Sulu releases 2.6.27 and 3.0.10: guided two-factor setup, cache invalidation, and Symfony 8 bundles
We have published two new patch releases: 2.6.27 and 3.0.10. Both add a guided setup for forced two-factor authentication, a faster publishing step on installations with many references, and language marks for text parts in the editor. Sulu 3.0.10 also makes pages refresh in the HTTP cache when the content they show changes, and fixes several content issues. The Sulu bundles for 3.0 now allow Symfony 8.
Guided setup for forced two-factor authentication
Sulu can require two-factor authentication for all users that match a pattern. Until now, users affected by this requirement were automatically assigned the email method. With the new setup option, they can choose from the available two-factor methods instead. A matching user without a working method gets an overlay right after the login. It cannot be closed, lists the enabled methods and guides the user through the setup of the chosen one. The option is off by default. Projects with the email method installed see no change, and without it the guided setup turns itself on when forcing is enabled.
# config/packages/sulu_security.yaml
sulu_security:
two_factor:
force:
enabled: true
pattern: '(.+)'
setup: trueWhile a user has not finished the setup, the admin API refuses all other requests, including those of technical API users. Both releases describe this in UPGRADE-2.x.md and UPGRADE-3.x.md.
Faster publishing with many references
Publishing a page or article cleans up the references it held before, and that lookup had no database index. On installations with many references, for example after a content migration, every publish scanned the whole table. Both releases add the missing index. Update your database schema, or create the index by hand as described in the upgrade notes.
Pages refresh in the HTTP cache in Sulu 3.0.10
When an editor changed a tag, a category, a contact or an account, the pages showing it stayed in the HTTP cache until their cache lifetime expired. The tags added to a page and the tags used to invalidate it did not match. They match now, and more things are tagged, such as teasers, links to media, Smart Content items, image maps and snippet areas. Collections refresh their pages when they change as well.
Clear the HTTP cache once after the upgrade, because pages cached before do not have the new tags. Projects that add their own cache tags, or extend the teaser providers and a few related services, need to adjust their code. The details are in UPGRADE-3.x.md.
Content fixes in Sulu 3.0.10
A page whose only teaser points at a deleted page no longer fails with an error. Commands and background workers that read a page in one language and save it in another no longer fail with a duplicate route. The SEO values of a page that has none saved yet are now available in templates, contributed by hual7, and teasers fall back to the page title when the excerpt title is empty, contributed by Roshan931.
Amoifr contributed two more fixes. The homepage of a portal with a language prefix redirects /de/ to /de, as all other pages already did. And reloading the preview keeps what the editor changed instead of showing the last saved version.
Symfony 8 for the Sulu bundles
Sulu 3.0.9 added Symfony 8 to the core. Since then, the bundles for Sulu 3.0 have followed. These releases allow Symfony 8:
The Symfony 8 changes of the Community, Comment, Headless and Theme bundles were contributed by Amoifr, those of the Automation and Redirect bundles by benr77 and those of the Form bundle by mamazu.
Fixes for editors
Editors can now mark the language of a text part. A new dropdown in the rich text editor tags the selected text with a language, so screen readers pronounce foreign-language passages correctly. This helps projects meet the WCAG 2.2 AA requirement for identifying the language of parts. The dropdown offers the languages of your webspaces, and you can replace that list in the configuration.
A mandatory field such as a text editor or a color now rejects an empty value. Existing content that has such a field empty cannot be saved until it is filled in.
Both releases also fix several smaller issues. Select filters keep their checked options after a reload, contributed by TheCadien, and the collection selection shows all collections instead of the first ten, contributed by MarkusHolstein. Amoifr contributed three more: changing the template of a form that has not been saved yet no longer crashes it, a media title of 0 is kept, and a link to a page of the external link type returns the external URL.
Check your roles. In Sulu 3.0.10, creating a page and copying require the add permission, and publishing, unpublishing and removing a draft require the live permission. In Sulu 2.6.27, copying a page or snippet requires the add permission. Without it, the request is refused.
For the full changelog, see the release notes for Sulu 2.6.27 and Sulu 3.0.10.
What is next?
We continue to improve Sulu 3.0 while keeping Sulu 2.6 stable for existing projects. Looking ahead, Sulu 3.1 is coming soon, with workflow transition requests and notifications for content events among its new features.
Your feedback helps shape these releases. Report bugs or request features on GitHub, connect with us on Slack, or reach out through our website. We're listening.
