NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1870 most downloaded on Packagist
🔑 Nette Security: provides authentication, authorization and a role-based access control management via ACL (Access Control List)
Last release 2 months ago
24 Jul 2026
Release timing varies
gaps range from 2 weeks to 13 months
Some releases are documented
notes for 9 of 34 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
34 releases · first in 2014
Hashed passwords in SimpleAuthenticator – stored passwords may now be crypt-format hashes (anything password_hash() produces) and can be freely mixed
SimpleAuthenticator – stored passwords may now be crypt-format hashes (anything password_hash() produces) and can be freely mixed with plain-text ones. The format is detected automatically, so hashes just work in the security: users: config section with no extra option. A hash whose algorithm the PHP build doesn't know fails closed instead of being compared as plain text, and plain-text comparison is timing-safe.Passwords::bcrypt() and Passwords::argon2id() – name the algorithm instead of juggling PASSWORD_* constants and options arrays: Passwords::bcrypt(12) or Passwords::argon2id(memoryCost: 65536). Omitted parameters keep PHP's defaults, and argon2id() fails with a clear exception on builds without Argon2 support.rules section lets you define permissions declaratively next to your roles and resources:
security:
rules:
allow:
- [guest, article, view]
- [registered, comment, [add, edit]]
- [admin]
deny:
- [banned, comment, add][role(s), resource(s), privilege(s)]; an omitted or null item means "all", and a bare string grants or revokes everything for that role. Malformed rules are rejected at config time, not at runtime.logout() no longer touches the storage when there is nothing to change, so logging out a guest doesn't needlessly regenerate the session ID or overwrite the logout reason. A stored authentication vetoed by wakeupIdentity() (a revoked token, say) is still properly cleared.Permission::isAllowed() now saves and restores the queried role and resource, making it re-entrant and exception-safe – an assertion callback can call isAllowed() again without corrupting the results of the outer query.One column per quarter.
fixed compatibility with nette/http 3.4
Guest identity – an IdentityHandler authenticator may now implement getGuestIdentity(): ?IIdentity to hand anonymous visitors a real identity. When pr
Guest identity – an IdentityHandler authenticator may now implement getGuestIdentity(): ?IIdentity to hand anonymous visitors a real identity. When present, getIdentity(), getId() and getRoles() transparently fall back to it, so guests carry their own roles and data instead of just the $guestRole string. The guest identity is resolved on read only and never written to storage.
$persistIdentity – the new User::$persistIdentity property lets you decide what happens to the identity after logout or expiration. It stays available for personalization by default; flip it to false and getIdentity()/getId() return null once the user is no longer logged in. Configurable straight from the security.authentication DI section.
SessionStorage no longer refreshes the sliding expiration timestamp once the session has already expired – an expired identity stays expired instead of being silently kept alive for another round
Adopted nette/phpstan-rules and made static analysis a mandatory part of the build, then resolved the errors it surfaced
Improved phpDoc types and descriptions across the codebase
Nothing published for this version
optimized global function calls
SecurityExtension: password can be dynamic #74
removed deprecated IUserStorage (BC break)
used #[\SensitiveParameter] to mark sensitive parameters
composer: allows nette/utils 4.0
CookieStorage: getState returns the previously set ID #67
SessionStorage::setExpiration() does not overwrite data in the sessionverifyPassword()Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →