0.23.x
0.23.0
Highlights
- Delivered ETSI Trust Lists / LoTL enterprise integration: standards-based trust-list sources, source assurance policies, LoTL support, and Trust Registry API/UI/test alignment.
- Brought OpenID4VCI client authentication, credential encryption, rate limiting, signed metadata, DPoP, and nonce-endpoint alignment into Enterprise Issuer2/Wallet2 via the shared OSS libraries.
- Expanded credential status operations with direct status-list index updates, paginated entries, and fixed CWT hex retrieval from cloud buckets.
- Hardened enterprise operations: resource tree DoS protections and service-limit datatypes, trust-registry permissions, Prometheus null-field safeguards, pagination sort symbols, and typed service dependency declarations.
- Advanced Wallet2, eIDAS audit logging, mobile/enterprise integration tests, and cloud CI resource-access wiring for AWS/Azure KMS and bucket coverage.
Features
ETSI Trust Lists / LoTL
- Integrated standards-based Trust Registry trust lists into the Enterprise stack (API, persistence, UI, CLI, and tests)
- Added source assurance / acceptance policy enforcement for trust sources
- Added LoTL support and trust-list assurance wiring for enterprise verification flows
Client Authentication and OpenID4VCI Hardening
- Enabled Enterprise Issuer2/Wallet2 client authentication through the shared OSS library
- Added encrypted credential requests/responses in Enterprise Issuer2
- Added rate limiting for OpenID4VCI token/credential endpoints
- Added issuer-signed metadata and DPoP support in enterprise issuer flows
- Aligned Enterprise Wallet2 nonce handling with OpenID4VCI 1.0 (
request-noncesequence) - Hardened proof-of-possession and nonce verification
Credential Status
- Exposed status-list index on the API surface for direct status updates alongside issuance sessions
- Added paginated/filterable/sortable status-list entries endpoint
- Fixed CWT status-list hex retrieval from cloud buckets and improved related tests
Wallet2 / Audit / Mobile Alignment
- Refactored Wallet2 enterprise paths in lockstep with OSS.
- Added eIDAS-oriented audit logging.
- Aligned wallet transaction-data registry and presentation fixtures with OSS mobile work
- Added self-contained Enterprise mobile platform tests against public Issuer2/Verifier2
Service Platform
- Limited
/v1/resources-api/treeresults and refined resource service limit datatypes to reduce DoS risk - Declared
supportedDependencyServiceTypesper enterprise service for accurate OpenAPI docs and validation - Enabled cloud CI resource-access config generation for AWS/Azure integration tests
Fixes and improvements
- Fixed ascending/descending pagination sort symbols for unencoded query strings
- Fixed DID document
contextvs@contextlabeling - Documented/aligned issuer-state / x5Chain runtime behavior
- Fixed trust registry permissions
- Ensured null fields do not break Prometheus metrics when creating verification sessions
- Improved OpenID4VCI/VP error responses and encryption-related error handling
- Declared text content type for S3 credential-status fixtures
Breaking changes
- Trust Registry trust-list loading moves to standards-based ETSI formats; legacy walt.id JSON/XML pilot trust-list formats are removed. Review trust-source uploads and
etsi-trust-listpolicy configuration before upgrading.
Last updated on July 27, 2026
