NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
The ORY Community is proud to present you the next iteration of ORY Kratos. In this release, we focused on improving production stability!
The ORY Community is proud to present you the next iteration of ORY Kratos. In this release, we focused on improving production stability!
CSRF token is required when using the Revoke Session API endpoint (#839) (d3218a0), closes #838
Make password policy configurable (#888) (7a00483), closes #450 #316:
Allows configuring password breach thresholds and optionally enforces checks against the HIBP API.
Set samesite attribute to lax if in dev mode (#824) (91d6698), closes #821
Use working cache-control header for cdn/proxies/cache (#869) (d8e3d40), closes #601
Add contributing to sidebar (#866) (44f33f9):
The same change as in https://github.com/ory/hydra/pull/2209
Add newsletter to config (1735ca2)
Add recovery flow (#868) (d95cfe9), closes #864:
Added a short section for the recovery flow on managing-user-identities.
Swagger specs for selfservice settings browser flow (#825) (28d50f4)
Update oidc provider with json conf support (#833) (670eb37)
This release introduces the new CLI command kratos hashers argon2 calibrate 500ms. This command will choose the best parameterization for Argon2. Chec
This release introduces the new CLI command
kratos hashers argon2 calibrate 500ms. This command will choose the best
parameterization for Argon2. Check out the
Choose Argon2 Parameters for Secure Password Hashing and Login
blog article for more insights!
Force brew install statement (#796) (ad542ad):
Closes https://github.com/ory/homebrew-kratos/issues/1
Add helper for choosing argon2 parameters (#803) (ca5a69b), closes #723 #572 #647:
This patch adds the new command "hashers argon2 calibrate" which allows one to pick the desired hashing time for password hashing and then chooses the optimal parameters for the hardware the command is running on:
$ kratos hashers argon2 calibrate 500ms
Increasing memory to get over 500ms:
took 2.846592732s in try 0
took 6.006488824s in try 1
took 4.42657975s with 4.00GB of memory
[...]
Decreasing iterations to get under 500ms:
took 484.257775ms in try 0
took 488.784192ms in try 1
took 486.534204ms with 3 iterations
Settled on 3 iterations.
{
"memory": 1048576,
"iterations": 3,
"parallelism": 32,
"salt_length": 16,
"key_length": 32
}
Nothing published for this version
This release improves the developer and user experience around CSRF counter-measures. It should now be possible to use the self-service API flows with
This release improves the developer and user experience around CSRF counter-measures. It should now be possible to use the self-service API flows without having to explicitly disable cookie features in your SDKs and integrations. Additionally, another issue in the CGO pipeline was resolved which finally allows running ORY Kratos without CGO if the target database is not SQLite.
Further improvements to default config values have been made and a full end-to-end test suite for the exemplary kratos-selfservice-ui-react-native app. The app is now available in the iTunes store as well - just search for "ORY Profile App"!
Add "x-session-token" to default allowed headers (3c912e4)
Do not set cookies on api endpoints (2f67c28)
Do not set csrf cookies on potential api endpoints (4d97a95)
Ignore unsupported migration dialects (12bb8d1), closes #778:
Skips sqlite3 migrations when support is lacking.
Improve semver regex (584c0b5)
Properly set nosurf context even when ignored (0dcb774)
Update cypress (ba8b172)
Use correct regex for version replacement (ce870ab), closes #787
This release addresses bugs and user experience issues.
This release addresses bugs and user experience issues.
This release resolves an issue where ORY Kratos Docker Images without CGO and SQLite support would fail to boot even when SQLite was not used as a dat
This release resolves an issue where ORY Kratos Docker Images without CGO and SQLite support would fail to boot even when SQLite was not used as a data source.
Please note that several things have changed in a breaking fashion. You can find details for the individual breaking changes in the changelog below.
The ORY team and community is very proud to present the next ORY Kratos iteration!
ORY Kratos is now capable of handling native (iOS, Android, Windows, macOS, ...) login, registration, settings, recovery, and verification flows. As a goodie on top, we released a reference React Native application which you can find on GitHub.
We co-released our reference React Native application which acts as a reference on implementing these flows:
In total, almost 1200 files were changed in about 480 commits. While you can find a list of all changes in the changelist below, these are the changes we are most proud of:
X-Session-Token HTTP Header).Additionally tons of bugs were fixed, tests added, documentation improved, and much more. Please note that several things have changed in a breaking fashion. You can find details for the individual breaking changes in the changelog below.
We would like to thank all community members who contributed towards this release (in no particular order):
Have fun exploring the new release, we hope you like it! If you haven't already, join the ORY Community Slack where we hold weekly community hangouts via video chat and answer your questions, exchange ideas, and present new developments!
The "common" keyword has been removed from the Swagger 2.0 spec which deprecates
the common module / package / class (depending on the generated SDK). Please
use public or admin instead!
Additionally, the SDK for TypeScript now uses the fetch API which allows the
SDK to be used in both client-side as well as server-side contexts. Please note
that several methods and parameters in the generated TypeScript SDK have
changed. Please check the TypeScript results to see what needs to be changed!
This patch changes the OpenID Connect and OAuth2 ("Sign in with Google,
Facebook, ...") Callback URL from
http(s)://<kratos-public>/self-service/browser/flows/strategies/oidc/<provider>
to http(s)://<kratos-public>/self-service/methods/oidc/<provider>. To apply
this patch, you need to update these URLs at the OAuth2 Client configuration
pages of the individual OpenID Conenct providers (e.g. GitHub, Google).
Configuration key selfservice.strategies was renamed to selfservice.methods.
This patch significantly changes how email verification works. The Verification Flow no longer uses its own system but now re-uses the API and Browser flows and flow methods established in other components such as login, recovery, registration.
Due to the many changes these patch notes does not cover how to upgrade this particular flow. We instead want to kindly ask you to check out the updated documentation for this flow at: https://www.ory.sh/kratos/docs/self-service/flows/verify-email-account-activation
This patch changes the SQL schema and thus requires running the SQL Migration
command (e.g. ... migrate sql). Never apply SQL migrations without backing up
your database prior.
Configuration items selfservice.flows.<name>.request_lifespan have been
renamed to selfservice.flows.<name>.lifespan to match the new flow semantics.
Wording has changed from "Self-Service Recovery Request" to "Self-Service Recovery Flow" to follow community feedback and practice already applied in the documentation. Additionally, fetching a recovery flow over the public API no longer requires Anti-CSRF cookies to be sent.
This patch renames several important recovery flow endpoints:
/self-service/browser/flows/recovery is now /self-service/recovery/browser
without functional changes./self-service/browser/flows/requests/recovery?request=abcd is now
/self-service/recovery/flows?id=abcd and no longer needs anti-CSRF cookies
to be available.Additionally, the URL for completing the password and oidc recovery method has been moved. Given that this endpoint is typically not manually called, you can probably ignore this change:
/self-service/browser/flows/recovery/link?request=abcd is now
/self-service/recovery/methods/link?flow=abcd without functional changes.The Recovery UI Endpoint no longer receives a ?request=abcde query parameter
but instead a ?flow=abcde query parameter. Functionality did not change
however.
As part of this change SDK methods have been renamed:
const kratos = new CommonApi(config.kratos.public)
// ...
- kratos.completeSelfServiceBrowserRecoveryLinkStrategyFlow(req.query.request)
+ kratos.completeSelfServiceRecoveryFlowWithLinkMethod(req.query.flow)
This patch requires you to run SQL migrations.
Wording has changed from "Self-Service Settings Request" to "Self-Service Settings Flow" to follow community feedback and practice already applied in the documentation.
This patch renames several important settings flow endpoints:
/self-service/browser/flows/settings is now /self-service/settings/browser
without functional changes./self-service/browser/flows/requests/settings?request=abcd is now
/self-service/settings/flows?id=abcd and no longer needs anti-CSRF cookies
to be available.Additionally, the URL for completing the password, profile, and oidc settings method has been moved. Given that this endpoint is typically not manually called, you can probably ignore this change:
/self-service/browser/flows/login/strategies/password?request=abcd is now
/self-service/login/methods/password?flow=abcd without functional changes./self-service/browser/flows/strategies/oidc?request=abcd is now
/self-service/methods/oidc?flow=abcd without functional changes./self-service/browser/flows/settings/strategies/profile?request=abcd is now
/self-service/settings/methods/profile?flow=abcd without functional changes.The Settings UI Endpoint no longer receives a ?request=abcde query parameter
but instead a ?flow=abcde query parameter. Functionality did not change
however.
As part of this change SDK methods have been renamed:
const kratos = new CommonApi(config.kratos.public)
// ...
- kratos.getSelfServiceBrowserSettingsRequest(req.query.request)
+ kratos.getSelfServiceSettingsFlow(req.query.flow)
// You will most likely not be using this:
const kratos = new PublicApi(config.kratos.public)
- kratos.completeSelfServiceBrowserSettingsPasswordStrategyFlow //...
- kratos.completeSelfServiceSettingsFlowWithPasswordMethod //..
- kratos.completeSelfServiceBrowserSettingsProfileStrategyFlow //...
- kratos.completeSelfServiceSettingsFlowWithProfileMethod //..
This patch requires you to run SQL migrations.
This patch makes the reverse proxy functionality required in prior versions of the self-service UI example obsolete. All examples work now with a simple set up and documentation has been added to assist in subdomain scenarios.
The session field sid has been renamed to id to stay consistent with other
APIs which also use id terminology to clarify identifiers. The payload of, for
example, /session/whoami has changed as follows:
{
- "sid": "abcde",
+ "id": "abcde",
"expires_at": "..."
"identity": {
// ..
}
}
Wording has changed from "Self-Service Registration Request" to "Self-Service Registration Flow" to follow community feedback and practice already applied in the documentation. Additionally, fetching a login flow over the public API no longer requires Anti-CSRF cookies to be sent.
This patch renames several important registration flow endpoints:
/self-service/browser/flows/registration is now
/self-service/registration/browser without behavioral change./self-service/browser/flows/requests/registration?request=abcd is now
/self-service/registration/flows?id=abcd and no longer needs anti-CSRF
cookies to be available.Additionally, the URL for completing the password registration method has been moved. Given that this endpoint is typically not manually called, you can probably ignore this change:
/self-service/browser/flows/registration/strategies/password?request=abcd is
now /self-service/registration/methods/password?flow=abcd without functional
changes./self-service/browser/flows/strategies/oidc?request=abcd is now
/self-service/methods/oidc?flow=abcd without functional changes.The Registration UI Endpoint no longer receives a ?request=abcde query
parameter but instead a ?flow=abcde query parameter. Functionality did not
change however.
As part of this change SDK methods have been renamed:
const kratos = new CommonApi(config.kratos.public)
// ...
- kratos.getSelfServiceBrowserRegistrationRequest(req.query.request)
+ kratos.getSelfServiceRegistrationFlow(req.query.flow)
This patch requires you to run SQL migrations.
Existing login sessions will no longer be valid because the session cookie data model changed. If you apply this patch, your users will need to sign in again.
Wording has changed from "Self-Service Login Request" to "Self-Service Login Flow" to follow community feedback and practice already applied in the documentation. Additionally, fetching a login flow over the public API no longer requires Anti-CSRF cookies to be sent.
This patch renames several important login flow endpoints:
/self-service/browser/flows/login is now /self-service/login/browser
without functional changes./self-service/browser/flows/requests/login?request=abcd is now
/self-service/login/flows?id=abcd and no longer needs anti-CSRF cookies to
be available.Additionally, the URL for completing the password and oidc login method has been moved. Given that this endpoint is typically not manually called, you can probably ignore this change:
/self-service/browser/flows/login/strategies/password?request=abcd is now
/self-service/login/methods/password?flow=abcd without functional changes./self-service/browser/flows/strategies/oidc?request=abcd is now
/self-service/methods/oidc?flow=abcd without functional changes.The Login UI Endpoint no longer receives a ?request=abcde query parameter but
instead a ?flow=abcde query parameter. Functionality did not change however.
As part of this change SDK methods have been renamed:
const kratos = new CommonApi(config.kratos.public)
// ...
- kratos.getSelfServiceBrowserLoginRequest(req.query.request)
+ kratos.getSelfServiceLoginFlow(req.query.flow)
This patch requires you to run SQL migrations.
Configuraiton value session.cookie_same_site has moved to
session.cookie.same_site. There was no functional change.
Add missing 'recovery' path in oathkeeper access-rules.yml (#763) (f180dba)
Add missing error handling (43c1446)
Add remote help description (f66bbe1)
Add serve help description (2eb072b)
Allow using json with form layout in password registration (bd2225c)
Annotate whoami endpoint with cookie and token (a8a781c)
Bump datadog version to fix build failure (4dfd322)
Change KRATOS_ADMIN_ENDPOINT to KRATOS_ADMIN_URL (763fdc5)
Clarify fetch use (8eb2e6f)
Complete verification by redirecting to UI with success (f0ecf51)
Correct cookie domain on logout (#646) (6d77e04), closes #645
Correct help message for import (a5f46d2)
Correct password and profile swagger annotations (668c184)
Correct password registration method api spec (08dd582)
Cover more test cases for persister (37d2e08)
Create decoder only once (34dc43b)
Deprecate packr2 dependency in makefile (be9a84d), closes #711 #750
Do not propagate parent validation error (bf6093d)
Don't resend verification emails once verified (#583) (a4d9969), closes #578
Enforce endpoint to be set (171ac18)
Escape jsx characters in api documentation (0946094)
Exit with code 1 on unimplemented CLI commands (66943d7)
Explicitly ignore fprint return values (f50e582)
Explicitly ignore fprintf results (a83dc50)
Fallback to default return url if logout after url is not defined (#594) (7edd367)
Favor packr2 over pkger (ac18a45):
See https://github.com/markbates/pkger/issues/117
Find and replace "request" references (41fb673)
Force exe buildmode for windows CGO (e017bb5)
Html form parse regression issue (6b07cbb)
Ignore x/net false positives (7044b95)
Improve debugging output for login hook and restructure files (dabac40)
Improve debugging output for registration hook and restructure files (ec11775)
Improve expired error responses (124a92e)
Improve hook tests (55ba485)
Improve makefile dependency building (8e1d69a)
Improve pagination when listing identities (c60bf44)
Improve post login hook log and audit messages (ddd5d5a)
Improve post registration hook log and audit messages (2495629)
Improve registration hook tests (8163152)
Keep HTML form type on registration error (#698) (6c9e756), closes #670
Lowercase emails on login (244b4dd)
Merge public and admin login flow fetch handlers (48c4906)
Missing write in registration error handler (3b2af53)
Properly annotate swagger password parameters (2ef57c4)
Properly fetch identity for session (7be4086)
Recursive loop on network errors in password validator (#589) (b4d5a42), closes #316:
The old code no error when ignoreNetworkErrors was set to true, but did not set a hash result which caused an infinite loop.
Remove incorrect security specs (4c3d46d)
Remove obsolete tests (f102f95):
The test is no longer valid as CSRF checks now happen after checking for login sessions in settings flows.
Remove redirector from code base (6689ecf)
Remove stray debug statements (a8e1ec4)
Rename import to put (8003e0f)
Rename quickstart schema file name (e943c90)
Rename recovery models and generate SDKs (d764435)
Resolve and test for missing data when updating flows (045ecab)
Resolve broken csrf tests (6befe2e)
Resolve broken docs links (56f4a39)
Resolve broken migrations and bump fizz (1ed9c70)
Resolve broken OIDC tests and disallow API flows (9986d8f)
Resolve cookie issues (6e2b6d2)
Resolve e2e headless test failures (82d506e)
Resolve e2e test failures (2627db2)
Resolve failing test cases (f8647b4)
Resolve flaky passwort setting tests (#582) (c42d936), closes #581 #577
Resolve handler testing issue (4f6bafd)
Resolve identity admin api issues (#586) (feef8a7), closes #435 #500:
This patch resolves several issues that occurred when creating or updating identities using the Admin API. Now, all hooks are running properly and updating privileged properties no longer causes errors.
Resolve interface type issues (064b305)
Resolve migratest failures (e2f34d3)
Resolve migratest ordering failing tests (dffecc0)
Resolve migration issues (b545e15)
Resolve panic on serve
(ae34155)
Resolve panic when DSN="memory" (#574) (05e55f3):
Executing the migration logic in registry.go cause a panic as the registry is not initalized at that point. Therefore we decided to move the handling to driver_default.go, after the registry has been initialized.
Resolve pkger issues (294066c)
Resolve remaining testing issues (af40d93)
Resolve SQL persistence tester issues (4952df4)
Resolve swagger issues and regenerate SDK (be4c7e4)
Resolve template loading issue (145fb20)
Resolve test issues introduced by new csrf protection (625ef5e)
Resolve verification sql errors (784da53)
Resolves a bug that prevents sessions from expiring (#612) (86b281a), closes #611
Revert disabling swagger flatten during sdk generation
(98c7915)
Set correct path for kratos in oathkeeper set up (414259f)
Set quickstart logging to trace (d3e9192)
Support browser flows only in redirector (cab5280)
Swagger models (1b5f9ab):
The swagger:parameters <id> definitions for updateIdentity and
createIdentity where defined two times with the same ID. They had some old
definition swagger used. The internal/httpclient should now work again as
expected.
Type (e264c69)
Update cli documentation examples (216ea7f)
Update contrib samples (79d24b4)
Update crdb quickstart version (249a6ba)
Update import description (aef1e1a)
Update quickstart kratos config (e3246e5)
Update recovery token field and column names (42abfa1)
Update status help description (b147831)
Update swagger names and fix broken tests (85b7fb1)
Update version help description (8bf4a79)
Use and test for csrf tokens and prevent api misuse (a4e3bc5)
Use correct HTTP method for password login (4f4fcee)
Use correct log message (53c384a)
Use correct redirection for registration (8d47113)
Use correct security annotation (c9bebe0)
Use correct swagger tags and regenerate (df99d8c)
Use helpers to create flow (aba8610)
Use nosurf fork to address VerifyToken bug (cd84e51)
Use params per_page and page for pagination (5dfb6e3)
Use proper pwd in makefile (52e22c3)
Use public instead of common sdk (dcb4a36)
Use relative threshold to judge longest common substring in password policy (#585) (3e9f8cc), closes #581
Add flow methods to verification (00ee828):
Completely refactors the verification flow to support other methods. The original email verification flow now moved to the "link" method also used for recovery.
Additionally, several upstream bugs in gobuffalo/pop and gobuffalo/fizz have been addressed, patched, and merged which improves support for SQLite and CockroachDB migrations:
Add method and rename request to flow (006bf56)
Change oidc callback URL (36d9380)
Complete login flow refactoring (ad2b3db)
Dry up login.NewFlow (f261c44)
Improve CSRF infrastructure (7e367e7)
Improve login test reuse (b4184e5)
Improve NewFlowExpiredError (1caefac)
Improve registration tests with testhelpers (9bf4530)
Improve selfservice method tests (df4d06d)
Improve settings helper functions (fda17ca)
Move samesite config to cookie parent-key (753eb86)
Moved clihelpers to ory/x (#756) (6ccffa8):
Contributes to https://github.com/ory/hydra/issues/2124.
Profile settings method is now API-able (c5f361f)
Remove common keyword from API spec (6619562)
Remove need for reverse proxy in selfservice-ui (beb4c32), closes #661
Rename session.sid to session.id
(809fe73)
Rename login request to login flow (9369d1b), closes #635:
As part of this change, fetching a login flow over the public API no longer requires Anti-CSRF cookies to be sent.
Rename LoginRequestErrorHandler to LoginFlowErrorHandler (66ae029)
Rename package recoverytoken to link (f87fb54)
Rename recovery request to flow internally (16c5618)
Rename recovery request to recovery flow (b0f433d), closes #635:
As part of this change, fetching a login flow over the public API no longer requires Anti-CSRF cookies to be sent.
Rename registration request to flow (8437ebc)
Rename registration request to registration flow (0470956), closes #635:
As part of this change, fetching a registration flow over the public API no longer requires Anti-CSRF cookies to be sent.
Rename request_lifespan to lifespan (#677) (3c8d5e0), closes #666
Rename strategies to methods (8985189):
This patch renames strategies such as "Username/Email & Password" to
methods.
Replace all occurrences of login request to flow (1b3c491)
Replace all registration request occurrences with registration flow (308ef47)
Replace packr2 with pkger fork (4e2acae)
Restructure login package (c99e2a2)
Use session token as cookie identifier (60fd9c2)
Add administrative user management guide (b97e0c6)
Add code samples to session checking (eba8eda)
Add descriptions to cobra commands (607b76d)
Add documentation for configuring cookies (e3dbc8a), closes #516
Add domain, subdomain, multi-domain cookie guides (3eb1e59), closes #661
Add guide for cors (a8ae759)
Add guide for cors (91fd278)
Add guide for dealing with login sessions (4e2718c)
Add identity state (fb4aedb)
Add login session to navbar (b212d64)
Add milestones to sidebar (aae13ec)
Add missing GitLab provider to the list of supported OIDC providers (#766) (a43ed33)
Add pagination docs (7fe0901)
Add secret key rotation guide (3d6e21a)
Add sequence diagrams for browser/api flows (590d767)
Add terminology section (29b81a7)
Add theme helpers and decouple mermaid (7c3eb32)
Added sidebar cli label (5d24a29):
clidoc.Generate expects to find an entry under sidebar.json/Reference that
contains the substring "CLI" in it's label. Because that was missing, a new
entry was appended on every regeneration of the file.
Added sidebar item (#639) (8574761):
Added Kratos Video Tutorial Transcripts document to sidebar.
Added transcript (#627) (cec7f1f):
Added Login with Github Transcript
Bring oidc docs up to date (7d0e470)
Changed transcript location (#642) (c52764d):
Changed the location so it is in the right place.
Clarify 302 redirect on expired login flows (ca31b53)
Clarify api flow use (a38b4a1)
Clarify feature-set (2266ae7)
Clarify kratos config snippet (e7732f3)
Clean up docs and correct samples (8627ec5)
Complete registration documentation (b3af02b)
Correct settings and verification redir (30e25e7)
Document APi flows in self-service overview (71ed0bd)
Document how to check for login sessions (9ad73b8)
Explain high-level API and browser flows (fe3ee0a), closes hi#level
Fix sidebar missing comment (d90123a)
Fix typo (c2f94da)
Fixed link (c2aebbd)
Fixed typos/readability (#620) (7fd3ce0):
Fixed a few typos, and moved some sentences around to improve readability.
Improve charts and examples in self-service overview (312c91d)
Improve documentation and add tests (3dde956)
Improve long messages and render cli documentation (e5fc02f)
Make assumptions neutral in concepts overview (e89d980)
Move development section (2e6f643)
Move hooks (c02b588)
Move to json sidebar (504af3b)
Password login and registration methods for API clients (5a44356)
Quickstart next steps (#676) (ee9dd0d):
Added a section outlining some easy config changes, that users can apply to the quickstart to test out different scenarios and configurations.
Refactor login and registration documentation (c660a04)
Refactor settings and recovery documentation (11ca9f7)
Refactor verification docs (70f2789)
Regenerate clidocs with up-to-date binary (e53289c)
Remove make tools task
(ec6e664),
closes #711
#750:
This task does not exist any more and the dependency building is much smarter now.
Remove duplicate word (b84e659)
Remove react native guide for now (daa5f2e)
Rename self service and add admin section (639c424)
Resolve regression issues (0470fd7)
Resolve typo in message IDs (562cfc4)
Update cli docs (085efca)
Update link to mfa issue (d03a706)
Update links (a06fd88)
Update MFA link to issue (#690) (7a744ad):
MFA issue was pushed to a later milestone. Update the documentation to point to the issue instead of the milestone.
Update repository templates (f422485)
Update sidebar (ea15c20)
Update ts examples (65cb46e)
Use correct id for multi-domain-cookies (b49288a)
Use NYT Capitalization for all Swagger headlines (#675) (6c96429), closes #664
Add ability to configure session cookie domain/path (faeb332), closes #516
Add and improve settings testhelpers (10a43fc)
Add bearer helper (ec6ca20)
Add enum to form field type (96028d8)
Add flow type to login (ce9133b)
Add HTTP request flow validator (1a6e847)
Add new prometheus metrics endpoint #672 (#673) (0f5c436):
Adds endpoint /metrics for prometheus metrics collection to the Admin API
Endpoint.
Add nocache helpers (54dcc4d)
Add pagination tests (e3aa81b)
Add session token security definition (d36c26f):
Adds the new Session Token as a Swagger security definition to allow setting
the session token as a Bearer token when calling /sessions/whoami.
Add test helper for fetching settings requests (3646383)
Add tests and helpers to test recovery/verifiable addresses (#579) (29979e6), closes #576
Add tests to cover auth (c9d3a15)
Add texts for settings (795548c)
Add the already declared (and settable) tracer as a middleware (#614) (e24fffe)
Add token to session (08c8c78)
Add type to all flows in SQL (5515776)
Allow import/validation of arrays (d11ac32)
Bump cli and migration render tasks (6dcb42a)
Finalize tests for registration flow refactor (8e52c3a)
Finish off client cli (36d60c7)
Implement administrative account recovery (f5f9c43)
Implement API flow for recovery link method (d65bf66)
Implement API-based tests for password method settings flows (60664aa)
Implement tests and anti-csrf for API settings flows (8b8b6e5)
Implement tests for new migrations (e08ece9)
Improve test readability for password method (a896d9b)
Log successful hook execution (f6026cf)
Log successful hook execution (1e7d044)
Make login error handle JSON aware (88f581f)
Make password settings method API-able (0cf6027)
Oidc provider claims config option (#753) (bf94a40), closes #735
Reply with cache-control: 0 for browser-facing APIs (1a45b53), closes #360
Schemas are now static assets (1776d58)
Support and document api flow in session issuer hook (91f3cc7)
Support application/json in registration (3476b97), closes #44
Support custom session token header (56bec76):
The /sessions/whoami endpoint now accepts the ORY Kratos Session Token in
the X-Session-Token HTTP header.
Support json payloads for login and password (354e8b2)
Support JSON payloads in password login flow (dd32c23)
Support session token bearer auth and lifecycle (c12600a):
This patch adds support for issuing, validating, and revoking session tokens. Session tokens carry a reference to a session, and are equal to session cookies but can be used on environments which do not support cookies (e.g. React Native) by sending them in the Bearer Authorization.
Update migration tests (fb28173)
Use uri-reference for ui_url etc. to allow relative urls (#617) (2dba450)
Write request -> flow rename migrations (d7189a9)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Resolves build and install issues and includes a few bugfixes.
Resolves build and install issues and includes a few bugfixes.
Resolves build and install issues and includes a few bugfixes.
Pin v0.4.5-alpha.1 release commit (3ea7fd3):
Bumps from v0.4.4-alpha.1
The purpose of this release is to resolve issues with install scripts, homebrew, and scoop.
The purpose of this release is to resolve issues with install scripts, homebrew, and scoop.
It is now much easier to enable account recovery and email verification. This is a breaking change - please read the breaking changes section with car…
We are very happy to announce the 0.4 release of ORY Kratos with 163 commits and 817 changed files with 52,681 additions and 9,876 deletions.
There have been many improvements and bugfixes merged. The biggest changes are:
prompt=login has been renamed to refresh=true. This is a breaking
change - please read the breaking changes section with care!update_successful with booleans, flows (e.g.
the settings flow) that have more than one state now include a state machine.
This is a breaking change - please read the breaking changes section with
care!Before upgrading, please make a backup of your database and read the section "Breaking Changes" with care!
Pin v0.4.3-alpha.1 release commit (a3a34b1):
Bumps from v0.4.0-alpha.1
It is now much easier to enable account recovery and email verification. This is a breaking change - please read the breaking changes section with car…
We are very happy to announce the 0.4 release of ORY Kratos with 153 commits and 760 changed files with 36,223 additions and 9,754 deletions.
There have been many improvements and bugfixes merged. The biggest changes are:
prompt=login has been renamed to refresh=true. This is a breaking
change - please read the breaking changes section with care!update_successful with booleans, flows (e.g.
the settings flow) that have more than one state now include a state machine.
This is a breaking change - please read the breaking changes section with
care!Before upgrading, please make a backup of your database and read the section "Breaking Changes" with care!
Pin v0.4.2-alpha.1 release commit (20024cb):
Bumps from v0.4.0-alpha.1
It is now much easier to enable account recovery and email verification. This is a breaking change - please read the breaking changes section with car…
We are very happy to announce the 0.4 release of ORY Kratos with 153 commits and 760 changed files with 36,223 additions and 9,754 deletions.
There have been many improvements and bugfixes merged. The biggest changes are:
prompt=login has been renamed to refresh=true. This is a breaking
change - please read the breaking changes section with care!update_successful with booleans, flows (e.g.
the settings flow) that have more than one state now include a state machine.
This is a breaking change - please read the breaking changes section with
care!Before upgrading, please make a backup of your database and read the section "Breaking Changes" with care! This release requires running SQL migrations when upgrading!
This patch renames the Identity Traits JSON Schema to Identity JSON Schema.
The identity payload has changed from
{
- "traits_schema_url": "...",
- "traits_schema_id": "...",
+ "schema_url": "...",
+ "schema_id": "...",
}
Additionally, it is now expected that your Identity JSON Schema includes a "traits" key at the root level.
Before (example)
{
"$id": "https://schemas.ory.sh/presets/kratos/quickstart/email-password/identity.schema.json",
"$schema": "http://json-schema.org/draft-07/schema#",
"title": "Person",
"type": "object",
"properties": {
"email": {
"type": "string",
"format": "email",
"title": "E-Mail",
"minLength": 3,
"ory.sh/kratos": {
"credentials": {
"password": {
"identifier": true
}
},
"verification": {
"via": "email"
},
"recovery": {
"via": "email"
}
}
}
},
"required": [
"email"
],
"additionalProperties": false
}
After (example)
{
"$id": "https://schemas.ory.sh/presets/kratos/quickstart/email-password/identity.schema.json",
"$schema": "http://json-schema.org/draft-07/schema#",
"title": "Person",
"type": "object",
"properties": {
"traits": {
"type": "object",
"properties": {
"email": {
"type": "string",
"format": "email",
"title": "E-Mail",
"minLength": 3,
"ory.sh/kratos": {
"credentials": {
"password": {
"identifier": true
}
},
"verification": {
"via": "email"
},
"recovery": {
"via": "email"
}
}
}
},
"required": [
"email"
],
"additionalProperties": false
}
}
}
You also need to remove the traits key from your ORY Kratos config like this:
identity:
- traits:
- default_schema_url: http://test.kratos.ory.sh/default-identity.schema.json
- schemas:
- - id: other
- url: http://test.kratos.ory.sh/other-identity.schema.json
+ default_schema_url: http://test.kratos.ory.sh/default-identity.schema.json
+ schemas:
+ - id: other
+ url: http://test.kratos.ory.sh/other-identity.schema.json
Do not forget to also update environment variables for the Identity JSON Schema as well if set.
To address these refactorings, the configuration had to be changed and with breaking changes as keys have moved or have been removed.
Hook configuration has also changed. It is no longer required to include hooks
such as verification to get verification working. Instead, verification is
enabled globally (selfservice.flows.verification.enabled). Also, the
redirect hook has been removed as it lead to confusion because there are
already default redirect URLs configurable. You will find more information in
the details below.
Session Management
-ttl:
- session: 1h
-security:
- session:
- cookie:
- same_site: Lax
+session:
+ lifespan: 1h
+ cookie_same_site: Lax
Secrets
-secrets:
- session:
- - secret-to-encrypt-session-cookies
- - old-session-cookie-secret-that-has-been-rotated
+secrets:
+ default:
+ # This secret is used as default and will also be used for encrypting e.g. cookies when a dedicated cookie secret (as shown below) is not defined.
+ - default-secret-to-encrypt-stuff
+ cookie:
+ - secret-to-encrypt-session-cookies
+ - old-session-cookie-secret-that-has-been-rotated
URLs
The Base URL configuration has moved to serve.public and serve.admin. They
are also no longer required and fall back to defaults based on the machine's
hostname, port configuration, and other settings:
-urls:
- self:
- public: https://kratos.my-website.com/
- admin: https://admin.kratos.cluster.localnet/
+serve:
+ public:
+ base_url: https://kratos.my-website.com/
+ admin:
+ base_url: https://admin.kratos.cluster.localnet/
The UI URLs have moved from urls to their respective self-service flows:
-urls:
- login_ui: http://127.0.0.1:4455/auth/login
- registration_ui: http://127.0.0.1:4455/auth/registration
- settings_ui: http://127.0.0.1:4455/settings
- verify_ui: http://127.0.0.1:4455/verify
- error_ui: http://127.0.0.1:4455/error
+selfservice:
+ flows:
+ login:
+ ui_url: http://127.0.0.1:4455/auth/login
+ registration:
+ ui_url: http://127.0.0.1:4455/auth/registration
+ settings:
+ ui_url: http://127.0.0.1:4455/settings
+ # please note that `verify` has changed to `verification`!
+ verification:
+ ui_url: http://127.0.0.1:4455/verify
+ error:
+ ui_url: http://127.0.0.1:4455/error
The default redirect URL as well as whitelisted redirect URLs have also changed their location:
-urls:
- default_return_to: https://self-service/dashboard
- whitelisted_return_to_urls:
- - https://self-service/some-other-url
- - https://example.org/another-url
+selfservice:
+ default_browser_return_url: https://self-service/dashboard
# Please note that the `to` has been removed (`whitelisted_return_to_urls` -> `whitelisted_return_urls`)
+ whitelisted_return_urls:
+ - https://self-service/some-other-url
+ - https://example.org/another-url
Self-Service Login
selfservice.login has moved to selfservice.flow.login:
selfservice:
- login:
+ flows:
+ login:
On top of this change, a few keys under login have changed as well:
selfservice
flows:
login:
+ ui_url: http://127.0.0.1:4455/auth/login
request_lifespan: 99m
- before:
- hooks:
- - hook: redirect
- config:
- default_redirect_url: http://test.kratos.ory.sh:4000/
- allow_user_defined_redirect: false
+ # The before hooks have been removed because there were no good use cases for them. If
+ # this is a problem for you feel free to open an issue!
after:
- default_return_to: https://self-service/login/return_to
+ default_browser_return_url: https://self-service/login/return_to
password:
- default_return_to: https://self-service/login/password/return_to
+ default_browser_return_url: https://self-service/login/password/return_to
hooks:
- hook: revoke_active_sessions
oidc:
- default_return_to: https://self-service/login/podc/return_to
+ default_browser_return_url: https://self-service/login/podc/return_to
hooks:
- hook: revoke_active_sessions
Self-Service Registration
selfservice.registration has moved from to selfservice.flow.registration:
selfservice:
- registration:
+ flows:
+ registration:
On top of this change, a few keys under registration have changed as well:
selfservice
flows:
registration:
+ ui_url: http://127.0.0.1:4455/auth/registration
request_lifespan: 99m
- before:
- hooks:
- - hook: redirect
- config:
- default_redirect_url: http://test.kratos.ory.sh:4000/
- allow_user_defined_redirect: false
+ # The before hooks have been removed because there were no good use cases for them. If
+ # this is a problem for you feel free to open an issue!
after:
- default_return_to: https://self-service/registration/return_to
+ default_browser_return_url: https://self-service/registration/return_to
password:
- default_return_to: https://self-service/registration/password/return_to
+ default_browser_return_url: https://self-service/registration/password/return_to
hooks:
- hook: revoke_active_sessions
+ # The verify hook is now executed automatically when verification is turned on.
- - hook: verify
+ # The redirect hook was confusing as it aborts the registration flow and does not solve redirection on
+ # success. It has thus been removed.
- - hook: redirect
oidc:
- default_return_to: https://self-service/registration/podc/return_to
+ default_browser_return_url: https://self-service/registration/podc/return_to
hooks:
- hook: revoke_active_sessions
+ # The verify hook is now executed automatically when verification is turned on.
- - hook: verify
+ # The redirect hook was confusing as it aborts the registration flow and does not solve redirection on
+ # success. It has thus been removed.
- - hook: redirect
Self-Service Settings
selfservice.settings has moved from to selfservice.flow.settings:
selfservice:
- settings:
+ flows:
+ settings:
On top of this change, a few keys under settings have changed as well:
selfservice
flows:
settings:
+ ui_url: http://127.0.0.1:4455/settings
request_lifespan: 99m
privileged_session_max_age: 99m
- default_return_to: https://self-service/settings/return_to
after:
+ default_browser_return_url: https://self-service/settings/return_to
+ # The profile/password after hooks have been removed as verification is now executed automatically
+ # when turned on.
- password:
- hooks:
- - hook: verify
- profile:
- hooks:
- - hook: verify
Self-Service Verification
selfservice.verify has moved from to selfservice.flow.verification:
selfservice:
- verify:
+ flows:
+ verification:
Instead of configuring verification with hooks and other components, it can now
be enabled in a central place. If enabled, a SMTP server must be configured in
the courier section. You are still required to mark a field as verifiable in
your Identity JSON Schema.
selfservice:
flows:
verification:
+ enabled: true # defaults to true
+ ui_url: http://127.0.0.1:4455/recovery
request_lifespan: 1m
- default_return_to: https://self-service/verification/return_to
after:
+ default_browser_return_url: https://self-service/verification/return_to
Replaces the update_successful field of the settings request with a field
called state which can be either show_form or success.
Flows, request methods, form fields have had a key errors to show e.g.
validation errors such as ("not an email address", "incorrect
username/password", and so on. The errors key is now called messages. Each
message now has a type which can be error or info, an id which can be
used to translate messages, a text (which was previously errors[*].message).
This affects all login, request, settings, and recovery flows and methods.
To refresh a login session it is now required to append refresh=true instead
of prompt=login as the second has implications for revoking an existing issue
and might be confusing when used in combination with OpenID Connect.
identity.addresses has moved to identity.verifiable_addresses.selfservice.verification.link_lifespan has been merged
with selfservice.verification.request_lifespan.Account recovery can't use recovery token (#526) (379f24e), closes #525
Add and document recovery to quickstart (c229c54)
Add pkger to docker builds (d3ef5a0)
Allow linking oidc credentials without existing oidc connection (#548) (39c1234), closes #532
Clear error messages after updating settings successfully (#421) (7eec388), closes #420
Document login refresh parameter in swagger (#482) (6b94993)
Enable recovery for quickstart (0ccc651)
Improvements to Dockerfiles (#552) (6023877):
Initialize verification request with correct state (3264ecf), closes #543
Re-add redirect targets for quickstart (3c48ad2)
Reduce docker bloat by ignoring docs and others (ecc555b)
Resolve broken redirect in verify flow (a9ca8fd), closes #436
Respect multiple secrets and fix used flag (#526) (b16c2b8), closes #525
Respect self-service enabled flag (#470) (b198faf), closes #417:
Respects the enabled flag for self-service strategies.
Also a new testhelper function was needed, to defer route registration (because whether strategies are enabled or not is determined only once: at route registration)
Typo accent -> account (984d978)
Improve and simplify configuration (#536) (8e7f9f5), closes #432
Move schema packing to pkger (173f9d2)
Move verify fallback to verification (1ce6469)
Rename identity traits schema to identity schema (#557) (949e743), closes #531
Rename prompt=login to refresh=true (#478) (c04346e), closes #477
Replace settings update_successful with state (#488) (ca3b3f4), closes #449
Text errors to text messages (#476) (8106951), closes #428:
This patch implements a better way to deal with text messages by giving them a unique ID, a context, and a default message.
Add azure to next docs (e1dd3fa)
Add fixme note for viper workaround (7e3eef6):
See https://github.com/ory/x/issues/169
Add guide for setting up account recovery (bbf3762)
Add guide for setting up email verification (1435cbc)
Add new guides to sidebar (24c5cbc)
Correct claims.email in github guide (#422) (052a622):
There is no email_primary in claims, and the selfservice strategy is currently using claims.email.
Correct claims.email in github guide (#422) (58f7e15):
There is no email_primary in claims, and the selfservice strategy is currently using claims.email.
Correct link in user-settings (d13317d)
Correct stray dot (e820f41)
Correct user settings render form (197e246)
Delete old redirect homepage (b6d9244)
Document new account recovery feature (2252a86), closes #436
Document refresh=true for login (#479) (2ab5ead), closes #464
Fix broken link (d20816e)
Fix broken link (aa9d3e6)
Fix broken link (#506) (dac8dfd):
The rest api is no longer under sdk but under reference.
Fix code sample comment (781a76b)
Fix copy paste errors in code docs (e456a4e)
Fix typos (81903a5)
Fix ui url keys everywhere (b75debb)
Fix username example by renaming property and removing format (#508) (4573426)
Fix wording in settings flow graph (e2a0084)
Fixed broken links (#451) (193a781):
Fixed a few broken links, .md in the url was the problem.
Format guides (407c70f)
Improve grammar, clarify sections, update images (#419) (79019d1)
Make whitelisted_return_to_urls examples an array (#426) (7ed5605), closes #425
Move security questions to own document (2b77fba)
Properly annotate forms disabled field (#486) (be1acb3):
See https://github.com/ory/kratos/pull/467#discussion_r434764266
Rename redirect page to browser-redirect-flow-completion (ae77d48)
Replace mailhog references with mailslurper (#509) (d0e5a0f)
Run format (2b3f299)
Typos and stale links (29fb466)
Update repository templates (4c89834)
Use central banner repo for README (d1e8a82)
Use shorthand closing tag for Mermaid (f9f2dbc)
Add support for Multitenant Azure AD as an OIDC provider (#434) (a8f1179)
Add tests for defaults (a16fc51)
Add User ID to a header when calling whoami (#530) (183b4d0)
Implement account recovery (#428) (e169a3e), closes #37:
This patch implements the account recovery with endpoints such as "Init
Account Recovery", a new config value urls.recovery_ui and so on. A new
identity field has been added identity.recovery_addresses containing all
recovery addresses.
Additionally, some refactoring was made to DRY code and make naming consistent. As part of dependency upgrades, structured logging has also improved and an audit trail prototype has been added (currently streams to stderr only).
Nothing published for this version
…connections will stop working. Check out the "Breaking Changes" section for more info! Want to learn more? Check out the docs!
This release finalizes the OpenID Connect and OAuth2 login, registration, and settings strategy with JsonNet data transformation! From now on, "Sign in with Google, Github, ..." is officially supported! It's also possible to link and unlink these connections using the Self-Service Settings Flow! The documentation has been updated to reflect those changes and includes guides to setting up "Sign in with GitHub" in under 5 Minutes! Please be aware that existing OpenID Connect connections will stop working. Check out the "Breaking Changes" section for more info! Want to learn more? Check out the docs!
We also changed the config validation output, making it easier than ever to find bugs in your config:
% kratos --config invalid-config.yml serve
INFO[0001] Config file loaded successfully. path=invalid-config.yml
ERRO[0001] The provided configuration is invalid and could not be loaded. Check the output below to understand why. config_file=invalid-config.yml
dsn: <nil>
^-- one or more required properties are missing
urls.whitelisted_return_to_urls: https://selfservice.office.example.com
^-- expected array, but got string
FATA[0001] The services failed to start because the configuration is invalid. Check the output above for more details.
This release concludes over 50 commits and 16.000 lines of code changed.
If you upgrade and have existing Social Sign In connections, it will no longer be possible to use them to sign in. Because the oidc strategy was undocumented and not officially released we do not provide an upgrade guide. If you run into this issue on a production system you may need to use SQL to change the config of those identities. If this is a real issue for you that you're unable to solve, please create an issue on GitHub.
This is a breaking change as previous OIDC configurations will not work. Please consult the newly written documentation on OpenID Connect to learn how to use OIDC in your login and registration flows. Since the OIDC feature was not publicly broadcasted yet we have chosen not to provide an upgrade path. If you have issues, please reach out on the forums or slack.
Access rules of oathkeeper for quick start (#390) (5ed6d05), closes #389:
To access / as dashboard
Active field should not be required (#401) (aed2a5c), closes ory/sdk#14
Adopt jsonnet in e2e oidc tests (5e518fb)
Detect postgres unique constraint (3a777af)
Fix oidc strategy jsonnet test (f6c48bf)
Improve config validation error message (#414) (d1e6896), closes #413
Reset request id after parse (9550205)
Resolve regression issues and bugs (e6d5369)
Return correct error on id mismatch (5915f28)
Test and implement mapper_url for jsonnet (40ac3dc)
Transaction usage in the identity persister (#404) (7f5072d)
Adopt new request parser (ad16cc9)
Dry config and oidc tests (3e98756)
Improve oidc flows and payloads and add e2e tests (#381) (f9a5079), closes #387:
This patch improves the OpenID Connect login and registration user experience by simplifying the network flows and introduces e2e tests using ORY Hydra.
Move cypress files to test/e2e (df8e627)
Partition files and change creds structure (4f1eb94):
This patch changes the data model of the OpenID Connect strategy. Instead of
using an array of providers as the base config item (e.g.
{"type":"oidc","config":[{"provider":"google","subject":"..."}]}) the
credentials config is now an object with a providers key:
{"type":"oidc","config":{"providers":[{"provider":"google","subject":"..."}]}}.
This change allows introduction of future changes to the schema without
breaking compatibility.
Replace oidc jsonschema with jsonnet (2b45e79), closes #380:
This patch replaces the previous methodology of merging OIDC data which used JSON Schema with Extensions and JSON Path in favor of a much easier to use approach with JSONNet.
settings: Use common request parser (ad6c402)
Document account enumeration defenses for oidc (266329c), closes #32
Document oidc strategy (#415) (9f079f4), closes #409 #124 #32
Explain that form data is merged with oidc data (#394) (b0dbec4), closes #127
Improve social sign in guide (#393) (647ced3), closes #49:
This patch changes the social sign in guide to represent more use cases such as Google and Facebook. Additionally, the example has been updated to work with Jsonnet.
This patch also documents limitations around merging user data from GitHub.
Prepare v0.3.0-alpha.1 (d6a6f43)
Add format and lint for JSONNet files (0a1b244):
This patch adds two commands kratos jsonnet format and kratos jsonnet lint
that help with formatting and linting JSONNet code.
Implement oidc settings e2e tests (919925c)
Introduce leaklog for debugging oidc map payloads (238d7a4)
Write tests and fix bugs for oidc settings (575a61f)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Resolves a bug in the kratos-selfservice-ui-node application.
BREAKING CHANGE: Please remove the redirect hook from both login, registration, and settings after configuration. Please remove the session hook from…
This is a heavy release with over hundreds of commits and files changed! Let's take a look at some of the highlights!
ORY Oathkeeper now optional
Using ORY Oathkeeper to protect your API is now optional. The basic quickstart now uses a much simpler set up. Go check it out now!
PostgreSQL, MySQL, CockroachDB support now tested and official!
All three databases now pass acceptance tests and are thus officially supported!
Self-Service Profile Flow
The self-service profile flow has been refactored into a more generic flow allowing users to make modifications to their traits and credentials. Check out the docs to learn more about the flow and it's features.
Please keep in mind that the flow's APIs have changed. We recommend re-reading the docs!
Managing Privileged Profile Fields
Flows such as changing ones profile or primary email address should not be possible unless the login session is fresh. This prevents your colleague or evil friend to take over your account while you make yourself a coffee.
ORY Kratos now supports this by redirecting the user to the login screen if changes to sensitive fields are made. The changes will only be applied after successful reauthentication.
Changes to Hooks
This patch focuses on refactoring how self-service flows terminate and changes how hooks behave and when they are executed.
Before this patch, it was not clear whether hooks run before or after an identity is persisted. This caused problems with multiple writes on the HTTP ResponseWriter and other bugs.
This patch removes certain hooks from after login, registration, and profile
flows. Per default, these flows now respond with an appropriate payload (
redirect for browsers, JSON for API clients) and deprecate the redirect hook.
This patch includes documentation which explains how these hooks work now.
Additionally, the documentation was updated. Especially the sections about hooks have been refactored. The login and user registration docs have been updated to reflect the latest changes as well.
BREAKING CHANGE: Please remove the redirect hook from both login,
registration, and settings after configuration. Please remove the session hook
from your login after configuration. Hooks have moved down a level and are now
configured at selfservice.<login|registration|settings>.<after|before>.hooks
instead of selfservice.<login|registration|settings>.<after|before>.hooks.
Hooks are now identified by hook: instead of job:. Please rename those
sections accordingly.
We recommend re-reading the Hooks Documentation.
Changing Passwords
It's now possible to change your password using the Self-Service Settings Flow! Lean more about this flow here
End-To-End Tests
We added tons of end-to-end and integration tests to find and fix pesky bugs.
Please remove the redirect hook from both login, registration, and settings
after configuration. Please remove the session hook from your login after
configuration. Hooks have moved down a level and are now configured at
selfservice.<login|registration|settings>.<after|before>.hooks instead of
selfservice.<login|registration|settings>.<after|before>.hooks. Hooks are now
identified by hook: instead of job:. Please rename those sections
accordingly.
Several profile-related URLs have and payloads been updated. Please consult the most recent documentation.
The payloads of the Profile Management Request API that previously were set in
{ "methods": { "traits": { ... } }} have now moved to
{ "methods": { "profile": { ... } }}.
This patch introduces a refactor that is needed for the profile management API to be capable of handling (password, oidc, ...) credential changes as well.
To implement this, the payloads of the Profile Management Request API that
previously were set in {"form": {...} } have now moved to
{"methods": { "traits": { ... } }}.
In the future, as more credential updates are handled, there will be additional
keys in the forms key {"methods": { "traits": { ... }, "password": { ... } }}.
Allow setting new password in profile flow (3b5fd5c)
Automatically append multiStatements parameter to mySQL URI (#374) (39f77bb)
Create pop connection without parsed connection options (#366) (10b6481)
Decouple quickstart scenarios (#336) (17363b3), closes #262:
Creates several docker compose examples which include various scenarios of the quickstart.
The regular quickstart guide now works without ORY Oathkeeper and uses the standalone mode of the example app instead.
Additionally, the Makefile was improved and now automatically pulls required dependencies in the appropriate version.
docker: Throw away build artifacts (481ec1b)
Document Schema API and serve over admin endpoint (#299) (4be417c), closes #287
Fix swagger annotation (#331) (5c5c78f):
Closes https://github.com/ory/sdk/issues/10
Properly annotate error API (a6f1300)
Remove unused returnTo (e64e5b0)
Resolve docker build permission issues (f3612e8)
Resolve failing test issues (2e968e5)
Resolve linux install script archive naming (#302) (c98b8aa)
Resolve NULL value for seen_at (#259) (a7d1e86), closes #244:
Previously, errorx tests were not executed which caused several bugs.
Resolve password continuity issues (56a44fa)
Revert use host volume mount for sqlite (#272) (#285) (a7477ab):
This reverts commit 230ab2d83f4d187f410e267c6d68554e82514948.
Self-service error query parameter name (#308) (be257f5):
The query parameter for the self-service errors endpoint was named id in the
API docs, whereas it is the error param that is used by the handler.
session: Regenerate CSRF Token on principal change (#290) (1527ef4), closes #217
session: Whoami endpoint now supports all HTTP methods (#283) (4bf645b), closes #270
Show log in ui only when unauthenticated or forced (df77310), closes #323
sql: Rename migrations with same version (#280) (07e46b9), closes #279
swagger: Move nolint,deadcode instructions to own file (#293) (1935510):
Closes https://github.com/ory/docs/pull/279
Use resilient client for HIBP lookup (#288) (735b435), closes #261
Use semver-regex replacer func (d5c9a47)
Use sqlite tag on make install (2c82784)
Verified_at field should not be required (#353) (15d5e26):
Closes https://github.com/ory/sdk/issues/11
Prepare profile management payloads for credentials (44493f3)
Rename traits method to profile (4f1e033)
Rework hooks and self-service flow completion (#349) (a7c7fef), closes #348 #347 #179 #51 #50 #31:
This patch focuses on refactoring how self-service flows terminate and changes how hooks behave and when they are executed.
Before this patch, it was not clear whether hooks run before or after an identity is persisted. This caused problems with multiple writes on the HTTP ResponseWriter and other bugs.
This patch removes certain hooks from after login, registration, and profile
flows. Per default, these flows now respond with an appropriate payload (
redirect for browsers, JSON for API clients) and deprecate the redirect
hook. This patch includes documentation which explains how these hooks work
now.
Additionally, the documentation was updated. Especially the sections about hooks have been refactored. The login and user registration docs have been updated to reflect the latest changes as well.
Also, some other minor, cosmetic, changes to the documentation have been made.
Add banner kratos (8a9dfbb)
Add csrf and cookie debug section (#342) (cac2948), closes #341
Add HA docs (2e5c591)
Add hook changes to upgrade guide (55b5fe0)
Add more examples to config schema (#372) (ed2ccb9), closes #345
Add quickstart notes for docker debugging (74f082a)
Add settings docs and improve flows (#375) (478cd9c), closes #345
concepts: Fix typo (a49184c):
Closes https://github.com/ory/docs/pull/296
concepts: Properly close code tag (1c841c2)
Declare api frontmatter properly (df7591f)
Document 0.2.0 high-level changes (9be1064), closes hi#level
Fix broken images in quickstart (52aa4cf)
Fix broken mermaid links (f24fc1b)
Improve profile section and restructure nav (#373) (3cc0979), closes #345
Regenerate and update changelog (7d4ed98)
Regenerate and update changelog (175b626)
Regenerate and update changelog (e60e2df)
Regenerate and update changelog (41eeb75)
Regenerate and update changelog (468105a)
Regenerate and update changelog (8414520)
Regenerate and update changelog (85d5866)
Regenerate and update changelog (e8d2d10)
Regenerate and update changelog (4c58b6d)
Regenerate and update changelog (a726eb2)
Regenerate and update changelog (87b47ba)
Regenerate and update changelog (537d496)
Regenerate and update changelog (00e6af9)
Regenerate and update changelog (48a2eca)
Regenerate and update changelog (8a71948)
Regenerate and update changelog (ad3d510)
Regenerate and update changelog (48bcc70)
Regenerate and update changelog (816a55c)
Regenerate and update changelog (4ed74d2)
Regenerate and update changelog (367927e)
Regenerate and update changelog (38f4019)
Update banner url (292c986)
Update forum and chat links (3039191)
Update linux install guide (3b8e549)
Update self service reg docs (#367) (4cf0323):
The old links pointed at /auth/browser/(login|registration) which seems to
be outdated now.
From the ui node code: https://github.com/ory/kratos-selfservice-ui-node/blob/489c76d1b0474ee55ef56804b28f54d8718747ba/src/routes/auth.ts#L28 and the api documentation for kratos https://www.ory.sh/kratos/docs/reference/api#get-the-request-context-of-browser-based-login-user-flows, these seem to be incorrect.
The actual url hit is
/self-service/browser/flows/requests/(login|registration). This commit
updates those links
This blob was previously one large inline string, which personally made the docs a bit hard to read. This formats it into an (arguably) easier to parse code block
Use git checkout <tag> in quickstart (#339) (2d2562b), closes #335
Allow configuring same-site for session cookies (#303) (2eb2054), closes #257:
It is now possible to set SameSite for the session cookie via the key
security.session.cookie.same_site.
continuity: Implement request continuity (135e047), closes #304 #311:
This patch adds a module which is capable of aborting a request, waiting for another option to complete, and then resuming the request again.
This feature makes use of a temporary cookie which keeps track of the request state.
This feature is required for several workflows that update privileged fields such as passwords, 2fa recovery codes, email addresses.
refactor: rename profile to settings flow
Renames selfservice/profile to settings. The settings flow includes a strategy for managing profile information
Enable CockroachDB integration (#260) (adc5153), closes #132 #155
Enable continuity management for settings module (009d755)
Enable updating auth related traits (#266) (65b88ba), closes #243
Implement password profile management flow (a31839a), closes #243
Introduce fallbacks for required configs (#376) (b3bcb25), closes #369 #352
login: Forced reauthentication (#248) (344fc9c), closes #243
Return 410 when selfservice requests expire (#289) (b414607), closes #235
Send verification emails on profile update (#333) (1cacc80), closes #267
u (0b6fa48)
u (03fa4f0)
u (a3dfd9d)
u (616aa0f)
fix:add graceful shutdown to courier handler (#296) (235d784), closes #296 #295:
Courier would not stop with the provided Background handler. This changes the methods of Courier so that the graceful package can be used in the same way as the http endpoints can be used.
fix(sql) change courier body to text field (#276) (ed5268d), closes #276 #269
Make format (b85e5af)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
docs: Regenerate and update changelog
Nothing published for this version
Nothing published for this version
feat: Add verification to quickstart
feat: Add verification to quickstart (#251)
Nothing published for this version
docs: Regenerate and update changelog
Nothing published for this version
Regenerate and update changelog
Nothing published for this version
ci: Bump ory/sdk orb ### Continuous Integration - Bump ory/sdk orb
Nothing published for this version
docs: Regenerate and update changelog
docs: Regenerate and update changelog
Update CHANGELOG [ci skip] (ce9390c)
refactor!: Improve user-facing error APIs (#219) (7d4054f), closes #219 #204:
This patch refactors user-facing error APIs:
/errors endpoint moved to /self-service/errors[{"code": ...}] is now
{"id": "...", "errors": [{"code": ...}]}This patch requires running kratos migrate sql as a new column
(csrf_token) has been added to the user-facing error store.
Update CHANGELOG [ci skip] (c368a11)
Nothing published for this version
docs: Updates issue and pull request templates
docs: Updates issue and pull request templates (#215)
Signed-off-by: aeneasr aeneas@ory.sh
Nothing published for this version
Update permissions in SQLite Dockerfile
Update permissions in SQLite Dockerfile
Nothing published for this version
Update README.md ### Unclassified - Update README.md
Nothing published for this version
Allow mounting SQLite in /home/ory/sqlite
Your coding agent can read these notes before it upgrades. Set up the MCP server →