# see https://symfony.com/doc/current/reference/configuration/framework.html framework: secret: '%env(APP_SECRET)%' #csrf_protection: true http_method_override: false handle_all_throwables: true # The OAuth2 redirect_uri handed to MyE&P is generated from the incoming request, so an # unvalidated Host header would let a crafted request point the authorization code # somewhere else. Regex patterns, matched against the host without the scheme or port. trusted_hosts: ['%env(APP_TRUSTED_HOSTS)%'] # Enables session support. Note that the session will ONLY be started if you read or write from it. # Remove or comment this section to explicitly disable session support. session: handler_id: session.handler.native_file cookie_secure: true cookie_samesite: lax storage_factory_id: session.storage.factory.native save_path: '%kernel.project_dir%/var/sessions/%kernel.environment%' name: epsession #esi: true #fragments: true php_errors: log: true router: default_uri: '%env(APP_BASE_URI)%' when@test: framework: test: true session: storage_factory_id: session.storage.factory.mock_file