Centreon Web 25.10.0
Enhancements
- [ACL] Added Image Folders in ACL groups to allow access control to images in MAP.
- [Administration] Added INFO logs on API and CMA Tokens Add/Delete/Activate/Revoke and API Tokens usage.
- [Agent configuration] It is now possible to configure both connection direction in the same configuration. The user interface has been improved according to this.
- [Configuration] Added Insecure TLS connection mode to Agent configuration.
- [Configuration] Agent configuration - All certificate fields are now optional, to handle public certificate use case.
- [Configuration] Cleaned up labels in Agent configuration screens.
- [Configuration] Insecure TLS is now available as encryption mode in Agent configuration.
- [Credentials encryption] Configuration generation is now able to handle encrypted credentials.
- Vault paths are now exported in plain-text to pollers.
- [API] Added a new endpoint to bulk Duplicate Host Groups.
- [API] Added bulk enable/disable endpoint for hostgroups.
- [API] Added an endpoint to bulk Delete Host groups.
- [API] Added a new endpoint to bulk Delete services.
- [API] Added missing configuration change logs for service template configuration.
- [Configuration] Hostgroup form is now using REST API for update.
- [Configuration] Host form is now using REST API.
- [Configuration] Hostgroup form is now using REST API for deletion.
- [Configuration] Host form is now using REST API for deletion.
- [Configuration] Service form is now using REST API for deletion.
- [Configuration] Service Template form is now using REST API.
- [Configuration] Default 24/7 notification time period is now defined on base pack Host templates.
- [Configuration] Host_down_disable_service_checks and flapping are now enabled by default on pollers.
- [Configuration] Improved Hostgroup Add/Edit.
- [Configuration] Improved Hostgroup listing (columns, filtering, sorting).
- [Configuration] Improved the tooltip for Broker’s Unified SQL output.
- [Configuration] Replication enabled option has been removed from the Broker output form.
- [Core] Migrated to PNPM 10 and upgraded dependencies (React 19 and Cypress 14).
- [Core] Updated PHP dependencies to 8.2 version.
- [Core] Rectangular logos are now correctly displayed on the login page.
- [CSS] The Tailwind framework is now used, optimizing the loading of CSS elements.
- [Packaging] Increased php memory limit in centreon php configuration.
- [Dashboards] Added default sizes for widgets, and optimized their default positioning on the grid of the dashboard.
- [Dashboards] Custom views menu is now hidden on new installation or if no custom views are present.
- [Dashboards] Improved Status Grid widget responsiveness in condensed mode.
- [Dashboards] It is now possible to use regex (regular expressions) to filter certain resource types in specific widgets.
- [Dashboards] It is now possible to expand an individual widget.
- [Dashboards] Reduced spacing between items of the Dashboard page. It is now possible to resize the widgets horizontally or diagonally, either on the left or the right side.
- [Dashboards] When creating a new widget, the list of existing types of widgets is now categorized and ordered alphabetically.
- [Dashboards][Metrics Graph] Added new time periods: 14 days and 2 months.
- [Resource Status] Improved copy of executed command.
- [Resource Status] Improved the label of the “Sticky” option in the acknowledgement window.
- [Authentication Tokens] Added a welcome page when no token exists in the Authentication tokens page.
- [Configuration] Harmonized the interface for Additional Configurations with other screens.
- [UX] Added a button to copy the breadcrumbs on ReactJS pages.
- [UX/UI] Updated forms and pop-ups to improve readability and added a new tab navigation system for quick access to collapsible sub-menus.
Bug fixes
- Fixed missing French translations.
- A default token has been generated and applied to existing agent configuration.
- [ACL] Fixed issue when cumulating ACLs for a same user.
- [Configuration] Fixed an issue where export wasn’t taking in account macros inherited from indirect template parents.
- [Configuration] Fixed issue preventing user from disabling a meta-service.
- [Dashboards] Fixed contact search when sharing a dashboard or a playlist.
- Fixed an issue where exported tokens was ignored by Engine.
- Fixed an issue where notes weren’t displayed correctly in Administration > Logs.
- Fixed an issue where service deploy endpoint was adding the command line to the service.
- Forced BBDO 3.0.1 instead of 3.1 on pollers, to prevent a blocking issue.
- [LDAP] Fixed an issue on Users & Groups filters validation.
- [Metrics Graph Widget] Fixed an issue where an unexpected application error was occurring when selecting a custom time period.
- [Packaging] Updated permissions of token purge log file.
- [Resource Status] Fixed an issue that prevented the details panel from displaying correctly for a service that is part of a service group.
- [Translations] Fixed issue preventing translations from being displayed.
- [Unattended] On versions that use MySQL 8.0, the default authentication plugin is now mysql_native_password.
Security fixes
- [Administration] Fixed XSS in Administration > ACL > Action Access.
- [Configuration] Fixed XSS in Configuration > SNMP Traps form
- [Vulnerability] Fixed XSS vulnerability on Hosts templates.
- [Vulnerability] Fixed XSS vulnerability on Recurrent downtimes.
- [Vulnerability] Fixed XSS vulnerability on Resources Access parameters.
- [Vulnerability] Fixed XSS vulnerability on SNMP traps.
- [Vulnerability] Fixed XSS vulnerability on Connectors.
- [Vulnerability] [security] Fixed an RCE on poller reload page.

