Skip to content

Releases: authlib/authlib

v1.6.5

14 Oct 06:27
9ec4256

Choose a tag to compare

What's Changed

  • Add a request param to RFC7591 generate_client_info and generate_client_secret methods by @azmeuk in #825
  • feat: support list params in prepare_grant_uri by @lisongmin in #827
  • chore(deps): bump SonarSource/sonarqube-scan-action from 5 to 6 in /.github/workflows by @dependabot[bot] in #828
  • fix(jose): add max size for JWE zip=DEF decompression by @lepture in #830

New Contributors

Full Changelog: v1.6.4...v1.6.5

v1.6.4

20 Sep 08:11
09a5185

Choose a tag to compare

What's Changed

  • fix(jose): prevent public/unprotected header overwriting protected header by @lepture in #809
  • Fix InsecureTransportError raising by @azmeuk in #810
  • Add conventional-commits pre-commit hook by @azmeuk in #811
  • Fix response_mode=form_post with Starlette client by @azmeuk in #812
  • Specify README.md as project long description by @EpicWink in #817
  • Migrate tests to pytest paradigm by @azmeuk in #813
  • jose/jws: Reject unprotected ‘crit’ and enforce type; add tests by @AL-Cybision in #823
  • Use explicit *.test urls in unit tests by @azmeuk in #824

New Contributors

Full Changelog: v1.6.3...v1.6.4

Version 1.6.3

26 Aug 12:13
v1.6.3
dbbfa9a

Choose a tag to compare

What's Changed

  • Add diff-cover check in GHA by @azmeuk in #803
  • Run GHA unit tests with uv by @azmeuk in #805
  • Move from pre-commit to prek by @azmeuk in #804
  • Sign OIDC id_token according to id_token_signed_response_alg client metadata by @azmeuk in #802

Full Changelog: v1.6.2...v1.6.3

Version 1.6.2

23 Aug 08:42
v1.6.2
3385fbf

Choose a tag to compare

What's Changed

  • Allow insecure transport for 127.0.0.1 for debugging by @geigerzaehler in #788
  • Raise a MissingCodeError when code parameter is missing by @lepture in #786
  • Temporarily restore OAuth2Request body parameter by @azmeuk in #791
  • Raise MissingCodeException when code parameter is missing by @lepture in #794
  • Fix id_token generation with EdDSA alg by @azmeuk in #800

Full Changelog: v1.6.1...v1.6.2

Version 1.6.1

20 Jul 07:41
ef3d573

Choose a tag to compare

  • Filter key set with additional "alg" and "use" parameters.

Version 1.6.0

23 May 06:59
v1.6.0
fe87a11

Choose a tag to compare

Version 1.5.2

02 Apr 13:03
v1.5.2
fb698d7

Choose a tag to compare

Released on Apr 1, 2025

  • Forbid fragments in redirect_uris. #714
  • Fix invalid characters in error_description. #720
  • Add claims_cls parameter for client's parse_id_token method. #725

Version 1.5.1

20 Mar 12:55
v1.5.1
4eafdc2

Choose a tag to compare

Released on Feb 28, 2025

  • Fix RFC9207 iss parameter. #715

Version 1.5.0

27 Feb 15:47
v1.5.0
2d0396e

Choose a tag to compare

  • Fix token introspection auth method for clients. #662
  • Optional typ claim in JWT tokens. #696
  • JWT validation leeway. #689
  • Implement server-side RFC9207. #700 #701
  • generate_id_token can take a kid parameter. #702
  • More detailed InvalidClientError. #706
  • OpenID Connect Dynamic Client Registration implementation. #707

Version 1.4.1

28 Jan 13:42
0e8f480

Choose a tag to compare

  • Improve garbage collection on OAuth clients. #698
  • Fix client parameters for httpx. #694