v1.19.1
Release Summary
FormKiQ 1.19.1 adds date attributes, site-scoped numbering sequences, branding configuration, and folder moves. The commercial platform adds Governance-mode immutable retention, reminder policies, user notifications, and expanded document reviews.
The release also improves document listing, folder permissions, artifact processing, authentication, and secure document delivery. Optional modules gain artifact output from document generation, PDF package generation, OpenSearch date attributes, and fixes for OCR, antivirus scanning, and watermarks.
Upgrade Notes
- Existing date-like
STRINGattributes remainSTRING. The newDATEtype usesdateValueordateValuesand normalizes values to UTC. - Completed document reviews now reject additional decisions with
409 Conflict. Applications should handle this response when another reviewer has already resolved the review. - SVG documents are downloaded as attachments, including when
inline=trueis requested.
FormKiQ Core (v1.19.1)
Features
- #529 Added
DATEdocument attributes withdateValueanddateValues, UTC normalization, schema validation and defaults, equality and range searches, and composite-key support. - #535 Added site-scoped numbering sequences for generating unique string attribute values with configurable patterns such as
CONTRACT-{YEAR}-{SEQUENCE}. - #555 Added independent global and site-level branding configuration through
GETandPATCH /system/configurationand/sites/{siteId}/configuration. - #534 Added Console installer support for extracting additional module ZIP files alongside the main Console.
- #518 Added asynchronous folder moves through
POST /folders/{indexKey}/moves. - #526 Added standard
resourceTypemetadata for content documents (DOCUMENT), metadata-only dossiers (DOSSIER), and deep links (DEEP_LINK).
Updates
- Updated Console to 4.2.13 and changed Console installation downloads to
https://artifacts.formkiq.com. - Added the Cognito domain URL to CloudFormation outputs.
Bug Fixes
- #516 Fixed
MOVEactions colliding with existing document paths and causing documents to disappear from folder search results. - #518 Fixed folder listings and access checks to respect folder read permissions consistently.
- #522 Fixed
POST /entityTypesreturning an internal server error when required fields such asnamespaceare missing; invalid requests now return validation errors. - #528 Fixed
cognito:groupsclaim mapping to roles in the self-hosted API server with Keycloak. - #537 Fixed soft deletion failing when document attribute data exceeds DynamoDB index-key size limits.
- #538 Fixed optional
ENTITYschema attributes requiring a default entity when none should be necessary. - #539 Fixed missing document-date index keys for child documents and document updates, which caused documents to be omitted from listings.
- #545 Fixed stale Console assets after CloudFront origin-path updates.
- #551 Fixed
GET /documentspagination stopping at a date boundary even when older documents remain.
Security
- #540 Added cryptographic validation of AWS SigV4 requests in the self-hosted API server, preventing forged authorization headers from granting document access. AWS API Gateway and Lambda deployments were unaffected by this issue.
- #544 Redacted
x-amz-security-tokenfrom Lambda request logs. - Redacted document contents and OAuth tokens from request logs.
- #262 Forced SVG document downloads to use attachment disposition, including requests for inline delivery.
- Added CloudFront response headers to prevent framing of the Console sign-in page.
- Normalized password-reset errors and sanitized diagnostic output.
FormKiQ Platform (v1.10.1)
Features
- #203 Added Governance-mode immutable retention backed by S3 Object Lock. Retention policies support
RETENTION_ONLYandGOVERNANCEmodes. - #235 Added
ReminderPolicypreset entities, date-based reminder scheduling, document notification records, and scheduled notification-action processing. Reminder repeat intervals are optional. - #249 Added
GET /userNotificationsfor document notifications addressed to the authenticated user throughccorbcc, including associated notification and action information. - #265 Added approval groups, notification blocks, and follow-up reviews to document reviews. Review decisions require membership in an assigned approval group when groups are configured.
- #248 Added scheduled agreement-expiration processing for eligible Agreement dossiers in
Active,Signed, orRenewal Reviewstatus.
Updates
- Added resource types to document activity records.
- Added deployment configuration for Console branding and optional Console modules.
- Added
custom:emailaccess-token mapping for Platform deployments using DEFINED sites or Okta/Entra SSO with Cognito V2 token generation.GET /userNotificationsuses this claim to identify the recipient instead of the username. - Removed unused Contract Management preset entity definitions.
- Updated the FormKiQ client dependency to 1.19.1 and upgraded vulnerable platform dependencies.
Bug Fixes
- #225 Fixed OPA attribute-policy validation for
POST /documentsandPOST /documents/upload. - #252 Fixed document and artifact review listings returning internal server errors when review decisions exist.
- #258 Made review decision submission atomic. Completed reviews reject subsequent decisions with
409 Conflict, including concurrent submissions. - Included artifact IDs when completing document workflows.
- Fixed agreement-expiration attribute updates and restricted expiration processing to eligible agreement statuses.
Enhanced Search / Fulltext (v1.10.1)
Features
- #239 Added
DATEdocument attribute support in OpenSearch.
Bug Fixes
- #224 Fixed OPA attribute-policy validation for
POST /queryFulltext. - Fixed document deletion to use the active OpenSearch alias target.
- Corrected OpenSearch CloudWatch alarm configuration.
Antivirus (v1.7.1)
Updates
- #236 Updated the ClamAV Lambda layer to 1.4.5.
- #237 Extended virus-definition object expiration from 30 days to one year.
Bug Fixes
- #238 Fixed warm Lambda instances failing to refresh their cached ClamAV definitions after the intended 12-hour interval.
Document Generation Module (v1.2.2)
Features
- #243 Added generated output as a new document artifact or a new version of an existing artifact using
saveAsArtifact,saveAsArtifactId, and optionalartifactCategory. - #257 Added PDF-source package generation, including appending or prepending other PDFs.
Bug Fixes
- #257 Unsupported generation source types now return
400 Bad Requestinstead of an internal server error. - Upgraded vulnerable document-generation dependencies, including FreeMarker to 2.3.35.
E-Signature Module (v1.2.1)
Features
- #231 Added draft DocuSign envelope creation and
POST /esignature/docusign/{documentId}/envelopes/{envelopeId}/views/senderfor preparing recipients and signature fields in DocuSign's sender interface. - Added
GET /esignature/docusign/{documentId}/envelopes/{envelopeId}for envelope status and recipient information. - #278, #279 Added on-demand reminders through
POST /esignature/docusign/{documentId}/envelopes/{envelopeId}/reminders, with envelope-wide resend or selected eligible signers usingrecipientIds. Targeted responses report individual provider outcomes. - #280 Added
POST /esignature/docusign/{documentId}/envelopes/{envelopeId}/voidwith a requiredvoidedReason. - #256 Added configured DocuSign environment selection and request-level environment overrides.
- #261 Added hybrid signing through
embeddedRecipientStartUrl, allowing signing invitations alongside embedded recipient views.
Bug Fixes
- #260 Only
envelope-completedcallbacks mark signing as completed, after the signed PDF has been stored. Recipient callbacks no longer mark documents completed prematurely, and terminal statuses are protected from regression. - Redacted sensitive DocuSign log values.
OCR (v1.7.1)
Bug Fixes
- #251 Preserved artifact IDs through OCR action requests and asynchronous Textract completion, allowing results and processing status to remain associated with the correct artifact.