This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
ReleasePort's take
Light signalThe release adds a guard that verifies auth providers are enabled before login attempts and fixes OIDC refresh token handling in the backend.
Why it matters: Ensures authentication flows only proceed when providers are active; critical for preventing failed logins. Fixes OIDC refresh‑token bugs (severity 40) that could cause access interruptions.
Summary
AI summaryFixed OIDC refresh token handling and added a guard to ensure auth providers are enabled before login attempts.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Checks OIDC/password auth providers are enabled before login attempt. Checks OIDC/password auth providers are enabled before login attempt. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Fixes OIDC refresh token handling in backend. Fixes OIDC refresh token handling in backend. Source: llm_adapter@2026-06-11 Confidence: high |
— |
Full changelog
v1.30.3 (2026-06-11)
Bug Fixes
-
backend: OIDC refresh tokens (
91bc17b) -
security: Check OIDC/password auth providers is enabled before trying to login by @finderer (
76371db)
Detailed Changes: v1.30.2...v1.30.3
Security Fixes
- Check OIDC/password auth providers are enabled before login to prevent unauthorized attempts
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]