github steveiliop56/tinyauth v5.0.3

latest release: nightly
8 hours ago

Tinyauth v5.0.3

Warning

This release contains security fixes, please update as soon as possible.

This release addresses GHSA-xg2q-62g2-cvcm and GHSA-3q28-qjrv-qr39 discovered by @e1024x.

Fixes

  • Don't continue authentication on empty X-Forwarded-* headers.
  • Ensure user is logged in and not in the 2FA flow in the authorize endpoint
  • Ensure client ID matches the code entry before issuing a token

Technical

  • Update dependencies
  • Update translations

Please let me know of any issues so as I can fix them as soon as possible.

Don't miss a new tinyauth release

NewReleases is sending notifications on new releases.