v4.5.0.7

FoundationVision/VARv4.5.0.7Jun 22, 2026by sid-swirl

AI Summary

A security patch release addressing critical vulnerabilities in OIDC sign-in and Microsoft 365 token handling to prevent privilege escalation.

Key Highlights

  • OIDC sign-in no longer provisions superuser or staff accounts
  • M365 token lookup strictly scoped to the requesting user (removed cross-user fallback)
  • No schema or dependency changes required for this update

Breaking Changes

  • OIDC sign-in behavior changed: superuser accounts are no longer provisioned automatically

Full Release Notes

SWIRL Community 4.5.0.7 — Security Patch
Fixes [#1941](https://github.com/swirlai/swirl-search/issues/1941):

* OIDC privilege escalation: sign-in no longer provisions superuser/staff accounts, and no longer sets a shared hardcoded password.
* Cross-user Microsoft token fallback: M365 token lookup is now strictly scoped to the requesting user; removed the fallback that could use another user's credentials.

No schema or dependency changes. Upgrade recommended for any deployment using OIDC sign-in or M365 connectors.