NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1266 most downloaded on Packagist
WebDAV Framework for PHP
Last release 3 months ago
07 Jul 2026
Release timing varies
gaps range from 8 days to 1.7 years
Nearly every release is documented
notes for 57 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
125 releases · first in 2012
4.7.1 (2026-07-07) #1561 Refactor ternary to elvis operator where possible ( @ChristophWurst ) #1562 refactor: Change class strings to ::class constan
One column per quarter.
Supports PHP 7.1 to 8.4 inclusive.
Supports PHP 7.1 to 8.4 inclusive.
4.6.0 (2023-12-11) #1526 : feat: add propFindUnfiltered public method to Client ( @phil-davis )
4.5.1 (2023-11-23) #1514 : fix: restore autoPrefix property of Href ( @phil-davis )
4.5.0 (2023-11-14) #1488 : fix: The WebDAV response element must only contain propstat OR status element(s) ( @susnux ) #1481 : docs: fix type definit
propstat OR status element(s) (@susnux)4.4.0 (2022-06-27) #1396 : Include "before" and "after" copy events ( @jvillafanez ) #1404 : Fix encoding detection on PHP 8.1 ( @come-nc )
4.3.1 (2022-01-20) #1385 : fix: ensure first argument on strpos is a string ( @DeepDiver1975 )
4.3.0 (2021-12-14) #1284 : A more secure and generalized approach for PDO Basic Auth Backend ( @lightbluetom )
Note: the change in #1365 was not strictly backward-compatible (BC). This release reverts that change, so that the 4.2.* patch release series is truly
Note: the change in #1365 was not strictly backward-compatible (BC). This release reverts that change, so that the 4.2.* patch release series is truly BC.
4.2.2 (2021-12-09) #1248 : CalDAV to sync properly when limit is set in PDO backend ( @nhirokinet ) #1365 : add params for put interface ( @yrong ) #1
* #1371: Fix phpdoc return type of findByUri in BackendInterface (@come-nc)
* #1317: Add primary key to schedulingobjects table in pgsql.calendars.sql example (@perguth) * #1335: don't remove lock on dir when deleting a child
* #1322: Fixes for addressbook-query filters (@mstilkerich) * #1329: Correctly process a POST with no Content-Type specified plus phpstan level 1 (@ph
* #1312: Reduce package size by ignoring test and other non-run-time files * #1316: Minor code changes for latest PHP cs-fixer * #1319: Fix "Trying to
* #1306: Return 409 when trying to PUT a file into a non-existent collection
* #1296: Add experimental support for PHP 8.0
Allow using custom SAPI implementations
CalDAV: send MIME-Version header in scheduling emails
DAV: Streaming PROPFIND server implementation
CardDAV: Fix content-type for Thunderbird
TemporaryFileFilterPlugin: Fix Strict Error
Lock: Support lock timeout value Infinity
strict_types in every php file.WildcardEmitter. This allows event
handlers to listen to events using a wildcard.beforeMethod or method
no longer get called. They must listen to beforeMethod:* and method:* now.Lock: Support lock timeout value Infinity
Fix issues with empty content-type header
Fix for litmus test suite - test case: props propfind_invalid2
* Fixes for PHP 7.3 * Depend on sabre/http 5.0
* Now supports PHP 7.3
Added Sabre\DAV\Server::start(). This replaces ::exec(). ::exec() is now deprecated, but we're keeping it around for a year or two to make the transit…
Sabre\DAV\Server::start(). This replaces ::exec(). ::exec()
is now deprecated, but we're keeping it around for a year or two to make
the transition easier.getChildren() function in any collection may now return an iterator
instead of an array. This can result in memory savings for large
collections.Tree::getChildren() now returns an Iterator instead of an array.$overrideName to all Sabre\DAV\FS and Sabre\DAV\FSExt classes,
so users can specify under what name these nodes show up in the tree.* #982: Make sure that files that are siblings of directories, are reported as files (@nickvergessen)
The zip release ships with [sabre/vobject 4.1.2][vobj], [sabre/http 4.2.2][http], [sabre/event 3.0.0][evnt], [sabre/uri 1.2.0][uri] and [sabre/xml 1.5
The zip release ships with [sabre/vobject 4.1.2][vobj], [sabre/http 4.2.2][http], [sabre/event 3.0.0][evnt], [sabre/uri 1.2.0][uri] and [sabre/xml 1.5
The default ACL rules allow an unauthenticated user to read information about nodes that don't have their own ACL defined. This was a security problem
The zip release ships with [sabre/vobject 4.1.0][vobj], [sabre/http 4.2.1][http], [sabre/event 3.0.0][evnt], [sabre/uri 1.1.0][uri] and [sabre/xml 1.4
Removed deprecated function: Sabre\DAV\Auth\Plugin::getCurrentUser().
./bin/migrateto32.php for more info.Sabre\DAV\Auth\Plugin::getCurrentUser().{DAV:}unauthorized and {DAV:}all
privileges. This allows you to assign a privilege to a resource, allowing
non-authenticated users to access it. For instance, this could allow you
to create a public read-only collection.Content-Disposition header. (@Xenopathic).Href object before, it's behavior
now changed a bit, and LocalHref was added to replace the old, default
behavior of Href. See the migration doc for more info.Sabre\DAVACL\Plugin::$allowAccessToNodesWithoutACL setting.
Instead, you can provide a set of default ACL rules with
Sabre\DAVACL\Plugin::setDefaultAcl().Sabre\DAVACL\ACLTrait which contains a default implementation
of Sabre\DAV\IACL with some sane defaults. We're using this trait all over
the place now, reducing the amount of boilerplate.groupwareserver.php
example.{DAV:}all privilege is now no longer abstract, so it can be assigned
directly. We're using the {DAV:}all privilege now in a lot of cases where
we before assigned both {DAV:}read and {DAV:}write.{DAV:}bind and
{DAV:}unbind privileges.UNLOCK no longer requires the {DAV:}write-content privilege.getPrincipalByUri plugin event. Allowing plugins to request
quickly where a principal lives on a server.phpunit.xml to phpunit.xml.dist to make local modifications easy.IShareableCalendar is merged into ISharedCalendar.MKCOL requests.principal-match ACL REPORT.acl-principal-prop-set ACL REPORT.firstoccurence field in MySQL CalDAV backend. This
should speed up common calendar-query requests.read-free-busy privilege on individual
calendars during freebusy operations in the scheduling plugin. Instead, we
check the schedule-query-freebusy privilege on the target users' inbox,
which validates access for the entire account, per the spec.Fixed: Creating a new calendar on some MySQL configurations caused an error.
The zip release ships with [sabre/vobject 4.1.0][vobj], [sabre/http 4.2.1][http], [sabre/event 3.0.0][evnt], [sabre/uri 1.1.0][uri] and [sabre/xml 1.4
master: Return vCards exactly as they were stored if
we don't need to convert in between versions. This should speed up many
large addressbook syncs sometimes up to 50%.Set minimum libxml version to 2.7.0 in composer.json.
composer.json.components column was 1 byte too small.Faster XML parsing and generating due to sabre/xml update.
The zip release ships with [sabre/vobject 4.0.2][vobj], [sabre/http 4.2.1][http], [sabre/event 3.0.0][evnt], [sabre/uri 1.0.1][uri] and [sabre/xml 1.3
Better error message when the browser plugin is not enabled.
utf8mb4 character set, allowing you to
use emoji in some tables where you couldn't before.Sabre\DAV\Tree::getChildren() were properly cached.Client::propPatch. We're now throwing
exceptions.Client:propFind, we're now
throwing Sabre\HTTP\ClientHttpException instead of Sabre\DAV\Exception.
This new exception contains a LOT more information about the problem.COPY requests.
Before this subtle bugs could appear that could cause data-loss.User-Agent.Massive calendars and addressbooks should see a big drop in peak memory usage.
simplefsserver.php example file. It's not simple enough.supported-calendar-component-set.{DAV:}prop. This
fixes issues when using sabre/dav as a client.Upgraded to vobject 4, which is a lot faster.
calendar-availability, draft 05.
[reference][calendar-availability].Set minimum libxml version to 2.7.0 in composer.json.
composer.json.components column was 1 byte too small.Faster XML parsing and generating due to sabre/xml update.
The zip release ships with [sabre/vobject 3.5.0][vobj], [sabre/http 4.2.1][http], [sabre/event 2.0.2][evnt], [sabre/uri 1.0.1][uri] and [sabre/xml 1.3
The zip release ships with [sabre/vobject 3.4.8][vobj], [sabre/http 4.1.0][http], [sabre/event 2.0.2][evnt], [sabre/uri 1.0.1][uri] and [sabre/xml 1.3
utf8mb4 character set, allowing you to
use emoji in some tables where you couldn't before.Sabre\DAV\Tree::getChildren() were properly cached.418 I'm a Teapot when generating a multistatus response that
has resources with no returned properties.migrate20.php script.The zip release ships with [sabre/vobject 3.4.7][vobj],
The zip release ships with [sabre/vobject 3.4.7][vobj], [sabre/http 4.1.0][http], [sabre/event 2.0.2][evnt], [sabre/uri 1.0.1][uri] and [sabre/xml 1.2
supported-calendar-component-set.{DAV:}prop. This
fixes issues when using sabre/dav as a client.MOVE request that gets prevented from deleting the source resource
will still remove the target resource. Now all events are triggered before
any destructive operations.Fixed example files to no longer use now-deprecated realm argument.
HEAD requests.Fixed a whole bunch of incorrect php docblocks.
The zip release ships with [sabre/vobject 3.4.5][vobj], [sabre/http 4.0.0][http], [sabre/event 2.0.2][evnt], [sabre/uri 1.0.1][uri] and [sabre/xml 1.1
Depth: infinity in a PROPFIND request.{DAV:}href properties.The zip release ships with [sabre/vobject 3.4.5][vobj], [sabre/http 4.0.0][http], [sabre/event 2.0.2][evnt], [sabre/uri 1.0.1][uri] and [sabre/xml 1.0
Fixed deserializing href properties with no value.
{DAV:}propstat without a {DAV:}prop.A node's properties should not overwrite properties that were already set.
migrate22.php is now called migrate30.php.
migrate22.php is now called migrate30.php.share request parser.Prefer header syntax, as defined in
[rfc7240][rfc7240].It's now possible to get all property information from files using the browser plugin.
{DAV:}acl property.Sabre\DAVACL\FS\HomeCollection for automatically
creating a private home collection per-user.VARCHAR to VARBINARY where possible.The zip release ships with [sabre/vobject 3.5.3][vobj], [sabre/http 3.0.5][http], and [sabre/event 2.0.2][evnt].
components column was 1 byte too small.The zip release ships with [sabre/vobject 3.5.0][vobj], [sabre/http 3.0.5][http], and [sabre/event 2.0.2][evnt].
The zip release ships with [sabre/vobject 3.5.0][vobj], [sabre/http 3.0.5][http], and [sabre/event 2.0.2][evnt].
The zip release ships with [sabre/vobject 3.4.8][vobj], [sabre/http 3.0.5][http], and [sabre/event 2.0.2][evnt].
migrate20.php script.Your coding agent can read these notes before it upgrades. Set up the MCP server →