← Back to release notes
Theka v1.1.1 — Multi-storage, AI and Security
Version 1.1.1 BetaApril 15, 2026
New Features
Multi-connector storage
- Configure multiple storages in parallel for the same tenant (S3 + SharePoint + SFTP + Dropbox)
- A writable default plus read-only storages for external mounts (SharePoint, read-only SFTP)
- Configurable derived path: originals can stay on SharePoint while thumbnails/previews live on fast S3
.gitignore-style exclusion patterns to skip specific files
New SFTP connector
- Full SFTP support with password or SSH key authentication (RSA + Ed25519)
- Connection pooling for optimal performance
- Backend proxy streaming for large file downloads
Folder browser + custom upload path
- New integrated file browser for storage folders
- At upload you can pick a specific path (e.g.
documents/suppliers/2026/) mirroring existing corporate structures
Automatic document classification (AI)
- AI suggests category and document type from the filename during upload
- Category is no longer mandatory: if uploaded without one, the AI classifies automatically after ingestion using the content
- Unclassified assets show a «To classify» badge
- Global toggle in AI settings to enable/disable
Auto-apply AI tags with smart dedup
- New «Apply tags automatically» toggle: AI-generated tags are assigned directly without confirmation
- Smart dedup: similar tags (e.g. «quotes» vs «quote», «user guide» vs «guide») are recognized and unified automatically
Ingestion monitoring + asset reprocessing
- Each asset exposes its processing state: Pending, Running, Completed, Partial, Failed
- Colored badges and dedicated filter to quickly find problematic assets
- New Reprocess button with dropdown: reprocess everything or specific steps only (OCR, embeddings, thumbnails, AI analysis…)
- Available to DAM admins only
Browser security (patch 1.1.1)
- Strict Content-Security-Policy with nonce: comprehensive XSS protection
- Trusted Types: additional defense against DOM XSS
- Clear-Site-Data on logout: automatic cleanup of cookies and session data from the browser
- Permissions-Policy: camera, microphone, geolocation, USB and sensors disabled by default
- Cross-Origin-Opener-Policy: isolation from popups
- Preparation for ISO 27001 / SOC 2 / HIPAA certifications
Updates
Secure PDF preview
- PDF preview now uses a canvas-rendered custom viewer: no more native Save/Print toolbar that bypassed download controls
- Custom controls: page navigation, 50-300% zoom, scroll
- The only way to get the original file is the Download button, subject to permissions and audit logging
Streaming download for large files
- Large files (PDF/images) streamed in 64KB chunks: zero memory buffering, support for slow connectors (SFTP)
- Progress bar with percentage in the Download button
Hard delete with folder cleanup
- Confirmation dialog with optional «Also delete empty folders» checkbox
- When enabled, walks up the tree and removes parent folders only if empty: no recursive deletion
Configurable hybrid-search tuning
- New «Search tuning» section in AI settings with two sliders: semantic threshold and full-text/semantic balance
- Optimized defaults, tweak only when you need more precise or broader results
Richer file metadata
- Author, title, creation/modification date, revision, keywords, paragraph/sheet count (Word/Excel), dimensions and format (images)
Markdown AI rendering
- AI summary, description and OCR text now rendered as formatted markdown (headings, lists, bold, tables)
AI embedding resilience
- Automatic retry with exponential backoff on provider rate-limits (5 attempts)
- Automatic notification to the tenant admin if the rate-limit exhausts all retries
Performance and accessibility (patch 1.1.1)
- Cookie banner deferred after page load (LCP -1.3s)
- Google Tag Manager on lazy load (TBT reduction)
- Lighter JS bundle (-14 KiB) and optimized preconnect (-90ms LCP)
- WCAG AA color contrast: footer, badges, chips, cookie banner now compliant
Bug Fixes
- Fixed the Microsoft/Google SSO login crash when the email was already registered
- AI-extracted metadata now displayed correctly even when the output is in Italian
- Downloads and previews via SFTP/SharePoint now work correctly (backend proxy routing)
- PDF preview no longer blocked by stricter browser security controls (CSP worker-src)
- Added missing «Published» status translation
- Upload without a preselected category no longer produces errors
- Fixed crash on connector configurations with empty fields (base URL, token limit)
- Fixed download requests that were pulling from the default connector instead of the asset's own
- Informative dialog on default-storage change to avoid confusion about already-uploaded files
General Info
This release bundles the v1.1.0 new features (multi-connector storage, AI classification, ingestion monitoring, auto tags) and the v1.1.1 security & performance hardening (strict CSP, Trusted Types, Clear-Site-Data, Core Web Vitals optimizations) into a single update.
Version 1.1.0 was never released to production: it ships directly as 1.1.1 to deliver everything in one step.
Upgrade notes:
- New database migrations apply automatically at startup. The PostgreSQL
pg_trgmextension is required for tag dedup. - The default storage cannot be read-only: if the existing configuration has it, it is auto-corrected on save.
- Asset category is now optional at upload: existing assets are not impacted.
- Regenerating embeddings after the upgrade is recommended if the semantic threshold is changed from defaults.