Repository navigation
v0.1.0
Fight AccessControl v0.1.0 is the first public pre-1.0 release of the framework-neutral identity, credential, session, authorization, and account-lifecycle package for Fight applications.
Highlights
- User invitation, activation, authentication, refresh-session rotation, logout, password recovery and change, email change, and account administration
- Role and Permission definition, assignment, managed-policy reconciliation, administrative reads, and retry-safe desired-state authorization changes
- Agent provisioning, credential rotation and revocation, direct Permission authority, HMAC request authentication, replay protection, and secret-free diagnostics
- One request-scoped
SecurityContextover distinct immutable User and Agent principals - Framework-neutral behavioral conformance support and exact production-statement coverage
Package boundary
The package contains framework-neutral Domain and Application code. Consumer projects continue to own framework adapters, persistence, HTTP, cookies, signing-key configuration, mail, queues, realtime, hosting, and composition roots. Full starter implementation follows tagged Fight AccessControl and Fight Common releases.
Requirements
- PHP 8.5 or newer
johnnickell/fight-common: ^1.1
Verification
- 607 tests and 4,675 assertions
- exact 4,609/4,609 production-statement coverage
- architecture, package-boundary, static-analysis, documentation-link, and production-only installation checks passed
- signed annotated tag verified by GitHub
Pre-1.0 policy
Public contracts may be refined in later 0.x releases as the framework starters are implemented. A separate stability review is required before 1.0.0.
Full changelog: https://github.com/johnnickell/fight-access-control/blob/v0.1.0/CHANGELOG.md