Repository navigation
chore: version packages - #242
Merged
Merged
Conversation
github-actions
Bot
force-pushed
the
changeset-release/main
branch
7 times, most recently
from
October 8, 2026 15:21
831a18d to
0fa9abe
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
October 8, 2026 15:29
0fa9abe to
2c18469
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
[email protected]
Minor Changes
64a9907: Add an adapter conformance suite that any server adapter can be held to (feat(verify): extract a language-agnostic adapter conformance suite #246).
seamless verify --adapter-url=<url>starts Postgres and the auth API and runs the adapter specs against a reference app you started at that URL, for adapters this repository does not build (Go, Rust, Python).verify/CONFORMANCE.mddocuments what the reference app must serve.seamless verify, now cover cookie attributes and clearing, refresh rotation, concurrent refresh and refresh-token reuse, bearer transport, the adapter's own guard on an app route, error passthrough, the absence of tokens in cookie-transport bodies, and forwarding of the client's address and user agent to the auth API.@seamless-auth/express0.19,@seamless-auth/fastify0.10).b051bff:
seamless config setandconfig applyacceptprompt_passkey_enrollmentandphishing_resistant_only, which need auth server v0.17.0 or later.prompt_passkey_enrollmentmakes email code, phone code and magic link sign-ins ask a user with no passkey to enroll one.phishing_resistant_onlylimits sign-in to passkeys. An older instance rejects a patch that includes either key.Patch Changes
seamless usersandseamless orgnow read admin responses with the shared@seamless-auth/typesschemas.users credentialsnames each passkey by the name its owner gave it (friendlyName), then by the device the auth server recorded, where it used to print "credential" for every one because it looked for fields the API never sends. A response missing a field the CLI needs now fails with a message naming the field, where it used to print placeholders such as(no id). Fields an instance sends that this CLI version does not know about are kept, so--jsonoutput still carries them.seamless login --localnow works for a phone number. The auth server sends an SMS code as a number in the delivery block, and the CLI only accepted a string, so every local phone login failed saying the instance had not returned the code. Login responses are now read with the shared@seamless-auth/typesschemas, and a login method the instance offers that this CLI version does not know no longer gets in the way of an OTP login.seamless profile add --identifier-typeis validated with the same schema.seamless sessionsnow reads the session list with the shared@seamless-auth/typesschema. A session the instance sends malformed fails the command with a message naming the field, where it used to be dropped from the list without a word.sessions list --jsonnow carries every field the API sends, includingdeviceName,ipAddressanduserAgentasnullwhen the API has none, where it used to leave them out.seamless config setandconfig applynow acceptflow_rate_limits, which the auth server has read from system config since v0.14.0;config applyused to drop it from a config file without a word.config applynow tells read-only keys from unknown ones, andconfig diffflags a key no config has, which is usually a typo. The writable keys are checked against the shared@seamless-auth/typespatch schema.config getandoauth-providers liststill show exactly what the instance stores: they check the response's shape but never fill in schema defaults or reject a stored value.seamless initnow downloads the starter templates by the commit their release tag pointed at when the CLI was published, rather than by the tag, so a moved tag cannot change what a scaffold extracts. Template extraction also fails with a clear error on an archive entry that would write outside the project, as the--admin=sourcedashboard download already did.SEAMLESS_TEMPLATES_REFandSEAMLESS_TEMPLATES_DIRstill override the source as before.