Curated reading recommendations on e-commerce architecture, Adobe Commerce/Magento, PHP and software engineering. Not a full translation: a short summary in my own words, with a link to the original source.
RSS feedSymfony Blog
·
September 30, 2026
Symfony 8.2 introduces two new security attributes, `IS_AUTHENTICATED_RECENTLY` and `IS_AUTHENTICATED_VERY_RECENTLY`, which check when the user last entered credentials, not just how they logged in. The default windows are 2 hours and 5 minutes, both configurable, and a failed check can redirect to a password-confirmation page instead of returning a 403. Users who arrived through a remember-me cookie never pass these checks, and OpenID Connect logins rely on the ID token `auth_time` claim. For a shop back office or account area (changing an email address, altering permissions, deleting an account) this delivers the familiar GitHub-style sudo mode without a third-party package.
martinfowler.com
·
September 29, 2026
Martin Fowler's short bliki entry pins down the term "sensible default": a practice you follow when no special constraint applies, and one you may depart from if you can explain why. The phrase was popularised at Thoughtworks by Evan Bottcher and is deliberately distinct from "best practice", which suggests universal validity. Version control, separating UI from domain logic and automated deployment are his examples. It is a handy frame for architecture teams: record guidelines as defaults and ask for a rationale when someone deviates, instead of banning alternatives.
Symfony Blog
·
September 25, 2026
The `messenger:consume` command gains a `--concurrency` option that lets one worker handle several messages at once through `amphp/parallel` child processes; in the authors' benchmark with 20 ms messages, a concurrency of 8 was 7.5 times faster. A new `prefetch_count` setting on the AMQP transport made consumption 13 to 18 times faster on a local broker, and rounding of delays cuts the number of delay queues by orders of magnitude. An optional `logging` middleware records processing time and memory per message, so slow handlers can be tracked on dashboards and alerts. Anyone running integration, ERP or catalog-sync queues, including in a Magento setup, can borrow the ideas.
php.net
·
September 24, 2026
On September 24, 2026 PHP shipped security releases for all four supported branches. According to the 8.5.11 changelog the fixes include an IPv6 ACL bypass in FPM `listen.allowed_clients`, OpenSSL TLS hostname verification falling back to the CN, a heap overflow triggered by a wildcard certificate, credential leakage in HTTP stream wrapper redirects, a Phar flaw and several SOAP vulnerabilities, along with many DOM, Intl and Opcache memory fixes. For anyone operating PHP it shows which components to watch and why patch-level updates should not wait; under Magento the runtime patch level has to be advanced on the hosting side.
Adobe Commerce (Experience League)
·
September 23, 2026
The September suite for the Edge Delivery-based Adobe Commerce Storefront lets shoppers pick their own free gift, adds Google Pay and PayPal Buttons, extends Apple Pay to coupon codes and supports several named wishlists. On the B2B side there is a shared company address book with role-based permissions, usable in account management, checkout and quotes. The drop-in SDK moves to 2.1.0 with a new `LiveRegion` component for screen readers, `sanitizeHtml()` helpers built on DOMPurify and better keyboard handling in cart, account and search. The release notes state it was tested with Adobe Commerce 2.4.7 through 2.4.9.
Laravel News
·
September 16, 2026
The headline of Laravel 13.32 is a Mercure broadcast driver: real-time messaging runs over SSE rather than WebSockets, with support for presence channels and encrypted private channels and matching Echo client support. It also adds `Storage::copyToDisk()` and `moveToDisk()` for moving files between disks (for example local and S3) in one call, and queue pause and resume now accept enums. The release bundles 29 commits, including Redis cache-tag expiry fixes. It is a modest release, but a useful reminder that SSE-based live updates (order status, stock levels) are a workable path without WebSocket infrastructure.
This site uses Google Analytics to measure visits. This requires your consent - see the privacy policy for details. Privacy Policy