Skip to main content

Trivore ID 6 changelog

Version 6 is a continuation of development from ID 5.24.0, rebuilt on new application frameworks: the backend moved from Java 11 and Spring Boot 2.7 to Java 25 and Spring Boot 4.x. Practically the entire Management UI was also re-implemented on Vaadin Flow, replacing the legacy Vaadin 8 framework used since early versions. It's the current production-ready major version of Trivore ID.

Upgrade instructions​

Review Important Upgrade Notes for version specific upgrade instructions.

6.3.0​

Released 2026-09-18.

New Features​

  • ONEP-4373: Added support for generating personal identifiers to users.
  • ONEP-4378: Added support for importing signed entity statement for OpenID client and automatic signed JWKS fetch
  • ONEP-4425: Added new API endpoint for fetching sent SMS messages, supports pagination and custom SCIM filtering
  • ONEP-4434: Added new webhooks USER_PROFILE_PHOTO_CHANGED and USER_PROFILE_PHOTO_DELETE for user profile photo changes.

Improvements​

  • ONEP-4244: Added support for signed authentication requests and private key JWT token endpoint authentication method
  • ONEP-4246: The inclusion of the namespace code claim in OIDC ID tokens can now be toggled per client. Existing clients continue to include the claim by default to preserve backward compatibility, newly created clients omit it by default.
  • ONEP-4248: Add support for FTN specific optional OpenID claims
  • ONEP-4249: Added support for required FTN OpenID claims
  • ONEP-4251: Added new mapper for ACR-values in Client Scopes.
  • ONEP-4252: Added support for signed OpenID entity statement via /.well-known/openid-federation
  • ONEP-4255: Added support for FTN specific ftn_spname OpenID auth request parameter
  • ONEP-4258: Added compatiblity option to always include refash token in token responses which is enabled for existing OpenID clients. Alternative option to fetch refresh token is to use offline_access scope.
  • ONEP-4260: Added support for configuring ID token expiration time per OpenID client
  • ONEP-4352: Added ID product version information to the Dashboard’s cluster members list.
  • ONEP-4368: Added "nsCode" parameter for SMS related REST endpoints. This parameter can be used to select namespace when sending SMS messages. Affects routing plan, default originator (sender ID) and billing of the message.
  • ONEP-4369: Added configuration option to enable SMS sender ID sanitization and allowed character regex to configure which characters are allowed in sender ID. Sanitization is disabled by default but can be configured per SMS routing plan.
  • ONEP-4387: Added namespace information to the Enabled Client Scopes -field in the OIDC Client editor.
  • ONEP-4395: Added last activity update endpoint parameter to set custom value for user's last activity timestamp
  • ONEP-4399: When user is hard-deleted, all related user files are also deleted
  • ONEP-4408: Updated dependency libraries.

Bugs​

  • ONEP-4263: Improved error handling when failing to save changes due to unique index violation errors. UI shows notification about the problem and REST endpoints return status code 400 with error code "index-violation".
  • ONEP-4279: Fixed an issue in the ID Dashboard where certain members that were actually stopped were still shown with the “Different partition” status instead of “Stopped”.
  • ONEP-4339: Fixed UI issue when selected cluster active partition is invalid (no nodes in selected partition exist)
  • ONEP-4345: Fixed a problem that prevented clearing the value for OpenID client default authentication flow
  • ONEP-4353: Fixed few bugs in Namespace editor that prevented editing LDAP server and LDAP certificate synchronization related fields
  • ONEP-4386: Fixed an issue where the Client Scopes view in the admin UI did not refresh after changing the namespace from the top bar.
  • ONEP-4388: Fixed namespace restriction handling with custom client scopes. Previously all defined custom client scopes were available regardless of their namespace.
  • ONEP-4396: Fixed custom CSS stylesheet loading and unloading when navigating between different views
  • ONEP-4407: Fixed UI bug which prevented listing authorisation objects if any authorisation was missing objectType or subjectType field
  • ONEP-4411: Sanitize filenames when uploading user files via REST API. UTF-8 filenames are also supported.
  • ONEP-4413: Fixed a bug that prevented editing allowed and default scope for OpenID client
  • ONEP-4416: Improved OIDC Client creation wizard user experience.
  • ONEP-4427: Fixed UI issue when editing web hook (previously selected values were not selected)
  • ONEP-4430: Fixed webhook view copy button functionality
  • ONEP-4456: Fixed access token handling in suomi.fi authorisation endpoint (produce error when token is missing userId value)
  • ONEP-4475: Fixed issue with suomi.fi authorisation and SMS delivery reports
  • ONEP-4494: Fix UI related URL paths in service path information
  • ONEP-4528: Fixed bug in passkey authentication and suomi.fi authorisation usage regarding security context handling in /api paths

Customer specific​

  • ONEP-4405: Customer requested changes to sale endpoint when handling student user and student product.

Release 6.2.0​

Released 2026-07-03.

This release adds a mass-onboarding API for new pupils via the DVV base database, per-user file hosting through the Users API, and support for Telia Identification as a user directory. It also brings a number of bug fixes (including corrected Elliptic Curve token signing and missing event log entries for client-credential tokens) and improvements such as OpenTelemetry tracing for outgoing HTTP calls, gzip-compressed API responses, a new /health endpoint, and visibility into archived users through the Users API.

New features​

  • ONEP-4083 API for mass onboarding of new pupils (e.g., first-graders) via the DVV base database (perustiedot). The solution supports safe repeated calls within the same namespace/group, processes PICs in batches with a 10,000-per-request limit, optionally locks/unlocks users, adds requested group memberships, and returns a transaction ID.
  • ONEP-4309 Added support for user-specific file hosting in the Users API. New endpoints under /user/{userId}/files allow listing, uploading, downloading, replacing, and deleting per-user files. Access requires the USER_FILE_READ / USER_FILE_WRITE permissions for API clients, or the user's own access token with the user.files.readonly / user.files scopes. By default the feature is disabled and no files can be uploaded until an administrator enables it for a namespace by allowing a number of files, with the maximum file size falling back to a system-wide default unless a namespace-specific limit is set.
  • ONEP-4351 Added support for Telia Identification service to use as user directory

Bug fixes​

  • ONEP-4175 Added fixes for configurations that whitelist automatic redirect url's for strong id and link account endpoints.
  • ONEP-4214 Recovering an archived user now includes the same duplicate and field validation checks as creating a new user.
  • ONEP-4310 Fixed an issue where opening the User Editor could fail when certain fields were returned as null.
  • ONEP-4328 Fixed Elliptic Curve usage for id_token and access token signatures
  • ONEP-4341 Fixed missing event log entries for OIDC client access tokens that were not bound to any user (for example client-credentials tokens). These token events are now logged with the OIDC client application as the event target. A "Token history"-button has also been added to the OIDC client "Tokens" window that opens the client's event log.
  • ONEP-4356 Fixed an issue with the MFA setup page user experience.
  • ONEP-4367 Fixed issue when deleting user directory and migrating users to internal directory
  • ONEP-4380 Corrected how database queries are built, which enables updating to newer Spring Boot version.
  • ONEP-4389 User export in Management UI produced empty files, this has been fixed.
  • ONEP-4391 API for running a Scheduled Task now uses a specific thread scheduler
  • ONEP-4392 Improved internal servlet registration methods to be compatible with new Spring Boot versions
  • ONEP-4406 OpenAPI descriptions of tags were not visible after servlet registration changes.

Improvements​

  • ONEP-2646 Added visual indication to namespace editor when related scheduled task is disabled but is required by namespace settings
  • ONEP-4117 Added OpenTelemetry instrumentation for OkHttp and enabled wherever OkHttpClient is used, including calls performed via Retrofit. This enables visibility into call timings, easier identification of slow calls, and supports ongoing performance improvements.
  • ONEP-4174 Added support for gzip compression in Management API JSON-responses. Send header Accept-Encoding: gzip with REST-requests to use.
  • ONEP-4219 Improved the Group Policy management UI to clarify order in which policies are processed
  • ONEP-4280 Added cluster settings view option to remove inactive cluster nodes manually
  • ONEP-4291 Archived users can now be fetched through the GET /users/{userId}-endpoint by setting the new includeSoftDeleted query parameter to true (defaults to false). User information responses now also include a read-only softDeleted field indicating whether the user is archived.
  • ONEP-4307 Replaced Slider fields with Textfields to allow more precise configuration.
  • ONEP-4330 Added new /health endpoint which can be used by load-balancer to check that service is alive and functional
  • ONEP-4362 Added support for RFC9440 formatted certificate headers to use with Smartcard based authentication
  • ONEP-4376 Updated dependency libraries.

Release 6.1.0​

Released 2026-06-05.

Administrators can now restrict which languages are offered in the language selection menu, and an API documentation "Preview" page shows planned endpoints ahead of release. Most other changes are under the hood: a refactor of the legacy user consent data model, signed/encrypted UserInfo and ID token support, an event log API for OAuth2 apps and API clients, property-based overrides for feature flags, and improved handling of DVV and LDAP connection failures.

New features​

  • ONEP-4264 Added support for configuring which languages are available in the application. Administrators can now specify the supported languages in the system settings, and only these languages will be shown in the language selection menu. This configuration can be managed via the settings user interface or the API. Existing systems are automatically migrated to include this new setting.
  • ONEP-4321 Added a "Preview" page to API documentation site, which allows showing a preview version of planned API endpoints.

Bug fixes​

  • ONEP-4197 Added support for editing a groups user policies with the update operation of Groups API.
  • ONEP-4208 User strong identity identification via management UI now shows proper error notification if there is duplicate/conflicting Personal ID or Electronic Identity Code
  • ONEP-4271 Improved display of progress updates for upgrade steps in admin user interfaces.
  • ONEP-4325 Fixed an issue where multipart servlet requests failed to parse, causing 500 errors with “No multipart configuration element / bad multipart”. The change adds proper error handling.
  • ONEP-4332 Fixed issues with translations of certain claim names

Improvements​

  • ONEP-4068 DVV lookup/update endpoints now return 503 Service Unavailable status code when unable to communicate with DVV. Error code "dvv-failure" is included in response. Additionally, Trivore ID metrics dashboard now shows amount of DVV failures.
  • ONEP-4120 LDAP related errors are no longer sent to Sentry. Added new tool to test LDAP connection which supports clustered environment.
  • ONEP-4201 New API's have been added to allow fetching the event log for OAuth2 apps and API clients, either by actor or target. These endpoints provide paginated access and filtering options for event logs. This improvement ensures that event log data is now accessible through the API in the same way as through the user interface.
  • ONEP-4204 Refactored the legacy user consent data models: removed the obsolete GrantedPermissions and deprecated/misleading consent fields from User, updated REST and claim generation to serve only the current consent collection (using new resolver logic with UserConsentService), and aligned read/write behavior across the consent APIs.
  • ONEP-4229 Improved the Group Policy Security editor by increasing the range of values for password settings, and now allowing users to insert their own preferred value for individual settings.
  • ONEP-4234 Implemented human-readable captions for Event Log “Event ID” values in the Management UI.
  • ONEP-4243 Added support for signed user info and encrypted id_token and user info
  • ONEP-4292 Added support for property-based overrides to ID feature flags. Feature flags can now be enabled or disabled directly via Spring properties (e.g., featureflags.<name>.enabled), bypassing Unleash configuration if a property is set.
  • ONEP-4302 Added translation keys for hardcoded texts in ID Management UI.
  • ONEP-4317 Updated dependency libraries.

Release 6.0.0​

Released 2026-05-08.

This release lays the foundation for the version 6 series: the backend moves to Java 17, Spring Boot 3.x, and the Jakarta namespace, while practically the entire Management UI (and most end-user UIs) is re-implemented on Vaadin 24 / Vaadin Flow, retiring the legacy Vaadin 8 framework.

New features​

  • ONEP-4033 Update to java 17, Spring Boot 3.x, Vaadin 24, jakarta namespace

Bug fixes​

Improvements​