NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1315 most downloaded on PyPI
WebSocket client & server library, WAMP real-time framework
Last release 2 months ago
15 Jul 2026
Release timing varies
gaps range from 9 days to 1.2 years
Nearly every release is documented
notes for 57 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
161 releases · first in 2011
…advisory GHSA-hxp9-w8x3-p566, same class as CVE-2016-10544). The limit is now re-checked at the inflation site against the running uncompressed messag…
Security
Fix WebSocket maxMessagePayloadSize being enforced against the compressed on-the-wire frame length instead of the uncompressed reassembled message size when permessage-compress (deflate/bzip2/snappy/brotli) is negotiated. A small compressed frame could inflate far beyond the configured limit and be delivered to the application (a decompression-bomb style denial-of-service; security advisory GHSA-hxp9-w8x3-p566, same class as CVE-2016-10544). The limit is now re-checked at the inflation site against the running uncompressed message size, and the connection is failed with close code 1009 (message too big) before delivery — for both the whole-message and streaming receive APIs and every compression backend. Behaviour change: a compressed message that inflates past maxMessagePayloadSize is now rejected where it previously passed; uncompressed traffic and the per-frame maxFramePayloadSize wire guard are unaffected (#1909)
Fix the permessage-deflate max_message_size receive cap silently truncating an over-limit message and raising a zlib error instead of cleanly rejecting it: the bounded decompress(…, max_length) left the remaining input in unconsumed_tail undrained, so the message was corrupted rather than reported. Decompression is now bounded cumulatively across frames and raises PayloadExceededError as soon as the uncompressed size would exceed the cap (#1908)
Make bounded decompression backend-agnostic: decompress_message_data() gains an optional max_output_len argument (documented on the PerMessageCompress base class) and every permessage-compress backend now honours it. deflate and bzip2 stop inflating once the limit is reached (native incremental cap); snappy and brotli, whose libraries expose no output-length argument, inflate the frame (already bounded on the wire by maxFramePayloadSize) and then reject — a weaker but still clean per-frame guarantee. The WebSocket receive path passes the remaining maxMessagePayloadSize budget so a compressed frame no longer expands unbounded into memory before the size check; the previous post-inflation check (#1909) remains as a backstop. Previously only deflate had any decompressed-output cap, so a snappy/bzip2/brotli frame could inflate fully into memory first (#1910)
Make the asyncio RawSocket receive size limit configurable, at parity with the Twisted backend. The asyncio WampRawSocketFactory now exposes setProtocolOptions(maxMessagePayloadSize=...) / resetProtocolOptions() (bounds [512, 2**24], default 16 MB), and the configured value drives both the advertised handshake length exponent and the enforced receive cap (rounded up to the next power of two), matching the Twisted factory. Previously the asyncio receive limit was hardwired to 16 MB (a dead max_size=None branch), so an asyncio WAMP peer could not tighten its RawSocket receive limit for DoS hardening and Crossbar's RawSocket max_message_size had no effect on the asyncio path (#1911)
FlatBuffers
Fix check_zlmdb_flatbuffers_version_in_sync() comparing the build-time version() (which is (0, 0, 0, None, None) on installed wheels, where the vendored FlatBuffers __git_version__ is unstamped) — it now compares the reliably-stamped __version__ and returns a version string. Added regression tests (#1891)
Make autobahn.flatbuffers.version() reliable on installed wheels: when the build-time __git_version__ is a bare commit hash or "unknown" (shallow clone / submodule absent from the sdist), version() now falls back to parsing the static vendored __version__ and returns (major, minor, patch, None, None) instead of (0, 0, 0, None, None); rich git describe detail is still returned on genuine dev/git builds. Also hardened hatch_build.py so it never stamps a non-parseable __git_version__. Return shape is unchanged (5-tuple); no API break (#1891)
Build & CI/CD
Add CalVer / PEP 440 version-management just recipes (file-version, bump-dev, bump-next, prep-release) mirroring Crossbar.io, and document the versioning policy in CONTRIBUTING.md (#1894)
Add ruff check --select ANN,UP,TCH (annotation presence, pyupgrade modern syntax, TYPE_CHECKING imports) to the just check-typing recipe so annotation/style regressions are caught in the quality-checks CI job. The existing gaps in src/autobahn/ are ratcheted via an explicit --ignore allowlist to be removed module-by-module (#1839); all other UP/TC rules are enforced immediately, and generated code is excluded. The annotation rules are scoped to this recipe via the command line rather than the global [tool.ruff.lint] select, so the repo-wide check-format gate is unaffected (#1840)
Fix the aarch64 CPython 3.14 wheel shipping the free-threaded ABI (cp314t) in the GIL cp314 slot (26.6.x). Root cause: manylinux images pre-install both the GIL and free-threaded 3.14 under /opt/python and prepend them to PATH, and uv resolved cpython-3.14 to the free-threaded interpreter (first on PATH). The create recipe now drops free-threaded …t/bin dirs from PATH for GIL envs so uv selects the GIL build. As defence-in-depth, just build also asserts (via _check-venv-abi) that the interpreter's GIL/free-threaded status matches the env and aborts on mismatch, so a wrong-ABI wheel can never be published. A reserved cpy314t env spec (cpython-3.14t) is added for a future free-threaded wheel variant (#1875)
Bump the .cicd (wamp-cicd) submodule to include exact CPython ABI-tag matching in the shared check-release-fileset release-gate action, so a wrong-ABI wheel (e.g. cp314t in the cp314 slot) is also rejected at release-fileset validation, not only by the build-time guard above (wamp-cicd #11, completes #1875)
Publish musllinux_1_2 (musl libc / Alpine Linux) binary wheels with NVX acceleration for CPython 3.11–3.14 on both x86_64 and aarch64. Previously pip install autobahn on Alpine fell back to a source build that failed (the clang-built python-build-standalone interpreter's sysconfig carries a --rtlib=compiler-rt flag that Alpine's gcc rejects), so Alpine users could not install autobahn at all; the prebuilt wheels make it "just work". Built inside the official PyPA musllinux_1_2 images (gcc toolchain), tagged automatically by auditwheel, and gated by the check-release-fileset targets. PyPy-on-musl is a tracked follow-up (no official PyPA musllinux PyPy image) (#1877)
One column per quarter.
Fix import autobahn.wamp.cryptosign raising TypeError: unsupported operand type(s) for |: 'str' and 'NoneType' on CPython 3.11/3.12/3.13 when crypto s
WAMP Cryptosign
Fix import autobahn.wamp.cryptosign raising TypeError: unsupported operand type(s) for |: 'str' and 'NoneType' on CPython 3.11/3.12/3.13 when crypto support (nacl) is installed. A ruff UP007 autofix in 26.6.1 (#1843) had rewritten Optional["ISecurityModule"] to "ISecurityModule" | None in a module that lacks from __future__ import annotations, so the string forward-reference union was evaluated eagerly at class-definition time (CPython 3.14 was unaffected because PEP 649 defers annotation evaluation). The regression broke WAMP-cryptosign and any importer with crypto dependencies present (e.g. xbr, Crossbar.io) on CPython < 3.14. Added from __future__ import annotations to cryptosign.py to defer annotation evaluation (#1878)
Build & CI/CD
Add an import smoke test that imports every public autobahn submodule with the crypto extras installed, so eager-evaluation annotation regressions like #1878 are caught in CI on all supported Python versions (#1878)
Fix the Twisted WampRawSocketProtocol raising TransportLost out of dataReceived when the opening handshake fails before a WAMP session is attached (e.
WAMP RawSocket
Fix the Twisted WampRawSocketProtocol raising TransportLost out of dataReceived when the opening handshake fails before a WAMP session is attached (e.g. an invalid magic byte from a port scanner). abort() now tears down the transport whenever a transport is present - rather than only when a session is open - so a failed handshake closes the connection cleanly with a single warning instead of an "Unhandled Error" stack trace, and handshake processing stops instead of continuing past the abort. The asyncio backend already behaved correctly; cross-backend regression tests were added for both. Thanks to @karel-un for the report (#1850)
WAMP Serialization
py-ubjson (unmaintained, sdist-only) is no longer an unconditional dependency. A base pip install autobahn — and the wheels-only / cross-arch case from #1849 (pip download --only-binary :all: --platform ...) — now resolves entirely from binary wheels (#1849)
The WAMP ubjson serializer is now backed by the maintained bjdata (Binary JData) package, provided as the OPTIONAL autobahn[serialization] extra (it also pulls in numpy), keeping both out of a minimal install (#1849)
bjdata is published sdist-only (no PyPI wheels) and is currently CPython-only: on PyPy its sdist build pulls an unbuildable numpy (upstream NeuroJSON/pybj#6), so the ubjson serializer is unavailable on PyPy - use cbor/msgpack there. On CPython without a compiler, set PYBJDATA_NO_EXTENSION=1 for a pure-Python build. For wheels-only or cross-arch deployments, also prefer cbor/msgpack (#1849)
⚠️ Wire-level change to watch out for: bjdata's octet-level encoding is NOT identical to the previous py-ubjson/UBJSON bytes (different integer markers, little-endian). The WAMP serializer id remains ubjson for transport negotiation. The wamp-proto UBJSON test vectors will be regenerated in a follow-up PR after this release; until then the ubjson serializer is excluded from the byte-vector conformance suite (round-trip and cross-serializer coverage retained) (#1849)
FlatBuffers
Bump vendored FlatBuffers from v25.9.23 to v25.12.19, restoring the version-sync with zlmdb 26.6.1 (#1853)
Commit the binary schemas (reflection.bfbs, wamp.bfbs) to the source tree and ship them as-is; the package build no longer runs flatc, which fixes cross-compilation from the PyPI sdist (e.g. Buildroot/Yocto/aarch64) (#1853)
Add just generate-reflection to regenerate the committed binary schemas with a version-matched flatc built from deps/flatbuffers (#1853)
Add just check-flatbuffers-sync and a unit test exercising check_zlmdb_flatbuffers_version_in_sync() (#1853)
Delete two orphaned generated files, Kdf.py and ChannelBinding.py, left in src/autobahn/wamp/gen/wamp/proto/ after the schema renamed those tables to KDF and TLSChannelBinding. Their case-insensitive collisions with the current KDF.py / TLSChannelBinding.py broke git clone and directory copies on case-insensitive filesystems (APFS/macOS, some Docker setups). They are no longer produced by flatc, and the verification from #1830 now keeps such orphans from recurring. Thanks to @dcki for the report (#1828)
Build & CI/CD
Bump shared .ai (wamp-ai) and .cicd (wamp-cicd) submodules to match zlmdb exactly (#1853)
Fix scripts/update_flatbuffers.sh git-version capture for submodule checkouts (.git is a file, not a directory) (#1853)
Bump the .cicd (wamp-cicd) submodule to pick up the script/shell-injection fix in the shared identifiers.yml reusable workflow (untrusted GitHub event fields are now passed via env: as quoted data with a fail-closed branch-name allowlist) (#1856)
Fail wheel builds hard when NVX was requested (AUTOBAHN_USE_NVX) but the CFFI extension did not compile, instead of silently degrading to a pure-Python (py3-none-any) wheel. A transient native-compile crash (e.g. a gcc SIGSEGV under QEMU ARM64 emulation) now aborts the build with a non-zero exit so CI can retry it, rather than uploading a structurally valid but unintended artifact. Building with AUTOBAHN_USE_NVX=0 still produces a pure-Python wheel as before (#1856)
Fix NVX native-extension builds breaking under cross-compilation (e.g. Buildroot/Yocto for aarch64), where the cross toolchain rejected the host-only -march=native flag (unknown value 'native' for '-march'). The default architecture target is now the portable baseline for all build contexts (wheels, local source installs, and cross-compilation), with -march=native available opt-in via AUTOBAHN_ARCH_TARGET=native. The target architecture is detected via sysconfig.get_platform() so the correct baseline is chosen when cross-compiling. Thanks to @jameshilliard for the original report and approach (#1834, #1835)
Fail the just build-all recipe (non-zero exit) when any per-interpreter wheel build fails, naming the interpreter(s). Previously a failed build was silently swallowed, producing a green wheels job with a missing wheel that was only caught downstream by strict release fileset validation (#1859)
Cap cbor2 < 6 on PyPy/Windows only (via environment markers), keeping cbor2 6.x everywhere else. cbor2 6.x is Rust/pyo3-only with no PyPy/Windows wheel and no pure-Python fallback, so it cannot be installed on PyPy/Windows; the 5.x line ships a pure-Python wheel (and runs at near-native speed on PyPy). This unblocks building and installing autobahn on PyPy/Windows (#1859)
Build and publish the missing CPython 3.12 and 3.14 manylinux_*_aarch64 (ARM64) wheels. The per-version ARM64 build matrix (added in commit 3d856f5 to deduplicate wheels) only covered cp311 and cp313, so no cp312 aarch64 wheel was ever published (and cp314 was never added) - e.g. pip download autobahn --platform manylinux_2_34_aarch64 for CPython 3.12 found no matching distribution. The strict release fileset manifest shared the same gap and so could not catch it; it now requires the cp312/cp314 aarch64 wheels (fail-closed). Thanks to @norrisjeremy for the report (#1848)
Make the release fileset symmetric across all four platforms: every supported interpreter (cp311, cp312, cp313, cp314, pypy311) is now required on macOS/arm64, Linux/x86_64, Linux/aarch64, and Windows/amd64. The macOS job already built all interpreters via just build-all, but the manifest only required cp313/cp314/pypy311, so the cp311/cp312 macOS wheels were built and then dropped as "extra" rather than published; they are now kept and required (#1848)
Remove orphaned/attic files left over from the pre-justfile/uv CI/CD system: Makefile.orig, Dockerfile.wheels, mypy.ini, test-docker-builds.sh, versions.sh, deploy.sh, .prettierrc.json, .coveragerc, docs/DOCKER_BUILDS.md, docker/README.md and the pyinstaller/ PyInstaller hooks, plus the unused pyinstaller dev dependency. The .coveragerc omit = */test/*.py setting was preserved by migrating it to [tool.coverage.run] in pyproject.toml (so coverage still excludes in-package test modules), and the stale DOCKER_BUILDS.md entry was dropped from the Sphinx exclude_patterns. mypy is unaffected: the typing recipe already passes --config-file pyproject-static-typing.toml explicitly. setuptools was added explicitly to the dev extra: it is required by cffi's ffi.compile() to build the NVX extensions in an editable install on Python >= 3.12 (stdlib distutils was removed in 3.12) and had been pulled in only transitively via the removed pyinstaller (#1831)
Fix the FlatBuffers generated-code verification so it actually detects drift. The build-fbs recipe now uses the vendored, version-matched flatc bundled in the venv (${VENV_PATH}/bin/flatc) instead of an arbitrary system flatc, and the CI job runs just clean-fbs before just build-fbs so orphaned/stale generated files no longer survive in both the before and after states (previously they matched checksums and went undetected). On drift the job now fails with an actionable, categorized table - content differs (regenerate & commit, e.g. after a vendored-flatc bump), orphan / not generated (delete), new, not committed (commit) - derived from git status of the regenerated tree (#1830)
Synchronize CI/CD, FlatBuffers vendoring, and wamp-ai/wamp-cicd submodules between autobahn-python and zlmdb
Build & CI/CD
Synchronize CI/CD, FlatBuffers vendoring, and wamp-ai/wamp-cicd submodules between autobahn-python and zlmdb (#1822)
Switch manylinux container from 2_34 to 2_28 for x86_64 ISA compatibility (fixes auditwheel flatc bundling)
Increase ARM64 build timeout to 60 minutes for QEMU emulation
Add .github/workflows/README.md documenting CI/CD architecture
Consolidate download-github-release and download-release-artifacts recipes
Add checksum verification to artifact download workflow
FlatBuffers
Simplify vendored FlatBuffers - use upstream as-is
Track vendored FlatBuffers in git (like zlmdb approach)
Add version() function to vendored FlatBuffers runtime
Add check_zlmdb_flatbuffers_version_in_sync() for cross-project compatibility
Generate .bfbs files for WAMP schemas during wheel build
Other
Rename install-flatc to install-flatc-system with prominent warning
Remove legacy readthedocs.yml to activate .readthedocs.yaml
Remove dev-latest optional dependency (PyPI rejects direct URLs)
Add vendored Flatbuffers (v25.9.23)
New
Add vendored Flatbuffers (v25.9.23) (#1761)
Add WAMP serdes functional and benchmark testing; WAMP-Flatbuffers; WAMP Serializer Composition (transport/payload) (#1765)
Fix
Fix 1757 (#1758)
Fix 1767 (#1769)
Fix 1771 complete (#1774)
Other
Rel v25.10.2 (#1734)
Rel v25.10.2 part2 (#1741)
WAMP Flatbuffers serialization test coverage; WAMP message classes refactoring (#1773)
Modernization phase 1.1 (#1785)
Phase 1.2: Build Tooling Modernization (#1788)
Phase 1.3: CI/CD Modernization (#1791)
Rel25 12 1 (#1794)
Modernization phase 1.4 (#1797)
Add Sphinx label to changelog for cross-references
add changelog/release-notes for 25.12.1 - first draft
Refactor release recipes to use external scripts
Add automated release docs generation recipes
Add changelog and release notes for 25.12.1
Bump .cicd submodule: fix recursive copy for directories
Bump .cicd submodule: fix download retry wiping other artifacts
Bump .cicd submodule: prefix matching for artifact download
Bump .cicd submodule: include-hidden-files fix
Remove workaround for hidden files, use .audit/ directly
Workaround: copy .audit to non-hidden dir for artifact upload
Fix container jobs: use relative paths for artifact upload
Fix container job: capture workspace path via pwd at runtime
Debug container workspace paths and retry github.workspace
Fix container job: get workspace path at runtime via pwd
Use env.GITHUB_WORKSPACE for container job artifact paths
Use absolute paths for all download-artifact-verified calls
Use absolute paths for all upload-artifact-verified calls
Fix summary upload: use relative path for .audit directory
Fix summary upload: use directory path instead of file path
Pass artifact names via job outputs for verified downloads
Add verbose permission logging to debug wstest artifact uploads
Use sudo chown to fix wstest directory permissions
Fix permissions on wstest directories before artifact upload
Fix multi-path artifact upload for verified action
Replace actions/*-artifact@v4 with verified actions
Fix GitHub Discussions category for CI-CD notifications
Add automatic GitHub Discussions post for stable releases
Add check-release-fileset action to release workflows
Fix release-stable job: use dynamic artifact names with meta-checksums
Add tag triggers to all workflows
Update wamp-cicd submodule for CRLF line ending fixes
Fix wheels-docker workflow: remove source dist copy
Separate wheel and source distribution builds
Add self-verification to catch GitHub artifact serving bugs
Use unique artifact names with meta-checksum for reliable downloads
Replace pattern-based downloads with individual verified downloads
Update .cicd submodule: add overwrite parameter to download-artifact-verified
Update .cicd submodule: fix unzip to force overwrite without prompting
Update .cicd submodule: fix download-artifact-verified to use gh api
fix: Output Sphinx docs to RTD-required directory
fix RTD project name
Supply Chain Security
new: Migrate to verified artifact actions (wamp-proto/wamp-cicd) for cryptographic integrity verification
new: Meta-checksum embedded in artifact names enables self-verification (detects GitHub serving wrong artifact)
new: Staging directory isolation prevents retry cleanup from destroying other successful downloads
fix: Recursive copy for artifacts containing directory structures
new: Add automated release docs generation recipes
new: Refactor release recipes to use external scripts
CI/CD Infrastructure
fix: Container job path handling - use relative paths to avoid host/container path conflicts
fix: Hidden files now included in artifact uploads (actions/upload-artifact@v4.4+ compatibility)
fix: Artifact prefix matching for downloads when names include meta-checksum suffix
Nothing published for this version
Nothing published for this version
fix: Server conformance testing properly tests both with-nvx and without-nvx configurations - servers now restart for each configuration ensuring accu
Critical Fixes
fix: Server conformance testing properly tests both with-nvx and without-nvx configurations - servers now restart for each configuration ensuring accurate test results
fix: Version consistency - autobahn/_version.py now matches pyproject.toml
fix: GitHub release artifact integration targets correct directory (docs/_build/html/_static/ not docs/_static/)
Supply Chain Security
fix: Issue #1716 - Added comprehensive source distribution integrity verification with cryptographic fingerprints
new: Chain of custody verification ensures artifact integrity from build → artifact → release
new: Re-verification in release workflow with OpenSSL version compatibility (handles both 1.x and 3.x formats)
new: PyPI upload safety check prevents duplicate version uploads
Documentation & Release Infrastructure
new: RTD documentation includes WebSocket conformance reports and FlatBuffers schemas via GitHub Release artifacts
new: Streamlined release artifact download with just download-github-release recipe (auto-detects nightly/stable/dev)
new: Automated docs integration with just docs-integrate-github-release recipe
fix: Nightly release detection now correctly identifies master-YYYYMMDDHHMM releases
fix: Pre-release checklist Section 6 simplified to use justfile recipes
Wheel Building
fix: ARM64 wheel builds eliminate duplicate wheels by building specific Python versions per job
fix: Filter out plain linux_* wheels before PyPI upload
fix: PyPI publishing removes non-package files from dist/
fix: Various deprecation warnings in tests
Major Features
new: NVX native XOR masking acceleration for WebSocket frame masking/unmasking (#1697) - up to 100x faster on supported CPUs
new: ARM64 wheel building infrastructure via QEMU emulation for CPython 3.11, 3.13 and PyPy 3.11
new: Docker QEMU multi-arch wheel building system (#1673) supporting manylinux_2_17 and manylinux_2_28
Tooling Modernization
new: Migration to modern Python toolchain - just, uv, and ruff (#1672, #1671, #1669, #1668, #1666)
new: Removed setuptools dependency (#1652) - now using modern pyproject.toml-based build
new: Concrete versioning for just (1.42.3) and uv (0.7.19) instead of "latest"
fix: GITHUB_TOKEN set for upstream just/uv installation to avoid rate limits
Deprecation Removals
fix: Stop using twisted.internet.defer.returnValue (#1667, #1651) - replaced with native return statements
fix: Various deprecation warnings in tests (#1647)
CI/CD & Release Improvements
new: Symmetric release structure across all 3 release types (stable, nightly, development)
new: Early Exit Pattern in release workflows prevents unnecessary runs
new: Completion marker prevents duplicate GitHub Discussions posts
new: GitHub Discussions support with correct category ID for automated release announcements
new: FlatBuffers schema packaged as tarball in GitHub releases
fix: Cross-workflow artifact downloads with run-id parameters
fix: Timestamp verification prevents matching old releases
fix: Event type detection in release-post-comment for nested workflow_run triggers
fix: Branch references updated from 'main' to 'master' throughout workflows
fix: Workflow naming simplified, tests no longer required for build-package
Platform-Specific Fixes
fix: PyPy ARM64 builds add /root/.local/bin to PATH for uv
fix: ARM64 CPython 3.11 uses manylinux_2_17, CPython 3.13 uses manylinux_2_28
fix: Build-tools extras added to avoid nh3 segfault under QEMU ARM64
fix: Auditwheel failures non-fatal to handle QEMU segfaults
fix: Windows builds use MSVC attributes and invoke pip via python
fix: VENV_PYTHON variable set and used consistently across platforms
Refactoring & Cleanup
new: AI policy announcement (#1663) - upcoming contributor guidelines for AI-assisted contributions
new: LMDB & XBR code refactored and broken out (#1664)
fix: Plain twisted utilities are sufficient (#1661) - removed unnecessary dependencies
fix: Emoji characters removed from bash scripts (causing syntax errors)
fix: External bash scripts for ARM64 build logic
fix: Ensure ID generator in range [1, 2 53]
fix: Ensure ID generator in range [1, 2 ** 53] (#1637)
fix: use regular PyPI bitarray>=2.7.5 rather than from GitHub master
fix: use regular PyPI bitarray>=2.7.5 rather than from GitHub master
fix: updated bitarray to make eth-account work on pypy
fix: updated bitarray to make eth-account work on pypy
fix: updated web3 and eth-abi to not use beta versions (#1616)
fix: monkey patch web3/eth_abi for python 3.11
fix: monkey patch web3/eth_abi for python 3.11
fix: support for Python up to v3.11
fix: support for Python up to v3.11
fix: update GitHub CI
fix: copyright transferred to typedef int GmbH - no license change!
fix: remove coverage crap
new: expand WAMP Flatbuffers schemata (session ID in each message for MUXing)
new: expand WAMP Flatbuffers schemata (session ID in each message for MUXing)
new: update flatc v22.12.06 and regenerate WAMP Flatbuffers type libraries
fix: Twisted 22.10.0 incompability (#1604)
fix: Rapid Cancelling Of Tasks Can Cause InvalidStateError (#1600)
fix: identify_realm_name_category (#1590)
fix: support Python 3.11 (#1599)
fix: building _nvx_utf8validator extension on non-x86 systems (#1596)
fix: asyncio rawsocket protocol transport details (#1592)
new: expand EIP712AuthorityCertificate; more tests
fix: remove log noise from autobahn.websocket.protocol
fix: Fix a few typos in docs (#1587)
fix: remove log noise from autobahn.websocket.protocol (#1588)
new: add more helpers to EthereumKey and CryptosignKey (#1583)
new: EIP712 certificate chains, incl. use for WAMP-Cryptosign
fix: improve message logging at trace log level
fix: forward correct TLS channel ID once the TLS handshake is complete
new: add eip712 types for WAMP-Cryptosign certificates
new: add more helpers to EthereumKey and CryptosignKey
new: add EthereumKey.from_keyfile, CryptosignKey.from_keyfile, CryptosignKey.from_pubkey
new: add SecurityModuleMemory.from_config and SecurityModuleMemory.from_keyfile
new: add SecurityModuleMemory.from_config and SecurityModuleMemory.from_keyfile
new: moved UserKey from crossbar to autobahn
fix: more WAMP-Cryptosign unit tests
new: experimental WAMP API catalog support
new: regenerate FlatBuffers WAMP messages
fix: allow tests to pass without XBR dependencies (#1580)
new: Flatbuffers IDL based WAMP payload validation (#1576)
fix: restore autobahn.twisted.testing to distribution (#1578)
new: WAMP Flatbuffers IDL and schema processing (experimental)
new: WAMP Flatbuffers IDL and schema processing (experimental)
new: WAMP-cryptosign trustroot (experimental)
new: add wrapper type for CryptosignAuthextra
fix: stricted type checking of Challenge; fix cryposign unit test;
new: more test coverage
fix: reduce log noise
fix: forward channel_binding selected in Component client
new: expand ISigningKey to provide security_module/key_id (if used)
fix: Component cryptosign test
fix: add type hints; fix channel_binding
new: work on federated realms and secmods
new: rename to and work on a.w.CryptosignKey
new: add bip44 for cryptosign test
fix: remove all txaio.make_logger refs from generic code (#1564)
new: initial support for federated WAMP realms via a.x.FederatedRealm/Seeder
new: moved utility functions and unit tests for WAMP realm name checking from Crossbar.io
new: allow list of URLs for transports in a.t.component.Component
new: add websocket_options to a.t.wamp.ApplicationRunner
new: add stop_at_close flag in a.t.component.run
fix: reduce log noise (regression) on ApplicationRunner Twisted (#1561)
new: allow max_retry_delay==0 for always-immediate auto-reconnect in ApplicationRunner on Twisted
new: add websocket_options to WAMP ApplicationRunner on Twisted (#888)
new: more type hints and docs
fix: can not import autobahn.twisted.util with no-TLS
fix: can not import autobahn.twisted.util with no-TLS (#1559)
new: improve ISession/ITransportHandler and implementations
new: modernize SessionDetails
new: improve ISession/ITransportHandler and implementations (#1557)
new: expand and refactor TransportDetails (#1551)
fix: misc fixes, add type hints, more docs (#1547)
new: key modules for use with WAMP-cryptosign (#1544)
fix: string formatting with binary values in TransportDetails.secure_channel_id (#1483)
fix: never default set authid/authrole in component authenticators
fix: TransportDetails string formatting (fixes #1486)
fix: reading private ssh key for cryptosign (fixes #932)
fix: do not throw (but log) when leaving a session not joined (#1542)
fix: store WAMP authextra received (#1541)
fix: split out UI deps into separate dist flavor
fix: split out UI deps into separate dist flavor (#1532)
fix: deps for RTD builds (#1540)
fix: use and bundle dev deps from requirements file
fix: reduce twisted log noise for wamp clients
fix: reduce twisted log noise for wamp clients (#1537)
fix: roundrobin in WAMP component (#1533)
fix: generate_token (#1531)
fix: add GitHub URL for PyPi (#1528)
fix: auto ping/pong logs should be debug instead of info
fix: auto ping/pong logs should be debug instead of info (#1524)
new: add auto-ping/pong configuration knob autoPingRestartOnAnyTraffic (see discussion here __).
new: add auto-ping/pong configuration knob autoPingRestartOnAnyTraffic (see discussion here).
new: extended websocket auto-ping/pong ("heartbeating") with builtin RTT measurement
new: experimental support for transaction_hash in WAMP Publish/Call (see discussion here).
new: support decimal numbers WAMP serialization and round-tripping in both JSON and CBOR
fix: only depend on cbor2 (for WAMP CBOR serialization), not also cbor
fix: PyInstaller and Docker build / CI issues
new: allow optional keys in endpoint config validation
new: support Python 3.10
new: allow optional keys in endpoint config validation
fix: reset transport retry status when connection succeeds
fix: update Docker/PyPy to pypy:3.8-slim
fix: autobahn installation in docker
fix: autobahn installation in docker (#1503)
new: refactor SigningKey class for reusability (#1500, #1501)
new: expand XBR node pairing helpers
fix: build with nvx by default and don't publish universal wheel. (#1493)
fix: update wamp flatbuffer schema for r2r links
fix: don't clobber factory (#1480)
fix: explicitly require setuptools
new: expand wamp auth scram and xbr argon2/hkdf (#1479)
fix: WebSocket compression, window size (zlib wbits) == 8 is illegal nowerdays (#1477)
fix: XBR IDL code generator - all 4 WAMP actions working now
new: add automated build of xbrnetwork CLI (single-file EXE) in CI
fix: Twisted v21.2.0 breaks Crossbar.io (see https://github.com/crossbario/crossbar/issues/1864)
fix: Twisted v21.2.0 breaks Crossbar.io (see https://github.com/crossbario/crossbar/issues/1864)
new: use_binary_hex_encoding option for JSON object serializer
new: use_binary_hex_encoding option for JSON object serializer
fix: correct some sphinx doc references
new: minimum supported Python (language) version is now 3.7 (on CPython and PyPy)
new: more XBR proxy/stub code generation capabilities (RPC call/invoation handlers)
fix: wamp-cryptosign loading of keys from SSH agent
fix: update Docker image building and build Docker multi-arch images
new: add more WAMP-cryptosign signature test vectors and unit tests
fix: include XBR code rendering templates in package manifest
new: XBR ABI files now via separate package ("xbr") - substantially reduce package size for non-XBR users
new: XBR ABI files now via separate package ("xbr") - substantially reduce package size for non-XBR users
fix: circular dependency in "xbr" install flavor (prohibited pip install from github master)
fix: XBR package manifest and CLI user profile loading
fix: consider 'wamp.close.goodbye_and_out' a clean exit
fix: consider 'wamp.close.goodbye_and_out' a clean exit (#1450)
fix: HASH import as well as improve diagnostics if things go wrong (#1451)
fix: add missing jinja2 dependency for XBR CLI (#1447)
fix: wamp.close.goodbye_and_out counts as a clean exit (#1370)
fix: URL must be re-encoded when doing redirect
fix: URL must be re-encoded when doing redirect (#1439)
fix: update and migrate CI/CD pipeline to GitHub Actions
new: minimum supported Python (language) version is now 3.6 (on CPython and PyPy)
fix: derive_bip32childkey traceback
fix: derive_bip32childkey traceback (#1436)
fix: update and adjust docker files to upstream changes
new: CLI commands for WAMP IDL (xbrnetwork describe-schema / codegen-schema)
new: CLI commands for WAMP IDL (xbrnetwork describe-schema / codegen-schema)
new: add eth address helpers (#1413)
new: cryptosign authextra allow arbitrary keys (#1411)
fix: adapt to planet api prefix change (#1408)
fix: Type check improve (#1405)
new: add market login eip. expose helpers
new: add market login eip. expose helpers (#1402)
fix: use cpy 3.8 for running flake in CI
fix: xbr fixes (#1396)
fix: use cpy 3.8 for running flake in CI
new: Ticket1392 internal attrs (#1394)
new: internal-only router attributes and hook for router to add custom information
new: massive expansion of XBR CLI and EIP712 helpers
new: massive expansion of XBR CLI and EIP712 helpers
new: more (exhaustive) serializer cross-tripping tests
fix: some code quality and bug-risk issues (#1379)
fix: removed externalPort assignment when not set (#1378)
fix: docs link in README (#1381)
fix: docs typo frameword -> framework (#1380)
fix: improve logging; track results on observable mixin
new: add environmental variable that strips xbr. (#1374)
fix: trollius is gone (#1373)
new: added ability to disable TLS channel binding (#1368)
fix: add missing XBR dependency py-multihash
new: XBR CLI (#1367)
fix: add missing XBR dependency py-multihash
new: XBR - package XBR v20.4.2 ABI files
new: XBR - package XBR v20.4.2 ABI files
new: XBR - adjust eip712 signature for channel close
new: XBR - adjustments after xbr refactoring (#1357)
new: XBR - add channel open/close eip712 types to AB (#1358)
new: WAMP-cryptosign - make channel_id_type optional in transport_channel_id()
new: XBR ABI files are downloaded from upstream and extracted into package (fixes #1349)
new: XBR ABI files are downloaded from upstream and extracted into package (fixes #1349)
new: expose new XBR top-level contracts
fix: bump dependencies versions for attrs and identity (#1346)
fix: FrontendProxyProtocol object has no attribute 'write' (#1339)
fix: WAMP-cryptosign authid is not mandatory; reduce log noise (#1340)
fix: confusion between paying and payment channel
fix: confusion between paying and payment channel (#1337)
new: forward explicitly set app level errors from ApplicationRunner.run() (#1336)
fix: simple typo: hookinh -> hooking (#1333)
new: update for xbr v20.3.1
fix: for #1327 - cancel Auto Ping Timeout (#1328)
new: helper function to create a configured Web3 blockchain connection (#1329)
new: update XBR ABI files to XBR release v20.2.2
new: update XBR ABI files to XBR release v20.2.2
new: update XBR ABI files to XBR release v20.2.1
new: update XBR ABI files to XBR release v20.2.1
fix: add AuthAnonymous to __all__ (#1303)
fix: use txaio.time_ns and drop deprecated autobahn.util.time_ns
fix: CI building (caching?) issue "corrupt ZIP file"
fix: update docker image build scripts and add ARM64/PyPy
fix: update XBR ABI files
fix: use txaio.time_ns and drop deprecated autobahn.util.time_ns
fix: update project README and docs for supported python versions (#1296)
fix: WebSocket protocol instances now raise autobahn.exception.Disconnected when sending on a closed connection (#1002)
fix: version conflict in xbr downstream application dependency (crossbarfx) (#1295)
fix: add python_requires>=3.5 to prevent installation on python 2
fix: add python_requires>=3.5 to prevent installation on python 2 (#1293)
IMPORTANT: release v19.11.2 will be the last release supporting Python 2. We will support Python 3.5 and later beginning with Autobahn v20.1.1.
IMPORTANT: release v19.11.2 will be the last release supporting Python 2. We will support Python 3.5 and later beginning with Autobahn v20.1.1.
fix: add docs for parameters to component.py (#1276)
new: statistics tracking on WAMP serializers autobahn.wamp.serializer.Serializer
new: helper autobahn.util.time_ns
fix: argument type check for fragmentSize in sendMessage
fix: argument type check for fragmentSize in sendMessage
new: start_loop option for WAMP components
new: ethereum bip39/32 helpers
new: enable XBR in Docker image build scripts
new: updated docker image scripts
new: updated docker image scripts
new: add WAMP serializer in use to SessionDetails
fix: partial support for xb buyers/sellers in pypy
fix: remove dependency on "ethereum" package (part of pypy support)
new: XBR - update XBR for new contract ABIs
new: XBR - update XBR for new contract ABIs
new: XBR - payment channel close
new: XBR - implement EIP712 signing of messages in endpoints
new: XBR - update XBR for new contract ABIs
new: XBR - update XBR for new contract ABIs
new: XBR - update XBR for new contract ABIs
new: XBR - update XBR for new contract ABIs
new: implement XBR off-chain delegate transaction signing and verification
new: implement XBR off-chain delegate transaction signing and verification (#1202)
new: update XBR for new contract ABIs
fix: monkey patch re-add removed helper functions removed in eth-abi
fix: monkey patch re-add removed helper functions removed in eth-abi
new: simple blockchain (XBR) client
new: update XBR ABI files
new: XBR endpoint transaction signing
new: client side catching of WAMP URI errors in session.call|register|publish|subscribe
fix: implement client side payload exceed max size; improve max size exceeded handling
fix: implement client side payload exceed max size; improve max size exceeded handling
fix: detect when our transport is "already" closed at connect time (#1215)
fix: XBR examples
fix: add forgotten cryptography dependency
fix: add forgotten cryptography dependency (#1205)
new: XBR client library integrated
new: XBR client library integrated (#1201)
new: add entropy depletion unit tests
fix: make CLI tool python2 compatible (#1197)
fix: use cryptography pbkdf2 instead of custom (#1198)
fix: include tests for packaging (#1194)
fix: set default retry_delay_jitter
fix: authextra merging (#1191)
fix: set default retry_delay_jitter (#1190)
new: add rawsocket + twisted example (#1189)
new: WebSocket testing support, via Agent-style interface (#1186)
new: decorator for on_connectfailure
fix: delayed call leakage (#1152)
new: CLI client (#1150)
fix: set up TLS over proxy properly (#1149)
new: expose ser modules (#1148)
fix: base64 encodings, add hex encoding (#1146)
new: onConnecting callback (with TransportDetails and ConnectingRequest). Note: if you've implemented a pure IWebSocketChannel without inheriting from Autobahn base classes, you'll need to add an onConnecting() method that just does return None.
fix: RegisterOptions should have details|bool parameter
fix: RegisterOptions should have details|bool parameter (#1143)
new: WAMP callee disclosure
new: WAMP forward_for in more message types; expose forward_for in options/details types
new: expose underlying serializer modules on WAMP object serializers
fix: WAMP-cryptosign fix base64 encodings, add hex encoding (#1146)
fix: import guards for flatbuffers (missed in CI as we run with "all deps installed" there)
fix: import guards for flatbuffers (missed in CI as we run with "all deps installed" there)
new: add experimental support for WAMP-FlatBuffers serializer: EVENT and PUBLISH messages for now only
new: add experimental support for WAMP-FlatBuffers serializer: EVENT and PUBLISH messages for now only
new: add FlatBuffers schema for WAMP messages
fix: improve serializer package preference behavior depending on CPy vs PyPy
fix: relax protocol violations: ignore unknown INTERRUPT and GOODBYE already sent; reduce log noise
fix: skipping Yield message if transport gets closed before success callback is called (#1119)
fix: integer division in logging in py3 (#1120)
fix: Await tasks after they've been cancelled in autobahn.asycio.component.nicely_exit (#1116)
fix: set announced roles on appsession object
fix: set announced roles on appsession object (#1109)
new: lower log noise on ApplicationErrors (#1107)
new: allow explicit passing of tx endpoint and reactor (#1103)
new: add attribute to forward applicationrunner to applicationsession via componentconfig
Your coding agent can read these notes before it upgrades. Set up the MCP server →