NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #681 by repository stars
Last release 10 months ago
20 Nov 2025
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
1103 releases · first in 2015
Resolve issues with error handling
Resolve issues with error handling (#174)
errors: do not convert errors compliant with rfcerrors
handler/oauth2: improve redirect message for insecure http
vendor: remove stray github.com/Sirupsen/logrus
One column per quarter.
Enable fosite composing with custom hashers.
This patch adds the ability to pass a custom hasher to compose.Compose, which
is a breaking change. You can pass nil for the fosite default hasher:
package compose
-func Compose(config *Config, storage interface{}, strategy interface{}, factories ...Factory) fosite.OAuth2Provider {
+func Compose(config *Config, storage interface{}, strategy interface{}, hasher fosite.Hasher, factories ...Factory) fosite.OAuth2Provider {
Nothing published for this version
Nothing published for this version
Nothing published for this version
docs: add notes for breaking changes that come with 0.8.0
docs: add notes for breaking changes that come with 0.8.0
Added context to GetClient storage interface (#162) (974585d), closes #161
Removed *http.Request from interfaces that access request objects (786b971):
removed the requirement to *http.Request for endpoints and response object, they are resolvable trough the request.GetRequestForm
updated readme to reflect changes to implementation
run goimports on internal dir added goimports command to generate-mocks.sh to force first run after generating the mock files
Set authorize code expire time before persist (#166) (305a74f)
This patch addresses some inconsistencies in the public interfaces. Also
remaining references to the old repository location at ory-am/fosite where
updated to ory/fosite.
ClientManagerThe
ClientManager
interface changed, as a context parameter was added:
type ClientManager interface {
// GetClient loads the client by its ID or returns an error
// if the client does not exist or another error occurred.
- GetClient(id string) (Client, error)
+ GetClient(ctx context.Context, id string) (Client, error)
}
OAuth2ProviderThe OAuth2Provider
interface changed, as the need for passing down *http.Request was removed.
This is justifiable because NewAuthorizeRequest and NewAccessRequest already
contain *http.Request.
The public api of those two methods changed:
- NewAuthorizeResponse(ctx context.Context, req *http.Request, requester AuthorizeRequester, session Session) (AuthorizeResponder, error)
+ NewAuthorizeResponse(ctx context.Context, requester AuthorizeRequester, session Session) (AuthorizeResponder, error)
- NewAccessResponse(ctx context.Context, req *http.Request, requester AccessRequester) (AccessResponder, error)
+ NewAccessResponse(ctx context.Context, requester AccessRequester) (AccessResponder, error)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Replace golang.org/x/net/context with context
Breaking changes:
"golang.org/x/net/context" with "context".github.com/ory-am/fosite to github.com/ory/fositeNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
access: revert regression issue introduced by #150
Nothing published for this version
oauth2: basic auth should www-url-decode client id and secret - closes #150
oauth2: basic auth should www-url-decode client id and secret - closes #150
handler/oauth2: removes RevokeHandler from JWT introspector (#155) (344dbef), closes #155:
RevokeHandler has been removed because it conflicts with Stateless JWT accesstokens and revocable hmac refresh tokens. The readme has been updated to warn users about possible misconfiguration.
Allow localhost subdomains such as blog.localhost:1234 (5e1c890)
Basic auth should www-url-decode client id and secret - closes #150 (ad395bf)
Get the token from the access_token query parameter (#156) (9edac04)
Nothing published for this version
Nothing published for this version
Nothing published for this version
make stateless validator return an error on revocation
readme: update badges to ory
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
errors: fixed typo in acccess_error
allow public clients to revoke tokens with just an ID
allow public clients to revoke tokens with just an ID
This functionality is described in the OAuth2 spec here: https://tools.ietf.org/html/rfc7009#section-5
allow public clients to revoke tokens with just an ID (7b94f47), closes /tools.ietf.org/html/rfc7009#section-5
Conform to RFC 6749 (c404554), closes /tools.ietf.org/html/rfc6749#section-5:
Section 5.2 specifies the parameters for access error responses; the "error" and "error_description" parameters are misnamed.
Nothing published for this version
request: fix SetRequestedScopes
request: fix SetRequestedScopes (#139)
Signed-off-by: Peter Schultz peter.schultz@classmarkets.com
authorize: allow custom redirect url schemas
Nothing published for this version
openid: c_hash / at_hash should use url-safe base64 encoding
openid: c_hash / at_hash should use url-safe base64 encoding
openid: c_hash / at_hash should be string not byte slice
openid: c_hash / at_hash should be string not byte slice
oauth2/implicit: fix redirect url on error Signed-off-by: Nikita Vorobey
oauth2/implicit: fix redirect url on error Signed-off-by: Nikita Vorobey nikita@vorobey.by
Nothing published for this version
lint: gofmt -w -s . ### Unclassified - Add id_token + code flow (3f347e3) - Fix typos (#130) (e6b410d) - Gofmt -w -s .
Nothing published for this version
Nothing published for this version
access: response expires in should be int, not string
access: response expires in should be int, not string
errors: add inactive token error
Nothing published for this version
Nothing published for this version
introspection: always return the error
token/jwt: Allow single element string arrays to be treated as strings
token/jwt: Allow single element string arrays to be treated as strings
This commit allows aud to be passed in as a single element array
during consent validation on Hydra. This fixes
https://github.com/ory-am/hydra/issues/314.
Signed-off-by: Son Dinh son.dinh@blacksquaremedia.com
token/jwt: Allow single element string arrays to be treated as strings (5388e10):
This commit allows aud to be passed in as a single element array
during consent validation on Hydra. This fixes
https://github.com/ory-am/hydra/issues/314.
Nothing published for this version
oauth2/introspection: endpoint responds to invalid requests appropriately
core: resolve issues with token introspection and sessions
core: resolve issues with token introspection and sessions
core: resolve session referencing issue
A bug related to refresh tokens was found. To mitigate it, a Clone() method
has been introduced to the fosite.Session interface. If you use a custom
session object, this will be a breaking change. Fosite's default sessions have
been upgraded and no additional work should be required. If you use your own
session struct, we encourage using package gob/encoding to deep-copy it in
Clone().
Nothing published for this version
handler/oauth2: set JWT ExpiresAt claim per TokenType from the session
handler/oauth2: set JWT ExpiresAt claim per TokenType from the session (#121)
Signed-off-by: Cristian Graziano cristian.graziano@gmail.com
Nothing published for this version
all: resolve regression issues introduced by 0.4.0 - closes #118
Breaking changes:
compose.OpenIDConnectExplicit is now compose.OpenIDConnectExplicitFactorycompose.OpenIDConnectImplicit is now compose.OpenIDConnectImplicitFactorycompose.OpenIDConnectHybrid is now compose.OpenIDConnectHybridFactorycompose.OAuth2*. Add compose.OAuth2TokenIntrospectionFactory to your
composer if you need token introspection.fosite.Session /
fosite.DefaultSession. All sessions must now implement this signature. The
new session interface allows for better expiration time handling.DefaultSession signature changed as well, it is now
implementing the fosite.Session interfaceall: clean up, resolve broken tests
Breaking changes:
./fosite-example is now a separate repository:
https://github.com/ory-am/fosite-examplegithub.com/ory-am/fosite/fosite-example/pkg.Store is now
github.com/ory-am/fosite/storage.MemoryStorefosite.Client has now a new method called IsPublic() which can be used to
identify public clients who do not own a client secretTokenValidator is now TokenIntrospector, TokenValidationHandlers is now
TokenIntrospectionHandlers.TokenValidator.ValidateToken is now TokenIntrospector.IntrospectTokenfosite.OAuth2Provider.NewIntrospectionRequest() has been addedfosite.OAuth2Provider.WriteIntrospectionError() has been addedfosite.OAuth2Provider.WriteIntrospectionResponse() has been addedNothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →