For the complete documentation index, see llms.txt. This page is also available as Markdown.

SigningHub v10.0.6

July 2026

New Features

Advanced Document Deletion Policies (SHE-47449)

SigningHub allows administrators to configure multiple document deletion policies based on document status and inactivity periods. Per-policy settings for pre-deletion notifications and email attachments provide greater flexibility and control over document retention workflows.

Multi-Lingual Slider Text Support (SHE-60300)

SigningHub supports multi-lingual slider text, allowing administrators to configure translations for slider content across all supported languages. Each slider can display language-specific text based on user preferences, improving localisation across the login and branding experience.


Improvements

Session-Based Logout Support Using x-session-id (SHE-60351)

The SigningHub Web authentication APIs return an x-session-id header upon successful login. This session ID enables session-based logout and revocation of active sessions.

Configurable Authentication Flow for Login (SHE-57488)

SigningHub allows administrators to configure the login authentication flow to use either a pop-up or browser redirection for third-party authentication methods such as OIDC, SAML, and OAuth.

Non-PDF/A Document Warning (SHE-47441)

SigningHub allows enterprises to enable warnings for documents that are not PDF/A compliant. When enabled, users are notified through visual indicators upon uploading a document during the workflow, improving document visibility and awareness.

SigningHub allows administrators to hide the forgot/reset password option from SigningHub applications or redirect users to a custom password reset URL.

Enterprise Role Assignment Restrictions (SHE-55701)

SigningHub allows enterprises to control which roles can be assigned by users of a specific enterprise role. This ensures that users can only assign authorised roles during user creation and management, providing greater control over role administration.

Personal to Enterprise Templates (SHE-55829)

SigningHub allows users to save personal templates as enterprise templates, making them available across the enterprise. Users with the appropriate permissions can also choose to save new templates to both personal and enterprise template libraries.

Immediate Termination of Active Signing Sessions (SHE-59880)

SigningHub ensures that when a workflow is recalled or deleted, all active recipient sessions are immediately terminated. Users viewing the document are notified in real time and redirected to the dashboard, ensuring secure and consistent session handling across the platform.

Dynamic Email Support in OIDC login_hint Parameter (SHE-60116)

The SigningHub OIDC flow passes the user’s email in the login_hint parameter when supported by the identity provider; if not allowed, it falls back to the email entered on the login screen.

Guest User Validation and National ID/Mobile Update Support (SHE-61067)

SigningHub enhances guest user management by enabling updates to National ID and mobile number during workflow user updates via the Add Users to Workflow API. A new user validation API is also introduced to identify guest users and return their status using a dedicated guest_user flag for non-existent, deleted, or guest accounts.

Enhanced PDF Rendering Quality on Mobile Web (SHE-60073)

The SigningHub mobile web experience has been enhanced to improve PDF rendering quality during document zoom operations. PDF content now displays with improved clarity and readability at supported zoom levels, ensuring sharper text and graphical content across supported mobile browsers.

Enterprise Logs in Admin (SHE-59877)

SigningHub allows administrators to view Enterprise Logs directly from the Admin Interface. This provides read-only, tenant-specific access to the same detailed audit information available to Enterprise Administrators, including support for search, filtering, and advanced log inspection within the Admin console.

Hide Login Options While Preserving API Authentication (SHE-60980)

SigningHub allows administrators to hide username/password login options from the user interface while still supporting authentication through APIs. This ensures that only configured identity providers (e.g., OIDC) are available on the login screen, while existing credentials remain usable for integration and API-based authentication flows.

JSON Import Template (SHE-46094)

SigningHub provides a JSON import template within both the Enterprise Templates and Enterprise Library import sections. This template helps users understand the required structure and format for JSON-based imports, improving accuracy and consistency during data upload.

Recipient NID Handling in GetPackageDetails Stored Procedure (SHE-61072)

SigningHub ensures that the GetPackageDetails stored procedure returns the correct National ID (NID) for recipients based on their associated enterprise in multi-enterprise scenarios. This resolves an issue where the logged-in user’s enterprise NID was previously returned instead of the intended recipient NID.

Auto-Trigger Last Authentication Method for Saved Accounts (SHE-59631)

SigningHub automatically triggers the last used authentication method when a user selects a previously saved login account. The email address is pre-filled, and the authentication flow is initiated seamlessly, improving the login experience for returning users across Web and Native applications.

Enhanced API Documentation Structure and Navigation (SHE-61174)

SigningHub now provides an improved API documentation experience with a new APIs Developer Guide page that provides centralized access to all API sections. Related links, access token references, and property descriptions have also been updated across Web and Admin API documentation.


Security Improvements

SigningHub strengthens session security by updating cookie configuration from SameSite=Lax to SameSite=Strict for frontend-generated cookies. This reduces CSRF exposure by ensuring cookies are only sent in first-party contexts, improving overall session protection across Web and Admin applications.

CSRF Antiforgery Validation for Web and Admin (SHE-60473)

SigningHub enforces antiforgery (CSRF) token validation for all state-changing operations across both Web and Admin applications. A dedicated middleware validates CSRF tokens for POST, PUT, PATCH, and DELETE requests, ensuring only requests with valid tokens are processed, while allowing configurable exemptions for specific endpoints.

Vulnerability Fixes

The following impacted CVEs have been resolved as part of this release:

CVE ID(s)
Severity
Affected Component
Updated Version

GHSA-4x5r-pxfx-6jf8

Low

babel/core

7.29.7

GHSA-g7r4-m6w7-qqqr

Low

esbuild

0.28.1

GHSA-p3vc-36g9-x9gr, GHSA-q6f4-qqrg-jv6x, GHSA-48r7-hpm6-gfxm , GHSA-39pv-4j6c-2g6v

High

angular/common

20.3.25

GHSA-rgjc-h3x7-9mwg

High

angular/core

20.3.25

GHSA-gcq2-9pq2-cxqm,

High

http-proxy-middleware

3.0.7

GHSA-36wm-hprc-mcf5, GHSA-7gg8-qqx7-92g5, GHSA-g22q-f7gc-5jhr, GHSA-q62c-h75r-2xhc, GHSA-8pj9-6897-74xc

High

Magick.NET-Q16-AnyCPU

14.14.0

GHSA-fx2h-pf6j-xcff

High

vite

7.3.5

GHSA-58w9-8g37-x9v5 GHSA-f3m7-gqxr-g87x

Moderate

angular/compiler

20.3.25

GHSA-9h5v-pfqq-x599

Moderate

ua-parser-js

2.0.10

GHSA-w5hq-g745-h8pq

Moderate

uuid

14.0.1

In addition, several other third-party dependencies have been updated to improve stability, security, and compatibility.


New ADSS Server Support

ADSS Server Support

SigningHub supports ADSS Server 8.4.1.


Important System Changes

As part of the upgrade to SigningHub 10.0.6:

  • SigningHub has been upgraded from .NET 8 to .NET 10, providing improved performance, enhanced security, and long-term platform support. This upgrade requires Microsoft .NET SDK 10.0.202 or later and Microsoft Windows Hosting Server 10.0.6 or later.

  • To enforce the principle of least privilege, Stamps and IDV are not allowed by default for all new and existing roles. During new enterprise registration, the default Enterprise Admin role allows the use of Stamps and IDV, and all configured enterprise stamps and IDV policies are available to the role. The default Enterprise User role does not allow the use of Stamps or IDV unless these permissions are explicitly granted.

  • For the Update Branding, Reset Branding, Update Enterprise Branding, and Reset Enterprise Branding APIs, the content parameter is no longer used to update branding content. From SigningHub version 10.0.6 onward, branding content must be provided through the translated_content parameter, which supports multilingual localised content. API responses, as well as the Get Branding, Get Enterprise Branding, and Get Enterprise Branding and Authentication Profile APIs, return localised branding content through translated_content, while content continues to contain only the default branding content for backward compatibility.

  • The ServicePlan APIs (Add, Update, GetById, and GetAll) include a breaking change in the auto-deletion configuration. The previous flat auto_delete_document structure has been updated to a nested model with two modes: Basic and Advanced. Existing settings like duration, notify, and email options are now part of the Basic section, while Advanced introduces support for multiple policies. The enabled state is now derived from the selected configuration rather than being stored directly. Clients using these APIs will need to adjust their integration to align with the updated structure.


Compatibility with Earlier Versions of SigningHub

SigningHub (iOS) & (Android) v10.0.6 are compatible with SigningHub 10.0.5 except for the breaking changes mentioned in the Important System Changes section.


For further details, contact us at sales@ascertia.com or visit www.ascertia.com.

Last updated