Releases: wultra/powerauth-server
Releases · wultra/powerauth-server
Release list
Release 2.2.1
This release contains the following fixes:
- Restored numeric (epoch-millisecond) serialization of operation callback timestamps, which regressed to ISO-8601 strings after the Jackson 3 upgrade and broke callback consumers that parse the timestamps as numbers (#2436)
Release 2.2.0
This release contains the following improvements:
- Temporary block of activation (#2390)
- Secure configuration store with per-application and per-activation scopes (#2391)
- AAGUID for Wultra Authenticator 1.2 (#2426)
- Migrated to Spring Boot 4 and Jackson 3 (#2379)
- Upgraded Docker base image to OpenJDK 25 (
ibm-semeru-runtimes:open-jdk-25.0.3.0-jre-noble) (#2396)
Release 2.1.0
This release contains the following improvements:
- Uniqueness of activation codes at the database level is enforced.
- Deprecated signature/authentication code types removed.
- Set the subject ID to the audit log records.
- Fixed the performance of the create operation for large inputs.
- Dependency updates.
Release 2.0.2
This release contains the following improvements:
- Fixed bad performance of create operation in case of large request payloads (#2312)
Release 1.10.3
This release contains the following improvements:
- Fixed bad performance of create operation in case of large request payloads (#2312)
Release 2.0.1
Due to a GHSA-pj23-86ww-f72p and GHSA-pj23-86ww-f72p
updated base image to open-21.0.9_10-jre-noble
Release 1.10.2
Due to a GHSA-pj23-86ww-f72p and GHSA-m494-w24q-6f7w
updated base image to tomcat:10.1.50-jre21-temurin-noble@sha256:be6ccee5e899a399f2c6dbf05090b0adbefd14275ffa7aa187533ce22e5564ce
Release 2.0.0
This release contains the following improvements:
- A major release of the PowerAuth protocol version 4.
- Provides high security resistant to known quantum attacks, see list of used algorithms.
- Activation via recovery codes is not possible anymore.
- The algorithm
AEAD_KMACis now the default database encryption algorithm. - Package names in Java code have been updated from historical
io.getlimetocom.wultra. - Dependency updates.
Release 1.10.1
This release contains the following improvements and bugfixes:
- Changed default timeouts for replay attack verifications service.
Release 1.10.0
This release contains the following improvements and bugfixes:
- The validation of requests is now stricter and more complete to ensure data integrity. For details, see Migration Instructions.
- It is possible to specify optional additional data during activation creation or initialization.
- Operation approval rejects operations without
userId. Such operations should be claimed before that. - Dependency updates