v0.1.15
Release the GHSA auth-hardening work (PRs #10–#12): email verification, verified-email OAuth linking, redirect allowlist, session revocation, scoped signout, PUT /user, hashed refresh tokens, email change with dual confirmation, user/app metadata, trusted-proxy IPs, and scanner-proof verify links. Cut [Unreleased] → [0.1.15]. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>