Repository navigation
v0.4.0
Fight AccessControl v0.4.0
This pre-1.0 minor release introduces breaking Permission-tier and authorization-composition changes. Review the migration guide before upgrading.
Changed
- Every Permission has a non-null tier. Custom Permissions are always
ADMIN_SAFE; safe read results and the OpenAPI Permission component expose the same required non-null tier. - Custom-Role grants and direct Agent grants/complete-set replacements accept only authoritative
ADMIN_SAFEPermissions, including idempotent requests. Protected or invalid membership fails without a partial write or success event. - The exact
ROLE_SUPER_ADMINname is reserved for the uniquely authoritative managed Role. Protected managed Permissions may belong only to this Role. Pending Users can receive it for bootstrap under ordinary User Role-assignment rules. - Managed-policy reconciliation rejects promotion to
SUPER_ADMIN_ONLYwhile a custom Role, ordinary managed Role or Agent still holds the Permission. It does not silently remove memberships. - Actor-only Role administration, User Role-assignment and Agent Permission authorization ports have been removed. Consumers must protect every command entry point; actor IDs remain provenance, not authorization. Ownership-sensitive session, email-change and invitation checks remain.
Upgrade requirements
Update consumer handler wiring, non-null persistence mappings/hydration/projections, and repository contracts together. Role, Agent and Permission adapters must share transaction-duration reference/tier fences across grants, no-ops and managed-policy promotion. Consumers retain ownership of caller/target authorization, real database locking, final-admin safeguards and deployment migration.
Requires PHP 8.5+ and Fight Common ^1.2. See the full changelog and changes since v0.3.0.
Verification
The signed v0.4.0 tag identifies release merge 380b134b35c722e6416787b13f5c20c64bd05388. Fresh certification of that exact commit passed planning integrity, the complete package quality gate, and OpenAPI consumer composition:
- 603 tests / 4,669 assertions.
- Exact 5,126/5,126 production statements covered.
- PHP 8.5.7 / Xdebug 3.5.3 / PHPUnit 13.3.5.
The component-only OpenAPI proof retains the advisory Required @OA\PathItem() not found because it intentionally defines no endpoints. This is package verification, not certification of a consumer API document, database isolation or consumer adoption.