Fire Arrow Server 1.14.0
· 7 min read
Fire Arrow Server 1.14.0 has been released.
- (breaking) The web UI now signs in through a server-side confidential OAuth client; every login profile must be given a client secret and have its identity provider redirect URI updated before upgrading, or the server will not start
- (feature) A new
$drop-privilegeoperation lets a privileged caller mint a short-lived token scoped down to a single identity, never granting more access than the caller already has