Monday, August 31, 2026
1 change · master
Security fixes and vulnerability patches
Custom signing fields can now be limited to selected user groups instead of being only private or visible to all employees. Sensitive HR-related signing fields are restricted to relevant HR and payroll roles, and only template owners or Sign Administrators can change template access settings.
Original PR description
Before this PR Custom sign field types (`sign.item.type`) were either private to their creator or, if marked `shared`, visible to every internal user. There was no way to make a custom field…
Before this PR Custom sign field types (`sign.item.type`) were either private to their creator or, if marked `shared`, visible to every internal user. There was no way to make a custom field available to specific groups only. After this PR Added a new "Used by" (`authorized_group_ids`) field. Marking a field `shared` still makes it visible to everyone, same as before. Left unshared, you can instead pick one or more groups in "Used by" to make the field visible to just those groups instead of making it fully private or fully public. HR-linked fields (Legal Name, Private City, Country Name, Private Street) are now restricted to Recruitment Interviewer (`group_hr_recruitment_interviewer`) + Payroll Assistant (`group_hr_payroll_user`) via "Used by", instead of being shared. Additionally, in `sign.template` only the template owner or Sign Administrator can edit authorized_ids/group_ids. the "Access Rights" menu item and Authorized Groups field are hidden in the UI otherwise. Task-id: 6425404