Changelog
4.15.0
New Features and Improvements
|
Introduce CSRF token mechanism in admin JSPs |
|
Authenticate against federated ArcGIS Server |
|
Provide properties to add flags "Secure" and "SameSite=Strict" to domain cookie |
|
Allow CORS configuration in application.properties |
|
Enable token authentication on ArcGIS Server services by default |
|
Don’t use JSESSIONID in URLs to transmit session ID |
Fixed Issues
|
AGS MapServer parent layer links not rendered correctly |
|
Classbreaks elements not rendered correctly on service directory HTML pages |
|
Server error 500 when navigating to enforcement point |
|
Context files written by installer do not contain "useHttpOnly=true" |
|
Layer metadata displays name of and links to forbidden layers |
|
ArcGIS token security allows ArcGIS Server with /arcgis substring only |
|
agstoken and token endpoint is available without token under some circumstances |