v1.3.0 - Nov. 30, 2021
almost 4 years ago
The following changes are included in this release.
Enhancements
Next Identity API
⭐ Added new /logout endpoint parameter
/logout endpoint parameterThe /logout endpoint now includes the all_sessions parameter option. Setting this parameter to true will revoke all user sessions across multiple devices.
Next Identity Journeys
⭐ Implemented a failover for reCAPTCHA feature in Threat Guard
This enhancement improves the reliability of the reCAPTCHA feature.
⭐ Improved rate limiting on /otp endpoints
/otp endpointsThis enhancement blocks mobile number verification requests after the user reaches a pre-configured number of attempts. This protects against brute-force attacks that can let an attacker potentially discover valid OTP codes and compromise user accounts.
Additionally, several other enhancements have been introduced to optimize code and increase overall security.
Bug Fixes
Next Identity Journeys
- Respond with a
403 Forbiddenwhen a user attempts to access a screen that requires an active session instead of a500 Internal Server Error.
Next Identity API
- Resolved an issue where an invalid value is returned when calling the
/profileAPI wherebirthdateis a required attribute
Other
- Resolved an issue that was generating a
500 Internal Server Errorresponse when using flows that are missing certain translation strings
