Version 1.18.2.13
Release Date: September 22, 2026
Release Type: Stable
Previously published as: 1.18.29 (image tag staging-1.18.29)
REST and SOAP Start nodes can now keep the caller's Authorization header so that a flow can pass it on.
Backend Server
New Features
- Keep Authorization Header on REST and SOAP Start nodes: The Authorization header of an accepted inbound request has always been removed before the flow runs. With the new opt-in Keep Authorization Header option the header is kept, so a flow can pass the caller's credential on. The option is off by default and existing flows behave exactly as before; gateway headers are still always removed, and rejected requests are handled as before.
- What a kept Authorization header implies: A kept header is the caller's credential as it was sent. It is written to the node logs, it is returned on the synchronous response (and on the asynchronous 202 response), and an outbound HTTP node that has no authentication of its own forwards it. On a flow that uses No Authentication the kept credential has never been verified.
- Inbound no-authentication setting renamed: The installation setting that makes the No Authentication option available on inbound connectors is now
SECURITY_INBOUND_NO_AUTH_OPTION_ENABLED(propertyapp.security.inbound.no-auth-option.enabled). The setting only offers the option; it is still chosen per flow in the designer. The previous environment nameINBOUND_ALLOW_NO_AUTHis still read as a fallback, so an installation that set it keeps its behaviour.
Frontend Server
New Features
- Keep Authorization Header stored with the flow: The setting is stored in the REST and SOAP Start node configuration and is preserved when a flow is exported and imported.
- Inbound no-authentication setting renamed: The installation setting is now
SECURITY_INBOUND_NO_AUTH_OPTION_ENABLED; the previous nameINBOUND_ALLOW_NO_AUTHis still read as a fallback.
Frontend Web
New Features
- Keep Authorization Header checkbox: The REST and SOAP Start nodes gain a Keep Authorization Header checkbox under the authentication options. It is unchecked by default, and flows saved before the option existed open with it unchecked.
1.18.2.13 is a stable release. Previous: 1.18.2.12