Download Latest Version v3.10.0 source code.zip (56.2 MB) Google Add to Preferred Sources
Home / v3.9.0
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-23 3.9 kB
v3.9.0 source code.tar.gz 2026-09-23 132.6 MB
v3.9.0 source code.zip 2026-09-23 134.1 MB
Totals: 3 Items   266.8 MB 0

Loomio 3.9.0 adds passkey sign-in and improves security by preventing account enumeration.

  • New: Sign in with a passkey without entering an email address, and manage passkeys from your profile
  • Fix: Prevent account enumeration through ordinary sign-in, sign-in code requests, and account-merge verification
  • Fix: Block deactivated sessions, enforce password attempt limits, and protect pending SSO identity links
  • Fix: Show moved poll comments immediately when opening their destination discussion

Sign in with a passkey

You can now sign in to Loomio with a passkey. A passkey is a secure credential saved on your device or in your password manager. You unlock it with your device's usual method, such as a fingerprint, face scan, or PIN; Loomio verifies it without receiving the credential itself. A passkey works only for Loomio's site address, which helps protect against phishing. You can sign in quickly without remembering a password or waiting for an emailed code, making it Loomio's easiest and most secure sign-in method.

If your device supports passkeys and you sign in with a password or emailed code, Loomio offers to add one if you do not already have one. You can skip the offer and add a passkey later from your profile, where you can also name and remove passkeys. On your next visit, select Use a passkey and unlock it to sign in without entering an email address, password, or code. Password and emailed-code sign-in remain available. Changing passkeys requires a recent sign-in.

The sign-in screen now separates passkey, emailed-code, password, and identity-provider choices. Account merging has its own action on the profile page. New accounts complete any missing name or terms acceptance after email, invitation, or SSO verification and before an application session is created. Previously active accounts with no recorded terms acceptance can continue signing in; operators can set LOOMIO_ENFORCE_TERMS_FOR_EXISTING_USERS when they are ready to require confirmation from them.

Private sign-in and SSO-only sites

Ordinary sign-in and account-merge requests no longer reveal whether an entered email address belongs to an account. Sign-in code requests show the same browser confirmation for known and unknown addresses. Operators who intentionally want to tell people that an account is unknown or deactivated during code requests can set FEATURES_REVEAL_EMAIL_ACCOUNT_STATUS; this permits account discovery through that workflow.

Set FEATURES_DISABLE_LOCAL_LOGIN=1 only after configuring and testing an identity provider. This removes Loomio-managed passwords, emailed codes, passkeys, and native account creation from an SSO-only site, including their server endpoints. FEATURES_DISABLE_EMAIL_LOGIN remains a compatibility alias.

Session and identity protections

Deactivated accounts can no longer continue using an existing browser session. Password sign-in enforces the configured failed-attempt limit, and emailed-code requests from the web app are subject to per-email rate limits. A pending SSO sign-in cannot reassign an identity already linked to another account. Invitation bearer tokens are reserved for redeemable guest invitations; existing group members use ordinary sign-in to vote.

Sessions from Loomio's previous authentication system are no longer accepted, so people still using one of those sessions will need to sign in again. Current sessions are unaffected.

Upgrade

This release adds database tables and columns for passkeys, one-time authentication challenges, account completion proofs, and Solid Queue batches. Follow the maintained Upgrading Loomio guide to run migrations and restart application and worker processes. No new server secret is required for passkeys.

Full changelog: https://github.com/loomio/loomio/compare/v3.8.2...v3.9.0

Source: README.md, updated 2026-09-23