better-release[bot] and GitHub
8b1e759c07
chore: release v1.7.0-beta.5 ( #9905 )
2026-06-10 12:34:04 -07:00
Gustavo Valverde
bf7f2c5b4e
chore: sync main to next
2026-06-10 11:30:38 -07:00
better-release[bot] and GitHub
1a3c8c478a
chore: release v1.6.16 ( #9958 )
2026-06-09 22:32:25 -07:00
Bereket Engida and GitHub
cb1cbfa4cc
fix: address bug findings across packages ( #9974 )
2026-06-09 19:46:12 -07:00
Gustavo Valverde and GitHub
0e1770ac75
feat(oauth-provider)!: enforce max_age ( #9936 )
2026-06-09 19:36:30 -07:00
Gustavo Valverde and GitHub
a6b0295df3
fix(sso): consume SAML AuthnRequest atomically ( #9972 )
2026-06-10 01:58:45 +00:00
Gustavo Valverde and GitHub
87e7aa5e0f
fix(api): validate Origin/Referer on cookieless email sign-in and sign-up ( #9973 )
2026-06-10 01:43:41 +00:00
Gustavo Valverde and GitHub
893cf6cb3f
fix(session): honor server-side session deletion in update-session and token routes ( #9967 )
2026-06-10 00:42:45 +00:00
Gustavo Valverde and GitHub
76a33429fc
fix(session): fire session-delete hooks for preserved sessions on secondaryStorage ( #9969 )
2026-06-10 00:40:56 +00:00
Gustavo Valverde and GitHub
3e852a2650
fix(oauth-provider): report unsupported_token_type for JWT access-token revocation ( #9970 )
2026-06-10 00:39:26 +00:00
Gustavo Valverde and GitHub
7abaaed53f
fix(oauth-provider): make private_key_jwt jti single-use atomic across processes ( #9964 )
2026-06-10 00:36:06 +00:00
Gustavo Valverde and GitHub
ec8a38c08f
feat(generic-oauth): verify discovery id_tokens and enable id_token sign-in ( #9966 )
2026-06-10 00:34:26 +00:00
Gustavo Valverde and GitHub
5e49c56a9e
fix(auth): mark plugin-owned session fields as non-input ( #9965 )
2026-06-09 23:59:09 +00:00
Paola Estefanía de Campos and GitHub
afcb4dd7f3
docs(two-factor): document newSession is null during 2FA challenge ( #9957 )
2026-06-09 13:15:00 -07:00
better-release[bot] and GitHub
03e0e36a98
chore: release v1.6.15 ( #9886 )
2026-06-08 06:57:06 -07:00
ef4e131b85
fix(kysely-adapter): inline migration-table constants to fix Turbopack build ( #9933 )
...
Co-authored-by: bytaesu <166604494+bytaesu@users.noreply.github.com >
2026-06-08 12:20:53 +00:00
Gustavo Valverde and GitHub
af572166a2
fix(auth)!: harden validateUserInfo source contract ( #9940 )
2026-06-07 22:52:59 -07:00
Gustavo Valverde and GitHub
fe9600bc07
feat(oauth-provider): accept POST on the userinfo endpoint ( #9937 )
2026-06-07 21:09:27 -07:00
0cbaf81bed
feat(oauth): server-trusted state channel; fix anonymous cookieless linking ( #9930 )
...
Co-authored-by: Taesu <166604494+bytaesu@users.noreply.github.com >
2026-06-08 01:00:05 +00:00
91f235f860
feat(auth): add per-provider requireEmailVerification for social sign-in ( #9929 )
...
Co-authored-by: Gautam Manchandani <161146829+GautamBytes@users.noreply.github.com >
2026-06-08 00:31:20 +00:00
e0140297a5
fix(electron)!: enforce S256 PKCE and harden origin checks ( #9645 )
...
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-07 23:43:06 +00:00
d23735b1de
feat(passkey): resolve authenticator name from AAGUID at read time ( #9927 )
...
Co-authored-by: Maxwell Weru <1645026+mburumaxwell@users.noreply.github.com >
2026-06-07 23:22:39 +00:00
b0ddfd3433
fix(oauth-provider): run configured hooks when authorize resumes ( #9919 )
...
Co-authored-by: Gautam Manchandani <manchandanigautam@gmail.com >
2026-06-07 14:43:47 -07:00
Gustavo Valverde and GitHub
7213d1ac3a
test(cli): give the integration-style suite a generous timeout ( #9926 )
2026-06-07 14:36:12 -07:00
41cca606d1
feat(auth): add user.validateUserInfo provisioning gate ( #9864 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-07 14:34:48 -07:00
Gustavo Valverde and GitHub
e0d2b9eb9b
feat(oauth-provider)!: add OIDC back-channel logout ( #9304 )
2026-06-06 07:06:53 -07:00
bff65fd620
fix(sso): pass clockSkew to samlify clockDrifts to fix ERR_SUBJECT_UNCONFIRMED ( #9748 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
Co-authored-by: ping-maxwell <maxwell.multinite@gmail.com >
2026-06-06 04:20:14 +00:00
7fe0e2b165
feat: add clientAssertion support to the Microsoft Entra ID social provider ( #9898 )
...
Co-authored-by: Bereket Engida <86073083+Bekacru@users.noreply.github.com >
Co-authored-by: Bereket Engida <Bekacru@gmail.com >
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-05 20:28:46 -07:00
Gustavo Valverde and GitHub
4f53b61f49
refactor(oauth)!: verify provider id_tokens with a single shared verifier ( #9828 )
2026-06-05 08:00:03 -04:00
Gustavo Valverde and GitHub
40b392ae21
feat(oauth)!: accumulate granted scopes as grantedScopes string[] ( #9825 )
2026-06-04 17:54:52 -04:00
0933c050ff
fix(kysely-adapter): import migration constants from 'kysely/migration' ( #9811 )
...
Co-authored-by: unsiqasik <rkhandriantonew@gmail.com >
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-03 22:32:20 +00:00
1012b69046
fix(admin): return USER_NOT_FOUND for missing users before update ( #9875 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-03 16:07:47 +00:00
ad60333d15
fix: list-session fresh age session check ( #9865 )
...
Co-authored-by: Cursor Agent <cursoragent@cursor.com >
Co-authored-by: Maxwell <ping-maxwell@users.noreply.github.com >
2026-06-03 11:23:14 +00:00
Taesu and GitHub
e111d63b8e
refactor(cookies): clarify cookie regex ranges ( #9879 )
2026-06-03 04:05:55 +00:00
better-release[bot] and GitHub
5038d41ca2
chore: release v1.6.14 ( #9846 )
2026-06-02 16:56:28 -04:00
Gustavo Valverde and GitHub
2d9781a83d
fix(organization): split invitation verification gates ( #9877 )
2026-06-02 16:45:44 -04:00
Taesu and GitHub
5a2d642bc7
fix: accept null for optional fields in generated schema ( #9841 )
2026-06-01 06:28:56 +00:00
Taesu and GitHub
9d3450ae23
fix(cookies): prefer __Secure- cookie in getSessionCookie ( #9806 )
2026-06-01 04:05:40 +00:00
better-release[bot] and GitHub
a5e2442e3c
chore: release v1.7.0-beta.4 ( #9534 )
2026-05-31 14:29:39 +01:00
Gustavo Valverde and GitHub
b4b086722c
fix(oauth-provider)!: bind RFC 8707 resource indicators to the authorization grant ( #9836 )
2026-05-31 14:14:50 +01:00
Gustavo Valverde and GitHub
a8ea86e25e
fix(scim)!: always bind personal SCIM connections to their creator ( #9840 )
2026-05-31 12:53:18 +00:00
Gustavo Valverde
1f4ca6e1e4
chore: sync main to next
...
Pull in #9845 (runtime-safe redirect-uri validation and fragment rejection) now that it merged to main, so next gets the corrected validation directly instead of waiting for a later sync.
2026-05-31 13:39:57 +01:00
Gustavo Valverde and GitHub
13abc7922b
fix(core): make redirect-uri validation runtime-safe and reject fragments ( #9845 )
2026-05-31 13:37:39 +01:00
Gustavo Valverde
065f5ad72d
chore: sync main to next
...
Brings the v1.6.13 stable fixes into next: redirect_uri scheme validation in oidc-provider and mcp (#9838 ), clientPrivileges enforcement on dynamic client registration (#9837 ), null organization logo support (#9842 ), the consumeOne non-numeric deleteMany guard (#9831 ), and the db-adapter guide alignment (#9830 ).
Conflicts were limited to release version bumps and CHANGELOG entries; resolved by keeping next's 1.7.0-beta.3 line. The ten changesets consumed by the v1.6.13 release are accepted as deleted, and no external dependencies changed.
2026-05-31 13:02:15 +01:00
better-release[bot] and GitHub
a6f38c72ee
chore: release v1.6.13 ( #9804 )
2026-05-31 12:41:17 +01:00
Gustavo Valverde and GitHub
17ab66c3a4
fix(oauth-provider): enforce clientPrivileges on dynamic client registration ( #9837 )
2026-05-31 11:02:27 +00:00
87c1a0cab2
fix(organization): allow null logo on create and update ( #9842 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-05-31 10:58:24 +00:00
Gustavo Valverde and GitHub
be32012ca3
fix(oauth): validate redirect_uri schemes in oidc-provider and mcp ( #9838 )
2026-05-31 11:38:52 +01:00
Taesu and GitHub
5c3e248cbf
fix(core): throw on non-numeric deleteMany in consumeOne fallback ( #9831 )
2026-05-31 09:00:18 +00:00
Gustavo Valverde
51a122fa6d
test(oidc-provider): align concurrent-redemption test to next's callback path ( #9533 )
...
The concurrent authorization-code redemption test (added on main for
GHSA-7w99-5wm4-3g79) exchanged the code against `/api/auth/oauth2/callback/test`,
but next renamed that callback path to `/api/auth/callback/test`. The merge
kept next's code-minting helper while preserving main's exchange path, so the
race winner failed redirect_uri validation and no caller minted a token,
tripping the "exactly one success" assertion.
Because that test threw before closing its listener on port 3000, the leaked
server poisoned the later EdDSA and HS256 oidc-jwt tests (stale server, code
not found on consume). Aligning the exchange path to next fixes all three.
2026-05-31 07:40:40 +01:00