This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryUpdates Other changes, Highlights, and SRI across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds link and unlink social logins from SDKs. Adds link and unlink social logins from SDKs. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Medium |
Enables account recovery by username in custom UI/Auth Flow. Enables account recovery by username in custom UI/Auth Flow. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Medium |
Shows account lockout status and reset capability in Portal User Details and Admin API. Shows account lockout status and reset capability in Portal User Details and Admin API. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Medium |
Includes identities claim in userinfo endpoint with provider details and timestamps. Includes identities claim in userinfo endpoint with provider details and timestamps. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Low |
Redesigns Getting Started page with cleaner layout and responsive grid. Redesigns Getting Started page with cleaner layout and responsive grid. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Low |
Adds project switcher to Portal header. Adds project switcher to Portal header. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Low |
Emits Subresource Integrity hashes and integrity‑checked import maps for Portal and AuthUI assets. Emits Subresource Integrity hashes and integrity‑checked import maps for Portal and AuthUI assets. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Fixes inability to turn off fraud protection once enabled. Fixes inability to turn off fraud protection once enabled. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Prevents Portal crash when an unknown OAuth provider type is configured. Prevents Portal crash when an unknown OAuth provider type is configured. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Handles 307 redirect during JWKS fetch when internal endpoint is HTTP and public endpoint is HTTPS. Handles 307 redirect during JWKS fetch when internal endpoint is HTTP and public endpoint is HTTPS. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Low |
Fixes clock skew issues in Admin API JWT verification and internal endpoint access. Fixes clock skew issues in Admin API JWT verification and internal endpoint access. Source: granite4.1:30b@2026-06-11-audit Confidence: low |
— |
| Bugfix | Low |
Prevents required array fields from disappearing during YAML config round‑trip. Prevents required array fields from disappearing during YAML config round‑trip. Source: granite4.1:30b@2026-06-11-audit Confidence: low |
— |
Full changelog
Highlights
- Link and unlink social logins from SDKs. End users can now connect or disconnect their OAuth/social providers themselves directly from the SDK, skipping the setting page.
- Account recovery by username. The account recovery flow now works for projects that use a username as the primary login ID, not just email or phone. (Custom UI/Auth Flow only.)
- Account lockout management. The Portal's User Details screen now shows a user's account lockout status and lets you reset it. The same is available through the Admin API via a new
resetAccountLockoutmutation, with audit logging for both. - Redesigned Getting Started page. The Portal onboarding page has been rebuilt with a cleaner layout, clearer integration CTAs, and a responsive grid that adapts down to smaller screens.
- Project switcher in the Portal header. A project selector now lives in the header.
- Identities in the userinfo endpoint. The userinfo endpoint now returns an
identitiesclaim, including provider type, login ID type and key, and created/updated timestamps. - Subresource Integrity (SRI). The Portal and AuthUI now emit SRI hashes and integrity-checked import maps for their bundled assets, hardening them against tampering.
Other changes
- User Details now has a paginated User Activities tab in place of the old inline logs view.
- Social and enterprise login tables now show the OAuth provider alias.
- Login-link email templates are now shown in the MFA via Email tab.
- Fixed: fraud protection could not be turned off once enabled.
- Fixed: Portal crash when an unknown OAuth provider type was configured.
- Fixed: JWKS fetch failed with a 307 redirect when the internal endpoint was HTTP and the public endpoint was HTTPS.
- Fixed: clock skew on Admin API JWT verification and internal endpoint access.
- Fixed: required array fields could drop out of a YAML config round-trip.
- Other misc fixes
Security Fixes
- Subresource Integrity (SRI) hashes and integrity‑checked import maps emitted by Portal and AuthUI, hardening bundled assets against tampering
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About authgear-server
Open source Auth0/Clerk/Firebase alternative. Passkeys, SSO, MFA, passwordless, biometric login. Self-hosted or cloud. Enterprise-ready for SaaS & mobile apps
Related context
Beta — feedback welcome: [email protected]