hydra · Issues· 98 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #4130
serve.admin.request_log.disable_for_health has no effect: health paths missing /admin prefix in exclusion list
Needs TriageUpdated Sep 14, 2026 - #4026
Add Janitor removing expired tokens by client_secret_expires_at
featstaleUpdated Sep 13, 2026 - #4127
Support localhost redirection with arbitrary port
featUpdated Sep 9, 2026 - #4061
Support "Client ID Metadata Document" (CIMD)
featUpdated Sep 9, 2026 - #4126
Accepting login challenge with `remember: true, remember_for: 0` creates cookie with 30-day expiration
bugUpdated Sep 8, 2026 - #4091
Post Quantum Roadmap
featUpdated Aug 27, 2026 - #3990
Support JWKS_URI for trust grant issuer
featstaleUpdated Aug 22, 2026 - #3132
Cannot force front/back-channel logout with id_token_hint when "Remember Me" is off
bugUpdated Aug 5, 2026 - #4118
Device verification GET query parameters are not propagated to the authorization request
Needs TriageUpdated Jul 30, 2026 - #3740
Assertions may be reused & dead lock
bugUpdated Jul 30, 2026 - #4113
SetClientAssertionJWT inline DELETE on hydra_oauth2_jti_blacklist causes lock contention and latency spikes under concurrent load
bugUpdated Jul 30, 2026 - #3829
Incorrect Handling of Scopes with Special Character "|" in scp Claim
bugUpdated Jul 30, 2026 - #3742
Add `prompt=create` alias for `prompt=registration`
featbacklogUpdated Jul 30, 2026 - #3622
Opentelemetry spans names have changed when changed tracing_provider
bugUpdated Jul 30, 2026 - #4044
Allow setting default values for optional DCR values
featbacklogUpdated Jul 30, 2026