Skip to content

3.1.1

Latest

Choose a tag to compare

@madeyoga madeyoga released this 04 Oct 06:29
· 3 commits to main since this release
576a277

Passkey and other CSRF-protected endpoints no longer return 500 when JWT is not enabled. The CSRF check skips authentication schemes the host has not registered, so anonymous passkey requestOptions, register/options, register, and login work on the default cookie and Identity bearer facades. Missing or invalid CSRF tokens return 400. Hosts with JWT enabled behave as before.