- allow empty body without content-type on userinfo (d5148ad)
- forbid “none” id token algorithm when backchannel logout is used (797919e)
- registered native loopback redirect_uris do not get normalized (96e035f)
- add support for secp256k1 elliptic curve use (30aa706)
- use shake256(m, 114) for Ed448 ID Token
*_hash claims (7e6ba6f)
- add script tag nonce resolution helper for session management and wmrm (#584) (b32b8e6), closes #583
- ensure BaseModel descendants have an exp property (22cc547), closes #580
- regression introduced in 58f7348 (4738a8b)
- add jwsreq Accept value to request_uri resolver (cec4016)
- expose client schema invalidate(err, code) to enable customization (d672ee8)
- ignore httpOnly and domain configuration options for resume cookies (952d68e), closes #574
- handle DPoP htu validation when mounted in express (f34526c), closes #572
- use sha512 for Ed25519 and shake256 for Ed448 ID Token
*_hash claims (fd3c9e9)
- autosubmit logout when there’s no accountId in the session (c6b1770), closes #566
- omit
*_hash ID Token claims if signed with “none” (code flow only) (5c540c0)
- add interaction<>session consistency checks (018255e)
- update DPoP implementation to indivudal draft 03 (a7f5d7d)
- respect mountPath when rendering device flow html views (74b434c), closes #561
- typescript: add findByUserCode to DeviceCode types (df58cff)
- remove registration access token when client is deleted (e24ad4a), closes #555
- typescript: allow registration policies type to be async (0a46a65), closes #551
- cookies: use ctx.secure from the mount context when available (c8d8fe6)
- mounted devInteractions now honour the mount path (8fb8af5), closes #549 #548
- typescript: add missing OIDCContext cookies property (0c04af6)
- forbid redirect_uri with an empty fragment component (ca196a0)
- v6.12.6 native app uris regression fixed (fd56ef6)
- typescript: revert void/undefined changes from 6.12.3 (e0bbaae), closes #541
- use updated jose package (ee17022)
- typescript: fix void/undefined inconsistencies and ts lint (96c9415)
- do not send empty secret to adapter in a DCR edge case (af9ecd9)
- fixed session management state fallback cookie name (91b0dea)
- handle sameSite=none incompatible user-agents (4e68415)
- typescript: provider.callback getter type regression fixed (5cea116), closes #534
- token TTL being a helper function is now accepted (a930355)
- default refresh token TTL policy for SPAs follows the updated BCP (d6a2a34)
- update JWT Response for OAuth Token Introspection to draft 08 (5f917e2)
- update FAPI RW behaviours (a7ed27a)
- update pushed authorization requests draft (aaf5740)
← Newer entries | Older entries →