Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,14 @@
# Changelog

## 2.5.1 - Unreleased
## 2.5.1 - 2026-08-09

- Restore ES256 DPoP key generation on OpenSSL 3.6 while asserting that the
generated named curve remains P-256 (`prime256v1`).
- Run PHPStan with an explicit bounded memory limit for reproducible local and
CI verification on smaller development machines.
- Remove duplicate PHPDoc annotations from the ID/logout-token validator; no
public API or protocol behavior changes.
- Point the Composer development alias at the canonical `main` branch.

## 2.5.0 - 2026-08-01

Expand Down
4 changes: 2 additions & 2 deletions COMPATIBILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@

| SDK line | PHP | Identity contract | Laravel adapter | Status |
|---|---|---|---|---|
| 2.5.x | 8.2–8.4 | `^2.0` | `identity-laravel ^2.5` | Current |
| 2.0.x | 8.2–8.4 | `^2.0` | `identity-laravel ^2.0` | Security fixes only |
| 2.5.x | 8.2–8.5 | `^2.0` | `identity-laravel ^2.5` | Current |
| 2.0.x | 8.2–8.5 | `^2.0` | `identity-laravel ^2.0` | Security fixes only |
| 1.2.x | 8.2–8.4 | `^1.1` | Application integration | Migration only |

The high-assurance profile requires server metadata and client registration for
Expand Down
41 changes: 41 additions & 0 deletions RELEASE-2.5.1-CHECKLIST.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
# Identity SDK PHP 2.5.1 release checklist

Release date: 2026-08-09

## Scope

This is a backward-compatible patch release for the 2.5 line. It restores
P-256 DPoP key generation on OpenSSL 3.6, keeps verification within a bounded
memory budget and removes duplicate internal PHPDoc annotations. It does not
change public classes, method signatures, claims, algorithms, endpoints or
wire formats.

## Candidate gate

- [ ] The release PR is approved and every required GitHub check passes.
- [ ] `composer install` resolves only published stable dependencies.
- [ ] `composer verify` passes from a clean checkout.
- [ ] The Quality matrix passes on PHP 8.2, 8.3, 8.4 and 8.5.
- [ ] `DpopKeyTest` proves the generated EC key remains `prime256v1` / P-256.
- [ ] Back-Channel Logout, ID token, PAR, JARM, DPoP, RFC 9207 and workload
validation tests remain green.
- [ ] `composer audit` reports no advisories.
- [ ] `CHANGELOG.md`, `COMPATIBILITY.md` and release notes agree on scope.

## Immutable publication

Run these steps only from the reviewed commit on `main`:

```bash
git switch main
git pull --ff-only origin main
composer install --no-interaction --prefer-dist
composer verify
git tag -a v2.5.1 -m "Novvor Identity SDK PHP v2.5.1"
git push origin v2.5.1
gh release create v2.5.1 --verify-tag --title "Novvor Identity SDK for PHP 2.5.1" --notes-from-tag
```

Never move or recreate the tag. If a defect is found after publication, create
a new patch version. Consumer lockfiles must remain unchanged until their own
integration and deployment evidence passes.
2 changes: 1 addition & 1 deletion composer.json
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
},
"extra": {
"branch-alias": {
"dev-codex/identity-sdk-2": "2.5.x-dev"
"dev-main": "2.5.x-dev"
}
},
"minimum-stability": "stable",
Expand Down
14 changes: 9 additions & 5 deletions docs/RELEASE_2_5_PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ Date: 2026-08-01
| `novvor/identity-contracts` v2.0.0 | Published baseline |
| `novvor/identity-sdk-php` v2.0.0 | Published baseline |
| SDK 2.5 core | Immutable `v2.5.0` tag exists; GitHub release record pending |
| SDK 2.5.1 compatibility patch | Release candidate; tag and release pending |
| First-party Laravel adapter | `v2.5.1` tagged with durable encrypted login intents |
| Platform and FilaSign runtime upgrade | Not yet validated against 2.5 |
| Console v1-to-v2 migration | Not started |
Expand Down Expand Up @@ -37,14 +38,17 @@ consumer-rollout approval.
## Consumer order

1. Publish a GitHub release record for the existing immutable SDK `v2.5.0` tag
after attaching the successful core-gate evidence; never retag it.
2. Retain the Laravel adapter's durable-login-intent transaction lifecycle as
after attaching its successful core-gate evidence; never retag it.
2. Publish `v2.5.1` from the reviewed release-candidate SHA after the checklist
in `RELEASE-2.5.1-CHECKLIST.md` passes. This patch restores OpenSSL 3.6
compatibility and does not alter OIDC contracts.
3. Retain the Laravel adapter's durable-login-intent transaction lifecycle as
the single supported Laravel boundary.
3. Upgrade Enix Platform and FilaSign in independent branches; run their
4. Upgrade Enix Platform and FilaSign in independent branches; run their
browser and negative callback flows against the new package.
4. Migrate Enix Console from `^1.1` to `^2.5` in a separate review because it
5. Migrate Enix Console from `^1.1` to `^2.5` in a separate review because it
is an authentication-boundary change, not a dependency bump.
5. Verify each deployment independently before the next consumer is changed.
6. Verify each deployment independently before the next consumer is changed.

## Rollback

Expand Down
3 changes: 0 additions & 3 deletions src/Oidc/IdTokenValidator.php
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,6 @@ public function __construct(private readonly ClientInterface $http)
{
}

/** @return array<string, mixed> */
/** @return array<string, mixed> */
public function validate(OidcClientConfiguration $configuration, string $idToken, ?string $expectedNonce = null, ?string $correlationId = null): array
{
Expand Down Expand Up @@ -91,7 +90,6 @@ private function assertIssuerAndAudience(OidcClientConfiguration $configuration,
}
}

/** @return array<string, mixed> */
/** @return array<string, mixed> */
private function jwks(string $uri, int $timeoutSeconds, bool $refresh, ?string $correlationId): array
{
Expand All @@ -111,7 +109,6 @@ private function jwks(string $uri, int $timeoutSeconds, bool $refresh, ?string $
return $this->jwksByUri[$uri] = $jwks;
}

/** @return array{0: array<string, mixed>, 1: array<string, mixed>} */
/** @return array<string, mixed> */
private function decodeHeader(string $token): array
{
Expand Down
Loading