Security
- KC-1471: Prevent newline injection in
connectcommand prompts. Control characters are now escaped and shell comments handled, closing a path where an operator with Can Edit on a shared record could hide commands in a confirmation prompt and exfiltrate device credentials without being noticed. - KC-1462: Validate record ownership in the
audit-logcommand. Only operator-owned records are now eligible as an export destination, preventing an attacker from hijacking an export by sharing a malicious record with a matching title. Also removes TLS verification bypass from Splunk exports.
Features
- KC-1442: Add Classic-to-NSF conversion command, with negative-flow tests and support for skipping records that are already nested-share.
- DR-1324: Generate and deliver tokens.
Improvements
- KC-1461: Limit NSF folder depth on import, with a sibling-flatten fallback and a structure report when limits are exceeded.
- Improve
LoadRecordTypescommand: continues past invalid custom record types instead of aborting, with more verbose and color-coded logging. - Add filtering while printing inherited and denied-access permissions for folders and records.
Fixes
- Fix folder properties mutation bug in the NSF share-folder command.
- Fix service mode response status.
- Fix SaaS field check incorrectly flagging non-required blank values.