NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #178 by repository stars
Last release 4 years ago
no release in 18 months
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
3599 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add OpenID Certification badge and info
docs: Improve badge placement
Fix docker linux link (#920) (694b483):
The old one 404's
Improve badge placement (49faed8)
Incorporates changes from version v1.0.0-beta.6 (ab04898)
id field (35bf581), closes #924Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
vendor: Updates vendor lockfile
vendor: Updates vendor lockfile
Signed-off-by: arekkas aeneas@ory.am
Add method that forces the endpoint url to be set (17903c6)
Allows import of PEM/DER/JSON encoded keys (312f8d1), closes #98
Fix sql migration step for oidc (#919) (ad5e8bc), closes #918:
A bug was introduced in beta.5 which caused the SQL migrations to fail if data existed in the database already. This patch resolves that and adds test cases for the migration steps by adding data after each migration.
Resolves minor issues in the HTTP handler (3bbd5e8)
Updates vendor lockfile (a6ec396)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
oauth2: Removes tokens when consent is revoked
oauth2: Removes tokens when consent is revoked
Closes #856
Signed-off-by: arekkas aeneas@ory.am
Adds ability to define default client scopes (215bef3):
Environment variable OIDC_DYNAMIC_CLIENT_REGISTRATION_DEFAULT_SCOPE was added in order to better implement the OpenID Connect Dynamic Client Registration protocol. The mentioned protocol does not support the concept of whitelisting OAuth 2.0 Scope on a per-client basis. Therefore, the functionality to define the default OAuth 2.0 Scope has been defined.
Keep in mind that exposing the OpenID Connect Dynamic Client Registration functionality to the public effectively disables the OAuth 2.0 Scope whitelisting functionality, as each caller of that API can define which OAuth 2.0 Scope a client may request.
If you decide to expose that functionality, you should NEVER assume that the granted OAuth 2.0 Scope has any meaning when handling requests at your consent endpoint, or when validating requests with tokens issued by the client_credentials flow.
Adds ability to revoke consent and login sessions (8780c03), closes #856
Adds jwk rotation and improves jwk codebase (a463d23)
Adds parameter broadcast to oidc discovery (1580677)
Adds private_key_jwt authentication method (259d63a)
Adds sector identifier URL (bfc9d09)
Adds userinfo tests (04929d0)
Better error detection in jwt key strategy (a0ac323)
Bumps fosite to request error handling (734f64d)
Bumps fosite version (92172b1)
Declares grant type refresh_token as supported (6837046)
Disallow fragments in client's redirect uri (457b877)
Do not re-use kid when rotating key (7b39d2b)
Do not recreate keys when refreshing (09d3ec7)
Enforces proper error layout (e38891a)
Exposes proper oidc configuration (8f2e931)
Fixes broken SDK test (0e85594)
Fixes typo in swagger docs (6c6fb3c)
Implements dynamic client registration (ad86dd1)
Implements oidc compliant response_type validation (8f1515a)
Implements proper refreshing strategy (1d02cae)
Implements userinfo response signing (bc0b54c)
Improves and DRYies validation in the handler (a689cb0), closes #909
Improves error response style (725c075)
Improves jwk generation error message (45d769a)
Improves key rotation logic (d25766c)
Improves oauth2 fallback endpoints (0704589)
Includes fosite's id_token bugfix (9ef48fa)
Keep id as alias to client_id (f344d10)
Key rotation does not rename keys (53ce537)
Properly instantiates client handler (a40cc49)
Properly return errors when resource not found (200aa81)
Refresh signing keys (7f495e3)
Removes broken instruction (ead9b97)
Removes buggy rotate command and improves jwk refresh (e41fcf2)
Removes nesting from error responses (d511cf8)
Removes tokens when consent is revoked (00fd517), closes #856
Renames id to client_id in response payload (97b7ac1):
Previously, a client's id was sent as field id. This patch renames field id to client_id as mandated by spec: https://openid.net/specs/openid-connect-discovery-1_0.html
Resolves issue where stack traces can't be recovered (92acfe4)
Resolves minor test issues (7399eef)
Resolves MySQL timing issue in tests (60d39fe)
Resolves well-known test issues (ffefb74)
Simplify error helper (91c06f0)
Support other signing algorithms than RS256 (072b88b)
Tests for simple equality in JWT strategy (95c96a0)
Updates vendored dependencies (4b138dc)
Updates vendored dependencies (87aae5f)
Uses proper jwt strategy in oauth2 factory (45e4439)
Uses RFC6749 errors everywhere (543e6bc)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →