- Initialize nonce of HTTP authenticator only when needed to omit creating unnecessairy sessions
- catch exception when retrieving user when handling exceptions
- ignore permission protection for requests without a route
- Added enabled paths to the HTTP authenticator. This can be used to enable this authenticator only for the API for example.
- composer.json for 1.0