• v0.2.9 4f9d13394b

    v0.2.9 Stable

    franz released this 2026-09-20 14:19:24 +00:00 | 2 commits to master since this release

    Signed by franz
    GPG key ID: 1B3418BA53820C4C

    Security

    • Org owners could mint recovery codes for co-members and take their accounts
    • Org owners could create OAuth clients that skip the consent screen
    • Team rename, delete and membership weren't bound to the org in the URL
    • Org overview and branding were readable by non-members
    • Handoff trusted any OAuth client, including self-registered ones
    • SAML login handed the browser a 15-minute recovery link
    • Invite and one-shot-reveal tokens were stored in plaintext
    • CIMD client registration had no ceiling
    • X-Real-IP was attacker-controlled on a short forwarded-for chain
    • The NSS resolver aborted sshd and sudo on an interior NUL
    • The Linux client pinned a vulnerable rustls (RUSTSEC-2026-0285)

    Changed

    • Identity and session admin pages are operator-only; ?org= no longer admits owners
    • Org-created OAuth clients are limited to their own org's registered audiences
    • New [oauth.cimd].max_clients and max_clients_per_host
      Builds, checksums and provenance: https://github.com/franzos/forseti/releases/tag/v0.2.9
    Downloads