Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 12 additions & 1 deletion CHANGES.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,14 +15,26 @@ To be released.
- Added the `federationOptions` option to `createBot()` and
`createInstance()` for private-address access in tests, circuit breaking,
OpenTelemetry providers, and HTTP Signature negotiation. [[#41], [#43]]
- Changed [FEP-044f] quote authorization handling to use Fedify's
*@fedify/interaction-controls* package. Quote authorization stamps are
now checked against their owner's [FEP-fe34] origin, so stamps whose IDs
have no comparable origin, such as opaque URIs, are no longer accepted.
[[#52], [#53]]
- Fixed a bug where a remote server could approve a quote with a quote
authorization stamp other than the one named in its `Accept` activity,
as long as the substituted stamp was on the same origin. [[#52], [#53]]
- Upgraded Fedify to 2.4.0, which adds support for [FEP-ef61] portable
objects and hardens HTTP Signature verification and document loading.

[FEP-044f]: https://w3id.org/fep/044f
[FEP-fe34]: https://w3id.org/fep/fe34
[FEP-ef61]: https://w3id.org/fep/ef61
[#40]: https://github.com/fedify-dev/botkit/issues/40
[#41]: https://github.com/fedify-dev/botkit/issues/41
[#42]: https://github.com/fedify-dev/botkit/pull/42
[#43]: https://github.com/fedify-dev/botkit/pull/43
[#52]: https://github.com/fedify-dev/botkit/issues/52
[#53]: https://github.com/fedify-dev/botkit/pull/53


Version 0.5.6
Expand Down Expand Up @@ -294,7 +306,6 @@ Released on July 8, 2026.

- Upgraded Fedify to 2.3.1, Hono to 4.12.27, and LogTape to 2.2.3.

[FEP-044f]: https://w3id.org/fep/044f
[#16]: https://github.com/fedify-dev/botkit/issues/16
[#24]: https://github.com/fedify-dev/botkit/pull/24
[#27]: https://github.com/fedify-dev/botkit/issues/27
Expand Down
17 changes: 17 additions & 0 deletions changes.d/botkit/quote-authorization-verification.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
links:
'#52': https://github.com/fedify-dev/botkit/issues/52
'#53': https://github.com/fedify-dev/botkit/pull/53
---
- Changed [FEP-044f] quote authorization handling to use Fedify's
*@fedify/interaction-controls* package. Quote authorization stamps are
now checked against their owner's [FEP-fe34] origin, so stamps whose IDs
have no comparable origin, such as opaque URIs, are no longer accepted.
[[#52], [#53]]

- Fixed a bug where a remote server could approve a quote with a quote
authorization stamp other than the one named in its `Accept` activity,
as long as the substituted stamp was on the same origin. [[#52], [#53]]

[FEP-044f]: https://w3id.org/fep/044f
[FEP-fe34]: https://w3id.org/fep/fe34
1 change: 1 addition & 0 deletions deno.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
"imports": {
"@fedify/denokv": "jsr:@fedify/denokv@~2.4.0",
"@fedify/fedify": "jsr:@fedify/fedify@~2.4.0",
"@fedify/interaction-controls": "jsr:@fedify/interaction-controls@~2.4.0",
"@fedify/vocab": "jsr:@fedify/vocab@~2.4.0",
"@fedify/vocab-runtime": "jsr:@fedify/vocab-runtime@~2.4.0",
"@js-temporal/polyfill": "npm:@js-temporal/polyfill@^0.5.1",
Expand Down
69 changes: 66 additions & 3 deletions deno.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions packages/botkit/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,7 @@
],
"dependencies": {
"@fedify/fedify": "catalog:",
"@fedify/interaction-controls": "catalog:",
"@fedify/vocab": "catalog:",
"@fedify/vocab-runtime": "catalog:",
"@fedify/markdown-it-hashtag": "^0.3.0",
Expand Down
Loading
Loading