Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Auth0, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Beta von nextjs-auth0 SDK v4

Die Beta von nextjs-auth0 SDK v4 bringt unter anderem Middleware-basierte Authentifizierung, verschlüsselte Cookies, Rolling Sessions und Unterstützung für Next.js 15, während v3 nicht für Next.js 15 aktualisiert wird und nach dem GA von v4 noch 6 Monate Sicherheitsupdates erhält.

Hello everyone, We're thrilled to announce the beta release of nextjs-auth0 SDK v4! This new version brings significant improvements, new features, and fixes to enhance your development experience. ### Important Notice About v3 As we move forward, **we will not be updating v3 of the SDK to support Next.js 15**. This allows us to focus on v4, which offers a wealth of new features and improvements. This will also enable us to support future releases of Next.js faster and with more confidence. We understand this may pose challenges, and we're here to help. v3 will continue to receive critical security updates for 6 months after the GA of v4. ### Highlights of v4 Beta - Middleware-Based Authentication: Improved compatibility and reduced maintenance by moving to middleware-based handlers. - Enhanced Security: Switched to encrypted cookies and removed outdated cookie logic. - Resolved State Mismatch Issues: Fixed long-standing issues reported by the community. - Improved Session Management: Implemented rolling sessions and eliminated cookie chunking. - Improved Hooks and Helpers: Introduced useUser(), getAccessToken(), and getSession() for easier data fetching and session handling. - Stateful Sessions with Custom Databases: Support for "Bring Your Own Database" (BYODB). - Compatibility with Next.js 15, Turbopack, and React 19 - Simplified architecture, API, and configuration options ### Try It Out and Provide Feedback We invite you to explore the beta release and share your fee…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Rules und Hooks in Public Cloud jetzt schreibgeschützt

Rules und Hooks sind in allen Public-Cloud-Umgebungen schreibgeschützt, sodass ihre Skripte nicht mehr bearbeitet werden können, während Deaktivieren, Löschen, Reaktivieren und Secrets-Änderungen weiter möglich sind und eine Migration zu Actions empfohlen wird.

We have transitioned the Rules and Hooks features to a read-only mode in all public cloud environments as part of their [announced deprecation](https://auth0.com/docs/troubleshoot/product-lifecycle/deprecations-and-migrations#rules-and-hooks-deprecations) plan. You can still disable, delete or re-enable an existing Rule or Hook. You can also add or remove Rules settings (for updating stored secrets) or Hook secrets but you will no longer be able to modify their script. If this impacts you, our recommendation is to migrate to Actions. Refer to the following docs for more details: - [Migrate Rules to Actions](https://auth0.com/docs/customize/actions/migrate/migrate-from-rules-to-actions) - [Migrate Hooks to Actions](https://auth0.com/docs/customize/actions/migrate/migrate-from-hooks-to-actions)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Bot Detection mit User-Agent-Signalen erweitert

Die Bot Detection der vierten Generation nutzt nun User-Agent-Signale in ihrem Machine-Learning-Modell, verfügbar für Enterprise-Kunden mit Attack-Protection-Add-on, und wird in den nächsten Wochen ausgerollt.

We are excited to announce that our fourth-generation Bot Detection has been upgraded with user-agent signals, and is now integrated into our proprietary machine learning model. This enhancement improves our capability to detect and thwart bot activity, further strengthening protection against malicious traffic without adding any additional friction for legitimate users. This security feature is available to all Enterprise customers with the Attack Protection add-on. We are currently rolling out this enhancement and expect to complete the process within the next few weeks, aligned with your individual release schedules. For activation details or further information, please check our [documentation](https://auth0.com/docs/secure/attack-protection/bot-detection) or reach out to your account team. We’re here to support you in safeguarding your systems against evolving threats. Thank you for trusting us with your security needs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Self-Service SSO: Neuerungen

Self-Service SSO bietet einen anpassbaren Einleitungstext, PingFederate-Unterstützung, einen API-Endpunkt zum Widerrufen von Access Tickets, geänderte Ticket-Ablauflogik sowie zusätzliche Parameter für das Login-Erlebnis beim Erstellen von Tickets.

Auth0 is excited to announce the following updates to Self-Service SSO: 1. __Custom Introduction Text:__ You can now customize the welcome message on the wizard's landing screen, aligning the experience with your brand’s tone and engaging users right from the start. 2. __PingFederate Support:__ We've expanded our list of supported Identity Providers (IdPs) to include PingFederate, giving you more flexibility in your authentication options. 3. __Revoking SSO Access Tickets:__ Our [new API endpoint](https://auth0.com/docs/api/management/v2/self-service-profiles/post-revoke) lets you revoke SSO access tickets at any time. 4. __Updated Ticket Expiration:__ Access tickets are now consumed only when a connection is created, enabled or edited — like when updating SAML or OIDC details — avoiding issues with scanners opening them prematurely. 5. __Customized Login Experience:__ When creating a [ticket](https://auth0.com/docs/api/management/v2/self-service-profiles/post-sso-ticket), you can now define the login experience — adding optional parameters for Home Realm Discovery, Organization Auto-Membership, and more to tailor every step of the way. To learn more, see the [Self-Service SSO documentation](https://auth0.com/docs/authenticate/enterprise-connections/self-service-SSO).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Zusätzliche SAML-Methoden in Actions

Der post-login-Trigger in Actions unterstützt jetzt api.samlResponse.setRelayState(relayState) und api.samlResponse.setIssuer(issuer).

Actions now supports the following APIs within the `post-login` trigger. - `api.samlResponse.setRelayState(relayState)` - `api.samlResponse.setIssuer(issuer)` You can see all available API methods supported within the `post-login` trigger along with details on these methods [from this link](https://auth0.com/docs/customize/actions/explore-triggers/signup-and-login-triggers/login-trigger/post-login-api-object).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Machine-to-Machine-Zugriff für Organizations allgemein verfügbar

M2M-Zugriff lässt sich nun per Client Credentials Flow auf bestimmte Organizations beschränken, verfügbar für B2B Professional, Enterprise und Enterprise Premium.

The possibility to __scope machine-to-machine access to a specific organization is now Generally Available__. This feature allows you to define the organizations that a given application can access for each API via the [Client Credentials Flow](https://auth0.com/docs/get-started/authentication-and-authorization-flow/client-credentials-flow). ![M2M_for_Orgs_Image](https://cdn.auth0.com/blog/M2M\_for\_Orgs\_changelog.png) You can easily __define and enforce access to one, many, or all the organizations in your tenant and securely expand the reach of your SaaS APIs__ to more use cases and scenarios, making sure sensitive data and operations are only accessible to authorized parties. After configuring the access rights for your API, you simply have to inspect the `org_id` in access tokens of incoming requests, independently of whether they come from third-party applications or your own applications. This feature is available for B2B Professional, Enterprise and Enterprise Premium customers. To learn more, read the [reference documentation](https://auth0.com/docs/manage-users/organizations/organizations-for-m2m-applications).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Private Performance Burst auf AWS (30x und 60x)

Für Private-Cloud-Deployments auf AWS gibt es neue Private-Performance-Burst-Angebote mit bis zu 3000 bzw. 6000 RPS für 80 Stunden im Monat und 1500 bzw. 3000 RPS in der übrigen Zeit.

Auth0 is delighted to launch __Private Performance Burst AWS - 30x (3000 RPS*) and 60x (6000 RPS)__ offerings for Private Cloud deployments on AWS. These cost-effective Private Performance options scale the Authentication traffic up to 3000 RPS and 6000 RPS respectively for 80 hours a month, and allow usage up to 1500 RPS and 3000 RPS respectively for the remaining duration. The elevated transaction capacity comes handy for planned and unplanned traffic spikes, e.g. during product launches, large media events, seasonal activities, and unpredictable usage peaks. The Private Performance Burst offering is just another milestone in our commitment to providing the functionality and flexibility our beloved customers need. Please refer to [Private Performance Burst documentation page](https://auth0.com/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy#private-performance-burst) for more information. *RPS: Requests Per Second

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Bedingte Relationship Tuples im Okta FGA Dashboard

Im Okta FGA Dashboard lassen sich nun bedingte Relationship Tuples erstellen und Kontextparameter in Assertions angeben, was zuvor nur über API oder CLI möglich war.

The [Okta FGA](https://fga.dev) authorization modeling language allows defining conditions that can be used to express certain ABAC authorization policies. Previously, if you wanted to take advantage of that feature you needed to use the [Okta FGA API](https://docs.fga.dev/api/service) or the [FGA CLI](https://docs.fga.dev/getting-started/cli). Now, with the [Okta Fine Grained Authorization Dashboard](https://dashboard.fga.dev "Okta FGA Dashboard"), you can create conditional relationship tuples and specify context parameters in assertions, making it easier to fully define ABAC-like conditions directly within the dashboard. For more details, refer to the [Okta FGA dashboard documentation](https://docs.fga.dev/intro/dashboard#conditions).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Erweitertes Gruppenattribut-Format für Google Workspace Enterprise

Die Google-Workspace-Enterprise-Verbindung unterstützt die Option Extended Group Attribute Format, die Gruppen als JSON-Objekte mit ID, Name und E-Mail-Adresse ins Nutzerprofil schreibt, sofort in der Public Cloud und in den nächsten Wochen in der Private Cloud.

The Google Workspace Enterprise connection now supports an **Extended Group Attribute Format** option. When selected, group memberships are written to the Auth0 user profile as an array of JSON objects containing the group unique ID, group name, and group email address for each group retrieved from Google. For more information, see [Connect Your App to Google Workspace](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/google-apps). This feature is immediately available in the public cloud and will be rolled out to private cloud environments in the next few weeks as per the release pipeline.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Self-Service SSO: IdP-Auswahl, Keycloak und weitere Verbesserungen

Tenant-Admins können wählen, welche IdPs im SSO-Einrichtungsassistenten angezeigt werden, außerdem wird Keycloak unterstützt, die Claims-Mapping-Hinweise entfallen ohne Nutzerattribute und das JSON beim Verbindungstest wird mehrzeilig dargestellt.

Auth0 is excited to introduce the following updates to Self-Service SSO: 1. Tenant admins now have the ability to choose which IdPs to display when their customers are setting up an SSO profile through the set up wizard, making the entire process more efficient and customizable. 2. We've added support for Keycloak expanding the available IdPs. 3. When no user attributes exist in the SSO profile, we skip the Claims Mapping instructions in the SSO wizard. 4. When testing the connection, the JSON has been formatted to show on multiple lines. To learn more, see the [Self-Service SSO documentation](https://auth0.com/docs/authenticate/enterprise-connections/self-service-SSO).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Custom Phone Providers in Early Access

Custom Phone Providers sind in Early Access verfügbar, sodass Kunden eigene Phone-Provider konfigurieren und Telefonnachrichten für die Nutzung der Telefonnummer als Identifier anpassen können, auch kontextabhängig etwa nach Organisation, Client oder User.

We’re excited to announce that __Custom Phone Providers__ in is now in __Early Access__. With this feature, customers can configure custom phone providers and customize phone messages associated with using phone number as an identifier. Using a custom phone provider for MFA and passwordless phone messages is planned for a later release. This early access release enables you to: - Configure your preferred phone provider for phone messages - Leverage various contexts for using different providers, including organization, client, user, and more We encourage you to get started with Custom Phone Providers today by checking out our [documentation](https://auth0.com/docs/customize/phone-messages/configure-phone-messaging-providers/configure-a-custom-phone-provider) and if you have any feedback, give us a shout in our [community channel](https://community.auth0.com/)!

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Geschlossene Support-Tickets älter als 24 Monate werden gelöscht

Auth0 speichert geschlossene Support-Tickets, die älter als 24 Monate sind, nicht mehr und löscht sie am 16. Oktober.

In our continuing effort to improve our security posture, Auth0 will no longer retain closed support tickets older than 24 months. Closed support tickets older than 24 months will be deleted on October 16. To view your support tickets, you can navigate to [https://support.auth0.com/tickets\](https://support.auth0.com/tickets) . For questions or issues on this change, please reach out to [Support](https://support.auth0.com/).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neue Private-Cloud-Region in den Vereinigten Arabischen Emiraten

Die Vereinigten Arabischen Emirate sind als neue AWS-Region für Auth0-Private-Cloud-Deployments verfügbar und ergänzen Bahrain als zweite Region im Nahen Osten.

Auth0 is delighted to introduce the __United Arab Emirates (UAE)__ as the latest __AWS region for Private Cloud__ deployments. We are committed to enhancing our presence in the Middle East. The UAE joins Bahrain as the second AWS region for Auth0 Private Cloud in this part of the world. This expansion opens up new possibilities in the UAE, where Private Cloud deployment is already supported on Azure.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Universal Login erfüllt EN 301 549

Universal Login erfüllt nun die Richtlinien des Standards EN 301 549 entweder von Haus aus oder durch Konfiguration, und das VPAT wurde entsprechend aktualisiert.

Okta CIC is excited to announce that Universal Login now satisfies out of the box or provide configurability to satisfy the guidelines for the [EN 301 549](https://www.etsi.org/human-factors-accessibility/en-301-549-v3-the-harmonized-european-standard-for-ict-accessibility) standard. We have updated our VPAT to include this information and it is available on [Okta.com](https://www.okta.com/accessibility/). By ensuring that Universal Login is accessible to all users, we enable our customers to confidently secure their applications with accessible authentication. See our [online documentation](https://auth0.com/docs/authenticate/login/auth0-universal-login#accessibility) for more details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Session bleibt beim Hinzufügen neuer Identifier bestehen

Beim Hinzufügen eines neuen Identifiers (E-Mail, Telefon oder Username) wird die Session nicht mehr beendet, während das Ändern eines bestehenden Identifiers weiterhin zur erneuten Authentifizierung führt; die Änderung wird schrittweise in den nächsten 1–4 Wochen ausgerollt.

**What’s Changing:** We are improving the user experience when adding or updating identifiers (email, phone number, or username) in profiles. **Key Updates:** 1. **New Identifier**: When a new identifier type (email, phone, or username) is added to a user profile where one **does not already exist**, the user’s session **will not be terminated**. This allows for a smoother **progressive profiling** experience, where users can add new identifiers without disruption. 2. **Changing Existing Identifier**: When an existing identifier is modified, the user’s session **will terminate**, and the user will have to re-authenticate. This ensures security best practices are followed when updating key account information. **Why This Matters:** Previously, any update to an identifier (whether adding or changing it) would terminate the user’s session. This could lead to a poor experience, especially during progressive profiling, where users are expected to update or add information without being logged out. With this update, customers can offer a seamless experience for users adding new identifiers while maintaining strict security for changes to existing identifiers. **Rollout Timing:** This change will be rolled out progressively over the next 1-4 weeks. Customers can expect to see the updated session handling behavior in their environments during this period. **Action Required:** No immediate action is required from customers, but it is recomme…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Email OTP Verification in Early Access

Als neue Methode zur E-Mail-Verifizierung steht Email OTP Verification in Early Access bereit, bei der Nutzer bei Signup oder Passwort-Reset ein per E-Mail gesendetes Einmalpasswort eingeben müssen, bevor der Vorgang abgeschlossen wird.

We have introduced __Email OTP Verification__ as a new method for email verification, available in Early Access. Expect to see the feature in your environments within the next 1-4 weeks. With __Email OTP Verification__, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens __before__ account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts. __Key Highlights:__ - __Synchronous Email Verification:__ Prevents account creation or password reset until users verify their email via OTP. - __Improved Security:__ Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links. - __Applicability:__ Available for both email verification during signup and password reset challenges. __Prerequisites:__ - Must be using __Universal Login__. - Connection must have __Flexible Identifiers__ enabled. - Email OTP is only compatible when using the __Identifier First Authentication Profile__. To enable this feature, navigate to the __Attributes__ tab on any connection and change the __Verification Method__ under the __Email__ attribute settings from __Verification Link__ to __OTP__. ![Email OTP Verification](https://cdn.auth0.com/blog/email\_otp\_verification.png)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Actions-Oberfläche auf „Triggers“ vereinheitlicht

Dashboard und Dokumentation von Auth0 Actions verwenden nun einheitlich den Begriff „Triggers“ statt einer Mischung aus Flows und Triggers, ohne das funktionale Verhalten von Actions zu ändern.

Auth0 Actions dashboard experience & documentation has been updated to consolidate around the concept of "Triggers" (as opposed to our previous mix of Flows and Triggers). A trigger represent points in the Auth0 process where Actions can be added. We believe this change will make it easier for you to identify available customization options (now simply labelled as [triggers](https://auth0.com/docs/customize/actions/explore-triggers)) and how they can be leveraged to personalize your identity needs. ![Actions Triggers](//images.ctfassets.net/kbkgmx9upatd/38P4yCQzOavZSewcUVRTOt/f40c6a6df9e9713449d6a1cf74404419/Screenshot_2024-09-25_at_2.27.21_PM.png) *Please note that this change does not have any impact on the current functional behaviour of Actions within Auht0.*

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Zwei neue Endpoints in den Session Management APIs

Die Session Management APIs bieten mit POST /api/v2/users/{id}/revoke-access und POST /api/v2/sessions/{id}/revoke zwei neue Endpoints, um Sessions eines Users bzw. eine einzelne Session samt zugehöriger Refresh Tokens zu widerrufen.

We are happy to announce that we just added two new endpoints to our Session Management APIs: [POST /api/v2/users/{id}/revoke-access](https://auth0.com/docs/api/management/v2/users/user-revoke-access) – This endpoint allows you to revoke sessions for a user and decide if you want to revoke the associated Refresh Tokens. [POST /api/v2/sessions/{id}/revoke](https://auth0.com/docs/api/management/v2/sessions/revoke-session) – This endpoint will revoke the session and all its related Refresh Tokens. Please refer to the [Auth0 Management API](https://auth0.com/docs/api/management/v2/introduction) for more information.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Continuous Session Protection für Enterprise-Kunden verfügbar

Continuous Session Protection ist für Enterprise-Kunden allgemein verfügbar und erlaubt es, in Actions Ablaufzeiten von Sessions und Refresh Tokens per setExpiresAt(Date) und setIdleExpiresAt(Date) zu steuern, diese zu widerrufen und zusätzliche Session- und Token-Daten abzurufen.

Continuous Session Protection is now generally available for enterprise customers, providing powerful tools to dynamically manage Sessions and Refresh Tokens within Auth0 Actions. This feature offers flexible options to configure expiration settings, access additional session and token data, and revoke sessions when necessary, enhancing security and control. Key benefits of Continuous Session Protection include: - Dynamic Session and Token Expiration: Configure custom absolute and idle timeouts for Sessions and Refresh Tokens using the new setExpiresAt(Date) and setIdleExpiresAt(Date) methods. These settings can be applied across users, organizations, or specific connections to meet your security and compliance needs. - Enhanced Security with Revocation: Revoke Sessions and Refresh Tokens programmatically using Actions, based on custom logic or risk assessments. This allows you to take immediate action when suspicious behavior is detected or when tokens no longer meet your security policies. - Comprehensive Session and Token Insights: Access additional session and refresh token attributes within Actions, enabling you to make more informed, data-driven decisions for managing user sessions. - These features allow enterprise customers to dynamically improve their security posture by customizing session behavior, enforcing shorter expiration times for high-risk roles (such as administrators), and revoking tokens when necessary to mitigate risks. To learn more, visit the product d…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Erweiterte Anpassung von Signup und Login

Universal Login unterstützt jetzt die Anpassung von Passwordless-Signup- und Login-Flows, und Auth0 CLI, Deploy CLI sowie Terraform Provider unterstützen die Partials API vollständig, inklusive Bearbeitung über auth0 ul customize.

**Passwordless Connection Support** Universal Login now supports customizing the passwordless signup and login authentication flows, allowing customers to address their unique data capture, security, and compliance requirements when users authenticate with email and SMS one-time passwords. See our [online documentation](https://auth0.com/docs/customize/login-pages/universal-login/customize-signup-and-login-prompts) for more information, instructions and examples. **Dev Tooling support for the Partials API** Auth0’s CI/CD tooling (Auth0 CLI, Deploy CLI, Terraform Provider) now fully supports the Partial API including the new Passwordless prompts. As a bonus, Partials can now also be edited using Auth0 CLI’s UL Customize interface. Run `auth0 ul customize` in your terminal to see it in action. To access these new capabilities, upgrade to the latest versions of Auth0 CLI, Deploy CLI, and Terraform Provider. ![Auth0 CLI - Partials API Support](//images.ctfassets.net/kbkgmx9upatd/4aJB7oZYi1eXnqa8QBXURf/b9fc528de063fc07efdf405204ffba68/Screenshot_2024-09-17_at_10.53.42_AM.png)

Originalquelle(öffnet in neuem Tab)Problem melden