diff --git a/CHANGELOG.md b/CHANGELOG.md index 40e9752..0848212 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,11 +1,14 @@ # Changelog -## 2.5.1 - Unreleased +## 2.5.1 - 2026-08-09 - Restore ES256 DPoP key generation on OpenSSL 3.6 while asserting that the generated named curve remains P-256 (`prime256v1`). - Run PHPStan with an explicit bounded memory limit for reproducible local and CI verification on smaller development machines. +- Remove duplicate PHPDoc annotations from the ID/logout-token validator; no + public API or protocol behavior changes. +- Point the Composer development alias at the canonical `main` branch. ## 2.5.0 - 2026-08-01 diff --git a/COMPATIBILITY.md b/COMPATIBILITY.md index 340b6aa..3802580 100644 --- a/COMPATIBILITY.md +++ b/COMPATIBILITY.md @@ -2,8 +2,8 @@ | SDK line | PHP | Identity contract | Laravel adapter | Status | |---|---|---|---|---| -| 2.5.x | 8.2–8.4 | `^2.0` | `identity-laravel ^2.5` | Current | -| 2.0.x | 8.2–8.4 | `^2.0` | `identity-laravel ^2.0` | Security fixes only | +| 2.5.x | 8.2–8.5 | `^2.0` | `identity-laravel ^2.5` | Current | +| 2.0.x | 8.2–8.5 | `^2.0` | `identity-laravel ^2.0` | Security fixes only | | 1.2.x | 8.2–8.4 | `^1.1` | Application integration | Migration only | The high-assurance profile requires server metadata and client registration for diff --git a/RELEASE-2.5.1-CHECKLIST.md b/RELEASE-2.5.1-CHECKLIST.md new file mode 100644 index 0000000..cd36abf --- /dev/null +++ b/RELEASE-2.5.1-CHECKLIST.md @@ -0,0 +1,41 @@ +# Identity SDK PHP 2.5.1 release checklist + +Release date: 2026-08-09 + +## Scope + +This is a backward-compatible patch release for the 2.5 line. It restores +P-256 DPoP key generation on OpenSSL 3.6, keeps verification within a bounded +memory budget and removes duplicate internal PHPDoc annotations. It does not +change public classes, method signatures, claims, algorithms, endpoints or +wire formats. + +## Candidate gate + +- [ ] The release PR is approved and every required GitHub check passes. +- [ ] `composer install` resolves only published stable dependencies. +- [ ] `composer verify` passes from a clean checkout. +- [ ] The Quality matrix passes on PHP 8.2, 8.3, 8.4 and 8.5. +- [ ] `DpopKeyTest` proves the generated EC key remains `prime256v1` / P-256. +- [ ] Back-Channel Logout, ID token, PAR, JARM, DPoP, RFC 9207 and workload + validation tests remain green. +- [ ] `composer audit` reports no advisories. +- [ ] `CHANGELOG.md`, `COMPATIBILITY.md` and release notes agree on scope. + +## Immutable publication + +Run these steps only from the reviewed commit on `main`: + +```bash +git switch main +git pull --ff-only origin main +composer install --no-interaction --prefer-dist +composer verify +git tag -a v2.5.1 -m "Novvor Identity SDK PHP v2.5.1" +git push origin v2.5.1 +gh release create v2.5.1 --verify-tag --title "Novvor Identity SDK for PHP 2.5.1" --notes-from-tag +``` + +Never move or recreate the tag. If a defect is found after publication, create +a new patch version. Consumer lockfiles must remain unchanged until their own +integration and deployment evidence passes. diff --git a/composer.json b/composer.json index 813dbd9..ed6aab8 100644 --- a/composer.json +++ b/composer.json @@ -20,7 +20,7 @@ }, "extra": { "branch-alias": { - "dev-codex/identity-sdk-2": "2.5.x-dev" + "dev-main": "2.5.x-dev" } }, "minimum-stability": "stable", diff --git a/docs/RELEASE_2_5_PLAN.md b/docs/RELEASE_2_5_PLAN.md index 664609f..ce989de 100644 --- a/docs/RELEASE_2_5_PLAN.md +++ b/docs/RELEASE_2_5_PLAN.md @@ -9,6 +9,7 @@ Date: 2026-08-01 | `novvor/identity-contracts` v2.0.0 | Published baseline | | `novvor/identity-sdk-php` v2.0.0 | Published baseline | | SDK 2.5 core | Immutable `v2.5.0` tag exists; GitHub release record pending | +| SDK 2.5.1 compatibility patch | Release candidate; tag and release pending | | First-party Laravel adapter | `v2.5.1` tagged with durable encrypted login intents | | Platform and FilaSign runtime upgrade | Not yet validated against 2.5 | | Console v1-to-v2 migration | Not started | @@ -37,14 +38,17 @@ consumer-rollout approval. ## Consumer order 1. Publish a GitHub release record for the existing immutable SDK `v2.5.0` tag - after attaching the successful core-gate evidence; never retag it. -2. Retain the Laravel adapter's durable-login-intent transaction lifecycle as + after attaching its successful core-gate evidence; never retag it. +2. Publish `v2.5.1` from the reviewed release-candidate SHA after the checklist + in `RELEASE-2.5.1-CHECKLIST.md` passes. This patch restores OpenSSL 3.6 + compatibility and does not alter OIDC contracts. +3. Retain the Laravel adapter's durable-login-intent transaction lifecycle as the single supported Laravel boundary. -3. Upgrade Enix Platform and FilaSign in independent branches; run their +4. Upgrade Enix Platform and FilaSign in independent branches; run their browser and negative callback flows against the new package. -4. Migrate Enix Console from `^1.1` to `^2.5` in a separate review because it +5. Migrate Enix Console from `^1.1` to `^2.5` in a separate review because it is an authentication-boundary change, not a dependency bump. -5. Verify each deployment independently before the next consumer is changed. +6. Verify each deployment independently before the next consumer is changed. ## Rollback diff --git a/src/Oidc/IdTokenValidator.php b/src/Oidc/IdTokenValidator.php index 2d2e5cc..a9968af 100644 --- a/src/Oidc/IdTokenValidator.php +++ b/src/Oidc/IdTokenValidator.php @@ -16,7 +16,6 @@ public function __construct(private readonly ClientInterface $http) { } - /** @return array */ /** @return array */ public function validate(OidcClientConfiguration $configuration, string $idToken, ?string $expectedNonce = null, ?string $correlationId = null): array { @@ -91,7 +90,6 @@ private function assertIssuerAndAudience(OidcClientConfiguration $configuration, } } - /** @return array */ /** @return array */ private function jwks(string $uri, int $timeoutSeconds, bool $refresh, ?string $correlationId): array { @@ -111,7 +109,6 @@ private function jwks(string $uri, int $timeoutSeconds, bool $refresh, ?string $ return $this->jwksByUri[$uri] = $jwks; } - /** @return array{0: array, 1: array} */ /** @return array */ private function decodeHeader(string $token): array {