Nextcloud OpenID Connect Provider App - 2.5.0
This is the an OIDC App for Nextcloud. This application allows to use your Nextcloud Login at other services supporting OpenID Connect.
Attention
A stricter validator and exact comparison is enabled. The implemented migration preserves the original URI and adds separate, exact registrations for safe static HTTP(S) variants: lowercase scheme/host spelling and an empty root path versus /. Query strings and non-root paths remain unchanged. For example, https://RP.example.com can receive the additional registrations https://rp.example.com, https://rp.example.com/ and https://RP.example.com/. Dynamically registered clients do not receive aliases. Static path wildcards remain supported; every wildcard form is rejected for DCR clients, including pre-existing DCR records at authorization time.For further details consult the documentation.
Provided features
- Support for OpenID Connect Code (response_type = code) and Implicit (response_type = id_token) Flow - Implicite Flow must be activated per client
- Support for the OAuth 2.0 Device Authorization Grant (RFC 8628)
- Support for PKCE
- Public and confidential types of clients are supported
- Creation of ID Tokens and UserInfo responses with claims based on requested scopes and the OpenID Connect
claimsparameter (currently supported scopes: openid, profile, email, roles, groups, and offline_access) - Supported signing algorithms RS256 (default) and HS256
- Group memberships can be passed as roles or groups claims
- Clients can be assigned to dedicated user groups - Only users in the configured group are allowed to retrieve an access token to fetch the ID token
- Support for RFC9068 JWT Access Tokens (must be activated per client)
- Support for OAuth 2.0 Token Exchange (RFC 8693) using a constrained access-token-to-access-token profile
- Discovery & WebFinger endpoint provided
- RP-Initiated Logout, OpenID Connect Front-Channel Logout 1.0, Back-Channel Logout 1.0, and Session Management 1.0
- Dynamic Client Registration
- Client Configuration Management (RFC 7592)
- Token Introspection (RFC 7662)
- Access/refresh token revocation (RFC 7009)
- Support for resource url (RFC 9728) at introspection
- User Consent Management
- Support for custom claims
- Administration of clients via CLI
- Generation and validation of access tokens using events
- User specific settings to define which data is passed to clients in ID token and via userinfo endpoint
Full documentation can be found at:
User Documentation
Developer Documentation
What's Changed
- Refactor redirect flow by @H2CK in #735
- Split Access and Refresh Token processing and additional hardening by @H2CK in #737
- Build(deps): Bump axios from 1.18.1 to 1.20.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #736
- Build(deps): Bump @nextcloud/vue from 9.13.0 to 9.13.1 by @dependabot[bot] in #738
- Build(deps-dev): Bump @vue/compiler-sfc from 3.5.42 to 3.5.43 by @dependabot[bot] in #739
- Build(deps): Bump dompurify from 3.4.15 to 3.4.16 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #740
Full Changelog: 2.4.1...2.5.0