Skip to content

v1.1.0-rc1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 22 Sep 12:32
· 9 commits to main since this release

What's Changed

  • Improve account sessions and provider profile refresh by @thecompez in #1
  • Fix/account session profile sync by @thecompez in #2
  • Add multi-chain mobile wallet authentication by @thecompez in #3
  • Restore federated conflict handling and document WalletConnect integration by @thecompez in #4
  • Add hardened Postfix verification delivery adapter by @thecompez in #5
  • Enable verified email sign-in management by @thecompez in #6
  • Fix OpenAPI gate and Linux GCC toolchain by @thecompez in #7
  • Support Apple OIDC form-post callbacks by @thecompez in #8
  • Document federated provider environment setup by @thecompez in #9
  • Enable one-time recovery codes for local MFA by @thecompez in #10
  • Avoid GitGuardian password false positives by @thecompez in #11
  • feat: add self-service TOTP enrollment and recovery codes by @thecompez in #12
  • fix: require TOTP for recovery code issuance by @thecompez in #13
  • feat: harden external OIDC providers by @thecompez in #14
  • fix: preserve Apple first-login profile name by @thecompez in #15
  • fix: encode OIDC basic client credentials by @thecompez in #16
  • fix: bound enterprise LDAP operations by @thecompez in #17
  • fix: validate SAML HTTPS endpoints by @thecompez in #18
  • feat: enrich OIDC profile display names by @thecompez in #19
  • fix: validate GitHub HTTPS callback URLs by @thecompez in #20
  • fix: bind passkey RP IDs to origins by @thecompez in #21
  • fix: validate Web3 RPC HTTPS endpoints by @thecompez in #22
  • fix: sanitize Web3 presentation metadata by @thecompez in #23
  • fix: normalize OIDC profile claims by @thecompez in #24
  • fix: normalize enterprise presentation claims by @thecompez in #25
  • fix: validate LDAP URI and base DN by @thecompez in #26
  • fix: enforce local subject invariant by @thecompez in #27
  • fix: make passkey auth challenges single-use by @thecompez in #28
  • fix: enforce siwe challenge expiry by @thecompez in #29
  • fix: harden Web3 authentication challenges by @thecompez in #30
  • fix: make enterprise authentication challenges single-use by @thecompez in #31
  • fix: make redirect authentication challenges single-use by @thecompez in #32
  • fix: keep provider challenge handling cluster-safe by @thecompez in #33
  • fix: make local authentication cluster-safe by @thecompez in #34

New Contributors

Full Changelog: https://github.com/genyleap/openproof/commits/v1.1.0-rc1