Version 13.0.13 - 2026/09/23
This release backports two bugfixes from v14 that address critical issues in Auth0 token validation and callback response caching.
Download
Download this version from the TYPO3 extension repository or from GitHub.
Fixed
- Token signature algorithm now correctly passed to Auth0 SDK: The Auth0 SDK v8 (used since v13.0.0)
expects the
tokenconfiguration key, but the migration from SDK v7 inadvertently kept the old parameter nameAlgorithm id_. Unknown keys are silently ignored by the SDK, so all installations have been verifying tokens with RS256 regardless of the configured algorithm. Tenants signing tokens with a shared secret (HS256) could not log in. The correct parameter name is now used.token_ alg - Callback responses now forbid caching: The callback returned the Auth0 session as Set-Cookie
without any cache directives, allowing intermediaries (proxies, CDNs) to store the response and strip
the cookies while doing so. The login then failed silently: back to the login screen, no session, no
error. All callback responses now carry
Cache-andControl: no- cache, no- store, must- revalidate, max- age=0 Pragma: no-headers to prevent storage by intermediaries.cache
Upgrade Notes
- No database migration is required, and existing Auth0 sessions stay valid.
- No code changes are required in third-party extensions or custom code.
All Changes
This is a list of all changes in this release:
2026-09-23 [BUGFIX] Forbid caching of callback responses [TER-516] (backport)
2026-09-23 [BUGFIX] Honour the configured token signature algorithm [TER-516] (backport)
Copied!