Version 0.6.7 Features and noteworthy implementation changes: - OAuth tokens now get their scopes, collapsed into the minimal equivalent set and brotli compressed to minimise the size of tokens. Thanks lou.gg (did:plc:w64dlsa4zwjv2wljlvmymldc)! - Update getServiceAuth to support the new aud parameter as per proposal 0014 (https://github.com/bluesky-social/proposals/tree/main/0014-service-auth-revised). Thanks lou.gg (did:plc:w64dlsa4zwjv2wljlvmymldc)! - Second OAuth flow and consent screen overhaul to better support transitional scopes, and to be more robust to erroneous or nonsensical scope requests. Thanks trezy.codes (did:plc:4jrld6fwpnwqehtce56qshzv)! - The S3 blob storage backend now supports a path config parameter. Thanks calico.lgbt (did:plc:qthgnl7ryv5fmh6lnssdmo6w)! - Unified various in-mem caches into the PDS cache. - Tranquil now serves on-demand TLS responses suitble for Caddy under `/.well-known/caddy/ask`.
Bug fixes: - Fix the URI parsing to support non-authority URIs. Thanks jack.is (did:plc:cwdkf4xxjpznceembuuspt3d)! - Restore RPC scopes for delegation presets. Thanks trezy.codes (did:plc:4jrld6fwpnwqehtce56qshzv)! - Keep blob ownership per user so we don't risk deleting an in-use blob that's used by multiple people. Thanks jola.dev (did:plc:bvraa6gajy4tfr3eh2sisdkr)! - Add MIME version to out going emails as mandated by RFC 2045. Thanks luna.pds.devcat.one (did:plc:qij7bjzgwlshfr2fljkjd7gc)! - Loosen CORS header requirements to be more flexible to apps adding unexpected headers. Thanks jola.dev (did:plc:bvraa6gajy4tfr3eh2sisdkr)! - Don't accidentally block migrations by denying signPlcOperation requests that remove the PDSs rotation keys.
Version 0.6.5
- (PR#175) Authenticated Bluesky feedgens now work properly. Thank you to @ave.zone (did:plc:mchrltkrhuzpxleiwpmmvpar). - (PR#162) putRecord without a $type now pulls the type off of the collection instead of failing. - tranquil-store now has some MST self healing features.
- Firehose no longer drops events when sequence numbers commit out of order. - Migration follows the oauth account:* spec (ie. *don't* use that lol) and supports p256 keys. - Nix data storage paths now default off the dataDir option. - TlsConfig rejects unknown keys, and the toolchain moves to rust 1.96.