Repository navigation
v0.8.0 — Security and Upload Reliability
This release strengthens deferred attachment security and fixes media replacement, ownership checks, queue ordering, and uploaded display names.
Security
- Deferred uploads now require a configured
authorizeAbilityand a successful Gate/Policy check against the saved target. - Attach events cannot switch an already-bound uploader to another record or change its expected model class.
- Attachment arguments cannot override the uploader’s configured collection or disk.
Fixes
- Preserve existing media until replacement storage succeeds, including single-file collections and failed destination writes.
- Store metadata with the replacement before removing the original.
- Support morph aliases and custom media models when editing, deleting, and reordering media.
- Place reordered queued uploads after existing media in the active collection.
- Preserve the original Media Library display name when staging uploads.
Upgrading from v0.7.x
Deferred uploaders must now set authorizeAbility and provide a matching Gate/Policy:
<livewire:media-uploader
model="post"
collection="images"
authorizeAbility="update"
channel="post-images"
/>Configure collection and disk on the uploader rather than overriding them through attach events. A mismatched collection is ignored; a mismatched disk or an attempt to switch the bound target returns 403.
Uploaders already bound to a saved record may continue relying on application authorization of that fixed target.
Dependency requirements are unchanged. No package database migration or new configuration key is required.
See the [upgrade guide](https://github.com/codebyray/livewire-media-uploader/blob/v0.8.0/README.md#upgrading-to-v080) for a policy example and matching attach event.
Testing
Expanded regression coverage to 51 passing tests with 151 assertions, verified on Laravel 12/Livewire 3 and Laravel 13/Livewire 4, including rendering checks for both supplied themes.