Tags: dereuromark/cakephp-menu
Tags
Bump dompurify from 3.4.13 to 3.4.16 in /docs (#39) Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.13 to 3.4.16. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.13...3.4.16) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.16 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Fix Bootstrap5 renderer defaults, dropdown toggles and resolver arity (… …#38) - Bootstrap5Renderer redeclared its default config and lost the parent's defaults, so addHeader() threw "Cannot find template named header". It now extends the parent defaults and renders dropdown headers as h6.dropdown-header. NavbarRenderer inherits the fix. - A branch without a link (or an active branch with currentAsLink=false) rendered a plain span, so the dropdown could not be opened. Branches now always render as a toggle. - Branches cut off by the depth option no longer get dropdown toggles or branch classes, and hideEmptyBranches uses the same depth-aware check. - Menu::fromArray() with external=true and no linkAttributes no longer raises an undefined array key warning. - PermissionResolver no longer counts a trailing variadic parameter, so authorizers like AuthorizationService::can() get three arguments instead of having the context pushed into their variadic.
Fix UrlArrayResolver prefix matching on routed requests (#36) * Fix UrlArrayResolver prefix matching on routed requests A non-prefixed route reports no `prefix` key in its parsed params, while a link with `prefix => false` normalizes to `prefix => null`. The fuzzy intersect check dropped the key and never matched, so links had to omit the prefix entirely, which in turn made them active on prefixed pages. Requests now default `prefix` to null, like `_ext`. Exact matching also never matched a routed request: Cake names every unnamed route automatically (`admin:_controller:_action`), which ended up in the request's `_name`. It is now ignored unless the link sets `_name`, the same as `_host` and `_method`. The new tests parse real URLs through the router; the existing ones built params by hand and could not see either case. * Fix PHPStan 2.2 findings Keep the separate null-coalescing assignments in extractParams(): the array union lost the known '?' offset. The cache test counted builds through a by-reference closure variable, which PHPStan 2.2 narrows to the constant 1; a test property is re-read after each method call. * Reorder native union types for updated sniffer php-collective/code-sniffer now enforces a canonical order for native type hints. Automated phpcbf fix, no behavior change. * Keep query values out of routing segments in exact matching Defaulting the request prefix to null stopped a ?prefix= query value from being promoted onto the request, while the link side still promoted it, so identical URLs no longer matched. Null routing values are now folded before the query is promoted, and query values are never promoted onto plugin, prefix or _ext on either side; they are still compared through the ? bucket. The request plugin is defaulted to null like prefix and _ext, so hand-built params behave the same.