Middleware Documentation deprecated

Welcome to the documentation about the inner workings of the Java-based middleware platform of OX App Suite. This technical documentation covers articles about different topics and features, grouped by different subtopics on the left.

The latest notable changes of the middleware can be found below. All notable changes to this project will be documented in this file.

8.52.191 - 2026-07-29

Added

  • PBSR-1717: Cross-Context Sharing, Deputy and Collaboration 78335af1
    • SCR-1730: Added New Bundles for Cross-Context Sharing
    • SCR-1731: Added the "xctx_liaisons" Cross-Context Liaison Registry Table and Create-Table Update Task
    • SCR-1732: Added a Permission-Context Column to the Folder-Permission Tables
    • SCR-1733: Restructured the Folder-Permission Primary Key to Include the Context Column
    • SCR-1734: Deputy Storage Table Qualifies the Deputy Entity With Its Context
    • SCR-1735: New Configuration Options for Cross-Context Sharing
    • SCR-1736: Folder Permissions Accept and Return Cross-Context Principal Identifiers
    • SCR-1737: New Read-Only Contact Field Exposing the Cross-Context Qualified Identifier
    • SCR-1738: Cross-Context Deputy via Qualified Identifiers (Deputy HTTP API)
    • SCR-1739: Cross-Context Principal Representation Over WebDAV / CalDAV / CardDAV
    • SCR-1740: New Administrative REST Endpoints for Cross-Context Liaison Audit and Purge
    • SCR-1741: Cross-Context Deputy in the Admin RMI Provisioning API
    • SCR-1742: Cross-Context Deputy in the Admin SOAP Provisioning API
    • SCR-1743: Cross-Context Sharing Access-Control Behavior
  • SCR-1758: New Command-Line Tool claimfolderadmin to Claim/Elevate a Folder Administrator on Public Folders 79cc9a1d
  • SCR-1776: HTTP API for proxy servlet - PUT /proxy?action=getUris 6d902a9f
  • SCR-1781: Micrometer metrics and access-log rotation for the Jetty HTTP engine 8f420fdc
  • SCR-1782: Optional cleartext HTTP/2 (h2c) for the Jetty HTTP engine d4040ba1
  • SCR-1787: Apache HttpClient 5 platform bundles and HttpClient-5-based managed HTTP client service efaff1a9
  • SCR-1797: Configurable additional parameters for OAuth token exchange (scheduled + snoozed mail) 5b87aec8 2370936b
  • SCR-1798: List built-in spam handler names in secondary account CLI help 484883c2
  • SCR-1801: New Administrative REST Servlet for Querying Free/Busy Data 03c3ecd8
  • core#527: Set personal folder owner for folders below personal Infostore folder f3ea7255
  • core#547: Persisted-ACL end-to-end case to phantom mail folder share reproducer e62fded6
  • support#1568: Values-driven topologySpreadConstraints, PDB unhealthyPodEvictionPolicy and HPA support to core-mw chart 57c47f38

Changed

  • Drop the legacy "folder" mapping from the shared-account mail JSlob 81c83bcd
  • Keep SQL exception identity across RMI-safe exception wrapping b3c047b2
  • SCR-1746: Upgraded third-party libraries 29a8aaf7
  • SCR-1747: Migrated JAX-RS from Jersey 2.17 to Jersey 3.1.x (jakarta.ws.rs) a32df983
  • SCR-1748: Load mails referenced from PIM attachments or Infostore files 648f20d0
  • SCR-1749: Upgraded Grizzly to 5.0.2 422c6ca9
  • SCR-1750: Upgraded Netty libraries to v4.2.15 and Lettuce to v7.6.0 6d5958cd
  • SCR-1752: Upgrade Micrometer to 1.17 (migrate Prometheus registry from simpleclient to prometheus-metrics) 864210a6
  • SCR-1754: Migrated S3 file storage to AWS SDK for Java v2 5146ad08
  • SCR-1755: Upgraded Kubernetes Java Client (fabric8) to v7.8.0 9e985e13
  • SCR-1756: Jetty-based HTTP engine as a switchable alternative to Grizzly 2226a59c a383e7f6
  • SCR-1757: Markup-aware hard truncation of HTML content for "view=raw" with "max_size" a4a1c0aa
  • SCR-1759: Seal proxy registration URLs via ObfuscatorService instead of static DES key 8454ef40
  • SCR-1761: Apply Compact Object Headers JVM flag independently of custom javaOpts.other in core-mw chart 1e573bc3
  • SCR-1762: Upgraded Liquibase to v5.0.3 and OpenCSV to v5.12.0 38a03d29
  • SCR-1763: Upgraded OkHttp to v5.4.0 900b24c7
  • SCR-1765: Upgraded BouncyCastle to v1.84 18b58bc8
  • SCR-1766: Upgraded webauthn-server-core to v2.9.0, reactor-core to v3.8.6 and zero-allocation-hashing to v2026.0 d1967265
  • SCR-1767: Upgraded ROME to v2.1.0, jaudiotagger to v3.0.1, Caffeine to v3.2.4, GeoIP2 to v5.1.0 and libphonenumber to v9.0.34 7c43973a
  • SCR-1768: Upgraded ez-vcard to v0.12.2 2a726d88
  • SCR-1769: Upgraded lib-recur to v0.17.1 2b6e81d0
  • SCR-1770: Upgraded Apache XML-RPC to v6.1.0 c83261e5
  • SCR-1771: Upgraded Dropbox Core SDK to v8.0.1 fa2ebebe
  • SCR-1772: Upgraded Box Java SDK to v4.16.4 2c5c7e29
  • SCR-1773: Upgraded OWASP ESAPI to v2.7.0.0 7bc15a66
  • SCR-1774: Upgraded Hazelcast to v5.7.0 9946ceb9
  • SCR-1775: Upgraded jOOX to v2.0.1 8b39febd b7cd4ada
  • SCR-1778: Mandatory 'objectid' mapping for LDAP contacts providers f69d0d8f
  • SCR-1780: Upgraded Apache CXF to v4.2.2 and Metro JAX-WS runtime to v4.0.5 77016bd7
  • SCR-1783: Removed the stateful Dovecot Push implementation abb9c6cc
  • SCR-1784: Upgraded Google client stack and Firebase Admin SDK 2306042d
  • SCR-1785: Upgraded OpenSAML to v5.2.3 9bc18133
  • SCR-1786: Upgraded Apache PDFBox to v3.0.7 00d692af
  • SCR-1788: The client-side prepared statement cache defaults are raised afa5b536
  • SCR-1792: Upgrade Cassandra driver to Apache Cassandra java-driver 4.19.3 d97da567
  • SCR-1793: Harden Redis connection lifecycle against stale/orphaned connected clients da3f1752
  • SCR-1794: Upgrade Box SDK to generated Box Java SDK 10.15.1 (com.box.sdkgen) 9dfa0e84
  • SCR-1795: Upgrade target platform to Jakarta EE 11 REST stack (Jersey 4.0.2 / jakarta.ws.rs 4.0 / HK2 4.0.1) 07afc3a2
  • SCR-1796: Upgrade io.netty to 4.2.16.Final 3e4d3789
  • SCR-1799: Optional Grizzly WebSocket side-car alongside the Jetty engine cd6804a0
  • Stage on-demand gRPC jars via the eclipse/cleanEclipse IDE-prep tasks 781c9bb3
  • Transport shared-account scheduling mail via the shared mailbox e889c4d6
  • Updated core-mw chart dependencies 03e24cdd
    • Updated Gotenberg image to v8.34.0
    • Updated Gotenberg chart to v1.22.0
    • Updated Collabora image to v26.04.2.3.1
    • Updated Collabora chart to v1.3.0
  • Aligned contacts account handling with its calendar counterpart 80ea4e7c
  • Build gRPC provisioning jars on demand instead of committing them 39ba450e
  • core#463: Provide details about stored event on out-of-sequence errors 811774de
  • core#546: Remove the time-based Entity2ACL look-up caches 315746c9
  • support#1561: Modernize CalDAV/CardDAV documentation and DAV routing diagrams 37c0d616

Fixed

  • CAL-5001: Run folder name checks before opening the create transaction 081046d5
  • Database folder cache lost stale-re-insert protection (unguarded region) and left in-memory replicas after group-member invalidation b16b11c8
  • Flaky statisticsAreMaintained() rejected by the capacity-less SynchronousQueue under load e4707582
  • Folder cache value codec overwrote a permission's numeric entity identifier with its entity info rendering such folders non-deserializable dc0ece1c
  • Groovy-interpolate registry/project/imageVersion in mirrorImage skopeo copy step 08212394
  • Load-through re-fetch loop spun forever on a non-deserializable Redis cache entry instead of self-healing it 4d417f64
  • Missing command-line tool scripts and inaccurate CLT documentation b5a39603
  • PBSR-1766: Indicate correct account prefix for folder ids in mail filter rules of non-primary accounts 996b650b
  • Re-align the Jetty Bundle-ClassPath with the 12.1.11 embedded JARs 01778a36
  • Register the globaldb utf8mb4 package in the Liquibase custom-change manifest header ebadfd63
  • SCR-1798: Provision per-account spam handler so "Mark as Spam" works for secondary/functional mailboxes c6b7cbd5
  • Set Jersey context class loader when building JAX-RS client 8328d211
  • core#532: Hardened the Jetty engine's servlet registry 25edb5dd 432be9cf 138847cd
  • Detect synthetic sessions by origin, not instanceof a5eb1a80
  • Reject corrupt ZIP/OLE2 documents before Collabora conversion in mail export previews 984c66ac
  • Rename changesharedaccount CLI tool documentation and help text to updatesharedaccount 4d5acd2a
  • Select chart release by prefix instead of trusting GitHub releases/latest 9059b889
  • Subscribe/unsubscribe for shared mail folders via share/management d298977a
  • Superfluous quoting of FEATURE parameter values in CONFERENCE property d1ec4beb
  • Prevent message alarm reminders from getting stuck until node restart 302a07df
  • core#552: Never let a single broken push client configuration abort start-up of com.openexchange.push.clients 464a931d 44ce38a1
  • core#553: Skip the JDBC reserved-word probe on MariaDB a9888f9e
  • core#555: Pin the gRPC protobuf export and slim down the framework jar shading 61d6c742 bc080324
  • core#556: Bind a task marker for HTTP requests dispatched on threads without one 7330fd8c
  • core#557: Sort shared calendar folders contributed by multiple calendar accounts 6e891bd7
  • support#1129: Tolerate missing parent folder during IMAP default folder check 0d30b71f
  • support#1438: Keep emitting user_id 0 for non-user contacts to preserve HTTP-API compatibility 9cdcae85
  • support#1522: Reuse GETACL results across folder-tree rebuilds 01987eb4 a5c7ad7b
  • support#1523: Apply healthCheckIntervalMillis to its own pool property instead of overwriting responseTimeoutMillis f0b3fb51
  • support#1531: Never skip sender validation when transmitting via action=new 5ddbb75b
  • support#1540: Limit the number of orphaned cookies removed per HTTP response to stay below the engine's response header limit 00b2f6da
  • support#1542: Populate internal user id consistently in results from LDAP contacts provider 824b5e04
  • support#1543: Preserved shared/deputy mailbox visibility with consolidated LIST-EXTENDED folder listing c37d9d7f f52d24ba 5b2adabc af6a4788 1256e580
  • support#1548: Exclude guest users from context user count for MaxUser restriction 70c0ab4a
  • support#1551: Restored xs:date/nillable for SOAP birthday and anniversary 3675981d
  • support#1552: Reject central-training spam handlers for external mail accounts 110aa808 9156b62e
  • support#1553: Bump About-box default copyright year to 2026 5f0cad7c
  • support#1554: Re-add org.glassfish.jersey.client.spi import to imageconverter.client bundle f2a79143
  • support#1555: Refuse applying incoming scheduling messages that collide with differently organized events e9c5cd22
  • support#1560: Drop RFC 2965 $-prefixed framing cookies in servlet bridge 101b317e
  • support#1562: Store DB-assignment and schema-update-state cache entries as plain per-context/per-schema keys instead of one global group hash 66cd076d
  • support#1564: Reference iMIP mail parts via "cid" URLs in analyzed event attachments 319743e9
  • support#1567: Replace CREATE TABLE ... AS SELECT with plain DDL + INSERT ... SELECT 3cb4d4e3
  • support#1577: Throw FOLDER_NOT_FOUND instead of NPE for missing calendar folder c4e1b9fb
  • support#1578: Guard composite LDAP filter construction against non-representable search term operands 537dac92
  • support#1582: Single-pass, escaping URI token compression to keep proxy registrations round-trip safe 88f529e2
  • support#1584: Propagate affected folders in folder map invalidation messages so remote nodes drop them for every user f23f815d fbbd92ec
  • support#1585: Report exact attachment sizes for composition space drafts a65c148a
  • support#1592: Run core-mw update job on dedicated ServiceAccount without API token automount 3d664352
  • support#1598: Always provide the mail's display date, also for nested messages d3220177

8.51.89 - 2026-07-01

Added

  • INU-5112: Checktablelayout tool to reconcile schema layout against CreateTableService reference 2dec0029
  • PBSR-1688: Include 'Sensitivity' header in scheduling and notification mails if applicable 82186cff
  • SCR-1583: Per-user Filters for LDAP Contacts Provider b1993da5
  • SCR-1714: PBSR-1613: REST Interface to Retrieve Effective Shared Account Permissions 40aab2eb
  • SCR-1726: Sanitize_css" parameter for /mail?action=get d0570eb0
  • Virtual threads for the Grizzly HTTP worker pool and request-driven fan-outs 9ffbb685
  • Made user provisioning site-aware c95f14b8
    • This includes a grpc connection between sites
  • Return oidc id token to edge-auth 448ffaf3
  • "replace_external_images" parameter for /mail?action=get 4cc34579
  • Documentation on outgoing calendar scheduling messages and notifications 875c3a20
  • Handle shares via external authentication service af092df1
  • Added new scopes for basic access and elevated access dd5768e9
    • Introduced the scopes "basic" which allow access to all basic functionality and "elevated" which allows access to everything including password changes and similar.
    • The basic scope is used as a fallback if no scope is defined for edge authentication.
  • External auth redeemToken action 4267a0ed
  • GRPC implementation for listBytypes for OXUser 62a778b7
  • Oidc login handler, common bundle and new endpoint 8aa2ae70
  • Poc for external auth login servlet 97f597fa
    • Added: added oauth in flight implementation
    • Added in flight handler with basic auth impl
  • Register rmi services as Remote + some cleanup c0b33583
    • Add o-x-reseller-grpc package to list
  • Translation updates 8.50 f6310575
    • all languages but Latvian
  • core#353: Introduced cross site bundle and push routing 0ef27317
    • introduced new bundle co.ox.multisite
    • introduced new MultiSiteService
    • implemented routing for dovecot push messages (mail and calendar)

Changed

  • Export com.openexchange.admin.rmi.exceptions from freshly introduced com.openexchange.rmi.common, adding new bundles to seperate (grpc) provisioning between 'admin' and 'non-admin' tools to establish a cleaner packaging and keep the option to disable the admin feature. 1cd6d392
  • SCR-1724: Upgraded OSGi core library in target platform (com.openexchange.bundles) 1b56dd02 06f4d917 e5ddf1f2
  • External auth refactorings cefbccf2
    • Simplified the response json structure
    • Some code cleanup + renamings
    • Added missing javadoc
  • Make Grpc core bundles extensible 72903454
    • introduced extension interfaces which allows to separate bundles. This allows more flexible packaging
  • Require c.o.multisite.enabled for grpc based communication bad49b39
    • To prevent excessive database load I adjusted the delegate logic with the AbstractSiteAwareService to check the c.o.multisite.enabled property first
  • Some renaming + javadoc + minor adjustments cf6b7f5c
  • Use correct redirect for shares with password e0e2c28d
  • core#520: Bound OXWorker platform-pool default and enable DB pool waiter cap 1d913f13
  • support#1329: Add owner-trace diagnostic logging for filestore snippets 2d7c14a5

Fixed

  • CP-572: Avoid full Redis key-space scan when closing sessions by user/context filter 77a858ed
  • INU-5112: Utf8mb4 conversion skips columns inheriting their charset from the table default 8857c54c
  • IOL-2841: Reconnect mail access when attachment handling takes too long 1fdfa778
  • Re-add UpdateTaskV2 import lost in rebase 5c3ee8f9
  • Liquibase migration failed on MariaDB with "Unknown column 'EXPRESSION'" e85b06b0
  • Minor preparations before merging activeactive into main 2cd83247
  • Orderly determine existingUISettingsSecret checksum and document existing*Secret values b16670bd
    • The existingUISettingsSecret was missing from core-mw.existingSecretsChecksum, so content changes to that secret did not trigger a rolling restart unlike the other existing* secrets. Added the missing block.
    • Also added a guide on the existing*Secret values to the chart README, clarified the additive-vs-replace behavior in the values.yaml comments, and bumped the chart version to 6.22.2.
  • Addressed some grpc converter issues c29c62ee
  • Adjusted packaging for removed request analyzer 327c0ffb
  • Adjusted tests 60be0b5c
    • Reduce wait time for no reply checks
    • Add timeout to avoid race condition for second precision checks
  • Did some grpc based refactoring/cleanup 6ce2b25f
    • Simplified the grpc based extension registration by removing all unnecessary trackers
  • Pin the JDOM SAX parser to Apache Xerces for deterministic XML parsing b25fe46d
    • JDOMParserImpl built its SAXBuilder via the default engine, i.e. SAXParserFactory.newInstance(). In the OSGi runtime that JAXP discovery resolves - depending on the thread-context classloader - to either the JDK built-in parser or the repackaged Apache Xerces (com.openexchange.xerces), which disagree on how a disabled-but-referenced external entity is handled. That non-determinism surfaced as a flaky DAV REPORT status (e.g. com.openexchange.dav.caldav.bugs.Bug30359Test intermittently getting 400 instead of 207). Pin the parser to Apache Xerces explicitly so the behavior is deterministic and independent of the JDK version; the XXE hardening (empty entity resolver, external entities and external DTD disabled) is unchanged.
  • Remove duplicate tracking d2284710
  • Remove legacy remote registration a2046069
    • fix: Breaking recursive calls of getService for optional gRPC services, some refactoring
    • Remove null==value check before setting valueSet bool flags
    • Fix unmarshalling of proto map for userAttributesMap in toRmiUser() converter
    • Adjust segmenter endpoint definition to match actual segmenter service
    • Remove old RMI registrations which shall be replaced by site-aware RMI
    • Make Site-Aware Services always start. Remove remaining Remote registrations
  • Some additional cleanup + refactoring dc6c8ac4
    • Remove session ids from response
    • Use login instead of formlogin
  • Some more hardening for edge authentication 06d74ceb
    • Adjusted form login handling
  • core#516: Deny Write-Access for Guest Users in Public Calendar Folders 370211ba
    • SCR-1717: Deny Write-Access for Guest Users in Public Calendar Folders
    • SCR-1718: Update Task to Downscope Unsupported Guest Permissions
  • core#522: Normalize ACL rights before checking their equality 7440cee8
  • core#523: Make del_user recovery-data insert idempotent via ON DUPLICATE KEY UPDATE to allow user deletion despite stale recovery rows 562f3039
  • core#524: Take over intermediate participation status from incoming COUNTER proposals c552a1e6
  • support#931: Data: URL inline images rendered with empty src in display path 473e7be9
  • support#1148: Recover attachment file name truncated at first space 16b72aea
  • support#1439: Calendar notifications not sent for delegate edits on shared calendars b9464aea
  • support#1440: Reply set wrong From/To for ambiguous alias on IDN domain d1762f84
  • support#1467: Merge schema lists in Java to avoid collation mismatch in update task listing 94ab55c0
  • support#1474: Skip non-applicable deputy modules on read instead of failing with DEPUTY-0006 919fb0e0
  • support#1482: Recover from read-only replica after Redis Sentinel fail-over 54a1f7e8
  • support#1495: Retry/back-off for retryable mail access errors when transporting scheduled mails f12e1b27 63942dd4 182a4592
  • support#1501: Stop DB heart-beat after a failed keep-alive instead of retrying on a dead connection 38628068
  • support#1504: Mimic Browser access to external image protected by Akamai 982440ab
  • support#1506: Delete db_cluster child row before db_pool parent on database unregistration 0386d332
  • support#1515: Make a failed scheduled-mail failure-notification visible 395d2f12
  • support#1517: Add opt-in overload protection for cache-outage DB stampedes 54ebb829
  • support#1518: Quota retrieval fails on global DB due to missing committedFiles column 926e6efa 1614de9d
  • support#1519: Clarify CLI error when provisioning credentials are missing 320d7f7e
  • support#1521: Timezone-dependent off-by-a-day in IMAP date search e3fa8907
  • support#1522: Reuse one IMAP connection per endpoint when serializing folder counts 95ebf75c
  • support#1524: Task notification mail labels medium priority as "Normal" instead of "Medium" 6f60154d
  • support#1527: Task notifications not sent for attachment changes 75ebfd7a
  • support#1531: Validate From/Sender ownership on mail bounce d2de16b5

Removed

  • Deleted obsolet request analyzer test 352a8ce3
  • Removed com.google.common.collect export that caused cyclic imports 0e1b8b45
  • Removed obsolet request analyzer framework 82a0bace

8.50.112 - 2026-05-27

Added

  • PBSR-1476: Expose 'io.ox/core//categories' JSlob from shared account entities 920bd605
  • PBSR-1576: Expose setting for 'Sent' folder preference of shared accounts bddce078
  • PBSR-1591: Expose simple overall "unread" indicator for mail account root folders if supported f9ed32e9 b75e0d24
    • SCR-1692: Additional Field 'com.openexchange.imap.rootFolderStatus' for Mail Account Root Folders
  • PBSR-1677: Overall "set" Method to Apply all Shared Account Permissions for Target cf0d1462 ac1ad896
  • PBSR-1599: New Action 'hasActive' in Module 'mailfilter/v2' d1045b37
    • SCR-1695: In order to get a quick information if there are currently specific mail filter rules active or not for an account, the new action hasActive is introduced in module mailfilter/v2 of the HTTP API
  • PBSR-1564: User can send Automatic Email Replies for every received email bdc10346
    • SCR-1696: New Configuration Property 'com.openexchange.mail.filter.options.vacation.minimumInterval.seconds' has been introduced
  • SCR-1711: Add validateSession mail action for the JMAP-IMAP proxy e3c0e9d0
  • Upgrade Grizzly 2.4 → 4.0.2 + jakarta.servlet bridge-only consolidation 1745cb3e
  • "davx5manual" onboarding scenario for manual DAVx5 Select setup b9800ad2
  • Documentation for com.openexchange.keystore.k8s.* properties 67dc6ab9
  • Documentation for customizable email templates 9748cca3
  • Expose "davx5" capability when both DAVx5 onboarding scenarios are enabled 23b2611a
  • HTTP API action mail?action=getByGuid to resolve a mail by backend GUID 864e73ec
  • Resolve plist signing keystore via KeyStoreService for k8s secret rotation e191431c
  • Translation updates version 8.49: cs_CZ, da_DK, de_DE, el_GR, en_GB, es_ES, es_MX, fi_FI, fr_CA, fr_FR, hu_HU, it_IT, ja_JP, lv_LV, nl_NL, pl_PL, pt_BR, ro_RO, ru_RU, sk_SK, sv_SE, tr_TR, zh_CN, zh_TW 942eeb36
  • support#1004: Optional aggressive ACL cleanup when revoking a deputy permission 2a854637

Changed

  • PBSR-1591: Rename folder field column from "com.openexchange.imap.rootFolderStatus" to "com.openexchange.mail.rootFolderStatus" cb5f4f9c
  • core#462: Introduced trace logging across free/busy pipeline f00d8b98
  • core#497: Introduced simple SMTP connection pool & Use PIPELINING extension for MAIL-FROM and RCPT-TO commands c00c83b6 1770e13b a439e916
  • support#1247: Added TRACE logging for event data loading and post-processing be119c3e
  • support#1363: Added possibility to log all connection-using thread on "too many connections" error 67be8e8d b033b7b4 47b0fbc2
  • support#1402: Register singleton service com.openexchange.hazelcast.DataMemberService to advertise at least one data member is available in Hazelcast cluster 3f63c74a

Fixed

8.49.91 - 2026-04-22

Added

  • PBSR-1603: Support migration of user accounts with deputy permissions to shared accounts 4ad04287
  • SCR-1693: New Configuration Property 'com.openexchange.saml.validationClockSkew' 7ccc3391
  • GUARD-520: Support for hidden recipients in PGP messages 9f6d3b17
  • Add DAVx5 Select integration for Android CalDAV/CardDAV onboarding ccf3cfde
    • SCR-1678: Added new bundle com.openexchange.davx5.rest for DAVx5 Select integration
    • SCR-1679: Removed Sync App onboarding bundle
    • SCR-1680: Introduced new REST endpoint for DAVx5 Select configuration
    • SCR-1681: Added DAVX5 constant to BuiltInProvider enum and deprecated SYNC_APP
    • SCR-1682: Replaced Sync App with DAVx5 Select in Android onboarding scenarios
    • SCR-1683: Added configuration properties for DAVx5 Select integration
  • German translation 8.48 d687985d
  • Translation updates 8.48: cs_CZ, da_DK, el_GR, en_GB, es_ES, es_MX, fi_FI, fr_CA, fr_FR, hu_HU, it_IT, ja_JP, lv_LV, nl_NL, pl_PL, pt_BR, ro_RO, ru_RU, sk_SK, sv_SE, tr_TR, zh_CN, zh_TW 7178c4b1

Changed

  • Added command-line tool dovecotpushunregisterall to unregister Dovecot Push for all users 854927a7
  • Added support for informal language preference - /appsuite/platform/core/merge_requests/4480 bd7dc3e3
  • Build descriptive app-specific password names during DAVx5 onboarding c030624e
  • SCR-1689: Updated Netty libraries from v4.1.130 to v4.1.131 f373468d
  • SCR-1691: Added command-line tools for mail signatures 28b134d6
  • Updated core-mw chart dependencies 0bf93207
    • Updated Collabora chart to v1.1.60
  • Use module-agnostic capabilities in shared accounts c20fa549
  • core#489: Ignore invalid vCard version string and fall back to version 3.0 012c58d1 e00886fa
  • core#494: Only match against calendar user if necessary when looking up overlapping events 460c68b8
  • support#1070: Provide details about stored event on UID conflict errors (2) 414d3426
  • support#1363: Ensure consistent connection pool state 1f1982b1

Fixed

  • PBSR-1664: Orderly consider mail login resolver when dealing with a user's ACL name 86565835
  • support#1099: Yield OR terms from mail category rule for batch-wise processing 7fdd048c
  • Skip system permissions when inheriting permissions for mail subfolders 0c2ccc6f
  • Stray placeholder in SQL UPDATE for sent folder in RdbMailAccountStorage f4fa89cc
  • Fix com.amazonaws build.properties path 1025cd17
  • core#473: Keep user in recipient list when replying to a mail in a shared folder 8f85745c
  • core#486: Avoid writing periodic save-points (by default) to avoid possible access problems 45fb536b
  • core#490: Detect Java version without additional JVM options e58b7910
  • core#491: Ensure to store normalized recurrence id in series master event a99a853c
  • core#493: Orderly read values from result set while initializing permissions 1eea181d
  • core#495: More sophisticated delta generation for subscribed iCalendar feeds 8407a10d
  • core#496: Merge multiple results during peer attendee lookup 25cfcb03
  • core#497: Limit number of concurrent transport attempts for scheduled mails 25f93af0 8b39b125 55df8424 fdfdb9e0
  • core#498: Don't skip shared folders when listening for incoming scheduling mails 4cc69f87
  • core#499: Skip empty or null result session list while gathering removable sessions bcec64f2
  • core#500: Also allow possible CR?LF sequences in CSS value portion ad1a3676
  • support#1004: Lenient behavior when dropping ACL permission (leftovers from deputy permission) from considerable mailboxes dd20d8fe
  • support#1070: Only consider effective calendar user during conflict checks for incoming scheduling actions 6f598647
  • support#1166: Don't drop stack trace if "includeStackTraceOnError=true" is present in request parameters 3a2d3868 be9e0ca4 d6fafc69
  • support#1326: Orderly handle 'fields' parameter when acknowledging alarms da994cf6

Removed

  • Remove com.openexchange.davx5.rest bundle and adopt lean configuration for DAV onboarding providers 181a64e0
    • SCR-1687: Renamed DAVx5 Select configuration properties
  • Remove discontinued OX Mail App and Mobile API Facade 8315c658
  • support#1264: Obsolete validating interceptor for Jitsi meetings eb9ff322

8.48.66 - 2026-03-19

Added

  • INF-581: Always apply default HTTP headers in WebDAV responses, including new 'X-Powered-By' header 595fb2dd
  • support#1242: Extend Multifactor implementation to store successful authentication in a cookie 1a1eb9ed
  • Allowing to enable IMAP trace logging by request 7c99eb86
  • Estonian backend translation updates b21aa159
  • Helm chart support for PodDisruptionBudget 370353ca
    • SCR-1677: Added Helm chart support for PodDisruptionBudget
  • Translation updates 8.47: cs_CZ, da_DK, de_DE, el_GR, en_GB, es_ES, es_MX, fi_FI, fr_CA, fr_FR, hu_HU, it_IT, ja_JP, lv_LV, nl_NL, pl_PL, pt_BR, ro_RO, ru_RU, sk_SK, sv_SE, tr_TR, zh_CN, zh_TW 26727940
  • SCR-1664: New Properties for Shared Accounts Configuration
  • SCR-1665: New Module 'sharedaccount' in HTTP API
  • SCR-1666: New Package 'open-xchange-sharedaccount'
  • SCR-1667: New SOAP Service for Shared Accounts
  • SCR-1668: New Commandline Utilities for Shared Accounts
  • SCR-1669: Update Tasks for Shared Account Tables
  • SCR-1675: New Properties for Mailfilter Secondary Accounts
  • SCR-1676: New Parameter 'accountid' in Actions of Module 'mailfilter/v2' Module of HTTP API

Changed

  • IAE-129: Added support for \Archive SPECIAL-USE on initial standard folder detection 2bf4251a f35822b6
  • PBSR-1415: Use new EntityType from User instead of guestCreatedBy/mail to derive the entity type wherever feasible 1f9816d8
    • SCR-1670: Update Task to add "type" column for Tables "user" and "del_user"
  • Updated core-mw chart dependencies 1def342d
    • Updated Gotenberg image to v8.27.0
    • Updated Gotenberg chart to v1.18.0
    • Updated Collabora image to v25.04.9.2.1
    • Updated Collabora chart to v1.1.58
  • Some refactoring for Redis health check 5b066f05
  • support#1195: Signal if a deputy permission has not been applied to a certain module since there is already a duplicate deputy permission on each affected folder 67983c1f 2c8105bd 4b404485 be7b6d2d

Fixed

  • Docker image missing stable-8.x tag when pushing release image ca6bd960
  • IOL-2841: Periodically touch composition space cache during file upload to ensure it does not vanish from cache cb7f9510
  • core#485: Added webp support for JDK-based image transformation 646ec6fb
    • SCR-1685: Updated & enhanced TwelveMonkeys ImageIO readers/writers
  • Collect embedded files from all PDF name tree kid nodes in ExportPDFTest 0feeb54e
  • Consider original request properties in undo action cdc6103e
  • core#464: Treat added attendee as external in case an attendee copy already exists 1e28e27c
  • core#465: Added retry behavior in case a recoverable SQL error occurs that suggests restarting 9ee5c161
  • core#466: Fix potential IMAP connection permit leak due to end-point key mismatch through binding connection limiter permit to IMAPProtocol (lease-based release) 2894b78f 76973491 e8754e57 3be43fca
  • core#468: Use more robust compare-and-set implementation when acquiring a unique sequence identifier 19ab49ec bc05b1ec
  • core#469: Orderly consider user/context information when evaluating "com.openexchange.mail.filter.activated" property 39d6bfe4
  • core#470: Pass proper thread context map on logout of a DAV session 9ad2eaab
  • core#471: Added alternative faster symmetric encryption for less security use cases & rather fail-fast behavior for Reids connector policies 25cc260b 55040fb9
  • core#473: Special handling when replying to a mail in a shared folder cd3795fa
  • core#480: Move MYSQL_ROOT_PASSWORD from plaintext env var to Kubernetes Secret dcfc2f4c
  • core#481: Ignore possible "file not found" error when moving entity-associated files due to deletion of that entity (e.g. user deletion) 9796e469
  • core#482: Improved direct INFORMATION_SCHEMA query and use custom connection having "useInformationSchema" set to "false" (to prefer SHOW commands for DDL) 5a6baa6a
  • core#483: Empty data field in Secrets when no secret values are configured 3a493265
  • core#484: Orderly keep URIs to external images 35964a81
  • support#1099: Avoid too many recursive calls when compiling IMAP SEARCH expression from a search term instance 022129dd 7e884f2d
  • support#1276: Added config option to Redis-based session storage to control execution of timer tasks aa20dcba
  • support#1288: Restored previous JAXB annotation for deputy module permissions 75f9e6dd

8.47.52 - 2026-02-18

Added

Changed

  • PBSR-1478: Accept a dedicated identifier referencing the account in whose standard Sent folder the message will be stored 7ce6eefc
  • SCR-1646: Updated OpenId Connect libraries 8059956a
  • SCR-1647: Updated Netty libraries from v4.1.124 to v4.1.130 db94f345
  • SCR-1648: Updated lettuce library from v6.5.5 to v6.8.2 c1128579
  • SCR-1649: Updated Fabric8 libraries from v7.4.0 to v7.5.2 f36adbaa
  • SCR-1650: Updated Jackson libraries from v2.19.2 to v2.21.0 572f7b9c
  • SCR-1652: Updated the OSGi target platform bundle org.eclipse.osgi_3.23.200.v20250812-1847.jar to org.eclipse.osgi_3.24.0.v20251126-0427.jar 01702a91
  • SCR-1653: Upgraded JSoup library from v1.21.1 to v1.22.1 6b4ee768
  • SCR-1654: Updated Apache Mime4j libraries 66862ed7
  • SCR-1655: Update Apache Commons Codec from v.1.17.2 to v1.21.0 55068542
  • SCR-1656: Updated Apache Commons CLI library from v1.9.0 to v1.11.0 86b7b563
  • SCR-1657: Updated Apache Commons Collections4 library from v4.4 to v4.5.0 4f252722
  • Support client-provided file name 26f60322
  • Updated core-mw chart dependencies a8d487df
    • Updated Gotenberg chart to v1.17.0
    • Updated Collabora image to v25.04.8.3.1
    • Updated Collabora chart to v1.1.56
  • Try to extract file name from request's path information and prefer it if present 4f6a83f4
  • core#444: More sophisticated mapping from Windows to Olson timezones bc9387dc 049d3ae2
  • core#446: Selectively load user attendee data for post processing during DAV:sync-collection REPORT d3eb1af2 65cbc452 f878efca
  • support#1146: Don't fail during mail compose if a referenced image could not be found 53e00999 023f3d18
  • support#1158: Include the hint on successful data export that some modules might not have exported 4f2c6faf 0ad36584
  • support#1205: Catch and log errors when formatting iTIP annotations 0a233ebc

Fixed

  • INU-5058: Correctly detect non-multipart iMIP messages 14b71bfd
  • core#459: Drop invalid deputy permissions from result set 577eff43
  • core#447: Avoid excessive parsing of corrupt E-Mail address string 5a0e6066
  • core#448: Drop superfluous "InitialTombstoneCleanupUpdateTask" update task since there is a periodic execution fcb651cf
  • core#449: Support to drop/remove birthday (and anniversary) date field from user 6322761a
  • core#450: Dropped Eclipse Collections and any of its usages c5a0f40c
  • core#453: Orderly return 'CALDAV:same-organizer-in-all-components' precondition if applicable aed55587
  • core#455: Remember reply headers in composition space's meta data 44b76d4f
  • core#457: Use DefaultAWSCredentialsProviderChain for AWS Identity and Access Management (IAM) credentials source b21b7168
  • core#458: Added possibility to move a context to another database (pool) w/o using a surrounding transaction on config database to not block concurrent context provisioning 2b3bbdcc a0409812
  • core#461: Try to obtain user identifier from thread's log properties to determine appropriate no-reply configuration dddae848
  • support#1162: Verify schema state if fetched from (Redis) cache 279aaf4e
  • core#1174: Remove obsolete Hazelcast group password from core-mw Helm chart 255762b1

8.46.83 - 2026-01-21

Added

  • Introduced notification queue to send arbitrary messages to client to notify users 7e5616a6

Changed

  • INU-5023: Correlate first vCard to OX contact property via 'x-1st' instead of 'pref' marker 60b29092
    • SCR-1635: Changed Handling of TEL Preference in vCard Mapping
  • SCR-1637: Upgraded Apache Tika and Commons IO libraries 8a0b75f2
  • Updated core-mw chart dependencies c4dac3b4
    • Updated Gotenberg image to v8.25.1
    • Updated Gotenberg chart to v1.14.0
    • Updated Collabora image to v25.04.8.1.1
    • Updated Collabora chart to v1.1.54
  • core#413: Quote log levels in values.yaml fd7d0abd
  • core#428: Handle possible failure to parse S3 document identifier to a UUID as FLS-0017 error (File does not exist in file storage) 610c7dc9 b997df75
  • support#1070: Only consider actual calendar user during conflict checks for incoming scheduling actions 7369e81c 11c17a08
  • support#1110: Only consider user image if alias is matched unambiguously 0272ef0a
  • support#1123: Corrected error mapping for AWS S3 code "ServiceUnavailable" 4a978880

Fixed

  • Invalidate user-caches after commit phase 6d05e3ec
  • Mark such scheduled mails as failed (and thus no further transport attempts) for which the transport attempt failed; e.g. SMTP error 3360d748
  • Reliable implementation for max. number of IMAP connections 683ef406
  • Error with OXToolMySQLStorage.existsUser with a user who only has a name. The query for user by id was executed. 573d496f
  • Fixing compiler errors as well as false positives with @NonNull annotations 5efee1d8
  • Translations for bug: Scheduled mail failure notification body wrong 49eecf1b
  • core#400: Follow-up to also accept URL parameters w/ empty value 9b2b8091
  • core#416: Drop all deputy-associated permissions from mail folders 541b7203
  • core#419: Keep valid %XX sequences in path of an URI b7e8afb3
  • core#421: Reliable implementation for max. number of IMAP connections 626f1317 34ac7e14
  • core#422: Added backticks around otherwise interpreted input a5fd0e0d
  • core#424: Orderly count read bytes from spooled file, properly encode ATTACH properties with Base64 encoding 68e48ae8
  • core#425: Do not collect addresses from mails located in spam folder 939dd669 9eabae34
  • core#427: Obey 'separateTransactionForSequenceIds' setting and partake in surrounding retry/backoff strategy when saving attachment metadata 7c17ec3a ac5e6a2e
  • core#431: Don't attempt to reload attendees if not applicable 0896923e
  • core#432: Don't put folders from secondary mail accounts into user-sensitive cache bb3f540b
  • core#433: Added fallback handling for incompatible DURATION values, skip inconvertible events during refresh of iCal subscriptions 1447ee05
  • core#435: Use common logic to generate file name when attaching contact as vCard 248bc5d7
  • core#436: Prefer possibly configured personal part for special no-reply address c7c35ca7
  • core#437: Insert appropriate information into notification mail in case no further attempt is made to transport a scheduled mail fed9a4db ddd895da
  • core#438: Detect & drop harmful content in CDATA section a3f587ef
  • core#439: Added documentation for available configuration settings for snoozed mail feature fcefe34d
  • core#440: Consider all commits since the last tag during the changelog commit check 99a4b62e
  • core#442: Handle possibly missing file store identifier when examining admin user 3d84afc7
  • core#443: Also consider SCHEDULE-AGENT parameter when checking PARTSTAT transitions a7bd7a02
  • core#445: Do not treat such inline images as extra images that are already referenced in HTML content ef1d223a
  • support#642: MacOS detection > v20 38ab03db
  • support#994: Orderly handle possible "user not found" error when looking-up by mail login string 41e2db03
  • support#1047: Optionally resolve hidden events to re-instantiate previously deleted events as attendee 20c1b981 2603b871
  • support#1055: Check for possibly failed login when performing POP3 ping fcea8ee7

8.45.48 - 2025-12-03

Added

  • Added mail snooze feature - /appsuite/platform/core86 6273c171

Changed

Fixed

  • CIC-930: Orderly add newlines when having multiple secret context sets 9f8944cd
  • Delete tombstone entries in chunks 28e60fe1
    • This limits the size of simultaneously loaded tombstone entries to 10k and therefore preventing overloads if the size is extremely big
  • core#375: Ensure IMAP folder is really not existent through dedicated LIST commands fc8b14b8 1ceabe39 a85cd047
  • core#381: Use retry mechanism when encountering special optimistic concurrency conflict e7938366 e7c5b8e6 3a47586a
  • core#382: Orderly process locally held inline images to have a "Content-Id"-referencing "src" attribute e680eec9
  • core#395: Properly recognize guest calendar user in public folder 918f4825
  • core#396: Dont delete foreign folder b733c1e5
  • core#398: Also allow TLDs as specified in RFC 6761 365576b2 0f837d89 18887594
  • core#399: Ignore failure to retrieve the metadata for a \NoSelect mailbox d777df68
  • core#400: Do not double URL-encode valid %XX sequences 762de379
  • core#402: Use an alternative polling-based watcher for changed k8s secret 8f9b2f22
  • core#406: Introduced possibility to let liveness fail, when health/readiness check failed consecutively for more than a configured duration 0087cda9
  • core#407: Avoid auto-creation of optional default Drive folder (Documents, Videos, Music, ...) b8803ffb a23f17e4
  • core#408: Corrected invocation of legacy (PIM) event queue and adjusted its logging behavior 6900bbdd cdec313d af56ac62 7dada2da
  • core#409: Use improved hash calculation for a folder name to avoid possible collisions dc491b6b
  • core#410: Chunk-wise output of resources in calendar- and addressbook-multiget report exceeding configured limits 201ccccc
    • SCR-1634: Changed Semantics for 'com.openexchange.carddav.addressbookMultigetLimit' and 'com.openexchange.caldav.calendarMultigetLimit'
  • core#411: Drop invalid deputy permissions from result set 221515e5
  • core#412: Read proper command-line tool parameter on secondary account creation 31a6a582
  • core#413: Enforce HTML sanitization if output view is set to "document" aeaa505f
  • core#414: Lowered log level for annoying log message 599579a6
  • core#415: Still offer to accept party crasher from outdated REPLY ff2d1341
  • core#417: Lowered log level to DEBUG if exception indicates an invalidly configured no-reply transport baf38b0b
  • core#418: Use "DELETE ... JOIN" statement to drop duplicate entries from "ratelimit" table 4739a26f
  • support#983: Corrected exception message argument order when importing to an incompatible parent folder f6c7bdc5

8.44.28 - 2025-10-28

Added

  • SCR-1622: Added new lean property com.openexchange.mail.bodyPartReadThresholdMillis that specifies the threshold in milliseconds for the read duration of body parts from mail storage. If that threshold is exceeded a warn log message is generated f89d1944 bef3059a
  • Allow setting new primary mail address during secondary account update d8473609
    • SCR-1619: New Element 'primaryAddress' in 'accountDataUpdate' for 'OXSecondaryAccountService'
    • SCR-1620: New Option '--new-primary-address' for 'updatesecondaryaccount'
  • Checksum configuration in helm chart for rolling upgrades 6233f1b1
  • support#902: New scenarios and custom login sources for manual drive client onboarding b122b945
    • SCR-1617: New Scenarios for Manual Drive Client Onboarding Configuration
    • SCR-1618: New Properties to Enable Custom Login Source for Drive Client Onboarding

Changed

  • SCR-1623: Introduced property "com.openexchange.snippet.preferredSnippetService" to specify preferred snippet service to use 82605d2f fb9e1e24
  • Updated core-mw chart dependencies a5750420
    • Updated Collabora image to v25.04.6.2.1
    • Updated Collabora chart to v1.1.51
  • Remove explicit cluster domain e386ba76

Fixed

  • INU-4853: Do not set a second invalidation cookie if no domain is configured eed9c664 d95e55e8
  • core#386: Detect harmful content in CSS fragment 45ff81bf
  • core#364: Improved handling for failed transport of a scheduled mail with mail notification be9c6094
  • core#388: More robust validation of deputy metadata in folder attributes 8165d446
  • Handle every contextSet and UI property as string so they will be orderly processed by oxprops 1caea19c 9cad1815
  • core#382: Orderly process locally held inline images to have a "Content-Id"-referencing "src" attribute e9ba6091 6134ad3f
  • core#389: Restore RFC 1123 compliant formatting of {DAV:}creationdate and {DAV:}getlastmodified 1f26b309
  • core#390: Allow applying iMIP manually after organizer changed 0c83bb73
    • SCR-1621: New Property 'com.openexchange.calendar.allowChangeOfOrganizerWithExternals'
  • core#391: Omit iOS version from device display name if not reliably detectable 606bc947
  • core#392: Corrected formatting of bullet-point list in markdown for secondary accounts documentation core#393: Handle IMAP ACLs according to RFC 4314 as recommended: ignore the virtual "d" and "c" rights b000b557
  • support#926: Allow a "reject" only or a "reject + stop" combination fb548b04 7ca8ce60

8.43.52 - 2025-10-02

Added

  • SCR-1605: New property to limit maximum attendees per conflict check (SCR-1605) a8ab6a50
  • SCR-1606: New property 'com.openexchange.caldav.calendarMultigetLimit' 9ebafff9
  • SCR-1607: New property 'com.openexchange.calendar.lookupPeerAttendeesEnabled' d60b22db 92b413fc
  • Support to disable TLS for mariadb-client 8fa9a1aa
  • core#378: Introduced options to limit reminder range requests ff01b6c6
    • SCR-1608: New Configuration Property 'com.openexchange.reminder.reminderLookbackDays'
    • SCR-1609: New Configuration Property 'com.openexchange.reminder.maxRemindersPerRequest'
    • SCR-1610: Implicitly Delete Alarms when Declining a Task
  • support#850: Documentation for 'com.openexchange.undo.enabled' 1d60817f
  • support#888: Indicate configured value of 'maxAttendeesPerConflictCheck' via JSlob API 13e27b0f

Changed

  • Added no-op mappings for orphaned user properties links/number_of_links (columns 591 and 595) 696a2e00
  • INU-4985: Consolidated parsing/writing of BDAY and ANNIVERSARY without year part in vCards fa640454
  • support#883: Query attendees chunk-wise fa6b1237
  • SCR-1599: Changed typo in property name and now properly use "com.openexchange.mail.proxyExternalImageUrls" instead of "com.openexchange.mail.proxyExternalImagerUrls" b3e3f26d
  • SCR-1604: Updated OSGi target platform bundles 8d2042e9
  • SCR-1611: Added possibility to enable round-robin on IP address selection e5170e58 cbd03571 7cbb4d40 e4038669
  • SCR-1612: Updated Spring Framework libraries from v5.3.32 to v5.3.39 2f79d5d3
  • Updated core-mw chart dependencies 1df9308f
    • Updated Gotenberg image to v8.23.2
    • Updated Collabora image to v25.04.5.3.1
    • Updated Collabora chart to v1.1.49
  • Check number of recipients against configured limit ("com.openexchange.mail.maxToCcBcc") as well as validate recipients' addresses b87f2b2b
  • Do not need to explicitly pass mysql args to initconfigdb script 69f04b2a
  • Updated integrated timezone definitions to tzdata2025a 29585c43
  • core#358: Delete previously scheduled mail data along with associated message when re-editing as draft 0a47882d 8b5e5baf
  • core#364: Cope with "Domain ends with dot" address parse exception on message transport e5629919
  • core#378: Only load data for limited amount of attendees during conflict checks af1beadf

Fixed

  • Also consider <iframe> tag when checking for possible HTML content 1e26cdcc
  • Drop existent scheduled mail on "Cancel send" and manual deletion from Scheduled folder e0f178b0
  • Fixed typo in table name in com.openexchange.groupware.update.tasks.DropJsonCacheTableTask update task 363eb65b
  • Removed the deprecated clause from property description for "com.openexchange.cache.v2.redis.disableHashExpiration" 66bed375
  • core#371: Minor contact trash oversights 241920d6
  • core#372: Process data chunk-wise during 'movecontextdatabase' 37352651
    • SCR-1603: New Configurartion Properties for 'movecontextdatabase'
  • core#377: Stick with common routines when resolving CardDAV resources from LDAP 7d162650
  • core#378: Include folder id term when resolving resources by UID 7e3b66eb ed65479e
  • core#383: More robust parsing of image URIs as well as apply proxy routing to external images on reply/forward 9082b8b8 235f6695 ef63083d 15e644cf 7362c334
  • core#384: Orderly update folder's anonymous guest permission on follow-up mail transport attempt 1659bb08

8.42.48 - 2025-09-03

Added

  • SCR-1594: New Configuration Property 'com.openexchange.admin.user.convertguest.default' (SCR-1594) e2dbf73e
  • #367: Documentation for external image proxy for HTML mails 1b9b592e

Changed

  • FCV-127: Don't use fallback path for image transformation if ImageConverter server is configured e13222f2
  • SCR-1588: Changed limitations for images in snippets (signatures) 8f458ee3
  • SCR-1589: Updated Apache Commons BeanUtils library from v1.9.4 to v1.11.0 1c2a66cf
  • SCR-1590: Updated Apache Commons FileUpload library from v1.5 to v1.6.0 4f046978
  • SCR-1591: Updated Apache Commons Lang library from v3.14.0 to v3.18.0 53adfa6d
  • SCR-1592: Updated Apache CXF libraries from v3.5.10 to v3.5.11 ec426be9
  • SCR-1593: Updated Nimbus JOSE+JWT library from v9.41.2 to v10.0.2 cb05b698
  • SCR-1595: Drop unused "jsonCache" table as well as referenced entries in "updatetask" table a1b9b056
  • SCR-1596: Updated Bouncy Castle libraries from v1.78.1 to v1.79 5f4c9638
  • SCR-1597: Updated Netty libraries from v4.1.121 to v4.1.124 bd60537e
  • SCR-1598: Updated UnboundID LDAP SDK from v5.1.4 to v7.0.3 ae280843
  • Updated core-mw chart dependencies 91a56a05
  • Improved documentation for session monitoring d22adcd0
  • Updated Gotenberg to v8.22.0 and Collabora to v25.04.4.3.1 3ec4d0c0
  • Wait for ongoing requests as specified by terminationGracePeriodSeconds 94fa50e7
  • #358: Preserve composition space header references when storing draft for scheduled transport 9eeb2fbb
  • #360: Copy and adjust user's jslobs too 31bb08a4
  • #364: Added extended logging when sending due scheduled mails 6e977ad9
  • #635: Use an SQL IN statement to delete multiple documents from infostore database tables 085b83e0 664364f5 d085d091
  • #754: Avoid annoying WARN log message if decryption of a secret string fails 929345b0

Fixed

8.41.52 - 2025-08-06

Added

  • SCR-1584: New Property 'com.openexchange.calendar.includeCreatorInFreeBusy' (SCR-1584) 3bac5ed8 d26c4b33
  • SCR-1586: New Parameter 'user' for Action 'resolve' in Module 'chronos' (SCR-1586) 1d120b60
  • #741: Documentation for defaultLanguage property that is used for the login page if no user language can be detected de118a79
  • #1101: Expose owner info for share mail folders - /appsuite/web-apps/ui 251d8570

Changed

Fixed

8.40.56 - 2025-07-09

Added

  • #6: Introduced limits for maximum number of tombstones per external calendar account 82af4d12
    • SCR-1576: New properties to control number of tombstone records

Changed

Fixed

  • #670: Determine file size from passed input stream instead of re-querying file storage bc1e9087
  • #317: Added missing snippet import action docu. Ref. 317 eb1ba639
  • Set default value for contact autodelete rententiondays c4140800
  • #205: Don't add events to existing calendar object resource w/o series id 4a9cbe2b
  • #245: Aligned identifying fields when checking maximum size of returned event collections ede890df
  • #262: Re-Initialize authentication information mail access state once new OAuth token were acquired 1620ad40
  • #282: Orderly set content type 'application/x-apple-aspen-config' after signing plist file 4523a01c
  • #320: Ensure moved/copied files are moved back/deleted on exception path during file storage move operation ee935054
  • #325: Use local reference when printing capabilities in debug mode e52cfbde
  • #327: Apply lowered read timeout when probing for file name search capability of an IMAP server 1d960a94
  • #331: Prevent amount quota deadlocks while creating events d6aea38d bfdd32d7
  • #333: Use a temporary table (derived table) when deleting entries from 'updateTask' table while reading from it in a subquery e81c52f2

Removed

  • #288: Removed dependencies to c.o.test.config.helper bundle. 0fffc47b

8.39.64 - 2025-06-11

Added

  • Made similarity service optional 653cc5cc
  • #268: Support for Cross-context ACLs in Mail Folders 7a1231dc
    • SCR-1573: New option 'identifiers' for 'folders?action=notify'
    • SCR-1574: New property 'com.openexchange.mail.crossContextPermissions'
  • #274 Extended copy action to support multi-contact selection and undo and overall polishing - 7f4810c9

Changed

  • SCR-1572: Introduce 'separateTransactionForSequenceIds' setting for calendar storage operations 14e81b53
  • Adjust contact autodelete configuration to use jslob 57d40a30
  • Extended mail category attributes by an icon name 0f12aed0 9efde57f 1eb29696 4821fc69 08e7db60
  • Adjusted tests to run without test contact providers. 3b508809
  • #262: Retry IMAP-IDLE run loading newest session representation from session storage into local cache 9a23afa0
  • #307: Added possibility to perform a case-insensitive look-up for context/user in database 308d05f7
  • #567: Added DEBUG logging when altering "no copy into standard sent folder" mail setting 6d1160ee

Fixed

  • Perform check to implicitly assume protocol=SOCKET for mysql command-line tool at right location 38df4bd1
  • Deal with possibly dying connection when probing for FILENAME SEARCH capability 5840ffdc
  • Initiate transaction for proper ID generation in case Unified Mail is newly initialized bb939049
  • Orderly invalidate mail account even though connection in transaction state might be passed 81105973
  • #267: Set proper version in API documentation a3ef0ba4
  • #272: Don't attempt to resolve external attendees by email unless required c70a165e 15cfecfc
    • SCR-1571: Exposed parameter 'trackAttendeeUsage' for 'chronos?action=new' and 'chronos?action=update'
  • #276: Do not cache trash folder at creation time 14fd750d
  • #277: Ensure no duplicate entry is inserted into update task table and clear existent ones 4bfc75e2 e986e4a5
  • #279: Only inject credential provider if proxy username is configured for mail autoconfig 879926b0
  • #280: Include managed attachments in iMIP when forwarding events f8d89095
  • #281: Use system proxies for APNs push if defined 8a6b5e2f
  • #306: Orderly throw exception if endpoint is not configured with TLS a7457309
  • #308: Obey to sort by received date descending in case messages' flags are equal dca8e845
  • #312: Perform chunk-wise deletion of tomb stone entries c562706e 2d38754c 970f5123
  • #567: Allow property-wise override for "no copy into standard sent folder" mail setting a6fbdef8
  • #600: Early return in case a chosen source's values have been applied e0158716

Removed

8.38.77 - 2025-05-15

Added

  • SCR-1453: New parameter "sortByUseCount" for "search" action in module "resource" 5a2665d0
  • SCR-1566: Update Task to Clear Empty Categories for Contacts 766e14cf
  • Add version label to base layer image e20991f7
  • Priority class for pods 16fb5c79
  • Redis connection monitoring in grafana dashboard aef939e8
  • #82: Free/Busy and Conflict Checks for iCalendar Subscriptions 490fcc0b
    • SCR-1564: New Configuration Property 'com.openexchange.calendar.externalConflictChecksTimeout'
  • #188: Ensure deputy folders are auto-subscribed implicitly 2dbe6443
  • #194: Send Notification Mail when Granting Deputy Permissions c2398f57
    • SCR-1567: Option "notification" when Granting Deputy Permissions
    • SCR-1568: New "notification" Element when Granting Deputy Permissions

Changed

  • FCV-127: Let wait time begin once image transformation task has been scheduled and be interrupt-aware during processing 001cf090
  • SCR-1562: Updated Jackson libraries from v2.18.1 to v2.19.0 e0496494
  • SCR-1565: Redis connector now uses a pool of shared connections 2ba79002
  • SCR-1569: Updated lettuce library from v6.5.5 to v6.6.0 0669f957
  • SCR-1570: Updated Netty libraries from v4.1.119 to v4.1.121 f8857a48
  • Enforce serial processing for modifying operations of modules 'addressbooks' and 'chronos' 08b20222
  • #217: Provide sensitive Helm Chart values alternatively as existing Secrets f891d856
  • #234: Contact trash adjustments and improvements d477a875
    • SCR-1559: Changed com.openexchange.contact.trashFolder.enabled default value
    • SCR-1560: Interface changes for contact move
    • SCR-1561: Introduced 'move' action for contacts/addressbooks
  • #237: Added 'dontResolveEntities' parameter also for 'POST' request method variants ee798df3
  • #247: Ensure delayed JSlobs are flushed to database on user update 64cfa9ac ad654add 07b3c87e 4de9f4fe
  • #253: Enhanced documentation for crawler-based contact subscriptions 8251da3f
  • #255: Lenient parsing for LAST-MODIFIED and CREATED property 85cba477
  • #257: Improved SIEVE parser error message if a nested rule is detected 4e47f411
  • #545: Assume same mail back-end (user base) for primary and secondary accounts a621b609

Fixed

  • Possible race-condition regarding contact trash folder d86bc505
  • Add watch permission for role to allow watching secrets 7577a55b
  • Apply header space if no html body tag exists a7dc1e13
  • Prevent Gotenberg from writing to /home/gotenberg/.local 11b9646e
  • Improved rule line counting for different line breaks f98b1aeb
  • #236: Guest user password setup fails f256050e
  • #251: Explicitly query relevant attribute when resolving mail login via LDAP 7b52bd7f
  • #256: Orderly display HTML content as-is if nothing has to be modified 6dd8beab
  • #259: Orderly write/read mail setting's quota and quota-per-file information to/from Redis cache a441bc27
  • #260: Orderly replace UI web path in notification link 6a2e1c17
  • #263: Orderly use languages configured by core-mw helm chart 9a7451a8
  • #264: Convert <input> elements of type "image" to appropriate <img> elements 50ab8a60
  • #270: Respect CSS content length when looking-up closing brace } as end of a CSS block 2c48bdd2
  • #273: Pass proper parameters on cache key generation fe0bb3b6
  • #573: Freshly obtain session by session identifier from session storage to avoid using possibly outdated authentication data ef8faad9 51fce319
  • Orderly invalidate mail account even though connection in transaction state might be passed 81105973
  • Deal with possibly dying connection when probing for FILENAME SEARCH capability 5840ffdc

8.37.72 - 2025-04-15

Added

  • #173: Added folder mode to deputy permission feature b984df95
  • #182: Auto-delete for contacts in trash folder 9022c6bb
    • SCR-1533: Added properties for contact auto-delete feature
    • SCR-1534: Introduced autodelete_contacts & autodelete_contacts_editable capability and config-path / jslob

Changed

  • SCR-1565: Redis connector now uses a pool of shared connections 249b96af
  • SCR-1551: Added newer Failsafe library to target platform 39225b61
  • SCR-1552: Upgraded the GSON library from v2.10.1 to v2.12.1 500471a5
  • SCR-1553: Upgraded JSoup library from v1.17.2 to v1.19.1 b5af6dac
  • SCR-1556: Upgraded MySQL-Connector-J from v.8.3.0 to v9.2.0 e37ea5a3
  • SCR-1558: Introduced dontResolveEntities parameter to support import of separate event copies 44affc26
  • #234: Contact trash feature polishing f65ee4d2
    • SCR-1554: Rename contact trash folder to maintain consistency across the modules
  • #252: Don't expect invocation of 'post_logout_redirect_uri' callback during OIDC logout flow a9e1fb2f 56a5e853

Fixed

  • Orderly copy configuration when using the go entrypoint script b1c36869
  • #154: Added documentation for contact origin column 4cb707a1
  • #154: Ensure contact trash folder is excluded for sync d5ae50a8
  • #182: Property documentation a698106b
  • #193: Only update attributes if there are actual changes c57ae562
  • #195: Check multiple possible public session cookie candidates for a valid session 5b587063 5993d1ee 6f22b4c4
  • #213: Preserve flags on edit draft 178dd702
  • #224: Corrected parameter handling when storing snippets into database 20967c51
  • #232: Save autodelete props in config-cascade 35cbc90c
  • #235: Adjusted "Limitations" sections of CalDAV documentation to emphasize that no shared tasks folders can be synchronized b81c65bc
  • #238: Use 'default dict' for safe handling of properties in YAML templates to prevent nil values in core-mw configuration files 58101fcf
  • #239: Escape illegal characters in cache filter suffix portions a12ea0ba
  • #241: Retry reinitialization of users_per_filestore table with manual INSERTs in case CREATE TABLE AS SELECT statement is prohibited aeff879b
  • #244: Don't check for possible locked document when dropping from trash folder 464c4c25
  • #248: More contact trash polishing 3b0d53f2
  • #250: Keep local IP address in generated session ef128617
  • #464: Added option to disable 'send on behalf of' detection 31837e29
  • #499: Removed superfluous call to hard-delete messages when moving messages from Unified Mail's folder to another Unified Mail's folder 5ce559fc
  • #223: Ensure proper result size for contact requests if com.openexchange.showAdmin is set to false 91fb9f20

8.36.36 - 2025-03-12

Added

  • SCR-1528: Documentation for new "convert-guest" option (SCR-1528) 690b888e
  • Introduced Go entrypoint script 5ef954d4
  • #154: Introduced trash folder for contacts 7d92eeac
    • SCR-1516: Added hardDelete parameter to contacts delete
    • SCR-1517: Added hardDelete to InternalContactsAccess Interface
    • SCR-1518: Added restoreContact to FolderReadWriteContactsAccess
    • SCR-1519: Added hardDelete to FolderReadWriteContactsAccess
    • SCR-1520: New restore action for addressbook endpoint
    • SCR-1523: New property com.openexchange.contact.trashFolder.enabled
    • SCR-1526: New origin column for prg_contacts and del_contacts
    • SCR-1532: Introduced 'contact_trash' capability and config-path / jslob
  • Added mail filter checker framework + reject single command check 3d92cbcc
  • #190: Import further EMAIL properties into email1/email2/email3 unless already populated 08eb5663
  • #200: More explanations and examples for Redis Cluster ab589f65

Changed

  • INU-4803: Additional tests for eager EMAIL import of vCards 9eed9407
  • SCR-1536: Updated Caffeine caching library from v3.1.8 to v3.2.0 1d7a4cef 8abddf98
  • SCR-1537: Updated Netty libraries from v4.1.115 to v4.1.119 56c9cee6
  • Updated gotenberg and collabora dependency 370c39db
  • #119: Convert guest to regular user dfa51990
  • #188: Added new lean properties to specify primary account's namespaces which are necessary when using Dovecot's DoveAdm API to manage deputy permissions 617bb891
  • #206: Use spooling directory also when generating a data export's result files e6841be1

Fixed

8.35.66 - 2025-02-12

Added

  • SCR-1486: New property com.openexchange.carddav.addressbookMultigetLimit dced5468
  • Added async provisioning framework 35b89cf8
  • #134: Health Check for Redis Cache cb4b20fd
  • #137: Expose CardDAV URL for Address Book Folders 185ab623
  • #138: Warm-up Thread-local Cache when Handling Client Requests 59b383b7
  • #139: Control Sharding for Redis Cluster 39594fad
  • #144: Fixed existing graphs and added new ones based on redis cache metrics 22e1f263

Changed

  • Add shared-read-only flag to snippet module to have shared snippets that may be seen, but must not be modified/deleted by other users 1c7e0b79
  • Batch-resolve resources when handling CARDDAV:addressbook-multiget request e5d88cea
  • INU-4548: Support configurable custom flag for mails 068cf122
  • SCR-1496: Enhanced OAuthAuthorizationService#validateAccessToken with Header collection parameter e2f67eb3
  • SCR-1510: Changed defaults for Client-Onboarding YAML configuration file ff520286
  • SCR-1511: Update Apache Commons Codec from v.1.17.0 to v1.17.2 22bc2e48
  • SCR-1512: Updated Apache Commons Codec library from v1.6.0 to v1.9.0 97cf880e
  • SCR-1513: Update Apache Commons CSV from v1.6 to v1.13.0 b6e9162b
  • SCR-1514: Limit number of addressed keys per MGET operation (SCR-1514) 2ddb4815
  • SCR-1522: Updated Snappy library from v1.1.10.5 to v1.1.10.7 7b1667e0
  • SCR-1528: New Option "convert-guest" in "createuser" Commandline Tool dfa51990
  • SCR-1529: New "convertguest" Element for "create" in "OXUserService" dfa51990
  • Added appropriate OAuth scopes to mail compose actions f573ffe3
  • Allow to overwrite securityContext 633bd9ef
  • Skip capability check and don't trigger preview generation if not needed fc3410fd
  • Updated collabora and gotenberg dependency 0c27b6ce
  • Changed copyright year to 2025 918cc6eb
  • Removed db defaults from values 0e9687e8
    • Removed the db defaults so that they can be overriden by global entries
    • Also adjusted the mysql secret to use those defaults in case nothing is configured
  • #62: Gather subfolder ids for search from condition tree map 9e45d258
  • #119: Convert guest to regular user dfa51990
  • #142: Disable Global Folder Cache by Default 061688e4
  • #156: Redirect to configured failure redirect location after erroneous token response 1da98a5a
  • #163: Updated to newest SLF4j and Logback libraries 350f77e9
  • #169: Update cxf-libraries to 3.5.10 (CVE-2025-23184) 32ee4852
  • #171: Added documentation article for database cleanup jobs 584fb812
  • #415: Subscribe/unsubscribe IMAP folder if deputy permission is granted/revoked 23e516da 74df2fb4
  • #697: Use more compact token format - /appsuite/web-apps/ui d3a42a18

Fixed

  • Connect CLT param access-denied-portal to code fc3907a8
  • IIJMX-554: Don't use IMAP folder's sequence number when sorting by received date is performed in application d0ec138c
  • INU-4767: Improved handling of corrupt address list dde1c354
  • Only check conflicts for added/updated attendees unless re-scheduled 9a8cdb59
  • PLG-450: Continue if visible folders cannot be collected for non-default contacts account bed1aa6b
  • Fixed main by removing commons-cli-1.6.0 from target platform 97ecdfe4
  • Adjusted documentation for 'flags' parameter 0a200e04
  • Sorting of distribution list by first name 9c227c1c
  • Allow deletion of user attributes via json null values aa90258d
  • Cache invalidator instance to prevent excessive pub key requests 7d0b14c5 e66fc312
  • Changed docu links to oss repo d7d42e84
  • Enable test on borrow for redis connection pool f8d5be57
  • Fixed AbstractAdvertisementConfigServiceTest f301738b
  • Made flagging documentation more independent of the client 8f0c48b9
  • Properly store host parameter during login c02c5045
  • #62: Include system type when gathering subfolders for infostore search 57f6fa30
  • #130: Skip initial reachability check for remote redis connections 654a44e0
  • #135: Fall back to storage access if accessing cache yields errors fedb75c9
  • #140: Corrected link in Contacts Provider LDAP documentation article 4d0e012c
  • #141: Use only one cache region for advertisment config 76287ed5
  • #143: Handle empty JSON input as no available value is Redis cache 132c9186
  • #147: Hard-delete mail(s) if located in trash folder 986b872f
  • #155: Don't attempt to invalidate caches if no group members are set 0459beba
  • #162: Explicitly use UTF-8 charset when writing vCards da0558ca
  • #168: Handle possibly absent password when checking subscribed mail account's status bc29ddb5
  • #170: Prevent from invalidating a remote node's JSlob entry if it has been stored after local node's entry 7a0b1413 764f684f
  • #175: Pick proper mail from conversation when performing sort 4e951b71
  • #179: Ignore unmappable ACLs when updating an IMAP folder's ACLs e8b25370
  • #180: More look-up attempts in case of missing draft 907c5286
  • #183: Fixed SQL 'INSERT INTO ... ON DUPLICATE KEY UPDATE' statement 7c290330
  • #185: Evaluate CARDDAV:limit in CARDDAV:addressbook-query Report 0c0a3eb4
  • #186: Consider all known 'devices' for CalDAV/CardDAV onboarding providers 0de5043a
  • #187: Added config switch to keep own address when replying to self-sent message 2bec6d40

8.34 - 2025-01-15

Added

  • PLG-360: Added entry for new feature 'open-xchange-plugins-contact-storage-provider' a2388168
  • SCR-1477: New property to select default collection for new contacts via iOS / CardDAV (SCR-1477) 807f8f65
  • SCR-1486: New property 'com.openexchange.carddav.addressbookMultigetLimit' dced5468
  • #134: Health Check for Redis Cache cb4b20fd
  • #137: Expose CardDAV URL for Address Book Folders 185ab623
  • #138: Warm-up Thread-local Cache when Handling Client Requests 59b383b7
  • #139: Control Sharding for Redis Cluster 39594fad
  • #144: Fixed existing graphs and added new ones based on redis cache metrics 22e1f263
  • #344: Documentation for Redis cache in "cluster" mode 053907a2

Changed

  • Additional add-opens for health monitor in JAVA_OPTS_OPENS 809d4d69
  • Batch-resolve resources when handling CARDDAV:addressbook-multiget request e5d88cea
  • MW-2012: Allow moving appointment series to other calendars 9cdf4674
  • SCR-1479: Updated Netty libraries from v4.1.114 to v4.1.115 46bc8634
  • SCR-1480: Updated lettuce library from v6.5.0 to v6.5.1 70d335a4
  • SCR-1481: Updated Fabric8 libraries from v6.10.0 to v6.13.4 a8b2bd86
  • SCR-1482: Added redis.tls chart value fea38f75
  • SCR-1485: New options for the Redis Connector 8604bb1d
  • SCR-1496: Enhanced OAuthAuthorizationService#validateAccessToken with Header collection parameter e2f67eb3
  • Type-specific redis configuration ca71e1d2
  • [Redis Cache] Added support for putting multiple key-value-pairs into cache f4a910da
  • Added appropriate OAuth scopes to mail compose actions f573ffe3
  • Skip capability check and don't trigger preview generation if not needed fc3410fd
  • Updated collabora and gotenberg dependency 0c27b6ce
  • #62: Allow to fetch multiple values at once from Redis cache 5d5061e5 9df6895c 9e45d258
  • #65: Allow specifying the name of the HTTP header that forwards the originating remote port 02bee688
  • #102: Make mail-related actions un-doable 2c7db142 23b032bd a9853a68
  • #114: Added check when storing user feedback if actually enabled as per configuration 8df5b5ca
  • #120: Added additional example for LDAP client configurations 159a0807
  • #142: Disable Global Folder Cache by Default 061688e4
  • #156: Redirect to configured failure redirect location after erroneous token response 1da98a5a
  • #340: Use shortcut when checking calendar/contacts provider capability a6b56856 f20ea710

Fixed

  • IIJMX-554: Don't use IMAP folder's sequence number when sorting by received date is performed in application d0ec138c
  • INU-4767: Improved handling of corrupt address list dde1c354
  • Only check conflicts for added/updated attendees unless re-scheduled 9a8cdb59
  • PLG-450: Continue if visible folders cannot be collected for non-default contacts account bed1aa6b
  • Set correct dependencies for update task f3da1e30
  • Improved skiptoken matching. 95642e67
  • Ensure compatibility with mysql 8+. 9f4edcc5
    • Removed unnecessary default value from the propertyValue column
  • Fixed AbstractAdvertisementConfigServiceTest f301738b
  • #113: Continue import w/o attachments on absence of 'filestore' capability 60d4732e
  • #121: Re-added formerly dropped method from Cache interface through a delegate implementation e69917bb
  • #122: Keep subsequent space characters through quoting 0ff626f0
  • #129: Remember upload chunk size beyond underlying file holder's validity f81de9c5
  • #130: Skip initial reachability check for remote redis connections 654a44e0
  • #135: Fall back to storage access if accessing cache yields errors fedb75c9
  • #140: Corrected link in Contacts Provider LDAP documentation article 4d0e012c
  • #141: Use only one cache region for advertisment config 76287ed5
  • #143: Handle empty JSON input as no available value is Redis cache 132c9186
  • #147: Hard-delete mail(s) if located in trash folder 986b872f
  • #155: Don't attempt to invalidate caches if no group members are set 0459beba

8.33 - 2024-12-18

Added

  • PLG-360: Added entry for new feature 'open-xchange-plugins-contact-storage-provider' a2388168
  • SCR-1477: New property to select default collection for new contacts via iOS / CardDAV (SCR-1477) 807f8f65
  • #344: Documentation for Redis cache in "cluster" mode 053907a2

Changed

Fixed

  • Set correct dependencies for update task f3da1e30
  • Improved skiptoken matching. 95642e67
  • Ensure compatibility with mysql 8+. 9f4edcc5
    • Removed unnecessary default value from the propertyValue column
  • #113: Continue import w/o attachments on absence of 'filestore' capability 60d4732e
  • #121: Re-added formerly dropped method from Cache interface through a delegate implementation e69917bb
  • #122: Keep subsequent space characters through quoting 0ff626f0
  • #129: Remember upload chunk size beyond underlying file holder's validity f81de9c5

8.32 - 2024-11-20

Added

  • SCR-1470: Added new lean property to control detection of inline images bbea0f54
  • #21; New setting for preferred Calendar User Address ba9e4fd9
  • #90: SSO Logout when OX Sessions are closed through "Sign out from all devices" b2940eee

Changed

  • MW-2254: Introduced baselayer image build 034f278f
  • MWB-2245: Avoid duplicate -XX:MaxHeapSize set via helm chart 1500ffdd
  • MWB-2614: Use BadPassword exception for failed decryption 1822715c
    • Also, log legacy encryption warning only once per day
  • SCR-1462: Added new property to track Redis operation taking longer than a configured threshold fcaa5081
  • SCR-1472: Updated Netty libraries from v4.1.112 to v4.1.114 cb0e08ca
  • SCR-1473: Updated lettuce library from v6.4.0 to v6.5.0 374b02a7 269f72d4
  • SCR-1476: Updated several libraries to update Jackson libraries from v2.16.1 to v2.18.1 9ccc5f1a
  • Adapted clearing Java's DNS cache to new supported Java version(s) e2b49305
  • Signal support for mail folder resynchronization & enhanced /mail?action=examine response to also include modseq if supported f875eba3
  • Updated the gotenberg image from 8.2.0 to 8.12.0 and the chart from 1.1.0 to 1.7.0 476a2207
  • #43: Optionally skip de-registration of push listeners during user/context delete 6adee17c
  • #65: Allow specifying the name of the HTTP header that forwards the originating remote port 8944f5f7 94774936 4aba5203
  • #66: Chunking for S3 file storage cc6ae987 39e84d07 8827a25a 42a6624f
  • #69: Check if tables still exist prior purging accounts 5db6da56
  • #75: Update vulnerable libraries 827c446a
    • Update libraries xmlrpc-commonclient/server to 5.0.0 (CVE-2016-5004)
    • Update library xmlsec to 2.3.4 (CVE-2023-44483)
    • Update library nimbus-jose-jwt to 9.41.2 (CVE-2023-52428)
    • Update library ion-java to 1.11.9 (CVE-2024-21634)
    • Update library mysql-connector-j to 8.3.0 (CVE-2023-22102)
    • Update library velocity-engine-core to 2.4 (CVE-2024-47554)
    • Update library protobuf-java to 3.25.5 (CVE-2024-7254)
    • Update library logback-classic/core to 1.2.13 (CVE-2023-6378)
    • Update cxf-libraries to 3.5.9 (CVE-2024-28752)
  • #76: Do not perform computation intensive obfuscation/un-obfuscation of sessions' password while holding Redis connection fa7b834c 59f9c834 11cece02 ec93381b
  • #80: Updated documentation about CardDAV collection handling for iOS clients f9bfa280
  • #95: Use more modern values for sun.net.inetaddr.ttl and networkaddress.cache.ttl 8476484f
  • #103: Added trace logging for authentication probes during request analysis 880854f6 f974d214
  • #109: Added logging in case a down-/upload request is interrupted or gets killed c84586f3 bf1ebcb0
  • #227: Ignore possible NoSuchFileException 59ec740a
  • #236: Added reference to 'checkTopLevelDomainOnAddressValidation' property in documentation dabcbca5

Fixed

  • MW-2371: Added required Zone to DateTimeFormatter 1d71991e 6b77a62a
  • MWB-2435: Do not generate new random values for missing secret env variables on every update 70ed49a4
  • MWB-2631: Inline Metadata Missing in Syncfiles Response c603e68b
  • MWB-2641: Use correct target DB for moved context 124a7bf6 4f5b8faa
  • Added missing update task dependency to Filestore2UserUpdateReferencesTask 4f1f52e4
    • See Ref. #55
  • Expose remote debug port and use correct role selector d4a27d52
  • Use hz service name that is defined by the document role 39de7859
  • Dont run pot generation on main e547461e
  • Improved regex for password filtering dbb1a528
  • Move POT to seperate stage again be4098e5
  • Prevent NPE if json error contains no message 0657a779
  • Revert imageBuildPod.yaml changes 48c482b5
  • Use ant container for pot generation 7436e13a
  • Use proper error 909e279f
  • #4: Pay attention to com.openexchange.push.dovecot.unregisterAfterDelete setting b6e249e2
  • #68: Un-mark schema for deletion after deletion fails, ensure to load db connection settings properly e0834696
  • #72: Do not try to reparse a mail when creating its JSONrepresentation 2f176f3d
  • #76: Establish a new connection to Redis if a timeout occurs while waiting for a connection to become available in pool 7ad17340 94f60ac3
  • #77: Properly indicate support for MKCOL in OPTIONS response 2e2d9bf7
  • #79: Check for valid credentials prior to store attempt 37aed19b
  • #85: Determine file name by Content-Type/Content-Disposition headers if not given through Subject header 0fa12c8e
  • #97: Sanitize UID prior using as 'id-left' in Message-ID header 6f9a4417
  • #98: Fixed NoClassDefFoundError when trying to access Scribe classes 77f2ba9c
  • #100: Encode resource (in)availability in cached representation 438fa052
  • #101: Replace illegal characters instead of throwing an error. b382e7cf
  • #105: Don't use unreliable piped streams for task export 25b188e3
  • #106: Properly check key name 782be787
  • #107: Adjusted config docu links in quota docu. 79d6963c
  • #110: Removed summary from request body of folder-modifying requests 84c80b60

8.31 - 2024-10-23

Added

  • New setting for preferred Calendar User Address ba9e4fd9

Changed

  • MW-2254: Introduced baselayer image build 034f278f
  • MWB-2614: Use BadPassword exception for failed decryption 1822715c
    • Also, log legacy encryption warning only once per day
  • SCR-1462: Added new property to track Redis operation taking longer than a configured threshold fcaa5081
  • Signal support for mail folder resynchronization & enhanced /mail?action=examine response to also include modseq if supported f875eba3
  • #43: Optionally skip de-registration of push listeners during user/context delete 6adee17c
  • #65: Allow specifying the name of the HTTP header that forwards the originating remote port 8944f5f7 94774936
  • #69: Check if tables still exist prior purging accounts 5db6da56
  • #80: Updated documentation about CardDAV collection handling for iOS clients f9bfa280
  • #227: Ignore possible NoSuchFileException 59ec740a
  • #236: Added reference to checkTopLevelDomainOnAddressValidation property in documentation dabcbca5

Fixed

  • MW-2371: Added required Zone to DateTimeFormatter 1d71991e 6b77a62a
  • MWB-2435: Do not generate new random values for missing secret env variables on every update 70ed49a4
  • MWB-2641: Use correct target DB for moved context 124a7bf6 4f5b8faa
  • Added missing update task dependency to Filestore2UserUpdateReferencesTask 4f1f52e4
  • Use hz service name that is defined by the document role 39de7859
  • Dont run pot generation on main e547461e
  • Move POT to seperate stage again be4098e5
  • Revert imageBuildPod.yaml changes 48c482b5
  • Use ant container for pot generation 7436e13a
  • #68: Un-mark schema for deletion after deletion fails, ensure to load db connection settings properly e0834696
  • #72: Do not try to reparse a mail when creating its JSONrepresentation 2f176f3d
  • #76: Establish a new connection to Redis if a timeout occurs while waiting for a connection to become available in pool 7ad17340 94f60ac3
  • #77: Properly indicate support for MKCOL in OPTIONS response 2e2d9bf7
  • #79: Check for valid credentials prior to store attempt 37aed19b

8.30 - 2024-09-25

Added

  • MW-1068: Improve support for SCHEDULE-AGENT 2fd626d0
  • SCR-1454: New configuration property "com.openexchange.cache.v2.redis.disableHashExpiration" 323c4fa1

Changed

Fixed

  • Avoid duplicate service instance for singleton LeanConfigurationService 66a48fbf
  • Perform synchronous unregistration from Dovecot HTTP Notify plugin using a lowered socket read timeout 6a4f87bb
  • #23: Reverted some checks for pretty old messages that should not occur 9fa35f10
  • #25: Restored enhanced conflict checks during attendee update operation 7114c95f
  • #29: Check mail messages reference retrieved from cache prior iterating ac674a24
  • #30: Update local file storage account reference after remembering error in metadata 6677a246
  • #31: Prevent NPE during shutdown. Ref. 12413312
  • #32: Added auto-expiration of possible write lock for table filestore2user 46c2abb6 52c202c9 53873901
  • #33: Throw proper error if mail is not found. Ref. 251098c8
  • #36: Properly apply HTTP client config for iCal timezone updater 814c70a8
  • #39: Don't retry login attempt by default (w/ exponential back-off wait policy) when IMAP server signals UNAVAILABLE response code 2b5a3191
  • #40: Keep user-sensitive information for isSubscribed() and getUsedForSync() e2ae5bac
  • #43: Unregister user from Dovecot HTTP Notify plugin asynchronously f00456a1
  • #44: Moved creation of reseller tables to accessing bundles a6cad0b7
  • #48: Retry fetching thread-sorted messages if an inconsistent received date is detected 8270853b 381f39c5
  • #49: Prevent possible NPE when replacing organizer in a calendar event 58fbb18f
  • #54: Added missing org.xml.sax dependency to MANIFEST.MF bbe6bf28
  • #562: Differentiate between deputy feature being 'enabled' and 'available' - appsuite/web-apps/ui 83447b85

Removed

8.29 - 2024-08-28

Added

  • MW-2319: Token Login Variant for PWA Onboarding 99832baa
    • Breaking Change: The file tokelogin-secrets has been removed. See also:
    • SCR-1405: Renamed parameter in /login?action=redeemToken
    • SCR-1406: Added a client defined expiration time to /token?action=acquireToken
    • SCR-1407: Replaced tokenlogin-secrets file with lean configuration
  • MW-2323: Adjust Helm Charts for Redis 7.4 9ca0b47f
  • MW-2339: Deputy-Management via Provisioning API c2073664
  • MW-2353: Documentation for Redis and Active/Active 3409b456

Changed

Fixed

  • Added checks for pretty old messages that should not occur #23 bbb60b00
  • Consider possible MX records on ISPDB look-up for a possible mail account setup #24 a305df9b
  • Optimized reading schema state (update tasks) #10 8cb20be4 2ecd9d47
  • Defer dependent capability checks 47f8b86d
  • Inject fallback display name for *DAV-based subscriptions if missing #22 a6e0cbe0
  • MWB-2512: Use 'no-reply' account for synthetic push sessions 6a623131
  • MWB-2530: Orderly compile path to a shared folder from target user's point of view 5898d475
  • MWB-2667: Deny writing rules requiring unsupported capabilities 55dfa3ba 8c0c8602
  • MWB-2701: Replace possible space characters in URLs with appropriate URL encoded representation (%20) ec8a08f4
  • MWB-2702: Properly compare user mail aliases with punycode 0f78cb94
  • MWB-2705: Fixed writing JSlob IDs as JSON array to channel f8178b31
  • Orderly track new cache service in IMAP bundle #8 6a991f77

Removed

  • MW-2367: Remove Xing integration 52ec3fa3
  • SCR-1426: Removed "FilteringObjectStreamFactory" Service and parent Bundle "com.openexchange.serialization" 3e051826

8.28 - 2024-07-31

Added

Changed

Fixed

Removed

  • SCR-1420: Removed unused xmlbeans library 78d2c577
  • Replaced 'subscription' permission availability with capability checker cdc1836f

8.27 - 2024-07-03

Added

  • MW-2325: Multi-Database Support for Redis da3e7525
    • SCR-1383: New Property com.openexchange.redis.resilientDatabase
  • SCR-1402: New Column priority for Database Tables calendar_event and calendar_event_tombstone b235659d
  • SCR-1403: New field priority in Event model of HTTP API 48e3ffef

Changed

  • MW-2309: Transform Next Caches to Redis 58109405
    • Previous regions FileStorageAccount and UserAlias are now backed by Redis cache
  • MW-2328: Additional (configurable) logging for some SOAP API requests 36705091
  • MW-2337: Transform MessagingAccount, c.o.messaging.json.messageCache, LDAPHostname and Reseller-related Caches to Redis 114878b4
  • MW-2340: Transform FolderUserProperty Cache to Redis 9b1e0ff2
  • MW-2651: Use canonical hostname when accessing distributed managed files 3cc5dafd
  • MWB-2641: Enhanced logging when copying a database table row fails during 'movecontextdatabase' ec85db90
  • SCR-1393: Updated Netty libraries from v4.1.106 to v4.1.111 918566ac
  • SCR-1394: Updated lettuce library from v6.3.1 to v6.3.2 97520f3d
  • SCR-1395: Updated Apache Commons IO library from v2.15.1 to v2.16.1 5add29cf
  • SCR-1396: Updated Apache Commons Codec library from v1.16.1 to v1.17.0 7c98d03e
  • SCR-1404: Updated JCTools (Java Concurrency Tools for the JVM) from v4.0.3 to v4.0.5 986656d6
  • SCR-1411: Added an account index to various calendar tables for improved look-up 40aaf3b0
  • Preparations to selectively invalidate caches after changing 2b3be06c
  • Updated integrated timezone definitions to tzdata2023d 256754a3

Fixed

  • MWB-2639: Don't filter w:sdt elements during sanitizing 5cf45632
  • MWB-2644: Added config option to specify whether to use HTML on reply/forward to/of text-only E-Mails if HTML is chosen as preferred message format 1fa4aa99
  • MWB-2649: Avoid NPE db5c060e
  • MWB-2650: Wrong FCM Push documentation 03419906
  • MWB-2657: Consistent value 200 for property AVERAGE_CONTEXT_SIZE dce8905b
  • MWB-2659: Use proper i18n service to use best-fitting translation for a user's locale 06307248
  • MWB-2664: Lowered periodic log message about completion status of a database clean-up job to DEBUG log level 220ef5f9
  • MWB-2666: Added missing import 5ce65bb4
  • MWB-2670: Redirect to configured logout page as fallback if session no longer exists 91dc5373
  • MWB-2676: Drop details (aka MDC) from JSON-formatted log message if DropMDC marker is present in log event 742918c4 8a65fcfc

Removed

8.26 - 2024-06-05

Added

Changed

  • MW-2326: Re-implemented put-if-absent for KeyDB; e.g. replaced special SET(GET) command with PX and NX option set ea34eba6
  • MW-2332: Export SimpleMeterRegistry 4724b21f
    • add io.micrometer.core.instrument.simple to the list of exported
    • packages in the bundle com.openexchange.metrics.micrometer, to allow
    • using it in unit tests
  • MWB-2622: Added logging when events w/o recurrence are encountered during 'needs-action' generation ae17204a

Fixed

Removed

8.25 - 2024-05-08

Added

Changed

  • MW-2222: DB TLS encryption for k8s fc64b729
  • MW-2263: Introduced Redis-backed cache service having its own cache event framework (based on Redis pub/sub) and refactored existent stand-alone cache invalidation classes to that new service/framework 05ea475b
  • MW-2264: Transform First Caches to Redis b04537ed
  • MW-2266: "Upgrading without Downtimes" in a Kubernetes cluster d032a637
  • MW-2314: Removed dependency from logback-extensions to Apache Commons Lang 2.6 7b007ce4
  • Identify sproxyd clients 95ccd0b4

Deprecated

  • SCR-1373: Deprecation of Apache Commons Lang 2.6

Fixed

  • CP-514: Let authentication plugin signal to ignore the call to it 7f3b0757
  • MWB-1957: Grafana dashboard shows multiple server versions cac3800f
  • MWB-2204: Missing API documentation for oidcLogin and oidcLogout actions of Login module 516239c2
  • MWB-2435: CredstoragePasscrypt not picked up in templates/typeSpecific/secret-envvars.tpl 1d0578df
  • MWB-2530: Added property com.openexchange.imap.assumeUserLocalPartForSharedFolderPath to control if user's local part should be assumed when determining a shared folder path; e.g. assume "jane.doe" instead of "jane.doe@invalid.com" c33caa7e
    • Synchronize all operations on ListLsubCollection objects
    • Removed IgnoreDeprecated methods as they became obsolete with synchronous operations (see Bug#41742)
  • MWB-2552: Decrypt mail prior if needed fdfa0087
  • MWB-2555: Deny scheduling a mail for transport if Guard-protected aa2c61c3
  • MWB-2556: Fixed typo ac08c82f
  • MWB-2562: Avoid issuing unused events for last gone session of a context/user 876e33b3
  • MWB-2563: Ensure JSON data is orderly flushed to output stream c11400a0
  • MWB-2564: Corrected property names in documentation article f8399bd3
  • MWB-2567: Introduced configurable file appender for logback.xml 60e230fb
  • MWB-2571: Use full-fledged HTML parser to locate possible <img> tags inside HTML content 22f36c8e
  • MWB-2577: Com.openexchange.gdpr.dataexport.impl bundle does not start without additional configuration b7e8e048
  • MWB-2582: Do not transform transparent GIF images 4d9afa36

Removed

8.24 - 2024-04-03

Added

  • MW-2174: Make com.openexchange.user.contactCollectOnMailAccess and com.openexchange.user.contactCollectOnMailTransport config-cascade aware. 624c22e1
  • MW-2251: Added REST-API and job to create pre-assembled contexts. Expose metrics for currently existing pre-assembled contexts 66712325
  • MW-2261: Optionally Exclude Disabled Contexts in listcontext e48282e1

Changed

Fixed

  • MWB-2525: Fixed wrong imports in commons compress. Will be fixed upstream with 1.27.0 91d657d9
  • MWB-2545: Use correct variable to pass number of contexts to pre-assemble ebd3ee38

Removed

8.23 - 2024-03-07

Added

Changed

Fixed

  • MWB-2398: Periodically check and remove orphaned cookies referencing no longer existing sessions from requests 35ec1789
  • MWB-2420: Support parsing address string with multiple opening angles '<'; e.g. "<jane@nowhere.com>" c0c6edcf
  • MWB-2482: Avoid excessive HTML processing w/ Jericho HTML parser 814cb61d
  • MWB-2485: Specify core-mw chart resources limits and maxHeapSize ea29bf46
  • MWB-2496: Mitigate with possible java.io.IOException: Resetting to invalid mark when writing ZIP entries to file storage location. Added possibility to have ZIP archive compiled for a certain module being spooled to a local disk. 6a7d3d67
  • MWB-2497: Ensure schema option is not set for pre-assembled contexts 94b73757
  • MWB-2499: Add archive + schedule to mail/folder paths 89361c4a
    • This is necessary to support the permanent switch to these paths
  • MWB-2502: Add missing archive httpi api docu e6aea42e
  • MWB-2504: Fix personal parts not in quotes in email address e9593fd5
  • MWB-2509: Don't mess-up MIME structure by adding multipart/* parts through attachment API 343cb2f8
  • MWB-2511: Look-up draft mail by cached association if possible fd2421dc
  • MWB-2515: Better handling of aborted attachment upload when composing a mail 92f40134
  • MWB-2516: Track SMS provider implementation as optional service 1c027e50
  • MWB-2517: Upgraded MaxMind GeoIP Libraries (SCR-1349) f1b1f9be
  • MWB-2525: Update Apache Commons Compress library from v1.21 to v1.26.0 27f90d39 478d4606
  • MWB-2528: Release acquired connection as soon as possible (e.g. prior to loading file storage data) 2d6d4663
  • MWB-2531: Filter possible parent folder from subfolder listing 70a9d207 2440686f
  • MWB2503: Unmangle folder id before parsing it to int 9c3e089a

8.22 - 2024-02-07

Added

Changed

  • MW-2145: Use cluster map service throughout Middleware code 9bcfd1f9
  • MW-2216: Dropped AJP route and need for JSESSIONID cookie (and HTTP session respectively) 66647c56
  • MW-2226: Remove ignore action for unknown CU 3f1d0227
  • MW-2229: Use pre-assembled contexts on context creation 814bf8ea
    • SCR-1331: Added lean property com.openexchange.admin.usePreAssembledContexts
    • SCR-1332: Added table context_lock to configdb
    • SCR-1339: Added methods in 'com.openexchange.admin.storage.interfaces.OXUserStorageInterface' for using pre-assembled contexts
  • MW-2268: Change copyright headers back to Open-Xchange GmbH 6a15c8d6 c68c8e61 b4b7616f
  • MWB-2430: Don't retry deleting the same events repeatedly when clearing a folder dfaa4dbf
  • MWB-2466: Improved error message in case cryptographic functionalities are requested, but no appropriate features/modules (OX Guard) are installed/available de3b459b
  • OXUIB-2704: Apply requested range when merging results from 808821fa
  • Log some repeatedly occurring messages only once per day 0d141908 a8aea518 9fc93733
  • SCR-1340: Updated Jackson & Fabric8 libraries 11643ffe
  • SCR-1341: Added new lean property to possibly add Open-Xchange server information to HTTP responses 080a0c13
  • SCR-1343: Updated Netty libraries from v4.1.97 to v4.1.106 baa9755a
  • SCR-1344: Updated lettuce library from v6.2.6 to v6.3.1 4a61b713
  • Updated logback-extensions from v2.1.10 to v2.1.11 1c3444db 2807ac93
  • Updated Gotenberg image from v7.9.2 to v8.0.3 to a custom image without MS fonts and chart from v0.6.0 to v1.0.1

Fixed

  • MWB-2250: Send proper notification mail to user in case data export failed due to missing content in selected module(s) 3957b8c0
  • MWB-2311: Include events with unset TRANSP when loading overlapping events from storage 5bcc8210
  • MWB-2401: Send REPLY if comment is removed d8646ca8
  • MWB-2414: Use default object metadata when initializing CopyObjectRequest 3b991f6c
  • MWB-2420: Don't advertise empty address string on corrupt address 0d2475a5
  • MWB-2425: Improved SQL statement and added logging f42fe4d3
  • MWB-2434: Don't empty trash folder in "fire & forget" fashion if processing takes place through (AJAX) job queue. Orderly await completion then. 279bde05
  • MWB-2439: Ensure attendee comment is set on REPLY 50febc36
  • MWB-2444: Support for arbitrary settings in PodSpec is missing bb464b2a
  • MWB-2452: Specify reasonable timeout when checking for possible shared attachment folders or scheduled mail references c755a394
  • MWB-2456: More lenient insert into database on duplicate attempt 014115e3
  • MWB-2458: Properly apply UID conflict strategy d552d3bb
  • MWB-2460: Advertise proper error message to client on exceeded quota 18a5dd56
  • MWB-2461: Updated restricted scopes in "Drive Sync App" example 6a793fc4
  • MWB-2464: Restored "Upgrading Without Downtimes" article 92b32f13
  • MWB-2467: Use context id as fall-back if no context name set d358aead
  • MWB-2470: Adjust 'login2user' table when using preassembled ctx 6aea8bb2
    • SCR-1339: Added methods in 'com.openexchange.admin.storage.interfaces.OXUserStorageInterface' for using pre-assembled contexts
  • MWB-2471: No replacement of illegal Content-Id identifiers 9a70859a
  • MWB-2482: Avoid excessive HTML processing w/ Jericho HTML parser f04860db

8.21 - 2024-01-10

Added

  • MW-2118: Implementation: REST Interface for Log Configuration ed20e40d
  • MW-2119: Extend Log Configuration with "includestacktrace" and "socketLogging" 6776d5a2
  • MW-2190: New metrics for provisioning aspects (PluginInterfaces, storage- and API-calls) b0b135a6
  • MW-2226: Send CANCEL Message when Declining Party Crasher fb9fd9e1

Changed

Fixed

8.20 - 2023-11-29

Added

  • MW-1994: Introduced scheduled mail feature 318e13b9 40809864 1ca1ede2
  • MW-2056: "Forward" Appointments via Email 0372cb66
  • MW-2088: Additional Analyzers for the App Suite Advanced Routing Stack 4b5d6d31
    • MW-2112: Request Analyzer Implementation for Tokens Login and Drive Jump
    • MW-2135: Request Analyzer for "Advertisement" REST endpoint
    • MW-2133: Request Analyzer for Dovecot Push
    • MW-2136: Request Analyzer for config-related "Preliminary" endpoints
    • MW-2134: Request Analyzer for "Admin" REST endpoints
    • SCR-1302: Added context_id field to TokenLogin json response
    • SCR-1284: Add parameters to drive jump redirect for request analyzing
  • MW-2173: Add logging for writeable database access to non-local segments 6387936e
    • SCR-1309: Added lean property com.openexchange.database.logWritesToNonLocalSegments

Changed

Fixed

  • MWB-1730: Orderly check if organizer event copy is targeted by scheduling messages (2) cfd168d4
  • MWB-2328: Use proper MySQL v8 compatible syntax on user creation a86108c0
  • MWB-2354: Ordlery deal with shared folders from different owners with the same display name 50143d91
  • MWB-2358: Drop PRIMARY KEY prior to modifying column belonging to PK, then re-create PRIMARY KEY 6592349d
  • MWB-2360: Mailfilter module not accessible via OAuth (cherry picked from commit 49f1551cc56bbe06bf422a7a6dbeaabb50d38842) 552a0d3f
  • MWB-2366: Respond with "Search too complex" error if applying a wildcard pattern to a mail search expression takes excessively long 93eeba9b
  • MWB-2367: Use simple glob matching for file/directory exclusions, use guarded matcher for regex patterns sent by legacy clients a8f6643f
  • MWB-2368: Advertise "search_in_folder_name" and "search_by_term" for "infostore" database folders c00a21b0
  • MWB-2370: Propagate master changes only into exception events the user actually attends bafc8cd1
  • MWB-2372: Folder API requests are not working with "Application Specific Passwords" 99a61a51
  • MWB-2374: Orderly handle Unified Mail messages when examining a message for scheduling information e45cabd5
  • MWB-2376: Indicate correct part number in multipart upload to S3 f6e52b17
  • MWB-2380: Generate exception events as needed for unsolicited REPLYs to recurring event instances 0abda2b6
  • MWB-2382: Select proper recipient addresses on reply to own mails a9f10444
  • SAZ-4: Use singleton connection to user database for all write accesses eb0836a5

8.19 - 2023-10-24

Added

  • MW-2088: Middleware components for the App Suite Advanced Routing Stack
    • Added new bundles for the request analyzer feature (SCR-1241)
    • New properties for Segmenter Client Service (SCR-1277)
    • Upgraded the gson library from 2.9.0 to 2.10.1 (SCR-1266)
    • New REST endpoint exposed at /request-analysis/v1/analyze to analyze client requests and associate them with segment markers
    • Added first batch of request analyzer implementations covering the most common client requests
    • Introduced request-analyzer service role to deploy and scale conainers independently
    • Implemented segmenter client API to determine active site for a certain segment a2705aa2

Changed

  • MW-2094: Added the 'LastModified' and 'ModifiedBy' metadata to each Sieve rule. 5197be2a
  • MWB-2296: Only allow certain URI schemes for external calendar attachments (SCR-1307) 5277863a
  • MWB-2345: Enhanced logging, added fallback for missing response error code from auth server 3da0018d e2332e6a
  • Removed vulnerable lib sqlite-jdbc and provided needed dependencies by plain snappy-java lib 3d9e92d3
  • Updated core-mw chart dependencies and enabled read-only filesystem for gotenberg 075e07d3
  • Updated vulnerable lib commons-fileupload 1.4 to latest version 1.5 353845aa
  • Updated vulnerable lib jackrabbit-webdav 2.19.1 to version 2.21.19 408e8dd3
  • Updated vulnerable lib net.minidev:json-smart and (its dependency accessors-smart) 2.4.8 to version 2.4.11 3b7dae91
  • Updated vulnerable lib snakeyaml 1.33 to version 2.2. Depending libraries (e. g. jackson-*) required an update too d48c6679
  • Updated vulnerable okio-jvm 2.8.0 lib to latest 3.5.0 and cleaned up dependencies (added okio, updated okhttp + kotlin*, test dependencies) 0aae47f3
  • Removed default values for chart dependencies and link to source 9861882b

Fixed

  • MWB-2220: use existing functionality for secret properties 3e12ce12
  • MWB-2250: No success notification if there are no result files 263f92eb
  • MWB-2283: Don't try to assign a new category when moving to "general" category 10e99977
  • MWB-2296: Check potential UID conflicts for newly added attendees d075d98f
  • MWB-2297: Prefer display name for object permission validation errors 43e8d4b8
  • MWB-2300: Optimized moving folder (and its subtree) to trash 8ef3f975 0b68cc47
  • MWB-2309: Cross-check resource attendees when evaluating 'all others declined' flag in list responses 154ae880
  • MWB-2310: "infostore?action=upload" fails with "EOF" error on Appsuite 8 269accfb c2840ffa
  • MWB-2322: Probe for name of the function for geo conversion (3) 12d7d73f
  • MWB-2333: Sanitize broken/corrupt Content-Type string when parsing multipart content 22a9393b
  • MWB-2336: Aligned naming of settings to the ones used by UI 86bf97bd
  • MWB-2337: Ignore possible "NO [NOPERM]" response when issuing a METADATA command to retrieve deputy information from all IMAP folders 3ce1f58a
  • MWB-2339: Ensure privisioning related log properties are dropped once message has been logged 35022c92
  • MWB-2343: Preferably consider 'X-MICROSOFT-CDO-INTENDEDSTATUS' when parsing event transparency from iTIP 2e04a819
  • MWB-2349: Orderly display plain-text mail w/ alternative text parts baefd0a8 711ea55b
  • MWB-2352: More user-readable error message in case message flags cannot be changed due to insufficient folder permissions 91188e1e
  • Enhanced detection for images with data URIs 997ed5ff
  • MWB-2353: No global lock when initializing in-memory folder map f7fef269

Removed

8.18 - 2023-09-27

Added

Changed

Fixed

Removed

Security

8.17 - 2023-08-30

Added

  • MW-2016: added deployment role 'businessmobility' for USM/EAS deployments 01bfa6d

Changed

  • MW-2003: Handle Time Transparency of Appointments per User
    • Added transp field to attendee
    • Handle transparencies set via CalDAV clients 12aee31
  • SCR-1270: Updated Google API Client libraries 800dc9f
  • MWB-2259: Added more DEBUG and INFO logging for GDPR data export 39f74ae ab77d3e
  • SCR-1275: Upgraded MySQL Connector for Java from v8.0.29 to v8.0.33 76146ce

Fixed

  • MWB-2266: Extremely long-running requests are not terminated f9e86fc 4bce9cd e434d32 4f05fa1 cc0833b 38fea46 2be0655 d3bd8f2 f85638f d494263
    • Hard timeout of 1h for tracked requests of any kind & hard timeout of 60 seconds for mail compose related communication with primary mail backend
    • Introduced wait time for concurrent operations. If elapsed, the operation is aborted
    • Use Apache FreeMarker template engine with safe configuration
  • MWB-2242: Take over selected filestore id properly during user creation
    • SCR-1264: Update task to insert missing references into 'filestore2user' table 867b465
  • MWB-2249: properly disable context during filestore move 92e1649
  • MW-2094: Backwards compatibility for extra metadata in sieve scripts dfee773
  • MWB-2275: Yield cloned objects from Caching LDAP Contacts Access f4d0b36
  • MWB-2250: Added sanity check for Task Status. 1858544
  • MWB-2272: Explicitly LIST a folder once not contained in LIST "" "*" queried from IMAP server ab95588
  • MWB-2265: Prefer to use config-cascade-wise configured value for com.openexchange.imap.imapSupportsACL c01a70a
  • MWB-2274: Properly encode dynamically inserted part of LDAP folder filters 91fe39e
  • MWB-2277: Changed displayed error messages according to customer's suggestion 7754cad
  • MWB-2242: Corrected invocation for 'list_unassigned' in filestore 08481d7
  • MWB-2280: Reset attendee transparency on rescheduling 2f13573

Security

8.16 - 2023-08-01

Added

  • ASP-131: Implemented a MailExportService that converts e-mails to PDFs
    • SCR-1235: Introduced a new action to the 'mail' module for exporting mails as PDFs
    • SCR-1236: Introduced new properties for the MailExportService
    • SCR-1237: Introduced new properties for the CollaboraMailExportConverter
    • SCR-1238: Introduced new properties for the GotenbergMailExportConverter
    • SCR-1239: Introduced new properties for the CollaboraPDFAConverter
    • SCR-1240: Introduced a new capability to activate the PDF MailExportService 4d0de04
  • MW-2036: added contact collector documentation 5441175
  • MW-2073: Log any HTTP header 852548b
  • MWB-2238: allow to configure a purge folder for trash deletion
    • The property com.openexchange.imap.purgeFolder allows to configure a parent folder for renamed trash folder. If one of those folders is configured then the trash is not deleted by the middleware itself. f870dcc
  • Add missing configuration for new packages c8651ec

Changed

  • Improve markdown for core-mw chart 6518c42
  • MW-1862: Upgrade encrypted data dynamically during usage
    • Throw exception if legacy encryption is detected in CryptoService
    • Services/storages detect legacy encryption by this exception and recrypt secrets themselves (by using async task)
    • If shared item protected by secret with legacy encryption is accessed, use LegacyCrypto and log this event (not possible to recrypt here)
    • When users logs in, all items shared by him are collected and checked if secrets needs to be recrypted
  • SCR-1233: Update encryption for passwords of anonymous guest users d5843c4
  • MW-1840: Reworked the CryptoService
    • changed the encrypting algorithm to AES/GCM/NoPadding
    • deprecated the encrypt and decrypt methods with the old mechanisms
    • removed default salting - Now callers are responsible for their salts
    • introduced fallbacks for the old mechanics
    • MW-1894: moved CryptoUtil to c.o.java, replaced all instances of SecureRandom with the centralised version 7a3e3e5
  • MW-1861: Use Implicit Salt in CryptoService
    • Utilise argon2i for password hashing
    • Use the legacy crypto for the Key-based methods
    • Let the callers dictate the byte size for salt and iv
    • Use a 96bit key for IV
    • Re-create secure random after a specified amount of time
    • Use implicit salt and IV in CryptoService 2faf2ca
  • SCR-1252: Updated Netty NIO libraries from v4.1.89 to v4.1.94 8c7eb32
  • SCR-1247: Updated pushy library from v0.15.1 to v0.15.2 8365cff
  • SCR-1245: Updated metadata-extractor from v2.17.0 to v2.18.0 bd4e29c
  • SCR-1253: Updated lettuce library from v6.2.3 to v6.2.5 731ca0b
  • SCR-1246: Updated Google Guava from v31.1 to v32.1.1 1cbe1a4
  • SCR-1231: Updated OSGi target platform bundles 2a0ea4e
  • MWB-2208: Do log possible IMAP protocol errors while trying to acquire a part's content 8867c1b
  • SCR-1255: Updated Apache Tika library from v2.6.0 to v2.8.0 d19b0fc
  • SCR-1256: Upgraded Javassist to 3.29.2-GA 6a6ac84
  • SCR-1244: Updated htmlcleaner from v2.22 to v2.29 ee140df
  • SCR-1243: Updated dnsjava from v3.5.1 to v3.5.2 558227a

Removed

  • SCR-1254: removed support for content_disposition=inline and delivery=view parameter 5d8bfd4

Fixed

  • MWB-2258: Adjust 'credentials' table for enhanced crypto service
  • SCR-1267: Extend password columns in db to store encrypted passwords e6cdc21
  • MWB-2253: removed unused import 804a806
    • to fix not working imageconverter and documentconverter
  • MWB-2252: Keep possible HTML comment markers when examining CSS 62add69
  • MWB-2251: Prefer configured call-back URL regardless of df0ed24
    • applicable dispatcher prefix
  • MWB-2186: The upload of big files gets slower and slower (against MW 8.x) d55359b 0efa733
  • properly load reseller service on demand 3166ed3
  • MWB-2228: Move EventsContactHalo into com.openexchange.halo.chronos bundle 8171cd7
  • MWB-2221: Append additionally available plain text content to existent one 738b68c
  • MWB-2184: Add support for extraStatefulSetProperties and make use of ox-common.pods.podSpec 92f6ce9
  • MWB-2240: Don't output inline images as attachment 8de296c
  • MW-2203: Omit OS version for web clients fca25d2
  • MWB-2228: Move contact halo into com.openxchange.server bundle 691da48
  • MWB-2231: Confirmation buttons not working when inviting a person to a series exception 19f8753
  • MWB-2248: Pass proper range when querying messages from contained sub-accounts if Unified Mail f9c8829
  • MWB-2227: Attendee cannot be re-invited to occurrence of event series 553bb34
  • MWB-2233: Removed ulimit configuration from start script 128ba0b
  • MWB-2241: Lowered log level to DEBUG when moving active/idle sessions to first short-term session container 82938e9
  • MWB-2223: convert all images with CID for the html body c7776e1
  • MWB-2210: Consider virtual folders when getting attachments through chronos module d992d75

8.15 - 2023-07-05

Added

  • MW-2045: Introduced separate bundle for parsing a schedule expression and for initiating periodic tasks. Refactored database clean-up framework to have a "maintenance" window, in which execution of general clean-up jobs is permitted. It also accepts custom clean-up jobs having their own schedule. 8b9bb19
  • MW-2020: Dedicated simple HTTP liveness end-point for early access to liveness check & await availability of database during start-up a476d76
  • MW-1084: Added support for segmented updates with OIDC 2277d3a
  • MW-2073: Log any HTTP header6bdd0d5

Changed

  • MWB-2212: Allow specifying deferrer URL with path cab25e7
  • MWB-2200: Output JSON session representation if it becomes too big 118f0db
  • MWB-2059: Improved access to queried message range in case IMAP server does not support SORT capability fffe20c
  • DOCS-4766: Include pdftool from docker image 4d9d0ad
  • Enhance session representation managed in Redis storage by user database schema 3798214
  • Enhance session representation managed in Redis storage by segment marker (that is the target database schema by now) c008e24
  • MWB-2214: Improved error handling in case a javax.mail.FolderNotFoundException occurs eb5a9f1

Fixed

  • MWB-2193: missed to remove deprecated servlet path to admin API.
    • removed servlet path registration for obsolete path
    • removed obvious parts related to AXIS2 017321e
  • MW-2050: Refactored message alarm delivery worker to orderly use database locks c99b0b5
  • MWB-2130: Try to perform hard-delete by delete-through-rename db8afce
  • MWB-2182: Fixed typo "(E|e)xcpetion" in code b054b35
  • MWB-2130: Try to perform hard-delete by delete-through-rename 54ac301
  • MWB-2201: Do translate standard folders of secondary accounts as well b549cf4
  • MWB-2196: Pay respect to order parameter when sorting contacts by special sorting 1db09a3
  • MWB-2168: Support AWS S3 IMAP role using AWS_WEB_IDENTITY_TOKEN_FILE environment variable 2b35ea82d9ad76
  • MWB-2187: Add necessary imports 61dd61e 51eb12f
  • MWB-2181: Fixed possible null dereference 15519ca f059c8d
  • MWB-2187: Assume configured IMAP host for IMAP authentication does not need to be checked against blocked hosts (see com.openexchange.mail.account.blacklist) 0971c88
  • MWB-2189: Orderly close database statements 083f2c3
  • MWB-2199: Mention the affected YAML file if an invalid format is detected 1b4a086
  • MWB-2178: Handle possible null session on account retrieval 357cc79
  • MWB-2045: Omit specific OS version for macOS clients (2) 78a60c1
  • MWB-2194: Fixed typo in property description b71221f
  • MWB-2179: Orderly handle iTip request without method 58fbf02
  • MWB-2180: Check for possible null return value when looking-up a user with invalid user identifier 44c3ede
  • MWB-2185: Use SMTP default settings when changing a user's assigned SMTP server d1c73cb
  • MWB-1764: Don't check against blocked hosts/allowed ports when obtaining status for subscribed mail accounts 2e7f30a
  • MWB-2214: Try to re-open folder in case a javax.mail.FolderNotFoundException occurs (IMAP folder not LISTed, but SELECTable) d60a70c

8.14 - 2023-06-06

Added

  • MW-1545: Option to hide own Free/Busy time
    • Users can now configure whether their free/busy data is exposed to others (values all, none, internal-only)
    • Appointments that are visible by other means (shared folder, common participation) continue to be visible
    • Default value of setting is all, configurable and protectable (SCR-1197), and exposed to clients in JSlob (SCR-1198) e5d91c8
  • MW-1981: Added caching to the resource storage ed81544
  • SCR-1213: Introduced event flag 'all_others_declined' to indicate if one might be alone in a meeting ae51f2c

Changed

  • MW-2007: Remove man pages from image 85e335d
  • SCR-1219: Upgraded JSoup library in target platform (con.openexchange.bundles) from v1.15.3 to v1.16.1 4d3cbc5
  • INF-173: Disable open-xchange-dataretention-csv by default 9048c7d

Fixed

  • MWB-2160: Avoid excessive parsing of E-Mail addresses possibly containing CFWS personal names; e.g. &lt;bob@example.com&gt; (Bob Smith) 2fb55a6 2ed855c
  • MWB-2150: Don't expunge messages from POP3 storage that could not be added to backing primary mail storage 6cf89a7
  • MWB-2156: Make DAV UserAgents configurable
    • Also add the new user agent part dataaccessd to properly recognize the Mac Calendar clients
    • Introduced new com.openexchange.dav.useragent.* properties, see also SCR-1220 for details e46c9a6
  • MWB-2158: Allow all folder names for iCAL feeds 94c0f36
  • MWB-2149: Prepare refreshing of subscriptions in a blocking manner to avoid having underlying HTTP being being recycled 1bb9343
  • MWB-2171: Split orphan instances on import 2db7d02
  • MWB-2167: Offered parameter and config option for sanitizing CSV cell content on contact export 8b1d684
  • MWB-2137: Unable to Delete Contacts Account if Implementation Missing 883b9bd
  • Redis Session Storage: Use tags to differentiate between common and brand-specific session metrics 6655f6f
  • MWB-2144: Disabled Hazelcast-based session test since Hazelcast has been replaced by Redis cab9736
  • MWB-2161: Allow relative paths in yaml file names 9dd17f3
  • MWB-2162: Limit number of considered filestore candidates to a reasonable amount when determining the filestore to use for a new context/user eb9e0ca c9b4b4d
  • MWB-2139: Check a session's origin for both - guest and application-specific authentication - prior to validating mail access' authentication data 43229c2
  • MWB-2153: Test for application/x-pkcs7-signature as well as application/pkcs7-signature e99052d
  • MWB-2165: Keep quotes in local part of an E-Mail address when extracted from ENVELOPE fetch item afdece9 57df52f
  • Prevent invalid Resource Names for new CalDAV Collections c7fae63
  • MWB-2143: Accept harddelete parameter to let client instantly delete a previously opened composition space ec80711 8ad2a99
  • MWB-2159: Avoid unnecessary error in case of attempting to remove an already dropped session a9e1914 c4ef016
  • MWB-2138: DAV file upload fails with redis session storage 364df81
  • MWB-2149: Prepare refreshing of subscriptions in a blocking manner to avoid having underlying HTTP being being recycled e5da60b
  • MWB-2164: Use header for authorization instead of query string 4634856
  • MWB-2150: Follow up, reset parameter index before re-using 6370ec6
  • MWB-2145: NumberFormatException on partial file upload 1feeed1

8.13 - 2023-05-03

Added

  • MW-1909: iTIP Analysis and Apply actions for Resource Notification Mails
    • Scheduling mails to/from booking delegates of managed resources are sent as iMIP messages
    • Introduced additional header X-OX-ITIP for quick identification of such mails, obeying unique server id (MW-1405)
    • Existing iTIP analysis and apply workflows were extended accordingly
    • Consolidated notifications and scheduling messages and their transport providers
    • Introduced property com.openexchange.calendar.useIMipForInternalUsers to switch to full iMIP messages for internal receivers generally (SCR-1191) 91c0491
  • MW-1908: Send Calendar Notifications to Resource Owners
    • Booking delegates now receive mails upon new, modified, deleted events with the resource
    • Organizers now receive mails upon replies for their booking requests
    • SENT-BY property of originator/recipient as well as mail's From / Sender header are set appropriately c9b28c4
  • MW-1405: Introduced a unique server identifier d891c9d

Changed

  • MW-1913: Changed mail push config to prevent multiple notifications
    • SCR-1158: Added toggle switches for mail push implementations, made existing properties reloadable 6156818

Deprecated

Fixed

Security

8.12 - 2023-04-03

Added

Changed

  • MW-1864: lost and found tests
    • fixed, refactored or deleted several tests
    • refactored SoapUserService and linked classes
    • deleted outdated indexedSearch 7f57ae9
  • MW-1516: Use IDBasedContactsAccess for CardDAV
    • SCR-1145: Refactored CardDAV to use IDBasedContactsAccess
    • SCR-1146: External contacts providers are now synced via CardDAV 50a0416
  • Refactored to have gnu.trove as a bundle in target platform 0ebe8ff
  • MW-1947: Updated vulnerable libraries
  • MW-1955: Hand-through possible Redis connectivity/communication errors to client during runtime & probe Redis end-point until available during start-up aae4f1c
  • MW-1955: Disable max. number of sessions by default for Redis session storage 1b65ceb
  • MW-1947: Updated vulnerable libraries cb95cbe
  • MWB-2059: Removed corrupt sort by UID d316136
  • MWB-2059: Fast sorting by IMAP UID in case sort by received date (INTERNALDATE) is requested 776449b
    • Moved JCTools as bundle to traget platform & updated it from v3.3.0 to v4.0.1 06f7328
    • Refactored to have gnu.trove as a bundle in target platform e6bf595

Fixed

  • MWB-1982: Timeouts for external content do not cancel the connection
    • The fix allows to interrupt client connects and InputStream reads by having hardConnectTimeout and hardReadTimeout parameters that are used for external connections
    • Defaults to 0 (disabled)
    • The following services have a defined default of 120000 for 'hardReadTimeout' and 30000 for 'hardConnectTimeout': autoconfig-server, davsub, icalfeed, rssfeed, snippetimg, vcardphoto 63b60eb
  • MWB-2040: Concurrency issue when moving a touched session to first session container. The moved session might not be "visible" for a short time. 52069a4
  • MWB-2061: Organizer URI not preserved when creating Appointment 7b3e574
  • MWB-2094: Yield a modifiable list instance from messages to copy 3aacd7a
  • MWB-2056: Include all overridden instances in scheduling object resource 3bd7550
  • MWB-1975: start report generation in parallel to task generation 72047d7
  • MWB-2101: Unnecessary Data Retrieved from Filestore when Serving d262bd1
  • MWB-2081: Check table existence prior to deletion attempt (and recognize if developer accidentally passed the cause as last argument) 2372064
  • MWB-2054: Auto-delete guests when owner of per-user filestore is deleted (SCR-1193) a296656
  • MWB-1985: delete all tasks in folders owned by deleted user 5f26d66
  • MWB-2055: Skip unrelated events when iterating events needing 98b8140
  • MWB-2086: Potentially malicious SQL injection when using full-text autocomplete 408fcda
  • MWB-2022: Generate a generic error response providing SMTP server response information in case an SMTP error code occurs while attempting to send a message 0d43966
  • MWB-2091: Mark each messages of a multiple mail forward as forwarded 2cde555
  • MWB-2089: Quite old 3rd party library uses weakly accessible sun.nio.ch package. User newer library making use of up-to-date JRE tools instead. 4ff5296
  • Fixed reading alias from settings 840d937
  • MWB-2080: Added details about 'baseDN' setting in LDAP client configuration 7668409
  • MWB-2058: Populate 'uuid' column when registering a new server as 692222c
  • MWB-1982: Timeouts for external content do not cancel the connection 75086ca

Security

8.11 - 2023-03-08

Added

  • Generic watcher for input stream read processes 85699c6 fd49709 b8dcbad 129749c
  • Added possibility to filter mail drive files 651999c
  • MWB-1959: added possibility to filter http api metric labels a75d3e0
  • Support hard timeout for processor tasks 8f1b1b9
  • SCR-1190: Added property accepting to define a timeout in milliseconds when reading responses from IMAP server after a command has been issued e2ef0ef 023c13c 6e81751
  • Add missing packages to cloud-plugins helm definition 935005a

Changed

  • Updated shipped VTIMEZONE resources 4fd83de
  • MWB-2049: Ensure no wrong push match has been determined for a certain push notification 307d766 f314ec7 ad17da7 cfc57a8 9564229 5dadcfb 508879f 70efa61
  • MWB-2063: Lenient parsing for DTSTAMP property 6401516
  • MWB-2039: Improved concurrency when loading time zone information 2ac192a
  • MWB-2059: Let /mail?action=all end-point support "allow_enqueue=true" parameter 70cf31d 273c592 c7b656f
  • MWB-2040: Added some logging and introduced a session-list mutator lock c625aef 702e171 845d03c e6938e0
  • MW-1964: optimizations referring to spectral findings a9ba5ed
  • MWB-1845: Ensure a reasonable size for buffers, which will be allocated for writing data to a connection b47f248 679df5a
  • Use only one AtomicLong to generate request number 8f34cbc
  • Uses timestamp to generate a unique name for the pre-update job so the helm chart can be applied multiple times in a row if needed. Also adds a (configurable) ttl to expire the job after 24hrs. cfcb71a
  • MWB-2061: Prepare entity processor decoding for internal organizers 270fe7e
  • Upgraded logback-extension to 2.1.5 eed8bf3
  • MWB-2031: Accept new property to disable black-listing of end-point for which an I/O error or HTTP protocol error was encountered 8efbc56
  • MWB-2039: Set missing log message argument d3fd63a
  • Assume property "logback.threadlocal.put.duplicate" is "false" by default to use concurrent MDC property map 6d84989

Removed

Fixed

  • MWB-2054: Auto-delete guests when owner of per-user filestore is deleted (SCR-1193) eaec0e9
  • MWB-2048: Limit accepted POP3 server response to reasonable length/size 478b986
  • MWB-1877: Avoid DNS rebinding attacks where possible (check against possible block-list on connection establishment) 2bf40e2
  • MWB-2038: Respect possible IPV4-mapped IPv6 addresses when checking if contained in a block-list e4566e4 3a97e40
  • MWB-2047: Limit accepted IMAP server response to reasonable length/size 9033774
  • MWB-2037: Drop FOREIGN KEYs from several Groupware tables 8a5ac87
  • MWB-2057: Add XCLIENT extension support for sieve b5e1320
  • MWB-2046: Limit accepted SMTP server response to reasonable length/size 1f8c5e2
  • MWB-1395: Introduced limitation for number of queued image transformation tasks 9c17e53
  • MWB-2020: only apply sanitizing to certain fields ac8c67c
  • MWB-2019: Sanitize non whitespace control character 5e1bf5d
  • MWB-2025: Fixed avoidable exception on DEBUG logging dd4514a
  • MWB-1967: Don't set i18n name for public IMAP namespace if there are multiple ones configured d26a8a5
  • MWB-2071: Indicate conflicting calendar object resource in different collection via CALDAV:unique-scheduling-object-resource precondition 3e20448
  • MWB-2041: Fixed "file not exists" errors for single shared files c95b330
  • MWB-1790: Orderly complain about missing command-line arguments b0a4cf9
  • MWB-2068: Orderly accept connect parameters when updating a mail account's attributes f78c307
  • MWB-2069: Yield "unsupported" result when analyzing links pointing to own shares 1dbc012
  • MWB-2030: Orderly set session- and share-cookie when resolving share link 212bed8
  • MWB-2044: Only update folder last-modified if permissions are sufficient f14cf42
  • MW-1778: Added missing annotation 7b29de7

8.10 - 2023-02-08

Added

  • MW-1910: Extended "needsAction" action to include Delegated Resources
    • Lookup for events needing action is now also done for attendees the user has delegated access to (resources and other users)
    • Introduced new parameter "includeDelegates" for "chronos?action=needsAction" (SCR-1162)
    • Adjusted method signature of "getEventsNeedingAction" throughout chronos stack (SCR-1163) 546c406
  • MW-1898: On-behalf management for Managed Resources
    • Actions 'updateAttendee' and 'update' in module 'chronos' can now be performed on behalf of a resource attendee
    • This can be indicated by targeting the virtual resource folder id
    • Added 'own_privilege' into 'resource' model to reflect the user's scheduling privilege for a certain resource (SCR-1154)
    • Participation status of managed resources will now be 'NEEDS-ACTION' if confirmation is pending
    • Initial hooks for subsequent notification messages are prepared ca32f9c
  • MW-1944: New Action "getRecurrence" in Module "chronos"
    • Clients can now discover whether a change exception is considered as rescheduled or overridden
    • Introduced new action "getRecurrence" in Module "chronos" (SCR-1166)
    • Added corresponding "getRecurrenceInfo" implementation throughout Chronos stack (SCR-1167) 2ff537d
  • MW-1931: Extended provisioning for managed resources
    • SCR-1161: Extended SOAP provisioning interface for managed resources 5af1d63
  • MW-1969: Accept "mail" as original to add attachments to a composition space referring to file attachments of existent mails #2 599a83d
  • SCR-1181: New Properties to Control 'used-for-sync" Behavior of Calendar Folders 821254b
  • INF-80: Activate additional languages in default App uite 8 installations b186a1d
  • MW-1969: Accept "mail" as original to add attachments to a composition space referring to file attachments of existent mails fdbd9d6
  • MW-1888: Upgraded Socket.IO server components to support Engine.IO v4 and Socket.IO v3 512d654 (https://gitlab.open-xchange.com/appsuite/platform/core/commit/0cb2b2f041236ea8c90b1e5863d8bf922f14a442) 57f4869

Changed

  • MWB-2024: Upgraded logback-extension to 2.1.4
  • MW-1912: Allow multiple Password-Change Services 0ad74d8
  • Fixed new warning since Eclipse 2022-06 "Project 'PROJECT_NAME' has no explicit encoding set" 05797c1
  • MW-1957: referring to RFC5455-3.8.5.3, shift start/end date of recurrence master to the first occurrence 1ef8fd9
  • Don't build log message if log level does not fit 35ba26f
  • MWB-1970: Use active database connection when loading enhanced entity data for events 5e20d9b
  • MWB-1970: Don't advertise 'count' capability for database-backed folders cdc6973
  • MWB-1970: Maintain cached list of file storage account identifiers per service 9d8a301
  • MWB-1970: Use active database connection when loading enhanced entity data for events (2) 7efa8fc
  • Added special HTTP protocol exception signaling that a certain URI is denied being accessed 0200041
  • Enrich calendar results with contact details for internal organizers if requested via 'extendedEntities=true' e5950b7
  • MW-1830: Generation of mandatory Secret Values through Helm Chart 9dbb102
  • Indicate 'optional' participants in notification mails e1b31f0
  • Fixed logging & some thread visibility issues 8fa7246
  • MWB-1991: upgraded micrometer from 1.5.1 to 1.10.3 63d112c
  • MWB-2001: Added logging for periodic attachment storage cleaner 55cc090
  • Use thread-safe classes b606631
  • MW-1985: Improve DB warning/error logs 9945242
  • Removed unused Apache POI library from JavaMail bundle f42b86d
  • Fixed some issues announced by Eclipse IDE e1b054b
  • Improved logged error message 9417579
  • Removed remnants cb9b85d
  • Resolved warnings 9778c66 ba04ee4 9fea797 5781986 2dbdc9d 06e0f60 2f2a31f 5e6de37 d206ac0 cf2ad17 e48753a
  • Don't build log message if log level does not fit b55c826

Removed

  • MW-1946 - removed org.apache.tika (and com.openexchange.textxtraction). The required functionality is now provided through the new bundle com.openexchange.tika.util f7076fa
  • MW-1930: Removed direct links from notification mail a2e29a9
  • Removed obsolete test 3733b38

Fixed

  • MWB-1983: Limit line length and header count when fetching HTTP headers of an HTTP message + Replaced usage of java.net.HttpURLConnection with Apache HttpClient where necessary 1d12911
  • MWB-2026: Try to handle possible connection loss errors during mail export operation 6ff82b6
  • MW-1840-8x-patch: Encrypt with old engine, try decrypt with new if possible 0f8a3f3
  • MWB-1999: impp type other than work or home is set properly e3f0d3c
  • MWB-2023: Fixes to pre-update job for installations with multiple complex roles c0bf897
  • MWB-2021: Return proper value for "com.openexchange.subscribe.subscriptionFlag" on folder retrieval 0d186b1
  • MWB-2027: Specify missing error message argument on SQL error beb2904
  • OXUIB-2162: wrong translation for calendar change 23ff72e
  • MWB-1997: API access not fully restricted when requiring 2FA bd67a4e
  • MWB-1983: Limit line length and header count when fetching HTTP headers of an HTTP message + Replaced usage of java.net.HttpURLConnection with Apache HttpClient where necessary c0e345b
  • MWB-2005: Fixed retrieving RSS feed fc07069
  • MWB-2028: Fixed look-up of attachments in case IMAP message has TNEF content 5934db4
  • MWB-2008: Don't allow to access snippets/signatures from other users if not shared 00957b4
  • MWB-1991: properly remove metrics in case pool is destroyed 38286d9
  • MWB-2020: added sanitizing to filter rules + improved the sanitizing regex 21ca22e
  • MWB-1981: properly check returned ical size 5bea149
  • MWB-2025: Fixed avoidable exception on DEBUG logging cf950d6
  • MWB-1939: Print exposure time as fraction if possible 8de8cb3
  • MWB-2006: use owc only on feature branches 65b1aa9
  • MWB-2007: Only set "domain" parameter when dropping a cookie if value is considered as valid: Not "localhost". Not an IPv4 identifier. Not an IPv6 identifier 22f9029
  • MWB-1928: Only check usage (space capacity) of destination storage when moving from user-associated file storage to context-associated one since no entity assignment takes place f76537b
  • MWB-2036: Do escape column names when building database statements for context move 89c9a1f
  • MWB-1991: adjusted 3rdPartyLibs.properties 0fa654a
  • MWB-2021: Return proper value for "com.openexchange.subscribe.subscriptionFlag" on folder retrieval (2) a1775e7
  • MWB-2000: Only query fields necessary to construct contact image URI 10856cc
  • MWB-2010: Set correct compression level for data exports fb07ee6
  • Fixed importing and exporting the same package db5cd45
  • MWB-2000: Only query fields necessary to construct contact image URI (2) 96bfe2d

8.9 - 2023-01-10

Added

  • SCR-1174: New Property 'com.openexchange.resource.simplePermissionMode' d48c9fc

Changed

  • Refactored context restore for better readability and maintenance 197a237
  • Change for MWB-1962: Upgraded Hazelcast from v5.1.2 to v5.2.1 bfe140b
  • IMAP: Check via ID command if IMAP server appears to be a Dovecot server f639fa4
  • Avoid unnecessary creation of byte array when outputting thumbnail content to client 6777845
  • Avoid unnecessary SELECT statement and use "INSERT ... ON DUPLICATE KEY UPDATE" instead 1b47613 a4f414d
  • Direct initialisation of "AttributeChangers" instances 6c4bf47
  • Use singleton w/ dedicated initialisation/dropping 48accd9
  • Thread-safe collection 48d858c
  • Use proper URL for HttpContext when trying 2nd time 2984c65
  • Use singleton w/ dedicated initialisation/dropping edeff71
  • Removed unnecessary variable 749e77b
  • bump helm chart version
    • This is for the new configurable helm chart deployment type 0cf0eb3
  • Cache as immutable set 0033fd3

Removed

  • removed unnecessary join (to be compatible with guest users) d46976c

Fixed

  • fixed some variables in the translation 26065e5
  • MWB-1947:
    • Introduced map for storing/managing state during authentication flow
    • Added property com.openexchange.oidc.mail.immediateTokenRefreshOnFailedAuth to enable/disable immediate refresh of OIDC OAuth tokens on failed authentication against mail/transport service
    • Implemented immediate refresh of OIDC OAuth tokens in case of failed authentication against mail/transport service 276670e
  • MWB-1966: Use proper error code to advertise resource exceptions to client 0e2e389
  • MWB-1995: Check if distribution list members are accessible prior to adding them #2 8beba6a
  • MWB-1963: More reasonable default value of 2GB (2147483648 bytes) for com.openexchange.servlet.maxBodySize property, which now effectively limits file uploads (no chunked HTTP upload anymore due to omission of Apache Web Server that is replaced by Istio). Moreover, introduced new property "com.openexchange.servlet.maxFormPostSize" with default value of 2MB (2097152 bytes) to have a dedicated property to control max. size for form data sent via POST. bd6fe39
  • MWB-1972: Correctly indicate resource type in principal resources 1ef0a13
  • MWB-1995: Check if distribution list members are accessible prior to adding them 153909b
  • MWB-1936: Revisited transport checks 8542d55
  • MW-1989: Don't let delete operation fail upon malformed change exception data while tracking changes 3d47d7e
  • MWB-1985: properly handle public tasks folder in case no-reassign is set 036afcc
  • MWB-1984: Prefer address from EMAIL parameter when deciding if iMIP mails from iCloud are considered as 'known' sender 543dbcc
  • Change for DOV-4625: Detect missing space character in case of corrupt NIL value for PREVIEW fetch item; e.g. "PREVIEW NILUID 1" d2ca600
  • MWB-1956: Apple Mail flag taken over even though Open-Xchange color flag has been explicitly set to NONE 9f18684
  • MWB-1964: Let guest inherit sharing user's filestore if applicable e82657b
  • MWB-1961: throw proper error in case user is missing d682bf8
  • MWB-1934: Don't allow empty "From" address on mail transport e64de8a
  • MWB-1820: only removes guests in case of real failures 110596f
  • MWB-1971: improved matching of distribution list members 1218c53
  • MWB-1851: Return proper folder identifier when saving draft to POP3 account 05e59fc
  • MWB-1951: Use unicode address to resolve mail recipient 7fb1c8c
  • MWB-1986: Fixed SQL error in SELECT statement (Mixing of GROUP columns (MIN(),MAX(),COUNT(),...) with no GROUP columns is illegal if there is no GROUP BY clause) 91105d0
  • MWB-1978: Prevent changes of object id when generating delta event 7de23e6

8.8 - 2022-12-14

Added

  • MW-1857: Option to disable SMTP for 3rd party Mail Accounts a6d5a0b
    • Added a new middleware property com.openexchange.mail.smtp.allowExternal which defaults to true
    • Utilise that property to filter the transport details in the mail account POJOs
    • Introduced a new read-only JSLob entry under io.ox/mail//features/allowExternalSMTP which reflects the middleware's property
    • Forbid sending mail from an external SMTP server as long as the setting is set to false
    • Forbid creating/updating mail accounts with transport information as long as the setting is set to false
    • Added a new warning for preflight/validity checks which reflect this
  • MW-1831: Push configuration for macOS drive client d2a9903
    • SCR-1157: Introduced properties for macOS client push notification configuration
  • SCR-1165: Added options to specify socket read timeout when applying filter to existent messages 53f3023
  • MW-1938: New Templates and Examples section for documentation and adapted jenkins workflow to dynamically point to the correct version of the files 11bbcbc

Changed

  • MAL: Enhanced MSG-1016 error code by actual connect timeout value e194eb1
  • Mail Auto-Config: Let auto-config attempt fail immediately in case login attempt encounters failed authentication due to wrong credentials/authentication data f1fea90 45b68d0
  • MWB-1943: Apply consistent configuration to mail auto-config as used when connecting to the account during runtime 1d682ef
  • Don't build log message if log level does not fit 4b55202
  • MW-1941: Updated and re-structured documentation 373dce4
  • OXUIB-2066: Propagate configured mail fetch limit via JSlob under "io.ox/mail//mailfetchlimit" 895d606
  • Database: Utility method to re-execute DB operation on transaction roll-back error bb47eab
  • MW-1904: Adjust for Reserved Words in MariaDB 10.6 d713340
    • Using back-ticks in SQL statements to handle new reserved words in MariaDB 10.6
    • Only the keyword OFFSET had to be adjusted in SQL statements
  • Don't build log message if log level does not fit 37dd1ad
  • JavaMail: Optimized creation of FetchResponse instances through remembering if RFC8970 "PREVIEW" capability is advertised by IMAP server cb17cd5
  • MAL: Enhanced "MSG-1016" error code by actual connect timeout value c108082
  • MWB-1909: Extended information in case an error occurs 470911d

Fixed

  • MWB-1902: Use localized display name for groups towards clients 27f0a50
  • MWB-1857: Incomplete response when requesting /infostore?action=list 0d4ddce
  • Change for OXUIB-2067: Avoid alternative MIME part look-up by Content-Id in case no such part is contained in IMAP message's BODYSTRUCTURE information 49f3b9e
  • MWB-1944: Don't cache user-sensitive non-file-backed properties e7d0385
  • MWB-1904: Properly indicate 'DAV:need-privilege' precondition with HTTP 403 for PUT requests w/o sufficient privileges 65e64e6
  • MWB-1940: Only inject a valid image URI into mail body's HTML part if such an inline image seems to exist in parental mail d70ce12
  • MWB-1887: Delete folders chunk-wise to avoid excessively big database transaction 244847d
  • MWB-1901: Disable usage of XCLIENT SMTP extension by default 4452098
  • MWB-1948: Perform alternative SASL long against SMTP server if initial response exceeds max. line length of 998 90b9477
  • MWB-1899: Accept escaped wild-card characters in search pattern 141e691
  • MWB-1912: aligned checks with documentation 8de34a9
  • USM-36: Re-introduce CUD actions e83189b
  • MWB-1928: Only check usage (space capacity) of destination storage when moving from user-associated file storage to context-associated one since no entity assignment takes place 06f177b
  • MWB-1909: Handle possible NULL result value when querying counts a64eb82
  • MWB-1950: Do not check the user while resolving mail recipients in recipientOnly modus 263a2b5
  • MWB-1929: Remove sessions from remote nodes during backchannel logout synchronously 82d4253
  • Fix connection leak in test clients a415e8e
  • MWB-1931: Don't allow empty passwords d506a00
  • MWB-1944: Don't cache user-sensitive non-file-backed properties eb74ebf
  • MWB-1887: Don't forget to finish Infostore instance f1d4fc4
  • MWB-1923: Avoid premature closing of attachments a9a5174
  • Use proper fall-back for "com.openexchange.imap.folderCacheTimeoutMillis" setting 87d9b67
  • MWB-1941: Deleteuser fails with invalid CU 035a397
  • MWB-1949: fixed wrong option within the documentation of the command line tool 357d263
  • GUARD-391: Split lines only on newline during normalization 8873cfd

Security

8.7.0-8.7.19 - 2022-11-11

Added

  • MW-1877: Permissions for Resources
    • Introduced resource scheduling privileges 'ask_to_book', 'book_directly' and 'delegate'
    • By default, group 0 has 'book_directly' privileges for each resource("unmanaged mode"), unless defined differently ("managed mode")
    • Extended resource model by a corresponding permissions array, storing privileges per entity
    • HTTP API is adjusted accordingly (SCR-1154)
    • New database table resource_permissions to store resource privileges of users/groups (SCR-1153) 4de788f
  • MWB-1871: added possibility to parse images of nested messages
    • Added new lean property com.openexchange.mail.handler.image.parseNested with defaults to true b42dfec
  • MW-1903: introduced CORE_TEST param to Jenkinsfile 6a4a0ba
  • MW-1507: Calendars for Resources
    • Introduced virtual folder identifiers for resource calendars (SCR-1149)
    • Folder ids can be used in typical "chronos?action=all" requests to get the contained events, actions "advancedSearch", "get" and "list" are supported as well
    • Events returned under the perspective of a virtual resource folder will also have this virtual identifier assigned within the folder field
    • The requesting user will either get all details of an event in a resource folder, or only an anonymized version - depending on whether the event is visible for the user in another folder view or not. 6fbc61a
  • MW-1792: Allow changing of "includeSubfolders" flag through link permission entity e326340

Changed

  • Minor changes for mail auto-config 8221066
  • MWB-1901: Do not issue XCLIENT command if no XCLIENT parameter is supported c915650
  • MWB-666: Send "431 - Request Header Fields Too Large" HTTP error response instead of "400 - Bad Request" when HTTP packet header is too large a7cc43c
  • JavaMail: Check appropriate capability "SEARCH=X-MIMEPART" prior to performing a file name search 3cc2ce8
  • OXUIB-2025: Added support for TEXT search term to filter messages that contain a specified string in the header or body of the message f775905
  • OXUIB-2025: Added support for TEXT search term to filter messages that contain a specified string in the header or body of the message 910eb69
  • MW-1915: Migrated helm lint/publish and docu build/publish to jenkins 391bc2b
  • MW-1813: New approach for centralized version information cf6d801
  • MWB-1826: Added some logging 49c0b33
  • MWB-1891: Don't validate distribution list member's mail address during user copy e3c0f22
  • MW-1914: Extend Webhook integration for Jitsi Conferences
    • Renamed Switchboard Packages and Bundles (SCR-1151)
    • Adjusted Switchboard Configuration (SCR-1152)
    • Implemented new interceptor for conferences of type "jitsi"
    • Transformed switchboard calendar handler into a handler for a generic webhook target 0593a47
  • INF-30: Use globally configured appRoot 16853d6

Removed

  • Removed c.o.dav.push leftovers 4369c69
  • Removed c.o.mail.authenticity leftovers c753f59
  • Removed c.o.oauth.linkedin leftovers 638988b
  • Removed c.o.halo.linkedin leftovers 121f054
  • Removed c.o.subscribe.linkedin leftovers 01d80d1
  • Removed c.o.mail.authentication leftover 2a846b0
  • Removed no more required folder d57ee8c
  • Removed no more required folder 1a482ee
  • Removed obsolete o-x-test-bundles dd513de
  • Removed c.o.printing leftovers a2f7b3e
  • Removed no more required folder 5ee810f
  • Removed redundant/obsolete folder implementations 102032c

Fixed

  • MWB-1907: Restored previous SOAP behaviour by accepting individual parameters instead of a wrapping parameter object d1c2de4
  • MWB-1876: Check redirect location against blacklisted hosts when creating an iCal subscription. e219389
  • MWB-1911: Do not require deputy service in case user replies to a message residing in a shared mail folder 4377dff
  • JavaMail: Add the ability to the API consumers to load the API implementations by using a different protection domain when the API is used with security manager enabled 12f4647
  • JavaMail: Implement equals() and hashcode() on jakarta.mail.Header 8294cf2
  • MWB-1908: Keep remembering OIDC -> OX session id mapping in state after auto-login c11a94d
  • JavaMail: j.m.u.FactoryFinder.factoryFromServiceLoader needs PrivilegedAction 83d9c14
  • MWB-1909: Adjusted queries issued by datamining tool to obey MySQL's ONLY_FULL_GROUP_BY mode a4e293e
  • JavaMail: Fix630 2 75b7136
  • MWB-1893: Don't let delete operation fail upon malformed change exception data while tracking changes 78615b9
  • MWB-1887: Fire events with a separate thread avoiding unnecessary occupation of deletion-performing main thread 0cbd10c
  • MWB-1887: Allow /folders?action=clear being performed as enqueuable operation cc226a7
  • MWB-1898: Added documentation examples for mapping context-/user-id properties to LDAP attributes properly 3be7f84
  • MW-1813: bug fixed by which the version was not resolved correctly aa0d040
  • MWB-1889: Drive mail with expiry date / with password can not be send 7b462f4
  • MWB-1892: Don't filter "com.openexchange.grizzly.serverName" property from log event 4d342b8
  • MWB-1878: Handle empty Disposition-Notification-To header on delete cf06c47
  • MWB-1882: Upgraded Apache Commons Text from v1.9 to v1.10.0 7a911be
  • MWB-1890: Do obey folder types restriction when constructing search term for looking up events of user 87ec00e
  • MWB-1874: Remove references to contact in distribution list member when contact's email is cleared db7ef9e
  • MWB-1695: Introduced "requiredCapabilities" for App-specific Password Applications SCR-1155 ec439e9
  • MWB-1865: Use internal resources for image build 320b808
  • MWB-1834: Check command line options before accessing the reseller service e94ab2a
  • MWB-1865: Use internal resources for image build a48433d
  • use proper fallback property for exclude file pattern 0eadd7d
  • MWB-1866: Orderly consider public folder mode when userizing event data in result tracker 15274d9
  • MWB-1719: Don't forget to reassign returned Stream instance when applying filter a76a018
  • MWB-1870: Multifactor Webauthn provider throws UnsupportedOperationException 8c8a2b7

8.5.0-8.6.3 - 2022-10-05

Added

  • MW-1785: Introduce pre-upgrade task framework 6396946
  • MW-1815: Attach files from drive to chronos events fabeec5
  • MW-1647: Handle linked attachments for appointments fc5477c
    • Externally hosted attachments can now be stored for appointments, with an URI pointing to the data
    • Introduced new field uri for AttachmentData object (HTTP API), with column id 891
    • Added new field uri for c.o.groupware.attach.AttachmentMetadata DTO as well
    • Adjusted interface c.o.chronos.storage.AttachmentStorage and implementation to reference non-managed attachments properly during deletions
    • Breaking Change Update task com.openexchange.groupware.update.tasks.AttachmentAddUriColumnTask to add column uri in table prg_attachment
  • MW-1817: Integrate upgrade preparation bundle into core-mw helm chart 997fb26
  • MW-1607: Add domain support for push payload e924d1b
    • Drive clients can now subscribe for push notifications using domains 'myFiles', 'sharedFiles' and 'publicFiles'
    • The domain value gets re-inserted into push payload for transport 'apn2'
    • Removed configuration property com.openexchange.drive.events.apn2.ios.pushDomain

Changed

  • MWB-1849: Improved parsing of OAuth provider error message 31933c5
  • MWB-1826: Added useful DEBUG log messages when adding an image to a signature 1f1e8f9
  • MWB-1828: Improved handling of javax.net.ssl.SSLException 5180c7b
  • MWB-1849: Improved parsing of OAuth provider error message c950617
  • MWB-1830: Improved error message in case of denied request e0d3c94
  • MWB-1759: Deny requesting large message chunk in case client queries more than only identifier fields 8e6ddb4
  • MWB-1800: Introduced configuration option 4e95327
    • "com.openexchange.calendar.storage.rangeIndexHint" to allow insertion of index hints into typical database queries of the calendar module
  • MWB-1776: Utility method to clear DNS cache b9c7ff3
  • MWB-1759: Don't query flags if not required 24729be
  • MWB-1716: Added some helpful logging about bundle status 1918165
  • MWB-1716: Added some helpful logging about bundle status d056354
  • MWB-1764: Added DEBUG logging when checking status of a mail account yields an error 2119413
  • MWB-1750: Improved handling of possible javax.net.ssl.SSLException "Unsupported or unrecognized SSL message" 0af276a
  • MWB-1776: Added logging when DNS cache has been cleared fe93ae2
  • MWB-1759: Delay initialization of TLongObjectHashMap bbb6a9f
  • MWB-1759: Nullify intermediate result 103f70f

Removed

Fixed

  • MWB-1842: Prophylactically decode potentially MIME-encoded strings in property values in iCalendar files from MS Exchange 24af8ec
  • MWB-1848: removed fallback value for manifest version field 8b468a8
  • MWB-1839: Use dedicated introductions for forwarded meeting requests the user is not invited to e03a09e
  • MWB-1608: Fixed RuntimeExceptions in calendar stack bd422ac
  • MWB-1808: properly detect reminders with missing permissions bb3f1e6
  • MWB-1813: Added documentation for mail?action=expunge 56bff39
  • MWB-1811: Ensure internal entity is admin, prevent permission 57ca47b 00b7702 1358b10
  • MWB-1838: Yield no result when auto-processing REQUEST with party crasher, let client re-apply iTip independently of message status flag 8ec6208
  • MWB-1840: Return empty ajax respone if no event was found during resolve action 81be74c
  • Add missing com.openexchange.gab import in bundle com.openexchange.admin.plugin.hosting 9749ecb
  • MWB-1805: Use URL-decoded variant of username in Authorization header for macOS Contacts client if applicable 7d805e8
  • MWB-1735: Fixed links in Command Line Tools articles b9ac1ac
  • MWB-1711: Removed obsolete ContextDbLookupPluginInterface d9309b1
  • MWB-1721: Evaluate 'X-Device-User-Agent' and pretty print common EAS devices in active clients overview 7b197c1
  • MWB-1702: Skip premature cache invalidations to prevent race conditions upon folder update 7e643b8
  • MWB-1787: Prefix download URI with current scheme/host if no absolute URI is configured in manifest 5424d16
  • MWB-1737: Removed obsolete ETag check after HTTP 409 errors eac8317
  • MW-1817: Proper yaml in overwrite configmap if no properties are set 7c4f3c8
  • MWB-1760: Properly indicate "share not found" status for invalid targets of anonymous shares 152f332
  • Apply maxHeapSize to init containers 493c5e4
  • MWB-1722: Do not convert aperture value, because we already read the f-number from exif data c5d97dc
  • Disable hz update bundle by default 01c5d7d

Security