From 348b79bb4a8eb170f40b7d8e7613421fe6fb6b04 Mon Sep 17 00:00:00 2001 From: Arash Date: Mon, 12 Jan 2026 17:41:17 +0100 Subject: [PATCH 1/7] Add credentials tags to schema template for tool requirements --- doc/schema_template.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/doc/schema_template.md b/doc/schema_template.md index d3c2ac63bc7..a50de0af8b7 100644 --- a/doc/schema_template.md +++ b/doc/schema_template.md @@ -34,6 +34,9 @@ $tag:tool|requirements://complexType[@name='Requirements'] $tag:tool|requirements|requirement://complexType[@name='Requirement'] $tag:tool|requirements|container://complexType[@name='Container'] $tag:tool|requirements|resource://complexType[@name='Resource'] +$tag:tool|requirements|credentials://complexType[@name='Credentials'] +$tag:tool|requirements|credentials|variable://complexType[@name='CredentialsVariable'] +$tag:tool|requirements|credentials|secret://complexType[@name='CredentialsSecret'] $tag:tool|required_files://complexType[@name='RequiredFiles'] $tag:tool|required_files|include://complexType[@name='RequiredFileInclude'] $tag:tool|required_files|exclude://complexType[@name='RequiredFileExclude'] From aabca704fa97522ea081cc79650fa8ca28cca232 Mon Sep 17 00:00:00 2001 From: Arash Date: Mon, 12 Jan 2026 17:41:56 +0100 Subject: [PATCH 2/7] Add documentation for the new tool credentials system in the vault --- doc/source/admin/special_topics/vault.md | 47 +++++++++++++++++++++++- 1 file changed, 46 insertions(+), 1 deletion(-) diff --git a/doc/source/admin/special_topics/vault.md b/doc/source/admin/special_topics/vault.md index 006a4ca8644..f6b0d6cfe97 100644 --- a/doc/source/admin/special_topics/vault.md +++ b/doc/source/admin/special_topics/vault.md @@ -125,4 +125,49 @@ In a file source the password could be used as follows: password: ${user.user_vault.read_secret('preferences/ufz-nextcloud/password')} ``` -This example assumes that the NextCloud username is identical to the Galaxy username. If this is not the case also the username could be a user preference that is stored in a vault. \ No newline at end of file +This example assumes that the NextCloud username is identical to the Galaxy username. If this is not the case also the username could be a user preference that is stored in a vault. + +## Tool Credentials System + +Starting with Galaxy 25.1, tools can request credentials directly through a new tool credentials system. This system provides a secure, user-friendly way for tools to access external APIs and services using credentials stored in the vault. + +### Overview + +The tool credentials system allows tool developers to declaratively specify credential requirements in their tool XML, and Galaxy automatically: +- Presents a user-friendly credential management interface in the tool form +- Stores sensitive credentials (secrets) encrypted in the configured vault +- Injects credentials as environment variables when tools execute +- Provides centralized credential management in User Preferences + +### How it works + +1. **Tool Definition**: Tool developers add a `` element to their tool XML defining required secrets (API keys, passwords) and optional variables (endpoints, usernames). +2. **User Experience**: When users run a tool requiring credentials, they see a credential management section in the tool form where they can provide or select existing credentials. +3. **Secure Storage**: All secrets are automatically stored encrypted in the vault (configured via `vault_config_file`). +4. **Automatic Injection**: When the tool runs, Galaxy injects the credentials as environment variables into the tool's execution environment. + +### Vault Configuration Requirements + +The tool credentials system requires a properly configured vault. Any of the supported vault backends (hashicorp, custos, or database) can be used. Ensure you have: + +1. Set up your vault configuration as described in the sections above +2. Configured the `vault_config_file` setting in `galaxy.yml` +3. Tested that the vault is working properly + +The tool credentials system will automatically use the configured vault to store all tool secrets. + +### Admin Considerations + +- **No additional configuration needed**: Unlike the older user preferences approach, the tool credentials system requires no admin configuration in `user_preferences_extra_conf.yml`. Tools can define their own credential requirements. +- **Vault is required**: The tool credentials system only works when a vault is configured. If no vault is configured, tools requesting credentials will not function properly. +- **User isolation**: Each user's credentials are isolated in the vault. Credentials cannot be shared between users. +- **Migration from user preferences**: If you previously configured tool credentials via `user_preferences_extra_conf.yml`, those can be gradually phased out as tools migrate to the new system. Both systems can coexist. + +### API Access + +The tool credentials system provides a REST API at `/api/users/{user_id}/credentials` for programmatic credential management. This can be useful for: +- Automating credential setup for multiple users +- Building custom credential management interfaces +- Integrating with external identity management systems + +For more information on the tool credentials system from a developer perspective, see the [Tool XML Schema documentation](https://docs.galaxyproject.org/en/master/dev/schema.html#tool-requirements-credentials). \ No newline at end of file From 8bd436b4cd72bd5d6ea7a9015a818f76aee70b72 Mon Sep 17 00:00:00 2001 From: Matthias Bernt Date: Mon, 12 Jan 2026 17:56:12 +0100 Subject: [PATCH 3/7] use double quotes for galaxy bibtex citation --- lib/galaxy/config/schemas/config_schema.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/galaxy/config/schemas/config_schema.yml b/lib/galaxy/config/schemas/config_schema.yml index d6deeda1ca7..60baf794d6d 100644 --- a/lib/galaxy/config/schemas/config_schema.yml +++ b/lib/galaxy/config/schemas/config_schema.yml @@ -1834,7 +1834,7 @@ mapping: citation_bibtex: type: str - default: "@article{Galaxy2024, title={The Galaxy platform for accessible, reproducible, and collaborative data analyses: 2024 update}, author={{The Galaxy Community}}, journal={Nucleic Acids Research}, year={2024}, doi={10.1093/nar/gkae410}, url={https://doi.org/10.1093/nar/gkae410}}" + default: '@article{Galaxy2024, title="The Galaxy platform for accessible, reproducible, and collaborative data analyses: 2024 update", author="{The Galaxy Community}", journal="Nucleic Acids Research", year="2024", doi="10.1093/nar/gkae410", url="https://doi.org/10.1093/nar/gkae410"}' required: false per_host: true desc: | From a74cacbdbf4e2f0d1fdee23f25540dc19d5b54db Mon Sep 17 00:00:00 2001 From: Matthias Bernt Date: Wed, 14 Jan 2026 10:04:14 +0100 Subject: [PATCH 4/7] update sample --- lib/galaxy/config/sample/galaxy.yml.sample | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/lib/galaxy/config/sample/galaxy.yml.sample b/lib/galaxy/config/sample/galaxy.yml.sample index d7f84092e25..53762d2fb98 100644 --- a/lib/galaxy/config/sample/galaxy.yml.sample +++ b/lib/galaxy/config/sample/galaxy.yml.sample @@ -23,7 +23,8 @@ gravity: # Process manager to use. # ``supervisor`` is the default process manager when Gravity is invoked as a non-root user. # ``systemd`` is the default when Gravity is invoked as root. - # Valid options are: supervisor, systemd + # ``multiprocessing`` is the default when Gravity is invoked as the foreground shortcut ``galaxy`` instead of ``galaxyctl`` + # Valid options are: supervisor, systemd, multiprocessing # process_manager: # What command to write to the process manager configs @@ -1518,7 +1519,7 @@ galaxy: # The BibTeX citation for Galaxy, to be displayed in the History Tool # Reference List - #citation_bibtex: '@article{Galaxy2024, title={The Galaxy platform for accessible, reproducible, and collaborative data analyses: 2024 update}, author={{The Galaxy Community}}, journal={Nucleic Acids Research}, year={2024}, doi={10.1093/nar/gkae410}, url={https://doi.org/10.1093/nar/gkae410}}' + #citation_bibtex: '@article{Galaxy2024, title="The Galaxy platform for accessible, reproducible, and collaborative data analyses: 2024 update", author="{The Galaxy Community}", journal="Nucleic Acids Research", year="2024", doi="10.1093/nar/gkae410", url="https://doi.org/10.1093/nar/gkae410"}' # The URL linked by the "Galaxy Version" link in the "Help" menu. #release_doc_base_url: https://docs.galaxyproject.org/en/release_ From 49ddccee28f04fc5c2f048690292b81a70e3c868 Mon Sep 17 00:00:00 2001 From: Matthias Bernt Date: Wed, 14 Jan 2026 10:04:36 +0100 Subject: [PATCH 5/7] update docs --- doc/source/admin/galaxy_options.rst | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/doc/source/admin/galaxy_options.rst b/doc/source/admin/galaxy_options.rst index c2fb7e9baf3..90e7952c801 100644 --- a/doc/source/admin/galaxy_options.rst +++ b/doc/source/admin/galaxy_options.rst @@ -1126,9 +1126,9 @@ :Type: str -~~~~~~~~~~~~~~~~~~~~~~~~~~ +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ``enable_tool_generated_tours`` -~~~~~~~~~~~~~~~~~~~~~~~~~~ +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ :Description: Allow tools to show the option of and create interactive tours @@ -2466,7 +2466,7 @@ :Description: The BibTeX citation for Galaxy, to be displayed in the History Tool Reference List -:Default: ``@article{Galaxy2024, title={The Galaxy platform for accessible, reproducible, and collaborative data analyses: 2024 update}, author={{The Galaxy Community}}, journal={Nucleic Acids Research}, year={2024}, doi={10.1093/nar/gkae410}, url={https://doi.org/10.1093/nar/gkae410}}`` +:Default: ``@article{Galaxy2024, title="The Galaxy platform for accessible, reproducible, and collaborative data analyses: 2024 update", author="{The Galaxy Community}", journal="Nucleic Acids Research", year="2024", doi="10.1093/nar/gkae410", url="https://doi.org/10.1093/nar/gkae410"}`` :Type: str From 775ab8b152e1fcd1a5e6c18b23c15feddf052d77 Mon Sep 17 00:00:00 2001 From: guerler Date: Tue, 13 Jan 2026 19:03:35 +0300 Subject: [PATCH 6/7] Fix parsing user id to preferences --- client/src/components/User/UserPreferencesForm.vue | 8 +++----- client/src/entry/analysis/router.js | 5 ++++- 2 files changed, 7 insertions(+), 6 deletions(-) diff --git a/client/src/components/User/UserPreferencesForm.vue b/client/src/components/User/UserPreferencesForm.vue index ab511379f19..31a984660c9 100644 --- a/client/src/components/User/UserPreferencesForm.vue +++ b/client/src/components/User/UserPreferencesForm.vue @@ -2,7 +2,6 @@ import { BAlert } from "bootstrap-vue"; import { storeToRefs } from "pinia"; import { computed, ref, watchEffect } from "vue"; -import { useRouter } from "vue-router/composables"; import { isRegisteredUser } from "@/api"; import { @@ -18,6 +17,7 @@ import LoadingSpan from "@/components/LoadingSpan.vue"; interface Props { formId: UserPreferencesKey; + id?: string; } const props = defineProps(); @@ -29,13 +29,11 @@ const breadcrumbItems = computed(() => [{ title: "User Preferences", to: "/user" const userStore = useUserStore(); const { currentUser } = storeToRefs(userStore); -const router = useRouter(); - const loading = ref(true); const model = computed(() => { - if (router.currentRoute.params.id) { - return getUserPreferencesModel(router.currentRoute.params.id); + if (props.id) { + return getUserPreferencesModel(props.id); } else if (isRegisteredUser(currentUser.value)) { return getUserPreferencesModel(currentUser.value.id); } else { diff --git a/client/src/entry/analysis/router.js b/client/src/entry/analysis/router.js index 8c8311ea218..8ca8c5fafcd 100644 --- a/client/src/entry/analysis/router.js +++ b/client/src/entry/analysis/router.js @@ -642,7 +642,10 @@ export function getRouter(Galaxy) { { path: "user/:formId", component: UserPreferencesForm, - props: true, + props: (route) => ({ + formId: route.params.formId, + id: route.query.id, + }), redirect: redirectAnon(), }, { From 96aabd0277f59058b2b232adea0733ceb9225b4e Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Fri, 16 Jan 2026 01:10:43 +0000 Subject: [PATCH 7/7] Add belated deprecation of Python 3.9 support --- doc/source/releases/25.1_announce.rst | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/doc/source/releases/25.1_announce.rst b/doc/source/releases/25.1_announce.rst index a44c8211c12..f47ced5d59c 100644 --- a/doc/source/releases/25.1_announce.rst +++ b/doc/source/releases/25.1_announce.rst @@ -97,6 +97,13 @@ Deprecation Notices * `Galaxy Monitoring with Telegraf and Grafana `__ * `Galaxy Monitoring with gxadmin `__ +**Deprecation of Python 3.9 support in Galaxy release 26.0** + Since Python 3.9 reached its end-of-life in October 2025, support for it will + be removed in Galaxy 26.0. + Administrators should upgrade their Python environment to version 3.10 or + higher to avoid security vulnerabilities and ensure a smooth transition to + Galaxy 26.0 and beyond. + Release Team ===========================================================