|
1 | 1 | # @cipherstash/cli |
2 | 2 |
|
| 3 | +## 1.0.0-rc.1 |
| 4 | + |
| 5 | +### Minor Changes |
| 6 | + |
| 7 | +- 134fd43: Add anonymous, opt-out usage analytics to the `stash` CLI, plus a |
| 8 | + `stash telemetry [status|enable|disable]` command to manage it. |
| 9 | + |
| 10 | + Only coarse events are collected — command name, CLI version, OS/arch, Node |
| 11 | + version, success/failure, duration, and a coarse caller class (e.g. |
| 12 | + `claude-code`, `cursor`, `interactive`) derived from environment markers so we |
| 13 | + can gauge agent- vs human-driven usage. Events carry a random install |
| 14 | + identifier (a locally generated UUID, not derived from any machine or user |
| 15 | + attribute) used only to de-duplicate events in aggregate. Plaintext, schema, |
| 16 | + table/column names, |
| 17 | + connection strings, argument values, and any session/trace identifier are never |
| 18 | + collected — enforced by a property-key allowlist at the emitter boundary plus |
| 19 | + closed-vocabulary coercion of every argv- or error-derived value (unrecognised |
| 20 | + commands, subcommands, and error class names all collapse to `<other>`). A |
| 21 | + one-time notice is shown on first run, and nothing is sent on that run. |
| 22 | + |
| 23 | + Telemetry is off by default in CI and can be disabled with `DO_NOT_TRACK=1` |
| 24 | + (the cross-tool standard), `STASH_TELEMETRY_DISABLED=1`, or |
| 25 | + `stash telemetry disable` (persisted to `~/.cipherstash/telemetry.json`). |
| 26 | + |
| 27 | + Events are sent via a first-party proxy and never block or slow the CLI. The |
| 28 | + feature ships dormant — no events are sent until a PostHog project key is |
| 29 | + embedded at release. Updates the `stash-cli` skill to document the command and |
| 30 | + opt-out controls. |
| 31 | + |
| 32 | +### Patch Changes |
| 33 | + |
| 34 | +- 59b994e: Add EQL v3 JSON **selector-with-constraint** querying to the Drizzle integration |
| 35 | + (#623). `ops.selector(col, '$.path')` returns comparison methods bound to a |
| 36 | + JSONPath into a `types.Json` column — `eq`/`ne`/`gt`/`gte`/`lt`/`lte` — emitting |
| 37 | + `col->'<selector>' <op> <value>` over the encrypted document. Its unique power |
| 38 | + over `contains` is **ordering at a path** (`col->'$.age' > 21`), which |
| 39 | + containment cannot express. |
| 40 | + |
| 41 | + Complements the existing `contains` (JSONB `@>`) containment operator. Core |
| 42 | + `@cipherstash/stack` needs no change — the selector hash and comparison entry are |
| 43 | + produced by `encryptQuery`/`encrypt` on the existing `types.Json` surface. v1 |
| 44 | + supports dot-notation object paths; array-index/wildcard paths are rejected with |
| 45 | + a clear error. The Supabase adapter is tracked separately. |
| 46 | + |
| 47 | + The right-hand comparison operand is currently a storage-encrypted needle (its |
| 48 | + ste_vec entry carries the ordering term), pending a ciphertext-free ordering |
| 49 | + query needle from protect-ffi (cipherstash/protectjs-ffi#137); until then the |
| 50 | + value's ciphertext appears in the WHERE clause. |
| 51 | + |
| 52 | + The bundled `stash-encryption` and `stash-drizzle` skills document the new |
| 53 | + `ops.selector(...)` surface (they previously said JSONPath selector queries were |
| 54 | + not yet implemented). |
| 55 | + |
| 56 | +- e297f64: Docs: EQL v3 is now the sole documented approach. The `stash-encryption`, |
| 57 | + `stash-drizzle`, and `stash-supabase` skills and the `@cipherstash/stack` |
| 58 | + README teach only the v3 typed surface (`EncryptionV3`, `types.*` concrete |
| 59 | + domains, `@cipherstash/stack-drizzle/v3`, `encryptedSupabaseV3`); EQL v2 |
| 60 | + shrinks to one short Legacy section per document. Two explicit exceptions are |
| 61 | + called out: DynamoDB still requires the v2 schema surface (#657), and the |
| 62 | + encrypt rollout tooling (`stash encrypt backfill`/`cutover`, |
| 63 | + `@cipherstash/migrate`) currently targets v2 columns (#648) — its guidance is |
| 64 | + kept under a version callout. Also corrects the legacy `@cipherstash/drizzle` |
| 65 | + README's pointer to the removed `@cipherstash/stack/drizzle` subpath (now the |
| 66 | + separate `@cipherstash/stack-drizzle` package). |
| 67 | +- 40ab142: Docs: stop teaching the deprecated `LockContext.identify()` as the primary |
| 68 | + identity-aware-encryption path (#591). The `stash-encryption` and `stash-supabase` |
| 69 | + skills and the `@cipherstash/stack` README now lead with the current pattern — |
| 70 | + authenticate the client with `OidcFederationStrategy`, then bind the claim per |
| 71 | + operation with `.withLockContext({ identityClaim })` — and demote |
| 72 | + `LockContext.identify()` to a clearly-marked deprecated note (per-operation CTS |
| 73 | + tokens were removed in protect-ffi 0.25). Skills ship in the `stash` tarball, so |
| 74 | + this keeps the bundled guidance correct for the 1.0 surface. |
| 75 | +- 5fe9a2f: Encrypted-JSON querying on the v3 Supabase surface (#650). A `types.Json` |
| 76 | + column now supports exact encrypted containment — `contains(col, subDocument)` |
| 77 | + (ste_vec `@>` via PostgREST `cs`, with the sub-document storage-encrypted |
| 78 | + against the column) — and JSONPath selector predicates: `selectorEq(col, path, |
| 79 | +value)` and `selectorNe(col, path, value)` (dot-notation paths; `ne` includes |
| 80 | + rows where the path is absent, mirroring the Drizzle selector's semantics). |
| 81 | + Raw `.filter(col, 'cs', subDocument)` and `not(col, 'contains', …)` route |
| 82 | + through the same encrypted path. Selector ordering is not expressible over |
| 83 | + PostgREST yet (needs an EQL-bundle overload — see |
| 84 | + cipherstash/encrypt-query-language#407); the Drizzle integration's |
| 85 | + `ops.selector()` covers ordering today. |
| 86 | + |
| 87 | + In core, `QueryTypesForColumn` gains the `searchableJson` arm (a `types.Json` |
| 88 | + column no longer resolves to `never`, so typed adapter key sets can include |
| 89 | + it), and the JSONPath selector-path helpers the Drizzle adapter introduced in |
| 90 | + #651 moved to `@cipherstash/stack/adapter-kit` so both adapters share one |
| 91 | + validation surface (`@cipherstash/stack-drizzle` re-exports them unchanged). |
| 92 | + |
| 93 | + The bundled `stash-supabase` and `stash-encryption` skills are updated to |
| 94 | + document the new querying surface (including the array-leaf and SQL-NULL |
| 95 | + semantics, and the operand-exposure caveat) — skills ship inside the `stash` |
| 96 | + tarball, hence the patch. |
| 97 | + |
| 98 | + - @cipherstash/migrate@1.0.0-rc.0 |
| 99 | + |
3 | 100 | ## 1.0.0-rc.0 |
4 | 101 |
|
5 | 102 | ### Major Changes |
|
0 commit comments