-
Notifications
You must be signed in to change notification settings - Fork 762
Pull requests: supabase/auth
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
chore(master): release 2.198.0
autorelease: pending
#2817
opened Sep 17, 2026 by
supabase-releaser
Bot
Loading…
fix(oidc): don't mutate shared config on Facebook id_token login
#2816
opened Sep 16, 2026 by
suvvvv
Loading…
fix(models): guard nil web_authn_credential in WebAuthnCredentials
#2815
opened Sep 16, 2026 by
suvvvv
Loading…
fix(models): guard nil authentication_method in IsAAL2Claim
#2814
opened Sep 16, 2026 by
suvvvv
Loading…
fix: stop leaking raw internal errors to clients in RefreshTokenGrant
#2813
opened Sep 15, 2026 by
Rakshit-gen
Loading…
5 tasks done
fix: recognize real Postgres unique violations in IsUniqueConstraintViolatedError
#2811
opened Sep 15, 2026 by
Rakshit-gen
Loading…
5 tasks done
fix(discord): use correct default avatar for the new username system
#2809
opened Sep 15, 2026 by
suvvvv
Loading…
fix(verify): harden OTP checks against nil sent-at and timing leaks
#2808
opened Sep 15, 2026 by
suvvvv
Loading…
fix(linkedin): avoid panic when the email response has no elements
#2807
opened Sep 15, 2026 by
suvvvv
Loading…
fix(redirect): accept allow-listed deep links with underscore schemes
#2805
opened Sep 15, 2026 by
suvvvv
Loading…
fix(models): guard identity email against non-string metadata
#2804
opened Sep 15, 2026 by
suvvvv
Loading…
fix: return verify-disabled error code when WebAuthn MFA verification is off
#2803
opened Sep 15, 2026 by
Dhvanit41
Loading…
fix(models): exclude oauth client sessions from mfa step-up invalidation (#2801)
#2802
opened Sep 14, 2026 by
melcheikh
Loading…
Migrate pop RawQuery call sites to sqlc (proof of concept)
#2799
opened Sep 11, 2026 by
hf
Contributor
Loading…
4 tasks done
feat(otp): handle test OTPs and Twilio Verify on the one_time_tokens path
#2798
opened Sep 10, 2026 by
annabkr
Contributor
Loading…
feat(otp): add one_time_tokens query helpers
#2797
opened Sep 9, 2026 by
annabkr
Contributor
Loading…
fix(provider): don't pin expected issuer for the Azure consumers endpoint
#2796
opened Sep 9, 2026 by
breken-ai
Loading…
fix: map concurrent MFA verify races to 4xx instead of 500
#2791
opened Sep 7, 2026 by
hsusul
Loading…
2 of 3 tasks
fix(api): guard against nil session pointer dereference in user update and recovery codes
#2789
opened Sep 6, 2026 by
Tyagiquamar
Loading…
feat(otp): switch one_time_tokens table to source of truth
#2788
opened Sep 4, 2026 by
annabkr
Contributor
Loading…
feat(auth): support distinct redirect URIs for OAuth mix-up defense (…
#2782
opened Sep 3, 2026 by
guptamilind0099
Loading…
Previous Next
ProTip!
Adding no:label will show everything without a label.