Skip to content

v2.14.3

Choose a tag to compare

@github-actions github-actions released this 04 Sep 05:19
· 57 commits to main since this release
v2.14.3: account bindings surface in multi-account detail

- The multi-account drill-down now lists every third-party identity behind each
  account — the built-in ones (email, GitHub, Discord, OIDC, WeChat, Telegram,
  LinuxDO, Steam) and custom OAuth bindings in one list, so a shared identity
  source can be spotted without opening user management account by account.
- The sign-up source is marked out. Custom OAuth reads it straight from the
  binding table; built-in identities are back-filled from register_method in the
  registration log. When neither path has it — old accounts, pruned logs — no
  source is marked rather than guessed, and the sign-up method is returned
  alongside the account so password-only sign-ups are still visible.
- Binding details follow the same privilege check user management applies:
  accounts the caller cannot manage return statistics only, so an admin cannot
  read root's identities from the risk-control page.
- The classic UI shows this read-only. A single binding is shown inline; with
  several, only the sign-up source is listed plus "+N view all", which opens a
  read-only detail dialog. No unbind action — this page is for judgement, the
  disposition stays a manual decision.