Highlights
Single sign-on with OpenID Connect — GoCron can now protect both the UI and the API behind any OIDC provider (tested against Pocket-ID).
- New
auth.oidcconfig section:enabled,issuer_url,client_id,client_secret,session_ttl,cookie_secure. Endpoints and signing keys are auto-discovered from the issuer's.well-known/openid-configuration - Authorization-code flow with PKCE + state; sessions are opaque, DB-backed, deleted on logout, and expire after
session_ttl(default 24h) - SPA requires login when SSO is enabled — unauthenticated visitors are redirected to the provider; only the
openidscope is requested and the session is keyed on the ID token'ssub, so no email claim is needed cookie_securetoggle for HTTPS deployments; anyauth.oidc.*value can be overridden viaGC_AUTH_OIDC_*env vars- Live-reloadable — changes to the
auth.oidcsection apply on config reload, no restart needed (the provider is re-discovered whenissuer_url/client_idchange; discovery failures retry on the next request) - Config file with comments: the commented reference
config/config.example.yamlis embedded viago:embedand written toconfig/config.yamlon first boot if no config exists.config.yamlis git-ignored so local credentials never get committed - Runtime-reloadable schedule and log level: changing
time_zoneorlog_levelinconfig.yamlapplies immediately on config reload — the cron scheduler and the default slog handler are rebuilt without a restart - Documented in the README with a commented example in
config/config.example.yaml
Fixes
- Scheduled jobs no longer start during shutdown — the scheduler stops accepting runs first and the shutdown channel closes only after all cleanup completes (#59, thanks @bensynapse)
- Job cancellation now fully finishes before shutdown returns
Improvements
- Configuration validation errors are translated and formatted for readability
- Custom validation rules moved into the
validatepackage - Coverage reporting excludes generated files; the coverage badge is published in the repo
- All protected API operations now declare the
cookieAuthsecurity scheme in the OpenAPI spec
Behavior changes
- Cron schedules now run in the configured
time_zone, applied on reload — the scheduler is built withcron.WithLocation(...). Previouslytime_zoneonly took effect viaTZat startup, so a config edit didn't move existing cron entries until a restart. If you run with a non-UTCtime_zone, double-check that schedules land where you expect after upgrading
Notes
- If you run GoCron behind a reverse proxy and enable SSO, the proxy must forward
/api/auth/, and the OIDC callback URL registered at your provider must be the public address (e.g.https://gocron.example.com/api/auth/callback) - Logout deletes the session server-side; when the provider advertises an
end_session_endpointthe frontend also redirects there to clear the provider-side session - Sessions are opaque tokens stored server-side — they expire after
session_ttland are cleaned up hourly - No config changes required for existing installations — auth stays disabled unless
auth.oidc.enabled: trueis set. Your existingconfig.yamlkeeps working as-is
Changes in This Release
- [refactor] Move README images and docker-bake into folders (b7862b4) by @flohoss
- [improve] Exclude generated files from coverage reporting (1081a10) by @flohoss
- [meta] Publish the coverage badge into the repo (039a933) by @flohoss
- [meta] Update coverage badge [skip ci] (70e57b9) by @github-actions[bot]
- [fix] Do not use cache for go service (a5c2c6b) by @flohoss
- [refactor] Move BackendURL to backend.ts (cc48e16) by @flohoss
- [improve] Translate and format configuration validation errors (ae2d523) by @flohoss
- [fix] Finish job cancellation before shutdown returns (5cc711a) by @bensynapse
- [meta] Update coverage badge [skip ci] (c6559ce) by @github-actions[bot]
- [improve] Move custom validation rules into the validate package (0238803) by @flohoss
- [improve] Cover env key validation and value expansion (391d415) by @flohoss
- [meta] Update coverage badge [skip ci] (2442ab9) by @github-actions[bot]
- [feature] Add OIDC single sign-on for the UI and API (0a2fdc8) by @flohoss
- [feature] Require login in the SPA when SSO is enabled (a399200) by @flohoss
- [docs] Document OIDC single sign-on (cb9879e) by @flohoss
- [docs] Add commented OIDC example to the config (f247a62) by @flohoss
- Merge branch 'main' of https://github.com/flohoss/gocron (6f62aa6) by @flohoss
- [meta] Update coverage badge [skip ci] (01c572c) by @github-actions[bot]
- Merge branch 'main' into fix-scheduled-job-shutdown (e70eff2) by @flohoss
- Merge pull request #59 from bensynapse/fix-scheduled-job-shutdown (04321d2) by @flohoss
- [refactor] Close shutdown channel after all cleanup completes (89574d5) by @flohoss
- [meta] Update coverage badge [skip ci] (e8ac6da) by @github-actions[bot]
- [meta] Remove deprecated config (4bf7835) by @flohoss
- [fix] Show logout in same style as open api docs (ea629b2) by @flohoss
- Merge branch 'main' of https://github.com/flohoss/gocron (462e11d) by @flohoss
- [refactor] Ship commented example config via go:embed (6dee2f3) by @flohoss
- [fix] Harden auth callback and document cookieAuth on protected operations (5d2fded) by @flohoss
- [fix] Fail closed on auth check and use return-based login redirect (0f7a7ac) by @flohoss
- [fix] Stop scheduler before jobs and close shutdown after cleanup (22949c5) by @flohoss
- [improve] Add auth route and session tests (4133b79) by @flohoss
- [docs] Point configuration docs at the example config (716c7c0) by @flohoss
- [refactor] Drop the unused username from sessions (77b7c5b) by @flohoss
- [refactor] Key sessions on the OIDC subject (7a38071) by @flohoss
- [refactor] Delete sessions on logout (5d23e19) by @flohoss
- [meta] Update coverage badge [skip ci] (354f571) by @github-actions[bot]
Full Changelog: v0.12.0...v0.13.0
Docker Image
docker pull ghcr.io/flohoss/gocron:v0.13.0
docker pull ghcr.io/flohoss/gocron:latestBinary Downloads
Download one of the attached binaries extracted from the release image:
gocron_<version>_linux_amd64gocron_<version>_linux_arm64
Verify with ./gocron_<version>_linux_<arch> --version.
Image digest:
ghcr.io/flohoss/gocron:v0.13.0@sha256:efd2f87ac3df91e95866ae7c2ecd4aff1440d213cdb255c6a39f6c7026991ce8
Build Information
- Version:
v0.13.0 - Build Time:
2026-09-29T07:17:20Z - Repository: https://github.com/flohoss/gocron
- Platform:
linux/amd64,linux/arm64 - Attestations: SLSA Provenance, SBOM