OpenProof 1.1.0-rc5 — October 9, 2026 reissue
OpenProof 1.1.0-rc5 — October 9, 2026
Reissued release tag: An earlier v1.1.0-rc5 tag and successful Release workflow existed on September 22, 2026 but were subsequently removed. This is a new, intentionally reissued RC5 build from Git commit 256f970aba84a406d4f7bb906dbb011252719f2e. If you obtained a historic RC5 artifact, do not assume it is byte-for-byte identical to this release. Verify the artifact against this release's SHA256SUMS before use.
Security and correctness improvements
- JavaScript OAuth SDK hardening: Rejects unsafe or ambiguous callback redirect URIs, aligns redirect URI validation with the identity server, validates the OIDC azp claim and rejects ambiguous duplicate OAuth callback parameters.
- Documentation MCP hardening: The latest source masks internal exception details behind a stable HTTP internal_error response. The hosted documentation MCP was separately updated and verified.
- Safer account flows: Browser account security and TOTP enrollment, robust password recovery with one-time proof handling, better stale-session recovery and safer Device Authorization approval surfaces.
- Migration-integrity protection: Packaging now validates that every expected migration is present, byte-identical and checksummed in both Debian and bundle artifacts. The Farcaster profile seed migration 0019_farcaster_profile_seed.sql is included and applies only display-only fields to missing profile values; email/phone ownership remains untouched.
- Native / browser integrations: Genycaster native OAuth client and production environment definitions and Tegra CMS browser client support.
- Constrained owner recovery: Maintenance operation for narrowly defined incomplete initial-owner bootstrap states, with IAL2 verification and audited transaction protections.
Verification
- Tagged commit: 256f970aba84a406d4f7bb906dbb011252719f2e.
- GitHub CI on that exact commit: successful Build and Test + Static Checks, run 37891378458.
- Local regression checks passed: JavaScript SDK tests, OpenAPI coverage (87 paths / 111 operations), migration artifact verifier (7 tests), and documentation MCP syntax.
- On the existing OpenProof production instance, migration inventory is consistent (22/22), public endpoint health checks passed and email configuration persistence was verified. Production state is not a substitute for testing a newly built release package.
- Binary artifacts: amd64 and arm64 Debian packages and Linux tarball bundles, with a SHA256SUMS file. Verify all downloaded artifacts before installation.
Pre-release: This is a release candidate, not a general-availability/stable release. Existing production installations are not automatically upgraded by creating this GitHub Release.