1. Product Enhancements
1.1 Consultation Check at Document Delivery
ID #1621889
ATIPXpress now checks consultation status before you deliver documents. When you initiate Deliver Documents, the consultation status of every selected document, section, and page is checked against the Consultation Review Log. If everything is closed, the delivery continues without an additional step. If any consultation is still open, a confirmation message lists the affected items by Consultation Name, Program Office, Document Name, Section, and Impacted Pages, and you select Deliver Anyway to continue. The check informs you; it never blocks the delivery.
To review consultation status and deliver documents:
In Document Management, select the documents, sections, or pages you want to deliver.
Click Deliver Documents.
Review the consultations listed, then click Deliver Anyway to continue.
.png?sv=2026-02-06&spr=https&st=2026-10-10T05%3A30%3A01Z&se=2026-10-10T06%3A12%3A01Z&sr=c&sp=r&sig=fjJtGGV0Lc2l3mG6P6IJG2Y4XifQ672TVsNhMvinunw%3D)
A consultation counts as open until it is marked completed through Take Action, in both the Send via Email/Save and Via Collaboration Portal modes. Every delivery now carries a Consultation Status value in the Document Delivery Log. Select it to view the consultations that were pending at the time of that delivery. That record does not change if those consultations are later closed or edited.
1.2 Page Marking Indicator and Consultation Details in the Document Viewer
#ID 1617777
Pages marked for consultation now carry a visible indicator in the Document Viewer, so an analyst reviewing thousands of pages can tell at a glance that a page is marked and identify the Program Offices it is marked for. The Mark for Consultation dialog has also been restructured to make the outcome of each action unambiguous.
A tag icon appears beside every marked page in the Document Viewer tree. Selecting the tag icon displays a read-only list of each Program Office the page is marked for, most recent first.
.png?sv=2026-02-06&spr=https&st=2026-10-10T05%3A30%3A01Z&se=2026-10-10T06%3A12%3A01Z&sr=c&sp=r&sig=fjJtGGV0Lc2l3mG6P6IJG2Y4XifQ672TVsNhMvinunw%3D)
The Program Office selection inside Mark for Consultation is now a table with a checkbox, the office name, and a Marked or Unmarked status for each row, together with a search field that filters the list by name. A Program Office shows Marked only if the page is marked for that office on every page currently targeted; a partial selection shows Unmarked.
To review which Program Offices a page is marked for:
1. Navigate to Document Management and select the document in the Review Log.
2. Locate the page in the Document Viewer tree. A tag icon indicates that the page is marked for consultation.
3. Select the tag icon to display the list of Program Offices the page is marked for.
To mark or unmark pages for a Program Office:
1. Right-click the folder or cabinet and select Mark for Consultation.
2. Select the pages you want to change.
3. Select the Program Offices in the table, using the search field to narrow the list if required.
4. Select Mark or Unmark to stage the change.
5. Select Done to save the change, or Cancel to discard it.
1.3 Unified "From" Address Behavior for Microsoft 365 Email
#ID 1566640, 1597473, 1597432
ATIPXpress now applies a single, administrator-configured sender identity to outbound email sent through Microsoft 365, rather than letting each email-producing area resolve its own "From" address. Administrators authenticate outbound mail per email domain in one place and set the sender identity in another, and that resolved identity is then applied consistently and read-only wherever email is sent. This removes the inconsistent outbound mail identity that previously differed between delivery modes, and closes the spoofing and deliverability risks created by manual "From" edits.
The administrator configuration surfaces — Authentication Mode and the Email Domain Credentials table in Mail Server Configuration, and the Global Email Address sender option in Correspondence Configuration — were introduced in v26.4.1.0. This version applies the configured identity at send time and adds automatic recipient batching.
To review the sender identity applied to outbound email:
1. Navigate to System Administration > Mail Server Configuration.
2. Set Authentication Mode to Microsoft 365 Email.
3. Confirm that each approved email domain has a complete credential row (Email Domain, OAuth Client ID, Secret Key, Client Secret Expiry Date, Tenant ID). Select + Add Domain to register an additional domain, or the row delete (✕) control to remove one.
4. Set the Recipient Limit to the maximum number of recipients permitted on a single send, then select Save.

5. Navigate to System Administration > Correspondence Configuration.
6. Select the required value in Sender's Default Email Address (From), then select Save.

Key behavior in Microsoft 365 mode:
• The resolved sender identity is applied across every email-producing area, including Correspondence, Request for Document (email mode), Report Scheduler recipients, report email exports, License Information, Document Management document delivery, and lifecycle notification emails.
• Wherever a "From" value is displayed it is read-only, and the free-text entry and "Other Email" options have been removed; the lock is enforced on the server so it cannot be bypassed from the screen.
• Selecting Microsoft 365 Email hides the User Email and User Action Office Email sender options, so all outbound mail resolves to the configured global address.
• A single Recipient Limit applies across all configured domains. An email exceeding the limit is partitioned automatically into compliant batches with no user action; an email within the limit is dispatched as a single send. Recipients spanning multiple domains on one email are partitioned against the same global limit.
• Outbound mail authenticates against the credential row matching the domain of the resolved "From" address.
• Each Email Domain value must be unique.
• A credential row whose Client Secret Expiry Date has passed is flagged, so credentials can be renewed before sends begin to fail.
• A resolved "From" address whose domain does not match a configured domain is validated in the background job, which records a validation error in the Email Log and marks the email as failed rather than reporting a false success.
NOTE: The Global Email Address behavior applies to Microsoft 365 authentication only. SMTP email sending is unchanged in this version, and the existing SMTP sender behavior continues to apply. The Set Reply-To to User's Email Address setting is displayed in Correspondence Configuration but is not yet active in this version. Replies are not routed to the sending user's address.
1.4 Read-Only View of Close Request Details
#ID 1620174
A closed request now provides direct access to the closing screen data that was entered at closure, so details can be validated for reporting without reconstructing them from a custom report. A View Close Request Details tab appears at the top of the request's left tab menu, and is present only while the request is closed.
Selecting the tab displays a read-only, field-for-field reproduction of the Close Request screen, sourced from the most recently saved closure.
To review the closing details of a closed request:
1. Navigate to the closed request.
2. Select View Close Request Details at the top of the left tab menu.
3. Review the Closed Details, Release Format, Request Complexities, Comment, and Notes blocks. All fields are read-only.

The Closed Details block displays Requester, Organization, Fee Waiver, Balance Due, Received Date, Disposition Accepted Date, Closed Date, Final Disposition, Review Status, and Method of Access. Balance Due retains its color coding — red for an amount owed by the requester, blue for an amount owed to the requester.
The Release Format block lists all six format types (Paper, Data set, E-record, Audio, Video, Other Format) with their released and reviewed values; format types that were not used display unchecked and blank. Request Complexities checkboxes (Consultation Required, Legal Advice Sought, Other, None) display their state at closure. Comment and Notes display exactly as saved.
NOTE: No changes can be made from this tab. A field left empty at closure displays as blank rather than being hidden or re-labelled; "N/A" appears only if "N/A" was the value actually saved. A request that was reopened and closed again displays only the most recent closure's data.
1.5 Correspondence Language Aligned to the Requester's Preferred Language
#ID 1619092
Send Correspondence now resolves the language from the requester's Preferred Language rather than defaulting to English, and it blocks sends that would produce a blank or wrong-language email. Previously, correspondence could be dispatched with empty content or with content in a language the requester had not asked for.
On accessing Send Correspondence, the Language drop-down menu is pre-populated from the requester's Preferred Language (English or French). Manual override of that selection remains available in every scenario.
To send correspondence in the requester's preferred language:
1. Navigate to the request and select the Correspondence tab.
2. Select Send Correspondence. The Language drop-down menu is pre-populated from the requester's Preferred Language.
3. Select a template. Adjust the Language selection if a different language is required.
4. Review the populated Subject and Body, then send the correspondence.

A new Both (English & French) option is also available in the Language drop-down menu. Selecting it against a template authored in both languages populates the Subject and Body with the combined English and French content.
NOTE: Selecting a template that has no authored content for the resolved language displays a Missing Template Content pop-up immediately, without waiting for you to send. The pop-up offers only a Close button, which returns you to the form; there is no option to send regardless. To proceed, select a different language or template that has content, or enter the content manually. Selecting Both (English & French) against a template missing either language displays the same guardrail, naming the language or languages that are absent.
1.6 Due Date Breakdown in Request Information
#ID 1508631
ATIP Coordinators can now trace exactly how a request's current due date was reached, without leaving the request page or reconstructing the record manually. A new Due Date Breakdown section inside Request Information presents a chronological, step-by-step record of every event that moved the due date — the received date, each hold, and each clock resume.
The section sits below Request Details and is collapsed by default, matching the expand and collapse behavior of the Address Details section. Its state persists until you toggle it again.
To review the due date breakdown for a request:
Navigate to the request and go to the Request Information section.
Click the plus (+) toggle beside Due Date Breakdown to expand the section.
Review the summary bar, which presents six fields: Received Date, Original Due Date, Total Authorized Days, Days Used (Before Hold), Remaining Days, and Current Due Date.
Review the event grid below the summary bar. Each row represents one event in chronological order, with the columns #, Event, Date, Status, and Resulting Due Date.
Hover over the indicator beside an adjusted date to display the weekend or holiday tooltip. The tooltip names the computed date, the adjusted next business day, and the reason for the adjustment — a weekend or a named Ontario public holiday.
Click the minus (−) toggle to collapse the section.
A hold that is still active shows Suspended in the Resulting Due Date column, and the summary bar presents the frozen Remaining Days and Current Due Date values. Once the clock resumes, the Clock Resumed row shows the due date that applies from that point on.
A request with no hold activity displays two rows only — Request Received and Original Due Date Set — with Remaining Days equal to Total Authorized Days.
NOTE: The summary bar and the grid refresh automatically as hold events occur; a page refresh is not required. Available in the ATIA/PA version only.
1.7 Updated Due-Date Calculations
#ID 1437776
ATIPXpress now uses a single, consistent rule to calculate request due dates holds, so that due dates, and the statistics derived from them, are dependable for government compliance reporting.
Due dates are now always calculated from the received date and not the previous Due Date. Holds pause and resume the due date consistently, and any weekend or holiday adjustment is applied once, at the end of the calculation. Any time a due date change is trigged, the system will recalculate the due date from the received date, plus allowed processing time, and then account for holds and extensions.
You can also review exactly how a due date was reached. A new expandable Due Date Breakdown section in the request details traces each step — received date, original due date, and adjustments — through to the current due date.
1.8 Extension Removal and Correction with Automatic Due-Date Recalculation
#ID 1508665
ATIP Coordinators can now correct an extension mistake directly on an active request, with no need to amend the request. An extension can be deleted in any status, and a Pending extension can also be edited. ATIPXpress then recalculates the Current Due Date, Compliance Status, Remaining Days, and Total Authorized Days automatically, following the calculation rules described in Correct Due-Date Calculation for Extensions and Holds.
Available actions depend on the extension status:
• Approved — can be deleted but not edited; deletion recalculates the due date
• Completed — can be deleted but not edited; deletion recalculates the due date
• Pending — can be deleted or edited; neither action recalculates the due date
• Denied — can be deleted but not edited; deletion does not recalculate the due date
Pending and Denied extensions do not count toward the due date, so deleting or editing them leaves the Current Due Date unchanged.
To delete an extension from an active request:
1. Navigate to the request and go to the extensions grid.
2. Select Delete on the extension row you want to remove. The Delete Extension screen presents the recomputed date fields — the extended due date and the Extended Estimate Delivery Date — calculated live with the selected extension excluded.
3. Review the confirmation message, which states the exact change: “Deleting this extension will change the Due Date from {current value} to {post-delete value} and the Extended Estimate Delivery Date from {current value} to {post-delete value}. This action will be recorded in Action History.”
4. Confirm the deletion. ATIPXpress re-runs the calculation and updates the request.
The recomputed date fields on the Delete Extension screen are read-only. ATIPXpress populates them at the moment the screen is displayed, and the values cannot be edited or overridden.
Deleting an Approved or Completed extension removes its days from the total and recalculates the due date from the original due date using the extensions that remain. Deleting an Approved 90-day 9(1)(c) extension while an Approved 60-day 9(1)(b) extension remains, for example, sets the new Current Due Date to the original due date plus 60 days, with the weekend and holiday adjustment applied once. Deleting the only Approved or Completed extension reverts the Current Due Date to the displayed original due date, and Total Authorized Days returns to Original Processing Days.
A deletion that pushes a request past its deadline is still permitted. ATIPXpress recalculates from the locked raw original due date, sets the compliance status to Overdue, and does not rebase the calculation to today's date.
Every delete and edit is captured in Action History with the user, the timestamp, the action type, the extension type, the duration, and the displayed due date before and after the change — or “No change” for a Pending or Denied extension.
A coordinator who deletes an Approved extension can re-add the same type and duration with no system restriction; the re-added extension enters as Pending and follows the standard approval workflow. Editing a Pending extension's duration or type saves the corrected values, and those corrected values are the ones evaluated should the extension later be approved.
NOTE: Holds in ATIPXpress are managed through the Start Clock and Stop Clock actions and have no standalone entry, so a hold cannot be deleted or edited from the extensions grid. Delete and edit actions are blocked on a closed or completed request, where ATIPXpress displays “This action is not permitted. The request is already closed.” Available in the ATIA/PA version only.
1.9 Correct Due-Date Calculation for Extensions and Holds
#ID 1628897
ATIPXpress recalculates the due date of a request from a fixed starting point each time an extension decision is recorded, so that deadlines and the compliance statistics derived from them are dependable for government reporting. The base of every calculation is the Received Date plus the original processing days, taken before any weekend or holiday adjustment; the adjustment applies to the date that is displayed, not to the value the next calculation starts from.
• Every extension in Approved or Completed status contributes its full number of days, whatever its type
• Extensions in Pending or Denied status contribute no days
• Several extensions on one request are added together, and no extension type replaces, competes with, or discounts another
• Each decision triggers a complete recalculation from the original due date, or from the clock start date once the clock has been stopped and restarted, using the full current list of approved extensions
• Reversing or denying an extension that was previously approved recalculates the due date from the remaining approved extensions, which can move the due date earlier and can leave the request overdue
The previously displayed due date is never used as the starting point for the next calculation, so approving a second extension does not add its days to the date produced by the first. A request with 30 original processing days, a 30-day extension and a 60-day extension therefore carries 120 authorized days in total.
A due date that lands on a weekend or on a configured public holiday moves forward to the next business day. The adjustment is applied once, to the final calculated date, and the days it adds are not carried into any later calculation.
Stopping the clock records Days Used as business days from the Received Date to the stop date and freezes the remaining days. Restarting the clock sets the due date to the restart date plus the remaining days. The Due Date Breakdown section on the Request Information tab lists each event and the due date that resulted from it.
NOTE: Extension days under Section 9 are counted as calendar days regardless of extension type. Business-day counting applies to the weekend and holiday adjustment, and to the days counted from the Received Date to the date the clock was stopped. A recalculated due date that falls in the past is retained and the request stays flagged as overdue; the due date is never moved forward to the current date to clear the overdue status. Available in the ATIA/PA version only.
1.10 Editable Due Date on Consultations That Are Not Closed
#ID 1611512
ATIPXpress now lets you revise the due date on any consultation that has not yet been closed, including consultations already marked Sent. A consultation recipient who asks for more time can be granted an extension directly on the record, without cancelling and re-issuing the consultation.
The date picker permits today's date and every later date, and disables all earlier dates. This restriction applies on the first visit to Take Action for a consultation even if no due date was previously set, and it applies identically to both consultation modes — Email/Save and Collaboration Portal.
To revise the due date on a consultation:
1. Navigate to the request and select the Consultations tab.
2. Select the consultation you want to revise, then select Take Action.
3. Select a new Due Date. Dates earlier than today are disabled in the calendar.
4. Select Save. The revised date is written to the consultation record and appears immediately in the Consultations grid.

NOTE: A closed consultation keeps its due date field disabled, exactly as before. Typing a past date manually is rejected at save with a warning message.
Revised due dates flow through to every place the consultation due date is displayed or used. The Annual and Custom Consultation reports reflect the new date on their existing hourly refresh cycle. Collaboration Portal users see the revised date against the same consultation record without needing to refresh the page.
1.11 Background Generation of Custom Reports
#ID 1514091
ATIPXpress now generates Custom Reports as a background job instead of building them inside your active session. Reports that span multiple years or include a large number of fields previously took significant time to process, tied up your session, and slowed down other operations across the application. Report generation now runs asynchronously, so you can continue working while a large report is prepared.
When you generate a Custom Report, you can choose the output format you need (such as Word or Excel) and decide whether to run the report immediately or schedule it for a later date and time. You can then track the status of each report — Queued, In Progress, Completed, or Failed — from the Job Monitoring window and download the finished report once it is ready.
Moving report generation to a background job reduces load on the application server and improves overall system responsiveness, especially for large, data-heavy reports.
1.12 Background Job Generation for Billing and Operational Reports
#ID 1514091
Building on the background job report generation introduced for custom request reports, ATIPXpress now extends the same asynchronous processing to a wide range of billing and operational reports. When you run one of these reports, many of which span multiple years and include a large number of selected fields, ATIPXpress produces it as a background job instead of building it directly in your active session. This keeps the application responsive for you and for other users while a large report is compiled, and removes the performance slowdowns that previously occurred when heavy reports were generated in-session.
The following reports are now generated as background jobs:
Billing reports — Payment, Delinquent Requester, Invoice Details, Pending Fees, Request – Processed Cost – Fees, and Work Hours
Custom request reports — Declassification, Document, Reading Room Documents, Request for Documents Actions, User Actions, and User Logins
For each report you can choose the output format, decide whether to generate it immediately or schedule it for a later date and time, and follow its progress and status from Jobs.
To generate a report as a background job:
Navigate to Reports and open the report you want to run.
Select a saved criteria and click Next. Alternatively, simply click Next to create a new criteria.
Configure the report criteria — for example, the reporting period and the fields to include — as you normally would.
Click Generate in Background.
Select the report format you want.

Choose a Schedule option:
Select Now to run the report immediately, or
Select Later and specify the date and time for the report to run later.
Click Export to submit the report. ATIPXpress queues the report as a background job.
Navigate to Administration > Jobs > All Jobs. Locate your report job and click the status to monitor the job.
When the status shows Completed, click Download to download the generated report in the format you selected.

NOTE: Since these reports now run as background jobs, you can continue working in ATIPXpress, or log out, while a report is being generated. Scheduled reports run automatically at the date and time you specify.
1.13 Configurable Group Assignments Display on the Home Page
#ID 1549268
We have substantially improved the performance and stability of the Annual Report. Running the Annual You can now control which requests appear in the Group Assignments section of the Home Page. A new system configuration lets an administrator choose whether the Group Assignments queue shows only requests where the group is the primary assignee, or both primary and secondary assigned requests. Existing environments keep their current behavior (both primary and secondary) until the setting is changed.
To configure the Group Assignments display:
Navigate to Administration > System Configuration > General Configuration.
Locate for Group Queue Assignments under Dashboard Configuration.
Select Primary to show only requests where the group is the primary assignee, Secondary to show only requests where the group is the secondary assignee, or Both to show both.

When you’re done, click Save.
The Home Page Group Assignments section updates to match.
1.14 Faster Documents Report Generation
#ID 1489523
We have improved the performance of the Documents Report, so that generating it no longer slows down the rest of the application. On environments with large data volumes, the report's underlying queries could block other operations and lead to timeout errors for concurrent users. We have optimized those database queries to reduce contention and minimize timeouts, so the Documents Report runs more reliably without impacting other activity in ATIPXpress.
1.15 Improved Certificate Validation for SAML SSO Configuration
#ID 1518900
We have improved the SAML SSO Configuration experience so that administrators can only upload supported certificate files when setting up single sign-on. Previously, selecting an unsupported file type could return a misleading "saved successfully" message, and some valid certificates were incorrectly shown as invalid even though they worked correctly.
The SAML SSO Configuration page now accepts only supported certificate file types (.cer, .pfx, .crt, and .pem). If you select any other file type, the page immediately displays a clear validation message — "Selected file extension is not allowed. Only the following extensions are allowed: .cer, .pfx, .crt, .pem." — instead of appearing to save successfully. Valid certificates are also now displayed correctly, so you can configure SSO with confidence.
1.16 Date Validation for Locked Annual Reporting Periods
#ID 1437760
ATIPXpress now blocks any date edit that would move a request into or out of a locked fiscal year (FY), thus strengthening the Statistical Report data integrity.

The check runs server-side at save and covers Received Date, Date Closed. A save is rejected whenever the old or new date falls before any FY lock date, covering all cases (moving out of, into, between, or within locked fiscal years), and a message notifies you of the same. The save is all-or-nothing: if any in-scope field violates the rule, nothing in the transaction is committed.
To make a blocked edit, a user with the Statistical Report-Edit permission must first unlock the affected reporting period from the Statistical Report configuration; lock state is re-evaluated at each save.
For mass close options, the rule is applied per request: violating requests are skipped and the rest are processed, and ATIPXpress reports how many were applied and how many were skipped.
1.17 Mandatory Client Secret Expiry for GraphAPI Configurations
#ID 1516434
GraphAPI configurations now enforce expiry date validation, rejecting past or empty values with clear messaging. This update enables better visibility into credential lifecycles, helping administrators prevent unexpected outages and maintain secure, uninterrupted authentication across all integrated components.
.png?sv=2026-02-06&spr=https&st=2026-10-10T05%3A30%3A01Z&se=2026-10-10T06%3A12%3A01Z&sr=c&sp=r&sig=fjJtGGV0Lc2l3mG6P6IJG2Y4XifQ672TVsNhMvinunw%3D)
Open Mail Server Configuration in the application.
Locate the Client Secret Expiry Date field. This field is mandatory.
Use the date picker to enter the same expiration date that was selected for the client secret in the Azure Portal.
Click Save to apply the changes.
1.18 Dedicated Document Management OCR Job
#ID 1549752
ATIPXpress now runs a dedicated OCR job for Document Management. When you add Pages to a Document Management Folder, OCR starts on the new Pages automatically to make them searchable — no manual step is required.
Previously, a single system job processed both Correspondence OCR and Document Management OCR, so a large volume of Pages could delay Correspondence OCR, Find and Redact, and AI-assisted redaction for everyone. The two now run independently.
A separate job is created for each Folder, so Pages in different Folders are processed at the same time. Job status shows live progress — for example, OCR Processing 8 of 73. A completion email lists the Folder name and the document, page, and reason for each failed Page. A job is marked Completed even when some Pages fail, and Failed only if the entire job fails. OCR errors never roll back a document upload.
To track a Document Management OCR job:
Navigate to Document Management and add Pages to a Folder. ATIPXpress starts the OCR job automatically.
Go to My Jobs to review the job and its live progress.
Go to Failed OCR Jobs to reprocess any Pages that did not complete.
NOTE: Pages that you set an OCR Priority for are processed by the OCR system job rather than by the automatic Document Management OCR job. If OCR is removed from the Scheduler Configuration, new Pages remain Pending in My Jobs until OCR is configured again.
2. Security Updates
We’ve made the following security updates in this version of ATIPXpress:
ID | Description |
1561616 | Resolved a stored Cross-Site Scripting (XSS) vulnerability in the PAL Reading Room – File Cabinets page by implementing server-side input validation, sanitization, and output encoding to prevent malicious script execution in File Cabinet Name and Description fields. |
1589751 | Addressed a SQL injection vulnerability, identified during a vulnerability assessment, in the reference value used when the application checks for duplicate and linked requests. |
1501243 | Resolved an improper error handling vulnerability in the Public Access Link (PAL), where requests for invalid or malformed file paths returned verbose error responses that could disclose internal application details. PAL now returns a generic error response for these requests. |
1585961 | Enhanced certificate password security by introducing encrypted password storage with automatic migration support through a configuration flag for backward compatibility. |
1622330 | Upgraded Telerik UI and System.Security.Cryptography.Xml in PAL to remediate reported security vulnerabilities. |
1622406 | Addressed an authorization bypass that allowed request pages to be reached by direct URL regardless of the user’s permission on that request. The user’s access to the request is now validated before the page loads. |
1622408 | Addressed a broken access control vulnerability in Document Management. The user’s permission on the requested folder or section, including cabinet view rights, reading room access, or request assignment, is now verified before documents are served, preventing unauthorized access. |
1622416 | Addressed a broken access control vulnerability on the Annual, Audit, and Custom report pages. Server-side permission checks are now enforced, preventing users without the required report permissions from accessing these pages directly. |
1622417 | Addressed a stored cross-site scripting (XSS) vulnerability in request Notes. Note content is now HTML-encoded when displayed, and note input is validated when saved, preventing malicious scripts from being stored or executed. |
1632862 | Fixed multiple stored XSS findings reported by SOC for the VAPT assessment, affecting the Collaboration Message field in the ATIPXpress and Collaboration modules. Two-layer remediation: server-side validation added to the message submission path to detect and block suspicious Unicode sequences used to bypass sanitization; and context-aware output encoding applied across every point where message content is rendered — list views, detail views, notifications, and export paths. The fix covers newly submitted and previously stored content, since encoding occurs at render time. |
1516488 | Addressed an authorization bypass that allowed the Reading Room Management and Consultation Management pages to be reached by direct URL. Access controls are now enforced so that only authorized users can reach these pages. |
1593932 | Upgraded AngleSharp (1.6.0) and Microsoft.Kiota.Abstractions (2.0) in ATIPXpress, the Collaboration Portal, and PAL to remediate reported security vulnerabilities. |
1603367 | Addressed a vulnerability in Request Custom Field file uploads, identified during a vulnerability assessment. The configured allowed file types are now enforced, so only permitted file types can be uploaded. |
1642807 | Addressed a user enumeration weakness on the Forgot Password page, identified during a vulnerability assessment. An unrecognized user name no longer returns an error revealing whether the account exists. The request proceeds to the same verification code screen shown for a valid user name, no email or verification code is generated, and any code entered returns the generic message, “Invalid verification code. Please try again.”. |
3. Bug Fixes
We’ve addressed the following bugs in this version of ATIPXpress:
ID | Description |
1406819 | Resolved an issue where, after an application fee payment was saved, the user was returned to the Request Information screen instead of the Correspondence screen; the correspondence prompt and navigation now open correctly after payment. |
1496997 | Fixed an issue where HTML files converted to PDF were cut off and did not capture all of the content. Converted PDFs now resize correctly and retain the full document. |
1512471 | Fixed Request Description search so that exact-phrase searches enclosed in double quotes ("phrase") or single quotes ('phrase') return only records containing the exact phrase, instead of producing an empty window or a search error. |
1514208 | Resolved the issue where the due date was being calculated incorrectly because of multiple overlapping holds. Additionally, if the clock is resumed on a non-business working day, the due date calculation will now start from the next business working day. |
1516831 | Fixed report exports to prevent the ATIPXpress title from appearing in Word and Excel report formats. |
1502744 | Resolved an "An Error Occurred" message that could appear when switching quickly between pages in the Document Management window. Page navigation now completes smoothly without spurious error popups. |
1515902 | Fixed SAML SSO logout handling so that users can log out successfully even when an optional Single Logout (SLO) URL has not been configured. |
1529946 | Corrected the page-count totals in Section 2.3 (Informal Requests) of the Statistical Report, which previously counted only paper pages. The released page count now includes datasets, e-records, and released video and audio minutes. |
1532074 | Corrected the page count shown when closing a FOIA request so that manually entered page counts are retained, even when no records were uploaded to the Review Log. |
1543328 | Fixed an issue where a request could not be saved while ATIPXpress was set to French if a custom date used a day later than the 12th. Custom dates are now interpreted correctly in French, so requests update as expected. |
1563866 | Fixed an issue where the Pages List text box became greyed out after the selected document was changed in Edit Pages, preventing further page entry. The field now stays available when the document selection changes. |
1571194 | Resolved an issue where the Review Flag drop-down menu did not display all available options while a consultation package was being edited. The full set of review flags is now listed. |
1573637 | Fixed a console error raised when a request was saved with HTML code entered in the manual processed-days override reason text area. The entered content is now handled safely and the request saves without error. |
1574476 | Resolved an issue in Consultation Package Edit where confirming the Page Selection window without making any change auto-selected all pages and displayed all review flags. Confirming without a change now preserves the existing selection. |
1579391 | Fixed a failure that prevented the General Configuration save operation from completing in the Collaboration Portal. Configuration changes now save successfully. |
1586168 | Resolved a mismatch in the marked-pages count shown after the Page Selection window was confirmed during an Edit Consultation action. The count now matches the pages actually marked. |
1592610 | Fixed an issue where the agency logo was missing from the Provincial Statistical Report in the HTML, Word, Excel, and CSV exports. The logo is now included in every export format. |
1593851 | Resolved an issue where the downloaded report file name remained in English while the site language was set to French. Report file names now follow the selected site language. |
1606394 | Fixed an issue where deleting one "User identification code" email template also deleted every duplicate entry of that template. Only the selected template is now removed. |
1607667 | Resolved an "Email template not found with name ‘User Identification Code’" error that appeared when a verification code was sent through "Forgot your password?". The verification code email is now sent successfully. |
1608046 | Fixed a security issue where SMTP passwords and OAuth secret keys could be exposed through browser developer tools. Only masked values are now displayed, and credentials are updated only when users enter new values. |
1616337 | Fixed an issue where table layouts changed unexpectedly during PDF conversion. Automatic table layout adjustments now apply only to HTML files. |
1617099 | Fixed the One Time Password email template to correctly replace Insert Field placeholders with their actual values before sending the email. |
1617935 | Enhanced email import to detect password-protected attachments and notify users when the attachments cannot be imported. |
1619046 | Resolved an error that occurred while signing out of PAL Configuration after a user was created. Sign-out now completes normally. |
1621878 | Fixed unnecessary blank space that appeared below the Invoice section in the invoice creation window. |
1622141 | Fixed the backlog count calculation by correcting the column mapping logic. Counts are now updated in the appropriate period columns without affecting key columns or causing runtime errors. |
1623374 | Fixed the Custom Number field to support the Enter key as expected. |
1624032 | Fixed an issue in Excel and CSV exports where the Grand Total could overlap and hide the first three data rows. Updated the total placement and removed the nested table structure causing the issue. |
1632482 | Resolved an issue where the report-viewer action buttons (Back, Print, Print All, Export, and Close) were included in the generated Word file for the Request for Documents Actions Report. The generated file now contains report content only. |
1637012 | Fixed an issue where Office of Primary Interest names containing double quotation marks (") caused errors. Removed unnecessary URL encoding from the grid data-loading process. |
1637185 | Fixed an issue where the Not Reviewed warning was incorrectly displayed for documents outside the selected Review Log section. Validation now applies only to documents within the selected section. |
1637230 | Fixed permission validation across six User Custom Report screens to ensure users with the appropriate User Custom Reports permission can access and open the reports successfully. |
1637912 | Fixed an issue where request extensions were not displayed in French after actions such as approval. Added language-specific display handling for English and French in AX sites. |
1638627 | Resolved an issue where HTML tags were displayed in the Action History Show Detail view on the French site. The detail view now renders formatted text. |
1638933 | Fixed an issue that prevented operations on Extension Logs while the French language was selected. Extension Log actions now work in French. |
1545765 | Fixed an issue where Appeal- and Complaint-type file types were missing from the File Type drop-down menu on the Provincial Statistical Report selection page. A file type now appears in the drop-down menu whenever Appear on Report is selected for it in Request/File Type administration, regardless of its case type. |
1576984 | Fixed timeout errors that occurred during request operations, such as Assign and Create, while a Statistical Report was being generated. The report queries no longer lock the underlying tables, so other users can continue working while the report runs. |
1530183 | Fixed an issue where the Number of Pages Released and Number of Pages Reviewed values entered on the Close Request screen were saved as 0 and shown as 0 on the request report. The values entered at closure are now retained. |
1544799 | Fixed a SAML SSO failure that blocked access to ATIPXpress after the Support Admin sign-in page had been used. The SAML configuration resolver was not restored once Support Admin single sign-on processing finished, so every later sign-on attempt resolved against a configuration that had no client identity provider. The resolver is now restored after Support Admin processing completes. |
1338606 | Fixed an issue where redaction codes were misaligned on a page after a left, right, or 180° rotation was applied. Page rotation is now handled consistently during OCR processing and annotation display. |
1516909 | Fixed an issue where corrupted files were skipped without notification during processing. A document that fails is now recorded in the Reject table, appears in the Failed Documents list, and is counted correctly in report statistics. |
1571419 | Fixed an issue where customized Technical Support page content reverted to the default after an upgrade. The saved Technical Support page file is now preserved during an upgrade, so the content remains intact. |
1587935 | Fixed an issue where the header, footer, and page number font sizes on redacted pages appeared smaller than those on non-redacted pages. Font sizes are now consistent across both. |
1588150 | Fixed an issue in the Request for Document report where the As of date filter for Request Status did not filter the data by the selected date. Results are now filtered as of the chosen date. |
1588907 | Fixed an issue where single sign-on login logging recorded the proxy's internal IP address rather than the user's. The client IP address is now resolved from the forwarded request headers. |
1589074 | Fixed an issue where a date custom field swapped the month and the day when saved. The default date format is now standardized to MM/DD/YYYY. |
1590460 | Fixed an issue where the Request for Documents list extended beyond the page boundaries. The list now stays within the page and provides a scroll bar when required. |
1591621 | Fixed an issue where the Request Type field remained disabled after a file was uploaded while creating a request. |
1593473 | Fixed an issue where the Create Request page could fail to load after a requester type change left an invalid Delivery Mode selected. |
1593540 | Fixed the User Identification Code email template so that every supported placeholder is populated, rather than only the Code and Application Name fields. |
1601407 | Fixed the Request Progress Report so that the Pages Released and Pages Reviewed counts cover all release formats rather than Paper only. |
1604690 | Fixed an issue where the Cost Sheet pop-up displayed excessive blank space. The pop-up now sizes itself to fit its content. |