Skip to content
This repository was archived by the owner on Sep 2, 2025. It is now read-only.

Releases: formancehq/oidc

Release list

v3.0.0

Choose a tag to compare

@github-actions github-actions released this 11 Jan 16:07
984e31a

3.0.0 (2024-01-11)

Bug Fixes

  • build callback url from server, not op (#468) (e5f0dca)
  • client/rs: do not error when issuer discovery has no introspection endpoint (#414) (406153a)
  • crypto: nil pointer dereference in crypto.BytesToPrivateKey (#491) (#493) (3a4d44c)
  • don't error on invalid i18n tags in discovery (#407) (d01a5c8), closes #406 #406
  • enforce device authorization grant type (#400) (a4dbe2a)
  • exampleop: pass the issuer interceptor to login (#430) (ce85a8b)
  • examples: Offer Storage with non-global client (#489) (7d0cdec)
  • Implement dedicated error for RevokeToken (#508) (e23b1d4)
  • modify ACRValues parameter type to space separated strings (#388) (e43ac6d)
  • oidc: ignore unknown language tag in userinfo unmarshal (#505) (dce79a7)
  • Only set GrantType once (#353) (#367) (312c2a0), closes #352
  • op: check if getTokenIDAndClaims succeeded (#429) (4ed2699)
  • op: export NewProvider to allow customized issuer (#479) (d88c0ac)
  • op: omit empty state from code flow redirect (#428) (37b5de0), closes #415 #415
  • op: return state in token response only for implicit flow (#460) (0dc2a6e)
  • op: terminate session from request in legacy server (#465) (164c5b2)
  • server: do not get client by id for introspection (#467) (73a1982)

chore

Features

BREAKING CHANGES

    • Just making sure v3 release is triggered.
  • rp: - rename RefreshAccessToken to RefreshToken
  • RefreshToken returns *oidc.Tokens instead of *oauth2.Token

This change allows the return of the id_token in an explicit manner,
as part of the oidc.Tokens struct.
The return type is now consistent with the CodeExchange function.

When an id_token is returned, it is verified.
In case no id_token was received,
RefreshTokens will not return an error.

As per specifictation:
https://openid.net/specs/openid-connect-core-1_0.html#RefreshTokenResponse

Upon successful validation of the Refresh Token,
the response body is the Token Response of Section 3.1.3.3
except that it might not contain an id_token.

  • rp.Userinfo and rs.Introspect now require
    a type parameter.
    • The various verifier types are merged into a oi...
Read more

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 25 May 15:24
eb10752

1.0.0 (2023-05-25)

Bug Fixes

  • add authorization to cors (#48) (d02653e)
  • add authorizations to userinfo (#37) (2966355)
  • add code_challenge_methods_supported to discovery endpoint (#43) (57cf8ee)
  • Add db scanner methods for SpaceDelimitedArray (#194) (5fb36bf)
  • add missing WithCustomEndSessionEndpoint (5af734d)
  • add missing WithCustomKeysEndpoint (c3e583b)
  • allow additional scopes (#69) (2370409)
  • allow http schema for redirect url for native apps in dev mode (#242) (a314c14)
  • allow loopback redirect_uri for native apps (72fc861)
  • allow RFC3339 encoded time strings (711a194), closes #292
  • allowed ConcatenateJSON with empty input (#138) (c45f03e)
  • another typo (4cf6c6d)
  • append client id to aud (#71) (13b1473)
  • aud (a731a46)
  • avoid potential race conditions (#220) (c4b7ef9)
  • change callbackpath (#74) (27f3bc0)
  • change channel for GetSigningKey to time (a2e2f06)
  • Change op.tokenHandler to follow the same pattern as the rest of the endpoint handlers (#210) (2d248b1)
  • check grant types and add refresh token to discovery (14faebb)
  • check refresh token grant type (#100) (3e336a4)
  • cli client (#92) (5cd7bae)
  • cli: added implementation for token to client for caching (#29) (303fdfc)
  • clock skew when using jwt profile (b23f37f)
  • code challenge (c316986)
  • correct returned field for JWTTokenRequest (a08ce50), closes #283
  • create access token from storage (5e7e5eb)
  • custom absolute endpoints (660519a)
  • decode basic auth header components (clientID, clientSecret) (deb3365)
  • dependencies (5b6175a)
  • do not modify userInfo when marshaling (e1d50fa)
  • Ease dev host name constraints (8661300)
  • encoding of basic auth header values (d7d7daa)
  • end session (#35) (628bc4e)
  • ensure signer has key on OP creation (e39146c)
  • exchange cors library and add X-Requested-With to Access-Control-Request-Headers (#260) (b031c1f)
  • explicit allow Origin from request (c88e6b4)
  • glob support for RedirectURIs (7e57985), closes #293
  • grant_types_supported in discovery (2ebbd7a)
  • handle code separately (#30) (58545a1)
  • handle keys without use in FindMatchingKey (bcd9ec8)
  • handle single aud string claim, extract en/decoder interface, comments (#51) (abd3b6f)
  • handle the zero cases for oidc.Time (115813e)
  • implement storage (7700cb3)
  • improve error handling when getting ClientIDFromRequest (#359) (dc2bdc6)
  • improve example & fix userinfo marshal (#132) (ff2c164)
  • improve interceptor handling (#49) (c828290)
  • improve JWS and key verification (#128) (a63fbee)
  • jwt profile request in op (fd3daa2)
  • make checkKey public (7e2c22f)
  • make GenerateJWTProfileToken public (#82) (fa92a20)
  • make pkce code_verifier spec compliant #125 (fcad98f)
  • make pkce code_verifier spec compliant #125 (af3a497), closes /datatracker.ietf.org/doc/html/rfc7636#section-4
  • marshal user info address (#58) (60560ce)
  • merge user info claims into id token claims (#349) (be3cc13)
  • move to new org (#177) (550f787)
  • nil pointer dereference on UserInfoAddress (#207) (fa222c5), closes #203 #203
  • Only set GrantType once (#353) (1a2db36), closes #352
  • parse error (cae42cc)
  • parse max_age and prompt correctly (and change scope type) (...
Read more