symfony-yoandev-security

Installation
SKILL.md

Security

Tier: core the moment the application has users — the wiring check, one firewall, roles for zones and voters for objects. The hardening table is core too; #[RateLimit] beyond login is on demand.

Who the request is, and what that lets them do. Two questions, two mechanisms — and the first is the one people skip.

First: is security actually wired?

On a freshly generated project it is not. The recipe ships a firewall with no authenticator and a users_in_memory provider: no User entity, no way to log in, nothing for #[CurrentUser] to resolve. Thirty seconds to check — an empty authenticator list alongside users_in_memory is the untouched skeleton state:

php bin/console debug:firewall main          # authenticators, provider, stateless or not
grep -A3 'providers:' config/packages/security.yaml
Installs
6
GitHub Stars
4
First Seen
Sep 5, 2026
symfony-yoandev-security — yoanbernabeu/symfony-yoandev-skills