controleonline / users
v1.0.7
2026-10-07 21:56 UTC
Requires
- php: ^8.4.1
- controleonline/common: 1.0.5
- symfony/cache: ^8.1
- symfony/http-foundation: ^8.1
- symfony/http-kernel: ^8.1
- symfony/lock: ^8.1
- symfony/routing: ^8.1
- symfony/security-bundle: ^8.1
- symfony/validator: ^8.1
Requires (Dev)
- controleonline/people: 1.0.2
- doctrine/doctrine-bundle: ^3.3
- doctrine/orm: ^3.7
- phpunit/phpunit: ^12.1
Suggests
None
Provides
None
Conflicts
None
Replaces
None
- dev-master
- v1.0.7
- v1.0.6
- v1.0.5
- v1.0.4
- v1.0.3
- v1.0.2
- v1.0.0
- dev-staging
- dev-rc/1.0.7-rc.1
- dev-dev
- dev-task-973
- dev-rc/1.0.6-rc.1
- dev-rc/1.0.5-rc.1
- dev-task-197
- dev-task-36
- dev-task-34
- dev-rc/1.0.2-rc.1
- dev-task-167
- dev-task-826
- dev-automation/reset-master-dev-e7499d6e-3b92c1c8
- dev-automation/reset-rc-1.10.31-rc.11-staging-d20ec93a-3b92c1c8
- dev-automation/reset-rc-1.10.31-rc.11-dev-e7499d6e-3b92c1c8
- dev-task-93
- dev-task-764
- dev-task-201
- dev-task-369
- dev-task-369-docs
- dev-task-26
- dev-task-80
- dev-task-68
- dev-task-462
- dev-task-324
- dev-task-21
- dev-task-279
- dev-task-95
- dev-task-307
- dev-task-18
- dev-task-5
- dev-task-17
- dev-task-323
- dev-task-324-docs
- dev-task-314
- dev-task-313
- dev-task-5-backup-20260513
- dev-task-6
- dev-merge-recover-staging-20260507
- dev-task-94
- dev-production
This package is auto-updated.
Last update: 2026-10-07 21:56:23 UTC
README
users
composer require controleonline/users:1.0.4
Add Service import: config\services.yaml
imports: - { resource: "../modules/controleonline/orders/tasks/services/tasks.yaml" }
Change your autentication file: config\packages\security.yaml
security: encoders: ControleOnline\Entity\User: algorithm: bcrypt providers: app_user_provider: entity: class: ControleOnline\Entity\User firewalls: dev: pattern : ^/(_(profiler|wdt)|css|images|js)/ security: false main: stateless : true anonymous : lazy provider : app_user_provider json_login: check_path : /token username_path: username password_path: password guard: authenticators: - App\Security\TokenAuthenticator role_hierarchy: ROLE_SUPER: ROLE_SUPER ROLE_OWNER: ROLE_OWNER ROLE_DIRECTOR: ROLE_DIRECTOR ROLE_MANAGER: ROLE_MANAGER ROLE_SALESMAN: ROLE_SALESMAN ROLE_AFTER_SALES: ROLE_AFTER_SALES ROLE_EMPLOYEE: ROLE_EMPLOYEE ROLE_CLIENT: ROLE_CLIENT ROLE_PROVIDER: ROLE_PROVIDER ROLE_FRANCHISEE: ROLE_FRANCHISEE ROLE_HUMAN: ROLE_HUMAN access_control: - { path: ^/my_contracts/signatures-finished, roles: PUBLIC_ACCESS, requires_channel: https }
And create a file: App\Security\TokenAuthenticator
<?php namespace ControleOnline\Security; use ControleOnline\Security\TokenAuthenticator as SecurityTokenAuthenticator; class TokenAuthenticator extends SecurityTokenAuthenticator { }
Password recovery flow
The public password recovery request no longer changes the user password immediately.
Current behavior:
- the initial request generates temporary recovery tokens and sends the recovery e-mail
- recovery tokens expire after 15 minutes
- the password only changes when the recovery flow is completed with a valid, non-expired token
- expired or successfully used recovery tokens are cleared after completion
Validation:
- focused PHPUnit coverage lives in
tests/Service/PasswordRecoveryServiceTest.php - the branch workflow
Pull Request Checksis the canonical automated evidence for this flow in review branches
User management scope
The user-management flow used by the manager area now keeps all sensitive operations on the same guarded service path.
Current behavior:
- direct user reads and management stay restricted by
UserService::securityFilter - cross-person management is limited to
owner,director, andmanager - disabled
people_linkrows and disabled companies no longer authorize reads, deletes, password changes, or API key rotation DELETE /users/{id}now follows the same guardedUserServicepath used by create, password-change, and API-key rotation flows
Validation:
- focused coverage lives in
tests/Service/UserServiceTest.php,tests/Controller/DeleteUserActionTest.php, andtests/Entity/UserSerializationGroupsTest.php - the branch workflow
Pull Request Checksis the canonical automated evidence for this flow in review branches