5.3.0
Fixes
- Apply the configured
cachePrefixto the ACL/Allow cache keys — two TinyAuth installs sharing a CakePHP cache pool previously collided on the bareacl/allowkeys, so multi-tenant or test setups could read another install's permission data. Keys are now namespaced (tiny_auth_acl/tiny_auth_allowby default); existing bare-key caches go cold once and repopulate (#169) - Fix route-slot matching swallowing falsy plugin/prefix values —
_isPublic/_getAllowRulemixedisset()with!empty(), comparing falsy slots like'0'or an empty string inconsistently between request and rule. Matching now treats null and empty string as the "no plugin / no prefix" sentinel and requires an exact match otherwise (#169)
Improvements
- Allow cakephp/authentication v4 — the plugin now supports authentication v3 and v4 (#171)
Full Changelog: 5.2.0...5.3.0