Repository navigation
Releases: udibo/oauth2
Releases · udibo/oauth2
Release list
0.15.0
0.14.1
0.14.0
0.14.0 (2026-10-07)
⚠ BREAKING CHANGES
- Login sessions follow the browser, not
signInAs.
Repeated authorization requests after onesignInAsno longer share a
session; each starts its own unless it sends back the session cookie the
tenant set, so a test that relied on a second sign-in revoking the first
credential must carry that cookie. Conversely, callingsignInAsagain
no longer starts a new browser: a browser that carries the cookie
continues its session for the same person, so a test modelling two
devices needs two cookie jars (browser contexts). Revoking someone's
last accepted role in an organization throughDELETE …/members/:userId/:rolenow also withdraws their pending memberships
and unaccepted invitations there and drops the permissionsaddMember
seeded, so a later accept of such an offer answersinvalidand
rejoining restores nothing.TenantContractFixturerequires a new
addRole(permissions)hook that defines a tenant-wide role and returns
its id.
Features
0.13.0
0.13.0 (2026-10-07)
⚠ BREAKING CHANGES
- server:
ClientCredentialsGrantrefuses a token request that presents no client secret with 401invalid_client. Register machine clients as confidential and authenticate them with their client secret, by HTTP Basic orclient_secretin the body. A client service written before 0.9.2 must passrunClientServiceContractTests, orclient_credentialsis not limited to confidential clients.
Bug Fixes
0.12.2
0.12.1
0.12.0
0.12.0 (2026-10-03)
BREAKING CHANGES
ResourceServer.clockSkewSecondsis now an accessor.
Subclasses must configure it through constructor options or assignment
rather than redeclaring a class field; reflection that expects an own
property must read it directly. Non-finite, negative, or
millisecond-overflowing skew is rejected at construction and on
reassignment.
Closes
0.11.1
0.11.0
0.11.0 (2026-10-02)
Features
- testing: add identity store contracts (#65) (4d9d7ad), closes udibo/udibo#405
0.10.0
0.10.0 (2026-10-02)
BREAKING CHANGES
- the fake tenant's introspection endpoint answers
{ active: false }to a public client, and to a confidential client asking
about a token issued to another client. Aclient_credentialsrequest
from a client registered without a secret answers 401invalid_client.
Fixtures passed torunTenantContractTestsmust implement
TenantContractFixture.addMachineClient, which registers a
client_credentialsapplication with a scopes allowlist,
administrator-assigned permissions and an optionalconfidentialflag.
It returns the application's id and, when confidential, its secret;
TenantContractClient.secretis optional.