IAM 8.7 - Changelog

Airlock IAM 8.7.0

The following tables show the changes from Airlock IAM 8.6 to 8.7.

Authentication

New

AI-20070
AI-20487
 

Latest usage of an Airlock 2FA device is tracked in the underlying service. This information is now used in Airlock IAM:

  • Display last usage to the help desk in the user management (Adminapp) and its REST API.
  • Display last usage to the end user in the device management self-service.
  • The new plugin Airlock 2FA Device Cleanup Task can periodically delete Airlock 2FA devices that are no longer or rarely used. See Cleanup of unused Airlock 2FA devices.

New

AI-21343

The new Airlock 2FA Push Event Subscriber plugin sends custom notification messages to the Airlock 2FA app (or custom app using the Airlock 2FA SDK) whenever a subscribed IAM event occurs. The message texts can be configured, translated, and parameterized to contain event attributes as well as input from value providers.

The new event subscriber is available for the Loginapp and the Adminapp.

See Airlock 2FA Push Event Subscriber.

New

AI-21439

The new Fallback Request Authentication plugin for REST request authentication supports combining multiple authentication methods.

New

AI-22423

The new HTTP Request Cookie Value Provider provides HTTP cookie values from the current HTTP request.

Improvement

AI-21804

Improved IAM's response to Cronto apps if a Cronto device does not exists in IAM.

Improvement

AI-22304

FIDO now supports native apps on iOS (apple-app-site-association) and Android (assetlinks.json).

See also FIDO in native mobile apps.

Improvement

AI-8559

The OATH OTP Settings have been improved and now allow configuring custom patterns for customer-specific OATH labels.

Bug

AI-22443

Fixed an issue where FIDO authentication could trigger endless UI loops if FIDO is not supported by the browser. The FIDO fallback mechanism has been improved for these cases.

Bug

AI-22480

Fixed an issue where Cronto push failed when using a proxy. Proxy support for Cronto push is now available again.

Loginapp

New

AI-15553

The new flow step Delete All Device Tokens Step deletes all device tokens for the current user. This may be useful, for example, after changing the password.

Improvement

AI-22608

The Loginapp UI Design Kit now uses pnpm 11. If you want to use an older pnpm version, regenerate the pnpm-lock.yaml file.

Improvement

AI-22496

Browser language auto-detection in the Loginapp has been improved. When language-country combinations such as de_CH or zh_CN are configured, IAM can now automatically select them based on the browser's language preferences. If no exact match is available, language selection fallback follows RFC 4647.

Improvement

AI-21627

In the target application configuration, the Allowed URI Patterns property of the Query Parameter URI Value Extraction plugin no longer accepts an empty list.

The Query Parameter URI Transformation plugin now provides the same property with the same behavior.

Ensure that the URI patterns configured in this property are valid, correct, and sufficiently restrictive. Lax regular expressions, such as .*, may lead to open redirect attacks.

Bug

AI-21496

Fixed a bug where the OpenApi Loginapp specification included unnecessary response status codes from OPTIONS/preflight endpoints. These response status codes have been removed.

Bug

AI-22136

Fixed an issue where date input in the Loginapp could be shifted by one day depending on the browser timezone. The Loginapp now handles date-only values correctly regardless of the browser timezone.

Bug

AI-22290

Fixed an issue where REST requests requiring authentication were artificially delayed even if no credentials were present. Such requests no longer trigger a response delay.

Bug

AI-

Fixed a bug where the device token list in the Loginapp's protected self-services did not return the user's devices after logging in with a username alias, such as an email address.

Bug

AI-22504

Fixed an issue where the password visibility toggle in the Loginapp was incorrectly positioned in the title bar. The toggle is now displayed in the correct position and is WCAG-compliant.

This change only affects customers who have enabled the toggle, which is disabled by default.

Customers who previously applied custom styling to work around this issue should review their styling, as this change may be breaking.

Bug

AI-22545

Fixes a bug in the Loginapp Design Kit in which actions were executed in the wrong directory. On some operating systems, this could lead to execution failures for dev or build.

OAuth / OIDC / SAML

New

AI-21267

The new OAuth 2.0/OIDC Authorization Request Parameter Value Provider is able to provide most values from an OAuth 2.0/OIDC authorization request.

The OAuth 2.0/OIDC remote consent can now forward request parameters from the authorization request to support bLink-compliant consent Management.

Improvement

AI-22376

AI 22499

OAuth 2.0 Token Exchange tokens now always contain a random jti claim.

Improvement

AI-22471

IAM's OAuth2/OIDC Discovery/JWKS clients now refresh their caches asynchronously, eliminating the lag on refresh.

Improvement

AI-22680

Improved performance in OAuth 2.0 setups with many static clients.

Bug

AI-22668

Endpoints below /oauth2/v3/ now return 40x (instead of 500) in the case of client-side errors, such as a wrong method or wrong accept headers.

Bug

AI-21429

Fixed a bug in OAuth2/OIDC, where context data set in a non-interactive step immediately before flow termination, for example in a Set Context Data Step, was not propagated. Such context data is now propagated correctly.

Bug

AI-22592

Fixed temporary connection leaks in SAML 2.0 Artifact Resolution on both SP and IdP sides.

Bug

AI-

Fixed a bug where the OAuth2 self-service did not display the session date correctly if its milliseconds fraction was exactly zero.

Bug

AI-22758

Fixed a race condition where parallel usage of OAuth 2.0 tokens resulted in a 500 error.

Adminapp and Config Editor

New

AI-22012

Separate users and delegate administrative rights with a much improved realm administration feature. User management permissions can be delegated selectively without granting unrestricted access to all admins.

See also Realm-based access control and administration.

The “old” realm administration feature is still available as “simple realm administration”.

New

AI-13406

The advanced user search in the user management (Adminapp) can now find users by the mobile phone numbers of their mTAN tokens.

To enable this new feature, add the new plugin mTAN Token User Search Filter to the advanced search filters of the user management

The new search filter is also available through the Adminapp REST API as the mtan-phone-number filter on the users endpoint.

New

AI-14063

The Adminapp can now display and edit integer user context data items with the new Integer User Profile Item plugin. It validates input as integer values and optionally supports uniqueness checks.

The new plugin can be configured as modifiable, optional, and sortable.

New

AI-21940

The Activities tab on the User Details page in the user management (Adminapp) now provides a search feature.

Additionally, every successful user identification now writes a user trail entry containing the flow ID (target application) and the browser/user agent, making these searches meaningful for tracing logins per application.

Bug

AI-22293

Fixed an issue where a session was not properly terminated when an admin with a valid account but no permissions logged in to the Adminapp, preventing a subsequent login with another account. The previous session is now properly terminated.

Bug

AI-22412

Fixed an issue where configuration activation could fail because IAM incorrectly counted the lost+found directory as an instance. IAM now ignores the lost+found directory during the license check.

Bug

AI-22431

Fixed the wrong country code for the Faroe Islands. We also updated some outdated country names in the default Adminapp translations.

Bug

AI-22561

Fixed a bug where entering a date in the Latest Successful Login Date Range Filter or the Latest Login Attempt Date Range Filter in the Adminapp 's Advanced Search UI caused an error. The filters now work again as expected.

Bug

AI-22629

Fixed an issue where untranslatable keys were displayed incorrectly in the Adminapp when they accidentally matched a node in the translation files.

Such keys are now displayed as raw keys again.

Bug

AI-22774

Fixed a bug where custom Loginapp or Adminapp texts were displayed as raw translation keys after a page reload if no translation was available in the active language. Such texts now correctly fall back to the configured default language.

Bug

AI-22686

Fixed a bug where external secrets in snippets were not resolved correctly when imported in the Config Editor. Snippets containing external secrets can now be imported correctly.

Miscellaneous

New

AI-22617

The correlation ID is now also forwarded to remote event subscribers.

New

AI-22118

Added a Device Usage Consistency User Change Listener to keep device usage data synchronized when users are renamed or deleted.

New

AI-8643

Maintenance message translations can now be used with country-specific language codes, such as de_CH.

New

AI-22409

Terms of service translations can now be used with country-specific language codes, such as de_CH.

New

AI-21793

AI-22283

Added support for Gateway 8.6

Support for Gateway 8.3 has been removed.

New

AI-22316

Added support for Microgateway 5.1 and Microgateway 4.8.

Note that starting with Microgateway 5.0, Microgateway supports only Gateway API. Sidecar mode is no longer supported.

Improvement

AI-21781

Replaced the inefficient index token_type_index on TOKEN(type) with an index better suited for cleanup of expired tokens using TOKEN (type,validity_range_upper).

Improvement

AI-21984
AI-22666

Updated Java, Guava, Tomcat, Bouncy Castle, Spring Boot, and Netty libraries to the latest revisions. Updated the Yubico library.

Improvement

AI-22419

The minimum supported DB versions are now:

  • H2: 2.1.214
  • MariaDB: 10.6
  • MySQL: 8.0
  • SQL Server: 2017
  • PostgreSQL: 14
  • Oracle: 19.3

See also System requirements.

Improvement

AI-16613

Legacy Remember-Me cookies from the JSP Loginapp (set in IAMs <8.0) are no longer supported. The corresponding configuration properties are automatically removed in the config migration process.

Bug

AI-22130

Fixed an issue concerning the size of the external transaction-approval OpenAPI specification file. The size of this spec file has been reduced.

Bug

AI-22233

Fixed a bug in the OpenAPI specification and REST documentation where query parameters are now on path level instead of per method.

Bug

AI-22259

Fixed an issue where Event Subscribers were mandatory when using the event outbox. Event Subscribers are now optional when using the “Reliable event delivery” feature.

Bug

AI-22284

Fixed a bug in which the license manager was instantiated multiple times when querying Prometheus license metrics. This resulted in multiplied log messages and a potential performance impact for the metrics endpoint.

Bug

AI-22611

Fixed some wrong queries when using Iterator Query or User Name ResolveQuery in the Database User Persister.

Bug

AI-22657

Fixed a bug where static roles configured with Grant Roles in the Database User Persister were persisted when other roles of the same user were modified. Static roles are now kept in memory only, while already persisted static roles remain unchanged.

Bug

AI-22748

Fixed a bug in the REDIS integration's Lua scripts that could affect state repository locking. The state repository is now more robust, and session expiration during requests is handled gracefully.

Bug

22795

Fixed a rare race condition that could cause a deadlock when the database layer was initialized by two concurrent requests.

Bug

AI-20123

Fixed a minor issue in JSON REST responses where the source pointer / was incorrectly included in validation errors, which did not conform to the JSON standard. Validation errors for query parameters now use parameter to indicate which query parameter failed validation.

Bug

AI-19324

Removed a workaround for a bug in the IAM Gateway 8.3 OpenAPI spec. Gateway 8.3 support has expired and is therefore no longer supported by IAM.