uaa

CloudFoundry User Account and Authentication (UAA) Server

APACHE-2.0 License

Stars
1.5K
Committers
208

Bot releases are hidden (Show)

uaa - 76.17.0

Published by cf-identity about 1 year ago

What's Changed

Fixes

Features

Dependency Bumps

Misc

New Contributors

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.16.0...v76.17.0

uaa - 76.16.0

Published by cf-identity over 1 year ago

Test ONLY

  • No need to consume it but created because of pipeline fixes

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.15.0...v76.16.0

uaa - 76.15.0

Published by cf-identity over 1 year ago

What's Changed

Fixes

Features

Dependency Bumps

Misc

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.14.0...v76.15.0

uaa - 76.14.0

Published by cf-identity over 1 year ago

What's Changed

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.13.0...v76.14.0

uaa - 76.13.0

Published by cf-identity over 1 year ago

What's Changed

Fixes

Dependency Bumps

Misc

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.12.0...v76.13.0

uaa - DO NOT USE 76.12.0

Published by cf-identity over 1 year ago

DO NOT USE

Contains a regression with regards to OIDC IdPs. A fix has been included in release 76.13.0

What's Changed

Fixes

Dependency Bumps

Misc

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.11.0...v76.12.0

uaa - 76.11.0

Published by cf-identity over 1 year ago

What's Changed

Fixes

Dependency Bumps

Misc

New Contributors

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.10.0...v76.11.0

uaa - 76.10.0

Published by cf-identity over 1 year ago

What's Changed

Fixes

Features

Dependency Bumps

New Contributors

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.9.0...v76.10.0

uaa - 76.9.0

Published by cf-identity over 1 year ago

What's Changed

Fixes

Dependency Bumps

Misc

New Contributors

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.8.0...v76.9.0

uaa - 76.8.0

Published by cf-identity over 1 year ago

What's Changed

Features

Dependency Bumps

Fixes

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.7.0...v76.8.0

uaa - 76.7.0

Published by cf-identity over 1 year ago

What's Changed

Fixes

Dependency Bumps

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.6.0...v76.7.0

uaa - 76.6.0

Published by cf-identity over 1 year ago

What's Changed

Features

Fixes

Dependency bumps

New Contributors

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.5.0...v76.6.0

uaa - 76.5.0

Published by cf-identity almost 2 years ago

What's Changed

Full Changelog: https://github.com/cloudfoundry/uaa/compare/v76.4.0...v76.5.0

uaa - 76.4.0

Published by cf-identity almost 2 years ago

Feature

  • Support refresh token rotation (#1969)
  • Add a section decsribing how to run local UAA server with PostgreSQL (#2091)

Fixes

  • Fix error "rawPassword cannot be null" and prevent null in password encoder (#2101)
  • Increase randomness of passcode (#2072)

Dependency bumps

  • Bump nimbus-jose-jwt from 8.23 to 9.24.4 (#2075)
  • Use jackson in jsonpath and exclude json-smart library (#2076)
  • build(deps): bump passay from 1.6.1 to 1.6.2 (#2077)
  • build(deps): bump github.com/onsi/gomega from 1.22.1 to 1.23.0 (#2080)
  • build(deps): bump jasmine-core from 4.4.0 to 4.5.0 (#2082)
  • build(deps): bump jasmine from 4.4.0 to 4.5.0 (#2083)
  • build(deps): bump javase from 3.5.0 to 3.5.1 (#2088)
  • build(deps): bump github.com/onsi/gomega from 1.23.0 to 1.24.0 (#2090)
  • build(deps): bump github.com/onsi/gomega from 1.24.0 to 1.24.1 in /k8s (#2092)
  • build(deps): bump k8s.io/client-go from 0.25.3 to 0.25.4 (#2096)
  • Upgrade Tomcat cargo version 9.0.69 (#2099)
  • Bump snakeyaml 1.33 (#2104)
  • Bump mariadb version 2.7.7 (#2103)

Full Changelog

uaa - 76.3.0

Published by cf-identity almost 2 years ago

Experimental Feature

  • UAA Rate Limiting on API level, Howto

Full Changelog

uaa - 76.2.0

Published by cf-identity almost 2 years ago

Feature

  • Set LDAP connection timeout to 30 minutes (#2063)

Fixes

  • Revert codestore random generator (#2070)
  • Jackson Update 2.13.4.2 because of CVE-2022-42003

Dependency bumps

  • Fix sonar smells (#2049)
  • Bump greenmail from 1.6.10 to 1.6.11 (#2050)
  • Add test for copy-to-clipboard functionality in passcode page 0 (#2051)
  • Bump github.com/onsi/gomega from 1.20.2 to 1.21.1 in /k8s (#2052)
  • Update UAA server debug mode run options 0 (#2054)
  • Bump k8s.io/client-go from 0.25.2 to 0.25.3 in /k8s (#2061)
  • Bump commons-rng-core from 1.4 to 1.5 (#2057)
  • Bump commons-rng-simple from 1.4 to 1.5 (#2056)
  • Bump github.com/onsi/gomega from 1.21.1 to 1.22.1 in /k8s (#2058)
  • Upgrade Tomcat cargo version 9.0.68 (#2064)
  • Bump versions.springBootVersion from 2.7.4 to 2.7.5 (#2065)
  • Bump nokogiri from 1.13.6 to 1.13.9 in /uaa/slate (#2066)
  • Refactor refreshAccessToken() (#2069)

Full Changelog

uaa - 76.1.0

Published by cf-identity about 2 years ago

Regression fixes

  • Regression with broken copy button (#2034)
  • Regression with legacy redirect patterns (#2035)

Security fixes

  • Bump snakeyaml version from 1.30 to 1.32 (#2023), solves CVE-2022-38751 and CVE-2022-38752

Dependency bumps

  • Bumps api-ldap-model from 1.0.3 to 2.1.2
  • Bump xmlsec from 3.0.0 to 3.0.1 (#2026)
  • Bump k8s.io/client-go from 0.25.0 to 0.25.1 (#2028)
  • Bump jQuery version to v3.6.1 (#2033)
  • Bump versions.springBootVersion from 2.7.3 to 2.7.4 (#2040)
  • Bump k8s.io/client-go from 0.25.1 to 0.25.2 in /k8s (#2037)
  • Bump json from 20220320 to 20220924 (#2042)
  • Bump Tomcat cargo version 9.0.67 (#2045)
  • Bump commons-text from 1.9 to 1.10.0 (#2047)
  • Bump versions.bouncyCastleVersion from 1.71.1 to 1.72 (#2048)

Full Changelog

uaa - 76.0.0

Published by cf-identity about 2 years ago

Security fixes

  • Added Content-Security-Policy headers for responses (#1981)

Breaking Changes

  • Removed the deprecated google analytics feature (#2022)

Dependency bumps

  • Bump github.com/onsi/gomega from 1.20.0 to 1.20.2 in /k8s (#2012) and (#2010)
  • Bump jasmine from 4.3.0 to 4.4.0 in /uaa (#2013)
  • Bump jasmine-core from 4.3.0 to 4.4.0 in /uaa (#2014)
  • Bump k8s.io/client-go from 0.24.4 to 0.25.0 in /k8s (#2006)
  • Bump postgresql from 42.4.2 to 42.5.0 (#2009)

Notes

  • MFA feature is being deprecated and will be removed in a future release (#2024)

Full Changelog

uaa - 75.23.0

Published by cf-identity about 2 years ago

Bug Fixes

Features

Dependency bumps

Full Changelog

uaa - 75.22.0

Published by cf-identity about 2 years ago

Bug Fixes

Features

Dependency bumps

Full Changelog