Bump oic from 0.12.0 to 1.2.1
Bumps oic from 0.12.0 to 1.2.1.
Release notes
Sourced from oic's releases.
Security vulnerability fix (CVE-2020-26244)
No release notes provided.
Logout fixes, OAuth improvements
Prepared logout for SameSite changes in browsers.
Fixed and improved OAuth2 support.
See CHANGELOG.md for more details.
Logout support bugfix
Fixed logout support
Logout support
No release notes provided.
Fixed PEP561 compliance
No release notes provided.
1.0.0
Many bugfixes and improvements.
Dropped support for python < 3.5.
Bugfix release
- Fixed error on encrypted IDTokens
- Fixed issue with cookie headers
Bugfixes, initiated logout
Several bugfixes, support for initiated logout.
This is the last major release to support python 2.7.
Internal refactoring, bugfixses and small improvements
No release notes provided.
Bugfix release
No release notes provided.
Refactoring and bugfixes
No release notes provided.
Changelog
Sourced from oic's changelog.
1.2.1 [2020-12-01]
Fixed
- Fixed several client vulnerabilities (CVE-2020-26244)
1.2.0 [2020-02-05]
Fixed
- #727 OAuth client request using Client Credentials grant
Added
- #719 Add support for JWT registration tokens
- #728 OAuth client request using Extension grant
- #731 Session cookie need to be visible to OP IFrame.
#719: OpenIDC/pyoidc#719 #727: OpenIDC/pyoidc#727 #728: OpenIDC/pyoidc#728 #731: OpenIDC/pyoidc#731
1.1.2 [2019-11-23]
Fixed
- #711 Deal with no post_logout_redirect_uri
- #712 Set Content-Type on BackChannel logout POST.
- #717 Missing OP logout metadata.
#711: OpenIDC/pyoidc#711 #712: OpenIDC/pyoidc#712 #717: OpenIDC/pyoidc#717
1.1.1 [2019-11-04]
Fixed
- #708 Wants the original non-parsed JWT and not an IDToken instance.
1.1.0 [2019-10-25]
Changed
- #688 Second stage of adding logout support.
- #700 Third stage of adding logout support, provider side
Fixed
... (truncated)
Commits
0bf07d0Prepare release 1.2.1fe0fbdaDisallow none alg in flows other than Authorization637c148Enforce alg verification in id_tokenb195d09Call verify_id_token in parse_authz to pass already verified tokenfb0ff05Fixiatclaim in the future766dd87Prepare release 1.2.0bac06a4Session cookie need to be visible to OP IFrame Javascript script. (#731)16167f0Merge branch 'fixed-deprecation-warning'20054ceFix MutableMapping deprecation warning44d35cfMerge pull request #736 from OpenIDC/refactoring- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.