We are pleased to announce that Opal 5.4 is now available. Opal is OBiBa’s core data management application
for biobanks.
This release introduces security improvements, to conform best practices:
-
User re-authentication is now requested when sensitive profile information is accessed or modified, enhancing overall security.
Default session timeout before re-authentication is configurable and is set to 5 minutes by default. Critical actions requiring
re-authentication include user profile updates and password changes by default. Additional actions can be configured as needed.
-
Cross-site Resource Forgery (CSRF) protection has been improved by enforcing CSRF tokens on all state-changing requests, following the
OWASP recommendations ,
ensuring robust defense against CSRF attacks.
Note: Make sure you are using the latest opalr R client (version 3.5.2 or higher) to benefit from the new CSRF protection.
This release was possible thanks to the support of the Leiden University Medical Center - LUMC .