NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1421 most downloaded on Packagist
Laravel wrapper for PHP GraphQL
Last release today
07 Oct 2026
Release timing varies
gaps range from 2 weeks to 5 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
102 releases · first in 2017
Fix privacy fields using configured default resolver by @mfn in #1280
GraphQLController resolves the schema from the URL-decoded request path, matching how the router matched it #1282 / pawell67One column per quarter.
This is the stable release of the 10.x series.
This is the stable release of the 10.x series.
Version 10 focuses on safer production defaults, cleaner core architecture, and moving the optional Eloquent query-selection machinery into its own package.
Before upgrading, read the Upgrade Guide. For the complete RC-by-RC history and pull request references, see the Changelog.
SelectFields is no longer part of core.
If you use SelectFields, install the new package:
composer require rebing/graphql-laravel-select-fieldsFor most users, this is enough. The package keeps the original namespaces and reads the same field config keys such as model, alias, selectable, always, is_relation, and query.
Core removals related to this extraction:
Rebing\GraphQL\Support\SelectFields removed from coreClosure type-hint in resolve() no longer auto-injects a SelectFields factory unless the external package is installedField::selectFieldClass() removedField::instanciateSelectFields() removedVersion 10 changes several defaults to be safer for production deployments:
POST onlybatching.max_batch_size, default 1013500authorize() must return exactly trueIf you previously relied on open defaults, explicitly configure them during upgrade.
To re-enable introspection, for example in development:
GRAPHQL_DISABLE_INTROSPECTION=falseTo re-enable GET requests:
'method' => ['GET', 'POST'],If you enable GET, also enable ReadOnlyOperationMiddleware after AutomaticPersistedQueriesMiddleware so mutations and subscriptions are rejected on GET requests.
Privacy::validate() now receives the parent/root object and field arguments:
-public function validate(array $queryArgs, $queryContext = null): bool
+public function validate(mixed $root, array $fieldArgs, mixed $queryContext = null, ?ResolveInfo $resolveInfo = null): boolPrivacy closures receive the same shape:
-'privacy' => function (array $args, $ctx): bool {
+'privacy' => function (mixed $root, array $args, $ctx, ?ResolveInfo $info = null): bool {The old first argument represented root query arguments. The new $fieldArgs contains the field's own arguments.
Resolver middleware now declares native mixed parameter and return types. Custom middleware overriding handle() must match:
-public function handle($root, array $args, $context, ResolveInfo $info, Closure $next)
+public function handle(mixed $root, array $args, mixed $context, ResolveInfo $info, Closure $next): mixedauthorize() signature changedThe unused $getSelectFields parameter was removed:
-public function authorize($root, array $args, $ctx, ?ResolveInfo $resolveInfo = null, ?Closure $getSelectFields = null): bool
+public function authorize($root, array $args, $ctx, ?ResolveInfo $resolveInfo = null): boolVersion 10 adds tracing infrastructure with an OpenTelemetry driver.
New tracing components include:
TracingDriverTracingManagerTracingExecutionMiddlewareTracingResolverMiddlewareOpenTelemetryTracingDriverTracing is disabled by default and can be enabled globally or per schema.
A new opt-in HTTP middleware is available:
Rebing\GraphQL\Support\Middleware\CsrfGuard::classUse this for GraphQL endpoints that rely on cookie/session authentication, including Laravel session auth or Sanctum cookie mode.
A new opt-in execution middleware rejects mutations and subscriptions submitted through GET:
Rebing\GraphQL\Support\ExecutionMiddleware\ReadOnlyOperationMiddleware::classThis is especially relevant if you enable GET for CDN-cacheable persisted queries.
External packages can now hook into resolver parameter injection through:
Rebing\GraphQL\Support\Contracts\ResolverParameterInjectorField::registerParameterInjector()Field::clearParameterInjectors()This is what allows the external SelectFields package to restore SelectFields injection without keeping it in core.
config() inside the config fileOperationParams now copies originalInput and readOnlyAddAuthUserContextValueMiddleware now resolves the guard from schema/global route configprivacy on nested/sub-type fields is now enforced through field resolversGraphQL::type() has a narrower PHPStan return typemake:graphql:executionMiddleware is now registered correctlywebonyx/graphql-php version is now ^15.31.0Stable release of the 10.x series.
No user-facing changes since 10.0.0-RC5. See the 10.0.0-RC1 through 10.0.0-RC5 entries below for the full set of breaking changes, additions, and fixes.
Warning Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
Warning
Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
ExecutionMiddleware\ReadOnlyOperationMiddleware rejects GET requests targeting mutations #1261 / mfnSupport\Middleware\CsrfGuard CSRF protection middleware #1265 / mfnExecutionMiddleware\AddAuthUserContextValueMiddleware now resolves the auth guard from the config #1262 / mfnBreaking changes
SelectFieldsextracted to separate package https://github.com/rebing/graphql-laravel-select-fields/
Rebing\GraphQL\Support\SelectFieldsclass removed from coreRebing\GraphQL\Support\Contracts\WrapTypeinterface removed from coreClosuretype-hint inresolve()no longer auto-injects SelectFields factoryField::selectFieldClass()andField::instanciateSelectFields()removed'selectable' => falseremoved from pagination type metadata fields- Generated query/mutation stubs no longer include SelectFields boilerplate
- Install
rebing/graphql-laravel-select-fieldsto restore all functionalityAdded
Rebing\GraphQL\Support\Contracts\ResolverParameterInjectorinterface for extensible resolver DIField::registerParameterInjector()/Field::clearParameterInjectors()for external DI hooks
Breaking changes
Privacy::validate()and closure signature changed #1251 / mfn
newmixed $rootfirst parameter, new optional?ResolveInfo $resolveInfofourth parameter,$queryContextnow typed asmixed- Remove
$getSelectFieldsparameter fromField::authorize()#1250 / mfn
it has been non-functional since half a decadeFixed
- Fix
SelectFieldscrashing when field types use callable #1252 / mfn- Fix APQ middleware race condition (TOCTOU) #1253 / mfn
- Fix
OperationParamsnot copyingoriginalInput/readOnly, causing TypeError #1254 / mfn- Fix APQ config not using
config()inside config file #1255 / mfn
Breaking changes
Privacy::validate()first parameter renamed from$queryArgsto$fieldArgs— it now receives the field's own arguments instead of root query argumentsSelectFieldsnow identifies wrapper types via theRebing\GraphQL\Support\Contracts\WrapTypemarker interface. Custom pagination types and wrap types used withSelectFieldsmust implement this interface. #1228 / mfnAdded
- Add tracing support with OpenTelemetry driver #1220 / mfn
Rebing\GraphQL\Support\Contracts\WrapTypemarker interface for wrapper types (pagination types and custom wrap types) #1228 / mfnFixed
- Narrow
GraphQL::type()PHPStan return type to(NullableType&Type)|NonNullso consumers can pass it toType::nonNull()without static analysis errors #1221 / mfn- Fix
SelectFieldsforcingselect *for Interface return types instead of selecting only the requested columns #683 / mfn- Fix
SelectFieldsnot calling customquerycallbacks on relation fields insideUnionTypemembers #900 / mfn- Fix cross-field validation rules (
prohibits,required_without,required_if, etc.) not working in nested InputTypes #930 / mfn- Fix
privacyattribute ignored on nested/sub-types by moving enforcement fromSelectFieldsto field resolvers inType::getFields()#1161 / mfn- Fix
SelectFieldsproducing emptySELECTclause for custom wrap types created viaGraphQL::wrapType()#1228 / mfn
Breaking changes
- Security hardening: safer defaults for production deployments #1210 / mfn
- Default HTTP method changed from
GET/POSTtoPOSTonly- Batching disabled by default (
batching.default→false)- Introspection disabled by default (
GRAPHQL_DISABLE_INTROSPECTIONenv var)- Default
query_max_depthset to13(was unlimited)- Default
query_max_complexityset to500(was unlimited)- Authorization now runs before validation in field resolver
- Authorization uses strict
=== truecomparisonAdded
- Added `max_batch_size` config option to limit batch query operations
Full Changelog: 10.0.0-RC4...10.0.0-RC5
Warning Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
Warning
Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
SelectFields extracted to separate package https://github.com/rebing/graphql-laravel-select-fields/
Rebing\GraphQL\Support\SelectFields class removed from coreRebing\GraphQL\Support\Contracts\WrapType interface removed from coreClosure type-hint in resolve() no longer auto-injects SelectFields factoryField::selectFieldClass() and Field::instanciateSelectFields() removed'selectable' => false removed from pagination type metadata fieldsrebing/graphql-laravel-select-fields to restore all functionalityRebing\GraphQL\Support\Contracts\ResolverParameterInjector interface for extensible resolver DIField::registerParameterInjector() / Field::clearParameterInjectors() for external DI hooksBreaking changes
Privacy::validate()and closure signature changed #1251 / mfn
newmixed $rootfirst parameter, new optional?ResolveInfo $resolveInfofourth parameter,$queryContextnow typed asmixed- Remove
$getSelectFieldsparameter fromField::authorize()#1250 / mfn
it has been non-functional since half a decadeFixed
- Fix
SelectFieldscrashing when field types use callable #1252 / mfn- Fix APQ middleware race condition (TOCTOU) #1253 / mfn
- Fix
OperationParamsnot copyingoriginalInput/readOnly, causing TypeError #1254 / mfn- Fix APQ config not using
config()inside config file #1255 / mfn
Breaking changes
Privacy::validate()first parameter renamed from$queryArgsto$fieldArgs— it now receives the field's own arguments instead of root query argumentsSelectFieldsnow identifies wrapper types via theRebing\GraphQL\Support\Contracts\WrapTypemarker interface. Custom pagination types and wrap types used withSelectFieldsmust implement this interface. #1228 / mfnAdded
- Add tracing support with OpenTelemetry driver #1220 / mfn
Rebing\GraphQL\Support\Contracts\WrapTypemarker interface for wrapper types (pagination types and custom wrap types) #1228 / mfnFixed
- Narrow
GraphQL::type()PHPStan return type to(NullableType&Type)|NonNullso consumers can pass it toType::nonNull()without static analysis errors #1221 / mfn- Fix
SelectFieldsforcingselect *for Interface return types instead of selecting only the requested columns #683 / mfn- Fix
SelectFieldsnot calling customquerycallbacks on relation fields insideUnionTypemembers #900 / mfn- Fix cross-field validation rules (
prohibits,required_without,required_if, etc.) not working in nested InputTypes #930 / mfn- Fix
privacyattribute ignored on nested/sub-types by moving enforcement fromSelectFieldsto field resolvers inType::getFields()#1161 / mfn- Fix
SelectFieldsproducing emptySELECTclause for custom wrap types created viaGraphQL::wrapType()#1228 / mfn
Breaking changes
- Security hardening: safer defaults for production deployments #1210 / mfn
- Default HTTP method changed from
GET/POSTtoPOSTonly- Batching disabled by default (
batching.default→false)- Introspection disabled by default (
GRAPHQL_DISABLE_INTROSPECTIONenv var)- Default
query_max_depthset to13(was unlimited)- Default
query_max_complexityset to500(was unlimited)- Authorization now runs before validation in field resolver
- Authorization uses strict
=== truecomparisonAdded
- Added `max_batch_size` config option to limit batch query operations
Full Changelog: 10.0.0-RC3...10.0.0-RC4
Warning Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
Warning
Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
Privacy::validate() and closure signature changed #1251 / mfnmixed $root first parameter, new optional ?ResolveInfo $resolveInfo fourth parameter, $queryContext now typed as mixed$getSelectFields parameter from Field::authorize() #1250 / mfnSelectFields crashing when field types use callable #1252 / mfnOperationParams not copying originalInput/readOnly, causing TypeError #1254 / mfnconfig() inside config file #1255 / mfnBreaking changes
Privacy::validate()first parameter renamed from$queryArgsto$fieldArgs— it now receives the field's own arguments instead of root query argumentsSelectFieldsnow identifies wrapper types via theRebing\GraphQL\Support\Contracts\WrapTypemarker interface. Custom pagination types and wrap types used withSelectFieldsmust implement this interface. #1228 / mfnAdded
- Add tracing support with OpenTelemetry driver #1220 / mfn
Rebing\GraphQL\Support\Contracts\WrapTypemarker interface for wrapper types (pagination types and custom wrap types) #1228 / mfnFixed
- Narrow
GraphQL::type()PHPStan return type to(NullableType&Type)|NonNullso consumers can pass it toType::nonNull()without static analysis errors #1221 / mfn- Fix
SelectFieldsforcingselect *for Interface return types instead of selecting only the requested columns #683 / mfn- Fix
SelectFieldsnot calling customquerycallbacks on relation fields insideUnionTypemembers #900 / mfn- Fix cross-field validation rules (
prohibits,required_without,required_if, etc.) not working in nested InputTypes #930 / mfn- Fix
privacyattribute ignored on nested/sub-types by moving enforcement fromSelectFieldsto field resolvers inType::getFields()#1161 / mfn- Fix
SelectFieldsproducing emptySELECTclause for custom wrap types created viaGraphQL::wrapType()#1228 / mfn
Breaking changes
- Security hardening: safer defaults for production deployments #1210 / mfn
- Default HTTP method changed from
GET/POSTtoPOSTonly- Batching disabled by default (
batching.default→false)- Introspection disabled by default (
GRAPHQL_DISABLE_INTROSPECTIONenv var)- Default
query_max_depthset to13(was unlimited)- Default
query_max_complexityset to500(was unlimited)- Authorization now runs before validation in field resolver
- Authorization uses strict
=== truecomparisonAdded
- Added `max_batch_size` config option to limit batch query operations
Full Changelog: 10.0.0-RC2...10.0.0-RC3
Warning Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
Warning
Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
Privacy::validate() first parameter renamed from $queryArgs to $fieldArgs — it now receives the field's own arguments instead of root query argumentsSelectFields now identifies wrapper types via the Rebing\GraphQL\Support\Contracts\WrapType marker interface. Custom pagination types and wrap types used with SelectFields must implement this interface. #1228 / mfnRebing\GraphQL\Support\Contracts\WrapType marker interface for wrapper types (pagination types and custom wrap types) #1228 / mfnGraphQL::type() PHPStan return type to (NullableType&Type)|NonNull so consumers can pass it to Type::nonNull() without static analysis errors #1221 / mfnSelectFields forcing select * for Interface return types instead of selecting only the requested columns #683 / mfnSelectFields not calling custom query callbacks on relation fields inside UnionType members #900 / mfnprohibits, required_without, required_if, etc.) not working in nested InputTypes #930 / mfnprivacy attribute ignored on nested/sub-types by moving enforcement from SelectFields to field resolvers in Type::getFields() #1161 / mfnSelectFields producing empty SELECT clause for custom wrap types created via GraphQL::wrapType() #1228 / mfnBreaking changes
- Security hardening: safer defaults for production deployments #1210 / mfn
- Default HTTP method changed from
GET/POSTtoPOSTonly- Batching disabled by default (
batching.default→false)- Introspection disabled by default (
GRAPHQL_DISABLE_INTROSPECTIONenv var)- Default
query_max_depthset to13(was unlimited)- Default
query_max_complexityset to500(was unlimited)- Authorization now runs before validation in field resolver
- Authorization uses strict
=== truecomparisonAdded
- Added `max_batch_size` config option to limit batch query operations
Full Changelog: 10.0.0-RC1...10.0.0-RC2
Privacy::validate() first parameter renamed from $queryArgs to $fieldArgs — it now receives the field's own arguments instead of root query argumentsSelectFields now identifies wrapper types via the Rebing\GraphQL\Support\Contracts\WrapType marker interface. Custom pagination types and wrap types used with SelectFields must implement this interface. #1228 / mfnMiddleware::handle() and Middleware::resolve() now declare native mixed parameter and return typesGraphQL::prependGlobalResolverMiddleware() for resolver middleware that must run before field/global appended middleware #1220 / mfnRebing\GraphQL\Support\Contracts\WrapType marker interface for wrapper types (pagination types and custom wrap types) #1228 / mfnwebonyx/graphql-php version to ^15.31.0 #1246 / mfnGraphQL::type() PHPStan return type to (NullableType&Type)|NonNull so consumers can pass it to Type::nonNull() without static analysis errors #1221 / mfnmake:graphql:executionMiddleware Artisan command #1229 / mfnSelectFields forcing select * for Interface return types instead of selecting only the requested columns #683 / mfnSelectFields not calling custom query callbacks on relation fields inside UnionType members #900 / mfnprohibits, required_without, required_if, etc.) not working in nested InputTypes #930 / mfnprivacy attribute ignored on nested/sub-types by moving enforcement from SelectFields to field resolvers in Type::getFields() #1161 / mfnSelectFields producing empty SELECT clause for custom wrap types created via GraphQL::wrapType() #1228 / mfnThis release focuses on hardening the security defaults of this library for production deployments and hence comes with breaking changes:
Warning
Please also read https://github.com/rebing/graphql-laravel/blob/master/UPGRADE.md#upgrading-from-9-to-10
This release focuses on hardening the security defaults of this library for production deployments and hence comes with breaking changes:
GET/POST to POST onlybatching.default → false)
max_batch_size config option to limit batch query operationsGRAPHQL_DISABLE_INTROSPECTION env var)query_max_depth set to 13 (was unlimited)query_max_complexity set to 500 (was unlimited)=== true comparisonSee also the upgrade guide from 9 to 10.
For discussion, please use #1211
Full Changelog: 9.17.0...10.0.0-RC1
GET/POST to POST onlybatching.default → false)max_batch_size config option to limit batch query operationsGRAPHQL_DISABLE_INTROSPECTION env var)query_max_depth set to 13 (was unlimited)query_max_complexity set to 500 (was unlimited)=== true comparisongha: remove dev constraints by @mfn in #1215
Support PHPUnit 12 by @mfn in #1209
Full Changelog: 9.15.0...9.16.0
webonyx/graphql-php to ^15.22.1--oneof flag to make:graphql:input Artisan commandbuild(deps): bump actions/cache from 4 to 5 in the deps group by @dependabot [bot] in #1205
Full Changelog: 9.14.0...9.15.0
Fix exponential time complexity in AliasArguments with circular type references \#1195 / artem-schander
Allow field to be passed as instance \#1178 / alancolant
Fixed type declaration mismatch in scalar type classes generated by makescalar command by removing premature type hints from the stub \#1190 / iisyos
make:graphql:scalar command by removing premature type hints from the stub #1190 / iisyosAdd route_attributes support for GraphQL routes \#1186 / alissn
route_attributes support for GraphQL routes #1186 / alissnSupport Laravels cursor pagination \#1180 / Davidnadejdin
Support for Laravel 10 & PHP 8.1 have been removed \#1170 / mfn
Support for Laravel 12 \#1164 / duncanmcclean
Fixes for implicit nullability deprecation (PHP 8.4 compat) \#1152 / duncanmcclean
Bring back laravel-mongodb support \#1144 / jsrodas-pdpaola
Relax PaginationType/SimplePaginationType getPaginationFields typehint \#1132 / jasonvarga
Possibility to add resolver middleware at runtime using GraphQL::appendGlobalResolverMiddleware(YourMiddleware::class) or GraphQL::appendGlobalResolve
GraphQL::appendGlobalResolverMiddleware(YourMiddleware::class) or GraphQL::appendGlobalResolverMiddleware(new YourMiddleware(...))Support for Laravel 9 & PHP 8.0 have been removed \#1123 / mfn
Support Laravel for 11 \#1117 / mfn
fix schema validation - resolve not allowed in input fields \#1078 / crissi
Upgrade to graphql-php 15 \#953 / mfn\ This includes possible breaking changes also outside of this package, see also https://github.com/webonyx/graph…
Upgrade to graphql-php 15 #953 / mfn
This includes possible breaking changes also outside of this package, see also https://github.com/webonyx/graphql-php/releases/tag/v15.0.0
Known breaking changes:
errors.*.<non-standard error key> any more, but have been moved to
errors.*.extensions.<non-standard error key>.errors.*.extensions.category has been removed upstream, but we try to
keep it alive with the interface
\Rebing\GraphQL\Error\ProvidesErrorCategory as it can be a useful
discriminator on the client side in certain cases. But only the cases from
this library are preserved, e.g. categories like request, graphql or
internal are gone.\Rebing\GraphQL\Support\OperationParams has added required types due to
its base class changes:
public function getOriginalInput($key)public function getOriginalInput(string $key)public function isReadOnly()public function isReadOnly(): boolSome BC may happen also if you extended code originating in graphql-php, some examples:
$name or $description\GraphQL\Validator\DocumentValidator in your code
directly, you now need use FQCN to reference them and not the shortened
string names.->getWrappedType(true) was replaced with ->getInnermostType()\GraphQL\Type\Definition\FieldArgument has been renamed to
\GraphQL\Type\Definition\ArgumentPagination and SimplePagination helper types now enforce nonNull on their data types--prefer-lowest #1055 / mfnlaragraph/utils and webonyx/graphql-php
and thus their minimum version had to be slightly bumped to 2.0.1 and
15.0.3 respectively.Nothing published for this version
Nothing published for this version
Nothing published for this version
Add Laravel 10 support \#983 / jasonvarga
Add support for thecodingmachine/safe 2.4 \#961 / tranvantri
Register directives via schema config \#947 / sforward
Add support to use array in controller param in config \#906 / viktorruskai
controller param in config #906 / viktorruskaiFix schema parsing issue when route prefix is empty string \#890 / hello-liang-shan\ Note: this is a follow-up fix to #888
Fix "No configuration for schema '' found" when route prefix is empty string \#888 / hello-liang-shan
Support for Laravel 9 \#879 / mfn
Remove deprecated \Rebing\GraphQL\Support\Type::$inputObject and \Rebing\GraphQL\Support\Type::$enumObject properties \#752 / mfn\ Instead in your cod…
Rewrite and simplify how schemas are handled
\Rebing\GraphQL\GraphQL::$schemas now only holds Schemas and not a
mixture of strings or arrays\Rebing\GraphQL\GraphQL::schema() now only accepts a "schema name", but no
ad hoc Schema or "schema configs". To use ad hoc schemas, use
\Rebing\GraphQL\GraphQL::buildSchemaFromConfig() and
\Rebing\GraphQL\GraphQL::addSchema()\Rebing\GraphQL\GraphQL::queryAndReturnResult() (and thus also
\Rebing\GraphQL\GraphQL::query()) does not accept ad hoc schemas via
$opts['schema'] anymore; it now only can reference a schema via its name.\Rebing\GraphQL\GraphQL::addSchema() now only accept Schema objects,
where before it would support ad hoc schemas via array configuration.
Use \Rebing\GraphQL\GraphQL::buildSchemaFromConfig() for that now.\Rebing\GraphQL\GraphQL::getSchemaConfiguration() has been removed due to
the simplifications.\Rebing\GraphQL\GraphQL::getNormalizedSchemaConfiguration() does not
support ad hoc schemas anymore and only accepts the schema name.\Rebing\GraphQL\GraphQLServiceProvider::bootSchemas() has been removed due
to the simplifications.The following methods now take a \Illuminate\Contracts\Config\Repository as
second argument:
\Rebing\GraphQL\GraphQL::__construct\Rebing\GraphQL\GraphQLServiceProvider::applySecurityRulesAs part of moving the architecture to an execution based middleware approach, the following methods have been removed:
\Rebing\GraphQL\GraphQLController::handleAutomaticPersistQueries has been
replaced by the AutomaticPersistedQueriesMiddleware middleware\Rebing\GraphQL\GraphQLController::queryContext has been
replaced by the AddAuthUserContextValueMiddleware middlewarequeryContext to inject a custom context, you
now need to create your own execution middleware and add to your
configuration\Rebing\GraphQL\GraphQLController::executeQuery has become obsolete, no
direct replacement.Routing has been rewritten and simplified #757 / mfn
route
configuration keygraphql.routesgraphql.prefix => graphql.route.prefixgraphql.controllers => graphql.route.controllerquery or mutation is not
supported anymore.graphql.middleware => graphql.route.middlewaregraphql.route_group_attributes => graphql.route.group_attributes'method' argument must provide the HTTP method
verbs in uppercase like POST or GET, post or get will not work.route an empty array or null\Rebing\GraphQL\GraphQL::routeNameTransformer has been removed- in their nameRemove the \Rebing\GraphQL\GraphQLController::$app property #755 / mfn
Injecting the application container early is incompatible when running within
an application server like laravel/octane, as it's not guaranteed that the
container received contains all the bindings. If you relied on this property
when extending the classes, invoke the container directly via
Container::getInstance().
Remove deprecated \Rebing\GraphQL\Support\Type::$inputObject and \Rebing\GraphQL\Support\Type::$enumObject properties #752 / mfn
Instead in your code, extend \Rebing\GraphQL\Support\InputType and \Rebing\GraphQL\Support\EnumType directly
Support for Lumen has been removed
Integrate laragraph/utils RequestParser #739 / mfn
The parsing of GraphQL requests is now more strict:
GET request, the GraphQL query has to be in the query parametersPOST request, the GraphQL query needs to be in the bodyPOST requests
This is due to RequestParser using \GraphQL\Server\Helper::parseRequestParams which includes this check
Further:params_key)GraphQLUploadMiddleware has been removed (RequestParser includes this functionality)In \Rebing\GraphQL\GraphQL, renamed remaining instances of $params to $variables
After switching to RequestParser, the support for changing the variable name
what was supposed to params_key has gone and thus the name isn't fitting anymore.
Also, the default value for $variables has been changed to null to better
fit the how OperationParams works:
old: public function query(string $query, ?array $params = [], array $opts = []): array
new: public function query(string $query, ?array $variables = null, array $opts = []): array
old: public function queryAndReturnResult(string $query, ?array $params = [], array $opts = []): ExecutionResult
new: public function queryAndReturnResult(string $query, ?array $variables = null, array $opts = []): ExecutionResult
\Rebing\GraphQL\Support\ResolveInfoFieldsAndArguments has been removed
$getSelectFields closure no longer takes a depth parameter
The $args argument, of the handle method of the execution middlewares requires array as type.
'graphql' as alias #768 / mfnValidationException is now formatted the same way as a ValidationError #748 / mfnconfig() function and preferable use the repository or the Facade otherwise #774 / mfn$args argument, of the handle method of the execution middlewares requires array as type #843 / sforwardTypeNotFound when an interface defined after another type where it is used #828 / kasian-sergeev\Rebing\GraphQL\GraphQLServiceProvider::provides was removed #769 / mfnNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Allow disabling batched requests \#738 / mfn
Basic Automatic Persisted Queries (APQ) support \#701 / illambo
Support Laravels simple pagination \#715 / lamtranb
Signature of \Rebing\GraphQL\Support\Privacy::validate changed, now it accepts both query/mutation arguments and the query/mutation context. Update yo
\Rebing\GraphQL\Support\Privacy::validate changed, now it accepts both query/mutation arguments and the query/mutation context.
Update your existing privacy policies this way:-public function validate(array $queryArgs): bool
+public function validate(array $queryArgs, $queryContext = null): bool
Middleware and methods can be used in class based schemas. \#724 / jasonvarga\ This is a follow-up fix for Support for class based schemas
Support for per-schema types \#658 / stevelacey
Support for class based schemas \#706 / jasonvarga
Lumen routing with regular expression constraints \#719 / sglitowitzsoci
Support for resolver middleware \#594 / stevelacey
Support for resolver middleware \#594 / stevelacey
Implemented generation of a SyntaxError instead of a hard Exception for empty single/batch queries \#685 / plivius
Nothing published for this version
Upgrade to webonyx/graphql-php 14.0.0 \#645 / mfn Be sure to read up on breaking changes in graphql-php => https://github.com/webonyx/graphql-php/rele…
Implemented generation of a SyntaxError instead of a hard Exception for empty single/batch queries \#685 / plivius
### Added - Support for PHP 8 \#686 / mfn
Hotfix release to replace 5.1.3
Hotfix release to replace 5.1.3
Apologies for the rushed 5.1.3 release causing trouble, it was in fact cut from the wrong branch and it was current state for the upcoming 6.x series 😬
5.1.4 intends to correct this.
### Added - Support Laravel 8 \#671 / mfn
Re-added support for validation in field arguments (with breaking change fix) \#630 / crissi
Your coding agent can read these notes before it upgrades. Set up the MCP server →