feat(deps): update dependency @backstage/plugin-auth-backend ( 0.25.6 ➔ 0.29.2 ) [security] #85

Open
renovate wants to merge 1 commit from renovate/npm-backstage-plugin-auth-backend-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@backstage/plugin-auth-backend (source) ^0.25.6 → ^0.29.0 age adoption passing confidence

🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Released is the upstream publish time. — means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so minimumReleaseAge cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's minimumReleaseAge to Released to get the eligibility moment.


@​backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch

CVE-2026-32236 / GHSA-qp4c-xg64-7c6x

More information

Details

Impact

A Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when auth.experimentalClientIdMetadataDocuments.enabled is set to true. The CIMD
metadata fetch validates the initial client_id hostname against private IP ranges but does not apply the same validation after HTTP redirects.

The practical impact is limited. The attacker cannot read the response body from the internal request, cannot control request headers or method, and the feature must be explicitly
enabled via an experimental flag that is off by default. Deployments that restrict allowedClientIdPatterns to specific trusted domains are not affected.

Patches

Patched in @backstage/plugin-auth-backend version 0.27.1. The fix disables HTTP redirect following when fetching CIMD metadata documents.

Workarounds

Disable the experimental CIMD feature by removing or setting auth.experimentalClientIdMetadataDocuments.enabled to false in your app-config. This is the default configuration.
Alternatively, restrict allowedClientIdPatterns to specific trusted domains rather than using the default wildcard pattern.

References

Severity

  • CVSS Score: 1.7 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


@​backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass

CVE-2026-32235 / GHSA-wqvh-63mv-9w92

More information

Details

Impact

The experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured allowedRedirectUriPatterns are affected.

A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token.

This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default.

Patches

Upgrade to @backstage/plugin-auth-backend version 0.27.1 or later.

Workarounds

Disable experimental Dynamic Client Registration and Client ID Metadata Documents features if they are not required.

References

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


@​backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via redirect_uri allowlist bypass

CVE-2026-73563 / GHSA-38hq-7x33-php4

More information

Details

Impact

The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in @backstage/plugin-auth-backend matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern such as https://*.example.com/callback, intended to allow subdomains of a trusted host, would also match an attacker-controlled URL such as https://attacker.example/x.example.com/callback. This applies to auth.experimentalDynamicClientRegistration.allowedRedirectUriPatterns as well as the allowedClientIdPatterns and allowedRedirectUriPatterns options of auth.experimentalClientIdMetadataDocuments.

An attacker could use this to register an OAuth client whose redirect URI points to a host they control while still passing the allowlist, causing authorization codes to be delivered to the attacker when a victim completes an authorization flow. In addition, allowlist patterns without an explicit protocol could match URLs with any protocol, and redirect URIs containing embedded credentials (user:pass@host) were accepted after the credentials were stripped for matching.

The practical impact is limited. Both features are experimental and disabled by default, and the default allowlist patterns only reference fixed or loopback hosts and are not affected. Deployments are only impacted if they enable one of these features and configure custom allowlist patterns that contain a wildcard in the hostname, or patterns without an explicit protocol.

Patches

Patched in @backstage/plugin-auth-backend version 0.29.2. Patterns are now matched against each URL component separately so that wildcards no longer match across the host and path boundary, patterns without an explicit protocol are rejected as invalid configuration, and redirect URIs with embedded credentials are always rejected.

Note that as part of this fix, a wildcard port no longer implicitly matches every path: a pattern such as http://localhost:* now only matches the root path. Use http://localhost:*/* to allow any port and any path.

Workarounds

Disable the experimental features by removing auth.experimentalDynamicClientRegistration and auth.experimentalClientIdMetadataDocuments from your app-config, which is the default configuration. Alternatively, restrict the configured allowlist patterns to fully specified URLs with an explicit protocol and no wildcard in the hostname, which are not affected by this vulnerability.

Severity

  • CVSS Score: 4.7 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

backstage/backstage (@​backstage/plugin-auth-backend)

v0.29.2

Compare Source

Patch Changes
  • e2b3472: Promoted Client ID Metadata Documents (CIMD) to the stable auth.clientIdMetadataDocuments configuration. The previous auth.experimentalClientIdMetadataDocuments key remains supported as a deprecated alias. Dynamic Client Registration now logs a deprecation warning when enabled and users should migrate to CIMD.
  • 2aeb246: Added token revocation support for clients using client ID metadata documents (CIMD). The /v1/revoke endpoint is now available whenever dynamic client registration or client ID metadata documents are enabled, and is advertised through revocation_endpoint in the OpenID provider configuration.
  • Updated dependencies

v0.29.1

Compare Source

Patch Changes

v0.29.0

Compare Source

Minor Changes
  • 29d398b: BREAKING: Hardened the default allowed patterns for CIMD and DCR to replace the previous permissive ['*'] wildcards with specific defaults for known MCP clients. If you previously relied on the default ['*'] patterns, you will need to explicitly configure the patterns you need in your app-config.yaml.

    CIMD (experimentalClientIdMetadataDocuments):

    • allowedClientIdPatterns now defaults to Claude, VS Code, and the built-in Backstage CLI instead of ['*']
    • allowedRedirectUriPatterns now defaults to loopback addresses (localhost, 127.0.0.1, [::1]) instead of ['*']

    DCR (experimentalDynamicClientRegistration):

    • allowedRedirectUriPatterns now defaults to Cursor and loopback addresses instead of ['*']

    If you need to allow additional clients or redirect URIs, you can override these defaults in your app-config.yaml:

    auth:
      experimentalClientIdMetadataDocuments:
        enabled: true
        allowedClientIdPatterns:
          - 'https://claude.ai/*'
          - 'https://vscode.dev/*'
          - 'https://my-custom-client.example.com/*'
        allowedRedirectUriPatterns:
          - 'http://localhost:*'
          - 'http://127.0.0.1:*'
          - 'https://my-app.example.com/callback'
      experimentalDynamicClientRegistration:
        enabled: true
        allowedRedirectUriPatterns:
          - 'cursor://*'
          - 'http://localhost:*'
          - 'http://127.0.0.1:*'
          - 'myapp://*'
    
Patch Changes
  • 9f269d7: Limit the size of fetched client ID metadata documents to prevent oversized responses from being accepted.
  • 3f5e7ec: Improved OIDC error messages to include the rejected redirect URI or client ID, making it easier to debug client registration failures.
  • e9b78e9: Removed the uuid dependency and replaced usage with the built-in crypto.randomUUID().
  • 27f24a9: Refresh token usage now verifies that the user's catalog entity still exists before issuing a new access token. If the user has been removed from the catalog, the refresh is rejected and the session is revoked. Transient catalog errors reject the refresh but preserve the session for retry. This check can be disabled by setting auth.experimentalRefreshToken.dangerouslyDisableCatalogPresenceCheck to true.
  • 4f62755: Improved the OAuth consent dialog for MCP authorization by showing more client details, including the client metadata host for CIMD clients, the metadata URL, callback URL, and requested scopes.
  • Updated dependencies

v0.28.0

Compare Source

Minor Changes
  • d7c67cd: BREAKING: The setting auth.omitIdentityTokenOwnershipClaim has had its default value switched to true.

    With this setting Backstage user tokens issued by the auth backend will no longer contain an ent claim - the one with the user's ownership entity refs. This means that tokens issued in large orgs no longer risk hitting HTTP header size limits.

    To get ownership info for the current user, code should use the userInfo core service. In practice code will typically already conform to this since the ent claim has not been readily exposed in any other way for quite some time. But code which explicitly decodes Backstage tokens - which is strongly discouraged - may be affected by this change.

    The setting will remain for some time to allow it to be set back to false if need be, but it will be removed entirely in a future release.

Patch Changes

v0.27.3

Compare Source

v0.27.2

Compare Source

Patch Changes
  • 1ccad86: Added who-am-i action to the auth backend actions registry. Returns the catalog entity and user info for the currently authenticated user.
  • d0f4cd2: Added optional client metadata document endpoint at /.well-known/oauth-client/cli.json relative to the auth backend base URL for CLI authentication. Enabled when auth.experimentalClientIdMetadataDocuments.enabled is set to true.
  • 6738cf0: build(deps): bump minimatch from 9.0.5 to 10.2.1
  • e9b6e97: Fixed a security vulnerability where the CIMD metadata fetch could follow HTTP redirects to internal hosts, bypassing SSRF protections.
  • 0f9d673: Improved redirect URI validation in the experimental OIDC provider to match against normalized URLs rather than raw strings.
  • a49a40d: Updated dependency zod to ^3.25.76 || ^4.0.0 & migrated to /v3 or /v4 imports.
  • 634eded: Fixed a foreign key constraint violation when issuing refresh tokens for CIMD clients, and
    prevented a failed refresh token issuance from failing the entire token exchange.
    Fixed AWS ALB auth provider incorrectly returning HTTP 500 instead of 401 for JWT validation failures,
    which caused retry loops and memory pressure under load.
  • 619be54: Update migrations to be reversible
  • Updated dependencies

v0.27.1

Compare Source

Patch Changes

v0.27.0

Compare Source

Minor Changes
  • 31de2c9: Added experimental support for Client ID Metadata Documents (CIMD).

    This allows Backstage to act as an OAuth 2.0 authorization server that supports the IETF Client ID Metadata Document draft. External OAuth clients can use HTTPS URLs as their client_id, and Backstage will fetch metadata from those URLs to validate the client.

    Configuration example:

    auth:
      experimentalClientIdMetadataDocuments:
        enabled: true
        # Optional: restrict which `client_id` URLs are allowed (defaults to ['*'])
        allowedClientIdPatterns:
          - 'https://example.com/*'
          - 'https://*.trusted-domain.com/*'
        # Optional: restrict which redirect URIs are allowed (defaults to ['*'])
        allowedRedirectUriPatterns:
          - 'http://localhost:*'
          - 'https://*.example.com/*'
    

    Clients using CIMD must host a JSON metadata document at their client_id URL containing at minimum:

    {
      "client_id": "https://example.com/.well-known/oauth-client/my-app",
      "client_name": "My Application",
      "redirect_uris": ["http://localhost:8080/callback"],
      "token_endpoint_auth_method": "none"
    }
    
  • d0786b9: Added experimental support for refresh tokens via the auth.experimentalRefreshToken.enabled configuration option. When enabled, clients can request the offline_access scope to receive refresh tokens that can be used to obtain new access tokens without re-authentication.

Patch Changes
  • 7dc3dfe: Removed the auth.experimentalDynamicClientRegistration.tokenExpiration config option. DCR tokens now use the default 1 hour expiration.

    If you need longer-lived access, use refresh tokens via the offline_access scope instead. DCR clients should already have the offline_access scope available. Enable refresh tokens by setting:

    auth:
      experimentalRefreshToken:
        enabled: true
    
  • 7455dae: Use node prefix on native imports

  • Updated dependencies

v0.26.0

Compare Source

Minor Changes
  • 7ffc873: Fix user_created_at migration causing SQLiteError regarding use of non-constants for defaults
Patch Changes

v0.25.7

Compare Source

Patch Changes

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [@backstage/plugin-auth-backend](https://backstage.io) ([source](https://github.com/backstage/backstage/tree/HEAD/plugins/auth-backend)) | [`^0.25.6` → `^0.29.0`](https://renovatebot.com/diffs/npm/@backstage%2fplugin-auth-backend/0.25.6/0.29.2) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@backstage%2fplugin-auth-backend/0.29.2?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@backstage%2fplugin-auth-backend/0.29.2?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@backstage%2fplugin-auth-backend/0.25.6/0.29.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@backstage%2fplugin-auth-backend/0.25.6/0.29.2?slim=true) | 🔒 **Security update**: prioritize review and verify the vulnerable component is actually deployed. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. `Released` is the upstream publish time. `—` means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so `minimumReleaseAge` cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's `minimumReleaseAge` to `Released` to get the eligibility moment. --- ### @&#8203;backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch [CVE-2026-32236](https://nvd.nist.gov/vuln/detail/CVE-2026-32236) / [GHSA-qp4c-xg64-7c6x](https://github.com/advisories/GHSA-qp4c-xg64-7c6x) <details> <summary>More information</summary> #### Details ##### Impact A Server-Side Request Forgery (SSRF) vulnerability exists in `@backstage/plugin-auth-backend` when `auth.experimentalClientIdMetadataDocuments.enabled` is set to `true`. The CIMD metadata fetch validates the initial `client_id` hostname against private IP ranges but does not apply the same validation after HTTP redirects. The practical impact is limited. The attacker cannot read the response body from the internal request, cannot control request headers or method, and the feature must be explicitly enabled via an experimental flag that is off by default. Deployments that restrict `allowedClientIdPatterns` to specific trusted domains are not affected. ### Patches Patched in `@backstage/plugin-auth-backend` version `0.27.1`. The fix disables HTTP redirect following when fetching CIMD metadata documents. ### Workarounds Disable the experimental CIMD feature by removing or setting `auth.experimentalClientIdMetadataDocuments.enabled` to `false` in your app-config. This is the default configuration. Alternatively, restrict `allowedClientIdPatterns` to specific trusted domains rather than using the default wildcard pattern. ### References - [IETF Client ID Metadata Document draft](https://datatracker.ietf.org/doc/draft-ietf-oauth-client-id-metadata-document/) - [MCP Authorization Specification - Client ID Metadata Documents](https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization#client-id-metadata-documents) #### Severity - CVSS Score: 1.7 / 10 (Low) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-qp4c-xg64-7c6x](https://github.com/backstage/backstage/security/advisories/GHSA-qp4c-xg64-7c6x) - [https://nvd.nist.gov/vuln/detail/CVE-2026-32236](https://nvd.nist.gov/vuln/detail/CVE-2026-32236) - [https://github.com/backstage/backstage/commit/17038abf2dfdb4abc08a59b1c95af39851de0e07](https://github.com/backstage/backstage/commit/17038abf2dfdb4abc08a59b1c95af39851de0e07) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-qp4c-xg64-7c6x) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### @&#8203;backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass [CVE-2026-32235](https://nvd.nist.gov/vuln/detail/CVE-2026-32235) / [GHSA-wqvh-63mv-9w92](https://github.com/advisories/GHSA-wqvh-63mv-9w92) <details> <summary>More information</summary> #### Details ##### Impact The experimental OIDC provider in `@backstage/plugin-auth-backend` is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured `allowedRedirectUriPatterns` are affected. A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token. This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default. ##### Patches Upgrade to `@backstage/plugin-auth-backend` version 0.27.1 or later. ##### Workarounds Disable experimental Dynamic Client Registration and Client ID Metadata Documents features if they are not required. ##### References - [RFC 6749 Section 3.1.2 - Redirection Endpoint](https://datatracker.ietf.org/doc/html/rfc6749#section-3.1.2) #### Severity - CVSS Score: 5.9 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-wqvh-63mv-9w92](https://github.com/backstage/backstage/security/advisories/GHSA-wqvh-63mv-9w92) - [https://nvd.nist.gov/vuln/detail/CVE-2026-32235](https://nvd.nist.gov/vuln/detail/CVE-2026-32235) - [https://github.com/backstage/backstage/commit/6042dd0c7f0706e0f473dafa92799ecf19c825ec](https://github.com/backstage/backstage/commit/6042dd0c7f0706e0f473dafa92799ecf19c825ec) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-wqvh-63mv-9w92) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### @&#8203;backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass [CVE-2026-73563](https://nvd.nist.gov/vuln/detail/CVE-2026-73563) / [GHSA-38hq-7x33-php4](https://github.com/advisories/GHSA-38hq-7x33-php4) <details> <summary>More information</summary> #### Details ##### Impact The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in `@backstage/plugin-auth-backend` matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern such as `https://*.example.com/callback`, intended to allow subdomains of a trusted host, would also match an attacker-controlled URL such as `https://attacker.example/x.example.com/callback`. This applies to `auth.experimentalDynamicClientRegistration.allowedRedirectUriPatterns` as well as the `allowedClientIdPatterns` and `allowedRedirectUriPatterns` options of `auth.experimentalClientIdMetadataDocuments`. An attacker could use this to register an OAuth client whose redirect URI points to a host they control while still passing the allowlist, causing authorization codes to be delivered to the attacker when a victim completes an authorization flow. In addition, allowlist patterns without an explicit protocol could match URLs with any protocol, and redirect URIs containing embedded credentials (user:pass@host) were accepted after the credentials were stripped for matching. The practical impact is limited. Both features are experimental and disabled by default, and the default allowlist patterns only reference fixed or loopback hosts and are not affected. Deployments are only impacted if they enable one of these features and configure custom allowlist patterns that contain a wildcard in the hostname, or patterns without an explicit protocol. ##### Patches Patched in `@backstage/plugin-auth-backend` version `0.29.2`. Patterns are now matched against each URL component separately so that wildcards no longer match across the host and path boundary, patterns without an explicit protocol are rejected as invalid configuration, and redirect URIs with embedded credentials are always rejected. Note that as part of this fix, a wildcard port no longer implicitly matches every path: a pattern such as `http://localhost:*` now only matches the root path. Use `http://localhost:*/*` to allow any port and any path. ##### Workarounds Disable the experimental features by removing `auth.experimentalDynamicClientRegistration` and `auth.experimentalClientIdMetadataDocuments` from your `app-config`, which is the default configuration. Alternatively, restrict the configured allowlist patterns to fully specified URLs with an explicit protocol and no wildcard in the hostname, which are not affected by this vulnerability. #### Severity - CVSS Score: 4.7 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-38hq-7x33-php4](https://github.com/backstage/backstage/security/advisories/GHSA-38hq-7x33-php4) - [https://github.com/backstage/backstage/commit/274acc51d22a7dd919cdda49d9086cf12c0b8711](https://github.com/backstage/backstage/commit/274acc51d22a7dd919cdda49d9086cf12c0b8711) - [https://github.com/backstage/backstage/commit/6370e53bce8b227c63092300594ffde29c006886](https://github.com/backstage/backstage/commit/6370e53bce8b227c63092300594ffde29c006886) - [https://github.com/backstage/backstage/commit/ef606a85545cb6d765e20afd1ff43ae5407a3660](https://github.com/backstage/backstage/commit/ef606a85545cb6d765e20afd1ff43ae5407a3660) - [https://github.com/backstage/backstage/commit/fdc0d2dcd9a571e3839d7f5de4133c4e242a3a41](https://github.com/backstage/backstage/commit/fdc0d2dcd9a571e3839d7f5de4133c4e242a3a41) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) - [https://github.com/backstage/backstage/releases/tag/v1.53.0](https://github.com/backstage/backstage/releases/tag/v1.53.0) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-38hq-7x33-php4) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>backstage/backstage (@&#8203;backstage/plugin-auth-backend)</summary> ### [`v0.29.2`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0292) [Compare Source](https://github.com/backstage/backstage/compare/v0.29.1...v0.29.2) ##### Patch Changes - [`e2b3472`](https://github.com/backstage/backstage/commit/e2b3472): Promoted Client ID Metadata Documents (CIMD) to the stable `auth.clientIdMetadataDocuments` configuration. The previous `auth.experimentalClientIdMetadataDocuments` key remains supported as a deprecated alias. Dynamic Client Registration now logs a deprecation warning when enabled and users should migrate to CIMD. - [`2aeb246`](https://github.com/backstage/backstage/commit/2aeb246): Added token revocation support for clients using client ID metadata documents (CIMD). The `/v1/revoke` endpoint is now available whenever dynamic client registration or client ID metadata documents are enabled, and is advertised through `revocation_endpoint` in the OpenID provider configuration. - Updated dependencies - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.7.3 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.9.3 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.2.3 ### [`v0.29.1`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0291) [Compare Source](https://github.com/backstage/backstage/compare/v0.29.0...v0.29.1) ##### Patch Changes - Updated dependencies - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.9.2 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.7.2 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.2.2 ### [`v0.29.0`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0290) [Compare Source](https://github.com/backstage/backstage/compare/v0.28.0...v0.29.0) ##### Minor Changes - [`29d398b`](https://github.com/backstage/backstage/commit/29d398b): **BREAKING**: Hardened the default allowed patterns for CIMD and DCR to replace the previous permissive `['*']` wildcards with specific defaults for known MCP clients. If you previously relied on the default `['*']` patterns, you will need to explicitly configure the patterns you need in your `app-config.yaml`. **CIMD (`experimentalClientIdMetadataDocuments`):** - `allowedClientIdPatterns` now defaults to Claude, VS Code, and the built-in Backstage CLI instead of `['*']` - `allowedRedirectUriPatterns` now defaults to loopback addresses (localhost, 127.0.0.1, \[::1]) instead of `['*']` **DCR (`experimentalDynamicClientRegistration`):** - `allowedRedirectUriPatterns` now defaults to Cursor and loopback addresses instead of `['*']` If you need to allow additional clients or redirect URIs, you can override these defaults in your `app-config.yaml`: ```yaml auth: experimentalClientIdMetadataDocuments: enabled: true allowedClientIdPatterns: - 'https://claude.ai/*' - 'https://vscode.dev/*' - 'https://my-custom-client.example.com/*' allowedRedirectUriPatterns: - 'http://localhost:*' - 'http://127.0.0.1:*' - 'https://my-app.example.com/callback' experimentalDynamicClientRegistration: enabled: true allowedRedirectUriPatterns: - 'cursor://*' - 'http://localhost:*' - 'http://127.0.0.1:*' - 'myapp://*' ``` ##### Patch Changes - [`9f269d7`](https://github.com/backstage/backstage/commit/9f269d7): Limit the size of fetched client ID metadata documents to prevent oversized responses from being accepted. - [`3f5e7ec`](https://github.com/backstage/backstage/commit/3f5e7ec): Improved OIDC error messages to include the rejected redirect URI or client ID, making it easier to debug client registration failures. - [`e9b78e9`](https://github.com/backstage/backstage/commit/e9b78e9): Removed the `uuid` dependency and replaced usage with the built-in `crypto.randomUUID()`. - [`27f24a9`](https://github.com/backstage/backstage/commit/27f24a9): Refresh token usage now verifies that the user's catalog entity still exists before issuing a new access token. If the user has been removed from the catalog, the refresh is rejected and the session is revoked. Transient catalog errors reject the refresh but preserve the session for retry. This check can be disabled by setting `auth.experimentalRefreshToken.dangerouslyDisableCatalogPresenceCheck` to `true`. - [`4f62755`](https://github.com/backstage/backstage/commit/4f62755): Improved the OAuth consent dialog for MCP authorization by showing more client details, including the client metadata host for CIMD clients, the metadata URL, callback URL, and requested scopes. - Updated dependencies - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.9.0 - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.3.1 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.9.1 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.2.1 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.7.1 - [@&#8203;backstage/config](https://github.com/backstage/config)@&#8203;1.3.8 ### [`v0.28.0`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0280) [Compare Source](https://github.com/backstage/backstage/compare/61fa5087679777660e1b7a22e00d793fbb5d1691...v0.28.0) ##### Minor Changes - [`d7c67cd`](https://github.com/backstage/backstage/commit/d7c67cd): **BREAKING**: The setting `auth.omitIdentityTokenOwnershipClaim` has had its default value switched to `true`. With this setting Backstage user tokens issued by the `auth` backend will no longer contain an `ent` claim - the one with the user's ownership entity refs. This means that tokens issued in large orgs no longer risk hitting HTTP header size limits. To get ownership info for the current user, code should use the `userInfo` core service. In practice code will typically already conform to this since the `ent` claim has not been readily exposed in any other way for quite some time. But code which explicitly decodes Backstage tokens - which is strongly discouraged - may be affected by this change. The setting will remain for some time to allow it to be set back to `false` if need be, but it will be removed entirely in a future release. ##### Patch Changes - [`482ceed`](https://github.com/backstage/backstage/commit/482ceed): Migrated from `assertError` to `toError` for error handling. - [`dc87ac1`](https://github.com/backstage/backstage/commit/dc87ac1): Fixed CIMD redirect URI matching to allow any port for localhost addresses per RFC 8252 Section 7.3. Native CLI clients use ephemeral ports for OAuth callbacks, which are now accepted when the registered redirect URI uses a localhost address. - Updated dependencies - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.9.0 - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.3.0 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.7.0 - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.8.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.2.0 - [@&#8203;backstage/config](https://github.com/backstage/config)@&#8203;1.3.7 ### [`v0.27.3`](https://github.com/backstage/backstage/compare/7918ae477c7b98b77c79249836898b342e41df29...61fa5087679777660e1b7a22e00d793fbb5d1691) [Compare Source](https://github.com/backstage/backstage/compare/7918ae477c7b98b77c79249836898b342e41df29...61fa5087679777660e1b7a22e00d793fbb5d1691) ### [`v0.27.2`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0272) [Compare Source](https://github.com/backstage/backstage/compare/28d7852a8b1660a2f0d4ecbb586120aa4bc11b8c...7918ae477c7b98b77c79249836898b342e41df29) ##### Patch Changes - [`1ccad86`](https://github.com/backstage/backstage/commit/1ccad86): Added `who-am-i` action to the auth backend actions registry. Returns the catalog entity and user info for the currently authenticated user. - [`d0f4cd2`](https://github.com/backstage/backstage/commit/d0f4cd2): Added optional client metadata document endpoint at `/.well-known/oauth-client/cli.json` relative to the auth backend base URL for CLI authentication. Enabled when `auth.experimentalClientIdMetadataDocuments.enabled` is set to `true`. - [`6738cf0`](https://github.com/backstage/backstage/commit/6738cf0): build(deps): bump `minimatch` from 9.0.5 to 10.2.1 - [`e9b6e97`](https://github.com/backstage/backstage/commit/e9b6e97): Fixed a security vulnerability where the CIMD metadata fetch could follow HTTP redirects to internal hosts, bypassing SSRF protections. - [`0f9d673`](https://github.com/backstage/backstage/commit/0f9d673): Improved redirect URI validation in the experimental OIDC provider to match against normalized URLs rather than raw strings. - [`a49a40d`](https://github.com/backstage/backstage/commit/a49a40d): Updated dependency `zod` to `^3.25.76 || ^4.0.0` & migrated to `/v3` or `/v4` imports. - [`634eded`](https://github.com/backstage/backstage/commit/634eded): Fixed a foreign key constraint violation when issuing refresh tokens for CIMD clients, and prevented a failed refresh token issuance from failing the entire token exchange. Fixed AWS ALB auth provider incorrectly returning HTTP 500 instead of 401 for JWT validation failures, which caused retry loops and memory pressure under load. - [`619be54`](https://github.com/backstage/backstage/commit/619be54): Update migrations to be reversible - Updated dependencies - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.8.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.1.0 - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.7.7 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.14 ### [`v0.27.1`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0271-next2) [Compare Source](https://github.com/backstage/backstage/compare/v0.27.0...28d7852a8b1660a2f0d4ecbb586120aa4bc11b8c) ##### Patch Changes - [`d0f4cd2`](https://github.com/backstage/backstage/commit/d0f4cd2): Added optional client metadata document endpoint at `/.well-known/oauth-client/cli.json` relative to the auth backend base URL for CLI authentication. Enabled when `auth.experimentalClientIdMetadataDocuments.enabled` is set to `true`. - Updated dependencies - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.8.0-next.1 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.14-next.2 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.1.0-next.2 ### [`v0.27.0`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0270) [Compare Source](https://github.com/backstage/backstage/compare/v0.26.0...v0.27.0) ##### Minor Changes - [`31de2c9`](https://github.com/backstage/backstage/commit/31de2c9): Added experimental support for Client ID Metadata Documents (CIMD). This allows Backstage to act as an OAuth 2.0 authorization server that supports the [IETF Client ID Metadata Document draft](https://datatracker.ietf.org/doc/draft-ietf-oauth-client-id-metadata-document/). External OAuth clients can use HTTPS URLs as their `client_id`, and Backstage will fetch metadata from those URLs to validate the client. **Configuration example:** ```yaml auth: experimentalClientIdMetadataDocuments: enabled: true # Optional: restrict which `client_id` URLs are allowed (defaults to ['*']) allowedClientIdPatterns: - 'https://example.com/*' - 'https://*.trusted-domain.com/*' # Optional: restrict which redirect URIs are allowed (defaults to ['*']) allowedRedirectUriPatterns: - 'http://localhost:*' - 'https://*.example.com/*' ``` Clients using CIMD must host a JSON metadata document at their `client_id` URL containing at minimum: ```json { "client_id": "https://example.com/.well-known/oauth-client/my-app", "client_name": "My Application", "redirect_uris": ["http://localhost:8080/callback"], "token_endpoint_auth_method": "none" } ``` - [`d0786b9`](https://github.com/backstage/backstage/commit/d0786b9): Added experimental support for refresh tokens via the `auth.experimentalRefreshToken.enabled` configuration option. When enabled, clients can request the `offline_access` scope to receive refresh tokens that can be used to obtain new access tokens without re-authentication. ##### Patch Changes - [`7dc3dfe`](https://github.com/backstage/backstage/commit/7dc3dfe): Removed the `auth.experimentalDynamicClientRegistration.tokenExpiration` config option. DCR tokens now use the default 1 hour expiration. If you need longer-lived access, use refresh tokens via the `offline_access` scope instead. DCR clients should already have the `offline_access` scope available. Enable refresh tokens by setting: ```yaml auth: experimentalRefreshToken: enabled: true ``` - [`7455dae`](https://github.com/backstage/backstage/commit/7455dae): Use node prefix on native imports - Updated dependencies - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.0.0 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.7.0 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.13 ### [`v0.26.0`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0260) [Compare Source](https://github.com/backstage/backstage/compare/d03fd681a91928c65419df989d9fc4adef3a2dba...v0.26.0) ##### Minor Changes - [`7ffc873`](https://github.com/backstage/backstage/commit/7ffc873): Fix `user_created_at` migration causing `SQLiteError` regarding use of non-constants for defaults ##### Patch Changes - Updated dependencies - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.6.1 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.11 ### [`v0.25.7`](https://github.com/backstage/backstage/blob/HEAD/plugins/auth-backend/CHANGELOG.md#0257) [Compare Source](https://github.com/backstage/backstage/compare/cd79f31c8ccb6d611bac2cfb13a019a555132011...d03fd681a91928c65419df989d9fc4adef3a2dba) ##### Patch Changes - [`de96a60`](https://github.com/backstage/backstage/commit/de96a60): chore(deps): bump `express` from 4.21.2 to 4.22.0 - Updated dependencies - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.10 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.6.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;1.20.1 </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjI3MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSIsInNlY3VyaXR5IiwidHlwZS9taW5vciJdfQ==-->
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-backstage-plugin-auth-backend-vulnerability:renovate/npm-backstage-plugin-auth-backend-vulnerability
git switch renovate/npm-backstage-plugin-auth-backend-vulnerability

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/npm-backstage-plugin-auth-backend-vulnerability
git switch renovate/npm-backstage-plugin-auth-backend-vulnerability
git rebase main
git switch main
git merge --ff-only renovate/npm-backstage-plugin-auth-backend-vulnerability
git switch renovate/npm-backstage-plugin-auth-backend-vulnerability
git rebase main
git switch main
git merge --no-ff renovate/npm-backstage-plugin-auth-backend-vulnerability
git switch main
git merge --squash renovate/npm-backstage-plugin-auth-backend-vulnerability
git switch main
git merge --ff-only renovate/npm-backstage-plugin-auth-backend-vulnerability
git switch main
git merge renovate/npm-backstage-plugin-auth-backend-vulnerability
git push origin main
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/backstage-application!85
No description provided.