- support hosting of Zeppelin notebooks on ShinyProxy (by using non-greedy pattern matching to get app name)
- possibility to set secure flag on cookies (
server.secureCookies
) - set HttpOnly on cookies set by ShinyProxy
- set X-Frame-Options header using
server.frameOptions
- perform CSRF check on the login form and set X-Content-Type-Options header to nosniff
- allow to set a forceAuthN flag when using SAML authentication (
proxy.saml.force-authn
) - improved parsing of custom OIDC role claims
- improved support for the 'emails' claim in OIDC
- Fix: AJAX error when using Keycloak
- Fix: 'Error: 200' page in case of login expiration
- Fix: 404 when a user makes concurrent /app_direct calls;
- Fix: error when stopping containers in a different namespace;
- Fix: documentation for web service authentication