Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump oauth2 from 4.0.0-alpha.3 to 4.0.0 #28

Closed
wants to merge 1 commit into from

Conversation

dependabot-preview[bot]
Copy link
Contributor

Bumps oauth2 from 4.0.0-alpha.3 to 4.0.0.

Release notes

Sourced from oauth2's releases.

4.0.0

Changes since 4.0.0-beta.1

  • Fix a couple of doc comments and an error message to say failed instead of Errored.

Summary of changes since 3.0.0

Breaking changes

  • Raise minimum supported Rust version (MSRV) to 1.45.
  • Upgrade reqwest to 0.11 and rename feature flag to reqwest. This upgrades tokio to 1.0 and removes support for both the reqwest-010 and reqwest-09 feature flags.
  • Drop support for futures 0.1 and remove the futures-01 and futures-03 feature flags; only async/await and futures 0.3 are now supported (without requiring any feature flags).
  • Eliminate Async* traits and move the request_async methods to the underlying *Request structs
  • Migrate public API from http 0.1 to 0.2.
  • Return error types that implement std::error::Error instead of failure::Fail.
  • Expose a serde_path_to_error::Error<serde_json::Error>> in the RequestTokenError::Parse variant instead of a serde_json::Error to make JSON deserialization errors easier to diagnose.
  • Add #[non_exhaustive] attribute to AuthType to support non-breaking additions in the future.

New features

Other changes

  • Have reqwest client use rustls-tls by default instead of native TLS. This behavior can be overridden using the native-tls feature flag.
  • RUSTSEC-2016-0005: replace rust-crypto with hmac in dev-dependencies

4.0.0-beta.1

This is the first beta release for the 4.0 major version. No further breaking changes are expected until the next major version.

Breaking Changes

  • Add rustls-tls (default) and native-tls feature flags for use with reqwest. Previously, enabling the reqwest feature flag would always use rustls. The default behavior is unchanged, but users that disable the default features and wish to continue using rustls may wish to add the rustls-tls feature flag to their Cargo.toml.
  • Expose a serde_path_to_error::Error<serde_json::Error>> in the RequestTokenError::Parse variant instead of a serde_json::Error. This change should make JSON deserialization errors easier to diagnose.

4.0.0-alpha.6

Breaking Changes

  • Fix URI/URL naming inconsistencies (#128). For context, see ramosbugs/openidconnect-rs#39.
    • set_introspection_url -> set_introspection_uri
    • set_redirect_url -> set_redirect_uri
    • set_revocation_url -> set_revocation_uri

4.0.0-alpha.5

Breaking Changes

  • Have Client::exchange_device_code, Client::introspect, and Client::revoke_token fail fast with a new ConfigurationError enum when the relevant OAuth2 endpoint hasn't been configured by calling set_device_authorization_url, set_introspection_url, or set_revocation_url, respectively. Previously, an error would not be returned until a call to request/request_async (#127).

Other Changes

  • Add extra_fields() getter to StandardTokenIntrospectionResponse (#126)
  • Fix missing closing parenthesis in doc comment (#125)

... (truncated)

Commits
  • c7945ce Bump version to 4.0.0
  • 7c10cf0 Fix MSRV comment
  • df8dc14 Add a Cargo.lock for MSRV 1.45 CI runs
  • 9dbaa96 Errored->Failed (#133)
  • a059cfc Bump version to 4.0.0-beta.2
  • d3b0899 Run rustfmt
  • 16325ea Use serde_path_to_error for better deserialization errors
  • d07d7f9 Bump version to 4.0.0-beta.1
  • 96d2591 Add rustls-tls and native-tls feature flags for reqwest client (#129)
  • 07b7045 Bump version to 4.0.0-alpha.7
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [oauth2](https://github.com/ramosbugs/oauth2-rs) from 4.0.0-alpha.3 to 4.0.0.
- [Release notes](https://github.com/ramosbugs/oauth2-rs/releases)
- [Commits](ramosbugs/oauth2-rs@4.0.0-alpha.3...4.0.0)

Signed-off-by: dependabot-preview[bot] <[email protected]>
@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Apr 19, 2021
@dependabot-preview
Copy link
Contributor Author

Superseded by #39.

@dependabot-preview dependabot-preview bot deleted the dependabot/cargo/oauth2-4.0.0 branch July 6, 2021 06:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants