[Security] Added check_post_only to the login link authenticator #38550
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This is useful when adding a page that requires a user action in order to validate the check link. That is required when using a single-use login link, to workaround browser and email client previews (which trigger a request).
See also the short docs discussion about this: symfony/symfony-docs#14389 (comment)
For reference, I choose this option name as it relates to the
post_onlyoption in theFormLoginAuthenticator, which is about exactly the same thing. I didn't thinkpost_onlywas a 100% clear name, but I'm happy to change this option to that for complete consistency.cc @weaverryan