Skip to main content

Version 1.18.1.5

Release Date: September 7, 2026 Release Type: Stable Previously published as: 1.18.10 (image tag staging-1.18.10)

Installation-level control over unauthenticated inbound access, a delete-only mode and an attempt history for sync jobs, connector step codes in flow references, alert mail that keeps working during a database outage, and AWS S3, password-reset and System Logs fixes.

Backend Server​

New Features​

  • The installation decides whether unauthenticated inbound access is honoured: A flow could switch off its own inbound authentication — REST and SOAP by listing NONE among their authentication types, AS2 through its optional-authentication setting — and every installation obeyed. Whether anonymous callers are accepted is now a deployment setting, app.security.inbound.allow-no-authentication, which is off by default. While it is off, a flow that asks for no authentication still requires a credential, including flows that were imported or saved earlier, and each refusal is logged as a warning with its own message code (MIP-AUTH-W-0004, MIP-AS2-W-0415).
  • Flow references name the connector step: The flow reference written on log lines gains a fourth segment, the connector step code (flowId/messageId/nodeId/stepCode@step), so a log line can be matched directly to the connector log entry of the step it was written under. Lines written outside a connector step carry a dash in that position.

Bug Fixes​

  • Alert mail is still sent while the database is unreachable: Sending an alert requires reading the SMTP configuration from PostgreSQL. During a database outage that read came back empty and was treated as "SMTP is not configured", so instant alerts were dropped and digest alerts used up their retries. The backend now keeps the last mail configuration and SMTP credential it read and falls back to them during an outage, logging how old the values are. The live database always wins while it is reachable, and a configuration that was deliberately deleted is not revived.
  • AWS S3 uploads with an object key work in synchronous flows: Uploads from a flow triggered by a synchronous request failed with "AWS S3 Key header missing" because the object key was lost before the upload; the storage class and content encoding settings were lost the same way without any error. All three now reach the upload. A blank object key now fails with an error that names the node and the bucket.
  • Log lines written outside a flow no longer show an empty correlation: Lines logged outside any flow could carry a flow reference made only of dashes, which the System Logs viewer displayed as if it were an identifier. Such lines now carry no correlation at all.

Frontend Server​

New Features​

  • The designer is told whether unauthenticated inbound access is offered: The server reads the same deployment setting the backend enforces (INBOUND_ALLOW_NO_AUTH, off by default) and reports it to the web application, so the designer and the runtime follow one value instead of two separately maintained ones.
  • Sync jobs can delete a time window without syncing it: A new mode deletes the selected time window from the source store and transfers nothing, for records that are not worth keeping. A request that asks for both delete-after-sync and delete-without-sync is rejected as a bad request.
  • Step code in flow references: The server uses the same four-segment flow reference as the backend. References in the older three-segment form, for example pasted from older log files, are still resolved.

Bug Fixes​

  • Password-reset links point to the web application's configured address: The link mailed to a user who requests a password reset was built from the backend host and a fixed port, so installations that serve the web application on another host, port or ingress sent links that did not open the reset form. The link is now built from the web application's public address in the endpoint configuration.
  • AI monitoring error report no longer splits one failure into several groups: A flow whose failures were classified under more than one error type was reported as separate groups with the count divided between them. Failures are now grouped by flow, status code and error message, the counts are summed, and each recorded error type is listed in the group's details.

Frontend Web​

New Features​

  • No-authentication options are offered only where the installation allows them: The NONE authentication type on inbound REST and SOAP connectors and the "No Authentication" checkbox on AS2 are shown only when the installation enables unauthenticated inbound access. A flow that already uses the option keeps showing it, so saving the flow does not change its security setting unnoticed.
  • Delete without syncing on the Start Sync dialog: A new checkbox deletes the selected tables for the selected time frame and transfers nothing. The delete-after-sync option is disabled in this mode, Direction stays editable because it selects the store the records are deleted from, and the confirm button reads "Delete Records".
  • Sync attempt history for outages: The resync chip on an outage opens a dialog listing every sync recorded against that outage with its trigger and outcome, so a repair that was cancelled and started again reads as two attempts.
  • System Logs viewer leads with Correlation and Message: The Correlation and Message columns move to the front of the table, and a long message can be expanded with a click instead of being cut to one line. The remaining columns keep their order.
  • Step code in flow references: The web application recognises the four-segment flow reference, including the connector step code.

Bug Fixes​

  • Resync chip shows the real outcome of the linked sync: The chip displayed every linked but unconfirmed job as "Sync running", including cancelled jobs and jobs that no longer exist. It now reflects the outcome of the linked job.
  • AI report Error Type for groups with several error types: A group that recorded more than one error type is no longer displayed as if no error type had been recorded.

Health Check​

New Features​

  • Health alerts use the mail server configured in the alert mail settings: Health Check sent its alerts through the mail server fixed at deployment, so changing the SMTP server in the alert mail settings affected flow alerts but not health alerts. The mail server is now read from the alert mail configuration on each send; when no configuration exists the deployment settings are used, and during a database outage the last known server is used. The sending account still comes from the deployment settings.
  • Sync attempts are recorded against each outage: Every sync job linked to an outage is recorded with its status, which is refreshed as the job progresses, including for outages that were linked before this release. This backs the attempt history shown in the web application.

Bug Fixes​

  • Down alerts are still evaluated during a database outage: Alert thresholds were read from the database on every check, so while the database was unreachable the alert could not be composed and the check itself failed. The last thresholds read are now kept and used when a later read fails.

1.18.1.5 is a stable release. Previous: 1.18.1.4