Skip to content

Keep team time private in the Summary, plus a security & maintenance release

Versions 2.0.39 and 2.0.40 · All release notes

We’ve published two updates to the Time Log extension for Azure DevOps. The headline is a new admin option that lets organisations keep each person’s logged time private in the Time Log Summary. There are also richer Summary CSV exports and a behind-the-scenes security and maintenance release. There’s nothing you need to do — here’s what changed.

  • 👤 New admin option: Restrict summary to current user — stop users browsing each other’s time (v2.0.40)
  • 📊 Richer Summary CSV exports — new Project Id, Team and Area columns (v2.0.39)
  • 🔧 Security & maintenance release — dependency and build-pipeline hardening (v2.0.39)

👤 Keep each person’s time private in the Summary

Section titled “👤 Keep each person’s time private in the Summary”

Some organisations don’t want everyone to be able to look up how much time their colleagues have logged. The Time Log Admin page now has a new option — “Restrict summary to current user” — that locks the Time Log Summary down to each person’s own time.

When it’s switched on

  • The team filter shows only the teams the current user belongs to.
  • The user filter offers only the user themselves — so they can view their own time, but not anyone else’s.
  • Azure DevOps team administrators are the exception: for each selected team they administer, every member of that team stays selectable — so team leads can still report on their team.

The rule is applied team by team: administering one team never exposes the members of a different team the user merely belongs to. And it’s strict by design — if the list of teams or members can’t be resolved for any reason, the Summary shows nothing rather than falling back to everyone.

How to turn it on

  1. Open Project Settings → Extensions → Time Log Admin.
  2. Tick “Restrict summary to current user” and save.

This option defaults to off, so existing organisations see no change until an administrator enables it.

The Download CSV button on the Time Log Summary now includes several extra columns, making it easier to slice, pivot and join your time data in Excel, Power BI or your own reporting tools:

  • Project Id — alongside the existing Project name.
  • Team Name and Team Id.
  • Area Path and Area Id — the work item’s area, next to its title.

The columns appear automatically in every export — there’s nothing to switch on, and no change to how you generate the report. Rows for deleted or unavailable work items simply leave the new cells blank.

Alongside the CSV improvements above, v2.0.39 includes housekeeping work you won’t see but will benefit from. Under the hood we’ve strengthened the build and keep-up-to-date foundations:

  • Resolved all outstanding high-severity dependency advisories in the build toolchain.
  • Hardened the build and release pipeline for more reliable, reproducible releases.
  • Fixed a local developer tooling issue so the project builds cleanly.

Nothing is required from you — the update installs automatically like any other.

Time Log Summary CSV: add Project Id (alongside the existing Project name), Team Name and Team Id, and the work item’s Area Path and Area Id (System.AreaPath / System.AreaId, placed after Work Item Title) columns to the download. The values reuse data already fetched by the Summary, so no extra Azure DevOps requests are made; placeholder rows (deleted / not found / failed batch) leave the new cells blank. Also a maintenance and security pass with no other functional changes: resolve all high-severity npm dependency advisories in the build toolchain (nth-check, serialize-javascript, brace-expansion and related transitive packages pulled in via react-scripts) using package.json overrides. Harden the build/release pipeline: declare a Node >=20 engine requirement, pin Node 22.x in Azure Pipelines, and switch CI to npm ci for reproducible installs from the committed lockfile. Also fix a local npm start dev-server crash by pinning webpack-dev-server to 4.11.1.

Time Log Summary: add an admin option Restrict summary to current user for organisations that need to stop users viewing each other’s time. When enabled, the Summary’s team filter lists only the teams the current user belongs to (resolved via the Core API’s mine filter, one request), and the user filter offers only the user themselves. Azure DevOps team administrators are the exception: for each selected team they administer, every member of that team remains selectable. The rule is evaluated team by team, so administering one team never exposes the members of another team the user merely belongs to. Every failure mode fails closed — an unresolvable team list or membership lookup yields no teams and no users rather than falling back to the full set. Defaults off, so existing organisations see no behaviour change. Maintenance: migrate the build and test toolchain from Create React App + Jest to Vite + Vitest; the extension’s behaviour, build output layout and test suite are unchanged.