This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+9 more
Affected surfaces
Summary
AI summaryRemoval of forbidden username and userIdentifier SAML attribute fields.
Full changelog
Compatible with PHP 8.2 to 8.5
Features
- Add working contract preferences to user when setting for the first time from API (#5894)
- SAML: allow to configure the attribute name for the user identifier (#5996)
- Translations update from Hosted Weblate (#5987)
Attention The username and userIdentifier fields must be removed from your SAML attribute mapping. This was never used and is now forbidden.
Bugfixes
- Fix broken redirect for expired login links (#5990)
- Added fallback redirects for /login and /logout (#5990)
Maintenance
- Allow dynamic templates for custom SystemConfiguration types (#5990)
- Update composer and npm packages (#5990) (#6006)
- Added new form model tests (#6000)
Involved in this release: @kevinpapst and @viggou
Breaking Changes
- Removal of `username` and `userIdentifier` fields from SAML attribute mapping (now forbidden).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kimai
Kimai is the #1 open-source time-tracking application. From freelancers to companies and organisations - everyone can manage timesheets, generate reports, create invoices and so much more... Web-based multi-user application, available as On-Premise or SaaS version: https://www.kimai.org
Beta — feedback welcome: [email protected]