Releases: mkrdnk/jam
Releases · mkrdnk/jam
Release list
v4.2.1
v4.2.0
Added
- Added first-class Macaroon credentials with explicit synchronous and
asynchronousJam.issue(..., via="macaroon")and
Jam.authenticate(..., via="macaroon")flows. - Added a standalone
jam.macaroonsmodule with standard binary v2
serialization, immutable attenuation, opaque and structured first-party
caveats, third-party caveats, bound and nested discharge Macaroons, and
compatibility with reference implementations. - Added built-in
permission,condition,expires_at, andnot_before
caveats, plus an instance-ownedCaveatRegistryfor custom structured
caveats. - Added generic
AuthorizationConstraint,ConditionConstraint, and
PermissionConstrainttypes. Authenticated principals now carry immutable
credential constraints separately from root claims and permissions. - Added
MACAROON-HMAC-SHA256KeyChain support, including historical-key
verification, rotation, revocation,Memory, andFileStorage. - Added Macaroon support to the Django credential adapters and documentation
for configuration, attenuation, custom and opaque caveats, and discharge
acquisition. - Added first-class SAML credentials to the synchronous and asynchronous
facades throughJam.issue(..., via="saml")and
Jam.authenticate(..., via="saml"). Facade authentication returns a
Principalcontaining the verified assertion subject, attributes, and
registered claims. - Added config-driven
SAMLconstruction and[jam.saml]facade assembly,
including issuer and audience defaults, expected-issuer validation, custom
modules, and directconfig/pointerconstruction. - Added SAML KeyChain signing and verification with XML
KeyInfo/KeyName,
historical-key lookup, rotation, revocation,Memory, andFileStorage
support.
Changed
- Authorization internals now live in the
jam.authzpackage with separate
contracts, constraints, policy compilation, roots, and condition helpers.
Existingfrom jam.authz import ...imports remain supported. - Credential constraints are evaluated before the configured authorization
policy. They can only reduce authority; a custom policy cannot bypass a
failing constraint or widen a Macaroon's root permissions. - Optional authentication modules are imported only when configured, allowing
a Macaroon-only Jam instance to run without unrelated extras. - Macaroon verification now accepts serialized primary and discharge tokens
only. The decodedMacaroonmodel remains available for attenuation and must
be serialized again before verification. - SAML response issuance now supports per-credential lifetime, not-before, and
assertion ID values through the facade'sexp,nbf, andjtiarguments.
Removed
- Removed the unused internal version compatibility helper and the direct
packagingdependency.cryptographyis now Jam's only mandatory runtime
dependency. - Remove CLAUDE.md file.
Fixed
- Missing context data, references, malformed condition values, unsafe regular
expressions, unsupported caveats, invalid timestamps, and runtime comparison
mismatches now fail closed for credential constraints. - Django principal adaptation now preserves credential constraints.
- Macaroon time boundaries now fail during authentication and remain mandatory
authorization constraints. Configurable issuer, audience, and floating-point
clock leeway checks are available in the Macaroon profile. - SAML public-key loading now accepts RSA private PEM material and derives its
public key, allowing generatedFileStorageKeyChains to verify assertions.
Security
- Macaroon signatures and complete discharge graphs are verified before
structured caveats or application satisfiers are invoked. - Added strict canonical parsing and configurable limits for serialized size,
caveat payloads, total caveat count, discharge count, and discharge depth. - SAML facade authentication fails closed for unsuccessful responses, missing
subject assertions, invalid signatures, issuer or audience mismatches,
expired or not-yet-valid assertions, replayed message IDs, and revoked keys. - Structured Macaroon satisfiers receive deeply immutable JSON values, so
callbacks cannot change the signed caveat represented by verification
results. - Added an internal NaCl-compatible XSalsa20-Poly1305 SecretBox implementation
for third-party caveat keys without an additional runtime dependency.
Poly1305 tags are verified before plaintext is returned. The Salsa20
implementation is pure Python and is not suitable when local or
high-resolution timing attackers are in scope.
v4.2.0a1
Added
- Added first-class Macaroon credentials with explicit synchronous and
asynchronousJam.issue(..., via="macaroon")and
Jam.authenticate(..., via="macaroon")flows. - Added a standalone
jam.macaroonsmodule with standard binary v2
serialization, immutable attenuation, opaque and structured first-party
caveats, third-party caveats, bound and nested discharge Macaroons, and
compatibility with reference implementations. - Added built-in
permission,condition,expires_at, andnot_before
caveats, plus an instance-ownedCaveatRegistryfor custom structured
caveats. - Added generic
AuthorizationConstraint,ConditionConstraint, and
PermissionConstrainttypes. Authenticated principals now carry immutable
credential constraints separately from root claims and permissions. - Added
MACAROON-HMAC-SHA256KeyChain support, including historical-key
verification, rotation, revocation,Memory, andFileStorage. - Added Macaroon support to the Django credential adapters and documentation
for configuration, attenuation, custom and opaque caveats, and discharge
acquisition.
Changed
- Authorization internals now live in the
jam.authzpackage with separate
contracts, constraints, policy compilation, roots, and condition helpers.
Existingfrom jam.authz import ...imports remain supported. - Credential constraints are evaluated before the configured authorization
policy. They can only reduce authority; a custom policy cannot bypass a
failing constraint or widen a Macaroon's root permissions. - Optional authentication modules are imported only when configured, allowing
a Macaroon-only Jam instance to run without unrelated extras. - Macaroon verification now accepts serialized primary and discharge tokens
only. The decodedMacaroonmodel remains available for attenuation and must
be serialized again before verification.
Deprecated
Removed
- Removed the unused internal version compatibility helper and the direct
packagingdependency.cryptographyis now Jam's only mandatory runtime
dependency.
Fixed
- Missing context data, references, malformed condition values, unsafe regular
expressions, unsupported caveats, invalid timestamps, and runtime comparison
mismatches now fail closed for credential constraints. - Django principal adaptation now preserves credential constraints.
- Macaroon time boundaries now fail during authentication and remain mandatory
authorization constraints. Configurable issuer, audience, and floating-point
clock leeway checks are available in the Macaroon profile.
Security
- Macaroon signatures and complete discharge graphs are verified before
structured caveats or application satisfiers are invoked. - Added strict canonical parsing and configurable limits for serialized size,
caveat payloads, total caveat count, discharge count, and discharge depth. - Structured Macaroon satisfiers receive deeply immutable JSON values, so
callbacks cannot change the signed caveat represented by verification
results. - Added an internal NaCl-compatible XSalsa20-Poly1305 SecretBox implementation
for third-party caveat keys without an additional runtime dependency.
Poly1305 tags are verified before plaintext is returned. The Salsa20
implementation is pure Python and is not suitable when local or
high-resolution timing attackers are in scope.
v4.2.0a0
Added
- Added first-class Macaroon credentials with explicit synchronous and
asynchronousJam.issue(..., via="macaroon")and
Jam.authenticate(..., via="macaroon")flows. - Added a standalone
jam.macaroonsmodule with standard binary v2
serialization, immutable attenuation, opaque and structured first-party
caveats, third-party caveats, bound and nested discharge Macaroons, and
compatibility with reference implementations. - Added built-in
permission,condition,expires_at, andnot_before
caveats, plus an instance-ownedCaveatRegistryfor custom structured
caveats. - Added generic
AuthorizationConstraint,ConditionConstraint, and
PermissionConstrainttypes. Authenticated principals now carry immutable
credential constraints separately from root claims and permissions. - Added
MACAROON-HMAC-SHA256KeyChain support, including historical-key
verification, rotation, revocation,Memory, andFileStorage. - Added Macaroon support to the Django credential adapters and documentation
for configuration, attenuation, custom and opaque caveats, and discharge
acquisition.
Changed
- Authorization internals now live in the
jam.authzpackage with separate
contracts, constraints, policy compilation, roots, and condition helpers.
Existingfrom jam.authz import ...imports remain supported. - Credential constraints are evaluated before the configured authorization
policy. They can only reduce authority; a custom policy cannot bypass a
failing constraint or widen a Macaroon's root permissions. - Optional authentication modules are imported only when configured, allowing
a Macaroon-only Jam instance to run without unrelated extras.
Deprecated
Removed
- Removed the unused internal version compatibility helper and the direct
packagingdependency.cryptographyis now Jam's only mandatory runtime
dependency.
Fixed
- Missing context data, references, malformed condition values, unsafe regular
expressions, unsupported caveats, invalid timestamps, and runtime comparison
mismatches now fail closed for credential constraints. - Django principal adaptation now preserves credential constraints.
Security
- Macaroon signatures and complete discharge graphs are verified before
structured caveats or application satisfiers are invoked. - Added strict canonical parsing and configurable limits for serialized size,
caveat payloads, total caveat count, discharge count, and discharge depth. - Added an internal NaCl-compatible XSalsa20-Poly1305 SecretBox implementation
for third-party caveat keys without an additional runtime dependency.
Poly1305 tags are verified before plaintext is returned. The Salsa20
implementation is pure Python and is not suitable when local or
high-resolution timing attackers are in scope.
v4.1.3
Added
- Added
aauthorize()for non-blocking permission checks in asynchronous
Django Modern REST controllers. - Added
source="session"as an explicit session-only mode for
JamSyncAuthandJamAsyncAuth.
Changed
- DMR authorization helpers now preserve an existing resource when
resource
is omitted and allow it to be cleared explicitly withresource=None. - DMR OpenAPI output now rejects auth instances with no enabled mechanism and
documents custom session-header prefixes and cookie-session CSRF responses. - Updated the 4.1.3 documentation and README links for the current
documentation layout, including valid serializer-backed DMR controllers.
Fixed
- Fixed DMR examples that used serializer-free controllers for Python return
values or imported decorators from an unsupported module. - Clarified Bearer-or-Session configuration so OpenAPI describes alternative
authentication methods instead of requiring both.
Security
- Jam Session credentials read from cookies now enforce Django CSRF validation
for unsafe requests in synchronous and asynchronous DMR controllers.