v0.43.0
Immutable
release. Only release title and notes can be modified.
0.43.0 (2026-10-02)
⚠ BREAKING CHANGES
- a client that sends authorization_details must now be registered with every type it requests in storage.RegisteredClientConfig.AuthorizationDetailsTypes (or, for clients registered automatically through OpenID Federation, server.Config.AutomaticRegistration.AuthorizationDetailsTypes), or the request is refused with invalid_authorization_details. An empty list allows no type. See UPGRADING.md for v0.43.0.
- client: custom storage.SessionStore implementations must persist NewSession.Record and return it as ConsumedSession.Record, in place of the Nonce, PKCEVerifier, ExpectedIssuer, ExpectedRedirectURI and ExpectedResponseMode fields, which are removed. A client requesting max_age now refuses an ID token without auth_time, or one older than max_age allows. See UPGRADING.md for v0.43.0.
Features
- client: bind the session handle to the browser in an encrypted cookie (6259639)
- client: check auth_time against max_age, with an opaque session record (33d1a03)
- client: seal token sets with a TokenSetSealer bound to their owner (6686ba5)
- extension: read the authorization details a token was granted (fcaf31d)
- register the RAR types each client may request (e2db87d)
- resource,serverresource: DPoP-Nonce and UserInfo response helpers (b85f443)
- resource: build a VerifyRequest from an http.Request (3d0574b)
- server: carry an interaction in one encrypted cookie (142c0b3)
- server: catch client RAR types Config.RAR doesn't register (9299dde)
- server: read the authorization endpoint's request strictly (6ccec35)
- server: say when an interaction expires, and expire its cookie then (5d8794b)
Bug Fixes
- client: refuse a max_age over 100 years when the flow begins (687e4b4)
- extension: refuse RAR members that differ only in case (252d5eb)
- extension: refuse RAR members that differ only in case at any depth (99cad87)
- resource: refuse a request with more than one Authorization header (17dc93b)
- server: answer an unreadable form body as invalid_request (ee2f80a)