parse-server · Issues· 561 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #10602
requestContextMiddleware DI missing on nested directAccess ops
type:bugUpdated Sep 11, 2026 - #10617
Saving a _Role clears the entire cache, issuing FLUSHDB on the Redis cache adapter
Updated Sep 10, 2026 - #10643
RestWrite.js auth and validation branches survive boolean negation under mutation testing
Updated Sep 1, 2026 - #9086
Allow to run queries through LiveQueryClient
type:featurebounty:$500bounty:sponsoredUpdated Aug 21, 2026 - #10640
masterKeyIps never validates the CIDR mask
Updated Aug 19, 2026 - #10639
allowCustomObjectId accepts an operation as objectId and creates an unreachable user
Updated Aug 19, 2026 - #10638
Malformed ACL on signup answers 500, or a 400 that still persists the user
Updated Aug 19, 2026 - #10637
Relation query with a null operand throws an uncaught TypeError (500)
Updated Aug 19, 2026 - #10636
Verification and password reset emails are dispatched without a rejection handler, producing unhandled rejections
Updated Aug 14, 2026 - #10634
RedisCacheAdapter put, del and clear reject on a Redis outage, producing unhandled rejections
Updated Aug 14, 2026 - #10631
Documentation for directAccess states the default is false, but it has defaulted to true since Parse Server 6
Updated Aug 13, 2026 - #10630
Per-entry cache TTL is silently ignored by the in-memory cache adapter
Updated Aug 13, 2026 - #10628
LiveQuery role cache is not invalidated for all users affected by a role write or delete
Updated Aug 13, 2026 - #10626
/installations and /audiences reject a find sent as POST + _method=GET with "Invalid key name: 0"
Updated Aug 13, 2026 - #10624
Rate limit Redis keys are not scoped to the configured route
type:bugUpdated Aug 11, 2026