Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

SymfonyCasts

Symfony Security: Going Further

via SymfonyCasts

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates

You've got login working, users have roles, and your app is protected. Nice! Now let's dig into some of the extra tools and techniques that can make your Symfony security system more flexible, polished and secure.

In this course, we'll build on the fundamentals from Symfony Security: The Basics and tackle the kinds of security problems that show up in real applications.

Here's what we'll cover:

  • Creating a super-admin voter that can override other permissions
  • Adding "sudo mode" to require a fresh, full authentication for sensitive actions
  • Customizing authentication error messages
  • Redirecting users after login with _target_path
  • Returning a 404 instead of a 403 with #[IsGranted]
  • Letting users log in with either their username or email address
  • Creating a custom voter to control who can impersonate whom
  • Rejecting compromised passwords with NotCompromisedPassword
  • Building logout forms with the new logout_form() helper
  • Hardening user impersonation with Symfony 8.2
  • Rate limiting registration with #[RateLimit]

Along the way, we'll see how to customize Symfony Security without fighting the framework, and how a few small changes can make authentication and authorization safer and nicer for your users.

Let's level up our security!

Syllabus

  • Returning a 404 Instead of 403 with IsGranted
  • Disabling Users with a Custom UserChecker
  • Forcing Logout on Disabled Users
  • Customizing Authentication Error Messages
  • Sudo Mode: Requiring Full Authentication
  • Creating a Super Admin Voter
  • Redirecting After Login with _target_path
  • Logging in with a Username or Email
  • Restricting Impersonation with a Voter
  • Blocking Compromised Passwords
  • Rate Limiting Registration with RateLimit (8.1)
  • Rendering a Logout Form with logout_form() (8.2)
  • Hardening Impersonation with POST & CSRF (8.2)
  • Deauthenticating with CheckRefreshedUserEvent (8.2)

Taught by

Kevin Bond

Reviews

Start your review of Symfony Security: Going Further

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.