github TykTechnologies/tyk v4.0.2
Tyk Gateway v4.0.2, Tyk Dashboard v4.0.2

latest releases: v5.4.0-alpha3, v5.0.12, v5.0.12-rc2...
23 months ago

Tyk Gateway v4.0.2

Added

  • Added support for custom plugins using Python 3.9.

Changed

  • Updated the version of Debian in our gateway standard and hybrid Docker images, in order to address the identified CVEs.

Fixed

  • Policy object has been optimised in size, by reducing the number of duplicate data in its data structure. Fixed the methods field in the policy object to not contain duplicate http method values.
  • Fixed Gateway panic, when creating an organisation level API key.
  • Fixed a bug where in hashed environemnt, in MDCB worker node, full key Id was exposed in the Redis DB

Tyk Dashboard v4.0.2

Added

  • Added new Dashboard configuration option: security.hide_login_failure_limit_error, which hides the login retry attempts failure message "Retry in N seconds", as exposing the number of seconds can be seen as a vulnerability.

Changed

  • Replaced the REST word with HTTP on the API Creation screen, as the API definition resulted can describe different types of API structures and not only REST (i.e. TCP)

Fixed

  • Fixed the request of changing the CNAME for the developer portal, from within the Dashboard. Previously this action was returning a 404 http code, which prevented the change of the CNAME.
  • Fixed the leakage of Dashboard admins password history (only bcrypt hashes), when security.enforce_password_history configuration option was enabled.
  • Fixed an issue where the usage of an object placeholder (e.g. {{.object.name}}) won't remove the quotes of a string in UDG resulting in undesired behavior like in URL paths /user/"johndoe"
  • Fixed some displaying issues of the API listing table with some of them related to shrinking the viewport.

Don't miss a new tyk release

NewReleases is sending notifications on new releases.