Repository navigation
v0.52.0
Immutable
release. Only release title and notes can be modified.
0.52.0 (2026-10-09)
⚠ BREAKING CHANGES
- server: under production assurance with attestation-based client authentication, server.New refuses an X5CAttesterChain whose TrustAnchors or Anchors source does not implement keys.KeySourceAssurance declaring LiveFetchHardened. StaticAttesterTrustAnchors and StaticAttesterAnchors already do. See UPGRADING.md for v0.52.0.
- keys: keys.NewKeyManagerFromSigners takes a []keys.SignerSpec and options instead of separate signer, algorithm and kid maps. See UPGRADING.md for v0.52.0.
- client: BackchannelAuthenticationSession's MarshalText and UnmarshalText and client.ParseBackchannelAuthenticationSession are removed in favour of client.BackchannelSessionSealer, and sessions stored by earlier versions don't open. RefreshTokens refuses a TokenSet from another issuer and one recording no issuer without a matching ID token, and TokenSetSealer.Seal refuses a set from another issuer. client.New refuses an unacceptable Config.RedirectURI. client.ErrorAuthorizationDenied is removed. See UPGRADING.md for v0.52.0.
- extension: extension.Definition's Sensitive bool is replaced by a Sensitivity field (NotSensitive or Sensitive), and NewRegistry refuses a definition that leaves it unset. See UPGRADING.md for v0.52.0.
- server.Config.HorizontallyScaled and resource.Config.HorizontallyScaled are replaced by a Deployment field (DeploymentSingleInstance or DeploymentHorizontallyScaled), and under AssuranceProduction server.New and resource.NewVerifier refuse a configuration that leaves it unset. See UPGRADING.md for v0.52.0.
- server: server.New refuses an extension returning a grant_type or code_grant_id claim in tokens, and resource.Verifier refuses a token whose grant_type claim is anything other than client_credentials. A resource server serving both end-user and client credentials tokens should authorize by AuthorizationContext.SubjectKind as well as Subject. See UPGRADING.md for v0.52.0.
- federation: federation.Resolver.VerifyTrustMark takes the subject's ResolvedEntity, as Resolve returned it, in place of its Entity Identifier, and refuses a Trust Mark whose issuer can't be trusted through the subject's own Trust Anchor. See UPGRADING.md for v0.52.0.
- server: a request whose claims parameter asks for the ID token's acr as an Essential Claim with values now fails when the application completes it at another class: login_required for the redirect flow, access_denied at the CIBA poll. Authenticate at one of InteractionRequest.EssentialACRValues, or complete with AuthenticationFailed. A malformed id_token acr entry is refused as invalid_request. See UPGRADING.md for v0.52.0.
Features
- extension: require each extension definition to declare its Sensitivity (9de5ead)
- fapihttp: RecommendedTransportConfig and RecommendedConfig (c7354fd)
- keys: build signer key managers from one SignerSpec per purpose (42ead83)
- replace HorizontallyScaled with a required Deployment (f4fefc0)
- server: Metadata.WriteJSON (792ccd6)
- storage: contract suites for the revocation store and client repository (aa95069)
Bug Fixes
- bump Go toolchain to 1.26.9 for GO-2026-6617 (6bec8b9)
- client: keep ResourceClient.Do off the caller's request (31134b5)
- client: seal stored CIBA sessions, bind token sets to their issuer, check the redirect URI at New (26552a0)
- conformance: require a bearer token for the trust-anchor admin endpoint (c740cfb)
- extension: refuse repeated and miscased members in extension values (5cb6eaa)
- federation: bound the automatic registration cache (f4f344f)
- federation: judge a Trust Mark by its subject's Trust Anchor (5f16450)
- federation: require an ASCII host in an Entity Identifier (01d437d)
- report every production assurance refusal at once (778e6ce)
- resolve every signing key at New, not at first use (ac294b7)
- resource: refuse a resolved access token with no revocation key (3aba5e2)
- revoke everything issued from a reused code, and mark client credentials tokens (4c3d1d3)
- server: audit an unverified client_id at the authorization endpoint as no client (8e0396b)
- server: enforce an essential acr request (#609) (35a44b4)
- server: honour dpop_jkt in a CIBA backchannel authentication request (ac5429f)
- server: re-check the client's registration at the code exchange (a4c0407)
- server: refuse a malformed claims parameter instead of ignoring it (9c0b330)
- server: require a hardened attester trust-anchor source in production (ac08345)
- server: require the CIBA identity hint to be a non-empty string (93e4045)
- server: reserve the grant_type and code_grant_id token claims (52dd7e4)
- server: scope replay records to the client or DPoP key that used them (5f4d047)
- server: send an application's reason as error_description only when it's error text (bd81630)