0.23.x

0.23.0

Highlights

  • Delivered ETSI Trust Lists / LoTL enterprise integration: standards-based trust-list sources, source assurance policies, LoTL support, and Trust Registry API/UI/test alignment.
  • Brought OpenID4VCI client authentication, credential encryption, rate limiting, signed metadata, DPoP, and nonce-endpoint alignment into Enterprise Issuer2/Wallet2 via the shared OSS libraries.
  • Expanded credential status operations with direct status-list index updates, paginated entries, and fixed CWT hex retrieval from cloud buckets.
  • Hardened enterprise operations: resource tree DoS protections and service-limit datatypes, trust-registry permissions, Prometheus null-field safeguards, pagination sort symbols, and typed service dependency declarations.
  • Advanced Wallet2, eIDAS audit logging, mobile/enterprise integration tests, and cloud CI resource-access wiring for AWS/Azure KMS and bucket coverage.

Features

ETSI Trust Lists / LoTL

  • Integrated standards-based Trust Registry trust lists into the Enterprise stack (API, persistence, UI, CLI, and tests)
  • Added source assurance / acceptance policy enforcement for trust sources
  • Added LoTL support and trust-list assurance wiring for enterprise verification flows

Client Authentication and OpenID4VCI Hardening

  • Enabled Enterprise Issuer2/Wallet2 client authentication through the shared OSS library
  • Added encrypted credential requests/responses in Enterprise Issuer2
  • Added rate limiting for OpenID4VCI token/credential endpoints
  • Added issuer-signed metadata and DPoP support in enterprise issuer flows
  • Aligned Enterprise Wallet2 nonce handling with OpenID4VCI 1.0 (request-nonce sequence)
  • Hardened proof-of-possession and nonce verification

Credential Status

  • Exposed status-list index on the API surface for direct status updates alongside issuance sessions
  • Added paginated/filterable/sortable status-list entries endpoint
  • Fixed CWT status-list hex retrieval from cloud buckets and improved related tests

Wallet2 / Audit / Mobile Alignment

  • Refactored Wallet2 enterprise paths in lockstep with OSS.
  • Added eIDAS-oriented audit logging.
  • Aligned wallet transaction-data registry and presentation fixtures with OSS mobile work
  • Added self-contained Enterprise mobile platform tests against public Issuer2/Verifier2

Service Platform

  • Limited /v1/resources-api/tree results and refined resource service limit datatypes to reduce DoS risk
  • Declared supportedDependencyServiceTypes per enterprise service for accurate OpenAPI docs and validation
  • Enabled cloud CI resource-access config generation for AWS/Azure integration tests

Fixes and improvements

  • Fixed ascending/descending pagination sort symbols for unencoded query strings
  • Fixed DID document context vs @context labeling
  • Documented/aligned issuer-state / x5Chain runtime behavior
  • Fixed trust registry permissions
  • Ensured null fields do not break Prometheus metrics when creating verification sessions
  • Improved OpenID4VCI/VP error responses and encryption-related error handling
  • Declared text content type for S3 credential-status fixtures

Breaking changes

  • Trust Registry trust-list loading moves to standards-based ETSI formats; legacy walt.id JSON/XML pilot trust-list formats are removed. Review trust-source uploads and etsi-trust-list policy configuration before upgrading.
Last updated on July 27, 2026