From a2ffef2c3e2ec6b75441bb984d33b486fb3ba4c7 Mon Sep 17 00:00:00 2001 From: Nathan Heskew Date: Tue, 1 Sep 2026 13:12:43 -0700 Subject: [PATCH] Release 1.6.2 Version bump, lockfile, and CHANGELOG for the 1.6.2 patch release on the 1.x maintenance line. Cuts the login-CSRF browser-binding fix (GHSA-xf67- jxfx-jf88, #215) and the Harper 4 peer-range pin (#214). Co-Authored-By: Claude Sonnet 4.6 --- CHANGELOG.md | 10 ++++++++++ package-lock.json | 6 +++--- package.json | 2 +- 3 files changed, 14 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 809da5e..125809d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,16 @@ Notable changes to the `@harperfast/oauth` **1.x maintenance line** are documented here, following [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). History prior to 1.6.0 lives in the [GitHub release notes](https://github.com/HarperFast/oauth/releases); the 2.x line has its own changelog on `main`. +## [1.6.2] - 2026-09-01 + +### Security + +- **Browser-initiated OAuth flows are bound to the initiating browser** (#215; backport of 2.x/#203, GHSA-xf67-jxfx-jf88): login mints a stable per-browser `__Host-oauth_browser` secret cookie whose SHA-256 hash travels in the CSRF state; the callback requires the cookie back (constant-time check) before any upstream code exchange, closing the login-CSRF / authorization-code-injection class for logged-out flows that the 1.6.1 state↔session binding could not cover. Hardening landed alongside: multi-crumb `Cookie` headers (HTTP/2) are joined before parsing, the single-use CSRF state is consumed even on provider-error callbacks, the cookie value is validated (bounded base64url) and the compare is guarded against non-string inputs, and browser-controlled values are CRLF-safe in logs. In-flight pre-upgrade logins (no hash in state) still complete, so a rolling deploy is safe. **⚠️ Requires HTTPS:** the `__Host-`/`Secure` cookie is dropped by browsers on plain-HTTP non-localhost origins, so OAuth must be served over TLS (or behind a TLS-terminating proxy) — otherwise every callback fails with `reason=csrf`. + +### Changed + +- **Peer range pinned to Harper 4** (#214): the `harperdb` peer dependency is now `>=4.6.0 <5.0.0`. The 1.x line targets Harper 4 only; Harper 5 ships as the separate `harper` package and is served by the 2.x line. + ## [1.6.1] - 2026-07-20 ### Security diff --git a/package-lock.json b/package-lock.json index 5879669..a0f8ead 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@harperfast/oauth", - "version": "1.6.1", + "version": "1.6.2", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@harperfast/oauth", - "version": "1.6.1", + "version": "1.6.2", "license": "Apache-2.0", "dependencies": { "jsonwebtoken": "^9.0.2", @@ -26,7 +26,7 @@ "node": ">=20" }, "peerDependencies": { - "harperdb": ">=4.6.0" + "harperdb": ">=4.6.0 <5.0.0" } }, "node_modules/@eslint-community/eslint-utils": { diff --git a/package.json b/package.json index 8150f1d..6f0e135 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@harperfast/oauth", - "version": "1.6.1", + "version": "1.6.2", "description": "OAuth 2.0 authentication plugin for Harper", "license": "Apache-2.0", "author": {