diff --git a/CHANGELOG.md b/CHANGELOG.md index c4bed344..3bf40ee5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,8 +1,12 @@ # Changelog -## Unreleased +## 0.4.31.2 -- **Docs/licensing:** added `NOTICE` reproducing Vercel Chat's MIT copyright notice — this package is a derivative (port) of `vercel/chat`, and the notice now ships in the sdist and in the wheel's `dist-info/licenses/`. No code changes. +Python-only fixes on top of `4.31.0` (`UPSTREAM_PARITY` unchanged at `4.31.0`). + +- **Teams: Graph SSRF / token-leak guard hardening** (#178, security). `call_teams_graph_api` decided absolute-vs-relative URLs with a case-sensitive `startswith("http")`, so `HTTPS://evil.example/x`, `HtTpS://…` or the scheme-relative `//evil.example/x` fell into the relative-path branch, where `urljoin` still resolved to the attacker host and the Graph-scoped bearer token was attached without consulting `is_trusted_graph_url`. Routing now uses the same scheme-insensitive parse as the allowlist, so every absolute or scheme-relative target goes through the trust check. Regression tests cover the mixed-case and scheme-relative forms. +- **Tests:** the Teams skip-auth fixture survives the SDK's flag rename (#180). No runtime change. +- **Docs/licensing:** added `NOTICE` reproducing Vercel Chat's MIT copyright notice — this package is a derivative (port) of `vercel/chat`, and the notice now ships in the sdist and in the wheel's `dist-info/licenses/` (#179). No code changes. ## 0.4.31.1 diff --git a/CLAUDE.md b/CLAUDE.md index 22a030ba..e6558edc 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -30,6 +30,7 @@ Our version embeds the upstream Vercel Chat version: `0.{upstream_major}.{upstre - `0.4.30` = synced to upstream `4.30.0` - `0.4.31` = synced to upstream `4.31.0` - `0.4.31.1` = Python-only fixes on top of `4.31.0` (Slack #138/#95) +- `0.4.31.2` = Python-only fixes on top of `4.31.0` (Teams Graph SSRF-guard hardening #178, NOTICE) - `UPSTREAM_PARITY` constant in `__init__.py` = programmatic access ## Architecture diff --git a/README.md b/README.md index 9b6c9acb..7c64097d 100644 --- a/README.md +++ b/README.md @@ -7,7 +7,7 @@ Multi-platform async chat SDK for Python. Port of [Vercel Chat](https://github.com/vercel/chat) (MIT, © Vercel, Inc. — see [NOTICE](NOTICE)). -> **Status: 0.4.31.1 — synced to [Vercel Chat 4.31.0](https://github.com/vercel/chat)** (`UPSTREAM_PARITY = "4.31.0"`). See [CHANGELOG.md](CHANGELOG.md). +> **Status: 0.4.31.2 — synced to [Vercel Chat 4.31.0](https://github.com/vercel/chat)** (`UPSTREAM_PARITY = "4.31.0"`). See [CHANGELOG.md](CHANGELOG.md). ## Why chat-sdk? diff --git a/pyproject.toml b/pyproject.toml index 94108bcc..17f8b161 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "chat-sdk" -version = "0.4.31.1" +version = "0.4.31.2" description = "Multi-platform async chat SDK for Python — port of Vercel Chat" keywords = [ "chat",