Release 2.5.26
Issues fixed
Items open correctly from the object pop-up
Previously, opening an item in full view from the object pop-up showed an error instead of the item.
The item now opens as expected. If the pop-up shows an older version of the item, that is the version you see.
Security fixes for access control in the Portal
This release fixes several security issues in the Portal:
- Project access: users could see items from projects they were not members of.
- User administration: a Manager could change or remove an Administrator.
- Signing in: some parts of the Portal answered without signing in.
- Sensitive information: database connection details and download links could be read by users who should not see them.
All of these are now closed. Debugging and deploying from Visual Studio now requires the Operator or Administrator role. If you have built your own Portal extensions, read the deployment notes before upgrading.
Setup uses the configured SQL Server connection options in every step
Previously, the Setup job could fail with "The target principal name is incorrect" when the SQL data source name configured for the server did not match the name on the SQL Server certificate, even though all other jobs connected without problems. One step of Setup ignored the connection options configured in the Portal, such as TrustServerCertificate. Setup now uses the configured connection options throughout.