You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
JWT_AUTH_DEFAULT_ROLE is no longer read. Sites that set it should copy the value into Settings > General > "New User Default Role" before updating; otherwise newly provisioned accounts take whatever that setting already says, which on most installs is subscriber. Existing users are unaffected — the role is only assigned at creation.
POST /authorize now requires a flow field matching the flow cookie, and rejects a non-empty client_secret. Sign-ins already on screen across the deploy must be reloaded.
Features
defer the new-user role to core's "New User Default Role" setting (95da39b)
Bug Fixes
build: hand npmConfigHook the rewritten lockfile, not a built node_modules (d398e9d)
close five findings from the security audit (c00c111)
require a verified address to adopt an account, and cap PIN guessing per identity (c3d764d)
woocommerce: stop the SSO button rendering twice on My Account (446fe20)