Skip to content
← Back to release notes

Theka v1.1.1 — Multi-storage, AI and Security

Version 1.1.1 BetaApril 15, 2026

New Features

Multi-connector storage

  • Configure multiple storages in parallel for the same tenant (S3 + SharePoint + SFTP + Dropbox)
  • A writable default plus read-only storages for external mounts (SharePoint, read-only SFTP)
  • Configurable derived path: originals can stay on SharePoint while thumbnails/previews live on fast S3
  • .gitignore-style exclusion patterns to skip specific files

New SFTP connector

  • Full SFTP support with password or SSH key authentication (RSA + Ed25519)
  • Connection pooling for optimal performance
  • Backend proxy streaming for large file downloads

Folder browser + custom upload path

  • New integrated file browser for storage folders
  • At upload you can pick a specific path (e.g. documents/suppliers/2026/) mirroring existing corporate structures

Automatic document classification (AI)

  • AI suggests category and document type from the filename during upload
  • Category is no longer mandatory: if uploaded without one, the AI classifies automatically after ingestion using the content
  • Unclassified assets show a «To classify» badge
  • Global toggle in AI settings to enable/disable

Auto-apply AI tags with smart dedup

  • New «Apply tags automatically» toggle: AI-generated tags are assigned directly without confirmation
  • Smart dedup: similar tags (e.g. «quotes» vs «quote», «user guide» vs «guide») are recognized and unified automatically

Ingestion monitoring + asset reprocessing

  • Each asset exposes its processing state: Pending, Running, Completed, Partial, Failed
  • Colored badges and dedicated filter to quickly find problematic assets
  • New Reprocess button with dropdown: reprocess everything or specific steps only (OCR, embeddings, thumbnails, AI analysis…)
  • Available to DAM admins only

Browser security (patch 1.1.1)

  • Strict Content-Security-Policy with nonce: comprehensive XSS protection
  • Trusted Types: additional defense against DOM XSS
  • Clear-Site-Data on logout: automatic cleanup of cookies and session data from the browser
  • Permissions-Policy: camera, microphone, geolocation, USB and sensors disabled by default
  • Cross-Origin-Opener-Policy: isolation from popups
  • Preparation for ISO 27001 / SOC 2 / HIPAA certifications

Updates

Secure PDF preview

  • PDF preview now uses a canvas-rendered custom viewer: no more native Save/Print toolbar that bypassed download controls
  • Custom controls: page navigation, 50-300% zoom, scroll
  • The only way to get the original file is the Download button, subject to permissions and audit logging

Streaming download for large files

  • Large files (PDF/images) streamed in 64KB chunks: zero memory buffering, support for slow connectors (SFTP)
  • Progress bar with percentage in the Download button

Hard delete with folder cleanup

  • Confirmation dialog with optional «Also delete empty folders» checkbox
  • When enabled, walks up the tree and removes parent folders only if empty: no recursive deletion

Configurable hybrid-search tuning

  • New «Search tuning» section in AI settings with two sliders: semantic threshold and full-text/semantic balance
  • Optimized defaults, tweak only when you need more precise or broader results

Richer file metadata

  • Author, title, creation/modification date, revision, keywords, paragraph/sheet count (Word/Excel), dimensions and format (images)

Markdown AI rendering

  • AI summary, description and OCR text now rendered as formatted markdown (headings, lists, bold, tables)

AI embedding resilience

  • Automatic retry with exponential backoff on provider rate-limits (5 attempts)
  • Automatic notification to the tenant admin if the rate-limit exhausts all retries

Performance and accessibility (patch 1.1.1)

  • Cookie banner deferred after page load (LCP -1.3s)
  • Google Tag Manager on lazy load (TBT reduction)
  • Lighter JS bundle (-14 KiB) and optimized preconnect (-90ms LCP)
  • WCAG AA color contrast: footer, badges, chips, cookie banner now compliant

Bug Fixes

  • Fixed the Microsoft/Google SSO login crash when the email was already registered
  • AI-extracted metadata now displayed correctly even when the output is in Italian
  • Downloads and previews via SFTP/SharePoint now work correctly (backend proxy routing)
  • PDF preview no longer blocked by stricter browser security controls (CSP worker-src)
  • Added missing «Published» status translation
  • Upload without a preselected category no longer produces errors
  • Fixed crash on connector configurations with empty fields (base URL, token limit)
  • Fixed download requests that were pulling from the default connector instead of the asset's own
  • Informative dialog on default-storage change to avoid confusion about already-uploaded files

General Info

This release bundles the v1.1.0 new features (multi-connector storage, AI classification, ingestion monitoring, auto tags) and the v1.1.1 security & performance hardening (strict CSP, Trusted Types, Clear-Site-Data, Core Web Vitals optimizations) into a single update.

Version 1.1.0 was never released to production: it ships directly as 1.1.1 to deliver everything in one step.

Upgrade notes:

  • New database migrations apply automatically at startup. The PostgreSQL pg_trgm extension is required for tag dedup.
  • The default storage cannot be read-only: if the existing configuration has it, it is auto-corrected on save.
  • Asset category is now optional at upload: existing assets are not impacted.
  • Regenerating embeddings after the upgrade is recommended if the semantic threshold is changed from defaults.