NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1470 most downloaded on Packagist
Support for authenticating users using both OAuth1.0a and OAuth2 in Symfony.
Last release 7 months ago
19 Feb 2026
Release timing varies
gaps range from 2 weeks to 1.6 years
Nearly every release is documented
notes for 49 of 49 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
54 releases · first in 2012
Added: Support for Symfony 8.0,
firebase/php-jwt support to 7.0,Added: LinkedIn OpenID resource owner,
show_dialog option to Spotify resource owner,One column per quarter.
BC Break: Dropped support for Symfony: 6.3 and 7.0 ,
6.3 and 7.0,Amazon Cognito resource owner,failure_path in AuthenticationFailureHandler when connect functionality is not enabled,failure_handler in security configuration if set,AuthenticatorInterface instead of OAuthAuthenticator in RefreshAccessTokenListener,OdnoklassnikiResourceOwner,Add Telegram resource owner by @zorn-v in #1966
null as $registrationForm in RegisterController by @stloyd in #1983AuthenticationFailureHandler by @stloyd in #1986Full Changelog: 2.1.0...2.2.0
use_authorization_to_get_token to be configured to false for generic OAuth2,null as $registrationForm in RegisterController,Add resource owner Passage by @malteschlueter in #1962
For details go and read the CHANGELOG file.
>6.0, <6.3,Remove direct deprecations reported on Symfony 6 by @stloyd in #1946
The main changes:
FOSUserBundle,For details go and read the CHANGELOG file.
Full Changelog: 2.0.0-BETA3...2.0.0
Deprecated: method UserResponseInterface::getUsername() was deprecated in favour of UserResponseInterface::getUserIdentifier() to match changes in Sym…
Templating\Helper\OAuthHelper was merged into Twig\Extension\OAuthRuntime,TYPE constant or is null, then key will be calculated by converting its class name without ResourceOwner suffix to snake_case, if neither is felt, then \LogicException will be thrown,UserResponseInterface::getUsername() was deprecated in favour of UserResponseInterface::getUserIdentifier() to match changes in Symfony Security component,@internal resourceOwner oauth types in Configuration are calculated automatically by scandir. All classes extended from GenericOAuth[X]ResourceOwner get oauth[X] type. If class only implements ResourceOwnerInterface then its oauth type is unknown. ResourceOwner key (parameter type in configs) should have defined ResourceOwner::TYPE constant. Each user defined custom ResourceOwner class that implemented ResourceOwnerInterface will be registered automatically. If autoconfigure option is disabled user have to add the tag hwi_oauth.resource_owner to the service definition,ConnectController was split into two smaller ones, Connect\ConnectController & Connect\RegisterController,OAuth1ResourceOwner & OAuth2ResourceOwner to cover case of implementing custom oauth resource owners,CleverResourceOwner::doGetRequest,TransportExceptionInterface in AbstractResourceOwner::getResponseContent() method,OAuthUserProvider::loadUserByOAuthUserResponse() when nickname is not available in OAuth response,firebase/php-jwt library,Templating\Helper\OAuthHelper class directly into Twig\Extension\OAuthRuntime by @stloyd in #1888OAuth1ResourceOwner & OAuth2ResourceOwner by @stloyd in #1889ConnectController & split it into smaller ones by @stloyd in #1887RefreshOAuthTokenCompilerPass class quality by @stloyd in #1881getIdentifier() into PathUserResponse to match Symfony changes by @stloyd in #1883SensioConnectUserResponse by @stloyd in #1894TransportExceptionInterface in AbstractResourceOwner::getResponseContent() method by @stloyd in #1911loadUserByOAuthUserResponse() when nickname is not available in OAuth response by @stloyd in #1913symfony/templating by @GromNaN in #1940Full Changelog: 2.0.0-BETA2...2.0.0-BETA3
Deprecated: configuration parameter firewall_names , firewalls are now computed automatically - all firewalls that have defined oauth authenticator/pr…
firewall_names, firewalls are now computed automatically - all firewalls that have defined oauth authenticator/provider will be collected,GenericOAuth2ResourceOwner resource owners), if option refresh_on_expire set to true,refresh_on_expure set to true,@internal) Removed/replaced redundant argument $firewallNames from controllers. If controller class was copied and replaced, adapt list of arguments: In controller use $resourceOwnerMapLocator->getFirewallNames(),RefreshTokenListener cannot be lazy. If current firewall is lazy (or anonymous: lazy) then current auth token is often initializing on kernel.response. In this case new access token will not be stored in session. Therefore, the expired token will be refreshed on each request,InteractiveLoginEvent will be triggered also for OAuthAuthenticator,*.xml to *.php (services and routes). Xml routing configs connect.xml, login.xml and redirect.xml are steel present but deprecated. Please use *.php variants in your includes instead.hwi_oauth.connect.confirmation parameter by @franmomu in #1756Makefile in favour of composer scripts by @stloyd in #1766connect option is not enabled by @stloyd in #1782connect configuration is not set but ConnectController was used by @stloyd in #1844RememberMeBadge into OAuth passport by @stloyd in #1846Full Changelog: 1.4.5...2.0.0-BETA2
BC Break: Dropped PHP 7.3 support,
>=5.1 & <5.4 (still with BC layer included),OAuthExtension is now a lazy Twig extension using a Runtime,FOSUserBundle,process() argument for Form/RegistrationFormHandlerInterface, from Form $form to FormInterface $form,Resources/views/Connect/connect_confirm.html.twig from fos_user_registration_register to registration_register,fosub from oauth_user_provider,hwi_oauth.fosub, & all related DI parameters,hwi_oauth.registration.form.factory in favour of declaring form class name as DI parameter: hwi_oauth.connect.registration_form,ResourceOwnerMapInterface::hasResourceOwnerByName signature, update if you use a custom resource owner,ResourceOwnerMapInterface::getResourceOwnerByName signature, update if you use a custom resource owner,ResourceOwnerMapInterface::getResourceOwnerByRequest signature, update if you use a custom resource owner,ResourceOwnerMapInterface::getResourceOwnerCheckPath signature, update if you use a custom resource owner,ResourceOwnerMap uses service locator instead of DI container,hwi_oauth.abstract_resource_owner.generic, hwi_oauth.abstract_resource_owner.oauth1 & hwi_oauth.abstract_resource_owner.oauth2,setName() method from OAuth/ResourceOwnerInterface,__construct() argument for OAuth/ResourceOwner/AbstractResourceOwner, from HttpMethodsClient $httpClient to HttpClientInterface $httpClient,php-http/httplug-bundle with symfony/http-clienthwi_oauth.http configuration,src/,tests/,Resources/doc into: docs/,methods requirements:
hwi_oauth_connect_service: GET & POST,hwi_oauth_connect_registration: GET & POST,hwi_oauth_connect: GET,hwi_oauth_service_redirect: GET,5.4 & 6.0,Full Changelog: 1.4.5...2.0.0-BETA1
Bugfix: Fixed BC break by restoring wrongly moved AbstractOAuthToken::getCredentials() method,
Changelog:
AbstractOAuthToken::getCredentials() method,Bugfix: Fixed VkontakteResourceOwner option: api_version to not point to deprecated one,
VkontakteResourceOwner option: api_version to not point to deprecated one,RequestStack::getMasterRequest() is deprecated since Symfony 5.3, use RequestStack::getMainRequest() if exists,GenericOAuth1ResourceOwnerTestCase, GenericOAuth2ResourceOwnerTestCase & ResourceOwnerTestCase test case classes for easier unit testing custom resource ownersBugfix: remove @final declaration from OAuthFactory & FOSUBUserProvider,
@final declaration from OAuthFactory & FOSUBUserProvider,.gitattributes to reduce amount of code in archives,Bugfix: Define missing hwi_oauth.connect.confirmation parameter,
hwi_oauth.connect.confirmation parameter,Added: Forward compatibility layer for session service deprecation,
__construct() argument for OAuth/RequestDataStorage/SessionStorage, from SessionInterface $session to RequestStack $requestStack,final,HWIOAuthEvents::CONNECT_COMPLETED is fired,OAuthProvide to properly refresh data inside tokens,AppleResourceOwner,GitHubResourceOwner,Wunderlist resource owner,BC Break: dropped support for Symfony <4.4,
<4.4,<2.0,id_token exception in Azure resource owner,Fixed: Doctrine persistence deprecation errors,
first_name & last_name in AzureResourceOwner,authorization & access_token urls,FilterUserResponseEvent,Added domain whitelist service to avoid open redirect on target_path,
target_path,LoginController,setContainer call to service configuration for LoginController,Auth0ResourceOwner::doGetTokenRequest,Auth0ResourceOwner,LoginController is now optional,Fixed: Symfony deprecation warning in symfony/config,
symfony/config,LoginController::connectAction should not fail if no token is available,Configuration has been marked final,ConnectController has been marked final,HWIOAuthExtension has been marked final,OAuthExtension has been marked final,SetResourceOwnerServiceNameCompilerPass has been marked final,ConnectController extends AbstractController instead of Controller,hwi_oauth.http_client has been marked private,hwi_oauth.security.oauth_utils has been marked private,Fixed: Vkontakte profile picture & nickname path,
Content-Length header must be a string,infos_url should not be empty,first- & last- names,Fixed: VK requires API version now,
getUserInformation() in ConnectController,AccountNotLinkedException,IS_AUTHENTICATED_FULLY in DI configuration,OAuthProvider::refreshAccessToken() when there is no refresh tokenBC BREAK: Replaced PHPUnit_Framework_TestCase with PHPUnit\Framework\TestCase in tests,
PHPUnit_Framework_TestCase with PHPUnit\Framework\TestCase in tests,getUserInformation() for Dropbox v2,httpRequest() method in various resource owners,public to make code compatible with Symfony 4BC BREAK: Fully replaced Buzz library with usage of HTTPlug & Guzzle 6,
hwi.http_client config options are remove. HTTP configuration must rely on the HTTPlug client,hwi_oauth.templating_engine was removed,php-http/httplug-bundle support, to auto-provide needed HTTPlug services and get full Symfony integration,hwi.http.client and hwi.http.message_factory config keys to provide your own HTTPlug services,HWIOAuthEvents,ResourceOwnerInterface::addPaths() method for easier managing paths in resource owners,Fixed: Bitbucket2 resource owner,
php-cs-fixer updated to latest version & run on base codeFixed: Prevent uncaught exception when redirecting to invalid route,
Fixed error that could occur with message "302 Header already sent",
Fixed: OAuthHelper should fallback to new Request in case of receiving null,
OAuthHelper should fallback to new Request in case of receiving null,FOSUserBundle integration,WechatResourceOwner,WechatResourceOwner,TrelloResourceOwner,OAuthProvider,target_path after successful registration/connection,Fixed: Fixed scope deprecating message,
Fixed: Change Discogs URL from http to https,
Fixed: Remove usage of deprecated Twig function form_enctype & replace with usage of form_start/form_end,
form_enctype & replace with usage of form_start/form_end,~3.0,include_email option into Twitter resource owner,Fixed: ResourceOwnerMap no longer depends on deprecated ContainerAware class,
UserResponseInterface#getFirstName() method, also a new default path firstname
was added, this path holds the first name of user,UserResponseInterface#getLastName() method, also a new default path lastname
was added, this path holds the last name of user,UserResponseInterface::getOAuthToken() & basic implementation in AbstractUserResponse,GenericOAuth1ResourceOwner::getRequestToken() is now public method (was protected),firewall_name (will be removed in next major version)
renamed to firewall_names to support multiple firewalls,failed_auth_path which contains route name, on which user
will be redirected after failure when connecting accounts (i.e. user denies connection),appsecret_proof functionality support to the Facebook resource owner,sandbox functionality support to the Salesforce resource owner,ResourceOwnerMap no longer depends on deprecated ContainerAware class,json_decode in Mail.ru resource owner,AuthenticationExceptionFix: Remove deprecated Twig features
FOSUBUserProvider::refreshUserFix: Deprecated graph URLs for FacebookResourceOwner
FacebookResourceOwnerFix: Don't use deprecated fields in FacebookResourceOwner,
SessionStorage::save() could throw php error,OAuthToken::isExpired() always returned false,FoursquareResourceOwner, TwitchResourceOwner, SensioConnectResourceOwner
not working with bearer header,FacebookResourceOwner,FOSUBUserProvider::refreshUser() always returning old user,Fix: InstagramResourceOwner regression while getting user details,
InstagramResourceOwner regression while getting user details,Fix: LinkedinResourceOwner regression while getting user details,
LinkedinResourceOwner regression while getting user details,revoke functionality to be available wider,SinaWeiboResourceOwner,Fix: Instagram OAuth redirect to one url,
FOSUBUserProvider should also implement UserProviderInterface,YahooResourceOwner infos_url to use new format,GithubResourceOwner revoke method,Fix: Incorrect redirect URL when no parameters are set,
prompt for GoogleResourceOwner,WordpressResourceOwner user details API call,oauth_callback_confirmed was set too false,FacebookResourceOwnerFix: Prevent SessionUnavailableException when returns back from service,
SessionUnavailableException when returns back from service,EntityUserProvider should implement UserProviderInterface,createdAt property was missing when serializing the OAuthToken,Fix: Change Twitter API call to use SSL URL,
VkontakteResourceOwner,YahooResourceOwner,FOSUBUserProvider when username is missing[BC break] AccountConnectorInterface::connect() method now requires the first parameter to be instance of Symfony\Component\Security\Core\User\UserInt
AccountConnectorInterface::connect() method now requires the first
parameter to be instance of Symfony\Component\Security\Core\User\UserInterfaceConnectController::authenticateUser() method now requires the first
parameter to be instance of Symfony\Component\HttpFoundation\RequestAbstractResourceOwner::addOptions() methodOAuthUtils::getAuthorizationUrl() & OAuthUtils::getLoginUrl() methods
now expect first parameter to be instance of Symfony\Component\HttpFoundation\Request[BC break] Added ResourceOwnerInterface::isCsrfTokenValid() method
ResourceOwnerInterface::isCsrfTokenValid() methodOAuth1RequestTokenStorageInterface along with the implementationsAbstractResourceOwner::__construct() now requires RequestDataStorageInterface
instance as last argumentRequestDataStorageInterface along with implementation[BC break] GenericOAuth2ResourceOwner::getAccessToken() now returns an array instead of a string. This array contains the access token and its 'expire
GenericOAuth2ResourceOwner::getAccessToken() now returns an array
instead of a string. This array contains the access token and its 'expires_in'
value, along with any other parameters returned from the authentication providerOAuthAwareExceptionInterface#setToken(), OAuthAwareExceptionInterface#getRefreshToken(),
OAuthAwareExceptionInterface#getRawToken(), OAuthAwareExceptionInterface#getExpiresIn()
methodsAbstractResourceOwner::doGetAccessTokenRequest to doGetTokenRequestAdvancedPathUserResponse & AdvancedUserResponseInterfaceUserResponseInterface#getEmail(), UserResponseInterface#getProfilePicture(),
UserResponseInterface#getRefreshToken(), UserResponseInterface#getExpiresIn(),
UserResponseInterface#setOAuthToken() methodsUserResponseInterface::setAccessToken() methodAbstractUserResponse::getOAuthToken() method because it was ambiguousPathUserResponse#setPaths() method no longer overwrite default pathsPathUserResponse#getPath() method no longer throws an exception if path
not existsPathUserResponse#getValueForPath() removed second argument from this method,
it will not throw exception anymore if response or value is missing, but now will return
null insteadResourceOwnerInterface#getOption($name) methodResourceOwnerInterface#getUserInformation() now must receive array ($accessToken)
as first parameter, also added second parameter ($extraParameters) to be consistent
along all implementationsOAuthToken::getRefreshToken(), OAuthToken::setRefreshToken(), OAuthToken::getExpiresIn(),
OAuthToken::setExpiresIn(), OAuthToken::getRawToken(), OAuthToken::setRawToken()AbstractResourceOwner#addOptions() & ResourceOwnerInterface#setOption($name, $value)
methods which allows easy overwriting resource specific optionsaccess_type, request_visible_actions, approval_prompt & hd
in Google resource ownerFix: use Symfony\Component\Security\Core\User\UserInterface in EntityUserProvider::refreshUser
Symfony\Component\Security\Core\User\UserInterface in EntityUserProvider::refreshUserSessionStorage compatible with Symfony 2.0Fix: Regression done in version 0.2.8 blocking usage without FOSUserBundle
0.2.8 blocking usage without FOSUserBundleOAuthUtils::getAuthorizationUrl() ignoring given redirect URLFix: Added missing parts in user providers like: loadUserByUsername() or refreshUser() methods
loadUserByUsername()
or refreshUser() methodsOAuthUtils::signRequest() compatible with OAuth1.0a specificationFix: Polish oauth error detection to cover cases from i.e. Facebook resource owner
Fix: Use same check for FOSUserBundle compatibility to prevent strange errors with calls of undefined services
Fix: Use user identifier represented as string for Twitter to prevent issues with losing accuracy for large numbers (i.e. Javascript) or type comparis
arg_separator.output data for URL generation to prevent issuesFix: Throw Symfony\Component\Security\Core\Exception\AccessDeniedException & Symfony\Component\HttpKernel\Exception\NotFoundHttpException instead of \
Symfony\Component\Security\Core\Exception\AccessDeniedException
& Symfony\Component\HttpKernel\Exception\NotFoundHttpException instead of \Exception
to make cases more clearoauth_problem as authorization error and inform user instead logging error
in backgroundYahooResourceOwnerAdded AbstractUserResponse::getOAuthToken() method to allow fetching only OAuth token details
AbstractUserResponse::getOAuthToken() method to allow fetching only OAuth token detailsFix: Use API 1.1 for Twitter, not the deprecated 1.0
Fixed issue with FOSUserBundle 2.x integration
Added support for a target_path_parameter in order to control the redirect path after login
target_path_parameter in order to control the redirect path after loginhwi_oauth_authorization_url() twig helper functionrealm in configurationfirewall_name is requiredAlreadyBoundException when using FOSUserBundle 1.x integrationprofilePicture in views before calling itInMemoryProvider now shows user nickname as name instead of unique identifierrealm option if is empty in request headers[BC break] Renamed path username to identifier to make it more clear that this path should hold the unique user identifier (previously username)
username to identifier to make it more clear that this path should
hold the unique user identifier (previously username)UserResponseInterface#getUsername() now always returns a real
unique user identifier, and uses path identifierOAuth1RequestTokenStorageInterface#save() second param $token must
now be an arrayredirect.xml routing has to be imported. See the setup docsUserResponseInterface#getRealName() method, also a new default path realname
was added, this path holds the real name of userUserResponseInterface#getNickName() method, also a new default path nickname
was added, this path holds the nickname of userUserResponseInterface#getAccessToken() and UserResponseInterface#setAccessTokenOAuthToken#getCredentials() returns an empty string to be consistent with
the security component. The access token can still be retrieved from the
getAccessToken() methodfirewall_name option required settingYour coding agent can read these notes before it upgrades. Set up the MCP server →