Skip to content

1.0.0-beta6

Choose a tag to compare

@hexblot hexblot released this 04 Oct 20:57
· 13 commits to main since this release
Immutable release. Only release title and notes can be modified.
1.0.0-beta6
14c88fb

Added

  • ServerConfig::problems(array $settings): what is wrong with a set of
    settings, in plain sentences, without constructing anything, for a host's
    status page on an install that is not configured yet. The constructor
    throws the first of them.
  • tools/consumer-smoke.php and a CI job that installs the package into an
    empty project without development dependencies and exercises the runtime.
  • Server\Deprecations logs, at notice level, every deprecated term an
    object carries when it is created or revised, as the compatibility guide
    promised.

Changed

  • ActionRequests::create() queues the Pending notification before
    dispatching ActionRequestCreated, and every decision queues its
    notification before its event, so a listener that decides a request
    synchronously cannot put its decision's notification ahead of the state it
    decided; create() and every decision return the stored request, which a
    listener may have advanced. DataHolder::change() and the holder's HTTP
    change path no longer decide a request a creation listener already decided;
    ChangeFailed is also thrown when such a listener rejected it
    (adversarial review 7, R7-001).

  • An integral xsd:double is written as an explicit value object, since a
    JSON number without a fraction reads back as xsd:integer in any JSON-LD
    processor; the client uses the package encoder (R7-002).

  • The expander applies a term's datatype coercion to native numbers and
    booleans, and an explicit value object without @language is a plain
    string under a default language (R7-003). A term definition never expands
    a document-relative @id (R7-004).

  • JWT time claims are NumericDate with their fraction or an absolute RFC 3339
    instant with a zone; anything else present is refused with
    JwtException::INVALID_CLAIM rather than read as absent (R7-005).

  • A posted logistics event may name only the object it is posted on in
    cargo:eventFor, however many values and in any order (R7-006).

  • Changes validate literals by each datatype's own grammar and against the
    property's range, as the checked builder does (R7-007).

  • DeliveryVerdict rejects a request PSR-18 reports as unusable
    (RequestExceptionInterface) instead of retrying it (R7-008).

  • The token endpoint refuses two client authentication methods in one
    request and repeated form parameters with invalid_request (R7-009).

  • Services validates against the newest configured data model version
    (ServerConfig::validationModel()), as the configuration documented; a
    server configured for 3.2 alone refuses 3.3-only terms (D7-001).

  • Claims::expiresAt(), notBefore() and issuedAt() return ?float
    instead of ?int
    , so a fractional NumericDate keeps its fraction. A
    consumer that needs whole seconds decides its own rounding, for example
    (int) floor($claims->expiresAt()) before DateTimeImmutable::setTimestamp();
    under strict_types passing the float directly is a TypeError.

  • DataHolder::subscribe() honours a creation listener's decision instead of
    accepting a second time (R8-001). Range checks follow XSD derivation
    (Rdf\Xsd): an xsd:int satisfies an xsd:integer range, any integer or
    decimal type satisfies a double, and bounded integer types are checked
    against their bounds; the builder and the change applier share the rules
    (R8-002). A native number or boolean under an @id-coerced term expands to
    the value it is rather than being refused (R8-003). The JWT verifier
    compares claims against the clock with its fraction (R8-004), refuses a
    present null or malformed nbf/iat, and validates the hour, minute,
    second and offset ranges of an RFC 3339 claim before parsing it (R8-005).

  • ActionRequestStore::save() states its envelope: the server saves a
    request once and moves it on with transition(); a later save() under
    the same IRI may replace status, history and errors, while type, payload,
    objects, requester and request time are fixed by the first save. The
    contract no longer asks a store to move a re-saved request to another
    object (beta5's test is withdrawn), since the SDK never does that and two
    hosts' query columns had been caught between the two readings (Laravel
    integration review, round 3).

  • AccessDelegation keeps each permission, delegate and logistics object
    once, in order, so a store projecting one row per (request, object) never
    sees a repeat.