magnetico-web/config/packages/security.yaml

48 lines
1.6 KiB
YAML
Raw Normal View History

2018-06-23 15:00:37 +00:00
security:
# https://symfony.com/doc/current/security.html#where-do-users-come-from-user-providers
providers:
default_provider:
2018-06-25 01:02:27 +00:00
entity:
class: App\Entity\User
property: username
manager_name: default
enable_authenticator_manager: true
password_hashers:
App\Entity\User:
algorithm: sodium
2018-06-23 15:00:37 +00:00
firewalls:
dev:
pattern: ^/(_(profiler|wdt)|css|images|js)/
security: false
2018-06-25 01:02:27 +00:00
api:
pattern: ^/api/
stateless: true
custom_authenticators:
- App\Security\ApiTokenAuthenticator
2018-06-25 01:02:27 +00:00
main:
pattern: ^/
provider: default_provider
2018-06-25 01:02:27 +00:00
form_login:
login_path: user_auth_login
check_path: user_auth_login
2018-06-25 01:02:27 +00:00
logout:
path: user_auth_logout
2018-06-25 01:02:27 +00:00
target: /
remember_me:
secret: '%kernel.secret%'
2018-10-26 00:11:32 +00:00
lifetime: 1209600
2018-06-25 01:02:27 +00:00
path: /
always_remember_me: true
2018-06-23 15:00:37 +00:00
# Easy way to control access for large sections of your site
# Note: Only the *first* access control that matches will be used
access_control:
- { path: ^/api/v1/login$, roles: PUBLIC_ACCESS }
- { path: ^/api/, roles: ROLE_USER }
- { path: ^/$, roles: PUBLIC_ACCESS }
- { path: ^/auth/, roles: PUBLIC_ACCESS }
- { path: ^/register/, roles: PUBLIC_ACCESS }
- { path: ^/magnet/, roles: PUBLIC_ACCESS }
2018-06-25 01:02:27 +00:00
- { path: ^/, roles: ROLE_USER }