Reference › Changelog
Changelog
All notable changes to NestLaravel are documented here. The project follows Semantic Versioning and the Keep a Changelog format. Upgrade instructions: UPGRADING.md.
#[Unreleased]
#[1.0.0] — first public release
#Added
nestlaravelCLI (packages/cli, zero runtime dependencies, Node ≥ 20.11):create, `generate service | kafka-event | kafka-topic,add tenancy,dev,test,lint,build,doctor,update`.nestlaravel/kafkapackage (packages/laravel-kafka): standard event envelope, transactional outbox (messaging:outbox-publish --daemon), hardened rdkafka producer and new rdkafka consumer with manual commits, retry/backoff, poison-message + schema-version dead-lettering, idempotent handling, graceful shutdown.nestlaravel/tenancypackage (packages/laravel-tenancy): optional single-database multi-tenancy with cross-tenant attack tests (Eloquent, queues, Kafka, cache keys, storage paths).- Service-to-service trust: HMAC-signed gateway → service calls (
GatewaySigner,VerifyGatewaySignature), per-service secrets, replay protection, fail-closed services,/readyprobe, correlation-id propagation. - Update system with managed-file tracking, backups and idempotent migrations (
nestlaravel update,--adoptfor pre-CLI workspaces). - Shared production Dockerfile (
infrastructure/docker/laravel.Dockerfile: PHP 8.4, rdkafka, redis, nginx),docker-build.mjs,lintandbuildNx targets on every Laravel project. - Documentation set, GitHub Actions CI and release pipeline, clean-install E2E test.
laravel/mcpdeclared as a dependency ofapps/api(routes/ai.phpreferenced it but it was missing, so the MCP tests and endpoints failed).
#Changed
- Dev infrastructure: Kafka KRaft (
apache/kafka:4.0.0) replaces Confluent + ZooKeeper; MinIO/Mailpit moved to the optionaltoolsprofile (Mailpit) or removed (MinIO); images pinned; ports bound to127.0.0.1; Redis requires a password;docker-compose.infra.ymlis now standalone and included bydocker-compose.yml. - Dependencies:
laravel/framework13.24 → 13.34,league/commonmark,league/flysystem(security),guzzlehttp/*(via framework), Nx^21.6→^23.2; PHP minimum documented as 8.3 (tested 8.4). Usersis no longer a reserved service name (generate service usersworks).- Event envelope gains
source(alias ofproducer) and optionaltenant_id. - Sanctum tokens expire after 24 h by default (
SANCTUM_TOKEN_EXPIRATION). - Code style: Laravel Pint applied to
apps/api.
#Security
- Critical —
POST /api/auth/registeraccepted a client-chosenrole, allowing anyone to self-register asplatform_admin. Now restricted toauth.self_registration_roles(defaultcustomer), enforced in the request and the action; regression tests added. - Critical — gateway proxy routes were unauthenticated and downstream services had no authentication at all. Proxy now requires
auth:sanctum+ throttling and signs every call; services verify or reject (401/503). - High — the outbox marked messages published before the broker confirmed delivery (message loss on broker failure). Rows are now marked only after
flush()succeeds; delivery-report errors surface. - High — dead-letter publish failures were swallowed and the offset acknowledged (message loss). Now the offset is not committed.
- High — no production Kafka consumer existed and the producer had no TLS/SASL,
acks=allor idempotence. Added. - High — vulnerable dependencies (
league/commonmarkDoS, Laravel debug-page XSS, Flysystem path check) updated;composer auditis clean. - Medium — gateway forwarded the user's bearer token to internal services;
/api/gateway/servicesexposed internal URLs unauthenticated; encoded../control characters in proxied paths; redirects followed (SSRF pivot); auth throttling was per-IP only; missingmcprate limiter caused HTTP 500s; committed default credentials (secret,minioadmin, a fixedAPP_KEYindocker-compose.test.yml);APP_DEBUG=truein.env.example. - Low —
/healthdisclosed the Kafka broker address.
#Breaking changes
See UPGRADING.md § 1.0.0. In short: direct calls to services now need the gateway signature; proxy routes require authentication; the gateway no longer forwards bearer tokens; compose files were restructured; registration role escalation must be closed in existing apps.
#Migration
npx nestlaravel update --adopt --dry-run, then npx nestlaravel update --adopt.
[Unreleased]: https://github.com/REPLACE_ME/nestlaravel/compare/v1.0.0...HEAD [1.0.0]: https://github.com/REPLACE_ME/nestlaravel/releases/tag/v1.0.0
Edit this page on GitHub