XPressEntry Desktop

Release Notes

3.7.7699

August 14, 2026 3.7.7699

XPressEntry 3.7.7699


This release focuses on muster and occupancy accuracy, single sign-on, and keeping every open

client in step with the server. It also adds three new access control integrations and replaces the

facial recognition engine.


Highlights


Muster and occupancy counts are accurate again

Several separate causes were making headcounts wrong. Re-badged users were dropped from occupancy by

a lookup filter, soft-deleted rows were still being counted, OnGuard occupancy was compared against

the wrong timestamp, and deleting a user through a data manager left their occupancy row behind.

Live muster and occupancy updates now also carry the badge number and reader name.


OAuth and OIDC authentication

XPressEntry can authenticate against an OAuth or OIDC provider, with scope, audience, issuer and

refresh token settings. LDAP and OAuth secrets are encrypted at rest, and provider changes take

effect without a restart.


Push-to-Talk

Readers can join named audio channels and talk to one another, with one speaker at a time per

channel. Channels and their reader assignments are managed from a new setup screen that shows which

readers are online and who is currently speaking.


A new facial recognition engine

Facial recognition now runs on telaeris_vision with a lighter, more accurate model and aligned

embeddings, and ships in the installer. The separate FaceRecognition application has been removed.


Three new integrations

Avigilon Alta, IN.Gov, and DOORS.NET.


Muster and Occupancy


  • Re-badged users are no longer dropped from occupancy, so muster counts include them.
  • Soft-deleted occupancy rows are excluded from muster counts.
  • Deleting a user through a data manager now clears their occupancy record.
  • Live muster and occupancy updates include the badge number and reader name.
  • Scans denied at a muster reader are flagged, so a user who was refused entry is not silently

counted.

  • A new Past Muster form lets you review previous muster events.
  • Muster and occupancy changes now push to open clients as they happen.
  • The External Muster Activity Sync setting has been renamed and now defaults to Always.
  • Reader profile data loads at startup, so the Muster node appears without opening settings first.
  • Muster map default queries have been updated.

Users, Badges and Enrollment


  • Badges can no longer be saved with an expiration date before their activation date.
  • Adding a new user no longer deletes the previous user's custom field values.
  • Badge printing gained a print preview, and the badge printer list is populated correctly.
  • Enrollment forms use the configured thumbnail size and quality.
  • Visitor and host checkboxes now behave as mutually exclusive toggles.
  • Clicking Add New clears the selection in the left-hand list.
  • Reader profiles gained an unauthorized user mode.
  • The default Wiegand format is chosen from a list instead of typed free-hand.
  • Reader names that collide are numbered from the name you provided.
  • Reader validation and the occupancy Edit User screen were corrected, and the Random Badge

Challenge percentage is now described accurately.

  • Deleting a timezone cascades to the records it owns instead of leaving orphans behind.
  • Deleting and restoring records with dependents works correctly.
  • Fixed errors on the Events page attendee list, including a crash when filtering.

Map Views


  • Map view summaries support a separate background colour, which is included when the map syncs.
  • Map view objects can be excluded from the map, and the editor preview honours that setting.
  • Zooming a map view no longer shows a stale image.
  • Map views load correctly against older database schemas rather than failing outright.

Keeping Clients Up To Date


  • User and badge changes refresh in open clients immediately, including in a record that is already

open for editing.

  • Settings and authentication provider changes apply in memory without a restart.
  • Deleting a picture now propagates to handhelds.
  • The "Settings Changed Externally" prompt no longer appears twice.

Sync Summaries


  • Sync summaries can be purged automatically, keeping the table from growing without bound.
  • Exporting sync summaries is paged, so large exports no longer time out at 30 seconds.
  • A finished sync appears at the top of the grid as it completes, without losing your selection.

Security


  • Fixed a SQL injection vulnerability in handheld badge enrollment.
  • Fixed a SQL injection vulnerability in the equipment occupants endpoint.
  • Credential hash comparison is constant-time.
  • Fixed a path traversal vulnerability in upload handling.
  • Reader credentials are generated with a cryptographically secure random number generator.
  • LDAP and OAuth secrets are encrypted at rest.

Sign-in


  • Login errors are shown on the login screen instead of being discarded.
  • Fixed an intermittent login failure at startup when the service port was not yet listening.
  • Fixed login for non-joined domains.
  • Legacy HTTP authentication settings are supported for existing deployments.

Settings and Configuration


  • Settings import and export now cover custom fields, OAuth and LDAP configuration.
  • All settings are editable from the Config Tool.
  • SQL Server connections can require encryption, with a Trust Server Certificate option.
  • Sync buttons are disabled when their corresponding sync option is unchecked.
  • The Data Manager node reappears after clearing a settings filter.
  • The custom display logo picker accepts PNG files and rejects oversized images.

Config Tool


  • The Config Tool is now authoritative over the web console's environment file, rather than

depending on the installer to write it.

  • More web console settings are editable, including mail settings, TLS options, public scheme and

port.

  • Email settings configured in XPressEntry are synced to the web console.
  • Status messages appear in an inline banner instead of interrupting with pop-up dialogs.
  • The collation check no longer blocks on a minor collation difference, warning instead.
  • Fixed web console configuration generation when the install path contains spaces.
  • Fixed schema mismatches on SQL Server installations using a non-default schema.

Performance and Stability


  • Fixed three faults in the reader connection pipeline: the listener could stop accepting new

reader connections, reader status updates could be dropped without warning, and the reader status

screen could freeze.

  • The server no longer halts on debug break statements left in production code paths.
  • Data manager log output no longer degrades the interface during heavy sync activity.
  • Large database imports no longer time out.
  • Disconnected clients are evicted correctly instead of blocking notifications to everyone else.
  • Errors now raise general alarms.
  • Updated XPressReports to resolve an authentication incompatibility that prevented reports from

loading.


Reporting


  • Added a Logins pivot table.
  • Fixed percentage calculations, timezone handling and password masking in the diagnostic report.

Removed


  • The Messages feature has been removed.
  • Manual Enter/Exit Users menu items and forms have been removed.
  • The deprecated legacy HTTP server has been removed. Deployments using it should move to the

current API.

  • The standalone FaceRecognition application has been removed, replaced by the telaeris_vision

engine described above.


Integrations


OnGuard

  • Fixed a timeout that went unhandled during session token checks.
  • Occupancy sync is limited to the activity look-back window.
  • Occupancy timestamp handling corrected, fixing headcount discrepancies.
  • Software events no longer write badge activities when activity sync is turned off.
  • Access levels can be filtered by panel selection, and the panel filter can be searched by name.
  • Durable OpenAccess subscriptions are removed on permanent teardown.
  • Activity and occupancy options were consolidated in the setup screen, removing duplicate

checkboxes.

  • Fixed subscription filtering and casing errors in hot-event recovery.
  • A full sync no longer aborts when a badge download returns partial results.

Brivo

  • Cardholders can be filtered by site access, and unknown users can be pulled on scan.
  • Added site partitioning and user custom field mapping.
  • Activity and occupancy timestamps display in local time rather than UTC.
  • Fixed a crash during activity sync when mapping activity data.
  • Token refresh recovers on its own after an invalid grant.

CCURE 9000

  • Clearance doors load correctly.
  • Fixed a crash during setup when a custom field had an empty external ID.
  • The embedded CCURE Connector Service has been removed; the REST connection now defaults to port

9501.

  • Installer fixes for shipped components.

Avigilon Unity (ACM)

  • Optionally pulse the door relay on a handheld scan, with a muster pulse toggle and per-door relay

filter.

  • Fixed activity polling missing scans that occurred on the watermark second.

Avigilon Alta

  • New data manager, with MQTT support and activity sync.

Galaxy

  • Fixed expiration dates not being sent.
  • Fixed activity sync never completing.
  • Fixed crashes caused by activity timestamps and empty muster reader IDs.

Honeywell Pro-Watch

  • Support for Pro-Watch API 7.0, including live events and data change notifications.
  • Improved reliability under load and safer handling of sync data.
  • Added credential protection on login for both DTU and REST.
  • Handheld button behaviour is configurable from the reader profile.
  • With No Groups Data enabled, full and partial syncs no longer create group memberships.

Autec

  • Fixed a sync delay and an authentication retry failure.
  • Profiles sync from all CMM panels rather than masters only.
  • Improved error reporting and login refresh.

AEOS

  • Fixed user and badge event parsing.
  • Fixed settings being corrupted during migration.

BioStar

  • User start and end dates and badge expiry dates map correctly.
  • Fixed date parsing on systems with a non-English regional format.

Genetec

  • Fixed a failure on systems with a conflicting Newtonsoft.Json version installed.
  • Fixed RIO login sending credentials with the wrong content type.

Amadeus

  • Card codes are assigned to the badge number exactly as provided.
  • Fixed event payload handling and cardholder card retrieval.

Bosch and Kantech

  • Fixed a crash during sync introduced by a change to how sync context is passed.

Frontier

  • Muster scans are sent as egress on single-sided doors.

RS2

  • Auto-exit hours are checked before occupancy is updated.

Spica

  • Fixed access denials being recorded as granted.
  • Fixed crashes during activity mapping and occupancy updates.
  • Removed a SQL injection risk in event processing and duplicate-activity checks.
  • A failed sync now reports failure instead of always reporting success.
  • Fixed a potential deadlock during status checks and a database connection leak while retrieving

activities.


Verkada

  • Optional verbose API request and response logging for troubleshooting.

ZKTeco

  • Kiosk settings for door unlock and Wiegand output.

DOORS.NET

  • New integration.

IN.Gov

  • New integration.

Other Fixes


  • Custom field values populate correctly after a data manager sync writes new records.
  • Added a unique index on time card activities.
  • Database schema kept in step with the web console for employee type, default work codes and time

card notes.

  • Fixed a database migration that could fail when run twice.

Available Builds

Build Number Name Description Date Downloads
#7709 3.7.7709 No description August 20, 2026
#7708 3.7.7708 No description August 20, 2026
#7707 3.7.7707 No description August 20, 2026
#7706 3.7.7706 No description August 18, 2026
#7699 3.7.7699 No description August 14, 2026
#7454 3.7.7454 No description May 7, 2026
#7240 3.7.7240 No description January 26, 2026
#7191 XPressEntry Desktop: 7191 No description January 5, 2026
#7187 XPressEntry Desktop: 7187 No description January 5, 2026
#7000 XPressEntry Desktop: 7000 No description January 5, 2026
#6952 XPressEntry Desktop: 6952 No description January 5, 2026
#6896 XPressEntry Desktop: 6896 No description January 5, 2026
#6870 XPressEntry Desktop: 6870 No description January 5, 2026
#6801 XPressEntry Desktop: 6801 No description January 5, 2026
#6786 XPressEntry Desktop: 6786 No description January 5, 2026
#6647 XPressEntry Desktop: 6647 No description January 5, 2026
#6645 XPressEntry Desktop: 6645 No description January 5, 2026

Related Products