phalcon/cphalcon
73.1
Strong · 26 September 2026
2k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is the Phalcon PHP framework, a high-performance web application toolkit implemented as a C extension compiled from Zephir source code. It provides a comprehensive suite of components for building web applications, including dependency injection, routing, database abstraction, authentication, and templating. The codebase also encompasses a robust build infrastructure for generating the extension, managing third-party dependencies, and enforcing strict type contracts for static analysis.
How it got here
2012–2019 — Zephir migration and PHP 8 modernization
142 changes.
The project underwent a comprehensive migration of its C extension codebase to Zephir, enabling support for PHP 8.1 and modernizing the underlying architecture. This period introduced a new modular component structure, including dedicated factories, contracts, and exception hierarchies, while adding significant new features such as image manipulation, cursor-based pagination, and persistent ACL storage.
2020–2026 — v7 contract interfaces and component restructuring
224 changes.
This period focused on establishing the foundational architecture for the upcoming v7 release by introducing canonical contract interfaces across the framework, including Db, Container, Events, and Security. It involved a comprehensive restructuring of core components such as DataMapper, Encryption, and Validation into modular, extensible hierarchies with dedicated exception hierarchies for granular error handling. The work also included significant refactoring of build systems, support utilities, and HTML helpers to standardize APIs and improve static analysis support.
Features
Added ADR contract interfaces for the Action Domain Responder pattern
The ext/phalcon/contracts/adr directory now includes the core PHP interfaces that define the Action Domain Responder (ADR) architecture within Phalcon. This adds the Handler, Action, Middleware, Dispatcher, and Application contracts, along with a central ADRTypes registry for PHPStan static analysis. These interfaces establish the standard request/response flow, middleware chaining, and dispatching behavior for ADR-based endpoints.
ext/phalcon/contracts/adr · high confidence
Added ADR event catalog for lifecycle hooks
Introduced the \Phalcon\\ADR\\Events\\Event\ class, which defines a set of constants representing specific lifecycle events for the Action Domain Responder (ADR) pattern. These constants, such as \ADR\_BEFORE\_EXECUTE\_ACTION\, \APPLICATION\_BEFORE\_HANDLE\, and \PIPELINE\_BEFORE\_DISPATCH\, provide a standardized vocabulary for listeners to attach to the native events manager, enabling users to hook into key phases of the request handling pipeline.
phalcon/ADR/Events · high confidence
Added DataMapper type contract definitions
The DataMapper component now includes a new \DataMapperTypes\ interface that serves as a central registry for PHPStan array shapes. This addition provides strict type definitions for internal structures such as query stores, connection arguments, and row formats, improving static analysis accuracy for developers using the DataMapper namespace.
ext/phalcon/contracts/datamapper · high confidence
Added EventsAwareTrait for unified event management
The Phalcon framework now includes an EventsAwareTrait that allows classes to easily integrate with the event system. This trait provides a protected eventsManager property and exposes methods to get and set the event manager, as well as a protected helper to fire events. By using this trait, developers can add event handling capabilities to their classes without reimplementing the logic, ensuring consistent event propagation across the framework.
ext/phalcon/events/traits · high confidence
Added Geometry contract interface for database spatial data
The Phalcon framework now includes a new \Phalcon\\Contracts\\Db\\Geometry\\Geometry\ interface that defines the contract for database geometry value objects. This interface specifies three abstract methods: \getSrid\ to retrieve the Spatial Reference System Identifier, \getType\ to identify the geometry type, and \toWkt\ to render the geometry as a Well-Known Text string. This provides a standardized way for applications to interact with spatial data within the database layer.
ext/phalcon/contracts/db/geometry · high confidence
Added HTTP Link header serialization capability
The \phalcon/Html/Link/Serializer\ component now includes a new \Header\ serializer class and its corresponding \SerializerInterface\. This addition allows users to serialize a collection of link objects into a valid HTTP Link header string, adhering to RFC 8288 by correctly handling relative links, templated links (which are skipped), and attribute quoting. This provides a dedicated way to generate HTTP headers from link data, distinct from other serialization formats.
phalcon/Html/Link/Serializer · high confidence
Added IoC container contracts and interfaces
New interfaces have been added to the \Phalcon\\Contracts\\Container\\Ioc\ namespace to define the structure of the Inversion of Control container. This includes \IocContainer\ for retrieving services by name, \IocContainerFactory\ for creating new container instances, \IocThrowable\ for marking IOC-related errors, and \IocTypeAliases\ for PHPStan type definitions. These contracts provide a standardized way to interact with the IoC container, allowing for better type safety and interoperability with external service providers.
phalcon/Contracts/Container/Ioc · high confidence
Added IsBetween number helper
A new IsBetween helper class has been added to the Phalcon Support Number helpers, allowing users to check if a given integer value falls within a specified inclusive range (start to end).
phalcon/Support/Helper/Number · high confidence
Added JSON and Text response formatters
Introduced new JsonFormatter and TextFormatter classes within the ADR Responder component to handle response serialization. The JsonFormatter renders payloads as JSON, supporting standard JSON and JSON-compatible MIME types, while the TextFormatter outputs plain text, handling scalar values and objects implementing Stringable, with fallbacks for arrays and non-stringable objects.
phalcon/ADR/Responder/Formatter · high confidence
Added Lemon parser generator and consolidated third-party licenses
The Lemon LALR(1) parser generator source code (lemon.c and lempar.c) has been added to the 3rdparty directory, consolidating the parser into a single file for easier integration. Additionally, a new 3rdparty/licenses directory has been created to centralize license files, with new entries added for Atlas, Aura, Diactoros, PHP, and Zend.
3rdparty · high confidence
Added PHP extension support for HTML Link Header serialization
The PHP extension now includes the \Phalcon\\Html\\Link\\Serializer\\Header\ class and the \SerializerInterface\, enabling the serialization of link collections into HTTP Link headers. This addition provides a native implementation for converting link data structures into the standard HTTP header format, complementing existing serialization capabilities within the framework.
ext/phalcon/html/link/serializer · high confidence
Added PHPStan type definitions for Application modules
Introduced the \ApplicationTypes\ interface in the \Phalcon\\Contracts\\Application\ namespace to serve as a central registry for PHPStan array shapes. This change adds static analysis support for application module configurations by defining \application\_module\_definition\ and \application\_modules\ types, improving type safety for developers using the Application component.
ext/phalcon/contracts/application, phalcon/Contracts/Application · high confidence
Added PHPStan type definitions for Config contracts
A new \ConfigTypes\ interface has been introduced in the \phalcon/Contracts/Config\ namespace to centralize PHPStan type aliases. This change provides stricter static analysis support for configuration data structures, defining specific array shapes for configuration data, callbacks, options, resolved options, extra arguments, and grouped entries, thereby improving type safety for developers using the Config component.
ext/phalcon/contracts/autoload, phalcon/Contracts/Autoload, phalcon/Contracts/Config · high confidence
Added PHPStan type definitions for Dependency Injection services
A new \DiTypes\ interface has been introduced in the \phalcon/Contracts/Di\ namespace to centralize PHPStan type aliases. This change provides stricter static analysis support for DI service definitions, arguments, calls, and properties, improving type safety for developers using the Dependency Injection component.
phalcon/Contracts/Di · high confidence
Added PHPStan type definitions for Session storage options
A new \SessionTypes\ interface has been introduced in the \Phalcon\\Contracts\\Session\ namespace to serve as a central registry for PHPStan array shapes. This change adds static analysis support for session configuration structures, specifically defining types for \session\_bag\_data\, \session\_files\, \session\_options\, and detailed option arrays for LibMemcached, Redis, and Stream storage handlers, improving type safety for developers using these session backends.
ext/phalcon/contracts/session, phalcon/Contracts/Session · high confidence
Added PHPStan type definitions for the Storage namespace
The Storage namespace now includes a central registry of PHPStan array shapes (e.g., \storage\_options\, \storage\_redis\_options\, \storage\_adapter\_options\) via the new \StorageTypes\ interface. This provides static analysis tools with precise type information for storage configuration arrays, adapter options, and internal data structures, improving type safety and IDE autocompletion for developers using the storage component.
ext/phalcon/contracts/storage, phalcon/Contracts/Storage · high confidence
Added PHPStan type definitions for the Translate component
A new \TranslateTypes\ interface has been introduced in the \Phalcon\\Contracts\\Translate\ namespace to serve as a central registry for PHPStan array shapes. This change adds static analysis support for the Translate module by defining specific types for placeholders, data, and configuration options for adapters such as Array, CSV, and Gettext, improving type safety for developers using the translation services.
ext/phalcon/contracts/translate, phalcon/Contracts/Translate · high confidence
Added SAPI Emitter for ADR pattern
Introduced the SapiEmitter class within the Phalcon\\ADR\\Emitter namespace to handle response emission via the Server API. This component implements the Emitter interface and ensures that responses are only sent when headers have not already been transmitted, throwing a HeadersAlreadySent exception otherwise.
phalcon/ADR/Emitter · high confidence
Added StringLength Min and Max validators
The Phalcon validation component now includes dedicated \Min\ and \Max\ validators for string length constraints. Users can apply \Phalcon\\Filter\\Validation\\Validator\\StringLength\\Min\ to enforce a minimum character count and \Phalcon\\Filter\\Validation\\Validator\\StringLength\\Max\ to enforce a maximum, both supporting options for inclusive/exclusive bounds and per-field configuration.
ext/phalcon/filter/validation/validator/stringlength · high confidence
Added ValidatorCompositeTrait for combined validation logic
The Phalcon validation component now includes a new \ValidatorCompositeTrait\ in the \ext/phalcon/filter/validation/traits\ directory. This trait provides shared state management for a collection of validators and implements a \validate\ method that iterates through them to perform combined validation on a specific field. It ensures that validation fails immediately if no validators are present or if any individual validator returns false, and exposes the validator list via a \getValidators\ method.
ext/phalcon/filter/validation/traits · high confidence
Added configuration classes for Session and Token authentication guards
Introduced new configuration classes in the \phalcon/Auth/Guard/Config\ namespace to manage settings for different authentication guard types. The \SessionGuardConfig\ class allows developers to define specific session key names, remember-me cookie names, TTL, and security flags, with automatic suffix derivation for multi-guard applications and validation to ensure session and remember names do not conflict. The \TokenGuardConfig\ class provides configuration for token-based authentication by storing the input and storage keys required for token validation. These classes implement the \GuardConfig\ interface and include specific exception handling for configuration errors.
phalcon/Auth/Guard/Config · high confidence
Added inline CSS and JavaScript asset classes
The Phalcon extension now includes \Phalcon\\Assets\\Inline\\Css\ and \Phalcon\\Assets\\Inline\\Js\ classes, allowing users to define inline CSS and JavaScript content directly within the asset manager. These classes accept the content string, an optional boolean to control filtering, and an optional array of HTML attributes (defaulting to \type="text/css"\ or \type="application/javascript"\), enabling more flexible inclusion of inline scripts and styles without requiring external files.
ext/phalcon/assets/inline · high confidence
Added new Phalcon MVC model exception classes
The \ext/phalcon/mvc/model/exceptions\ directory now includes generated C and header files for several new exception classes, such as \BelongsToRequiresObject\, \BindTypeNotDefined\, \CannotResolveAttribute\, \ColumnNotInMap\, \CorruptColumnType\, \CursorIsImmutable\, \DataTypeNotDefined\, \EagerRowLimitExceeded\, \HandlerMustImplementBindable\, \IdentityNotInColumnMap\, \IndexNotInCursor\, \InvalidConnectionService\, \InvalidContainer\, \InvalidDumpResultKey\, and \InvalidEagerParameter\. These classes extend the base \Phalcon\\Mvc\\Model\\Exception\ and provide specific error messages for model-related issues, such as invalid column mappings, eager loading limits, and binding requirements.
ext/phalcon/mvc/model/exceptions · high confidence
Added non-ASCII safe file basename helper
A new \Basename\ helper class has been added to the \Phalcon\\Support\\Helper\\File\ namespace. This utility extracts the filename from a given path, addressing limitations in PHP's native \basename()\ function which does not properly support streams or filenames containing non-US-ASCII characters. It provides robust handling for internationalized file paths by stripping directory separators and optional suffixes.
phalcon/Support/Helper/File · high confidence
Added resolver contract interfaces for dependency injection
The \phalcon/Contracts/Container/Resolver\ directory now includes new interface definitions (\ReflectionMethodResolver\, \ReflectionParameterResolver\, \Resolvable\, \ResolverService\, and \ResolverThrowable\) that establish the contract for resolving classes, methods, and parameters within the IoC container. These interfaces provide the structural foundation for the container's resolution logic, allowing implementations to handle dependency injection for reflection-based targets.
phalcon/Contracts/Container/Resolver · high confidence
Added specific PHQL query exception classes
The \phalcon/Mvc/Model/Query/Exceptions\ directory now includes a comprehensive set of new exception classes (e.g., \AmbiguousColumn\, \BindParameterNotInPlaceholders\, \CorruptedAst\, \UnknownPhqlStatement\) to provide detailed error reporting for PHQL query preparation and execution issues.
phalcon/Mvc/Model/Query/Exceptions · high confidence
Added specific exception class for Helper component
A new \Phalcon\\Support\\Helper\\Exception\ class has been introduced to serve as the base exception type for errors occurring within the Helper support component. This allows applications to catch and handle helper-specific issues separately from general support exceptions.
phalcon/Support/Helper · high confidence
Added specific exception classes for URL and View components
This change introduces new, specific exception classes for the URL and View components to improve error handling clarity. For the URL component, new exceptions include \MissingRouteName\, \RouteNotFound\, and \RouterServiceUnavailable\, which provide distinct error messages for missing route parameters, unresolvable route names, and unavailable router services. For the View component, new exceptions such as \InvalidEngineRegistration\, \InvalidViewsDirType\, \SimpleViewNotFound\, \ViewNotFound\, \ViewServicesUnavailable\, and \ViewsDirItemMustBeString\ are added to handle issues like invalid template engine configurations, incorrect views directory types, missing view files, and unavailable application services.
phalcon/Mvc/Url/Exceptions, phalcon/Mvc/View/Exceptions · high confidence
Annotations adapters now support a configurable cache size limit
The annotations adapters (Memory, Stream, and APCu) now include a new \annotationsLimit\ property and corresponding \setAnnotationsLimit\/\getAnnotationsLimit\ methods. This allows you to cap the number of class annotation entries retained in the in-memory cache; setting a positive value ensures the cache is cleared when adding a new class would exceed the limit, preventing unbounded memory growth.
ext/phalcon/annotations · high confidence
Annotations component rewritten with PHP 8 attribute support and hardened cache adapters
The Phalcon Annotations component has been completely rewritten in Zephir to support both traditional docblock annotations and modern PHP 8 attributes via a new AttributesReader. The Stream adapter now restricts unserialization to a whitelist of Phalcon annotation classes to prevent object injection vulnerabilities, and the abstract adapter introduces an optional annotations limit to cap in-memory cache size. Additionally, new attribute classes are provided for routing (Connect, Delete, etc.) and model metadata (Column, Identity, Primary, Source), allowing developers to define routes and model structures using native PHP attributes.
phalcon/Annotations · high confidence
CLI Dispatcher introduces dedicated exception class
The Phalcon CLI Dispatcher now includes a dedicated exception class (Phalcon\\Cli\\Dispatcher\\Exception) that extends the base Phalcon\\Dispatcher\\Exception. This allows applications to catch and handle exceptions specific to the CLI dispatcher separately from general dispatcher errors.
phalcon/Cli/Dispatcher · high confidence
Cursor-based pagination adapter for PHQL query builders
The paginator adapter component now includes a new QueryBuilderCursor adapter that enables keyset (cursor-based) pagination for PHQL query builders. This provides O(1) index seeks for deep pagination by appending a WHERE condition on a unique, indexed cursor column, avoiding the performance degradation of ever-growing OFFSET clauses. Users must specify a cursor column and pass the cursor value from the previous page to retrieve subsequent pages. Note that this adapter does not support total item counts or random page access.
ext/phalcon/paginator/adapter · high confidence
Expanded set of specific database exception classes
The \phalcon/Db/Exceptions\ directory now includes a comprehensive suite of new, granular exception classes (such as \CannotInsertWithoutData\, \UnsupportedOperator\, \ReturningNotSupported\, and various SQLite-specific constraints like \SqliteAlterColumnNotSupported\). This change improves error handling by replacing generic failures with distinct, named exceptions for specific database operations, dialect limitations, and schema validation rules, allowing applications to catch and respond to precise database errors.
phalcon/Db/Exceptions · high confidence
Flash messages now support custom icon CSS classes
The Flash component has been refactored to allow styling of message icons independently of the message containers. Users can now configure specific CSS classes for the icons used in flash notifications via the new \setIconCssClasses()\ method and retrieve them with \getCssIconClasses()\. This change is implemented in the \AbstractFlash\ base class and its \Direct\ and \Session\ implementations, which now maintain a separate \cssIconClasses\ array alongside the existing \cssClasses\ for message containers.
phalcon/Flash · high confidence
Hydration now supports cloning results and case-insensitive column mapping
The model hydration layer introduces new capabilities for populating models from data arrays. The \CloneResult\ hydrator allows creating a new model instance by cloning a base object and populating it with provided data, including support for setting private properties via reflection and firing the \afterFetch\ event. The \CloneResultMapHydrate\ hydrator maps data to models using a column map, and now respects the \orm.case\_insensitive\_column\_map\ setting to perform case-insensitive lookups when a column is not found in the map. A new \CaseInsensitiveColumnMap\ helper and a \GetPrivateProperties\ utility with caching support these behaviors, ensuring private properties are written directly rather than through potentially interfering setters.
ext/phalcon/mvc/model/hydration · high confidence
Introduce ADR (Action Domain Responder) application components
Added the core ADR pattern implementation for Phalcon, including the Application composition root, Dispatcher, Pipeline, EventfulHandler, and ErrorResponder. The Application class now manages the request lifecycle by routing, filtering attributes, dispatching actions through a middleware pipeline, and handling errors via a dedicated responder that logs exceptions and returns appropriate HTTP responses. This provides a structured, decoupled approach to handling HTTP requests within the framework.
phalcon/ADR · high confidence
Introduce AbstractBag base class for HTTP request data
The \ext/phalcon/http/request/bag\ location now includes the \AbstractBag\ class, which serves as the shared foundation for HTTP request bags. This class implements \ArrayAccess\, \Countable\, and \IteratorAggregate\, providing a unified interface for storing and retrieving string- or integer-keyed values. It exposes standard methods such as \get\, \set\, \has\, \remove\, \all\, and \clear\, along with typed readers like \getInt\, \getString\, \getBool\, \getFloat\, and \getArray\ that support default values. The implementation also includes protected hooks (\normalizeKey\, \normalizeItems\) to allow subclasses to customize key handling, and explicitly rejects the array append syntax (\$bag\[\] = $value\) to prevent ambiguous writes. Additionally, the \AttributeBag\ class is introduced as a concrete subclass of \AbstractBag\ specifically for holding arbitrary application-defined request attributes.
ext/phalcon/http/request/bag · high confidence
Introduce Factory component with abstract base classes and exception
The \ext/phalcon/factory\ directory now contains the compiled C source and header files for the new Factory component. This includes \AbstractConfigFactory\ for validating configuration inputs (accepting arrays or \ConfigInterface\ objects and ensuring required elements are present), \AbstractFactory\ which extends the config factory to manage service registration and retrieval via a mapper, and a dedicated \Exception\ class for factory-related errors. These classes provide the foundational structure for service instantiation and configuration management within the Phalcon framework.
ext/phalcon/factory · high confidence
Introduce Phalcon Time Clock abstraction
Added the \Phalcon\\Time\\Clock\ component, providing a \ClockInterface\ and two implementations: \SystemClock\ for retrieving the current time based on a specified timezone, and \FrozenClock\ for deterministic timekeeping in tests or simulations. The \FrozenClock\ supports static factory methods \fromSystemTimezone\ and \fromUTC\, as well as an \adjust\ method to mutate the frozen time using date modifier strings. The component also includes a dedicated \InvalidModifier\ exception for handling invalid time adjustments.
ext/phalcon/time · high confidence
Introduces ADR convention-based router with attribute filtering
Adds a new Action Domain Responder (ADR) router implementation that derives action classes from HTTP method and path segments without requiring a static route table. The router matches requests by deriving class names from the path structure and resolves middleware via a namespace-prefix map. It includes an AttributeFilter that processes static \params()\ declarations on action classes to validate, cast, and convert URL segments into typed attributes, and a RouterMatch value object to hold the resulting action, attributes, and middleware.
phalcon/ADR/Router · high confidence
Introduces Access contract for authorization gates
Adds the \Access\ interface in the \Phalcon\\Contracts\\Auth\\Access\ namespace, defining the contract for authorization gates that determine whether an identity may perform a specific action. The interface specifies methods to check permissions (\isAllowed\), retrieve action exclusions or inclusions (\getExceptActions\, \getOnlyActions\), configure these lists (\setExceptActions\, \setOnlyActions\), and handle redirections (\redirectTo\). This establishes the foundational API for gate-based access control within the authentication system.
phalcon/Contracts/Auth/Access · high confidence
Introduces PSR-13 compliant Link and LinkProvider value objects
The \phalcon/Html/Link\ component now implements the PSR-13 HTTP Link interface, providing immutable value objects for managing link relationships. Users can create \Link\ instances with attributes, HREFs, and relationship types (rels), and check if a link is templated. The \LinkProvider\ allows collecting and filtering links by relationship. Additionally, \EvolvableLink\ and \EvolvableLinkProvider\ classes offer builder-style methods (\withAttribute\, \withHref\, \withRel\, \withLink\, etc.) to create modified copies of these objects, supporting a fluent API for constructing link collections.
phalcon/Html/Link · high confidence
Introduces core ADR (Action Domain Responder) contract interfaces
The \phalcon/Contracts/ADR\ namespace now provides the foundational interfaces for the Action Domain Responder pattern, including \Application\ for end-to-end request handling, \Dispatcher\ for resolving actions and managing middleware pipelines, \Handler\ and \Action\ for request processing, and \Middleware\ for wrapping the handler chain. Additionally, \ADRTypes\ defines a central registry of PHPStan type aliases for route attributes, middleware maps, and input data, ensuring consistent type checking across the ADR components.
phalcon/Contracts/ADR · high confidence
Introduces factory classes for storage adapters and serializers
The Storage component now includes \AdapterFactory\ and \SerializerFactory\ classes to centralize the creation of storage adapters (such as Redis, Memcached, and Weak) and serialization formats (including JSON, PHP, and Igbinary). These factories allow users to instantiate specific adapter and serializer implementations by name, passing configuration options and shared dependencies like the serializer factory to the adapter constructor. A dedicated \Storage\\Exception\ class is also introduced to handle errors within this namespace.
phalcon/Storage · high confidence
Introduces immutable ADR Payload, Status constants, and injectable factory
The \phalcon/ADR/Payload\ component now provides an immutable \Payload\ class that carries result data, messages, and exceptions, along with a \Status\ class defining named constants (e.g., \SUCCESS\, \NOT\_FOUND\, \ERROR\) for common response states. To support testing and dependency injection, a \PayloadFactory\ is included, mirroring the payload's static named factories (such as \success\, \error\, \notFound\) as injectable instance methods.
phalcon/ADR/Payload · high confidence
Introduces lazy resolution helpers for the dependency injection container
Adds a new \Lazy\ resolver subsystem under \phalcon/Container/Resolver/Lazy\ that enables deferred, on-demand resolution of container dependencies. This includes concrete lazy wrappers for retrieving services (\Get\), instantiating new objects (\NewInstance\), invoking static or instance methods (\GetCall\, \NewCall\, \StaticCall\), calling functions (\FunctionCall\, \Call\), and resolving environment variables (\Env\, \EnvDefault\, \CsEnv\). A \LazyFactory\ provides static entry points for these types, and \ArrayValues\ allows lazy resolution of arrays containing mixed lazy and concrete values. These components allow developers to define complex dependency graphs where resolution is triggered only when the value is actually accessed, improving performance and enabling circular dependency handling.
phalcon/Container/Resolver · high confidence
Introduces shared queue adapter base classes and utilities
Adds a set of abstract base classes and helper utilities to the \phalcon/Queue/Adapter\ namespace to standardize how queue transports are implemented. This includes \AbstractConsumer\ for polling-based message consumption, \AbstractProducer\ with default unsupported behaviors for delivery delay, priority, and TTL, and \AbstractContext\ for creating generic queue and topic destinations. It also introduces \MessageEnvelope\ for consistent serialization/deserialization of message bodies and headers, \QueueDestinationGuard\ for validating destination types, and concrete \GenericQueue\ and \GenericTopic\ classes. These components provide a common foundation for all queue adapters, reducing duplication and ensuring consistent behavior across different transport implementations.
phalcon/Queue/Adapter · high confidence
Introduction of ADR Payload contract
Added the \Payload\ interface within the \Phalcon\\Contracts\\ADR\\Payload\ namespace, defining the contract for immutable payloads produced by the domain layer. This interface specifies methods to retrieve domain data such as exceptions, extras, input, messages, results, and status, alongside immutable 'with' methods to create modified copies of the payload.
phalcon/Contracts/ADR/Payload · high confidence
Introduction of ADR Responder and Formatter contracts
Added new interface contracts for the Action Domain Responder (ADR) pattern: the \Responder\ interface, which defines how a payload is converted into an HTTP response, and the \Formatter\ interface, which specifies how payloads are rendered into strings for specific content types. These interfaces establish the foundational structure for response handling within the framework's ADR layer.
phalcon/Contracts/ADR/Responder · high confidence
Introduction of ADR Router contract interfaces
The framework introduces a new set of interfaces under the \Phalcon\\Contracts\\ADR\\Router\ namespace to support convention-based routing aligned with the Action Domain Responder pattern. The \Router\ interface defines methods for matching requests to action classes based on HTTP method and path conventions, deriving candidate classes, and generating canonical paths. The \AttributeFilter\ interface specifies how positional URL segments are converted into named request attributes based on static action declarations. The \RouterMatch\ interface represents the result of a route match, exposing the resolved action class, extracted attributes, middleware list, and optional route name.
phalcon/Contracts/ADR/Router · high confidence
Introduction of ADRThrowable interface for unified exception handling
A new \ADRThrowable\ interface has been added to the \Phalcon\\Contracts\\ADR\\Exceptions\ namespace, extending PHP's native \Throwable\. This contract serves as a base type for all ADR (Action Domain Responder) exceptions, allowing users to catch all ADR-related errors with a single type check rather than handling each specific exception individually.
phalcon/Contracts/ADR/Exceptions · high confidence
Introduction of Auth Adapter contracts
The framework now exposes a set of interfaces in the \Phalcon\\Contracts\\Auth\\Adapter\ namespace to standardize authentication implementations. The \Adapter\ interface defines the core contract for looking up users by credentials or ID and validating passwords, while \AdapterConfig\ provides a shared configuration hook for specifying the user model. Additionally, the \RememberAdapter\ interface extends the base contract to support persistent 'remember-me' functionality, allowing adapters to create and validate remember tokens.
phalcon/Contracts/Auth/Adapter · high confidence
Introduction of BindableInterface for Model Binding
The Phalcon MVC Model Binder now includes a new BindableInterface, allowing classes to define how they map to model names and parameters. This interface introduces a getModelName method, enabling developers to create custom bindable objects that integrate seamlessly with the model binding process.
ext/phalcon/mvc/model/binder · high confidence
Introduction of Factory and Config traits for service instantiation
New traits have been added to the Phalcon framework to support a mapper-based factory pattern. The FactoryTrait provides mechanisms for caching instantiated objects, retrieving services by name from a registered mapper, and initializing service definitions, while throwing exceptions for unregistered services. The ConfigTrait complements this by standardizing configuration handling, allowing inputs to be either arrays or Phalcon Config objects, and enforcing the presence of required configuration elements.
phalcon/Traits/Factory · high confidence
Introduction of Flash message contracts and type definitions
Added the \Phalcon\\Contracts\\Flash\\Flash\ interface, which defines the canonical contract for flash messengers by specifying methods for error, notice, success, and warning messages. Also introduced the \Phalcon\\Contracts\\Flash\\FlashTypes\ interface to centralize PHPStan type definitions for flash CSS classes and message arrays, establishing a structured foundation for flash message handling.
phalcon/Contracts/Flash · high confidence
Introduction of Front Controller contract for unified execution entry points
The framework now includes a new \FrontController\ interface within the \Phalcon\\Contracts\\Front\ namespace, providing a standardized entry point for handling execution contexts such as HTTP and CLI. This contract defines a \run()\ method that returns an integer exit status (0 for success, 1–254 for non-success), allowing the framework to gracefully handle exceptions without forcing process termination via \exit()\. This change enables better integration with worker loops, test harnesses, and supervised processes by letting the caller decide how to handle the result, while also introducing \FrontTypeAliases\ to support static analysis with specific exit status type definitions.
phalcon/Contracts/Front · high confidence
Introduction of HTML Attributes interfaces
New interfaces, AttributesInterface and RenderInterface, have been added to the Phalcon\\Html\\Attributes namespace. AttributesInterface defines the contract for getting and setting HTML attributes, while RenderInterface specifies the method for generating a string representation of those attributes. These interfaces provide a standardized structure for HTML attribute handling within the framework.
phalcon/Html/Attributes · high confidence
Introduction of ItemTrait for ACL roles and components
A new \ItemTrait\ has been added to the \Phalcon\\Acl\\Traits\ namespace to standardize the structure of ACL roles and components. This trait introduces a \name\ property and an optional \description\ property, along with corresponding \getName()\ and \getDescription()\ accessors. It also implements \\_\_toString()\ to allow roles and components to be converted to their string name representation, providing a consistent interface for these entities within the Access Control List system.
phalcon/Acl/Traits · high confidence
Introduction of JWT Signer components
This change introduces the core signing infrastructure for JSON Web Tokens (JWT) within the Phalcon Encryption module. It adds the \SignerInterface\ contract, an \AbstractSigner\ base class, and concrete implementations including \Hmac\ (supporting SHA-512, SHA-384, and SHA-256 algorithms) and \None\ (for unsigned tokens). These components provide the ability to sign and verify JWT payloads using HMAC algorithms or no signature at all, forming the foundational layer for JWT security operations.
phalcon/Encryption/Security/JWT/Signer · high confidence
Introduction of Logger contract interfaces and PHPStan type definitions
This change introduces a new set of interfaces in the \Phalcon\\Contracts\\Logger\ namespace to define the canonical contracts for the logging system. Specifically, it adds \Adapter\ for logger adapter behaviors, \Formatter\ for message formatting, and \Logger\ for the main logger interface, which includes standard logging methods (e.g., \alert\, \critical\, \debug\, \error\, \info\, \warning\, \trace\) and adapter management. Additionally, a \LoggerTypes\ interface is added to centralize PHPStan array shape definitions (such as \logger\_context\, \logger\_levels\, and configuration structures) used across the logger namespace, improving static analysis support.
phalcon/Contracts/Logger · high confidence
Introduction of Paginator contracts and type definitions
This change introduces new interface contracts for the Paginator component, specifically \Adapter\, \Repository\, and \PaginatorTypes\. The \Adapter\ interface defines the contract for paginator adapters, including methods to get/set limits, set the current page, and retrieve paginated results. The \Repository\ interface standardizes the structure of pagination state, supporting both offset-based and cursor-based pagination strategies by defining properties like current page, items, limits, and navigation links. Additionally, \PaginatorTypes\ provides a centralized registry of PHPStan type aliases for paginator configurations, queries, and results, improving type safety and consistency across the paginator namespace.
phalcon/Contracts/Paginator · high confidence
Introduction of Phalcon Image component with factory and enum support
The Phalcon framework now includes a new Image component located in the \phalcon/Image\ namespace. This addition introduces an \ImageFactory\ that allows users to create image manipulation instances (supporting GD and Imagick adapters) via a configuration array or service container. It also provides an \Enum\ class for defining resizing constraints (such as AUTO, WIDTH, HEIGHT) and flipping directions, along with a dedicated \Exception\ class for error handling within the image module.
phalcon/Image · high confidence
Introduction of Phalcon\\Autoload component with dedicated exception hierarchy
The Phalcon\\Autoload component is introduced, providing a new autoloader capable of automatically loading namespaced or non-namespaced classes, files, and extensions. This location specifically implements the core Loader class along with a dedicated exception hierarchy (Phalcon\\Autoload\\Exception and specific subclasses like LoaderDirectoriesNotArray and LoaderMethodNotCallable) to handle validation errors, such as invalid directory parameters or non-callable methods, ensuring robust error reporting during the autoloading process.
phalcon/Autoload · high confidence
Introduction of Phalcon\\Contracts\\Db canonical interfaces
The Db namespace now includes a new \Phalcon\\Contracts\\Db\ namespace containing canonical interface contracts for core database objects, including \Check\, \Column\, \Dialect\, \Index\, \Reference\, \Result\, and \Geometry\. These interfaces define the public API for database schema elements and dialect operations, serving as the foundation for the Db layer in the upcoming v7 release. The \Dialect\ interface specifically introduces row-locking modifiers (\LOCK\_NOWAIT\, \LOCK\_SKIP\_LOCKED\) for \FOR UPDATE\ clauses, while the \Column\ and \Index\ interfaces lay the groundwork for future support of features like invisible columns, partial indexes, and array columns. A central \DbTypes\ interface is also provided to standardize PHPStan type aliases across the Db namespace.
phalcon/Contracts/Db · high confidence
Introduction of Phalcon\\Di\\Service\\Builder for complex service definitions
The dependency injection container now includes a new \Phalcon\\Di\\Service\\Builder\ class that allows users to instantiate services using complex, array-based definitions. This builder supports defining a target class name, passing constructor arguments, and specifying method calls (such as setters) to be executed on the instance after creation, providing a more declarative way to wire up services compared to simple factory closures.
ext/phalcon/di/service · high confidence
Introduction of Phalcon\\Tag component for HTML generation
The \Phalcon\\Tag\ class has been added to the framework, providing a set of static helpers to simplify the creation of HTML tags. This component supports various HTML document types (HTML5, XHTML, etc.) and includes methods for generating input fields (such as checkboxes, colors, dates, and datetime-local), managing document titles, and handling URL services. It integrates with the dependency injection container for escaper and URL services, ensuring consistent HTML escaping and link generation across the application.
phalcon · high confidence
Introduction of Simple View component and dedicated exception class
The \phalcon/Mvc/View\ area now includes a new \Simple\ view component and a dedicated \Exception\ class. The \Simple\ component allows developers to render views without hierarchical levels, supporting direct rendering of templates with parameters and partials. It implements the \Renderer\ contract and utilizes traits for directory separation and file handling. The new \Exception\ class provides a specific exception type for errors thrown by the \Phalcon\\Mvc\\View\ namespace, improving error handling granularity.
phalcon/Mvc/View · high confidence
Introduction of a new standalone Container component
The Phalcon framework now includes a new \phalcon/Container\ component, providing a dedicated dependency injection container and factory. This new implementation, located in the \Phalcon\\Container\ namespace, introduces classes such as \Container\ and \ContainerFactory\ which implement interfaces like \Collection\, \Enumerable\, and \IocContainerFactory\. The container supports service binding, aliasing, parameter resolution, and extensible service definitions via processors for objects, closures, and strings. This change represents a structural addition to the framework's core, moving container logic into its own dedicated folder and namespace, distinct from the previous \Phalcon\\Di\ implementation.
phalcon/Container · high confidence
Introduction of canonical database adapter contract
The Phalcon framework now provides a canonical interface for database adapters in the new \Phalcon\\Contracts\\Db\\Adapter\ namespace. This \Adapter.zep\ file defines the standard contract that all database adapters must implement, ensuring consistency across different database drivers. The interface includes methods for common database operations such as connecting, executing queries, managing transactions, and describing schema objects. This change establishes a unified contract layer that third-party adapters and internal implementations can rely on for compatibility.
phalcon/Contracts/Db/Adapter · high confidence
Introduction of centralized PHPStan type definitions for the DataMapper
A new \DataMapperTypes\ interface has been added to the \phalcon/Contracts/DataMapper\ namespace to serve as a central registry for array shapes used across the DataMapper component. This file defines a comprehensive set of \@phpstan-type\ annotations covering connection arguments, query stores, fetch results, and various data structures, enabling stricter static analysis and improved type safety for developers using the DataMapper.
phalcon/Contracts/DataMapper · high confidence
Introduction of dedicated CSS and JavaScript asset classes
The Assets component now includes specific \Css\ and \Js\ classes within the \Phalcon\\Assets\\Asset\ namespace to represent CSS and JavaScript assets respectively. These classes extend the base \Asset\ class and provide a typed constructor interface, allowing users to instantiate assets with explicit type handling for paths, local/remote status, filtering, attributes, and versioning.
phalcon/Assets/Asset · high confidence
Introduction of dedicated Transaction exception classes
The \Phalcon\\Mvc\\Model\\Transaction\ namespace now includes specific exception classes: \Exception\ (extending the base model exception) and \Failed\. The \Failed\ exception is designed to be thrown to exit try/catch blocks for isolated transactions and provides methods to retrieve the associated model record (\getRecord\) and its validation messages (\getRecordMessages\), allowing developers to handle transaction failures with more context about the specific model state that caused the issue.
phalcon/Mvc/Model/Transaction · high confidence
Introduction of new Phalcon Auth Guard system
This change introduces the core components for the new authentication guard system in the \phalcon/Auth/Guard\ directory. It adds \AbstractGuard\ as the base implementation for guards, providing standard methods for checking authentication status, retrieving the current user, and managing adapters. It includes \GuardLocator\ to manage and resolve specific guard instances, with built-in support for 'session' and 'token' guards. The \Session\ guard implements stateful authentication, handling login, logout, session regeneration, and 'remember me' functionality via cookies. The \Token\ guard provides stateless authentication by extracting and validating bearer tokens from HTTP requests. Additionally, \UserRemember\ is added as a value object to safely parse and represent the contents of remember-me cookies.
phalcon/Auth/Guard · high confidence
Introduction of new Phalcon Forms Element classes
The \phalcon/Forms/Element\ directory now contains a comprehensive set of new form element classes, including \AbstractElement\, \Check\, \CheckGroup\, \Date\, \Email\, \File\, \Hidden\, \Numeric\, \Password\, \Radio\, \RadioGroup\, \Select\, \Submit\, \Text\, and \TextArea\. These classes provide the foundational components for building HTML forms, with specific implementations for various input types and groups. Notably, the \Check\ element now supports setting an unchecked value via \setUncheckedValue()\, addressing issue \#16982, and the \Select\ element's constructor signature has been adjusted as per issue \#15186. The \CheckGroup\ and \RadioGroup\ classes allow for rendering groups of checkboxes and radio buttons respectively, with options passed as associative arrays.
phalcon/Forms/Element · high confidence
Introduction of the Phalcon Cache Contract interface
A new \Phalcon\\Contracts\\Cache\\Cache\ interface has been added to define the canonical contract for cache operations. This interface standardizes the API for caching by specifying methods for clearing the cache, deleting single or multiple items, fetching values, checking for existence, and setting data with optional time-to-live (TTL) parameters. Implementing this contract allows for consistent behavior across different cache backends within the Phalcon framework.
ext/phalcon/contracts/cache, phalcon/Contracts/Cache · high confidence
Introduction of the Phalcon Storage Adapter component
The framework now includes a new \Phalcon\\Storage\\Adapter\ namespace providing a unified interface for data persistence. This release introduces a suite of adapters—Apcu, Libmemcached, Memory, Redis, RedisCluster, Stream, and Weak—along with an \AbstractAdapter\ base class and \AdapterInterface\. Users can now leverage consistent methods for storing, retrieving, and deleting data, including support for atomic counters, key prefixes, and time-to-live (TTL) management. The component also adds specific exception classes for handling connection and authentication failures, enabling more robust error handling in storage operations.
phalcon/Storage/Adapter, phalcon/Storage/Serializer · high confidence
Introduction of the Phalcon\\Filter component with dedicated exception handling and validation capabilities
The \phalcon/Filter\ area now introduces the core \Filter\ class, which provides a centralized API for sanitizing input data using a wide range of built-in sanitizers (such as \absint\, \alnum\, \email\, \ip\, \url\, etc.) and supports custom mapper configurations. This release also adds a dedicated \Phalcon\\Filter\\Exception\ class to handle filter-specific errors and introduces the \Validation\ class, enabling data validation against custom or built-in validators with support for default messages and combined-field validation. Additionally, a \FilterFactory\ is provided to instantiate the filter service, and the \Validation\ class includes a \fails()\ method to check validation status.
phalcon/Filter · high confidence
New ACL and binary access gates for the Auth component
The \phalcon/Auth/Access\ directory now introduces a new access-control system built around an \AbstractAccess\ base class and a service locator (\AccessLocator\). This adds three specific access gates: \Acl\, which enforces permissions by checking a user's role against a Phalcon ACL adapter (supporting module-prefixed components and handler-based context); \Auth\, which allows access only when the user is authenticated; and \Guest\, which allows access only when the user is unauthenticated. All gates support granular filtering via \exceptActions\ and \onlyActions\ lists, allowing developers to bypass or restrict specific actions within a gate's scope.
phalcon/Auth/Access · high confidence
New ADR (Action Domain Responder) application component
The framework now includes a new ADR-based application layer under \ext/phalcon/adr\. This adds the \Phalcon\\ADR\\Application\ composition root, which manages the service container and request handling flow. The component introduces \Phalcon\\ADR\\Container\\AdrProvider\ to register ADR-specific service bindings (such as the router, dispatcher, and responder) into the container. It also provides \Phalcon\\ADR\\Dispatcher\ for resolving and executing actions through a middleware pipeline, \Phalcon\\ADR\\Emitter\\SapiEmitter\ for sending HTTP responses, and \Phalcon\\ADR\\ErrorResponder\ for converting exceptions into appropriate HTTP responses with correlation IDs. Additionally, event constants are defined in \Phalcon\\ADR\\Events\\Event\ to support lifecycle hooks like \adr:beforeExecuteAction\ and \pipeline:beforeDispatch\. Several new exception classes (e.g., \ActionDirectoryNotSet\, \HeadersAlreadySent\) are also included to handle specific ADR-related errors.
ext/phalcon/adr · high confidence
New ADR Emitter contract for response handling
A new \Emitter\ interface has been added to the \Phalcon\\Contracts\\ADR\\Emitter\ namespace, defining a contract for sending HTTP responses to the client. This interface, based on the Action Domain Responder pattern, specifies an \emit\ method that accepts a \ResponseInterface\ object and is intended to be called by the front controller to finalize and deliver the response.
phalcon/Contracts/ADR/Emitter · high confidence
New ADR HTTP front controller entry point
The framework introduces a new Action Domain Responder (ADR) HTTP front controller located in \phalcon/ADR/Front\. \AbstractHttpFront\ provides the core lifecycle: it boots a DI container, loads the environment, registers providers (defaulting to \AdrProvider\), builds an \Application\ instance, handles the request, and emits the response. \HttpFront\ serves as the concrete default implementation that users can extend to customize environment loading or provider registration.
phalcon/ADR/Front · high confidence
New ADR Input bag for unified request data access
Introduced a new \Phalcon\\ADR\\Input\\Input\ class that consolidates query parameters, POST data, JSON body, and route attributes into a single, string-keyed bag. This component simplifies input handling in Action Domain Responder patterns by providing a unified interface (\get\, \has\, \toArray\) and supports extension for typed input objects via late static binding on factory methods like \fromRequest\ and \fromArray\.
phalcon/ADR/Input · high confidence
New ADR Responder layer with chainable, typed response handling
The framework introduces a new Action Domain Responder (ADR) responder layer in \phalcon/ADR/Responder\ that replaces ad-hoc response logic with a composable chain of single-purpose responders. \ChainResponder\ links \StatusResponder\ (mapping domain \Status\ constants to HTTP codes via \StatusMapper\), \RedirectResponder\ (applying \Location\ headers with open-redirect protection for internal URLs), and \FormatResponder\ (negotiating content types via \Accept\ headers). Concrete responders like \JsonResponder\, \TextResponder\, and \ViewResponder\ bind specific formatters or templates, allowing actions to return structured payloads while the responder chain handles status codes, redirects, and content serialization.
phalcon/ADR/Responder · high confidence
New ADR Router contract interfaces for convention-based routing
The framework introduces a new set of interfaces under the Action Domain Responder (ADR) pattern to support convention-based routing without a static route table. The \Phalcon\\Contracts\\ADR\\Router\\Router\ interface defines the core routing logic, including methods to match requests, derive candidate action classes from HTTP methods and paths, and configure the base namespace and action directory. The \Phalcon\\Contracts\\ADR\\Router\\RouterMatch\ interface specifies the structure of a successful route match, exposing the resolved action class, extracted route attributes, middleware list, and optional route name. Additionally, the \Phalcon\\Contracts\\ADR\\Router\\AttributeFilter\ interface provides a contract for validating and converting positional URL segments into named request attributes based on the matched action's configuration.
ext/phalcon/contracts/adr/router · high confidence
New ADR exception hierarchy for structured error handling
The ADR component now includes a dedicated exception hierarchy under the Phalcon\\ADR\\Exceptions namespace. A base Exception class implements the ADRThrowable contract, serving as the parent for specific typed exceptions: RouteNotFound, MethodNotAllowed, NotAnAction, ActionDirectoryNotSet, HeadersAlreadySent, and OutputAlreadySent. This allows applications to catch specific ADR-related errors rather than relying on generic exception handling.
phalcon/ADR/Exceptions · high confidence
New ADR middleware components for request tracking, timing, method override, and CORS
The \phalcon/ADR/Middleware\ area introduces four new middleware classes that enhance request handling and security. \RequestIdMiddleware\ ensures every request has a unique \X-Request-Id\ header, reusing incoming IDs or generating new ones, and exposes this ID in request attributes and response headers. \TimingMiddleware\ measures pipeline execution time and adds an \X-Response-Time\ header to responses. \MethodOverrideMiddleware\ safely enables HTTP method overriding (PUT, PATCH, DELETE) via the \\_method\ parameter for POST requests, preventing spoofing of other methods. \CorsMiddleware\ provides configurable Cross-Origin Resource Sharing support, allowing specific origins, methods, and headers, with strict handling of credentials to prevent security vulnerabilities like CWE-942 by not reflecting wildcard origins when credentials are enabled.
phalcon/ADR/Middleware · high confidence
New ADR service provider for dependency injection
A new \AdrProvider\ class has been added to the \Phalcon\\ADR\\Container\ namespace to register ADR-specific service bindings in the application container. This provider configures the container to use ADR contracts (such as \Dispatcher\, \Router\, \Responder\, and \Emitter\) with their concrete implementations, allowing applications following the Action Domain Responder pattern to leverage Phalcon's dependency injection for these components.
phalcon/ADR/Container · high confidence
New Arr helper classes for array manipulation
The \phalcon/Support/Helper/Arr\ directory now contains a comprehensive set of new helper classes for array operations, including \Blacklist\, \Chunk\, \Filter\, \First\, \FirstKey\, \Flatten\, \Get\, \Group\, \Has\, \IsUnique\, \Last\, \LastKey\, \Order\, \Pluck\, \Set\, \SliceLeft\, \SliceRight\, \Split\, \ToObject\, \ValidateAll\, \ValidateAny\, and \Whitelist\. These classes provide standardized, callable interfaces for common array tasks such as filtering, sorting, grouping, and extracting data, with \AbstractArr\ serving as a base class that composes the \FilterTrait\ for shared functionality.
phalcon/Support/Helper/Arr · high confidence
New Auth contract interfaces and type definitions
The \phalcon/Contracts/Auth\ directory now includes a set of new interfaces and a type registry to standardize the authentication layer. \AuthUser\ and \AuthRemember\ define the contracts for user models and remember-me token persistence, while \RememberToken\ specifies the interface for token storage entries. The \Manager\ interface establishes the core API for managing guards, handling authentication attempts, and enforcing access gates. Additionally, \AuthTypes\ provides a centralized registry of PHPStan array shapes (such as credentials, guard configurations, and access contexts) to ensure consistent type checking across the authentication system.
phalcon/Contracts/Auth · high confidence
New Beanstalkd queue adapter
Adds a new Beanstalkd adapter to the Phalcon Queue component, enabling applications to use Beanstalkd as a message queue backend. The implementation includes a low-level socket client (BeanstalkConnection) that supports persistent connections, tube management, and job operations (put, reserve, delete, release, bury, touch). It provides a full adapter suite including a connection factory, producer (supporting priority and delivery delay), consumer (with blocking and non-blocking receive modes), subscription consumer, and context for queue inspection and purging.
phalcon/Queue/Adapter/Beanstalk · high confidence
New CLI ConsumerTask for queue workers
Added a new ConsumerTask class in the Phalcon Queue CLI component that provides a command-line interface for running queue workers. This task allows users to bind a specific queue to a processor service and configure worker limits (max messages, time, memory, jitter) via CLI options, serving as a thin adapter for Phalcon CLI applications while keeping the core worker logic decoupled.
phalcon/Queue/Cli · high confidence
New Complex and Simple resultset implementations with serialization support
The \phalcon/Mvc/Model/Resultset\ area introduces two new concrete resultset classes: \Complex\ and \Simple\. The \Complex\ resultset handles rows containing both complete objects and scalar values, building each row on demand based on column types and hydration mode. The \Simple\ resultset handles rows containing only complete model objects, supporting eager loading maps and snapshot keeping. Both classes implement \\_\serialize()\ and \\\_unserialize()\ methods to allow resultsets to be serialized and deserialized, preserving their state (rows, cache, column types/map, hydration mode) for storage or transmission.
phalcon/Mvc/Model/Resultset · high confidence
New DataMapper PDO connection and event infrastructure
The \phalcon/DataMapper/Pdo\ directory now includes the core classes for the PDO-based DataMapper implementation. This adds a \Connection\ class that manages database connectivity, supports read/write connection splitting via a \ConnectionLocator\, and integrates with the profiler. It also introduces an \Events\ class that defines lifecycle hooks (such as \beforeConnect\, \afterQuery\, and \beforePerform\) allowing users to intercept and monitor DataMapper operations.
phalcon/DataMapper/Pdo · high confidence
New DataMapper PDO connection layer with auto-reconnect and event support
The Phalcon DataMapper introduces a new PDO connection architecture in \phalcon/DataMapper/Pdo/Connection\, featuring an \AbstractConnection\ base class and a \Decorated\ wrapper for existing PDO instances. This implementation adds opt-in automatic reconnection (disabled by default) to handle lost database connections transparently, integrates lifecycle events for monitoring and debugging, and includes a built-in profiler for tracking database operations. The new layer provides enhanced fetch methods and transaction management while maintaining compatibility with existing interfaces.
phalcon/DataMapper/Pdo/Connection · high confidence
New DataMapper PDO exception classes
The DataMapper component now includes a dedicated set of exception classes under the \Phalcon\\DataMapper\\Pdo\\Exception\ namespace to provide more granular error handling for PDO operations. These new exceptions include \CannotDisconnect\ for issues when disconnecting from an externally injected connection, \ConnectionNotFound\ when a named connection cannot be located, \DriverNotSupported\ for unsupported database drivers, \OperationCancelled\ to distinguish deliberate listener cancellations from database failures, and \UnknownDriverMethod\/\UnknownQueryMethod\ for invalid method calls. This allows applications to catch and handle specific DataMapper PDO errors rather than relying on generic exceptions.
ext/phalcon/datamapper/pdo/exception, ext/phalcon/encryption/crypt/exception, phalcon/DataMapper/Pdo/Exception · high confidence
New DataMapper Query Builder components
The \phalcon/DataMapper/Query\ area introduces a new set of query-building classes (\Select\, \Insert\, \Update\, \Delete\, \Bind\, \QueryFactory\, and their abstract bases) that provide a fluent API for constructing SQL statements. This adds the capability to programmatically build and execute database queries with support for binding values, handling \WHERE\/\HAVING\ conditions, and managing result fetching through the \Select\ object's proxied connection methods.
phalcon/DataMapper/Query · high confidence
New Db Profiler Item class with precise elapsed time tracking
The Db Profiler now includes a dedicated Item class to represent individual profiling records. This class exposes getters and setters for SQL statements, bind parameters, and timestamps, and introduces a getTotalElapsedNanoseconds method to provide high-precision duration calculations for database operations.
phalcon/Db/Profiler · high confidence
New Domain Payload component with status vocabulary and factory
The \phalcon/Domain\ area now includes a new \Payload\ component (\Phalcon\\Domain\\Payload\) that standardizes how domain-layer results are communicated. This change introduces a \Payload\ class and corresponding \PayloadInterface\ to hold input, output, messages, extras, and potential exceptions, along with a \PayloadFactory\ to allow dependency-injection-based instantiation. A new \Status\ class provides a vocabulary of string constants (e.g., SUCCESS, ERROR, FAILURE) to indicate outcome states, distinguishing between exceptions and business-rule failures. The interfaces are marked as deprecated in favor of contracts in \Phalcon\\Contracts\\Domain\\Payload\, signaling a migration path for consumers.
phalcon/Domain · high confidence
New Encryption and Security components with hardened authentication
The \phalcon/Encryption\ area now introduces two new classes: \Crypt\, which provides encryption/decryption capabilities using configurable ciphers, padding, and HMAC-based integrity checks, and \Security\, which handles password hashing (supporting bcrypt and Argon2), CSRF token management, and random string generation. The \Security\ component includes a \workFactor\ property for password hashing cost and uses \hmac\_equals\ for constant-time token comparison to prevent timing attacks. These components replace the previous \Crypt\ and \Security\ implementations, offering a more robust and standardized API for application security.
phalcon/Encryption · high confidence
New EventsAwareTrait for event integration
Added the EventsAwareTrait to the Phalcon Events namespace, providing classes with a standardized way to integrate with the event system. This trait introduces properties and methods to manage an EventsManager instance, including getters and setters, and a protected helper method to fire events. The implementation includes logic to ensure that when an event is stopped by a listener (stopOnFalse), the cancellation is respected and not overwritten by subsequent listeners, enhancing the reliability of event handling within components that use this trait.
phalcon/Events/Traits · high confidence
New Forms Schema contract and type definitions
The Forms namespace now includes a new \Phalcon\\Contracts\\Forms\\Schema\ interface that defines a contract for objects supplying a normalized list of form element definitions (including type, name, label, default, attributes, filters, validators, and options). Additionally, a \Phalcon\\Contracts\\Forms\\FormsTypes\ interface has been added to serve as a central registry for PHPStan array shapes used across the Forms namespace, such as \forms\_schema\_definition\, \forms\_options\, and \forms\_elements\. These additions provide a standardized way to define and type-check form structures.
ext/phalcon/contracts/forms · high confidence
New Grouped config adapter and refactored INI adapter
The Config component now includes a new Grouped adapter that allows merging multiple configuration sources (files, arrays, or existing Config objects) into a single Config instance, supporting mixed adapter types via the ConfigFactory. The INI adapter has been refactored to use the new IniTrait for parsing and explicitly casts string values to appropriate PHP types (booleans, integers, floats, null) to ensure consistent data types, addressing previous inconsistencies in how INI values were handled.
phalcon/Config/Adapter · high confidence
New HTML debug renderer for exception reports
The Phalcon debug component now includes an HTML renderer that transforms exception reports into a structured, interactive debug page. This renderer generates a complete HTML document featuring a masthead with the Phalcon logo and version badge, an error card displaying the exception class, message, file location, and PHP version, and a tabbed interface for viewing the backtrace, request and server superglobals, included files, memory usage, and variables. The output is styled via external CSS/JS assets and includes interactive features such as theme toggling, trace copying, and collapsible backtrace frames.
phalcon/Support/Debug/Renderer · high confidence
New HTTP Request File handling components
The \phalcon/Http/Request\ area now includes dedicated classes for handling uploaded files: \Phalcon\\Http\\Request\\File\ provides an object-oriented wrapper around the \$\_FILES\ superglobal with methods to access file metadata (name, size, type, error) and move the file, while \Phalcon\\Http\\Request\\FileInterface\ defines the contract for these operations. Additionally, a new \Phalcon\\Http\\Request\\Exception\ class is introduced to handle exceptions specific to the HTTP Request component, ensuring that errors thrown during file handling or request processing are properly categorized.
phalcon/Http/Request · high confidence
New HTTP contract interfaces and PHPStan type definitions
The HTTP contracts module now includes the \AttributeRequest\ interface, which exposes the \getAttributes()\ method for requests carrying an attribute bag without modifying the base \RequestInterface\, allowing consumers to type against attribute-bearing requests safely. Additionally, the new \HttpTypes\ interface provides a central registry of PHPStan array shapes for HTTP components, covering cookies, request/response headers, authentication data, and file uploads to improve static analysis accuracy.
phalcon/Contracts/Http · high confidence
New HTTP request attribute bag for storing arbitrary request data
The framework introduces a new \AttributeBag\ class within the \Phalcon\\Http\\Request\\Bag\ namespace, backed by a new \AbstractBag\ base implementation. This allows developers to store and retrieve arbitrary, application-defined values attached to the request lifecycle (such as data from routers or security components) separately from standard HTTP parameters. The bag supports standard array-like operations (get, set, has, remove, all) and provides typed accessors (getBool, getInt, getFloat, getArray) with default value fallbacks, while explicitly rejecting array-append syntax to ensure key integrity.
phalcon/Http/Request/Bag · high confidence
New Image component with factory and enum support
The ext/phalcon/image directory now includes the generated C source and header files for the Phalcon\\Image namespace. This adds the Phalcon\\Image\\Enum class, which defines integer constants for image manipulation options such as AUTO, HEIGHT, INVERSE, NONE, PRECISE, TENSILE, WIDTH, HORIZONTAL, and VERTICAL. It also introduces Phalcon\\Image\\Exception as the base exception class for image-related errors, and Phalcon\\Image\\ImageFactory, which provides a factory mechanism to create image adapter instances based on configuration (e.g., specifying adapter type, file path, width, and height). These files constitute the backend implementation layer for the new image handling capability.
ext/phalcon/image · high confidence
New JSON encoding and decoding traits with exception handling
Added DecodeTrait and EncodeTrait to the Phalcon framework, providing reusable components for JSON serialization and deserialization. These traits wrap PHP's native json\_encode and json\_decode functions to automatically throw a native \\JsonException on failure, ensuring consistent error handling for JSON operations within the framework.
phalcon/Traits/Support/Helper/Json · high confidence
New JSON helper classes with dedicated error handling
The \phalcon/Support/Helper/Json\ directory now contains dedicated \Encode\ and \Decode\ helper classes that wrap PHP's native \json\_encode\ and \json\_decode\ functions. These helpers enforce specific default options (such as \JSON\_HEX\_TAG\ and \JSON\_UNESCAPED\_SLASHES\) and provide robust error handling by throwing custom \JsonEncodeError\ and \JsonDecodeError\ exceptions instead of returning null or silent failures, ensuring that JSON processing errors are explicitly caught and handled by the application.
phalcon/Support/Helper/Json · high confidence
New JWT Token component with validation and verification capabilities
The \phalcon/Encryption/Security/JWT/Token\ namespace introduces a new set of classes for handling JSON Web Tokens, including \Token\, \Parser\, \Item\, \Signature\, and \Enum\. This addition provides a structured way to parse JWTs into headers, claims, and signatures, and offers the \Token\ class with \validate()\ and \verify()\ methods. The \validate()\ method checks registered claims (such as audience, expiration, issuer) against a provided \Validator\, while \verify()\ checks the token's signature using a \SignerInterface\. This component is part of the broader encryption and security restructuring in Phalcon.
phalcon/Encryption/Security/JWT/Token · high confidence
New MVC and CLI authentication dispatcher listeners
Added \AuthDispatcherListener\ classes for both MVC and CLI environments to automatically enforce active access gates during dispatch. The MVC listener attaches to the events manager to check permissions on controller actions and forwards the request if access is denied, while the CLI listener performs similar checks on CLI tasks.
phalcon/Auth/Mvc · high confidence
New MVC contracts and PHPStan type registry
The \phalcon/Contracts/Mvc\ area now includes new interface contracts and a centralized type registry to improve static analysis and extensibility. A new \Dispatcher\ interface extends the base dispatcher contract, exposing methods to manage active, last, and default controllers. A \CacheKeyProvider\ interface allows models to supply custom unique keys for the reusable records cache, ensuring stable cache hits across multiple object instances. Additionally, \MvcTypes\ introduces a comprehensive registry of PHPStan array shapes (prefixed with \mvc\_\) for models, routers, queries, and Volt nodes, providing a single source of truth for type definitions across the MVC namespace.
phalcon/Contracts/Mvc · high confidence
New MVC contracts and type definitions for static analysis
The framework introduces new contract interfaces and a centralized type registry within the \ext/phalcon/contracts/mvc\ directory to improve static analysis and code consistency. A new \Phalcon\\Contracts\\Mvc\\Dispatcher\ interface defines the contract for dispatcher operations, including methods to get and set controller names and suffixes. Additionally, a \Phalcon\\Contracts\\Mvc\\Model\\Relation\\CacheKeyProvider\ interface allows models to supply custom unique keys for the reusable records cache, ensuring stable cache hits across multiple object instances. Finally, a new \Phalcon\\Contracts\\Mvc\\MvcTypes\ interface serves as a central registry for PHPStan type aliases, declaring array shapes for MVC components such as routers, models, queries, and Volt nodes to prevent naming clashes and ensure uniform type definitions across the codebase.
ext/phalcon/contracts/mvc · high confidence
New Messages contract and type definitions
Added the \Phalcon\\Contracts\\Messages\\Messages\ interface to define the canonical contract for the message collection, specifying methods for appending messages, filtering by field, and iteration behavior. Introduced \Phalcon\\Contracts\\Messages\\MessagesTypes\ to centralize PHPStan type aliases for message lists, metadata, and serialized structures, ensuring consistent static analysis across the Messages namespace.
phalcon/Contracts/Messages · high confidence
New PDO Profiler with in-memory logging support
The DataMapper PDO layer now includes a new Profiler component that logs SQL query performance details (such as duration, statement, and backtrace) to a logger. This change introduces a MemoryLogger class for capturing log messages in memory without external dependencies, and updates the Profiler to use high-resolution timing (hrtime) for accurate performance measurement. Users can now enable query profiling to debug slow database operations via the new ProfilerInterface.
phalcon/DataMapper/Pdo/Profiler · high confidence
New PHP contracts for ACL components, roles, and adapters
The ACL namespace now includes a set of canonical PHP interfaces that define the structure and behavior of access-control entities. The new Phalcon\\Contracts\\Acl\\Adapter\\Adapter interface specifies the core ACL operations (adding/removing components and roles, allowing/denying access, and querying state), while Phalcon\\Contracts\\Acl\\Adapter\\Persistable adds load and save methods for snapshot-based persistence of the entire policy. Entity contracts Phalcon\\Contracts\\Acl\\Component and Phalcon\\Contracts\\Acl\\Role define the shape of component and role objects, and Phalcon\\Contracts\\Acl\\ComponentAware and Phalcon\\Contracts\\Acl\\RoleAware provide interfaces for objects that reference a component or role by name. A central Phalcon\\Contracts\\Acl\\AclTypes interface aggregates PHPStan type aliases used across the ACL namespace to improve static analysis consistency.
ext/phalcon/contracts/acl · high confidence
New PHP wrapper traits for caching, encoding, file, hash, and system operations
The \ext/phalcon/traits/php\ directory now includes a comprehensive set of new PHP wrapper traits that provide consistent, static-access methods for common PHP functions. These include \ApcuTrait\ for APCu caching operations (dec, delete, exists, fetch, inc, iterator, store), \Base64Trait\ for Base64 encoding/decoding and URL-safe variants, \FileTrait\ for file handling (exists, get/put contents, open, write, mkdir, unlink, etc.), \HashTrait\ for hashing and HMAC operations, \HeaderTrait\ for checking if headers are sent, \IgbinaryTrait\ for igbinary serialization, \InfoTrait\ for checking loaded extensions and defined functions, \IniTrait\ for reading and parsing php.ini values, \MbCaseTrait\ for multibyte case conversion, \MsgpackTrait\ for MessagePack packing/unpacking, and \OpensslTrait\ for OpenSSL cipher operations. These traits allow developers to access standard PHP functionality through a unified, trait-based interface within the Phalcon framework.
ext/phalcon/traits/php · high confidence
New PHP wrapper traits for common operations
The \phalcon/Traits/Php\ directory now includes a suite of new traits that provide static wrapper methods for standard PHP functions. These include \ApcuTrait\ for APCu caching, \Base64Trait\ for Base64 encoding/decoding, \FileTrait\ for file I/O operations, \HashTrait\ for hashing, \HeaderTrait\ for header checks, \IgbinaryTrait\ for igbinary serialization, \InfoTrait\ for extension/function existence checks, \IniTrait\ for PHP configuration access, \MbCaseTrait\ for multibyte case conversion, \MsgpackTrait\ for MessagePack serialization, \OpensslTrait\ for OpenSSL utilities, \SerializeTrait\ for standard serialization, \UrlTrait\ for URL parsing and encoding, and \YamlTrait\ for YAML file parsing. These traits allow developers to access these PHP functionalities in a consistent, static manner within the Phalcon framework.
phalcon/Traits/Php · high confidence
New Paginator factory and repository classes
The Paginator component now includes a new \PaginatorFactory\ that simplifies creating paginator adapters (Model, NativeArray, QueryBuilder, QueryBuilderCursor) from configuration, and a \Repository\ class that implements \JsonSerializable\ to represent the current pagination state. These additions provide a more structured way to instantiate paginators and serialize their results, while a new \Exception\ class centralizes error handling for the paginator namespace.
phalcon/Paginator · high confidence
New Phalcon Auth adapters (Memory, Model, Stream) with timing-attack hardening
The framework now ships with a new authentication adapter system in the \phalcon/Auth/Adapter\ namespace, providing three concrete implementations: \Memory\ for in-memory user lists, \Model\ for database-backed lookups via Phalcon models, and \Stream\ for JSON file-backed users. These adapters share a common base that enforces constant-time comparison for non-password credentials and mitigates login-timing user enumeration by performing a dummy hash check when a user is not found. The \AdapterLocator\ service allows resolving these adapters by name (memory, model, stream).
phalcon/Auth/Adapter · high confidence
New Phalcon Auth component with Manager, Factory, and Dispatcher integration
The \phalcon/Auth\ directory now contains the core implementation of the authentication and authorization system. This includes the \Manager\ class, which acts as a facade for managing multiple authentication guards and authorization access policies, and the \ManagerFactory\, which wires these components together using configuration and the application's dependency injection container. The \AbstractAuthDispatcherListener\ provides a shared enforcement algorithm for checking access during request dispatching in CLI, MVC, and Micro applications, handling both forward-based redirects and exception-based denials. Additionally, the \AuthUser\ value object is introduced to represent authenticated users backed by array data, and specific exception classes (such as \AccessDenied\) are defined to handle granular error reporting.
phalcon/Auth · high confidence
New Phalcon Config exception classes for specific error scenarios
The Phalcon Config component now includes dedicated exception classes to provide more precise error reporting. These new exceptions include \CannotLoadConfigFile\ (which exposes the specific file name that failed to load), \ConfigNotArrayOrObject\, \GroupedAdapterRequiresArray\, \InvalidMergeData\, \MissingConfigOption\ (which exposes the missing option name), \MissingFileExtension\, and \MissingYamlExtension\. This allows applications to catch and handle specific configuration errors rather than relying on generic exceptions.
ext/phalcon/config/exceptions · high confidence
New Phalcon HTML Link component with immutable and provider classes
The \ext/phalcon/html/link\ directory now contains the generated C code for the new \Phalcon\\Html\\Link\ namespace. This adds immutable link objects (\Link\, \EvolvableLink\) that allow chaining modifications to attributes, hrefs, and relationships, as well as link providers (\LinkProvider\, \EvolvableLinkProvider\) to manage collections of links. These classes implement the PSR-13 \LinkInterface\ and \LinkProviderInterface\, enabling users to generate and manage HTML link metadata in a standardized, immutable way.
ext/phalcon/html/link · high confidence
New Phalcon Html Helper component for structured HTML generation
The \phalcon/Html/Helper\ directory now contains a comprehensive set of new helpers for generating HTML elements, replacing or supplementing the previous tag-based approach. This includes an \AbstractHelper\ base class for common functionality, specific helpers for structural elements (\Anchor\, \Body\, \Base\, \Button\, \Close\, \Element\, \Form\, \Img\, \Label\, \Tag\, \VoidTag\), asset management series (\Link\, \Meta\, \Script\, \Style\, \Preload\), list structures (\Ul\, \Ol\, \AbstractList\), and content utilities (\Title\, \FriendlyTitle\, \Breadcrumbs\). The \Doctype\ helper allows explicit control over document type declarations. These components provide a more structured, object-oriented way to build HTML output within the Phalcon framework.
phalcon/Html/Helper · high confidence
New Phalcon Image exception classes
The Phalcon Image component now includes a comprehensive set of specific exception classes to provide clearer error reporting during image operations. New exceptions include CompositeFailed, ExtensionNotLoaded, ImageLoadFailed, ImageTooLarge, InvalidColor, MissingDimensions, MissingHeight, MissingWidth, ResizeFailed, ResourceTypeError, TextRenderingFailed, UnsupportedImageType, and VersionMismatch. These exceptions allow developers to catch and handle specific failure scenarios, such as invalid colors, missing dimensions, or unsupported image formats, rather than relying on generic errors.
ext/phalcon/image/exceptions · high confidence
New Phalcon\\Contracts\\Events interface contracts
The Events subsystem now exposes a set of formal contracts in the Phalcon\\Contracts\\Events namespace, providing a stable API surface for event handling. This includes the Manager interface for core operations like attaching listeners and managing subscribers, the Subscriber interface for declaring event maps, and the Event interface for interacting with event instances. Additional contracts such as Enumerable allow querying the full listener map, Stoppable mirrors PSR-14 behavior for propagation control, and EventsTypes centralizes PHPStan type definitions. These interfaces enable developers to type-hint against the event system's capabilities without depending on internal implementation details.
phalcon/Contracts/Events · high confidence
New Phalcon\\Db\\Check class for table CHECK constraints
The \ext/phalcon/db\ extension now includes a new \Phalcon\\Db\\Check\ class, allowing developers to define CHECK constraints on tables. This class accepts a constraint name and a definition array containing a boolean SQL \expression\, and can be used within \createTable()\ definitions or added to existing tables via \addCheck()\ (supported by MySQL 8.0.16+ and PostgreSQL). The implementation also introduces the \Phalcon\\Db\\CheckInterface\ (deprecated in favor of \Phalcon\\Contracts\\Db\\Check\) and associated exception classes to enforce that the expression is provided and is a non-empty string.
ext/phalcon/db · high confidence
New Phalcon\\Db\\Geometry classes for spatial data handling
The \ext/phalcon/db/geometry\ directory now contains the compiled C source and header files for the spatial geometry subsystem. This adds the \Phalcon\\Db\\Geometry\ namespace, including an \AbstractGeometry\ base class, a \GeometryInterface\, and concrete types for \Point\, \LineString\, \Polygon\, \MultiPoint\, \MultiLineString\, \MultiPolygon\, and \GeometryCollection\. These classes provide constructors for spatial coordinates, accessors for their components, and \toWkt()\ methods to export data to Well-Known Text format. Additionally, a \WkbParser\ class is included to decode binary spatial data (WKB/EWKB) from databases into these geometry objects.
ext/phalcon/db/geometry · high confidence
New Phalcon\\Di\\FactoryDefault\\Cli service container for CLI applications
The framework now includes a CLI-specific dependency injection container that automatically registers a standard set of services required for command-line applications. When instantiated, this container pre-configures services such as the CLI dispatcher, router, annotations adapter, event manager, filter, helper factory, settings, models manager, metadata manager, queue factory, security component, and HTML tag factory, removing the need for manual registration in CLI projects.
ext/phalcon/di/factorydefault · high confidence
New Phalcon\\Encryption\\Security classes for random generation and UUIDs
The \ext/phalcon/encryption/security\ directory now includes regenerated C source and header files for \Phalcon\\Encryption\\Security\\Exception\, \Phalcon\\Encryption\\Security\\Random\, and \Phalcon\\Encryption\\Security\\Uuid\. The \Random\ class provides secure random generation capabilities, including methods for base58, base62, base64, hex, and UUID v4 strings. The \Uuid\ class acts as a factory for generating immutable UUID objects of versions 1, 3, 4, 5, 6, and 7, allowing users to create time-based, name-based, and random UUIDs with additional metadata access.
ext/phalcon/encryption/security · high confidence
New Phalcon\\Html component with dedicated helpers and escaper
The \phalcon/Html\ namespace now provides a new, Aura-inspired HTML component suite. This includes an \Attributes\ class for managing and rendering HTML attributes with configurable escaping, a \Breadcrumbs\ helper for generating navigation lists, and a centralized \Escaper\ facade that delegates to specific context-aware escapers (HTML, CSS, JS, URL, and attributes) while maintaining backward compatibility with legacy scalar parameters. Additionally, a \TagFactory\ service locator is introduced, offering a fluent interface to generate and cache a wide range of HTML helpers (such as anchors, forms, inputs, and metadata tags) via magic method calls.
phalcon/Html · high confidence
New Redis queue adapter implementation
The Phalcon framework now includes a Redis adapter for its queue component, enabling users to use Redis as a message broker. This new location introduces the core transport classes: \RedisConnectionFactory\ for establishing connections via the existing storage adapter, \RedisContext\ for managing queue operations (including FIFO delivery via lists and delayed message support via sorted sets), \RedisProducer\ for sending messages with optional delivery delays, \RedisConsumer\ for single-queue consumption using blocking \BRPOP\, and \RedisSubscriptionConsumer\ for multi-queue polling. \RedisMessage\ handles the message structure. This addition provides a new backend option for asynchronous task processing without requiring external dependencies beyond the Redis server and PHP's ext-redis.
phalcon/Queue/Adapter/Redis · high confidence
New Storage adapter for persistent ACL policies
The \Phalcon\\Acl\\Adapter\\Storage\ class is now available, allowing access-control lists to be persisted to any Phalcon\\Storage backend (such as Redis, Memcached, or file streams). It saves the entire policy as a versioned, scalar-only snapshot, enabling roles, components, and access rules to be restored via \load()\ and updated via \save()\. Note that callable (closure) rules are not serializable and will be persisted as DENY, requiring re-registration after a reload.
ext/phalcon/acl/adapter · high confidence
New Storage adapter for persistent ACL snapshots
A new \Phalcon\\Acl\\Adapter\\Storage\ class has been added, extending the in-memory adapter to persist ACL policies to any Phalcon storage backend (such as Redis, Memcached, or Apcu). This adapter saves the entire ACL state as a versioned, scalar-only snapshot, allowing roles, components, and access rules to survive application restarts. Note that access rules backed by closures are persisted as DENY to ensure a fail-closed state upon reload, requiring closures to be re-registered after loading the snapshot.
phalcon/Acl/Adapter · high confidence
New Storage component with Adapter and Serializer factories
The \ext/phalcon/storage\ directory now contains the generated C code for the new \Phalcon\\Storage\ component, introducing \AdapterFactory\ and \SerializerFactory\ classes. The \AdapterFactory\ allows users to instantiate storage adapters (such as APCu, Memcached, Memory, Redis, RedisCluster, Stream, and Weak) by name, while the \SerializerFactory\ provides access to various serialization handlers (including Base64, Igbinary, JSON, Memcached variants, Msgpack, and PHP). This change adds the underlying C implementation for these factory classes, enabling the creation and configuration of storage and serialization instances within the Phalcon framework.
ext/phalcon/storage · high confidence
New Support namespace with core utility classes and helpers
The \phalcon/Support\ namespace now provides a suite of foundational classes for application development. This includes a \Collection\ class for managing data with case-insensitive keys and strict null handling, a \Registry\ for global state storage, and a \Settings\ class to safely read and override Phalcon extension ini settings without affecting shared PHP processes. Additionally, an \AbstractLocator\ base class standardizes service registration and resolution, a \HelperFactory\ offers a unified entry point for array, string, and JSON manipulation helpers, and a \Debug\ component coordinates exception reporting and variable inspection.
phalcon/Support · high confidence
New TemplateAwareTrait for debug template management
Added the TemplateAwareTrait to the Phalcon Debug component, providing a shared mechanism for classes to manage named, overridable template strings. This trait introduces getTemplate and setTemplate methods, allowing debug-related classes to supply default templates via an abstract defaultTemplate method while supporting runtime overrides, thereby standardizing how debug views or outputs are rendered across the framework.
phalcon/Support/Debug/Traits · high confidence
New Time Clock component for time abstraction
A new \Phalcon\\Time\\Clock\ namespace has been introduced, providing an abstraction layer for time that allows applications to decouple from the system clock. This includes a \ClockInterface\ defining a \now()\ method, a \SystemClock\ implementation that returns the current time based on a specified timezone, and a \FrozenClock\ implementation for testing or deterministic scenarios where time can be fixed or adjusted. The component also includes a dedicated \Exception\ class and handles PHP version compatibility (specifically pre-8.3 warning behaviors) within the \FrozenClock\ adjustments.
phalcon/Time/Clock · high confidence
New UUID generation and security exception classes in Encryption/Security
The \phalcon/Encryption/Security\ namespace now includes a dedicated \Exception\ class for security-related errors, a \Uuid\ factory for generating UUID versions 1 through 7 as immutable objects, and updated \Random\ functionality. The \Random\ class retains its existing methods (such as \hex\, \base64\, \base58\) but now explicitly documents that UUID generation should be handled via the new \Uuid\ factory for versions 1, 3, 5, 6, and 7, while \uuid()\ remains for version 4. This change introduces new capabilities for structured UUID generation and better error handling within the security module.
phalcon/Encryption/Security · high confidence
New UUID generation library with RFC 4122 compliance
The Phalcon framework now includes a comprehensive UUID generation library under \Phalcon\\Encryption\\Security\\Uuid\. This addition introduces support for multiple UUID versions: Version 1 (time-based, using MAC address or random fallback), Version 3 (name-based MD5), Version 4 (random), Version 5 (name-based SHA-1), and Version 6 (time-ordered). The implementation includes a base abstract class, interfaces for node providers and UUID types, and specific providers for system MAC addresses and random generation, ensuring standards-compliant UUID creation for security and identification purposes.
ext/phalcon/encryption/security/uuid · high confidence
New ValidatorCompositeTrait for composite validation logic
A new \ValidatorCompositeTrait\ has been added to the \Phalcon\\Filter\\Validation\\Traits\ namespace to manage shared validator collection state and combined validation for composite validators. This trait provides a \getValidators()\ method to retrieve the list of validators and a \validate()\ method that iterates through them, executing each validator against a specific field and returning false immediately if any validation fails, or throwing a \NoValidatorsInComposite\ exception if the collection is empty.
phalcon/Filter/Validation/Traits · high confidence
New View Renderer contract introduced
A new \Phalcon\\Contracts\\View\\Renderer\ interface has been added, defining a standard contract for template rendering. This interface specifies a single \render\ method that accepts a template path and parameters, returning the rendered output as a string. This provides a neutral abstraction for view rendering that is not tied to the MVC or ADR patterns, allowing userland template engines to implement this interface to become drop-in replacements for the existing \Phalcon\\Mvc\\View\\Simple\ renderer.
phalcon/Contracts/View · high confidence
New Volt exception classes for template compilation and validation errors
The Volt template engine now includes a comprehensive set of specific exception classes in the \Phalcon\\Mvc\\View\\Engine\\Volt\\Exceptions\ namespace to provide clearer error reporting. These new classes cover scenarios such as missing or unreadable template files (\TemplateFileNotFound\, \TemplateFileNotOpenable\), compilation issues (\CannotOpenCompiledFile\, \VoltDirectoryNotWritable\, \InvalidCompilationPrefix\), and invalid template syntax or definitions (\InvalidStatement\, \CorruptedStatement\, \UnknownVoltExpression\, \UnknownVoltFilter\, \MacroNotFound\, \InvalidUserFilterDefinition\). This allows applications to catch and handle specific Volt-related errors more precisely.
phalcon/Mvc/View/Engine/Volt/Exceptions · high confidence
New Zephir compiler optimizers for framework functions
The Zephir compiler now includes a set of new optimizer classes that replace generic function calls with optimized C code generation for specific Phalcon framework functions. This change adds support for optimizing CSS and JavaScript minification (phalcon\_cssmin, phalcon\_jsmin), string escaping (phalcon\_escape\_css, phalcon\_escape\_js), and data filtering (phalcon\_filter\_alphanum, phalcon\_is\_basic\_charset). It also introduces optimizations for ORM operations (phalcon\_orm\_singlequotes, phalcon\_orm\_destroy\_cache), URL handling (phalcon\_get\_uri, phalcon\_replace\_paths), path manipulation (phalcon\_fix\_path, phalcon\_prepare\_virtual\_path, phalcon\_possible\_autoload\_filepath), and parsing annotations, PHQL, and Volt views (phannot\_parse\_annotations, phql\_parse\_phql, phvolt\_parse\_view). These optimizers ensure that calls to these functions are compiled into efficient C-level operations, improving runtime performance.
optimizers · high confidence
New abstract base classes for the queue adapter subsystem
The \ext/phalcon/queue/adapter\ directory now includes generated C and header files for the core abstract classes that define the queue adapter contract: \AbstractConsumer\ (polling receive loop, acknowledge/reject), \AbstractContext\ (factory methods for queues, topics, and temporary queues), \AbstractMessage\ (body, headers, properties, and metadata accessors), \AbstractProducer\ (send method with default unsupported delivery delay/priority/TTL), and \AbstractSubscriptionConsumer\ (multi-subscription polling loop with subscribe/unsubscribe). These classes implement the corresponding Phalcon queue contracts and provide the shared implementation that concrete transport adapters (such as the new Beanstalk socket client) extend to deliver queue functionality.
ext/phalcon/queue/adapter · high confidence
New and updated validation validators
The validation component now includes a comprehensive set of new validators for common data types and file uploads. Users can validate alphanumeric and alphabetic strings (Alnum, Alpha), numeric ranges (Between), and specific character sets (Digit). Email validation now supports UTF-8 characters via the allowUTF8 option. A new File validator allows checking uploaded files against size, MIME type, and resolution constraints (min/max/equal/aspect ratio), while the Files validator handles multiple file uploads by delegating to the File validator. Additional validators include Callback for custom logic, Confirmation for field matching, CreditCard for Luhn algorithm checks, Date for format validation, and ExclusionIn for domain exclusion checks.
phalcon/Filter/Validation/Validator · high confidence
New annotation-based metadata strategy for model columns
The \phalcon/Mvc/Model/MetaData/Strategy\ directory now includes a new \Annotations\ strategy class alongside the existing \Introspection\ strategy and the \StrategyInterface\. This addition allows developers to define model metadata, such as column maps, data types (including BIGINT handling), and primary keys, using PHPDoc annotations on model properties instead of relying solely on database introspection or manual configuration. The \Annotations\ class implements the \StrategyInterface\ to parse these annotations and populate the model's metadata index, providing an alternative, code-centric approach to defining model structure.
phalcon/Mvc/Model/MetaData/Strategy · high confidence
New array helper traits for filtering and typed value retrieval
The Phalcon framework now includes two new internal traits in the \Phalcon\\Traits\\Support\\Helper\\Arr\ namespace to simplify array manipulation. The \FilterTrait\ adds a \toFilter\ method that allows filtering an array collection using an optional callable, mirroring PHP's \array\_filter\. The \GetTrait\ introduces a \getArrVal\ method to safely retrieve an array element by key with a default fallback, and additionally supports casting the returned value to a specific type via an optional \cast\ parameter.
ext/phalcon/traits/support/helper/arr, phalcon/Traits/Support/Helper/Arr · high confidence
New associative and indexed array interpolators for translation placeholders
The translation component now includes two new interpolator implementations: \AssociativeArray\ and \IndexedArray\, along with the \InterpolatorInterface\ they implement. The \AssociativeArray\ interpolator replaces named placeholders (e.g., \%key%\) in translation strings using an associative array of key-value pairs, while the \IndexedArray\ interpolator replaces positional placeholders (e.g., \%s\) using \vsprintf\ with a numeric array. This allows users to choose the interpolation strategy that best fits their translation data structure.
ext/phalcon/translate/interpolator · high confidence
New authentication contract interfaces for Phalcon
The \ext/phalcon/contracts/auth\ directory now contains the generated C and header stubs for the new Phalcon authentication contract layer. This adds the \Phalcon\\Contracts\\Auth\ namespace, introducing interfaces for the central \Manager\, \Guard\ implementations (including stateful session guards and HTTP Basic auth), \Adapter\ contracts for credential lookup, and \Access\ gates for action-level authorization. It also defines supporting contracts for \AuthUser\, \AuthRemember\ (for persistent login tokens), \RememberToken\, and a centralized \AuthTypes\ registry for PHPStan type shapes, providing the structural foundation for the framework's authentication system.
ext/phalcon/contracts/auth · high confidence
New authentication guard contracts introduced
The Phalcon Framework now exposes a set of new interfaces in the \Phalcon\\Contracts\\Auth\\Guard\ namespace to define the structure of authentication guards. This includes the core \Guard\ interface for general authentication checks and user retrieval, \GuardStateful\ for managing persistent sessions (login, logout, remember-me), \BasicAuth\ for HTTP Basic authentication support, and \GuardConfig\ as a marker interface for per-guard configuration. These contracts provide a standardized API for implementing and wiring authentication guards within the framework.
phalcon/Contracts/Auth/Guard · high confidence
New authentication listener for Phalcon Micro applications
A new \AuthMicroListener\ class has been added to the \Phalcon\\Auth\\Micro\ namespace, enabling access control enforcement on Phalcon Micro routes. This listener integrates with the application's event manager to check the active access gate before each route execution, using the route name or pattern as the action identifier. It is designed to work with the existing \AbstractAuthDispatcherListener\ and \Manager\ interfaces, allowing developers to secure Micro-based applications without needing a full MVC router setup.
phalcon/Auth/Micro · high confidence
New build configuration and generation scripts for Phalcon extension
This change introduces a new \build/config\ directory containing the build system configuration and code-generation scripts for the Phalcon PHP extension. It adds \config.m4\ and \config.w32\ to handle the build process on Unix and Windows respectively, enforcing a minimum PHP version of 7.4.1. It also includes PHP scripts (\phalcon\_c\_header.php\, \phalcon\_c\_priority\_files.php\, \phalcon\_c\_skip\_files.php\) that define the C header content, file inclusion order, and exclusion rules for generating the final \phalcon.c\ source file, ensuring compatibility with PHP 8.2+ by conditionally including headers like \php\_pcre.h\ and \php\_json.h\.
build/config · high confidence
New cache adapter implementations
The \phalcon/Cache/Adapter\ directory now contains concrete adapter classes (Apcu, Libmemcached, Memory, Redis, RedisCluster, Stream, and Weak) that extend their corresponding Storage adapters and implement the new \CacheAdapterInterface\. Each adapter sets a specific event type prefix to "cache", enabling cache-specific event handling while reusing the underlying storage logic.
phalcon/Cache/Adapter · high confidence
New canonical contracts for ACL components, roles, and adapters
This change introduces a new set of interfaces in the \Phalcon\\Contracts\\Acl\ namespace to standardize the Access Control List (ACL) system. It adds \Component\ and \Role\ contracts for entity definitions, along with \ComponentAware\ and \RoleAware\ interfaces for objects that reference these entities. A central \AclTypes\ interface provides PHPStan type definitions for consistent static analysis across the namespace. Additionally, the \Adapter\ interface defines the core ACL operations (adding roles/components, allowing/denying access), while the \Persistable\ adapter contract enables saving and loading the entire ACL policy snapshot to a backing store, with a note that callable rules are not persisted.
phalcon/Contracts/Acl · high confidence
New canonical contracts for the Phalcon Events system
The \ext/phalcon/contracts/events\ directory now provides a set of published interface contracts that define the public surface of the events subsystem. These include \Phalcon\\Contracts\\Events\\Manager\ for core event dispatching (attaching/detaching listeners, managing subscribers, priority ordering, and response collection), \Phalcon\\Contracts\\Events\\Event\ for standard event data and control (stopping propagation, getting/setting data and type), \Phalcon\\Contracts\\Events\\Subscriber\ for declaring event subscriptions via a static map, \Phalcon\\Contracts\\Events\\EventsAware\ for components that accept an events manager, \Phalcon\\Contracts\\Events\\Enumerable\ for reporting all attached listeners, \Phalcon\\Contracts\\Events\\Stoppable\ mirroring PSR-14's stoppable event behavior, and \Phalcon\\Contracts\\Events\\EventsTypes\ for centralizing PHPStan type definitions. These contracts allow tooling and user code to depend on stable interfaces rather than implementation details, improving type safety and decoupling.
ext/phalcon/contracts/events · high confidence
New canonical database contract interfaces and type registry
The \ext/phalcon/contracts/db\ directory now provides the canonical Zephir interfaces for the database layer, including \Check\, \Column\, \Index\, \Reference\, \Result\, and \Dialect\, along with a central \DbTypes\ interface that defines PHPStan type aliases for database structures. These interfaces establish the official contract for database objects, allowing static analysis tools to enforce type safety across the framework. The \Dialect\ interface also introduces constants for row-locking modifiers (\LOCK\_NONE\, \LOCK\_NOWAIT\, \LOCK\_SKIP\_LOCKED\) to support advanced locking strategies in SQL queries.
ext/phalcon/contracts/db · high confidence
New collection contract and static type definitions
This release introduces a new \Collection\ interface in the \Phalcon\\Contracts\\Support\ namespace, defining the canonical contract for collection operations such as filtering, mapping, and accessing elements. It also adds a \SupportTypes\ interface that centralizes PHPStan type definitions for various support-related data structures, improving static analysis accuracy across the framework.
phalcon/Contracts/Support · high confidence
New configuration classes for memory, model, and stream auth adapters
Added new configuration classes (\MemoryAdapterConfig\, \ModelAdapterConfig\, \StreamAdapterConfig\) and a shared \ModelConfigTrait\ to the \Phalcon\\Auth\\Adapter\\Config\ namespace. These classes provide structured configuration for different authentication adapter types: in-memory user lists, database model mappings with customizable ID columns, and file-based stream authentication. An abstract base class \AbstractAdapterConfig\ is also introduced to standardize the model configuration interface, ensuring consistent access to model names across adapter configurations.
phalcon/Auth/Adapter/Config · high confidence
New container definition types and processors
The container now supports defining services via closures, plain objects, class strings, and parameters. This is implemented by adding the DefinitionType and ServiceLifetime constants, the ServiceDefinition class to hold service metadata, and a set of processors (ClosureProcessor, ObjectProcessor, ParameterProcessor, StringProcessor) that convert these raw definitions into standardized ServiceDefinition objects.
ext/phalcon/container/definition · high confidence
New container exception types for dependency injection errors
The \phalcon/Container/Exceptions\ directory now includes a comprehensive set of new exception classes to provide clearer error reporting during service resolution. These include \CannotExtendResolved\, \CircularAliasFound\, \FrozenDefinition\, \InstanceNotFound\, \InvalidExtender\, \NoClassSet\, \NoFactorySet\, \NoProcessorFound\, \ParameterNotFound\, \ServiceNotFound\, and \ServiceNotRegistered\. A base \Exception\ class and a \ContainerThrowable\ interface are also introduced to standardize the hierarchy, ensuring that dependency injection failures are handled with specific, descriptive error messages rather than generic exceptions.
phalcon/Container/Exceptions · high confidence
New contract interfaces for Assets components
Added canonical contract interfaces for the Assets component, including \Asset\ (defining methods for key, type, attributes, and filtering), \Filter\ (defining the content filtering contract), and \AssetsTypes\ (centralizing PHPStan type definitions for assets collections, attributes, and options). These interfaces establish the structural contracts for asset management within the framework.
phalcon/Contracts/Assets · high confidence
New contract interfaces for form schema and type definitions
Added two new interfaces to the Phalcon Forms contracts: \Schema\, which defines a contract for objects that supply a normalized list of form element definitions (supporting sources like arrays, JSON, or YAML), and \FormsTypes\, which provides a central registry of PHPStan array shapes used across the Forms namespace to improve static analysis accuracy for form attributes, data, elements, filters, and validators.
phalcon/Contracts/Forms · high confidence
New data provider classes for Select helper
The Select helper now supports structured data sources through two new provider classes: \ArrayData\ wraps plain PHP arrays as option lists, and \ResultsetData\ wraps Phalcon resultsets, allowing options to be generated from database rows with configurable value/label fields and per-option attributes.
phalcon/Html/Helper/Input/Select · high confidence
New data providers for select helpers
The select input helper now supports two new data provider classes: ArrayData, which wraps a plain PHP array as a source for options and attributes, and ResultsetData, which wraps a Phalcon ResultsetInterface to generate options and per-option attribute maps from database result sets. These classes implement the SelectData contract, allowing users to bind select elements directly to array structures or ORM result sets without manual transformation.
ext/phalcon/html/helper/input/select · high confidence
New data structures for exception debugging reports
Added \BacktraceItem\ and \ExceptionReport\ classes in the \Phalcon\\Support\\Debug\\Report\ namespace to structure exception debugging data. \BacktraceItem\ represents a single resolved frame of an exception backtrace, storing details like function name, file, line, and arguments. \ExceptionReport\ aggregates all data collected for an exception, including the backtrace, class name, message, file, line, memory usage, URI, included files, request/server superglobals, and variables, preparing it for rendering without containing presentation logic.
phalcon/Support/Debug/Report · high confidence
New database exception classes for schema and query validation
The Phalcon database extension now includes a comprehensive set of new exception classes in the \Phalcon\\Db\\Exceptions\ namespace to provide more specific error reporting. These new classes cover scenarios such as invalid SQL expressions (ORDER BY, GROUP BY, list), missing required parameters for indexes and foreign keys, conflicts with generated or auto-increment columns, and issues with dialect classes or bind parameters. This allows applications to catch and handle database schema and query errors with greater precision.
ext/phalcon/db/exceptions · high confidence
New debug renderer contracts introduced
Added two new interfaces, \Renderer\ and \TemplateAware\, to the \Phalcon\\Contracts\\Support\\Debug\ namespace. The \Renderer\ interface defines the contract for components that convert exception reports into output, including methods to retrieve CSS/JS sources, the framework version, and the final rendered string. The \TemplateAware\ interface provides a standard way for these components to manage and override named template strings, enabling customizable debug output rendering.
phalcon/Contracts/Support/Debug · high confidence
New dependency injection contract interfaces and type definitions
The \ext/phalcon/contracts/container\ directory now includes a comprehensive set of PHP interfaces and PHPStan type aliases that define the structure of the dependency injection container. This adds the \IocContainer\ and \IocContainerFactory\ interfaces for service retrieval and instantiation, the \ResolverService\ interface for resolving classes and methods via reflection, and the \ServiceCollection\ and \ServiceDefinition\ interfaces for managing service bindings, aliases, and lifetimes. These contracts provide the foundational API for the container's service management and resolution capabilities.
ext/phalcon/contracts/container · high confidence
New domain payload classes and status constants
The \ext/phalcon/domain\ extension now includes generated C code for the \Phalcon\\Domain\\Payload\ namespace, introducing the \Payload\ class (with properties for exception, extras, input, messages, output, and status, plus getters/setters), a \PayloadFactory\ for creating instances, and a \Status\ class exposing constants such as SUCCESS, ERROR, and FAILURE. It also adds the \PayloadInterface\, \ReadableInterface\, and \WriteableInterface\ (all marked deprecated in favor of corresponding contracts), enabling consumers to work with domain-layer payloads in a structured way.
ext/phalcon/domain · high confidence
New domain payload contracts for Action-Domain-Responder separation
The framework introduces new interface contracts in the \Phalcon\\Contracts\\Domain\\Payload\ namespace to enforce a cleaner separation between the domain and responder layers. The \Readable\ interface exposes getters for status, output, input, messages, extras, and exceptions, allowing responders to consume finished payloads without modification. The \Writeable\ interface exposes setters for the same properties, restricting the domain layer to building the payload. The concrete \Payload\ class implements both interfaces, enabling type-hinting against the narrower contract at each boundary to keep each side to the capabilities it needs.
ext/phalcon/contracts/domain, phalcon/Contracts/Domain · high confidence
New eager loading infrastructure for model relations
The \ext/phalcon/mvc/model/eager\ location introduces the core C implementation for the new eager loading system. This includes the \Phalcon\\Mvc\\Model\\Eager\\Loader\ class, which handles bulk loading of model relations by executing a bounded number of queries per relation node and applying results during hydration, and the \Phalcon\\Mvc\\Model\\Eager\\PathTree\ class, which parses the \eager\ find parameter into a structured tree to optimize query execution. These components provide the underlying mechanism for efficient, bulk relation loading in Phalcon models.
ext/phalcon/mvc/model/eager · high confidence
New eager loading system for model relations
The Phalcon Framework introduces a new eager loading mechanism for model relations, implemented in the \Phalcon\\Mvc\\Model\\Eager\ namespace. The \Loader\ class enables bulk loading of related records using a bounded number of queries per relation node, applying results during hydration to prevent the N+1 query problem while guarding against excessive fan-out with a configurable row limit. The \PathTree\ class parses the \eager\ find parameter into a structured tree, supporting nested paths and merging prefixes, while enforcing a maximum depth and rejecting unsupported options like \limit\ and \offset\ to ensure predictable performance.
phalcon/Mvc/Model/Eager · high confidence
New encryption and security contract interfaces
The \ext/phalcon/contracts/encryption\ directory now contains the canonical contract interfaces for the framework's encryption and security subsystems. This includes the \Crypt\ interface for symmetric encryption (defining methods like \encrypt\, \decrypt\, and AEAD support), a \Pad\ interface for padding strategies, and a suite of security contracts: \CryptoUtils\ for HMAC and random bytes, \CsrfProtection\ for token management, \PasswordSecurity\ for hashing, a \Signer\ interface for JWT signing, and UUID-related contracts (\Uuid\, \TimeBasedUuid\, \NodeProvider\). Additionally, an \EncryptionTypes\ interface provides centralized PHPStan type aliases for the namespace. These interfaces define the abstract methods and type signatures that implementations must adhere to.
ext/phalcon/contracts/encryption · high confidence
New encryption contracts and type definitions
The framework introduces a new set of interfaces and type definitions within the \Phalcon\\Contracts\\Encryption\ namespace to standardize encryption capabilities. The \Crypt\ interface defines the contract for the encryption service, specifying methods for encrypting and decrypting data (including base64 variants), managing ciphers, keys, and padding, and handling authentication data and tags for AEAD ciphers. It also documents the wire format for encrypted payloads. Additionally, the \Pad\ interface standardizes padding strategies, and the \EncryptionTypes\ interface serves as a central registry for PHPStan type aliases used across the encryption components.
phalcon/Contracts/Encryption/Crypt, phalcon/Contracts/Filter · high confidence
New exception classes for Filter, Validation, and Forms components
This change introduces a comprehensive set of new exception classes to improve error handling and debugging for the Filter, Validation, and Forms components. In the Filter namespace, a new \FilterNotRegistered\ exception is added to handle cases where a filter is not found. The Filter/Validation namespace now includes specific exceptions for validation errors, such as \FieldNotPrintable\, \FilterServiceUnavailable\, \InvalidAllowedTypes\, \InvalidCallbackReturn\, \InvalidDomainOption\, \InvalidFieldType\, \InvalidFilterService\, \InvalidStrictOption\, \InvalidValidationData\, \InvalidValidator\, \InvalidValidatorScope\, \MissingMbstring\, \NoDataToValidate\, \NoValidators\, \NoValidatorsInComposite\, \UniquenessConversionMustBeArray\, \UniquenessModelRequired\, \UniquenessOnlyForPhalconModel\, and \ValidationEntityNotObject\. Additionally, the Forms namespace adds exceptions for form-related issues, including \ElementNotInForm\, \FormElementNameRequired\, \FormNotInLocator\, \FormNotRegistered\, \InvalidEntity\, \InvalidFilterType\, \InvalidJsonSchema\, \JsonSchemaNotArray\, \NoFormElements\, \SchemaEntryMissingKey\, \SchemaEntryNotArray\, \UnknownFormElementType\, \YamlExtensionRequired\, and \YamlSchemaNotArray\. These changes allow developers to catch and handle specific error conditions more precisely.
phalcon/Filter/Exceptions, phalcon/Filter/Validation/Exceptions, phalcon/Forms/Exceptions · high confidence
New exception classes for the Cache component
The Phalcon Cache component now includes dedicated exception classes: \Phalcon\\Cache\\Exception\\Exception\ and \Phalcon\\Cache\\Exception\\InvalidArgumentException\. These classes extend the global \\\Exception\ and are used to handle errors and invalid arguments specifically within the cache functionality, providing clearer error handling for users interacting with cache operations.
phalcon/Cache/Exception · high confidence
New exception classes for the Translate component
The Translate component now includes a set of specific exception classes to provide clearer error reporting. New exceptions include FileOpenError for translation file access issues, KeyNotFound for missing translation keys, MissingRequiredParameter for missing arguments, InvalidDataType for non-array data, MissingContent for empty translations, ImmutableObject for attempts to modify immutable objects, MissingGettextExtension for missing PHP extensions, and placeholders for InterpolatorNotRegistered and TranslatorNotRegistered. These exceptions inherit from the base translate exception class and provide descriptive messages to help developers debug translation-related errors.
ext/phalcon/translate/exceptions · high confidence
New exception hierarchy for the Queue component
The Queue component now introduces a dedicated exception hierarchy under the \Phalcon\\Queue\\Exceptions\ namespace. A new \QueueThrowable\ interface and a base \Exception\ class provide a unified way to catch all queue-related errors. Specific exceptions have been added to handle distinct failure scenarios, including \DeliveryDelayNotSupportedException\, \InvalidDestinationException\, \InvalidMessageException\, \PriorityNotSupportedException\, \PurgeQueueNotSupportedException\, \SubscriptionConsumerNotSupportedException\, \TemporaryQueueNotSupportedException\, and \TimeToLiveNotSupportedException\, allowing developers to handle transport limitations and validation errors with greater precision.
phalcon/Queue/Exceptions · high confidence
New extensible authentication and access-control subsystem
The \ext/phalcon/auth\ directory now provides a complete, contract-driven authentication and authorization layer. It introduces a unified adapter system (\AbstractAdapter\, \Memory\, \Stream\, \Model\) for user credential validation, featuring timing-safe password checks to prevent user-enumeration attacks. Access control is handled via a gate-based system (\AbstractAccess\, \Acl\, \Auth\, \Guest\) that supports role-based ACL enforcement and simple binary gates, with configurable 'only' and 'except' action filters. Dispatchers (\AbstractAuthDispatcherListener\) enforce these policies across CLI, MVC, and Micro applications, supporting fail-open modes and configurable redirect targets for access-denied scenarios. Service locators (\AccessLocator\, \AdapterLocator\) manage instantiation and resolution of these components from the container.
ext/phalcon/auth · high confidence
New extensible metadata strategy interface and implementations
The model metadata system now supports pluggable strategies via a new \Phalcon\\Mvc\\Model\\MetaData\\Strategy\\StrategyInterface\. This interface defines the contract for retrieving column maps and metadata, and is implemented by two new strategies: \Annotations\, which reads metadata from PHPDoc annotations, and \Introspection\, which queries the database information schema to determine column details. This allows users to choose how model metadata is discovered and cached.
ext/phalcon/mvc/model/metadata/strategy · high confidence
New factory traits for service management and configuration validation
The \ext/phalcon/traits/factory\ directory now includes generated C and header files for two new Zephir traits: \ConfigTrait\ and \FactoryTrait\. \ConfigTrait\ provides methods to validate configuration inputs, ensuring they are either arrays or \Phalcon\\Config\\ConfigInterface\ objects, and to verify the presence of required configuration elements. \FactoryTrait\ introduces a mapper-based service factory pattern, offering methods to retrieve services by name, initialize the factory with a service map, and manage cached instances to avoid redundant object creation. These traits enable classes to implement consistent service resolution and configuration handling logic.
ext/phalcon/traits/factory · high confidence
New file resolution validators for image uploads
Added four new validators to the Phalcon file validation suite: AspectRatio, Equal, Max, and Min. These allow developers to enforce specific image dimensions (e.g., 1920x1080) or aspect ratios (e.g., 16x9) on uploaded files, with support for per-field configuration and custom error messages.
ext/phalcon/filter/validation/validator/file/resolution · high confidence
New file size validation validators (Equal, Max, Min)
The Phalcon validation component now includes three new file size validators: Equal, Max, and Min. These allow developers to enforce exact, maximum, or minimum file sizes during validation. The validators support per-field size configurations and an 'included' option to control whether boundary values are accepted, providing granular control over file upload constraints.
phalcon/Filter/Validation/Validator/File/Size · high confidence
New file validation validators for MIME type and abstract file checks
The Phalcon framework now includes new validators for file uploads: \Phalcon\\Filter\\Validation\\Validator\\File\\MimeType\ allows validating uploaded files against specific MIME types (with optional wildcard support), and \Phalcon\\Filter\\Validation\\Validator\\File\\AbstractFile\ provides the base class for file validators, implementing checks for upload status, empty files, and maximum file size limits.
ext/phalcon/filter/validation/validator/file · high confidence
New filesystem-based Stream queue adapter
Adds a new Stream adapter for the Phalcon Queue component, enabling message queuing via the local filesystem. This adapter introduces a set of new classes—StreamConnectionFactory, StreamContext, StreamConsumer, StreamProducer, StreamSubscriptionConsumer, and StreamMessage—that implement the standard queue interfaces. Messages are stored as base64-encoded entries in append-only files within a configurable storage directory (defaulting to the system temp directory), with cross-process safety ensured through file locking. The transport supports basic send/receive operations and subscription-based polling, though it does not support advanced features like priority or time-to-live scheduling.
phalcon/Queue/Adapter/Stream · high confidence
New form schema loaders for array, JSON, and YAML sources
The \ext/phalcon/forms/loader\ directory now includes compiled C implementations for three new form schema loaders: \ArrayLoader\, \JsonLoader\, and \YamlLoader\. \ArrayLoader\ accepts a PHP array of form element definitions directly. \JsonLoader\ loads definitions from a JSON string or file, automatically detecting file paths and throwing specific exceptions for invalid JSON or non-array structures. \YamlLoader\ provides similar functionality for YAML strings or files, requiring the PHP \yaml\ extension and throwing a dedicated exception if the extension is missing. All three loaders implement the \Phalcon\\Contracts\\Forms\\Schema\ interface and return a standardized array of definitions for use in form construction.
ext/phalcon/forms/loader, phalcon/Forms/Loader · high confidence
New grouped config adapter and regenerated C extensions
The \ext/phalcon/config/adapter\ directory now includes a new \Grouped\ adapter (C and header files) that allows loading and merging multiple configuration sources (files, arrays, or mixed) into a single \Phalcon\\Config\\Config\ object. Additionally, the C source and header files for the existing \Ini\, \Json\, \Php\, and \Yaml\ adapters have been regenerated, likely reflecting updates to the underlying Zephir compiler or internal API changes.
ext/phalcon/config/adapter · high confidence
New immutable UUID version classes with node discovery and RFC 9562 support
The \phalcon/Encryption/Security/Uuid\ directory now contains a complete set of immutable UUID version classes (Version1, Version3, Version4, Version5, Version6, and Version7) that replace previous procedural or mutable approaches. Version1 and Version6 are time-based and utilize a new \SysNodeProvider\ to discover the system's hardware MAC address (with APCu caching and a \RandomNodeProvider\ fallback), while Version7 implements the new RFC 9562 Unix timestamp layout. All versions are now constructor-based value objects that implement standard interfaces like \UuidInterface\ and \TimeBasedUuidInterface\, providing consistent methods such as \getDateTime()\ and \getNode()\ for time-based variants.
phalcon/Encryption/Security/Uuid · high confidence
New in-memory profiler and logger for DataMapper PDO queries
The DataMapper PDO layer now includes a built-in in-memory logger (\Phalcon\\DataMapper\\Pdo\\Profiler\\MemoryLogger\) and a profiler (\Phalcon\\DataMapper\\Pdo\\Profiler\\Profiler\) that implement a new \ProfilerInterface\. This allows developers to capture and inspect database query profiles directly in memory without needing an external logging backend, with the profiler defaulting to this in-memory logger when no logger is explicitly provided.
ext/phalcon/datamapper/pdo/profiler · high confidence
New in-memory queue adapter for local development
The Phalcon framework now includes a Memory queue adapter, allowing applications to use an in-process, FIFO-based queue for message production and consumption without requiring an external broker. This new component introduces several classes within the \Phalcon\\Queue\\Adapter\\Memory\ namespace: \MemoryConnectionFactory\ to create contexts, \MemoryContext\ to manage named queues in memory, \MemoryProducer\ to send messages, \MemoryConsumer\ to poll for single-queue messages, \MemorySubscriptionConsumer\ for round-robin polling across multiple queues, and \MemoryMessage\ to represent message payloads. This enables developers to test queue-dependent logic locally or in environments where a persistent message broker is not available.
phalcon/Queue/Adapter/Memory · high confidence
New interfaces for HTTP method and status code constants
Added \RequestMethodInterface\ and \ResponseStatusCodeInterface\ to the \phalcon/Http/Message\ namespace. These interfaces define standard constants for HTTP methods (such as GET, POST, PUT, DELETE) and HTTP status codes (such as 200 OK, 404 Not Found, 500 Internal Server Error), providing a centralized and type-safe way to reference these values in HTTP message handling.
phalcon/Http/Message · high confidence
New lazy resolution strategies for the dependency container
The container resolver now supports several new lazy resolution strategies, allowing services to be resolved on demand rather than at instantiation. These include resolving environment variables (with optional type casting and default values), invoking specific functions with arguments, calling callables, and retrieving or instantiating other container services by ID. This enables more flexible and efficient dependency injection patterns within the Phalcon framework.
ext/phalcon/container/resolver · high confidence
New model behaviors for soft deletes and automatic timestamps
The framework now includes dedicated behavior classes for \SoftDelete\ and \Timestampable\ model operations. The \SoftDelete\ behavior intercepts delete events to update a specified flag column instead of removing the record, requiring 'field' and 'value' options and handling snapshot updates via the Settings component. The \Timestampable\ behavior automatically writes datetime values to specified fields on create or update, supporting custom formats, closure-based generators, or the current time. Both behaviors enforce required configuration options by throwing a new \MissingRequiredOption\ exception if settings are omitted.
phalcon/Mvc/Model/Behavior · high confidence
New modular padding implementations for cryptographic operations
The encryption subsystem now includes dedicated padding classes (Ansi, Iso10126, IsoIek, Noop, Pkcs7, Space, and Zero) that implement the PadInterface. This change introduces a standardized, extensible approach to block cipher padding, allowing users to select specific padding schemes for their encryption needs while ensuring compatibility with the underlying Phalcon encryption contracts.
phalcon/Encryption/Crypt/Padding · high confidence
New padding adapters for Phalcon encryption
The \ext/phalcon/encryption/crypt/padding\ directory now includes generated C implementations for several new padding strategies: Ansi, ISO-10126, ISO-IEC 7816-4 (IsoIek), No-op, PKCS7, Space, and Zero. Each adapter implements the \Phalcon\\Encryption\\Crypt\\Padding\\PadInterface\ (which now delegates to \Phalcon\\Contracts\\Encryption\\Crypt\\Padding\\Pad\ and is marked deprecated), providing \pad\ and \unpad\ methods so users can select the specific padding algorithm required for their cryptographic operations.
ext/phalcon/encryption/crypt/padding · high confidence
New queue adapter and context factories
The queue component now includes \Phalcon\\Queue\\AdapterFactory\ and \Phalcon\\Queue\\QueueFactory\ to simplify connection management. The adapter factory maps adapter names (beanstalk, memory, redis, stream) to their respective connection factories, while the queue factory builds a queue Context from a standard configuration array or by directly instantiating a connection for a named adapter.
ext/phalcon/queue · high confidence
New queue consumer and worker components
This location introduces the core queue consumption infrastructure: the \QueueConsumer\ class handles binding processors to queues, polling for messages, and dispatching them while firing lifecycle events (such as \queue:beforeProcess\ and \queue:afterReceive\); the \Worker\ class provides a long-running operational shell that manages the consumption loop, enforces lifetime bounds (maximum messages, seconds, or memory usage), and handles graceful shutdown via signals; supporting classes include \BoundProcessor\ to link queues with their processors and consumers, \WorkerOptions\ to configure the worker's limits and jitter, and \Events\ to define the event constants used by the consumer.
phalcon/Queue/Consumer · high confidence
New queue consumer runtime with lifecycle events and worker lifetime bounds
The \ext/phalcon/queue/consumer\ directory now contains the compiled C implementation for the queue consumer subsystem. This adds the \Phalcon\\Queue\\Consumer\\QueueConsumer\ class, which binds processors to queues, polls them round-robin, and dispatches messages while firing lifecycle events (such as \queue:beforeProcess\ and \queue:afterEnd\) defined in the new \Phalcon\\Queue\\Consumer\\Events\ class. It also introduces the \Phalcon\\Queue\\Consumer\\Worker\ class, which wraps the consumer in a long-running operational shell that supports graceful shutdown via signals and enforces lifetime bounds (max messages, seconds, memory, and jitter) configured through the new \Phalcon\\Queue\\Consumer\\WorkerOptions\ class. The \Phalcon\\Queue\\Consumer\\BoundProcessor\ class is added to manage the binding of a processor to a specific queue and consumer.
ext/phalcon/queue/consumer · high confidence
New queue contract interfaces for message transport
The \phalcon/Contracts/Queue\ namespace now provides a comprehensive set of interfaces defining the queue transport layer, including \Context\, \Producer\, \Consumer\, \Message\, \Processor\, and destination types (\Queue\, \Topic\). This addition introduces support for standard messaging operations such as sending messages with delivery delays and priorities, consuming messages with acknowledgment or rejection, and processing jobs via the \Processor\ interface. It also adds optional capability contracts like \Inspectable\ for queue statistics and \VisibilityAware\ for visibility timeouts, along with \QueueTypes\ for PHPStan type definitions, establishing the foundational API for queue adapter implementations.
phalcon/Contracts/Queue · high confidence
New queue contract interfaces for transport-agnostic messaging
The \ext/phalcon/contracts/queue\ directory now provides a complete set of PHP interfaces that define the contract for queue transports, enabling developers to write code that is decoupled from specific message-broker implementations. These interfaces include \Context\ for managing sessions and creating producers/consumers, \Producer\ for sending messages with optional delays and priorities, \Consumer\ and \SubscriptionConsumer\ for receiving and processing messages, and \Message\ for handling message bodies, headers, and properties. Additionally, the contracts introduce \Destination\ (with \Queue\ and \Topic\ implementations), \Processor\ for defining message handling logic with standard ACK/REJECT/REQUEUE constants, and optional capability markers like \Inspectable\ for queue statistics and \VisibilityAware\ for visibility timeouts. A \QueueTypes\ registry is also included to standardize PHPStan type definitions for headers, properties, and transport-specific options.
ext/phalcon/contracts/queue · high confidence
New queue factory and adapter registration system
The Queue component now includes an AdapterFactory and QueueFactory to standardize how queue connections are created. The AdapterFactory maps adapter names (beanstalk, memory, redis, stream) to their respective ConnectionFactory classes, while the QueueFactory allows users to build a queue Context from a configuration array or object, supporting the same set of adapters.
phalcon/Queue · high confidence
New security and encryption contract interfaces
This change introduces a new set of interfaces in the \Phalcon\\Contracts\\Encryption\\Security\ namespace to define the contract for security-related functionality. The \Security\ interface serves as the main entry point, extending \CryptoUtils\ (for HMAC, random bytes, and salt generation), \CsrfProtection\ (for token management), and \PasswordSecurity\ (for hashing and verification). Additionally, specific contracts are added for JWT signing (\Signer\) and UUID generation (\Uuid\, \TimeBasedUuid\, \NodeProvider\), providing a standardized API for these security features.
phalcon/Contracts/Encryption/Security · high confidence
New service container contracts for Phalcon
Added a new set of interfaces in the \Phalcon\\Contracts\\Container\\Service\ namespace to define the service container's capabilities. This includes \Collection\ for core service management (binding, resolving, aliasing), \Definition\ for service configuration, \Enumerable\ for listing registered service names, \Provider\ for service registration hooks, and \Throwable\ for container-specific exceptions. These contracts provide a stable API surface for dependency injection, decoupled from internal implementation details.
phalcon/Contracts/Container/Service · high confidence
New service definition and processor architecture for the dependency injection container
The container now uses a new \ServiceDefinition\ class and a set of dedicated processors (\ClosureProcessor\, \ObjectProcessor\, \ParameterProcessor\, \StringProcessor\) to handle different types of service definitions. This change introduces explicit support for defining services via closures, raw objects, class strings, and parameters, with each type processed into a standardized \ServiceDefinition\ object. The architecture also includes \DefinitionType\ and \ServiceLifetime\ constants to manage service types (closure, object, parameter, string) and lifetimes (scoped, singleton, transient). This refactoring aligns the container with interop standards and prepares for future integration with external packages once they become compatible with PHP 8.1.
phalcon/Container/Definition · high confidence
New service providers for CLI and Web application bootstrapping
Added \Phalcon\\Container\\Provider\\Cli\ and \Phalcon\\Container\\Provider\\Web\ classes that implement the \Provider\ interface to automatically register common services into the dependency injection container. The CLI provider binds core CLI components such as the dispatcher, router, and model manager, while the Web provider extends this with HTTP-specific services like request, response, cookies, and flash messages. These providers allow applications to initialize a standard set of dependencies with a single call, reducing manual configuration.
phalcon/Container/Provider · high confidence
New shared traits for queue message handling and subscription consumption
Added MessageTrait and SubscriptionConsumerTrait to the Queue adapter layer. MessageTrait provides a standardized implementation for message body, headers, properties, and convenience accessors (such as correlation ID, message ID, and reply-to), ensuring binary compatibility with the queue-interop ecosystem. SubscriptionConsumerTrait introduces a transport-agnostic, round-robin polling loop that dispatches messages to subscribed callbacks, allowing concrete adapters to focus on their specific transport logic while reusing common consumption behavior.
phalcon/Queue/Adapter/Traits · high confidence
New specific exception classes for ACL validation errors
The ACL component now includes a dedicated set of exception classes in the \Phalcon\\Acl\\Exceptions\ namespace to provide clearer error reporting. New exceptions such as \AccessRuleNotFound\, \CircularInheritanceError\, \ForbiddenDelimiter\, \ForbiddenWildcard\, \InvalidAccessList\, \InvalidComponentImplementation\, \InvalidRoleImplementation\, \InvalidRoleType\, \RoleNotFoundException\, and others have been added. These classes extend the base \Phalcon\\Acl\\Exception\ and offer specific, descriptive error messages for common ACL configuration issues, such as invalid role/component implementations, forbidden characters in names, and missing access rules.
phalcon/Acl/Exceptions · high confidence
New specific exception classes for Phalcon MVC Model operations
The Phalcon Framework now provides a comprehensive set of dedicated exception classes within the \Phalcon\\Mvc\\Model\\Exceptions\ namespace to improve error handling and debugging. These new classes cover specific failure scenarios including eager loading constraints (e.g., \EagerRowLimitExceeded\, \InvalidEagerParameter\, \UnknownEagerRelation\), relation integrity issues (e.g., \BelongsToRequiresObject\, \ReferencedFieldsMismatch\), column and map validation errors (e.g., \ColumnNotInMap\, \IdentityNotInColumnMap\), and service/container misconfigurations (e.g., \InvalidContainer\, \ManagerOrmServicesUnavailable\). This allows developers to catch and handle precise ORM errors rather than relying on generic exception types.
phalcon/Image/Exceptions, phalcon/Mvc/Model/Exceptions · high confidence
New string helper traits for case conversion, path manipulation, and pattern matching
The \ext/phalcon/traits/support/helper/str\ directory now includes compiled C and header files for several new string helper traits. These add capabilities to convert strings to camelCase (\CamelizeTrait\) or non-camelized formats (\UncamelizeTrait\), enforce directory separators (\DirSeparatorTrait\), generate directory structures from filenames (\DirFromFileTrait\), and perform case-insensitive prefix/suffix checks (\StartsWithTrait\, \EndsWithTrait\). Additionally, an \InterpolateTrait\ allows replacing placeholders in strings using context arrays, and \LowerTrait\/\UpperTrait\ provide multibyte-safe case conversion. These traits are now available for use within the Phalcon framework's string handling utilities.
ext/phalcon/traits/support/helper/str · high confidence
New string manipulation traits added to Phalcon
This change introduces a suite of new helper traits in the \Phalcon\\Traits\\Support\\Helper\\Str\ namespace, providing developers with reusable components for common string operations. The new traits include \CamelizeTrait\ for converting strings to camelCase, \UncamelizeTrait\ for reversing that process, \UpperTrait\ and \LowerTrait\ for case conversion using mbstring, \StartsWithTrait\ and \EndsWithTrait\ for prefix/suffix checks with optional case-insensitivity, \InterpolateTrait\ for PSR-3 style message interpolation, \DirFromFileTrait\ for generating directory structures from filenames, and \DirSeparatorTrait\ for ensuring consistent directory path separators.
phalcon/Traits/Support/Helper/Str · high confidence
New support contracts for collections and debug rendering
The framework introduces canonical interface contracts in the \Phalcon\\Contracts\\Support\ namespace to standardize the Support component. This includes a \Collection\ interface defining methods for array-like access, filtering, mapping, and reduction, alongside a \SupportTypes\ registry for PHPStan array shapes. Additionally, new \Debug\ contracts (\Renderer\ and \TemplateAware\) are added to standardize how exception reports are rendered and how debug output templates are managed.
ext/phalcon/contracts/support · high confidence
New value objects for database geometry types
The \phalcon/Db/Geometry\ namespace now includes a set of new value objects (\Point\, \LineString\, \Polygon\, \MultiPoint\, \MultiLineString\, \MultiPolygon\, and \GeometryCollection\) that represent spatial data. These classes implement \GeometryInterface\ and provide methods to retrieve coordinates, rings, or sub-geometries, as well as to serialize the data to Well-Known Text (WKT) format. A \WkbParser\ class is also introduced to decode binary spatial data from MySQL and PostGIS into these objects, handling both standard WKB and EWKB formats while enforcing a nesting depth limit to prevent stack exhaustion.
phalcon/Db/Geometry · high confidence
New version-bumping and parser-generation scripts added to bin
The bin directory now includes two new helper scripts. The PHP script \bump-version.php\ automates updating the project version across multiple configuration and source files (including \config.json\, \package.xml\, GitHub Actions workflows, Dockerfiles, and the C++ version definition) based on a provided version string and optional date. The shell script \genparsers.sh\ automates the regeneration of lexer and parser source files for specific language components (model query, Volt, annotations) by compiling the Lemon parser generator and using re2c, streamlining the build process for these internal components.
bin · high confidence
New view renderer contract interface
A new \Phalcon\\Contracts\\View\\Renderer\ interface has been added to the framework, providing a neutral abstraction for template rendering that is independent of MVC or ADR patterns. This contract defines a single \render\ method, allowing userland template engines to integrate as drop-in replacements by implementing this standard interface.
ext/phalcon/contracts/view · high confidence
Removals
Removal of legacy Phalcon C extension source files
The \dev\ directory has been cleaned up by deleting the C source files for the legacy Phalcon framework components, including \config\, \controller\, \db\, \dispatcher\, \exception\, and their associated adapters and dialects. This removal eliminates the underlying C implementation for these core modules from the development tree.
dev · high confidence
Removed legacy release folder and build files
The \release\ folder, which previously contained the PHP extension build configuration (\config.m4\, \config.w32\) and the core C source files (\phalcon.c\, \phalcon.h\, \php\_phalcon.h\), has been deleted. This change removes the legacy build artifacts and source code from this directory, indicating a shift in how the Phalcon extension is packaged or built.
release · high confidence
Security
Image adapters now enforce pixel limits to prevent memory exhaustion
The Image adapters (GD and Imagick) now include a built-in safety mechanism to reject oversized images before they are fully decoded into memory, addressing a potential decompression bomb vulnerability (CWE-409). By default, images exceeding 50 million pixels are rejected, though this limit can be customized per instance or disabled entirely. This change ensures that crafted or maliciously large images cannot cause the application to run out of memory during loading.
phalcon/Image/Adapter · high confidence
Architecture
Forms component refactored with new locator, manager, and exception classes
The Forms component has been restructured to introduce a new FormsLocator for managing named form factories and element type registrations, a Manager class for centralized form creation and retrieval, and a dedicated Exception class for specific error handling. This change also includes updates to the core Form class, such as moving the initialize() call to the end of the constructor and refining validation and binding logic, providing a more modular and extensible foundation for form handling.
phalcon/Forms · high confidence
Behavioural changes
ACL component and role validation hardening
The Phalcon ACL module now enforces stricter validation on Role and Component names: constructors for Phalcon\\Acl\\Role and Phalcon\\Acl\\Component will throw ForbiddenWildcard exceptions if the name is "\*" and ForbiddenDelimiter exceptions if the name contains "!", preventing ambiguous or malformed identifiers. Additionally, the ACL interfaces (ComponentAwareInterface, ComponentInterface, RoleAwareInterface, RoleInterface) are now marked as deprecated in favor of their equivalents in the Phalcon\\Contracts\\Acl namespace, signaling that these legacy interfaces will be removed in a future major release.
phalcon/Acl · high confidence
Added central type registry for Annotations namespace
A new \AnnotationsTypes\ interface has been introduced in the \ext/phalcon/contracts/annotations\ location to serve as a central registry for array shapes used across the Annotations namespace. This change provides a single definition for types such as \annotations\_expression\, \annotations\_argument\, and \annotations\_node\, which are imported via \phpstan-import-type\ tags to ensure consistent static analysis and prevent naming clashes. This supports the underlying annotation parser by standardizing the type definitions for nodes, arguments, and route metadata.
ext/phalcon/contracts/annotations · high confidence
Added centralized PHPStan type registry for the Image namespace
A new \ImageTypes\ interface has been introduced in the \Phalcon\\Contracts\\Image\ namespace to serve as a central registry for PHPStan array shapes. This change defines specific type aliases—such as \image\_channel\, \image\_color\_channels\, \image\_crop\_rectangle\, \image\_factory\_config\, \image\_factory\_services\, and \image\_text\_bounds\—to ensure consistent static analysis across the Image component. By centralizing these definitions, the framework improves type safety and reduces duplication for developers using the Image library.
ext/phalcon/contracts/image, phalcon/Contracts/Image · high confidence
Added specific exception classes for JWT validation and security errors
The JWT component now includes a dedicated set of exception classes under the \Phalcon\\Encryption\\Security\\JWT\\Exceptions\ namespace to provide more granular error handling. New types such as \EmptyPassphrase\, \WeakPassphrase\, \InvalidAudience\, \InvalidClaims\, \MalformedJwtString\, and \UnsupportedAlgorithmException\ allow developers to catch and distinguish between specific JWT validation failures, structural issues, and cryptographic constraints rather than relying on generic exceptions.
phalcon/Encryption/Security/JWT/Exceptions · high confidence
Adds specific exception classes for Phalcon Config errors
This change introduces a set of new, dedicated exception classes within the \Phalcon\\Config\\Exceptions\ namespace to provide more granular error handling for configuration operations. The new classes include \CannotLoadConfigFile\ (which exposes the problematic file name), \ConfigNotArrayOrObject\, \GroupedAdapterRequiresArray\, \InvalidMergeData\, \MissingConfigOption\ (which exposes the missing option name), \MissingFileExtension\, and \MissingYamlExtension\. These replace generic error handling with specific types that allow developers to catch and react to distinct configuration failure scenarios.
phalcon/Config/Exceptions · high confidence
Assets component refactored to use traits and new exception classes
The Assets component has been refactored to improve code organization and maintainability. Common functionality for HTML attributes and source/target paths has been extracted into shared traits (\AttributesTrait\, \SourceTargetTrait\), which are now used by \Asset\, \Collection\, and \Inline\ classes. Additionally, the component now utilizes specific exception classes (e.g., \CannotReadAsset\, \AssetSourceTargetCollision\) instead of generic exceptions, providing more precise error handling for asset operations.
phalcon/Assets · high confidence
CLI Console, Dispatcher, and Router components rewritten in Zephir
The Phalcon CLI subsystem has been completely rewritten in Zephir, introducing new implementations for Console, Dispatcher, Router, and Task. Console now enforces a required dependency injection container and provides specific exceptions (ContainerRequired, InvalidModuleDefinition, ModuleDefinitionPathNotFound) for module loading errors. The Dispatcher has been refactored to extend AbstractDispatcher, with updated method signatures for handling CLI options and parameters. The Router's default route patterns have been adjusted, and the getParams() method is now deprecated in favor of getParameters(). Task classes now support an onConstruct lifecycle hook.
phalcon/Cli · high confidence
CLI Router exception classes and Route interface are regenerated
The C source and header files for the CLI Router extension have been regenerated, introducing a new base exception class (Phalcon\\Cli\\Router\\Exception) and three specific exception types: BeforeMatchNotCallable, InvalidRoutePaths, and RouterArgumentsInvalidType. The Route class and its interface have also been updated to reflect these structural changes, ensuring that routing errors now throw distinct, typed exceptions rather than generic errors.
ext/phalcon/cli/router · high confidence
CSS and JS minification filters are deprecated and return content unchanged
The \Phalcon\\Assets\\Filters\\Cssmin\ and \Phalcon\\Assets\\Filters\\Jsmin\ classes have been updated to return asset content without modification, effectively disabling minification. These classes are now marked as deprecated; users should switch to \Phalcon\\Assets\\Filters\\None\ for no processing or implement a custom \FilterInterface\ wrapping a real minifier to achieve minification.
ext/phalcon/assets/filters · high confidence
Cache component refactored to use new adapter and factory classes
The \ext/phalcon/cache\ directory has been regenerated to implement a new caching architecture. The \Phalcon\\Cache\\Cache\ class now serves as the primary facade, delegating operations to pluggable adapters (such as APCu, Redis, Memory, and Stream) created via the new \Phalcon\\Cache\\AdapterFactory\ and \Phalcon\\Cache\\CacheFactory\. This change introduces a factory-based approach for cache instantiation and adapter management, replacing the previous direct implementation structure.
ext/phalcon/cache · high confidence
Cache component refactored with event support and factory pattern
The Phalcon Cache component has been restructured to introduce an event-driven architecture and a factory-based instantiation model. The core \Cache\ class now extends \AbstractCache\, which implements \EventsAwareInterface\ to emit \cache:\*\ events (such as \cache:beforeGet\ and \cache:afterDelete\) around all cache operations, allowing applications to hook into caching behavior. Additionally, a new \CacheFactory\ and \AdapterFactory\ have been introduced to simplify the creation of cache instances and their underlying adapters (including support for Redis Cluster and Weak Storage) via configuration or programmatic options, replacing direct instantiation.
phalcon/Cache · high confidence
Config component refactored to extend Collection and restructured factory logic
The Phalcon Config component has been restructured so that the Config class now extends the Collection class, inheriting its core data handling capabilities while adding specific configuration methods like merge, path, and setPathDelimiter. The ConfigFactory has been updated to align with this new structure, including changes to how adapter aliases are resolved and how file extensions are handled during the loading process. This refactoring ensures that configuration data is managed through a consistent collection-based interface, improving code maintainability and alignment with other Phalcon components.
phalcon/Config · high confidence
Crypt module refactored with new interface and padding factory
The Crypt component has been restructured to align with new encryption contracts. A new CryptInterface has been introduced that extends the Phalcon\\Contracts\\Encryption\\Crypt\\Crypt contract, marking the legacy interface as deprecated for future removal. Additionally, a PadFactory class has been added to manage padding implementations (such as PKCS7, ANSI, and Zero), providing a centralized way to instantiate padding services based on standard constants.
phalcon/Encryption/Crypt · high confidence
Database schema definition classes and dialect refactored to use new contract interfaces
The Phalcon\\Db component has been restructured to rely on new canonical contract interfaces (e.g., Phalcon\\Contracts\\Db\\Check, Column, Dialect, Index, Reference, Result) while keeping the existing concrete classes (Check, Column, Dialect, Index, Reference, Result) as deprecated wrappers that extend these contracts. This change introduces new schema definition classes such as Check for CHECK constraints and RawValue for unquoted SQL fragments, and enhances the Index class to support modern database features like per-column sort directions, partial indexes (WHERE predicates), concurrent index creation on PostgreSQL, and invisible indexes on MySQL 8.0+. The Dialect class now supports advanced SQL transformations including ON CONFLICT DO UPDATE upserts, RETURNING clauses for PostgreSQL and SQLite, and row-lock modifiers like NOWAIT and SKIP LOCKED. Additionally, the Profiler has been updated to use high-resolution timing via hrtime() and includes a configurable limit for retained profiles.
phalcon/Db · high confidence
Debug component moved to Phalcon\\Support\\Debug namespace
The Debug component has been relocated from the Phalcon\\Debug namespace to Phalcon\\Support\\Debug. This change introduces new classes such as Dump, Exception, and ReportBuilder within the Support namespace, along with associated traits and report structures. Users relying on the previous Phalcon\\Debug namespace will need to update their imports and references to the new Phalcon\\Support\\Debug location.
phalcon/Support/Debug · high confidence
Dependency injection component regenerated with Zephir
The C source files for the Phalcon\\Di component have been regenerated using the latest Zephir compiler. This update refreshes the underlying implementation of the dependency injection container, including the main Di class, the FactoryDefault variant, the Service class, and related interfaces and exception classes, ensuring compatibility with the current Zephir toolchain.
ext/phalcon/di · medium confidence
Dependency injection container refactored with new service resolution and aliasing
The Phalcon\\Di container has been refactored to improve service resolution and management. The container now supports service aliases, allowing one service name to point to another, with specific exceptions thrown for invalid alias configurations (e.g., circular references or duplicate names). Service definitions are now handled via a dedicated Service class and a Builder, which supports complex instantiation including constructor arguments, method calls, and property injection. The Injectable base class has been updated to cache resolved services on declared properties while re-resolving dynamic ones, and the FactoryDefault containers for both web and CLI applications have been updated to register the new Helper and Queue Factory services.
phalcon/Di · high confidence
Deprecated CollectionInterface and added ReadOnlyCollection
The \Phalcon\\Support\\Collection\\CollectionInterface\ is now deprecated and will be removed in a future major release; users should migrate to \Phalcon\\Contracts\\Support\\Collection\. Additionally, a new \Phalcon\\Support\\Collection\\ReadOnlyCollection\ class has been introduced, which extends the standard collection but prevents modification via methods like \set\, \remove\, \replace\, and \clear\, throwing a \ReadOnlyViolation\ exception if a write operation is attempted.
ext/phalcon/support/collection · high confidence
Deprecation of CssMin and JsMin asset filters
The CssMin and JsMin classes in the Assets component have been deprecated and now return content unchanged, effectively disabling automatic CSS and JavaScript minification. Users relying on these built-in filters will see no change in output; they are advised to switch to the None filter or implement a custom FilterInterface wrapping a real minification library.
phalcon/Assets/Filters · high confidence
Dispatcher contract introduces parameter naming convention and type definitions
The Dispatcher contract now defines the \Phalcon\\Contracts\\Dispatcher\\Dispatcher\ interface and \DispatcherTypes\ registry. For users, this establishes a new parameter naming convention where methods like \getParam\, \getParams\, \hasParam\, \setParam\, and \setParams\ are deprecated in favor of their \\*Parameter\ counterparts (\getParameter\, \getParameters\, \hasParameter\, \setParameter\, \setParameters\). The contract also introduces PHPStan type definitions for dispatcher parameters and forward actions, ensuring stricter type checking for these operations.
ext/phalcon/contracts/dispatcher · high confidence
Dispatcher introduces specific exception classes for better error handling
The Dispatcher component now includes dedicated exception classes, specifically \ResponseServiceUnavailable\, to provide more granular error reporting. This change allows applications to catch and handle specific dispatcher errors, such as missing dependency injection containers for response services, rather than relying on generic exceptions.
phalcon/Mvc/Dispatcher · high confidence
Dispatcher refactored with shared base class and new event hooks
The Dispatcher component has been restructured to introduce AbstractDispatcher as a shared base class for MVC and CLI dispatchers, consolidating common logic and error handling. A new event channel, dispatch:beforeCallAction, allows observers to intercept and modify the handler, action, and parameters before execution, with the dispatcher re-validating any substituted callable to prevent runtime errors. Additionally, a new ForwardInInitializeForbidden exception is now thrown to explicitly prevent forwarding operations within a controller's initialize() method, and the DispatcherInterface is marked as deprecated in favor of the underlying contract.
phalcon/Dispatcher · high confidence
Events subsystem regenerated with Zephir
The C source files for the Phalcon events extension (including the Manager, Event, AbstractEventsAware, and related interfaces) have been regenerated using the latest Zephir compiler. This update refreshes the underlying C implementation to align with the current Zephir toolchain, ensuring compatibility and incorporating any internal compiler improvements, while preserving the existing public API surface.
ext/phalcon/events · medium confidence
Events system overhaul with strict validation, subscriber support, and dispatch controls
The Events component has been significantly refactored to improve reliability and performance. The Event class now enforces strict type validation, throwing InvalidEventSource if the source is not an object, and supports stopping propagation via a new stop() method. The Manager introduces a subscriber pattern (addSubscriber) for bulk event binding, along with new Manager methods to retrieve subscribers and event types. Dispatch behavior is enhanced with a halt/resume kill switch, a stopOnFalse option to short-circuit on false returns, and a strict mode that throws if no listeners are found. Performance is improved through caching of parsed event types and method existence checks, and the storage backend has been swapped from SplPriorityQueue to a sorted array for faster iteration.
phalcon/Events · high confidence
Flash component regenerated with typed properties and new exception classes
The C code for the Phalcon Flash extension has been regenerated, introducing typed protected properties (autoescape, automaticHtml, cssClasses, cssIconClasses, customTemplate, escaperService, implicitFlush, messages, sessionService) to AbstractFlash and adding a sessionKey property to Session. The Session constructor now accepts an optional sessionKey argument to customize the storage key, defaulting to "\_flashMessages". Additionally, specific exception classes (EscaperServiceUnavailable, FlashMessageNotStringOrArray, SessionServiceUnavailable) are now generated to provide clearer error reporting when required services are missing or messages are invalid.
ext/phalcon/flash · high confidence
Forms component regenerated with Zephir for PHP 8 compatibility
The C source files for the Phalcon Forms extension have been regenerated using the latest Zephir compiler. This update ensures compatibility with PHP 8, addressing internal type handling changes (such as replacing \uint\/\ulong\ with \zend\_uint\/\zend\_ulong\) and removing compiler warnings. The diff shows the regeneration of core form classes including \Form\, \FormsLocator\, \Manager\, and \Exception\, which now utilize modern Zephir typed properties and updated Zend engine APIs.
ext/phalcon/forms · medium confidence
Granular authentication exception types
The \phalcon/Auth/Exceptions\ directory now contains a comprehensive set of specific exception classes (e.g., \AccessDenied\, \GuardNotDefined\, \FileDoesNotExist\, \ConfigRequiresNonEmptyValue\) that replace generic error handling. This change allows applications to catch and distinguish between precise authentication failures—such as missing guards, invalid file formats, or configuration errors—rather than relying on broad, undifferentiated exceptions.
phalcon/Auth/Exceptions · high confidence
Granular exception classes for the Translate component
The Translate component now provides specific exception classes to help identify errors more precisely. New types include FileOpenError for translation file access issues, ImmutableObject for attempts to modify read-only data, InterpolatorNotRegistered and TranslatorNotRegistered for missing service registrations, InvalidDataType and MissingContent for data validation errors, KeyNotFound for missing translation keys, MissingGettextExtension for environment requirements, and MissingRequiredParameter for invalid arguments. This allows developers to catch and handle specific failure modes rather than relying on generic exceptions.
phalcon/Translate/Exceptions · high confidence
HTML escaper refactored to use traits and context-specific classes
The HTML escaper implementation has been restructured to replace the previous \AbstractEscaper\ base class with a shared \EscaperTrait\ for common encoding and flag state, while introducing dedicated context-specific escaper classes (\HtmlEscaper\, \AttributeEscaper\, \CssEscaper\, \JsEscaper\, \UrlEscaper\) that compose the trait. This change introduces new behaviors such as \AttributeEscaper\ supporting arrays of attribute pairs (where \null\/\false\ are skipped and \true\ renders as a bare key) and \HtmlEscaper\ tolerating \null\ input by returning an empty string, alongside improved character encoding detection and normalization for CSS/JS contexts.
ext/phalcon/html/escaper · high confidence
HTTP component classes restructured into new namespace hierarchy
The Phalcon HTTP component has been reorganized into a new namespace structure under \Phalcon\\Http\. Core classes such as \Request\, \Response\, and \Cookie\ have been moved from their previous locations to \Phalcon\\Http\\Request\, \Phalcon\\Http\\Response\, and \Phalcon\\Http\\Cookie\ respectively. This change includes the introduction of dedicated sub-namespaces for interfaces (e.g., \Phalcon\\Http\\Cookie\\CookieInterface\), exceptions (e.g., \Phalcon\\Http\\Cookie\\Exceptions\), and traits (e.g., \Phalcon\\Http\\Traits\), requiring updates to any code that directly references the old class paths.
phalcon/Http · high confidence
Historical changelogs moved to dedicated versioned files
The resources directory now organizes historical release notes into separate markdown files (CHANGELOG-0.x.md, CHANGELOG-1.x.md, CHANGELOG-2.0.md, CHANGELOG-3.0.md) within a new changelogs subfolder, replacing the previous monolithic or flat structure. This change improves the readability and maintainability of the project's release history by grouping entries by major version.
resources · high confidence
Image adapter layer regenerated with Zephir and PHP 8 compatibility fixes
The C source and header files for the image adapter layer (AbstractAdapter, AdapterInterface, Gd, and Imagick) have been regenerated using the latest Zephir compiler. This update aligns the extension with PHP 8, resolving compilation warnings and ensuring correct type handling for image manipulation operations such as resizing, rotating, and watermarking.
ext/phalcon/image/adapter · medium confidence
Internal container resolution and option parsing infrastructure
Added two internal helper classes to the Auth module: ContainerResolver, which provides a unified way to resolve services from both the new Phalcon Container and the legacy Di container (normalizing exceptions and handling shared-instance freshness), and Options, which standardizes the parsing and validation of configuration arrays and strings for auth adapters and guards.
phalcon/Auth/Internal · high confidence
Introduces PHPStan type contracts for HTML helpers
The Html contracts namespace now includes dedicated interfaces (\HtmlTypes\, \LinkTypes\, and \SelectData\) that define PHPStan array shapes for attributes, options, and link collections. This provides stricter static analysis support for HTML helper data structures, ensuring consistent type definitions for select options, element attributes, and link collections across the framework.
phalcon/Contracts/Html · high confidence
Introduces static analysis type definitions for the Annotations component
A new \AnnotationsTypes\ interface has been added to the \phalcon/Contracts/Annotations\ namespace to serve as a central registry for PHPStan type aliases. This change introduces specific array shapes for annotations, including expressions, arguments, collections, nodes, and reflection data, ensuring consistent type checking across the annotations namespace. This supports improved static analysis and type safety for developers using the annotations feature.
phalcon/Contracts/Annotations · high confidence
Introduction of Factory type definitions for static analysis
A new \FactoryTypes\ interface has been added to the \Phalcon\\Contracts\\Factory\ namespace to serve as a central registry for PHPStan array shapes. This change introduces specific type definitions (\factory\_config\, \factory\_services\, and \factory\_instances\) to improve static analysis accuracy and resolve uninitialized variable warnings within the Factory component.
phalcon/Contracts/Factory · high confidence
Introduction of Read-Only Collection and Serialization Support
The Support/Collection component now includes a new ReadOnlyCollection class that prevents modification of collection data after construction, throwing a ReadOnlyViolation exception for any mutation attempts. Additionally, the collection now supports serialization and unserialization, with special handling in ReadOnlyCollection to allow state restoration during unserialization while maintaining read-only integrity. The component also introduces specific exception classes (InvalidValueType, ReadOnlyViolation) for better error handling and deprecates the legacy CollectionInterface in favor of the contract-based approach.
phalcon/Support/Collection · high confidence
JSON helpers now throw specific error exceptions
The \Phalcon\\Support\\Helper\\Json\\Decode\ and \Phalcon\\Support\\Helper\\Json\\Encode\ classes have been regenerated to wrap PHP's native JSON functions with stricter error handling. If encoding or decoding fails, these helpers now throw \JsonDecodeError\ or \JsonEncodeError\ respectively, providing a consistent way to catch JSON processing issues instead of relying on silent failures or generic exceptions.
ext/phalcon/support/helper/json · high confidence
JWT Builder and Validator regenerated for Phalcon 13.0
The C source and header files for the JWT Builder and Validator classes in the Phalcon extension have been regenerated to align with the latest Zephir compiler and Phalcon 13.0 standards. This update refreshes the underlying implementation of the JWT Builder (handling claims, headers, and signing) and the Validator (handling token validation, claims, and errors), ensuring compatibility with the current framework version without altering the public API surface.
ext/phalcon/encryption/security/jwt · medium confidence
JWT builder and validator restructured with new validation API
The JWT component in phalcon/Encryption/Security/JWT has been refactored to introduce a dedicated Builder class for constructing tokens and a Validator class for verifying them. The Builder now explicitly manages claims and JOSE headers, requiring a signer and passphrase to generate signed tokens. The Validator replaces previous inline validation logic with a fluent API, adding methods like validateAudience, validateExpiration, and validateClaim, while also supporting a ClockInterface for testable time handling and exposing validation errors via getErrors().
phalcon/Encryption/Security/JWT · high confidence
Logger adapters now implement the new Phalcon\\Contracts\\Logger\\Adapter\\Adapter interface
The logger adapter hierarchy (AbstractAdapter, Stream, Syslog, and Noop) has been updated to implement the new Phalcon\\Contracts\\Logger\\Adapter\\Adapter contract. The legacy Phalcon\\Logger\\Adapter\\AdapterInterface is now deprecated and simply extends this new contract. This change ensures that all logger adapters adhere to the standardized contract interface, providing a consistent foundation for future logger enhancements while maintaining backward compatibility through the deprecated adapter interface.
ext/phalcon/logger/adapter · high confidence
Logger adapters now prevent serialization and manage transactions safely
The logger adapters in \Phalcon\\Logger\\Adapter\ now throw exceptions if you attempt to serialize or unserialize them, preventing invalid state persistence. Additionally, the base \AbstractAdapter\ now supports transactional logging: you can group messages using \begin()\ and \commit()\, and the adapter will automatically commit any queued messages in its destructor if an active transaction is still open when the object is destroyed. The \Stream\ adapter also ensures that \PHP\_EOL\ is appended to log lines.
phalcon/Logger/Adapter · high confidence
Logger component regenerated with Zephir 0.13.0 and updated type signatures
The \ext/phalcon/logger\ C source files have been regenerated using the latest Zephir compiler (0.13.0), introducing stricter type safety and modern PHP features. Key changes include the addition of a \Phalcon\\Time\\Clock\\ClockInterface\ dependency for timestamping in \AbstractLogger\, the introduction of a \Phalcon\\Logger\\Enum\ class for log level constants, and the adoption of typed properties and \RETURN\_MEMBER\_TYPED\ macros across \AbstractLogger\, \Item\, and \Logger\. The \LoggerFactory\ now explicitly requires an \AdapterFactory\ instance in its constructor, and the deprecated \LoggerInterface\ now implements the \Phalcon\\Contracts\\Logger\\Logger\ contract.
ext/phalcon/logger · high confidence
Logger component restructured with new adapters, factories, and trace level
The Phalcon Logger has been restructured to introduce a new \AdapterFactory\ for creating stream, syslog, and noop adapters, alongside a \LoggerFactory\ for instantiating loggers from configuration. The core \Logger\ and \AbstractLogger\ classes now support a new \trace\ log level (value 9) and utilize \DateTimeImmutable\ for precise timestamping via a \SystemClock\. Additionally, the logger now includes dedicated exception classes for adapter and transaction states, and log levels are standardized to lowercase strings for internal checking.
phalcon/Logger · high confidence
Logger formatters now sanitize log lines and interpolate context safely
The Line formatter now escapes C0 control characters and DEL in log messages to prevent log injection (CWE-117), and both Line and Json formatters use a new interpolation mechanism that safely converts non-stringable context values to empty strings instead of failing. This ensures that untrusted input in log context cannot forge extra log lines or abort formatting, while maintaining backward-compatible message formatting for existing users.
phalcon/Logger/Formatter · high confidence
Logger formatters now support configurable date formats and interpolation placeholders
The logger formatter classes (AbstractFormatter, Line, and Json) now allow users to customize the date format string and the left/right interpolation placeholders used for context variable substitution. Previously, these were hardcoded (e.g., 'c' for ISO 8601 dates and '%' for placeholders); now, the constructors for Line and Json accept optional parameters to override these defaults, and AbstractFormatter exposes get/set methods for the date format. This enables users to tailor log output formatting to their specific needs without modifying the core formatter logic.
ext/phalcon/logger/formatter · high confidence
MVC components restructured with granular exception classes and new interfaces
The Phalcon MVC layer has been refactored to improve error handling and type safety. Application and Micro components now throw specific, granular exceptions (such as ContainerRequired, InvalidModuleDefinition, and ModuleDefinitionPathNotFound) instead of generic errors, providing clearer diagnostics for configuration issues. New interfaces like BindModelInterface and BindableInterface have been introduced to standardize model binding in controllers and Micro applications. Additionally, the Dispatcher and Model classes have been updated with stricter return types, enhanced hydration logic, and support for eager loading, while the Router has been optimized for performance.
phalcon/Mvc · high confidence
Major overhaul of MySQL, PostgreSQL, and SQLite dialects with expanded SQL generation capabilities
The MySQL, PostgreSQL, and SQLite dialect implementations have been significantly refactored to support a wider range of modern database features. Users can now leverage support for generated/computed columns, CHECK constraints, and invisible indexes in MySQL, as well as concurrent index creation, materialized views, and advanced data types (such as arrays, ranges, and network types) in PostgreSQL. SQLite dialect updates include support for the RETURNING clause, upsert operations (ON CONFLICT DO UPDATE), and partial indexes. Additionally, the dialects now handle raw values in default clauses, per-column index directions, and specific locking modifiers (NOWAIT, SKIP LOCKED) for row-level locking.
phalcon/Db/Dialect · high confidence
Micro routing and lazy loading restructured with dedicated exception classes
The Phalcon\\Mvc\\Micro component has been refactored to improve type safety and error handling. The Collection class now strictly enforces that its handlers property is an array, and route definition methods (get, post, etc.) accept a nullable name parameter. A new LazyLoader class handles deferred handler instantiation, including model binding and method invocation. Additionally, a suite of specific exception classes (e.g., LazyHandlerNotFound, HandlerNotCallable) has been introduced to provide clearer error messages for common micro application issues.
phalcon/Mvc/Micro · high confidence
Model metadata storage adapters now use the Cache Adapter Factory
The model metadata storage adapters for APCu, Libmemcached, Redis, and Stream have been updated to accept a Phalcon\\Cache\\AdapterFactory instance as their primary constructor argument. This change replaces direct backend configuration with a factory-based approach, allowing these adapters to leverage the unified cache adapter system for managing their underlying storage backends while retaining their specific metadata handling logic.
ext/phalcon/mvc/model/metadata · high confidence
New Dispatcher and CLI Contracts with standardized parameter methods
The framework introduces canonical interface contracts for the Dispatcher (\Phalcon\\Contracts\\Dispatcher\\Dispatcher\) and CLI Dispatcher (\Phalcon\\Contracts\\Cli\\Dispatcher\), along with type definition interfaces (\DispatcherTypes\, \CliTypes\) to standardize static analysis. The Dispatcher contract establishes \getParameter\, \getParameters\, \hasParameter\, \setParameter\, and \setParameters\ as the primary methods for handling action parameters, while marking the legacy \getParam\, \getParams\, \hasParam\, \setParam\, and \setParams\ methods as deprecated for removal in the next major version. The CLI Dispatcher contract defines the interface for managing CLI tasks, options, and task names.
phalcon/Contracts/Dispatcher · high confidence
New Interpolator Interface and Implementations for Translation
The translation system now uses a dedicated \InterpolatorInterface\ with two concrete implementations: \AssociativeArray\ for named placeholders and \IndexedArray\ for positional placeholders. The \IndexedArray\ implementation includes a safety fix that catches \ValueError\ exceptions during \vsprintf\ calls, preventing crafted translation keys from causing Denial of Service errors when format specifiers do not match provided arguments.
phalcon/Translate/Interpolator · high confidence
New InvalidModifier exception for time clock operations
A new InvalidModifier exception class has been added to the Phalcon Time Clock namespace. This exception is thrown when an invalid modifier is provided during time clock operations, allowing developers to catch and handle specific errors related to modifier validation rather than generic exceptions.
phalcon/Time/Clock/Exceptions · high confidence
New PHQL query exception classes for ambiguous columns and joins
The \ext/phalcon/mvc/model/query/exceptions\ directory now includes generated C and header files for new exception classes, specifically \AmbiguousColumn\ and \AmbiguousJoinRelation\. These exceptions provide detailed error messages when a PHQL query references a column name that is ambiguous across multiple tables or when a join between two models is ambiguous due to multiple relations, requiring the use of aliases to resolve the conflict.
ext/phalcon/mvc/model/query/exceptions · high confidence
New Phalcon\\Tag\\Exception class and refactored Select helper
The Phalcon\\Tag component now includes a dedicated Exception class for tag-related errors, ensuring consistent error handling. The Select helper has been refactored to improve security and robustness: it now explicitly escapes empty option values and text to prevent XSS vulnerabilities, and uses a dedicated Exception for missing 'using' parameters when processing resultsets. Additionally, the toStringValue method ensures non-stringable values are safely converted to empty strings rather than causing errors.
phalcon/Tag · high confidence
New URL generation utilities and interface definitions
The \ext/phalcon/mvc/url\ component now includes generated C source and header files for the \Phalcon\\Mvc\\Url\\UrlInterface\ and a new \Phalcon\\Mvc\\Url\\Exception\ class, establishing the public API contract and error handling for URL generation. Additionally, \utils.c\ and \utils.h\ introduce low-level C functions (\phalcon\_get\_uri\, \phalcon\_replace\_paths\, and \phalcon\_extract\_named\_params\) that handle the core logic for extracting URIs, replacing path placeholders, and processing named parameters, providing the underlying implementation for the URL service.
ext/phalcon/mvc/url · high confidence
New cache and file-based metadata adapters for model metadata
The model metadata system now includes dedicated adapters for storing metadata in APCu, Memcached, Redis, and local PHP files (Stream), alongside a Memory adapter for temporary storage. These new classes replace the previous storage mechanism by leveraging the Cache Adapter Factory for distributed caches (APCu, Memcached, Redis) and the Settings component for file-based persistence options. Users can now choose the appropriate storage backend via the new constructor options, with sensible defaults like a 48-hour lifetime for cache-based adapters and configurable directories for file storage.
phalcon/Mvc/Model/MetaData · high confidence
New dependency injection container and factory implementation
The \ext/phalcon/container\ location now provides a regenerated C implementation for the \Phalcon\\Container\\Container\ class and a new \Phalcon\\Container\\ContainerFactory\. The container class implements \ServiceCollection\ and \ServiceEnumerable\ interfaces, manages service definitions, aliases, parameters, and instances, and includes built-in processors for object and closure definitions. The factory allows adding service providers and instantiating a new container configured by those providers.
ext/phalcon/container · high confidence
New exception classes for Dependency Injection and Security validation
The Phalcon framework now includes a comprehensive set of new exception classes to provide more specific error reporting. In the Dependency Injection component, exceptions have been added to handle scenarios such as alias conflicts, circular references, missing service definitions, and invalid parameter types. Additionally, the Encryption Security component introduces an exception for invalid random input numbers. These changes ensure that developers receive precise feedback when service resolution or security validation fails.
(repo-wide) · high confidence
New exception classes for the Autoload Loader
The Phalcon Autoload component now includes specific exception classes to provide clearer error reporting when configuration is invalid. If the directories parameter passed to the loader is not a string or array, a \Phalcon\\Autoload\\Exceptions\\LoaderDirectoriesNotArray\ exception is thrown. Similarly, if the method parameter is neither a callable nor NULL, a \Phalcon\\Autoload\\Exceptions\\LoaderMethodNotCallable\ exception is raised. These exceptions extend the base \Phalcon\\Autoload\\Exception\ class, allowing applications to catch and handle these specific loader configuration errors.
ext/phalcon/autoload · high confidence
New file validation validators with wildcard MIME type support
The file validation logic has been refactored into a new \AbstractFile\ base class and specific validators like \MimeType\. This introduces a \MimeType\ validator that checks uploaded files against allowed types, supporting both exact matches and wildcard patterns via a new \allowWildcards\ option. The underlying \AbstractFile\ class centralizes upload checks (empty, valid structure, max size) and improves reliability by using \finfo\ for MIME detection when available, falling back to the client-provided type otherwise.
phalcon/Filter/Validation/Validator/File · high confidence
New internal token model classes for JWT parsing
The \ext/phalcon/encryption/security/jwt/token\ directory now contains the regenerated C source and header files for the internal JWT token model. This adds the \Phalcon\\Encryption\\Security\\JWT\\Token\\AbstractItem\ base class, the \Phalcon\\Encryption\\Security\\JWT\\Token\\Item\ class for storing claims and headers, the \Phalcon\\Encryption\\Security\\JWT\\Token\\Signature\ class for handling signature data, the \Phalcon\\Encryption\\Security\\JWT\\Token\\Token\ container class, and the \Phalcon\\Encryption\\Security\\JWT\\Token\\Parser\ for decoding and validating token structures. These classes provide the underlying data structures and parsing logic used by the JWT encryption component.
ext/phalcon/encryption/security/jwt/token · high confidence
New paginator contract interfaces and type registry
The \ext/phalcon/contracts/paginator\ directory now contains the generated C and header files for the \Phalcon\\Contracts\\Paginator\ namespace. This introduces the \Adapter\ interface (defining \getLimit\, \paginate\, \setCurrentPage\, and \setLimit\), the \Repository\ interface (exposing pagination state like \getCurrent\, \getItems\, \getTotalItems\, and cursor-specific behaviors), and the \PaginatorTypes\ interface which serves as a central registry for PHPStan array shapes used across the paginator components.
ext/phalcon/contracts/paginator · high confidence
New serializer implementations for Phalcon Storage
The \ext/phalcon/storage/serializer\ directory now contains the regenerated C source and header files for the storage serializer component. This update introduces concrete serializer classes including \AbstractSerializer\, \Base64\, \Igbinary\, \Json\, \Msgpack\, \None\, and \Php\, along with their corresponding exception classes (\InvalidSerializationInput\, \InvalidUnserializationInput\) and Memcached-specific serializers (\MemcachedIgbinary\, \MemcachedJson\, \MemcachedPhp\). These files provide the underlying PHP extension code that enables data serialization and deserialization for the Phalcon Storage component.
ext/phalcon/storage/serializer · high confidence
New specific exception classes for Asset Manager errors
The Asset Manager now throws distinct exception types for specific failure scenarios, replacing generic errors with more descriptive ones. Developers will now encounter \AssetSourceTargetCollision\ when an asset's source and target paths are identical, \CannotReadAsset\ when asset content cannot be read, \CollectionNotFound\ when a named collection is missing, \InvalidAssetSourcePath\ and \InvalidAssetTargetPath\ for invalid path configurations, \InvalidFilter\ for bad filter definitions, \InvalidTargetPath\ for general target path issues, and \TargetPathIsDirectory\ when the target path incorrectly points to a directory. This allows for more precise error handling in asset management workflows.
phalcon/Assets/Exceptions · high confidence
New specific exception classes for Encryption and HTML components
Added new, granular exception classes to improve error handling in the Encryption and HTML components. In the Encryption namespace, \InvalidRandomInput\ and \UnknownHashAlgorithm\ now provide specific errors for invalid input numbers and unrecognized hashing algorithms. In the HTML namespace, \AttributeNotRenderable\, \FriendlyTitleConversionFailed\, \InvalidResultsetValue\, \ServiceNotRegistered\, and \UsingRequiresTwoValues\ allow developers to catch and handle specific failures related to attribute rendering, title conversion, resultset values, service registration, and parameter validation.
phalcon/Encryption/Security/Exceptions, phalcon/Html/Exceptions · high confidence
New specific exception classes for Paginator validation errors
The Paginator component now includes a set of dedicated exception classes to provide clearer error reporting during pagination operations. New exceptions such as BuilderModelNotDefined, InvalidBuilderInstance, InvalidCursorColumn, InvalidLimit, MissingColumnsForHaving, MissingRequiredParameter, and PaginatorDataNotArray have been added to the Phalcon\\Paginator\\Exceptions namespace. These classes replace generic error handling with specific, descriptive messages for common configuration and data issues, allowing developers to catch and handle pagination errors more precisely.
phalcon/Http/Request/Exceptions, phalcon/Paginator/Exceptions · high confidence
New specific exception classes for Phalcon\\Encryption\\Crypt
The \phalcon/Encryption/Crypt/Exception\ directory now contains a dedicated set of exception classes to provide clearer error reporting during encryption and decryption operations. This includes a base \Exception\ class and specific subclasses such as \DecryptionFailed\, \EncryptionFailed\, \EmptyDecryptionKey\, \EmptyEncryptionKey\, \InvalidAuthTagLength\, \InvalidDecryptLength\, \InvalidPaddingSize\, \IvLengthCalculationFailed\, \Mismatch\, \MissingAuthData\, \MissingOpensslExtension\, \RandomBytesGenerationFailed\, and \UnsupportedAlgorithm\. These changes allow developers to catch and handle specific cryptographic errors rather than relying on generic exceptions.
phalcon/Encryption/Crypt/Exception · high confidence
Paginator component regenerated with new Repository and Factory classes
The C extension code for the Paginator module has been regenerated, introducing a new Repository class that implements JsonSerializable and a RepositoryInterface (marked deprecated in favor of a contracts version), alongside a PaginatorFactory for creating paginator instances. These changes update the internal structure of the paginator, affecting how pagination state is represented and how paginator adapters are instantiated.
ext/phalcon/paginator · medium confidence
Phalcon ACL component and role classes now reject wildcard and exclamation mark names
The C implementation for Phalcon\\Acl\\Component and Phalcon\\Acl\\Role now validates constructor names at runtime: names containing a wildcard (\*) or an exclamation mark (!) throw specific exceptions (ForbiddenWildcardException and ForbiddenDelimiterException). This prevents invalid or ambiguous identifiers from being registered in the ACL system.
ext/phalcon/acl · high confidence
Phalcon PHP extension regenerated for version 5.22.0
The build artifacts for the Phalcon PHP extension have been regenerated, updating the extension to version 5.22.0. This refresh includes updated build configuration files (config.m4 and config.w32) and regenerated C source and header files (phalcon.zep.c, phalcon.zep.h, php\_phalcon.h) produced by the Zephir compiler, ensuring the extension is rebuilt with the latest changes.
build/phalcon · high confidence
Phalcon extension build system regenerated for version 5.20.3
The \ext/\ directory has been regenerated, introducing a new \clean\ script to remove build artifacts and updating \config.m4\ and \config.w32\ to reflect the new source file layout. This update aligns the C extension build configuration with the current Phalcon 5.20.3 codebase, ensuring that the extension compiles correctly against the latest PHP and Zephir versions.
ext · high confidence
Refactored Application module handling and exception hierarchy
The application module management logic has been moved into a new AbstractApplication base class, which now serves as the foundation for both Phalcon\\Mvc\\Application and Phalcon\\Cli\\Console. This change introduces a dedicated ModuleNotRegistered exception for clearer error reporting when accessing unregistered modules, and updates the default module property to initialize as an empty string instead of null. Additionally, the events manager is now explicitly synchronized with the dependency injection container when set.
phalcon/Application · high confidence
Refactored CLI Router with dedicated exception classes and route validation
The CLI Router now uses a dedicated \Phalcon\\Cli\\Router\\Exception\ base class and specific sub-exceptions (such as \BeforeMatchNotCallable\ and \InvalidRoutePaths\) instead of generic exceptions, providing clearer error messages for routing failures. The \Route\ class has been updated to validate that \beforeMatch\ callbacks are callable, throwing a specific exception if they are not, and it now supports a configurable global delimiter for route patterns. Additionally, the router introduces a \RouteInterface\ to standardize route properties and methods, and fixes a potential catastrophic backtracking issue in the default \:params\ route pattern by tightening the regular expression.
phalcon/Cli/Router · high confidence
Refactored HTML Escaper into context-specific classes
The HTML Escaper component has been restructured to use dedicated classes for each escaping context—HtmlEscaper, AttributeEscaper, CssEscaper, JsEscaper, and UrlEscaper—instead of a single monolithic class. This change introduces an AbstractEscaper base class that composes a shared EscaperTrait, and defines an EscaperInterface that standardizes the public API for escaping HTML, attributes, CSS, JavaScript, and URLs. Users interacting with this location will now find a more modular architecture where specific escaping logic is isolated per context, improving maintainability and allowing for more precise type handling (e.g., AttributeEscaper now supports associative arrays of attribute pairs).
phalcon/Html/Escaper · high confidence
Refactored HTTP Response headers and cookies into dedicated bag classes
The \Phalcon\\Http\\Response\ component now uses dedicated \Headers\ and \Cookies\ classes to manage response data, replacing the previous inline implementation. The new \Headers\ bag tracks an \isSent\ state to prevent duplicate header transmission and uses \array\_key\_exists\ for existence checks. The \Cookies\ bag introduces similar \isSent\ and \isRegistered\ tracking to ensure cookies are only sent once, and it now relies on the \AbstractInjectionAware\ base class and \EncryptionAwareTrait\ for dependency injection and encryption handling.
phalcon/Http/Response · high confidence
Refactored Messages component with new interfaces and exception hierarchy
The Phalcon Messages component has been restructured to improve type safety and error handling. A new \MessageInterface\ defines the contract for individual messages, implemented by the \Message\ class which now supports JSON serialization. The \Messages\ collection class has been updated to use a \MessagesHelperTrait\ for iterator and array-access functionality, and it now strictly enforces that only \MessageInterface\ instances are added via \offsetSet\, throwing a new \MessageNotObject\ exception otherwise. Additionally, a dedicated \MessagesNotIterable\ exception is thrown when non-iterable data is passed to \appendMessages\. These changes provide a more robust and type-safe API for handling validation and application messages.
phalcon/Messages · high confidence
Refactored Model ORM core with new interfaces and behavior support
The \phalcon/Mvc/Model\ component has been refactored to introduce a formalized behavior system and updated internal contracts. A new \Behavior\ class and \BehaviorInterface\ allow models to register reusable logic hooks, while the \Manager\ now explicitly supports these behaviors and new relation types like \hasOneThrough\. The refactoring also introduces dedicated interfaces for core components (\CriteriaInterface\, \BinderInterface\, \MetaDataInterface\, \QueryInterface\, \RelationInterface\) and adds a \Binder\ class for automatic model injection into handlers. Additionally, the \MetaData\ component now uses a strategy pattern for metadata retrieval and includes a \pendingMetaDataWrites\ mechanism to handle initialization order issues.
phalcon/Mvc/Model · high confidence
Refactored PDO database adapters with improved type handling and connection management
The Phalcon database layer has been refactored to improve type safety and connection reliability. The \AbstractPdo\ base class now enforces \void\ return types for \connect()\, \close()\, and \getErrorInfo()\ (returning an array), and exposes a new \autoReconnect\ option to transparently retry failed queries. MySQL-specific behavior has been adjusted so that \BIGINT\ columns are treated as strings to prevent precision loss, and MariaDB-specific default value unquoting is now correctly isolated. Additionally, SQLite and PostgreSQL adapters now explicitly reject charset configuration in the DSN, and the \connect()\ method signature has been standardized across all PDO adapters.
phalcon/Db/Adapter/Pdo · high confidence
Refactored Query Builder and PHQL components to Zephir
The Query Builder and related PHQL handling components have been rewritten in Zephir (Builder.zep, BuilderInterface.zep, Lang.zep, Status.zep, StatusInterface.zep). This change introduces stricter type safety for bind parameters and types (now always treated as arrays), ensures the GROUP BY field is always an array, and fixes PostgreSQL compatibility by properly quoting string conditions. It also simplifies limit/offset handling (ignoring zero offsets) and improves internal consistency across the query building API.
phalcon/Mvc/Model/Query · high confidence
Refactored Session component with new exception hierarchy and Bag namespace support
The Session component has been restructured to improve error handling and data organization. A new exception hierarchy has been introduced under \Phalcon\\Session\\Exceptions\, replacing generic errors with specific classes such as \InvalidSessionId\, \InvalidSessionName\, \InvalidSessionAdapter\, \SessionAlreadyStarted\, and \SessionModificationDenied\ to provide clearer feedback on session state and configuration issues. Additionally, the \Session\\Bag\ class has been refactored to extend \Support\\Collection\, allowing session data to be managed as a typed collection within specific namespaces. The \Manager\ interface and implementation now enforce stricter validation, including checks for valid session IDs and names, and prevent session name changes after the session has started.
phalcon/Session · high confidence
Refactored StringLength validators into Max and Min classes with boundary option support
The StringLength validation logic has been split into dedicated \Max\ and \Min\ validator classes. These new validators support per-field configuration for minimum/maximum lengths and error messages, and introduce an \included\ option (with \includedMinimum\/\includedMaximum\ aliases) to control whether the boundary value is inclusive or exclusive. The implementation also adds support for multi-byte string length calculation via \mb\_strlen\ when available.
phalcon/Filter/Validation/Validator/StringLength · high confidence
Refactored build system with automated generation and PHP 7.4+ enforcement
The build process has been restructured to use an automated generator (gen-build.php) that creates optimized source copies for 32-bit and 64-bit targets, replacing manual synchronization. The new install script enforces a minimum PHP version of 7.4, detects CPU-specific optimization flags, and supports custom phpize/php-config paths. Additionally, a .gitignore file has been added to exclude generated build artifacts.
build · high confidence
Refactored build utilities into a modular PHP generator system
The build process in the \build/util\ directory has been restructured to use a new set of PHP classes for generating the C extension source files. A new \Autoloader\ and \Util\ class provide core support, while a \Generator\ orchestrates the creation of \phalcon.h\, \phalcon.c\, \config.m4\, and \config.w32\. Specific file generators (\Generator\_File\_PhalconH\, \Generator\_File\_PhalconC\, etc.) handle the logic for processing source code, such as inlining headers, removing extern declarations, and managing file lists, replacing the previous build logic.
build/util · high confidence
Refactored database adapter architecture with new contracts and factory
The database adapter layer has been restructured to improve type safety and separation of concerns. The core \AbstractAdapter\ class now implements the new \AdapterInterface\, which extends the canonical \Phalcon\\Contracts\\Db\\Adapter\\Adapter\ contract, while the legacy interface is marked as deprecated. A new \PdoFactory\ has been introduced to handle the instantiation of PDO-based adapters (MySQL, PostgreSQL, SQLite) from configuration, centralizing service discovery. Additionally, the adapter now integrates with the global \Settings\ component for configuration and enforces stricter type declarations, such as returning \void\ for connection lifecycle methods and \mixed\ for internal handlers.
phalcon/Db/Adapter · high confidence
Refactored factory service discovery and configuration handling
The Factory component has been restructured to improve service discovery and configuration validation. A new AbstractConfigFactory base class now handles config validation, ensuring that inputs are either arrays or ConfigInterface objects and enforcing the presence of required 'adapter' elements. The AbstractFactory class has been updated to extend this base, introducing a service mapper and initialization logic that merges provided services with default adapters. Additionally, a dedicated Factory\\Exception class has been added to provide more specific error handling for factory operations.
phalcon/Factory · high confidence
Refactored input helpers into a generic, extensible class hierarchy
The input helper classes have been restructured into a shared base hierarchy (AbstractInput, AbstractChecked, AbstractGroup) to reduce duplication and standardize behavior. A new Generic input helper allows rendering any HTML5 input type (e.g., color, date, email) via a single class configured by type, while Checkbox and Radio helpers now support label wrapping, unchecked companion inputs, and configurable strict/loose value matching. Group helpers (CheckboxGroup, RadioGroup) simplify rendering multiple options from an array, and the Select helper has been updated to support optgroups, placeholders, and data-driven population.
phalcon/Html/Helper/Input · high confidence
Refactored model hydration into dedicated strategy classes
The model hydration logic has been reorganized into specific classes within the \Phalcon\\Mvc\\Model\\Hydration\ namespace to improve clarity and maintainability. \CloneResult\ now handles cloning a base model instance and assigning data, including support for setting private properties via reflection. \CloneResultMapHydrate\ manages the mapping of database columns to model attributes, incorporating case-insensitive column map lookups when enabled. \GetPrivateProperties\ provides a cached mechanism to retrieve private properties using reflection, ensuring raw values are assigned correctly without triggering setters. \CaseInsensitiveColumnMap\ supports the case-insensitive lookup feature. These changes represent an internal architectural refinement of how model data is hydrated from result sets.
phalcon/Mvc/Model/Hydration · high confidence
Refactored paginator adapters to use Repository and return RepositoryInterface
The paginator adapters (Model, NativeArray, QueryBuilder, and QueryBuilderCursor) have been refactored to return a Repository object instead of an array or Resultset. This change standardizes the pagination result structure, providing consistent access to items, total count, and navigation metadata (current page, next/previous page, etc.) through the RepositoryInterface. The AbstractAdapter now manages the repository instance, and specific adapters populate it with paginated data. This affects how consumers of the paginator interact with the results, requiring them to use the repository's methods to access pagination details.
phalcon/Paginator/Adapter · high confidence
Refactored string helpers into individual classes using traits
The string helper classes in \phalcon/Support/Helper/Str\ have been restructured to use dedicated traits (such as \EndsWithTrait\, \InterpolateTrait\, \LowerTrait\, \StartsWithTrait\, and \UpperTrait\) for their core logic, replacing the previous \AbstractStr\ base class. This change introduces new specific exception classes (\InsufficientArguments\, \InvalidReplaceFormat\, \SyntaxError\) to handle validation errors in helpers like \Concat\ and \Friendly\, and updates the \Camelize\ helper to support configurable delimiters and case options via its \\_\_invoke\ method.
phalcon/Support/Helper/Str · high confidence
Refactored translation adapters with strict mode and new interface
The translation adapter layer has been restructured to improve consistency and error handling. A new \AdapterInterface\ and \AbstractAdapter\ base class now define the core contract, introducing a \triggerError\ option that enables strict mode; when enabled, missing translation keys throw a \KeyNotFound\ exception instead of returning the key itself. The \exists()\ method is deprecated in favor of \has()\, and \toArray()\ has been added to the \Csv\ and \NativeArray\ adapters to expose the internal translation data. Additionally, the \Gettext\ adapter now uses the \InfoTrait\ for system checks, and the \Csv\ adapter utilizes \FileTrait\ for file operations.
phalcon/Translate/Adapter · high confidence
Refactored translation factories with granular exceptions
The translation component now uses dedicated factory classes (TranslateFactory and InterpolatorFactory) that extend AbstractFactory to instantiate adapters and interpolators. This change introduces specific exception types (TranslatorNotRegistered, InterpolatorNotRegistered) for better error handling when requested adapters or interpolators are not found, replacing the previous generic exception behavior.
phalcon/Translate · high confidence
Refactored translation factory to use explicit interpolator dependency
The \Phalcon\\Translate\\TranslateFactory\ constructor now requires an \InterpolatorFactory\ instance as its first argument, replacing the previous implicit or default initialization. This change ensures that the factory explicitly depends on the configured interpolator service, making the translation adapter creation process more predictable and aligned with dependency injection best practices.
ext/phalcon/translate · high confidence
Refactored view engine architecture with new abstract base class and interface
The view engine subsystem has been restructured to improve type safety and event handling. A new \AbstractEngine\ base class now serves as the foundation for all template engines, implementing \EngineInterface\ and \EventsAwareInterface\ to provide standardized access to the view component, content, and event manager. Concrete engines like \Php\ and \Volt\ now extend this abstract class, inheriting common behaviors such as partial rendering and event firing. This change introduces explicit event manager integration for view engines, allowing users to attach listeners to engine-specific events, and enforces stricter type definitions for engine parameters and return values.
phalcon/Mvc/View/Engine · high confidence
Refreshed Phalcon Db Adapter contract definitions
The canonical contract for Phalcon database adapters has been regenerated to align with the latest internal changes. This update refreshes the generated C and header files for the \Phalcon\\Contracts\\Db\\Adapter\\Adapter\ interface, ensuring that the method signatures, argument types, and PHPDoc annotations (including \@phpstan-import-type\ definitions) remain consistent with the current framework state. For users, this maintains the stability of the database abstraction layer and ensures type-safety for custom adapter implementations without introducing new features or behavioral changes.
ext/phalcon/contracts/db/adapter · medium confidence
Regenerated C code for Db\\Profiler\\Item
The C source and header files for the Phalcon\\Db\\Profiler\\Item class have been regenerated. This update refreshes the underlying implementation to align with the latest Zephir compiler version, ensuring the profiler item's getter and setter methods for SQL statements, bind parameters, and timing data are correctly compiled for the current PHP runtime.
ext/phalcon/db/profiler · medium confidence
Regenerated C code for MySQL, PostgreSQL, and SQLite dialects
The C source and header files for the MySQL, PostgreSQL, and SQLite database dialects have been regenerated. This update refreshes the underlying implementation of these dialects, ensuring they are compiled with the latest Zephir changes and maintaining compatibility with the current Phalcon framework version.
ext/phalcon/db/dialect · medium confidence
Regenerated C code for Phalcon\\Mvc\\Micro components
The C source files for the Phalcon\\Mvc\\Micro module have been regenerated using the latest Zephir compiler. This update refreshes the underlying implementation for the Micro application, its route collections, the lazy loader, and the associated exception classes, ensuring compatibility with the current Zephir version and resolving any compilation warnings.
ext/phalcon/mvc/micro · medium confidence
Regenerated C code for database adapter components
The C source and header files for the Phalcon database adapter layer have been regenerated, including the abstract adapter, the PDO factory, and the adapter interface. This update refreshes the underlying implementation for database connection handling and adapter instantiation, ensuring the C code aligns with the current Zephir definitions.
ext/phalcon/db/adapter · medium confidence
Regenerated C code for the DataMapper PDO connection classes
The C source and header files for the Phalcon DataMapper PDO connection layer (AbstractConnection, ConnectionInterface, Decorated, and PdoInterface) have been regenerated. This update refreshes the underlying Zephir-generated implementation for database connection handling, including the abstract base class, the connection interface, the PDO decorator, and the native PDO interface, ensuring the extension code is synchronized with the latest Zephir compiler output.
ext/phalcon/datamapper/pdo/connection, ext/phalcon/mvc/model/transaction · medium confidence
Regenerated C code for the PDO DataMapper connection layer
The C source and header files for the PDO DataMapper connection components have been regenerated to align with the latest Zephir compiler. This update refreshes the underlying implementation for the \Phalcon\\DataMapper\\Pdo\\Connection\ class, the \ConnectionLocator\ (which manages default, read, and write connection instances), the \ConnectionLocatorInterface\, and the \Events\ class (which defines lifecycle event constants).
ext/phalcon/datamapper/pdo · medium confidence
Regenerated C code for the Phalcon filter sanitization classes
The C source and header files for the \ext/phalcon/filter/sanitize\ directory have been regenerated, updating the compiled implementations for sanitizers such as \AbsInt\, \Alnum\, \Alpha\, \BoolVal\, \Email\, \FloatVal\, \IntVal\, \Ip\, \Lower\, \LowerFirst\, \Regex\, \Remove\, \Replace\, \Special\, \SpecialFull\, \StringVal\, \StringValLegacy\, \Striptags\, \Trim\, and \Upper\. This regeneration aligns the extension code with the latest Zephir compiler updates and ensures the sanitization logic matches the current framework definitions.
ext/phalcon/filter/sanitize · high confidence
Regenerated C code for the ext/phalcon/html component
The C source files in the ext/phalcon/html directory have been regenerated using the latest Zephir compiler. This update refreshes the underlying PHP extension implementation for HTML helpers, including the Attributes, Breadcrumbs, Escaper, EscaperFactory, and TagFactory classes, ensuring they align with the current Zephir version and framework standards.
ext/phalcon/config, ext/phalcon/html · medium confidence
Regenerated C code for the session component using the latest Zephir compiler
The C source files for the session extension (including \Phalcon\\Session\\Bag\, \Phalcon\\Session\\Manager\, and their respective interfaces) have been regenerated. This update aligns the compiled extension with the latest Zephir version, ensuring compatibility with current PHP internals and applying any underlying compiler improvements or bug fixes present in the Zephir toolchain.
ext/phalcon/cli, ext/phalcon/session · medium confidence
Regenerated C extension code for Complex and Simple resultsets
The C source and header files for Phalcon\\Mvc\\Model\\Resultset\\Complex and Phalcon\\Mvc\\Model\\Resultset\\Simple have been regenerated. This rebuild aligns the compiled extension with the current Zephir definitions, ensuring that serialization, unserialization, and constructor signatures match the expected PHP types and method entries.
ext/phalcon/mvc/model/resultset · medium confidence
Regenerated C extension code for HTML helper classes
The C source and header files for the HTML helper classes (AbstractHelper, AbstractList, AbstractSeries, Anchor, Base, Body, Breadcrumbs, Button) in ext/phalcon/html/helper have been regenerated. This update refreshes the underlying C implementation to align with the latest Zephir compiler changes, ensuring the helpers continue to function correctly with current PHP and Zephir versions.
ext/phalcon/datamapper/query, ext/phalcon/html/helper · medium confidence
Regenerated C extension code for HTML input helpers
The C source and header files in ext/phalcon/html/helper/input have been regenerated to match the current Zephir definitions. This update refreshes the compiled implementations for the input helper classes (AbstractInput, AbstractChecked, AbstractGroup, Checkbox, Radio, Select, Textarea, and their group variants), ensuring the extension binary stays in sync with the Zephir source layer without altering the public API surface.
ext/phalcon/html/helper/input · high confidence
Regenerated C extension code for HTTP response components
The C source files for the Phalcon HTTP response subsystem have been regenerated to align with the latest Zephir compiler version. This update refreshes the generated code for the Cookies bag, Headers bag, and their respective interfaces, as well as the response exception classes, ensuring compatibility with the current build environment without altering the public API.
ext/phalcon/http, ext/phalcon/http/response · high confidence
Regenerated C extension code for Phalcon Messages
The C source and header files in ext/phalcon/messages were regenerated, updating the compiled implementation of the message handling components. This includes the base Phalcon\\Messages\\Exception, the specific exception classes Phalcon\\Messages\\Exceptions\\MessageNotObject and Phalcon\\Messages\\Exceptions\\MessagesNotIterable, the Phalcon\\Messages\\Message class, the Phalcon\\Messages\\MessageInterface, the Phalcon\\Messages\\Messages collection, and the Phalcon\\Messages\\Traits\\MessagesHelperTrait. The regeneration ensures the C code aligns with the current Zephir definitions for these classes.
(repo-wide) · medium confidence
Regenerated C extension code for Phalcon\\Tag using latest Zephir
The C source files for the Phalcon\\Tag extension (including Phalcon\\Tag\\Select and Phalcon\\Tag\\Exception) have been regenerated with the latest Zephir compiler. This update refreshes the underlying C implementation to align with the current Zephir version, ensuring compatibility and incorporating any internal compiler improvements, without changing the public API surface.
ext/phalcon, ext/phalcon/mvc/model, ext/phalcon/tag · medium confidence
Regenerated C extension code for form elements
The C source and header files for the Phalcon\\Forms\\Element classes (AbstractElement, Check, CheckGroup, Date, Email, File, Hidden, Numeric, Password, Radio, RadioGroup, and ElementInterface) have been regenerated. This update aligns the compiled extension with the latest Zephir compiler version, ensuring compatibility and resolving any build warnings or obsolete function references in the underlying C code.
ext/phalcon/forms/element · high confidence
Regenerated C extension code for model behaviors
The C source and header files for the Phalcon model behavior extension have been regenerated using the latest Zephir compiler. This update refreshes the underlying implementation for behaviors such as SoftDelete, Timestampable, and the associated MissingRequiredOption exception, ensuring compatibility with the current Zephir version and resolving any compilation warnings or style issues in the generated PHP extension code.
ext/phalcon/mvc/model/behavior · medium confidence
Regenerated C extension code for storage adapters
The C source and header files for the storage adapter layer (AbstractAdapter, AdapterInterface, Apcu, Libmemcached, and Memory) have been regenerated. This update refreshes the underlying PHP extension implementation to align with the latest Zephir compiler and framework changes, ensuring the adapters continue to function correctly with current PHP versions.
ext/phalcon/storage/adapter · medium confidence
Regenerated C extension code for the Assets component
The C source files for the Phalcon\\Assets component (Asset, Collection, Inline, Manager, and their interfaces) have been regenerated using the latest Zephir compiler. This update refreshes the underlying C implementation to align with the current Zephir version, ensuring compatibility and incorporating any internal compiler improvements, while preserving the existing public API for managing CSS and JavaScript assets.
ext/phalcon/assets · medium confidence
Regenerated C extension sources for Phalcon encryption components
The C source files for the Phalcon encryption extension have been regenerated, updating the compiled implementations of Phalcon\\Encryption\\Crypt, Phalcon\\Encryption\\Security, and their supporting classes (PadFactory, CryptInterface). This refresh aligns the C code with the latest Zephir compiler version, ensuring the encryption and security APIs remain consistent with the current framework build environment.
ext/phalcon/encryption · medium confidence
Regenerated C extension sources for Phalcon\\Support classes
The C source and header files for the Phalcon\\Support namespace (including AbstractLocator, Collection, Debug, HelperFactory, and Registry) have been regenerated. This update aligns the compiled extension with the latest Zephir compiler and internal framework changes, ensuring the support utilities remain consistent with the current Phalcon codebase.
ext/phalcon/support · high confidence
Regenerated C kernel code for PHP 8.1+ compatibility
The C source files in the ext/kernel directory (including array, concat, and backtrace modules) have been regenerated to support PHP 8.1 and later. This update introduces a deprecation notice when \false\ is automatically converted to an array, aligns array index handling with PHP 8.1's \zend\_long\ type to prevent truncation on 32-bit Windows, and adapts internal memory management and backtrace functions to remain compatible with modern PHP versions.
ext/kernel · high confidence
Regenerated C source files for Phalcon Cache exception classes
The C implementation files for the Phalcon Cache exception classes (Exception and InvalidArgumentException) have been regenerated. This update ensures the underlying PHP extension code matches the current Zephir definitions, maintaining compatibility and correctness for cache-related error handling.
ext/phalcon/cache/exception · medium confidence
Regenerated C source for the MVC Router extension
The C source files for the \ext/phalcon/mvc/router\ directory have been regenerated using the latest version of Zephir. This update refreshes the compiled C code for core router components, including the \Annotations\ router, \Group\ routing, and the full suite of router-specific exception classes (such as \AnnotationsServiceUnavailable\ and \BeforeMatchNotCallable\), ensuring alignment with the current Zephir compiler standards.
ext/phalcon/mvc/router · medium confidence
Regenerated C source for validation validators
The C implementation files for the Phalcon validation validators (Alnum, Alpha, Between, Callback, Confirmation, CreditCard, Date, and Digit) have been regenerated. This update refreshes the underlying C code generated from the Zephir source, ensuring the validators remain compatible with the current Zephir compiler and PHP engine without changing their public API or validation logic.
ext/phalcon/filter/validation/validator · medium confidence
Regenerated C source for view engine adapters
The C implementation files for the Phalcon view engine layer (AbstractEngine, EngineInterface, Php, and Volt) have been regenerated using the latest Zephir compiler. This update refreshes the underlying C code to align with recent Zephir changes, ensuring compatibility and resolving build warnings without altering the public API surface.
ext/phalcon/mvc/view/engine · medium confidence
Regenerated JWT signer implementation files
The C source and header files for the JWT signer components (AbstractSigner, Hmac, None, and SignerInterface) in ext/phalcon/encryption/security/jwt/signer have been regenerated. This update refreshes the underlying Zephir-generated C code for these classes, ensuring they align with the latest framework changes, while preserving the existing API surface for HMAC signing, no-op signing, and algorithm retrieval.
ext/phalcon/encryption/security/jwt/signer · medium confidence
Regenerated JWT validation exception classes in the PHP extension
The PHP extension source files for the \ext/phalcon/encryption/security/jwt/exceptions\ directory have been regenerated. This update refreshes the C implementations for JWT validation exception classes, including \EmptyPassphrase\, \InvalidAudience\, \InvalidAudienceType\, \InvalidClaims\, \InvalidExpirationTime\, \InvalidHeader\, \InvalidNotBefore\, \MalformedJwtString\, \MissingJwtTypHeader\, \UnsupportedHmacAlgorithm\, \ValidatorException\, and \WeakPassphrase\. These classes provide specific error handling for JWT validation failures, such as invalid claims, weak passphrases, or unsupported algorithms.
ext/phalcon/encryption/security/jwt/exceptions · medium confidence
Regenerated MVC extension code for Zephir compatibility
The C source files for the Phalcon MVC components (Application, Controller, Dispatcher, Micro, and related interfaces and exceptions) have been regenerated. This update aligns the extension with the latest Zephir compiler version, ensuring compatibility with current PHP internals and resolving compilation warnings.
ext/phalcon/mvc · high confidence
Regenerated PDO database adapter C code from Zephir
The C source and header files for the PDO database adapters (AbstractPdo, Mysql, Postgresql, Sqlite) have been regenerated using the latest Zephir compiler. This mechanical update refreshes the underlying PHP extension code to align with the current Zephir version, ensuring compatibility and incorporating any internal compiler improvements, without introducing new user-facing features.
ext/phalcon/db/adapter/pdo · medium confidence
Regenerated PDO result set implementation
The C source and header files for the Phalcon\\Db\\Result\\PdoResult class in the C extension have been regenerated. This update refreshes the internal implementation of the PDO-based database result set, ensuring the compiled extension code remains synchronized with the underlying Zephir definitions for handling query results.
ext/phalcon/db/result · medium confidence
Regenerated PHP cache adapter bindings
The PHP extension files for the Phalcon cache adapters (Apcu, Libmemcached, Memory, Redis, RedisCluster, Stream, and Weak) have been regenerated. This update refreshes the underlying C bindings for these adapters, ensuring they correctly implement the AdapterInterface and extend their respective storage base classes, while maintaining the protected eventType property.
ext/phalcon/cache/adapter · medium confidence
Regenerated PHP extension code for HTTP Request components
The C source and header files for the Phalcon HTTP Request extension have been regenerated, introducing typed properties and updated method signatures for the Request\\File class and its FileInterface. This update ensures the underlying PHP extension code aligns with the latest Zephir compiler standards, maintaining compatibility and performance for file upload handling within the framework.
ext/phalcon/http/request · medium confidence
Regenerated PHP extension code for Phalcon\\Filter\\Validation
The C source files for the Phalcon\\Filter\\Validation extension have been regenerated, updating the compiled implementations of core validation classes such as AbstractValidator, AbstractCombinedFieldsValidator, AbstractValidatorComposite, and the ValidatorFactory. This refresh ensures the underlying C code stays synchronized with the Zephir definitions, maintaining the existing validation behavior and API surface without introducing new user-facing features.
ext/phalcon/filter/validation · medium confidence
Regenerated PHP extension code for array helper classes
The PHP extension source files in ext/phalcon/support/helper/arr have been regenerated, updating the compiled C implementations for array manipulation helpers such as AbstractArr, Blacklist, Chunk, Filter, First, FirstKey, Flatten, Get, Group, Has, IsUnique, Last, LastKey, and Order. This refresh ensures the extension code aligns with the latest Zephir compiler output and internal framework changes.
ext/phalcon/support/helper/arr · medium confidence
Regenerated PHP extension helpers for string and file operations
The C source files for the Phalcon extension in ext/phalcon/support/helper/str (and related file helpers) have been regenerated, updating the underlying implementations for string manipulation utilities such as camelize, concat, countvowels, decapitalize, decrement, dirfromfile, dirseparator, dynamic, and endswith, as well as the abstract base class and exception classes. This refresh ensures the compiled PHP extension code stays in sync with the current Zephir definitions, preserving existing behavior for these helper functions without introducing new public features.
ext/phalcon/support/helper/str · medium confidence
Regenerated PHP extension sources for Phalcon\\Support\\Debug
The C source and header files for the Phalcon\\Support\\Debug component (including Dump, HtmlRenderer, ExceptionReport, BacktraceItem, and related exception classes) have been regenerated from the Zephir definitions. This rebuild aligns the compiled extension with the current Zephir compiler version and ensures the PHP-facing debug utilities—variable dumping, HTML exception rendering, and report data structures—are consistent with the latest upstream changes.
ext/phalcon/support/debug · medium confidence
Regenerated PHQL parser and query builder components
The PHQL parser and query builder implementation in the C extension has been regenerated using the latest Zephir version. This update refreshes the underlying C code for the parser, scanner, and query builder classes, incorporating fixes for memory leaks, segmentation faults, and PHP 7/8 compatibility issues while maintaining the existing PHQL syntax and builder API.
ext/phalcon/mvc/model/query · medium confidence
Renamed PDO result class to PdoResult
The internal class encapsulating PDO resultset internals has been renamed from \Pdo\ to \PdoResult\ to improve naming clarity and consistency within the \Phalcon\\Db\\Result\ namespace. This change affects the class identity used for result handling but maintains the same functionality for fetching and managing database query results.
phalcon/Db/Result · high confidence
Router component refactored with new exception hierarchy and factory
The \phalcon/Mvc/Router\ location has been restructured to improve error handling and instantiation. A new \Exception\ base class and a dedicated \Exceptions\ namespace have been introduced, replacing the previous generic exception handling with specific error types such as \AnnotationsServiceUnavailable\, \BeforeMatchNotCallable\, and \InvalidRoutePaths\. Additionally, a \RouterFactory\ class has been added to provide a standardized way to build and configure \Router\ instances from arrays or \ConfigInterface\ objects, while the \Annotations\ router now utilizes \Route\ objects to compile pattern prefixes for more efficient route handling.
phalcon/Mvc/Router · high confidence
Sanitizers refactored to implement the Sanitizer interface
The sanitizers in the Filter component (including AbsInt, Alnum, Alpha, BoolVal, Email, FloatVal, IntVal, Ip, Lower, LowerFirst, Regex, Remove, Replace, Special, SpecialFull, StringVal, StringValLegacy, Striptags, Trim, Upper, UpperFirst, UpperWords, and Url) now implement the Phalcon\\Contracts\\Filter\\Sanitizer interface and use the \_\_invoke method. This change standardizes how sanitizers are called and allows them to be used as first-class callable objects, improving consistency and flexibility when applying sanitization rules.
phalcon/Filter/Sanitize · high confidence
Session adapters refactored to use Storage adapters with Redis locking
The session adapters (Stream, Redis, Libmemcached) have been refactored to delegate storage operations to the Phalcon Storage component via an AdapterInterface, rather than managing storage directly. This change introduces a new AbstractAdapter base class and specific adapters for Redis, Libmemcached, and file-based (Stream) sessions. A key behavioral addition is support for distributed locking in the Redis adapter, configurable via options like \lockingEnabled\, \lockExpiry\, and \lockRetries\, which helps prevent race conditions during concurrent session writes. The Stream adapter now uses traits for file and path handling, and all adapters implement \SessionUpdateTimestampHandlerInterface\ to support lazy session writes.
phalcon/Session/Adapter · high confidence
Session adapters regenerated with Zephir
The C source files for the session adapter components (AbstractAdapter, Libmemcached, Noop, Redis, Stream, and their exception classes) have been regenerated using the latest Zephir compiler. This update aligns the generated PHP extension code with the current Zephir toolchain, ensuring compatibility and applying any internal compiler improvements without changing the public API or behavior of the session adapters.
ext/phalcon/session/adapter · medium confidence
Shared encoding and flag state management for HTML escapers
The HTML escaper components (HTML, Attribute, CSS, JS, and URL) now share a common trait that centralizes the management of encoding detection, normalization, and escaping flags. This change ensures consistent behavior across all escaper contexts by providing shared utilities for detecting character encoding (with special handling for specific byte sequences) and normalizing strings to UTF-32 before C-level escaping, while also exposing getters and setters for double-encoding, encoding, and flag settings.
phalcon/Html/Escaper/Traits · high confidence
Standardized repository configuration and build hygiene
The repository now includes standardized configuration files to improve developer experience and build consistency. A new \.editorconfig\ enforces consistent indentation, line endings, and character encoding across all project files. A \.dockerignore\ file ensures that unnecessary files (such as \vendor\, \build\, and IDE folders) are excluded from Docker images, reducing image size and build times. Additionally, \.gitattributes\ and \.gitignore\ have been updated to properly handle binary files, exclude generated build artifacts (like \ext/\ and \build/\), and optimize Git operations (e.g., \export-ignore\ for archives). These changes streamline local development and CI/CD workflows without altering the core framework functionality.
(repo-wide) · high confidence
Translate adapters now require an InterpolatorFactory and support strict missing-key handling
The translation adapter constructors (AbstractAdapter, Csv, Gettext, NativeArray) now require an InterpolatorFactory instance as their first argument, replacing the previous options-only signature. Additionally, the AbstractAdapter accepts a \triggerError\ option; when enabled, missing translation keys throw a KeyNotFound exception instead of falling back to the key string, giving applications strict control over undefined translations.
ext/phalcon/translate/adapter · high confidence
Validation component refactored with new abstract base classes and message template system
The Phalcon\\Filter\\Validation component has been restructured to introduce new abstract base classes, including AbstractValidator and AbstractCombinedFieldsValidator, which serve as the foundation for all validators. A key behavioral change is the introduction of a message template system: validators now support per-field templates via setTemplates(), and the getTemplate() method enforces a precedence order where explicitly assigned templates override global defaults registered via Validation::setDefaultMessages(). The allowEmpty logic has been moved into the validator base class, allowing validators to independently determine if a field should be skipped based on the allowEmpty option. Additionally, the ValidatorFactory has been updated to instantiate validators using ::class references, and the ValidatorCompositeInterface now defines the contract for combined field validators.
phalcon/Filter/Validation · high confidence
Volt compiler refactoring and exception handling improvements
The Volt template compiler has undergone significant internal refactoring, including the introduction of a \FileTrait\ for file operations, stricter type declarations, and the addition of specific exception classes (such as \CannotOpenCompiledFile\ and \CorruptedStatement\) to provide more detailed error context during compilation. The compiler's logic for handling template inheritance, block returns, and argument escaping has been corrected to ensure compatibility with PHP 8 and to fix issues with nested templates and raw slice escaping. Additionally, the compiler now supports preloading templates and allows for custom paths for Volt templates, enhancing performance and flexibility for users.
phalcon/Mvc/View/Engine/Volt · medium confidence
Volt engine regenerated with latest Zephir
The C source files for the Volt template engine have been regenerated using the latest version of Zephir. This update refreshes the underlying parser and compiler implementation, which may include bug fixes, performance improvements, and compatibility updates for the PHP runtime, while maintaining the existing Volt syntax and API surface.
ext/phalcon/mvc/view/engine/volt · medium confidence
Fixes
Added PHPStan type definitions for Container namespace
A new \ContainerTypes\ interface has been introduced to centralize PHPStan type aliases (such as \container\_aliases\, \container\_services\, and \container\_providers\) used across the Container namespace. This change improves static analysis accuracy and IDE support for developers working with the dependency injection container by providing explicit type shapes for internal data structures.
phalcon/Contracts/Container · high confidence
Test coverage
New test infrastructure for the DataMapper PDO connection
Added a suite of PHPUnit tests for the \Phalcon\\DataMapper\\Pdo\\Connection\ class, covering core lifecycle methods (connect, disconnect, auto-reconnect), transaction handling (commit, rollback), and event dispatching for operations like exec, perform, and query. The tests also include a smoke test (\MassMockTest\) to verify that mocking Phalcon classes does not cause segmentation faults, and introduce base test case classes (\AbstractDatabaseTestCase\, \AbstractStatementTestCase\) and a bootstrap script to standardize database test execution.
tests · high confidence
Dependencies
Initial Composer configuration for Phalcon PHP extension
The project now includes a \composer.json\ and \composer.lock\ file to manage its development dependencies and build process. This configuration defines the package as a PHP extension (\type: php-ext\) and sets the minimum PHP version to 8.1. It introduces a suite of development tools including \phpunit/phpunit\ (^10.5), \vimeo/psalm\ (^6.16), \phpstan/phpstan\ (^2.2), and \friendsofphp/php-cs-fixer\ (^3.95) for testing, static analysis, and code style enforcement. It also adds \phalcon/zephir\ (^1.5.0) for building the extension, \phalcon/talon\ (^1.0.0) for running test suites, and various other libraries like \predis/predis\ (^3.4) and \vlucas/phpdotenv\ (^5.6) required for the test environment. Composer scripts are defined to facilitate running unit tests, database tests (MariaDB, MySQL, PostgreSQL, SQLite), and code quality checks.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 40 → 73 (+32.7)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 73 → 100 (+26.5)
- Architecture 97 → 100 (+3.4)
- Maturity 54 → 59 (+5.1)
- Readiness 13 → 88 (+74.9)
- Security 71 → 78 (+6.7)
Resolved (5)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- No exposed public API
- No tests found
- Test reliability not included
New (17)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-DOCKER-0001 (resources/docker/develop/Dockerfile)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- No checksums published for release artifacts
- TodoComment (tests/unit/Filter/Validation/Validator/StringLength/ValidateTest.php)
Changes since last survey
- 300 commits — 296 feature/other, 4 fixes
By area
- ext/phalcon — 69 commits
- (repo) — 61 commits
- (root) — 41 commits
- tests/unit — 21 commits
- phalcon/Mvc — 20 commits
- .github/workflows — 11 commits
- tests/database — 10 commits
- phalcon/Db — 7 commits
- phalcon/Filter — 7 commits
- build/phalcon — 6 commits
- phalcon/Contracts — 6 commits
- phalcon/Auth — 5 commits
- phalcon/Annotations — 4 commits
- phalcon/Forms — 4 commits
- tests/support — 4 commits
- phalcon/Acl — 2 commits
- phalcon/Encryption — 2 commits
- phalcon/Http — 2 commits
- phalcon/Queue — 2 commits
- resources/php-cs-fixer.php — 2 commits
Notable commits
- fix: Merge pull request #17531 from phalcon/security-fixes
- fix: [CP-17444] - phpstan fixes and phalcon alignment
- fix: [CP-17447] - phpstan fixes
- fix: adding tests for hardening fixes
- change: 5.20.2 prep
- change: Adding more annotations tests
- change: Bump docker/build-push-action from 7.3.0 to 7.4.0
- change: Bump docker/build-push-action from 7.3.0 to 7.4.0
- change: Bump docker/setup-buildx-action from 4.3.0 to 4.4.1
- change: Bump docker/setup-buildx-action from 4.3.0 to 4.4.1
- change: Bump docker/setup-qemu-action from 4.2.0 to 4.3.0
- change: Bump docker/setup-qemu-action from 4.3.0 to 4.4.0
- change: Bump docker/setup-qemu-action from 4.3.0 to 4.4.0
- change: Merge branch '5.0.x' into CP-17428-alignment
- change: Merge branch '5.0.x' into CP-17446-datamapper-alignment
- change: Merge branch '5.0.x' into CP-17447-db-alignment
- change: Merge branch '5.0.x' into CP-17448-di-alignment
- change: Merge branch '5.0.x' into CP-17451-encryption-alignment
- change: Merge branch '5.0.x' into CP-17561-stream-mkdir
- change: Merge branch '5.0.x' into CP-17568-simple-current
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
phalcon/cphalcon was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6bcbc2156566b9e7a16033352f5e8902ff7f5cc5 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.