0.43.0 (2026-09-28)
Features
- apply per-client limits to sign-in and password checks (38fc8f3)
- explain sign-in waits and show login protection status to admins (cec2ed0)
- security: harden authentication endpoints against abuse (#1317) (#1401) (9d4e230)
Bug Fixes
- clarify when to trust a forwarded-header sender in login protection guidance (9b47aa0)
- document release-please first-parent-adjacency skip (#1408) (e665bce)
- document release-please first-parent-adjacency skip and add recovery steps (927907b)
- isolate state between repeated route registration tests (8f84e2e)
- keep a fresh sign-in from being cleared by a stale unauthenticated request (bfb2028)
- sanitize client and route fields in rate-limit denial logs (96fb071)
- security: harden request throttling in the API layer (9934520)
- stop Firefox page loads hanging on the cross-origin opener policy header in E2E (513a2c3)
- tolerate wall-clock refill in throttle Retry-After assertions (22daaba)
- update dependency tldts to ^7.4.15 (594ae34)
- update inline-script hash in content security policy and guard against drift (91ba374)