| 12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061 |
- security:
- # https://symfony.com/doc/current/security.html#registering-the-user-hashing-passwords
- password_hashers:
- Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface: 'auto'
- # https://symfony.com/doc/current/security.html#loading-the-user-the-user-provider
- providers:
- # used to reload user from session & other features (e.g. switch_user)
- app_user_provider:
- entity:
- class: App\Entity\User
- property: username
- firewalls:
- dev:
- # Ensure dev tools and static assets are always allowed
- pattern: ^/(_profiler|_wdt|assets|build)/
- security: false
- main:
- lazy: true
- provider: app_user_provider
- form_login:
- login_path: app_login
- check_path: app_login
- enable_csrf: true
- logout:
- path: app_logout
- # where to redirect after logout
- # target: app_any_route
- remember_me:
- secret: '%kernel.secret%' # required
- #lifetime: 604800 # 1 week in seconds
- # by default, the feature is enabled by checking a
- # checkbox in the login form (see below), uncomment the
- # following line to always enable it.
- #always_remember_me: true
- # Activate different ways to authenticate:
- # https://symfony.com/doc/current/security.html#the-firewall
- # https://symfony.com/doc/current/security/impersonating_user.html
- # switch_user: true
- # Note: Only the *first* matching rule is applied
- access_control:
- # - { path: ^/admin, roles: ROLE_ADMIN }
- # - { path: ^/profile, roles: ROLE_USER }
- role_hierarchy:
- ROLE_ADMIN: ROLE_MODERATOR, ROLE_CONTACT
- ROLE_CONTACT: ROLE_AUTHOR
- when@test:
- security:
- password_hashers:
- # Password hashers are resource-intensive by design to ensure security.
- # In tests, it's safe to reduce their cost to improve performance.
- Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface:
- algorithm: auto
- cost: 4 # Lowest possible value for bcrypt
- time_cost: 3 # Lowest possible value for argon
- memory_cost: 10 # Lowest possible value for argon
|