Skip to content

[LiveComponent] Check secret is not empty + add [SensitiveParameter] - #2461

Merged
smnandre merged 1 commit into
symfony:2.xfrom
smnandre:live/fix-secret-sensitive-not-empty
Dec 24, 2024
Merged

[LiveComponent] Check secret is not empty + add [SensitiveParameter]#2461
smnandre merged 1 commit into
symfony:2.xfrom
smnandre:live/fix-secret-sensitive-not-empty

Conversation

@smnandre

Copy link
Copy Markdown
Member
Q A
Bug fix? yes
New feature? no
Issues Fix #...
License MIT

Improve security before we allow secret customization for LiveComponents (cf #2453)

I consider this a fix as passing an empty string for secret produces the same hash as passing null... which is deprecated for obvious reasons.

…ameter]

Improve security before we allow secret customization for LiveComponents (cf symfony#2453)

I consider this a fix as passing an empty string for secret produce the same hash as passing null... which is deprecated for obvious reasons.
@carsonbot carsonbot added Bug Bug Fix LiveComponent Status: Needs Review Needs to be reviewed labels Dec 21, 2024
@smnandre

Copy link
Copy Markdown
Member Author

(fabbot errors unrelated)

@carsonbot carsonbot added Status: Reviewed Has been reviewed by a maintainer and removed Status: Needs Review Needs to be reviewed labels Dec 21, 2024
@smnandre
smnandre merged commit a63464e into symfony:2.x Dec 24, 2024
smnandre added a commit that referenced this pull request Dec 24, 2024
… and checksums (smnandre)

This PR was squashed before being merged into the 2.x branch.

Discussion
----------

[LiveComponent] Allow configuring secret for fingerprints and checksums

| Q             | A
| ------------- | ---
| Bug fix?      | no
| New feature?  | yes
| Issues        | Fix #2453
| License       | MIT

Allow to configure a dedicated secret (used in FingerprintCalculator and LiveComonentHydrator)

Suggested by `@dkarlovi` in #2453
Implementation inspired by [symfony #56840](symfony/symfony#56840)

Should be merged _after_  #2461

Commits
-------

a641a2e [LiveComponent] Allow configuring secret for fingerprints and checksums
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Bug Bug Fix LiveComponent Status: Reviewed Has been reviewed by a maintainer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants