Skip to content

Conversation

@Spomky
Copy link
Contributor

@Spomky Spomky commented Dec 12, 2025

ping @javiereguiluz

As you mentioned, Symfony Forms add CSRF tokens by default, including for forms using the GET method.
This change clarifies that this practice is not recommended and points users to the section explaining how to disable CSRF protection.

@carsonbot carsonbot added this to the 7.4 milestone Dec 12, 2025
@carsonbot carsonbot changed the title Enhance CSRF documentation with OWASP best practices and guidelines Enhance CSRF documentation with OWASP best practices and guidelines Dec 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants