This is the first patch release in the 4.2 cycle. Anybody using TWiki-4.2.0 is urged to upgrade.
There've been some major bugfixes, some of which are even security related.
There've been a lot of people that tried to integrate 4.2.0 into their LDAP infrastructure using one of the latest LdapContrib beta releases, and failed unfortunately. That's been a major headache for all of us and it turned out that 4.2.0 did a bad job refactoring its authentication and authorization code. While digging into the code we not only found it to be suboptimal in terms of performance and internal API, but also containing some sublte security bug when using non-alphabetic characters in a login name. That's been weeded out in 4.2.1 now. However, the latest LdapContrib betas will have to be rewritten once again to meet the changed internals of TWiki's user code. LdapContrib will continue to support TWiki-4.1.x, as well as TWiki-4.2.1 onwards, but not 4.2.0 as this simply was too buggy.
Anyway, a lot of people take a deep breath of relief that this patch release finally made its way out into the field and we are now able to concentrate on the next major release rolling your way with yet more exciting stuff under the hood.
Read on on what's new in this patch release, go get it
here.