Skip to content

Conversation

@stevehobbsdev
Copy link
Contributor

Important

This release contains a change to how custom signup fields are processed. From this release, all HTML tags are stripped from user input into any custom signup field before being sent to Auth0 to register the user. This is a security measure to help mitigate from potential XSS attacks in signup verification emails.

If you would be affected by this change and require HTML to be specified in a custom signup field, please leave us some feedback in our issue tracker.

Changed

Fixed

Security

@stevehobbsdev stevehobbsdev requested a review from a team as a code owner May 5, 2022 10:45
@stevehobbsdev stevehobbsdev merged commit 49e517d into master May 5, 2022
@stevehobbsdev stevehobbsdev deleted the release/v11.33.0 branch May 5, 2022 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants