Skip to content

v0.6.0

Latest

Choose a tag to compare

@github-actions github-actions released this 15 Sep 17:33
de16739

0.6.0 (2026-09-15)

⚠ BREAKING CHANGES

  • service: TERMS_URL, TERMS_SHARED_SECRET and TERMS_TIMEOUT_MS are ESIGN_PREFILL_URL, ESIGN_PREFILL_SECRET and ESIGN_PREFILL_TIMEOUT_MS, and the callback header is x-esign-prefill-secret (was x-esign-terms-secret). SESSION_JWKS_URL, SESSION_ISSUER, SESSION_AUDIENCE, SESSION_USER_CLAIM, MOCK_PAGES, MOCK_PAGES_ORIGIN, TRUST_PROXY, RATE_LIMIT_*PER_MIN and CORS_ALLOWED_ORIGINS gain the ESIGN prefix. SESSION_HS256_SECRET is ESIGN_SESSION_SECRET and the JWT_SECRET alias is removed with no replacement. The exported terms names are the prefill names: createTermsPrefill is createPrefillHook, createEnvelopeTerms is createEnvelopePrefillHook, termsConfigFromEnv is prefillConfigFromEnv, TermsError is PrefillError, TermsConfig/TermsDeps/EnvelopeTermsDeps are PrefillConfig/PrefillDeps/ EnvelopePrefillDeps, EnvelopeAppTermsInput is EnvelopeAppPrefillInput, and src/terms.ts is src/prefill.ts. docs/integration/locked-terms{,-envelopes}.md are locked-prefill{,-envelopes}.md.

Features

  • service: envelope mint, direct signing from templates with no Web Form (#96) (5165023)
  • service: report the deployment posture instead of refusing it, and one naming convention (#106) (ba9ba6f)

Bug Fixes

  • node: derive the mock pages origin from ESIGN_PORT_BASE (#104) (acd2af8)
  • node: stop CodeQL flagging the JWT grant, by fixing the aud claim it misread (#108) (a8551cf)