> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What's changed in v19.2.0

> Bug fixes hardening the static auth template cache, covering environment-variable leaks, legacy session auth, and query parameter handling, plus a dangling-timer fix in the logger

*Released: 2026-10-06*

This release fixes eleven issues in the static auth template system introduced in recent core versions, plus a dangling-timer fix in the logger. Several of the auth template fixes close security gaps where environment variable values could end up baked into a cached template. Others fix legacy session auth, middleware-derived query parameters, and how auth field placeholders are built from a connection's actual auth shape.

## cli

* \[fix] Pass declared environment variable names from `invoke` to auth template rendering, so the `zapier-platform invoke auth template` command gets the same env-var protection as production ([#1340](https://github.com/zapier/zapier-platform/pull/1340))

## core

* \[fix] Decline auth templates built from an empty legacy auth mapping, which previously dumped the whole credential set into the request ([#1330](https://github.com/zapier/zapier-platform/pull/1330))
* \[fix] Resolve undeclared environment variables to `undefined` during auth template capture, matching production behavior ([#1331](https://github.com/zapier/zapier-platform/pull/1331))
* \[fix] Fix auth template capture and rendering for query parameters that middleware computes in `beforeRequest` ([#1335](https://github.com/zapier/zapier-platform/pull/1335))
* \[fix] Build auth template placeholders from only the fields a connection actually populated, so a multi-credential app no longer serves one connection's credential branch to another ([#1338](https://github.com/zapier/zapier-platform/pull/1338))
* \[fix] Keep declared environment variable values out of the static auth template cache ([#1340](https://github.com/zapier/zapier-platform/pull/1340))
* \[fix] Apply the legacy pre method when rendering session auth templates ([#1342](https://github.com/zapier/zapier-platform/pull/1342))
* \[fix] Gate the auth template fallback on a diff against the target request instead of on emptiness ([#1343](https://github.com/zapier/zapier-platform/pull/1343))
* \[fix] Add missing legacy-scripting globals to the auth-template loader, including `require`, `crypto`, and `atob`/`btoa` ([#1344](https://github.com/zapier/zapier-platform/pull/1344))
* \[fix] Keep the `user-agent` header in the static auth template ([#1345](https://github.com/zapier/zapier-platform/pull/1345))
* \[fix] Only flag credential-derived query parameters as stripped, so templates with constant parameters are not unnecessarily demoted ([#1346](https://github.com/zapier/zapier-platform/pull/1346))
* \[fix] Release the logger's abort timer as soon as the log server responds, instead of leaving a dangling timer that keeps a Lambda invocation alive ([#1349](https://github.com/zapier/zapier-platform/pull/1349))

## schema

None!
