1_6_7.md

doc/release_notes/1_6_7.md

1.6.7

Improvements

  • Some new capabilities were built into rodauth recently, which rodauth-oauth now taps into:

  • plugins are now object shape friendly, by defining ivars using rodauth‘s :uses_instance_variables auth method (introduced in v2.44)

  • :oidc plugin get_oidc_param and get_additional_param now have a default implementation, which raises an error (eliminates warnings).

  • only_json? auth method is no longer defined (unless the :jwt plugin is used).

  • some internal methods were now moved to private, instead of being needlessly exposed (eliminates security warnings).

  • a new auth method, confidential?(oauth_application), was added to the :oauth_base plugin, which is now used internally to check in some key flows whether the OAuth client application is a public or a confidential client, as it’s defined in the OAuth RFC:

  • when using the :oauth_dynamic_client_registration plugin, a client secret won’t be generated for public clients (same logic will be applied for client registration management endpoints).

  • when using the :oauth_application_management plugin, default templates will include a client type column, and omit the client secret for public clients, where they would previously.

Bugfixes

  • do not render null fields in the payload of the oauth server metadata endpoint (RFC 8414 section 2 requires omission of undefined values, so clients can apply the recommended defaults).

  • fixed regexp used for json requests (same fix as in rodauth)