v1.4.0
This release implements certificate-based authentication as an alternative to using a static client secret. This authentication method works by creating and using a signed, short-lived JWT assertion to authenticate the client to the OpenID provider.
The benefits of this authentication method are:
- The clients private key is never shared with anyone. The OpenID provider only needs to known the corresponding public certificate to validate the clients JWT assertions.
- A signed JWT is only valid for 30 seconds and cannot be replayed, thus greatly reducing the risks of token theft or secrets being compromised.
For more information on how to use certificate-based authentication, see the README.md
Added
- Support for client assertion authentication method (
007bf54)