Passkey and other CSRF-protected endpoints no longer return 500 when JWT is not enabled. The CSRF check skips authentication schemes the host has not registered, so anonymous passkey requestOptions, register/options, register, and login work on the default cookie and Identity bearer facades. Missing or invalid CSRF tokens return 400. Hosts with JWT enabled behave as before.
- NuGet: AuthEndpoints 3.1.1
- Docs: https://madeyoga.github.io/AuthEndpoints/changelog/
- Compare: v3.1.0...v3.1.1