v0.2.0-beta.21
Platform & APISecurity
- OAuth login no longer bypasses two-factor authentication. Google and GitHub sign-in issued a full session immediately, ignoring the account's
twoFactorEnabledflag — so a user who had enabled 2FA (or whose email/password account got linked to an OAuth identity) could log in without the second factor.googleLogin/githubLoginnow apply the same 2FA gate as password login: when 2FA is enabled they return a short-livedrequiresTwoFactorchallenge instead of tokens, and the client completes via the existingPOST /auth/login/2fa. No full session is created until the second factor is verified.