Security: Patreon provider user ID collision fix, see GHSA-f6qq-3m3h-4g42. Credit to @Nadav0077.
Other changes since v2.1.1
- #275 fix: validate "from" redirect target in OAuth/verify flows
- #273 Update dependencies to latest versions
- docs: recommend pairing with http.CrossOriginProtection for browser apps
- #266 feat: make Microsoft Entra ID tenant configurable
- feat(middleware): add customizable error handler for auth failures
Full Changelog: v2.1.1...v2.1.2