Hein
|
640faeeeaf
|
feat(security): full OAuth 2.1 / OpenID Connect server and OIDC relying-party client
Authorization server: consent and scopes, OIDC (nonce, auth_time, acr, sid,
at_hash, signed userinfo, RP-initiated and back-channel logout), managed
refresh tokens with rotation and reuse detection, RFC 9068 JWT access tokens,
DPoP, PAR, device grant, token exchange, private_key_jwt, RFC 7591/7592
registration, RFC 9207 iss, signing keyring with rotation.
State is DB-backed through a new lookup.OAuthGrantStore (procedure and direct
backends, four dialect DDLs, conformance cases).
Client side: WithOIDC discovery, PKCE, nonce, id_token validation, OAuth2LogoutURL.
PeekRefresh now returns already rotated tokens so RotateRefresh can detect reuse.
Docs: OAUTH2_SERVER.md, oauth2_full_example.go, breaking_changes.md step 8.
|
2026-10-01 14:42:12 +02:00 |
|