Important: #110629 - Extension manager downloads ZIP archives from TER
See forge#110629
Description
When installing an extension from TER, the Extension Manager fetched the
.t3x file: a serialized PHP array holding every file's contents,
verified with an MD5 hash taken from the extension index. The extension
directory was then rebuilt from that array, and its ext_
regenerated from the embedded
EM_ block.
TER stores the ZIP archive the extension author uploaded next to the
.t3x file, and now publishes its SHA-256 hash in the extension index
as
<artifactsha256>
. Whenever such a hash is available, the Extension
Manager downloads that archive instead, verifies it against the hash and
extracts it.
What this changes for an installed extension: it is now the archive the author
uploaded rather than a copy reassembled from serialized file contents. Files
that the t3x rebuild could not reproduce faithfully - most importantly
composer., which classic mode relies on since forge#109783 -
are installed unchanged, and ext_ is the author's own file
instead of a generated one.
The .t3x file remains the fallback. Remotes that do not publish an
artifact hash, and versions uploaded before TER recorded one, are downloaded
and verified exactly as before, so nothing has to be re-uploaded.
Extension authors do not need to change anything. TER keeps publishing both artifacts and the upload itself is unaffected.
Custom remotes implementing
\TYPO3\
now receive a hash of a known algorithm prefixed with its name, for example
sha256:<hash>
. The method signature is unchanged, and an unprefixed
value keeps its previous meaning, so a remote that only ever supplies MD5
hashes of .t3x files continues to work untouched.