> This page is for Applications Protection.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.humansecurity.com/llms.txt.

# Changelog

## July 5, 2026

## Version 4.1.1

### Added

* Support Regex configuration for sensitive route
* Added `orig_cookie_vid` field across all Enforcer activities

## January 29, 2026

## Version 4.1.0

### Added

* Support for Cross-Tab Session (CTS) extraction from `pxcts` cookie
* Support for JWT-based User Identifiers extraction from cookies or headers

### Fixed

* Decoded cookie (`px_cookie`) now included in risk API request for sensitive route calls
* Decoded cookie (`px_cookie`) now included in block activities when a valid cookie exists

## November 16, 2025

## Version 4.0.1

### Changed

* Updated composer requirements for psr/log dependency

## November 3, 2025

## Version 4.0.0

### Changed

* Updated minimum PHP version from 5.5 to 7.2.5
* Updated Guzzle HTTP client from 6.0 to 7.0

### Fixed

* Removed `<script>` tags from test fixture that caused "headers already sent" errors in unit tests

## September 11, 2024

## Version 3.10.2

### Fixed

* Bug that caused custom parameters not to be added to async activities

## December 6, 2022

## Version 3.10.1

### Fixed

* Bug in block page challenge rendering on 3rd party configuration

## August 25, 2022

## Version 3.10.0

### Added

* Support for first party
* Support for CI V2 hashing protocol

### Fixed

* Bug in client IP extraction feature

## April 11, 2022

## Version 3.9.1

### Fixed

* URLs with query params did not render properly on new block page

## Version 3.9.0

### Added

* Custom logo added to JSON block response

### Changed

* Updated block page to use new template

## February 8, 2022

## Version 3.8.0

### Added

* Support for credentials intelligence protocols `v1` and `multistep_sso`
* Support for login successful reporting methods `header`, `status`, and `custom`
* Support for automatic sending of `additional_s2s` activity
* Support for manual sending of `additional_s2s` activity via header or API call
* Support for sending raw username on `additional_s2s` activity
* New `request_id` field to all Enforcer activities

### Changed

* Login credentials extraction handles body encoding based on `Content-Type` request header
* Successful login credentials extraction automatically triggers risk\_api call without needing to enable sensitive routes

## February 3, 2022

## Version 3.7.8

### Fixed

* Minor index not found verbosity error fixed

## January 11, 2022

## Version 3.7.7

### Added

* Added default cookie origin on context creation

## January 7, 2022

## Version 3.7.6

### Fixed

* Bug with sensitive routes on mobile

### Added

* Sending graphql operation type and name on activities

## December 22, 2021

## Version 3.7.5

### Fixed

* Allows extraction of login credentials via a custom static class method

## December 20, 2021

## Version 3.7.4

### Added

* Option to extract login credentials via custom callback function

## December 14, 2021

## Version 3.7.3

### Fixed

* HMAC validation failed bug

### Added

* Compromised credentials header support

## August 3, 2021

## Version 3.7.2

### Fixed

* sanitize PXHD before setting cookie
* cookieOrigin value set when appropriate
* tweaked async activities to match spec

## June 16, 2021

## Version 3.7.1

### Fixed

* hostUrl typo in `handleVerification()`

## June 13, 2021

## Version 3.7.0

### Added

* Support for advanced blocking response
* Support for return response

### Fixed

* Minor bugs (lowercase headers, nonexistent `is_iterable` function in PHP \<7.0)

## May 11, 2021

## Version 3.6.0

### Added

* Support for login credentials extraction feature
* New s2s\_error pass reason in activities
* Detailed s2s\_error information

## March 11, 2021

## Version 3.5.4

### Fixed

* Updated deprecated syntax.

_Showing the 20 most recent of 46 entries. Append `/llms.txt` to the changelog URL for the complete index._