/settings/index.html#session-expired-control-enabled>`_ setting is set to `True` (by default it is set to `True`)
* If the `SESSION_EXPIRED_CONTROL_ENABLED` setting is set to `True` (by default it is set to `True`)
a registered user cannot login to neither GeoNode nor GeoServer without a valid ``Access token``.

* When logging-in into GeoNode through the sign-up form, GeoNode checks if a valid ``Access token`` exists and it creates a new one if not, or extends
the existing one if expired.

* New ``Access tokens`` expire automatically after `ACCESS_TOKEN_EXPIRE_SECONDS <../../basic/settings/index.html#access-token-expire-seconds>`_ setting (by default 86400)
* New ``Access tokens`` expire automatically after the [`ACCESS_TOKEN_EXPIRE_SECONDS`](../../setup/configuration/settings.md) setting (by default 86400)

* When an ``Access token`` expires, the user will be kicked out from the session and forced to login again

## Create a new token or extend an existing one

It is possible from the :guilabel:`Admin > DJANGO/GEONODE OAUTH TOOLKIT` panel to create a new ``Access token`` for a user.
It is possible from the `Admin > DJANGO/GEONODE OAUTH TOOLKIT` panel to create a new ``Access token`` for a user.

In order to do that, just click on the :guilabel:`Add` button beside ``Access tokens`` topic
In order to do that, just click on the `Add` button beside ``Access tokens`` topic

![oauth2-tokens/admin-panel-tokens-0001](img/oauth2-tokens/admin-panel-tokens-0002.png)

Expand All @@ -58,7 +58,7 @@ select the followings:

![oauth2-tokens/admin-panel-tokens-0003b](img/oauth2-tokens/admin-panel-tokens-0003c.png)

5. ``Expires``; select an expiration date by using the :guilabel:`date-time` widgets.
5. ``Expires``; select an expiration date by using the `date-time` widgets.

![oauth2-tokens/admin-panel-tokens-0003b](img/oauth2-tokens/admin-panel-tokens-0003d.png)

Expand All @@ -67,7 +67,7 @@ select the followings:
![oauth2-tokens/admin-panel-tokens-0003b](img/oauth2-tokens/admin-panel-tokens-0003e.png)


Do not forget to :guilabel:`Save`.
Do not forget to `Save`.

From now on, GeoNode will use this ``Access Token`` to control the user session (notice that the user need to login again if closing the browser session),
and the user will be able to access the OWS Services by using the new ``Access Token``, e.g.:
Expand All @@ -87,4 +87,4 @@ force its session to expire.

Remember that the user could activate another session by logging-in again on GeoNode with its credentials.

In order to be sure the user won't force GeoNode to refresh the token, reset first its password or de-activate it.
In order to be sure the user won't force GeoNode to refresh the token, reset first its password or de-activate it.
Loading
Loading