<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" media="screen" href="git-log.css"?>

<log>
  <title>UniTime v4.9 build 156 change log (since the last release, build 152 on 12 Sep 2026 02:00)</title>
  <logentry revision="fafef8d">
    <commit>fafef8d73b1384bb239f11ba35996b32630f9ab3</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>2-Oct-2026 4:14 PM</date>
    <subject>Course Timetabling: Suggestions</subject>
    <msg>- Committed student conflicts: improved handling of committed student conflict when they are loaded in (not computed)</msg>
  </logentry>
  <logentry revision="6eb5743">
    <commit>6eb57433e66df50486c9744556a88ab5f76cead0</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>2-Oct-2026 4:14 PM</date>
    <subject>Examinations: Table</subject>
    <msg>- do not wrap assigned periods or individual assigned rooms</msg>
  </logentry>
  <logentry revision="e0909ee">
    <commit>e0909ee4bc0e609342e7afe63a419c31ad6531ec</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:57 PM</date>
    <subject>Hibernate Statistics: GWT</subject>
    <msg>- Hibernate Statistics page rewritten to GWT</msg>
    <msg>(set unitime.legacy.hibernateStats to true for the old Struts-based page)</msg>
  </logentry>
  <logentry revision="27b7e02">
    <commit>27b7e020ebe8dfe9a2afaca1afbadbd434540c31</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:57 PM</date>
    <subject>Solver Configurations: GWT</subject>
    <msg>- Solver Configurations page rewritten to GWT</msg>
    <msg>(set unitime.legacy.solverConfig to true for the old Struts-based page)</msg>
  </logentry>
  <logentry revision="90e2386">
    <commit>90e2386e6e8b62c08269d843a72d2cad677f3daf</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:57 PM</date>
    <subject>GWT: Buttons</subject>
    <msg>- when AriaButton.setAccessKey(char) is used, underline the matching character in on the button</msg>
  </logentry>
  <logentry revision="653d8e3">
    <commit>653d8e32d9526cb24f985322458b14301e60da84</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:57 PM</date>
    <subject>Application Configuration: GWT</subject>
    <msg>- Application Configuration page rewritten to GWT</msg>
    <msg>(set unitime.legacy.applicationConfig to true for the old Struts-based page)</msg>
  </logentry>
  <logentry revision="c35cab9">
    <commit>c35cab9a44bfac01524042627641c032b5a03e6f</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:57 PM</date>
    <subject>Test HQL</subject>
    <msg>- fixed an error when __Link or __Details are used</msg>
  </logentry>
  <logentry revision="a8ea3f0">
    <commit>a8ea3f069b7469db9022c8ff0643fc7c213d1531</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:57 PM</date>
    <subject>Code Cleanup: GWT</subject>
    <msg>- fixed a few Java warnings</msg>
  </logentry>
  <logentry revision="e3c8478">
    <commit>e3c8478cac1aa227ff6997cd1cbba8de3c047ea3</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:56 PM</date>
    <subject>Data Exchange: Academic Session Export</subject>
    <msg>- exclude scheduled tasks from the academic session export</msg>
  </logentry>
  <logentry revision="659b6a7">
    <commit>659b6a73bdc08b9f258200e7ab6d25ff9f9822a9</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:56 PM</date>
    <subject>XML API: disallow-doctype-decl</subject>
    <msg>- also secure XML parser against XXE attacks</msg>
  </logentry>
  <logentry revision="ae456b3">
    <commit>ae456b36107b49e9d2da109e5e6c9ab1693edfd8</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:56 PM</date>
    <subject>XML Security: Use Default SAXReader</subject>
    <msg>- use SAXReader.createDefault() when reading an XML file that disables external-general-entities, external-parameter-entities, and load-external-dtd</msg>
    <msg>- this is to fix the CWE-611 weakness (Improper Restriction of XML External Entity Reference)</msg>
  </logentry>
  <logentry revision="ecfc418">
    <commit>ecfc418b4c04328960b97df16ffbc3b4ff302166</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:55 PM</date>
    <subject>Dependencies: Apache FreeMarker</subject>
    <msg>- Apache FreeMarker updated to 2.3.35 (was 2.3.34)</msg>
    <msg>- this is to fix CVE-2026-84939 Apache FreeMarker template loading mechanism vulnerable to path traversal</msg>
  </logentry>
  <logentry revision="021d598">
    <commit>021d598541f2d65b08636e7ca6223a7cff09b6fc</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:55 PM</date>
    <subject>Users: API Token</subject>
    <msg>- new GWT-based page: make sure API token fits the page (does not get trimmed)</msg>
  </logentry>
  <logentry revision="ad54397">
    <commit>ad5439740e4903c7b8d69defb6d6b0fc3ed950a2</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>1-Oct-2026 5:55 PM</date>
    <subject>Add/Edit Academic Session: Dates</subject>
    <msg>- new GWT-based page: set the dates in server timezone</msg>
  </logentry>
  <logentry revision="a485676">
    <commit>a485676bd9dbd8ca3deb21fbdc45766115a5c7be</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>24-Sep-2026 7:32 AM</date>
    <subject>Code Cleanup: Unique Ids</subject>
    <msg>- do not convert unique ids to integers</msg>
  </logentry>
  <logentry revision="fd7f76c">
    <commit>fd7f76c2e130233ada35e4bd81fd17ef00b9003c</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>23-Sep-2026 9:16 AM</date>
    <subject>Room Availability: GWT</subject>
    <msg>- Room Availability page rewritten to GWT</msg>
    <msg>(set unitime.legacy.roomAvailability to true for the old Struts-based page)</msg>
  </logentry>
  <logentry revision="65cd05b">
    <commit>65cd05b990f5439d5d4292458a7cdbfdd1b3bc35</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>23-Sep-2026 9:16 AM</date>
    <subject>Instructional Types, Users: GWT</subject>
    <msg>- Instructional Types page rewritten to GWT</msg>
    <msg>(set unitime.legacy.itypes to true for the old Struts-based page)</msg>
    <msg></msg>
    <msg>- Users page rewritten to GWT</msg>
    <msg>(set unitime.legacy.users to true for the old Struts-based page)</msg>
  </logentry>
  <logentry revision="1255fd4">
    <commit>1255fd45a4018cdc68f426d00e17c0616846d7b3</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>23-Sep-2026 9:16 AM</date>
    <subject>Administration: GWT</subject>
    <msg>- admin pages using SimpleEditPage</msg>
    <msg>- when list field must be unique, only show current and unused items on the detail page</msg>
    <msg>- added long label for lists (long labels are used on the detail, short label when all records are edited at once)</msg>
    <msg>- field description can be an HTML</msg>
  </logentry>
  <logentry revision="4aceb9a">
    <commit>4aceb9a3225836cf2e3d655837e062b5d0b6b438</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>23-Sep-2026 9:16 AM</date>
    <subject>Administration: GWT</subject>
    <msg>- admin pages using SimpleEditPage</msg>
    <msg>- set max length for number fields</msg>
    <msg>- when multi field must be unique, each item can be selected at most once across all the records</msg>
  </logentry>
  <logentry revision="64d0f62">
    <commit>64d0f624fa28ce02348551ae37bb059bba765939</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>23-Sep-2026 9:15 AM</date>
    <subject>Customization: Banner 9 Catalog Course Details</subject>
    <msg>- improved error checking on the Ellucian API calls</msg>
  </logentry>
  <logentry revision="3bf03de">
    <commit>3bf03def29c7139d443279207ee12847cab6c175</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>23-Sep-2026 9:15 AM</date>
    <subject>Edit Class, Edit Scheduling Subpart: Date Pattern</subject>
    <msg>- old Struts-version of the page: fixed date pattern checking when date pattern id exceeds the max integer value</msg>
  </logentry>
  <logentry revision="4c22860">
    <commit>4c22860ea3e59ecd97f0e04732e226445170b18e</commit>
    <author>Tomáš Müller &lt;muller@unitime.org&gt;</author>
    <date>23-Sep-2026 9:15 AM</date>
    <subject>Instructor Detail: GWT</subject>
    <msg>- fixed the ability for the new GWT-based Instructor Detail page to be used the instructor</msg>
  </logentry>
</log>
