NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1455 most downloaded on Packagist
Set path based HTTP cache headers and send invalidation requests to your HTTP cache
Last release 4 months ago
08 Jun 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
81 releases · first in 2014
Fixed configuration validation to allow generate_url_type also when proxy_client.varnish.http.base_url is configured, not only when proxy_client.[clie
generate_url_type also when proxy_client.varnish.http.base_url is configured, not only when proxy_client.[client].base_url is configured.Configuring cache_manager.generate_url_type is deprecated and will be removed in version 4.
generate_url_type is now on top level instead of on the cache_manager, and applies to the InvalidationListener too.cache_manager.generate_url_type is deprecated and will be removed in version 4.One column per quarter.
Compatibility with Symfony 8 (changed configuration from XML to PHP).
If a custom proxy client is configured on the cache manager, the ProxyClient class is an alias to that client, to support autowiring.
ProxyClient class is an alias to that client, to support autowiring.__invoke method.proxy_client.*.http.request_factory and stream_factory to support custom PSR-17 HTTP request and stream factories for proxy clients.Fixed match_response configuration to work with Symfony 6+. #644
Fixed regression with the extension class when ttl_header is not set.
ttl_header is not set.New Feature: allow configuring the TTL header name for the special reverse_proxy_ttl config value. #638
reverse_proxy_ttl config value. #638cache_control.ttl_header to configure the TTL header name for the reverse_proxy_ttl cache control rule configuration. #638Fixed extension to depend on the DependencyInjection component rather than the HttpKernel.
Fixed regression in AttributesListener: Ignore other attributes on controller methods.
Removed deprecated FOS\HttpCacheBundle\UserContext\AnonymousRequestMatcher, use the class from the FOSHttpCache component instead: FOS\HttpCache\UserC…
fos_http_cache.tags.annotationsfastly and cloudflare clients lazy loaded to support Symfony secrets that are only available at runtime, but
not yet when the container is built.FOS\HttpCacheBundle\UserContext\AnonymousRequestMatcher, use the class from the FOSHttpCache
component instead: FOS\HttpCache\UserContext\AnonymousRequestMatcher.ContextInvalidationLogoutHandler, use ContextInvalidationSessionLogoutHandler instead.New configuration option proxy_client.*.http.request_factory to support custom HTTP request factories for proxy clients.
proxy_client.*.http.request_factory to support custom HTTP request factories for proxy clients.* Fix readthedocs build.
Support to configure the fastly CDN client.
Catch SessionNotFoundException in FlashMessageListener, as Symfony 6 moved from returning null to throwing an exception.
SessionNotFoundException in FlashMessageListener, as Symfony 6 moved from returning null to throwing an exception.: void to commands to avoid warning from Symfony 6.3, prepare for Symfony 7 support.Add : void return to compiler passes to avoid warning from Symfony 6.3, and prepare for Symfony 7 support.
: void return to compiler passes to avoid warning from Symfony 6.3, and prepare for Symfony 7 support.Added support for AWS cloudfront, using the jean-beru/fos-http-cache-cloudfront package.
jean-beru/fos-http-cache-cloudfront package.* Added Cloudflare proxy client.
Fix handling of custom glue for response tags. If you use custom glue with the Symfony HttpCache, you can now configure a customized tag header parser
PurgeTagsListener.Fix Symfony 6 deprecations on the command name configuration.
Fix some PHP 8.1 deprecation warnings.
Drop support for Symfony 3 and 4.3 (keep using 2.11.* for legacy projects).
2.11.* for legacy projects).Fixed servers_from_jsonenv to actually work with an array.
servers_from_jsonenv to actually work with an array.Fixed readthedocs.io configuration. This needs a release to show up as the latest doc (which had no longer been updated in quite a while because of bu
New configuration option servers_from_jsonenv to support a variable amount of proxy servers defined via an environment variable.
servers_from_jsonenv to support a variable amount of proxy servers defined via an environment variable.Do not error in InvalidationListener nor TagListener when symfony/expression-language is missing but no expression is used.
InvalidationListener nor TagListener when symfony/expression-language is missing but no expression is used.symfony/expression-language when an expression is used in response configuration.The fix about overwriting flash messages on multiple redirects introduced in version 2.9.1 created the risk of losing flash messages when redirecting
Fix typehint in PHP 8 attributes handling to use ControllerResolverInterface
Added support for PHP 8 Attributes
The fix about overwriting flash messages on multiple redirects introduced in version 2.9.1 created the risk of losing flash messages when redirecting
Flash messages won't be lost even when redirecting multiple times.
New Feature: Command fosclear to clear the whole http cache.
fos:httpcache:clear to clear the whole http cache.Adjusted to work with Symfony 5
Avoid deprecation warning about ContainerAwareCommand.
ContainerAwareCommand.Avoid deprecation warning about TokenInterface::getRoles.
TokenInterface::getRoles.Allow to use environment variables to configure the caching proxy.
Do not leak the Symfony-Session-NoAutoCacheControl header when the Symfony session system is not enabled.
Symfony-Session-NoAutoCacheControl header when the Symfony session system is not enabled.User context lookup now tags the hash lookup response. The logout listener can now invalidate that tag instead of doing a BAN request. The previous va
SensioFrameworkExtraBundle. There is a new configuration option
tags.annotations.enabled that can be set to false.Cache Tagging: Clear the SymfonyResponseTagger after we tagged a response. Usually PHP uses a new instance for every request. But for example the hash
New Feature: Support for the max_header_value_length option to split huge tag lists into multiple headers. #483
Adjust session_listener to work with Symfony 3.4.12 (https://github.com/symfony/symfony/pull/27467).
The old service names are still available, but using them directly is deprecated.
Support for the Varnish xkey vmod for more efficient cache tagging.
Autoconfigure support for custom context providers.
Autowiring support for the services in this bundle:
The old service names are still available, but using them directly is deprecated.
Regression in the configuration when you explicitly specified the default proxy client. This started to be reported as error in 2.3.0 and now works ag
default
proxy client. This started to be reported as error in 2.3.0 and now works
again.[Symfony HttpCache] You can now configure the Symfony proxy client to directly call the HttpCache for invalidation requests instead of executing real
HttpCache for invalidation requests instead of executing
real web requests.
Use the new configuration option proxy_client.symfony.use_kernel_dispatcher
and follow the instructions in FOSHttpCache to adjust your kernel and
bootstrap things accordingly.Fix session_listener decoration when session is not enabled.
session_listener decoration when session is not enabled.Adjust user context listener to handle Symfony 4.1 breaking behaviour change.
The ContextInvalidationLogoutHandler has been deprecated in favor of the ContextInvalidationSessionLogoutHandler. The original handler was called afte…
Support for Symfony 4. (Note that only the fos_http_cache.cache_manager
service is public in Symfony 4. Use dependency injection if you need direct
access to other services.)
You can now use cache tags and invalidate them with the Symfony HttpCache
reverse proxy. You can tweak configuration in the proxy_client.symfony
section of the configuration. See the FOSHttpCache documentation for
instructions on how to set up the cache.
Allow to configure the purge method for the Symfony proxy client.
You can now also match requests with regular expressions on the query string.
The new option match.query_string is available for cache control rules, tags
and invalidation.
ETags can now be false, strong or weak by setting headers.etag option to
"strong" or "weak" respectively.
Value true due to backward compatibility will be resolved as "strong".
The FlashMessageListener has been broken during refactoring for 2.0 and now works again. Constructor uses an options array.
Tag annotations now work with SensioFrameworkExtraBundle 4. An accidental exception prevents using them with FOSHttpCacheBundle 2.0 and 2.1.
User context is more reliable not cache when the hash mismatches. (E.g. after login/logout.)
The ContextInvalidationLogoutHandler has been deprecated in favor of the
ContextInvalidationSessionLogoutHandler. The original handler was called
after the invalidation of the session, and thus did not invalidate the session
it should have but a newly created one. You should remove the deprecated service
fos_http_cache.user_context.logout_handler from the logout.handlers section
of your firewall configuration.
User context compatibility which was broken due to Symfony making responses private if the session is started as of Symfony 3.4+.
$commandName constructor argument will be removed in 3.0.Nothing published for this version
Nothing published for this version
Nothing published for this version
Individual rules in the cache_control can now again have a match_response or additional_response_status configuration to limit the rule to certain res
Individual rules in the cache_control can now again have a match_response
or additional_response_status configuration to limit the rule to certain
responses.
For this, the signature of CacheControlListener::addRule had to be changed. It now expects a RuleMatcherInterface instead of the ResponseMatcherInterface. If you extended the listener or change the service configuration, this could be a BC BREAK for your application.
If no response matching is configured on cache_control, the global
cacheable configuration is now respected to decide whether cache headers
should be set. By default, this follows RFC 7234, only responses with status
200, 203, 204, 206, 300, 301, 404, 405, 410, 414 or 501 get cache headers.
We decided to consider this a bugfix, but if your relied on this behaviour it will be a BC BREAK for your application.
Deprecated methods have been removed.
http and servers must be a list - a comma separated
string of server IPs is no longer supported.UserContextListener constructor signature was changed to
take an array of options.XyzListener.BC break: The match_response and additional_cacheable_status
configuration parameters were removed for individual match rules.
Note that match_response and additional_response_status have been re-added for
cache_control in 2.0.1.
BC break: The second argument of the RuleMatcher constructor was changed
to take a ResponseMatcherInterface.
Cacheable status codes are now configured globally
(cacheable.response.additional_status or cacheable.response.expression).
fos_http_cache.handler.tag_handler no longer exists. For
tagging responses, use fos_http_cache.http.symfony_response_tagger instead,
and to invalidate tags use the service fos_http_cache.cache_manager.tags.header has been removed. Configuring
the header for tagging responses is now done at tags.response_header.
Configuring the header for tag invalidation requests is now done at
proxy_client.varnish.tags_header.fos_http_cache.test.client.varnish and
fos_http_cache.test.client.nginx no longer exist.always_vary_on_context_hash to make it possible to disable
automatically setting the vary headers for the user hash.Nothing published for this version
Nothing published for this version
Nothing published for this version
Adjust session_listener to work with Symfony 3.4.12 (https://github.com/symfony/symfony/pull/27467).
Fix session_listener decoration when session is not enabled.
User context compatibility which was broken due to Symfony making responses private if the session is started as of Symfony 3.4+.
Symfony HttpCache User Context: Move the AnonymousRequestMatcher to FOSHttpCache.
Symfony HttpCache User Context: Move the AnonymousRequestMatcher to FOSHttpCache.
The recommended way to ignore cookie based sessions is to set session_name_prefix to
false rather than omit the Cookie header from user_identifier_headers.
Prevent potential accidental caching on user context hash mismatch (particularly with symfony HttpCache).
* #395 : Compatibility with SensioFrameworkExtraBundle 4.
Your coding agent can read these notes before it upgrades. Set up the MCP server →