Aeon 7.0.1828
Released August 12, 2026. Template export/import, batch field updates from addons, and fast identifier search
Highlights​
- Move templates between systems. Export and import individual layout templates (form, card, queue, and activity designers) and email templates as portable files — with Overwrite or Import-as-Copy when a name already exists — or use the new Customization Manager "Template Export / Import" page to package print, layout, and email templates into one file and load them on another system, with a preview of what will be created or updated before anything changes.
- Addons can now add field updates to Batch Processing. The new Batch Field Updates addon lets you configure per-process inputs — a fixed value, a choice list, or free text — that set a request field (for example a delivery location) on every request as it is batch processed, with skip-or-overwrite control and history entries recording each change.
- Field Customizations can now import your field renames from the Windows client — open Customization Manager → Field Customizations and choose "Import from Windows Client" to review every rename found in the desktop client's data, resolve any differences between staff templates, and apply the ones you approve.
- The Single Sign-On page now shows the web addresses single sign-on uses for your system, and lets you correct them — open Customization Manager → Single Sign-On, where the Service provider tab lists the API and staff web client addresses your server is configured with. Enter an address to override one that's wrong, use "Fill in from patron web URL" to derive both from your existing patron web address, and restart the service from the page when a change is waiting to take effect. Saving an address asks for the same emergency-access confirmation as turning single sign-on on, because it changes the addresses your identity provider is told to trust. Single sign-on invitations can now only be sent once single sign-on is switched on — before that, the emailed link can't be completed.
- A request's billing account can now be set from the Billing tab. The new Billing Account selector lists the accounts assigned to the request's user and can be cleared, matching the desktop client. Email template tags for Billing Account ID/Description now have a way to be populated for web-created requests.
Fixes​
- Searching by identifier is now fast on large databases. Pasting a reference number, call number, item number, barcode, username, or email into the search box (Cmd/Ctrl+K or the search page) uses new database indexes to match identifiers by their beginning instead of scanning every request — previously this could take 30+ seconds or time out entirely on systems with hundreds of thousands of requests. When an identifier matches this way, the results show those direct matches; searches that don't look like identifiers (names, title words) behave exactly as before, and identifier fragments that only appear mid-value still fall back to the previous deep search.
- Searches that can't finish quickly now stop early with guidance. A search that would previously hang for 30+ seconds (a partial identifier fragment, for example) is now stopped after 10 seconds, and the search box explains what will find it fast: paste the full identifier or how it begins, target one field with an operator like
ref:, or search within a queue or filtered view. - Search results and a user's request list now update immediately after you route a request. Previously a request routed or cancelled from inside the search page (or a user's Requests tab) kept showing its old queue in the list until the page refreshed.
- Routing a request now returns you to where you came from. When you open a request directly — from a user's request list, a search result, or the dashboard — routing or finishing it takes you back to that previous page instead of an unrelated queue page.
- Sending an email template that routes the request now closes the request like other routing actions. Previously the request stayed open on screen after the email moved it to another queue.
- The transaction-number box keeps focus after you confirm a batch-processing prompt. When processing a request raised a confirmation prompt — such as the "user is not signed into a reading room" warning during Check Out — dismissing it left the cursor out of the transaction-number box, so you had to click back in before entering the next number. Focus now returns to the box automatically, matching what already happens when a request processes without a prompt.
- Addon prompts and alerts now fire reliably when a record is opened from a direct link. Opening a request, user, or activity via a shared URL, a new tab, or a page refresh could intermittently skip the Form Prompts / Form Alerts configured for it, because the record could finish loading before the addons were ready to be told about it. The open event is now delivered once each addon is ready, so prompts fire on every open regardless of how you navigated there.
- Addon fields for a request's linked appointment or activity no longer show placeholder text. Nested sub-objects previously reached addons as the literal string
[object Object]; they are now excluded from the addon field map, matching how user and activity contexts already behave. - Condition values for yes/no fields are now picked from a Yes/No dropdown. In the Form Prompts and Form Alerts settings, picking a Boolean (checkbox) field for a condition previously left the Value as a free-text box, inviting typed values like "true" that older addon versions compared incorrectly. The Value input now offers Yes (checked) / No (unchecked) and stores the exact value the record reports.
- Item Delivered now defaults to editing the delivery email before sending, not sending it automatically. The first time you use the Item Delivered button its email mode is set to "Edit email before sending" so you can review the notification, rather than sending it automatically. Your own choice is still remembered per browser, so change it once from the button's menu and it sticks.
- Upload Item now accepts ZIP files. The electronic-delivery upload allows ZIP archives alongside PDF and image files.
- Action buttons now match the permission their action actually requires, and permission errors read plainly. Eleven controls were offered to roles that couldn't use them (or checked the wrong category): Generate/Update Invoice, appointment Confirm/Unconfirm, the User Clearance page, activity note and attendance deletes, user attachment add/delete, and Cancel Photoduplication / Undo Initialization. Each now gates on the permission its endpoint enforces. Refusals also no longer surface as "Request failed with status code 403" — the client now says the role lacks permission.
- API keys can no longer change customization keys. Customization keys hold deployment configuration — including the web addresses that password-reset emails are built from — so changing them is now staff-only, and API keys are refused whatever their endpoint grants say. This includes existing keys that were migrated with access to every endpoint. API keys are also refused the Implementation setup wizard, whose modules can write customization keys as they run. Reading customization values through an API key is unchanged.
- Request billing account must belong to the request's user or researcher. The API now rejects linking a request to a billing account that isn't assigned to the request's user or researcher, matching the desktop client's dropdown and the bulk-association validity rule. Clearing, and re-linking the already-linked account, remain allowed.
- Request researcher must be a real researcher for that user. Saving a request now rejects a researcher the request's user isn't a proxy for — the same rule the bulk assign-researcher action already enforced — and the researcher picker offers only that user's researchers. Clearing, and re-saving an already-stored researcher, remain allowed.
- Customization Manager no longer shows two "Other" categories. Keys with an empty (rather than unset) category formed a second category also named "Other" in the explorer's navigation tree, logging React duplicate-key errors in the console and making the two same-named sections expand and collapse together. Empty, blank, and unset categories now all fold into the one "Other" bucket (and likewise "General" for subcategories).
- New customization keys can no longer be saved with a blank category or a padded name. Creating a key now trims its name, category, and subcategory and stores blank categories as unset, so every key groups cleanly into the navigation tree instead of persisting an ambiguous empty-string category, and a key can't be created under a whitespace-padded variant of an existing name.
- The Implementation section is now hidden unless Implementation Mode is on. The guided setup experience (dashboard, module wizards, module specs) no longer appears in Customization Manager while the
ImplementationModecustomization key is off, and new installs default the key to off. Turning the key on brings the whole section back. - Staff now see a warning when "Require password change on next login" would have no effect. When user password expiration is turned off (
UserPasswordExpirationEnabled), the user change-password dialog and the New User page show a caution instead of silently accepting a setting the patron would never be prompted by. - Clearer helper text on the Reading Room "Notify on Appointment Request" setting. The checkbox's helper text now reads "Email staff on each appointment request" instead of the ambiguous "Email staff on each request", so it's clear the notification is about appointment requests rather than item requests.
- Form designer previews now show sample values for a request's linked-activity fields. Activity fields placed on the Request form previewed blank in the designer even though they render on real requests with a linked activity.
- Menu scrollbars now use a visible, theme-matched color. Scrollbars in dropdown and popover menus (such as the Route menu's queue list) no longer render with a near-black track and an almost-invisible thumb in light mode. The thumb is now clearly visible and its position shows where you are in a long list.
- Updated the bundled Node.js runtime to 22.23.2 with the July 2026 Node.js security fixes.