diff --git a/.changeset/enroll-a-passkey-while-signed-in.md b/.changeset/enroll-a-passkey-while-signed-in.md deleted file mode 100644 index 955f46e..0000000 --- a/.changeset/enroll-a-passkey-while-signed-in.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -'@seamless-auth/react': minor ---- - -Add a passkey while signed in, and say what a 401 at enrollment means. - -`registerPasskey` is now on `useAuth()` and on the framework-agnostic session actions, -not only on the client. The bundled UI already told users they could "add a passkey later -from a device that does", and nothing in the package implemented that: `credentials` could -be listed and deleted but never added. The context version refreshes the session -afterwards, so a settings screen renders the new passkey without a reload. - -Enrollment now requires a signed-in session, which is a coordinated change with -`seamless-auth-api` and the server adapters. Upgrade all three together: the auth API and -the adapter have no safe release order between them, and enrollment answers `401` until -both land. The signup flow already satisfies it, because -verifying the email OTP issues a session before the passkey screen is reached, so nothing -in the bundled views moves. An application that called `registerPasskey()` before -verifying an address has to move that call after it. - -A 401 from enrollment now reads "Your session expired before the passkey was saved" rather -than the generic "Error registering passkey." It is the session rather than anything about -the authenticator, and the generic wording invited the user to retry with the same expired -one. `isUnauthenticated(error)` is exported for callers rendering their own screens. - -Corrects a stale README example that still passed a `token` to `registerPasskey`, a field -removed when the wire contract moved to `@seamless-auth/types`. diff --git a/CHANGELOG.md b/CHANGELOG.md index 762761a..8606864 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,33 @@ # @seamless-auth/react +## 0.12.0 + +### Minor Changes + +- f59be34: Add a passkey while signed in, and say what a 401 at enrollment means. + + `registerPasskey` is now on `useAuth()` and on the framework-agnostic session actions, + not only on the client. The bundled UI already told users they could "add a passkey later + from a device that does", and nothing in the package implemented that: `credentials` could + be listed and deleted but never added. The context version refreshes the session + afterwards, so a settings screen renders the new passkey without a reload. + + Enrollment now requires a signed-in session, which is a coordinated change with + `seamless-auth-api` and the server adapters. Upgrade all three together: the auth API and + the adapter have no safe release order between them, and enrollment answers `401` until + both land. The signup flow already satisfies it, because + verifying the email OTP issues a session before the passkey screen is reached, so nothing + in the bundled views moves. An application that called `registerPasskey()` before + verifying an address has to move that call after it. + + A 401 from enrollment now reads "Your session expired before the passkey was saved" rather + than the generic "Error registering passkey." It is the session rather than anything about + the authenticator, and the generic wording invited the user to retry with the same expired + one. `isUnauthenticated(error)` is exported for callers rendering their own screens. + + Corrects a stale README example that still passed a `token` to `registerPasskey`, a field + removed when the wire contract moved to `@seamless-auth/types`. + ## 0.11.0 ### Minor Changes diff --git a/package.json b/package.json index 0ca4eb8..90797fc 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@seamless-auth/react", - "version": "0.11.0", + "version": "0.12.0", "description": "A drop-in authentication solution for modern React applications.", "type": "module", "exports": {