NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #178 by repository stars
Last release 4 years ago
no release in 18 months
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
3599 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
docker: Update compose definitions
docker: Update compose definitions (#1020)
Signed-off-by: arekkas aeneas@ory.am
Accept expired JWTs as id_token_hint (#1017) (67346d3), closes #1014
Add new methods to SDK interface (#994) (fed7823), closes #991
Clarify HYDRA_ADMIN_URL in missing endpoint message (#1018) (cf20b4f), closes #1016
Disable CORS by default (#997) (251bd5c), closes #996:
This patch introduces environment variable CORS_ENABLED which toggles CORS.
Disable plugin backend through 'noplugin' tag (#986) (96f4cb3):
Debugging Hydra in Go 1.10 and 1.11 (confirmed by one of its members), is not possible due to this unresolved bug which is related to the use of the plugin functionality.
This change allows passing a build tag which will disable plugin implementation and therefore allow to debug in all the use-cases where plugin backend is not needed.
Enable client specific CORS settings (#1009) (a36d0af), closes #975:
Field allowed_cors_origins was added to OAuth 2.0 Clients. It enables
CORS for the whitelisted URLS for paths which clients interact with,
such as /oauth2/token.
Fix use of uninitialized logger (#1015) (6549f1e):
The MustValidate() function is sometimes called before any other logging function has been called and this results in a crash. An easy way to reproduce the crash is to change OAUTH2_ACCESS_TOKEN_STRATEGY=jwt in the default docker-compose.yml
Forward session and login information (2217103), closes #1003:
Consent and login requests now carry context information for previous requests.
Populate consent session with default values (#989) (c67b7fe), closes #988
Public subject type should cause public id alg (#993) (3040c0f), closes #992
Remove config option (5292f6c)
Resolve broken expiry when refreshing id token (#1002) (c72e64c), closes #985
Upgrade to new fosite compose API (480904f)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Deprecate public flag (8f71806), closes #938:
consent: Add logout api endpoint (#984)
Closes #970
Signed-off-by: Michael DeRazon mderazon@gmail.com Signed-off-by: arekkas aeneas@ory.am
unstaged (5ca384d)
unstaged (5026bfb)
Use spdx expression for license in package.json (c2a9ca4)
Add AdminURL and PublicURL to configuration (191902d)
Add and enhance access/refresh token tests (e79014d):
This patch introduces more tests for code and refresh flows and the JWT strategy.
Add api endpoint to list all authorized clients by user (#954) (7aace33), closes #953
Add flags for newly introduced oidc client settings (c4b902d), closes #938
Add ListUserConsentSessions to OAuth2API interface (#977) (1bd8ab7)
Adds JWT Access Token strategy (c932ab4), closes #248:
This patch adds the (experimental) ability to issue JSON Web Tokens instead of ORY Hydra's opaque access tokens. Please be aware that this feature has had little real-world and unit testing and may not be suitable for production.
Simple integration tests using the JWT strategy have been added to ensure functionality.
To use the new JWT strategy, set environment variable OAUTH2_ACCESS_TOKEN_STRATEGY to jwt. For example: export OAUTH2_ACCESS_TOKEN_STRATEGY=jwt.
Please be aware that we (ORY) do not recommend using the JWT strategy for various reasons. If you can, use the default and recommended "opaque" strategy instead.
Adds subject_type support to oidc discovery (78e6552), closes #950
Deprecate public flag (8f71806), closes #938:
The public flag has been deprecated in favor of setting token_endpoint_auth_method=none.
Deprecate field id, now only client_id is to be used (a8b9b02)
Expose ./well-known/jwks.json on public port (e30d48b)
Fix 2-port tests and improve upgrade guide (f32c97e)
Fix reporting of epected vs. received status codes (#961) (8632a2e):
Asking for a non-existent client results in the following confusing error message:
Command failed because calling "GET http://hydra:4444/clients/no-such-client" resulted in status code "200" but code "404" was expected.
{"error":"Unable to locate the resource","error_description":"","status_code":404}
This commit fixes the expectedStatusCode and response.StatusCode arguments to fmt.Fprintf which were reversed.
Improve "token user" flag defaults (2172bc0)
Improve CLI tests (ba34b0c)
Improve client help messages (8c08f41)
Improve memory manager error messages (#978) (5093152), closes #976
Improve token endpoint authentication error message (6885a3f)
Introduce pairwise support (479acd7), closes #950:
This patch introduces the OpenID Connect pairwise Subject Identifier Algorithm.
Introduce public and administrative ports (cfee3eb), closes #904:
This patch introduces two ports, public and administrative. The public port is responsible for handling API requests to public endpoints such as /oauth2/auth, while the administrative port handles requests to JWK, OAuth 2.0 Client, and Login & Consent endpoints.
Introduce subject type algorithm configuration (fdd3bb2), closes #950
Introduce SubjectType to OAuth2 Clients (e99d820), closes #950
Make test-e2e-plugin.sh executable (299928f)
Print "active:false" when token is inactive (#981) (2227691), closes #964:
Previously, omitempty caused active to be omitted when set to false.
Properly identify revoked login sessions (f143949), closes #944
Refactor backend connectivity and bootstrap process (#956) (4ea7496), closes #949:
This patch introduces a new backend interface and improves the plugin loading system.
Refactor OAuth2 JWT strategy as an interface (#972) (e4e3163)
Removes authorization from introspection (17e6311)
Resolve benchmark build issues (2663d42)
Resolve broken tests caused by public flag removal (1a2250d)
Resolve remaining benchmark issue (7d4b708)
Resolves panic when network fails (7fe4a21)
Return proper error when no consent was found (#980) (8c1a290), closes #959
Share error details with redirect fallback (#982) (123e37e), closes #974
Update .dockerignore (98d85d5)
Upgrade superagent to 3.7.0 (ff68f28)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →