Skip to content

v0.4.0

Choose a tag to compare

@camcima camcima released this 24 May 18:03
· 70 commits to main since this release
b52a9fd

Added

  • /userinfo endpoint (GET/POST), advertised via userinfo_endpoint in discovery, plus claims_supported.
  • First-class profile fields mapping to standard OIDC claims: givenName, familyName, locale, hostedDomain, emailVerified; avatar now also surfaces as the picture claim.
  • ID-token claims azp, at_hash, and auth_time (stable across refresh).
  • examples/google.config.json and a README "Emulating Google" section.

Changed (BREAKING)

  • Identity claims (name, email, given_name, …) are now scope-gated (profile/email) and emitted in the ID token and /userinfo only — they are no longer in the access token. Custom profile.claims are unaffected and remain in every token.
    • Migration: read identity claims from the ID token or /userinfo, and make sure your app requests the profile/email scopes.

Changed

  • Refreshed in-range dependencies (lockfile only).