Initial commit
This commit is contained in:
85
docs/releases/2.1.0.md
Normal file
85
docs/releases/2.1.0.md
Normal file
@@ -0,0 +1,85 @@
|
||||
## Barong 2.1.0 (April 22, 2019) ##
|
||||
|
||||
### Overview ###
|
||||
|
||||
Release includes significant new features, numerous functional fixes and stabilizing patches.
|
||||
Barong 2.2.0 comes without views, controllers, huge dependencies, but with clean, fast and readable API.
|
||||
Release is optimized, more compact and elegant version of OAuth server concept.
|
||||
Since we've removed dependencies like `devise` a lot of the flow was not only recoded but implemented in fully new way.
|
||||
|
||||
This release notes is must-read for migrating from 2.0 version.
|
||||
|
||||
### Release is NOT compatible with 1.9 or older versions of barong ###
|
||||
|
||||
### New features ###
|
||||
|
||||
* [#655](https://github.com/rubykube/barong/pull/655): Reworked (complaining to 1.9) seed feature. Supports seeding levels, users with optional parameters and labels
|
||||
|
||||
* [#679](https://github.com/rubykube/barong/pull/679): Adds an ability to upload N number of documents. Maximum number can be configured by ENV
|
||||
|
||||
* [#665](https://github.com/rubykube/barong/pull/665): Support of GeeTest captcha and captcha configuration
|
||||
|
||||
* [#681](https://github.com/rubykube/barong/pull/681): Move all admin functionality to API
|
||||
|
||||
* [#686](https://github.com/rubykube/barong/pull/686): New authorize endpoint (White- and Black- listing features, Rails Metal based (optimized), api keys and cookies logic)
|
||||
|
||||
* [#716](https://github.com/rubykube/barong/pull/716): Ability to specify and control CORS policy
|
||||
|
||||
* [#726](https://github.com/rubykube/barong/pull/726): Support asian language characters, rework validations
|
||||
|
||||
* [#734](https://github.com/rubykube/barong/pull/734): Add tokens blacklisting feature. Additional checks to avoid reusing tokens
|
||||
|
||||
* [741](https://github.com/rubykube/barong/pull/741): Unify errors format to prepare base for translations
|
||||
|
||||
|
||||
### Enhancements ###
|
||||
|
||||
* [#677](https://github.com/rubykube/barong/pull/677): Improve activities coverage
|
||||
* [#688](https://github.com/rubykube/barong/pull/688): Add change password endpoint
|
||||
* [#693](https://github.com/rubykube/barong/pull/693): Change multiple docs uploading logic from object to array to become compatible with browser files transfering policy
|
||||
* [#697](https://github.com/rubykube/barong/pull/697): Add label on profile adding without level increase to strictly
|
||||
* [#709](https://github.com/rubykube/barong/pull/709): Add referral_id to users table and as an optional param on signup
|
||||
* [#707](https://github.com/rubykube/barong/pull/707): Update to ruby 2.6.0
|
||||
* [#745](https://github.com/rubykube/barong/pull/745): Add event API documentation with examples
|
||||
* [#767](https://github.com/rubykube/barong/pull/767): Add language field in reset pass and confirm acc events
|
||||
* [#763](https://github.com/rubykube/barong/pull/763): User controller improvements
|
||||
** Fixed inconsistent indentation in user controller
|
||||
** Rework POST '/get' request to allow to receive email and phone num
|
||||
** Added several additional tests
|
||||
* [#771](https://github.com/rubykube/barong/pull/771): Add pagination on /resource/users/activity endpoint
|
||||
* [#769](https://github.com/rubykube/barong/pull/769): Search on user fields, admin API
|
||||
* [#785](https://github.com/rubykube/barong/pull/786): Add Entities::Activity model, include it Entities::UserWithFullInfo
|
||||
* [#789](https://github.com/rubykube/barong/pull/789): Use 'paginate' on api/v2/admin/users/search
|
||||
* [#804](https://github.com/rubykube/barong/pull/804): DESC order in user activity API
|
||||
* [#807](https://github.com/rubykube/barong/pull/807): Allow to list API Keys without providing OTP code
|
||||
* [#809](https://github.com/rubykube/barong/pull/809): Update rails-related gems versions in favor of vulnerability alerts
|
||||
|
||||
### Fixes ###
|
||||
* [#658](https://github.com/rubykube/barong/pull/658): Fix share cookies for development, fix Bump
|
||||
* [#664](https://github.com/rubykube/barong/pull/664): Fix user activity api endpoint bug https://github.com/rubykube/barong/issues/663
|
||||
* [#674](https://github.com/rubykube/barong/pull/674): Added missing validations on password update functionality
|
||||
* [#675](https://github.com/rubykube/barong/pull/675): Fix unhandled totp errors
|
||||
* [#683](https://github.com/rubykube/barong/pull/683): Hotfix for whitelisting public peatio and barong routes
|
||||
* [#684](https://github.com/rubykube/barong/pull/684): Add missing link_config script(required for deployment process)
|
||||
* [#685](https://github.com/rubykube/barong/pull/685): Update the production database configuration with DATABASE_NAME from env
|
||||
* [#694](https://github.com/rubykube/barong/pull/694): Add missing event with confirmation token on signup
|
||||
* [#699](https://github.com/rubykube/barong/pull/699): Add carrierwave config for production
|
||||
* [#702](https://github.com/rubykube/barong/pull/702): Small fixes (drone ci, event api updated_at bug)
|
||||
* [#706](https://github.com/rubykube/barong/pull/706): Add missing users entity on login and /me
|
||||
* [#718](https://github.com/rubykube/barong/pull/718): Move ActionDispatch::Session::CookieStore to sessions controller
|
||||
* [#720](https://github.com/rubykube/barong/pull/720): Add ability to configure expire_after time through env variable, fix hardcoded one
|
||||
* [#724](https://github.com/rubykube/barong/pull/724): Fix change password api action from post to put
|
||||
* [#713](https://github.com/rubykube/barong/pull/713): Split swagger doc into restful and management)
|
||||
* [#737](https://github.com/rubykube/barong/pull/737): Add storage envs in config store and update fetch logic
|
||||
* [#730](https://github.com/rubykube/barong/pull/730): Fix change code on phone initialize, remove code from logs
|
||||
* [#739](https://github.com/rubykube/barong/pull/739): Fix Barong::CORS load problem in production env
|
||||
* [#742](https://github.com/rubykube/barong/pull/742): Add missing user details in 2fa login response
|
||||
* [#749](https://github.com/rubykube/barong/pull/749): Fix session_id check & add bypass session lazy load
|
||||
* [#753](https://github.com/rubykube/barong/pull/753): Change default set-cookie header policy on authz to :skip
|
||||
* [#757](https://github.com/rubykube/barong/pull/757): Take only data from Vault::Secret object && minor refactoring
|
||||
* [#747](https://github.com/rubykube/barong/pull/747): Phone API improvements (additional error)
|
||||
* [#760](https://github.com/rubykube/barong/pull/760): Add additional error on login in case of banned user
|
||||
* [#768](https://github.com/rubykube/barong/pull/768): Add more API Key validations, fix error on creating with invalid algo
|
||||
* [#772](https://github.com/rubykube/barong/pull/772): Split activity no records error to wrong_topic and no_activity
|
||||
* [#776](https://github.com/rubykube/barong/pull/776): Use destroy instead of delete to enable missing validations
|
||||
* [#805](https://github.com/rubykube/barong/pull/805): Move event api jwt private key to Barong::App.config store
|
||||
114
docs/releases/2.3.0.md
Normal file
114
docs/releases/2.3.0.md
Normal file
@@ -0,0 +1,114 @@
|
||||
## Barong 2.3.0 ##
|
||||
|
||||
### Overview ###
|
||||
|
||||
We are pleased to present Barong Open Source 2.3.0.
|
||||
|
||||
This release concentrated on improving overall project flexibility, security and session updates and several new storage/phone providers and updates
|
||||
|
||||
1. Server side sessions via rails cache
|
||||
2. Restrictions and related Admin API
|
||||
3. Support Twilio Verify service (without dropping legacy sms solution)
|
||||
4. Flexible state - labels flow
|
||||
5. Support Ali Cloud storage provider and S3 custom storages
|
||||
|
||||
This release notes is must-read for migrating from older versions.
|
||||
|
||||
### New Features ###
|
||||
- Add ability to configure sms content for phone verification [#877](https://github.com/rubykube/barong/pull/877) ([ec](https://github.com/ec))
|
||||
- This PR introduce an ability to configurate (via ENV) before deployment the future Twilio sms content:
|
||||
- "Your verification code for Barong: {{code}}"" - default one
|
||||
- You can change position of verification code, words and content in template
|
||||
- e.q. "Hoooray! Here is magic {{code}} for you to verify your account!""
|
||||
|
||||
- Simple rake task to create users and api keys [#816](https://github.com/rubykube/barong/pull/816) ([ec](https://github.com/ec))
|
||||
- [ATTENTION] The best usage for the rake task - testing purpose
|
||||
- You can generate up to N (1000 by default) users with valid api keys to simulate any platform actions
|
||||
- Add Resctrictions [#891](https://github.com/rubykube/barong/pull/891) ([dnfd](https://github.com/dnfd))
|
||||
- AuthZ level validations to ban traffic on a network base.
|
||||
- Available types of validations: IP IP_SUBNET CONTINENT COUNTRY
|
||||
- After being created restriction can be toggled to be turned ON or OF via admin api
|
||||
- Full support of CRUD functionality in the admin module
|
||||
- Feature Ability to change UID prefix with BARONG_UID_PREFIX=ABC [#893](https://github.com/rubykube/barong/pull/893) ([ec](https://github.com/ec))
|
||||
- This PR introduce an ability to configurate (via ENV) before deployment the future user UIDs:
|
||||
- ID{RANDOM_HASH} - default
|
||||
- MYAWESOMEAPP{RANDOM_HASH} - available to configurate
|
||||
- Add Management API: push document for user [#894](https://github.com/rubykube/barong/pull/894) ([ec](https://github.com/ec))
|
||||
- New management API call that gives an ability to push documents for the user in base64
|
||||
- Good base for any third-party KYC providers
|
||||
- Add endpoint for delete restriction [#902](https://github.com/rubykube/barong/pull/902) ([chumaknadya](https://github.com/chumaknadya))
|
||||
- Admin endpoint to delete Restriction (remove from DB, cant be rolled back)
|
||||
- Add state to Profile model [#910](https://github.com/rubykube/barong/pull/910) ([mnaichuk](https://github.com/mnaichuk))
|
||||
- Define 2 Profile states: partial and completed
|
||||
- Allow to create EMPTY profile (with empty fields)
|
||||
- Profile state - attributes dependency
|
||||
- Ability to update and delete users profiles [#913](https://github.com/rubykube/barong/pull/913) ([ec](https://github.com/ec))
|
||||
- New admin and user API endpoints that allows to update / delete profiles
|
||||
- Flexible state - labels flow [#907](https://github.com/rubykube/barong/pull/907) ([ec](https://github.com/ec))
|
||||
- State - Label dependency
|
||||
- Similar to levels configuration now you can configurate requirements for each of the user states
|
||||
- Separately - ACTIVE requirements
|
||||
- Now on every label change (update, remove, delete) user state recalculates and forces to update
|
||||
- Default values remains the same as in the <= 2.2 version
|
||||
- Add AliCloud Carrierwave storage provider [#911](https://github.com/rubykube/barong/pull/911) ([dnfd](https://github.com/dnfd))
|
||||
- Now Barong support Ali Cloud storages and easily deploys on AliBaba cloud
|
||||
- Add ability to restrict by geoip [#920](https://github.com/rubykube/barong/pull/920) ([dnfd](https://github.com/dnfd))
|
||||
- Add support of CONTINENT and COUNTRY restriction scopes
|
||||
- Add ability to skip label creation on doc save [#922](https://github.com/rubykube/barong/pull/922) ([dnfd](https://github.com/dnfd))
|
||||
- Add ability to disable 2fa [#925](https://github.com/rubykube/barong/pull/925) ([dnfd](https://github.com/dnfd))
|
||||
- Add AliCloud Uploader [#926](https://github.com/rubykube/barong/pull/926) ([dnfd](https://github.com/dnfd))
|
||||
- Now Barong support Ali Cloud storages and easily deploys on AliBaba cloud
|
||||
- Define DocumentTypes class for flexible doc type configuration [#935](https://github.com/rubykube/barong/pull/935) ([ec](https://github.com/ec))
|
||||
- This PR introduce an ability to predefine available document types before deployment. There is hardcoded freezed array anymore.
|
||||
- By default, abailable document type list remains the same as <= 2.2 versions
|
||||
- Make labels acts_as_eventable on: [create update] [#936](https://github.com/rubykube/barong/pull/936) ([ec](https://github.com/ec))
|
||||
- Spread events on label CUD
|
||||
- Add the support of twilio verify API [#928](https://github.com/rubykube/barong/pull/928) ([ec](https://github.com/ec))
|
||||
- Now Barong supports twilio verification service ( via CALL and SMS )
|
||||
- Should be switched from SMS to Twilio Verify via ENV before deployment
|
||||
- Server side sessions via cache_store [#949](https://github.com/rubykube/barong/pull/949) ([ec](https://github.com/ec))
|
||||
- Now session stores on the server side in the cache
|
||||
- User receives only 1 session cookie, that proves he got it from Barong
|
||||
- Session lifetime extends after every private call
|
||||
- Session will automatically close if user will try to reuse cookies in another browser or IP network
|
||||
- Session will expire in 24h
|
||||
|
||||
### Enhancements ###
|
||||
- Updating gem multisign and jwt [45f975](https://github.com/rubykube/barong/commit/45f975fcb489aaa3b0b4f56b1307258b8bc85d18) ([mod](https://github.com/mod))
|
||||
- Allow pending user to open session [#881](https://github.com/rubykube/barong/pull/881) ([ec](https://github.com/ec))
|
||||
- Update to ruby 2.6.3 and rails 5.2.3 [#867](https://github.com/rubykube/barong/pull/867) ([ec](https://github.com/ec))
|
||||
- Update models' annotations [#895](https://github.com/rubykube/barong/pull/895) ([dnfd](https://github.com/dnfd))
|
||||
- Small fixes in document and profile model [#901](https://github.com/rubykube/barong/pull/901) ([ec](https://github.com/ec))
|
||||
- Feature: Add redeploy on devkube step to drone [#874](https://github.com/rubykube/barong/pull/874) ([alinetskyi](https://github.com/alinetskyi))
|
||||
- Add validation for referral && Add ability to get referral uid [#882](https://github.com/rubykube/barong/pull/882) ([chumaknadya](https://github.com/chumaknadya))
|
||||
- Update nokogiri version [#906](https://github.com/rubykube/barong/pull/906) ([dnfd](https://github.com/dnfd))
|
||||
- Update Barong::App validations [#904](https://github.com/rubykube/barong/pull/904) ([dnfd](https://github.com/dnfd))
|
||||
- Support 'with replace' policy on labels update [#915](https://github.com/rubykube/barong/pull/915) ([ec](https://github.com/ec))
|
||||
- UPDATES: sessions delete, permissions update, log error on 500 [#917](https://github.com/rubykube/barong/pull/917) ([chumaknadya](https://github.com/chumaknadya))
|
||||
- Add :upload in list of params to be filtered [#919](https://github.com/rubykube/barong/pull/919) ([ec](https://github.com/ec))
|
||||
- Fix structure of event API messages [#912](https://github.com/rubykube/barong/pull/912) ([shal](https://github.com/shal))
|
||||
- Use Barong::App.config.barong_uid_prefix in referral validation [#923](https://github.com/rubykube/barong/pull/923) ([ec](https://github.com/ec))
|
||||
- Allow blank doc_expire for documents controllers [#927](https://github.com/rubykube/barong/pull/927) ([dnfd](https://github.com/dnfd))
|
||||
- Add system.session.create event with user and request_ip data [#916](https://github.com/rubykube/barong/pull/916) ([chumaknadya](https://github.com/chumaknadya))
|
||||
- Update seeds.yml [#934](https://github.com/rubykube/barong/pull/934) ([ec](https://github.com/ec))
|
||||
- Simple GET levels requirements endpoint for admin [#932](https://github.com/rubykube/barong/pull/932) ([ec](https://github.com/ec))
|
||||
- Get rid of 'serialize: JSON', accept 'metadata' as json instead of pure hash [#930](https://github.com/rubykube/barong/pull/930) ([ec](https://github.com/ec))
|
||||
- Add missing labels event api documentation [#937](https://github.com/rubykube/barong/pull/937) ([ec](https://github.com/ec))
|
||||
- Add session autorenew [#903](https://github.com/rubykube/barong/pull/903) ([dnfd](https://github.com/dnfd))
|
||||
- Introduce MockPhoneVerifyService [#941](https://github.com/rubykube/barong/pull/941) ([ec](https://github.com/ec))
|
||||
- Use uid instead of id on profile update && delete api [#943](https://github.com/rubykube/barong/pull/943) ([ec](https://github.com/ec))
|
||||
- Profile act as eventable on update [#945](https://github.com/rubykube/barong/pull/945) ([ec](https://github.com/ec))
|
||||
- Update ruby to 2.6.5 for security reasons [#946](https://github.com/rubykube/barong/pull/946) ([ec](https://github.com/ec))
|
||||
- Add ability to configure aws_signature_version && endpoint [#947](https://github.com/rubykube/barong/pull/947) ([ec](https://github.com/ec))
|
||||
- Feature: allow # \ () & ' : " in profile residental address field [#950](https://github.com/rubykube/barong/pull/950) ([ymasiuk](https://github.com/ymasiuk))
|
||||
- Add redis - hiredis dependency, specify driver in dev env [#951](https://github.com/rubykube/barong/pull/951) ([ec](https://github.com/ec))
|
||||
- Protect superadmin against changes from non-superadmin users [#955](https://github.com/rubykube/barong/pull/955) ([ec](https://github.com/ec))
|
||||
- Update storage-related gems [#957](https://github.com/rubykube/barong/pull/957) ([ec](https://github.com/ec))
|
||||
|
||||
### Bug Fixes ###
|
||||
- Use CGI::escape instead of pure url in documents event api [#942](https://github.com/rubykube/barong/pull/942) ([ec](https://github.com/ec))
|
||||
- fix binstubs issue [#867](https://github.com/rubykube/barong/pull/867) ([ec](https://github.com/ec))
|
||||
- Fix rollback to pending state, add missing data in entities [#914](https://github.com/rubykube/barong/pull/914) ([ec](https://github.com/ec))
|
||||
- Handle Vault errors on POST /api/v2/resource/api_keys [#918](https://github.com/rubykube/barong/pull/918) ([dnfd](https://github.com/dnfd))
|
||||
- Avoid no method error UTC for nil entities [#921](https://github.com/rubykube/barong/pull/921) ([ec](https://github.com/ec))
|
||||
- Event API changes: remove blocking check for on_update events [#933](https://github.com/rubykube/barong/pull/933) ([ec](https://github.com/ec))
|
||||
Reference in New Issue
Block a user