Release Notes 2024
Version 2024.09.0
Release Date: September 9, 2024
This document contains New Features, Changes, Improvements, and Bug Fixes for version 2024.09.0.
For users updating from version 2024.05.3 Patch, multiple API Proxy selection in API Proxy Group has been enabled. With this setting, the feature of applying policies from API Proxy Group to API Proxies that was previously available has been removed.
For users updating from version 2024.05.4 Patch, with the security update made, value validation of client IP addresses from browsers in Apinizer Management Console has been made mandatory. Therefore, the requirement for organizations connecting to the interface using "Kubernetes Ingress Controller" to send client IP information via X-Forwarded-For header has been removed.
-
Downloadable Specifications in API Portal
Specifications can now be downloaded in API Portal.
-
New Policies for Management APIs
New policies have been added to Management APIs. See.
IMPORTANT CHANGES AND IMPROVEMENTS-
With the Disable Routing button, a service loaded with a definition file can now run without going to the backend. See.
-
Values written in Routing addresses have been detailed to make it clearer where proxies' routing addresses go when they don't go to the backend. See.
-
IMPORTANT! Mirror API selected when creating API Proxy has been deprecated and removed in this version. It should now be configured in the API Proxy Routing tab.
-
Operations that can be performed in the Development tab of API Proxy and API Proxy Group have been customized for each pipeline. See.
-
The active/passive button in Connection Configurations has also been placed on the listing screen. See.
-
A warning has been added to the DB-2-API screen that in GET queries, results return as top1/limit1 which are not visible. See.
-
Apiops can now be completely disabled. See.
-
A list of those used in Proxy Group has been added to Global policies.
-
In endpoint testing in API Portal, when an application is selected, Auth information now comes automatically. See.
-
When Cache is started, loading of previous quota data from the database can now be done lazily or eagerly. See.
-
Production and Test fields have been added to Gateway Environments. See.
-
The enable button in Connection Configurations has been standardized in tables.
APNZ-4562 : The WSDL example file creation size limit determined in the General Settings section is not reflected in Rest2Soap configuration.
APNZ-4559 : In API Portal Test Console, body content comes with old data and is not updated.
APNZ-4558 : When General Settings are saved, LogRetentionSetting configuration is deleted.
APNZ-4549 : A method cannot be opened due to example message not being created in Rest2Soap.
APNZ-4546 : When endpoint editing is done and method name is changed, response body content in design is lost.
APNZ-4545 : When error handling type is not set as default and backend connection cannot be established, status code is not determined.
APNZ-4552 : API Portal Issues:
- In methods, 'Request Body', 'Description', and 'Header' parameters are not displayed on the portal screen even though they are defined in manager.
- There is no table addition support when adding description in Manager; the current editor does not support table addition.
- Font type cannot be selected as corporate font or multiple fonts in API Portal.
- The documentation section on the API Portal main screen cannot be customized or made clearer.
- When colors are set, colors of all buttons do not change.
- There is a line in the middle of the API Portal navbar.
APNZ-4553 : ApinizerKubernetesClientService cannot read k8s metrics.
APNZ-4540 : When the latest version (2024.05.4) is used with an empty database, necessary database tables are not created.
APNZ-4537 : When a project is exported in test environment, error messages imported in production environment appear empty in global policies due to different IDs of error messages.
APNZ-4525 : When there are meaningful characters in the name of exported data in the file system, the export file becomes corrupted.
APNZ-4544 : Problems occur when concurrency increases in XML operations.
APNZ-4507 : Authentication policy exported from proxy group gives null error when imported to proxy.
APNZ-4529 : When 'private' or 'public' option is selected while adding a key in Secret Manager, keys do not activate.
APNZ-4521 : Accounts do not come in the account filtering section on the Credentials screen.
APNZ-4435 : When deploy or undeploy operation is performed in API Proxy Group, endpoint URLs are not updated without refreshing the page.
APNZ-4518 : Portal quick test issues:
- After pressing the 'Authorize' button and performing the 'Try' operation, parameters we defined do not appear in headers.
- Only X-Client-Id and X-Client-Secret fields appear in the Parameters section. Also, after closing the 'Try' screen, parameters we first added are also deleted from the 'Parameters' section.
APNZ-4516 : In Integration, jobs in 'disabled' status are triggered and remain in 'in progress' status.
APNZ-4536 : Date and sorting work incorrectly on the Alert history screen.
APNZ-4512 : Manager health check cannot be done with HTTPS protocol.
APNZ-4511 : There are errors in the membership model selection field in Portal.
APNZ-4510 : Namespace is not added to values sent as null in Rest2Soap operations.
APNZ-4506 : When an Authentication policy exported from a proxy group is imported to a different proxy group, although a successful response is returned, the policy is not visible. It cannot be understood whether the policy was added, and the policy still does not appear even after refreshing the page.
APNZ-4358 : Path parameters do not appear in the API Proxy design tab.
APNZ-4351 : After logout is performed and login is done, the last record deletion operation remains open in front of the project selection popup.
APNZ-4520 : Routing NTLM Authentication configuration does not work.
APNZ-4502 : Cache opens slowly and unnecessarily pings a public IP.
APNZ-4569 : There is an issue where environments sometimes do not load in the API Proxy analytics tab.
APNZ-4508 : When 'LDAP API Authentication' is selected in JWT policy, a problem occurs when the LDAP API Authentication definition is deleted.
APNZ-4533 : Some connections are missing when a project is exported.
For detailed information about New Features, Important Changes, and Improvements that came with Version 2024.05.3 Patch and Version 2024.05.4 Patch, you can review the relevant Document: 2024.05.x
Version 2024.05.0
Release Date: June 7, 2024
NEW FEATURE-
New Fields for Script and Variable Environment Values
New fields have been added to script and variable environment values (context values). See.
-
Project and Admin Overview Pages Improvement
Project and Admin Overview pages have been made more interactive. See Project See Admin
-
Credential Secret Access to Script Policy
Access to secret values belonging to credentials has been added to Script policy. See.
-
Second-Based Filtering Added to API Traffic Screen
Second-based filtering has been added to the API traffic screen.
-
Logging in Graylog GELF Format
Logs can now be logged in Graylog GELF format via UDP/TCP. See.
-
Manager and Portal HTTPS Support
Manager and Portal can now be opened with HTTPS.
-
Error Policies Pipeline
An Error Policies pipeline has been added for policies determined in error situations to work. See.
-
user_token_blackList Added to Old Log Deletion
The user_token_blackList object has been added to old log deletion. See.
-
Multi-Tab/Location Login Setting
A setting has been added to general settings to allow users to log in from multiple tabs/locations at the same time. See.
-
Truststore Tab Added to Certificates Screen
A truststore tab has been added to the Certificates screen. See.
-
API Portal Frequently Asked Questions
Frequently Asked Questions can now be defined dynamically in API Portal. See.
-
Application Addition to Portal
Application addition to Portal has been enabled. See.
-
Documentation&Test Tab Added to Portal
A Documentation&Test tab has been added to Portal.
-
Credential Screen Filtering
The Credential screen has been configured to filter according to applications and accounts in Portal.
-
Tools Menu Added to Portal
A Tools menu has been added to Portal.
-
Test User Role
Test User role has been added. See.
-
Notifications Added to Purge Jobs List
Notifications have been included in the purge jobs list in the system. See.
-
Script Policy Asynchronous Execution
Script policy can now run asynchronously. See.
IMPORTANT CHANGES AND IMPROVEMENTS-
When API Call policy works unidirectionally and an error is received from an API call, this error can now be reflected to the relevant API Proxy's result.
-
In the API Proxy Traffic screen, search can now be done in the advanced query field with options empty/is not empty/exists/not exists/contains/not contains/in list/not in list. See.
-
Organization API Visibility screen has been added to Portal Management. See.
-
It has been enabled to check values such as included/not included in a list when a list is given to Condition. See.
-
The feature to enter specific days has been added to Time policy. See.
-
When a user of LDAP type is searched on the Users screen, if the user is not found, a warning is displayed on the screen.
-
In LDAP information in Identity provider, if advanced is selected, the object comes as default, cannot be deleted, and can only be edited.
-
LDAP Connections within LDAP provider now come correctly.
-
Headers in the administrator panel have been corrected. See.
-
New values have been added to values accessible via Script. See.
-
Two people logging in with the same user at the same time can now be prevented. See.
-
The method of selecting hostname verification for secure connections has been enabled in system settings.
-
When there is a problem in the xslt file in Test console, the detail of the problem is also displayed on the screen.
-
JWT created when a user logs into API Manager is now created in smaller size.
-
When relative path conflicts during deployment, details about which proxy or proxy group the conflict is with have been provided.
-
Elasticsearch template settings can now be edited from the screen. See.
-
Account registration in API Developer Portal can now be configured. See.
-
Rollover feature has been added to Elasticsearch operations. See.
-
Performance improvements have been made on Uptime Monitor and Anomaly screens.
-
Feature to sign request body as JSON has been added to Test console. See.
-
In the JWK screen, Key Store, Public Key, Private Key, and Certificate fields that open now come in order and can be searched.
-
Searching by organization and names coming in order have been enabled on the Credential screen.
-
Certificates can now be edited. See.
-
Performance improvements have been made in XML transformation policy and protocol transformation.
-
Connection Request Timeout value in Routing can now be set. See.
-
Feature to sign request body as WS Security has been added to Test console. See.
APNZ-4309 : When API Manager is opened in different tabs, project information gets mixed up.
APNZ-4369 : There is an error in converting numeric fields in response messages to text in REST-SOAP-REST transformation.
Large numbers were being displayed using scientific notation in JSON. After this fix, numbers in response messages are now used as they are.
Conversion operations that were working incorrectly before will be fixed with this update. However, this situation may cause previously unnoticed errors to appear. Therefore, we recommend checking your REST-2-SOAP operations.
APNZ-3833 : Even when log level is "off" in application logs, logs continue to be kept.
APNZ-3857 : There are problems with variables in Context Values.
APNZ-4022 : Error is received when working with routing-based settings such as retry count in Uptime monitor.
APNZ-4039 : In analytics graphs, when an authorized user's authorization is removed, the user is not listed.
APNZ-4061 : Report generator is not working.
APNZ-4093 : Default value "Elasticsearch has logs on disk" in Alerts has been removed.
APNZ-4101 : Existing Cron expressions are not being updated.
APNZ-4123 : ACL Reports issues:
- Project list does not come.
- Search By Credentials does not work with desired filtering.
APNZ-4138 : Even though the log option is open in error situations, when logging is closed on the proxy, log record for the request stuck on White IP cannot be found.
APNZ-4162 : Cannot be saved after OpenAPI parsing.
APNZ-4174 : Integration is triggered but cannot send requests.
APNZ-4183 : Query cannot be made for Elasticsearch disk usage alarm.
APNZ-4208 : When project is changed, there is a 5-6 second pause on screens.
APNZ-4210 : Label error is received in Context Value.
APNZ-4215 : Ldap Secure is not working.
APNZ-4229 : Certificate in the project is not listed in API Call.
APNZ-4236 : Even if anomaly is closed, 'anomaly detected' continues to be added to the result list.
APNZ-4244 : Application logs keep logs for a maximum of the last 1 day.
APNZ-4245 : If an environment is connected to a project, when that project is deleted, that environment cannot be entered on the gateway page.
APNZ-4259 : Even though HTTP is closed in Environment settings, svc is created in Kubernetes.
APNZ-4260 : Purge Jobs operation in Application Logs is not working.
APNZ-4262 : When an API Manager user closes their session, JWT does not become invalid.
APNZ-4263 : In Rest2Soap transformations, the data size limit of the jackson library (default) has been increased from 20mb to the integer limit of 2.1Gb.
APNZ-4274 : When we open the service only over HTTPS, the XSD address in WSDL remains as HTTP.
APNZ-4276 : Business rule is not working in JWT requests.
APNZ-4294 : Adding data to body with Business Rule works incorrectly.
APNZ-4297 : Even if API is not public in Portal, its page can be accessed directly via IP. My account page does not come in Portal.
APNZ-4298 : When there is more than one Cache pod, HTTP protocol error is received.
APNZ-4308 : When a user logs into API Manager, their default project does not come.
APNZ-4318 : When threshold value is determined for disk usage alarm, error is received when any value is entered.
APNZ-4323 : Deletion operation in Redaction does not work, and value cannot be entered in the relevant field during replacement operation.
APNZ-4324 : Error is received when loading certificates without CN expression.
APNZ-4332 : In REST to SOAP transformation, namespace prefix is not added to XML in special cases when xsi:nil situation occurs.
APNZ-4335 : Cache service is not created in republished environment.
APNZ-4349 : A user logging in from Active Directory and having full authority in the project, when trying to write something instead of name in Connection Configuration > Database option and does not have administrator authority, their session is automatically closed.
APNZ-4357 : When more than one policy is added to Error Policy, they change places.
APNZ-4358 : Path param does not appear in API Proxy design tab.
APNZ-4360 : Policies added to Error Policy pipeline do not appear in Global policies' references.
APNZ-4362 : Error policies in Global policies are not displayed and cannot be updated.
Version 2024.01.0
Release Date: January 2, 2024
NEW FEATURE-
API Traffic Log Setting
Which fields will be logged or not in message regions belonging to API Proxy and API Proxy Groups was being managed from their own pages. To improve user experience, this setting can now be made application-based and project-based, environment-based from the API Proxy list. Additionally, logging operations can be activated or deactivated with connectors assigned at API Proxy or API Proxy Group level. See.
-
New Connection Configuration: Syslog
Connection definitions can now be made for Syslog to keep log records created through Apinizer in the Syslog system. See.
-
New Action/Connector: Syslog
Data can now be sent to the relevant system using the connector created using Syslog connection definitions. See.
-
New Connection Configuration: Webhook
Webhook connection definitions can now be made to transfer log records created through Apinizer to the target system via Webhook. See.
-
New Action/Connector: Webhook
Data can now be transferred to the relevant system using the connector created using Webhook connection definitions. See.
-
New Connection Configuration: RabbitMQ
RabbitMQ connection definitions can now be made to send log records created through Apinizer to queue systems via RabbitMQ. See.
-
New Action/Connector: RabbitMQ
Data can now be sent to the relevant queue system using the connector created using RabbitMQ connection definitions. See.
-
New Connection Configuration: Kafka
Kafka connection definitions can now be made to transfer log records created through Apinizer to the relevant target via Kafka. See.
-
New Action/Connector: Kafka
Data can now be sent to the relevant target using the connector created using Kafka connection definitions. See.
-
New Connection Configuration: Elasticsearch
Elasticsearch connection definitions can now be made to keep log records created through Apinizer in the Elasticsearch system. See.
-
New Action/Connector: Elasticsearch
Data can now be sent to the relevant system using the connector created using Elasticsearch connection definitions. See.
-
New Connection Configuration: Apache ActiveMQ
ActiveMQ connection definitions can now be made to send log records created through Apinizer to message systems via ActiveMQ. See.
-
New Action/Connector: Apache ActiveMQ
Data can now be sent to the relevant message system using the connector created using ActiveMQ connection definitions. See.
-
New Connection Definition: Logback
Logback connection definitions can now be made to keep log records created through Apinizer in the Logback system. See.
-
New Connector: Logback
Data can now be sent to the relevant target system using the connector created using Logback connection definitions. See.
-
Environment-Based Log Connector Definition
By default, log storage was being done with Elasticsearch, or this default setting could be closed and logs could be transferred to another system (Syslog, Kafka).
To make log management flexible, this setting can now be made environment-based, can be disabled when needed, and simultaneous logging can be done on multiple log connectors (Database, Elasticsearch, Kafka, RabbitMQ, ActiveMQ, Syslog, Webhook). See.
-
Failover Connector Support
When API Proxy Traffic could not be recorded, it was kept in the Apinizer database. With the transition to the connector infrastructure, this feature has been removed and the ability to select a failover connector for the connector has been added. Thus, when there is a problem with the connector, traffic can be transferred to failover connector(s).
-
API Proxy Creation with Connector
API Proxy can now be created using the newly defined connectors (Elasticsearch, Kafka, RabbitMQ, ActiveMQ, Syslog). Thus, API access to the integration point in the connector has been provided. See.
-
Connector Definition for Application and Token Logs
By default, Application and Token logs were being recorded in the Apinizer database. To make log management flexible, connector definitions can be made, and application and token logs can be transferred to other systems in addition to the Apinizer database through these connectors. See.
-
Privacy Settings Definition
Privacy settings could previously be set generally. With the update made, Privacy Settings can now be configured specifically for the connector in the environment. See.