Skip to main content
Version: Aeon 7.0

Aeon 7.0.1837

Released September 23, 2026. Accessibility across the web client, lists that hold still while you read, and single sign-on setup from deployment configuration

Highlights​

  • Public URLs come from the deployment configuration only. The Single Sign-On page's override fields and its Restart button, added in 7.0.1828, are gone: the addresses single sign-on is built from come from the deployment configuration only (PublicUrls__ApiBaseUrl and PublicUrls__FrontendBaseUrl, stamped at install or applied on deploy). The Service provider tab shows both addresses and where each came from, warns before you generate a certificate if the API address is still the built-in default, and compares them with the patron web URL on request. On a deployed install the API now refuses to start when either address is missing or invalid, naming the setting to fix, instead of running on localhost.
  • Lists and records hold still while you read them. A queue, a search result set or the user list no longer re-sorts under you when another member of staff saves: rows keep their place and their values update where they sit, while rows arriving, leaving or moving wait behind an "updates waiting" button until you ask for them or move on. An open record updates the same way, and a field you are part-way through editing is never replaced.
  • Live updates can be paused from the status bar. The new Live updates switch beside the connection indicator stops queues, lists and open records refreshing while you work through something. It shows how many updates are waiting so a paused screen never looks like a quiet one, and resuming loads them all at once. If a record you had unsaved edits in changed meanwhile, it asks whether to keep yours or take theirs.
  • Grid views are now full keyboard grids. Arrow keys move between cells, Enter opens the row and Space selects it, and each row now carries one link on its leading column instead of one in every cell.
  • The month and week calendars are keyboard grids. Arrow keys move between days, Home and End jump to the ends of a week, and each day announces its date and how many appointments it holds — with a new button on each day for booking an appointment on it.
  • Dashboard rows can be reordered without dragging. While you are customizing the Queues or Activities tab, each row and category carries a Row actions menu that moves it up, down, to the top or to the bottom — and moves a queue or activity into another category.
  • Single-key shortcuts can be turned off. User Preferences now has a Keyboard shortcuts switch that silences D, R, U, C and A and the J/K list keys, for anyone who uses speech input or finds stray keys navigate away.
  • Your preferences follow your account. Notification settings, in-app message timing and the keyboard-shortcut switch now save to your staff account, so they are the same on every browser you sign in to.
  • Password rules are shown. When no description is configured, the rules the server enforces (length, letter, number and symbol requirements) are listed on the password forms and in the error when a password is rejected.
  • More screens in the command palette. Web Alerts, Billing Accounts, Batch Processing and Release Notes can be reached from the go-to list.

Fixes​

  • Upgrading a multi-site database no longer locks administrators out of the web client. The upgrade now gives every administrator without working site access the All Sites group, fills the empty site groups the Aeon 6 update left behind, and reports at install time if anyone would still be locked out.
  • Appointments stay within the request's site. Assign to Appointment lists only appointments in reading rooms that serve the selected requests' sites, and Aeon refuses any assignment, site change or reading-room change that would pair a request with a reading room that doesn't serve its site.
  • Reading rooms mapped only to other sites stay hidden. A room assigned to another site, with its appointments, exceptions, open hours and sign-in history, is hidden from staff signed into a different site instead of showing as a global room, and appointment actions on such a room are refused.
  • Routing rule edits save. Changes made to an existing routing rule are now saved; before, the editor closed without saving them.
  • Routing rules validate more strictly. Match strings must use only fields, the allowed SQL functions, and comparison keywords; custom-field rules using >=, <=, BETWEEN, or IS NULL now evaluate correctly.
  • Required fields are enforced on save. A field marked Required in the Form Designer now blocks the save when it is empty, with the field marked "This field is required" and the missing labels listed.
  • Custom fields hold their value on new records. Custom-field selections made while creating a user, request, or activity are now saved with the record instead of reverting to the placeholder.
  • Unlock with unsaved changes now asks what to do. Unlocking a request, user, or activity you were editing used to re-lock it immediately; it now offers Save, Discard, or Cancel.
  • Merging users now sends the notification email. With "Send notification email" checked, the MergeUser template is queued to the surviving user with both accounts' details filled in. It was never generated before.
  • Merge warnings are shown on screen. When a merge completes but part of it was skipped, such as the notification email, a warning appears after the success message instead of only being written to the log.
  • User Clearance waits for you to pick a merge target. Choosing an uncleared user lists similar accounts without selecting one, so Merge User stays disabled until you click a match. The Score column is gone; matches are still listed best first.
  • Easier to find User Clearance. It is now linked from the More menu, the Users page, the dashboard's Clearance tab, and the command palette.
  • Signing in with SSO no longer bounces back to the sign-in page when you are already signed in. Opening the sign-in page while a session is still active (a bookmark, or another tab kept you signed in) now takes you straight into Aeon instead of leaving you on a form where the SSO button did nothing until you cleared your cookies.
  • InCommon single sign-on on IIS installs. Federation metadata certificates are held in memory instead of written to the install folder, and pasted certificates may include their PEM BEGIN/END lines.
  • Generated single sign-on certificates now name your server. A certificate generated on the SSO settings page carries the API's public host name and the SP entity ID, the shape federation administrators expect, and uses a 3072-bit key. On a deployed install whose public URL is not configured, generation is refused and the message names the setting to fix, instead of producing a localhost certificate.
  • No more "Send SSO invitation" for accounts already on SSO. The staff editor offers invitations only to Local accounts; an SSO account's identifier is changed directly instead.
  • Emergency-access check says which account to use. The dialog now states the account must be a password (Local) administrator, since an account switched to single sign-on cannot confirm it.
  • Fewer sign-in prompts after a brief connection blip. Restoring a session on page load now retries a transient failure before showing the sign-in form.
  • Re-enrolling an authenticator after an MFA reset no longer fails for users who had used a recovery code. Regenerating recovery codes from user settings had the same failure.
  • Resetting a staff member's MFA now also clears their recovery codes. The next enrollment issues a fresh set.
  • Grid view shows a selected record. Opening a request, user, or activity link while a list is in grid view now shows the record beside the grid; before, the record stayed hidden until the list was switched back to cards.
  • New Activity works from grid view. In grid view, New opens a New Activity page, as do the New menu and the command palette from anywhere; before, the form opened where it could not be seen.
  • Web alert type shows on first open. Opening a web alert for the first time now shows its type and its username or status.
  • Implementation modules work after a queue is renamed. The Photoduplication and Appointments modules now find the built-in queues they route through even when a site has relabeled them, so Apply no longer reports the queue as missing and the module's toggles reflect rules the site already has.
  • Photoduplication "ready for payment" email binds to the right queue. The module bound the OrderReadyForPayment template to a queue that does not exist; it now fires on Awaiting Order Billing.
  • Implementation report. Repeater item labels containing an ampersand no longer show &amp; in the downloaded report.
  • The Alma/Primo Catalog addon now allows the API host you configure. Its proxy allowlist follows the AlmaAPIURL setting, so sites with their own Alma API gateway can import records after updating the addon.
  • Addon settings start with their defaults filled in. Installing or updating a web addon now saves the manifest's default values for any setting you haven't set, instead of only showing them in the form.
  • Sign-in screens scroll when zoomed. The sign-in, verification, SSO and account-setup cards can be scrolled at 200% zoom instead of clipping.
  • Password screens wait for you. Password reset and account setup end on a "Continue to sign in" button instead of redirecting on their own after two seconds.
  • Forgot-password confirmation is announced. The "check your email" message takes keyboard focus and is read out by assistive technology instead of appearing silently.
  • Unconfirmed appointments are marked by more than color. Their calendar chips now carry a dashed border as well as the amber tint, and date pickers underline today and ring the selected day.
  • Calendar view switch shows its selection. The active view uses the primary fill, and the appointment, account and user search boxes are named by their placeholder text.
  • Clearing a search keeps focus. The search box regains focus when its clear button is used, and the calendar overflow popover returns focus to its button.
  • Clone Activity primary-user picker works from the keyboard. Arrow keys move through the suggestions, Enter picks one, Escape closes the list, and a stray click outside the dialog no longer discards your selections.
  • Same action, same name. Save, Clear Form and Back to sign in read the same on every screen, and the activities empty state names the New button.
  • Clearer focus and field outlines. Keyboard focus rings, text-field borders, checkbox and switch outlines, selected rows and small status text now meet WCAG contrast minimums in both light and dark appearance.
  • Named icon buttons and drop-downs. Icon-only buttons and drop-down triggers now announce what they do to screen readers.
  • Renaming a dashboard category saves on click. Clicking the confirm button keeps the new name instead of discarding it.
  • Dashboard rows read as rows. The reorder handle appears on a dashboard row only while you are customizing, so the row is not announced as draggable the rest of the time.
  • Dashboard header wraps. Customize and Done stay reachable when the card header runs out of width.
  • Dashboard panels have headings. Each panel carries its own heading, so screen-reader users can jump between them.
  • Results grid controls named and keyboard-reachable. Column filters, sort state, saved-view pin and delete, and column width are usable by keyboard and announced to screen readers.
  • Designed forms are accessible. Date-time picker parts are named, field warnings show as text, type-or-select fields and form tabs commit on release, and rendered selects announce their labels.
  • Dialogs return focus. Closing a dialog, sheet or confirmation returns keyboard focus to the control you used before it opened, instead of the top of the page.
  • Search dialogs keep what you typed. The bundle, user-search, clone-to-user and user-picker dialogs no longer close on a stray click outside them; Cancel and Escape still close.
  • Filter builder keeps focus. Choosing a field or operator moves focus to the next control instead of dropping it.
  • Hover-only explanations are reachable. The Partial indicator can take keyboard focus and reads its explanation; a disabled Sign In button says why.
  • Icons that carry meaning have text. Checked-out and tour-completed marks, bundle request counts and the issue screenshot now have text equivalents for assistive technology.
  • Missing required fields are now named next to the field. Batch processing, New Request (site), and the appointment dialogs show an inline message instead of rejecting silently.
  • Keyboard-selectable rows. Rows in user pickers, clearance grids, alerts, attachments and similar lists can be reached with Tab and selected with Space or Enter.
  • List shortcuts stay in the list. J and K move the selection only while the list has keyboard focus; arrow keys are unchanged.
  • Lists announce their structure and selection. Request, user, activity, search-result and appointment lists read as lists, and the selected row is announced as current.
  • Loading states labeled. Loading spinners now carry a status role and a label for assistive technology.
  • Your own record locks now look different, not just a different color. A lock you hold shows a padlock with a person on it; a lock held by another staff member stays a plain padlock.
  • Outgoing mail queue switch stays put. Choosing Pending or Failed emails updates the list in place instead of loading a new page.
  • Outgoing mail fits small screens. The mail pages collapse to one pane on narrow screens, the action bar wraps, and the To, CC, BCC and Subject fields are labeled.
  • Screen readers can read the merge and clearance tables. The request-merge comparison, the user-merge comparison, and the clearance grids now announce their columns and row labels.
  • New Request header no longer clips on narrow screens. The site picker and buttons wrap onto a second row at small widths and high zoom.
  • Page titles stay put. Browser tab titles no longer fall back to "Aeon Staff Web" after navigating, and error screens and invalid record links get their own titles.
  • Password fields. The show/hide password toggle is reachable by keyboard, and Change My Password fields tell the browser which password is which.
  • Release notes wrap long keys. Inline configuration keys wrap instead of forcing the page to scroll sideways.
  • Easier-to-grab pane dividers. The divider between panes now responds to the pointer within a 24px band, not just the thin visible line.
  • The reading-room appointment count no longer changes color with load. Every room badge uses one style and simply shows how many appointments are waiting.
  • Row checkboxes stand on their own. The select checkbox on request rows and email cards is no longer nested inside the row link, so Enter and Space reach both.
  • The screenshot editor no longer needs a drag. Crop and redact now take one click per corner, and annotate marks a spot on a single click.
  • Every validation error is shown, not just the first. Rejected saves and searches list each field the server refused, and merging without a target queue now says so instead of doing nothing.
  • Header holds up under larger text spacing. The navigation wraps instead of pushing the New, Process and account controls out of the header, and the status bar fits a 320px window.
  • Sort controls are named. The sort-by button announces "Sort by" and the direction toggle keeps one name with a pressed state.
  • Counts, errors and lock changes are announced. Result and selection counts, load failures and record-lock changes are read out by assistive technology, and an expired lock is reported as expired.
  • The status bar shows the date instead of a ticking clock. The footer now shows today's date next to a calendar icon, with no time counting up every second.
  • Status messages are not lost behind dialogs. A status-bar message raised while a dialog is open stays until the dialog closes and is announced then.
  • Status bar messages follow your message settings. Messages in the footer status bar now use the display time from User Preferences, stay put when "Keep messages until I dismiss them" is on, and carry a dismiss button.
  • Tabs switch on release. Tab strips switch panels when you release the mouse button; with a keyboard, arrow keys move between tabs and Enter or Space selects one.
  • Bigger hit areas. Dialog and toast close buttons and calendar pills reach the 24px target size without a visual change.
  • Messages move out of the way of the keyboard. A message in the bottom-right corner now slides to the other side when it would cover the control you just moved focus to.
  • Every input and control is named. The query-builder value, filter date, category name and photo zoom controls announce their purpose; history sections and bundle choices announce their state.
  • Notifications is now User Preferences. The user menu entry opens the same notification settings, with a Keyboard shortcuts section alongside them.
  • Web-alerts editor scrolls. Each column of the web-alerts page scrolls on its own, so Save and Delete stay reachable under zoom and text spacing.
  • Welcome card steps aside. The first-sign-in welcome card sits above the status bar and moves out of the way when keyboard focus lands beneath it.