Skip to content

Releases: udibo/oauth2

0.15.0

Choose a tag to compare

@github-actions github-actions released this 10 Oct 15:04

0.15.0 (2026-10-10)

Features

  • run on Node and publish to npm and JSR from one TypeScript source (ec64cc5)

Bug Fixes

  • release: push the release commit over the deploy key's SSH remote (#88) (1744d2f)

0.14.1

Choose a tag to compare

@github-actions github-actions released this 09 Oct 13:22

0.14.1 (2026-10-09)

Bug Fixes

  • bff: destroy the session a new sign-in replaces (#85) (224995c)

0.14.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 02:28

0.14.0 (2026-10-07)

⚠ BREAKING CHANGES

  • Login sessions follow the browser, not signInAs.
    Repeated authorization requests after one signInAs no longer share a
    session; each starts its own unless it sends back the session cookie the
    tenant set, so a test that relied on a second sign-in revoking the first
    credential must carry that cookie. Conversely, calling signInAs again
    no longer starts a new browser: a browser that carries the cookie
    continues its session for the same person, so a test modelling two
    devices needs two cookie jars (browser contexts). Revoking someone's
    last accepted role in an organization through DELETE …/members/:userId/:role now also withdraws their pending memberships
    and unaccepted invitations there and drops the permissions addMember
    seeded, so a later accept of such an offer answers invalid and
    rejoining restores nothing. TenantContractFixture requires a new
    addRole(permissions) hook that defines a tenant-wide role and returns
    its id.

Features

  • mirror member roles and per-sign-in sessions in the fake tenant (#84) (e94a8d7)

0.13.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 02:19

0.13.0 (2026-10-07)

⚠ BREAKING CHANGES

  • server: ClientCredentialsGrant refuses a token request that presents no client secret with 401 invalid_client. Register machine clients as confidential and authenticate them with their client secret, by HTTP Basic or client_secret in the body. A client service written before 0.9.2 must pass runClientServiceContractTests, or client_credentials is not limited to confidential clients.

Bug Fixes

  • server: admit only confidential clients to client_credentials (#83) (638123e)

0.12.2

Choose a tag to compare

@github-actions github-actions released this 03 Oct 10:19

0.12.2 (2026-10-03)

Bug Fixes

  • use placeholders in example commands (#80) (d359857), closes #79

0.12.1

Choose a tag to compare

@github-actions github-actions released this 03 Oct 03:25

0.12.1 (2026-10-03)

Bug Fixes

  • reject duplicate singleton form parameters (#70) (5b0a05f), closes #69

0.12.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 02:18

0.12.0 (2026-10-03)

BREAKING CHANGES

  • ResourceServer.clockSkewSeconds is now an accessor.
    Subclasses must configure it through constructor options or assignment
    rather than redeclaring a class field; reflection that expects an own
    property must read it directly. Non-finite, negative, or
    millisecond-overflowing skew is rejected at construction and on
    reassignment.

Closes

0.11.1

Choose a tag to compare

@github-actions github-actions released this 03 Oct 01:47

0.11.1 (2026-10-03)

Bug Fixes

  • ci: reject private release references (#67) (b0cbbb9), closes #24

0.11.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 10:58

0.11.0 (2026-10-02)

Features

0.10.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 09:18

0.10.0 (2026-10-02)

  • feat!: add machine clients to the fake tenant (#60) (5c01bfe)

BREAKING CHANGES

  • the fake tenant's introspection endpoint answers { active: false } to a public client, and to a confidential client asking
    about a token issued to another client. A client_credentials request
    from a client registered without a secret answers 401 invalid_client.
    Fixtures passed to runTenantContractTests must implement
    TenantContractFixture.addMachineClient, which registers a
    client_credentials application with a scopes allowlist,
    administrator-assigned permissions and an optional confidential flag.
    It returns the application's id and, when confidential, its secret;
    TenantContractClient.secret is optional.