Compose Enterprise - Release notes
This page provides an overview of the most recent features and updates in the Compose Enterprise low-code platform. The version notes provides a description of new functionalities and various bug fixes.
Log in to upgrade to the latest version. You will also find instructions in the upgrade package.
Customers who do not manage the upgrades themselves must contact Compose Support to arrange a time for the upgrade.
Contact our support team at support@usecompose.com if you have any questions.
Version 8.7.11
Lansert Jan 19, 2026
New functionality
New workflow authentication - Feide can now be integrated as an identity provider using OpenID Connect and OAuth2, enabling secure, authenticated access for users in the Norwegian education sector.
The date picker now only accepts dates in the correct format and does not auto-select a date when random digits are entered.
Navigation buttons in the Respondent User Interface can now only be activated with the "Enter" key when the button is in focus.
The loading animation now includes accessible HTML content for screen readers, providing vision-impaired users with information such as extended loading times and system status.
Bug fixes
A bug where multiple clicks on the start button resulted in an error message "Session expired" is now resolved.
A bug where the search field in the workflow builder displayed overlapped content when performing a search is now resolved.
A bug in the text generator builder, where pasting HTML content and switching the syntax highlight to HTML caused the builder to break, is now resolved.
A bug where an invalid name was displayed on the Start Point authentication profile for the Feide login option is now resolved.
Security upgrades
Resolved a security issue by updating the session configuration in
web.xmlto enforce secure cookies. The<secure>true</secure>setting was added to ensure session cookies are only transmitted over HTTPS, improving protection against interception.Directory listings are now disabled in Tomcat when no welcome file is defined.
Server tokens are now disabled in nginx to hide version information and improve security.
Server version information is now suppressed in HTTP headers and error pages to improve security in the Struts-based application.
Version 8.7.10
Released Oct 31, 2025
New functionality
Grafana is now fully integrated as a centralized monitoring platform, providing real-time visibility into VM performance (CPU, RAM, disk, network), Nginx activity, and application Catalina logs. etc.
Workflow Builder (WFB) - Added configuration to skip the start page in workflows with a single authentication method (e.g., ID-porten, BankID), enabling automatic SSO for users already logged in.
WFB: Updated labels to align terminology with 'Start Page' across the interface.
Form Builder: The file upload file size input in the Properties panel is changed from bits to bytes.
Improved backend logging for workflow session timeouts and fixed misleading logging in
RetryUploadAmbassador.Reviewed access logs and configured allowed HTTP methods per environment.
Bug fixes
An issue where users experience a white page after logging in to the Compose Enterprise Builder (Entra ID Signature Failure) has been resolved.
Resolved an issue where data from read-only fields was lost when navigating within a form. Data is now correctly stored in the database after form submission.
Form Builder: Form PDF preview was returning an error when generating previews for certain forms.
Form Builder: Clicking the “User Guide” link in the Dynamic Variable input popup is no longer redirecting the entire page to the documentation site in the same tab, causing unsaved progress to be lost.
Clicking workspaces now displays a proper loading animation, instead of no response.
Error validation in duplicatable groups: When a group is removed and then duplicated (re-added), the error message from the custom validation that was triggered before removing the group reappears in the duplicated group.
Security Upgrades
Mitigated vulnerability to malicious files by allowing only known safe MIME types.
A client-side HTTP parameter pollution vulnerability was identified due to improper handling of URL query parameters. Additional validation measures have been implemented to ensure that only valid HTTP/HTTPS URLs are accepted, including sanitization and rejection of malformed or potentially malicious URLs.
Removed the possibility of injecting arbitrary query string parameters into URLs in the application’s response.
Fixed an issue that could allow CSRF attacks on authenticated users.
Resolved arbitrary CSS injection vulnerability in application responses.
Updated jQuery version in Compose Enterprise.
Version 8.7.9.2 (patch)
Released Jun 3, 2025
New functionality
Version 8.7.9.1 (patch)
Released Jun 3, 2025
New functionality
CORS filter to limit which applications are allowed to continue Compose workflows
Bug fixes
A vulnerability in the the jsessionID parameter for ID-porten authentication is mitigated
Version 8.7.9
Released May 28, 2025
New functionality
Support for Form Data Integration (FDI) has been implemented.
Modified the binary user interface to support form data integration.
User interface for adding and submitting form data.
JSON conversion between frontend and backend.
Service calls to external URLs based on the data structure.
Support for file uploads from both single file upload fields and duplicatable groups.
Metadata handling similar to that in Groovy scripts.
Consistent heading structure (h1 > h2 > h3 > h4) across all pages in accordance with WCAG requirements.
Bug fixes
Autosave now triggers before user interaction to prevent session timeout.
Emails with reference numbers are now correctly sent after "Continue Later" saves, even in workflows with custom designs
Version 8.7.8.1 (patch)
Released Apr 23, 2025
New functionality
Security – Upgraded Apache Tomcat to version 9.0.99 to mitigate vulnerability CVE-2025-24813
Bug Fixes
Fixed issue where display conditions broke inside duplicatable question groups in version 8.7.8
Version 8.7.8
Released Mar 11, 2025
New functionality
New form element: Multiselect dropdown in Form Builder and respondent user interface.
Support for input variables in labels, with real-time reflection and editing capabilities.
"Continue Later" functionality: Autosave enabled for Start and Pause Points in Workflow Builder and respondent user interface.
New activity: E-signing via Posten/Digdir.
PDF generation now supports PDF/A-2b format and read-only PDFs.
Security improvements: Protection against CSRF attacks and jQuery upgraded to version 3.5.0.
Login page update: Eye icon added for password visibility.
New option to customize "browse" label for file uploads.
Improved caching mechanism in Organizer to optimize folder loading.
BankID Signing: Signed documents are now stored as PDFs.
Vipps Payment: Missing transaction text validation added.
Improved system resource management during PDF generation.
Bug fixes
Fixed design issue where login page placeholder overrode saved credentials.
Added error validation when copying elements with empty names in Organizer.
Disabled questions are now correctly excluded from generated PDFs.
Fixed PDF generation failures when attached images are included in forms.
Data Model Script now triggers correctly after focusing on empty input elements.
Alignments fixed for Add/Remove buttons in duplicatable accordion groups.
Correct error handling for invalid session IDs.
Fixed issue causing form freezes when uploading files in Map elements.
'Delete File', 'Delete', and 'Add Group' buttons are now disabled in Read-Only mode.
Related Documentation
Signing with Posten & Posten Signing
Version 8.7.7.1 (patch)
Released Oct 30, 2024
New functionality
Reflect style tags on the confirmation page in the respondent user interface
Handling of Norwegian characters for transaction messages in Vipps Payment in the respondent user interface and workflow builder.
Bug fixes
An Error occurs in the respondent user interface with empty parameters in generic services (POST) calls.
Entra ID - White page after logging in with Entra ID to CE (Signing Redirect Callback failure)
Reduced latency by logging into folders with large capacities.
Backslash in the input field causing the form to crash in the respondent user interface
Design files are not displayed unless you load the workspace folder where the design is located
Version 8.7.6.4 (patch)
Released Oct 1, 2024
Bug fixes
PKCE validation on ID-porten client. ID- porten issue which occurs sporadically.
Version 8.7.4.2 (patch)
Released Sep 23, 2024
Bug fixes
PKCE validation on ID-porten client. ID- porten issue which occurs sporadically.
Version 8.7.7
Released 12 August 2024
New functionality
New Group element feature- Accordion property.
Implement the possibility of referencing request variables in response variable transformation scripts.
Implement index attributes for visible pages in the horizontal navigation menu and progression tracker.
Bug fixes
Groups with display conditions display the group layout and title when the display condition is false.
Changed height and width styling for Script and Text Window size.
The instance creation of duplicatable groups is not reflected immediately.
When using the vertical/horizontal navigation bar - jumps between processes.
An error occurs when a text formatting mask is used in the form.
Accidental Deletion of Pages on Forms.
Related Documentation
https://composetogo.atlassian.net/wiki/x/YQAc
Integrations (Generic Service)
Version 8.7.6.1 (patch)
Released 03 of June 2024
Security Fixes
Many High-risk issues related “Continue later” functionality were fixed.
Vulnerabilities to SQL injection attacks were resolved.
The security issue in the Request Parameter was Fixed.
Version 8.7.6
Released 12 of May 2024
New functionality
Confirmation Window when exiting browser in the RUI (Respondent User Interface).
Increase Script and Text Window size and allow resizing as percentage of screen in form Builder.
Error message when using capital letters while creating variables.
Vipps Payment – Transaction Text support dynamic variables
Bug fixes
Error after multiple clicks while entering a workflow.
Metadata added to pausePoint not automatically added to the DB after versioning.
Confirmation Window when exiting browser in the RUI.
Zabbix alert not generating properly for Multiform.
Returning an exception for unsaved pages when the Preview Form Button is clicked.
Incorrect behavior of Display Conditions in Drop-Down menus in Form Builder.
Update Import/Export Compose Item Button Name.
Related Documentation
Version 8.7.5
Released 26 of March 2024
New functionality
Continue Later - Shortcut for continuing a workflow session without having to manually load the session.
Confirmation Window when exiting browser in the Respondent user interface
Security update
Upgraded Tomcat version to 10.1.5
Bug fixes
RUI-The Validate Form function crashes when the form is re-updated
FormBuilder -The Remove button does not clean all of the Text Box fields related to the Tables and the Group
FormBuilder - Calculation Trigger - Remove button 'breaks' calculation script
FormBuilder - The form freezes when uploading a folder and empty files (0 Kb)
Bootstrap framework doesn't reflect checking/unchecking check-boxes from trigger script
Increase the number of visible fields in the 'Hidden Error Log' of the multiform.