Upgrade to upstream v7.15.4 and port the Atlassian provider - #2
Merged
Merged
Conversation
fix: wrong documentation for --trusted-ip (oauth2-proxy#2959)
…ead-of-expires pkg/cookies: use 'Max-Age' instead of 'Expires' for cookie expiration
Update golang.org/x/oauth2 to v0.27.0.
This addresses CVE-2025-22870 (https://go.dev/issue/71984).
Update golang.org/x/net to v0.36.0.
…e-3.x chore(deps): update alpine docker tag to v3.21.3
…gci-golangci-lint-1.x chore(deps): update dependency golangci/golangci-lint to v1.64.7
Remove github.com/oauth2-proxy/tools/reference-gen from dependencies. Instead we are now running it with "go run" with a version suffix. Long version: - github.com/oauth2-proxy/tools/reference-gen is removed from tools/tool/go - in pkg/apis/options/doc.go we now run reference-run with a version suffix (go run package@version) with the version comming from go.mod. - the "//go:generate" line is split in 2 lines (using the -command flag) for readability - "go mod tidy" for cleaning dependencies from go.mod, go.sum Note: we are not upgrading reference-gen here. That will be a further separate change.
* chore(deps): update gomod Co-authored-by: Jan Larwig <jan@larwig.com>
…curity] (oauth2-proxy#3003) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…3.x release (oauth2-proxy#3011) Signed-off-by: Jan Larwig <jan@larwig.com>
* update to release version v7.8.2 * docs: release letter --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jan Larwig <jan@larwig.com>
…th2-proxy#3004) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
* Update gitlab.md with correct url for creating an application * docs: fix gitlab docs url for oauth2 integration --------- Co-authored-by: Jan Larwig <jan@larwig.com>
…auth2-proxy#3001) * Update Go version in devcontainer * Add option to change response mode in authorization request * Fix option name * Update docs and changelog * Rename config value to underscore * Add unit tests for added parameter * Move change to upcoming release * Generate alpha config --------- Co-authored-by: Michael Cornel <michael@stieler.it>
…r-compose chore(deps): update docker-compose
* add --deny-invalid-bearer-tokens * update changelog * PR feedback, update api-routes description * update --api-routes description * revert load_test fix that I needed locally --------- Co-authored-by: Justin Ryan <j.ryan@mwam.com>
…uth2-proxy#3035) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…Rewrite Signed-off-by: Jan Larwig <jan@larwig.com>
…to-1.26-and-migrate-of-reverse-proxy-handling chore(dep): bump go to 1.26 and migrate of reverse proxy handling
* update to release version v7.15.3 * docs: changelog for v7.15.3 Signed-off-by: Jan Larwig <jan@larwig.com> --------- Signed-off-by: Jan Larwig <jan@larwig.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
chore(deps): update gomod
…r-compose chore(deps): update docker-compose
…ns-upload-pages-artifact-5.x chore(deps): update actions/upload-pages-artifact action to v5
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* Update inviter link --------- Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com> Co-authored-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
…uth2-proxy#3507) Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…stead of etcd Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: nightcityblade <nightcityblade@gmail.com> Co-authored-by: nightcityblade <nightcityblade@gmail.com>
Signed-off-by: nightcityblade <jackchen@haloailabs.com>
Signed-off-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com> Co-authored-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com>
* update to release version v7.15.4 * docs: add changelog for v7.15.4 Signed-off-by: Jan Larwig <jan@larwig.com> --------- Signed-off-by: Jan Larwig <jan@larwig.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jan Larwig <jan@larwig.com>
Merges the upstream v7.15.4 tag and ports the Atlassian Cloud provider to its provider interface: - registers the "atlassian" provider type, including the provider-verifier list v7.15.4 uses to reject unknown types - GetLoginURL takes the new extraParams argument; audience=api.atlassian.com is always sent, and prompt defaults to consent in place of approval_prompt - EnrichSession replaces the deprecated GetEmailAddress and reads the email from the configured profile URL (https://api.atlassian.com/me) - docs move to docs/docs/configuration/providers/atlassian.md Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves the fork from upstream code of February 2022 to upstream v7.15.4 (August 2026), keeping our Atlassian provider.
What changes on top of v7.15.4
providers/atlassian-cloud.go: ported to the v7.15.4 provider interface. Behaviour is unchanged:audience=api.atlassian.comandprompt=consenton sign-in, email read fromapi.atlassian.com/me.atlassianprovider type is registered, including the list v7.15.4 uses to reject unknown types.docs/docs/configuration/providers/atlassian.md.Upstream has no provider that works with Atlassian: its generic
oidcprovider was tested live against a test Atlassian app, and Atlassian refuses theopenidscope for developer-console apps. So the fork stays, now as one small provider on stock v7.15.4.Verified
gofmtandgo vetare clean./mewithcookie-refreshset (valid only within the 1-hour lifetime of Atlassian's access token).Deploying (current Helm chart 4.2.2 is compatible)
--build-arg BUILD_IMAGE=golang:1.26-bookworm --build-arg RUNTIME_IMAGE=gcr.io/distroless/static:nonroot; a plaindocker build .fails.v7.15.4-dtt.1) and set it asimage.taginstead oflatest.cookie-refresh: Atlassian's access tokens expire after 1 hour and the provider has no refresh token, so every check after that hour fails and users would sign in again roughly hourly. Sessions keep the default 7-daycookie-expire.🤖 Generated with Claude Code