3 All notable changes to this project will be documented in this file, in reverse chronological order by release.
9 - [#219](https://github.com/zendframework/zend-diactoros/pull/219) adds two new
10 classes, `Zend\Diactoros\Request\ArraySerializer` and
11 `Zend\Diactoros\Response\ArraySerializer`. Each exposes the static methods
12 `toArray()` and `fromArray()`, allowing de/serialization of messages from and
15 - [#236](https://github.com/zendframework/zend-diactoros/pull/236) adds two new
16 constants to the `Response` class: `MIN_STATUS_CODE_VALUE` and
17 `MAX_STATUS_CODE_VALUE`.
21 - [#240](https://github.com/zendframework/zend-diactoros/pull/240) changes the
22 behavior of `ServerRequestFactory::fromGlobals()` when no `$cookies` argument
23 is present. Previously, it would use `$_COOKIES`; now, if a `Cookie` header is
24 present, it will parse and use that to populate the instance instead.
26 This change allows utilizing cookies that contain period characters (`.`) in
27 their names (PHP's built-in cookie handling renames these to replace `.` with
28 `_`, which can lead to synchronization issues with clients).
30 - [#235](https://github.com/zendframework/zend-diactoros/pull/235) changes the
31 behavior of `Uri::__toString()` to better follow proscribed behavior in PSR-7.
32 In particular, prior to this release, if a scheme was missing but an authority
33 was present, the class was incorrectly returning a value that did not include
34 a `//` prefix. As of this release, it now does this correctly.
48 ## 1.3.11 - 2017-04-06
56 - [#241](https://github.com/zendframework/zend-diactoros/pull/241) changes the
57 constraint by which the package provides `psr/http-message-implementation` to
58 simply `1.0` instead of `~1.0.0`, to follow how other implementations provide
71 - [#161](https://github.com/zendframework/zend-diactoros/pull/161) adds
72 additional validations to header names and values to ensure no malformed values
75 - [#234](https://github.com/zendframework/zend-diactoros/pull/234) fixes a
76 number of reason phrases in the `Response` instance, and adds automation from
77 the canonical IANA sources to ensure any new phrases added are correct.
79 ## 1.3.10 - 2017-01-23
95 - [#226](https://github.com/zendframework/zend-diactoros/pull/226) fixed an
96 issue with the `SapiStreamEmitter` causing the response body to be cast
97 to `(string)` and also be read as a readable stream, potentially producing
100 ## 1.3.9 - 2017-01-17
116 - [#223](https://github.com/zendframework/zend-diactoros/issues/223)
117 [#224](https://github.com/zendframework/zend-diactoros/pull/224) fixed an issue
118 with the `SapiStreamEmitter` consuming too much memory when producing output
121 ## 1.3.8 - 2017-01-05
137 - [#222](https://github.com/zendframework/zend-diactoros/pull/222) fixes the
138 `SapiStreamEmitter`'s handling of the `Content-Range` header to properly only
139 emit a range of bytes if the header value is in the form `bytes {first-last}/length`.
140 This allows using other range units, such as `items`, without incorrectly
141 emitting truncated content.
143 ## 1.3.7 - 2016-10-11
147 - [#208](https://github.com/zendframework/zend-diactoros/pull/208) adds several
148 missing response codes to `Zend\Diactoros\Response`, including:
150 - 308 ('Permanent Redirect')
151 - 444 ('Connection Closed Without Response')
152 - 499 ('Client Closed Request')
153 - 510 ('Not Extended')
154 - 599 ('Network Connect Timeout Error')
155 - [#211](https://github.com/zendframework/zend-diactoros/pull/211) adds support
156 for UTF-8 characters in query strings handled by `Zend\Diactoros\Uri`.
170 ## 1.3.6 - 2016-09-07
174 - [#170](https://github.com/zendframework/zend-diactoros/pull/170) prepared
175 documentation for publication at https://zendframework.github.io/zend-diactoros/
176 - [#165](https://github.com/zendframework/zend-diactoros/pull/165) adds support
177 for Apache `REDIRECT_HTTP_*` header detection in the `ServerRequestFactory`.
178 - [#166](https://github.com/zendframework/zend-diactoros/pull/166) adds support
179 for UTF-8 characters in URI paths.
180 - [#204](https://github.com/zendframework/zend-diactoros/pull/204) adds testing
181 against PHP 7.1 release-candidate builds.
193 - [#186](https://github.com/zendframework/zend-diactoros/pull/186) fixes a typo
194 in a variable name within the `SapiStreamEmitter`.
195 - [#200](https://github.com/zendframework/zend-diactoros/pull/200) updates the
196 `SapiStreamEmitter` to implement a check for `isSeekable()` prior to attempts
197 to rewind; this allows it to work with non-seekable streams such as the
199 - [#169](https://github.com/zendframework/zend-diactoros/pull/169) ensures that
200 response serialization always provides a `\r\n\r\n` sequence following the
201 headers, even when no message body is present, to ensure it conforms with RFC
203 - [#175](https://github.com/zendframework/zend-diactoros/pull/175) updates the
204 `Request` class to set the `Host` header from the URI host if no header is
205 already present. (Ensures conformity with PSR-7 specification.)
206 - [#197](https://github.com/zendframework/zend-diactoros/pull/197) updates the
207 `Uri` class to ensure that string serialization does not include a colon after
208 the host name if no port is present in the instance.
210 ## 1.3.5 - 2016-03-17
226 - [#160](https://github.com/zendframework/zend-diactoros/pull/160) fixes HTTP
227 protocol detection in the `ServerRequestFactory` to work correctly with HTTP/2.
229 ## 1.3.4 - 2016-03-17
233 - [#119](https://github.com/zendframework/zend-diactoros/pull/119) adds the 451
234 (Unavailable for Legal Reasons) status code to the `Response` class.
246 - [#117](https://github.com/zendframework/zend-diactoros/pull/117) provides
247 validation of the HTTP protocol version.
248 - [#127](https://github.com/zendframework/zend-diactoros/pull/127) now properly
249 removes attributes with `null` values when calling `withoutAttribute()`.
250 - [#132](https://github.com/zendframework/zend-diactoros/pull/132) updates the
251 `ServerRequestFactory` to marshal the request path fragment, if present.
252 - [#142](https://github.com/zendframework/zend-diactoros/pull/142) updates the
253 exceptions thrown by `HeaderSecurity` to include the header name and/or
255 - [#148](https://github.com/zendframework/zend-diactoros/pull/148) fixes several
256 stream operations to ensure they raise exceptions when the internal pointer
257 is at an invalid position.
258 - [#151](https://github.com/zendframework/zend-diactoros/pull/151) ensures
259 URI fragments are properly encoded.
261 ## 1.3.3 - 2016-01-04
277 - [#135](https://github.com/zendframework/zend-diactoros/pull/135) fixes the
278 behavior of `ServerRequestFactory::marshalHeaders()` to no longer omit
279 `Cookie` headers from the aggregated headers. While the values are parsed and
280 injected into the cookie params, it's useful to have access to the raw headers
283 ## 1.3.2 - 2015-12-22
287 - [#124](https://github.com/zendframework/zend-diactoros/pull/124) adds four
288 more optional arguments to the `ServerRequest` constructor:
290 - `array $queryParams`
291 - `null|array|object $parsedBody`
292 - `string $protocolVersion`
293 `ServerRequestFactory` was updated to pass values for each of these parameters
294 when creating an instance, instead of using the related `with*()` methods on
307 - [#122](https://github.com/zendframework/zend-diactoros/pull/122) updates the
308 `ServerRequestFactory` to retrieve the HTTP protocol version and inject it in
309 the generated `ServerRequest`, which previously was not performed.
311 ## 1.3.1 - 2015-12-16
327 - [#113](https://github.com/zendframework/zend-diactoros/pull/113) fixes an
328 issue in the response serializer, ensuring that the status code in the
329 deserialized response is an integer.
330 - [#115](https://github.com/zendframework/zend-diactoros/pull/115) fixes an
331 issue in the various text-basd response types (`TextResponse`, `HtmlResponse`,
332 and `JsonResponse`); due to the fact that the constructor was not
333 rewinding the message body stream, `getContents()` was thus returning `null`,
334 as the pointer was at the end of the stream. The constructor now rewinds the
335 stream after populating it in the constructor.
337 ## 1.3.0 - 2015-12-15
341 - [#110](https://github.com/zendframework/zend-diactoros/pull/110) adds
342 `Zend\Diactoros\Response\SapiEmitterTrait`, which provides the following
343 private method definitions:
344 - `injectContentLength()`
349 The `SapiEmitter` implementation has been updated to remove those methods and
350 instead compose the trait.
351 - [#111](https://github.com/zendframework/zend-diactoros/pull/111) adds
352 a new emitter implementation, `SapiStreamEmitter`; this emitter type will
353 loop through the stream instead of emitting it in one go, and supports content
368 ## 1.2.1 - 2015-12-15
384 - [#101](https://github.com/zendframework/zend-diactoros/pull/101) fixes the
385 `withHeader()` implementation to ensure that if the header existed previously
386 but using a different casing strategy, the previous version will be removed
387 in the cloned instance.
388 - [#103](https://github.com/zendframework/zend-diactoros/pull/103) fixes the
389 constructor of `Response` to ensure that null status codes are not possible.
390 - [#99](https://github.com/zendframework/zend-diactoros/pull/99) fixes
391 validation of header values submitted via request and response constructors as
393 - numeric (integer and float) values are now properly allowed (this solves
394 some reported issues with setting Content-Length headers)
395 - invalid header names (non-string values or empty strings) now raise an
397 - invalid individual header values (non-string, non-numeric) now raise an
400 ## 1.2.0 - 2015-11-24
404 - [#88](https://github.com/zendframework/zend-diactoros/pull/88) updates the
405 `SapiEmitter` to emit a `Content-Length` header with the content length as
406 reported by the response body stream, assuming that
407 `StreamInterface::getSize()` returns an integer.
408 - [#77](https://github.com/zendframework/zend-diactoros/pull/77) adds a new
409 response type, `Zend\Diactoros\Response\TextResponse`, for returning plain
410 text responses. By default, it sets the content type to `text/plain;
411 charset=utf-8`; per the other response types, the signature is `new
412 TextResponse($text, $status = 200, array $headers = [])`.
413 - [#90](https://github.com/zendframework/zend-diactoros/pull/90) adds a new
414 `Zend\Diactoros\CallbackStream`, allowing you to back a stream with a PHP
415 callable (such as a generator) to generate the message content. Its
416 constructor accepts the callable: `$stream = new CallbackStream($callable);`
428 - [#77](https://github.com/zendframework/zend-diactoros/pull/77) updates the
429 `HtmlResponse` to set the charset to utf-8 by default (if no content type
430 header is provided at instantiation).
432 ## 1.1.4 - 2015-10-16
436 - [#98](https://github.com/zendframework/zend-diactoros/pull/98) adds
437 `JSON_UNESCAPED_SLASHES` to the default `json_encode` flags used by
438 `Zend\Diactoros\Response\JsonResponse`.
450 - [#96](https://github.com/zendframework/zend-diactoros/pull/96) updates
451 `withPort()` to allow `null` port values (indicating usage of default for
453 - [#91](https://github.com/zendframework/zend-diactoros/pull/91) fixes the
454 logic of `withUri()` to do a case-insensitive check for an existing `Host`
455 header, replacing it with the new one.
457 ## 1.1.3 - 2015-08-10
461 - [#73](https://github.com/zendframework/zend-diactoros/pull/73) adds caching of
462 the vendor directory to the Travis-CI configuration, to speed up builds.
474 - [#71](https://github.com/zendframework/zend-diactoros/pull/71) fixes the
475 docblock of the `JsonResponse` constructor to typehint the `$data` argument
477 - [#73](https://github.com/zendframework/zend-diactoros/pull/73) changes the
478 behavior in `Request` such that if it marshals a stream during instantiation,
479 the stream is marked as writeable (specifically, mode `wb+`).
480 - [#85](https://github.com/zendframework/zend-diactoros/pull/85) updates the
481 behavior of `Zend\Diactoros\Uri`'s various `with*()` methods that are
482 documented as accepting strings to raise exceptions on non-string input.
483 Previously, several simply passed non-string input on verbatim, others
484 normalized the input, and a few correctly raised the exceptions. Behavior is
485 now consistent across each.
486 - [#87](https://github.com/zendframework/zend-diactoros/pull/87) fixes
487 `UploadedFile` to ensure that `moveTo()` works correctly in non-SAPI
488 environments when the file provided to the constructor is a path.
490 ## 1.1.2 - 2015-07-12
506 - [#67](https://github.com/zendframework/zend-diactoros/pull/67) ensures that
507 the `Stream` class only accepts `stream` resources, not any resource.
509 ## 1.1.1 - 2015-06-25
525 - [#64](https://github.com/zendframework/zend-diactoros/pull/64) fixes the
526 behavior of `JsonResponse` with regards to serialization of `null` and scalar
527 values; the new behavior is to serialize them verbatim, without any casting.
529 ## 1.1.0 - 2015-06-24
533 - [#52](https://github.com/zendframework/zend-diactoros/pull/52),
534 [#58](https://github.com/zendframework/zend-diactoros/pull/58),
535 [#59](https://github.com/zendframework/zend-diactoros/pull/59), and
536 [#61](https://github.com/zendframework/zend-diactoros/pull/61) create several
537 custom response types for simplifying response creation:
539 - `Zend\Diactoros\Response\HtmlResponse` accepts HTML content via its
540 constructor, and sets the `Content-Type` to `text/html`.
541 - `Zend\Diactoros\Response\JsonResponse` accepts data to serialize to JSON via
542 its constructor, and sets the `Content-Type` to `application/json`.
543 - `Zend\Diactoros\Response\EmptyResponse` allows creating empty, read-only
544 responses, with a default status code of 204.
545 - `Zend\Diactoros\Response\RedirectResponse` allows specifying a URI for the
546 `Location` header in the constructor, with a default status code of 302.
548 Each also accepts an optional status code, and optional headers (which can
549 also be used to provide an alternate `Content-Type` in the case of the HTML
558 - [#43](https://github.com/zendframework/zend-diactoros/pull/43) removed both
559 `ServerRequestFactory::marshalUri()` and `ServerRequestFactory::marshalHostAndPort()`,
560 which were deprecated prior to the 1.0 release.
564 - [#29](https://github.com/zendframework/zend-diactoros/pull/29) fixes request
565 method validation to allow any valid token as defined by [RFC
566 7230](http://tools.ietf.org/html/rfc7230#appendix-B). This allows usage of
567 custom request methods, vs a static, hard-coded list.
569 ## 1.0.5 - 2015-06-24
585 - [#60](https://github.com/zendframework/zend-diactoros/pull/60) fixes
586 the behavior of `UploadedFile` when the `$errorStatus` provided at
587 instantiation is not `UPLOAD_ERR_OK`. Prior to the fix, an
588 `InvalidArgumentException` would occur at instantiation due to the fact that
589 the upload file was missing or invalid. With the fix, no exception is raised
590 until a call to `moveTo()` or `getStream()` is made.
592 ## 1.0.4 - 2015-06-23
594 This is a security release.
596 A patch has been applied to `Zend\Diactoros\Uri::filterPath()` that ensures that
597 paths can only begin with a single leading slash. This prevents the following
598 potential security issues:
600 - XSS vectors. If the URI path is used for links or form targets, this prevents
601 cases where the first segment of the path resembles a domain name, thus
602 creating scheme-relative links such as `//example.com/foo`. With the patch,
603 the leading double slash is reduced to a single slash, preventing the XSS
605 - Open redirects. If the URI path is used for `Location` or `Link` headers,
606 without a scheme and authority, potential for open redirects exist if clients
607 do not prepend the scheme and authority. Again, preventing a double slash
610 If you are using `Zend\Diactoros\Uri` for creating links, form targets, or
611 redirect paths, and only using the path segment, we recommend upgrading
616 - [#25](https://github.com/zendframework/zend-diactoros/pull/25) adds
617 documentation. Documentation is written in markdown, and can be converted to
618 HTML using [bookdown](http://bookdown.io). New features now MUST include
619 documentation for acceptance.
631 - [#51](https://github.com/zendframework/zend-diactoros/pull/51) fixes
632 `MessageTrait::getHeaderLine()` to return an empty string instead of `null` if
633 the header is undefined (which is the behavior specified in PSR-7).
634 - [#57](https://github.com/zendframework/zend-diactoros/pull/57) fixes the
635 behavior of how the `ServerRequestFactory` marshals upload files when they are
636 represented as a nested associative array.
637 - [#49](https://github.com/zendframework/zend-diactoros/pull/49) provides several
638 fixes that ensure that Diactoros complies with the PSR-7 specification:
639 - `MessageInterface::getHeaderLine()` MUST return a string (that string CAN be
640 empty). Previously, Diactoros would return `null`.
641 - If no `Host` header is set, the `$preserveHost` flag MUST be ignored when
642 calling `withUri()` (previously, Diactoros would not set the `Host` header
643 if `$preserveHost` was `true`, but no `Host` header was present).
644 - The request method MUST be a string; it CAN be empty. Previously, Diactoros
646 - The request MUST return a `UriInterface` instance from `getUri()`; that
647 instance CAN be empty. Previously, Diactoros would return `null`; now it
648 lazy-instantiates an empty `Uri` instance on initialization.
649 - [ZF2015-05](http://framework.zend.com/security/advisory/ZF2015-05) was
650 addressed by altering `Uri::filterPath()` to prevent emitting a path prepended
651 with multiple slashes.
653 ## 1.0.3 - 2015-06-04
657 - [#48](https://github.com/zendframework/zend-diactoros/pull/48) drops the
658 minimum supported PHP version to 5.4, to allow an easier upgrade path for
659 Symfony 2.7 users, and potential Drupal 8 usage.
673 ## 1.0.2 - 2015-06-04
677 - [#27](https://github.com/zendframework/zend-diactoros/pull/27) adds phonetic
678 pronunciation of "Diactoros" to the README file.
679 - [#36](https://github.com/zendframework/zend-diactoros/pull/36) adds property
680 annotations to the class-level docblock of `Zend\Diactoros\RequestTrait` to
681 ensure properties inherited from the `MessageTrait` are inherited by
694 - [#41](https://github.com/zendframework/zend-diactoros/pull/41) fixes the
695 namespace for test files to begin with `ZendTest` instead of `Zend`.
696 - [#46](https://github.com/zendframework/zend-diactoros/pull/46) ensures that
697 the cookie and query params for the `ServerRequest` implementation are
698 initialized as arrays.
699 - [#47](https://github.com/zendframework/zend-diactoros/pull/47) modifies the
700 internal logic in `HeaderSecurity::isValid()` to use a regular expression
701 instead of character-by-character comparisons, improving performance.
703 ## 1.0.1 - 2015-05-26
707 - [#10](https://github.com/zendframework/zend-diactoros/pull/10) adds
708 `Zend\Diactoros\RelativeStream`, which will return stream contents relative to
709 a given offset (i.e., a subset of the stream). `AbstractSerializer` was
710 updated to create a `RelativeStream` when creating the body of a message,
711 which will prevent duplication of the stream in-memory.
712 - [#21](https://github.com/zendframework/zend-diactoros/pull/21) adds a
713 `.gitattributes` file that excludes directories and files not needed for
714 production; this will further minify the package for production use cases.
726 - [#9](https://github.com/zendframework/zend-diactoros/pull/9) ensures that
727 attributes are initialized to an empty array, ensuring that attempts to
728 retrieve single attributes when none are defined will not produce errors.
729 - [#14](https://github.com/zendframework/zend-diactoros/pull/14) updates
730 `Zend\Diactoros\Request` to use a `php://temp` stream by default instead of
731 `php://memory`, to ensure requests do not create an out-of-memory condition.
732 - [#15](https://github.com/zendframework/zend-diactoros/pull/15) updates
733 `Zend\Diactoros\Stream` to ensure that write operations trigger an exception
734 if the stream is not writeable. Additionally, it adds more robust logic for
735 determining if a stream is writeable.
737 ## 1.0.0 - 2015-05-21
739 First stable release, and first release as `zend-diactoros`.