WUIC ← Back to downloads

Release Notes — WUIC Framework v1.7.21

Date: 4 October 2026 Previous published version: 1.7.20 (1 October 2026) Backend: .NET 10 + IIS / Linux nginx Frontend: Angular 21


A release focused on security and data access. It closes the findings of a complete security review of the framework and brings OData to the same permission level as the CRUD. In short:

Metadata schema changes are applied automatically at startup. The features were verified with end-to-end tests on SQL Server, MySQL, PostgreSQL and Oracle, in the three enableCookieAuthentication modes.


🔐 Authentication and sessions

🔗 OData

🛡️ Security

Best-effort hardening across the whole surface: checks on the values that end up in queries (sorting, operators, aggregates, keys, numeric filters) aligned across the four providers; upload and report paths confined to their folders; administration functions (report designer, report removal and scaffolding, column reordering, restart, OData scaffold) reserved to the superadmin verified on the database; workflow emails only from users who can run the workflow; sample data of the AI-assistant tools only to the superadmin and never with credential columns; guards on users and roles bound to the table, not to the route name; licence public key embedded in the package.

📎 Upload

🚦 Errors

The user gets a translated message with a tracking code ("Copy code" button in the error dialog). The same code is stored with the full stack in _error__logs. SQL, stacks and internal messages reach only the superadmin. Translations of the new error messages are added automatically at startup.

🐛 Notable bug fixes

📦 Updated packages

Package From To
WuicCore 1.7.20 1.7.21
Wuic.Webcore 1.7.20 1.7.21
WuicOData 1.7.20 1.7.21
RuntimeEfCore 1.7.20 1.7.21
Wuic.MySqlProvider 1.7.20 1.7.21
Wuic.PostgresProvider 1.7.20 1.7.21
Wuic.OracleProvider 1.7.20 1.7.21
wuic-framework-lib (npm) 1.7.20 1.7.21
  1. Cookie mode: in production set enableCookieAuthentication to "signed" (or true); false is for development only.
  2. Several instances behind a load balancer: copy the same cookie-signing-key to every instance; with different keys a session is valid only on the instance that created it. Check in the log that the fingerprint matches.
  3. OData clients: clients that read $metadata without a session must authenticate, or set odataPublicMetadata=true. OData writes now run the CRUD triggers and logging and, on routes with logical delete, set the flag instead of deleting the row.
  4. md_service_apply_default_filter: deprecated. The default filter always applies, OData included.
  5. Licence: the machine fingerprint override is set only with the WUIC_LICENSE_MACHINE_FINGERPRINT environment variable; the license-machine-fingerprint-override and license-public-key-pem keys in appsettings.json are ignored.
  6. API tokens: to connect Power BI, Excel or scripts set apiTokensEnabled=true (and optionally apiTokenMaxLifetimeDays) from the AppSettings editor.