Skip to content

#93 Protect the login form against CSRF - #94

Open
njoubert-cleverage wants to merge 1 commit into
mainfrom
93
Open

njoubert-cleverage wants to merge 1 commit into
mainfrom
93

Conversation

@njoubert-cleverage

@njoubert-cleverage njoubert-cleverage commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Description

Fixes #93.

Milestone v4.0 (BC break, see below).

  • CleverAgeUiProcessExtension::prepend(): enable_csrf: true on the form_login of the main firewall (token id authenticate, parameter _csrf_token: the form_login defaults, also used by the EasyAdmin login template)
  • LoginController: passes csrf_token_intention: authenticate, so the EasyAdmin login template renders the _csrf_token hidden field
  • composer.json: symfony/security-csrf declared (it was only installed as a transitive dependency)
  • docs: 03-users_and_security.md (prepended configuration, CSRF requirements) and UPGRADE.md v4.0 (overridden login template, opt-out); CHANGELOG entry under BC break

Tests:

  • SecurityTest::testLoginWithAnInvalidCsrfToken: the login page has the _csrf_token field; valid credentials with an invalid token are rejected (Invalid CSRF token.), the user stays logged out. testLogin still logs in with the token of the page
  • CleverAgeUiProcessExtensionTest::testPrepend: enable_csrf in the prepended firewall

Checked:

  • bundle (Symfony 8.1, PHP 8.5): 330 tests OK; without the fix, both tests fail. composer validate, PHPStan, PHP-CS-Fixer, Rector OK
  • process-bundle-demo (Symfony 7.4, session-based CSRF tokens): login without token rejected with Invalid CSRF token., login with the token of the page redirects to the UI

Logout CSRF (logout.enable_csrf) is not changed: the logout is a GET link of the EasyAdmin menu.

Requirements

  • Documentation updates
    • Reference
    • Changelog
  • Unit tests

Breaking changes

Applications that override the login template without the _csrf_token field, or that submit the login form without it, must add it, or set enable_csrf: false on their main firewall (see UPGRADE.md). The Symfony CSRF protection must be enabled (framework.csrf_protection, enabled by default when the session is).

🤖 Generated with Claude Code

@njoubert-cleverage njoubert-cleverage added bug Something isn't working enhancement New feature or request and removed bug Something isn't working labels Oct 5, 2026
@njoubert-cleverage njoubert-cleverage added this to the v4.0 milestone Oct 5, 2026
The prepended form_login configuration enables enable_csrf (token id `authenticate`, parameter `_csrf_token`) and
LoginController passes csrf_token_intention, so that the EasyAdmin login template renders the token field.
symfony/security-csrf is declared (it was only a transitive dependency). BC break for overridden login templates, see
UPGRADE.md v4.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@njoubert-cleverage njoubert-cleverage changed the title fix #93 Protect the login form against CSRF #93 Protect the login form against CSRF Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Login form not protected against CSRF

1 participant