diff --git a/CHANGELOG.md b/CHANGELOG.md index a70cfdd..e03ad35 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,12 +6,31 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). ## [Unreleased] +## [0.2.0] - 2026-01-07 + +### Added + +- **OAuth 2.0 authorization server** with full AT Protocol support + - Discovery endpoints (AS metadata, protected resource, JWKS) + - Pushed Authorization Requests (PAR) + - Authorization endpoint with dark-themed consent UI + - Token endpoint (authorization_code + refresh_token grants) + - Token revocation (RFC 7009) + - DPoP proof validation and token binding + - PKCE with S256 code challenge + - Client metadata fetching and validation + - Loopback client support for development +- DPoP JTI tracking to prevent replay attacks +- Comprehensive OAuth e2e tests + ### Changed - **BREAKING:** Normalized SQL schema to snake_case convention - Tables: `blob` → `blobs`, `record_blob` → `record_blobs` - Columns: `mimeType` → `mime_type`, `createdAt` → `created_at`, `blobCid` → `blob_cid`, `recordUri` → `record_uri` - Existing Durable Objects require storage reset +- Consolidated error responses to use `errorResponse` helper +- Moved OAuth types to TYPES & CONSTANTS section ## [0.1.0] - 2025-01-07 diff --git a/package.json b/package.json index a6615ec..a2ff6b0 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "pds.js", - "version": "0.1.0", + "version": "0.2.0", "private": true, "type": "module", "scripts": {