Repository navigation
Releases: codebyray/livewire-media-uploader
Release list
v0.8.0
v0.8.0 — Security and Upload Reliability
This release strengthens deferred attachment security and fixes media replacement, ownership checks, queue ordering, and uploaded display names.
Security
- Deferred uploads now require a configured
authorizeAbilityand a successful Gate/Policy check against the saved target. - Attach events cannot switch an already-bound uploader to another record or change its expected model class.
- Attachment arguments cannot override the uploader’s configured collection or disk.
Fixes
- Preserve existing media until replacement storage succeeds, including single-file collections and failed destination writes.
- Store metadata with the replacement before removing the original.
- Support morph aliases and custom media models when editing, deleting, and reordering media.
- Place reordered queued uploads after existing media in the active collection.
- Preserve the original Media Library display name when staging uploads.
Upgrading from v0.7.x
Deferred uploaders must now set authorizeAbility and provide a matching Gate/Policy:
<livewire:media-uploader
model="post"
collection="images"
authorizeAbility="update"
channel="post-images"
/>Configure collection and disk on the uploader rather than overriding them through attach events. A mismatched collection is ignored; a mismatched disk or an attempt to switch the bound target returns 403.
Uploaders already bound to a saved record may continue relying on application authorization of that fixed target.
Dependency requirements are unchanged. No package database migration or new configuration key is required.
See the [upgrade guide](https://github.com/codebyray/livewire-media-uploader/blob/v0.8.0/README.md#upgrading-to-v080) for a policy example and matching attach event.
Testing
Expanded regression coverage to 51 passing tests with 151 assertions, verified on Laravel 12/Livewire 3 and Laravel 13/Livewire 4, including rendering checks for both supplied themes.
v0.7.0
v0.7.0 — Image Watermarking
This release adds optional server-side watermarking for uploaded images, expands package configuration documentation, and strengthens upload security and compatibility.
Watermarking is disabled by default, so existing uploaders will continue to behave as before.
Highlights
- Apply a configurable watermark before an image is stored.
- Enable watermarking globally or for individual uploader components.
- Configure position, size, padding, fit, and opacity.
- Use percentage-based sizing for consistent results across different image dimensions.
- Watermark the stored original and all Media Library conversions generated from it.
- Leave documents, videos, and other non-image uploads unchanged.
Enable watermarking globally:
MEDIA_UPLOADER_WATERMARK_ENABLED=true
MEDIA_UPLOADER_WATERMARK_PATH=/absolute/path/to/watermark.pngOr enable it for a specific uploader:
<livewire:media-uploader
:for="$post"
collection="images"
preset="images"
:watermark="true"
/>Improvements
- Uploads are staged locally before processing, allowing watermarking to work with remote Livewire temporary-upload storage.
- Preset file sizes, extensions, and MIME types can be overridden per uploader while still supplying sensible defaults.
- The README now documents the complete configuration file and watermarking options.
- CI coverage now includes PHP 8.5 and dependency security auditing.
Security and reliability
- Server-controlled authorization and upload-policy properties are protected from client-side Livewire mutation.
- Watermark processing completes before replacement conflict handling, preserving existing media if processing fails.
- Deferred uploaders with a configured channel now reject attachment events that omit or mismatch that channel.
- Supported Livewire minimums have been raised to patched releases.
Upgrade requirements
This release requires:
- PHP 8.2 or newer
- Laravel 12 or 13
- Livewire
^3.8.3or^4.3.4 - Spatie Media Library
^11.0
Spatie Image ^3.3.2 is now installed as an explicit package dependency.
After upgrading, republish or compare your config/media-uploader.php file if you want to configure watermarking.
Full changelog
Full comparison: v0.6.0...v0.7.0
v0.6.0
v0.6.0 — Drag-and-Drop Media Ordering
This release adds drag-and-drop media ordering to Livewire Media Uploader, along with improved image preview interactions and updated documentation for current Spatie Media Library usage.
What's New
Drag-and-Drop Ordering
Media can now be reordered directly from the uploader using native drag-and-drop.
- Reorder existing attached media.
- Reorder files in the pending upload queue before uploading.
- Drop items before or after another item, including at the end of the list.
- Visual drop indicators show exactly where the dragged item will be placed.
- Attached media ordering is persisted using Spatie Media Library's
order_column. list-allmode keeps ordering scoped to each individual media collection.- Available in both Tailwind CSS and Bootstrap themes.
- No additional JavaScript dependency is required beyond Alpine.js.
A new media-reordered event is dispatched after persisted media has been reordered.
Clickable Image Thumbnails
Image thumbnails can now be clicked to open the existing image preview overlay.
This works for both:
- Pending image uploads.
- Existing attached images.
The filename and thumbnail now provide the same convenient preview behavior.
Documentation Improvements
- Clarified the interaction between multiple uploads and Spatie Media Library's
singleFile()collection configuration. - Updated image conversion examples to use
Spatie\Image\Enums\Fitfor compatibility with current Spatie Image releases. - Updated examples and documentation for the new media ordering functionality.
Upgrade
No breaking changes are expected when upgrading from v0.5.x.
composer require codebyray/livewire-media-uploader:^0.6Existing uploader implementations should continue to work without modification. Drag-and-drop ordering and the improved preview interactions are available automatically when using the updated package views.
v0.5.0
v0.5.0
⚠️ Breaking: narrower Laravel/PHP support
This release intentionally drops Laravel 10 and 11 support and raises the PHP floor to 8.2.
Both Laravel majors are past their security-support window (Laravel 10 is fully EOL; Laravel 11's security support ended March 2026), and current releases in both lines carry unpatched CVEs — meaning a fresh composer install against either is now blocked outright by Composer's own security-advisory audit for most consumers. This isn't a preference change; it's the ecosystem itself telling us those versions shouldn't be recommended for new installs anymore.
If you're on Laravel 10/11: stay on v0.4.x and prioritize upgrading Laravel — that's the more urgent fix regardless of this package.
Now supported: Laravel ^12.0 | ^13.0, PHP ^8.2, Livewire ^3.0 | ^4.0 — every combination verified via CI on every push.
✨ Added
- Optional
authorizeAbilityprop. Set it to a Gate/Policy ability name and the component will callGate::authorize()against the target model before any mutating action (uploadFiles,remove,saveEdit, and themedia:attachhandler). Left unset, behavior is unchanged from prior versions — this is opt-in and fully backward-compatible. See the Authorization section in the README. - CI. GitHub Actions now runs the full PHP × Laravel × Livewire test matrix on every push and PR.
🐛 Fixed
- README/
composer.jsonsaid "Livewire v3" despite^3.0 || ^4.0already being supported.
Upgrading
No code changes required if you're already on Laravel 12/13 + PHP 8.2+. If you're on Laravel 10/11 or PHP 8.1, hold on v0.4.x until you've upgraded your app.
Full Changelog: v0.4.0...v0.5.0
v0.4.0
v0.4.0: Architectural Refactor & Enhanced Resolution
This release focuses on architectural stability, introducing strict typing for name conflicts, better error handling, and more flexible model resolution.
Highlights
- Strongly Typed Name Conflicts: Replaced string-based checks with the NameConflictStrategy Enum.
- Dedicated Exception Handling: Replaced generic abort() calls with a new ModelResolutionException, making debugging easier when model binding fails.
- Modular Model Resolution: Added support for model_namespaces in the config, making it easier to use the package in Domain-Driven Design (DDD) or modular architectures.
- Testing Improvements: Refined the test suite to correctly catch and assert internal package exceptions.
What's Changed
- refactor(release): prepare v0.4.0 and refactor core architecture by @codebyray in #5
Full Changelog: v0.3.2...v0.4.0
v0.3.2
v0.3.1
Added
- Compatibility with spatie/laravel-medialibrary ^11 (works on Laravel 12).
Changed
- Relaxed dependency:
spatie/laravel-medialibrary→^10.12 || ^11.0.
Impact/Migration
- No breaking changes. Existing users on v10 remain supported.
- On Laravel 12, update with:
composer require codebyray/livewire-media-uploader:^0.3 -W
Thanks
- Community feedback on Laravel 12 support 🙌
v0.3.0
What's Changed
- feat(uploader): deferred uploads on create + grouped
listAllview by @codebyray in #3
Full Changelog: v0.2.0...v0.3.0
v0.2.0
What's Changed
- Add bootstrap version by @codebyray in #2
New Contributors
- @codebyray made their first contribution in #2
Full Changelog: v0.1.0...v0.2.0
v0.1.0
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog,
and this project adheres to Semantic Versioning.
Versioning policy: Until
1.0.0, minor bumps (e.g.,0.1 → 0.2) may include breaking changes. Patch releases in the same minor (e.g.,0.1.x) are bug fixes only.
Unreleased
Added
- Docs: environment variable examples for presets (
MEDIA_TYPES_*,MEDIA_MIMES_*,MEDIA_MAXKB_*). - Tests: deterministic duplicate-detection test helper (
TestableMediaUploader) and event-based assertions. - Troubleshooting guidance for Testbench/SQLite and Livewire temp upload disk.
Changed
- Test suite favors Pest; PHPUnit example retained only if desired by consumers.
- Assertions updated to reflect Spatie filename sanitization (spaces → dashes on rename).
Fixed
- Intermittent test failures: ensured
mediatable migration loads under Testbench and configured fake disks (public,local,tmp-for-tests).
v0.1.0 — 2025-08-30
Added
- Livewire v3 media uploader component.
- Tailwind-only publishable Blade view with Alpine-powered image preview overlay and delete confirmation modal.
- Spatie Laravel Media Library integration:
- Attach/list/delete media within a configurable collection (e.g.,
images,avatars,photos). - Per-file metadata (caption, description, order).
- Optional thumbnail usage (
getUrl('thumb')) with graceful fallback.
- Attach/list/delete media within a configurable collection (e.g.,
- Drag & drop uploads with progress indicator.
- Validation presets via config (types, mimes, max size) with collection→preset mapping and optional auto-
acceptattribute. - Name-conflict strategies:
rename,replace,skip,allow. - Exact duplicate detection (SHA-256) with
skipExactDuplicates. - Flexible model resolution:
:for="$model"(saved instance),model="user" :id="1"(short name + id),- FQCN, morph map alias, or dotted paths with custom namespaces and local aliases.
- Events for UX integrations:
media-uploaded,media-deleted(withid),media-meta-updated.
- Publishable config (
media-uploader.php) and view (livewire/media-uploader.blade.php). - Test suite (Pest + Testbench) with in-memory SQLite and fake disks.
Deprecations Policy
- Any deprecations will be noted here and kept for at least one subsequent minor (e.g., deprecate in
0.3.x, remove in0.4.0). After1.0.0, deprecations will be removed in the next major release.
Upgrade Notes
- To get thumbnail previews, add a
thumbconversion on your model or adjust the view to your conversion names. - For single-file collections (e.g.,
avatars), declare the collection in your model and call->singleFile(); the component’smultiple=falseonly affects the input, not backend replacement.