Skip to content

#93 Protect the login form and the logout against CSRF - #94

Draft
njoubert-cleverage wants to merge 2 commits into
mainfrom
93
Draft

njoubert-cleverage wants to merge 2 commits into
mainfrom
93

Conversation

@njoubert-cleverage

@njoubert-cleverage njoubert-cleverage commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Description

Fixes #93.

Milestone v4.0 (BC break, see below).

  • CleverAgeUiProcessExtension::prepend(): enable_csrf: true on the form_login of the main firewall (token id authenticate, parameter _csrf_token: the form_login defaults, also used by the EasyAdmin login template)
  • CleverAgeUiProcessExtension::prepend(): enable_csrf: true on the logout of the main firewall (token id logout, parameter _csrf_token): the logout link of the EasyAdmin user menu (LogoutUrlGenerator) carries the token, /process/logout without a valid token is refused (403)
  • LoginController: passes csrf_token_intention: authenticate, so the EasyAdmin login template renders the _csrf_token hidden field
  • composer.json: symfony/security-csrf declared (it was only installed as a transitive dependency)
  • docs: 03-users_and_security.md (prepended configuration, CSRF requirements, logout_path()) and UPGRADE.md v4.0 (overridden login template, own logout links, opt-outs); CHANGELOG entry under BC break

Tests:

  • SecurityTest::testLoginWithAnInvalidCsrfToken: the login page has the _csrf_token field; valid credentials with an invalid token are rejected (Invalid CSRF token.), the user stays logged out. testLogin still logs in with the token of the page
  • SecurityTest::testLogout: logout with the link of the user menu (with the token); testLogoutWithoutCsrfToken: /process/logout without token gives a 403, the user stays logged in
  • CleverAgeUiProcessExtensionTest::testPrepend: enable_csrf in the prepended form_login and logout

Checked:

  • bundle (Symfony 8.1, PHP 8.5): 331 tests OK; without the fix, the login and logout tests fail. composer validate, PHPStan, PHP-CS-Fixer, Rector OK
  • process-bundle-demo (Symfony 7.4, session-based CSRF tokens): login without token rejected with Invalid CSRF token., login with the token of the page redirects to the UI; /process/logout without token: 403, still logged in; logout link of the menu: logged out, redirected to the login

Requirements

  • Documentation updates
    • Reference
    • Changelog
  • Unit tests

Breaking changes

Applications that override the login template without the _csrf_token field, or that submit the login form without it, must add it, or set form_login.enable_csrf: false on their main firewall. Links to path('process_logout') in application templates must use logout_path() (or set logout.enable_csrf: false). See UPGRADE.md. The Symfony CSRF protection must be enabled (framework.csrf_protection, enabled by default when the session is).

🤖 Generated with Claude Code

@njoubert-cleverage njoubert-cleverage added bug Something isn't working enhancement New feature or request and removed bug Something isn't working labels Oct 5, 2026
@njoubert-cleverage njoubert-cleverage added this to the v4.0 milestone Oct 5, 2026
The prepended form_login configuration enables enable_csrf (token id `authenticate`, parameter `_csrf_token`) and
LoginController passes csrf_token_intention, so that the EasyAdmin login template renders the token field.
symfony/security-csrf is declared (it was only a transitive dependency). BC break for overridden login templates, see
UPGRADE.md v4.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@njoubert-cleverage njoubert-cleverage changed the title fix #93 Protect the login form against CSRF #93 Protect the login form against CSRF Oct 5, 2026
@njoubert-cleverage
njoubert-cleverage marked this pull request as draft October 8, 2026 09:00
The prepended logout configuration enables enable_csrf (token id `logout`, parameter `_csrf_token`): the logout link
of the EasyAdmin menu (LogoutUrlGenerator) carries the token, /process/logout without a valid token is refused (403).
UPGRADE.md v4.0 completed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@njoubert-cleverage njoubert-cleverage changed the title #93 Protect the login form against CSRF #93 Protect the login form and the logout against CSRF Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Login form and logout not protected against CSRF

1 participant