Skip to main content

17.3.0

Key Updates & Fixes:

  • Added:

    • Enumaretion protection
    • Optin users strict option
    • Forced users support
    • Optout users support
    • Customize WebAuthn options
    • Custom pre/post blocks
    • Custom roles synchronization
    • OIDC support in the IDP app
    • 5MB limit for buffering and replacing
    • Ghost system integration
    • Extended internalauth customization (images and colors per language)
    • UI: User status update functionality with i18n support
    • UI: WebAuthn support in OIDC app management with improved UI elements
    • UI: Recovery payload validation and notifications for missing channels
    • UI: Recovery channel notifications with configuration links
    • UI: UserStatusToggle for user suspension and reactivation
  • Changed:

    • Split_all architecture release (foundational infrastructure change)
    • Users report updated with FACTOR_FIRST_ADDED_AT column
  • Fixed:

    • LDAP check for blocked users
    • Microauth URI validator
    • Microauth paths handling
    • LDAP users sync now finds users recursively
    • Updated default Yubico CA certificates
    • Fixed error log configuration in NGINX proxy settings
    • Tuned email/SMS bgproc test jobs for better error detection
    • SMS/email proxy now uses system certificates
    • Nginx exceptions
    • UI: Prevented auto-logout on 502 errors from IDP endpoints
    • UI: Reset test connection state before initiating tests in multiple components

The 17.x series represents a major evolution of the platform. It introduces the split_all architecture as a foundational change, and builds on it with a broad set of new capabilities: enumeration protection, strict opt-in and opt-out user flows, forced user support, customizable WebAuthn options, custom pre/post request blocks, custom role synchronization, OIDC support in the IDP app, Ghost system integration, and extended internalauth per-language customization for images and colors. UI improvements add user status management with suspend/reactivate controls, enhanced OIDC app management, and improved recovery channel notifications. Stability fixes address LDAP user detection and sync, microauth validation, certificate handling, NGINX configuration, and proxy logging.