Repository navigation
Conversation
- Move the Mercure JWT keys into an `issuer` block (configurable with `MERCURE_TRUSTED_ISSUERS`), as `publisher_jwt`/`subscriber_jwt` are now rejected outside of compatibility mode - Enable `protocol_version_compatibility 8` so tokens issued by MercureBundle's default "0.x" protocol version keep working - Replace the removed `demo` directive with `playground` in dev - Use the `match` subscribe parameter in CI
2a10c93 to
9c9c8d6
Compare
Mercure 1.0 allows only one unnamed hub per configuration, but the
default SERVER_NAME ("localhost, php:80") creates two servers, each
with its own mercure handler. Naming the hub also makes both servers
share the same transport, so updates published through http://php
reach subscribers on https://localhost.
|
It doesn't work in Firefox. https://localhost shows SEC_ERROR_BAD_SIGNATURE |
|
I will check that, mine is working fine on Firefox but i'm using a custom TLD rather than |
- dunglas/symfony-docker#969 を取り込み - issuer / protocol_version_compatibility 導入と demo→playground、CI の match 対応 Co-authored-by: Cursor <cursoragent@cursor.com>
|
@akerbel If you added the certificate authority to your local machine's certificate store as described in the docs/tls.md, that is likely the root cause of the error! Firefox still trusts the root of a previous Caddy local CA. When the caddy_data volume is recreated, Caddy generates a new root with the same name, and Firefox rejects the new chain with SEC_ERROR_BAD_SIGNATURE. To fix it, remove the "Caddy Local Authority - 2026 ECC Root" entry in Firefox (Settings → Privacy & Security → View Certificates → Authorities), then trust the current root again or import it into Firefox directly. |
|
Two notes from the MercureBundle side:
resource_identifier {$MERCURE_PUBLIC_URL} |
MercureBundle 0.6 defaults to protocol version 1.0 and issues tokens with iss/aud claims. Pin the hub's resource identifier to MERCURE_PUBLIC_URL so tokens stay valid when the app publishes through http://php, and share the issuer between the app (MERCURE_JWT_ISSUER) and the hub (MERCURE_TRUSTED_ISSUERS).
|
Thanks @dunglas!
Tested locally with FrankenPHP 1.13, mercure-bundle 0.6.0 and the
This depends on symfony/recipes#1589: bundle 0.6 won't start without the |
FrankenPHP v1.13.0 embeds Mercure 1.0, which breaks the current configuration: the container fails to start.
Changes
publisher_jwt/subscriber_jwtare now a configuration error outside of compatibility mode. The keys move into anissuerblock, as in the upstream sampleCaddyfile. The trusted issuer is configurable with the newMERCURE_TRUSTED_ISSUERSenv var (defaults tohttps://localhost).name default). Mercure 1.0 allows only one unnamed hub per configuration, but the defaultSERVER_NAME(localhost, php:80) creates two servers, each with its ownmercurehandler. With the same name, both servers also share one transport, so updates published throughhttp://phpreach subscribers onhttps://localhost.defaultis the name the unnamed hub had internally, so existing data is kept.resource_identifier {$MERCURE_PUBLIC_URL}. In 1.0 mode the hub derives the expectedaudfrom each request, so tokens issued for the public URL would be rejected when the app publishes throughhttp://php.MERCURE_TRUSTED_ISSUERS(hub) andMERCURE_JWT_ISSUER(app, used by the [symfony/mercure-bundle] Use the Mercure 1.0 hub with bundle 0.5 and pin older recipes to Mercure 0.x symfony/recipes#1589 recipe) are both set fromCADDY_MERCURE_JWT_ISSUER(defaults tohttps://localhost), so the tokenissand the trusted issuer stay in sync.demodirective was removed in Mercure 1.0 and made the dev container crash-loop. It is replaced withplayground(UI now at/.well-known/mercure/debug/).matchsubscribe parameter instead oftopic.MERCURE_TRUSTED_ISSUERSandMERCURE_PUBLIC_URL.No
protocol_version_compatibility: apps must use MercureBundle ≥ 0.6, which defaults toprotocol_version: 1.0, issues tokens withiss/aud, and uses themercure_access_tokencookie in debug mode (matchingplayground).Requirements
iss/sub/client_idclaims that bundle 0.6 requires (the container fails to compile without them)Testing
Ran the new
Caddyfileagainst FrankenPHP v1.13.0 / Caddy 2.11.7, in both dev (playground) and prod modes:?match=and?topic=: 200Ran the CI steps against a copy of the branch, with the default
SERVER_NAME(localhost, php:80):http://phpreaches a subscriber onhttps://localhostRan a Symfony app on a copy of the branch, with mercure-bundle 0.6.0 and the
mercure.yamlfrom symfony/recipes#1589:http://phpsucceeds (401 withoutresource_identifier)mercure_access_tokencookie receives the update; an anonymous subscriber doesn'tThe
1-php8.5base image tag now resolves to 1.13; this config doesn't work on 1.12, so existing users needdocker compose build --pull.