- memory adapter grant references for intended models (357ced3)
- build client symmetric keys from all client signing alg properties (a26f87d)
- url encode client_id returned in registration responses (500dfeb)
- graduate jwtResponseModes (JARM) feature as stable (7b878cd)
- enable v18 LTS in package.json (e423b4d)
- graduate backchannelLogout feature as stable (617e260)
- ignore instead of throw on unverified post_logout_redirect_uri (04b1096)
- PAR: set additional stored PAR object properties on plain requests (1be15fa)
- PAR: skip stored PAR object alg validation when it’s being used (406caa4)
- arrow & static class methods as adapter factories (#1197) (cee552f)
- updated
signed to trusted in the Interaction model (#1192) (eb91aea)
- client schema invalidation code not set (edf22fb)
- allow native app callbacks in client post_logout_redirect_uris (3fca22b)
- bump backchannelLogout to draft-07 (95611d9)
- graduate issAuthResp feature as stable and enable by default (e774f60)
- ensure jwt replay detection takes clockTolerance into account (f167233)
- substr > slice change in mountPath should have been substring (adc0d63)
- resourceIndicators: await the result of useGrantedResource (#1173) (64a8028)
- add iss to error responses when issAuthResp is enabled (05ac3a8)
- expose invalid_dpop_proof error code and set it to 401 on userinfo (2628d7e)
- use paseto configuration from
getResourceServerInfo (#1150) (02c821d)
- clearly mark that multiple pop mechanisms are not allowed (49eed4c)
- duplicate iss and aud as JWE Header Parameters (b26ea44)
- add LTS Gallium as a supported runtime version (19b4d0d)
- use insufficient_scope instead of invalid_scope at userinfo_endpoint (ba8a8f0)
- OAuth 2.0 Pushed Authorization Requests (PAR) is now a stable feature (3c54d8d)
- CIBA Core 1.0 is now a stable feature (cc8bc0d)
- support v3.local, v3.public, and v4.public paseto access tokens format (aca5813)
- add missing x-ua-compatible to form_post and dag input (f773669), closes #1052
- memory adapter grant references for intended models (2fe4dc8)
- use correct keystore select method for paseto access tokens (ce394bc)
- issue id tokens with claims when resource is used (#1038) (4b16c71)
- use 303 See Other HTTP response status code for built in redirects (c243bf6)
- handle backchannel requests in grant revocation (8fe9aec)
← Newer entries | Older entries →