Skip to content

Support PHP 8.3–8.5: typed API, PdoStorage rework, JS catcher, relicense GPLv3

Latest

Choose a tag to compare

@Xakki Xakki released this 12 Jun 22:48
· 1 commit to master since this release

Overview

Branch chore/php-8.3-8.5-support (squashed): PHP 8.3–8.5 support, a storage/JS-catcher rework, a typed public API, a finished PDO backend, a relicense to GPL-3.0-or-later, and a GitHub Pages landing. Version → 0.8.4. Backward compatible.

PHP 8.3–8.5 support

  • Update deps; unify storage record format (Monolog-style buildRecord()) across backends.
  • Fix file-storage date handling and level mapping; add storage/tools tests.
  • declare(strict_types=1) across src/, tests/, example/; type previously-untyped props/returns.
  • CI PHPUnit matrix on 8.3 / 8.4 / 8.5; phpcs + PHPStan (level 8) on 8.3.

Public API — typed constructor (0.8.3)

  • __construct is now public with named typed arguments (one per config key); it registers the singleton itself, only after successful construction.
  • init(array $config) kept and @deprecated: maps only known keys (unknown ignored), idempotent — old init([...]) calls keep working.

PDO storage rework (0.8.4)

  • Real write() using the canonical record schema + prepared statements; portable, auto-created table for mysql/mariadb, postgresql, sqlite.
  • getPdo() accepts a ready PDO, a params array, or a callable factory.
  • No longer excluded from PHPStan (level-8 clean). Env-DSN tests: sqlite always; mariadb/postgres via make test-db + a CI db-tests job on mariadb:12 + postgres:17.

JS error-catcher rework (src/catcher.js + JsLogPlugin)

  • Catch unhandledrejection and failed resource loads, plus window.onerror / console.error.
  • Skip bots (navigator.webdriver + UA regex) and noise (cross-origin "Script error." without a stack, browser-extension origins); de-dup in a 5 s window with a per-session send cap.
  • Richer ctx (viewport, build version, session-id, anonymized breadcrumbs — no input values / element text).
  • Fixes: console.error override always calls the original; dropped arguments.callee; typeof-guarded app; exposes window.errorCatcher.
  • Optional dynamic delivery: JsLogPlugin can serve /catcher.js (GET) with a stateless HMAC token; empty secret keeps initGetKey-only gating (default). Old m/v/r/u/ua/l/s field format still accepted.

Hardening & cleanup

  • FileViewer: path-traversal sanitisation at the source (Tools::sanitizeRelativePath).
  • JsLogPlugin: input hardening (POST-only, json-array guard, length caps); typed constants.
  • applyConfig: drop reflection — config writes static props only.
  • PhpErrorCatcher::$traceShowArgs now defaults to false.

License & docs

  • Relicensed LGPL-2.1 → GPL-3.0-or-later (GPLv3 LICENSE; composer.json / package.json / docs updated); in-code comments translated to English.
  • GitHub Pages landing (root _config.yml, README as the home page); composer.json homepage set. ⚠️ Pages must be enabled in repo Settings → Pages.

Verification

make check green; make test-php-all green on 8.3 / 8.4 / 8.5 (79 tests, 4 sqlite-skipped without live DBs); make test-db green against real mariadb:12 + postgres:17.