Skip to content

[Security] Tell about stateless CSRF protection #20964

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 22, 2025

Conversation

nicolas-grekas
Copy link
Member

Fix #20306

Copy link
Member

@wouterj wouterj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wonderful, thank you Nicolas!

I've made some suggestions to try to avoid a "wall of text", but other than that I think this is great!

@nicolas-grekas
Copy link
Member Author

Thanks @wouterj, PR updated.

@javiereguiluz javiereguiluz added this to the 7.2 milestone May 22, 2025
@javiereguiluz javiereguiluz merged commit 5a63313 into symfony:7.2 May 22, 2025
3 checks passed
@javiereguiluz
Copy link
Member

Nicolas, thanks a lot for this important contribution and for updating the docs too. This is now merged!

Thanks also to all the folks who did a great technical review of this contribution!

@nicolas-grekas nicolas-grekas deleted the csrf branch May 22, 2025 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment