Tinyauth v5.0.3
Warning
This release contains security fixes, please update as soon as possible.
This release addresses GHSA-xg2q-62g2-cvcm and GHSA-3q28-qjrv-qr39 discovered by @e1024x.
Fixes
- Don't continue authentication on empty
X-Forwarded-*headers. - Ensure user is logged in and not in the 2FA flow in the authorize endpoint
- Ensure client ID matches the code entry before issuing a token
Technical
- Update dependencies
- Update translations
Please let me know of any issues so as I can fix them as soon as possible.