hwi/oauth-bundle
Support for authenticating users using both OAuth1.0a and OAuth2 in Symfony.
2.5.0
23M downloads/mo
#1657 most downloaded on Packagist
hwi/HWIOAuthBundle
What this package is like to depend on
Last release 6 months ago
19 Feb 2026
Release timing varies
gaps range from 2 weeks to 1.6 years
Nearly every release is documented
notes for 49 of 49 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
54 releases · first in 2012
1 release in the last 12 months
see the full history below
Release timeline
54 releases · Aug 2012 to Feb 2026Releases
latest 54-
2.5.019 Feb 2026Release notes
Open source →- Added: PHP 8.5 test coverage,
- Added: Support for Symfony 8.0,
- Added: Handles absolute URL's in Amazon Cognito,
- Bugfix: Wrong HTTP status code in RegisterController,
- BC Break: Increased
firebase/php-jwtsupport to 7.0, - BC Break: Dropped support for Symfony < 6.4,
- BC Break: Dropped support for PHP < 8.3,
Release notes
Open source →- Added: PHP 8.5 test coverage,
- Added: Support for Symfony 8.0,
- Added: Handles absolute URL's in Amazon Cognito,
- Bugfix: Wrong HTTP status code in RegisterController,
- BC Break: Increased
firebase/php-jwtsupport to 7.0, - BC Break: Dropped support for Symfony < 6.4,
- BC Break: Dropped support for PHP < 8.3,
-
2.4.029 May 2025Release notes
Open source →- Added: PHP 8.4 test coverage,
- Added: LinkedIn OpenID resource owner,
- Added:
show_dialogoption to Spotify resource owner, - Use CSPRNG for generating nonce,
Release notes
Open source →- Added: PHP 8.4 test coverage,
- Added: LinkedIn OpenID resource owner,
- Added:
show_dialogoption to Spotify resource owner, - Use CSPRNG for generating nonce,
-
2.3.001 Jan 2025Release notes
Open source →- BC Break: Dropped support for Symfony:
6.3and7.0, - Added:
Amazon Cognitoresource owner, - Bugfix: Prevent overwriting
failure_pathinAuthenticationFailureHandlerwhen connect functionality is not enabled, - Bugfix: Prevent overwriting
failure_handlerin security configuration if set, - Bugfix: Type hint
AuthenticatorInterfaceinstead ofOAuthAuthenticatorinRefreshAccessTokenListener, - Bugfix: Add missing parameters to
OdnoklassnikiResourceOwner,
Release notes
Open source →- BC Break: Dropped support for Symfony:
6.3and7.0, - Added:
Amazon Cognitoresource owner, - Bugfix: Prevent overwriting
failure_pathinAuthenticationFailureHandlerwhen connect functionality is not enabled, - Bugfix: Prevent overwriting
failure_handlerin security configuration if set, - Bugfix: Type hint
AuthenticatorInterfaceinstead ofOAuthAuthenticatorinRefreshAccessTokenListener, - Bugfix: Add missing parameters to
OdnoklassnikiResourceOwner,
- BC Break: Dropped support for Symfony:
-
2.2.028 Feb 2024Release notes
Open source →What's Changed
- Add Telegram resource owner by @zorn-v in #1966
- Drop not supported PHP 7.4 & 8.0 by @stloyd in #1969
- Allow "use_authorization_to_get_token" to be configured to false for generic OAuth2 by @ldaspt in #1974
- Update API version for Facebook to the latest available by @stloyd in #1975
- Replace custom authenticator passport with custom badge usage by @stloyd in #1976
- Replace custom authenticator passport with custom badge usage by @stloyd in #1978
- Fix registration of failure handler by @stloyd in #1979
- Don't miss the refresh token by @kurian86 in #1963
- Fix security setup docs by @stloyd in #1980
- Add GH action to close stale stuff by @stloyd in #1981
- Allow
nullas$registrationForminRegisterControllerby @stloyd in #1983 - Make Twig & Symfony Routing hard requirement by @stloyd in #1984
- Document how to configure entity provider by @stloyd in #1985
- Remove Twig usage from
AuthenticationFailureHandlerby @stloyd in #1986 - Add connect functionality docs by @stloyd in #1987
- Adjust changelog for release 2.2 by @stloyd in #1988
New Contributors
- @zorn-v made their first contribution in #1966
- @ldaspt made their first contribution in #1974
- @kurian86 made their first contribution in #1963
Full Changelog: 2.1.0...2.2.0
Release notes
Open source →- BC Break: Dropped support for PHP 7.4 & 8.0,
- Added: Telegram resource owner,
- Bugfix: Allow
use_authorization_to_get_tokento be configured tofalsefor generic OAuth2, - Bugfix: Update API version for Facebook to latest available
- Bugfix: Replace custom authenticator passport with custom badge usage,
- Bugfix: Fix registration of failure handler,
- Bugfix: Don't miss refresh token in registration controller,
- Bugfix: Allow
nullas$registrationForminRegisterController, - Bugfix: Fix connect functionality with authentication managers,
-
2.1.030 Nov 2023Release notes
Open source →What's Changed
- Add resource owner Passage by @malteschlueter in #1962
- Allow usage of Symfony 7 by @stloyd in #1968
- Fixed compatiblity with Symfony 6.4+
New Contributors
- @malteschlueter made their first contribution in #1962
For details go and read the CHANGELOG file.
Release notes
Open source →- BC Break: Dropped support for Symfony:
>6.0, <6.3, - Added: New Passage resource owner,
- Bugfix: Remove deprecations reported by Symfony 6.4,
- Chore: Added support for Symfony 7,
-
2.0.001 Oct 2023Release notes
Open source →Long awaited 2.0 release!
The main changes:
- completely reworked resource owners internals,
- official support for Symfony 6,
- official support for PHP 8,
- dropped support for Symfony <5.4,
- dropped support for PHP <7.4,
- removed support for
FOSUserBundle,
For details go and read the CHANGELOG file.
What's Changed
- Remove direct deprecations reported on Symfony 6 by @stloyd in #1946
- Enable integration tests on Symfony 6 by @stloyd in #1947
- Prevent refreshing non-expired token by @stloyd in #1948
- Update GH actions by @stloyd in #1949
- Remove deprecations reported by Symfony 6.x by @stloyd in #1951
- Improve compatibility with Symfony 6.x by @stloyd in #1950
- Prevent fatal error when token doesn't have resource owner name set by @stloyd in #1952
- Run tests against PHP 8.3 by @stloyd in #1953
Full Changelog: 2.0.0-BETA3...2.0.0
Release notes
Open source →- Bugfix: Prevent refreshing non-expired tokens
- Bugfix: Remove deprecations reported by Symfony 6.x
- Bugfix: Prevent fatal error when token doesn't have resource owner name set
-
2.0.0-BETA320 Aug 2023 pre-releaseRelease notes
Open source →Changelog
- BC Break: Dropped support for Symfony: 4.4 & 6.0.*,
- BC Break: Class
Templating\Helper\OAuthHelperwas merged intoTwig\Extension\OAuthRuntime, - BC Break: When resource owner class doesn't define
TYPEconstant or isnull, then key will be calculated by converting its class name withoutResourceOwnersuffix tosnake_case, if neither is felt, then\LogicExceptionwill be thrown, - Deprecated: method
UserResponseInterface::getUsername()was deprecated in favour ofUserResponseInterface::getUserIdentifier()to match changes in Symfony Security component, - Enhancement:
@internalresourceOwner oauth types in Configuration are calculated automatically by scandir. All classes extended fromGenericOAuth[X]ResourceOwnergetoauth[X]type. If class only implements ResourceOwnerInterface then its oauth type isunknown. ResourceOwner key (parametertypein configs) should have defined ResourceOwner::TYPE constant. Each user defined custom ResourceOwner class that implementedResourceOwnerInterfacewill be registered automatically. Ifautoconfigureoption is disabled user have to add the taghwi_oauth.resource_ownerto the service definition, - Enhancement: Class
ConnectControllerwas split into two smaller ones,Connect\ConnectController&Connect\RegisterController, - Bugfix: Added
OAuth1ResourceOwner&OAuth2ResourceOwnerto cover case of implementing custom oauth resource owners, - Bugfix: Fixed Authorization Header in
CleverResourceOwner::doGetRequest, - Bugfix: Catch also the
TransportExceptionInterfaceinAbstractResourceOwner::getResponseContent()method, - Bugfix: Current matched Firewall is respected during generation of resource owner check path links,
- Bugfix: Prevent fatal error in
OAuthUserProvider::loadUserByOAuthUserResponse()whennicknameis not available in OAuth response, - Bugfix: Use newer version of
firebase/php-jwtlibrary, - Chore: Removed not used Symfony Templating component
What's Changed
- Add Apple client_secret auto generation by @Seb33300 in #1884
- Update ConnectController.php by @stephanvierkant in #1886
- Merged
Templating\Helper\OAuthHelperclass directly intoTwig\Extension\OAuthRuntimeby @stloyd in #1888 - Added
OAuth1ResourceOwner&OAuth2ResourceOwnerby @stloyd in #1889 - Refactor
ConnectController& split it into smaller ones by @stloyd in #1887 - Improve
RefreshOAuthTokenCompilerPassclass quality by @stloyd in #1881 - Added
getIdentifier()intoPathUserResponseto match Symfony changes by @stloyd in #1883 - Improve Configuration.php readability by @gassan in #1891
- Fixed wrong class name in
SensioConnectUserResponseby @stloyd in #1894 - Allow "symfony/flex" plugin by @stloyd in #1908
- Removed support for Symfony ~6.0 by @stloyd in #1907
- Fixed links to documentation by @stloyd in #1909
- Remove invalid CI job by @stloyd in #1910
- Fix typo by @dlondero in #1899
- Fix Authorization header for CleverResourceOwner.php by @gassan in #1868
- Catch also the
TransportExceptionInterfaceinAbstractResourceOwner::getResponseContent()method by @stloyd in #1911 - Current matched Firewall is respected during generation of check path links. by @gassan in #1890
- Added funding button by @stloyd in #1912
- All ResourceOwners are collected automatically. by @gassan in #1872
- Fixed configuration of custom resource owners by @stloyd in #1915
- Add custom resource owner to confirm it's working correctly by @stloyd in #1916
- Fix typo in configuration comment by @reyostallenberg in #1933
- Update apple connector doc link by @Nek- in #1929
- Fix PHP 8.2 compatibility by @IonBazan in #1926
- Avoid confusion about Symfony version support dropped by @lyrixx in #1936
- Added feature to auto hint towards specific idp by @pimjansen in #1931
- Prevent fatal error in
loadUserByOAuthUserResponse()whennicknameis not available in OAuth response by @stloyd in #1913 - Fixed wrong PHP version used in CI by @stloyd in #1941
- Fix CS and PHPStan by @Seb33300 in #1938
- Remove
symfony/templatingby @GromNaN in #1940 - Temporary skip broken test on Symfony 6 by @stloyd in #1942
- Don't use native file session in tests by @stloyd in #1943
- Remove BC layer for Symfony 4.4 by @stloyd in #1945
New Contributors
- @Seb33300 made their first contribution in #1884
- @dlondero made their first contribution in #1899
- @reyostallenberg made their first contribution in #1933
- @lyrixx made their first contribution in #1936
- @pimjansen made their first contribution in #1931
- @GromNaN made their first contribution in #1940
Full Changelog: 2.0.0-BETA2...2.0.0-BETA3
Release notes
Open source →- BC Break: Dropped support for Symfony: 6.0.*,
- BC Break: Class
Templating\Helper\OAuthHelperwas merged intoTwig\Extension\OAuthRuntime, - BC Break: When resource owner class doesn't define
TYPEconstant or isnull, then key will be calculated by converting its class name withoutResourceOwnersuffix tosnake_case, if neither is felt, then\LogicExceptionwill be thrown, - Deprecated: method
UserResponseInterface::getUsername()was deprecated in favour ofUserResponseInterface::getUserIdentifier()to match changes in Symfony Security component, - Enhancement:
@internalresourceOwner oauth types in Configuration are calculated automatically by scandir. All classes extended fromGenericOAuth[X]ResourceOwnergetoauth[X]type. If class only implements ResourceOwnerInterface then its oauth type isunknown. ResourceOwner key (parametertypein configs) should have defined ResourceOwner::TYPE constant. Each user defined custom ResourceOwner class that implementedResourceOwnerInterfacewill be registered automatically. Ifautoconfigureoption is disabled user have to add the taghwi_oauth.resource_ownerto the service definition, - Enhancement: Class
ConnectControllerwas split into two smaller ones,Connect\ConnectController&Connect\RegisterController, - Bugfix: Added
OAuth1ResourceOwner&OAuth2ResourceOwnerto cover case of implementing custom oauth resource owners, - Bugfix: Fixed Authorization Header in
CleverResourceOwner::doGetRequest, - Bugfix: Catch also the
TransportExceptionInterfaceinAbstractResourceOwner::getResponseContent()method, - Bugfix: Current matched Firewall is respected during generation of resource owner check path links,
- Bugfix: Prevent fatal error in
OAuthUserProvider::loadUserByOAuthUserResponse()whennicknameis not available in OAuth response, - Bugfix: Use newer version of
firebase/php-jwtlibrary, - Chore: Removed not used Symfony Templating component
-
2.0.0-BETA216 Jan 2022 pre-releaseRelease notes
Open source →Changelog
- Deprecated: configuration parameter
firewall_names, firewalls are now computed automatically - all firewalls that have definedoauthauthenticator/provider will be collected, - Added: Ability to automatically refresh expired access tokens (only for derived from
GenericOAuth2ResourceOwnerresource owners), if optionrefresh_on_expireset totrue, - Enhancement: Refresh token listener is disabled by default and will only be enabled if at least one resource owner has option
refresh_on_expureset totrue, - Enhancement: (
@internal) Removed/replaced redundant argument$firewallNamesfrom controllers. If controller class was copied and replaced, adapt list of arguments: In controller use$resourceOwnerMapLocator->getFirewallNames(), - Bugfix:
RefreshTokenListenercannot be lazy. If current firewall is lazy (or anonymous: lazy) then current auth token is often initializing onkernel.response. In this case new access token will not be stored in session. Therefore, the expired token will be refreshed on each request, - Bugfix:
InteractiveLoginEventwill be triggered also forOAuthAuthenticator, - Maintain: Changed config files from
*.xmlto*.php(services and routes). Xml routing configsconnect.xml,login.xmlandredirect.xmlare steel present but deprecated. Please use*.phpvariants in your includes instead.
Details What's Changed
- increase phpstan to level 2 by @dmaicher in #1754
- Define
hwi_oauth.connect.confirmationparameter by @franmomu in #1756 - Maintain | Remove
Makefilein favour of composer scripts by @stloyd in #1766 - make twig extension lazy by using a Runtime by @dmaicher in #1741
- Remove support for FOSUser bundle by @stloyd in #1732
- bump to phpstan level 3 by @dmaicher in #1770
- Bump minimal PHP version to 7.4 by @XWB in #1774
- Maintain | Adjust codebase to match PHPStan level 5 by @stloyd in #1771
- Use type hints and return types in ResourceOwnerMapInterface by @XWB in #1773
- Rework ResourceOwnerMap to use service locator instead of whole DI container by @stloyd in #1775
- Bugfix | Prevent issue with missing parameter when
connectoption is not enabled by @stloyd in #1782 - Maintain | Update min. Twig version to work with PHP 8 by @stloyd in #1789
- [BC Break] Rework resource owners to use Symfony Http Client internally by @stloyd in #1681
- BC Break | Make classes final where expected & adjust types to PHP 7.4 by @stloyd in #1778
- Maintain | Update tests to use type & return hints by @stloyd in #1791
- Update Yahoo resource owner to use OAuth2 by @stloyd in #1790
- [2.x] Fix HTTP client definition by @Jean85 in #1792
- Maintain | Fixed php-cs-fixer & phpstan reports by @stloyd in #1801
- Rework Github Actions to be more efficient by @stloyd in #1807
- Update link to LinkedIn by @alexisLefebvre in #1811
- Fix EntityUserProviderTest by @sjerdo in #1822
- Fix parsing OAuth1.0a responses for Twitter by @sjerdo in #1821
- Spotify | Add path for profile picture by @sjerdo in #1819
- Pass content in HTTP POST request on OAuth server by @rmlev in #1826
- Fix code style issue by @sjerdo in #1827
- Maintain | Update compatibility with PHP 8.1 by @stloyd in #1828
- Maintain | Rework CI by @stloyd in #1829
- Maintain | Update PHPStan to version 1.0 by @stloyd in #1830
- Maintain | Add support for Symfony 6 by @stloyd in #1800
- Maintain | Merge branch 1.4 into master one by @stloyd in #1834
- Maintain | Run new security already on Symfony 5.4 by @stloyd in #1837
- Bugfix | Test BC layer for Symfony Security <5.4 by @stloyd in #1839
- Bugfix | Fixed issue when
connectconfiguration is not set butConnectControllerwas used by @stloyd in #1844 - Reviewed authenticator and made refreshToken method public. by @gassan in #1831
- Maintain | Adjust docs to follow Symfony changes by @stloyd in #1845
- Bugfix | Added missing
RememberMeBadgeinto OAuth passport by @stloyd in #1846 - Force particular methods on internal routes by @stloyd in #1847
- Maintain | Rework bundle structure to match Symfony best practices by @stloyd in #1799
- oauth token of the same class will be created. fix in tests by @gassan in #1849
- Track oauth requests by symfony-profiler by @gassan in #1852
- Allow null User for refreshing oauth token by @gassan in #1855
- Http client for symfony 4.4 by @gassan in #1856
- RFC | Lets switch configs from xml to php by @gassan in #1859
- Review: Removed/replaced redundant parameter $firewallNames in Controllers by @gassan in #1861
- auto refresh oauth2 token on expire by @gassan in #1850
- Maintain | Improved code quality by adding hint & return types by @stloyd in #1863
- Keycloak: default paths mapping for a new created keycloak realm by @gassan in #1858
- Removed option firewall_names by @gassan in #1864
- Maintain | Added new Composer 2.2 config for "allow-plugins" by @stloyd in #1865
- Bugfix: Refresh token listener should not be lazy. by @gassan in #1867
- set resourceOwner services directly without using tag by @dmaicher in #1874
- Bugfix: InteractiveLoginEvent Event will be triggered also for OAuthAuthenticator by @gassan in #1877
New Contributors
- @sjerdo made their first contribution in #1822
- @rmlev made their first contribution in #1826
- @gassan made their first contribution in #1831
Full Changelog: 1.4.5...2.0.0-BETA2
Release notes
Open source →- Deprecated: configuration parameter
firewall_names, firewalls are now computed automatically - all firewalls that have definedoauthauthenticator/provider will be collected, - Added: Ability to automatically refresh expired access tokens (only for derived from
GenericOAuth2ResourceOwnerresource owners), if optionrefresh_on_expireset totrue, - Enhancement: Refresh token listener is disabled by default and will only be enabled if at least one resource owner has option
refresh_on_expureset totrue, - Enhancement: (
@internal) Removed/replaced redundant argument$firewallNamesfrom controllers. If controller class was copied and replaced, adapt list of arguments: In controller use$resourceOwnerMapLocator->getFirewallNames(), - Bugfix:
RefreshTokenListenercannot be lazy. If current firewall is lazy (or anonymous: lazy) then current auth token is often initializing onkernel.response. In this case new access token will not be stored in session. Therefore, the expired token will be refreshed on each request, - Bugfix:
InteractiveLoginEventwill be triggered also forOAuthAuthenticator, - Maintain: Changed config files from
*.xmlto*.php(services and routes). Xml routing configsconnect.xml,login.xmlandredirect.xmlare steel present but deprecated. Please use*.phpvariants in your includes instead.
- Deprecated: configuration parameter
-
2.0.0-BETA110 Dec 2021 pre-releaseRelease notes
Open source →Changelog
- BC Break: Dropped PHP 7.3 support,
- BC Break: Dropped support for Symfony:
>=5.1&<5.4(still with BC layer included), - BC Break:
OAuthExtensionis now a lazy Twig extension using a Runtime, - BC Break: removed support for
FOSUserBundle, - BC Break: changed
process()argument forForm/RegistrationFormHandlerInterface, fromForm $formtoFormInterface $form, - BC Break: changed form class name in template
Resources/views/Connect/connect_confirm.html.twigfromfos_user_registration_registertoregistration_register, - BC Break: removed configuration option
fosubfromoauth_user_provider, - BC Break: removed configuration options
hwi_oauth.fosub, & all related DI parameters, - BC Break: removed DI parameter
hwi_oauth.registration.form.factoryin favour of declaring form class name as DI parameter:hwi_oauth.connect.registration_form, - BC Break: changed
ResourceOwnerMapInterface::hasResourceOwnerByNamesignature, update if you use a custom resource owner, - BC Break: changed
ResourceOwnerMapInterface::getResourceOwnerByNamesignature, update if you use a custom resource owner, - BC Break: changed
ResourceOwnerMapInterface::getResourceOwnerByRequestsignature, update if you use a custom resource owner, - BC Break: changed
ResourceOwnerMapInterface::getResourceOwnerCheckPathsignature, update if you use a custom resource owner, - BC Break:
ResourceOwnerMapuses service locator instead of DI container, - BC Break: Removed abstract services:
hwi_oauth.abstract_resource_owner.generic,hwi_oauth.abstract_resource_owner.oauth1&hwi_oauth.abstract_resource_owner.oauth2, - BC Break: Removed
setName()method fromOAuth/ResourceOwnerInterface, - BC Break: changed
__construct()argument forOAuth/ResourceOwner/AbstractResourceOwner, fromHttpMethodsClient $httpClienttoHttpClientInterface $httpClient, - BC Break: replaced
php-http/httplug-bundlewithsymfony/http-client - BC Break: removed
hwi_oauth.httpconfiguration, - BC Break: reworked bundles structure to match Symfony best practices:
- bundle code moved to:
src/, - tests moved to:
tests/, - docs moved from
Resources/docinto:docs/,
- bundle code moved to:
- BC Break: routes provided by bundle now have
methodsrequirements:hwi_oauth_connect_service:GET&POST,hwi_oauth_connect_registration:GET&POST,hwi_oauth_connect:GET,hwi_oauth_service_redirect:GET,
- Added support for PHP 8.1,
- Added support for Symfony
5.4&6.0,
Kudos to "Old" Contributors (random order)
New Contributors
- @sjerdo made their first contribution in #1822
- @rmlev made their first contribution in #1826
- @gassan made their first contribution in #1831
Full Changelog: 1.4.5...2.0.0-BETA1
Release notes
Open source →- BC Break: Dropped PHP 7.3 support,
- BC Break: Dropped support for Symfony: >=5.1 & <5.4,
- BC Break:
OAuthExtensionis now a lazy Twig extension using a Runtime, - BC Break: removed support for
FOSUserBundle, - BC Break: changed
process()argument forForm/RegistrationFormHandlerInterface, fromForm $formtoFormInterface $form, - BC Break: changed form class name in template
Resources/views/Connect/connect_confirm.html.twigfromfos_user_registration_registertoregistration_register, - BC Break: removed configuration option
fosubfromoauth_user_provider, - BC Break: removed configuration options
hwi_oauth.fosub, & all related DI parameters, - BC Break: removed DI parameter
hwi_oauth.registration.form.factoryin favour of declaring form class name as DI parameter:hwi_oauth.connect.registration_form, - BC Break: changed
ResourceOwnerMapInterface::hasResourceOwnerByNamesignature, update if you use a custom resource owner, - BC Break: changed
ResourceOwnerMapInterface::getResourceOwnerByNamesignature, update if you use a custom resource owner, - BC Break: changed
ResourceOwnerMapInterface::getResourceOwnerByRequestsignature, update if you use a custom resource owner, - BC Break: changed
ResourceOwnerMapInterface::getResourceOwnerCheckPathsignature, update if you use a custom resource owner, - BC Break:
ResourceOwnerMapuses service locator instead of DI container, - BC Break: Removed abstract services:
hwi_oauth.abstract_resource_owner.generic,hwi_oauth.abstract_resource_owner.oauth1&hwi_oauth.abstract_resource_owner.oauth2, - BC Break: Removed
setName()method fromOAuth/ResourceOwnerInterface, - BC Break: changed
__construct()argument forOAuth/ResourceOwner/AbstractResourceOwner, fromHttpMethodsClient $httpClienttoHttpClientInterface $httpClient, - BC Break: replaced
php-http/httplug-bundlewithsymfony/http-client - BC Break: removed
hwi_oauth.httpconfiguration, - BC Break: reworked bundles structure to match Symfony best practices:
- bundle code moved to:
src/, - tests moved to:
tests/, - docs moved from
Resources/docinto:docs/,
- bundle code moved to:
- BC Break: routes provided by bundle now have
methodsrequirements:hwi_oauth_connect_service:GET&POST,hwi_oauth_connect_registration:GET&POST,hwi_oauth_connect:GET,hwi_oauth_service_redirect:GET,
- Added support for PHP 8.1,
- Added support for Symfony 5.6,
-
1.4.508 Dec 2021Release notes
Open source →Changelog:
- Bugfix: Fixed BC break by restoring wrongly moved
AbstractOAuthToken::getCredentials()method,
Release notes
Open source →- Bugfix: Fixed: BC break by restoring wrongly moved
AbstractOAuthToken::getCredentials()method,
- Bugfix: Fixed BC break by restoring wrongly moved
-
1.4.307 Dec 2021Release notes
Open source →- Bugfix: Fixed support for PHP 8.1,
- Bugfix: Fixed support for Symfony 5.4,
- Bugfix: Fixed
VkontakteResourceOwneroption:api_versionto not point to deprecated one, - Bugfix:
RequestStack::getMasterRequest()is deprecated since Symfony 5.3, useRequestStack::getMainRequest()if exists, - Maintain: Added
GenericOAuth1ResourceOwnerTestCase,GenericOAuth2ResourceOwnerTestCase&ResourceOwnerTestCasetest case classes for easier unit testing custom resource owners
-
1.4.209 Aug 2021Release notes
Open source →- Bugfix: remove
@finaldeclaration fromOAuthFactory&FOSUBUserProvider, - Maintain: added
.gitattributesto reduce amount of code in archives,
- Bugfix: remove
-
1.4.128 Jul 2021Release notes
Open source →- Bugfix: Define missing
hwi_oauth.connect.confirmationparameter, - Bugfix: Added missing success/failure handlers,
- Bugfix: Define missing
-
1.4.026 Jul 2021Release notes
Open source →- BC Break: dropped Symfony 5.0 support as it is EOL,
- BC Break: dropped PHP 7.2 support as it is EOL,
- BC Break: changed
__construct()argument forOAuth/RequestDataStorage/SessionStorage, fromSessionInterface $sessiontoRequestStack $requestStack, - BC Break: all internal classes are "softly" marked as
final, - Added: Symfony 5.1 Security system support,
- Added: Forward compatibility layer for session service deprecation,
- Added: state support for service authentication URL's,
- Added: ability to change the response after
HWIOAuthEvents::CONNECT_COMPLETEDis fired, - Added: PHPStan static analyse into CI,
- Fixed:
OAuthProvideto properly refresh data inside tokens, - Fixed: PHP notice in
AppleResourceOwner, - Fixed: use new GitHub API in
GitHubResourceOwner, - Fixed: functional tests with & without FOSUserBundle,
- Fixed: controller don't depend on service container if possible,
- Maintain: removed
Wunderlistresource owner, - Maintain: removed several Symfony BC layers,
- Maintain: removed Prophecy in favour of PHPUnit mocking,
-
1.3.003 Jan 2021Release notes
Open source →- BC Break: dropped support for Symfony
<4.4, - BC Break: dropped support for Doctrine Bundle
<2.0, - Added PHP 8 support,
- Upgraded Facebook API to v8.0,
- Upgraded Twitch resource owner to incorporate latest Twitch API,
- Fixed: undefined
id_tokenexception in Azure resource owner, - Docs: changed firewall name to match flex receipt,
- Maintain: moved from Travis CI to Github Actions,
- BC Break: dropped support for Symfony
-
1.2.019 Oct 2020Release notes
Open source →- BC Break: dropped Symfony 4.3 support,
- Added
first_name&last_namein AzureResourceOwner, - Added: support for multiple OAuth2 state parameters,
- Added: Apple resource owner,
- Fixed: updated Azure
authorization&access_tokenurls, - Fixed: Doctrine persistence deprecation errors,
- Allow modification of the response in
FilterUserResponseEvent,
-
1.1.006 Apr 2020Release notes
Open source →- Added Symfony 5 support,
- Added domain whitelist service to avoid open redirect on
target_path, - Fixed: session service was not injected in
LoginController, - Fixed: missing
setContainercall to service configuration forLoginController, - Fixed: client id and client secret must be set in
Auth0ResourceOwner::doGetTokenRequest, - Fixed: missing client id and client secret in
Auth0ResourceOwner, - Twig dependency on
LoginControlleris now optional,
-
1.0.017 Jan 2020Release notes
Open source →- Dropped support for PHP 5.6, 7.0 and 7.1,
- Dropped support for FOSUserBundle 1.3,
- Dropped support for Symfony 2.8,
- Minimum Symfony 3 requirement is 3.4,
- Minimum Symfony 4 requirement is 4.3,
- Fixed: WindowsLive Resource Owner token request,
- Fixed: Update Facebook API to v3.1,
- Fixed: Update Linkedin API to v2,
- Fixed: YahooResourceOwner::doGetUserInformationRequest uses wrong arguments,
- Fixed: Symfony deprecation warning in
symfony/config, - Fixed: SensioConnect now uses new API URLs,
- Fixed: Do not add Authorization header if no client_secret is present,
- Fixed:
LoginController::connectActionshould not fail if no token is available, - Added: Genius.com resource owner,
- Added: HTTPlug 2.0 support,
- Added: Keycloak resource owner,
- Added: The controller is now available as a service,
- Added: Allow to use HTTP Basic auth for token request,
- [BC break] Class
Configurationhas been marked final, - [BC break] Class
ConnectControllerhas been marked final, - [BC break] Class
HWIOAuthExtensionhas been marked final, - [BC break] Class
OAuthExtensionhas been marked final, - [BC break] Class
SetResourceOwnerServiceNameCompilerPasshas been marked final, - [BC break] Class
ConnectControllerextendsAbstractControllerinstead ofController, - [BC break] Service
hwi_oauth.http_clienthas been marked private, - [BC break] Service
hwi_oauth.security.oauth_utilshas been marked private, - [BC break] Several service class parameters have been removed,
-
0.6.331 Jul 2018Release notes
Open source →- Fixed: Vkontakte profile picture & nickname path,
- Fixed:
Content-Lengthheader must be a string, - Fixed: Upgraded GitLab end point to v4,
- Fixed: Resource owner map parameters must be public,
- Fixed: Azure resource owner
infos_urlshould not be empty, - Fixed: Don't start sessions twice & don't start sessions if already started,
- Fixed: Updated BitBucket docs,
- Added: Further compatibility changes for Symfony 4.1,
- Added: LinkedIn
first-&last-names, - Added: Facebook profile picture
-
0.6.228 Mar 2018Release notes
Open source →- Fixed: VK requires API version now,
- Fixed: Updated Slack resource owner to use new Slack API methods,
- Fixed: Changing authorization and access token to v2 for LinkedIn,
- Fixed: Fix double call of
getUserInformation()inConnectController, - Fixed: Fix serialization of
AccountNotLinkedException, - Fixed: Check for grant_rule value
IS_AUTHENTICATED_FULLYin DI configuration, - Fixed: Don't execute
OAuthProvider::refreshAccessToken()when there is no refresh token
-
0.6.123 Jan 2018Release notes
Open source →- BC BREAK: Replaced
PHPUnit_Framework_TestCasewithPHPUnit\Framework\TestCasein tests, - Added: Implemented
getUserInformation()for Dropbox v2, - Fixed: Headers passed to
httpRequest()method in various resource owners, - Fixed: Marked some services as
publicto make code compatible with Symfony 4
- BC BREAK: Replaced
-
0.6.001 Dec 2017Release notes
Open source →- BC BREAK: Fully replaced Buzz library with usage of HTTPlug & Guzzle 6,
- BC BREAK:
hwi.http_clientconfig options are remove. HTTP configuration must rely on the HTTPlug client, - BC BREAK: Template engine other than Twig are no longer supported,
- BC BREAK: Option
hwi_oauth.templating_enginewas removed, - Added: Symfony 4 support,
- Added:
php-http/httplug-bundlesupport, to auto-provide needed HTTPlug services and get full Symfony integration, - Added:
hwi.http.clientandhwi.http.message_factoryconfig keys to provide your own HTTPlug services, - Added:
HWIOAuthEvents, - Added:
ResourceOwnerInterface::addPaths()method for easier managing paths in resource owners, - Fixed: Update Facebook API to v2.8,
-
0.5.308 Jan 2017Release notes
Open source →- Fixed: Bitbucket2 resource owner,
- Fixed: GitHub resource owner documentation,
- Fixed: Don't require any form for the connect feature,
- Fixed: Uncaught exception with custom error page,
- Fixed:
php-cs-fixerupdated to latest version & run on base code
-
0.5.212 Dec 2016Release notes
Open source →- Fixed: Prevent uncaught exception when redirecting to invalid route,
- Fixed: Add more details too exception when account was not linked,
- Fixed: Odnoklassinki resource owner,
- Fixed: Office365 resource owner,
- Fixed: StackExchange resource owner,
- Fixed: WeChat resource owner,
- Fixed: WindowsLive resource owner
-
0.5.103 Oct 2016Release notes
Open source →- Fixed error that could occur with message "302 Header already sent",
- Exclude tests from Composer autoloader
-
0.5.011 Sep 2016Release notes
Open source →- Fixed:
OAuthHelpershould fallback to newRequestin case of receivingnull, - Fixed: Better
FOSUserBundleintegration, - Fixed: Serialization issue in
WechatResourceOwner, - Fixed: Incorrect refresh token in
WechatResourceOwner, - Fixed: Broken
TrelloResourceOwner, - Fixed: Removed dead code in
OAuthProvider, - Fixed: Update Facebook API to v2.7,
- Added: Symfony 3 support,
- Added: Redirect to
target_pathafter successful registration/connection, - Added: Asana resource owner,
- Added: Bitbucket resource owner,
- Added: Clever resource owner,
- Added: Itembase resource owner,
- Added: Jawbon resource owner,
- Added: Office365 resource owner,
- Added: Wunderlist resource owner,
- Added: Hungarian translation
- Fixed:
-
0.4.311 Sep 2016Release notes
Open source →- Fixed: Request parameters are not copied into new Request on forward,
- Fixed: Fixed scope deprecating message,
- Fixed: Resolved deprecated message in ConnectController,
- Fixed: Removed usage of deprecated code in tests
-
0.4.227 Jul 2016Release notes
Open source →- Fixed: Change Discogs URL from http to https,
- Fixed: Update Facebook API URLs to not use outdated ones
-
0.4.108 Mar 2016Release notes
Open source →- Fixed: Remove usage of deprecated Twig function
form_enctype& replace with usage ofform_start/form_end, - Fixed: Mark as not fully compatible with Symfony
~3.0, - Fixed: Multiple firewalls can now have different resource owners,
- Fixed: Wrong URL generated for Safesforce resource owner,
- Added:
include_emailoption into Twitter resource owner, - Added: Hungarian translation,
- Added: Documentation about FOSUser integration
- Fixed: Remove usage of deprecated Twig function
-
0.4.004 Dec 2015Release notes
Open source →- [BC break] Added
UserResponseInterface#getFirstName()method, also a new default pathfirstnamewas added, this path holds the first name of user, - [BC break] Added
UserResponseInterface#getLastName()method, also a new default pathlastnamewas added, this path holds the last name of user, - [BC break] Added
UserResponseInterface::getOAuthToken()& basic implementation inAbstractUserResponse, - [BC break]
GenericOAuth1ResourceOwner::getRequestToken()is now public method (was protected), - Added: configuration parameter
firewall_name(will be removed in next major version) renamed tofirewall_namesto support multiple firewalls, - Added: configuration parameter:
failed_auth_pathwhich contains route name, on which user will be redirected after failure when connecting accounts (i.e. user denies connection), - Added:
appsecret_prooffunctionality support to the Facebook resource owner, - Added:
sandboxfunctionality support to the Salesforce resource owner, - Added Auth0 resource owner,
- Added Azure resource owner,
- Added BufferApp resource owner,
- Added Deezer resource owner,
- Added Discogs resource owner,
- Added EveOnline resource owner,
- Added Fiware resource owner,
- Added Hubic resource owner,
- Added Paypal resource owner,
- Added Reddit resource owner,
- Added Runkeeper resource owner,
- Added Slack resource owner,
- Added Spotify resource owner,
- Added Soundcloud resource owner,
- Added Strava resource owner,
- Added Toshl resource owner,
- Added Trakt resource owner,
- Added Wechat resource owner,
- Added Wordpress resource owner,
- Added Xing resource owner,
- Added Youtube resource owner,
- Fixed: Revoking tokens for Facebook & Google resource owners,
- Fixed: Instagram allows only GET calls to fetch user details,
- Fixed:
ResourceOwnerMapno longer depends on deprecatedContainerAwareclass, - Fixed: Wrong usage of
json_decodein Mail.ru resource owner, - Fixed: Transform storage exceptions in OAuth1 resource owners into
AuthenticationException - Fixed: Default scopes & fields for VKontakte resource owner
- [BC break] Added
-
0.3.928 Aug 2015Release notes
Open source →- Fix: Remove deprecated Twig features
- Fix: Undefined variable in
FOSUBUserProvider::refreshUser - Fix: Restore property accessor for Symfony 2.3
-
0.3.804 May 2015Release notes
Open source →- Fix: Remove BC break for Symfony < 2.5,
- Fix: Compatibility issues with Symfony 2.6+,
- Fix: Deprecated graph URLs for
FacebookResourceOwner
-
0.3.715 Nov 2014Release notes
Open source →- Fix:
SessionStorage::save()could throw php error, - Fix:
OAuthToken::isExpired()always returnedfalse, - Fix:
FoursquareResourceOwner,TwitchResourceOwner,SensioConnectResourceOwnernot working with bearer header, - Fix: Don't use deprecated fields in
FacebookResourceOwner, - Fix:
FOSUBUserProvider::refreshUser()always returning old user,
- Fix:
-
0.3.602 Jun 2014Release notes
Open source →- Fix:
InstagramResourceOwnerregression while getting user details, - Fix: Add smooth migration for session (de)serialization
- Fix:
-
0.3.530 May 2014Release notes
Open source →- Fix:
LinkedinResourceOwnerregression while getting user details, - Fix: OAuth
revokefunctionality to be available wider, - Fix: Removed undocumented functionality from
SinaWeiboResourceOwner, - Fix: Always remove default ports from URLs to match OAuth 1.0a, Spec: 9.1.2
- Fix:
-
0.3.412 May 2014Release notes
Open source →- Fix: Instagram OAuth redirect to one url,
- Fix:
FOSUBUserProvidershould also implementUserProviderInterface, - Fix:
YahooResourceOwnerinfos_urlto use new format, - Fix: Send authorization via headers instead of URL parameter,
- Fix:
GithubResourceOwnerrevoke method, - Fix: Add login routing documentation note
-
0.3.317 Feb 2014Release notes
Open source →- Fix: Incorrect redirect URL when no parameters are set,
- Fix: Add missing parameter
promptforGoogleResourceOwner, - Fix:
WordpressResourceOwneruser details API call, - Fix: PHP Notice when
oauth_callback_confirmedwas set toofalse, - Fix: PHP Fatal when session returns boolean instead of object,
- Fix: Add missing query parameters for
FacebookResourceOwner
-
0.3.207 Feb 2014Release notes
Open source →- Fix: Prevent
SessionUnavailableExceptionwhen returns back from service, - Fix:
EntityUserProvidershould implementUserProviderInterface, - Fix:
createdAtproperty was missing when serializing theOAuthToken, - Added Italian translations
- Fix: Prevent
-
0.3.117 Jan 2014Release notes
Open source →- Fix: Change Twitter API call to use SSL URL,
- Fix: Problems with options in
VkontakteResourceOwner, - Fix: Problems with OAuth 1.0a token &
YahooResourceOwner, - Fix: Throw exception in
FOSUBUserProviderwhen username is missing - Added SalesForce resource owner
-
0.3.028 Sep 2013Release notes
Open source →- [BC break]
AccountConnectorInterface::connect()method now requires the first parameter to be instance ofSymfony\Component\Security\Core\User\UserInterface - [BC break]
ConnectController::authenticateUser()method now requires the first parameter to be instance ofSymfony\Component\HttpFoundation\Request - [BC break] Removed
AbstractResourceOwner::addOptions()method - [BC break]
OAuthUtils::getAuthorizationUrl()&OAuthUtils::getLoginUrl()methods now expect first parameter to be instance ofSymfony\Component\HttpFoundation\Request - [BC break] LinkedIn resource owner now uses OAuth2 approach, visit official web page for details how to migrate: https://developer.linkedin.com/documents/authentication#migration
- [BC break] Dropbox resource owner now uses OAuth2 approach
- Added ability to merge response parts into single path
- Added Bitly resource owner
- Added Box resource owner
- Added Dailymotion resource owner
- Added DeviantArt resource owner
- Added Eventbrite resource owner
- Added Mail.ru resource owner
- Added Sina Weibo resource owner
- Added QQ.com resource owner
- Added Trello resource owner
- Added Wordpress resource owner
- [BC break]
-
0.3.0-alpha229 Jul 2013 pre-releaseRelease notes
Open source →- [BC break] Added
ResourceOwnerInterface::isCsrfTokenValid()method - [BC break] Removed
OAuth1RequestTokenStorageInterfacealong with the implementations - [BC break]
AbstractResourceOwner::__construct()now requiresRequestDataStorageInterfaceinstance as last argument - Fix: Yandex resource owner using invalid parameter when requesting user data
- Fix: To prevent unusual content headers response from resource owners should be first threaten as json and only in case of failure threaten as query text
- Fix: Instagram resource owner is not able to receive user data more than once
- Added ability to disable confirmation page when connecting accounts
- Added CSRF protection for OAuth2 providers (turned off by default)
- Added
RequestDataStorageInterfacealong with implementation - Added Stereomood resource owner
- [BC break] Added
-
0.3.0-alpha103 Jul 2013 pre-releaseRelease notes
Open source →- [BC break]
GenericOAuth2ResourceOwner::getAccessToken()now returns an array instead of a string. This array contains the access token and its 'expires_in' value, along with any other parameters returned from the authentication provider - [BC break] Added
OAuthAwareExceptionInterface#setToken(),OAuthAwareExceptionInterface#getRefreshToken(),OAuthAwareExceptionInterface#getRawToken(),OAuthAwareExceptionInterface#getExpiresIn()methods - [BC break] Renamed
AbstractResourceOwner::doGetAccessTokenRequesttodoGetTokenRequest - [BC break] Removed
AdvancedPathUserResponse&AdvancedUserResponseInterface - [BC break] Added
UserResponseInterface#getEmail(),UserResponseInterface#getProfilePicture(),UserResponseInterface#getRefreshToken(),UserResponseInterface#getExpiresIn(),UserResponseInterface#setOAuthToken()methods - [BC break] Removed
UserResponseInterface::setAccessToken()method - [BC break] Removed
AbstractUserResponse::getOAuthToken()method because it was ambiguous - [BC break]
PathUserResponse#setPaths()method no longer overwrite default paths - [BC break]
PathUserResponse#getPath()method no longer throws an exception if path not exists - [BC break]
PathUserResponse#getValueForPath()removed second argument from this method, it will not throw exception anymore if response or value is missing, but now will returnnullinstead - [BC break] Added
ResourceOwnerInterface#getOption($name)method - [BC break]
ResourceOwnerInterface#getUserInformation()now must receive array ($accessToken) as first parameter, also added second parameter ($extraParameters) to be consistent along all implementations - Added
OAuthToken::getRefreshToken(),OAuthToken::setRefreshToken(),OAuthToken::getExpiresIn(),OAuthToken::setExpiresIn(),OAuthToken::getRawToken(),OAuthToken::setRawToken() - Added
AbstractResourceOwner#addOptions()&ResourceOwnerInterface#setOption($name, $value)methods which allows easy overwriting resource specific options - Added support for options:
access_type,request_visible_actions,approval_prompt&hdin Google resource owner - Added 37signals resource owner
- Added Amazon resource owner
- Added Bitbucket resource owner
- Added Disqus resource owner
- Added Dropbox resource owner
- Added Flickr resource owner
- Added Instagram resource owner
- Added Odnoklassniki resource owner
- Added Yandex resource owner
- [BC break]
-
0.2.1009 Dec 2013Release notes
Open source →- Fix: use
Symfony\Component\Security\Core\User\UserInterfaceinEntityUserProvider::refreshUser - Fix: made
SessionStoragecompatible with Symfony 2.0
- Fix: use
-
0.2.925 Sep 2013Release notes
Open source →- Fix: Regression done in version
0.2.8blocking usage withoutFOSUserBundle - Fix:
OAuthUtils::getAuthorizationUrl()ignoring given redirect URL
- Fix: Regression done in version
-
0.2.819 Sep 2013Release notes
Open source →- Fix: Added missing parts in user providers like:
loadUserByUsername()orrefreshUser()methods - Fix: Registering of user provider services
- Fix: Make
OAuthUtils::signRequest()compatible with OAuth1.0a specification
- Fix: Added missing parts in user providers like:
-
0.2.703 Aug 2013Release notes
Open source →- Fix: Polish oauth error detection to cover cases from i.e. Facebook resource owner
- Fix: Changed authorization url for Vkontakte resource owner
-
0.2.624 Jun 2013Release notes
Open source →- Fix: Use same check for FOSUserBundle compatibility to prevent strange errors with calls of undefined services
- Fix: User-land aliased (resource owner) services have the appropriate name
-
0.2.529 May 2013Release notes
Open source →- Fix: Use user identifier represented as string for Twitter to prevent issues with losing accuracy for large numbers (i.e. Javascript) or type comparison (i.e. MongoDB)
- Fix: Don't depend on
arg_separator.outputdata for URL generation to prevent issues
-
0.2.415 May 2013Release notes
Open source →- Fix: Throw
Symfony\Component\Security\Core\Exception\AccessDeniedException&Symfony\Component\HttpKernel\Exception\NotFoundHttpExceptioninstead of\Exceptionto make cases more clear - Fix: Detect
oauth_problemas authorization error and inform user instead logging error in background - Fix: Request extra parameters should have higher priority than default
- Fix: How urls are build in resource owners
- Fix: Missing parameter in
YahooResourceOwner
- Fix: Throw
-
0.2.306 May 2013Release notes
Open source →- Added
AbstractUserResponse::getOAuthToken()method to allow fetching only OAuth token details - Added french translation
- Fix: FB incompatibility with 'error' field in response
- Added
-
0.2.215 Apr 2013Release notes
Open source →- Fix: FOSUB registration form handler
- Fix: Use API 1.1 for Twitter, not the deprecated 1.0
-
0.2.127 Mar 2013 -
0.2.026 Mar 2013Release notes
Open source →- Added support for a
target_path_parameterin order to control the redirect path after login - Added
hwi_oauth_authorization_url()twig helper function - Added Jira resource owner
- Added Yahoo resource owner
- Added setting
realmin configuration - Added support for FOSUserBundle 2.x integration
- Added Stack Exchange resource owner
- Fix: configuration parameter
firewall_nameis required - Fix: prevent throwing
AlreadyBoundExceptionwhen using FOSUserBundle 1.x integration - Fix: check for availability of
profilePicturein views before calling it - Fix:
InMemoryProvidernow shows user nickname as name instead of unique identifier - Fix: don't set
realmoption if is empty in request headers - Fix: for infinity loop blockade and error token response handling
- Added support for a
-
0.1-alpha14 Aug 2012Release notes
Open source →- [BC break] Renamed path
usernametoidentifierto make it more clear that this path should hold the unique user identifier (previouslyusername) - [BC break] Method
UserResponseInterface#getUsername()now always returns a real unique user identifier, and uses pathidentifier - [BC break]
OAuth1RequestTokenStorageInterface#save()second param$tokenmust now be an array - [BC break] Configuration type 'generic' is renamed to 'oauth2'
- [BC break]
redirect.xmlrouting has to be imported. See the setup docs - Added
UserResponseInterface#getRealName()method, also a new default pathrealnamewas added, this path holds the real name of user - Added
UserResponseInterface#getNickName()method, also a new default pathnicknamewas added, this path holds the nickname of user - Added
UserResponseInterface#getAccessToken()andUserResponseInterface#setAccessToken - Added
OAuthToken#getCredentials()returns an empty string to be consistent with the security component. The access token can still be retrieved from thegetAccessToken()method - Added change that forces all authentication requests are now redirected to the login path
- Added change that makes
firewall_nameoption required setting - Added OAuth 1.0a support (linkedin/twitter/generic)
- [BC break] Renamed path