next-auth@4.24.14
blakeblackshear/frigatenext-auth@4.24.14Apr 14, 2026by gustavovalverde
AI Summary
Fixes the GitHub OAuth provider by adding the issuer parameter to comply with RFC 9207, resolving authentication failures for applications that did not configure a custom issuer.
Key Highlights
- GitHub provider issuer compliance (RFC 9207)
- Resolves authentication failures for apps missing issuer configuration
- Sets default issuer to https://github.com/login/oauth
Full Release Notes
## Bugfixes - **providers**: add issuer to GitHub provider for [RFC 9207](https://datatracker.ietf.org/doc/html/rfc9207) compliance (#13412) GitHub now returns an `iss` parameter in OAuth callbacks. `openid-client` validates it unconditionally, which was breaking authentication for apps that didn't configure an issuer. This sets the default GitHub provider issuer to `https://github.com/login/oauth`.