🔐 Symfony Security Basics #11
Our User class is a Doctrine entity, which means it can have normal Doctrine relationships. Let's add one and use it to personalize our application. https://t.co/K3MFZNhC45
TailwindBundle 1.0 is here! :tada:
Add Tailwind CSS to your Symfony + AssetMapper app, with no Node required.
A huge thank you to everyone who contributed, reported issues, and helped us reach 1.0!
Check out the release:
https://t.co/k4mu4lqZc8
🔐 Symfony Security Basics #10
Why assign users five roles when one will do? Let's use Symfony's role hierarchy to inherit permissions, then secure an entire admin section with `access_control`. https://t.co/vppSv7rLnD
🔐 Symfony Security Basics #9
Let's compare a few different ways to protect a page with a custom user role. Then we'll follow the login flow to access it and fix a sneaky Turbo gotcha along the way! https://t.co/aiMIvvJOxv
🔐 Symfony Security Basics #8
A remembered login isn't the same as a fresh login. Let's explore Symfony's authentication attributes and see how they can help protect sensitive actions. https://t.co/jvNeeb5ihs
Let's take a tour through the internals of Brontie, our AI assistant, we'll take a peek into how it actually works inside SymfonyCasts! 🦕 🤖
https://t.co/cbJmCW0PZ0
🔐 Symfony Security Basics #7
We're using session-based authentication, so let's take a peek behind the curtain to see how it works. Then we'll enable Symfony's "Remember Me" feature so users don't need to log in every time they reopen their browser. https://t.co/w4gesBfNbw
Encryption is a locked box 🔐
Hashing is a fingerprint 👆
One is designed to be opened later.
The other is designed to never reveal the original value.
-- A poem from the SymfonyCasts team
https://t.co/lqzk7n67Ec
🔐 Symfony Security Basics #6
Let’s see why using a simple link for logout is a bad idea. We’ll look at the reason GET requests should never change application state, then secure our logout flow with POST and CSRF protection. https://t.co/3NHNmbQNNT
Upgrading to Symfony 8 #6 (Bonus)
AI is changing security research, and that means more vulnerabilities are being found and fixed than ever before. Let's explore "composer audit", CVEs, and how to automate dependency security checks. https://t.co/I7q9oiwXTi
🔐 Symfony Security Basics #5 Time to improve our user experience! We'll detect whether someone is logged in, show the appropriate login/logout links, and learn a handy trick for generating logout URLs.
https://t.co/LWTttmdcxq
🔐 Symfony Security Basics #4
Hashing and encryption are very different things. We'll compare them, & see how Symfony automatically chooses the best password hashing algorithm and transparently upgrades your users as better algorithms become available. https://t.co/alDaHLiiuU
I've been thinking about this for years.
Most Symfony best practices encourage code that's explicit and hard to misuse. Doctrine entities have always felt like a strange exception.
There are reasons we do it this way... but I think ObjectMapper changes the equation.
🤔 Your #Doctrine entities are lying to you. Or at least... they might be. We've spent years making required properties nullable so entities can double as form models. #Symfony's new ObjectMapper component has me wondering if there's a better way.
https://t.co/QIphv0vNnG
🔐 Symfony Security Basics #3
Time to log in! We'll generate a login form with MakerBundle, see how Symfony's built-in form authenticator works, explore the generated code, and take a peek at the CSRF protection that's keeping us safe. https://t.co/tFTiHVqkBJ
Need clarification on a SymfonyCasts lesson without waiting for a reply?
Meet Brontie 🦕, our new AI companion that understands the course and chapter you're currently watching.
Read more about Brontie and why we built it: https://t.co/Eja6Qa9oB5
🔐 Symfony Security Basics #2
In order for users to log in, we need a user object and a user provider. Let’s build the most common implementation: a database-backed user/provider + a user factory to quickly spin them up in our dev & test environments. https://t.co/M7ur0IoJ3m
🚨 New course 🚨
🔐 Symfony Security Basics #1
Symfony Security is the gatekeeper of your application. We'll install the Security component, explore the default configuration, talk firewalls, & learn the difference between authentication & authorization. https://t.co/bQxy9tRhWv
Thanks, #SymfonyDay Montreal!
We had a great time at the @SymfonyCasts booth meeting members of the community and talking #Symfony.
Also pictured: future #Symfony developers?! Maybe someday they'll finally get my 10-year-old Doctrine ORM PR merged. 🙃🤪🤞