ASB-162: Parse mail filter rule metadata for non-IPv4 update sources and heal polluted rule names SCR-1844: ASB-132: SCR-1844: Report send-on-behalf-of and the granter's addresses in deputy action=reverseIds SCR-1843: ASB-132: SCR-1843: Honor an explicitly configured read responses timeout for primary and secondary IMAP accounts SCR-1844: ASB-132: SCR-1844: Light-weight deputy action=reverseIds listing grantors without resolving grant details ASB-147: Keep inline image references resolvable across composition spaces Require the folder creation permission for renaming or moving mail folders Honor the timezone parameter when converting a single mail outside the get action (support#1598) ASB-132: Serve the reverse deputy look-up from one cached server-wide sweep instead of one sweep and connection per grant Take a snippet's identity from the database instead of stale file-storage headers (support#1329) Only require administrative rights for mail folder updates that actually change permissions Indicate the folder admin flag on administrable calendar folders of shared accounts and reject permission changes Error FLD-1001 on creating new subscribed calendar folder for shared accounts SCR-1826: New metrics for the Redis circuit breakers and bulkhead SCR-1827: New configuration option for the Redis connector start-up behavior SCR-1827: Await the Redis end-point on start-up by default again Register RedisConnectorService only once the Redis end-point answered (#23) Abort start-up when the Redis end-point reports a condition that will not resolve Deny when a security-relevant rate limit fails with an unchecked exception Keep awaiting a Redis end-point that answers but is not usable yet Let security-relevant rate limits deny instead of passing when they cannot be enforced Report an unusable lock-out store instead of reading it as "not locked out" Restore the back-off jitter and make the resilience signals attributable Wait out Redis conditions by default instead of aborting start-up on unlisted ones Do not fail sessiond start-up because the timer task lock probe cannot reach Redis (#22) Establish the session structure version along with session data (#24) Attach each Redis pub/sub listener once, even when a subscribe succeeds between retries Build the command facades with the timeout of the running operation Do not drop session data from the deferred structure version check Retry a Redis pub/sub listener whose attach attempt failed Take the command facade timeout from the configuration instead of the shared connection Write the session structure version when there is no stale data to keep SCR-1825: New configuration option for Redis Sentinel authentication SCR-1822: Command-line tool threaddump for dumps covering virtual threads Collect a virtual-thread-aware dump in oxsysreport Cover virtual threads in the out-of-memory thread dump Drop the thread dump from the uncaught-exception handlers Dump virtual threads too when the graceful shutdown does not get through State in showruntimestats that virtual threads are not listed SCR-1822: Command-line tool threaddump for dumps covering virtual threads Collect a virtual-thread-aware dump in oxsysreport Cover virtual threads in the out-of-memory thread dump Drop the thread dump from the uncaught-exception handlers Dump virtual threads too when the graceful shutdown does not get through State in showruntimestats that virtual threads are not listed ASB-130: Apply the best-effort invalidation to the mail account insert path as well ASB-130: Do not fail a stored mail account because its trailing cache invalidation could not reach Redis Always evict grantee caches in the doveadm deputy revoke path too, matching the IMAP provider (support#1126) Unsubscribe deputy from shared mailbox when aggressive ACL cleanup wipes the restored previous rights (support#1126) Confirm absence of a calendar folder on master database before treating it as deleted, so stale replica reads or cache transients no longer surface as folder deletion (support#1599) Fall back to database when the folder cache transiently returns null so folder look-ups keep their non-null-or-throw contract (support#1599) Update the documentation-properties plugin to 6.0.3 so the plugin classpath survives jackson 2.22.1 from plugin-bom 2.2.0 Invalidated grantee caches on shared-account/deputy revocation so revoked shared accounts and mailboxes no longer linger (support#1126) Do not purge calendar data when a folder cannot be resolved (support#1599) Do not report a failed IMAP quota look-up as exceeded quota (support#1636) Route getContextAdmin to the site owning the context instead of recursing into itself (support#1632) SCR-1814: Let the reseller extension take part in the usercopy provisioning call - /appsuite/platform/middleware Release the per-session JMAP trace appender when the access is retired - /appsuite/platform/middleware (core#11) Match contexts to their owners by identifier when checking ownership of multiple contexts - /appsuite/platform/middleware (core#15) Replace 'which' command by 'command -v' to make it wolfi compatible Check attachment quota and max mail size against the spooled attachment size (support#1627) Group search could pin a CPU core indefinitely on a crafted wild-card pattern (support#1628) Keep writing a datamining report when a database schema is unreachable (support#1618) Close the static service registry mock that leaked into other POP3 tests Correct the misspelled mail capability cache idle time property, keeping the old name as a fallback Expire a failed or degraded mail server capability probe instead of caching it forever Documentation for the mail account property infixes Honor the ".secondary" property infix alongside ".primary" for mail accounts Treat empty and whitespace-padded mail account property values correctly Resolve allowFetchSingleHeaders per mail account in the conversation view Documentation for the virtual-thread executor metrics Documentation for the virtual-thread executor metrics Micrometer meters and JMX MBean for the virtual-thread executor Validate vacation notice sender address against the account the rule belongs to (support#1611) Release the IMAP debug logger on every path that gives up an IMAP session (#5) Correct the HTTP engine switch runbook for the access log switch, packaging and configuration file (#532) Report the statistics of whichever HTTP engine is running in showruntimestats (#532) End-to-end regression test for a decorating javax filter on the Jetty engine Run the bundle class path check in the artifact-producing build path Stop advertising the Jetty package as an HTTP service alternative (#532) Answer only GET and HEAD on the Jetty liveness listener Correct the Jetty access log documentation and the bundle stop rationale Answer what javax cannot express from the original request when re-bridging Correct the Jetty connector's forwarded header trust, shut-down grace period and header compliance Evaluate repeated forwarded-for field lines and sanitize the tracking identifier Keep the jakarta wrapper identity when re-bridging a foreign servlet request wrapper Release the in-flight gate even when the asynchronous hand-off fails Strip control characters from client-supplied log properties in every case Register whiteboard servlet patterns as sub-tree aliases like the Grizzly engine (#532) Accept only http and https from the forwarded protocol header and cap the patient stop timeout Await every alias and asynchronous cycle before a Jetty servlet or filter is destroyed Keep foreign servlet wrappers in the path when crossing the servlet bridge Sanitize the user agent and Unicode line separators before they reach the log context Unregister the aliases of a shared whiteboard servlet collectively IMAP command injection through user flags and the headers request parameter Redirect reads to the master while a read replica reports broken or excessive replication lag (#4) Restore replica staleness check by tracking the replication monitor counter process-locally (support#1599) Advertise cross-context mail grantees as type user in extended permissions Promote guest recipients only on enabled cross-context surfaces PBSR-1717: Cross-Context Sharing, Deputy and Collaboration SCR-1730: Added New Bundles for Cross-Context Sharing SCR-1731: Added the "xctx_liaisons" Cross-Context Liaison Registry Table and Create-Table Update Task SCR-1732: Added a Permission-Context Column to the Folder-Permission Tables SCR-1733: Restructured the Folder-Permission Primary Key to Include the Context Column SCR-1734: Deputy Storage Table Qualifies the Deputy Entity With Its Context SCR-1735: New Configuration Options for Cross-Context Sharing SCR-1736: Folder Permissions Accept and Return Cross-Context Principal Identifiers SCR-1737: New Read-Only Contact Field Exposing the Cross-Context Qualified Identifier SCR-1738: Cross-Context Deputy via Qualified Identifiers (Deputy HTTP API) SCR-1739: Cross-Context Principal Representation Over WebDAV / CalDAV / CardDAV SCR-1740: New Administrative REST Endpoints for Cross-Context Liaison Audit and Purge SCR-1741: Cross-Context Deputy in the Admin RMI Provisioning API SCR-1742: Cross-Context Deputy in the Admin SOAP Provisioning API SCR-1743: Cross-Context Sharing Access-Control Behavior SCR-1758: New Command-Line Tool claimfolderadmin to Claim/Elevate a Folder Administrator on Public Folders SCR-1776: HTTP API for proxy servlet - PUT /proxy?action=getUris SCR-1781: Micrometer metrics and access-log rotation for the Jetty HTTP engine SCR-1782: Optional cleartext HTTP/2 (h2c) for the Jetty HTTP engine SCR-1787: Apache HttpClient 5 platform bundles and HttpClient-5-based managed HTTP client service SCR-1797: Configurable additional parameters for OAuth token exchange (scheduled + snoozed mail) SCR-1798: List built-in spam handler names in secondary account CLI help SCR-1801: New Administrative REST Servlet for Querying Free/Busy Data Set personal folder owner for folders below personal Infostore folder (core#527) Persisted-ACL end-to-end case to phantom mail folder share reproducer (core#547) Values-driven topologySpreadConstraints, PDB unhealthyPodEvictionPolicy and HPA support to core-mw chart (support#1568) Drop the legacy "folder" mapping from the shared-account mail JSlob Keep SQL exception identity across RMI-safe exception wrapping SCR-1746: Upgraded third-party libraries SCR-1747: Migrated JAX-RS from Jersey 2.17 to Jersey 3.1.x (jakarta.ws.rs) SCR-1748: Load mails referenced from PIM attachments or Infostore files SCR-1749: Upgraded Grizzly to 5.0.2 SCR-1750: Upgraded Netty libraries to v4.2.15 and Lettuce to v7.6.0 SCR-1752: Upgrade Micrometer to 1.17 (migrate Prometheus registry from simpleclient to prometheus-metrics) SCR-1754: Migrated S3 file storage to AWS SDK for Java v2 SCR-1755: Upgraded Kubernetes Java Client (fabric8) to v7.8.0 SCR-1756: Jetty-based HTTP engine as a switchable alternative to Grizzly SCR-1757: Markup-aware hard truncation of HTML content for "view=raw" with "max_size" SCR-1759: Seal proxy registration URLs via ObfuscatorService instead of static DES key SCR-1761: Apply Compact Object Headers JVM flag independently of custom javaOpts.other in core-mw chart SCR-1762: Upgraded Liquibase to v5.0.3 and OpenCSV to v5.12.0 SCR-1763: Upgraded OkHttp to v5.4.0 SCR-1765: Upgraded BouncyCastle to v1.84 SCR-1766: Upgraded webauthn-server-core to v2.9.0, reactor-core to v3.8.6 and zero-allocation-hashing to v2026.0 SCR-1767: Upgraded ROME to v2.1.0, jaudiotagger to v3.0.1, Caffeine to v3.2.4, GeoIP2 to v5.1.0 and libphonenumber to v9.0.34 SCR-1768: Upgraded ez-vcard to v0.12.2 SCR-1769: Upgraded lib-recur to v0.17.1 SCR-1770: Upgraded Apache XML-RPC to v6.1.0 SCR-1771: Upgraded Dropbox Core SDK to v8.0.1 SCR-1772: Upgraded Box Java SDK to v4.16.4 SCR-1773: Upgraded OWASP ESAPI to v2.7.0.0 SCR-1774: Upgraded Hazelcast to v5.7.0 SCR-1775: Upgraded jOOX to v2.0.1 SCR-1778: Mandatory 'objectid' mapping for LDAP contacts providers SCR-1780: Upgraded Apache CXF to v4.2.2 and Metro JAX-WS runtime to v4.0.5 SCR-1783: Removed the stateful Dovecot Push implementation SCR-1784: Upgraded Google client stack and Firebase Admin SDK SCR-1785: Upgraded OpenSAML to v5.2.3 SCR-1786: Upgraded Apache PDFBox to v3.0.7 SCR-1788: The client-side prepared statement cache defaults are raised SCR-1792: Upgrade Cassandra driver to Apache Cassandra java-driver 4.19.3 SCR-1793: Harden Redis connection lifecycle against stale/orphaned connected clients SCR-1794: Upgrade Box SDK to generated Box Java SDK 10.15.1 (com.box.sdkgen) SCR-1795: Upgrade target platform to Jakarta EE 11 REST stack (Jersey 4.0.2 / jakarta.ws.rs 4.0 / HK2 4.0.1) SCR-1796: Upgrade io.netty to 4.2.16.Final SCR-1799: Optional Grizzly WebSocket side-car alongside the Jetty engine Stage on-demand gRPC jars via the eclipse/cleanEclipse IDE-prep tasks Transport shared-account scheduling mail via the shared mailbox Updated core-mw chart dependencies Updated Gotenberg image to v8.34.0 Updated Gotenberg chart to v1.22.0 Updated Collabora image to v26.04.2.3.1 Updated Collabora chart to v1.3.0 Aligned contacts account handling with its calendar counterpart Build gRPC provisioning jars on demand instead of committing them Provide details about stored event on out-of-sequence errors (core#463) Remove the time-based Entity2ACL look-up caches (core#546) Modernize CalDAV/CardDAV documentation and DAV routing diagrams (support#1561) CAL-5001: Run folder name checks before opening the create transaction Database folder cache lost stale-re-insert protection (unguarded region) and left in-memory replicas after group-member invalidation Flaky statisticsAreMaintained() rejected by the capacity-less SynchronousQueue under load Folder cache value codec overwrote a permission's numeric entity identifier with its entity info rendering such folders non-deserializable Groovy-interpolate registry/project/imageVersion in mirrorImage skopeo copy step Load-through re-fetch loop spun forever on a non-deserializable Redis cache entry instead of self-healing it Missing command-line tool scripts and inaccurate CLT documentation PBSR-1766: Indicate correct account prefix for folder ids in mail filter rules of non-primary accounts Re-align the Jetty Bundle-ClassPath with the 12.1.11 embedded JARs Register the globaldb utf8mb4 package in the Liquibase custom-change manifest header SCR-1798: Provision per-account spam handler so "Mark as Spam" works for secondary/functional mailboxes Set Jersey context class loader when building JAX-RS client Hardened the Jetty engine's servlet registry (core#532) Detect synthetic sessions by origin, not instanceof Reject corrupt ZIP/OLE2 documents before Collabora conversion in mail export previews Rename changesharedaccount CLI tool documentation and help text to updatesharedaccount Select chart release by prefix instead of trusting GitHub releases/latest Subscribe/unsubscribe for shared mail folders via share/management Superfluous quoting of FEATURE parameter values in CONFERENCE property Prevent message alarm reminders from getting stuck until node restart Never let a single broken push client configuration abort start-up of com.openexchange.push.clients (core#552) Skip the JDBC reserved-word probe on MariaDB (core#553) Pin the gRPC protobuf export and slim down the framework jar shading (core#555) Bind a task marker for HTTP requests dispatched on threads without one (core#556) Sort shared calendar folders contributed by multiple calendar accounts (core#557) Tolerate missing parent folder during IMAP default folder check (support#1129) Keep emitting user_id 0 for non-user contacts to preserve HTTP-API compatibility (support#1438) Reuse GETACL results across folder-tree rebuilds (support#1522) Apply healthCheckIntervalMillis to its own pool property instead of overwriting responseTimeoutMillis (support#1523) Never skip sender validation when transmitting via action=new (support#1531) Limit the number of orphaned cookies removed per HTTP response to stay below the engine's response header limit (support#1540) Populate internal user id consistently in results from LDAP contacts provider (support#1542) Preserved shared/deputy mailbox visibility with consolidated LIST-EXTENDED folder listing (support#1543) Exclude guest users from context user count for MaxUser restriction (support#1548) Restored xs:date/nillable for SOAP birthday and anniversary (support#1551) Reject central-training spam handlers for external mail accounts (support#1552) Bump About-box default copyright year to 2026 (support#1553) Re-add org.glassfish.jersey.client.spi import to imageconverter.client bundle (support#1554) Refuse applying incoming scheduling messages that collide with differently organized events (support#1555) Drop RFC 2965 $-prefixed framing cookies in servlet bridge (support#1560) Store DB-assignment and schema-update-state cache entries as plain per-context/per-schema keys instead of one global group hash (support#1562) Reference iMIP mail parts via "cid" URLs in analyzed event attachments (support#1564) Replace CREATE TABLE ... AS SELECT with plain DDL + INSERT ... SELECT (support#1567) Throw FOLDER_NOT_FOUND instead of NPE for missing calendar folder (support#1577) Guard composite LDAP filter construction against non-representable search term operands (support#1578) Single-pass, escaping URI token compression to keep proxy registrations round-trip safe (support#1582) Propagate affected folders in folder map invalidation messages so remote nodes drop them for every user (support#1584) Report exact attachment sizes for composition space drafts (support#1585) Run core-mw update job on dedicated ServiceAccount without API token automount (support#1592) Always provide the mail's display date, also for nested messages (support#1598) Prev
App Suite UI
Next
Additional Components