better-release[bot] and GitHub
0d8b238acc
chore: release v1.6.17 ( #9984 )
2026-06-11 19:50:30 -07:00
Taesu and GitHub
eff3c99952
test(next-js): verify nextCookies forwards all set-cookie headers ( #10013 )
2026-06-11 18:46:21 -07:00
Taesu and GitHub
ac69e81a29
fix(cli): skip Unsupported() fields when regenerating prisma schema ( #10011 )
2026-06-11 17:19:17 -07:00
Gautam Manchandani and GitHub
e0a768c973
refactor(access): flatten access plugin role authorization logic ( #9677 )
2026-06-11 17:04:07 -07:00
Gautam Manchandani and GitHub
3310ebc4a0
fix(open-api): mark model ids as required ( #9704 )
2026-06-11 17:01:24 -07:00
108aadd251
fix(cli): update existing prisma field types ( #9729 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-11 16:59:14 -07:00
59e0ccbedc
fix(client): updateSession should infer session additional fields ( #9777 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-11 16:56:45 -07:00
Gautam Manchandani and Bereket Engida
96c78c3e98
fix(logger): downgrade validation logs level to warn
2026-06-11 16:50:14 -07:00
Arnav Sharma and GitHub
d3758fb2a3
fix(expo): on /linkSocial include cookie for id token ( #9953 )
2026-06-11 16:45:19 -07:00
5c289b52bc
fix(account): resolve stateless account cookies across instances ( #9979 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-11 16:44:11 -07:00
Gustavo Valverde and GitHub
8960f5f3bd
fix(client): restructure session fetch architecture ( #8760 )
2026-06-11 22:49:34 +00:00
Gustavo Valverde and GitHub
7faddd4a1d
refactor(core): prevent accidental HTTP exposure of server-only endpoints ( #9835 )
2026-06-11 20:37:51 +00:00
Gustavo Valverde and GitHub
ed7b6c9ac0
fix: enforce team capacity, constant-time SCIM tokens, and org-admin SSO domain verification ( #10002 )
2026-06-11 19:21:34 +00:00
Gustavo Valverde and GitHub
fdef997eb9
fix: harden provider identity validation (One Tap, Microsoft, SSO, WeChat, Reddit) ( #10003 )
2026-06-11 19:10:55 +00:00
7343284149
fix: jwks caching, oauth id mapping, team invitations, account cookie, and scim deprovision bugs ( #9987 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-11 08:25:19 -07:00
Gustavo Valverde and GitHub
0c3856f098
fix: harden session authority against stale cookie cache and unverified selectors ( #9991 )
2026-06-11 13:31:13 +00:00
Taesu and GitHub
d9c526b2a5
feat(oauth-popup): add popup-based OAuth sign-in ( #9890 )
2026-06-11 05:38:22 +00:00
Taesu and GitHub
3e99e6c77e
fix(admin): create credential account in setUserPassword when missing ( #9482 )
2026-06-11 05:36:55 +00:00
Gustavo Valverde and GitHub
baeaa00bc2
fix: make single-use credentials, counters, and replay markers atomic ( #9993 )
2026-06-11 05:11:26 +00:00
Gustavo Valverde and GitHub
1dbf5bb59d
fix: harden trusted request context ( #9990 )
2026-06-11 03:50:35 +00:00
6987c628f1
fix(cli): resolve SvelteKit, Vite asset, and Cloudflare virtual-module imports ( #9834 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-11 01:06:43 +00:00
b803c61fdc
fix(organization): reject setting unknown or empty roles on updateMemberRole ( #9962 )
...
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-06-10 16:57:24 -07:00
Taesu and GitHub
a11a706ff2
fix(stripe): correct subscription handling and customer linking ( #9971 )
2026-06-10 18:58:40 +00:00
better-release[bot] and GitHub
1a3c8c478a
chore: release v1.6.16 ( #9958 )
2026-06-09 22:32:25 -07:00
Bereket Engida and GitHub
cb1cbfa4cc
fix: address bug findings across packages ( #9974 )
2026-06-09 19:46:12 -07:00
Gustavo Valverde and GitHub
a6b0295df3
fix(sso): consume SAML AuthnRequest atomically ( #9972 )
2026-06-10 01:58:45 +00:00
Gustavo Valverde and GitHub
87e7aa5e0f
fix(api): validate Origin/Referer on cookieless email sign-in and sign-up ( #9973 )
2026-06-10 01:43:41 +00:00
Gustavo Valverde and GitHub
893cf6cb3f
fix(session): honor server-side session deletion in update-session and token routes ( #9967 )
2026-06-10 00:42:45 +00:00
Gustavo Valverde and GitHub
5e49c56a9e
fix(auth): mark plugin-owned session fields as non-input ( #9965 )
2026-06-09 23:59:09 +00:00
Paola Estefanía de Campos and GitHub
afcb4dd7f3
docs(two-factor): document newSession is null during 2FA challenge ( #9957 )
2026-06-09 13:15:00 -07:00
better-release[bot] and GitHub
03e0e36a98
chore: release v1.6.15 ( #9886 )
2026-06-08 06:57:06 -07:00
ef4e131b85
fix(kysely-adapter): inline migration-table constants to fix Turbopack build ( #9933 )
...
Co-authored-by: bytaesu <166604494+bytaesu@users.noreply.github.com >
2026-06-08 12:20:53 +00:00
Gustavo Valverde and GitHub
fe9600bc07
feat(oauth-provider): accept POST on the userinfo endpoint ( #9937 )
2026-06-07 21:09:27 -07:00
d23735b1de
feat(passkey): resolve authenticator name from AAGUID at read time ( #9927 )
...
Co-authored-by: Maxwell Weru <1645026+mburumaxwell@users.noreply.github.com >
2026-06-07 23:22:39 +00:00
b0ddfd3433
fix(oauth-provider): run configured hooks when authorize resumes ( #9919 )
...
Co-authored-by: Gautam Manchandani <manchandanigautam@gmail.com >
2026-06-07 14:43:47 -07:00
Gustavo Valverde and GitHub
7213d1ac3a
test(cli): give the integration-style suite a generous timeout ( #9926 )
2026-06-07 14:36:12 -07:00
bff65fd620
fix(sso): pass clockSkew to samlify clockDrifts to fix ERR_SUBJECT_UNCONFIRMED ( #9748 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
Co-authored-by: ping-maxwell <maxwell.multinite@gmail.com >
2026-06-06 04:20:14 +00:00
0933c050ff
fix(kysely-adapter): import migration constants from 'kysely/migration' ( #9811 )
...
Co-authored-by: unsiqasik <rkhandriantonew@gmail.com >
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-03 22:32:20 +00:00
1012b69046
fix(admin): return USER_NOT_FOUND for missing users before update ( #9875 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-03 16:07:47 +00:00
ad60333d15
fix: list-session fresh age session check ( #9865 )
...
Co-authored-by: Cursor Agent <cursoragent@cursor.com >
Co-authored-by: Maxwell <ping-maxwell@users.noreply.github.com >
2026-06-03 11:23:14 +00:00
Taesu and GitHub
e111d63b8e
refactor(cookies): clarify cookie regex ranges ( #9879 )
2026-06-03 04:05:55 +00:00
better-release[bot] and GitHub
5038d41ca2
chore: release v1.6.14 ( #9846 )
2026-06-02 16:56:28 -04:00
Gustavo Valverde and GitHub
2d9781a83d
fix(organization): split invitation verification gates ( #9877 )
2026-06-02 16:45:44 -04:00
Taesu and GitHub
5a2d642bc7
fix: accept null for optional fields in generated schema ( #9841 )
2026-06-01 06:28:56 +00:00
Taesu and GitHub
9d3450ae23
fix(cookies): prefer __Secure- cookie in getSessionCookie ( #9806 )
2026-06-01 04:05:40 +00:00
Gustavo Valverde and GitHub
13abc7922b
fix(core): make redirect-uri validation runtime-safe and reject fragments ( #9845 )
2026-05-31 13:37:39 +01:00
better-release[bot] and GitHub
a6f38c72ee
chore: release v1.6.13 ( #9804 )
2026-05-31 12:41:17 +01:00
Gustavo Valverde and GitHub
17ab66c3a4
fix(oauth-provider): enforce clientPrivileges on dynamic client registration ( #9837 )
2026-05-31 11:02:27 +00:00
87c1a0cab2
fix(organization): allow null logo on create and update ( #9842 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-05-31 10:58:24 +00:00
Gustavo Valverde and GitHub
be32012ca3
fix(oauth): validate redirect_uri schemes in oidc-provider and mcp ( #9838 )
2026-05-31 11:38:52 +01:00