This repository was archived by the owner on Jun 5, 2026. It is now read-only.
1.0.0
[1.0.0] - 2026-05-23
feat(http): propagateClientToApis sends the locally-computed secretHash instead of the plain secret; target stores it as-is via setSecretHashfeat(http): propagateClientToApis falls back to the local Redis credentialStore for secretHash when both secret and secretHash are omittedfeat(types): HmacHttpPropagationPlan.secret is now optionaltest(propagation): 4 new vitest cases - hash on the wire, Redis fallback, missing-everything throw, caller secretHash prioritydocs(release-notes): add docs/release-notes/1.0.0.md (before/after, resolution priority, FAQ on 3 acceptance scenarios)docs(diagrams): add docs/diagrams/ with architecture.puml + seq-signed-fetch.puml + seq-propagation.puml + seq-message.pumldocs(architecture): refresh docs/architecture.md with per-file responsibilities, hashing/signing/propagation contracts, prepublishOnly gatedemo(poc): 11 propagated clientIds incl. client_via_redis_lookup (secret omitted), 3 distinct HMAC_SECRET_TOKEN, verifyAllPropagatedClients logs ok=11/11 at boot + every 15s