NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1728 most downloaded on Packagist
Symfony FOSUserBundle
Last release 7 months ago
13 Feb 2026
Ships unpredictably
gaps range from 9 days to 3.5 years
Nearly every release is documented
notes for 36 of 36 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
41 releases · first in 2011
Convert XML config files to other formats to fix the deprecation of XML config files in Symfony
UserInterface::eraseCredentials\FOS\UserBundle\Model\User::eraseCredentials[BC break] Removed the CouchDB ODM integration
@finalOne column per quarter.
Deprecated the TwigSwiftMailer implementation
Deprecated the CouchDB ODM integration as the ODM is unmaintained
Fixed remaining deprecations with Symfony 6.3
Fixed deprecations with Symfony 6.3
Added support for Symfony 6
Added support for Symfony 6
Fixed some deprecations when using Symfony 5.4.
Fixed the wiring of controllers to avoid a deprecation warning when using Twig.
[BC break] Change the base class of controllers to use the AbstractController (but extending the controllers is not officially supported anymore).
AbstractController (but extending the controllers is not officially supported anymore).Symfony\Contracts\EventDispatcher\Event instead of Symfony\Component\EventDispatcher\EventSymfony\Component\Security\Core\User\AdvancedUserInterface methods from our UserInterfaceisAccountNonLocked method of the AdvancedUserInterface. Projects customizing isAccountNonLocked for that purpose should instead register their own listener for the FOSUserEvents::RESETTING_RESET_REQUEST event to set a response instead of processing the request.\FOS\UserBundle\Model\User::serialize and \FOS\UserBundle\Model\User::unserialize final. Child classes needing to extend the serialization must override __serialize and __unserialize instead.\FOS\UserBundle\Event\GetResponseNullableUserEvent no longer inherits from \FOS\UserBundle\Event\GetResponseUserEvent and \FOS\UserBundle\Event\UserEvent as that was breaking variance rules.FOS\UserBundle\Model\User now have return types (in methods where Symfony 6 requires them)fos_user.mailer.twig_swift or a custom mailer service.FOS\UserBundle\Mailer\MailerInterfaceFixed a deprecation warning reported by DebugClassLoader in the AdvancedUserInterface BC layer due to the change done in 2.2.3.
Added missing deprecations on some group-related event classes
UserInterface being deprecated in static analyzers\FOS\UserBundle\Event\GetResponseNullableUserEvent::getUserFixed a deprecation warning about groups being triggered when loading all Doctrine metadata.
Fixed a deprecation warning about groups being triggered when loading the User class of the bundle.
Fixed several Symfony deprecation notices.
AdvancedUserInterface anymore.SessionInterface.Fixed compatibility of controllers with Symfony 2.8
Fixed the check for the required session, to account for the fact it is not always required.
Refactored controllers and commands to use DI. Projects extending these classes will need to adapt their code (but should rather use supported extensi
Fix empty password in ChangePasswordFormType.
Add SwiftMailer 6 compatibility.
user_checker into LoginManager.Removed default fos_user.from_email configuration values.
fos_user.from_email configuration values.UserManager::getRepository() instead of UserManager::$repository.UserManager::getClass() instead of UserManager::$class.Use ceil in ResettingController for a better token lifetime approximation.
ResettingController for a better token lifetime approximation.@-based Twig syntax for templates.DateUtil class.Fix UserPassword constraint validation groups.
UserManager.confirmation_token field.checkPostAuth by checkPreAuth in AuthenticationListener.ResettingController::getObfuscatedEmail has been removed.UserManager::refreshUser.UserManager::loadUserByUsername.UserManager::supportsClass.FOS\UserBundle\Model\User properties $locked, $expired, $expiredAt, $credentialsExpired, $credentialsExpiredAt and associated setter and getter (see here).Initializer constructor has changed.LoginManager constructor has changed.UserListener constructor has changed.UserManager constructor has changed.resetting.request.invalid_username has been removed.salt field of the User class is now nullable.Reverted the removed of the expired and credentialsExpired properties as the BC break could lead to corrupted objects being created if server sessions
expired and credentialsExpired properties as the BC break could lead to corrupted objects being created if server sessions are not cleared when upgrading the bundle.[BC break] The deprecated entity classes have been removed.
UserInterface::isUser has been removed as it was used only by the old validation logic removed a long time ago.FOSUserBundle:Security:login.html.twig template now receives an AuthenticationException in the error
variable rather than an error message.http://friendsofsymfony.github.io/schema/dic/userUserInterface::getId.expired and credentialsExpired including corresponding methods. This may break code,
which makes use of this methods, extending classes, and/or existing installations because of missing mappings for required db fields.Removed the deprecated UserManager and GroupManager classes for the different Doctrine implementations.
Fixed deprecated routing configuration
UserProvider::refreshUser()Fix compatibility with Symfony 2.7 #1777
This release fixes a security issue. You are encouraged to update as soon as possible.
This release fixes a security issue. You are encouraged to update as soon as possible.
BC break: The characters used in generated tokens have changed. They
now include dashes and underscores as well. Any routing requirement
matching them should be updated to [\w\-]+.
Fixed the compatibility with FrameworkBundle 2.5
This releases prevents a potential DOS attack. You are encouraged to update as soon as possible.
This releases prevents a potential DOS attack. You are encouraged to update as soon as possible.
Changed the flash message handling to use the non-deprecated api
Replaced the deprecated validation constraints by the new ones
Refactored the Propel implementation to get rid of the UserProxy
FOS\UserBundle\Model\GroupableInterface#getGroups to TraversableThis releases prevents a potential DOS attack. You are encouraged to update as soon as possible.
This releases prevents a potential DOS attack. You are encouraged to update as soon as possible.
This release fixes another security issue. Please update to it as soon as possible.
This release fixes another security issue. Please update to it as soon as possible.
Fixed the serialization of users to include the id
Fixed a bug in the previous fix
This release fixes a security issue. You are encouraged to update to it as soon as possible.
This release fixes a security issue. You are encouraged to update to it as soon as possible.
Prefixed fos table names in propel schema with "fos_" to avoid using reserved sql words
fos_user.user_to_username_transformer.Hide part of the email when requesting a password reset
Your coding agent can read these notes before it upgrades. Set up the MCP server →