Repository navigation
Releases: iamceeso/saasphp
Release list
v1.1.1
Dependency & Maintenance Update
This release focuses on dependency maintenance, security, and keeping the application stack up to date.
What's Changed
Composer Dependencies
- Updated Laravel from
v13.21.1tov13.30.1. - Updated Filament packages from
v5.7.3tov5.7.8. - Updated Livewire from
v4.3.3tov4.4.3. - Updated Laravel Cashier, Fortify, Socialite, Sail, Pint, and supporting Laravel packages.
- Updated Symfony components and supporting PHP libraries.
- Updated Stripe PHP SDK from
v17.6.0tov21.3.1. - Updated authentication, WebAuthn, database, testing, and development dependencies.
- Refreshed Filament frontend assets and bundled fonts following the framework update.
- Removed the obsolete
paragonie/random_compatdependency.
NPM Dependencies
- Updated frontend npm dependencies to their latest compatible versions.
- Refreshed the frontend dependency lockfile.
Security
- Composer security audit reports no known security vulnerability advisories.
Maintenance
- Regenerated application assets following dependency upgrades.
- Refreshed dependency lockfiles to ensure reproducible installations.
- General dependency and framework maintenance.
Commits
a1d94df— chore(deps): update Composer dependenciesc5635cc— chore(deps): update npm dependencies
Full Changelog: v1.1.0...v1.1.1
v1.1.0
This release focuses on security, reliability, maintainability, and documentation. It significantly hardens the authentication and billing systems, expands automated test coverage, streamlines internal architecture, and introduces a new API documentation site powered by Doctum.
Highlights
Security
- Hardened authentication, authorization, billing, and webhook security.
- Strengthened OAuth verification and account linking.
- Improved magic link authentication flow and user assignment safeguards.
- Enforced password reset token expiration.
- Deferred email and phone verification until password reset succeeds.
- Prevented two-factor authentication secrets from being serialized.
- Strengthened settings verification and two-factor authentication.
- Unified impersonation session detection across middleware and the user interface.
- Prevented blank password updates, enforced maintenance bypass checks, and invalidated other sessions after password changes.
- Restored registration settings enforcement and social login authorization.
Billing
- Centralized current subscription status handling.
- Fixed Stripe customer persistence to prevent duplicate customer creation.
- Expanded Stripe-backed subscription testing.
- Improved internal billing architecture and removed duplicated logic.
Testing
- Added comprehensive regression coverage across the billing system.
- Added authorization tests for Filament resources.
- Added subscription ownership (IDOR) regression tests.
- Added webhook processing and subscription lifecycle tests.
- Expanded policy coverage.
- Increased automated test coverage while resolving previously undiscovered production issues.
Refactoring
- Consolidated billing services and removed unused code.
- Simplified authentication, billing, and configuration internals.
- Centralized billing, settings, impersonation, and security configuration.
- Removed obsolete code and improved maintainability throughout the framework.
Documentation
- Added Doctum-powered API documentation.
- Published API documentation through GitHub Pages.
- Added Doctum-compatible documentation headers across controllers, models, middleware, actions, and services.
- Added navigation from the API documentation back to the main documentation site.
- Improved project documentation and updated the README.
Continuous Integration
- Added automated API documentation generation and deployment.
- Improved GitHub Actions workflow for documentation builds.
- Updated CI to use the correct Doctum binary.
- Optimized documentation builds by skipping unnecessary Laravel Composer scripts.
Fixes
- Fixed OAuth login authorization regressions.
- Removed duplicate profile image handling.
- Fixed invalid translation helper usage.
- Improved password management and session handling.
- Applied numerous reliability and stability improvements across the framework.
Upgrade Notes
- API documentation is now generated automatically using Doctum and published via GitHub Pages.
- The billing layer has been refactored internally, but remains backward compatible for existing integrations.
- Developers should review the updated API documentation and security improvements before extending authentication or billing functionality.
Full Changelog: v1.0.2...v1.1.0
v1.0.3
Security Patch
This release addresses known vulnerabilities in project dependencies.
What's changed
- Patched npm dependency vulnerabilities (critical, high, moderate, and low severity)
Notes
- No breaking changes
- Recommended update for all users
v1.0.2
This release improves the installation experience and reduces setup friction for new users.
Improvements
- Added a standard (non-Docker) installation path alongside Laravel Sail
- Clarified frontend build steps (Vite) during setup
- Simplified and streamlined README for faster onboarding
- Repositioned Sail as optional instead of required
Notes
- No functional or breaking changes
- Existing projects are not affected
Full Changelog: v1.0.1...v1.0.2
v1.0.1
This release upgrades the application to Laravel 13 and updates the surrounding stack for full compatibility.
Key Changes
- Upgraded to Laravel 13
- Updated core dependencies including Filament, Cashier, Fortify, Socialite, Pest, and PHPUnit
- Replaced deprecated Blade icon packages with Heroicons
- Republished Filament assets for the new version
Improvements
- Improved boot-time stability by preventing crashes when the database connection is unavailable in CLI contexts
- Updated authentication tests to match new framework behavior
- Reduced IDE false positives in key resources
Verification
- Laravel Framework 13.7.0
- Filament upgrade completed successfully
- Test suite: 116 passed
Full Changelog: v1.0.0...v1.0.1
v1.0.0
SaaS PHP v1.0.0 establishes a production-ready foundation for building Laravel-based SaaS applications.
It brings together authentication, Stripe billing, a Filament-powered admin panel, and a database-driven settings system into a cohesive baseline you can build on immediately.
What you get
-
Authentication
- Email / phone login
- Magic links
- Social OAuth (Google, GitHub, Microsoft, Twitter, Yahoo)
- Optional 2FA
-
Stripe Billing
- Free & paid plans
- Monthly / annual pricing
- Plan swaps, pause, cancel, resume
- Webhook handling
-
Filament Admin Panel (v5)
- User management
- Roles & permissions (Spatie + Shield)
- User impersonation
- Subscription oversight
-
Database-backed Settings
- Runtime configuration (no redeploys)
- Branding, auth toggles, integrations, payments
-
React + Inertia Frontend
- React 19 + TypeScript
- SPA experience with server-driven routing
What’s new in v1.0.0
- Upgrade to Filament 5 across the admin panel
- Stabilised admin resources, billing flows, and settings system
- Improved subscription plan seeders
- Added full Docusaurus-compatible documentation
- Fixed upgrade-related issues across auth, billing, and tests
Stack baseline
- Laravel 12
- Filament 5
- React 19 + Inertia.js
- TypeScript
- Stripe billing
Getting started
After pulling v1.0.0:
./vendor/bin/sail artisan migrate
./vendor/bin/sail artisan db:seed
./vendor/bin/sail artisan test
./vendor/bin/sail npm run types
./vendor/bin/sail npm run lintUpgrade notes
- Filament has been upgraded to v5, including API and configuration changes
- Filment shield has been upgraded to v4, including configuration changes
- Filment shield has been upgraded to v3, including configuration changes
- Existing projects should review custom Filament resources and panel configuration
Acknowledgements
This release represents the stabilisation of the core SaaS PHP stack following the Filament 5 upgrade.
v0.4.3
Admin UX, Billing Fallbacks & Stability Fixes
This release focuses on improving admin usability, stabilizing billing configuration, and fixing edge cases in settings and tests.
Features
-
Stripe config fallback logic
- Billing now prioritizes database-stored Stripe values before falling back to environment variables
- Makes runtime config more flexible for multi-tenant / admin-controlled setups
-
Subscription call-to-action improvements
- Added clearer entry points into the subscription module
- Introduced direct tagging for “most popular” plans
Improvements
-
Subscription admin UI
- Grouped subscription management into tabs for better organization
- Simplified plan table by removing redundant “most popular” icon
-
Admin settings UX
- Settings can now be saved without requiring a logo upload
- Removes unnecessary friction in configuration workflows
-
Theme updates
- Minor design simplification and consistency improvements across the panel
Fixes
- Fixed failing test caused by missing import
- General stability improvements around billing and settings handling
Chores
- Package upgrades and dependency maintenance
Notes
-
Stripe configuration behavior has changed:
- Database values now take precedence over
.env - Ensure your admin panel settings are correctly populated if relying on dynamic config
- Database values now take precedence over
Full Changelog: v0.4.2...v0.4.3
v0.4.2
Security, Stability & Dev Environment Improvements
This release focuses on hardening authentication flows, stabilizing billing logic, and introducing a Docker-based development environment via Laravel Sail.
Security Improvements
- Prevented potential OAuth account takeover by enforcing stricter provider matching
- Secured social login flow to avoid unsafe account linking
- Reduced verification email spam using session-based throttling
- Limited unnecessary exposure of 2FA-related data
Billing & Subscription Fixes
- Fixed incorrect handling of free-tier subscription periods
- Enforced active plan validation across billing flows
- Improved transaction safety in billing operations
- Resolved edge cases in webhook handling and billing behaviour
- Ensured subscription plan factory slugs are unique
Testing & Reliability
- Fixed failing billing tests caused by outdated assumptions
- Restored missing model factories for billing-related models
- General test cleanup and improved consistency
Developer Experience
- Added Laravel Sail support for a consistent Docker-based local environment
- Updated
.gitignorefor container-based workflows - Replaced
auth()helper withAuthfacade to improve compatibility with Intelephense - Updated MySQL SSL configuration to use PHP 8.5-compatible constants
Miscellaneous
- Improved verification flow UX with debounced prompts
- General codebase cleanup and internal consistency improvements
Notes
- If upgrading, ensure your environment supports the updated MySQL SSL configuration (PHP 8.5+ compatible)
- Recommended to use Sail for local development going forward
Full Changelog: v0.4.1...v0.4.2
v0.4.1
This release focuses on stabilizing the billing system, improving Stripe checkout reliability, strengthening webhook handling, and ensuring correct monetary data handling across subscriptions.
Improvements
Checkout Flow
- Improved Stripe checkout flow with proper PaymentIntent handling
- Avoids unnecessary confirmation calls for already processed payments
- Better handling of client secrets and payment states
Webhook Reliability
- Enhanced webhook logging with replay-safe payload storage
- Improved retry logic with ability to reconstruct events
- Clearer separation between signature verification and payload validation errors
Monetary Data Integrity
- Standardized all billing amounts to integer (minor units / cents)
- Eliminates float/decimal inconsistencies in pricing and subscriptions
- Prevents undercharging/overcharging issues
Subscription Consistency
- Improved logic for determining the current active subscription
- Better normalization of subscription state across the system
Free Plan Support
- Added proper handling for free tier subscriptions
- Avoids invalid Stripe price creation for zero-value plans
- Improved frontend flow for free plan activation
Authorization & Policies
- Fixed inconsistencies in panel access authorization
- Improved policy handling for user access checks
Frontend Stability
-
Safer handling of API responses (prevents JSON parsing errors)
-
Improved error handling for:
- expired sessions
- CSRF issues
- invalid responses
Breaking / Important Notes
- Billing amounts are now stored as integer cents
- Existing installations must ensure proper data migration
- Stripe price creation now expects valid minor-unit values
- Free plans are handled separately from paid Stripe flows
Summary
- 36 files updated
- +1240 / -270 lines changed
- Multiple fixes across billing, frontend, and policies
Full Changelog: v0.4.0...v0.4.1
v0.4.0
What’s New
Subscriptions
- Full lifecycle management: create, swap, cancel, resume
- Grace period cancellations with resume support
- Prorated plan switching via
SubscriptionService - Monthly and annual billing cycle support
Stripe Integration
- Webhook handling for 6 event types (idempotent & retry-safe)
- Signature verification with proper CSRF exemption
- Invoice sync from Stripe
- Lazy-loaded Stripe client for reduced API calls
Plan Management
- Multiple pricing tiers (monthly / annual)
- Configurable trial periods
- Feature definitions via
PlanFeature - Plan activation and deactivation
Frontend
- Pricing page with monthly/annual toggle
- Checkout flow
- Subscription dashboard and detail view
- Invoice history
Security & Data Integrity
- Policy-based authorization (user isolation)
- Atomic database transactions
- Race condition prevention
- Full PHP 8.3 type safety
- Audit trail via
BillingEvent - Webhook logging with retry support
Database
-
6 new tables:
subscription_plansplan_pricesplan_featurescustomer_subscriptionsbilling_eventswebhook_logs
-
2 versioned migrations with constraints and integrity enforcement
Testing
- 100 passing tests
- Covers unit, feature, authorization, webhook, and transaction flows