Repository navigation
Releases: 3BRS/enterprise-security-bundle
Releases · 3BRS/enterprise-security-bundle
Release list
v2.3.0
What's Changed
- 2.3.0: extract the passkey assertion and known-device abstracts by @ondrej-kuhnel in #13
Full Changelog: v2.2.2...v2.3.0
v2.2.2
What's Changed
- 2.2.2: settings fallback, OAuth flash key, issuer hook, English translations by @ondrej-kuhnel in #12
Full Changelog: v2.2.1...v2.2.2
v2.2.1
Release 2.2.1 Fixed - The admin guide's "block account" action claimed the block covers both the next sign-in and sessions already open. Setting enabled = false stops the next sign-in; revoking stamps revokedAt and closes nothing until the integrator's session revocation listener is in place, as the note below the bullet says. The clause was introduced in 2.2.0 while rewriting that release's corrections from audit notes into instructions, reintroducing the defect the release existed to remove: a summary asserting an outcome that is only qualified further down the page. Documentation only; no code or behaviour change.
v2.1.0
What's Changed
- SLS-145: ES: Password login fixes by @FilipHoracek in #6
Full Changelog: v2.0.0...v2.1.0
v2.0.0
What's Changed
- SLS-141: OAuth: store Apple in a dedicated SameSite=None cookie (so … by @FilipHoracek in #5
- SLS-142: Change validation method of linking already existing account, change password login disabled to global settings by @FilipHoracek in #4
Full Changelog: v1.1.0...v2.0.0
v1.1.0
Password-expiration fix + magic-link/passkey now bypass 2FA.
- Fix: enabling password expiration no longer forces a reset on every existing user. Users without a recorded passwordChangedAt now fall back to the account creation date (getCreatedAt()), so only accounts older than the window are affected.
- Change: magic-link and passkey logins authenticate directly and bypass 2FA — the second factor guards plain password login only.