3.9.4 Release Notes

June 10th, 2024

Improvements

  • Due to new security restrictions in the latest versions of Safari, the browser can no longer differentiate between different types of connection errors. As a result, Web Password Filler now displays a more general error message: 'Unable to reach server. Verify that the server URL is correct, and that the server has a valid certificate.' This message appears for both certificate and network issues.

  • The caching of autofill matches have been removed. Web Password Filler now calls Secret Server every time it finds a login page. This change prevents issues where the system did not present new secrets to users for autofill.

Bug Fixes

  • A bug in the caching logic caused some secrets to not show up in the autofill match list.

  • The refresh icon appeared in the popup if the user did not have the 'Add Secret' permission and no secrets were present for that site.

  • Web Password Filler would sometimes display the 'Add Secret' dialog in the wrong browser window when adding a secret.

  • When working in Mimecast, the Web Password Filler icon was displayed for some email fields, even though those fields were not valid for autofill.

  • https://sso.cloud.com would not autofill in Web Password Filler.

  • Fixed an issue that caused visual corruption in some recorded sessions.

  • When using the Web Password Filler popup window to generate a password, the generated password contained duplicate letters. The passwords generated did not follow the Secret Server password policy.

  • The system sometimes displayed 404 errors to the user when making background network calls to check the validity of login URLs.

  • Updated the autofill field detection logic to handle login forms in Italian.

  • Web Password Filler did not close launched Chrome sessions upon secret check in or when the secret timeout limit was reached.

  • Web Password Filler reloaded the username page after the user submitted the username on some sites.

  • An OTP API call occurred every 30 seconds, even if the user did not have the secret information page open.