Skip to content

feat: set flight.views.restrict_to_path and disable method override in bootstrap - #12

Merged
n0nag0n merged 3 commits into
masterfrom
feat/bootstrap-security-hardening
Oct 6, 2026
Merged

n0nag0n merged 3 commits into
masterfrom
feat/bootstrap-security-hardening

Conversation

@ambrose5773

@ambrose5773 ambrose5773 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Bootstrap now sets:

  • flight.allow_method_override → false
  • flight.views.restrict_to_path → true

Older cores simply ignore the unknown config key. Documents both in SECURITY.md.

Depends on flightphp/core#729.

Test plan

  • PHPUnit green (12 tests)

…tstrap

New projects get flight.allow_method_override off and View::$restrictToPath on when core supports it. Twig still uses its own loader root under app/views.
Use Flight::set for view path containment, same as the other hardening switches. Harmless on older core that ignores the key.
@ambrose5773 ambrose5773 changed the title feat: enable view path restriction and disable method override in bootstrap feat: set flight.views.restrict_to_path and disable method override in bootstrap Oct 5, 2026
@n0nag0n
n0nag0n merged commit 2ebe48a into master Oct 6, 2026
@n0nag0n
n0nag0n deleted the feat/bootstrap-security-hardening branch October 6, 2026 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants