Skip to content

authgear-server

v2026-06-11.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

2fa auth0 authentication biometric clerk-alternative firebase-alternative
+14 more
identity identity-provider keycloak login mfa oauth2 oidc openid-connect passkeys passwordless self-hosted sso supertokens webauthn

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Updates Other changes, Highlights, and SRI across a mixed release.

Changes in this release

Feature Medium

Adds link and unlink social logins from SDKs.

Adds link and unlink social logins from SDKs.

Source: llm_adapter@2026-06-11

Confidence: high

Feature Medium

Enables account recovery by username in custom UI/Auth Flow.

Enables account recovery by username in custom UI/Auth Flow.

Source: llm_adapter@2026-06-11

Confidence: high

Feature Medium

Shows account lockout status and reset capability in Portal User Details and Admin API.

Shows account lockout status and reset capability in Portal User Details and Admin API.

Source: llm_adapter@2026-06-11

Confidence: high

Feature Medium

Includes identities claim in userinfo endpoint with provider details and timestamps.

Includes identities claim in userinfo endpoint with provider details and timestamps.

Source: llm_adapter@2026-06-11

Confidence: high

Feature Low

Redesigns Getting Started page with cleaner layout and responsive grid.

Redesigns Getting Started page with cleaner layout and responsive grid.

Source: llm_adapter@2026-06-11

Confidence: high

Feature Low

Adds project switcher to Portal header.

Adds project switcher to Portal header.

Source: llm_adapter@2026-06-11

Confidence: high

Feature Low

Emits Subresource Integrity hashes and integrity‑checked import maps for Portal and AuthUI assets.

Emits Subresource Integrity hashes and integrity‑checked import maps for Portal and AuthUI assets.

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Medium

Fixes inability to turn off fraud protection once enabled.

Fixes inability to turn off fraud protection once enabled.

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Medium

Prevents Portal crash when an unknown OAuth provider type is configured.

Prevents Portal crash when an unknown OAuth provider type is configured.

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Medium

Handles 307 redirect during JWKS fetch when internal endpoint is HTTP and public endpoint is HTTPS.

Handles 307 redirect during JWKS fetch when internal endpoint is HTTP and public endpoint is HTTPS.

Source: llm_adapter@2026-06-11

Confidence: high

Bugfix Low

Fixes clock skew issues in Admin API JWT verification and internal endpoint access.

Fixes clock skew issues in Admin API JWT verification and internal endpoint access.

Source: granite4.1:30b@2026-06-11-audit

Confidence: low

Bugfix Low

Prevents required array fields from disappearing during YAML config round‑trip.

Prevents required array fields from disappearing during YAML config round‑trip.

Source: granite4.1:30b@2026-06-11-audit

Confidence: low

Full changelog

Highlights

  • Link and unlink social logins from SDKs. End users can now connect or disconnect their OAuth/social providers themselves directly from the SDK, skipping the setting page.
  • Account recovery by username. The account recovery flow now works for projects that use a username as the primary login ID, not just email or phone. (Custom UI/Auth Flow only.)
  • Account lockout management. The Portal's User Details screen now shows a user's account lockout status and lets you reset it. The same is available through the Admin API via a new resetAccountLockout mutation, with audit logging for both.
  • Redesigned Getting Started page. The Portal onboarding page has been rebuilt with a cleaner layout, clearer integration CTAs, and a responsive grid that adapts down to smaller screens.
  • Project switcher in the Portal header. A project selector now lives in the header.
  • Identities in the userinfo endpoint. The userinfo endpoint now returns an identities claim, including provider type, login ID type and key, and created/updated timestamps.
  • Subresource Integrity (SRI). The Portal and AuthUI now emit SRI hashes and integrity-checked import maps for their bundled assets, hardening them against tampering.

Other changes

  • User Details now has a paginated User Activities tab in place of the old inline logs view.
  • Social and enterprise login tables now show the OAuth provider alias.
  • Login-link email templates are now shown in the MFA via Email tab.
  • Fixed: fraud protection could not be turned off once enabled.
  • Fixed: Portal crash when an unknown OAuth provider type was configured.
  • Fixed: JWKS fetch failed with a 307 redirect when the internal endpoint was HTTP and the public endpoint was HTTPS.
  • Fixed: clock skew on Admin API JWT verification and internal endpoint access.
  • Fixed: required array fields could drop out of a YAML config round-trip.
  • Other misc fixes

Security Fixes

  • Subresource Integrity (SRI) hashes and integrity‑checked import maps emitted by Portal and AuthUI, hardening bundled assets against tampering

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track authgear-server

Get notified when new releases ship.

Sign up free

About authgear-server

Open source Auth0/Clerk/Firebase alternative. Passkeys, SSO, MFA, passwordless, biometric login. Self-hosted or cloud. Enterprise-ready for SaaS & mobile apps

All releases →

Beta — feedback welcome: [email protected]