Version 2.27.0
NeuesteThis release improves browser error handling, Directory Connector integration, API localisation, claim processing, and platform security across FoxIDs.
User-facing error pages now keep technical diagnostics in the logs while showing clearer messages and additional troubleshooting identifiers. Directory Connector integrations can return a dedicated login_rejected response with an optional localised UI message, and selected FoxIDs culture settings are now forwarded to connected APIs.
The release also strengthens handling of claims returned by external APIs, reduces the amount of unauthenticated Control Client configuration exposed before login, tightens Content Security Policy (CSP), and improves health check responses by removing internal error details from HTTP responses while preserving diagnostics in the logs.
In addition, SAML metadata generation and Home Realm Discovery (HRD) behaviour have been corrected in specific edge cases.
New Features and Improvements
Improved Browser Error Pages
Technical diagnostics are kept in the logs while helpful user messages remain visible.
The Sequence ID, when available, is now shown alongside the Operation ID, making troubleshooting easier.
Directory Connector Login Rejection and API Localisation
Added support for login_rejected with an optional uiErrorMessage that is shown directly on the login form.
If the message is missing or blank, FoxIDs uses the existing general login error while keeping diagnostic details in the logs. Directory Connectors must verify the supplied credentials before returning login_rejected.
Directory Connector, External Password, and Extended UI now send the selected FoxIDs culture in the Accept-Language header, allowing connected APIs to return messages in the same language as the login page.
Improved Handling of Empty Claims from External APIs
FoxIDs now ignores claims with a missing, null, empty, or whitespace-only type or value in responses from:
- Claims API
- Extended UI
- External Login
- Directory Connector
When trace message logging is enabled, received claims are logged before filtering to support troubleshooting. Long trace messages are truncated.
Control Client Settings and Content Security Policy
Before login, the Control Client now returns only the configuration required to start the login process. Other settings require an authenticated session and access to the relevant tenant.
The Content Security Policy (CSP) has also been tightened to further restrict dynamic JavaScript execution and allowed content.
Improved Health Check Responses
Health check endpoints now return fixed messages and HTTP status codes without exposing internal error details.
Failed component checks continue to return HTTP 503, allowing monitoring systems to detect operational issues.
Bugs Resolved
SAML Metadata Generation After Metadata Import
Fixed an issue where SAML metadata generation could fail with SAML binding '0' not supported after metadata import.
Unspecified bindings now default to HTTP-POST, and existing zero values are normalised when configurations are loaded and saved. Explicitly configured bindings are preserved.
Correct Home Realm Discovery After Authentication Method Changes
Fixed a rare issue where an existing session could cause a local password prompt instead of the expected OpenID Connect redirect after changing an application's allowed authentication methods.
Home Realm Discovery (HRD) now resumes correctly when the previous Login session has expired or its cookie is missing.
- www.foxids.com/foxids:2.27.0 Eingeschränkt
- www.foxids.com/foxidscontrol:2.27.0 Eingeschränkt
- FoxIDs-2.27.0-linux-x64.tar.gz Eingeschränkt (169,0 MB)
- FoxIDs-2.27.0-win-x64.zip Eingeschränkt (190,6 MB)
- FoxIDs.DirectoryConnector.ActiveDirectory-2.27.0-win-x64.zip (49,2 MB)
- FoxIDs.CosmosDbToPostgreSQLMigrator-2.27.0-linux-x64.tar.gz Eingeschränkt (59,2 MB)
- FoxIDs.CosmosDbToPostgreSQLMigrator-2.27.0-win-x64.zip Eingeschränkt (58,4 MB)
- FoxIDs.MasterSeedTool-2.27.0-linux-x64.tar.gz Eingeschränkt (59,2 MB)
- FoxIDs.MasterSeedTool-2.27.0-win-x64.zip Eingeschränkt (58,4 MB)
- FoxIDs.SeedTool-2.27.0-linux-x64.tar.gz Eingeschränkt (59,2 MB)
- FoxIDs.SeedTool-2.27.0-win-x64.zip Eingeschränkt (58,4 MB)