Improved request approver flow with slight visual changes
Added a new table view in User Settings to display active request reviewer delegations, making it easier to manage and track who can review requests on your behalf
Added manager full name and manager ID to user export CSVs
Display Role name on soon to expire notification subevent table
Search and Filtering
Enhanced search filter on Inventory group users or resource user tables to now filter on names, email, or position
Added the ability to filter resources by remote ID and resource type in the Resources API, enabling more precise resource lookups based on external system identifiers
API Enhancements
Added REST Public API support for Github Org Roles
Bug Fixes
Updated errors to include more details when Jira credentials are incorrect
Self-hosted only
Added ability to tune memory requests and limits for some key opal pods
Fixed an issue where grants and ipsets would be dropped from the Tailscale policy file.
Fixed an issue where propagating access to two Okta roles at the same time would sometimes result in the user gaining access to only one of the roles.
Fixed an issue that caused duplicate events to be created when removing a group from another group.
Fixed an issue where Manage in Inventory was missing in the group details modal.
Fixed issues related to bulk selecting bundle assets.
Added target_user_id and requester_id to requests API filters.
Added database support for request reviewer delegations, allowing users to delegate their request review responsibilities to other users for a specified time period.
Added lastSuccessfulSyncto groups API.
Added lastSuccessfulSync to resources API.
Updated Event Filters modal styling.
Increased task timeout for most tasks to 3 hours.
Moved remote events to the Usage tab for Okta apps, AWS IAM roles, and resources in custom connectors.
This upgrade contains a substantial migration. You may notice higher latency across all actions in your Opal instance for up to 10 minutes while deploying this release. We recommend running this upgrade off-hours if possible.
Improvements and updates:
Deprecated USERS_ADDED_TO_GROUPS, GROUP_USERS_UPDATED, and USERS_REMOVED_FROM_GROUPS events and migrated them to ROLE_ASSIGNMENT_CREATED, ROLE_ASSIGNMENTS_UPDATED, and ROLE_ASSIGNMENTS_DELETED, respectively
Fixed an issue where attribute mapping was inaccessible without a direct link
Fixed an issue where multiple concurrent tasks synchronizing removals of users from groups could attempt to propagate those removals back to the end system.
Fixed an issue when viewing requested groups
Added Microsoft Active Directory as a new IDP provider
Added client-side validation for custom field character limits
Added catalog modals to UARs, so you don't have to leave the page to view more details about a resource
Updated user-first UARs to open the catalog modal, so you can see additional information without leaving the UAR
Updated and modernized Access Changes table under access reviews
Updated resources table under group modals
Updated integration settings styling
Updated Add Principals Sidebar
Updated month picker styles on Create UAR Schedule page
Updated copying fields on resource and app details
Updated the My Access section of the details modal