Symfony Security in Depth
The Symfony Security Component has always been a powerful tool. And with the advent of the new Authenticator system, customizing Symfony Security has become more streamlined and flexible!
In this workshop, we will start out with a recap of the basics of building a modern authentication, and how the Authenticator system ties into standard authentication methods like a simple form login.
In the main part, we will look at how we can utilize the new Authenticators: we will use them to add JWT/OAuth support, and we check out how to use existing libraries to easily add customizable 2FA to your application.
The last part rounds up a collection of best practices that you should not neglect when building your authentication: Topics like CSRF protection, protection from timing attacks, rate limiting against brute force attempts.
Requirements for this workshop: You should bring a working knowledge of how to build generic applications with Symfony. Having configured a standard form login in Symfony before helps, but is not mandatory.
Check out the other workshops from SymfonyWorld Online 2021 Winter Edition conference.