NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #178 by repository stars
Last release 4 years ago
no release in 18 months
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
3599 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
oauth2: Resolves failing SQL store test cases
oauth2: Resolves failing SQL store test cases
Use packagist to get hydra sdk (383b267)
Generate php sdk and point php autoloader to lib folder (e2f8756):
Add docs/sdk/php.md
Resolves client secrets from potentially leaking to the database in cleartext (#820) (848d479):
This release resolves a security issue (reported by platform.sh) related to the fosite storage implementation in this project. Fosite used to pass all of the request body from both authorize and token endpoints to the storage adapters. As some of these values are needed in consecutive requests, the storage adapter of this project chose to drop all of the key/value pairs to the database in plaintext.
This implied that confidential parameters, such as the client_secret which can be passed in the request body since fosite version 0.15.0, were stored as key/value pairs in plaintext in the database. While most client secrets are generated programmatically (as opposed to set by the user) and most popular OAuth2 providers choose to store the secret in plaintext for later retrieval, we see it as a considerable security issue nonetheless.
The issue has been resolved by sanitizing the request body and only including those values truly required by their respective handlers. This also implies that typos (eg client_secet) won't "leak" to the database.
There are no special upgrade paths required for this version.
This issue does not apply to you if you do not use an SQL backend. If you do upgrade to this version, you need to run hydra migrate sql path://to.your/database.
If your users use POST body client authentication, it might be a good move to remove old data. There are multiple ways of doing that. Back up your data before you do this:
hydra_oauth2_refresh, hydra_oauth2_access, hydra_oauth2_oidc,
hydra_oauth2_code. This implies that all your users have to re-authorize.form_data in tables hydra_oauth2_refresh, hydra_oauth2_access with
an empty string. This will keep all authorization sessions alive. Tables hydra_oauth2_oidc and hydra_oauth2_code
do not contain sensitive information, unless your users accidentally sent the client_secret to the /oauth2/auth endpoint.We would like to thank platform.sh for sponsoring the development of a patch that resolves this issue.
Resolves failing SQL store test cases (f6ddee8)
Resolves issue with godep, fosite memory store (6ab7260):
This issue solves a broken update with godep and properly includes the 0.17.0 fosite patch.
Uses UTC timecodes everywhere (45eabc2)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This patch resolves a vulnerability in the consent flow. This vulnerability affects versions 0.10.0 ~ 0.11.5 only. Versions < 0.10.0 are not affected.
pkg: remove unused code
This code was meant to be deleted in 9592a0069ed4b851cec8591038f9be5ce6d81a28 I believe.
Signed-off-by: Euan Kemp euank@euank.com
Adds "Edit on GitHub" link to each document in guide (ec6f000)
Changes readme title" (122f7d1)
Clean up swagger specification (2ad0a96)
Experiments with domain redirect (2604b99)
Fixes dead link to example policy (#767) (4f3148e):
The policy linked to as an example has since been removed. Just point to a different policy instead.
Fixes redirect path (d05c97b)
Forwards docs to website (560441d)
Improves API docs (5a2e4df)
Incorporates changes from version v0.11.4 (6bf7e80)
Lowercase source files and dirs (6a56630)
Removes apiary how-to (6cbfa58)
Removes summary plugin (857d85f)
Resolves broken discord link (8c445bc)
Resolves broken header image link (2820efc)
Resolves broken links in docs (b2698f1)
Resolves broken redirects (340cea7)
Resolves issues with book.json (5ac721b)
Resolves issues with broken images and docs publish task (39ea6c3)
Resolves uppercase readme redirects (7e3dd70)
Updates chat badge to discord (5261ae1)
Updates JSON Swagger specification (1e1c1c1)
Updates outdated links in README (1ceaae2), closes #788:
The new website introduced a new link structure which broke links in the README. This patch resolves that.
Updates readme, contribution guide, and templates (#806) (c12c629)
Updates recovering root access section to SQL (9c923b6), closes #756
Updates summary (4bcc8ed)
Updates various sections in README (f1ca802)
Upgrades install guide to v0.11.6 (764282c)
Updates license to 2018 (fd0f06f)
Adds ability to flush old access tokens (ed0aa28), closes #738:
Previously, no way of removing old access tokens from the database.
This patch adds a new endpoint (POST /oauth2/flush) capable of
flushing old / stale access tokens.
Additionally, hydra token flush was added which is the CLI command
for flushing tokens using the api.
Adds newsletter sign up capabilities to CLI commands (#759) (049f581)
Adds OpenID Connect refresh handler (#797) (84ddafe), closes #794:
Previously, it was impossible to refresh OpenID Connect ID Tokens. This is now possible as the factory has been added to the oauth2 factory in the host process.
Adds support for PKCE (IETF RFC7636) (343e216), closes #744:
This patch adds support for PKCE which is especially useful for native mobile apps.
Spec: https://tools.ietf.org/html/rfc7636
Allows anonymous users access to ./well-known/jwks.json (f867fd9), closes #761:
The ./well-known/jwks.json endpoint contains important, publicly accessible keys for validating signatures such as the OpenID Connect ID Token signature.
Currently, this endpoint shows the public key for validating ID Tokens only. As this key is public, a policy was added which allows any user (including anonymous ones) to access this specific key.
Thus, administrators no longer need to add a policy to allow access to this endpoint on a fresh installation. It is still possible to change this behaviour by removing the policy ("hydra policies delete default-oidc-id-token-public-policy") or replacing it.
This change affects new installations only.
Correct docker exec wording (bda2c6c):
exec is an nsenter, not an ssh
Forces JWK to have a unique ID (acd0107), closes #589:
Previously, JSON Web Keys did not have to specify a unique id. JWKs
generated by ORY Hydra typically only used public or private
as KeyID. This patch changes that and appends a unique id if no
KeyID was given. To be able to separate between public and private key
pairs in resource name, the public/private convention was kept.
This change targets specifically the OpenID Connect ID Token and HTTP TLS keys. The ID Token key was previously "hydra.openid.id-token:public" and "hydra.openid.id-token:private" which now changed to something like "hydra.openid.id-token:public:9a458aa3-65a0-4982-835f-343eec45183c" and "hydra.openid.id-token:private:fa353995-d77d-420a-b967-63bf0721271b" with the UUID part being random for every installation.
This change will help greatly with key rotation in the future.
Forces UTC in consent strategy (#775) (7c4fd7d), closes #679:
This resolves an issue when different timezones are used between systems by enforcing UTC everywhere.
Generate php sdk and point php autoloader to lib folder (#736) (f84eb65)
Introduces pagination to client management (#774) (02b3708), closes #739:
Previously, all clients were returned by GET /clients. To mitigate
DoS attacks against large databases, pagination has been introduced.
Parallelizes database instantiation in tests (8e894bc)
Parallelizes database instantiation in tests (a0d6a0d)
Persists config file right before starting the server (7fb51e5):
Tests would fail because the config file is polled in order to check if the server is already started or not. Moving the persist command right before starting the server resolves issues with racy tests.
Remove unused code (c97e764):
This code was meant to be deleted in 9592a0069ed4b851cec8591038f9be5ce6d81a28 I believe.
Remove unused named returns (8bba5a0)
Resolves an issue with broken build time display (#799) (5c847ea), closes #792:
Previously, the build time was always the current time. This patch resolves that issue.
Resolves broken JWK cast tests (5740f32)
Resolves broken sql schema test (1b76f4b)
Resolves composer license complaint (#763) (6f9f906):
Composer complained because an unknown license was used "Apache 2.0" instead of "Apache-2.0". This patch resolves that.
Resolves possible session fixation attack (1e80a1d):
This patch resolves a vulnerability in the consent flow. This vulnerability affects versions 0.10.0 ~ 0.11.5 only. Versions < 0.10.0 are not affected.
The vulnerability can be exploited as follows:
https://hydra/oauth2/auth?client=...&consent=example-id. However,
through some means, Malice is able to prevent redirection of Bob's
user agent.https://hydra/oauth2/auth?client=...&consent=example-idFor this attack to work, the following preconditions must be met:
For these reasons, an exploit for this vulnerability is not likely, but possible.
This patch closes the described vulnerability by requiring a
consent_csrf value additional to the consent value in the query
parameters of the authorization url. Without that value, the authorization
code flow will not be successful. The consent_csrf is transmitted out-of-band
to the consent app and not accessible to Malice. Let's revisit the example
from above:
https://hydra/oauth2/auth?client=...&consent=example-id&consent_csrf=csrf_token.
The redirection URL is only accessible to the consent app and Bob's user agent.
However, through some means, Malice is able to prevent redirection of Bob's
user agent.consent_csrf, accessing
https://hydra/oauth2/auth?client=...&consent=example-id without
setting consent_csrf causes the request to fail and the consent to
be revoked.This patch does not introduce breaking changes. Upgrading to the version which contains this patch does not require any code changes or deployment changes.
Skips parallelization when not using docker (57d0b12):
Previously, databases connected in parallel even when dockertest was skipped - typically in CI environments. This caused issues on those environments. This patch resolves that.
Stops creating client when secret is too short (#764) (f818f85), closes #725:
Previously, clients were created despite an error which said that the secret was too short. This patch changes that and improves error output in the CLI as well for this command.
Strips client secret from output when client is public (#765) (439267b), closes #737:
Previously a newly created public client had a secret send with the initial response and this secret was displayed in the CLI.
Now it is clear that there is no secret needed for public clients. It is not displayed in the CLI anymore.
Updates text for newsletter signup (#780) (459703f):
Before newsletter text did not seem to make clear that it is just for security information.
Use existing alpha-lower sequence (343cb09)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
metrics: Improves naming of traits
Nothing published for this version
cmd: Adds OpenID Connect refresh handler
cmd: Adds OpenID Connect refresh handler
Previously, it was impossible to refresh OpenID Connect ID Tokens. This is now possible as the factory has been added to the oauth2 factory in the host process.
Closes #794
This patch resolves a vulnerability in the consent flow. This vulnerability affects versions 0.10.0 ~ 0.11.5 only. Versions < 0.10.0 are not affected.
oauth2: Resolves possible session fixation attack
This patch resolves a vulnerability in the consent flow. This vulnerability affects versions 0.10.0 ~ 0.11.5 only. Versions < 0.10.0 are not affected.
The vulnerability can be exploited as follows:
https://hydra/oauth2/auth?client=...&consent=example-id. However,
through some means, Malice is able to prevent redirection of Bob's
user agent.https://hydra/oauth2/auth?client=...&consent=example-idFor this attack to work, the following preconditions must be met:
For these reasons, an exploit for this vulnerability is not likely, but possible.
This patch closes the described vulnerability by requiring a
consent_csrf value additional to the consent value in the query
parameters of the authorization url. Without that value, the authorization
code flow will not be successful. The consent_csrf is transmitted out-of-band
to the consent app and not accessible to Malice. Let's revisit the example
from above:
https://hydra/oauth2/auth?client=...&consent=example-id&consent_csrf=csrf_token.
The redirection URL is only accessible to the consent app and Bob's user agent.
However, through some means, Malice is able to prevent redirection of Bob's
user agent.consent_csrf, accessing
https://hydra/oauth2/auth?client=...&consent=example-id without
setting consent_csrf causes the request to fail and the consent to
be revoked.This patch does not introduce breaking changes. Upgrading to the version which contains this patch does not require any code changes or deployment changes.
Resolves possible session fixation attack (69cc450):
This patch resolves a vulnerability in the consent flow. This vulnerability affects versions 0.10.0 ~ 0.11.5 only. Versions < 0.10.0 are not affected.
The vulnerability can be exploited as follows:
https://hydra/oauth2/auth?client=...&consent=example-id. However,
through some means, Malice is able to prevent redirection of Bob's
user agent.https://hydra/oauth2/auth?client=...&consent=example-idFor this attack to work, the following preconditions must be met:
For these reasons, an exploit for this vulnerability is not likely, but possible.
This patch closes the described vulnerability by requiring a
consent_csrf value additional to the consent value in the query
parameters of the authorization url. Without that value, the authorization
code flow will not be successful. The consent_csrf is transmitted out-of-band
to the consent app and not accessible to Malice. Let's revisit the example
from above:
https://hydra/oauth2/auth?client=...&consent=example-id&consent_csrf=csrf_token.
The redirection URL is only accessible to the consent app and Bob's user agent.
However, through some means, Malice is able to prevent redirection of Bob's
user agent.consent_csrf, accessing
https://hydra/oauth2/auth?client=...&consent=example-id without
setting consent_csrf causes the request to fail and the consent to
be revoked.This patch does not introduce breaking changes. Upgrading to the version which contains this patch does not require any code changes or deployment changes.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →