Skip to content

Commit db15305

Browse files
committed
Merge branch '7.4' into 8.0
* 7.4: fix default CSRF token input name
2 parents c7243e0 + da5113a commit db15305

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

security/csrf.rst

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@ to do anything to be protected against CSRF attacks.
102102

103103
.. _form-csrf-customization:
104104

105-
By default Symfony adds the CSRF token in a hidden field called ``_csrf_token``, but
105+
By default Symfony adds the CSRF token in a hidden field called ``_token``, but
106106
this can be customized (1) globally for all forms and (2) on a form-by-form basis.
107107
Globally, you can configure it under the ``framework.form`` option:
108108

@@ -151,7 +151,7 @@ method of each form::
151151
// enable/disable CSRF protection for this form
152152
'csrf_protection' => true,
153153
// the name of the hidden HTML field that stores the token
154-
'csrf_field_name' => '_token',
154+
'csrf_field_name' => 'custom_token_name',
155155
// an arbitrary string used to generate the value of the token
156156
// using a different string for each form improves its security
157157
// when using stateful tokens (which is the default)

0 commit comments

Comments
 (0)