upd: csrf

add csrf protection for forms
This commit is contained in:
2026-03-26 15:12:56 -04:00
parent 840058873a
commit c948b1e39d

11
config/packages/csrf.yaml Normal file
View File

@@ -0,0 +1,11 @@
# Enable stateless CSRF protection for forms and logins/logouts
framework:
form:
csrf_protection:
token_id: submit
csrf_protection:
stateless_token_ids:
- submit
- authenticate
- logout