6.2026.0916.2

Updated by Cheryl Wallace

Release Notes for update version 6.2026.0916.2

This is a partial list of enhancements and fixes included with this release.

IMPORTANT CUSTOMER IMPACT

On Premise subscribers: Custom scripts, scheduled tasks, monitoring checks or integrations that access ToolHound pages or APIs without signing in may stop working after this update. Test custom integrations before applying the update to production.

Enhancement Highlights

NEW FEATURES
Browser
  • Account lockout is now enforced. Five failed sign in attempts lock the account for one minute. Incorrect two factor authentication codes count toward the same limit.
  • Import Data now gives each new user a unique 14 character password. The passwords are displayed once after the import and can be downloaded as a CSV file.
Download or copy the generated passwords before leaving the Import Data page. ToolHound cannot display them again. Distribute the passwords securely, delete the CSV when finished and ask each user to change their password after signing in.
API
  • The administrator password reset now requires an authorized user and generates a unique password for each reset. The password is displayed once.
Installation & Upgrade
  • Each ToolHound installation now uses its own access token signing key. Access tokens issued before this update stop working once, which signs out Browser, Mobile and integration sessions.

ENHANCEMENTS
Browser
  • Two factor authentication now requires the user's password before the authentication code is accepted. Enter the code within five minutes. Five code attempts are allowed for each password entry.
  • Add, Edit and Delete permissions configured for Roles are now enforced for Users, Roles, Settings, Reports, Notifications, the Command Window, selected Personnel fields and Location Services integrations.
  • Email Password on Utilities, Settings now appears empty even when a password is stored. Leave the field blank to keep the existing password. Enter a value only when replacing it.
  • Users must be signed in before opening or downloading an attachment. A signed out user who opens a shared attachment link is directed to the ToolHound login page.
  • The Export to Excel action on the Command Window now submits the command through the signed in session. Old bookmarked, emailed or automated Command Window export links no longer work.
Review customized Roles before applying the update. A user may still see a screen but be prevented from saving, deleting, exporting, designing a report or opening a restricted Location Services screen when the required permission is not granted.
Reporting Enhancements
  • Report filters now support apostrophes and values longer than 128 characters.
  • IN and NOT IN report filters now add quotation marks automatically. Enter values without quotation marks and separate multiple values with commas.
  • Report sorting and advanced filter expressions are validated before the report runs.
  • Opening the Report Designer and its query builder now requires Edit permission for Reporting, Reports. Report viewing is not affected.
  • The Report Designer now saves updated layouts without leaving content from the previous version of the file.
Review saved IN and NOT IN filters after the update. Remove manually entered quotation marks before saving. A rejected filter may produce a No Data PDF or an empty Excel file.
API
  • ToolHound pages and most APIs now require an authenticated user. Browser page requests made while signed out are directed to the login page. API requests made without a valid token are refused.
  • GPS callbacks now return consistent authentication responses for invalid company names or credentials.
Installation & Upgrade
  • On Premise installations with a read only or replaceable application folder must configure JwtToken:SigningKey so the same key is retained after a restart or redeployment. Azure App Service users must open the Console in the Azure Portal, enter openssl rand -hex 24 and press Enter. In Settings, create an environment variable named JwtToken__SigningKey and use the generated signing key as the value. Keep this key private and do not share it.

FIXES
Browser
  • Forgot Password now displays the same confirmation for all account dependent outcomes. If the company does not have email configured, the user is told to contact the system administrator.
  • Changing a password through Forgot Password or the Users page no longer appears to bypass an active account lockout. Wait until the one minute lockout has expired before signing in with the new password.
  • The password expired message is now displayed only after the correct password has been entered.
  • Text custom fields containing an apostrophe can now be saved without preventing the rest of the record from saving.
  • Legacy attachments stored without a filename now download instead of opening in the Browser.
  • Home Messages, page alerts, confirmation messages and customized captions are handled more securely when displayed in the Browser. Standard formatting, images and links continue to display normally.
Reporting
  • Report filters containing apostrophes or long values no longer fail or return blank results.
  • Saving a shorter report layout no longer leaves content from the previous layout in the file. Layouts damaged before this update must still be restored from a backup or rebuilt.
  • Report names containing an apostrophe can now be imported.
  • Dashboard requests containing an invalid date range are now refused instead of returning all historical data under an incorrect date heading.
Mobile & Integration APIs
  • Created and modified audit information from offline work is now accepted only from users configured for Mobile access.
  • Notification updates submitted through the API now save the notification body correctly when the text identifier is not included.
Installation & Upgrade
  • Creating a database now displays clear messages for missing, duplicate or invalid database names.

See also:

Copyright © 2020-2026 ToolHound Inc. All Rights Reserved.


How did we do?