Release Notes — WUIC Framework v1.7.13
Date: 24 September 2026 Previously published version: 1.7.12 (20 September 2026) Backend: .NET 10 + IIS / Linux nginx Frontend: Angular 21
This version is mainly a security release. An audit of the entire API surface found methods and controllers reachable without login, or by a user without administration rights, and session data taken from the request instead of the server. All of them were closed, with an automated test for each case. Alongside them come the fixes that emerged from the PostgreSQL, MySQL and Oracle test cells, and the completion of multi-tenant support.
Upgrading is recommended for all installations. Read the final section "Recommended operational updates": a couple of behaviors change.
🛡️ Security
AsmxProxy calls closed by default. Every method reachable from /api/Meta/AsmxProxy/{service}.{method} now requires a valid session, except those declared anonymous. Three attributes in the WEB_UI_CRAFTER.Helpers namespace govern access:
[AsmxAnonymous]: method callable without login (login,me, translations, registration, password reset);[AsmxAdmin]: reserved for administrators (superadminrole);[AsmxFirstRun]: anonymous only during first run, then reserved for administrators.
The proxy also only invokes the service classes (MetaService, scaffolding, the application's services in WEB_UI_CRAFTER.ProjectData.Servizi): a fully qualified class name from another namespace is rejected.
Session verified everywhere. Best-effort hardening across all session handling:
- the
k-usercookie is validated on the server for the PostgreSQL and Oracle providers as well (token, expiry, session replaced by a new login); - the user for personal settings, menu and pivot is the one from the session, not the one indicated in the request;
- logout closes only its own session;
- in multi-tenant, the cookie's superadmin flag counts only if the database confirms it;
- the user list no longer returns session tokens and IPs.
The controller endpoints are aligned too:
- the
appsettings.jsoneditor, OData, upload and report check session and role on the server; - uploads stay within the record's folder;
- the designer accepts only the project's own
.csssheets; - the administration functions for webhooks, metrics and license are reserved for administrators.
Notifications. The REST and WebSocket endpoints for notifications are tied to the session's user: a request for another user gets 403 errors.auth.notification_forbidden. The WebSocket also works behind a reverse proxy, thanks to X-Forwarded-For.
Registration off by default. It only turns on with registrationEnabled=true in appsettings.json and never assigns an admin or superadmin role: default-role-id must point to an existing role with no administration rights.
First run.
- The password chosen in the wizard for the administrator is applied even if the name matches a user that already exists.
- The MySQL and Oracle first-run scripts no longer contain the automated tests' users.
- The dedicated
wuic_assistantuser (WUIC Assistant, MCP server) is created with a password generated for each installation, saved inscripts/mcp/wuic-assistant.credentials.json(excluded from git).
🤖 RAG and WUIC Assistant
/api/Rag/Chatrequires login;/api/Rag/Queryremains without login.- The
/api/Rag/MetadataDetaildetails that return data (sample_records,lookup_value,db_*) are reserved for administrators. - The LLM key configured on the server is never sent to a provider or address chosen by the caller.
- The
wuic-ragMCP server opens the session by itself when needed, withWUIC_USER/WUIC_PASSWORDor with thewuic_assistantuser's credentials file.
🏢 Multi-tenant
- Separate per-tenant caches for menu, table and column permissions, styles, available routes and data cache: a tenant no longer sees another tenant's entries.
- Propagating a table to the tenants invalidates the cache of every destination tenant, so the new entry appears immediately in the menus.
- Per-tenant notifications.
- PostgreSQL support.
🗄️ Database providers
- PostgreSQL: pagination, data cache, empty many-to-many filters, themes, dates with any host.
- MySQL: counts on distinct selects, system constraints, provider loading on Linux.
- Oracle:
- pagination, geographic filters (area and distance), record restriction by user and role, stored procedure names, booleans on numeric columns, grouping on long text, data cache;
- much faster translations: from 3-4.6 s to 0.3-0.7 s;
- correct number of updated and deleted rows;
- complete geographic data in the first-run scripts (all states and countries);
- order approval workflow demo;
- timeline column names aligned with the other databases.
- All: typed optimistic concurrency error (
409 errors.validation.optimistic_concurrency), single upload path, notification creation dates in UTC (automatic migration), correct role restrictions for users with multiple roles.
🐛 Notable bug fixes
- Record navigation via URL: moving from one record to another in edit or detail mode, the dialog reloads the new record instead of showing the previous one.
data-record-loadedgoes back tofalsewhen the dialog reloads the record, so automated tests do not read stale data.- Geographic filter waits for Google Maps to load before drawing.
- Scheduler list applies the template before reloading the data.
📦 Updated packages
| Package | From | To |
|---|---|---|
WuicCore |
1.7.12 | 1.7.13 |
Wuic.Webcore |
1.7.12 | 1.7.13 |
WuicOData |
1.7.12 | 1.7.13 |
RuntimeEfCore |
1.7.12 | 1.7.13 |
Wuic.MySqlProvider |
1.7.12 | 1.7.13 |
Wuic.PostgresProvider |
1.7.12 | 1.7.13 |
Wuic.OracleProvider |
1.7.12 | 1.7.13 |
wuic-framework-lib (npm) |
1.7.12 | 1.7.13 |
🔧 Recommended operational updates
- Custom services called before login: the methods of your services in
WEB_UI_CRAFTER.ProjectData.Servizithat must respond without a session need to be marked[AsmxAnonymous]; without it, they respond401 errors.auth.unauthenticated. - Registration: if you use it, set
registrationEnabled=trueand check thatdefault-role-idpoints to a role with no administration rights. wuic_assistantuser on existing installations: the old default password is no longer accepted. Set a new one from an administrator and write it intoscripts/mcp/wuic-assistant.credentials.json(or in the WUIC Assistant extension settings).- Oracle and MySQL installations with tutorials up to 1.7.12: check the users table and remove the users
wuic_e2e_admin,wuic_e2e_admin_2,wuic_e2e_admin_3andguest_1, if present. - Tools that read data from
/api/Rag/MetadataDetailor used/api/Rag/Chatwithout login: they now need to authenticate (for data, with an administrator).