Version 1.3.1: Performance and security fixes
Performance and security fixes
This release contains multiple performance and security improvements, as well as preliminary specifications for upcoming additions to the api.
New releases of our documentation
View All TagsThis release contains multiple performance and security improvements, as well as preliminary specifications for upcoming additions to the api.
The CAR API now supports issuers with external consent directories and external signup URLs. Lookups for these issuers will return true and a YTAConsentTime for recipients with YesToAll activated.
Also included in this release:
With version 1.2.0, CTDs can now use the recipient import feature to batch-upload recipient information directly to CAR. The import/upload endpoint supports gzipped CSV uploads and provides detailed validation feedback.
We've improved error handling during the process of consent recreation.
When a recipient deactivates their YesToAll status, the system will now automatically recreate specific consents for any issuers where the recipient has been part of a lookup during their time with YesToAll. This change allows the recipient to continue receiving e-invoices from these issuers, even after opting out of receiving from all issuers.
Why this change? Previously, deactivating YTA would remove broad consent, but any prior individual consents were lost. This update carefully tracks and restores applicable specific consents, providing a more precise and user-friendly experience.
Extended the system logging to capture additional events.
Added more restrictions for issuer creation
We have implemented stricter validation of request parameters across our APIs.
We've made several improvements to system performance and logging capabilities.
We've made a minor update to the format of the EFIr response.