Release 2.6.13
Issues fixed
Items open correctly from the object pop-up
Previously, opening an item in full view from the object pop-up showed an error instead of the item.
The item now opens as expected. If the pop-up shows an older version of the item, that is the version you see.
Security fixes for access control in the Portal
This release fixes several security issues in the Portal:
- Project access: users could see items from projects they were not members of.
- User administration: a Manager could change or remove an Administrator.
- Signing in: some parts of the Portal answered without signing in.
- Sensitive information: database connection details and download links could be read by users who should not see them.
All of these are now closed. Debugging and deploying from Visual Studio now requires the Operator or Administrator role. If you have built your own Portal extensions, read the deployment notes before upgrading.
Source files are always picked up from the track folder (ticket: 4651)
Previously, files copied into a track’s source folders were not always registered, so they could be missing from the Data page or skipped by load jobs. The Data page and table load jobs now check those folders directly every time they run. There is nothing to configure.
After the upgrade, the first refresh of the Data page updates file dates to the real file timestamps, so a few already loaded files may show as newer than their load until they are loaded again.
Jobs continue to start after earlier jobs fail
Previously, failed jobs during a database interruption could leave later jobs Pending until the track was restarted. Failed jobs now release their execution slots so later jobs can start.
Automation engine deploys reach every subscribed track
Previously, deploying a target engine with the PowerShell automation module left tracks subscribed to the newest revision on the previous active revision. These tracks now pick up target engine deployments as well as source engine deployments.
Setup uses the configured SQL Server connection options in every step
Previously, the Setup job could fail with "The target principal name is incorrect" when the SQL data source name configured for the server did not match the name on the SQL Server certificate, even though all other jobs connected without problems. One step of Setup ignored the connection options configured in the Portal, such as TrustServerCertificate. Setup now uses the configured connection options throughout.
Export no longer fails when a key insert is chosen as a deadlock victim
Previously, an export could stop with SQL error 9815, "Waitfor delay and waitfor time cannot be of type time", when the database chose the insert of a business key as the victim of a deadlock. The retry meant to handle the deadlock failed itself. In rarer cases the retry continued with a key that had been rolled back, or gave a duplicate item the key of the original item instead of its own.
The retry now waits and inserts the key again as intended, and each key the export uses exists in the database.
Note that the fix is in the migration database and takes effect only after the database migration of this release has been run on every migration database.
Tracks start when the engine assembly name contains a space
Previously, a track whose deployed engine had a space in its assembly name failed to start with a file-not-found error. Engine assembly names and cache paths containing spaces now work.
Workaround on earlier versions: give the engine project an assembly name without spaces and redeploy the engine.