Added
spiffeid.MatchIDPrefixmatcher andtlsconfig.AuthorizeIDPrefixauthorizer, which accept any SPIFFE ID in the same trust domain whose path matches the given prefix's path or extends it on a segment boundary. The prefix must have a nonempty path, otherwise no ID matches (#406)
Changed
PeerIDon connections returned byspiffetls, andspiffetls.PeerIDFromConn, now complete the TLS handshake if needed, so the peer ID can be retrieved before the first read. When the handshake is still pending, the call performs I/O like aReadwould and honors the connection deadlines (#422)