.. include:: ../../Includes.txt
============================
Version 13.0.12 - 2026/09/10
============================
This release restores the backend login on installations that have ``guzzlehttp/psr7`` 3.x. TYPO3
v13.4.35 widened the core constraint to allow it, and any ``composer update`` picking it up made
the Auth0 login provider unreachable.
Download
========
Download this version from the `TYPO3 extension repository `__ or from
`GitHub `__.
Fixed
=====
* **Backend login no longer breaks with guzzlehttp/psr7 3.x:** ``ApplicationFactory`` built the
``SdkConfiguration`` without the ``httpRequestFactory``, ``httpResponseFactory``,
``httpStreamFactory`` and ``httpClient`` options, so the Auth0 SDK resolved them through
``PsrDiscovery\Discover``. That library gates its candidates on hardcoded package constraints
instead of on the classes that are actually loadable: it caps ``guzzlehttp/psr7`` at ``^2.0`` and
lists TYPO3 under the non-existent package ``typo3/core`` with a constraint capped at ``^12.0``.
With psr7 3.x installed all three PSR-17 factories therefore resolved to ``null`` and the SDK
raised ``InvalidArgumentException`` - *"Could not find a PSR-17 compatible request factory. Please
install one, or provide one using the ``setHttpRequestFactory()`` method."* - on every call of
``/typo3/?loginProvider=1526966635``. All four implementations are now passed in explicitly, using
``TYPO3\CMS\Core\Http\RequestFactory``, ``TYPO3\CMS\Core\Http\ResponseFactory``,
``TYPO3\CMS\Core\Http\StreamFactory`` and the ``Psr\Http\Client\ClientInterface`` TYPO3 registers,
which keeps the SDK out of runtime discovery entirely.
Changed
=======
* **Management-token request runs through the TYPO3 HTTP layer:** the request fetching the Auth0
management token instantiated its own ``GuzzleHttp\Client`` and therefore ignored
``$GLOBALS['TYPO3_CONF_VARS']['HTTP']``. It now uses the injected
``TYPO3\CMS\Core\Http\RequestFactory``, so the project's proxy, certificate-verification and
timeout settings apply to it like they do to every other HTTP request TYPO3 makes.
* **ApplicationFactory is a dependency-injection service:** it receives the
``ApplicationRepository``, the three PSR-17 factories and the PSR-18 client through its
constructor instead of reaching for ``GeneralUtility::makeInstance()``. The new instance method
``create()`` carries the previous behaviour of ``build()`` unchanged.
Deprecated
==========
* ``ApplicationFactory::build()`` is deprecated and will be removed in v15. It remains fully
functional and delegates to ``create()``. Third-party code should inject
``Leuchtfeuer\Auth0\Factory\ApplicationFactory`` and call ``create()`` with the same arguments.
Upgrade Notes
=============
* No database migration is required, and existing Auth0 sessions stay valid.
* The constructors of ``Auth0Provider``, ``AuthenticationService``, ``Auth0SessionValidator`` and
``CleanUpCommand`` gained an ``ApplicationFactory`` argument. Installations that subclass one of
them or instantiate them manually need to pass it along; everything wired through the Symfony
container is handled automatically.
* Projects that pinned ``"guzzlehttp/psr7": "^2.8"`` to work around the broken login can drop that
pin after updating.
All Changes
===========
This is a list of all changes in this release::
2026-09-10 [BUGFIX] ApplicationFactory: Supply PSR-17 factories and PSR-18 client explicitly [TER-509] (Commit 2f37376 by Oliver Heins)
2026-09-10 [TASK] ApplicationFactory: Route management token request through TYPO3 HTTP layer [TER-509] (Commit 33798ff by Oliver Heins)