Skip to content

tinyauth

v5.1.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

2fa authentication caddy go middleware nginx
+6 more
oidc self-hosted sso tinyauth totp typescipt

Affected surfaces

auth

Summary

AI summary

Security fixes address access control vulnerabilities and fix redirection logic for Nginx/Swag users.

Full changelog

Tinyauth v5.1.2

This path fix addresses some issues around the redirection logic (especially for Nginx/Swag users) and some security issues in access controls.

[!WARNING]
This release contains security fixes, please update as soon as possible.

Improvements

  • Parent domain is now considered a trusted domain
  • Allow for OAuth auto-redirect in OIDC flow

Fixes

  • Make login_for parameter optional
  • Fix redirection issues in HTTPS to HTTP downgrade redirect
  • Fix ACLs normalization in Docker and Kubernetes ACL providers

Technical

  • Update dependencies

Full Changelog: https://github.com/tinyauthapp/tinyauth/compare/v5.1.1...v5.1.2

Security Fixes

  • Fix ACLs normalization in Docker and Kubernetes ACL providers — resolves access‑control security issues

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track tinyauth

Get notified when new releases ship.

Sign up free

About tinyauth

The tiniest authentication and authorization server you have ever seen.

All releases →

Related context

Earlier breaking changes

  • v5.1.0 Changes CLI flag from `--experimental.configfile` to `--configfile`.
  • v5.1.0 Removes lockdown mode and reworks rate-limiting.

Beta — feedback welcome: [email protected]