Skip to content

Releases: nowo-tech/ContactFormBundle

Release v1.1.2

Choose a tag to compare

@github-actions github-actions released this 09 Oct 09:05

Release v1.1.2

Changelog

Changed

  • CSP: the inline <script> in admin/base.html.twig now carries nonce="…" from the request attribute csp_nonce when it is set. The submission delete form (admin/submission/show.html.twig) no longer uses an inline onsubmit handler: it declares data-confirm and the admin base script confirms via a delegated submit listener. Added a template scan test (inline blocks must declare the nonce; no inline event handlers).

Full Changelog: v1.1.1...v1.1.2

Release v1.1.1

Choose a tag to compare

@github-actions github-actions released this 09 Oct 07:30

v1.1.1

Changelog

Fixed

  • PHPStan 2.3 / doctrine/orm 3.7.4: WorkerSafeServiceEntityRepository::findBy()/findOneBy() forward SortDirection order values without a static-analysis error (ORM 3.7 accepts them at runtime).

Dependencies

  • Dependabot: doctrine/orm 3.7.3, nowo-tech/form-kit-bundle 2.5.4, nowo-tech/ui-kit-bundle 1.8.4, dev igor-php/igor-php 0.10, nowo-tech/phpstan-frankenphp 1.2.1, phpstan/phpstan-phpunit.
  • Lock refresh: doctrine/orm 3.7.4, FormKitBundle 2.6.0, UiKitBundle 1.9.1; dev PHPStan 2.3.1, PHPUnit 11.5.57, Rector 2.7.0.
  • Demo (Symfony 8): Symfony 8.1.8, doctrine/dbal 4.5.0, PhoneInputBundle 1.4.2, Twig 3.30.0.

What's Changed

  • chore(deps): bump nowo-tech/form-kit-bundle from 2.5.2 to 2.5.3 by @dependabot[bot] in #33
  • chore(deps): bump nowo-tech/phpstan-frankenphp from 1.1.3 to 1.2.0 by @dependabot[bot] in #34
  • chore(deps): bump nowo-tech/ui-kit-bundle from 1.8.3 to 1.8.4 by @dependabot[bot] in #35
  • chore(deps): bump phpstan/phpstan-phpunit from 2.0.18 to 2.0.21 in the phpstan group by @dependabot[bot] in #36
  • chore(deps): bump nowo-tech/form-kit-bundle from 2.5.3 to 2.5.4 by @dependabot[bot] in #37
  • chore(deps): bump doctrine/orm from 3.7.2 to 3.7.3 by @dependabot[bot] in #38
  • chore(deps): bump nowo-tech/phpstan-frankenphp from 1.2.0 to 1.2.1 by @dependabot[bot] in #39
  • chore(deps): bump igor-php/igor-php from 0.9.7 to 0.10.0 by @dependabot[bot] in #40

Full Changelog: v1.1.0...v1.1.1

Release v1.1.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 07:57

Release v1.1.0

Changelog

Security

  • Consent HTML is sanitized on admin persist (and again on render).
  • Empty security.access_roles is fail-closed (deny) unless allow_unauthenticated or a custom access_checker is set.

Changed

  • Doctrine ORM SortDirection: replace string 'ASC'/'DESC' in #[ORM\OrderBy] and QueryBuilder orderBy/addOrderBy with SortDirection::Ascending/Descending (doctrine/orm deprecation, doctrine/orm#11313); require doctrine/orm ^3.7 where applicable.

Full Changelog: v1.0.23...v1.1.0

Release v1.0.23

Choose a tag to compare

@github-actions github-actions released this 27 Sep 16:40

v1.0.23

Changelog

Added

  • REQ-CS-008: igor-php/igor-php (require-dev only), root igor.json, Composer/Makefile igor target, and release-check wiring for FrankenPHP worker-state audit.

Changed

  • Worker safety (Igor): justified // @igor-ignore annotations and/or ResetInterface / request-scoped fixes so make igor passes on package src/.

Full Changelog: v1.0.22...v1.0.23

Release v1.0.22

Choose a tag to compare

@github-actions github-actions released this 24 Sep 15:24

Release v1.0.22

FrankenPHP worker compatibility with kernel not reset between requests:
EntityManager recovery, submission detach, HINT_REFRESH reads,
WorkerSafeServiceEntityRepository, and MySQL demo migrations.

Release v1.0.21

Choose a tag to compare

@github-actions github-actions released this 24 Aug 16:06

Release 1.0.21

See docs/CHANGELOG.md for details.

Changelog

Changed

  • Demos: MySQL env policy in FrankenPHP stack (REQ-DEMO-011).
  • Docs: PHP-FIG PSR evaluation (REQ-CS-007).

Notes

  • No API or configuration changes for integrators unless noted above.

Full Changelog: v1.0.20...v1.0.21

Release v1.0.20

Choose a tag to compare

@github-actions github-actions released this 20 Aug 21:36

Release v1.0.20

Changelog

Fixed

  • Public dynamic forms: DynamicContactFormBuilder applies FormKit profile contact_form (FormOptionsMerger) so host nowo_form_kit.profiles.contact_form.defaults.row_attr / attr affect public fields (form name public_contact). CMS labels/help/placeholders stay as plain strings.

Full Changelog: v1.0.19...v1.0.20

Release v1.0.19

Choose a tag to compare

@github-actions github-actions released this 20 Aug 08:48

Release 1.0.19

Changelog

Security

  • Flex recipe: when@prod keeps ROLE_ADMIN, allow_unauthenticated: false, and tighter public rate limits; ship security_nowo_contact_form.yaml (access_control for /admin/contact-forms). Prefer ^1.0.19.

What's Changed

  • feat(recipe): prod rate limit + admin access_control by @HecFranco in #23

New Contributors

Full Changelog: v1.0.18...v1.0.19

Release v1.0.18

Choose a tag to compare

@github-actions github-actions released this 19 Aug 16:02

Release v1.0.18: composer audit CI

Changelog

Security

  • CI: run composer audit --locked after dependency install (REQ-SEC / P3).

Full Changelog: v1.0.17...v1.0.18

Release v1.0.17

Choose a tag to compare

@github-actions github-actions released this 19 Aug 07:28

Release v1.0.17

Changelog

Fixed

  • Allow doctrine/orm 3.6.8 again (removed the temporary <3.6.8 constraint from 1.0.16).
  • Integration TestKernel uses array cache adapters so SchemaTool does not hit DoctrineDbalCacheAdapterSchemaListener / DBAL Schema::edit on DBAL 4.4.

Full Changelog: v1.0.16...v1.0.17