Pega Infinity™ includes an industry-standard patch release process to simplify and maintain high-quality releases. Several cumulative patches are released a year for each release stream. The Resolved Issues page contains information about client-reported issues that have been addressed for the specific release.
For a complete set of the Resolved Issues for this release, download the PDF attachment at the bottom of this page. (Note that you must be logged in to access the attachment.)
As part of Pega's long-term security strategy, AI-assisted scanning has been implemented on a proactive basis. Pega strongly recommends that clients stay current with the latest product versions to receive current security enhancements, patches, and hardening improvements, and promptly install all critical hotfixes.
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| E-4598 | Operator records no longer allow multiple email addresses | Previously, the Operator profile allowed multiple email addresses to be entered. With this update, one-time password (OTP) generation and email delivery are supported only for a single verified email address. Before updating to this release, review existing operators to ensure no more than one email address is set. If an existing user's operator record includes more than one email address or an invalid email address in the email field, the error "Please enter a valid email address" will be generated and email will not be sent when using the Forgot Password flow or opening any case which directly or indirectly validates the Email property. | Security | |
| INC-D561 INC-D31676 INC-D9237 INC-D9965 INC-D12271 INC-D15530 INC-D17687 INC-D18031 INC-D18258 INC-D19017 INC-D22001 INC-D22396 INC-D26272 INC-D27189 INC-D28037 INC-D30345 INC-D32353 INC-D33196 |
1004813 1004861 1004863 |
Recommended altered garbage collection characteristics | Frequent and misleading PEGA0028 alerts were being triggered by free heap falling below the configured threshold even when no genuine memory risk existed. This was caused by behavior changes in the JVM Garbage Collection (GC) process introduced with JDK21 in Pega Infinity 25.1. and later releases. Newer JDK versions delay collection cycles, increase minor GC frequency, and allow heap utilization to remain elevated for longer periods before cleanup occurs. As a result, the PEGA0028 alert "GC cannot reclaim memory from memory pools" has been triggered more frequently than in prior releases even in the absence of an actual out-of-memory (OOM) condition or any measurable business impact. To address this, it is recommended to adjust the JVM Argument value to G1ReservePercent=15 to return alert frequency to Java 17 levels. | Special Note |
Low-code Application Development
Case Management
25.1.4 Patch Resolved Issues for Case Management
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-D14757 | 993501 | Case creation lock management improved | After update, the pxCreateCase activity was generating lock gone exceptions at step 12. This has been resolved by updating the handling in the pxCreateCase activity to properly acquire and maintain locks throughout the entire case creation workflow. | Case Management |
| INC-D15718 | 1001011 | Dynamic audit history text localized | Audit history was displaying raw field values instead of executing dynamic localized text expressions, causing flow action names and field labels to appear as literal text rather than their intended localized values. This was caused by the @getLocalizedText function not being properly added for local action labels in the audit trail processing, and has been resolved. | Case Management |
| INC-D16465 | 1005797 | Case resolution status synchronization corrected | Cases configured with optional cancel actions were experiencing inconsistent resolution behavior where the assignment was properly removed and work history was correctly updated, but the work status remained as "New" instead of "Resolved-Cancelled" with missing resolution details. Investigation showed this was caused by improper page handling in the findPageByHandle method. This has been resolved by fixing the page synchronization logic to ensure work status properly reflects the resolution state. | Case Management |
| INC-D16597 INC-D24369 |
994565 998110 |
Annotation functionality made backwards compatible | After update, attempting to add annotations to images attached to work cases resulted in the attached image not displaying and the Draw button not being clickable. This was related to updates made to the SignaturePad version, and has been resolved by adding compatibility support for older plugin API behavior/signatures so they work as expected with the new version. | Case Management |
| INC-D17832 | 1008449 | URL mapping authentication restored | Applications were experiencing 403 forbidden errors when users clicked "Go to dashboard" buttons after being redirected back to Pega through URL mapping from external payment websites, despite successful URL mapping redirection. This was caused by improper BAC (Business Action Control) registration handling after external redirections that replaced the browser window context. This has been resolved by updating the authentication context restoration logic for URL mapping scenarios involving external redirections. | Case Management |
| INC-D17848 | 994218 | Multiselect control duplicate values eliminated | Multiselect controls were displaying duplicate values in the options list when users removed items after initially selecting all options, particularly when the data source contained options with similar names like "Life" and "Childrens Life". This was caused by improper option list management when dynamically updating the available choices after user selections. This has been resolved by correcting the multiselect control logic to properly maintain unique option lists and prevent duplication when options are added or removed. | Case Management |
| INC-D18672 | 996975 | Flow error display accuracy improved | Flow error displays were showing incorrect assignment labels when routing failures occurred, displaying the preceding step's label instead of the actual failed assignment label. This was caused by improper error context tracking in the flow error reporting mechanism, and has been resolved by correcting the error display logic along with updating the label from "Step" to "Problem occurred at" for better clarity. | Case Management |
| INC-D19898 | 998034 | Relative src handling restored in sanitization |
Relative image/resource paths were intermittently failing to render. This was traced to sanitization stripping the src attribute, which was presenting as missing media/content in processed UI output while markup was being cleaned, and was caused by an overly restrictive DOMPurify protocol/regex validation path that had been treating valid relative URLs as disallowed and removing src. This has been corrected by updating protocol handling to accommodate src attributes with relative URLs so sanitization will preserve legitimate relative paths while continuing to block unsafe protocols. | Case Management |
| INC-D21979 | 1001984 | Visibility condition rendering corrected for summary panel tabs | Applications were experiencing visibility condition failures when summary panels were collapsed or zoomed, where tabs configured with visibility conditions and "Reserve space when hidden" enabled were incorrectly displaying even when their conditions evaluated to false. Investigation showed that while the "show-space" class with visibility:hidden styling was being applied to individual elements, it was not being applied to their parent layout groups during panel state changes. This has been resolved by updating the CSS class application to ensure the show-space class is properly applied to layout groups when reserve space is hidden with visibility conditions. | Case Management |
| INC-D29702 | 1008971 | Archival settings retained after update | During system update, archival configurations were being automatically changed from archive-only to purge mode with a default 1825-day retention period, causing cases that were previously set to archive indefinitely to be scheduled for permanent deletion. Investigation showed this was caused by the upgrade process defaulting archival settings to include data retention policies when only archival was previously enabled. This has been resolved by modifying the upgrade process to preserve existing archival configurations without automatically enabling purge functionality by updating the pzPolicySettings section to separate the Enable archival policy and Enable data retention policy options. The Enable data retention policy checkbox will be shown only when Enable archival policy is selected, for both "Based on time since resolution" and "Based on business logic and time since resolution" configurations. For new case types, Archival days will be defaulted as 10 years and Data retention days will be defaulted as 100 years for both "Based on time since resolution" and "Based on business logic and time since resolution" configurations. | Case Management |
| INC-D31580 | 1015263 | Case review context synchronized | While assignments were being completed into review mode, the case was showing the correct mode at the top level while the container context could retain a stale or missing context_data.caseViewMode, resulting in inconsistent downstream state handling. Investigation showed this was caused by the finish-assignment flow updating commonOutActionPayload.caseViewMode without updating the corresponding nested context value. To address this, data.context_data.caseViewMode will be set to REVIEW_MODE alongside the top-level value in packages/corejs/src/case/finish-assignment/index.ts, ensuring both payload locations remain synchronized. | Case Management |
| INC-D35622 | 1019456 | Signed email attachment naming improved | Signed emails were sometimes arriving with inline images or attachments that had no filename metadata, and null names were being passed through processing, leading to inconsistent handling. Investigation showed this was caused by parser paths using the raw attachment filename from signed MIME parts even when it was blank or null. This has been resolved by adding a noname_<N> fallback naming approach in both Java Mail and MS Graph parsers. | Case Management |
| INC-D37937 | 1023372 | Inbound usage update reliability improved |
Daily Decision Usage processing could fail when updating existing inbound Decision Usage records, resulting in incomplete or inaccurate aggregation. This has been addressed by updating pzUpdateDailyDecisionUsage to detect existing records, open with lock, increment pyUsageValue, and persist through a single save path, while continuing to create a new record when no match exists. | Case Management |
| INC-D38863 INC-D43308 |
1014857 1017859 |
Chart insight displays localized | Chart Insights were displaying English or raw internal values for trend labels, status dimensions, and “N/A” placeholders instead of being localized. Trend tooltips and accessibility text were also being generated inconsistently, and invalid configurations could appear as “Invalid data configuration.” Investigation showed that chart text was being hardcoded or translated after dynamic strings had been assembled, while the data-transformer was not receiving the class metadata required for status localization. This has been corrected. | Case Management |
| INC-D39664 INC-D34019 |
1017986 1013403 |
Improved performance for declare expressions | A modal was freezing in Constellation when records were being added to an embedded table containing a multi-select control linked to a calculated property. This was traced to declare expressions being evaluated during high-cost processing steps (4, 9, 12) where they weren’t needed for correct behavior, causing extra processing overhead and slowing execution. This has been resolved by disabling declare expressions during those steps to reduce unnecessary computation and improve runtime performance. | Case Management |
| INC-D40966 | 1018480 | Correspondence timestamps preserved | The timestamp of the first outgoing correspondence was being incorrectly overwritten by the timestamp of a subsequent incoming correspondence. This issue only affected the first outgoing correspondence record; all subsequent outgoing and incoming correspondences retained the correct timestamps. This was due to the pulse post being created when a response was received from the customer, not by the originating outbound message. As a result, the sent datetime of the outbound email and the create datetime of pulse post did not match. To address this, separate original and creation timestamps will be maintained for each correspondence record so the time the outgoing email was actually sent is preserved and not overwritten by the later timestamp introduced by correspondence processing. | Case Management |
| INC-D41102 | 1021872 | Corrected grouped worklist refresh | Grouped worklists in tabbed views were either not refreshing or refreshing unexpectedly. Investigation showed that refresh was not being reliably called due to namespacing causing a mismatch when comparing the classIDs, and an insight inside the tabbed view being unnecessarily remounted when selecting a table action. This has been resolved with an update to derive a namespace-qualified class ID and by correcting the view lifecycle so the Insight is not remounted unnecessarily. | Case Management |
| INC-D41194 | 1016402 | TempPage lifecycle stabilized in security preload paths | After update, temporary pages were not being released as expected in specific user page flows. Investigation showed object cleanup for transient pages was not consistently happening, so memory-resident temp structures accumulated. This has been corrected by adding unconditional try/finally cleanup while preserving existing exception contracts and validating behavior. | Case Management |
| INC-D43824 | 1018892 | Restored stable REST class generation behavior: | During REST rule generation, it was being observed that more rules were being generated than expected and generated class structures were changing (notably in nested map/array and duplicate-property scenarios). Investigation showed this was caused by a shift to hierarchical class-name derivation in RuleGeneratorREST.handleJsonValue(...) that was altering legacy naming patterns for embedded objects and array-of-map structures. To address this, DSS-controlled legacy naming (Pega-IntegrationEngine/ruleRestGenerator/useLegacyClassGeneration) has been introduced so generation will use legacy class naming when enabled while preserving current behavior when disabled. | Case Management |
| INC-D45215 | 1019588 | Remote case type visibility restored | While working with case type discovery, remote case types were not appearing in the expected listing. Investigation showed this was caused by a missing privilege condition in the pzDiscoverCaseTypes activity path that was preventing authorized access to remote case type discovery results. To address this, a new privilege has been added to pzDiscoverCaseTypes to ensure remote case types are returned and visible as expected for appropriately authorized access. | Case Management |
Cloud Services
25.1.4 Resolved Issues for Cloud Services
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-B45609 | 950983 | File attachment handling improved in repository operations | The error message "Couldn't upload file. The specified file/folder already exists in the target repository. Please specify a different file/folder" was generated when trying to attach files with names that had been previously used, even after removing the original attachments from forms or case records. This issue was particularly problematic in scenarios where process flows encountered exceptions during file creation, as the attachment would persist in the S3 repository while the database transaction rolled back, creating an inconsistent state between the repository and database records. Investigation showed this was caused by insufficient cleanup of repository artifacts when attachment operations failed or were reversed, leaving orphaned files that blocked subsequent uploads with identical filenames. This has been resolved by implementing proper synchronization between repository and database operations to ensure complete cleanup of attachment artifacts during rollback scenarios and improved handling of duplicate filename conflicts. | Cloud Services |
Conversational Channels
25.1.4 Resolved Issues for Conversational Channels
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-D15916 | 994063 | Error handling updated for email reply with inline images | After update, email replies to inflight cases containing inline images were failing to send. Investigation showed that when sending an email containing inline images, any failure during image processing (e.g. malformed base64, missing data-content reference, bad CID) would throw an unhandled exception in the `pzUploadRTEImageFromBase64Url` activity, causing the entire send operation to abort. This has been resolved by updating the error handling to make the send operation more robust. | Conversational Channels |
| INC-D2743 INC-D2905 INC-D2908 INC-D3766 INC-D3770 INC-D5255 INC-D8280 INC-D8815 INC-D18871 INC-D23075 INC-D23203 INC-D23761 INC-D25316 INC-D26570 INC-D27194 INC-D41713 INC-D43111 INC-D45218 INC-D48110 |
993084 | Restored chat timeouts | Chat sessions were continuing beyond the configured timeout interval without displaying a timeout message. This was due to an issue with the timeout handling, and has been resolved by refactoring the handling to better cover multiple timeout scenarios and edge cases. | Conversational Channels |
| INC-D32442 | 1009188 | Email channel configuration reference corrected | Incoming email interactions were failing due to an incorrect variable reference in the pyTreatIncomingText activity for Work-Channel-Triage. This was caused by an incomplete variable reference in the activity step configuration, and has been resolved by correcting the declaration in the IVA Email feature. | Conversational Channels |
| INC-D35855 | 1011801 | Bot interaction timeout resolution improved | Bot interactions were failing to resolve automatically after the configured 24-hour timeout period, resulting in an excessive number of accumulated bot sessions. This was traced to the system not properly evaluating the pyIsExpired condition when determining which bot interactions should be automatically resolved, and has been corrected. | Conversational Channels |
| INC-D37526 | 1013974 | Agent conversation history and tool configuration issues resolved | Case Agent conversation history was disappearing following application version upgrades, and tool default values were failing to resolve when systems were running on different Infinity versions. Investigation showed the first issue was caused by the pzGetConversationsByContext Report Definition filtering conversations based on application version, making earlier conversations invisible after update. This has been resolved by changing the pzGetConversationsByContext report definition to pyGetConversationsByContext to make it available for customer customization. The second issue resulted from version compatibility problems when resolving Chat_with_your_data tool parameters. In some scenarios, the MCP failed to resolve default values for tool parameters, which could lead to missing-parameter errors or inconsistent tool behavior when optional inputs were omitted. This has been resolved by correcting the default-value resolution logic so tool defaults are consistently applied when explicit values are not provided. | Conversational Channels |
| INC-D38573 | 1017230 | Masking coverage improved | In order to improve security, masking coverage for sensitive message data has been extended to cover additional relevant properties. | Conversational Channels |
| INC-D39772 | 1020950 | Forwarded content correctly displays | Forwarded email content was not fully displayed in the receiving case’s email thread; only part of the message appeared. Investigation found that forwarded content was parsed separately but not rendered for incoming messages. This fix updates email processing so full content is preserved and displayed for forwarded and replied emails. | Conversational Channels |
Data Integration
25.1.4 Resolved Issues for Data Integration
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-259502 INC-B14827 INC-B32387 INC-C34516 |
946180 | Error handling improved for platform upgrade conclusion cache building | Platform updates could fail during class conclusion cache build due to ConclusionCachePreBuilder treating repeated ClassInfoConclusion initialization failures like generic build failures, triggering stop-building behavior. To address this, ClassInfoConclusion init failures are now treated with targeted handling, and those specific failures are captured and reported in a consolidated error. Non-ClassInfoConclusion failures still follow the original stop-building path. | Data Integration |
| INC-C59927 | 996934 | Logging added for DirectStreamEncoderV7 | Targeted logging has been added to the DirectStreamEncoderV7 class in order to assist with diagnosing BLOB/PageList corruption or indexing issues. | Data Integration |
| INC-D14282 | 996503 | Archived data display restored for migrated cases | Case Note and Activity data was not displaying for archived cases migrated from on-premises Pega 8.7 environments to PegaCloud, while locally archived cases displayed correctly. This was caused by compatibility issues with the database regex patterns for migrated archive data, and has been resolved by updating the MSSQL regex to properly handle migrated archive data formats. | Data Integration |
| INC-D14356 | 1000283 | Improved data transform error diagnostics: | During Data Transform assistance, processing was intermittently failing while retrieving page-list values, and the failure was surfacing as an IndexOutOfBoundsException (including access via getListValues().get(aIndex - 1)). To address this, exception handling in getPageValue (ClipboardPropertyBase.java) has been improved by catching IndexOutOfBoundsException during list access and rethrowing a more descriptive platform exception using handleIOOBException. This improves clarity when malformed or out-of-range index data is encountered in Data Transform assistance, enabling faster diagnosis of bad input data paths. | Data Integration |
| INC-D17635 | 997519 | Date calculation timezone handling standardized | After migration, the pxDifferenceInDays function was producing different results between on-premise and cloud environments. This was traced to the report calculations using pxDifferenceIn* functions which could return values based on the database or raw timezone rather than the operator’s effective timezone, causing users in non-database timezones to see off-by-one or otherwise skewed differences, especially around date boundaries. To address this, the timezone conversion logic has been updated and a new DSS "useOperatorTimeZone" setting has been added for configuration control so report difference values are aligned to their timezone context. When dateCalculations/OnPegaCloud/useOperatorTimezone is enabled, the functions convert timestamps using the operator timezone from pxRequestor.pyUseTimeZone, with a fallback to the default operator timezone. | Data Integration |
| INC-D18151 | 993534 | Assignment page null pointer exception fixed | Assignment operations were intermittently failing with a NullPointerException in the OpenAndLockWork activity. Investigation showed the assignPage variable was unexpectedly null when the activity attempted to rename it, causing the "Cannot invoke rename(String) because assignPage is null" error. This has been resolved by updating the null checking and error handling in the assignment processing logic to prevent the null pointer exception. | Data Integration |
| INC-D20267 | 1000228 | Data migration pipeline service availability improved | Data migration pipelines were failing when attempting to write to file datasets with ""503 Service Unavailable"" errors from Google Cloud Storage during resumable uploads. The failures occurred during POST operations to storage.googleapis.com/upload/storage/v1 endpoints, preventing completion of data migration workflows. This has been resolved by implementing improved error handling and retry mechanisms for cloud file repository operations. | Data Integration |
| INC-D21011 | 996424 | User reference properties visibility restored in authoring | User reference properties like pxStatusStartOperator and pxStatusCompleteOperator were not appearing during List view authoring even after being marked as relevant. This has been resolved by updating the UI controls to pxDropdown or pxAutoComplete and creating proper association rules with Data-Admin-Operator-ID. | Data Integration |
| INC-D21326 | 1000570 | Restored rule validation and saving | Blank screens were seen when opening selected rules or creating and saving rules, and revalidation of the affected section was failing. This was traced to incomplete page/class context for the section rule pzRARecor at runtime, and has been resolved with an updated to add the missing pages and classes so validation and saving can complete. | Data Integration |
| INC-D22247 | 1005217 | Email approval flow processing restored | Email approval flows were getting stuck at approval stages and not resuming after email processing. This was caused by a mismatch in action name comparison logic between UI-Kit applications using "pyApproveInternal" and Constellation applications using "pzApproveInternal" in the pyProcessEmailRequest activity. This has been resolved by correcting the action name matching logic to handle both UI-Kit and Constellation approval actions. | Data Integration |
| INC-D23418 INC-D36526 |
1009417 1011806 |
Case archival optimized for complex hierarchies | Pipeline archival jobs were not completing the archival process when encountering extremely complex case hierarchies. Investigation showed that when a case type class had no sub-cases in its hierarchy, the archival pipeline built an invalid CTE and silently returned empty results, causing jobs to run to completion without archiving any data. This has been resolved with an update to resolve silent archival failures by introducing a configurable fallback strategy: DSS-configured case types skip traditional hierarchy construction and use native SQL recursive (START WITH / CONNECT BY) queries on single tables, while all other case types continue using the existing multi-table union-CTE approach. Additionally, when any case type has an empty sub-case list at runtime, a fallback recursive query is automatically triggered to prevent failed archival operations. | Data Integration |
| INC-D23653 | 1003857 | Screenflow navigation state accuracy restored | Screenflow progress indicators were displaying incorrect states in embedded subprocess scenarios, showing navigation elements as both completed and current simultaneously with partially colored progress bars. This was a missed use case caused by the pyTabbedScreenFlow7Nav rule not correctly handling navigation state for nested screenflows containing subflow navigation, and has been resolved by updating the screenflow navigation logic to properly manage state transitions in embedded subprocess scenarios. | Data Integration |
| INC-D23798 | 996665 | Database upgrade DDL generation corrected | Platform update from Infinity 24.2 to Infinity 25.1 was failing during DDL application due to incorrect "drop function" command generation when duplicate database functions existed with different argument types (varchar vs text). Investigation showed this was caused by the DDL generator not properly handling metadata inconsistencies when multiple versions of the same function existed in the database. This has been resolved by improving the DDL generation logic to correctly handle function metadata variations during database upgrades. | Data Integration |
| INC-D24248 | 1006135 | Set value event action functionality corrected for hidden tabs | After update, dropdown controls were failing to update other properties when their values changed, especially when one tab was hidden and submit logic was triggered from the active tab. Investigation showed this was caused by field validation logic not correctly accounting for tab visibility/active context during submit-time checks on hidden tabs, affecting OnSubmit processing in active tabs. This has been resolved by correcting the field validation logic to properly handle event actions across tab configurations. | Data Integration |
| INC-D24451 | 999280 | Real Time Extraction (RTE) BIX performance and scalability improvements | Writing events to Kafka was taking an excessive amount of time when handling a large number of events (100k). In order to address this, new alerting and context-building capabilities for extract event processing have been introduced, primarily focused on Kafka integration and message size monitoring. This reflects a change in implementation: instead of processing BIX extract events internally, changed events are now published directly to an external Kafka system. Outbound payload shaping for external Kafka consumers uses the more efficient metadata + data structure. New utility methods for raising event alerts, logging message size threshold violations, and constructing standardized alert context strings have been provided. To improve performance and scalability, the legacy single Job Scheduler flow has been replaced with a Queue Processor-based pipeline with three dedicated queue processors: pzRealTimeExtractionCaseQP pzRealTimeExtractionDataUpdateQP pzRealTimeExtractionDataDeleteQP The previous rule pzProcessBIXExtractEvents is disabled by default but remains available as an override option if there is a need to process in-flight data during migration to external Kafka. Please refer to the documentation for configuring real-time data extraction for further information. |
Data Integration |
| INC-D24561 | 1000957 | Autocomplete leave blank display corrected for embedded page properties | Autocomplete controls were displaying incorrectly for "Leave Blank" options when configured with embedded page property data sources from report definitions. This was traced to the markup handling where a blank value in the “TOP” result could show up as a narrow/incorrect blank entry, and has been corrected. | Data Integration |
| INC-D25552 | 1010160 1019475 |
Recent list population performance improved | The pzPopulateRecentList activity was experiencing significant performance degradation due to inefficient blob column retrieval in the recent items query. This was caused by missing optimization for large data retrieval in the recent list population logic. To address this, a DSS has been added to enable query optimization along with reducing blob column access frequency to improve database performance for recent list operations. This replaces a costly full-row scan/query pattern with an indexed retrieval + per-row hydration approach. The DSS "useIndexedHydration" defaults to false to maintain the current behavior of directly selecting the full set of needed fields (pySelectFields) in one go, without per-row open/hydration. When set to 'true', the query fetches lightweight row keys (uses pzInsKey/handle), then each result row is “hydrated” by opening the full record (Obj-Open by handle) to populate fields like label/description/content type. Note that some newly-created cases may be excluded from the results when "useIndexedHydration" is enabled and its use may not be preferred in all environments. | Data Integration |
| INC-D27517 | 1001614 | Queue processor maintenance updated for cross-database compatibility | After update, queue processor maintenance jobs were failing on non-PostgreSQL databases, including Microsoft SQL Server environments, during the execution of a new delayed item metrics calculation step that was introduced as part of internal queue processor monitoring enhancements. These were traced to database-specific datetime formatting in a SQL query within the pzQueueProcessorMaintenance activity that was incompatible with MSSQL's datetime conversion requirements , and which generated the error "There was a database problem when performing an RDBExecute: code: 241 SQLState: S0001 Message: An error occurred during the current command (Done status 0). Conversion failed when converting date and/or time from character string." This has been resolved by updating the SQL statement for queue processor metrics to use the ANSI CURRENT_TIMESTAMP keyword, ensuring cross-database compatibility for the delayed item metrics functionality. | Data Integration |
| INC-D28560 | 1013856 | Assignment label length validation updated for work actions populate activity | Work object action menus were generating string length errors when usernames exceeded 64 characters, causing the pyWorkActionsPopulate activity to fail during label extraction from workflow assignments. This was caused by the activity concatenating flow names and usernames into the pyLabel property without considering the 64-character database field limit, and has been resolved by implementing proper string truncation and length validation in the pyWorkActionsPopulate activity for pzGetAssignmentLabel to print the first 64 characters. | Data Integration |
| INC-D29311 | 1006804 | File upload size validation precision corrected for drag-drop controls | File upload operations were exhibiting inconsistent size validation behavior across versions, with the drag-drop control accepting files that exceeded configured limits due to precision errors during megabyte-to-byte conversion calculations. This has been resolved by ensuring file size validation accurately enforces the configured pyMaxDragDropAttachSizeMB limits by updating the validateMaxSize function in AttachmentUtils.ts to check if the file size (in MB) is less than or equal to the maximum allowed size, and no longer round the file size before comparison. | Data Integration |
| INC-D29605 INC-D29605 |
1008610 1005793 |
Restricted Pulse message security enhanced | To improve security for Pulse messages, an updated access verification mechanism has been introduced in the Constellation API endpoint to ensure authorization checks are properly enforced on the messageID path parameter before allowing users to view, like, or interact with messages. | Data Integration |
| INC-D30480 | 1014027 | TrackSecurityChanges activity deprecated | Field-level auditing (FLA) has been replaced by the current Case Type Design Settings implementation. The TrackSecurityChanges activity rule has been marked as deprecated to clearly indicate it is no longer the supported method for field-level auditing. | Data Integration |
| INC-D30924 | 1009438 | Feature toggle guard added for purge/index deletion behavior | Archival operations were failing with exceptions during indexing when the workenabled parameter was set to false, and the message "Failed to delete live indexes" was generated. Investigation showed the purge flow did not gate live-index deletion on the indexing/workenabled dynamic setting. As a result, purge logic still called deleteLiveIndexes in code paths where work indexing was intentionally off. This has been addressed with a check for whether work indexing is enabled before trying to delete live search indexes during archival purge. If the setting is false, purge code skips live-index deletion (deleteLiveIndexes) and returns without calling the archive indexer, preventing unnecessary failures. | Data Integration |
| INC-D31037 | 1009864 | Parent case refresh addressed | The parent case remained open with stale assignments after a child case had been resolved through the case hierarchy widget. The correct status was shown after a manual refresh was performed. Investigation showed that auto-refresh was not triggered when navigating back to the parent case after resolving a child case, causing the task list to not reflect the updated state and continue to show outdated tasks. This has been corrected. | Data Integration |
| INC-D31506 | 1011445 | Restored survey radio scores | Survey scores for radio-button answers were remaining at zero on the clipboard, causing the final score to be incorrect. This was traced to the scoring for simple radio-button questions not being carried over from the selected answer, and has been corrected. | Data Integration |
| INC-D31861 INC-D42358 |
1012476 1017362 |
Datetime function timezone handling standardized | Report definitions and datetime functions were not properly considering user timezone settings when processing constant parameters, causing date filtering mismatches. This has been resolved by implementing explicit type casting for datetime constants in SQL queries to ensure consistent timezone behavior. | Data Integration |
| INC-D32169 | 1015757 | Notification recovery corrected | Recents entries could remain stale after a thread was passivated and reactivated, often until another interaction triggered refresh behavior. This was traced to stream change trackers losing active thread/requestor associations and watch registrations during passivation, resulting in missed cross-thread updates which didn’t produce the required RequestorChangeSet. This has been resolved by restoring tracker requestor/thread bindings and re-registering watches during activation, allowing Recents to refresh automatically. | Data Integration |
| INC-D32395 | 1013034 | SLA queue processor lock timeout corrected | When workflows transitioned from Wait shapes to Assignment shapes and errors occurred during transitions, the pyProcessSLA Queue Processor would lock cases for SLA processing, but if transactions encountered errors and rolled back, locks would persist until the 30-minute lease timeout expired automatically. This was caused by improper lock release handling when transaction rollbacks occurred during SLA processing. This has been resolved by updating the lock cleanup procedures in the Case Locking feature to ensure locks acquired in restore assignment are released correctly on commit. | Data Integration |
| INC-D32863 | 1017943 | Improved action timing accuracy | Assignment action-duration metrics were being overstated or understated during perform/flow-action processing, especially when assignments were revisited, cancelled, or hit optimistic-locking paths. Investigation showed this was caused by pyPerformActionTime being derived from assignment lock/update timing rather than a persisted action-specific start/stop record keyed by action, assignment, and operator. This has been resolved with the implementation of persistent System-ActionHandlingTime lifecycle handling which includes the new activities pzCreateSystemHandlingTimeRecord, pzDeleteSystemHandlingTimeRecord, and pzCleanupStaleActionHandlingTimeRecords. Retention control has been introduced through the DSS systemActionHandlingTime/lifeInMinutes (default 120) via the utility pzGetSystemActionHandlingTimeRecordLifeInSeconds. | Data Integration |
| INC-D33350 | 1016988 | Corrected duplicate mapping in column population wizard | During reruns of the Column Population (colpop) wizard on page-optimized classes, duplicate column mappings and conflicting column map names were causing inconsistent mapping outcomes across class hierarchy processing. This was caused by reuse of a single mutable pageColumn value across class iterations combined with early loop exit behavior, and has been resolved by introducing per-class column tracking (classToColumn). | Data Integration |
| INC-D33776 | 1009828 | Popup data refresh functionality restored | After update, the pyRefreshData data transform specific to the List class was not being invoked when submitting popups from modal windows invoked from grids. Investigation showed this was caused by the pzFormPageInstructionsForRowOperations activity missing page context when adding Param.InterestPage for applying the data transform, causing pyRefreshData to be resolved using the work page context during certain refresh operations instead of the embedded page context associated with the list item being refreshed. This has been resolved with an update to run the pyRefreshdata data transform based on interestPage parameter populated and to not run for v1 APIs. | Data Integration |
| INC-D34094 INC-D18233 |
1010273 1008948 |
Archival SQL generation logic updated | Archival jobs were failing with ORA-01489 errors when processing cases with large text content during SQL generation. This was due to the archival SQL generation logic using nested Oracle CONCAT implementations that exceeded Oracle's 4,000-character VARCHAR2 limit when handling large note content. To address this, the archival SQL generation logic has been updated to replace the existing nested Oracle CONCAT implementation with a TO_CLOB() based approach to support larger content without data loss. | Data Integration |
| INC-D34778 | 1012395 | Process Fabric archival policy purge functionality enabled for PPF work classes | Archival policies configured for direct purging of PPF-Work-Case and PPF-Work-Task classes were failing to remove resolved cases older than the specified retention period. Investigation showed that pyID can be blank in PPF cases, causing null map keys in getPyIDsMap(). To resolve this, null and blank checks for pyID have been added, with fallback handling for the map key if pyID is blank. | Data Integration |
| INC-D34814 | 1015435 | Wait deadline handling corrected | Assignments following multiple wait points were displaying the deadline associated with the first wait point rather than the corresponding wait point. Investigation showed the assignment context was not being refreshed when processing flows containing multiple Wait shapes, leading to stale assignment information from the first Wait shape being reused. To address this, the pyContinueAfterWaitPre activity has been updated to the refresh assignment data before determining each deadline. | Data Integration |
| INC-D35204 | 1013421 | Optimistic locking local action context preserved | Users were being navigated away from local actions and losing their work when clicking "Refresh" in the optimistic locking stale case dialog, as the refresh process updated case pages but did not maintain the local action context. This was caused by the refresh mechanism updating pyWorkPage and newAssignPage without preserving the current local action state. This has been resolved by modifying the refresh process to retain local action context so users remain on the same screen and can continue their work after refreshing stale case data. | Data Integration |
| INC-D35205 | 1010116 | Case archival search capability expanded to support embedded properties | Case archival search functionality was limited to embedded page-list and embedded page-group properties, preventing searches using standard embedded properties. This has been resolved by adding comprehensive logic to support search operations using embedded properties, expanding the search capabilities for archived case data. | Data Integration |
| INC-D35279 INC-D35160 INC-D39403 |
1011091 1011396 1014639 1011219 |
Null check added for assignment drag and drop | Assignment transfers using drag and drop functionality were failing with error popups and preventing successful work transfers between workbaskets and worklists. This was traced to a null pointer exception in Step 2 of the pxTransferAssignment activity, and has been resolved by adding a condition to verify whether the step page exists, and if the step page is empty, Step 2 will be skipped to prevent null step page issues. | Data Integration |
| INC-D35647 | 1013224 | Assignment creation restored | After update, Review Requirement assignments were not being created when completing Action assignments in requirement case flows, preventing cases from progressing from Pending-Response to Pending-Review status. Investigation showed this was caused by changes to step 8 in the pxDeleteAssignmentsForWork activity within the Pega-ProcessEngine ruleset to handle cleanup of flow pages. This step invoked the RecalculateAndSave method, which unexpectedly interrupted the flow progression and caused cases to stall at a stage. This has been resolved by adding a boolean parameter CleanupFlows to the pxDeleteAssignmentsForWork activity, where step 8 will only execute to delete flow pages when this parameter is true, and by enabling the CleanupFlows parameter in step 11 of the pzUpdateAndDeleteAssignments activity to properly control assignment cleanup behavior. | Data Integration |
| INC-D37420 | 1013454 | Non-PDF attachment processing restored | Non-PDF file attachments (.xlsx, .docx) were failing to save to cases with a NullPointerException in the SaveAttachment activity while PDF attachments continued to work correctly through the AttachToWork activity. Investigation showed this was caused by improper page context handling in the SaveAttachment, and has been corrected. | Data Integration |
| INC-D38018 | 1018460 | Corrected formatting evaluation | A number-formatting failure was being observed after update. Investigation showed that an incompatible API cast had been introduced during formatting evaluation. To address this, the 'when' rule evaluation for pyCurrencyQualifierFormat has been updated to use the correct casting/logic. | Data Integration |
| INC-D38605 | 1017686 | Enabled secure scheduled emails | Scheduled report emails were failing during secure connection negotiation while other system-generated emails continued sending successfully. Investigation showed that the scheduled report activity chain was not passing the pyNotifyAccountName parameter needed to load the truststore configuration. This has been resolved by passing the parameter through the scheduled report email flow so secure connection settings can be applied. | Data Integration |
| INC-D42932 | 1019802 | Corrected attachment page handling | Email replies were sent successfully, but a background attachment-processing error was triggered. Investigation found that an existing attachmentpage of an incompatible class was being reused. To resolve this, pzLoadFirstInboundEmail has been updated to validate the attachmentpage class and instantiate a new page of the expected class when a mismatch is detected, preventing class/type conflicts in the reply flow. | Data Integration |
| INC-D43421 | 1020575 | Date parsing strengthened |
Date handling was intermittently presenting as accepted but incorrect values when malformed or ambiguous date strings were being processed, and downstream behavior was appearing inconsistent across conversion and strict-formatting paths. Investigation showed this was caused by overly permissive parsing logic that had been accepting invalid inputs instead of enforcing strict validation. This has been resolved by tightening date parsing behavior so invalid/ambiguous inputs are rejected instead of being leniently interpreted. | Data Integration |
| INC-D44038 | 1021049 | Corrected assignment page comparison | Assigning a sub-case was not consistently transferring the assignment to the expected workbasket. Investigation showed that an empty page reference prevented the page-copy operation from executing because the comparison used the wrong page context. To address this, the assignment logic will set the proper step page to avoid assignment mismatch issues on the pxFlow page. | Data Integration |
| INC-D5453 | 995178 | Idle connection handling improved | Requests to the v2 Case DXAPI for remote cases were intermittently returning an HTTP 500 error on the first access while succeeding on subsequent requests. Investigation showed this was caused by stale idle HTTP connections being reused from the gateway connection pool. To address this, automatic eviction of idle connections has been made configurable through the gateway/evictidleconnectionstimeout DASS setting, with a default of 180 seconds and supported limits of 10–300 seconds. | Data Integration |
| INC-D7602 | 994066 | Ajax container tab behavior stabilized | Ajax container tabs in the pyCaseManager portal were exhibiting inconsistent behavior including tabs reappearing after closure, incorrect tab names displaying after browser reload, and SafeURL null pointer exceptions when closing tabs, particularly after upgrading from deprecated tab group layouts. This was caused by improper state management in the Ajax container implementation and race conditions in the tab lifecycle events, and has been resolved by updating the tab state management. | Data Integration |
| INC-D8250 INC-D297 INC-D36939 INC-D45377 |
1010082 1006704 1011413 1022232 |
Pega archiver pipeline execution stabilized | The pyPegaArchiverUsingPipeline job scheduler was running endlessly without performing any archival actions, requiring manual environment restarts to resolve the issue. Investigation showed this was caused by missing end time conditions in the copier logic that prevented the archival process from stopping when the job scheduler duration was completed. This has been resolved by adding proper fail-safe cleanup and predictable termination. | Data Integration |
| INC-D9141 | 992864 | Parent case lock release mechanism fixed | Parent case locks were not being properly released when child case assignments were canceled in Constellation applications with default locking configuration. This was occurring when child cases skipped the create stage and had "not lock parent case" option unchecked. This was caused by the pxLockHandle not being properly populated for parent case lock management, and has been resolved. | Data Integration |
Decision Management
25.1.4 Resolved Issues for Decision Management
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-D13523 | 1004465 | Email markdown rendering restored in notifications | Pulse email notifications were intermittently showing malformed content, with Markdown links and images failing to render correctly after sanitization and appearing as plain/broken markup in notification emails. This was caused by encoded Markdown parentheses being preserved through sanitization, which prevented proper parsing in `PRAdvancedMarkupEmitterImpl.java` for link/image formatting. This has been resolved by decoding encoded Markdown parentheses before rendering and by adding automated coverage in `TestPRAdvancedMarkupEmitterImpl.java` for encoded Markdown links, encoded Markdown images, and HTML regression-boundary protection. | Decision Management |
| INC-D15355 INC-D34669 |
1001980 1009129 |
Queue processor lag calculation corrected | Queue processor dataflows were displaying misleading lag metrics with extremely high lag values while the Ready to Process (RTP) count remained at zero. This was traced to a calculation mismatch caused by two edge cases where the source offset meets or exceeds the stream end offset, and is a race condition observed specifically with AWS Kafka's delayed offset pointer updates. This has been resolved by correcting the lag calculation algorithm to accurately reflect the true processing state, ensuring that lag metrics now properly correspond with the Ready to Process counts and provide reliable monitoring data for queue processor performance. | Decision Management |
| INC-D15984 | 1002115 | Adaptive model predictor display limit increased | Adaptive model reports were displaying only 500 predictors in the predictor importance tab despite having more than 500 predictors available in the model. This was caused by hardcoded limits in the pzgbpredictorinfo and pzpredictorinfo data retrieval queries, and has been resolved by increasing pyMaxRecords from 500 to 2000 for predictor reports. | Decision Management |
| INC-D15986 | 1003690 | Prediction response timeout validation improved | It was possible to set prediction response timeout values that exceeded the corresponding TTL settings in ADMShortTimeoutForDelayedLearning or ADMTimeoutForDelayedLearning DSS, particularly when setting timeouts to 30 days or more. This has been resolved by implementing validation warnings that alert users when response timeout values approach or exceed the relevant TTL thresholds. | Decision Management |
| INC-D16320 | 993806 | Corrected data-flow alert thresholds | Data-flow performance alerts were being generated with threshold values that did not match the configured KPI. Investigation showed that alert processing was using a default duration instead of the configured value for each run. To address this, alert processing will use the configured KPI and fall back to the default value of 5 minutes (300000ms) only when no value is provided. | Decision Management |
| INC-D19329 | 1003357 | Application overlay save performance improved | Application Overlay save functionality was failing when overlays contained a high number of rules, with the RevisionRecords data instance not updating with saved rules and success banners failing to appear, though minor overlay ruleset versions were still being generated. This was caused by performance bottlenecks in the code when processing large rule sets. This has been resolved by implementing code optimizations that allow overlay saves to work properly regardless of the number of rules. | Decision Management |
| INC-D21058 | 993782 | Handled reserved email subject terms | Email triage was failing when a subject contained the word "Call," preventing normal topic, subject, and entity analysis. Investigation showed that the subject was being parsed as a rule invocation because it was not separated from the reserved term. This has been resolved by updating pyGetTextToAnalyzeForEmail to add a space before the email subject during analysis. | Decision Management |
| INC-D21197 INC-D40122 |
1002312 1017173 |
Email processing restored after agent queue handling improved | Outbound emails were getting stuck in processing status without completing or failing, requiring manual intervention to restore normal operations. Investigation showed this was caused by a dataflow progress tracking mechanism that returned stale progress information when checking non-existent runs on the same thread. This has been resolved by ensuring the pxLoadProgress activity never returns stale progress for deleted runs, preventing the SendEmailChild agent from getting stuck in processing state. | Decision Management |
| INC-D21366 | 1001067 | Handling updated for value finder simulation date casting | Value Finder simulations were failing with "InvalidValueException: Cannot cast to date the value 2026-05-18 00:56:56" errors during data flow execution. This occurred when date properties were stored in App-SR class instead of the expected Data-PxStrategy class format, and has been addressed by saving pxObjClass to files in specific data sets to ensure properties are deserialized using correct context. | Decision Management |
| INC-D21427 | 997462 | Data migration thread handling updated for ADM factory | The ADM Migration Import DataFlow was running at only 1 record per second with single thread execution, causing excessively long migration durations. This was traced to the DataFlow not applying RunOptions configuration for thread count and batch size, and was due to the DSS values not being honored for the path when import ran with repository persistence enabled. This has been resolved with an update to ensure the system considers requestor and batch size DSS values when configured. | Decision Management |
| INC-D21632 | 1007475 | Audience simulation results display corrected for mixed engagement policies | Audience simulation was not displaying eligible counts when actions contained a mix of engagement policy rules including both 'when' rules and strategies, preventing proper simulation analysis. Investigation showed this was caused by PropositionFilter in Explain Mode not passing context pages correctly to sub-strategies when proposition filters were not inlined. This has been resolved by updating the strategy execution flow so sub-strategies receive the same context page data as the parent path. | Decision Management |
| INC-D22143 | 997735 | Error handling updated for DataFlow resiliency | DataFlows with failureThreshold configured were remaining in In-Progress status when failures occurred within threshold limits, requiring node shutdown to recover. This was caused by the resiliency layer not checking completion status or posting terminal signals when failures were within threshold, leading to the in-flight request counter not being decremented. This has been resolved by ensuring count down latches do not leak when errors are encountered in secondary sources. | Decision Management |
| INC-D23612 | 1011298 | Proposition filter corruption prevention added | The Proposition Filter was experiencing corruption when rule conditions were automatically processed through the pyAddSpecificCriteria API. This was caused by the API immediately calling pzSetSelectedPropertyDetails without proper preparation or validation of the proposition filter state. To resolve this, proper validation and state management have been implemented in the proposition filter processing to prevent corruption during automatic rule condition handling. | Decision Management |
| INC-D23714 | 998777 | Updated error handling in Globally Optimized Strategy execution | Campaign DataFlow execution was failing with NullPointerException "Cannot read field 'state' because 'v' is null" in ExecutionProfileRegistry during Globally Optimized Strategy (GOS) execution. This has been addressed by making profile-registry handling null-safe and initializing/guarding the registry access path. | Decision Management |
| INC-D23783 | 1000694 | Added handling to avoid data flow stuck threads | Data flows were experiencing NPE exceptions in pyProcessSLA operations and becoming stuck in inconsistent states when the PRPulseDispatcher class terminated the same requestor that the data flow was using for pyProcessSLA runs. This was traced to a race condition where two processes were borrowing the same requestor, leading to stale PRPC thread failures including StaleThreadError exceptions. This has been resolved by updating the handling for stale thread exceptions to mark the data flow as failed instead of ending in a stuck state. | Decision Management |
| INC-D25251 | 997737 | Data import completion restored | A data import was remaining pending when one of its data flow runs was completed with failure. Investigation showed that the step entry condition logic had an overly strict success criterion which only recognized fully successful completion and did not include the state “Completed with failures.” As a result, executions that should have been treated as acceptable completion were misclassified. To address this, the activity condition will recognize completed-with-failure runs appropriately so the import can complete. | Decision Management |
| INC-D26381 | 1010025 | Email processing with large attachments made configurable | Email processing was failing when large attachments were sent through background processing via the DelayedItemsDataFlowService, generating "IllegalArgumentException: Unsupported property mode J. Property: pyPayload" errors during serialization. Investigation showed this was caused by the system's inability to properly serialize large Java objects in the queue processor when handling substantial email attachments. This has been resolved by adding serialization options for Java objects in queue processors and implementing the "PegaEngine:queueprocessors/serialization/maxJavaObjectSizeMb" DSS to control the maximum attachment size that can be serialized (default is 32MB). | Decision Management |
| INC-D26477 | 1002789 | Documentation updated for post-Hazelcast clustering settings | The documentation for configuring a prpcUtils streaming service has been updated to clarify the setting configurations for connecting to an externalized Kafka streaming service. This configuration is necessary to override the default stream provider settings and ensure that clustering continues to work in a client-managed cloud deployment after Hazelcast removal. | Decision Management |
| INC-D27869 INC-D36960 |
1003615 1011885 |
Campaign data flow startup timing issue resolved | Campaign data flows were failing during system startup when the data flow batch service was becoming available before the ADM (Adaptive Decision Manager) service had fully initialized on the same pod. This was occurring because the ADM service is designed to start sequentially across pods, creating a timing window where campaign processing could begin and then fail when attempting to access ADM functionality that was not yet ready. This has been resolved by updating the data flow startup behavior to ensure that pods do not begin processing data flow runs until the node is in running state, which guarantees that all dependent services including ADM are fully available before campaign processing begins. | Decision Management |
| INC-D27883 | 1003863 | Added handling for unsupported scorecard results in response-processing data flow | The pxHandleResponses DataFlow was failing at the Analytics stage when it encountered scorecard model results, generating the exception "error Unknown model type SCORECARD, cannot handle model execution". The Scorecard model type is not supported by Pega in Capture response. To address this error, scorecard results will be handled silently instead of throwing an exception. | Decision Management |
| INC-D28112 | 1002148 | Adaptive analytics batch processing stabilized | Daily batch runs were failing intermittently with NullPointerException errors while saving decision data into the pxAdaptiveAnalytics dataset, affecting one or two records out of every 1000 processed. Investigation showed this was caused by a race condition where concurrent FutureCallback invocations in ClientImpl.handleStrategyResult corrupted the internal ArrayList in HandledStrategyResult.Builder. This has been resolved by making the HandledStrategyResult.Builder thread-safe to prevent concurrent access issues. | Decision Management |
| INC-D28245 INC-D28336 INC-D29551 INC-D29079 |
1002296 | Commons-lang dependency restored | After update, class-loading and runtime linkage failures were seen inside the DSM action analysis service when attempting to compile functions. This has been resolved by restoring libs.commons.lang to the implementation dependencies of the action-analysis-service-remote module to guarantee runtime classpath availability. | Decision Management |
| INC-D28403 | 1009897 | Diagnostic logging improved for DSM property cache | In order to assist with diagnosing issues related to interaction History files being generated with properties lacking proper datatype definitions, existing log statements have been refined to improve troubleshooting information. | Decision Management |
| INC-D29078 | 1015440 | Enabled decision data keys | Newly added decision data fields were not being enabled as key attributes by default while rules were being created or updated. Investigation showed that key-option initialization was not being applied to newly added fields. To address this, key-option initialization will be corrected for newly added fields. | Decision Management |
| INC-D29509 | 1011863 | Background process execution stabilized for cases using custom HTML fragments | Cases were becoming stuck and failing to auto-resolve when custom flows executed SIHistoryAndAttachments HTML rules as part of background processes. Investigation showed this was caused by the pzPegaBaseScripts fragment attempting to access OperatorID.pyPreferences when the OperatorID page was null during background execution. This has been resolved by removing the unnecessary conditional logic and implementing proper null checks to ensure background processes can execute HTML fragments without operator context dependencies. | Decision Management |
| INC-D29522 | 1003697 | Hyphen character validation made consistent in Prediction Studio | Validation errors occurred when attempting to configure initial response event labels containing hyphens such as "card-displayed" in Prediction Studio settings despite the system allowing the same hyphen-containing values in target labels. This was caused by inconsistent validation rules between the initial response and target label fields, and has been resolved by updating the validation logic to consistently allow hyphen characters in both initial response and target label configurations across Prediction Studio. | Decision Management |
| INC-D30494 | 1007459 | Improved strategy dependency readiness | Strategy deployments were being served before non-inlined proposition filter dependencies were ready, which could cause service disruption during offer deployment. Investigation showed that the optimization was treating those dependencies as external black boxes and marking the strategy ready prematurely. To address this, the revision invalidation logic will account for non-inlined dependencies and handle the application requestor type correctly. | Decision Management |
| INC-D31631 | 1009215 | Ethical bias simulation threshold evaluation fixed | Ethical bias simulation reports were incorrectly flagging bias as True even when bias values were within configured threshold ranges and outside confidence interval ranges, particularly affecting numeric fields that were not actually biased. Investigation showed the threshold and confidence interval evaluation logic was inverted and incorrectly processing the conditional statements. This has been resolved by correcting the threshold comparison logic in the Bias Check feature so bias will be detected only when the lower bound of the confidence interval is greater than the configured upper threshold. | Decision Management |
| INC-D31906 | 1008269 | Kafka OAuth authentication scope error corrected | OAuthBearer authentication for Confluent Kafka integration was failing during server startup with "invalid_scope" error messages stating "missing required scopes, [openid]" in the api.StreamOAuthBearerCallbackHandler logger. This was caused by the callback handler not including subproperty keys, so valid nested config values were silently dropped. This has been resolved by ensuring nested/sub-properties are included when building the JAAS config for Kafka OAuth bearer auth. | Decision Management |
| INC-D32353 | 1010045 | Interaction history summary cache memory handling refactored for improved performance | Campaign runs were experiencing significant performance degradation after update, accompanied by abnormal increases in strategy performance profile samples. The original batch cache implementation used multi-level nested maps that stored results keyed by every unique combination of optional parameters. In scenarios where queries had many optional keys with varying values (like interaction IDs, ranks, etc.), the cache would create exponentially many entries - one for each combination - leading to unbounded memory growth as the cache was never pruned. This has been resolved by restructuring how the cache stores and retrieves data. Instead of caching at the granularity of every unique combination of optional keys (which could lead to exponential memory growth), the new approach caches at the subject level and filters results in-memory, dramatically reducing memory consumption and improving cache efficiency. | Decision Management |
| INC-D34742 INC-D31071 INC-D34743 |
1009005 1008546 1010534 |
GOS performance profile download functionality restored | Attempting to download Globally Optimized Strategies (GOS) full performance profiles failed with the error message "Index -1 out of bounds for length 7136". CSV format downloads continued to work without issue. Investigation showed this was caused by the internal state of the execution profile data becoming corrupted under specific conditions. This has been resolved by refactoring the execution-tree nodes handling and adding internal structure validation so merged profiles stay consistent and serializable. | Decision Management |
| INC-D35993 | 1015025 | Improved Sub-When resolution for circumstanced rules | During rule execution, a Sub-When rule was being added to a circumstanced rule (CR) when pxInsName was only partially matched, causing Revision Integrity Enforcer (RIE) failure. This was due to partial pxInsName matching being accepted in Sub-When-to-CR resolution logic, and has been resolved by enforcing stricter full-identifier matching behavior in the Sub-When/CR resolution path so partial-name matches will no longer be treated as valid. | Decision Management |
| INC-D37353 | 1018342 | Corrected interaction partitioning | Interaction-history aggregation was becoming stuck. Investigation showed this was due to records being assigned an incorrect zero partition key, affecting downstream aggregation and suppression processing. To address this, interaction-history persistence will assign the correct partition key for aggregation and log when there is a mismatch. | Decision Management |
| INC-D37731 INC-D29801 |
1015053 1017650 |
Updated expression grammar | Expressions containing combined comparisons and logical operators were producing errors after an upgrade, and boolean properties were evaluating incorrectly. This occurred when using Ajax containers, and was a missed use case. To resolve this, the antlr grammar has been updated to support the affected expressions. | Decision Management |
| INC-D38585 | 1015824 | Prediction access restored for high-volume models | In high-volume Production/Simulation environments, predictions were intermittently failing to open in Prediction Studio and a java.lang.NumberFormatException was generated from pzGetModelPerformance. This was caused by accumulating pyResponseCount values which caused the Java int local parameter to overflow past Integer.MAX_VALUE (2,147,483,647). This has been resolved by updating the responseCount from int to double in Data-Decision-Prediction so large counts are processed correctly. | Decision Management |
| INC-D38615 | 1012613 | Reference tracker differential processing optimized to return targeted properties | ReferenceTracker.diff() operations were returning entire page contents instead of only referenced properties during HTML template streaming, resulting in excessive data volume when persisting shallow copies to database storage, unnecessary data serialization/deserialization, and larger payloads in Kafka streams. This was caused by overly broad property inclusion logic in the differential processing mechanism, and has been resolved by implementing precise property filtering to return only actually referenced data elements. | Decision Management |
| INC-D44590 | 1021181 | Corrected manifest status handling | Data ingestion was completing successfully and files were parsing correctly, but the manifest-loading activity was reporting failure. Investigation showed that the activity status was being set to failed without confirming that manifest loading had actually failed. To address this, the release will apply checks that set failure status only when manifest loading fails. | Decision Management |
| INC-D45360 | 1019513 | Warning logs sanitized | To improve security, warning logs will record only the outcome-time values during database-backed Interaction History processing and exclude the full interaction record. | Decision Management |
Low-Code Application Development
25.1.4 Resolved Issues for Low-Code Application Development
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-C55557 | 999509 | Email attachment issue resolved when using email draft saving | Issues were seen with email attachments for certain file types including Excel and MP4 files when saving draft emails through the Pega email bot. Investigation showed that when attachments were uploaded in the email composer and then saved as a draft, the attachment data was being partially cleared during the save process. As a result, the system tried to re-upload those attachments during the send process, but since they had already been saved to the external storage repository the duplicate upload caused an error and the send failed. To address this, an update has been made to prevent re-uploading attachments that are already stored in the repository, resolving the error and allowing emails with draft attachments to be sent successfully. | Low-code Application Development |
| INC-D12023 | 992309 | Inherited-rule rollback handling corrected | Rollback was leaving rules undeleted when they had been resolved through inheritance, causing the rule to remain available after the rollback operation. Investigation showed that RuleSaver.rollback() was deleting the resolved rule without confirming that it had been newly created for the current class, so inherited or reused rules were being handled incorrectly. To address this, rollback will delete the rule only when its owning class matches the current class, preventing inherited rule instances from being retained or incorrectly removed. | Low-code Application Development |
| INC-D12879 | 1007978 | App/Infinity Studio datatype deletion accuracy improved | Deleting one datatype incorrectly removed additional datatypes from the interface. This was caused by incorrect selection logic affecting multiple items, and has been resolved by updating the logic around how the target data object is resolved along with adjusting the underlying report/filter behavior. | Low-code Application Development |
| INC-D14440 | 999624 | Handling updated for unavailable SOAP services | A SOAP request to an unavailable service was returning an unexpected HTML error response. Previously, the exception path treated the missing service as a generic server error and generated a SOAP fault. To resolve this, an explicit HTTP 404 Not Found response will be returned with a clear message. | Low-code Application Development |
| INC-D14468 | 1001229 | Corrected session header handling | A SOAP connection was failing at runtime when session maintenance was enabled. Investigation showed that the transport headers were being cast to an outdated concrete type. To address this, the session cookie will be retrieved through the shared Map interface instead of relying on the concrete header class. | Low-code Application Development |
| INC-D18648 | 1008632 | JSON data transform class resolution corrected | JSON data transforms were not resolving to the correct circumstanced rules when called from REST services during case creation, causing incorrect rule selection. Investigation showed that the class context was not being properly maintained for JSON data transforms, and this has been corrected. | Low-code Application Development |
| INC-D20120 | 1002008 | New DSS keys for JFrog/Artifactory repository resiliency | File operations to JFrog repositories were failing with ""java.io.IOException: Pipe closed"" errors during file uploads, causing data flow interruptions and preventing successful file storage. Investigation showed connection timeouts and network interruptions were not being properly handled during repository operations. This has been resolved by implementing improved exception handling and an enhanced retry strategy for JFrog repository clients with configurable maximum retries configured through new DSS entries added to the Pega-IntegrationEngine repository: repository/jfrogMaxAttempts repository/jfrogInitialRetryDelayInMillis repository/jfrogMaxRetryDelayInMillis repository/jfrogBufferMemoryThresholdBytes |
Low-code Application Development |
| INC-D21220 INC-D26722 INC-D36733 |
1005443 1009244 1011271 |
File listener parsing errors resolved for structured data processing | After update, file listeners were stopping processing during structured data parsing after a variable number of records (typically 6-7 records) and throwing the error "com.pega.pegarules.pub.PRRuntimeException: Attempting to read more data than available on reader" at ParseStateImpl.parseCharsText. This has been addressed by updating ParseStateImpl.parseCharsText to replace the single reader.read(chars, 0, length) call with a new readFully(...) helper so it can correctly read character fields even when the underlying Reader returns partial reads. | Low-code Application Development |
| INC-D21299 INC-D28331 |
997158 1002429 |
JSON transformation with namespaces restored | JSON data transform mapping and deserialization was failing when array lists contained namespace-qualified declarations. This has been resolved by updating the JSON transformation logic context parsing to avoid splitting namespace-qualified / URL-like keys. | Low-code Application Development |
| INC-D22406 | 997482 | JSON string length constraints increased | REST connector operations were failing when processing JSON responses containing strings larger than 20MB, throwing StreamConstraintsException with the error "String value length (20000105) exceeds the maximum allowed (20000000)" during inbound JSON-to-clipboard mapping operations. This was due to Jackson library default constraints limiting string processing to 20MB. This has been resolved by increasing the StreamReadConstraints maximum string length limit to accommodate larger JSON payloads exceeding 20MB in ArrayList processing. | Low-code Application Development |
| INC-D22620 | 1004808 | Email listener message deletion resolved | Email listeners were experiencing intermittent failures when attempting to delete processed messages from Microsoft Exchange mailboxes through MS Graph API integration. The failures manifested as HTTP 404 "object not found" errors with specific error messages including "The specified object was not found in the store" and "The process failed to get the correct properties" appearing in logs with MSGraphEmailClient and ExceptionAlertResolver components. Investigation showed this was caused by Microsoft Graph changing underlying message item IDs during high mailbox activity or synchronization events, which invalidated previously retrieved message identifiers used for subsequent delete operations. This has been resolved by implementing the 'Prefer: IdType="ImmutableId"' request header to obtain stable message identifiers that persist across mailbox changes, ensuring reliable message deletion regardless of mailbox synchronization activities. | Low-code Application Development |
| INC-D22638 | 998077 | Data page source validation enhanced | Data pages with missing pyLoadActivity or pySourceWhen values were causing sources to be ignored during runtime initialization and execution. This was caused by insufficient validation during data page configuration and missing default conditions. To resolve this, an activity has been provided to identify, revalidate, and save impacted Data Pages where one of the configured sources is missing the pyLoadActivity value. | Low-code Application Development |
| INC-D23165 | 996472 | Connector wizard class naming compliance enforced | Dev Studio could not open integration classes created through the Connect REST wizard when class names exceeded 56 characters and the truncation process resulted in class segments beginning with digits. This was caused by the truncateByHashing method generating Java hashCode values that could create invalid class names which violated Pega's alphabetic character requirement for segment starts. This has been resolved by modifying the truncation logic to ensure all class segments begin with alphabetic characters. | Low-code Application Development |
| INC-D24582 INC-D35493 |
1002610 1018317 |
Search group column data isolated | Shared columns between multiple search groups were displaying the same entered values across all search group tables, causing data confusion when users performed searches with common column configurations. This was traced to the publish-subscribe mechanism not properly isolating column data between different search group contexts, and has been resolved by including view name as a key in the publish-subscribe mechanism to ensure proper data isolation between search groups. | Low-code Application Development |
| INC-D26237 | 1000539 | S3 file upload connection stability improved | Data flows were failing during S3 file uploads with "PRRuntimeException: Failed to close some of the writers" and "WriterClosingException: Failed to close writer" errors, specifically showing "java.io.IOException: Pipe closed" messages during file operations. Investigation showed connection interruptions were occurring during large file transfers to S3 repositories. This has been resolved by implementing improved connection management and retry logic for S3 operations o address socket exception handling and broken pipe recovery mechanisms. | Low-code Application Development |
| INC-D26597 | 1013996 | Ruleset placement corrected | Metadata rules were being created in the application’s top ruleset instead of the ruleset selected for a new data type. This was caused by the required ruleset context not being passed during metadata creation, and has been resolved with an update to ensure the data type creation flow will pass the ruleset version, name, and branch context so related rules are created in the selected ruleset. | Low-code Application Development |
| INC-D26613 | 1007047 | Workspace rule creation streamlined | Platform Designer Studio was incorrectly prompting users to manually enter ruleset and ruleset version information when creating new rules with workspace feature activated and all rulesets locked. This was caused by improper handling of workspace private branch assignments during rule creation, and has been resolved by implementing automatic assignment of rules to workspace private branches (ruleset version 01-01-01) without requiring manual input. | Low-code Application Development |
| INC-D27013 | 1009236 | Added handling for file attachment names with leading spaces | File attachments with leading space characters in their filenames were generating "file does not exist" errors when uploaded using the Select file button in Cosmos and UI Kit themes on Mac and Linux systems. Windows systems were unaffected due to OS filename restrictions. This was due to an updated library version which began internally trimming leading/trailing whitespace from the filename parsed out of the Content-Disposition header. To restore the earlier behavior, this has been resolved by adding FileUploadHandler.getUnTrimmedFileName(FileItem fileItem) to support files with leading space characters across all operating systems. | Low-code Application Development |
| INC-D27385 | 1007489 | Manifest repository delivery enabled for hybrid BIX outputs | When BIX extracts were written to local storage but manifests needed to go to a repository, manifests were not handled separately. This made hybrid output setups difficult and sometimes unreliable. To address this, logic has been added to treat manifest output independently: manifest files are staged in BIXTemp, zipped locally, then uploaded to the repository with consistent naming and better repository/cloud path handling. Zip creation and cleanup were also improved so repository uploads (including S3-backed flows) are more reliable. | Low-code Application Development |
| INC-D29725 | 1004032 | PDF generation performance improved for heavy data scenarios | PDF generation was experiencing performance issues when processing heavy data scenarios, particularly during invoice export operations. Investigation showed this was caused by PDFBox 3.0 using legacy mode instead of the more efficient JOIN_FORM_FIELDS_MODE during PDF append operations. This has been resolved by introducing configuration to use JOIN_FORM_FIELDS_MODE and suppressing redundant warning logs related to missing dummy font files to reduce log noise. | Low-code Application Development |
| INC-D29776 | 1005989 | DevStudio logging display updated | In order to prevent exposing internal system paths in diagnostic requests generated from the alerts view, the MyAlerts HTML rule has been updated to remove the logFile hidden field and change the displayed file link on the UI to show only the basename of the log path instead of the full path. | Low-code Application Development |
| INC-D33899 INC-D44397 |
1010266 1019453 |
FTP internal server connectivity enabled | After update, FTP connectivity to trusted internal server hostnames was being unexpectedly blocked with SSRF protection errors. This was a result of new Server-Side Request Forgery (SSRF) protection that blocked FTP/SFTP connections to internal or private IP addresses by default. To support this use, configurable prconfig allowlists have been added to enable sites with internal FTP/CMIS servers to bypass site-local SSRF blocking for trusted hosts while maintaining security protections for loopback and link-local addresses. | Low-code Application Development |
| INC-D34683 | 1009811 | JSON schema validation updated | After update, case creation via REST API was failing during schema validation with "validateJSONAgainstYAML method undefined" compilation errors. This has been resolved by updating to a newer networknt library to improve how YAML is validated, and adding robust support for validating JSON payloads against both JSON and YAML schemas in the AutomationUtils utility. | Low-code Application Development |
| INC-D35134 | 1011440 | Bulk processing assignment pagination display fixed | Pagination was not displaying in the pyBulkProcessingAssignDisplay section, preventing proper navigation through bulk assignment lists. The issue was caused by incorrect pagination placement/rendering logic in pyBulkProcessingAssignDisplay, which incorrectly added pygridpaginator to the table footer instead of the recommended header location. This has been resolved by moving the pagination component to the table header where it will execute properly and display at the top of the table. | Low-code Application Development |
| INC-D35359 | 1016134 | Grid results corrected | A grouped table was displaying duplicate or unexpected rows when navigating directly to a later page for the first time. This was traced to shared data sources that were retaining an inconsistent grid categorization state between the grouped and paginated views, and has been resolved by correcting the grid categorization state for shared data sources. | Low-code Application Development |
| INC-D36925 INC-D40977 |
1012798 1015915 |
File processing updated for non-standard streams and problematic input data | File listeners were failing to process some records after update. Investigation showed that short reads from streams were causing record-type parsing to be incomplete or incorrect, and NUL bytes in log fields were causing database persistence errors for log messages and stack traces. To address this, file processing has been updated to be more robust, handling has been added for partial reads, and log messages and stack traces are sanitized before persistence to prevent database errors caused by NUL bytes. | Low-code Application Development |
| INC-D7948 | 998059 | Azure archival size limitations removed | Case archival operations to Azure repositories were failing with "maximum size for put Blob is 256MB" errors when archiving cases containing large numbers of attachments and dependencies, specifically when using OAuth authentication with Data Lake Gen2/Blob storage configurations. Investigation showed this was caused by OAuth authentication using different libraries that incorrectly enforced the 256MB limitation during blob uploads. This has been resolved by implementing size-based upload logic that uses putMultipartBlob method for files exceeding 256MB and putBlob method for smaller files. | Low-code Application Development |
Mobile
25.1.4 Resolved Issues for Mobile
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-B25606 | 949716 | iOS location services configuration consistency restored | The iOS app configuration was incorrectly maintaining the "Enable constant tracking when app is offline-enabled" setting as true even after the parent "Enable geolocation tracking" option was disabled, leading to inconsistent location service behavior. Investigation showed the visibility condition was not properly clearing the dependent setting when the parent option was disabled, and this has been resolved by ensuring both location tracking properties are properly synchronized when geolocation tracking is disabled. | Mobile |
| INC-D14695 | 992583 | Offline data persistence improved for child page list operations | When working offline, clearing child page lists within parent page list rows and attempting to save changes resulted in the cleared child list data not being persisted despite the save operation appearing to complete successfully. This has been resolved by updating the serialization logic to prevent missing child-page placeholders when saving sparse pagelists offline, and ensuring the removal flows guard against missing/null resolved assignment or remove payloads. | Mobile |
| INC-D2050 | 988164 | Photo upload popup handling corrected for offline apps | Multiple attachment popups were appearing when uploading 2 or more photos/files using pxAttachContent control with action sets in offline-enabled applications. This has been resolved by adding a guard to prevent multiple attachment pickers from being launched during multi-file/photo uploads in the Hybrid Client attachment control. | Mobile |
| INC-D23964 INC-D33553 INC-D25664 |
1004341 1008467 1001775 |
Date/time handling updated for zh_TW (Taiwanese) and in_ID (Indonesian) locales | After migration to Cloud, entering a date/time value on mobile applications with Native Control enabled would cause the input to revert to the current date/time instead of preserving the user's entry when a Save action was configured on Change and the zh_TW (Taiwanese) or in_ID (Indonesian) locales were set. This has been resolved by updating the UI datepicker control handling in Offline mode for mobile applications to preserve meridiem labels (上午/下午) in offline mode via formatDateTime for zh_tw, and offline-gated support for localized meridiem in in_id (PAGI/SORE). Calendar time formatting has also been corrected for these locales by normalizing dot-separated time values and improving AM/PM display handling. | Mobile |
| INC-D29726 | 1006461 | Stream loading error resolved | Users were encountering "Failed to load stream" errors when attempting to create streams in the mobile application. This was caused by over-broad screen detection which incorrectly treated some non-worklist screens as WorkList WebView screens. To resolve this, an update has been made to better handle fast-loading pages by avoiding false Worklist detection on case pages, and filter empty offline reconciliation records. | Mobile |
| INC-D44678 | 1019612 | Corrected localized calendar handling | Localized time entries in the offline mobile calendar were causing the interface to freeze. To address this, the handling of time values with dot separators (e.g., "09.09") for certain locales has been improved by refactoring and centralizing the logic for normalizing time separators, ensuring more robust parsing | Mobile |
Project Delivery
25.1.4 Resolved Issues for Project Delivery
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-D26477 | 1002789 | Documentation updated for post-Hazelcast clustering settings | The documentation for configuring a prpcUtils streaming service has been updated to clarify the setting configurations for connecting to an externalized Kafka streaming service. This configuration is necessary to override the default stream provider settings and ensure that clustering continues to work in a client-managed cloud deployment after Hazelcast removal. | Project Delivery |
Reporting
25.1.4 Resolved Issues for Reporting
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-D16200 | 1003092 | Handling added for semantic search response attributes containing empty values | The vector store and buddy ingestions APIs allow ingestion of empty attributes, but Java API written to get semantic search results with response attributes has validation added to throw an error when response attributes do not have a value. This was causing semantic search to fail in this scenario. To resolve this, validation will now allow empty attribute values while preserving valid search results. | Reporting |
| INC-D16855 | 992860 | Fallback handling added for search date filtering timezone alignment | Case search filters using the "Yesterday" selection were incorrectly displaying cases updated on the current day. This was caused by a null on the SRS dispatch thread which caused ZonedDateTime.now() to fall back back to the JVM default zone (UTC), and has been resolved by updating the handling for the search date filtering and including a timeForThread function that re-zones the current instant to the thread's timezone before computing interval boundaries. | Reporting |
| INC-D17133 INC-D27602 INC-D26104 INC-D29756 INC-D24802 INC-D36327 |
950983 993651 1003029 1003736 1010506 1016227 1017625 |
Character encoding corrected for Word document generation | When using the standard document generation feature with Microsoft Word templates, Latin and technical characters such as the micro symbol (µ) were appearing incorrectly, with values like "20µm-500µm" being rendered as "20µm-500µm" in the generated output. Investigation showed this was caused by character encoding defects during the processing stage, specifically affecting Section tags rather than P tags, and creating additional complications with table of contents duplication when TOC elements appeared outside sdtContent containers. This has been resolved by preserving non-ASCII characters as authored along with making the DOCX generator more Word-template-aware. Instead of treating TOC or field content too broadly, it now distinguishes real TOC fields from plain text, preserves template TOCs for Word to refresh, and fixes field/page-break handling so generated documents keep the intended structure. | Reporting |
| INC-D18339 | 993112 | Added handling to avoid Oracle database query limit | After update, report definitions were failing with ORA-01795 error message "maximum number of expressions in a list is 1000". This was caused by Oracle database queries exceeding the 1000 expression limit when processing large datasets, and has been addressed by implementing query expression splitting logic that automatically divides large query expressions into smaller chunks when they exceed Oracle's 1000-item limit. | Reporting |
| INC-D19802 | 1004826 | Insight column filter scrollbar display corrected | Column filters in insights were displaying two nested vertical scrollbars at 100% zoom. This has been resolved with an update to the SelectFilter dialog layout to prevent nested/double scrollbars by constraining the dialog content with a flex “height chain” so the checkbox list is the only element that scrolls, instead of both parent and child containers competing for overflow. | Reporting |
| INC-D19967 INC-D35580 INC-D39935 INC-D42836 |
1006046 1010183 1015513 1017212 |
InvalidReferenceException resolved for report definitions with external table mappings | Report definitions were failing with InvalidReferenceException ".pxObjClass Unexposed properties cannot be selected for classes mapped to external tables" when using a specific class hierarchy involving data classes mapped as parents of abstract classes with subclasses containing report definitions, particularly after creating Access Control Policies on the parent class. This was an inadvertent side effect of work done on attribute-based access control functionality for complex inheritance hierarchies, has been resolved by correcting a property population with a stale/incorrect class reference that interfered with the SQL generation path for secured properties. | Reporting |
| INC-D20438 | 996598 | Scheduled insights date filtering accuracy restored | Scheduled insight exports with relative date filters like "Current day" and "Last 1 day" were returning identical datasets based on the schedule creation date rather than the current execution date. This was caused by the system using static date references from schedule creation instead of dynamic date calculation at execution time, and has been corrected. | Reporting |
| INC-D20561 | 1000662 | BIX metadata provided for improved validation/troubleshooting | When publishing CDC data to external Kafka, metadata details were not surfaced, reducing visibility into published event context. To address this, metadata details are now available as part of the external Kafka publish flow for traceability and downstream interpretation. | Reporting |
| INC-D31507 | 1014828 | Chart drill-down behavior aligned | A column chart drill-down action was producing an empty breadcrumb when group headings were disabled and a filter was open. This was caused by chart drill-down remaining enabled while the corresponding table interaction was disabled. To address this, chart drill-down will be disabled while the filter is open to ensure consistent behavior. | Reporting |
| INC-D35499 | 1013075 | Corrected insight duplication | Duplicate insight records were appearing for the same case when multiple child cases and promoted association filters were involved. This has been addressed with an update to avoid passing Promoted filter fields in select if the condition is empty. |
Reporting |
Security
25.1.4 Resolved Issues for Security
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-C54382 | 1013510 | Corrected logout routing | Logout was redirecting to a success page instead of the login screen after a Basic Access Group timeout. The issue was traced to a missing activity in the logout decision/evaluation flow, and has been resolved by restoring the missing activity so logout returns to the login screen as expected. | Security |
| INC-C58612 | 991699 | Security checklist verification handling updated in Deployment Manager | The verify security checklist task in Deployment Manager was failing with the error "Unable to fetch task status due to invalid configuration. Unable to derive access group for application" when the system was configured as Production-5 level. This was caused by case-sensitive application name comparison logic in the security task manager that failed to properly match application names with their corresponding access groups, and has been resolved by implementing case-insensitive application name comparison. | Security |
| INC-D12478 | 993118 | Corrected insight scheduling | Scheduled insight reports were not generating their email attachments when access policies were configured. This was traced to the policy evaluation using a default class instead of the class associated with the insight, and has been corrected by removing the hardcoded report class and using a dynamic value instead. | Security |
| INC-D13958 | 994324 | Case note handling updated | Cross-site scripting protections have been updated for case notes. | Security |
| INC-D15457 | 997634 | Access role read rules configuration corrected | Access Role Name configuration was failing when attempting to modify Read Rules settings, displaying errors when selecting or creating when rules, with the system incorrectly listing and creating rules in the ARO class instead of the proper Rule- class. This has been resolved by correcting the class determination logic to properly target Rule- classes for when rule operations. | Security |
| INC-D15835 | 1005834 | Corrected Content security policy relogin handling | SAML authentication environments with disabled Unsafe Inline and Unsafe Eval in Content Security Policies were experiencing non-responsive relogin popups in Constellation portals, requiring manual intervention to proceed after token expiration. This was caused by the relogin screen using Traditional UI portal CSP settings that blocked required JavaScript execution. This has been resolved by updating the relogin mechanism to properly handle CSP restrictions while maintaining security compliance. | Security |
| INC-D15898 | 997350 | Rich Text Editor security updated | Cross-site scripting protections have been updated for CKEditor. | Security |
| INC-D16199 | 996640 | Case ID security updated | Cross-site scripting (XSS) protections have been updated for case ID. | Security |
| INC-D16804 | 1008637 | Application checklist guide generation stabilized | Application checklist guides in Dev Studio were failing to display properly after application version upgrades, showing identical guide names and generating null pointer exceptions with the error "Cannot invoke com.pega.pegarules.pub.clipboard.ClipboardPage.getProperty(String) because currentRulePage is null". This was caused by improper rule page handling during security analysis for checked-out rules, and has been resolved by implementing proper null checking and page validation in the security analysis framework. | Security |
| INC-D17662 | 994824 | Work link email access authentication fixed | After update, work links received in emails were returning 403 Forbidden errors which prevented users from accessing cases directly from email notifications. The error message "Unauthorized request detected: pyActivity is outside Encrypted parameter" was generated. This was caused by changes in the URL encryption validation logic that incorrectly flagged legitimate work link requests as unauthorized. To address this, the pxWorkLink rule and associated encryption validation have been updated to properly handle encrypted URL parameters while maintaining security requirements. | Security |
| INC-D18445 | 993614 | Report browser security updated | Cross-site scripting protections have been updated for Report Browser. | Security |
| INC-D18613 | 996645 | Security updated for Infinity Studio | Server side input validation in Infinity Studio has been updated for improved security. | Security |
| INC-D1873 | 993296 | Screen reader accessibility for empty values improved | Screen readers were announcing "n dash n dash" instead of "no value" when navigating to text fields populated by declare expressions that returned empty or null values. This has been resolved by implementing proper "no value" text rendering for screen reader compatibility. | Security |
| INC-D19874 INC-D27916 |
997274 1002684 |
Security improved for URLs | Cross-site scripting protections have been updated for hashed URLs. | Security |
| INC-D20018 | 1003562 | Improved security for Infinity Studio / App Studio | Cross-site scripting protections have been updated for Infinity Studio / App Studio. | Security |
| INC-D20715 | 997879 | Navigation tree accessibility improved | Screen reader tools were announcing "Blank" when navigating through navigation tree items that contained person image icons. This was caused by missing aria-hidden attributes on decorative image elements, and has been resolved by adding aria-hidden="true" attributes to person image icons in the generateCellContent function. | Security |
| INC-D20802 | 999972 | OAuth token authentication accuracy improved for duplicate client identifiers | After update or after decommissioning Hazelcast caching and clustering functionality, OAuth token authorization errors appeared. This was caused by the tokens being stored/looked up by mOperatorId instead of the resource owner's username, causing token collisions, and was due to centralized token caching changing from a shared global cache to a node-local cache. This led to issues when multiple users shared the same client ID, which is against best practices. To resolve this, for ROPC grant type only, the resolved resource owner username will use pyUserIdentifier instead of the Pega operator ID. | Security |
| INC-D21294 | 1007817 | Blended UI action permissions stabilized | Applications were generating "action is not allowed" exceptions when users were working on cases in blended UI environments. This was traced to thread selection during token reissue: in concurrent request scenarios, the refresh token process could return an in-flight case-processing thread rather than the portal’s STANDARD thread, causing UI actions to be rejected as being outside the current transaction. To resolve this, the refresh-token reissue flow has been updated to always use the dedicated STANDARD thread so transaction-id tracking stays isolated to the correct thread and concurrent case-processing activity no longer interferes with portal UI state. | Security |
| INC-D21305 | 1005169 | Harness footer accessibility corrected | The aria-label attribute was incorrectly persisting on the footer element within the Perform Harness when Display options were configured to show both Header and Footer. This occurred because the template_workarea.js file was not properly removing the aria-label from the footer element, and has been corrected. | Security |
| INC-D21320 | 994936 | BIX file generation for complex data structures corrected | BIX extracts were failing to generate files when processing complex embedded data pages with rarely-populated referenced pages, throwing StringIndexOutOfBoundsException errors with "begin 0, end -1, length 19" during XML generation. This was caused by improper parsing logic in BIXXMLUtils.getKeyNameForTheProperty when handling wildcard properties in complex embedded data structures, and has been resolved by implementing enhanced parsing logic for deep structured embedded properties referenced through property-ref to external embedded properties. | Security |
| INC-D21743 | 999718 | URL tampering protections updated | The validation handling for URL parameters has been updated for improved security. | Security |
| INC-D22043 | 1001001 | Improved editor announcements | Screen readers were announcing duplicate labels and an unnecessary frame role when focusing Rich Text Editor fields. This has been resolved by changing the role to textbox and setting the title to Rich Text Editor. | Security |
| INC-D23451 | 1002159 | Table group expand/collapse functionality restored | Table grid expand/collapse controls were not functioning correctly when Group By functionality was enabled, with the "Collapse All" option unexpectedly expanding previously collapsed groups instead of collapsing all groups. Users were also experiencing accessibility issues with incorrect aria-label updates and visual problems with row overlays such as clicking on a row causing the row value to become hidden due to an additional white-colored overlay/background being applied. This was caused by improper state management in the table grouping logic and missing accessibility attribute updates, and has been resolved by fixing the expand/collapse state handling and correcting the accessibility attributes for grouped table rows. | Security |
| INC-D23970 | 1005763 | Password change method security enforced | HTTP method validation has been updated to ensure password change operations only accept POST requests. | Security |
| INC-D24187 | 1001392 | Nested menu navigation improved | Applications were experiencing difficulty viewing the last option while scrolling in nested menus. Investigation showed deeply nested submenus with large numbers of menu items could extend beyond the viewport, preventing access to the last menu options. To resolve this, submenu positioning and height calculation logic have been updated to respect available viewport space and allow full access to all menu items, and the keyboard menu focus management logic has been adjusted to maintain correct tabindex during keyboard navigation. | Security |
| INC-D24287 | 1002152 | Modal dialog accessibility corrected for zoom | Applications were experiencing focus navigation issues when using tab controls in modal dialogs at 200% zoom or above, where focus would shift to background elements instead of remaining within the modal dialog. This was caused by improper focus management in zoomed modal dialog implementations, and has been corrected. | Security |
| INC-D24517 | 1001715 | Application alias validation updated | Applications continued to function when users manually changed the application alias in the URL and updated cookie paths. This has been resolved by implementing proper validation checks for the app alias with access group upon change. | Security |
| INC-D27218 | 1007270 | Table empty value display restored | After update, empty text field values in configured tables were displaying as blank spaces instead of the expected "--" placeholder that was shown in previous versions. This was an intentional change made in an earlier release where "--" rendering was moved from DOM to CSS for accessibility reasons. To address this, the change has now has been modified by providing fine-tuned CSS changes to restore the "--" display for empty values while maintaining accessibility compliance. | Security |
| INC-D28118 | 1009532 | JWT Bearer grant type authentication restored | JWT Bearer grant type connectors were failing with "Unable to fetch token page" errors, preventing SSO-based data page connections from functioning properly. Investigation showed this was caused by OAuth2 token retrieval issues affecting existing authentication profiles. This has been resolved by enhancing OAuth2 token retrieval with database fallback mechanisms to ensure reliable token access. | Security |
| INC-D29649 INC-D31577 INC-D32814 |
1005424 1006050 1006699 1008458 |
OIDC authorization parameter encoding corrected | OIDC authentication was failing after platform upgrades with the error message "error=invalid_request&error_description=unable+to+parse+claims+parameter&state" appearing during the authorization step. This was traced to the pxCreateAuthURL activity applying double encoding to OAuth2 parameters, and has been resolved by correcting the encoding logic to apply only standard URL encoding to OAuth2 parameters, eliminating the redundant HTML encoding step that was corrupting the authorization URLs. | Security |
| INC-D29776 | 1006539 | Secured log path display | In order to prevent exposing internal system paths in diagnostic requests generated from the alerts view, the LogFileDownload HTML rule has been updated to display only the log filename. | Security |
| INC-D30018 INC-D41186 |
1007294 1017339 |
Password change flags properly reset after forgot password flow | Users who reset passwords through the Forgot Password functionality were being prompted to change their password again upon first login. Investigation showed that when the 'Force password change on next login' flag was enabled on operator profiles, the system was setting pyChangePassword and pyChangePasswordOnNextLogin flags to True, but after users completed password changes via the Forgot Password flow the flags were not reset to False. This was caused by incorrect state handling in the Forgot Password flow, and has been resolved by implementing proper flag clearing logic in the Security Policies component. | Security |
| INC-D30168 | 1005674 | Accessibility labels maintained after section refresh for AnyPicker controls | The clear icon in AnyPicker controls was losing its aria-label attribute following section refresh actions. This was traced to incomplete DOM reconstruction during the refresh process, and has been resolved by adding dynamic aria-label generation to the clear icon to ensure consistent accessibility information. | Security |
| INC-D30362 | 1009150 | Hierarchical table link outline spacing improved | When tab focus was applied to link controls in hierarchical tables, a solid outline was appearing with insufficient padding around the content that caused values to appear cramped. This has been resolved by adjusting the outline spacing and padding properties to improve accessibility and visual appearance for focused link elements in hierarchical tables. | Security |
| INC-D30917 | 1006918 | Security updated for SVG file uploads | SVG content validation and sanitization has been updated for improved security. | Security |
| INC-D31125 | 1010498 | Security updated for multi-select control | Cross-site scripting (XSS) protections have been updated for the multi-select control. | Security |
| INC-D31718 | 1017699 | Enabled KMS data page preloading | Incremental indexing was failing on a search node while attempting to load an encrypted indexed instance, although equivalent processing was succeeding on other node types. Investigation showed that declarative processing was being disabled before a required KMS data page could load on a cold search node. To address this, a DSS has been added which allows KMS Data Page preloading before IncrementalIndexThreadModificationHelper disables declarative processing. The behavior applies only to the incremental-idx flow: non-incremental, attachment, bulk, purge, and default request flows remain unchanged. Ruleset: Pega-SearchEngine DSS: indexer/srs/incremental/kmsDataPagesToPreload Example: D_LoadKeyFromProviderA,D_LoadKeyFromProviderB Default: Blank (no preloading) |
Security |
| INC-D32618 | 1016003 | Corrected autocomplete character rendering | Special characters were being displayed as ASCII codes in autocomplete multiselect descriptions. Investigation showed that an additional client-side cross-scripting filter was altering already-sanitized values containing certain terms. To address this, the rendering logic will preserve sanitized special characters without applying the redundant filtering step. | Security |
| INC-D33338 | 1012083 | ABAC condition evaluation improved for blank properties | Attribute-Based Access Control when conditions were not evaluating correctly for records with blank or null property values, causing inconsistent masking behavior between report definitions and individual record access. This has been resolved by updating the query generation to include an explicit IS NOT NULL guard for every field used in ABAC conditions, except when the condition itself is IS NULL or IS NOT NULL. | Security |
| INC-D34195 INC-D30034 INC-D31675 |
1009123 1009097 1009748 |
Support added for multi-node session management | When maximum concurrent session limit was set to 1 for an operator, logging into a second node (cross-node) with the same operator ID did not invalidate the first session. Both sessions remained active and fully functional simultaneously. This was due to the concurrent session enforcement mechanism having been designed only for same-node scenarios where both sessions share the same server memory. To resolve this, cross-node session invalidation mechanisms have been implemented that update the shared database and ensure sessions are properly terminated when operators log into different nodes. | Security |
| INC-D34338 | 1016164 | Returned modal focus | Focus was not returning to the edit control after a Case Preview modal was closed. This has been resolved with an update to ensure the modal behavior will return focus to the control that opened it. | Security |
| INC-D34469 | 1009766 | DPoP authentication reliability improved for multi-node environments | DPoP-enabled authentication profiles were experiencing intermittent failures when accessing APIs, particularly when UserInfo requests were processed on different nodes or threads from where tokens were originally issued. Investigation showed this was caused by DPoP nonce caching issues and keypair ID lookup problems across pooled threads and distributed nodes. This has been resolved by updating the userinfo endpoint API call to ensure it uses the same keypair which was used for the access endpoint invocation. | Security |
| INC-D34784 | 1022382 | Improved OAuth2 token handling | Outbound REST integrations were failing with HTTP 429 responses after federated authentication was enabled because token requests were exceeding the configured rate limit. Investigation showed that concurrent client-credentials requests were not coordinating access-token retrieval. To address this, OAuth2 database-lock handling will be extended for rate-limit responses. | Security |
| INC-D34831 INC-D36534 |
1012582 1016449 |
Stabilized token refresh | Concurrent OAuth2/OIDC token refreshes could intermittently fail with authorization-style errors when multiple requests attempted to use the same refresh token at once. This has been resolved by serializing refresh at the DB/sys-lock layer (per cache/token context), so one request performs the refresh while others wait for the updated token. For node-local cache deployments, the refreshed token is now propagated through cache-sync payload sharing so peer nodes can update local cache without reusing stale refresh state. The change also preserves existing provider-token handling and non-OIDC OAuth grant behavior. Where enabled, replacement of older matching OIDC login-token rows is applied (configurable via security/oauth2/oidc/replaceexistinglogintoken) to reduce stale-row-related authorization/expired-style failures. | Security |
| INC-D34857 | 1008860 | Log filter security improved | Log filtering has been updated to ensure that credential values are not included in debug output. | Security |
| INC-D34878 | 1012035 | Report definition query generation fixed for descendant classes | Report definitions were failing with PostgreSQL SQLState 42703 errors when using "Convert Time Units" function aliases on decimal fields from descendant classes mapped to different tables. This has been resolved by correcting the SQL generation logic to ensure proper column reference alignment between inner and outer queries when processing descendant class data with function aliases. | Security |
| INC-D34893 | 1009664 | Accessibility corrected for progress loading | Screen readers were announcing a "progressbar" for the loader div regardless of loading state. This was caused by incorrect ARIA role assignment in the AnyPicker control template, and has been resolved by removing the static role from the template and dynamically setting/resetting it in the JavaScript control, ensuring screen readers comply with W3C HTML-ARIA standards and correctly announce loading status based on actual UI state. | Security |
| INC-D35545 | 1011674 | Keyboard navigation improved for success dialogs | Success banner dialogs were not properly announcing the close button to assistive technologies during keyboard navigation. This was caused by improper focus management in the success banner dialog component, and has been resolved. | Security |
| INC-D35623 | 1011399 | Kafka OAuth token retrieval stabilized under concurrent load | Applications were experiencing OAuth token retrieval failures when processing concurrent partition and case loads in Kafka streaming applications integrated with Confluent Cloud, encountering repeated "Unable to retrieve the token" messages from StreamOAuthBearerCallbackHandler despite OAuth tokens being issued successfully. Investigation showed this was caused by IDP rate-limiting triggered by HTTP 429 responses when multiple KafkaConsumer instances simultaneously initiated SASL/OAUTHBEARER handshakes, overwhelming the identity provider with concurrent token requests. This has been resolved by adding JVM-wide token caching, proactive refresh, and graceful fallback when the identity provider rate-limits token requests. | Security |
| INC-D35629 | 1012654 | Production alert security updated | The generation process for PEGA0117 alerts has been updated to ensure PII data is correctly suppressed. | Security |
| INC-D35741 | 1014017 | Report filter display formatting improved | Report definition filters were displaying technical function names rather than the expected localized captions. This has been resolved by modifying the control logic to properly display localized captions and creating a new control pzGetLocalizedValueForReports in the pzEditSingleFilter section to ensure consistent filter display formatting. | Security |
| INC-D36439 | 1016395 | Improved SSO attribute handling | Some SSO sign-ins were intermittently creating operator records without names, while other profile attributes were populated correctly. Investigation showed that during OIDC SSO, stale cached D_pzSSOAttributes instances could be reused across authentications, causing inconsistent attributes to be sent by the OIDC identity provider in tokens/userinfo. To address this, all existing SSO attribute data page instances will be cleared before creating fresh data. | Security |
| INC-D36943 | 1011627 | OAuth toggle label length constrained | Installation of new Pega instances was failing during the data loading phase when attempting to save the OAuth security toggle with the error "String or binary data would be truncated in table 'pegadata.pr_data_toggle', column 'pyLabel'. Truncated value: 'This toggle enables next generation OAuth security capabilitie'." Investigation showed this was caused by the pyLabel column having insufficient length (64 characters) to accommodate the full OAuth toggle description which required 65 characters. This has been resolved with an update to constrain the description/label value to ≤64 characters. | Security |
| INC-D37436 | 1018429 | Improved validation focus handling | Keyboard focus was remaining on the action area instead of moving to fields with validation errors. This was caused by focus logic that did not correctly account for required fields. To address this, validation focus handling will allow focus to move to the affected field while preserving initial focus behavior. | Security |
| INC-D37524 | 1016103 | Corrected OTP error handling | One-Time Password (OTP) requests were returning a success status when email delivery had failed. Investigation showed that email-processing errors were not routing execution away from the success path, and this has been corrected. | Security |
| INC-D37752 | 1013029 | OIDC logout flow fixed with URL encryption | Authentication timeout scenarios were failing to properly logout users when both URL encryption and obfuscated URL submission were enabled, resulting in HTTP 400 Bad Request errors instead of successful logout. Investigation showed this was caused by PRErrorResponseBuilder.java appending logout parameters as plain text without accounting for URL encryption requirements. This has been resolved. | Security |
| INC-D37893 | 1015331 | Report fields correctly filtered | An automatically included row-header field was appearing in report column controls even when it had not been configured. Investigation showed that metadata fields were being exposed without checking whether they were authored columns. To address this, report controls will display the field only when it has been explicitly configured. | Security |
| INC-D38392 | 1017573 | Special characters displayed correctly in labels | Special characters in pop-up flow action labels were being displayed as encoded numeric values when a flexible modal template was used. This was caused by modal title handling encoding the label content incorrectly while applying XSS protection, and has been corrected. | Security |
| INC-D38747 | 1015481 | Remote case context retained | A remote case was presenting without its expected case label. This was traced to the active case context not having the necessary identifying data to retain the web mashup thread name through authentication, and was caused by thread-name parsing adding an unintended trailing slash. This has been resolved by preserving the intended thread name and retaining it across OIDC authentication. | Security |
| INC-D38999 | 1022246 | Updated security for TinyMCE | Security protections have been updated for TinyMCE. | Security |
| INC-D40406 | 1017930 | Corrected new operator event logging | Previously, creating a new Operator ID could be logged as if it were an update to an existing operator. This was caused by the creation metadata being present before the persistent key was assigned, causing the operator to be treated as pre-existing. This has been corrected, and a security event will be logged for operator creation with the event type "New Operator Created". | Security |
| INC-D42126 INC-D35863 |
1017839 1018645 |
HSTS headers correctly applied | Security scans were showing that HSTS headers were missing from document redirects while appearing on other response types. This was caused by redirect responses being committed before the configured response-header processing ran, and has been addressed by ensuring response-header processing will apply HSTS headers to redirect responses as well. | Security |
| INC-D42282 | 1019629 | Cross-site scripting protections updated for response | Security has been updated for the session-return response. | Security |
| INC-D42402 | 1018455 | Improved related-cases accessibility | Screen readers were not announcing the settings control in the Related Cases section. This has been resolved by adding helper text to identify the button for assistive technologies. | Security |
| INC-D43330 | 1021428 | Security update for Java usage | Java injection detection and enforcement have been updated to improve security against unsafe activities. | Security |
| INC-D43728 | 1018277 | Corrected portal layering | The navigation collapse control on the Insights landing page of the Theme Cosmos portal was becoming overlapped when returning to the "Explore Data" page. This was caused by portal layering conflicts involving the left navigation and modal elements, and has been resolved by correcting the styling and z-index handling. | Security |
| INC-D43750 INC-D47961 |
1018879 1022503 |
Updated security libraries | The DOMpurify and markdown-it libraries have been updated. | Security |
System Administration
25.1.4 Resolved Issues for System Administration
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-C58146 | 973649 | Portal routing made more robust | The handling for portal routing has been updated to ensure users are directed to their Access Group’s default portal, with a fallback to the standard portal when no default is set. | System Administration |
| INC-D11117 | 998761 | Skin Preview diagnostic logging added | In order to assist with issues using Skin Preview in Dev Studio, diagnostic loggers have been added to capture ruleset and ruleset version details along with validation to check for null or blank values in both. | System Administration |
| INC-D11498 | 1003414 | Debug logging accuracy improved | The LockManagerImpl.expireRequestorLocks() method was consistently printing 0 in debug logs regardless of actual expired locks, making troubleshooting difficult when invoking the getDatabase().getLockManager().expireRequestorLocks() API. This was caused by incorrect logging implementation in the lock manager. and has been resolved. | System Administration |
| INC-D12574 | 992758 | Corrected Rich Text Editor image source attribution loss | Images added to Rich Text Editor content were losing their src attributes when DOM purification was applied, resulting in broken image references where became after source editing. This was a missed use case in the updated DOM purification feature implementation, and has been corrected. | System Administration |
| INC-D12711 | 992763 | Lock handling in modal workflows corrected | Users were receiving "You have lost the lock" errors when submitting local actions on work objects launched in modals from tables, despite holding valid locks. This was occurring due to erroneous LockInfo page creation when Obj-Open-By-Handle performed extra Delete and Insert operations on pr_sys_locks, and has been resolved by correcting the lock handling mechanism to prevent erroneous lock state modifications. | System Administration |
| INC-D15390 | 986167 | Error message improved for search fuzziness parameter validation | Failed Fuzzy searches did not have helpful error messages when incorrect parameters were entered. This has been addressed by updating the description of the pyFuzziness parameter with the values allowed: AUTO, 0, 1 and 2. | System Administration |
| INC-D17999 | 992676 | "#resolvedissues note: | Operator validation error persistence resolved Operator ID records with custom property validation were experiencing persistent validation errors where subsequent save attempts continued to fail with "page is not valid" messages even after correcting the property values that initially caused validation failures. This was traced to validation errors not being properly cleared from the page history data after successful property corrections, and has been resolved by updating the operator save process to properly clear validation error history when property values are corrected and validation passes. |
System Administration |
| INC-D18549 | 997914 | Text input maxlength validation improved | Text input controls were allowing users to exceed the configured maxlength limit when typing quickly and pressing tab before composition events triggered. This was caused by maxlength validation only occurring on composition end or keyup events, missing edge cases with rapid input. This has been resolved by adding maxlength validation on blur events as a failsafe mechanism. | System Administration |
| INC-D20318 | 1000055 | Queue processor logging noise reduced | Queue processors were generating excessive error messages such as ""Threads mismatch null"" and ""Requestor thread is null. Recover from last usage"" that were flooding Splunk logs without causing functional impact. Investigation showed these messages occurred during normal queue processor operations but provided no actionable information. This has been resolved by updating the log statement to debug to suppress these non-functional error messages. | System Administration |
| INC-D24523 INC-D34219 |
1006332 1013301 |
Job scheduler graceful shutdown improved | Job schedulers were being terminated prematurely during Cloud Kubernetes cluster restarts, causing interruption of running jobs that were expected to complete before restart. This has been resolved by implementing proper graceful shutdown handling that allows sufficient time for job schedulers to complete their processing before node termination. | System Administration |
| INC-D2543 | 997855 | Kafka credential security enhanced with vault integration | HashiCorp Vault support has been integrated into the Stream Dataset feature to ensure sensitive authentication information remains encrypted throughout the deployment lifecycle. | System Administration |
| INC-D25431 | 1005581 | Decision table import validation updated | Applications could corrupt decision tables when importing modified Excel files with deleted 'if' statement rows, causing runtime issues due to different page list sizes without showing import or save errors. This was caused by insufficient validation during the import process when "allowed to return value" and "Evaluate all" rows were unchecked. This has been resolved by implementing proper validation checks during decision table import operations. | System Administration |
| INC-D27614 | 1003517 | Email notes count display corrected | When working with email interactions, the private notes count displayed in the email interaction header was not updating after posting new private notes through the notebook panel and required a manual refresh to display correctly. This was traced to the notebook panel not triggering the header count refresh when notes were added, and has been resolved by implementing automatic count updates when the notebook panel is closed after adding notes. | System Administration |
| INC-D34910 | 1010716 | Corrected Decision table import operator override | Decision table imports were incorrectly overriding result column operators to '=' when importing tables with 'Evaluate all rows' enabled and operators other than '=', such as '+='. This was caused by incorrect logic in DecisionTableWorkbenchConverter.java that used '>1' instead of '>2' in the condition check, and has been resolved by correcting the condition logic to prevent unintended operator modification during import operations. | System Administration |
| INC-D35152 | 1009071 | Legacy model aspect casting issue fixed | Multiple application actions were generating ClassCastException errors with the message "class com.pega.platform.clipboard.adapters.internal.LegacyPageAdapter cannot be cast to class com.pega.pegarules.data.internal.clipboard.ClipboardPageBase" after update. This was caused by incompatible class casting in the LegacyModelAspectInvokableRuleContainer.invoke method, and has been resolved by adding a safeguard to prevent ClassCastException when both the Tracer tool and the ReferencePropertyLink debug logger are enabled. | System Administration |
| INC-D39649 | 1015925 | Corrected status truncation | Long status values were being displayed without ellipses in the Summary panel, making truncated content unclear. Investigation showed that status properties were not using the same truncation handling as other property types. To address this, the summary display will apply consistent ellipsis handling to truncated status values. | System Administration |
| INC-D40505 INC-D47124 |
1015942 1021108 |
S3 retry stability improved for large file uploads | Intermittent S3 Identity Federation (IDF) authentication failures were occurring during upload retry processing of large files. This was traced to the retry-time credential/session refresh executing on the BlobWriter worker thread without valid context, and has been resolved with an update to capture the caller PRThread at stream creation, improve retry observability, and update the handling for worker-thread context cleanup/reuse, non-expired-token error propagation, and multipart upload flow. | System Administration |
| INC-D41801 | 1017477 | Column-drop safeguards strengthened | After update, data schema columns were being dropped during RAP import despite automatic schema changes being disabled. Investigation showed this was caused by a process bypassing the auto-schema-change setting check. To address this, an additional gate has been added which will cause the deleteColumns API to fail if automatic schema changes are disabled. If this is triggered, a DatabaseException will be logged with searchable text “Automatic schema changes are disabled”. | System Administration |
| INC-D42741 | 1019107 | Corrected database log exception | Database configuration processing was raising an exception when debug logging was enabled. Investigation showed that a formatted log message was missing an argument for one of its placeholders. To address this, the log call has been updated to pass both expected values (database instance and datastore type). | System Administration |
| INC-D42885 | 1016937 | Added check for library protections | After update, the email listener was able to read incoming emails but failed to create triage cases. This was traced to a java.lang.ClassNotFoundException originating from the SentenceDetectorMesh component in the NLP/sentence detector component, and was caused by a hotfix having been installed which included an older version of the NLP library. To address this, an additional overloaded-method check has been included in the SentenceDetectorMesh activity. | System Administration |
| INC-D43032 | 1018185 | Improved queue processor publishing | Queue processor information was only partially published when one processor lacked its associated data-flow configuration. This was traced to an exception from the data-flow layer that was stopping processing for all remaining queue processors. To resolve this, exception handling has been added which will allow processing to continue when an individual queue processor cannot provide its information. | System Administration |
| INC-D43071 | 1021040 | Added handling for queue processor exception | Delayed queue processing remained in progress and was no longer handling records after a brief database or thread interruption. Investigation showed that an unexpected runtime failure during item cleanup left an item orphaned and kept the processing loop waiting indefinitely. This has been resolved by adding updating the exception handling. | System Administration |
| INC-D43655 | 1021369 | Expanded Cloud storage metric controls | High memory utilization was seen due to the CaptureInteractionHistoryStorageDetails activity accumulating data pages. Investigation showed that the SkipS3MetricsCollection control was only covering cloud file storage metrics. To address this, the control will be extended to all related cloud storage metric activities, including interaction history, explainability extract, action analysis, and overall cloud file storage to prevent unnecessary accumulation and reduce memory usage. | System Administration |
| INC-D43709 | 1017774 | Restrictive Kafka messaging topic naming supported for stricter ACL alignment | Kafka stream creation, publishing, subscription, and OAuth2 cache synchronization were failing or being blocked in environments enforcing restrictive Kafka ACL naming rules because internal topic names included uppercase letters, digits, underscores, dots, or other characters outside the permitted pattern. To address this, the opt-in messaging/restrictive/topic/naming/enabled setting has been added which will normalize Kafka topic names to the [a-z-]+ format across stream, publisher, subscriber, and OAuth2 cache-sync operations while preserving original logical names for message routing; the setting will default to false for backward compatibility and will require a node restart when enabled. NOTE: This applies only to Pega's internal system messaging that uses Kafka as the underlying transport - i.e. the Stream-API-backed pub/sub used for internal cache synchronization and internal messaging channels (platform/kernel/messaging and the OAuth2 cache-sync channel in core/printegrint). It does not apply to client-authored/application-level Kafka integrations, external Kafka connectors, or any other Kafka usage outside of Pega's own internal messaging infrastructure. | System Administration |
| INC-D9419 INC-D38066 | 1003674 1019289 |
Autopopulate blob growth prevented | Case opening was becoming slow as persisted data grew substantially when reference-type autopopulate properties were configured across multiple stages. Investigation showed that missing data pages could alter page hashes, clear reference metadata, and leave forward links accumulating in persisted data. To address this, cleanup logic has been implemented to remove stale forward link references at critical points and bulk-clean accumulated entries exceeding a configurable threshold. | System Administration |
User Experience
25.1.4 Resolved Issues for User Experience
| Ticket # | Issue # | Title | Description | Product Area |
|---|---|---|---|---|
| INC-C23344 INC-C32243 INC-D10100 INC-D7451 |
994598 | Menu state management handling updated | The enableLabelBasedActiveMenuState DSS setting was causing JavaScript errors and UI freezes when navigating between cases and tabs, particularly affecting Case Preview panel functionality. This was caused by the active menu persistence logic storing tab label text instead of expected length values, causing validation failures during menu state restoration, and has been resolved. | User Experience |
| INC-C32526 | 945190 | Table cell context menu keyboard accessibility implemented | To improve accessibility, the keyboard shortcut of Shift+Alt+F10 in Windows has been implemented to open and access context menus on focused cells. | User Experience |
| INC-C38928 | 952578 | Overlay focus retention improved | While working with overlay dialogs, keyboard focus was intermittently shifting away from the invoking control when the overlay was closing, creating inconsistent navigation and accessibility behavior in the flow. Investigation showed this was caused by focus-restoration sequencing that was occurring after or during overlay teardown instead of returning focus to the invoking element first. To address this, focus will be restored to the element that opened the overlay before the overlay is closed. | User Experience |
| INC-C58000 | 977651 | Loader-on-refresh behavior enabled/disabled via toggle | Cascading dropdowns in table layouts were experiencing value deletion and changes when rows were deleted or reordered, with subsequent rows having their values unexpectedly modified. This was caused by the dropdown component setting values to empty during unmounting while connected to Redux, triggering re-rendering before proper row deletion. This has been resolved by implementing a toggle-controlled behavior for showing a loader during refresh flows. Instead of always showing (or not showing) loader behavior on refresh, the experience is now configurable. To enable loader on refresh, make the When rule pyEnableLoaderForFormRefresh evaluate to true (default is false), and pyFormRefreshLoaderDelayInMS controls how long to wait before showing the loader, default value 1000. | User Experience |
| INC-D14196 | 991915 | Localization property filtering improved | Applications with identical properties across different ruleset versions were experiencing localization inconsistencies where the pzAllPropertiesForLocalizationByApp report definition returned duplicate properties from multiple ruleset versions instead of filtering to the latest version. Investigation showed the report definition lacked proper ruleset version filtering logic, causing older property versions to be selected during language pack generation. This has been resolved by updating the pzAllPropertiesForLocalizationByApp report definition to filter properties based on the latest ruleset version, ensuring consistent localization behavior. | User Experience |
| INC-D14225 | 990578 | Worklist button labeling improved for accessibility | Worklist Go buttons were displaying non-unique labels when multiple assignments of the same type appeared. This has been resolved by modifying the button labels to include case IDs in the format "Go - [Current assignment] [Case ID]", ensuring each button has a unique, descriptive label. | User Experience |
| INC-D15926 | 999501 | Blended UI login modal visibility restored during token expiration scenarios | Login continuation prompts were becoming unresponsive during refresh token expiration in blended UI implementations due to UI masking elements obscuring the authentication modal. Investigation showed this was caused by incorrect z-index layering between the authentication modal and UI masking components during modal state changes. This has been resolved by adjusting the display layer prioritization to ensure login prompts remain accessible. | User Experience |
| INC-D17037 | 997034 | Radio button display issue resolved | Radio buttons configured with segmented display type were briefly showing a circle overlay when selected or during page load. Investigation showed this was caused by improper CSS styling in the py-cosmos-control.css rule. This has been resolved by adding z-index:-1 to the appropriate class identifiers so focused segmented radio buttons now show box shadow + outline so they are clearly visible during keyboard navigation for improved accessibility. | User Experience |
| INC-D17344 | 996070 | Case title translation enabled in navigation panel | Case titles in the left navigation panel were not being correctly localized. This was due to incorrect handling for the pyLabel property in pyCaseTab ,and has been resolved. | User Experience |
| INC-D18188 | 995983 | Improved error handling for Localization wizard | The Localization Wizard was incorrectly showing complete status on the first trigger and taking excessive time to reset the distributed map. This has been resolved by updating the exception handling. | User Experience |
| INC-D18430 INC-D19506 |
1002716 1005109 |
System information page display corrected for IBM WebSphere | After update, the System Information page was becoming inaccessible on IBM WebSphere server environments when accessed through the Pega logo in the bottom right corner, displaying the message "Error There has been an issue; please consult your system administrator" instead of the expected system information. This was traced to JSON deserialization encountering unknown properties like "java.fullversion" that were not defined in the SystemProperties POJO, combined with XML serialization format issues where INDENT_OUTPUT was adding newlines that broke regex-based XML declaration replacement. This has been resolved by updating the exact-string regex with a relaxed, anchored matcher to better handle differences in declaration formatting. | User Experience |
| INC-D18937 | 992515 | Date time control week localization corrected | Date time controls with "Display week numbers on the calendar" enabled were showing "Week" in English without proper localization support. This has been resolved by adding proper localization support for week number headers in the pzpega_ui_calendar.js buildDaysRow function calendar control and updating pzClientLocaleData with the necessary field values. | User Experience |
| INC-D19024 INC-D19024 |
992508 993094 |
Filter column localization corrected | Filter dialog labels and column headers were not being properly localized. This has been resolved by implementing proper localization support for filter dialog labels and correcting aria-label generation to provide meaningful accessibility text for screen readers. | User Experience |
| INC-D19060 | 995990 | Attachment validation error messages restored | After update, custom attachment validation errors were not displaying to users in Constellation UI. This has been resolved with an update to ensure the rUpload failure state now fully clears progress flags for file errors in fileutility and clears cached progress entries for all files in the failed batch. | User Experience |
| INC-D19105 | 1021238 | Inline case creation support added for multi doc apps | The case creation flow in the customer service framework differs from the platform behavior, opening the new case immediately instead of keeping the current view visible after creation from a case reference table. To address this, the toggle "pyOpenCasePageAfterCreateInMultiDoc" has introduced to let apps configure the behavior. This setting is disabled by default to retain the current behavior in the customer service framework of auto-opening the newly created case. When enabled, the flow will match platform behavior of creating the case, showing a notification, and retaining the current screen. | User Experience |
| INC-D19274 | 991341 | Dynamic text field labels in partial views corrected | Field labels using dynamic text with decisioning configuration in partial views were not updating correctly at runtime, displaying static text instead of the expected dynamic content based on decisioning rules. This has been resolved with an update to ensure Details components re-render as expected. | User Experience |
| INC-D19366 | 1001240 | Component version retention corrected | Non-library mode components were losing their previous ruleset versions when new versions were published, preventing users from restoring or comparing earlier versions of components. This was caused by the prior ruleset context not being preserved/restored correctly in the non-library component flow, and. has been resolved by modifying the component publishing process so the previous ruleset is retained. | User Experience |
| INC-D19585 | 997950 | Localized table view record count display fixed | Constellation table views in some non-English locales were displaying incorrect record counts after saving personalized views or switching between views, with readonly DataPages showing unchanged counts when switching to default view and editable DataPages reverting to initial default counts after view operations. Investigation showed this was caused by locale-specific formatting issues in the view count calculation and display logic, and has been resolved by updating the localization for the generateCountText method. | User Experience |
| INC-D20177 | 1011219 | GenAI agent session management improved | The Pega Gen AI agent was becoming unresponsive when left idle for approximately 10 minutes, and response chunking was not working correctly for multi-line responses. This was traced to the Constellation frontend framework's handling of the streaming API response lifecycle, and has been resolved by updating the streaming message state handling so incremental updates and final message content are handled consistently. | User Experience |
| INC-D20470 | 997895 | Mobile modal dialog display corrected | Modal dialogs on mobile devices were experiencing issues with rendering and positioning of modal content on mobile screens. This was an inadvertent side effect of previous work which introduced conflicting CSS rules that interfered with mobile-specific modal styling. This has been resolved by adjusting the CSS implementation to ensure proper modal dialog behavior across all mobile device types. | User Experience |
| INC-D20482 | 1002558 | Error message rendering restored for refresh failures | Error messages configured through pxAddMessageToPage were not displaying in the UI when form refresh operations failed. This was caused by the banner rendering logic in the Standard form component only checking for property validation errors and submission errors, not refresh failure scenarios. This has been resolved with an update to the Assignment banner focusing behavior so focus is triggered when banner message content changes rather than when the bannerMessages prop merely receives a new reference with the same content. | User Experience |
| INC-D20526 | 993688 | Table navigation focus management restored | Table icons with menu actions that opened modal local actions were losing focus after modal submission, causing focus to jump to the first table element instead of returning to the original icon position. This was an issue where the keyboard focus behavior for navigation rules rendered in a table did not properly handle the complex navigation chain of icon → menu → modal → table refresh. To resolve this, the focus management logic has been modified to properly restore focus to the originating table icon after modal actions complete and table refreshes occur. | User Experience |
| INC-D20584 | 992848 | Summary set as default active tab in mobile view | Constellation case views in mobile browsers were defaulting to the first custom tab instead of the expected Summary tab, creating inconsistent user experience across different case types and custom configurations. This has been resolved by updating the mobile case tab initialization to default to the Summary tab when no explicit tab selection has been made by the user. | User Experience |
| INC-D20586 | 994059 | Table view font consistency improved | Table views were displaying inconsistent font sizes across columns within the same row. This has been resolved by standardizing font sizes across all column types in table views to ensure uniform display throughout. | User Experience |
| INC-D20896 | 997665 | Percentage control display calculation fixed | Percentage UI controls were incorrectly multiplying decimal values by 100 at the case level, showing 6.12 as 612% instead of 6.12%. Values displayed correctly at the data context level. This was caused by inconsistent percentage formatting logic between different UI contexts, and has been resolved by standardizing the percentage calculation across all display contexts in Constellation. | User Experience |
| INC-D20946 | 996351 | Case navigation fixed in blended portal appointments | Users were experiencing sporadic issues where clicking on a parent case from an appointment summary would reload the appointment case instead of opening the parent case. This was traced to an issue with case ID management in the Redux store when navigating between cases in the blended portal, and has been resolved by ensuring the caseID is populated for traditional UI (coexistence) cases during the SHOW_HISTORY flow, so the Redux store has the case identifier available across page refreshes and direct URL access. | User Experience |
| INC-D21238 | 1013860 | Textarea focus restored during zoomed scrolling | The focus was getting lost in a textarea with large text during scrolling, and pressing Enter caused the focus to jump back to the top of the screen. Investigation showed that when zooming in and out, some CSS rules were not being validated correctly. As a result, the height was not calculated properly and led to unexpected behavior in the text area. This has been resolved by shifting from margin/height-offset compensation to explicit viewport scroll preservation during textarea auto-resize. | User Experience |
| INC-D21353 | 997046 | Radio button aria-label attribute corrected | Radio button controls were displaying "pyCaption" as the aria-label value when no label was configured. This was caused by incorrect parameter passing in the getLocalizedValue function within pzpega_ui_template_radiogroup.js, where the mode was being sent instead of the field value, and has been corrected. | User Experience |
| INC-D21391 | 996765 | Multi-step form restart stage rendering corrected | Multi-step forms routed to work queues were displaying error banners and failing to show the first step when pyRestartStage was executed from non-first steps, particularly when routing was directed to specific users. This was caused by improper API calls triggering "low-action is not a valid action to use" errors during stage restart operations. This has been resolved by fixing the flow action validation and refresh mechanism to additionally validate that the stored actionID still exists on the matching assignment’s actions list before allowing PERFORM-mode updates. | User Experience |
| INC-D21488 | 996314 | Assignment instruction text display corrected | The Assignment instruction text was being truncated mid-sentence and followed by unwanted bullet points, such as "Select the track(s) to reserve for this trai•" instead of displaying the complete instruction text. This has been resolved by updating the CSS used by webwb to modify how the item-separator helper class injects the dot separator. | User Experience |
| INC-D21731 | 997222 | PDF preview functionality restored in Pulse comments | PDF attachments in Pulse comments were not displaying image previews or thumbnails. This was caused by compatibility issues with the IcePDF API when running on Java 21 environments. This has been resolved by replacing the IcePDF API with the Apache PDFBox API, which provides full Java 21 compatibility and properly renders PDF poster images for preview display in Pulse comments | User Experience |
| INC-D22022 | 994126 | Promoted filter time range issue resolved | When specifying a time range of 7:00-7:30 in the Promoted Filter in Insights, the start time (7:00) was being excluded from the results, while the same filter worked correctly when applied directly on the column. Investigation showed this was caused by seconds being added from the current time when clicking the option in the select dropdown, which interfered with the time range filtering logic. This has been resolved by correcting the time handling mechanism in the Promoted Filter functionality to ensure consistent behavior with column-level filtering. | User Experience |
| INC-D22142 | 997364 | Accessibility corrected for left panel tabs | When using JAWS to navigate through the tabs on the left panel, the narration indicated to use the left and right arrow keys instead of the correct up and down arrow keys. This was caused by navigation logic in the menu control not accounting for the semantic role of the menubar element. To resolve this for correct accessibility, an update has been made to detect when navigating within a menubar role element and automatically map left/right arrow key presses to up/down navigation. |
User Experience |
| INC-D22584 INC-D26790 |
997637 1003753 |
Firefox date picker keyboard navigation enabled | Date picker calendars were not displaying when accessed via keyboard navigation in Mozilla Firefox, while working correctly in Google Chrome. This was caused by Firefox-specific event handling differences that interfered with the keyboard navigation implementation, and has been resolved by adding Firefox-specific condition logic to prevent secondary key down events that were interfering with calendar display. | User Experience |
| INC-D22822 | 1006152 | List view custom action submission corrected | Custom actions from the three-dot menu in list views were failing to submit when modal actions contained query fields sourced from the same data page as the list view. This was caused by incorrect data page metadata population where the linkedField parameter was not being set properly, causing metadata conflicts in the client redux layer. This has been resolved by correcting the addDataPageMetadata logic to properly populate linkedField parameters. | User Experience |
| INC-D23082 | 1001996 | Browser back button behavior corrected after attachment downloads | After downloading multiple attachments in the Theme Cosmos User Portal, the browser back button functionality was incorrectly triggering re-downloads of previously accessed files instead of navigating to the previous page. This was caused by improper handling of browser history state after attachment download operations, and has been resolved by explicitly removing the iframe to prevent the attachment from being re-downloaded when using the browser's back button. | User Experience |
| INC-D23195 | 997308 | Localized worklist label | The worklist label was not being correctly localized. This was due to the parameter being hardcoded, and has been corrected. | User Experience |
| INC-D23211 | 998868 | Arabic text overflow in multistep components resolved | Right-to-left (RTL) languages like Arabic were experiencing step label overflow issues in Constellation MultiStep components, causing display problems in the user interface. Investigation showed that the component library was not properly handling RTL text layout requirements. This has been resolved by implementing proper handling to correct the MultiStepForm horizontal progress step popover alignment when the app is in RTL mode, ensuring the first/last step popovers anchor to the correct edge. | User Experience |
| INC-D23369 | 997171 | Corrected non-template Calendar picker issue | After update, calendar picker controls were intermittently failing to open. This was traced to WEEKDAYS_LONG missing from the data-calendar locale array built in pzdatetimelocalescript, and has been resolved by updating the non-template calendar locale bootstrap so that the client-side calendar utilities receive a localized long weekday name list (WEEKDAYS_LONG) from the data-calendar payload, aligning non-template behavior with the DateTimeUtil-backed path. | User Experience |
| INC-D23381 | 1003428 | Assignment instructions display made consistent | Assignment instructions were not appearing when opening assignments from the Todo widget, while the same instructions displayed correctly when accessing cases through review mode. Investigation showed this was caused by the getCaseInfo().getCurrentAssignmentViewClassName() API not returning the necessary values when navigating through nested array paths (dot-separated) before indexing. This has been addressed by extending getValueByPath to resolve nested pyViewContext array keys via dotted-path traversal before applying the index, ensuring consistent API behavior across different launch contexts to properly display assignment instructions. | User Experience |
| INC-D23481 | 996433 | Promoted filter infinite scroll duplication eliminated | Promoted filters using non-queryable, non-searchable DataPages were causing infinite refetch loops during scroll-based pagination, resulting in duplicate results. This was caused by the condition-builder continuously requesting more records even though the server returned the full dataset on every call. This has been resolved by implementing proper DataPage limitation handling to prevent multiple requests for the same data. | User Experience |
| INC-D23500 | 1000513 | Constellation form refresh performance improved | Applications were experiencing significant delays when dropdown controls and form refresh events were triggered in Constellation interfaces, particularly noticeable with large payloads where dropdown fields were briefly displaying cached values from previous sessions before updating to correct server values several seconds later. Investigation showed this was caused by a race condition between multiple refreshFor calls targeting the same component, creating performance bottlenecks during form refresh operations. This has been resolved by implementing logic to cancel redundant refreshFor calls when multiple pending calls target the same component. | User Experience |
| INC-D23860 | 997619 | AnyPicker apostrophe handling corrected | AnyPicker controls were truncating values at apostrophes and failing to load results properly when categorization was enabled, affecting department names like "Clie'nt support" which would display as "Clie". Investigation showed that the categorization feature was not properly escaping special characters in field values. This has been resolved by adding a function escapeMarkupValue in the anypicker.js to implement proper character escaping in the categorized search results functionality. | User Experience |
| INC-D24010 | 996581 | Improved promoted filter picklist handling | Promoted filters were failing to render when picklist properties were configured for search box or radio-style presentation. Investigation showed that field types were not being handled consistently when configuring promoted filter display options. This has been resolved by preventing duplicate display configurations for picklists without available options. | User Experience |
| INC-D24251 | 1003987 | Keyboard navigation visibility corrected | When two CaseActionHeader sections were rendered on the page, keyboard focus incorrectly moved to the inactive header's Edit and Actions buttons before Collapse Summary, causing focus on controls that are not visible to the user. This was caused by duplicate button elements from case action sections remaining in the tab order when not visible, and has been resolved by keeping only the active CaseActionHeader keyboard accessible by applying inert to the inactive header based on the Summary Panel state, ensuring the correct tab order. | User Experience |
| INC-D24934 | 997516 | Language bundle reupload functionality corrected | Language pack reuploads were not updating existing bundles when branching was enabled, causing translation changes to be ignored. This was caused by the language bundle rule creation process not properly handling updates during the reupload workflow with branch configurations, and has been resolved by updating the Constellation UI localization bundle saving so that the save path avoids overwriting the rule’s ruleset/ruleset-version metadata when operating on a localization rule that already belongs to a branch ruleset. | User Experience |
| INC-D25044 | 1005539 | Digital messaging conversation closure synchronized with wrap-up actions | Customer service representative chat conversations were remaining active and allowing continued interaction even after wrap-up completion, despite having the "Update CSR capacity upon wrap-up" setting enabled. Investigation showed this was caused by a mismatch between wrap-up actions and conversation closure behavior in Digital Messaging. This has been resolved by preventing PubSub subscriber mutations during callback unsubscribe, ensuring conversations properly close when wrap-up is completed. | User Experience |
| INC-D25196 | 1001446 | Search updated for localized environments | When switching between "All instances" and specific case type filters in Constellation UI with German localization enabled, search results would disappear after applying case type filters and would not return even when switching back to "All instances" view. Investigation showed this was caused by the search context failing to reinitialize properly after filter changes in localized environments. This has been resolved by updating the Constellation UI search context management to apply localization logic for the case type list while comparing, so that it will be compared properly. | User Experience |
| INC-D25799 | 1003008 | Advanced search bar behavior standardized | The search bar was retaining entered strings after opening work objects through advanced search results, while properly resetting when opening objects through regular search results. This was caused by inconsistent reset behavior between different search result pathways, and has been resolved by explicitly clearing the tracked search input state on the case-open navigation event to standardize the search bar reset functionality across all search result interactions. | User Experience |
| INC-D25992 | 1006170 | Modal popup positioning corrected | Modal popups were appearing at the bottom of the screen instead of their intended centered position when launched within Constellation applications loaded in iframes. Investigation showed that a fix intended for mobile modal dialog positioning was appending inline CSS to iframe elements and modal-align-cell class, causing modal height to use full iframe scroll height rather than viewport height and resulting in bottom-screen placement in iframe mashup scenarios. This has been resolved by updating the modal positioning algorithm to properly calculate viewport coordinates and ensure modals appear in the correct screen location. | User Experience |
| INC-D26877 | 1001639 | Advanced search special character handling improved | Advanced search functionality was experiencing content disappearance when certain key combinations like parentheses were entered and submitted, causing console errors in the Constellation application. This has been resolved by updating the character encoding and validation in the advanced search processing, ensuring special characters are handled correctly without causing application content to disappear. | User Experience |
| INC-D27000 | 1005266 | Prevented duplicate tabs | Opening an existing interaction or service case from navigation was creating a duplicate tab whenever its tab was selected again. Investigation showed that active cases were not being reused in the navigation container. To address this, existing case containers will be activated instead of creating duplicate tabs. | User Experience |
| INC-D27678 | 1008173 | Dynamic text refresh functionality corrected | Dynamic text content using VerbatimParagraph templates was not refreshing after onChange data transforms, causing outdated content to persist even when underlying decision parameters changed. This was seen with static text display despite radio button selections that should have triggered content updates based on when rules. Investigation showed this was caused by the template rendering system not responding to state changes in react_pconnect views. This has been resolved by implementing proper re-rendering triggers for dynamic text in VerbatimParagraph templates when refresh conditions are met. | User Experience |
| INC-D27679 | 1003242 | Focus restored to date picker calendar icon | When using a date picker within a modal dialog, pressing the escape key to close the calendar was leaving focus in an undefined state rather than returning it to the calendar icon. This was caused by the modal dialog's closeChildOverlay function not properly handling the focus return for date time fields, and has been resolved by adding conditional logic to send the close reason as ""clickaway"" in the callback parameter, ensuring focus returns to the calendar icon after escape key usage. | User Experience |
| INC-D27868 | 1005505 | #resolvedissues note | Promoted filters display behavior improved for dashboard insights Dashboard chart insights were displaying promoted filters in collapsed mode at 100% screen zoom even when sufficient screen space was available to show them in full expanded view. The same filters displayed properly at 75% zoom. This was caused by incorrect rendering logic that failed to properly calculate available space for promoted filter display, particularly affecting single primitive-type filters, and has been resolved by updating the promoted filters rendering mechanism to prevent unnecessary collapsing into modal dialogs when adequate screen space exists. |
User Experience |
| INC-D28177 | 1004416 | Dynamic text rules applied consistently across embedded repeating rows | Dynamic text configured through decision rules on embedded data properties was only functioning for the first row in repeating views, while subsequent rows displayed without the dynamic text evaluation. Investigation showed the rule evaluation was not being triggered for rows beyond the first instance. This has been resolved with an update that ensures all the dynamic properties of a paragraph rule are processed for each entry in a list. | User Experience |
| INC-D28395 | 1003927 | Stakeholder widget party labeling corrected | The stakeholder widget was displaying incorrect field labels for party role radio buttons, showing the internal technical party role instead of the user-friendly party label previously seen. This has been resolved by keeping the API role ID and role label as separate fields in Stakeholders role handling so the proper party label displays in the stakeholder widget role radio button fields. | User Experience |
| INC-D28467 | 1005456 | Preserved invalid date input | Date validation was displaying the replacement message "invalid is not a valid date value" instead of retaining the incomplete or incorrect value entered during date processing. This was due to the raw date input not being preserved in the validation state, and has been resolved with an update to save the original invalid datetime value in the redux state for consistent error handling. | User Experience |
| INC-D28666 | 1002920 | Discard unsaved changes functionality restored in pop-up screens | When working in pop-up screens and making changes, clicking cancel was presenting a "Discard unsaved changes?" dialog, but clicking "Discard" did not have any effect. This was seen in various scenarios including KMR (Knowledge Management Repository) case creation screens and other embedded data modals where users were unable to properly exit after making unsaved changes. This was caused by the discard changes functionality not working correctly on dirty dialogs for open embedded data modals, and has been resolved. | User Experience |
| INC-D29577 | 1005460 | Search context properly cleared when navigating to home page | After performing a search operation and switching to advanced search mode, search context was not being reset when navigating back to home screen. This was caused by incomplete search state cleanup during navigation events, and has been resolved by ensuring search context is explicitly cleared whenever a navigation item is activated. | User Experience |
| INC-D29662 | 1008472 | Screen reader announcements consistent between modal types | When a flow action was opened using a modal window, the pyCaption was correctly announced by screen readers. However, when the same flow action was opened using an overlay modal, the screen reader announced the flow action name instead of the configured pyCaption. This was due to a missed localization path for a modal title, and has been resolved by updating to use getLocalizedTextForString so the title is now translated consistently. | User Experience |
| INC-D29835 | 1004768 | Delete confirmation message localized | Delete confirmation dialogs were displaying in English instead of the configured language on Constellation landing pages. This has been resolved. | User Experience |
| INC-D30243 INC-D34832 |
1011541 1018383 |
Corrected transaction search error message handling | Transaction search screens in customized Pega Smart Dispute Agentic Automation (SDAA) interfaces were displaying misplaced error messages that persisted after performing valid date searches. This was an unintended change made as part of a DSS configuration update, and has been resolved by adjusting the error message handling logic in Constellation. | User Experience |
| INC-D30341 | 1006208 | Data page picklist property display corrected | Data pages configured with table type were displaying incorrect values from associated properties in list views. When unexposed properties were mapped to associated properties in response data transforms, the unexposed property was holding display text values instead of code values, while direct reference to associated properties in list views was not functioning as expected. Investigation showed this was caused by incorrect mapping logic in the presentation layer despite the DX API correctly retrieving code values from the backend. This has been resolved by extending rule-store property metadata lookup to also match on associationClassID, enabling correct resolution for associated picklist properties. | User Experience |
| INC-D31311 | 1012677 | Restored details tab display | The details tab was not appearing after case resolution when the summary panel was collapsed. This was a missed use case, and has been resolved by updating the page template with the required dynamic layout refresh behavior. | User Experience |
| INC-D31508 | 1008338 | Corrected hierarchical button behavior | Configured action buttons were functioning in standard forms but were failing when placed in hierarchical forms. This was traced to hierarchical components receiving an incorrect container name, and has been resolved by adding the hierarchical form container name to the deferred-load context. | User Experience |
| INC-D31573 | 1008617 | Screen freeze resolved | An embedded assignment screen was becoming unresponsive after local actions and navigation, requiring a browser refresh to recover. This was due to the initialization path conflicting with embedded navigation/local action behavior, causing the assignment UI state to stall. To resolve this, the bootstrap logic has been reordered to detect EMBED mode first and disable broadcast initialization for embed contexts (initBroadcast excludes EMBED). As a result, BroadcastChannel is not started in standalone Web Embed, and Close/Cancel now works reliably regardless of pyEnableTraditionalUICoexistence, without affecting future blended UI scenarios. | User Experience |
| INC-D31585 | 1009396 | DX component builder template classification corrected | Custom templates created via DX Component Builder were being incorrectly classified as form views instead of partial views across multiple applications and data objects. Templates not containing the keyword 'details' in their names were being treated as form views and assigned 'embeddeddata' view type, which triggered unintended mode:editable properties in pxViewMetaData configuration. This was caused by flawed logic in pzAddView Activity step 4 that determined view type based solely on whether template names contained the 'details' keyword. This has been resolved by improving the template classification logic in the UI Authoring component. | User Experience |
| INC-D32432 | 1007651 | Expand/collapse navigation button layout corrected | The clickable area of the expand/collapse toggle button in case left navigation was not accessible due to being partially covered by the ShowSmartTip style overlay. This was caused by conflicting CSS positioning that created an invisible overlay blocking user interaction with parts of the toggle button, and has been resolved by adjusting the button format from Standard to TinyTipHeader and correcting the CSS positioning to ensure the entire button area remains clickable. | User Experience |
| INC-D32920 | 1008442 | Time input validation corrected for 24-hour format | Time-of-day controls were rejecting valid "00" hour values when 24-hour formatting was enabled, preventing the entry of midnight times like "00:30" and causing validation errors during data entry. This was caused by incorrect hour validation logic in the pzpega_ui_calendar_util.js file, and has been resolved by updating the appendToDate and getHoursIn24HoursFormat functions to correctly process "00" hour values when 24-hour formatting is enabled. | User Experience |
| INC-D33009 INC-D38305 |
1010530 1017097 |
Unique column value retrieval corrected | Incomplete, empty, or inconsistent unique-value lists were returned when filtering table columns. This was due to the request query being constructed differently across the server, client, and non-queryable data paths, and was caused by relying on general table-state query preparation instead of consistently generating the required column-specific query.select structure. To address this, unique-value retrieval will use a shared query builder across ServerApi, DataClientApi, and NonQueryableDataAPI to preserve distinct-result and paging behavior and safely return no results for unavailable columns. | User Experience |
| INC-D33013 | 1016674 | Flyout menu stale data behavior corrected | Common phrases were being duplicated and submenu content was remaining stale while categories were being hovered during flyout navigation. investigation showed this was caused by the existing Popover instance being reused across expandedItem changes, allowing stale internal menu content/state to persist. This has been resolved by keying the Popover with expandedItem.id so it will remount on each parent transition. | User Experience |
| INC-D33043 | 1008397 | Negative decimal values with leading zeros accepted in Constellation | Decimal number fields in Constellation were rejecting negative values that began with zero (such as -0.5). This was caused by input validation logic that incorrectly identified these values as invalid numeric formats, and has been corrected. | User Experience |
| INC-D33072 | 1007307 | Localization support improved for insight charts | Case status values were displaying in English within Insight chart legends despite localization being enabled for the application. This has been resolved by implementing proper localization handling for case status values in Insight charts. | User Experience |
| INC-D33360 | 1012460 | Table validation alignment corrected | After update, required field validation warnings were appearing on incorrect grid rows. This was caused by incorrect row-to-data array mapping in pzpega_ui_doc_domUtils where the 4th visible row was incorrectly mapped to the 5th position in the data array, leading to misalignment between visible UI positions and underlying data array indices. This has been resolved by correcting the row indexing logic in the DOM utilities to ensure proper alignment between visible table rows and their corresponding data array positions during validation processing. | User Experience |
| INC-D33662 | 1010826 | Table checkbox validation error icons restored | Validation error icons were not displaying beside checkboxes in tables after update. This was an inadvertent side effect of work done on checkbox validation error icon positioning, and has been resolved. | User Experience |
| INC-D33684 | 1009261 | Case manager dashboard editor layout fixed | The dashboard widget editor in the UI Kit was experiencing overlapping content issues where the DELETE icon overlapped the right-hand panel and the stages view created additional overlap elements. This was caused by incorrect positioning and layering of UI elements in the dashboard personalization interface, and has been resolved. | User Experience |
| INC-D34169 | 1013730 | Security updated for localization submission | A dropdown localization submission was failing with an HTTP 500 response. This has been resolved by adding security settings and updating the save logic to support branching. | User Experience |
| INC-D34215 | 1010436 | Related case opening corrected for blended UI | Attempting to open related cases in a new tab within Constellation blended UI environments generated a 404 error. This was caused by improper URL handling for Constellation cases when accessed through the "Open in tab" functionality from the related cases widgets in a traditional portal, and has been resolved by updating the generation logic so a semantic link now handles the open in tab for Constellation cases. | User Experience |
| INC-D34445 | 1010945 | Report browser element focus corrected | Report field editing was becoming unresponsive when users attempted to modify column formats using the magnifier glass icon, causing screen freezes. This was traced to the system not sufficiently validating state/target conditions before attempting to move focus, and has been resolved by adding a conditional guard so focus navigation only proceeds when the target element is valid for focus movement. | User Experience |
| INC-D34795 INC-D41337 |
1011703 1018423 |
App and Data Explorer loading issue corrected | After update, App Explorer and Data Explorer were not loading on the first login and were appearing only after a refresh. This was traced to an issue in Oracle-based environments where the branch gadget was throwing an exception related to aggregate SQL queries returning database-dependent column names while pxDisplayWarningInHome was attempting to read the lowercase count property. To address this, the queries will expose a consistent "COUNT" alias so the count property is correctly populated and the application and data explorers will load as expected. | User Experience |
| INC-D35534 | 1017850 | Save for later" selections preserved | Selections were not retained when a single-select data reference was reused in multiple embedded contexts of the same class on one screen. Investigations showed that when a property model for that class had already been registered by an earlier context, model registration returned no result, so page metadata processing was skipped for later contexts and their data-page parameter bindings were dropped. To resolve this, page metadata is now tracked per rendering context. The shared property model is still registered once, but each context gets its own data-page parameter bindings. | User Experience |
| INC-D35636 | 1019364 | Corrected field group borders | Field groups nested within bordered items were displaying misaligned or incomplete full-width borders. Investigation showed that the border styling was constrained to content width rather than container/full-row width, and this has been corrected. | User Experience |
| INC-D35657 | 1012603 | TinyTipHeader smart tip format added | System warnings were being generated during case processing related to smart tips not being rendered as intended. This was due to a missing format component in the pyCaseMainInner section, and has been corrected by adding a new smart tip skin format called TinyTipHeader to Cosmos skin. This supports styling for the header variant to present a more compact/header-oriented smart tip appearance. | User Experience |
| INC-D35856 | 1012408 | DateTime table rendering corrected | Tables configured with DateTime properties as primary fields were generating JavaScript download requests for incorrect files at runtime. This was traced to improper file path generation for DateTime controls in table configurations, and has been resolved by correcting the JavaScript file path generation for DateTime controls in table views. | User Experience |
| INC-D36702 | 1013900 | Report navigation functionality restored for Blended UI | After update, work orders were not opening when clicked from Report Definition screens in Blended UI configurations. Investigation showed this was caused by broken navigation handling in the Blended UI report integration, and has been resolved by ensuring UI/report click handling and/or the route/open invocation logic resolves to a valid work-object open action. | User Experience |
| INC-D37287 | 1013179 | Search filter persistence maintained during work object search operations | Applied case filters were being cleared when performing work object searches outside the filter context, causing loss of previously established search criteria. This was traced to inconsistent filter state management during search transitions, and has been resolved by implementing proper filter context preservation across all search operation pathways. | User Experience |
| INC-D37540 | 1014278 | Preserved custom favicons | A configured custom favicon was being replaced by the default product icon after portal navigation. This was traced to the favicon <link rel="icon"> markup being included in dynamic container content and then injected/replaced during dcViewUpdate(), which caused loss of the intended head state. The fix preserves custom favicon links by moving any generated icon links back into document.head after navigation updates. | User Experience |
| INC-D37716 | 1019608 | Corrected layout rendering | After update, portal pages were visibly displaying layout metadata instead of rendering the affected layouts correctly. Investigation showed that client-side layout assembly failed to resolve the LAST predicate for a specific dynamic-layout configuration, causing metadata to be emitted as visible text. This has been resolved by restoring correct context-aware rendering for layouts that reference list elements such as .TestList(<LAST>), while leaving unrelated layout rendering paths unchanged. | User Experience |
| INC-D37824 | 1018945 | Stabilized repeating-view tooltips | Tooltip dynamic text was displaying for one record but was failing to show expected values for additional records in a repeating view. Investigation showed that repeated context-property processing was causing recursive behavior while multiple rows were being handled. To address this, stop-gap conditions will prevent infinite recursion during repeated-row processing. | User Experience |
| INC-D38501 | 1015625 | DateTime defaults to browser timezone | DateTime values were being displayed in GMT when no operator timezone was configured, rather than using the browser timezone. This was due to case-context DateTime properties lacking a system-timezone fallback, and has been addressed with the new Rule pyEnableDateTimeSystemTimezoneFallback. With this update, Date Time values will be displayed using the browser timezone by default. When pyEnableDateTimeSystemTimezoneFallback is set to false, Date Time values are displayed in GMT. | User Experience |
| INC-D38517 INC-D38517 |
1013636 1018492 |
Axios library updated | The Axios library has been updated to the latest version. | User Experience |
| INC-D38856 | 1014284 | Corrected multiselect values persistence | Selected values were disappearing from multiselect controls after an upgrade, leaving related properties incompletely populated at runtime. Investigation showed that display fields were being added incorrectly when additional keys were present. To address this, display fields will be excluded from non-form properties in that situation. | User Experience |
| INC-D39163 | 1015799 | Child case context synchronized | Child cases were showing a mixture of parent and child information in the Constellation interface after update. Investigation showed that deferred case-summary updates were being applied during child-case process actions. To address this, deferred summary updates will be skipped for child-case process actions so the displayed context remains synchronized. | User Experience |
| INC-D39245 | 1015681 | Exception handling added for questionnaire | An exception was occurring while a screen flow was rendering a section associated with the questionnaire framework. This has been corrected. | User Experience |
| INC-D40052 | 1015045 | Corrected Arabic time ordering | Time values were appearing with hours and minutes in the wrong order in right-to-left Arabic layouts. This has been addressed with improvements to the DateTime components to improve time display and input behavior for RTL locales, focusing on keeping hour/minute ordering stable and handling meridiem rendering. | User Experience |
| INC-D40100 | 1019574 | Cleared hidden search selections | Forms were being rejected after a conditional search-and-select field was hidden because its previously selected value was still being submitted. This was caused by hidden field data remaining in the submission payload after the controlling selection changed, which was due to it not having the necessary association for filtering. To address this, the form handling will derive the associated property from the selection key, editable reference list, or field value and pass it through Data Reference updates so it can be filtered. | User Experience |
| INC-D41022 | 1017206 | Corrected duplicate multiselect entries | Duplicate entries were appearing when selected multiselect values were removed and the related dropdown was changed. This was caused by an incorrect selection-tree state during pill removal. To address this, the selection tree will remain synchronized so removal operations will not re-add deleted values. | User Experience |
| INC-D41696 | 1016202 | Locale handling stabilized for request processing: | During processing, request localization was intermittently presenting in an unexpected language/region. This was due to the requestor context being switched to the operator’s original locale, which was appearing as inconsistent translated text and regional formatting across the same flow. This has been resolved by updating locale-handling behavior so request execution will preserve and apply the intended requestor locale consistently rather than reverting to the operator’s original setting. | User Experience |
| INC-D41986 | 1018589 | Corrected add link field validation | After update, the Add Link modal could show mandatory-field errors, but URL validation was not correctly tied to blank/invalid URL inputs. This has been addressed with explicit field-level handling for URL validation in the modal, so blank or malformed URLs surface the correct error state (including whitespace-only URL values after trimming). | User Experience |
| INC-D43886 | 1020352 | Corrected review-mode local actions | Local actions were failing to launch when cases were opened in review mode without assignment permission. Investigation showed that direct confirmation loads were not updating the case view mode, causing an invalid assignment save attempt. This has been resolved by updating the case view mode to remain in "review" during direct confirmation loads, preventing the invalid save invocation when there are insufficient permissions to perform the assignment. | User Experience |
| INC-D44120 | 1019961 | Added consistent loading feedback | Navigation between multi-step form steps was appearing unresponsive because breadcrumb actions did not show a loading indicator, while save-for-later messaging could appear before the review screen loaded. Investigation showed that breadcrumb navigation lacked the loading-state handling used by other navigation controls. To address this, a loading indicator has been added which will display when navigating between steps in a multistep assignment form. The indicator remains visible until navigateToStep completes, and is cleared for both rejected promises and synchronous failures to prevent the form becoming stuck in a loading state. | User Experience |
| INC-D44476 | 1020663 | Promoted picklist display improved | A promoted Picklist filter was failing to display selected values from large queryable data pages, although filtering was continuing to work. Investigation showed that label lookup was limited to the first 5,000 data page results by client-side filter metadata. To address this, selected-value labels will be loaded through an ID-filtered data page request. | User Experience |
| INC-D46778 | 1021917 | Enabled popup field selection | Options in a multi-select field were not being selected with mouse clicks when the assignment was displayed in a creation popup, although the same field worked on a regular stage screen. Investigation showed that popup-rendered assignments handled field interaction incorrectly, and this has been corrected. | User Experience |
| INC-D5197 | 977915 | JSP tags fixed in table headers | Sections containing non-optimized tables were failing to save when JSP tags like " " were used in column header labels. This was traced to the GenerateCellContent Rule-Utility-Function not properly handling JSP tag processing in table header contexts, and has been corrected. | User Experience |
| INC-D7400 INC-D39971 |
980892 1016032 |
Application save-as data type copying corrected | Application save-as operations were failing with "URL Alias is already in use" errors and not copying data types to newly created applications. Investigation showed the PreSaveAs path did not correctly update pyProductAlias before the copy/save logic executed, causing the downstream logic used an incorrect/old alias context, so related data type rules were not associated and copied as expected. This has been resolved with an update to ensure Save As updates the alias context correctly. | User Experience |