Skip to content

5.3.0

Choose a tag to compare

@dereuromark dereuromark released this 25 May 23:23
· 6 commits to master since this release
3311863

Fixes

  • Apply the configured cachePrefix to the ACL/Allow cache keys — two TinyAuth installs sharing a CakePHP cache pool previously collided on the bare acl / allow keys, so multi-tenant or test setups could read another install's permission data. Keys are now namespaced (tiny_auth_acl / tiny_auth_allow by default); existing bare-key caches go cold once and repopulate (#169)
  • Fix route-slot matching swallowing falsy plugin/prefix values — _isPublic / _getAllowRule mixed isset() with !empty(), comparing falsy slots like '0' or an empty string inconsistently between request and rule. Matching now treats null and empty string as the "no plugin / no prefix" sentinel and requires an exact match otherwise (#169)

Improvements

  • Allow cakephp/authentication v4 — the plugin now supports authentication v3 and v4 (#171)

Full Changelog: 5.2.0...5.3.0