diff --git a/CHANGELOG.md b/CHANGELOG.md index 18d509c..4bdce14 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,30 @@ # changelog +## 0.3.28 + +OAuth requests can be pinned to validated addresses, DPoP nonces are optional, +and identity resolution rejects the full special-purpose address space. + +- **feat**: OAuth requests accept an optional `resolved_connection`, carrying + the `HttpTransport.ResolvedConnection` already produced during identity + resolution through PAR, token exchange, refresh, and arbitrary DPoP requests. + Connecting to the addresses that were validated, rather than re-resolving the + host, closes a DNS-rebinding window between the safety check and the request. + `discoverAuthorizationServerResolved` and + `fetchAuthorizationServerMetadataResolved` take the pin explicitly; the + existing `discoverAuthorizationServer` and `fetchAuthorizationServerMetadata` + are unchanged wrappers that pass `null`. +- **fix**: a DPoP nonce is no longer required. Previously any server that never + issued a `DPoP-Nonce` header failed with `MissingDpopNonce`; the nonce is now + retained until replaced and only demanded when the server actually issues a + `use_dpop_nonce` challenge. +- **fix**: identity resolution rejects the IETF special-purpose ranges it + previously allowed — CGNAT `100.64.0.0/10` (including the cloud-metadata + address `100.100.100.200`), `192.0.0.0/24`, TEST-NET, benchmarking, + `192.88.99.0/24`, multicast, and reserved space. IPv6 now requires globally + routed unicast, carving out `2001::/23`, `2001:db8::/32`, and `2002::/16`; + IPv4-mapped addresses inherit the full IPv4 policy. + ## 0.3.27 Reconnect backoff resets after a connection that was established. diff --git a/build.zig.zon b/build.zig.zon index d8a808e..4704036 100644 --- a/build.zig.zon +++ b/build.zig.zon @@ -1,6 +1,6 @@ .{ .name = .zat, - .version = "0.3.27", + .version = "0.3.28", .fingerprint = 0x8da9db57ee82fbe4, .minimum_zig_version = "0.16.0-dev.3070+b22eb176b", .dependencies = .{