Skip to content

v1.1.0

Choose a tag to compare

@iamceeso iamceeso released this 25 Jul 16:15
· 2 commits to main since this release

This release focuses on security, reliability, maintainability, and documentation. It significantly hardens the authentication and billing systems, expands automated test coverage, streamlines internal architecture, and introduces a new API documentation site powered by Doctum.

Highlights

Security

  • Hardened authentication, authorization, billing, and webhook security.
  • Strengthened OAuth verification and account linking.
  • Improved magic link authentication flow and user assignment safeguards.
  • Enforced password reset token expiration.
  • Deferred email and phone verification until password reset succeeds.
  • Prevented two-factor authentication secrets from being serialized.
  • Strengthened settings verification and two-factor authentication.
  • Unified impersonation session detection across middleware and the user interface.
  • Prevented blank password updates, enforced maintenance bypass checks, and invalidated other sessions after password changes.
  • Restored registration settings enforcement and social login authorization.

Billing

  • Centralized current subscription status handling.
  • Fixed Stripe customer persistence to prevent duplicate customer creation.
  • Expanded Stripe-backed subscription testing.
  • Improved internal billing architecture and removed duplicated logic.

Testing

  • Added comprehensive regression coverage across the billing system.
  • Added authorization tests for Filament resources.
  • Added subscription ownership (IDOR) regression tests.
  • Added webhook processing and subscription lifecycle tests.
  • Expanded policy coverage.
  • Increased automated test coverage while resolving previously undiscovered production issues.

Refactoring

  • Consolidated billing services and removed unused code.
  • Simplified authentication, billing, and configuration internals.
  • Centralized billing, settings, impersonation, and security configuration.
  • Removed obsolete code and improved maintainability throughout the framework.

Documentation

  • Added Doctum-powered API documentation.
  • Published API documentation through GitHub Pages.
  • Added Doctum-compatible documentation headers across controllers, models, middleware, actions, and services.
  • Added navigation from the API documentation back to the main documentation site.
  • Improved project documentation and updated the README.

Continuous Integration

  • Added automated API documentation generation and deployment.
  • Improved GitHub Actions workflow for documentation builds.
  • Updated CI to use the correct Doctum binary.
  • Optimized documentation builds by skipping unnecessary Laravel Composer scripts.

Fixes

  • Fixed OAuth login authorization regressions.
  • Removed duplicate profile image handling.
  • Fixed invalid translation helper usage.
  • Improved password management and session handling.
  • Applied numerous reliability and stability improvements across the framework.

Upgrade Notes

  • API documentation is now generated automatically using Doctum and published via GitHub Pages.
  • The billing layer has been refactored internally, but remains backward compatible for existing integrations.
  • Developers should review the updated API documentation and security improvements before extending authentication or billing functionality.

Full Changelog: v1.0.2...v1.1.0