Skip to content

Novolis.Security 2026.1.1

Latest

Choose a tag to compare

@frankhaugen frankhaugen released this 30 Sep 01:57
· 19 commits to main since this release

Ship the first-party Authentication, OAuth, and Authorization stack.

  • Authentication is separate from OAuth: global IdentityId, isolated credential vault, no password grant.
  • OAuth is Authorization Code + mandatory S256 PKCE, client credentials, rotating refresh tokens, ES384 JWTs, and RFC 8414 discovery.
  • Authorization is tenant-scoped RBAC with groups, roles, composite roles, and default deny.
  • Packable surfaces: Novolis.Security.Authentication.*, Novolis.Security.OAuth.*, Novolis.Security.Authorization.*.

GitHub Packages: 2026.1.* from merge.yml. nuget.org versions use this release line plus the release workflow run number.