tag:github.com,2008:https://github.com/logto-io/logto/releases

Release notes from logto

2026-08-31T10:39:03Z tag:github.com,2008:Repository/378310716/v1.43.0 2026-08-31T12:42:51Z

v1.43.0

<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/12833674/643562961-8c173344-814c-4220-99ce-250e6b537db6.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3OTA1Nzk1MjYsIm5iZiI6MTc5MDU3OTIyNiwicGF0aCI6Ii8xMjgzMzY3NC82NDM1NjI5NjEtOGMxNzMzNDQtODE0Yy00MjIwLTk5Y2UtMjUwZTZiNTM3ZGI2LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA5MjglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwOTI4VDA3MDcwNlomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWFkNThiNzVlODNiMWM3NjM2NzU2MDBhOThlOTBmYzk4NTZkMDI3ZTg5MWYxZjc4ZDllMjdlODIyZWE2YzNhZTYmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.2yPvPI6p7dRNPs4xE0_pMEUTK6gNq6LwkJOd2gqz2_I"><img width="2000" height="1125" alt="logto-changelog-2026" src="https://private-user-images.githubusercontent.com/12833674/643562961-8c173344-814c-4220-99ce-250e6b537db6.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3OTA1Nzk1MjYsIm5iZiI6MTc5MDU3OTIyNiwicGF0aCI6Ii8xMjgzMzY3NC82NDM1NjI5NjEtOGMxNzMzNDQtODE0Yy00MjIwLTk5Y2UtMjUwZTZiNTM3ZGI2LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA5MjglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwOTI4VDA3MDcwNlomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWFkNThiNzVlODNiMWM3NjM2NzU2MDBhOThlOTBmYzk4NTZkMDI3ZTg5MWYxZjc4ZDllMjdlODIyZWE2YzNhZTYmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.2yPvPI6p7dRNPs4xE0_pMEUTK6gNq6LwkJOd2gqz2_I" content-type-secured-asset="image/png" style="max-width: 100%; height: auto; max-height: 1125px;"></a> <p>Sign-in Experience now supports <code>es-MX</code> (Spanish, Mexico).</p> <p>For users whose language is Spanish (Mexico), phone inputs default to the Mexico country code (<code>+52</code>). This release also fixes list formatter placeholders and the remaining untranslated MFA message in the Spanish locales.</p> <h2>Security hardening</h2> <h3>SSRF protection for webhooks and enterprise SSO</h3> <p>Outbound requests configured through the Management API are now blocked when they resolve to loopback, private, link-local, cloud metadata, or other special-use addresses.</p> <p>Protection now covers:</p> <ul> <li>Webhook delivery, including <code>POST /api/hooks/:id/test</code>.</li> <li>OIDC enterprise SSO discovery, token, and userinfo requests.</li> <li>SAML identity-provider metadata fetching.</li> <li>Every redirect hop made by these requests.</li> </ul> <p>DNS names are checked when the connection is established, so a hostname that resolves to a protected address is rejected like a literal IP address.</p> <h3>Token exchange validation</h3> <p>In addition to requiring first-party subject tokens, Logto now validates that a JWT presented as an <code>access_token</code> subject is actually an access token.</p> <p>The JWT must contain:</p> <ul> <li>The RFC 9068 <code>at+jwt</code> type header.</li> <li>A <code>client_id</code> claim.</li> </ul> <p>OIDC ID tokens and other JWTs signed by the tenant can no longer be substituted for an access token. Invalid subject tokens are rejected with <code>invalid_grant</code>.</p> <h3>Third-party Account API restrictions</h3> <p>Third-party applications can no longer mutate account data through the Account API or Verification API. Such requests now return:</p> <div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="403 auth.third_party_application_forbidden"><pre lang="text" class="notranslate"><code>403 auth.third_party_application_forbidden </code></pre></div> <p>First-party applications, including Account Center and Console, are unaffected.</p> <p>The check fails closed for unresolved client identifiers. This includes deleted applications whose access tokens are still active and CIMD clients whose identifier is a metadata URL.</p> <p>No read route received a new direct guard. However, the following reads require verification records created through guarded routes and are therefore no longer reachable by third-party applications:</p> <ul> <li><code>GET /api/my-account/grants</code></li> <li><code>GET /api/my-account/sessions</code></li> <li><code>GET /api/my-account/mfa-verifications/backup-codes</code></li> </ul> <h3>Suspended users cannot receive new tokens</h3> <p>Token issuance and userinfo now reject suspended users with <code>invalid_grant</code>, matching the existing behavior for deleted users.</p> <p>This applies across refresh token, authorization code, device code, and token exchange flows, even if an earlier token or session revocation did not complete successfully.</p> <h3>Third-party application scopes are revalidated</h3> <p>Removing a user scope from a third-party application's consent configuration now affects existing grants as well as new authorization requests.</p> <ul> <li>Refresh token exchanges drop scopes that are no longer configured.</li> <li>Authorization requests resuming an existing grant fail with <code>invalid_scope</code> when appropriate.</li> <li>Organization token requests fail with <code>insufficient_scope</code> after the organizations scope is removed.</li> <li>Consent submission no longer grants a scope that was removed while the consent screen was open.</li> </ul> <h3>Identifier lockouts use normalized identifiers</h3> <p>Sentinel lockout counters now use the same normalized identifier form as account lookup:</p> <ul> <li>Email addresses are lower-cased.</li> <li>Phone numbers are canonicalized.</li> <li>Usernames are case-folded only when the tenant's username policy is case-insensitive.</li> </ul> <p>This prevents alternate spellings of the same identifier from creating separate attempt buckets and weakening <code>maxAttempts</code>.</p> <p>Manual unlock also clears equivalent spellings where they identify the same account. After upgrading, an existing lockout recorded under a non-canonical spelling may end early, but no user becomes more locked out than before.</p> <h3>Redirect validation</h3> <ul> <li>Social landing-page <code>redirect_to</code> values must use <code>http</code> or <code>https</code>.</li> <li>Native callback links must use a custom application scheme.</li> <li>Stored callback links are checked again before the browser returns control to a native app.</li> <li>The unused Experience Springboard route has been removed to eliminate an untrusted redirect surface.</li> </ul> <h2>Bug fixes & stability</h2> <h3>Authentication and authorization</h3> <ul> <li>Revoking a user's third-party application authorization now invalidates only that application's tokens. The user's browser SSO session remains active.</li> <li>Elliptic Curve signing keys now advertise the algorithm matching their curve: P-256 uses <code>ES256</code>, P-384 uses <code>ES384</code>, and P-521 uses <code>ES512</code>.</li> <li>Switching from passkey sign-in to verification-code sign-in no longer prevents users from completing CAPTCHA.</li> <li>OIDC <code>invalid_scope</code> and <code>insufficient_scope</code> messages now show the rejected scope instead of raw <code>{{error_description}}</code> or <code>{{scope}}</code> placeholders.</li> </ul> <h3>Experience and localization</h3> <ul> <li>Safari and other password managers can now suggest and save a strong password on set-password and reset-password screens using the correct account identifier.</li> <li><code>Accept-Language</code> quality values with whitespace, such as <code>en; q=0.7</code>, are now parsed correctly. Invalid quality values fall back safely instead of producing <code>NaN</code>.</li> <li>Gmail custom allowlist and blocklist matching now treats <code>gmail.com</code> and <code>googlemail.com</code> as equivalent and ignores dots in the local part.</li> <li>Console now provides clearer examples, descriptions, and shorter placeholders for custom email rules.</li> </ul> <h3>Account Center and Management API</h3> <ul> <li>Saving Account Center or sign-up settings now drops references to deleted custom profile fields instead of returning <code>custom_profile_fields.entity_not_exists_with_names</code>.</li> <li>Deleted fields remain removable from Console even when their permission control is Off.</li> <li>Management API relation endpoints now accept empty scope or role arrays as no-ops instead of returning a 500 error. This includes endpoints such as: <ul> <li><code>POST /applications/:applicationId/user-consent-scopes</code></li> <li><code>POST /organizations/:id/users/:userId/roles</code></li> </ul> </li> <li>Date validation now matches the complete input and rejects trailing characters after an otherwise valid date.</li> </ul> <h3>Webhook delivery</h3> <p>Webhook POST requests now retry up to three times when the endpoint returns an HTTP 5xx response, matching the documented delivery contract.</p> <p>Because a retried event may be delivered more than once, webhook receivers should process events idempotently.</p> <h2>Connectors</h2> <h3>Microsoft Azure AD</h3> <p>The Microsoft Azure AD connector now supports a <code>disableEmailSync</code> option.</p> <p>By default, the connector continues to copy the Microsoft Graph <code>mail</code> attribute into the Logto user profile. Enable this option when the connector should authenticate the user without synchronizing that address, matching the existing control available for Azure OIDC enterprise SSO.</p> <h2>Self-hosting & OSS notes</h2> <ul> <li> <p><strong>Action required — outbound request protection</strong>: If webhooks or enterprise SSO connectors intentionally access services on a private network, add the required IP addresses or CIDR ranges to <code>SSRF_ALLOWED_ADDRESSES</code> before upgrading:</p> <div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="SSRF_ALLOWED_ADDRESSES=10.0.0.0/8,127.0.0.1"><pre lang="text" class="notranslate"><code>SSRF_ALLOWED_ADDRESSES=10.0.0.0/8,127.0.0.1 </code></pre></div> <p>Allowlisting only the required destinations is safer than disabling protection globally.</p> </li> <li> <p><strong>Dynamic app compatibility</strong>: Configuring <code>SSRF_ALLOWED_ADDRESSES</code> disables CIMD so unauthenticated dynamic clients cannot use the allowlist to reach private services. Setting <code>SSRF_PROTECTION_DISABLED=true</code> also disables CIMD.</p> </li> <li> <p><strong>Configuration compatibility</strong>: <code>OIDC_PROVIDER_SSRF_PROTECTION_DISABLED</code> remains supported as an alias for <code>SSRF_PROTECTION_DISABLED</code>. These variables apply only to self-hosted deployments.</p> </li> <li> <p><strong>Script runtime limits</strong>: Custom JWT and Actions scripts must complete within 5 seconds, stay within the 128 MB worker memory budget, and return JSON-serializable values.</p> </li> <li> <p><strong>Database migration required</strong>: This release ships new schema alterations and indexes. After upgrading, run the database alteration command (<code>npm run alteration deploy</code> in the <code>@logto/cli</code>/core image, or <code>logto db alteration deploy</code>) before starting the new version. See the <a href="https://docs.logto.io/logto-oss/upgrading-oss-version" rel="nofollow">upgrade guide</a>.</p> </li> </ul> <h2>Contributors</h2> <p>Huge thanks to the community members whose work shipped in this release:</p> <ul> <li><a href="https://github.com/arpitjain099">@arpitjain099</a> - complete-string date validation (<a href="https://github.com/logto-io/logto/pull/9266" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9266/hovercard">#9266</a>)</li> <li><a href="https://github.com/shuvamk">@shuvamk</a> - RFC-compliant <code>Accept-Language</code> quality parsing (<a href="https://github.com/logto-io/logto/pull/9338" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9338/hovercard">#9338</a>)</li> <li><a href="https://github.com/darcyYe">@darcyYe</a> - webhook retries for HTTP 5xx responses (<a href="https://github.com/logto-io/logto/pull/9410" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9410/hovercard">#9410</a>)</li> </ul> <p>For the complete list of changes, see the <a href="https://github.com/logto-io/logto/blob/master/packages/core/CHANGELOG.md">full changelog</a>.</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/tunnel@0.3.11 2026-08-31T10:39:23Z

@logto/tunnel@0.3.11

<p>@logto/tunnel@0.3.11</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/translate@0.2.17 2026-08-31T10:39:23Z

@logto/translate@0.2.17

<p>@logto/translate@0.2.17</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/shared@3.4.3 2026-08-31T10:39:22Z

@logto/shared@3.4.3

<p>@logto/shared@3.4.3</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/phrases-experience@1.15.0 2026-08-31T10:39:21Z

@logto/phrases-experience@1.15.0

<p>@logto/phrases-experience@1.15.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/phrases@1.31.0 2026-08-31T10:39:21Z

@logto/phrases@1.31.0

<p>@logto/phrases@1.31.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/language-kit@1.4.0 2026-08-31T10:39:22Z

@logto/language-kit@1.4.0

<p>@logto/language-kit@1.4.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/experience@1.22.0 2026-08-31T10:39:21Z

@logto/experience@1.22.0

<p>@logto/experience@1.22.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/core-kit@2.13.0 2026-08-31T10:39:22Z

@logto/core-kit@2.13.0

<p>@logto/core-kit@2.13.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/core@1.43.0 2026-08-31T10:39:02Z

@logto/core@1.43.0

<p>@logto/core@1.43.0</p> silverhand-bot