Release Notes Version 4.3.x
Major changes from version 4.2 to version 4.3
- The Admin Dashboard has been redesigned and System Status page has been significantly expanded with comprehensive network diagnostics. New checks include outgoing HTTPS connectivity to LiquidFiles services, Ubuntu repositories, ClamAV mirror reachability, DNS server responsiveness, LDAP server connectivity and authentication, mail queue status, and a configurable TCP packet quality test. All checks run asynchronously with clear pass/fail indicators and troubleshooting guidance.
- Outlook add-in: File Request. Admins can turn on a new setting that adds a File Request button and pane to the Secure Send add-in. Users can create a file request for one To recipient, then copy the link or insert it into the message. The pane warns them if they reopen it without having used the link. The group's File Request permission controls who can use it.
- Outlook add-in: FileLink. A new, separate Links add-in turns attachments into a FileLink. It applies the group's expiry, download confirmation, authentication and password policy.
- Added support for Microsoft Office 365 as an email relay using OAuth2 authentication (Device Code Flow). This replaces the need for basic SMTP credentials, which Microsoft has been deprecating. Administrators configure their Microsoft Entra tenant ID and Client ID, then complete a guided authorization flow.
- Comprehensive accessibility overhaul to meet WCAG Level A and AA compliance. Includes skip navigation links, semantic HTML elements, keyboard-accessible tooltips and popovers, screen reader support with ARIA attributes, proper form labels, table header scoping, image alt text, and correct heading hierarchy.
- Added session timeout warning with a countdown popup that lets users extend their session or re-authenticate with their password, TOTP code, or SMS token after expiry without losing their work.
- Added secondary admin re-authentication. Administrators are now required to re-authenticate before accessing /admin and /system pages, providing defense-in-depth against session hijacking. Supports password, SAML email verification, and strong authentication (TOTP, SMS, Duo). Includes a configurable session timeout with an expiry warning modal. API access is not affected.
- Restructured locale system now ships with 20 pre-translated languages. New sticky search/filter bar in the locale editor for quickly finding translation keys. Locale key remapping automatically migrates existing customizations when keys are reorganized.
- Added configurable filename sanitizer to protect against malicious or problematic filenames. Applies multiple layers of protection including stripping invalid UTF-8 bytes, recursive percent-encoding decode, HTML entity decoding, and tag stripping. The sanitization pattern is configurable with regex validation and ReDoS protection.
- Security: Added Cross-Origin-Resource-Policy (CORP), Cross-Origin-Opener-Policy (COOP) and Cross-Origin-Embedder-Policy (COEP) headers to all responses for cross-origin isolation. Added X-DNS-Prefetch-Control header to prevent DNS prefetching leakage. Added Clear-Site-Data header on logout to ensure complete cookie cleanup. Added Retry-After and X-RateLimit headers on brute force protection responses. Removed the legacy X-Frame-Options header for Outlook responses where it conflicted with the CSP frame-ancestors policy. See Frequent Responses after Security Reviews for details.
- Security: SSO signature verification now uses constant-time comparison to prevent timing attacks.
- Added Certificate API for managing SSL/TLS certificates programmatically. Enables external certificate automation tools (certbot, Venafi, internal PKI, etc.) to view and upload certificates via the REST API using a Sysadmin API key.
- Added Bearer Token authentication as the preferred API authentication method. API clients can now use Authorization: Bearer <api_key> instead of HTTP Basic Auth. Both static and expiring API keys are supported. HTTP Basic Auth remains available for backward compatibility.
- API clients now receive JSON-formatted error responses from nginx error pages instead of HTML, covering maintenance pages and HTTP errors 400, 403, 404, 405, 422, 429 and 500.
- Added curve25519-sha256@libssh.org key exchange to SFTP defaults.
- System Hardening:
- Replaced ntpsec with chrony for FIPS compatibility.
- Ensure internal SHA256/SHA384 digests are calculated using the OpenSSL validated FIPS modules.
- Libvips (image processing — i.e. thumbnails) are now compiled without ImageMagic support.
- Extensive harding based on results of AI tools scanning the source, both internally and as reported by Wuming Zhang.
- Feature: New admin Transfer Stats interface (Admin > Data > Transfer Stats) with volume and speed charts, top breakdowns and a CSV-exportable transfer log.
- Feature: Admin-configurable ClamAV signature mirrors with reachability status, and a per-domain antivirus scan-size limit.
- Fixed Outlook add-in authentication on browsers that block third-party cookies. Previously, the Outlook add-in set its authentication cookie inside a dialog window, which modern browsers (Safari, Firefox, and Chromium-based browsers with strict cookie policies) would silently discard as a third-party cookie — preventing users from logging in. Authentication now uses a secure one-time code handoff: after the user logs in via the dialog, a short-lived single-use code is passed back to the Outlook task pane, which exchanges it for an authentication cookie in its own browsing context. This ensures the cookie is always set as a first-party cookie, making login work reliably across all browsers. The exchange codes expire after 2 minutes and include brute-force protection.
- FileLinks have been completely modernised. A single FileLink can now share multiple files under one URL, with files added or removed without changing the link or losing the download log. New recipient-facing experiences include an image gallery with fullscreen lightbox, in-browser video playback, an inline PDF viewer, and a choice of view modes (table, list, gallery, or single-file). Owners can set a memorable custom URL, send an email invite directly from the FileLink, customise the page header and footer, enable direct (hot-link) URLs for embedding, and download all files as a single zip. Views are now tracked separately from downloads. Each capability is governed by its own per-group permission.
- Replaced the Summernote rich-text editor with TipTap for full Content-Security-Policy compliance.
- Added upload connectivity diagnostics to help identify reverse-proxy upload failures.
- Make FTP connection limits configurable and exempt whitelisted hosts from them.
- Updated internal functions like Ruby and libraries to later versions.
Version 4.3.0 (released 2026-09-23)
- Initial release of v4.3.x
Incompatibilities and Warnings
These are a few things you need to be aware of when updating to LiquidFiles v4.3.
API Changes
Bearer Token authentication (Authorization: Bearer <api_key>) is now the preferred method for API authentication. HTTP Basic Auth continues to work but is deprecated and will be removed no earlier than April 2027. We recommend updating your API clients to use Bearer Token authentication. See the API Authentication documentation for details.
API clients sending Accept: application/json will now receive JSON-formatted error responses ([{"error": "..."}]) from nginx error pages instead of HTML. This includes maintenance pages and HTTP errors 400, 403, 404, 405, 422, 429 and 500.
Require the password on password-protected FileLinks for API requests, via the new X-Link-Password header.
External User Registration
An External User can now only register an account when an active message in the domain has been sent to their email address. Other addresses, such as someone validating their email to send to a Filedrop, get an email-only session instead, even with Require Registration set.
Single Sign-On with Pre-Shared Key
Each domain must now use its own unique SSO secret key. The same key can no longer be configured on more than one domain — if you currently share a key across domains, generate a new unique key for each, so a link signed for one domain can never be used on another.
A new labelled signature format is now recommended — sha256('email:"..." group:"..." timestamp:"..." secret:"..."'). The older unlabelled format (sha256(email + timestamp + secret)) continues to work but is deprecated and may be removed in a future release. See SSO with pre-shared key for details.
Duo Two-Factor Authentication
LiquidFiles now verifies that the subject returned by Duo's callback matches the authenticating user's Strong Auth Username (case-insensitive) before completing login. This check was introduced in v4.2.59 as part of the ongoing security hardening and carries through into v4.3.0. Previously, a mismatch between the value Duo returned and the user's Strong Auth Username was silently accepted; it is now rejected, and login fails with “Duo authentication failed”.
The Strong Auth Username defaults to the user's email address. If your Duo integration returns a different identifier as the subject — for example an Active Directory sAMAccountName or another short username — affected users will no longer be able to complete Duo login after upgrading. Before upgrading, check the Duo Admin Panel Authentication Log to confirm what Duo returns for your users, and make sure it matches each user's Strong Auth Username in LiquidFiles (Admin → Users), or, for LDAP-mapped users, point the Strong Auth Username Attribute setting (Admin → LDAP Servers) at the LDAP attribute that holds the value Duo returns (typically the email attribute). See Duo Two-Factor Authentication for details.
FTPdrop and FTPdir Login over SFTP
Login to FTPdrop and FTPdir accounts over the SFTP protocol (port 22) is now possible only with an SSH key. Previously, the SFTP listener also advertised password authentication alongside public-key authentication; this was removed in v4.2.51 (the first v4.3 beta) and carries through into v4.3.0. Plain FTP and FTPs (port 21) are unaffected and continue to support the FTPdrop or FTPdir Password.
If any of your FTPdrop or FTPdir accounts are used with an SFTP or SCP client configured for password authentication rather than an SSH key, that client will no longer be able to connect after upgrading. Confirm each account has an SSH key configured under its FTPdrop or FTPdir settings (Admin → Data → FTPdrops / FTPdirs) before upgrading, and update the client accordingly. See FTPdrops and FTPdirs for details.