Skip to content

v5.4.0

Choose a tag to compare

@CarlosGude CarlosGude released this 19 Sep 09:46
· 99 commits to main since this release

Fixed

  • Lifecycle events now reach Symfony listeners. SymfonyEventDispatcherAdapter couldn't be instantiated (Cannot call constructor: it called a parent constructor that doesn't exist), and the bundle never passed a LifecycleEventDispatcher to the integrations. The bundle now injects the IntegrationEngine\Core\Lifecycle\LifecycleEventDispatcher service into every integration; point that service at SymfonyEventDispatcherAdapter (as LIFECYCLE.md and the Flex recipe do) and #[AsEventListener] listeners receive ActionStarted, ActionCompleted, etc.
  • HttpResponseReceived::statusCode() reports the real HTTP status for the built-in REST and GraphQL clients; it was always 0. The client response shape gains an optional statusCode key; a custom client that doesn't set it keeps reporting 0.
  • Flex recipe: drops the unused INTEGRATION_ENGINE_CACHE env var, and shows the per-integration options inside an example integration instead of at the root, where they're invalid.

Changed

  • Cache keys for dynamic-auth tokens and cached responses are hashed with xxh128 instead of sha1 (non-cryptographic use). After upgrading, tokens and responses cached under the old keys aren't found and are fetched once again.
  • MultiPlatformWebhookController::ingest() no longer declares the unused $platform argument. Callers passing it keep working: PHP accepts extra arguments, and Symfony resolves controller arguments by name.

Security

  • IntegrationWebhookRequestParser verified signatures with an empty key when framework.webhook.routing.<type>.secret was empty. It now falls back to getSignatureSecret(), and rejects the request (406) when both are empty.
  • MultiPlatformWebhookController always verified signatures with an empty key, so it accepted HMACs anyone can compute. It now verifies with WebhookPlatformConfig::$secret and answers 500 while none is configured.
  • Dead-letter queue failure ids are generated from random_bytes() instead of mt_rand().

Added

  • WebhookPlatformConfig optional secret argument (last position, default '').

Deprecated

  • MultiPlatformWebhookController: it verifies and acknowledges webhooks but never dispatches them. Use IntegrationWebhookRequestParser with Symfony's Webhook component instead (see WEBHOOK.md).

Internal

  • PHPStan level max passes (it reported 59 errors) and php-cs-fixer is clean.
  • Contract test workflow: fixed the YAML syntax error that made every run fail instantly, and pointed it at the public demo app (integrationEngine-demo, PHP 8.4); the previous target was a private repository the workflow couldn't check out.
  • Broken documentation links and stale namespaces fixed; the documentation tests pass again.
  • README's webhook feature list now matches what ships: the DLQ, audit trail and idempotency pieces are contracts you provide storage for, and multi-platform routing is deprecated.
  • Landing page: code snippets showed PHP namespaces without their backslashes, and 14 snippets never rendered (a span missing its >).
  • SonarCloud: the analysis config moves to .sonarcloud.properties, the only file automatic analysis reads (its exclusions were being ignored, so tests and the landing's i18n counted as duplication). Intentional composer update steps and a false positive are annotated, and the remaining issues are fixed.

Respecto a la sección del CHANGELOG que había, he añadido dos líneas: el cambio de firma de ingest() y el arreglo del landing.

¿Commiteo y subo el CHANGELOG? Si quieres, después creo yo el tag y la release sobre ese commit con estas notas, o lo haces tú.