Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/auth-stack-auth-0-43-0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
"@cipherstash/auth": patch
---

The native binding is now built from the `stack-auth` 0.43.0 crate, so its
requests identify themselves as `stack-auth/0.43.0` in the user agent. No API
or behaviour change for `@cipherstash/auth` consumers.
7 changes: 4 additions & 3 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -233,9 +233,10 @@ updates:
- minor
- patch
ignore:
# Released from cipherstash-suite and pinned with exact `=` requirements
# in the root Cargo.toml and the guests: stack-auth's API carries their
# types, so they move in lockstep with the suite, by hand.
# Released from cipherstash-suite: stack-auth's API carries their types,
# so they move in lockstep with the suite, by hand. The guests pin them
# with `=`; the root Cargo.toml pins recipher and cllw-ore with `=`, and
# gives cts-common and zerokms-protocol caret requirements.
- dependency-name: "cts-common"
- dependency-name: "zerokms-protocol"
- dependency-name: "recipher"
Expand Down
7 changes: 5 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -624,8 +624,11 @@ monorepo, which is where the silent failures are.

The stack-* crates came from `cipherstash/cipherstash-suite`, which still owns
`cipherstash-client`, `cts-common`, `zerokms-protocol`, `recipher` and
`cllw-ore`. Here those come from crates.io, pinned exactly in the root
`Cargo.toml`.
`cllw-ore`. Here those come from crates.io, and `Cargo.lock` holds their
exact versions. In the root `Cargo.toml`, `recipher` and `cllw-ore` are
pinned with `=`. `cts-common` and `zerokms-protocol` take caret
requirements, because the published `stack-auth` inherits them, and an
exact pin would stop the suite sharing one `cts-common` with it.

- **Three Cargo workspaces, not one.** The root workspace (the six stack-*
crates and the three node binding crates), protect-ffi's and EQL's. The root
Expand Down
4 changes: 2 additions & 2 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -68,8 +68,8 @@ incremental = true
# but cannot subtract them, and `stack-kms` / `stack-encrypt` need stack-auth
# without `http`. Consumers that want the default transport re-enable it with
# `features = ["http"]`.
stack-auth = { path = "./packages/stack-auth", version = "0.42.3", default-features = false }
stack-profile = { path = "./packages/stack-profile", version = "0.42.3" }
stack-auth = { path = "./packages/stack-auth", version = "0.43.0", default-features = false }
stack-profile = { path = "./packages/stack-profile", version = "0.43.0" }

# Suite crates, from crates.io; Cargo.lock holds the exact versions.
# cts-common and zerokms-protocol take caret requirements because the
Expand Down
4 changes: 2 additions & 2 deletions languages/golang/stackauth/guest/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions languages/golang/stackencrypt/guest/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

54 changes: 54 additions & 0 deletions packages/stack-auth/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,58 @@

## [0.43.0] - 2026-10-02


### ⚠ Breaking changes

- `RequestError`'s tuple payload is now `Box<dyn std::error::Error + Send + Sync + 'static>` instead of `reqwest::Error`. Construct it with `RequestError::from(reqwest_error)` (or box the error yourself) instead of `RequestError(reqwest_error)`, and recover the concrete error with `.0.downcast_ref::<reqwest::Error>()` instead of using `.0` as a `reqwest::Error` directly. `source()` is unchanged; the `Display` message is now "Request to the auth server failed" (it was "HTTP request failed").
- `DeviceClientError::Request` now carries a `RequestError` rather than a `reqwest::Error`; a match on that variant's payload changes type.
- `From<reqwest::Error> for AuthError` is removed. Every reqwest failure enters the crate through `ReqwestTransport` as a `RequestError`; a caller that lifted a `reqwest::Error` into `AuthError` directly should wrap it in `RequestError` (`AuthError::Request(RequestError(Box::new(e)))`) or, better, send through the transport.
- Depends on `cts-common` 0.43 (vitaminc 0.5) and `zerokms-protocol` 0.12.31, from crates.io. `Crn` (re-exported here), `Region`, `WorkspaceId` and the `cts-common` errors in this crate's API are `cts-common` 0.43 types, so a caller that passes them in needs `cts-common` 0.43 too.

### CI

- mutation-testing gate for stack-auth and stack-encrypt (cargo-mutants --in-diff)

### Documentation

- correct stale StaticTokenStrategy comments in Cargo manifests

### Features

- build stack-auth, stack-kms and stack-encrypt for WASI without reqwest
- classify credential rejections where the variants live
- a workspace CRN is reachable without reaching for cts-common
- an HTTP transport trait mirroring the guest's host import, reqwest behind `http`
- add Go credential strategies

### Fixes

- address review findings on the http feature split
- address Copilot review on error Display strings
- test modules keep a literal `cfg(test)` so the CRAP gate skips them; add the npm changeset
- the wire types print nothing secret, wipe their headers, and lend reqwest the body
- satisfy credential guest CI
- lock only device refresh
- never replay a spent refresh token after a failed save
- identify every auth request with a user-agent

### Miscellaneous

- per-crate rustdoc gates for the stack crates, fanned out by `doc`
- move to cipherstash/stack with its history: the first release from that repository's `release-plz.yml`, in a version group with stack-profile alone

### Refactoring

- replace crate-wide no-http allow(dead_code) with item-level http gates

### Testing

- pin mutation regression behavior
- cover remaining mutation paths
- address PR review findings
- keep browser launcher mutable
- address review notes on assertion messages

## [0.42.3] - 2026-08-26


Expand Down
2 changes: 1 addition & 1 deletion packages/stack-auth/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
[package]
name = "stack-auth"
description = "Authentication library for CipherStash services"
version = "0.42.3"
version = "0.43.0"
edition.workspace = true
authors.workspace = true
repository.workspace = true
Expand Down
4 changes: 2 additions & 2 deletions packages/stack-auth/fuzz/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions packages/stack-encrypt/fuzz/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions packages/stack-kms/fuzz/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

12 changes: 12 additions & 0 deletions packages/stack-profile/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,18 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0



## [0.43.0] - 2026-10-02

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking, and the problem was there before this PR. Above this entry there is a ### Fixes / ### Documentation block that has no version heading (atomic ProfileStore writes, refresh-token rotation, the 0.34.0-alpha.1 header fix). Before this PR, that block was above 0.42.3. Now it is above 0.43.0. In Keep a Changelog layout, a reader thinks that a block above the newest version is not released yet. But these fixes were released in an earlier version. You can move the block under the correct version heading, or delete it. You can also do this in a follow-up PR.



### Features

- the crate builds for wasm32-wasip1, and names the lock file's path

### Miscellaneous

- per-crate rustdoc gates for the stack crates, fanned out by `doc`
- move to cipherstash/stack with its history: the first release from that repository's `release-plz.yml`, in a version group with stack-auth alone. No change to the API; the version follows stack-auth's breaking release

## [0.42.3] - 2026-08-26


Expand Down
2 changes: 1 addition & 1 deletion packages/stack-profile/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name = "stack-profile"
description = "Centralised ~/.cipherstash profile file management"
license-file = "LICENSE"
version = "0.42.3"
version = "0.43.0"
edition.workspace = true
authors.workspace = true
repository.workspace = true
Expand Down
Loading