SSO module changelog

The changelog gives you an overview of the changes made to the SSO module at each release.

This changelog covers the 3.x branch of the SSO module. For the 2.x changelog, see here.

Because of some changes introduced in the AdmincentralServlet for Magnolia 6.2.38, customers using SSO are unable to log out.

We recommend that you do not upgrade to Magnolia 6.2.38 if your project relies on SSO. ADMINCTR-478 covers this issue.

The issue is resolved in Magnolia 6.2.39.

3.1.8

Released on October 19, 2023.

Ticket Type Description

MGNLSSO-313

Make the targetProperty name configurable for GroupsAuthorizationGenerator.

MGNLSSO-316

Invalidating/reloading the SSO YAML configuration doesn’t work.

3.1.7

Released on September 7, 2023.

We keep the details of security fixes (indicated by the lock icon) private in line with our security policy. Contact our Support team if you need more information.

Ticket Type Description

MGNLSSO-81

Add SSO logging to Magnolia access log.

MGNLSSO-301

Invalid token issue.

3.1.6

Released on August 23, 2023.

Ticket Type Description

MGNLSSO-298

Module update tasks not working in SSO 3.1.0 and later.

3.1.5

Released on June 13, 2023.

Ticket Type Description

MGNLSSO-265

Possibility to implement custom SSO configuration.

3.1.4

Released on June 2, 2023.

Ticket Type Description

MGNLSSO-270

Custom authorizationGenerators configuration not found.

MGNLSSO-271

SsoRedirectClient callback should not occur for APP/global.

MGNLSSO-283

3.1.3

Released on April 21, 2023.

Ticket Type Description

MGNLSSO-230

SsoUser does not use transitive groups and roles correctly.

MGNLSSO-239

Tasks for publishers are only displayed upon a page refresh using SSO module 3.0.1.

MGNLSSO-254

We have upgraded pac4j to version 5.7.1.

This upgrade includes a fix for malformed Accept headers.

3.1.2

Released on March 31, 2023.

Ticket Type Description

MGNLSSO-250

Module dependency on Magnolia Core is raised to version 6.2.31.

3.1.1

Released on March 21, 2023.

Ticket Type Description

MGNLSSO-240

The Update Task was inadvertently throwing errors instead of logging warnings.

3.1.0

Released on March 8, 2023.

Ticket Type Description

MGNLSSO-189

Offer custom SSO authorization generators.

MGNLSSO-188

Refresh SSO configuration when loading YAML config file.

As part of this change, the module descriptor <name> changed from magnolia-sso to sso.

3.0.1

Released on January 20, 2023.

Ticket Type Description

MGNLSSO-218

Upload requests attempt to start an indirect flow.

A new flow logic has been implemented in this release.

Sec-Fetch-Mode header is navigate (indicates a user-originated request, as opposed to one loaded from a script).

If the header above is not set, Vaadin excludes typical requests (UIDL, HEARTBEAT, PUSH, etc.)

MGNLSSO-184

Property Expansion in magnolia-sso/config.yaml fails on creation of SSOCallbackServlet.

MGNLSSO-206

We have upgraded pac4j to version 5.7.0.

This upgrade introduces a new property called clientAuthenticationMethod to the configuration of the clients.

MGNLSSO-172

We have upgraded Mockito to version 4.

MGNLSSO-200

We have updated Guice to version 5.1.0

3.0.0

Released on August 26, 2022.

Ticket Type Description

MGNLSSO-140

SSO now builds on JDK 11.

MGNLSSO-132

Enhances multiple clients configuration and support a configurable authenticator for direct clients.

MGNLSSO-105

We have upgraded pac4j to v5.

MGNLSSO-96

Non-interactive SSO access to REST endpoints.

MGNLSSO-82

Map OIDC attributes to Magnolia properties with new userFieldMappings config property.

MGNLSSO-79

Authorize and validate incoming token for programmatic resource access.

Feedback

DX Core

×

Location

This widget lets you know where you are on the docs site.

You are currently perusing through the SSO module docs.

Main doc sections

DX Core Headless PaaS Legacy Cloud Incubator modules