Insights and release announcements
Blog
-
Connect2id server 19.16
Connect2id server 19.16
Connect2id Server 19.16 introduces configurable length limits for the OAuth 2.0 state and OpenID Connect nonce parameters used in authorisation requests. While these parameters are normally small, the protocols themselves don’t impose...
Connect2id serverRead article -
Connect2id server 19.15
Connect2id server 19.15
Connect2id Server 19.15 introduces configurable retry for OpenID Connect Back-Channel Logout notifications, helping...
Connect2id serverRead article -
Connect2id server 19.14
Connect2id server 19.14
Connect2id server 19.14 introduces more precise logout error reporting and configurable validation of OAuth 2.0 state...
Connect2id serverRead article -
Connect2id server 19.13
Connect2id server 19.13
Connect2id server 19.13 introduces dedicated timeouts for bootstrapped web sessions and a new authorisation code age...
Connect2id serverRead article -
Connect2id server 19.12.1
Connect2id server 19.12.1
Connect2id server 19.12.1 is a maintenance release that fixes issues affecting the authorisation request validation...
Connect2id serverRead article -
Connect2id server 19.12
Connect2id server 19.12
Connect2id server 19.12 introduces a new low-level plugin interface (SPI) for intercepting OAuth 2.0 authorisation...
Connect2id serverRead article -
Connect2id server 19.11
Connect2id server 19.11
Connect2id server 19.11 introduces a small but useful configuration improvement for service-oriented deployments,...
Connect2id serverRead article -
Connect2id server 19.10 protects OAuth redirects against browser-swap attacks
Connect2id server 19.10 protects OAuth redirects against browser-swap attacks
Connect2id server 19.10 strengthens protection against browser-swap attacks by adding validation of state and nonce...
Connect2id serverRead article -
Connect2id server 19.9 introduces selective refresh token revocation
Connect2id server 19.9 introduces selective refresh token revocation
Connect2id server 19.9 brings more flexibility to token revocation and a couple of important fixes and updates. The...
Connect2id serverRead article -
Connect2id server 19.8
Connect2id server 19.8
Connect2id server 19.8 introduces support for seamless migration of OAuth 2.0 client authentication methods. This new...
Connect2id serverRead article -
Connect2id server 19.7
Connect2id server 19.7
Connect2id server release 19.7 ships an update to consent prompts to enable IdPs easy access to previous decisions...
Connect2id serverRead article -
Connect2id server 19.6 introduces a web session bootstrap endpoint
Connect2id server 19.6 introduces a web session bootstrap endpoint
Integrated web session bootstrap for native apps Connect2id server 19.6 introduces a groundbreaking feature - a web...
Connect2id serverRead article -
Connect2id server 19.5
Connect2id server 19.5
The DPoP (RFC 9449) OAuth 2.0 security extension enables a client to bind an access token to a private key...
Connect2id serverRead article