| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-17 | 5.0 kB | |
| v3.8.0 source code.tar.gz | 2026-09-17 | 130.6 MB | |
| v3.8.0 source code.zip | 2026-09-17 | 132.0 MB | |
| Totals: 3 Items | 262.6 MB | 0 | |
Loomio 3.8.0 expands the User API for service accounts and integrations, adds bulk account operations for instance administrators, and lets operators place every new account in a default onboarding group. It also fixes modified-Enter submission so keyboard submission no longer inserts an unintended line break.
- New: Discover groups, search visible content, and manage outgoing group webhooks through the User API
- New: Read public discussions and polls without group membership and list group memberships without exposing member email addresses
- New: Use an OpenAPI 3.1 contract, compact responses, response exclusions, and reliable collection totals for User API clients
- New: Select users in the instance administration panel and bulk deactivate, redact, or destroy them as spam
- New: Automatically add new accounts to an operator-configured onboarding group
- Fix: Submit editors and forms with modified Enter without inserting a line break
User API
The bearer-authenticated User API now provides GET /api/b2/groups for group discovery and GET /api/b2/search for full-text and fuzzy search across visible discussions, comments, polls, votes, and outcomes. Group administrators can list, create, update, test, and delete outgoing webhooks through /api/b2/chatbots.
API-key users can list public discussions and polls without joining their publicly visible groups. Group members can list membership names, IDs, titles, and roles, while other members' email addresses remain restricted to group administrators. Instance-administrator status no longer expands a User API key's access to private groups, private topics, membership data, membership management, or instance-wide participation reports; B2 permissions now consistently follow the API-key user's group roles.
Clients can pass compact=1 to omit bulky related records or use exclude_types for direct control over compound responses. Collection endpoints provide an exact pre-pagination meta.total where one is defined and omit the field where no meaningful total exists.
The published OpenAPI 3.1 contract covers every B2 and B3 route, and automated route coverage now detects undocumented or stale operations. The User API guide also documents webhook events, payload formats, delivery behavior, and the absence of webhook signatures. Webhook destinations should therefore use HTTPS and an unguessable URL token.
Instance administration
Instance administrators can search for users, select individual results or all results on the current page, and apply one bulk account operation. Deactivation blocks sign-in and is reversible. Redaction permanently removes personal and sign-in data while retaining anonymized authored content. Destroying a spam account deletes the account and dependent authored content and cannot be undone.
These operations are queued for background processing. Review the selected operation carefully before confirming it, especially redaction and destruction.
Default onboarding group
Operators can set DEFAULT_ONBOARDING_GROUP_ID to the numeric ID of an enabled group. Every account is added to that group when it first becomes a registered user. Existing accounts are not backfilled.
Add the setting to the deployment environment only when this behavior is wanted:
:::env
DEFAULT_ONBOARDING_GROUP_ID=123
The configured group must exist and be enabled. Remove the variable to disable automatic onboarding membership.
Keyboard submission
Modified Enter submission is now handled by one Vue directive across comments, discussions, polls, outcomes, authentication forms, profile password changes, and other supported forms. On macOS use Command+Enter; on other platforms use Ctrl+Enter. The form submits without adding a newline at the cursor.
Database and API compatibility
This release contains no database migrations.
B2 clients that relied on an API-key user's instance-administrator status to bypass group permissions must use a user with the required group membership or group-administrator role. Server-level user administration remains available through the B3 API and continues to authenticate exclusively with B3_API_KEY.
Existing full compound API responses remain the default. compact=1 and exclude_types are optional. Clients should tolerate the omission of meta.total on endpoints such as bounded search results where an exact total is not defined.
Upgrade
Make and verify a current database backup, set LOOMIO_CONTAINER_TAG=3.7 in .env, then run:
:::sh
./update.sh
No migration command or required environment-variable change is needed. Restart every application and worker process after updating. If using the default onboarding group, set DEFAULT_ONBOARDING_GROUP_ID before restarting. After the release is available, confirm that the application and worker containers report version 3.8.0.
Full changelog: https://github.com/loomio/loomio/compare/v3.7.1...v3.8.0