URL hacking in symfony admin generator
In symfony's admin generator, I can choose, for instance, to disable the delete 开发者_如何学JAVAand edit actions in generator.yml
Could a user change the URL and still access those functions, or should I also disable them in security.yml ?
Obviosly, if you disable them in config, they will not work in any way unless you enable them again. Fabien is not stupid ;)
精彩评论