Releases: Oire/Iridium-php
Releases · Oire/Iridium-php
Release list
Version 3.2
Changes
Mac, message authentication with a shared key: HMAC-SHA256, returned as URL-safe Base64.
Until now the only thing aSharedKeycould do was encrypt. Every MAC is made under a required
context, and the MAC key is derived from the shared key with HKDF-SHA256 under that context,
so one key can serve Crypt and any number of MAC purposes without one being able to forge for
another.KeyRing, a map from key ID toSharedKeyfor rotation, when old and new clients call the
same server for a while.KeyRing::fromPairs()reads pairs straight from configuration and
skips a slot that is not filled rather than holding an empty key: a MAC under an empty key can
be forged by anyone, which is an easy mistake to make with an unused "previous key" variable.- Request signing:
Request\RequestSignerandRequest\RequestVerifierauthenticate a whole
HTTP request — method, path, timestamp and body — without ever sending the secret, which suits a
credential both sides hold (a secret built into an app, or shared between two services) where a
SplitToken, being a bearer token, does not. They take and return plain strings, so there is no
framework dependency and no fixed header names. The verifier reports why it refused through the
RequestVerificationFailureenum, meant for the log, never for the response. The acceptance
window is 300 seconds by default; there is no nonce, which the README states plainly. - Test vectors for clients in other languages, computed outside PHP:
tests/fixtures/request-signing-vectors.json. The signed string and the key derivation are
specified in the README.
Nothing existing changes: this release only adds classes.
Version 3.0
What's Changed
Breaking Changes 🛠
- Set minimum PHP version to 8.3 and update copyright by @Menelion in #95
- Dockerize local development and CI by @Menelion in #99
- Modernize code, add AES-256-GCM encryption, fix bugs by @Menelion in #100
- Change license to Apache 2.0, update copyright to mention Oire Software by @Menelion in #98
Other Changes
- Bump phpunit/phpunit from 11.5.6 to 11.5.7 by @dependabot[bot] in #96
- Bump friendsofphp/php-cs-fixer from 3.68.5 to 3.69.0 by @dependabot[bot] in #97
- Bump actions/checkout from 4 to 6 by @dependabot[bot] in #101
Full Changelog: v2.0...v3.0
Version 2.0
What's Changed
Breaking Changes 🛠
- Upgrade PHP to support 8.2 and 8.3 only; Remove CaptainHook by @Menelion in #93
- SplitToken: Move to private constructor model by @Menelion in https://github.com/Oire/Iridium-php/pull/94### Other Changes
- Change default token expiration time to 1 hour by @Menelion in #76
Full Changelog: v1.2...v2.0
Version 1.2
Version 1.1
Version 1.0
Initial release
Full Changelog: https://github.com/Oire/Iridium-php/commits/v1.0