Changelog
Copy MarkdownAll notable changes to Lockspire will be documented in this file.
The format is based on Keep a Changelog, and versions follow Semantic Versioning.
1.3.0 (2026-07-28)
Features
- 108-01: add semantic admin design tokens (a08c2ca)
- 108-01: tokenize admin CSS interaction styles (44539d4)
- 108-02: add safe admin row and action primitives (b68d7b5)
- 108-02: add structural admin primitives (8be147b)
- 108-03: migrate admin filter bars (2c83e64)
- 108-03: migrate admin hero and metric primitives (ba86255)
- 108-03: migrate copy-once secret panels (219d380)
- 109-01: polish token support investigation (bcb7853)
- 109-02: polish consent support investigation (a72ed2f)
- 109-03: recompose operations queues (86c2dd9)
- 109-04: polish DCR onboarding and IAT flows (b1a29b2)
- 109-05: polish keys and client actions (173b7d6)
- 110-01: expand admin proof demo state (2db3e18)
- 111-01: add explicit adoption demo bind IP option (f7adec3)
- 111-01: derive demo endpoint URL and issuer from base URL (167a742)
- 111-02: derive developer callback URL from demo base URL (b69b557)
- 111-02: derive seeded demo URLs from base URL (4bf58d9)
- 111-02: label adoption smoke URL drift assertions (3a58a61)
- 112-01: add default demo compose stack (0bf5183)
- 112-02: add docker startup readiness wrapper (420afc6)
- 113-01: add direct compose conflict controls (c7f38c5)
- 113-01: add scoped demo reset docs (3afdf61)
- 113-02: add optional Traefik adoption demo routing (8b0b1ae)
- 114-01: print redacted adoption demo startup info (3e09e4e)
- 114-02: add adoption smoke wrapper (34a8398)
- 115-01: add scoped adoption demo cleanup helper (19f07b9)
- 115-01: add volume-preserving demo stop helper (5ecae2e)
- 115-02: add deterministic CI hygiene contracts (0653eca)
- 115-02: add local demo hygiene checks (41fb3fd)
- 115-03: align adoption demo lifecycle docs (8794089)
- 119-01: recompose client detail panes (adcc7b2)
- 119-02: group DCR policy workflow (688e085)
- 119-03: align IAT onboarding workflow (671cb20)
- 119-03: align support detail hierarchy (d114204)
- 119-04: render device and interaction queues as read-only lists (0759773)
- 119-04: render logout deliveries as read-only list (df8c544)
- 120-02: add rendered HTML assertion helper (86260f9)
- 120-02: support read-only route control assertions (9969717)
- 120-03: satisfy docs boundary contract (5d5343c)
- 121-02: add route scorecard parser helper (75a8856)
- 122-01: convert consent index to dense support flow (13149b1)
- 122-01: convert token index to dense support flow (7f15950)
- 122-02: polish token detail investigation actions (977281d)
- 122-03: polish consent detail investigation actions (ce8fcf0)
- 123-01: implement pressure-first interaction rows (eca93f2)
- 123-02: implement pressure-first device authorization rows (9599882)
- 123-03: implement logout delivery support truth (e90efb9)
- 124-01: implement client configure hierarchy (a90336e)
- 124-02: implement DCR IAT onboarding confirmation (b4d0a12)
- 124-03: implement key lifecycle hierarchy (42a314d)
- 124-04: implement policy posture review flow (e03a03f)
- 124-05: add non-DCR policy posture summaries (3d3d8d9)
- 125-01: implement shared fixture matrix (189c394)
- 125-01: render internal stress matrix proof (4c2f357)
- 125-02: implement global proof guardrail contracts (ba3264b)
- 125-02: implement rendered html assertion helpers (de6eb5d)
- 125-06: implement browser evidence parser (8f8e35c)
- admin: polish v1.28 operator experience (4558388)
- admin: Upgrade UI/UX with BEM design system and components (f2b573b)
- brand: add brand book and re-skin admin UI to Signal Cyan identity (3a23a49)
- harden adoption, prefix storage, and CI (f3ace6d)
Bug Fixes
- 109: correct logout delivery metrics (1534496)
- 109: revise plans based on checker feedback (2f639eb)
- 109: revise plans based on checker feedback (4f8945a)
- 110-05: prevent client route mobile overflow (a55bac7)
- 110-05: wrap inline admin code values (6db0c0c)
- 112-01: run demo image from repo mount (a4d5d1b)
- 112-02: keep docker startup output minimal (67cd5e6)
- 112-02: make demo image install noninteractive (d7c97ac)
- 112-02: run demo compose through startup wrapper (01c061d)
- 112-02: use available demo base image (01bfe4a)
- 113: bind demo database override to loopback (a6a4749)
- 113: revise conflict-control plan feedback (b3d1015)
- 113: tighten validation feedback latency (d0417ec)
- 114: close adoption demo startup review findings (22cf8c7)
- 116: revise inventory lab plans (36da81a)
- 117-01: render component lab empty fixtures (db6b9d7)
- 119: resolve plan checker artifacts (221ad36)
- 120-01: point logout support pivot at supported route (be9a328)
- 120: resolve code review proof warnings (d3beec5)
- 121: WR-01 reject invalid admin follow-up exceptions (07b4627)
- 121: WR-02 reject duplicate scorecard fields (da03bd1)
- 121: WR-03 broaden secret evidence guard (a5eff43)
- 122: correct token family reuse action states (00e379e)
- 122: revise plans based on checker feedback (d4b55e5)
- 123: revise plans based on checker feedback (26df814)
- 125-06: make browser evidence patterns portable (4e5abb4)
- close v1.30 demo reprint audit gap (ea516df)
- deps: resolve 13 security advisories blocking CI (#70) (f805e6e)
- resolve post-merge conflicts from wave 3 (31f58f6)
- test: Fix integration test regressions and add seeding helpers (41667e1)
- types: Fix Dialyzer warnings around token formatting and signing keys (6a5f880)
1.2.0 (2026-05-27)
Features
1.1.2 (2026-05-27)
Bug Fixes
1.1.1 (2026-05-27)
Bug Fixes
1.1.0 (2026-05-26)
Added
- Automatic
DPoP-Noncechallenge and retry support across the shipped Lockspire-owned DPoP surfaces and the canonical Phoenix protected-route pipeline. - Dynamic Client Registration and RFC 7592 management support for the existing logout propagation metadata fields.
- A narrow
client_secret_jwtdirect-client authentication slice on the shipped Lockspire-owned endpoints that already reuse the shared verifier. - Shared remote-
jwks_uridiagnostics plusmix lockspire.doctor remote-jwksand matching admin support surfaces for the shippedprivate_key_jwtand JARM remote-key story.
Changed
- The canonical advanced-setup support contract now aligns runtime behavior, admin wording, doctor output, and public docs for remote
jwks_uri, mTLS setup, logout propagation, and the protected-route plug pipeline. - The public support posture now reflects one near-complete embedded-provider story rather than an actively expanding feature roadmap; new milestones should be trigger-based and evidence-driven.
Fixed
- Release-truth docs now describe the shipped Phoenix protected-route plug pipeline and stop treating it as future work.
Features
- 91-01: add shared remote jwks diagnostics taxonomy (13064b7)
- 91-01: align jarm remote jwks diagnostics (0fbd363)
- 91-01: normalize private_key_jwt remote jwks incidents (93c71a5)
- 91-02: add remote jwks doctor surface (445f511)
- 91-02: surface remote jwks truth in admin client detail (a26dce5)
Bug Fixes
- phase-91: wire remote jwks operator diagnostics (ce8f313)
1.0.0 (2026-05-07)
Added
- Canonical Phoenix-first install and onboarding documentation.
- Executable onboarding proof for the generated host seam.
- Release-readiness CI, package metadata, changelog, and workflow scaffolding.
Changed
- The checked-in
1.0.0release-candidate contract keepsmix.exs,.release-please-manifest.json,CHANGELOG.md, and the expected root taglockspire-v1.0.0on one embedded-library release story before authenticated publish proof begins. - Hex-facing package metadata, release configuration, and changelog posture now describe one
lockspirepackage and defer authenticated publish evidence to the protectedhex-publishlane.
0.2.0 (2026-04-24)
Features
- 09-02: extend preview posture contract coverage (70107c8)
Bug Fixes
- 10-01: restore contributor gate proof (20d53f7)