You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Symfony 3.4配置security.yml:为特定正则路由开放匿名访问

How to Securely Allow Anonymous Access to a Locale-Prefixed Shared Route in Symfony 3.4

Got it, let's tackle this problem step by step. The core issue here is that all your application routes are prefixed with {_locale}, so your previous path attempts (like ^/q/) weren't matching the actual URL structure (e.g., /en/q/abc123), and you’re right to worry about q being misinterpreted as a locale. Here are two reliable solutions, with the first being the most maintainable:

Instead of relying on path patterns, you can directly target the customer_view route by name. This is better because it’s decoupled from the URL structure—if you ever change the route’s path later, you won’t have to update your security config.

Add this rule to your access_control list, making sure it comes before the catch-all ^/ rule (since Symfony processes rules top-to-bottom and stops at the first match):

access_control:
  - { path: ^/login, role: IS_AUTHENTICATED_ANONYMOUSLY }
  - { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY }
  - { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY }
  - { route: customer_view, role: IS_AUTHENTICATED_ANONYMOUSLY } # New rule
  - { path: ^/, role: ROLE_USER }

Symfony will automatically match all URLs associated with the customer_view route (including those with the {_locale} prefix) and allow anonymous access to them. No locale-related conflicts here—this is clean and future-proof.

2. Use a Regex Path to Match Valid Locales

If you prefer to stick with path patterns, you can write a regex that matches only valid locale prefixes followed by your /q/{token} path. This ensures q won’t be mistaken for a locale (since valid locales follow a standard format like en, fr, or en_US).

Add this regex-based rule before the catch-all:

access_control:
  - { path: ^/login, role: IS_AUTHENTICATED_ANONYMOUSLY }
  - { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY }
  - { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY }
  - { path: ^/[a-z]{2}(_[A-Z]{2})?/q/, role: IS_AUTHENTICATED_ANONYMOUSLY } # New regex rule
  - { path: ^/, role: ROLE_USER }

Breakdown of the regex:

  • ^/[a-z]{2}: Matches the start of the URL, followed by 2 lowercase letters (e.g., en, fr)
  • (_[A-Z]{2})?: Optionally matches a region suffix (e.g., _US, _GB)
  • /q/: Matches your shared route’s path segment

This ensures only URLs with valid locale prefixes followed by /q/ are allowed anonymously. Any request like /q/abc123 (without a valid locale) will still be blocked by the catch-all ^/ rule, since q doesn’t match the locale regex.

Critical Note:

Always remember that access control order matters. More specific rules must come before general ones—otherwise, the catch-all ^/ rule will override your shared route’s anonymous access permission.

内容的提问来源于stack exchange,提问作者Gauthier

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:19:23