Skip to content

Version Packages - #190

Merged
Bccorb merged 1 commit into
mainfrom
changeset-release/main
Oct 7, 2026
Merged

Bccorb merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@seamless-auth/core@0.19.0

Minor Changes

  • a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity: GET /admin/auth-events/integrity (Audit records are updatable and have no integrity protection seamless-auth-api#174), GET /admin/auth-events/export (Audit events have no retention policy and no bulk export seamless-auth-api#173) and GET /admin/reports/authentication-coverage (No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.

    The export and the coverage report answer with a file (NDJSON, or CSV when format=csv), so proxied routes can now forward an upstream response unparsed. proxyRequest takes raw: true and returns raw: { headers, body }, holding the body stream and its content-type, content-disposition and cache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in { message }.

    ResponseAdapter gains a required sendRaw(status, raw). A custom adapter that implements ResponseAdapter itself has to add it. The adapters in this repository already do.

    @seamless-auth/types is now ^0.27.0.

  • 79aad32: Add authServerIssuer, the expected iss of the tokens and signed responses the auth server returns. It defaults to authServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs as http://auth:5312, while an app run on the host calls http://localhost:5312, and every sign-in failed with Invalid signed response from Auth Server (Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go to authServerUrl; only the iss check reads the new option.

    The auth API sets aud to its ISSUER as well, and audience stays required with no default, so with authServerIssuer set, set audience to the same value. For the Docker stack from the host that is authServerUrl: "http://localhost:5312", authServerIssuer: "http://auth:5312", audience: "http://auth:5312". The option docs and READMEs now say this.

    It is accepted by createSeamlessAuthServer, requireAuth and getSeamlessUser in Express, the seamlessAuth plugin, requireAuth and getSeamlessUser in Fastify, and createSeamlessAuthHandler and getSeamlessSession in Next.js. In core, verifySignedAuthResponse, verifyAccessToken and verifyUpstreamSession take it as an optional last argument, and getSeamlessUser, authenticateBearer, authenticateRequest (under bearer), issueSessionCookies, sessionResult and the session-issuing handlers' options take it as a field (AuthServerIssuerOption).

    The startup warning for an unset or dev-main jwksKid now says what the value is: the kid header on the HS256 service tokens the adapter signs with serviceSecret, not the auth server's signing key. The READMEs describe jwksKid the same way.

  • 629c428: - GET /internal/metrics/dashboard and GET /internal/security/anomalies now forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped. getDashboardMetricsHandler and getSecurityAnomaliesHandler accept query.

Patch Changes

@seamless-auth/express@0.19.0

Minor Changes

  • a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity: GET /admin/auth-events/integrity (Audit records are updatable and have no integrity protection seamless-auth-api#174), GET /admin/auth-events/export (Audit events have no retention policy and no bulk export seamless-auth-api#173) and GET /admin/reports/authentication-coverage (No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.

    The export and the coverage report answer with a file (NDJSON, or CSV when format=csv), so proxied routes can now forward an upstream response unparsed. proxyRequest takes raw: true and returns raw: { headers, body }, holding the body stream and its content-type, content-disposition and cache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in { message }.

    ResponseAdapter gains a required sendRaw(status, raw). A custom adapter that implements ResponseAdapter itself has to add it. The adapters in this repository already do.

    @seamless-auth/types is now ^0.27.0.

  • 79aad32: Add authServerIssuer, the expected iss of the tokens and signed responses the auth server returns. It defaults to authServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs as http://auth:5312, while an app run on the host calls http://localhost:5312, and every sign-in failed with Invalid signed response from Auth Server (Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go to authServerUrl; only the iss check reads the new option.

    The auth API sets aud to its ISSUER as well, and audience stays required with no default, so with authServerIssuer set, set audience to the same value. For the Docker stack from the host that is authServerUrl: "http://localhost:5312", authServerIssuer: "http://auth:5312", audience: "http://auth:5312". The option docs and READMEs now say this.

    It is accepted by createSeamlessAuthServer, requireAuth and getSeamlessUser in Express, the seamlessAuth plugin, requireAuth and getSeamlessUser in Fastify, and createSeamlessAuthHandler and getSeamlessSession in Next.js. In core, verifySignedAuthResponse, verifyAccessToken and verifyUpstreamSession take it as an optional last argument, and getSeamlessUser, authenticateBearer, authenticateRequest (under bearer), issueSessionCookies, sessionResult and the session-issuing handlers' options take it as a field (AuthServerIssuerOption).

    The startup warning for an unset or dev-main jwksKid now says what the value is: the kid header on the HS256 service tokens the adapter signs with serviceSecret, not the auth server's signing key. The READMEs describe jwksKid the same way.

  • 629c428: - GET /internal/metrics/dashboard and GET /internal/security/anomalies now forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped. getDashboardMetricsHandler and getSecurityAnomaliesHandler accept query.

Patch Changes

@seamless-auth/fastify@0.10.0

Minor Changes

  • a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity: GET /admin/auth-events/integrity (Audit records are updatable and have no integrity protection seamless-auth-api#174), GET /admin/auth-events/export (Audit events have no retention policy and no bulk export seamless-auth-api#173) and GET /admin/reports/authentication-coverage (No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.

    The export and the coverage report answer with a file (NDJSON, or CSV when format=csv), so proxied routes can now forward an upstream response unparsed. proxyRequest takes raw: true and returns raw: { headers, body }, holding the body stream and its content-type, content-disposition and cache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in { message }.

    ResponseAdapter gains a required sendRaw(status, raw). A custom adapter that implements ResponseAdapter itself has to add it. The adapters in this repository already do.

    @seamless-auth/types is now ^0.27.0.

  • 79aad32: Add authServerIssuer, the expected iss of the tokens and signed responses the auth server returns. It defaults to authServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs as http://auth:5312, while an app run on the host calls http://localhost:5312, and every sign-in failed with Invalid signed response from Auth Server (Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go to authServerUrl; only the iss check reads the new option.

    The auth API sets aud to its ISSUER as well, and audience stays required with no default, so with authServerIssuer set, set audience to the same value. For the Docker stack from the host that is authServerUrl: "http://localhost:5312", authServerIssuer: "http://auth:5312", audience: "http://auth:5312". The option docs and READMEs now say this.

    It is accepted by createSeamlessAuthServer, requireAuth and getSeamlessUser in Express, the seamlessAuth plugin, requireAuth and getSeamlessUser in Fastify, and createSeamlessAuthHandler and getSeamlessSession in Next.js. In core, verifySignedAuthResponse, verifyAccessToken and verifyUpstreamSession take it as an optional last argument, and getSeamlessUser, authenticateBearer, authenticateRequest (under bearer), issueSessionCookies, sessionResult and the session-issuing handlers' options take it as a field (AuthServerIssuerOption).

    The startup warning for an unset or dev-main jwksKid now says what the value is: the kid header on the HS256 service tokens the adapter signs with serviceSecret, not the auth server's signing key. The READMEs describe jwksKid the same way.

  • 629c428: - GET /internal/metrics/dashboard and GET /internal/security/anomalies now forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped. getDashboardMetricsHandler and getSecurityAnomaliesHandler accept query.

Patch Changes

@seamless-auth/nextjs@0.3.0

Minor Changes

  • a004f89: Pass the auth API's audit and reporting routes through with the caller's access identity: GET /admin/auth-events/integrity (Audit records are updatable and have no integrity protection seamless-auth-api#174), GET /admin/auth-events/export (Audit events have no retention policy and no bulk export seamless-auth-api#173) and GET /admin/reports/authentication-coverage (No authentication coverage report for assessment and insurance responses seamless-auth-api#178), each with its query.

    The export and the coverage report answer with a file (NDJSON, or CSV when format=csv), so proxied routes can now forward an upstream response unparsed. proxyRequest takes raw: true and returns raw: { headers, body }, holding the body stream and its content-type, content-disposition and cache-control. Each adapter streams it through as is, so the download keeps its type and filename rather than arriving wrapped in { message }.

    ResponseAdapter gains a required sendRaw(status, raw). A custom adapter that implements ResponseAdapter itself has to add it. The adapters in this repository already do.

    @seamless-auth/types is now ^0.27.0.

  • 79aad32: Add authServerIssuer, the expected iss of the tokens and signed responses the auth server returns. It defaults to authServerUrl, so nothing changes unless you set it. Set it when the auth server is reached at a different URL from the issuer it advertises: on the local Docker stack the auth server signs as http://auth:5312, while an app run on the host calls http://localhost:5312, and every sign-in failed with Invalid signed response from Auth Server (Sign-in fails when the app runs on the host against the Docker auth server (issuer mismatch) seamless-cli#224). Requests and key set fetches still go to authServerUrl; only the iss check reads the new option.

    The auth API sets aud to its ISSUER as well, and audience stays required with no default, so with authServerIssuer set, set audience to the same value. For the Docker stack from the host that is authServerUrl: "http://localhost:5312", authServerIssuer: "http://auth:5312", audience: "http://auth:5312". The option docs and READMEs now say this.

    It is accepted by createSeamlessAuthServer, requireAuth and getSeamlessUser in Express, the seamlessAuth plugin, requireAuth and getSeamlessUser in Fastify, and createSeamlessAuthHandler and getSeamlessSession in Next.js. In core, verifySignedAuthResponse, verifyAccessToken and verifyUpstreamSession take it as an optional last argument, and getSeamlessUser, authenticateBearer, authenticateRequest (under bearer), issueSessionCookies, sessionResult and the session-issuing handlers' options take it as a field (AuthServerIssuerOption).

    The startup warning for an unset or dev-main jwksKid now says what the value is: the kid header on the HS256 service tokens the adapter signs with serviceSecret, not the auth server's signing key. The READMEs describe jwksKid the same way.

  • 6538393: Add createSeamlessConsoleProxy, which serves the Seamless admin console from a Next.js application. Mount it at app/console/[[...path]]/route.ts and export its GET and HEAD, and the dashboard loads from the same origin as /auth, as it does with the Express and Fastify console proxies. It forwards only the method and the path upstream, copies the caching headers back, and refuses any path that leaves the console subtree. A mountPath option covers a route mounted elsewhere or under a Next.js basePath. Closes feat(nextjs): serve the admin console from a Next.js application #185.

  • 629c428: - GET /internal/metrics/dashboard and GET /internal/security/anomalies now forward their query string, so the time range and paging the auth API accepts on them reach it ([Feature]: Dashboard metrics and security anomalies accept no time range seamless-auth-api#132). Before, both handlers were built without a query, and a range from the dashboard was silently dropped. getDashboardMetricsHandler and getSecurityAnomaliesHandler accept query.

Patch Changes

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 6 times, most recently from 63eb7b2 to 0bc3659 Compare October 7, 2026 02:55
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 0bc3659 to 7a39726 Compare October 7, 2026 02:58
@Bccorb
Bccorb merged commit a35dde0 into main Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant