v2.6.3 - Production CLI Authentication Fixes & Security Updates
What's Changed in v2.6.3 (includes v2.6.2)
This release delivers critical fixes for CLI authentication with production workspaces, loopback server synchronization, and upstream security dependency patches.
🔐 Authentication & CLI Session Fixes (v2.6.2)
- Canonical Domain Normalization: Fixed an issue where calls to
https://iobend.comtriggered an HTTP 308 redirect that caused Node.jsfetchto strip theAuthorizationheader. All CLI requests now directly target canonicalhttps://www.iobend.com. - Enhanced
iobend login --token <token>Flow: Added automatic candidate endpoint validation (https://www.iobend.com, configured API, and local dev fallback) when authorizing directly via CLI tokens. - Callback Origin Propagation: Ensured loopback authentication callbacks on
localhost:54321correctly retain and persist the active server origin. - Token Sanitization: Cleaned and trimmed tokens across authentication actions and API requests to prevent whitespace and newline issues.
🛡️ Security & Dependency Patches (v2.6.3)
- Patched
sharp: Upgraded to>=0.35.4, remediating high-severitylibheifvulnerabilities (GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545). - Patched
vitest/@vitest/mocker: Upgraded testing suite to>=4.1.11, remediating path traversal / arbitrary file read vulnerability (GHSA-82fw-gwwq-j7x9). - Verified Zero Vulnerabilities: Completed full
npm auditwith 0 vulnerabilities and verified 100% pass across all 13 test suites (64 unit tests).
📦 Installation & Upgrade
Upgrade to the latest version globally via npm:
npm install -g iobend@latest