Frozen snapshot, not a maintained package, not the official split repository.
This repository holds the
symfony/security-coredirectory of welcoMattic/symfony@oidc-login-tuning, the head of the 7-PR stack that adds a native OpenID Connect Authorization Code Flow authenticator (oidc_login) to Symfony. Umbrella PR: symfony/symfony#64954.It exists for one reason: letting a demo application install the branch with Composer while the PRs are still under review. Symfony forbids requiring
symfony/symfonyfrom an application, and the official split repositories only carry merged code.{ "repositories": [ {"type": "vcs", "url": "https://github.com/welcoMattic/security-core"} ], "require": { "symfony/security-core": "dev-demo-apiplatformcon-2026 as 8.2.x-dev" } }The branch
demo-apiplatformcon-2026is deliberately frozen: rebasing the PR stack must not break the demo given at API Platform Con 2026. Once the PRs are merged, use the officialsymfony/security-corepackage instead.
Security provides an infrastructure for sophisticated authorization systems, which makes it possible to easily separate the actual authorization logic from so called user providers that hold the users credentials.
composer require symfony/security-coreuse Symfony\Component\Security\Core\Authentication\AuthenticationTrustResolver;
use Symfony\Component\Security\Core\Authentication\Token\UsernamePasswordToken;
use Symfony\Component\Security\Core\Authorization\AccessDecisionManager;
use Symfony\Component\Security\Core\Authorization\Voter\AuthenticatedVoter;
use Symfony\Component\Security\Core\Authorization\Voter\RoleVoter;
use Symfony\Component\Security\Core\Authorization\Voter\RoleHierarchyVoter;
use Symfony\Component\Security\Core\Exception\AccessDeniedException;
use Symfony\Component\Security\Core\Role\RoleHierarchy;
$accessDecisionManager = new AccessDecisionManager([
new AuthenticatedVoter(new AuthenticationTrustResolver()),
new RoleVoter(),
new RoleHierarchyVoter(new RoleHierarchy([
'ROLE_ADMIN' => ['ROLE_USER'],
]))
]);
$user = new \App\Entity\User(...);
$token = new UsernamePasswordToken($user, 'main', $user->getRoles());
if (!$accessDecisionManager->decide($token, ['ROLE_ADMIN'])) {
throw new AccessDeniedException();
}The Security component for Symfony 8.1 is backed by SymfonyCasts.
Learn Symfony faster by watching real projects being built and actively coding along with them. SymfonyCasts bridges that learning gap, bringing you video tutorials and coding challenges. Code on!
Help Symfony by sponsoring its development!