Repository navigation
Version Packages - #199
Merged
Merged
Version Packages#199
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@seamless-auth/core@0.19.1
Patch Changes
0314dfa: Check a silently refreshed access token against
authServerIssuer. The silent refresh inensureCookiesnow verifies the token it returns, but it checkedissagainstauthServerUrleven whenauthServerIssuerwas set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake an optionalauthServerIssuer, and the adapters pass their configured one.ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it.
ensureCookiesrefreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit/refreshroute) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token'ssidclaim, as the other flows do.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake a new optionalaccessTokenAudience, the audience user access tokens are issued for. The adapters pass their configuredaudience. Code that callsensureCookiesorcreateEnsureCookiesMiddlewaredirectly should pass it too; it defaults toauthServerUrl.@seamless-auth/express@0.19.1
Patch Changes
0314dfa: Check a silently refreshed access token against
authServerIssuer. The silent refresh inensureCookiesnow verifies the token it returns, but it checkedissagainstauthServerUrleven whenauthServerIssuerwas set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake an optionalauthServerIssuer, and the adapters pass their configured one.ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it.
ensureCookiesrefreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit/refreshroute) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token'ssidclaim, as the other flows do.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake a new optionalaccessTokenAudience, the audience user access tokens are issued for. The adapters pass their configuredaudience. Code that callsensureCookiesorcreateEnsureCookiesMiddlewaredirectly should pass it too; it defaults toauthServerUrl.Updated dependencies [0314dfa]
Updated dependencies [ca8fa4a]
@seamless-auth/fastify@0.10.1
Patch Changes
0314dfa: Check a silently refreshed access token against
authServerIssuer. The silent refresh inensureCookiesnow verifies the token it returns, but it checkedissagainstauthServerUrleven whenauthServerIssuerwas set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake an optionalauthServerIssuer, and the adapters pass their configured one.ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it.
ensureCookiesrefreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit/refreshroute) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token'ssidclaim, as the other flows do.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake a new optionalaccessTokenAudience, the audience user access tokens are issued for. The adapters pass their configuredaudience. Code that callsensureCookiesorcreateEnsureCookiesMiddlewaredirectly should pass it too; it defaults toauthServerUrl.Updated dependencies [0314dfa]
Updated dependencies [ca8fa4a]
@seamless-auth/nextjs@0.3.1
Patch Changes
0314dfa: Check a silently refreshed access token against
authServerIssuer. The silent refresh inensureCookiesnow verifies the token it returns, but it checkedissagainstauthServerUrleven whenauthServerIssuerwas set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake an optionalauthServerIssuer, and the adapters pass their configured one.ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it.
ensureCookiesrefreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit/refreshroute) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token'ssidclaim, as the other flows do.EnsureCookiesOptionsand the ExpresscreateEnsureCookiesMiddlewaretake a new optionalaccessTokenAudience, the audience user access tokens are issued for. The adapters pass their configuredaudience. Code that callsensureCookiesorcreateEnsureCookiesMiddlewaredirectly should pass it too; it defaults toauthServerUrl.Updated dependencies [0314dfa]
Updated dependencies [ca8fa4a]