IAM 8.7 - Required upgrade actions

Various

IAM Module

Affected Feature(s)
(Relevant if using ...)

Issue(s)

Required Action

Version

All

DB/OS

AI-22419

Check the current operating system and database version requirements and deprecations: System requirements.

8.7

All

Gateway 8.3 or older

AI-22283

Upgrade to Airlock Gateway 8.4 or later if you are still on Gateway 8.3. IAM 8.7 (and newer) is no longer compatible with Gateway 8.3.

8.7

All

REDIS session store with export mode configuration

AI-22401

If using REDIS as a session store in conjunction with the Expert Mode Redis State Repository plugin, verify that your configuration is still working with the updated Redisson library (version 4.6.1).

In particular, the retryInterval property is no longer supported. See https://github.com/redisson/redisson/blob/master/docs/configuration.md for details.

Adminapp

User search based on token data
(new feature)

AI-13406

A new Adminapp feature allows searching users based on token information (e.g., by mobile phone number).

If you use this feature, it is strongly recommended that you update the database schema to 8.7. In particular, apply the new index on the token_data column in the token table.

See Relational databases for IAM for details on the schema upgrade.

8.7

Loginapp
Adminapp

Language Settings

AI-8643

Ensure that only language values of length 2 (“en”) or 5 (“en_US”) are configured in the language settings of the Adminapp, the Loginapp, for maintenance messages and terms of service features.

The config validation is now stricter. In older releases, language values like “en_US_something” were considered valid (but resulted in runtime issues).

8.7

Loginapp

Device usage features

AI-22118

If using device-usage based features (e.g. conditions in flows), it is strongly recommended to configure the new plugin Device Usage Consistency Change Listener in the Database User Persister's user change event listeners.

It ensures that device usage data is deleted when deleting a user account and that username changes are handled correctly.

8.7

Loginapp Design Kit

Password Visibility Toggle

AI-22504

The password visibility toggle was wrongly placed (and therefore not WCAG compliant). This has been fixed.

If you had the password visibility toggle enabled and fixed the position in your UI customizing code, you may need to adapt that code.

8.7

Config API Changes

With the config automation features introduced in IAM 8.4, a part of the configuration becomes an API with limited guarantees. For details, see Config automation.

The following table documents changes to the config API that may require manual adaptations in scripts manipulating the YAML configuration.

  • IAM config migration will automatically apply changes to config files and snippets.
  • Modifications in snippets may have to be adapted manually.
  • Note that the plugin type and the property names in the first two columns refer to the config API of the previous release, i.e., before migrating to this release.

Plugin type and properties (old)

Description of change

Plugins: ExpertModeRedisStateRepository, SingleModeRedisStateRepository

Property: legacyKeyFormat

The property is no longer supported and can be removed.

Plugin: JspRememberMe

The plugin is no longer supported and must be removed from configs.

Plugin: RememberMeResetStep

Property: jspCredentialPersister

The property is no longer supported and must be removed.

Plugin: RememberMeUserIdentifyingStep

Property: migrateJspRememberMeCookies

The property is no longer supported and can be removed.

Plugin: UsersConfiguration

Property: jspLoginappRememberMeSettings

The property is no longer supported and must be removed.

Plugin: OathOtpSettings

Properties: orgLabelContextProperty, orgLabelDefault

The properties have been replaced by the following new properties. See plugin documentation for details.

  • defaultIssuer
  • includeIssuerInParameters
  • issuerContextDataProperty
  • labelPattern

Plugin: RoleBasedAccessController

The plugin is no longer supported and must be removed (and unconnected if connected).

Plugin: UsernameUserProfileItem

The plugin is no longer supported and must be removed (and unconnected if connected).

Further information and links