Category: Development

Security Enhancements in MIDAS v4.13

If you follow our blog, then you’ll know we’ve been busy putting the finishing touches to the next update to MIDAS. Whilst each new version of our world class room booking and resource scheduling software includes exciting new and improved features and functionality, we’re also proactively committed to providing a secure scheduling solution for your organization.

To that end, MIDAS v4.13 includes a number of security enhancements which we’ll explain below…

15-Point Security Audit

We’re including an on-demand security audit with v4.13. Administrators may access this audit via MIDAS Admin Options → Manage MIDAS → Security. When run, the audit will test a number of key metrics of your MIDAS system. This includes your MySQL setup, MIDAS files, and recommended MIDAS settings. A detailed report is generated with appropriate advisories for improving and hardening the security of your MIDAS system:
15-Point Security Audit

Password “Block list”

MIDAS v4.13 includes a list of passwords that are considered “banned”. Banned passwords cannot be used by users when setting a new password or changing an existing password. By default, the block list contains the Top 1000 most common passwords of 2016. Passwords such as “123456”, “password”, “qwerty”, etc are included.

For our self-hosted customers, the list of banned passwords is also editable allowing you to add/remove banned passwords. You’ll find this within within the a file named “bannedpw.dat” within your MIDAS installation.

Improved clean-up of Temporary Logs

MIDAS has included a “Keep temporary logs for x days” setting for many years. This setting has previously defined how long entries persist in the “Recent Activity” log (an audit log which records all user activity within MIDAS). For v4.13 we’ve extended the functionality of this setting to also cover the persistence of log files which MIDAS may create from time to time. For instance, a log file is created if there are issues upgrading MIDAS from a previous version, or issues when importing data from another application, or when logging of API calls is enabled, etc. Whilst these log files would be retained until manually removed, the “Keep temporary logs for x days” setting will now ensure that these files are also removed after a specific period of time.

“Minimum” Minimum Password Length

MIDAS has also included a “Minimum password length” setting since its inception. This setting allowed administrators to set a minimum password length for all user passwords. Starting with v4.13 it will no longer be possible to set this value less than 5 characters.

Password Strength Indicator

Password Strength IndicatorOur password strength indicator has been a feature for administrators creating new user accounts since v4.07. For v4.13, we’ve also made this useful visual indicator available whenever an end-users changes their password. The visual indicator classifies the password as either “Very Weak”, “Weak”, “Fair”, “Good” or “Strong” as you type, with a corresponding color to match (i.e. Red = Very Weak, Orange = Fair, Green = Strong). This classification is based upon a number of factors including the length of the password, the presence of upper and lower case letters as well as numbers and special characters, and whether the password has been banned.
We hope the addition of this visual indicator for end-users will help promote the use of strong passwords.

MIDAS v4.13 is expected to be made available to Beta Testers in the next few weeks, with a general release shortly after. We’re always looking for additional testers to help test and provide feedback/bug reports on pre-release versions of our software, like v4.13. Becoming a tester is free and no experience is required, and what’s more we’ll reward you for your participation! Find out more about becoming a MIDAS Beta Tester here.

If you would like to be notified when v4.13 is fully released, then why not join our Mailing List?

Invoicing Improvements in MIDAS v4.13

With development on the next update to our room booking and resource scheduling software, MIDAS nearing completion, we’re shedding a little light here on some of the new and improved features coming in v4.13.

v4.13 includes a sprinkling of small improvements to the already extensive invoicing capabilities of MIDAS. These include…

Option to automatically mark invoices totaling zero as paid

MIDAS already provides options to generate invoices only if the invoice total is non-zero, or generate invoices regardless of the invoice total.

In v4.13 we’re adding an additional setting to control what happens in the event that a zero total invoice is generated. When enabled, any invoice generated that has a total of zero will automatically be marked as “Paid in full”.

You’ll find this new setting via MIDAS Admin Options → Manage MIDAS → Invoicing.

Option to generate an invoice when directly approving booking request

Previously, if you wanted to generate an invoice from a booking request you were about to approve, you would either need to firstly approve it and then separately generate an invoice, or modify the booking request and tick the “Create Invoice” box when approving.

We’re making it even easier in v4.13 to generate an invoice at the same time as approving a booking request. At the bottom of your “Pending Booking Requests” screen, there’s now an “Generate Invoices when approving requests” tick box. Selecting this option before you approve booking requests will automatically generate invoices accordingly.

Note: This option will not be available if your user permissions don’t allow access to the invoicing capabilities of MIDAS.

%PAIDON% Receipt template placeholder variable to denote date invoice was paid in full

We’re also introducing a new placeholder variable for the “Invoice: Receipt” template.

The new %PAIDON% variable will be automatically substituted for the date the corresponding invoice was paid in full on.

Templates (including the “Invoice: Receipt” template) can be viewed and modified via MIDAS Admin Options → Manage MIDAS → Templates.


Development is nearing completion on the next update to our room booking and resource scheduling software, MIDAS. So we’re shedding a little light here on our blog on some of the new and improved features coming to v4.13…

When a new booking request or message is received, or a new “watch notification” triggered, MIDAS alerts the user. In the user is logged in, the relevant toolbar icon changes to denote the number of new booking requests or messages requiring their attention. Users can also optionally choose to see a list of these requests/messages each time they login in.

Furthermore, a user can optionally choose to be sent email notifications upon each new booking request, message, or watch notification.

With the upcoming new addition of Desktop Notifications in v4.13, which enables more prominent on-screen alerts to logged in users, we’ve added a useful new option to v4.13.

Suppress New Booking Request Email NotificationsSuppress New Message/Watch Notification Emails
Suppress new Booking Request email notifications whilst logged inSuppress new Message/Watch notification emails whilst logged in

The new settings will allow a user to suppress receiving such notifications in their email inbox whilst they are currently logged in to MIDAS. Email notifications will then only be sent during those times they’re away from their device, and logged out.

We believe these new per-user setting will help to reduce the number of redundant email notifications from your MIDAS system. But of course this setting can easily be toggled on/off by users at any time. If you do still want to receive an email notification on every new request/message – even when you’re logged in – you’ll still be able to do so!


New Desktop Notifications

MIDAS Desktop NotificationsDevelopment is nearing completion on the next exciting update to our room booking and resource scheduling software, MIDAS, and over the next few weeks, we’ll be sharing a “first look” at some of the new and improved features coming in v4.13.

One of the new features in MIDAS v4.13 is “Desktop Notifications” on web browsers which support such notifications (At time of writing, this includes current versions of Firefox, Chrome, Safari, Opera, with Edge support coming soon!).

Desktop Notifications are small pop-up messages (sometimes called “toasts” due to the way they animate – like toast popping up out of a toaster!) generated by an application. You’ve probably seen similar notifications before – for example in your email client or messenger apps when a new message arrives.

In MIDAS, Desktop Notifications will alert you to new booking requests requiring your approval, as well as new messages from other users, reminders, and watch notifications. Notifications will usually display in the lower left corner of your screen, even if your web browser window is minimized or hiding behind another application – so you’ll never miss another notification!

The notifications will also automatically close after a few seconds, or can be closed manually.

Enable MIDAS Desktop NotificationsIn order to take advantage of Desktop Notifications in MIDAS v4.13, the first time a notification is to be shown, your web browser will prompt you to allow desktop notifications for your MIDAS system. Simply click “Allow” to grant permission to MIDAS to show you notifications (you’ll only need to grant this permission once):

If you decide at a later stage that you wish to turn off your MIDAS Desktop Notifications, you’ll be able to disable them in your browser’s settings.

MIDAS v4.13 is expected to be made available to Beta Testers in the next few weeks, with a general release shortly after. We’re always looking for additional testers to help test and provide feedback/bug reports on pre-release versions of our software, like v4.13. Becoming a tester is free and no experience is required, and what’s more we’ll reward you for your participation! Find out more about becoming a MIDAS Beta Tester here.

If you would like to be notified when v4.13 is fully released, then why not join our Mailing List?