NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #5398 most downloaded on Packagist
User module
Last release 6 days ago
02 Oct 2026
Ships fairly regularly
a new release about every 2 months
Some releases are documented
notes for 15 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
81 releases · first in 2016
Included commits: 3.35.1...3.35.2
Included commits: 3.35.1...3.35.2
PageObject test support directory to autoload.psr-4 in composer.json to publish it to consumers of the module.Included commits: 3.35.0...3.35.1
Included commits: 3.35.0...3.35.1
spryker/gui version constraint to ^5.8.0 to align with the Back Office frontend builder moved into the Gui module.One column per quarter.
Included commits: 3.34.0...3.35.0
Included commits: 3.34.0...3.35.0
UserConstants::PASSWORD_HASH_COST and UserConfig::getPasswordHashCost() to make the bcrypt cost factor for Zed user passwords configurable, lowering hashing time in test environments.User::isRawPassword() and UserConfig::getUserFromGlobalConfig() from private to protected.Included commits: 3.33.0...3.34.0
Included commits: 3.33.0...3.34.0
CurrentUserDataRequestProcessorPlugin::__invoke() and CurrentUserDataRequestLogProcessor::__invoke() to accept \Monolog\LogRecord in addition to an array, restoring current-user request-data enrichment in logs under Monolog 3.UserForm::createUniqueEmailConstraint() to construct the Callback constraint using named arguments instead of an options array, for Symfony 7 compatibility.Included commits: 3.32.0...3.33.0
Included commits: 3.32.0...3.33.0
UserIdentityRequestSubscriber in the Glue layer, which resolves the user behind a Backend API access token and publishes it as Zed's current user, so Persistent ACL and ACL rule checks resolve the acting user on Backend API requests.401, a token whose claims identify no user is not looked up, and one whose claims identify several users is refused.UserDependencyProvider::getUserIdentityCriteriaExpanderPlugins(), the plugins that decide how a token's claims identify the user. The id_user claim is the default and applies only when no plugin identified the user.User to keep the current user in a process-local property where no session accepts the write, so the current-user API also works in applications that run without a session. A session, wherever one is present, stays the source of truth.UserFacade::resetCurrentUser() to discard the current user wherever setCurrentUser() stored it. An entry point that relies on the process-local fallback must call it before establishing a new request's identity.UserConfig::RESPONSE_CODE_USER_NOT_RESOLVED (003): a token whose user is not active, or whose claims identify no single user, is answered 401 with this code.spryker/user-extension to ^1.6.0 and added spryker/api-platform as a suggested dependency.Included commits: 3.31.0...3.32.0
Included commits: 3.31.0...3.32.0
User::setCurrentUser() to exclude the password hash before storing the user transfer in the session to improve authentication security.CurrentPasswordValidator to fetch a fresh user from the database instead of relying on session data for current password validation, ensuring up-to-date credential checks.CurrentUserSessionHandlerListener to verify the existence of a current user before processing to prevent errors on unauthenticated requests.Included commits: 3.30.1...3.31.0
Included commits: 3.30.1...3.31.0
Included commits: 3.30.0...3.30.1
Included commits: 3.30.0...3.30.1
Included commits: 3.29.0...3.30.0
Included commits: 3.28.0...3.29.0
Included commits: 3.28.0...3.29.0
UserDataImportMerchantFileExpanderPlugin to expand DataImportMerchantFile transfers with User data.DataImportMerchantFileCollection transfer.DataImportMerchantFile transfer.Kernel module version dependency.DataImportMerchantExtension module to dependencies.Included commits: 3.27.0...3.28.0
Included commits: 3.26.0...3.27.0
Included commits: 3.26.0...3.27.0
EditController::updateAction() to display form errors.Included commits: 3.25.0...3.26.0
Included commits: 3.25.0...3.26.0
EditController::passwordResetAction(), EditController::createAction() and EditController::updateAction() to enhance validation rules.Validator module to dependency.Included commits: 3.24.1...3.25.0
Included commits: 3.24.1...3.25.0
UserConfig::getUserPasswordPattern().UserConfig::getPasswordValidationMessage().EditController::passwordResetAction(), EditController::createAction(), and EditController::updateAction() to enhance validation rules.de_DE.csv translations.en_US.csv translations.Included commits: 3.24.0...3.24.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →