🏷️ v3.1.0 — 2026-08-07
🚀 New features
Payhub API
A merged registration edit page has been added, including provider-specific fields and logo display corrections.
Subscription system mapping is now supported, and the development Payhub domain has been aligned with the new setup.
Negative order line amounts are now permitted for Klarna prepayments.
Financing
A back link has been added to the Eurobank onboarding page for easier navigation.
Error messages returned during Eurobank onboarding are now mapped to clear, user-friendly descriptions.
✨ Improvements
Payhub API
The provider name in API response examples is now generated dynamically rather than hardcoded.
All API responses now consistently use camelCase JSON formatting.
Payment descriptions are now forwarded to Paygate, and the sandbox URL has been corrected.
Paygate API
Default validity period handling has been added, and merchant update workflows have been improved.
Financing
The consent confirmation on the LeDoB flow now displays as a text confirmation rather than a pre-checked checkbox.
The Eurobank call-to-action card is now hidden when the LeDoB feature is disabled.
The loan submission success page has been redesigned for a clearer user experience.
Product cards now display horizontally on single-column screen breakpoints.
The business financing header now combines the logo and product name into a single unified element.
Open Banking API
Eurobank corporate consent flows are now routed to the financial simulator in the development environment.
Other changes
Failures when loading Key Vault secrets during parallel configuration startup are now surfaced immediately rather than silently ignored.
🐛 Bug fixes
Payhub API
Users are now correctly created during the subscription registration process.
Provider activation routing and a card overflow display issue in the carousel have been corrected.
Klarna now accepts a broader set of allowed order line types.
Duplicate input fields for Klarna credentials have been removed.
Paygate API
The merchant approval workflow and handling of pending changes have been corrected.
The JSON property name for the error label in cancel payment responses has been fixed.
The IBAN field is now cleared at the correct step when switching payment account types.
Merchant logo audit trail recording and DIAS aggregator credential handling have been corrected.
The merchant creator ID field now correctly accepts null values, and warnings are enforced as errors in the background worker.
Maximum length limits on payment request receiver and issuer fields have been increased.
Open Banking API
The required authentication header for Alpha Bank payments has been corrected.
🔒 Security
Payhub API
Viva ISV credentials are now loaded securely from Key Vault instead of being stored in configuration files.
Paygate callback error responses are now sanitised before being returned to callers.
Response headers have been hardened to reduce unnecessary information disclosure.
An OData filter injection vulnerability in the user audit query has been resolved.
The Paygate registration log Azure Table filter is now parameterised to prevent injection attacks.
Paygate API
The Eurobank API client ID is now stored and loaded from Key Vault.
An OData filter injection vulnerability in the user audit query has been resolved.
Financing
JWT token lifetime is now validated on every authentication request.
The JWT expiration grace period has been removed to enforce stricter token validation.
A per-request Content Security Policy nonce is now enforced, and unsafe inline and eval script sources have been removed.
Existence checks have been added to the data request handler to prevent invalid operations.
Open Banking API
SSL certificate validation bypass has been removed from the Alpha Bank integration.
SSL certificate validation bypass has been removed from the Eurobank adapter.
Sensitive payment data is now encrypted at rest in Azure Table Storage.
Bearer token extraction and parsing have been hardened against malformed input.
An OData filter injection vulnerability has been fixed.
Piraeus Bank payment data is now encrypted at rest using Key Vault envelope encryption.
Bank API credentials have been moved to secure Key Vault loading.