WUIC ← Back to downloads

Release Notes — WUIC Framework v1.7.22

Date: 6 October 2026 Previous published version: 1.7.21 (4 October 2026) Backend: .NET 10 + IIS / Linux nginx Frontend: Angular 21


This release aligns scaffolding across the four databases and completes the second part of the security review of OData, API tokens and reports. In short:

Metadata changes are applied automatically at startup. The end-to-end tests for OData, API tokens, reports, scaffolding, secure uploads, many-to-many and pivot passed on SQL Server, MySQL, PostgreSQL and Oracle, on clean installs on both Windows (IIS) and Linux, and on Oracle both version 21 and 23.


🗄️ Uniform scaffolding across databases

🔗 OData

🔐 API tokens

🛡️ Security

Best-effort hardening: SQL join fragments sent by the client require a superadmin, like where fragments; the pivot of a non-admin user starts from their visible rows (restriction, default filter, soft deletion) and no longer receives the query text; the report of a denied route answers 403 on MySQL, PostgreSQL and Oracle too; protected upload areas apply to every company in multi-company mode; with custom authentication the cookie is renewed on every request; trusted proxies can be configured with forwardedHeadersKnownProxies and forwardedHeadersKnownNetworks.

🐛 Notable bug fixes

📦 Updated packages

Package From To
WuicCore 1.7.21 1.7.22
Wuic.Webcore 1.7.21 1.7.22
WuicOData 1.7.21 1.7.22
RuntimeEfCore 1.7.21 1.7.22
Wuic.MySqlProvider 1.7.21 1.7.22
Wuic.PostgresProvider 1.7.21 1.7.22
Wuic.OracleProvider 1.7.21 1.7.22
wuic-framework-lib (npm) 1.7.21 1.7.22
  1. OData clients with large pages: a $top above 1000 now answers 400. Raise odataMaxTop if a client reads larger pages.
  2. OData clients that write: send Content-Type: application/json on POST and PATCH, otherwise the response is 415.
  3. Reports: on MySQL, PostgreSQL and Oracle a report whose data source matches no route answers 403. Check that existing reports open and, if needed, rename the data source after the route.
  4. API tokens in multi-company mode: a token of a user whose row has a company different from the token's is rejected. Check multi-company installations where user rows have an id_azienda different from the tenant's company.
  5. Behind a load balancer: set forwardedHeadersKnownProxies (or forwardedHeadersKnownNetworks) to the proxy addresses, so attempt limits count per client and not per proxy.
  6. Token roles: to restrict who can create tokens or write through OData, set apiTokenAllowedRoles and apiTokenWriteRoles from the AppSettings editor.