PandaAuthChangelog

Newest first; entries were imported from the product site and keep the component names and wording of the time.

  1. Quickstart Preview: a local authentication experience package

    Public container images and a one-command startup script are now available for quickly trying PandaAuth's core authentication flows on your own machine.

    server · admin · me · portal

  2. Community Preview 0.2.0-preview.1: production preview

    PandaAuth Community Preview 0.2.0-preview.1 is deployed to production for early community trials; the historical v1.0.0 release materials are kept as an archive and do not represent a completed stable-release gate.

    server · sdk · admin · me · portal

  3. Portal rebuilt on Astro, live status page, and in-site docs

    The portal was reworked in place into an Astro build-to-wwwroot shape; a live status page aggregating the three services and in-site integration docs were added; the IDP health check now covers database connectivity.

    portal · server

  4. Security events and claim refinement (0.9)

    The 0.9 batch introduces security-event capabilities and refined token claims.

    server

  5. Portal reduced to a landing page; /docs temporarily points off-site

    Marketing content moved to the brand site; /docs 301-redirects to the brand site's product page (ADR-031). Partially superseded on 2026-09-23 when in-site docs returned.

    portal

  6. Passkey platform authenticators and enrollment-flow fixes

    Passkey login now prefers platform authenticators, and enrollment-flow issues are fixed; released to production.

    server · me

  7. Regular-user MFA and legacy credential reconfiguration (0.8)

    The 0.8 batch delivers multi-factor authentication for regular users and legacy credential reconfiguration; deployed to production.

    server · me

  8. User storage layer moves off Identity

    User storage was rebuilt in-house on our own panda_users model, removing the ASP.NET Core Identity dependency; existing password hashes (Argon2id PHC) carried over unchanged, invisible to users.

    server

  9. Email channel and self-service credentials (first 0.4 batch)

    The Resend email channel, OTP infrastructure, and three flows around forgot-password and self-service password change went live, with anti-enumeration and rate limiting throughout.

    server

  10. Five-part admin user management suite

    The admin console gains the full set of user operations — account creation, role management, unlock, profile editing with 2FA reset, and terminal-state deletion — every action wired to audit logging and token revocation.

    server · webadmin

  11. webadmin admin login implemented (OIDC client flow)

    Admin console login reuses the OIDC client flow (authorization code + PKCE + refresh token); no separate admin authentication API is introduced.

    webadmin

  12. Release engineering settled, first production deployment

    The five-repo split landed, the historical production domain was once auth.pandalabs.cc, and Caddy same-domain routing went live; release engineering settled on per-repo SHA versioning, targeted rebuilds, and per-service rollback.

    server · webadmin · me · portal