Skip to content

Release v1.1.4

Choose a tag to compare

@github-actions github-actions released this 26 Jul 21:29
· 41 commits to main since this release

Release v1.1.4

Security hardening for path safety, loader defense, panel ids, and import limits,
plus FrankenPHP / TOC documentation updates.

Changelog

Security

  • SafePublicPath rejects additional control characters, encoded bypasses (%5c, %00, %0d/%0a, %252f%252f), and .. segments.
  • redirects.root_home_path is validated at config compile time with SafePublicPath.
  • DbRouteLoader skips unsafe stored paths and ignores non-allowlisted controller overrides even when allow_controller_override is true.
  • Panel {id} requirements and manager saves accept only [A-Za-z0-9_.-]+.
  • Import rejects payloads larger than 1 MiB (HTTP 413); unexpected import errors no longer echo internal exception messages.

Docs

  • Expanded DEMO-FRANKENPHP.md (dev/prod, FRANKENPHP_MODE, troubleshooting).
  • Added table of contents to USAGE, UPGRADING, CHANGELOG, and GITHUB_CI (REQ-DOCS-005).
  • Demo Symfony 8: config/packages/dev/twig.yaml (cache: false); longer local APP_SECRET in .env.example / Compose fallback.

Changed

  • Dev dependency: pin phpstan/phpstan to ^2.0 <2.2.6 (Rector incompatibility with PHPStan 2.2.6).

Compatibility

  • PHP >=8.2, <8.6; Symfony ^7.4 || ^8.0 (CI minors 7.4, 8.0, 8.1).
  • BC notes (fail-closed): previously accepted unsafe public paths / root_home_path values, non-allowlisted stored controllers (with override on), and non [A-Za-z0-9_.-]+ definition ids are now rejected or ignored.

Full Changelog: v1.1.3...v1.1.4