Fixed batch unique constraint owner backfill in setup step 79
Corrected a bug in setup step 79 related to batch unique constraint owner backfill to ensure database consistency during initialization.
ZITADEL — Auth, Security product updates and releases, tracked on megachangelog.
Corrected a bug in setup step 79 related to batch unique constraint owner backfill to ensure database consistency during initialization.
This release includes a bug fix for eventstore that omits owners on empty unique constraint inserts, and a feature to remove application constraints by app owner in the eventstore.
Release 4.18.0 includes bug fixes for eventstore unique constraints and projection event skipping, login improvements with external IdP support and startup API credential verification, new database metrics publishing, telemetry enhancements for Google attributes, and query performance improvements for user list operations.
This release includes critical bug fixes for encryption of IDP intent tokens, IDP linking authorization logic, translation of authentication strings, and organization-level auth method permissions.
This release includes bug fixes for caching and relations of well-known app link files, cross-instance caching prevention, console support for Zitadel Support IDP, login flow improvements including proper IdP URL handling and account selection after logout, OIDC token exchange enhancements, and TOTP reuse prevention for improved security.
Fixed permission checks when issuing passkey enrollment codes and updated the login flow to require MFA prompt step before 2FA enrollment to improve security.
This release fixes multiple security and authentication issues: blocks Login V2 auth for deactivated organizations, enforces permission checks for passkey enrollment, prevents unwanted OTP requests, and requires MFA prompt before 2FA enrollment.
This release adds support for Zitadel as an identity provider with full CRUD operations, dynamic OIDC client registration and management per RFC 7591/7592, native passkey app links, and numerous bug fixes including improvements to login flows, metadata handling, and database operations.
Fixed telemetry to record route patterns instead of full request paths in HTTP metrics, preventing high-cardinality metric explosion and improving observability.
Fixed a security vulnerability in Login V1 where external identity provider accounts could be pre-hijacked, and now requires authentication before enrolling WebAuthn, U2F, TOTP, or OTP methods.
This release includes critical security fixes for login flows including prevention of external-IDP account hijacking and required authentication before enrollment, plus improvements to random string generation and ListUsers query performance.
Fixed a security issue in the actions module that prevented unauthorized disk access through the require function.
Bug fixes including prevention of disk access via require in actions, improved password complexity messaging, fixed submit button state during password set operations, and prevented crash from stale session cookies.
ZITADEL v4.16.0 includes multiple bug fixes for token exchange scope validation, user grants management, login UI improvements, and IDP handling, plus new features for invite code management in secret generators and FIPS 140-3 compliant crypto builds.
This release includes fixes for client and scope validation in token exchange, ensures external users' emails are verified before auto-linking, centers text for IDP buttons without icons, and guards the default redirect URI in OIDC/SAML failure paths.
Fixed JWT IdP token validation to always check exp and iat claims, added client_id verification during code exchange and refresh token flows, and improved JWT IdP audience management and validation.
Bug fixes including JWT IdP claim validation, client ID verification during OAuth flows, connection handling after migrations, PKCE application for OAuth/OIDC providers, and JWT audience management. Also improves login handling for passkey registration and custom font loading in branding.
Fixed a permission check issue where user update operations were not correctly validating permissions based on the actual provided data, which could have allowed unauthorized modifications.
15 more changes from ZITADEL. Sign up to read the whole changelog.
Sign up freeGitHub or email — no card needed.