We rebuilt rate limiting from the ground up. If you've ever hit a limit and wondered what just happened — or worse, gotten locked out because someone else was hammering the API — this one's for you.
Sign-in rate limits now tell you what went wrong. Hit the limit and you'll see exactly how long to wait before trying again. If your whole org got throttled, the error names the org so you know who to yell at. We also split the budget: one limit per account+IP pair, and a separate per-IP limit that's 10x higher. Translation: one person mashing refresh can't lock out your entire office.
SAML and OAuth have their own rate limits now. Authentication flows no longer compete with regular API traffic for budget. If you're using SSO, you won't get throttled because someone's running a bulk import script.
Change order and component pages use a consistent layout. Cleaned up some visual inconsistencies. You won't notice unless you were bothered by the old spacing.
Change order templates no longer include validation rules. We were shipping default validations with templates, which made no sense — you define your own rules anyway. Templates are lighter now.