This release fixes organization access checks and two-factor authentication for OAuth logins.

Fixes

  • Fixed repository creation accepting SSH keys from another organization. Key ownership is now checked when adding a repository and before Git uses the key. (#182)
  • Fixed forbidden organization pages including private package and repository search data. Search results are now limited to organization members. (#183)
  • Fixed GitHub and GitLab logins skipping local two-factor authentication. Users with two-factor enabled now complete the existing authenticator or recovery-code challenge before signing in. (#184)