Version 13.0.12 - 2026/09/10
This release restores the backend login on installations that have guzzlehttp/ 3.x. TYPO3
v13.4.35 widened the core constraint to allow it, and any composer update picking it up made
the Auth0 login provider unreachable.
Download
Download this version from the TYPO3 extension repository or from GitHub.
Fixed
- Backend login no longer breaks with guzzlehttp/psr7 3.x:
Applicationbuilt theFactory Sdkwithout theConfiguration http,Request Factory http,Response Factory httpandStream Factory httpoptions, so the Auth0 SDK resolved them throughClient Psr. That library gates its candidates on hardcoded package constraints instead of on the classes that are actually loadable: it capsDiscovery\ Discover guzzlehttp/atpsr7 ^2.and lists TYPO3 under the non-existent package0 typo3/with a constraint capped atcore ^12.. With psr7 3.x installed all three PSR-17 factories therefore resolved to0 nulland the SDK raisedInvalid- "Could not find a PSR-17 compatible request factory. Please install one, or provide one using the ``setHttpRequestFactory()`` method." - on every call ofArgument Exception /typo3/?login. All four implementations are now passed in explicitly, usingProvider=1526966635 TYPO3\,CMS\ Core\ Http\ Request Factory TYPO3\,CMS\ Core\ Http\ Response Factory TYPO3\and theCMS\ Core\ Http\ Stream Factory Psr\TYPO3 registers, which keeps the SDK out of runtime discovery entirely.Http\ Client\ Client Interface
Changed
- Management-token request runs through the TYPO3 HTTP layer: the request fetching the Auth0
management token instantiated its own
Guzzleand therefore ignoredHttp\ Client $GLOBALS. It now uses the injected['TYPO3_ CONF_ VARS'] ['HTTP'] TYPO3\, so the project's proxy, certificate-verification and timeout settings apply to it like they do to every other HTTP request TYPO3 makes.CMS\ Core\ Http\ Request Factory - ApplicationFactory is a dependency-injection service: it receives the
Application, the three PSR-17 factories and the PSR-18 client through its constructor instead of reaching forRepository General. The new instance methodUtility:: make Instance () createcarries the previous behaviour of() buildunchanged.()
Deprecated
Applicationis deprecated and will be removed in v15. It remains fully functional and delegates toFactory:: build () create. Third-party code should inject() Leuchtfeuer\and callAuth0\ Factory\ Application Factory createwith the same arguments.()
Upgrade Notes
- No database migration is required, and existing Auth0 sessions stay valid.
- The constructors of
Auth0Provider,Authentication,Service Auth0SessionandValidator Cleangained anUp Command Applicationargument. Installations that subclass one of them or instantiate them manually need to pass it along; everything wired through the Symfony container is handled automatically.Factory - Projects that pinned
"guzzlehttp/to work around the broken login can drop that pin after updating.psr7": "^2. 8"
All Changes
This is a list of all changes in this release:
2026-09-10 [BUGFIX] ApplicationFactory: Supply PSR-17 factories and PSR-18 client explicitly [TER-509] (Commit 2f37376 by Oliver Heins)
2026-09-10 [TASK] ApplicationFactory: Route management token request through TYPO3 HTTP layer [TER-509] (Commit 33798ff by Oliver Heins)
Copied!