NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #681 by repository stars
Last release 10 months ago
20 Nov 2025
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
1103 releases · first in 2015
Nothing published for this version
pkce: Return error when PKCE is used with private clients
pkce: Return error when PKCE is used with private clients (#375)
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
openid: Allow promp=none for https/localhost
openid: Allow promp=none for https/localhost (#359)
Signed-off-by: aeneasr aeneas@ory.sh
core: Add debug log to invalid_client error
core: Add debug log to invalid_client error(#358)
Signed-off-by: nerocrux nerocrux@gmail.com
Nothing published for this version
Improve IsRedirectURISecure check
Nothing published for this version
Allow providing a custom redirect URI checker
Allow providing a custom redirect URI checker (#355)
Signed-off-by: aeneasr aeneas@ory.sh
token: Improve rotated secret error reporting in HMAC strategy
token: Improve rotated secret error reporting in HMAC strategy (#354)
Signed-off-by: aeneasr aeneas@ory.sh
Improve rotated secret error reporting in HMAC strategy (#354) (f21d930)
Propagate session data properly (#353) (5ba0f04):
This example is slightly inaccurate; the session data will need to come from the returned AccessRequester, not the pre-created session. The session passed to IntrospectToken isn't mutated.
Update HISTORY.md, README.md, CONTRIBUTING.md (#347) (de5e61e):
0.26.0 as was stuck inside a code block.Nothing published for this version
Nothing published for this version
Nothing published for this version
oauth2: add test coverage to exercise the transactional support in the AuthorizeExplicitGrantHandler's PopulateTokenEndpointResponse method.
oauth2: add test coverage to exercise the transactional support in the AuthorizeExplicitGrantHandler's PopulateTokenEndpointResponse method.
Signed-off-by: Amir Aslaminejad aslaminejad@gmail.com
Transactional which is to be implemented by storage providers that can support transactions. (c364b33)Transactional interface) to address #309 (e00c567)Transactional interface) to address #309 (07d1a39)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
compose: Expose token entropy setting
compose: Expose token entropy setting (#342)
Signed-off-by: nerocrux nerocrux@gmail.com
Nothing published for this version
oauth2: Add ability to specify refresh token lifespan
oauth2: Add ability to specify refresh token lifespan (#337)
Set it to -1 to disable this feature. Defaults to 30 days.
Closes #319
Signed-off-by: arekkas aeneas@ory.am
This version (re-)introduces refresh token lifespans. Per default, this feature is enabled and set to 30 days. If a refresh token has not been used within 30 days, it will expire.
To disable refresh token lifespans (previous behaviour), set
compose.Config.RefreshTokenLifespan = -1.
replace NewMemoryStore with NewExampleStore
docs: Fix quickstart (#335)
Signed-off-by: Peter Schultz peter.schultz@classmarkets.com
Fix quickstart (#335) (25cc6c4):
Nothing published for this version
oauth2: Set exp for authorize code issued by hybrid flow
oauth2: Set exp for authorize code issued by hybrid flow (#333)
Signed-off-by: nerocrux nerocrux@gmail.com
Signed-off-by: Adam Shannon Signed-off-by: Wenhao Ni
pkce: Allow hybrid flows (#328)
Signed-off-by: Adam Shannon adamkshannon@gmail.com Signed-off-by: Wenhao Ni niwenhao@gmail.com
Allow hybrid flows (#328) (cdfddc8):
Signed-off-by: Wenhao Ni niwenhao@gmail.com
Nothing published for this version
oauth2: Improve refresh security and reliability
oauth2: Improve refresh security and reliability (#332)
This patch resolves several issues regarding the refresh flow. First, an issue has been resolved which caused the audience to not be set in the refreshed access tokens.
Second, scope and audience are validated against the client's whitelisted values and if the values are no longer allowed, the grant is canceled.
Closes #331 Closes #325 Closes #324
Improve refresh security and reliability (#332) (4e4121b), closes #331 #325 #324:
This patch resolves several issues regarding the refresh flow. First, an issue has been resolved which caused the audience to not be set in the refreshed access tokens.
Second, scope and audience are validated against the client's whitelisted values and if the values are no longer allowed, the grant is canceled.
oauth2: Update jwt access token interface
oauth2: Update jwt access token interface (#330)
The interface needed to change in order to natively handle the audience claim.
Signed-off-by: arekkas aeneas@ory.am
Introduce audience capabilities (#327) (e2441d2), closes #326:
This patch allows clients to whitelist audiences and request that audiences are set for oauth2 access and refresh tokens
Update jwt access token interface (#330) (2da9764):
The interface needed to change in order to natively handle the audience claim.
This PR adds the ability to specify a target audience for OAuth 2.0 Access Tokens.
From now on, scope and audience will be checked against the client's
whitelisted scope and audience on every refresh token exchange. This prevents
clients, which no longer are allowed to request a certain audience or scope, to
keep using those values with existing refresh tokens.
type fosite.Client interface {
+ // GetAudience returns the allowed audience(s) for this client.
+ GetAudience() Arguments
}
type fosite.Request struct {
- Scopes Argument
+ RequestedScope Argument
- GrantedScopes Argument
+ GrantedScope Argument
}
type fosite.Requester interface {
+ // GetRequestedAudience returns the requested audiences for this request.
+ GetRequestedAudience() (audience Arguments)
+ // SetRequestedAudience sets the requested audienc.
+ SetRequestedAudience(audience Arguments)
+ // GetGrantedAudience returns all granted scopes.
+ GetGrantedAudience() (grantedAudience Arguments)
+ // GrantAudience marks a request's audience as granted.
+ GrantAudience(audience string)
}
type fosite/token/jwt.JWTClaimsContainer interface {
- // With returns a copy of itself with expiresAt and scope set to the given values.
- With(expiry time.Time, scope, audience []string) JWTClaimsContainer
+ // With returns a copy of itself with expiresAt, scope, audience set to the given values.
+ With(expiry time.Time, scope, audience []string) JWTClaimsContainer
}
Nothing published for this version
hash: Raise bcrypt cost factor lower bound
hash: Raise bcrypt cost factor lower bound (#321)
Users of this library can easily create the following:
hasher := fosite.BCrypt{} hasher.Hash(..)
This is a problem because WorkFactor will default to 0 and x/crypto/bcrypt will default that to 4 (See https://godoc.org/golang.org/x/crypto/bcrypt).
Instead this should be some higher cost factor. Callers who need a lower WorkFactor can still lower the cost, if needed.
Signed-off-by: Adam Shannon adamkshannon@gmail.com
Raise bcrypt cost factor lower bound (#321) (799fc70):
Users of this library can easily create the following:
hasher := fosite.BCrypt{} hasher.Hash(..)
This is a problem because WorkFactor will default to 0 and x/crypto/bcrypt will default that to 4 (See https://godoc.org/golang.org/x/crypto/bcrypt).
Instead this should be some higher cost factor. Callers who need a lower WorkFactor can still lower the cost, if needed.
Nothing published for this version
Nothing published for this version
all: Rearrange commits with goreturns
This release makes it easier to define custom JWT Containers for access tokens when using the JWT strategy. To do that, the following signatures have changed:
// github.com/ory/fosite/handler/oauth2
type JWTSessionContainer interface {
// GetJWTClaims returns the claims.
- GetJWTClaims() *jwt.JWTClaims
+ GetJWTClaims() jwt.JWTClaimsContainer
// GetJWTHeader returns the header.
GetJWTHeader() *jwt.Headers
fosite.Session
}
+ type JWTClaimsContainer interface {
+ // With returns a copy of itself with expiresAt and scope set to the given values.
+ With(expiry time.Time, scope []string) JWTClaimsContainer
+
+ // WithDefaults returns a copy of itself with issuedAt and issuer set to the given default values. If those
+ // values are already set in the claims, they will not be updated.
+ WithDefaults(iat time.Time, issuer string) JWTClaimsContainer
+
+ // ToMapClaims returns the claims as a github.com/dgrijalva/jwt-go.MapClaims type.
+ ToMapClaims() jwt.MapClaims
+ }
All default session implementations have been updated to reflect this change. If you define custom session, this patch will affect you.
Nothing published for this version
handler/openid: Populate at_hash in explicit/refresh flows
handler/openid: Populate at_hash in explicit/refresh flows (#315)
Signed-off-by: Wenhao Ni niwenhao@gmail.com
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix broken go modules tests (#311) (02ea4b1), closes #311
Nothing published for this version
Propagate context in jwt strategies
This release addresses areas where the go context was missing or not propagated down the call path properly.
fosite/handler/oauth2.JWTStrategyThe
fosite/handler/oauth2.JWTStrategy
interface changed as a context parameter was added to its method signature:
type JWTStrategy interface {
- Validate(tokenType fosite.TokenType, token string) (requester fosite.Requester, err error)
+ Validate(ctx context.Context, tokenType fosite.TokenType, token string) (requester fosite.Requester, err error)
}
OpenIDConnectRequestValidator.ValidatePromptThe
OpenIDConnectRequestValidator.ValidatePrompt
method signature was updated to take a go context as its first parameter:
- func (v *OpenIDConnectRequestValidator) ValidatePrompt(req fosite.AuthorizeRequester) error {
+ func (v *OpenIDConnectRequestValidator) ValidatePrompt(ctx context.Context, req fosite.AuthorizeRequester) error {
Nothing published for this version
Add breaking change to the Hasher interface to the change log
Add breaking change to the Hasher interface to the change log
Signed-off-by: Amir Aslaminejad aslaminejad@gmail.com
This releases addresses inconsistencies in some of the public interfaces by passing in the go context to their signatures.
HasherThe Hasher interface
changed as a context parameter was added to its method signatures:
type Hasher interface {
- Compare(hash, data []byte) error
+ Compare(ctx context.Context, hash, data []byte) error
- Hash(data []byte) ([]byte, error)
+ Hash(ctx context.Context, data []byte) ([]byte, error)
}
Nothing published for this version
Nothing published for this version
jwt: update JWTStrategy to take in context
jwt: update JWTStrategy to take in context (#302)
Signed-off-by: Amir Aslaminejad aslaminejad@gmail.com
This releases addresses inconsistencies in some of the public interfaces by passing in the go context to their signatures.
JWTStrategyThe JWTStrategy
interface changed as a context parameter was added to its method signatures:
type JWTStrategy interface {
- Generate(claims jwt.Claims, header Mapper) (string, string, error)
+ Generate(ctx context.Context, claims jwt.Claims, header Mapper) (string, string, error)
- Validate(token string) (string, error)
+ Validate(ctx context.Context, token string) (string, error)
- GetSignature(token string) (string, error)
+ GetSignature(ctx context.Context, token string) (string, error)
- Hash(in []byte) ([]byte, error)
+ Hash(ctx context.Context, in []byte) ([]byte, error)
- Decode(token string) (*jwt.Token, error)
+ Decode(ctx context.Context, token string) (*jwt.Token, error)
GetSigningMethodLength() int
}
Nothing published for this version
Nothing published for this version
Nothing published for this version
openid: Allow JWT from id_token_hint to be expired
openid: Allow JWT from id_token_hint to be expired (#299)
Signed-off-by: arekkas aeneas@ory.am
Your coding agent can read these notes before it upgrades. Set up the MCP server →