Changelog

4.16.6

New Features and Improvements

SECMAN-2025

Block WFS request if no service parameter with value 'WFS' is provided

Fixed Issues

SECMAN-1093

SOAP QueryRelatedRecords request is not authorized correctly when SourceTableID points to layer

SECMAN-1122

Export Web Map Task fails if JSON contains null values

SECMAN-1332

Allow to create spatial obligations for protected services that require basic authentication

SECMAN-1545

GetFeatureInfo on WMS returns exception for disallowed areas

SECMAN-1762

Wrong WMS ServiceException code when requesting non-existing layers

SECMAN-1798

Installer option "Drop old database tables" does not work correctly on Oracle 18.4 XE

SECMAN-2001

Required database grant not documented

SECMAN-2005

Error when querying metadata from AGS Map Service

SECMAN-2007

Improve XSS protection means

SECMAN-2009

Prevent NPE if protected server does not provide a response body

SECMAN-2011

WMS should pass on mandatory parameters

4.16.5

New Features and Improvements

SECMAN-543

Allow for configurations of IP ranges in addition to hostnames

Fixed Issues

SECMAN-1714

INSPIRE Feature Download Service: GetFeature does not return features

SECMAN-1885

WFS GetFeature XML request fails when defining custom namespace prefix

SECMAN-1928

Logging interceptor logs wrong timestamps

SECMAN-1956

WFS DescribeFeatureType request fails if no namespace is defined within TYPNAME parameter

SECMAN-1961

Multiple users locked after failed logins by a single user

SECMAN-1971

Web app might fail to start because of API incompatibility

4.16.4

Fixed Issues

SECMAN-765

Printing via protected printing service from ArcGIS Desktop fails

SECMAN-1325

WMTS REST endpoint cannot be secured

SECMAN-1407

Installation folder is missing postinstall\sql\ssosession-db and postinstall\sql\upgrade folder

SECMAN-1903

Wrong SRS URN used if spatial filter added to WFS requests

SECMAN-1914

Cannot create policy for REST-only WMTS

4.16.3

New Features and Improvements

SECMAN-1896

Improve caching of spatial restriction geometries defined for WFS

Fixed Issues

SECMAN-979

WFS GetFeature request with BBOX fails when spatial obligation exists in different SRS

SECMAN-1538

Spatial obligation for WFS fails with XtraServer WFS 2.0

SECMAN-1895

Spatial obligation may not get enforced on WFS

4.16.2

New Features and Improvements

SECMAN-1470

Trim whitespaces when saving LDAP attribute value mappings

SECMAN-1875

Describe configuration for LDAP-S

Fixed Issues

SECMAN-1624

AGS feature services layer metadata may get wiped out on update

SECMAN-1802

Secured UMN Mapserver WFS 2.0.0 does not return feature types for version 1.x.0

SECMAN-1836

Installation fails on Linux if installation path contains spaces

SECMAN-1848

Printing doesn’t work with SSO-secured services when using subfolder in context path for WSS

SECMAN-1849

Attribute fields with "/" get replaced by URLs in ArcGIS Server query response

SECMAN-1851

WFS GetFeature request via HTTP POST fails

SECMAN-1860

Cannot create protected service for WMS when service URL contains query parameters

SECMAN-1870

No attribute values displayed when querying service with joined tables

SECMAN-1871

Map preview not displayed if HTTPS with untrusted certificate is used

SECMAN-1876

Error message when opening a newly added layer

SECMAN-1880

FeatureServer may expose forbidden features

SECMAN-1881

ArcGIS user account locked when using wrong password in enforcement point configuration

SECMAN-1884

User matching a role defined by dn value not displayed

4.16.1

New Features and Improvements

SECMAN-1830

Redirect to profile page if /register or /pwrecovery is accessed by authenticated user

Fixed Issues

SECMAN-823

ImageServer based WMS cannot be requested

SECMAN-1083

Policy Administration does not allow to fetch resources from AGS Token secured WMS, WFS, and WCS services

SECMAN-1368

Logout does not clear IdP cookies

SECMAN-1801

Wrong URL used when displaying queryRelatedRecords results on MapServer request

SECMAN-1803

Broken umlauts in installer

SECMAN-1808

WFS request fails when filter expression obligation is defined

SECMAN-1809

MapServer may allow access to restricted features

SECMAN-1810

Failure when parsing error response from ArcGIS Server >= 10.5

SECMAN-1812

Login with old password is possible after password change for a short time

SECMAN-1831

Spatial obligation not enforced on WFS point or line feature types

4.16.0

New Features and Improvements

SECMAN-1723

Compliance with ArcGIS Enterprise 10.7

SECMAN-1760

Compliance with ArcGIS Enterprise 10.7.1

SECMAN-1779

Ensure that ArcGIS Server SOAP URL is used when creating a protected service

SECMAN-1791

Remove servlet container selection dialog from installer

SECMAN-1795

Render URLs to ArcGIS Server services in policy and resource as clickable HTML links

SECMAN-1796

Support Java 11

Fixed Issues

SECMAN-954

URL replacement in HTML REST browsing output fails if ArcGIS Server residing on the same host like sec.man

SECMAN-1153

"Content-Disposition" header is not forwarded

SECMAN-1358

'resultRecordCount' parameter not respected for MapServer queries

SECMAN-1509

Improve salutation when sending email when user’s gender is not set

SECMAN-1696

URL replacement in ArcGIS Server HTML REST browsing output fails

SECMAN-1701

XtraServer authorization header is missing when accessing external resources

SECMAN-1703

security.manager can’t handle AGS labelExpression in some cases

SECMAN-1739

Accessing secured JSON file via URL protection increases CPU load dramatically

SECMAN-1740

Protected Feature Service returns "Access denied to some of the requested features" on /applyEdits

SECMAN-1742

Cannot navigate from a role to a user having that role

SECMAN-1754

Use '…​' instead of <…​> in sec.man logs to avoid incorrect HTML rendering in the AGS logger

SECMAN-1755

Features are shown outside of spatial restriction

SECMAN-1756

Button "Show Users" does not show up in role administration UI

SECMAN-1757

StoredQuery request fails

SECMAN-1761

WFS GET request fails when DEBUG log enabled

SECMAN-1764

Fix typo in properties name error.common.exceute.cmd

SECMAN-1776

Cannot create policy sets for AGS services containing umlauts in service name

SECMAN-1777

Fix typos in property names license.generic.error.update.decription and wmts.error.update.decription

SECMAN-1778

Special chars not encoded in AGS HTML browsing

SECMAN-1788

HTML product link points to an invalid location

SECMAN-1794

/query fails in HTML browsing