OpenID Connect Relying Party and OAuth 2.0 Resource Server for Apache HTTP Server 2.x

Edit Package apache2-mod_auth_openidc

OpenID Connect Relying Party and OAuth 2.0 Resource Server for Apache HTTP Server 2.x

Refresh
Refresh
Source Files
Filename Size Changed
apache2-mod_auth_openidc-2.4.2.1.tar.gz 0000246982 241 KB
apache2-mod_auth_openidc.changes 0000010435 10.2 KB
apache2-mod_auth_openidc.spec 0000002245 2.19 KB
Revision 9 (latest revision is 31)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 788232 from Petr Gajdos's avatar Petr Gajdos (pgajdos) (revision 9)
- Update to version 2.4.2.1
  Changes since 2.4.1:
  * oops: fix json_deep_copy of claims
  * fix memory leak in OAuth 2.0 JWT validation
  * fix configured private/public key cleanup on process exit
  * allow for expressions in Require statements, see #469
  * always refresh keys from jwks_uri when there is no kid in the
    JWT header
  * destroy shared memory segments only in parent process; see #458
  * fix memory leaks introduced by #457
  * if content was already returned via html/http send then don't
    return 500 but send 200 to avoid extraneous internal error
    document text to be sent on some Apache 2.4.x versions
  * if OIDCPublicKeyFiles contains a certificate, the corresponding
    x5c, x5t and x5t#256 parameters will be added to the generated
    jwkset available at "<redirect_uri>?jwks=rsa"
  - fix: also add SameSite=None to by-value session cookies
  - try to fix graceful restart crash; see #458 (forwarded request 788227 from mnhauke)
Comments 0
openSUSE Build Service is sponsored by