Wallet 0.2.2
Pre-release
Pre-release
Release date: 25th of October, 2024
- All commits in this release: v0.2.1...v0.2.2
- Documentation for this release: https://github.com/MinBZK/nl-wallet/blob/v0.2.2/documentation/index.md
We have the following artifacts as a part of this release:
wallet-sbom_v0.2.2_generic.zip
: The software-bill-of-materials for this releasewallet-verification-server_v0.2.2_x86_64-linux-glibc.zip
: The wallet verification server for relying parties, for glibc-based Linux systemswallet-verification-server_v0.2.2_x86_64-linux-musl.zip
: The wallet verification server for relying parties, for musl-libc based Linux systemswallet-web_v0.2.2_generic.zip
: The javascript helper library for relying parties, to assist with integrating relying party applications with the wallet platform
Upgrade Instructions
verification_server.toml
: Theverifier.trust_anchors
setting is moved one level up and renamed toissuer_trust_anchors
verification_server.toml
: Sentry support is removed from theverification_server
, so the[sentry]
configuration setting is removedverification_server.toml
: A new configuration settingreader_trust_anchors
has been added, which should contain the trusted CAs that issue reader certificates
Changes
- Implement change_pin flow in wallet
- Implement e2e tests for (e2e) testable AC's
- Support simultaneous reading and writing of encrypted preloaded data
- Add test data for demo BSNs
- Add job for encrypting example GBA-V data
- Focus op onzichtbare elementen
- Markering kopteksten
- Add Elf-proef to Bsn
- Add option to delete single and all preloaded data
- [App] Kleurcontrast hyperlink
- Update CI to add RP url to profile Android build
- Implement web frontend for gba_fetch
- Once GBA-V fixes their TLS negotiation, remove
max_tls_version
constraint in gba-hc-converter - alerts/vulnerabilities uit OWASP ZAP scans
- Root/Jailbreak screen is always scrollable
- Privacy Policy and Terms&Conditions
- Implement Proof of Association (PoA) during issuance in wallet and WP
- Add configurable Origin to verification_server
- Add performance_test to main pipeline
- Live preloading of BRP data
- Implement PIN change in wallet core and wallet provider
- Issue WTE using WP instruction and OpenID4VCI
- Validate RP and issuer keypairs on wallet server startup
- Mock relying party Docker image doesn't get release tag
- Warning in pipeline stage(s) if there are vulnerabilities
- unexpected errors capture
error
in panic message - Improve Sentry sensitive data handling
- Improve Sentry sensitive data handling in Flutter
- Update Ruby to 3.x in CI images
- Document how we handle logging of possibly privacy-sensitive data to Sentry
- Minimum requirements in README.md
- [Improvement] Login - See details button
- Execute manual e2e tests for release v0.2.2
- Execute manual performance tests for release v0.2.2
- Fix e2e introduction privacy & conditions tests
- Figure out if our served CSP is really a wildcard directive and fix, if needed
- Fix wallet_web vulnerability in rollup:4.22.1
- Yanked package futures-util op wallet_core verhelpen
- Sync Lokalise & update English privacy texts
- Publication of release v0.2.2
- Documentatie mbt genereren certificaten niet correct waardoor RPs niet kunnen aansluiten
- Support Rustls 0.23.10 and up
- Update mapping documentation
- Fix UX 3.1 "Personalize" e2e tests after PID content update
- Update Figma links for v0.2.2
- Automate wallet web e2e/acceptance test