From f7e207f5daae00f18a3c1e94041d7ab4391720b6 Mon Sep 17 00:00:00 2001 From: Oscar Sanderson Date: Sun, 4 Oct 2026 22:16:10 +0800 Subject: [PATCH 1/2] chore(main): release 0.48.1 --- .release-please-manifest.json | 2 +- CHANGELOG.md | 9 +++++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/.release-please-manifest.json b/.release-please-manifest.json index 1383393b..c0615afc 100644 --- a/.release-please-manifest.json +++ b/.release-please-manifest.json @@ -1,3 +1,3 @@ { - ".": "0.48.0" + ".": "0.48.1" } diff --git a/CHANGELOG.md b/CHANGELOG.md index e5359993..475b7497 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,14 @@ # Changelog +## [0.48.1](https://github.com/IDFoundry/FAPIgo/compare/v0.48.0...v0.48.1) (2026-10-04) + + +### Bug Fixes + +* **client:** apply every mTLS endpoint alias, whatever the reason for mutual TLS ([d8b4e79](https://github.com/IDFoundry/FAPIgo/commit/d8b4e797ae4a59e4ebe6afb467469780052fd3a2)) +* **client:** apply the mTLS alias for revocation under certificate client auth ([d72fdc0](https://github.com/IDFoundry/FAPIgo/commit/d72fdc06e3231b887aadec56e433779e72525264)) +* **client:** keep PAR off the mTLS alias for certificate-bound tokens alone ([9a0e000](https://github.com/IDFoundry/FAPIgo/commit/9a0e000b0e9fb5bd075a398f6441398fee810d45)) + ## [0.48.0](https://github.com/IDFoundry/FAPIgo/compare/v0.47.0...v0.48.0) (2026-10-04) From d821ec97e76ac5dea3152d8ecfc17931704fe72d Mon Sep 17 00:00:00 2001 From: Oscar Sanderson Date: Sun, 4 Oct 2026 22:16:39 +0800 Subject: [PATCH 2/2] chore: describe v0.48.1's mTLS alias change as one fix Co-Authored-By: Claude Opus 5.5 --- CHANGELOG.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 475b7497..f257f3b9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,9 +5,7 @@ ### Bug Fixes -* **client:** apply every mTLS endpoint alias, whatever the reason for mutual TLS ([d8b4e79](https://github.com/IDFoundry/FAPIgo/commit/d8b4e797ae4a59e4ebe6afb467469780052fd3a2)) -* **client:** apply the mTLS alias for revocation under certificate client auth ([d72fdc0](https://github.com/IDFoundry/FAPIgo/commit/d72fdc06e3231b887aadec56e433779e72525264)) -* **client:** keep PAR off the mTLS alias for certificate-bound tokens alone ([9a0e000](https://github.com/IDFoundry/FAPIgo/commit/9a0e000b0e9fb5bd075a398f6441398fee810d45)) +* **client:** a client authenticating with its TLS certificate now also uses the server's mTLS endpoint aliases for token revocation and the CIBA backchannel authentication endpoint (`MTLSEndpoints.ApplyForClientAuth`, RFC 8705 ยง5); `ApplyForSenderConstrain` is unchanged ([9a0e000](https://github.com/IDFoundry/FAPIgo/commit/9a0e000b0e9fb5bd075a398f6441398fee810d45)) ## [0.48.0](https://github.com/IDFoundry/FAPIgo/compare/v0.47.0...v0.48.0) (2026-10-04)