Skip to content

v26.09.3 — Spring Security parity, two OAuth2 packages, Spring Data, tracing, and documentation held to the code

Choose a tag to compare

@ancongui ancongui released this 23 Sep 14:32
· 172 commits to main since this release

Seven waves of framework work and the documentation set that describes them truthfully.

Spring-Security-grade authentication and authorization: session-persisted context, form login
with the framework's own page, HTTP Basic, logout, remember-me, an entry point that negotiates
a login redirect against a 401 problem document, method security on any stereotyped bean through
one compiled proxy chain that runs security before transaction, principal injection, an Eloquent
user store, the authentication event family, and test support.

Two new packages: firefly/security-oauth2-client (OpenID Connect login with provider presets and
discovery, PKCE, id-token validation, RP-initiated logout, client credentials, Http::oauth2Client())
and firefly/security-oauth2-server (a Spring-Authorization-Server-shaped OAuth 2.1 / OIDC provider:
registered clients, /oauth2/authorize with a consent page, three grants, introspection, revocation,
userinfo, JWKS, both .well-known documents, RS256/ES256 keys with rotation).

Spring-Data-grade data: a translated DataAccessException family, query by example, #[Modifying],

OpenTelemetry-shaped tracing with W3C propagation across the web filter, the Http client, both CQRS
buses and EDA envelopes; structured logging (json, ECS, logstash); histogram buckets on timers.

Spring-shaped validation messages and #[Valid] cascading into list elements.

A browser end-to-end suite: Pest 4 and Playwright driving real Chromium over the shipped skeleton,
with its own CI job.

And the documentation held to the code: every fenced listing in the README, the guides and both
book editions is now proved against the file it came from, or marked as the reader's own code.
Nine diagrams, a redesigned site, and a bilingual book caught up with all of it.


Gate: 3,340 tests · PHPStan level max · Pint · Deptrac 0 violations · 68 browser scenarios in real Chromium · 14 book tests · 294 verified code listings per manuscript · mkdocs build --strict. CI green on PHP 8.3, 8.4 and 8.5.

Documentation: https://fireflyframework.github.io/fireflyframework-php/

Note on installation: the per-package mirrors are not published for this tag — the release workflow's credential preflight refused, by design, because the org token is not configured. Install from this monorepo until the mirrors are set up; see docs/publishing.md.