Skip to content

Update dependency @backstage/plugin-auth-backend to ^0.29.0 [SECURITY] - #11

Open
renovate-wibrow[bot] wants to merge 1 commit into
mainfrom
renovate/npm-backstage-plugin-auth-backend-vulnerability
Open

renovate-wibrow[bot] wants to merge 1 commit into
mainfrom
renovate/npm-backstage-plugin-auth-backend-vulnerability

Conversation

@renovate-wibrow

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
@backstage/plugin-auth-backend (source) dependencies minor ^0.22.6 → ^0.29.0

@​backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass

CVE-2026-32235 / GHSA-wqvh-63mv-9w92

More information

Details

Impact

The experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured allowedRedirectUriPatterns are affected.

A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token.

This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default.

Patches

Upgrade to @backstage/plugin-auth-backend version 0.27.1 or later.

Workarounds

Disable experimental Dynamic Client Registration and Client ID Metadata Documents features if they are not required.

References

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


@​backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch

CVE-2026-32236 / GHSA-qp4c-xg64-7c6x

More information

Details

Impact

A Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when auth.experimentalClientIdMetadataDocuments.enabled is set to true. The CIMD
metadata fetch validates the initial client_id hostname against private IP ranges but does not apply the same validation after HTTP redirects.

The practical impact is limited. The attacker cannot read the response body from the internal request, cannot control request headers or method, and the feature must be explicitly
enabled via an experimental flag that is off by default. Deployments that restrict allowedClientIdPatterns to specific trusted domains are not affected.

Patches

Patched in @backstage/plugin-auth-backend version 0.27.1. The fix disables HTTP redirect following when fetching CIMD metadata documents.

Workarounds

Disable the experimental CIMD feature by removing or setting auth.experimentalClientIdMetadataDocuments.enabled to false in your app-config. This is the default configuration.
Alternatively, restrict allowedClientIdPatterns to specific trusted domains rather than using the default wildcard pattern.

References

Severity

  • CVSS Score: 1.7 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


@​backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via redirect_uri allowlist bypass

CVE-2026-73563 / GHSA-38hq-7x33-php4

More information

Details

Impact

The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in @backstage/plugin-auth-backend matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern such as https://*.example.com/callback, intended to allow subdomains of a trusted host, would also match an attacker-controlled URL such as https://attacker.example/x.example.com/callback. This applies to auth.experimentalDynamicClientRegistration.allowedRedirectUriPatterns as well as the allowedClientIdPatterns and allowedRedirectUriPatterns options of auth.experimentalClientIdMetadataDocuments.

An attacker could use this to register an OAuth client whose redirect URI points to a host they control while still passing the allowlist, causing authorization codes to be delivered to the attacker when a victim completes an authorization flow. In addition, allowlist patterns without an explicit protocol could match URLs with any protocol, and redirect URIs containing embedded credentials (user:pass@host) were accepted after the credentials were stripped for matching.

The practical impact is limited. Both features are experimental and disabled by default, and the default allowlist patterns only reference fixed or loopback hosts and are not affected. Deployments are only impacted if they enable one of these features and configure custom allowlist patterns that contain a wildcard in the hostname, or patterns without an explicit protocol.

Patches

Patched in @backstage/plugin-auth-backend version 0.29.2. Patterns are now matched against each URL component separately so that wildcards no longer match across the host and path boundary, patterns without an explicit protocol are rejected as invalid configuration, and redirect URIs with embedded credentials are always rejected.

Note that as part of this fix, a wildcard port no longer implicitly matches every path: a pattern such as http://localhost:* now only matches the root path. Use http://localhost:*/* to allow any port and any path.

Workarounds

Disable the experimental features by removing auth.experimentalDynamicClientRegistration and auth.experimentalClientIdMetadataDocuments from your app-config, which is the default configuration. Alternatively, restrict the configured allowlist patterns to fully specified URLs with an explicit protocol and no wildcard in the hostname, which are not affected by this vulnerability.

Severity

  • CVSS Score: 4.7 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

backstage/backstage (@​backstage/plugin-auth-backend)

v0.29.2

Compare Source

Patch Changes
  • e2b3472: Promoted Client ID Metadata Documents (CIMD) to the stable auth.clientIdMetadataDocuments configuration. The previous auth.experimentalClientIdMetadataDocuments key remains supported as a deprecated alias. Dynamic Client Registration now logs a deprecation warning when enabled and users should migrate to CIMD.
  • 2aeb246: Added token revocation support for clients using client ID metadata documents (CIMD). The /v1/revoke endpoint is now available whenever dynamic client registration or client ID metadata documents are enabled, and is advertised through revocation_endpoint in the OpenID provider configuration.
  • Updated dependencies

v0.29.1

Compare Source

Patch Changes

v0.29.0

Compare Source

Minor Changes
  • 29d398b: BREAKING: Hardened the default allowed patterns for CIMD and DCR to replace the previous permissive ['*'] wildcards with specific defaults for known MCP clients. If you previously relied on the default ['*'] patterns, you will need to explicitly configure the patterns you need in your app-config.yaml.

    CIMD (experimentalClientIdMetadataDocuments):

    • allowedClientIdPatterns now defaults to Claude, VS Code, and the built-in Backstage CLI instead of ['*']
    • allowedRedirectUriPatterns now defaults to loopback addresses (localhost, 127.0.0.1, [::1]) instead of ['*']

    DCR (experimentalDynamicClientRegistration):

    • allowedRedirectUriPatterns now defaults to Cursor and loopback addresses instead of ['*']

    If you need to allow additional clients or redirect URIs, you can override these defaults in your app-config.yaml:

    auth:
      experimentalClientIdMetadataDocuments:
        enabled: true
        allowedClientIdPatterns:
          - 'https://claude.ai/*'
          - 'https://vscode.dev/*'
          - 'https://my-custom-client.example.com/*'
        allowedRedirectUriPatterns:
          - 'http://localhost:*'
          - 'http://127.0.0.1:*'
          - 'https://my-app.example.com/callback'
      experimentalDynamicClientRegistration:
        enabled: true
        allowedRedirectUriPatterns:
          - 'cursor://*'
          - 'http://localhost:*'
          - 'http://127.0.0.1:*'
          - 'myapp://*'
Patch Changes
  • 9f269d7: Limit the size of fetched client ID metadata documents to prevent oversized responses from being accepted.
  • 3f5e7ec: Improved OIDC error messages to include the rejected redirect URI or client ID, making it easier to debug client registration failures.
  • e9b78e9: Removed the uuid dependency and replaced usage with the built-in crypto.randomUUID().
  • 27f24a9: Refresh token usage now verifies that the user's catalog entity still exists before issuing a new access token. If the user has been removed from the catalog, the refresh is rejected and the session is revoked. Transient catalog errors reject the refresh but preserve the session for retry. This check can be disabled by setting auth.experimentalRefreshToken.dangerouslyDisableCatalogPresenceCheck to true.
  • 4f62755: Improved the OAuth consent dialog for MCP authorization by showing more client details, including the client metadata host for CIMD clients, the metadata URL, callback URL, and requested scopes.
  • Updated dependencies

v0.28.0

Compare Source

Minor Changes
  • d7c67cd: BREAKING: The setting auth.omitIdentityTokenOwnershipClaim has had its default value switched to true.

    With this setting Backstage user tokens issued by the auth backend will no longer contain an ent claim - the one with the user's ownership entity refs. This means that tokens issued in large orgs no longer risk hitting HTTP header size limits.

    To get ownership info for the current user, code should use the userInfo core service. In practice code will typically already conform to this since the ent claim has not been readily exposed in any other way for quite some time. But code which explicitly decodes Backstage tokens - which is strongly discouraged - may be affected by this change.

    The setting will remain for some time to allow it to be set back to false if need be, but it will be removed entirely in a future release.

Patch Changes

v0.27.3

Compare Source

v0.27.2

Compare Source

Patch Changes
  • 1ccad86: Added who-am-i action to the auth backend actions registry. Returns the catalog entity and user info for the currently authenticated user.
  • d0f4cd2: Added optional client metadata document endpoint at /.well-known/oauth-client/cli.json relative to the auth backend base URL for CLI authentication. Enabled when auth.experimentalClientIdMetadataDocuments.enabled is set to true.
  • 6738cf0: build(deps): bump minimatch from 9.0.5 to 10.2.1
  • e9b6e97: Fixed a security vulnerability where the CIMD metadata fetch could follow HTTP redirects to internal hosts, bypassing SSRF protections.
  • 0f9d673: Improved redirect URI validation in the experimental OIDC provider to match against normalized URLs rather than raw strings.
  • a49a40d: Updated dependency zod to ^3.25.76 || ^4.0.0 & migrated to /v3 or /v4 imports.
  • 634eded: Fixed a foreign key constraint violation when issuing refresh tokens for CIMD clients, and
    prevented a failed refresh token issuance from failing the entire token exchange.
    Fixed AWS ALB auth provider incorrectly returning HTTP 500 instead of 401 for JWT validation failures,
    which caused retry loops and memory pressure under load.
  • 619be54: Update migrations to be reversible
  • Updated dependencies

v0.27.1

Compare Source

Patch Changes

v0.27.0

Compare Source

Minor Changes
  • 31de2c9: Added experimental support for Client ID Metadata Documents (CIMD).

    This allows Backstage to act as an OAuth 2.0 authorization server that supports the IETF Client ID Metadata Document draft. External OAuth clients can use HTTPS URLs as their client_id, and Backstage will fetch metadata from those URLs to validate the client.

    Configuration example:

    auth:
      experimentalClientIdMetadataDocuments:
        enabled: true
        # Optional: restrict which `client_id` URLs are allowed (defaults to ['*'])
        allowedClientIdPatterns:
          - 'https://example.com/*'
          - 'https://*.trusted-domain.com/*'
        # Optional: restrict which redirect URIs are allowed (defaults to ['*'])
        allowedRedirectUriPatterns:
          - 'http://localhost:*'
          - 'https://*.example.com/*'

    Clients using CIMD must host a JSON metadata document at their client_id URL containing at minimum:

    {
      "client_id": "https://example.com/.well-known/oauth-client/my-app",
      "client_name": "My Application",
      "redirect_uris": ["http://localhost:8080/callback"],
      "token_endpoint_auth_method": "none"
    }
  • d0786b9: Added experimental support for refresh tokens via the auth.experimentalRefreshToken.enabled configuration option. When enabled, clients can request the offline_access scope to receive refresh tokens that can be used to obtain new access tokens without re-authentication.

Patch Changes
  • 7dc3dfe: Removed the auth.experimentalDynamicClientRegistration.tokenExpiration config option. DCR tokens now use the default 1 hour expiration.

    If you need longer-lived access, use refresh tokens via the offline_access scope instead. DCR clients should already have the offline_access scope available. Enable refresh tokens by setting:

    auth:
      experimentalRefreshToken:
        enabled: true
  • 7455dae: Use node prefix on native imports

  • Updated dependencies

v0.26.0

Compare Source

Minor Changes
  • 7ffc873: Fix user_created_at migration causing SQLiteError regarding use of non-constants for defaults
Patch Changes

v0.25.7

Compare Source

Patch Changes

v0.25.6

Compare Source

Patch Changes

v0.25.5

Compare Source

Patch Changes

v0.25.4

Compare Source

Patch Changes

v0.25.3

Compare Source

Patch Changes

v0.25.2

Compare Source

Patch Changes

v0.25.1

Compare Source

Patch Changes

v0.25.0

Compare Source

Minor Changes
  • 57221d9: BREAKING: Removed support for the old backend system, and removed all deprecated exports.

    If you were using one of the deprecated imports from this package, you will have to follow the instructions in their respective deprecation notices before upgrading. Most of the general utilities are available from @backstage/plugin-auth-node, and the specific auth providers are available from dedicated packages such as for example @backstage/plugin-auth-backend-module-github-provider. See the auth docs for specific instructions.

Patch Changes
  • 0d606ac: Added the configuration flag auth.omitIdentityTokenOwnershipClaim that causes issued user tokens to no longer contain the ent claim that represents the ownership references of the user.

    The benefit of this new flag is that issued user tokens will be much smaller in
    size, but they will no longer be self-contained. This means that any consumers
    of the token that require access to the ownership claims now need to call the
    /api/auth/v1/userinfo endpoint instead. Within the Backstage ecosystem this is
    done automatically, as clients will still receive the full set of claims during
    authentication, while plugin backends will need to use the UserInfoService
    which already calls the user info endpoint if necessary.

    When enabling this flag, it is important that any custom sign-in resolvers directly return the result of the sign-in method. For example, the following would not work:

    const { token } = await ctx.issueToken({
      claims: { sub: entityRef, ent: [entityRef] },
    });
    return { token }; // WARNING: This will not work with the flag enabled

    Instead, the sign-in resolver should directly return the result:

    return ctx.issueToken({
      claims: { sub: entityRef, ent: [entityRef] },
    });
  • 72d019d: Removed various typos

  • ab53e6f: Added support for the new dangerousEntityRefFallback option for signInWithCatalogUser in AuthResolverContext.

  • b128ed9: The static key store now issues tokens with the same structure as other key stores. Tokens now include the typ field in the header and the uip (user identity proof) in the payload.

  • Updated dependencies

v0.24.5

Compare Source

Patch Changes
  • 25d05f9: Slight update to the config schema
  • Updated dependencies
    • @​backstage/plugin-auth-backend-module-bitbucket-provider@​0.3.2
    • @​backstage/plugin-catalog-node@1.16.3
    • @​backstage/plugin-auth-backend-module-oidc-provider@​0.4.2
    • @​backstage/backend-plugin-api@1.3.0
    • @​backstage/plugin-auth-backend-module-atlassian-provider@​0.4.2
    • @​backstage/plugin-auth-backend-module-auth0-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-bitbucket-server-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-cloudflare-access-provider@​0.4.2
    • @​backstage/plugin-auth-backend-module-github-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-gitlab-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-microsoft-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-oauth2-provider@​0.4.2
    • @​backstage/plugin-auth-backend-module-okta-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-onelogin-provider@​0.3.2
    • @​backstage/plugin-auth-node@0.6.2
    • @​backstage/catalog-client@1.9.1
    • @​backstage/catalog-model@1.7.3
    • @​backstage/config@1.3.2
    • @​backstage/errors@1.2.7
    • @​backstage/types@1.2.1
    • @​backstage/plugin-auth-backend-module-aws-alb-provider@​0.4.2
    • @​backstage/plugin-auth-backend-module-azure-easyauth-provider@​0.2.7
    • @​backstage/plugin-auth-backend-module-gcp-iap-provider@​0.4.2
    • @​backstage/plugin-auth-backend-module-google-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-oauth2-proxy-provider@0.2.7

v0.24.4

Compare Source

Patch Changes
  • 7956beb: Marked the remaining exports related to createRouter and the old backend system as deprecated.

    For more information about migrating to the new backend system, see the migration guide.

    Support for the old backend system will be removed in the next release of this plugin.

  • b6702ea: Deprecated getDefaultOwnershipEntityRefs in favor of the new .resolveOwnershipEntityRefs(...) method in the AuthResolverContext.

    The following code in a custom sign-in resolver:

    import { getDefaultOwnershipEntityRefs } from '@backstage/plugin-auth-backend';
    
    // ...
    
    const ent = getDefaultOwnershipEntityRefs(entity);

    Can be replaced with the following:

    const { ownershipEntityRefs: ent } = await ctx.resolveOwnershipEntityRefs(
      entity,
    );
  • Updated dependencies

    • @​backstage/plugin-auth-node@0.6.1
    • @​backstage/plugin-auth-backend-module-microsoft-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-oauth2-provider@​0.4.1
    • @​backstage/plugin-auth-backend-module-oidc-provider@​0.4.1
    • @​backstage/plugin-auth-backend-module-okta-provider@​0.2.1
    • @​backstage/backend-plugin-api@1.2.1
    • @​backstage/catalog-client@1.9.1
    • @​backstage/catalog-model@1.7.3
    • @​backstage/config@1.3.2
    • @​backstage/errors@1.2.7
    • @​backstage/types@1.2.1
    • @​backstage/plugin-auth-backend-module-atlassian-provider@​0.4.1
    • @​backstage/plugin-auth-backend-module-auth0-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-aws-alb-provider@​0.4.1
    • @​backstage/plugin-auth-backend-module-azure-easyauth-provider@​0.2.6
    • @​backstage/plugin-auth-backend-module-bitbucket-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-bitbucket-server-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-cloudflare-access-provider@​0.4.1
    • @​backstage/plugin-auth-backend-module-gcp-iap-provider@​0.4.1
    • @​backstage/plugin-auth-backend-module-github-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-gitlab-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-google-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-oauth2-proxy-provider@0.2.6
    • @​backstage/plugin-auth-backend-module-onelogin-provider@​0.3.1
    • @​backstage/plugin-catalog-node@1.16.1

v0.24.3

Compare Source

Patch Changes
  • Updated dependencies
    • @​backstage/plugin-auth-backend-module-github-provider@​0.3.0
    • @​backstage/backend-plugin-api@1.2.0
    • @​backstage/plugin-catalog-node@1.16.0
    • @​backstage/plugin-auth-node@0.6.0
    • @​backstage/plugin-auth-backend-module-oidc-provider@​0.4.0
    • @​backstage/plugin-auth-backend-module-cloudflare-access-provider@​0.4.0
    • @​backstage/plugin-auth-backend-module-bitbucket-server-provider@​0.2.0
    • @​backstage/plugin-auth-backend-module-atlassian-provider@​0.4.0
    • @​backstage/plugin-auth-backend-module-bitbucket-provider@​0.3.0
    • @​backstage/plugin-auth-backend-module-microsoft-provider@​0.3.0
    • @​backstage/plugin-auth-backend-module-onelogin-provider@​0.3.0
    • @​backstage/plugin-auth-backend-module-aws-alb-provider@​0.4.0
    • @​backstage/plugin-auth-backend-module-gcp-iap-provider@​0.4.0
    • @​backstage/plugin-auth-backend-module-gitlab-provider@​0.3.0
    • @​backstage/plugin-auth-backend-module-google-provider@​0.3.0
    • @​backstage/plugin-auth-backend-module-oauth2-provider@​0.4.0
    • @​backstage/plugin-auth-backend-module-auth0-provider@​0.2.0
    • @​backstage/plugin-auth-backend-module-okta-provider@​0.2.0
    • @​backstage/catalog-client@1.9.1
    • @​backstage/catalog-model@1.7.3
    • @​backstage/config@1.3.2
    • @​backstage/errors@1.2.7
    • @​backstage/types@1.2.1
    • @​backstage/plugin-auth-backend-module-azure-easyauth-provider@​0.2.5
    • @​backstage/plugin-auth-backend-module-oauth2-proxy-provider@0.2.5

v0.24.2

Compare Source

Patch Changes
  • 8379bf4: Remove usages of PluginDatabaseManager and PluginEndpointDiscovery and replace with their equivalent service types
  • Updated dependencies
    • @​backstage/plugin-auth-backend-module-cloudflare-access-provider@​0.3.4
    • @​backstage/types@1.2.1
    • @​backstage/plugin-auth-node@0.5.6
    • @​backstage/backend-plugin-api@1.1.1
    • @​backstage/catalog-client@1.9.1
    • @​backstage/catalog-model@1.7.3
    • @​backstage/config@1.3.2
    • @​backstage/errors@1.2.7
    • @​backstage/plugin-auth-backend-module-atlassian-provider@​0.3.4
    • @​backstage/plugin-auth-backend-module-auth0-provider@​0.1.4
    • @​backstage/plugin-auth-backend-module-aws-alb-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-azure-easyauth-provider@​0.2.4
    • @​backstage/plugin-auth-backend-module-bitbucket-provider@​0.2.4
    • @​backstage/plugin-auth-backend-module-bitbucket-server-provider@​0.1.4
    • @​backstage/plugin-auth-backend-module-gcp-iap-provider@​0.3.4
    • @​backstage/plugin-auth-backend-module-github-provider@​0.2.4
    • @​backstage/plugin-auth-backend-module-gitlab-provider@​0.2.4
    • @​backstage/plugin-auth-backend-module-google-provider@​0.2.4
    • @​backstage/plugin-auth-backend-module-microsoft-provider@​0.2.4
    • @​backstage/plugin-auth-backend-module-oauth2-provider@​0.3.4
    • @​backstage/plugin-auth-backend-module-oauth2-proxy-provider@0.2.4
    • @​backstage/plugin-auth-backend-module-oidc-provider@​0.3.4
    • @​backstage/plugin-auth-backend-module-okta-provider@​0.1.4
    • @​backstage/plugin-auth-backend-module-onelogin-provider@​0.2.4
    • @​backstage/plugin-catalog-node@1.15.1

v0.24.1

Compare Source

Patch Changes
  • c907440: Improved error forwarding for OAuth refresh endpoints
  • 40518ab: Fix issue with jwks endpoint returning invalid data with firestore
  • 5c9cc05: Use native fetch instead of node-fetch
  • Updated dependencies
    • @​backstage/plugin-auth-node@0.5.5
    • @​backstage/backend-plugin-api@1.1.0
    • @​backstage/plugin-catalog-node@1.15.0
    • @​backstage/catalog-client@1.9.0
    • @​backstage/plugin-auth-backend-module-cloudflare-access-provider@​0.3.3
    • @​backstage/plugin-auth-backend-module-bitbucket-server-provider@​0.1.3
    • @​backstage/plugin-auth-backend-module-microsoft-provider@​0.2.3
    • @​backstage/plugin-auth-backend-module-aws-alb-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-google-provider@​0.2.3
    • @​backstage/errors@1.2.6
    • @​backstage/plugin-auth-backend-module-atlassian-provider@​0.3.3
    • @​backstage/plugin-auth-backend-module-auth0-provider@​0.1.3
    • @​backstage/plugin-auth-backend-module-bitbucket-provider@​0.2.3
    • @​backstage/plugin-auth-backend-module-github-provider@​0.2.3
    • @​backstage/plugin-auth-backend-module-gitlab-provider@​0.2.3
    • @​backstage/plugin-auth-backend-module-oauth2-provider@​0.3.3
    • @​backstage/plugin-auth-backend-module-oidc-provider@​0.3.3
    • @​backstage/plugin-auth-backend-module-okta-provider@​0.1.3
    • @​backstage/plugin-auth-backend-module-onelogin-provider@​0.2.3
    • @​backstage/catalog-model@1.7.2
    • @​backstage/config@1.3.1
    • @​backstage/types@1.2.0
    • @​backstage/plugin-auth-backend-module-azure-easyauth-provider@​0.2.3
    • @​backstage/plugin-auth-backend-module-gcp-iap-provider@​0.3.3
    • @​backstage/plugin-auth-backend-module-oauth2-proxy-provider@0.2.3

v0.24.0

Compare Source

Minor Changes
  • 75168e3: BREAKING: The AWS ALB fullProfile will no longer have the its username or email converted to lowercase. This is to ensure unique handling of the users. You may need to update and configure a custom sign-in resolver or profile transform as a result.
Patch Changes
  • d52d7f9: Support ISO and ms string forms of durations in config too
  • 4e58bc7: Upgrade to uuid v11 internally
  • Updated dependencies
    • @​backstage/catalog-client@1.8.0
    • @​backstage/config@1.3.0
    • @​backstage/plugin-auth-backend-module-google-provider@​0.2.2
    • @​backstage/types@1.2.0
    • @​backstage/plugin-auth-backend-module-aws-alb-provider@​0.3.0
    • @​backstage/plugin-auth-node@0.5.4
    • @​backstage/plugin-catalog-node@1.14.0
    • @​backstage/plugin-auth-backend-module-cloudflare-access-provider@​0.3.2
    • @​backstage/backend-plugin-api@1.0.2
    • @​backstage/plugin-auth-backend-module-oidc-provider@​0.3.2
    • @​backstage/catalog-model@1.7.1
    • @​backstage/errors@1.2.5
    • @​backstage/plugin-auth-backend-module-atlassian-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-auth0-provider@​0.1.2
    • @​backstage/plugin-auth-backend-module-azure-easyauth-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-bitbucket-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-bitbucket-server-provider@​0.1.2
    • @​backstage/plugin-auth-backend-module-gcp-iap-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-github-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-gitlab-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-microsoft-provider@​0.2.2
    • @​backstage/plugin-auth-backend-module-oauth2-provider@​0.3.2
    • @​backstage/plugin-auth-backend-module-oauth2-proxy-provider@0.2.2
    • @​backstage/plugin-auth-backend-module-okta-provider@​0.1.2
    • @​backstage/plugin-auth-backend-module-onelogin-provider@​0.2.2

v0.23.1

Compare Source

Patch Changes
  • 094eaa3: Remove references to in-repo backend-common
  • Updated dependencies
    • @​backstage/plugin-auth-backend-module-cloudflare-access-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-atlassian-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-bitbucket-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-microsoft-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-onelogin-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-aws-alb-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-gcp-iap-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-github-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-gitlab-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-google-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-oauth2-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-oidc-provider@​0.3.1
    • @​backstage/plugin-auth-backend-module-okta-provider@​0.1.1
    • @​backstage/plugin-auth-node@0.5.3
    • @​backstage/plugin-catalog-node@1.13.1
    • @​backstage/catalog-client@1.7.1
    • @​backstage/backend-plugin-api@1.0.1
    • @​backstage/catalog-model@1.7.0
    • @​backstage/config@1.2.0
    • @​backstage/errors@1.2.4
    • @​backstage/types@1.1.1
    • @​backstage/plugin-auth-backend-module-auth0-provider@​0.1.1
    • @​backstage/plugin-auth-backend-module-azure-easyauth-provider@​0.2.1
    • @​backstage/plugin-auth-backend-module-bitbucket-server-provider@​0.1.1
    • @​backstage/plugin-auth-backend-module-oauth2-proxy-provider@0.2.1

v0.23.0

Compare Source

Minor Changes
  • d425fc4: BREAKING: The return values from createBackendPlugin, createBackendModule, and createServiceFactory are now simply BackendFeature and ServiceFactory, instead of the previously deprecated form of a function that returns them. For this reason, createServiceFactory also no longer accepts the callback form where you provide direct options to the service. This also affects all coreServices.* service refs.

    This may in particular affect tests; if you were effectively doing createBackendModule({...})() (note the parentheses), you can now remove those extra parentheses at the end. You may encounter cases of this in your packages/backend/src/index.ts too, where you add plugins, modules, and services. If you were using createServiceFactory with a function as its argument for the purpose of passing in options, this pattern has been d

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants