release: version packages - #9541
silverhand-bot wants to merge 1 commit into
Conversation
COMPARE TO
|
| Name | Diff |
|---|---|
| .changeset/apple-services-id-clarity.md | 📈 +637 Bytes |
| .changeset/calm-ravens-paginate.md | 📈 +95 Bytes |
| .changeset/olive-otters-sing.md | 📈 +838 Bytes |
| .changeset/shiny-mugs-hope.md | 📈 +590 Bytes |
| packages/account/CHANGELOG.md | 📈 +507 Bytes |
| packages/account/package.json | 0 Bytes |
| packages/api/CHANGELOG.md | 📈 +948 Bytes |
| packages/api/package.json | 0 Bytes |
| packages/cli/CHANGELOG.md | 📈 +93 Bytes |
| packages/cli/package.json | 0 Bytes |
| packages/connectors/connector-apple/CHANGELOG.md | 📈 +645 Bytes |
| packages/connectors/connector-apple/package.json | 📈 +1 Bytes |
| packages/console/CHANGELOG.md | 📈 +508 Bytes |
| packages/console/package.json | 0 Bytes |
| packages/core/CHANGELOG.md | 📈 +751 Bytes |
| packages/core/package.json | 0 Bytes |
| packages/create/CHANGELOG.md | 📈 +51 Bytes |
| packages/create/package.json | 0 Bytes |
| packages/experience/CHANGELOG.md | 📈 +508 Bytes |
| packages/experience/package.json | 0 Bytes |
| packages/schemas/CHANGELOG.md | 📈 +508 Bytes |
| packages/schemas/package.json | 0 Bytes |
| pnpm-lock.yaml | 0 Bytes |
There was a problem hiding this comment.
🟢 Approval recommended
The version bump and changelog entry are consistent with the described patch release and the changeset has been appropriately consumed/removed.
Pull request overview
This PR is an automated Changesets release PR to publish a patch release of @logto/connector-apple by bumping the package version, promoting the changeset text into the package changelog, and removing the consumed changeset file.
Changes:
- Bump
@logto/connector-appleversion from1.6.9to1.6.10 - Add a
1.6.10entry to the connector’sCHANGELOG.mdwith the patch-release notes - Remove the consumed changeset file for this release
File summaries
| File | Description |
|---|---|
| packages/connectors/connector-apple/package.json | Updates the published package version to 1.6.10. |
| packages/connectors/connector-apple/CHANGELOG.md | Records the 1.6.10 patch release notes for the connector. |
| .changeset/apple-services-id-clarity.md | Removes the changeset after it has been incorporated into the changelog. |
Review details
- Files reviewed: 3/3 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
5cfb542 to
af084cb
Compare
af084cb to
9beed60
Compare
9beed60 to
f0d3dc4
Compare
There was a problem hiding this comment.
🟢 Approval recommended
This is a standard Changesets release PR with consistent version/changelog updates and no apparent correctness or safety issues.
Review details
- Files reviewed: 3/3 changed files
- Comments generated: 0 new
- Review effort level: Lite
f0d3dc4 to
a395908
Compare
There was a problem hiding this comment.
🟢 Approval recommended
The version bump and changelog updates are consistent with the described patch release and the processed changeset removal is expected for a Changesets release PR.
Review details
- Files reviewed: 3/3 changed files
- Comments generated: 0 new
- Review effort level: Lite
There was a problem hiding this comment.
🟢 Approval recommended
The generated versions, changelogs, dependency metadata, consumed Changesets, and migration are internally consistent.
Review details
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
- Files reviewed: 33/35 changed files
- Comments generated: 0 new
- Review effort level: Lite
There was a problem hiding this comment.
🟢 Approval recommended
The generated versions, dependency metadata, migration, changelogs, and consumed Changesets are internally consistent.
Review details
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
- Files reviewed: 33/35 changed files
- Comments generated: 0 new
- Review effort level: Lite
There was a problem hiding this comment.
🟢 Approval recommended
Release versions, changelogs, dependency metadata, migrations, and consumed changesets are internally consistent.
Review details
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
- Files reviewed: 33/35 changed files
- Comments generated: 0 new
- Review effort level: Lite
There was a problem hiding this comment.
🔵 Needs a closer look
It combines a database migration with coordinated releases across multiple packages and requires final release validation.
Review details
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
- Files reviewed: 33/35 changed files
- Comments generated: 0 new
- Review effort level: Lite
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The generated versions, changelogs, consumed changesets, migration, and lockfile updates are internally consistent with the release metadata.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The user-ID migration changes a referenced key before handling its foreign keys, so existing database upgrades will fail.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The release includes multi-table schema migrations whose upgrade and rollback behavior warrants final human validation.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The multi-table production schema migration and coordinated release of numerous packages require final human validation.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Release metadata, changelogs, migrations, and changeset cleanup are internally consistent with the stated releases.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The user-ID migration does not handle its direct and composite foreign-key constraints, so deployment and rollback can fail.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The user-ID migration leaves subject_tokens.creator_id limited to 32 characters, so longer migrated user IDs can still fail subject-token creation.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It includes production database migrations across many user-related tables and requires human validation of deployment impact.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The user-ID migration omits subject_tokens.creator_id, so long user IDs can still fail when creating subject tokens.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Release metadata, consumed Changesets, lockfile updates, and schema migrations are internally consistent with no blocking issue found.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The user ID migration changes a referenced column before removing dependent foreign-key constraints, so PostgreSQL can reject the migration.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Release metadata, changelogs, dependencies, and schema migrations are internally consistent with no blocking defects found.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Release metadata, dependency updates, changelogs, consumed changesets, and schema migrations are internally consistent.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It spans a multi-package release with schema migrations and dependency metadata changes, warranting final human approval.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The user-ID migration leaves subject_tokens.creator_id limited to 32 characters, blocking subject-token creation for longer custom IDs.
Review effort: Lite
Findings: None
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to master, this PR will be updated.
Releases
@logto/api@1.44.0
Minor Changes
1bac1b7: add a typed async iterator for paginated Management API endpoints
fd41d8f: improve API SDK client reliability and ergonomics
401responses.get()and.post()while keeping the uppercase methods available@logto/phrases@1.32.0
Minor Changes
022317f: add a client compatibility setting so dynamic app clients such as ChatGPT and Codex can receive refresh tokens
These clients request
offline_accesswithoutprompt=consent, so they don't receive a refresh token and users have to sign in again whenever the access token expires. Turn on "Add consent prompt for offline access" under Client compatibility in the dynamic app settings, and Logto adds the consent prompt to these requests. The setting is experimental and off by default, and audit logs show the addedconsentinprompt.5bd627f: add a configurable score threshold for reCAPTCHA Enterprise so admins can control how strict CAPTCHA verification is
3f9fd15: add authentication policies for SAML applications
SAML applications force fresh authentication by default, as before. To let a SAML application reuse an existing Logto session, turn off "Always force authentication" in the application settings, or set
authnRequestConfig.forceAuthntofalseusing the SAML application Management API. The service provider can still require fresh authentication for a single sign-in withForceAuthn="true"(SAML 2.0 core, section 3.4.1).SAML assertions report the actual authentication time.
To require signed authentication requests, set
authnRequestConfig.requireSignedAuthnRequeststotrueand provide the service provider’s PEM-encoded RSA X.509 certificate inauthnRequestConfig.signingCertificate. Both HTTP-POST and HTTP-Redirect signatures are verified. Unsigned requests remain accepted by default.Patch Changes
0f1af96: support custom user ID when creating a user via the Management API
This capability is available in Logto Open Source only and is not supported in Logto Cloud.
POST /api/usersnow accepts an optionalid(up to 128 characters of letters, numbers, and_ - . @ : + = |). This lets you preserve existing user IDs, such asauth0|abc123or UUIDs, when migrating users from another identity provider. If the ID is already taken, the request fails withuser.id_already_in_use.@logto/schemas@1.44.0
Minor Changes
9af3b69: allow user IDs up to 128 characters
users.idand every column referencing it were limited to 12 or 21 characters. They now accept up to 128 characters, so users migrated from another identity provider can keep their original IDs.022317f: add a client compatibility setting so dynamic app clients such as ChatGPT and Codex can receive refresh tokens
These clients request
offline_accesswithoutprompt=consent, so they don't receive a refresh token and users have to sign in again whenever the access token expires. Turn on "Add consent prompt for offline access" under Client compatibility in the dynamic app settings, and Logto adds the consent prompt to these requests. The setting is experimental and off by default, and audit logs show the addedconsentinprompt.5bd627f: add a configurable score threshold for reCAPTCHA Enterprise so admins can control how strict CAPTCHA verification is
3f9fd15: add authentication policies for SAML applications
SAML applications force fresh authentication by default, as before. To let a SAML application reuse an existing Logto session, turn off "Always force authentication" in the application settings, or set
authnRequestConfig.forceAuthntofalseusing the SAML application Management API. The service provider can still require fresh authentication for a single sign-in withForceAuthn="true"(SAML 2.0 core, section 3.4.1).SAML assertions report the actual authentication time.
To require signed authentication requests, set
authnRequestConfig.requireSignedAuthnRequeststotrueand provide the service provider’s PEM-encoded RSA X.509 certificate inauthnRequestConfig.signingCertificate. Both HTTP-POST and HTTP-Redirect signatures are verified. Unsigned requests remain accepted by default.c5bd438: add MFA trusted devices with configurable policies and device management
Configure tenant-wide trusted-device policies and organization-level restrictions. After completing MFA, users can choose whether to trust their device on a dedicated page at the end of sign-in or sign-up, then skip repeated MFA on that browser. Manage trusted devices through Console, Account Center, the Management API, and the Account API, and subscribe to device lifecycle webhooks.
Patch Changes
@logto/cli@1.44.0
Patch Changes
a2d6e83: explain existing PostgreSQL tenant roles before database seeding stops
The database seed command now checks for the roles it needs before creating tables. If roles from a previous Logto database remain in the PostgreSQL cluster, the command reports the conflict and explains why dropping the database did not remove them, so an administrator can clean them up safely before retrying.
Updated dependencies [9af3b69]
Updated dependencies [022317f]
Updated dependencies [5bd627f]
Updated dependencies [3f9fd15]
Updated dependencies [c5bd438]
@logto/connector-apple@1.6.10
Patch Changes
bad3854: clarify that the Apple connector's identifier is a Services ID
The connector's identifier field is now labeled "Services ID" and states that an App ID (bundle ID) is not a valid value, which Apple rejects with an
invalid_clienterror.Setup instructions cover the Apple Developer portal, so enabling Sign in with Apple no longer appears to require Xcode. Troubleshooting guidance explains
invalid_clientandinvalid_request, including Apple's caching of identifier configuration, which has been observed to take up to 24 hours to refresh and can make a correct configuration look broken.@logto/connector-dingtalk-web@0.4.7
Patch Changes
corpIdfrom the DingTalk token response in social user informationrawData@logto/create@1.44.0
Patch Changes
@logto/connector-kit@5.1.2
Patch Changes
noneprompt with other prompt values in OIDC configuration@logto/account@0.7.0
Minor Changes
c5bd438: add MFA trusted devices with configurable policies and device management
Configure tenant-wide trusted-device policies and organization-level restrictions. After completing MFA, users can choose whether to trust their device on a dedicated page at the end of sign-in or sign-up, then skip repeated MFA on that browser. Manage trusted devices through Console, Account Center, the Management API, and the Account API, and subscribe to device lifecycle webhooks.
@logto/console@1.41.0
Minor Changes
022317f: add a client compatibility setting so dynamic app clients such as ChatGPT and Codex can receive refresh tokens
These clients request
offline_accesswithoutprompt=consent, so they don't receive a refresh token and users have to sign in again whenever the access token expires. Turn on "Add consent prompt for offline access" under Client compatibility in the dynamic app settings, and Logto adds the consent prompt to these requests. The setting is experimental and off by default, and audit logs show the addedconsentinprompt.5bd627f: add a configurable score threshold for reCAPTCHA Enterprise so admins can control how strict CAPTCHA verification is
3f9fd15: add authentication policies for SAML applications
SAML applications force fresh authentication by default, as before. To let a SAML application reuse an existing Logto session, turn off "Always force authentication" in the application settings, or set
authnRequestConfig.forceAuthntofalseusing the SAML application Management API. The service provider can still require fresh authentication for a single sign-in withForceAuthn="true"(SAML 2.0 core, section 3.4.1).SAML assertions report the actual authentication time.
To require signed authentication requests, set
authnRequestConfig.requireSignedAuthnRequeststotrueand provide the service provider’s PEM-encoded RSA X.509 certificate inauthnRequestConfig.signingCertificate. Both HTTP-POST and HTTP-Redirect signatures are verified. Unsigned requests remain accepted by default.c5bd438: add MFA trusted devices with configurable policies and device management
Configure tenant-wide trusted-device policies and organization-level restrictions. After completing MFA, users can choose whether to trust their device on a dedicated page at the end of sign-in or sign-up, then skip repeated MFA on that browser. Manage trusted devices through Console, Account Center, the Management API, and the Account API, and subscribe to device lifecycle webhooks.
@logto/core@1.44.0
Minor Changes
0f1af96: support custom user ID when creating a user via the Management API
This capability is available in Logto Open Source only and is not supported in Logto Cloud.
POST /api/usersnow accepts an optionalid(up to 128 characters of letters, numbers, and_ - . @ : + = |). This lets you preserve existing user IDs, such asauth0|abc123or UUIDs, when migrating users from another identity provider. If the ID is already taken, the request fails withuser.id_already_in_use.9af3b69: allow user IDs up to 128 characters
users.idand every column referencing it were limited to 12 or 21 characters. They now accept up to 128 characters, so users migrated from another identity provider can keep their original IDs.c8d00ee: support looking up users by external identity in the Management API
GET /api/usersnow acceptsidentityType,identityProvider, andidentityIdquery parameters for exact user lookup. UseidentityType=socialwith a connector target (such asdingtalk), oridentityType=ssowith an enterprise SSO issuer, together with the user identifier issued by the external provider. The identity filter is combined with other search filters using AND logic022317f: add a client compatibility setting so dynamic app clients such as ChatGPT and Codex can receive refresh tokens
These clients request
offline_accesswithoutprompt=consent, so they don't receive a refresh token and users have to sign in again whenever the access token expires. Turn on "Add consent prompt for offline access" under Client compatibility in the dynamic app settings, and Logto adds the consent prompt to these requests. The setting is experimental and off by default, and audit logs show the addedconsentinprompt.5bd627f: add a configurable score threshold for reCAPTCHA Enterprise so admins can control how strict CAPTCHA verification is
3f9fd15: add authentication policies for SAML applications
SAML applications force fresh authentication by default, as before. To let a SAML application reuse an existing Logto session, turn off "Always force authentication" in the application settings, or set
authnRequestConfig.forceAuthntofalseusing the SAML application Management API. The service provider can still require fresh authentication for a single sign-in withForceAuthn="true"(SAML 2.0 core, section 3.4.1).SAML assertions report the actual authentication time.
To require signed authentication requests, set
authnRequestConfig.requireSignedAuthnRequeststotrueand provide the service provider’s PEM-encoded RSA X.509 certificate inauthnRequestConfig.signingCertificate. Both HTTP-POST and HTTP-Redirect signatures are verified. Unsigned requests remain accepted by default.c5bd438: add MFA trusted devices with configurable policies and device management
Configure tenant-wide trusted-device policies and organization-level restrictions. After completing MFA, users can choose whether to trust their device on a dedicated page at the end of sign-in or sign-up, then skip repeated MFA on that browser. Manage trusted devices through Console, Account Center, the Management API, and the Account API, and subscribe to device lifecycle webhooks.
Patch Changes
7d54310: use a supported base language for API error messages when the requested regional language is unavailable
3da75ce: support a trailing slash in the issuer of OIDC enterprise SSO connectors
The discovery path is now joined onto the connector's
Issuer, sohttps://idp.example.com/andhttps://idp.example.comboth resolve tohttps://idp.example.com/.well-known/openid-configuration. The stored issuer value stays exactly as configured, so existing SSO identities keep resolving.Failed outbound requests made by an OIDC SSO connector now report a concise reason: the error message, or the status code alongside the response body for an HTTP failure.
Updated dependencies [0f1af96]
Updated dependencies [9af3b69]
Updated dependencies [e11805c]
Updated dependencies [022317f]
Updated dependencies [5bd627f]
Updated dependencies [3f9fd15]
Updated dependencies [a2d6e83]
Updated dependencies [c5bd438]
@logto/experience@1.23.0
Minor Changes
c5bd438: add MFA trusted devices with configurable policies and device management
Configure tenant-wide trusted-device policies and organization-level restrictions. After completing MFA, users can choose whether to trust their device on a dedicated page at the end of sign-in or sign-up, then skip repeated MFA on that browser. Manage trusted devices through Console, Account Center, the Management API, and the Account API, and subscribe to device lifecycle webhooks.
Patch Changes
e11805c: opt the sign-in experience out of browser auto-translation
Browser auto-translation replaces the text nodes React created (
<font><font>…</font></font>). React's DOM bookkeeping no longer matches the document, so the next update throwsNotFoundError: Failed to execute 'removeChild' on 'Node'; the experience app has no error boundary, so the whole tree unmounts and the user is left on a blank page in the middle of signing in or signing up — a reload is the only way out.The experience is already localized per tenant (custom phrases plus language detection), so the page now ships
translate="no"and<meta name="google" content="notranslate">, which is what Chrome, Edge and Safari read before offering or applying a translation.