This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
Summary
AI summarySecurity fixes address access control vulnerabilities and fix redirection logic for Nginx/Swag users.
Full changelog
Tinyauth v5.1.2
This path fix addresses some issues around the redirection logic (especially for Nginx/Swag users) and some security issues in access controls.
[!WARNING]
This release contains security fixes, please update as soon as possible.
Improvements
- Parent domain is now considered a trusted domain
- Allow for OAuth auto-redirect in OIDC flow
Fixes
- Make
login_forparameter optional - Fix redirection issues in HTTPS to HTTP downgrade redirect
- Fix ACLs normalization in Docker and Kubernetes ACL providers
Technical
- Update dependencies
Full Changelog: https://github.com/tinyauthapp/tinyauth/compare/v5.1.1...v5.1.2
Security Fixes
- Fix ACLs normalization in Docker and Kubernetes ACL providers — resolves access‑control security issues
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About tinyauth
The tiniest authentication and authorization server you have ever seen.
Related context
Related tools
Beta — feedback welcome: [email protected]