This repository was archived by the owner on Sep 2, 2025. It is now read-only.
Repository navigation
Releases: formancehq/oidc
Releases · formancehq/oidc
Release list
v3.0.0
3.0.0 (2024-01-11)
Bug Fixes
- build callback url from server, not op (#468) (e5f0dca)
- client/rs: do not error when issuer discovery has no introspection endpoint (#414) (406153a)
- crypto: nil pointer dereference in crypto.BytesToPrivateKey (#491) (#493) (3a4d44c)
- don't error on invalid i18n tags in discovery (#407) (d01a5c8), closes #406 #406
- enforce device authorization grant type (#400) (a4dbe2a)
- exampleop: pass the issuer interceptor to login (#430) (ce85a8b)
- examples: Offer Storage with non-global client (#489) (7d0cdec)
- Implement dedicated error for RevokeToken (#508) (e23b1d4)
- modify ACRValues parameter type to space separated strings (#388) (e43ac6d)
- oidc: ignore unknown language tag in userinfo unmarshal (#505) (dce79a7)
- Only set GrantType once (#353) (#367) (312c2a0), closes #352
- op: check if getTokenIDAndClaims succeeded (#429) (4ed2699)
- op: export NewProvider to allow customized issuer (#479) (d88c0ac)
- op: omit empty state from code flow redirect (#428) (37b5de0), closes #415 #415
- op: return state in token response only for implicit flow (#460) (0dc2a6e)
- op: terminate session from request in legacy server (#465) (164c5b2)
- server: do not get client by id for introspection (#467) (73a1982)
chore
-
replace gorilla/mux with go-chi/chi (#332) (57fb9f7), closes #301
-
Merge pull request zitadel#456 from zitadel/next-main (976b406), closes #456
Features
- add CanTerminateSessionFromRequest interface (#418) (be89c3b)
- add context to all client calls (#345) (6af94fd), closes #309
- add slog logging (#432) (0879c88)
- add typ:JWT header to tokens (#435) (5ade1cd)
- Allow CORS policy to be configured (#484) (7b64687)
- Allow modifying request to device authorization endpoint (#356) (c778e83), closes #354
- delete PKCE cookie after code exchange (#419) (45582b6)
- generic Userinfo and Introspect functions (#389) (d5a9bd6)
- issuer from Forwarded header (#443) (364a759)
- merge the verifier types (#336) (33c716d)
- op: add opentelemetry to token endpoint (#436) (1683b31)
- op: allow double star globs (#507) (c37ca25)
- op: allow Legacy Server extension (#466) (bab5399)
- op: create a JWT profile with a keyset (f7a0f7c)
- op: ID token for device authorization grant (#500) (b300027)
- op: issuer from custom headers (#478) (7475023)
- op: JWT profile verifier with keyset (a8ef8de)
- op: PKCE Verification in Legacy Server when AuthMethod is not NONE and CodeVerifier is not Empty (#496) (9d12d1d)
- op: Server interface (#447) (0f8a058)
- op: User-configurable claims_supported (#495) (7bdaf9c)
- rp: Add UnauthorizedHandler (#503) (984e31a)
- rp: client credentials grant (#494) (fe3e02b), closes /datatracker.ietf.org/doc/html/rfc6749#section-4
- rp: return oidc.Tokens on token refresh (#423) (6708ef4), closes #364
BREAKING CHANGES
-
- Just making sure v3 release is triggered.
- rp: - rename RefreshAccessToken to RefreshToken
- RefreshToken returns *oidc.Tokens instead of *oauth2.Token
This change allows the return of the id_token in an explicit manner,
as part of the oidc.Tokens struct.
The return type is now consistent with the CodeExchange function.
When an id_token is returned, it is verified.
In case no id_token was received,
RefreshTokens will not return an error.
As per specifictation:
https://openid.net/specs/openid-connect-core-1_0.html#RefreshTokenResponse
Upon successful validation of the Refresh Token,
the response body is the Token Response of Section 3.1.3.3
except that it might not contain an id_token.
- rp.Userinfo and rs.Introspect now require
a type parameter. -
- The various verifier types are merged into a oi...
v1.0.0
1.0.0 (2023-05-25)
Bug Fixes
- add authorization to cors (#48) (d02653e)
- add authorizations to userinfo (#37) (2966355)
- add code_challenge_methods_supported to discovery endpoint (#43) (57cf8ee)
- Add db scanner methods for SpaceDelimitedArray (#194) (5fb36bf)
- add missing WithCustomEndSessionEndpoint (5af734d)
- add missing WithCustomKeysEndpoint (c3e583b)
- allow additional scopes (#69) (2370409)
- allow http schema for redirect url for native apps in dev mode (#242) (a314c14)
- allow loopback redirect_uri for native apps (72fc861)
- allow RFC3339 encoded time strings (711a194), closes #292
- allowed ConcatenateJSON with empty input (#138) (c45f03e)
- another typo (4cf6c6d)
- append client id to aud (#71) (13b1473)
- aud (a731a46)
- avoid potential race conditions (#220) (c4b7ef9)
- change callbackpath (#74) (27f3bc0)
- change channel for GetSigningKey to time (a2e2f06)
- Change op.tokenHandler to follow the same pattern as the rest of the endpoint handlers (#210) (2d248b1)
- check grant types and add refresh token to discovery (14faebb)
- check refresh token grant type (#100) (3e336a4)
- cli client (#92) (5cd7bae)
- cli: added implementation for token to client for caching (#29) (303fdfc)
- clock skew when using jwt profile (b23f37f)
- code challenge (c316986)
- correct returned field for JWTTokenRequest (a08ce50), closes #283
- create access token from storage (5e7e5eb)
- custom absolute endpoints (660519a)
- decode basic auth header components (clientID, clientSecret) (deb3365)
- dependencies (5b6175a)
- do not modify userInfo when marshaling (e1d50fa)
- Ease dev host name constraints (8661300)
- encoding of basic auth header values (d7d7daa)
- end session (#35) (628bc4e)
- ensure signer has key on OP creation (e39146c)
- exchange cors library and add
X-Requested-Withto Access-Control-Request-Headers (#260) (b031c1f) - explicit allow Origin from request (c88e6b4)
- glob support for RedirectURIs (7e57985), closes #293
- grant_types_supported in discovery (2ebbd7a)
- handle code separately (#30) (58545a1)
- handle keys without
usein FindMatchingKey (bcd9ec8) - handle single
audstring claim, extract en/decoder interface, comments (#51) (abd3b6f) - handle the zero cases for oidc.Time (115813e)
- implement storage (7700cb3)
- improve error handling when getting ClientIDFromRequest (#359) (dc2bdc6)
- improve example & fix userinfo marshal (#132) (ff2c164)
- improve interceptor handling (#49) (c828290)
- improve JWS and key verification (#128) (a63fbee)
- jwt profile request in op (fd3daa2)
- make checkKey public (7e2c22f)
- make GenerateJWTProfileToken public (#82) (fa92a20)
- make pkce code_verifier spec compliant #125 (fcad98f)
- make pkce code_verifier spec compliant #125 (af3a497), closes /datatracker.ietf.org/doc/html/rfc7636#section-4
- marshal user info address (#58) (60560ce)
- merge user info claims into id token claims (#349) (be3cc13)
- move to new org (#177) (550f787)
- nil pointer dereference on UserInfoAddress (#207) (fa222c5), closes #203 #203
- Only set GrantType once (#353) (1a2db36), closes #352
- parse error (cae42cc)
- parse max_age and prompt correctly (and change scope type) (...