NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #681 by repository stars
Last release 10 months ago
20 Nov 2025
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
1103 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
oauth2: added refresh token generation for password grant type
oauth2: added refresh token generation for password grant type (#107)
Signed-off-by: Jason Rossiter jrossiter403@gmail.com
handler/oauth2: resolve issues with refresh token flow
handler/oauth2: resolve issues with refresh token flow (#110)
Nothing published for this version
handler/oauth2: refresh token does not migrate original access data - closes #103
authorize: scopes should be separated by %20 and not +, to ensure javascript compatibility - closes #101
authorize: scopes should be separated by %20 and not +, to ensure javascript compatibility - closes #101 (#102)
Nothing published for this version
openid: resolves an issue with the explicit token flow
openid: resolves an issue with the explicit token flow
all: better error handling - closes #100
0.3.1 (#98)
token+code+id_token returns multiple tokens of the same type - closes #99Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Signed-off-by: Alexander Widerberg
vendor: jwt-go is now v3.0.0 (#77)
Signed-off-by: Alexander Widerberg alexander.widerberg@cybercom.com
Nothing published for this version
all: resolve race condition and package fosite with glide
all: resolve race condition and package fosite with glide
Nothing published for this version
vendor: commit missing lock file
vendor: updated go-jwt to use semver instead of gopkg
vendor: updated go-jwt to use semver instead of gopkg
core: remove unused fields and methods from client
Nothing published for this version
all: composable factories, better token validation, better scope handling and simplify structure
all: composable factories, better token validation, better scope handling and simplify structure
Breaking changes:
ValidateRequestAuthorization is now Validate
and does not require a http request but instead a token and a token hint. A
token can be anything, including authorization codes, refresh tokens, id
tokens, ...fosite) has been removed as it
has proven impractical.scope instead of
granted_scopes when using the DefaultClient.core/client or oidc/explicit have been merged
and moved one level uphandler/oidc is now handler/openidhandler/core is now handler/oauth2oauth2: implicit handlers do not require tls over https
oauth2: implicit handlers do not require tls over https (#61)
closes #60
Add -d option to go get (0e63038)
Define implicitHandler (745a4df):
Someone forgot to rename the variable name when copy-pasting in the example.
Document new token generation and validation (ddef55b)
Drafted workflows (4ad1d14)
Explain what handlers are (48ca03b)
Fix typos in readme (b9ed7ac)
Readme (a5aa697)
Readme (f77fd41)
Readme (e143d8c)
Readme (d483568)
Updated authorize section (9c21afb)
Updated readme docs (336a2cd)
updated gif (39c239f)
gofmt (f813288)
updated example gif (29b39ea)
added open id connect to example (6f0ce68)
added integration tests (8d47f80)
added doc to fix travis (a0db129)
Add go report card (204c5d6)
Clean-up fosite-example/main.go link in README.md (497ff80):
The README url to the suggested example was broken.
Added jti as parameter to claims helper to privide better interface to developers (bde3822)
Added missing jti claim (26f41a0)
Added NOTE (64516f8)
Removed unnecessary print. Added bugfix from Arekkas. (96458b6)
Example updated (5022339)
Added working example of jwt token (9410fca)
Added tests. Still need to verify implemtation with test (1ebdd88)
WIP (caaa43a)
readme (c97d844)
readme (fe24f26)
readme (be8cd23)
refactor done (unstaged) (625f168)
unstaged (6c616b1)
unstaged (17ad70b)
Include user session data in all calls to storage handlers. (2be3fc1)
unstaged (fde7c80)
unstaged (e775aad)
unstaged (ae2fc16)
handler/core: fixed tests (7f5938a)
core handlers: added tests (e9affb7)
authorize/explicit ✓ (d61635b)
authorize/explicit: minor name refactoring and tests for authorize endpoint (4736e28)
plugin/token: fix import path (fdba2f7)
unstaged (f939597)
Initial commit (7adad58)
Access code request workflow finalized (0232918)
Access request api draft (9f482ef)
Add api stability section (3ca6ec9)
Add go-rethink tags (49c82bc)
Add ValidateToken to CoreValidator (4c2b9d8)
Added authorize code grant example (269c5fa)
Added client grant and did some renaming (75c8179)
Added cristiangraz to the hall of fame (1b6e2b4)
Added danielchatfield to the hall of fame (2b988a8)
Added go 1.6 (ae41a0a)
Added go1.4 to allowed failures (49aa920)
Added grant and response type validation (f524fc2)
Added json and gorethink tags (99c836c)
Added missing file (8fc1615)
Added owner method (78012ed)
Added tests fragment capabilities to writeresponse (6df0eca)
Api cleanup, gofmt (3d6e8b6)
Api refactor (d936c91)
Basic draft (480af91)
Defined OAuth2.HandleResponseTypes (30b6e74):
Incorporated feedback from GitHub, did refactoring and renaming, added tests
Enforce https for all redirect endpoints except localhost (d65b45a)
Finalized auth endpoint, added tests, added integration tests (c6dcb90)
Finalized token endpoint api (8de3f10)
Finished up integration tests (a6d027e)
Fix broken test (653e324)
Fix config (82e9332)
Fix deps (bcc6a07)
Fix unique scope tests (3ac3a79)
Fixed granted scope match (13b7efa)
Fixed racy tests (f0b691d)
Fixed tests (8bf73e3)
Fixed tests refactor broke (5da857b)
Fixed urls (58908b8)
Fixed wrongfully set constant ErrTemporaryUnvailableName (71a9105), closes #9
Generic claims and headers (1f2e97f)
Godep save (c457104)
Goimports (8b9816c)
Goimports (96be194)
Implemented all core grant types (ce0a849)
Implemented and documented examples (8c625c9)
Implemented new token generator based on hmac-sha256 (01f9ede), closes #11
Implemented validator for access tokens (4140422)
Implicit handlers do not require tls over https (#61) (6c40c08), closes #60
Improve handling of expiry and include a protected api example (dfb047d)
Improve strategy API (21f5e8c)
Increased coverage (83194b6)
Issue refresh token only when 'offline' scope is set (34068b9), closes #47
Made hybrid flow optional (08ddbae)
Major refactor, use enigma, finalized authorize skeleton (38bacd3), closes #8 #11
More test cases (1188750)
More tests (164506a)
Moved to root package, updated docs (1871702)
Moved to root package, updated docs (5b9b20c)
No "session" secret required (d1f45ad)
Preview (ba84987)
Refactor (eb9153c)
Refactor, fixed tests, incorporated feedback (9e59df2)
Refactoring, more tests (df79a81)
Refactoring, renaming, docs (e5476d1)
Refactoring, renaming, more tests (9467ca8)
Remove duplicate field (e134351)
Remove store mock (80c14f7)
Rename fields name to client_name and secret to client_secret (99ce066)
Renaming and refactoring (d3697bd)
Replace pkg.ErrNotFound with fosite.ErrNotFound (4390c49)
Request should return unique scopes (af66918)
Resolve an issue where query params could be used instead of post body (7eb85c6)
Resolve danger of not reading enough bytes (c68a3e9)
Resolve id token issues with empty claims (89c60c9)
Resolve scope issues (#55) (9d54b98):
handler: resolve scope issues
Sanitized tests and apis (12c70bb)
Tests for client credentials flow (c13298c)
Tests for resource owner password credentials grant (f503615)
Update (88e84de)
Updated example and added implicit grant (d12fa5c)
Use jwt-go.v2 and fix bc break (f731d88)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →