Releases: faustbrian/go-http-signature
Release list
github.com/faustbrian/go-http-signature v1.0.0
1.0.0 - 2026-08-25
Fixed
- Invoke comparison benchmarks directly from their owning module and resolve
its stable root-module requirement from the current standalone source.
Changed
-
Upgrade cryptography dependencies in comparison and differential modules to
the current security-fixed release. -
Exclude intentional nested modules from root local-proxy archives so local,
bootstrap, CI, and public module checksums describe the same source
boundary. -
Track the pinned documentation-tool lockfile so clean CI checkouts install
the exact validated cspell dependency. -
Reconcile standalone dependency checksums against deterministic current
module archives so CI, local verification, and release consumers resolve
identical content. -
Harden standalone documentation validation with deterministic spelling and
link checks, package-specific documentation gates, and repository-local
contributor guidance.
Fixed
- Prove escaped quoted-string scanning before repairing a following integral
RFC 8941 Decimal, killing the previously surviving conditional mutant.
Documentation
- Link the package README to the repository-wide Golib documentation portal.
Added
- Add an auditable RFC 8941, RFC 9421, and RFC 9530 specification decision
register with explicit compatibility and security consequences. - Add isolated equivalent request sign-and-verify benchmarks against pinned
yaronf/httpsignanddadrus/httpsig, with separate correctness proof,
repeated samples, environment capture, and documented policy-cost
differences. - Convert Structured Fields dependency panics on hostile extension syntax into
typed parse failures across signature, digest, and canonicalization entry
points. - Combine multiple Structured Field lines with the RFC-mandated comma and space
before parsing, reject leading horizontal tabs outside RFC 8941
optional-whitespace positions, and retain the required fractional zero when
canonicalizing integral Decimal values. - Add isolated compatibility
RoundTripperand verification middleware seams
for Cavage drafts, AWS SigV4, OAuth 1.0, and explicitly named vendor schemes;
outbound callbacks cannot replace request identity or RFC 9421 signature
fields, and inbound callback mutations cannot reach later RFC verification. - Add streaming response digest/signature trailers with canonical application
declarations, bounded authenticated late-trailer support, fail-closed
protocol constraints, and client-side verification that waits for EOF before
releasing response content. - Make buffered response signing inherit outer ordinary headers with normal
handler replacement semantics and reject handler-managed transfer or trailer
framing, protocol switching, and successfulCONNECTbefore signing. - Fail streaming adapters on zero-progress body readers and reject protocol
switching where digest/signature trailers cannot complete. - Preserve application trailer values populated at EOF across buffered request
digest generation and verification without losing caller-declared framing. - Prevent streaming request downgrade by forcing supported HTTP/1 attempts to
chunk even empty bodies, preserving and authenticating only predeclared EOF
trailers, rejecting early responses andCONNECT, and refusing profiles that
cover transport-dependent connection or framing fields. - Clear handler-injected protected response trailers on every late streaming
failure, omit mutable TLS state from verification callback snapshots, and
report signed buffered-response short, invalid, or failed writes once through
a redacted late diagnostic path. - Add deterministic RFC 9530 SHA-256 and SHA-512 integrity-field generation,
strict byte-sequence parsing, immutable ordered values, and policy-selected
constant-time verification. - Add ordered RFC 9530 integrity-preference parsing and serialization with
strict integer weights, duplicate rejection, and unknown-algorithm retention. - Add explicit and default-bounded parser resource limits across signature,
digest, and negotiation fields. - Bound complete signature-base canonicalization by default and permit a
stricter per-message ceiling. - Bind transport-owned Host, content-length, transfer-encoding, trailer, and
connection components to deterministicnet/httpwire state, including
method- and status-sensitive zero-length request and response emission,
exact transfer-coding spelling and order, and response body-probe ambiguity,
with an explicit received-versus-Response.Writetransport mode that rejects
ambiguous zero-value contexts, unavailable inbound trailer identity, and
stale outbound header aliases. - Reject noncanonical or multi-line Cookie coverage and require binary wrapping
for multiple Set-Cookie field lines to prevent transformation collisions. - Add strict ordered parsing for
Signature-InputandSignature, rejecting
duplicate labels, wrong Structured Fields member types, duplicate covered
component identifiers, and RFC 9651-only values outside RFC 8941. - Preserve RFC 8941 Item parameters on
Signature,Content-Digest, and
Repr-Digestmembers instead of rejecting legal extensions. - Add ordered
Accept-Signatureparsing and serialization with distinct
Boolean creation and expiration request semantics. - Add request signature-base construction for registered derived components,
header and trailer selection, field combination, explicit external request
context, request-response component binding, and Structured Fields modes. - Add all active IANA signature algorithms with exact RFC encodings, strict key
compatibility, Go-managed cryptographically secure RSA-PSS and ECDSA
randomness, cancellation, and secret-safe typed verification failures;
retain the former caller-random inputs as ignored compatibility parameters so
weak or blocking readers cannot affect signing. - Add explicit verification profiles with mandatory coverage, parameter,
algorithm, time, tag, key-resolution, cache-freshness, and nonce policy. - Reject zero-length verification-key validity windows even when configured
clock skew would otherwise make the instant appear acceptable. - Add explicit signing profiles and context-bounded rotating-key providers that
create deterministic matching field pairs without mutating messages or
consuming bodies. - Add profile-level mandatory trusted external request context that fails
before signing-provider or verification-resolver access. - Reject trusted external-origin contexts whose scheme or authority
contradicts an absolute-form request target. - Preserve double-slash origin-form paths and reject request-target fragments,
user information, opaque targets, and absolute targets without authority. - Reconstruct authority-form and asterisk-form target URIs with an empty
path/query while retaining the normalized/value for@path, and reject
special forms used with the wrong method. - Normalize authority ports numerically so leading-zero default ports are
omitted and other ports have a stable decimal representation. - Reject authority values containing query, fragment, or opaque URI data.
- Add explicit outbound signing round-tripper and inbound verification
middleware adapters with caller-owned label selection, trusted external
request context, failure mapping, existing-field policy, and body ownership. - Add bounded fail-closed response-signing middleware and a response-verifying
round-tripper with request-response binding, authenticated digest coverage,
callback isolation, transparent-decompression rejection, and replayable
verified bodies; buffered digest and trailer paths reject 101 and successful
CONNECTbefore reading opaque protocol or tunnel bytes. - Match body suppression for
HEAD, 204, 205, and 304 when signing responses,
including rejecting RFC-forbidden 205 handler content and digesting only
content actually emitted. - Add explicit bounded Content-Digest round-tripper and verification
middleware with caller-body closure, replayable clones, and no partial
delegation after size or digest failure. - Add a bounded streaming request adapter that computes Content-Digest while
the transport reads, then signs the declared digest trailer at EOF without
falsely advertising replayability. - Add eager inbound trailer verification that waits for EOF, checks the
bounded content digest, authenticates a profile-required trailer component,
and only then delegates a replayable body. - Fail buffered body processing closed when releasing caller-owned body
resources fails, without exposing the underlying close error. - Add an atomic bounded process-local replay store and a context-aware durable
replay adapter contract with fail-closed capacity and backend semantics. - Pin the RFC texts, errata records, and relevant IANA registries with explicit
decisions for every currently listed erratum.
Changed
- Publish the module from its standalone
github.com/faustbrian/go-http-signatureidentity while preserving its documented API and behavior. - Breaking:
ResponseSigningMiddlewareConfig.ReportErroris now required.
Callers must provide a concurrency-safe callback that records redacted late
output failures;MapErrorremains responsible only for failures that can be
mapped before response commitment.
Release integrity
- Source commit:
490c6455b1921d63bfd690b6b4c5b70051e15255 - Exact-head CI: https://github.com/faustbrian/go-http-signature/actions/runs/32907455679
- Release dry-run: urn:sha256:325c0eb64ec91796126dd325279c8b877407498b397b804e336205fb964939a7
- Assets include a CycloneDX SBOM, SLSA v1 in-toto provenance, and SSH-signed checksums.
Verify the checksum attestation with:
`ssh-keygen -Y verify -f A...