.. include:: ../../Includes.txt
============================
Version 13.0.13 - 2026/09/23
============================
This release backports two bugfixes from v14 that address critical issues in Auth0 token validation and
callback response caching.
Download
========
Download this version from the `TYPO3 extension repository `__ or from
`GitHub `__.
Fixed
=====
* **Token signature algorithm now correctly passed to Auth0 SDK:** The Auth0 SDK v8 (used since v13.0.0)
expects the ``tokenAlgorithm`` configuration key, but the migration from SDK v7 inadvertently kept
the old parameter name ``id_token_alg``. Unknown keys are silently ignored by the SDK, so all
installations have been verifying tokens with RS256 regardless of the configured algorithm. Tenants
signing tokens with a shared secret (HS256) could not log in. The correct parameter name is now used.
* **Callback responses now forbid caching:** The callback returned the Auth0 session as Set-Cookie
without any cache directives, allowing intermediaries (proxies, CDNs) to store the response and strip
the cookies while doing so. The login then failed silently: back to the login screen, no session, no
error. All callback responses now carry ``Cache-Control: no-cache, no-store, must-revalidate, max-age=0``
and ``Pragma: no-cache`` headers to prevent storage by intermediaries.
Upgrade Notes
=============
* No database migration is required, and existing Auth0 sessions stay valid.
* No code changes are required in third-party extensions or custom code.
All Changes
===========
This is a list of all changes in this release::
2026-09-23 [BUGFIX] Forbid caching of callback responses [TER-516] (backport)
2026-09-23 [BUGFIX] Honour the configured token signature algorithm [TER-516] (backport)