Skip to content

[pull] main from appwrite:main - #271

Merged
pull[bot] merged 13 commits into
djacidfx:mainfrom
appwrite:main
Sep 30, 2026
Merged

pull[bot] merged 13 commits into
djacidfx:mainfrom
appwrite:main

Conversation

@pull

@pull pull Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

loks0n and others added 13 commits September 29, 2026 18:35
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…in-mode JWTs

MQTT's appwrite-jwt auth decoded the same user JWT and loaded the user
from the connecting project without the binding added to HTTP and
realtime in #13992, so a sessionless JWT from another project still
authenticated there.

account.createJWT in admin mode stamped the managed project's ID on a
token backed by a console session, which the admin-mode verifier then
rejected; it now stamps console.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d next)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Bind MQTT user JWTs to their project; console claim for admin-mode JWTs
fix: require GitHub webhook secret like other VCS providers
#13992 threw user_jwt_invalid when a JWT was not issued for the request's
project. A function domain resolves to the console, and clients send
their own project's JWT there for the function to read, so every such
request got 401 before reaching the function. The token still grants
nothing: the request continues as a guest, as it did before #13992.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Unbound user JWT authenticates nobody instead of failing the request
@pull pull Bot locked and limited conversation to collaborators Sep 30, 2026
@pull pull Bot added the ⤵️ pull label Sep 30, 2026
@pull
pull Bot merged commit f7e33f7 into djacidfx:main Sep 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants