CSSCurrent en:Version 7.0.0
Release Date: 13.02.2024
Important Update Notes
Language Packages
In case your language packages have been modified, the attached delta-file delta_english_lp_6.1.0_to_6.2.0.txt can help you to locate the changes in this update and re-apply the modifications. The structure of this file is explained in Language Pack Changes.
- Flexible Update Paths: Direct updates to the most current version are possible, regardless of the currently installed version. Conditional Manual Updates: For versions that require manual intervention, the update process halts, ensuring all necessary configurations are properly handled.
- Rollback on Failure: Automated rollbacks preserve system integrity if an update fails at any step.
- Smart Update Checks: The system displays the most advanced version that can be installed unattended.
Enhanced Automatic Update Features
- Update Warnings for Manual Steps: Alerts users when the latest version cannot be updated automatically due to required manual steps.
- Alternative Version Notification: If a lower version is available for automatic update, this will be mentioned in the warning.
- Optimized Unattended Installation: The system automatically selects the highest version available for unattended updates.
- Admin Notifications: Emails notify administrators of available updates, differentiating between manual and automatic options.
Advanced Post-Update Automation
- Non-Interactive Post-Update Steps: If no administrator action is required, post-update steps run automatically and non-interactively.
- Automatic Return to Operation: After an update, the Cryptshare Server automatically returns to a usable state.
- Critical Failure Handling: In case of critical failures during post-update steps, an automatic rollback to the previous state is triggered.
- Non-Critical Failure Notifications: Non-critical failures are displayed on the "Status" page, visible only to users with "Administrator" or "Config Admin" roles. These messages remain until confirmed by one of these users.
- Update Success Notification: After a successful update, a success message and a link to the release notes are displayed on the "Status" page.
- Backup Restoration Option: Information about the possibility to restore the pre-update backup is mentioned post-update.
Enhanced Transfer Policy Configuration through csv
Administrators can now fully configure transfer policies by importing a CSV file. With this update, every configuration input available through the admin web application's wizard can also be set via CSV import. This enhancement provides a comprehensive and efficient method for managing transfer policy settings, ensuring greater flexibility and control.
Improved Password Generation Validation
We have resolved an issue where generated passwords could inadvertently trigger dictionary word filters, leading to their rejection. To address this, we have implemented a dictionary check for all generated passwords. This ensures that passwords containing common words are identified as invalid before they are used. As a result, transfers cannot proceed with an invalid password, enhancing security and compliance.
Legacy Archiving Update
Legacy archiving functionality, which has been prone to issues and is no longer maintained, has undergone significant changes:
- Feature Flag Introduction: A new feature flag has been introduced in the properties settings to control the enabling of legacy archiving.
- Admin Interface Visibility: Legacy archiving options are now only displayed in the Admin Interface if the feature is actively enabled.
- Default Setting: The feature flag for legacy archiving is disabled by default, reflecting our move towards file based archiving solutions.
- Post-Update Notification: If legacy archiving is configured, information will be displayed on the Post-Update screen. This includes a link to documentation for Local File Archiving, guiding administrators on transitioning to newer, supported archiving methods.
5. Additional chages
----
ipv6 and ipv4 can set CSS-13131
JRE update for permissions -CSS-13970
Fixed CSS-14229
Fixed update check issue -CSS-14307
Rest api changes to include - CSS-14340
Long file names are within box- CSS-14342
Xss- vulnerability fixes CSS-14371/CSS-14530
JRE/Spring library updates - CSS-14447 / CSS-14445
Broken custom links fix - CSS-14526
Accessibility (WCAG 2.1 Conformance Level AA) of the Web App improved
- The Cryptshare Web App now fulfils the WCAG 2.1 (Web Content Accessibility Guidelines) in conformance level AA by default.
- The contrast of the standard colours of a new installation has been improved.
- Long texts such as file names are now displayed in full.
Please note that custom changes to the advanced CSS or the choice of low-contrast colours (e.g. white text on a light blue button) can have a negative impact on accessibility.
Changes of CSS Selectors
In this version, some HTML structures have been revised due to the changes for accessibility. This can lead to incompatibilities in the case of individually implemented adjustments using the "advanced CSS" functionality. Before updating, please check in the menu item Customization-> Web Application Designer -> Advanced whether advanced CSS has been stored and check after the update whether all individually implemented adjustments are still effective.
Additional Changes
- The creation of the automatically generated Open API documentation of the REST API has been adjusted.
- The calculation of values on the statistics page has been accelerated.
- The time required for the Cryptshare server to shut down has been reduced.
- The Cryptshare product logo has been updated.
- The Java runtime environment has been updated to version 17.0.10.
- Several included third-party components have been updated.