GluuFederation/oxd
Client software to secure apps with OAuth 2.0, OpenID Connect, and UMA
JavaApache-2.0
Issues
- 1
fix(oxd):JSONException in oxd-server
#644 opened by manojs1978 - 0
- 0
fix: failure in oxd test-cases
#638 opened by duttarnab - 1
fix(oxd): fix runtime errors in version_4.5.3
#629 opened by duttarnab - 2
Remote code execution vulnerability in Commons Text library (commons-text-1.9)
#625 opened by roney492 - 1
fix: update the dependencies to resolve vulnerability
#623 opened by duttarnab - 1
fix: use remove method with OC to conform SQL ORM
#602 opened by yurem - 3
fix: fix test cases
#587 opened by duttarnab - 3
Casa script fails due to empty client redirect uri
#595 opened by yurem - 1
fix: change `expired_objects` table column name to adjust with `h2` dependency upgrade
#586 opened by duttarnab - 0
- 1
Change `client_frontchannel_logout_uri` from `List` to `string` type during client registration
#553 opened by duttarnab - 1
- 1
Add isFips check in oxd
#571 opened by duttarnab - 2
- 1
Create fallback to convert space separated scopes string to List for token introspection response.
#570 opened by duttarnab - 0
Upgrade dropwizard framework to stable with jackson dependency which does not conflict with oxauth
#567 opened by yuriyz - 4
- 2
FAPI: If the ID Token contains multiple audiences, the Client SHOULD verify that an azp Claim is present.
#536 opened by duttarnab - 3
Write test with state=base64urlencode(url)
#538 opened by yuriyz - 2
- 2
- 2
Add `id_token_hint` parameter in LogoutUrl
#550 opened by duttarnab - 1
Create `login initiation endpoint` in oxd to initiate Login from a Third Party
#565 opened by duttarnab - 1
- 1
Add `response_mode` parameter in `/get-authorization-url` to support `form_post`
#564 opened by duttarnab - 1
Displaying oxd version in `/health-check` and `/opt/oxd-server/bin/oxd-server version` output
#560 opened by duttarnab - 4
- 4
Automation of swagger client generation in oxd
#557 opened by duttarnab - 1
Handle jwks from OP where keys are without `kid`
#555 opened by duttarnab - 1
Add `client_assertion`, `TokenEndpointAuthSigningAlgorithm` params in ` /get-tokens-by-code`.
#511 opened by duttarnab - 1
- 1
For `private_key_jwt`, `tls_client_auth` , `self_signed_tls_client_auth` allow certificate-based client authentication.
#518 opened by duttarnab - 1
Validate `s_hash` in id_token
#519 opened by duttarnab - 1
The algorithm used to sign the `id_token` should match with `id_token_signed_response_alg` set during client registration.
#537 opened by duttarnab - 1
- 1
Minor: Show clear error message when get `redirect_uri` with fragment component during registration instead of generic `invalid_redirect_uri`
#526 opened by yuriyz - 4
Upgrade dropwizard to version: 2.0.12
#512 opened by duttarnab - 1
Save `client_id` and `client_secret` in oxd storage (in Rp table) when it is passed as paramater during client registration.
#510 opened by duttarnab - 1
Merge latest changes and fix in 4.2.1 branch
#515 opened by duttarnab - 4
Add `bindHost` with default value localhost
#503 opened by yuriyz - 1
Passing `Request Object by Value` and `Request Object by Reference` in Authorization Request
#499 opened by duttarnab - 1
Use WebFinger (RFC7033) and OpenID Provider Issuer Discovery to determine the location of the OpenID Provider
#498 opened by duttarnab - 6
Correct security alert in test dependency
#501 opened by yuriyz - 0
Merge two oxd dbs data into one
#487 opened by ldeveloperl1985 - 1
- 1
- 7
Add persistence manager support from oxcore
#477 opened by yuriyz - 1
Upgrade oxd to log4j version 2
#484 opened by yuriyz - 1
Read jedis version from `gluu-core-bom`
#478 opened by duttarnab