welcoMattic/security-core

Frozen snapshot of symfony/security-core from the oidc_login PR stack (symfony/symfony#64954), for the API Platform Con 2026 demo. Not the official split repository.

★ 0Forks 0PHPGitHub ↗Compare

README

Frozen snapshot, not a maintained package, not the official split repository.

This repository holds the symfony/security-core directory of welcoMattic/symfony@oidc-login-tuning, the head of the 7-PR stack that adds a native OpenID Connect Authorization Code Flow authenticator (oidc_login) to Symfony. Umbrella PR: symfony/symfony#64954.

It exists for one reason: letting a demo application install the branch with Composer while the PRs are still under review. Symfony forbids requiring symfony/symfony from an application, and the official split repositories only carry merged code.

{
    "repositories": [
        {"type": "vcs", "url": "https://github.com/welcoMattic/security-core"}
    ],
    "require": {
        "symfony/security-core": "dev-demo-apiplatformcon-2026 as 8.2.x-dev"
    }
}

The branch demo-apiplatformcon-2026 is deliberately frozen: rebasing the PR stack must not break the demo given at API Platform Con 2026. Once the PRs are merged, use the official symfony/security-core package instead.


Security Component - Core

Security provides an infrastructure for sophisticated authorization systems, which makes it possible to easily separate the actual authorization logic from so called user providers that hold the users credentials.

Getting Started

composer require symfony/security-core
use Symfony\Component\Security\Core\Authentication\AuthenticationTrustResolver;
use Symfony\Component\Security\Core\Authentication\Token\UsernamePasswordToken;
use Symfony\Component\Security\Core\Authorization\AccessDecisionManager;
use Symfony\Component\Security\Core\Authorization\Voter\AuthenticatedVoter;
use Symfony\Component\Security\Core\Authorization\Voter\RoleVoter;
use Symfony\Component\Security\Core\Authorization\Voter\RoleHierarchyVoter;
use Symfony\Component\Security\Core\Exception\AccessDeniedException;
use Symfony\Component\Security\Core\Role\RoleHierarchy;

$accessDecisionManager = new AccessDecisionManager([
    new AuthenticatedVoter(new AuthenticationTrustResolver()),
    new RoleVoter(),
    new RoleHierarchyVoter(new RoleHierarchy([
        'ROLE_ADMIN' => ['ROLE_USER'],
    ]))
]);

$user = new \App\Entity\User(...);
$token = new UsernamePasswordToken($user, 'main', $user->getRoles());

if (!$accessDecisionManager->decide($token, ['ROLE_ADMIN'])) {
    throw new AccessDeniedException();
}

Sponsor

The Security component for Symfony 8.1 is backed by SymfonyCasts.

Learn Symfony faster by watching real projects being built and actively coding along with them. SymfonyCasts bridges that learning gap, bringing you video tutorials and coding challenges. Code on!

Help Symfony by sponsoring its development!

Resources

Contributors

welcoMattic

Issues