Zum Inhalt springen

golang-jwt Release Notes

23 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge golang-jwt, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.3.1

Version 5.3.1 ergänzt die Parser-Option WithNotBeforeRequired, speichert die Signatur nach dem Signieren bzw. in ParseUnverified im Token und behebt ein vorzeitiges Schließen von Dateien im jwt-CLI.

<!-- Release notes generated using configuration in .github/release.yml at main -->

What's Changed

🔐 Features

👒 Dependencies

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.3.0

Version 5.3.0 ist fast identisch mit v5.2.3, gibt aber nun korrekt Go 1.21 als Mindestanforderung an.

This release is almost identical to to v5.2.3 but now correctly indicates Go 1.21 as minimum requirement.

What's Changed

Full Changelog: https://github.com/golang-jwt/jwt/compare/v5.2.3...v5.3.0

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.2.3

Version 5.2.3 implementiert die Validierung mehrerer Audiences und behebt dabei einen Fehler, außerdem wurden Workflows und Go-Versionen aktualisiert.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v5.2.2...v5.2.3

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.2.2

Version 5.2.2 behebt die Sicherheitslücke GHSA-mh63-6h87-95cp sowie den Fehler bei jwt -show und aktualisiert Dokumentation und CI.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v5.2.1...v5.2.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v4.5.1: Sicherheitsfix bei ParseWithClaims

Version 4.5.1 portiert die Fehlerbehandlung von ParseWithClaims aus v5 zurück, sodass ein abgelaufenes und zugleich ungültiges Token nicht mehr fälschlich akzeptiert werden kann (GHSA-29wx-vh33-7x7r).

Security

Unclear documentation of the error behavior in ParseWithClaims in <= 4.5.0 could lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by ParseWithClaims return both error codes. If users only check for the jwt.ErrTokenExpired using error.Is, they will ignore the embedded jwt.ErrTokenSignatureInvalid and thus potentially accept invalid tokens.

This issue was documented in https://github.com/golang-jwt/jwt/security/advisories/GHSA-29wx-vh33-7x7r and fixed in this release.

Note: v5 was not affected by this issue. So upgrading to this release version is also recommended.

What's Changed

Full Changelog: https://github.com/golang-jwt/jwt/compare/v4.5.0...v4.5.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.2.1

Version 5.2.1 korrigiert eine falsche Fehlerrückgabe sowie einen Tippfehler in einer ECDSA-Fehlermeldung.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v5.2.0...v5.2.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.2.0

Version 5.2.0 exportiert NewValidator und verbessert die ErrInvalidKeyType-Fehlermeldungen.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v5.1.0...v5.2.0

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.1.0

Version 5.1.0 bringt Key Rotation mit VerificationKeySet, nutzt das native ErrInvalidType und enthält mehrere Refactorings und Dokumentationsverbesserungen.

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.0.0: neue Hauptversion

Version 5.0.0 ist eine neue Hauptversion mit überarbeiteter Validierung samt Parser-Optionen, neu gestaltetem Claims-Interface und überarbeiteter Fehlerbehandlung sowie dem neuen Importpfad github.com/golang-jwt/jwt/v5.

🚀 New Major Version v5 🚀

It's finally here, the release you have been waiting for! We don't take breaking changes lightly, but the changes outlined below were necessary to address some of the challenges of the previous API. A big thanks for @mfridman for all the reviews, all contributors for their commits and of course @dgrijalva for the original code. I hope we kept some of the spirit of your original v4 branch alive in the approach we have taken here. ~@oxisto, on behalf of @golang-jwt/maintainers

Version v5 contains a major rework of core functionalities in the jwt-go library. This includes support for several validation options as well as a re-design of the Claims interface. Lastly, we reworked how errors work under the hood, which should provide a better overall developer experience.

Starting from v5.0.0, the import path will be:

"github.com/golang-jwt/jwt/v5"

For most users, changing the import path should suffice. However, since we intentionally changed and cleaned some of the public API, existing programs might need to be updated. The following sections describe significant changes and corresponding updates for existing programs.

Parsing and Validation Options …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.0.0-rc.2

Version 5.0.0-rc.2 ist ein weiterer Release Candidate für v5, der unter anderem DecodeSegement in den Parser verschiebt und die Migrationsanleitung aktualisiert.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v4.5.0...v5.0.0-rc.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt v5.0.0-rc.1

Version 5.0.0-rc.1 ist der erste Release Candidate der neuen Hauptversion v5 mit Parser-Optionen für die Validierung, überarbeitetem Claims-Interface, neuer Fehlerbehandlung und neuem Importpfad.

🚨 New major version v5 (release candidate 1) 🚨

Huge kudos to @oxisto for pushing this 10+ year-old project further and building a solid foundation. We don't take breaking changes lightly, but the changes outlined below were necessary to address some of the shortcomings of the previous API.

Version v5 contains a major rework of core functionalities in the jwt-go library. This includes support for several validation options as well as a re-design of the Claims interface. Lastly, we reworked how errors work under the hood, which should provide a better overall developer experience.

Starting from v5, the import path will be:

"github.com/golang-jwt/jwt/v5"

For most users, changing the import path should suffice. However, since we intentionally changed and cleaned some of the public API, existing programs might need to be adopted. The following paragraphs go through the individual changes and make suggestions how to change existing programs.

The existing v4 version is available on the v4 branch at commit 9358574a

Parsing and Validation Options

Under the hood, a new validator struct takes care of validating the claims. A long awaited feature has been the option to fine-tune the validation of tokens. This is now possible with several ParserOption functions that can be appended to most Parse functions, such as ParseWithClaims. The most important options and changes are: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt Jwt Version 4.4.3

Version 4.4.3 ergänzt einen BearerExtractor, erweitert die CI-Matrix um go1.19 und bringt Dokumentations-, README- und Beispielanpassungen sowie eine kleine Code-Bereinigung.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v4.4.2...v4.4.3

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt Jwt Version 4.2.2 bzw. 4.4.2

Version 4.4.2 behebt einen Integer-Überlauf in NumericDate.MarshalJSON, ersetzt ioutil durch io und os und ergänzt SECURITY.md, Installationshinweise und eine CI-Prüfung der Code-Formatierung.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v4.4.1...v4.4.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt Jwt Version 4.4.1

Version 4.4.1 macht die in v4.4.0 hinzugefügte Clockskew-Unterstützung rückgängig, nimmt go1.18 in die CI auf und zieht v4.4.0 wegen einer inkompatiblen Änderung am Claims-Interface per Go-Modul-Retraction zurück.

What's Changed

Note, this release contains a Go module retraction for a prior release v4.4.0:

retract (
    v4.4.0 // Contains a backwards incompatible change to the Claims interface.
)

Full Changelog: https://github.com/golang-jwt/jwt/compare/v4.4.0...v4.4.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt Jwt Version 4.4.0

Version 4.4.0 korrigiert die Fehlermeldung bei abgelaufenen Tokens und portiert die Clockskew-Unterstützung.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v4.3.0...v4.4.0

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt Jwt Version 4.3.0

Version 4.3.0 unterstützt errors.Is für Token-Extractors und Go-1.13-Fehlerprüfung über Is(err) bool und setzt die Präzision der JSON-Kodierung, dazu kommen kleinere Bereinigungen und README-Ergänzungen.

What's Changed

New Contributors

Full Changelog: https://github.com/golang-jwt/jwt/compare/v4.2.0...v4.3.0

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt Jwt Version 4.2.0

Version 4.2.0 führt funktionale Optionen für den Parser-Typ ein, ergänzt Unwrap für ValidationError und VerifyIssuer für RegisteredClaims, unterstützt EdDSA und den none-Algorithmus im jwt-Befehl und behebt einen int64-Überlauf.

  • Fix the comment of VerifyExpiresAt (#109) @shogo82148
  • Introducing functional-style options for the Parser type (#108) @oxisto
  • Improve code comments, including security consideration (#107) @sebastien-rosset
  • Fix int64 overflow in newNumericDateFromSeconds (#112) @PiotrKozimor
  • Fixes jwt command to support EdDSA algorithm (#118) @AlexanderYastrebov
  • Revert Encoding/Decoding changes for better compatibility (#117) @ajermaky
  • Allow none algorithm in jwt command (#121) @AlexanderYastrebov
  • Unwrap for ValidationError (#125) @kdeberk
  • cmd: list supported algorithms (-alg flag) (#123) @AlexanderYastrebov
  • Added VerifyIssuer method to RegisteredClaims (#130) @tfonfara

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Jwt von golang-jwt

golang-jwt Jwt Version 4.1.0

Version 4.1.0 unterstützt go1.17, führt die RFC7519-konforme Struktur RegisteredClaims ein (statt des veralteten StandardClaims), korrigiert die exp-Logik und ergänzt ein generisches crypto.Signer für ed25519.PublicKey.

  • Adds support for go1.17 (#89).
  • Adds RFC7519-compliant RegisteredClaims struct (#15). Use this instead of StandardClaims (deprecated but not removed).
  • Adds generic crypto.Signer for ed25519.PublicKey (#95).
  • Adds regular code scanning (#101).
  • Corrects "exp" logic to conform to https://datatracker.ietf.org/doc/html/rfc7519#section-4.1.4 (#86).
  • Adds additional parsing tests (#106).
  • Changed error string (#97).
  • Various Code fixes and cleanup (#53, #83, #102, #103).

Originalquelle(öffnet in neuem Tab)Problem melden