## goauthentik/authentik — version/2026.8.0-rc6…version/2026.8.0-rc7

_48 commits._

### Features
- **providers/oauth2: add token exchange targeting (cherry-pick #24874 to version-2026.8) (#24955)** (dd0cee6)
- **website/docs: Get notified about new releases (cherry-pick #24885 to version-2026.8) (#24941)** (6ec8c63)
- **root: add optional pyroscope for profiling (cherry-pick #24887 to version-2026.8) (#24945)** (6cc3533)
- **website/docs: welcome email notification rule: Add LDAP exception (cherry-pick #24672 to version-2026.8) (#24681)** (c33ff01)
- **blueprints Add `EQ` and `NEQ` modes to the `!Condition` tag (cherry-pick #20315 to version-2026.8) (#24842)** (d4ad0fe)
- **website/docs: add gitguardian to 2026.8 release notes (#24830)** (1bb842b)
- **blueprints: handle invalid yaml, add dry run to apply_blueprint (cherry-pick #24813 to version-2026.8) (#24821)** (6813942)
- **enterprise/agents: add (cherry-pick #24598 to version-2026.8) (#24790)** (c3b0a5c)
- **website/docs: recpatcha: add mention of google enterprise (cherry-pick #24658 to version-2026.8) (#24769)** (a91594a)
- **source/oauth: add cas source integration (cherry-pick #24737 to version-2026.8) (#24768)** (5e193bb)
- **website/docs: release notes: add ws-fed info (cherry-pick #24659 to version-2026.8) (#24661)** (48af3df)
- **website/docs: Add feedback from previous agent pr (cherry-pick #24713 to version-2026.8) (#24735)** (93491be)

### Fixes
- **providers/scim: fix display of SCIMRequestException (2026.8) (#24833)** (e99a7e2)
- **providers/oauth2: fix client_credentials regression (cherry-pick #24900 to version-2026.8) (#24901)** (a1d716b)
- **web/flows: fix missing required flag on password input (cherry-pick #24831 to version-2026.8) (#24837)** (ae3fe54)
- **web: fix file search input interactions (cherry-pick #24609 to version-2026.8) (#24811)** (c373d24)
- **enterprise/agents: fix enterprise required check for agents (cherry-pick #24814 to version-2026.8) (#24825)** (bf1588a)
- **providers/oauth2: fix missing authorization event for oauth provider, add tests (cherry-pick #24819 to version-2026.8) (#24822)** (da32dc9)
- **website/docs: fix link in .8 release notes (cherry-pick #24757 to version-2026.8) (#24758)** (568fd39)
- **web/admin: fix alignment of task list filters (cherry-pick #24752 to version-2026.8) (#24754)** (552f240)
- **blueprints: fix mismatched stage name in example 2fa login flow (cherry-pick #24668 to version-2026.8) (#24750)** (9d1e939)
- **website/docs: fix broken link in 2026.11 release notes draft (cherry-pick #24746 to version-2026.8) (#24747)** (eff98b3)

### Backend
- **release: 2026.8.0-rc7** (1697d68)
- **core: return the intended status code from error views for all request methods (cherry-pick #24902 to version-2026.8) (#24958)** (5b4b46d)
- **providers/oauth2: automatically invalidate ProviderInfoView cached claims (cherry-pick #24944 to version-2026.8) (#24960)** (c55cdeb)
- **enterprise/requests: integrate agents with requests (cherry-pick #24844 to version-2026.8) (#24952)** (10825e8)
- **providers/oauth2: move DCR to OSS (cherry-pick #24949 to version-2026.8) (#24953)** (a4d0996)
- **rbac: use constant-time comparison in SecretKeyFilter (cherry-pick #24888 to version-2026.8) (#24948)** (9706c35)
- **enterprise/endpoints/connectors/fleet: decrease page size (cherry-pick #24908 to version-2026.8) (#24911)** (3e18b58)
- **providers/oauth2: cache ProviderInfoView get_claims (cherry-pick #24890 to version-2026.8) (#24914)** (71a139e)
- **providers/oauth2: refactor token parsing logic (cherry-pick #24904 to version-2026.8) (#24906)** (3bed95d)
- **lib/evaluator: use lazy proxy for http session (cherry-pick #24893 to version-2026.8) (#24909)** (2bc2f8b)
- **providers/oauth2: optimize JWKS conversion (cherry-pick #24889 to version-2026.8) (#24907)** (a6e7e87)
- **website/docs: release: sync integrations (#24876)** (ccb3390)
- **blueprints: run initial migration before flows are created (cherry-pick #24880 to version-2026.8) (#24883)** (0cc091e)
- **root: pin pnpm 11.20.0 everywhere (cherry-pick #24789 to version-2026.8) (#24854)** (e3ddcb9)
- **website/docs: cleanup 07-12: polish endpoint device guidance (cherry-pick #23968 to version-2026.8) (#24629)** (1e98260)
- **web: contain long text in tables and application cards (cherry-pick #24621 to version-2026.8) (#24689)** (dded059)
- **server: avoid looping indefinitely on embedded outpost start (take 2) (cherry-pick #24824 to version-2026.8) (#24827)** (e882ff2)
- **core: bump django from 5.2.16 to v5.2.17 (cherry-pick #24793 to version-2026.8) (#24816)** (916c471)
- **web/admin: drop misleading delete consequences from user activation review (cherry-pick #24273 to version-2026.8) (#24787)** (91cd4d3)
- **core: delete expired actor tokens (cherry-pick #24767 to version-2026.8) (#24783)** (8fa87c5)
- **web/common: allow line-break in dom-purify (cherry-pick #24755 to version-2026.8) (#24784)** (62a556d)
- **web/components: update styling for user account switcher (cherry-pick #24749 to version-2026.8) (#24753)** (0ce1e77)
- **providers/oauth2: token exchange delegation (cherry-pick #24356 to version-2026.8) (#24745)** (9462fa2)
- **enterprise/requests: only show requests tab when usable (cherry-pick #24705 to version-2026.8) (#24743)** (b383287)
- **website/docs: document API scope and domain join required by the authentik Agent (cherry-pick #24599 to version-2026.8) (#24715)** (6053ae9)
- **core: Actors (cherry-pick #24353 to version-2026.8) (#24709)** (84fbadc)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/goauthentik/authentik?utm_source=github-action)._