- Added support for the 'auth0-forwarded-for' header in server-side resource-owner password flows.
- Brute-force detection now uses this header to avoid false blocking of legitimate requests.
- Improves security and reliability of password flow authentication.