blob: 42617c22f66d4daca807b982a06cc10840552a88 [file] [log] [blame]
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -05001.. This work is licensed under a Creative Commons Attribution 4.0 International License.
2.. http://creativecommons.org/licenses/by/4.0
Lorraine Welchf8a5f072020-04-08 16:33:08 -04003.. Copyright 2017-2020 AT&T Intellectual Property. All rights reserved
LF Jenkins CI75b504e2020-04-07 20:25:00 +00004.. _release_notes:
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -05005
6
7Portal Platform Release Notes
8=============================
Lorraine Welchf8a5f072020-04-08 16:33:08 -04009Version: 3.2.0
10--------------
11:Release Date: 2020-05-21
12
13.. toctree::
14 :maxdepth: 1
15
16This release contains an Angular upgrade, bug fixes and security enhancements.
17
18**New Features**
19
20 * Angular Upgrade from 1.X to 7.0 - Portal and SDK (Backward Compatible)
21 * OParent 2.0 Migration & Self Release Jobs
22 * UI/TypeScript Test Coverage - (Portal Coverage 60% and SDK Coverage 63%)
23 * Spring Boot Migration (Portal only/ Partially Completed)
24
25**Bug Fixes**
26
27 * License scan issues addressed
28 * Fixed Sonar reported critical issues.
29
30**Known Issues**
Lorraine Welchd17fae72020-06-08 15:48:58 -040031 * User management pages do not work properly. We will be addressing this in the Guilin release. So, the work around is:
32
33 1. If we try to add user role by navigating directly to an application, like A&AI, we are unable to add roles.
34 2. However, With Portal admin privileges a user (in this case Demo user) can navigate to User screen and select Portal/Default from the drop down.
35 3. Then update user roles for A&AI and other applications in the popup.
36 4. We validated that this operation is correctly updating the role in AAF.
Lorraine Welchf8a5f072020-04-08 16:33:08 -040037
38**Security Notes**
39
40 * Closed HTTP Ports (Portal, SDK)
41 * Address Security Vulnerabilities from Nexus-IQ (Jars and Javascript libraries)
42 * Containers to run as Non-Root user: portal, portal-sdk, portal-widget
43
44*Fixed Security Issues*
45
46 * OJSI-97 - portal-app exposes plain text HTTP endpoint using port 8989 [`OJSI-97 <https://jira.onap.org/browse/OJSI-97>`_]
47 * OJSI-105 - portal-sdk exposes plain text HTTP endpoint using port 30212 [`OJSI-105 <https://jira.onap.org/browse/OJSI-105>`_]
48 * OJSI-106 - portal-app exposes plain text HTTP endpoint using port 30215 [`OJSI-106 <https://jira.onap.org/browse/OJSI-106>`_]
49
50*Known Security Issues*
51
52*Known Vulnerabilities in Used Modules*
53 * Portal was granted a waiver by SECCOM for OJSI-190. Portal stores users passwords encrypted instead of hashed. This was not fixed for Frankfurt.
54
55Quick Links:
56 - `PORTAL project page <https://wiki.onap.org/display/DW/Portal+Platform+Project>`_
57
58 - `Passing Badge information for PORTAL <https://bestpractices.coreinfrastructure.org/en/projects/1441>`_
59
60 - `Project Vulnerability Review Table for PORTAL <https://wiki.onap.org/pages/viewpage.action?pageId=68542388>`_
61
62**Upgrade Notes**
63 * These still apply:
64 1. For https Apps onboarded to portal, a certificate has to be downloaded in the browser when first trying to access the landing page of the App.
65 2. For onboarded Apps using http (since Portal is using https) the browser asks the user to click to Proceed to the unsafe URL.
66 3. For onboarded Apps using http the icon in the URL bar will appear red, click on it and allow unsafe scripts. Different browsers use different methods to accomplish this, Firefox has a security icon near the URL that you can click on "Unblock" and "Disable protection for now"
67 4. The first time some apps are selected in the Applications panel, an error stating the webpage might be temporarily down, copy the presented URL to a new browser; once that is done, the application will open in the Portal.
68
69**Deprecation Notes**
70 * 2.6.0 portal/sdk is the last version to support the old AngularJS UI versions.
71 * Expect upgrade on Angular frontend and SpringBoot backend in next releases: The components like Policy, VID, SDC, AAI, MSB, SO – if any of them use portal/sdk java libraries, then please anticipate MAJOR changes to portal/sdk with respect to technology stack upgrade which is pending for long time on Angular frontend and SpringBoot backend.
72 * The tech stack upgrade helps resolve many security vulnerabilities and also provides latest rich UI and microservices features that components can take advantage of, just by upgrading to latest portal/sdk.
73
74**Other**
75 * Below are the docker images released as part of Portal Platform project:
Lorraine Welch8be1cc02020-06-04 10:40:53 -040076 * onap/portal-app:3.2.3
77 * onap/portal-db:3.2.3
Lorraine Welchd17fae72020-06-08 15:48:58 -040078 * onap/portal-sdk:3.2.0
Lorraine Welch8be1cc02020-06-04 10:40:53 -040079 * onap/portal-wms:3.2.3
Lorraine Welchd17fae72020-06-08 15:48:58 -040080 * portal/sdk java artifacts - (Release branch: “release-3.2.0”; Jar Version: "3.0.0")
Lorraine Welchf8a5f072020-04-08 16:33:08 -040081
Welch, Lorraine (lb2391)0ed78102019-09-13 12:58:31 -040082Version: 2.6.0
83--------------
84:Release Date: 2019-10-03
85
86.. toctree::
87 :maxdepth: 1
88
Lorraine Welch9d9cd782019-10-14 10:04:47 -040089Maintenance release with bug fixes and security enhancements.
Welch, Lorraine (lb2391)0ed78102019-09-13 12:58:31 -040090
91**No New Features**
92
93**Bug Fixes**
94 * Portal Setup - MariaDB issue.
95 * Issue editing application url.
96 * PORTAL-* charts now use nodePortPrefix variable.
97 * Fixed Sonar reported critical issues.
98
99**Known Issues**
LF Jenkins CI75b504e2020-04-07 20:25:00 +0000100 * AAI UI's new role "ui_view" is not registered in AAF, Portal cannot fetch it. So, the work around is
Welch, Lorraine (lb2391)9306dd82019-09-25 14:24:27 -0400101
102 1. upload new role from Bulk Upload in Portal Roles page (create a csv file which has one line like: ui_view,10 )
103 2. Sync Roles on same page
104 3. Assign this ui_view role to demo account in User page
105 4. Then demo user can access AAI UI app from Portal
Welch, Lorraine (lb2391)0ed78102019-09-13 12:58:31 -0400106
107**Security Notes**
Krzysztof Opasiak8d4ac882019-10-05 23:49:14 +0200108
109*Fixed Security Issues*
110
Krzysztof Opasiak33d10dd2019-10-05 23:52:06 +0200111 * CVE-2019-12122 - ONAP Portal allows to retrieve password of currently active user [`OJSI-65 <https://jira.onap.org/browse/OJSI-65>`_]
112 * CVE-2019-12121 - ONAP Portal is vulnerable for Padding Oracle attack [`OJSI-92 <https://jira.onap.org/browse/OJSI-92>`_]
113
Krzysztof Opasiak8d4ac882019-10-05 23:49:14 +0200114*Known Security Issues*
115
116*Known Vulnerabilities in Used Modules*
Welch, Lorraine (lb2391)0ed78102019-09-13 12:58:31 -0400117 * Addressed security issues reported by NexusIQ Critical and Severe issues
118
119Quick Links:
120 - `PORTAL project page <https://wiki.onap.org/display/DW/Portal+Platform+Project>`_
Welch, Lorraine (lb2391)9306dd82019-09-25 14:24:27 -0400121
Welch, Lorraine (lb2391)0ed78102019-09-13 12:58:31 -0400122 - `Passing Badge information for PORTAL <https://bestpractices.coreinfrastructure.org/en/projects/1441>`_
123
124 - `Project Vulnerability Review Table for PORTAL <https://wiki.onap.org/pages/viewpage.action?pageId=68542388>`_
125
126**Upgrade Notes**
127 * For https Apps onboarded to portal, a certificate has to be downloaded in the browser when first trying to access the landing page of the App.
128 * For onboarded Apps using http (since Portal is using https) the browser asks the user to click to Proceed to the unsafe URL.
129 * For onboarded Apps using http the icon in the URL bar will appear red, click on it and allow unsafe scripts.
130 * The first time some apps are selected in the Applications panel, an error stating the webpage might be temporarily down, copy the presented URL to a new browser; once that is done, the application will open in the Portal.
131
132**Deprecation Notes**
Welch, Lorraine (lb2391)9306dd82019-09-25 14:24:27 -0400133 * 2.6.0 portal/sdk is the last version to support the old AngularJS UI versions.
LF Jenkins CI75b504e2020-04-07 20:25:00 +0000134 * Expect upgrade on Angular frontend and SpringBoot backend in next releases: The components like Policy, VID, SDC, AAI, MSB, SO - if any of them use portal/sdk java libraries, then please anticipate MAJOR changes to portal/sdk with respect to technology stack upgrade which is pending for long time on Angular frontend and SpringBoot backend.
Welch, Lorraine (lb2391)9306dd82019-09-25 14:24:27 -0400135 * The tech stack upgrade helps resolve many security vulnerabilities and also provides latest rich UI and microservices features that components can take advantage of, just by upgrading to latest portal/sdk.
Welch, Lorraine (lb2391)0ed78102019-09-13 12:58:31 -0400136
137**Other**
138 * Below are the docker images released as part of Portal Platform project:
139 * onap/portal-app:2.6.0
140 * onap/portal-db:2.6.0
141 * onap/portal-sdk:2.6.0
142 * onap/portal-wms:2.6.0
LF Jenkins CI75b504e2020-04-07 20:25:00 +0000143 * portal/sdk java artifacts - (Release branch: "release-2.6.0")
Welch, Lorraine (lb2391)0ed78102019-09-13 12:58:31 -0400144
Welch, Lorraine (lb2391)9306dd82019-09-25 14:24:27 -0400145
Welch, Lorraine (lb2391)52602972019-05-23 17:45:27 -0400146Version: 2.5.0
147--------------
148:Release Date: 2019-06-13
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500149
Welch, Lorraine (lb2391)52602972019-05-23 17:45:27 -0400150.. toctree::
151 :maxdepth: 1
152
153We worked on SDK upgrade to integrate with AAF. We partially implemented multi-language.
154
155**New Features**
156 * SDK upgrade to integrate with AAF
157 * Use of CADI
158 * 68% JUnit Test Coverage
159 * Addressing security issues
Welch, Lorraine (lb2391)07bcd632019-08-01 11:25:48 -0400160 * Angular 6 upgrade delivered foundation code with sample screen
161 * Documentation on the Angular 6 upgrade can be found `here <https://docs.onap.org/en/latest/submodules/portal.git/docs/tutorials/portal-sdk/your-angular-app.html>`_
162 * Internationalization language support - partially implemented.
Welch, Lorraine (lb2391)52602972019-05-23 17:45:27 -0400163 * Reporting feature enhancement in portal/sdk - design and partial code changes
Welch, Lorraine (lb2391)07bcd632019-08-01 11:25:48 -0400164 * There is more information about new features at `DEMOS - R4 Dublin Demos <https://wiki.onap.org/display/DW/DEMOS+-+R4+Dublin+Demos>`_
Welch, Lorraine (lb2391)52602972019-05-23 17:45:27 -0400165
166**Bug Fixes**
167 * Fixed Sonar reported critical issues.
168
169**Known Issues**
170 * Mismatch while displaying active online user in Portal.
171 * Internationalization Language component partially completed.
172 * Functional Menu change requires manual refresh.
Welch, Lorraine (lb2391)07bcd632019-08-01 11:25:48 -0400173 * Modifying Onboarded App configurations from the onboarding page malfunctions but changes to the App configuration can be done through accessing the database (portal:fn_app table) directly.
Welch, Lorraine (lb2391)52602972019-05-23 17:45:27 -0400174
175**Security Notes**
176
Krzysztof Opasiak53de06c2019-05-24 23:30:00 +0200177*Fixed Security Issues*
178
179*Known Security Issues*
Krzysztof Opasiaka370f0b2019-05-30 15:25:46 +0200180
Welch, Lorraine (lb2391)e98d94e2019-06-11 14:14:22 -0400181 * CVE-2019-12317 - Number of XSS vulnerabilities in Portal [`OJSI-15 <https://jira.onap.org/browse/OJSI-15>`_]
182 * CVE-2019-12122 - ONAP Portal allows to retrieve password of currently active user [`OJSI-65 <https://jira.onap.org/browse/OJSI-65>`_]
183 * CVE-2019-12121 - ONAP Portal is vulnerable for Padding Oracle attack [`OJSI-92 <https://jira.onap.org/browse/OJSI-92>`_]
Welch, Lorraine (lb2391)07bcd632019-08-01 11:25:48 -0400184 * In default deployment PORTAL (portal-app) exposes HTTP port 8989 outside of cluster. [`OJSI-97 <https://jira.onap.org/browse/OJSI-97>`_]
185 * In default deployment PORTAL (portal-app) exposes HTTP port 30215 outside of cluster. [`OJSI-105 <https://jira.onap.org/browse/OJSI-105>`_]
186 * In default deployment PORTAL (portal-sdk) exposes HTTP port 30212 outside of cluster. [`OJSI-106 <https://jira.onap.org/browse/OJSI-106>`_]
Welch, Lorraine (lb2391)e98d94e2019-06-11 14:14:22 -0400187 * CVE-2019-12318 - Number of SQL Injections in Portal [`OJSI-174 <https://jira.onap.org/browse/OJSI-174>`_]
188 * Portal stores users passwords encrypted instead of hashed [`OJSI-190 <https://jira.onap.org/browse/OJSI-190>`_]
Krzysztof Opasiak53de06c2019-05-24 23:30:00 +0200189
190*Known Vulnerabilities in Used Modules*
191
Welch, Lorraine (lb2391)52602972019-05-23 17:45:27 -0400192PORTAL code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The PORTAL open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=51283057>`_.
193
194Quick Links:
195 - `PORTAL project page <https://wiki.onap.org/display/DW/Portal+Platform+Project>`_
196
197 - `Passing Badge information for PORTAL <https://bestpractices.coreinfrastructure.org/en/projects/1441>`_
198
199 - `Project Vulnerability Review Table for PORTAL <https://wiki.onap.org/pages/viewpage.action?pageId=51283057>`_
200
201**Upgrade Notes**
202 * For https Apps onboarded to portal, a certificate has to be downloaded in the browser when first trying to access the landing page of the App.
203 * For onboarded Apps using http (since Portal is using https) the browser asks the user to click to Proceed to the unsafe URL.
Welch, Lorraine (lb2391)e98d94e2019-06-11 14:14:22 -0400204 * For onboarded Apps using http the icon in the URL bar will appear red, click on it and allow unsafe scripts.
205 * The first time some apps are selected in the Applications panel, an error stating the webpage might be temporarily down, copy the presented URL to a new browser; once that is done, the application will open in the Portal.
Krzysztof Opasiak53de06c2019-05-24 23:30:00 +0200206
Welch, Lorraine (lb2391)52602972019-05-23 17:45:27 -0400207**Deprecation Notes**
208
209**Other**
210 * Below are the docker images released as part of Portal Platform project:
211 * onap/portal-app:2.5.0
212 * onap/portal-db:2.5.0
213 * onap/portal-sdk:2.5.0
214 * onap/portal-wms:2.5.0
LF Jenkins CI75b504e2020-04-07 20:25:00 +0000215 * portal/sdk java artifacts - (Release branch: "release-2.5.0")
Krzysztof Opasiak53de06c2019-05-24 23:30:00 +0200216
217Version: 2.3.2
Welch, Lorraine (lb2391)9256cac2019-04-10 18:27:30 -0400218--------------
219:Release Date: 2019-04-15
220
221.. toctree::
222 :maxdepth: 1
223
224This is the official release notes for the Casablanca Maintenance Release 3.0.2.
225
Welch, Lorraine (lb2391)1b9bedf2019-04-15 17:03:25 -0400226**Known Issues**
Welch, Lorraine (lb2391)fd3af2a2019-04-16 15:19:40 -0400227 * The issue is an application running on HTTPS will not open in Portal if the AAF root CA is missing.
Krzysztof Opasiak53de06c2019-05-24 23:30:00 +0200228 An error message will appear in a separate tab in Portal. It will say something like:
LF Jenkins CI75b504e2020-04-07 20:25:00 +0000229 "The webpage at https://portal.api.simpledemo.onap.org:30200/vid/welcome.htm?cc=........ might
230 be temporarily down or it may have moved permanently to a new web address."
Krzysztof Opasiak53de06c2019-05-24 23:30:00 +0200231 Here is the work-around, copy above VID (or other app) URL and replace welcome.htm to login.htm
Welch, Lorraine (lb2391)1b9bedf2019-04-15 17:03:25 -0400232 in a new browser window; after login come back to Portal home page and click VID, it will now work.
233
Welch, Lorraine (lb2391)fd3af2a2019-04-16 15:19:40 -0400234 * For applications running on HTTP (for example SDC), the user needs to disable the security check in the browser to access the application.
235
Welch, Lorraine (lb2391)9256cac2019-04-10 18:27:30 -0400236**Other**
237 * Portal updated Keystore certificate from AAF to extend its expiry date; This change was made in OOM project.
238
Welch, Lorraine (lb2391)2b790b62019-02-06 17:07:48 -0500239Version: 2.3.1
240--------------
241:Release Date: 2019-01-31
242
243.. toctree::
244 :maxdepth: 1
245
246This is the official release notes for the Casablanca Maintenance.
247
248**Bug Fixes**
249 * During installation Maria DB can now be accessed from within the portal-db container. The fix was made in OOM scripts to handle the db issue identified in the previous release.
250
st782s7d4fa6e2018-08-28 12:34:01 -0400251Version: 2.3.0
252--------------
Manoop Talasila0a915d32018-11-12 11:49:01 -0500253:Release Date: 2018-11-30
st782s7d4fa6e2018-08-28 12:34:01 -0400254
255.. toctree::
256 :maxdepth: 1
257
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400258We worked on SDK upgrade to integrate with AAF. We completed Architecture review for Portal and use case UI to support multi-language.
st782s7d4fa6e2018-08-28 12:34:01 -0400259
260**New Features**
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400261 * Platform Maturity Guidelines - Integrating with OOM
262 * SDK upgrade to integrate with AAF
263 * Use of Semantic Versioning - V3 is the supported version
264 * Integration with AAF via REST; Supports both SDK and Framework Applications
265 * 65% JUnit Test Coverage
266 * Addressing security issues
267 * Internationalization language support - design related
268 * Reporting feature enhancement in portal/sdk - design and partial code changes
269 * Platform Enhancements - Improved logging, docker separation, and SDK Simplification
Manoop Talasila2115ee52018-11-15 10:42:08 -0500270 * Angular 5 upgraded with sample POC in SDK to build rich UI
Welch, Lorraine (lb2391)2b790b62019-02-06 17:07:48 -0500271
st782s7d4fa6e2018-08-28 12:34:01 -0400272**Bug Fixes**
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400273 * Improved exception handling in reporting feature and also in login feature while getting a lock from Zookeeper.
274 * Improved documentation to get access to Portal through port 8989.
275 * Fixed Sonar reported critical issues.
276 * Improved OOM deployment 30235 external port mapping for portal-sdk.
st782s7d4fa6e2018-08-28 12:34:01 -0400277
278**Known Issues**
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400279 * Mismatch while displaying active online user in Portal.
280 * UI misaligned on updating widgets in Portal.
281 * On Logout redirect landing page needs to be corrected.
282 * Functional Menu change requires manual refresh.
st782s7d4fa6e2018-08-28 12:34:01 -0400283
284**Security Notes**
285
Manoop Talasila2115ee52018-11-15 10:42:08 -0500286PORTAL code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The PORTAL open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=35522356>`_.
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400287
288Quick Links:
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400289 - `PORTAL project page <https://wiki.onap.org/display/DW/Portal+Platform+Project>`_
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400290
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400291 - `Passing Badge information for PORTAL <https://bestpractices.coreinfrastructure.org/en/projects/1441>`_
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400292
Manoop Talasila2115ee52018-11-15 10:42:08 -0500293 - `Project Vulnerability Review Table for PORTAL <https://wiki.onap.org/pages/viewpage.action?pageId=35522356>`_
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400294
st782s7d4fa6e2018-08-28 12:34:01 -0400295**Upgrade Notes**
Welch, Lorraine (lb2391)9d5f5d62018-10-26 18:13:36 -0400296 * For https Apps onboarded to portal, a certificate has to be downloaded in the browser when first trying to access the landing page of the App.
297 * For onboarded Apps using http (since Portal is using https) the browser asks the user to click to Proceed to the unsafe URL.
Welch, Lorraine (lb2391)2b790b62019-02-06 17:07:48 -0500298
st782s7d4fa6e2018-08-28 12:34:01 -0400299**Deprecation Notes**
300
301**Other**
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400302 * Below are the docker images released as part of Portal Platform project:
Welch, Lorraine (lb2391)9d5f5d62018-10-26 18:13:36 -0400303 * onap/portal-app:2.3.1
304 * onap/portal-db:2.3.1
305 * onap/portal-sdk:2.3.1
306 * onap/portal-wms:2.3.1
LF Jenkins CI75b504e2020-04-07 20:25:00 +0000307 * portal/sdk java artifacts - (Release branch: "release-2.4.0")
st782s7d4fa6e2018-08-28 12:34:01 -0400308
Welch, Lorraine (lb2391)05005db2018-05-30 14:59:48 -0400309Version: 2.2.0
lorraineawelch34712d12018-03-27 16:05:16 -0400310--------------
311
Gildas Lanilis8764d782018-05-31 10:28:40 -0700312:Release Date: 2018-06-07
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400313
lorraineawelch34712d12018-03-27 16:05:16 -0400314.. toctree::
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400315 :maxdepth: 1
lorraineawelch34712d12018-03-27 16:05:16 -0400316
317We worked on hardening the ONAP Portal platform by improving code quality and addressing security issues.
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400318
lorraineawelch34712d12018-03-27 16:05:16 -0400319**New Features**
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400320 * Platform Maturity Guidelines
lorraineawelch34712d12018-03-27 16:05:16 -0400321 * Integrating with MUSIC, OOM, and AAF
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400322 * 50% JUnit Test Coverage
lorraineawelch34712d12018-03-27 16:05:16 -0400323 * Addressing security issues
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400324 * Bootstrapping of VID roles and tighter integration with AAF
325 * Role Centralization capability for framework based partners - design related
326 * Platform Enhancements - Improved logging, Security Hardening, and SDK Simplification
327
lorraineawelch34712d12018-03-27 16:05:16 -0400328**Bug Fixes**
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400329 * Issues with roles fixed in this release.
330 * Now able to deselect widget on Widget catalog page
331 * Replaced the word ECOMP to ONAP
332 * Terminated menu access by App Admin User that are supposed to be available to Portal Admin only
333 * Upgraded software packages to resolve security issues
lorraineawelch34712d12018-03-27 16:05:16 -0400334
335**Known Issues**
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400336 * Need to upgrade to new encrypt/decrypt algorithm in coordination with Partnering apps
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400337 * Logging needs improvement
338 * Not able to delete portal admin user
339 * Add support to connect with AAF Runtime
340 * Portal's SDK UI documentation in ONAP wiki needs samples
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400341 * The Portal/SDK fn_user table has encrypted passwords that need to change to using a hash algorithm
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400342 * UI cleanup needed: on adding entries to News Widget and display on Application Onboarding page
lorraineawelch34712d12018-03-27 16:05:16 -0400343
sa282waa9b3202018-07-25 13:25:43 -0400344**Security Issues**
345 * https://wiki.onap.org/pages/viewpage.action?pageId=27689089
346
Gildas Lanilis8764d782018-05-31 10:28:40 -0700347**Security Notes**
348
349PORTAL code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The PORTAL open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=27689089>`_.
350
351Quick Links:
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400352 - `PORTAL project page <https://wiki.onap.org/display/DW/Portal+Platform+Project>`_
Gildas Lanilis8764d782018-05-31 10:28:40 -0700353
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400354 - `Passing Badge information for PORTAL <https://bestpractices.coreinfrastructure.org/en/projects/1441>`_
Gildas Lanilis8764d782018-05-31 10:28:40 -0700355
Welch, Lorraine (lb2391)1b9c4d32018-10-18 17:05:59 -0400356 - `Project Vulnerability Review Table for PORTAL <https://wiki.onap.org/pages/viewpage.action?pageId=27689089>`_
lorraineawelch34712d12018-03-27 16:05:16 -0400357
358**Upgrade Notes**
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400359 * Upgrades to Portal platform can be performed using Heat based installation scripts available under demo repository.
lorraineawelch34712d12018-03-27 16:05:16 -0400360
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400361**Deprecation Notes**
362 * The encryption algorithm used in Portal is now changed from AES to AES/CBC/PKCS5PADDING.
363
364**Other**
365 * Below are the docker images released as part of Portal Platform project:
Welch, Lorraine (lb2391)05005db2018-05-30 14:59:48 -0400366 * onap/portal-db:v2.2.0
367 * onap/portal-apps:v2.2.0
368 * onap/portal-wms:v2.2.0
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400369 * onap//music/music-cassandra:v3.0
370 * zookeeper:v3.4.0
Welch, Lorraine (lb2391)05005db2018-05-30 14:59:48 -0400371 * portal/sdk - (Release branch: "release-2.2.0")
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400372
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500373Version: 1.3.0
374--------------
375
Gildas Lanilis8764d782018-05-31 10:28:40 -0700376:Release Date: 2017-11-16
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500377
Christopher Lott (cl778h)3b0029e2017-11-15 12:28:15 -0500378The ONAP Portal is a platform that provides the ability to integrate different ONAP applications into a centralized Portal Core. The platform seed code is improved with below listed enhancements in this release. This is technically the first release of ONAP Portal Platform, previous release was the seed code contribution. As such, the defects fixed in this release were raised during the course of the release and while its integration testing. Anything not closed is captured below under Known Issues. If you want to review the defects fixed in the Amsterdam release, refer to Jira (jira.onap.org).
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400379
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500380**New Features**
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400381 * Digital Experience Control/UI upgrade.
382 * Portal Notification Enhancement and act on it w/o copy/paste, e.g. hyperlink to target function with context transfer.
383 * Prepared onboarding App process where the partner is ready for centralized user authentication via AAF.
384 * Source code of Portal Platform and its SDK is released under the following repositories on gerrit.onap.org
385 * portal - (Release branch: "release-1.3.0")
386 * portal/sdk - (Release branch: "release-1.3.2")
387
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500388**Bug Fixes**
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400389 * Onboarding script updated due to user/role integration/synchronization issues with Partner Applications.
390 * Fixed search and remove bugs in Widget Onboarding.
391 * Fixed issues in the Application Onboarding.
392 * Fixed issues in the Microservice Onboarding.
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400393 * Fixed deployment scripts and streamlined the reference variables.
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500394
395**Known Issues**
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400396 * `PORTAL-140 <https://jira.onap.org/browse/PORTAL-140>`_ - Portal role synch error with partner apps.
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500397
398**Security Issues**
Welch, Lorraine (lb2391)f62ab6d2018-09-20 16:45:24 -0400399 * The issue "`PORTAL-137 <https://jira.onap.org/browse/PORTAL-137>`_ -Enhance Authentication" is fixed in Portal and in its SDK. The Portal team recommend partnering apps like Policy, VID, AAI, and SDC to upgrade to SDK's 1.3.2 or latest version to address the login vulnerability.
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500400
401**Upgrade Notes**
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400402 * This is an initial release.
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500403
Welch, Lorraine (lb2391)787573a2018-04-25 18:17:24 -0400404**Deprecation Notes**
405 * This is an initial release.
406
407**Other**
408 * Below are the docker images released as part of Portal Platform project:
409 * onap/portal-db:v1.3.0
410 * onap/portal-apps:v1.3.0
411 * onap/portal-wms:v1.3.0
Christopher Lott (cl778h)6cf15692017-11-08 17:25:29 -0500412
413End of Release Notes