Main changes¶
- New dependency: IO::Socket::Timeout
- TOTP check tolerates forward AND backward clock drift (totp2fRange)
- Avoid assignment in expressions option is disabled by default
- RHEL/CentOS SELinux users should install the new lemonldap-ng-selinux package to fix an issue with the new default cache directory
- If you use Mattermost Team Edition with OpenID Connect, you need to set the id claim type to Integer
- BruteForceProtection plugin now prevents authentication on backend if an account is locked
- In the Manager API, postLogoutRedirectUri is now returned and consumed as an array
- We fixed a bug that caused SAML sessions to be created and never deleted, you should check your session databases for sessions that have "_session_kind": "ISAML" but no _utime. You can safely delete SAML sessions with no _utime during the upgrade.
