diff --git a/.changeset/oauth-credential-scopes.md b/.changeset/oauth-credential-scopes.md deleted file mode 100644 index 48fa62d..0000000 --- a/.changeset/oauth-credential-scopes.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@codelitdev/platform": patch ---- - -`PlatformCredential` has an optional `scopes` field. Authentication adapters set it for `oauth` credentials so products can narrow permissions to the token's granted scopes (ADR 0008). diff --git a/.changeset/template-data-scopes.md b/.changeset/template-data-scopes.md deleted file mode 100644 index 149d8a6..0000000 --- a/.changeset/template-data-scopes.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -"@codelitdev/platform-cli": minor ---- - -The template enforces OAuth data scopes (ADR 0008). It adds a `data:write` scope, advertises `data:read`, `data:write`, and `offline_access` to MCP clients, carries a token's scopes on its OAuth credential, and narrows tenant permissions to what those scopes allow. Previously a token approved as `data:read` received every permission of the member's role. - -**Product changes for this release** - -- Add `data:write` to the OAuth provider's `scopes` and `clientRegistrationAllowedScopes`, and advertise `["data:read", "data:write", "offline_access"]` in `createMcpOAuthDiscoveryRoutes`. -- Set `scopes: resolved.identity.scopes` on the OAuth credential, and keep only the permissions those scopes cover. Reads belong to `data:read`; anything that creates, changes, or deletes belongs to `data:write`. -- Existing OAuth tokens carry only `data:read`. Users re-authorize their MCP clients once to regain write access. diff --git a/packages/billing/CHANGELOG.md b/packages/billing/CHANGELOG.md index 7f2c995..e07b0af 100644 --- a/packages/billing/CHANGELOG.md +++ b/packages/billing/CHANGELOG.md @@ -1,5 +1,9 @@ # @codelitdev/billing +## 0.3.0 + +No changes in this release. + ## 0.2.0 ### Patch Changes diff --git a/packages/billing/package.json b/packages/billing/package.json index 86cfa1c..672fb4f 100644 --- a/packages/billing/package.json +++ b/packages/billing/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/billing", - "version": "0.2.0", + "version": "0.3.0", "description": "Provider-neutral billing engine for CodeLit products", "author": "CodeLit", "type": "module", diff --git a/packages/design-system/CHANGELOG.md b/packages/design-system/CHANGELOG.md index b2c0a4c..c60cc2b 100644 --- a/packages/design-system/CHANGELOG.md +++ b/packages/design-system/CHANGELOG.md @@ -1,5 +1,9 @@ # @codelitdev/design-system +## 0.3.0 + +No changes in this release. + ## 0.2.0 No changes in this release. diff --git a/packages/design-system/package.json b/packages/design-system/package.json index 0cdb1b0..cc34f79 100644 --- a/packages/design-system/package.json +++ b/packages/design-system/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/design-system", - "version": "0.2.0", + "version": "0.3.0", "description": "Shared CodeLit design tokens, Tailwind preset, and React primitives for CourseLit, MediaLit, SendLit, and FrontLit.", "license": "Apache-2.0", "author": "CodeLit", diff --git a/packages/mcp-server-kit/CHANGELOG.md b/packages/mcp-server-kit/CHANGELOG.md index 3c7f484..3003c0a 100644 --- a/packages/mcp-server-kit/CHANGELOG.md +++ b/packages/mcp-server-kit/CHANGELOG.md @@ -1,5 +1,12 @@ # @codelitdev/mcp-server-kit +## 0.3.0 + +### Patch Changes + +- Updated dependencies [8cbb124] + - @codelitdev/platform@0.3.0 + ## 0.2.0 ### Patch Changes diff --git a/packages/mcp-server-kit/package.json b/packages/mcp-server-kit/package.json index e9ee63e..ca2abc7 100644 --- a/packages/mcp-server-kit/package.json +++ b/packages/mcp-server-kit/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/mcp-server-kit", - "version": "0.2.0", + "version": "0.3.0", "description": "MCP transport, session, auth hooks, and error mapping for CodeLit products", "author": "CodeLit", "type": "module", @@ -37,7 +37,7 @@ "zod": "^3.25.76" }, "peerDependencies": { - "@codelitdev/platform": ">=0.2.0" + "@codelitdev/platform": ">=0.3.0" }, "devDependencies": { "@codelitdev/platform": "workspace:*", diff --git a/packages/oauth-server-kit/CHANGELOG.md b/packages/oauth-server-kit/CHANGELOG.md index bff07e7..392c9d1 100644 --- a/packages/oauth-server-kit/CHANGELOG.md +++ b/packages/oauth-server-kit/CHANGELOG.md @@ -1,5 +1,9 @@ # @codelitdev/oauth-server-kit +## 0.3.0 + +No changes in this release. + ## 0.2.0 ### Patch Changes diff --git a/packages/oauth-server-kit/package.json b/packages/oauth-server-kit/package.json index 30c8fdf..91559e7 100644 --- a/packages/oauth-server-kit/package.json +++ b/packages/oauth-server-kit/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/oauth-server-kit", - "version": "0.2.0", + "version": "0.3.0", "description": "Lean Better Auth OAuth authentication framework for web, mobile, REST, and MCP surfaces.", "author": "CodeLit", "license": "MIT", diff --git a/packages/observability/CHANGELOG.md b/packages/observability/CHANGELOG.md index 11465e4..4f002dc 100644 --- a/packages/observability/CHANGELOG.md +++ b/packages/observability/CHANGELOG.md @@ -1,5 +1,9 @@ # @codelitdev/observability +## 0.3.0 + +No changes in this release. + ## 0.2.0 No changes in this release. diff --git a/packages/observability/package.json b/packages/observability/package.json index cac7904..68324ea 100644 --- a/packages/observability/package.json +++ b/packages/observability/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/observability", - "version": "0.2.0", + "version": "0.3.0", "description": "Provider-neutral logging and optional telemetry for CodeLit products", "author": "CodeLit", "type": "module", diff --git a/packages/platform-cli/CHANGELOG.md b/packages/platform-cli/CHANGELOG.md index 1372066..fe03d22 100644 --- a/packages/platform-cli/CHANGELOG.md +++ b/packages/platform-cli/CHANGELOG.md @@ -1,5 +1,17 @@ # @codelitdev/platform-cli +## 0.3.0 + +### Minor Changes + +- 8cbb124: The template enforces OAuth data scopes (ADR 0008). It adds a `data:write` scope, advertises `data:read`, `data:write`, and `offline_access` to MCP clients, carries a token's scopes on its OAuth credential, and narrows tenant permissions to what those scopes allow. Previously a token approved as `data:read` received every permission of the member's role. + + **Product changes for this release** + + - Add `data:write` to the OAuth provider's `scopes` and `clientRegistrationAllowedScopes`, and advertise `["data:read", "data:write", "offline_access"]` in `createMcpOAuthDiscoveryRoutes`. + - Set `scopes: resolved.identity.scopes` on the OAuth credential, and keep only the permissions those scopes cover. Reads belong to `data:read`; anything that creates, changes, or deletes belongs to `data:write`. + - Existing OAuth tokens carry only `data:read`. Users re-authorize their MCP clients once to regain write access. + ## 0.2.0 ### Minor Changes diff --git a/packages/platform-cli/package.json b/packages/platform-cli/package.json index 76db58a..8d7d86a 100644 --- a/packages/platform-cli/package.json +++ b/packages/platform-cli/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/platform-cli", - "version": "0.2.0", + "version": "0.3.0", "description": "Create, check, and sync CodeLit Platform products", "author": "CodeLit", "type": "module", diff --git a/packages/platform-cli/src/preset.json b/packages/platform-cli/src/preset.json index 4c56720..d938580 100644 --- a/packages/platform-cli/src/preset.json +++ b/packages/platform-cli/src/preset.json @@ -5,42 +5,42 @@ }, "packages": { "@codelitdev/platform": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/observability": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/mcp-server-kit": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/platform-conformance": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/platform-cli": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.0 <2", "minimumSecure": "0.1.0-alpha.0" }, "@codelitdev/billing": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.4 <1", "minimumSecure": "0.1.0-alpha.4" }, "@codelitdev/oauth-server-kit": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.2 <1", "minimumSecure": "0.1.0-alpha.2" }, "@codelitdev/design-system": { - "recommended": "0.2.0", + "recommended": "0.3.0", "supported": ">=0.1.0-alpha.7 <1", "minimumSecure": "0.1.0-alpha.7" } diff --git a/packages/platform-conformance/CHANGELOG.md b/packages/platform-conformance/CHANGELOG.md index f8c767e..5d475f7 100644 --- a/packages/platform-conformance/CHANGELOG.md +++ b/packages/platform-conformance/CHANGELOG.md @@ -1,5 +1,12 @@ # @codelitdev/platform-conformance +## 0.3.0 + +### Patch Changes + +- Updated dependencies [8cbb124] + - @codelitdev/platform@0.3.0 + ## 0.2.0 ### Patch Changes diff --git a/packages/platform-conformance/package.json b/packages/platform-conformance/package.json index f866103..c23b975 100644 --- a/packages/platform-conformance/package.json +++ b/packages/platform-conformance/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/platform-conformance", - "version": "0.2.0", + "version": "0.3.0", "description": "Shared HTTP conformance suites for CodeLit Platform products", "author": "CodeLit", "type": "module", @@ -37,7 +37,7 @@ "tag": "latest" }, "peerDependencies": { - "@codelitdev/platform": ">=0.2.0" + "@codelitdev/platform": ">=0.3.0" }, "devDependencies": { "@codelitdev/platform": "workspace:*", diff --git a/packages/platform/CHANGELOG.md b/packages/platform/CHANGELOG.md index d8a2fd2..faeeb9c 100644 --- a/packages/platform/CHANGELOG.md +++ b/packages/platform/CHANGELOG.md @@ -1,5 +1,11 @@ # @codelitdev/platform +## 0.3.0 + +### Patch Changes + +- 8cbb124: `PlatformCredential` has an optional `scopes` field. Authentication adapters set it for `oauth` credentials so products can narrow permissions to the token's granted scopes (ADR 0008). + ## 0.2.0 ### Minor Changes diff --git a/packages/platform/package.json b/packages/platform/package.json index 0a0f1be..6b964a2 100644 --- a/packages/platform/package.json +++ b/packages/platform/package.json @@ -1,6 +1,6 @@ { "name": "@codelitdev/platform", - "version": "0.2.0", + "version": "0.3.0", "description": "Composition kernel for CodeLit Platform products", "author": "CodeLit", "type": "module",