Skip to content

Release v1.1.0

Choose a tag to compare

@github-actions github-actions released this 26 Jul 17:48
· 50 commits to main since this release

Release v1.1.0

Security hardening: CSRF fail-closed, panel.role, path allowlists,
safe redirects, trailing-slash fix, signed export/import.

See docs/CHANGELOG.md and docs/UPGRADING.md.

Changelog

Security

  • CSRF is fail-closed and symfony/security-csrf is a hard requirement.
  • panel.role (default ROLE_ADMIN) gates the panel via AuthorizationCheckerInterface.
  • route_name must be #[Routable]; locale must be configured; free-form _controller overrides are disabled by default (discovery allowlist only).
  • Path safety rejects //… / schemes / control characters; redirect subscribers only emit safe Location targets.
  • Trailing-slash redirects apply only to paths managed by that definition (fixes global redirect bug).
  • enabled: false unregisters panel, DB loader, and redirect subscribers.

Added

  • Conflict detection / rejection (panel.reject_conflicts), panel.max_definitions.
  • Signed export/import (HMAC) and conflict preview endpoint.
  • RoutePathAuditSubscriber (logs user when a security token is present).
  • Recipe access_control example and panel security defaults.

Compatibility

  • PHP >=8.2, <8.6; Symfony ^7.4 || ^8.0 (CI minors 7.4, 8.0, 8.1).
  • BC notes: CSRF manager required; panel.role defaults to ROLE_ADMIN (set null to restore pre-1.1 behaviour without in-bundle gate); controller override field removed unless allow_controller_override: true.

Full Changelog: v1.0.3...v1.1.0