Skip to content

Releases: mkrdnk/jam

v4.2.1

Choose a tag to compare

@mkrdnk mkrdnk released this 22 Sep 13:53

Added

Changed

  • Add lists support to SAML and Macaroons.

Fixed

  • Fix lists documentation.

Security

  • Update cryptography to 50.0.1.

v4.2.0

Choose a tag to compare

@mkrdnk mkrdnk released this 21 Sep 16:16

Added

  • Added first-class Macaroon credentials with explicit synchronous and
    asynchronous Jam.issue(..., via="macaroon") and
    Jam.authenticate(..., via="macaroon") flows.
  • Added a standalone jam.macaroons module with standard binary v2
    serialization, immutable attenuation, opaque and structured first-party
    caveats, third-party caveats, bound and nested discharge Macaroons, and
    compatibility with reference implementations.
  • Added built-in permission, condition, expires_at, and not_before
    caveats, plus an instance-owned CaveatRegistry for custom structured
    caveats.
  • Added generic AuthorizationConstraint, ConditionConstraint, and
    PermissionConstraint types. Authenticated principals now carry immutable
    credential constraints separately from root claims and permissions.
  • Added MACAROON-HMAC-SHA256 KeyChain support, including historical-key
    verification, rotation, revocation, Memory, and FileStorage.
  • Added Macaroon support to the Django credential adapters and documentation
    for configuration, attenuation, custom and opaque caveats, and discharge
    acquisition.
  • Added first-class SAML credentials to the synchronous and asynchronous
    facades through Jam.issue(..., via="saml") and
    Jam.authenticate(..., via="saml"). Facade authentication returns a
    Principal containing the verified assertion subject, attributes, and
    registered claims.
  • Added config-driven SAML construction and [jam.saml] facade assembly,
    including issuer and audience defaults, expected-issuer validation, custom
    modules, and direct config / pointer construction.
  • Added SAML KeyChain signing and verification with XML KeyInfo/KeyName,
    historical-key lookup, rotation, revocation, Memory, and FileStorage
    support.

Changed

  • Authorization internals now live in the jam.authz package with separate
    contracts, constraints, policy compilation, roots, and condition helpers.
    Existing from jam.authz import ... imports remain supported.
  • Credential constraints are evaluated before the configured authorization
    policy. They can only reduce authority; a custom policy cannot bypass a
    failing constraint or widen a Macaroon's root permissions.
  • Optional authentication modules are imported only when configured, allowing
    a Macaroon-only Jam instance to run without unrelated extras.
  • Macaroon verification now accepts serialized primary and discharge tokens
    only. The decoded Macaroon model remains available for attenuation and must
    be serialized again before verification.
  • SAML response issuance now supports per-credential lifetime, not-before, and
    assertion ID values through the facade's exp, nbf, and jti arguments.

Removed

  • Removed the unused internal version compatibility helper and the direct
    packaging dependency. cryptography is now Jam's only mandatory runtime
    dependency.
  • Remove CLAUDE.md file.

Fixed

  • Missing context data, references, malformed condition values, unsafe regular
    expressions, unsupported caveats, invalid timestamps, and runtime comparison
    mismatches now fail closed for credential constraints.
  • Django principal adaptation now preserves credential constraints.
  • Macaroon time boundaries now fail during authentication and remain mandatory
    authorization constraints. Configurable issuer, audience, and floating-point
    clock leeway checks are available in the Macaroon profile.
  • SAML public-key loading now accepts RSA private PEM material and derives its
    public key, allowing generated FileStorage KeyChains to verify assertions.

Security

  • Macaroon signatures and complete discharge graphs are verified before
    structured caveats or application satisfiers are invoked.
  • Added strict canonical parsing and configurable limits for serialized size,
    caveat payloads, total caveat count, discharge count, and discharge depth.
  • SAML facade authentication fails closed for unsuccessful responses, missing
    subject assertions, invalid signatures, issuer or audience mismatches,
    expired or not-yet-valid assertions, replayed message IDs, and revoked keys.
  • Structured Macaroon satisfiers receive deeply immutable JSON values, so
    callbacks cannot change the signed caveat represented by verification
    results.
  • Added an internal NaCl-compatible XSalsa20-Poly1305 SecretBox implementation
    for third-party caveat keys without an additional runtime dependency.
    Poly1305 tags are verified before plaintext is returned. The Salsa20
    implementation is pure Python and is not suitable when local or
    high-resolution timing attackers are in scope.

v4.2.0a1

v4.2.0a1 Pre-release
Pre-release

Choose a tag to compare

@mkrdnk mkrdnk released this 21 Sep 12:11

Added

  • Added first-class Macaroon credentials with explicit synchronous and
    asynchronous Jam.issue(..., via="macaroon") and
    Jam.authenticate(..., via="macaroon") flows.
  • Added a standalone jam.macaroons module with standard binary v2
    serialization, immutable attenuation, opaque and structured first-party
    caveats, third-party caveats, bound and nested discharge Macaroons, and
    compatibility with reference implementations.
  • Added built-in permission, condition, expires_at, and not_before
    caveats, plus an instance-owned CaveatRegistry for custom structured
    caveats.
  • Added generic AuthorizationConstraint, ConditionConstraint, and
    PermissionConstraint types. Authenticated principals now carry immutable
    credential constraints separately from root claims and permissions.
  • Added MACAROON-HMAC-SHA256 KeyChain support, including historical-key
    verification, rotation, revocation, Memory, and FileStorage.
  • Added Macaroon support to the Django credential adapters and documentation
    for configuration, attenuation, custom and opaque caveats, and discharge
    acquisition.

Changed

  • Authorization internals now live in the jam.authz package with separate
    contracts, constraints, policy compilation, roots, and condition helpers.
    Existing from jam.authz import ... imports remain supported.
  • Credential constraints are evaluated before the configured authorization
    policy. They can only reduce authority; a custom policy cannot bypass a
    failing constraint or widen a Macaroon's root permissions.
  • Optional authentication modules are imported only when configured, allowing
    a Macaroon-only Jam instance to run without unrelated extras.
  • Macaroon verification now accepts serialized primary and discharge tokens
    only. The decoded Macaroon model remains available for attenuation and must
    be serialized again before verification.

Deprecated

Removed

  • Removed the unused internal version compatibility helper and the direct
    packaging dependency. cryptography is now Jam's only mandatory runtime
    dependency.

Fixed

  • Missing context data, references, malformed condition values, unsafe regular
    expressions, unsupported caveats, invalid timestamps, and runtime comparison
    mismatches now fail closed for credential constraints.
  • Django principal adaptation now preserves credential constraints.
  • Macaroon time boundaries now fail during authentication and remain mandatory
    authorization constraints. Configurable issuer, audience, and floating-point
    clock leeway checks are available in the Macaroon profile.

Security

  • Macaroon signatures and complete discharge graphs are verified before
    structured caveats or application satisfiers are invoked.
  • Added strict canonical parsing and configurable limits for serialized size,
    caveat payloads, total caveat count, discharge count, and discharge depth.
  • Structured Macaroon satisfiers receive deeply immutable JSON values, so
    callbacks cannot change the signed caveat represented by verification
    results.
  • Added an internal NaCl-compatible XSalsa20-Poly1305 SecretBox implementation
    for third-party caveat keys without an additional runtime dependency.
    Poly1305 tags are verified before plaintext is returned. The Salsa20
    implementation is pure Python and is not suitable when local or
    high-resolution timing attackers are in scope.

v4.2.0a0

v4.2.0a0 Pre-release
Pre-release

Choose a tag to compare

@mkrdnk mkrdnk released this 21 Sep 10:50

Added

  • Added first-class Macaroon credentials with explicit synchronous and
    asynchronous Jam.issue(..., via="macaroon") and
    Jam.authenticate(..., via="macaroon") flows.
  • Added a standalone jam.macaroons module with standard binary v2
    serialization, immutable attenuation, opaque and structured first-party
    caveats, third-party caveats, bound and nested discharge Macaroons, and
    compatibility with reference implementations.
  • Added built-in permission, condition, expires_at, and not_before
    caveats, plus an instance-owned CaveatRegistry for custom structured
    caveats.
  • Added generic AuthorizationConstraint, ConditionConstraint, and
    PermissionConstraint types. Authenticated principals now carry immutable
    credential constraints separately from root claims and permissions.
  • Added MACAROON-HMAC-SHA256 KeyChain support, including historical-key
    verification, rotation, revocation, Memory, and FileStorage.
  • Added Macaroon support to the Django credential adapters and documentation
    for configuration, attenuation, custom and opaque caveats, and discharge
    acquisition.

Changed

  • Authorization internals now live in the jam.authz package with separate
    contracts, constraints, policy compilation, roots, and condition helpers.
    Existing from jam.authz import ... imports remain supported.
  • Credential constraints are evaluated before the configured authorization
    policy. They can only reduce authority; a custom policy cannot bypass a
    failing constraint or widen a Macaroon's root permissions.
  • Optional authentication modules are imported only when configured, allowing
    a Macaroon-only Jam instance to run without unrelated extras.

Deprecated

Removed

  • Removed the unused internal version compatibility helper and the direct
    packaging dependency. cryptography is now Jam's only mandatory runtime
    dependency.

Fixed

  • Missing context data, references, malformed condition values, unsafe regular
    expressions, unsupported caveats, invalid timestamps, and runtime comparison
    mismatches now fail closed for credential constraints.
  • Django principal adaptation now preserves credential constraints.

Security

  • Macaroon signatures and complete discharge graphs are verified before
    structured caveats or application satisfiers are invoked.
  • Added strict canonical parsing and configurable limits for serialized size,
    caveat payloads, total caveat count, discharge count, and discharge depth.
  • Added an internal NaCl-compatible XSalsa20-Poly1305 SecretBox implementation
    for third-party caveat keys without an additional runtime dependency.
    Poly1305 tags are verified before plaintext is returned. The Salsa20
    implementation is pure Python and is not suitable when local or
    high-resolution timing attackers are in scope.

v4.1.3

Choose a tag to compare

@mkrdnk mkrdnk released this 18 Sep 16:08

Added

  • Added aauthorize() for non-blocking permission checks in asynchronous
    Django Modern REST controllers.
  • Added source="session" as an explicit session-only mode for
    JamSyncAuth and JamAsyncAuth.

Changed

  • DMR authorization helpers now preserve an existing resource when resource
    is omitted and allow it to be cleared explicitly with resource=None.
  • DMR OpenAPI output now rejects auth instances with no enabled mechanism and
    documents custom session-header prefixes and cookie-session CSRF responses.
  • Updated the 4.1.3 documentation and README links for the current
    documentation layout, including valid serializer-backed DMR controllers.

Fixed

  • Fixed DMR examples that used serializer-free controllers for Python return
    values or imported decorators from an unsupported module.
  • Clarified Bearer-or-Session configuration so OpenAPI describes alternative
    authentication methods instead of requiring both.

Security

  • Jam Session credentials read from cookies now enforce Django CSRF validation
    for unsafe requests in synchronous and asynchronous DMR controllers.

v4.1.2

Choose a tag to compare

@mkrdnk mkrdnk released this 18 Sep 12:44

Fixed

  • Fix documentation routing.

v4.1.1

Choose a tag to compare

@mkrdnk mkrdnk released this 18 Sep 11:34

Fixed

  • Build workflows
  • Linter workflows

v4.1.0

Choose a tag to compare

@mkrdnk mkrdnk released this 18 Sep 11:23

Added

  • Integration with django jam.ext.django:
    • Django-native auth perms
    • Mixins
    • Templates permissions
    • Django REST framework (drf) integration
    • Django modern REST (dmr) integration
  • Added more logs hooks.

Fixed

  • Fix keychain docs

v4.1.0b0

v4.1.0b0 Pre-release
Pre-release

Choose a tag to compare

@mkrdnk mkrdnk released this 18 Sep 10:42

Added

  • Integration with django jam.ext.django:
    • Django-native auth perms
    • Mixins
    • Templates permissions
    • Django REST framework (drf) integration
    • Django modern REST (dmr) integration
  • Added more logs hooks

v4.1.0a3

v4.1.0a3 Pre-release
Pre-release

Choose a tag to compare

@mkrdnk mkrdnk released this 18 Sep 07:55

Added

  • Integration with django jam.ext.django:
    • Django-native auth perms
    • Mixins
    • Templates permissions
    • Django REST framework (drf) integration
    • Django modern REST (dmr) integration