v0.5.0
What's Changed
- fix(injection): log rejected session cookies, use the first well-formed same-name pair, validate sessionCookieName; ci: pre-release tags (#73-#76) by @y1o1 in #77
- docs: correct the revocation, introspection-client and rate-limit sections; add stripInboundAuthorization by @y1o1 in #78
- fix(auth): enforce introspection expiry and reject bound bearer tokens by @y1o1 in #79
- docs: align browser session revocation guidance with the current provider by @y1o1 in #80
- fix: internalize @o3co/auth.utils, restoring the shutdown deadline and NDJSON logs by @y1o1 in #81
- release: v0.5.0 by @y1o1 in #82
Full Changelog: v0.4.0...v0.5.0