Changelog
2.6.0
- Added:
generateandWebp generateextension settings turn generation of theAvif .webpor.avifsidecar off for the whole installation (see WebP/AVIF generation). Both default to on; the per-URLskip/Web P skipparameters still apply on top. Sidecars already on disk are served until the processed images are cleared.Avif - Added: the maintenance module deletes only the processed variants
derived from a given original file path, a directory prefix
(trailing
/) or a glob pattern (*/?), instead of clearing the wholeprocessed/directory. - Fixed: AVIF variants are written when
qualityisAvif 100. At quality 100 ImageMagick requests lossless AVIF, the AOM encoder rejects it, and no AVIF variant was written. The processor now hands at most99to the AVIF encoder. - Fixed: processed AVIF originals requested with
q100no longer fail with HTTP 500. Their URL quality is capped at99as well; the cached file name keepsq100. - Fixed: the maintenance module no longer walks
processed/while rendering the page. Statistics load asynchronously, and the five largest files are tracked during the directory pass instead of collecting every file, which exhaustedmemory_on largelimit processed/trees. - Fixed: the documentation describes variant selection as the
processor does it (see Variant negotiation):
the first non-empty file of
.avif,.webpand the original is served, theAcceptheader is not inspected, andskip/Web P skiponly suppress generation. See pull request #203.Avif
2.5.0
- Added:
imageandcroparguments onVariant Source-- when a FALSet View Helper Fileis passed viaReference image, the ViewHelper derives the effective height from that image's crop-variant area (falling back to its original aspect ratio when the variant has no crop data), instead of requiring callers to pre-compute a crop-aware height themselves via a separate, site-specific ViewHelper.heightremains authoritative whenimageis omitted.
2.4.2
- Fixed: source images under a folder with a non-ASCII character
(e.g. an umlaut) no longer return an empty-body HTTP 500 for
/processed/*requests. The regression was inintervention/v4:image InputchecksHandler:: handle () BinarybeforeImage Decoder File, andPath Image Decoder Binary's heuristic treats any string containing a byte outside printable ASCII as binary image data -- including a legitimate absolute path whose only non-ASCII content is a UTF-8 umlaut. Wrapping the path inImage Decoder Splbefore handing it toFile Info Image/Manager:: read () decodemakes decoder selection match on input type rather than content, sidestepping the heuristic.() v3(3.7.2, 3.11.1) was not affected -- noTYPO3_backport needed. See pull request #156.12
2.4.1
- Fixed: the TYPO3 version constraint now targets the v14 LTS.
typo3/was declared ascms- core ^13.and4 | | ^14. 0 ext_asemconf. php 13., which also covered the 14.0--14.2 sprint releases. Both now target 14.3 (4. 0- 14. 4. 99 ^13.,4 | | ^14. 3 13.). See pull request #139.4. 0- 14. 3. 99 - Fixed: the version metadata published to Packagist matches the
release again. The
v2.tag was first pushed against a commit whose4. 0 ext_still reademconf. php 2.. Packagist recorded that reference for3. 1 2.and, under its immutable-version policy, kept it when the tag was moved -- so4. 0 2.installed via Composer reports4. 0 2.to the Extension Manager. Installs from 2.4.1 on carry the matching version. The3. 1 2.release on TER is unaffected.4. 0
2.4.0
- Added:
Environment::(the composer-modeget Var Path () var/directory, a sibling ofpublic/rather than nested under it) is now an allowed root for path validation, so TYPO3-internal generated assets (cache, lock, transient, log) are accepted. - Added:
additionalextension configuration -- per-instance, opt-in, comma-separated list of absolute filesystem paths that are realpath-resolved and added directly to the path-validation allow-list. Closes the gap for integrator-trusted locations that are neither a FAL storage base path nor one of the hardcoded TYPO3-internal locations. See Additional trusted roots.Trusted Roots - Added: configurable WebP/AVIF output quality via the new
quality(default 75) andWebp quality(default 60) extension-configuration settings. Previously both variants were encoded at the same numeric quality as the primary image; AVIF's steeper quality scale made AVIF variants larger than WebP at matching numbers, so format negotiation ended up serving the biggest file. The lower AVIF default keeps AVIF variants genuinely smaller than WebP while staying visually comparable. See WebP/AVIF output quality. Changing either setting requires clearing processed images, since per-format quality is not part of the cache filename. Reported in issue #132.Avif - Fixed:
clear-(Maintenance module) failed on symlinked deployments. The action validated the target path withprocessed- images realpath, which resolves a() processedsymlink (shared-directory deployment layouts, e.g. Deployer) to its target and never matched<public>/-- so clearing failed on every symlinked deployment. The directory is now emptied in place instead ofprocessed rmdir+() mkdir, preserving the symlink. Reported in issue #131.()
2.3.1
- Fixed: the backend module icon and Maintenance module templates
were not TYPO3 v14 theme-aware. The module icon
(
module-) and extension icon (image- optimize. svg Extension.) were flat, hard-coded tiles that did not adapt to the v14 backend light/dark colour scheme. The Maintenance module's Fluid templates also used Bootstrap utility classes with fixed light values (svg bg-,light table-,light text-), causing card headers, table heads, and code chips to render as light boxes on a dark backend. The module icon is now theme-aware viadark fill="current(TYPO3 v14+, with a legacy full-colour tile kept for v13), and the templates use adaptiveColor" bg-tokens instead.body- tertiary
2.3.0
- Added:
additionalextension configuration -- per-instance, opt-in, comma-separated list of directory names that, when found as a symlink directly inside a Local FAL storage's own base path (e.g.Trusted Storage Symlinks fileadmin/_), are resolved and added to the path-validation allow-list. Closes the gap where deployments relocate TYPO3 core's ownprocessed_ _processed_image cache onto local/ephemeral storage to keep it off shared/NFS storage, leaving a symlink behind that the FAL-storage basePath lookup cannot see. Default empty; keeps today's behaviour for every installation that doesn't opt in. See Trusted storage symlinks. Reported in issue #120. - Fixed: images published via
public/_symlinks (extensionassets/<hash> Resources/assets) were rejected with HTTP 400. TYPO3 core publishes each extension'sPublic/ Resources/directory by symlinkingPublic/ public/_to a location outside the public webroot.assets/<hash>/ getdid not resolve these symlinks, so variant requests for e.g. an extension's default/fallback image failed even though the file is a legitimate part of the deployed application. Every immediate child ofAllowed Roots () _assetsis now resolved individually. Reported in issue #117.
2.2.4
- Fixed: the
sourceViewHelper passes absolute URLs (Set http://,https://,//),data:URIs, and URLs carrying a query string through unchanged and renders them as a plain<img>tag. Previously such paths — e.g. the tokenizedeURLs fal_securedownload generates for files in non-public storages — were mangled into brokenID=dump File /processed/...variant paths. The access control of the generating extension stays intact; see Public images only: absolute URLs are passed through for the trade-off. - Fixed: backend module labels are resolved via array format.
2.2.3
- Fixed: processed image requests no longer return
HTTP 400 when
fileadmin(or any other Local FAL storage) is a symlink to an external location such as an NFS/EFS mount.isnow accepts any realpath-resolved path that lies within the TYPO3 public root or the realpath of any configured Local storage'sPath Within Allowed Roots base. Symlinks placed inside a storage that escape every allowed root -- e.g.Path fileadmin/->evil /etc-- continue to be rejected. Reported in issue #70. - Hardened: paths containing NUL bytes are rejected outright, closing a minor realpath-bypass via the not-yet-existing-path parent-walk branch.
- Changed (BC for subclasses and manual instantiators):
Netresearch\\gains a new requiredNr Image Optimize\\ Processor Storageconstructor parameter. Consumers that autowire the service (the default in TYPO3 12+) are unaffected; any code that extends the class or constructs it by hand must forward the new dependency.Repository
2.2.2
- Added
Optimize-- PSR-14 listener that runsOn Upload Listener optipng/gifsicle/jpegoptimonAfterandFile Added Event After. Keyed byFile Replaced Event storageto avoid cross-storage re-entrancy collisions; restoresUid . ':' . identifier setin aEvaluate Permissions finallyblock. - Added
nr:-- bulk optimization command withimage: optimize --,dry- run --,storages --, andjpeg- quality --options. Uses a streaming Generator overstrip- metadata sys_so large installations don't load the full index into memory.file - Added
nr:-- heuristic analysis command that estimates optimization potential without invoking any binary. Fast even on large installations.image: analyze - Added
Imageservice -- shared backend used by the listener and both CLI commands. Env overrides (Optimizer OPTIPNG_,BIN GIFSICLE_,BIN JPEGOPTIM_) are authoritative: a set-but-invalid override is reported as unavailable rather than silently falling back toBIN $PATH.$PATHlookups also verifyis_.executable ()
2.2.1
- Adjusted author information in
ext_.emconf. php
2.2.0
- Fixed: always render
altattribute on generated<img>tags. - Expanded unit test coverage for Processor and SourceSetViewHelper.
2.1.0
New in version 2.1.0
Width-based responsive srcset with sizes
attribute, configurable width variants, and
fetchpriority support.
- Added responsive width-based
srcsetgeneration as opt-in feature. - Added
widthparameter for custom breakpoints.Variants - Added
sizesparameter for responsive image sizing. - Added
fetchpriorityattribute for resource hints. - Optimized default
sizesattribute values.
2.0.1
- Fixed
declarestatement issue preventing TER publishing via GitHub Actions.
2.0.0
New in version 2.0.0
TYPO3 13 compatibility with PHP 8.2--8.4 support.
- Added TYPO3 13 compatibility.
- Added PHP 8.2, 8.3, and 8.4 support.
- Dropped support for older TYPO3 versions.
- Switched to Intervention Image 3.x.
- Removed obsolete system binary checks.
1.0.1
- Added
ext_for classic installation.emconf. php
1.0.0
- Initial stable release.
- GitHub Actions CI workflows.
0.1.5
- Fixed
strtolowernull argument error.() - Fixed array offset access on boolean value.
- Allowed numeric characters in file extensions.
- Added extension icon.
- Corrected crop variant examples.
- Improved lazy loading behavior.