/
security.yml
89 lines (75 loc) · 3.34 KB
/
security.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
security:
providers:
contao.security.backend_user_provider:
id: contao.security.backend_user_provider
contao.security.frontend_user_provider:
id: contao.security.frontend_user_provider
encoders:
Contao\User:
algorithm: auto
firewalls:
dev:
pattern: ^/(_(profiler|wdt|error)|css|images|js)/
security: false
contao_install:
pattern: ^/contao/install$
security: false
contao_backend:
entry_point: contao.security.entry_point
request_matcher: contao.routing.backend_matcher
provider: contao.security.backend_user_provider
user_checker: contao.security.user_checker
anonymous: ~
switch_user: true
contao_login:
login_path: contao_backend_login
check_path: contao_backend_login
default_target_path: contao_backend
success_handler: contao.security.authentication_success_handler
failure_handler: contao.security.authentication_failure_handler
remember_me: false
two_factor:
auth_form_path: contao_backend_login
check_path: contao_backend_two_factor
auth_code_parameter_name: verify
logout:
path: contao_backend_logout
handlers:
- contao.security.logout_handler
success_handler: contao.security.logout_success_handler
contao_frontend:
request_matcher: contao.routing.frontend_matcher
provider: contao.security.frontend_user_provider
user_checker: contao.security.user_checker
anonymous: ~
switch_user: false
contao_login:
login_path: contao_frontend_login
check_path: contao_frontend_login
default_target_path: contao_root
failure_path: contao_root
success_handler: contao.security.authentication_success_handler
failure_handler: contao.security.authentication_failure_handler
remember_me: true
use_forward: true
two_factor:
auth_form_path: contao_frontend_two_factor
check_path: contao_frontend_two_factor
auth_code_parameter_name: verify
success_handler: contao.security.two_factor.frontend_success_handler
failure_handler: contao.security.two_factor.frontend_failure_handler
remember_me:
secret: '%secret%'
remember_me_parameter: autologin
logout:
path: contao_frontend_logout
target: contao_root
handlers:
- contao.security.logout_handler
success_handler: contao.security.logout_success_handler
access_control:
- { path: ^/contao/login$, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/contao/logout$, roles: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/contao(/|$), roles: ROLE_USER }
- { path: ^/_contao/two-factor, roles: [IS_AUTHENTICATED_2FA_IN_PROGRESS, ROLE_MEMBER] }
- { path: ^, roles: [IS_AUTHENTICATED_2FA_IN_PROGRESS, IS_AUTHENTICATED_ANONYMOUSLY] }