Skip to content

Releases: Oire/Iridium-php

Version 3.2

Choose a tag to compare

@Menelion Menelion released this 20 Sep 23:18
503de36

Changes

  • Mac, message authentication with a shared key: HMAC-SHA256, returned as URL-safe Base64.
    Until now the only thing a SharedKey could do was encrypt. Every MAC is made under a required
    context, and the MAC key is derived from the shared key with HKDF-SHA256 under that context,
    so one key can serve Crypt and any number of MAC purposes without one being able to forge for
    another.
  • KeyRing, a map from key ID to SharedKey for rotation, when old and new clients call the
    same server for a while. KeyRing::fromPairs() reads pairs straight from configuration and
    skips a slot that is not filled rather than holding an empty key: a MAC under an empty key can
    be forged by anyone, which is an easy mistake to make with an unused "previous key" variable.
  • Request signing: Request\RequestSigner and Request\RequestVerifier authenticate a whole
    HTTP request — method, path, timestamp and body — without ever sending the secret, which suits a
    credential both sides hold (a secret built into an app, or shared between two services) where a
    SplitToken, being a bearer token, does not. They take and return plain strings, so there is no
    framework dependency and no fixed header names. The verifier reports why it refused through the
    RequestVerificationFailure enum, meant for the log, never for the response. The acceptance
    window is 300 seconds by default; there is no nonce, which the README states plainly.
  • Test vectors for clients in other languages, computed outside PHP:
    tests/fixtures/request-signing-vectors.json. The signed string and the key derivation are
    specified in the README.

Nothing existing changes: this release only adds classes.

Version 3.0

Choose a tag to compare

@Menelion Menelion released this 02 Mar 22:24
Immutable release. Only release title and notes can be modified.
b88b207

What's Changed

Breaking Changes 🛠

  • Set minimum PHP version to 8.3 and update copyright by @Menelion in #95
  • Dockerize local development and CI by @Menelion in #99
  • Modernize code, add AES-256-GCM encryption, fix bugs by @Menelion in #100
  • Change license to Apache 2.0, update copyright to mention Oire Software by @Menelion in #98

Other Changes

Full Changelog: v2.0...v3.0

Version 2.0

Choose a tag to compare

@Menelion Menelion released this 20 Apr 21:54
v2.0
ce17d6a

What's Changed

Breaking Changes 🛠

Full Changelog: v1.2...v2.0

Version 1.2

Choose a tag to compare

@Menelion Menelion released this 11 Dec 15:42
v1.2
ea5cb63

What's Changed

New Features 🎉

Full Changelog: v1.1...v1.2

Version 1.1

Choose a tag to compare

@Menelion Menelion released this 03 Jul 19:00
d3ed8b0

What's Changed

Full Changelog: v1.0...v1.1

Version 1.0

Choose a tag to compare

@Menelion Menelion released this 03 Jul 18:54
v1.0
31aae5a

Initial release

Full Changelog: https://github.com/Oire/Iridium-php/commits/v1.0