6.2026.0916.2

Updated by Cheryl Wallace

Release Notes for update version 6.2026.0916.2

This is a partial list of enhancements and fixes included with this release.

IMPORTANT CUSTOMER IMPACT

This is an important security update. All existing ToolHound Browser, Mobile and integration sessions will be signed out once when the update is applied. Users must sign in again. Mobile users must sign in through the Browser once after the server update before signing in to ToolHound Mobile.
On Premise subscribers: Custom scripts, scheduled tasks, monitoring checks or integrations that access ToolHound pages or APIs without signing in may stop working after this update. Test custom integrations before applying the update to production.

Enhancement Highlights

NEW FEATURES
Browser
  • Account lockout is now enforced. Five failed sign in attempts lock the account for one minute. Incorrect two factor authentication codes count toward the same limit.
  • Import Data now gives each new user a unique 14 character password. The passwords are displayed once after the import and can be downloaded as a CSV file.
Download or copy the generated passwords before leaving the Import Data page. ToolHound cannot display them again. Distribute the passwords securely, delete the CSV when finished and ask each user to change their password after signing in.
API
  • The administrator password reset now requires an authorized user and generates a unique password for each reset. The password is displayed once.
Installation & Upgrade
  • Each ToolHound installation now uses its own access token signing key. Access tokens issued before this update stop working once, which signs out Browser, Mobile and integration sessions.

ENHANCEMENTS
Browser
  • Two factor authentication now requires the user's password before the authentication code is accepted. Enter the code within five minutes. Five code attempts are allowed for each password entry.
  • Add, Edit and Delete permissions configured for Roles are now enforced for Users, Roles, Settings, Reports, Notifications, the Command Window, selected Personnel fields and Location Services integrations.
  • Email Password on Utilities, Settings now appears empty even when a password is stored. Leave the field blank to keep the existing password. Enter a value only when replacing it.
  • Users must be signed in before opening or downloading an attachment. A signed out user who opens a shared attachment link is directed to the ToolHound login page.
  • The Export to Excel action on the Command Window now submits the command through the signed in session. Old bookmarked, emailed or automated Command Window export links no longer work.
  • Import ToolHound 5 Data has moved from the registration process to Utilities, Import Data. Register the ToolHound 6 company, sign in as the administrator and then run the conversion. The user completing the conversion must have Edit permission for Utilities, Command Window.
Review customized Roles before applying the update. A user may still see a screen but be prevented from saving, deleting, exporting, designing a report or opening a restricted Location Services screen when the required permission is not granted.
Reporting Enhancements
  • Report filters now support apostrophes and values longer than 128 characters.
  • IN and NOT IN report filters now add quotation marks automatically. Enter values without quotation marks and separate multiple values with commas.
  • Report sorting and advanced filter expressions are validated before the report runs.
  • Opening the Report Designer and its query builder now requires Edit permission for Reporting, Reports. Report viewing is not affected.
  • The Report Designer now saves updated layouts without leaving content from the previous version of the file.
Review saved IN and NOT IN filters after the update. Remove manually entered quotation marks before saving. A rejected filter may produce a No Data PDF or an empty Excel file.
Mobile
  • Mobile users must have Mobile selected on the Users page for offline work to retain its original created and modified dates and user information when it synchronizes.
Each Mobile user must sign in again after the server update before synchronizing offline work.
API
  • ToolHound pages and most APIs now require an authenticated user. Browser page requests made while signed out are directed to the login page. API requests made without a valid token are refused.
  • Azuga can now send its API secret in the X Api Secret request header. The existing query string method remains available for compatibility.
  • GPS callbacks now return consistent authentication responses for invalid company names or credentials.
Installation & Upgrade
  • On Premise installations with a read only or replaceable application folder must configure JwtToken:SigningKey so the same key is retained after a restart or redeployment. Azure App Service users must open the Console in the Azure Portal, enter openssl rand -hex 24 and press Enter. In Settings, create an environment variable named JwtToken__SigningKey and use the generated signing key as the value. Keep this key private and do not share it.
  • Cloud customers using Digital Matter GPS must have the webhook username and password configured when the update is applied. Missing credentials cause new GPS positions to be refused.

FIXES
Browser
  • Forgot Password now displays the same confirmation for all account dependent outcomes. If the company does not have email configured, the user is told to contact the system administrator.
  • Changing a password through Forgot Password or the Users page no longer appears to bypass an active account lockout. Wait until the one minute lockout has expired before signing in with the new password.
  • The password expired message is now displayed only after the correct password has been entered.
  • Text custom fields containing an apostrophe can now be saved without preventing the rest of the record from saving.
  • Legacy attachments stored without a filename now download instead of opening in the Browser.
  • Home Messages, page alerts, confirmation messages and customized captions are handled more securely when displayed in the Browser. Standard formatting, images and links continue to display normally.
Reporting
  • Report filters containing apostrophes or long values no longer fail or return blank results.
  • Saving a shorter report layout no longer leaves content from the previous layout in the file. Layouts damaged before this update must still be restored from a backup or rebuilt.
  • Report names containing an apostrophe can now be imported.
  • Dashboard requests containing an invalid date range are now refused instead of returning all historical data under an incorrect date heading.
Mobile & Integration APIs
  • Created and modified audit information from offline work is now accepted only from users configured for Mobile access.
  • Notification updates submitted through the API now save the notification body correctly when the text identifier is not included.
  • Hapn GPS no longer writes device locations and tracked positions to the application log.
Installation & Upgrade
  • ToolHound 5 conversion now stops when the source is invalid, the target is missing or the target has already been converted. Clearer validation messages are displayed.
  • Creating a database now displays clear messages for missing, duplicate or invalid database names.

See also:

Copyright © 2020-2026 ToolHound Inc. All Rights Reserved.


How did we do?