v0.74.58
Changelog
✨ Features
- auth: apply browser session policy on login (77dcf95) (by glennmichael123 gtorregosa@gmail.com)
- auth: add browser session policy (8672d4b) (by glennmichael123 gtorregosa@gmail.com)
🐛 Bug Fixes
- scaffold: deploy only the tip of main, and only this repo's pushes (b3454c7) (by Chris chris@stacksjs.com)
- mail: require explicit mailbox user backend (3d03fe7) (by glennmichael123 gtorregosa@gmail.com) (#2790)
- dashboard: exclude IP addresses from proxy domains (2b9b102) (by glennmichael123 gtorregosa@gmail.com) (#2791)
- dashboard: initialize app runtime before loading routes (941b0ac) (by glennmichael123 gtorregosa@gmail.com) (#2789)
- auth: recognize native SQL error records during recovery (2a19a05) (by glennmichael123 gtorregosa@gmail.com)
- auth: keep direct login reads on the held transaction (edb3206) (by glennmichael123 gtorregosa@gmail.com)
- auth: avoid MySQL refresh token hash gap locks (b2cf546) (by glennmichael123 gtorregosa@gmail.com)
- auth: recheck refresh clients after lock waits (6923ac3) (by glennmichael123 gtorregosa@gmail.com)
- auth: enforce the initial session expiry deadline (fcd8309) (by glennmichael123 gtorregosa@gmail.com)
- auth: verify persisted access grants before issuance (35c749c) (by glennmichael123 gtorregosa@gmail.com)
- auth: bind issued grants to verified OAuth clients (3a74270) (by glennmichael123 gtorregosa@gmail.com)
- auth: bind client token requests to verified login (2b17d73) (by glennmichael123 gtorregosa@gmail.com)
- auth: render token SQL for the configured database (f2145d2) (by glennmichael123 gtorregosa@gmail.com)
- auth: reject refresh of revoked access credentials (e4a3248) (by glennmichael123 gtorregosa@gmail.com)
- auth: preserve live refresh grants after access expiry (78bfd90) (by glennmichael123 gtorregosa@gmail.com)
- auth: revoke pending magic links during password recovery (19bab93) (by glennmichael123 gtorregosa@gmail.com)
- auth: preserve request identity when direct login fails (edf2425) (by glennmichael123 gtorregosa@gmail.com)
- auth: bind magic link issuance to current email ownership (03e5cfc) (by glennmichael123 gtorregosa@gmail.com)
- auth: enforce deadlines on cached access tokens (410a1a7) (by glennmichael123 gtorregosa@gmail.com)
- auth: recheck magic link expiry after claiming (e6db4e7) (by glennmichael123 gtorregosa@gmail.com)
- auth: honor shipped two-factor timestamp precision (0575eaf) (by glennmichael123 gtorregosa@gmail.com)
- auth: preserve session renewal across daylight saving changes (da95943) (by glennmichael123 gtorregosa@gmail.com)
- auth: prevent MySQL access token deadline extension (67468b9) (by glennmichael123 gtorregosa@gmail.com)
- build: restore required Craft version in Pantry lock (002017d) (by glennmichael123 gtorregosa@gmail.com)
- database: isolate concurrent transaction routing contexts (18f110b) (by glennmichael123 gtorregosa@gmail.com)
- auth: verify stored session renewal before success (660d5f3) (by glennmichael123 gtorregosa@gmail.com)
- auth: verify refresh grants before committing issuance (0da8692) (by glennmichael123 gtorregosa@gmail.com)
- auth: verify paired revocation before refresh exchange (b07c385) (by glennmichael123 gtorregosa@gmail.com)
- auth: serialize two-factor redemption with password recovery (6ad5e5b) (by glennmichael123 gtorregosa@gmail.com)
- auth: revoke pending two-factor challenges during recovery (6577e43) (by glennmichael123 gtorregosa@gmail.com)
⚡ Performance Improvements
- auth: index owner and refresh token revocation scopes (4ddc837) (by glennmichael123 gtorregosa@gmail.com)
✅ Tests
- database: isolate query log application configuration (b090007) (by glennmichael123 gtorregosa@gmail.com)
🔧 Chores
- release v0.74.58 (a2ff4ba) (by Chris chris@stacksjs.com)
Contributors
- Chris chris@stacksjs.com
- glennmichael123 gtorregosa@gmail.com