NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #178 by repository stars
Last release 4 years ago
no release in 18 months
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
3599 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Please be aware that deprecated configuration flags have finally been removed with this change. It is also possible that ORY Hydra might complain abou…
We are excited to present the next big step towards ORY Hydra 1.9! In this release we completely refactored the configuration internals and moved from spf13/viper to knadh/koanf:
--config flag now possible.Please be aware that deprecated configuration flags have finally been removed with this change. It is also possible that ORY Hydra might complain about an invalid configuration due to a significantly improved validation process.
In addition, this release includes the new OpenID Connect Conformity Test Suite as part of the ORY Hydra CI pipeline. This means every PR and change will be checked for OpenID Connect Compliance. As part of these tests, we uncovered some regression issues which have since been resolved. Please be aware that fields error_hint and error_debug will no longer be sent. You can re-enable those legacy fields by setting oauth2.include_legacy_error_fields to true.
Furthermore, support for OpenID Connect flows response_mode=form_post was added and has been tested with the OpenID Connect Conformity Test Suite, making it ready for production.
Several other bugs have been resolved and we have completely overhauled the tests, deprecating test tables in favor of test suites. This greatly improves the readability of our tests and allows new contributors to more easily understand what is going on!
If you wish to get into ORY Hydra, check out the newly published YouTube tutorial:
After battling with spf13/viper for several years we finally found a viable alternative with knadh/koanf. The complete internal configuration infrastructure has changed, with several highlights:
--config flag.Please be aware that deprecated configuration flags have finally been removed with this change. It is also possible that ORY Hydra might complain about an invalid configuration, because the validation process has improved significantly.
This patch requires running SQL Migrations. Please be aware that a NOT NULL column is being dropped which could require a lot of time when the authentication_session table contains a lot of data.
This patch removes error_hint and error_debug fields from OAuth2 responses. These are now all merged into error_description which is according to the OAuth2 and OpenID Connect specification. If you wish to keep the old behavior around, set oauth2.include_legacy_error_fields to true in your ORY Hydra configuration.
Applying this patch requires running SQL migrations. The SQL migrations will remove a UNIQUE constraint and add new INDEX to several tables which should speed up certain operations. Please be aware that this might cause certain databases to lock which could be problematic if there are many rows affected.
This changes the OAuth2 Token Introspection response to ensure compliance with the OAuth2 Token Introspection specification. Previously, token_type would return access_token or refresh_token. The specification however mandates that token_type is always Bearer. This patch resolves that issue. The previous behaviour of token_type has now been moved to token_use which can be access_token or refresh_token.
Add encrypt_at_rest option to config schema (3219c16)
Add required aud, jti claims to userinfo response (d0697fa)
Add standardized client registration errors (02a9137):
Adds new errors to fully comply with the OpenID Connect Dynamic Client Registration specification.
Allow all request object signing algs per default (edc54c2):
This patch resolves an issue where RS256 would be the only allowed request object signing algorithm. The spec however mandates that all algorithms are allowed if the client does not explicitly set the request object signing algorithm.
Allow lower bcrypt values and add tests (812a21c)
Ensure consistent auth_time in session handling (e973ffe)
Increase parallelism to 4 (ae02706)
Mark false gosec positive (206d1ee)
Nonce is not required for hybrid flows (c708ada)
Quickstart yml (5ebd984)
Remove session from store on logout (4495f56):
This patch resolves an issue where the session would not be purged from the store when performing an RP-initiated logout request from a client, if said client does not purge the authentication session properly because the client does not have access to it or because the client misbehaves.
Remove unrelated quickstart entry (#2214) (a583d78), closes #2213
Request_id should not be unique (a8ca333):
This patch resolves an issue where certain OpenID Connect Hybrid flows would error with a UNIQUE violation. The cause of this issue was an incorrect UNIQUE constraint on the request_id field of the access, refresh, pkce, and other, similar tables.
Resolve broken quickstart (95a1dfb)
Update deprecated config in quickstart (1c1433a)
Update invalid quickstart config (8d076a5)
Update package lock (18bfc96)
Update schema to support new koanf (29763c8)
token_type to token_use in introspection (152fd5d), closes #1762Add config debug section (c53f036)
Add contributing to sidebar (#2209) (21f3b1f):
Added Contributing Guidelines to the introduction menu point on the sidebar. I think it should be as obvious as possible. Another good solution would be to add them to the top bar?
If this is merged, I will do the same changes for Kratos/Oathkeeper/Keto.
Add newsletter banner (5b63aa4)
Deps are installed automagically and make deps was removed (#2157) (25e96e2), closes #2154
Minor improvements to the concepts/consent page (#2168) (1128cfc)
Use codefromremote for consent samples (51c0874)
Add ability to override oidc discovery urls (bb8b982):
Added config options webfinger.oidc_discovery.token_url, webfinger.oidc_discovery.auth_url, webfinger.oidc_discovery.jwks_url.
Add new request_object_signing_alg_values_supported to oidc discovery (4220959)
Add oidc conformity tests (651f424)
Improve and clean up error handling (b727367)
Improve error responses for consent handler (44ab747)
Improve error stack trace wrapping (fdf142c)
Only set state-param if it was passed (#2183) (568434a):
Using state in the logout flow is optional, so state can be empty. In order to avoid an ugly /post-logout-redirect-uri?state= URI, the state should only be appended if it is not empty.
Remove legacy error fields unless configured to do so (e2a7135)
Support OpenID Connect's response_mode=form_post (8ab9eff), closes #1621:
This patch adds support for the response_mode parameter as defined in OAuth 2.0 Form Post Response Mode. Additionally, values fragment and query are supported as defined in OAuth 2.0 Multiple Response Type Encoding Practices.
Support pkger (07a360e)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →