Skip to content

v1.1.0

Choose a tag to compare

@ondrej-kuhnel ondrej-kuhnel released this 17 Jun 14:07
· 16 commits to main since this release
530eb11

Password-expiration fix + magic-link/passkey now bypass 2FA.

  • Fix: enabling password expiration no longer forces a reset on every existing user. Users without a recorded passwordChangedAt now fall back to the account creation date (getCreatedAt()), so only accounts older than the window are affected.
  • Change: magic-link and passkey logins authenticate directly and bypass 2FA — the second factor guards plain password login only.

⚠️ Requires integration changes — see UPGRADE.md (new getCreatedAt() contract method, updated verify-controller constructors, removed skip_2fa_when_user_verified).