NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #178 by repository stars
Last release 4 years ago
no release in 18 months
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
3599 releases · first in 2015
Nothing published for this version
Deprecates connect command and introduces configurable credentials (0b5f466), closes #841 #840:
docs: Add oidc conformity docs
Tells linguist to ignore SDK files (e10016c)
Tells linguist to ignore SDK files (f7f010a)
Merge remote-tracking branch 'origin/master' into 1.0.x (052ee83):
cmd/server: Adds SQL consent DBAL configuration (50e5509)
cmd/server: Shortens long banner message (78be474):
The original banner message was way to big and cluttered logs a lot. This patch reduces the banner's size significantly.
Removes policy, warden and groups from this project (3d0bf0b), closes #807:
We have learned a lot over the last year in terms of how ORY Hydra is being used. Initially, we wanted to avoid the problems facing popular databases like MongoDB or others, which did not include authentication for their management APIs.
For this reason, the Warden API was born and primarily used internally and exposed via HTTP. We learned that access control policies are well received, but also add additional complexity to understanding the software. While we firmly believe that these policies implement best practices for access control in complex systems, we do understand that they add a barrier to getting started with ORY Hydra.
For this reason we are planning on moving the Warden API from this project to ORY Oathkeeper or potentially it's own server. We would add a migration path for existing policy definitions to the new service. The default docker image would combine the services in such a way, that ORY Hydra is protected. We would additionally have an (insecure) docker image without authentication which can be used for testing.
This also opens up the possibility of having more access control mechanisms than access control policies. For example, we can add ACL and RBAC and other mechanisms too.
First I think it makes good sense to move this functionality into a separate service and remove the warden calls internally completely. The reason being that not everyone wants to rely on Hydra's access control. Sometimes it's enough to use a gateway in front and require e.g. an API key for management or whatever. New adopters are always baffled by complexity involved with policies and scopes. Removing that from the core could really help. The user survey has also shown that this stuff is quite complex to grasp.
The idea is to have a separate service which is basically ladon as a HTTP API. I think it makes sense to add some functionality to resolve access tokens so it would basically be very similar to the current warden API - probably even equal. There would definitely be some backup mode where hydra's database tables and migrations are used as to make migration as easy as possible.
Then, we would ship docker images and example set ups where different configurations are shown. One of the configurations would be the current one, so basically what we have now in hydra but with the three services combined in one image.
Add experimental detection of SQL error (051a4b9):
Returns a human-readable error for SQL errors.
Adds additional tests for prompt, max_age, id_token_hint (3ef32e2)
Adds authN session revokation on specific errors (11d1497), closes #854 #855
Adds e2e tests for authorize code flow (0a9ae28)
Adds e2e tests for authorize code flow (68e006b)
Adds endpoint flag to token introspection (9d27d47)
Adds id_token_hint_claims to oidc_context (0e84341)
Adds jwt strategy and fixes nil pointer exception (e608739)
Adds more strategy tests (99fd63b)
Adds mutex to memory manager (6a60c45)
Adds new prometheus metrics and metrics endpoint (#827) (ef94f98)
Adds port 4445 to docker-compose example (576ac55)
Adds test cases for prompt parameter (c83cb3f)
Adds tests for prompt and max_age handling (82310ff)
Adds welcome screen to token user command (5a7c73b)
Aligns issuer URL from well known with one from id token (f739045)
Always bust auth session if remember is false (78e2bff), closes #859
Always bust auth session if remember is false (b2725a7), closes #859
Correct docker exec wording (cbb01d2):
exec is an nsenter, not an ssh
Declare auto-generated key as use:sig (9d489dd)
Deprecates connect command and introduces configurable credentials (0b5f466), closes #841 #840:
This patch deprecates the hydra connect command as internal
access control has been removed from ORY Hydra and this command
no longer serves any purpose.
Instead, all commands are supplied with environment variables HYDRA_URL,
OAUTH2_CLIENT_ID, OAUTH2_CLIENT_SECRET, OAUTH2_ACCESS_TOKEN.
Please check out hydra help <command> for usage instructions. You
should also check out the upgrade guide for more detailed upgrade instructions.
This patch also renames some flags and command names which have been documented in the upgrade guide.
Detect and handle max_age/prompt in consent strategy (af2b8e4)
Do not fail if max_age is very low but satisfied (127561c), closes #862
Formats and resolves missing test (3db984d)
Handle empty error as nil error in SQL helper (6a9a0c0)
Handles auth time across login & consent flow (3accccd):
This patch improves the handling of auth_time and thus resolves issues with prompt & max_age handling within fosite.
Handles consent error properly in SQL DBAL (b1c2a39)
Handles OAuth2 errors in token user command properly (720adce)
Ignores JTI in userinfo (f2ef5b1)
Improves API route naming (da5026c)
Improves auth_time handling (538bfb9)
Improves the consent flow design (a002e30), closes #771 #772:
This patch makes significant changes to the consent flow. First, the consent flow is being renamed to "User Login and Consent Flow" and is split into two redirection flows, the "User Login Redirection Flow" and the "User Consent Flow".
Conceptually, not a lot has changed but the APIs have been cleaned up and the new flow is a huge step towards OpenID Connect Certification.
Besides easier implementation on the (previously known as) consent app, this patch introduces a new set of features which lets ORY Hydra detect previous logins and previously accepted consent requests. In turn, the user does not need to login or consent on every OAuth2 Authorize Code Flow.
This patch additionally lays the foundation for revoking tokens per user or per user and client.
Awesome.
Improves the token user command (9bde521)
Includes error debug message in token user command (3f80d4e)
Introduces client_secret_expires_at to client metadata (#870) (56aa5d2), closes #778:
This patch introduces the client_secret_expires_at field without any functionality but to comply with the IETF spec.
Moves templates to .github (ba8f4f7)
Properly handle id_token error response (28d3fcd)
Properly handle requestedAt across the login/consent flow (fccfc4d)
Properly handles no result errors from consent check (12aa6c5)
Properly import mysql/pg drivers (669f134)
Properly initializes consent strategy (196925f)
Properly uses issuer in JWT (1940c3c)
Rejects reqeuests with insufficient permissions (7675144), closes #776:
Currently, authorization requests fail when a client is being granted scopes that the client is not allowed to request - after consent.
We should add an additional check that makes sure that the client isn't able to request scopes he isn't allowed to request before doing consent.
We should keep the check after consent as well to make sure he wasn't accidentally granted scopes he isn't allowed to request.
This patch resolves the addressed issue
Rejects requests without nonce in implicit/hybrid (39a72c0), closes #867
Remove client secret from consent/login response (acf9893), closes #878
Remove rat (requested_at) from userinfo endpoint (d091914)
Remove unused code (bcdc278):
This code was meant to be deleted in 9592a0069ed4b851cec8591038f9be5ce6d81a28 I believe.
Remove unused named returns (3977b94)
Removes access control relics (a4d2e73)
Removes duplicate / in .well-known (e387aea)
Removes stale code (c730e36)
Removes the forced hydra.* scope in the SDK (8c1adc3)
Removes the need to specify OAuth2 credentials in config (#869) (98044aa)
Removes unused code and updates go dep (d72efbf)
Renames --scopes flag to --scope (a948211)
Replaces internal dockertest with sqlcon (5cbf121)
Requests re-permission only custom schemes are used (929f2f0), closes #866
Resolves broken consent detection (a7949ed)
Resolves broken reference in e2e test (da4334b)
Resolves broken SDK test (476dff1)
Resolves broken well-known test (aa01423)
Resolves consent DBAL type conversion issues (6edfe76)
Resolves e2e test issues (1a8a3b3)
Resolves flaky MySQL tests on Circle-CI (fcd9180), closes #861
Resolves issue with duplicate login session id (14aae6a)
Resolves issues with broken tests (526e3a7)
Resolves issues with e2e tests (ff15dc5)
Resolves issues with SQL and time.Zero() (ad2c1c5)
Resolves mutex issues (9376b74)
Resolves test issues (ba81fdf)
Resolves timing issues in broken tests (540ccc9)
Resolves timing issues in slow tests (246e491)
Resolves type mixup (7e05c26)
Resolves typo in issue template (204886c)
Resolves typo in issue template (8c32d93)
Resolves various issues related to audience claims (7afed88), closes #790 #687:
This patch resolves issues related to the ID and Access Token audience claim:
Resolves various issues related to revokation (608cc3d), closes #884 #693 #889:
This patch properly tracks access and refresh tokens across requests and thus resolves several issues related to broken token revokation:
Returns an error if skip is used together with remember (6f8cef6):
Previously, it was possible to remember an already remembered consent/login request. This patch resolves that.
Returns error on duplicate key in memory manager (abe54ca)
Returns token type on introspection (#832) (bf226dc):
This patch adds the ability to return the token type ("refresh_token", "access_token") upon token introspection.
Returns token type on token introspection (da6bb30), closes #831
Reverts 307 change (66304eb)
Reverts 307 change (425b33d)
Runs gofmt (126f0e0)
Runs gofmt (a88c499)
Separates between readiness and aliveness (fd289c0), closes #887
Trim left slash from userinfo endpoint (a7edf63)
Updates auth-time to resolve timing issues (6aff825)
Updates dependencies (49b9a72)
Updates entrypoint command from host to serve (2230ce6)
Updates fosite version to 0.19.2 (eb0c3e6)
Updates issue template (63aec91)
Updates issue template (915a20b)
Updates to fosite 0.19.x (1942715)
Updates to latest sqlcon version (92e8d58)
Upgrades fosite dependency (5fccb80)
Upgrades fosite dependency to 0.20.2 (7acd9bf)
Use 307 instead of 302 to redirect (2b43ce3)
Use 307 instead of 302 to redirect (f4962c6)
Use existing alpha-lower sequence (93fb772)
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →