Skip to content

1.1.2

Choose a tag to compare

@github-actions github-actions released this 15 Sep 14:25
· 3 commits to master since this release

πŸš€ UPC 1.1.2

Additive release exposing the OpenID Connect id_token on TokenOutput, so a consuming plugin can
identify who authorized a connection β€” not just which account the resulting token authorizes.
No breaking changes; a plugin that upgrades and changes nothing is unaffected.

✨ Added

  • πŸͺͺ TokenOutput::$idToken β€” the id_token returned by an authorization-code exchange, the only
    place a logged-in person's identity surfaces. GET /account carries no email (its payload is
    id, company_ref, country, object, is_live, configuration, permissions,
    payment_methods and nothing else, verified live against several QA accounts), and the
    client_credentials token authenticates a machine, so it names no user either. A consumer wanting
    the merchant's address has to read the email claim off this token at login time.
  • πŸ”“ OAuth2Client::requestToken() passes id_token through when the token-endpoint response
    carries one, instead of discarding it while constructing the TokenOutput.

♻️ Changed

  • Nothing behavioural. idToken is a trailing 4th constructor argument defaulting to null, and
    a purely additive public property β€” every pre-existing 3-argument caller and every read of
    accessToken / expiresIn / tokenType is untouched.
  • idToken is deliberately optional and unvalidated: requestToken() is shared by
    exchangeAuthorizationCode() and getClientCredentialsToken(), and only the former can ever
    produce an id_token, so asserting on it would reject a perfectly usable client-credentials
    response. UPC does not parse the JWT β€” consumers decode whichever claim they need.

πŸ” Compatibility

Upgrading from 1.1.x with no plugin-side change is a no-op:

  • TokenOutput is final, so nothing can have subclassed it with a 3-argument constructor.
  • The new read is isset($data['id_token']) && \is_string(...) β€” it cannot throw and adds no failure
    path.
  • No cache invalidation needed. TokenManager caches only the bare access-token string, never
    the object, so the token-cache format is unchanged. Nothing in UPC serializes, json_encodes or
    get_object_vars() a TokenOutput.
  • idToken is non-null only when a caller uses exchangeAuthorizationCode() and passes a scope
    containing openid/email; the client_credentials grant always yields null.

⚠️ One passive behaviour change worth knowing: a consumer that dumps a whole TokenOutput for
debugging (print_r, var_dump, json_encode, or a logger that serializes context objects) will now
see an id_token in that output where nothing appeared before β€” and an id_token is a JWT carrying PII
(email, sub). No current consumer does this, and it affects only the authorization-code path.

βœ… Quality

PHPStan level 8, PHP-CS-Fixer, PHPUnit, and CI verifying PHP 7.1–8.2 compatibility β€” all clean on this
release branch. Six unit tests added: three on the value object (assignment, the null default, and
one asserting the constructor explicitly does not validate idToken) and three on OAuth2Client
(surfaced from an authorization-code response, left null when absent, left null for
client_credentials). The last two guard the optionality β€” they fail the day someone makes id_token
required in the shared requestToken(). make verify-71 passes; the new nullable type hint is 7.1
syntax.

πŸ“¦ Consumers

  • Sylius plugin PRE-3631 pins ^1.1.2 β€” it displays the connected PayPlug account's email on the
    gateway-configuration admin screen, which is impossible on 1.1.0/1.1.1.

πŸ“‹ Requirements

  • PHP β‰₯7.4 to install/develop (build-tooling floor only β€” shipped source runs on PHP 7.1)
  • Runtime dependency: giggsey/libphonenumber-for-php

πŸ”— Full Changelog: 1.1.1...1.1.2