Fixed a vulnerability affecting disabled client enforcement.
Fixed a vulnerability affecting cached client response lifecycle.
Fixed a vulnerability affecting upstream response handling.
2.0.20 2026-10-02
Changed
Updated the required version of verbb/base to 3.0.19.
Fixed
Fixed a high-severity authorization vulnerability.
Invalidate saved OAuth tokens when client connection settings change.
Validate Zendesk subdomains and Vend store names before constructing OAuth endpoints.
2.0.19 2026-09-30
Changed
Route plugin settings through the plugin’s authorized settings controller.
Fixed
Fixed a high-severity authorization vulnerability.
Fixed a moderate-severity information disclosure vulnerability.
Fixed OAuth callback transaction validation.
Fixed authorization for connecting and disconnecting OAuth clients.
Fixed OAuth callback redirects being evaluated as Twig templates.
2.0.18 2026-09-14
Changed
Align documentation filenames with page titles and update internal links.
Updated documentation for clearer, more consistent guidance.
Clarified optional PHP configuration with focused examples and linkable setting details.
2.0.17 2026-09-13
Changed
Normalize plugin settings.
2.0.16 2026-07-15
Fixed
Fix cache keys differing for equivalent requests when using Consume-only options like includeErrorResponse, or when passing a client handle as a string vs an array.
2.0.15 2026-06-20
Fixed
Fix an issue where format: 'raw' would fail for OAuth client requests that return already-parsed string content.
2.0.14 2026-05-30
Fixed
Fix an issue where client scopes aren’t normalized.
2.0.13 2026-05-14
Changed
Update fetchData() logic to set the cache data for requests.
2.0.12 2026-05-03
Changed
Bump verbb/auth to allow firebase/php-jwt 7.x.
2.0.11 2026-03-28
Added
Add the ability to override the default Redirect URI as a plugin setting.
2.0.10 2026-02-07
Fixed
Fix a redirect error when connecting to a client in the control panel.
Fix an error when creating a new client.
2.0.9 2026-01-23
Changed
Bump verbb/auth.
2.0.8 2025-11-06
Added
Add better trace information for logging when connecting to OAuth provider.
2.0.7 2025-09-16
Added
Add username and password to Generic OAuth client settings.
Fixed
Fix “Authorization URL” and “Token URL” from being shown for a “Client Credentials” type client.
Fix error handling for duplicate-named clients.
2.0.6 2025-08-13
Added
Add support for raw response handling for requests.
2.0.5 2025-07-18
Changed
Update symfony/property-access and symfony/serializer dependency.
2.0.4 2025-07-18
Changed
Update English translations.
Update status indicator.
2.0.3 2025-04-12
Changed
Update GitHub, GitLab and PayPal provider classes to be proper case.
2.0.2 2025-02-03
Added
Add CA to Zoho domains.
Add consume/tokens/refresh console command.
Fixed
Fix backward compatibility check for custom clients and proxy field setting support.
Fix status indicators.
Fix deleting a client not working from the editing client interface.
2.0.1 2024-07-21
Changed
Update English translations.
Fixed
Fix Generic OAuth provider now parsing .env variables for Auth/Token/API URLs.
2.0.0 2024-05-13
Added
Add improved session-handling for authorization and callback methods, to improve failed sessions in some cases.