Stylus SFTP Server リリース

各リリースの最新情報を、機能・強化・解決済みの課題の詳細とともに確認しましょう。

1月
2月
3月
4月
5月
6月
7月
8月
9月
10月
11月
12月
Stylus SFTP Server 1.0.0.7652026年9月12日
機能
  • The administration console now answers at /admin:
    • The web root shows a short product page instead of opening the console, so the address of the server is no longer the address of its administration. Bookmarks pointing at the root need updating. The File Portal and the Knowledge Base keep the addresses they had.
修正
  • The server never announced that a new version was available:
    • Every check for new releases was refused by the website, so no notification was ever shown. The check now sends a request the website accepts.
Stylus SFTP Server 1.0.0.7642026年9月11日
修正
  • A virtual folder whose location no longer exists could make the whole root directory unlistable over SFTP:
    • When the directory behind a granted folder was moved, renamed or entered incorrectly, an SFTP client listing the root was told "No such file or directory" for the root itself, so every other folder in it became unreachable as well. The Web Portal listed the folder but could not open it, and the broken folder also hid any folder of the same name in the user's own home. A folder the server has found missing is now left out for the user over SFTP, FTP, WebDAV and the Web Portal alike. Administrators still see it marked missing, and it reappears on its own once its location is corrected.
  • The Web Portal reported unrelated errors as a storage database problem:
    • When a folder could not be listed, the portal replaced the server's explanation with a generic "The server is waiting for the storage database" notice, even though the database was fine. The portal now shows the reason the server gives.
  • The command-line installer now defaults to the embedded database for user accounts:
    • Previously command line installer defaulted to the file based provider. A provider given explicitly on the command line is unaffected.
  • Real-time updates now work when the console is served over HTTPS:
    • Browsers blocked the notification connection on HTTPS pages, so live updates silently stopped. Notifications now use the same address, port and certificate as the console.
Stylus SFTP Server 1.0.0.7592026年8月21日
機能
  • The server refuses connections cleanly when it is at capacity:
    • Under more simultaneous sign-ins than the machine can service, new connections were queued behind the key exchange, which is the most expensive part of a login and is limited by CPU rather than by threads. The server now turns away new handshakes above its configured capacity with an immediate refusal instead of accepting work it cannot finish, so clients get a fast, clear failure and the sessions already in progress are not slowed down. The <threading><io-threads> setting is now applied to the network layer as well.
  • LDAP timeouts are set from a single time budget:
    • <authentication-time-budget-seconds> in the <ldap> block bounds how long one authentication may take in total, including the automatic retry; the connect and read timeouts are derived from it as percentages (<connect-timeout-percent-of-budget>, <read-timeout-percent-of-budget>) rather than being set individually. Default 5 seconds. The individual timeouts could previously be combined into a total far longer than intended, which is what a user experiences as a sign-in that hangs.
  • The command-line installer can install the Web Admin Console:
    • A scripted installation can now deploy the Web Admin Console in the same pass as the server, with --adminconsole and an optional --adminport (9980 by default). Previously the command-line installer always produced an SFTP-only installation and the console had to be added afterwards by running the installer a second time with --add-admin-console. That second pass still works and is unchanged; unattended installations no longer need it.
  • The time the server waits for the authentication provider is now configurable:
    • Set <provider-timeout-seconds> in the <user-manager> block of sftp-server.xml. The default is now 5 seconds, raised from 3: a directory or database that answers slowly under load was being given up on too early, and the sign-in refused for a reason that had nothing to do with the credentials. Sites with a distant domain controller can raise it further.
  • The server records its process id:
    • A running server writes server_pid.txt in the data directory and removes it on shutdown, so scripts can find and stop the right process rather than searching the process table. The file is rewritten on every start and is safe to delete while the server is stopped.
修正
  • A directory outage was still reported as a wrong password on LDAP and flat-file installations:
    • The previous release separated "these credentials are wrong" from "we could not check them", but only on installations using a JDBC user manager. LDAP and users.xml installations kept the original behaviour: an unreachable directory produced the same audit record and the same message to the client as a mistyped password, so operators looked for a user problem while the directory was down. All four affected paths — password and public key, both provider types — now record the new AUTH_PROVIDER_UNAVAILABLE audit event and log at error level. The sign-in is still refused, which is the only safe answer, and it is still never counted toward account lockout.
  • Organizations and groups were unavailable on LDAP and flat-file installations:
    • The tables behind the identity model — organizations, groups, group membership, folders and folder permissions — were created only when a JDBC user manager was configured. An installation authenticating against LDAP or users.xml never got them, so the admin identity commands had no database to work against. They are now created in the administration database on those installations. Nothing moves on an installation that already had a JDBC user manager: there the identity tables stay exactly where they are.
  • Security
    • The server could lose its host key and present a new one on the next start:
      • On some systems the Ed25519 host key was written as an empty file while the log reported that the key was ready. A host key that was never persisted is regenerated at the next start, so every client is told the server's identity has changed — which is what a client is meant to see during an interception attempt, and which stops SFTP clients and scripts until someone accepts the new key. The key is now generated and stored by one implementation throughout, and a host key that cannot be written stops the server instead of being reported as a success. Most visible on ARM64 systems.
Stylus SFTP Server 1.0.0.7282026年8月12日
機能
  • Virtual folders over WebDAV:
    • Folders granted to a user now appear and work over WebDAV exactly as they do over SFTP, FTP and the Web Portal — listed at the root alongside the home directory, browsable, and readable and writable according to the grant. Previously a user could see a granted folder over SFTP but not over WebDAV, and a file uploaded by WebDAV into such a folder was written to the user's home directory instead. Requires the mount-routing option that already governs the Portal.
  • Failed notification emails are retried:
    • If the mail server is unreachable when a notification is sent, delivery is now retried three times, thirty seconds apart, instead of the message being dropped after a single attempt. The retry state is held in the database, so pending notifications survive a server restart, and one unreachable address cannot delay notifications to anyone else. A notification abandoned after the final attempt is recorded in the audit trail rather than only in a log file.
修正
  • Installing onto a disk without enough space:
    • The installer now checks free space before writing anything and stops with a clear message naming the location, the space required, the space available and the shortfall. Previously it began extracting, ran out of room part-way through, and stopped with a raw error, leaving a partially written installation behind.
  • Faster sign-in:
    • Authenticating a user took four database queries where one suffices — the account was looked up twice, and each lookup also fetched public keys that password sign-in never uses. Over LDAP it meant two directory searches per sign-in instead of one. This is most noticeable when many users connect at once.
  • Larger default database connection pool:
    • The default max-pool-size for the user and audit databases is now 10, up from 5, which suits servers handling many simultaneous sign-ins. Existing installations keep their configured value; the new default applies to new installations.
  • Security
    • A database problem could be reported as a wrong password — and count against the account:
      • When the user database was slow or unreachable, the server could not check the credentials, yet answered the client as though they were invalid and incremented the account's failed-login counter. Under sustained load that could push a valid account into lockout: an outage escalating into users being locked out of their own accounts. The server now separates "these credentials are wrong" from "we could not check them". The connection is still refused — failing closed is the only safe answer — but the event is logged as an infrastructure fault, is never counted toward lockout, and says so explicitly in the server log.
    • Account lockout could be bypassed for LDAP and flat-file accounts:
      • On the standard authentication path, the lockout check was skipped for accounts from providers that do not use database identifiers — LDAP and users.xml. A locked account presenting a valid password was admitted. Lockout now applies to every provider on every path, and is checked before the password is verified so a locked account no longer consumes server CPU on each attempt.
Stylus SFTP Server 1.0.0.7142026年8月5日
機能
  • Update notifications. The server now checks periodically whether a newer version has been published and shows a dismissible "New version available" notice - on the Web Admin Dashboard, the desktop console's Server tab, and via admin update-status on the command line - listing the actual changes between the version you are running and the latest release, with a download link. Display-only: the server never downloads or installs anything by itself. On by default; disable with <update-check><enabled>false</enabled></update-check>. Privacy, in full: the check is one HTTPS GET of the public release-notes feed every six hours, sending no license key, no build number, and no installation identifier.
  • Release notes feed. Stylus Studio's release notes are now published in machine-readable form at release-notes.xml - the same document that generates their release notes page. It is what your server reads to power the update notice.
Stylus SFTP Server 1.0.0.7072026年8月4日
機能
  • Realtime everywhere - polling is gone. A WebSocket notification hub now runs inside the server, and every surface updates by push: the Web Admin, the Knowledge Base, the File Portal, and the desktop admin. Sessions appear the moment a user connects, audit rows stream in live, and a change made in one admin tool shows up in the others instantly - no refresh timers anywhere in the product. A new server-side folder monitor also detects files placed into virtual folders from outside the server (Windows Explorer drops, downstream jobs), so Portal users see them appear in real time. The hub is on by default and failure-isolated: if it cannot start, the server boots normally and the consoles fall back gracefully.
  • Knowledge Base - per-page "Block AI Agent access." Editors can mark a page off-limits to AI agents. Requests authenticating with an API token or OAuth cannot read, update, or publish a blocked page; search and topic listings omit it entirely. Only a signed-in person can change the flag - an agent cannot unblock itself, and reverting a page to an older version cannot resurrect an unblocked state. Blocked pages are additionally served with X-Robots-Tag noai/noindex and a configurable crawler User-Agent denylist, and every change is audited.
  • Database backups on demand. Back up every configured database, online and with no downtime, from any admin tool: the Web Admin's Database tab, the desktop admin's "Back Up Now", or the CLI (admin backup-db / admin list-backups). Backups land in db.backup/ as one zip per database and are recorded in the audit log.
修正
  • Upgrades can no longer corrupt the embedded database. The installer now takes a mandatory full backup of all databases before an upgrade proceeds (upgrade aborts if the backup fails), verifies every database file is free before touching it, and stops services in a safe order so the database always closes cleanly - each process now logs databases closed cleanly on shutdown. This closes the root cause of a field incident where an interrupted close during an upgrade could silently revert the database to an old state.
  • SFTP traffic now shows in the bandwidth charts. The Dashboard and Activities throughput charts previously counted only Portal and FTP transfers; SFTP - typically the bulk of the load - was invisible. Every SFTP byte is now metered.
  • Desktop admin launch reliability. A startup crash could kill the admin GUI with no window and no message. The crash is fixed, the GUI now writes a log (data/logs/admin-gui.log), and unexpected errors are reported instead of dying silently.
  • Installer upgrades now refresh the bundled Java runtime. Previously an upgraded installation kept running the runtime from its original install indefinitely.
Stylus SFTP Server 1.0.0.6752026年8月1日
機能
  • Check Folders - folder health on demand. A new button in the Virtual Folders toolbar of both admin consoles runs the folder-health check immediately and reports the OK/MISSING counts, instead of waiting for the periodic five-minute cycle. Also available as admin folder-check from the command line.
  • Folder-health audit trail. When a virtual folder's backing directory disappears - or comes back - the server now records it in the audit log (FOLDER_HEALTH_MISSING / FOLDER_HEALTH_RESTORED), so an outage that self-heals overnight is still visible the next morning. Events fire only on state changes and record who or what triggered the check.
  • Virtual Folders filter. A filter box in the folder toolbar narrows the list as you type, matching the logical path or the real path - find a folder by either side of the mapping. Also on the CLI: folder-list --filter.
  • SSH host private keys are locked down on disk. Host keys are now restricted to the system, administrators, and the server's own service account the moment they are created (owner-only permissions on Linux). Older installations left host keys readable by any local user through inherited folder permissions; the server now re-hardens existing keys automatically at every startup. If hardening would ever lock the service out of its own key, the server keeps the key readable and logs the problem instead of failing to start.
修正
  • Virtual-folder health monitoring now runs. The STATUS column in folder-list and the folder-health indicators in the admin consoles are now live: each virtual folder's backing directory is verified at server startup and re-checked every five minutes, so a folder whose disk path has been removed or unmounted shows MISSING within minutes - and returns to OK when the path comes back. Previously the health status was never updated and always showed unchecked.
  • Audit filter tidy-up. The Event Type filter on the Web Admin's Audit tab now lists event types alphabetically.
Stylus SFTP Server 1.0.0.6642026年7月31日
機能
  • File Portal - "Expires" column. Each file now shows the date it will be removed under its folder's content-retention policy, so users can see at a glance what is scheduled for deletion. Files due today are flagged, and folders without a retention policy show no date. The date is resolved from the folder that actually owns the content, so it is correct even when the file is reached through a parent directory.
  • Upload rename patterns. The <rename-pattern> setting now takes effect on every upload path - SFTP, FTPS, WebDAV, and the web portal. A completed upload's final name is built from ${basename}, ${filename}, ${ext}, and ${username} - for example ${username}_${basename} to prefix every file with the account that uploaded it. The default keeps the client's original filename, so existing installations are unaffected.
  • Account lockout is now enabled by default - five consecutive failed sign-ins lock an account for 30 minutes, providing protection against password-guessing out of the box. Any threshold you have already configured is respected.
Stylus SFTP Server 1.0.0.6602026年7月28日
機能
  • AI Integration - Knowledge Base MCP server. The Knowledge Base speaks the Model Context Protocol: AI assistants such as Claude Code and Claude Desktop can search, read, and (with a write-scoped token) author knowledge content. Eight typed tools, per-user access tokens, and the same organization/group ACL as interactive sessions.
  • OAuth 2.1 for the MCP server. MCP clients authorize with a browser sign-in using their SFTP credentials (MFA enforced when enrolled) instead of a pre-shared token - full authorization-code flow with mandatory PKCE, single-use codes, and rotating refresh tokens. Registering the endpoint without a token now "just works".
  • New "AI Integration" admin page across Web, desktop, and CLI: a master enable switch for the MCP endpoint, ready-to-copy client-registration instructions, and API-token management. AI-authored page edits are tagged in the page version history.
  • Knowledge editor. Mermaid diagrams, YouTube and video embeds, twelve additional syntax-highlighting grammars, drag-and-drop content ordering, and a simplified editor toolbar.
修正
  • SFTP host keys now persist in the writable data directory (RSA + ECDSA + Ed25519) instead of the read-only install root - no more "host key changed" prompts from WinSCP and other clients after a reinstall.
  • MFA enrollment issuer includes the server host (e.g. "Stylus SFTP Server (sftp.example.com)") so accounts enrolled on different instances stay distinct in the authenticator app.
  • Knowledge audit-coverage gaps closed, plus editor polish: toast clipping, phantom scrollbars, in-place hyperlink editing, and highlight-color persistence on save.
Stylus SFTP Server 1.0.0.6152026年7月24日
機能
  • Knowledge Base - full authoring and reader platform. A rich page editor (styles, syntax-colored code snippets, tables with CSV import/export, images, file attachments, and an embedded draw.io diagram editor), page version history with side-by-side compare and revert, and per-organization content segregation. New "Knowledge Base" chapter in the User's Guide.
  • License management from the admin console. View, replace (paste or upload activation.key), or clear the license from the Web admin, desktop console, and CLI - no more stopping the service and hand-copying files. Old keys are archived automatically and every change is audited.
  • Knowledge reader ACL is now enforced uniformly across the topic tree, page reads, and search; draft pages are hidden from readers.
  • Knowledge - Portal single sign-on: a signed-in Knowledge user reaching the file portal is admitted automatically, with authorization unchanged.
Stylus SFTP Server 1.0.0.5232026年7月23日
機能
  • Content Retention - per-virtual-folder aged-file deletion. Each virtual folder gains an optional policy: retention days, a CREATED-vs-MODIFIED anchor, recursive-vs-root-only scope, and an optional path regex. Deletion is a two-step move-then-reap with a 24-hour grace bin, so an administrator can Restore or Delete Now before a file is gone for good.
  • A new "Content Retention" admin tab (Web, Swing, and CLI) shows the worker schedule, a live grace-bin countdown, and run history, with a Run Now button and four dedicated audit events. Off by default and available on every edition - compliance, not a paid tier.
Stylus SFTP Server 1.0.0.5122026年7月21日
機能
  • Identity model - organizations, groups, and virtual folders. Groups carry capability flags (read-only, locked, can-sign, MFA-required); virtual folders map a logical path to a real-world root with per-group READ / WRITE / READ_WRITE grants, enforced across SFTP, FTPS, WebDAV, and the Web Portal. Includes a custom NIO filesystem provider for mount routing, hot-reload of folder toggles, and cross-mount rename and copy.
  • Portal file integrity. Per-file SHA-512 checksums and armored OpenPGP detached signatures (Enterprise), a public /KEYS endpoint, and a standalone Verifier tool shipped as a fat JAR, a portable JRE bundle, and Windows launchers.
  • License administration across the Web, Swing, and CLI surfaces, and session idle timers that expire the admin console and Portal on real user inactivity rather than wall-clock time.
  • Probe-all-parallel login orchestrator with hot-swappable authentication providers.
修正
  • New executed_by column on the audit trail records which operator performed each admin action; audit coverage extended to folder-permission and identity-model mutations.
  • A large sweep of admin-parity, mount-routing, and Portal navigation fixes across Web, Swing, and CLI (folds in development builds 434–477).
Stylus SFTP Server 1.0.0.4332026年6月24日
修正
  • Completed the UTC timestamp sweep - four remaining write sites (the audit-event INSERT, two time-series cutoffs, and the server heartbeat) now bind UTC explicitly. Fixes negative uptime and false "server down" reports on hosts running in a non-UTC time zone.
  • Audit shutdown no longer races its writer thread on slow hosts, so in-flight audit batches are no longer lost when the server stops.
Stylus SFTP Server 1.0.0.4322026年6月23日
機能
  • [Enterprise] Web File Portal white-label / branding. Re-brand the portal with your own product name, vendor name, logo, favicon, ten distinct color slots, and font, configured from a single branding file. Four ready-to-copy starter themes ship with the product.
Stylus SFTP Server 1.0.0.416メジャーバージョン2026年6月22日
機能
  • Free Edition. A single Setup-Free installer with edition gating across the runtime, installer, CLI, and both admin consoles - Free, Standard, Professional, and Enterprise tiers.
  • Windows installer improvements. Desktop and Start Menu shortcut options (per-user or all-users) and an Apps & Features registry entry; the uninstaller cleans up both.
修正
  • Server timestamps now persist in UTC regardless of the host time zone.
  • A broad sweep of Web admin, Swing admin, and Web File Portal fixes - selection persistence across refresh, lockout state shared across surfaces, read-only enforcement in the portal, and more.