diff --git a/CHANGELOG.md b/CHANGELOG.md index d966ba0..710d10d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,21 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). ## [Unreleased] +## [0.5.0] - 2026-01-08 + +### Added + +- **Direct OAuth authorization** without requiring Pushed Authorization Requests (PAR) + - `/oauth/authorize` now accepts direct query parameters (client_id, redirect_uri, code_challenge, etc.) + - Creates authorization request record on-the-fly, same as PAR flow + - DPoP binding deferred to token exchange time for direct auth flows + - Matches official AT Protocol PDS behavior + +### Changed + +- AS metadata: `require_pushed_authorization_requests` now `false` +- Extracted `validateAuthorizationParameters()` helper shared between PAR and direct auth + ## [0.4.0] - 2026-01-08 ### Added diff --git a/package.json b/package.json index c815832..1989556 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "pds.js", - "version": "0.4.0", + "version": "0.5.0", "private": true, "type": "module", "scripts": { diff --git a/src/pds.js b/src/pds.js index 62ad7c0..a638b5f 100644 --- a/src/pds.js +++ b/src/pds.js @@ -32,7 +32,7 @@ // ╚══════════════════════════════════════════════════════════════════════════════╝ // PDS version (keep in sync with package.json) -const VERSION = '0.4.0'; +const VERSION = '0.5.0'; // CBOR primitive markers (RFC 8949) const CBOR_FALSE = 0xf4;