Skip to content

Releases: boxyhq/jackson

Release v1.39.2

20 Feb 16:26
Compare
Choose a tag to compare

Fixed

  • Prevent loading of arbitrary mdx files in Setup Links

Full Changelog: v1.39.1...v1.39.2

Release v1.39.1

20 Feb 12:33
Compare
Choose a tag to compare

Fixed

  • Prevent loading of arbitrary mdx files in Setup Links

Changed

  • Updated dependencies

Full Changelog: v1.39.0...v1.39.1

Release v1.39.0

19 Feb 13:13
Compare
Choose a tag to compare

This release contains security fixes, please update to this version as soon as you can

Added

  • Added login_hint to requested object
  • Additional Open Telemetry metrics for Identity Federation

Fixed

  • Security fix: Protect against potential timing attacks during login and webhooks processing
  • Security fix: Limit content length during webhooks processing

Changed

  • Updated dependencies

Full Changelog: v1.38.0...v1.39.0

Release v1.38.0

12 Feb 00:25
Compare
Choose a tag to compare

Added

  • Docker compose file for local runs
  • Performance benchmarking scripts based on k6s

Fixed

  • Validation of Setup Link API paths for PATCH and GET requests in SSO. Please update your Jackson version if you are using long-lived Setup Links

Changed

  • Updated dependencies
  • Cleaned up references to google_domain in DSync which is no longer used

Full Changelog: v1.37.1...v1.38.0

Release v1.37.1

05 Feb 11:23
Compare
Choose a tag to compare

Added

  • SSO Tracing for token and userinfo endpoints

Fixed

  • Our OpenAPI Spec is now fully compliant with 3.0, buggy JSDoc annotations have been fixed

Changed

  • Updated dependencies

Full Changelog: v1.37.0...v1.37.1

Release v1.37.0

31 Jan 12:46
Compare
Choose a tag to compare

Added

  • Added back Ory integration
  • Progress section for SSO Setup Links

Changed

  • Updated dependencies

Full Changelog: v1.36.0...v1.37.0

Release v1.36.0

15 Jan 10:23
Compare
Choose a tag to compare

Added

  • Store encrypted profile information with no way to access it without the key which is sent to client and never stored on the server
  • Added structured logging using pino library

Changed

  • Updated dependencies

Full Changelog: v1.35.1...v1.36.0

Release v1.35.1

26 Dec 10:15
Compare
Choose a tag to compare

Added

  • Additional Open Telemetry metrics to track errors

Changed

  • Updated dependencies

Full Changelog: v1.35.0...v1.35.1

Release v1.35.0

22 Dec 10:20
Compare
Choose a tag to compare

Added

  • Flags to disable, redact and modify TTL for SSO Traces. SSO_TRACES_DISABLE=true, SSO_TRACES_REDACT=true, SSO_TRACES_TTL (in hours)

Changed

  • Updated dependencies

Full Changelog: v1.34.7...v1.35.0

Release v1.34.7

16 Dec 23:36
Compare
Choose a tag to compare

Fixed

  • Added a dummy import of openid-client so that nextjs doesn't do tree shaking on it.

Changed

  • Updated dependencies

Full Changelog: v1.34.5...v1.34.7