Security is one of those things every app needs... but firewalls, authenticators, users, roles, voters and all the other pieces can feel like a lot. Let's make sense of it!
We'll start by getting a user logged in, then work our way through authentication, authorization and the tools Symfony gives us to secure a real application.
Here's what we'll tackle:
- Installing and configuring Symfony's Security system
- Creating the User class and loading users from the database
- Building a login form and understanding password hashing
- Accessing the logged-in user and adding login/logout links
- Protecting logout with CSRF
- Keeping users logged in with "remember me"
- Authentication attributes like IS_AUTHENTICATED_FULLY
- Roles, role hierarchy and access_control
- Fetching the current user from controllers and services
- Creating custom voters for object-level permissions
- Impersonating users with switch_user and safely exiting impersonation
- Limiting login attempts
- Hooking into security events
- Building a registration form
Along the way, we'll peek behind the scenes so you understand not just how to configure Symfony Security, but how all of these pieces fit together.
Let's secure some stuff!