v5.4.0
Fixed
- Lifecycle events now reach Symfony listeners.
SymfonyEventDispatcherAdaptercouldn't be instantiated (Cannot call constructor: it called a parent constructor that doesn't exist), and the bundle never passed aLifecycleEventDispatcherto the integrations. The bundle now injects theIntegrationEngine\Core\Lifecycle\LifecycleEventDispatcherservice into every integration; point that service atSymfonyEventDispatcherAdapter(as LIFECYCLE.md and the Flex recipe do) and#[AsEventListener]listeners receiveActionStarted,ActionCompleted, etc. HttpResponseReceived::statusCode()reports the real HTTP status for the built-in REST and GraphQL clients; it was always0. The client response shape gains an optionalstatusCodekey; a custom client that doesn't set it keeps reporting0.- Flex recipe: drops the unused
INTEGRATION_ENGINE_CACHEenv var, and shows the per-integration options inside an example integration instead of at the root, where they're invalid.
Changed
- Cache keys for dynamic-auth tokens and cached responses are hashed with
xxh128instead ofsha1(non-cryptographic use). After upgrading, tokens and responses cached under the old keys aren't found and are fetched once again. MultiPlatformWebhookController::ingest()no longer declares the unused$platformargument. Callers passing it keep working: PHP accepts extra arguments, and Symfony resolves controller arguments by name.
Security
IntegrationWebhookRequestParserverified signatures with an empty key whenframework.webhook.routing.<type>.secretwas empty. It now falls back togetSignatureSecret(), and rejects the request (406) when both are empty.MultiPlatformWebhookControlleralways verified signatures with an empty key, so it accepted HMACs anyone can compute. It now verifies withWebhookPlatformConfig::$secretand answers500while none is configured.- Dead-letter queue failure ids are generated from
random_bytes()instead ofmt_rand().
Added
WebhookPlatformConfigoptionalsecretargument (last position, default'').
Deprecated
MultiPlatformWebhookController: it verifies and acknowledges webhooks but never dispatches them. UseIntegrationWebhookRequestParserwith Symfony's Webhook component instead (see WEBHOOK.md).
Internal
- PHPStan level max passes (it reported 59 errors) and php-cs-fixer is clean.
- Contract test workflow: fixed the YAML syntax error that made every run fail instantly, and pointed it at the public demo app (
integrationEngine-demo, PHP 8.4); the previous target was a private repository the workflow couldn't check out. - Broken documentation links and stale namespaces fixed; the documentation tests pass again.
- README's webhook feature list now matches what ships: the DLQ, audit trail and idempotency pieces are contracts you provide storage for, and multi-platform routing is deprecated.
- Landing page: code snippets showed PHP namespaces without their backslashes, and 14 snippets never rendered (a span missing its
>). - SonarCloud: the analysis config moves to
.sonarcloud.properties, the only file automatic analysis reads (its exclusions were being ignored, so tests and the landing's i18n counted as duplication). Intentionalcomposer updatesteps and a false positive are annotated, and the remaining issues are fixed.
Respecto a la sección del CHANGELOG que había, he añadido dos líneas: el cambio de firma de ingest() y el arreglo del landing.
¿Commiteo y subo el CHANGELOG? Si quieres, después creo yo el tag y la release sobre ese commit con estas notas, o lo haces tú.