friendsofsymfony/user-bundle
Symfony FOSUserBundle
v4.1.0
37M downloads/mo
#1380 most downloaded on Packagist
FriendsOfSymfony/FOSUserBundle
What this package is like to depend on
Last release 6 months ago
13 Feb 2026
Ships unpredictably
gaps range from 9 days to 3.5 years
Nearly every release is documented
notes for 36 of 36 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
41 releases · first in 2011
1 release in the last 12 months
see the full history below
Release timeline
41 releases · Dec 2011 to Feb 2026Releases
latest 41-
v4.1.013 Feb 2026Release notes
Open source →- Convert XML config files to other formats to fix the deprecation of XML config files in Symfony
- Add PHP routing files alongside the XML ones. Loading the XML routing files triggers a deprecation in Symfony 7.4.
- Fix deprecation in the UserChecker
- Fix the HashingPasswordUpdater to avoid trigger deprecations for
UserInterface::eraseCredentials - Deprecate
\FOS\UserBundle\Model\User::eraseCredentials - Remove support for Symfony < 7.3
- Remove support for PHP < 8.2
Release notes
Open source →- Convert XML config files to other formats to fix the deprecation of XML config files in Symfony
- Add PHP routing files alongside the XML ones. Loading the XML routing files triggers a deprecation in Symfony 7.4.
- Fix deprecation in the UserChecker
- Fix the HashingPasswordUpdater to avoid trigger deprecations for
UserInterface::eraseCredentials - Deprecate
\FOS\UserBundle\Model\User::eraseCredentials - Remove support for Symfony < 7.3
- Remove support for PHP < 8.2
-
v4.0.004 Jul 2024Release notes
Open source →- [BC break] Removed the CouchDB ODM integration
- [BC break] Added return types in most methods
- [BC break] Marked classes as final when they were
@final - Removed support for symfony <6.4
- Removed support for PHP <8.1
- Remove the mailer implementation based on Swiftmailer
- Added support for Symfony 7
Release notes
Open source →- [BC break] Removed the CouchDB ODM integration
- [BC break] Added return types in most methods
- [BC break] Marked classes as final when they were
@final - Removed support for symfony <6.4
- Removed support for PHP <8.1
- Remove the mailer implementation based on Swiftmailer
- Added support for Symfony 7
-
v3.4.025 Jun 2024Release notes
Open source → -
v3.3.024 Jun 2024Release notes
Open source →- Added a mailer implementation based on symfony/mailer and Twig
- Added tentative return types in most methods
- Deprecated the CouchDB ODM integration as the ODM is unmaintained
Release notes
Open source →- Added a mailer implementation based on symfony/mailer and Twig
- Added tentative return types in most methods
- Deprecated the CouchDB ODM integration as the ODM is unmaintained
-
v3.2.106 Jul 2023 -
v3.2.006 Jul 2023Release notes
Open source →- Fixed deprecations with Symfony 6.3
- Fixed deprecations with Doctrine ORM (requires using DoctrineBundle 2.10.1 or newer for the fix to be effective)
- Fixed the way to access the session when enabling confirmation emails
- Fixed the way to access the firewall name when enabling the registration feature
Release notes
Open source →- Fixed deprecations with Symfony 6.3
- Fixed deprecations with Doctrine ORM (requires using DoctrineBundle 2.10.1 or newer for the fix to be effective)
- Fixed the way to access the session when enabling confirmation emails
- Fixed the way to access the firewall name when enabling the registration feature
-
v3.1.026 Oct 2022 -
v3.0.226 Oct 2022Release notes
Open source →- Fixed support for the remember-me in the programmatic login when using the new authentication system of Symfony.
- Fixed some deprecations when using Symfony 5.4.
Release notes
Open source →- Fixed support for the remember-me in the programmatic login when using the new authentication system of Symfony.
- Fixed some deprecations when using Symfony 5.4.
-
v3.0.127 Aug 2022Release notes
Open source →- Fixed the wiring of controllers to avoid a deprecation warning when using Twig.
Release notes
Open source →- Fixed the wiring of controllers to avoid a deprecation warning when using Twig.
-
v3.0.028 Apr 2022Release notes
Open source →- [BC break] Change the base class of controllers to use the
AbstractController(but extending the controllers is not officially supported anymore). - [BC break] Remove the group feature
- [BC break] Change the base class for events to
Symfony\Contracts\EventDispatcher\Eventinstead ofSymfony\Component\EventDispatcher\Event - [BC break] Remove the
Symfony\Component\Security\Core\User\AdvancedUserInterfacemethods from ourUserInterface - [BC break] The ResettingListener now longer blocks password resetting requests based on the
isAccountNonLockedmethod of theAdvancedUserInterface. Projects customizingisAccountNonLockedfor that purpose should instead register their own listener for theFOSUserEvents::RESETTING_RESET_REQUESTevent to set a response instead of processing the request. - [BC break] Made
\FOS\UserBundle\Model\User::serializeand\FOS\UserBundle\Model\User::unserializefinal. Child classes needing to extend the serialization must override__serializeand__unserializeinstead. - [BC break]
\FOS\UserBundle\Event\GetResponseNullableUserEventno longer inherits from\FOS\UserBundle\Event\GetResponseUserEventand\FOS\UserBundle\Event\UserEventas that was breaking variance rules. - [BC break] A few methods of
FOS\UserBundle\Model\Usernow have return types (in methods where Symfony 6 requires them) - [BC break] The legacy mailer based on SwiftMailer and symfony/templating is no longer used by default. Selecting a mailer service is now mandatory when using a feature needing the mailer.
- [BC break] Remove the legacy mailer based on SwiftMailer and symfony/templating. Use
fos_user.mailer.twig_swiftor a custom mailer service. - Add support for Symfony 5.
- Add return types in most methods.
- Add autowiring support for
FOS\UserBundle\Mailer\MailerInterface
Release notes
Open source →- [BC break] Change the base class of controllers to use the
AbstractController(but extending the controllers is not officially supported anymore). - [BC break] Remove the group feature
- [BC break] Change the base class for events to
Symfony\Contracts\EventDispatcher\Eventinstead ofSymfony\Component\EventDispatcher\Event - [BC break] Remove the
Symfony\Component\Security\Core\User\AdvancedUserInterfacemethods from ourUserInterface - [BC break] The ResettingListener now longer blocks password resetting requests based on the
isAccountNonLockedmethod of theAdvancedUserInterface. Projects customizingisAccountNonLockedfor that purpose should instead register their own listener for theFOSUserEvents::RESETTING_RESET_REQUESTevent to set a response instead of processing the request. - [BC break] Made
\FOS\UserBundle\Model\User::serializeand\FOS\UserBundle\Model\User::unserializefinal. Child classes needing to extend the serialization must override__serializeand__unserializeinstead. - [BC break]
\FOS\UserBundle\Event\GetResponseNullableUserEventno longer inherits from\FOS\UserBundle\Event\GetResponseUserEventand\FOS\UserBundle\Event\UserEventas that was breaking variance rules. - [BC break] A few methods of
FOS\UserBundle\Model\Usernow have return types (in methods where Symfony 6 requires them) - [BC break] The legacy mailer based on SwiftMailer and symfony/templating is no longer used by default. Selecting a mailer service is now mandatory when using a feature needing the mailer.
- [BC break] Remove the legacy mailer based on SwiftMailer and symfony/templating. Use
fos_user.mailer.twig_swiftor a custom mailer service. - Add support for Symfony 5.
- Add return types in most methods.
- Add autowiring support for
FOS\UserBundle\Mailer\MailerInterface
- [BC break] Change the base class of controllers to use the
-
v2.2.414 Jan 2022Release notes
Open source →- Fixed a deprecation warning reported by DebugClassLoader in the AdvancedUserInterface BC layer due to the change done in 2.2.3.
-
v2.2.314 Jan 2022Release notes
Open source →- Added missing deprecations on some group-related event classes
- Fixed an invalid report of
UserInterfacebeing deprecated in static analyzers - Fixed the documented return type for
\FOS\UserBundle\Event\GetResponseNullableUserEvent::getUser
-
v2.2.208 Sep 2021Release notes
Open source →- Fixed a deprecation warning about groups being triggered when loading all Doctrine metadata.
-
v2.2.108 Sep 2021Release notes
Open source →- Fixed a deprecation warning about groups being triggered when loading the User class of the bundle.
-
v2.2.026 Aug 2021Release notes
Open source →- Deprecated the Groups feature.
- Marked all controllers final.
- Marked internal classes as such.
- Added Mongolian translation.
- Added an email provider.
- Added a custom user checker.
- Added PHP 7.4 and PHP 8.0 support.
- Removed fieldName attribute in MongoDB mapping.
- Registration confirmation now redirects to login page if token is invalid.
- User model will not rely on
AdvancedUserInterfaceanymore. - Self-salting password encoders will not create a salt anymore.
- FlashListener constructor now accepts
SessionInterface. - Fixed several Symfony deprecation notices.
- Fixed several translations.
- Bumped the min PHP version to 7.1.3.
- Bumped the min Symfony version to 4.4.
- Added compatibility with Twig 3.
- Added compatibility with doctrine/persistence 2.
-
v2.1.208 Mar 2018 -
v2.1.120 Feb 2018Release notes
Open source →- Fixed the check for the required session, to account for the fact it is not always required.
-
v2.1.019 Feb 2018Release notes
Open source →- Dropped Symfony < 2.8 support.
- Add Symfony 4 compatibility.
- Refactored controllers and commands to use DI. Projects extending these classes will need to adapt their code (but should rather use supported extension points when possible).
- Redirect to login when requesting resetting password with invalid token.
- Added autocomplete hints for password inputs.
- Fixed several incorrect Turkish translations.
-
v2.0.229 Nov 2017Release notes
Open source →- Fix empty password in ChangePasswordFormType.
- Fix empty password in ProfileFormType.
- Introduced aliases for autowiring user and group managers.
- Added Bengali translation.
- Added Galician translation.
- Updated Danish translation.
- Updated Japanese translation.
-
v2.0.131 May 2017Release notes
Open source →- Add SwiftMailer 6 compatibility.
- Inject firewall
user_checkerintoLoginManager. - Updated English translation.
- Updated Estonian translation.
- Updated Persian translation.
- Updated Turkish translation.
- Updated several docs.
-
v2.0.029 Mar 2017Release notes
Open source →- Removed default
fos_user.from_emailconfiguration values. - Removed usage of internal Twig APIs when rendering emails.
- Add a timeout for the reset retry request.
- Add Esperanto translations.
- Fixed incorrect confirmation url.
- Commented outdated entries in several translation files.
- [BC break] Use
UserManager::getRepository()instead ofUserManager::$repository. - [BC break] Use
UserManager::getClass()instead ofUserManager::$class.
- Removed default
-
2.0.0-beta230 Jan 2017 pre-releaseRelease notes
Open source →- Use ceil in
ResettingControllerfor a better token lifetime approximation. - Removed unused translation keys.
- Removed form deprecations.
- Use
@-based Twig syntax for templates. - Improved several language files.
- Improved documentation.
- Ability to disable the authentication listener.
- Removed
DateUtilclass. - [BC break] Changed validation max length to match the database structure.
- Use ceil in
-
v2.0.0-beta129 Nov 2016 pre-releaseRelease notes
Open source →- Dropped Symfony < 2.7 support.
- Dropped PHP < 5.5 support.
- Exclude tests from autoloader.
- Allow to use POST for logout.
- Fix UserPassword constraint validation groups.
- Harmonized email detection in
UserManager. - Added unique index for
confirmation_tokenfield. - Added Kyrgyz translation files.
- Added user manipulator events.
- Replaced
checkPostAuthbycheckPreAuthinAuthenticationListener. - [BC break] Method
ResettingController::getObfuscatedEmailhas been removed. - [BC break] Renamed templates to underscore case.
- [BC break] Removed
UserManager::refreshUser. - [BC break] Removed
UserManager::loadUserByUsername. - [BC break] Removed
UserManager::supportsClass. - [BC break] Removed
FOS\UserBundle\Model\Userproperties$locked,$expired,$expiredAt,$credentialsExpired,$credentialsExpiredAtand associated setter and getter (see here). - [BC break] The signature of the
Initializerconstructor has changed. - [BC break] The signature of the
LoginManagerconstructor has changed. - [BC break] The signature of the
UserListenerconstructor has changed. - [BC break] The signature of the
UserManagerconstructor has changed. - [BC break] The translation key
resetting.request.invalid_usernamehas been removed. - [BC break] The propel dependency was dropped.
- [BC break] The
saltfield of theUserclass is now nullable.
-
v2.0.0-alpha315 Sep 2015 pre-releaseRelease notes
Open source →- Reverted the removed of the
expiredandcredentialsExpiredproperties as the BC break could lead to corrupted objects being created if server sessions are not cleared when upgrading the bundle.
- Reverted the removed of the
-
v2.0.0-alpha215 Sep 2015 pre-releaseRelease notes
Open source →- The minimum requirement for Doctrine is now ORM 2.4 and MongoDB ODM 1.0-alpha10.
- [BC break] The deprecated entity classes have been removed.
- The minimum requirement for Symfony has been bumped to 2.3 (older versions are already EOLed).
- [BC break]
UserInterface::isUserhas been removed as it was used only by the old validation logic removed a long time ago. - [BC break] The
FOSUserBundle:Security:login.html.twigtemplate now receives an AuthenticationException in theerrorvariable rather than an error message. - [BC break] The templating engine configuration has been removed, as well as the related code.
- [BC break] Changed the XML namespace to
http://friendsofsymfony.github.io/schema/dic/user - [BC break] Added
UserInterface::getId. - [BC break][Reverted] Removed unused properties
expiredandcredentialsExpiredincluding corresponding methods. This may break code, which makes use of this methods, extending classes, and/or existing installations because of missing mappings for required db fields.
-
v2.0.0-alpha126 Sep 2014 pre-releaseRelease notes
Open source →- Updated many translations.
- Changed the way to pass the email to the page asking to check the email to avoid issues with non-blocking sessions.
- Changed the fos_user_security_check route to enforce POST.
- Removed the deprecated UserManager and GroupManager classes for the different Doctrine implementations.
- [BC break] Refactored the structure of controller to dispatch events instead of using form handlers.
- Removed all form handlers.
- [BC break] Changed Datetime properties of default User entity that were nullable to default to null when no value supplied.
- [BC break] Updated schema.xml for Propel BaseUser class to allow nullable and typehint accordingly.
-
v1.3.712 Aug 2016Release notes
Open source →- Fixed some yaml errors in translation files
- Fixed bad credentials translations
- Fixed canonicalizer with illegal chars
- Fixed deprecated routing configuration
- Fixed class name check in
UserProvider::refreshUser() - Updated several translation files
- Removed colons from translation files
- Updated several documentation examples
- Converted documentation to rst format
-
v1.3.601 Jun 2015 -
v1.3.504 Sep 2014Release notes
Open source →This release fixes a security issue. You are encouraged to update as soon as possible.
BC break: The characters used in generated tokens have changed. They now include dashes and underscores as well. Any routing requirement matching them should be updated to
[\w\-]+.- Fixed the TokenGenerator to preserve entropy.
-
v1.3.413 Jun 2014Release notes
Open source →- Fixed the compatibility with FrameworkBundle 2.5
- Fixed a few issues in translations
- Enforce the POST method for the login_check route
-
v1.3.323 Sep 2013Release notes
Open source →This releases prevents a potential DOS attack. You are encouraged to update as soon as possible.
- Added a max length validation on the password
-
v1.3.225 May 2013Release notes
Open source →- Changed the flash message handling to use the non-deprecated api
- Updated the composer constraint to allow Symfony 2.3
-
v1.3.122 Dec 2012Release notes
Open source →- Replaced the deprecated validation constraints by the new ones
- Added an error message when the repeated password is invalid
- Updated many translations
- Made the composer requirement compatible with Symfony 2.2.*
- Fixed the handling of the target url after the registration
-
v1.3.005 Oct 2012Release notes
Open source →- Refactored the Propel implementation to get rid of the UserProxy
- Changed the expectation for
FOS\UserBundle\Model\GroupableInterface#getGroupstoTraversable - Moved the role constants to the UserInterface instead of the abstract User class
- Refactored the Doctrine implementations to use the same manager classes
- Removed the custom uniqueness validation in favor of the core constraints
- Added getRedirectionUrl method to ProfileController
- Added an extension point in the registration handler
- Moved the generation of the token to a dedicated class
- Added new user provider classes. They should be preferred over using the UserManager as UserProvider.
- Removed the custom password validation in favor of the Symfony 2.1 constraint
- Refactored the translation of form labels using the translation_domain option of Symfony 2.1
- Bumped the requirement to Symfony 2.1
-
v1.2.523 Sep 2013Release notes
Open source →This releases prevents a potential DOS attack. You are encouraged to update as soon as possible.
- Added a max length on the password field
- Fixed a Yaml parsing error in the Japanese translations
-
v1.2.410 Jul 2012Release notes
Open source →This release fixes another security issue. Please update to it as soon as possible.
- Fixes a security issue where the session could be hijacked
-
v1.2.310 Jul 2012 -
v1.2.210 Jul 2012 -
v1.2.110 Jul 2012Release notes
Open source →This release fixes a security issue. You are encouraged to update to it as soon as possible.
- Fixed the user refreshing to check the identity by primary key instead of username
-
1.2.011 Apr 2012Release notes
Open source →- Prefixed fos table names in propel schema with "fos_" to avoid using reserved sql words
- Added a fluent interface for the entities
- Added a mailer able to use twig blocks for the each part of the message
- Fixed the authentication in case of locked or disabled users. Github issue #464
- Add CSRF protection to the login form
- Added translations: bg, hr
- Updated translations
- Added translations for the validation errors and the login error
- Removed the user-level algorithm. Use FOSAdvancedEncoderBundle instead if you need such feature.
- Fixed resetting password clearing the token but not the token expiration. Github issue #501
- Renamed UsernameToUsernameTransformer to UserToUsernameTransformer and changed its service ID to
fos_user.user_to_username_transformer.
-
1.1.015 Dec 2011Release notes
Open source →- Added "custom" as valid driver
- Hide part of the email when requesting a password reset
- Changed the validation messages to translation keys
- Added the default validation group by default
- Fixed updating of changed fields in listener. Github issue #403
- Added support for Propel
- Added composer.json
- Made it possible to override the role constants in derived User class
- Updated translations: da, de, en, es, et, fr, hu, lb, nl, pl, pt_BR, pt_PT, ru
- Added translations: ca, cs, it, ja, ro, sk, sl, sv
- Changed the instanceof check for refreshUser to class instead of interface to allow multiple firewalls and correct use of UnsupportedUserException
- Added an extension point in the form handlers. Closes #291
- Rewrote the documentation entirely