Skip to content

Conversation

@Spomky
Copy link
Contributor

@Spomky Spomky commented Dec 12, 2025

ping @javiereguiluz

As you mentioned, Symfony Forms add CSRF tokens by default, including for forms using the GET method.
This change clarifies that this practice is not recommended and points users to the section explaining how to disable CSRF protection.

@carsonbot carsonbot added this to the 7.4 milestone Dec 12, 2025
@carsonbot carsonbot changed the title Enhance CSRF documentation with OWASP best practices and guidelines Enhance CSRF documentation with OWASP best practices and guidelines Dec 12, 2025
@javiereguiluz javiereguiluz modified the milestones: 7.4, 6.4 Dec 16, 2025
@carsonbot carsonbot changed the title Enhance CSRF documentation with OWASP best practices and guidelines [Form] Enhance CSRF documentation with OWASP best practices and guidelines Dec 16, 2025
@javiereguiluz javiereguiluz changed the base branch from 7.4 to 6.4 December 16, 2025 15:52
@javiereguiluz javiereguiluz merged commit 39e014b into symfony:6.4 Dec 16, 2025
3 checks passed
@javiereguiluz
Copy link
Member

Thanks Florent! We did some minor changes while merging:

  • Merged in 6.4 branch and all the upper maintained branches
  • Moved the note down a bit to include it in the form section (it felt a bit odd to show it at the very beginning of the article)
  • Minor rewords in some phrases

@Spomky Spomky deleted the csrf-token-idempotency branch December 16, 2025 16:12
@Spomky
Copy link
Contributor Author

Spomky commented Dec 16, 2025

Perfect 👍. If it's good for you, it's good for me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants