Stable release · npm
latest
npm install -g titen-memory@0.10.0Install guide · Release page · npm package
Added
- Optional WebAuthn passkeys now protect dashboard accounts on Cloudflare and
Bun/SQLite with exact RP ID and origin verification. - First passkey enrollment returns eight recovery codes once. Profile can list,
revoke, and add passkeys or replace the recovery set. - The dashboard completes passkey assertions through fixed same-origin routes.
A real browser WebAuthn test uses a virtual authenticator. - A public-artifact release gate rejects private deployment identifiers in the
source tree and generated package assets.
Changed
- Migration 24 adds persistent login throttles, explicit API-key authentication
stages, WebAuthn credentials and challenges, and recovery generations. - Password login now applies progressive SQL-backed delays before verification.
The fifth failure waits 30 seconds. Later delays reach at most 30 minutes. - Accounts with passkeys receive a 15-minute staged key until passkey or
recovery verification creates a full dashboard session. - Dashboard sessions are no longer part of credential portability exports.
- Account-specific Cloudflare configuration and private runtime evidence are no
longer part of the public repository or npm release surface.
Security
- Login throttle rows store only a hashed account bucket and bounded timing
state. Passwords and submitted usernames do not enter throttle storage. - Challenges bind to organization, account, session, purpose, and expiry.
Conditional SQL claims prevent challenge and recovery-code replay. - First passkey enrollment revokes older dashboard sessions. Removing the last
passkey requires the current password. - Staged keys have no product scopes. Central route authorization permits only
the required password-change or second-factor completion operations.