From 0d0558d11bd68aedae3bccd67b804c932a814ac4 Mon Sep 17 00:00:00 2001 From: disqualifier Date: Thu, 2 Jul 2026 16:50:55 -0400 Subject: [PATCH] chore: unpin envelope_crypto dependency (track latest release) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit envauth used envelope_crypto pinned at v0.1.0, two data-loss fixes behind (the lib is now v0.1.4). envauth uses only stable crypto primitives (initialize, encrypt_data/ decrypt_data, create_aes_key, *_aes_key_with_rsa, get_rsa_key_fingerprint, self_test) — never the record-rotation functions whose contract changed — so tracking latest is safe and keeps the crypto fixes flowing without a manual bump each release. Verified: full CLI round-trip (init -> authorize server -> privilege gate -> envauth-1 self-authorize refusal -> list) against envelope_crypto v0.1.4 source; all 8 used primitives present. v0.1.4. Signed-off-by: disqualifier --- README.md | 8 ++++---- pyproject.toml | 4 ++-- src/envelope_authorizer/__init__.py | 2 +- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index 06befa2..c5537f6 100644 --- a/README.md +++ b/README.md @@ -13,26 +13,26 @@ authorization system and the key-document schema; the crypto primitives live in ## Install ``` -envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.3 +envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.4 ``` Direct: ```bash -pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.3" +pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.4" ``` The base install uses a local JSON file for storage (stdlib only). For shared dev→server storage, install the mongo extra: ```bash -pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.3" +pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.4" ``` Installing pulls `envelope_crypto` (and `mongo` with the extra). After install, the `authorizer` command is on your PATH; `python -m envelope_authorizer` also works. -Drop the `@v0.1.3` suffix from the line above to install the latest unpinned. +Drop the `@v0.1.4` suffix from the line above to install the latest unpinned. ## Trust model (read this) diff --git a/pyproject.toml b/pyproject.toml index b363f81..4bf605c 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,11 +4,11 @@ build-backend = "hatchling.build" [project] name = "envelope_authorizer" -version = "0.1.3" +version = "0.1.4" description = "CLI key-authorization manager for envelope_crypto" requires-python = ">=3.10" dependencies = [ - "envelope_crypto @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_crypto.git@v0.1.0", + "envelope_crypto @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_crypto.git", "tomli>=2.0; python_version<'3.11'", ] diff --git a/src/envelope_authorizer/__init__.py b/src/envelope_authorizer/__init__.py index ae73625..bbab024 100644 --- a/src/envelope_authorizer/__init__.py +++ b/src/envelope_authorizer/__init__.py @@ -1 +1 @@ -__version__ = "0.1.3" +__version__ = "0.1.4"