WUIC ← Back to downloads

Release Notes — WUIC Framework v1.7.13

Date: 24 September 2026 Previously published version: 1.7.12 (20 September 2026) Backend: .NET 10 + IIS / Linux nginx Frontend: Angular 21


This version is mainly a security release. An audit of the entire API surface found methods and controllers reachable without login, or by a user without administration rights, and session data taken from the request instead of the server. All of them were closed, with an automated test for each case. Alongside them come the fixes that emerged from the PostgreSQL, MySQL and Oracle test cells, and the completion of multi-tenant support.

Upgrading is recommended for all installations. Read the final section "Recommended operational updates": a couple of behaviors change.


🛡️ Security

AsmxProxy calls closed by default. Every method reachable from /api/Meta/AsmxProxy/{service}.{method} now requires a valid session, except those declared anonymous. Three attributes in the WEB_UI_CRAFTER.Helpers namespace govern access:

The proxy also only invokes the service classes (MetaService, scaffolding, the application's services in WEB_UI_CRAFTER.ProjectData.Servizi): a fully qualified class name from another namespace is rejected.

Session verified everywhere. Best-effort hardening across all session handling:

The controller endpoints are aligned too:

Notifications. The REST and WebSocket endpoints for notifications are tied to the session's user: a request for another user gets 403 errors.auth.notification_forbidden. The WebSocket also works behind a reverse proxy, thanks to X-Forwarded-For.

Registration off by default. It only turns on with registrationEnabled=true in appsettings.json and never assigns an admin or superadmin role: default-role-id must point to an existing role with no administration rights.

First run.

🤖 RAG and WUIC Assistant

🏢 Multi-tenant

🗄️ Database providers

🐛 Notable bug fixes

📦 Updated packages

Package From To
WuicCore 1.7.12 1.7.13
Wuic.Webcore 1.7.12 1.7.13
WuicOData 1.7.12 1.7.13
RuntimeEfCore 1.7.12 1.7.13
Wuic.MySqlProvider 1.7.12 1.7.13
Wuic.PostgresProvider 1.7.12 1.7.13
Wuic.OracleProvider 1.7.12 1.7.13
wuic-framework-lib (npm) 1.7.12 1.7.13
  1. Custom services called before login: the methods of your services in WEB_UI_CRAFTER.ProjectData.Servizi that must respond without a session need to be marked [AsmxAnonymous]; without it, they respond 401 errors.auth.unauthenticated.
  2. Registration: if you use it, set registrationEnabled=true and check that default-role-id points to a role with no administration rights.
  3. wuic_assistant user on existing installations: the old default password is no longer accepted. Set a new one from an administrator and write it into scripts/mcp/wuic-assistant.credentials.json (or in the WUIC Assistant extension settings).
  4. Oracle and MySQL installations with tutorials up to 1.7.12: check the users table and remove the users wuic_e2e_admin, wuic_e2e_admin_2, wuic_e2e_admin_3 and guest_1, if present.
  5. Tools that read data from /api/Rag/MetadataDetail or used /api/Rag/Chat without login: they now need to authenticate (for data, with an administrator).