Login and Sessions

View saved

Goal

This snapshot advances Keystone Gazette by teaching you to authenticate with Symfony Security form login.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use PHP 8.2+, Composer, and Docker for MySQL stages.

Port 8002 must be free. Copy .env.example before starting database stages.

  • PHP 8.2+ and Composer
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Security form login uses a firewall and a signed session cookie.

Keep controllers thin: forms accept input, Doctrine entities enforce rules, and Twig escapes output by default.

Walkthrough

Configure form_login, verify credentials, clear session on logout.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

security:\n  firewalls:\n    main:\n      form_login: true

Run and verify

Enter 07-Login-And-Sessions, install Composer deps, copy .env.example, and start the Symfony server on port 8002.

Open http://127.0.0.1:8002. Watch the terminal for validation and database errors.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-symfony-blog.git
cd fcc-symfony-blog/07-Login-And-Sessions
composer install
cp .env.example .env
symfony server:start --port=8002 --no-tls
# or: php -S 127.0.0.1:8002 -t public

Troubleshooting

Changing APP_SECRET invalidates sessions.

For database failures, confirm Docker and the keystone_NN name when applicable. Never commit .env or vendor.

  • Read the first error first
  • Restart after environment changes
  • Never commit secrets

Try this

Log in, restart, confirm session, then log out.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Profiles and Media

Comments

One comment per signed-in account. Comments are saved with this page’s URL.