Product Enhancements
Consultation Check at Document Delivery
FOIAXpress now checks consultation status before you deliver documents. When you initiate Deliver Documents, the consultation status of every selected document, section, and page is checked against the Consultation Review Log. If everything is closed, the delivery continues without an additional step. If any consultation is still open, a confirmation message lists the affected items by Consultation Name, Program Office, Document Name, Section, and Impacted Pages, and you select Deliver Anyway to continue. The check informs you; it never blocks the delivery.
To review consultation status and deliver documents:
In Document Management, select the documents, sections, or pages you want to deliver
Click Deliver Documents
Review the consultations listed, then click Deliver Anyway to continue

A consultation counts as open until it is marked completed through Take Action, in both the Send via Email/Save and Via Collaboration Portal modes. Every delivery now carries a Consultation Status value in the Document Delivery Log. Select it to view the consultations that were pending at the time of that delivery. That record does not change if those consultations are later closed or edited.
Page Marking Indicator and Consultation Details in the Document Viewer
#ID 1617777
Pages marked for consultation now carry a visible indicator in the Document Viewer, so an analyst reviewing thousands of pages can tell at a glance that a page is marked and identify the Program Offices it is marked for. The Mark for Consultation dialog has also been restructured to make the outcome of each action unambiguous.
A tag icon appears beside every marked page in the Document Viewer tree. Selecting the tag icon displays a read-only list of each Program Office the page is marked for, most recent first.
.png?sv=2026-02-06&spr=https&st=2026-10-10T06%3A22%3A20Z&se=2026-10-10T06%3A40%3A20Z&sr=c&sp=r&sig=CYB%2B54bcXntMYifR1oMxpuw9MIpMUXQKWQVLVPAI9zc%3D)
The Program Office selection inside Mark for Consultation is now a table with a checkbox, the office name, and a Marked or Unmarked status for each row, together with a search field that filters the list by name. A Program Office shows Marked only if the page is marked for that office on every page currently targeted; a partial selection shows Unmarked.
To review which Program Offices a page is marked for:
Navigate to Document Management and select the document in the Review Log.
Locate the page in the Document Viewer tree. A tag icon indicates that the page is marked for consultation.
Select the tag icon to display the list of Program Offices the page is marked for.
To mark or unmark pages for a Program Office:
Right-click the folder or cabinet and select Mark for Consultation
Select the pages you want to change
Select the Program Offices in the table, using the search field to narrow the list if required
Select Mark or Unmark to stage the change
Select Done to save the change, or Cancel to discard it
Unified "From" Address Behavior for Microsoft 365 Email
#ID 1566640
FOIAXpress now applies a single, administrator-configured sender identity to outbound email sent through Microsoft 365, rather than letting each email-producing area resolve its own "From" address. Administrators authenticate outbound mail per email domain in one place and set the sender identity in another, and that resolved identity is then applied consistently and read-only wherever email is sent. This removes the inconsistent outbound mail identity that previously differed between delivery modes, and closes the spoofing and deliverability risks created by manual "From" edits.
The administrator configuration surfaces — Authentication Mode and the Email Domain Credentials table in Mail Server Configuration, and the Global Email Address sender option in Correspondence Configuration — were introduced in v26.4.1.0. This version applies the configured identity at send time and adds automatic recipient batching.
To review the sender identity applied to outbound email:
Navigate to System Administration > Mail Server Configuration
Set Authentication Mode to Microsoft 365 Email
Confirm that each approved email domain has a complete credential row (Email Domain, OAuth Client ID, Secret Key, Client Secret Expiry Date, Tenant ID). Select + Add Domain to register an additional domain, or the row delete (✕) control to remove one.
Set the Recipient Limit to the maximum number of recipients permitted on a single send, then select Save
.png?sv=2026-02-06&spr=https&st=2026-10-10T06%3A22%3A20Z&se=2026-10-10T06%3A40%3A20Z&sr=c&sp=r&sig=CYB%2B54bcXntMYifR1oMxpuw9MIpMUXQKWQVLVPAI9zc%3D)
Navigate to System Administration > Correspondence Configuration
Select the required value in Sender's Default Email Address (From), then select Save
.png?sv=2026-02-06&spr=https&st=2026-10-10T06%3A22%3A20Z&se=2026-10-10T06%3A40%3A20Z&sr=c&sp=r&sig=CYB%2B54bcXntMYifR1oMxpuw9MIpMUXQKWQVLVPAI9zc%3D)
Key behavior in Microsoft 365 mode:
The resolved sender identity is applied across every email-producing area, including Correspondence, Request for Document (email mode), Report Scheduler recipients, report email exports, License Information, Document Management document delivery, and lifecycle notification emails.
Wherever a "From" value is displayed, it is read-only, and the free-text entry and "Other Email" options have been removed; the lock is enforced on the server so it cannot be bypassed from the screen.
Selecting Microsoft 365 Email hides the User Email and User Action Office Email sender options, so all outbound mail resolves to the configured global address.
A single Recipient Limit applies across all configured domains. An email exceeding the limit is partitioned automatically into compliant batches with no user action; an email within the limit is dispatched as a single send. Recipients spanning multiple domains on one email are partitioned against the same global limit.
Outbound mail authenticates against the credential row matching the domain of the resolved "From" address.
Each Email Domain value must be unique.
A credential row whose Client Secret Expiry Date has passed is flagged, so credentials can be renewed before sends begin to fail.
A resolved "From" address whose domain does not match a configured domain is validated in the background job, which records a validation error in the Email Log and marks the email as failed rather than reporting a false success
NOTE: The Global Email Address behavior applies to Microsoft 365 authentication only. SMTP email sending is unchanged in this version, and the existing SMTP sender behavior continues to apply. The Set Reply-To to User's Email Address setting is displayed in Correspondence Configuration but is not yet active in this version. Replies are not routed to the sending user's address.
Faster Custom Request Report Generation
#ID 1634934
Custom Request Report generation has been optimized across the select fields that previously slowed it down the most. Instead of recalculating values for every request at run time, the report now reads pre-calculated values maintained by the system - stored values for closed requests, and for Request Age and Total Days on Hold, values maintained by the daily Request Age calculation job and the backfill job. Values that have no stored equivalent, such as those for requests still in progress, continue to be calculated at run time. The remaining fields - requester addresses and extension related fields - gained optimized queries. Report output and values are unchanged; only generation time improves.
The optimized select fields are the following:
Request assignment user fields - Secondary Users and the three related user fields, for both the Include and Exclude options
Document page count fields - # of pages attached to request folder, # of documents delivered, Total # of pages in a request, Total # of pages in the review log, and the related field that excludes redacted pages
Payment Date, Refund Amount, Extension Days, and Documents Released
Request Age and Total Days on Hold
Requester Billing Address and Requester Shipping Address
Extension related fields
Two accuracy refinements accompany the change. An As Of date that matches the current date is now recognized by comparing actual dates rather than the displayed text, so a different date format no longer forces the slower calculation. A request with no stored hold days value now has the value calculated at run time and reported correctly, in place of the 0 that was previously shown.
Security Updates
We’ve made the following security update in this version of FOIAXpress Portal:
ID | Description |
|---|---|
1622406 | Addressed an authorization bypass that allowed request pages to be reached by direct URL regardless of the user’s permission on that request. The user’s access to the request is now validated before the page loads. |
1622408 | Addressed a broken access control vulnerability in Document Management. The user’s permission on the requested folder or section, including cabinet view rights, reading room access, or request assignment, is now verified before documents are served, preventing unauthorized access. |
1622416 | Addressed a broken access control vulnerability on the Annual, Audit, and Custom report pages. Server-side permission checks are now enforced, preventing users without the required report permissions from accessing these pages directly. |
1622417 | Addressed a stored cross-site scripting (XSS) vulnerability in request Notes. Note content is now HTML-encoded when displayed, and note input is validated when saved, preventing malicious scripts from being stored or executed. |
Bug Fixes
We’ve addressed the following bugs in this version of FOIAXpress:
ID | Description |
|---|---|
1622406 | Fixed a security issue where SMTP passwords and OAuth secret keys could be exposed through browser developer tools. Only masked values are now rendered, and credentials are updated only when users enter new values. |
1616337 | Fixed an issue where table layouts changed unexpectedly during PDF conversion. Automatic table layout adjustments now apply only to HTML files. |
1617099 | Fixed the One-Time Password email template to replace Insert Field placeholders with their actual values before sending the email. |
1617935 | Enhanced email import to detect password-protected attachments and notify users when the attachments cannot be imported. |
1621908 | Fixed a timeout that prevented the Response Letter from opening for requests with large redacted documents. Improved the redacted-page counting performance while preserving the existing counts. |
1622141 | Fixed the backlog count calculation by correcting the column mapping logic. Counts now appear in the appropriate period columns without affecting key columns or causing runtime errors. |
1623374 | Fixed the Custom Number field to support the Enter key as expected. |
1624032 | Fixed an issue in Excel and CSV exports where the Grand Total overlapped and hid the first three data rows. Updated the total placement and removed the nested table structure causing the issue. |
1637012 | Fixed an issue where Office of Primary Interest names containing double quotation marks (") caused errors. Removed unnecessary URL encoding from the grid data-loading process. |
1637185 | Fixed an issue where the Not Reviewed warning appeared for documents outside the selected Review Log section. Validation now applies only to documents within the selected section. |
1637230 | Fixed permission validation across six User Custom Report screens. Users with the appropriate User Custom Reports permission can now access and open the reports successfully. |
1637058 | Fixed an issue where a Request Report generated as a background job was not recorded in the audit trail. Background report generation is now captured in the User Actions report, so report activity is fully traceable. |