v0.39.4
liriliri/ayav0.39.4Jun 14, 2026by github-actions[bot]
AI Summary
PocketBase release that removes a required validator for OAuth2 redirect URLs and enables sorting by implicit relation fields.
Key Highlights
- Removed redirectURL required validator from code-to-token exchange endpoint
- Enabled sorting by the first implicit presentable relation field
- Fixed minor UI issues like tooltip clearing and sortable elements
- Updated goja and related golang.org/x dependencies
Breaking Changes
- Removed redirectURL required validator from the authWithOAuth2Code() endpoint
New Features
- Implicit relation field sorting
- Dependency updates
Full Release Notes
> _To update the prebuilt executable you can run `./pocketbase update`._
- Removed `redirectURL` required validator from the code->token exchange endpoint (aka. `authWithOAuth2Code()`) ([#7734](https://github.com/pocketbase/pocketbase/issues/7734)).
_Note that OAuth2 providers have their own validations and whether it is allowed to be empty or not could depend on the configured OAuth2 app (in most cases it is required and the redirect address must match with the initial value submitted with the authorization request)._
- Enabled sorting by the first _implicit_ presentable relation field ([#7735](https://github.com/pocketbase/pocketbase/discussions/7735)).
- Other minor UI fixes (tooltip clear on hovered element removal, optional before element sortable fix, etc.).
- Updated goja and the related `golang.org/x/*` dependencies (regex support improvements).