Skip to content
This repository was archived by the owner on Sep 2, 2025. It is now read-only.

v3.0.0

Latest

Choose a tag to compare

@github-actions github-actions released this 11 Jan 16:07
984e31a

3.0.0 (2024-01-11)

Bug Fixes

  • build callback url from server, not op (#468) (e5f0dca)
  • client/rs: do not error when issuer discovery has no introspection endpoint (#414) (406153a)
  • crypto: nil pointer dereference in crypto.BytesToPrivateKey (#491) (#493) (3a4d44c)
  • don't error on invalid i18n tags in discovery (#407) (d01a5c8), closes #406 #406
  • enforce device authorization grant type (#400) (a4dbe2a)
  • exampleop: pass the issuer interceptor to login (#430) (ce85a8b)
  • examples: Offer Storage with non-global client (#489) (7d0cdec)
  • Implement dedicated error for RevokeToken (#508) (e23b1d4)
  • modify ACRValues parameter type to space separated strings (#388) (e43ac6d)
  • oidc: ignore unknown language tag in userinfo unmarshal (#505) (dce79a7)
  • Only set GrantType once (#353) (#367) (312c2a0), closes #352
  • op: check if getTokenIDAndClaims succeeded (#429) (4ed2699)
  • op: export NewProvider to allow customized issuer (#479) (d88c0ac)
  • op: omit empty state from code flow redirect (#428) (37b5de0), closes #415 #415
  • op: return state in token response only for implicit flow (#460) (0dc2a6e)
  • op: terminate session from request in legacy server (#465) (164c5b2)
  • server: do not get client by id for introspection (#467) (73a1982)

chore

Features

BREAKING CHANGES

    • Just making sure v3 release is triggered.
  • rp: - rename RefreshAccessToken to RefreshToken
  • RefreshToken returns *oidc.Tokens instead of *oauth2.Token

This change allows the return of the id_token in an explicit manner,
as part of the oidc.Tokens struct.
The return type is now consistent with the CodeExchange function.

When an id_token is returned, it is verified.
In case no id_token was received,
RefreshTokens will not return an error.

As per specifictation:
https://openid.net/specs/openid-connect-core-1_0.html#RefreshTokenResponse

Upon successful validation of the Refresh Token,
the response body is the Token Response of Section 3.1.3.3
except that it might not contain an id_token.

  • rp.Userinfo and rs.Introspect now require
    a type parameter.
    • The various verifier types are merged into a oidc.Verifir.
  • oidc.Verfier became a struct with exported fields
  • use type aliases for oidc.Verifier

this binds the correct contstructor to each verifier usecase.

  • fix: handle the zero cases for oidc.Time

  • add unit tests to oidc verifier

  • fix: correct returned field for JWTTokenRequest

JWTTokenRequest.GetIssuedAt() was returning the ExpiresAt field.
This change corrects that by returning IssuedAt instead.

  • The returned router from op.CreateRouter() is now a chi.Router