Skip to content

v4.0.0

Choose a tag to compare

@SAY-5 SAY-5 released this 08 Sep 23:31
· 40 commits to main since this release

Inbound secrets can be rotated without a cutover window. POST /sources/{source}/rotate issues a new secret (returned once) and keeps the previous one verifying until the overlap expires, after which it is rejected as an invalid signature; rotating again replaces the previous key so at most two are live. GET /sources shows rotation state without exposing secrets.

Replay detection now runs on a nonce store (Alembic 0003): every accepted signature is recorded before anything else, so re-sending a request whose first copy was deduplicated is rejected too, and the worker expires nonces after twice the timestamp window. Outbound keys rotate through destinations.yaml with previous_secret and key_id, which add X-Signature-Previous and X-Key-Id to every delivery. The smoke suite has a rotation check (15 checks); 128 tests.