Release v2.20.0
Summary
Allow applications that treat identity verification as authorization authority to invalidate the caller's local AuthProxy session when verification denies access. The external identity-provider session remains untouched.
Added
- Add opt-in local session termination for Required identity-verification denials, including Aspire configuration and real cookie-pipeline coverage. (#103)