v3.1.1
AuthEndpoints
On hosts without o.Jwt.Enabled, CSRF-protected endpoints returned 500 for callers without an application cookie. The CSRF check tried to authenticate against the JWT Bearer scheme, which those hosts never register. Anonymous passkey requestOptions, register/options, register, and login failed on the default cookie facade and the Identity bearer facade. The check now skips unregistered schemes. Requests without a CSRF token return 400, and requests with a valid token succeed.
- Anonymous passkey ceremonies work on the default cookie and Identity bearer facades without JWT
- Missing or invalid CSRF tokens return 400 instead of 500
- Hosts with JWT enabled behave as before
Packages
- AuthEndpoints
3.1.1 - AuthEndpoints.External.OAuth, AuthEndpoints.OAuth.GitHub, and AuthEndpoints.OAuth.Google unchanged at
3.0.0-preview.4