NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3592 most downloaded on Packagist
Authentication and Authorization for CodeIgniter 4
Last release 1 months ago
18 Aug 2026
Release timing varies
gaps range from 4 weeks to 13 months
Nearly every release is documented
notes for 9 of 9 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
17 releases · first in 2022
One column per quarter.
fix: PwnedValidator cannot reach the HIBP API by @michalsn in #1372
fix: require login actions for magic links by @memleakd in #1329
loginView() by @tomatlscomm in #1306only option for authentication routes configuration by @dimtrovich in #1323Full Changelog: v1.3.0...v1.4.0
JWT: Minimum Key Length Now Enforced
If you are using the JWT authenticator with an HMAC algorithm (HS256, HS384, HS512), note that the underlying firebase/php-jwt library was upgraded to v7, which now enforces minimum key lengths at runtime. If your secret is too short, every JWT encode and decode call will throw: LogicException: Cannot encode/decode JWT: Provided key is too short.
How to fix it? Generate a new key:
php -r 'echo base64_encode(random_bytes(32));' # HS256
php -r 'echo base64_encode(random_bytes(48));' # HS384
php -r 'echo base64_encode(random_bytes(64));' # HS512Then update your configuration:
// app/Config/AuthJWT.php
'secret' => '<output of the command above>',Warning
Existing tokens signed with the old (short) secret will become invalid after updating.
Users will need to re-authenticate to obtain new tokens.
withPermissions() for users without permissions by @michalsn in #1290Full Changelog: v1.2.0...v1.3.0
fix: escape string to prevent XSS attack by @warcooft in #1148
lang('Auth.invalidEmail') by @kenjis in #1159chain filter does not update last_active by @kenjis in #1160AuthToken::$authenticatorHeader config by @alxjzx100 in #1169emailer() function by @FrancoisChaumont in #1174shield:user create does not assign a default group by @kenjis in #1162shield:user addgroup/removegroup by @kenjis in #1176invalidEmail by @kenjis in #1175invalidEmail to return user email. by @warcooft in #1145shield:user create by @kenjis in #1164UserModel::createNewUser() and RegisterController uses it by @kenjis in #1196invalidEmail by @kenjis in #1158Full Changelog: v1.1.0...v1.2.0
fix: setup command cannot update Config\Autoload::$helpers with multiple lines by @kenjis in #1110
Config\Autoload::$helpers with multiple lines by @kenjis in #1110Full Changelog: v1.0.3...v1.1.0
fix: Can't create new users via CLI if username is disabled by @kenjis in #1078
Full Changelog: v1.0.2...v1.0.3
fix: JWT::loggedIn() does not remove Bearer prefix by @kenjis in #1040
JWT::loggedIn() does not remove Bearer prefix by @kenjis in #1040'Y-m-d H:i:s' by @kenjis in #1027Full Changelog: v1.0.1...v1.0.2
fix: Shield may not send correct HTML mail by @kenjis in #1020
Full Changelog: v1.0.0...v1.0.1
This has breaking changes. See Upgrade Guide .
Full Changelog: v1.0.0-beta.8...v1.0.0
This has breaking changes. See Upgrade Guide .
errorPasswordPwned by @datamweb in #954/> with > for input tags by @kenjis in #894$hashCost to 12 by @datamweb in #916Full Changelog: v1.0.0-beta.7...v1.0.0-beta.8
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →