Repository navigation
3.0.0 (2024-01-11)
Bug Fixes
- build callback url from server, not op (#468) (e5f0dca)
- client/rs: do not error when issuer discovery has no introspection endpoint (#414) (406153a)
- crypto: nil pointer dereference in crypto.BytesToPrivateKey (#491) (#493) (3a4d44c)
- don't error on invalid i18n tags in discovery (#407) (d01a5c8), closes #406 #406
- enforce device authorization grant type (#400) (a4dbe2a)
- exampleop: pass the issuer interceptor to login (#430) (ce85a8b)
- examples: Offer Storage with non-global client (#489) (7d0cdec)
- Implement dedicated error for RevokeToken (#508) (e23b1d4)
- modify ACRValues parameter type to space separated strings (#388) (e43ac6d)
- oidc: ignore unknown language tag in userinfo unmarshal (#505) (dce79a7)
- Only set GrantType once (#353) (#367) (312c2a0), closes #352
- op: check if getTokenIDAndClaims succeeded (#429) (4ed2699)
- op: export NewProvider to allow customized issuer (#479) (d88c0ac)
- op: omit empty state from code flow redirect (#428) (37b5de0), closes #415 #415
- op: return state in token response only for implicit flow (#460) (0dc2a6e)
- op: terminate session from request in legacy server (#465) (164c5b2)
- server: do not get client by id for introspection (#467) (73a1982)
chore
-
replace gorilla/mux with go-chi/chi (#332) (57fb9f7), closes #301
-
Merge pull request zitadel#456 from zitadel/next-main (976b406), closes #456
Features
- add CanTerminateSessionFromRequest interface (#418) (be89c3b)
- add context to all client calls (#345) (6af94fd), closes #309
- add slog logging (#432) (0879c88)
- add typ:JWT header to tokens (#435) (5ade1cd)
- Allow CORS policy to be configured (#484) (7b64687)
- Allow modifying request to device authorization endpoint (#356) (c778e83), closes #354
- delete PKCE cookie after code exchange (#419) (45582b6)
- generic Userinfo and Introspect functions (#389) (d5a9bd6)
- issuer from Forwarded header (#443) (364a759)
- merge the verifier types (#336) (33c716d)
- op: add opentelemetry to token endpoint (#436) (1683b31)
- op: allow double star globs (#507) (c37ca25)
- op: allow Legacy Server extension (#466) (bab5399)
- op: create a JWT profile with a keyset (f7a0f7c)
- op: ID token for device authorization grant (#500) (b300027)
- op: issuer from custom headers (#478) (7475023)
- op: JWT profile verifier with keyset (a8ef8de)
- op: PKCE Verification in Legacy Server when AuthMethod is not NONE and CodeVerifier is not Empty (#496) (9d12d1d)
- op: Server interface (#447) (0f8a058)
- op: User-configurable claims_supported (#495) (7bdaf9c)
- rp: Add UnauthorizedHandler (#503) (984e31a)
- rp: client credentials grant (#494) (fe3e02b), closes /datatracker.ietf.org/doc/html/rfc6749#section-4
- rp: return oidc.Tokens on token refresh (#423) (6708ef4), closes #364
BREAKING CHANGES
-
- Just making sure v3 release is triggered.
- rp: - rename RefreshAccessToken to RefreshToken
- RefreshToken returns *oidc.Tokens instead of *oauth2.Token
This change allows the return of the id_token in an explicit manner,
as part of the oidc.Tokens struct.
The return type is now consistent with the CodeExchange function.
When an id_token is returned, it is verified.
In case no id_token was received,
RefreshTokens will not return an error.
As per specifictation:
https://openid.net/specs/openid-connect-core-1_0.html#RefreshTokenResponse
Upon successful validation of the Refresh Token,
the response body is the Token Response of Section 3.1.3.3
except that it might not contain an id_token.
- rp.Userinfo and rs.Introspect now require
a type parameter. -
- The various verifier types are merged into a oidc.Verifir.
- oidc.Verfier became a struct with exported fields
- use type aliases for oidc.Verifier
this binds the correct contstructor to each verifier usecase.
-
fix: handle the zero cases for oidc.Time
-
add unit tests to oidc verifier
-
fix: correct returned field for JWTTokenRequest
JWTTokenRequest.GetIssuedAt() was returning the ExpiresAt field.
This change corrects that by returning IssuedAt instead.
- The returned router from
op.CreateRouter()is now achi.Router