Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork9.7k
[Security] Throw LogicException instead of Error when trying to generate logout-…#47932
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Uh oh!
There was an error while loading.Please reload this page.
Conversation
…URL without request
carsonbot commentedOct 20, 2022
Hey! I see that this is your first PR. That is great! Welcome! Symfony has acontribution guide which I suggest you to read. In short:
Review the GitHub status checks of your pull request and try to solve the reported issues. If some tests are failing, try to see if they are failing because of this change. When two Symfony core team members approve this change, it will be merged and you will become an official Symfony contributor! I am going to sit back now and wait for the reviews. Cheers! Carsonbot |
fabpot commentedOct 20, 2022
Thank you@addiks. |
nicolas-grekas commentedOct 26, 2022
For cross-ref, the empty-stack issue has been fixed in#47857 |
…URL without request
Currently the LogoutUrlGenerator will raise an Error if called without a current request present because it does not check if there is a request present before using it.
The error that is raised is:
Call to a member function getBaseUrl() on nullon line 110 (line 114 with this patch applied)In my use-case, this get's called by
Symfony\Bundle\SecurityBundle\DataCollector\SecurityDataCollector::collect()using the following code:The above code inside the
SecurityDataCollectortries to "fail silently" if no logout-URL cannot be generated. But this silent-fail fails itself because the thrown "exception" is not an\Exception, but an\Errorinstead (\Erroris not an descendant of\Exception, so it does not get catched here).In order to resolve this situation, the proposed patch makes the LogoutUrlGenerator explicitly test if a request is actually present and then throw a
\LogicExceptioninstead of an\Errorif that check fails.