App Suite Middleware
CLT
SCR-1691
Summary: Added command-line tools for mail signatures
Added the following command-line tools for mail signatures
usage: listsignatures -c <contextId> -u <userId> -A <masterAdmin | contextAdmin> -P <masterAdminPassword |
contextAdminPassword> [-p <RMI-Port>] [-s <RMI-Server] [--responsetimeout <responseTimeout>] |
[-h]
-A,--adminuser <adminUser> Admin username
-c,--context <contextId> The context identifier
-h,--help Prints this help text
-p,--port <rmiPort> The optional RMI port (default:1099)
-P,--adminpass <adminPassword> Admin password
--responsetimeout <timeout> The optional response timeout in seconds when reading data from server (default: 0s;
infinite)
-s,--server <rmiHost> The optional RMI server (default: localhost)
-u,--user <userId> The user identifier
Command-line tool for listing signatures of a certain user.
usage: deletesignature -c <contextId> -u <userId> -s <signatureId> -A <masterAdmin | contextAdmin> -P
<masterAdminPassword | contextAdminPassword> [-p <RMI-Port>] [-s <RMI-Server] [--responsetimeout
<responseTimeout>] | [-h]
-A,--adminuser <adminUser> Admin username
-c,--context <contextId> The context identifier
-h,--help Prints this help text
-i,--identifier <signatureId> The signature identifier
-p,--port <rmiPort> The optional RMI port (default:1099)
-P,--adminpass <adminPassword> Admin password
--responsetimeout <timeout> The optional response timeout in seconds when reading data from server (default: 0s;
infinite)
-s,--server <rmiHost> The optional RMI server (default: localhost)
-u,--user <userId> The user identifier
Command line tool to delete a certain signatures of a user.
[8.47.52]
General
SCR-1656
Summary: Updated Apache Commons CLI library from v1.9.0 to v1.11.0
Updated Apache Commons CLI library from v1.9.0 to v1.11.0 in target platform (com.openexchange.bundles)
SCR-1650
Summary: Updated Jackson libraries from v2.19.2 to v2.21.0 in target platform
Updated Jackson libraries from v2.19.2 to v2.21.0 in `}com.openexchange.bundles}
jackson-annotationsv2.19.2 to v2.21.0jackson-corev2.19.2 to v2.21.0jackson-databindv2.19.2 to v2.21.0jackson-dataformat-cborv2.19.2 to v2.21.0jackson-dataformat-xmlv2.19.2 to v2.21.0jackson-dataformat-yamlv2.19.2 to v2.21.0jackson-datatype-jsr310v2.19.2 to v2.21.0jackson-datatype-jsr353v2.19.2 to v2.21.0jackson-jakarta-rs-basev2.19.2 to v2.21.0jackson-jakarta-rs-json-providerv2.19.2 to v2.21.0jackson-jakarta-rs-xml-providerv2.19.2 to v2.21.0jackson-module-jakarta-xmlbind-annotationsv2.19.2 to v2.21.0jackson-module-jaxb-annotationsv2.19.2 to v2.21.0
3rd Party Libraries/License Change
SCR-1657
Summary: Updated Apache Commons Collections4 library from v4.4 to v4.5.0
Updated Apache Commons Collections4 library from v4.4 to v4.5.0 in target platform (com.openexchange.bundles)
SCR-1655
Summary: Update Apache Commons Codec
Updated Apache Commons Codec from v.1.17.2 to v1.21.0 in target platform (com.openexchange.bundles)
SCR-1654
Summary: Updated Apache Mime4j
Updated Apache Mime4j libraries in target platform (com.openexchange.bundles)
apache-mime4j-core-0.8.10.jar->apache-mime4j-core-0.8.13.jarapache-mime4j-dom-0.8.10jar->apache-mime4j-dom-0.8.13.jarapache-mime4j-storage-0.8.10.jar->apache-mime4j-storage-0.8.13.jar
SCR-1653
Summary: Upgraded JSoup library
Upgraded JSoup library from v1.21.1 to v1.22.1 in target platform (com.openexchange.bundles)
SCR-1652
Summary: Updated OSGi target platform bundles
Updated the following OSGi target platform bundles
org.eclipse.osgi_3.23.200.v20250812-1847.jarupdated toorg.eclipse.osgi_3.24.0.v20251126-0427.jar
SCR-1649
Summary: Updated Fabric8 libraries from v7.4.0 to v7.5.2
Updated Fabric8 ibraries from v7.4.0 to v7.5.2 in bundle io.fabric8.kubernetes
kubernetes-client-7.5.2.jarkubernetes-client-api-7.5.2.jarkubernetes-httpclient-jdk-7.5.2.jarkubernetes-model-admissionregistration-7.5.2.jarkubernetes-model-apiextensions-7.5.2.jarkubernetes-model-apps-7.5.2.jarkubernetes-model-autoscaling-7.5.2.jarkubernetes-model-batch-7.5.2.jarkubernetes-model-certificates-7.5.2.jarkubernetes-model-common-7.5.2.jarkubernetes-model-coordination-7.5.2.jarkubernetes-model-core-7.5.2.jarkubernetes-model-discovery-7.5.2.jarkubernetes-model-events-7.5.2.jarkubernetes-model-extensions-7.5.2.jarkubernetes-model-flowcontrol-7.5.2.jarkubernetes-model-gatewayapi-7.5.2.jarkubernetes-model-metrics-7.5.2.jarkubernetes-model-networking-7.5.2.jarkubernetes-model-node-7.5.2.jarkubernetes-model-policy-7.5.2.jarkubernetes-model-rbac-7.5.2.jarkubernetes-model-resource-7.5.2.jarkubernetes-model-scheduling-7.5.2.jarkubernetes-model-storageclass-7.5.2.jarzjsonpatch-7.5.2.jar
SCR-1648
Summary: Updated lettuce library from v6.5.5 to v6.8.2
Updated lettuce library from v6.5.5 to v6.8.2 in bundle io.lettuce
lettuce-core-6.8.2.RELEASE.jar
SCR-1647
Summary: Updated Netty libraries
Updated Netty libraries from v4.1.124 to v4.1.130 in bundle io.netty
- netty-buffer-4.1.130.Final.jar
- netty-codec-4.1.130.Final.jar
- netty-codec-dns-4.1.130.Final.jar
- netty-codec-http2-4.1.130.Final.jar
- netty-codec-http-4.1.130.Final.jar
- netty-codec-socks-4.1.130.Final.jar
- netty-common-4.1.130.Final.jar
- netty-handler-4.1.130.Final.jar
- netty-handler-proxy-4.1.130.Final.jar
- netty-resolver-4.1.130.Final.jar
- netty-resolver-dns-4.1.130.Final.jar
- netty-transport-4.1.130.Final.jar
- netty-transport-native-unix-common-4.1.130.Final.jar
- netty-transport-classes-epoll-4.1.130.Final.jar
- netty-transport-native-epoll-4.1.130.Final.jar
- netty-transport-classes-kqueue-4.1.130.Final.jar
- netty-transport-native-kqueue-4.1.130.Final.jar
- netty-tcnative-classes-2.0.72.Final
SCR-1646
Summary: Updated OpenId Connect libraries
Updated OpenId Connect libraries in bundle com.nimbus:
accessors-smart-2.4.11.jarupdated toaccessors-smart-2.5.2.jarasm-9.1.jarupdated toasm-9.7.1.jarcontent-type-2.2.jarupdated tocontent-type-2.3.jarjson-smart-2.4.11.jarupdated tojson-smart-2.5.2.jarnimbus-jose-jwt-10.0.2.jarupdated tonimbus-jose-jwt-10.6.jaroauth2-oidc-sdk-10.7.jarupdated tooauth2-oidc-sdk-11.32.jar
SCR-1641
Summary: Added RE2/J - linear time regular expression matching in Java
Added Google Open Source library RE2/J "re2j-1.8.jar" as bundle to target platform "com.openexchange.bundles". RE2 is a regular expression engine that runs in time linear in the size of the input.
SCR-1638
Summary: Updated Spring Framework libraries
Updated Spring Framework libraries from v5.3.39 to v6.2.15 in bundle com.openexchange.xml
com.openexchange.xml/lib/spring-beans-5.3.39.jar->com.openexchange.xml/lib/spring-beans-6.2.15.jarcom.openexchange.xml/lib/spring-core-5.3.39.jar->com.openexchange.xml/lib/spring-core-6.2.15.jarcom.openexchange.xml/lib/spring-jcl-5.3.39.jar->com.openexchange.xml/lib/spring-jcl-6.2.15.jar
API - Java
SCR-1505
Summary: Added methods to the MultifactorLoginService
Extended the com.openexchange.login.multifactor.MultifactorLoginService interface by following methods:
/**
* Checks if multi-factor enforcement property is set and the enforceMfa flag is set for a given user.
*
* @param userId The user identifier
* @param contextId The context identifier
* @return <code>true<code> If multi-factor enforcement is enabled
* @throws OXException
*/
boolean checkEnforceMultiFactorAuthentication(int userId, int contextId)throws OXException;
/**
* Checks if multi-factor enforcement property is set for a given user.
*
* @param userId The user identifier
* @param contextId The context identifier
* @return <code>true<code> If multi-factor enforcement is enabled as dismissable; otherwise <code>false</code>
* @throws OXException If something went wrong trying to access the database
*/
boolean checkEnforceMultiFactorAuthenticationDismissable(int userId, int contextId);
/**
* Records the login attempt for a given user.
*
* @param userId The user identifier
* @param contextId The context identifier
* @throws OXException If something went wrong trying to access the database
*/
void recordLoginAttempt(int id, int contextId) throws OXException;
/**
* Gets the login information record.
*
* @param userId The user identifier
* @param contextId The context identifier
* @return A MultifactorEnforcementInformation record holding the information
* @throws OXException If something went wrong trying to access the database
*/
MultifactorEnforcementInformation getLoginInformation(int id, int contextId) throws OXException;
/**
* Enhances JSON with multi-factor enforcement data.
*
* @param json The JSON content to enhance
* @param userId The user identifier
* @param contextId The context identifier
*/
void enhanceLoginJson(JSONObject json, int userId, int contextId);
/**
* Resets the login information for an user.
*
* @param userId The user identifier
* @param contextId The context identifier
* @throws OXException If something went wrong trying to access the database
*/
void resetLoginInformation(int userId, int contextId) throws OXException;
API - REST
SCR-1504
Summary: Introduced a new REST interface for multifactor enforcement
New REST endpoint is introduced in order to manage multifactor enforcement.
Retrieve login information for a certain user:
GET /admin/v1/contexts/\{context-id}/users/\{user-id}/multifactor/enforcement
Response:
{
"enforceMfa": true,
"loginCounter": 5,
"firstLogin": "<time-stamp>"
}
Reset login information for a certain user:
DELETE /admin/v1/contexts/\{context-id}/users/\{user-id}/multifactor/enforcement
CLT
SCR-1503
Summary: Add CLT for multifactor enforcement
Command-line tool resetenforcemfa to allow a reset of the multi-factor enforcement informations
usage: resetenforcemfa -c <contextId> -i <userId> -A <masterAdmin | contextAdmin> -P <masterAdminPassword |
contextAdminPassword>
-A,--adminuser <adminuser> Admin username
--api-host <arg> URL for an alternative REST end-point host. Example: 'https://192.168.0.1:8443'.
Default: 'http://localhost:8009'
--api-root <arg> URL to an alternative HTTP API endpoint. Example: 'https://192.168.0.1:8443/admin/v1/'
-c,--contextid <arg> A valid context identifier.
-h,--help Prints this help text
-i,--userid <arg> A valid user identifier.
-P,--adminpass <adminpassword> Admin password
The command-line tool to reset the multifactor enforcement for an user.
Configuration
SCR-1645
Summary: Added various properties for proxy functionality
Added various lean properties for proxy functionality
com.openexchange.proxy.pathSpecifies the path taken when replacing URIs and for registering proxy Servlet. Default value is"/servlet/proxy". It is reloadable, but not config-cascade aware.com.openexchange.proxy.servlet.enabledThe switch to enable/disable Proxy Servlet. Default value istrue. It is reloadable, but not config-cascade aware. If Proxy Servlet is enabled,com.openexchange.proxy.encodingis required being set to"object".com.openexchange.proxy.encodingThe method how original URI and accompanying proxy registration is encoded."plain": Only the original URI is base64-encoded."object": The complete registration object is compressed and obfuscated within a base64 representation. Default value is"object". It is reloadable, but not config-cascade aware.
SCR-1501
Summary: Added new properties for MFA enforcement
Introduced new lean webauthn properties to use webauthn as a 2nd factor and as a preparation for webautn as a "full" authentication service
com.openexchange.multifactor.enabledDefines if MFA should be enforced.com.openexchange.multifactor.login_limitConfigures the amount of login attempts a user can do before MFA is really enforced.com.openexchange.multifactor.period_limitConfigures the period of time in days, starting from the first login, which defines when MFA is really enforced.
Database
SCR-1502
Summary: Add table for mfa enforcement
In order to implement the possibility to enforce multi-factor, a database table called multifactor_enforcement needs to be created to store the relevant informations.
CREATE TABLE `multifactor_enforcement`(
`cid` int(10) unsigned NOT NULL,
`id` int(10) unsigned NOT NULL,
`enforceMfa` TINYINT(1) DEFAULT 0,
`loginCounter` int(10) DEFAULT 0,
`firstLogin` DATETIME DEFAULT NULL,
PRIMARY KEY (`cid`, `id`)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci"