06-10-2025 Quick Release V1
Summary
Important security and integration improvements release addressing security vulnerabilities in authentication logging and Intercom user provisioning, along with enhanced Intercom integration features and QR code functionality improvements. This release resolves 7 issues including 3 high-priority security fixes and 4 medium-priority enhancements ensuring improved system security and user experience.
Security
Auth Logging Removed from Slow Request Logs - Sensitive auth data is no longer logged in , preventing potential security vulnerabilities in production environments.
Unauthorised Intercom User Provisioning Fixed - Blocked unauthorised Intercom user creation via public pages. System now properly validates authentication before provisioning Intercom users, preventing security boundary violations (opt in only feature).
Intercom Integration
Staff Permissions Tracking Added - New Intercom attribute
cf_permissionstracks staff permission levels (Organisation/Project level access for Staff, Incident, Inspection, Contractor, and Risk modules). Support team can now quickly identify user access levels for better troubleshooting (opt in only feature).Improved User Provisioning Data - Enhanced staff provisioning to Intercom by including
user_idandentity_idfields. Improves user identification accuracy and support ticket routing (opt in only feature).
QR Codes
Visitor Sign-In Blocking Message Improved - Updated visitor sign-in message when sign-in is blocked via QR codes. Users now receive clear feedback when visitor access is restricted, improving user experience.
Multi-Identity Management
Null Value Handling Fixed in Multi-Identity Account Confirmation - Resolved type error in
MultiIdentityServicewhen processing null values during account confirmation. System now properly handles edge cases in multi-account user flows.