IAM 8.7 - Changelog
Airlock IAM 8.7.0
The following tables show the changes from Airlock IAM 8.6 to 8.7.
Authentication | ||
|---|---|---|
New | AI-20070 | Latest usage of an Airlock 2FA device is tracked in the underlying service. This information is now used in Airlock IAM:
|
New | AI-21343 | The new Airlock 2FA Push Event Subscriber plugin sends custom notification messages to the Airlock 2FA app (or custom app using the Airlock 2FA SDK) whenever a subscribed IAM event occurs. The message texts can be configured, translated, and parameterized to contain event attributes as well as input from value providers. The new event subscriber is available for the Loginapp and the Adminapp. |
New | AI-21439 | The new Fallback Request Authentication plugin for REST request authentication supports combining multiple authentication methods. |
New | AI-22423 | The new HTTP Request Cookie Value Provider provides HTTP cookie values from the current HTTP request. |
Improvement | AI-21804 | Improved IAM's response to Cronto apps if a Cronto device does not exists in IAM. |
Improvement | AI-22304 | FIDO now supports native apps on iOS ( See also FIDO in native mobile apps. |
Improvement | AI-8559 | The OATH OTP Settings have been improved and now allow configuring custom patterns for customer-specific OATH labels. |
Bug | AI-22443 | Fixed an issue where FIDO authentication could trigger endless UI loops if FIDO is not supported by the browser. The FIDO fallback mechanism has been improved for these cases. |
Bug | AI-22480 | Fixed an issue where Cronto push failed when using a proxy. Proxy support for Cronto push is now available again. |
Loginapp | ||
|---|---|---|
New | AI-15553 | The new flow step Delete All Device Tokens Step deletes all device tokens for the current user. This may be useful, for example, after changing the password. |
Improvement | AI-22608 | The Loginapp UI Design Kit now uses |
Improvement | AI-22496 | Browser language auto-detection in the Loginapp has been improved. When language-country combinations such as |
Improvement | AI-21627 | In the target application configuration, the Allowed URI Patterns property of the Query Parameter URI Value Extraction plugin no longer accepts an empty list. The Query Parameter URI Transformation plugin now provides the same property with the same behavior. Ensure that the URI patterns configured in this property are valid, correct, and sufficiently restrictive. Lax regular expressions, such as |
Bug | AI-21496 | Fixed a bug where the OpenApi Loginapp specification included unnecessary response status codes from OPTIONS/preflight endpoints. These response status codes have been removed. |
Bug | AI-22136 | Fixed an issue where date input in the Loginapp could be shifted by one day depending on the browser timezone. The Loginapp now handles date-only values correctly regardless of the browser timezone. |
Bug | AI-22290 | Fixed an issue where REST requests requiring authentication were artificially delayed even if no credentials were present. Such requests no longer trigger a response delay. |
Bug | AI- | Fixed a bug where the device token list in the Loginapp's protected self-services did not return the user's devices after logging in with a username alias, such as an email address. |
Bug | AI-22504 | Fixed an issue where the password visibility toggle in the Loginapp was incorrectly positioned in the title bar. The toggle is now displayed in the correct position and is WCAG-compliant. This change only affects customers who have enabled the toggle, which is disabled by default. Customers who previously applied custom styling to work around this issue should review their styling, as this change may be breaking. |
Bug | AI-22545 | Fixes a bug in the Loginapp Design Kit in which actions were executed in the wrong directory. On some operating systems, this could lead to execution failures for |
OAuth / OIDC / SAML | ||
|---|---|---|
New | AI-21267 | The new OAuth 2.0/OIDC Authorization Request Parameter Value Provider is able to provide most values from an OAuth 2.0/OIDC authorization request. The OAuth 2.0/OIDC remote consent can now forward request parameters from the authorization request to support bLink-compliant consent Management. |
Improvement | AI-22376 AI 22499 | OAuth 2.0 Token Exchange tokens now always contain a random |
Improvement | AI-22471 | IAM's OAuth2/OIDC Discovery/JWKS clients now refresh their caches asynchronously, eliminating the lag on refresh. |
Improvement | AI-22680 | Improved performance in OAuth 2.0 setups with many static clients. |
Bug | AI-22668 | Endpoints below |
Bug | AI-21429 | Fixed a bug in OAuth2/OIDC, where context data set in a non-interactive step immediately before flow termination, for example in a Set Context Data Step, was not propagated. Such context data is now propagated correctly. |
Bug | AI-22592 | Fixed temporary connection leaks in SAML 2.0 Artifact Resolution on both SP and IdP sides. |
Bug | AI- | Fixed a bug where the OAuth2 self-service did not display the session date correctly if its milliseconds fraction was exactly zero. |
Bug | AI-22758 | Fixed a race condition where parallel usage of OAuth 2.0 tokens resulted in a 500 error. |
Adminapp and Config Editor | ||
|---|---|---|
New | AI-22012 | Separate users and delegate administrative rights with a much improved realm administration feature. User management permissions can be delegated selectively without granting unrestricted access to all admins. See also Realm-based access control and administration. The “old” realm administration feature is still available as “simple realm administration”. |
New | AI-13406 | The advanced user search in the user management (Adminapp) can now find users by the mobile phone numbers of their mTAN tokens. To enable this new feature, add the new plugin mTAN Token User Search Filter to the advanced search filters of the user management The new search filter is also available through the Adminapp REST API as the |
New | AI-14063 | The Adminapp can now display and edit integer user context data items with the new Integer User Profile Item plugin. It validates input as integer values and optionally supports uniqueness checks. The new plugin can be configured as modifiable, optional, and sortable. |
New | AI-21940 | The Activities tab on the User Details page in the user management (Adminapp) now provides a search feature. Additionally, every successful user identification now writes a user trail entry containing the flow ID (target application) and the browser/user agent, making these searches meaningful for tracing logins per application. |
Bug | AI-22293 | Fixed an issue where a session was not properly terminated when an admin with a valid account but no permissions logged in to the Adminapp, preventing a subsequent login with another account. The previous session is now properly terminated. |
Bug | AI-22412 | Fixed an issue where configuration activation could fail because IAM incorrectly counted the |
Bug | AI-22431 | Fixed the wrong country code for the Faroe Islands. We also updated some outdated country names in the default Adminapp translations. |
Bug | AI-22561 | Fixed a bug where entering a date in the Latest Successful Login Date Range Filter or the Latest Login Attempt Date Range Filter in the Adminapp 's Advanced Search UI caused an error. The filters now work again as expected. |
Bug | AI-22629 | Fixed an issue where untranslatable keys were displayed incorrectly in the Adminapp when they accidentally matched a node in the translation files. Such keys are now displayed as raw keys again. |
Bug | AI-22774 | Fixed a bug where custom Loginapp or Adminapp texts were displayed as raw translation keys after a page reload if no translation was available in the active language. Such texts now correctly fall back to the configured default language. |
Bug | AI-22686 | Fixed a bug where external secrets in snippets were not resolved correctly when imported in the Config Editor. Snippets containing external secrets can now be imported correctly. |
Miscellaneous | ||
|---|---|---|
New | AI-22617 | The correlation ID is now also forwarded to remote event subscribers. |
New | AI-22118 | Added a Device Usage Consistency User Change Listener to keep device usage data synchronized when users are renamed or deleted. |
New | AI-8643 | Maintenance message translations can now be used with country-specific language codes, such as |
New | AI-22409 | Terms of service translations can now be used with country-specific language codes, such as |
New | AI-21793 AI-22283 | Added support for Gateway 8.6 Support for Gateway 8.3 has been removed. |
New | AI-22316 | Added support for Microgateway 5.1 and Microgateway 4.8. Note that starting with Microgateway 5.0, Microgateway supports only Gateway API. Sidecar mode is no longer supported. |
Improvement | AI-21781 | Replaced the inefficient index |
Improvement | AI-21984 | Updated Java, Guava, Tomcat, Bouncy Castle, Spring Boot, and Netty libraries to the latest revisions. Updated the Yubico library. |
Improvement | AI-22419 | The minimum supported DB versions are now:
See also System requirements. |
Improvement | AI-16613 | Legacy Remember-Me cookies from the JSP Loginapp (set in IAMs <8.0) are no longer supported. The corresponding configuration properties are automatically removed in the config migration process. |
Bug | AI-22130 | Fixed an issue concerning the size of the external transaction-approval OpenAPI specification file. The size of this spec file has been reduced. |
Bug | AI-22233 | Fixed a bug in the OpenAPI specification and REST documentation where query parameters are now on path level instead of per method. |
Bug | AI-22259 | Fixed an issue where Event Subscribers were mandatory when using the event outbox. Event Subscribers are now optional when using the “Reliable event delivery” feature. |
Bug | AI-22284 | Fixed a bug in which the license manager was instantiated multiple times when querying Prometheus license metrics. This resulted in multiplied log messages and a potential performance impact for the metrics endpoint. |
Bug | AI-22611 | Fixed some wrong queries when using |
Bug | AI-22657 | Fixed a bug where static roles configured with |
Bug | AI-22748 | Fixed a bug in the REDIS integration's Lua scripts that could affect state repository locking. The state repository is now more robust, and session expiration during requests is handled gracefully. |
Bug | 22795 | Fixed a rare race condition that could cause a deadlock when the database layer was initialized by two concurrent requests. |
Bug | AI-20123 | Fixed a minor issue in JSON REST responses where the source pointer |
Bug | AI-19324 | Removed a workaround for a bug in the IAM Gateway 8.3 OpenAPI spec. Gateway 8.3 support has expired and is therefore no longer supported by IAM. |