ReadonlyREST Changelog Feed https://api.beshu.tech/changelog Subscribe to this feed to get updates from ReadonlyREST about new releases. http://www.rssboard.org/rss-specification python-feedgen https://i.imgur.com/ZjN4Eq9.png ReadonlyREST Changelog Feed https://api.beshu.tech/changelog en Thu, 25 Apr 2024 01:39:33 +0000 1.56.0 Released https://api.beshu.tech/changelog <h2>1.56.0</h2><ul> <li>🚀New (KBN) Provide a way to switch light/dark mode per user</li> <li>🚀New (KBN) 8.13.2, 8.13.1, 8.13.0, 7.17.20, 7.17.19 support</li> <li>🚀New (ES) 8.13.2, 8.13.1, 8.13.0, 7.17.20, 7.17.19 support</li> <li>⚠️Warning (ES) for ES > 6.5 patching is required since this version of ROR</li> <li>🧐Enhancement (KBN) The activation key will be revalidated in the interval </li> <li>🧐Enhancement (KBN) Provide a way to define Activation key retrieval mode</li> <li>🐞Fix (KBN) Sometimes reports are not generated correctly for Kibana >= 8.0.0 and "Max attempt reached" error appears </li> <li>🐞Fix (KBN) The OIDC scope configuration property was not applied and the default configuration was used instead.</li> <li>🐞Fix (KBN) The OIDC proxy parameter was not handled properly in case of HTTPs connection over HTTP proxy server</li> <li>🐞Fix (KBN) Missing information when Kibana is not patched</li> <li>🐞Fix (ES) Repositories and Snapshots handling by ES coordinating nodes</li> <li>🐞Fix (ES) Internode SSL certificate_verification: true was causing problems with nodes discovery</li> <li>🐞Fix (ES) Missing x-elastic-product header in the response when fields and filter rules were used</li> <li>🐞Fix (ES) Proper forbid policy handling during processing ROR login request</li> <li>🐞Fix (ES) application/nd-json media type handling (in case of ES 7.x versions)</li> </ul> 1.56.0 Sun, 21 Jul 2024 01:39:33 +0000 1.55.0 Released https://api.beshu.tech/changelog <h2>1.55.0</h2><ul> <li>🚨Security Fix (ES) CVE-2023-51074</li> <li>🚀New (KBN) 8.12.2 ,8.12.1, 7.17.18, 7.17.17 support</li> <li>🚀New (ES) 8.12.2, 8.12.1, 7.17.18 support</li> <li>🚀New (ES) Elasticsearch images with preinstalled ReadonlyREST plugin in Docker Hub</li> <li>🧐Enhancement (KBN) Optional readonlyrest_kbn.auth.oidc_kc.proxyURL kibana.yml configuration for the OIDC connection which allows declaring your proxy URL</li> <li>🧐Enhancement (KBN) Upon successful activation and edition changes all sessions are cleared and users are logged out</li> <li>🐞Fix (KBN) Saved objects are not visible for the users on Kibana >= 8.8.0</li> <li>🐞Fix (ES) LDAP nested group names are properly escaped</li> <li>🐞Fix (ES) Logout when a user with restricted kibana.access tried to see a restoration status of snapshots in Kibana</li> </ul> 1.55.0 Sat, 20 Jul 2024 01:39:33 +0000 1.54.0 Released https://api.beshu.tech/changelog <h2>1.54.0</h2><ul> <li>🚨Security Fix (ES) Scroll API: protected data could leak when the fields rule was used with fls_engine set to es or es_with_lucene</li> <li>🚀New (KBN) 8.12.0, 8.11.4 support</li> <li>🚀New (ES) 8.12.0, 8.11.4, 7.17.17 support</li> <li>🧐Enhancement (KBN) Provide automatic cleaning of stale sessions</li> <li>🧐Enhancement (KBN) Provide automatic cleaning of stale CSRF cookies</li> <li>🐞Fix (KBN) Adjust the ROR API POST license endpoint body to the contract to respect the license body parameter instead of a token</li> <li>🐞Fix (KBN) `CorelationId`` is changed on every session refresh</li> <li>🐞Fix (ES) "missing authorization info" problem in some situations when xpack.security.enabled was configured to be true</li> </ul> 1.54.0 Fri, 19 Jul 2024 01:39:33 +0000 1.53.0 Released https://api.beshu.tech/changelog <h2>1.53.0</h2><ul> <li>🚨Security Fix (ES) CVE-2023-4586, CVE-2023-5072</li> <li>🚀New (KBN) 8.11.3, 8.11.2, 8.11.1, 8.11.0, 7.17.16 support</li> <li>🚀New (ES) 8.11.3, 8.11.2, 8.11.1, 8.11.0, 7.17.16 support</li> <li>🧐Enhancement (KBN) Provide Activate license endpoint to the ReadonlyREST API</li> <li>🧐Enhancement (ES) when the kibana rule and the indices rule are defined in the same block, there is no need to explicitly allow kibana-related indices</li> <li>🐞Fix (KBN) problem with reports generation when kibana.index in kibana.yml is used</li> <li>🐞Fix (KBN) crash loop during license service initialization</li> <li>🐞Fix (KBN) problem with logging in in KBN 7.17.13 (and above) and 8.10.4 (and above) when deployed using ECK</li> <li>🐞Fix (KBN) problem with multi-tenancy and ECK</li> <li>🐞Fix (KBN) problem with forbidden /_create/config response on Login to the Kibana</li> <li>🐞Fix (ES) patching fix, when a non-default ES path is used (e.g. on K8s)</li> </ul> 1.53.0 Thu, 18 Jul 2024 01:39:33 +0000 1.52.0 Released https://api.beshu.tech/changelog <h2>1.52.0</h2><ul> <li>🚨Security Fix (ES) CVE-2023-4586</li> <li>🚀New (KBN) 8.10.4, 8.10.3, 7.17.15, 7.17.14 support</li> <li>🚀New (ES) 8.10.4, 8.10.3, 7.17.15, 7.17.14 support</li> <li>🚀New (ES) New token_authentication rule</li> <li>🧐Enhancement (KBN) Permanently hide Kibana|ES features that are impossible to support</li> <li>🧐Enhancement (KBN) License expiration reminder</li> <li>🧐Enhancement (KBN) Make kibana.index setting from kibana.yml an invalid property for an Enterprise user</li> <li>🐞Fix (KBN) Issue with not adding elasticsearch.customHeaders setting from kibana.yml to ROR requests</li> <li>🐞Fix (KBN) Logout after opening Stack management Upgrading assistant</li> <li>🐞Fix (KBN) Problem with logging in of two users in two tabs when two Kibana instances are used</li> <li>🐞Fix (KBN) Problem with logging in when multi-tenancy is enabled and the indices rule is defined in the ROR settings</li> </ul> 1.52.0 Wed, 17 Jul 2024 01:39:33 +0000 1.51.1 Released https://api.beshu.tech/changelog <h2>1.51.1</h2><ul> <li>🚨Security Fix (ES) fields rule didn't work well in the case of ES 7.10.0 and later and more than 10 documents in the response</li> <li>🐞Fix (KBN) issue with Observability Overview-based applications hiding</li> <li>🐞Fix (KBN) Correct kibana.index handling for KBN >= 7.9.0 when multi-tenancy is disabled or unavailable</li> <li>🐞Fix (KBN) Unrestricted Kibana Access on the tenancy switch when a selected tenant is not available anymore</li> <li>🐞Fix (KBN) Unhandled error during login when multiTenancyEnabled: false</li> <li>🐞Fix (ES) LDAP connectivity improvements</li> </ul> 1.51.1 Tue, 16 Jul 2024 01:39:33 +0000 1.51.0 Released https://api.beshu.tech/changelog <h2>1.51.0</h2><ul> <li>🚨Security Fix (KBN) the issue with api_only access level user and accessing via Kibana UI</li> <li>🚀New (KBN) 8.10.2, 8.10.1, 8.9.2, 7.17.13 support</li> <li>🚀New (ES) 8.10.2, 8.10.1, 8.10.0, 8.9.2, 7.17.13 support</li> <li>🚀New (ES) Dynamic variables transformation support</li> <li>🧐Enhancement (KBN) Expose interactive Swagger as a new Security settings tab</li> <li>🧐Enhancement (KBN) Provide detailed information about the invalid activation key</li> <li>🧐Enhancement (ES) additional hide_apps validation in the kibana rule</li> <li>🐞Fix (KBN) the issue with the persistence of an activation key provided via UI when readonlyrest_kbn.cookiePass was not provided. The readonlyrest_kbn.cookiePass is required kibana.yml property</li> <li>🐞Fix (KBN) issues for Kibana versions between 7.9.0 and 7.10.2, related to the activation key, Spaces, and readonlyREST menu crash</li> <li>🐞Fix (KBN) The issue with a logout from Kibana when the link to the Kibana is open from a third-party application like Gmail</li> <li>🐞Fix (ES) getting data streams when not full names of backing indices are declared in the indices rule</li> <li>🐞Fix (ES) stack-management screen fix in case of xpack.security.enabled: true</li> </ul> 1.51.0 Mon, 15 Jul 2024 01:39:33 +0000 1.50.0 Released https://api.beshu.tech/changelog <h2>1.50.0</h2><ul> <li>🚀New (KBN/ES) ECK support</li> <li>🚀New (KBN) 8.9.1, 8.9.0, 7.17.12 support</li> <li>🚀New (ES) 8.9.1, 8.9.0, 7.17.12 support</li> <li>🚀New (KBN) Introduce the new ReadonlyREST API</li> <li>🧐Enhancement (KBN) Remove application item info from URL on the tenant switch to avoid a 404 not found message</li> <li>🧐Enhancement (KBN) Provide Reordering available tenancies for proxy auth authentication</li> <li>🧐Enhancement (KBN) Provide information about granted/rejected log-in users to debug logs</li> </ul> 1.50.0 Sun, 14 Jul 2024 01:39:33 +0000 1.49.1 Released https://api.beshu.tech/changelog <h2>1.49.1</h2><ul> <li>🚨Security Fix (ES) CVE-2023-2976</li> <li>🚨Security Fix (ES) CVE-2023-34462</li> <li>🚀New (KBN) 8.8.2, 8.8.1, 8.8.0, 7.17.11 support</li> <li>🚀New (ES) 8.8.2, 7.17.11 support</li> <li>🚀New (ES) LDAP nested groups support</li> <li>🧐Enhancement (KBN) Allow setting default tenancy via /login?defaultGroup query param. To be used with “Custom Middleware” feature for reordering available tenancies in the ROR menu </li> <li>🐞Fix (ES) Fix for ES warnings in logs about custom action names (ROR internal actions)</li> <li>🐞Fix (ES) kibana access rw and admin should allow to manage component templates</li> </ul> 1.49.1 Sat, 13 Jul 2024 01:39:33 +0000 1.49.0 Released https://api.beshu.tech/changelog <h2>1.49.0</h2><ul> <li>🚀New (ES) 8.8.1 support</li> <li>🧐Enhancement (KBN) Handle elasticsearch.serviceAccountSupport configuration property</li> <li>🧐Enhancement (KBN) Provide a way to Hidden apps Stack management items hiding</li> <li>🧐Enhancement (KBN) Provide an automated migration of tenancy indices on major Kibana version upgrade</li> <li>🧐Enhancement (ES) external group name patterns support in the external to local groups mapping</li> <li>🐞Fix (KBN) the issue with the replica number being set to 0 on tenant index creation</li> <li>🐞Fix (KBN) users won’t log out from Kibana on the 500 status error</li> <li>🐞Fix (KBN) the issue with Kibana keystore not being read by the Kibana plugin</li> <li>🐞Fix (KBN < 7.9.0) logging issue when two Kibanas are handled by one browser at the same time</li> <li>🐞Fix (ES) resolving ENVs to YAML number in ROR settings</li> </ul> 1.49.0 Fri, 12 Jul 2024 01:39:33 +0000 1.48.0 Released https://api.beshu.tech/changelog <h2>1.48.0</h2><ul> <li>🚨Security Fix (ES) CVE-2022-45688</li> <li>🚀New (KBN) 8.7.1, 7.17.10 support</li> <li>🚀New (ES) 8.8.0, 8.7.1, 7.17.10 support</li> <li>🚀New (KBN/ES) Introducing "Custom Middleware" functionality</li> <li>🚀New (KBN/ES) allowed_api_paths support in the kibana ACL rule</li> <li>🚀New (KBN) Add CSRF protection in the login form</li> <li>🚀New (KBN) Restore deprecated “kibana.index” support for Kibana > 8.x</li> <li>🚀New (ES) all Kibana-related rules are gathered in one, new kibana ACL rule</li> <li>🚀New (ES) audit supports a new output type: log</li> <li>🧐Enhancement (KBN) Provide a way to disable multi-tenancy in ROR Enterprise</li> <li>🧐Enhancement (KBN) Realign index templates behaviour to the old platform</li> <li>🧐Enhancement (KBN) Error logs when SAML obtains an unusable username from the assertion</li> <li>🧐Enhancement (KBN) Test configuration warnings improvement</li> <li>🧐Enhancement (ES) Added support to override default response code for not started ROR</li> <li>🐞Fix (KBN) Security card not hidden by default</li> <li>🐞Fix (KBN) Hidden apps regex with two “or” operators don’t hide all kibana apps</li> <li>🐞Fix (KBN) Fix Alerting Rules resulting in logout issue</li> <li>🐞Fix (KBN) Fix audit dashboard</li> <li>🐞Fix (KBN) Stop handling 500 error from api/lens/existing_fields</li> <li>🐞Fix (KBN) Fix lens app</li> <li>🐞Fix (KBN < 7.9.x) using a custom kibana index in cooperation with ROR Free</li> </ul> 1.48.0 Thu, 11 Jul 2024 01:39:33 +0000 1.47.0 Released https://api.beshu.tech/changelog <h2>1.47.0</h2><ul> <li>🚨Security Fix (ES) "/" endpoint was not protected for ES 8.x</li> <li>🚨Security Fix (ES) "/_cat" endpoint was not protected for all ES versions</li> <li>🚀New (KBN) 8.7.0, 8.6.2 support</li> <li>🚀New (ES) 8.7.0, 8.6.2 support</li> <li>🚀New (ES) the data_streams rule</li> <li>🧐Enhancement (KBN) optimisation in hidden apps feature</li> <li>🐞Fix (KBN) Opening index management mappings tab forces logout</li> <li>🐞Fix (KBN) Fix dark mode in the ROR menu</li> <li>🐞Fix (KBN) YAML editor updates and fixes</li> <li>🐞Fix (ES) Data streams support in the indices rule</li> <li>🐞Fix (ES) NPE when _search with aggregations (script) and the fields rule were used together</li> </ul> 1.47.0 Wed, 10 Jul 2024 01:39:33 +0000 1.46.0 Released https://api.beshu.tech/changelog <h2>1.46.0</h2><ul> <li>🚨Security Fix (ES) CVE-2022-1471, CVE-2022-41915, CVE-2022-36944 in audit Scala 2.13 jar</li> <li>🚀New (KBN) 8.6.1, 8.6.0, 7.17.9 support</li> <li>🚀New (ES) 8.6.1, 8.6.0, 7.17.9 support</li> <li>🧐Enhancement (KBN) Activation key management UI</li> <li>🧐Enhancement (KBN) Less verbose logging in info mode</li> <li>🧐Enhancement (KBN) “Stack management” kibana compatibility</li> <li>🐞Fix (KBN) Test settings pop up won’t show</li> <li>🐞Fix (KBN) hide apps behaviour when “Management” is hidden</li> <li>🐞Fix (KBN) Data view with a “:” symbol forces logout from a kibana</li> <li>🐞Fix (KBN) Session probe causes constant refresh when no kibana_access defined</li> <li>🐞Fix (ES) large report generation using data from a remote cluster with enabled x-pack security</li> </ul> 1.46.0 Tue, 09 Jul 2024 01:39:33 +0000 1.45.1 Released https://api.beshu.tech/changelog <h2>1.45.1</h2><ul> <li>🚀New (KBN) 8.5.3, 7.17.8 support</li> <li>🚀New (ES) 8.5.3, 7.17.8 support</li> <li>🐞Fix (KBN) ROR KBN patching script </li> </ul> 1.45.1 Mon, 08 Jul 2024 01:39:33 +0000 1.45.0 Released https://api.beshu.tech/changelog <h2>1.45.0</h2><ul> <li>🚨Security Fix (ES) CVE-2022-42003, CVE-2022-45146</li> <li>🚀New (KBN) Activation Key API: read AK from ROR_ACTIVATION_KEY.txt</li> <li>🚀New (KBN) Activation Key API: submit AK via POST /pkp/license (Basic auth)</li> <li>🚀New (KBN) Inject CSS/JS files in login page</li> <li>🚀New (KBN) Add user metadata to for extra UI customization</li> <li>🚀New (ES) Added groups_and mode to groups_provider_authorization rule</li> <li>🧐Enhancement (ES) all authorization rules support wildcards in group names </li> <li>🧐Enhancement (ES) connections in the LDAP pool should not be closed unnecessarily </li> <li>🧐Enhancement (KBN) Deterministic reporting index detection</li> <li>🧐Enhancement (KBN) Move free type impersonation to the local users area</li> <li>🧐Enhancement (KBN) don’t logout when initial JWT token expires</li> <li>🐞Fix (KBN) Direct Kibana API requests not aware of kibana_index</li> <li>🐞Fix (KBN) RO and RO_strict kibana accesses</li> <li>🐞Fix (ES) when fls_engine: es is configured and fields rule is used, aggregations should be available only for allowed fields</li> <li>🐞Fix (ES) Data streams creation issue fix</li> <li>🐞Fix (ES) Unknown structure of index settings issue fix</li> <li>🐞Fix (ES) resolving index names with wildcards should take into consideration the current index state and request indices options</li> </ul> 1.45.0 Sun, 07 Jul 2024 01:39:33 +0000 1.44.0 Released https://api.beshu.tech/changelog <h2>1.44.0</h2><ul> <li>🚨Security Fix (ES) CVE-2022-25857</li> <li>🚀New (KBN) 8.5.2, 8.5.1, 8.5.0, 7.17.7 support</li> <li>🚀New (ES) 8.5.2, 8.5.1, 8.5.0, 7.17.7 support</li> <li>🚀New (KBN) plugin packages are now universal</li> <li>🚀New (KBN) Manage your activation keys through the customer portal</li> <li>🚀New (ES) Added support for certificates in PEM format</li> <li>🧐Enhancement (KBN) SAML groups list duplication made header size exceed limits</li> <li>🧐Enhancement (KBN) kibana_access: admin has now privileges to manage a Kibana cluster</li> <li>🧐Enhancement (ES) added distributed and persistent Test Settings & Auth Mocks configuration for the Impersonation Feature</li> <li>🧐Enhancement (ES) handling high load when LDAP rules are used</li> <li>🧐Enhancement (ES) client_authentication settings in internode SSL configuration</li> <li>🧐Enhancement (ES) acl:available_groups dynamic variable can be used in a single value context</li> <li>🐞Fix (ES) SNI handling (internode SSL)</li> </ul> 1.44.0 Sat, 06 Jul 2024 01:39:33 +0000 1.43.0 Released https://api.beshu.tech/changelog <h2>1.43.0</h2><ul> <li>🚀New (KBN) 8.4.3, 8.4.2, 8.4.1, 8.4.0, 7.17.6 support</li> <li>🚀New (ES) 8.4.3, 8.4.2, 8.4.1, 8.4.0, 7.17.6 support</li> <li>🚀New (KBN) kibana_custom_js_inject_file feature</li> <li>🐞Fix (ES) ror-tools fix for Windows OS (patching ES 3.x issue)</li> <li>🐞Fix (ES) resolving indices in the remote x-pack cluster</li> <li>🐞Fix (KBN|PRO) ROR menu title wraps when version text is too short (cosmetic)</li> <li>🐞Fix (KBN) infinite loading when kibana_access not defined for user</li> <li>🐞Fix (KBN) transient error with randomly choosing off range bind port on localhost</li> <li>🐞Fix (KBN) 404 on login when xpack.spaces.enabled: false</li> </ul> 1.43.0 Fri, 05 Jul 2024 01:39:33 +0000 1.42.0 Released https://api.beshu.tech/changelog <h2>1.42.0</h2><ul> <li>🚀New (KBN|ES) 8.3.3, 8.3.2, 8.3.1, 8.3.0, 7.15.5 support</li> <li>🧐Enhancement (KBN) Search box in tenancy switcher (when #tenancies > 5)</li> <li>🧐Enhancement (ES) added configuration warnings in the Impersonation Feature</li> <li>🐞Fix (KBN) Logout didn’t delete the SAML session on the IdP</li> <li>🐞Fix (KBN) 5xx errors from Elasticsearch break Kibana users’ session unrecoverably</li> <li>🐞Fix (ES) ROR node cooperation with X-pack nodes</li> </ul> 1.42.0 Thu, 04 Jul 2024 01:39:33 +0000 1.41.0 Released https://api.beshu.tech/changelog <h2>1.41.0</h2><ul> <li>🚀New (ES) Added groups_and mode to ror_kbn_auth and jwt_auth rules</li> <li>🧐Enhancement (KBN) Prevent native credentials dialogue to appear in Kibana when ES responds 401</li> <li>🧐Enhancement (KBN) Logging in after logout shows the same page you last visited</li> <li>🧐Enhancement (KBN) x-ror-correlation-id header lets you audit a whole Kibana session</li> <li>🐞Fix (ES|KBN) tenancy selector didn't work well with jwt_auth and ror_kbn_auth rules</li> <li>🐞Fix (KBN) Support for special characters in tenancy names</li> <li>🐞Fix (KBN) OIDC logout flow redirecting to bad request error</li> <li>🐞Fix (KBN) OIDC connector not working in Kibana < 7.12.0</li> </ul> 1.41.0 Wed, 03 Jul 2024 01:39:33 +0000 1.40.0 Released https://api.beshu.tech/changelog <h2>1.40.0</h2><ul> <li>🚨Security Fix (ES) CVE-2022-25647 & CVE-2022-24823 & CVE-2020-13956 & CVE-2020-36518 & CVE-2020-13956 & CVE-2020-36518</li> <li>🚨Security Fix (KBN) “Security” app not entirely hidden in 8.2.x</li> <li>🚀New (ES) New Support for 8.2.3, 8.2.2, 8.2.1, 7.17.4</li> <li>🚀New (KBN) New Support for 8.2.2 8.2.1, 7.17.4</li> <li>🚀New (ES & KBN) The Impersonation feature</li> <li>🚀New (ES) FIPS compliant SSL mode</li> <li>🧐Enhancement (KBN) SAML cert is now required</li> <li>🧐Enhancement (KBN) moved OIDC to better library</li> <li>🧐Enhancement (KBN) OIDC jwksURL is now required</li> <li>🐞Fix (ES) indices: ["1"] interpreted as integer and fails to parse</li> <li>🐞Fix (KBN) /login?jwt=xxx authorization now works again</li> <li>🐞Fix (KBN) OIDC/SAML assertion claims were not forwarded to ES</li> <li>🐞Fix (KBN) include whitelisted headers while logging</li> <li>🐞Fix (KBN) basepath handling fixes (too many redirects)</li> <li>🐞Fix (KBN) Make ROR default space the actual default one</li> <li>🐞Fix (KBN) OIDC connection error</li> </ul> 1.40.0 Tue, 02 Jul 2024 01:39:33 +0000 1.39.0 Released https://api.beshu.tech/changelog <h2>1.39.0</h2><ul> <li>🚨Security Fix (KBN) XSS sanitize path requested</li> <li>🚨Security Fix (ES) CVE-2020-36518 & CVE-2022-21653</li> <li>🚀New (KBN) New Support for 8.2.0 8.1.3, 8.1.2, 8.1.1, 8.1.0, 8.0.0, 8.0.1, 7.17.3, 7.17.2</li> <li>🚀New (ES) New Support for 8.2.0, 8.1.3, 8.1.2, 8.1.1, 8.1.0, 8.0.0, 8.0.1 (required additional patching step)</li> <li>🚀New (ES) New Support for 7.17.3, 7.17.2</li> <li>🚀New (ES) New groups_and ACL rule</li> <li>🧐Enhancement (KBN) Stop inlining whitelisted headers into Authorization header</li> <li>🧐Enhancement (KBN) Log additional errors and info related to HA</li> <li>🧐Enhancement (KBN) Misc internal dependencies upgrades </li> <li>🐞Fix (KBN) Mandatory elasticsearch credentials in kibana.yml </li> <li>🐞Fix (KBN) Reporting page redirect on refresh when kibana_hide_apps: ["Stack Management"]</li> <li>🐞Fix (KBN) whitelistedPaths: log errors when 404 occurs</li> <li>🐞Fix (KBN) Issue uploading large payload</li> <li>🐞Fix (KBN) elasticsearch.requestHeadersWhitelist should be case insensitive</li> <li>🐞Fix (ES) Issue with handling data streams by indices rule</li> <li>🐞Fix (ES) X-Pack SSL nodes cooperation with ROR SSL nodes</li> <li>🐞Fix (ES) _msearch issue when filter rules was used in matched block</li> </ul> 1.39.0 Mon, 01 Jul 2024 01:39:33 +0000 1.38.0 Released https://api.beshu.tech/changelog <h2>1.38.0</h2><ul> <li>🚀New (ES) New Support for 7.17.0, 7.17.1</li> <li>🚀New (KBN) New Support for 7.17.0</li> <li>🚀New (ES) Configuration for custom audit cluster</li> <li>🧐Enhancement (ES) Separate "audit" section for all audit settings</li> <li>🐞Fix (KBN) Editor rendering issue with kibana basePath enabled</li> </ul> 1.38.0 Sun, 30 Jun 2024 01:39:33 +0000 1.37.0 Released https://api.beshu.tech/changelog <h2>1.37.0</h2><ul> <li>🚨Security Fix (ES) CVE-2021-43797</li> <li>🚀New (ES) New Support for 7.16.3, 7.16.2, 6.8.23, 6.8.22</li> <li>🚀New (KBN) New Support for 7.16.3, 7.16.2, 7.16.1, 7.16.10, 6.8.23, 6.8.22, 6.8.21</li> <li>🧐Enhancement (ES) fields rule handling in the context of x-Pack SQL requests</li> <li>🐞Fix (ES) filter rule handling in the context of x-Pack SQL requests</li> <li>🐞Fix (KBN) POST / bulk cause an 400 error in devtools console</li> <li>🐞Fix (KBN) More robust Kibana patcher + better logs messages</li> </ul> 1.37.0 Sat, 29 Jun 2024 01:39:33 +0000 1.36.0 Released https://api.beshu.tech/changelog <h2>1.36.0</h2><ul> <li>🚀New (ES) New Support for 7.16.1, 7.16.0, 6.8.21</li> <li>🚀New (KBN) Support Kibana 7.15.2</li> <li>🚀New (ES) Added support for setting up cluster containing ES with ROR (with disabled XPack security) and ES with XPack security enabled</li> <li>🧐Enhancement (KBN) kibana_hide_apps: [ror|kibana] to remove kibana mgmt button</li> <li>🐞Fix (ES) /_snapshot/_status should return only running snapshots</li> <li>🐞Fix (ES) Adding policy to index template bug</li> <li>🐞Fix (KBN) Index management tabs result in "forbidden" error</li> <li>🐞Fix (KBN) corrupted patch file for Kibana 7.9.x</li> <li>🐞Fix (KBN) YAML editor not working in air-gapped environments</li> <li>🐞Fix (KBN) Devtools not working</li> <li>🐞Fix (KBN) Monitoring not working in multi-tenancy</li> <li>🐞Fix (KBN) Regression in Kibana < 6.8.x front end crash</li> <li>🐞Fix (KBN) Kibana < 7.8.x prevent navigation to hidden apps from home links</li> <li>🐞Fix (KBN) Kibana < 7.8.x implicitly hide kibana:dashboard when kibana:dashboards is hidden (and viceversa)</li> <li>🐞Fix (KBN) Kibana < 7.8.x broken clearSessionOnEvents: [tenancyHop]</li> </ul> 1.36.0 Fri, 28 Jun 2024 01:39:33 +0000 1.35.1 Released https://api.beshu.tech/changelog <h2>1.35.1</h2><ul> <li>🚨Security Fix (ES) CVE-2021-21409 & CVE-2021-27568</li> <li>🚀New (KBN) Support Kibana 7.15.1</li> <li>🚀New (ES) New Support for 7.15.2</li> <li>🧐Enhancement (KBN) Support "server.ssl.supportedProtocols" settings</li> <li>🧐Enhancement (KBN) Support "server.ssl.cipherSuites"</li> <li>🧐Enhancement (KBN) Always honor SSL cipher order</li> <li>🐞Fix (KBN) Don'thide "Add/Remove field as column" in Discover app for RO users</li> <li>🐞Fix (KBN) More alerting fixes (only for main tenancy)</li> </ul> 1.35.1 Thu, 27 Jun 2024 01:39:33 +0000 1.35.0 Released https://api.beshu.tech/changelog <h2>1.35.0</h2><ul> <li>🚀New (KBN) Support Kibana 7.15.0, 7.14.2</li> <li>🚀New (ES) New Support for 7.15.1, 6.8.19, 6.8.20</li> <li>🧐Enhancement (ES) local->external groups detailed mapping for groups rule</li> <li>🧐Enhancement (ES) when ROR is starting any request is going to end up with HTTP 403 response, instead of HTTP 503</li> <li>🧐Enhancement (KBN) "server.basePath" kibana option implementation</li> <li>🧐Enhancement (KBN) Support full regex in kibana_hidden_apps rule</li> <li>🧐Enhancement Crash if Kibana is not patched</li> <li>🧐Enhancement (KBN) Honour kibana setting "logging.dest"</li> <li>🧐Enhancement (KBN) Confirm before overwriting audit log dashboard</li> <li>🐞Fix (ES) verbosity: error fix in case of ROR KBN login request</li> <li>🐞Fix (KBN) Make alerting work on primary tenancy</li> <li>🐞Fix (KBN) OIDC fix sameSite / secure cookie options</li> <li>🐞Fix (KBN) Login form is stretched when long error</li> <li>🐞Fix (KBN) Login form is stretched when long error</li> <li>🐞Fix (KBN-PRO) Don't send x-ror-currentgroup in PRO</li> <li>🐞Fix (KBN) Resolve browser console errors on a popover close</li> </ul> 1.35.0 Wed, 26 Jun 2024 01:39:33 +0000 1.34.0 Released https://api.beshu.tech/changelog <h2>1.34.0</h2><ul> <li>🚀New (ES) New Support for 7.15.0, 7.14.2</li> <li>🚀New (KBN) VS Code style YAML editor</li> <li>🚀New (KBN) Skip rendering hidden app groups entirely</li> <li>🚀New (KBN) Redesigned ROR Menu</li> <li>🚀New (KBN) Dark theme awareness</li> <li>🐞Fix (KBN) Broken Kibana Spaces</li> <li>🐞Fix (KBN) Support Kibana's undocumented "server.ssl.*" settings</li> <li>🐞Fix (KBN) cookiePass config parsing broke load balancing</li> </ul> 1.34.0 Tue, 25 Jun 2024 01:39:33 +0000 1.33.1 Released https://api.beshu.tech/changelog <h2>1.33.1</h2><ul> <li>🚀New (ES) New Support for 7.14.1</li> <li>🐞Fix (KBN) Error in patching for 7.14.0</li> <li>🐞Fix (KBN) clearSessionOnEvents now works as expected</li> <li>🐞Fix (KBN) login form font loads correctly</li> </ul> 1.33.1 Mon, 24 Jun 2024 01:39:33 +0000 1.33.0 Released https://api.beshu.tech/changelog <h2>1.33.0</h2><ul> <li>🚨Security Fix (KBN) xml-crypto dependency update</li> <li>🚀New (KBN) New Support for 7.14.0, 6.8.18</li> <li>🧐Enhancement (KBN) Parse credentials in /api/* requests, no need for valid cookie. Supersedes whitelistedPaths</li> <li>🐞Fix (KBN)Caching issues switching tenancies with dark/light theme</li> <li>🐞Fix (KBN) Newly created Space shows in all tenancies when using default kibana index</li> <li>🐞Fix (KBN < 7.9.x) nextUrl works again with SAML and OIDC</li> </ul> 1.33.0 Sun, 23 Jun 2024 01:39:33 +0000 1.32.0 Released https://api.beshu.tech/changelog <h2>1.32.0</h2><ul> <li>🚨Security Fix (ES) Apache Commons Codec vulnerability</li> <li>🚨Security Fix (KBN) upgraded dependencies due to security fixes</li> <li>🚨Security Fix (KBN) disable x-powered-by to avoid fingerprinting</li> <li>🚀New (ES) Support for ES 7.14.0 & 6.8.18</li> <li>🚀New (KBN) Support for Kibana 7.13.x series</li> <li>🧐Enhancement (KBN) honor configurations coming from ENV and CLI options</li> <li>🧐Enhancement (KBN) when metadata has no username, login must be denied</li> <li>🧐Enhancement (KBN) audit tab ported to new platform</li> <li>🧐Enhancement (ES) improved ES resources cleaning when ROR returns FORBIDDEN response</li> <li>🧐Enhancement (KBN < 7.9.x) auto clean-up dangling SAML/OIDC cookies</li> <li>🐞Fix (ES) incomplete response for request GET */_alias</li> <li>🐞Fix (ES) not allowed aliases should not present in a response for a Get Index API request</li> <li>🐞Fix (KBN) fix dev-tools and import saved object not working</li> <li>🐞Fix (KBN) honor requestHeadersWhitelist in user metadata request (login)</li> <li>🐞Fix (KBN < 7.9.x) do not crash on invalid metadata</li> </ul> 1.32.0 Sat, 22 Jun 2024 01:39:33 +0000 1.31.0 Released https://api.beshu.tech/changelog <h2>1.31.0</h2><ul> <li>🚨Security Fix (KBN) prevent direct navigation to hidden apps</li> <li>🚀New (ES) 7.13.4, 7.13.3, 7.13.2, 6.8.17 support</li> <li>🚀New (KBN) new minimal Kibana Management menu when "Management" app is hidden</li> <li>🧐Enhancement (KBN) logout active Kibana session if key metadata/permissions change in ACL</li> <li>🧐Enhancement (KBN) better port number validation</li> <li>🧐Enhancement (ES) improved cluster indices handling</li> <li>🐞Fix (ES) Kibana access rule regression fix</li> <li>🐞Fix (ES) search template API handling with filter and fields rule</li> <li>🐞Fix (ES) multi-tenancy issue when groups_provider_authorization is used</li> <li>🐞Fix (ES) x_forwarded_for rule: wrong handling of / request</li> <li>🐞Fix (ES) Issue with handling ResizeRequest which made it unable to upgrade Kibana to version 7.12.0+</li> <li>🐞Fix (KBN) some Kibana requests arrive to ES without credentials</li> <li>🐞Fix (KBN) inconsistent read after write in session storage lead to issues with round robin load balancing</li> <li>🐞Fix (KBN) bad multipart POST handling leads to saved object import errors</li> </ul> 1.31.0 Fri, 21 Jun 2024 01:39:33 +0000 1.30.1 Released https://api.beshu.tech/changelog <h2>1.30.1</h2><ul> <li>🚨Security Fix (ES) CVE-2021-27568</li> <li>🚀New (ES) 7.13.0, 7.13.1 support</li> <li>🐞Fix (ES) Regression in multi-tenancy handling</li> <li>🐞Fix (ES) Proper handling of _snapshot/_status endpoint</li> </ul> 1.30.1 Thu, 20 Jun 2024 01:39:33 +0000 1.30.0 Released https://api.beshu.tech/changelog <h2>1.30.0</h2><ul> <li>🚀New (KBN) 7.12.x compatibility</li> <li>🚀New (ES) LDAP connector circuit breaker</li> <li>🧐Enhancement (ES) Username with wildcard support in users section and groups mapping</li> <li>🧐Enhancement (KBN < 7.9.x) OIDC errors visibility</li> <li>🧐Enhancement (KBN < 7.9.x) Smarter session probe algorithm</li> <li>🐞Fix (KBN >= 7.9.x) Load CertificateAuthorities as an array if not specified as an array</li> <li>🐞Fix (KBN < 7.9.x) Don't hide visualizations list search box in RO mode</li> </ul> 1.30.0 Wed, 19 Jun 2024 01:39:33 +0000 1.29.0 Released https://api.beshu.tech/changelog <h2>1.29.0</h2><ul> <li>🚨Security Fix (ES) Security Fix (ES) CVE-2021-21409</li> <li>🚀New (KBN) support 7.9.0, 7.9.1, 7.10.0, 7.10.1, 7.10.2, 7.11.0, 7.11.1, 7.11.2 (with ROR new platform) </li> <li>🚀New (ES) 7.12.1 support </li> <li>🧐Enhancement (KBN) logout if the credentials/metadata of the current user change in the ACL</li> </ul> 1.29.0 Tue, 18 Jun 2024 01:39:33 +0000 1.28.2 Released https://api.beshu.tech/changelog <h2>1.28.2</h2><ul> <li>🚨Security Fix (ES) CVE-2021-21295</li> <li>🐞Fix (KBN) prevent SAML/OIDC initiated Kibana sessions from expiring after session_timeout_minutes despite continued interaction</li> </ul> 1.28.2 Mon, 17 Jun 2024 01:39:33 +0000 1.28.1 Released https://api.beshu.tech/changelog <h2>1.28.1</h2><ul> <li>🐞Fix (ES) Getting index templates issue when no indices rule was used in matched block</li> <li>🐞Fix (ES) NPE on getting template aliases</li> </ul> 1.28.1 Sun, 16 Jun 2024 01:39:33 +0000 1.28.0 Released https://api.beshu.tech/changelog <h2>1.28.0</h2><ul> <li>🚀New (ES) 7.12.0, 7.11.2 support </li> <li>🚀New (ES) full Index and Component Templates API support </li> <li>🧐Enhancement (ES) Username case sensitivity settings</li> <li>🐞Fix (ES) Kibana logout event storing fix</li> <li>🐞Fix (ES) Fixed remote reindex operation with "type" parameter</li> <li>🐞Fix (KBN) Prevent cookie expiration deadlock in browsers when using SAML/OIDC</li> <li>🐞Fix (KBN) When credentials change in the ACL, make it possible to login again</li> <li>🐞Fix (KBN) Kibana management app ID changed from "kibana:management" to "kibana:stack_management"</li> </ul> 1.28.0 Sat, 15 Jun 2024 01:39:33 +0000 1.27.1 Released https://api.beshu.tech/changelog <h2>1.27.1</h2><ul> <li>🚨Security Fix (ES) CVE-2021-21290</li> <li>🚀New (ES) 7.11.1 support </li> </ul> 1.27.1 Fri, 14 Jun 2024 01:39:33 +0000 1.27.0 Released https://api.beshu.tech/changelog <h2>1.27.0</h2><ul> <li>🚀New (ES) 7.11.0, 7.10.2, 6.8.14 support</li> <li>🧐Enhancement (KBN) X-Forwarded-For copied from incoming request (or filled with source IP) before forwarding to ES</li> <li>🧐Enhancement (KBN) Kibana logout event generates a special audit log entry in ROR audit logs index</li> <li>🧐Enhancement (KBN) ROR panel shows "reports" button if kibana:management app is hidden</li> <li>🐞Fix (ES) blocks containing filter and/or fields won't match internal kibana requests, so kibana_* rules won't have to be placed in such blocks</li> <li>🐞Fix (ES) SQL API - better handling of invalid query</li> </ul> 1.27.0 Thu, 13 Jun 2024 01:39:33 +0000 1.26.1 Released https://api.beshu.tech/changelog <h2>1.26.1</h2><ul> <li>🐞Fix (ES) wrong behaviour of kibana_access rule for ROR actions when ADMIN value is set</li> </ul> 1.26.1 Wed, 12 Jun 2024 01:39:33 +0000 1.26.0 Released https://api.beshu.tech/changelog <h2>1.26.0</h2><ul> <li>🚨Security Fix (ES) CVE-2020-35490 & CVE-2020-35490 (removed Jackson dependency from ROR core)</li> <li>🚀New (ES) New response_fields rule</li> <li>🚀New (ES) Support for LDAP server discovery using _ldaps._tcp SRV record</li> <li>🚀 New (ES) New configuration option allowing to ignore LDAP connectivity problems</li> <li>🧐Enhancement (ES) Full support for ILM API</li> <li>🧐Enhancement (KBN) Enforce read-after-write consistency between kibana nodes</li> <li>🧐Enhancement (KBN ENT) OIDC custom claims incorporated in "assertion" claim</li> <li>🧐Enhancement (KBN ENT) OIDC support for configurable kibanaExternalHost (good for Docker)</li> <li>🧐Enhancement (KBN ENT) ROR adds "ror-user_" class to "body" tag for easy per-user CSS/JS</li> <li>🧐Enhancement (KBN ENT/PRO) ROR adds "ror-group_" class to "body" tag for easy per-group CSS/JS</li> <li>🐞Fix (ES) ROR authentication endpoint action</li> <li>🐞Fix (ES) "username" in audit entry when request is rejected</li> </ul> 1.26.0 Tue, 11 Jun 2024 01:39:33 +0000 1.25.2 Released https://api.beshu.tech/changelog <h2>1.25.2</h2><ul> <li>🐞Fix (ES) removed verbose logging</li> </ul> 1.25.2 Mon, 10 Jun 2024 01:39:33 +0000 1.25.1 Released https://api.beshu.tech/changelog <h2>1.25.1</h2><ul> <li>🚨Security Fix (ES) CVE-2020-25649</li> <li>🚀New (ES) 7.10.1 support</li> </ul> 1.25.1 Sun, 09 Jun 2024 01:39:33 +0000 1.25.0 Released https://api.beshu.tech/changelog <h2>1.25.0</h2><ul> <li>🚨Security Fix (ES) Common Vulnerabilities and Exposures (CVE)</li> <li>🚀New (ES) 7.10.0 support</li> <li>🚀New (ES) auth_key_pbkdf2 rule</li> <li>🚀New (ES) Introduced configuration property defining FLS engine used by fields rule</li> <li>🧐Enhancement (ES) Fields rule performance improvement</li> <li>🧐Enhancement (ES) Resolved index API support</li> <li>🐞Fix (ES) "username" in audit entry when user is authenticated via proxy_auth</li> <li>🐞Fix (ES) index resolve action should be treated as readonly action</li> <li>🐞Fix (ES) /_snapshot and /_snapshot/_all should behave the same</li> </ul> 1.25.0 Sat, 08 Jun 2024 01:39:33 +0000 1.24.0 Released https://api.beshu.tech/changelog <h2>1.24.0</h2><ul> <li>🚨Security Fix (ES) search template handling fix</li> <li>🚀New (ES) 7.9.3 & 6.8.13 support</li> <li>🧐Enhancement (ES) full support for ES Snapshots and Restore APIs</li> <li>🐞Fix (KBN) fix crash in error handling</li> <li>🐞Fix (ES) don't remove ES response warning headers</li> <li>🐞Fix (ES) issue when entropy of /dev/random could have been exhausted when using JwtToken rule</li> </ul> 1.24.0 Fri, 07 Jun 2024 01:39:33 +0000 1.23.1 Released https://api.beshu.tech/changelog <h2>1.23.1</h2><ul> <li>🚀New (ES) 7.9.2 support</li> <li>🐞Fix (KBN) fix code 500 error on login in Kibana</li> </ul> 1.23.1 Thu, 06 Jun 2024 01:39:33 +0000 1.23.0 Released https://api.beshu.tech/changelog <h2>1.23.0</h2><ul> <li>🚀New (ES) introduced must_involve_indices option for indices rule</li> <li>🧐Enhancement (ES) negation support in headers rules</li> <li>🧐Enhancement (ES) x-pack rollup API handling</li> <li>🐞Fix (KBN) deep links query parameters are now handled</li> <li>🐞Fix (KBN) make sure default kibana index is always discovered (fixes reporting in 6.x)</li> <li>🐞Fix (ES) settings file permission issue with JDK 1.8.0 25.262-b10</li> <li>🐞Fix (ES) /_cluster/allocation/explain request should not be forbidden if matched block doesn't have indices rules</li> <li>🐞Fix (ES) remote address extracting issue</li> <li>🐞Fix (ES) fixed TYP audit field for some request types</li> </ul> 1.23.0 Wed, 05 Jun 2024 01:39:33 +0000 1.22.1 Released https://api.beshu.tech/changelog <h2>1.22.1</h2><ul> <li>🐞Fix (ES) missing handling of aliases API for ES 7.9.0</li> </ul> 1.22.1 Tue, 04 Jun 2024 01:39:33 +0000 1.22.0 Released https://api.beshu.tech/changelog <h2>1.22.0</h2><ul> <li>🚀New (ES) 7.9.0 support</li> <li>🧐Enhancement (ES) aliases API handling</li> <li>🧐Enhancement (ES) dynamic variables support in fields rule</li> <li>🐞Fix (ES) adding aliases issue</li> <li>🐞Fix (ES) potential memory leak for ES 7.7.x and above</li> <li>🐞Fix (ES) cross cluster search issue fix for X-Pack _async_search action</li> <li>🐞Fix (ES) XFF entry in audit issue</li> <li>🐞Fix (KBN) SAML certificate loading</li> <li>🐞Fix (KBN) SAML loading groups from assertion</li> <li>🐞Fix (KBN) fix reporting in pre-7.7.0</li> </ul> 1.22.0 Mon, 03 Jun 2024 01:39:33 +0000 1.21.0 Released https://api.beshu.tech/changelog <h2>1.21.0</h2><ul> <li>🧐Enhancement (ES) cluster API support improvements</li> <li>🐞Fix (ES) X-Pack _async_search support</li> <li>🐞Fix (ES) _rollover request handling</li> <li>🐞Fix (ES) handling numeric ssl configuration properties</li> <li>🐞Fix (KBN) multitenancy+reporting regression fix (for 7.6.x and earlier)</li> <li>🐞Fix (KBN) "x-" headers should be forwarded in /login route when proxy passthrough is enabled</li> <li>🐞Fix (KBN) Logout now redirects to login screen when using proxy</li> <li>🐞Fix (KBN) SAML metadata.xml endpoint not responding</li> <li>🐞Fix (KBN) NAT/reverse proxy support for SAML</li> <li>🐞Fix (KBN) SAML login redirect error</li> <li>🐞Fix (ES) _readonlyrest/metadata/current_user should be always allowed by filter/fields rule</li> </ul> 1.21.0 Sun, 02 Jun 2024 01:39:33 +0000 1.20.0 Released https://api.beshu.tech/changelog <h2>1.20.0</h2><ul> <li>🚀New 7.7.1, 7.8.0 support</li> <li>🧐Enhancement (KBN) tidy up audit page</li> <li>🧐Enhancement (KBN FREE) clearly inform when features are not available</li> <li>🧐Enhancement (KBN) ship license report of libraries</li> <li>🧐Enhancement (ES) filter rule performance improvement</li> <li>🐞Fix (KBN) proxy_auth: avoid logout-login loop</li> <li>🐞Fix (KBN) 404 error on font CSS file</li> <li>🐞Fix (ES) wildcard in filter query issue</li> <li>🐞Fix (ES) forbidden /_snapshot issue</li> <li>🐞Fix (ES) /_mget handling by indices rule when no index from a list is found</li> <li>🐞Fix (ES) available groups order in metadata response should match the order in which groups appear in ACL</li> <li>🐞Fix (ES) .readonlyrest and audit index - removed usage of explicit index type</li> <li>🐞Fix (ES) tasks leak bug</li> </ul> 1.20.0 Sat, 01 Jun 2024 01:39:33 +0000 1.19.5 Released https://api.beshu.tech/changelog <h2>1.19.5</h2><ul> <li>🚀New 7.7.0, 7.6.2, 6.8.9, 6.8.8 support</li> <li>🧐Enhancement (ES/KBN) kibana_access can be explicitly set to unrestricted</li> <li>🧐Enhancement (ES) LDAP connection pool improvement</li> <li>🐞Fix (ES) better LDAP request timeout handling</li> <li>🐞Fix (ES) remote indices searching bug</li> <li>🐞Fix (ES) cross cluster search support for _field_caps request</li> <li>🚨Security Fix (ES) create and delete templates handling</li> <li>🐞Fix (KBN) Regression in proxy_auth_passthrough</li> <li>🧐Enhancement (KBN) whitelistedPaths now accepts basic auth credentials</li> <li>🧐Enhancement (KBN) Dump logout button, new ROR Panel</li> <li>🧐Enhancement (KBN) removed ROR from Kibana sidebar. Admins have a link in new panel.</li> <li>🧐Enhancement (KBN) avoid show login form redirecting from SAML IdP</li> <li>🚀New (KBN) OpenID Connect (OIDC) authentication connector</li> <li>🚀New (KBN) login_title, login_subtitle enable 2 column login page</li> <li>🚨Security Fix (KBN) server-side navigation prevention to hidden apps</li> </ul> 1.19.5 Fri, 31 May 2024 01:39:33 +0000 1.19.4 Released https://api.beshu.tech/changelog <h2>1.19.4</h2><ul> <li>🐞Fix (ES) Interpolating config with environment variables in SSL section</li> <li>🐞Fix (KBN Ent 6.x) Fixed default space creation in</li> <li>🐞Fix (KBN 6.x) Fixed error toast notification not showing</li> <li>🐞Fix (KBN Ent) Fixed missing Axios dependency</li> <li>🐞Fix (KBN Ent) Fixed SAML connector</li> <li>🐞Fix (KBN) Toast notification overlap with logout bar</li> <li>🧐Enhancement (KBN) Restyled logout bar</li> <li>🧐Enhancement (KBN) Configurable periodic session checker</li> </ul> 1.19.4 Thu, 30 May 2024 01:39:33 +0000 1.19.3 Released https://api.beshu.tech/changelog <h2>1.19.3</h2><ul> <li>🚀New (ES/KBN) 7.6.1 compatibility</li> <li>🚀New (ES) customizable name of settings index</li> <li>🧐Enhancement (KBN) configurable ROR cookie name</li> <li>🧐Enhancement (ES/KBN) handling of encoded ROR headers in Authorization header values</li> <li>🧐Enhancement (KBN) user feedback on why login failed</li> <li>🐞Fix (ES) support for multiple header values</li> <li>🐞Fix (ES) releasing LDAP connection pool on reloading ROR settings</li> <li>🐞Fix (KBN) multitenancy issue with 7.6.0+</li> <li>🐞Fix (KBN) creation of default space for new tenant</li> <li>🐞Fix (KBN 6.x) in RO mode, don't hide add/remove over fields in discovery</li> <li>🐞Fix (KBN 6.x) index template & in-index session manager issues</li> </ul> 1.19.3 Wed, 29 May 2024 01:39:33 +0000 1.19.2 Released https://api.beshu.tech/changelog <h2>1.19.2</h2><ul> <li>🚀New (KBN) 7.6.0 support</li> <li>🧐Enhancement (KBN) less verbose info logging</li> <li>🧐Enhancement (KBN) start up time semantic check for settings</li> <li>🐞Fix (KBN Free) missing logout button</li> <li>🐞Fix (KBN) error message creating internal proxy</li> <li>🐞Fix (KBN 6.x) add field to filter button invisible in RO mode</li> </ul> 1.19.2 Tue, 28 May 2024 01:39:33 +0000 1.19.1 Released https://api.beshu.tech/changelog <h2>1.19.1</h2><ul> <li>🎁Product (KBN) Launched ReadonlyREST Free for Kibana!</li> <li>🚀New (ES) 7.6.0 support, Kibana support coming soon</li> <li>🚀New (KBN) Audit log dashboard</li> <li>🚀New (KBN) Template index can now be declared per tenant instead of globally</li> <li>🚀New (ES) custom trust store file and password options in ROR settings</li> <li>🧐Enhancement (ES) When "prompt_for_basic_auth" is enabled, ROR is going to return 401 instead of 404 when the index is not found or a user is not allowed to see the index</li> <li>🧐Enhancement (ES) literal ipv6 with zone Id is acceptable network address</li> <li>🧐Enhancement (ES) LDAP client cache improvements</li> <li>🐞Fix (ES) /_all/_settings API issue</li> <li>🐞Fix (ES) Index stats API & Index shard stores API issue</li> <li>🐞Fix (ES) readonlyrest.force_load_from_file setting decoding issue</li> <li>🐞Fix (KBN) allowing user to be logged in in two tabs at the same time</li> <li>🐞Fix (KBN) logging with JWT parameter issue</li> <li>🐞Fix (KBN) parsing of sessions fetched from ES index</li> <li>🐞Fix (KBN) logout issue</li> </ul> 1.19.1 Mon, 27 May 2024 01:39:33 +0000 1.19.0 Released https://api.beshu.tech/changelog <h2>1.19.0</h2><ul> <li>🚀New (KBN) Configurable option to delete docs from tenant index when not present in template</li> <li>🧐Enhancement (ES) Less verbose logging of blocks history</li> <li>🧐Enhancement (ES) Enriched logs and audit with attempted username</li> <li>🧐Enhancement (ES) Better settings validation - only one authentication rule can be used in given block</li> <li>🧐Enhancement (ES/KBN) Plugin versions printing in logs on launch</li> <li>🧐Enhancement (ES) When user doesn't have access to given index, ROR pretends that the index doesn't exist and return 404 instead of 403</li> <li>🐞Fix (ES) Searching for nonexistent/forbidden index with wildcard mirrors default ES behaviour instead of returning 403</li> <li>🐞Fix (KBN) Switching groups bug</li> </ul> 1.19.0 Sun, 26 May 2024 01:39:33 +0000 1.18.10 Released https://api.beshu.tech/changelog <h2>1.18.10</h2><ul> <li>🚀New (ES/KBN) Support v6.8.6, v7.5.0, v7.5.1</li> <li>🚀New (KBN) Group names can now be mapped to aliases</li> <li>🚀New (ES) New, more robust and simple method of creating custom audit log serializers</li> <li>🚀New (ES) Example projects with custom audit log serializers</li> <li>🐞Fix (KBN) Prevent index migration after kibana startup</li> <li>🧐Enhancement (KBN) If default space doesn't exist in kibana index then copy from default one</li> <li>🧐Enhancement (KBN) Crypto improvements - store init vector with encrypted data as base64 encoded json.</li> <li>🧐Enhancement (ES) Better settings validation - prevent duplicated keys in readonlyrest.yml</li> </ul> 1.18.10 Sat, 25 May 2024 01:39:33 +0000 1.18.9 Released https://api.beshu.tech/changelog <h2>1.18.9</h2><ul> <li>🚀New (ES/KBN) Support v7.4.1, v7.4.2</li> <li>🚀New (KBN) Kibana sessions stored in ES index</li> <li>🐞Fix (ES) issue with in-index settings auto-reloading</li> <li>🐞Fix (ES) _cat/indices empty response when matched block doesn't contain 'indices' rule</li> </ul> 1.18.9 Fri, 24 May 2024 01:39:33 +0000 1.18.8 Released https://api.beshu.tech/changelog <h2>1.18.8</h2><ul> <li>🚀New (ES/KBN) Support v7.4.0</li> <li>🚀New (ES) Elasticsearch SQL Support</li> <li>🚀New (ES) Internode ssl support for es5x, es60x, es61x and es62x</li> <li>🚀New (ES) new runtime variable @{acl:current_group}</li> <li>🚀New (ES) namespace for user variable and support for both versions: @{user} and @{acl:user}</li> <li>🚀New (ES) support for multiple values in uri_re rule</li> <li>🧐Enhancement (ES) more reliable in-index settings loading of ES with ROR startup</li> <li>🧐Enhancement (ES) less verbose logs in JWT rules</li> <li>🧐Enhancement (ES) Better response from ROR API when plugin is disabled</li> <li>🧐Enhancement (ES) Splitting verification ssl property to client_authentication and certificate_verification</li> <li>🐞Fix (ES) issue with backward compatibility of proxy_auth settings</li> <li>🐞Fix (ES) /_render/template request NPE</li> <li>🐞Fix (ES) _cat/indices API bug fixes</li> <li>🐞Fix (ES) _cat/templates API return empty list instead of FORBIDDEN when no indices are found</li> <li>🐞Fix (ES) updated regex for kibana access rule to support 7.3 ES</li> <li>🐞Fix (ES) proper resolving of non-string ENV variables in readonlyrest.yml</li> <li>🐞Fix (ES) lang-mustache search template handling</li> </ul> 1.18.8 Thu, 23 May 2024 01:39:33 +0000 1.18.7 Released https://api.beshu.tech/changelog <h2>1.18.7</h2><ul> <li>🚀New (ES) Field level security (FLS) supports nested JSON fields</li> <li>🐞Security Fix (ES) Authorization headers appeared in clear in logs</li> <li>🧐Enhancement (KBN) Don't logout users when they are not allowed to search a index-pattern</li> <li>🧐Enhancement (ES) Headers obfuscation is now case insensitive</li> </ul> 1.18.7 Wed, 22 May 2024 01:39:33 +0000 1.18.6 Released https://api.beshu.tech/changelog <h2>1.18.6</h2><ul> <li>🚀New (ES/KBN) Support v7.3.1, v7.3.2</li> <li>🚀New (ES) Configurable header names whose value should be obfuscated in logs</li> <li>🚀New (KBN) Dynamic variables from user identity available in custom_logout_link</li> <li>🧐Enhancement (ES) Richer logs for JWT errors</li> <li>🧐Enhancement (ENT) nextUrl works also with SAML now</li> <li>🧐Enhancement (ENT) SAML assertion object available in ACL dynamic variables</li> <li>🧐Enhancement (KBN) Validate LDAP server(s) before accepting new YAML settings</li> <li>🧐Enhancement (KBN) Ensure a read-only UX for 'ro' users in older Kibana</li> <li>🐞Fix (ES) Fix memory leak from dependency (snakeYAML)</li> </ul> 1.18.6 Tue, 21 May 2024 01:39:33 +0000 1.18.5 Released https://api.beshu.tech/changelog <h2>1.18.5</h2><ul> <li>🐞Security Fix (ES) indices rule can now properly handle also the templates API</li> <li>🧐Enhancement (ES) Array dynamic variables are serialized as CSV wrapped in double quotes</li> <li>🧐Enhancement (ES) Cleaner debug logs (no stacktraces on forbidden requests)</li> <li>🧐Enhancement (ES) LDAP debug logs fire also when cache is hit</li> <li>🚀New (ES/KBN) Support v7.2.1, v7.3.0</li> <li>🐞Fix (PRO) PRO plugin crashing for some Kibana versions</li> <li>🐞Fix (ENT) SAML library wrote a too large cookie sometimes</li> <li>🐞Fix (ENT) SAML logout not working</li> <li>🐞Fix (ENT) JWT fix exception "cannot set requestHeadersWhitelist"</li> <li>🐞Fix (PRO/ENT) Hide more UI elements for RO users</li> <li>🐞Fix (PRO/ENT) Sometimes not all the available groups appear in tenancy selector</li> <li>🐞Fix (PRO/ENT) Feature "nextUrl" broke</li> <li>🐞Fix (PRO/ENT) prevent user kick-out when APM is not configured and you are not an admin</li> <li>🚀New (PRO/ENT) Kibana request path/method now sent to ES (good for policing dev-tools)</li> </ul> 1.18.5 Mon, 20 May 2024 01:39:33 +0000 1.18.4 Released https://api.beshu.tech/changelog <h2>1.18.4</h2><ul> <li>🚀New (ES) User impersonation API</li> <li>🚀New (ES) Support latest 6.x and 5.x versions</li> <li>🐞Security Fix (ES) filter/fields rules leak</li> <li>🐞Fix (KBN/ENT) allow more action for kibana_access, prevent sudden logout</li> <li>🐞Fix (KBN/ENT) temporarily roll back "support for unlimited tenancies"</li> </ul> 1.18.4 Sun, 19 May 2024 01:39:33 +0000 1.18.3 Released https://api.beshu.tech/changelog <h2>1.18.3</h2><ul> <li>🚀New Support added for ES/Kibana 6.8.1</li> <li>🧐Enhancement (ES) Crash ES on invalid settings instead of stalling forever</li> <li>🧐Enhancement (ES) Better logging on JWT, JSON-paths, LDAP, YAML errors</li> <li>🧐Enhancement (ES) Block level settings validation to user with precious hints</li> <li>🧐Enhancement (ES) If force_load_from_file: true, don't poll index settings</li> <li>🧐Enhancement (ES) Order now counts declaring LDAP Failover HA servers</li> <li>🐞Fix (ES) "EsIndexJsonContentProvider" had a null pointer exception</li> <li>🐞Fix (ES) "es.set.netty.runtime.available.processors" exception</li> <li>🧐Enhancement (KBN) Collapsible logout button</li> <li>🧐Enhancement (KBN) ROR App now uses a HA http client</li> <li>🧐Enhancement (KBN) Automatic logout for inactivity</li> <li>🧐Enhancement (KBN) Support unlimited amount of tenancies</li> <li>🐞Fix (KBN/ENT) concurrent multitenancy bug</li> <li>🐞Fix (KBN) Avoid sporadic errors on Save/Load buttons</li> </ul> 1.18.3 Sat, 18 May 2024 01:39:33 +0000 1.18.2 Released https://api.beshu.tech/changelog <h2>1.18.2</h2><ul> <li>🚀New Support for Elasticsearch & Kibana 7.2.0</li> <li>🐞Fix (ES) restore indices ("IDX") in audit logging</li> <li>🧐Enhancement (ES) New algorithm of setting evaluation order</li> <li>🚀New (ES) JWT claims as dynamic variables. I.e. "@{jwt:claim.json.path}"</li> <li>🚀New (ES) "explode" dynamic variables. I.e. indices: ["@explode{x-indices}"]</li> <li>🐞Fix (PRO/Enterprise) preserve comments and formatting in YAML editor</li> <li>🐞Fix (PRO/Enterprise) Print error message when session is expired</li> <li>🐞Regression (PRO/Enterprise) Redirect to original link after login</li> <li>🐞Regression (PRO/Enterprise) Broken CSV reporting</li> <li>🧐Enhancement (PRO/Enterprise) Prevent navigating away from YAML editor w/ unsaved changes</li> <li>🐞Fix (Enterprise) Exception when SAML connectors were all disabled</li> <li>🐞Fix (Enterprise) Concurrent tenants could mix up each other kibana index</li> <li>🐞Fix (Enterprise) Cannot inject custom JS if no custom CSS was also declared</li> <li>🐞Fix (Enterprise) Injected JS had no effect on ROR logout button</li> <li>🐞Fix (Enterprise) On narrow screens, the YAML editor showed buttons twice</li> </ul> 1.18.2 Fri, 17 May 2024 01:39:33 +0000 1.18.1 Released https://api.beshu.tech/changelog <h2>1.18.1</h2><ul> <li>🐞Fix (Elasticsearch) Reindex requests failed for a regression in indices extraction</li> <li>🐞Fix (Elasticsearch) Groups rule erratically failed</li> <li>🐞Fix (Elasticsearch) JWT claims can now contain special characters</li> <li>🧐Enhancement (Elasticsearch) Better ACL History logging</li> <li>🧐Enhancement (Elasticsearch) QueryLogSerializer and old custom log serializers work again</li> <li>🐞Fix (PRO/Enterprise) ReadonlyREST icon in Kibana was white on white</li> <li>🐞Fix (Enterprise) SAML connectors could not be disabled</li> <li>🐞Fix (Enterprise) SAML connector "buttonName" didn't work</li> </ul> 1.18.1 Thu, 16 May 2024 01:39:33 +0000 1.18.0 Released https://api.beshu.tech/changelog <h2>1.18.0</h2><ul> <li>🚀New Support for Elasticsearch & Kibana 7.0.1</li> <li>🧐Enhancement (Elasticsearch) empty array values in settings are invalid</li> <li>🐞Security Fix (Elasticsearch) arbitrary x-cluster search referencing local cluster</li> <li>🐞Fix (Elasticsearch) ArrayOutOfBoundException on snapshot operations</li> <li>🧐Enhancement (PRO/Enterprise) History cleaning can now be disabled ("clearSessionOnEvents")</li> </ul> 1.18.0 Wed, 15 May 2024 01:39:33 +0000 1.17.7 Released https://api.beshu.tech/changelog <h2>1.17.7</h2><ul> <li>🚀New Support for Elasticsearch 7.0.0 (Kibana is coming soon)</li> <li>🧐Enhancement (Elasticsearch) rewritten LDAP connector</li> <li>🧐Enhancement (Elasticsearch) new core written in Scala is now GA</li> <li>🐞Fix (Enterprise) devtools requests now honor the currently selected tenancy</li> <li>🐞Security Fix (Enterprise/PRO) Fix "connectorsService" error in installation</li> </ul> 1.17.7 Tue, 14 May 2024 01:39:33 +0000 1.17.5 Released https://api.beshu.tech/changelog <h2>1.17.5</h2><ul> <li>🚀New Support for Kibana/Elasticsearch 6.7.1</li> <li>🧐Enhancement (Enterprise >= Kibana 6.6.0) Multiple SAML identity provider</li> <li>🐞Security Fix (Enterprise/PRO) Don't pass auth headers back to the browser</li> <li>🐞Fix (Enterprise/PRO) Missing null check caused error in reporting (CSV)</li> <li>🐞Fix (Enterprise) Don't reject requests if SAML groups are not configured</li> <li>🐞Fix filter/fields rules not working in msearch (in 6.7.x)</li> <li>🧐Enhancement Print whole LDAP search query in debug log</li> </ul> 1.17.5 Mon, 13 May 2024 01:39:33 +0000 1.17.4 Released https://api.beshu.tech/changelog <h2>1.17.4</h2><ul> <li>🚀New Support for Kibana/Elasticsearch 6.7.0</li> <li>🧐Enhancement (PRO/Enterprise) JWT query param is the preferred credentials provider</li> <li>🧐Enhancement (PRO/Enterprise) admin users can use indices management</li> <li>🧐Enhancement (PRO/Enterprise) ro users can dismiss telemetry form</li> <li>🐞Fix Audit logging in 5.1.x now works again</li> <li>🐞Fix unpredictable behaviour of "filter" and "fields" when using external auth</li> <li>🐞Fix LDAP ConcurrentModificationException</li> <li>🐞Fix Audit logging in 5.1.x now works again</li> <li>🐞Fix (PRO/Enterprise) JWT deep-link works again</li> </ul> 1.17.4 Sun, 12 May 2024 01:39:33 +0000 1.17.3 Released https://api.beshu.tech/changelog <h2>1.17.3</h2><ul> <li>🐞Fix (Enterprise) Tenancy selector showing if user belonged to one group</li> <li>🐞Fix (PRO/Enterprise) RW buttons not hiding for RO users in React Kibana apps</li> <li>🐞Fix (Enterprise) Tenancy templating now works much more reliably</li> <li>🐞Fix (Enterprise) Missing tenancy selector icon after switching tenancy</li> <li>🐞Fix (PRO/Enterprise) barring static files requests caused sudden logout</li> <li>🐞Fix Numerous fixes to better support Kibana 6.6.x</li> <li>🐞Fix Critical fixes in new Scala core</li> <li>🐞Fix Exception in reindex requests caused tenancy templating to fail</li> <li>🧐Enhancement Bypass cross-cluster search logic if single cluster</li> </ul> 1.17.3 Sat, 11 May 2024 01:39:33 +0000 1.17.1 Released https://api.beshu.tech/changelog <h2>1.17.1</h2><ul> <li>🐞Fix (PRO/Enterprise) SAML now works well in 6.6.x</li> <li>🐞Fix (PRO/Enterprise) "undefined" authentication error before login</li> <li>🐞Fix (Enterprise) Default space creation failures for new tenants</li> <li>🐞Fix (Enterprise) Icons/titles CSS misalignment in sidebar (Firefox)</li> <li>🧐Enhancement(Enterprise) UX: Larger tenancy selector</li> <li>🐞Security Fix (Enterprise) Privilege escalation when changing tenancies under monitoring</li> <li>🐞Fix (Elasticsearch) compatibility fixes to support new Kibana features</li> <li>🧐Enhancements (Elasticsearch) New core and LDAP connector written in Scala is finished, now under QA.</li> </ul> 1.17.1 Fri, 10 May 2024 01:39:33 +0000 1.17.0 Released https://api.beshu.tech/changelog <h2>1.17.0</h2><ul> <li>🚀New Feature Support for Kibana/Elasticsearch 6.6.0, 6.6.1</li> <li>🚀New Feature Internode SSL (ES 6.3.x onwards)</li> <li>🧐Enhancement(PRO/Enterprise) UI appearence</li> <li>🧐Enhancement Made HTTP Connection configurable (PR #410)</li> <li>🐞Fix slow boot due to SecureRandom waiting for sufficient entropy</li> <li>🐞Fix Enable kibana_access:ro to create short urls in es6.3+ (PR #408)</li> </ul> 1.17.0 Thu, 09 May 2024 01:39:33 +0000 1.16.34 Released https://api.beshu.tech/changelog <h2>1.16.34</h2><ul> <li>🧐Enhancement X-Forwarded-For header in printed es logs ("XFF")</li> <li>🧐Enhancement kibana_index: ".kibana_@{user}" when user is "John Doe" becomes .kibana_john_doe</li> <li>🐞Fix (Enteprise) parse SAML groups from assertion as array of strings</li> <li>🐞Fix (Enteprise) SAMLRequest in location header was URLEncoded twice, broke on some IdP</li> <li>🐞Fix (PRO/Enteprise) "cookiePass" works again, no more need for sticky cookies in load balancers!</li> <li>🐞Fix (PRO/Enteprise) fix redirect loop with JWT deep linking when JWT token expires</li> <li>🧐Enhancement (PRO/Enteprise) fix audit demo page CSS</li> <li>🧐Enhancement (Enteprise) SAML more configuration parameters available</li> <li>🚀New Feature (PRO/Enteprise) set ROR to debug mode (readonlyrest_kbn.logLevel: "debug")</li> </ul> 1.16.34 Wed, 08 May 2024 01:39:33 +0000 1.16.33 Released https://api.beshu.tech/changelog <h2>1.16.33</h2><ul> <li>🐞Fix(PRO/Enteprise) compatibility problems with older Kibana versions</li> <li>🐞Fix(PRO/Enteprise) compatibility problems with OSS Kibana version</li> </ul> 1.16.33 Tue, 07 May 2024 01:39:33 +0000 1.16.32 Released https://api.beshu.tech/changelog <h2>1.16.32</h2><ul> <li>🚀New Feature "kibanaIndexTemplate": default dashboards and spaces for new tenants</li> <li>🧐Enhancement Support for ES/Kibana 6.5.4</li> <li>🧐Enhancement Upgraded LDAP library</li> <li>🧐Enhancement (Enterprise) Now tenants save their CSV exports in their own reporting index</li> <li>🐞Fix(PRO/Enteprise) Support passwords that start and/or end with spaces</li> <li>🐞Fix (PRO/Enterprise) Now reporting works again</li> </ul> 1.16.32 Mon, 06 May 2024 01:39:33 +0000 1.16.31 Released https://api.beshu.tech/changelog <h2>1.16.31</h2><ul> <li>🧐Enhancement Support for ES/Kibana 6.5.2, 6.5.3</li> <li>🚧WIP: Laid out the foundation for LDAP HA support</li> </ul> 1.16.31 Sun, 05 May 2024 01:39:33 +0000 1.16.29 Released https://api.beshu.tech/changelog <h2>1.16.29</h2><ul> <li>🧐Enhancement Support for ES/Kibana 6.4.3</li> <li>🚀New Feature (PRO/Enterprise) configurable server side session duration</li> <li>🚀New Feature [LDAP] High Availability: Round Robin or Failover</li> </ul> 1.16.29 Sat, 04 May 2024 01:39:33 +0000 1.16.28 Released https://api.beshu.tech/changelog <h2>1.16.28</h2><ul> <li>🧐Enhancement Support for ES/Kibana 6.4.2</li> <li>🐞Fix (Enterprise) Multi tenancy: sometimes changing tenancy would not change kibana index</li> <li>🐞Security Fix (Enterprise/PRO) Avoid echoing Base64 encoded credentials in login form error message</li> <li>🧐Enhancement (Enterprise/PRO) Remove latest search/visualization/dashboard history on logout</li> <li>🧐Enhancement (Enterprise/PRO) Clear transient authentication cookies on login error to avoid authentication deadlocks</li> <li>🐞Fix: External JWT verification may throw ArrayOutOfBoundException</li> <li>🚧WIP: Laid out the foundation for internode SSL transport (port 9300)</li> </ul> 1.16.28 Fri, 03 May 2024 01:39:33 +0000 1.16.27 Released https://api.beshu.tech/changelog <h2>1.16.27</h2><ul> <li>🚀New Feature [JWT] external validator: it's now possible to avoid storing the private key in settings</li> <li>🧐Enhancement Support for ES/Kibana 6.4.1</li> <li>🧐Enhancement Rewritten big part of ES plugin documentation</li> <li>🧐Enhancement SAML Single log out flow</li> <li>🐞Fix (Enterprise/PRO) cookiePass works again, but only for Kibana 5.x. Newer Kibana needs sticky sessions in LB.</li> <li>🧐Enhancement (Enterprise/PRO) much faster logout</li> </ul> 1.16.27 Thu, 02 May 2024 01:39:33 +0000 1.16.26 Released https://api.beshu.tech/changelog <h2>1.16.26</h2><ul> <li>🐞 Fix (PRO/Enterprise) bugs during plugin packaging and installation process</li> </ul> 1.16.26 Wed, 01 May 2024 01:39:33 +0000 1.16.25 Released https://api.beshu.tech/changelog <h2>1.16.25</h2><ul> <li>🚀New Feature Users rule: easily restrict external authentication to a list of users</li> <li>🧐Enhancement Support for ES 5.6.11</li> <li>🐞Hot Fix (Enterprise/PRO) Error 404 when logging in with older versions of Kibana</li> </ul> 1.16.25 Tue, 30 Apr 2024 01:39:33 +0000 1.16.24 Released https://api.beshu.tech/changelog <h2>1.16.24</h2><ul> <li>🚀New Feature (Enterprise) SAML Authentication</li> <li>🚀New Feature Support for Elasticsearch and Kibana 6.4.0</li> <li>🚀New Feature Headers rule now split in headers_or and headers_and</li> <li>🧐Enhancement Headers rule now allows wildcards</li> <li>🚀New Feature (Enterprise) Multi-tenancy now works also with JSON groups provider</li> <li>🐞 Fix Multi-tenancy (Enterprise) incoherent initial kibana_index and current group</li> </ul> 1.16.24 Mon, 29 Apr 2024 01:39:33 +0000 1.16.23 Released https://api.beshu.tech/changelog <h2>1.16.23</h2><ul> <li>🧐Enhancement Support for Elastic Stack 6.3.1 and 5.6.10</li> <li>🚀New Feature (Enterprise) Custom CSS injection for Kibana</li> <li>🚀New Feature (Enterprise) Custom Javascript injection for Kibana</li> <li>🚀New Feature (PRO/Enterprise) access paths without need to login (i.e. /api/status)</li> <li>🐞Fix (PRO/Enterprise) Navigating to X-Pack APM caused hidden Kibana apps to reappear</li> </ul> 1.16.23 Sun, 28 Apr 2024 01:39:33 +0000 1.16.22 Released https://api.beshu.tech/changelog <h2>1.16.22</h2><ul> <li>🚀New Feature: map LDAP groups to local groups (a.k.a. role mapping)</li> <li>🐞 Fix (Elasticsearch) wildcard aliases resolution not working in "indices" rule.</li> <li>🧐Enhancement: it is now possible now to use JDK 9 and 10</li> <li>🐞 Fix (PRO/Enterprise) wait forever for login request (i.e. slow LDAP servers)</li> <li>🐞 Fix (PRO/Enterprise) add spinner and block UI if login request is being sent</li> <li>🐞 Fix (PRO/Enterprise) if user is logged out because of LDAP cache expiring + slow authentication, redirect to login.</li> <li>🐞 Fix (PRO/Enterprise) let RO users delete/edit search filters</li> </ul> 1.16.22 Sat, 27 Apr 2024 01:39:33 +0000 1.16.21 Released https://api.beshu.tech/changelog <h2>1.16.21</h2><ul> <li>🚀New Feature: Introducing support for Elasticsearch and Kibana v6.3.0</li> <li>🐞 Fix (Enterprise) multi tenancy - switching tenancy does not always switch kibana index</li> </ul> 1.16.21 Fri, 26 Apr 2024 01:39:33 +0000 1.16.20 Released https://api.beshu.tech/changelog <h2>1.16.20</h2><ul> <li>🧐 Enhancement: when login, forward "elasticsearch.requestHeadersWhitelist" headers. (useful for "headers" rule and "proxy_auth" to work well.)</li> </ul> 1.16.20 Thu, 25 Apr 2024 01:39:33 +0000