Changelog¶
WAPT-2.7 Serie¶
WAPT-2.7.0.19593 (2026-09-30)¶
hash: 10b94c8e
This is the first release of WAPT 2.7. As this is this a major version, it introduces some minor breaking changes. Please be sure to read thoroughly the breaking change list to prepare the upgrade.
Main highlights:
Redesign of WaptConsole and WaptSelfService
Performance improvement in console for large install base
Performance improvement on server with uWSGI enabled by default on Linux installation
Performance and stability gain on remote repositories using the new Wapt ProxyCache technology
Caching of Linux client updates using ProxyCache technology
Support for OpenID / Oauth2 / EntraID authentication
Kerberos auth handling directly in WAPT, no need of nginx SPNego module anymore
Improve ACL handling with role support and delegated admin role for user management
Upgrade from Python 3.10 to Python 3.11, all COTS upgraded
Support for ArcDataShield Digital Air Gap (DAG) product for isolated network
WAPT Discovery License has been re-written to explicitly exclude the use case where one install multiple WAPT servers to circumvent 300 desktops limit. WAPT Discovery was released for smaller organisations as a goto solution to keep their network uptodate and secure. It was not designed to help multi-million revenue corporations to improve their bottom lines.
Breaking changes:
[IMP] waptserver: user accounts and roles are now fully qualified (
myuser@mydomain.lan) if they are linked to a domain. A fallback to theuseraccount exists for the transition period using the parameteruser_acls_fallback_without_domain = True(default valueFalse) WaptUsers: addedroles. WaptUserAcls: addedmanaged_by,is_role, anddescriptionattributes.[NEW] wads:
login_on_wadsenabled by default.[IMP] waptagent: the
ad_groups_use_nested_groupparameter has been renamed touse_ad_nested_groups.[IMP] waptagent: dynamic configurations: maturities are additive. If several configuration packages specify the maturities parameter, the resulting value is the union of all values. Previously, the last configuration overwrote all the others.
[IMP] waptagent:
<pf86>\wapt\binis now in the Windows PATH instead of<pf86>\wapt. So onlywapt-get.exebinary is still one the%PATH%[IMP] waptagent: installation and audit logs are limited to 100 KB by default to avoid potential network and db overload
Warning
There are a few beaking changes, please be sure to review them before upgrading, see above
Known issues:
If kerberos is enabled on waptserver, if you connect to Wapt webserver welcome page using Google Chrome WITHOUT a proper client Kerberos configuration, the login prompt will be shown twice. This is due to a Google Chrome bug (https://issues.chromium.org/issues/40739141). You can switch to Firefox to have a proper Kerberos Negotiate handshake support.
Detailed changes:
[IMP] waptcore: updated COTS, Python 3.11.16, OpenSSL 3.5.8
[IMP] waptcore: in
waptdeploy.exeadd a manifest to avoid being run with UAC elevation[IMP] waptagent:
<pf86>\wapt\binis now in the Windows PATH instead of<pf86>\wapt. This prevents WAPT’s Python from potentially being used for other purposes, such as on development workstations. wapt-get.exe remains available in the PATH.[IMP] waptagent: installation and audit logs are limited to 100 KB by default to avoid potential network and db overload This can be modified on the agent using the
max_package_log_sizeparameter.[IMP] waptagent: the
ad_groups_use_nested_groupparameter has been renamed touse_ad_nested_groups.[IMP] waptagent: dynamic configurations: maturities are additive. If several configuration packages specify the maturities parameter, the resulting value is the union of all values. Previously, the last configuration overwrote all the others.
[IMP] waptagent: target verification for the installation of
host,unit, andprofilepackages: If the packages are not intended for the machine, they cannot be installed. Previously, they could still be installed, notably through a force install using the console.[NEW] waptagent: improve mustache templates with new built-in functions. Can be used in wapt-get outputs, in the WAPT console HTML viewers, and to format console plugin command lines:
DateTimeToText,DateToText,DateFmt,TimeLogToTextJsonQuoteJsonQuoteUri,ToJson,MarkdownToHtml,SimpleToHtml,WikiToHtml,BlobToBase64,EnumTrim,EnumTrimRight,PowerOfTwo,EqualsIf,NewGuidExtractFileName,HumanBytes,Sub', :code:`Values,Keys,MatchMatchI,GlobGlobILowerUpper,CamelCase,UnCamelCase,SnakeCase,KebabCase,DotCase,tojson2httpget,httpgetsafe,httppost,httppostsafejoin,joinvalues,get,countpadpadleft,localdatetimelocaldate,localtime,first,last,slice,b64encode,b64decode,sha256,sha1,md5,chr,csv,itemsiif,uncamelcase,unsnakecase,evaluate,calctotp[NEW] waptagent: added integrated HTML viewer helper for update package
html_view(title:str, html: str, autoclose:int=None, borderless:bool=False)->Dict[NEW] waptagent: wapt-get command line, added the
--login_method=option (auto,password,sessionkerberos,kerberos,oauth2,token,x509) to specify the authentication mode on the server.[NEW] waptagent: added wapt-get command line option for package management for the WAPT server repository:
search-package,download-package,show-package,edit-package. Filtering with--this,--locale,--maturity,--target_os,--architecture, and keywords or{package_uuid}. The--thisoption filters search results based on the machine’s capabilities.[NEW] waptagent: added wapt-get command line option
show-cert,sign-json,check-json,check-file-hash,open-config,.ini,wgets[NEW] waptagent: added wapt-get command line option
list-hostsOptions:--reachable,--has_errors,--need_upgrade,--order_by=,--limit=,--query_id=<int>,--uuid={uuid}, or--search=<keywords>or-q,--columns=<csv>,--try_kerberos=0/1[NEW] waptagent: added wapt-get command line option
trigger-action <action> args --optionsArgs are provided either as a simple single-quoted JSON object or as a list of arg=value pairs:{'package':'package','force':true} or package=package force=trueExample:wapt-get trigger-action trigger_host_audit force=true --login_method=openid -c waptconsole --reachable[NEW] waptagent: remote repositories: use of new ProxyCache technology instead of full synchronization.
[IMP] waptagent:
wapt-get uninstall <dir>can now only be used on a directory for package developement as it has no use in production[IMP] waptagent: improve local cache management, remove packages and updates that are needed anymore in a more deterministic fashion
[NEW] waptagent: in remoterepo ProxyCache, add a
head_timeoutoption for HEAD requests (default value 1000ms)[IMP] waptagent: during install, better handling of locked files to avoid blocking the upgrade. WaptSetup closes wapt binaries, pyscripter, vscode.
[IMP] waptagent: on Windows, set default
wapt_temp_dirto<wapt>\private\installto try to workaround potential “heuristic” false positive from EDR[IMP] waptagent: don’t add
wapt_base_dirto%PATH%to avoid wapt DLLs to be in the default search PATH[IMP] waptagent: set default
max_audit_data_size = 1Mto avoid having too large audit sent to the server.[IMP] waptagent: in waptdeploy, use
%WINDIR%\SYSTEMTEMPif it exists and user is SYSTEM account, else use%WINDIR%\TEMPto avoid lock stated due to EDR[IMP] waptagent: on linux, remove dependency on
kinit(krb5-user/krb5package)[IMP] waptconsole: global graphical redesign. Merged the package status and package summary tabs. Improved some progress indicators. Explicit choice of authentication mode in the login dialog.
[IMP] waptconsole: improve responsiveness : most server requests are now asynchronous to avoid graphical freezes. Limitation of the amount of queried data: only displayed columns are queried. Optimized the data transfer format: the mORMot compact format is faster to encode/decode and more compact (attribute name are not repeated on each json line of a same array)
[NEW] waptconsole: support for importing packages via a network partitioning security device such as DAG from ArcDataShield, and for
file:type URLs.[IMP] waptconsole: better display of stdout / stderr log from package installations.
[IMP] waptconsole: in remote repo, add check on remote repo availability and sanity-check.
[IMP] waptconsole: add app icons support in grids
[IMP] waptconsole: better text display widget with coloration, zoom, etc.
[IMP] waptconsole: add zoom on html viewer
[IMP] waptserver: enabled
uWSGImode by default on Linux. Allows long console requests to be processed using multithreading.[NEW] waptserver: added OpenID / OAuth2 authentication.
[NEW] waptserver: added the concept of “roles” to define ACLs for a user account. Mapping to AD groups if the WAPT server is linked to an AD. Explicit roles can be added to an account. AD groups are mapped to roles with the same qualified name (
mygroup@mydomain.lan).[NEW] waptserver: Added the account management ACL to allow account creation to be delegated to administrators without granting the full “admin” ACL. Accounts created by a delegated administrator have ACLs limited to those of the account administrator.
[NEW] waptserver: Kerberos authentication is now handled by the waptserver service and no longer at the nginx level. The
libnginx-mod-http-auth-spnegomodule is no longer required.[IMP] waptserver: user accounts and roles are now fully qualified (
myuser@mydomain.lan) if they are linked to a domain. A fallback to theuseraccount exists for the transition period using the parameteruser_acls_fallback_without_domain = True(default valueFalse) WaptUsers: addedroles. WaptUserAcls: addedmanaged_by,is_role, anddescriptionattributes.[NEW] waptserver: added configuration parameters
admin_subnetsto limits access to administration endpoints to an IP range.[NEW] waptserver: added
default_host_audit_data_expiration_daysparameter. If no expiration date is set on audit data, the expiration is calculated by adding this value, in days, to the data creation date (created_on).[NEW] waptserver: expired audit data is deleted asynchronously by the wapttasks service. HostAuditData: added
replaced_by, populated by a trigger when one data item replaces another with the same host, section, key, and a newer date.[NEW] waptserver: data model changes: Hosts: added
asset_typeto add non waptagent inventory line in wapt inventory[IMP] waptserver: for Linux, proxycache can now be used as a caching mechanism for Linux client update (deb or rpm repositories).
[IMP] waptserver: add log cleaning tasks. By default
logsapi_keep_days = 365[IMP] waptserver: on windows, add a
UseDemoDHParamoption to speed up windows server install for demonstrations on virtual machines[IMP] waptserver: force readonly connexion on wapt db connexion if writing is not necessary in the api call.
[NEW] wads: Improved
wads.execommand line with parameterswads_matching_mode: 'uuid', 'serial_number', or 'mac_address'[NEW] wads:
login_on_wadsenabled by default.[NEW] wads: new waptserver config parameter
ipxe_urls, which is properly taken care during nginx postconf. Allows to use multiple custom reverse proxies to the/api/v3/baseipxe endpoint.[IMP] wads: deployement of Linux with encrypted filesystem using LUKS is now supported (template available)
[IMP] wads: deployment using secure boot through iPXE is now supported for Windows and Linux
[IMP] wads: in waptconsole inventory view, add option to add a machine to OS deploy to prepare re-imaging
[IMP] wads: during WADS deploymenent process, restart deployment automatically once machine has been properly registered in waptconsole
[IMP] waptwua: set status to
PENDING_REBOOTif a reboot is pending (to avoid unneededNEED_SCANstatus)[IMP] waptselfservice: improve support for accessibility on Windows with NVDA for visual impaired users
[IMP] waptselfservice: graphical redesign. Icons are now loaded on demand for better user experience and better performance
[IMP] waptselfservice: users and groups are fully qualified names for authentication and self-service ACLs (no fallback on short name)
[IMP] setuphelpers: when developing
update_packagefunction, addsetupdevhelpersimports too[IMP] setuphelpers: added
get_computer_domain,get_hostname_and_domain, andget_netfirewallrule. Use of Kerberos Keytab and CCache under Unix.[IMP] setuphelpers: improvements to
install_aptandinstall_deb. Addyaml_loads/yaml_dumpsyaml parser helper. Addsevenzip_extract_allhelper to uncompress all format supported by 7zip Addget_dmg_versionfor macOSextract_tarhelpers
WAPT-2.6 Serie¶
Please refer to WAPT 2.6 documentation