NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #787 most downloaded on Packagist
This Bundle provides various tools to rapidly develop RESTful API's with Symfony
Last release 8 months ago
10 Feb 2026
Release timing varies
gaps range from 8 days to 1.1 years
Some releases are documented
notes for 35 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
99 releases · first in 2012
Don't use deprecated #[Route] methods by @HypeMC in #2422
#[Route] methods by @HypeMC in #2422Full Changelog: 3.8.0...3.9.0
One column per quarter.
Allow usage with symfony/config v8 by @W0rma in #2429
Full Changelog: 3.9.0-beta1...3.9.0-beta2
Don't use deprecated #[Route] methods by @HypeMC in #2422
#[Route] methods by @HypeMC in #2422Full Changelog: 3.8.0...3.9.0-beta1
Update route requirements docblock by @vracini in #2411
fix: Sensio extra bundle TemplateListener invocation before view response listener and serialization by @flohw in #2410
Full Changelog: 3.7.0...3.7.1
Conditionally stop extending from the SensioFrameworkExtraBundle's Template annotation class by @mbabker in #2401
Full Changelog: 3.6.0...3.7.0
bad url link readme.md by @asuri0n in #2382
Full Changelog: 3.5.0...3.6.0
Fixed SF 6.1 and SF 6.2 deprecations by @thomaspicquet in #2377
Full Changelog: 3.4.0...3.5.0
Allow jms serializer bundle 5.0 by @goetas in #2373
Allow new version of willdurand/jsonp-callback-validator by @mbabker in #2360
Full Changelog: 3.2.1...3.3.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fixed being able to configure exception codes and messages based on interfaces (e.g. Throwable)
Throwable)fixed the ViewHandler to not override an already set status_code in the serialization context
ViewHandler to not override an already set status_code in the serialization contextfixed handling requests without a content type inside the RequestBodyParamConverter
RequestBodyParamConverterFlattenExceptionNormalizer does no longer implement the CacheableSupportsMethodInterface to
ensure compatibility with older versions of the Symfony Serializer componentadded support for Symfony 5 compatibility
the route generation feature was removed, setting it to another value than false leads to an
exception
support for serializing exceptions was removed, setting the fos_rest.exception.serialize_exceptions
option to anything else than false leads to an exception
support for returning anything other than string or null from resolve() when implementing
the VersionResolverInterface was removed
removed support for passing version numbers as integers to Context::setVersion()
removed the isFormatTemplating(), renderTemplate(), and prepareTemplateParameters() methods
from the ViewHandler class and the ViewHandlerInterface
the constructor of the ViewHandler class is private now, use the static create() factory
method instead
removed the setTemplateVar(), setPopulateDefaultVars(), getTemplateVar(), and
isPopulateDefaultVars() methods from the Controller\Annotations\View class
removed the setEngine(), setTemplate(), setTemplateData(), setTemplateVar(), getEngine(),
getTemplate(), getTemplateData(), and getTemplateVar() methods from the View\View class
changed the default value of the fos_rest.body_listener option to false
removed the setMaxDepth()/getMaxDepth() methods from the Context class, use
enableMaxDepth()/disableMaxDepth() instead
dropped support for Symfony components < 4.4
removed the following options:
fos_rest.access_denied_listenerfos_rest.exception.exception_controllerfos_rest.exception.exception_listenerfos_rest.exception.servicefos_rest.service.inflectorfos_rest.service.routerfos_rest.service.templatingfos_rest.view.default_enginefos_rest.view.force_redirectsfos_rest.view.templating_formatsremoved the following classes and interfaces:
FOS\RestBundle\Controller\Annotations\NamePrefixFOS\RestBundle\Controller\Annotations\NoRouteFOS\RestBundle\Controller\Annotations\PrefixFOS\RestBundle\Controller\Annotations\RouteResourceFOS\RestBundle\Controller\Annotations\VersionFOS\RestBundle\Controller\ExceptionControllerFOS\RestBundle\Controller\TemplatingExceptionControllerFOS\RestBundle\Controller\TwigExceptionControllerFOS\RestBundle\EventListener\AccessDeniedListenerFOS\RestBundle\EventListener\ExceptionListenerFOS\RestBundle\Inflector\DoctrineInflectorFOS\RestBundle\Inflector\InflectorInterfaceFOS\RestBundle\Routing\Loader\DirectoryRouteLoaderFOS\RestBundle\Routing\Loader\Reader\RestActionReaderFOS\RestBundle\Routing\Loader\Reader\RestControllerReaderFOS\RestBundle\Routing\Loader\RestRouteLoaderFOS\RestBundle\Routing\Loader\RestRouteProcessorFOS\RestBundle\Routing\Loader\RestXmlCollectionLoaderFOS\RestBundle\Routing\Loader\RestYamlCollectionLoaderFOS\RestBundle\Routing\ClassResourceInterfaceFOS\RestBundle\Routing\RestRouteCollectionFOS\RestBundle\Serializer\Normalizer\ExceptionHandlerFOS\RestBundle\Serializer\Normalizer\ExceptionNormalizerremoved the following services and aliases:
fos_rest.access_denied_listenerfos_rest.exception_listenerfos_rest.exception.controllerfos_rest.exception.twig_controllerfos_rest.inflectorfos_rest.routerfos_rest.routing.loader.controllerfos_rest.routing.loader.directoryfos_rest.routing.loader.processorfos_rest.routing.loader.reader.controllerfos_rest.routing.loader.reader.actionfos_rest.routing.loader.xml_collectionfos_rest.routing.loader.yaml_collectionfos_rest.serializer.exception_normalizer.jmsfos_rest.serializer.exception_normalizer.symfonyfos_rest.templatingthe following classes are marked as internal (backwards compatibility will no longer be guaranteed):
FOS\RestBundle\DependencyInjection\Compiler\HandlerRegistryDecorationPassFOS\RestBundle\DependencyInjection\FOSRestExtensionFOS\RestBundle\Form\Extension\DisableCSRFExtensionFOS\RestBundle\Form\Transformer\EntityToIdObjectTransformerFOS\RestBundle\Normalizer\CamelKeysNormalizerFOS\RestBundle\Normalizer\CamelKeysNormalizerWithLeadingUnderscoreFOS\RestBundle\Serializer\Normalizer\FormErrorHandlerFOS\RestBundle\Serializer\Normalizer\FormErrorNormalizerFOS\RestBundle\Util\ExceptionValueMapthe following classes are now final:
FOS\RestBundle\Decoder\ContainerDecoderProviderFOS\RestBundle\Decoder\JsonDecoderFOS\RestBundle\Decoder\JsonToFormDecoderFOS\RestBundle\Decoder\XmlDecoderFOS\RestBundle\Form\Transformer\EntityToIdObjectTransformerFOS\RestBundle\Negotiation\FormatNegotiatorFOS\RestBundle\Request\ParamFetcherFOS\RestBundle\Request\ParamReaderFOS\RestBundle\Request\RequestBodyParamConverterFOS\RestBundle\Response\AllowMethodsLoader\AllowedMethodsRouterLoaderFOS\RestBundle\Serializer\JMSSerializerAdapterFOS\RestBundle\Serializer\SymfonySerializerAdapterFOS\RestBundle\Version\ChainVersionResolverFOS\RestBundle\Version\Resolver\HeaderVersionResolverFOS\RestBundle\Version\Resolver\MediaTypeVersionResolverFOS\RestBundle\Version\Resolver\QueryParameterVersionResolverFOS\RestBundle\View\JsonpHandlerFOS\RestBundle\View\ViewFOS\RestBundle\View\ViewHandlerNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fixed being able to configure exception codes and messages based on interfaces (e.g. Throwable)
Throwable)fixed the ViewHandler to not override an already set status_code in the serialization context
ViewHandler to not override an already set status_code in the serialization contextfixed handling requests without a content type inside the RequestBodyParamConverter
RequestBodyParamConverterFlattenExceptionNormalizer does no longer implement the CacheableSupportsMethodInterface to
ensure compatibility with older versions of the Symfony Serializer componentthe route generation feature is deprecated, disable it explicitly:
added a SerializerErrorHandler that leverages the FOS\RestBundle\Serializer\Serializer interface
to hook into the error rendering process provided by the ErrorHandler component since Symfony 4.4
added a new normalizer (for the Symfony serializer) and a new handler (for the JMS serializer) to
serialize FlattenException instances, for backwards compatibility the resulting format by default
is the same as was used for exceptions/errors before, use the flatten_exception_format to opt-in
to a format compatible with the API Problem spec (RFC 7807):
fos_rest:
exception:
flatten_exception_format: 'rfc7807'
added a new ResponseStatusCodeListener that maps exception/error codes to response status codes,
enable it by setting the new map_exception_codes option to true
the route generation feature is deprecated, disable it explicitly:
fos_rest:
routing_loader: false
You need to configure your routes explicitly, e.g. using the Symfony Core annotations or the FOSRestBundle
shortcuts like FOS\RestBundle\Controller\Annotations\Get. You can use
bin/console debug:router --show-controllers to help with the migration and compare routes before and after it.
Change the routing loading:
Before:
Acme\Controller\TestController:
type: rest
resource: Acme\Controller\TestController
After:
Acme\Controller\TestController:
type: annotation
resource: Acme\Controller\TestController
When using the Symfony Core route loading, route names might change as the FOSRestBundle used a different naming
convention. Mind the .{_format} suffix if you used the fos_rest.routing_loader.include_format option.
In case you have OpenAPI/Swagger annotations, you can also use OpenAPI-Symfony-Routing
which removes the need to have routing information duplicated. It also allows to add the .{_format} suffix automatically as before.
If migration to explicit routes is not possible or feasible, consider using RestRoutingBundle which extracted the auto-generation of routes in a BC way.
deprecated support for serializing exceptions, disable it by setting the serialize_exceptions
option to false:
fos_rest:
exception:
serialize_exceptions: false
deprecated returning anything other than string or null from resolve() when implementing the VersionResolverInterface.
deprecated support for passing version numbers as integers to Context::setVersion() (strings
will be enforced as of 3.0)
deprecated the isFormatTemplating(), renderTemplate(), and prepareTemplateParameters()
methods of the ViewHandler class and the ViewHandlerInterface
deprecated the constructor of the ViewHandler class, use the static create() factory method
instead
deprecated the setTemplateVar(), setPopulateDefaultVars(), getTemplateVar(), and
isPopulateDefaultVars() methods of the Controller\Annotations\View class
deprecated the setEngine(), setTemplate(), setTemplateData(), setTemplateVar(), getEngine(),
getTemplate(), getTemplateData(), and getTemplateVar() methods of the View\View class
deprecated not enabling the fos_rest.body_listener option explicitly, it will be disabled by default
in 3.0
deprecated the following options:
fos_rest.access_denied_listenerfos_rest.exception.exception_controllerfos_rest.exception.exception_listenerfos_rest.exception.servicefos_rest.service.inflectorfos_rest.service.routerfos_rest.service.templatingfos_rest.view.default_enginefos_rest.view.force_redirectsfos_rest.view.templating_formatsthe following classes and interfaces are marked as deprecated, they will be removed in 3.0:
FOS\RestBundle\Controller\Annotations\NamePrefixFOS\RestBundle\Controller\Annotations\NoRouteFOS\RestBundle\Controller\Annotations\PrefixFOS\RestBundle\Controller\Annotations\RouteResourceFOS\RestBundle\Controller\Annotations\VersionFOS\RestBundle\Controller\ExceptionControllerFOS\RestBundle\Controller\TemplatingExceptionControllerFOS\RestBundle\Controller\TwigExceptionControllerFOS\RestBundle\EventListener\AccessDeniedListenerFOS\RestBundle\EventListener\ExceptionListenerFOS\RestBundle\Inflector\DoctrineInflectorFOS\RestBundle\Inflector\InflectorInterfaceFOS\RestBundle\Routing\Loader\DirectoryRouteLoaderFOS\RestBundle\Routing\Loader\Reader\RestActionReaderFOS\RestBundle\Routing\Loader\Reader\RestControllerReaderFOS\RestBundle\Routing\Loader\RestRouteLoaderFOS\RestBundle\Routing\Loader\RestRouteProcessorFOS\RestBundle\Routing\Loader\RestXmlCollectionLoaderFOS\RestBundle\Routing\Loader\RestYamlCollectionLoaderFOS\RestBundle\Routing\ClassResourceInterfaceFOS\RestBundle\Routing\RestRouteCollectionFOS\RestBundle\Serializer\Normalizer\ExceptionHandlerFOS\RestBundle\Serializer\Normalizer\ExceptionNormalizerthe following services and aliases are marked as deprecated, they will be removed in 3.0:
fos_rest.access_denied_listenerfos_rest.exception_listenerfos_rest.exception.controllerfos_rest.exception.twig_controllerfos_rest.inflectorfos_rest.routerfos_rest.routing.loader.controllerfos_rest.routing.loader.directoryfos_rest.routing.loader.processorfos_rest.routing.loader.reader.controllerfos_rest.routing.loader.reader.actionfos_rest.routing.loader.xml_collectionfos_rest.routing.loader.yaml_collectionfos_rest.serializer.exception_normalizer.jmsfos_rest.serializer.exception_normalizer.symfonyfos_rest.templatingthe following classes are marked as internal (backwards compatibility will no longer be guaranteed
starting with FOSRestBundle 3.0):
FOS\RestBundle\DependencyInjection\Compiler\HandlerRegistryDecorationPassFOS\RestBundle\DependencyInjection\FOSRestExtensionFOS\RestBundle\Form\Extension\DisableCSRFExtensionFOS\RestBundle\Form\Transformer\EntityToIdObjectTransformerFOS\RestBundle\Normalizer\CamelKeysNormalizerFOS\RestBundle\Normalizer\CamelKeysNormalizerWithLeadingUnderscoreFOS\RestBundle\Serializer\Normalizer\FormErrorHandlerFOS\RestBundle\Serializer\Normalizer\FormErrorNormalizerFOS\RestBundle\Util\ExceptionValueMapthe following classes are marked as final (extending them will not be supported as of 3.0):
FOS\RestBundle\Decoder\ContainerDecoderProviderFOS\RestBundle\Decoder\JsonDecoderFOS\RestBundle\Decoder\JsonToFormDecoderFOS\RestBundle\Decoder\XmlDecoderFOS\RestBundle\Form\Transformer\EntityToIdObjectTransformerFOS\RestBundle\Negotiation\FormatNegotiatorFOS\RestBundle\Request\ParamFetcherFOS\RestBundle\Request\ParamReaderFOS\RestBundle\Request\RequestBodyParamConverterFOS\RestBundle\Response\AllowMethodsLoader\AllowedMethodsRouterLoaderFOS\RestBundle\Serializer\JMSSerializerAdapterFOS\RestBundle\Serializer\SymfonySerializerAdapterFOS\RestBundle\Version\ChainVersionResolverFOS\RestBundle\Version\Resolver\HeaderVersionResolverFOS\RestBundle\Version\Resolver\MediaTypeVersionResolverFOS\RestBundle\Version\Resolver\QueryParameterVersionResolverFOS\RestBundle\View\JsonpHandlerFOS\RestBundle\View\ViewFOS\RestBundle\View\ViewHandlerNothing published for this version
Nothing published for this version
Nothing published for this version
fixed compatibility with JMS Serializer with explicitly disabled max depth checks
Throwable instances of classes
that do not extend PHP's Exception class (#2131)harden the JsonToFormDecoder to not error on non-array input
JsonToFormDecoder to not error on non-array input (#2145)fixed serializing Error instances when the Symfony Serializer is used
null owner returned by SensioFrameworkExtraBundle (#2097)Throwable objects in ExceptionController::showAction(),
continues #2093 (#2096)fixed handling all Throwable objects in ExceptionController::showAction()
Throwable objects in ExceptionController::showAction() (#2093)ViewHandlerInterface alias definition (#2085)fixed ExceptionListener deprecation warning
SessionInterface and UserInterface controller action argumentsExceptionListener deprecation warningControllerNameParser deprecation warningDisableCSRFExtension::getExtendedTypes() return typeEngineInterface error message in ViewHandlerdeprecated using the ParamFetcher class without passing a validator as the third argument, this argument will become mandatory in 3.0
FlattenException from the new ErrorRenderer componentserialize_null option with the Symfony serializerrequirements option of the @RequestParam
annotationParamFetcher class without passing a validator as the third argument, this
argument will become mandatory in 3.0deprecated the FOSRestController base class, use the new AbstractFOSRestController instead
FOSRestController base class, use the new AbstractFOSRestController insteadnullable option of the param annotations when the map option is enabled[BC BREAK] The @Route annotation and all its children no longer extend SensioFrameworkExtraBundle's annotation. The main effect is that @Route::$servi
@Route annotation and all its children no longer extend SensioFrameworkExtraBundle's annotation.
The main effect is that @Route::$service is no longer available. Instead, define your controllers using the FQCN
as service IDs or create an alias in the container using the FQCN.improved Symfony 4 compatibility
improved Symfony 4 compatibility
manually decorate the core JMS handler registry
run checks after SensioFrameworkExtraBundle
made the view handler alias public
check for definitions before they might be removed
added Yaml routing resource support
refactored several unit tests
added support for file paths to the directory route loader
added support for file paths to the directory route loader
added support for context factories when using JMS Serializer
the RequestBodyParamConverter ignores unrelated controller arguments to not conflict with Symfony's built-in
argument resolver
made the bundle compatible with SensioFrameworkExtraBundle 4.x
added some interface aliases to support by ID autowiring
added support for custom keys for groups when using JMSSerializerBundle
allow to load FOSRestBundle inside the kernel before JMSSerializerBundle
added the fos_rest.routing_loader.prefix_methods option to disable method name prefixes in generated route names
removed newline characters from exception messages
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
deprecated the FOS\RestBundle\Util\ViolationFormatter class and the FOS\RestBundle\Util\ViolationFormatterInterface
added a new InvalidParameterException as a specialization of the BadRequestHttpException
deprecated the FOS\RestBundle\Util\ViolationFormatter class and the
FOS\RestBundle\Util\ViolationFormatterInterface
deprecated the ViolationFormatterInterface argument of the ParamFetcher class constructor
deprecated the RedirectView and RouteRedirectView classes, use View::createRedirect() and
View::createRouteRedirect() instead
added a fos_rest.exception.debug config option that defaults to the kernel.debug container
parameter and can be turned on to include the caught exception message in the exception controller's
response
introduced the concept of REST zones which makes it possible to disable all REST listeners when a request matches certain attributes
fixed that serialization groups are always passed to the constructor as an array
added annotations to support additional HTTP methods defined by RFC 2518 (WebDAV)
added a new loader that allows to extract REST routes from all controller classes from a directory
introduced a serializer adapter layer to ease the integration of custom serialization implementations
deprecated the getter methods of the ViewHandler class
fixed an issue that prevented decoration of the TemplateReferenceInterface from the Symfony
Templating component
fixed: no longer overwrite an explicitly configured template in the view response listener
added support for API versioning in URL parameters, the Accept header or using a custom header
marked some classes and methods as internal, do no longer use them in your code as they are likely to be removed in future releases
deprecated the DoctrineInflector class and the InflectorInterface from the
FOS\RestBundle\Util\Inflectorin favor of their replacements in the FOS\RestBundle\Inflector
namespace
deprecated the FormatNegotiator class and the FormatNegotiatorInterface from the
FOS\RestBundle\Util namespace in favor of the new FOS\RestBundle\Negotiation\FormatNegotiator
class
deprecated the FOS\RestBundle\Util\MediaTypeNegotiatorInterface which should no longer be used
Nothing published for this version
Nothing published for this version
handle \Throwable instances in the ExceptionController
handle \Throwable instances in the ExceptionController
fixed that the default exclusion strategy groups for the serializer are not the empty string
fixed a BC break that prevented the CamelKeysNormalizer from removing leading underscores
fixed the AllowedMethodsRouteLoader to work with Symfony 3.0
removed uses of the reflection API in favor of faster solutions when possible
removed uses of the reflection API in favor of faster solutions when possible
fixed the configuration to use serialization groups and versions at the same time
when using Symfony 3.x, the bundle doesn't call methods anymore that have been deprecated in Symfony 2.x and were removed in Symfony 3.0
when using Symfony 3.x, the bundle doesn't call methods anymore that have been deprecated in Symfony 2.x and were removed in Symfony 3.0
the ViewResponseListener does not overwrite explicitly configured templates anymore
fixed the ParamFetcher class to properly handle sub requests
added a CamelKeysNormalizerWithLeadingUnderscore that keeps leading underscores when converting snake case to camel case (for example, leaving _userna
CamelKeysNormalizerWithLeadingUnderscore that keeps leading underscores when
converting snake case to camel case (for example, leaving _username unchanged)removed some code from the ViewResponseListener class that was already present in the parent TemplateListener class
ViewResponseListener class that was already present in the parent
TemplateListener classYour coding agent can read these notes before it upgrades. Set up the MCP server →