Admin access fix for non-English projects, real work item icons in the Summary, and per-project time type control
Version 2.0.41 · All release notes
We’ve published a new update to the Time Log extension for Azure DevOps. The headline is an important fix for administrators on projects created in a language other than English, alongside real work item type icons in the Time Log Summary, a better Summary experience for Project Administrators, and per-project control over time types. There’s nothing you need to do — here’s what changed.
At a glance
Section titled “At a glance”- 🌐 Fixed: administrators locked out on non-English projects — the Admin page now recognises Project Administrators in every language
- 👤 Project Administrators see the full Summary — even when “Restrict summary to current user” is on
- 🔒 Time types are now managed per project — only administrators of a type’s own project can change it
- 🎨 Real work item type icons in the Summary — including your custom types and colours
- 🔧 Maintenance — modernised build toolchain and dependency updates
🌐 Fixed: administrators locked out on non-English projects
Section titled “🌐 Fixed: administrators locked out on non-English projects”Fixed in v2.0.41
Since v2.0.37 the Time Log Admin page has been locked to the project’s Project Administrators. That check looked the built-in administrators group up by its English name — but Azure DevOps translates built-in group names when a project is created in another language (for example “Administrateurs de projet” on a French project). On those projects the check found nothing and, because it is strict by design, locked out even genuine administrators.
The group is now identified by its language-independent built-in identifier instead of its display name, so the Admin page works regardless of the language your projects were created in. The same applies to the nested-group check, so Project Collection Administrators and members of AAD / Entra ID or on-premises AD groups inside Project Administrators are still recognised. If you were affected, access simply comes back with this update.
👤 Project Administrators see the full Summary
Section titled “👤 Project Administrators see the full Summary”v2.0.40 introduced the admin option “Restrict summary to current user”, which stops users browsing each other’s time in the Time Log Summary. Previously it applied to everyone — including the administrators who configure the extension — so getting a project-wide view meant turning the option off for the whole organisation.
Project Administrators are now exempt: with the option on, an administrator sees the full team and user lists for the current project, exactly as if the option were off. Everyone else is unaffected, and the existing team-administrator exception still works as before. As with the rest of the restriction, the check is strict by design — until administrator status is confirmed, the restriction stays in force.
🔒 Time types are now managed per project
Section titled “🔒 Time types are now managed per project”The Time Log Admin page lists time types from every project, and previously an administrator of one project could edit, move or delete another project’s types. Now:
- The edit, delete and move actions on a time type are only available if you administer the project that type belongs to — other rows are shown greyed out.
- The create / edit form’s Add / Update button is disabled, with an explanation, when the selected project isn’t one you administer.
- “All Projects” (organisation-wide) types are managed by administrators of the project you’re viewing from, and types whose owning project has been deleted are now clearly labelled “Unknown project” instead of showing a blank.
🎨 Real work item type icons in the Summary
Section titled “🎨 Real work item type icons in the Summary”Work item and parent rows in the Time Log Summary now show the work item’s actual Azure DevOps type icon — the same icon you see everywhere else in Azure DevOps, and the same treatment the My Time Log page already has.
Previously the Summary marked rows with a coloured bar that only recognised the seven built-in work item types — so custom types, and built-in types with customised icons or colours, weren’t represented. Now every type shows its own icon, straight from your process template. There’s nothing to configure.
🔧 Maintenance
Section titled “🔧 Maintenance”In v2.0.41
Behind the scenes we’ve continued modernising the foundations the extension is built on — upgrading the build and test toolchain to the latest major versions and keeping dependencies current and free of known advisories. You won’t see any of this, and nothing is required from you — the update installs automatically like any other.
Full change list
Section titled “Full change list”2.0.41
Section titled “2.0.41”Time Log Admin: fix genuine Project Administrators being locked out of the Admin page on projects created in a language other than English. The access check introduced in 2.0.37 identified the built-in Project Administrators group by its English display name, but Azure DevOps localises built-in group names when a project is provisioned — a French project has “Administrateurs de projet” and no English spelling at the data layer — so the lookup matched nothing and the strict default-deny policy denied every administrator. The group is now identified by its well-known, language-independent security identifier (S-1-9-...-0-0-0-0-1), resolved by listing the project scope’s groups rather than searching for a name, and the group’s owning project is verified before it is trusted. The Identity Service transitive check (used for Project Collection Administrators and nested AAD / Entra ID / AD groups) now matches on the same identifier, so it no longer depends on the localised [Project]\Project Administrators account name either. The English name match is retained only as a last resort, so installs that work today are unaffected. Also fixes a diagnostic gap: failing to resolve the admin group previously denied access silently, leaving no console message to explain a lockout. Time Log Summary: Project Administrators are now exempt from the Restrict summary to current user option added in 2.0.40, so they can see logged time for every user in the current project. Previously the option narrowed the Summary for everyone, including the administrators who configure the extension, so a project administrator wanting a project-wide view had to turn the option off for the whole organisation. With the option on, an administrator now sees the full team and user lists exactly as if it were off; everyone else is unaffected, keeping the existing per-team rules (own time only, unless they are an Azure DevOps team administrator of a selected team). Administrator status is resolved with the same language-independent, transitive check described above, so Project Collection Administrators and members of AAD / Entra ID / AD groups nested inside Project Administrators are recognised too, and it is only requested when the option is on. It fails closed: while the answer is being resolved, or if it cannot be resolved at all, the restriction stays in force. Time Log Admin: time type management is now restricted to administrators of each type’s project. The admin page already required Project Administrator rights on the current project, but the time type table lists every project’s types and the create / edit form could target any project — so an administrator of one project could edit, move or delete another project’s types. The table’s edit, delete and move controls are now greyed out unless the user administers the row’s project, and the create / edit form’s Add / Update button is disabled with an explanatory message when the selected project is not one the user administers. Organisation-wide (“All Projects”) types, and orphaned types whose owning project has been deleted or is not visible (now labelled “Unknown project” in the table, form and Move dialog instead of a blank cell), defer to the current project’s administrator. Per-project administrator status is resolved lazily for the projects on screen using the same language-independent, fail-closed check described above. Time Log Summary: work item and parent rows in the pivot now show the work item’s real Azure DevOps type icon, as My Time Log already does. Previously rows were marked with a hard-coded coloured bar that only recognised the seven built-in process-template types, so custom work item types — and customised icons or colours on built-in types — were not represented. The icon is fetched from Azure DevOps per project and work item type (cached, and concurrency-capped like the Summary’s other Azure DevOps requests); the old coloured bar remains only as a fallback for a type whose icon cannot be resolved. Maintenance: upgrade the build toolchain to Vite 8 (Rolldown-powered) and Vitest 4 — with @vitejs/plugin-react 6 and esbuild updates, plus the fixes to the Azure DevOps AMD module shim, plugin peer range and CSS minification the new majors required — bump uuid and jest-junit, and regenerate the npm lockfile to resolve a picomatch dependency issue.