Repository navigation
Release v1.1.0
Release v1.1.0
Security hardening: CSRF fail-closed, panel.role, path allowlists,
safe redirects, trailing-slash fix, signed export/import.
See docs/CHANGELOG.md and docs/UPGRADING.md.
Changelog
Security
- CSRF is fail-closed and
symfony/security-csrfis a hard requirement. panel.role(defaultROLE_ADMIN) gates the panel viaAuthorizationCheckerInterface.route_namemust be#[Routable];localemust be configured; free-form_controlleroverrides are disabled by default (discovery allowlist only).- Path safety rejects
//…/ schemes / control characters; redirect subscribers only emit safeLocationtargets. - Trailing-slash redirects apply only to paths managed by that definition (fixes global redirect bug).
enabled: falseunregisters panel, DB loader, and redirect subscribers.
Added
- Conflict detection / rejection (
panel.reject_conflicts),panel.max_definitions. - Signed export/import (HMAC) and conflict preview endpoint.
RoutePathAuditSubscriber(logs user when a security token is present).- Recipe
access_controlexample and panel security defaults.
Compatibility
- PHP
>=8.2,<8.6; Symfony^7.4 || ^8.0(CI minors 7.4, 8.0, 8.1). - BC notes: CSRF manager required;
panel.roledefaults toROLE_ADMIN(setnullto restore pre-1.1 behaviour without in-bundle gate); controller override field removed unlessallow_controller_override: true.
Full Changelog: v1.0.3...v1.1.0