Skip to content

Releases: nuxt-modules/hanko

v2.0.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 12:53
Immutable release. Only release title and notes can be modified.
82d8cd3

v2.0.0 is the next major release, mostly because @teamhanko/hanko-elements moves from v1 to v3. It also adds Nuxt 5 support and an opt-in global middleware.

👀 Highlights

🎉 Nuxt 5 support

The module now works on both Nuxt 4 and Nuxt 5 (#511). Server code is resolved per major version: on Nuxt 5 it imports from nuxt/server and registers the context middleware with an explicit /** route, as Nitro v3 requires. On Nuxt 4 the existing h3 based path is unchanged.

🔒 Global middleware

globalMiddleware makes every page require a logged in user by default (#163, thanks to @felixdolderer!):

export default defineNuxtConfig({
  hanko: {
    globalMiddleware: true,
  },
})

Pages opt out through page meta, with either allow or deny:

definePageMeta({
  hanko: {
    allow: 'all', // or 'logged-in' | 'logged-out'
    // deny: 'logged-in' | 'logged-out'
  },
})

Middleware is assigned at build time, so a page that already sets hanko-logged-in or hanko-logged-out in middleware keeps it and its hanko page meta is ignored. It applies to pages only; it adds no checks to your API routes.

It is off by default, so existing apps are unaffected.

🚨 Breaking changes

@teamhanko/hanko-elements v3

The module dependency is now ^3.0.0 (#355, thanks to @Harm-Nullix). hanko-elements v3 uses the newer flow-based Hanko API, so make sure to upgrade any self-hosted deployment before updating the module. (You do not need to do this if you are on Hanko Cloud.)

useHanko() returns a different Hanko shape

The instance is still a Hanko from @teamhanko/hanko-elements, but its methods have moved from sub-clients onto the top-level class:

  const hanko = useHanko()
- await hanko!.user.getCurrent()
+ await hanko!.getCurrentUser()

- await hanko!.user.logout()
+ await hanko!.logout()

Session helpers moved too: hanko.validateSession() and hanko.getSessionToken() replace the hanko.session.* calls. The user, session, webauthn, email, thirdParty, config, token and enterprise sub-clients are no longer public API.

The built-in hanko-logged-in and hanko-logged-out middleware are already updated, so if you only use those there is nothing to do.

onSessionCreated payload changed

The event detail is now { claims, expirationSeconds } rather than { jwt, userID, expirationSeconds }:

- hanko.onSessionCreated(({ userID }) => { /* ... */ })
+ hanko.onSessionCreated(({ claims }) => { /* claims.subject */ })

useHanko() is memoised per Nuxt app

useHanko() used to construct a new Hanko on every call, so each call site started its own session-validation polling. It now creates the instance once per Nuxt app and reuses it. On the server it still returns null, and nothing is cached across requests.

👉 Changelog

compare changes

🚀 Enhancements

  • add globalMiddleware option to guard all pages by default (#163)
  • support nuxt v5 + add tests (#511)
  • ⚠️ deps: update @teamhanko/hanko-elements to v3 (#355)

🩹 Fixes

  • type <hanko-login>, <hanko-registration> + <hank-auth> props (4676f64)

🏡 Chore

🤖 CI

  • run on merge groups (a6afe17)
  • use pnpm/setup and devEngines (#503)
  • add explicit permissions (445734e)
  • migrate agentscan-action to v2 (2a4632c)
  • add agent-scan workflow to flag bot-authored PRs (5e16eb1)

🎉 New Contributors

❤️ Contributors

v1.0.1

Choose a tag to compare

@github-actions github-actions released this 08 Jun 21:17
c60ff39

v1.0.1 is the next patch release.

👉 Changelog

compare changes

🩹 Fixes

  • pass storageKey to runtimeConfig (9f306a5)

📖 Documentation

  • add nuxt.care health badge (1ffd208)

🏡 Chore

  • migrate to pnpm v11 (#425)
  • migrate resolutions to pnpm-workspace.yaml (5bbb5b1)
  • migrate npm badges and links to npmx.dev (60e1aab)
  • revert pnpm trust policy and restore provenance action (808a1a0)
  • update pnpm to 10.21 and enable trust policy (e666c9e)
  • lint (f102ebc)
  • prefer nuxt over nuxi (#259)

🤖 CI

  • migrate release workflow to uppt (#444)
  • pin github actions to full-length commit shas (3ea02d7)
  • add provenance action to check for downgrades in provenance (bc556e7)
  • run tests on last node LTS (9aa6d4b)
  • remove forced corepack installation (0603de4)

❤️ Contributors

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 21 Feb 15:03
ec8499c

   🚨 Breaking Changes

   🚀 Features

   🐞 Bug Fixes

  • Replace onAuthFlowCompleted with onSessionCreated  -  by felix-dolderer in #169 (3b310)
    View changes on GitHub

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 26 Jun 10:56
d63c72f

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 11 Apr 08:31
257f148

   🐞 Bug Fixes

    View changes on GitHub

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 14 Nov 11:48
93942ef

No significant changes

    View changes on GitHub

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 08 Aug 09:53

   🚀 Features

  • Add support for custom 'cookieName'  -  by @McPizza0 in #47 (0ae91)
    View changes on GitHub

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 18 Jun 21:15

No significant changes

    View changes on GitHub

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 13 Jun 18:34

   🐞 Bug Fixes

  • Add missing return for logged-out middleware  -  by @McPizza0 in #9 (d4f0b)
    View changes on GitHub

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 07 Jun 14:00

   🚀 Features

  • Support followRedirect and (in future) custom cookieName  -  by @McPizza0 in #6 (1f48e)
    View changes on GitHub