Skip to content

Upgrade to upstream v7.15.4 and port the Atlassian provider - #2

Merged
alexrunsk merged 729 commits into
masterfrom
upgrade-v7.15.4
Oct 1, 2026
Merged

alexrunsk merged 729 commits into
masterfrom
upgrade-v7.15.4

Conversation

@alexrunsk

@alexrunsk alexrunsk commented Oct 1, 2026 •

Copy link
Copy Markdown

Moves the fork from upstream code of February 2022 to upstream v7.15.4 (August 2026), keeping our Atlassian provider.

What changes on top of v7.15.4

  • providers/atlassian-cloud.go: ported to the v7.15.4 provider interface. Behaviour is unchanged: audience=api.atlassian.com and prompt=consent on sign-in, email read from api.atlassian.com/me.
  • The atlassian provider type is registered, including the list v7.15.4 uses to reject unknown types.
  • Tests for the provider, and docs at docs/docs/configuration/providers/atlassian.md.

Upstream has no provider that works with Atlassian: its generic oidc provider was tested live against a test Atlassian app, and Atlassian refuses the openid scope for developer-console apps. So the fork stays, now as one small provider on stock v7.15.4.

Verified

  • Upstream's full test suite passes; gofmt and go vet are clean.
  • Live against a test Atlassian app: sign-in, and re-validation against /me with cookie-refresh set (valid only within the 1-hour lifetime of Atlassian's access token).

Deploying (current Helm chart 4.2.2 is compatible)

  • The v7.15.4 Dockerfile needs --build-arg BUILD_IMAGE=golang:1.26-bookworm --build-arg RUNTIME_IMAGE=gcr.io/distroless/static:nonroot; a plain docker build . fails.
  • Push a versioned tag (e.g. v7.15.4-dtt.1) and set it as image.tag instead of latest.
  • No other config change. Do not add cookie-refresh: Atlassian's access tokens expire after 1 hour and the provider has no refresh token, so every check after that hour fails and users would sign in again roughly hourly. Sessions keep the default 7-day cookie-expire.

🤖 Generated with Claude Code

JoelSpeed and others added 30 commits February 19, 2025 00:31
…ead-of-expires

pkg/cookies: use 'Max-Age' instead of 'Expires' for cookie expiration
Update golang.org/x/oauth2 to v0.27.0.
Update golang.org/x/net to v0.36.0.
…e-3.x

chore(deps): update alpine docker tag to v3.21.3
…gci-golangci-lint-1.x

chore(deps): update dependency golangci/golangci-lint to v1.64.7
Remove github.com/oauth2-proxy/tools/reference-gen from dependencies.
Instead we are now running it with "go run" with a version suffix.

Long version:
- github.com/oauth2-proxy/tools/reference-gen is removed from
  tools/tool/go
- in pkg/apis/options/doc.go we now run reference-run with a version
  suffix (go run package@version) with the version comming from go.mod.
- the "//go:generate" line is split in 2 lines (using the -command
  flag) for readability
- "go mod tidy" for cleaning dependencies from go.mod, go.sum

Note: we are not upgrading reference-gen here. That will be a further
separate change.
* chore(deps): update gomod

Co-authored-by: Jan Larwig <jan@larwig.com>
…curity] (oauth2-proxy#3003)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…3.x release (oauth2-proxy#3011)

Signed-off-by: Jan Larwig <jan@larwig.com>
* update to release version v7.8.2

* docs: release letter

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
…th2-proxy#3004)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Update gitlab.md with correct url for creating an application

* docs: fix gitlab docs url for oauth2 integration

---------

Co-authored-by: Jan Larwig <jan@larwig.com>
…auth2-proxy#3001)

* Update Go version in devcontainer

* Add option to change response mode in authorization request

* Fix option name

* Update docs and changelog

* Rename config value to underscore

* Add unit tests for added parameter

* Move change to upcoming release

* Generate alpha config

---------

Co-authored-by: Michael Cornel <michael@stieler.it>
…r-compose

chore(deps): update docker-compose
)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* add --deny-invalid-bearer-tokens

* update changelog

* PR feedback, update api-routes description

* update --api-routes description

* revert load_test fix that I needed locally

---------

Co-authored-by: Justin Ryan <j.ryan@mwam.com>
…uth2-proxy#3035)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tuunit and others added 27 commits June 8, 2026 14:12
…Rewrite

Signed-off-by: Jan Larwig <jan@larwig.com>
…to-1.26-and-migrate-of-reverse-proxy-handling

chore(dep): bump go to 1.26 and migrate of reverse proxy handling
* update to release version v7.15.3

* docs: changelog for v7.15.3

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
…r-compose

chore(deps): update docker-compose
…ns-upload-pages-artifact-5.x

chore(deps): update actions/upload-pages-artifact action to v5
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* Update inviter link

---------

Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…stead of etcd

Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
Signed-off-by: nightcityblade <jackchen@haloailabs.com>
Signed-off-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com>
Co-authored-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com>
* update to release version v7.15.4

* docs: add changelog for v7.15.4

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
Merges the upstream v7.15.4 tag and ports the Atlassian Cloud provider to
its provider interface:

- registers the "atlassian" provider type, including the provider-verifier
  list v7.15.4 uses to reject unknown types
- GetLoginURL takes the new extraParams argument; audience=api.atlassian.com
  is always sent, and prompt defaults to consent in place of approval_prompt
- EnrichSession replaces the deprecated GetEmailAddress and reads the email
  from the configured profile URL (https://api.atlassian.com/me)
- docs move to docs/docs/configuration/providers/atlassian.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alexrunsk alexrunsk mentioned this pull request Oct 1, 2026
@alexrunsk
alexrunsk merged commit d291edb into master Oct 1, 2026
8 of 10 checks passed
@alexrunsk
alexrunsk deleted the upgrade-v7.15.4 branch October 1, 2026 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.