Releases: genyleap/openproof
Releases · genyleap/openproof
Release list
OpenProof 1.1.0-rc4
Farcaster profile bootstrap
- Farcaster SIWF presentation metadata now seeds missing canonical profile fields after the signed identity proof is verified, so first-time Farcaster users receive their display name, preferred username and avatar automatically.
- Provider presentation refreshes remain display-only: they do not import email or phone ownership claims, and existing user-chosen canonical name, username and picture values are preserved.
- Added migration
0019_farcaster_profile_seed.sqlto backfill empty canonical profile fields from already stored Farcaster connection metadata without overwriting populated profile values.
Upgrade
sudo openproof upgrade --version 1.1.0-rc4Full Changelog: v1.1.0-rc3...v1.1.0-rc4
v1.1.0-rc3
OpenProof 1.1.0-rc2
Fixed
- Fixed duplicate canonical identities when a user first authenticated through a trusted federated provider and later enrolled local email/password with the same verified email. OpenProof now converges onto the single active canonical identity instead of creating a second account.
- Verified-email convergence now fails closed when that email maps ambiguously to multiple active identities, or belongs to a suspended/non-authenticating identity, rather than guessing an owner.
- Completing signup email verification now establishes an IAL1 browser session, removing the unnecessary second sign-in immediately after proving control of the address. The OpenAPI response now includes
session_idandassurance.
Documentation and developer tooling
- Added the end-to-end Deployment & Developer Handbook for installation, production configuration, OAuth/OIDC, Node.js, PHP, C++ and generic HTTP integration.
- Added machine-readable LLM documentation surfaces and the public, read-only OpenProof documentation MCP server with reproducible source.
Full Changelog: v1.1.0-rc1...v1.1.0-rc2
v1.1.0-rc1
What's Changed
- Improve account sessions and provider profile refresh by @thecompez in #1
- Fix/account session profile sync by @thecompez in #2
- Add multi-chain mobile wallet authentication by @thecompez in #3
- Restore federated conflict handling and document WalletConnect integration by @thecompez in #4
- Add hardened Postfix verification delivery adapter by @thecompez in #5
- Enable verified email sign-in management by @thecompez in #6
- Fix OpenAPI gate and Linux GCC toolchain by @thecompez in #7
- Support Apple OIDC form-post callbacks by @thecompez in #8
- Document federated provider environment setup by @thecompez in #9
- Enable one-time recovery codes for local MFA by @thecompez in #10
- Avoid GitGuardian password false positives by @thecompez in #11
- feat: add self-service TOTP enrollment and recovery codes by @thecompez in #12
- fix: require TOTP for recovery code issuance by @thecompez in #13
- feat: harden external OIDC providers by @thecompez in #14
- fix: preserve Apple first-login profile name by @thecompez in #15
- fix: encode OIDC basic client credentials by @thecompez in #16
- fix: bound enterprise LDAP operations by @thecompez in #17
- fix: validate SAML HTTPS endpoints by @thecompez in #18
- feat: enrich OIDC profile display names by @thecompez in #19
- fix: validate GitHub HTTPS callback URLs by @thecompez in #20
- fix: bind passkey RP IDs to origins by @thecompez in #21
- fix: validate Web3 RPC HTTPS endpoints by @thecompez in #22
- fix: sanitize Web3 presentation metadata by @thecompez in #23
- fix: normalize OIDC profile claims by @thecompez in #24
- fix: normalize enterprise presentation claims by @thecompez in #25
- fix: validate LDAP URI and base DN by @thecompez in #26
- fix: enforce local subject invariant by @thecompez in #27
- fix: make passkey auth challenges single-use by @thecompez in #28
- fix: enforce siwe challenge expiry by @thecompez in #29
- fix: harden Web3 authentication challenges by @thecompez in #30
- fix: make enterprise authentication challenges single-use by @thecompez in #31
- fix: make redirect authentication challenges single-use by @thecompez in #32
- fix: keep provider challenge handling cluster-safe by @thecompez in #33
- fix: make local authentication cluster-safe by @thecompez in #34
New Contributors
- @thecompez made their first contribution in #1
Full Changelog: https://github.com/genyleap/openproof/commits/v1.1.0-rc1