Nextcloud OpenID Connect Provider App - 1.16.3
This is the an OIDC App for Nextcloud. This application allows to use your Nextcloud Login at other services supporting OpenID Connect.
Provided features:
- Support for OpenID Connect Code (response_type = code) and Implicit (response_type = id_token) Flow - Implicite Flow must be activated per client
- Support for PKCE
- Public and confidential types of clients are supported
- Creation of ID Token with claims based on requested scope (Currently supported scopes: openid, profile, email, roles, groups, and offline_access)
- Supported signing algorithms RS256 (default) and HS256
- Group memberships are passed as roles in ID token
- Clients can be assigned to dedicated user groups - Only users in the configured group are allowed to retrieve an access token to fetch the ID token
- Support for RFC9068 JWT Access Tokens (must be activated per client)
- Discovery & WebFinger endpoint provided
- Logout endpoint
- Dynamic Client Registration
- Client Configuration Management (RFC 7592)
- Token Introspection (RFC 7662)
- Support for resource url (RFC 9728) at introspection
- User Consent Management
- Support for custom claims
- Administration of clients via CLI
- Generation and validation of access tokens using events
- User specific settings to define which data is passed to clients in ID token and via userinfo endpoint
Changes:
- Reduced session dependency by passing oidc parameters within redirect url (#628) and also for consent flow
- Updated dependencies
- Updated translations
Full documentation can be found at:
User Documentation
Developer Documentation
What's Changed
- Build(deps): Bump flatted from 3.3.4 to 3.4.1 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #627
- Build(deps): Bump flatted from 3.4.1 to 3.4.2 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #629
- Build(deps): Bump the npm_and_yarn group across 1 directory with 1 update by @dependabot[bot] in #632
- Build(deps): Bump yaml from 2.8.2 to 2.8.3 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #633
- fix: Preserve OIDC params across SAML session regeneration by @abraxaswd in #631
New Contributors
- @abraxaswd made their first contribution in #631
Full Changelog: 1.16.2...1.16.3