From 4aca5c7942d1fb04458a6be6fa0a3f474f9ced30 Mon Sep 17 00:00:00 2001 From: Mathieu Santostefano Date: Fri, 4 Sep 2026 19:53:02 +0200 Subject: [PATCH] [symfony/security-bundle] Import the OIDC login routes (#1569) --- .../8.2/config/packages/security.yaml | 39 +++++++++++++++++++ .../8.2/config/routes/security.yaml | 7 ++++ symfony/security-bundle/8.2/manifest.json | 9 +++++ 3 files changed, 55 insertions(+) create mode 100644 symfony/security-bundle/8.2/config/packages/security.yaml create mode 100644 symfony/security-bundle/8.2/config/routes/security.yaml create mode 100644 symfony/security-bundle/8.2/manifest.json diff --git a/symfony/security-bundle/8.2/config/packages/security.yaml b/symfony/security-bundle/8.2/config/packages/security.yaml new file mode 100644 index 00000000..89640445 --- /dev/null +++ b/symfony/security-bundle/8.2/config/packages/security.yaml @@ -0,0 +1,39 @@ +security: + # https://symfony.com/doc/current/security.html#registering-the-user-hashing-passwords + password_hashers: + Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface: 'auto' + + # https://symfony.com/doc/current/security.html#loading-the-user-the-user-provider + providers: + users_in_memory: { memory: null } + + firewalls: + dev: + # Ensure dev tools and static assets are always allowed + pattern: ^/(_profiler|_wdt|assets|build)/ + security: false + main: + lazy: true + provider: users_in_memory + + # Activate different ways to authenticate: + # https://symfony.com/doc/current/security.html#the-firewall + + # https://symfony.com/doc/current/security/impersonating_user.html + # switch_user: true + + # Note: Only the *first* matching rule is applied + access_control: + # - { path: ^/admin, roles: ROLE_ADMIN } + # - { path: ^/profile, roles: ROLE_USER } + +when@test: + security: + password_hashers: + # Password hashers are resource-intensive by design to ensure security. + # In tests, it's safe to reduce their cost to improve performance. + Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface: + algorithm: auto + cost: 4 # Lowest possible value for bcrypt + time_cost: 3 # Lowest possible value for argon + memory_cost: 10 # Lowest possible value for argon diff --git a/symfony/security-bundle/8.2/config/routes/security.yaml b/symfony/security-bundle/8.2/config/routes/security.yaml new file mode 100644 index 00000000..cc2fd75f --- /dev/null +++ b/symfony/security-bundle/8.2/config/routes/security.yaml @@ -0,0 +1,7 @@ +_security_logout: + resource: security.route_loader.logout + type: service + +_security_oidc_login: + resource: security.authenticator.oidc_login.route_loader + type: service diff --git a/symfony/security-bundle/8.2/manifest.json b/symfony/security-bundle/8.2/manifest.json new file mode 100644 index 00000000..5d8527e4 --- /dev/null +++ b/symfony/security-bundle/8.2/manifest.json @@ -0,0 +1,9 @@ +{ + "bundles": { + "Symfony\\Bundle\\SecurityBundle\\SecurityBundle": ["all"] + }, + "copy-from-recipe": { + "config/": "%CONFIG_DIR%/" + }, + "aliases": ["security"] +}