Skip to main content

v1.19.1

Release Summary​

FormKiQ 1.19.1 adds date attributes, site-scoped numbering sequences, branding configuration, and folder moves. The commercial platform adds Governance-mode immutable retention, reminder policies, user notifications, and expanded document reviews.

The release also improves document listing, folder permissions, artifact processing, authentication, and secure document delivery. Optional modules gain artifact output from document generation, PDF package generation, OpenSearch date attributes, and fixes for OCR, antivirus scanning, and watermarks.

Upgrade Notes​

  • Existing date-like STRING attributes remain STRING. The new DATE type uses dateValue or dateValues and normalizes values to UTC.
  • Completed document reviews now reject additional decisions with 409 Conflict. Applications should handle this response when another reviewer has already resolved the review.
  • SVG documents are downloaded as attachments, including when inline=true is requested.

FormKiQ Core (v1.19.1)​

Features​

  • #529 Added DATE document attributes with dateValue and dateValues, UTC normalization, schema validation and defaults, equality and range searches, and composite-key support.
  • #535 Added site-scoped numbering sequences for generating unique string attribute values with configurable patterns such as CONTRACT-{YEAR}-{SEQUENCE}.
  • #555 Added independent global and site-level branding configuration through GET and PATCH /system/configuration and /sites/{siteId}/configuration.
  • #534 Added Console installer support for extracting additional module ZIP files alongside the main Console.
  • #518 Added asynchronous folder moves through POST /folders/{indexKey}/moves.
  • #526 Added standard resourceType metadata for content documents (DOCUMENT), metadata-only dossiers (DOSSIER), and deep links (DEEP_LINK).

Updates​

  • Updated Console to 4.2.13 and changed Console installation downloads to https://artifacts.formkiq.com.
  • Added the Cognito domain URL to CloudFormation outputs.

Bug Fixes​

  • #516 Fixed MOVE actions colliding with existing document paths and causing documents to disappear from folder search results.
  • #518 Fixed folder listings and access checks to respect folder read permissions consistently.
  • #522 Fixed POST /entityTypes returning an internal server error when required fields such as namespace are missing; invalid requests now return validation errors.
  • #528 Fixed cognito:groups claim mapping to roles in the self-hosted API server with Keycloak.
  • #537 Fixed soft deletion failing when document attribute data exceeds DynamoDB index-key size limits.
  • #538 Fixed optional ENTITY schema attributes requiring a default entity when none should be necessary.
  • #539 Fixed missing document-date index keys for child documents and document updates, which caused documents to be omitted from listings.
  • #545 Fixed stale Console assets after CloudFront origin-path updates.
  • #551 Fixed GET /documents pagination stopping at a date boundary even when older documents remain.

Security​

  • #540 Added cryptographic validation of AWS SigV4 requests in the self-hosted API server, preventing forged authorization headers from granting document access. AWS API Gateway and Lambda deployments were unaffected by this issue.
  • #544 Redacted x-amz-security-token from Lambda request logs.
  • Redacted document contents and OAuth tokens from request logs.
  • #262 Forced SVG document downloads to use attachment disposition, including requests for inline delivery.
  • Added CloudFront response headers to prevent framing of the Console sign-in page.
  • Normalized password-reset errors and sanitized diagnostic output.

FormKiQ Platform (v1.10.1)​

Features​

  • #203 Added Governance-mode immutable retention backed by S3 Object Lock. Retention policies support RETENTION_ONLY and GOVERNANCE modes.
  • #235 Added ReminderPolicy preset entities, date-based reminder scheduling, document notification records, and scheduled notification-action processing. Reminder repeat intervals are optional.
  • #249 Added GET /userNotifications for document notifications addressed to the authenticated user through cc or bcc, including associated notification and action information.
  • #265 Added approval groups, notification blocks, and follow-up reviews to document reviews. Review decisions require membership in an assigned approval group when groups are configured.
  • #248 Added scheduled agreement-expiration processing for eligible Agreement dossiers in Active, Signed, or Renewal Review status.

Updates​

  • Added resource types to document activity records.
  • Added deployment configuration for Console branding and optional Console modules.
  • Added custom:email access-token mapping for Platform deployments using DEFINED sites or Okta/Entra SSO with Cognito V2 token generation. GET /userNotifications uses this claim to identify the recipient instead of the username.
  • Removed unused Contract Management preset entity definitions.
  • Updated the FormKiQ client dependency to 1.19.1 and upgraded vulnerable platform dependencies.

Bug Fixes​

  • #225 Fixed OPA attribute-policy validation for POST /documents and POST /documents/upload.
  • #252 Fixed document and artifact review listings returning internal server errors when review decisions exist.
  • #258 Made review decision submission atomic. Completed reviews reject subsequent decisions with 409 Conflict, including concurrent submissions.
  • Included artifact IDs when completing document workflows.
  • Fixed agreement-expiration attribute updates and restricted expiration processing to eligible agreement statuses.

Enhanced Search / Fulltext (v1.10.1)​

Features​

  • #239 Added DATE document attribute support in OpenSearch.

Bug Fixes​

  • #224 Fixed OPA attribute-policy validation for POST /queryFulltext.
  • Fixed document deletion to use the active OpenSearch alias target.
  • Corrected OpenSearch CloudWatch alarm configuration.

Antivirus (v1.7.1)​

Updates​

  • #236 Updated the ClamAV Lambda layer to 1.4.5.
  • #237 Extended virus-definition object expiration from 30 days to one year.

Bug Fixes​

  • #238 Fixed warm Lambda instances failing to refresh their cached ClamAV definitions after the intended 12-hour interval.

Document Generation Module (v1.2.2)​

Features​

  • #243 Added generated output as a new document artifact or a new version of an existing artifact using saveAsArtifact, saveAsArtifactId, and optional artifactCategory.
  • #257 Added PDF-source package generation, including appending or prepending other PDFs.

Bug Fixes​

  • #257 Unsupported generation source types now return 400 Bad Request instead of an internal server error.
  • Upgraded vulnerable document-generation dependencies, including FreeMarker to 2.3.35.

E-Signature Module (v1.2.1)​

Features​

  • #231 Added draft DocuSign envelope creation and POST /esignature/docusign/{documentId}/envelopes/{envelopeId}/views/sender for preparing recipients and signature fields in DocuSign's sender interface.
  • Added GET /esignature/docusign/{documentId}/envelopes/{envelopeId} for envelope status and recipient information.
  • #278, #279 Added on-demand reminders through POST /esignature/docusign/{documentId}/envelopes/{envelopeId}/reminders, with envelope-wide resend or selected eligible signers using recipientIds. Targeted responses report individual provider outcomes.
  • #280 Added POST /esignature/docusign/{documentId}/envelopes/{envelopeId}/void with a required voidedReason.
  • #256 Added configured DocuSign environment selection and request-level environment overrides.
  • #261 Added hybrid signing through embeddedRecipientStartUrl, allowing signing invitations alongside embedded recipient views.

Bug Fixes​

  • #260 Only envelope-completed callbacks mark signing as completed, after the signed PDF has been stored. Recipient callbacks no longer mark documents completed prematurely, and terminal statuses are protected from regression.
  • Redacted sensitive DocuSign log values.

OCR (v1.7.1)​

Bug Fixes​

  • #251 Preserved artifact IDs through OCR action requests and asynchronous Textract completion, allowing results and processing status to remain associated with the correct artifact.

Watermark (v3.0.3)​

Bug Fixes​

  • #242 Fixed watermarks drifting outside PDF page boundaries.
  • #241 Fixed text watermark positioning on PNG and JPG images.