Skip to content

Releases: nextauthjs/next-auth

next-auth@4.24.15

Choose a tag to compare

@gustavovalverde gustavovalverde released this 20 Jul 23:22
d857eec

Security patch release for the 4.x line.

  • getToken() now returns null instead of throwing when the Authorization header contains a malformed Bearer value.
  • OAuth state, nonce, and PKCE check cookies are now bound to the provider that created them and are rejected when a different provider handles the callback. Sign-ins in flight across the upgrade fail once and succeed on retry.
  • Email addresses are Unicode-normalized (NFKC) before validation in the email sign-in flow, closing a homoglyph @ bypass.
  • An explicitly configured NEXTAUTH_URL now takes precedence over the auto-detected forwarded host in trusted-host mode.
  • Restores CommonJS compatibility by pinning uuid to ^11.1.1; the 14.x line is ESM-only and broke require() on Node versions below 20.19.

@auth/xata-adapter@1.11.3

Choose a tag to compare

@Bekacru Bekacru released this 20 Jul 21:54

Other

  • @auth/core: dependency update (8a933f9)

@auth/upstash-redis-adapter@2.11.3

Choose a tag to compare

Other

  • @auth/core: dependency update (8a933f9)

@auth/unstorage-adapter@2.11.3

Choose a tag to compare

Other

  • @auth/core: dependency update (8a933f9)

@auth/typeorm-adapter@2.11.3

Choose a tag to compare

Other

  • @auth/core: dependency update (8a933f9)

@auth/sveltekit@1.11.3

Choose a tag to compare

@Bekacru Bekacru released this 20 Jul 21:54

Other

  • @auth/core: dependency update (8a933f9)

@auth/surrealdb-adapter@2.2.3

Choose a tag to compare

Other

  • @auth/core: dependency update (8a933f9)

@auth/supabase-adapter@1.11.3

Choose a tag to compare

Other

  • @auth/core: dependency update (8a933f9)

@auth/solid-start@0.19.3

Choose a tag to compare

@Bekacru Bekacru released this 20 Jul 21:54

Other

  • @auth/core: dependency update (8a933f9)

@auth/sequelize-adapter@2.11.3

Choose a tag to compare

Other

  • @auth/core: dependency update (8a933f9)