ChangelogΒΆ
All notable changes to JIM (Junctional Identity Manager) will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
UnreleasedΒΆ
AddedΒΆ
- β¨ The Metaverse Object Table view is now Inspect, showing where every value came from and why it beat the other sources. The source also appears on the Changes tab and Pending Export detail, and via REST and
Get-JIMMetaverseObjectProvenance. (#399) - β¨ A refused server certificate now shows its chain and where JIM found each certificate. Choose what to trust offers any of them, recommending the root because it survives renewals; REST and
Get-JIMConnectedSystemServerCertificatereturn the chain androotThumbprint. (#1914) - β¨ Expressions are syntax highlighted as you type them, in an Attribute Flow's Expression and a Generated Value's base expression, with Metaverse (
mv["..."]) and Connected System (cs["..."]) attribute references in colours of their own, here and in the Attribute Flow table. - β¨ JIM warns when a Connected System projects into an object type deleted When Authoritative Source Disconnected without being one of its sources, on the Deletion Rules panel, when saving the Synchronisation Rule, and via REST and PowerShell. (#1256)
- β¨ Preview what a Full Synchronisation of a Connected System would do, from the pending configuration notice, a Full Synchronisation Run Profile, the REST API or PowerShell: every change, here and in the systems it reaches, per object. A run started from it records it. (#1530)
- β¨ Preview what deleting a Connected System would do (values taken over or cleared, identities made eligible for deletion, downstream corrections) from its Danger Zone tab,
New-JIMConfigurationChangePreview -Deletionor REST; the deletion's Activity records the preview. (#134) - β¨ REST and
Get-JIMActivity -Idnow return a change'sPreviewActivityId, so a script can read back which Configuration Change Preview informed it. (#134) - β¨ JIM can now generate unique values such as account names, employee numbers and badge codes: a Generated Value Attribute Flow adds a number only if a value is taken, or uses a forward-only sequence or a random token, and keeps each value once issued. (#242)
- β¨ Generated values are never reissued by default: a leaver's value goes into a retired values register, viewable from the Attribute Flow, REST or
Get-JIMRetiredGeneratedValue, so it can never pass to someone new. (#242) - β¨ An import Attribute Flow can now derive one Metaverse attribute from others with
mv["..."], such as Email from Account Name; JIM evaluates them in dependency order in one synchronisation and refuses a loop when you save it. (#1750) - β¨ The Attribute Flow tab shows each derived flow's step, offers Metaverse attributes to insert, checks for loops as you type, and warns before a change leaves a derived flow without an input; REST and PowerShell report the same. (#1750)
- β¨ Before choosing a generated value, JIM now asks the LDAP directories it is exported to whether it is in use, catching accounts JIM doesn't import. The Attribute Flow's Checked for availability in panel shows how each system is checked and lets you exclude one. (#242)
- β¨ A generated value exported to a SCIM service or SQL database is now checked there too before JIM chooses it, catching accounts created since the last import. (#1941)
- β¨ When a target refuses a generated value as already in use, JIM now corrects it (
joe.bloggsbecomesjoe.bloggs1) and the next synchronisation carries the new value to every target. If another system already uses the value, the export waits for a decision instead. (#242) - β¨ See why a generated value is waiting for a decision, allow the rename or try again, from REST (
/generated-values/decisions) orGet-JIMGeneratedValueDecision,Approve-JIMGeneratedValueRenameandReset-JIMGeneratedValueDecision; each action records who took it. (#242) - β¨ Collision Remediation can be switched off per generated Attribute Flow in the portal, via REST (
collisionRemediation) and-CollisionRemediation, and each Connected System it is checked in now says whether it can report a value as already in use. (#242) - ⨠A new Generated Values tab under Operations lists the generated values waiting for a decision, with Allow the rename⦠and Try again; Synchronisation Rules, Connected Systems and Metaverse Objects flag their held values. (#242)
- β¨ A Metaverse Object's Connections tab now explains each connection: expand a row to see how it joined, the Synchronisation Rule responsible, and whether each relevant rule's scoping still includes it. JIM records the joining rule from now on. (#348)
- β¨ A new Not connected section says why a Metaverse Object has no account in each Connected System an enabled export rule targets, and what would bring it into scope, with a Copy summary for tickets; REST and
Get-JIMMetaverseObjectConnectionsay the same. (#348) - β¨ REST and
Get-JIMMetaverseObjectnow return a Metaverse Object's Created By and Last Updated By, as the portal's Properties tab shows. (#348) - β¨ Each release now publishes
jim-release-X.Y.Z.tar.gz.sha256, so an air-gapped bundle can be checked after downloading it and before carrying it into the site. (#1942) - β¨ In a multi-domain Active Directory forest, JIM now probes
userPrincipalName,mailand other forest-wide attributes through a Global Catalog, so a value used in another domain is found. Set one with the new Global Catalog Server setting. (#1940) - β¨ When JIM checks Active Directory for an email address before choosing it, it now also looks in every object's
proxyAddresses, so an address already used as someone else's alias counts as taken. (#1940)
ChangedΒΆ
- π An export an LDAP directory, SCIM service or SQL database refuses because a value such as an account name or email address is already in use is now recorded as Value Already in Use, and completes the Activity with a warning rather than as an unhandled error. (#242)
- π A synchronisation that generates a value now contacts every Connected System it is exported to whose Connector can probe, with that system's own credentials; if one can't be reached, JIM uses its own records and records one Activity warning for that system. (#242)
- π Reviewing export scope after a rule change now records an execution item only for objects it provisions or deprovisions, named after the Metaverse Object, instead of a blank item for every object reviewed. (#1925)
- π A Configuration Change Preview's summary no longer lists one row per object when each object has values of its own (five different Job Titles cleared); it shows one row for the attribute, and the drill-down names each value. (#1935)
- π
mv["..."]in an import Attribute Flow expression now reads the Metaverse Object; it previously read nothing. Review any import expression that already readsmv, as it now derives a value. (#1750) - π REST: deleting a Synchronisation Rule or one of its Attribute Flows now returns 200 with the affected counts instead of an empty 204, and saving a whole Synchronisation Rule returns any save warnings alongside the rule. Scripts expecting 204 need updating.
- π Scoping Criteria on a multi-valued attribute such as
objectClassnow test every value, not whichever loaded first: equals or contains is met by any value, does not by none, so an object's scope no longer depends on value order. (#1923) - π Predefined Search does not operators now match as Synchronisation Rule scoping does, needing a value and no match: does not equal no longer matches a multi-valued attribute holding the value, nor does not contain an object with no value. (#1962)
- π The bundled PostgreSQL's memory is now set in
.envorjim-config.yaml(JIM_DB_SHARED_BUFFERSand four more), whichsetup.sh --upgradesizes to the host. Upgrading on Podman or by hand on a host over 4 GB, add them, or the database uses 4 GB defaults. (#1943)
FixedΒΆ
- π A synchronisation that withdraws queued export changes because the target already holds the values now records it on the Activity, and the Sync Preview and Full Synchronisation preview show it beforehand, instead of the changes silently disappearing. (#2001)
- π Deleting a Synchronisation Rule, deleting a Connected System through synchronisation, and the stranded value sweep now record queued export changes they withdraw on their Activity too, and the Connected System deletion preview shows them beforehand. (#2011)
- π An Active Directory or Samba AD Delta Import now stops and asks for a Full Import when the domain controller's update sequence number has gone backwards (a restore that kept its invocationId), instead of silently missing the changes made since the restore. (#1869)
- π A 389 Directory Server Delta Import now stops and asks for a Full Import when the changelog's newest change number is below the last import's (a restore from backup or snapshot), instead of silently missing the changes made since the restore. (#2004)
- π An OpenLDAP Delta Import now refuses, and asks for a Full Import, when the accesslog has been purged past where the last import ended (Delta Imports paused for longer than
olcAccessLogPurgekeeps entries); the discarded changes were previously lost without an error. (#2008) - π A 389 Directory Server Delta Import now also catches an online restore (
dsconf backup restore), and a restore followed by enough writes to pass the last import's change number, by reading that change back; both previously went unnoticed. (#2008) - π The LDAP Connector's Connection Timeout now applies to a directory server behind a firewall that drops traffic. Each connection waited over two minutes, so an unreachable domain controller held up a run for about nine minutes; it now fails in under a minute. (#2003)
- π
setup.shnow writes aJIM_INFRASTRUCTURE_API_KEYgiven to it into.envon Docker, as it already did into Podman's secret, so an automated Docker install gets its key; it also refuses a key JIM would not create. (#1950) - π
Connect-JIM -ApiKeynow stops with "JIM rejected the API key" when JIM does not accept the key, instead of reporting a connection that is authorised. (#1950) - π On Podman, stopping or restarting JIM no longer leaves its connections open on the bundled PostgreSQL for about two hours: the database now drops a connection whose client has gone within two minutes. (#1980)
- π A rootful Podman JIM now survives a firewalld reload, which left it unable to reach its database until restarted:
setup.shenables Podman'snetavark-firewalld-reload.service. Upgrading from v0.16.0 or earlier, enable it as the Podman page shows. (#2009) - π A service waiting for its database at start-up now names the address the database's name led to, so a name pointing at a server that has moved shows in the log. (#2009)
- π A rootful Podman JIM on RHEL-family hosts no longer stays down after a restart, logging
No route to hostfor its database:setup.shstops NetworkManager unplugging JIM's pods. Upgrading from v0.16.0 or earlier, add the setting as the Podman page shows. (#2009) - π An export scope review item's causality panel now starts from its Metaverse Object; it showed a Connected System Object that took no part in the run, as though the review had imported it. (#1982)
- π An export scope review's execution item now reads as an Export Scope Review of its Metaverse Object and links it; it showed "Operation: Not Set" and said the Connected System Object had been deleted. (#1971)
- π Creating or re-enabling an export Synchronisation Rule, switching provisioning on, or changing its Scoping Criteria now reaches existing Metaverse Objects at the next synchronisation, not when each next changes. Changes saved before upgrading need saving again. (#1925)
- π Objects moved into or out of scope by a relative date are now provisioned or deprovisioned by the next Delta Synchronisation even when it has nothing new to import, and are no longer missed when two Synchronisation Rules with relative dates cover them. (#1925)
- π A synchronisation no longer fails with a duplicate key error when it deprovisions objects a relative date has moved out of an export rule's scope. (#1925)
- π An export scope change that lands while a synchronisation is running (a saved rule change, or a relative date being crossed) now reaches every object it affects; objects that run updated could miss it. (#1925)
- π A delete queued because an object left an export rule's scope now shows on that object's execution item and in the run's Pending Exports total, as a provisioning does. (#1925)
- π An object leaving an export rule's scope under a Disconnect Deprovisioning Action is now reported on its execution item as Disconnected from target system, in synchronisation, recall and Sync Preview; it was visible only in the service log. (#1966)
- π Sync Preview of a Connected System Object now shows what synchronising it would do: it no longer proposes corrections to values changed in other systems, which the synchronisation leaves alone, and now shows the drift corrections the synchronisation makes where an export rule enforces state. (#1530)
- π Sync Preview of an object leaving import scope now shows the updates its departure sends to target systems, where the values it contributed are withdrawn or handed to another source; it showed only the disconnection. (#1530)
- π Sync Preview of an object whose Expression would fail it no longer also shows the projection and exports the synchronisation then discards; it shows the error alone, as the run records it. (#1530)
- π Sync Preview now hands an attribute to the next source, as the synchronisation does, when the source holding it stops supplying a value, and withdraws a value whose Attribute Flow has been deleted, along with what is derived from or exported for it. It showed the attribute cleared, or the old value kept. (#1899)
- π Switching an export rule's Deprovisioning Action from Delete to Disconnect now withdraws its queued deletes not yet exported and disconnects those objects instead; they were still deleted at the next export. (#1970)
- π PowerShell:
-MetaverseAttributeNamenow works onNew-JIMScopingCriterion,Set-JIMScopingCriterion,New-JIMPredefinedSearchCriterionandSet-JIMPredefinedSearchCriterion; it always reported the attribute as not found. (#1965) - π A value cleared in the Metaverse is now cleared from a File Connector file in Export Only mode; JIM did not record what it wrote there. For files written before this release, the File Connector page explains how to bring JIM up to date. (#1936)
- π Deleting a Connected System with "Deprovision through synchronisation" no longer clears the values contributed by an Object Type whose Remove Contributed Attributes On Obsoletion setting is off; they are kept, exactly as a normal disconnection keeps them. (#134)
- π When
setup.sh, run again over an installation, stops before starting JIM (a refused setting, or Ctrl+C), it now puts the installation's files back; it had replaced.envwith the template, so JIM's next start failed. A first install that stops leaves nothing behind. (#1994) - π When deleting a Connected System or Synchronisation Rule withdraws values an export rule's scope depends on, the downstream account is now deprovisioned per that rule's Deprovisioning Action, as a synchronisation would, instead of left provisioned. (#134)
- π Removing a Scoping Criteria group or criterion from a Synchronisation Rule now deletes it. It used to linger unseen and stop the Connected System it compared ever being deleted; systems already affected can be deleted again. (#134)
- π REST: a Connected System's deletion preview now fills in
mvosWithOtherConnectorsCountandmvosWithGracePeriodCount, which always read 0. (#134) - π Predefined Search criteria groups nested more than two deep are now applied; the deeper groups were ignored, so such searches returned objects their criteria excluded. The portal now shows and edits groups at any depth. (#1929)
- π PowerShell:
-MetaverseAttributeNameon the Predefined Search and scoping criterion cmdlets, andGet-JIMHistoryCount -ConnectedSystemName, now find what they name; they always reported it not found.Get-JIMConnectedSystemnow lists every system, not just 25. (#1967) - π An export Synchronisation Rule's Attribute Flow Expression no longer suggests
cs["..."], which reads nothing on export; its example and Insert attribute menu now offer Metaverse attributes (mv["..."]) instead. - π Trusting an intermediate certificate authority or a server's own certificate now works for SQL Server, as for LDAPS and SCIM; it used to report "Certificate trusted." and still be refused, and the card kept saying untrusted. (#1914)
- π SQL Connector, encrypted SQL Server connections: a certificate whose issuer is in Admin > Certificates is now accepted, and a refused one is reported with its reason instead of "Unable to connect". (#1472)
- π Synchronisation Rule scoping criteria nested more than two groups deep are now evaluated; previously the deeper groups were ignored, so such rules could include objects their criteria excluded, and the editor dropped those groups from view after saving. (#348)
- π Following a reference from one Metaverse Object to another now shows the new object's Changes, Connections, Password and Properties details; previously the first object's could stay on screen, and Load more could mix two objects' change history. (#348)
- π When JIM is not ready after installing or upgrading,
setup.shnow names each container that is not running properly, the bundled database included, with the end of its log, instead of pointing at the web and worker logs only. (#1944) - π
setup.shnow stops before starting anything when given aJIM_DB_SHARED_BUFFERSthe host cannot hold, which the bundled PostgreSQL could not start with, and warns above half the host's memory; its summary marks the sizes it was given. (#1948) - π The commands for operating a rootless Podman JIM now work on a minimal RHEL-family host such as AlmaLinux 9;
systemctl --user -M jim@, which the documentation and installer gave, fails there withoutsystemd-container. Use the documentedjim-systemctlinstead. (#1955) - π The bundled PostgreSQL now starts on hosts with less than about 10 GB of memory, the documented 4 GB minimum and 8 GB recommendation included: the installer sizes its memory to the host, on Docker and Podman. (#1943)
- π
sha256sum -c checksums.sha256in an extracted release bundle now passes; in every earlier release it failed on every line, because each file was listed under the build machine's folders. The bundle also no longer carries a development notes file. (#1942) - π Running
setup.shagain over a Docker installation now restartsjim.webwhen it has to, so JIM serves the certificate that run issued instead of the previous one. (#1956) - π Declining
setup.sh's Start JIM now? now prints commands that work: on Podman with systemd they no longer fail to find JIM's unit, and a JIM already running is restarted on the new settings and certificate instead of left as it was. (#1984) - π On Ubuntu 24.04, a rootful Podman JIM's services no longer crash and restart:
setup.shnow adds the AppArmor rule letting a container's processes signal one another. Upgrading from v0.16.0 or earlier, add it as the Podman page shows and restart the server. (#1953) - π A Synchronisation Rule that has synchronised objects can now be deleted; it failed with a database error. Its change history is kept and still shows the rule's name. (#1990)
PerformanceΒΆ
- β‘ Configuration Change Previews that weigh up every affected object, such as deleting a Connected System or changing an Attribute Flow, now evaluate them once rather than twice, so the full answer arrives in about half the time. (#1530)
0.16.0 - 2026-09-29ΒΆ
AddedΒΆ
- β¨ JIM can now be deployed with Podman, rootful or rootless, with no Docker or other extra software, including air-gapped: the setup script installs it on RHEL and other Podman hosts, and systemd starts it at boot. Ansible can deploy it too. (#1808)
- β¨ Air-gapped installs use the same setup script: run it inside the extracted release bundle and it loads the images and installs without an internet connection. (#1808)
- β¨
setup.sh --upgradeupgrades a Docker installation, online or from a release bundle: it keeps your settings and compose files of your own, refuses to overwrite edited ones, and puts everything back if it fails before JIM restarts. (#1854) - β¨ Adding an auxiliary class to a Connected System Object Type now lists the attributes each class would contribute, in a dialog that opens on the suggested classes and applies several at once; REST and
Get-JIMConnectedSystemAuxiliaryClassreturn them too. - β¨ Feature flags let JIM roll out a capability gradually: Preview features can be switched on from Service Settings, PowerShell (
Get/Enable/Disable-JIMFeature) or REST, each change fully audited. (#1781) - β¨ Set once per Schedule whether it stops or continues when a step fails, with each step able to follow the Schedule or override it (including via the new
Set-JIMScheduleStepcmdlet); existing Schedules behave exactly as before. (#1787) - β¨ A Schedule run that carried on past a failed step now ends Complete With Error, naming the failed steps, instead of a plain Complete, so the portal, PowerShell and monitoring scripts can tell it apart from a clean run. (#1787)
- β¨ The Connector Space list's new Columns menu shows or hides the External ID and Secondary External ID columns, remembered per Connected System in your browser, so an LDAP directory's list can show just the distinguished names.
ChangedΒΆ
- π Multi-valued attributes on Connected System Object and Pending Export pages now list their values in the row, as on a Metaverse Object, instead of behind +n more; over 10 get a scrolling table in the row. The Metaverse Object Table view gains search and sorting.
- π The portal is more compact, with smaller text, denser forms, buttons and tables, so more fits on screen; lists open with dense rows unless you chose otherwise.
- π The Connected System's Partitions & Containers tab is now called Scope: it is where you choose what JIM manages in a system, whatever shape that takes. Links to the old tab name open the Details tab.
- π The Password Channel check and the discovered Password Policy now sit on the Connected System's Passwords tab, beneath the Password Synchronisation settings, rather than on the Schema tab.
- π A Connected System's Schema tab now opens on a one-line status with a Refresh Schema button instead of a warning band, and each Object Type shows Attribute Selection before its settings.
- π The Auxiliary Classes panel on a Connected System Object Type now shows what the type is made of (its class plus the merged auxiliary classes) instead of listing every auxiliary class in the schema, so Attribute Selection is no longer pushed off the screen.
- π The Directory Capabilities card on a Connected System's Details tab is now a compact strip of detected facts beneath the form, with its explanation in an info button.
- π A Schedule step's failure setting now also covers a step that cannot be queued when the Schedule starts, and in parallel steps only a step that actually failed decides whether the Schedule stops. (#1768)
- π Deselecting an Object Type now takes it out of management: the next Full Import obsoletes its objects, as for a partition, and it is refused while an enabled Synchronisation Rule manages the type. (#1474)
- π JIM now serves HTTPS out of the box, with your organisation's certificate or one the setup script creates, so sign-in works from any machine without a reverse proxy. Before upgrading, put the certificate in the
tlsfolder beside the compose files. (#1808) - π The production compose file now publishes the web UI and API over HTTPS on the standard port, 443, so JIM's address needs no port (set
JIM_WEB_PORTto change it). - π The setup script installs in
/opt/jimwhen run as root, waits until JIM is ready, and keeps a copy of itself there to renew (--renew-certificate) or change (--certificate) JIM's certificate. (#1808) - π The Worker now reports healthy while it upgrades the database or warms its caches at start-up, so a long upgrade no longer looks like a hung Worker. (#1808)
- π JIM's services now wait for the database at start-up, logging each attempt, instead of exiting and restarting until it is available; an external database that is briefly unreachable no longer takes the web portal down. (#1808)
- π A Delta Import stopped because an Active Directory or Samba AD domain controller's invocationId changed now says the directory was probably restored from a backup or snapshot, why continuing would miss changes, and that a Full Import fixes it. (#1853)
FixedΒΆ
- π Sync Preview now reports an Attribute Flow whose Missing Input Behaviour is "Fail the object" as a blocking error, in the words the synchronisation records, instead of failing to preview, and lists generated values in the same order the synchronisation does.
- π A group with more members than Active Directory returns in one read (MaxValRange, 1,500 by default) now imports with every member, instead of failing as a configuration error naming
member;range=0-1499. (#1853) - π Schema, container and domain controller discovery on Active Directory now read page by page, so a forest with more attributes, organisational units or domain controllers than MaxPageSize (1,000 by default) no longer fails with "size limit exceeded". (#1853)
- π A signed-in administrator can now update or revert a Service Setting through the REST API (
PUT/DELETE api/v1/service-settings/{key}); the change is attributed to them instead of being refused with a misleading 400. API key callers and the portal were unaffected. (#1802) - π A queued Pending Export change is now withdrawn instead of exported once nothing authorises it (its Attribute Flow or Synchronisation Rule was disabled or removed, or the object left scope with Disconnect) or the Connected System already holds the value.
- π A Run Profile execution that fails while saving its changes to the database is now recorded as failed, with its error, instead of Complete. (#1874)
- π When a pinned domain controller stops answering, JIM now clears the pin as documented, so the next run re-discovers a domain controller instead of failing against the same unreachable one every time. (#1875)
- π An import that fails after reading its changes no longer moves the Connected System's change watermark on, so the next Delta Import reads those changes again instead of silently skipping them. (#1868)
- π Air-gapped installs with the bundled PostgreSQL now work on Docker's classic image store, which could not find the bundle's PostgreSQL image. (#1854)
- π Drift Correction now reverts an attribute edited in a Connected System whose import Attribute Flow reads a different attribute (a
displayNameedit where Display Name comes fromgivenNameandsn), instead of leaving the two out of step. (#1864) - π A Delta Sync that removes objects no longer skips others: when more than one page of changes included deleted objects, about half were left unprocessed until the next Full Sync (for example, a leaver's account deleted from a target directory stayed in JIM).
- π Running the setup script again over an installation with the bundled PostgreSQL no longer locks JIM out of its database: it keeps the database's password instead of generating a new one. (#1808)
- π New Docker installations no longer trust the development identity provider's token issuer,
http://localhost:8181/realms/jim, which the settings template set. On an existing one, delete theJIM_SSO_VALID_ISSUERSline from.envunless you added it yourself. (#1808) - π Installing with the setup script's bundled PostgreSQL works: it pointed JIM at
localhostinstead of the bundled database, so JIM never started. - π The release bundle's PostgreSQL image now loads under its name, so an air-gapped install with the bundled database finds it.
- π The setup script no longer stops at
Failed to download .env.example, and the manual download commands in the Deployment Guide and Quick Start work again: releases publish the environment template asdefault.env.example. - π A Synchronisation Rule attribute flow created with every inbound value processing option turned off is now saved that way; previously it was saved with "treat whitespace as no value" switched back on.
- π The LDAP Connector's Delete Behaviour setting now shows Delete, the value export uses when it is unset, instead of an empty dropdown.
- π Connected Systems now receive settings their Connector gains in a later release, and unset settings take a newly declared default, when JIM starts; previously these reached only Connected Systems created afterwards, so a new setting never appeared on existing ones.
- π The File Connector's import no longer fails when Delimiter is blank; it uses the default comma, as export already did.
- π Discover Domain Controllers, refused on a directory that is not Active Directory or Samba AD, now names the detected directory as the portal does elsewhere ("389 Directory Server") rather than by its internal identifier.
- π An auxiliary class's contributed attribute count (portal, REST and PowerShell) no longer includes attributes the Object Type already carries, such as the directory's common entry attributes, which overstated every class by the same few.
- π Opening JIM over plain HTTP from another machine no longer loops endlessly between JIM and the identity provider; sign-in stops on a page explaining that browser access from other machines requires HTTPS. A one-off lost sign-in cookie is still recovered automatically.
- π
Get-JIMScheduleExecution -Statusand the REST API's Schedule Execution list now return only executions with the requested status, instead of every execution. - π A Schedule with a step that cannot be queued, for example because its Connected System is being deleted, no longer runs its earlier steps and then reports Complete; it runs nothing, fails naming the step, and each step shows why it did not run. (#1768)
- π A Schedule Execution cancelled while a step is running now stays cancelled, instead of being marked Complete or Failed when that step finishes. (#1768)
- π An object that leaves scope but keeps its join is now recorded as Left scope, join kept, naming its Synchronisation Rule, rather than as an Attribute Flow that never happened and inflated the Activity's Attribute Flows count. (#1649)
- π A Synchronisation Rule or Attribute Flow disabled with a reason (as a schema refresh's "Apply and Disable Dependents" does), or re-enabled afterwards, is now classified in the configuration change history instead of being recorded without a classification. (#1753)
- π The SQL Connector now matches Microsoft SQL Server's legacy
datetimecolumns exactly, so a Delta Import no longer skips changes sharing a timestamp, stalls on them, or re-reads unchanged rows, and an export keyed on such a column finds its row. (#1451) - π Reordering an attribute's priority straight after deleting a contributing Synchronisation Rule no longer fails while its values are being recalled: the rule drops to the bottom and may be left out. A refused order now names what is missing. (#1597)
- π On Oracle Database, a Delta Import reading a
TIMESTAMP WITH TIME ZONEwatermark or change-log column no longer skips or re-reads changes when the Connected System's Database Time Zone is not UTC. (#1783) - π A new deployment using the bundled PostgreSQL container now starts, instead of failing to create its database because of the
LANGsetting in.env. - π A production deployment is now reachable at the address the setup script gives, and the
jim.webcontainer reports healthy instead of unhealthy. - π The air-gapped release bundle no longer ships development settings (a demo Keycloak with
admin/admin, PostgreSQL open on port 5432) thatdocker composeapplied automatically when run without-f. - π Case-insensitive Object Matching Rules treated
_and%as wildcards, soj_smithcould matchjxsmithand join the wrong object, on inbound joins and export matching alike; they now require an exact case-insensitive match. - π Filtering Metaverse Objects by attribute value (REST
filterAttributeValue,Get-JIMMetaverseObject -AttributeValue) treated_and%as wildcards and could return objects with a different value; it now returns only exact case-insensitive matches. - π JIM's services now exit with a failure code when they stop on an error, instead of reporting a clean stop to the container runtime, systemd or monitoring. (#1808)
- π A synchronisation that fails while saving its progress is now marked Failed straight away, instead of only after two further attempts that logged misleading database errors.
- π Deleting a Pending Export no longer leaves its attribute changes behind in the database, where they accumulated indefinitely. (#1818)
- π Synchronisation no longer reopens Failed Pending Exports, or counts errors against exports awaiting confirmation; this could silently strand an export outside both the export queue and the Failed list.
- π A Failed Pending Export now clears automatically once a confirming import shows every change it asserts has taken effect, without waiting for a manual retry.
- π A Pending Export interrupted by a worker crash or restart mid-export is recovered when the worker next starts, instead of being stranded in Executing forever.
- π A cancelled import no longer records the connector's new watermark when it staged nothing, so the next Delta Import reads from the watermark the cancelled run started with instead of silently skipping the changes it never imported. (#1853)
SecurityΒΆ
- π The setup script makes
.env, which holds the database password and the identity provider's client secret, readable by its owner only. (#1808) - π The Worker container no longer holds the
SYS_ADMINandDAC_READ_SEARCHLinux capabilities, which it never used. (#1808) - π On Docker, the bundled database container no longer receives JIM's settings and secrets, such as the identity provider's client secret, which PostgreSQL never used. (#1862)
PerformanceΒΆ
- β‘ Synchronisation no longer queries the database once per object to look for an existing target object before provisioning; it checks once per page, speeding up large initial synchronisations.
- β‘ Large imports do much less database work: new objects are no longer looked up one at a time, the object type's schema is no longer reloaded for every object, and checking that provisioned objects were created no longer loads each one in full.
- β‘ Synchronisation starts and writes faster: it skips a redundant lookup when provisioning, and writes each page of objects, Pending Exports and Activity results in bulk.
0.15.0 - 2026-09-23ΒΆ
AddedΒΆ
- β¨ An info icon beside key terms such as Projection, Join, Connector Space and Pending Export explains each one where you first meet it, with a link to the glossary. (#1670)
- β¨ Service Health on Administration > Operations shows whether the Worker and Scheduler are healthy, what each is doing and which version it runs, with a portal-wide banner if one stops or stalls; also via REST and
Get-JIMServiceHealth. (#1635) - β¨ Run Profile Safeguards cap how many creates, updates and deletes an Export may attempt, and how many deletions a Full Import may detect, so a broken filter or mistaken rule change warns instead of making mass changes. (#1618)
- β¨ A new Data Flow view under Administration > Schema lists every Attribute Flow across all Connected Systems in both directions, showing where each attribute's value comes from and what writes it out; also via REST and
Get-JIMDataFlow. (#1199) - β¨ Data Generation Templates can now be created, updated and deleted through the REST API and PowerShell, validated as a whole before anything is saved; built-in templates stay protected. (#894)
- β¨ The Schema Object Types and Attributes tabs can now be filtered, by Deletion Rule, data type, plurality, built-in status and Metaverse Object Type.
- β¨ A Connected System's details page shows a Directory Capabilities card with what JIM has detected about an LDAP directory, such as its type, vendor, paging support and pinned domain controller; also via REST and PowerShell. (#231)
- β¨ The Synchronisation Rules list can now be filtered by Connected System, direction, action and status alongside the search box, with the same filters on the REST API and
Get-JIMSyncRule. - β¨ The Activity history can now be filtered from the REST API and
Get-JIMActivityby operation, outcome, status, initiator, date range, Connected System, Run Profile and Schedule, with combined filters matching the portal's results exactly. - β¨ Deleting Metaverse Objects when an authoritative source disconnects can now wait until all selected sources have gone (the new default), so one source system failing or being rebuilt cannot trigger deletions. (#119)
- β¨ The LDAP Connector now pins connections to a single Active Directory or Samba AD domain controller, avoiding the replication-lag and Delta Import risks of reaching a different one each run; a Preferred Domain Controller can be named instead. (#230)
- β¨ A Discover... action beside the LDAP Connector's Preferred Domain Controller lists every domain controller in the forest with its Site, in the portal, REST API and PowerShell (
Get-JIMConnectedSystemDirectoryServer). (#1167) - β¨ A directory's own configuration and operational object classes, such as OpenLDAP's
cn=configclasses and 389 Directory Server's console classes, are now hidden on a Connected System's Schema tab; Show internal object types reveals them. (#434, #1745) - β¨ JIM now warns when a When Last Connector Disconnected Deletion Rule will keep Metaverse Objects alive because provisioned objects still count as connectors, and Activities record the values preserved at each disconnection. (#1570)
- β¨ Deleting a Connected System now offers Deprovision through synchronisation (the default), processing every object as a normal disconnection as a monitored, resumable operation, or immediate deletion that keeps contributed data. (#809)
- β¨ Deleting a Synchronisation Rule or Attribute Flow that contributed Metaverse values now asks whether to recall them (the default, letting surviving contributors take over by Attribute Priority) or keep them; rule recalls run as a monitored background operation. (#1533, #1537)
- β¨
Remove-JIMSyncRule -Waitblocks until a Synchronisation Rule's value recall has finished and the rule has gone, so scripts no longer race the background deletion; a recall that fails or times out is reported as an error. (#1597) - β¨ After a Connector Space clear and re-import, the next Full Synchronisation applies each type's Deletion Rule to objects that did not return, honouring grace periods, and refuses if far fewer objects returned than were cleared. (#1605)
Sync PreviewΒΆ
- β¨ Sync Preview shows what synchronising a Connected System Object or Metaverse Object would do, including whether a Metaverse Object would be deleted and which downstream objects would be deprovisioned, without changing anything. (#1519)
- β¨ A Metaverse Object's new Connections tab lists every joined Connected System Object with its role, join type and State; the same detail is returned by the REST API and
Get-JIMMetaverseObject. (#1519) - β¨ The Connector Space list now shows each object's State (In sync, Update pending, Export failed, Obsolete and more), also on the REST API and
Get-JIMConnectedSystemObject. (#1519) - β¨ Attribute value changes now record which Synchronisation Rule contributed each value, across change history and Pending Exports, in the portal, REST API and PowerShell. (#1519)
Configuration Change PreviewΒΆ
- β¨ A configuration change can now be previewed before it is saved, starting with a Metaverse Object Type's deletion settings: see which Metaverse Objects would become, or stop being, eligible for deletion, and drill into them. (#827, #1114)
- β¨ Saving a configuration change that affects synchronisation now confirms what changed, with before and after values and a plain statement of anything that could delete or disconnect objects; cosmetic edits save without a prompt. (#827)
- β¨ Connected Systems now show when configuration changes are waiting on a Full Synchronisation to take effect, with a distinct warning when one is destructive; also on the REST API and
Get-JIMConnectedSystem. (#827) - β¨ A Configuration Change Preview opens with a plain-English summary of what saving would do, worst consequence first, and names the kind of edit each row describes, such as a domain change, a container move or a case-only change. (#827, #1275)
- β¨ Connected System changes can now be previewed before saving: deselecting Object Types, attributes, partitions or Containers, and changing Object Matching Rules, each report which objects would stop importing, disconnect or join differently. (#1251, #1457, #1475)
- β¨ Synchronisation Rule changes can now be previewed before saving: Attribute Flow, Scoping Criteria, deprovisioning actions and the rule's behaviour switches each report which objects would be affected and how. (#1115, #1436, #1437, #1443, #1462)
Schema RefreshΒΆ
- β¨ Refresh Schema now shows what changed (additions, removals and data type changes) before anything is applied, so you can apply or discard it; also via REST and
Import-JIMConnectedSystemSchema -Preview. (#421) - β¨ A destructive schema refresh now offers a clear choice: cancel, apply as-is, apply and disable the Synchronisation Rules and Attribute Flows it invalidates, or apply and remove them for a decommissioned Object Type or attribute. (#1485)
Attribute FlowΒΆ
- β¨ An individual Attribute Flow can now be disabled (or created disabled) without touching the rest of its Synchronisation Rule, in the portal, REST API and PowerShell. (#1485, #1537)
- β¨ An Attribute Flow's settings, such as its Expression or Initial Export Only, can now be changed in place over the REST API and
Set-JIMSyncRuleMapping, keeping its Attribute Priority position. (#1361) - β¨ An Expression can now choose what happens when an attribute it reads has no value: evaluate anyway (the default), contribute nothing, or fail the mapping or the object, so structurally broken values never flow. (#1361)
- β¨ An Expression can now be tested where it is written in the portal, with a box for each attribute it reads, so a malformed result is caught before the Synchronisation Rule is saved. (#1405)
- β¨ The Attribute Flow editor now shows where a new inbound mapping sits in its Metaverse Attribute's priority order, and Null is a value can be set there and via
New-JIMSyncRuleMapping. (#1199) - β¨ The Attribute Flow editor now suggests the Metaverse Attribute (or, for export, the Connected System attribute) a Standard Mapping pairs with your source, with one-click apply, and explains any suggestion it cannot apply. (#1122)
Partitions and ContainersΒΆ
- β¨ A selected Container can now import only the objects held directly in it (This level only) rather than its whole subtree, letting Containers beneath it carry their own scope. (#351)
- β¨ Each Container now shows how many objects it holds, read from the Connected System itself, so you can decide what to manage before the first import. (#1276)
- β¨ A Container can now be excluded from a selection made above it, with nesting and previews, and each import reports how many objects every exclusion removed. (#1255)
- β¨ Container Scope can now be edited as text, one statement per line, so it can be pasted, reviewed, kept under version control or copied between Connected Systems; also via PowerShell. (#1255)
LDAP Auxiliary Object ClassesΒΆ
- β¨ Auxiliary object classes on OpenLDAP and 389 Directory Server (such as
posixAccount) can now be merged into an Object Type, making their attributes available to flow; JIM adds the class on export alongside the attributes that need it. (#492) - β¨ Object Types defined by an auxiliary class can now be provisioned by naming the Structural Carrier Class to create them with. (#492)
- β¨ Auxiliary class discovery reports which classes a directory's entries actually carry, by quick sample or full scan, to guide which to merge; it changes no configuration. (#492)
SQL ConnectorΒΆ
- β¨ The new SQL Connector synchronises with Microsoft SQL Server and Oracle Database tables and views, with Full and Delta Imports and exports, nothing native to install, and encrypted connections by default. (#170)
- β¨ An attribute can now be marked Set on creation only, so a table keyed on a natural identifier such as an employee number can be provisioned into without JIM ever rewriting the key. (#170)
- β¨ Oracle whole-number columns are now read as whole numbers, so they can flow into built-in numeric Metaverse Attributes such as Employee Number; refresh an existing Connected System's schema to adopt this. (#1354)
- β¨ The data type JIM inferred for a SQL or Oracle attribute can now be corrected per attribute on the Schema tab until the attribute is in use; also via REST and
Set-JIMConnectedSystemAttribute. (#1354)
CertificatesΒΆ
- β¨ When an LDAPS connection fails because of the directory's certificate, JIM now shows that certificate, which check it failed and what to do, when testing settings and on the failed Activity. (#1132)
- β¨ A server's certificate can now be trusted straight from the failure that reported it, or fetched in advance from a Connected System's settings, after confirming its thumbprint; also via REST and PowerShell. (#1139)
PasswordsΒΆ
- β¨ Password Synchronisation now delivers: each change is queued encrypted per Connected System and sent by a dedicated Password Delivery Service within about a second, with retries, parking of refused changes, and only the newest password sent. (#1119, #1635)
- β¨ Password Synchronisation can now be configured per Connected System on a new Passwords tab, setting the target Object Type and retry behaviour, with a separate enable switch so it can be prepared ahead of a change window. (#1119)
- β¨ Only send passwords over an encrypted connection makes a Connected System refuse to send any password over a connection JIM cannot confirm is encrypted, leaving the work queued rather than warning and sending anyway. (#1119)
- β¨ REST endpoints that accept a password refuse requests unless the transport is confirmed encrypted, with guidance for TLS terminated at a reverse proxy JIM has not been told to trust. (#1119)
- β¨ Set Password resets a person's password on the accounts you choose (none selected by default), generated to satisfy the strictest policy among them, or propagates their own change to every system using Password Synchronisation. (#1119, #1172, #1635)
- β¨ An administrator can now set the password on a single account from its Connected System Object, typing one or generating one that meets the system's policy, with masked copy and every attempt recorded as an Activity. (#1121)
- β¨ Setting a password over the REST API or PowerShell (
-Wait) can now wait up to 30 seconds and report what each Connected System did with it, so a service desk can confirm a reset has landed. (#1635) - β¨ Automation can ask JIM to generate a password that satisfies each target system's discovered policy (
-Generate), and read a system's policy withGet-JIMConnectedSystemPasswordPolicy. (#1121) - β¨ A person's page now has an administrator-only Password tab showing what is still owed to each Connected System, with Retry, and what their recent password changes did on each. (#1119, #1635)
- β¨ A new Passwords tab on Administration > Operations lists every queued password change with the target system's own error, counts and filters, never the password itself; also via REST and
Get-JIMPendingPasswordChange. (#1119, #1635) - β¨ Queued password changes can be retried or cancelled, singly or in bulk, from the portal, REST API and PowerShell; a cancellation is recorded with who and when rather than silently deleted. (#1119)
- β¨ The Connected Systems list now shows each system's Password Synchronisation state with parked and expired counts, and a Needs attention filter. (#1119)
- β¨ Password Synchronisation history has its own retention period (a year by default), which also bounds how long JIM holds a password it cannot deliver; changes still owed are never removed. (#1119)
- β¨ A Synchronisation Rule now warns when an Attribute Flow targets an attribute whose name suggests a password, pointing you to Password Synchronisation instead. (#1119)
- β¨ Connected Systems that accept passwords show the password policy JIM read from the system and a safe, read-only Check password channel test covering encryption, mechanism, permissions and policy. (#1121)
- β¨ Password policy discovery now covers OpenLDAP (with the ppolicy overlay) and 389 Directory Server as well as Active Directory, so generated passwords meet each directory's own rules. (#1702)
- β¨ Newly provisioned accounts receive their initial password within seconds, owed for a window each Connected System sets; one the target refuses is parked until the Synchronisation Rule's initial password settings are corrected, and saving them retries it. (#1221, #1316, #1697)
- β¨ A Synchronisation Rule can now give every account it provisions one chosen initial password, so new starters can be told it; JIM advises against it, stores it encrypted and write-only, and requires a change at next sign-in by default. (#1273)
- β¨ The Synchronisation Rules list and each rule's Passwords tab now flag accounts parked or expired waiting on their initial password, grouped by what the target system said, and confirm how many a fix will release. (#1221)
Run ProgressΒΆ
- β¨ A Run Profile execution's Activity now shows its whole journey as a stepped progress bar, including the Connector's own steps, with durations for finished steps and the step a failed run stopped in. (#454)
- β¨ Imports now show how far through they are: file imports show a percentage and time remaining, and directory imports, including large Delta Imports, show counts and rate as objects arrive. (#454)
- β¨ Long-running File and LDAP Connector work now reports what it is doing on the Activity, so a healthy long phase can be told apart from a stuck run. (#637)
- β¨ The Operations queue now shows each running task's steps and progress, and each running Schedule as a step rail with every parallel task's outcome. (#1162)
- β¨ Automation sees the same steps: the REST API,
Start-JIMRunProfile -Wait,Get-JIMActivity -Follow,Get-JIMWorkerTaskandGet-JIMScheduleExecutionreport progress as "Step 3 of 7: Saving changes". (#454, #1162)
CausalityΒΆ
- β¨ A Run Profile Execution Item's Causality Tree is replaced by a redesigned causality panel: a plain-English summary above Lineage, Timeline and Table views, events in plain language, searchable attribute changes and links to every object involved. (#1087, #1495)
- β¨ The Lineage view, which opens first, traces an outcome from its source records through the Metaverse Object to its targets and back to the root cause, highlighting this run's events, and still reads correctly after the objects involved are deleted or renamed. (#1223, #1495)
- β¨ Export Run Profile Execution Items now trace their causal chain back through the synchronisation and import that led to each change, linking to each run along the way. (#1223)
- β¨ The Table view lists every change flat, filterable and sortable, grouped by the object each one touched. (#1519)
- β¨ Every card on the Lineage view, queued exports included, carries a coloured Created, Updated, Deleted or Joined marker, so an export states what it did rather than a bare "Exported". (#1495)
- β¨ The causality panel notes when a Metaverse Object was deleted after the run you are viewing, with a link to its deletion record, rather than leaving a dead end. (#1495)
- β¨ When a rejoin cancels a scheduled Metaverse Object deletion, the Lineage now records which Connected System rejoined and which Deletion Rule allowed it. (#1620)
SCIM 2.0 Client Connector (#545)ΒΆ
- β¨ JIM now synchronises with any system offering a SCIM 2.0 service provider interface, using one standards-based Connector: it reads the provider's schema, imports users and groups with their memberships, and exports changes back.
- β¨ Delta Imports request only what changed where the provider supports it, and exports send only what changed, preserving attributes JIM does not manage and guarding against overwriting changes JIM never saw.
- β¨ A SCIM connection refused over certificate trust now shows the certificate the provider presented, so you can verify its thumbprint and trust it under Admin > Certificates.
- β¨ Provider rate limits are respected: JIM honours
Retry-After, backs off with jitter and paces itself, reporting throttling as a warning rather than failing the run. - β¨ A schema import that had to work around gaps in what a provider publishes now says so, on the schema refresh summary and as a warning on its Activity.
- β¨ An optional Use Bulk Operations setting sends exports in batches to providers that support SCIM Bulk, considerably faster over high-latency links; it is off by default, and falls back to per-object requests if the provider does not serve it.
Schedule Execution visibility (#1196)ΒΆ
- β¨ The Schedules list now shows how each Schedule's last run ended, naming the step a failed run stopped on, and each Schedule's history button opens a list of all its executions.
- β¨ A new Schedule Execution view shows every step of a run with its outcome, duration and a link to its Activity, so a failed overnight run no longer has to be pieced together.
- β¨ Activities produced by a Schedule now link back to the run and step, and the Activity history can be filtered by Schedule, even after the Schedule is deleted.
ChangedΒΆ
- π Delta Import against 389 Directory Server now refuses to run, and Schema Discovery warns, when the Retro Changelog plug-in is not recording deletions, naming the setting to turn on so no deletion is silently missed. (#1479)
- π An LDAP Delta Import with no change watermark to start from now performs a Full Import and completes with a warning, for every directory type and in line with the SQL and SCIM Connectors, instead of failing. (#1725)
- π₯οΈ The Partitions & Containers tab has been redesigned around what you import: a summary of the selection, readable Container names, a filter, a clearer Container Scope control, and Preview Changes beside Save. (#351)
- π₯οΈ In a Connector Space, a value still waiting on a Pending Export is shown muted and italic with a clock, and its tooltip says whether it is staged or exported and awaiting confirmation; the REST API and PowerShell gain
pendingExportStatusto match. - π₯οΈ Page descriptions now open from an info button beside the page title rather than sitting as text beneath it, and alerts across the portal have a cleaner, borderless style.
- π The portal now speaks one vocabulary: Connected System Object and Metaverse Object are written in full, objects are named by type and Connected System ("user Jane Smith in Contoso AD"), and the causality panel uses the portal's own outcome names. (#1666, #1667, #1669)
- π An export no longer writes objects outside the Containers selected on a Connected System, where JIM cannot read them back; it fails with an error naming the Distinguished Name. Behaviour change: select any Container you deliberately export into before upgrading. (#827)
- π The Activity that deletes Metaverse Objects once their grace period ends is now called Scheduled Metaverse Object Deletion (formerly Metaverse Object Housekeeping); Activities recorded before this release keep their original name. (#1668)
- π₯οΈ Every object the portal names, from Metaverse Objects to Synchronisation Rules and Pending Exports, now appears as the same linked chip everywhere, including the causality panel and Configuration Change Previews, with its external ID in the tooltip.
- π A Synchronisation Rule's Connected System, direction and Object Types now sit in a strip beneath the breadcrumbs, visible on every tab, with the arrow drawn the way data flows.
- π Clearing a Connector Space through the REST API or PowerShell now runs as a tracked background operation with a full audit trail, as it does in the portal;
Clear-JIMConnectedSystemreturns a tracking object and gains-Wait. (#1549) - π An Object Matching Rule whose scope does not suit the Connected System's matching mode is now refused by the REST API and PowerShell rather than created silently inert, and switching matching mode warns about any rules it would strand. (#1569)
- π When a source disconnects, JIM now recalls its attribute values only while another source still stands behind the object; an object left with only provisioned target accounts keeps its last known values, protecting live accounts from a transient source outage. (#1570)
- π₯οΈ A Connected System now shows how many of its objects are obsolete and waiting on a Synchronisation Run Profile, with a Review link, and the Connector Space can be filtered by the Obsolete status. (#1527)
- π A Synchronisation Rule now refuses a second Attribute Flow to an attribute it already flows to, which was accepted but never honoured; an existing duplicate is refused on its next save, so replace it with one
Coalesceexpression or a second Synchronisation Rule. (#1532) - π History retention now runs as History Retention Cleanup, a built-in Schedule running daily at 02:30, so you can see when it last ran and what it removed, and re-time or pause it like any other Schedule. (#1118)
- π Built-in configuration added in a new release (Metaverse Object Types, Predefined Searches, Example Data Sets, Schedules and Roles) now reaches existing deployments on upgrade, leaving everything you have changed untouched. (#916)
- π A factory reset now restores all of JIM's built-in configuration, and re-applies read-only Service Settings (such as SSO endpoints) from the deployment's environment variables. (#916)
- π Breaking: REST API responses for Connector Definitions, Example Data Sets, Data Generation Templates and Predefined Searches are now purpose-built; scripts reading a Predefined Search's
metaverseObjectTypeshould readmetaverseObjectTypeName. (#1447) - π An outbound Synchronisation Rule can now write back into the Connected System an inbound rule reads from, so a derived value such as an email address reaches the system the data came from. (#1284)
- π₯οΈ Lists and tables throughout the portal now scroll continuously instead of paging, showing their size beside the search box and searching and sorting across the whole list, so a list of eight hundred thousand objects reads as easily as one of eight.
- π₯οΈ Scrolling table rows are now one line tall: a cell holding several values shows the first with +n more to open the rest, and long text shows in full on hover.
- π An account queued for removal now shows as Deprovision queued in the causality views rather than as an ordinary attribute export. (#1087)
- π View deletion record in the causality views now opens the deleted object's own change history, and Deleted Objects accepts bookmarkable
?mvo=<id>and?cso=<id>links. (#1087) - π A Pending Export in the causality views now links to that individual Pending Export rather than the Connected System's whole queue. (#1087)
- π Objects without a display name, such as LDAP groups, now show their common name or name throughout the portal instead of a raw identifier.
- π Search boxes across the portal now filter as you type; the query forms on Deleted Objects and Admin > Logs still run when you press Search. (#864)
- π The REST API now limits paging depth by rows retrieved (1,000,000) rather than page number, so far larger result sets can be paged through; every request accepted before is still accepted. (#487)
- π Error stack traces are now tucked behind a Show stack trace toggle wherever JIM reports an error, so the error message itself leads. (#1132)
- π A Delta Import against Active Directory or Samba AD now fails fast with a clear error if it reaches a different domain controller from the one its watermark came from; run a Full Import to re-establish the baseline. (#230)
- π A Connected System's Connector Space and Pending Exports now sit above its tabs with their counts, reachable from anywhere on its page. (#231)
- π A Metaverse Object reappearing during its deletion grace period now cancels the deletion only if it reverses the disconnection that triggered it. (#119)
- π Deletion decisions are now explained from facts recorded when they were made, on the Activity and the Pending Deletions page, so the explanation stays accurate after rules are edited. (#119)
- π Breaking: a successful Schedule Execution's status is now
Complete, notCompleted, matching Activities; update any REST or PowerShell script that filters onCompleted. (#1196) - π₯οΈ A Run Profile execution item's detail page is now split into tabs, with any Pending Export the item created or failed on on its own tab.
- π₯οΈ The Projection Details and Metaverse Impact sections have been retired from execution item pages; the causality panel now tells that story, including a Metaverse Object not deleted step giving the reason a Deletion Rule chose not to delete. (#1223)
RemovedΒΆ
- ποΈ The LDAP Connector's Certificate Validation setting has gone, and LDAPS certificates are now always validated; trust a directory's certificate in Admin > Certificates, and fix a name mismatch with a host entry rather than weakening validation. (#1132)
FixedΒΆ
- π A Schedule that cannot start (for example, because one of its steps runs against a Connected System that is being deleted) now fails once per scheduled run and is tried again at its next run time, instead of failing again every few seconds until the cause is fixed. (#1765)
- π Delta Import from 389 Directory Server and other changelog-based directories now returns changes, applies deletions, follows renames, and no longer fails with "Duplicate external ID" when an object changed more than once since the last import. (#1479, #1725)
- π A Delta Import from OpenLDAP, 389 Directory Server or a generic LDAP directory now fails with a clear remedy when the account JIM connects as cannot read the accesslog or changelog, instead of completing with no changes; Schema Discovery warns of the same gap. (#1725)
- π A Delta Import from Active Directory or Samba AD now imports every deletion: it pages its search of the Deleted Objects container, and fails fast or warns when the account JIM connects as cannot list that container, instead of silently importing none. (#1723, #1724)
- π An import the directory stops at its search limit now refuses before importing anything from that container, naming the container and explaining that the account JIM connects as needs exempting from the directory's search limits.
- π The LDAP Connector's hierarchy import now skips, with a warning, any naming context the service account cannot read, rather than failing the whole import. (#1715)
- π A Full Synchronisation no longer loses a group's provisioning when the group is processed on an earlier page than its members; the group is now created with its members rather than failing at export.
- π Provisioning withdrawn before it was exported is now cancelled cleanly: JIM exports nothing and reports Provisioning cancelled, rather than failing a Delete export or later creating an account for someone out of scope.
- π Provisioning exported but not yet confirmed by an import is now handled correctly: later changes go as a single Update rather than a second Create, an unconfirmed Create is retried, and an object deprovisioned in the meantime is removed once its Delete is exported.
- π A synchronisation run no longer fails with a duplicate-key database error, or loses a scheduled deletion, when a Metaverse Object is scheduled for deletion or a joined Connected System Object falls out of scope partway through the run. (#1610)
- π Two outbound Synchronisation Rules targeting the same Connected System for one Metaverse Object no longer crash a synchronisation run with an unreported error; the clash is reported against the object and the run continues. (#1331)
- π Synchronisation runs no longer end with a warning for every correctly provisioned person when two outbound Synchronisation Rules with non-overlapping scopes export different Object Types to the same Connected System. (#1399)
- π An export whose reference cannot be resolved yet now writes everything else straight away and fills the reference in later, so an account whose manager is out of scope is still created, and a reference that can never resolve is reported. (#1398)
- π Import reference resolution now respects Object Types: two sharing anchor values no longer fail the import, an ambiguous reference is reported rather than guessed, and references to earlier-imported objects resolve whatever the anchor's data type. (#1285)
- π A deleted Connected System Object is now reported once, by the first import that finds it missing, rather than again on every import until a synchronisation runs, which inflated deletion totals and Causality. (#1527)
- π After a Connector Space is cleared and re-imported, the next Full Synchronisation now recalls the values its departed objects contributed, handing each attribute to a surviving contributor or clearing it, with the outcome reported on the Activity. (#1549)
- π A data type an administrator chose for a Connected System attribute now survives a schema refresh, instead of being silently reverted in a way that could write values to the wrong place on the Metaverse Object. (#1354)
- π Object Matching Rules added in the portal's Matching tab now name the Metaverse Object Type they search, so they match instead of silently projecting duplicate Metaverse Objects; rules that could never match are refused or flagged. (#1458)
- π Object Matching Rules are now kept and cleared correctly: saving an export Synchronisation Rule in advanced matching mode no longer wipes them, and clearing them deletes them rather than leaving hidden orphans that blocked deleting the Connected System. (#1589)
- π Switching a Connected System's matching mode now works with API key authentication, so
Switch-JIMMatchingModeand the REST endpoint can be used from automation. (#1569) - π Deleting a Synchronisation Rule, or removing one of its Attribute Flow mappings, now removes everything it owns rather than leaving hidden orphaned configuration behind; orphaned mappings from earlier removals are cleaned up on upgrade. (#1477, #1550)
- π A Connected System that imported a nested Container hierarchy (an OU inside an OU) can now be deleted instead of failing with a save error. (#1477)
- π Schedules now run on their cron trigger; a cron-triggered Schedule never fired on its own, and only running one by hand worked. (#1514)
- π The Worker's memory no longer grows with every task it runs, and its housekeeping now acts on Synchronisation Rule and Metaverse Object Type changes straight away, so an export rule switched from Delete to Disconnect stops deleting without a Worker restart.
- π A failed Worker task can no longer stop the Worker processing further queued operations until it is restarted. (#1568)
- π A Run Profile execution item's error heading now names the phase the problem happened in, so import errors a Connector reports, and some export errors, are no longer headed "Synchronisation Failed". (#1150)
- π An instance interrupted while creating its built-in configuration now recovers on the next start, and an upgraded instance now receives any built-in Connector added since it was installed. (#1287)
- π A factory reset now completes on deployments with SSO configured or custom configuration such as a Predefined Search's criteria, instead of failing with a 409 or foreign-key error. (#1477)
- π A finished import's Activity now summarises the whole run, with objects read, created, updated, errors and throughput, instead of showing "0 / 0" from its last internal step. (#170)
- π The causality view now nests Provisioning and Pending Export outcomes beneath the Attribute Flow that produced them, and an execution item's Attribute Flow count includes references resolved at the end of a batch. (#1428)
- π The Metaverse Object detail API now returns the object's joined Connected System Objects in its
connectedSystemObjectsfield, which always came back empty. (#1606) - π
Set-JIMApiKeynow updates an API Key with a single role, or no roles, without a validation error. (#1531) - π PowerShell cmdlets that accept a name in place of an id now find it however long the list, rather than reporting "not found" for anything beyond the first page. (#894)
- π Client IP addresses from IPv4 connections are now recorded in plain IPv4 form on Authentication Activities and in logs, without the
::ffff:prefix, so one client no longer occupies two rate limit buckets. - π The home page's Run your first synchronisation step now ticks when any Run Profile is run, including by hand, not only when a Schedule fires. (#1482)
- π Button labels, chips and selected filter chips now meet WCAG AA contrast in every theme, including outlined and text buttons on the light themes and Black Dark. (#1495, #1527)
- π A long attribute value in a Change History card now ends in an ellipsis with the full value on hover, and uses the card's full width, instead of being cut off mid-value.
- π Several portal elements now read clearly on every theme: the Connector Space and Pending Exports button counts, the Created and Updated chips on hover, selected Object Types on the Schema tab, and selection highlights, which now take the theme's own accent.
- π The Pending Deletions summary cards, the REST API and
Get-JIMPendingDeletion -Summarynow count every object awaiting deletion rather than the first hundred, and honour the Metaverse Object Type filter. - π My Activity now filters the list when chosen from the Activity page, the navigation no longer highlights both entries at once, and the Initiator filter is disabled on that view.
- π Returning to a stale sign-in page (a restored tab, the back button, or a refresh) now restarts sign-in cleanly and takes you where you were headed instead of showing an error page; every failed attempt is still recorded as a security Activity.
- π Partition discovery against Active Directory and Samba AD no longer fails with an access denial on a working, authenticated connection: JIM now declines LDAP referrals rather than following them anonymously. (#1352)
- π A Metaverse Attribute value is now credited to the Synchronisation Rule that wins Attribute Priority, so deleting a contributing Rule no longer leaves values unowned, and a lower-priority source can no longer overwrite the winner's value. (#1292)
- π Deleting an Attribute Flow from a Synchronisation Rule over the REST API or with
Remove-JIMSyncRuleMappingnow works; it previously failed every time. - π Object Types anchored on a 64-bit whole number or a decimal now import correctly, with deletions detected and no duplicates created. Run a Full Import after upgrading to catch deletions missed while this was broken. (#1283)
- π An export no longer fails when Drift Correction and a fresh Metaverse value are staged against the same attribute of the same object; the new value now supersedes anything else staged for it. (#1199)
- π An import Synchronisation Rule's Scoping Criteria are now honoured when its Attribute Flows run, so one system can own a defined subset of objects while another holds the rest, and two Rules competing for a single-valued attribute no longer both write. (#1199)
- π Adding, removing or retargeting an inbound Attribute Flow in the portal now maintains the Metaverse Attribute's priority order, as the REST API and PowerShell already did. (#1199)
- π Delta Imports from OpenLDAP and other changelog-based directories now honour the selected Containers, so they no longer import objects a Full Import would never return. (#351)
- π The Connector Space now shows, searches and sorts on every Connected System Object's External Id, including Active Directory and Samba AD objects anchored on
objectGUID. (#1286) - π Containers discovered from directories other than Active Directory are now named after their leaf component (
Sales) rather than their whole Distinguished Name; refresh the hierarchy to rename existing ones. - π A Schedule Execution containing parallel steps now reports its true number of steps, so its progress reaches its own total in the portal and the REST API.
- π Deleting a Connected System that still had a queued Clear Connected System Objects task no longer empties the Operations queue.
- π A queued task whose Connected System or Run Profile has since been deleted now names what it was going to act on, rather than reporting "Run Profile not found!".
- π The Operations queue no longer opens a separate database connection for every row it displays, which on a busy queue added up to a connection per task per update.
- π A Connected System's settings can now be saved after changing a setting that controls which others apply: settings that no longer apply stop blocking Save Settings with leftover "is required" errors.
- π Saving a change while a Connected System's external system is temporarily unreachable no longer takes away its Schema, Partitions & Containers and Matching tabs.
- π Renaming or moving a Container in a directory no longer silently takes it out of import scope: JIM now tracks Containers by the directory's immutable identifier, so your selection survives. (#827)
- π A Container created in a directory since the last hierarchy refresh now appears on the Partitions & Containers tab, so it can be selected. (#827)
- π Deselecting a Partition now takes effect on every Run Profile, and a Run Profile left targeting a deselected or missing Partition is refused with a clear error and marked Not selected in the portal, REST API and PowerShell. (#827)
- π Problems a Connector reports with an individual imported object now appear on the Activity instead of being discarded, so an import of malformed data no longer finishes looking clean. (#637)
- π A Full Import no longer fails outright when one imported object names an Object Type missing from the schema; that object is reported and the rest import. (#637)
- π A setting withdrawn from a Connector no longer lingers on Connected Systems that already held a value for it. (#1132)
- π Saving an LDAPS Connected System's settings, or retrieving its schema or hierarchy, no longer hangs in the portal when certificates are present in Admin > Certificates. (#1132)
- π Retrieving or refreshing a Connected System's hierarchy from the portal no longer fails with a database error when it discovers a new Partition or Container.
- π A failed schema or hierarchy retrieval now finishes its Activity as failed with the reason, instead of leaving it in progress for ever.
- π Importing a schema through the REST API or PowerShell now auto-selects a Connected System's only Object Type, as the portal does, so every surface produces the same configuration.
- π The REST API's pagination depth limit now protects every paginated endpoint, including the largest lists such as the Connector Space and Pending Exports. (#487)
- π
-All -Forceon the paginatedGet-JIM*cmdlets now stops at the API's maximum retrieval depth with a warning, after returning everything it could, instead of failing part-way. (#487) - π
Get-JIMSyncRulenow returns every Synchronisation Rule rather than only the first 25. - π Saving a Metaverse Object Type's Deletion Rules no longer fails with a database error on any type with attributes bound.
- π Piping a Connected System into
Get-JIMSyncRule, as its documentation shows, now works. - π The Pending Exports list can once again be sorted by its Source Metaverse Object column, and searching it by name once again returns matches.
- π Selecting a Partition for a domain the connected Active Directory or Samba AD domain controller does not host now fails the import with clear guidance, instead of silently importing nothing. (#230)
- π
Start-JIMSchedule -Waitnow waits for the run to finish rather than returning immediately while it is still queued. (#1196) - π Re-running Schema Import after the directory gains new attributes no longer fails with a duplicate key error, and a failed Schema Import no longer partially applies. (#1171)
- π After an upgrade your browser now loads the new interface straight away, theme colours included, without a hard refresh, because the portal's stylesheets and scripts are versioned by their content.
- π A newly created Metaverse Object is no longer described as
00000000-0000-0000-0000-000000000000in the causality record. (#1087) - π The Pending Deletions page and API now list Metaverse Objects scheduled for deletion because an authoritative source disconnected, not only those whose last connector had gone. (#119)
- π A directory entry matching two selected Object Types, such as user and person on Active Directory, is now imported once rather than twice, and resolves to the same Object Type on every run. (#492)
SecurityΒΆ
- π LDAPS connections now fully validate the directory's certificate (issuer, validity and host name) before sending credentials, and honour certificates added in Admin > Certificates alongside the operating system's trust store. (#1132)
- π The container images now build on the current .NET 10.0.11 base images, clearing CVE-2026-62901 and the systemd advisories CVE-2026-15059 and CVE-2026-16742 (
libsystemd0,libudev1). - π The container images now apply Ubuntu's published security fixes at build time, resolving more than seventy low and medium advisories (in
openssl,util-linux,perl-baseand others) that waited on base image rebuilds. - π The PowerShell module no longer writes your API key, passwords or Connected System setting values to debug output, so running a cmdlet with
-Debugno longer leaks credentials into transcripts, CI logs or shared troubleshooting output. (#1119, #1516) - π Attributes holding credential material, such as
unicodePwdanduserPassword, can no longer be imported, selected for management, or used in an Attribute Flow; any already selected are deselected and locked, leaving Synchronisation Rules intact.
0.14.0 - 2026-07-25ΒΆ
SecurityΒΆ
- π Values imported from connected systems can no longer forge or corrupt service log entries via embedded line breaks; every such value is now sanitised before logging. Identity display names are no longer written to service logs at all.
- π The expression evaluation engine has been security-reviewed and hardened with defence-in-depth guardrails, with no change to expression functionality.
- π Every response from JIM now carries defence-in-depth security headers, including a Content Security Policy, clickjacking denial, and MIME-sniffing protection.
- π Every NuGet dependency, including transitive packages, is now locked to exact known-good versions, making JIM's builds reproducible and tamper-evident from source through to container image.
- π Sign-ins and API key authentication attempts now appear in the Activity audit log, with failed attempts grouped by key, IP address and reason so the log stays bounded under a credential-spraying attack. Security events carry their own retention period, defaulting to one year.
- π Patched a transitive dependency (
System.Security.Cryptography.Xml) to clear four newly published high-severity advisories. The package arrives via ASP.NET Core Data Protection and is not used by JIM at runtime. - π LDAP Distinguished Name parsing is now built into the LDAP Connector, removing the third-party DNParser package, and its non-OSI-approved licence, from JIM's supply chain.
AddedΒΆ
- β¨ Run Profile executions now report live progress with throughput and an estimated time remaining: on the Activity detail page, from a new lightweight progress REST endpoint, and in the terminal via
Get-JIMActivity -FollowandStart-JIMRunProfile -Wait. (#202) - β¨ The Operations page now updates in real time: the queue and history react the moment tasks are queued, progress or complete, pushed from the database rather than polled, with automatic fallback to polling if the notification channel is unavailable. (#307)
- β‘ Schedules now advance between steps and complete near-instantly, instead of waiting up to 30 seconds for the Scheduler's next polling cycle. (#307)
- π₯οΈ Executing an Example Data Template now shows a live progress bar on the template page itself, so you no longer have to switch to the Operations page to watch it. (#307)
- β¨
Invoke-JIMExampleDataTemplategains-Wait(with an optional-Timeout), blocking until generation completes with a live progress display, and-PassThrunow returns the trackingActivityIdandTaskId. (#1112) - β¨ Administrators can now create, rename, re-icon and delete custom Metaverse Object Types, from the portal, the REST API or PowerShell. The built-in User and Group types are protected, and deletion is blocked while any object or Synchronisation Rule still uses the type.
- β¨ Administrators can now create, edit, delete and bind custom Metaverse Attributes, from the portal, the REST API or PowerShell, with a live duplicate-name check. Deletion is blocked only when objects hold a value; configuration-only references cascade behind a confirmation.
- β¨ New built-in Metaverse Attributes make SCIM 2.0 systems map cleanly onto JIM's schema: Emails, Account Enabled, Nickname, Preferred Language, Locale, Time Zone, Middle Name, Honorific Prefix and Honorific Suffix. Existing deployments gain them on upgrade. (#1104)
- β¨ Metaverse Attributes now carry Standard Mappings, recording how each corresponds to its SCIM 2.0 and LDAP/Active Directory counterparts so you can see which attribute to target. They are guidance only; what flows between systems is set solely by your Attribute Flows. (#1104)
- β¨ You can now filter a Metaverse Object Type's list to just the objects holding a value for a given attribute, from the portal (a
hasAttribute:search), the REST API, orSearch-JIMMetaverseObject -HasAttribute. - β¨ Attribute Flows on export Synchronisation Rules can now be marked Initial Export Only: the attribute is set once when JIM provisions the object, then left to the Connected System so Drift Correction ignores it. Ideal for initial passwords and one-time tokens. (#223)
- β¨ Attributes can now be typed as Decimal, an exact fractional number for values like FTE fraction or contracted hours. Decimal values compare numerically in scoping and searches, and round-trip losslessly from import to export. (#1046)
- β¨ Each Connected System can now choose how imports treat reference values that cannot be resolved: raise an error on each affected object (the default), complete with a single warning summary, or ignore them entirely. (#873)
- β¨ The REST API is now protected by configurable rate limiting, tunable from Service Settings without a restart and returning standard 429 responses with Retry-After guidance. Infrastructure API keys are exempt, and the PowerShell module backs off and retries automatically.
- β¨ Background housekeeping that deletes Metaverse Objects past their grace period is now recorded as a Metaverse Object Housekeeping Activity, with every deletion and staged Pending Export visible and filterable on the Activities page. Previously it was only in the log.
- β¨ Full Import Run Profiles gain a Verification Mode toggle that temporarily disables the content-hash skip (see Performance) and reports any disagreement as an error, for validating after an upgrade or investigating a suspected discrepancy. (#1082)
- π₯οΈ Multi-valued attribute values on Connected System Object and Metaverse Object detail pages are now browsed in a searchable, paginated table inline on the page, rather than behind a "+N more" dialog.
ChangedΒΆ
- π An Attribute Flow mapping a Multi-Valued source attribute to a Single-Valued target now raises a per-object error when an object holds more than one value, instead of silently synchronising an arbitrary one. Pre-v1.0 breaking change: review yours before upgrading. (#435)
- π Deleting an identity now deprovisions downstream accounts according to each export Synchronisation Rule's Deprovisioning Action, rather than only deleting accounts JIM originally created. Existing rules keep the safe Disconnect default; set Delete per rule to opt in. (#655)
- π Breaking (REST API and PowerShell): the object type in Metaverse Object list responses is now a nested
typeobject ({ id, name }), matching the single-object response, instead of flattypeId/typeName. Callers must switch to.type.id/.type.name. (#813) - π The REST API now rejects numeric enum values in request bodies with a
400; send the string name instead ("mode": "AllOf"). Responses and the PowerShell module are unaffected, so only a client hand-crafting request bodies must change. Pre-v1.0 breaking change. (#1060) - π The JIM PowerShell module now returns PascalCase property names (
$obj.DisplayName), following PowerShell convention rather than the REST API's camelCase. Member access is case-insensitive, so only scripts comparing property-name strings need updating. - π Paginated list APIs and every
-Allauto-paginating cmdlet now guard against runaway pagination: a page beyond 1000 returns a400rather than being silently clamped, and-Allstops at 1000 pages with a warning. A new-Forcefetches everything. (#487) - π Executing an Example Data Template through the REST API now queues the generation and returns the tracking Activity's id, exactly like the portal, instead of running it inside the HTTP request with no Activity recorded. Pre-v1.0 breaking change. (#1112)
- π Object Matching Rule sources no longer accept a Metaverse attribute as the source value; export matching always needs a Connected System attribute to compare accounts on, and the standard rule shape now serves both import and export matching. (#1053)
- π Exports now default to a conservative connector-recommended degree of parallelism when a Connected System's Max Export Parallelism is not set, instead of always running sequentially. An explicitly configured value is always respected.
- π The LDAP Connector's default Modify Batch Size is now 1000 values per request, up from 100, cutting the round trips needed for very large group memberships by an order of magnitude. Existing Connected Systems keep their stored value; raise it in Export settings to benefit.
FixedΒΆ
- π Accounts queued for deletion when an identity is deleted are now reported on the Activity of the run that queued them, nested beneath the MVO Deleted outcome and counted in the run's Pending Exports total, instead of appearing only in service logs. (#1044)
- π A Pending Export execution item now shows its Pending Export's details, including its change type, rather than rendering the panel only for export errors; a queued deletion is now described as such. (#1044)
- π Provisioning now joins to a matching existing account instead of always creating a duplicate: export matching previously ignored every configured Object Matching Rule, so a rehire's retained account failed with errors such as "The object exists".
- π Two identities being provisioned at the same time can no longer both join the same pre-existing target system account; the join is now claimed atomically, and the identity that loses the race is provisioned a new account as normal. (#1051)
- π Export matching now works for Object Matching Rules on Long Number attributes, such as numeric badge identifiers, and rules on attribute types that cannot be matched are reported as a warning in the service log instead of silently doing nothing. (#1052)
- π Import matching now works for Object Matching Rules on Long Number and Decimal attributes; these previously never joined an incoming account to its existing identity, so synchronisation projected a duplicate instead. (#1046)
- π An object that left an export Synchronisation Rule's scope and returned before the deprovision executed no longer has its live target account deleted by the stale Pending Delete, even when the returning change touches only the scoping attribute.
- π Deprovisioning a group member no longer destroys the group's other pending exports: a group with an unexported Delete keeps it, and a group provisioned but not yet exported keeps its Create rather than being stranded unprovisioned.
- π Membership removals staged when deleting Metaverse Objects now appear on the run's Activity, named by their referencing group and counted into the run's totals; previously an Activity could stage thousands of removals while reporting zero Pending Exports.
- π Deleting identities referenced by many groups no longer over-reports the resulting membership-removal Pending Exports: each group is now recorded once with its coalesced export (on a 500,000-user run, a reported 21,824 became the 5,421 actually staged).
- π Deleting objects that other objects reference no longer leaves invisible empty entries behind: group member lists no longer show blank rows or inflated member counts, and later exports no longer stage empty attribute changes. Upgrading cleans up any left by earlier deletions.
- π Exports running with Max Export Parallelism above one no longer send unresolved reference values (raw internal identifiers) to the target system; reference resolutions are now persisted before the parallel batches execute.
- π Large exports with many reference-bearing objects no longer fail partway with "the connection pool has been exhausted"; each parallel batch's resources are now released as it completes, instead of being pinned for the rest of the run.
- π The progress shown while an export works through its deferred reference phase is now accurate. It previously restarted the processed count from zero against the full run total, producing a misleadingly low rate and a wildly inflated time remaining.
- π Very large imports no longer fail with a database statement timeout while Pending Exports are loaded for reconciliation; the load now runs in bounded chunks (measured at 525,000 Pending Exports with 9.8 million attribute value changes).
- π Very large synchronisation runs no longer fail with a database command timeout while change history reference links are resolved. Resolution now runs in bounded batches, and the export stage resolves the references its own change records create.
- π Connected System Objects now retain their partition assignment. The high-volume import write paths silently discarded it, leaving objects invisible to their partition's obsoletion sweep, so they could never be flagged as deleted. (#1046)
- π Long Number attributes now flow correctly everywhere the other data types already did: inbound flows no longer fail the object, expression results are no longer dropped or truncated, and export evaluation no longer skips a genuine change as no-net-change. (#1046)
- π The REST API now returns Long Number, Decimal and Binary attribute values instead of null, and every attribute type surfaces its real value in its natural JSON type when listing Metaverse Objects with requested attributes. Binary values are returned as Base64 text. (#1046)
- π Deletion audit records now retain Long Number, Decimal and reference values, which previously recorded blank, and values beyond the 32-bit range are no longer truncated to a wrong number. The stored attribute values themselves were never affected. (#1046, #871)
- π The File Connector now writes Binary attribute values to export files as Base64 text, instead of silently writing empty cells. (#1046)
- π Executing an Example Data Template through the REST API no longer crashes with an index-out-of-range error when generating pattern-based values; a template referencing a genuinely empty Example Data Set now fails with a clear message naming the set. (#1112)
- π Example Data generation no longer crashes intermittently under load. The parallel generator shared a random number generator that is not safe for concurrent use, so its internal state could be corrupted and abort generation partway.
- π The Example Data generation progress bar now advances about once a second instead of appearing frozen and then jumping; the CPU-bound parallel generation was consuming every worker thread and starving the progress reporter.
- π The Operations queue progress bar for Example Data generation now sweeps smoothly from 0% to 100% across the whole job, including the database-persistence phase where it previously sat frozen at 100%, with a rolling estimated time remaining.
- π The rate and time-remaining estimate on a running Activity now reflect recent throughput rather than a whole-run average, which misled badly on long runs with fast and slow phases. A stalled counter now reads "finishing up" instead of showing a fabricated estimate.
- π The Activity Operations tab no longer pegs the server at 100% CPU for Activities with tens of thousands of execution items; it now reads only the columns the grid needs (measured: a 26,824-item Activity page went from effectively unusable to about a second).
- π MVO Deleted and MVO Deletion Scheduled outcomes triggered by an out-of-scope disconnection no longer render as bare labels; each now shows the deleted identity's display name, why the deletion rule fired, and a link to the deletion record browser. (#1086)
- π Synchronisation runs whose only outcomes were out-of-scope disconnections no longer show an empty Outcomes cell in the Operations history and Activity list; new chips display out-of-scope disconnections and out-of-scope retained joins.
- π Temporal Scope Reconciliation tasks now display their name and type on the Operations queue, instead of "Unknown WorkerTask type".
- π LDAP Distinguished Names containing escaped separators (an escaped backslash before a Relative Distinguished Name comma, or a comma inside a quoted value) are now parsed correctly when resolving container hierarchies and parent containers.
- π Recording an API key's last-used timestamp no longer surfaces error-level log entries when the database is briefly saturated by a large synchronisation run. The last-used display is unaffected beyond a coarser precision.
- π Closing the browser or navigating away from a tabbed admin page no longer records spurious Error-level entries in the JIM.Web log. Remaining browser-disconnect noise is logged at Warning, so Error entries once again indicate genuine problems.
- π
Add-JIMScheduleStepworks again, sending step type and execution mode as enum names; it also now passes existing steps through verbatim, instead of silently rewriting any PowerShell or parallel step it did not recognise. - π Piping a Schedule into
Get-JIMScheduleExecutionnow filters executions to that Schedule. Previously the piped Schedule did not bind, so the cmdlet silently returned every execution in the system whilst appearing to filter. - π
Reset-JIMServiceSettingnow accepts Service Settings from the pipeline, as its documentation described.
PerformanceΒΆ
- β‘ Full Imports at large scale are dramatically faster, and confirming a very large group no longer gets disproportionately slower as its membership grows. A Full Import of 210,000 objects that took over 40 minutes now completes in around 8.
- β‘ Full Import now skips loading and comparing objects whose content has not changed since the previous import, making its cost proportional to the number of changed objects rather than the size of the whole connector space. Any doubt falls back to the full comparison. (#1082)
- β‘ Full Imports over existing objects are faster again: the per-object database work that dominated them at scale (over half a million separate lookups at 500,000 users) is now done in bulk.
- β‘ Full Synchronisation at large scale no longer spends most of its time re-verifying large groups for drift; this accounted for 35 minutes of a 52-minute confirming synchronisation at 500,000 users, and is now effectively instant regardless of group size.
- β‘ Synchronisation runs no longer slow down page by page as they work through a large Connected System. Each page used to take longer than the last (around 200ms early, degrading to 1.5s late; 16 minutes of waiting across a 525,000-object run); every page now costs the same.
- β‘ Deleting Metaverse Objects that groups reference is now dramatically faster: a 2,000-user leaver cohort at 200,000 objects with 10,000 groups that took over 9 hours to synchronise is projected to finish in well under one.
- β‘ Deleting Metaverse Objects during synchronisation is dramatically faster: a page of deletions that took around 50 seconds now completes in a fraction of that, and no longer gets slower as the number of objects grows.
- β‘ Deprovisioning users who are members of large groups no longer slows synchronisation to a crawl, however large those groups are.
- β‘ Exports no longer stall between batches at large scale. At 200,000 objects with 10,000 reference-bearing groups, an export previously spent hours getting organised before the first group reached the target system.
- β‘ The tail of a large, reference-heavy export no longer crawls through work it has already identified, so an export that is mostly group memberships finishes promptly instead of trailing off.
- β‘ Export runs no longer spend around 11 minutes preparing to retry previously deferred references at 525,000 Pending Exports, even when there is nothing left to resolve. (#1102)
- β‘ Exports now update JIM's own record of an object the moment the export succeeds, rather than waiting for the next confirming import to read the values back, so that import has far less to do. Applies to LDAP and similar connectors; file-based exports are unchanged. (#1079)
- β‘ Watching a Run Profile execute no longer competes with the run itself: refreshing its statistics cost around 85 minutes of cumulative database time over one 500,000-user run, and is now instant. (#1078)
- β‘ The worker service no longer places constant background load on the database for the entire duration of any running task, competing with the very run it is monitoring.
- β‘ Bookkeeping after an export no longer gets disproportionately slower as a batch grows; a batch containing a 100,000-member group spent over ten minutes in it. This also fixes a batch failure that could abort after the target system write had succeeded.
0.13.0 - 2026-07-10ΒΆ
AddedΒΆ
- β¨ Synchronisation Rules can now carry an optional description recording what the rule is for. Set it in the admin portal, with
New-JIMSyncRule/Set-JIMSyncRule, or the REST API; changes appear in the change history. - β¨ Date/time scope filters and object searches can now be relative to "now" (a count, a unit from Hours to Years, and a direction, for example "30 to 364 days ago") rather than a fixed date, re-evaluating every run so the scope keeps moving with time.
- β¨ Relative-date scopes keep working when source data isn't changing: a new built-in hourly Temporal Scope Reconciliation schedule re-evaluates time-driven transitions, so leavers deprovision and joiners provision as their dates pass. It can be re-timed or disabled, not deleted.
- β¨ Predefined Searches can now filter on any attribute type (Number, Long Number, Date/Time, Boolean and GUID) with type-appropriate operators and case-sensitive or -insensitive text matching. Manage criteria from a new editor, the PowerShell module, or the REST API.
- β¨ Predefined Search criteria can now be combined with AND/OR logic and nested groups, for example "(Department is Finance or Sales) and active", rather than a flat list.
- β¨ Example data templates can now build a text attribute from an expression, using the same
mv["Attribute Name"]syntax and functions as Attribute Flows, so a generated value can derive from other attributes on the same object. Circular references are detected up front. - β¨ The Activity list is easier to audit: category (Configuration, Identity, Synchronisation, System), initiator (user, API key, system) and created-date filters narrow the view, and the filter state is reflected in the URL so a view can be bookmarked or shared.
- β¨ An API Key's Name and Description can now be edited directly from its Details tab in the admin portal, without PowerShell or the REST API.
Attribute Priority (#91)ΒΆ
- β¨ When more than one Connected System contributes a Metaverse attribute, a configurable per-attribute priority order now picks the winner, so a higher-priority source is never overwritten by a lower one; a "Null is a value" option lets an authoritative source assert "no value".
- β¨ Attribute Priority is manageable in the admin portal: a Metaverse Object Type's Attributes tab shows each attribute's contributor count, and expanding a multi-contributor one lets you drag its Synchronisation Rules into priority order and toggle "Null is a value".
- β¨ The REST API and
Get-JIMMetaverseObjectnow show each attribute value's provenance: the Connected System and Synchronisation Rule that won priority resolution. Asserted nulls appear as flagged, value-less rows, distinguishing a deliberate blank from one with no contributor. - β¨ Synchronisation Activities now report when an attribute became blank with nothing to replace it, as a distinct "MVO No Contributor" outcome alongside "MVO Null Asserted", so you can tell a deliberate clear from every source falling away.
Configuration Change History (#14)ΒΆ
- β¨ JIM now tracks a versioned history of who changed what and when across its configuration: Synchronisation Rules, Connected Systems, Schedules, Service Settings, Metaverse schema, and more. Retrieve it in the portal, via
Get-JIMConfigurationChangeHistory, or the REST API. - β¨ Secrets are never captured in the change history: encrypted setting values, a Schedule step's SQL connection string, certificate material, and API key secrets are all flagged as changed but never stored, not even as a hash.
- β¨ You can record a reason for any configuration change:
-ChangeReasonon the write cmdlets or an optional REST field, plus a "Reason for change" prompt when saving in the admin portal. The reason shows with the change and on its Activity. - β¨ Deleting a Connected System records a final snapshot of its configuration, so a decommissioned system's last-known state and who removed it stay auditable; the captured state is shown on the delete Activity as a clearly-marked removal.
- β¨ Configuration change history is retained on its own schedule: a new Configuration change retention period Service Setting (default ~10 years) governs it, separate from general history retention.
- β¨ First-time seeding of built-in configuration now appears as a single System Initialisation Activity with the seeded objects as children, so a new deployment starts with one clear entry instead of a page of system rows.
- π A factory reset now preserves the change-history provenance of the built-in objects it keeps, re-recording their version-1 baselines under a fresh System Initialisation Activity instead of stripping their factory origin from the audit trail.
- π Data-generation runs are now a distinct "Data Generation" activity type, separated from Example Data Template configuration changes, so the Activities Configuration filter isn't cluttered by generation runs. Existing runs are reclassified on upgrade.
API & PowerShell Coverage (#154)ΒΆ
- β¨ Connected System Objects can now be listed and filtered via a paginated REST endpoint and the extended
Get-JIMConnectedSystemObjectcmdlet, rather than looked up one at a time. - β¨ Example Data Sets now support full create, update, and delete via the REST API and the new
New-,Set-, andRemove-JIMExampleDataSetcmdlets, alongside the existing read access. - β¨ Queued and in-progress background operations can now be listed, inspected, and cancelled remotely via a new Worker Tasks REST endpoint and the
Get-JIMWorkerTask/Stop-JIMWorkerTaskcmdlets. - β¨ File system browsing, log viewing, and Metaverse Attribute priority management (previously UI-only) are now available as PowerShell cmdlets, giving the module full parity with the REST API.
- β¨ A single Connected System Object Type can now be retrieved by id from the REST API, returning the object type with its attributes, to match the existing update endpoint.
PowerShell Log Streaming (#466)ΒΆ
- β¨ Service logs can now be streamed live from PowerShell with the new
Watch-JIMLogcmdlet: it polls the Logs API, shows only new entries, supports the same filters asGet-JIMLogEntry, and keeps polling through transient failures until you stop it with Ctrl+C.
ChangedΒΆ
- π Multi-source Metaverse attributes now resolve by attribute priority instead of synchronisation timing (last-writer-wins). Single-source attributes are unaffected; existing multi-source ones resolve deterministically until you set an explicit priority order.
- π When a source supplying a multi-source attribute disconnects, leaves scope, or stops providing the value, JIM now hands it to the next-priority contributor still supplying it (reference attributes included), clearing it only when none survives.
- π A deletion grace period no longer freezes attribute hand-over at scope exit: a re-elected attribute is still handed over, and only a single-source value with no surviving contributor is held for the grace window.
- π Activity displays no longer abbreviate "Synchronisation Rule" to "Sync Rule". The underlying
ActivityTargetType.SyncRuleenum value is renamed toSynchronisationRule, a breaking REST/OpenAPI change acceptable pre-v1.0. - π The Activity children REST endpoint and
Get-JIMActivityChildrenare now paged, returning a paged envelope rather than every child at once; the cmdlet gains-Page,-PageSize, and-All, and is now exported from the module (previously unreachable). - π A Connected System's Settings tab now groups its top-level setting categories into a collapsible accordion and separates second-level headings with a divider, making dense connector settings easier to scan.
PerformanceΒΆ
- β‘ Synchronisation imports use far less memory: comparison no longer keeps every loaded object (plus a change-tracking snapshot) for the whole run, nor loads referenced objects in full just to compare group memberships; at 100,000 users with ~5,000 groups this had cost gigabytes.
- β‘ The worker now returns memory to the operating system after each heavy operation completes, instead of holding its peak allocation while idle, and logs its garbage-collection configuration at startup.
- β‘ Generating example data is dramatically faster: the built-in "Users & Groups" template (10,000 users) now completes in seconds rather than minutes, after moving blocking progress writes out of the parallel generation loop.
- β‘ Example data value uniqueness is now tracked with constant-time lookups instead of rescanning an ever-growing list under a global lock, removing a cost that grew with the square of the object count at larger template sizes.
FixedΒΆ
- π Adding a Trusted Certificate via the REST API or
Add-JIMCertificateno longer returns a "No route matches" error on success (the certificate was stored regardless);Get-JIMCertificateon an empty store no longer emits the pagination envelope as a certificate. - π Re-keying an identity in a source (so a new record re-matches an identity while the old one is removed) no longer fails a Full Synchronisation with a database constraint violation; two new records matching one identity fail cleanly on the second, not aborting the run.
- π A Full Synchronisation after a configuration change (attribute priority, enabling/disabling a rule, scoping) now applies it to every object; previously objects whose source data hadn't changed were skipped, so a pure configuration change never took effect for them.
- π A synchronisation run that both created a Metaverse Object and detected drift on it no longer fails with a database foreign-key violation; drift is now evaluated after new objects are saved, so the corrective export always references a real object.
- π A Full or Delta Synchronisation no longer aborts with a database concurrency error when updating a Metaverse Object created earlier in the same run, a race seen at scale; a page that fails to persist now reports which objects were affected instead of a generic error.
- π Deleting a Metaverse Object (for example a deprovisioned leaver) now stages membership-removal exports for every object that referenced it, so groups in target systems without referential integrity no longer keep the deleted user as a member forever.
- π Deleting a Connected System Object that other objects still reference no longer fails the whole run with a database foreign-key violation; the stale references are cleared as part of the deletion, with the raw strings preserved so the next confirming import reconciles.
- π A synchronisation run that fails while saving to the database no longer leaves its Activity stuck in progress; the failure is recorded via a fresh database session, since the failing one cannot save anything further.
- π A Connected System hierarchy refresh that returns no partitions no longer wipes the configured hierarchy: a transient connection or scope problem previously deleted every partition and container, including selected ones. JIM now leaves it untouched and records a warning.
- π A factory reset no longer strips the built-in "Users & Groups" example data template of its attributes (a side effect of the bulk wipe that left generated objects value-less); the template is now restored as part of the reset.
- π Editing an API Key or Trusted Certificate now records who made the change and when; previously the "last updated" attribution was silently lost on save.
- π Activity targets now deep-link to where their subject is managed: an Attribute Flow change to the rule's Attribute Flow tab, imports to the Connected System's Schema and Partitions tabs, and Schedule, Service Setting, and Metaverse activities to their pages.
- π The Schedules links on the home page now open the Schedules tab on the Operations page directly, instead of landing on the default Queue tab.
- π Save and create buttons across the admin portal now react as you type instead of waiting for the field to lose focus, and no longer start disabled when editing an existing item whose required fields are already filled in.
- π The Service Setting edit dialog no longer allows saving an unparseable duration into a time-period setting; the value is validated as you type and Save stays disabled until it is valid.
- π Updated the bundled Microsoft.OpenApi library to a patched release (2.7.5), clearing a high-severity advisory (GHSA-v5pm-xwqc-g5wc) in JIM's API documentation generation.
- π The
-ConnectedSystemAttributeNameparameter onNew-/Set-JIMScopingCriterionnow resolves the attribute correctly; it previously queried a non-existent endpoint, so scoping criteria specified by attribute name failed (the id-based parameter was unaffected).
0.12.0 - 2026-06-23ΒΆ
AddedΒΆ
- β¨ Inbound attribute mappings can now clean and normalise imported text per mapping: treat whitespace-only and empty values as no value (on by default, so a stray space no longer masquerades as a real value), trim and collapse whitespace, and normalise case (Upper, Lower or Title), configurable in the mapping editor, REST API, and PowerShell module. Switch it off per mapping where whitespace is meaningful, and the portal then flags such values with a "(whitespace)" indicator instead of rendering them blank.
- β¨ Inbound text attribute mappings can now clean and normalise imported values per mapping: treat whitespace-only/empty as no value (default on), trim, collapse internal whitespace, and normalise case. Configurable in the mapping editor, REST API, and PowerShell module.
- β¨ The PowerShell module now persists your interactive SSO sign-in across terminal sessions: after
Connect-JIM, new terminals reconnect silently, storing only the refresh token in the OS credential store. Use-NoPersist,-Force, andDisconnect-JIMto control it. - β¨ Factory reset is now available in the portal: a new Administration danger area (
/admin/factory-reset) with a backup warning, type-to-confirm, and an optional "delete administrators" path. - β¨ The initial administrator can now be bootstrapped via the PowerShell module or REST API, not just the portal. Their first authenticated call just-in-time creates the identity and grants the Administrator role, so an air-gapped instance is fully CLI-administrable.
ChangedΒΆ
- π₯οΈ The Synchronisation Rule editor is now organised into deep-linkable tabs (Details, Matching, Scope, Attribute Flow, Danger Zone) instead of one long page, with a single save bar beneath every tab so the whole rule still saves in one action.
- π₯οΈ The Connected System Schema tab is now split into sub-tabs: a searchable, filterable "Object Types" grid for choosing which types JIM manages, plus a tab per selected type for its attributes. This stays usable when a system exposes hundreds of object types.
- π₯οΈ Connected System settings that only apply in certain configurations are now hidden until relevant and required once shown (for example, LDAP Certificate Validation appears only with LDAPS enabled), enforced in the form and for API callers.
- π The REST API now rejects an invalid Connected System settings update with HTTP 400 and a per-setting list of what failed and why, instead of silently saving it.
Set-JIMConnectedSystemsurfaces these field-level messages. - π JIM now requests the
offline_accessscope at interactive sign-in so the identity provider issues a refresh token; this enables in-session token renewal and PowerShell token persistence. Existing SSO deployments must permitoffline_accesson the interactive client. - π Factory reset now preserves administrator users by default (so you are not locked out) and records a Reset activity. Removing administrators too is opt-in via
-IncludeAdministratorsonReset-JIMSystem(andincludeAdministratorson the reset API). - π The reconnection overlay now shows live attempt progress (for example, "Attempt 2 of 5...") while JIM re-establishes a dropped connection.
- π Running a PowerShell cmdlet before connecting now shows a clear one-line prompt to run
Connect-JIM -Url <your JIM URL>instead of a raw internal error; it is non-terminating by default and can be made fatal with-ErrorAction Stop. - π The "not authorised" message shown when an authenticated user has no JIM identity now explains that identities arrive via synchronisation or administrator provisioning, rather than directing them to sign in to the portal first.
FixedΒΆ
- π Editing an existing Synchronisation Rule in the portal now saves. Changes such as disabling a rule appeared to succeed but were silently discarded; the editor now keeps a single database session and fails loudly rather than dropping the change.
- π Creating a Synchronisation Rule from scratch in the portal no longer fails (previously it raised a database foreign-key violation, so a new rule could not be saved at all), and the page now switches into edit mode once the rule is created.
- π The Synchronisation Rule expression tester now resolves attribute names case-insensitively, exactly as live synchronisation does, so an expression that works during a sync run no longer reports "no result" in the tester purely because an attribute name's casing differs.
- π A failed synchronisation expression is no longer silently swallowed, leaving stale metaverse data. The affected object is errored with a distinct "expression evaluation error" and its target left untouched, while the run continues (inbound and export mappings).
- π The File Connector now enforces "exactly one of Object Type Column or Object Type" at save time, with live form feedback and server-side validation, instead of failing later or silently ignoring a value. Connectors can declare such either/or setting groups generically.
- π Deleting a Connected System (including a synchronised one) no longer fails with a database error and is now atomic. Dependent objects are removed in the correct order, and metaverse values it contributed are kept with their contributor link cleared.
SecurityΒΆ
- π A factory reset now invalidates every existing portal sign-in session, so no stale access or privileges survive the wipe; users must re-authenticate. API key access is unaffected.
- π The REST API now rejects request bodies containing duplicate JSON property names, removing an ambiguous-parsing and request-smuggling vector.
0.11.0 - 2026-06-06ΒΆ
AddedΒΆ
- β¨ Create custom Metaverse Object Types via the API and the new
New-JIMMetaverseObjectTypecmdlet, to model identity types beyond Users and Groups. - β¨ Scoping criteria now support long-integer and case-sensitive comparisons via the API and
New-JIMScopingCriterion. - β¨ Synchronisation Rules can now set their out-of-scope and deprovisioning actions and drift detection via the API and
Set-JIMSyncRule. - β¨ New factory reset (
Reset-JIMSystem/POST /api/v1/system/reset) wipes all customer data and configuration in one transaction while preserving the schema, built-ins, and infrastructure access.
FixedΒΆ
- π Refreshing a Connected System's schema now persists the discovered object types and attributes, so the selection interface appears immediately instead of reading back empty.
- π Outbound deprovisioning no longer fails with a duplicate-key error when the target object still has a Pending Export from a prior run.
- π Adding scoping criteria to an existing Synchronisation Rule via the API no longer fails to save.
ChangedΒΆ
- π JIM is now distributed under the Tetron Software License Agreement v2.0.
0.10.3 - 2026-05-10ΒΆ
AddedΒΆ
- β¨ Metaverse Object change history is now available via the API and PowerShell module: new
GET /api/v1/metaverse/objects/{id}/change-historyendpoint returns paginated change records, and the newGet-JIMMetaverseObjectChangeHistorycmdlet wraps it for automation and compliance scenarios. - β¨ Connected System Object change history is now available via the API and PowerShell module: new
GET /api/v1/synchronisation/connected-systems/{id}/connector-space/{csoId}/change-historyendpoint returns paginated change records, and the newGet-JIMConnectedSystemObjectChangeHistorycmdlet wraps it for automation and compliance scenarios.
PerformanceΒΆ
- β‘ Metaverse Object detail pages load substantially faster on objects with long change histories: the page no longer materialises the entire change graph upfront, fetching only a count alongside the object and loading change rows on demand when the Changes tab is opened.
- β‘ Connected System Object detail pages load substantially faster on objects with long import histories: the page no longer materialises the entire change graph upfront, fetching only a count alongside the object and loading change rows on demand when the Change History tab is opened.
- β‘ Connector Space list pages load substantially faster: the per-page projection no longer materialises full pending-export graphs or attribute-value entities, returning only the scalar columns the table actually renders.
FixedΒΆ
- π Export Run Profile Execution Items and their linked Connected System Object Change rows now persist with the correct
ConnectedSystemObjectIdforeign key, restoring causality navigation from Operations into the CSO detail page and preventing exported objects from being mis-labelled as "Deleted" on the activity item detail page (#683). - π Pending-export reference values in the Causality Tree attribute change table now render the resolved identifier (e.g. group member DN) alongside a clickable link to the stub Connected System Object, instead of showing only a clock icon with no value.
ChangedΒΆ
- π The Activity Run Profile Execution Item detail page no longer duplicates the Connected System Object's external ID in the Execution Summary prose; the identifier is already shown as a chip directly below.
0.10.2 - 2026-04-29ΒΆ
AddedΒΆ
- β¨ Predefined Searches can now be retrieved individually via the API and PowerShell module: new
GET /api/v1/predefined-searches/{id}andGET /api/v1/predefined-searches/by-uri/{uri}endpoints return the full search graph, andGet-JIMPredefinedSearch -Id/-Urinow resolve directly against the server instead of filtering the list client-side (#154)
FixedΒΆ
- π The "Initiated By" link on Activity and Activity Run Profile Execution Item detail pages now points to the correct Metaverse Object URL, derived dynamically from the initiator's Metaverse Object Type plural name (
/t/{typePluralName}/v/{id}) instead of a broken hardcoded/identity/person/{id}path. - π Safari sign-in against the development stack at
http://localhost:5200no longer fails withCorrelation failed; OIDC correlation cookies are now configured appropriately for plain-HTTP localhost in Development while production HTTPS defaults remain untouched. - π The bundled "Users & Groups" example data template now persists at production speed without stalling the worker or pressuring memory; generation has been rewritten to use PostgreSQL
COPYbinary import in bounded batches, mirroring the proven pattern used on the synchronisation hot path. - π Filled alerts in the
navy-o6themes now meet WCAG AA contrast: light-theme info/success/warning/error variants and dark-theme filled info no longer place dark text on saturated backgrounds, and links inside filled alerts pick up the on-colour text colour rather than clashing with the semantic background.
ChangedΒΆ
- π Example data generation now reports live, batch-level persistence progress with a rolling ETA on the Activity record and progress bar, so administrators can see exactly where a large generation run is up to.
- π Compact row spacing on the Metaverse Object detail Table view now extends to multi-valued reference rows (e.g. group Owners, Static Members), keeping large memberships readable at a glance.
- π₯οΈ Refreshed the JIM portal and documentation typography to IBM Plex Sans and IBM Plex Mono, with a Space Grotesk accent on docs hero surfaces and the portal sidebar wordmark, for sharper identifier disambiguation and a more polished, designed feel across the product.
- π₯οΈ The production error page now renders in the JIM brand (broken-cog illustration, Plex / Space Grotesk fonts, navy-o6 palette), honours the user's saved dark-mode preference and
prefers-reduced-motion, and runs without a Blazor circuit so it remains reachable when middleware throws. - π οΈ
jim-resetnow stops any natively-run JIM.Web/Worker/Scheduler processes before tearing down the Docker stack, preventing port collisions (e.g. host port 5200) when the Docker stack is restarted after ajim-build-lightdebug session.
0.10.1 - 2026-04-27ΒΆ
AddedΒΆ
- β¨ Interactive browser-based SSO for the JIM PowerShell module now works against identity providers that require a separate public client registration for desktop/CLI tools, including Keycloak. Two new optional environment variables let administrators advertise client-facing SSO configuration to interactive clients without affecting backend token validation:
JIM_SSO_PUBLIC_AUTHORITYfor deployments where the backend and clients reach the identity provider on different URLs (split-horizon reverse proxies, development containers), andJIM_SSO_PUBLIC_CLIENT_IDfor deployments where the PowerShell module's public OAuth client is a distinct registration from the web application's confidential client. Both variables are optional and fall back toJIM_SSO_AUTHORITY/JIM_SSO_CLIENT_IDrespectively, so single-URL single-client production deployments are unaffected.
ChangedΒΆ
- π Refined sidebar navigation styling: selected and hover items now show a contrasting rounded "pill" background that is inset from the drawer edges, with the hover background a stronger shade than the selected background so it remains visible when hovering an already-selected item. Active and hover backgrounds are theme-driven (
--jim-nav-active-bg/--jim-nav-hover-bg) and tuned per theme, with sensible derived fallbacks for any future theme that does not set them. - π₯οΈ A more polished sidebar experience: the signed-in user menu is now anchored to the bottom of the drawer for quick access regardless of how many sections are above it, and pinning or collapsing the drawer is now a single click on a dedicated chevron in the drawer header.
FixedΒΆ
- π Interactive
Connect-JIMagainst Keycloak deployments previously failed withInvalid parameter: redirect_uribecause JIM advertised the confidential web client ID to the PowerShell module. Administrators can now register a separate public client (as the SSO Setup Guide has always instructed) and advertise it to interactive clients via the newJIM_SSO_PUBLIC_CLIENT_IDenvironment variable. - π
Get-JIMRoleand theGET /api/v1/security/rolesendpoint now report the correct static member count for each role; previously the count was always zero because the underlying query did not load role memberships. The count is now aggregated directly in SQL, so even roles with very large memberships are returned cheaply. - π
Get-JIMRole -IdandGET /api/v1/security/roles/{id}now report the correct static member count when retrieving a single role. - π
Get-JIMMetaverseObjectRoleandGET /api/v1/security/metaverse-objects/{id}/rolesnow report the correct static member count for each role a Metaverse Object belongs to. - π
GET /api/v1/synchronisation/connected-systems/{id}now reports the correct Connected System Object count; previously it always returned zero because the navigation property was not loaded. The count is now sourced from a dedicated count query, mirroring howpendingExportCountis already computed.
SecurityΒΆ
- π Patched
Microsoft.AspNetCore.DataProtectionto 10.0.7 to address CVE-2026-40372 (GHSA-9mv3-2cwr-p262, high-severity elevation of privilege / authentication cookie forgery in ASP.NET Core Data Protection). Also drops the now-redundant transitive override ofSystem.Security.Cryptography.Xml, which Data Protection 10.0.7 brings in at a patched version directly.
0.10.0 - 2026-04-22ΒΆ
AddedΒΆ
- β¨ Added a Service Name and Service ID so you can tell JIM instances apart at a glance. Set a friendly name per instance on the Service Settings page and see it under "JIM" in the sidebar, in the browser tab title, and in the footer. The Service ID is generated once per instance and never changes, useful for tooling, logs, and telemetry (#583)
- β¨ Predefined Searches can now be disabled and re-enabled without deleting them; disabled searches are hidden from the portal, the search API, and the sidebar navigation, while administrators can still manage them via the admin UI, the new
/api/v1/predefined-searchesendpoints, and the newGet-JIMPredefinedSearch/Set-JIMPredefinedSearchPowerShell cmdlets (#555) - β¨ PowerShell cmdlets for System endpoints:
Get-JIMHealth(with-Readyand-Liveprobes),Get-JIMVersion,Get-JIMAuthConfig, andGet-JIMUserInfo; health, version, and auth config cmdlets work withoutConnect-JIMvia a-Urlparameter (#468) - β¨ Interactive API reference powered by Scalar, available at
/api/referencein all environments including air-gapped deployments; OpenAPI document is pre-generated at build time for instant loading with zero runtime overhead - β¨ Public API reference published to the JIM documentation site at docs.junctional.io/api/reference/; automatically updated on every release to match the published JIM version
- β¨ Clear Connected System activity now tracks and displays removal statistics, showing how many Pending Exports and Connected System Objects were removed (#74)
- β¨ New count endpoints for Metaverse Objects, connector space, and Pending Exports, with filtering by object type, partition, change type, and status; suitable for dashboards, SIEM integration, and capacity monitoring (#154)
- β¨ New user menu in the navigation drawer showing the signed-in user's avatar (with initials), display name and username, with pinning, dark mode and sign-out controls in a single polished popover (#49)
- β¨ Automated integration test metrics streaming to central tracking system with Grafana dashboards (#476)
- π API and PowerShell support for managing Role membership on Metaverse Objects, enabling administrators to appoint or remove additional admins without restarting the service (#467)
- β¨ New API endpoints for Role member management: list members, add member, remove member, get Role by ID, and list the Roles a Metaverse Object is a member of
- β¨ New PowerShell cmdlets
Get-JIMRoleMember,Add-JIMRoleMember,Remove-JIMRoleMember, andGet-JIMMetaverseObjectRolewith full pipeline support - β¨
Get-JIMRolecmdlet now supports-Idparameter for direct Role lookup by identifier - π Safety checks prevent administrator lockout: self-removal from the Administrator role and removing the last Administrator are both blocked with clear error messages
- π Sign-out with identity provider, gated by the
SSOEnableLogOutservice setting, with a confirmation dialog to prevent accidental clicks (#49)
PerformanceΒΆ
- β‘ Connected System detail lookups are much cheaper on write-path and validation API calls: introduced a lightweight
GetConnectedSystemCoreAsyncretrieval variant that loads only essential properties, and migrated the API controllers that previously paid for the full schema, partition and container graph just to verify the system exists (#494) - β‘ Connected System container hierarchy loading now handles arbitrary depth and avoids the cartesian-explosion risk of the previous 11-level hard-coded Include chain; containers are loaded flat and rebuilt into a tree in memory (#494)
- β‘ Full Connected System loads now issue one database query for Object Matching Rules instead of four, eliminating the fan-out that split-query mode introduced when walking
Sources.ConnectedSystemAttribute,Sources.MetaverseAttribute,TargetMetaverseAttributeandMetaverseObjectTypeas separate Include branches (#494) - β‘ Default all EF Core queries to
AsNoTracking, reducing memory and CPU overhead for read-heavy operations; write paths explicitly opt in to change tracking (#484) - β‘ Enriched diagnostic spans with cumulative object count and wall-clock offset tags for throughput profiling (#476)
- β‘ Added MetricsCheckpoint log lines for guaranteed throughput tracking at any log level (#476)
ChangedΒΆ
- π₯οΈ Partition-configuration validation errors now pinpoint the exact gap (hierarchy not imported, no partitions selected, or selected partitions have no container selected) and name the partition involved, replacing the previous generic "no partitions or containers have been selected" message and making misconfigurations far faster to diagnose (#564)
- π₯οΈ Page footer now links the Tetron name to tetron.io and includes a GitHub link next to the version number (#49)
- π¦ File Connector storage uses the formal Docker named volume
jim-connector-files-volume, mounted at/connector-filesinside JIM Web and JIM Worker. Default deployments get working File Connector exports out of the box without any host-side permission setup. Customers integrating with external file shares bind-mount over a subdirectory of/connector-files. See the JIM File Connector documentation for both patterns.
FixedΒΆ
- π Group and other multi-valued-reference sync activities no longer produce duplicate execution items; cross-page reference resolution now merges reference Attribute Flow into the original Projected/Joined record instead of creating a second standalone "Attribute Flow" record for the same object. Fixes inflated activity counts and removes the confusing split-outcome rows that appeared in activity detail
- π Static member values and other multi-valued references on group activity detail pages now render as clickable user chips with display names instead of raw GUIDs; reference change records now carry their target as a proper foreign key so the link can be materialised on display
- π Export failures caught by exception handlers now produce Run Profile Execution Items reliably; previously a thrown connector exception could mark a batch failed without producing any RPEI, so the activity appeared to complete successfully despite silent export failures
- π Metaverse Object and Connected System Object change history is now persisted during sync RPEI flush and on single-object create, ensuring the audit timeline reflects every sync run
- π Sign-out with the bundled Keycloak no longer fails with "Missing parameters: id_token_hint"; JIM now persists the ID token during sign-in so the OIDC middleware can include it on the end-session request per the OIDC spec (#49)
- π Keycloak hostname configuration corrected so that browsers and Docker back-channel clients each get the right endpoint URLs, fixing sign-in and sign-out for all four deployment scenarios (Codespaces, devcontainer native, devcontainer Docker, production) (#49)
- π Connected System partition trees now include nested containers below the top level. Directories with nested organisational units (e.g.
OU=Users,OU=Corp) are loaded and returned through the API in full, so administrators can select nested containers for import and automation can address them via PowerShell (#586)
SecurityΒΆ
- π Supply chain hardening: all Docker base images are digest-pinned, all GitHub Actions are pinned by commit SHA, and the main branch is protected with required status checks including automated code review, CodeQL, container scan, and dependency scan (#520, #517, #521)
- π Patched transitive
System.Security.Cryptography.Xmlto 10.0.6 to address CVE-2026-33116 (low-severity DoS inEncryptedXml); the package is pulled in via ASP.NET Core Data Protection but not used by JIM at runtime - π Patched
basic-ftpCRLF injection vulnerabilities (GHSA-chqc-8p9q-pq6q and GHSA-rp42-5vxx-qpwr) and picked up Ubuntu Noble security updates for libldap and cifs-utils in all production container images
0.9.1 - 2026-04-08ΒΆ
AddedΒΆ
Search Objects API (#482, #488)ΒΆ
- β¨ New
GET /api/v1/metaverse/objects/search/{predefinedSearchUri}endpoint for fast, lightweight object searches optimised for 100K+ object deployments - β¨ New
Search-JIMMetaverseObjectPowerShell cmdlet with predefined search support, sorting, filtering, and auto-pagination
PerformanceΒΆ
Paginated List Optimisation (#482, #485)ΒΆ
- β‘ Metaverse Object list sorting now uses a pre-computed cached display name column, eliminating expensive per-query subqueries for display name resolution
- β‘ New composite index on metaverse attribute values for faster attribute-based sorting and filtering
- β‘ Paginated list queries for Metaverse Objects and Connected System Objects rewritten to use keyset pagination with optimised sort subqueries
FixedΒΆ
- π₯οΈ Fixed oversized text on avatar chips in Synchronisation Rule list and detail pages
- π₯οΈ Multi-valued attribute value counts on Metaverse Object detail pages now display with thousand separators for readability
0.9.0 - 2026-04-07ΒΆ
AddedΒΆ
100K Object Scale (#451, #437, #438)ΒΆ
JIM now supports deployments of 100,000+ objects, validated by Scale100K integration tests across the full import, sync, and export pipeline. A bounded memory architecture ensures stable, predictable resource usage regardless of dataset size.
- β¨ Bounded memory sync and export pipelines: change tracker cleared at every page boundary and caches loaded per-page instead of upfront, enabling 100K+ object operations without out-of-memory crashes
- β¨ Partition-scoped deletion detection for full imports: deletion detection is now scoped to the imported partition, preventing CSOs from other partitions being incorrectly marked as obsolete during large-scale imports
- π₯οΈ Import processing now displays throughput (objects/sec) and ETA in progress messages, completing progress tracking coverage across all long-running phases
.NET 10 Migration (#174)ΒΆ
- β¨ Migrated from .NET 9.0 (STS) to .NET 10.0 (LTS), extending support from November 2026 to November 2028
- β¨ Upgraded all NuGet packages to .NET 10-compatible versions, including EF Core 10, MudBlazor 9, and Humanizer 3
- β¨ Replaced Swashbuckle with built-in
Microsoft.AspNetCore.OpenApi+ Scalar for modern API documentation UI - π All Docker containers now run as non-root (
USER app, UID 1654), improving security posture for enterprise deployments - π Docker container hardening (#333): read-only root filesystem, dropped all Linux capabilities with selective re-add, and
no-new-privilegesflag on all application containers - π Moved CIFS/SMB utilities and capabilities from Web to Worker container, applying least-privilege principle (only the Worker executes file connector operations)
- π¦ Docker images migrated from Debian Bookworm to Ubuntu 24.04 Noble base with pinned SHA256 digests
- π¦ Added
global.jsonto pin .NET 10 SDK version across all environments
Service Settings REST API & PowerShell CmdletsΒΆ
- β¨ New REST API for managing service settings (
GET/PUT/DELETE /api/v1/service-settings), enabling automation of change tracking, sync page size, history retention, and other operational settings - β¨ New PowerShell cmdlets:
Get-JIMServiceSetting,Set-JIMServiceSetting,Reset-JIMServiceSettingfor managing service settings from the command line or automation scripts
Data Integrity Validation (#465)ΒΆ
- π Metaverse attribute operations now validate data integrity before executing: deleting attributes with stored values, deleting attributes referenced by Synchronisation Rules, and removing object type mappings with existing data all return structured validation errors instead of silently corrupting state
PowerShell Module EnhancementsΒΆ
- β¨
-Nameparameter added to sixGet-JIM*cmdlets (Get-JIMRunProfile,Get-JIMSyncRule,Get-JIMApiKey,Get-JIMCertificate,Get-JIMRole,Get-JIMConnectorDefinition), enabling direct filtering withoutWhere-Object - β¨ New
Get-JIMPendingDeletioncmdlet with List, Count, and Summary parameter sets for monitoring objects awaiting deletion - β¨ New
Get-JIMActivityChildrencmdlet for retrieving child activities of a parent activity
Integration Test Runner EnhancementsΒΆ
- β¨
-LogLevelparameter for integration test runner: override log verbosity (Verbose/Debug/Information/Warning/Error/Fatal) for the test run without permanently modifying.env - β¨
-DisableChangeTrackingswitch for integration test runner: disable CSO and MVO change tracking during large-scale tests to reduce database writes and improve throughput - π₯οΈ Interactive menus for log level and change tracking selection when running tests without explicit parameters
FixedΒΆ
- π Safe cancellation for sync operations (#339): when an admin cancels a running Full Sync or Delta Sync, the current page's flush pipeline now completes before exiting. Previously, cancellation could leave orphaned Metaverse Objects without corresponding Pending Exports, causing target systems to silently miss updates.
- π Fixed import tasks continuing to process after cancellation (#339); cancelling a Full Import or Delta Import from the Operations Queue now stops the import between pages and skips persistence. Previously, the import processor ignored the cancellation signal and ran to completion.
- π Fixed cancelled tasks having their status overwritten to Completed or Failed; the Worker now correctly preserves the Cancelled activity status instead of overwriting it when the processor finishes.
- π Fixed sync progress bar showing inflated object counts (CSOs + Pending Exports) instead of just CSOs; progress percentage and ETA are now accurate for Full Sync and Delta Sync
ChangedΒΆ
- β‘ LDAP export concurrency is now auto-tuned based on the detected directory server type; AD DS and OpenLDAP default to 16 concurrent operations (up from 4), while Samba AD and unknown directories remain at 4 for compatibility. Administrators who have manually configured the value will not be affected.
PerformanceΒΆ
- β‘ Selective attribute loading for full sync: unchanged CSOs (based on watermark comparison) skip attribute value loading and Attribute Flow entirely, dramatically reducing I/O for large-scale repeat syncs
- β‘ Eliminated redundant per-page COUNT queries during sync; total count is now passed from sync start, removing 200+ unnecessary full-table scans at 100K objects
- β‘ Default sync page size increased from 500 to 1,000, halving the number of database round-trips per sync run
- β‘ Sync progress updates now use direct SQL instead of EF Core change tracker, reducing per-page overhead
- β‘ Removed explicit RepeatableRead transactions from sync page loading; PostgreSQL MVCC provides sufficient consistency without the round-trip overhead
- β‘ Pending Exports table on CSO detail page now uses server-side paging; pages with thousands of pending changes (e.g. 10K member adds) load instantly instead of rendering all rows at once
- β‘ All export evaluation and Pending Export cache queries now use
AsNoTracking, eliminating unnecessary entity tracking overhead during sync - β‘ Per-page memory diagnostics logging: administrators can monitor memory usage across sync pages to verify bounded memory behaviour
0.8.1 - 2026-04-02ΒΆ
AddedΒΆ
- β¨ Pre-export CREATEβDELETE reconciliation β when an object is created and then deleted before export runs, the redundant Pending Exports are automatically cancelled instead of failing during export (#218)
PerformanceΒΆ
- β‘ Export rule evaluation optimised to reduce per-MVO processing cost, improving sync performance for configurations with many export rules (#417)
- β‘ Active Directory schema discovery now batches LDAP queries, reducing connection round-trips during schema import (#433)
FixedΒΆ
- π Fixed entity tracking conflict during cross-page reference resolution at scale β Full Sync no longer fails with "ConnectedSystemObject cannot be tracked" when groups share members across resolution batches (10,000+ users)
- π Error messages no longer display the internal "EMERGENCY UPDATE" prefix β user-facing messages now show clean, actionable text (#448)
- π Activity and RPEI detail page breadcrumbs are now context-aware, showing the correct navigation path based on how the page was reached
- π Sanitised
Request.Methodin global exception handler logging to prevent log injection (CWE-117) (#444)
0.8.0 - 2026-04-01ΒΆ
AddedΒΆ
OpenLDAP Connector Support (#72)ΒΆ
- β¨ Full OpenLDAP and RFC 4512-compliant LDAP directory support β connect to OpenLDAP, 389 Directory Server, and other standards-based LDAP directories alongside Active Directory
- β¨ Automatic directory type detection from rootDSE (Active Directory, OpenLDAP, Generic LDAP) with per-type external ID handling (objectGUID vs entryUUID)
- β¨ RFC 4512 schema discovery β object classes and attribute types parsed from the subschemaSubentry with OID-based data type mapping and superclass hierarchy walking
- β¨ Multi-suffix partition discovery via rootDSE namingContexts for non-AD directories
- β¨ Accesslog-based delta import for OpenLDAP β queries
cn=accesslogfor incremental changes with automatic fallback to full import - β¨ Parallel import with configurable concurrency β each container/objectType combination runs on its own LDAP connection, working around RFC 2696 paging cookie limitations
- β¨ Transparent
groupOfNamesplaceholder member handling β automatically manages the RFC 4519 MUST constraint so administrators never see placeholder entries in the metaverse - β¨ DN-aware RDN attribute detection for correct export naming
- β¨ Partition-scoped imports β Run Profiles can target a specific partition instead of importing all selected partitions (#353)
Worker Redesign (#394)ΒΆ
- β¨ Pure domain engine (
ISyncEngine) β 7 stateless methods with zero I/O dependencies, making core sync logic independently testable with plain objects - β¨ Formal data access boundary (
ISyncRepository) β ~80-method interface separating Worker data access from shared EF Core repositories, with purpose-built in-memory implementation for tests - β¨ Dependency injection throughout Worker and Scheduler β
IJimApplicationFactory,IConnectorFactory, per-task context isolation
Bundled Keycloak IdP for Development (#197)ΒΆ
- β¨ Zero-config SSO β
jim-stackstarts a pre-configured Keycloak instance alongside JIM; developers sign in immediately withadmin/admin - β¨ Pre-configured realm with
jim-web(confidential + PKCE) andjim-powershell(public + PKCE) clients,jim-apiscope, and two test users - β¨
.env.exampledefaults point to the bundled Keycloak β no manual IdP configuration needed for local development - β¨
jim-keycloak/jim-keycloak-stop/jim-keycloak-logsaliases for standalone Keycloak (F5 debugging workflow) - β¨ Keycloak admin console accessible at
http://localhost:8181 - π HTTP OIDC authority support for development (RequireHttpsMetadata conditionally disabled)
Object Type Icons (#92)ΒΆ
- π₯οΈ Configurable icons for Metaverse Object Types β assign icons to object types, displayed across the homepage, navigation menu, schema pages, and object detail views
Pending Export ManagementΒΆ
- π₯οΈ Pending Export detail page with grouped attribute changes, capped multi-valued attribute loading, and server-side paginated drill-down for large change sets
- π₯οΈ
Get-JIMPendingExportandGet-JIMConnectedSystemObjectPowerShell cmdlets with corresponding API endpoints - π₯οΈ Pending Exports list now shows display names instead of raw GUIDs
Activity MonitoringΒΆ
- π₯οΈ Auto-refresh polling on the activity list page β data updates automatically without manual refresh
- π₯οΈ Pause/resume toggle for auto-refresh polling
- π₯οΈ Compact determinate progress bar on the History tab for in-progress activities
- π₯οΈ Phase-specific activity messages during imports β "Connecting to Connected System" and "Importing objects from Connected System" show the current phase before object processing begins (#342)
Run Profile EditingΒΆ
- π₯οΈ Run Profile editing UI β edit name, file path, partition, and page size for existing Run Profiles
- β¨
SupportsFilePathsconnector capability β File Path fields only appear for connectors that use file-based import/export - β¨
SupportsPagingconnector capability β Page Size controls only appear for connectors that support paged queries
Navigation and LayoutΒΆ
- π₯οΈ Browser back/forward navigation support for all tabbed pages via URL query parameters
- π₯οΈ Tabs view mode for Metaverse Object details β attribute categories displayed as horizontal tabs alongside existing form and table views
- π₯οΈ Expanded Target section in the Operations sidebar with type-specific links
- π₯οΈ Connector capabilities grouped by category on the detail page
InfrastructureΒΆ
- π¦ Docker healthchecks for Worker and Scheduler β file-based heartbeat monitoring detects stalled service loops (#185)
- β¨ Multi-valued to single-valued import Attribute Flow β when a multi-valued source Attribute Flows to a single-valued target, JIM automatically selects the first value and records a warning (#435)
PerformanceΒΆ
Worker Redesign (#394)ΒΆ
- β‘ Parallel multi-connection writes β
ParallelBatchWritersplits bulk database writes across N concurrent PostgreSQL connections, utilising multiple CPU cores during save phases. Configurable viaJIM_WRITE_PARALLELISMenvironment variable - β‘ COPY binary protocol for bulk inserts β CSO creates, RPEIs, MVO creates, and sync outcomes now use PostgreSQL's COPY binary import, eliminating SQL parsing overhead and parameter limits (#338)
- β‘ Worker-exclusive bulk SQL in
SyncRepositoryβ hot-path operations (RPEI persistence, CSO bulk create, Pending Export operations) moved from shared repositories into dedicated partial classes, reducing shared repo surface by 1,200+ lines
Import Pipeline (#427, #440)ΒΆ
- β‘ Import CSO matching now uses a pre-fetched dictionary for O(1) external ID lookups, replacing N per-object database queries with a single bulk query at import start β eliminates the dominant bottleneck in full imports (#440)
- β‘ Import reference resolution is now case-insensitive (matching RFC 4514 DN semantics) and batches sort non-referencing objects first with committed ID tracking β eliminates the expensive post-import LOWER() fixup SQL query (#427)
- β‘ Two-phase parallel write commits CSO rows before attribute values, giving cross-partition references full FK visibility and eliminating post-import fixup queries (#427)
Sync and ExportΒΆ
- β‘ Immediate MVO deletion (zero grace period) skips unnecessary attribute recall and export evaluation, eliminating wasted database round-trips (#390)
- β‘ Deferred export resolution progress reporting throttled to every 50 items instead of per-item, eliminating ~540 unnecessary database round-trips for typical batches (#426)
- β‘ Bulk RPEI and CSO change persistence timeouts increased to 300 seconds for large imports (#426)
- β‘ Log file rolling size reduced from 500 MB to 50 MB per file (100 files retained, ~5 GB max per service)
FixedΒΆ
- π Attribute change history is no longer cascade-deleted when a metaverse or Connected System attribute definition is removed β the FK is set to null and snapshot
AttributeName/AttributeTypeproperties preserve the audit trail indefinitely (#58) - π Expression attribute lookups (e.g.
mv["Department"]) are now case-insensitive, preventing silent failures when attribute name casing in expressions did not exactly match stored names (#341) - π Pending Export reconciliation now correctly matches all 8 attribute data types β Boolean, Guid, and LongNumber exports previously failed to reconcile and appeared permanently stuck (#263)
- π Deferred export progress bar no longer shows values exceeding 100%
- π Progress bars on the History tab now update in real-time instead of freezing after initial page load
- π Worker database operations no longer time out during large imports β command timeout increased from 30s default to 300s (#426)
- π Connector-level warnings (e.g. delta import fallback) now appear as activity banners instead of phantom RPEIs with no CSO association
- π MVO reference attribute foreign keys are now reliably persisted across cross-page and cross-batch scenarios
- π MVO change tracking no longer crashes when recording deletion changes for objects with unloaded reference navigation properties
ChangedΒΆ
Worker Redesign (#394)ΒΆ
- π All Worker and Workflow tests (~1,300) migrated from mocked
DbContextto purpose-builtInMemoryData.SyncRepository, eliminating three-way code path divergence between production, workflow tests, and unit tests -
π Removed ~32 try/catch EF fallback blocks from repository files (-642 lines) β production and test code paths are now identical
-
π Object type names from camelCase LDAP schemas (e.g.
groupOfNames) now display correctly as "Group Of Names" - π Error type column merged inline with outcome chips on the activity detail page
0.7.1 - 2026-03-19ΒΆ
FixedΒΆ
- π¨ Sidebar background colour in the Navy O6 theme now matches the page background for a seamless, cohesive look
0.7.0 - 2026-03-19ΒΆ
AddedΒΆ
- β¨
GET /api/v1/userinfoendpoint β returns the authenticated user's JIM identity, roles, and authorisation status without requiring Administrator privileges - β¨
Connect-JIMnow verifies authorisation after authentication and warns if the user has no JIM identity, with clear guidance to sign in via the web portal first - π₯οΈ Improved 403 error messages in the PowerShell module β now explains the likely cause (no JIM identity) and how to resolve it
- π₯οΈ Properties tab on the Metaverse Object detail page β shows creation date, last modified, and clickable initiator links
- π₯οΈ Form and table view toggle on the Metaverse Object detail page
- π₯οΈ Server-side paginated dialog for large multi-valued attributes on the MVO detail page
- π₯οΈ Object type chip prefix on reference values in MVO table view
- π₯οΈ Server-side paging on the schema attributes table
- π₯οΈ Sortable columns on the staging object attribute table
- β¨ Activity tracking for initial admin user creation
- π
Connect-JIMnow skips the authorisation check when using API key authentication
ChangedΒΆ
- π¨ New default theme with a refined colour palette β deeper backgrounds, improved button and chip contrast across dark and light modes, and better visual hierarchy for a more polished, readable experience
- π¨ Switched web font to Inter β self-hosted for air-gapped deployment, delivering improved readability and a modern feel
- ποΈ Removed legacy themes consolidated into the new default
- π "Connected System Objects" pages renamed to "Staging" with cleaner URL structure and improved introductory UX
- π "Data Generation" renamed to "Example Data" across the entire stack for consistent naming β models, API routes (
/example-data/), PowerShell cmdlets (Get-JIMExampleDataTemplate,Invoke-JIMExampleDataTemplate), database tables, and UI all now share the "Example Data" family prefix - β‘ Database migrations flattened into a single
InitialCreatemigration for faster first-start performance and simpler codebase - π₯οΈ Redesigned object matching tab layout and combined status chips on the RPEI detail page
FixedΒΆ
- π Resolved intermittent DbContext concurrency errors across all Blazor Server pages β overlapping async lifecycle methods (e.g. data load and table pagination) no longer share a single database context
- π FK violation in import change history bulk persistence no longer causes import failures
- π
HasPredefinedSearchesnow returns the correct value for object types with predefined searches - π Spurious Pending Exports no longer surface during full sync operations
Deleted Object Change HistoryΒΆ
- π Deleted MVO change history now shows the full timeline of prior changes (Created, AttributeFlow, Disconnected) β previously only the Deleted record was visible due to a broken FK correlation after deletion
- π Final attribute values are now captured on MVO deletion change records, showing exactly what the object looked like before it was removed
- π Final attribute values are now captured on CSO deletion change records β previously only the external ID and display name were preserved
- π MVO deletion no longer fails with FK constraint violations when the deleted object is referenced by other MVOs (e.g., as a Manager) or by change history records
Pending Export Reference Display (#404)ΒΆ
- π Pending Export reference attributes (e.g. group members) now display meaningful identifiers (DN, External ID) instead of raw GUIDs with a misleading "unresolved reference" warning
- π References to objects processed later on the same sync page are now resolved via a post-page resolution pass
- π Resolved reference attributes (e.g. group members) now appear in export causality tree attribute changes β previously they were silently dropped
- π₯οΈ Pending Export references show a "Pending Export" indicator to distinguish them from fully resolved and genuinely unresolved references
Database Resilience (#408, #409)ΒΆ
- π Transient database errors now return HTTP 503 (Service Unavailable) with a
Retry-Afterheader instead of HTTP 400 (Bad Request) - π Cross-batch reference fixup hardened against database timeouts and FK gaps at scale
- β‘ Transient database failures handled gracefully at API level with retry guidance
- β‘ Connection pool sizing reduced from 50 to 30 per service to leave headroom within PostgreSQL's
max_connections - π¦ Development database (
db.yml) now explicitly setsmax_connections=200to match the full Docker stack
PerformanceΒΆ
- β‘ MVO detail page now caps multi-valued attribute values with server-side pagination, dramatically reducing load time for objects with large MVAs
- β‘ Pending Export reconciliation query optimised with sub-phase progress messages
0.6.1 - 2026-03-15ΒΆ
AddedΒΆ
- β¨ Child activity tracking β sync activities now show nested child activities with drill-down navigation (#298)
- β¨
Clear-JIMConnectedSystemPowerShell cmdlet β wipe all objects from a Connected System without deleting the configuration (#365) - π‘οΈ Global error boundary catches unhandled rendering exceptions in the UI β instead of a broken page, users see a friendly error message with "Try Again" and "Go to Dashboard" recovery options (#167)
- π₯οΈ "Has child activities" filter on the Activities list and Operations history pages
- π₯οΈ Contextual page heading icons, refined operation/outcome chip colours, and improved causality tree display
- π Log injection sanitisation across all logging calls to prevent CWE-117 log forging
- π Trivy container image scanning added to CI pipeline
ChangedΒΆ
- π Built-in "Employee Status" metaverse attribute replaced with the more generic "Status"
FixedΒΆ
- π Cross-batch and cross-run reference resolution now correctly handles out-of-order LDAP imports and foreign key persistence
- π Cross-page reference RPEIs are now merged instead of creating duplicates
- π LDAP AddRequest now chunks large multi-valued attributes to avoid directory server size limits
- π Default
userAccountControlto 512 on Create exports via Coalesce, preventing AD account creation failures - π Parent activity progress messages no longer overwritten by child activities
- π Activity detail page correctly reloads when navigating between parent and child activities
- π Group member change history no longer shows "(identifier not recorded)" for members imported in a later batch β the DN string is now recorded when the referenced CSO hasn't been persisted yet at change history time
PerformanceΒΆ
- β‘ Change history and RPEI persistence now uses PostgreSQL COPY binary import, dramatically reducing write time for large sync operations (#398)
- β‘ Cross-batch reference fixup skipped entirely when no unresolved references exist (#398)
- β‘ Partial database indexes added for cross-batch reference fixup queries (#397)
0.6.0 - 2026-03-12ΒΆ
AddedΒΆ
- β¨ Disconnection causality tracking β causality tree now traces MVO attribute changes and deletion fate during disconnection and recall, showing exactly what happened and why (#392)
- β¨ Reference attributes rendered as clickable links on RPEI detail page for easy navigation to related objects
- π₯οΈ Filter controls on the Activities list page for quick searching by status, connector, and profile
- π₯οΈ Initiated-by name now included in activity search results
FixedΒΆ
- π Export activity detail page now shows display name for Create-type exports even after the target CSO is later deleted β display name is now snapshotted from the Pending Export's attribute changes at export time
- π Causality tree no longer shows a spurious attribute count chip on MVO Projected nodes when reference attributes were merged into the projection
- π Export runs no longer silently skip Pending Exports when a batch contains only deferred or ineligible items β all staged exports are now reliably processed in a single export run
- π Activity detail page now shows display name and object context for Create-type Pending Exports surfaced during sync (previously showed dashes as no CSO exists yet)
- π RPEI detail page now shows Pending Export attribute changes for staged (informational) Pending Exports, not only for error states
- π Causality tree no longer shows unrelated Pending Exports when a secondary import connector syncs while a previous connector's Create exports are still queued β only exports caused by the current sync's attribute changes are shown
- π Group membership exports no longer arrive empty β resolved reference foreign keys are now persisted during import
- π Resolved reference values now correctly persisted after export, preventing data loss on subsequent sync runs
- π Duplicate Pending Exports no longer accumulate β stale entries are automatically self-healed
- π Activities with unhandled errors now correctly marked as completed with error instead of appearing successful
- π Multi-valued attributes in LDAP group member exports are now consolidated into a single AddRequest, fixing partial membership writes
- π Export batch queries now include CSO object type, resolving objectClass errors in LDAP targets
- π Single-valued attribute duplicates no longer occur during Pending Export merges
PerformanceΒΆ
CSO Large MVA Pagination (#320)ΒΆ
- β‘ CSO detail page and API now load capped MVA values (first 100) instead of the full collection, dramatically reducing memory and load time for objects with 10K+ multi-valued attributes
- β¨ New paginated attribute values API endpoint (
GET /api/connected-systems/{csId}/objects/{csoId}/attributes/{attributeName}/values) with server-side search and pagination - π₯οΈ MVA dialog now fetches data on demand with server-side search and pagination β no longer holds the full value set in Blazor circuit memory
- β¨ API responses include per-attribute value summaries showing total count, returned count, and whether more values are available
Large-Scale Import OptimisationΒΆ
- β‘ Full import operations now handle 100K+ objects without out-of-memory failures through batch processing, raw SQL persistence, and incremental memory release
- β‘ Export operations at scale now batch-load to eliminate EF change tracker overhead
- β‘ Real-time batch progress reporting during large CSO persistence operations
0.5.0 - 2026-03-08ΒΆ
AddedΒΆ
- β¨ Self-contained Object Matching Rules β Synchronisation Rules now carry their own matching logic for import and export, enabling fully portable rule definitions (#386)
- β¨ CRUD API endpoints for Synchronisation Rule Object Matching Rules (
GET,POST,PUT,DELETE/api/v1/synchronisation/sync-rules/{id}/matching-rules) - β¨ Matching mode switching API β toggle between simple and advanced object matching per Connected System
- π₯οΈ Sortable Object Mapping and Capabilities columns on the Synchronisation Rules page
FixedΒΆ
- π Setup script now correctly detects Docker Desktop alongside Docker Engine
0.4.0 - 2026-03-05ΒΆ
AddedΒΆ
- β¨ One-command deployment β new interactive installer auto-detects the latest release, configures SSO and database, and starts JIM in minutes
- π¦ Production-ready Docker Compose configuration β deploy JIM from pre-built images without needing source code
- π¦ Standalone deployment files attached to each GitHub release for easy download without cloning the repository
- β¨ Welcome banner displayed on successful PowerShell connection
- π Comprehensive Deployment Guide covering prerequisites, topology options, TLS, reverse proxy, upgrades, and monitoring
- π₯οΈ Sortable columns on the Attribute Flow table
- π₯οΈ Filter controls on the Attribute Flow table
- β¨ Edit Attribute Flow mappings inline on the Synchronisation Rule detail page
- π₯οΈ Synchronisation Rule detail page redesign with expression highlighting, table/card views, and improved layout
- π₯οΈ Synchronisation Rules quick link on the homepage dashboard
- π₯οΈ Filter controls on the Connected System Objects list page
- π₯οΈ Full-width layout option for table-heavy pages
- π₯οΈ Confirmation dialog before deleting Attribute Flow mappings
- β¨
Get-JIMMetaverseObject -Allβ automatically paginates through all results in a single command - β¨ Pronouns attribute support (#360, #362)
- β¨ Sync Outcome Graph β full causal tracing of every change during synchronisation, showing exactly why each object was projected, joined, updated, disconnected, or exported (#363)
- β¨ Configurable sync outcome tracking level (None / Standard / Detailed) β control how much causal detail is recorded per synchronisation (#363)
- π₯οΈ Colour-coded outcome summary chips on Activity Detail rows for at-a-glance sync result visibility (#363)
- π₯οΈ Filter activity results by outcome type β quickly find projections, joins, Attribute Flows, exports, and more (#363)
- β¨ Export change history β drill into exactly which attributes were changed on each exported object, with before/after values
- π Hardened release pipeline with container scanning, SBOM attestation, and build validation
- π¦ Application blocks readiness until database migrations are applied
ChangedΒΆ
- π Replaced "Change Type" filter with richer outcome type filtering on the Activity Detail page (#363)
- π Renamed Activity statistics labels for clarity ("Stats" β "Outcomes", "Unchanged" β "CSOs Unchanged")
FixedΒΆ
- π
Get-JIMMetaverseObjectnow correctly returns all results when page size exceeds 100 - π Fixed spurious export operations being generated for objects queued for immediate deletion
- π Activity Attribute Flow statistics now show accurate object counts instead of inflated per-attribute counts
- π Connected System Object join state now reliably persisted during synchronisation
- π Activity Detail rows now show display name and object type even after the Connected System Object has been deleted (#363)
- π OIDC
Identity.Namenow correctly resolved when claims are unmapped - π Two-pass CSO processing prevents false
CouldNotJoinDueToExistingJoinerrors during synchronisation
PerformanceΒΆ
- β‘ Sync engine performance β up to 37% faster synchronisation through optimised batch persistence of activity results (#338)
0.3.0 - 2026-02-25ΒΆ
AddedΒΆ
Scheduler Service (#168)ΒΆ
- Schedule data model with cron and interval-based trigger support
- Background scheduler service with 30-second polling cycle
- Multi-step schedule execution with sequential and parallel step modes
- Schedule management REST API (CRUD, enable/disable, manual trigger, execution monitoring)
- Schedule management UI integrated into Operations page with tabbed interface
- Custom cron expression support with pattern-based UI
- Queue all schedule steps upfront for near-instant step transitions
- PowerShell cmdlets:
New-JIMSchedule,Get-JIMSchedule,Set-JIMSchedule,Remove-JIMSchedule,Enable-JIMSchedule,Disable-JIMSchedule,Add-JIMScheduleStep,Remove-JIMScheduleStep,Start-JIMSchedule,Get-JIMScheduleExecution,Stop-JIMScheduleExecution - Scheduler integration tests (Scenario 6)
Change History (#14, #269)ΒΆ
- Full change tracking for Metaverse Objects and Connected System Objects with timeline UI
- Initiator and mechanism tracking (User, API, Sync, System)
- Deleted objects view with change audit trail
- Configurable retention and cleanup
- Change history records for data generation operations
- Granular per-change-type statistics replacing aggregate activity stats
Progress Indication (#246)ΒΆ
- Real-time progress bars for running operations on Operations page
- Percentage tracking and contextual messages
- Progress reporting for deferred exports and cross-page reference resolution
- Import progress tracking with pagination support
- Hidden page number indicator for single-page imports
DashboardΒΆ
- Home page redesigned as an informative dashboard
- Hover effect on clickable dashboard cards
- Application version displayed in page footer
Security and AuthenticationΒΆ
- Interactive browser-based authentication for the PowerShell module
- API key authentication support for sync endpoints
- Just-in-time initial admin creation on first sign-in (replaces startup-time creation)
LDAP Schema DiscoveryΒΆ
- Attribute writability detection during schema discovery
- Support for LDAP omSyntax 66 (Object(Replica-Link)) mapping to Binary data type
- LDAP description attribute plurality override on AD SAM-managed classes
Data GenerationΒΆ
SplitandJoinfunctions for multi-valued attribute transforms- Centralised GUID/UUID handling with
IdentifierParserutility
PowerShell ModuleΒΆ
- Flattened module directory structure
- Version endpoint with server version display on
Connect-JIM - Module now includes 75 cmdlets (11 new scheduler cmdlets added to the 64 from 0.2.0)
UI EnhancementsΒΆ
- Searchable dialog for large multi-valued CSO attributes
- CSO attribute table sizing and column order improvements
- Persist navigation drawer pin state to user preferences
- Persist category expansion state per object type in user preferences
- Show all attributes on RPEI projection detail page
- Culture-aware thousand separators on all numeric statistics
- Culture-specific day-of-week ordering in schedule configuration
- Theme preview page at
/admin/theme-preview - Demo mode for Operations Queue
Integration TestingΒΆ
-SetupOnlyflag for integration test runner-CaptureMetricsflag for performance metrics on large templates-ExportConcurrencyand-MaxExportParallelismrunner parameters- Scenario 8: Samba AD group existence checks with retry
Assert-ParallelExecutionTimingvalidation helperjim-test-allalias for comprehensive test runs (unit + workflow + Pester)
Logging and ObservabilityΒΆ
- PostgreSQL logs integrated into unified Logs UI
- Diagnostic logging for cache operations and stale entry invalidation
- Separate Disconnected RPEI recorded when processing source deletions
InfrastructureΒΆ
- Automated Structurizr diagram export via
jim-diagramsalias - Review-dependabot Claude Code skill for dependency PR review
ChangedΒΆ
- Purple theme refresh with vibrant logo-inspired colours
- Navy-o5 dark theme improvements
- Execution detail API returns all parallel sub-steps with
ExecutionModeandConnectedSystemId - Expression models and
IExpressionEvaluatormoved to JIM.Models for broader use - Change tracking built into
MetaverseServerCreate/Update methods - JIM version injected into diagram metadata from VERSION file
- Build timestamp added to dev version suffix
- Reduced logging level for high-rate sync events to improve log readability
- Removed hardcoded
JIM_LOG_LEVELoverrides from compose files - Removed fixed height constraint from MVA table on MVO detail page
- Description attribute categorised under Identity on MVO detail page
FixedΒΆ
- Cross-page reference persistence and export evaluation for
AsSplitQuerymaterialisation failures - Post-load SQL repair for
AsSplitQuerymaterialisation failures - LDAP export consolidation and drift merge for multi-valued attributes
- Null-value Update exports now correctly confirmed during reconciliation
- MVO Type included in cross-page reference resolution query
- EF Core identity conflicts during cross-page reference resolution and Pending Export reconciliation
- Pending CSO disconnections now accounted for when validating join constraints
- Connected System settings not persisting on save
- Partition column hidden on Run Profiles tab when connector doesn't support partitions
- Run Profile create/delete and dropdown positioning
- Container tree duplicates and selection not persisting
- Matching rule creation failing with duplicate key violation
ExecuteDeleteAsyncused for Pending Export deletion with inner exception unwrapping- Split child/parent
SaveChangescalls to prevent FK constraint violation FindTrackedOrAttachused for untracked Pending Export persistence- History cleanup interval respected across worker restarts
- Scheduler waits for full application readiness on startup
- Graceful worker cancellation instead of immediate task deletion
- Transient unresolved reference warnings downgraded to debug level
- Button styling improvements and error alert panel overflow prevention
- Visited link hover colour consistency
- Log external ID instead of empty GUID for unpersisted CSOs in reference resolution
- MVA table page size wired to global user preference
- Cache diagnostic logging and stale entry invalidation on external ID changes
- Integration test runner try/finally structure repaired
- Total execution time captured in integration test log files
PerformanceΒΆ
- Batch database operations for export processing (single
SaveChangesAsyncper batch instead of per-object) - Bulk reference resolution for deferred exports (single query instead of N+1)
- LDAP connector async pipelining with configurable "Export Concurrency" setting (1-16)
- Parallel batch export processing with per-system
MaxExportParallelismsetting (1-16) SupportsParallelExportconnector capability flag (LDAP: true, File: false)- Parallel schedule step execution (steps at the same index run concurrently via
Task.WhenAll) - Raw SQL for import and export bulk write operations (replacing EF Core bulk writes)
- Lightweight ID-only matching for MVO join lookups
- Skip CSO lookups entirely for first-ever imports on empty Connected Systems
- Service-lifetime CSO lookup index to eliminate N+1 import queries
- Tracker-aware persistence for untracked Pending Export entities
- Parallel in-memory Pending Export reconciliation using
Parallel.ForEach - Lightweight
AsNoTrackingquery for Pending Export reconciliation - Skip Pending Export reconciliation for CSOs without exports
- Parallel in-memory reference resolution using
Parallel.ForEach - Lightweight DB queries for batch reference resolution
- Raw SQL for
MarkBatchAsExecutingstatus update - Diagnostic instrumentation spans for export DB operations
- Worker heartbeat-based stale task detection and crash recovery
0.2.0-alpha - 2026-01-27ΒΆ
AddedΒΆ
PowerShell Module (61 new cmdlets, 64 total)ΒΆ
- Connected Systems management:
Get-JIMConnectedSystem,New-JIMConnectedSystem,Set-JIMConnectedSystem,Remove-JIMConnectedSystem - Schema management:
Import-JIMConnectedSystemSchema,Set-JIMConnectedSystemObjectType,Set-JIMConnectedSystemAttribute - Hierarchy management:
Import-JIMConnectedSystemHierarchy - Partition and container management:
Get-JIMConnectedSystemPartition,Set-JIMConnectedSystemPartition,Set-JIMConnectedSystemContainer - Connector definitions:
Get-JIMConnectorDefinition - Synchronisation Rules:
Get-JIMSyncRule,New-JIMSyncRule,Set-JIMSyncRule,Remove-JIMSyncRule - Synchronisation Rule Mappings with expression support:
Get-JIMSyncRuleMapping,New-JIMSyncRuleMapping,Remove-JIMSyncRuleMapping - Object Matching Rules:
Get-JIMMatchingRule,New-JIMMatchingRule,Set-JIMMatchingRule,Remove-JIMMatchingRule - Scoping Criteria:
Get-JIMScopingCriteria,New-JIMScopingCriteriaGroup,Set-JIMScopingCriteriaGroup,Remove-JIMScopingCriteriaGroup,New-JIMScopingCriterion,Remove-JIMScopingCriterion - Run Profiles:
Get-JIMRunProfile,New-JIMRunProfile,Set-JIMRunProfile,Remove-JIMRunProfile,Start-JIMRunProfile - Real-time progress tracking for Run Profile executions
- Activities:
Get-JIMActivity,Get-JIMActivityStats - Metaverse:
Get-JIMMetaverseObject,Get-JIMMetaverseObjectType,Set-JIMMetaverseObjectType,Get-JIMMetaverseAttribute,New-JIMMetaverseAttribute,Set-JIMMetaverseAttribute,Remove-JIMMetaverseAttribute - MVO deletion rule configuration
- API Keys:
Get-JIMApiKey,New-JIMApiKey,Set-JIMApiKey,Remove-JIMApiKey - Certificates:
Get-JIMCertificate,Add-JIMCertificate,Set-JIMCertificate,Remove-JIMCertificate,Export-JIMCertificate,Test-JIMCertificate - Security:
Get-JIMRole - Example Data:
Get-JIMExampleDataTemplate,Get-JIMExampleDataSet,Invoke-JIMExampleDataTemplate - Expressions:
Test-JIMExpression - History:
Get-JIMDeletedObject,Get-JIMHistoryCount,Invoke-JIMHistoryCleanup - Name-based parameter alternatives for all cmdlets (e.g.,
-ConnectedSystemNameinstead of-ConnectedSystemId)
API EndpointsΒΆ
- CRUD endpoints for Connected Systems (
POST,PUT/api/v1/synchronisation/connected-systems) - CRUD endpoints for Synchronisation Rules (
POST,PUT,DELETE/api/v1/synchronisation/sync-rules) - CRUD endpoints for Run Profiles (
POST,PUT,DELETE/api/v1/synchronisation/connected-systems/{id}/run-profiles)
InfrastructureΒΆ
- Release workflow for automated builds and publishing
- Air-gapped deployment bundle support
- PowerShell Gallery publishing
ChangedΒΆ
- Server-side filtering and sorting for MVO type list pages
0.1.0-alpha - 2025-12-12ΒΆ
AddedΒΆ
Core PlatformΒΆ
- Initial development release
- Core identity management functionality
- Blazor web interface
- REST API
- PostgreSQL database support
- Docker containerisation
- CSV connector
- Basic synchronisation engine
PowerShell Module (3 cmdlets)ΒΆ
- Initial preview release published to PSGallery
- Connection management:
Connect-JIM,Disconnect-JIM,Test-JIMConnection
InfrastructureΒΆ
- Release workflow for automated builds and publishing
- Air-gapped deployment bundle support
- PowerShell Gallery publishing