Skip to content

feat: lazy evaluation context, SecurityBundle detection and profiler fixes - #7

Open
aubes wants to merge 3 commits into
mainfrom
feature/lazy-evaluation-context
Open

aubes wants to merge 3 commits into
mainfrom
feature/lazy-evaluation-context

Conversation

@aubes

@aubes aubes commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Evaluation context

  • evaluation_context.user_provider: auto now works: SecurityBundle is detected through kernel.bundles, so the authenticated user identifier becomes the targeting key. With SecurityBundle enabled but not configured (Symfony 6.4), the user provider does nothing instead of breaking the container compilation.
  • Context providers run on the first flag evaluation instead of on kernel.request. A request that evaluates no flag no longer reads the security token: a lazy firewall stays lazy and the response stays HTTP-cacheable.
  • An exception thrown by a context provider, or by a listener of EvaluationContextContributedEvent, is logged instead of failing the request.

Feature gate

  • feature_flag.on_disabled: auto picks access_denied only when SecurityBundle is enabled. With symfony/security-core installed but no SecurityBundle, a closed gate returned a 500 instead of a 403.

Profiler (second commit)

  • The panel reports when context providers did not run.
  • Object flags and array or date context attributes are shown with the VarDumper instead of breaking the panel.

Docs: lazy context providers, provider priority, personal data note, feature gate responses, configuration reference, debug:feature-flags output.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant