Logo Questions Linux Laravel Mysql Ubuntu Git Menu

Disable symfony 2 csrf token protection on ajax submit





i'm building a mobile app talking to my symfony2 app via webservices I can't find a way to disable csrf protection on a specific controller/action

i want to post registration data to this action and use sf2 form validation. I do not call the form in my mobile app

Can't change container parameters in action, throw an exception because it is a frozen parameter...

I do not want to disable form protection for whole my application

any clue ?

thanks !

update: with symfony 2.1.x

/**  * {@inheritdoc}  */ public function setDefaultOptions(OptionsResolverInterface $resolver) {     $resolver->setDefaults(array(         'csrf_protection'   => false,     )); } 
like image 748
Julien Rollin Avatar asked Mar 27 '12 10:03

Julien Rollin

2 Answers

If you're looking for a bit easier and faster solution than suggested in answer above, here's how:

<?php  // ...  use Symfony\Component\Form\AbstractType; use Symfony\Component\Form\FormBuilder; use Symfony\Component\OptionsResolver\OptionsResolver;  class MyType extends AbstractType {     // ...     public function configureOptions(OptionsResolver $resolver)     {         $resolver->setDefaults(array(             'csrf_protection' => false,         ));     } } 

.. or if you're using older versions (Symfony 2.0.*):

<?php  // ...  use Symfony\Component\Form\AbstractType; use Symfony\Component\Form\FormBuilder;  class MyType extends AbstractType {     // ....      public function getDefaultOptions(array $options)     {         $options = parent::getDefaultOptions($options);         $options['csrf_protection'] = false;          return $options;     } } 

Consult the Symfony documentation for additional information.

Edit: updated answer to latest Symfony version, thanks naitsirch

like image 147
Inoryy Avatar answered Sep 17 '22 15:09


Using the form factory

For those who want to create a simple form in a controller:

$form = $this->container->get('form.factory')     ->createNamedBuilder(null, 'form', null, array('csrf_protection' => false))     ->add('yourField','text', array(         'label' => false,         'mapped' => false     ))     ->getForm(); 
like image 23
Mick Avatar answered Sep 16 '22 15:09
