NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #681 by repository stars
Last release 10 months ago
20 Nov 2025
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
1103 releases · first in 2015
Adds ability to catch non-conform OIDC authorizations
Adds ability to catch non-conform OIDC authorizations
Fosite is now capable of detecting authorization flows that are not conformant with the OpenID Connect spec.
Nothing published for this version
One column per quarter.
token/jwt: Adds ability to specify acr value natively in id token payload
token/jwt: Adds ability to specify acr value natively in id token payload
Improves test coverage report by removing internal package from it
Upgrades history.md
This release focuses on improving compatibility with OpenID Connect Certification and better error context.
/oauth2/token endpoint. Please
note that this method is not recommended to be used, unless the client making
the request is unable to use HTTP Basic Authorization./oauth2/token endpoint
which was previously only possible by adding an arbitrary secret.This release has no breaking changes to the external API but due to the nature of the changes, it is released as a new major version.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Makes use of rfcerr in access error endpoint writer explicit
Makes use of rfcerr in access error endpoint writer explicit
Exports ErrorToRFC6749Error again
Simplifies how errors are instantiated. Errors now contain all necessary information without relying on fosite.ErrorToRFC6749Error any more. fosite.Er
Simplifies error contexts (#227)
Simplifies how errors are instantiated. Errors now contain all necessary information without relying on fosite.ErrorToRFC6749Error any more. fosite.ErrorToRFC6749Error is now an internal method and was renamed to fosite.errorToRFC6749Error.
Improves error contexts. A breaking code changes to the public API was reverted with 0.14.1.
handler/oauth2: Client IDs in revokation requests must match now
handler/oauth2: Client IDs in revokation requests must match now (#226)
Closes #225
Nothing published for this version
Nothing published for this version
vendor: replace glide with dep ### Unclassified - Replace glide with dep
scripts: fix goimports import path
scripts: fix goimports import path
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
handler/oauth2: set expiration time before the access token is generated
handler/oauth2: set expiration time before the access token is generated (#216)
Signed-off-by: Nikita Vorobey nikita@vorobey.by
Nothing published for this version
oauth2/ropc: Set expires at for password credentials flow
oauth2/ropc: Set expires at for password credentials flow (#210)
Signed-off-by: Beorn Facchini beornf@gmail.com
Fixes documentation oauth2 variable and updates old method (#205) (fa50c80):
It seems that the documentation was declaring as OAuth2Provider the variable oauth2Provider whereas it used a non-declared variable oauth2. I renamed oauth2 into the variable declared oauth2Provider.
Furthermore, on line 333, the IntrospectToken method was called without the TokenType argument. I added the fosite.AccessToken type.
Update docs on scope strategy (68119ca)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
scope: resolve haystack needle mixup - closes #201
handler/openid: only refresh id token with id_token response type (dd2463a), closes #199
Nothing published for this version
Nothing published for this version
handler/oauth2: remove code validity check from test
handler/oauth2: update docs
To simplify the storage adapter logic, and also reduce the likelihoods of bugs within the storage adapter, the interface was greatly simplified. Specifically, these two methods have been removed:
PersistRefreshTokenGrantSession(ctx context.Context, requestRefreshSignature, accessSignature, refreshSignature string, request fosite.Requester) errorPersistAuthorizeCodeGrantSession(ctx context.Context, authorizeCode, accessSignature, refreshSignature string, request fosite.Requester) errorFor this change, you don't need to do anything. You can however simply delete those two methods from your store.
In the long term, fosite should remove all gomocks and instead test against the internal implementations. This will increase iterations per line during tests and reduce annoying mock updates.
fosite/handler/oauth2.AuthorizeCodeGrantStorage was removedAuthorizeCodeGrantStorage was used specifically in the composer. Refactor
references to AuthorizeCodeGrantStorage with CoreStorage.
fosite/handler/oauth2.RefreshTokenGrantStorage was removedRefreshTokenGrantStorage was used specifically in the composer. Refactor
references to RefreshTokenGrantStorage with CoreStorage.
fosite/handler/oauth2.AuthorizeCodeGrantStorage was removedAuthorizeCodeGrantStorage was used specifically in the composer. Refactor
references to AuthorizeCodeGrantStorage with CoreStorage.
A new scope strategy was introduced
called WildcardScopeStrategy. This strategy is now the default when using the
composer. To set the HierarchicScopeStrategy strategy, do:
import "github.com/ory/fosite/compose"
var config = &compose.Config{
ScopeStrategy: fosite.HierarchicScopeStrategy,
}
Using JWTs for refresh tokens and authorize codes did not make sense:
Also, one compose method changed due to this:
package compose
// ..
- func NewOAuth2JWTStrategy(key *rsa.PrivateKey) *oauth2.RS256JWTStrategy
+ func NewOAuth2JWTStrategy(key *rsa.PrivateKey, strategy *oauth2.HMACSHAStrategy) *oauth2.RS256JWTStrategy
Please delete access tokens in your store when you persist a refresh session. This increases security. Here is an example of how to do that using only existing methods:
func (s *MemoryStore) PersistRefreshTokenGrantSession(ctx context.Context, originalRefreshSignature, accessSignature, refreshSignature string, request fosite.Requester) error {
if ts, err := s.GetRefreshTokenSession(ctx, originalRefreshSignature, nil); err != nil {
return err
} else if err := s.RevokeAccessToken(ctx, ts.GetID()); err != nil {
return err
} else if err := s.RevokeRefreshToken(ctx, ts.GetID()); err != nil {
return err
} else if err := s.CreateAccessTokenSession(ctx, accessSignature, request); err != nil {
return err
} else if err := s.CreateRefreshTokenSession(ctx, refreshSignature, request); err != nil {
return err
}
return nil
}
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
oauth2/introspector: remove auth code, refresh scopes
oauth2/introspector: remove auth code, refresh scopes (#187)
Removes authorize code introspection in the HMAC-based strategy and now checks scopes of refresh tokens as well.
oauth2/introspector: remove auth code, refresh scopes (#187) (ef8f175), closes #187:
Removes authorize code introspection in the HMAC-based strategy and now checks scopes of refresh tokens as well.
Separate test dependencies (#186) (71451f0):
It is no longer possible to introspect authorize codes, and passing scopes to the introspector now also checks refresh token scopes.
Nothing published for this version
handler/openid: remove forced nonce
handler/openid: remove forced nonce (#185)
Signed-off-by: Wyatt Anderson wanderson@gmail.com
oauth2: basic auth should decode client id and secret
Nothing published for this version
handler/oauth2: grant scopes before the access token is generated
handler/oauth2: grant scopes before the access token is generated (#177)
Signed-off-by: Nikita Vorobey nikita@vorobey.by
introspection: return with active set false on token error
vendor: remove unnecessary go-jose import
Your coding agent can read these notes before it upgrades. Set up the MCP server →