61 Commits (release/8.0.0-preview.4)

Author SHA1 Message Date
Kévin Chalet 77ca35a53f
Use private claims for the token creation/expiration dates and introduce new Data Protection authentication properties 6 years ago
Kévin Chalet 414e05eed4 Create a DB entry for all types of tokens, rework reference tokens support and add token entry validation to the validation handler 7 years ago
Kévin Chalet fb92acbdaf Replace OpenIddictApplicationManager.IsConfidentialAsync()/IsPublicAsync()/IsHybridAsync() by HasClientTypeAsync() 7 years ago
Kévin Chalet 8b097321c3 Update the ValidatePrincipal handler to ensure the token type of the claims principal matches the expected type 7 years ago
Drew Fleming 78d14adb33 Reject token requests containing a code_verifier when no code_challenge is attached to the authorization code 7 years ago
Kévin Chalet 97dffed124 Implement complete WWW-Authenticate response header support 7 years ago
Kévin Chalet dae66ef974 Add integration tests for the PKCE enforcement feature 7 years ago
Kévin Chalet 76a432e045 Port the challenge integration tests 7 years ago
Kévin Chalet 831a5b988a Port the sign-in integration tests 7 years ago
Kévin Chalet 0214951ffc Port the revocation endpoint tests and disable GET support 7 years ago
Kévin Chalet 6a3afb52c4 Make the supported code_challenge_methods configurable via advanced options and disable plain by default 7 years ago
Kévin Chalet a25907cd52 Automatically map the scope/azp access token claims to their OpenIddict private claims equivalents 7 years ago
Kévin Chalet eb35cbefb7 Port the token endpoint integration tests 7 years ago