Skip to content

Releases: johnnickell/fight-access-control

Fight AccessControl v0.5.0

Choose a tag to compare

@johnnickell johnnickell released this 06 Oct 21:55
Immutable release. Only release title and notes can be modified.
v0.5.0
46ffcf7

Fight AccessControl v0.5.0

Breaking pre-v1 contract release. Requires PHP 8.5+ and Fight Common ^1.3.

Highlights

  • Recoverable Agent provisioning and rotation with retained operation keys and safe outcomes; protected delivery, bounded restart recovery, maintenance and restoration admission guards.
  • Package-owned human credential expiry discovery/cleanup, including email authority and reservation release after downtime or account-state changes.
  • Complete Permission-based Feature lifecycle: declarations, atomic provisioning, preparation, fresh evaluation, revision-fenced management and reference-safe retirement.
  • Agent name updates, minimal profile reads and protected self-service MCP profile Tools.
  • Expanded OpenAPI components and corrected invitation-delivery status values.

Breaking integration changes

Consumers must implement current repository and authorization contracts, transaction-duration reference/authority fences, explicit delivery claim/outcome state, email reservation-revision binding and current Agent operation correlation/cohort/restoration readiness. The invitation status schema removes obsolete failed/confirmed; the old password-reset confirmation Command/component and raw-return Agent issuance APIs are removed. Managed policy requires the Agent repository.

Only the current pre-v1 API and persisted model are supported. There are no historical readers, legacy modes, compatibility shims or package-owned migration/backfill routes. No consumer data reset is authorized.

See the contract overview and changelog for detailed obligations and guide links. Package acceptance/publication does not qualify actual consumer databases, keys/sinks, scanner/runtime security, restore procedures, enrollment activation or credential use. Consumer adoption and deployment remain separate.

Full comparison

v0.4.0

Choose a tag to compare

@johnnickell johnnickell released this 27 Sep 21:59
Immutable release. Only release title and notes can be modified.
v0.4.0
380b134

Fight AccessControl v0.4.0

This pre-1.0 minor release introduces breaking Permission-tier and authorization-composition changes. Review the migration guide before upgrading.

Changed

  • Every Permission has a non-null tier. Custom Permissions are always ADMIN_SAFE; safe read results and the OpenAPI Permission component expose the same required non-null tier.
  • Custom-Role grants and direct Agent grants/complete-set replacements accept only authoritative ADMIN_SAFE Permissions, including idempotent requests. Protected or invalid membership fails without a partial write or success event.
  • The exact ROLE_SUPER_ADMIN name is reserved for the uniquely authoritative managed Role. Protected managed Permissions may belong only to this Role. Pending Users can receive it for bootstrap under ordinary User Role-assignment rules.
  • Managed-policy reconciliation rejects promotion to SUPER_ADMIN_ONLY while a custom Role, ordinary managed Role or Agent still holds the Permission. It does not silently remove memberships.
  • Actor-only Role administration, User Role-assignment and Agent Permission authorization ports have been removed. Consumers must protect every command entry point; actor IDs remain provenance, not authorization. Ownership-sensitive session, email-change and invitation checks remain.

Upgrade requirements

Update consumer handler wiring, non-null persistence mappings/hydration/projections, and repository contracts together. Role, Agent and Permission adapters must share transaction-duration reference/tier fences across grants, no-ops and managed-policy promotion. Consumers retain ownership of caller/target authorization, real database locking, final-admin safeguards and deployment migration.

Requires PHP 8.5+ and Fight Common ^1.2. See the full changelog and changes since v0.3.0.

Verification

The signed v0.4.0 tag identifies release merge 380b134b35c722e6416787b13f5c20c64bd05388. Fresh certification of that exact commit passed planning integrity, the complete package quality gate, and OpenAPI consumer composition:

  • 603 tests / 4,669 assertions.
  • Exact 5,126/5,126 production statements covered.
  • PHP 8.5.7 / Xdebug 3.5.3 / PHPUnit 13.3.5.

The component-only OpenAPI proof retains the advisory Required @OA\PathItem() not found because it intentionally defines no endpoints. This is package verification, not certification of a consumer API document, database isolation or consumer adoption.

v0.3.0

Choose a tag to compare

@johnnickell johnnickell released this 25 Sep 21:49
Immutable release. Only release title and notes can be modified.
v0.3.0
22ffab6

Fight AccessControl v0.3.0

This release adds recoverable, provider-neutral credential delivery for invitations, password resets, and email changes. The package now owns due-work discovery, committed claims, typed delivery outcomes, and recovery after interrupted work. Provider attempts use a stable delivery-generation ID for deduplication; delivery remains at-least-once.

Breaking changes before 1.0

  • CredentialDeliveryProvider replaces the invitation and email-change invoker contracts. Consumers must update cipher, repository, transaction, and worker composition and migrate existing delivery rows.
  • Transaction-aware constructors now require Fight Common's TransactionalUnitOfWork instead of the deprecated UnitOfWork contract.

Read the v0.3.0 migration guide before upgrading a consumer. Consumer cutovers require their own adapter, data, provider-deduplication, and recovery qualification.

Fight AccessControl v0.2.0

Choose a tag to compare

@johnnickell johnnickell released this 14 Sep 01:25
Immutable release. Only release title and notes can be modified.
v0.2.0
c986b48

Added

  • Opt-in, non-autoloaded OpenAPI component metadata for consumer-owned documents.
  • A repository-owned release certification gate that binds a clean exact commit to planning, package-quality, and OpenAPI consumer-composition evidence.

Verification

The signed tag resolves to the certified main commit. This draft has no attached artifacts.

v0.1.0

Choose a tag to compare

@johnnickell johnnickell released this 11 Sep 00:35
Immutable release. Only release title and notes can be modified.
v0.1.0
4219612

Fight AccessControl v0.1.0 is the first public pre-1.0 release of the framework-neutral identity, credential, session, authorization, and account-lifecycle package for Fight applications.

Highlights

  • User invitation, activation, authentication, refresh-session rotation, logout, password recovery and change, email change, and account administration
  • Role and Permission definition, assignment, managed-policy reconciliation, administrative reads, and retry-safe desired-state authorization changes
  • Agent provisioning, credential rotation and revocation, direct Permission authority, HMAC request authentication, replay protection, and secret-free diagnostics
  • One request-scoped SecurityContext over distinct immutable User and Agent principals
  • Framework-neutral behavioral conformance support and exact production-statement coverage

Package boundary

The package contains framework-neutral Domain and Application code. Consumer projects continue to own framework adapters, persistence, HTTP, cookies, signing-key configuration, mail, queues, realtime, hosting, and composition roots. Full starter implementation follows tagged Fight AccessControl and Fight Common releases.

Requirements

  • PHP 8.5 or newer
  • johnnickell/fight-common: ^1.1

Verification

  • 607 tests and 4,675 assertions
  • exact 4,609/4,609 production-statement coverage
  • architecture, package-boundary, static-analysis, documentation-link, and production-only installation checks passed
  • signed annotated tag verified by GitHub

Pre-1.0 policy

Public contracts may be refined in later 0.x releases as the framework starters are implemented. A separate stability review is required before 1.0.0.

Full changelog: https://github.com/johnnickell/fight-access-control/blob/v0.1.0/CHANGELOG.md