Announcing FusionAuth 1.63 - The Proof Pangolin
Blog post from FusionAuth
FusionAuth 1.63.0, dubbed the Proof Pangolin release, introduces several new features and improvements, focusing on enhanced security and user experience. Key updates include the implementation of Demonstrating Proof-of-Possession (DPoP) to bind access and refresh tokens to a client key pair, improving protection against token theft and replay attacks. DPoP is particularly useful for securing APIs, handling multi-domain scenarios, and as an alternative to Mutual TLS (mTLS) in environments where mTLS is challenging to implement. This release also enhances the Multi-Factor Authentication (MFA) Lambda with the addition of the AuthenticationType parameter, allowing for more targeted MFA challenges. Improvements to the Setup Wizard and Admin UI were informed by feedback from the Developer Success team, aiming to streamline the setup process. Additionally, numerous bugs and visual issues were addressed, further refining the user interface and functionality.