Releases: EUDIPLO/eudiplo
Releases · EUDIPLO/eudiplo
Release list
v9.0.0
9.0.0 (2026-10-05)
- Fix OIDF FAPI2 conformance coverage (#1079) (446e875)
- fix(authorization)!: bound refresh tokens, enforce S256 for interactive authorization, honor built-in token settings (#1135) (42cfbdb), closes #1104
- fix(authorization)!: verify DPoP proofs, require PKCE for every authorization code, bind codes to their grant and verify interactive authorization (#1143) (500f50d)
- fix(issuance)!: call external and upstream authorization servers under the outbound URL policy (#1157) (def2051)
- fix(platform)!: fail closed on broken TLS configuration and clean up repository tooling (#1140) (b98cc00)
- fix(registrar)!: match registration certificate claims by path and add SKIP_* flags (#1097) (474e249)
- fix(security)!: protect key material and KMS secrets, enforce key attestation requirements and federation trust (#1146) (d5dca08)
- fix(session)!: enforce session expiry at request time and count sessions from the database (#1127) (03b2591), closes #1120 #1123 #1120 #1123
- fix(session)!: scope session access by role and fix the session event stream (#1145) (21c667e), closes #1142 #820 #820 #1141
- fix(status-list)!: reject values that do not fit the list, make revocation final and restrict status changes to issuance roles (#1142) (a83e1b5)
- fix(storage)!: replace MinIO with RustFS across deployments (#1075) (57d70a6)
- fix(trust)!: derive DCQL aki values from listed issuers and renew managed trust lists (#1134) (ed0bbe9)
- fix(trust)!: fetch trust lists, status lists, federation entities and CRLs under the outbound URL policy (#1155) (af23b1d)
- fix(verifier)!: enforce DCQL claim values in OpenID4VP presentations (#1148) (4b1d728)
- fix(verifier)!: report failed presentations to webhooks, classify mDOC failures and finish SSE streams (#1133) (f50c3a2)
Bug Fixes
- verifier: accept wallet error responses with HTTP 200 and record them on the session (#1112) (950ae62)
- storage: allow S3 credentials to be omitted for IRSA/instance-profile auth (#1073) (89088d2)
- database: bootstrap fresh schemas through migrations (#1072) (74d83f3)
- trust: bound the status list caches (#1159) (2f454a0), closes #1155
- trust: clear the federation trust cache from the cache endpoints (#1105) (5af1761)
- security: enforce outbound URL policy on schema metadata fetches and remove ReDoS-prone regex (#1109) (7a6b13b)
- issuance: enforce PKCE with S256 on the chained authorization servers (#1104) (2bf496f)
- config-import: follow symlinked tenant folders during discovery (#1107) (5cca3ed)
- improve protocol debugging logs (#1077) (b992728)
- issuance: keep mDOC signed date within the signing certificate validity (#1113) (5c8a904)
- move to the EUDIPLO organization and LF Decentralized Trust (#1161) (d3706be)
- issuance: open OID4VP wallet request via tap instead of bare redirect (#1098) (672625e)
- deployment: pin the bundled PostgreSQL to 16 in the Compose files (#1139) (3c4fbcd), closes #1129
- client: preserve array child wildcard paths during credential config nesting (#1071) (66cc9c9)
- verifier: require non-empty vp_token entries and enforce DCQL multiple (#1106) (4e47fd9)
- client: require status management for Single Active Credential and default built-in token lifetime to 300 s (#1144) (fb37ece)
- issuance: resolve notification sessions like the credential endpoint and validate activeCredentials in the API (#1138) (545119e)
- webhook: return mandatory mDL claims from the example claims webhook (#1111) (6eb6376)
- issuance: send presented credentials to the attribute provider (#1108) (0c0759d)
- database: store the session OAuth expiry columns as timestamp on PostgreSQL (#1151) (728e41e)
- issuance: treat children of array claim fields as item properties (#1099) (53974dc), closes #1080
- sdk,cli: use the /api prefix where the backend serves it and await the stored request object (#1141) (05183ed)
- client: use the logged-in instance URL after an SSO login (#1118) (e8b8571), closes #1076
- security: verify CRLs against the issuing CA before trusting them ...
v8.1.0
8.1.0 (2026-09-24)
Bug Fixes
- add PAT for auto queue function (#1069) (a9f319d)
- cli: honour --no-wait on Kubernetes restart (#1052) (5da6b85)
- observability: initialize OpenTelemetry before NestJS (#1066) (030af68)
Features
- cli: add Compose ps, restart, logs options and open with Podman coverage (#1051) (d5396a9)
- cli: add Compose pull and upgrade commands (#1060) (97e12cf)
- align with German sandbox (#1068) (c041b28)
- client: guide users through credential, issuance, and presentation setup with step-by-step wizards (#1048) (3b6a116)
- load-test: support self-hosted targets (#1058) (5c9708a)
- verifier: support x509_san_dns client IDs (#1057) (12e3bbc)
This release is also available on:
v8.1.0- npm package (@latest dist-tag)
v8.1.0
v8.0.2
8.0.2 (2026-09-20)
Bug Fixes
- publish release attestations and address scorecard findings (#1045) (e9e4e6b)
- cli: resolve bundled template asset paths (#1042) (3c48429)
- restrict config portability bundle role assignment (#1044) (0055fa0)
This release is also available on:
v8.0.2- npm package (@latest dist-tag)
v8.0.2
v8.0.1
v7.6.1
v7.6.0
7.6.0 (2026-09-08)
Bug Fixes
- load testing (#1008) (4715689)
- migrate backend to native ESM (#1000) (59d53ab)
- remove mocked wallet trust list from OIDF issuance tests (#1009) (3b2a9e7)
- status-list: serialise write transactions on SQLite (#976) (#999) (a1457ff)
- backend: update root endpoint documentation url and add response dto (#995) (de18e63)
Features
- oid4vci: add caching and deduplication for authorization server metadata and federation trust (#834) (#998) (1885065)
- client: add configurable dashboard views (#993) (9807e41)
- cli: complete registered instance names (#996) (cc08b13)
This release is also available on:
v7.6.0- npm package (@latest dist-tag)
v7.6.0
v7.5.0
7.5.0 (2026-09-04)
Bug Fixes
- accept presentation registration certificate fields (#989) (68a7f6c)
- docs: fall back to the Algolia placeholders on an empty secret (#971) (e154c77)
- harden Kubernetes deployment profiles (#990) (b63ab87)
- upgrade to NestJS 12 (CommonJS) and fold in pending dependency updates (#988) (57c64a0)
Features
- issuance: enforce active-credential limit per subject (#843) (#975) (0178f22)
- client: improve light and dark theme support (#969) (4956556)
- session: persist a structured verification outcome (#974) (3cb222a)
- docs: replace Algolia classic search with DocSearch v5 + Ask AI (#986) (58b9e7d)
- verifier: structured verification failure with a shared taxonomy (#970) (00c612a)
- verifier: support TS12 SCA transaction data (#992) (925aad4)
This release is also available on:
v7.5.0- npm package (@latest dist-tag)
v7.5.0
v7.4.0
v7.3.0
7.3.0 (2026-08-26)
Bug Fixes
- db: add the session columns that no migration ever created (#955) (adf8d90), closes #894
- webhook: allow presentation:manage to manage webhook endpoints (#957) (b7bac52)
- implement optimistic concurrency control for Status List operations (#950) (343725f)
- iso18013: read meta.doctype_value, the field the schema allows (#954) (fb5d4cb)
- release workflow (#963) (a913e99)
Features
- cli: add setup cookbook and podman runtime support (#949) (5fdd9ce)
- config: add versioned configuration portability (#953) (20c3901)
- config: validate TLS env vars and de-duplicate config/CLI docs tooling (#960) (766caef)
This release is also available on:
v7.3.0- npm package (@latest dist-tag)
v7.3.0
v7.2.0
7.2.0 (2026-08-19)
Features
This release is also available on:
v7.2.0- npm package (@latest dist-tag)
v7.2.0