0.4.0
Pre-release
Pre-release
Added
- Schema validation during decrypt/extract paths in JmixDecryptor
- Validates manifest.json, metadata.json, and audit.json against schemas
- Clear, aggregated error messages on validation failure
- Payload hash verification improvements
- Encrypted envelopes: verify SHA-256 of payload.encrypted
- Unencrypted envelopes: recompute structured directory hash for payload/
- Assertion verification enhancements
- Expiration handling and invalid-signature detection
- CLI support:
jmix-decrypt analyze --verify-assertionsprints verification summary
- Configurable schema path
- Library: pass custom schema directory to
new JmixBuilder($schemaPath)andnew JmixDecryptor($schemaPath) - CLI: optional 4th arg to
jmix-buildto set schema directory - Default schema path resolves to a sibling repo:
../jmix/schemas
- Library: pass custom schema directory to
- JWS manifest signing (optional)
JwsHandlerto create/verify EdDSA (Ed25519) JWS for manifest.json- When configured,
manifest.jwsis written alongsidemanifest.jsonand referenced inmanifest.security.jws
- Samples for tests and demos:
/samplesfolder for CLI and PHPUnit
Changed
- Documentation: README updated for schema path configuration, JWS signing, and CLI assertion verification
- Minor CLI output polish in analyze/build commands
Testing
- 43 PHPUnit tests covering builder, decryptor, assertions, encryption, and JWS