Skip to content

Releases: duosecurity/duo_universal_java

Version 1.4.0

Choose a tag to compare

@mihir-pradhan mihir-pradhan released this 16 Sep 18:27
b84eb79

Version 1.4.0

Changes

  • Added nonce support to createAuthUrl and the token exchange, and exposed the nonce claim on Token
  • Added dest_app_name, dest_app_id, display_username, max_age and prompt parameters via a new AuthUrlOptions builder
  • Replaced certificate pinning with a bundled trust store that performs full certificate chain validation
  • Reduced the outgoing JWT expiration from 1 hour to 5 minutes to match the other Duo SDKs
  • Added the CA bundle version and pinning status to the user agent string
  • Added a KEYS file and README instructions for verifying signed release artifacts
  • Upgraded the example app to Spring Boot 3.x, which requires Java 17; the SDK still supports Java 8

Version 1.3.2

Choose a tag to compare

@mihir-pradhan mihir-pradhan released this 13 Jul 15:12
3b159b6

Version 1.3.2

Changes

  • Added amr (Authentication Methods Reference) claim to the Token model
  • Added a builder option to disable CA certificate pinning
  • Configured OkHttp connection pool with 55s keep-alive to improve connection reuse

Version 1.3.1

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 01 May 18:46
3024c46

Version 1.3.1

Changes

  • Fix a problem with the certificate pinning

Version 1.3.0

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 30 Apr 19:17
036076a

Version 1.3.0

Changes

  • Adds support for new Duo certificate authorities

Version 1.2.0

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 14 Oct 15:15
1ccc698

Version 1.2.0

Changes

  • Adds support for an HTTP proxy
  • Includes more detail in the DuoException when the token exchange fails
  • Generates an SBOM during the build process
  • Removes Lombok as a dependency
  • Updates various dependency versions to address multiple CVEs
  • Removes various unnecessary dependencies

Version 1.1.3

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 27 Aug 18:00

Updated dependency versions wherever feasible

Version 1.1.2

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 27 Jul 15:12

Bug Fixes

  • Fixed a potential NullPointerException when the token response from Duo is in a bad state

Version 1.1.1

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 15 Mar 20:24

Bug Fixes

  • Fixed issues with Javadocs that prevented publishing to Maven

Version 1.1.0

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 15 Mar 19:46

Features

  • Enabled toggling of whether the client will use code or duo_code for the OIDC authorization code parameter name

Other Changes

  • Introduced Builder for Client class for flexibility
  • Updated dependencies
  • Updated documentation links

duo_universal_java version 1.0.3

Choose a tag to compare

@AaronAtDuo AaronAtDuo released this 10 Nov 21:51
v1.0.3

Version 1.0.3