Skip to content

Behaviour changes ​

This page collects the changes that can affect an application that already uses Arrel. The notes of every version are in Releases.

1.0.0-rc.1 ​

These changes tighten the panel's security. If you are upgrading from an earlier version, review them one by one.

A Resource the user cannot list is closed ​

Before, a model with no Policy left canCreate(), canEdit() and canDelete() open, and they could be reached separately. Now, if canViewAny() is false, the Resource answers 403 at every endpoint.

What to do: nothing, if all your models have a Policy with viewAny. If a Resource had no Policy and you wanted it to be accessible, it still is. If you wanted it not to be, define a Policy.

Actions without authorize() require edit permission ​

A custom action that does not declare authorize() now requires canEdit() on the record, or canCreate() if it is standalone(). Before, any user who could see the Resource could run it.

What to do: declare authorize() on actions that must stay open to more users than those who can edit.

php
Action::make('export')
    ->authorize(fn (): bool => auth()->user()->can('posts.export'))

An action's options are only served to those who can run it ​

The options an action offers for its relation fields are now only served to users who can run the action.

A Relation field's scope is applied on save ​

A Relation field with query() now refuses on save a record that the scope hides, with a validation error. This holds for the forms of a Resource, of a Relation manager and of an action.

What to do: check that no form sends identifiers that query() excludes, for example because the value comes from another source.

Attempt limits ​

  • Sign-in allows five failed attempts per email and address. There is a new translation key, arrel::auth.throttle, with the message.
  • A sign-in waiting for the second factor ends after five wrong codes.
  • File uploads are limited to 60 per minute and user.

Signatures ​

Action::validationRules() and the schema trait's validationRules() accept the owner record as an optional last argument. If you override either of these methods, add the parameter.

Fixes that can change a behaviour ​

  • canEdit() checks the Policy's update ability, not edit.
  • A model that blocks its own deletion (with a RuntimeException in deleting) answers 422 instead of failing.
  • When saving a record, only files that were really uploaded to the temporary directory are moved.