Identity

669 items RSS
C
Casdoor Identity v4.15.0

v4.15.0

Changelog Bug fixes 0feded2 fix: handle missing organization and user in remove-user-from-group API 29c2451 fix: mark JWT-Custom refresh tokens with tokenType refresh-token 0cef429 fix: redirect to the requested page after login 956c405 fix: release camera on unmount and attach video after face dialog mounts 84a262a fix: restrict uploaded groups, roles and permissions to the admin's organization 2…

C
Casdoor Identity v4.14.0

v4.14.0

Changelog Features b94dce9 feat: open account menu on hover bd13018 feat: return stable error code in login failure response Bug fixes 8f7efcf fix: check terms of use by default on login page c92ff2d fix: check terms of use by default on signup page 94c0ef0 fix: end access-token sessions when the token is revoked by SSO logout 51bd444 fix: inherit DCR token lifetimes from the default application a…

Z
ZITADEL Identity v4.19.4

v4.19.4

4.19.4 (2026-10-01) Bug Fixes actions: set instance ID in async execution worker context (#12730) (03a2469), closes #11985 notification: correct ID order of the invite code sent handler (#12846) (101343a) skip finalized unique-constraint backfill and exclusive owner deletes (#12833) (aee8b88), closes #12831 #12834

A
Auth0 Identity

changed Upcoming changes to the length of refresh tokens As part of our commitment to main

changed Upcoming changes to the length of refresh tokens As part of our commitment to maintaining the highest security and compliance standards, we will soon be updating our authentication service configuration to increase the length and entropy of our refresh tokens. What is changing? We are increasing the cryptographic entropy of our issued Refresh Tokens. As a result, the string length of newly…

C
Casdoor Identity v4.13.0

v4.13.0

Changelog Features c9adca0 feat: add Audit provider to forward audit logs to Syslog Bug fixes 9944731 fix: keep provider host, endpoint and type unchanged on demo database 11f53fb fix: publish all certs in the global JWKS again 153bea5 fix: skip invalid certs instead of failing the whole JWKS fad4d7b fix: treat demo database as demo mode for provider APIs

L
Logto Identity v1.44.0

v1.44.0

Highlights MFA trusted devices: After completing MFA, users can trust their browser and skip repeated MFA prompts on it. Admins set the policy for the whole tenant, restrict it per organization, and manage devices from Console, Account Center, and the APIs. Keep your user IDs when migrating: User IDs can now be up to 128 characters, and self-hosted Logto accepts a custom id when creating a user, s…

C
Casdoor Identity v4.12.0

v4.12.0

Changelog Features 9f13005 feat: add application-level token group format option 3377f35 feat: support OIDC prompt=none on the authorize page (#5884) de6fc6d feat: support RFC 9207 iss parameter in authorization responses 980ad12 feat: support max session count for exclusive signin 6c18f6c feat: upgrade React to 19.3.0 in web Bug fixes 91fc924 fix: accept JWT-Standard subject tokens in token excha…

Z
ZITADEL Identity v4.19.3

v4.19.3

4.19.3 (2026-09-29) Performance Improvements query: index users14 by instance and org (#12830) (d378dea), closes #12826 query: stop expanding login names for every ListUsers row (#12826) (2c6acd8), closes #10037 #10840 #11768 #12830

O
OpenFGA Identity v1.21.0

v1.21.0

What's Changed Added Added "Dynamic Conditions" as a new experimental feature. #3313 Full Changelog: v1.20.0...v1.21.0

O
OpenFGA Identity v1.20.0

v1.20.0

What's Changed Added Added WithServiceName server option to allow embedders to override the serviceName field used for the grpc_service label on OpenFGA's package-level Prometheus metrics and telemetry.RPCInfo.Service. This enables multiple Server instances in the same process to emit separate metric series. Note it does not rename the standard gRPC server metrics (e.g. grpc_server_handled_total),…

Z
ZITADEL Identity v4.19.2

v4.19.2

This release fixes three security vulnerabilities. We recommend all 4.x deployments upgrade. Security GHSA-x4c7-fpcx-w9q6 (high): SAML identity-provider confusion leading to account takeover GHSA-jh92-5mrj-p2w2 (high): account takeover through the unsigned Login V2 session cookie GHSA-w4gv-rcwj-w6r5 (low): end-user impersonators could impersonate administrators ⚠️ Upgrade notes for the Login UI (L…

F
FusionAuth Identity v1.69.3

Release 1.69.3

FusionAuth 1.69.3 fixes an HTTP 403 issue with /confirmation-required.

C
Casdoor Identity v4.11.0

v4.11.0

Changelog Bug fixes 1278f9d fix: bind MFA remember to device and block avatar SSRF and forged payment notifies 6179955 fix: block cross-org API permission fallback on empty owner a0701ad fix: harden DCR, session rotation, Kerberos realm and XSS sinks 03c6c9a fix: harden OAuth, MFA, CAS and signup security checks a8f8d56 fix: harden consent, password reset, master code and CAS checks 8b6360b fix: r…

C
Casdoor Identity v4.10.0

v4.10.0

Changelog Features 0f7d684 feat: support SAML Single Logout protocol Bug fixes 3343aa5 fix: authorize session APIs against sessionPkId instead of id b40db12 fix: block cross-org token minting and secret-field query oracles fcc949c fix: enforce MCP token scopes on token-derived session cookies 2b91d9e fix: harden MFA, device flow and cross-org group checks 18b4671 fix: harden credential and session…

C
Casdoor Identity v4.9.0

v4.9.0

Changelog Bug fixes 5b456e1 fix: make account item names selectable in organization edit page 9db04af fix: restore web-old behavior in the console's editable sub-tables 2ad0722 fix: send Vary: Origin from the CORS filter

Z
ZITADEL Identity v4.19.1

v4.19.1

4.19.1 (2026-09-23) Bug Fixes setup step 79 batch unique constraint owner backfill (#12803) (42cdd5d)

C
Casdoor Identity v4.8.0

v4.8.0

Changelog Bug fixes eff25f6 fix: allow an org-scoped subject to update its own organization af0b022 fix: attribute audit records of unauthenticated requests to an organization 92c2db6 fix: correct Ukrainian (uk) i18n translations (#5869) 3cd925a fix: default the MFA setup wizard to the organization's required factor 2db20ea fix: don't prefill a random invalid phone number for new users 5370339 fix…

Z
ZITADEL Identity v4.18.0

v4.18.0

⚠️ Please skip this release and use v4.19.0. The setup step fails in this version (issue). 4.18.0 (2026-09-21) Bug Fixes eventstore: add owners to unique constraints (#12740) (c397a60) eventstore: prevent projections from skipping events (#12703) (d49a665), closes #8509 #10480 #10560 #10710 login: forward login_hint to the external IdP (#12760) (482ddc7), closes #6899 #11552 #12080 #12683 login: v…

Z
ZITADEL Identity v4.19.0

v4.19.0

4.19.0 (2026-09-23) Bug Fixes eventstore: omit owners on empty unique constraint inserts (#12785) (6308539), closes #12740 #12780 #12740 Features eventstore: remove application constraints by app owner (#12798) (765027e)