What’s new

4.7.4.7

2023-08-16

  • Corrections have been made in the e-mails changing block;

  • Recaptcha V2 module has been updated;

  • Inclusion of media in the CSP.

4.7.4.4

2023-08-09

  • Authorization policies for files;

  • Corrections were made in the module Redirect User on Login.

4.7.4.3

2023-07-19

  • The names of the administrative menus were revised.

4.7.4.0

2023-06-30

  • Drupal’s Core has been updated to 7.98;

  • Improvements in the Terms of Use and Privacy module;

  • Improvements in the SAML module;

  • Performance improvements with fewer calls on the Platform;

  • Improvements in the Redoc module;

  • Sending of emails in HTML format;

  • Fixed a bug that caused extrainfo to be excluded when editing an APP;

  • Fixed a bug in the Swagger module, which replaced APIs with similar names.

4.7.3.25

2023-06-09

  • Improvements in the Terms of Use and Privacy module;

  • Correction in the registration of the user;

  • Removed permission for anonymous user on MyApps.

4.7.3.24

2023-05-30

  • The names of the administrative menus were revised.

4.7.3.22

2023-05-17

  • Swagger download was improved.

4.7.3.20

2023-05-15

  • Corrections were made in:

    • Register Flow module;

    • DevDashboard modal;

    • the sending of images during the registration/editing of APP;

    • Redoc;

  • Drupal 7.97 Core Security was updated.

4.7.3.15

2023-04-12

  • Plans would not return when APP Fields were blocked while editing APPs.

4.7.3.14

2023-04-06

  • Fixes were made in the API Status.

4.7.3.12

2023-03-31

  • Fixed invalid icon in MyApps V2.

4.7.3.9

2023-03-27

  • Drupal 7.95 Core Security updated;

  • Changes to Swagger3 to be compatible with the new Redoc add-on.

4.7.3.7

2023-03-21

  • Fixes were made in MyApps V2.

4.7.3.6

2023-03-13

  • Vulnerabilities were fixed.

4.7.3.5

2023-02-27

  • Correction in the loading of APIs in new APP registration;

  • Password reset for blocked registration;

  • Module to remove other modules;

  • Content change revision flag is enabled by default;

  • Change in MyApps/New/Edit Extra Fields after created;

  • Fixed API Search.

4.7.3.2

2023-02-20

  • Fixed password reset.

4.7.3.1

2023-01-27

  • Correction in the visualization of APPs for Manager;

  • Improvements in the Terms of Use module;

  • Improvements in the listing of Swaggers.

4.7.3.0

2023-01-23

  • E-mail sending after changing the password;

  • Administrator can no longer change the user’s password;

  • Fixed the modal window for APP deletion;

  • Client Secret hidden, but with visualization by modal;

  • Setting maximum amount for creation of APPs;

  • Activate/Deactivate optional fields in the APPs view;

  • Inclusion of Loading in the submission of all forms in the Dev Portal;

  • Improvements in loading APPs;

  • Inclusion of button to delete Swagger inside the Swagger3 module;

  • Drupal 7.94 Core Update;

  • Fields were disabled in the editing of APPs;

  • Functional module to put a rate limit on the creation of APPs.

4.7.2.15

2023-01-23

  • Update on the CSP.

4.7.2.14

2022-12-26

  • Module for creating forms;

  • Module for MyApps with restrictions.

4.7.2.7

2022-10-30

  • Creation of a module to purge inactive developers on the Dev Portal;

  • Visual improvements in the API Browser;

  • Stored Cross-Site Scripting (XSS);

  • Improvements to prevent automated User Registration;

  • Download Swagger button was included in the API technical documentation.

4.7.2.5

2022-10-26

  • Public access to .json files with API restrictions;

  • Performance improvements in registering APPs;

  • APIs organized in alphabetical order in the register of APPs;

  • More options to manage the plans in the registration of APPs;

  • Improvements in CSP (Content-Security-Policies);

  • Drupal core updated to version 7.92.

4.7.2.4

2022-10-11

  • Automatically add extrainfo in the APPs with the Registration data.

4.7.2.3

2022-10-06

  • New directives in httpdconf;

  • Registration of DEVs is no longer linked to the API Platform.

4.7.2.2

2022-09-14

  • Inclusion of customized endpoint for registration of APPs.

4.7.2.1

2022-08-02

  • Fixed an issue related to the listing of users by IDOR.

4.7.2.0

2022-07-31

  • Security update of Drupal core to 7.91;

  • Inclusion of download button for Swagger for APIs sent by API Platform;

  • When uploading a new Swagger through the Dev Portal, the old one is no longer deleted;

  • Audit shows who uploaded Swagger;

  • Improvements for loading APIs listing in API Browser and MyApps;

  • Report generation of modules installed/activated in Dev Portal using administrator login;

  • Inclusion of the Back button in the Access Token view;

  • Google Analytics Module updated;

  • Permission for Administrator to view the Custom Signup module;

  • CSP (Content Security Policy) updated;

4.7.1.10

2022-07-26

  • CSP updated.

4.7.1.6

2022-05-31

  • Fixed: user was not being notified of account created by an administrator;

  • Fixed: reset was not working due to page redirection after login;

  • Fixed: Terms of Use was returning error upon refusal;

  • Correction in Swagger’s permission settings ;

  • Correction in the new module API Segregation V2;

  • Swagger-Ui version Update;

  • Correction in API Segregation;

  • APPs editing fix was implemented for Manager 19.x and 18.x.

4.7.1.4

2022-05-25

  • Correction in user registration for API Platform 4.8.0.1 and for 18.x and 19x.

4.7.1.3

2022-05-23

  • Recaptcha corrected in module Login/Registration/Password-reset.

4.7.1.2

2022-05-18

  • New module to load APIs listing via CSV and via Database;

  • Improvements in Permission List, adding the “.site” as a restriction of new registrations;

  • Improvements to view only APPs from only one Environment per extrafield;

4.7.1.1

2022-05-04

  • Release of Hotjar and Google Tag Manager to CSP.

4.7.1.0

2022-04-27

  • Fixed the Core of the Rules module;

  • New cache control security guidelines on the header;

  • Option to block email editing;

  • New SameSite and HttpOnly attributes guidelines in the cookie has_js.

4.7.0.19

2022-03-28

  • Fixed the apps for monetizable APIs.

4.7.0.17

2022-03-25

  • Included the shownOnAPIBrowser param in the API Browser.

4.7.0.16

2022-03-25

  • Fixed the Portal database.

4.7.0.15

2022-03-23

  • Created apps for monetizable APIs.

4.7.0.14

2022-03-14

  • Drupal Core 7.89 update;

  • Update of the user table in the field changed, which was null and showing 52 years;

  • Enables the adm permission to edit pages in full html;

  • Fixed the table name.

4.7.0.13

2022-03-02

  • Drupal Core 7.88 update with the latest security release;

  • Module Register Flow enables registration without email validation;

  • Integration Status URL allows you to monitor if the integration between the Portal and Manager is working properly;

  • Fixes error when editing apps for the old Manager;

  • Fixes issue when filtering apps through the APIs Manager;

  • Correction of security flaws (Injection and XSS);

  • New audit module within the Dev Portal.

4.7.0.12

2022-02-16

  • Drupal Core 7.87 updated with the latest security release;

  • Option to return all of the resources from the APIs in the API Status;

  • Content-Security-Policies updates;

  • Removed the class .fas (compatibility with some visual identity);

  • Fixed a Bounty error in the API Browser;

  • Increases the file upload size in the Dev Portal to 5MB;

  • Password module to force the Dev Portal user to use a stronger password;

  • Fixed a bug in the User-Registration-Password module, which did not correctly send the reset of the password.

4.7.0.11

2022-01-18

  • All modules developed by Sensedia have been released for Admin type profiles;

  • Synchronization of documents from Github to the Dev Portal;

  • Fixed a bug which the "&" character was not allowed to be used when creating Apps;

  • Cache fix in the API Browser.

4.7.0.10

2022-01-94

  • Updated the JS to accept the OpenAPI 3.0 in the API Browser;

  • Fixed JS that caused an error in the dropdown menu within MyApps;

  • Fixed recaptcha within MyApps/new. It was not possible to disable recaptcha;

  • New CSP guidelines that blocked external resources;

  • Fixed conflicts in URLs caused by a redirection condition.

4.7.0.9

2021-12-24

  • Included Redocs in the CSP security header since it was blocking the use of Redocs;

  • Fixed a bug in the developer registration that was not validating the email already registered.

4.7.0.8

2021-12-16

  • Fixed the Auto-Logout system;

  • Fixed the bug when accessing the administrative tab within the MyApps module;

  • Upgrade from PHP 7.2 to 7.4,

  • Included the new Register Flow module that releases the registration only for one domain while the others are blocked and wait for the administrator to activate the registration;

  • Fixed the Tryout in the API Browser that was being blocked by the CSP header;

  • Change root’s e-mail address.

4.7.0.7

2021-12-06

  • Set Permissions-Policy and Content-Security-Policy;

  • Make the TFA module mandatory;

  • Fixed the IP security lock.

Improvements in the MyApps module:

  • Improvements in API segregation.

4.7.0.6

2021-10-06

  • API search in the API registration process was fixed;

  • reCaptcha removed from APPs registration, but with automated registration restriction (rate limit).

4.7.0.5

2021-09-27

  • Tokens visualization for older versions of Manager, as there was a change in the endpoint for returning tokens in more recent versions of Manager;

  • Multilingual reCaptcha for APP registration.

4.7.0.4

2021-09-11

  • The administrator role will be able to view all Sensedia modules;

  • Module to download data from registered developers, with fields already filled, eliminating the need to request support to extract the database;

  • New version of API Status. It now shows all API operations for which the developer has a registered APP;

  • Error message on the Deny List was corrected.

Security improvements:

  • XMLs visualization was blocked.

Detailing of APPs (MyApps):

  • Number of APPs per page;

  • Enable/Disable detailing of Access Tokens;

  • Client ID and Client Secret encode, with Base64;

  • Enable/Disable Client Secret;

  • Enable/Disable button for APP registration;

  • Enable/Disable APP Editing;

  • Add the Extrafield view of an APP.

Registering New APPs (MyApps/New):

  • API is mandatory for registering new APP;

  • When an API is set as non-mandatory, it is possible to disable the visualization of the API.

API segregation:

  • Possibility to separate APIs as Internal and External;

  • Possibility of setting email domains to view the Internal APIs;

  • In this case, the options "Allow Apps Link" and "Show iterative documentation (Swagger)" of the API inside the API Platform are disabled;

mail_edit table was fixed and data was inserted in the table;

Module for exporting data was fixed;

Modal for Terms of Use:

  • Possibility to set, in HTML, the Terms of Use within the module;

  • For all changes made in the Terms of Use using HTML, a record will be kept informing who made the changes, when it was done and what was changed;

  • Possibility to download the data of the acceptance of the developers;

  • Possibility to reset the table of data of acceptance, but only for root users.

4.7.0.3

2021-07-30

  • Removal of the memory setting in settings.php, because the configuration is part of the infrastructure.

4.7.0.1

2021-07-29

  • Adjustment in the log so that the response of API calls in the "watchdogs" table is not registered, which used to cause high session rate in the DB.

4.7.0.0

2021-07-27

  • Drupal CMS Core updated to 7.82

4.6.0.9

2021-07-26

  • Multilingual email sending;

  • Registration restriction for certain configurable domains (DenyList);

  • Restriction of environments for the visualization of the Dev Dashboard;

  • Copy and Download buttons on request/response in API Browse (Swagger);

  • Correction on role validation on API Browser/Swagger visualization.

4.6.0.8

2021-07-01

Security enhancements:

  • Restriction of the config file visualization;

  • Configuration of Cookie Secure and samesite=Lax;

  • Remotion of the meta tag from Drupal generator;

  • Inclusion of reCaptcha when creating APPs.

Private APIs will not be shown in Swagger;

Integrating menu-per-role module into master.

4.6.0.6

2021-05-27

  • Set number of APPs per Page;

  • Enable/Disable Client Secret;

4.6.0.4

2021-05-17

  • API as mandatory when registering an APP.

4.6.0.2

2021-05-10

  • Adjustments were made in Sensedia modules;

  • Inclusion of a module that closes a session by time.

4.6.0.1

Security enhancements:

  • Restriction on txt file visualization;

  • Session cookie is now set to be closed in 30 min. Previously it was set for 23 days.

4.6.0.0

  • Drupal CMS Core updated to 7.80.

4.5.0.2

  • When deleting a user in Dev Portal, the Developer status in API Platform will be changed to BLOCKED. The developer will not be deleted from Manager;

  • For Manager versions 4.3.3.0 and above, PATCH will be performed instead of PUT;

4.5.0.0

2021-03-22

  • Adjustments were made in the default modules (Admin Menu, Password Policy, Rules and Token).

Thanks for your feedback!
EDIT

Share your suggestions with us!
Click here and then [+ Submit idea]