Repository navigation
v1.1.0
This release focuses on security, reliability, maintainability, and documentation. It significantly hardens the authentication and billing systems, expands automated test coverage, streamlines internal architecture, and introduces a new API documentation site powered by Doctum.
Highlights
Security
- Hardened authentication, authorization, billing, and webhook security.
- Strengthened OAuth verification and account linking.
- Improved magic link authentication flow and user assignment safeguards.
- Enforced password reset token expiration.
- Deferred email and phone verification until password reset succeeds.
- Prevented two-factor authentication secrets from being serialized.
- Strengthened settings verification and two-factor authentication.
- Unified impersonation session detection across middleware and the user interface.
- Prevented blank password updates, enforced maintenance bypass checks, and invalidated other sessions after password changes.
- Restored registration settings enforcement and social login authorization.
Billing
- Centralized current subscription status handling.
- Fixed Stripe customer persistence to prevent duplicate customer creation.
- Expanded Stripe-backed subscription testing.
- Improved internal billing architecture and removed duplicated logic.
Testing
- Added comprehensive regression coverage across the billing system.
- Added authorization tests for Filament resources.
- Added subscription ownership (IDOR) regression tests.
- Added webhook processing and subscription lifecycle tests.
- Expanded policy coverage.
- Increased automated test coverage while resolving previously undiscovered production issues.
Refactoring
- Consolidated billing services and removed unused code.
- Simplified authentication, billing, and configuration internals.
- Centralized billing, settings, impersonation, and security configuration.
- Removed obsolete code and improved maintainability throughout the framework.
Documentation
- Added Doctum-powered API documentation.
- Published API documentation through GitHub Pages.
- Added Doctum-compatible documentation headers across controllers, models, middleware, actions, and services.
- Added navigation from the API documentation back to the main documentation site.
- Improved project documentation and updated the README.
Continuous Integration
- Added automated API documentation generation and deployment.
- Improved GitHub Actions workflow for documentation builds.
- Updated CI to use the correct Doctum binary.
- Optimized documentation builds by skipping unnecessary Laravel Composer scripts.
Fixes
- Fixed OAuth login authorization regressions.
- Removed duplicate profile image handling.
- Fixed invalid translation helper usage.
- Improved password management and session handling.
- Applied numerous reliability and stability improvements across the framework.
Upgrade Notes
- API documentation is now generated automatically using Doctum and published via GitHub Pages.
- The billing layer has been refactored internally, but remains backward compatible for existing integrations.
- Developers should review the updated API documentation and security improvements before extending authentication or billing functionality.
Full Changelog: v1.0.2...v1.1.0