Upgrade guide
All five FloCMS packages, core, API, CLI, uploader and CAPTCHA, use exact version requirements, and composer.lock records the installed versions. Use composer install for repeatable deployments and update dependencies deliberately. Upgrade one site at a time, and test before you deploy.
From 1.7.x to 1.7.5
-
Require the new core and captcha releases:
composer require hostkurd/flocms-core:2.2.2 hostkurd/flocms-captcha:1.1.0 -
Compiled templates are rebuilt automatically, because the template compiler version changed. Run
php flo optimizeafter deploying if you compile templates ahead of time. -
If your code calls the captcha's
verify()twice for the same answer, the second call now fails, because codes are single-use. Check once and keep the result, or set'single_use' => falsein the captcha configuration. Callingclear()afterverify()still works; it's just no longer needed. See captcha. -
If you renamed multi-word view folders to
views/blog_post/style and link to/blog_post, that keeps working./blog-postnow works too, with views inviews/blog-post/.
If you're on 1.7.3 or older, also follow the 1.7.4 steps below.
From 1.7.x to 1.7.4
-
Require the core security release:
composer require hostkurd/flocms-core:2.2.1 -
Optional: add the admin dashboard from 1.7.3, so
/admin/no longer answers 404 after login. Copyadmin_index()from the skeleton'scontrollers/PagesController.php, the viewviews/pages/admin_index.html, and therolesblock fromconfig/config.php. -
Check your controllers for public helper methods. Public methods on your controller or your own base controller can be reached from a URL, so make helpers
protectedorprivate. Since core 2.2.1, methods inherited fromFloCMS\Core\Controller, protected/private/static methods and magic method names answer 404.
From 1.6 to 1.7
-
Composer. In
composer.json, require"hostkurd/flocms-cli": "2.0.1"and"hostkurd/flocms-api": "1.2.0", add"App\\Commands\\": "commands/"toautoload.psr-4, and runcomposer update. -
Launcher. Replace the root
flofile with this one, a one-time step:#!/usr/bin/env php <?php require __DIR__ . '/vendor/autoload.php'; exit(FloCMS\CLI\Kernel::handle(__DIR__, $argv));Then delete
support/KeyGenerator.php. -
Maintenance mode. Copy
includes/maintenance.phpandtemplates/default/errors/503.html, and the maintenance lines ofpublic/index.phpandpublic/api.php. -
Optional.
- Copy
commands/LoginUnlockCommand.phpand theunlockIp()method ofsupport/LoginThrottle.php. - Copy
config/schedule.phpand add the cron job.
- Copy
-
Check. Run
php flo doctorandphp flo migrate. The API tables are only recorded when they already exist.
Note
Sites created before 1.6 follow the same steps. Until the flo file is replaced, composer update gives them flocms-cli 1.0.5, and its "command not found" message points to these steps.
After upgrading
- Run
php flo env:checkto find new.envkeys. - Run
php flo view:clearso templates are compiled again. - Read the release notes for what changed.
Moving older API code
FloCMS\Core\Api and FloCMS\Core\ApiController are deprecated. The API package also supplies FloCMS\Api\Legacy\LegacyApiController as a compatibility bridge, but new endpoints should use FloCMS\Api\Controller.
- Move handlers into
api/Controllers/with theApp\Api\Controllersnamespace. - Declare each HTTP method/path in
api/routes.php, with authentication and rate limits where needed. - Replace global input/query access with the handler's
Requestargument. Positional page parameters become named API route parameters. - Return
Responseobjects or resources rather than echoing JSON and exiting. Use the controller helpers for the response envelope. - Test clients against the
/api/v1URLs, response bodies and status codes, then leaveLEGACY_API=false.
Keeping a compatibility class does not configure explicit routes, middleware or authorization for you. See building an API.