Skip to content

Releases: xyo-financial/sdk-rust

v2.1.0

Choose a tag to compare

@syniol syniol released this 22 Aug 23:51
b6e23c0

🚀 v2.1.0 Enterprise Banking Security & Distributed Tracing

v2.1.0 introduces enterprise-grade banking security, enhanced async ergonomics, zero-panic runtime guarantees, and production-ready telemetry to the XYO Financial Rust SDK (xyo-sdk).

Key Highlights

  • 64 KiB Error Body Read Cap: Prevents unbounded memory allocation or denial-of-service vulnerabilities when consuming unexpected HTTP error response bodies.
  • HTTP-Date Retry-After Parsing: Full support for parsing both integer seconds and RFC 2822 / HTTP-Date timestamp headers during rate limiting (429 Too Many Requests) handling.
  • Lazy Streaming Batch Iterator: Offloads CPU-intensive archive extraction, decompression, and JSON parsing in download_enrichment_collection to background worker pools with memory-bounded chunk streaming.
  • OpenAPI Crate Clippy Allowances: Pre-configured Clippy lint suppressions in auto-generated transport bindings to ensure clean compiler builds under strict -D warnings settings.
  • Pure OpenAPI Isolation: Enforces a strict architecture separating low-level OpenAPI transport bindings (xyo-openapi-client) from high-level, ergonomic async Rust APIs (xyo-sdk).

🛠 What's Changed

Features & Security Hardening

  • ClientBuilder & Fluent Configuration: Builder pattern (Client::builder()) supporting custom HTTP timeouts, connection pool limits, custom reqwest clients, and multi-cloud security policies.
  • Dynamic Token Rotation: Support for runtime secret and API key rotation via Client::with_token_supplier callbacks without client re-instantiation.
  • Structured Tracing Telemetry: Integrated tracing instrumentation across client invocations, batch submissions, and status polling.
  • Zero-Trust Security Defenses:
    • Strict domain allowlists (DEFAULT_PERMITTED_HOSTS) for tarball downloads.
    • Tar bomb and Zip-Slip path traversal mitigations (DEFAULT_MAX_TAR_ENTRIES, DEFAULT_MAX_ENTRY_BYTES, DEFAULT_MAX_ARCHIVE_BYTES).
    • CWE-113 CRLF header injection validation on custom headers.
    • SSRF URL scheme restriction to http/https.
    • Sensitive credential masking ([REDACTED]) in Debug output.
  • Error Handling & Classification: Programmatic error query methods (is_auth(), is_rate_limited(), is_server_error(), is_retryable(), is_not_found()).

Detailed Commit Log

  • b6e23c0 chore(release): bump version to 2.1.0 (#35)
  • 54737a9 Automated SDK Update (#34)
  • 8677bb0 feat: support v2.0.0 tracing parameters in client wrapper and use create-pull-request in generate workflow
  • 11c15f3 fix(docs): use absolute raw github URL for mascot (#32)
  • 1c1b3e2 docs(readme): add Axum and Tokio framework integration recipes (#31)
  • 1a265eb chore(docs): update mascot image to sleek neon design (#30)
  • 8ab8c63 style(readme): standardize header structure to match PHP SDK standard (#29)
  • 429916e docs(readme): simplify headings and summary phrasing (#28)
  • 602884f docs(security): add Rust MSRV and Edition support schedule SVG and 3-month proactive policy
  • 8c39d6d docs: polish markdown section headings and standardize emojis (#27)
  • 1cc9eff docs(changelog): audit historical tags and document unreleased changes (#26)
  • 29e010a ci: add GitHub release workflow (#25)
  • 0c659e5 fix(sdk): zero panic vectors, thread-safe test harness, and client-side validation (#24)
  • d3c7fcf feat(sdk): strict zero-trust domain allowlist and raw header dispatch (#23)
  • 9670af9 feat(sdk): structured tracing telemetry and error classification (#22)
  • 5bd2ba6 feat(sdk): enterprise hardening, ClientBuilder, and async stream optimizations (#21)
  • e752d88 feat(sdk): add EnrichmentRequest validation, CWE-113 CRLF defense, and dynamic token rotation (#20)
  • 12d91bd feat(sdk): enforce zero trust domain validation and eliminate SSRF error preview (#18)
  • eb90bbf feat(sdk): enterprise banking resilience, tar bomb mitigations, SSRF, and WAF diagnostics (#17)
  • 399bbf8 docs(license): align LICENSE with exact standard Apache 2.0 text for licensecheck compliance

📦 Installation & Usage

Add xyo-sdk to your Cargo.toml:

cargo add xyo-sdk@2.1.0

Or add it manually:

[dependencies]
xyo-sdk = "2.1.0"
tokio = { version = "1.38", features = ["full"] }

Quickstart Example

use xyo_sdk::{Client, EnrichmentRequest};

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new("YOUR_BEARER_TOKEN", None)?;

    let request = EnrichmentRequest::new(
        "BARCLAYS BANK PLC LONDON UK",
        Some("GB".to_string()),
    )?;

    let response = client.enrich_transaction(request).await?;
    println!("Merchant Name: {:?}", response.merchant_name);

    Ok(())
}

v2.0.0

Choose a tag to compare

@syniol syniol released this 12 Aug 21:20

Release Notes: v2.0.0

The XYO Financial SDK for Rust v2.0.0 is a major architectural overhaul that transitions the entire SDK from a synchronous prototype to an institutional-grade, fully asynchronous, non-blocking library natively integrated with Tokio, Reqwest, and OpenAPI specifications.


🚨 Breaking Changes & Migration Guide

  • Native Async/Await (Tokio): All SDK calls are now non-blocking and asynchronous. You must run the SDK within an async runtime (e.g. #[tokio::main]).
  • Deprecation & Removal of xyo-http: The raw, custom xyo-http crate has been completely removed in favor of reqwest (with rustls-tls), bringing native HTTP/2 connection pooling, keep-alive connections, and robust TLS handling out of the box.
  • Modernized Client Interface:
    • Client::new(bearer_token, base_url) replaces the old config object initialization.
    • Methods updated to idiomatic async names:
      • client.enrich_transaction(content, country_code).await
      • client.enrich_transactions(requests, api_user).await
      • client.get_enrichment_status(id, api_user).await
  • Licensing: Re-licensed to Apache License 2.0 (Apache-2.0).

✨ New Features & Enhancements

⚡ Async & High-Throughput Engine

  • Tokio & Reqwest Integration: Native non-blocking I/O capable of handling thousands of concurrent transaction enrichment requests across worker pools and async web frameworks (Axum, Actix-web).
  • Thread-Safe by Design: Client is Send + Sync, designed to be shared across threads as an application singleton.

📦 In-Memory Tar/Gzip Bulk Archive Decompression

  • download_enrichment_collection: Added a helper that streams and unpacks bulk .tar.gz archive results directly in-memory using flate2 and tar, returning strongly typed Vec<EnrichmentResponse> without writing temporary files to disk.

🤖 OpenAPI Codegen Integration (xyo-openapi-client)

  • Scoped Workspace Crate: Codegen crate configured and published under the unique namespace xyo-openapi-client (v2.0.0) to avoid public crates.io naming collisions.
  • Deterministic Code Generation: Integrated @openapitools/openapi-generator-cli with an openapitools.json configuration and workspace crate openapi/.
  • Automated Spec Sync: Added .github/workflows/generate.yml supporting repository_dispatch and workflow_dispatch triggers for automated OpenAPI schema updates from xyo-financial/specs.

🧪 Comprehensive Integration Test Suite

  • WireMock Test Suite: Added tests/client_test.rs (>1,000 lines of tests) validating:
    • Single and bulk transaction enrichment
    • Bulk job status polling (Ready, Pending, Failed)
    • Bearer token authentication and custom header injection
    • HTTP status error mapping (400, 401, 403, 404, 429, 500, 503)
    • End-to-end .tar.gz archive generation and in-memory decompression

📖 Runnable Examples & Quickstarts

Added standalone, runnable examples under examples/:

  • examples/quickstart.rs: Single transaction enrichment walkthrough.
  • examples/bulk_enrichment.rs: Batch submission, status polling, and archive download.
  • examples/error_handling.rs: Robust error matching and inspection.

🔒 Security & Governance

  • Zero unsafe Code: 100% safe Rust code with verified dependency boundaries.
  • Security Policy: Added SECURITY.md defining vulnerability reporting processes.
  • Enterprise Governance: Expanded CONTRIBUTING.md with deterministic build steps and cross-repo spec generation documentation.
  • Support Channel: Updated official support email to support@syniol.com.

📦 Dependency Highlights

[dependencies]
xyo-sdk = "2.0.0"
tokio = { version = "1", features = ["rt-multi-thread", "macros"] }
  • xyo-openapi-client = "2.0.0"
  • reqwest = "0.11" (rustls-tls, json, stream)
  • tokio = "=1.38.0"
  • flate2 = "1.0"
  • tar = "0.4"
  • serde = "1.0.219"
  • serde_json = "1.0.143"

v1.1.9

Choose a tag to compare

@syniol syniol released this 07 Aug 15:40
7e41d08

Release Notes: v1.1.9

🔄 Repository & Organization Migration

  • GitHub Repository URL: Migrated repository URLs to https://github.com/xyo-financial/sdk-rust across Cargo.toml, xyo-http/Cargo.toml, and README.md.
  • Badges & Assets: Updated GitHub Actions CI workflow badges and documentation image links in README.md to point to the new organization repository.

🚀 Version Bump

  • xyo-sdk: Incremented version from 1.1.8 to 1.1.9 in Cargo.toml.
  • xyo-http: Incremented version from 1.1.8 to 1.1.9 in xyo-http/Cargo.toml.
  • example: Updated xyo-sdk dependency to 1.1.9 in example/Cargo.toml.
  • Lockfiles: Updated Cargo.lock and example/Cargo.lock to reflect version 1.1.9.
  • Changelog: Added CHANGELOG.md documenting recent release history and changes.

v1.1.8

Choose a tag to compare

@syniol syniol released this 20 Jul 20:51
04ec129

Here is the changelog comparing 20-july-2026-release to main. This content has also been saved to CHANGELOG.md:

Changelog

All notable changes to the XYO Financial SDK for Rust will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[1.1.8] - 2026-07-20

🚀 Version Bump

  • xyo-sdk: Incremented package version from 1.1.7 to 1.1.8 in Cargo.toml.
  • xyo-http: Incremented package version from 1.1.7 to 1.1.8 in xyo-http/Cargo.toml.
  • Dependencies: Updated xyo-http workspace dependency requirement to 1.1.8 in root Cargo.toml and updated xyo-sdk dependency requirement to 1.1.8 in example/Cargo.toml.
  • Lockfiles: Synchronized Cargo.lock and example/Cargo.lock to reflect version 1.1.8.

📄 Licensing

  • Relicensed to BSD 3-Clause: Relicensed the project to the BSD 3-Clause License (BSD-3-Clause).
  • LICENSE: Replaced license terms in LICENSE with the standard BSD 3-Clause License text for Syniol Limited.
  • Package Manifests: Set SPDX license field to "BSD-3-Clause" in Cargo.toml and xyo-http/Cargo.toml.
  • Documentation: Updated license notices in README.md and xyo-http/README.md.

⚙️ CI/CD & Workflows

  • Publish Workflow: Updated push tag filter to v[0-9]+.[0-9]+.[0-9]+ in .github/workflows/crates_xyo_http_publish.yml.

1.1.7

Choose a tag to compare

@syniol syniol released this 14 Jul 21:52

Release Notes: v1.1.7

This is a maintenance release focused on updating documentation, licensing, and repository contribution policies. There are no functional code changes to the SDK client in this release.

📝 Licensing Updates

  • Migrated to MIT License: The SDK and xyo-http client have officially transitioned from the Apache-2.0 license to the MIT License.
  • Documentation Sync: The repository LICENSE file has been replaced to reflect the MIT terms, and the README.md has been updated to explicitly state the new license.

🔒 Repository Policy

  • Strict Contribution Guidelines: Updated CONTRIBUTING.md to explicitly state that the repository is closed to external contributions. A highly visible notice was added to inform outside developers that Pull Requests are exclusively restricted to Syniol Limited engineering staff.

🎨 Branding & Documentation

  • New Official Mascots: Added high-fidelity, enterprise-grade AI concepts of the Rust mascot tailored for the financial sector.
  • Mascot Concept Docs: Introduced a new docs/mascot_concepts.md presentation file and bundled the accompanying sleek_neon and platinum_geometric image assets into the docs/ directory for internal branding reference.

1.1.6

Choose a tag to compare

@syniol syniol released this 14 Jul 21:06
87956d6

Release Notes: v1.1.6

This release introduces critical security patches and a massive architectural refactor to make the Rust SDK robust, panic-free, and enterprise-ready.

🔒 Security Updates

  • Enforced TLS (HTTPS): Migrated the underlying transport layer from plain-text TCP sockets (Port 80) to secure, encrypted TLS streams (Port 443) using native-tls. Financial payloads are now securely encrypted in transit.
  • Header Injection & Authentication: Fixed a critical defect where the API key was not being transmitted. The xyo-http client now natively supports dynamic header injection, guaranteeing the Authorization: Bearer <key> header is present on every secured request.

🛠 Architectural Refactoring & Stability

  • Zero-Panic Guarantee: Eradicated all reckless .unwrap() calls across the client.rs codebase. JSON serialization/deserialization failures and network I/O errors are now safely wrapped and returned as standard ClientError results. The SDK will no longer panic the host process.
  • Robust HTTP/1.1 Parsing: The bespoke xyo-http parser was completely overhauled. It no longer arbitrarily splits the entire response body string by \r\n (which broke on JSON payloads containing newlines). It now correctly boundaries headers at \r\n\r\n and relies on safe byte extraction for the payload.
  • Safe Content-Length Calculation: The Content-Length header is now strictly calculated using .as_bytes().len() instead of string length, ensuring payload sizes do not desync when multibyte UTF-8 characters are present.
  • Structured HttpResponse: The HTTP client now returns a strongly-typed HttpResponse struct (containing the status_code and body) instead of a raw String, eliminating massive heap allocation/cloning bottlenecks that previously occurred during response parsing.

🚀 API Changes

  • Idiomatic Signatures: The enrich_transaction_collection method was refactored. It now accepts an idiomatic slice &[EnrichmentRequest] rather than forcing the caller to allocate an awkward Vec<&EnrichmentRequest>.

1.1.5

Choose a tag to compare

@syniol syniol released this 28 Jun 12:45

Release Notes: v1.1.5

This release delivers secure HTTPS communication, fixes Docker compilation issues for Alpine/musl environments, and cleans up compiler warnings.

🚀 What's New in v1.1.5

1. 🔒 HTTPS Migration

  • TLS Integration: Upgraded the client from plain HTTP (port 80) to HTTPS (port 443) using native-tls. All SDK traffic to api.xyo.financial is now encrypted in transit.
  • Double CRLF Line Endings: Corrected HTTP header endings to the RFC-compliant \r\n\r\n format.

2. 🐳 Docker Build Fixes

  • Alpine Static Linking Support: Added openssl-dev and openssl-libs-static to the Dockerfile's Alpine package list. This enables the compiler to find the necessary C headers and static libraries (libssl.a, libcrypto.a) to statically link openssl-sys on musl targets.

3. 📦 Dependency & Compatibility Pinning

  • Cargo 1.75+ Compatibility: Downgraded native-tls to v0.2.11 and getrandom to v0.3.0 in the workspace lockfile. This avoids pulling in newer crates that require the unreleased edition2024 Cargo feature, ensuring the SDK builds on older toolchains.

4. 🧪 Testing & CI Improvements

  • Time-Travel Resiliency: Added XYO_SDK_DANGER_ACCEPT_INVALID_CERTS environment variable support. This allows integration tests to bypass certificate expiration checks when running in environments with skewed system clocks, while keeping production connections 100% secure.

5. 🧹 Code Quality

  • Warning Cleanups: Removed the unused mut keyword on tcp_stream_socket.
  • Robust I/O: Replaced write() with write_all() to guarantee full request transmission.
  • Panic Prevention: Removed unsafe .unwrap() calls on socket flush() and shutdown().

1.1.4

Choose a tag to compare

@syniol syniol released this 28 Jun 10:57
f81ec11

Release Notes: v1.1.4

This release addresses a critical issue in the HTTP client module (xyo-http) regarding socket timeouts and persistent connections, alongside several robustness and performance improvements.

🚀 What's New in v1.1.4

1. Fix Indefinite Request Blocking & Premature Timeouts

Previously, the SDK did not explicitly signal the server to close the connection, causing read_to_string to block indefinitely due to HTTP/1.1 persistent connection defaults. A temporary 100ms read timeout was used as a workaround, which caused slow requests to fail prematurely.

  • Added Connection: close Header: Instructs the server to close the TCP connection immediately after transmitting the response. The client now receives an EOF and completes the read instantly.
  • Increased Default Timeout: Increased the socket read timeout from 100ms to 10s (Duration::from_secs(10)). This prevents premature timeouts on slower network paths or complex queries, while fast requests still return immediately.

2. RFC-Compliant HTTP Formatting

  • Corrected HTTP header endings from \r\n\n to the standard double CRLF (\r\n\r\n) to prevent parsing issues on stricter upstream proxies and servers.

3. Production-Grade Robustness

  • Guaranteed Writes: Replaced tcp_stream_socket.write() with write_all() to guarantee the entire payload is written to the socket, avoiding partial write issues.
  • Panic Prevention: Removed .unwrap() on socket flush() and shutdown(). If the remote host closes the socket early, the SDK now handles it gracefully instead of panicking.
  • Proper Error Propagation: All I/O errors during connection, configuration, writing, and reading are now properly captured and returned as HttpClientError rather than being silently ignored.

📦 Dependency Updates

  • Upgraded xyo-http and xyo-sdk to v1.1.4 across the workspace and examples.

1.1.3

Choose a tag to compare

@syniol syniol released this 19 Oct 15:07
c510f95
  • Added a new field location to an enrichment response
  • Added a new field address to an enrichment response

Stable Release

Choose a tag to compare

@syniol syniol released this 23 Sep 09:12
7e2586e

Stable release with complete error handling