Skip to content

5.0.0

Latest

Choose a tag to compare

@Ks89 Ks89 released this 27 May 22:11
8942d00

Features

  • Added separate GitHub OAuth flows for web and mobile clients, including dedicated routes, handlers, client configuration, callback handling, and refresh/logout behavior.
  • Added PKCE-based OAuth security with high-entropy state values, one-time mobile app codes, and app-state round-tripping for mobile login validation.
  • Added persisted, opaque refresh tokens with HMAC hashing, rotation, family revocation on reuse, transactional updates, and separate web/mobile refresh flows.
  • Added stronger API token storage using hashed lookup values and AES-GCM encrypted token storage.
  • Added database indexes for refresh tokens, mobile app login codes, and GitHub profile uniqueness.
  • Added support for multiple allowed GitHub login emails via LIMIT_TO_USER_EMAILS.

Bugfixes And Security Fixes

  • Hardened startup validation for JWT, cookie, OAuth, API-token, and production CORS configuration.
  • Tightened JWT validation, enforced access-token usage, fixed signing to HS512, and required web JWT identity to match the authenticated session.
  • Reduced sensitive logging, removed plaintext API token exposure, avoided Gin default request logging, and added request body size limits.
  • Fixed mobile refresh, web refresh cookie scoping, OAuth callback cleanup, and refresh-token logout revocation behavior.
  • Improved internal service reliability with bounded HTTP calls, status checks, path escaping, correct request contexts, and safer MongoDB transaction boundaries.
  • Fixed profile API token rotation so updated credentials propagate to profiles, sensors, controllers, online state, and FCM mappings.

Go Improvements

  • Refactored authentication, OAuth, JWT, PKCE, cookie, random, and session logic into clearer, more idiomatic Go modules.
  • Cleaned up common correctness issues around error handling, context usage, type assertions, cursor cleanup, loop variables, deferred resources, timestamp handling, and ObjectID comparisons.

Test Improvements

  • Hardened make test with protobuf generation, vet, shadow checks, staticcheck, race-enabled tests, and coverage generation.
  • Added startup validator unit coverage for valid configuration, missing OAuth secrets, short cookie secrets, and production CORS refusal.