v4.2.0a0
Pre-release
Pre-release
Added
- Added first-class Macaroon credentials with explicit synchronous and
asynchronousJam.issue(..., via="macaroon")and
Jam.authenticate(..., via="macaroon")flows. - Added a standalone
jam.macaroonsmodule with standard binary v2
serialization, immutable attenuation, opaque and structured first-party
caveats, third-party caveats, bound and nested discharge Macaroons, and
compatibility with reference implementations. - Added built-in
permission,condition,expires_at, andnot_before
caveats, plus an instance-ownedCaveatRegistryfor custom structured
caveats. - Added generic
AuthorizationConstraint,ConditionConstraint, and
PermissionConstrainttypes. Authenticated principals now carry immutable
credential constraints separately from root claims and permissions. - Added
MACAROON-HMAC-SHA256KeyChain support, including historical-key
verification, rotation, revocation,Memory, andFileStorage. - Added Macaroon support to the Django credential adapters and documentation
for configuration, attenuation, custom and opaque caveats, and discharge
acquisition.
Changed
- Authorization internals now live in the
jam.authzpackage with separate
contracts, constraints, policy compilation, roots, and condition helpers.
Existingfrom jam.authz import ...imports remain supported. - Credential constraints are evaluated before the configured authorization
policy. They can only reduce authority; a custom policy cannot bypass a
failing constraint or widen a Macaroon's root permissions. - Optional authentication modules are imported only when configured, allowing
a Macaroon-only Jam instance to run without unrelated extras.
Deprecated
Removed
- Removed the unused internal version compatibility helper and the direct
packagingdependency.cryptographyis now Jam's only mandatory runtime
dependency.
Fixed
- Missing context data, references, malformed condition values, unsafe regular
expressions, unsupported caveats, invalid timestamps, and runtime comparison
mismatches now fail closed for credential constraints. - Django principal adaptation now preserves credential constraints.
Security
- Macaroon signatures and complete discharge graphs are verified before
structured caveats or application satisfiers are invoked. - Added strict canonical parsing and configurable limits for serialized size,
caveat payloads, total caveat count, discharge count, and discharge depth. - Added an internal NaCl-compatible XSalsa20-Poly1305 SecretBox implementation
for third-party caveat keys without an additional runtime dependency.
Poly1305 tags are verified before plaintext is returned. The Salsa20
implementation is pure Python and is not suitable when local or
high-resolution timing attackers are in scope.