Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork5.3k
[DX] Suggest a hint to any auth-check#4304
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Uh oh!
There was an error while loading.Please reload this page.
Conversation
Suggest a hint that you need a minimum of auth-check to let the voters vote.
stof commentedOct 8, 2014
I don't understand what you mean |
wouterj commentedOct 8, 2014
Voters are used when using ->isGranted. When that's called depends on your code if I'm correct. The security system in general only works when the page is under a firewall, it doesn't depend on the access rules. |
DavidBadura commentedOct 9, 2014
If you have only following security configuration without |
stof commentedOct 9, 2014
Of course they won't execute. Defining a firewall allows you to authenticate the user. Voters are not involved in this process at all. They are the authorization system. they are what |
larsborn commentedOct 10, 2014
If you implement the IP Blacklist example in a freshly created Symfony app, it doesn't work, since you don't ask for any permissions (as stof pointed out). This is exactly the reason, I suggested this minimal authorization check for IS_AUTHENTICATED_ANONYMOUSLY. If you think, that it bloats this recipe, I could also suggest a small hint instead. Either way I think, that at least a hint is necessary. |
larsborn commentedOct 30, 2014
push |
wouterj commentedOct 31, 2014
I believe the complete article is wrong. The voter is part of the authorization process, while the article suggests it's part of the authentication process. I think a backlist needs to be implemented by an |
larsborn commentedNov 28, 2014
does renaming even help, if I want to get noticed by dx.symfony.com? :) |
stof commentedDec 6, 2014
Currently, dx.symfony.com only checks labelled issues. It does not yet check issue titles. |
larsborn commentedDec 6, 2014
then Ryan might have talked about a future version of dx.symfony.com on the SymfonyCon Madrid. |
stof commentedDec 16, 2014
Well, it is planned. There is a TODO in the code saying it is not implemented yet |
larsborn commentedDec 16, 2014
but am I right, when I say, that I cannot add labels? :) |
xabbuh commentedDec 16, 2014
@larsborn Yes, only repository collaborators can add or remove labels. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
The comma is not needed here.
xabbuh commentedDec 16, 2014
However, we should first finish the discussion if the change does make sense at all. |
wouterj commentedFeb 19, 2015
@weaverryan@stof@iltar can you please share your opinions on my comment:
|
linaori commentedFeb 20, 2015
@wouterjcookbook/security/access_control.html IP Blacklisting is mentioned here, seems to me like this is part of the authorization and not authentication.
Right now I can't check if this is still a valid case; I remember that if you login(authenticate) without setting up proper As far as I know, the |
weaverryan commentedMar 15, 2015
Hey@larsborn! So sorry, I got a little busy :). Some points:
So, I'm going to merge this, but open an issue about this whole article. Thanks! |
Suggest a hint that you need a minimum of auth-check to let the voters vote.