Skip to content

Releases: thephpleague/oauth2-server

8.3.4

Choose a tag to compare

@Sephster Sephster released this 07 Apr 21:35

Fixed

  • Server previously rejected valid uris with custom schemes. Now use league/uri for parsing to accept all valid uris (PR #1274)

8.3.3

Choose a tag to compare

@Sephster Sephster released this 11 Oct 20:49

Security

8.3.2

Choose a tag to compare

@Sephster Sephster released this 27 Jul 08:18

Changed

  • Conditionally support the StrictValidAt() method in lcobucci/jwt so we can use version 4.1.x or greater of the library (PR #1236)
  • When providing invalid credentials, the library now responds with the error message The user credentials were incorrect (PR #1230)
  • Keys are always stored in memory now and are not written to a file in the /tmp directory (PR #1180)
  • The regex for matching the bearer token has been simplified (PR #1238)

8.3.1

Choose a tag to compare

@Sephster Sephster released this 04 Jun 08:29
97dbc97

Fixed

  • Revert check on clientID. We will no longer require this to be a string (PR #1233)

8.3.0

Choose a tag to compare

@Sephster Sephster released this 03 Jun 21:55

Added

  • The server will now validate redirect uris according to rfc8252 (PR #1203)
  • Events emitted now include the refresh token and access token payloads (PR #1211)
  • Use the revokeRefreshTokens() function to decide whether refresh tokens are revoked or not upon use (PR #1189)

Changed

  • Keys are now validated using openssl_pkey_get_private() and openssl_pkey_get_public()` instead of regex matching (PR #1215)

Fixed

  • The server will now only recognise and handle an authorization header if the value of the header is non-empty. This is to circumvent issues where some common frameworks set this header even if no value is present (PR #1170)
  • Added type validation for redirect uri, client ID, client secret, scopes, auth code, state, username, and password inputs (PR #1210)
  • Allow scope "0" to be used. Previously this was removed from a request because it failed an empty() check (PR #1181)

8.2.4

Choose a tag to compare

@Sephster Sephster released this 10 Dec 11:36
622eaa1

Fixed

  • Reverted the enforcement of at least one redirect_uri for a client. This change has instead been moved to version 9 (PR #1169)

8.2.3

Choose a tag to compare

@Sephster Sephster released this 03 Dec 21:34
70bb329

Added

8.2.2

Choose a tag to compare

@Sephster Sephster released this 30 Nov 10:15

Fixed

  • Fix issue where the private key passphrase isn't correctly passed to JWT library (PR #1164)

8.2.1

Choose a tag to compare

@Sephster Sephster released this 26 Nov 11:19
284c2b5

Fixed

  • If you have a password on your private key, it is now passed correctly to the JWT configuration object. (PR #1159)

8.2.0

Choose a tag to compare

@Sephster Sephster released this 25 Nov 23:49
8837ed9

Added

  • Add a getRedirectUri function to the OAuthServerException class (PR #1123)
  • Support for PHP 8.0 (PR #1146)

Removed

  • Removed support for PHP 7.2 (PR #1146)

Fixed

  • Fix typo in parameter hint. code_challenged changed to code_challenge. Thrown by Auth Code Grant when the code challenge does not match the regex. (PR #1130)
  • Undefined offset was returned when no client redirect URI was set. Now throw an invalidClient exception if no redirect URI is set against a client (PR #1140)