NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #681 by repository stars
Last release 10 months ago
20 Nov 2025
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
1103 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: be more permissive in time checks
fix: be more permissive in time checks
Time equality should not cause failures in OpenID Connect validation.
This patch removes fields error_hint, error_debug from error responses. To use the legacy error format where these fields are included, set UseLegacyErrorFormat to true in your compose config or directly on the Fosite struct. If UseLegacyErrorFormat is set, the error_description no longer merges error_hint nor error_debug messages which reverts a change introduced in v0.33.0. Instead, error_hint and error_debug are included and the merged message can be constructed from those fields.
As part of this change, the error interface and its fields have changed:
RFC6749Error.Name was renamed to RFC6749Error.ErrorField.RFC6749Error.Description was renamed to RFC6749Error.DescriptionField.RFC6749Error.Hint was renamed to RFC6749Error.HintField.RFC6749Error.Code was renamed to RFC6749Error.CodeField.RFC6749Error.Hint was renamed to RFC6749Error.HintField.RFC6749Error.WithCause() was renamed to RFC6749Error.WithWrap() *RFC6749Error and alternatively to RFC6749Error.Wrap() (without return value) to standardize naming conventions around the new Go 1.14+ error interfaces.As part of this change, methods GetResponseMode, SetDefaultResponseMode, GetDefaultResponseMode where added to interface AuthorizeRequester. Also, methods GetQuery, AddQuery, and GetFragment were merged into one function GetParameters and AddParameter on the AuthorizeResponder interface. Methods on AuthorizeRequest and AuthorizeResponse changed accordingly and will need to be updated in your codebase. Additionally, the field Debug was renamed to DebugField and a new method Debug() string was added to RFC6749Error.
Co-authored-by: hackerman 3372410+aeneasr@users.noreply.github.com
Allow all request object algs when client value is unset (1d14636):
Allows all request object signing algorithms when the client has not explicitly allowed a certain algorithm. This follows the spec:
*request_object_signing_alg - OPTIONAL. JWS [JWS] alg algorithm [JWA] that MUST be used for signing Request Objects sent to the OP. All Request Objects from this Client MUST be rejected, if not signed with this algorithm. Request Objects are described in Section 6.1 of OpenID Connect Core 1.0 [OpenID.Core]. This algorithm MUST be used both when the Request Object is passed by value (using the request parameter) and when it is passed by reference (using the request_uri parameter). Servers SHOULD support RS256. The value none MAY be used. The default, if omitted, is that any algorithm supported by the OP and the RP MAY be used.
Always return non-error response for inactive tokens (#517) (5f2cae3)
Be more permissive in time checks (839d000):
Time equality should not cause failures in OpenID Connect validation.
Do not accidentally leak jwks fetching errors (6d2092d), closes /github.com/ory/fosite/pull/526#discussion_r517491738
Do not require nonce for hybrid flows (de5c8f9):
This patch resolves an issue where nonce was required for hybrid flows, which does not comply with the OpenID Connect conformity test suite, specifically the oidcc-ensure-request-without-nonce-succeeds-for-code-flow test.
Guess default response mode in NewAuthorizeRequest (a2952d7)
Improve claims handling for jwts (a72ca9a)
Improve error stack wrapping (620d4c1)
Kid header is not required for key lookup (27cc5c0)
Only use allowed characters in error_description (431f9a5), closes #525:
Replace LF and quotes with . and ' to match allowed and recommended character set defined in various RFCs.
Prevent debug details from leaking during key lookup (c0598fb), closes /github.com/ory/fosite/pull/526#discussion_r517490461
Reset jti and hash ID token claims on refresh (#523) (ce2de73)
Use state from request object (8cac1a0):
Resolves failing OIDC conformity test "oidcc-request-uri-unsigned".
Add support for response_mode=form_post (#509) (3e3290f):
This patch introduces support for response_mode=form_post as well as response_mode of none and query and fragment.
To support this new feature your OAuth2 Client must implement the fosite.ResponseModeClient interface. We suggest to always return all response modes there unless you want to explicitly disable one of the response modes:
func (c *Client) GetResponseModes() []fosite.ResponseModeType {
return []fosite.ResponseModeType{
fosite.ResponseModeDefault,
fosite.ResponseModeFormPost,
fosite.ResponseModeQuery,
fosite.ResponseModeFragment,
}
}
Introduce WithExposeDebug to error interface (625a521)
Support passing repeated audience parameter in URL query (#518) (47f2a31), closes #504:
Added GetAudiences helper function which tries to have current behavior and also support multiple/repeated audience parameters. If there are parameter is repeated, then it is not split by space. If there is only one then it is split by space. I think this is the best balance between standard/backwards behavior and allowing repeated parameter and allowing also URIs/audiences with spaces in them (which we probably all agree is probably not something anyone should be doing).
Also added ExactAudienceMatchingStrategy which is slightly more suitable to use for audiences which are not URIs. In OIDC spec audience is described as:
Audience(s) that this ID Token is intended for. It MUST contain the OAuth 2.0 client_id of the Relying Party as an audience value. It MAY also contain identifiers for other audiences. In the general case, the aud value is an array of case sensitive strings. In the common special case when there is one audience, the aud value MAY be a single case sensitive string.
client_id is generally not an URI, but some UUID or some other random string.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
autogen(docs): regenerate and update changelog
autogen(docs): regenerate and update changelog
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →