ATIPXpress Collaboration Portal Release Notes 26.4.2.0

Prev Next

1. Product Enhancements

1.1 Collab SAML SSO Redesign - Self-Service SSO Documentation & Onboarding Guide

#ID 1506659

Collaboration Portal Administrators can now configure SAML SSO through a guided, step-by-step wizard that separates the essential settings from the advanced ones, so routine single sign-on setup is faster and less error-prone. The wizard is reached from Administration > Security > Sign On Mode, and the existing Security page and Sign On Mode entry point are unchanged.

  1. Navigate to Administration > Security > Sign On Mode and select SAML SSO from the Collab Portal Sign On Mode dropdown.

  2. Enter the Service Provider details, including the Issuer/Entity ID and Assertion Service URL.

  3. Upload the Identity Provider metadata XML, review the populated settings, and select Test Connection.

  4. Review the configuration summary and select Save Configuration.

Use the step-by-step wizard with validation, progress tracking, and expandable Advanced Settings to complete the setup.

1.2 Unified From Address Handling Across Email Authentication Modes  

#ID 1566640

Mail Server Configuration now supports Microsoft 365 Email authentication for portal email. Portal Administrators can configure a single email domain using Azure app credentials instead of a service account.

  1. Go to Mail Server Configuration.

  2. Set Authentication Mode to Microsoft 365 Email.

  3. Enter Email Domain, OAuth Client ID, Secret Key, Client Secret Expiry Date, and Tenant ID.

  4. Select Save.

  • The Email Domain Credentials list always shows a single row, populated with saved values or left blank for a new configuration.

  • Only one sending domain is supported, so + Add Domain and row deletion are not available.

  • All fields are required, and the Email Address domain must match the Email Domain.

  • Configuration changes are saved as a single transaction.

  • SMTP settings remain hidden when Microsoft 365 Email is selected.

  • Recipient limits and batching behavior are unchanged.

NOTE: Validation prevents saving if required fields are missing, or the email address domain does not match the configured domain. Domain mismatches generate an authentication failure at send time. If Microsoft 365 is unavailable, the email is marked as a delivery failure and follows the existing retry process.

Portal users cannot view or modify these settings, and all portal emails continue to use the configured system sender address.

1.3 Consultation Check at Document Delivery

ID #1621889

ATIPXpress now checks consultation status before you deliver documents. When you initiate Deliver Documents, the consultation status of every selected document, section, and page is checked against the Consultation Review Log. If everything is closed, the delivery continues without an additional step. If any consultation is still open, a confirmation message lists the affected items by Consultation Name, Program Office, Document Name, Section, and Impacted Pages, and you select Deliver Anyway to continue. The check informs you; it never blocks the delivery.

To review consultation status and deliver documents:

  1. In Document Management, select the documents, sections, or pages you want to deliver.

  2. Click Deliver Documents.

  3. Review the consultations listed, then click Deliver Anyway to continue.

A consultation counts as open until it is marked completed through Take Action, in both the Send via Email/Save and Via Collaboration Portal modes. Every delivery now carries a Consultation Status value in the Document Delivery Log. Select it to view the consultations that were pending at the time of that delivery. That record does not change if those consultations are later closed or edited.

1.4 Page Marking Indicator and Consultation Details in the Document Viewer

#ID 1617777

Pages marked for consultation now carry a visible indicator in the Document Viewer, so an analyst reviewing thousands of pages can tell at a glance that a page is marked and identify the Program Offices it is marked for. The Mark for Consultation dialog has also been restructured to make the outcome of each action unambiguous.

A tag icon appears beside every marked page in the Document Viewer tree. Selecting the tag icon displays a read-only list of each Program Office the page is marked for, most recent first.

The Program Office selection inside Mark for Consultation is now a table with a checkbox, the office name, and a Marked or Unmarked status for each row, together with a search field that filters the list by name. A Program Office shows Marked only if the page is marked for that office on every page currently targeted; a partial selection shows Unmarked.

To review which Program Offices a page is marked for:

1. Navigate to Document Management and select the document in the Review Log.

2. Locate the page in the Document Viewer tree. A tag icon indicates that the page is marked for consultation.

3. Select the tag icon to display the list of Program Offices the page is marked for.

To mark or unmark pages for a Program Office:

1. Right-click the folder or cabinet and select Mark for Consultation.

2. Select the pages you want to change.

3. Select the Program Offices in the table, using the search field to narrow the list if required.

4. Select Mark or Unmark to stage the change.

5. Select Done to save the change, or Cancel to discard it.

1.5 Editable Due Date on Consultations That Are Not Closed

#ID 1611512

ATIPXpress now lets you revise the due date on any consultation that has not yet been closed, including consultations already marked Sent. A consultation recipient who asks for more time can be granted an extension directly on the record, without cancelling and re-issuing the consultation.

The date picker permits today's date and every later date, and disables all earlier dates. This restriction applies on the first visit to Take Action for a consultation even if no due date was previously set, and it applies identically to both consultation modes — Email/Save and Collaboration Portal.

To revise the due date on a consultation:

1. Navigate to the request and select the Consultations tab.

2. Select the consultation you want to revise, then select Take Action.

3. Select a new Due Date. Dates earlier than today are disabled in the calendar.

4. Select Save. The revised date is written to the consultation record and appears immediately in the Consultations grid.

NOTE: A closed consultation keeps its due date field disabled, exactly as before. Typing a past date manually is rejected at save with a warning message.

Revised due dates flow through to every place the consultation due date is displayed or used. The Annual and Custom Consultation reports reflect the new date on their existing hourly refresh cycle. Collaboration Portal users see the revised date against the same consultation record without needing to refresh the page.

1.6 Mandatory Client Secret Expiry for GraphAPI Configurations

#ID 1516434

GraphAPI configurations now enforce expiry date validation, rejecting past or empty values with clear messaging. This update enables better visibility into credential lifecycles, helping administrators prevent unexpected outages and maintain secure, uninterrupted authentication across all integrated components.

  1. Open Mail Server Configuration in the application.

  2. Locate the Client Secret Expiry Date field. This field is mandatory.

  3. Use the date picker to enter the same expiration date that was selected for the client secret in the Azure Portal.

  4. Click Save to apply the changes.

1.7 Improved Certificate Validation for SAML SSO Configuration

#ID 1518900

We have improved the SAML SSO Configuration experience so that administrators can only upload supported certificate files when setting up single sign-on. Previously, selecting an unsupported file type could return a misleading "saved successfully" message, and some valid certificates were incorrectly shown as invalid even though they worked correctly.

The SAML SSO Configuration page now accepts only supported certificate file types (.cer, .pfx, .crt, and .pem). If you select any other file type, the page immediately displays a clear validation message — "Selected file extension is not allowed. Only the following extensions are allowed: .cer, .pfx, .crt, .pem." — instead of appearing to save successfully. Valid certificates are also now displayed correctly, so you can configure SSO with confidence.

1.8 Identity Provider Fields Restricted in the Database Management Tool

#ID 1592779

SAML configuration is now held in the database, so the identity provider fields have been removed from the Database Management Tool. Editing those fields in the tool while a user signed in at the same time could overwrite the values that had just been applied, and restricting them removes that conflict.

1.9 Task Instructions in a Separate Browser Tab

#ID 1517483

Collaboration Portal users can now view task Instructions in a separate browser tab, so that the instructions stay visible as a persistent reference while an RFD or Consultation task is completed. The document viewer tab and the active workflow are unaffected.

There are two entry points. The Open in new tab button in the footer of the Instructions pop-up displays the standalone page in a new tab and dismisses the pop-up; the pop-up title bar is unchanged. Selecting Instructions from the Show menu displays the standalone page directly in a new tab with no pop-up, whether or not the automatic pop-up was shown or dismissed earlier in the session. The Show menu is the primary route for a returning user, once the automatic pop-up no longer appears.

To view task instructions in a separate tab:

  1. In the document viewer, select Open in new tab in the Instructions pop-up footer, or select Instructions from the Show menu.

  2. Review the instructions on the standalone page, titled Instructions — Collaboration Portal.

  3. Switch between the Request For Documents and Consultations tabs as required. Request For Documents is active by default.

Each tab displays the content configured by the administrator under Administration > Organization Setup > Enterprise; a tab for which blank content has been saved renders empty. Each selection creates a new, independent Instructions tab and leaves any existing Instructions tabs untouched, and the standalone page is fully independent of the document viewer.

NOTE: This is a convenience enhancement. Existing functionality is unchanged.

2. Security Updates

We’ve made the following security updates to the Collaboration Portal:

ID

Description

1593932

Upgraded AngleSharp (1.6.0) and Microsoft.Kiota.Abstractions (2.0) in the ATIPXpress, Collaboration, and PAL to remediate reported security vulnerabilities.

1632862

Fixed multiple stored XSS findings reported by SOC for the VAPT assessment, affecting the Collaboration Message field in the ATIPXpress and Collaboration modules. Two-layer remediation: server-side validation added to the message submission path to detect and block suspicious Unicode sequences used to bypass sanitization; and context-aware output encoding applied across every point where message content is rendered — list views, detail views, notifications, and export paths. The fix covers newly submitted and previously stored content, since encoding occurs at render time.

1642712

Addressed a user enumeration weakness on the Collaboration Portal Forgot Password page, identified during a vulnerability assessment. A password reset response no longer reveals whether a specific user account exists.

1642712

Enhanced the password reset functionality to prevent user enumeration, ensuring that responses do not reveal whether a specific user account exists. This improves application security and protects user account information in Collaboration Portal.

3. Bug Fixes

We’ve addressed the following bugs in the Collaboration Portal:

ID

Description

1534282

Updated the task ID structure to support a larger range of records, preventing errors when creating additional Review Statuses, Alerts, and Notes.

1589283

Resolved a login malfunction reported against the portal in a production environment.

1604166

Fixed an issue where a revised consultation package due date was not reflected in the Collaboration Portal after the first change. The portal now shows the current due date against the consultation record.

1496995

Fixed an issue where two Collaboration Portal users working on the same Request for Documents at the same time each created a review layer, and only the most recent layer was transferred on submission. A user saving a review layer for a document another user has already saved is now prompted to reload the Document Management page, after which the changes can be added to the existing layer or saved as a new one.

1579391

Fixed a failure that prevented the General Configuration save operation from completing in the Collaboration Portal. Configuration changes now save successfully.