Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Keycloak
  3. Keycloak - Package Updates

Keycloak - Package Updates

Scheduled Pinned Locked Moved Keycloak
31 Posts 1 Posters 4.9k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Package UpdatesP Offline
    Package UpdatesP Offline
    Package Updates
    App Dev
    wrote on last edited by
    #22

    [1.3.4]

    • Update keycloak to 26.3.4
    • Full Changelog
    • #​40630 Double check when working with multithreading. SAST
    • #​42245 Upgrade to Quarkus 3.20.2.2
    • #​35825 Per client session idle time capped by realm level client idle timeout core
    • #​40374 Random but frequent duplicate key value violates unique constraint "constraint_offl_us_ses_pk2" errors authentication
    • #​40463 Login to Account Console produces two consecutive LOGIN events account/ui
    • #​40857 Unbounded login_hint Parameter Can Corrupt KC_RESTART Cookie and Break Login Flow oidc
    • #​41427 Parallel token exchange fails if client session is expired token-exchange
    • #​41801 Lack of coordination in database creation in 26.3.0 causes deployment failures (Reopen) core
    • #​41942 Uncaught server error: org.keycloak.models.ModelException: Database operation failed : Sync LDAP Groups to Keycloak (Custom Provider) core
    • #​42012 Client session timestamp not updated in the database if running multiple nodes infinispan
    1 Reply Last reply
    0
    • Package UpdatesP Offline
      Package UpdatesP Offline
      Package Updates
      App Dev
      wrote on last edited by
      #23

      [1.3.5]

      • Update keycloak to 26.3.5
      • Full Changelog
      1 Reply Last reply
      0
      • Package UpdatesP Offline
        Package UpdatesP Offline
        Package Updates
        App Dev
        wrote on last edited by
        #24

        [1.4.0]

        • Update keycloak to 26.4.0
        • Full Changelog
        • Passkeys for seamless, passwordless authentication of users.
        • Federated Client Authentication to use SPIFFE or Kubernetes service account tokens for client authentication.
        • Simplified deployments across multiple availability zones to boost availability.
        • FAPI 2 Final: Keycloak now supports the final specifications of FAPI 2.0 Security Profile and FAPI 2.0 Message Signing.
        • DPoP: The OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) is now fully supported. Improvements include the ability to bind only refresh tokens for public clients, and securing all Keycloak endpoints with DPoP tokens.
        • FIPS 140-2 mode now supports EdDSA
        • Listing supported OAuth standards on one page
        • Automatic certificate management for SAML clients
        • Update Email Workflow (supported)
        • Optional email domain for organizations
        1 Reply Last reply
        0
        • Package UpdatesP Offline
          Package UpdatesP Offline
          Package Updates
          App Dev
          wrote on last edited by
          #25

          [1.4.1]

          • Update keycloak to 26.4.1
          • Full Changelog
          • #​43020 Secure Client-Initiated Renegotiation - disable by default dist/quarkus
          • #​42990 Hide read-only email attribute in update profile context with update email enabled user-profile
          • #​43357 JDBC_PING should publish its physical address on startup
          • #​40965 Group permission denies to view user admin/fine-grained-permissions
          • #​41292 openid-connect flow is missing response type on language change authentication
          • #​42565 Standard Token Exchange: chain of exchanges eventually fails token-exchange
          • #​42676 Security Defenses realm settings lost when switching between Headers and Brute Force Detection tabs (v25+) admin/ui
          • #​42907 Race condition in authorization service leads to NullPointerException when evaluating permissions during concurrent resource deletion authorization-services
          • #​43042 Avoid NPE in FederatedJWTClientAuthenticator when checking for supported assertion types core
          • #​43070 Update email page with pending verification email messages prefilled with old email user-profile
          1 Reply Last reply
          0
          • Package UpdatesP Offline
            Package UpdatesP Offline
            Package Updates
            App Dev
            wrote on last edited by
            #26

            [1.4.2]

            • Update keycloak to 26.4.2
            • Full Changelog
            • #43351 Make pending email verification attribute removable by admin user-profile
            • #43650 SPIFFE should support OIDC JWK endpoint
            • #30939 Vulnerability in brute force detection settings authentication
            • #43022 Incorrect Basic Auth encoding for OIDC IDentity Provider when Client ID contains colon identity-brokering
            • #43244 UI crash on admin /users/add-user since 26.4.0 admin/ui
            • #43561 Server does not shutdown gracefully when started with --optimized core
            1 Reply Last reply
            0
            • Package UpdatesP Offline
              Package UpdatesP Offline
              Package Updates
              App Dev
              wrote on last edited by
              #27

              [1.4.3]

              • Update keycloak to 26.4.4
              • Full Changelog
              • #10388 Allow to hide client scopes from scopes_supported in discovery endpoint
              • #43076 Add rate limiter for sending verification emails in context of update email
              • #43509 Role authorization for workflows. admin/api
              • #41270 Cannot save new attribute group admin/ui
              • #41271 Changing user profile attribute results in an error everytime admin/ui
              • #43082 ExternalLinksTest is broken due to missing path parameters docs
              • #43091 Duplicate Email Fields on Temporarily Locked Out Sign In With Organization Identity-First Login login/ui
              • #43160 Regression in DEBUG_PORT handling since 26.4.0 host binding (*:port / 0.0.0.0:port) no longer works dist/quarkus
              • #43460 FGAP/UI: reset-password succeeds but UI shows 403 without Users:manage admin/fine-grained-permissions
              • #43505 DPoP proof replay check doesn't consider clock skew oidc
              1 Reply Last reply
              0
              • Package UpdatesP Offline
                Package UpdatesP Offline
                Package Updates
                App Dev
                wrote on last edited by
                #28

                [1.4.4]

                • Update keycloak to 26.4.5
                • Full Changelog
                • #​43564 Invalid liquibase check sum for jpa-changelog-2.5.0.xml <code>core</code>
                • #​43718 Email Not Persisted During Registration When "Email as Username" is Enabled and User Edit Permission is Disabled <code>user-profile</code>
                • #​43793 import does not seem to run db migration <code>import-export</code>
                • #​43883 Creating group policy on a client uses "manage-clients" role if FGAP V1 is disabled <code>authorization-services</code>
                • #​44010 Ordering attributes will unset the unmanaged attribute policy <code>user-profile</code>
                • #​44031 Can't build keycloak 26.4.4 with quarkus.launch.rebuild=true <code>dist/quarkus</code>
                • #​44056 Allow only normalized URLs in requests caused a regression in view authz permission details in Admin Consol <code>admin/ui</code>
                1 Reply Last reply
                0
                • Package UpdatesP Offline
                  Package UpdatesP Offline
                  Package Updates
                  App Dev
                  wrote on last edited by
                  #29

                  [1.4.5]

                  • Update keycloak to 26.4.6
                  • Full Changelog
                  • This release adds filtering of LDAP referrals by default.
                  • #43323 Sessions not removed when user is deleted infinispan
                  • #43738 UPDATE_EMAIL action invalidates old email login/ui
                  • #43812 Admin console sends non-JSON payload with content-type: application/json admin/ui
                  • #44125 Double-encoding of query parameter values (e.g. acr_values) for version 26.4 identity-brokering
                  • #44189 [jdbc-ping] SQLIntegrityConstraintViolationException: Duplicate entry infinispan
                  • #44229 Unexpected FORMAT_FAILURE error when using cache-config-file with feature-disabled=persistent-user-sessions infinispan
                  • #44269 Admin Client creates malformed paths for requests admin/client-js
                  • #44287 Caching of static theme resources in dev mode is disabled core
                  1 Reply Last reply
                  0
                  • Package UpdatesP Offline
                    Package UpdatesP Offline
                    Package Updates
                    App Dev
                    wrote on last edited by
                    #30

                    [1.4.6]

                    • Update keycloak to 26.4.7
                    • Full Changelog
                    • #43156 [Docs] Warn users about printing headers in HTTP access logs docs
                    • #43643 Upgrade to Quarkus 3.27.1 dist/quarkus
                    • #44438 Intermittent ConcurrentModificationException during SAML initialization causing status code 400 for clients saml
                    • #44480 Wrong persistent group permissions when multiple group membership changes happen in the same request core
                    1 Reply Last reply
                    0
                    • Package UpdatesP Offline
                      Package UpdatesP Offline
                      Package Updates
                      App Dev
                      wrote last edited by
                      #31

                      [1.5.0]

                      • Update keycloak to 26.5.0
                      • Full Changelog
                      • Workflows to automate administrative tasks and process within a realm.
                      • JWT Authorization Grants, our recommended alternative to external to internal token exchange.
                      • Guide for using Keycloak as an authorization server for Model Context Protocol (MCP) servers.
                      • Authenticating clients with Kubernetes service account tokens to avoid static client secrets.
                      • OpenTelemetry support for metrics and logging, combining all observability information in this popular standard.
                      • CORS (Cross Origin Resource Sharing) is a browser security feature that controls how web pages on one domain can request resources from a different domain.
                      • For the OpenID Connect Dynamic Client Registration, you can now specify which CORS headers are allowed via the client registration access policies.
                      • For the overall CORS configuration, you can now allow environment specific headers to be allowed using the SPI option spi-cors--default--allowed-headers.
                      • The client logout configuration now includes an option to show a logout confirmation page. When enabled, users will see a You are logged out confirmation page upon successful logout.
                      • Previously, all scopes of an OpenID Connect client were advertised in the discovery endpoint.
                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search