> Source: https://docs.nometa.az/changelog/4-1

# SAMURAI 4.1

_Released June 21, 2026._

## Features

- collapsed=row, expanded=column inside the detail box
- enrichment as right-aligned key/value column panel
- make APIC modified cards expandable + drop host fvIp noise
- make switch/router modified cards expandable (parity with APIC)
- merge cross-source endpoint rows into one rich enrichment
- place enrichment column beside native attrs (side-by-side)
- pure change_log enrichment core (endpoint index + ranking + identity leg)
- redesign enrichment UI as merged labeled Badge chips
- render endpoint + AD identity enrichment on change items
- render enrichment in vendor renderers (individual-expand)
- split person identity into separate rows in expanded column
- wire enrichment into sync + AD NetBIOS capture & resolver
- general search box ignores expression DSL (literal phrase)
- make firewall IP search range-aware (start-end address ranges)
- support CIDR-vs-CIDR containment in firewall IP search
- **538,539:** numeric port matching for firewall service search
- enrich 'modified' switch change cards (Auth Sessions etc.)
- enrich 'modified' router change cards (ARP/MAC)
- **Aci:** collect + parse ACI COOP IP database
- **Aci:** COOP Endpoints tab on the ACI switch page
- **Aci:** COOP/zoning tab refinements — DSL filtering, owning-leaf, export
- **Aci:** fetch + surface ACI leaf deployed zoning rules
- **Acl Ui:** server-side ACL tab — filter/sort/paginate/export like Routes
- **ACL:** server-side ACL export (csv/xlsx/html/pdf), parsed columns
- **ACL:** unified vendor-neutral parsed ACL model
- **Active Directory:** Created column on Users+Computers, drop Groups column from Users
- **Active Directory:** domain overview (rootDSE) + device info bar on AD panel
- **Active Directory:** export (CSV/XLSX/HTML/PDF) + fix bool filter_options
- **Active Directory:** export memberOf/member as CN only, not full DN
- **Active Directory:** fetch computer description + show column/export
- **Active Directory:** fetch user description + show column/export
- **Active Directory:** fetch user manager + show CN column/export/diff
- **Active Directory:** fetcher, sync registration, and objectGUID-keyed diff
- **Active Directory:** frontend panel, registries, Microsoft icon, change detail
- **Active Directory:** handlers, routes, monitor port, license pool, timeline wiring
- **Active Directory:** LDAP connector with paged search + member range retrieval
- **Active Directory:** pure parsing helpers (objectGUID, UAC, groupType, range attrs)
- **Active Directory:** show functional level as the device card 'version'
- **Apic,ise,vcenter:** correlation-time admin stamps + slim changes payloads
- **Backend:** /api/ftd/* first-class endpoint family
- **Backend:** CompareFTDSnapshots + ftd timeline dispatch
- **Backend:** FTD fetcher emits first-class ftd_* collections
- **Backend:** ftd in picker/monitor/endpoints/topology/license/compliance/changemail
- **Backend:** migrate-ftd-devices history-migration CLI, dry-run default
- **Backend:** range-aware FMC port filtering
- **Backend:** register ftd_* collections in SyncCollections + indexes
- **Backend:** rolling palo_config_audit archive + windowed compare payload
- **Backend:** router fetcher self-heals masquerading FTDs to type ftd
- **Backend:** wire ftd into sync registries, hash strip, config encryption
- **Changemail:** AD vendor card renderer (membership deltas, friendly labels)
- **Changemail:** APIC vendor card renderer (DN/tenant/contracts/children)
- **Changemail:** badge, fieldDiffRow, kvGrid primitives
- **Changemail:** FMC vendor card renderer (flow rules/ports/settings)
- **Changemail:** ISE vendor card renderer (prominent attrs + structural diff)
- **Changemail:** NDO + FortiGate vendor card renderers
- **Changemail:** Palo vendor card renderer (flow/IPSec/modified/renamed)
- **Changemail:** RenderContext, registry, Generic renderer
- **Changemail:** Router/Switch vendor card renderer
- **Changemail:** setDiff primitive
- **Changemail:** structuredValue primitive (replaces %v dump)
- **Changemail:** vCenter vendor card renderer (4-arm structured diff)
- **Changes:** collapsed per-field deltas for all RouterChangeDetail types
- **Changes:** FTD modified card collapsed view shows per-field deltas
- **Changes:** global Changes page card matches per-device card
- **Changes:** multi-admin card header from primary_admins
- **Changes:** per-device card shows aggregate badges + per-section overview
- **Changes:** resolve prior AD identity on auth-session login changes (#580 P1)
- **Changes:** running-config diff as side-by-side before→after
- **Cmd:** backfill-changelog-primaryadmin — recompute Palo attribution
- **Database:** ChunkedCollections registry + chunk index
- **Devices:** device-type picker as a dropdown, defaults to first type
- **Docker:** bundle MongoDB with external-first, embedded-fallback
- **Email:** add device deep-link to change-notification emails
- **Email:** delegate item rendering to changemail
- **Email:** render renamed and reordered change types
- **Email:** render truncated-snapshot notice and fire on it
- **Enrichment:** stamp resolved_from on each identity to tie it to the change side
- **Export:** brand Excel/PDF/HTML exports with SAMURAI wordmark
- **Export:** use "SAMURAI Networks" text instead of the wordmark image (#586 follow-up)
- **Filters:** standardize filter bars onto per-field URL params
- **Fmc,ndo,fortigate,router:** admin stamps for the remaining vendors
- **Frontend:** FtdPanel + /ftd routes, retire synthetic firewall sidebar group
- **Frontend:** per-entry Proxy IDs diff rows in Palo change cards
- **Frontend:** rebuild router/switch Configuration tab
- **Frontend:** register ftd across device-type constants and registries
- **Cisco FTD/ASA:** add Access Policy / NAT / Objects tabs to panel
- **Cisco FTD/ASA:** api constants + hooks for objects/nat/access-rules
- **Cisco FTD/ASA:** chassis view on Interfaces + Endpoints tabs
- **Cisco FTD/ASA:** config parser layer — objects, groups, services, resolver, NAT, ACE, access-rules (plan Tasks 1-7)
- **Cisco FTD/ASA:** diff structured collections; drop ftd_acls from diff
- **Cisco FTD/ASA:** emit objects/nat/access-rules collections from sync
- **Cisco FTD/ASA:** export carries resolved-IP columns + readable headers (enterprise export)
- **Cisco FTD/ASA:** firewall-aware Changes cards (Source-&gt;Action-&gt;Dest flow) via FtdChangeDetail
- **Cisco FTD/ASA:** NAT, Access Rules, Objects tab components
- **Cisco FTD/ASA:** range/port-aware search + normalized services + expandable rule detail
- **Cisco FTD/ASA:** read + export handlers for structured collections
- **Cisco FTD/ASA:** register structured collections (cascade-delete + picker)
- **Cisco FTD/ASA:** remove ACLs + Configuration tabs from FTD panel
- **Cisco FTD/ASA:** routes for objects/nat/access-rules
- **Cisco FTD/ASA:** shared ValueChips + ZoneBadge firewall cells
- **Cisco FTD/ASA:** strip structured sections from running-config diff (decision A)
- **Interfaces:** add VRF column to Interfaces tab DataTable
- **License:** XOR-obfuscate validation endpoints so they aren't plaintext in the binary
- **NDO:** add validated APIC-parity columns to entity tabs (#652 #653 #654)
- **NDO:** change-detail field labels + ref-tail decoding
- **NDO:** Contracts tab — consumer/provider/action + filter-name columns
- **NDO:** per-filter change-email rendering + wire register-node route
- **NDO:** transaction-accurate audit correlation (userTransactionId)
- **Palo Ui:** virtual-system selector on the Palo page
- **Palo Alto:** authoritative interface-based zone detection for the traffic sim
- **Palo Alto:** correlation-time admin stamps + slim /api/palo/changes payload
- **Palo Alto:** multi-vsys config sync — fetch all vsys, not just vsys1
- **Palo Alto:** render [~likely] section-level attribution in STATE 2
- **Palo Alto:** section-level single-admin attribution fallback
- **Palo Alto:** stamp per-item admin + diff-correlated multi-admin header
- **Routes:** add "Next Device" filter option (#590 follow-up)
- **Routes:** advanced filter bar, sortable columns, export, page-size fix
- **Routes:** cross-vendor route search via routes_index materialized model
- **Routes:** filter-only search + persist query in URL (#588 follow-up)
- **Routes:** load all routes by default instead of an empty prompt (#588 follow-up)
- **Routes:** prefix column filter, single-line protocol badge, always-on export
- **Routes:** resolve next-hop IP to owning device — Next Device column
- **Settings:** License 'Choose file' opens a drag-and-drop upload dialog
- **Snapshot:** reassembling chunked reader with completeness check
- **Switch:** per-field URL filter params on COOP/zoning tabs
- **Sync:** Auto min/max bounds + live sync count on dashboard
- **Sync:** canonical device-type list + conformance-test safety net
- **Sync:** chunked write path with completion sentinel + dedup guard
- **Sync:** DeviceIntegration interface + registry, all 11 vendors
- **Sync:** operator-managed sync concurrency, Manual + Auto
- **Sync:** pure chunk-split util for oversize snapshots
- **Topology:** accurate-graph engine (passes + dedup + scope filter)
- **Topology:** CDP/LLDP + MAC-attachment edge passes
- **Topology:** confidence slider + method toggles + evidence panel
- **Topology:** cytoscape canvas lifecycle component
- **Topology:** cytoscape extension registration
- **Topology:** cytoscape layout presets (fcose/dagre/concentric)
- **Topology:** cytoscape stylesheet factory
- **Topology:** device icon + reach-dot data-uris for cytoscape
- **Topology:** edges carry method/confidence/evidence; append manual conns at read time
- **Topology:** layout switcher control
- **Topology:** MAC/ARP/IP index builders for accurate topology
- **Topology:** materialize topology_graph + debounced post-sync rebuild
- **Topology:** NetworkView orchestrator for cytoscape network mode
- **Topology:** overlap-free node layout (label-aware fcose + separation pass)
- **Topology:** pure cytoscape element builder
- **Topology:** redesign network node cards with typographic hierarchy
- **Topology:** render network view via cytoscape; remove react-flow network path
- **Topology:** serve materialized graph + manual rebuild endpoint
- **Traffic Simulation:** #634 authoritative LISP map-server resolver (the finisher)
- **Traffic Simulation:** ACI contract-based access evaluation, multi-site
- **Traffic Simulation:** ACI fabric egress-leaf resolution, stop spine wander
- **Traffic Simulation:** APIC-primary multi-site ACI egress resolution, NDO-aware
- **Traffic Simulation:** authoritative FMC zones from synced device interfaces
- **Traffic Simulation:** COOP-backed ACI egress-leaf resolution
- **Traffic Simulation:** destination-aware termination to end fabric loops/wander
- **Traffic Simulation:** ECMP enumeration + AD/metric best-path selection
- **Traffic Simulation:** egress-unresolved primitive + regression fixture (#632/#633/#634 step 0)
- **Traffic Simulation:** firewall security-policy evaluation in the trace
- **Traffic Simulation:** FMC NAT evaluation via authoritative policy assignments
- **Traffic Simulation:** FortiGate firewall policy + NAT adapters
- **Traffic Simulation:** forward through FTD/FortiGate via their routing tables
- **Traffic Simulation:** FTD firewall policy adapter
- **Traffic Simulation:** FTD↔FMC reconciliation + governing-policy annotation
- **Traffic Simulation:** full FMC rule evaluator — intended-vs-deployed verdict
- **Traffic Simulation:** interface→ACL binding for directional ACL enforcement
- **Traffic Simulation:** make FTDs first-class trace participants + authoritative FTD zones
- **Traffic Simulation:** multi-vsys-aware Palo policy/zone/route selection
- **Traffic Simulation:** multipath — discover redundancy paths (ECMP/dual-border/dual-uplink) (#629 inc2)
- **Traffic Simulation:** NAT evaluation (opt-in, non-destructive) + disabled-rule badge; respect enabled state
- **Traffic Simulation:** per-hop confidence labels + DB-RIB consistency harness
- **Traffic Simulation:** redesign trace UI as a vertical ledger + surface firewall policy/zone/NAT (#629 prep)
- **Traffic Simulation:** return ALL matching policy rules per flow; keep zone detection data-driven (#594/#601)
- **Traffic Simulation:** source-resolution provenance — controller/device correlation (#631 increment 1)
- **Traffic Simulation:** Stage 0 — interface→VRF membership + admin distance
- **Traffic Simulation:** surface per-hop confidence/VRF/ACI + source-VRF override
- **Traffic Simulation:** VRF-confidence marker + consume #593 interface→VRF (#592 Gap 1)
- **Traffic Simulation:** zone-resolution foundation for firewall policy eval
- **UI:** DataTable loading polish — full-height shimmer, soft fade-out, softer scrollbars
- **UI:** smoother page + tab-switch transitions
- **UI:** standardize all export buttons onto a shared useExport hook
- **UI:** standardize DataTable loading skeletons to shimmer
- **Versioning:** single-source product version + release-please + Docker Hub publish
- **Website:** /algosec-alternative landing page + easy-keyword FAQ coverage
- **Website:** about mission quote - simple Motion reveal instead of scroll-pinned widening
- **Website:** align deploy story with Docker Hub + link to it
- **Website:** best-network-monitoring-tools guide + ManageEngine alternative page
- **Website:** blog quality pass - og cards, lang honesty, content polish
- **Website:** click-to-copy docker command (CommandCopy)
- **Website:** connect former NetMoon/nwmon brand to SAMURAI for search
- **Website:** Docker Hub try-it-yourself card on contact page (3 locales)
- **Website:** footer link integrity + minimal /docs page with licensing posture
- **Website:** framer-motion interactions - magnetic CTAs + lightbox drag-to-dismiss
- **Website:** GEO batch (b) - Tufin/FireMon pages, docs pricing FAQ, nm comparison, updated stamps
- **Website:** Home nav link before Platform (all 3 locales)
- **Website:** home page brand pass — katana sweep, drenched CTA, ember diff (#542 P2)
- **Website:** migrate canonical host to nometa.az; serve apex + network subdomains
- **Website:** network.exploit.az domain alias - 301 to canonical host
- **Website:** remove hero version eyebrow (v4.0 pill + text, all locales)
- **Website:** SEO + GEO pass - og coverage, AI-crawler policy, schema, titles
- **Website:** SEO/GEO batch (a) + TweaksPanel to left
- **Website:** SEO/GEO landing pages, working forms, official vendor logos, critique P1 fixes
- **Website:** SEO/GEO vendor analyzer pages + flagship polish pass
- **Website:** site-wide taste + interaction polish pass
- **Website:** soften ZoomTopology zoom in/out
- **Website:** stop writing section hashes (#hero) into the URL on scroll
- **Website:** Tawk.to live chat widget

## Bug Fixes

- match enrichment column font size to native attrs (text-xs)
- match real change_log item shape + UPN/NetBIOS dot1x logins
- show enrichment row on modified items (fixes APIC)
- treat colon-hex MACs as global terms in search tokenizer
- **Acl Ui:** q+per-field URL params, flat export, protocol-aware port search
- **Active Directory:** deduped collections no longer diff as 'all removed'
- **Active Directory:** efficient chunked reader (indexed FindOne) + friendly load-error message
- **Active Directory:** ldap:// URL handling, scheme-aware reachability port, monochrome icon
- **Active Directory:** live AD card on global Changes page + per-element membership diff
- **Active Directory:** register ad in the snapshot-picker collection list
- **Backend:** backfill Palo admin stamps from change_log on live re-diffs
- **Backend:** DeviceGroupOf classifies first-class ftd as firewall
- **Backend:** ftd diffCollectionsForType mirrors router running_config exclusion
- **Backend:** load config (.env) before encryption key in migrate CLI
- **Backend:** migrate CLI treats cleaned sources as completed, not partial
- **Backend:** migrate-ftd-devices partial-copy abort + batched inserts
- **Backend:** read device id, not _id, in the palo audit-merge loader
- **Backend:** restore VPN-peer endpoint rows for FTD via ftd_crypto_maps leg
- **Backend:** smaller insert batches for running-config blobs in migrate CLI
- **Changemail:** FMC flow card treats empty nested field as 'any'
- **Changemail:** renamed body-only (no orphan name); drop dead email helpers
- **Changes:** card polish — house-style running-config diff, drop severity rail, fix nested button
- **Changes:** hide 'Seen on' in collapsed card, keep it expanded-only
- **Changes:** render FTD object-group members, not [object Object]
- **Changes:** router/switch tab expand uses live diff (friendly labels + expandable items)
- **Database:** harden Mongo connect — index ctx, server-selection timeout, explicit concern, closes #637 #638 #639
- **Database:** tie DB health monitor to the cancellable root context
- **Docker:** clear Trivy CRITICAL/HIGH from mongo:7.0 base image
- **Email:** bulletproof Open-in-Samurai button for desktop Outlook
- **Email:** keep "Open in Samurai" button on the device-name row
- **Email:** pure rename/reorder no longer suppresses notification
- **Endpoints:** skip disabled/inactive devices in materialized path
- **Endpoints:** surface device interface IPs (Loopback/SD-WAN), merge shared IPs
- **Enrichment:** anchor change headline to home device + add "Seen on" provenance
- **Filterbar:** keep Search button visible when autoApply is on (#588 follow-up)
- **Cisco FMC:** cross-reference FTD devices by url host, not just ip
- **Cisco FMC:** validate comment date against the change interval (±30min); dedup footer; stamp backfill tool
- **Frontend:** correct page title/meta to "monitoring & security platform"
- **Frontend:** critique P0/P1 - partial-sync visibility, DataTable keyboard access, type-map drift
- **Frontend:** graft stored enrichment onto device-tab live diffs - the #533 fast-follow; router/switch + APIC timeline expands now merge change_log items enrichment into the live re-diff exactly like the global Changes page
- **Frontend:** guard ProxyIdsDiff row.entry for tsc -b narrowing
- **Frontend:** unbreak npm run build — toast import + vendor↔shared diff casts
- **Cisco FTD/ASA:** align timeline diff-collection set with structured collections
- **Cisco FTD/ASA:** export filter matches table — full-doc firewall matcher, not reduced row
- **Cisco FTD/ASA:** field-scoped search matches resolved-value companion (&lt;field&gt;_values)
- **Cisco FTD/ASA:** flatten access-rule operands to collapsible value chips; drop repetitive section from Rule cell
- **Cisco FTD/ASA:** harden config parser — nil-panic, empty-name, nil-slices, description lines
- **Cisco FTD/ASA:** narrow config-diff strip to match parser breadth (decision A invariant)
- **Cisco FTD/ASA:** parse ACE source port operator (don't bleed into destination)
- **Cisco FTD/ASA:** resolve all NAT operands (translated src + both dest), not just original source
- **Cisco FTD/ASA:** resolve object-group member values for display + wire access-rules export
- **Cisco FTD/ASA:** resolve SSH host from url when ip is empty (deviceHost fallback)
- **Cisco FTD/ASA:** stop ValueChips more/less click from toggling row expansion
- **Cisco FTD/ASA:** treat ftd as an SSH/IP device (not url/API) across both tiers
- **Landing:** ration section eyebrows + decorative dots to check icons
- **Landing:** strip em-dashes + replace fake screenshot with real image
- **Login:** raise footer-tagline contrast to AA + add katana keyline
- **NDO:** exclude client-derived columns from filter field list
- **NDO:** persist Changes Timeline + Audit pagination/filters in URL
- **Palo Alto:** correlate address/service group edits with audit log
- **Parsers:** consume day/week-form route age in FTD route regex
- **Parsers:** drop bled command echoes from VLAN Ports column
- **Routes:** include device_name in the free-text route search (#588 follow-up)
- **Ssh,aci:** recover ACI management VRF routes — prompt false-match + vsh context
- **SSH:** prompt-gated NX-OS bulk send to kill echo bleed at source
- **SSH:** strip bled session-closing 'exit' from running-config blob
- **Timeline:** clone AllDeviceTypes instead of aliasing in scanTypes
- **Topology:** align ise node hue to canonical teal (de-collide from ad)
- **Topology:** bump wheelSensitivity to 3 for snappier scroll-zoom
- **Topology:** carry node status + style accuracy-engine edge methods
- **Topology:** coerce optional connection_type in legacy NetworkBuilder (tsc -b)
- **Topology:** normalize theme colors so light-theme node cards aren't gray
- **Topology:** pin node bg to hex literal — real fix for gray light-theme cards
- **Topology:** pre-bundle cytoscape deps in optimizeDeps to avoid dev re-optimize reload
- **Topology:** restore default wheel zoom sensitivity in network view
- **Topology:** single DEVICE_HEX for node icon+border; fix ISE indigo border
- **Topology:** skip redundant initial re-layout in CytoscapeCanvas
- **Traffic Simulation:** #634 off-fabric egress — naming-form tolerance + multi-border honesty (advisor)
- **Traffic Simulation:** #634 resolve public off-fabric egress (kill the dead-end)
- **Traffic Simulation:** COOP keep-all-copies — resolve by distinct owner, end the false-unresolved
- **Traffic Simulation:** COOP name-only egress fallback (partial; #635 tracks root cause)
- **Traffic Simulation:** cross-plane fallback → fail honest in-VN
- **Traffic Simulation:** deterministic IP→device resolution across cache rebuilds
- **Traffic Simulation:** distinguish vrf-no-route from vrf-unknown
- **Traffic Simulation:** don't misclassify IS-IS routes as connected in VRF derivation
- **Traffic Simulation:** egress through border leaf + firewalls for external dests (#629 increment 1)
- **Traffic Simulation:** exclude disabled/inactive devices from trace + firewall eval
- **Traffic Simulation:** gate the FMC-policy hop annotation on evaluate_policy
- **Traffic Simulation:** kill ACI spine-wander — spine-proxy TEP trigger + reachability-constrained search
- **Traffic Simulation:** model VRF per-hop via routes_index containment
- **Traffic Simulation:** remove env-tuned mgmt-VRF skip + make fallback deterministic
- **Traffic Simulation:** replace ACL matched-entry side-stripe with leading marker
- **Versioning:** make /api/version actually public (auth-exempt)
- **Website:** #542 P2/P3 cleanup — token fossils, honest footer, stats rule, a11y
- **Website:** critique re-run - i18n wave 2, claim consistency, ZoomTopology CLS, contrast, FocusSection, docs security
- **Website:** hero headline invisible on some GPUs - solid color instead of background-clip:text gradient
- **Website:** new page opening scrolled to bottom after bottom-of-page navigation
- **Website:** polish pass - dead blog cards, ZoomTopology motion contract, i18n leaks, token fossils
- **Website:** purge em-dashes from EN marketing copy
- **Website:** WCAG AA contrast on emerald CTA + light accent; a11y defaults

## Performance Improvements

- **Topology:** cache texture + hide edges + cap pixelRatio on viewport
- **Topology:** skip fcose relayout on edge/data-only changes; memoize icon SVGs
- **Website:** animation polish from design-engineering review
