Skip to content

3.33.0

Choose a tag to compare

@spryker-release-bot spryker-release-bot released this 11 Sep 11:31
· 4 commits to master since this release

Included commits: 3.32.0...3.33.0

Improvements

  • Introduced UserIdentityRequestSubscriber in the Glue layer, which resolves the user behind a Backend API access token and publishes it as Zed's current user, so Persistent ACL and ACL rule checks resolve the acting user on Backend API requests.
  • Restricted that lookup to active users: a token whose user is no longer active is answered 401, a token whose claims identify no user is not looked up, and one whose claims identify several users is refused.
  • Introduced UserDependencyProvider::getUserIdentityCriteriaExpanderPlugins(), the plugins that decide how a token's claims identify the user. The id_user claim is the default and applies only when no plugin identified the user.
  • Adjusted User to keep the current user in a process-local property where no session accepts the write, so the current-user API also works in applications that run without a session. A session, wherever one is present, stays the source of truth.
  • Introduced UserFacade::resetCurrentUser() to discard the current user wherever setCurrentUser() stored it. An entry point that relies on the process-local fallback must call it before establishing a new request's identity.
  • Introduced UserConfig::RESPONSE_CODE_USER_NOT_RESOLVED (003): a token whose user is not active, or whose claims identify no single user, is answered 401 with this code.
  • Raised spryker/user-extension to ^1.6.0 and added spryker/api-platform as a suggested dependency.