Skip to content

Releases: blinkbitcoin/esign

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 15 Sep 17:33
de16739

0.6.0 (2026-09-15)

⚠ BREAKING CHANGES

  • service: TERMS_URL, TERMS_SHARED_SECRET and TERMS_TIMEOUT_MS are ESIGN_PREFILL_URL, ESIGN_PREFILL_SECRET and ESIGN_PREFILL_TIMEOUT_MS, and the callback header is x-esign-prefill-secret (was x-esign-terms-secret). SESSION_JWKS_URL, SESSION_ISSUER, SESSION_AUDIENCE, SESSION_USER_CLAIM, MOCK_PAGES, MOCK_PAGES_ORIGIN, TRUST_PROXY, RATE_LIMIT_*PER_MIN and CORS_ALLOWED_ORIGINS gain the ESIGN prefix. SESSION_HS256_SECRET is ESIGN_SESSION_SECRET and the JWT_SECRET alias is removed with no replacement. The exported terms names are the prefill names: createTermsPrefill is createPrefillHook, createEnvelopeTerms is createEnvelopePrefillHook, termsConfigFromEnv is prefillConfigFromEnv, TermsError is PrefillError, TermsConfig/TermsDeps/EnvelopeTermsDeps are PrefillConfig/PrefillDeps/ EnvelopePrefillDeps, EnvelopeAppTermsInput is EnvelopeAppPrefillInput, and src/terms.ts is src/prefill.ts. docs/integration/locked-terms{,-envelopes}.md are locked-prefill{,-envelopes}.md.

Features

  • service: envelope mint, direct signing from templates with no Web Form (#96) (5165023)
  • service: report the deployment posture instead of refusing it, and one naming convention (#106) (ba9ba6f)

Bug Fixes

  • node: derive the mock pages origin from ESIGN_PORT_BASE (#104) (acd2af8)
  • node: stop CodeQL flagging the JWT grant, by fixing the aud claim it misread (#108) (a8551cf)

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 22:55
a86ffb5

0.5.0 (2026-09-11)

Features

  • node: locked prefill and multi-document signing for template envelopes (#91) (82de337)

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 22:46
00a980f

0.4.0 (2026-09-10)

The production release of the backend: one library for hosts that mint in-process, one
service that runs from environment alone as a function or a container, and a runbook by
role. Migration notes: docs/upgrading.md; operations:
docs/operations/production.md.

⚠ Breaking changes

  • Package rename: @blinkbitcoin/esign-server is now @blinkbitcoin/esign-node
    (packages/esign-node), platform-named like esign-react / esign-react-native.
    No aliases: update every import, including the /docusign, /express and /knex
    subpaths. (#83, 97e55a3)
  • The service is a package and its image is renamed: examples/full-service-demo
    is now packages/esign-service (@blinkbitcoin/esign-service, published); the image
    ghcr.io/blinkbitcoin/esign-api is now ghcr.io/blinkbitcoin/esign-service. (#83)
  • The service is no longer an Express app. createApp() is gone; the entry points
    are createESignApp(env, deps) (Fetch) and startServer(env) on
    @blinkbitcoin/esign-service/node. The container command is node dist/node.js,
    migrations are node dist/node.js migrate (was dist/migrate.js). express,
    helmet, cors and express-rate-limit are no longer dependencies. (#86, 302ab25)
  • ESIGN_ENV=production replaces NODE_ENV=production as the production switch
    (GraphQL introspection off; demo DocuSign hosts and the mock provider refused unless
    ESIGN_ALLOW_DEMO=true; a client's own prefill refused unless
    ESIGN_ALLOW_CLIENT_PREFILL=true). The image sets ESIGN_ENV=production itself; a
    non-container deployment that relied on NODE_ENV must set it. (#84, #86)
  • Boot checks moved earlier and changed shape: DOCUSIGN_HMAC_KEY and
    DOCUSIGN_TEMPLATE_ID are required only when envelope orchestration is on; a mint
    requires DOCUSIGN_WEBFORM_ID and DOCUSIGN_RETURN_URL at provider selection;
    validateSecurityConfig() is validateConfig(env, { runtime }). (#84, #86)

Features

  • node: production guard (ESIGN_ENV, ESIGN_ALLOW_DEMO), hosted-form boot checks
    (HOSTED_FORM_SETTINGS, incl. the return URL that used to fail silently), private key
    from DOCUSIGN_PRIVATE_KEY_BASE64 / DOCUSIGN_PRIVATE_KEY_FILE,
    hostedFormProviderFromEnv, and two presets that serve the mint, the return-URL
    bridge and /health: createHostedFormRouter (Express) and createHostedFormApp
    (Fetch), with a prefill hook so the host computes locked terms from its own data;
    a hook rejects with Errors.validationError → 400. (#84, e621645)
  • service: one deployable for the mint and the full envelope orchestration,
    capability by environment: the mint is always on, DATABASE_URL adds /graphql,
    POST /webhook/esign and the Knex store. Entries for Node (the image, in-memory rate
    limits, TRUST_PROXY), Vercel and Cloudflare Workers (mint only). Session
    verification via SESSION_JWKS_URL or SESSION_HS256_SECRET (JWT_SECRET stays an
    alias). Locked terms via a TERMS_URL callback (TERMS_SHARED_SECRET,
    TERMS_TIMEOUT_MS; plaintext refused in production unless private or
    TERMS_ALLOW_INSECURE=true). Deploy templates for Compose, Kubernetes, Vercel,
    Cloudflare and NixOS ship in the package; /health reports the capabilities that
    are on. (#86, 302ab25)
  • demo: the mint-only demo builds, ships a Dockerfile and uses the hosted-form router (#85) (aad60ca)

Documentation

  • The production runbook by role (DocuSign go-live, backend, DevOps, mobile, verification,
    failure modes), a "who are you" router and a backend-options table in the README, and
    the architecture docs and diagrams redrawn for the two tiers. (#87, 0ecf631)

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 09 Sep 21:36
db20ec4

0.3.0 (2026-09-09)

Features

  • demo: lock server-minted Web Forms prefill and verify it live (#72) (2968341)
  • link the homepage and issue tracker from the published packages (#64) (371617b)
  • server: esign-server package, server examples, live DocuSign verification and hardening (#73) (338407a)

v0.2.0

Choose a tag to compare

@grimen grimen released this 04 Sep 20:18
a990939

Two new integration paths next to the drop-in component, in both @blinkbitcoin/esign-react and @blinkbitcoin/esign-react-native:

  • Themed: theme, styles and labels props on ESignature recolor and relabel the built-in screens. Defaults are unchanged, so existing integrations render byte-identical.
  • Headless: useESignature exposes the signing state machine (status, sign, webViewProps) so a host app can draw every screen itself and hand the props to its own WebView or iframe.

No breaking changes; all existing props and testIDs keep working. @blinkbitcoin/esign-core is republished unchanged at 0.2.0 so the three packages stay in lockstep. Install notes: docs/integration/consuming.md.

Since 0.1.0 the CI pipeline was also reworked (staged Checks → Unit → E2E, iOS simulator suite on every run, CodeQL) — none of that ships in the packages.

What's Changed

Changes

  • ci: ship a release only once the commit's main run is green by @grimen in #25
  • ci(e2e): make the iOS simulator suite opt-in, default off by @grimen in #32
  • ci(e2e): run the Android emulator on the AOSP image by @grimen in #26
  • ci(e2e): drop the temporary 5x Android soak matrix by @grimen in #34
  • ci(e2e): key the native app build caches on native inputs by @grimen in #29
  • ci(e2e): build the native apps in their own jobs and hand the emulator jobs an artifact by @grimen in #30
  • ci: stage the pipeline - Checks, then Unit, then E2E by @grimen in #35
  • chore: rename repo blink-esign -> esign by @grimen in #36
  • ci: skip Unit and E2E on docs-only PRs by @grimen in #37
  • ci(e2e): move inline shell into scripts/e2e and scripts/ci by @grimen in #38
  • ci: move publish, release-gate and gh-pages shell into scripts by @grimen in #39
  • ci: move the docs-freshness, diagram and change-class shell into scripts by @grimen in #40
  • fix(ci): resolve registry smoke packages from the install dir by @grimen in #42
  • docs: keep README table first columns on one line by @grimen in #45
  • docs: keep the integration mode names on one line in the README table by @grimen in #47
  • docs: require a git worktree for branch work in the agent instructions by @grimen in #46
  • fix(e2e): bound the Android Maestro step and keep logcat on a hang by @grimen in #44
  • ci: add CodeQL analysis workflow by @grimen in #49
  • ci(e2e): build the E2E APK for x86_64 only and persist the Gradle build cache by @grimen in #43
  • fix(demo): regenerate Podfile.lock for react-native 0.86.3 by @grimen in #51
  • ci: npm ci --prefer-offline wherever the npm cache is restored by @grimen in #53
  • build: settle the eslint peer conflict so npm ci makes no registry request; ci: no per-job audit, 60s fetch-timeout by @grimen in #54
  • fix: resolve the CodeQL security-and-quality alerts by @grimen in #55
  • ci(e2e): build the iOS E2E app for the host simulator architecture only by @grimen in #50
  • ci: give the dependency audit its own fetch-timeout by @grimen in #56
  • ci: build the packages once in E2E; Web tests it, Publish ships it by @grimen in #57
  • fix(api): suppress false-positive CodeQL password-hash alert on JWT signing by @grimen in #58
  • ci: run iOS E2E by default by @grimen in #59
  • ci(e2e): take Homebrew Postgres off the iOS job's critical path by @grimen in #61
  • ci(e2e): start the iOS test database in the background by @grimen in #62
  • feat: headless useESignature hook and ESignature theming for RN and web by @grimen in #60

Full Changelog: v0.1.0...v0.2.0

v0.1.0

Choose a tag to compare

@grimen grimen released this 02 Sep 18:23
7c3bd08

Initial public feature set: provider-agnostic ESignature component (React Native WebView + React web iframe/DocuSign.js) over a shared SigningSource core with three modes — public URL, DocuSign Web Forms instances, and proxy envelopes (Apollo). Apollo-free /webform subpath entries for minimal Web Forms-only consumers.

Packages (GitHub Packages, @blinkbitcoin scope): esign-core, esign-react-native, esign-react — all 0.1.0. Install notes: docs/integration/consuming.md.

What's Changed

Changes

  • fix(e2e): launch the app once per Maestro run; reset in-app instead of relaunching by @grimen in #15
  • ci(e2e): cache native app builds and the Android system image, retry per Maestro flow by @grimen in #8
  • ci: render the README coverage badge from measured coverage by @grimen in #16
  • ci(e2e): build the iOS app for the generic simulator destination by @grimen in #17
  • docs: title-case the Coverage and License badges by @grimen in #18
  • ci: cancel in-flight runs when a PR is closed or merged by @grimen in #19
  • ci: make the registry smoke assert what GitHub Packages can deliver by @grimen in #20
  • ci: one pipeline per branch so every badge is correct for its branch by @grimen in #21
  • ci: unit and E2E status badges per branch, rendered from the job results by @grimen in #22
  • ci: combined HTML coverage report as a run artifact; drop the badge JSON by @grimen in #23
  • ci: one-step releases - the Git tag is the version by @grimen in #24

New Contributors

Full Changelog: https://github.com/blinkbitcoin/blink-esign/commits/v0.1.0