Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
132 commits
Select commit Hold shift + click to select a range
c8c160d
Create FUNDING.yml
tuunit Jul 11, 2025
1a03217
Merge pull request #3121 from oauth2-proxy/add-funding
JoelSpeed Jul 11, 2025
abb0a35
feat: bump to go1.24.5 and full dependency update (#3116)
wardviaene Jul 13, 2025
c4a02ec
chore(deps): update dependency golangci/golangci-lint to v2.2.2 (#3111)
renovate[bot] Jul 13, 2025
d390877
chore(deps): update dependency @easyops-cn/docusaurus-search-local to…
renovate[bot] Jul 13, 2025
40f3ef1
chore(deps): update example docker-compose files (#3096)
renovate[bot] Jul 13, 2025
b05bdc0
chore(deps): update helm examples (#2951)
renovate[bot] Jul 13, 2025
6c30a3c
chore(deps): update alpine base image to v3.22.0 (#3097)
renovate[bot] Jul 13, 2025
0e1dc9b
fix: return error for empty Redis URL list (#3101)
dgivens Jul 17, 2025
07a388d
add new docs version 7.10.x
github-actions[bot] Jul 17, 2025
5808f53
update to release version v7.10.0
github-actions[bot] Jul 17, 2025
e25f9ec
add changelog entry
tuunit Jul 17, 2025
78d2a36
Merge pull request #3128 from oauth2-proxy/release/v7.10.0
JoelSpeed Jul 17, 2025
313a2cb
chore(deps): update dependency @easyops-cn/docusaurus-search-local to…
renovate[bot] Jul 20, 2025
658256d
chore(deps): update gomod (#3132)
renovate[bot] Jul 20, 2025
c403d61
chore(deps): update helm release oauth2-proxy to v7.14.1 (#3133)
renovate[bot] Jul 20, 2025
20f561c
chore(deps): update docker-compose (#3130)
renovate[bot] Jul 20, 2025
d5f8507
chore(deps): update alpine docker tag to v3.22.1 (#3129)
renovate[bot] Jul 20, 2025
b57c821
feat(cookie) csrf per request limit (#3134)
tuunit Jul 20, 2025
5e7f14b
fix: show login page on broken session cookie (#2605)
Primexz Jul 20, 2025
3ac834d
Fix local-environment ports (#3136)
sim642 Jul 20, 2025
4d17bc1
feat: allow use more possible google admin-sdk api scopes (#2743)
BobDu Jul 21, 2025
a88306b
feat: add SourceHut (sr.ht) provider (#2359)
bitfehler Jul 22, 2025
137e59d
fix: regex substitution for $ signs in upstream path handling before …
dashkan Jul 22, 2025
dc8b162
feat(cookie): add feature support for cookie-secret-file (#3104)
sandy2008 Jul 22, 2025
b905f2c
feat: use non-default authorization request response mode in OIDC pro…
stieler-it Jul 23, 2025
e75a258
feat: make google-groups argument optional (#3138)
sourava01 Jul 24, 2025
f4b33b6
feat: differentiate between "no available key" and error for redis se…
nobletrout Jul 24, 2025
9ffafad
Merge commit from fork
tuunit Jul 30, 2025
c0a928e
release v7.11.0 (#3145)
github-actions[bot] Jul 30, 2025
4eaa1bc
fix: port for local-environment (#3148)
hunterboerner Aug 1, 2025
9667bce
feat(e2e): add workflow to trigger e2e test suite through PR comments…
tuunit Aug 12, 2025
4c86a4d
feat: add Cidaas provider (#2273)
Bibob7 Aug 12, 2025
744b31a
chore(dep): upgrade to latest golang 1.24.6 (#3166)
tuunit Aug 18, 2025
82e0169
chore(deps): update actions/checkout action to v5 (#3164)
renovate[bot] Aug 18, 2025
26813d3
chore(deps): update dependency golangci/golangci-lint to v2.4.0 (#3161)
renovate[bot] Aug 18, 2025
3978b2f
chore(deps): update docker-compose (#3160)
renovate[bot] Aug 18, 2025
f18a0b7
feat: allow disable-keep-alives configuration in upstream (#3156)
jet-go Aug 19, 2025
8c1b2b6
fix: Gitea team membership (#3150)
MagicRB Aug 19, 2025
413d4f6
add new docs version 7.12.x
github-actions[bot] Aug 19, 2025
b4b69a6
update to release version v7.12.0
github-actions[bot] Aug 19, 2025
7294eeb
add changelog entry for v7.12.0
tuunit Aug 19, 2025
5082db0
Merge pull request #3169 from oauth2-proxy/release/v7.12.0
tuunit Aug 19, 2025
8afb047
doc: SourceHut documentation fixes (#3170)
bitfehler Aug 20, 2025
f1c08a3
chore(deps): update actions/upload-pages-artifact action to v4 (#3194)
renovate[bot] Sep 25, 2025
66cdb9d
doc: update contribution guide to avoid a specific mention of the ver…
dsymonds Sep 25, 2025
9168731
fix(deps): revert actions/upload-pages-artifact action to v3 (#3211)
illrill Sep 28, 2025
a3349ad
chore(deps): update alpine docker tag to v3.22.2 (#3241)
renovate[bot] Oct 28, 2025
bccc988
chore(deps): update actions/setup-node action to v6 (#3242)
renovate[bot] Oct 28, 2025
65ef2ca
chore(deps): update actions/stale action to v10 (#3193)
renovate[bot] Oct 28, 2025
5539e59
chore(deps): update actions/setup-go action to v6 (#3191)
renovate[bot] Oct 28, 2025
e693f40
chore(deps): update actions/labeler action to v6 (#3190)
renovate[bot] Oct 28, 2025
dea0d0c
chore(deps): update helmv3 (#3189)
renovate[bot] Oct 28, 2025
a50bbcd
chore(deps): update docker-compose (#3188)
renovate[bot] Oct 28, 2025
4295f0c
chore(deps): update dependency golangci/golangci-lint to v2.5.0 (#3212)
renovate[bot] Oct 28, 2025
c0a087d
chore(deps): update actions/upload-artifact action to v5 (#3243)
renovate[bot] Oct 28, 2025
51e80f2
fix: use GetSecret() in ticket.go makeCookie to respect cookie-secret…
stagswtf Oct 28, 2025
ea1dc3f
Fix typo: diffrerent -> different (#3222)
vprivat-ads Oct 28, 2025
31b275f
docs: clarify ingress-nginx integration and remove Lua block example …
paulsc54 Oct 28, 2025
f950dc9
feat(makefile): simplify validate-go-version (#3147)
dolmen Oct 28, 2025
8f687e4
chore(deps): upgrade to latest go1.25.3 (#3244)
tuunit Oct 28, 2025
110d51d
test: replace mock pkg/clock with narrowly targeted stub clocks. (#3238)
dsymonds Oct 28, 2025
8782743
feat: added organizationId/employee id as preferred username (#3237)
pixeldrew Nov 7, 2025
5993067
Merge commit from fork
tuunit Nov 8, 2025
f3f30fa
Merge commit from fork
tuunit Nov 8, 2025
22053dc
fix: validation of refreshed sessions using the access_token in the O…
gysel Nov 8, 2025
fcc2db0
feat: add allowed_* constraint option to proxy endpoint query string…
jacobalberty Nov 8, 2025
082b49a
release: v7.13.0 (#3251)
github-actions[bot] Nov 8, 2025
fcf4e79
fix: hmacauth dependency licensing issue (#3253)
tuunit Nov 9, 2025
0107d6d
Add license scan report and status (#3248)
fossabot Nov 9, 2025
6a4255c
chore(deps): update docker-compose (#3255)
renovate[bot] Nov 11, 2025
e4becfd
chore(deps): update dependency node to v24 (#3256)
renovate[bot] Nov 11, 2025
7cf69b2
fix: NewRemoteKeySet is not using DefaultHTTPClient (#3197)
rsrdesarrollo Nov 11, 2025
7c20001
introduce mapstructure decoder for yaml parsing
tuunit May 4, 2024
676f56a
apply review suggestions
tuunit Feb 1, 2025
6720d8d
add duration test
tuunit Feb 9, 2025
c186d40
use official upstream yaml library v3
tuunit Feb 9, 2025
4c0dd28
fix alpha config example
tuunit Feb 9, 2025
18fc898
resolve cipher deprecation and update mapstructures v2
tuunit May 24, 2025
aaf1889
fix alpha config
tuunit May 24, 2025
810f629
revert: secrets as []byte instead of string
tuunit Jul 25, 2025
48bd2d7
fix merge problems and test cases
tuunit Jul 25, 2025
955ab6b
fix test setup and add local image build make target
tuunit Jul 26, 2025
5041435
return nil directly
tuunit Aug 19, 2025
9d70e04
feat: migrate all alpha config booleans to pointers
tuunit Aug 19, 2025
51b1fd0
chore(deps): replace with forked official yaml library
tuunit Oct 30, 2025
527c72f
feat: add ensure defaults to all migrated structs
tuunit Oct 30, 2025
ceb9a38
deref everything... but why?
tuunit Oct 31, 2025
638fba4
deref everything but now with default constants
tuunit Nov 7, 2025
137decb
adapting unit tests and fixing minor issues introduced with the derefing
tuunit Nov 7, 2025
0eec65e
refactor: ptr.Ptr to ptr.To
tuunit Nov 16, 2025
15041dd
feat: migrate google used organization id and header normalization bo…
tuunit Nov 16, 2025
aee540a
doc: fix mapstructure configuration comments
tuunit Nov 28, 2025
e27921e
Merge pull request #2628 from tuunit/use-mapstructures-for-parsing-an…
tuunit Nov 28, 2025
4956bab
chore(deps): update module golang.org/x/crypto to v0.45.0 [security] …
renovate[bot] Dec 24, 2025
699f367
chore(deps): upgrade gomod and bump to golang v1.25.5 (#3292)
tuunit Dec 24, 2025
12564e0
chore(deps): update docker-compose (#3272)
renovate[bot] Dec 24, 2025
6a0d821
chore(deps): update actions/checkout action to v6 (#3273)
renovate[bot] Dec 24, 2025
854a747
chore(deps): update dependency golangci/golangci-lint to v2.7.2 (#3254)
renovate[bot] Jan 4, 2026
0100ca9
chore(deps): update alpine docker tag to v3.23.2 (#3296)
renovate[bot] Jan 6, 2026
a2f2223
doc: improved clarity and correctness of proxy behaviour (#3305)
NirronCD Jan 14, 2026
a8e2084
docs: add Cisco Duo SSO provider documentation (#3306)
shri3016 Jan 14, 2026
3c37312
fix: added conditional so default is not always set and env vars are …
pixeldrew Jan 14, 2026
f3dcffe
chore(deps): update traefik docker tag to v2.11.35 (#3295)
renovate[bot] Jan 14, 2026
b4eb611
feat: more aggressively truncate logged access_token (#3264)
MartinNowak Jan 14, 2026
4953603
fix: session refresh handling in OIDC provider (#3267)
gysel Jan 14, 2026
3c22bc7
docs: split integration.md into separate integration guides (#3299)
pierluigilenoci Jan 16, 2026
1d6721f
fix: WebSocket proxy to respect PassHostHeader setting (#3290)
UnsignedLong Jan 16, 2026
86c2469
docs: clarify secret file format requirements (#3311)
shri3016 Jan 17, 2026
d16a0c4
add new docs version 7.14.x
github-actions[bot] Jan 15, 2026
3124bf7
update to release version v7.14.0
github-actions[bot] Jan 15, 2026
34c2712
doc: add changelog and migration guide for v7.14.0 alpha config changes
tuunit Jan 15, 2026
f46dcc7
doc: cncf onboarding and sponsor update
tuunit Jan 15, 2026
a360cb3
docs: backport integrations split to v7.14.x & v7.13.x
tuunit Jan 16, 2026
3bc1a53
doc: extend the alpha config changelog notice
tuunit Jan 16, 2026
1f29953
docs: add todo for revamping the usage / naming of PassHostHeader
tuunit Jan 16, 2026
707e6c4
Merge pull request #3308 from oauth2-proxy/release/v7.14.0
tuunit Jan 17, 2026
9c61c49
fix: skip provider button auth only redirect (#3309)
StefanMarkmann Jan 17, 2026
59f4e42
fix: static upstreams failing validation due to `passHostHeader` and …
sourava01 Jan 17, 2026
844e4e3
chore(deps): upgrade to go1.25.6; upgrade all go dependencies
tuunit Jan 17, 2026
cc0b48d
ci: fix linter warnings for preallocation
tuunit Jan 17, 2026
5020c33
ci: fix qlty coverage upload
tuunit Jan 17, 2026
56b5c08
Merge pull request #3312 from oauth2-proxy/chore/gomod
tuunit Jan 17, 2026
3ed3baf
update to release version v7.14.1
github-actions[bot] Jan 17, 2026
8f52b14
doc: changelog entry for v7.14.1
tuunit Jan 17, 2026
7bf586c
Merge pull request #3313 from oauth2-proxy/release/v7.14.1
tuunit Jan 17, 2026
cf5d34a
revert: "fix: skip provider button auth only redirect (#3309)" (#3314)
StefanMarkmann Jan 17, 2026
dcc7970
docs: fix how to use skip-provider-button with proper auth redirect h…
StefanMarkmann Jan 17, 2026
d5ea33b
ci: avoid running qlty coverage report for PRs (#3316)
tuunit Jan 18, 2026
3a55dad
release v7.14.2 (#3317)
github-actions[bot] Jan 18, 2026
e7724f3
ci: ensure release branches originate from the local repository and r…
tuunit Feb 12, 2026
56eece3
✨ Add Name and ObjectID claims for OIDC providers
Brawdunoir Apr 15, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
15 changes: 15 additions & 0 deletions .github/FUNDING.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# These are supported funding model platforms

github: tuunit # Replace with up to 4 GitHub Sponsors-enabled usernames e.g., [user1, user2]
patreon: # Replace with a single Patreon username
open_collective: oauth2-proxy # Replace with a single Open Collective username
ko_fi: # Replace with a single Ko-fi username
tidelift: # Replace with a single Tidelift platform-name/package-name e.g., npm/babel
community_bridge: # Replace with a single Community Bridge project-name e.g., cloud-foundry
liberapay: # Replace with a single Liberapay username
issuehunt: # Replace with a single IssueHunt username
lfx_crowdfunding: # Replace with a single LFX Crowdfunding project-name e.g., cloud-foundry
polar: # Replace with a single Polar username
buy_me_a_coffee: # Replace with a single Buy Me a Coffee username
thanks_dev: # Replace with a single thanks.dev username
custom: # Replace with up to 4 custom sponsorship URLs e.g., ['link1', 'link2']
33 changes: 23 additions & 10 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,29 +7,31 @@ on:
pull_request:
branches:
- '**'
permissions:
contents: read
id-token: write

jobs:
build:
runs-on: ubuntu-latest
env:
COVER: true
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6

- name: Set up Go
uses: actions/setup-go@v5
uses: actions/setup-go@v6
with:
go-version-file: go.mod
id: go

- name: Get dependencies
- name: Install golangci-lint
env:
# renovate: datasource=github-tags depName=golangci/golangci-lint
GOLANGCI_LINT_VERSION: v2.1.6
GOLANGCI_LINT_VERSION: v2.8.0
run: |
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin ${GOLANGCI_LINT_VERSION}
curl -L https://codeclimate.com/downloads/test-reporter/test-reporter-latest-linux-amd64 > ./cc-test-reporter
chmod +x ./cc-test-reporter

- name: Verify Code Generation
run: |
Expand All @@ -51,16 +53,27 @@ jobs:
make release

- name: Test
env:
CC_TEST_REPORTER_ID: ${{ secrets.CC_TEST_REPORTER_ID }}
run: |
./.github/workflows/test.sh
make test

- name: Generate Coverage Report
if: github.event_name == 'push'
run: |
go install github.com/jandelgado/gcov2lcov@latest
gcov2lcov -infile=c.out -outfile=lcov.info

- name: Upload Coverage Report
if: github.event_name == 'push'
uses: qltysh/qlty-action/coverage@v2
with:
oidc: true
files: lcov.info

docker:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v6

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/create-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: master
fetch-depth: 0
Expand Down Expand Up @@ -54,7 +54,7 @@ jobs:
git config --local user.email "41898282+github-actions[bot]@users.noreply.github.com"

- name: Setup node
uses: actions/setup-node@v4
uses: actions/setup-node@v6
with:
node-version-file: docs/package.json

Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,16 +14,16 @@ jobs:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6

- name: Setup Pages
id: pages
uses: actions/configure-pages@v5

- uses: actions/setup-node@v4
- uses: actions/setup-node@v6
with:
# renovate: datasource=node-version depName=node
node-version: 22
node-version: 24

- name: Test Build
working-directory: ./docs
Expand All @@ -35,12 +35,12 @@ jobs:
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6

- uses: actions/setup-node@v4
- uses: actions/setup-node@v6
with:
# renovate: datasource=node-version depName=node
node-version: 22
node-version: 24

- name: Build docusaurus
working-directory: ./docs
Expand Down
14 changes: 14 additions & 0 deletions .github/workflows/e2e.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
name: E2E

on:
issue_comment:
types: [created]

jobs:
e2e:
uses: oauth2-proxy/e2e-suite/.github/workflows/e2e.yml@main
permissions:
contents: read
statuses: write
issues: write
pull-requests: write
2 changes: 1 addition & 1 deletion .github/workflows/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ jobs:
pull-requests: write
runs-on: ubuntu-latest
steps:
- uses: actions/labeler@v5
- uses: actions/labeler@v6
with:
sync-labels: true
dot: true
2 changes: 1 addition & 1 deletion .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
if: github.repository == 'oauth2-proxy/oauth2-proxy'
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: master
fetch-depth: 0
Expand Down
19 changes: 9 additions & 10 deletions .github/workflows/publish-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,27 +14,28 @@ permissions:

jobs:
publish:
if: github.event.pull_request.merged && startsWith(github.event.pull_request.head.ref, 'release/')
if: github.event.pull_request.merged && startsWith(github.event.pull_request.head.ref, 'release/') && github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
outputs:
tag: ${{ steps.tag.outputs.version }}
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 0
fetch-tags: true

- name: Tag release
env:
BRANCH: ${{ github.event.pull_request.head.ref }}
run: |
# Set up github-actions[bot] user
git config --local user.name "github-actions[bot]"
git config --local user.email "41898282+github-actions[bot]@users.noreply.github.com"

# Get the version from the branch name
branch="${{ github.event.pull_request.head.ref }}"
version="${branch#release/}"
version="${BRANCH#release/}"
echo ${version}

# Tag and create release
Expand All @@ -43,18 +44,16 @@ jobs:
id: tag

- name: Set up go
uses: actions/setup-go@v5
uses: actions/setup-go@v6
with:
go-version-file: go.mod

- name: Get dependencies
env:
# renovate: datasource=github-tags depName=golangci/golangci-lint
GOLANGCI_LINT_VERSION: v2.1.6
GOLANGCI_LINT_VERSION: v2.8.0
run: |
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin ${GOLANGCI_LINT_VERSION}
curl -L https://codeclimate.com/downloads/test-reporter/test-reporter-latest-linux-amd64 > ./cc-test-reporter
chmod +x ./cc-test-reporter

# Install go dependencies
go mod download
Expand All @@ -64,7 +63,7 @@ jobs:

# Upload artifacts in case of workflow failure
- name: Upload Artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v5
with:
name: oauth2-proxy-artifacts
path: |
Expand Down Expand Up @@ -100,7 +99,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: ${{ needs.publish.outputs.tag }}
fetch-depth: 0
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/stale.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/stale@v9
- uses: actions/stale@v10
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
days-before-stale: 180
Expand Down
26 changes: 0 additions & 26 deletions .github/workflows/test.sh

This file was deleted.

1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ c.out
# Folders
_obj
_test
.DS_Store
.idea/
.vscode/*
!/.vscode/tasks.json
Expand Down
9 changes: 8 additions & 1 deletion .golangci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ linters:
- linters:
- revive
path: _test\.go
text: 'dot-imports:'
text: "dot-imports:"
# # If we have tests in shared test folders, these can be less strictly linted
- linters:
- bodyclose
Expand All @@ -49,6 +49,13 @@ linters:
- linters:
- staticcheck
text: QF1008
- linters:
- revive
path: util/.*\.go$
text: "var-naming: avoid meaningless package names"
- linters:
- prealloc
path: _test\.go
paths:
- third_party$
- builtin$
Expand Down
28 changes: 0 additions & 28 deletions ADOPTERS.md

This file was deleted.

Loading
Loading