jumbojett/openid-connect-php
Bare-bones OpenID Connect client
v1.0.2
12M downloads/mo
#991 most downloaded on Packagist
jumbojett/OpenID-Connect-PHP
What this package is like to depend on
Last release 2 years ago
no release in 18 months
Release timing varies
gaps range from 3 weeks to 1.2 years
Most releases are documented
notes for 20 of 23 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
23 releases · first in 2016
0 releases in the last 12 months
see the full history below
Release timeline
23 releases · Mar 2016 to Sep 2024Releases
latest 23-
v1.0.213 Sep 2024Release notes
Open source →What's Changed
- fix: protected $responseCode to allow proper overloading of fetchURL() by @DeepDiver1975 in #433
- release: v1.0.1 by @DeepDiver1975 in #432
- fix: bring back #404 by @DeepDiver1975 in #437
- test: add unit test for SERVER_PORT type cast by @DeepDiver1975 in #438
Full Changelog: v1.0.1...v1.0.2
-
v1.0.105 Sep 2024Release notes
Open source →What's Changed
- release: 1.0.0 by @DeepDiver1975 in #402
- Update ci and add dependabot by @ricklambrechts in #407
- Update README.md to correct addScope parameter type in 1.0.0 by @jasongill in #405
- chore(deps): bump actions/checkout from 2 to 4 by @dependabot in #416
- chore(deps): bump actions/cache from 3 to 4 by @dependabot in #417
- Cast SERVER_PORT to integer by @timsmid in #404
- Check if subject is equal to subject of id token when verifying JWT claims by @ricklambrechts in #406
- Removed duplicate check on jwks_uri and only check if jwks_uri exists when needed by @ricklambrechts in #373
- fix: method signatures after 1.0 release by @DeepDiver1975 in #427
- fix: handle JWT decode of non JWT tokens by @DeepDiver1975 in #428
- chore: enable dependabot for composer by @DeepDiver1975 in #429
- ci: run GitHub workflows on pull requests and pushes to master by @DeepDiver1975 in #431
- chore(deps): update phpseclib/phpseclib requirement from ~3.0 to ^3.0.7 by @artemboyko43 in #384
- chore(deps-dev): update yoast/phpunit-polyfills requirement from ^1.0 to ^2.0 by @dependabot in #430
New Contributors
- @jasongill made their first contribution in #405
- @dependabot made their first contribution in #416
- @timsmid made their first contribution in #404
- @artemboyko43 made their first contribution in #384
Full Changelog: v1.0.0...v1.0.1
Release notes
Open source →Fixed
- Cast
$_SERVER['SERVER_PORT']to integer to prevent adding 80 or 443 port to redirect URL. #437
-
v1.0.013 Dec 2023Release notes
Open source →Added
- PHP 7.0 is required. #327
- Support for signed and encrypted UserInfo response and ID Token. #305
- Allow to set User-Agent header. #370
Fixed
- User-Agent is set for any HTTP method in fetchURL() (not just POST). #382
- Update visibility of getWellKnownConfigValue to protected. #363
- Fixed issue on authentication for php8. #354
- Update construct typehint in docblock. #364
- Fixed LogoutToken verification for single value aud claims. #334
- Update well known config value function response types. #376
-
v0.9.1030 Sep 2022Release notes
Open source →Fixed
private_key_jwtandclient_secret_jwtneed to explicitly be enabled #331
Release notes
Open source →Fixed
private_key_jwtandclient_secret_jwtneed to explicitly be enabled #331
-
v0.9.928 Sep 2022Release notes
Open source →Added
- Added support for back-channel logout. #302
- Added support for
private_key_jwtClient Authentication method #322
Fixed
- Harden self-signed JWK header usage. #323
Release notes
Open source →Added
- Added support for back-channel logout. #302
- Added support for
private_key_jwtClient Authentication method #322 - Added support for
client_secret_jwtClient Authentication method #324 - Added PS512 encryption support #342
Fixed
- Harden self-signed JWK header usage. #323
-
v0.9.805 Aug 2022 -
v0.9.713 Jul 2022Release notes
Open source →Added
- Support for Self-Contained JWTs. #308
- Support for RFC8693 Token Exchange Request. #275
Fixed
- PHP 5.4 compatibility. #304
- Use session_status(). #306
-
v0.9.608 May 2022Release notes
Open source →Added
- Support for phpseclib/phpseclib version 3. #260
- Support client_secret on token endpoint with PKCE. #293
- Added new parameter to
requestTokens()to pass custom HTTP headers #297
Changed
- Allow serializing
OpenIDConnectClientusingserialize()#295
Release notes
Open source →Added
- Support for phpseclib/phpseclib version 3. #260
- Support client_secret on token endpoint with PKCE. #293
- Added new parameter to
requestTokens()to pass custom HTTP headers #297
Changed
- Allow serializing
OpenIDConnectClientusingserialize()#295
-
v0.9.524 Nov 2021Release notes
Open source →Changed
- signOut() Method parameter $accessToken -> $idToken to prevent confusion about access and id tokens usage. #127
- Fixed issue where missing nonce within the claims was causing an exception. #280
-
v0.9.421 Nov 2021Release notes
Open source →Added
- Enabled
client_secret_basicauthentication onrefreshToken()#215 - Basic auth support for requestResourceOwnerToken #271
- Enabled
-
v0.9.320 Nov 2021Release notes
Open source →Added
- getRedirectURL() will not log a warning for PHP 7.1+ #179
- it is now possible to disable upgrading from HTTP to HTTPS for development purposes by calling
setHttpUpgradeInsecureRequests(false)#241 - bugfix in getSessionKey when _SESSION key does not exist #251
- Added scope parameter to refresh token request #225
- bugfix in
verifyJWTclaimswhen $accessToken is empty and $claims->at_hash is not #276 - bugfix with the
emptyfunction in PHP 5.4 #267
-
v0.9.216 Nov 2020Release notes
Open source →Added
- Support for PKCE. Currently, the supported methods are 'plain' and 'S256'.
-
v0.9.127 Aug 2020Release notes
Open source →Added
- Add support for MS Azure Active Directory B2C user flows
Changed
- Fix at_hash verification #200
- Getters for public parameters #204
- Removed client ID query parameter when making a token request using Basic Auth
- Use of
random_bytes()for token generation instead ofuniqid(); polyfill for PHP < 7.0 provided.
Removed
- Removed explicit content-length header - caused issues with proxy servers
-
v0.9.009 Mar 2020Release notes
Open source →Added
- php 7.4 deprecates array_key_exists on objects, use property_exists in getVerifiedClaims and requestUserInfo
- Adding a header to indicate JSON as the return type for userinfo endpoint #151
- ~Updated OpenIDConnectClient to conditionally verify nonce #146~
- Add possibility to change enc_type parameter for http_build_query #155
- Adding OAuth 2.0 Token Introspection #156
- Add optional parameters clientId/clientSecret for introspection #157 & #158
- Adding OAuth 2.0 Token Revocation #160
- Adding issuer validator #145
- Adding signing algorithm PS256 #180
- Check http status of request user info #186
- URL encode clientId and clientSecret when using basic authentication, according to https://tools.ietf.org/html/rfc6749#section-2.3.1 #192
- Adjust PHPDoc to state that null is also allowed #193
Changed
- Bugfix/code cleanup #152
- Cleanup PHPDoc #46e5b59
- Replace unnecessary double quotes with single quotes #2a76b57
- Use original function names instead of aliases #1f37892
- Remove unnecessary default values #5ab801e
- Explicit declare field $redirectURL #9187c0b
- Remove unused code #1e65384
- Fix indent #e9cdf56
- Cleanup conditional code flow for better readability #107f3fb
- Added strict type comparisons #167
- Bugfix: required
openidscope was omitted when additional scopes were registered usingaddScopemethod. This resulted in failing OpenID process.
-
v0.8.002 Jan 2019Release notes
Open source →Added
- Fix
verifyJWTsignature(): verify JWT to prevent php errors and warnings on invalid token
Changed
- Decouple session manipulation, it's allow use of other session libraries #134
- Broaden version requirements of the phpseclib/phpseclib package. #144
- Fix
-
0.7.015 Oct 2018Release notes
Open source →Added
- Add "license" field to composer.json #138
- Ensure key_alg is set when getting key #139
- Add option to send additional registration parameters like post_logout_redirect_uris. #140
Changed
- disabled autoload for Crypt_RSA + make refreshToken() method tolerant for errors #137
-
0.6.017 Jul 2018Release notes
Open source →Added
- Added five minutes leeway due to clock skew between openidconnect server and client.
- Fix save access_token from request in implicit flow authentication #129
verifyJWTsignature()method private -> public #126- Support for providers where provider/login URL is not the same as the issuer URL. #125
- Support for providers that has a different login URL from the issuer URL, for instance Azure Active Directory. Here, the provider URL is on the format: https://login.windows.net/(tenant-id), while the issuer claim actually is on the format: https://sts.windows.net/(tenant-id).
Changed
- refreshToken method update #124
-
v0.5.009 Apr 2018 -
0.4.116 Feb 2018 -
0.4.015 Feb 2018Release notes
Open source →Added
- Timeout is configurable via setTimeout method. This addresses issue #94.
- Add the ability to authenticate using the Resource Owner flow (with or without the Client ID and ClientSecret). This addresses issue #98
- Add support for HS256, HS512 and HS384 signatures
- Removed unused calls to $this->getProviderConfigValue("token_endpoint_…
-
0.3.020 Feb 2017Nothing published for this version
-
0.2.012 Aug 2016Nothing published for this version
-
0.1.004 Mar 2016Nothing published for this version