Skip to content

1.5.0

Latest

Choose a tag to compare

@vishal-mb vishal-mb released this 10 Sep 07:28
f0513a2

Enhancements

  • Support public OAuth2 clients that hold no client secret (#178).
    • OAuth2ClientConfiguration gains init(publicClientIdentifier:environment:guestUsername:guestPassword:) and a read-only isPublicClient flag. A public client identifies itself with client_id in the token grant body and sends no Authorization: Basic header across every grant type. Confidential clients are unchanged.
    • Client-level authorization for a public client through OAuth2RequestPipelineMiddleware requires guest credentials. Client-level basic, and client-level bearer without guest credentials, fail with OAuth2Error.internalFailure instead of sending a request with no credential.
    • A public client using authorization_code must use PKCE and the authorization server must enforce it (RFC 8252 §6). Pass code_challenge via OAuth2AuthorizationRequest.additionalParameters and code_verifier via tokenGrantRequestAdditionalBodyParameters.