NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #988 most downloaded on Packagist
Bare-bones OpenID Connect client
Last release 2 years ago
no release in 18 months
Release timing varies
gaps range from 3 weeks to 1.2 years
Most releases are documented
notes for 20 of 23 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
23 releases · first in 2016
fix: protected $responseCode to allow proper overloading of fetchURL() by @DeepDiver1975 in #433
Full Changelog: v1.0.1...v1.0.2
One column per quarter.
release: 1.0.0 by @DeepDiver1975 in #402
Full Changelog: v1.0.0...v1.0.1
$_SERVER['SERVER_PORT'] to integer to prevent adding 80 or 443 port to redirect URL. #437Support for signed and encrypted UserInfo response and ID Token. #305
private_key_jwt and client_secret_jwt need to explicitly be enabled #331
private_key_jwt and client_secret_jwt need to explicitly be enabled #331Added support for back-channel logout. #302
private_key_jwt Client Authentication method #322client_secret_jwt Client Authentication method #324Do not use PKCE if IdP does not support it. #317
Support for Self-Contained JWTs. #308
Support for phpseclib/phpseclib version 3 . #260
requestTokens() to pass custom HTTP headers #297OpenIDConnectClient using serialize() #295signOut() Method parameter $accessToken -> $idToken to prevent confusion about access and id tokens usage. #127
Enabled client_secret_basic authentication on refreshToken() #215
getRedirectURL() will not log a warning for PHP 7.1+ #179
setHttpUpgradeInsecureRequests(false) #241verifyJWTclaims when $accessToken is empty and $claims->at_hash is not #276empty function in PHP 5.4 #267Support for PKCE. Currently, the supported methods are 'plain' and 'S256'.
Add support for MS Azure Active Directory B2C user flows
random_bytes() for token generation instead of uniqid(); polyfill for PHP < 7.0 provided.php 7.4 deprecates array_key_exists on objects, use property_exists in getVerifiedClaims and requestUserInfo
openid scope was omitted when additional scopes were registered using addScope method. This resulted in failing OpenID process.Fix verifyJWTsignature(): verify JWT to prevent php errors and warnings on invalid token
verifyJWTsignature(): verify JWT to prevent php errors and warnings on invalid tokenAdd "license" field to composer.json #138
Added five minutes leeway due to clock skew between openidconnect server and client.
verifyJWTsignature() method private -> public #126Implement Azure AD B2C Implicit Workflow
Documentation updates for include path.
Timeout is configurable via setTimeout method. This addresses issue #94.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →