diff --git a/.changeset/auth-stack-auth-0-43-0.md b/.changeset/auth-stack-auth-0-43-0.md new file mode 100644 index 000000000..3427e1619 --- /dev/null +++ b/.changeset/auth-stack-auth-0-43-0.md @@ -0,0 +1,7 @@ +--- +"@cipherstash/auth": patch +--- + +The native binding is now built from the `stack-auth` 0.43.0 crate, so its +requests identify themselves as `stack-auth/0.43.0` in the user agent. No API +or behaviour change for `@cipherstash/auth` consumers. diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2796fff27..b2dc14f31 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -233,9 +233,10 @@ updates: - minor - patch ignore: - # Released from cipherstash-suite and pinned with exact `=` requirements - # in the root Cargo.toml and the guests: stack-auth's API carries their - # types, so they move in lockstep with the suite, by hand. + # Released from cipherstash-suite: stack-auth's API carries their types, + # so they move in lockstep with the suite, by hand. The guests pin them + # with `=`; the root Cargo.toml pins recipher and cllw-ore with `=`, and + # gives cts-common and zerokms-protocol caret requirements. - dependency-name: "cts-common" - dependency-name: "zerokms-protocol" - dependency-name: "recipher" diff --git a/AGENTS.md b/AGENTS.md index b9cb92844..430d142d7 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -624,8 +624,11 @@ monorepo, which is where the silent failures are. The stack-* crates came from `cipherstash/cipherstash-suite`, which still owns `cipherstash-client`, `cts-common`, `zerokms-protocol`, `recipher` and -`cllw-ore`. Here those come from crates.io, pinned exactly in the root -`Cargo.toml`. +`cllw-ore`. Here those come from crates.io, and `Cargo.lock` holds their +exact versions. In the root `Cargo.toml`, `recipher` and `cllw-ore` are +pinned with `=`. `cts-common` and `zerokms-protocol` take caret +requirements, because the published `stack-auth` inherits them, and an +exact pin would stop the suite sharing one `cts-common` with it. - **Three Cargo workspaces, not one.** The root workspace (the six stack-* crates and the three node binding crates), protect-ffi's and EQL's. The root diff --git a/Cargo.lock b/Cargo.lock index e5eb6615d..6412c37b6 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -3201,7 +3201,7 @@ checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" [[package]] name = "stack-auth" -version = "0.42.3" +version = "0.43.0" dependencies = [ "aquamarine", "axum", @@ -3355,7 +3355,7 @@ dependencies = [ [[package]] name = "stack-profile" -version = "0.42.3" +version = "0.43.0" dependencies = [ "dirs", "gethostname", diff --git a/Cargo.toml b/Cargo.toml index 78d1e14e3..791530e09 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -68,8 +68,8 @@ incremental = true # but cannot subtract them, and `stack-kms` / `stack-encrypt` need stack-auth # without `http`. Consumers that want the default transport re-enable it with # `features = ["http"]`. -stack-auth = { path = "./packages/stack-auth", version = "0.42.3", default-features = false } -stack-profile = { path = "./packages/stack-profile", version = "0.42.3" } +stack-auth = { path = "./packages/stack-auth", version = "0.43.0", default-features = false } +stack-profile = { path = "./packages/stack-profile", version = "0.43.0" } # Suite crates, from crates.io; Cargo.lock holds the exact versions. # cts-common and zerokms-protocol take caret requirements because the diff --git a/languages/golang/stackauth/guest/Cargo.lock b/languages/golang/stackauth/guest/Cargo.lock index 106a30b75..eee72b24b 100644 --- a/languages/golang/stackauth/guest/Cargo.lock +++ b/languages/golang/stackauth/guest/Cargo.lock @@ -1809,7 +1809,7 @@ checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" [[package]] name = "stack-auth" -version = "0.42.3" +version = "0.43.0" dependencies = [ "aquamarine", "base64", @@ -1862,7 +1862,7 @@ dependencies = [ [[package]] name = "stack-profile" -version = "0.42.3" +version = "0.43.0" dependencies = [ "dirs", "gethostname", diff --git a/languages/golang/stackencrypt/guest/Cargo.lock b/languages/golang/stackencrypt/guest/Cargo.lock index 8bb00e5ea..e80577f68 100644 --- a/languages/golang/stackencrypt/guest/Cargo.lock +++ b/languages/golang/stackencrypt/guest/Cargo.lock @@ -1952,7 +1952,7 @@ checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" [[package]] name = "stack-auth" -version = "0.42.3" +version = "0.43.0" dependencies = [ "aquamarine", "base64", @@ -2065,7 +2065,7 @@ dependencies = [ [[package]] name = "stack-profile" -version = "0.42.3" +version = "0.43.0" dependencies = [ "dirs", "gethostname", diff --git a/packages/stack-auth/CHANGELOG.md b/packages/stack-auth/CHANGELOG.md index 9cab0d081..8cd4ec3f5 100644 --- a/packages/stack-auth/CHANGELOG.md +++ b/packages/stack-auth/CHANGELOG.md @@ -1,4 +1,58 @@ +## [0.43.0] - 2026-10-02 + + +### ⚠ Breaking changes + +- `RequestError`'s tuple payload is now `Box` instead of `reqwest::Error`. Construct it with `RequestError::from(reqwest_error)` (or box the error yourself) instead of `RequestError(reqwest_error)`, and recover the concrete error with `.0.downcast_ref::()` instead of using `.0` as a `reqwest::Error` directly. `source()` is unchanged; the `Display` message is now "Request to the auth server failed" (it was "HTTP request failed"). +- `DeviceClientError::Request` now carries a `RequestError` rather than a `reqwest::Error`; a match on that variant's payload changes type. +- `From for AuthError` is removed. Every reqwest failure enters the crate through `ReqwestTransport` as a `RequestError`; a caller that lifted a `reqwest::Error` into `AuthError` directly should wrap it in `RequestError` (`AuthError::Request(RequestError(Box::new(e)))`) or, better, send through the transport. +- Depends on `cts-common` 0.43 (vitaminc 0.5) and `zerokms-protocol` 0.12.31, from crates.io. `Crn` (re-exported here), `Region`, `WorkspaceId` and the `cts-common` errors in this crate's API are `cts-common` 0.43 types, so a caller that passes them in needs `cts-common` 0.43 too. + +### CI + +- mutation-testing gate for stack-auth and stack-encrypt (cargo-mutants --in-diff) + +### Documentation + +- correct stale StaticTokenStrategy comments in Cargo manifests + +### Features + +- build stack-auth, stack-kms and stack-encrypt for WASI without reqwest +- classify credential rejections where the variants live +- a workspace CRN is reachable without reaching for cts-common +- an HTTP transport trait mirroring the guest's host import, reqwest behind `http` +- add Go credential strategies + +### Fixes + +- address review findings on the http feature split +- address Copilot review on error Display strings +- test modules keep a literal `cfg(test)` so the CRAP gate skips them; add the npm changeset +- the wire types print nothing secret, wipe their headers, and lend reqwest the body +- satisfy credential guest CI +- lock only device refresh +- never replay a spent refresh token after a failed save +- identify every auth request with a user-agent + +### Miscellaneous + +- per-crate rustdoc gates for the stack crates, fanned out by `doc` +- move to cipherstash/stack with its history: the first release from that repository's `release-plz.yml`, in a version group with stack-profile alone + +### Refactoring + +- replace crate-wide no-http allow(dead_code) with item-level http gates + +### Testing + +- pin mutation regression behavior +- cover remaining mutation paths +- address PR review findings +- keep browser launcher mutable +- address review notes on assertion messages + ## [0.42.3] - 2026-08-26 diff --git a/packages/stack-auth/Cargo.toml b/packages/stack-auth/Cargo.toml index e004b61c7..ae18811be 100644 --- a/packages/stack-auth/Cargo.toml +++ b/packages/stack-auth/Cargo.toml @@ -1,7 +1,7 @@ [package] name = "stack-auth" description = "Authentication library for CipherStash services" -version = "0.42.3" +version = "0.43.0" edition.workspace = true authors.workspace = true repository.workspace = true diff --git a/packages/stack-auth/fuzz/Cargo.lock b/packages/stack-auth/fuzz/Cargo.lock index 75797cb9c..756d51a69 100644 --- a/packages/stack-auth/fuzz/Cargo.lock +++ b/packages/stack-auth/fuzz/Cargo.lock @@ -2583,7 +2583,7 @@ checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" [[package]] name = "stack-auth" -version = "0.42.3" +version = "0.43.0" dependencies = [ "aquamarine", "base64", @@ -2619,7 +2619,7 @@ dependencies = [ [[package]] name = "stack-profile" -version = "0.42.3" +version = "0.43.0" dependencies = [ "dirs", "gethostname", diff --git a/packages/stack-encrypt/fuzz/Cargo.lock b/packages/stack-encrypt/fuzz/Cargo.lock index 32e39436e..30234dfae 100644 --- a/packages/stack-encrypt/fuzz/Cargo.lock +++ b/packages/stack-encrypt/fuzz/Cargo.lock @@ -1994,7 +1994,7 @@ checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" [[package]] name = "stack-auth" -version = "0.42.3" +version = "0.43.0" dependencies = [ "aquamarine", "base64", @@ -2087,7 +2087,7 @@ dependencies = [ [[package]] name = "stack-profile" -version = "0.42.3" +version = "0.43.0" dependencies = [ "dirs", "gethostname", diff --git a/packages/stack-kms/fuzz/Cargo.lock b/packages/stack-kms/fuzz/Cargo.lock index ebe0a0f54..aaa4ad420 100644 --- a/packages/stack-kms/fuzz/Cargo.lock +++ b/packages/stack-kms/fuzz/Cargo.lock @@ -1937,7 +1937,7 @@ checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" [[package]] name = "stack-auth" -version = "0.42.3" +version = "0.43.0" dependencies = [ "aquamarine", "base64", @@ -1999,7 +1999,7 @@ dependencies = [ [[package]] name = "stack-profile" -version = "0.42.3" +version = "0.43.0" dependencies = [ "dirs", "gethostname", diff --git a/packages/stack-profile/CHANGELOG.md b/packages/stack-profile/CHANGELOG.md index 74c659b65..ee9d741ea 100644 --- a/packages/stack-profile/CHANGELOG.md +++ b/packages/stack-profile/CHANGELOG.md @@ -37,6 +37,18 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 +## [0.43.0] - 2026-10-02 + + +### Features + +- the crate builds for wasm32-wasip1, and names the lock file's path + +### Miscellaneous + +- per-crate rustdoc gates for the stack crates, fanned out by `doc` +- move to cipherstash/stack with its history: the first release from that repository's `release-plz.yml`, in a version group with stack-auth alone. No change to the API; the version follows stack-auth's breaking release + ## [0.42.3] - 2026-08-26 diff --git a/packages/stack-profile/Cargo.toml b/packages/stack-profile/Cargo.toml index 93f11306b..0d59bba2b 100644 --- a/packages/stack-profile/Cargo.toml +++ b/packages/stack-profile/Cargo.toml @@ -2,7 +2,7 @@ name = "stack-profile" description = "Centralised ~/.cipherstash profile file management" license-file = "LICENSE" -version = "0.42.3" +version = "0.43.0" edition.workspace = true authors.workspace = true repository.workspace = true