Skip to content

Loomio

v3.1.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 5d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Affected surfaces

auth

Summary

AI summary

Broad release touches Other workflow improvements, Performance and reliability, Interface changes, and Other fixes.

Full changelog

Loomio 3.1.0

This release adds threaded discussion to polls, bookmarks, organization-wide tags, expanded participation reports, Copy for AI, read-only agent access, new moderation controls, and a user-facing What’s new page.

It also includes substantial authentication and anonymous-poll security work, performance improvements for larger installations, an interface refresh, and infrastructure changes.

Security advisory: anonymous poll metadata

This release fixes an issue where metadata associated with anonymous poll responses could weaken ballot anonymity.

Loomio removed participant identities from anonymous responses, but exact timestamps, response ordering, event metadata, search results, and some exports could provide enough information to correlate a participant with an individual ballot.

Anonymous poll responses now:

  • omit creation, update, and voting timestamps;
  • are not returned in voting-time order;
  • omit voter and event-actor identities;
  • withhold individual choices until the poll’s result-visibility setting permits them;
  • omit voter identity, membership information, and response timestamps from poll exports; and
  • remove identifying and temporal metadata from group CSV and JSON exports.

When an anonymous poll closes, Loomio removes participant links from ballots and associated event actors. Participant verification remains separate from ballot data: authorized people can verify participation, subject to the poll’s quorum settings, without seeing how each participant voted.

These protections remove identifying metadata supplied by Loomio. They cannot prevent someone from identifying themselves in a written vote reason.

A separate security advisory provides further technical details.

Administrators should upgrade promptly if their instance uses anonymous polls.

Poll comments

Polls can now host threaded discussion.

Standalone polls behave as threads: participants can comment on the poll, reply to comments, and reply to visible votes and reasons. Polls embedded in discussions use the surrounding discussion timeline.

Closing voting does not close the conversation. Poll administrators can stop new comments by locking the topic or disabling comments.

Comments on polls support the same permissions, guests, reactions, notifications, moderation, and read tracking as discussion threads. Public visibility alone does not grant permission to comment.

This change includes a substantial migration of discussions and polls onto a shared topic model. Integrations that depend on legacy discussion_id relationships or DiscussionReader records may need updating.

Read more about poll comments on Loomio Community.

What’s new

Loomio now includes a What’s new page with a chronological history of user-facing features and improvements.

Open Settings → What’s new to see recent changes, with the newest updates shown first. The page also includes earlier Loomio changes so users can review how features and workflows have developed over time.

The page is available at /whats_new and includes a link to subscribe to the Loomio newsletter for release updates and stories from groups using Loomio.

Bookmarks

Signed-in users can bookmark:

  • threads;
  • comments;
  • polls;
  • votes; and
  • outcomes.

Bookmarks are private. A new Bookmarks page in the sidebar lists saved items, with links back to their original locations and a count of saved items.

Users can only create, view, and remove their own bookmarks. Bookmarking does not modify the original content or notify other participants.

Organization-wide tags

Parent groups and their subgroups now share one tag catalogue.

  • Tags are normalized and deduplicated across the organization.
  • A tag represents the same category in the parent group and its subgroups.
  • Discussion and poll panels share a searchable tag filter.
  • Existing tags can be applied by anyone permitted to edit the thread or poll.
  • The new Members can create tags setting controls whether members can introduce new tag names.
  • Subgroup administrators can create tags while tagging content in their subgroup.
  • Parent-group administrators manage tag names, colors, and deletion across the organization.
  • Tags are displayed alphabetically rather than using manually maintained priority ordering.

Tag changes save immediately. The selector initially shows tags used in the current group, with an option to show all tags in the organization.

Existing subgroup tags are consolidated into organization-level records during the upgrade. Topic assignments are retained.

Participation reports

Participation reports now support:

  • All groups, My groups, and Custom selection scopes;
  • tag activity grouped over time;
  • participation in tagged threads by user;
  • an Authored only view;
  • name and country filters; and
  • CSV export for the new report tables.

Members can report on groups they belong to. Supplying group IDs manually does not expand access beyond those memberships. Instance administrators can report across the instance and include direct threads.

Participation in a tagged thread includes authoring a thread or poll, commenting, casting a current vote, or publishing an outcome. Authored only counts discussion and standalone-poll authors.

Historical tag reports use each thread’s current tags and group those threads by creation date. They are not a history of when individual tags were added or removed.

Copy for AI and agent access

Thread members can copy a complete thread as structured Markdown for use with an AI assistant.

The Copy for AI dialog offers three actions:

  • copy the Loomio facilitator skill and thread together;
  • copy only the facilitator skill; or
  • copy only the thread.

The exported thread includes its context, timestamps, replies, polls, visible results, vote reasons, and outcomes. Loomio applies the current member’s permissions when preparing the export: hidden poll results and vote reasons are excluded, and voters remain unidentified in anonymous polls.

The facilitator skill provides guidance for identifying agreement, concerns, objections, participation still needed, and a suitable next step. It instructs the AI to ask for confirmation before posting content, creating a poll, or recording an outcome.

Loomio does not send thread content to an AI service. The content is displayed for review and copied to the clipboard, and the user decides where to paste it.

This release also introduces the first read-only endpoints for user-owned agents. An agent using a user’s API key can list the threads that user can access and read their ordered items. The agent receives the same visibility restrictions as the user.

Comment and vote moderation

Comment length limits

Threads, standalone polls, discussion templates, and poll templates can now specify a maximum comment length.

The editor shows the limit and prevents submission when the visible text is too long. The server also applies the limit when a comment is created or edited.

Existing topics and templates remain unlimited unless a limit is configured. Existing long comments are not changed, but they must be shortened before they can be edited after a limit is introduced.

Vote-reason redaction

Poll coordinators can redact and restore vote reasons.

Redaction hides the reason, attachments, and link previews from normal interfaces, APIs, notifications, and search results. The ballot and its contribution to the result are retained.

Redaction is reversible moderation rather than deletion. The original content remains stored so an authorized coordinator can restore it.

Interface changes

Updated interface components

Loomio now uses Vuetify 4. This updates typography, spacing, menus, forms, buttons, dialogs, voting screens, thread events, group settings, member lists, email settings, and report controls.

The underlying concepts of groups, threads, polls, votes, and memberships remain unchanged.

The upgrade also includes improvements to:

  • thread and poll action menus;
  • tag selection;
  • meeting-poll table layout;
  • account merge screens; and
  • consistent display of tag colors.

Emoji picker and Unicode emoji

The emoji picker now includes:

  • the complete standard emoji set;
  • localized keyword search;
  • frequently used emoji; and
  • a saved skin-tone preference.

Reactions and picker-inserted emoji are now stored as native Unicode. Existing known reaction values are migrated automatically, and a background job converts known shortcodes in existing rich-text content.

Emoji search uses the user’s account language while continuing to recognize English names and common aliases.

Rendering now uses the emoji font available on the user’s device.

Translation consistency

Several translations have been reviewed to use a consistent informal form of address:

  • German uses du and dein;
  • Spanish uses and tu;
  • French uses tu;
  • Italian uses informal tu forms; and
  • Brazilian Portuguese uses a consistent informal register.

These changes correct places where automated translation had introduced formal or inconsistent language.

Read-state improvements

Comments, polls, outcomes, and votes created by the current user are immediately marked as read, preventing unread indicators caused by a person’s own activity.

Thread navigation now includes New to you and Latest shortcuts.

Read-range calculations have also been corrected for partially overlapping ranges.

Other workflow improvements

  • Existing polls can once again be added to a discussion through Add to discussion.
  • Changing a group handle no longer breaks old group links or email-to-group addresses. Retired handles redirect to the current handle.
  • OAuth profile pictures are imported at login when the user has not uploaded an avatar.
  • User-created discussion and poll templates appear in the template browser and can be forked.
  • Forking a template no longer carries draft content from a previous fork.
  • People who use emailed login codes and do not have a password are prompted to set one. They can dismiss the prompt and continue using email sign-in.
  • BlueSky is available as a contact method.

Authentication and account security

This release includes a broader review of login, account recovery, OAuth, SAML, invitation, merge, and session behavior.

Login codes and registration links

  • Email login codes are single-use and expire.
  • Codes must match the submitted email address.
  • Repeated incorrect attempts are rate-limited.
  • After five failed attempts, the current code is invalidated.
  • Expired or previously used registration links cannot verify an email address or sign someone in.
  • Only valid login codes can bypass the normal anti-bot check.
  • Invalid and malformed authentication referrers are handled without interrupting login.

Sessions and password changes

Loomio now uses Rails-backed sessions instead of Devise sessions.

  • Each browser session can be revoked independently.
  • Signing out ends the current session.
  • Changing a password ends other active sessions.
  • Password changes invalidate outstanding login links and previously issued account access tokens.
  • Existing signed-in sessions are carried across the upgrade.

Password lockout and breached-password protections remain in place.

OAuth and SAML

  • OAuth callbacks must match an authorization attempt started in the same browser session.
  • SAML responses must match the sign-in request initiated by Loomio.
  • SAML assertions must be signed.
  • Unsolicited identity-provider-initiated SAML responses are rejected by default. Deployments that require this workflow can enable it explicitly.
  • Disconnecting an OAuth or SAML identity requires an explicit, CSRF-protected account action.
  • OAuth and API access tokens are redacted from application logs.

Account merging and invitations

  • Account merges require the recipient to be signed in as the destination account.
  • Merge verification requests are rate-limited.
  • Successful merge verification links cannot be reused.
  • Requesting a merge no longer invalidates unrelated destination-account sessions or recovery links.
  • Invitation acceptance is transactional, preventing a failed acceptance from leaving partial membership, reader, or voting records.

Additional permission protections

This release also strengthens authorization around:

  • task visibility;
  • deleted polls;
  • moving records between groups or topics;
  • chatbot configuration and connection testing;
  • identity disconnection;
  • translation requests; and
  • administrator edits to invited members.

Authentication rate limits now use verified client addresses rather than trusting client-supplied proxy headers.

Chatbot connection tests require an authorized group administrator and reject private or unsafe destination addresses.

Administration and APIs

User management API

A server-level administration API can now:

  • list and inspect users;
  • update user details;
  • deactivate and reactivate accounts;
  • redact accounts;
  • delete accounts; and
  • find users by Loomio ID or an external identity.

Redacting an account also revokes its active sessions.

The /api/b2 API now supports editing and soft-deleting discussions, polls, and comments.

Legacy /api/b1 routes and the old /help/api documentation endpoint have been removed. Integrations should use /api/b2 or the appropriate server administration API.

Profile management

Operators can separately configure whether users may edit externally managed profile fields and whether SSO refreshes names and email addresses at login.

Configurable upload limits

Operators can set a maximum upload size with FILE_UPLOAD_MAX_MB.

Performance and reliability

Performance and scale

Several frequently used queries have been optimized for larger groups, older instances, and accounts belonging to many groups.

Improvements include:

  • faster inbox and thread-list loading;
  • faster unread-count calculations;
  • more predictable loading of large or deeply nested threads;
  • fewer repeated database queries when loading notifications and activity;
  • faster topic visibility checks;
  • faster comment, reaction, and voter-list loading;
  • more efficient mention search in large groups and threads; and
  • more reliable participation reports across many groups, tags, or time periods.

Reactions are fetched lazily in a batched request rather than being included in every initial discussion, poll, and topic response. This reduces initial database work and response sizes.

Unread sidebar counts focus on topics active within the previous six weeks, keeping the count relevant and reducing work for accounts with a long history.

Redis is optional, but recommended

Background jobs now use PostgreSQL-backed Solid Queue instead of Sidekiq.

Caching and Action Cable can also use PostgreSQL-backed services, allowing a smaller installation to run without Redis. For production installations with sustained activity, Redis remains recommended because PostgreSQL-backed cache and live-update traffic can place substantial additional load on the database.

loomio-deploy continues to include and use Redis for caching and Action Cable by default.

Redis is no longer used for background jobs, sessions, or other durable application state. This means it can be configured as a bounded, non-persistent cache:

  • RDB snapshots can be disabled with save "";
  • append-only persistence can be disabled with appendonly no;
  • a suitable maxmemory limit can be set; and
  • maxmemory-policy allkeys-lru can be used so less recently used cache entries are discarded when the limit is reached.

Losing or evicting Redis keys may cause cache misses or Action Cable clients to reconnect, but it does not lose queued jobs, user sessions, or primary application data.

Solid Queue workers run with bin/jobs start. Job monitoring is available at /admin/jobs.

Recurring hourly work is now scheduled by Solid Queue through config/recurring.yml. New installations no longer need a host crontab entry for loomio:hourly_tasks.

Moving existing Sidekiq jobs

Outstanding Sidekiq jobs are not transferred automatically. Operators who want to process them before upgrading can run the included drain script using the old Sidekiq-enabled application bundle:

RAILS_ENV=production bundle exec rails runner script/drain_sidekiq_before_job_cutover.rb

The script:

  • runs every currently queued Sidekiq job;
  • runs every scheduled Sidekiq job;
  • removes each job from Redis after it succeeds; and
  • reports how many queued, scheduled, retry, and dead jobs remain.

The script deliberately does not run jobs in the retry or dead sets. It also runs scheduled jobs immediately, including jobs whose scheduled time has not yet arrived.

Running the drain script is optional. Skipping it does not prevent the upgrade or affect primary application data, but outstanding Sidekiq jobs will not be transferred to Solid Queue.

The drain script must run while the old bundle still includes Sidekiq. If the old checkout or container does not contain the script, copy it from this release before running it with the old bundle. After deploying the new release, start Solid Queue with bin/jobs start.

Faster and more reliable imports

Group imports now allocate and translate record IDs before inserting data. This avoids foreign-key collision windows, removes a second database rewrite pass, and improves the reliability and speed of larger imports.

Data integrity and cleanup

  • Polls and discussions can no longer reference deleted topics.
  • Deleting groups or topics cleans up dependent polls and discussions.
  • Previously orphaned active records are discarded so scheduled jobs do not repeatedly fail.
  • Missing-group records no longer cause serialization errors.
  • New operator tools can audit and remove dangling records, orphaned version history, and long-inactive users without durable references.
  • Closed-poll read-state backfills use more efficient lookups and report progress during upgrades.

Destructive cleanup remains an explicit operator action rather than an automatically scheduled task.

Other fixes

  • Atom feeds now provide working direct links to comments.
  • Daily catch-up mail correctly accounts for guest-topic activity and avoids sending empty summaries.
  • Comments attached to poll outcomes load correctly.
  • Group handle redirects preserve query parameters and existing access controls.
  • Own activity no longer produces incorrect unread counts.
  • Tags and reactions update more consistently without requiring a page refresh.
  • Email-to-group addresses continue to work after a group handle changes.
  • Missing group records no longer prevent related content from being serialized.
  • Read-state calculations correctly handle overlapping ranges.

Upgrade notes

Administrators should plan for the following changes:

  1. Poll comments perform a substantial topic-model migration. Allow additional migration time on large installations and review integrations that use legacy discussion-specific relationships.

  2. Background jobs move from Sidekiq to Solid Queue. Deploy the new release and run workers with bin/jobs start. Outstanding Sidekiq jobs are not transferred automatically. To process them before upgrading, optionally run RAILS_ENV=production bundle exec rails runner script/drain_sidekiq_before_job_cutover.rb using the old Sidekiq-enabled bundle. Redis is optional but remains recommended for cache and Action Cable. Because Redis no longer contains jobs or sessions, it can run without persistence and with a bounded allkeys-lru eviction policy.

  3. Organization tags are consolidated. Subgroup-specific tag metadata becomes organization-wide. Existing topic assignments are retained, but previous subgroup-specific metadata cannot be reconstructed automatically.

  4. Emoji reactions are converted to Unicode. Ensure background workers run so existing rich-text shortcodes are migrated.

  5. Legacy /api/b1 routes are removed. API integrations should use /api/b2 or the appropriate server administration API.

  6. Anonymous-poll protections apply immediately after upgrade. Existing ballot metadata is suppressed at API and export boundaries.

  7. The hourly host crontab is obsolete. Solid Queue schedules HourlyTaskJob through config/recurring.yml. Existing installations can remove the cron entry that runs bundle exec rake loomio:hourly_tasks.

  8. Session handling has changed. Existing users remain signed in, but operators should review any custom authentication, session, OAuth, or SAML integrations.

Full changelog: https://github.com/loomio/loomio/compare/v3.0.24...v3.1.0

Breaking Changes

  • Removed legacy `/api/b1` routes and old `/help/api` documentation endpoint.
  • Background jobs moved from Sidekiq to Solid Queue; Redis is optional but recommended for cache and Action Cable.

Security Fixes

  • GHSA-j7p3-rqf4-9f44 – Anonymous poll metadata (timestamps, ordering, voter identities) removed to preserve ballot anonymity.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Loomio

Get notified when new releases ship.

Sign up free

About Loomio

Collaborative decision-making tool that makes it easy for anyone to participate in decisions which affect them.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]