Skip to content

chore(main): release 0.43.0 - #496

Merged
osanderson merged 3 commits into
mainfrom
release-please--branches--main
Oct 2, 2026
Merged

osanderson merged 3 commits into
mainfrom
release-please--branches--main

Conversation

@osanderson

@osanderson osanderson commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

🤖 I have created a release beep boop

0.43.0 (2026-10-02)

⚠ BREAKING CHANGES

  • a client that sends authorization_details must now be registered with every type it requests in storage.RegisteredClientConfig.AuthorizationDetailsTypes (or, for clients registered automatically through OpenID Federation, server.Config.AutomaticRegistration.AuthorizationDetailsTypes), or the request is refused with invalid_authorization_details. An empty list allows no type. See UPGRADING.md for v0.43.0.
  • client: custom storage.SessionStore implementations must persist NewSession.Record and return it as ConsumedSession.Record, in place of the Nonce, PKCEVerifier, ExpectedIssuer, ExpectedRedirectURI and ExpectedResponseMode fields, which are removed. A client requesting max_age now refuses an ID token without auth_time, or one older than max_age allows. See UPGRADING.md for v0.43.0.

Features

  • client: bind the session handle to the browser in an encrypted cookie (6259639)
  • client: check auth_time against max_age, with an opaque session record (33d1a03)
  • client: seal token sets with a TokenSetSealer bound to their owner (6686ba5)
  • extension: read the authorization details a token was granted (fcaf31d)
  • register the RAR types each client may request (e2db87d)
  • resource,serverresource: DPoP-Nonce and UserInfo response helpers (b85f443)
  • resource: build a VerifyRequest from an http.Request (3d0574b)
  • server: carry an interaction in one encrypted cookie (142c0b3)
  • server: catch client RAR types Config.RAR doesn't register (9299dde)
  • server: read the authorization endpoint's request strictly (6ccec35)
  • server: say when an interaction expires, and expire its cookie then (5d8794b)

Bug Fixes

  • client: refuse a max_age over 100 years when the flow begins (687e4b4)
  • extension: refuse RAR members that differ only in case (252d5eb)
  • extension: refuse RAR members that differ only in case at any depth (99cad87)
  • resource: refuse a request with more than one Authorization header (17dc93b)
  • server: answer an unreadable form body as invalid_request (ee2f80a)

This PR was generated with Release Please. See documentation.

@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@osanderson
osanderson force-pushed the release-please--branches--main branch 17 times, most recently from 69d43e6 to 8b2f53d Compare October 2, 2026 08:07
@osanderson
osanderson force-pushed the release-please--branches--main branch from 8b2f53d to 8e5adb7 Compare October 2, 2026 08:12
osanderson and others added 2 commits October 2, 2026 16:13
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…note

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@osanderson
osanderson merged commit 269882d into main Oct 2, 2026
17 checks passed
@osanderson
osanderson deleted the release-please--branches--main branch October 2, 2026 08:58
@osanderson

Copy link
Copy Markdown
Collaborator Author

🤖 Created releases:

🌻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant