Dear Valued Partners,


BioStar X version 1.0.2 is now available at the Suprema Download Center.


This release strengthens system security and improves backup and restore.

It also supports changing the main server IP address and adds support for BioStation 3 MAX and XPass Q2.

Other updates include device event log deletion, directory synchronization modes, camera group permissions, and Nx Witness v6 integration.


1. Security Improvements

BioStar X v1.0.2 addresses security vulnerabilities in the system and in Time & Attendance (T&A).

System

  • Applied HTTP security headers to the web server.
  • Enhanced the encryption method for database connection passwords.
  • Improved XSS security vulnerabilities.
  • Improved SQL Injection security vulnerabilities.
  • Improved security vulnerabilities related to access permissions on the user list page.
  • Improved security vulnerabilities related to device secure communication and encryption keys.
  • Improved security vulnerabilities related to PDF export.
  • Updated the Open JDK version.

Time & Attendance

  • Updated the Minimist library to address security vulnerabilities.
  • Improved security vulnerabilities in script files.
  • Enhanced the database password encryption method.
  • Upgraded web libraries (AngularJS, jQuery, and Moment.js).

[Note] When upgrading to BioStar X, a popup message recommends deleting unnecessary Redis.


2. Server Operations

BioStar X v1.0.2 makes server changes and recovery more reliable.

Improved Backup and Restore

  • Restoration is supported even when the server IP address has changed.
  • Backups include data from user-defined paths, such as encryption keys and image logs.
  • The backup and restore process is more stable.

For details, see System Backup and System Restore in Suprema Docs.

Main Server IP Address Change

Administrators can change the IP address of the main server.

[Windows Start > BioStar X > BioStar X IP Setting]

[Note] 

  • Select the new IP address from the list in Server Address. You cannot enter it manually.
  • After the change, restart all services.
  • Devices registered with the Device ▶ Server Connection option need a manual update of the server IP.
  • If the database runs on the same server, update server_ip in system.conf.
  • If you use a Multi Communications Server, update the main server IP on that server.

For details, see Change the Main Server IP Address in Suprema Docs.


3. Other New Features and Improvements

New Device Support

BioStar X v1.0.2 supports the following new devices:

  • BioStation 3 MAX
  • XPass Q2

For device details, see BioStation 3 Max and XPass Q2 in Suprema Docs. 


Device Event Log Deletion

Administrators can delete device event logs in BioStar X.

[BioStar X > Settings > Device > Select devices > More > Delete All Event Logs in Device]


[Important] Deleted event logs cannot be recovered or resent from the server to the device. Before deleting, confirm that the event logs are stored on the server. Slave, virtual, and Wiegand devices do not store logs and are excluded.


[Note]

  • Only users with the Administrator Role permission can use this feature.
  • The deletion history is recorded in the Audit Trail. [BioStar X > Settings > System > Audit Trail]

For details, see Delete Event Logs From a Device in Suprema Docs.


Directory Service Synchronization Modes

When integrating with a directory service, you can choose one of two user synchronization modes.

Mode

Behavior

Add/Update Only (Default for new installations)

Adds new users and updates changed users. Users registered only in BioStar X and users deleted from the directory are not deleted.

Add/Update/Delete

Keeps BioStar X users identical to the directory. Users registered only in BioStar X and users deleted from the directory are deleted.

[BioStar X > Settings > System > Directory Integration > Synchronization > Sync Mode]


[Important] If you upgrade to BioStar X v1.0.2 with directory integration enabled, the sync mode defaults to Add/Update/Delete. Check the sync mode after upgrading. To keep specific users, enable Exclude from Directory Integration for those users.

For details, see Directory Integration Settings in Suprema Docs.


Camera Group-Based Permissions

Administrators can be assigned access permissions based on camera groups. An administrator can access only the cameras in the designated groups.

For details, see Add Custom Permissions in Suprema Docs.


Nx Witness v6 Support

BioStar X v1.0.2 supports Nx Witness v6 for VMS integration.

For details, see Integrate VMS in Suprema Docs.


Bug Fixes

BioStar X v1.0.2 includes the following main fixes:

  • Fixed BioStar X being inaccessible after installation in environments with multiple network adapters.
  • Fixed the upgrade failure from BioStar 2 to BioStar X when BioStar 2 was installed in a custom path.
  • Fixed new user registration failures and device sync errors after upgrading from BioStar 2 to BioStar X.
  • Fixed server errors after restoring a backup file on a server with a different IP address.
  • Fixed an issue where non-admin users could access other users' report filters through the API.
  • Fixed failure to retrieve group lists or synchronize data from Microsoft Entra ID when there are more than 100 user groups.

For the full list, see BioStar X v1.0.2 Release Notes.