Skip to content

Conversation

@nicolas-grekas
Copy link
Member

Q A
Branch? 7.4
Bug fix? no
New feature? yes
Deprecations? no
Issues -
License MIT

Thanks to @dunglas for pointing me at https://www.alexedwards.net/blog/preventing-csrf-in-go

This check allows confirming the same-origin of the request without having to configure the X-Forwarded et al header when using a reverse-proxy.

Nice DX improvement! Browser support is almost as good as for Origin/Referer headers: https://caniuse.com/mdn-http_headers_sec-fetch-site

@nicolas-grekas nicolas-grekas merged commit ad96ad5 into symfony:7.4 Oct 16, 2025
5 of 12 checks passed
@nicolas-grekas nicolas-grekas deleted the sec-fetch branch October 16, 2025 16:30
This was referenced Oct 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants