Immutable
release. Only release title and notes can be modified.
6.3.1 (2026-09-27)
This release fixes a security vulnerability. All users of @adonisjs/ally v6 should upgrade.
The OAuth2 and OAuth1 drivers accepted a callback with no state param (or no oauth_token param for OAuth1) when the state cookie was also missing. An attacker could use this to sign a victim in to the attacker's account, or to link the attacker's provider account to the victim's account. A missing state cookie now counts as a state mismatch, so stateMisMatch() returns true and accessToken() and user() throw E_OAUTH_STATE_MISMATCH.
See the security advisory for details: GHSA-j577-w94j-8p3p
Bug Fixes
- treat a missing state cookie as a state mismatch (4126dc4)
- add support for
@adonisjs/inertia@5peer dep (5c511d0)
Full Changelog: v6.3.0...v6.3.1