Skip to content

Releases: auth0/nextjs-auth0

v4.0.2

19 Feb 07:26
724310c
Compare
Choose a tag to compare

Changed

Fixed

v4.0.1

12 Feb 09:30
715e995
Compare
Choose a tag to compare

Fixed

  • fix: sanitize the returnTo parameter to prevent open redirect vulnerabilities. #1897 (guabu)

v3.6.0

31 Jan 11:37
51ae671
Compare
Choose a tag to compare

v3.6.0 (2025-01-31)

This is a maintainance release for V3 of the SDK.
V4 supports Next.JS 15 and React 19 and is published on npm!
We will continue to add features and security upgrades in V4 going further. Please migrate to V4 for a better experience.

Security

v4.0.0

30 Jan 15:09
f456baf
Compare
Choose a tag to compare

🛠️ Changes

⚠️ This is a major release with breaking changes.

  • Significant updates have been introduced in this release. Please refer to the V3 → V4 MIGRATION GUIDE for details on upgrading.

What's Changed

New Contributors

Full Changelog: v3.5.0...v4.0.0

v4.0.0-beta.14

06 Jan 09:58
1703914
Compare
Choose a tag to compare
v4.0.0-beta.14 Pre-release
Pre-release

🛠️ Changes

  • fix: propagate session data updates within the same request (fixes: #1841)
  • chore: export SessionDataStore and LogoutToken types (closes: #1852)
  • feat: add generateSessionCookie testing helper (closes: #1857)

v4.0.0-beta.13

20 Dec 05:51
92df43b
Compare
Choose a tag to compare
v4.0.0-beta.13 Pre-release
Pre-release

🛠️ Changes

  • chore: refresh the token set when calling getAccessToken instead of the middleware (fixes: #1851 and #1841)
  • feat: add idToken to beforeSessionSaved hook (closes: #1840)
  • fix: ensure builds succeed without AUTH0_DOMAIN set (closes: #1849)
  • chore: allow specifying client assertion config via env vars

v4.0.0-beta.12

18 Dec 06:18
5bd9a1e
Compare
Choose a tag to compare
v4.0.0-beta.12 Pre-release
Pre-release

🛠️ Changes

  • chore: add note about RP-Initiated logout
  • chore: warn instead of throwing error when using insecure requests flag in prod (closes: #1846)
  • chore: remove warning for prod env with non-https (closes: #1847)

v4.0.0-beta.11

17 Dec 11:23
1e482a4
Compare
Choose a tag to compare
v4.0.0-beta.11 Pre-release
Pre-release

🛠️ Changes

  • feat: introduce updateSession helper (closes: #1836)
  • feat: private_key_jwt authentication method
  • fix: peerDependencies for React 19 (closes: #1844)
  • chore: allowInsecureRequests for mock OIDC server during development (closes: #1846)

v4.0.0-beta.10

10 Dec 12:33
fed3bf4
Compare
Choose a tag to compare
v4.0.0-beta.10 Pre-release
Pre-release

🛠️ Changes

  • chore: add more description in error log on discovery errors (closes: #1832)
  • chore: migration guide
  • chore: include typeVersions for type resolution (fixes: #1816)
  • fix: only dist files should be published (fixes: #1825)
  • feat: add PAR support
  • feat: allow customizing auth routes (closes: #1834)
  • chore: set secure cookie attribute based on app base URL protocol (closes: #1821)

v4.0.0-beta.9

03 Dec 07:39
726a8ed
Compare
Choose a tag to compare
v4.0.0-beta.9 Pre-release
Pre-release

🛠️ Changes

  • fix: clear session before redirecting to /v2/logout (closes #1826)
  • feature: add Auth0Provider to pass initialUser (closes: #1823)
  • fix: getAccessToken types should not return null (closes: #1831)