# ZITADEL: what changed from 3 to 4 - Product: ZITADEL (https://whatsnew.fyi/product/zitadel) - Vendor: ZITADEL - Range: changelog entries numbered after v3.4.15 up to and including v4.17.2, stable releases only - Entries below: 9 releases (newest first) - Resolved: 3 is v3.4.15 and 4 is v4.17.2, the newest stable release of each major we track - Carrying security changes: 3 · CVEs mentioned: 0 · Mentioning breaking changes: 0 · Removing or deprecating something: 0 - Page: https://whatsnew.fyi/product/zitadel/compare/3...4 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## What changed (72 changes, grouped by kind) ### Added #### v4.17.0 (2026-08-12) - Add API definition to update Zitadel IdP - Add API definition to add new Zitadel providers - Implement command layer for AddZitadelProvider - Add autovacuum tuning for events2 table in eventstore - Extend DeleteProvider to include Zitadel IdP - Extend start/retrieve idp intent for Zitadel provider - Add get/list Zitadel IdP functionality - Handle Zitadel provider IdP login via login v1 - Implement AddZitadelProvider in ManagementService - Implement instance-level UpdateZitadelProvider - Implement UpdateZitadelProvider in ManagementService #### v4.16.0 (2026-07-10) - Allow managing invite code in secret generators - FIPS 140-3 compliant build and runtime checks ### Changed #### v4.16.2 (2026-07-29) - speed up ListUsers login name equality filters ### Fixed #### v4.17.2 (2026-08-31) - Correct caching and relations of well-known app link files - Prevent cross-instance caching of well-known app link files - Support Zitadel Support IDP in console - Don't prepend base path to absolute IdP URL on login_hint redirect - Redirect unknown users to external IdP after domain discovery when enumeration protection is active - Resolve the registration org consistently with the login policy - Show account selection after RP-initiated logout - Allow OrgRoleIDScope downscoping in token exchange #### v4.17.1 (2026-08-14) - Block Login V2 auth for users in deactivated organizations - Enforce permission check when issuing passkey enrollment codes - Prevent the browser from requesting OTP codes via returnCode - Require MFA prompt step before 2FA enrollment #### v4.17.0 (2026-08-12) - Allow adding raw metadata values via appendMetadataRaw in actions - Allow invite codes for users whose auth methods were all removed - Accept SetSecuritySettings on /v2/settings/security API endpoint - Change username abort dialog and set email as verified in console - Skip CREATE USER when role exists to avoid password in Postgres logs - Honour login_hint and skip the auto-submit loop in OIDC flow - Provide hidden username on password set/change forms in login - Resolve unknownContext error on password page caused by inconsistent ignoreUnknownUsernames handling - Treat user-verified passkey as fulfilling MFA in session validity check #### v4.16.3 (2026-08-07) - Record route patterns instead of request paths on HTTP metrics #### v4.16.2 (2026-07-29) - improve random string generation - redirect to external IdP after domain discovery regardless of registration policy #### v4.16.1 (2026-07-17) - Display minimum length in password complexity message - Keep submit button disabled/loading during password set - Prevent crash on a stale session cookie #### v4.16.0 (2026-07-10) - Correct scope validation in token exchange - Correctly remove adjacent roles on user grants - Increase performance of ListUser by login name ignore case - Allow custom protocols for native apps again - Improve contrast of IDP processing message - Improve error handling for user registration - Migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color - Preserve org domain suffix through account chooser navigation - Prevent IDP auto-creation failure when name fields are missing - Redirect to loginname instead of empty accounts page when org scope filters all sessions - Use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow - Prevent double triggering of verification emails #### v4.15.3 (2026-06-22) - Add client and scope validation for token exchange - Ensure external user's email is verified before auto-linking - Center text for generic IDP buttons without icons in login - Guard defaultRedirectUri in OIDC/SAML FailedPrecondition paths #### v4.15.2 (2026-06-17) - Always validate exp and iat claims of JWT IdPs - Client_id verification during code exchange and refresh token flows - Connection handling in setup after migration steps 40, 64 and 70 - Allow overwriting resource owner of events in eventstore - Apply PKCE when building OAuth and OIDC providers - Manage and validate audience in JWT IdP - Accept IDP sessions on passkey registration in login - Load custom font from branding settings and allow in CSP in login - Remove unnecessary entry from default denylist - Use protected http client for outgoing connections ### Security #### v4.17.2 (2026-08-31) - Prevent TOTP reuse #### v4.16.2 (2026-07-29) - prevent external-IDP account pre-hijack in Login V1 - require authentication before WebAuthn/U2F and TOTP/OTP enrollment - use protected http client for org domain HTTP verification #### v4.16.1 (2026-07-17) - Prevent disk access via require in actions ## Release notes ### v4.17.2 - Date: 2026-08-31 - Version: v4.17.2 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.17.2 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.17.2 - **fixed** — Correct caching and relations of well-known app link files - **fixed** — Prevent cross-instance caching of well-known app link files - **fixed** — Support Zitadel Support IDP in console - **fixed** — Don't prepend base path to absolute IdP URL on login_hint redirect - **fixed** — Redirect unknown users to external IdP after domain discovery when enumeration protection is active - **fixed** — Resolve the registration org consistently with the login policy - **fixed** — Show account selection after RP-initiated logout - **fixed** — Allow OrgRoleIDScope downscoping in token exchange - **security** — Prevent TOTP reuse ##### [4.17.2](https://github.com/zitadel/zitadel/compare/v4.17.1...v4.17.2) (2026-08-31) ###### Bug Fixes * **api:** correct caching and relations of well-known app link files ([#12634](https://github.com/zitadel/zitadel/issues/12634)) ([21dbb2e](https://github.com/zitadel/zitadel/commit/21dbb2e8ca8614fbd1b4555401e16521e7e489ef)), closes [#12580](https://github.com/zitadel/zitadel/issues/12580) [#12497](https://github.com/zitadel/zitadel/issues/12497) * **api:** prevent cross-instance caching of well-known app link files ([#12644](https://github.com/zitadel/zitadel/issues/12644)) ([f0329f0](https://github.com/zitadel/zitadel/commit/f0329f0298f2d8e141f147b990034080a20d0d71)), closes [#12634](https://github.com/zitadel/zitadel/issues/12634) [#12634](https://github.com/zitadel/zitadel/issues/12634) [#12634](https://github.com/zitadel/zitadel/issues/12634) [#12497](https://github.com/zitadel/zitadel/issues/12497) * **console:** support Zitadel Support IDP ([#12619](https://github.com/zitadel/zitadel/issues/12619)) ([c543449](https://github.com/zitadel/zitadel/commit/c543449e0f7946f3abbec9fe91c32beeb6b93d30)), closes [#11825](https://github.com/zitadel/zitadel/issues/11825) [#5127](https://github.com/zitadel/zitadel/issues/5127) [#12018](https://github.com/zitadel/zitadel/issues/12018) [#12056](https://github.com/zitadel/zitadel/issues/12056) [#12371](https://github.com/zitadel/zitadel/issues/12371) [#12378](https://github.com/zitadel/zitadel/issues/12378) [#12384](https://github.com/zitadel/zitadel/issues/12384) [#12394](https://github.com/zitadel/zitadel/issues/12394) [#12396](https://github.com/zitadel/zitadel/issues/12396) [#12422](https://github.com/zitadel/zitadel/issues/12422) [#12469](https://github.com/zitadel/zitadel/issues/12469) [#12530](https://github.com/zitadel/zitadel/issues/12530) [#12568](https://github.com/zitadel/zitadel/issues/12568) * **login:** don't prepend base path to absolute IdP URL on login_hint redirect ([#12610](https://github.com/zitadel/zitadel/issues/12610)) ([c660049](https://github.com/zitadel/zitadel/commit/c660049de4cfa510cb2432c1c81944b8e42ebb60)), closes [#12431](https://github.com/zitadel/zitadel/issues/12431) * **login:** redirect unknown users to external IdP after domain discovery when enumeration protection is active ([#12581](https://github.com/zitadel/zitadel/issues/12581)) ([af3a9b2](https://github.com/zitadel/zitadel/commit/af3a9b2baef04369df11a4e440c4e565f06f4cf6)), closes [#12369](https://github.com/zitadel/zitadel/issues/12369) [#12369](https://github.com/zitadel/zitadel/issues/12369) * **login:** resolve the registration org consistently with the login policy ([#12621](https://github.com/zitadel/zitadel/issues/12621)) ([8fb897d](https://github.com/zitadel/zitadel/commit/8fb897d8c8cd96e6b10ca46829f072d70e099696)) * **login:** show account selection after RP-initiated logout ([#12638](https://github.com/zitadel/zitadel/issues/12638)) ([e5f526f](https://github.com/zitadel/zitadel/commit/e5f526fc8e3a440e3371e4802a6cba637690392e)), closes [#12471](https://github.com/zitadel/zitadel/issues/12471) [#12252](https://github.com/zitadel/zitadel/issues/12252) * **oidc:** allow OrgRoleIDScope downscoping in token exchange ([#12563](https://github.com/zitadel/zitadel/issues/12563)) ([60a2195](https://github.com/zitadel/zitadel/commit/60a2195f458c11f19b48792567ecde7b65c14880)), closes [#12312](https://github.com/zitadel/zitadel/issues/12312) [#12413](https://github.com/zitadel/zitadel/issues/12413) [#12312](https://github.com/zitadel/zitadel/issues/12312) [#11869](https://github.com/zitadel/zitadel/issues/11869) * **security:** prevent TOTP reuse ([#12616](https://github.com/zitadel/zitadel/issues/12616)) ([20cbfcf](https://github.com/zitadel/zitadel/commit/20cbfcf552b517f4e20cd8c7eea65d5ecd85fe05)), closes [/datatracker.ietf.org/doc/html/rfc6238#section-5](https://github.com//datatracker.ietf.org/doc/html/rfc6238/issues/section-5) ### v4.17.1 - Date: 2026-08-14 - Version: v4.17.1 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.17.1 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.17.1 - **fixed** — Block Login V2 auth for users in deactivated organizations - **fixed** — Enforce permission check when issuing passkey enrollment codes - **fixed** — Prevent the browser from requesting OTP codes via returnCode - **fixed** — Require MFA prompt step before 2FA enrollment ##### [4.17.1](https://github.com/zitadel/zitadel/compare/v4.17.0...v4.17.1) (2026-08-14) ###### Bug Fixes * block Login V2 auth for users in deactivated organizations ([a9311b8](https://github.com/zitadel/zitadel/commit/a9311b8c702531832575351a663e98a2242778e5)) * **command:** enforce permission check when issuing passkey enrollment codes ([76dd58e](https://github.com/zitadel/zitadel/commit/76dd58ecdf3b6fcb9fb321c9ba7d009fcfa345e5)) * **login:** prevent the browser from requesting OTP codes via returnCode ([5f75afb](https://github.com/zitadel/zitadel/commit/5f75afb98c75bf415df0c061563a39fb016f0e22)) * **login:** require MFA prompt step before 2FA enrollment ([db42371](https://github.com/zitadel/zitadel/commit/db4237161c7293d5410e8495765a9b4935bdd7af)) ### v4.17.0 - Date: 2026-08-12 - Version: v4.17.0 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.17.0 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.17.0 - **fixed** — Allow adding raw metadata values via appendMetadataRaw in actions - **fixed** — Allow invite codes for users whose auth methods were all removed - **fixed** — Accept SetSecuritySettings on /v2/settings/security API endpoint - **fixed** — Change username abort dialog and set email as verified in console - **fixed** — Skip CREATE USER when role exists to avoid password in Postgres logs - **fixed** — Honour login_hint and skip the auto-submit loop in OIDC flow - **fixed** — Provide hidden username on password set/change forms in login - **fixed** — Resolve unknownContext error on password page caused by inconsistent ignoreUnknownUsernames handling - **fixed** — Treat user-verified passkey as fulfilling MFA in session validity check - **added** — Add API definition to update Zitadel IdP - **added** — Add API definition to add new Zitadel providers - **added** — Implement command layer for AddZitadelProvider - **added** — Add autovacuum tuning for events2 table in eventstore - **added** — Extend DeleteProvider to include Zitadel IdP - **added** — Extend start/retrieve idp intent for Zitadel provider - **added** — Add get/list Zitadel IdP functionality - **added** — Handle Zitadel provider IdP login via login v1 - **added** — Implement AddZitadelProvider in ManagementService - **added** — Implement instance-level UpdateZitadelProvider - **added** — Implement UpdateZitadelProvider in ManagementService #### [4.17.0](https://github.com/zitadel/zitadel/compare/v4.16.3...v4.17.0) (2026-08-12) ###### Bug Fixes * **actions:** allow adding raw metadata values via appendMetadataRaw ([#12567](https://github.com/zitadel/zitadel/issues/12567)) ([c1b9885](https://github.com/zitadel/zitadel/commit/c1b9885de1baf899c923de86d77ff434bf21a724)), closes [#10666](https://github.com/zitadel/zitadel/issues/10666) [#5526](https://github.com/zitadel/zitadel/issues/5526) [#10470](https://github.com/zitadel/zitadel/issues/10470) [#5526](https://github.com/zitadel/zitadel/issues/5526) * allow invite codes for users whose auth methods were all removed ([#12453](https://github.com/zitadel/zitadel/issues/12453)) ([eb7af25](https://github.com/zitadel/zitadel/commit/eb7af256a42bff3e428f57b9fd221553709475db)) * **api:** accept SetSecuritySettings on /v2/settings/security ([#12518](https://github.com/zitadel/zitadel/issues/12518)) ([6e07fb7](https://github.com/zitadel/zitadel/commit/6e07fb756898fce72836b33d818d1f3c54098e4a)), closes [#12313](https://github.com/zitadel/zitadel/issues/12313) * **console:** change username abort dialog and set email as verified [#10803](https://github.com/zitadel/zitadel/issues/10803) [#12146](https://github.com/zitadel/zitadel/issues/12146) ([#12155](https://github.com/zitadel/zitadel/issues/12155)) ([8e2dc18](https://github.com/zitadel/zitadel/commit/8e2dc18136af0f8af848e64701ce59fc1b79fe44)) * **database:** skip CREATE USER when role exists to avoid password in Postgres logs ([#12538](https://github.com/zitadel/zitadel/issues/12538)) ([207f14a](https://github.com/zitadel/zitadel/commit/207f14abbb9f989bac603f0dbc8ce51c67b42c0a)), closes [#12178](https://github.com/zitadel/zitadel/issues/12178) * **login:** honour login_hint and skip the auto-submit loop in OIDC flow ([#12431](https://github.com/zitadel/zitadel/issues/12431)) ([3bb23d2](https://github.com/zitadel/zitadel/commit/3bb23d243516725954f0ffafe339795a3e709ccb)), closes [#12346](https://github.com/zitadel/zitadel/issues/12346) * **login:** provide hidden username on password set/change forms ([#12490](https://github.com/zitadel/zitadel/issues/12490)) ([e82b845](https://github.com/zitadel/zitadel/commit/e82b8455320db441c8cad069cec29f38a9f6133a)) * **login:** resolve unknownContext error on password page caused by inconsistent ignoreUnknownUsernames handling ([#12512](https://github.com/zitadel/zitadel/issues/12512)) ([65e50fc](https://github.com/zitadel/zitadel/commit/65e50fcf12b826a4817bf67e9869d9d18b947a11)) * **login:** treat user-verified passkey as fulfilling MFA in session validity check ([#12575](https://github.com/zitadel/zitadel/issues/12575)) ([4f3a1dd](https://github.com/zitadel/zitadel/commit/4f3a1dd032ba607262115dcd3ad4342cc720490a)) ###### Features * add api definition to update Zitadel IdP ([#12371](https://github.com/zitadel/zitadel/issues/12371)) ([8106304](https://github.com/zitadel/zitadel/commit/8106304a18fad1fc2e8e2039947280b8adebf596)) * API definition to add new Zitadel providers ([#12018](https://github.com/zitadel/zitadel/issues/12018)) ([9996463](https://github.com/zitadel/zitadel/commit/9996463c9f6fd9859e033e1013b55268923b5187)) * command layer implementation for AddZitadelProvider ([#12020](https://github.com/zitadel/zitadel/issues/12020)) ([a45ac66](https://github.com/zitadel/zitadel/commit/a45ac66cfb28b22cb88199c435d0ad4ed444b016)) * **eventstore:** autovacuum tuning for events2 table ([#12449](https://github.com/zitadel/zitadel/issues/12449)) ([0011448](https://github.com/zitadel/zitadel/commit/001144819d1d3e16fad93c699d068ca908d254ab)), closes [#12448](https://github.com/zitadel/zitadel/issues/12448) [#10754](https://github.com/zitadel/zitadel/issues/10754) [#10260](https://github.com/zitadel/zitadel/issues/10260) [#8585](https://github.com/zitadel/zitadel/issues/8585) [#9239](https://github.com/zitadel/zitadel/issues/9239) * extend DeleteProvider to include Zitadel IdP ([#12396](https://github.com/zitadel/zitadel/issues/12396)) _[Truncated at 4000 characters — full notes: https://github.com/zitadel/zitadel/releases/tag/v4.17.0]_ ### v4.16.3 - Date: 2026-08-07 - Version: v4.16.3 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.3 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.3 - **fixed** — Record route patterns instead of request paths on HTTP metrics ##### [4.16.3](https://github.com/zitadel/zitadel/compare/v4.16.2...v4.16.3) (2026-08-07) ###### Bug Fixes * **telemetry:** record route patterns instead of request paths on HTTP metrics ([#12557](https://github.com/zitadel/zitadel/issues/12557)) ([beffd5e](https://github.com/zitadel/zitadel/commit/beffd5e32e98a1518e5f6dc17acda93f7786cc1e)), closes [#9286](https://github.com/zitadel/zitadel/issues/9286) [#9523](https://github.com/zitadel/zitadel/issues/9523) [#11435](https://github.com/zitadel/zitadel/issues/11435) [#12315](https://github.com/zitadel/zitadel/issues/12315) [#12556](https://github.com/zitadel/zitadel/issues/12556) [#9286](https://github.com/zitadel/zitadel/issues/9286) [#9523](https://github.com/zitadel/zitadel/issues/9523) [#11435](https://github.com/zitadel/zitadel/issues/11435) ### v4.16.2 - Date: 2026-07-29 - Version: v4.16.2 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.2 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.2 - **fixed** — improve random string generation - **security** — prevent external-IDP account pre-hijack in Login V1 - **fixed** — redirect to external IdP after domain discovery regardless of registration policy - **security** — require authentication before WebAuthn/U2F and TOTP/OTP enrollment - **security** — use protected http client for org domain HTTP verification - **changed** — speed up ListUsers login name equality filters ##### [4.16.2](https://github.com/zitadel/zitadel/compare/v4.16.1...v4.16.2) (2026-07-29) ###### Bug Fixes * improve random string generation ([#12266](https://github.com/zitadel/zitadel/issues/12266)) ([34345ea](https://github.com/zitadel/zitadel/commit/34345ea8f6d98e7a7db58dac0ba106239caa8876)) * **login:** prevent external-IDP account pre-hijack in Login V1 ([917ade3](https://github.com/zitadel/zitadel/commit/917ade35af9c51e4b57ca8e57488ae95928182ad)) * **login:** redirect to external IdP after domain discovery regardless of registration policy ([#12369](https://github.com/zitadel/zitadel/issues/12369)) ([c4ba5a1](https://github.com/zitadel/zitadel/commit/c4ba5a1da5c56bac33b9f10e5e29fad39f0be05e)), closes [#12021](https://github.com/zitadel/zitadel/issues/12021) [#12023](https://github.com/zitadel/zitadel/issues/12023) * **login:** require authentication before WebAuthn/U2F and TOTP/OTP enrollment ([c20d613](https://github.com/zitadel/zitadel/commit/c20d6132965654bb761cd9009a5f013be2b5cf68)) * use protected http client for org domain HTTP verification ([35122e4](https://github.com/zitadel/zitadel/commit/35122e43974d542297018c57cc0fffb9db8a64ac)) ###### Performance Improvements * **query:** speed up ListUsers login name equality filters ([#12460](https://github.com/zitadel/zitadel/issues/12460)) ([b3b8da0](https://github.com/zitadel/zitadel/commit/b3b8da01b54fd1c698226cc261d7bca17dcd1478)) ### v4.16.1 - Date: 2026-07-17 - Version: v4.16.1 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.1 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.1 - **security** — Prevent disk access via require in actions - **fixed** — Display minimum length in password complexity message - **fixed** — Keep submit button disabled/loading during password set - **fixed** — Prevent crash on a stale session cookie ##### [4.16.1](https://github.com/zitadel/zitadel/compare/v4.16.0...v4.16.1) (2026-07-17) ###### Bug Fixes * **actions:** prevent disk access via require ([afe1086](https://github.com/zitadel/zitadel/commit/afe108640cf57a17e8b743fbcdad9ae636eb3eb7)) * **console:** display minimum length in password complexity message ([#12419](https://github.com/zitadel/zitadel/issues/12419)) ([cc3812a](https://github.com/zitadel/zitadel/commit/cc3812a940d629984802fd1246f84fd91d07f6e8)), closes [#12390](https://github.com/zitadel/zitadel/issues/12390) * **login:** keep submit button disabled/loading during password set r… ([#12429](https://github.com/zitadel/zitadel/issues/12429)) ([0a355f7](https://github.com/zitadel/zitadel/commit/0a355f77db2f6dafc4e2d1b3254775d3a2c4a627)), closes [#12416](https://github.com/zitadel/zitadel/issues/12416) * **login:** prevent crash on a stale session cookie ([#12423](https://github.com/zitadel/zitadel/issues/12423)) ([6030a43](https://github.com/zitadel/zitadel/commit/6030a4316aceff23f9730bf8ccd3d1fa2411b293)), closes [#11130](https://github.com/zitadel/zitadel/issues/11130) ### v4.16.0 - Date: 2026-07-10 - Version: v4.16.0 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.0 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.0 - **fixed** — Correct scope validation in token exchange - **fixed** — Correctly remove adjacent roles on user grants - **fixed** — Increase performance of ListUser by login name ignore case - **fixed** — Allow custom protocols for native apps again - **fixed** — Improve contrast of IDP processing message - **fixed** — Improve error handling for user registration - **fixed** — Migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color - **fixed** — Preserve org domain suffix through account chooser navigation - **fixed** — Prevent IDP auto-creation failure when name fields are missing - **fixed** — Redirect to loginname instead of empty accounts page when org scope filters all sessions - **fixed** — Use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow - **fixed** — Prevent double triggering of verification emails - **added** — Allow managing invite code in secret generators - **added** — FIPS 140-3 compliant build and runtime checks #### [4.16.0](https://github.com/zitadel/zitadel/compare/v4.15.3...v4.16.0) (2026-07-10) ###### Bug Fixes * correct scope validation in token exchange ([#12312](https://github.com/zitadel/zitadel/issues/12312)) ([02d07e9](https://github.com/zitadel/zitadel/commit/02d07e951b0b6ff8d5fa5e74b65209a8e9efddfe)), closes [#12319](https://github.com/zitadel/zitadel/issues/12319) [#12322](https://github.com/zitadel/zitadel/issues/12322) [#12319](https://github.com/zitadel/zitadel/issues/12319) [#12322](https://github.com/zitadel/zitadel/issues/12322) * Correctly remove adjacent roles on user grants ([dc89900](https://github.com/zitadel/zitadel/commit/dc899002ec77eb30c1c2ab6326dcccf6f522d419)) * increase performance of ListUser by login name ignore case ([#12350](https://github.com/zitadel/zitadel/issues/12350)) ([8fed358](https://github.com/zitadel/zitadel/commit/8fed3582c47f01724bb70cf199570188f24a692d)) * **login:** allow custom protocols for native apps again ([#12332](https://github.com/zitadel/zitadel/issues/12332)) ([5b3c10e](https://github.com/zitadel/zitadel/commit/5b3c10ecd7cf4730071eab3acbd05afd2d470405)) * **login:** improve contrast of IDP processing message ([#12309](https://github.com/zitadel/zitadel/issues/12309)) ([30ad9ab](https://github.com/zitadel/zitadel/commit/30ad9ab8a1afc8fb9af00fd653b96560ff1a1d3d)) * **login:** improve error handling for user registration ([#12338](https://github.com/zitadel/zitadel/issues/12338)) ([fa916e7](https://github.com/zitadel/zitadel/commit/fa916e7659695d0e101d3af9c2b9afb155de7909)) * **login:** migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color ([#12360](https://github.com/zitadel/zitadel/issues/12360)) ([70850db](https://github.com/zitadel/zitadel/commit/70850db9d53ebdc96cdab40f6c04c654bbd2da78)) * **login:** preserve org domain suffix through account chooser navigation ([#12304](https://github.com/zitadel/zitadel/issues/12304)) ([3311fb9](https://github.com/zitadel/zitadel/commit/3311fb9ccdbcd232a59da148791bc906c04314c6)), closes [#12024](https://github.com/zitadel/zitadel/issues/12024) * **login:** Prevent IDP auto-creation failure when name fields are missing ([#11070](https://github.com/zitadel/zitadel/issues/11070)) ([ab2e099](https://github.com/zitadel/zitadel/commit/ab2e099514ff63ff39c3c36755301d461d237dd3)) * **login:** redirect to loginname instead of empty accounts page when org scope filters all sessions ([#12346](https://github.com/zitadel/zitadel/issues/12346)) ([f21f95c](https://github.com/zitadel/zitadel/commit/f21f95ce37699c5ed48618ccfa0839dfb09ee954)), closes [#11914](https://github.com/zitadel/zitadel/issues/11914) * **login:** use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow ([#12376](https://github.com/zitadel/zitadel/issues/12376)) ([57eb145](https://github.com/zitadel/zitadel/commit/57eb1453f26db3efdfcce26f294ad0436363e9db)), closes [#11946](https://github.com/zitadel/zitadel/issues/11946) [#11946](https://github.com/zitadel/zitadel/issues/11946) * prevent double triggering of verification emails ([#11995](https://github.com/zitadel/zitadel/issues/11995)) ([9ae9bf3](https://github.com/zitadel/zitadel/commit/9ae9bf3bc8bc55b9f47d72c48e51584fc935b814)) ###### Features * allow managing invite code in secret generators ([#12109](https://github.com/zitadel/zitadel/issues/12109)) ([915586a](https://github.com/zitadel/zitadel/commit/915586a40f1174014b116a2a653e4933468a2465)) * **crypto:** FIPS 140-3 compliant build and runtime checks ([#12233](https://github.com/zitadel/zitadel/issues/12233)) ([c03d9f4](https://github.com/zitadel/zitadel/commit/c03d9f4c6ecbd4af39e5c4dbd876244f3740e13a)) ### v4.15.3 - Date: 2026-06-22 - Version: v4.15.3 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.15.3 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.15.3 - **fixed** — Add client and scope validation for token exchange - **fixed** — Ensure external user's email is verified before auto-linking - **fixed** — Center text for generic IDP buttons without icons in login - **fixed** — Guard defaultRedirectUri in OIDC/SAML FailedPrecondition paths ##### [4.15.3](https://github.com/zitadel/zitadel/compare/v4.15.2...v4.15.3) (2026-06-22) ###### Bug Fixes * added client and scope validation for token exchange ([e2886a6](https://github.com/zitadel/zitadel/commit/e2886a61670ca8fd41c9434f87036546e5620bcc)) * ensure external user's email is verified before auto-linking ([c97012f](https://github.com/zitadel/zitadel/commit/c97012f0c5dc2fe960ae6e940cbea23229f0557f)) * **login:** center text for generic IDP buttons without icons ([#12211](https://github.com/zitadel/zitadel/issues/12211)) ([aadc664](https://github.com/zitadel/zitadel/commit/aadc664a206ebdf6bfd85145e9c6fcdc165a6cee)), closes [#12182](https://github.com/zitadel/zitadel/issues/12182) * **login:** guard defaultRedirectUri in OIDC/SAML FailedPrecondition paths ([0382659](https://github.com/zitadel/zitadel/commit/038265925a3b05ac1df8aad461ab071983e9eb85)) ### v4.15.2 - Date: 2026-06-17 - Version: v4.15.2 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.15.2 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.15.2 - **fixed** — Always validate exp and iat claims of JWT IdPs - **fixed** — Client_id verification during code exchange and refresh token flows - **fixed** — Connection handling in setup after migration steps 40, 64 and 70 - **fixed** — Allow overwriting resource owner of events in eventstore - **fixed** — Apply PKCE when building OAuth and OIDC providers - **fixed** — Manage and validate audience in JWT IdP - **fixed** — Accept IDP sessions on passkey registration in login - **fixed** — Load custom font from branding settings and allow in CSP in login - **fixed** — Remove unnecessary entry from default denylist - **fixed** — Use protected http client for outgoing connections ##### [4.15.2](https://github.com/zitadel/zitadel/compare/v4.15.1...v4.15.2) (2026-06-17) ###### Bug Fixes * always validate exp and iat claims of JWT IdPs ([4925fab](https://github.com/zitadel/zitadel/commit/4925fab849d39a88674485d937b79e54318b48a8)) * client_id verification during code exchange and refresh token flows ([5624030](https://github.com/zitadel/zitadel/commit/562403079a98cf2059cdac11865a45e2f285be71)) * connection handling in setup after migration steps 40, 64 and 70 ([#12293](https://github.com/zitadel/zitadel/issues/12293)) ([c53d977](https://github.com/zitadel/zitadel/commit/c53d9774d4272d3cebeee4131012c20bd77b9dfb)) * **eventstore:** allow overwriting resource owner of events ([#12261](https://github.com/zitadel/zitadel/issues/12261)) ([a939b84](https://github.com/zitadel/zitadel/commit/a939b847d90c3370bd162064e57764b89c01be46)) * **idp:** apply PKCE when building OAuth and OIDC providers ([#12247](https://github.com/zitadel/zitadel/issues/12247)) ([ab7c6c0](https://github.com/zitadel/zitadel/commit/ab7c6c09d3bb34ac3ec18fc9e0c72d810a614263)), closes [#12036](https://github.com/zitadel/zitadel/issues/12036) [#12054](https://github.com/zitadel/zitadel/issues/12054) * **jwt idp:** manage and validate audience ([999e2bb](https://github.com/zitadel/zitadel/commit/999e2bbc81b56fca693ccc87a863fdfc182b1316)) * **login:** accept IDP sessions on passkey registration ([#12275](https://github.com/zitadel/zitadel/issues/12275)) ([add46e0](https://github.com/zitadel/zitadel/commit/add46e0c8be3dbf014f77f4ca264f832e4ee49b0)) * **login:** load custom font from branding settings and allow in CSP ([#12279](https://github.com/zitadel/zitadel/issues/12279)) ([9f1561d](https://github.com/zitadel/zitadel/commit/9f1561dc8e56419bba816f5f003e96c606c9f5b1)), closes [#11200](https://github.com/zitadel/zitadel/issues/11200) * remove unnecessary entry from default denylist ([#12294](https://github.com/zitadel/zitadel/issues/12294)) ([1ca1fbd](https://github.com/zitadel/zitadel/commit/1ca1fbdab4aea43aac76e66abeda3dd3238afc84)) * use protected http client for outgoing connections ([b6f7808](https://github.com/zitadel/zitadel/commit/b6f78086913b8d916bce9ab2e049ab0d84f947fd))