296 Commits (v2.30.x)

Author SHA1 Message Date
Tomasz Kleczek 4ffaa60d21 Improve auth flow error handling 5 years ago
Henning 138364ceeb
handlePasswordGrant: insert connectorData into OfflineSession (#2199) 5 years ago
Mark Sagi-Kazar ceb4324c18
test: quick fix flaky test 5 years ago
m.nabokikh 21a01ee811 Add sprig v3 functions to web templates 5 years ago
m.nabokikh 4b54433ec2 Bump golag-ci lint version to 1.40.1 5 years ago
Mark Sagi-Kazar 0bef10ef80
chore(deps): update gosundheit 5 years ago
Alastair Houghton cd0c24ec4d fix: add an extra endpoint to avoid refresh generating AuthRequests. 5 years ago
Alastair Houghton 030a6459d6 fix: reinstate TestHandleAuthCode. 5 years ago
Alastair Houghton 88025b3d7c fix: remove some additional dependencies. 5 years ago
Alastair Houghton 0284a4c3c9 fix: back link on password page needs to be explicit. 5 years ago
Alastair Houghton cdbb5dd94d fix: defer creation of auth request. 5 years ago
Maksim Nabokikh 20875c972e
Discard package "version" (#2107) 5 years ago
Rui Yang fe8085b886 remove client secret encryption option 5 years ago
Rui Yang ecea593ddd fix a bug in hash comparison function 5 years ago
Mark Sagi-Kazar 95796b04a3
chore(deps): upgrade protobuf and grpc 5 years ago
Mark Sagi-Kazar d25051c867
chore(deps): upgrade protobuf in server/internal package 5 years ago
Mark Sagi-Kazar d1e8b085e2
feat: use embedded assets by default 5 years ago
Rui Yang 2f28fc7451 default to ./web when Dir and WebFS are not set 5 years ago
Rui Yang 4e569024fd use go 1.16 new package io/fs 5 years ago
Rui Yang 7b50cbf0ac use pkger for embedding static contents 5 years ago
Rui Yang 1eab25f89f use web host url for asset hosting 5 years ago
Rui Yang 10e9054811 Use http.FileSystem for web assets 5 years ago
Rui Yang d658c24e8f add dex config flag for enabling client secret encryption 5 years ago
Josh Winters ec6f3a2f19 use bcrypt when comparing client secrets 5 years ago
Maksim Nabokikh 568fc06520 Update server/refreshhandlers.go 5 years ago
m.nabokikh 3bd0e91a68 Make /device/token deprecation warning more concise 5 years ago
m.nabokikh 9ed5cc00cf Add deprecation warning for /device/token endpoint 5 years ago
m.nabokikh 1211a86d58 fix: use /token endpoint to get tokens with device flow 5 years ago
Steffen Pøhner Henriksen 0f68fadb9a
Allow public clients created with API to have no client_secret (#1871) 5 years ago
Mark Sagi-Kazar 7da0a89936
refactor: remove unused health checker 5 years ago
Mark Sagi-Kazar 316da70545
refactor: use new health checker 5 years ago
m.nabokikh 9340fee011 Fixes after rebasing to the actual main branch 5 years ago
m.nabokikh 89295a5b4a More refresh token handler refactoring, more tests 5 years ago
m.nabokikh 4e73f39f57 Do not refresh id token claims if refresh token is allowed to reuse 5 years ago
m.nabokikh 0c75ed12e2 Add refresh token expiration tests and some refactoring 5 years ago
m.nabokikh 06c8ab5aa7 Fixes of naming and code style 5 years ago
m.nabokikh 91de99d57e feat: Add refresh token expiration and rotation settings 5 years ago
m.nabokikh d6b5105d9b fix: check code presence 5 years ago
m.nabokikh a7667dff38 fix: remove empty RefreshTokens 5 years ago
m.nabokikh 30a5dade0f fix: unsupported request parameter error 5 years ago
m.nabokikh 123185c456 fix: return invalid_grant error for invalid or expired auth codes 5 years ago
m.nabokikh 283a87855a fix: update auth methods and claims in discovery endpoint 5 years ago
m.nabokikh bb503dbd81 Use constants in errors 5 years ago
m.nabokikh a7978890c7 Add Cache-control headers to token responses 5 years ago
m.nabokikh b2e9f67edc Enable unparam, prealloc, sqlclosecheck linters 5 years ago
Mark Sagi-Kazar b8ac640c4f
Update oidc library 5 years ago
Maksim Nabokikh 35da73de38
chore: add frontend section to dev config (#1913) 5 years ago
m.nabokikh 30c3d78365 fix: log device flow entities GC result if no auth entities collected 5 years ago
m.nabokikh 1e88cca59a Make dark theme even darker, add fallback for legacy themes 5 years ago
Josh Soref 5d659a108c spelling: templates 5 years ago