Skip to content

Release v4.0.0

Choose a tag to compare

@gsalingu gsalingu released this 20 Apr 23:49
· 83 commits to main since this release
4360833

BREAKING CHANGE

  • Removed impl FromRequestParts for OrgId. The bare axum extractor allowed tenant-confusion — a client holding a valid token for org A could send X-Org-Id: <org B> and land at a handler that wrote to org B with org A's principal. Handlers must take OrganizationContext exclusively, which reconciles token claims, the X-Org-Id header, and any path parameter.

Added

  • OrgId::try_from_headers(&http::HeaderMap) -> Result<OrgId, OrgIdHeaderError> (feature http) — non-extractor parser for callers without an AuthLayer (webhook verifiers, out-of-band tooling).
  • OrgIdHeaderError with Missing, NotUtf8, Invalid variants.
  • examples/header_parser.rs demonstrating the sanctioned non-axum usage.

Migration

// Before (rejected — tenant-confusion loophole):
async fn handler(org_id: OrgId) { /* writes to org_id without reconciling auth */ }

// After:
async fn handler(ctx: OrganizationContext) {
    let org_id = ctx.org_id;
    // ctx also carries the authenticated Principal, RequestId, roles, and attestation.
}