diff --git a/CHANGELOG.md b/CHANGELOG.md index 9cff3e6..63b6a1a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,7 +1,11 @@ # changelog +Reconstructed from git history for everything up to `v0.1.1`; kept by hand from there. + ## unreleased +Two months of work since `v0.1.1` (2026-06-18). Headlines: + - **fix**: bump zat to `v0.4.3`, which makes `Mst.collectBlocks` emit the block for an empty MST node instead of mistaking it for an unloaded stub and skipping it. Two repos on pds.zat.dev carried empty subtree nodes minted by a pre-`v0.3.19` writer whose blocks @@ -15,3 +19,62 @@ - **ops**: repaired the three stranded empty MST nodes in the `zat.dev` repo with forward create/delete commits. Its served root now matches a canonical rebuild of its keyset. No history was rewritten. +- **feat**: permissioned data (spaces) brought in line with the proposal — the simplespace + authority split, `com.atproto.space.getRepoState`, `space:` OAuth scopes end to end, + aligned credential and sync semantics, scoped self reads in external spaces, portable + repo exports, and blob-ref tracking for permissioned records. +- **feat**: resident account surfaces — a create-account flow at `/signup` with invite CTA, + the resident account hub, app-password and passkey management, account takedown status, + and hosted handle resolution/updates with a hardened lifecycle. +- **feat**: firehose account announcements for new and pre-existing commit-less accounts; + `community.lexicon.service.describe` capability discovery. +- **fix**: firehose subscriptions start at the live cursor, disconnected workers are + released, and backfill slots are released on catch-up rather than on disconnect. +- **fix**: email verification separated from email change. +- **perf**: bounded blob garbage collection, repo exports isolated from primary storage, + lazily buffered request-body streaming, bounded threaded-I/O worker growth, no global + store stalls during blob I/O, and database lock-contention owners identified in logs. +- **fix**: OAuth client documents cached, expired access tokens advertised, and codes + preserved across DPoP challenges. +- **fix**: repo correctness — `zat.signCommit` for commits, complete imported CARs + required, full repo export reachability, and the `HEAD getRepo` response path. +- **ops**: deploy to fly on push to main via spindle; docker arm build arch mismatch and + the webauthn dependency fetch fixed. +- **deps**: moved onto the canonical first-party websocket/httpz/zat graph, with zat pinned + by release tag. + +## 0.1.1 — 2026-06-18 + +- **fix**: OAuth DPoP token families hardened, and token/code grant failures logged. +- **perf**: lazy MST loading for repo writes. +- **fix**: firehose commit `since` rev, advertised repo and sync parameters honored. +- **fix**: repo block and OAuth token migration ordering; sync event rebuild bounded in + memory and its migrations cleaned up. + +## 0.1.0 — 2026-06-16 + +- **feat**: OAuth DPoP binding. +- **feat**: Comail mail provider, with operator documentation. +- **fix**: handle large `applyWrites` bodies. +- **feat**: expanded PDS benchmark coverage. + +## 0.0.3 — 2026-06-10 + +- **feat**: port and database path configurable from the environment. + +## 0.0.2 — 2026-06-10 + +First tagged release. The initial PDS surface, built up from a Zig smoke harness on +2026-05-19: + +- SQLite-backed record store, real repo write commits, per-account signing keys, and the + `subscribeRepos` firehose. +- Reference-shaped account creation with invite-code gating; PLC operation signing, + migration identity endpoints, repo import backbone, and per-account PLC repair recovery. +- Full atproto OAuth flow — private-key clients, permission sets, query-form repo scopes, + passkey login (including discoverable), and app-password lifecycle with its security UI. +- Permissioned spaces with permission sets, plus a resident viewer and operator + diagnostics. +- Resident landing page and preferences, app-view notification and moderation surfaces, + Resend-backed mail delivery, generated API reference, Fly deployment config, and + benchmark suites (local store, metastore-shaped, HTTP route, reference-PDS parity).