Skip to content

Releases: nowo-tech/symfony-beacon

Release v1.24.5

Choose a tag to compare

@github-actions github-actions released this 29 Aug 15:30

docs(release): cut v1.24.5 changelog, upgrading, and roadmap.

Align AUTH-005 / QR docs with base enabled + prod overlay disabled.

Changelog

Fixed

  • AUTH-005 docs: operator docs now match the real QR login split — base qr_login.mode: enabled (local / PHPUnit / E2E); production disables via config/packages/prod/nowo_auth_kit.yaml. Corrected ENGINEERING-AUDIT, API, UPGRADING, and ROADMAP (they previously described a stale when@dev / when@test overlay pattern).

Notes for integrators

  • No Doctrine migrations and no Composer pin changes.
  • After pull: no runtime steps. Prefer reading AUTH-005 / QR notes in API.md and ENGINEERING-AUDIT.md.
  • See UPGRADING.md Upgrading from 1.24.4 to 1.24.5.

Release v1.24.4

Choose a tag to compare

@github-actions github-actions released this 29 Aug 14:40

docs(release): cut v1.24.4 changelog, upgrading, and roadmap.

Changelog

Changed

  • Kit-over-shim (OTHER pass 40): HotReload 1.5.2, LoginThrottle 3.2.0, CookieConsent 1.9.7, Pwa 1.5.0. Deleted host shims now owned by kits: AuthKitAwareLoginRateLimiter, PwaStatelessCookieSubscriber, PushServiceWorkerListener. Web Push uses kit service_worker.web_push + host WebPushPresentation (title/body/tag in the push JSON); PWA cache_version v8.

Notes for integrators

  • No Doctrine migrations.
  • After pull: composer install. Soft-reload browsers so clients pick up the new service worker. Optional: bin/console nowo:hot-reload:check in dev.
  • See UPGRADING.md Upgrading from 1.24.3 to 1.24.4.

Release v1.24.3

Choose a tag to compare

@HecFranco HecFranco released this 29 Aug 13:58

docs(release): cut v1.24.3 changelog, upgrading, and roadmap.

Align README/INSTALL/DSN/CONTRIBUTING/ARCHITECTURE and specs 058/100 with auto reload-env and beacon-suite DB/long-content kinds.

Changelog

Changed

  • Dogfood DX: make seed / make dogfood / make ready call reload-env-if-beacon-dsn-stale so php/messenger recreate when .env.local BEACON_DSN differs from the container (avoids ingest 401 after project recreate). New make reload-env recreates without Vite. See DSN.md.
  • make beacon-suite: adds kinds db-sql, db-connection, and long-content (Query facts / connection errors / truncation). Spec 058 FR-015.

Notes for integrators

  • No Doctrine migrations.
  • After pull: no env changes required for local dogfood. Prefer make dogfood / make ready (auto reload). Manual: make reload-env.
  • See UPGRADING.md Upgrading from 1.24.2 to 1.24.3.

Release v1.24.2

Choose a tag to compare

@HecFranco HecFranco released this 29 Aug 08:45

docs(release): cut v1.24.2 changelog, upgrading, and roadmap.

HotReloadBundle 1.5.1 shared_worker, CSP inline nonce stamp, Redis AUTH outside local, and E2E slide-to-confirm PointerEvents.

Changelog

Changed

  • Hot reload via HotReloadBundle 1.5.1: host config uses auto_inject: true, client_mode: shared_worker (bundle-served /_nowo/hot-reload/*), Idiomorph + WDT/Twig Inspector preserve selectors. See FRANKENPHP-HOT-RELOAD.md.
  • CSP: stamps vendor inline <script> tags with _beacon_csp_nonce before setting the header; optional app.csp.connect_src_extra / app.csp.script_src_extra append after Mercure origin. KitInlineConfigScriptSubscriber unchanged.
  • Shared Redis AUTH (REQ-INFRA-SHARED-003): REDIS_PASSWORD in .env.dist / .env.e2e.dist / compose.infra.yaml (optional local; required outside dev/test). SiteBackupSecurityDefaultsGuard refuses boot when Redis has no AUTH (REDIS_PASSWORD empty and no pass in REDIS_URL). Never interpolate an empty password (redis://:@host). See SHARED-SERVER.md and PRODUCTION.md.

Fixed

  • E2E: slide-to-confirm confirmed with in-page PointerEvents (CI-friendly drag) instead of brittle host pointer injection.

Notes for integrators

  • No Doctrine migrations.
  • After pull: composer install (pins nowo-tech/hot-reload-bundle 1.5.1 require-dev). Outside dev/test, set REDIS_PASSWORD and put the same password in REDIS_URL / MESSENGER_TRANSPORT_DSN (never redis://:@host). Dev: optional bin/console nowo:hot-reload:check after make up.
  • See UPGRADING.md Upgrading from 1.24.1 to 1.24.2.

Release v1.24.1

Choose a tag to compare

@github-actions github-actions released this 26 Aug 10:11

docs(release): cut v1.24.1 changelog, upgrading, and roadmap.

Setup token default, versioned .env.e2e.dist, and compare-link fix for 1.24.0.

Changelog

Changed

  • Setup token gate: .env.dist ships SITE_SETUP_TOKEN=beacon-local-setup (same pattern as the FrankenPHP boilerplate). /setup without ?token= returns 403 and the FormKit paste form even when the env var is empty (fallback to that documented local default; prod still refuses it).
  • Isolated E2E env template: versioned file is .env.e2e.dist (sibling of .env.dist). Working file .env.e2e.local stays gitignored (cp .env.e2e.dist .env.e2e.local / make ensure-e2e-env overlays shared infra from .env.local). Never commit .env.local or .env.e2e.local. Spec 104.

Fixed

  • CI Quality: restore PHPStan-clean / includable 100% coverage and Rector dry-run for issue 107 (Query panel / AI export branches).

Notes for integrators

  • No Doctrine migrations.
  • After pull: merge SITE_SETUP_TOKEN from .env.dist into .env.local if missing. For isolated E2E, cp .env.e2e.dist .env.e2e.local or make ensure-e2e-env (do not commit .env.local / .env.e2e.local).
  • See UPGRADING.md Upgrading from 1.24.0 to 1.24.1.

Release v1.24.0

Choose a tag to compare

@github-actions github-actions released this 26 Aug 07:40

docs(release): cut v1.24.0 changelog, upgrading, and roadmap.

AuthKit 1.20 security kits, ops ingest hardening (106), and SQL error context (107).

Changelog

Added

  • AuthKit 1.20.0 with optional kits: nowo-tech/slide-to-confirm-bundle 1.1.0 (registration consent slider, profile gate; clear history in project Settings uses the danger profile), nowo-tech/device-intelligence-bundle 1.1.1 (collect on AuthKit pages, new-device email, extra device-keyed rate limit on register/reset/magic, Account → Security → Trusted browsers), and nowo-tech/otp-input-bundle on /reset-password/complete (otp_input.enabled, multi-box OtpType; server OTP checks unchanged). Device ID is not a credential; AuthKit never auto-trusts a device after login. QR approve stays a button (UC-AUTH-22). Cookie di_obs is inventoried as required account-security. Migration Version20260824120000. Phone SMS verification remains ROADMAP Later.
  • Ops ingest hardening (106): Redis-backed MessengerQueueHealth depths for async_ingest / async / failed on Ops overview and /metrics (beacon_messenger_failed_pending); cached daily/monthly event quota usage; one Envelope flush retry on unique-constraint races; batched retention purge (1000-row batches); shared PrivateNetworkTarget SSRF helper for Mercure hub + outbound webhooks; app:project:api-key-legacy-secrets dry-run / --apply for redundant Halite API-key ciphertext; EVENT-STORAGE.md growth stages.
  • SQL / database error context (107): issue and event detail show a Query panel (SQLSTATE, vendor code, SQL, bindings) derived from contexts.db, extra, query breadcrumbs, or exception text. Stack opens the in-app frame. issue.culprit widened to 255 (migration Version20260826120000 on MySQL). AI export includes optional query. Sample seed issue #1 is a QueryException-like event. Companion BeaconBundle 1.8.0 attaches contexts.db on PDO/DBAL exceptions.
  • Setup: paste SITE_SETUP_TOKEN through a FormKit GET gate on the setup wizard.

Changed

  • Guest AuthKit layout loads slide-to-confirm, device-intelligence, and OTP-input assets; device collect boot uses the CSP nonce (vendor inline script would be blocked).
  • Composer pins (nowo-tech/* patch + FormKit minor): audit-kit 1.1.15, auth-kit 1.20.0, beacon-bundle 1.8.0, breadcrumb-kit 2.1.7, cookie-consent 1.9.6, dashboard-menu 2.1.10, device-intelligence 1.1.1, doctrine-encrypt 2.3.12, form-kit 2.5.2, http-log 1.1.5, login-throttle 3.1.4, maintenance-mode 1.5.7, migrations-kit 2.0.21, password-policy 1.4.3, password-strength 2.2.3, password-toggle 2.1.4, phone-input 1.3.3, pwa 1.3.3, routing-kit 1.4.4, select-all-choice 1.5.4, site-backup 1.13.8, tag-input 1.1.3, ui-kit 1.8.3, user-kit 1.1.9. Symfony 8.1.5 where that patch exists (console/form/framework/http-client/mailer/messenger/translation/uid/validator/yaml + browser-kit/css-selector/web-profiler). Dev: php-cs-fixer 3.95.22, composer-update-helper 2.0.36, hot-reload 1.4.2, phpstan-frankenphp 1.1.3, twig-inspector 1.1.4, phpstan 2.2.9.
  • Dashboard Menu 2.1.10: kit tags SearchQueryType as form.type (with FormOptionsMerger); remove host config/services/dashboard_menu.yaml override that was required on 2.1.9.
  • FormKit 2.5.2: drop host nowo_form_kit.type_map.search (built-in since 2.4.0); project clear history uses addSlideToConfirmField() (mapped: false is the type default).
  • Device collect while gated: MaintenanceMode excludes /_device; PWA deny_cache_patterns includes /_device (cache_version v6). SiteBackup documents setup.short_circuit_when_done: true (1.13.7+ default — Beacon detectors must not re-open the wizard after done).
  • Member alert preference/event and push subscription timestamps use AuditKit TimestampableTrait (not host-copied trait logic).
  • PHPStan / QA: empty baseline; no ignoreErrors in phpstan.neon.dist; injectable Clock / DNS / Halite FS seams for FrankenPHP rules; Rector semantic-only (CS-Fixer owns formatting); PHPUnit suite PHPStan-clean; includable coverage 100%.
  • Cookie consent embedded without a kernel sub-request (faster public pages).
  • Prod Compose: Messenger Redis DSNs no longer use path /messages (path is the stream name, not a DB index).

Fixed

  • Mercure hub URL guard aligned with outbound webhook SSRF policy (PrivateNetworkTarget; metadata targets always blocked).
  • Ops overview queue depth sourced from App\Ops\Messenger\MessengerQueueHealth (Redis transports, including failed).
  • E2E: slide-to-confirm confirmed via pointer drag and keyboard in CI; flaky 403 navigation retries.

Notes for integrators

  • Doctrine migrations: Version20260824120000 (device intelligence tables) and Version20260826120000 (issue.culprit → VARCHAR(255) on MySQL).
  • After pull: composer install, php bin/console doctrine:migrations:migrate -n, php bin/console assets:install (or make ready), make seed-platform (cookie inventory for di_obs), rebuild assets if you override kit templates (make vite-build).
  • Dogfood / client apps: pin nowo-tech/beacon-bundle ≥ 1.8.0 for structured contexts.db on database exceptions.
  • PWA operators: deploy assets/SW so cache_version v6 picks up /_device deny-cache.
  • See UPGRADING.md Upgrading from 1.23.3 to 1.24.0.

Release v1.23.3

Choose a tag to compare

@github-actions github-actions released this 20 Aug 15:03

release: cut v1.23.3 (kit pins + prod hardening + E2E Messenger)

Document the nowo-tech pin refresh, when@prod kit lockdown, /admin ROLE_ADMIN catch-all, and isolated E2E Redis ?dbindex= / Compose env_file override.

Changelog

Changed

  • Composer pins (nowo-tech/* patch/minor refresh): audit-kit 1.1.14, auth-kit 1.17.4, beacon-bundle 1.7.7, breadcrumb-kit 2.1.6, cookie-consent 1.9.4, dashboard-menu 2.1.8, doctrine-encrypt 2.3.11, form-kit 2.4.4, http-log 1.1.4, login-throttle 3.1.2, maintenance-mode 1.5.6, migrations-kit 2.0.20, password-policy 1.4.2, password-strength 2.2.2, password-toggle 2.1.3, phone-input 1.3.2, pwa 1.3.2, routing-kit 1.4.3, select-all-choice 1.5.3, site-backup 1.13.6, tag-input 1.1.2, ui-kit 1.8.2, user-kit 1.1.8. Dev: hot-reload 1.4.1, twig-inspector 1.1.3, phpstan-frankenphp 1.1.2, composer-update-helper 2.0.35, php-cs-fixer 3.95.20, rector 2.6.3. Transitive: paragonie/sodium_compat 2.5.2.
  • Prod kit hardening (when@prod): HttpLog turns off JSON body capture, caps body size / export / retention (14d), and requires ROLE_ADMIN; MaintenanceMode disables anonymous 503 preview; SiteBackup disables /setup, enables password protection, and requires ROLE_ADMIN; Dashboard Menu reaffirms admin-only access.
  • Security access control: catch-all ^/adminROLE_ADMIN (defense in depth alongside per-bundle checkers; previously unmatched /admin/* fell through to ROLE_USER).

Fixed

  • Isolated E2E stack: MESSENGER_TRANSPORT_DSN uses Redis ?dbindex=N (path is the stream name, not the DB index). compose.e2e.yaml uses env_file: !override and stops re-interpolating DATABASE_URL / REDIS_URL / MESSENGER_TRANSPORT_DSN / BEACON_DSN from the process environment (empty or dogfood-sourced shell vars were wiping .env.e2e.local). Make DC_E2E forces Redis DSNs on the process env. Spec 104 / REQ-MESSENGER-001.

Notes for integrators

  • No Doctrine migrations.
  • After pull: composer install.
  • Production: SiteBackup setup UI is off (setup.enabled: false); finish cold-start before flipping APP_ENV=prod, or use CLI/make ready. HttpLog no longer stores JSON response bodies in prod (less forensics, less PII). Ensure operators who need kit admin UIs under /admin have ROLE_ADMIN.
  • Local E2E: regenerate .env.e2e.local (make up-e2e / ensure-e2e-env) so Messenger DSNs pick up ?dbindex=.

Release v1.23.2

Choose a tag to compare

@github-actions github-actions released this 18 Aug 10:28

release: cut v1.23.2 (Rector 2.6.2 Symfony set constants)

Document the CI Quality fix: drop removed SymfonySetList::SYMFONY_81 and keep code-quality sets only.

Changelog

Fixed

  • CI Quality: Rector 2.6.2 removed SymfonySetList::SYMFONY_81. rector.php no longer references per-version Symfony set constants; keep SYMFONY_CODE_QUALITY + ANNOTATIONS_TO_ATTRIBUTES only (composer-based Symfony sets deferred — they would rewrite Autowire/eraseCredentials/Twig helpers). Spec 091.

Notes for integrators

  • No Doctrine migrations. No operator runtime steps beyond pulling v1.23.2.

Release v1.23.1

Choose a tag to compare

@github-actions github-actions released this 18 Aug 09:16

release: cut v1.23.1 (pin refresh + update-deps helper)

make update-deps now runs composer-update-helper --run so exact pins move;
bump hot-reload 1.4.0, FormKit 2.4.1, password kits, Mercure 0.5.0, and Symfony 8.1.4.

Changelog

Changed

  • make update-deps: runs nowo-tech/composer-update-helper generate-composer-require.sh --run (rewrites exact pins in composer.json) before composer update + pnpm update. Preview still: make composer-outdated. Exact pins never move on composer update alone.
  • Composer pins: Symfony 8.1.4 (console/form/framework/messenger/uid/validator/http-client/rate-limiter/redis-messenger/doctrine-messenger/translation + web-profiler); doctrine/orm 3.6.8; nelmio/api-doc-bundle 5.11.1; symfony/mercure-bundle 0.5.0 (host hubs stay protocol 0.x); FormKit 2.4.1; password-strength 2.2.0; password-toggle 2.1.1; nowo-tech/hot-reload-bundle 1.4.0 (nowo:hot-reload:check + profiler environment checks). Dev: php-cs-fixer 3.95.19, phpunit 13.3.1, rector 2.6.2. Frontend: @openai/codex-security ^0.1.14.

Notes for integrators

  • No Doctrine migrations. No production operator runtime steps.
  • After pull: composer install (and pnpm install if you rebuild assets). Dev: optional bin/console nowo:hot-reload:check after make up.

Release v1.23.0

Choose a tag to compare

@github-actions github-actions released this 17 Aug 21:26

release: cut v1.23.0 (kit polish + setup gate)

Ship hot-reload-bundle 1.3.2, drop the PWA install_links fork, close BP-004
audit gates, gate AuthKit until SiteBackup setup finishes, and the PhoneInput
theme bridge (Phase 6.56).

Changelog

Changed

  • Platform OTHER 100% close: BP-004 boundary script asserts SqlLikeEscaper + Project EXTRA_LAZY; ENGINEERING-AUDIT records hot-path query inventory (REV-003) and kit Twig fork inventory (REV-004); removed host fork templates/bundles/NowoPwaBundle/pwa/install_links.html.twig (vendor + SCSS BEM + Preferences hint). Matrix: Beacon column no remaining ⚠️/❌.
  • FrankenPHP hot reload client: nowo-tech/hot-reload-bundle 1.3.2 (Twig Extra runtime; Twig @NowoHotReloadBundle profiler panel, CSP nonce via _beacon_csp_nonce, csp_augment_script_src, WDT). Host config only sets the nonce attribute (bundle defaults for the rest). Removed host Vite/Twig Idiomorph client and always-on jsDelivr in debug CSP. See FRANKENPHP-HOT-RELOAD.md.
  • Setup gate: SiteBackup no longer excludes AuthKit /login//register (or localized twins). First admin is created in the wizard (admin_user) or via make ready / CLI — not a public register flow on an incomplete catalog (056 FR-014).
  • PhoneInput theme bridge: host _phone_input.scss remaps kit Bootstrap tokens to Beacon --color-* / data-theme (no Twig/JS fork). Rebuild assets after pull (make vite-build).

Notes for integrators

  • No Doctrine migrations.
  • After pull: composer install (pins nowo-tech/hot-reload-bundle 1.3.2, require-dev) and make vite-build (PhoneInput theme bridge).
  • Cold-start: finish /setup (or make ready) for the first admin. Existing instances with setup_completed_at are unchanged.