Security Advisory: Insecure email token verification in Prisma adapter (CVE-2021-21310)
Implementations using the Prisma adapter with the Email provider are impacted.
All impacted users who are not already running 3.3.0 should upgrade immediately.
github.com/nextauthjs/next-a…
Implementations not using the Email provider are not impacted by this issue.
Implementations using the Email provider with the default adapter (TypeORM) are also not impacted.
We would like to thank Alessandro Angelino for notifying us of this issue via responsible disclosure.
Live in 2 hours!
Part 3 of our series on building NextJS apps with GraphQL starts at 9:30 am PT.
Learn how to use the auth library NextAuth.js in an existing Next app & create a JWT solution that can be integrated with Hasura #GraphQL
➡️youtube.com/watch?v=Vy0UldnC…#nextjs
next-auth@3.2.0 is out! 🚀🎉
🔒 better OIDC support (PKCE, id_token, forward auth params)
🔒 new built-in providers
🔒 Prisma 2.15 support
🔒 support dark mode on pages
🔒 improved logs
... more!
Check out github.com/nextauthjs/next-a… for the whole list.
It's just the beginning! 🤫
Awesome!🤘
github.com/nextauthjs/adapte… is growing fast! 🚀
- TypeORM
- Prisma
- FaunaDB
- Firebase
- DynamoDB
- ...?
Who is next? 👀 Come, we help you add/migrate your custom adapter if you want to move it to the official organization!
Cannot wait! So on Monday 1st Feb we'll try to release a stable next-auth@3.2.0! 🎉
The list of changes is huge (See for yourself github.com/nextauthjs/next-a…), but (🤞) NO BREAKING CHANGES!
Only some final touches in the weekend.
Also, we want your adapters!: github.com/nextauthjs/adapte…
🎉 Created a new home 🏡 for custom adapters for next-auth:
github.com/nextauthjs/adapte…
Be part of the discussion github.com/nextauthjs/next-a… to figure out the best flow.
Add your adapter in a PR, or let us know if you want to be a maintainer of one.