Skip to content

v0.4.0

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 16:17
· 1 commit to main since this release

Released commit: 2371d7a143dbd9f44185d08152c1ddb4fe334ab8

Added

  • core/resource: WithResourceMetadataURL(string) option and Resource.ResourceMetadataURL() accessor point the resource_metadata challenge parameter at an AS-hosted RFC 9728 document; the http, mcp and mark3labs adapters advertise it via Options.ResourceMetadataURL.
  • core/resource: AuthErrorResponseWithMetadata(err, resourceMetadataURL, realm...) emits the RFC 9728 §5.1 resource_metadata parameter that the http adapter used to append itself; the header is byte-identical.
  • core/authplane: ErrAccessDenied and ErrInvalidTarget sentinels for the token-endpoint errors access_denied (403, cross-client exchange not allowlisted on the target Resource) and invalid_target (400, RFC 8707 §2.2); match with errors.Is.
  • core/authplane: the auto-wired introspection checker warns once per resource when the AS answers active: false for a locally valid token, pointing at the runtime-client requirement (authserver ≥ 0.1.2).
  • core/resource/verifier: the fail-open revocation branch logs a log/slog warning carrying the checker error instead of accepting the token silently.
  • http, mcp, mark3labs: every 401 WWW-Authenticate challenge now carries scope="…" listing the resource's configured scopes (RFC 6750 §3; MCP authorization spec SHOULD), omitted when none are configured. 403 challenges are unchanged.
  • core/resource: AuthErrorResponseVerbose(err error, realm ...string) — AuthErrorResponse with the error's own message restored in the JSON error_description. A development aid: it discloses SDK-internal detail to unauthenticated callers, so do not use it in production.

Fixed

  • core/resource: a resource URI rejected at construction no longer appears unredacted in the error when it carries credentials; errors.As(err, new(*url.Error)) keeps working.
  • core/internal/cache: an unknown kid no longer costs one JWKS fetch per verification; forced refreshes have a retry floor of min(jwksCacheTTL, 1m). Impact: a newly rotated kid can be rejected until that floor elapses.
  • core/internal/cache: a server expiry at or before caching time no longer leaves the document permanently expired, and a server expiry longer than the configured interval is clamped to it.
  • core/resource: the JSON error body for a request with no credentials no longer says invalid_request; like the challenge, it now omits error.

Changed

  • core/authplane: access_denied and invalid_target no longer count toward the circuit breaker — both are policy answers about the request, not an AS outage.
  • BREAKING core/resource: AuthErrorResponse emits a fixed error_description per error code instead of the error's message; RequireScopes no longer lists missing scopes in the body. Migration: the net/http adapter logs the diagnostic at DEBUG; log err yourself elsewhere, or use AuthErrorResponseVerbose in development.
  • BREAKING core/resource: resource.New rejects a resource URI with a literal space in the path, a " in the host, userinfo, or a query that is not valid RFC 3986. Migration: percent-encode the offending octets and remove credentials.
  • BREAKING core/resource: PRMURL() now keeps the resource identifier's query in the derived PRM URL (RFC 9728 §3); WellKnownPRMPath() is unchanged. Migration: update any hard-coded expectation of the query-less URL.

Deprecated

  • core/resource/verifier: (*VerifiedClaims).MayAct() — authserver 0.2.0 no longer issues may_act; removed in the next minor. Parsing is unchanged until then.