Delegated User Management v2 - Release Notes
About Delegated User Management v2
Delegated User Management v2 (DMv2) is the OneWelcome/Onegini identity platform's admin and self-service solution for managing organizations, users, invitations, applications, and access/admin roles across multi-tenant environments. It enables tenant administrators to delegate day-to-day user and access management, such as, inviting users, assigning roles, managing organizations and scopes, to designated admins within their organizations without requiring platform-level support.
DMv2 is the modernized successor to RITM and is built as a modular set of APIs and micro-frontends (MFEs) that can be combined to create a full self-service console or embedded in other applications.
Release 0.25.0
Release date: 2026-09-09
Features
-
Super Admin Configuration without Organization Switching: Super admins can now configure tenant- or organization-wide settings without first switching their active organization. This simplifies administration by eliminating the need to switch organizations.
-
Improved Multi-Organization Delegated Admin Login and Organization Switching: Delegated admins who manage multiple organizations can now sign in and switch between their organizations more seamlessly. The updated flow reduces the need for re-authentication when switching between organizations.
Bug fixes
-
Unable to invite a user in Kadaster test from the DM UI: Fixed an issue that prevented users from creating invitations in the Kadaster test environment due to an unhandled edge case in the invitation-creation flow.
-
Withdraw invitation API
withdrawReasonthrows mandatory error: Fixed an issue where thewithdrawReasonfield in the withdraw-invitation API was incorrectly enforced as mandatory. The field is now optional, allowing callers to withdraw an invitation without providing a reason. -
Equans unable to rename organizations in the UI: Fixed a defect that prevented the customer Equans, and potentially other tenants with the same configuration, from renaming organizations through the UI.
Release 0.24.0
Release date: 2026-08-28
Features
-
Life Cycle Management (umbrella feature): Introduced a consistent life cycle model for core DMv2 object types, including creating, activating, deactivating, and deleting objects, with defined status transitions.
-
Application Life Cycle Management: Applications in DMv2 can now be managed through defined life cycle states (for example, enabled/disabled/removed), rather than being limited to creation or hard-deletion.
-
Access Role Life Cycle Management: Access roles support the same life cycle handling, allowing roles to be safely retired without affecting existing user/role relationships.
-
Admin Role Life Cycle Management: Admin roles now follow the same life cycle pattern, improving consistency in how administrative permissions are provisioned and decommissioned.
-
Organization Life Cycle Management: Organizations can be managed through life cycle states, supporting scenarios such as temporarily disabling an organization without deleting its data.
-
Scope and User Life Cycle Management: Scopes and users also adopt the same life cycle handling, completing life cycle coverage across all the major DMv2 object types.
Release 0.23.0
Release date: 2026-08-24
Features
-
Scope-Based Administrative Authorization: Introduced scope-based authorization so that admin permissions can be constrained to specific scopes rather than being all-or-nothing.
-
DMv2: Implement tenant settings PATCH endpoint (correlation layer): Added a PATCH endpoint for partially updating tenant settings without resending the full settings payload.
-
DMv2: Allow changing access roles for scopes: Admins can now change the access roles assigned to a scope after its creation.
Improvements
- Replace calls that now fetch a full graph: Reworked several internal calls to fetch the complete relationship graph in a single pass instead of multiple round trips, reducing latency and the number of backend calls required to render certain views.
Bug fixes
-
Users UI: Invitations overview does not show all attributes: Fixed the Invitations overview grid so that all configured attributes and columns are displayed instead of a subset being silently omitted.
-
Create invitation "fails" when the Tulip workflow fails to be initiated: Fixed an issue where the Create invitation action was reported as failed when the downstream Tulip workflow failed to start, even though the invitation record was created successfully. The invitation outcome is now reported accurately.
-
Incorrect query parameter format for
searchScopein Administrator Roles search request: Fixed thesearchScopequery parameter format used when searching Administrator Roles. The parameter was previously malformed, which could cause search requests to be ignored or misinterpreted.
Release 0.22.0
Release date: 2026-07-23
Features
-
Application Launchpad: New self-service UI for end users to access their applications: Delivered a new self-service Application Launchpad screen where end users can view and access the applications they are entitled to, without requiring administrator assistance.
-
Access Roles: Access roles overview for self-service: Added a self-service overview page that lists a user's own access roles, improving visibility into the permissions they currently hold.
-
Searching, sorting, and filtering of objects in the DMv2 UI: Extended searching, sorting, and filtering capabilities across DMv2 UI object overviews, making it easier to locate specific users, roles, or organizations in larger tenants.
-
Introduced translatable custom validation messages: Form validation messages can now be translated and customized instead of being hard-coded, supporting localized and tenant-specific wording.
-
General DMv2 UI improvements: Implemented a collection of smaller UI/UX improvements and polish items across the DMv2 console.
-
Users MFE: Separate views for Users and Invitations: Separated the combined Users/Invitations screen into two dedicated views, making each easier to navigate and reducing clutter when managing large numbers of records.
Improvements
-
DMv2 and Users UI: Helper text shown when only one character is entered in a search: Added guidance text in the DMv2 and Users UI search fields to clarify the minimum number of characters required for a search, reducing confusion when searches return no results.
-
Implemented correct pagination for the "Get relationships with pagination" endpoint: Fixed the pagination logic for the relationships endpoint so that result pages are returned correctly and consistently.
-
DMv2 APIs: Add input validation and graceful error handling for malicious input: Hardened API input handling so that malformed or malicious payloads are rejected with clear error messages instead of causing unexpected failures.
-
Users UI: Hide the search bar and field dropdown when no attributes are marked as
DM_searchable: The Users UI now hides the search controls entirely when no searchable attributes are configured, preventing a non-functional search UI from being displayed.
Bug fixes
-
Custom Objects API: Fixed misleading "Invalid sortBy" error: Corrected an error message that incorrectly reported Invalid sortBy when the actual issue was sorting by a non-existing object type.
-
Users UI: Unable to select the current date as the Start Date for the Users and Roles validity period: Fixed a date-picker restriction that incorrectly prevented users from selecting today's date as the start of a validity period.
-
Add admin roles to user:
relationshipTypeis missing from the response: Updated the API response for adding admin roles to a user to include the missing relationshipType field, enabling consumers to correctly identify the type of relationship created. -
Access role visibility issues: Fixed cases where access roles were not visible as expected due to incorrect visibility and permission filtering.
Security
- Input validation and sanitization to protect against injection attacks: Added stricter input sanitization across DMv2 APIs to reduce the risk of injection-style attacks, including attempts to manipulate backend queries using malformed query or request body payloads.
Dependency updates
- Upgraded DMv2 to Node.js 24
- Upgraded TypeScript to 6.x
- Upgraded Vite to 8.x
- Upgraded Vitest to 4.x
- Upgraded Cypress to 15.18.1
Release 0.21.0
Release date: 2026-06-12
Improvements
-
Users UI: Improved admin roles and assignments: Improved the workflow for assigning admin roles to users in the Users UI, making the process clearer and less error-prone.
-
Admin Config MFE: Improved handling of validation schemas: Improved how the Admin Config micro-frontend processes and applies validation schemas, reducing edge-case validation errors.
Bug fixes
-
Issues with updating admin role assignments: Fixed issues encountered when updating an existing admin role assignment, as opposed to creating a new assignment.
-
DMv2 UI: Clicking the logo led to a 404 page: Fixed broken navigation where clicking the application logo routed users to a non-existent page instead of the home or dashboard screen.
Release 0.20.0
Release date: Not recorded
Features
-
Date optionality and DMv2 control of date optionality: Introduced control over whether date fields, such as validity start and end dates, are required or optional. This allows tenants to configure date handling according to their business rules instead of requiring dates in all cases.
-
Allow clearing attributes and properties: Added the ability to explicitly clear previously set attribute or property values instead of requiring users to overwrite them with a new value.
-
Implemented admin settings UI components for validity sections: Added new UI components to the Admin Settings screens for configuring validity-period sections.
-
Loading spinner for
removeRoleMutationinOrganizationAccessRolesTab: Added visual feedback in the form of loading spinner while a role-removal action is in progress, providing clear feedback that the action has been initiated.
Improvements
-
Improved "Create invitation" performance: Optimized the invitation creation flow to reduce response time.
-
Updated dynamic columns for all five overview pages so that each overview grid reflects the currently configured attributes.
-
Updated invitation date validation and user role date validation to improve consistency between date validation for invitations and user-role assignments.
Bug fixes
-
Hotfix for date optionality: Follow-up fix to the date optionality feature that addresses an issue found shortly after the initial rollout.
-
Fixed blank Settings page in console-ui hash routing context: Fixed an issue where the Settings page was blank when the application was loaded under hash-based routing within the console-ui shell.
-
Added
Acting-Tenant-Idheader for API calls in console-ui context: Ensured that API calls made from within the console-ui shell correctly include theActing-Tenant-Idheader so that requests are attributed to the correct tenant context. -
Intercept fetch to add
Acting-Tenant-Idfor theme SDK manifest request: Extended the tenant-context header handling to the theme SDK manifest request, which was not included in the initial fix.
Release 0.19.0
Release date: 2026-06-09
Features
- Added dynamic sorting support to DMv2 List/Search/Filter endpoints: Backend endpoints now accept a configurable sort parameter, allowing UI screens and API consumers to request results sorted by any supported field instead of using a fixed default order.
Improvements
- Added a generic, reusable Loading Spinner component to
dm-ui-mf-sdk: Introduced a shared loading spinner component in the shared UI SDK so that all DMv2 micro-frontends can provide consistent loading feedback instead of implementing their own components.
Release 0.18.0
Release date: 2026-05-22
Features
- Language selection in DMv2: Added the ability for users to select their preferred display language in the DMv2 UI.
Release 0.13.0
Release date: 2026-04-01
Features
-
Persona Selection: Introduced a persona selection step so that users with multiple roles or personas can choose the context in which they want to operate.
-
DMv2 UI: Use the
organizationIdfrom the user access token to support AJO/Tulip: The UI now derives the active organization from the claims in the user's access token instead of requiring theorganizationIdto be passed separately, enabling correct behavior when embedded in AJO/Tulip flows.
Improvements
-
Convert the List/Search/Filter invitations endpoint from using
queryto usingsearchin SA: Migrated the invitations listing, search, and filtering endpoint to use thesearchmechanism in the Scaled Access (SA) layer instead ofquery, aligning it with the pattern used by other object types and improving search consistency. -
Improved "Get/Add/Remove user's access roles/permissions in organization": Improved the reliability and correctness of the endpoints used to view, add, and remove a user's access roles and permissions within an organization.
-
Optional context usage in queries: Made the organization or tenant context parameter optional in certain queries where it was previously required, simplifying calls that do not need to be scoped to a specific context.
Release 0.5.0
Release date: 2024-12-01
Features
- Manage users: Create, view, update and manage users within an organization.
- Manage organizations: Create and manage organizations and their configuration.
- Manage applications: Create, view, and manage applications.
- Manage permissions: Define and manage permissions that control access to applications.
- Manage administrator roles: Assign administrative roles to users based on their responsibilities.
- Manage scopes: Define and manage scopes to control the organizations and access roles that an administrator can manage.
- Manage access roles: Assign access roles to users and control the permissions they have.