Changelog

WAPT-2.7 Serie

WAPT-2.7.0.19593 (2026-09-30)

hash: 10b94c8e

This is the first release of WAPT 2.7. As this is this a major version, it introduces some minor breaking changes. Please be sure to read thoroughly the breaking change list to prepare the upgrade.

Main highlights:

  • Redesign of WaptConsole and WaptSelfService

  • Performance improvement in console for large install base

  • Performance improvement on server with uWSGI enabled by default on Linux installation

  • Performance and stability gain on remote repositories using the new Wapt ProxyCache technology

  • Caching of Linux client updates using ProxyCache technology

  • Support for OpenID / Oauth2 / EntraID authentication

  • Kerberos auth handling directly in WAPT, no need of nginx SPNego module anymore

  • Improve ACL handling with role support and delegated admin role for user management

  • Upgrade from Python 3.10 to Python 3.11, all COTS upgraded

  • Support for ArcDataShield Digital Air Gap (DAG) product for isolated network

  • WAPT Discovery License has been re-written to explicitly exclude the use case where one install multiple WAPT servers to circumvent 300 desktops limit. WAPT Discovery was released for smaller organisations as a goto solution to keep their network uptodate and secure. It was not designed to help multi-million revenue corporations to improve their bottom lines.

Breaking changes:

  • [IMP] waptserver: user accounts and roles are now fully qualified (myuser@mydomain.lan) if they are linked to a domain. A fallback to the user account exists for the transition period using the parameter user_acls_fallback_without_domain = True (default value False) WaptUsers: added roles. WaptUserAcls: added managed_by , is_role, and description attributes.

  • [NEW] wads: login_on_wads enabled by default.

  • [IMP] waptagent: the ad_groups_use_nested_group parameter has been renamed to use_ad_nested_groups.

  • [IMP] waptagent: dynamic configurations: maturities are additive. If several configuration packages specify the maturities parameter, the resulting value is the union of all values. Previously, the last configuration overwrote all the others.

  • [IMP] waptagent: <pf86>\wapt\bin is now in the Windows PATH instead of <pf86>\wapt. So only wapt-get.exe binary is still one the %PATH%

  • [IMP] waptagent: installation and audit logs are limited to 100 KB by default to avoid potential network and db overload

Warning

There are a few beaking changes, please be sure to review them before upgrading, see above

Known issues:

  • If kerberos is enabled on waptserver, if you connect to Wapt webserver welcome page using Google Chrome WITHOUT a proper client Kerberos configuration, the login prompt will be shown twice. This is due to a Google Chrome bug (https://issues.chromium.org/issues/40739141). You can switch to Firefox to have a proper Kerberos Negotiate handshake support.

Detailed changes:

  • [IMP] waptcore: updated COTS, Python 3.11.16, OpenSSL 3.5.8

  • [IMP] waptcore: in waptdeploy.exe add a manifest to avoid being run with UAC elevation

  • [IMP] waptagent: <pf86>\wapt\bin is now in the Windows PATH instead of <pf86>\wapt. This prevents WAPT’s Python from potentially being used for other purposes, such as on development workstations. wapt-get.exe remains available in the PATH.

  • [IMP] waptagent: installation and audit logs are limited to 100 KB by default to avoid potential network and db overload This can be modified on the agent using the max_package_log_size parameter.

  • [IMP] waptagent: the ad_groups_use_nested_group parameter has been renamed to use_ad_nested_groups.

  • [IMP] waptagent: dynamic configurations: maturities are additive. If several configuration packages specify the maturities parameter, the resulting value is the union of all values. Previously, the last configuration overwrote all the others.

  • [IMP] waptagent: target verification for the installation of host, unit, and profile packages: If the packages are not intended for the machine, they cannot be installed. Previously, they could still be installed, notably through a force install using the console.

  • [NEW] waptagent: improve mustache templates with new built-in functions. Can be used in wapt-get outputs, in the WAPT console HTML viewers, and to format console plugin command lines: DateTimeToText, DateToText, DateFmt, TimeLogToText JsonQuote JsonQuoteUri, ToJson, MarkdownToHtml, SimpleToHtml, WikiToHtml, BlobToBase64, EnumTrim, EnumTrimRight, PowerOfTwo, Equals If, NewGuid ExtractFileName, HumanBytes, Sub', :code:`Values, Keys, Match MatchI, Glob GlobI Lower Upper, CamelCase, UnCamelCase, SnakeCase, KebabCase, DotCase, tojson2 httpget, httpgetsafe, httppost, httppostsafe join, joinvalues, get, count pad padleft, localdatetime localdate, localtime, first, last, slice, b64encode, b64decode, sha256, sha1, md5, chr, csv, items iif, uncamelcase, unsnakecase, evaluate, calctotp

  • [NEW] waptagent: added integrated HTML viewer helper for update package html_view(title:str, html: str, autoclose:int=None, borderless:bool=False)->Dict

  • [NEW] waptagent: wapt-get command line, added the --login_method= option (auto, password, sessionkerberos, kerberos, oauth2, token, x509) to specify the authentication mode on the server.

  • [NEW] waptagent: added wapt-get command line option for package management for the WAPT server repository: search-package, download-package, show-package, edit-package. Filtering with --this, --locale, --maturity, --target_os, --architecture, and keywords or {package_uuid}. The --this option filters search results based on the machine’s capabilities.

  • [NEW] waptagent: added wapt-get command line option show-cert, sign-json, check-json, check-file-hash, open-config, .ini, wgets

  • [NEW] waptagent: added wapt-get command line option list-hosts Options: --reachable, --has_errors, --need_upgrade, --order_by=, --limit=, --query_id=<int>, --uuid={uuid}, or --search=<keywords> or -q, --columns=<csv>, --try_kerberos=0/1

  • [NEW] waptagent: added wapt-get command line option trigger-action <action> args --options Args are provided either as a simple single-quoted JSON object or as a list of arg=value pairs: {'package':'package','force':true} or package=package force=true Example: wapt-get trigger-action trigger_host_audit force=true --login_method=openid -c waptconsole --reachable

  • [NEW] waptagent: remote repositories: use of new ProxyCache technology instead of full synchronization.

  • [IMP] waptagent: wapt-get uninstall <dir> can now only be used on a directory for package developement as it has no use in production

  • [IMP] waptagent: improve local cache management, remove packages and updates that are needed anymore in a more deterministic fashion

  • [NEW] waptagent: in remoterepo ProxyCache, add a head_timeout option for HEAD requests (default value 1000ms)

  • [IMP] waptagent: during install, better handling of locked files to avoid blocking the upgrade. WaptSetup closes wapt binaries, pyscripter, vscode.

  • [IMP] waptagent: on Windows, set default wapt_temp_dir to <wapt>\private\install to try to workaround potential “heuristic” false positive from EDR

  • [IMP] waptagent: don’t add wapt_base_dir to %PATH% to avoid wapt DLLs to be in the default search PATH

  • [IMP] waptagent: set default max_audit_data_size = 1M to avoid having too large audit sent to the server.

  • [IMP] waptagent: in waptdeploy, use %WINDIR%\SYSTEMTEMP if it exists and user is SYSTEM account, else use %WINDIR%\TEMP to avoid lock stated due to EDR

  • [IMP] waptagent: on linux, remove dependency on kinit (krb5-user / krb5 package)

  • [IMP] waptconsole: global graphical redesign. Merged the package status and package summary tabs. Improved some progress indicators. Explicit choice of authentication mode in the login dialog.

  • [IMP] waptconsole: improve responsiveness : most server requests are now asynchronous to avoid graphical freezes. Limitation of the amount of queried data: only displayed columns are queried. Optimized the data transfer format: the mORMot compact format is faster to encode/decode and more compact (attribute name are not repeated on each json line of a same array)

  • [NEW] waptconsole: support for importing packages via a network partitioning security device such as DAG from ArcDataShield, and for file: type URLs.

  • [IMP] waptconsole: better display of stdout / stderr log from package installations.

  • [IMP] waptconsole: in remote repo, add check on remote repo availability and sanity-check.

  • [IMP] waptconsole: add app icons support in grids

  • [IMP] waptconsole: better text display widget with coloration, zoom, etc.

  • [IMP] waptconsole: add zoom on html viewer

  • [IMP] waptserver: enabled uWSGI mode by default on Linux. Allows long console requests to be processed using multithreading.

  • [NEW] waptserver: added OpenID / OAuth2 authentication.

  • [NEW] waptserver: added the concept of “roles” to define ACLs for a user account. Mapping to AD groups if the WAPT server is linked to an AD. Explicit roles can be added to an account. AD groups are mapped to roles with the same qualified name (mygroup@mydomain.lan).

  • [NEW] waptserver: Added the account management ACL to allow account creation to be delegated to administrators without granting the full “admin” ACL. Accounts created by a delegated administrator have ACLs limited to those of the account administrator.

  • [NEW] waptserver: Kerberos authentication is now handled by the waptserver service and no longer at the nginx level. The libnginx-mod-http-auth-spnego module is no longer required.

  • [IMP] waptserver: user accounts and roles are now fully qualified (myuser@mydomain.lan) if they are linked to a domain. A fallback to the user account exists for the transition period using the parameter user_acls_fallback_without_domain = True (default value False) WaptUsers: added roles. WaptUserAcls: added managed_by , is_role, and description attributes.

  • [NEW] waptserver: added configuration parameters admin_subnets to limits access to administration endpoints to an IP range.

  • [NEW] waptserver: added default_host_audit_data_expiration_days parameter. If no expiration date is set on audit data, the expiration is calculated by adding this value, in days, to the data creation date (created_on).

  • [NEW] waptserver: expired audit data is deleted asynchronously by the wapttasks service. HostAuditData: added replaced_by, populated by a trigger when one data item replaces another with the same host, section, key, and a newer date.

  • [NEW] waptserver: data model changes: Hosts: added asset_type to add non waptagent inventory line in wapt inventory

  • [IMP] waptserver: for Linux, proxycache can now be used as a caching mechanism for Linux client update (deb or rpm repositories).

  • [IMP] waptserver: add log cleaning tasks. By default logsapi_keep_days  = 365

  • [IMP] waptserver: on windows, add a UseDemoDHParam option to speed up windows server install for demonstrations on virtual machines

  • [IMP] waptserver: force readonly connexion on wapt db connexion if writing is not necessary in the api call.

  • [NEW] wads: Improved wads.exe command line with parameters wads_matching_mode: 'uuid', 'serial_number', or 'mac_address'

  • [NEW] wads: login_on_wads enabled by default.

  • [NEW] wads: new waptserver config parameter ipxe_urls, which is properly taken care during nginx postconf. Allows to use multiple custom reverse proxies to the /api/v3/baseipxe endpoint.

  • [IMP] wads: deployement of Linux with encrypted filesystem using LUKS is now supported (template available)

  • [IMP] wads: deployment using secure boot through iPXE is now supported for Windows and Linux

  • [IMP] wads: in waptconsole inventory view, add option to add a machine to OS deploy to prepare re-imaging

  • [IMP] wads: during WADS deploymenent process, restart deployment automatically once machine has been properly registered in waptconsole

  • [IMP] waptwua: set status to PENDING_REBOOT if a reboot is pending (to avoid unneeded NEED_SCAN status)

  • [IMP] waptselfservice: improve support for accessibility on Windows with NVDA for visual impaired users

  • [IMP] waptselfservice: graphical redesign. Icons are now loaded on demand for better user experience and better performance

  • [IMP] waptselfservice: users and groups are fully qualified names for authentication and self-service ACLs (no fallback on short name)

  • [IMP] setuphelpers: when developing update_package function, add setupdevhelpers imports too

  • [IMP] setuphelpers: added get_computer_domain, get_hostname_and_domain, and get_netfirewallrule. Use of Kerberos Keytab and CCache under Unix.

  • [IMP] setuphelpers: improvements to install_apt and install_deb. Add yaml_loads / yaml_dumps yaml parser helper. Add sevenzip_extract_all helper to uncompress all format supported by 7zip Add get_dmg_version for macOS extract_tar helpers

WAPT-2.6 Serie

Please refer to WAPT 2.6 documentation