Current issue state, recent activity, and per-issue timelines from the indexed issue data.
| Date | Opened | Closed | Comments | Events | Open Backlog |
|---|---|---|---|---|---|
| 2026-09-21 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-20 | 1 | 0 | 2 | 6 | 35 |
| 2026-09-19 | 1 | 0 | 0 | 0 | 0 |
| 2026-09-18 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-17 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-16 | 1 | 0 | 0 | 0 | 0 |
| 2026-09-15 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-14 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-13 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-12 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-11 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-10 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-09 | 1 | 0 | 0 | 0 | 0 |
| 2026-09-08 | 0 | 0 | 0 | 0 | 0 |
Opened: 3
Closed: 0
Comments: 2
Events: 6
| Issue | Author | State | Labels | Comments | Reactions | Updated |
|---|---|---|---|---|---|---|
#1845 Support `private_key_jwt` in CIMD Opened 26 days ago | ewjoachim | open - reopened | enhancement | 5 | 0 | 8 hours ago |
#1857 CIMD ignores token_endpoint_auth_methods_supported and rejects usable clients Opened 8 hours ago | flaviovl | open | bug | 0 | 0 | 8 hours ago |
#1855 CIMD: a metadata document is rejected when it declares an extra grant_type the server doesn't support Opened 1 day ago | flaviovl | open | bug | 1 | 0 | 23 hours ago |
#1853 CIMD applications don't get algorithm set Opened 4 days ago | cfra | open | bug | 0 | 0 | 4 days ago |
#1851 Serve up /o/token instead of redirecting it even if `APPEND_SLASH` is True Opened 11 days ago | mlissner | open | No labels | 1 | 0 | 11 days ago |
#1702 oauth2_settings.AUTHENTICATION_SERVER_EXP_TIME_ZONE violates specification Opened 4 months ago | dopry | open | bug | 3 | 0 | 12 days ago |
#1773 Remove JSONOAuthLibCore (deprecated in 3.4.1) Opened 2 months ago | dopry | open | No labels | 4 | 0 | 12 days ago |
#1716 Hash user tokens, refresh tokens and grants in the DB Opened 3 months ago | ewjoachim | open | enhancement | 9 | 0 | 16 days ago |
#1805 DOT is now vibe-coded/slopware – alternatives/forks? Opened 2 months ago | Natureshadow | closed - not_planned | No labels | 6 | 0 | 18 days ago |
#1843 3.4.1 update not functional on Oracle Opened 27 days ago | msmitherdc | open | bug | 3 | 0 | 19 days ago |
#1731 DCR: allowlist settings for registration metadata (grant_types, token_endpoint_auth_method, redirect_uris) Opened 3 months ago | dopry | open | enhancement | 3 | 0 | 19 days ago |
#1846 RFC 9207: MUST include iss on error response Opened 24 days ago | ewjoachim | open | bug | 0 | 0 | 24 days ago |
#1844 Store and use logo_uri, client_uri, tos_uri, policy_uri, contacts from CIMD Opened 26 days ago | ewjoachim | open | enhancement | 0 | 0 | 26 days ago |
#1756 Deploy check for OAUTH2_RESPONSE_TYPES_SUPPORTED entries the server can never accept (response_type order-independence) Opened 2 months ago | dopry | open | No labels | 1 | 0 | 28 days ago |
#984 Oauth2 Throttle class for Client Credentials Opened 5 years ago | nico-deforge | closed - completed | enhancement | 0 | 3 | 30 days ago |
#1453 fix test.mig_settings for OIDC migrations and swappable dependencies? Opened 2 years ago | n2ygk | closed - completed | bug | 0 | 0 | 30 days ago |
#753 Skip auth form if valid refresh token exists? Opened 7 years ago | madprime | open | enhancement | 6 | 0 | 30 days ago |
#1746 e2e: add cross-site hosts + Firefox to test third-party-cookie impacts Opened 2 months ago | dopry | closed - completed | enhancement | 1 | 0 | 30 days ago |
#1098 OAuth 2.0 BCP -> OAuth 2.1 Opened 5 years ago | n2ygk | open | enhancement | 1 | 1 | 30 days ago |
#490 Allow custom redirect_uri validator for AbstractApplication Opened 9 years ago | alvingonzales | closed - completed | enhancement | 3 | 4 | 30 days ago |
#483 token_expires_in method of oauthlib.Server is ignored by DOT Opened 9 years ago | petrdanecek | closed - completed | enhancement | 4 | 0 | 30 days ago |
#657 Use of Content-Type "application/x-www-form-urlencoded" not enforced Opened 8 years ago | marcofucci | closed - completed | enhancement | 4 | 0 | 30 days ago |
#1828 bug: log.exception() misused in two resource-server paths (+ implicit return in the introspection client) Opened 1 month ago | dopry | closed - completed | bug | 0 | 0 | 1 month ago |
#1786 Policy setting: allow a refresh token to survive access-token revocation (4.x) Opened 2 months ago | dopry | open | enhancement | 0 | 0 | 1 month ago |
#1782 Natively support CORS on the OIDC UserInfo endpoint Opened 2 months ago | dopry | closed - completed | No labels | 0 | 0 | 1 month ago |