v5.0.7
tinyauthapp/tinyauthv5.0.7Apr 17, 2026by steveiliop56
AI Summary
This is the final release under the previous username, focusing on OpenID Connect enhancements and Envoy proxy compatibility before the project moves to the new organization.
Key Highlights
- Final release under previous username
- OpenID Connect PKCE support
- Envoy proxy 307 redirects
- Server-side CSRF state storage
- X-Tinyauth-Location header for Nginx
New Features
- OpenID Connect PKCE support
- User info endpoint POST request support
- Access token in POST request body support
- Unsigned OpenID Connect request objects
- X-Tinyauth-Location header for Nginx
Full Release Notes
# Tinyauth v5.0.7 Hello everyone! This is officially the last release under my username. After this last patch, Tinyauth will move to its new home [tinyauthapp](https://github.com/tinyauthapp), no breaking changes for now. As for this release, it addresses some further issues with the Envoy proxy and improves the OpenID Connect experience. ## Improvements - The OpenID Connect server now supports PKCE - The OpenID Connect user information endpoint now supports POST requests @scottmckendry - The OpenID Connect user information endpoint now supports the access token in the POST request body @scottmckendry - The OAuth flow now supports the OpenID Connect parameters and stores CSRF states server-side for anti-tampering - Add `X-Tinyauth-Location` header for Nginx instances to support redirect to login and unauthorized pages automatically - Support unsigned OpenID Connect request objects @scottmckendry - Accessibility improvements ## Fixes - Use 307 redirects for Envoy proxy - Fix TOTP field auto-fill not working in some password managers @scottmckendr ## Technical - Update dependencies - Update translations - Use own fork of the [paerser](https://github.com/tinyauthapp/paerser) library for better flexibility in configuration parsing - Fail app early when the app URL is missing Please let us know of any issues so we can address them as soon as possible. **Full Changelog**: https://github.com/steveiliop56/tinyauth/compare/v5.0.6...v5.0.7