Version 1.4.X - Dashing Quetzal

Version 1.4.25

Release date : June 2026

Security

  • Update Envoy to 1.38.0

  • Update MongoDB to 7.0.34

  • Update Mysql to 8.4.9

  • Update Antmedia to 2.17.1

  • Update Netty to 4.2.13.Final

  • Update Jetty to 12.0.33

Version 1.4.24

Release date : March 2026

Bug fix

  • #1715: Milestone server state was not updated properly when a request is failing.

  • Modules osp-rights, osp-cli and osp-web use right certificate injected by dispatcher.

    This replace the right certificate certs/ca/modules_rights_rights.crt loaded from configuration with the one present on /run/secrets/modules_rights_rights.crt.

Security

  • Update MongoDB to 7.0.30

  • Update Openresty to 1.27.1.2-11

Version 1.4.23

Release date : February 2026

Bug fix

  • #1685: When alarms expiration was failing, it wasn’t recovering properly.

  • #1694: API service http client was not loading certificates provided by certs/external properly.

  • #1694: API service http client handle digest authentication properly.

  • #1348: Properly clean up WebSocket connections for every module to fix a thread leak.

Security

  • Update InfluxDB to 2.8.0

  • Update GraalVM Jdk to 25.0.2

  • Update docker-compose to 5.0.2

  • Update MongoDB to 7.0.29

  • Update Mysql to 8.4.8

Version 1.4.22

Release date : January 2026

Bug fix

  • #1688: Modify the configuration of a service tag ${{image-version}} was not replaced if ${{image-repository}} was missing.

  • #1685: Protect alarms archive process to avoid failures without automatic restart.

  • #1684: Load PMTiles with the user token correctly attached.

  • #1677: MongoDB will retry to initialize the replicat set if it fail during the initialization.

Security

  • Update Antmedia to 2.16.2

  • Update Keycloak to 26.4.7

Version 1.4.21

Release date : December 2025

Security

  • Update MongoDB to 7.0.28

Bug fix

  • #1679: When using Schematic with menu, when scrolling down before opening a menu, the position was wrongly computed.

Version 1.4.20

Release date : December 2025

Security

  • #1662: Protects assets and theme web resources with user token verification.

Bug fix

  • #1668 : In composer templates (playbooks), the composer now parses variablesFile- columns in CSV inventories correctly for FileRender tasks.

Version 1.4.19

Release date : November 2025

Security

  • Update Antmedia to 2.16.0

Bug fix

  • #1630 : Ensure that a long disconnect to rabbit will trigger an healthcheck failure.

  • #1640 : The dispatcher was not cleaning the empty directories inside the volume ops-runtime-configuration mounted on /osp/run/config/ particularly inside the folder tmp/modules.

    Note

    The content of the folder /osp/run/config/tmp/modules can be removed without risk when no aggregation is running.

  • #1641 : The dispatcher was not filtering the ‘module.service’ found inside the configuration, which could result in an aggregation error for module that didn’t exist.

  • #1642 : The web module will wait for the correct permissions before accepting a connection. This will prevent unexpected unauthorized values.

  • #1643 : Faster api key sync between Keycloak and web.

  • #1491 : The front-end Media Widget controls are fixed and less confusing. The front-end Media Widget now handles properly the navigation between different dashboard and restore properly the state of the player. The module media let’s you handle some of the properties contained in application settings via the antmedia-server.media file.

  • #1659 : In composer templates (playbooks), the composer now parses variablesFile- columns in CSV inventories correctly.

Minor features

  • #1647: Template variables supports complex objects and array. See Variable key access for more information.

  • #1660: Implemented partial disabled behavior support for IP-RCT clusters, allowing each IP-RCT instance to define which behaviors are turned off. Enables multiple concurrent environment connections.

Version 1.4.18

Release date : November 2025

Bug fix

Security

  • Update Mysql to 8.4.7

  • Update Openresty to 1.27.1.2-5

  • Update MongoDB to 7.0.25

Minor features

  • #1627: Script allow to ping target with the Network controller.

Version 1.4.17

Release date : October 2025

Bug fix

  • #1634: Messaging service close publishing properly which avoid blocking message. When the load increased, the delay to process message was increasing.

  • #1634: Collection websocket handles reconnects by resubscribing to current subscription

  • #1634: Widgets tracks collections subscriptions to perform cleanup upon widget destruction

Minor features

  • #1633: Add keyboard shortcut (CTRL+S) to save a Form that use a Deferred submit. This is disabled by default but can be enabled on the widget settings.

  • #1633: Add an alert displayed when attempting to leave a Form that still has unsaved changes and use a Deferred submit. This is disabled by default but can be enabled on the widget settings.

Version 1.4.16

Release date : October 2025

Bug fix

  • #1629: A resource leak was present when processing some request which lead to unexpected crash.

Version 1.4.15

Release date : October 2025

Minor features

  • #1623: Allow to selectively activate collection rights retrieval from web module when collection rights is used and let integrators change timeout and retry delays.

Bug fix

  • #1617: The internal Git server was accessible too early during dispatcher startup. This could lead to a corrupted configuration in rare cases.

Security fix

  • Update netty library to version 4.2.7.Final.

Version 1.4.14

Release date : October 2025

Bug fix

  • #1607: Allow to use username and password on the analytics module. This allow to remove the default InfluxDb token.

    The migration script will replace the default token if it is used to connect to InfluxDB.

  • #1610: On some case mongodb can fail to start due to a Name or service not known on modules_mongodb_osp-mongo-1. Adding the field hostname=${{service-name}} on the module.service file for mongodb solve the problem.

  • #1611: Improve the speed of the cache clean-up process when removing a large number of elements (>5,000 files) from the configuration.

  • #1612: Reduce JSON transformation logs failing to deserialize to trace level.

Documentation

  • #1613: Add a note on Customize logo about keycloak cache effect when changing the logo.

Version 1.4.13

Release date : October 2025

Bug fix

  • #1609: Prevent runtime exceptions in value pipeline transformation from terminating downstream operations. Whenever we handled a runtime exception, we set the value in error.

  • #1609: Protects preTransform and postTransform operations which might parse numbers from throwing runtime exceptions.

  • #1605: Clustered IP-RCTs handled alarms per IP-RCT rather than per cluster. This leads to unwanted behavior when an alarm occurs on one IP-RCT and the restoration occurs on another IP-RCT. Remote orders and SPT state setters also contact one IP-RCT after another.

  • #1603: Prevent runtime exceptions in observable subscriptions from terminating downstream operations. Adds guards around observable subscriptions so a thrown runtime exception does not cancel subsequent processing. This addresses cases where a module hits a configuration/device mismatch (e.g., OnVIF user not authorized).

Security fix

  • Update antmedia to 2.15

Version 1.4.12

Release date : October 2025

Bug fix

  • Change wrongly configured timeout for RabbitMq consumer. The minimum value should be 5 minutes.

  • #1600: Fix issues with severity columns export as csv files on widget table.

  • #1600: Fix order of String render columns to display contains as default operation.

  • #1598: Fix state of Collection table not correct after change from the url parameters

  • #1599: Fix issue with forms references not processed when validating schema properties for collection component options.

Minor features

  • #1601: Evaluation operation url supports array input.

  • #1600: Adding alarm and collection tables icon customizations options.

Documentation

Version 1.4.11

Release date : September 2025

Bug fix

  • Change wrongly configured timeout for RabbitMq consumer. On rare occasions, this has led to an unexpected crash of a module.

  • #1580 : Guarantee widget creation ordering to expose osp context reliably.

  • #1579 : Change collections.insert() to better handle data input before inserting the new document. This aims to have a better control of the data received when the data is transform between the script and the JAVA controller.

  • #1583 : The MongoDB health check was causing an infinite restart loop whenever the database needed to recover after a bad stop.

  • #1583 : The MongoDB indexes were recreated despite no changes being applied. This increased the load.

Security fix

Version 1.4.10

Release date : August 2025

Bug fix

  • #1563 : Modbus did not correctly check the range of addresses when reading bits from the input register. This resulted in an error message similar to Count [283] is greater than [125] for [INPUT_REGISTER].

  • #1567 : Expression language automatic conversion of var was causing problem when evaluation some condition.

    For example, neq(var(root.test.state), var(value))) with root.test.state=35 and value=36 was resulting to false.

    Warning

    This fix may alter implicit behavior. To avoid errors, it is strongly recommended that you asBoolean, asInteger, asDecimal and asText.

  • BACNet explorer now properly acknowledges messages sent by the front-end widget.

Minor features

Security fix

  • Update netty to 4.2.4.Final

Version 1.4.9

Release date : August 2025

Bug fix

  • #1553 : When a snackbar was configured, the result of an action performed via a menu was not displayed properly.

  • #1555 : Add the missing translation for the reload tooltip when the front-end configuration changes.

  • #1556 : Modbus module crashed when a Smooth was applied to a value that was in error.

  • #1557 : The Collection Table and Alarm Table were displaying the column summary button even though no summary aggregations were configured for any of the visible columns.

  • #1558 : When having multiple Form widgets, using the submit on one of any of the form would trigger the submit for every form present in the dashboard.

Security fix

  • Update Msyql to 8.4.6

  • Update Keycloak to 26.3.2

  • Update docker-compose to 2.39.2

  • Update mongodb to 7.0.22

Version 1.4.8

Warning

To ensure that the front-end link to the Keycloak admin console continues to function, you must manually update the security-admin-console client with the following values:

  • Home URL: /admin/onsphere/console/

  • Valid redirect URIs: /admin/onsphere/console/*

Release date : July 2025

Security fix

  • Update GraalVM to 24.0.2

  • Update OpenJDK to 21.0.8

Bug fix

  • #1510 : owner.collections was not generating a value when a new entry was inserted inside the collection.

  • #1543: The Keycloak admin console URL is now entirely lowercase and no longer contains capital letters.

  • The resolution of link between file with placeholder ${} was broken with the performance improvement. This was generating unexpected MISSING FILE ERROR during the aggregation.

  • #1547: Fix an issue where collections PULL updates would not remove anything when attempting to remove an object from an array.

  • #1547: Fix an issue where a CollectionTable would cancel too soon his subscription with a collection entry when editing this entry, leading to issues with further requests to the collections websocket.

  • #1549: Fix usage of convertNanoToDatetime template method that could throw an unchecked error depending on the given value.

  • #1536: Toolbar menu support touch interactions properly.

Minor features

  • #1537: Field tags on dashboard.web is not mandatory anymore.

  • #1546: alarms.AlarmBuilder() allow to override the serial and severity.

  • #1428: Dashboard edition can be disabled.

    The dashboard edition can be disable by setting the option theme.disableDashboardEdit on the file stack.cfg.

    ../../_images/dashboard-edit.png
  • Provides Base64/Base32/Base16 and URL encoding/decoding, charset conversion between various encodings, plus text normalization utilities for osp-scripts on Encoder.

Documentation

  • #1544: Added link to dynamic evaluation in the form prompt data description.

Version 1.4.7

Release date : July 2025

Bug fix

  • #1535: A Modbus failure during a read would generate an error for all values within the requested address range, even if only one address was invalid.

  • #1536: Touch interaction with sub menu expand/collapse them properly.

  • #1542: The ON_ALARM value was published without any changes or deletions. This was triggering callback needlessly.

Performance improvement

  • The aggregation process has been optimized. This improves the aggregation time by up to 4 times.

Minor features

  • Added support for additional image formats (PNG, JPG, ICO) alongside existing SVG for Keycloak’s background, logo, and favicon.

Documentation

  • #1540: Typos correction and small improvements in the Getting Started chapter.

Version 1.4.6

Release date : June 2025

Minor features

Bug fix

  • #1529: Fix severity column render when severity falls back to empty string following fix in #1522.

  • #1531: Disabled IP-RCT behavior ACKNOWLEDGE_ALARM properly dispatches to linked action.

  • Fix Object browser value display needing to be expanded twice to show value the first time the widget is used.

Security fix

  • Update mysql to 8.4.5

  • Update docker-compose to 2.37.2

Version 1.4.5

Release date : June 2025

New features

Schematic moveTo scale limitations - #1525

When using moveTo on the schematic widget, depending on the shape, it might zoom really close the shape, losing surroundings information.

We add an object with minScale and maxScale fields to be given to the moveTo interaction to solve this. See Context for more information.

Bug fix

  • #1518: Fix issues with collections historic entries that could have duplicated or missing updates differences.

  • #1518: Fix issue with form CheckboxGroup component where undefined values where not handled in some cases.

  • #1518: Change behaviour of conflicts resolution for forms because of multiple cases where conflict resolution was wrong or misleading. When an unresolvable conflict appears, the form data must be reloaded.

  • #1518: Fix issue where Collection form component had trouble when both settings multi and as object were used.

  • #1522: Fix severity column render when severity value is 0 no longer being shown.

  • #1524: API service was not supporting correctly the reference to another schema inside the one define in api-endpoint.ospp ResponseValidationConfiguration.

  • #1525: Fix schematic toggled layers status was not properly reflected on the toolbar.

Version 1.4.4

Release date : June 2025

Bug fix

  • #1514: Fix issue where schematic widget evaluation was now longer capable of sending actions.

  • #1514: Hide the close button from journal widget when used outside of the side panel in mobile version, as it is not applicable.

  • #1515: Fix issue where every entry in the collections history was inserted with an operation type as insert, even when the collection was updated.

  • #1515: Fix issue where CollectionTable form view was not able to load a previous historized version of a collection entry.

  • #1515: Fix issue where sometimes the selected form would be wrongly reset.

  • #1515: Fix issues with collections filters where filters on field _id was not possible.

Version 1.4.3

Release date : June 2025

Bug fix

  • A performance regression was found during the publication of messages.

  • #1508: Fix issue where collections could not be queried from a collection form component if the form was open in a menu prompt.

  • #1508: Fix issue where severity column render could show Unknown inside cell if the value was undefined.

Version 1.4.2

Release date : May 2025

New features

Schematic supports freehand - #1504

Drawing shapes with drawio plugin using the freehand tool (Arrange > Insert > Freehand) are now supported by the Schematic widget.

Bug fix

  • #1499: Keycloak was blocking during event processing. This created an unexpected delay in token generation, triggering a timeout.

  • #1501: Internally developed form component respects the visible flag. This allows SHOW and HIDE rules to be followed correctly.

  • #1505: Fix issues with how tables column width were calculated, making column resizing impossible.

  • #1505: Fix issue where a Journal table as a Form component or inside a alarm/collection table would make it impossible to store the changes to the table inside the browser local storage.

  • #1505: Fix equality check on collection form component, making the selected option not checked inside the options of the selector.

  • #1506: Moving a item used by a template was causing the aggregation to fail with a missing file error pointing to the old file location.

Security fix

  • Update envoy to 1.34.1

  • Update influxDB to 2.7.12

  • Update openresty to 1.27.1.2-1

Version 1.4.1

Release date : May 2025

New features

Schematic supports toggle layer visibility - #1495

It is possible to use toggleLayer(id) to show and hide layers with widget interactions. It avoids having to store state by providing layer visibility as toggleable.

Gauge value size can be updated - #1495

Gauge text value size can be set by integrators with valueSize settings. It supports CSS length dimension properties (pixels, em, vh, …).

Front-end - Keycloak forced reload interval - #1495

The environment variable VITE_KEYCLOAK_FORCE_RELOAD_TIMEOUT_OVERRIDE lets integrators define how long the front-end waits before forcing a reload when it can’t contact Keycloak.

  • Location: set in the module.service file of the front-end module.

  • Default value: 5 seconds.

  • Disable reload: assign 0 to deactivate the automatic page-reload mechanism altogether.

Bug fix

  • #1499: Keycloak was failing to generate token in time.

  • #1502: The Modbus value were not being republished correctly. This resulted in missing values on dashboards and potentially after a module restart.

  • #1503: The front-end was not loading the value on some case. This resulted in missing values on dashboards.

Version 1.4.0

Release date : May 2025

Warning

Please read carefully upgrade warning before upgrading to 1.4.0

Upgrading warnings

Alarm API script deprecation

The script API Alarms manipulation call to alarms.create() and alarms.insert() with the full list of alarm field is deprecated.

New parameters added to the alarm creation process will only be added to the new alarms.AlarmBuilder().

The new call uses an alarms.Alarm() build with the new alarms.AlarmBuilder() created with alarms.newAlarmBuilder().

OPC-UA configuration field name changed

In OPC-UA, the file device.opc-ua has been updated from ipAddress to hostname for greater precision.

Analytics password provider

In analytics, the file module.analytics use password provider for token field.

Onvif certificate client

The definition of Client Certificate , for files camera.onvif - controller.onvif - target.snmp - device.opc-ua and broker.mqtt are changed to support the usage of orchestrator secret and so have a new configuration. Run the patch of Composer to perform the update.

Alarm insertion timestamps default behavior changed

The action INSERT_ALARM now uses current time instead of epoch time if no timestamp is provided.

Output IP-RCT callback value changed

The IP-RCT output.ip-rct callbacks value triggers must be FIRE_AND_FORGET to avoid sending orders upon value retransmission. Run the patch #1408 of Composer to perform the update.

Script runtime environnement policy changed

The execution script environment now uses up-to-date configuration parameters from GraalVM. We have updated it to a more secure and faster default configuration.

If the scripts are using the following operations, the default configuration must be adjusted accordingly.

  • Environment variables are no longer accessible by default

  • Host files are no longer accessible by default

  • Process creation is no longer accessible by default

The other operations are not likely used by a script in the OnSphere context, but check the default configuration if you are using operation outside the standard OnSphere script API.

All fields are configured securely by default, which may cause errors in current script execution. To avoid issues, you can disable all settings in the module.scripts configuration file.

MongoDB version changes

MongoDB has been upgraded from 6.0 to 7.0 with 1.4.0 release.

Before upgrading to 1.4.0, the feature version must be set to 6.0.

The current feature version can be checked by running the following command inside the MongoDB container:

$ mongosh --eval "db.adminCommand({getParameter:1,featureCompatibilityVersion:1})"
{ featureCompatibilityVersion: { version: '5.0' }, ok: 1 }

Setting the feature version can be done with:

$ mongosh --eval "db.adminCommand({setFeatureCompatibilityVersion:'6.0'})"

After the update, when OnSphere is stable, the feature version can be updated to the current version:

$ mongosh --eval "db.adminCommand({setFeatureCompatibilityVersion:'7.0'})"

RabbitMq queue management change

The RabbitMq queue configuration was changed to avoid keeping queues alive when no modules used them. The upgrade is transparent but the stack will not work properly until all modules are updated.

Warning

To rollback to the previous version, the queue must be deleted manually.

You can list and delete the queues by running the following commands on the RabbitMq container.

rabbitmqctl -q -s list_queues name
rabbitmqctl delete_queue <queue-name>

You might need to run the deletion multiple time if the modules are not at the same version.

After the rollback, we recommend to restart all modules.

Documentation

  • Restored the previous documentation for action, which was lost during the migration to Sphinx. This section will be rewritten soon.

  • Fix: Updated the URL for the official documentation to the latest link, correcting issues with fields like “anyOf/oneOf/allOf” in JSON schema.

  • Corrected multiple typos and added further details in multiple sections.

  • Minor change in the example Manage the maintenance state of alarms to be more understandable.

  • The json-schema now include the default value in the description to help the integration process.

  • The documentation of widget context and extraction of data is improved.

  • OPC-UA and BACnet documentation are updated.

  • A new chapter is available for user authentication and user authorization.

  • Standardize the prerequisite section for each example.

  • The frontend page is currently being reorganized.

  • The Value history / analytics documentation is totally reworked.

  • Enhance the styling of capabilities tables by setting fixed percentage-based column widths.

New features

Introduction of new video module osp-media

Warning

Beta version This feature is currently in beta. It may change in a future version without prior notice. See the Beta Features page for the full list of beta features and their planned release. If you’re using this feature, we encourage you to share your feedback to help with the evaluation process.

Deprecation Notice: The osp-video module will be soon deprecated and will be removed by the end of 2026. Moving forward, we are adopting a more efficient and standardized approach for video streaming using HLS (HTTP Live Streaming).

For details on the new media module, see how to use the new media module.

New reports template method to fetch a BACnet device - #1366

New template method allows retrieving a BACnet device from a FTL report.

Learn more about templates methods.

Add attachments to email notifications - #1381

Email notification can now hold attachments, sending them alongside the email. Currently, this feature is only available when using notification from scripts.

Learn more about notification attachments.

Generate report from a script - #1381

Reports can now be generate from a script. Result of the generation can then be used to define attachments for a email notification.

Learn more reports here.

Adding generators to automatically fetch the necessary data for a report - #1381

New generators entity allows defining multiple data sources that will be automatically retrieved by OnSphere and sent to the report.

Learn more about generators here.

Adding new menu extract transform option as numbers, integers and decimal - #1379

New accepted type as with values number, integer and decimal to extract and transform input in a menu evaluation.

Form Action component to evaluate and run actions - #888

Newly added form component Action allows evaluating and run an action.

More information on this on the form component documentation.

Toolbar selects (forms, analytics, …) can be disabled - #1407

Any toolbar selects supports disabled flag in order to properly deactivate user selection.

Should only option be selectable, the select no longer is shown (either filtered by include/exclude options or rights).

Form support Severity picker - #1406

Newly added form component Severity allows selecting alarms severity.

More information on this on the form component documentation.

Restore deleted elements from a collection - #1376

New request restore to re-enable previously deleted elements. The only elements that can be restored are the one that is still present in the database but have been “deleted”, meaning their __is_active flag is set as false.

You can now have a dashboard with only deleted elements in a collection table and add a menu to restore any one of them. Look at this example for more detail on this.

Collections filter to target deleted elements - #1376

Add new collection filter scope to define if the filter is applied to:

  • ONLY_ACTIVE: only the active elements (default)

  • ONLY_INACTIVE: only the inactive elements (after delete)

  • ALL: every element

This new feature allows querying elements of a collection that were deleted, which was previously impossible since every request would only target active elements.

This could allow displaying a Collection table showing deleted elements. Look at this example for more detail on this.

Validation path is now an absolute path clickable URI.

  • The path returned by the git-push command can now be configured to yield a URI instead of a relative path. See configuration.

  • The logging now shows only the final status, omitting internal details like thread and log level and origin.

Support of certificate secret

It’s now possible to use an orchestrator secret for storing certificates of the following files :

See detailed configuration guide for details.

Composer - Improve validator

  • Error files are now clickable URI links.

Composer - Remove the validation of files in background

Previously we had a mechanism of validation of format of not opened files, this process was costly for the host system and provides no real utility since we had the new validation command. This feature was removed.

OPC-UA - client certificate auth

  • In client certificate auth, if no certificate is supplied, the default module certificate will be used.

OPC-UA - multiple timer configuration

It’s now possible to configure the keep-alive timer and connection timer see device.opc-ua for information. keep-alive default value comes from 5 to 15 seconds

OPC-UA - unencrypted messaging

It is now possible to use unencrypted messages for debugging purposes in OPC-UA devices. For details, see documentation.

Alarms and Collections placeholder for filter - #1399

The alarm and collections filters allow setting placeholder inside the filter.

For alarms, this is available on filter.alarms and the filter generated by the pre-insertion and action-rule.

For collection, this is available on schema.collections and on all query generated from the scripts.

See Filter placeholder for more information.

IP-RCT - Prevent criteria state to change when handling older events - #1408

IP-RCT module handles events with ordering by default. Should an older event occurs, the module acknowledges it but does not reflect it to the state.

This feature can be disabled by using disableEventOrdering on owner-criteria.ip-rct.

IP-RCT - Allow disabling IP-RCT behavior - #1118

Communication with IP-RCT can be partially or completely disabled with disabledIpRctBehavior server.ip-rct.

It is possible to disable:

  • Alarm handling

  • Alarm acknowledgement

  • Remote order to be sent

  • Administrative state management

IP-RCT - Alarm owners can handle more than one alarm type - #1412

It is now possible to handle more than one alarm type with owner-alarm.ip-rct.

This allows handling, for example, with a linked action, ALARM as well as ATS state.

Warning

Payload may change depending on the alarm types and should be handled directly by called linked action.

Script - Improve security settings

The configuration of the virtual machine used for script execution has been updated. For more details, refer to the updated change warning.

Alarms, Collections, Reports and Maps - Allow the definition of unique indexes

The option unique, with a default to false, was added the index configuration to :

Warning

Setting an index to unique will cause MongoDB to refuse new insertion if the index match an already present element.

Form submits can be disabled - #1410

It is now possible (following #888) to disable form submit in form.web. This is done by not providing a value to submit.

Form access rights improvements - #1410

When a user has no write capability on a schema.ospp or form.web, the UI reflects this by disabling collection creation, edition and provide data as read only.

Allow access to the rabbitmq management interface

The rabbitmq management interface is now accessible with https://<stack-hostname>/rabbit/. If the admin access is enable on the front-end.

The /rabbit url can be changed by setting :

Warning

To enable the login, the secret admin-pwd and admin-user must be set for the service rabbit.

Keycloak configuration allows inject data from ENV or secrets - #1436

The Keycloak configuration allows defining elements from a secret or an environment variable. This is available for the realm.keycloak, users.keycloak, groups.keycloak, identityProviders.keycloak and federations.keycloak files. See Variable substitution for more information.

MongoDb username and password can be defined outside of serverUrl

The modules osp-alarms, osp-collections, osp-maps and osp-reports allow defining the username and password to connect to the database outside of the serverUrl with the field credential.

For example:

"mongoDbConfigurationEntity": {
  "serverUrl": "mongodb://modules_mongodb_osp-mongo-1",
  "databaseName": "collections"
  "credential": {
    "username": "<username of the module>"
    "authenticationDatabase": "<database where the user are defined>",
    "password": {
      "type": "SECRET",
      "secretPath": "<path to the secret containing the password>"
    }
  }
}

Specify table severity and acknowledgement per view - #1429

Previously, alarm tables (AlarmTable, AlarmHistoryTable) only displayed row severity and acknowledgement by their respective column. It is now possible to specify additionalData content to show a severity or acknowledgement per view.

This allows users to show a table with specific color coding which might change when updating view.

Table column options type definition - #1429

Previously, tables (AlarmTable, AlarmHistoryTable, CollectionTable) supported options which were not fully checked and described.

We now provide help and description of each option and how to use it.

Table columns filter options type definition - #1447

Improve column filter definition. Previously, depending on render type, filter was fixed. Now it is possible to define which filter is used.

Available filters are:

  • STRING filter column content and handle it as a string

  • NUMBER filter column content as a number

  • BOOLEAN filter column content as a boolean

  • LIST filter column content as element list

  • COLLECTION filter column content as collection element list

  • SEVERITY filter column content as severity

  • TIMESTAMP filter column content as timestamp

Depending on the filter type, different filter operations are available.

Analytics - Change default configuration

  • The HTTP port 8086 is no more exposed by default in module.service file.

  • The token for authenticating on InfluxDB is using password provider method to allow to use secret instead of clear password.

PDFViewer widget loading PDF from configuration - #1421

The PDF Viewer widget can now load PDF from the configuration if they are defined as a module web resource.

External URLs also work but may require some extra work for the widget to be able to load the desired PDF.

The visual aspect of the widget was also reworked. Please look into the PDF Viewer widget documentation for more information about this widget.

Bacnet - Output can be controlled to relinquish the priority

The output.bacnet now support a boolean control value to relinquish the priority used by OnSphere. See Writing values for more information.

Offline maps supports with Protomaps - #1440

Leveraging MapLibre and Protomaps, it is now possible to host map tiles locally without online access. It uses MapLibre library to show maps to users.

See Offline map display standard points on map example to understand how to use it.

Beta features

Warning

Beta version This feature is currently in beta. It may change in a future version without prior notice. See the Beta Features page for the full list of beta features and their planned release. If you’re using this feature, we encourage you to share your feedback to help with the evaluation process.

Audit trail log

Audit users interaction with the system. The following list show in detail all recorded interactions:

  • Logs all user logins.

  • Tracks all data access by users, recording which data is viewed or modified.

  • Monitors any configuration changes made by users.

  • Provides visibility into user actions for improved auditing and security.

More information on feature documentation.

New Discovery widget for BACnet devices - #1366

New Discovery widget is added to fetch data from BACnet devices and display their objects/properties.

Learn more about this widget here.

Keycloak - embedding additional data in auth Token within scripts

A new feature has been introduced that enables scripts to enhance authentication tokens. This functionality allows for dynamic scenarios, such as incorporating authentication groups from a data collection or retrieving this information via an external REST API. It provides the flexibility to configure access rights based on collections or fetch these details in real-time from an API.

See enrich authentication token for details.

Access external data (Rest API) from the front-end - #1425

The API service allow a better access to external API.

It is available for the following part:

  • Frontend: To access external data on the context for the menu, form, …

  • HTTP requests

Bug fix

  • Keycloak theme was not configured properly during a new deployment.

  • #1380 : The VSCode composer’s autocompletion was replacing existing content instead of inserting the new part.

  • #1318 : Fix some crash of the osp-composer at the opening

  • #1371 : The license validator was disabled due to issues occurring in certain specific cases

  • #1387 : The reconnection of the OPC-UA device was incorrectly implemented.

  • #1387 : The OPC-UA with certificate client authentication is now working as expected.

  • #1387 : The OPC-UA was not closing correctly the session when stopping nicely.

  • #1400 : RabbitMq channel were not handle properly on some cases.

  • #1401 : Internal control messages use a now sensible TTL and are filtered by module.

  • #1401 : RabbitMq will stop processing new messages if the free disk space is less than 5GB (on the volume osp-rabbitmq). This can be changed in rabbitmq.conf. The configuration patch #1401 will automatically update the RabbitMq configuration.

  • #1405 : Avoid forms based on similar schema to load partially (specifically initial value)

  • #1410 : Disable form toolbar when none is provided

  • #1410 : CollectionTable filtering for filter and view (with include and exclude) will no longer match parts of ID and will strictly match selected IDs

  • #1371 : The license validator was disabled due to issues occurring in certain specific cases

  • #1411 : Allow preemptive authentication on HTTP requests.

  • #1412 : Output for Menus and toolbars navigate support external URLs.

  • #1430 : Check for minimal duration of bucket (one hour)

  • #1431 : Fixing an issue where chart widget analytics selector would not react as expected when selecting a value, making them disappear.

  • #1899 : Module osp-video sometimes failed to initialize Kurento client, which implied a manual module restart.

  • #1434 : The option to disabling the export bouton in alarmes tables was missing. It is now available.

  • #1429 : as: "boolean" handles number and string content properly (parse content).

  • #1429 : Report generation outputs user parameters.

  • #1447 : Upon Tables widget column changes, remove non-matching column filter.

  • #1447 : Exporting Tables widget handles TAG with string content.

  • #1454 : The module web was running multiple times at the same time (replica n/1).

  • #1459 : Reports couldn’t load images and font assets anymore after upgrade of PDF generation library.

  • #1445 : Object browser widget was not handling correctly response from values search request.

  • #1474 : Fixing an issue where values owned by variables might not be updatable by a ValueSubscription widget without restarting the osp-configuration-dispatcher module.

  • schema.web validation was not handling multi level correctly for the field.

  • #1483 : Add missing formatterExport to table TIMESTAMP options.

  • #1488 : Composer extension was not loading correctly on VSCode startup.

Security fix

  • #1196 : Keycloak admin console can be blocked by setting ALLOW_ADMIN_ACCESS to false on the module.service of the front-end.

    Warning

    The default value is true to avoid potentially breaking current installation.

    Warning

    If you have a proxy in front of OnSphere, we recommend to block /auth/admin.

  • #1389 : The rights are now signed before being passed to the other module. This ensures that the rights are not tampered with and come from the correct source.

  • Keycloak update to 26.0.7

  • React update to 19.0.0

  • Material UI update to 6.2.0

  • JSON forms update to 3.4.1

  • AJV update to 8.6.1

  • i18next update to 24.1.0

  • JSON path plus update to 10.2.0

  • MapboxGL update to 3.8.0

  • React PDF update to 9.1.1

  • Migrade from React SizeMe to React Resize Detector

  • Remeda update to 2.17.4

  • TypeScript update to 5.7.2

  • Update docker-compose to 2.33.1.

  • Update influxDB to 2.7.11.

  • Update envoy to 1.32.3.

  • Update logback to 1.5.13.

  • Update jetty to 12.0.16.

  • Update freemarker to 2.3.34.

  • Update graalvm to 23.

  • Increase default ssh key size to 4096.

    Warning

    The key is not update automatically. To update it, you need to remove the secrets ssh_host_rsa_key.key and ssh_host_rsa_key.pub. The dispatcher will regenerate them.

Configuration changes

External modules update

  • MongoDb was upgraded to the version 7.