Skip to content

Commit d5919dd

Browse files
committed
minor symfony#59080 [Security] Update incorrect form authenticator changelog item (bobvandevijver)
This PR was merged into the 7.1 branch. Discussion ---------- [Security] Update incorrect form authenticator changelog item | Q | A | ------------- | --- | Branch? | 7.1 <!-- see below --> | Bug fix? | yes | New feature? | no <!-- please update src/**/CHANGELOG.md files --> | Deprecations? | no <!-- please update UPGRADE-*.md and src/**/CHANGELOG.md files --> | Issues | # <!-- prefix each issue number with "Fix #", no need to create an issue if none exists, explain below instead --> | License | MIT <!-- Replace this notice by a description of your feature/bugfix. This will help reviewers and should be a good start for the documentation. Additionally (see https://symfony.com/releases): - Always add tests and ensure they pass. - Bug fixes must be submitted against the lowest maintained branch where they apply (lowest branches are regularly merged to upper ones so they get the fixes too). - Features and deprecations must be submitted against the latest branch. - For new features, provide some code snippets to help understand usage. - Changelog entry should follow https://symfony.com/doc/current/contributing/code/conventions.html#writing-a-changelog-entry - Never break backward compatibility (see https://symfony.com/bc). --> Related to symfony#53851, symfony#57378 & symfony#59079. ~~Whether or not this an actual CVE, I believe this should be removed from the changelog anyways as it does not throw a bad request anymore.~~ ~~If we do keep considering it a new feature, it should probably be changed to reflect the correct exception.~~ As discussed, now only an update to note the actual exception being thrown. Commits ------- 38f8ec2 Fix change log to mentioned thrown exception
2 parents aacfaa2 + 38f8ec2 commit d5919dd

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/Symfony/Component/Security/Http/CHANGELOG.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ CHANGELOG
66

77
* Add `#[IsCsrfTokenValid]` attribute
88
* Add CAS 2.0 access token handler
9-
* Make empty username or empty password on form login attempts return Bad Request (400)
9+
* Make empty username or empty password on form login attempts throw `BadCredentialsException`
1010

1111
7.0
1212
---

0 commit comments

Comments
 (0)