Skip to content

Releases: 3BRS/enterprise-security-bundle

v2.3.0

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 24 Aug 08:05
v2.3.0

What's Changed

  • 2.3.0: extract the passkey assertion and known-device abstracts by @ondrej-kuhnel in #13

Full Changelog: v2.2.2...v2.3.0

v2.2.2

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 24 Aug 07:36
v2.2.2

What's Changed

  • 2.2.2: settings fallback, OAuth flash key, issuer hook, English translations by @ondrej-kuhnel in #12

Full Changelog: v2.2.1...v2.2.2

v2.2.1

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 20 Aug 07:50
v2.2.1
Release 2.2.1

Fixed
- The admin guide's "block account" action claimed the block covers both
  the next sign-in and sessions already open. Setting enabled = false stops
  the next sign-in; revoking stamps revokedAt and closes nothing until the
  integrator's session revocation listener is in place, as the note below
  the bullet says.

  The clause was introduced in 2.2.0 while rewriting that release's
  corrections from audit notes into instructions, reintroducing the defect
  the release existed to remove: a summary asserting an outcome that is
  only qualified further down the page.

Documentation only; no code or behaviour change.

v2.1.0

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 14 Jul 13:08
v2.1.0
100a14e

What's Changed

Full Changelog: v2.0.0...v2.1.0

v2.0.0

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 02 Jul 12:56
v2.0.0
662e381

What's Changed

  • SLS-141: OAuth: store Apple in a dedicated SameSite=None cookie (so … by @FilipHoracek in #5
  • SLS-142: Change validation method of linking already existing account, change password login disabled to global settings by @FilipHoracek in #4

Full Changelog: v1.1.0...v2.0.0

v1.1.0

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 17 Jun 14:07
530eb11

Password-expiration fix + magic-link/passkey now bypass 2FA.

  • Fix: enabling password expiration no longer forces a reset on every existing user. Users without a recorded passwordChangedAt now fall back to the account creation date (getCreatedAt()), so only accounts older than the window are affected.
  • Change: magic-link and passkey logins authenticate directly and bypass 2FA — the second factor guards plain password login only.

⚠️ Requires integration changes — see UPGRADE.md (new getCreatedAt() contract method, updated verify-controller constructors, removed skip_2fa_when_user_verified).

v1.0.0

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 15 Jun 12:54
SLS-129: Documentation changes