Skip to content

Releases: NrgXnat/openid-auth-plugin

1.6.0

Choose a tag to compare

@kelseym kelseym released this 22 Sep 18:51

Built against XNAT 1.10.1, Java 21.

New

  • Optional claim-validation gates for token authorization — audience (aud) and role — opt-in, and configurable once per provider or scoped to a single path.
  • Opt-in bearer-token authentication for REST requests carrying Authorization: Bearer <jwt>. Tokens are fully validated: RSA signature against the provider's JWKS, plus iss and exp. Note the aud gate is on by default on this path — set openid.<providerId>.audCheck.acceptedAudiences or every bearer token is rejected with 403 (fail-closed).
  • Opt-in account linking (linkExisting.enabled) — on a mapping miss, attach the identity to the XNAT account another provider's mapping already names. linkExisting.sourceProvider is required; linking never creates accounts and grants nothing.
  • Opt-in auto-login (autoLogin) via OIDC prompt=none, plus unified logout (logoutUri), which is meaningful only alongside autoLogin. Only one provider may enable auto-login.
  • usernamePattern can now name a claim by URI, e.g. [https://example.org/upn] — for providers that namespace custom claims, Auth0 among them.

Fixed

  • Account creation now refuses when a provider's usernamePattern resolves to a login an XNAT account already holds and no mapping links the two. Previously the sign-in appeared to succeed while silently modifying the unrelated account. This changes behaviour for existing deployments with a colliding usernamePattern and forceUserCreate on: those logins used to go through and now fail, with the collision named in the log. Configure linkExisting.sourceProvider to attach deliberately, or change the pattern so it stops colliding.

Full notes: CHANGELOG.md

Install: copy openid-auth-plugin-1.6.0-xpl.jar (the xpl classifier bundles the plugin's dependencies) into your XNAT plugins folder and restart.

1.5.0

Choose a tag to compare

@willhorton-xw willhorton-xw released this 02 Jun 19:10
Update to version 1.5.0 and parent version 1.10.0

1.4.1

Choose a tag to compare

@willhorton-xw willhorton-xw released this 02 Jun 19:10
Update to version 1.4.1

1.4.0

Choose a tag to compare

@willhorton-xw willhorton-xw released this 02 Jun 19:10
Update to version 1.4.0 and parent version 1.9.2

1.3.1

Choose a tag to compare

@willhorton-xw willhorton-xw released this 02 Jun 19:10
Update to version 1.3.1

1.3.0

Choose a tag to compare

@willhorton-xw willhorton-xw released this 02 Jun 19:09
Update to version 1.3.0 and parent version 1.8.7