Repository navigation
Compare: 3.8.4...3.9.0
Elsa Studio 3.9.0 — Release Notes
Minor release, shipped as an aligned 3.9.0 train with Elsa 3.9.0 and Elsa Extensions 3.9.0.
Studio 3.9 requires core 3.9. The new access model depends on the 3.9 server endpoints and permissions.
🌟 Highlights
- Studio shows what you can use. Menus, pages and in-page actions are gated by the user's permissions. Anything a user can't use is hidden or shows one consistent access-denied page, instead of a raw 403. (#1075, #1076, #1092, #1094)
- A dashboard for every user. The dashboard is open to all signed-in users, and each widget is gated by the permission of the data it shows. (#1103)
- Proper sign-out. The app bar has a sign-out for OIDC. Elsa Identity sign-out revokes the session on the server, so a copied refresh token stops working. (#1081, #1100)
- 3.9 branding. The app bar, About dialog and WASM host read "Elsa Studio 3.9". (#1063, via #1071)
- Simpler Roles screens. The Roles list and editor drop the explanatory text and zero counters. The list shows a plain role count and no ID column, the editor title is the role name, wildcards get a single "Wildcard" label, and Select all switches to Deselect once everything visible is selected. (#1115, via #1116)
🔐 Security
- Open redirect fixed on OIDC Blazor Server login.
returnUrlnow accepts only a local rooted path, so values like/%09/evil.comredirect to/. The External Authentication callback and logout endpoints apply the same rule. (#1106, via #1105) - Select all in the Roles editor no longer grants hidden permissions. With a permission filter active, Select all used to grant every permission in the category, including ones the filter hid. It now selects only the permissions on screen, and Deselect clears only those. (#1114, via #1116)
🐛 Fixes
- The Blazor Server host no longer crashes at startup with ElsaIdentity and the Environments module. Environments load once a circuit exists, not during host start. (#1062, via #1064)
- Identity provider connections and external identity links work again. Studio-local API contracts were renamed to stop clashing with
Elsa.Api.Client. (#1075) - Users who can't view the landing page are sent to their first accessible page. (#1093)
- The Users pages no longer show a tenant scope label. (#1077)
- Pressing Enter submits the sign-in form. (#1090)
- The dashboard shows a loading state. The user, language and environment menus open below their buttons. (#1091, #1097)
⚠️ Upgrade notes and breaking changes for hosts
📖 Upgrade guide: Upgrading to Elsa 3.9
- Studio 3.9 requires core 3.9. Upgrade elsa-core, elsa-studio and elsa-extensions to 3.9.0 together.
- OIDC Blazor Server:
GET /authentication/logoutis now POST with antiforgery. Custom sign-out links have to use the user menu, or POST with an antiforgery token. (#1081) - OIDC Blazor Server: a custom
_Host.cshtmlneeds<persist-component-state />before_framework/blazor.server.js. Without it, Sign out on a long-polling circuit has no antiforgery token and is rejected with a 400. (#1081) - Two External Authentication interfaces were renamed to
IExternalAuthenticationConnectionManagementApiandIExternalIdentityLinkManagementApi, and the old permission constants were removed. (#1075) - Constructors changed.
DefaultMenuServicehas a new optionalIPermissionServiceparameter, andElsaIdentityRefreshTokenServicenow takes anElsaIdentitySessionGate(#1075).ElsaIdentitySignOutService, new in 3.9, gained more dependencies during the previews (#1100). Resolve these from DI. If you create or subclass them yourself, pass the new arguments. ForDefaultMenuServicea rebuild is enough. - The Elsa Identity and OpenID Connect sign-in modules now add a user menu with Sign out to the app bar (#1075, #1081). If your host adds its own user menu, you'll see two. Remove yours.
- Permission gating fails open for third-party OIDC tokens. If a token has no
permissionsclaim, Studio behaves as before. Elsa-issued tokens always carry the claim; a user with no grants gets"none". (#1075; core#8566)
🚧 Known limitations
- The UI updates only after a page reload when a user's permissions change or the user is disabled.
- Other tabs and Blazor Server circuits stay signed in after sign-out until their next call, because revocation is checked on the server.
- Permission changes apply when the access token is refreshed. Access tokens stay valid until they expire after sign-out (up to 15 minutes). See the core 3.9.0 notes for the full list.
🙏 Credits
- Everyone who reported issues and tested the 3.9 previews.