Repository navigation
3.33.0
·
4 commits
to master
since this release
Included commits: 3.32.0...3.33.0
Improvements
- Introduced
UserIdentityRequestSubscriberin the Glue layer, which resolves the user behind a Backend API access token and publishes it as Zed's current user, so Persistent ACL and ACL rule checks resolve the acting user on Backend API requests. - Restricted that lookup to active users: a token whose user is no longer active is answered
401, a token whose claims identify no user is not looked up, and one whose claims identify several users is refused. - Introduced
UserDependencyProvider::getUserIdentityCriteriaExpanderPlugins(), the plugins that decide how a token's claims identify the user. Theid_userclaim is the default and applies only when no plugin identified the user. - Adjusted
Userto keep the current user in a process-local property where no session accepts the write, so the current-user API also works in applications that run without a session. A session, wherever one is present, stays the source of truth. - Introduced
UserFacade::resetCurrentUser()to discard the current user whereversetCurrentUser()stored it. An entry point that relies on the process-local fallback must call it before establishing a new request's identity. - Introduced
UserConfig::RESPONSE_CODE_USER_NOT_RESOLVED(003): a token whose user is not active, or whose claims identify no single user, is answered401with this code. - Raised
spryker/user-extensionto^1.6.0and addedspryker/api-platformas a suggested dependency.