Release notes — Version 2.5
What changed in each version 2.5 release, newest first, as published with the release.
v2.5.8
Released 2026-10-11
- IMPORTANT: this update permanently removes the remaining SMS leftovers from the database: the empty SMS tables and fields, the seven SMS permissions, the reseller permission "SMS" and the setting "SMS_Active" (the SMS feature itself was removed in v2.5.6). Tables and fields are only deleted when they are empty; if an SMS value is still stored anywhere, the update stops and deletes nothing. After this update, going back is only possible to v2.5.6 or later, and going back does not restore what was removed.
- Profile pictures: every user account can have its own picture (a company logo works too). Without a picture, a circle with the initials is shown. The picture appears in the top bar (now also on phones and tablets), in the greeting, in the user list, on the user page, in the "signed in as" banner and in the search. Everyone changes their own picture; administrators and resellers can also change the pictures of their own customers. Allowed are PNG, JPG and WebP files up to 200 KB.
- Favorites in the sidebar: a star next to every menu item adds it to a "Favorites" group at the top of the sidebar. Favorites are saved per account (up to 20) and can be sorted with up/down buttons; the menu item also stays at its usual place.
- User list: "Devices" and "Add balance" are now separate buttons next to the edit pencil instead of entries in the three-dot menu.
- Payments: when a payment was booked for a customer with a tax rate and the tax field was left empty, the payment stored no tax, and deleting that payment removed a larger amount from the balance than had been added. The tax is now stored with the payment, and deleting a payment returns exactly the amount that was booked.
- Payments in a foreign currency are now converted with the exchange rate when they are added to the balance (before, the plain number was added). Unknown or disabled currencies are rejected.
- Manual payments: the gross amount is now checked against the net amount and the tax rate before booking. Payments entered on the "new payment" page always have the type "manual" and now also store the balance before and after the booking.
- Security: the client address used for sign-in records, the admin sign-in address restriction and the session address check is now the address seen by the system's own web server. Installations behind an additional reverse proxy of their own can set the number of proxies (VOIPLIX_TRUSTED_PROXIES in apps/web/.env, default 1). Users whose network adds its own forwarding header may have to sign in again once after the update. If such a network leaves through several outgoing addresses, these users are signed out whenever their outgoing address changes; in that case the session address check can be switched off for the whole installation with the setting do_not_logout_on_session_ip_change (currently a database setting without a page).
- Security: values inserted into HTML e-mail templates (names, user names and similar) are now escaped. If a template exists twice, the oldest one is used consistently.
- Customer portal: changing the e-mail address or the password now requires the current password. Name, phone numbers and postal address can still be changed without it.
- API: the balance query endpoints for devices now limit repeated failed requests. After too many failed requests from one address they answer "Too many wrong attempts" for up to 15 minutes. Successful queries are never limited, and nothing changes while "Allow devices to check balance" is switched off.
- The display name of a device is now shown in further places: the customer portal pages, the call list, the weak-password list, the inactivity preview and the trunk selection of a DID. Bulk creation of devices now reports how many names were skipped, and the API call device_create rejects names with invalid characters like the device form does.
- E-mail templates: opening and saving a template with the format "plain" no longer silently switches it to HTML.
- Creating a user no longer reports "not created" when the user was created and only a later step failed.
- New installations: the customer templates for the low-balance warning, the payment confirmation and the statement of account are now also available in German (the first two also in Albanian), as long as the English default text was not changed.
- Four texts that the browser showed as raw names (an error message of the PJSIP extra page and three step names of the setup wizard) are now translated. In the customer portal the postcode field is no longer labelled in German in other languages, and an opened payment row now says "Balance before booking" for the earlier balance.
v2.5.7
Released 2026-10-11
- IMPORTANT: from this update on, your customers get an e-mail for every manual payment, and you get one too (two switches in Settings, group "Payment and balance e-mails", both on). Customers also get the new e-mails "Password was changed" and "Account created". If e-mail sending is switched off on your system, nothing is sent; the mail log then shows one "failed" line per e-mail.
- Devices with "Send recording by e-mail" ticked now really send the recording as an attachment. If "Keep recordings after sending" is set to No, the recording disappears from your customer's list after it was sent (it is hidden, never deleted). All existing devices are set to "do not send, keep", so nothing changes until you tick it.
- New: you get an e-mail whenever a balance is changed with "Add balance" or through the API (third switch in the same group, on).
- New e-mail templates you can edit under E-mails, in English, German and Albanian: password reset link, password was changed, account created, alert raised, alert cleared, admin IP authorization, subscription report. Alerts, admin IP requests and subscription reports now appear in the mail log under these names.
- Removed four e-mail templates that were never sent: password reminder, both registration confirmations, CDR export error.
- A blocked customer no longer gets invoice, statement, balance warning and payment e-mails, unless "Allow login and receive e-mails" is ticked for him. The e-mail about the block itself is still sent, and a waiting invoice is sent automatically after the customer is unblocked.
- Fixed: the e-mail about a subscription block now also reaches the owner of the customer; before, only the customer got it. A customer with several unpaid subscriptions now gets one e-mail instead of one per subscription.
- Fixed: balance warnings for customers of a reseller now go to the reseller, not to the system operator. A reseller sees a new line "Reseller" for his warning threshold in the user form of his customers.
- Fixed: "Add balance" and "Add payment" now reject anything that is not a plain number (for example "+50", "€50" or "2e5") instead of booking 0 or a wrong amount, and they have an upper limit.
- Fixed: a daily credit limit or maximum call rate that cannot be read, or that would be stored as 0, is now rejected instead of silently becoming "unlimited". Tariff rates typed in exponent notation are rejected.
- User form: numbers like "1e3" are now read as 1000. If the exchange rate changed between opening and saving the form, saving is refused with a note to reload the page; before, the money fields were silently recalculated.
- Fixed: changing a customer's balance warning threshold now re-arms the warning.
- Fixed: the statement of account no longer shows "-0.00" for a settled balance, and invoice PDFs round exactly like the invoice run (before, 1.005 could be printed as 1.00).
- Deleting recordings in bulk now stops with a message when more than 4000 are selected; nothing is deleted in that case.
- Call media rows (codec and quality per call) older than 90 days are now removed automatically at night. Calls themselves are never touched.
- New setting under Settings, API: "Allow devices to check balance" (off). The SMTP settings warn when the sender address is empty and customers of resellers exist.
- The portal now checks the e-mail address a customer enters.
v2.5.6
Released 2026-10-10
- The SMS feature has been removed: the SMS menu, all SMS pages, the SMS switches in alerts and alert groups and the "SMS module" setting are gone. Nothing is deleted from the database in this version.
- API: the methods sms_send and send_sms no longer exist and now answer "Unknown method".
- Certificates moved: they are now a section on the System status page (/health). The separate page /health/certificates no longer exists. The section is only shown to accounts that hold the certificate permission.
- Devices: new "Display name" (the former "Description" field) - a free name such as "Front desk 1" that is shown next to the technical name in the device list, on device pages, in the DID assignment, in monitoring, in the call details and in the customer portal. It changes nothing in telephony.
- Devices with IP authentication: the technical name is assigned automatically. The field is now read-only and says so, and an existing technical name is kept. Before, a typed name was replaced without any notice.
- Fixed: two devices could end up with the same name, which could break the device configuration of the phone system. Device names must now be unique - in the device form, bulk creation, reassignment, CSV import and the API (device_create answers "Device name must be unique"). Existing devices are not changed.
- Alert contacts: the field "Phone (SMS)" is now simply "Phone".
- Staff accounts that are restricted to selected customers: ring groups, queues and BLF groups now only show the members of the allowed customers, a group that contains other customers' members can no longer be changed or deleted by such an account, shared export and import templates can no longer be changed by it, and the caller ID fields of a device no longer accept a number that belongs to another customer.
- API: dids_get now requires the DID permission for accountant accounts and answers "You are not authorized to manage DIDs" otherwise.
- DID tariff and DID rates: the actions behind these two panels are now closed for resellers, as the panels themselves always were.
- System accounts: the SMS areas are no longer offered in the permission list.
- User form: "Minimal charge" accepts whole numbers only and shows a message for an invalid value. A very large number caused an error page before.
- Statistics, Users finances: an invalid balance filter in the address no longer causes an error page, a comma is accepted as decimal separator, and the credit column and the credit total now follow the same credit rule as the rest of the system (unlimited credit is shown as a dash and is not added up).
- DID bulk changes: the action log now lists only the DIDs that were really changed.
- More messages are translated: the result of the CDR import, the results of the rule simulator, error messages of the device form, the setup wizard and the DID tariff panel, and the T.38 option "Redundancy" in the provider form.
- Fixed: the System status page showed raw labels in several status lines, for example "N restarts" instead of the real number of restarts and "Tz matches billing clock" instead of the full sentence. These lines are now complete in every language.
v2.5.5
Released 2026-10-10
- Call protection settings that could be saved but had no effect now work on calls. A user's "Max. call rate": calls to destinations that cost more per minute are rejected before dialling (cause 269).
- Daily credit limit of a user: the amount still left for the day now limits the call duration and rejects further calls once it is used up (cause 211); the used amount is counted after every paid call and starts again with the first call of a new day (local time). The daily credit warning e-mail uses this value.
- LCR "First provider percent limit" (order by price) and "Minimal Rate Margin Percent": providers that are too expensive are now skipped, including the failover provider (causes 235 and 265). The LCR form explains both settings.
- Monitoring > Blocked numbers: the global source and destination lists are now applied to outgoing calls (causes 277 to 280).
- Destinations with a price of 0 per minute but a connection fee are rejected when balance and credit do not cover the fee (cause 211); destinations that cost nothing at all stay reachable.
- New: codec, transcoding and media quality (packet loss, jitter, round-trip time) are recorded for both sides of a call and shown in a new "Media" card on the call details page; the two codec fields there are now filled. Customers only see the side of their own device. Recording can be switched off under Monitoring > Settings. A new database table is created during the update.
- Fixed: a call that was tried over several providers showed the first provider together with the result of the last one. The call list and the per-provider statistics now show the provider that was dialled last.
- Fixed: when a forwarded call was declined by the provider, the row of the called number showed a different result than the outgoing row.
- Fixed: a call that was answered for less than one second by a second provider, after the first provider had failed, was not charged and still showed the failed first attempt. It is now charged like any other answered call (one second plus the connection fee).
- Fixed: the automatic number cool-down could count its own rejection one call too late.
- Cause rule simulator: optional SIP response field, so a provider decline (603) is evaluated exactly like on a real call.
- Routing probe: shows the new checks (max. call rate, daily credit limit, global lists, percent limit, margin).
- Fixed: every call over a local channel wrote a warning line to the Asterisk log.
v2.5.4
Released 2026-10-10
- Action log: settings that hold passwords, tokens or keys are no longer recorded in clear text - the log only shows that they were changed; the license code appears only with its last four characters.
- Browser phone: staff accounts (admin, accountant) no longer receive a customer's device; they see a notice instead. A dedicated test phone for staff follows in a later version.
- Call list (/calls) is more compact and fits a laptop screen without sideways scrolling: info button as first column, short column headers, direction as an icon, From and To in one column, smaller font in the table.
- DID bulk actions (release, assign, terminate) now change all selected numbers in one step or none at all, and report how many were changed.
- Statistics pages, the calls-per-day export, the dashboard finance card and the customer portal keep money exact to the last decimal place instead of rounding through floating point; credit is shown with the same rule the call check uses (a credit of -2 is no longer shown as unlimited, an empty credit of a postpaid customer is shown as unlimited).
- Calls-per-day export: the revenue and profit columns follow the same permission as the page (partners and guests no longer get them); an invalid date falls back to the default range instead of an error.
- Usage report: groupings by device, destination, prefix or hour cover at most 31 days of the selected period (with a notice), so they finish reliably on large systems; the customer usage report counts its row limit by displayed rows.
- Trunk health: the ASR counts all dial attempts of the last hour (skipped providers excluded), so a trunk that rejects calls and is bridged by a fallback now shows a low ASR instead of no calls. A new database index on dial attempts is created during the update (a few seconds).
- Statement of account with a custom opening balance: a payment on the start day between midnight and 2 a.m. local time is no longer missing.
- Customer form: money fields that were not changed are no longer rewritten on save (no drift with a foreign currency, no exponent display such as 5e-8); amounts too large for the database are rejected with a message; -1.0 in the user template means unlimited; a conditional block requires a day.
- User import: a balance or credit too large for the database is reported per row instead of failing.
- Staff accounts restricted to selected customers are now limited to those customers in further areas, both when reading and when changing (alerts, reseller groups, data import, PBX, BLF, external DIDs, caller ID pools, LCR cloning, provider deviations, location rules, DID settings, caller IDs, forwarding, active-call cleanup, XML API location rules).
- Scheduled tasks and automatic CDR exports belong to the operator instead of the single admin account: a second admin now sees and manages them; refusals are shown as messages instead of an error page.
- Re-rating lock by paid invoices compares whole local days and no longer locks one day too early.
- XML API: financial_statements_get counts invoices by whole days; dids_get searches numbers exactly and supports the status filters for admins; further hardening of responses.
- Customer portal: account pages (details, devices, invoices, payments, forwards, rates) are open only to the account holder; /api/health no longer shows database error details.
- Number pools: saving a pool without the cooldown fields keeps the stored limits.
- Invoice list PDF: its own limit of 2000 invoices with a visible notice when cut, and the same filters as the CSV export (period, issue date).
- Deleting a credit note or payment without permission now shows a message; several forms show translated error messages; provider and device option labels (Never, Route, Originate, Refuse, Redundancy) are translated.
v2.5.3
Released 2026-10-09
- Staff accounts limited to selected customers now only see and change those customers everywhere: statement of account, dashboard figures, call list, call export and call details, DIDs, recordings, devices and all device tabs, customer accounts and their tabs, payments and receipts, invoices, credit notes, subscriptions, scheduled tasks, CDR rerating/import, automatic exports, mail log and statistics. Previously several of these pages and actions ignored the selection.
- Such limited staff accounts no longer see free DIDs, cannot create DIDs, cannot create administrator, accountant, reseller or partner accounts, cannot change system-wide settings (main location rules, operator rule groups, provider extra lines, services, provider tariff schedules, automatic device release) and no longer see system-wide load figures.
- Staff accounts without the providers permission no longer see carrier names, purchase prices, SIP traces or call logs on call details, and no self-cost, profit or margin on the dashboard.
- Local calls statistics: the IP filter no longer shows calls of other customers.
- A blocked or deleted login can no longer download call traces, recordings or dashboard data with a session that was still open.
- Email templates belong to the tenant: a second administrator (for example the support account) and accountants now see the operator's templates, and new templates are saved for the operator instead of the individual login.
- Emails sent on behalf of a reseller never use the operator's mail server login as sender. If a reseller has no sender address and the operator has none either, the email is not sent and the mail log shows "sender missing" - set "Email from" in the email settings.
- Bulk DID actions (free, assign, terminate) and "DID to pool" now also require the DID assign permission. "Set as CID" only works for a device of the DID's owner.
- Legacy API: when the API is disabled, every request is refused, including the two balance lookups and login. A reseller's phones only receive their balance through the API if that reseller has the API enabled.
- Legacy API: device_create rejects unknown device types with "Device type invalid"; dids_get with search_did_owner now only returns DIDs of the matching owner.
- Exports: protection against spreadsheet formulas also covers values with leading spaces or full-width characters.
- A reseller now sees their own account read-only (saving was already refused); the PBX switch is only shown with the matching permission.
- The web softphone configuration for staff only offers devices of customers the account may see; a blocked login no longer receives it.
- Every page now checks the required permission itself in addition to the route guard; the release build enforces this.
v2.5.2.2
Released 2026-10-09
- Provider rejections (SIP 603 Decline) still show as BUSY, but the provider's own reason is now kept: 603 with cause 17 stays BUSY 17 (a real busy, it no longer counts for the number cooldown); 603 with cause 21, without a reason or with cause 127 is BUSY 21 and counts. The previous version wrote every 603 as BUSY 21.
- Number pools: the reject rule (for the whole system and per pool) now accepts any Q.850 cause code from 1 to 127, chosen from a searchable list with names. Choosing a busy, no-answer or normal-clearing cause shows a warning. Up to about 16 codes fit at once; a longer rule is refused instead of being cut. Q.850 causes never count for answered or cancelled calls.
- Existing call records are not changed; only new calls are affected.
v2.5.2.1
Released 2026-10-08
- Provider rejections (SIP 603 Decline) are now recorded as BUSY with hangup cause 21 (call rejected), no matter which Reason the provider adds. Before, the same rejection showed as BUSY 17 or as NO ANSWER 21, depending on the provider.
- Call attempts, cause routing rules and the number pool cooldown now see a provider SIP 603 as BUSY 21; the original SIP code 603 stays visible in the call attempts. Note: such rejections now count for the number cooldown on every system.
- A SIP 603 from a provider no longer triggers failover to the next provider, unless "Interpret BUSY as FAILED" is enabled for that provider.
- Existing call records are not changed; only new calls are affected.
v2.5.2
Released 2026-10-08
- Customers are no longer set to "blocked" after a call when their money runs out. Before, a customer was blocked after the call, could no longer log in and had to be unblocked by hand after topping up. Now the next call is simply refused when there is no balance or credit, and the customer can call again right after topping up. Blocking for unpaid subscriptions is unchanged.
- Credit is now worked out by one single rule for the call check, subscription charging and conference legs (no change in the result).
- User form: nine customer settings can now be edited when creating and editing a user - show calls with zero price on invoices, generate empty invoices, block on a day of the month, allow login while blocked, disable subscriptions when there is not enough money, show tariff name, balance warning e-mail address, and the admin and accountant warning thresholds. They are also part of the default user template and the CSV user import.
- User form: the daily credit limit warning can now be switched on (admin only), also in the default user template.
- CSV user import: the credit from the file is now converted with the currency rate of the person importing, like in the user form. Before, it was stored unconverted.
- User page, "Add balance": the current balance is now shown in the viewer's currency and money format. Before, it carried the customer's currency label and showed up to 15 decimal places.
- Statement of account: an invoice dated on the last day before the chosen period was shown inside the period instead of in the opening balance. Fixed on the page and in the statement e-mail.
- Settings, device defaults: the three limits of the automatic release of unused devices (most devices at once, most percent at once, shortest measuring gap) can now be set here instead of only in the database.
- Conference rooms: the error and warning messages of the room form are now shown translated instead of as technical names.
v2.5.1
Released 2026-10-08
- Conference rooms can now call an outside number into the room ("Call outside number" in the room's live panel). The call goes out through the room owner's normal outgoing route, like a call from one of the owner's phones: provider selection, price, balance and credit check, channel and device limits and the loss guard all apply, and it is charged to the room owner.
- An outside call ends automatically when the last device of the room owner leaves the room, so outside participants cannot keep talking at the owner's expense.
- Customers who pay in advance or have a limited credit can have only one outside conference call at a time (new hangup cause 905); customers with unlimited credit are not limited.
- If an outside call cannot be connected, the room's live panel shows why (for example low balance, a limit, or the provider's answer). Balance and time announcements of the calling device are not played into the room.
- Outside calls use the same permission as managing a room; for end customers they stay off until the operator enables conferences for that customer.
- Fixed: call records inside a conference room are never charged and never carry a provider. Before, a tariff rate matching the room number could have charged the room side of a call, and a device in a room with a caller who dialled in through a DID was recorded with that caller's provider and counted in the provider's minute limits.
v2.5.0
Released 2026-10-08
- Status per origin now also applies to calls between devices of the same customer: when such a call fails (busy, no answer, failed, unreachable) and the called device has no voicemail and no call-flow branch of its own, the calling phone receives the status set for the calling device.
- Existing status rows set up for calls to the outside take effect for calls between devices right after the update; devices without rows behave exactly as before.
- The original status stays in the call record (hangup cause and status), in the call details and in the hangup-cause statistics; calls between devices remain free of charge.
- Saving the status per origin now reloads the dial plan at once and confirms it was loaded; if the confirmation fails, the device form shows a warning.
- Ring groups, queues, IVR menus and conference rooms are not affected.