Repository navigation
v1.1.0
Password-expiration fix + magic-link/passkey now bypass 2FA.
- Fix: enabling password expiration no longer forces a reset on every existing user. Users without a recorded passwordChangedAt now fall back to the account creation date (getCreatedAt()), so only accounts older than the window are affected.
- Change: magic-link and passkey logins authenticate directly and bypass 2FA — the second factor guards plain password login only.