Version 1.4.0
Changes
- Added nonce support to createAuthUrl and the token exchange, and exposed the nonce claim on Token
- Added
dest_app_name,dest_app_id,display_username,max_ageandpromptparameters via a new AuthUrlOptions builder - Replaced certificate pinning with a bundled trust store that performs full certificate chain validation
- Reduced the outgoing JWT expiration from 1 hour to 5 minutes to match the other Duo SDKs
- Added the CA bundle version and pinning status to the user agent string
- Added a KEYS file and README instructions for verifying signed release artifacts
- Upgraded the example app to Spring Boot 3.x, which requires Java 17; the SDK still supports Java 8