-
-
Notifications
You must be signed in to change notification settings - Fork 9.8k
[Security] Add RememberMe Badge to LoginLinkAuthenticator #39584
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
wouterj
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍 This still keeps all control by the user (as remember me needs to be explicitly enabled on the firewall), but I see no reason not to allow login links to support remembered (if someone decides that for their application).
I think this can be merged as bugfix in 5.2? (given that this class is experimental, login link is extremely new and it doesn't change any behavior unless a user explicitly enabled remember me)
chalasr
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍🏼 as a bugfix on 5.2
d47ae9a to
d38fc4d
Compare
|
rebased |
weaverryan
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍 That's a bug - good catch!
|
Thank you Jérémy. |
I'm replacing a custom home-made magic link authenticator by the Symfony one, and I missed this behavior. I had to use a EventListener to add the badge to the passeport.
I'm not sure, if the badge were missing on purpose /cc @weaverryan @wouterj