Breaking
Read these before upgrading: each one can turn a login that worked into one that does not.
- oidc: reconcile authentication hardening and validation (#13) (896e5cd815af)
Back-channel logout providers must include an integerexpclaim in every Logout Token; otherwise configure front-channel logout.
New
- auth: receive shared signals security events (#27) (345a5095f082)
- contribution: keep contribution work coherent and visible (#18) (46774401ed2c)
- add verified release provenance and provider branding (ace51ac04bb7)
- harden OpenID Connect sign-in and administration (4550d44ab21f)
- OpenID Connect sign-in for the OPNsense web interface (c57a3c6b3150)
Fixed
- ci: avoid inaccessible release policy query (#30) (50b992ce03d3)
- release: ignore template comments in breaking notes (#29) (91c475bb4032)
- ci: validate release prerequisites before publishing (#26) (fca2867321d0)
- contribution: italicize agent authorship disclosure (#15) (58eabfabe29f)
Documentation
- tests: add OIDF conformance pilot (#8) (16fea0696004)
- add contribution message templates (#5) (bcc959ccacb5)
Pipeline
- retain pull request snapshot packages (#22) (b2fe8bdf50c5)
- add importable GitHub main ruleset (#4) (b2263a0f8d75)
- retain downloadable snapshot packages (6acc43604898)
Tests
- e2e: validate local provider matrix (#20) (9ede5f4879a1)
Housekeeping
- add CODEOWNERS file for repository ownership (#7) (2cd217b6f47a)
Verify and install
pkg checks nothing about a file handed to it directly. Establish its
GitHub/Sigstore provenance before the package reaches the firewall.
On an administrator workstation:
curl --fail --location --output /tmp/os-openid-connect-1.0.0.beta1.pkg \
https://github.com/jpawlowski/opnsense-openid-connect/releases/download/v1.0.0-beta1/os-openid-connect-1.0.0.beta1.pkg
gh attestation verify /tmp/os-openid-connect-1.0.0.beta1.pkg \
-R jpawlowski/opnsense-openid-connect \
--signer-workflow jpawlowski/opnsense-openid-connect/.github/workflows/build.yml \
--deny-self-hosted-runners
Copy that verified package to /tmp on the firewall. Confirm that the
transfer preserved its exact bytes, then install it:
sha256 -c c2ae1bd82171caf2f2a4b73cca619d1f32997b789e38205950859776545a26b7 /tmp/os-openid-connect-1.0.0.beta1.pkg
pkg add /tmp/os-openid-connect-1.0.0.beta1.pkg
No restart, no service affected. Signing in locally with a username and
password is untouched; the way back is always
pkg delete os-openid-connect.
17 commit(s), the first release.
Built from 50b992ce03d3e61d7a492f5e84266faaf3e9bc5a.