Released
Changelog Update: October 2025
Enhanced authorization framework, modernized certificate handling, and added various improvements across the Vidos identity platform.
Authorization Framework
TypeScript Policy Engine: Replaced the Open Policy Agent (OPA) with a native TypeScript-based policy engine for authorization decisions
- Implemented
PolicyEngineclass with comprehensiveevaluateAllowandevaluateMustDenymethods - Added detailed resource and action matching using glob patterns for flexible policy rules
- Removed OPA-related dependencies
- Streamlined policy evaluation logic and test coverage
Authorizer Testing:
- Enhanced the Authorizer Tester with improved request handling and visualization
- Fixed date handling in authorization to properly handle the "now" parameter
- Added comprehensive testing samples for various authorization scenarios, used throughout documentation and dashboard testers
Cryptography and Verification
X.509 Certificate Generation: Refactored X.509 certificate handling
- Completed upgrade of legacy certificate generation
- Updated validity period handling to use explicit notBefore and notAfter dates
- Improved test coverage for certificate generation and validation
Mobile Document Support: Fixed date fetching for mDOC format when applying notBefore and notAfter policies
Wallet Integration: Enhanced support for Multipaz/Valera wallets
- Additional OpenID4VP compatibility and conformance testing to ensure better interoperability with wallet providers
- Added custom test credentials for more comprehensive end-to-end testing
Documentation and Developer Experience
W3C Verification Guides: Improved documentation and examples for W3C verification standards
Documentation Site: Migrated documentation site to a more modern and maintainable architecture
Verifier Configuration: Added comprehensive documentation for verifier configuration options
Database and Infrastructure
SSL Database Support: Enhanced database connection configurations and improved connection pooling
Security Enhancements:
- Updated authorization logic in viewer-request.js
- Enhanced helmet security configuration in application setup
Error Handling and Logging
- Gateway Errors: Improved gateway error reporting for clearer troubleshooting
- Instance Configuration: Enhanced instance configuration UI with improved validation
- Error Handling: Fixed resource ID checking in applicableForTestingOptions function
- Logging Framework: Implemented a logging wrapper for verifier and validator services