Re-pin the fluttersdk stack to the 2026-09-21 releases - #16
Conversation
Every in-house constraint names the newest release of the 2026-09-21 batch: magic ^0.0.15, magic_deeplink ^0.1.2, magic_notifications ^0.3.3, magic_social_auth ^0.0.4, magic_starter ^0.0.31, magic_devtools ^0.0.5, fluttersdk_dusk ^0.0.15, fluttersdk_telescope ^0.0.6 and fluttersdk_artisan ^0.0.16. The backend moves fluttersdk/magic-starter-laravel ^0.0.5 -> ^0.0.9. Composer's caret on 0.0.x pins the patch, so this pin had held the backend four releases behind; only that package is updated in the lock, plus the four packages 0.0.9 requires (laravel/cashier and its stripe, moneyphp and intl polyfill dependencies), not a --with-dependencies sweep.
|
Note Kodizm (AI-generated). May contain mistakes; verify before acting. Dependency-only re-pin that resolves and passes everything I ran; one stale published-config artefact of the backend jump is worth following up, nothing blocking. Minor
I verified the parts of the 0.0.5→0.0.9 jump that could have broken quietly and they are clean: the published action stubs, policies, models and vendor lang files under TestsNothing in this repo covers the backend bump specifically — Checks I ran
|
The published copy dated from 0.0.5. Config merging is shallow, so its onesignal array shadowed the package's whole block and the three keys 0.0.6 to 0.0.9 added under it (external_id_prefix, web_origin, self_test_enabled) were unreachable through config for this repo and every fork taken from it. route_middleware and billing were only present through mergeConfigFrom's top-level fallback, which is also where a fork would never look for them. Taken verbatim from vendor/fluttersdk/magic-starter-laravel 0.0.9, with this app's six lines reapplied: the Features import, use_uuids false, and the four enabled features (two-factor, teams, sessions, email verification).
|
Fixed in
Re-checked: @kodizm please re-review. |
|
Note Kodizm (AI-generated). May contain mistakes; verify before acting. The republished config in Since my last review the only change is I checked the republish rather than taking it on trust:
TestsUnchanged from my last pass — Checks I ran
|
The last step of the 2026-09-21 release batch: this boilerplate is what a fork copies, so it re-pins every in-house package to the release the batch just published.
What moves
magic^0.0.11^0.0.15magic_deeplink^0.1.0^0.1.2magic_notifications^0.3.2^0.3.3magic_social_auth^0.0.3^0.0.4magic_starter^0.0.27^0.0.31magic_devtools^0.0.4^0.0.5fluttersdk_dusk^0.0.13^0.0.15fluttersdk_telescope^0.0.5^0.0.6fluttersdk_artisan^0.0.15^0.0.16fluttersdk/magic-starter-laravel(backend)^0.0.5^0.0.9pubspec.lockresolves every one of them from pub.dev (no path source in it), plusfluttersdk_wind1.6.2 andmagic_payments0.0.3 transitively.The backend pin was a real lag, not a cosmetic one. Composer's caret on a
0.0.xversion pins the patch (^0.0.5is>=0.0.5 <0.0.6), unlike pub's, so this boilerplate's backend had been held at 0.0.5 through four releases, including the__()translations, the route middleware seam and the native-client session agent the Flutter side already reads. The lock update is scoped to that package:composer update fluttersdk/magic-starter-laravelbrings it plus the four packages 0.0.9 requires (laravel/cashier,stripe/stripe-php,moneyphp/money,symfony/polyfill-intl-icu). A--with-dependenciesrun would also have movedsymfony/console7 to 8 andphpseclib3 to 4, which is not what this PR is about.The jump crosses magic 0.0.14, which stops the app at
Magic.initwhen a route names an unregistered middleware alias. The only aliases in play areauthandguest, andlib/app/kernel.dartregisters both.Verified by running it
Against the hosted graph, with the gitignored
pubspec_overrides.yamlmoved aside so nothing resolved from a sibling checkout:flutter analyze --no-fatal-infos: no issues.flutter test: 30 passed.vendor/bin/pint --testpassed,php artisan testpassed,php artisan migrate --pretendhas nothing to run./auth/login. Registering through the UI againstphp artisan serveon the 0.0.9 backend first surfaced the backend's password rule as a field error (the 422 contract round-tripping), then signed in and landed on/with the dashboard, the personal team and the notification poll all live.One console line, not from this change:
Push identity operation failed for "user_18": OneSignal must be initialized before login, because a local web run has no OneSignal app id.magic_notifications0.3.3 differs from 0.3.2 inlib/only by its version constant, so it predates these pins.Not touched
dart format --set-exit-if-changed .reports six files onmainas well (two generated barrels among them); CI does not run the formatter here, and reformatting them does not belong in a dependency PR.