Delegated User Management v2 - Release Notes (Formatted)
About Delegated User Management v2
Delegated User Management v2 (DMv2) is the OneWelcome/Onegini identity platform's admin and self-service solution for managing organizations, users, invitations, applications, and access/admin roles across multi-tenant environments. It lets tenant administrators delegate day-to-day user and access management (inviting users, assigning roles, managing organizations and scopes) to designated admins within their own organizations, without requiring platform-level support. DMv2 is the modernized successor to RITM, built as a modular set of APIs and micro-frontends (MFEs) that can be composed into a full self-service console or embedded into other applications.
0.26.0 Feature
Orphan organization functionality and use-cases — Adds support for identifying and handling organizations that have no owner/parent linkage, along with related use-case flows.
Improvements
Users UI - Use "get user's roles in organization" endpoint instead of per-access-role "get access role by id" calls — Optimizes the Users UI by fetching all of a user's organization roles in a single call instead of making multiple individual access-role lookups. Application launchpad - Launch application by clicking on the application — Enables users to launch an application directly by clicking on its tile/icon in the launchpad, improving usability.
Bug Fixes
Cannot save user profile changes in Dev/Test & Pre-prod — edit form applies create-time start-date minimum — Fixes a bug where the edit form incorrectly reused the create-time minimum start-date validation, blocking profile updates in Dev/Test and Pre-prod environments.
Missing boolean field eHLoginExcluded in customAttributes API response payloads — Fixes the customAttributes API to include the missing eHLoginExcluded boolean field in its response payloads.
Release 0.25.0
Release date: 2026-09-09
Features
- Super Admin Configuration Without Organization Switching Super admins can now configure tenant/organization-wide settings without first having to switch their active organization context. This removes an extra manual step that previously forced admins to change organizations just to reach configuration screens.
- Multi-Organization Delegated Admin Login and Organization Switching Experience Delegated admins who belong to multiple organizations get a smoother login and organization-switching flow, letting them move between the organizations they manage without repeated re-authentication or a confusing selection experience.
Bug fixes
- Error while trying to invite a user in Kadaster test from the DM UI Fixed an issue where creating an invitation failed for a specific customer (Kadaster) due to an unhandled edge case in the invitation-creation flow.
- Withdraw invitation API
withdrawReasonthrows mandatory error ThewithdrawReasonfield on the withdraw-invitation API was being enforced as mandatory even though it is intended to be optional. The field's validation has been corrected so callers can withdraw an invitation without being forced to supply a reason. - Equans can't rename orgs in the UI Fixed a defect that prevented the customer Equans (and potentially other tenants in the same configuration) from renaming an organization through the UI.
Release 0.24.0
Release date: 2026-08-28
Features
- Life Cycle Management (umbrella feature) Introduced a consistent lifecycle model (create → activate/deactivate → delete, with associated status transitions) that is now applied uniformly across the core DMv2 object types below, instead of each object type handling activation/removal differently.
- Application Lifecycle Management: Applications registered in DMv2 can now be managed through defined lifecycle states (e.g. enabled/disabled/removed) rather than being only created or hard-deleted.
- Access Role Lifecycle Management: Access roles support the same lifecycle handling, so roles can be safely retired without breaking existing user/role relationships.
- Admin Role Lifecycle Management: Admin roles now follow the same lifecycle pattern, improving consistency for how administrative permissions are provisioned and decommissioned.
- Organization Lifecycle Management: Organizations can be managed through lifecycle states, supporting scenarios like temporarily disabling an organization without deleting its data.
- Scope / User Lifecycle Management: Scopes and users also adopt the same lifecycle handling, completing lifecycle coverage across all the major DMv2 object types.
Release 0.23.0
Release date: 2026-08-24
Features
- Scope-Based Administrative Authorization Introduced scope-based authorization so admin permissions can be constrained to specific scopes rather than being all-or-nothing.
- DMv2: Implement tenant settings PATCH endpoint (correlation layer) Added a PATCH endpoint for partially updating tenant settings without resending the full settings payload.
- DMv2: Allow changing access roles for scopes Admins can now change the access roles assigned to a scope after creation.
Improvements
- Replace calls that now fetch a full graph Reworked several internal calls to fetch the complete relationship graph in one pass instead of multiple round trips, reducing latency and backend calls needed to render certain views.
Bug fixes
- Users UI: Invitations overview doesn't show all attributes Fixed the Invitations overview grid so all configured attributes/columns are displayed, instead of a subset being silently dropped.
- Create invitation "fails" when the Tulip workflow fails to be initiated Previously, if the downstream Tulip workflow failed to start, the whole "create invitation" action was reported as failed even when the invitation record itself was created successfully. This has been corrected so the invitation outcome is reported accurately.
- Incorrect query parameter format for
searchScopein Administrator Roles search request Fixed thesearchScopequery parameter format used when searching Administrator Roles, which was previously malformed and could cause search requests to be ignored or misinterpreted.
Release 0.22.0
Release date: 2026-07-23
Features
- Application Launchpad: new self-service UI for end-users to access their applications
- Access Roles: access roles overview (self-service)
- Searching, sorting, and filtering of objects in the DMv2 UI
- Introduced (translatable) custom validation messages
- General DMv2 UI improvements
- Users MFE: split Users and Invitations into separate views
Improvements
- DMv2 and Users UI: show a helper text when only 1 character is typed for a search
- Implement correct pagination for the "Get relationships with pagination" endpoint
- DMv2 APIs: add input validation and graceful error handling for malicious input
- Users UI: hide search bar and field dropdown when no attributes are marked as DM_searchable
Bug fixes
- Custom Objects API: fix misleading "Invalid sortBy" error when sorting with a non-existing object type
- Users UI: unable to select the current date as Start Date for Users and Roles validity period
- Add admin roles to user:
relationshipTypeis missing in the response - Access role visibility issues
Security
- Add input validation and sanitization against injection attacks
Dependency updates
- Upgrade DMv2 to Node 24
- Update/upgrade to TypeScript 6.x
- Update/upgrade to Vite 8.x
- Update/upgrade to Vitest 4.x
- Update Cypress to 15.18.1
Release 0.21.0
Release date: 2026-06-12
Improvements
- Users UI: admin roles and assignment improvements
- Admin Config MFE: improved handling of validation schemas
Bug fixes
- Admin role assignment update issues
- DMv2 UI: clicking the logo led to a 404 page
Release 0.20.0
Release date: Not recorded
Features
- Date optionality & DMv2 optionality control of dates
- Allow clearing attributes & properties
- Implement admin settings UI components (validity sections)
- Add loading spinner to the
removeRoleMutationinOrganizationAccessRolesTab
Improvements
- Improve "Create invitation" performance
- Updated dynamic columns for all 5 overview pages, so each overview grid reflects the currently configured attributes.
- Invitation date validation and user role date validation changes, tightening consistency between how dates are validated for invitations versus user-role assignments.
Bug fixes
- Hotfix for date optionality A follow-up fix to the date-optionality feature above, addressing an issue found shortly after the initial rollout.
- Fix blank Settings page in console-ui hash routing context Fixed the Settings page rendering blank when the app was loaded under hash-based routing inside the console-ui shell.
- Add
Acting-Tenant-Idheader for API calls in console-ui context Ensured API calls made from within the console-ui shell correctly include theActing-Tenant-Idheader, so requests are attributed to the right tenant context. - Intercept fetch to add
Acting-Tenant-Idfor theme SDK manifest request Extended the same tenant-context header handling to the theme SDK's manifest request, which had been missed in the initial fix.
Release 0.19.0
Release date: 2026-06-09
Features
- Added dynamic sorting support to DMv2 List/Search/Filter endpoints Backend endpoints now accept a configurable sort parameter, so UI screens (and API consumers) can request results ordered by any supported field instead of a fixed default order.
Improvements
- Added a generic, reusable Loading Spinner component to
dm-ui-mf-sdkIntroduced a shared loading-spinner component in the shared UI SDK so all DMv2 micro-frontends can show consistent loading feedback instead of each team building their own.
Release 0.18.0
Release date: 2026-05-22
Features
- Language selection in DMv2 Added the ability for users to select their preferred display language within the DMv2 UI.
Release 0.13.0
Release date: 2026-04-01
Features
- Persona Selection Introduced a persona-selection step so users with multiple roles/personas can choose which context they want to operate in.
- The DMv2 UI picks up the
organizationIdfrom the user access token, supporting AJO/Tulip The UI now derives the active organization from the claims in the user's access token rather than requiring it to be passed separately, enabling correct behavior when embedded in AJO/Tulip flows.
Improvements
- Convert the List/Search/Filter invitations endpoint from using
queryto usingsearchin SA Migrated the invitations listing/search/filter endpoint to use thesearchmechanism in the Scaled Access (SA) layer instead ofquery, aligning it with the pattern used by other object types and improving search consistency. - Improve "Get/Add/remove user's access-roles/permissions in organization" Improved the reliability and correctness of the endpoints used to view, add, and remove a user's access roles/permissions within an organization.
- Optional context usage in queries Made the organization/tenant "context" parameter optional in certain queries where it was previously always required, simplifying calls that don't need to be scoped to a specific context.
Release 0.5.0
Release date: 2024-12-01
Features
- Manage users — Create, view, update and manage users within an organisation.
- Manage organisations — Create and manage organisations and their configuration.
- Manage applications — Create, view and manage applications.
- Manage permissions — Define and manage permissions that control access to applications.
- Manage administrator roles — Assign administrative roles to users based on their responsibilities.
- Manage scopes — Define and manage scopes to control the organisations and access roles an administrator can manage.
- Manage access roles — Assign access roles to users and control the permissions they have