Brightspace / D2L.Security.OAuth2

Brightspace OAuth 2.0 for C#
Apache License 2.0
7 stars 16 forks source link

Bump System.IdentityModel.Tokens.Jwt from 6.14.1 to 6.15.1 #212

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps System.IdentityModel.Tokens.Jwt from 6.14.1 to 6.15.1.

Release notes

Sourced from System.IdentityModel.Tokens.Jwt's releases.

6.15.1

Enhancements

  • Performance improvement when caching signature providers. No need to use LRU logic since it is assumed only a small number of signature providers will be in play at a time (#1783).
  • DisposableObjectPool disposes of objects on Free() when full (#1802).

Bugs

  • TestTokenCreator modified to throw SecurityTokenInvalidSignatureException rather than ArgumentException(#1798).
  • AadIssuerValidator fixed issue where AadIssuerValidatorConstants.Tid was used where AadIssuerValidatorConstants.TenantId should have been used (#1801).

6.15.0

New Features

  • Added support for the Last Known Good feature (#1723)
  • Made logging more legible by displaying Non-PII information in clear text (#1757)
  • Added new GitHub Templates to report bugs (#1756)
  • Added the OpenID standard scope "address" (#1787)

Enhancements

  • Added multi-auth scheme support in AadIssuerValidator (#1753)
  • Added default values for TokenValidationParameters (#1767)
  • Improved logging to indicate issuer is an empty string (#1758) (#1761)
  • Improved exception handling when metadata retrieval results in a failure (#1776)
  • Added string optimizations (#1765)
  • Improved performance of Saml2 attributes consolidation (#1764)
  • Updated comments to use references (#1769)
  • Added new unit test samples that make negative testing easier for consumers of this library. These show the most common problem token types and gives examples for validation. (#1748)

Bug Fixes

  • Fixed broken links to ietf.org (#1723)
Commits
  • 33879ec Update DisposableObjectPool to dispose on Free() when full
  • dbb701d Simplify the EventBasedLRUCache and Allows Skipping LRU (#1783)
  • 824d58c rename JwtHandler -> JsonWebTokenHandler
  • 9229015 Adding more information on key location to error messages (#1786)
  • 16c939e Adding immediate retry on network failure + better logging during configuatio...
  • a782ff5 Revert "Remove deprecated "language" attribute"
  • 5c51220 Remove deprecated "language" attribute
  • 7c1c523 Fix capitalization of acronym in documentation
  • 1fd6014 Updating assembly version number to 6.15.1 (#1791)
  • 1a95376 Removed log property
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
omsmith commented 2 years ago

@dependabot rebase