Please Review 8.8.0 release notes
Who is this article for?
Administrators responsible for managing Please Review.
IT access will be required to implement this update.
This article includes details on the changes to Please Review 8.8.0 and provides a link with instructions on how to perform the upgrade.
1. Product changes
Mazlan Home enhancements: user deletion, sync and non-email usernames (PR-43204)
What's new: Enhanced integration with Ideagen Hub adds support for non-email usernames and shared email accounts, automated syncing of job titles and account deletions, and improved session reliability across load-balanced environments.
Benefit: Streamlines enterprise user management and onboarding, ensuring seamless, reliable provisioning and lifecycle management across multi-instance estates without manual intervention.
File upload security (PR-42515)
What's new: File upload security and format controls now apply across the entire application, including web interfaces, ingestion APIs, Veeva Vault integrations, comment attachments and nested ZIP archives. Strict format allow lists and header-level magic-byte validation are enforced throughout. Workgroup file format settings now use a clear, categorised checkbox interface, with improved upload errors offering actionable guidance.
Benefit: Protects Please Review from malicious uploads and extension spoofing, simplifies format management for administrators, and provides consistent security and clearer feedback across review and integration workflows.
2. Software improvements
| PR Code | Description |
|---|---|
| PR-43910 | Fixed an issue where an extra '=' symbol appeared in email notification content and non-ASCII characters were corrupted. |
3. Known issues
Cascade logout in Offline Client and Word Plugin
If both the Offline Client and Word Plugin are open during a cascade logout, the second application may display a “WebView2 Initialization Error” if the Hub login form remains open in the first.
Close the Hub login form before completing the logout, upload or publish action in the second application.
Owner password download blocking on AES-128 encrypted PDFs
When owner-password-protected PDF downloads are blocked, legacy AES-128 (Revision 4) PDFs containing redactions or comments may still download instead of displaying the blocking prompt. This is due to a PDF engine limitation when distinguishing owner and user authentication without credentials.
Use modern encryption, such as AES-256 (Revision 6), to enforce download restrictions.
File extension renaming in Veeva Vault integration
When creating a review or uploading formats such as .xls, .dot, .pps, .pot or .jpeg through the Veeva Vault integration, the extension may change because it is resolved from content-type metadata.
To prevent upload rejections, configure only permitted formats in Enable file formats for upload. Contact Ideagen Support if application-level configuration is required.
Missing error message when attaching a blocked file to a comment
Unsupported, disabled or incorrectly named files attached to general or header/footer comments may be blocked without an error message. The comment is created without the attachment.
Use supported, enabled formats and do not rename files to change their extensions. Confirm that the attachment is present after creating the comment.
4. Known behaviours
ZIP file upload when starting a review in Veeva Vault
When starting a Please Review review from Veeva Vault with an uploaded ZIP file containing supported document formats, an "Upload blocked" error message will appear. This happens because file format validation in the Veeva Vault integration is unable to resolve the underlying file extensions within the ZIP archive.
To resolve this, extract the archive contents and upload or add the individual supported files directly before starting the review.