Repository navigation
Version Packages - #190
Merged
Merged
Version Packages#190
Conversation
github-actions
Bot
force-pushed
the
changeset-release/main
branch
6 times, most recently
from
October 7, 2026 02:55
63eb7b2 to
0bc3659
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
October 7, 2026 02:58
0bc3659 to
7a39726
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@seamless-auth/core@0.19.0
Minor Changes
a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity:
GET /admin/auth-events/integrity(Audit records are updatable and have no integrity protection seamless-auth-api#174),GET /admin/auth-events/export(Audit events have no retention policy and no bulk export seamless-auth-api#173) andGET /admin/reports/authentication-coverage(No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.The export and the coverage report answer with a file (NDJSON, or CSV when
format=csv), so proxied routes can now forward an upstream response unparsed.proxyRequesttakesraw: trueand returnsraw: { headers, body }, holding the body stream and itscontent-type,content-dispositionandcache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in{ message }.ResponseAdaptergains a requiredsendRaw(status, raw). A custom adapter that implementsResponseAdapteritself has to add it. The adapters in this repository already do.@seamless-auth/typesis now^0.27.0.79aad32: Add
authServerIssuer, the expectedissof the tokens and signed responses the auth server returns. It defaults toauthServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs ashttp://auth:5312, while an app run on the host callshttp://localhost:5312, and every sign-in failed withInvalid signed response from Auth Server(Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go toauthServerUrl; only theisscheck reads the new option.The auth API sets
audto its ISSUER as well, andaudiencestays required with no default, so withauthServerIssuerset, setaudienceto the same value. For the Docker stack from the host that isauthServerUrl: "http://localhost:5312",authServerIssuer: "http://auth:5312",audience: "http://auth:5312". The option docs and READMEs now say this.It is accepted by
createSeamlessAuthServer,requireAuthandgetSeamlessUserin Express, theseamlessAuthplugin,requireAuthandgetSeamlessUserin Fastify, andcreateSeamlessAuthHandlerandgetSeamlessSessionin Next.js. In core,verifySignedAuthResponse,verifyAccessTokenandverifyUpstreamSessiontake it as an optional last argument, andgetSeamlessUser,authenticateBearer,authenticateRequest(underbearer),issueSessionCookies,sessionResultand the session-issuing handlers' options take it as a field (AuthServerIssuerOption).The startup warning for an unset or
dev-mainjwksKidnow says what the value is: thekidheader on the HS256 service tokens the adapter signs withserviceSecret, not the auth server's signing key. The READMEs describejwksKidthe same way.629c428: -
GET /internal/metrics/dashboardandGET /internal/security/anomaliesnow forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped.getDashboardMetricsHandlerandgetSecurityAnomaliesHandleracceptquery.GET /admin/review-accounts(with itsdaysquery) through to the auth API with the caller's access identity (feat(otp): record review account sign-ins and surface enabled review accounts seamless-auth-api#331).Patch Changes
kid. The cached key set was only refetched for an unknownkid, so after such a change (a recreated local auth container regenerates its dev key this way) every signed auth response and Bearer token failed verification for up to 10 minutes, and sign-in answered 500 until the application restarted. A signature that does not match a cached key now refetches the key set once and verifies again, at most once per 30 second cooldown so a stream of bad signatures cannot hammer the JWKS endpoint. The verification failure log now includes thejoseerror code. Fixes fix(core): signed auth responses fail for up to 10 minutes after keys change under the same kid #184.enginesfield now requires>=22instead of>=24 <25, and CI runs on Node 22, 24, and the latest release (chore: support Node versions beyond 24 across the ecosystem seamless-auth-api#339).@seamless-auth/types^0.28.0, which adds the ranged dashboard metrics and security anomalies schemas ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132).@seamless-auth/express@0.19.0
Minor Changes
a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity:
GET /admin/auth-events/integrity(Audit records are updatable and have no integrity protection seamless-auth-api#174),GET /admin/auth-events/export(Audit events have no retention policy and no bulk export seamless-auth-api#173) andGET /admin/reports/authentication-coverage(No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.The export and the coverage report answer with a file (NDJSON, or CSV when
format=csv), so proxied routes can now forward an upstream response unparsed.proxyRequesttakesraw: trueand returnsraw: { headers, body }, holding the body stream and itscontent-type,content-dispositionandcache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in{ message }.ResponseAdaptergains a requiredsendRaw(status, raw). A custom adapter that implementsResponseAdapteritself has to add it. The adapters in this repository already do.@seamless-auth/typesis now^0.27.0.79aad32: Add
authServerIssuer, the expectedissof the tokens and signed responses the auth server returns. It defaults toauthServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs ashttp://auth:5312, while an app run on the host callshttp://localhost:5312, and every sign-in failed withInvalid signed response from Auth Server(Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go toauthServerUrl; only theisscheck reads the new option.The auth API sets
audto its ISSUER as well, andaudiencestays required with no default, so withauthServerIssuerset, setaudienceto the same value. For the Docker stack from the host that isauthServerUrl: "http://localhost:5312",authServerIssuer: "http://auth:5312",audience: "http://auth:5312". The option docs and READMEs now say this.It is accepted by
createSeamlessAuthServer,requireAuthandgetSeamlessUserin Express, theseamlessAuthplugin,requireAuthandgetSeamlessUserin Fastify, andcreateSeamlessAuthHandlerandgetSeamlessSessionin Next.js. In core,verifySignedAuthResponse,verifyAccessTokenandverifyUpstreamSessiontake it as an optional last argument, andgetSeamlessUser,authenticateBearer,authenticateRequest(underbearer),issueSessionCookies,sessionResultand the session-issuing handlers' options take it as a field (AuthServerIssuerOption).The startup warning for an unset or
dev-mainjwksKidnow says what the value is: thekidheader on the HS256 service tokens the adapter signs withserviceSecret, not the auth server's signing key. The READMEs describejwksKidthe same way.629c428: -
GET /internal/metrics/dashboardandGET /internal/security/anomaliesnow forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped.getDashboardMetricsHandlerandgetSecurityAnomaliesHandleracceptquery.GET /admin/review-accounts(with itsdaysquery) through to the auth API with the caller's access identity (feat(otp): record review account sign-ins and surface enabled review accounts seamless-auth-api#331).Patch Changes
kid. The cached key set was only refetched for an unknownkid, so after such a change (a recreated local auth container regenerates its dev key this way) every signed auth response and Bearer token failed verification for up to 10 minutes, and sign-in answered 500 until the application restarted. A signature that does not match a cached key now refetches the key set once and verifies again, at most once per 30 second cooldown so a stream of bad signatures cannot hammer the JWKS endpoint. The verification failure log now includes thejoseerror code. Fixes fix(core): signed auth responses fail for up to 10 minutes after keys change under the same kid #184.enginesfield now requires>=22instead of>=24 <25, and CI runs on Node 22, 24, and the latest release (chore: support Node versions beyond 24 across the ecosystem seamless-auth-api#339).@seamless-auth/fastify@0.10.0
Minor Changes
a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity:
GET /admin/auth-events/integrity(Audit records are updatable and have no integrity protection seamless-auth-api#174),GET /admin/auth-events/export(Audit events have no retention policy and no bulk export seamless-auth-api#173) andGET /admin/reports/authentication-coverage(No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.The export and the coverage report answer with a file (NDJSON, or CSV when
format=csv), so proxied routes can now forward an upstream response unparsed.proxyRequesttakesraw: trueand returnsraw: { headers, body }, holding the body stream and itscontent-type,content-dispositionandcache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in{ message }.ResponseAdaptergains a requiredsendRaw(status, raw). A custom adapter that implementsResponseAdapteritself has to add it. The adapters in this repository already do.@seamless-auth/typesis now^0.27.0.79aad32: Add
authServerIssuer, the expectedissof the tokens and signed responses the auth server returns. It defaults toauthServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs ashttp://auth:5312, while an app run on the host callshttp://localhost:5312, and every sign-in failed withInvalid signed response from Auth Server(Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go toauthServerUrl; only theisscheck reads the new option.The auth API sets
audto its ISSUER as well, andaudiencestays required with no default, so withauthServerIssuerset, setaudienceto the same value. For the Docker stack from the host that isauthServerUrl: "http://localhost:5312",authServerIssuer: "http://auth:5312",audience: "http://auth:5312". The option docs and READMEs now say this.It is accepted by
createSeamlessAuthServer,requireAuthandgetSeamlessUserin Express, theseamlessAuthplugin,requireAuthandgetSeamlessUserin Fastify, andcreateSeamlessAuthHandlerandgetSeamlessSessionin Next.js. In core,verifySignedAuthResponse,verifyAccessTokenandverifyUpstreamSessiontake it as an optional last argument, andgetSeamlessUser,authenticateBearer,authenticateRequest(underbearer),issueSessionCookies,sessionResultand the session-issuing handlers' options take it as a field (AuthServerIssuerOption).The startup warning for an unset or
dev-mainjwksKidnow says what the value is: thekidheader on the HS256 service tokens the adapter signs withserviceSecret, not the auth server's signing key. The READMEs describejwksKidthe same way.629c428: -
GET /internal/metrics/dashboardandGET /internal/security/anomaliesnow forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped.getDashboardMetricsHandlerandgetSecurityAnomaliesHandleracceptquery.GET /admin/review-accounts(with itsdaysquery) through to the auth API with the caller's access identity (feat(otp): record review account sign-ins and surface enabled review accounts seamless-auth-api#331).Patch Changes
kid. The cached key set was only refetched for an unknownkid, so after such a change (a recreated local auth container regenerates its dev key this way) every signed auth response and Bearer token failed verification for up to 10 minutes, and sign-in answered 500 until the application restarted. A signature that does not match a cached key now refetches the key set once and verifies again, at most once per 30 second cooldown so a stream of bad signatures cannot hammer the JWKS endpoint. The verification failure log now includes thejoseerror code. Fixes fix(core): signed auth responses fail for up to 10 minutes after keys change under the same kid #184.enginesfield now requires>=22instead of>=24 <25, and CI runs on Node 22, 24, and the latest release (chore: support Node versions beyond 24 across the ecosystem seamless-auth-api#339).@seamless-auth/nextjs@0.3.0
Minor Changes
a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity:
GET /admin/auth-events/integrity(Audit records are updatable and have no integrity protection seamless-auth-api#174),GET /admin/auth-events/export(Audit events have no retention policy and no bulk export seamless-auth-api#173) andGET /admin/reports/authentication-coverage(No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.The export and the coverage report answer with a file (NDJSON, or CSV when
format=csv), so proxied routes can now forward an upstream response unparsed.proxyRequesttakesraw: trueand returnsraw: { headers, body }, holding the body stream and itscontent-type,content-dispositionandcache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in{ message }.ResponseAdaptergains a requiredsendRaw(status, raw). A custom adapter that implementsResponseAdapteritself has to add it. The adapters in this repository already do.@seamless-auth/typesis now^0.27.0.79aad32: Add
authServerIssuer, the expectedissof the tokens and signed responses the auth server returns. It defaults toauthServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs ashttp://auth:5312, while an app run on the host callshttp://localhost:5312, and every sign-in failed withInvalid signed response from Auth Server(Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go toauthServerUrl; only theisscheck reads the new option.The auth API sets
audto its ISSUER as well, andaudiencestays required with no default, so withauthServerIssuerset, setaudienceto the same value. For the Docker stack from the host that isauthServerUrl: "http://localhost:5312",authServerIssuer: "http://auth:5312",audience: "http://auth:5312". The option docs and READMEs now say this.It is accepted by
createSeamlessAuthServer,requireAuthandgetSeamlessUserin Express, theseamlessAuthplugin,requireAuthandgetSeamlessUserin Fastify, andcreateSeamlessAuthHandlerandgetSeamlessSessionin Next.js. In core,verifySignedAuthResponse,verifyAccessTokenandverifyUpstreamSessiontake it as an optional last argument, andgetSeamlessUser,authenticateBearer,authenticateRequest(underbearer),issueSessionCookies,sessionResultand the session-issuing handlers' options take it as a field (AuthServerIssuerOption).The startup warning for an unset or
dev-mainjwksKidnow says what the value is: thekidheader on the HS256 service tokens the adapter signs withserviceSecret, not the auth server's signing key. The READMEs describejwksKidthe same way.6538393: Add
createSeamlessConsoleProxy, which serves the Seamless admin console from a Next.js application. Mount it atapp/console/[[...path]]/route.tsand export itsGETandHEAD, and the dashboard loads from the same origin as/auth, as it does with the Express and Fastify console proxies. It forwards only the method and the path upstream, copies the caching headers back, and refuses any path that leaves the console subtree. AmountPathoption covers a route mounted elsewhere or under a Next.jsbasePath. Closes feat(nextjs): serve the admin console from a Next.js application #185.629c428: -
GET /internal/metrics/dashboardandGET /internal/security/anomaliesnow forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped.getDashboardMetricsHandlerandgetSecurityAnomaliesHandleracceptquery.GET /admin/review-accounts(with itsdaysquery) through to the auth API with the caller's access identity (feat(otp): record review account sign-ins and surface enabled review accounts seamless-auth-api#331).Patch Changes
kid. The cached key set was only refetched for an unknownkid, so after such a change (a recreated local auth container regenerates its dev key this way) every signed auth response and Bearer token failed verification for up to 10 minutes, and sign-in answered 500 until the application restarted. A signature that does not match a cached key now refetches the key set once and verifies again, at most once per 30 second cooldown so a stream of bad signatures cannot hammer the JWKS endpoint. The verification failure log now includes thejoseerror code. Fixes fix(core): signed auth responses fail for up to 10 minutes after keys change under the same kid #184.enginesfield now requires>=22instead of>=24 <25, and CI runs on Node 22, 24, and the latest release (chore: support Node versions beyond 24 across the ecosystem seamless-auth-api#339).@seamless-auth/types^0.28.0, which adds the ranged dashboard metrics and security anomalies schemas ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132).