Fix4.17.2
v4.17.2
This release includes bug fixes for caching and relations of well-known app link files, cross-instance caching prevention, console support for Zitadel Support IDP, login flow improvements including proper IdP URL handling and account selection after logout, OIDC token exchange enhancements, and TOTP reuse prevention for improved security.
4.17.2 (2026-08-31)
Bug Fixes
- api: correct caching and relations of well-known app link files (#12634) (21dbb2e), closes #12580 #12497
- api: prevent cross-instance caching of well-known app link files (#12644) (f0329f0), closes #12634 #12634 #12634 #12497
- console: support Zitadel Support IDP (#12619) (c543449), closes #11825 #5127 #12018 #12056 #12371 #12378 #12384 #12394 #12396 #12422 #12469 #12530 #12568
- login: don't prepend base path to absolute IdP URL on login_hint redirect (#12610) (c660049), closes #12431
- login: redirect unknown users to external IdP after domain discovery when enumeration protection is active (#12581) (af3a9b2), closes #12369 #12369
- login: resolve the registration org consistently with the login policy (#12621) (8fb897d)
- login: show account selection after RP-initiated logout (#12638) (e5f526f), closes #12471 #12252
- oidc: allow OrgRoleIDScope downscoping in token exchange (#12563) (60a2195), closes #12312 #12413 #12312 #11869
- security: prevent TOTP reuse (#12616) (20cbfcf), closes /datatracker.ietf.org/doc/html/rfc6238#section-5
apioidcloginsecurityidpcaching
Source: original entry ↗