Skip to main content

0.8.0

ยท 9668 words
Downloads for 0.8.0

Welcome to Excalibur 0.8! This release improves the Excalibur Encryption Format, which enhances both security and performance. Expect a significant speed-up when encrypting and decrypting files when using the new encryption format.

The Excalibur documentation website was also updated in this release.

If you are developing a custom Excalibur client, please read the 0.8 upgrade guide to learn how to interact with Excalibur 0.8 servers. If you are using the official app and server, there is no need to follow the upgrade guide.

Read all about the changes to Excalibur below. Enjoy!

Appโ€‹

๐Ÿ”’๏ธ Securityโ€‹

  • ๐Ÿ”’๏ธ Overridden version minima of dependencies in pnpm-workspace.yaml to address security vulnerabilities:

    • GHSA-6mj3-qw4j-hgrw, GHSA-g53g-w8rj-fmg7, GHSA-w2rr-34g9-rvrj, GHSA-4w3w-2rp5-g8jm, GHSA-c7q8-3ch8-vqpv, GHSA-27p8-2357-5qqv, GHSA-3px3-54cx-rmw9, GHSA-vr34-hp96-76pp, GHSA-8344-3jmq-59r6, GHSA-965w-775f-mr7g, GHSA-93r5-fhx6-vmg9, GHSA-6gmq-8vp8-gcm6, GHSA-6h8r-xr42-gp59: @xmldom/xmldom to 0.9.12
    • GHSA-c83g-rgw3-j3cx, GHSA-73wf-gq98-2v4g: browserslist to 4.28.7
    • GHSA-2883-xcg3-v3hh: js-yaml to 4.3.2
    • GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp: fast-uri to 3.1.6
    • GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g: qs to 6.16.0
    • GHSA-rgj7-g3m4-5g8c: sharp to 0.35.4

โœจ New Featuresโ€‹

  • โœจ All new encryption performed on the app will now use the Excalibur Encryption Format (ExEF) version 4
    • Read about the performance improvements below
  • ๐Ÿ”ง Added new "file read chunk size" setting to configure file reading operations

๐Ÿ”„ Changesโ€‹

  • ๐Ÿ’ฌ The displayed value of the file size will now include the ExEF overhead (previously it would have been the raw plaintext size)

โšก๏ธ Performance Improvementsโ€‹

  • โšก๏ธ Use @noble/ciphers's webcrypto.js implementation for ExEF v4 instead of the aes.js implementation

    • Benchmarking shows that webcrypto.js encryption/decryption is ~35x faster than aes.js

      =================================== 64 KiB ====================================
      aes.js โ•ขโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘ 40.7 ms
      webcrypto.js โ•ขโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ 0.7 ms
      โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
      0 45

      =================================== 256 KiB ===================================
      aes.js โ•ขโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–“โ–‘โ–‘ 52.5 ms
      webcrypto.js โ•ขโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ 1 ms
      โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
      0 55

      ==================================== 1 MiB ====================================
      aes.js โ•ขโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘ 182.4 ms
      webcrypto.js โ•ขโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ 9.4 ms
      โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
      0 200

      ==================================== 4 MiB ====================================
      aes.js โ•ขโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ 732.9 ms
      webcrypto.js โ•ขโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ 30.7 ms
      โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
      0 750

      =================================== 16 MiB ====================================
      aes.js โ•ขโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 2888.9 ms
      webcrypto.js โ•ขโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ 85.7 ms
      โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
      0 3000

      =================================== 64 MiB ====================================
      aes.js โ•ขโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 11506 ms
      webcrypto.js โ•ขโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ 439.9 ms
      โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
      0 12000
    • This performance improvement only applies to ExEF files and streams. ExEF v3 files do not enjoy this performance improvement (as they still rely on a single-chunk encryption/decryption process)

  • โšก๏ธ Slightly improved performance of encryption/decryption operations by removing stream chunking.

    • We no longer pre-chunk streams before passing them to the encryption/decryption functions as ExEF v4 handles chunking internally.

โฌ†๏ธ Dependenciesโ€‹

  • โฌ†๏ธ Updated Android dependencies:

    • androidxAppCompatVersion from 1.7.1 to 1.8.0
  • โฌ†๏ธ Updated Capacitor dependencies (#151):

    • @capacitor/android from 8.4.0 to 8.5.0
    • @capacitor/core from 8.4.0 to 8.5.0
  • โฌ†๏ธ Updated React dependencies (#149):

    • react from 19.2.7 to 19.2.8
    • react-dom from 19.2.7 to 19.2.8
    • @types/react development dependency from 19.2.7 to 19.2.8
  • โฌ†๏ธ Updated @capacitor/filesystem from 8.1.2 to 8.1.3 (#169)

  • โฌ†๏ธ Updated @noble/ciphers from 2.2.0 to 2.4.0 (#148, #177)

  • โฌ†๏ธ Updated @noble/hashes from 2.2.0 to 2.3.0 (#147)

  • โฌ†๏ธ Updated immer from 11.1.15 to 11.1.18 (#171)

  • โฌ†๏ธ Updated ionicons from 8.0.13 to 8.1.0 (#152)

  • โฌ†๏ธ Updated baseline-browser-mapping development dependency from 2.10.44 to 2.11.19 (#167)

  • โฌ†๏ธ Updated cypress development dependency from 15.20.0 to 15.21.0 (#150, #162)

  • โฌ†๏ธ Updated eslint-plugin-react-refresh development dependency from 0.5.3 to 0.5.4 (#154)

  • โฌ†๏ธ Updated start-server-and-test development dependency from 3.0.11 to 3.0.12 (#156)

  • โฌ†๏ธ Updated typescript-eslint development dependency from 8.66.0 to 8.69.0 (#172, #175)

  • โฌ†๏ธ Updated vitest development dependency from 4.1.10 to 4.1.11 (#176)

Serverโ€‹

๐Ÿ’ฅ Breaking Changesโ€‹

  • ๐Ÿ’ฅ All encryption performed on the server will now use the Excalibur Encryption Format (ExEF) version 4

    • ExEF v3 is no longer supported
    • This affects all routes that require encryption, including file uploads and downloads

    Please read the documentation for the ExEF v4 specification to learn how to handle ExEF v4 data.

  • ๐Ÿ’ฅ Changed how authentication works for WebSocket endpoints

    • Please see the updated documentation for "authenticating subsequent requests"
  • ๐Ÿ’ฅ Removed include_exef_size query parameter from the following endpoints:

    • /api/files/search
    • /api/files/list/{path}

    The behaviour now is to always include the ExEF additional size (i.e., header and, possibly, footer) in file sizes.

  • ๐Ÿ—‘๏ธ Removed the /api/well-known/info endpoint

    • The maximum upload size and times required to compute the time offset will be sent along with login responses
    • To get the version, use the /api/well-known/version endpoint instead
  • ๐Ÿ’ฅ We will now use uv's 0.12.x series to build and install the server package, updating the minimum version from 0.11.26 in pyproject.toml and GitHub actions to 0.12.13

๐Ÿ—‘๏ธ Deprecationsโ€‹

  • โšฐ๏ธ Removed ExEF v3 code
  • ๐Ÿ—‘๏ธ Removed the excalibur user add command
    • User creation must now be done through the API

โฌ†๏ธ Dependenciesโ€‹

  • โฌ†๏ธ Updated alembic from 1.18.5 to 1.19.1 (#146)
  • โฌ†๏ธ Updated gitpython from 3.1.58 to 3.1.59 (#145)
  • โฌ†๏ธ Updated packaging from 26.2 to 26.3 (#160)
  • โฌ†๏ธ Updated pydantic-settings from 2.14.2 to 2.15.0 (#143)
  • โฌ†๏ธ Updated uvicorn from 0.52.0 to 0.52.4 (#158)
  • โฌ†๏ธ Updated ipython development dependency from 9.15.0 to 9.16.1 (#144)
  • โฌ†๏ธ Updated ruff development dependency from 0.16.1 to 0.16.3 (#161)
  • โฌ†๏ธ Updated httpx2 test dependency from 2.9.1 to 2.12.0 (#142, #159)