Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Security] Add support forSec-Fetch-Site toSameOriginCsrfTokenManager#62077

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
nicolas-grekas merged 1 commit intosymfony:7.4fromnicolas-grekas:sec-fetch
Oct 16, 2025

Conversation

@nicolas-grekas
Copy link
Member

QA
Branch?7.4
Bug fix?no
New feature?yes
Deprecations?no
Issues-
LicenseMIT

Thanks to@dunglas for pointing me athttps://www.alexedwards.net/blog/preventing-csrf-in-go

This check allows confirming the same-origin of the request without having to configure the X-Forwarded et al header when using a reverse-proxy.

Nice DX improvement! Browser support is almost as good as for Origin/Referer headers:https://caniuse.com/mdn-http_headers_sec-fetch-site

@nicolas-grekasnicolas-grekas merged commitad96ad5 intosymfony:7.4Oct 16, 2025
5 of 12 checks passed
@nicolas-grekasnicolas-grekas deleted the sec-fetch branchOctober 16, 2025 16:30
This was referencedOct 27, 2025
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@dunglasdunglasdunglas left review comments

@chalasrchalasrAwaiting requested review from chalasrchalasr is a code owner

Assignees

No one assigned

Projects

None yet

Milestone

7.4

Development

Successfully merging this pull request may close these issues.

3 participants

@nicolas-grekas@dunglas@carsonbot

[8]ページ先頭

©2009-2025 Movatter.jp