1.6.7
Improvements
-
Some new capabilities were built into
rodauthrecently, whichrodauth-oauthnow taps into: -
plugins are now object shape friendly, by defining ivars using
rodauth‘s:uses_instance_variablesauth method (introduced in v2.44) -
:oidcpluginget_oidc_paramandget_additional_paramnow have a default implementation, which raises an error (eliminates warnings). -
only_json?auth method is no longer defined (unless the:jwtplugin is used). -
some internal methods were now moved to private, instead of being needlessly exposed (eliminates security warnings).
-
a new auth method,
confidential?(oauth_application), was added to the:oauth_baseplugin, which is now used internally to check in some key flows whether the OAuth client application is a public or a confidential client, as it’s defined in the OAuth RFC: -
when using the
:oauth_dynamic_client_registrationplugin, a client secret won’t be generated for public clients (same logic will be applied for client registration management endpoints). -
when using the
:oauth_application_managementplugin, default templates will include a client type column, and omit the client secret for public clients, where they would previously.
Bugfixes
-
do not render null fields in the payload of the oauth server metadata endpoint (RFC 8414 section 2 requires omission of undefined values, so clients can apply the recommended defaults).
-
fixed regexp used for json requests (same fix as in rodauth)