Skip to content
This repository has been archived by the owner on Jul 31, 2024. It is now read-only.

Add strict JAR mode #4409

Merged
merged 5 commits into from
May 25, 2020
Merged

Add strict JAR mode #4409

merged 5 commits into from
May 25, 2020

Conversation

leastprivilege
Copy link
Member

@leastprivilege leastprivilege commented May 15, 2020

Adds additional checks to conform with JAR (JWT typ and content type for request_uri).

This is not backwards compatible with OIDC request objects and for v4 turned off by default.

@leastprivilege leastprivilege added this to the 4.0 milestone May 15, 2020
@leastprivilege leastprivilege marked this pull request as draft May 15, 2020 10:03
* master:
  add null check when validating post logout redirect uri  #4295
  return setters back to public on AuthorizationRequest #4368
  update AspId host with UI updates
  update EF host with update UI
  Features/bootstrap update (#4427)
  add additional PKCE test
  add more detailed version logging
  cleanup in DefaultBackChannelLogoutService
  enhancements to add logout notification service as first class service (#4390)
  make apis that manipulate AuthenticationProperties public for client list and session id (#4411)

# Conflicts:
#	src/IdentityServer4/src/Configuration/DependencyInjection/BuilderExtensions/Additional.cs
@leastprivilege leastprivilege changed the title JAR additions Add strict JAR mode May 23, 2020
@leastprivilege leastprivilege marked this pull request as ready for review May 23, 2020 10:44
@brockallen brockallen merged commit 6d18e30 into master May 25, 2020
@brockallen brockallen deleted the features/more-jar-work branch May 25, 2020 14:14
@github-actions
Copy link

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 25, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants