Issues 共 482
bug: Null byte (\x00) in POST body to /oidc/token causes HTTP 500 instead of 400
#8990 · Allen-wick · 2026-06-10
bug: Tenant-to-host escape risk via vm.runInNewContext in custom JWT scripts
#8977 · Allen-wick · 2026-06-09
bug:auth flows like sign in, sign out and account center Flash bang the user (Theme Flash)
#8959 · Heracraft · 2026-06-05
Security: Open redirect via unvalidated redirect_to param in SocialLanding page
#8903 · Shivam8584 · 2026-05-29
feature request: Headless API support
#8891 · monolithed · 2026-05-27
bug: MFA and oneTimeToken
#8841 · adam-authlgc · 2026-05-21
Bug: "Social connection not enabled" error when linking new social account in /account/security (v1.39.0)
#8800 · vicenteyu · 2026-05-12
feature request: Clarify SPA refresh token TTL behavior on rotation (revisit #4520)
#8779 · SongRongLee · 2026-05-09
bug: security page bind with the social issue
#8775 · ashtonli · 2026-05-09
feature request: MCPJam inspector compatibility
#8712 · tleyden · 2026-04-25