Elias Schneider
|
d259a15131
|
feat: restore old behavior of automatically creating client secret
|
2026-09-23 22:00:43 +02:00 |
|
 
|
2075de3234
|
feat: add OIDC back-channel logout (#1734)
Co-authored-by: Alessandro (Ale) Segala <43508+ItalyPaleAle@users.noreply.github.com>
Co-authored-by: Elias Schneider <login@eliasschneider.com>
|
2026-09-23 21:34:38 +02:00 |
|
Alessandro (Ale) Segala
|
155a1fcba0
|
feat: support multiple client secrets per OIDC client (#1679)
|
2026-08-11 00:54:52 +00:00 |
|
Elias Schneider
|
3ca9a55c71
|
feat: hide apps without launch url on My Apps page
|
2026-08-10 22:53:35 +02:00 |
|
Alessandro (Ale) Segala
|
1c9233c236
|
fix: make OIDC client token lifetimes optional (#1650)
|
2026-08-05 20:11:40 +00:00 |
|
Elias Schneider
|
5d43c4aaeb
|
feat: add ability to customize session duration of clients (#1641)
|
2026-08-03 23:23:29 +02:00 |
|
Elias Schneider
|
7a4d0dd275
|
refactor: standardize API error handling (#1635)
|
2026-08-02 23:36:06 +02:00 |
|
Elias Schneider
|
598895e7c5
|
fix: session revoke fails if orphaned session tokens exist
|
2026-08-02 18:31:15 +02:00 |
|
 Jean-François RoyandElias Schneider
|
1934efa84c
|
feat: implement OAuth Client ID Metadata Document (#1525) (#1526)
Co-authored-by: Elias Schneider <login@eliasschneider.com>
|
2026-08-02 15:05:39 +00:00 |
|
Markus Schanz
|
9f559788a4
|
feat: add support for declaritive client secret configuration (#1619)
|
2026-07-26 16:27:42 +02:00 |
|
Elias Schneider
|
e10f66c07a
|
fix: show only accessible clients on "My Apps" page
|
2026-07-22 18:33:57 +02:00 |
|
 Alessandro (Ale) SegalaandClaude
|
2cfbcb4b67
|
refactor: use actors for db configuration (#1604)
Co-authored-by: Claude <noreply@anthropic.com>
|
2026-07-20 08:48:05 +02:00 |
|
 Sean McKenzieandElias Schneider
|
6734585712
|
feat: add description field to oidc clients (#1547)
Co-authored-by: Elias Schneider <login@eliasschneider.com>
|
2026-07-08 13:41:51 +02:00 |
|
Elias Schneider
|
8158452b37
|
refactor: use fosite for OAuth 2.0 logic (#1520)
|
2026-06-22 18:42:02 +02:00 |
|
Elias Schneider
|
9dd3d319cf
|
feat: delete OAuth refresh token on RP initiated logout (#1480)
|
2026-05-19 17:05:44 +02:00 |
|
Elias Schneider
|
b27a52a591
|
revert: delete refresh tokens on end-session to prevent reuse after logout (#1458)
This reverts commit 7aacbd0245.
|
2026-05-18 23:36:39 +02:00 |
|
Elias Schneider
|
8ad95b8af1
|
refactor: apply go 1.26.0 syntax updated
|
2026-05-18 23:06:54 +02:00 |
|
Elias Schneider
|
ce6bdb9d7e
|
fix: reject unknown PKCE code challenge methods
|
2026-05-18 22:07:20 +02:00 |
|
 wucm667andAlessandro Segala
|
7aacbd0245
|
fix(oidc): delete refresh tokens on end-session to prevent reuse after logout (#1458)
Co-authored-by: Alessandro (Ale) Segala <43508+ItalyPaleAle@users.noreply.github.com>
Signed-off-by: wucm667 <stevenwucongmin@gmail.com>
|
2026-05-15 21:25:40 +00:00 |
|
 Alessandro (Ale) SegalaandElias Schneider
|
f4706cd6cc
|
feat: add support for "select_account" prompt (#1453)
Co-authored-by: Elias Schneider <login@eliasschneider.com>
|
2026-04-26 17:26:21 +00:00 |
|
Elias Schneider
|
e33a9b8c88
|
chore: post dependency upgrade fixes
|
2026-04-26 15:46:35 +02:00 |
|
Elias Schneider
|
978ac87def
|
fix: access token renewal bypasses important checks
|
2026-04-19 18:27:44 +02:00 |
|
  
|
59fe481af9
|
feat: add OpenID Connect prompt Parameter Handling (#1299)
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Elias Schneider <login@eliasschneider.com>
|
2026-04-19 18:03:08 +02:00 |
|
Elias Schneider
|
5c4d7ff877
|
feat: add auth method claim (amr) to tokens (#1433)
|
2026-04-18 22:31:24 +02:00 |
|
 
|
4d22c2dbcf
|
fix: federated client credentials not working if sub ≠ client_id (#1342)
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
2026-03-01 18:48:20 +01:00 |
|
Elias Schneider
|
2af70d9b4d
|
feat: add CLI command for encryption key rotation (#1209)
|
2026-01-07 09:34:23 +01:00 |
|
Elias Schneider
|
f0144584af
|
feat!: drop support for storing JWK on the filesystem (#1088)
|
2025-12-30 17:01:22 +01:00 |
|
 Alessandro (Ale) SegalaandElias Schneider
|
29a1d3b778
|
feat: add database storage backend (#1091)
Co-authored-by: Elias Schneider <login@eliasschneider.com>
|
2025-11-16 18:23:46 +01:00 |
|
Alessandro (Ale) Segala
|
eb3963d0fc
|
fix: use constant time comparisons when validating PKCE challenges (#1047)
|
2025-10-24 08:30:50 +02:00 |
|
Savely Krasovsky
|
901333f7e4
|
feat: client_credentials flow support (#901)
|
2025-09-02 18:33:01 -05:00 |
|
Elias Schneider
|
a5efb95065
|
feat: allow custom client IDs (#864)
|
2025-08-23 18:41:05 +02:00 |
|
 Alessandro (Ale) SegalaandKyle Mendell
|
5550729120
|
feat: encrypt private keys saved on disk and in database (#682)
Co-authored-by: Kyle Mendell <kmendell@ofkm.us>
|
2025-07-03 13:34:34 -05:00 |
|
 Elias SchneiderandAlessandro Segala
|
aefb308536
|
fix: token introspection authentication not handled correctly (#704)
Co-authored-by: Alessandro (Ale) Segala <43508+ItalyPaleAle@users.noreply.github.com>
|
2025-07-01 21:14:07 +00:00 |
|
Alessandro (Ale) Segala
|
b62b61fb01
|
feat: allow introspection and device code endpoints to use Federated Client Credentials (#640)
|
2025-06-09 21:17:55 +02:00 |
|
  
|
05bfe00924
|
feat: JWT bearer assertions for client authentication (#566)
Co-authored-by: Kyle Mendell <ksm@ofkm.us>
Co-authored-by: Kyle Mendell <kmendell@ofkm.us>
Co-authored-by: Elias Schneider <login@eliasschneider.com>
|
2025-06-06 12:23:51 +02:00 |
|