ATIPXpress PAL Release Notes 26.4.2.0

Prev Next

1. Product Enhancements

1.1 Remove Enable SSL Configuration Option from PAL Graph API Settings

#ID 1516461

The PAL Graph API configuration no longer includes the Enable SSL toggle, reducing complexity and avoiding confusion. Existing Graph API integrations continue to function seamlessly, and no administrator action is required after the upgrade.

The Enable SSL option has been removed from the PAL Graph API configuration settings. Secure transport for Graph API communication is managed automatically by the Microsoft Graph endpoints, so a separate SSL toggle is no longer required. Removing it streamlines the configuration screen and prevents confusion from an obsolete setting.

1.2 Mandatory Client Secret Expiry for GraphAPI Configurations

#ID 1516434

PAL Configuration now requires a client secret expiry date on every Graph API configuration, so that expiring credentials can be renewed before authentication begins to fail. A configuration cannot be saved without a valid expiry date.

  1. Navigate to PAL Configuration and go to the Graph API configuration settings.

  2. Locate the Client Secret Expiry Date field. This field is mandatory.

  3. Use the date picker to enter the same expiry date that was set for the client secret in the Azure portal.

  4. Select Save.

A configuration saved with no date, or with a date that has already passed, is rejected with a validation message naming the Client Secret Key Expiry Date. Existing Graph API integrations continue to function without change.

1.3 PAL Configuration SAML SSO Redesign - Self-Service SSO Documentation & Onboarding Guide

#ID 1454726

PAL Configuration Administrators can now configure SAML SSO through a redesigned step-by-step wizard that organizes settings into logical sections and separates basic configuration from advanced options. The new experience simplifies setup, improves validation, and supports purpose-based SAML configurations for PAL Application Sign In, Proof of Identity, and PAL Config Sign In without changing existing authentication entry points.

  1. Navigate to PAL Configuration > Authentication and select SAML SSO from the Authentication Options.

  2. Select the SAML configuration purpose, such as PAL Application Sign In, Proof of Identity, or PAL Config Sign In.

  3. Configure the Service Provider settings, including Issuer/Entity ID, Assertion Service URL, and certificate options.

  4. Upload Identity Provider metadata, review the populated settings, and test the SAML connection.

  5. Configure SAML field mappings when applicable and review the configuration summary.

  6. Select Save Configuration to apply the SAML SSO settings for the selected purpose.

Use the step-by-step wizard with validation, progress tracking, and expandable Advanced Settings to complete the setup.

1.4 Component Space SAML Library Upgraded

#ID 1506043

The Component Space SAML component in PAL and PAL Config has been upgraded from the previous version to the latest approved stable version. The upgrade strengthens the security and standards-compatibility of the SAML SSO integration while keeping all existing authentication behavior intact:

  • Existing SSO authentication flows continue to work after the upgrade.

  • No change to login, logout, or session management behavior.

  • SAML metadata generation and consumption continue to function correctly.

  • All existing identity provider (IdP) integrations remain valid and were validated after the upgrade.

2. Security Updates

We’ve made the following security updates in this version of ATIPXpress:

ID

Description

1501243

Resolved an improper error handling vulnerability in the Public Access Link (PAL), where requests for invalid or malformed file paths returned verbose error responses that could disclose internal application details. PAL now returns a generic error response for these requests.

1603384

Upgraded AngleSharp and Microsoft.Kiota.Abstractions in PAL and PALConfig to remediate reported security vulnerabilities.

1622330

Upgraded Telerik UI and System.Security.Cryptography.Xml in PAL to remediate reported security vulnerabilities.

1561616

Resolved multiple stored Cross-Site Scripting (XSS) vulnerabilities on the PAL Reading Room – File Cabinets page. Server-side input validation now detects and blocks suspicious Unicode characters, and HTML and JavaScript output encoding is applied at every rendering point to prevent malicious script execution.

3. Bug Fixes

We’ve addressed the following bugs in this version of ATIPXpress:

ID

Description

1487562

Resolved an issue where, while submitting multiple requests without signing in through the PAL application, the selected Requester Category was not retained correctly. The system previously defaulted to the same category for all submissions regardless of user selection. The system now correctly captures and applies the selected Requester Category for each unregistered request, ensuring accurate categorization.

1533356

Resolved an issue where the Forgot Password functionality in the PAL application did not work reliably and resulted in inconsistent behavior. In some cases, users were unable to proceed to the verification code screen despite receiving the email, while in others, the verification screen appeared but no email was received. Additionally, password reset attempts for synced requesters incorrectly displayed an error indicating the account was not synced. The system now ensures proper handling of password reset flow, consistent email delivery, and accurate validation of synced requester status.

1546116

Resolved an issue where CAPTCHA errors in the AX PAL production environment blocked all request submissions, causing the request submission system to become unresponsive. The system now properly validates CAPTCHA responses and ensures uninterrupted submission of requests, restoring normal functionality.

1540224

Resolved an issue where SAML authentication for login failed when POI configuration contained data. The system previously used the POI IdP incorrectly for all authentication levels, breaking the login process. The system now correctly selects the IdP based on the authentication level, ensuring successful login functionality.

1619032

Fixed an issue where Reading Room content search did not return published documents that matched the entered keywords. Search results now correctly display matching published Reading Room documents.

1619046

Fixed an error raised while signing out of PAL Configuration after a user was created. Sign-out now returns to the login page as expected.