Product Enhancements
Replace Captcha with reCAPTCHA
reCAPTCHA verification is now in place across key PAL actions to prevent automated and fraudulent submissions. Built on Google-approved standards, it ensures secure and consistent validation across the platform. With clear messaging and proper expiry handling, users get a smooth and reliable verification experience every time.

1. Navigate to PAL Configuration, then select Messages.
2. From the Message Type drop down list, select Login.gov Verification Failure Page.
The WYSIWYG editor is pre-populated below the note.
• On first-time selection the editor displays the system-defined default body content shown below.
• On subsequent selections the editor displays the most recently saved body content.
3. Edit the body content using the available tools provided by the Editor program. Replace the placeholders [User’s Agency Name] and [User’s Agency Contact Email / Phone Number] with your agency’s information.
4. Click Save.
If the save operation fails (for example, due to a network error, server timeout, or backend error), the existing PAL Config error notification is displayed. The body content you entered is retained in the editor, so no work is lost — fix the issue and click Save again.
Login.gov Requires a Failure To Proof Site
PAL Config Administrators can now easily set up a dedicated Login.gov Verification Failure Page right from the Messages section. So, when identity verification fails, requesters instantly see a clear, agency-specific message.

1. Navigate to PAL Configuration, then select Messages.
2. From the Message Type drop down list, select Login.gov Verification Failure Page.
The WYSIWYG editor is pre-populated below the note.
• On first-time selection the editor displays the system-defined default body content shown below.
• On subsequent selections the editor displays the most recently saved body content.
3. Edit the body content using the available tools provided by the Editor program. Replace the placeholders [User’s Agency Name] and [User’s Agency Contact Email / Phone Number] with your agency’s information.
4. Click Save.
If the save operation fails (for example, due to a network error, server timeout, or backend error), the existing PAL Config error notification is displayed. The body content you entered is retained in the editor, so no work is lost — fix the issue and click Save again.
Security Updates
We’ve made the following security updates in this version of FOIAXpress PAL:
ID | Description |
|---|---|
1459746 | Implemented fixes for all critical vulnerabilities identified during the Vulnerability Assessment and Penetration Testing (VAPT) of the PAL module to strengthen system security and mitigate potential risks. |
1473544 | Addressed VAPT findings in PAL Configuration by remediating security vulnerabilities and strengthening compliance, ensuring a secure and stable application environment. |
1505249 | Removed the deprecated PortalXpress project references from PAL and the FX Dashboard Service, eliminating reliance on outdated, unsupported components and ensuring both services build, deploy, and run cleanly using only supported dependencies. |