ItalyPaleAle
fadb1a5552
feat: add FRANCIS_HOST to connect to a standalone Francis runtime
...
FRANCIS_HOST decides where the Francis actor runtime lives. When set to "embedded" (the default), Pocket ID starts the runtime inside its own process.
Any other value is the address, or a comma-separated list of addresses, of a standalone Francis runtime. Pocket ID then connects to it as a remote actor host and starts no embedded runtime.
Because when using a remote runtime, it's likewise not possible to enforce a single instance of Pocket ID is running at once, the env vars currently have the `EXPERIMENTAL_` prefix, are **undocumented**, and show a warning if used.
Notes:
- Connecting to a standalone runtime also needs FRANCIS_HOST_PSK or FRANCIS_HOST_JWT_FILE, and optionally (but recommended) FRANCIS_CA.
- When connecting to a remote runtime, exporting Pocket ID data does not include the actor state, which will need to be backed up and restored separately
2026-09-19 23:38:18 -07:00
Elias Schneider
2084dffd8d
fix: prevent PAR requirement bypass via conflicting request parameters
2026-09-17 21:37:41 +02:00
Alessandro (Ale) Segala
01cc44246a
chore: upgrade jwx to v4 ( #1730 )
2026-08-31 14:12:35 -07:00
Alessandro (Ale) Segala
fa8aa44706
chore: update Francis to rc.2 ( #1728 )
2026-08-31 05:15:48 -07:00
Alessandro (Ale) Segala and copilot-swe-agent[bot]
7c79a9e14b
feat: add explicit public keys for federated client credentials ( #1702 )
...
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
2026-08-28 21:12:15 +00:00
Elias Schneider
915a6bcf08
feat: allow admins to auto grant APIs to CIMD clients ( #1692 )
2026-08-18 20:02:14 +02:00
Alessandro (Ale) Segala
be4c395528
refactor: move remaining database cleanup jobs to actors ( #1698 )
2026-08-17 08:38:35 +02:00
Elias Schneider
9421d43f8e
fix: ignore trailing slash in resources
2026-08-17 08:34:28 +02:00
Elias Schneider
1bb21c5d73
refactor: move iss param handling to Fosite
2026-08-12 23:25:35 +02:00
Alessandro (Ale) Segala
155a1fcba0
feat: support multiple client secrets per OIDC client ( #1679 )
2026-08-11 00:54:52 +00:00
Alessandro (Ale) Segala
84a58cd757
fix: ignore unsupported grant types in client ID metadata documents ( #1682 )
2026-08-10 09:45:34 -07:00
Elias Schneider
5d43c4aaeb
feat: add ability to customize session duration of clients ( #1641 )
2026-08-03 23:23:29 +02:00
Elias Schneider
7a4d0dd275
refactor: standardize API error handling ( #1635 )
2026-08-02 23:36:06 +02:00
Elias Schneider
598895e7c5
fix: session revoke fails if orphaned session tokens exist
2026-08-02 18:31:15 +02:00
Jean-François Roy and Elias Schneider
1934efa84c
feat: implement OAuth Client ID Metadata Document ( #1525 ) ( #1526 )
...
Co-authored-by: Elias Schneider <login@eliasschneider.com >
2026-08-02 15:05:39 +00:00
Elias Schneider
7c55bdf115
feat: make oauth access tokens RFC 9068 compliant
2026-08-02 15:59:21 +02:00
Elias Schneider and ItalyPaleAle
e1fd1d320f
feat: add qr code alternative sign in method ( #1594 )
...
Co-authored-by: ItalyPaleAle <43508+ItalyPaleAle@users.noreply.github.com >
2026-07-28 01:30:13 +02:00
Elias Schneider
6bd058ac46
fix: make oidc device code redemption atomic
2026-07-27 20:32:42 +02:00
Elias Schneider
d9ead47d19
fix: allow insecure callback URLs by default until next major release
2026-07-13 09:21:53 +02:00
Alessandro (Ale) Segala
b2711ced99
fix: /authorize endpoint crashes when list of scopes is empty ( #1575 )
2026-07-08 17:48:32 -07:00
Elias Schneider
190914fd72
refactor: remove duplicate fosite config properties
2026-07-08 11:01:50 +02:00
Elias Schneider
25dcad757a
feat: add support for unencrypted OIDC request parameter
2026-07-08 10:42:05 +02:00
Elias Schneider
fa2d08cb6d
refactor: remove redundant dtos
2026-07-07 11:51:37 +02:00
Elias Schneider
2f55b7cbc3
fix: device authorization resolve resource creating device_code
2026-07-07 11:51:02 +02:00
Elias Schneider
7667377c98
refactor: pass transaction to resolveResource
2026-07-07 11:14:19 +02:00
Elias Schneider
5e2cc6f40e
fix: merge requested scopes instead of replacing them
2026-07-07 11:03:06 +02:00
Elias Schneider
e8cb0c831c
fix: re-check api permissions on access token refresh
2026-07-07 10:58:39 +02:00
Elias Schneider
9a94aa0694
refactor: move Pocket ID specific logic from Fosite into Pocket ID repo
2026-07-06 23:34:33 +02:00
Elias Schneider
34e9a6d198
fix: restore behavior that unknown scopes get ignored
2026-07-06 22:42:38 +02:00
Elias Schneider and Alessandro Segala
09d196f7c5
feat: add OAuth APIs with scoped permissions ( #1542 )
...
Co-authored-by: Alessandro (Ale) Segala <43508+ItalyPaleAle@users.noreply.github.com >
2026-07-06 12:25:02 -07:00
9607495ab4
refactor: integrate Francis actor framework for background jobs, cron scheduling, and rate limiting ( #1556 )
...
Co-authored-by: Elias Schneider <login@eliasschneider.com >
Co-authored-by: Claude <noreply@anthropic.com >
2026-07-03 08:36:45 +02:00
97bd466f38
feat: prompt admin with PKCE client support hint ( #1499 )
...
Co-authored-by: james <james@goldfish.net >
Co-authored-by: Alessandro (Ale) Segala <43508+ItalyPaleAle@users.noreply.github.com >
Co-authored-by: Elias Schneider <login@eliasschneider.com >
Co-authored-by: Kyle Mendell <kmendell@ofkm.us >
2026-06-28 11:10:30 -07:00
Elias Schneider
d467855870
feat: add ability to skip consent for client
2026-06-26 23:35:26 +02:00
Elias Schneider
16b5c16a66
fix: CSP error with response_mode=form_post
2026-06-26 14:51:56 +02:00
Elias Schneider
2ed703540d
fix: don't reject offline_accessscope
2026-06-26 14:43:22 +02:00
Elias Schneider
8689ddd72b
feat: improve error handling on authorize page
2026-06-22 22:12:14 +02:00
Elias Schneider
519cda0eef
refactor: remove dead code
2026-06-22 21:58:55 +02:00
Elias Schneider
8158452b37
refactor: use fosite for OAuth 2.0 logic ( #1520 )
2026-06-22 18:42:02 +02:00