Skip to content

Hotfix 1.2.3: add app:apikeys:add command - #63

Merged
turegjorup merged 7 commits into
mainfrom
hotfix/1.2.3
Oct 7, 2026
Merged

turegjorup merged 7 commits into
mainfrom
hotfix/1.2.3

Conversation

@turegjorup

@turegjorup turegjorup commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Hotfix 1.2.3: add an app:apikeys:add console command that generates an API key for a user and writes it to .env.local.

Changes

  • New app:apikeys:add [<username>] command (src/Command/ApiKeysAddCommand.php):
    • Prompts for the username (QuestionHelper) when omitted; fails without it under --no-interaction.
    • Reads APP_API_KEYS from .env.local (Symfony Dotenv parser, so the multi-line format from the README works) and refuses duplicate usernames.
    • Generates a key with bin2hex(random_bytes(32)), rewrites only the APP_API_KEYS line (or appends it), and prints the key.
    • Writes .env.local.temp (exclusive create, so a leftover file or a concurrent run fails), reads it back and verifies the keys, then copies .env.local to .env.local.backup and atomically renames the temp file over .env.local. File permissions are preserved and .env.local is never touched if anything fails.
    • Offers to delete the backup afterwards (default yes). Refuses to run while .env.local.backup exists, or if .env.local is a symlink.
    • If .env.local.php exists, warns that composer dump-env prod must be run for the key to take effect, plus an extra warning when its APP_API_KEYS differs from .env.local. It only advises; it never runs the dump.
  • Command tests in tests/Command/ApiKeysAddCommandTest.php.
  • .gitignore entries for .env.local.temp and .env.local.backup.
  • README section on generating keys.

Why

There is no self-service registration, so API keys are hand-written JSON in .env.local. The command removes the manual editing and key generation. ApiUserProvider, the authenticator and the config are unchanged, and %env()% is resolved at runtime, so a new key works on the next request without a cache clear.

Targets main as a gitflow hotfix so it can ship ahead of Release 1.3.0 (#62). It only adds new files, so merging back to develop should conflict only in CHANGELOG.md.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

✅ No changes detected in API specification

@turegjorup turegjorup self-assigned this Oct 7, 2026
@turegjorup
turegjorup merged commit c127140 into main Oct 7, 2026
10 of 11 checks passed
@turegjorup
turegjorup deleted the hotfix/1.2.3 branch October 7, 2026 08:13
This was referenced Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant