Changelog

Copy Markdown

All notable changes to Lockspire will be documented in this file.

The format is based on Keep a Changelog, and versions follow Semantic Versioning.

1.3.0 (2026-07-28)

Features

  • 108-01: add semantic admin design tokens (a08c2ca)
  • 108-01: tokenize admin CSS interaction styles (44539d4)
  • 108-02: add safe admin row and action primitives (b68d7b5)
  • 108-02: add structural admin primitives (8be147b)
  • 108-03: migrate admin filter bars (2c83e64)
  • 108-03: migrate admin hero and metric primitives (ba86255)
  • 108-03: migrate copy-once secret panels (219d380)
  • 109-01: polish token support investigation (bcb7853)
  • 109-02: polish consent support investigation (a72ed2f)
  • 109-03: recompose operations queues (86c2dd9)
  • 109-04: polish DCR onboarding and IAT flows (b1a29b2)
  • 109-05: polish keys and client actions (173b7d6)
  • 110-01: expand admin proof demo state (2db3e18)
  • 111-01: add explicit adoption demo bind IP option (f7adec3)
  • 111-01: derive demo endpoint URL and issuer from base URL (167a742)
  • 111-02: derive developer callback URL from demo base URL (b69b557)
  • 111-02: derive seeded demo URLs from base URL (4bf58d9)
  • 111-02: label adoption smoke URL drift assertions (3a58a61)
  • 112-01: add default demo compose stack (0bf5183)
  • 112-02: add docker startup readiness wrapper (420afc6)
  • 113-01: add direct compose conflict controls (c7f38c5)
  • 113-01: add scoped demo reset docs (3afdf61)
  • 113-02: add optional Traefik adoption demo routing (8b0b1ae)
  • 114-01: print redacted adoption demo startup info (3e09e4e)
  • 114-02: add adoption smoke wrapper (34a8398)
  • 115-01: add scoped adoption demo cleanup helper (19f07b9)
  • 115-01: add volume-preserving demo stop helper (5ecae2e)
  • 115-02: add deterministic CI hygiene contracts (0653eca)
  • 115-02: add local demo hygiene checks (41fb3fd)
  • 115-03: align adoption demo lifecycle docs (8794089)
  • 119-01: recompose client detail panes (adcc7b2)
  • 119-02: group DCR policy workflow (688e085)
  • 119-03: align IAT onboarding workflow (671cb20)
  • 119-03: align support detail hierarchy (d114204)
  • 119-04: render device and interaction queues as read-only lists (0759773)
  • 119-04: render logout deliveries as read-only list (df8c544)
  • 120-02: add rendered HTML assertion helper (86260f9)
  • 120-02: support read-only route control assertions (9969717)
  • 120-03: satisfy docs boundary contract (5d5343c)
  • 121-02: add route scorecard parser helper (75a8856)
  • 122-01: convert consent index to dense support flow (13149b1)
  • 122-01: convert token index to dense support flow (7f15950)
  • 122-02: polish token detail investigation actions (977281d)
  • 122-03: polish consent detail investigation actions (ce8fcf0)
  • 123-01: implement pressure-first interaction rows (eca93f2)
  • 123-02: implement pressure-first device authorization rows (9599882)
  • 123-03: implement logout delivery support truth (e90efb9)
  • 124-01: implement client configure hierarchy (a90336e)
  • 124-02: implement DCR IAT onboarding confirmation (b4d0a12)
  • 124-03: implement key lifecycle hierarchy (42a314d)
  • 124-04: implement policy posture review flow (e03a03f)
  • 124-05: add non-DCR policy posture summaries (3d3d8d9)
  • 125-01: implement shared fixture matrix (189c394)
  • 125-01: render internal stress matrix proof (4c2f357)
  • 125-02: implement global proof guardrail contracts (ba3264b)
  • 125-02: implement rendered html assertion helpers (de6eb5d)
  • 125-06: implement browser evidence parser (8f8e35c)
  • admin: polish v1.28 operator experience (4558388)
  • admin: Upgrade UI/UX with BEM design system and components (f2b573b)
  • brand: add brand book and re-skin admin UI to Signal Cyan identity (3a23a49)
  • harden adoption, prefix storage, and CI (f3ace6d)

Bug Fixes

  • 109: correct logout delivery metrics (1534496)
  • 109: revise plans based on checker feedback (2f639eb)
  • 109: revise plans based on checker feedback (4f8945a)
  • 110-05: prevent client route mobile overflow (a55bac7)
  • 110-05: wrap inline admin code values (6db0c0c)
  • 112-01: run demo image from repo mount (a4d5d1b)
  • 112-02: keep docker startup output minimal (67cd5e6)
  • 112-02: make demo image install noninteractive (d7c97ac)
  • 112-02: run demo compose through startup wrapper (01c061d)
  • 112-02: use available demo base image (01bfe4a)
  • 113: bind demo database override to loopback (a6a4749)
  • 113: revise conflict-control plan feedback (b3d1015)
  • 113: tighten validation feedback latency (d0417ec)
  • 114: close adoption demo startup review findings (22cf8c7)
  • 116: revise inventory lab plans (36da81a)
  • 117-01: render component lab empty fixtures (db6b9d7)
  • 119: resolve plan checker artifacts (221ad36)
  • 120-01: point logout support pivot at supported route (be9a328)
  • 120: resolve code review proof warnings (d3beec5)
  • 121: WR-01 reject invalid admin follow-up exceptions (07b4627)
  • 121: WR-02 reject duplicate scorecard fields (da03bd1)
  • 121: WR-03 broaden secret evidence guard (a5eff43)
  • 122: correct token family reuse action states (00e379e)
  • 122: revise plans based on checker feedback (d4b55e5)
  • 123: revise plans based on checker feedback (26df814)
  • 125-06: make browser evidence patterns portable (4e5abb4)
  • close v1.30 demo reprint audit gap (ea516df)
  • deps: resolve 13 security advisories blocking CI (#70) (f805e6e)
  • resolve post-merge conflicts from wave 3 (31f58f6)
  • test: Fix integration test regressions and add seeding helpers (41667e1)
  • types: Fix Dialyzer warnings around token formatting and signing keys (6a5f880)

1.2.0 (2026-05-27)

Features

1.1.2 (2026-05-27)

Bug Fixes

  • align support truth for CIBA and JAR (#36) (fc6baa6)

1.1.1 (2026-05-27)

Bug Fixes

  • isolate test config for logout worker (#32) (ffd922a)

1.1.0 (2026-05-26)

Added

  • Automatic DPoP-Nonce challenge and retry support across the shipped Lockspire-owned DPoP surfaces and the canonical Phoenix protected-route pipeline.
  • Dynamic Client Registration and RFC 7592 management support for the existing logout propagation metadata fields.
  • A narrow client_secret_jwt direct-client authentication slice on the shipped Lockspire-owned endpoints that already reuse the shared verifier.
  • Shared remote-jwks_uri diagnostics plus mix lockspire.doctor remote-jwks and matching admin support surfaces for the shipped private_key_jwt and JARM remote-key story.

Changed

  • The canonical advanced-setup support contract now aligns runtime behavior, admin wording, doctor output, and public docs for remote jwks_uri, mTLS setup, logout propagation, and the protected-route plug pipeline.
  • The public support posture now reflects one near-complete embedded-provider story rather than an actively expanding feature roadmap; new milestones should be trigger-based and evidence-driven.

Fixed

  • Release-truth docs now describe the shipped Phoenix protected-route plug pipeline and stop treating it as future work.

Features

  • 91-01: add shared remote jwks diagnostics taxonomy (13064b7)
  • 91-01: align jarm remote jwks diagnostics (0fbd363)
  • 91-01: normalize private_key_jwt remote jwks incidents (93c71a5)
  • 91-02: add remote jwks doctor surface (445f511)
  • 91-02: surface remote jwks truth in admin client detail (a26dce5)

Bug Fixes

  • phase-91: wire remote jwks operator diagnostics (ce8f313)

1.0.0 (2026-05-07)

Added

  • Canonical Phoenix-first install and onboarding documentation.
  • Executable onboarding proof for the generated host seam.
  • Release-readiness CI, package metadata, changelog, and workflow scaffolding.

Changed

  • The checked-in 1.0.0 release-candidate contract keeps mix.exs, .release-please-manifest.json, CHANGELOG.md, and the expected root tag lockspire-v1.0.0 on one embedded-library release story before authenticated publish proof begins.
  • Hex-facing package metadata, release configuration, and changelog posture now describe one lockspire package and defer authenticated publish evidence to the protected hex-publish lane.

0.2.0 (2026-04-24)

Features

  • 09-02: extend preview posture contract coverage (70107c8)

Bug Fixes

  • 10-01: restore contributor gate proof (20d53f7)

0.1.2 (2026-04-24)

Bug Fixes

  • release: make recovery lane publishable (cd5e40d)
  • release: run hex tasks before docs (046a14c)

0.1.1 (2026-04-24)

Bug Fixes

  • 08-01: harden trusted release lane contract (ed52b00)
  • ci: bootstrap test db in fast lane (bcb2ce3)
  • ci: provide postgres for fast checks (6b9d761)
  • test: avoid brittle key detail id assertion (a550cbb)