Repository navigation
Release v1.1.4
Release v1.1.4
Security hardening for path safety, loader defense, panel ids, and import limits,
plus FrankenPHP / TOC documentation updates.
Changelog
Security
SafePublicPathrejects additional control characters, encoded bypasses (%5c,%00,%0d/%0a,%252f%252f), and..segments.redirects.root_home_pathis validated at config compile time withSafePublicPath.DbRouteLoaderskips unsafe stored paths and ignores non-allowlisted controller overrides even whenallow_controller_overrideis true.- Panel
{id}requirements and manager saves accept only[A-Za-z0-9_.-]+. - Import rejects payloads larger than 1 MiB (HTTP 413); unexpected import errors no longer echo internal exception messages.
Docs
- Expanded DEMO-FRANKENPHP.md (dev/prod,
FRANKENPHP_MODE, troubleshooting). - Added table of contents to USAGE, UPGRADING, CHANGELOG, and GITHUB_CI (REQ-DOCS-005).
- Demo Symfony 8:
config/packages/dev/twig.yaml(cache: false); longer localAPP_SECRETin.env.example/ Compose fallback.
Changed
- Dev dependency: pin
phpstan/phpstanto^2.0 <2.2.6(Rector incompatibility with PHPStan 2.2.6).
Compatibility
- PHP
>=8.2,<8.6; Symfony^7.4 || ^8.0(CI minors 7.4, 8.0, 8.1). - BC notes (fail-closed): previously accepted unsafe public paths /
root_home_pathvalues, non-allowlisted stored controllers (with override on), and non[A-Za-z0-9_.-]+definition ids are now rejected or ignored.
Full Changelog: v1.1.3...v1.1.4