Release Notes for Oracle Health Insurance Value-Based Payments Release 4.26.1.0.0

This document contains the release notes for Oracle Health Insurance Value-Based Payments Release 4.26.1.0.0.

Version compatibility: Oracle Health Insurance Value-Based Payments Release 4.26.1.x is only compatible with other Oracle Health Insurance applications release version 4.26.1.x unless explicitly stated otherwise.
In accordance with the OHI error correction policy (Document KB347263 on My Oracle Support), error correction will be provided for: a) the current release, and b) the preceding release for a grace period of 6 months.

Enhancements

ID Summary Patch

CPN-3502

Improved query efficiency for configuration entities with dynamic data tables

This enhancement optimizes how the system handles queries on configuration entities with dynamic data tables (such as message groups). Previously, the system repeatedly fetched information from these dynamic data tables, resulting in slower access. With this release, the system retrieves data from memory whenever possible, delivering faster performance.

CPN-3641

Enhanced PHI logs access using base views

In SaaS deployments, PHI access logs are stored in the database for 60 days in the PHI_LOG_EVENTS table. Logs older than 60 days are moved to OCI Object Storage by a daily database scheduler job. Prior to this release, customers could query recent logs (≤ 60 days) using the logphievents generic API, but accessing older logs required raising an SR with the AMS team to retrieve files from OCI Object Storage.

This enhancement improves the customer experience by enabling PHI access logs to be extracted directly through base view generation. The PHI_LOG_EVENTS table is now included in base view generation, allowing customers to schedule a daily extract of the PHI_LOG_EVENTS_BV base view and load the extracted data into their own data warehouse for analysis and reporting.

An access restriction is created for PHI_LOG_EVENTS_BV, but it is not automatically granted to the ALL_VIEW_ACCESS_ROLE.

4.25.1.0.1

CPN-3676

Upgrade to Java 21, Jakarta EE 9.1 and WebLogic 15.1.1

This enhancement upgrades Java to version 21, Java EE to Jakarta EE 9.1 and WebLogic to version 15.1.1. See "Additional Upgrade Steps for Installation" below and the installation guide for more details.

CPN-3775

Allow purging of data with a 7-day retention period in non-production environments

The data purge process previously required a minimum retention period of 30 days. This enhancement allows to configure a lower retention period (e.g: 7 days) specifically in non-production environments, while production environments maintain the 30-day policy. This change will help optimize disk space in non-production environments.

CPN-3799

Operational Reports and Data Transfer

The following changes are made in Operational Reports and Data Transfer:

  • In the previous release, the CSV files generated by the Data Transfer IP did not include a header row. In this release, CSV files include the header.

  • In the previous release, when a query returned no records, the Data Transfer IP responded with HTTP 200 with an empty response body. This behavior is changed to return HTTP 204 (No Content).

  • Two new error messages are introduced in the Operational Reporting IP. The IP returns an HTTP 422 response with one of the following error messages:

    • OHI-IP-ORV-008: View {0} does not exist

    • OHI-IP-ORV-009: Access restriction grant is missing to query the view {0}

  • Default PAR (Pre-Authenticated Request) URL expiry time has been changed from 30 minutes to 1 minute.

  • The following issues specific to On-Prem deployments are fixed:

    • Incomplete or truncated responses when querying very large data.

4.25.1.0.1

CPN-3862

Optimized evaluation of logging parameters in dynamic logic

When debug or trace logging is turned off, certain log statements may still trigger additional data retrieval or calculations in the background. This can slow down execution or cause errors, for example when trying to log a null value.

With this enhancement, such log statements are automatically guarded. When debug or trace logging is disabled, the associated expressions are skipped, avoiding unnecessary work and improving overall efficiency.

Example:

log.debug("Claim ID: {0}", claim.getId())

In earlier versions, claim.getId() was executed even if debug logging was disabled. If claim was null, this resulted in a NullPointerException, even though debug logging was turned off. With this enhancement, the expression is executed only when debug logging is enabled.

This enhancement applies only to new or recompiled dynamic logic.

CPN-3869

Expose Foreign Keys and Unique Keys on Base Views

The Data Transfer functionality requires some understanding of the data model and the keys between different Base Views. A Base View does not have a key on its own, but the underlying tables do.

This enhancement introduced two new tables:

  • BVG_FOREIGN_KEYS, representing the foreign key relations between two Base Views

  • BVG_KEYS, representing the unique and primary keys on a single Base View

The data from each table can be accessed by a Base View itself.

CPN-3926

Automatic heap histogram collection for improved memory analysis

A heap histogram is a lightweight memory dump that provides detailed information about objects in the heap, including their class names, sizes, and counts. It helps identify memory leaks, understand object allocation patterns, and optimize memory usage.

With this enhancement, heap histograms are automatically captured in SaaS deployments when the heap memory reaches a critical state, enabling proactive and improved memory analysis.

CPN-3973

Groovy 5 upgrade

This release includes an upgrade from Groovy 4.x to Groovy 5.0.7. This upgrade introduces performance enhancements and new syntax options. For detailed information, please refer to the Groovy 5.0 Release Notes.

Some of the key breaking changes in Groovy 5 include:

  • Stricter handling of duplicate imports: In earlier versions of Groovy, the compiler was lenient when finding duplicate imports or an import and a similarly-named class definition. While having duplicates was considered poor style, the compiler followed the lenient behavior of letting the last definition "win". From Groovy 5, the compiler now follows Java behavior and gives an error in such cases.

  • New default imports from java.time: The java.time packages are an additional default import in Groovy 5. If you have classes in the default (no) package with the same names as classes in the java.time package, you will need to rename those classes, or place them in a package, or use an import alias, to avoid conflicts. The most common classes that might conflict are Year, Month, and Duration.

For additional details, see the Breaking changes section in the Groovy 5.0 release notes.

Not all internal compiler or runtime changes are fully described in the Groovy 5.0 release notes. Customers are therefore strongly advised to perform comprehensive unit and regression testing of the dynamic logic to ensure compatibility with Groovy 5.

To enable compatibility with Groovy 5, the bytecode of existing dynamic logic is reset during the upgrade. This reset causes the application start-up time to be slightly longer on the first startup after the upgrade, as the dynamic logic are recompiled at startup time. Future application restarts do not recompile this bytecode, so subsequent startups are faster.

CPN-3975

Optimized memory usage during dynamic field/records retrieval and activity processing through chunking strategy

Memory utilization is improved during the retrieval of dynamic fields and records in the dynamic logic. A new predefined method, getDynamicRecordsByType, is introduced to retrieve dynamic records based on the field usage name (refer to "Predefined Methods" in the Developer Guide for details).

Write access is enabled for all dynamic fields of attachedPolicyData within "Policy Calculation Period Segments", allowing these fields to be modified using Groovy-style property access instead of the setDynamicField method (see "Policy Calculation Period Segments" in the Developer Guide).

Additionally, activity processing chunking is introduced to further optimize memory usage. When enabled, activity groups are processed based on a configurable chunk size (default 100 MB), and transactions are committed once the defined threshold is reached to prevent excessive memory consumption, after which processing continues for the remaining activities of the group within the same iteration.

CPN-4025

Security logs retrieval via API and data transfer

Prior to this release, security logs were written only to the file system and were not accessible through any API. With this enhancement, SaaS customers can now retrieve security logs using a dedicated API as well as through the data transfer feature.

A new API, logsecurityevents, is introduced, backed by the new table LOG_SECURITY_EVENTS. A corresponding base view, PHI_LOG_SECURITY_EVENTS_BV, is now available to support extraction of security logs via the data transfer feature. This allows customers to schedule regular extracts (e.g., daily) and load the data into their own analytics or SIEM systems.

Access to security logs is controlled:

  • The access restriction for PHI_LOG_SECURITY_EVENTS_BV is created but not granted automatically to ALL_VIEW_ACCESS_ROLE.

  • A dedicated access role must be explicitly granted to users who are allowed to extract security logs.

The table LOG_SECURITY_EVENTS is included in auto-purge with a default retention period of 7 days.

4.25.1.0.1

CPN-4206

Introduced additional attributes in security logs for enhancing log auditing and parsing capabilities

Introduced the following new attributes in security logs:

  • eventCategory: All security events are categorized into distinct categories. This attribute holds the category assigned to the security event being logged.

  • eventType: Brief summary of the security event being logged.

  • eventOutcome: Outcome of the event. Possible values: Success or Failure.

  • eventSeverity: Describes the severity of the event. Possible values: INFO, WARN or ERROR.

  • httpStatusCode: HTTP response code of the request for which the event is being logged. This will be null whenever the code is not deterministic at the time of event.

  • failureReason: Briefly describes the reason of failure. This attribute will be non-null only where relevant.

  • apiEndpoint: Holds the API endpoint to which the request was sent.

  • sessionId: Identifies the session provided by the caller. Applicable to SaaS and UI requests.

  • accessTokenId: Identifies the access token associated with the request. Applicable to SaaS and non-UI requests

4.25.1.0.2

CPN-4207

Enhanced PHI access logs to include access scope, session ID and access token ID

Enhanced PHI access logs to include three new attributes:

  • accessScope: Indicates whether a single record or multiple records are accessed within a transaction.

  • sessionId: Identifies the session provided by the caller. Applicable to SaaS and UI requests.

  • accessTokenId: Identifies the access token associated with the request. Applicable to SaaS and non-UI requests.

4.25.1.0.2

CPN-4302

Configurable PHI Event Logging for Data Transfer IP

PHI event logging for Data Transfer IP is now configurable using the system property ohi.datatransfer.logging.phi.events.enabled.

By default, this property is set to true, so existing behavior remains unchanged and PHI access events continue to be written to LOG_PHI_EVENTS when PHI data is accessed during Data Transfer IP operations.

When this property is set to false, PHI access event records during Data Transfer IP operations are not written to LOG_PHI_EVENTS.

Before disabling PHI event logging, customers should review their audit, compliance, and security requirements.

NXT-26542

Exposed generic API for deployment metadata and extended User Preferences to support switching between customer and browser timezones

A generic deployment metadata API is now available to retrieve the customer time zone. The User Preferences API includes a new browserTimeZone flag, which defaults to false. When set to true, timestamps are displayed in the end user’s browser time zone. When set to false, timestamps are displayed in the configured customer time zone.

4.25.1.0.2

NXT-31011

Access Restriction on Download Feature

This enhancement links the ability to download data from the JET user interface to a user role. Only users with access to the Download Data restriction grant can download data from JET UI using the download action.

4.25.1.0.1

NXT-31023

Search Result Download in CSV Format

This enhancement addresses the issue of referenced fields being downloaded in one column as JSON data in the CSV exports from UI. With this enhancement all the displayed data of a reference field will be downloaded into separate columns.

4.25.1.0.1

NXT-31178

Upgrade to JET version 19.0.0

This enhancement upgrades the JET (JavaScript Extension Toolkit) core library to version 19 from 17. This uptake includes the required dependency, tooling, and compatibility updates to align the UI with the OJET 19, enabling continued support for the latest Oracle JET components, framework fixes, and runtime improvements.

NXT-31594

JET: Save user preferences for table displays

This enhancement enables you to save your table column selections and column widths on supported pages. After you adjust a table, select Save Preferences to save your settings for that page.

Where it applies

  • System- or floorplan-driven pages that use following templates when the flexColumn property is true (Note: Default setting is true):

    • View/Edit List

    • Search Object Table

Supported pages and tables

  • Product Definition

    • Product Service Definition table in products and across products page

  • Claims

    • Draft provider pricing clause table within worksheet and across worksheet page

    • Fee Schedule lines

    • Provider Pricing Clause

    • Claim lines table within claims page

  • Common

    • Reference Sheets

4.25.1.0.2

NXT-32017

UI: Additional Features Advanced Search

With this enhancement, the following multiple capabilities are added to the advanced search:

  • Ability to select query operators for different search criteria.

  • Ability to specify selected criteria as mandatory in advanced search.

  • Multiple adjustments to reference sheet lines, page searches, and sort, including the ability to search on nulls, the ability to sort on start and end dates, view last updated by, and time details.

4.25.1.0.2

NXT-32037

User Interface - Additional tab features

Added a 'Close Other Tabs' option via a three-dot menu to close all but the active tab, auto-scroll to keep the active tab visible, and improved tab closing behavior to fall back to the previous tab when closing the last tab.

4.25.1.0.2

NXT-32464

Non-Unique Provider Identifiers

This enhancement enables the configuration setting that controls whether a provider identifier is unique across providers.

NXT-32471

Improve handling of HTTP error: 401 UnAuthorized in JET UI

With this enhancement, OHI uses system property OHI_DEPLOYMENT_TYPE to handle HTTP 401 error. When this property value is set to "CLOUD", this will force a "401" response to re-direct the OHI JET login page when the IDCS OpenID session cookie is missing/expired.

4.25.1.0.2

NXT-32524

Table component improvements - Usability with editable row

Introduced check (Apply) icon as a table row-level action in edit mode. Clicking the check icon returns the row from edit mode to view mode. Actions in other rows will be disabled until the user clicks on the check icon of the current row being edited. Editable row remains in edit mode and persists the data when the user clicks outside the table or switches to another browser tab.

4.25.1.0.1

NXT-32617

UI: Ability to exclude trailing wildcard with like search

This enhancement allows excluding the automatic inclusion of the trailing wildcard for like search in quick search, advanced search, and lookups by setting the application property ohi.ui.likesearch.wildcard.enabled to false.

The system also auto-truncates the leading and trailing white space for searches.

4.25.1.0.1

NXT-32621

UI: Additional Features Quick Search

With this enhancement, the quick search component is extended, and it will be possible:

  • To include all types of fields in the quick search.

  • To have query operators like between, less than, greater than, etc, configurable in quick search.

  • To set specific search criteria flagged as mandatory.

4.25.1.0.1

NXT-32629

UI: Expandable "more" section in tables

With this enhancement, the overflow region for the table ("More" link) is now expandable to a two-column layout, allowing more information to be viewed at once.

4.25.1.0.1

NXT-32633

UI: Additional Features Sort

With this enhancement, the sort component is updated to display null values based on the sort order, that is, for Default and Criteria:

  • If the sort order is descending, nulls last is applied.

  • If the sort order is ascending, nulls first is applied.

It is now possible to specify sorting criteria for a multi-value property (list) configuration in a form and region.

4.25.1.0.2

NXT-33004

Copy Action for Duplicating Records on HRR Pages

The Copy Action is available when the metadata indicates that cloning is supported for a resource. It allows users to quickly duplicate an existing record by providing a new functional key. The system pre-fills the remaining values from the original record (excluding system-generated fields), allowing users to modify and save the new record while keeping the original record unchanged.

During cloning, the following child entities are not copied: User Roles for Access Roles, Relation Identifiers for Persons, and Provider Limit Rules for Provider Limit Categories.

Modifying individual child records during the clone operation is currently not supported for Access Restriction Grants under Access Roles, Partial Provider Pricing Clauses under Pricing Options, and Diminishing Rate Blocks, along with nested block amount and size lists, under Diminishing Rates.

4.25.1.0.2

NXT-33070

Improved Multi-Select Behavior for Row Selection in Tables

The record-selection behaviour has now been updated to follow an additive selection model, ensuring that selecting a record no longer clears existing selections. All previously selected records will remain selected and will not be unintentionally deselected.

Prior to this implementation, when user selects multiple records using checkboxes, clicking anywhere on a another row (outside the checkbox) would deselect all selected records except the one that was clicked.

NXT-33394

UI: Search Object - Table template to support edits

This enhancement introduces the ability to inline-edit table data on the search page, built on the 'Search Object - Table' template.

NXT-33488

Remove outer join for 'And' mode quick search

As part of this enhancement outer join is removed from "AND" mode based quick search and selection pop-up in LOV field. Also, outer join is removed for searches on insurable entity field in JET UI when used in quick search "OR" mode

4.25.1.0.2

NXT-33659

Disable user location based time conversion

JET UI no longer relies only on the user’s browser timezone for datetime display. This helps prevent incorrect time conversion for customers operating across different geographic locations. The customerTimeZone, configured in the deployment metadata table during application installation, is used by default by JET UI. Users can override this through the "Use Browser Timezone?" option in the Preferences dialog, after which the UI will use the browser timezone. If customerTimeZone is not configured or is invalid/unsupported by JET, the UI falls back to the browser timezone.

4.25.1.0.2

NXT-33697

UI: European date/number formatting for English Language

With this enhancement, support is added to keep the UI in English language while using European date and number formats (e.g., dd/MM/yyyy and 1.234.567,00), when user sets 'en‑EU' in the existing ohi.ui.default.locale system property. If the property is not set, date and number formats continue to follow the user’s selected locale (language + region), with no change in behaviour.

NXT-33718

Extended user preference - Reorder and Auto-commit

With this enhancement it is now possible to reorder table columns as per user’s preference. Also, the save button to store preference is replaced by auto commit feature.

This feature is available for all pages based on the following floor plan template:

  • View and Edit List Table

  • List View - Table

This feature is also available for selected pages which are not floorplan based:

  • Common Pages like Reference sheets.

  • Claims page claim line tab.

  • In Policies application, pages like Premium schedule lines, Adjustment lines, and Fee schedule lines.

4.25.1.0.2

NXT-33750

Enhance UI download functionality to include all search results based on query criteria.

This enhancement expands the UI download functionality, allowing users to export the complete set of search results that match the active query across all download-enabled use cases in the application.

POL-16056

Store Long Addresses

The character limit for the "Additional Address" fields has been increased from 60 to 250 characters. This change applies to the following fields:

  • ADDITIONAL PART 1

  • ADDITIONAL PART 2

  • ADDITIONAL PART 3

This update affects Relation Entities.

4.25.1.0.1

POL-16598

Detecting & resolving duplicate message transformation task.

  1. If a more recent transformation task exists, the older task is stopped to avoid duplicate tasks. This applies only to the Policies application.

  2. Only tasks with an Errored status can be restarted.

POL-16770

Ability to configure function change event rule for additional entities

This enhancement enables the use of function change event rules for the Relation Identifier entity.

POL-17431

Providers - Service Address - Store Long Addresses

The character limit for the "Additional Address" fields has been increased from 60 to 250 characters. This change applies to the following fields:

  • ADDITIONAL PART 1

  • ADDITIONAL PART 2

  • ADDITIONAL PART 3

This update affects Provider entity.

POL-17575

Reset a value using floorplan conditions

With this enhancement, a new optional floorplan property resetValue is introduced, which can be used within the condition block to reset the value for a field.

4.25.1.0.1

POL-17690

Integration Point’s design updated to handle code references case-insensitively.

After this enhancement, Integration Point’s design updated to handle code references case-insensitively (e.g. brandCode, policyCode, addOnCode), so values like "abc" match an existing "ABC" instead of causing update failures or unique-key violations.

POL-17946

Generic Auditing Framework

This enhancement introduces a Generic Audit Framework in OHI to provide standardized tracking of record-level and field-level changes across supported entities. It captures create, update, and delete actions along with details of what changed, who performed the action, and when it occurred. A new API allows users to retrieve audit history with filtering and pagination, while built-in access controls ensure audit visibility aligns with entity, record, and field-level permissions. Audit tracking applies only to user-driven or directly modified fields and does not include technical or system-generated (calculated) fields.

Audit API resources use separate access restrictions instead of inheriting those of their parent resources. Therefore, users with access to a resource, such as Policies, may still require an additional Audit API-specific grant.

The need to grant separate Audit API access will be removed in the next patch. Users with access to the main resource will automatically be able to access its Audit API.

POL-18132

UI: Conditional display of row-level actions: edit and delete for tabs.

This enhancement introduces the ability to control the display of actions (edit/delete) through initconditions.

4.25.1.0.2

POL-18358

Improved activity notification tracking and recovery by migrating to the OHI task-based framework.

This enhancement migrates activity notification processing to the OHI task-based framework. As a result, notifications are easier to track, support, and recover when delivery is delayed or fails.

POL-18631

Increased length for street and city address fields

With this enhancement, the 'street' and 'city' fields for relation addresses and provider service addresses now support up to 250 characters, increased from the previous limit of 60 characters.

Additional Upgrade Steps

Pre-Upgrade phase

  1. As part of CPN-3830, the access restriction type "Line of Business" is removed from Capitation application. If any access restrictions are currently configured using the "Line of Business" type, remove them using accessrestrictions API or JET UI.

Post-Deploy phase

  1. Groovy 5 is more restrictive and doesn’t support direct use of .size or .value on collections (lists)

    Example: Replace .size with size() and list*.value.sum() with list.sum()

    checkPOEP = defaultPoliciesSql.getPolicyEnrollmentProducts(testCode + '_POLI_001', 2, 'PERSON', testCode + '_RELA_001')
    // def poepSize = checkPOEP.size //INVALID,throws error
    def poepSize = checkPOEP.size() //VALID
    def customerList = getCustomerList(inputList)
    // Integer b = customerList*.value.sum(); //INVALID,throws error
    Integer b = customerList.sum(); //VALID

    The impacted dynamic logic to be identified and updated as stated below

    Identify the impacted dynamic logic using GUI based search or API as mentioned below

    API: POST generic/dynamiclogic/search

    {
    "resource": {"q":"logic.like('%*.value.sum()%').or.logic.like('%.size%')"}
    }
  2. Java 21 and Groovy 5 enforce stricter rules and no longer allow direct use of private variables and methods

    Example: Parsing the below JSON as a String and then calling .value on it results in an error, since .value is a private field of the String class and is not accessible

    "communicationPreference":[{"communicationMode": "EMAIL"}]
    person.communicationPreference.get(0).communicationMode.value //INVALID, throws error
    person.communicationPreference.get(0).communicationMode //VALID

    Identify the impacted dynamic logic using GUI based search or API as mentioned below and update it

    API: POST generic/dynamiclogic/search

    {
    "resource": {"q":"logic.like('%.value').or.logic.like('%.value.toString%')"}
    }
  3. With the Java 21 upgrade, Java EE-related package names have changed from javax to jakarta (for example, javax.ws is now jakarta.ws) as part of the adoption of Jakarta EE standards. Please update any use of javax.ws. in dynamic logic to jakarta.ws. to ensure compatibility.

    Identify the impacted dynamic logic using GUI based search or API as mentioned below and update it

    API: POST generic/dynamiclogic/search

    {
    "resource": {"q":"logic.like('%javax.ws.%')"}
    }

Upgrade Steps for Installation

To perform the upgrade, perform the following steps:

  1. Perform any pre-upgrade steps.

  2. Stop all the managed nodes running the existing version of the application.

  3. Perform any pre-undeploy steps.

  4. Undeploy the existing version of the application.

  5. Back up the database.

  6. Perform any post-undeploy steps.

  7. Unpack the release bundle into a directory that we refer to as OHI_ROOT from now on.

  8. Change Installation Configuration: In <OHI_ROOT>/util/install, make a copy of ohi_install.cfg.template and name it ohi_install.cfg.

  9. Edit ohi_install.cfg to contain your specific database connection data and other configuration settings. The settings are explained in the file itself.

  10. Make sure NO connections are present to the database using the OHI_xxx_USER account (where xxx is the abbreviation of the application)

  11. Run the Upgrade script:

    1. Open a command window and browse to <OHI_ROOT>/util/install.

    2. Run the upgrade by executing ./ohi-update.sh .

  12. Make the required changes to the ohi properties file

  13. Perform any post-upgrade steps

  14. Start WebLogic application server

  15. Deploy the Application

  16. Perform any post-deploy steps

Additional Upgrade Steps for Installation

The following phases are defined:

  1. pre-upgrade: Application is still running.

  2. pre-undeploy: Application is stopped, but not undeployed.

  3. post-undeploy: Application is undeployed. Database is backed up.

  4. post-upgrade: Released upgrade script run is complete.

  5. post-deploy: New application is deployed, and is up and running.

Post-UnDeploy Phase

See the "Upgrade Steps for JDK and WebLogic Installation" section in the Installation Guide.

Post-Upgrade Phase

  1. A new MDC (Mapped Diagnostic Context) field, user, has been introduced for security logs.

    To ensure this information appears in the security log file, update the log pattern for the securityAppender (which uses RollingFileAppender) to include the user MDC field.

    Example updated pattern
    <appender name="securityAppender" class="ch.qos.logback.core.rolling.RollingFileAppender">
        <encoder>
            <pattern>%d{ISO8601} [ %t ] %marker %c - %m [user:%X{user:-N/A}] %n</pattern>
        </encoder>
        ...
    </appender>
  2. Create a new securityDBAppender in SaaS deployments. This appender enables writing security logs to the database.

    Example Logback configuration
    <configuration debug="true" scan="true" scanPeriod="60 seconds">
      ...
      <appender name="securityDBAppender"
                class="com.oracle.healthinsurance.loggingsupport.appender.impl.OhiSecurityLoggerAppender">
        <connectionSource class="ch.qos.logback.core.db.JNDIConnectionSource">
          <jndiLocation>jdbc/policiesUserOhiApplicationDS</jndiLocation>
        </connectionSource>
        <logType>security</logType>
        <bufferDir>/writable/log/storage/buffer/security</bufferDir>
      </appender>
      ...
      <root level="error">
        ...
        <appender-ref ref="securityDBAppender"/>
      </root>
    </configuration>

Configuration Properties

Ref Action Description

CPN-3975

Added

ohi.activityprocessing.group.transaction.commit.strategy

This property configures group strategy to manage memory using Single-Commit (DEFAULT) or Chunking-Memory (CHUNK) strategy. By default Single-Commit is applied

CPN-3975

Added

ohi.activityprocessing.group.transaction.commit.chunking.memory.threshold

This property configures the memory threshold (in MB) at which Group Chunking-Memory strategy commits and continues processing.

CPN-4302

Added

ohi.datatransfer.logging.phi.events.enabled

Introduced a new optional property

NXT-32617

Added

ohi.ui.likesearch.wildcard.enabled

This property enables or disables the trailing '%' sign from quick, advanced search, and lookup (LOV) with the query operators like and likeic.

NXT-33750

Added

ohi.api.download.max.rows

The ohi.api.download.max.rows system property, which allows users to configure the maximum number of rows that can be downloaded through the Download API.

By default, this property is set to 2,000 rows. The maximum supported value is capped at 10,000 rows.

Web Services

Ref Action Description

CPN-3799

Modified

Operational Reporting IP

Two new error messages are introduced in the Operational Reporting IP. The IP returns an HTTP 422 response with one of the following error messages:

  • OHI-IP-ORV-008: View {0} does not exist

  • OHI-IP-ORV-009: Access restriction grant is missing to query the view {0}

CPN-3799

Modified

Data Transfer IP

  • CSV files generated by the Data Transfer IP includes the header.

  • When the query returned no records, the Data Transfer IP responds with HTTP 204 (No Content).

CPN-3830

Modified

accessrestrictions Generic API

Access restriction of type 'Line of Business' is removed from the Capitation application.

CPN-3876

Modified

Providers

ADDITIONAL_PART_3 is updated

CPN-3876

Modified

Providers

ADDITIONAL_PART_2 is updated

CPN-3876

Modified

Providers

ADDITIONAL_PART_1 is updated

CPN-4206

Modified

logsecurityevents

Added 9 new attributes: eventCategory, eventType, eventOutcome, eventSeverity, httpStatusCode, failureReason, apiEndpoint, sessionId, accessTokenId.

CPN-4207

Modified

logphievents

Added three new attributes: accessScope, sessionId, and accessTokenId.

NXT-26542

Added

deploymentmetadata API

New read-only generic API is added.

NXT-26542

Modified

userpreferences API

Added a new attribute browserTimeZone to the user preferences API.

NXT-32464

Modified

Provider IP

If more than 1 provider is matched to an identifier, then an error message is thrown

NXT-33750

Added

Download API

New HTTP API integration Point -Download API is added

POL-17690

Modified

policyaccounttransactions IP

search on account number, account definition are case insensitive

POL-17690

Modified

policyaccounts IP

search on account number, account definition are case insensitive

POL-17690

Modified

policyupdaterequests IP

checks on references like brand are case in sensitive, also matching on details where code is involved, like add on and check on policy if it exists is case insensitive

POL-17690

Modified

policies (Patch) IP

checks on references like brand are case in sensitive, also matching on details where code is involved, like add on and check on policy if it exists is case insensitive

POL-17690

Modified

persons IP

checks to references like prefixes, titles, relation tags are case insensitive

POL-17690

Modified

organizations IP

checks to references like relation tags are case insensitive

POL-17690

Modified

groupclients IP

checks on references like referencing group client, data access group are case in sensitive, also matching on details where code is involved like group account and check on group client if it exists is case insensitive

POL-17690

Modified

individualproviders IP

checks on references to specialty are case insensitive match on provider using provider code and flex code system are still case sensitive since both are not stored as upper case

POL-17690

Modified

organizationproviders IP

checks on references to specialty are case insensitive match on provider using provider code and flex code system are still case sensitive since both are not stored as upper case

POL-17690

Modified

macros IP

search on Macro Definition is case insensitive

POL-17690

Modified

activities IP

search on activity type is case insensitive

POL-17690

Modified

policymutations IP

checks on references like output definition and fee definition are case insensitive

POL-17946

Added

Audit Search Generic API

Enable Generic POST operations.

Retrieves Generic Audit records for a selected auditable entity, including its create, update, and delete history.

Data Conversion

Ref Action Description

NXT-31011

Added

OHI_ACCESS_RESTRICTION_GRANTS

The new access restriction will be provided to all non system active roles (with retrieve flag as Y), having at least a system function access grant with retrieve flag as Y

NXT-32464

Removed

Provider Identifiers

Unique constraint on identifier and identifier type is dropped in all the applications.

Dynamic Logic

Ref Action Description

CPN-3973

Modified

Groovy 5 upgrade

Upgraded Groovy from 4.x to 5.0.7.

UI Changes

Ref Action Description

CPN-3830

Modified

Access Restrictions page

Access restriction of type 'Line of Business' is removed from the Capitation application.

NXT-33659

Modified

Preferences Dialog

A new checkbox - "Use Browser Timezone?" has been introduced in Preferences which can be used to override the customer’s configured timezone.

NXT-33750

Modified

Proddef - Product Service Definition (Products and Across)

Boilerplate text value is updated for all the Regime fields to indicate the type of regime

NXT-33750

Modified

All floorplan based pages (and Reference Sheet Lines)

API based download is enabled in UI pages.

However, there is an exclusion list application wise:

UI based download is retained in Extensibility tabs and tabs of some Detail pages:

  • Claims - Transaction Sources (Transaction Source Usages), Banks (Addresses, Bank Account Number Relations), tabs in all the Pricing Rule pages

POL-16770

Modified

PO0032 (Change event rules)

The Relation Identifier entity is newly added for Subject field.

Breaking Changes

Ref Action Description

CPN-3676

Modified

DB Log Appender

The third-party library used to log application, dynamic logic, and security events to the database (via the database appender) relies on Java reflection to access private variables. Since reflection access is restricted by default in Java 21, environments (eg: SaaS deployments) using the database appender must update the startWeblogic.sh script for each managed server to include the following JVM options:

--add-opens java.base/java.lang.reflect=ALL-UNNAMED --add-exports java.base/sun.nio.ch=ALL-UNNAMED

CPN-3775

Modified

Installer

The installer is enhanced to automatically create or update deployment metadata in the OHI$DEPLOYMENT_METADATA database table during installation or upgrade operations. As part of this enhancement, the ohi_install.cfg template now includes the following new configuration parameters:

  • timeZoneOverride

  • deploymentType

  • isEnvironmentProduction

CPN-3973

Modified

Groovy 5 upgrade

Upgraded Groovy from 4.x to 5.0.7.

CPN-4025

Modified

securityAppender

A new MDC (Mapped Diagnostic Context) field, user, has been introduced for security logs. To ensure this information appears in the security log file, update the log pattern for the securityAppender (which uses RollingFileAppender) to include the user MDC field.

Example updated pattern:

<appender name="securityAppender" class="ch.qos.logback.core.rolling.RollingFileAppender">
    <encoder>
        <pattern>%d{ISO8601} [ %t ] %marker %c - %m [user:%X{user:-N/A}] %n</pattern>
    </encoder>
    ...
</appender>

Also, security log messages now refer to the "login name" of the user instead of the "ID" of the user.

CPN-4195

Removed

Data File Sets IP

Removed the GET operation on the datafilesets IP endpoint.

NXT-31011

Added

OHI_ACCESS_RESTRICTION_GRANTS

JET (UI) will implement a new access restriction called "Download 'Data'" to manage the visibility of the Download button. Users who are not granted this access restriction will no longer see the download action, making this a breaking change.

NXT-33750

Modified

Below breaking change will be observed for UI download enhancement.

  • Date / date time fields are not formatted.

  • For system enumerations ( example status field on claim) key will be download.

  • For composite columns - example when two different fields were shown in one column in UI, download will have columns per value. Example instead of one column for formatted name, download will have separate columns for first name, middle name , last name and so on. Another example is maximum value / current value in counters, and setup pages, in download separate columns will be present for maximum/current days, units and amount.

  • Product service definition - download will show separate columns for each regime.

  • In UI if a custom list of value is added on a native field / string field using floorplan based configuration, only native data will be part of download - example - partial provider pricing clauses only method code will be download

Access Restrictions

Ref Action Description

CPN-3980

Modified

CO0019

keyboardshortcuts API and floorplans.enhance IP added to CO0019 function code

NXT-31011

Added

OHI_ACCESS_RESTRICTIONS_B

A new access restriction of type DWDATA and code as UI_DATA_DOWNLOAD has been added. The same has been assigned to ALL_FUNCTIONS_ACCESS_ROLE

NXT-33659

Modified

CO0019

The 'deploymentmetadata API' access restriction has been added to function code CO0019.

NXT-33750

Added

Download API access

A user who has been granted GET access to a resource’s HTTP API can download that resource’s data using this endpoint.

Bug Fixes

BugDB SR Internal Summary

36967832

CPN-3407

Activities remain in QD status after OutOfMemoryProtector is triggered

Description:

After exceeding the critical memory threshold and having recovered the application memory, the queued activities are not dequeued and remain in QD status.

Resolution:

Once the application memory reaches normal state, the activities in QD status are re-queued to resume processing of the activities.

36970168

3-37743857111

CPN-3410

Property ohi.ws.client.readtimeout does not work as intended

Description:

The system property ohi.ws.client.readtimeout is intended to control the time (in milliseconds) that the client will wait for a response from the server after sending a request. However, it is currently being incorrectly applied to set the timeout for the entire request/response conversation, rather than just the response wait time.

Resolution:

36991723

3-37582942001

CPN-3423

Application logs are not persisted in the database in rare scenarios

Description:

Application logs are internally queued before writing to the database. In rare cases, these logs are not successfully written, causing the internal queue to grow significantly in size - several GBs in some instances. This led to a loop in the log persistence mechanism, impacting system performance.

Resolution:

The elements are not requeued to prevent an endless loop and to avoid increasing the queue file size.

37882208

CPN-3778

Zip and Unzip operations in Data File Sets IP return HTTP 405 in SaaS

Description:

The Zip and Unzip operations in Data File Sets IP return HTTP 405 (Method Not Allowed) in SaaS

Resolution:

Added support for zip and unzip operations in the Data File Sets IP in SaaS

37257823

3-38637505211

CPN-3515

Query API does not return correct results when the search criteria contains an apostrophe

Description:

Query API does not return correct results when the search criteria contains an apostrophe.

Resolution:

37334534

3-37528423931

CPN-3566

Additional field values when emptied are not retained after save

Description:

Additional field value (dynamic fields of a dynamic record) nullification does not work and original value gets retained. When a payload to update a dynamic field in a dynamic record is sent via api, such that only the fields that are nullified are present and any non-null field is not present, then those updates are not being handled properly and the nullification for the fields present in the payload does not happen. If any non-null field is also included with the payload along with nullified fields then the persistence happens properly and the respective values get nullified also.

Resolution:

Individual fields of a dynamic record can be nullified by passing in empty tags (i.e. "") in the PATCH payload.

35031585

3-31969350441

CPN-2430

Query API returns incorrect results for combined conditions

Description:

When you do a query search with a combination of a null, for instance (multicore.eq('Y').or.multicore.eq(null)), the result shows the records having value Y and not the ones with a null value.

Resolution:

When a query search is done with a combination of a null, the rows with null values are returned correctly.

37828688

3-39371159781

CPN-3779

Base View generation fails for an entity which has an apostrophy character in the display name

Description:

For entities which have dynamic attributes, base view generation adds column remark using display name. If display name has apostrophy character ('), it fails with following exception: java.sql.SQLSyntaxErrorException: ORA-00933: SQL command not properly ended

Resolution:

No SQL exception is thrown when a display name has apostrophy character (')

Backports:

4.25.1.0.0

37785812

CPN-3707

Contract adjustment page does not display schedule dimensions

Description:

Schedule dimensions are not displayed in the contract adjustment page. The values are seen in the API response but the columns are not displayed in the UI.

Resolution:

Contract adjustment page now displays schedule dimensions.

37924882

CPN-3793

Data File Sets IP does not return the message text in the response for error codes DAT-IP-DAFI-013 and DAT-IP-DAFI-014

Description:

Data File Sets IP does not return the message text in the response for error codes DAT-IP-DAFI-013 and DAT-IP-DAFI-014

Resolution:

35686859

CPN-2724

Dynamic logic statistics IP returns incorrect statistics for test unit dynamic logic

Description:

Dynamic logic statistics IP returns incorrect statistics when a test unit dynamic logic is used to test one dynamic logic and then modified to test another dynamic logic.

Resolution:

The reset method in the QueryStatisticsService is called for each dynamic logic because of which the statistics are cleared by the second dynamic logic. We need to ensure the reset method is called only once for every test unit call

39842877

4-0002675908

CPN-4451

Fixed number field validation to accept valid decimal values

Description:

Numeric fields that allow no digits before the decimal point caused valid decimal values to be rejected.

Resolution:

Valid decimal values are now accepted when the number field definition allows no digits before the decimal point.

39828823

4-0003326305

CPN-4436

Reference sheet lines remain unavailable after creating flex codes removed through CMT

Description:

Reference sheet lines are not returned when they reference a flex code that was missing during an earlier lookup and is subsequently created. The missing lookup result remains cached, so the reference sheet lines remain unavailable until the affected application nodes are restarted.

Resolution:

38616123

3-42597605671

CPN-4051

All the files stored in the object storage are returned as data transfer response when no files are generated for the data transfer request.

Description:

All the files stored in the object storage are returned as data transfer response when no files are generated for the data transfer request.

Resolution:

HTTP 204 no content is returned as response when no files are generated for the data transfer request.

38725536

CPN-3903

Task processing integration point restart and restart all operations did not resolve associated system event log

Description:

Invoking Task Processing IP Restart or Restart All operations on tasks in ERRORED status did not resolve the associated SystemEventLog, leaving log entries unresolved

Resolution:

System event logs associated with ERRORED tasks are now resolved when attempting restart

38438852

CPN-3991

Access role codes are not logged in security log when all the access roles are revoked from user

Description:

When all the access roles are revoked from a user, the security log records the user who performed the revocation and the user from whom the roles were revoked, but it does not record the access role codes.

Resolution:

The security log now also records the access role codes when all the access roles are revoked from a user.

38856867

4-0001793793

CPN-4159

Missing secrets for OAuth clients while ohistore is used as keystore

Description:

Missing secrets for OAuth clients while ohistore is used as keystore

Resolution:

OAuth client credential keys are now correctly fetched.

Backports:

4.25.1.0.2

38819749

4-0001674695

CPN-4143

Dynamic logic fails when an output writer is created but no data is written in data file stored in object storage

Description:

Dynamic logic fails when the output writer is instantiated even though there is no data to process and no write operation is performed on the data file stored in object storage

Resolution:

The system allows the output writer to be instantiated and closed without performing any actual write operation on data file stored in object storage.

39835295

3-40007142171

CPN-4446

Query API fields parameter does not expand dynamic fields on referenced entities

Description:

A Query API search using the fields parameter did not expand requested dynamic fields on an entity when that entity appeared through one or more resource paths

Resolution:

The Query API response now includes dynamic fields and records strictly based on the request parameters. Dynamic fields and records are returned only for the lists explicitly specified in the fields parameter. The fields attribute takes precedence over the expand attribute.

Example

Assume a dynamic field paymentPreference is defined on the Provider entity. To retrieve this field for a serviceProvider at the Claim level, use the following request body:

{
    ...
    "resourceRepresentation": {
        ...
        "fields": "serviceProvider.paymentPreference"
    }
}

Prior to this fix
The request did not return the dynamic field paymentPreference for the specified serviceProvider path.

After this fix
The response includes paymentPreference only for the explicitly requested serviceProvider path.

To retrieve paymentPreference for the serviceProvider at both the Claim and ClaimLine levels, explicitly specify both paths in the fields parameter:

{
    ...
    "resourceRepresentation": {
        ...
        "fields": "serviceProvider.paymentPreference|claimLineList.serviceProvider.paymentPreference"
    }
}

Additionally, if an entity (for example, Person) appears in more than one sub-resource, such as Policyholder and PolicyEnrollment, the response includes data only for the paths explicitly requested through the fields attribute.

This behavior applies to all APIs. Representative examples include:

  • Person appearing under Policyholder and PolicyEnrollment in the Policies application using the policies Generic API

  • Person (servicedMember) appearing at the Claim and ClaimLine levels in the Claims application using the claims Generic API

  • Provider (serviceProvider, servicedProvider, claimantProvider, and similar references) appearing through different resource paths in applications that expose these entities, including the Claims and Capitation applications

39026234

4-0002125064

CPN-4212

Resources cannot be searched when code starts with %255%

Description:

POST search API requests fail with an IntrusionDetectionException when the query contained specific special patterns. These legitimate input parameters were incorrectly identified as potential intrusion attempts, resulting in search failures.

Resolution:

Enhanced the intrusion detection mechanism to correctly handle search query parameters, preventing legitimate requests from being incorrectly flagged.

Backports:

4.25.1.0.2

39079764

3-42957456931

CPN-4233

Flex Code Base Views are both removed and updated at the same time

Description:

During Base View Generation, the generation of Flex Code Base View is unstable: (1) Concurrent update/remove operations occasionally targeted the same view, raising the Oracle error “table or view does not exist”. This happened intermittently. (2) The generator skipped creating some Flex Code Base Views whenever the Flex Code System code contained lowercase characters.

Resolution:

The update/removal operations are serialized to prevent errors like “table or view does not exist”. Flex Code Base Views are generated for Flex Code Systems with a code containing lowercase characters.

Backports:

4.25.1.0.2

39920309

CPN-4479

Dynamic logic security checks fail for unresolved Groovy receiver types

Description:

Dynamic logic execution could fail with a NullPointerException when the receiver type of a Groovy method call could not be resolved during security rule evaluation.

Resolution:

Dynamic logic security predicates now safely handle unresolved receiver types, allowing valid dynamic logic execution to continue without a NullPointerException.

39112961

CPN-4249

Query API returns incorrect totalResults when groupBy is used

Description:

When the Query API is invoked with the groupBy parameter, the totalResults value in the response is incorrect. Instead of returning the total number of groups produced by the groupBy attribute, the response returns the total number of records matching the q attribute.

Resolution:

The Query API now returns the correct totalResults value when groupBy is used, reflecting the total number of groups produced by the groupBy attribute.

39128521

CPN-4262

ORA-06502 when querying base view with column name longer than 30 characters in on-prem deployment

Description:

When a base view contains column names beyond 30 characters, the on‑prem runtime raises ORA‑06502: PL/SQL: numeric or value error: character string buffer too small while retrieving the result set.

Resolution:

Data transfer on on-prem deployments now handles columns longer than 30 characters without raising ORA‑06502.

38226997

3-40724895331

CPN-3901

Tracking/Tracing of requests should not be sent to external systems

Description:

Tracing headers (such as B3 headers) are being sent to external systems. This leads to a 500 error response. However, when the spanId header is removed, the request goes through successfully with a 201 response

Resolution:

B3 Tracing headers will be added when the host of the request and the application are identical.

Backports:

4.25.1.0.1

39410201

4-0002782929

CPN-4324

Improved reliability of dynamic logic updates across application nodes

Description:

During configuration migration or dynamic logic updates, some application nodes could intermittently continue using previously cached logic. This could result in inconsistent behavior because the latest logic changes were not always applied immediately across all processing threads.

Resolution:

The system now ensures that dynamic logic cache updates are consistently recognized across processing threads. As a result, cache refreshes are applied reliably during configuration migration and dynamic logic updates, preventing intermittent use of outdated cached logic.

38819492

4-0001350333

CPN-4142

Reading large files from object storage fails due to non-configurable read timeout.

Description:

OHI does not provide configurable timeout settings (connection and read timeouts) while reading or streaming files from Object Storage (OS). As a result, file read operations rely on default OCI SDK timeout values, which are not suitable for large files or long-running streaming use cases.

When files are read record-by-record, the read operation may exceed the default socket read timeout, leading to java.net.SocketTimeoutException: Read timed out. This causes long-running processes to fail unexpectedly, even though the connection itself is healthy.

Resolution:

Support for configurable Object Storage timeouts has been added to improve reliability when processing large files and long-running streaming workloads. Two new properties are now available: a. ohi.object.storage.read.timeout.millis b. ohi.object.storage.connect.timeout.millis

Both default to 60,000 ms (60 seconds) and can be increased as needed to prevent read timeouts errors during extended Object Storage operations

38968968

CPN-4195

Remove GET support on datafilesets IP

Description:

Remove the GET operation on the datafilesets IP endpoint as it is no longer required.

Resolution:

Removed the GET operation on the datafilesets IP endpoint.

38400837

CPN-3980

keyboardshortcuts API should be part of CO0019 function code

Description:

keyboardshortcuts API and floorplans.enhance IP should be added to CO0019 function code

Resolution:

keyboardshortcuts API and floorplans.enhance IP added to CO0019 function code and also removed duplicate access from setup access role

Backports:

4.25.1.0.1

39086808

CPN-4241

Translation errors are seen while running the JET UI in Virtual Machines

Description:

The JET UI is not fully compatible with virtual environments, causing translation-related errors during application use.

Resolution:

Updated the JET UI configuration and handling to ensure translations load and function correctly when the application runs in a Virtual Machine.

38077332

CPN-3847

eventDate attribute in logapplicationevents and logdynamiclogicevents resources ignores time component

Description:

The eventDate attribute in both logapplicationevents and logdynamiclogicevents resources ignores time component in Query API. So, the query criteria including a time component (e.g., 2025-06-15T14:30:00 are not honored. The system defaults to 00:00:00 as the time, effectively filtering by date only. Also, the response payload includes only the date portion, omitting time entirely.

Resolution:

The eventDate attribute is updated to honor the time component in Query API criteria. The response now also includes the time component (hours, minutes, and seconds). Fractional seconds (e.g., milliseconds) are not included in the response.

Backports:

4.25.1.0.1

38309264

3-40091618181, 3-41125321001, 3-41542636421

CPN-3941

Add error handling for duplicate columns in base view generation

Description:

Throw a clear and descriptive error message when duplicate columns are detected in views during base view generation. Currently, if a table has duplicate columns in its view, the base view generation fails silently without any error message, causing confusion and making it difficult to identify the root cause.

Resolution:

Added a duplicate columns check in base view generation process and throwing descriptive error message to user.

Backports:

4.25.1.0.1

38309833

CPN-3944

Populate flex code columns in reference sheets base views with the corresponding key values

Description:

On generating reference sheets base views, the Flex code columns are appearing as NULL values.

Resolution:

Populated the flex code columns with corresponding key values.

38586966

CPN-4046

javax.persistence.NoResultException in CalculationPeriodRepositoryImpl

Description:

Log pollution is occurring due to inconsistent log levels, specifically using 'error' where 'warn' was appropriate.

Resolution:

Adjusted the log level from error to warn to reduce unnecessary log noise.

38659265

4-0001344048

CPN-4077

The activity thread pool size does not revert to its original value of 8 after memory usage returns to normal

Description:

During periods of high memory usage, the system automatically reduces the number of activity threads it can handle to 1, to prevent further strain. However, after memory usage returns to normal, the system does not increase this capacity back to its usual level i.e. 8. As a result, the affected node can only process one activity at a time, which causes slow performance and delays.

Resolution:

Once memory usage returns to normal, the system automatically restores it the thread-pool capacity back to the usual level of 8 threads on the impacted node. This ensures that performance returns to normal and multiple tasks can be processed at the same time, preventing delays.

Backports:

4.25.1.0.2

38526830

CPN-4027

Capitation Contract: Adjustment override - Copy button should not be shown

Description:

Copy button should not be shown for Adjustment Overrides in the table level row actions. Since update operation is not allowed for overrides.

Resolution:

Copy button is removed for Adjustment Overrides in the table level row actions.

38282352

3-41496402011

CPN-3931

Error when creating individual and organization providers using 'Save and Next' action in JET UI

Description:

Users is getting error when creating individual and organization providers using JET UI. This error occurs when you create a provider and click 'Save and Next' button and subsequently try to create a second provider. Error : Value "undefined" provided is not of type Number (post , flexcodesetdetails).

Resolution:

Fixed the issue preventing users from creating individual and organization providers using the 'Save and Next' action.

37993537

CPN-3830

The Capitation application does not support 'Line of Business' as a configurable entity, however, the application allows creation of access restriction of type 'Line of Business'

Description:

The Capitation application does not support 'Line of Business' as a configurable entity, however, the application allows creation of access restriction of type 'Line of Business'

Resolution:

Access restriction of type 'Line of Business' is removed from the Capitation application

39401615

4-0002426307, 4-0002660956

CPN-4323

Work manager ws-work-manager is not used for API/IP requests

Description:

Work manager ws-work-manager is not used for API/IP requests. As a result, when a large number of API/IP requests are submitted at the same time, the system may process more requests concurrently than expected instead of applying the usual throttling or queuing behavior. This can contribute to degraded performance or service instability under heavy load.

Resolution:

The fix restores the intended request handling behavior so API/IP traffic is processed with the appropriate concurrency limits.

38904235

4-0001784507

CPN-4168

System throwing NullPointerException when there is no value for EXCL_PHI_LOGGING in the OHI_REPORTING_VIEWS table

Description:

When invoking the Data Transfer IP, the system verifies if any PHI information is fetched and creates PHI log entries when needed. In case the EXCL_PHI_LOGGING column in the OHI_REPORTING_VIEWS table is empty, the system throws a NullPointerException.

Resolution:

The EXCL_PHI_LOGGING column in the OHI_REPORTING_VIEWS table gets a default value 'N'

Backports:

4.25.1.0.2

39834113

4-0003422821

CPN-4439

Cleared dynamic fields could still return the previous value during the same processing flow.

Description:

When a dynamic field was cleared by assigning null, the value was removed, but a cached copy could still be used for later reads in the same flow. As a result, the dynamic field could appear to still contain its old value immediately after being cleared. This could affect dynamic fields, including flex-code dynamic fields, across single-value time valid, multi-value non-time-valid & time-valid, configurations.

Resolution:

The cache is now invalidated when a dynamic field is cleared. After assigning null, later reads correctly and returns no value instead of the previously cached value.

39287362

CPN-4295

Domain attribute allowlist property set through API was not applied at runtime

Description:

The property ohi.untrusteddata.allowlist.domainattribute was not being applied when configured through the API. The same property continued to work correctly when set in the properties file. As a result, valid requests could still be flagged by the default untrusted-data intrusion check after the property was updated through the API.

Resolution:

Fixed the allowlist refresh behavior so updated domain attribute values are picked up immediately, preventing valid requests from being incorrectly flagged by the default untrusted-data intrusion check.

38471292

CPN-4014

Error is observed after navigating to Adjustment Schedule Lines in Adjustment Schedules page

Description:

API access error is shown in Adjustment Schedule Lines of Adjustment Schedules page

Resolution:

API access error is fixed in Adjustment Schedule Lines of Adjustment Schedules page

39445821

CPN-4327

PHI logging includes unmatched 'left joins' rows

Description:

When a query selects a PHI column from the right side of a LEFT JOIN, PHI logging is created for all rows from the left-side table, including rows where the joined row does not exist. In those cases the PHI column is effectively null, but a PHI log event is still written. This leads to incorrect PHI audit entries for rows that did not actually expose PHI.

Resolution:

When the joined column is marked as PHI but there is no match, no PHI Event is logged for that missing column.

Backports:

4.25.1.0.2

39444869

CPN-4326

PHI audit logs corrected for aliased base views in data transfer payloads

Description:

In specific data transfer scenarios, when a base view is queried through an alias and the Base View is outside of the Relation context, PHI logging was not generated correctly.

Resolution:

The system now generates the PHI audit logs correctly for these aliased base view scenarios.

Backports:

4.25.1.0.2

39706842

CPN-4383

Activity purge fails with integrity constraint violation error

Description:

Activity purge fails with an integrity constraint violation error because not all child data associated with the activity is cleaned up successfully.

Resolution:

Child data associated with the activity is now successfully deleted before the activity is purged.

39468986

4-0002614945

CPN-4328

Add business rule validation for character field length in dynamic field usages

Description:

Dynamic field usages are incorrectly allowed to use CHAR fields with length greater than 1000 for dynamic fields, flex code definitions, and non-reference sheet dynamic record definitions. This can lead to a database error when values longer than 1000 characters are inserted.

Resolution:

A business rule has been updated to ensure that dynamic field usages for dynamic fields, flex code definitions, and non-reference sheet dynamic record definitions cannot use CHAR fields with length greater than 1000.

38104348

CPN-3856

Performance degradation in activity processing due to the overhead caused by the heartbeat query

Description:

The cleanup_act_status activity monitoring heart-beat query, which performs a SELECT on the ACT_ACTIVITIES table to fetch records with status 'IP', is experiencing performance issues. The query is currently executing a full table scan as the status field is not indexed, resulting in increased execution time.

Resolution:

The query was optimized by using the VIRTUAL_UNPROCESSED_STATUS column, which is indexed and offers better performance.

Backports:

4.25.1.0.1

39571878

CPN-4354

Generic search requests with total results could fail for some resources like calculationresults

Description:

When a generic search request included totalResults=true for some resources (like calculationresults), the response could fail instead of returning the matching records and total result count.

Resolution:

Generic search requests with totalResults=true now return the expected response, including the total result count, for the affected resources. Requests with totalResults=false continue to return matching records without calculating total results.

Backports:

4.25.1.0.2

38171947

3-40948058341

CPN-3883

Message text field is not available in Message Group Details tab

Description:

Message text field is not available in Message Group Details tab. Message text and severity for the table is missing.

Resolution:

Added message text and severity column in the table

39835803

3-41886923721

CPN-4448

Writing incident data files in Object Storage fails intermittently

Description:

Writing an incident data file in Object Storage fails intermittently with NoSuchElementException

Resolution:

The intermittent issue that prevented incident data files from being written to Object Storage has been resolved. The fix improves the reliability of file creation and storage operations.

38789077

CPN-4132

Data transfer requests fail with ORA-06502 when the schema name exceeds 30 characters.

Description:

Data transfer requests fail with the error ORA-06502: PL/SQL numeric or value error character string buffer too small when the schema name is longer than 30 characters.

Resolution:

A fix has been implemented in the data transfer functionality to support schema names of up to 120 characters.

38862393

CPN-4161

File count incorrectly shown as 1 instead of 0 when multiple data transfer requests are dequeued together

Description:

A concurrency issue was identified in the data transfer dequeue processing logic.

When multiple data transfer requests are dequeued and processed together, if one of the requests does not return any data, the system incorrectly reports the file_count as 1 instead of 0.

This issue does not occur when requests are dequeued and processed individually. The incorrect file count is observed only in concurrent dequeue scenarios.

Resolution:

The dequeue processing logic has been corrected to ensure that the file_count is properly initialised and calculated independently for each request during concurrent processing.

38556067

CPN-4035

Activities left unprocessed after crashing a primary node.

Description:

In multi-node cluster where activities are running on all the nodes. If primary node is killed/crashed then activities in cluster remain unprocessed. Other nodes also stop processing the activities, this is gridlock scenario.

Resolution:

This is resolved to ensure that killing primary node does not stop the processing of activities across cluster. Fixed gridlock scenario

38979390

4-0002159777

CPN-4204

The Person API does not accept non Latin or accented characters in the local part or user name of the email address.

Description:

The Person API does not accept non Latin or accented characters in the local part or user name of the email address.

Resolution:

The Person API now accepts non Latin or accented characters in the local part or user name of the email address.

38352669

3-41237424921

CPN-3958

Duplicate entries in OHI_TABLE_COLUMNS

Description:

The table OHI_TABLE_COLUMNS keeps track of database columns which are marked as PII, but also if a column is subject to diacritics search options. Currently there are duplicate entries. As a result, when generating base views the system could throw a Null Pointer Exception.

Resolution:

The duplicate entries as merged into a single entry with PII on subtype 'PERS' and diacritic search enabled. A similar action is taken on the duplicate DATA_FILE entry from the Data Files table.

Backports:

4.25.1.0.1

39113966

CPN-4250

OAuth RestClientBuilder lookup fails due to duplicate enum keys across authentication feature enums

Description:

A key mismatch occurred due to duplicate OAuth enum values defined in different authentication feature enums, resulting in a lookup failure and the error “No RestClientBuilder specified for OAuth”

Resolution:

The application now correctly resolves the RestClientBuilder specified for OAuth

38926047

4-0001692989

CPN-4173

Add Widget tile is not visible in Dashboard page

Description:

When user logs in with access CO0019, add widget tile is not visible in view edit Dashboard page because user preference API has only retrieve access and not update.

Resolution:

Seed data is updated for CO0019 access restriction and user will be able to see Add Widget tile

38714849

3-41728688211

CPN-4095

Increase in heap memory usage following the Groovy 4 upgrade

Description:

Post Groovy 4 upgrade, noticed higher memory usage, which can slow down the system. Groovy stores the reference of large Groovy-meta-class objects using soft references, meaning these objects are only removed when garbage collection runs and memory is low. Before this happens, the system can approach critical memory levels, triggering safety measures that reduce processing capacity on affected nodes and cause visible performance issues.

Resolution:

Disabled the use of Groovy meta classes to address the memory issue. The necessary functionality will now be provided using non meta class references and methods instead.

Issues that were backported in previous Release / Patch

BugDB Internal Summary Backport BugDB SR

37828688

CPN-3779

Base View generation fails for an entity which has an apostrophy character in the display name

4.25.1.0.0

37886824

38077332

CPN-3847

eventDate attribute in logapplicationevents and logdynamiclogicevents resources ignores time component

4.25.1.0.1

38350741

38104348

CPN-3856

Performance degradation in activity processing due to the overhead caused by the heartbeat query

4.25.1.0.1

38176456

38226997

CPN-3901

Tracking/Tracing of requests should not be sent to external systems

4.25.1.0.1

38227012

38309264

CPN-3941

Add error handling for duplicate columns in base view generation

4.25.1.0.1

38309268

38352669

CPN-3958

Duplicate entries in OHI_TABLE_COLUMNS

4.25.1.0.1

38352690

38400837

CPN-3980

keyboardshortcuts API should be part of CO0019 function code

4.25.1.0.1

38471399

38659265

CPN-4077

The activity thread pool size does not revert to its original value of 8 after memory usage returns to normal

4.25.1.0.2

38659276

38856867

CPN-4159

Missing secrets for OAuth clients while ohistore is used as keystore

4.25.1.0.2

38856877

4-0001793793

38904235

CPN-4168

System throwing NullPointerException when there is no value for EXCL_PHI_LOGGING in the OHI_REPORTING_VIEWS table

4.25.1.0.2

38904244

4-0001784507

39026234

CPN-4212

Resources cannot be searched when code starts with %255%

4.25.1.0.2

39026272

4-0002125064

39079764

CPN-4233

Flex Code Base Views are both removed and updated at the same time

4.25.1.0.2

39079794

39444869

CPN-4326

PHI audit logs corrected for aliased base views in data transfer payloads

4.25.1.0.2

39526243

39445821

CPN-4327

PHI logging includes unmatched 'left joins' rows

4.25.1.0.2

39526134

39571878

CPN-4354

Generic search requests with total results could fail for some resources like calculationresults

4.25.1.0.2

39693600

Known Issues

BugDB SR Internal Summary

37793706

CPN-3733

Boilerplate texts are not displayed for dimensions in adjustments page

Description:

Labels (Boilerplate texts) are not displayed for Schedule dimensions in contract adjustments page. Boilerplate code is displayed instead

38209311

3-41305444821

CPN-3898

When dynamic logic is updated while one or more nodes are starting up, those nodes fail to come up and get stuck

Description:

When dynamic logic is created, updated, deleted or when the invalidateall IP operation is invoked on one node, and at the same time one or more other nodes are starting up, those nodes can get stuck due to a deadlock between threads. As a result, the nodes fail to complete startup and do not come up.

38892194

4-0001784507

CPN-4163

Invalidate View and View Column cache after Base View Generation

Description:

View and View Column information as used by the Data Transfer functionality or Reporting View functionality is cached, as it does not change often. Once the Base Views are (re)generated, this cache should be cleared so the view and view columns information is not out of sync.

39262594

CPN-4291

Tasks can remain pending after a service-protection limit is reached.

Description:

When task processing reaches a service-protection limit, affected tasks can remain pending and are not scheduled again. This can prevent the affected tasks from continuing to process.

39345989

4-0002705959

CPN-4303

Antivirus scanning configuration changes require an application restart.

Description:

Changes to enable or disable antivirus scanning do not take effect until the application restarts. This creates operational overhead and can cause unnecessary service disruption.

39687956

CPN-4370

Datatransfer incorrectly raises a SQL injection validation error when the filter value contains a SQL keyword like insert

Description:

Data transfer export requests could fail with OHI-IP-ORV-006: Invalid request. Potential SQL injection detected when the request contained SQL keywords such as insert inside a quoted string literal in the where clause. For example, a valid filter value like: rel.code='FN0061_1_1_3_1_insert_file1' was incorrectly rejected because the validation detected the word insert inside the literal value, even though it was not executable SQL syntax.

39920131

CPN-4452

Download api does not return results for all rate schedule line properties

Description:

For a request of type /api/generic/rateschedules/{rateScheduleId}/rateschedulelines/defaulttimeperiod/{defaultTimePeriodId}/download, the schedule dimension values are not included in the download response

39853661

CPN-4459

Data transfer fails with ORA-00028 after ADB DBMS_CLOUD patching

Description:

Following Autonomous Database maintenance, some Data Transfer jobs failed with ORA-00028: your session has been killed. The maintenance temporarily invalidated database packages used by Data Transfer. As a result, active database sessions using those packages were terminated. This was a transient database-session event; no data corruption occurred.

39855228

CPN-4461

Activity starts can time out while files are scanned for viruses.

Description:

Starting an activity can wait for virus scanning to complete and may time out when the scan takes too long. Imports remain unavailable until virus scanning completes successfully.

39920402

CPN-4462

Delete audit records can be missing for configuration entities.

Description:

When configuration data is deleted, the audit log can omit the corresponding delete record even though the configuration record is removed. This limits the audit history available for deleted configuration data.

39909016

CPN-4475

Prevent application startup stall caused by Coherence cache initialization

Description:

During application startup, the plan manager could remain blocked while accessing a shared cache. This could prevent a node from completing startup and processing cluster communication.

39926914

CPN-4489

Audit API should inherit the access restriction of its parent resource

Description:

Currently, Audit API resources have their own newly created access restriction instead of inheriting the access restriction of the corresponding resource.

As a result, a user who already has access to a resource (for example, Policies) may still be unable to access that resource’s Audit API unless an additional Audit API-specific access restriction and grant are provided.

The Audit API must work by default for users who are authorized to access the underlying resource. It should therefore use the same access restriction as its parent resource, rather than requiring a separate restriction.

Deprecated Items

These features will be removed in a future release. Customers are advised to review the documentation and take timely action.

JIRA Key Announced Release Announced Summary

NXT-25000

3.22.2.0.0

The use of parameters that influence the resource representation in the 'Accept' header of an HTTP request is deprecated.

CPN-3249

4.25.1.0.0

HTTP API Caching override feature is deprecated in this release and will be removed in a future release.

POL-14428

4.25.1.0.0

The webTarget and initCallOut functions, which are used to make HTTP calls from dynamic logic, have been deprecated.