Skip to content

Releases: nowo-tech/BlogKitBundle

Release v1.4.1

Choose a tag to compare

@HecFranco HecFranco released this 28 Sep 09:28

Release v1.4.1

sync pnpm-lock for @types/node bump

  • Dev dependencies: bump @types/node / Vite and sync pnpm-lock.yaml so CI pnpm install --frozen-lockfile succeeds.

Changelog

Changed

  • Dev dependencies: bump @types/node / Vite and sync pnpm-lock.yaml so CI pnpm install --frozen-lockfile succeeds.

What's Changed

  • chore(deps): bump vite from 8.3.0 to 8.3.1 by @dependabot[bot] in #19

Full Changelog: v1.4.0...v1.4.1

Release v1.4.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 07:57

Release v1.4.0

Changelog

Security

  • Default html.sanitize.strategy is allowlist (was none). Flex recipe ships allowlist; when@prod still forces allowlist. Set none only for fully trusted editors.

Added

  • REQ-DEMO-013: Playwright e2e under demo/symfony8/e2e/ (make test-e2e), demo-screenshots target, and README gallery with full demo context (masthead + public index / article / admin; docs/images/demo/overview.png, article.png, admin.png).

Changed

  • Doctrine ORM SortDirection: replace string 'ASC'/'DESC' in #[ORM\OrderBy] and QueryBuilder orderBy/addOrderBy with SortDirection::Ascending/Descending (doctrine/orm deprecation, doctrine/orm#11313); require doctrine/orm ^3.7 where applicable.

Full Changelog: v1.3.1...v1.4.0

Release v1.3.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 16:39

v1.3.1

Changelog

Added

  • REQ-CS-008: igor-php/igor-php (require-dev only), root igor.json, Composer/Makefile igor target, and release-check wiring for FrankenPHP worker-state audit.

Changed

  • Worker safety (Igor): justified // @igor-ignore annotations and/or ResetInterface / request-scoped fixes so make igor passes on package src/.

Full Changelog: v1.3.0...v1.3.1

Release v1.3.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 14:55

Release 1.3.0

Changelog

FrankenPHP worker mode with kernel not reset between requests (scenario B / reset_kernel=false): bundle-owned state is request-scoped without relying on services_resetter. Full write-up: docs/FRANKENPHP-WORKER-AUDIT.md.

Added

  • BlogKitWorkerStateSubscriber: clears the bundle memos (settings, settings provider, tag caches, publish-event buffer) at the start of every main request and resets the blog entity manager when a previous request closed it.
  • Twig functions nowo_blog_kit_can_manage(), nowo_blog_kit_can_moderate(), nowo_blog_kit_can_configure() evaluated per call.
  • comments.captcha.timeout_seconds (default 5.0) for the default StreamCaptchaHttpClient.

Changed

  • Admin templates use the new access functions instead of the per-user Twig globals.
  • BlogSettingsRepository::findSingleton() refreshes the settings row from the database (HINT_REFRESH) when loading it, so a long-lived identity map cannot serve stale comment protection settings.

Deprecated

  • Twig globals nowo_blog_kit_can_manage, nowo_blog_kit_can_moderate, nowo_blog_kit_can_configure (frozen per Twig environment in worker mode without reset).

Fixed

  • BlogArticlePublishedDoctrineSubscriber: a failed flush no longer leaks its pending articles into the next flush (buffer cleared per top-level flush; implements ResetInterface).

What's Changed

  • chore(deps): bump happy-dom from 20.11.2 to 20.11.12 by @dependabot[bot] in #9
  • chore(deps): bump @types/node from 26.2.0 to 26.4.0 by @dependabot[bot] in #10
  • chore(deps): bump happy-dom from 20.11.12 to 20.14.0 by @dependabot[bot] in #11
  • chore(deps): bump @types/node from 26.4.0 to 26.4.1 by @dependabot[bot] in #12
  • chore(deps): bump happy-dom from 20.14.0 to 20.14.3 by @dependabot[bot] in #13
  • chore(deps): bump vite from 8.2.2 to 8.3.0 by @dependabot[bot] in #15
  • chore(deps): bump @types/node from 26.4.1 to 26.5.1 by @dependabot[bot] in #14
  • chore(deps): bump @types/node from 26.5.1 to 26.6.1 by @dependabot[bot] in #16
  • chore(deps): bump happy-dom from 20.14.3 to 20.14.5 by @dependabot[bot] in #17

Full Changelog: v1.2.0...v1.3.0

Release v1.2.0

Choose a tag to compare

@github-actions github-actions released this 28 Aug 07:10

Release 1.2.0

Changelog

Changed

  • Admin blog settings: split into section routes (/admin/blog/settings/{listing|cards|index-aside|article|comments}); /admin/blog/settings redirects to listing.
  • BlogSettingsType: optional section form option; listingMode, masonryStrategy, and heroImageMode render as <select> (expanded: false).
  • BlogKitAdminAccessSubscriber: authorize all admin_blog_settings* routes via canConfigure.
  • Templates: portable area nav, section tabs, and sectioned settings UI (_area_nav, _settings_section_tabs, _nav_tabs).

Fixed

  • Demo (symfony8): install pdo_mysql so Compose MySQL DATABASE_URL works (REQ-DEMO-011).

Notes

  • Hosts that overrode settings with a custom controller/form for section tabs can remove those overrides and use the bundle routes/form.
  • Override Twig templates if you need host-specific admin chrome; form fields come from BlogSettingsType.

Full Changelog: v1.1.7...v1.2.0

Release v1.1.7

Choose a tag to compare

@github-actions github-actions released this 24 Aug 16:05

Release 1.1.7

See docs/CHANGELOG.md for details.

Changelog

Changed

  • Demos: MySQL env policy in FrankenPHP stack (REQ-DEMO-011).
  • Docs: PHP-FIG PSR evaluation (REQ-CS-007).
  • Style: PHP CS Fixer alignment.

Notes

  • No API or configuration changes for integrators unless noted above.

What's Changed

  • chore(deps): bump nowo-tech/audit-kit-bundle from 1.1.12 to 1.1.14 by @dependabot[bot] in #4
  • chore(deps): bump friendsofphp/php-cs-fixer from 3.95.19 to 3.95.20 by @dependabot[bot] in #5
  • chore(deps): bump typescript from 5.9.3 to 7.0.2 by @dependabot[bot] in #6
  • chore(deps): bump @types/node from 24.13.3 to 26.2.0 by @dependabot[bot] in #7
  • chore(deps): bump vite from 6.4.3 to 8.2.2 by @dependabot[bot] in #8

New Contributors

Full Changelog: v1.1.6...v1.1.7

Release v1.1.6

Choose a tag to compare

@github-actions github-actions released this 19 Aug 15:42

Release 1.1.6: restore 100% coverage after query memoization

Changelog

Restore 100% PHP line coverage after the v1.1.5 query-memoization changes.

Fixed

  • BlogCatalog: cover sidebar tag resolution when no search/tag filters are active (published tag summaries path).

Full Changelog: v1.1.5...v1.1.6

Release v1.1.5

Choose a tag to compare

@github-actions github-actions released this 19 Aug 15:17

Release v1.1.5: memoize blog tag lookups per request

Changelog

Reduce duplicate Doctrine queries on public blog index and detail pages.

Fixed

  • BlogArticleRepository: memoize tags-by-article lookups per request (ResetInterface) so paginated lists and sidebars reuse cached tag rows instead of re-querying overlapping article ids.
  • BlogTagRepository: memoize findPublishedTagSummaries() per locale per request.
  • BlogCatalog: sidebar without search/tag filters reuses published tag summaries instead of a heavier filtered SQL query.

What's Changed

  • ci(security): composer audit --locked in CI by @HecFranco in #3

Full Changelog: v1.1.4...v1.1.5

Release v1.1.4

Choose a tag to compare

@github-actions github-actions released this 19 Aug 15:10
fc57fe2

Security remediation release v1.1.4 (Ago-2026 campaign).

What's Changed

  • fix(security): enable HTML allowlist sanitizer in prod recipe by @HecFranco in #2

New Contributors

Full Changelog: v1.1.3...v1.1.4

Release v1.1.3

Choose a tag to compare

@github-actions github-actions released this 19 Aug 10:14

Release 1.1.3

Changelog

Restore 100% PHP coverage for BlogProtection when no settings row exists yet.

Fixed

  • Test coverage for YAML fallback rate-limit limits when the settings singleton is absent

Full Changelog: v1.1.1...v1.1.3