github H2CK/oidc 2.5.2
Nextcloud OIDC Provider App - 2.5.2

4 hours ago

Nextcloud OpenID Connect Provider App - 2.5.2

This is the an OIDC App for Nextcloud. This application allows to use your Nextcloud Login at other services supporting OpenID Connect.

Upgrade notes

  • Consent pages opened before the upgrade must be restarted; old single-use consent IDs are no longer accepted.
  • Administrators must explicitly approve resource audiences before they are accepted, even for existing client registrations.
  • Existing device consent approvals and refresh/grant state created under the old behavior should be re-tested after upgrade, because consent revocation, scope changes and replay protection are now re-checked at redemption time.
  • Device authorization now returns the short verification_uri without a user_code by default, in line with RFC 8628. If an existing client still relies on the old behavior, re-enable it explicitly with device_code_in_verification_uri=true; otherwise use verification_uri_complete for QR or direct-approval links.
  • HS256 ID tokens issued before this fix do not have valid issuance proof and will no longer pass the validation fallback; reissue them from a trusted provider or client application.
  • A stricter validator and exact comparison is enabled. The implemented migration preserves the original URI and adds separate, exact registrations for safe static HTTP(S) variants: lowercase scheme/host spelling and an empty root path versus /. Query strings and non-root paths remain unchanged. For example, https://RP.example.com can receive the additional registrations https://rp.example.com, https://rp.example.com/ and https://RP.example.com/. Dynamically registered clients do not receive aliases. Static path wildcards remain supported; every wildcard form is rejected for DCR clients, including pre-existing DCR records at authorization time. For further details consult the documentation.

Provided features

  • Support for OpenID Connect Code (response_type = code) and Implicit (response_type = id_token) Flow - Implicite Flow must be activated per client
  • Support for the OAuth 2.0 Device Authorization Grant (RFC 8628)
  • Support for PKCE
  • Public and confidential types of clients are supported
  • Creation of ID Tokens and UserInfo responses with claims based on requested scopes and the OpenID Connect claims parameter (currently supported scopes: openid, profile, email, roles, groups, and offline_access)
  • Supported signing algorithms RS256 (default) and HS256
  • Group memberships can be passed as roles or groups claims
  • Clients can be assigned to dedicated user groups - Only users in the configured group are allowed to retrieve an access token to fetch the ID token
  • Support for RFC9068 JWT Access Tokens (must be activated per client)
  • Support for OAuth 2.0 Token Exchange (RFC 8693) using a constrained access-token-to-access-token profile
  • Discovery & WebFinger endpoint provided
  • RP-Initiated Logout, OpenID Connect Front-Channel Logout 1.0, Back-Channel Logout 1.0, and Session Management 1.0
  • Dynamic Client Registration
  • Client Configuration Management (RFC 7592)
  • Token Introspection (RFC 7662)
  • Access/refresh token revocation (RFC 7009)
  • Support for resource url (RFC 9728) at introspection
  • User Consent Management
  • Support for custom claims
  • Administration of clients via CLI
  • Generation and validation of access tokens using events
  • User specific settings to define which data is passed to clients in ID token and via userinfo endpoint

Full documentation can be found at:

User Documentation
Developer Documentation

What's Changed

  • Fix problem if no max_age is requested by @H2CK in #744

Full Changelog: 2.5.1...2.5.2

Don't miss a new oidc release

NewReleases is sending notifications on new releases.