Note that 0.X.X releases are reverved for the beta version of the server and may include breaking changes.
- [infra] published container images include provenance attestations
- [auth][ssi] universal keys can be created for oauth client id token and verifiable credentials signing
- [admin] client forms display the JWT authentication public key field for EC signing algorithms
- [cli] configuration file uploads accept release-local file paths
- [gateway] invalid TLS handshakes no longer stop HTTPS gateway acceptors
- [ssi] credential status token resolution verifies tokens against client DIDs
- [wallet] imported credentials are encrypted in local storage
- [admin] token dashboard provides issuance charts, filtering, full-text search, token-chain details, claim inspection, and revocation controls
- [admin] administration interface supports selectable Boruta, Gruvbox, and Nord themes
- [cli]
borutaandboruta_adminreleases include a YAML command-line interface for administration resources - [gateway] native Phi model trains noise detection with degree-one and sparse degree-two terms over OpenAPI request contexts
- [gateway] Phi request matching treats the root path as legal for every HTTP method
- [gateway] Phi noise detection evaluates unmatched paths across the entire gateway
- [gateway] Phi prediction accepts bounded recency-decayed request memory as context
- [gateway] Phi memory can classify otherwise legal requests as contextual noise
- [gateway] upstreams can train and apply noise cancellation from transient OpenAPI uploads while storing only the Phi binary
- [infra] Disable file logging configuration environment variable
- [admin] token dashboard and API default to tokens issued since the beginning of the current hour
- [admin] request and business event dashboards and log API default to the current UTC hour
- [admin] sidebar sections reflect authorized scopes and remain expanded across nested dashboard routes
- [admin] remove the redundant
roles:manage:allscope from new installations and administration scope requests - [admin] new OAuth clients default to confidential
- [admin] credential presentation template actions use clearer wording
- [admin] coalesce concurrent logout token revocations
- [admin] resource activity refreshes when navigating between routes
- [admin] fix sidebar upstream navigation
- [admin] form fields wrap correctly on mobile viewports
- [auth] log oauth revocation requests subject
- [infra] include the database migration that defaults OAuth clients to confidential
- [admin] token administration responses omit token values and other reusable secrets
- validate DID public clients against the issuer, registered redirect URIs, and supported grant types
- require secret authentication for client and agent credentials grants and introspection, including public clients
- allow decentralized non-confidential public-client grants without a secret only when issuer-bound
- [admin] form save buttons show loading states and prevent duplicate submissions
- [admin] request and business event dashboards support text search across log messages
- [admin] current node upstream panel items link to their edit pages
- [gateway] service registry CAs remain separate from the VM-wide system CA trust store
- [admin] user identifiers exact match search
- [admin] upstream node listing ignores failed cluster RPC responses
- [ssi] fix outbound did requests TLS
- [ssi] fix id token redirection scope forwarding
- [ssi] fix vp token redirection scope forwarding
- [infra] daily log rotation reconfigures logger backends on every clustered node
- [admin] request log parsing handles microsecond durations consistently with Erlang/OTP 29
- [infra] fix startup database migrations updating jose dependency
- [infra] example Docker Compose services use the Kagome alpha.6 image
- [admin] administration API actions emit privacy-preserving business events with actor, resource, allowlisted change, and failure attributes
- [admin] resource edit pages display resource activity history alongside configuration tabs
- [admin] user activity includes administration events and refreshes when the activity tab opens
- [admin] user searches accept exact user identifiers
- [admin] resource form submissions execute once
- [infra] administration client seed enables the implicit and revoke grant types
- [admin] user administration displays last login and detailed user activity history with selectable retention periods
- [web] business event logs include direct post successes and failures and credential issuance
- [admin] request dashboard graphs display the 50 most frequent labels and group the remainder as
Other - [infra] development applications write to a shared, configurable log directory
- [infra] container images use Elixir 1.20, Erlang/OTP 29, and Alpine Linux, with OTP 29-compatible X509 and SMTP dependencies
- [admin] user activity correlates authorize, token, credential, and identity events consistently by user ID
- [web] pre-authorized code credential offers emit authorize business events
- [infra] target latest Elixir docker images mitigating supply chain issues
- [gateway] upstreams can use HTTP Basic authentication
- [admin] clients can configure trusted hosts and trusted authorities
- [admin] request dashboard logs can be filtered by HTTP status and request method
- [infra] minimum supported Elixir version is 1.15
- [auth] API rate limiting defaults to 10 requests per second
- [admin] request and business event dashboards default to the last hour with minute-scale graphs
- [admin] example verifiable credential configuration no longer restricts issuance by scope
- [admin] organization creation and dark theme layouts are improved
- [admin] user pagination links navigate correctly
- [admin] tables and upstream details display correctly in dark mode
- [auth] Boruta dependency database migrations run correctly
- [identity] identity provider updates invalidate cached client identity provider configuration
- [infra] update the Plug dependency to address query and multipart parsing vulnerabilities and unsafe cookie attributes (CVE-2026-54892, CVE-2026-56813, CVE-2026-56814)
- [auth] update the Boruta dependency to reject expired JWT client assertions (CVE-2026-53431)
- [auth] update the Boruta dependency to prevent dynamic registration from creating over-privileged clients (CVE-2026-65635)
- [auth] update the Boruta dependency to prevent SSRF through remote URI fetching (CVE-2026-54885)
- [admin] prevent request values from creating unbounded atoms
- [gateway] omit URL query and fragment details from request logs
- [gateway] enforce strict request framing to prevent pipelined requests and request bodies from bypassing authorization
- [gateway] bound request headers, idle connections, and TLS handshakes to prevent gateway acceptor exhaustion
- [gateway] mounted certificate and private key files can configure HTTPS gateway certificates
- [gateway] forward proxy requests appear in request logs
- [gateway] compilation warnings
- [wallet] credentials view navigation
- [wallet] service worker cache reloads after application updates
- [admin] example links
- [wallet] credential issuance encrypts credentials correctly
- [wallet] credential issuance inserts credential consent
- [admin] upstream security settings are displayed more clearly
- [infra] Kubernetes deployment manifests are improved
- [admin] gateway request logs are displayed
- [admin] client identity provider associations are saved correctly
- [ssi] credential issuance fetches resource owner configuration correctly
- [gateway] HTTP and HTTPS forward proxies
- [gateway] HTTPS gateway and sidecar listeners
- [gateway] service registry root CA and node certificate generation
- [gateway] service registry records expose node gateway and proxy listener configuration
- [gateway] service registry records expose certificate paths and node certificates
- [gateway] gateway listeners can be configured with
BORUTA_GATEWAY_SERVERandBORUTA_GATEWAY_SIDECAR - [gateway] upstreams can require mTLS
- [gateway] static configuration supports node aliases
- [admin] service registry node upstreams are displayed in the upstreams section
- [admin] gateway and proxy configuration is folded in service registry records
- [auth] EPMD cluster hosts can be configured with
LIBCLUSTER_HOSTS - [infra] docker compose runs multiple Boruta nodes with static gateway configuration
- [gateway] mesh proxy traffic routes through service registry records
- [admin] upstream creation and edition use service registry records
- [infra] release node distribution and cookie can be configured with environment variables
- [gateway] service registry database notifications remain small when records include certificates and configuration
- [openid] integration tests for OID4VCI credential issuance and OID4VP direct post flows
- [wallet] (breaking) credentials and key selection use password-protected local storage
- [gateway] URI strip rewriting only updates the request-line path
- [auth] prompt and request object claims are validated before public client flows
- [auth] prompt none requires a preauthenticated user
- [auth] max age parameters must parse completely
- [auth] WebAuthn state is cleared after authorization errors
- [gateway] upstream TLS hostname verification
- [gateway] HEAD request forwarding
- [gateway] upstream matching ignores query strings and uses the longest matching upstream URI
- [gateway] Authorization headers match bearer token schemes case-insensitively
- [gateway] upstream store notifications are deduplicated
- [gateway] malformed Content-Length responses are handled safely
- [identity] auth flow state is cleared on logout
- [identity] auth return query parameters are parsed correctly
- [identity] sessions are marked chosen after user selection
- [gateway] upstreams can rate-limit traffic
- [gateway] request and business event history in the administration dashboard
- [admin] administrators can see user identifiers in user lists
- [infra] operators can benchmark OAuth grants and gateway requests
- [infra] request count documentation for OAuth and OpenID4VC flows
- [auth] OAuth acceptor count can be configured and defaults to 8
- [gateway] gateway acceptor count can be configured
- [gateway] authorization returns clearer OAuth error responses
- [gateway] upstream authorization includes configured scopes
- [gateway] keepalive tuning is removed from gateway configuration
- [infra] deployment secrets are provided through environment variables
- [admin] gateway configuration fields are easier to read
- [admin] user displays prefer usernames over emails
- [admin] verifiable credential array claims can be deleted
- [admin] feedback form
- [admin] gateway dashboard request times graph
- [gateway] upstream routes match paths correctly
- [gateway] empty forwarded token headers are ignored
- [gateway] successful requests appear in logs
- [identity] users are redirected correctly after federated sign in
- [identity] federation error pages render correctly
- [admin][identity] upgrade vulnerable npm packages
- [auth] OAuth token state values are handled without atom exhaustion risk
- [gateway] reduce exposure of local runtime artifacts in container builds
- [gateway] malformed requests are handled more safely
- [identity] user settings values are handled without atom exhaustion risk
- [identity] development environment defaults are sanitized
- [infra] aggregate log responses are size-limited
- [infra] redact OAuth credentials from logs
- [infra] remove local deployment secrets
- [web] close presentation SSE streams when clients disconnect
- [web] require secure cookies
- [ssi] code chains
- verify verifiable presentation from code chains
- issuance code chains
- next flow redirection in case of presentation success
- agent token management
- [ssi] code metadata policies
- restrict issuance / presentation key usage for enabled check public client id clients
- [ssi] server sent events verifiable presentation page navigation
- [identity] add resource owner in credentials templates
- [ssi] credential issuance scope restriction
- [wallet] display credential presentation purposes
- [admin] home page selective login
- [ssi] remove resource owner constraint for openid4vc flows
- [ssi] default backend authorization details for anonymous users
- [ssi] issuance / presentation default templates open integrated wallet in a popup
- [ssi] add client_id to credential offers
- [identity] improve identity providers querying and cache
- [admin] group direct post requests in dashboard
- [infra] rate limit boruta identity requests
- [admin] set backend as default in example configuration
- [admin] improve administration login
- [ssi] local did creation / resolution
- [infra] database pool management
- [admin] add credential offer and presentation in breadcrumb
- [admin] update identity provider title in breadcrumb
- [admin] feedback stars display
- [wallet] qr code scan redirection
- [ssi] public and unknown users presentation
- [infra] halt request on 429 rate limit response
- [admin] fix key pair management display
- [admin] only expose client name in templates
- [auth] remove default client secret from seeds
- [admin] set minimum oauth client private key modulus size
- [auth] set 2048 as minimum rsa keys modulus
- [auth] agent credentials / code flows
- [wallet] key selection
- [ssi] verify public client id oauth client option
- [auth] max authorization code ttl to 600 seconds
- [ssi] remove authentication on siopv2 flow
- [admin] file upload text editor update
- [ssi] expose public credential configuration for authenticated users
- [wallet] fix presentation duplicates
- [auth] experimental request rate limiting
- [auth] remove dynamic client registration
- [auth] fix boruta core migration
- [ssi] do not use ES256 alg to verify EdDSA JWTs
- [identity] expose default templates static assets
- [admin] signatures adapter
- [wallet] display an error when no credential match presentation
- [identity] add reload button in credentials temapltes
- [wallet] close qr code scanner on click
- [wallet] fix npm vulnerabilities
- [admin] fix npm vulnerabilities
- [admin] update verifiable presentations default template
- [identity] passwordless user creation (WIP)
- [identity] destroy user
- [ssi] transaction code in OID4VCI preauthorized code flow
- [ssi] vct configuration in verifiable credentials
- [admin] feedback form
- [wallet] web identity wallet bootstrap (PWA)
- [identity] scope user emails per backend
- [admin] decentralized identity example flows
- [ssi] verifiable credentials nested claims
- [identity] remove user metadata value constraints
- [admin] verifiable credentials claim format
- [admin] defered configuration
- [admin] example credential issuance link
- [ssi] oauth clients did persistence
- [admin] verifiable presentation definition text edition
- [admin] remove cdnjs dependency
- [identity] remove picsum dependency
- [admin] user csv import metadata
- [infra] organization creation in static configuration
- [admin] client key pair configuration + support for EC keys
- [ssi] several verifiable credentials issuance and presentation fixes
- [auth] configurable status display in id_token claims
- [admin] user with empty metadata save
- [admin] federated users deletion
- [ssi] OpenID for Verifiable Credentials Presentation implementation
- [auth] fix authorize entrypoint
- [admin] ipv6 log display
- [infra] remove .env.example.sig as suspicious file
- [ssi] Configurable verifiable credentials issuance with oid4vci implementation
- [ssi] Siopv2 same device implementation
- [auth] Demonstration proof of possession implementation
- [auth] Pushed Authorization Request implementation
- [infra] Server ip address bindings configuration via environment variables
- [infra]Infrastructure as Code with static file configuration
- [admin] Admin ui improvements
- [auth] Better identity federation
- [identity] Webauthn integration
- [infra] Remote IP logging
- [admin] instance authenticated admins are sub or organization restricted
- [infra] Fix organization and sub admin access restriction
- [identity] user organisation management
- [identity] TOTP second factor support
- [identity] user roles management
- [infra] split auth/admin/gateway/all docker images
- [infra] split gateway, admin, auth releases
- [infra] system wide installation script
- [infra] gather statistical info on installation
- [gateway] introspected token forwarding to updatreams
- [identity] email templates edition
- [identity] configure, expose and edit user metadata
- [identity] user metadata configuration
- [gateway] static configuration
- [gateway] microgateways
- [identity] identity federation (login with button)
- [auth] better well-known openid configuration
- [auth] dynamic client registration
- [auth] client authentication methods configuration
- [auth] global signing key pairs
- [identity] invalidate user reset password token at use
Initial beta release