diff --git a/.changeset/silent-refresh-auth-server-issuer.md b/.changeset/silent-refresh-auth-server-issuer.md deleted file mode 100644 index 0e8818b..0000000 --- a/.changeset/silent-refresh-auth-server-issuer.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -"@seamless-auth/core": patch -"@seamless-auth/express": patch -"@seamless-auth/fastify": patch -"@seamless-auth/nextjs": patch ---- - -Check a silently refreshed access token against `authServerIssuer`. The silent refresh in `ensureCookies` now verifies the token it returns, but it checked `iss` against `authServerUrl` even when `authServerIssuer` was set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out. `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take an optional `authServerIssuer`, and the adapters pass their configured one. diff --git a/.changeset/verify-silent-refresh-token.md b/.changeset/verify-silent-refresh-token.md deleted file mode 100644 index adab403..0000000 --- a/.changeset/verify-silent-refresh-token.md +++ /dev/null @@ -1,10 +0,0 @@ ---- -"@seamless-auth/core": patch -"@seamless-auth/express": patch -"@seamless-auth/fastify": patch -"@seamless-auth/nextjs": patch ---- - -Verify the access token a silent refresh returns before issuing cookies from it. `ensureCookies` refreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit `/refresh` route) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token's `sid` claim, as the other flows do. - -`EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take a new optional `accessTokenAudience`, the audience user access tokens are issued for. The adapters pass their configured `audience`. Code that calls `ensureCookies` or `createEnsureCookiesMiddleware` directly should pass it too; it defaults to `authServerUrl`. diff --git a/packages/core/CHANGELOG.md b/packages/core/CHANGELOG.md index 7c6ddb0..2a4abdb 100644 --- a/packages/core/CHANGELOG.md +++ b/packages/core/CHANGELOG.md @@ -1,5 +1,14 @@ # @seamless-auth/core +## 0.19.1 + +### Patch Changes + +- 0314dfa: Check a silently refreshed access token against `authServerIssuer`. The silent refresh in `ensureCookies` now verifies the token it returns, but it checked `iss` against `authServerUrl` even when `authServerIssuer` was set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out. `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take an optional `authServerIssuer`, and the adapters pass their configured one. +- ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it. `ensureCookies` refreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit `/refresh` route) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token's `sid` claim, as the other flows do. + + `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take a new optional `accessTokenAudience`, the audience user access tokens are issued for. The adapters pass their configured `audience`. Code that calls `ensureCookies` or `createEnsureCookiesMiddleware` directly should pass it too; it defaults to `authServerUrl`. + ## 0.19.0 ### Minor Changes diff --git a/packages/core/package.json b/packages/core/package.json index b26c756..1a651ad 100644 --- a/packages/core/package.json +++ b/packages/core/package.json @@ -1,6 +1,6 @@ { "name": "@seamless-auth/core", - "version": "0.19.0", + "version": "0.19.1", "description": "Framework-agnostic core authentication logic for SeamlessAuth", "keywords": [ "authentication", diff --git a/packages/express/CHANGELOG.md b/packages/express/CHANGELOG.md index d5da94a..a88059c 100644 --- a/packages/express/CHANGELOG.md +++ b/packages/express/CHANGELOG.md @@ -1,5 +1,18 @@ # @seamless-auth/express +## 0.19.1 + +### Patch Changes + +- 0314dfa: Check a silently refreshed access token against `authServerIssuer`. The silent refresh in `ensureCookies` now verifies the token it returns, but it checked `iss` against `authServerUrl` even when `authServerIssuer` was set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out. `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take an optional `authServerIssuer`, and the adapters pass their configured one. +- ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it. `ensureCookies` refreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit `/refresh` route) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token's `sid` claim, as the other flows do. + + `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take a new optional `accessTokenAudience`, the audience user access tokens are issued for. The adapters pass their configured `audience`. Code that calls `ensureCookies` or `createEnsureCookiesMiddleware` directly should pass it too; it defaults to `authServerUrl`. + +- Updated dependencies [0314dfa] +- Updated dependencies [ca8fa4a] + - @seamless-auth/core@0.19.1 + ## 0.19.0 ### Minor Changes diff --git a/packages/express/package.json b/packages/express/package.json index c1532d0..62b63e4 100644 --- a/packages/express/package.json +++ b/packages/express/package.json @@ -1,6 +1,6 @@ { "name": "@seamless-auth/express", - "version": "0.19.0", + "version": "0.19.1", "description": "Express adapter for Seamless Auth passwordless authentication", "keywords": [ "authentication", diff --git a/packages/fastify/CHANGELOG.md b/packages/fastify/CHANGELOG.md index f3c7f41..97970be 100644 --- a/packages/fastify/CHANGELOG.md +++ b/packages/fastify/CHANGELOG.md @@ -1,5 +1,18 @@ # @seamless-auth/fastify +## 0.10.1 + +### Patch Changes + +- 0314dfa: Check a silently refreshed access token against `authServerIssuer`. The silent refresh in `ensureCookies` now verifies the token it returns, but it checked `iss` against `authServerUrl` even when `authServerIssuer` was set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out. `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take an optional `authServerIssuer`, and the adapters pass their configured one. +- ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it. `ensureCookies` refreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit `/refresh` route) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token's `sid` claim, as the other flows do. + + `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take a new optional `accessTokenAudience`, the audience user access tokens are issued for. The adapters pass their configured `audience`. Code that calls `ensureCookies` or `createEnsureCookiesMiddleware` directly should pass it too; it defaults to `authServerUrl`. + +- Updated dependencies [0314dfa] +- Updated dependencies [ca8fa4a] + - @seamless-auth/core@0.19.1 + ## 0.10.0 ### Minor Changes diff --git a/packages/fastify/package.json b/packages/fastify/package.json index a42d62e..4ce57d7 100644 --- a/packages/fastify/package.json +++ b/packages/fastify/package.json @@ -1,6 +1,6 @@ { "name": "@seamless-auth/fastify", - "version": "0.10.0", + "version": "0.10.1", "description": "Fastify adapter for Seamless Auth passwordless authentication", "keywords": [ "authentication", diff --git a/packages/nextjs/CHANGELOG.md b/packages/nextjs/CHANGELOG.md index 375cc0e..ceec16d 100644 --- a/packages/nextjs/CHANGELOG.md +++ b/packages/nextjs/CHANGELOG.md @@ -1,5 +1,18 @@ # @seamless-auth/nextjs +## 0.3.1 + +### Patch Changes + +- 0314dfa: Check a silently refreshed access token against `authServerIssuer`. The silent refresh in `ensureCookies` now verifies the token it returns, but it checked `iss` against `authServerUrl` even when `authServerIssuer` was set, so an app reaching the auth server at another URL (the local Docker stack from the host) answered 401 on every silent refresh and signed the user out. `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take an optional `authServerIssuer`, and the adapters pass their configured one. +- ca8fa4a: Verify the access token a silent refresh returns before issuing cookies from it. `ensureCookies` refreshes an expired session on the auth routes and wrote the auth API's response straight into the access cookie, while every other flow that issues a session (login, OTP, OAuth, magic link, and the explicit `/refresh` route) first checks the token against the auth server's JWKS and confirms it names the same user as the body. The access cookie is signed with the application's own secret and its roles are trusted on every later request, so a refresh response that did not come from the auth server could become a trusted session. The silent refresh now runs the same check and answers 401, clearing the session cookies, when it fails. The session id is now read from the signed token's `sid` claim, as the other flows do. + + `EnsureCookiesOptions` and the Express `createEnsureCookiesMiddleware` take a new optional `accessTokenAudience`, the audience user access tokens are issued for. The adapters pass their configured `audience`. Code that calls `ensureCookies` or `createEnsureCookiesMiddleware` directly should pass it too; it defaults to `authServerUrl`. + +- Updated dependencies [0314dfa] +- Updated dependencies [ca8fa4a] + - @seamless-auth/core@0.19.1 + ## 0.3.0 ### Minor Changes diff --git a/packages/nextjs/package.json b/packages/nextjs/package.json index 6afd20c..be917ec 100644 --- a/packages/nextjs/package.json +++ b/packages/nextjs/package.json @@ -1,6 +1,6 @@ { "name": "@seamless-auth/nextjs", - "version": "0.3.0", + "version": "0.3.1", "description": "Next.js App Router adapter for Seamless Auth passwordless authentication", "keywords": [ "authentication",