Skip to content

v0.43.0

Choose a tag to compare

@osanderson osanderson released this 02 Oct 08:59
Immutable release. Only release title and notes can be modified.
269882d

0.43.0 (2026-10-02)

⚠ BREAKING CHANGES

  • a client that sends authorization_details must now be registered with every type it requests in storage.RegisteredClientConfig.AuthorizationDetailsTypes (or, for clients registered automatically through OpenID Federation, server.Config.AutomaticRegistration.AuthorizationDetailsTypes), or the request is refused with invalid_authorization_details. An empty list allows no type. See UPGRADING.md for v0.43.0.
  • client: custom storage.SessionStore implementations must persist NewSession.Record and return it as ConsumedSession.Record, in place of the Nonce, PKCEVerifier, ExpectedIssuer, ExpectedRedirectURI and ExpectedResponseMode fields, which are removed. A client requesting max_age now refuses an ID token without auth_time, or one older than max_age allows. See UPGRADING.md for v0.43.0.

Features

  • client: bind the session handle to the browser in an encrypted cookie (6259639)
  • client: check auth_time against max_age, with an opaque session record (33d1a03)
  • client: seal token sets with a TokenSetSealer bound to their owner (6686ba5)
  • extension: read the authorization details a token was granted (fcaf31d)
  • register the RAR types each client may request (e2db87d)
  • resource,serverresource: DPoP-Nonce and UserInfo response helpers (b85f443)
  • resource: build a VerifyRequest from an http.Request (3d0574b)
  • server: carry an interaction in one encrypted cookie (142c0b3)
  • server: catch client RAR types Config.RAR doesn't register (9299dde)
  • server: read the authorization endpoint's request strictly (6ccec35)
  • server: say when an interaction expires, and expire its cookie then (5d8794b)

Bug Fixes

  • client: refuse a max_age over 100 years when the flow begins (687e4b4)
  • extension: refuse RAR members that differ only in case (252d5eb)
  • extension: refuse RAR members that differ only in case at any depth (99cad87)
  • resource: refuse a request with more than one Authorization header (17dc93b)
  • server: answer an unreadable form body as invalid_request (ee2f80a)